|
The table below includes any files beginning with s, from which further information can be found by clicking on the process title. The icon beside the information can be used to quickly determine if this is a safe file in combination with the key below:
[#] [A] [B] [C] [D] [E] [F] [G] [H] [I] [J] [K] [L] [M] [N] [O] [P] [Q] [R] [S] [T] [U] [V] [W] [X] [Y] [Z] |
Files beginning with s:
| File Type | File Name | Process Name and Information |
![]() |
system32.exe |
Added by the AGOBOT-KU WORM! Note - has a blank entry under the Startup Item/Name field |
![]() |
svchost.exe |
Added by the DELF-UX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field |
![]() |
SP00Lsv32.pif |
(L4r1$$4) (4nt1) (V1ruz)
Added by the ASSIRAL.B WORM! |
![]() |
secctr.exe |
*Security Center
Added by the SDBOT.BRO WORM! |
![]() |
statemgr.exe |
*StateMgr
Windows ME default for System Restore. Do NOT disable! |
![]() |
systemupd.exe |
*WindowsAudio
Added by the AGENT-TH WORM! |
![]() |
svhost.exe |
.mscsbl
Added by the CMQ TROJAN! |
![]() |
sysmon32.exe |
.NET config
?? |
![]() |
smss.exe |
.nvsvc
Added by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup! |
![]() |
smssb.exe |
.nvsvcb
Added by the BOXED.CG TROJAN! |
![]() |
services.exe |
.Prog
Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
![]() |
system32THotkey.exe |
00THotkey
For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev |
![]() |
svchost.scr |
1
Added by the BANCOS.X TROJAN! |
![]() |
sysockeu.exe |
1029BB4B-16A9-4E77-AA3D-96930BD68EEC
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
![]() |
stubinstaller****.exe [* = digit] |
180ClientStubInstall
180Solutions adware related |
![]() |
SpyAgent4.exe |
1Srv32
SpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC." |
![]() |
SpyBuddy.exe |
1Win32Cfg
SpyBuddy keystroke logger/monitoring program - remove unless you installed it yourself! |
![]() |
sysokuaw.exe |
2177F056-0AA6-4D6C-A944-13F71F341C29
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
![]() |
slsorve.exe |
27
Added by the SLSORVE-A TROJAN! |
![]() |
svchost.exe |
333
Added by the JD-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This one is located in a "Syswm1i" directory |
![]() |
Ska.exe |
666
Added by the PIPES TROJAN! |
![]() |
sysoghcx.exe |
756349DC-6D9E-4F2A-9B24-269661F073C3
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
![]() |
sysodkcs.exe |
852EBF20-A95D-4F1F-B9C2-B2CD24350F3E
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
![]() |
sys.exe |
AAMSFree702
Added by the BACKDOOR-CPC TROJAN! |
![]() |
snddrv.exe |
Ac97Sound
Detected by Sophos as the SILLYFDC-A TROJAN! |
![]() |
schedhlp.exe |
Acronis Scheduler Helper
Part of Acronis True Image backup software. Co-operates with the "schedul2.exe" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images |
![]() |
schedhlp.exe |
Acronis Scheduler2 Service
Part of Acronis True Image - backup software. Co-operates with the "schedul2.exe" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images |
![]() |
systray32.exe |
ActiveDesktop
Added by the DABOOM WORM! |
![]() |
svcss.exe |
ActiveXUpdate
Added by a variant of the DEDLER.C TROJAN! |
![]() |
svchost.scr |
Administrator
Added by the NOVACAL TROJAN! |
![]() |
sysfile.vbs |
AdminSoft
Added by the STARGRUB-A WORM! |
![]() |
sysconfig.exe |
Adobe
Added by an unidentified WORM or TROJAN! |
![]() |
sysbat32.exe |
Adobe
Added by the LOWZONES.T TROJAN! |
![]() |
sysmsn.exe |
AdobeReaderPros
Added by the RBOT-BGH WORM! |
![]() |
services.exe |
AdRotator.Application
Added by FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in an "Inetsrv" subfolder |
![]() |
stopAds.exe |
AdsBlocker
Reported as DILAER.DW by NOD32 |
![]() |
SystemtrayV100B.exe |
ADSLSYSTEMTRAY
Apparently Annex A ADSL modem related. What does it do and is it required? |
![]() |
sysupudt.exe |
AdUpdater
Unidentified adware downloader/updater |
![]() |
schedules.exe |
AdwareKiller_schedules
EAdwareKiller spyware remover - not recommended, see here |
![]() |
scchost.exe |
Alive SYstem
Added by the TOFDROP-B TROJAN! |
![]() |
scchostc.exe |
Alive SYstem
Added by the TOFDROP-B TROJAN! |
![]() |
stswin.exe |
All Aboard Status
All Aboard! Internet Connection Sharing status icon |
![]() |
svchost.exe |
alpha
Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
![]() |
SecurityCenter.exe |
Aluria Security Center
Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here |
![]() |
SpyWareKiller.exe |
ANONYMIZER_SPYWAREKILLER
Anonymizer Spyware Killer - now Anti-Spyware |
![]() |
spamsvc.exe |
Anti Spam Service
Added by the MYTOB-BK WORM! |
![]() |
SVCHST32.EXE |
AntiClicker
Added by the CBH TROJAN! |
![]() |
svchst.exe |
Antivir
Added by the RAGRUK-A TROJAN! |
![]() |
scvhost.exe |
AntiVir
Added by the AGENT-DSF TROJAN! |
![]() |
sysrtmvs.exe |
aouei
Chivio dialer |
![]() |
smsbvl32.exe |
ApplicationProtocolRun
Added by the IRCBOT-CX TROJAN! |
![]() |
simenu.exe |
apyginapygin
Added by the SDBOT.BTR WORM! |
![]() |
SocksA.exe |
ASocksrv
Added by the VB.CBW WORM! |
![]() |
servicos..exe |
ASP.NET State Service
Added by the DADOBRA-I TROJAN! |
![]() |
SAUpdate.exe |
ATTBroadbandUpdate
Big Brother from Quest Software. System and network monitor |
![]() |
SOUND.exe |
AUDIO
Added by the PLOYB-A TROJAN! |
![]() |
symcsvc.exe |
aupd
Added by the ABWIZ.D TROJAN! |
![]() |
sysvcs.exe |
aupd
Added by the ABWIZ.C TROJAN! |
![]() |
sywsvcs.exe |
aupd
Added by the ORSE-M TROJAN! |
![]() |
sa3dsrv.exe |
Aureal A3D Interactive Audio
For Aureal based 3D soundcards. A3D sound features won't work with this disabled |
![]() |
startauth.exe |
Auth Starter Ident
Added by the RBOT-WP WORM! |
![]() |
scricon.exe |
Auto File System Conversion Utility
Added by a variant of the SDBOT WORM! |
![]() |
svchost.exe |
Auto Update
Added by the DUMARDI-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
![]() |
svchost.exe |
Auto Updates
Added by the CHEUKO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
![]() |
SERVICES.EXE |
AutoAdministrator
Added by the PUNYA-A WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
![]() |
spooll.exe |
autoload
Detected by Symantec as the SILLYFDC WORM! See here |
![]() |
suchost.exe |
Automatic Microsoft Windows Updater
Added by the RBOT-EQ WORM! |
![]() |
sxs.exe |
autorun
Added by the SMALLVBS-A WORM! |
![]() |
smss.exe |
AutoUpdate
Added by a variant of the WINSPY.AA TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "debug64" subfolder of the Winnt or Windows folder |
![]() |
StartFX.exe |
AVFX Engine
Advanced Video FX - supported by a number of Creative Web Cameras. "Have more fun by adding a wide range of special effects and backgrounds to your video chat with Advanced Video FX" |
![]() |
svchost323.exe |
AvG
Added by the RBOT-ZA WORM! |
![]() |
serbw.exe |
avnort
Added by the SERFLOG.A WORM! |
![]() |
SCHSC9X.EXE |
AVSchedScan
Command Antivirus related |
![]() |
svosm.exe |
AvSer
Added by the SERFLOG.B WORM! |
![]() |
sysup.exe |
AvSer
Added by the SERFLOG.B WORM! |
![]() |
svchst32.exe |
bab
Added by the AGENT.Q TROJAN! |
![]() |
SYSMONMS.EXE |
bal
Added by the FAKEALERT TROJAN! |
![]() |
station.sbrt |
Bart Station
Related to PeoplePC ISP. May be a dialler for dial-up accounts? |
![]() |
secure2.bat |
Bat
Added by the ZCREW.C TROJAN! |
![]() |
skinkers.exe |
BBC News alerts
BBC News Desktop Alerts service - see here. Desktop alert and breaking news e-mail services let you find out about all the latest news as it happens |
![]() |
saqevre.exe |
Beawver
Added by the RANKY.AGA TROJAN! |
![]() |
svchost.exe |
beta
Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
![]() |
smnp.exe |
blah service
Added by the RBOT.IZ WORM! |
![]() |
syser.exe |
boler.exe
Added by the RBOT-AYS WORM! |
![]() |
syncit.exe |
BookMarkSink
Bookmark synchronization utility |
![]() |
syncit.exe |
BookMarkSync
Sync2IT BookMarkSync - "real-time automatic synchronization service that allows you to access your bookmarks, favorites and favorite files from any computer or any browser". Only installed with the users explicit permission and generally only remains running if the user decides to subscribe to the service. If it is no longer required it should be uninstalled to prevent a large number of clients 'checking in' to the server that have no chance of synchronizing |
![]() |
sync2it.exe |
BookMarkSync2It
Sync2IT BookMarkSync - "real-time automatic synchronization service that allows you to access your bookmarks, favorites and favorite files from any computer or any browser". Only installed with the users explicit permission and generally only remains running if the user decides to subscribe to the service. If it is no longer required it should be uninstalled to prevent a large number of clients 'checking in' to the server that have no chance of synchronizing |
![]() |
svchostt.exe |
Bot Loader
Added by the GAOBOT.ALV WORM! |
![]() |
servicecenter.exe |
Bredbandsbolaget
Related to the Brebband Swedish Broadband provider |
![]() |
sempalong.exe |
Bron-Spizaetus
Added by the BRONTOK-E WORM! |
![]() |
s_menu.exe |
browser
Added by the TACTSLAY.C TROJAN! |
![]() |
SVCH0ST.EXE |
BSVCHOST
Added by the VOXOM TROJAN! |
![]() |
services.exe |
BuildLab
Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
![]() |
SetupCmd.exe |
C:WINDOWSsystem32SetupCmd.exe
Detected by Kaspersky as the AGENT.AAW TROJAN! |
![]() |
sddriver.exe |
Call Function System32
Added by a variant of the SDBOT TROJAN! |
![]() |
svchost.exe |
CashToolbar
CashToolbar Downloader-MY adware. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
![]() |
svcrhost.exe |
ccAppr
Added by the TACTSLAY.A TROJAN! |
![]() |
svcshost.exe |
ccAppr
Added by the TACTSLAY.A TROJAN! |
![]() |
services.exe |
ccApps
Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
![]() |
svcrhost.exe |
ccRegVfY
Added by the TACTSLAY.A TROJAN! |
![]() |
svcshost.exe |
ccRegVfY
Added by the TACTSLAY.A TROJAN! |
![]() |
stealth.exe |
CCWC7s
Moleculesoft Cache, Cookie & Windows Cleaner. No longer supported but available for free |
![]() |
svchost.exe |
CDriver
Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
![]() |
SafeSignCertReg.exe |
CertificateRegistration
SafeSign Certificate Registration Utility for Microsoft Crypto applications |
![]() |
server.exe |
CesarFTP FTP Server
CesarFTPd - FTP server |
![]() |
sfcmonit.exe |
cftmon
Added by a variant of the AGENT.ERG TROJAN! |
![]() |
SPMSMON.EXE |
ChangeICON
Card reader related program. Note - may cause problems with My Computer loading at startup. Disabling through MsConfig seems to solve the problem |
![]() |
sokscmpn.exe |
CHIPDRIVEPinManager
ChipDrive Smartcard software |
![]() |
SCMgr.exe |
CHIPDRIVESmartcardManager
ChipDrive Smartcard software |
![]() |
srv.exe |
Classes
Switch adult content dialler |
![]() |
srv2.exe |
Classes
Switch adult content dialler |
![]() |
service.exe |
Clean up
Added by the AGENT-FPY TROJAN! |
![]() |
smmss.exe |
Client Server Runtime Process
Backdoor TROJAN! Possible SDBOT-GEN variant |
![]() |
Sync.exe |
ClockSync
ClockSync - synchronizes your system clock with an internet time server. It's by WhenU, the makers of the Save Now spyware, and they're usually seen in tandem, so it's advised to replace it with one of may spyware free alternatives available |
![]() |
sed.exe |
CLSID
Adult content dialler |
![]() |
SmWizard.exe |
CM-SmWizard
SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required? |
![]() |
startupmon.exe |
cmonitor
SystemDoctor is a security risk that may give exaggerated reports of threats on the computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported threats |
![]() |
system.exe |
cmss
Added by a variant of the RBOT WORM! |
![]() |
Systray.exe |
Coldlife -icmp
Added by the FLOOD.AV TROJAN! Note - this is not the legitimate systray.exe process |
![]() |
suchost.exe |
COM++ System
Added by a variant of the LOVGATE WORM! |
![]() |
svchost.exe... |
COM++ System
Added by a variant of the LOVGATE WORM! |
![]() |
svdhost.exe |
COMDRV32
Orvell Monitoring 2003 surveillance software. Uninstall this software unless you put it there yourself. Note - asks for permission to contact the IP address of http://www.protectcom.com/ |
![]() |
system.exe |
Command
Added by the GATECRASH.A or GATECRASH.B TROJANS! |
![]() |
SCCENTER.EXE |
Compaq Computer Corp SCCenter Module
For Compaq PC's. Part of Backweb |
![]() |
silent.exe & matcli.exe |
Compaq Knowledge Center
matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file while silent.exe executes matcli.exe quietly in the background. Compaq Knowledge Center is required to run with the Help and Support program. If you uncheck Compaq Knowledge Center and and then run help and Support it will add another Compaq Knowledge Center in the startup menu. If you remove the Compaq Knowledge Center in the add/remove program some help menus in help and support will not be available like Fix my Presario, Preference, and Contact Technical Support. You decide |
![]() |
systeminfos.exe |
Compaq Service Drivers
Added by the SDBOT-XC WORM! |
![]() |
sounddr.exe |
Compaq Sound Drivers For WINDOWS
Added by the SDBOT-XG WORM! |
![]() |
SRP.exe |
ConfidentUser
ConfidentUser misleading security software - the site's "online scanner" detected by Kaspersky antivirus as WinFixer.ba |
![]() |
service.exe |
Config
Added by the ISRAZ.B WORM! |
![]() |
svchosl.exe |
Config Loader
Added by the GAOBOT.P WORM! |
![]() |
sysldr32.exe |
Config Loader
Added by the GAOBOT WORM! |
![]() |
scvhost.exe |
Config Loader
Added by the GAOBOT.AE or GAOBOT.AO WORMS! |
![]() |
svhost.exe |
Config Loader
Added by a variant of the AGOBOT/GAOBOT WORM! |
![]() |
service5.exe |
Configuration Loader
Added by the GAOBOT.AF WORM! |
![]() |
sycfg34.exe |
Configuration Loader
Added by the GAOBOT.AN WORM! |
![]() |
Service.exe |
Configuration Loader
Added by the GAOBOT.AO WORM! |
![]() |
Servicess.exe |
Configuration Loader
Added by the GAOBOT.AO WORM! |
![]() |
sw32.exe |
Configuration Loader
Added by the AGOBOT.BQ WORM! |
![]() |
System.exe |
Configuration Loader
Added by the GAOBOT.AO WORM! |
![]() |
sysinfo.exe |
Configuration Loader
Added by the GAOBOT.FQ WORM! |
![]() |
svhst.exe |
Configuration Loader
Added by the GAOBOT.YC WORM! |
![]() |
systemry.exe |
Configuration Loader
Added by a variant of the AGOBOT/GAOBOT WORM! |
![]() |
smss32.exe |
Configuration Loader
Added by the AGOBOT.MB WORM! |
![]() |
seru32.exe |
Configuration Loader
Added by the SDBOT-VR WORM! |
![]() |
smsai.exe |
Configuration Loader
Added by the SDBOT-YE WORM! |
![]() |
svupdate.exe |
Configuration Loader
Added by the RANDEX.DXP WORM! |
![]() |
scvhost.exe |
Configuration Loader
Added by the AGOBOT-AAE and SDBOT.AR WORMS! |
![]() |
svchost.exe |
Configuration Loader
Added by the PARADROP-A WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
![]() |
svchost2.exe |
Configuration Loader
Added by the AGOBOT.JR WORM! |
![]() |
svchost.exe |
Configuration Loader
Added by the PARADROP-AI WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup! |
![]() |
syscfg32.exe |
Configuration Loader
Added by the SDBOT.B TROJAN! |
![]() |
svchos1.exe |
Configuration Loading
Added by the GAOBOT.DK WORM! |
![]() |
sewins.exe |
Configuration Servecie
Added by the SDBOT-COH WORM! |
![]() |
suchost.exe |
Configuration Service
Added by the TREB TROJAN! |
![]() |
sysconf16.exe |
ConfLoader
Added by the SDBOT-FB TROJAN! |
![]() |
SYS.EXE |
Connector
Added by the dialer.Nunci premium dialer |
![]() |
sms.EXE |
Connector
Added by the ExDial-B premium rate adult content dialer |
![]() |
smctrlw.exe |
control panel
System Tray icon for a Silicon Motion LynxEM based PCI Graphics Card |
![]() |
System.exe |
Control Panel
Added by the DANI TROJAN! |
![]() |
systemctrl.exe internet.dll, LoadNetworkProfile |
ControlPanel
Browser hijacker, also detected as STARTPA-FX |
![]() |
svcc.exe |
ControlPanel
WorldSearch adware |
![]() |
s_menu.exe |
cpl
Added by the TACTSLAY.C TROJAN! |
![]() |
simcss.exe |
cpntmgc
Added by the MAGICON.A TROJAN! |
![]() |
StartEAK.exe |
CPQEASYACC
For Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys |
![]() |
STARTDRV.exe |
CPQEASYACC
For Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys |
![]() |
stutfix.exe |
CPQSTUTFIX
For Compaq PC's. Fixes audio stutter problems for ESS Maestro soundcards. You can download it here. This is a Compaq originated file and has been verified as free from viruses by McAfree/Norton |
![]() |
svchost32.exe |
CRC Value Verifier
Added by the RBOT-OA WORM! |
![]() |
stacture.exe |
Creates stractures for system management
Added by the SDBOT-DHS WORM! |
![]() |
starter.exe |
Creative PCI Audio Configuration Utility
System Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on this special page. Similar to EnsoniqMixer |
![]() |
scrnsave.pif |
Crnsava
Added by the SDBOT-ZV WORM! |
![]() |
spqmdmui.exe |
csaRem
Compaq modem country selection |
![]() |
softok.exe |
csoftok
Added by the QQPASS.G TROJAN! |
![]() |
ssms.exe |
csrss
Added by an unidentified malware |
![]() |
SCHWIZEX.EXE |
CSScheduleCheck
Part of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot |
![]() |
SVOHOST.exe |
ctfnom.exe
Added by the DIGIDOR-A TROJAN! |
![]() |
Screendragon_VS_Taskbar.exe |
cursor
ScreenDragon video player |
![]() |
sdservss.exe |
cvmsyslpd
Added by the MAILBOT-BY TROJAN! |
![]() |
showmode.exe |
Cyber Trio
From G-Tek Technologies. Allows you to set the PC in one of three modes, Standard, Enhanced and Kiddo. Standard is full function, Enhanced prevents accidental damage and Kiddo is a play environment for kids. Pre-installed on some Packard Bell PCs |
![]() |
System.dat.vbs |
Data
Added by the BISCUIT.A WORM! |
![]() |
starter.exe |
dbar_starter
Deskbar adware - adds a search bar to your Windows taskbar which performs searches on www.w-w-w-dot-com.com |
![]() |
SVIQ.EXE |
dc2k5
Added by the COIDUNG-A WORM! |
![]() |
sprtcmd.exe /P ddoctorv2 |
ddoctorv2
Comcast Desktop Doctor (provided by SupportSoft, Inc) is a free self-help tool for Comcast broadband users. Identifies and automatically fixes typical problems that may occur with your high-speed internet service |
![]() |
svchost.exe |
DDriver
Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
![]() |
shell32.exe |
default
Added by the BINGHE TROJAN! |
![]() |
svchost.exe |
defragsys
Added by the BIFROSE-TH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
![]() |
sprtcmd.exe /P DellSupportCenter |
DellSupportCenter
Dell Support Center (provided by SupportSoft, Inc) is a free self-help tool for Dell users. Identifies and automatically fixes typical problems that may occur with your high-speed internet service |
![]() |
smvss.exe |
devenv
Added by the DEDLER-G TROJAN! |
![]() |
smss.exe |
DHCP
Added by the WINSPY.AG TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
![]() |
services.exe |
DHCP32
Added by the WINSPY.AG TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
![]() |
sdchost.exe |
Direct settings
Added by the DAEMONI-I TROJAN! |
![]() |
Sqlexploit.exe |
directx
Added by the SDBOT.D TROJAN! |
![]() |
Sservice.exe |
DirectX for Microsoft Windows
Added by the PRORAT TROJAN! |
![]() |
SECURITY.EXE |
Disk Keeper
Daosearch adware |
![]() |
Snt.exe |
Diskstart
Adult content dialler |
![]() |
svchoist.exe |
Dll Link
Added by the AUTOSKY WORM! |
![]() |
svchost.exe |
Dll Link
Added by the AUTOSKY WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Documents and SettingsFavourites folder |
![]() |
server.exe |
dreams
Added by a variant of the SDBOT WORM! |
![]() |
SysDrefIWv2.exe |
DrefIW
Added by the DREF-C WORM! |
![]() |
SysDref.exe |
DrefIW
Added by the DREF-D WORM! |
![]() |
Scam32.exe |
Driver32
Added by the SIRCAM WORM! |
![]() |
svchost.exe |
DriverCheck
Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a C:DriverLoad folder |
![]() |
svcmdx32.exe |
DriverDB
Added by the BERPI TROJAN! |
![]() |
svchost.exe |
DriverLoad
Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a C:DriverLoad folder |
![]() |
system32.exe |
DriverPath
Added by the PRORAT-S TROJAN! |
![]() |
SmartAgt.exe |
dRMON SmartAgent
Part of the network monitoring program group for 3Com NIC cards. See here for more info |
![]() |
stmhosts.exe |
drmsrv32
Added by the AGENT.AGWU TROJAN! |
![]() |
spdstrm.exe |
DSL Monitor
Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray |
![]() |
svosm.exe |
DsmSer
Added by the SERFLOG.B WORM! |
![]() |
sysup.exe |
DsmSer
Added by the SERFLOG.B WORM! |
![]() |
StartUpDualCoreCenter.exe |
DualCoreCenter
Unified control center for overclocking both the graphics card and the CPU, but for the program to have its full functionality you must have an MSI mainboard with a CoreCell chip |
![]() |
spoolc.exe |
dumprep
Detected by Kaspersky as a variant of the AGENT.CXF TROJAN! |
![]() |
support.exe |
DwlClient
Download manager for Dell support alerts |
![]() |
sys*.exe [* = random number] |
Dx
Added by the DEXTER.A WORM! |
![]() |
sys_alert.exe |
eanth_critical_update_alert
eAcceleration Stop-Sign security software related. Previously not recommended, see here |
![]() |
sys_alert.exe |
eanth_system_patcher
eAcceleration Stop-Sign security software related. Previously not recommended, see here |
![]() |
sbsetup.exe |
Eapcisetup
Rockwell RipTide soundcard application software. Sound works without it |
![]() |
Server.exe |
easyServ
Added by the EASYSERV TROJAN! |
![]() |
smproxy.exe |
ELNKProxy
Surfmonkey adware |
![]() |
surfboard.exe |
ENCSurf
?? |
![]() |
starter.exe |
EnsoniqMixer
Puts the Ensoniq mixer in system tray. From Ensoniq Technologies "Our mixer is a critical part of the soundcard as it fixes sound problems and replaces the MS mixer which can no longer be used". If you find you don't need it - try one of the solutions on this special page. Similar to Creative PCI Audio Configuration Utility |
![]() |
STMS.EXE |
EPSON Background Monitor
Supposed to keep an Epson printer ready for quick printing. Users report little difference whether it is on or not |
![]() |
SysRep.exe |
ErrClean
ErrClean misleading security software - not recommended, see here |
![]() |
svc.exe |
erthgdr
Added by the BEAGLE.BN or BEAGLE.BP WORM! |
![]() |
svc23.exe |
erthgdr2
Added by the BAGLE.CG WORM! |
![]() |
smrrs.exe |
Ethernet Drivers
Added by the RBOT-AAK WORM! |
![]() |
smschk.exe |
EventApplicationCmd
Added by the IRCBOT-AO TROJAN! |
![]() |
shellexpl.exe |
Explorer
Added by the SHELDOR TROJAN! |
![]() |
shellexp.exe |
Explorer
Added by a variant of the SHELDOR TROJAN! |
![]() |
sys.exe |
EXPLORER
Added by the SILLYFDC-A TROJAN! |
![]() |
svchost.exe |
F-Secure 2005
Added by the BIFROSE-CH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
![]() |
svcnvt.exe |
Fast Home
Detected by Kaspersky as the DELF.KS TROJAN! This file may be found in the System folder on 9x machines, however as of this writing it has only been seen in the System32 folder |
![]() |
svcnv.exe |
Fast Search
Homepage, Startpage hijacker. Possible variant of Trojan-Downloader.Win32.Delf |
![]() |
svcnt.exe |
Fast start
Adware - detected by Kaspersky as a variant of the FAVADD TROJAN! |
![]() |
svcnut.exe |
FastStart
Browser hijacker - a variant of the STARTPAGE.L TROJAN! |
![]() |
svcnut32.exe |
FastStart
Browser hijacker - a variant of the STARTPAGE.L TROJAN! |
![]() |
SPEED UP.EXE |
FastTrack Accelerator
FastTrack Accelerator - "speedup" utility for programs that use the FastTrack network such as KaZaA Media Desktop, Grokster and Morpheus |
![]() |
sp2.exe |
Fdr Command Module
Added by the SDBOT.WP WORM! |
![]() |
SVCH0ST.EXE |
fegoze
Added by the GRAYBIRD.D VIRUS! Note - the filename has the digit 0 rather then the uppercase "o" |
![]() |
shdochp.exe |
FHPage
Added by the DELF-Ks TROJAN! |
![]() |
shdocsvc.exe |
FHStart
Added by the DELF-Ks TROJAN! |
![]() |
SyncService.exe |
FieldForms Sync
Resco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run, on a wide range of mobile devices. Supports Microsoft Access databases, and provides for synchronization of other data as well |
![]() |
ssmss.exe |
FireFox Service Drivers
Added by a variant of the SDBOT WORM! |
![]() |
SP2 UPDATE.exe |
Firewall
Added by the ELITPER.E WORM! |
![]() |
sys32.exe |
Firewall Controls
Added by the SDBOT-DGI WORM! |
![]() |
sys32Conf.exe |
Firewall Sp2 system
Added by the Rbot-ABT WORM! |
![]() |
samx.exe |
FireWire Driver
Added by the SDBOT.AE WORM! |
![]() |
services.exe |
Flash Media
Added by a variant of the IRCBOT TROJAN! See here. Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
![]() |
SDSTAT.EXE |
FlashPath Monitor
System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs |
![]() |
SDSTAT.EXE |
FlashPath Status
System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs |
![]() |
service.exe |
foxwudy9912
Added by the BANCOS-BT TROJAN! |
![]() |
stub_113_4_0_4_0.exe |
fqor
TargetSaver adware |
![]() |
svchost.exe |
France
Added by the MIMAIL.L WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
![]() |
shdrkmck.exe |
frguk
?? |
![]() |
services.exe |
FriendlyTypeName
Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
![]() |
SELFCERT.EXE |
FriendlyWebQuick-Launch
selfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as well |
![]() |
StCenter.exe |
FRITZ!DSL Startcenter
FRITZ! ISP software "StartCenter" User interface that allows you to manage, tweak and diagnose many aspects of your internet connection - is it required? |
![]() |
svcnva.exe |
FSH
Malware, detected by Ewido Security Suite as TrojanDownloader.Delf.ks |
![]() |
svhost32.exe |
fzg
Added by the DLOADER.BDK TROJAN! |
![]() |
shit.exe |
game
Added by the Netclap Gold backdoor TROJAN! |
![]() |
svshost.exe |
Games Acceleration
EasySearch adware |
![]() |
svshost1.exe |
Games Acceleration
Added by the DLOADR-AWD TROJAN! |
![]() |
svchost.exe |
gamma
Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
![]() |
setgamma.exe |
GammaHotKeys
Part of the RadeonTweaker program for adjusting ATI Radeon graphics cards. Allows you to adjust the gamma (or brightness) when playing a full-screen game without switching back to the desktop |
![]() |
Systpl.exe |
Gate Personal Firewall
Added by the RBOT.ADC WORM |
![]() |
SpaceMan.exe |
GBSpaceMan
GreenBorder - secure your browsing activities on the internet |
![]() |
SVCHOSTS.EXE |
Generic host proccess for windows
Added by the SPYBOT-GQ WORM! |
![]() |
SCHOST.EXE |
Generic Host Process
Added by the RBOT-NC WORM! |
![]() |
svchost.exe |
Generic Host Process
Added by the DLOADER-NX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
![]() |
svlhost.exe |
Generic Host Process for Win32 Service
Added by the WOOTBOT.EX WORM! |
![]() |
svchost.exe |
Generic Host Process for Win32 Service
Added by the SPYBOT.NC WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
![]() |
SPSVC.EXE |
Generic Host Process for Win32 Services
Added by the SDBOT.DA WORM! |
![]() |
svchost32.exe |
Generic Host Process for Win32 Services
Added by the AGOBOT.ALH WORM! |
![]() |
svñhîst.exe |
Generic Host Process for Win32 Services
Added by the DLOADER.AK TROJAN! |
![]() |
scvhost2.exe |
Generic Host Process2 System Backup
Added by the RBOT-BAH WORM! |





