Arcade File Downloads UsenetGeeks
Email
Confirm email
Articles Spyware Removal File Help Startup DB Tips Service DB News Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
U QuickTV QuickTV.exe"Infra-red remote control driver for the AVerTV Studio TV tuner/personal video recoder from AVerMedia. Required if you use the remote control"
X Quickzip Ls.exeMsConnect browser hijacker and dialler
X QuickZip lu.exeMsConnect browser hijacker and dialler
N QuikShield qkshield.exe"QuikShield popup blocker - reportedly stealth installed
N QuikSync QUIKSYNC.EXEUsed by Iomega drives. Available via Start -> Programs
X qwe qwe.exe"Added by the LINEAGE-F TROJAN!"
? QWERTY qwerty.exePossibly adult content related adware
U QWS3270 Sessions sessions.exeQWS3270 Secure terminal emulation software
X R [path] rundll32.exe msprt.dllChinese originated browser hijacker - redirecting to 4199.com
X RA Server Slave.exe"Added by the RA TROJAN!"
X RabbitWannaHome rabbit.exe"Added by the MIMAIL.S WORM!"
Y Rabo Session Monitor RaboSessionMon.exe"Related to RaboBank electronic banking software"
N RaConfig2500 RaConfig2500.exe"RaLink wireless LAN configuration utility"
N RadarSync RadarSync.exe"Radarsync utility comes from DFI with their latest motherboards
U RadBoot RadBoot.exeRadLinker - tweaker/linker for ATI Radeon based graphics cards. It allows you easy access to per game settings
U Radio365Agent Radio365TrayAgent.exe"Radio365 - create playlists and broadcast live straight from your PC!"
U RadioSvr RadioSvr.EXEUsed to configure wire less networks. Windows automatically detects the Wireless network and it configures the network
U RaidTool raid_tool.exeVIA V-RAID Tool - hard disk striping/mirroring utility for increased performance and reliability
U Rainlendar Rainlendar.exe"Rainlendar is a customizable calendar that displays the current month"
U RAM Idle Professional RAM_XP.exe"RAM Idle - a memory management program which manages the free RAM that is available to Windows
U RAMASST RAMASST.exe"Optionally installed with some DVD drives (LG
X RamBooster2 rb.exe"Added by the AKAK TROJAN!"
U RAMDef ramdef.exe"Ram Def Xtreme - monitors and defragments your system RAM to improve reliability and speed. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
U RAMDrive RDTask.exe"Virtual Hard Drive (Ram Drive) takes a portion of your system memory (RAM) and uses it to simulate a hard disk drive. For more information see FarStone"
U RamIdle ramidle.exe"RAM Idle - ""A smart memory management program that will keep your computer running better
U RAMpage RAMpage.exe"Small Windows utility that displays the amount of available memory in an icon in the System Tray. It can also free memory by double clicking the tray icon
X Randex virus built for IRBMe irbme.exe"Added by the RANDEX.RH WORM!"
X random random.exe"Added by the DLOADER-KM TROJAN!"
X Random Unique ID [worm filename]"Added by the XROVE-A WORM!"
X RandomWin32 mgnwin32.exe"Added by the SDBOT-DV WORM!"
Y rant rant.exe"Added by the RBOT-ZB WORM!"
Y RapApp RAPAPP.EXE"Application protection component of BlackICE PC Protection (was Defender) firewall
X Rapdata ravsecs.exe"Added by the QQPASS-V TROJAN!"
X Rapdatae rabseuser.exe"Added by the QQPASS-S TROJAN!"
U Rapid Restore rrpcsb.exe"XPoint ""Rapid Restore PC"" - a ""Managed Recovery™ solution that enables IT Administrators to protect the corporate image
X RapidBlaster rb32.exe"RapidBlaster parasite. Recommended you use RapidBlaster Killer to uninstall - see here"
X Raptelnet ravspeger.exe"Added by the QQPASS-AA TROJAN!"
X Raptelt ravspegtl.exe"Added by the QQPASS-AB TROJAN!"
Y Raptor Mobile vpnservices.exe"Symantec VPN Client used to connect to corporate networks. If unchecked
X RasCon Remote Access Service Manager rasmngr.exe"Added by the SPYBOT.EM WORM!"
X rasctrs rasctrs.exe"Hijacker
X Rase boln.exe"PurityScan/Clickspring adware"
X RasMan.exe RasMan.exe"Added by the FEUTEL-H TROJAN!"
X rate.exe i11r54n4.exe"Added by the BEAGLE.E WORM and variants!"
X rate.exe ********.exe [* = random char]Unidentified adware
Y RAV8Tray ravtray8.exe"RAV anti-virus related"
X RAVEN_VLZS.EXE RAVEN_VLZS.EXE"DownloadReceiver parasite - no longer in existence"
Y RavMon RavMon.exe"RAV AntiVirus"
X RavTime Mstray.exe"Added by the WUKILL.A WORM!"
X RavTimer RavTimer.exe"RAV AntiVirus"
X RavTimer explores.exe"Added by the HOMEY-A TROJAN!"
X RavTimeXP [worm filename]"Added by the WULLIK.B WORM!"
X RavTimeXP Virus"Added by the CAGER.A WORM!"
X RavTimXP [worm filename]"Added by the WULLIK.B WORM!"
X RavUptets agetlke.exe"Added by the QQPASS-AK TROJAN!"
X RavUptkt agetlktz.exe"Added by the QQPASS-AJ TROJAN!"
X RavUptpe ravsesur.exe"Added by the QQPASS-T TROJAN!"
? rav_temp.exe rav_temp.exe"??"
X RAX SYSTEM scrigz.exe"Added by the MYTOB.KR WORM!"
N Ray Process Killer Prkill.exe"Ray Process Killer - clicking right mouse button produces popup menu with current active tasks. You can choose any task and click "Ok" to terminate it. Use CTRL+ALT+DEL instead"
U razer razerhid.exe"Razer mouse driver"
X rb32 lptt01 rb32.exe"RapidBlaster variant (in a ""RapidBlaster"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X rb32 ml097e rb32.exe"RapidBlaster variant (in a ""RapidBlaster"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X rbenh ml***e rbenh.exe"RapidBlaster variant (in a ""RBEnhance"" folder in Program Files) where *** represents random digits. Recommended you use RapidBlaster Killer to uninstall - see here"
X RBOT v2 with NetAPI exploit traded with billgates I gave my mother Greetz - OG - Bluehell Irc Server glossary.exe"Added by the VANEBOT-J WORM!"
X Rcf Driver rcf.exe"Added by the RANDEX.BLD WORM!"
X rCron rcron.exe"""Switch"" adult content dialler"
X rCron dservice.exeSwitch premium rate adult content dialer
U RCScheduleCheck RCSCHED.EXE"Scheduler for VCOM's Recovery Commander - which ""can restore your non-booting system back to normal. It only takes a few minutes to get your system back up and running"""
X RCSync RCSync.exe"PrizeSurfer related. ""PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!"" Stealth installed malware"
U RCSystem DLLML.exe RCSystem"Related to Creative DLL Module Loader for the Sound Blaster X-Fi (and maybe others). This program is non-essential process to the running of the system
U RDClient RDCLIENT.EXE"Remote Disconnection Utility from Twiga. Used for connecting and disconnecting dial up connections on a network - only needed if there is a shared internet connection"
X RDLL RunDll16.exe"Added by the SDBOT.F TROJAN!"
X rdvs [worm filename]"Added by the ULTIMAX WORM!"
X Reactor3 [random name]32.exe"Added by the BOFRA.A WORM!"
X Reactor5 [random name]32.exe"Added by the BOFRA.D WORM!"
X Reactor6 [random name]32.exe"Added by the BOFRA.C WORM!"
X Reactor7 [random name]32.exe"Added by the BOFRA.B WORM!"
X Reactor8 [random name]32.exe"Added by the BOFRA.E WORM!"
X Reactor9 [random name]32.exe"Added by the BOFRA.E WORM!"
X readdb40 "rundll32.exe [path] readdb40.dll EnableRunDLL32"
N REAL realjbox.exe"Real Jukebox - MP3 and music files player"
X Real Internet Player Reaiplay.exe"Added by a variant of the SPYBOT WORM!"
X Real player updater realupd.exe"Added by the PARLAY TROJAN!"
X real scheduler.hta RealAudio.exe"Added by the CEEGAR TROJAN! Note - this is not associated with the popular RealPlayer media player"
U Real Spy Monitor Winrsm.exe"Realspy keystroke logger/monitoring program - remove unless you installed it yourself!"
X Real Statics Agent ccreal.exe"Added by a variant of the RBOT WORM!"
X Real-Tens Real-Tens.exe"DownloadWare adware"
X RealAudio RealAudio.exe"Added by the CEEGAR TROJAN! Note - this is not associated with the popular RealPlayer media player"
N RealDownload RealPlay.exeDownload manager. Available via Start -> Programs
X RealDownload Express npnzdad.exeAdvertising spyware
N Reality Fusion GameCam SE RFTRay.exe"System Tray access for Logitech's Reality Fusion GameCam. For more details see here. Available via Start -> Programs"
N RealJukeboxSystray tsystray.exeSystem Tray icon for RealJukebox
X realone_nt2003 moniker.exe"Added by the SNONE.A WORM!"
X RealP1ayer [path to file]"Added by the RPLAY.A TROJAN! Note that the name has a number ""1"" in place of the second lower case ""L"""
N realplay realplay.exeSystem Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences
X realplay lptt01 realplay.exe"RapidBlaster variant (in a ""RealPlay"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not RealPlayer which can have the same executable name"
X realplay ml097e realplay.exe"RapidBlaster variant (in a ""RealPlay"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not RealPlayer which can have the same executable name"
X RealPlayer Ath Check rnathchk.exe"Added by the MYTOB.AG WORM!"
X Realplayer Codec Support realsched.exe"Added by the AGOBOT-AAD WORM! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name"
X Realplayer One realplay.exe"Added by the RBOT-NK WORM!"
X Realplayer.exe Realplayer.exe"Added by the DELF.CNV TROJAN!"
N RealPlayer2 MsgCenterExe"RealNetworks RealPlayer related - disabling this application will not affect Real Player in any way"
X RealPlayerUpdater realupd32.exe"Added by the LOHAV-T TROJAN!"
? Realpopup Realpopup.exe"RealPopup - "Replaces old winpopup with a full featured freeware tool which remains stable and simple as its predecessor""
N Realsched realsched.exe"Application Scheduler installed along with RealOne Player. Runs independently of RealOne Player
U RealSPEED RealSPEED.Exe"RealSPEED - tweaking utility to speed-up your internet connection"
U Realtime Audio Engine mmrtkrnl.exe"Associated with ALCATech BPM Studio"
Y Realtime Monitor realmon.exe"Realtime scanner part of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates"
? RealTimeUpdate RealTimeUpdate.exe"Product description in properties is ""InternetExplorerCommunicationAgent Module"" ?"
X realtpsk realsched.exe"Chinese originated adware - detected by Panda antivirus as NewWeb. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name"
N RealTray RealPlay.exeSystem Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences
X RealUpdater realupd.exe"Added by the PARLAY or MITGLIEDER.I TROJANS!"
X RebateNation0 RebateNation0.exe"RebateNation adware"
N Reboot Reboot.exeMS-DOS/Win3.1 utility use to clean boot a system. Sometimes installed by default from some driver CDs for motherboards
Y Recguard recguard.exe"On HP computers
? recguard recguard.exe??
N Reclip reclip.exe"Reclip Popup Clipboard manager"
X Recommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B} RH.DLL"SmartPops search hijacker"
N Recover N/AAdded during the installation of Comcast High Speed Internet software. During installation the system reboots and if the disk is removed a screen appears asking for the disk to be re-inserted to complete installation. Not required once installion is complete
X recover.bmp.exe Rundll.exe"Added by the ANAFTP-01 TROJAN! Note - this is NOT the Windows system file of the same name as described here"
N RecoverFromReboo RECOVE~1.EXE"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
N RecoverFromReboo RecoverFromReboot.exe"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
N RecoverFromReboot RECOVE~1.EXE"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
N RecoverFromReboot RecoverFromReboot.exe"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
N RecShe RecSche.exeRecording scheduler for WatchTV Capture Card (TV Tuner card)
X Recycle Bin Handler recycler.exe"Added by the SHUCKBOT-A TROJAN!"
X Recycle Bin Handler 2005 system.exe"Added by the HO TROJAN!"
X RecycleSTR msreg32.exe"Added by the RBOT-TC WORM!"
N Red Flag redflag.exePMS prediction program with modes for guys and girls - no longer available
U Red Swoosh EDN Client RSEDNClient.exe"Red Swoosh - mechanism used by web sites to allow you to download files from those sites quicker and more efficiently via P2P. Note from the license agreement they automatically update the software
X redirect redirect*.exeDotcomtoolbar/Linksummary hijacker installer - where * is a random digit
N Redline Taskbar taskbar.exeTaskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list