| Status | Autorun name | Command | Description |
| X | RPCserv32 | services.exe | Added by the MYDOOM.AL WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | RPCserv32g | NB32EXT2.EXE | Added by the BOBAX.AD WORM! |
| X | RPCserv32g | WINLOGON.EXE | Added by the BOBAX.AD WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | RPCserv32g | services.exe | Added by the BOBAX.AA WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | RPCserv32g | CSRSS.EXE | Added by the BOBAX.AD WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | RPCserv32g | MSDEFR.EXE | Added by the BOBAX.AD WORM! |
| Y | RPCSS.exe | rpcss.exe | Remote Procedure Call. Required by windows for programs to communicate with each other on networks/different machines. Originally for NT only but now installed with Win98/98se. Under Win98/98se, a program may need it to communicate with other components of itself. You could delete the program but if any abnormalities occur soon after then reinstall. Under NT, deleting this critical system component will disable the OS. For a more detailed explanation see here |
| X | RpcxWindows Extensions | rpcxwinex.exe | Added by the RBOT.ACP WORM! |
| Y | Rps | Rps.exe | Main program for internet security suites sourced by Radialpoint for ISP customers such as Virgin Media, AT&T, Bell Canada, TELUS Corporation and Verizon Online |
| U | RPSP | Rpsserv32.exe | Red Pill Spy surveillance software. Uninstall this software unless you put it there yourself |
| X | Rr2 | rundll32.exe | Added by the LINEAG-ADI TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir%\addins |
| X | RRMedic | rrmedic.exe | Troubleshooting utility for the RoadRunner cable internet service. Not required and you are advised to completely uninstall it. Provides a lot of false alarms and gets a lot of people panicking about there internet connection |
| X | rrmso | bqhrmug.exe | Added by the AGENT-GYY TROJAN! |
| X | rro | rundll32.exe | Added by the LINEAG-AAE TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %ProgramFiles%\Microsoft |
| X | rs32net | rs32net.exe | Added by the AGENT-IFH TROJAN! |
| U | rscmpt | rscmpt.exe | Required on the GeFroce 64 meg MX card to show the full 64 meg memory and appears to be a software memory emulator running under the Win2K - see here. High CPU useage results - hence the U status |
| N | RSD_HDDThermo | HDD Thermometer.exe | Freeware hard disk thermometer from RSD Software that constantly monitors the temperature of the hard disk and takes the necessary measures to avoid overheating by providing warnings with alarm tones or switching off the computer or entering hibernation mode. No longer supported |
| X | rsmb | rsmb.exe | Added by the WAREZOV.C WORM! |
| X | rsmb32 | rsmb32.exe | Added by the STRATION.AV WORM! |
| U | rsMenu | rsMenu.exe | Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000. Formally Randsoft Harmony '98 |
| X | RSPC Driver | [random filename].exe | Added by the RBOT-SN WORM! |
| X | RSPC Driver D | [random filename] | Added by a variant of the RBOT WORM! |
| ? | RSRCMTZ | RSRCMTZ.exe | ?? |
| X | rsrvmon.exe | rsrvmon.exe | Added by the AGENT.NY TROJAN! |
| X | RSS | rundll32 RSSToolbar.dll, DllRunMain | "Related Sites" toolbar - SearchAndClick hijacker variant |
| U | RssReader | RssReader.exe | RssReader - a free RSS reader able to display any RSS and Atom news feed (XML) |
| X | rsvp | rsvp.exe /waitservice | Added by the HORST.Q TROJAN! Note - this is not the legitimate rsvp.exe which is always located in %System%. This one is located in either %Windir%, %Windir%\System, %Temp%, %AppData%, %AppData%\Microsoft or %System%\drivers |
| X | RsWin | lsass.exe | Added by the DELCANTI-B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "12053" subfolder |
| X | RsWin | lsass.exe | Added by the SILLY.BR WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "4350" subfolder |
| X | RSync | netsync.exe | SafeSurfing adware |
| X | rtasks | rtasks.exe | Part of rogue software including members of the AVSystemCare security suite family (see here for examples), WinAntiVirus Pro 2006 and WinAntiVirus Pro 2007 |
| U | rtcdll | rtcdll.exe | RTCDLL is "Real Time Communication" and is associated with Windows Messenger (the IM application, not messenger service). It is only necessary if you use Windows Messenger. Most people use MSN Messenger instead, so it is not required in those cases |
| X | RTHDBPL | lsass.exe | Added by the ROUTROBOT WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\SystemProc |
| N | RTHDCPL | RTHDCPL.EXE | Realtek HD Audio Control Panel, installed with the XP/2K drivers for on-board Realtek HD audio codecs. Unless you have the default (but optional) System Tray icon enabled, the only purpose this entry serves is to detect and allow you to configure any devices plugged into the jacks - such as headphones and a microphone. With the System Tray icon enabled it will also inform you when devices are removed and give you access to the Sound Manager and other multimedia functions. The Sound Manager is also available via the Control Panel and this entry is therefore only required if you regularly change sound schemes |
| N | RtHDVCpl | RtHDVCpl.exe | Realtek HD Audio Manager, installed with the Vista/7 drivers for on-board Realtek HD audio codecs. Unless you have the default (but optional) System Tray icon enabled, the only purpose this entry serves is to detect and allow you to configure any devices plugged into the jacks - such as headphones and a microphone. With the System Tray icon enabled it will also inform you when devices are removed and give you access to the Sound Manager and other multimedia functions. The Sound Manager is also available via the Control Panel and this entry is therefore only required if you regularly change sound schemes |
| N | RtHDVCpl | RAVCpl64.exe | Realtek HD Audio Manager, installed with the 64-bit Vista/7 drivers for on-board Realtek HD audio codecs. Unless you have the default (but optional) System Tray icon enabled, the only purpose this entry serves is to detect and allow you to configure any devices plugged into the jacks - such as headphones and a microphone. With the System Tray icon enabled it will also inform you when devices are removed and give you access to the Sound Manager and other multimedia functions. The Sound Manager is also available via the Control Panel and this entry is therefore only required if you regularly change sound schemes |
| X | rtkernsw | [random filename] | Added by a variant of the SLAPER TROJAN! |
| X | rtl.exe | rtl.exe | Added by the TIOTUA-J TROJAN! |
| X | RtlAudio | RtlAudio.exe | Added by the GRAYBIR-U TROJAN! |
| N | RtlMon.exe | RtlMon.exe | Monitor for RealTek network card |
| Y | RTMonitor | RTMONI~1.exe | Real-time monitor for Cheyenne AntiVirus - acquired by CA and no longer available |
| X | rtos | rtos.exe | IRC trojan |
| ? | RTStartMute | N/A | ?? |
| Y | rtvscn95 | RTVSCN95.EXE | Real-time virus scanner component of Norton Anti-Virus Corporate Edition |
| U | RtWLan | RtWLan.exe | Configuration utility for the Netgear WG111 54 Mbps Wireless USB 2.0 Adapter that "provides wireless access to your desktop or notebook PC through the computer's USB port" |
| X | RubeL | RubeL.exe | Added by the RUBY-B TROJAN! |
| X | Ruby13 | Ruby13.exe | Added by the MEXER.E WORM! |
| X | Ruby14 | Ruby14.exe | Added by the FIGHTRUB-A WORM! |
| X | rudll32 | spooler.exe | Added by the VB-EZJ WORM! |
| X | ruin | system32.exe | Added by the DELF-JM TROJAN! |
| U | RuLaunch | RuLaunch.exe | Instant Updater for McAfee's VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis |
| X | Run | real.exe | Added by the LOVGATE.E WORM! |
| X | run | Autoexec.com | Added by the HOLCAS.A WORM! |
| X | run | inetinfo.exe | Added by the BINGHE TROJAN! |
| X | Run | help.exe | IESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN! |
| X | run | services.exe | Added by the KREPPER-N TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\inet10066 |
| X | run | rundll32.exe rsrc.dll | Chinese originated browser hijacker - redirecting to 4199.com Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | run | cchost.exe | Added by the SQUATBOT-C TROJAN! |
| X | run | e.exe | Added by the IMONI-E TROJAN! |
| X | run | winsys32.exe | Added by the DELF.CP BACKDOOR! |
| X | run | mexica.exe | Added by the AUTORUN.AEV WORM! |
| X | Run | Manager.exe | Added by the DELF.EUN TROJAN! The file is found in %AppData%\Roaming\Adobe - see the link for more information |
| U | Run Google Web Accelerator | GoogleWebAccWarden.exe | Google Web Accelerator |
| X | Run Msn Messenger | msnmgr.exe | Added by the AGOBOT.HA WORM! |
| X | Run MSupdt32 | wscript MSupdt32.vbs | Added by the CASER WORM! |
| U | Run Nintendo Wi-Fi USB Connector Registration Tool | NintendoWFCReg.exe | Related to Wi-Fi USB Connector from Nintendo |
| U | Run POPFile in background | perl.exe | POPFile - E-mail spam blocker |
| U | Run POPFile in background | wperl.exe | POPFile - E-mail spam blocker |
| X | Run Services as Application | localsvc.exe | Added by the DLOADER-NY TROJAN! |
| X | Run Services as Application | netsvc.exe | Added by the DLOADER-NY TROJAN! |
| X | Run Services as Application | spoolsvc.exe | Added by the DLOADER-NY TROJAN! |
| X | Run Services as Application | svcadmin.exe | Added by the DLOADER-NY TROJAN! |
| X | Run Services as Application | svcman.exe | Added by the DLOADER-NY TROJAN! |
| X | Run Services as Application | svcrun.exe | Added by the DLOADER-NY TROJAN! |
| X | Run Services as Application | tcpsvc.exe | Added by the DLOADER-NY TROJAN! |
| X | Run Services as Application | websvc.exe | Added by the DLOADER-NY TROJAN! |
| U | Run StartupMonitor | StartupMonitor.exe | Mike Lin's StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu |
| X | run windows | servic.bat | Added by the REBOOT-AP TROJAN! |
| N | run= | pcfix2k.exe | pcfix2k splash screen |
| X | run= | ptlseq.cpl | PhoenixNet BIOS adware. See here |
| U | run= | ramsys.exe | Advanced Startup Manager from Rays Lab |
| ? | run= | wallflip.exe | Desktop wallpaper changer? |
| X | run= | svcinit.exe | CoolWebSearch parasite variant |
| X | run= | fntldr.exe | CoolWebSearch Tapicfg parasite variant |
| Y | run= | smsrun16.exe | Microsoft Systems Management Server (SMS) related - program that reads SMSRUN16.INI on clients running Win 3.1, Windows for Workgroups, Win95, or OS/2 to create program groups on the client and then launch SMS client programs |
| ? | run= | win.ini | ?? |
| X | run= | RAVMOND.exe | Added by the LOVGATE-F WORM! |
| X | run= | dec25.exe | Added by the ATAK.F WORM! |
| ? | run= | LXBTppls.exe | Reportedly part of Lexmark printer software - what does it do and is it required? |
| N | run= | fmedia.exe | FMedia FaxWorks related - can be run manually |
| Y | run= | wswpd.exe | Used with some models of Panasonic, Epson and NEC printers - required for printer to work |
| X | run= | cyxid98.exe | Unidentified malware |
| X | run= | info32.exe | CoolWebSearch Tapicfg parasite variant |
| X | run= | mouse_configurator.win | Added by the GAGGLE.E WORM! |
| X | run= | RegistryReminder.exe | Added by the APSTROJAN.OB TROJAN! |
| X | run= | sec5dec.exe | Added by the ATAK.G WORM! |
| X | run= | wmplayer.exe | CoolWebSearch Smartsearch parasite variant |
| X | run= | Autoexec.com | Added by the HOLCAS.A WORM! |
| X | run= | htmlsync.exe | Searchforfree.info browser hijacker |
| X | run= | msoffice.exe | Added by the ADWARELOADER TROJAN! Note - do not confuse with the legitimate Microsoft Office file, which would typically be located in %Program Files%\Microsoft Office\Office |