| X | RA Server | Slave.exe | Added by the RA TROJAN! |
| X | RabbitWannaHome | rabbit.exe | Added by the MIMAIL.S WORM! |
| Y | Rabo Session Monitor | RaboSessionMon.exe | Related to RaboBank electronic banking software |
| N | RadarSync | RadarSync.exe | Radarsync utility comes from DFI with their latest motherboards, e.g., DFI LanParty Ultra - checks for BIOS and driver updates periodically |
| U | RadBoot | RadBoot.exe | RadLinker - tweaker/linker for ATI Radeon based graphics cards. It allows you easy access to per game settings |
| U | RadioSvr | RadioSvr.EXE | Used to configure wire less networks. Windows automatically detects the Wireless network and it configures the network |
| U | RAMASST | RAMASST.exe | Optionally installed with some DVD drives (LG, Panasonic, etc). Disables Windows XP's CD-burning abilities because they cause some incompatibilities. It does not affect your ability to burn CDs. If you do not have this program running, you may have some compatibility issues with burnt DVDs |
| X | RamBooster2 | rb.exe | Added by the AKAK TROJAN! |
| U | RAMDef | ramdef.exe | Ram Def Xtreme - monitors and defragments your system RAM to improve reliability and speed. Some users swear by programs such as this but I suggest you read this article and make up your own mind |
| U | RamIdle | ramidle.exe | RAM Idle - "A smart memory management program that will keep your computer running better, faster, and longer. RAM Idle works by freeing up physical RAM wasted by Windows and other applications. In addition, RAM Idle also includes Cache and startup manager program that will give you more power to optimize your Windows." Some users swear by programs such as this but I suggest you read this article and make up your own mind |
| U | RAMpage | RAMpage.exe | Small Windows utility that displays the amount of available memory in an icon in the System Tray. It can also free memory by double clicking the tray icon, or by setting a threshold that activates the program automatically, or by having it run automatically when an application exits. RAMpage is free, and open source |
| X | Randex virus built for IRBMe | irbme.exe | Added by the RANDEX.RH WORM! |
| X | RandomWin32 | mgnwin32.exe | Added by the SDBOT-DV WORM! |
| Y | RapApp | RAPAPP.EXE | Application protection component of BlackICE PC Protection (was Defender) firewall, informing you of any modifications to programs, files or folders and detecting unknown programs trying to launch |
| U | Rapid Restore | rrpcsb.exe | XPoint "Rapid Restore PC" - a "Managed Recovery™ solution that enables IT Administrators to protect the corporate image, while offloading personal data backup and recovery chores to the end user" |
| X | RapidBlaster | rb32.exe | Homepage hijacker (adult content) - see this newsgroup thread |
| Y | Raptor Mobile | vpnservices.exe | Symantec VPN Client used to connect to corporate networks. If unchecked, must be uninstalled using Add/Remove Programs as it tightly integrates into networking |
| X | RasCon Remote Access Service Manager | rasmngr.exe | Added by the SPYBOT.EM WORM! |
| X | Rase | boln.exe | PurityScan/Clickspring adware |
| X | rate.exe | i11r54n4.exe | Added by the BEAGLE.E or BEAGLE.F or BEAGLE.G or BEAGLE.H or BEAGLE.I WORMS! |
| X | rate.exe | ********.exe [* = random char] | Unidentified adware |
| Y | RAV8Tray | ravtray8.exe | RAV anti-virus related |
| X | RAVEN_VLZS.EXE | RAVEN_VLZS.EXE | Another eAcceleration program - spyware. Read their privacy statement here |
| Y | RavMon | RavMon.exe | RAV AntiVirus |
| X | RavTime | Mstray.exe | Added by the WUKILL.A WORM! |
| X | RavTimer | RavTimer.exe | RAV AntiVirus |
| X | RavTimeXP | [worm filename] | Added by the WULLIK.B WORM! |
| X | RavTimXP | [worm filename] | Added by the WULLIK.B WORM! |
| ? | rav_temp.exe | rav_temp.exe | ?? |
| N | Ray Process Killer | Prkill.exe | Ray Process Killer - clicking right mouse button produces popup menu with current active tasks. You can choose any task and click "Ok" to terminate it. Use CTRL+ALT+DEL instead |
| X | rb32 lptt01 | rb32.exe | Variant of the RapidBlaster parasite (in a "RapidBlaster" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | rb32 ml097e | rb32.exe | Variant of the RapidBlaster parasite (in a "RapidBlaster" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | rbenh ml***e | rbenh.exe | Variant of the RapidBlaster parasite (in a "RBEnhance" folder in Program Files) where *** represents random digits. It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | Rcf Driver | rcf.exe | Added by the RANDEX.BLD WORM! |
| X | rCron | rcron.exe | "Switch" adult content dialler |
| X | rCron | dservice.exe | Switch premium rate adult content dialer |
| U | RCScheduleCheck | RCSCHED.EXE | Scheduler for VCOM's Recovery Commander - which "can restore your non-booting system back to normal. It only takes a few minutes to get your system back up and running" |
| X | RCSync | RCSync.exe | PrizeSurfer related. "PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!" Stealth installed malware |
| U | RDClient | RDCLIENT.EXE | Remote Disconnection Utility from Twiga. Used for connecting and disconnecting dial up connections on a network - only needed if there is a shared internet connection |
| X | RDLL | RunDll16.exe | Added by the SDBOT.F TROJAN! |
| X | rdvs | [worm filename] | Added by the ULTIMAX WORM! |
| X | Reactor3 | [random name]32.exe | Added by the BOFRA.A WORM! |
| X | Reactor5 | [random name]32.exe | Added by the BOFRA.D WORM! |
| X | Reactor6 | [random name]32.exe | Added by the BOFRA.C WORM! |
| X | Reactor7 | [random name]32.exe | Added by the BOFRA.B WORM! |
| X | Reactor8 | [random name]32.exe | Added by the BOFRA.E WORM! |
| X | Reactor9 | [random name]32.exe | Added by the BOFRA.E WORM! |
| X | readdb40 | rundll32.exe [path] readdb40.dll, EnableRunDLL32 | LZIO.com adware downloader |
| X | Real Internet Player | Reaiplay.exe | Added by a variant of the SPYBOT WORM! |
| X | Real player updater | realupd.exe | Added by the PARLAY TROJAN! |
| X | real scheduler.hta | RealAudio.exe | Added by the CEEGAR TROJAN! |
| X | Real-Tens | Real-Tens.exe | DownloadWare based advetising spyware |
| X | RealAudio | RealAudio.exe | Added by the CEEGAR TROJAN! Note - this is not associated with the popular RealPlayer media player |
| N | RealDownload | RealPlay.exe | Download manager. Available via Start -> Programs |
| X | RealDownload Express | npnzdad.exe | Advertising spyware |
| N | Reality Fusion GameCam SE | RFTRay.exe | System Tray access for Logitech's Reality Fusion GameCam. For more details see here. Available via Start -> Programs |
| N | RealJukeboxSystray | tsystray.exe | System Tray icon for RealJukebox |
| X | realone_nt2003 | moniker.exe | Added by the SNONE.A WORM! |
| X | RealP1ayer | [path to file] | Added by the RPLAY.A TROJAN! Note that the name has a number "1" in place of the second lower case "L" |
| N | realplay | realplay.exe | System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences |
| X | realplay lptt01 | realplay.exe | Variant of the RapidBlaster parasite (in a "RealPlay" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not RealPlayer which can have the same executable name |
| X | realplay ml097e | realplay.exe | Variant of the RapidBlaster parasite (in a "RealPlay" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not RealPlayer which can have the same executable name |
| X | Realplayer One | realplay.exe | Added by the RBOT-NK WORM! |
| ? | Realpopup | Realpopup.exe | RealPopup - "Replaces old winpopup with a full featured freeware tool which remains stable and simple as its predecessor" |
| N | Realsched | realsched.exe | Application Scheduler installed along with RealOne Player. Runs independently of RealOne Player, to remind AutoUpdate and Message Center to perform their tasks at pre-scheduled intervals. If it can't be disabled try deleting or renaming realsched.exe and then delete the entry in the registry |
| ? | Realtime Audio Engine | mmrtkrnl.exe | ?? |
| Y | Realtime Monitor | realmon.exe | Realtime scanner part of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates |
| ? | RealTimeUpdate | RealTimeUpdate.exe | Product description in properties is "InternetExplorerCommunicationAgent Module" ? |
| N | RealTray | RealPlay.exe | System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences |
| X | RealUpdater | realupd.exe | Added by the PARLAY or MITGLIEDER.I TROJANS! |
| N | Reboot | Reboot.exe | MS-DOS/Win3.1 utility use to clean boot a system. Sometimes installed by default from some driver CDs for motherboards |
| Y | Recguard | recguard.exe | On HP computers, Recguard prevents the deletion or corruption of the WinXP Recovery Partition. Without it enabled, it is possible to knock that completely out and force the customer to send the PC back to HP for a re-image, possibly at the customer's expense |
| N | Reclip | reclip.exe | Reclip Popup Clipboard manager |
| X | Recommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B} | RH.DLL | SmartPops adware |
| N | Recover | N/A | Added during the installation of Comcast High Speed Internet software. During installation the system reboots and if the disk is removed a screen appears asking for the disk to be re-inserted to complete installation. Not required once installion is complete |
| ? | RecoverFromReboo | RECOVE~1.EXE | ?? |
| ? | RecoverFromReboo | RecoverFromReboot.exe | ?? |
| ? | RecoverFromReboot | RECOVE~1.EXE | ?? |
| ? | RecoverFromReboot | RecoverFromReboot.exe | ?? |
| N | RecShe | RecSche.exe | Recording scheduler for WatchTV Capture Card (TV Tuner card) |
| X | RecycleSTR | msreg32.exe | Added by the RBOT-TC WORM! |
| N | Red Flag | redflag.exe | PMS prediction program with modes for guys and girls - no longer available |
| X | Red Swoosh EDN Client | RSEDNClient.exe | Red Swoosh - mechanism used by web sites to allow you to download files from those sites quicker and more efficiently. Note from the license agreement they automatically update the software and share non-personally identifiable information with others in the network |
| X | redirect | redirect*.exe | Dotcomtoolbar/Linksummary hijacker installer - where * is a random digit |
| N | Redline Taskbar | taskbar.exe | Taskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards |
| X | REEGRUN | [path to file] | Added by the SECDROP.AI TROJAN |
| U | Referee | referee.exe | MediaComm's monitor for file association changes. Stop rogue programs from screwing your settings either on installation or whenever they run |
| N | Refresh | Refresh.exe | (Iomega) Refresh - loads the Iomega desktop icons at startup |
| X | Reg | Reg.hta | Homepage hi-jacker. Removal instructions here |
| ? | Reg Check | lpt.exe | Related to Supanet ISP software - what does it do and is it required? |
| X | Reg Service | winsy.exe | Added by a variant of the SPYBOT WORM! |
| X | Reg Services | Winboot32.exe | Added by the RBOT.PB WORM! |
| X | reg1.reg | vuamgard.exe | Added by a variant of the IRC.BOT TROJAN! |
| X | Reg32 | Reg32.exe | Hijacker - redirecting to only-virgins.com |
| X | reg32 | reg32.exe | Added by the NOUPDATE.B TROJAN! |
| X | Reg32 | reg33.exe | CoolWebSearch parasite variant |