Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
N RecoverFromReboo RecoverFromReboot.exePart of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched this entry may be left in the registry
N RecoverFromReboot RECOVE~1.EXEPart of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched this entry may be left in the registry
N RecoverFromReboot RecoverFromReboot.exePart of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched this entry may be left in the registry
X Recoveru system svchast.exe"Added by a variant of the LINEAGE-AV TROJAN!"
X Recoveru systems svchost.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! ! This file is located in the ""temp"" folder"
N RecShe RecSche.exeRecording scheduler for WatchTV Capture Card (TV Tuner card)
X Recycle Bin Handler recycler.exe"Added by the SHUCKBOT-A TROJAN!"
X Recycle Bin Handler 2005 system.exe"Added by the BDOOR-HO BACKDOOR!"
X Recycler DO NOT MODIFY recyclecl.exe"Added by the RBOT.DDA WORM!"
X RecycleSTR msreg32.exe"Added by the RBOT-TC WORM!"
N Red Flag redflag.exePMS prediction program with modes for guys and girls - no longer available
U Red Swoosh EDN Client RSEDNClient.exe"Red_Swoosh distributed networking software - a desktop client that enables users to download and stream files from each other rather than from webservers"
X redirect redirect*.exeDotcomtoolbar/Linksummary hijacker installer - where * is a random digit
N Redline Taskbar taskbar.exeTaskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards
X REEGRUN [path to file]"Added by the SECDROP.AI TROJAN"
X Reek 32 Server reek32.exe"Added by the RANDEX.AL WORM!"
U Referee referee.exe"MediaComm's monitor for file association changes. Stop rogue programs from screwing your settings either on installation or whenever they run"
U Reflex Vision ReflexVision.exe"Reflex Vision from Increment Software. ""A background application for Windows XP that makes switching windows faster and easier"""
N Refresh Refresh.exe(Iomega) Refresh - loads the Iomega desktop icons at startup
X Reg Reg.hta"Passon homepage hi-jacker"
? Reg Check lpt.exe"Related to Supanet ISP software - what does it do and is it required?"
X reg run Systen.exe"Added by the BANCOS-BS TROJAN!"
X Reg Service winsy.exe"Added by a variant of the SPYBOT WORM!"
X Reg Service winslogon.exe"Added by the AGOBOT-SC WORM!"
X Reg Service ipcfg.exe"Added by the AGOBOT-SO WORM!"
X Reg Service REGSRV32.EXE"Added by the RBOT.ZW WORM!"
X Reg Service WinnConfig.exe"Added by the AGOBOT-PF WORM!"
X Reg Service NT32.exe"Added by the AGOBOT.G TROJAN!"
X Reg Services Winboot32.exe"Added by the RBOT.PB WORM!"
X reg1.reg vuamgard.exe"Added by a variant of the IRCBOT TROJAN!"
U reg2.0 SVCH0ST.EXE"eSpyNow surveillance software. Uninstall this software unless you put it there yourself. Note - the filename has the digit 0 rather then the uppercase ""o"""
X Reg32 Reg32.exeHijacker - redirecting to only-virgins.com
X reg32 reg32.exe"Added by the NOUPDATE.B TROJAN!"
X Reg32 reg33.exe"CoolWebSearch parasite variant - also detected as the STARTPA-M TROJAN!"
X Regcheck ~CAB001.EXE"Added by the CYBRSPY.13A or CYBRSPY.13B TROJANS!"
X regcheck [path to file]"Added by the SERVPAM TROJAN!"
U RegClean Expert Scheduler RCHelper.exe"""Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry your system will run faster and error free"""
U RegClean Expert Scheduler RCScheduler.exe"""Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry your system will run faster and error free"""
X RegCleaner SYSio32.exeAdded by an unidentified VIRUS WORM or TROJAN! Note - do not confuse this with the popular RegCleaner registry cleaner freeware
X RegCompres Regcpm32.exe"Added by the POLDO.B TROJAN!"
X RegCompres REGCPM32.EXE"Added by the DASMIN-E TROJAN!"
X Regcxdinaf REGCXDINAF.EXE"Added by the BANCOS-BW TROJAN!"
X Regcxmarq REGCXMARQ.EXE"Added by the BANCOS.DK TROJAN! Note that the filename has a leading space ie "" REGCXMARQ.EXE"""
X Regcxn Regcxn.exe"Added by the COIBOA-D TROJAN!"
U regdefend regdefend.exe"""RegDefend is a configurable kernel based registry protection system designed to intercept selected changes before they occur thus also preventing malicious software like viruses trojans and worms from using the registry to their advantage"""
X RegDone services.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process which should not appear in Msconfig/Startup!"
X RegDone winlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
X RegDone Ex csrss.exe"Added by the WEBUS TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X RegDoneEx lsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder"
X regedit regedit.exe"Added by the BRID.A WORM! Note - this is not the valid Windows registry editor which resides in Windows or Winnt and will not figure in Msconfig/Startup! This version resides in the System (9x/Me) or System32 (NT/2K/XP) folder"
X REGEDIT Regsrv32.com"Added by the SOUTHGHOST WORM!"
X regedit autoexe.exe"Added by a variant of the RBOT WORM!"
X regedit svchost.exe ccRegVfy"Added by the HOTWORD.B TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
X regedit regedit.exe"Added by the GANBATE.A WORM! Note - this is not the valid Windows registry editor which resides in Windows or Winnt and will not figure in Msconfig/Startup! This version resides in a ""securityDatabase"" subfolder"
X RegEdit32 RegEdit32.exe"Added by the VOUMIT-A WORM! Note - this is not the legitimate regedit32.exe application which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a ""mirc32"" folder"
X Regexit runlli32.exe"Added by the QQPASS-U TROJAN!"
X Regexit Updadv.exe"Added by the QQPASS-N TROJAN!"
U RegFreeze regfreeze.exe"RegFreeze anti-spyware software"
X reggsdg spoolserv.exe"Added by the SDBOT-MS WORM!"
X reggsdg spoolsrv.exe"Added by the SDBOT-DI WORM!"
U RegHelp svchosts.exe"SpyGraphica spy software - ""Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world."""
? reginfo32 reginfo32.exe"??"
X Register Manager RegistryManage.exe"Added by the SDBOT.AYH WORM!"
N Register MediaRing Talk register.exeIf you don't want to register MediaRing and be reminded about it every bootup disable it
? Register SeqChk regsvr32.exe ..csseqchk.dll"??"
U RegisterDropHandler REGIST~1.EXE"Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for ""Send To"" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation"
X Registration Service toker.exe"Added by the SDBOT-BB WORM!"
X Registration Service msvdm6.exe"Added by the SDBOT-HE TROJAN!"
N Registration-Studio 8 RegTool.exe"Registration for Pinnacle Studio Version 8 home video software from Pinnacle Systems"
X Registry wscript.exe ShakiraPics.jpg.vbs"Added by the VBSWG.AQ WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ShakiraPics.jpg.vbs"" file is located in the Winnt or Windows folder"
U Registry class0117[random].exe"Blackbox captures emails and chat logs and monitors Internet activity - remove if you didn't intentionally install it"
X Registry Checker Regrun.exe"Added by the SDBOT TROJAN!"
X Registry Checkup winreg.exeAdded by an unidentified WORM or TROJAN!
X Registry Checkup System326a Monitor Winregs326a.exe"Added by a variant of the SDBOT WORM!"
X Registry Cleaner Regclean.exe"Registry Cleaner misleading security software - not recommended see here"
X Registry Integrity Checker regintmon.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Registry Integritycheck WCPDT.EXE"Added by the AGOBOT-RF WORM!"
X Registry Loader regloadr.exe"Added by the GAOBOT.AO WORM!"
X Registry Loader winhlpp32.exe"Added by the GAOBOT.AO WORM!"
X Registry Monitor regmon.exe"Added by the BCKDR-QKH BACKDOOR!"
X Registry oidet win32.exe"Added by the RBOT.BMT WORM!"
X Registry Protector regprotect.exe"Added by the ARIVER.A WORM!"
X Registry Scanner regscanr.exe"Added by a variant of the OPTIX TROJAN!"
X Registry Serv regsvr.exe"Added by the WEBMONEY-G TROJAN!"
X Registry Server regsrv32.exe"Added by the RBOT-GM WORM!"
X Registry Server regserv.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Registry Service REGSRV32.EXE"Added by a variant of the RBOT WORM!"
X Registry Service resvs.exe"Added by the DELBOT-I WORM!"
X Registry Services Registry.exe"Added by the CILE TROJAN!"
X Registry Startup Check checkreg.exe"Added by the REMLOAD-A or DANMEC-B TROJANS!"
X Registry System Regsys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Registry System16 Checkup Monitor SystemReg16.exe"Added by a variant of the RBOT WORM!"
X Registry System166 Checkup Monitor SystemReg166.exe"Added by a variant of the RBOT WORM!"
X Registry Value Name roses.exe"Added by the RBOT-AFT WORM!"
X Registry Value Name service.exe"Added by the RBOT-AHT WORM!"
X Registry Value Name winapi32.exe"Added by a variant of the RBOT WORM!"
X Registry Value Name syswinxp.exe"Added by the RBOT.BTZWORM!"
X Registry Value Name Start MsPMSPSa.exe"Added by a variant of the SDBOT WORM!"
X RegistryCheck rundll32.exe chkreg.dll CheckRegistry"Ulubione adult content dialer. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
X RegistryChk winbackup.exe"Added by the MERTIAN WORM!"
X RegistryCleanFixMFC registrycleanfix.exe"RegistryCleanFix misleading security program - not recommended see here"
U RegistryMechanic RegMech.exe"Registry Mechanic - ""you can safely clean and repair Windows registry problems with a few simple mouse clicks! Problems with the Windows registry are a common cause of Windows crashes and error messages"""
X RegistryMonitor registry.pif"Affilred adware"
X RegistryMonitor sysfade.exe"Added by the SYSFADE TROJAN!"
X RegistryMonitor1 mljul1.exe"Added by the SPAMBOT TROJAN!"
U REGIST~1 REGIST~1.EXE"Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for ""Send To"" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation"
X Regkey for autostart winservice.exe"Added by the RBOT-NU WORM!"
U RegKillTray RegKillTray.exe"DVD region killer part of CloneDVD from Elaborate Bytes AG. Copies the main movie Special Features and/or the original menu onto a DVD Recordable or onto your harddisk"
X Regmonitor regmaping.exe"Added by the BEAGLE.DO WORM!"
X REGMSYS [path to file]"Added by the LOWZONE-AX TROJAN!"
X RegMutex lexplore_.exe"Added by the MSNOPT-A TROJAN!"
X RegPowerClean RegPowerClean.exe"RegistryPowerCleaner misleading secuirty software - not recommended see here"
Y RegProt Regprot.exe"RegistryProt from Diamond Computer Systems - protects the system registry against changes"
X Regptmens REGPTMENS.EXE"Added by the BANCOS-ED TROJAN!"
X Regro rundll132.exe"Added by the OKARAG TROJAN!"
X RegRun mActiveX.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
X REGRUN winfix22490.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
X REGRUN [path to trojan]"Added by the LOWZONE-AH TROJAN!"
X REGRUN regeditt.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
X REGRUN sory.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
X REGRUN dialer.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
U RegRun WinBait winbait.exe"Part of RegRun - used to detect unknown viruses. RegRun compares winbait.exe with the original copy called winbait.org and warns if the files are different.."
Y Regrun2 WatchDog.exe"Greatis Software's RegRun security suite which amongst other things replaces MSCONFIG. The WatchDog check for registry changes caused by trojan's viruses etc"
X REGRUNM autoprotect.exeAdded by an unidentified WORM or TROJAN!
X Regrx rundll32.exe"Added by the WAYIC-A TROJAN! Note - this is not the legitimate rundll32.exe process which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). The file is located in C:Windows"
X Regscan regscanr.exe"Added by the OPTIX-SE TROJAN!"
X RegScan DLLSRV32.EXE"Added by the AGOBOT.AEW WORM!"
X RegScan Regscan.exe"Added by the TALEX TROJAN!"
? RegServer regserve.exe"Related to XGI Technology's Volari graphics cards - what does it do and is it required?"
X regservices.exe regservices.exeAdded by an unidentified VIRUS WORM or TROJAN!
N RegShave regshave.exePart of the USB driver for your Fuji digital cameras - used when uninstalling the USB drivers erasing all entries from the registry. Only required BEFORE attempting to uninstall the Fuji software or the uninstall may not work correctly
X regsrv regsrv.exe"Added by the OPTIXPRO.11 TROJAN!"
X regsrv scvhost.exe"Added by the AGOBOT.E WORM!"
X RegSrv64D RegSrv64D.exE"Added by the WINKO.AO WORM!"
X regsrvc regsrvc.exe"Added by the STOPED-A TROJAN!"
X Regsv regsv.exeSearch hijacker - redirecting to scheo.com
X Regsvc regsv.exeAdded by an unidentified TROJAN!
X regsvc32 regsvc32.exeHomepage hijacker that changes your homepage to an adult content site
X regsvr regsvr.exe"Added by the WEBMONEY-G TROJAN!"
U REGSVR32 regsvr32.exe ctasio.dll"ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
X RegSvr32 msmsgs.exe"Added by the ZLOB.B TROJAN!"
X regsync regsync.exe"SafeSurfing adware"
? regtmlp N/A"??"
U RegTweak RegTwk.exe"Rage3d Tweak - ATI Radeon tweaker which allows access to registry tweak options custom display modes refresh rates and overclocking all through an easy to use interface"
X RegVer REGVER.EXE"Added by the LATINUS.16 TROJAN!"
X RegVfy32 Regverif32.exe"Added by the SYGYP.A WORM!"
X RegWrite csrss.exe"Added by the SOKACAPS TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Media"
Y Regx10EXE atix10.exe"ATI Remote Wonder? - PC wireless remote control driver. Required if you use it"
X reg_key FUKULAMER.exe"Added by the BEAGLE.AH WORM!"
X reg_key loader_name.exe"Added by the BEAGLE.Y or BEAGLE.Z or BEAGLE.AA WORMS!"
X Reg_WFT Regsysw.com"Added by the WILSEF VIRUS!"
X Reg_WFT scanreg32.com"Added by the SENNASPY-F TROJAN!"
U ReleaseRAM RRAM.exe"""Release RAM allows your computer to run faster and uses your computer's RAM more efficiently"". MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
X relinson cmdno.exe"Added by the DROPPER-PS TROJAN!"
X reload reload.vbs"Added by the LOVELETTER.AS VIRUS!"
X Reload reload.exe"Added by the LAZAR TROJAN!"
N RemHelp Remhelp.exeBT Voyager ADSL Modem Help related
N Reminder reminder.exeFrom MS Money. Reminds you of your bills
N Reminder Remind_XP.exeHP-specific program that reminds users to create System Recovery CDs. Once they use the Recovery CD Creator (Start -> PC Help & Tools -> Recovery CD Creator) to make the recovery CDs the entry will remove itself from the startup list
N Reminder Reminder.exe"Registration reminder for the PC Pitstop Optimize 2.0 system optimizatoon utility by CA. Located in %ProgramFiles%\PCPitstop\Optimize2"
N Reminder-cpqXXXXX remind32.exeCompaq printer Registration
N Reminder-hpcXXXXX remind32.exeHP CD-Writer Registration
N Reminder-ranXXXXX remind32.exeRegistration reminder widget for Rand Mcnally maps
N reminder-ScanSoft Product Registration remind32.exeRegistration reminder for ScanSoft products such as PaperPort
U RemindMe RemindMe.exe"Remind-Me - calendar software"
N Remind_XP Remind_XP.exeHP-specific program that reminds users to create System Recovery CDs. Once they use the Recovery CD Creator (Start -> PC Help & Tools -> Recovery CD Creator) to make the recovery CDs the entry will remove itself from the startup list
X Remndr CsRemnd.exeCasinoOnline foistware
U Remote Remote.exe"Remote Control driver for LifeView internal and external TV products"
U Remote Access rnaapp.exeDial-up networking application - not normally found in the startup locations. It runs when you connect to the net via this method (ie analogue 56K modem) and terminates after the connection is closed
X Remote Access Adapter rvasvc.exe"Detected by PCTools as the IRCBOT.BIF TROJAN! See here"
X Remote Access Domain rswsvc.exe"Added by the IRCBOT.BFA TROJAN!"
X Remote Access Monitor rpgsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Remote Access Service Manager rasmngr.exe"Added by the AGOBOT.KU WORM!"
X Remote Access Slave Synchost.exe"Added by the RIPJAC TROJAN!"
X Remote Access Tool rwosvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
N Remote Control Rc.exeHinet Hi-Five ISP software
N Remote Controller TVRMVCR.EXE"ProLink PlayTVpro TV tuner software"
U Remote Data Backups CBSysTray.exe"System Tray access to Remote Data Backups online system/data backup utility"
U Remote Data Backups COBackup.exe"Remote Data Backups online system/data backup utility"
U Remote Data Backups TaskBar Icon CBSysTray.exe"System Tray access to Remote Data Backups online system/data backup utility"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list