Computer Tutorials Computer Help and Spyware Removal File DatabaseUninstall Database Windows Startup Programs Database Computer Resources Computer Glossary Forums Computer Help and Spyware Removal
 

  Have a problem and would like to ask us for help? To learn how to ask your question Click Here!
  Do you have popups or other malware infecting your computer? If so, Start Here!
  Are you having trouble using this site? Then you should visit the New User Orientation Center!




A    B    C    D    E    F    G    H    I    J    K    L    M    N    O    P    Q    R    S    T    U    V    W    X    Y    Z    Other   
HJT: F0, F1, F2, F3 · O4 · O20 · O21 · O22 · O23
Rootkit List · Submit a Startup · Top Submitters
 Startup Index · Newest Entries · Mozilla Search Tools · WebMaster Site Tools · Status Key
Startup Database Forum · Computer Help Forums · How to use the Startup Database

Enter the filename or keyword you would like to search for:
Advanced Search

Name Filename Status Description
123456 123456.cpl
X
Added by the KITRO.C (or DANDI.A) WORM! 123456 can be any random 3 to 6 digit number. Please not that C:\Windows\System32\shell32.dll is a legitimate ... Read More
AUNPS2 AUNPS2.DLL
X
AlwaysUpdatedNews.com parasite related
bxxs5 bxxs5.dll
X
BookedSpace parasite
cmpciaudio CMICNFG3.CPL
U
Registers the Control Panel applet for a C-Media PCI sound card
AsioReg ctasio.dll
U
ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this ... Read More
REGSVR32 ctasio.dll
U
ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this ... Read More
SoundFusion cwcprops.cpl
?
Control panel item for the Terratec DMX Xfire 1024 soundcard (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Also fo ... Read More
a70f6a1d-0195-42a2-934c-d8ac0f7c08eb E6F1873B.DLL
X
BrowserAid/Startium parasite related
gsifinal gspndll.dll
?
USB DSL modem related - [what does it do and is it required in startup?
ICSDCLT Icsdclt.dll
U
Internet Connection Sharing allows more than one computer to simultaneously access the internet with a single connection. Also required when networkin ... Read More
desktopupdate MSA64CHK.dll
X
MatrixDialer related ... Read More
takemp3 MSA64CHK.dll
X
MatrixDialer related ... Read More
Rundll32_7 MSIEFR40.DLL
X
BrowserAid "Featured Results" hijacker variant
NvCplDaemon NvCpl.dll
U
Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card ... Read More
NvMediaCenter NvMCTray.dll
U
System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - ... Read More
NvCplDaemon NvQtwk.dll
N
System Tray icon used to change display settings, change the clock rate and memory speed for nVidia based graphics cards. This is unnecessary since yo ... Read More
P17Helper P17.dll
?
ASIO driver for the Sound Blaster Audigy & Audigy 2 series sound card - is it required in startup? ... Read More
ptiupbmd ptipbm.dll
?
Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. If used is it required? ... Read More
windows service r.exe
X
Added by a variant of the TROJ_SMALL.VZ TROJAN ... Read More
valuename r.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
update r00t.exe
X
Added by the W32/Rbot-ACO worm. When started, this infection connects to an IRC where it waits for remote commands to execute. ... Read More
HOT FIX R0chis.exe
X
Identified by Kaspersky antivirus as a variant of the Backdoor.Win32.SdBot.cic malware. ... Read More
msftp service config r3grun.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Fellowes Proxy R3proxy.exe
U
Installed with Fellowes EasyPoint mouse software. Not necessary for normal functioning of Fellowes mice but it is necessary to use the extended featur ... Read More
[random name] r?gedit.exe
X
PurityScan/Clickspring adware ... Read More
[random name] r?gsvr32.exe
X
PurityScan/Clickspring adware
[random name] r?ndll.exe
X
PurityScan/Clickspring adware ... Read More
[random name] r?ndll32.exe
X
PurityScan adware variant.
f~a ra32.exe
X
Password stealer trojan
webexremoteaccessagent raagtapp.exe
U
Related to Web_Meetings from WebEx Communications, Inc. Share and present online with anyone, anywhere. ... Read More
RabbitWannaHome rabbit.exe
X
Added by the MIMAIL.S WORM!
Rabo Session Monitor RaboSessionMon.exe
Y
Related to RaboBank electronic banking software
Rapdatae rabseuser.exe
X
Added by the Troj/QQPass-S/a> Trojan.
raconfig2500 RaConfig2500.exe
N
Related to RaLink_Config_Utility It is used to configure the RaLink Wireless LAN cards. This is a non-essential program. *Disabling or enabling it is ... Read More
RadarSync RadarSync.exe
N
Radarsync utility comes from DFI with their latest motherboards, e.g., DFI LanParty Ultra - checks for BIOS and driver updates periodically ... Read More
RadBoot RadBoot.exe
U
RadLinker - tweaker/linker for ATI Radeon based graphics cards. It allows you easy access to per game settings ... Read More
RadClock RadClock.exe
Y
Manages Radeon clock rate at system boot. Found in %windir%system32RadClock.exe
Windows DLL Loader radeonfx.exe
X
Added by the W32/Poebot-E trojan. When started this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Free Radio radio.exe
X
Added by the Downloader.Centim Trojan.
radio365agent Radio365TrayAgent.exe
U
Related to Radio365 Create playlists and broadcast LIVE straight from your PC! ... Read More
RadioSvr RadioSvr.EXE
U
Used to configure wire less networks. Windows automatically detects the Wireless network and it configures the network ... Read More
Microsoft radnom.exe
X
Added by the W32/Rbot-GHO worm and IRC backdoor.
rdshost rafba.dll
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
OrigRage128Tweaker RAGE128TWEAK.EXE
U
Third party tweaker for ATI Rage 128 Video cards from http://www.rageunderground.com ... Read More
logmein gui ragui.exe
U
RemotelyAnywhere is a remote administration and remote control solution for Windows. It allows access to the host computer via the network (the LAN, a ... Read More
highpoint ata raid management software raidman.exe
Y
Related to RAID_management_software Products from HighPoint Technologies. Note: located in C:\Program Files\HighPoint Technologies, Inc\HighPoint ATA ... Read More
raidtool raid_tool.exe
U
Related to VIA_RAID_Tool from VIA Technologies. This is the VIA Raid configuration ... Read More
rainit RAinit.dll
Y
Associated with Remotely Anywhere.
rainlendar Rainlendar.exe
U
Rainlendar is a customizable calendar that displays the current month. ... Read More
Bron-Spizaetus RakyatKelaparan.exe
X
Added by the W32/Brontok-I worm.
Msn Service raloded.exe
X
Added by the W32/Mytob-DY worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
LogMeIn Maintenance Service RaMaint.exe
U
RemotelyAnywhere is a remote administration and remote control applications for Windows. ... Read More
RAMASST RAMASST.exe
U
Optionally installed with some DVD drives (LG, Panasonic, etc). Disables Windows XP's CD-burning abilities because they cause some incompatibilities. ... Read More
RAMBooster.Net RAMBooster.exe
U
The Ram Booster .NET memory optimizer.
RAMDef ramdef.exe
U
Ram Def Xtreme - monitors and defragments your system RAM to improve reliability and speed. Some users swear by programs such as this but I suggest yo ... Read More
RamIdle ramidle.exe
U
RAM Idle - "A smart memory management program that will keep your computer running better, faster, and longer. RAM Idle works by  freeing up physical ... Read More
RAMpage RAMpage.exe
U
Small Windows utility that displays the amount of available memory in an icon in the System Tray. It can also free memory by double clicking the tray ... Read More
RamPrx RamPrx.dll
X
Identified by Kaspersky as a variant of the Trojan.Win32.Agent.evy Trojan.
RamRunOnce RamRunOnce.dll
X
Identified by Kaspersky as a variant of the Trojan.Win32.Agent.evy Trojan.
run= ramsys.exe
U
Advanced Startup Manager from Rays Lab
FPU mainboard extention ramvxt.sys
X
Variant of the Troj/Haxdor-Fam rootkit.
ram idle professional RAM_XP.exe
U
RAM_Idle - a memory management program which manages the free RAM that is available to Windows, thus preventing your computer from running progressive ... Read More
RandomWin32 rand32.exe
X
Added by the Troj/SdBot-HG worm. When started, this infection connects to an IRC server where it waits for remote commands to execute. ... Read More
windows update checker random file names
X
adware downloader trojan
random random.exe
X
Added by Troj/Dloader-KL.
rant rant.exe
X
Added by the W32/Rbot-ZB WORM/IRC backdoor Trojan!
RapApp RAPAPP.EXE
Y
Application protection component of BlackICE PC Protection (was Defender) firewall, informing you of any modifications to programs, files or folders a ... Read More
RaptorDefence RaptorDefence.exe
X
Added by the RaptorDefence rogue anti-spyware program.
NtmsSvc rar2.com
X
Added by the Troj/GrayBrd-CB backdoor Trojan.
{6598FF45-DA60-F48A-BC43-10AC47853D56} rarjfpi.dll
X
Added by the PWS-OnlineGames.q password-stealing Trojan for online games.
macromedia critical updater rarww.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
NET-SERVICES rascal32.exe
X
Added by the W32/Otakbokep-A worm.
<not used> rascal32.exe
X
Added by the W32/Otakbokep-A worm.
rasctrs rasctrs.exe
X
Hijacker, also detected as the ADWAHECK TROJAN! ... Read More
rasdfgl32 rasdfgl32.exe
X
Added by the W32/Tilebot-CH worm and IRC backdoor.
RasMan.exe RasMan.exe
X
Added by the Troj/Feutel-H keylogging backdoor trojan.
rasman rasman32.exe
X
Added by the Troj/Bckdr-QGN backdoor Trojan.
Microsoft DirectX rasmngr.exe
X
Added by a variant of the RBOT WORM!
RasCon Remote Access Service Manager rasmngr.exe
X
Added by the SPYBOT.EM WORM!
<not used> rasmnlht.dll
X
Added by the W32.Stration.D@mm mass-mailing worm. W32.Stration.D@mm is a mass-mailing worm that gathers email addresses from the compromised computer. ... Read More
rasmvc.exe
X
Unknown malware.
RemoteAgent RAUAgent.exe
Y
Trend Micro's Office Scan Client, see here - "Its Web-based management console gives administrators transparent access to desktop and mobile clients t ... Read More
UpDate RAuth.exe
X
Added by the Troj/Dloader-UL Trojan downloader.
Microsoft Autorun9 Ravasktao.exe
X
Added by the W32.Ogleon.A worm. W32.Ogleon.A is a worm that spreads through removable storage devices. It also drops a copy of Infostealer.Gampass, on ... Read More
RAVEN_VLZS.EXE RAVEN_VLZS.EXE
X
Another eAcceleration program - spyware. Read their privacy statement here
RavMon RavMon.exe
Y
RAV AntiVirus
RavMont RavMon.exe
X
Added by the W32/VB-CYK worm.
<not used> RAVMOND.exe
X
Added by a variant of the LOVGATE WORM!
RavAV RavMonE.exe
X
Added by the Troj/Bdoor-DIJ backdoor Trojan.
WinsRavon Ravon.exe
X
Added by the Troj/QQPass-ALV keylogger Trojan.
ravqjmon ravqjmon.exe
X
Added by the Trojan-Downloader.Win32.Agent.dey Trojan.
Rapdata ravsecs.exe
X
Added by the Troj/QQPass-V Trojan.
RavUptpe ravsesur.exe
X
Added by the Troj/QQPass-T Trojan.
Rapdatei ravseteyi.exe
X
Added by the Troj/QQPass-AO Trojan.
Rapdatybs ravseteyns.exe
X
Added by the Troj/PWS-ACP password-stealing Trojan.
Update.exe ravseuper.exe
X
Added by the Troj/QQPass-P password-stealing Trojan. This also installs a file named winpose.dll in the Windows %System% directory that can be delete ... Read More
Raptelnet ravspeger.exe
X
Added by the Troj/QQPass-AA Trojan.
Raptelt ravspegtl.exe
X
Added by the Troj/QQPass-AB Trojan.
Rapdeyer ravspepts.exe
X
Added by the Troj/LegMir-DZ information stealing Trojan for the online game Legend of Mir. ... Read More
RavTimer RavTimer.exe
X
RAV AntiVirus
RAV8Tray ravtray8.exe
Y
RAV anti-virus related
ravztmon ravztmon.exe
X
Added by the rojan-PSW.Win32.OnLineGames.cei information-stealing Trojan.
rav_temp.exe rav_temp.exe
?
??
Shell ray.exe
X
Homepage hijacker re-directing browsers to adult content websites
SfKg6w rayiou.exe
X
Identified as the Trojan-Downloader.Win32.Agent.buo Trojan. This file can also be found in the %StartupFolder%. ... Read More
CaptionMgr32 raz32.exe
X
Added by the W32/VBSun-A WORM!
razer razerhid.exe
U
Related to Razer diamondback mouse driver its offers task bar changes for buttons / movements. ... Read More
Tarantula razerhid.exe
U
Related to Razer Tarantula mouse driver its offers task bar changes for buttons / movements. ... Read More
Copperhead razerhid.exe
U
Related to Razer CopperHead mouse driver its offers task bar changes for buttons / movements. ... Read More
DeathAdder razerhid.exe
U
Related to Razer DeathAdder mouse driver its offers task bar changes for buttons / movements. ... Read More
razertra razertra.exe
Y
razer diamondback mouse driver ... Read More
RazeSpyware RazeSpyware.exe
X
Added by the RazeSpyware rogue anti-spyware application. RazeSpyware is a program claiming to remove spyware, even from those computers which are clea ... Read More
RazeSpyware Monitor RazeSpyware_monitor.exe
X
Added by the RazeSpyware rogue anti-spyware application. RazeSpyware is a program claiming to remove spyware, even from those computers which are clea ... Read More
razor.exe razor.exe
X
Added by the W32/SillyFDC-AY worm.
RamBooster2 rb.exe
X
Added by the AKAK TROJAN!
RapidBlaster rb32.exe
X
Homepage hijacker (adult content) - see this newsgroup thread
rb32 lptt01 rb32.exe
X
Variant of the RapidBlaster parasite (in a "RapidBlaster" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use ... Read More
rb32 ml097e rb32.exe
X
Variant of the RapidBlaster parasite (in a "RapidBlaster" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use ... Read More
rbenh ml***e rbenh.exe
X
Variant of the RapidBlaster parasite (in a "RBEnhance" folder in Program Files) where *** represents random digits. It is not recommended you manuall ... Read More
rBot.exe rBot.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
: rbot.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Update Machine rBot.exe
X
Added by the Troj/Drop-AF Trojan.
sl4 rules rbot32.exe
X
Added by the W32/SDBOT-QC WORM! ... Read More
WinUpdate RBSKQQBO.EXE
X
Added by the VBSWG2B.A WORM!
MicrosoftUpdate RBuilder.exe
X
Added by the Troj/Dloadr-BMV Trojan.
Remote Control Rc.exe
N
Hinet Hi-Five ISP software
RC.exe RC.exe
U
Remote control software for the AVerTV DVB-T PC HDTV tuner.
ElsaCapiCtl Rcapi.exe
Y
Assumed to stand for Remote Common Application Programming Interface (RCAPI), this was installed with an Elsa Microlink ISDN modem. If it is not there ... Read More
<not used> rcbwmpd.dll
X
Added by the WORM_STRATIO.MY mass-mailing worm.
Soot rcea.exe
?
??
Ring Central Fax rcenterrll.exe
U
Only needed if you want a PC to answer faxes automatically
Rcf Driver rcf.exe
X
Added by the RANDEX.BLD WORM!
RegClean Expert Scheduler RCHelper.exe
U
Required to run scheduled Registry cleanings.
.norton rchost.exe
X
Added by a variant of the BOXED-A TROJAN!
rcimlby.exe rcimlby.exe
X
Added by the W32/Sdbot-DHK worm and IRC backdoor.
LTCISI rckit.exe
X
Added by the W32/IRCBot-YJ worm and IRC backdoor.
Inters Configuration Loader RCL0ADERS.exe
X
Added by the W32/Sdbot-KX worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
RemoteCenter RcMan.exe
U
Remote control for Creative MediaSource - plays back music in DVD-Audio, MP3, WMA, WAV and other media formats ... Read More
{b23dc537-3e13-44c7-bf67-d8405eb377f7} rcohty.dll
X
Part of the Zlob trojan that displays fake security alerts for the rogue anti-spyware program called SpywareLocked. ... Read More
rCron rcron.exe
X
"Switch" adult content dialler
RCScheduleCheck RCSCHED.EXE
U
Scheduler for VCOM's Recovery Commander - which "can restore your non-booting system back to normal. It only takes a few minutes to get your system ba ... Read More
RCSync RCSync.exe
X
PrizeSurfer related. "PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping onli ... Read More
buzme RCUI.exe
U
Display Client for the BuzMe Internet Call Waiting Service. ... Read More
RDClient RDCLIENT.EXE
U
Remote Disconnection Utility from Twiga. Used for connecting and disconnecting dial up connections on a network - only needed if there is a shared int ... Read More
rdshost rdfhost.dll
X
Added by the W32/IrcWorm-A worm and IRC backdoor.
{3D38667C-CF08-4060-BAD3-30797B8FE363} rdihost.dll
X
Added by the W32/IRCBot-VR worm and IRC backdoor.
RDP Host Device Driver rdpdrv.sys
X
Added by the Backdoor.Sanjicom backdoor Trojan.
rdriv rdriv.sys
X
A rootkit bundled with various infections in order to hide them.
rdrVR2 rdrVR2.dll
X
Added by the Troj/Haxdoor-AJ backdoor Trojan.
rdshost rdshost.dll
X
Identified as the Backdoor.Win32.IRCBot.aaq worm and IRC backdoor.
RAMDrive RDTask.exe
U
Virtual Hard Drive (Ram Drive) takes a portion of your system memory (RAM) and uses it to simulate a hard disk drive. For more information see FarSton ... Read More
Microsoft Software10 re101.exe
X
Added by the Troj/Bckdr-QNV backdoor Trojan.
RealP1ayer rea1p1ayer.exe
X
Added by the Trojan.Rplay.A Trojan! Files are located in the C: drive or in the folder where the trojan was run. ... Read More
RealP Rea1P1ayer.exe
X
Added by the Trojan.Rplay.A Trojan! Files are located in the C: drive or in the folder where the trojan was run. ... Read More
WinReader read.exe
X
Added by the W32/Delbot-V worm and IRC backdoor.
Microsoftz turn Control read.pif
X
Added by the W32/Rbot-AFS worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
User32 Read101.exe
X
Added by Backdoor.Cyn. This infection listens on ports 15432 and 51234 awaiting remote commands. ... Read More
readericon readericon45G.exe
N
Tray icon to set various configuration settings for Sunkist media card readers.
Mobipocket Reader Notifications readernotify.exe
N
Added by the MobiPocket Blackberry Bookreader software.
Adobe Reader Speed Launch reader_sl.exe
N
Speeds up the time it takes to load the Adobe Reader application. Your choice, but not required for Adobe Reader to function properly ... Read More
adobe reader speed lauch READER~1.EXE
N
Speeds up the lauch of Adobe (Acrobat) Reader 7
gouday.exe readme.exe
X
Added by the BEAGLE.C WORM!
eomsistem readme.exe
X
Added by the W32.Racita.A worm. W32.Racita.A is a worm that copies itself to mapped drives D through H. It also attempts to lower security settings on ... Read More
readme Driver readme.VBS
X
Added by the W32/VB-CTH worm.
Vista ReadyService readysrv.exe
X
Added by the W32/Sdbot-CTZ worm and IRC backdoor.
Real Internet Player Reaiplay.exe
X
Added by a variant of the SPYBOT WORM!
atidriver reaIplayer.exe
X
Added by the W32/WarPigs-E worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
real scheduler real scheduler.hta
X
Added by the CEEGAR TROJAN! ... Read More
Real-Tens Real-Tens.exe
X
DownloadWare based advetising spyware
run= real.exe
X
Added by a variant of the LOVGATE WORM!
Service real.exe
X
Added by the W32/Rbot-CUG worm and IRC backdoor.
RealUpdate real.exe
X
Added by the Troj/DwnLdr-FUU downloader Trojan.
<not used> real.exe
X
Added by the W32.Snaban worm. W32.Snaban is a worm that spreads by copying itself to removable drives and network drives on the compromised computer. ... Read More
RealAudio RealAudio.exe
X
Added by the CEEGAR TROJAN! Note - this is not associated with the popular RealPlayer media player ... Read More
real scheduler.hta RealAudio.exe
X
Added by the CEEGAR TROJAN!
Realaudio Player realaudio32.exe
X
Added by the Worm.AGOBOT-VA.Process network worm and IRC backdoor.
RealAV RealAV.exe
X
Added by the RealAV rogue anti-spyware program.
Java inetice realetin.exe
X
Added by the Troj/Bckdr-PQM Trojan.
real realjbox.exe
N
Related to Real_Jukebox which allows you to play your MP3 and music files. This is a non-essential process. Disabling or enabling this is down to use ... Read More
Realtime Monitor realmon.exe
Y
Realtime scanner part of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates ... Read More
[not used]