Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
? rndll2 rndll2.exe"May be related to the DivX program as a *.dat file in the same directory had ""DivXPro505Bundle.exe"" mentioned within?"
X rngmf [path to trojan]"Added by the RANKY.C TROJAN!"
X Rnudll32 tadxtr.exe"Added by the QQPASS-O TROJAN!"
X rnwabmig rnwabmig.exe"Added by the AGENT-LMI TROJAN!"
? rnxqh rnxqh.exe"??"
X Roam04 ActiveX.exe"Added by the ROAMER-A TROJAN!"
N RoboForm RoboTaskBarIcon.exe"Roboform - password manager and web form filler. Will work without this startup entry
N RoboFormWatcher RoboFormWatcher.exe"Roboform from Siber Systems. Automatically completes web forms. Available via Start -> Programs"
U Rocket.Time RocketTime.exe"Rocket.Time - time synchronization software from Rocket Software"
N RocketDock RocketDock.exe"""RocketDock is a smoothly animated
X Roflcopteur seman.exeAdded by an unidentified WORM or TROJAN!
Y RogueMonitor RogueRemoverPRO.exe"Part of Malwarebytes' RogueRemover PRO - the realtime ""RogueMonitor will alert you before you download a rogue application keeping you safe and secure before trouble occurs."" Now discontinued and the funtionality is included in Malwarebytes' Anti-Malware"
Y RogueRemoverPRO RogueRemoverPRO.exe"Part of Malwarebytes' RogueRemover PRO - the realtime ""RogueMonitor will alert you before you download a rogue application keeping you safe and secure before trouble occurs."" Now discontinued and the funtionality is included in Malwarebytes' Anti-Malware"
? roketpipe rpclient.exe"??"
U Rollback RollbackTray.exe"Added by the RollBack Rx system restore program"
X rollbk dsm.exe"Added by the SERFLOG.B WORM!"
X rollbk msmpatch.exe"Added by the SERFLOG.B WORM!"
X rollbk svosm.exe"Added by the SERFLOG.B WORM!"
X rollbk sysup.exe"Added by the SERFLOG.B WORM!"
X romahere matrixhere.exe"SuperSpider hijacker - a CoolWebSearch parasite variant"
X romahere2 ************.exe [* = random char]"SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as the KREPPER-AE TROJAN!"
X romahere3 ************.exe [* = random char]"SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as the KREPPER-AE TROJAN!"
X Root_Machine [path to trojan]"Added by the BANCBAN-DI TROJAN!"
X ROOT_Machine winlogon.exe"Added by the BANKER-FI TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\inf"
X RosTika RosTika.exe"Added by the BRONTOK-BU WORM!"
? ROUTD ROUTD.exe"??"
X Router Router.exe"Added by the AGENT.FJN TROJAN!"
N RoxAssist RoxAssist.exe"Roxio Assistant is designed to correct engine initialization errors in Easy CD & DVD Creator 6. If the engine does not initialize
? Roxio Engine MSMNGR32.EXE"Not believed to be a valid Roxio program - more likely a variant on the WOMANIZ.A TROJAN!"
Y Roxio Engine Compatibility Wizard EngUtil.exe"Part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools - corrects any modification made to the Roxio Engine
N RoxioAudioCentral RxMon.exe"Part of Roxio EasyCD Creator 6.0 - places the Roxio AudioCentral icon in you system tray. ""Includes a player
N RoxioDragToDisc DrgToDsc.exe"System Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly and available via the Start menu"
Y RoxioEngineUtility EngUtil.exe"Part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools - corrects any modification made to the Roxio Engine
N RoxWatchTray RoxWatchTray.exe"System Tray access to managing the ""Watched Folders""
N RoxWatchTray RoxWatchTray10.exe"System Tray access to managing the ""Watched Folders""
N RoxWatchTray RoxWatchTray9.exe"System Tray access to managing the ""Watched Folders""
N RoxWatchTray10 RoxWatchTray10.exe"System Tray access to managing the ""Watched Folders""
N RoxWatchTray9 RoxWatchTray9.exe"System Tray access to managing the ""Watched Folders""
U RP32 rp32.exe"Unicenter Remote Control (was Remotely Possible) from Enterprise International for remote control and access to Win9x/NT systems"
X RPC MSschost.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X RPC DCOM Vulnerability Patch msgfix.exe"Added by the RBOT.S WORM!"
X RPC Drivers rpcall.exe"Added by the SDBOT.FLY WORM!"
X RPC Patcher [path to worm]"Added by the BOLGI WORM!"
X RPC Service [random filename]"Added by the BDOOR-AAD BACKDOOR!"
X rpc Win32 shost32.exe"Added by the RBOT-ABL WORM!"
X rpc Win32 spoolscv.exe"Added by a variant of the RBOT WORM!"
X RPCall_WIN2K Kurawas.exe"Added by the BHARAT.A WORM!"
X RPCall_[ComputerName] smhost.exe"Added by the REDPLUT-B TROJAN!"
X rpcc rpcc.exe"Added by the SPAMMIT-E TROJAN!"
X rpcda Win32 rpcda.exe"Added by the RBOT-AEE WORM!"
X RPCInstall [path to trojan]"Added by the AGENT-DQM TROJAN!"
X RpcLocator explorer.exe"Added by the RBOT-GSA WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X RPCser32g services.exe"Added by the RITDOOR-C WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X RPCser32g1 services.exe"Added by the PREX.D WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X RPCser32g3 services.exe"Added by the PREXOT.D BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X RPCser32g4 services.exe"Added by the PREXOT.E BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X RPCserr32g winlogon.exe"Added by the RITDOOR-B WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X RPCserv32 services.exe"Added by the MYDOOM.AL WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X RPCserv32g services.exe"Added by the BOBAX.AA WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X RPCserv32g CSRSS.EXE"Added by the BOBAX.AD WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X RPCserv32g MSDEFR.EXE"Added by the BOBAX.AD WORM!"
X RPCserv32g NB32EXT2.EXE"Added by the BOBAX.AD WORM!"
X RPCserv32g WINLOGON.EXE"Added by the BOBAX.AD WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Y RPCSS.exe rpcss.exe"Remote Procedure Call. Required by windows for programs to communicate with each other on networks/different machines. Originally for NT only but now installed with Win98/98se. Under Win98/98se
X RpcxWindows Extensions rpcxwinex.exe"Added by the RBOT.ACP WORM!"
U RPSP Rpsserv32.exe"Red Pill Spy surveillance software. Uninstall this software unless you put it there yourself"
X Rr2 rundll32.exe"Added by the LINEAG-ADI TROJAN! Note - this is not the legitimate rundll32.exe process
X RRMedic rrmedic.exe"Troubleshooting utility for the RoadRunner cable internet service. Not required and you are advised to completely uninstall it. Provides a lot of false alarms and gets a lot of people panicking about there internet connection"
X rrmso bqhrmug.exe"Added by the AGENT-GYY TROJAN!"
X rro rundll32.exe"Added by the LINEAG-AAE TROJAN! Note - this is not the legitimate rundll32.exe process
X rs32net rs32net.exe"Added by the AGENT-IFH TROJAN!"
U rscmpt rscmpt.exe"Required on the GeFroce 64 meg MX card to show the full 64 meg memory and appears to be a software memory emulator running under the Win2K - see here. High CPU useage results - hence the U status"
X rsmb rsmb.exe"Added by the WAREZOV.C WORM!"
X rsmb32 rsmb32.exe"Added by the STRATION.AV WORM!"
U rsMenu rsMenu.exe"Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000. Formally Randsoft Harmony '98"
X RSPC Driver [random filename].exe"Added by the RBOT-SN WORM!"
X RSPC Driver D [random filename]"Added by a variant of the RBOT WORM!"
? RSRCMTZ RSRCMTZ.exe"??"
X rsrvmon.exe rsrvmon.exe"Added by the AGENT.NY TROJAN!"
X RSS "rundll32 RSSToolbar.dll DllRunMain"
U RssReader RssReader.exe"RssReader - a free RSS reader able to display any RSS and Atom news feed (XML)"
X RsWin lsass.exe"Added by the DELCANTI-B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""12053"" subfolder"
X RsWin lsass.exe"Added by the SILLY.BR WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""4350"" subfolder"
X RSync netsync.exe"SafeSurfing adware"
X rtasks rtasks.exe"Part of rogue software including members of the AVSystemCare security suite family (see here for examples)
U rtcdll rtcdll.exe"RTCDLL is ""Real Time Communication"" and is associated with Windows Messenger (the IM application
X RTHDBPL lsass.exe"Added by the ROUTROBOT WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\SystemProc"
N RTHDCPL RTHDCPL.EXE"Realtek HD Audio Control Panel
N RtHDVCpl RtHDVCpl.exe"Realtek HD Audio Manager
X rtkernsw [random filename]"Added by a variant of the SLAPER TROJAN!"
X rtl.exe rtl.exe"Added by the TIOTUA-J TROJAN!"
N RtlMon.exe RtlMon.exeMonitor for RealTek network card
Y RTMonitor RTMonitor.exe"Cheyenne (now eTrust) antivirus"
X rtos rtos.exeIRC trojan
? RTStartMute N/A"??"
Y rtvscn95 RTVSCN95.EXEReal-time virus scanner component of Norton Anti-Virus Corporate Edition
U RtWLan RtWLan.exe"Configuration utility for the Netgear WG111 54 Mbps Wireless USB 2.0 Adapter that ""provides wireless access to your desktop or notebook PC through the computer's USB port"""
X RubeL RubeL.exe"Added by the RUBY-B TROJAN!"
X Ruby13 Ruby13.exe"Added by the MEXER.E WORM!"
X Ruby14 Ruby14.exe"Added by the FIGHTRUB-A WORM!"
X ruin system32.exe"Added by the DELF-JM TROJAN!"
U RuLaunch RuLaunch.exe"Instant Updater for McAfee's VirusScan
X Run real.exe"Added by the LOVGATE.E WORM!"
X run Autoexec.com"Added by the HOLCAS.A WORM!"
X run inetinfo.exe"Added by the BINGHE TROJAN!"
X Run help.exeIESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!
X run services.exe"Added by the KREPPER-N TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\inet10066"
X run rundll32.exe rsrc.dll"Chinese originated browser hijacker - redirecting to 4199.com Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
X run cchost.exe"Added by the SQUATBOT-C TROJAN!"
X run e.exe"Added by the IMONI-E TROJAN!"
X run winsys32.exe"Added by the DELF.CP BACKDOOR!"
X run mexica.exe"Added by the AUTORUN.AEV WORM!"
X Run Manager.exe"Added by the DELF.EUN TROJAN! The file is found in %AppData%\Roaming\Adobe - see the link for more information"
U Run Google Web Accelerator GoogleWebAccWarden.exe"Google Web Accelerator"
X Run Msn Messenger msnmgr.exe"Added by the AGOBOT.HA WORM!"
X Run MSupdt32 wscript MSupdt32.vbs"Added by the CASER WORM!"
U Run Nintendo Wi-Fi USB Connector Registration Tool NintendoWFCReg.exe"Related to Wi-Fi USB Connector from Nintendo"
U Run POPFile in background perl.exe"POPFile - E-mail spam blocker"
U Run POPFile in background wperl.exe"POPFile - E-mail spam blocker"
X Run Services as Application localsvc.exe"Added by the DLOADER-NY TROJAN!"
X Run Services as Application netsvc.exe"Added by the DLOADER-NY TROJAN!"
X Run Services as Application spoolsvc.exe"Added by the DLOADER-NY TROJAN!"
X Run Services as Application svcadmin.exe"Added by the DLOADER-NY TROJAN!"
X Run Services as Application svcman.exe"Added by the DLOADER-NY TROJAN!"
X Run Services as Application svcrun.exe"Added by the DLOADER-NY TROJAN!"
X Run Services as Application tcpsvc.exe"Added by the DLOADER-NY TROJAN!"
X Run Services as Application websvc.exe"Added by the DLOADER-NY TROJAN!"
U Run StartupMonitor StartupMonitor.exe"Mike Lin's StartupMonitor
X run windows servic.bat"Added by the REBOOT-AP TROJAN!"
X Run05 rundll_32.exe"Added by the BANCOS-DT TROJAN!"
X run32 run32dll.exe"Added by the SDBOT-CWB WORM!"
X run32dll WINClock.exe"Added by an unidentified VIRUS
X run32dll task32.exe"Added by an unidentified VIRUS
X Run32dll ocxdll.exe"Added by an unidentified VIRUS
N run= cmmpu.exeMIDI emulator driver for the integrated sound chip by C-Media based on the CMI-8330 chip set normally found in cheap motherboards. Also installed as part of the software for a Guillemot Maxi Muse sound card (PCI)
N run= hpfschedHPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature
N run= lxdboxcp.exeLexmark DOS-Printing Control Program for the Lexmark 2050. Only required if you need to print from DOS
N run= pcfix2k.exepcfix2k splash screen
X run= ptlseq.cpl"PhoenixNet BIOS adware. See here"
U run= ramsys.exe"Advanced Startup Manager from Rays Lab"
? run= wallflip.exe"Desktop wallpaper changer?"
X run= svcinit.exe"CoolWebSearch parasite variant"
X run= fntldr.exe"CoolWebSearch Tapicfg parasite variant"
Y run= smsrun16.exe"Microsoft Systems Management Server (SMS) related - program that reads SMSRUN16.INI on clients running Win 3.1
? run= win.ini"??"
X run= RAVMOND.exe"Added by the LOVGATE-F WORM!"
X run= dec25.exe"Added by the ATAK.F WORM!"
? run= LXBTppls.exe"Reportedly part of Lexmark printer software - what does it do and is it required?"
N run= fmedia.exeFMedia FaxWorks related - can be run manually
Y run= wswpd.exe"Used with some models of Panasonic
X run= cyxid98.exeUnidentified malware
X run= info32.exe"CoolWebSearch Tapicfg parasite variant"
X run= mouse_configurator.win"Added by the GAGGLE.E WORM!"
X run= RegistryReminder.exe"Added by the APSTROJAN.OB TROJAN!"
X run= sec5dec.exe"Added by the ATAK.G WORM!"
X run= wmplayer.exe"CoolWebSearch Smartsearch parasite variant"
X run= Autoexec.com"Added by the HOLCAS.A WORM!"
X run= htmlsync.exeSearchforfree.info browser hijacker
X run= msoffice.exe"Added by the ADWARELOADER TROJAN! Note - do not confuse with the legitimate Microsoft Office file
X run= DRDOOM.EXE"Added by the SEMAPI-A WORM!"
X run= svhost.exe"Added by the ADMINCASH.B TROJAN!"
X run= dllreg.exe"Added by the DUMARU-L TROJAN!"
X run= Celine.scr"Added by the CELINE-A TROJAN!"
U RunAlert AService.exe"PC Alert III - MSI motherboard monitoring software. Only required if you ""overclock"" your system. Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98/2K"
N runAP runAP.exe"Not required but what is it?"
X runapp icqchk.exe"Added by the BOMKA TROJAN!"
X Runapp32 Runapp32.exe"Added by the NEODURK TROJAN!"
Y RunCA InvokeSvc3.exeWireless-G USB Wireless Network Adapter related - would appear to be required
X Rund11 Rund11.EXE"Added by the MARIO-C WORM!"
X rund1132 rund1132.exe"Added by the DOPBOT-A WORM!"
X Rund1132.exe Rund1132.exe"Added by the STARTPA-HS TROJAN!"
X Rund1l32 Winfi1e32.exe"Added by the MERTIAN WORM!"
X runddlfile runddl.exe"Added by the DELF.D TROJAN!"
X Rundil32 runlli32.exe"Added by the QQPASS-U TROJAN!"
X Rundil32 Updadv.exe"Added by the QQPASS-N TROJAN!"
X rundl332 math.exe ...pluged.exe"Added by the DOOMJUICE WORM!"
X rundli32 rundli32.exe"Added by the LADE WORM!"
X RunDLL "rundll32.exe [path] Bridge.dllLoad"
X Rundll Rundll~.exe"Added by the DELF-KT TROJAN!"
X Rundll rundll32.exe [random filename].dll"Added by the MYTOB.IG WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in %System%"
X RunDll RunDll.exe"Added by the QQPASS-AH TROJAN! Note - this is NOT the Win9x/Me system file of the same name as described here"
X RunDll [path to trojan]"Added by the DROPPER.EAT TROJAN!"
X RunDLL Kernel File Core rundll.exe"Added by a variant of the RBOT WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
X rundll*** die.exe [path] mdll.exe"Added by the SUMTAX TROJAN! where *** is 134
X rundll*** die.exe [path] secure.bat"Added by the SUMTAX TROJAN! where *** is 134
X rundll*** die.exe [path] secure.exe"Added by the SUMTAX TROJAN! where *** is 134
X rundll*** die.exe [path] ttg.exe"Added by the SUMTAX TROJAN! where *** is 134
X Rundll16 Rundll16.exe"Added by a number of VIRUSES
X Rundll32 Rundll32.exe"Added by a variant of the DVLDR TROJAN! Note - this is not the legitimate rundll32.exe process
U RUNDLL32 "RUNDLL32.EXE NvQTwkNvCplDaemon"
U RunDLL32 "RunDLL32.exe NvMCTray.dllNvTaskbarInit"
X RunDLL32 winupdate.exe"Added by an unidentified TROJAN! - possibly a BMBOT variant"
X Rundll32 Windows.exe"Added by the QQPASS.E TROJAN!"
U Rundll32 "Rundll32.exe ptipbm.dll SetWriteBack"
X rundll32 [path to worm]"Added by the AUTEX WORM!"
? rundll32 "rundll32.exe ptipbmf.dll SetWriteCacheMode"
X rundll32 rundll32.exe"Added by the SANKER WORM! Note - this is not the legitimate rundll32.exe process
X rundll32 csrss.exe"Added by the GUTTA TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
U rundll32 "rundll32.exe irprops.cpl
X RUNDLL32 rundl32.exe"Added by the DEMOTRY-A WORM!"
X rundll32 rundll32.exe"Added by the AGENT-EZ TROJAN! Note - this is not the legitimate rundll32.exe process
X Rundll32 RUNDDLL32.EXEAdded by the STARTPAGE.AXH TROJAN!
X rundll32 kernel32.exe"Added by the STAP-C WORM!"
X rundll32 kernel33.exe"Added by the STAP-D WORM!"
X rundll32 MSDTC.exe"Added by the STAP-E WORM!"
X rundll32 rookie.vbs"Added by the ROOKIE-A TROJAN!"
X rundll32 rundll64.exe"Added by the DELF.BKC TROJAN!"
U rundll32 "rundll32.exe bthprops.cpl
U rundll32 "rundll32.exe nview.dllnViewLoadHook"
X rundll32 svchs0t.exe"Added by the PWSTEAL-E TROJAN!"
N Rundll32 cmicnfg "Rundll32 cmicnfg.cpl CMICtrlWnd"
Y RunDll32 essprops "RunDll32 essprops.cpl TaskbarIconWnd"
U Rundll32 P17 "Rundll32 P17.dll P17Helper"
X Rundll32.exe Proyecto1.exe"Added by the GRUEL WORM!"
X Rundll32.exe Root.exe"Added by the GRUEL WORM!"
X Rundll32_7 "rundll32.exe MSIEFR40.DLL DllRunServer"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list