Arcade File Downloads UsenetGeeks
Email
Confirm email
Articles Spyware Removal File Help Startup DB Tips Service DB News Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X REEGRUN [path to file]"Added by the SECDROP.AI TROJAN"
X Reek 32 Server reek32.exe"Added by the RANDEX.AL WORM!"
U Referee referee.exe"MediaComm's monitor for file association changes. Stop rogue programs from screwing your settings either on installation or whenever they run"
N Refresh Refresh.exe(Iomega) Refresh - loads the Iomega desktop icons at startup
X Reg Reg.hta"Homepage hi-jacker. Removal instructions here"
? Reg Check lpt.exe"Related to Supanet ISP software - what does it do and is it required?"
X reg run Systen.exe"Added by the BANCOS-BS TROJAN!"
X Reg Service winsy.exe"Added by a variant of the SPYBOT WORM!"
X Reg Service winslogon.exe"Added by the AGOBOT-SC WORM!"
X Reg Service ipcfg.exe"Added by the AGOBOT-SO WORM!"
X Reg Service REGSRV32.EXE"Added by the RBOT.ZW WORM!"
X Reg Service WinnConfig.exe"Added by the AGOBOT-PF WORM!"
X Reg Service NT32.exe"Added by the AGOBOT.G TROJAN!"
X Reg Services Winboot32.exe"Added by the RBOT.PB WORM!"
X reg1.reg vuamgard.exe"Added by a variant of the IRC.BOT TROJAN!"
U reg2.0 SVCH0ST.EXE"Added by the eSpyNow surveillance software. Uninstall this software unless you put it there yourself. Note - the filename has the digit 0 rather then the uppercase ""o"""
X Reg32 Reg32.exeHijacker - redirecting to only-virgins.com
X reg32 reg32.exe"Added by the NOUPDATE.B TROJAN!"
X Reg32 reg33.exe"CoolWebSearch parasite variant - also detected as the STARTPA-M TROJAN!"
X Regcheck ~CAB001.EXE"Added by the CYBRSPY.13A or CYBRSPY.13B TROJANS!"
X regcheck [path to file]"Added by the SERVPAM TROJAN!"
X RegCleaner SYSio32.exe"Added by an unidentified VIRUS
X RegCompres Regcpm32.exe"Added by the POLDO.B TROJAN!"
X RegCompres REGCPM32.EXE"Added by the DASMIN-E TROJAN!"
X Regcxdinaf REGCXDINAF.EXE"Added by the BANCOS-BW TROJAN!"
X Regcxn Regcxn.exe"Added by the COIBOA-D TROJAN!"
U regdefend regdefend.exe"""RegDefend is a configurable
X RegDone services.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
X RegDone winlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
X RegDone Ex csrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process
X RegDoneEx lsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder"
X regedit regedit.exe"Added by the BRID.A WORM! Note - this is not the valid Windows registry editor which resides in Windows or Winnt and will not figure in Msconfig/Startup! This version resides in the System (9x/Me) or System32 (NT/2K/XP) folder"
X REGEDIT Regsrv32.com"Added by the SOUTHGHOST WORM!"
X regedit autoexe.exe"Added by a variant of the RBOT WORM!"
X regedit svchost.exe ccRegVfy"Added by the HOTWORD.B TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
X RegEdit32 RegEdit32.exe"Added by the VOUMIT-A WORM! Note - this is not the legitimate regedit32.exe application which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a ""mirc32"" folder"
X Regexit runlli32.exe"Added by the QQPASS-U TROJAN!"
X Regexit Updadv.exe"Added by the QQPASS-N TROJAN!"
U RegFreeze regfreeze.exe"RegFreeze anti-spyware software"
X reggsdg spoolserv.exe"Added by the SDBOT-MS WORM!"
U RegHelp svchosts.exe"SpyGraphica spy software - ""Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world."""
? reginfo32 reginfo32.exe"??"
X Register Manager RegistryManage.exe"Added by the SDBOT.AYH WORM!"
N Register MediaRing Talk register.exeIf you don't want to register MediaRing and be reminded about it every bootup disable it
? Register SeqChk regsvr32.exe ..csseqchk.dll"??"
U RegisterDropHandler REGIST~1.EXE"Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for ""Send To"" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation"
X Registration Service toker.exe"Added by the SDBOT-BB WORM!"
N Registration-Studio 8 RegTool.exe"Registration for Pinnacle Studio Version 8 home video software from Pinnacle Systems"
X Registry wscript.exe"Added by the VBSWG.AQ WORM!"
U Registry class0117[random].exe"Blackbox captures emails and chat logs
X Registry Checkup winreg.exeAdded by an unidentified WORM or TROJAN!
X Registry Checkup System326a Monitor Winregs326a.exe"Added by a variant of the SDBOT WORM!"
X Registry Integrity Checker regintmon.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Registry Integritycheck WCPDT.EXE"Added by the AGOBOT-RF WORM!"
X Registry Loader regloadr.exe"Added by the GAOBOT.AO WORM!"
X Registry Loader winhlpp32.exe"Added by the GAOBOT.AO WORM!"
X Registry oidet win32.exe"Added by the RBOT.BMT WORM!"
X Registry Scanner regscanr.exe"Added by a variant of the OPTIX TROJAN!"
X Registry Server regsrv32.exe"Added by the RBOT-GM WORM!"
X Registry Service REGSRV32.EXE"Added by a variant of the RBOT WORM!"
X Registry Services Registry.exe"Added by the CILE TROJAN!"
X Registry Startup Check checkreg.exe"Added by the REMLOAD-A or DANMEC-B TROJANS!"
X Registry System16 Checkup Monitor SystemReg16.exe"Added by a variant of the RBOT WORM!"
X Registry System166 Checkup Monitor SystemReg166.exe"Added by a variant of the RBOT WORM!"
X Registry Value Name roses.exe"Added by the RBOT-AFT WORM!"
X Registry Value Name service.exe"Added by the RBOT-AHT WORM!"
X Registry Value Name winapi32.exe"Added by a variant of the RBOT WORM!"
X Registry Value Name Start MsPMSPSa.exe"Added by a variant of the SDBOT WORM!"
X RegistryCheck "rundll32.exe chkreg.dll CheckRegistry"
X RegistryChk winbackup.exe"Added by the MERTIAN WORM!"
U RegistryMechanic RegMech.exe"Registry Mechanic for Windows - ""you can safely clean and repair Windows registry problems with a few simple mouse clicks! Problems with the Windows registry are a common cause of Windows crashes and error messages"""
X RegistryMonitor registry.pif"Affilred adware"
U REGIST~1 REGIST~1.EXE"Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for ""Send To"" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation"
X Regkey for autostart winservice.exe"Added by the RBOT-NU WORM!"
U RegKillTray RegKillTray.exe"DVD region killer part of CloneDVD from Elaborate Bytes AG. Copies the main movie
X Regmonitor regmaping.exe"Added by the BEAGLE.DO WORM!"
X REGMSYS [path to file]"Added by the LOWZONE-AX TROJAN!"
X RegMutex lexplore_.exe"Added by the MSNOPT-A TROJAN!"
Y RegProt Regprot.exe"RegistryProt from Diamond Computer Systems - protects the system registry against changes"
X Regptmens REGPTMENS.EXE"Added by the BANCOS-ED TROJAN!"
X Regro rundll132.exe"Added by the OKARAG TROJAN!"
X RegRun mActiveX.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
X REGRUN winfix22490.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
X REGRUN [path to trojan]"Added by the LOWZONE-AH TROJAN!"
X REGRUN regeditt.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
X REGRUN sory.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
X REGRUN dialer.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
U RegRun WinBait winbait.exe"Part of RegRun - used to detect unknown viruses. RegRun compares winbait.exe with the original copy called winbait.org and warns if the files are different.."
Y Regrun2 WatchDog.exe"Greatis Software's RegRun 3 Security Suite which amongst other things replaces MSCONFIG. The WatchDog check for registry changes caused by trojan's
X REGRUNM autoprotect.exeAdded by an unidentified WORM or TROJAN!
X Regrx rundll32.exe"Added by the WAYIC-A TROJAN! Note - this is not the legitimate rundll32.exe process
X Regscan regscanr.exe"Added by the OPTIX-SE TROJAN!"
X RegScan DLLSRV32.EXE"Added by the AGOBOT.AEW WORM!"
X RegScan Regscan.exe"Added by the TALEX TROJAN!"
? RegServer regserve.exe"Related to XGI Technology's Volari graphics cards - what does it do and is it required?"
X regservices.exe regservices.exe"Added by an unidentified VIRUS
N RegShave regshave.exe"Part of the USB driver for your Fuji digital cameras - used when uninstalling the USB drivers
X regsrv regsrv.exe"Added by the OPTIXPRO.11 TROJAN!"
X regsrv scvhost.exe"Added by the AGOBOT.E WORM!"
X regsrvc regsrvc.exe"Added by the STOPED-A TROJAN!"
X Regsv regsv.exeSearch hijacker - redirecting to scheo.com
X Regsvc regsv.exeAdded by an unidentified TROJAN!
X regsvc32 regsvc32.exeHomepage hijacker that changes your homepage to an adult content site
X regsvr regsvr.exe"Added by the WEBMONEY-G TROJAN!"
U REGSVR32 regsvr32.exe ctasio.dll"ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
X RegSvr32 msmsgs.exe"Added by the ZLOB.B TROJAN!"
X regsync regsync.exe"SafeSurfing adware"
? regtmlp N/A"??"
U RegTweak RegTwk.exe"Rage3d Tweak - ATI Radeon tweaker which allows access to registry tweak options
X RegVer REGVER.EXE"Added by the LATINUS.16 TROJAN!"
X RegVfy32 Regverif32.exe"Added by the SYGYP.A WORM!"
X RegWrite csrss.exe"Added by the SOKACAPS TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a WindowsMedia folder"
Y Regx10EXE atix10.exe"ATI Remote Wonder™ - PC wireless remote control driver. Required if you use it"
X reg_key FUKULAMER.exe"Added by the BEAGLE.AH WORM!"
X reg_key loader_name.exe"Added by the BEAGLE.Y or BEAGLE.Z or BEAGLE.AA WORMS!"
X Reg_WFT Regsysw.com"Added by the WILSEF VIRUS!"
X Reg_WFT scanreg32.com"Added by the SENNASPY-F TROJAN!"
U ReleaseRAM RRAM.exe"""Release RAM allows your computer to run faster and uses your computer's RAM more efficiently"". MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
X reload reload.vbs"Added by the LOVELETTER.AS VIRUS!"
X Reload reload.exe"Added by the LAZAR TROJAN!"
N RemHelp Remhelp.exeBT Voyager ADSL Modem Help related
N Reminder reminder.exeFrom MS Money. Reminds you of your bills
N Reminder Remind_XP.exeHP-specific program that reminds users to create System Recovery CDs. Once they use the Recovery CD Creator (Start -> PC Help & Tools -> Recovery CD Creator) to make the recovery CDs the entry will remove itself from the startup list
N Reminder-cpqXXXXX remind32.exeCompaq printer Registration
N Reminder-hpcXXXXX remind32.exeHP CD-Writer Registration
N Reminder-ranXXXXX remind32.exeRegistration reminder widget for Rand Mcnally maps
N reminder-ScanSoft Product Registration remind32.exeRegistration reminder for ScanSoft products such as PaperPort
U RemindMe RemindMe.exe"Remind-Me - calendar software"
N Remind_XP Remind_XP.exeHP-specific program that reminds users to create System Recovery CDs. Once they use the Recovery CD Creator (Start -> PC Help & Tools -> Recovery CD Creator) to make the recovery CDs the entry will remove itself from the startup list
X Remndr CsRemnd.exeCasinoOnline foistware
U Remote Remote.exe"Driver for Mercury Ez View TV Tuner Card remote control"
U Remote Access rnaapp.exe"Dial-up networking application - not normally found in the startup locations. It runs when you connect to the net via this method (ie
X Remote Access Slave Synchost.exe"Added by the RIPJAC TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list