 |
Shania.vbs |
(Default)
Added by the SHANIA BACKDOOR! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank |
 |
spolsvr2.exe |
(Default)
Added by the EVILSOCK.10 TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank |
 |
Systrsy.exe |
(Default)
Added by the CDTRAY TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank |
 |
syspol.exe |
(Default)
Added by the DREMN-B TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank |
 |
SP00Lsv32.pif |
(L4r1$$4) (4nt1) (V1ruz)
Added by the ASSIRAL.B WORM! |
 |
secctr.exe |
*Security Center
Added by the SDBOT.BRO WORM! |
 |
statemgr.exe |
*StateMgr
Windows ME default for System Restore. Do NOT disable! |
 |
systemupd.exe |
*WindowsAudio
Added by the AGENT-TH WORM! |
 |
svhost.exe |
.mscsbl
Added by the CMQ TROJAN! |
 |
sysmon32.exe |
.NET config
?? |
 |
smss.exe |
.nvsvc
Added by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup! |
 |
smssb.exe |
.nvsvcb
Added by the BOXED.CG TROJAN! |
 |
services.exe |
.Prog
Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
 |
system32THotkey.exe |
00THotkey
For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev |
 |
svchost.scr |
1
Added by the BANCOS.X TROJAN! |
 |
sysockeu.exe |
1029BB4B-16A9-4E77-AA3D-96930BD68EEC
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
 |
sxgnsvuxct.exe |
1234klsjdc uiar924c af
Detected by McAfee as the FAKEALERT-AM TROJAN! See here |
 |
sysvtypkbjx.exe |
1234klsjdc uiar924c af
Detected by McAfee as the FAKEALERT-AM TROJAN! See here |
 |
stubinstaller****.exe [* = digit] |
180ClientStubInstall
180Solutions adware related |
 |
SpyAgent4.exe |
1Srv32
SpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC." |
 |
SpyBuddy.exe |
1Win32Cfg
SpyBuddy keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
sysokuaw.exe |
2177F056-0AA6-4D6C-A944-13F71F341C29
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
 |
slsorve.exe |
27
Added by the SLSORVE-A TROJAN! |
 |
svchost.exe |
333
Added by the JD-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This one is located in a "Syswm1i" directory |
 |
Ska.exe |
666
Added by the PIPES TROJAN! |
 |
sysoghcx.exe |
756349DC-6D9E-4F2A-9B24-269661F073C3
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
 |
sysodkcs.exe |
852EBF20-A95D-4F1F-B9C2-B2CD24350F3E
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
 |
sys.exe |
AAMSFree702
Added by the BACKDOOR-CPC TROJAN! |
 |
snddrv.exe |
Ac97Sound
Detected by Sophos as the SILLYFDC-A TROJAN! |
 |
schedhlp.exe |
Acronis Scheduler Helper
Part of Acronis True Image backup software. Co-operates with the "schedul2.exe" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images |
 |
schedhlp.exe |
Acronis Scheduler2 Service
Part of Acronis True Image - backup software. Co-operates with the "schedul2.exe" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images |
 |
systray32.exe |
ActiveDesktop
Added by the DABOOM WORM! |
 |
svcss.exe |
ActiveXUpdate
Added by a variant of the DEDLER.C TROJAN! |
 |
svchost.scr |
Administrator
Added by the NOVACAL TROJAN! |
 |
sysfile.vbs |
AdminSoft
Added by the STARGRUB-A WORM! |
 |
sysconfig.exe |
Adobe
Added by an unidentified WORM or TROJAN! |
 |
sysbat32.exe |
Adobe
Added by the LOWZONES.T TROJAN! |
 |
sysmsn.exe |
AdobeReaderPros
Added by the RBOT-BGH WORM! |
 |
services.exe |
AdRotator.Application
FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in an "Inetsrv" subfolder |
 |
stopAds.exe |
AdsBlocker
Reported as DILAER.DW by NOD32 |
 |
SystemtrayV100B.exe |
ADSLSYSTEMTRAY
Apparently Annex A ADSL modem related. What does it do and is it required? |
 |
sysupudt.exe |
AdUpdater
Unidentified adware downloader/updater |
 |
schedules.exe |
AdwareKiller_schedules
EAdwareKiller spyware remover - not recommended, see here |
 |
scchost.exe |
Alive SYstem
Added by the TOFDROP-B TROJAN! |
 |
scchostc.exe |
Alive SYstem
Added by the TOFDROP-B TROJAN! |
 |
stswin.exe |
All Aboard Status
All Aboard! Internet Connection Sharing status icon |
 |
svchost.exe |
alpha
Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
SecurityCenter.exe |
Aluria Security Center
Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here |
 |
SpyWareKiller.exe |
ANONYMIZER_SPYWAREKILLER
Anonymizer Spyware Killer - now Anti-Spyware |
 |
spamsvc.exe |
Anti Spam Service
Added by the MYTOB-BK WORM! |
 |
SVCHST32.EXE |
AntiClicker
Added by the CBH TROJAN! |
 |
scan.exe |
antispy
IE AntiVirus rogue security software - not recommended, see here |
 |
svchst.exe |
Antivir
Added by the RAGRUK-A TROJAN! |
 |
scvhost.exe |
AntiVir
Added by the AGENT-DSF TROJAN! |
 |
sysrtmvs.exe |
aouei
Chivio dialer |
 |
smsbvl32.exe |
ApplicationProtocolRun
Added by the IRCBOT-CX TROJAN! |
 |
simenu.exe |
apyginapygin
Added by the SDBOT.BTR WORM! |
 |
SocksA.exe |
ASocksrv
Added by the VB.CBW WORM! |
 |
servicos..exe |
ASP.NET State Service
Added by the DADOBRA-I TROJAN! |
 |
SAUpdate.exe |
ATTBroadbandUpdate
Big Brother from Quest Software. System and network monitor |
 |
SOUND.exe |
AUDIO
Added by the PLOYB-A TROJAN! |
 |
symcsvc.exe |
aupd
Added by the ABWIZ.D TROJAN! |
 |
sysvcs.exe |
aupd
Added by the ABWIZ.C TROJAN! |
 |
sywsvcs.exe |
aupd
Added by the ORSE-M TROJAN! |
 |
sa3dsrv.exe |
Aureal A3D Interactive Audio
For Aureal based 3D soundcards. A3D sound features won't work with this disabled |
 |
startauth.exe |
Auth Starter Ident
Added by the RBOT-WP WORM! |
 |
scricon.exe |
Auto File System Conversion Utility
Added by the SDBOT.EYB WORM! |
 |
svchost.exe |
Auto Update
Added by the DUMARDI-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
svchost.exe |
Auto Updates
Added by the CHEUKO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
SERVICES.EXE |
AutoAdministrator
Added by the PUNYA-A WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
 |
spooll.exe |
autoload
Detected by Symantec as the SILLYFDC WORM! See here |
 |
suchost.exe |
Automatic Microsoft Windows Updater
Added by the RBOT-EQ WORM! |
 |
sxs.exe |
autorun
Added by the SMALLVBS-A WORM! |
 |
smss.exe |
AutoUpdate
Added by a variant of the WINSPY.AA TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "debug64" subfolder of the Winnt or Windows folder |
 |
StartFX.exe |
AVFX Engine
Advanced Video FX - supported by a number of Creative Web Cameras. "Have more fun by adding a wide range of special effects and backgrounds to your video chat with Advanced Video FX" |
 |
svchost323.exe |
AvG
Added by the RBOT-ZA WORM! |
 |
serbw.exe |
avnort
Added by the SERFLOG.A WORM! |
 |
SCHSC9X.EXE |
AVSchedScan
Command Antivirus related |
 |
svosm.exe |
AvSer
Added by the SERFLOG.B WORM! |
 |
sysup.exe |
AvSer
Added by the SERFLOG.B WORM! |
 |
svchst32.exe |
bab
Added by the AGENT.Q TROJAN! |
 |
SYSMONMS.EXE |
bal
Added by the FAKEALERT TROJAN! |
 |
station.sbrt |
Bart Station
Related to PeoplePC ISP. May be a dialler for dial-up accounts? |
 |
secure2.bat |
Bat
Added by the ZCREW.C TROJAN! |
 |
skinkers.exe |
BBC News alerts
BBC News Desktop Alerts service - see here. Desktop alert and breaking news e-mail services let you find out about all the latest news as it happens |
 |
saqevre.exe |
Beawver
Added by a variant of the RANKY TROJAN! |
 |
svchost.exe |
beta
Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
 |
smnp.exe |
blah service
Added by the RBOT.IZ WORM! |
 |
syser.exe |
boler.exe
Added by the RBOT-AYS WORM! |
 |
syncit.exe |
BookMarkSink
Bookmark synchronization utility |
 |
syncit.exe |
BookMarkSync
Sync2IT BookMarkSync - "real-time automatic synchronization service that allows you to access your bookmarks, favorites and favorite files from any computer or any browser". Only installed with the users explicit permission and generally only remains running if the user decides to subscribe to the service. If it is no longer required it should be uninstalled to prevent a large number of clients 'checking in' to the server that have no chance of synchronizing |
 |
sync2it.exe |
BookMarkSync2It
Sync2IT BookMarkSync - "real-time automatic synchronization service that allows you to access your bookmarks, favorites and favorite files from any computer or any browser". Only installed with the users explicit permission and generally only remains running if the user decides to subscribe to the service. If it is no longer required it should be uninstalled to prevent a large number of clients 'checking in' to the server that have no chance of synchronizing |
 |
svchostt.exe |
Bot Loader
Added by the GAOBOT.ALV WORM! |
 |
servicecenter.exe |
Bredbandsbolaget
Related to the Brebband Swedish Broadband provider |
 |
sempalong.exe |
Bron-Spizaetus
Added by the BRONTOK-E WORM! |
 |
s_menu.exe |
browser
Added by the TACTSLAY.C TROJAN! |
 |
SVCH0ST.EXE |
BSVCHOST
Added by the VOXOM TROJAN! |
 |
services.exe |
BuildLab
Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
 |
SetupCmd.exe |
C:WINDOWSsystem32SetupCmd.exe
Detected by Kaspersky as the AGENT.AAW TROJAN! |
 |
sddriver.exe |
Call Function System32
Added by a variant of the SDBOT TROJAN! |
 |
svchost.exe |
CashToolbar
BrowserAid/CashToolbar adware! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup! |
 |
svcrhost.exe |
ccAppr
Added by the TACTSLAY.A TROJAN! |
 |
svcshost.exe |
ccAppr
Added by the TACTSLAY.A TROJAN! |
 |
services.exe |
ccApps
Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
 |
svcrhost.exe |
ccRegVfY
Added by the TACTSLAY.A TROJAN! |
 |
svcshost.exe |
ccRegVfY
Added by the TACTSLAY.A TROJAN! |
 |
stealth.exe |
CCWC7s
Moleculesoft Cache, Cookie & Windows Cleaner. No longer supported but available for free |
 |
svchost.exe |
CDriver
Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
 |
SafeSignCertReg.exe |
CertificateRegistration
SafeSign Certificate Registration Utility for Microsoft Crypto applications |
 |
server.exe |
CesarFTP FTP Server
CesarFTPd - FTP server |
 |
sfcmonit.exe |
cftmon
Added by a variant of the AGENT.ERG TROJAN! |
 |
SPMSMON.EXE |
ChangeICON
Card reader related program. Note - may cause problems with My Computer loading at startup. Disabling through MsConfig seems to solve the problem |
 |
sokscmpn.exe |
CHIPDRIVEPinManager
ChipDrive Smartcard software |
 |
SCMgr.exe |
CHIPDRIVESmartcardManager
ChipDrive Smartcard software |
 |
srv.exe |
Classes
"Switch" premium rate adult content dialler variant |
 |
srv2.exe |
Classes
"Switch" premium rate adult content dialler variant |
 |
service.exe |
Clean up
Added by the AGENT-FPY TROJAN! |
 |
smmss.exe |
Client Server Runtime Process
Backdoor TROJAN! Possible SDBOT-GEN variant |
 |
Sync.exe |
ClockSync
ClockSync - synchronizes your system clock with an internet time server. It's by WhenU, the makers of the Save Now spyware, and they're usually seen in tandem, so it's advised to replace it with one of may spyware free alternatives available |
 |
sed.exe |
CLSID
Adult content dialler |
 |
SmWizard.exe |
CM-SmWizard
SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required? |
 |
startupmon.exe |
cmonitor
SystemDoctor misleading security software - not recommended, see here |
 |
system.exe |
cmss
Added by a variant of the RBOT WORM! |
 |
Systray.exe |
Coldlife -icmp
Added by the FLOOD.AV TROJAN! Note - this is not the legitimate systray.exe process |
 |
suchost.exe |
COM++ System
Added by the LOVGATE-F WORM! |
 |
svchost.exe... |
COM++ System
Added by a variant of the LOVGATE WORM! |
 |
svdhost.exe |
COMDRV32
Orvell Monitoring 2003 surveillance software. Uninstall this software unless you put it there yourself. Note - asks for permission to contact the IP address of http://www.protectcom.com/ |
 |
system.exe |
Command
Added by the GATECRASH.A or GATECRASH.B TROJANS! |
 |
SCCENTER.EXE |
Compaq Computer Corp SCCenter Module
For Compaq PC's. Part of Backweb |
 |
silent.exe & matcli.exe |
Compaq Knowledge Center
"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file while silent.exe executes matcli.exe quietly in the background. Compaq Knowledge Center is required to run with the Help and Support program. If you uncheck Compaq Knowledge Center and and then run help and Support it will add another Compaq Knowledge Center in the startup menu. If you remove the Compaq Knowledge Center in the add/remove program some help menus in help and support will not be available like Fix my Presario, Preference, and Contact Technical Support". You decide |
 |
systeminfos.exe |
Compaq Service Drivers
Added by the SDBOT-XC WORM! |
 |
sounddr.exe |
Compaq Sound Drivers For WINDOWS
Added by the SDBOT-XG WORM! |
 |
SRP.exe |
ConfidentUser
ConfidentUser misleading security software - the site's "online scanner" detected by Kaspersky antivirus as WinFixer.ba |
 |
service.exe |
Config
Added by the ISRAZ.B WORM! |
 |
svchosl.exe |
Config Loader
Added by the GAOBOT.P WORM! |
 |
sysldr32.exe |
Config Loader
Added by the GAOBOT WORM! |
 |
scvhost.exe |
Config Loader
Added by the GAOBOT.AE or GAOBOT.AO WORMS! |
 |
svhost.exe |
Config Loader
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
syscfg32.exe |
Configuration Loader
Added by the SDBOT.B TROJAN! |
 |
service5.exe |
Configuration Loader
Added by the GAOBOT.AF WORM! |
 |
sycfg34.exe |
Configuration Loader
Added by the GAOBOT.AN WORM! |
 |
Service.exe |
Configuration Loader
Added by the GAOBOT.AO WORM! |
 |
Servicess.exe |
Configuration Loader
Added by the GAOBOT.AO WORM! |
 |
sw32.exe |
Configuration Loader
Added by the AGOBOT.BQ WORM! |
 |
System.exe |
Configuration Loader
Added by the GAOBOT.AO WORM! |
 |
sysinfo.exe |
Configuration Loader
Added by the GAOBOT.FQ WORM! |
 |
svhst.exe |
Configuration Loader
Added by the GAOBOT.YC WORM! |
 |
systemry.exe |
Configuration Loader
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
smss32.exe |
Configuration Loader
Added by the AGOBOT.MB WORM! |
 |
seru32.exe |
Configuration Loader
Added by the SDBOT-VR WORM! |
 |
smsai.exe |
Configuration Loader
Added by the SDBOT-YE WORM! |
 |
svupdate.exe |
Configuration Loader
Added by the RANDEX.DXP WORM! |
 |
scvhost.exe |
Configuration Loader
Added by the AGOBOT-AAE and SDBOT.AR WORMS! |
 |
svchost.exe |
Configuration Loader
Added by the PARADROP-A WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
 |
svchost2.exe |
Configuration Loader
Added by the AGOBOT.JR WORM! |
 |
svchost.exe |
Configuration Loader
Added by the PARADROP-AI WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup! |
 |
svschost.exe |
Configuration Loader
Added by the SDBOT-NS WORM! |
 |
svchos1.exe |
Configuration Loading
Added by the GAOBOT.DK WORM! |
 |
sewins.exe |
Configuration Servecie
Added by the SDBOT-COH WORM! |
 |
suchost.exe |
Configuration Service
Added by the TREB TROJAN! |
 |
sysconf16.exe |
ConfLoader
Added by the SDBOT-FB TROJAN! |
 |
SYS.EXE |
Connector
Nunci premium rate dialer |
 |
sms.EXE |
Connector
Added by the ExDial-B premium rate adult content dialer |
 |
smctrlw.exe |
control panel
System Tray icon for a Silicon Motion LynxEM based PCI Graphics Card |
 |
System.exe |
Control Panel
Added by the DANI TROJAN! |
 |
systemctrl.exe internet.dll, LoadNetworkProfile |
ControlPanel
Browser hijacker, also detected as STARTPA-FX |
 |
svcc.exe |
ControlPanel
WorldSearch adware - re-directing searches to "world-search.biz" |
 |
syscorehd.exe |
Core System Hardware
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
s_menu.exe |
cpl
Added by the TACTSLAY.C TROJAN! |
 |
simcss.exe |
cpntmgc
Added by the MAGICON.A TROJAN! |
 |
StartEAK.exe |
CPQEASYACC
Easy Access Button Support for Compaq PCs. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keys |
 |
STARTDRV.exe |
CPQEASYACC
For Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys |
 |
stutfix.exe |
CPQSTUTFIX
For Compaq PC's. Fixes audio stutter problems for ESS Maestro soundcards. You can download it here. This is a Compaq originated file and has been verified as free from viruses by McAfree/Norton |
 |
svchost32.exe |
CRC Value Verifier
Added by the RBOT-OA WORM! |
 |
stacture.exe |
Creates stractures for system management
Added by the SDBOT-DHS WORM! |
 |
starter.exe |
Creative PCI Audio Configuration Utility
System Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on this special page. Similar to EnsoniqMixer |
 |
scrnsave.pif |
Crnsava
Added by the SDBOT-ZV WORM! |
 |
spqmdmui.exe |
csaRem
Compaq modem country selection |
 |
softok.exe |
csoftok
Added by the QQPASS.G TROJAN! |
 |
ssms.exe |
csrss
Added by an unidentified malware |
 |
SCHWIZEX.EXE |
CSScheduleCheck
Part of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot |
 |
SVOHOST.exe |
ctfnom.exe
Added by the DIGIDOR-A TROJAN! |
 |
Screendragon_VS_Taskbar.exe |
cursor
ScreenDragon video player |
 |
sdservss.exe |
cvmsyslpd
Added by the MAILBOT-BY TROJAN! |
 |
showmode.exe |
Cyber Trio
From G-Tek Technologies. Allows you to set the PC in one of three modes, Standard, Enhanced and Kiddo. Standard is full function, Enhanced prevents accidental damage and Kiddo is a play environment for kids. Pre-installed on some Packard Bell PCs |
 |
SPUVolumeWatcher.exe |
Cyber-shot Viewer Media Check Tool
Part of the Sony Picture Uility software supplied with Sony Cybershot digital cameras. What does it do and is it required? |
 |
System.dat.vbs |
Data
Added by the BISCUIT.A WORM! |
 |
starter.exe |
dbar_starter
Deskbar adware - adds a search bar to your Windows taskbar which performs searches on www.w-w-w-dot-com.com |
 |
SVIQ.EXE |
dc2k5
Added by the COIDUNG-A WORM! |
 |
sprtcmd.exe /P ddoctorv2 |
ddoctorv2
Comcast Desktop Doctor (provided by SupportSoft, Inc) is a free self-help tool for Comcast broadband users. Identifies and automatically fixes typical problems that may occur with your high-speed internet service |
 |
svchost.exe |
DDriver
Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
 |
shell32.exe |
default
Added by the BINGHE TROJAN! |
 |
svchost.exe |
defragsys
Added by the BIFROSE-TH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
ShrCL.EXE |
DelayShred
McAfee Delay Shreder - not required at startup. You can use QuickClean manually via McAfee Security Center and run it from there |
 |
sprtcmd.exe /P DellSupportCenter |
DellSupportCenter
Dell Support Center (provided by SupportSoft, Inc) is a free self-help tool for Dell users. Identifies and automatically fixes typical problems that may occur with your high-speed internet service |
 |
smvss.exe |
devenv
Added by the DEDLER-G TROJAN! |
 |
smss.exe |
DHCP
Added by the WINSPY.AG TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
 |
services.exe |
DHCP32
Added by the WINSPY.AG TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
 |
sdchost.exe |
Direct settings
Added by the DAEMONI-I TROJAN! |
 |
Sqlexploit.exe |
directx
Added by the SDBOT.D TROJAN! |
 |
stdhost.exe |
DirectX Driver
Added by a variant of the RBOT WORM! See here |
 |
stdhost.exe |
DirectX Driver
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
Sservice.exe |
DirectX for Microsoft Windows
Added by the PRORAT TROJAN! |
 |
SECURITY.EXE |
Disk Keeper
Daosearch adware |
 |
Snt.exe |
Diskstart
Adult content dialler |
 |
svchoist.exe |
Dll Link
Added by the AUTOSKY WORM! |
 |
svchost.exe |
Dll Link
Added by the AUTOSKY WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Documents and Settings\Favourites folder |
 |
server.exe |
dreams
Added by a variant of the SDBOT WORM! |
 |
SysDrefIWv2.exe |
DrefIW
Added by the DREF-C WORM! |
 |
SysDref.exe |
DrefIW
Added by the DREF-D WORM! |
 |
Scam32.exe |
Driver32
Added by the SIRCAM WORM! |
 |
svchost.exe |
DriverCheck
Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a C:DriverLoad folder |
 |
svcmdx32.exe |
DriverDB
Added by the BERPI TROJAN! |
 |
svchost.exe |
DriverLoad
Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a C:DriverLoad folder |
 |
system32.exe |
DriverPath
Added by the PRORAT-S TROJAN! |
 |
SmartAgt.exe |
dRMON SmartAgent
Part of the network monitoring program group for 3Com NIC cards. See here for more info |
 |
stmhosts.exe |
drmsrv32
Added by the AGENT.AGWU TROJAN! |
 |
spdstrm.exe |
DSL Monitor
Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray |
 |
svosm.exe |
DsmSer
Added by the SERFLOG.B WORM! |
 |
sysup.exe |
DsmSer
Added by the SERFLOG.B WORM! |
 |
StartUpDualCoreCenter.exe |
DualCoreCenter
Unified control center for overclocking both the graphics card and the CPU, but for the program to have its full functionality you must have an MSI mainboard with a CoreCell chip |
 |
spoolc.exe |
dumprep
Detected by Kaspersky as a variant of the AGENT.CXF TROJAN! |
 |
support.exe |
DwlClient
Download manager for Dell support alerts |
 |
sys*.exe [* = random number] |
Dx
Added by the DEXTER.A WORM! |
 |
sys_alert.exe |
eanth_critical_update_alert
eAcceleration Stop-Sign security software related. Previously not recommended, see here |
 |
sys_alert.exe |
eanth_system_patcher
eAcceleration Stop-Sign security software related. Previously not recommended, see here |
 |
sbsetup.exe |
Eapcisetup
Rockwell RipTide soundcard application software. Sound works without it |
 |
Server.exe |
easyServ
Added by the EASYSERV TROJAN! |
 |
smproxy.exe |
ELNKProxy
Surfmonkey adware |
 |
surfboard.exe |
ENCSurf
?? |
 |
starter.exe |
EnsoniqMixer
Puts the Ensoniq mixer in system tray. From Ensoniq Technologies "Our mixer is a critical part of the soundcard as it fixes sound problems and replaces the MS mixer which can no longer be used". If you find you don't need it - try one of the solutions on this special page. Similar to Creative PCI Audio Configuration Utility |
 |
STMS.EXE |
EPSON Background Monitor
Supposed to keep an Epson printer ready for quick printing. Users report little difference whether it is on or not |
 |
SysRep.exe |
ErrClean
ErrClean misleading security software - not recommended, see here |
 |
svc.exe |
erthgdr
Added by the BEAGLE.BN or BEAGLE.BP WORM! |
 |
svc23.exe |
erthgdr2
Added by the BAGLE.CG WORM! |
 |
smrrs.exe |
Ethernet Drivers
Added by the RBOT-AAK WORM! |
 |
smschk.exe |
EventApplicationCmd
Added by the IRCBOT-AO TROJAN! |
 |
shellexpl.exe |
Explorer
Added by the SHELDOR TROJAN! |
 |
shellexp.exe |
Explorer
Added by a variant of the SHELDOR TROJAN! |
 |
sys.exe |
EXPLORER
Added by the SILLYFDC-A TROJAN! |
 |
svchost.exe |
F-Secure 2005
Added by the BIFROSE-CH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
svcnvt.exe |
Fast Home
Detected by Kaspersky as the DELF.KS TROJAN! This file may be found in the System folder on 9x machines, however as of this writing it has only been seen in the System32 folder |
 |
svcnv.exe |
Fast Search
Homepage, Startpage hijacker. Possible variant of Trojan-Downloader.Win32.Delf |
 |
svcnt.exe |
Fast start
Adware - detected by Kaspersky as a variant of the FAVADD TROJAN! |
 |
svcnut.exe |
FastStart
Browser hijacker - a variant of the STARTPAGE.L TROJAN! |
 |
svcnut32.exe |
FastStart
Browser hijacker - a variant of the STARTPAGE.L TROJAN! |
 |
SPEED UP.EXE |
FastTrack Accelerator
FastTrack Accelerator - "speedup" utility for programs that use the FastTrack network such as KaZaA Media Desktop, Grokster and Morpheus |
 |
sp2.exe |
Fdr Command Module
Added by the SDBOT.WP WORM! |
 |
SVCH0ST.EXE |
fegoze
Added by the GRAYBIRD.D VIRUS! Note - the filename has the digit 0 rather then the uppercase "o" |
 |
shdochp.exe |
FHPage
Added by the WINHOUND TROJAN! |
 |
shdocsvc.exe |
FHStart
Added by the WINHOUND TROJAN! |
 |
SyncService.exe |
FieldForms Sync
Resco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run, on a wide range of mobile devices. Supports Microsoft Access databases, and provides for synchronization of other data as well |
 |
shwizard.exe |
File-Sharing Wizard
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
ssmss.exe |
FireFox Service Drivers
Added by a variant of the SDBOT WORM! |
 |
SP2 UPDATE.exe |
Firewall
Added by the ELITPER.E WORM! |
 |
sys32.exe |
Firewall Controls
Added by the SDBOT-DGI WORM! |
 |
sys32Conf.exe |
Firewall Sp2 system
Added by the RBOT-ABT WORM! |
 |
samx.exe |
FireWire Driver
Added by the SDBOT.AE WORM! |
 |
services.exe |
Flash Media
Added by a variant of the IRCBOT TROJAN! See here. Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
 |
SDSTAT.EXE |
FlashPath Monitor
System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs |
 |
SDSTAT.EXE |
FlashPath Status
System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs |
 |
service.exe |
foxwudy9912
Added by the BANCOS-BT TROJAN! |
 |
stub_113_4_0_4_0.exe |
fqor
TargetSaver adware |
 |
svchost.exe |
France
Added by the MIMAIL.L WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
shdrkmck.exe |
frguk
?? |
 |
services.exe |
FriendlyTypeName
Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
 |
SELFCERT.EXE |
FriendlyWebQuick-Launch
selfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as well |
 |
StCenter.exe |
FRITZ!DSL Startcenter
FRITZ! ISP software "StartCenter" User interface that allows you to manage, tweak and diagnose many aspects of your internet connection - is it required? |
 |
svcnva.exe |
FSH
Malware, detected by Ewido Security Suite as TrojanDownloader.Delf.ks |
 |
svhost32.exe |
fzg
Added by the DLOADER.BDK TROJAN! |
 |
shit.exe |
game
Added by the Netclap Gold backdoor TROJAN! |
 |
svshost.exe |
Games Acceleration
EasySearch adware |
 |
svshost1.exe |
Games Acceleration
Added by the DLOADR-AWD TROJAN! |
 |
svchost.exe |
gamma
Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
 |
setgamma.exe |
GammaHotKeys
Part of the RadeonTweaker program for adjusting ATI Radeon graphics cards. Allows you to adjust the gamma (or brightness) when playing a full-screen game without switching back to the desktop |
 |
Systpl.exe |
Gate Personal Firewall
Added by the RBOT.ADC WORM |
 |
SpaceMan.exe |
GBSpaceMan
GreenBorder - secure your browsing activities on the internet |
 |
SVCHOSTS.EXE |
Generic host proccess for windows
Added by the SPYBOT-GQ WORM! |
 |
SCHOST.EXE |
Generic Host Process
Added by the RBOT-NC WORM! |
 |
svchost.exe |
Generic Host Process
Added by the DLOADER-NX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
svlhost.exe |
Generic Host Process for Win32 Service
Added by the WOOTBOT.EX WORM! |
 |
svchost.exe |
Generic Host Process for Win32 Service
Added by the SPYBOT.NC WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
SPSVC.EXE |
Generic Host Process for Win32 Services
Added by the SDBOT.DA WORM! |
 |
svchost32.exe |
Generic Host Process for Win32 Services
Added by the AGOBOT.ALH WORM! |
 |
sv?h?st.exe |
Generic Host Process for Win32 Services
Added by the DLOADER.AK TROJAN! |
 |
scvhost2.exe |
Generic Host Process2 System Backup
Added by the RBOT-BAH WORM! |
 |
scvhost326a.exe |
Generic Host Process326a System Backup
Added by a variant of the SDBOT WORM! |
 |
serv1ces.exe |
Generic Service Process
Added by the AGOBOT-JK WORM! |
 |
svghost.exe |
Genius Mose Driver
Added by a variant of the SPYBOT WORM! See here |
 |
sysoobe.exe |
Gestionnaire de disques universel
Added by the TOADER-A TROJAN! |
 |
smsiexec.exe |
GLSetT32
Added by the OPTIX-D TROJAN! |
 |
svchost.exe |
GNP Generic Host Process
Added by the ZAPCHAS TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
 |
svchost.exe |
GNP Generic Host Process
Added by the ZAPCHAS-R TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup and is always located in the System32 folder. This worm file is found in the System folder |
 |
svchost.exe |
GNP Generic Host Process
Added by the ZAPCHAS-AA TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This one replaces svchost.exe in the System32 folder with a copy of Mirc on (NT/2K/XP) systems and just adds svchost.exe to the System folder on (9x/Me) systems |
 |
services.exe |
Golum
Added by the GOLUM.A TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
 |
services.exe |
golumm
Added by the DLOADER-ET TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "golumm" subfolder |
 |
smss32.exe |
Graphic Driver
Added by a variant of the RBOT WORM! |
 |
skinkers.exe |
HalifaxHowardCluster
"Howard the Weatherman" desktop client from Halifax by Skinkers - marketing/messaging tool. Leave enabled if you want to receive messages |
 |
svchots.exe |
hdlfoe df98ndf
Added by a variant of the RBOT WORM! |
 |
svchost.exe |
hellfire
Added by the LEOX.D TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
shost.exe |
hellodolly
Added by the YODO WORM! |
 |
sweden.exe |
HELPER
AsdPlug premium rate adult content dialer variant |
 |
spoler.exe |
helpmanager
Added by the RANDEX.J WORM! |
 |
softhost.exe |
hErcUnes
Added by the GARROCH WORM! |
 |
SetupClickHere.EXE |
Highspeeddownloader
Homepage hijacker, redirecting to "turbo-search101.com" - see here |
 |
srhelper.exe |
Hitman Pro SurfRight Helper
Hitman Pro - a utility to start a number of Security Protection software. They can be started individualy |
 |
slvhosts.exe |
Hollaback
Added by the SDBOT.BMO WORM! |
 |
SchSvr.exe |
Home Theater SchSvr
WinScheduler is installed with Home Theater Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs |
 |
svchost.exe |
Host Process
Detected by Kaspersky as the AGENT.DGO TROJAN! See here. Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! The file is located in the Fonts directory |
 |
sachostx.exe |
HostSrv
Added by the LOOKSKY.H WORM! Drops multiple files in the System (9x/ME) or System32 (NT/2K/XP) folders |
 |
sachostx.exe |
HostSrv
Added by the LOOKSKY.A or LOOKSKY.F or LOOKSKY.G WORMS! |
 |
sachostx.exe... |
HostSrv
Added by the LOOKSKY.E WORM! |
 |
SK9910DM.exe |
Hot Key Kbd 2690 Daemon
Multimedia keyboard manager - required if you use any special keys |
 |
SK9910DM.exe |
Hot Key Keybd 9910 Daemon
Multimedia keyboard manager - required if you use any special keys |
 |
svdhost32.exe |
Hotfix Updat
Added by the GAOBOT.ZW WORM! |
 |
ShadowBar.exe |
hp center UI
User Interface for HP Center - see here |
 |
SURFBRD.EXE |
HP Internet Center
Loads the HP Internet center surfboard on startup. HP Internet Center allows you to customize the multimedia keys on the fly without having to go the Control Panel --> Keyboards to change them |
 |
SetConfig.exe |
HPLJ Config
Connects system to networked HP printer. |
 |
scannerfb.exe |
hpScannerFirstBoot
HP scanner related |
 |
sexgame.exe |
hsim
Unidentified malware |
 |
s_menu.exe |
httpd
Added by the TACTSLAY.C TROJAN! |
 |
system_wc.exe |
Hwp
Eziin adware |
 |
svchost.exe |
I just want to say I love Milko and I need a drink
Added by the CHIKO WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Documents and SettingsAdministratorLocal SettingsApplication Data folder |
 |
svcnet.exe |
I/O Controllers
Added by the TIBIK-B TROJAN! |
 |
scvhost.exe |
icq lite
Added by the AGENT-DSF TROJAN! |
 |
Service32.exe |
ICU-Sucker
Added by the ILLNOTIFIER.D TROJAN! |
 |
spvic.exe |
IC_KEY_3
Instant Chess related |
 |
ssmss.exe |
IE6
Added by the GAOBOT.DXO WORM! |
 |
surfya.exe |
IEACCESS
IEAccess premium rate adult content dialer variant |
 |
syslaunch.exe |
Iehelper
Outwar adware downloader |
 |
svshosts.exe |
IExploer
Added by the IRCBOT.BT TROJAN! |
 |
systems.exe |
IISADMINS
Added by the AGOBOT.U WORM! |
 |
Systemwiper.exe |
iIWiper
System Wiper from iI Software - allows you to clear the history of your activites from you computer. Run manually on a regular basis |
 |
sysvn.exe |
Image Remote Players
Added by a variant of the IRCBOT BACKDOOR! |
 |
SonyTray.exe |
Image Transfer
Sony Image Transfer software provides direct image transfer from your digital camera to a PC - can be started manually |
 |
Svhosl.exe |
IMClass
Added by an unidentified WORM or TROJAN! |
 |
svchosts.exe |
ine
Added by the RBOT.BNL WORM! |
 |
sifxinst.exe |
Install Pending Files
Uninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see here. Is it required? |
 |
SETUP.EXE |
InstallNAIProduct
Could be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error? |
 |
svehost.exe |
Intel system tool
Added by the AGENT-EBT TROJAN! |
 |
smss.exe |
InteliSys
Advertisingvision adware! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
sysintmemory.exe |
Internal Memory File
Added by the RBOT-GKT WORM! |
 |
systray.exe |
Internat
Added by the ALADINZ.P TROJAN! Note - this is not the legitimate systray.exe process. If you right-click on the real systray.exe the "Properties" reveal it to be a Microsoft file |
 |
smss.exe |
internet
Added by the MIFENG-K TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup! |
 |
svchosts.exe |
Internet Config
Added by the SDBOT TROJAN! |
 |
stisvsq.exe |
Internet Connection Wizard
EasySearch adware |
 |
stisvsq1.exe |
Internet Connection Wizard
Added by the DLOADR-AWD TROJAN! |
 |
syscfg32.exe |
internet service
Added by the RBOT-QS WORM! |
 |
ssvhost.exe |
internet service
Added by a variant of the RBOT WORM! |
 |
svho0st98.exe |
internet service
Added by the RBOT.EAT WORM! |
 |
systemdev.exe |
Internet Services
Added by the SDBOT-PW WORM! |
 |
story.exe |
Internet Suspention
Added by the WOOTBOT.HV WORM! |
 |
Sweeper.exe |
Internet Sweeper
Internet Sweeper - removes unnecessart left over files after browsing the internet |
 |
SchSvr.exe |
Intervideo WinScheduler
WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs |
 |
SYS32CFG.EXE |
intranet
Added by the SPYBOT-DW WORM! |
 |
schost.exe |
Intranet
Detected by Kaspersky as the RBOT.SV BACKDOOR! See here |
 |
SPLASHA.EXE |
Introducing Media Manager
MS Media Manager tour. Not required |
 |
SMUtilityBar.exe |
iolo Utility Bar
Iolo System Mechanic Utility Bar - can be launched manually |
 |
system32.exe |
ioroxxo microsoft sux
Added by a variant of the RBOT WORM! |
 |
svcxnv32.exe |
IPConfig
Added by the HACARMY.E TROJAN! |
 |
svcxnw32.exe |
IPConfig
Added by a variant of the HACARMY.E TROJAN! |
 |
sessionmgr.exe |
irc session
Added by the SDBOT-ACE WORM! |
 |
slipgui.exe |
ISP.COM High Speed
User interface for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet, Wanadoo, Terra, OnSpeed, United Online and AOL Canada. Required if the user's account is locked in to that proxy server |
 |
system.exe |
java
Added by a variant of the IRCBOT BACKDOOR! |
 |
svchqs.exe |
jiahus
Added by the WOWPWS-AL TROJAN! |
 |
srvd.exe |
johkjh
Added by a variant of the SLAPER TROJAN! |
 |
srrvc.exe |
john315
Added by a variant of the MAILBOT-BI TROJAN! |
 |
srvc.exe |
johnj315
Added by variant of the MAILBOT-BI TROJAN! |
 |
srvcc.exe |
johnj3155
Added by variant of the MAILBOT-BI TROJAN! |
 |
srvdc.exe |
johnj3cd
Added by a variant of the SLAPER TROJAN! |
 |
svhost.exe |
Jufualt
Added by the SDBOT-ADJ WORM! |
 |
severe.exe |
jusodl
Added by the QQPASS.48436 TROJAN! |
 |
svchost.exe |
KAVPersonal
Added by the LINEAGE-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
services.exe |
Kernel
Added by the FOOZ-A TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
SKERNEL32.com |
KERNEL 32
Added by the SEMAPI-A WORM |
 |
smss.exe |
Kernel Safe Mode
Added by the 78CRACK-A TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
service32.exe |
Kernel Services
Added by the PRX-B TROJAN! |
 |
svchosts.exe |
Kernel32
Added by an unidentified WORM or TROJAN! |
 |
sys****.exe [* = digit] |
KernelCheck
Added by an unidentified TROJAN! |
 |
sms.exe |
KernelFaultChk
Added by the DEADHAT WORM! Do not confuse with the valid "kernelfaultcheck" which runs "dumprep 0 -k" or "dumprep 0 -u" |
 |
systems.exe |
Kernell
Added by the TARNO.C TROJAN! |
 |
smss.exe |
KernellApps32
Added by the BANCBAN-AN TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup! |
 |
sysxp.exe |
key
Added by the BEAGLE.AB WORM! |
 |
sys_xp.exe |
key
Added by the BEAGLE.AC WORM! |
 |
serve.exe |
Key2
?? |
 |
shwicon.exe |
KYE_Showicon
Card reader for memory cards from digital cameras. Is it required? |
 |
srvany32.exe |
Live update monitor
Added by the AGOBOT.AFM WORM! |
 |
smss.exe |
LiveUpdate
Added by the VB.BAU TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "isas" subfolder of the Winnt or Windows folder |
 |
services.exe |
LiveUpdate32
Added by the VB.BAU TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "isas" subfolder of the Winnt or Windows folder |
 |
svhost32.exe |
load
Added by the WOWCRAFT TROJAN! |
 |
svchsot.exe |
load
Added by the GWGHOST-O TROJAN! |
 |
SvHost.exe |
Load Service
Added by the PESIN-D WORM! |
 |
swchost.exe |
load32
Added by the TURTA.A WORM! |
 |
shambl3r.exe |
load=
Added by the REMABL WORM! |
 |
Spoolsv.exe |
load=
Added by the CIADOOR.B TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir% |
 |
svhost32.exe |
load=
Added by the LINEAGE-AB TROJAN! |
 |
sys*****.exe [***** = random digit] |
loader32
Added by the DOMCOM TROJAN! |
 |
smss32.exe |
loadMefs
Added by the FLOOD-EL TROJAN! |
 |
suploads.exe |
loads.exe
Added by the AGENT-BZ TROJAN! |
 |
srvc32.exe |
Local runole service
Added by the SMALL-DP TROJAN! |
 |
services.exe |
Local Service
Added by the P2PWORM-T WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "Cursors" subfolder of the Windows or Winnt folder |
 |
svchost.exe |
LocalSystem
EHU adware. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
 |
Soundcane.exe |
Logitech Camera
Added by the SDBOT.MUC WORM! |
 |
Setpoint.exe |
Logitech SetPoint
Logitech SetPoint Event Manager for their range of mice and keyboards. Required if you want to use the advanced features of these devices and is located in the LogitechSetpoint sub-folder of Program Files |
 |
smartctr.exe |
Lotus QuickStart
Lotus central application, called SmartCenter, which runs on the Windows desktop. SmartCenter toolbar stretches across the top or, optionally, the bottom of the screen. Uses a lot of resources. Available via Start -> Programs |
 |
suitest.exe |
Lotus SuiteStart
Puts the individual Lotus components in the system tray taskbar when you start Windows. Can be disabled via MSCONFIG -> Startup as "Lotus SuiteStart 97 Edition". All individual components available via Start -> Programs |
 |
start.bat |
lsass
Added by the ZCREW TROJAN! |
 |
Sygate.exe |
LsasS
Added by the SDBOT.BCA WORM! |
 |
SVCHOST32.exe |
LTM2
Added by the LITMUS.203B TROJAN! |
 |
SVCHOST?.exe |
LTM2
Added by the DROPPERFL.A TROJAN! |
 |
Shell32.exe |
LTSMSG
Added by the LEMIR.B TROJAN! |
 |
serbw.exe |
ltwob
Added by the SERFLOG.A WORM! |
 |
systemconfig.exe |
M1cr0s0ft S3rcurity
Added by the RBOT.BKB WORM! |
 |
scvhost.exe |
Macromedia Flash Update
Added by a variant of the RBOT WORM! |
 |
svcmfte32.exe |
MainStart
Added by the STINX-A TROJAN! |
 |
SDKrepair2.exe |
Mascro soft SDK updates2
Added by the SDBOT.BXM WORM! |
 |
svcghost.exe |
Master
Added by the IRCBOT.RB TROJAN! |
 |
scorti.exe |
MCX Updte
Added by the RBOT-ARP WORM! |
 |
service.exe |
MDNS
Detected by Symantec as a variant of the Mirar adware |
 |
smss.exe |
MDSA Sentinel X
SentinelX spyware. Note - SentinelX is spyware that logs keystrokes. It also monitors and records Web sites visited and applications used. The risk can capture periodic screen shots and may be configured so as to block access to specific Web sites and chat rooms, must be manually installed. Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "MDSA Software" subfolder of the Program Files folder |
 |
Sysdll.exe |
Media Player
Added by the BANKER-BR TROJAN! |
 |
Sysnet.exe |
Media Player
Added by the BANKER.MW WORM! |
 |
SYSTEM64.EXE |
Media service
Added by the RBOT.QV WORM! |
 |
sscs.exe |
Media Software UPdater
Added by the RBOT-ABE WORM! |
 |
Sethook.exe |
MediaFace Integration
Fellowes Neato? cd label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar" |
 |
stub.exe |
media_stub
Mini-Player, IMESH related foistware |
 |
sprtcmd.exe /P MEDIC |
MEDIC
Self-help support tool for an unidentified high-speed internet provider (provided by SupportSoft, Inc). Identifies and automatically fixes typical problems that may occur with your high-speed internet service |
 |
SetupIE.com |
MemConfig
Added by the TAPLAK WORM! |
 |
StartMessager.exe |
MessagerStarter Freeserve
Freeserve Messenger |
 |
s_menu.exe |
Messanger
Added by the TACTSLAY.C TROJAN! |
 |
SCANMSG.EXE |
Messenger
AntiVirus Quick Heal - virus protection |
 |
svshost.exe |
Messenger Service Updater
Added by the MYTOB.GC WORM! |
 |
scorti.exe |
Mi7sft sdce
Added by the RBOT.ELC WORM! |
 |
svshosts.exe |
Micosoft Data Core stuff
Added by the RBOT.FZA WORM! |
 |
soundblaster.exe |
Micr Update
Added by the SDBOT.NP WORM! |
 |
svchost32.exe |
Micr0s0ft Upd4t4z
Added by the RBOT.ALF WORM! |
 |
spoolsal.exe |
Micrcoft Exploerer
Added by the RBOT-AKK WORM! |
 |
svchose.exe |
Micrcoft Exploerer
Added by the RBOT-ASL WORM! |
 |
spoolsae.exe |
Micrcoft Updat
Added by the RBOT-AIB WORM! |
 |
spoolsaex.exe |
Micrcoft Updat
Added by the RBOT-AJM WORM! |
 |
scrc32.exe |
Micro CRC Protocol
Added by a variant of the SDBOT WORM! |
 |
Smoked.exe |
MicroedSoft Toolbar
Added by the RBOT-ALN WORM! |
 |
spoolsac.exe |
Microft Exploerer
Added by the RBOT-AMD WORM! |
 |
sarvice.exe |
Microsft Updtes
Added by a variant of the SDBOT WORM! |
 |
svhost32.exe |
Microsof Windows Host
Added by the RBOT.ADY WORM! |
 |
system32.exe |
Microsofot x386 System Monitor
Added by the WOOTBOT.M WORM! |
 |
schost.exe |
Microsoft
Detected by Kaspersky as the RBOT.FEH BACKDOOR! See here |
 |
soundvol32.exe |
Microsoft
Detected by Kaspersky as the RBOT.CIJ BACKDOOR! See here |
 |
sqlservice.exe |
Microsoft
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
svhost.exe |
Microsoft
Added by a variant of the IRCBOT BACKDOOR! |
 |
svchost.exe |
microsoft
Added by the ASTEF or RESPAN WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
 |
svchost.exe |
Microsoft
Added by the ADUYO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
ssmss.exe |
Microsoft
Added by the RBOT-FZF WORM! |
 |
svchost.exe |
Microsoft (R) Windows Configuration Backup Service
Added by the RANKY.X TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in either a "config", "mapping" or "security" subfolder of the Winnt or Windows folder |
 |
sp2vc.exe |
Microsoft (R) Windows Network Latency Controller
Added by a generic password stealer TROJAN - see here |
 |
services.exe |
Microsoft (R) Windows Protected Content Restoration Service
Added by the AGENT.AGV TROJAN! |
 |
services.exe |
Microsoft (R) Windows TCP/IP Socket Layer
Added by the RBOT.ARM WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\winsock |
 |
svch0st.exe |
Microsoft Agent
Added by the VB-DRO WORM! |
 |
svhost.exe |
Microsoft AutoUpdater
Added by the RBOT.QG WORM! |
 |
spoolsrv.exe |
Microsoft Client Pc
Added by the RBOT-AQM WORM! |
 |
sysconf.exe |
Microsoft Conf Ldr
Added by a variant of the SDBOT TROJAN! |
 |
sqlcer.exe |
Microsoft Corp SQL Certificates
Added by the ZYBOT-C WORM! |
 |
sqlhandler.exe |
Microsoft Corporaticn SQL Handler
Added by a variant of the RBOT WORM! |
 |
svhhost.exe |
Microsoft Critical Services
Added by the AGOBOT-AJA WORM! |
 |
svcswin.exe |
Microsoft Device Manager
Added by the IRCBOT-YH TROJAN! |
 |
Spoolserv.exe |
Microsoft DirectX
Added by the DINFOR WORM! |
 |
scansdisk.exe |
Microsoft Disk Scanner
Added by the WOOTBOT.DT WORM! |
 |
SystemDll.exe |
Microsoft DLL Extensions
Added by the RBOT-ADV WORM! |
 |
svcdllhst.exe |
Microsoft DLL Host Service
Added by the AGENT.EAK TROJAN! |
 |
svchost.exe |
Microsoft dll Host Service
Detected by Kaspersky as the RBOT.BMS WORM! See here. Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
 |
servicedll.exe |
Microsoft DLL Service
Detected by Trend Micro as the RCBOT.OX TROJAN! See here |
 |
svcdll.exe |
Microsoft DLL Service
Added by a variant of the SPYBOT WORM! |
 |
svapache.exe |
Microsoft Explorer
Added by the RBOT-VR WORM! |
 |
system.exe |
Microsoft Explorer2
Added by the IRCBOT.BS TROJAN! |
 |
svchost.exe |
Microsoft Genetic Procress
Added by a variant of the SDBOT WORM! |
 |
svchost.exe |
Microsoft Genuine Logon
Added by the SDBOT.EXT WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
svh0st.exe |
Microsoft Help
Added by a variant of the SPYBOT WORM! |
 |
svhost.exe |
Microsoft Host Protocol
Added by a variant of the RBOT WORM! |
 |
syshost.exe |
Microsoft IIS
Added by the FRANCETTE WORM! |
 |
speedkey.exe |
Microsoft Intellitype Pro
Additional keyboard shortcuts on MS programmable keyboard |
 |
smbvhost.exe |
Microsoft Internel Corporat
Added by a variant of the IRCBOT BACKDOOR! |
 |
svzhost.exe |
Microsoft Internet Explorer
Added by a variant of the RBOT WORM! |
 |
sysini.exe |
Microsoft Internet Explorer
Added by the DELF-LN TROJAN! |
 |
svchost.exe |
Microsoft Internet Explorer
Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "drivers" subfolder |
 |
Smss32.exe |
Microsoft Internet Services
Added by the RBOT.MS WORM! |
 |
Soundsyst.exe |
Microsoft Intrenet Explorer
Added by the RBOT-AQU WORM! |
 |
system.exe |
Microsoft IPC
Added by the NULLBOT TROJAN! |
 |
svshost.exe |
Microsoft IPC
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
svchsst.exe |
Microsoft IT Update
Added by the RBOT-DH WORM! |
 |
Syst3m32.exe |
MicroSoft Legal Syst3m32
Detected by PCTools as the RBOT.UYL WORM! See here |
 |
scvhost32.exe |
Microsoft LSASS386 Protocol
Added by a variant of the SPYBOT WORM! |
 |
svchost.exe |
Microsoft machine
Detected by Kaspersky as the RBOT.AEU TROJAN! See here. Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
 |
sychost.exe |
Microsoft Manage Services
Detected by Trend Micro as the SLENFBOT.AD WORM! See here |
 |
schost.exe |
Microsoft Manage Services
Detected by PCTools as the SLENFBOT.B WORM! See here |
 |
SpoolSvc.exe |
Microsoft MSUPDATE
Added by the SXTB-A TROJAN! |
 |
svc0host.exe |
Microsoft Network Host
Added by the SDBOT-AEN WORM! |
 |
svxhost.exe |
Microsoft Office
Added by a variant of the RBOT WORM! |
 |
scvhvst.exe |
Microsoft Office Studio
Added by the RANDEX.CST WORM! |
 |
svchst.exe |
Microsoft Outlook Express Protocol
Added by a variant of the RBOT WORM! |
 |
sfrcdlg32.exe |
Microsoft PC Health Remote Assistance File Open & Save controls
Added by the RBOT-AVY WORM! |
 |
sysconf32.exe |
Microsoft RDLL
Added by a variant of the SDBOT TROJAN! |
 |
systen.exe |
Microsoft Redirect
Added by the BANCOS-FO TROJAN! |
 |
svchostt.exe |
Microsoft Registro
Added by the BANCOS-DH TROJAN! |
 |
scrgrd.exe |
Microsoft Restore
Added by the SPYBOT.BR WORM! |
 |
safemode.exe |
Microsoft Safe Mode Manager
Detected by Trend Micro as the IRCBOT.HM TROJAN! See here |
 |
scvhost32.exe |
Microsoft SCVHOST32 Protocol
Added by a variant of the RBOT WORM! |
 |
sdktemp.exe |
Microsoft sdk temp
Added by the RBOT-ANP WORM! |
 |
securitychk.exe |
Microsoft Secure Messenger.NET Service
Added by the SDBOT.VT WORM! |
 |
savservices.exe |
Microsoft Security Center
Added by the RBOT-ANU WORM! |
 |
sp2fix.exe |
Microsoft Security Management
Added by the RBOT.UB WORM! |
 |
service.exe |
Microsoft Security Monitor Process
Detected by PCTools as the DELF.BERW BACKDOOR! See here |
 |
svcchost.exe |
Microsoft Security Monitor Process
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
security32.exe |
Microsoft Security Update
Added by the DELF-JJ TROJAN! |
 |
Sound.exe |
Microsoft Server Application
Added by the RBOT-NE WORM! |
 |
svhst32.exe |
Microsoft Server Process
Added by the BCKDR-QHR TROJAN! |
 |
sysddm32.exe |
Microsoft Service 32
Detected by Kaspersky as the SDBOT.AKC TROJAN! See here |
 |
sboot.exe |
Microsoft Service Boot
Added by a variant of the IRCBOT TROJAN! |
 |
services.exe |
Microsoft Service Controller
Added by the KALEL-D WORM! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
 |
System.exe |
Microsoft Service Drivers
Added by a variant of the RBOT WORM! |
 |
svchost.exe |
Microsoft Service Host Process
Added by the KRYNOS.B WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "Help" subfolder of the Winnt or Windows folder |
 |
service32.exe |
Microsoft Service Manager
Added by a variant of the RBOT WORM! See here |
 |
svchost2.exe |
Microsoft Service Pack2.1
Added by a variant of the RBOT WORM! |
 |
services.exe |
Microsoft Services
Added by the ALETS TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
svshost.exe |
Microsoft Services
Added by the ALETS.B TROJAN! |
 |
Smss32.exe |
Microsoft Services
Added by the RBOT-AD WORM! |
 |
svssshost.exe |
Microsoft Services
Added by a variant of the RBOT WORM! |
 |
servicemgrz.exe |
Microsoft Servicez Manager
Added by the RBOT-ASN WORM! |
 |
smss.exe |
Microsoft Session Manager Subsystem
Added by the KALEL-D WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup! |
 |
SWTRAY.EXE |
Microsoft Sidewinder Game Controller Software
MS SideWinder game controller system tray icon. Available via Start -> Programs |
 |
sysinfo33.exe |
Microsoft Software
Added by the RBOT.LS WORM! |
 |
sound32.exe |
Microsoft Sound Driver
Added by a variant of the SPYBOT WORM! |
 |
soundman.exe |
Microsoft Sounds
Added by the RBOT-GCI WORM! |
 |
spool**.exe |
Microsoft Spool ** Service
Added by a variant of the IRCBOT TROJAN - where ** represents a 2 digit number |
 |
spoolsrv.exe |
Microsoft Spool Server for Win32
Added by the RANDEX.H WORM! |
 |
spoolsvc32.exe |
Microsoft Spool Svc
Added by a variant of the IRCBOT BACKDOOR! |
 |
Spoolsv.exe |
Microsoft Spooler Services
Added by a variant of the SPYBOT WORM! See here |
 |
SADASDA.exe |
MicroSoft ssas3s1
Detected by PCTools as the RBOT.URF WORM! See here |
 |
ssisvri.exe |
Microsoft SSISVRI32 Protocol
Added by a variant of the SPYBOT WORM! |
 |
sum32.exe |
Microsoft Sum32
Added by the RBOT-YW WORM! |
 |
sys32ms.exe |
Microsoft Support
Added by the RBOT-AHI WORM! |
 |
svchostt.exe |
microsoft support
Added by the AGOBOT.AWN WORM! |
 |
slhost.exe |
Microsoft Synchronization Manager
Added by the SDBOT.YH WORM! |
 |
svhost.exe |
Microsoft Synchronization Manager
Added by the SDBOT-PY WORM! |
 |
svchosts.exe |
Microsoft Synchronization Manager
Added by the SDBOT-LM WORM! |
 |
svxhost.exe |
Microsoft Synchronization Manager
Added by the SDBOT-ZU WORM! |
 |
screen.exe |
Microsoft Synchronization Manager
Added by the SDBOT-ACO WORM! |
 |
sysmsgr32.exe |
MicroSoft sys32
Added by a variant of the SPYBOT WORM! See here |
 |
sys.exe |
Microsoft System
Added by the RBOT.AKI WORM! |
 |
system.exe |
Microsoft System Administration
Added by a variant of the IRCBOT BACKDOOR! |
 |
sysmgr.exe |
Microsoft System Checkup
Added by the SDBOT-OO TROJAN! |
 |
services32.exe |
Microsoft System Debug
Added by the RBOT.AKH WORM! |
 |
svchots.exe |
Microsoft System File
Added by the RBOT.BYU WORM! |
 |
system.exe |
Microsoft System Monitor
Detected by PCTools as the IRCBOT.AUT TROJAN! See here |
 |
svhost.exe |
Microsoft System NT
Added by the SDBOT.COU WORM! |
 |
sysupdate.exe |
Microsoft System Update
Added by the SDBOT.DG WORM! |
 |
sys57.exe |
Microsoft system Value
Added by a variant of the RBOT WORM! |
 |
svchost32.exe |
Microsoft TCP/IP Connection Monitor
Added by the RBOT.KS WORM! |
 |
svcchost.exe |
Microsoft Telecoms Center
Added by a variant of the RBOT WORM! |
 |
Smss32.exe |
Microsoft Update
Added by the RBOT.CB WORM! |
 |
sys32cfg.exe |
Microsoft Update
Added by the RBOT.DR WORM! |
 |
systemi32.exe |
Microsoft Update
Added by a variant of the SPYBOT WORM! |
 |
snlogsvc.exe |
Microsoft Update
Added by a variant of the RBOT WORM! |
 |
svhost.exe |
Microsoft Update
Added by the RBOT-PI WORM! |
 |
sghost.exe |
Microsoft Update
Added by the SDBOT.AKV WORM! |
 |
scvhost.exe |
Microsoft Update
Added by the RBOT-AEM WORM! |
 |
svghost.exe |
Microsoft Update
Added by the RBOT.BUJ WORM! |
 |
sys.exe |
Microsoft Update
Added by the RBOT-AJ WORM! |
 |
svzhost.exe |
Microsoft Update
Added by the RBOT.OX WORM! |
 |
system32.exe |
Microsoft Update
Added by the RBOT.IS WORM! |
 |
Sygate.exe |
Microsoft Update
Added by a variant of the SDBOT WORM! |
 |
spool.exe |
Microsoft Update
Added by the AGENT-GJC TROJAN! |
 |
SetPoints.exe |
Microsoft Update
Added by a variant of the IRCBOT BACKDOOR! |
 |
system.exe |
Microsoft Update
Detected by Kaspersky as a variant of the RBOT BACKDOOR! See here |
 |
service.exe |
Microsoft Update
Added by a variant of the RBOT WORM! See here |
 |
spoolvs.exe |
Microsoft Update 23
Added by a variant of the RBOT WORM! |
 |
servic.exe |
Microsoft Update 32
Added by the RBOT-AXN WORM! |
 |
schvost.exe |
Microsoft Update 64 BIT
Added by the RBOT.CAU WORM! |
 |
system03.exe |
Microsoft Update Machine
Added by the RBOT-NM WORM! |
 |
systemll.exe |
Microsoft Update Machine
Added by the RBOT-JT WORM! |
 |
svshost.exe |
Microsoft Update Machine
Added by the RBOT.AK WORM! |
 |
scvhost.exe |
Microsoft Update Machine
Added by the RBOT-GS WORM! |
 |
servicez.exe |
Microsoft Update Machine
Added by the SPYBOT.BI WORM! |
 |
spoolserv.exe |
Microsoft Update Machine
Added by a variant of the RBOT WORM! |
 |
Systemnt.exe |
Microsoft Update Machine
Added by the RBOT.DA WORM! |
 |
systemse.exe |
Microsoft Update Machine
Added by the RBOT-BD WORM! |
 |
system.exe |
Microsoft Update Machine
Added by a variant of the RBOT WORM! |
 |
serviz.exe |
Microsoft Update Machine
Added by a variant of the RBOT WORM! |
 |
syadpo.exe |
Microsoft Update Machine
Detected by Kaspersky as the CIADOOR.GN BACKDOOR! See here |
 |
systemi.exe |
Microsoft Update Machine
Detected by McAfee as the PUSHBOT.A WORM! See here |
 |
servicz.exe |
Microsoft Update Machine
Added by the RBOT-HU WORM! |
 |
SP2.exe |
Microsoft Update Machine
Added by the SPYBOT.FP WORM! |
 |
svshost.exe |
Microsoft Update Manager
Added by a variant of the RBOT WORM! |
 |
scvhost.exe |
Microsoft Update Manager
Added by the AGOBOT.AXJ WORM! |
 |
scvideo.exe |
Microsoft Update Manager
Added by the SDBOT-CVP TROJAN! |
 |
systemm.exe |
Microsoft update service
Added by a variant of the SDBOT WORM! |
 |
svhost.exe |
Microsoft Updater
Detected by Kaspersky as the AGENT.CDF TROJAN! See here |
 |
sysconfigs.exe |
Microsoft Updaters
Added by the RBOT-DF TROJAN! |
 |
systemc32.exe |
Microsoft Updates
Added by the RBOT-GR WORM! |
 |
svehost.exe |
Microsoft Updates
Added by the RBOT-GRW WORM! |
 |
svshost.exe |
Microsoft Updates
Added by the AGOBOT-AIW WORM! |
 |
svdhost.exe |
Microsoft Updates
Added by the RBOT-GVH WORM! |
 |
service.exe |
Microsoft Updates
Detected by Kaspersky as the POISON.HPT BACKDOOR! See here |
 |
sp3fixer.exe |
Microsoft Updates 5 USB
Added by the RBOT-ADS WORM! |
 |
syswr.exe |
Microsoft Updating
Added by a variant of the RBOT WORM! |
 |
sysc0de.exe |
Microsoft Updating Machine
Added by the RBOT.RB WORM! |
 |
sysuptime.exe |
Microsoft uptime Service
Added by the RBOT-ACG WORM! |
 |
sycuptime.exe |
Microsoft uptime Service
Added by the RBOT-AHY WORM! |
 |
sms.exe |
Microsoft Virual Machine
Added by the RBOT-SP WORM! |
 |
services.exe |
Microsoft Visual SourceSafe
Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
 |
svctrl.exe |
Microsoft Webserver
Personal web server program which enables you to create and host a web server from your computer. Not required for most people |
 |
system12.exe |
Microsoft Windows 128bit Subsystem
Added by the RANCK-CZ TROJAN! |
 |
spvsper.exe |
Microsoft Windows Security
Added by a variant of the SDBOT WORM! |
 |
ssvvcchhoosst.exe |
Microsoft Windows Services Edt
Added by the RBOT-FYF TROJAN! |
 |
smss.exe |
Microsoft Windows Session Manager Subsystem
Added by the PROXYSER-R TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
svghost.exe |
Microsoft Windows Sound
Added by a variant of the SPYBOT WORM! See here |
 |
svshost.exe |
Microsoft Windows Sound
Detected by Kaspersky as the RBOT.ME BACKDOOR! See here |
 |
svuhost.exe |
Microsoft Windows Sound
Detected by PCTools as the KOLAB.XC WORM! See here |
 |
srwhost.exe |
Microsoft Windows System
Added by a variant of the RBOT-ASW WORM! |
 |
syshost.exe |
Microsoft Windows System
Added by the RBOT-ASW WORM! |
 |
scvhost.exe |
Microsoft Windows Updata
Added by a variant of the RBOT WORM! |
 |
spools.exe |
Microsoft Windows Update
Added by the SDBOT.TD WORM! |
 |
svchos.exe |
Microsoft Windows Update
Added by the SDBOT.AC WORM! |
 |
svcshost.exe |
Microsoft Windows Update
Added by the FORBOT-CF WORM! |
 |
svmhost.exe |
Microsoft Windows Update
Added by the FORBOT-CH WORM! |
 |
svshost.exe |
Microsoft Windows Update
Added by the WOOTBOT.CJ WORM! |
 |
scvvhost.exe |
Microsoft Windows Update
Added by the FORBOT-DH WORM! |
 |
swwhost.exe |
Microsoft Windows Update
Added by a variant of the RBOT WORM! |
 |
svzhost.exe |
Microsoft Windows Update
Added by the FORBOT-EV WORM! |
 |
sccvhost.exe |
Microsoft Windows Update
Added by a variant of the SDBOT WORM! |
 |
scrhost.exe |
Microsoft Windows Update
Added by the RBOT-AOW WORM! |
 |
srshost.exe |
Microsoft Windows Update
Added by a variant of the SDBOT WORM! |
 |
spoolvs.exe |
Microsoft Windows Updater
Added by the RBOT.ACQ WORM! |
 |
suvhost.exe |
Microsoft Windows Updater
Added by a variant of the SDBOT WORM! |
 |
svh0st.exe |
Microsoft WinUpdate
Added by the SPYBOT.DL WORM! |
 |
syslx32.exe |
Microsoft WinUpdate
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
syswin32.exe |
Microsoft WinUpdate
Added by the RBOT-HO WORM! |
 |
spfix.exe |
Microsoft WinUpdate
Added by a variant of the RBOT WORM! |
 |
serm32.exe |
Microsoft WinUpdates
Added by the RBOT.GE WORM! |
 |
svchost.exe |
Microsoft WPCEmail
Added by the SNIFFER-N TROJAN! |
 |
Syswu32.exe |
Microsoft Wxdate
Added by the SPYBOT.HZ WORM! |
 |
Sysmodule.exe |
Microsoft's System Module
Added by the FJ TROJAN! |
 |
sysmgr.exe |
Microsoft(R) System Manager
Added by the AGENT.QTR TROJAN! |
 |
sxvhost.exe |
Microsoft--Updates
Added by the RBOT-FH WORM! |
 |
svxhost.exe |
Microsoft-Updates
Added by the RBOT-CT WORM! |
 |
setdebugnt.exe |
Microsoft? ActiveX Debugger NT
Added by the BANCOS-CZ TROJAN! |
 |
SysMap.exe |
Microsoft? System Mapper
Added by the MAPSY TROJAN! |
 |
soff.pif |
Microsoftf DDEs Control
Added by the RBOT-AKH WORM! |
 |
systemproc.exe |
Microsoftkeysd
Added by the FORBOT-BI WORM! |
 |
systemwin32s.exe |
Microsoftkeysd
Added by the WOOTBOT.CO WORM! |
 |
smvss.exe |
MicrosoftOEM
Added by the DEDLER-G TROJAN! |
 |
Shellcomm.exe |
MicrosoftShell
Added by the BANCBAN-QG TROJAN! |
 |
SPOOLSYS.exe |
MicrosoftSys
Added by the TARNO.N TROJAN! |
 |
syshelper.exe |
MicrosoftUpdate
Added by the WOOTBOT.AC WORM! |
 |
syscnfg.exe |
MicrosoftValue
Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
 |
sysoverload.exe |
Microsoftvirus
Added by the FORBOT-AL WORM! |
 |
servicepack2.exe |
MicrosoftXP Service Pack 2
Added by the RBOT.EMC WORM! |
 |
svchosts11.exe |
Microsong
Added by the SDBOT-EV WORM! |
 |
snddrv.exe |
microsystem
Detected by Kaspersky as the VB.AXG TROJAN! |
 |
svchst.exe |
Microszoft Update Mach1nezs
Added by the RBOT-ED WORM! |
 |
ScannerFinder.exe |
Microtek Scanner Finder
Monitors whether a scanner is present. Provided with Microtek scanners |
 |
ShieldWorker.exe |
MilShieldSlave
Mil Shield from Mil Incorporated. It protects your privacy by removing all tracks from your online or offline computer activities |
 |
svchost.exe |
Mircosoft DNS Service
Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "drivers" subfolder |
 |
svchost32.exe |
Mircrosoft Svchost32
Added by the RBOT-AZW WORM! |
 |
setup.exe |
MM Install
Possibly Money Manager from Moneysoft? |
 |
syscnfg.exe |
ModularConfig
Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
 |
syschost.exe |
Modulo 00FE0F01 Host Internet
Added by the DELF-KW TROJAN! |
 |
SD Monitor.exe |
Monitor
"Transfer data quickly between your memory card and your computer with SanDisk's Readers, Writers and Adapters" |
 |
svchost.exe |
Monitoring Service
Added by the CONE.C WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "tasks" subfolder of the Winnt or Windows folder |
 |
SDMonitor.exe |
MonitorSD
Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here |
 |
Sounds.exe |
MotherBoard Sounds
Added by the RBOT-AAP WORM! |
 |
Search.exe |
MoveSearch
PigSearch adware |
 |
Sysdata.EXE |
Mp3 Loader
Added by the AVETTE-A VIRUS! |
 |
scheduler.exe |
MRU-Blaster Scheduler
Scheduler for MRU-Blaster - "a program made to do one large task - detect and clean MRU (most recently used) lists on your computer" |
 |
svhost32.exe |
ms
Added by the LEGMIR-AQO TROJAN! |
 |
svchos1.exe |
MS Config Loader
Added by the AGOBOT.R WORM! |
 |
svcrhost.exe |
MS Config Loader
Added by a variant of the RBOT WORM! |
 |
scrsave.scr |
MS Screen Saver
Added by the RBOT-AGT WORM! |
 |
systm.pif |
MS Security
Added by the RBOT-AQN WORM! |
 |
service5.exe |
MS Security Hotfix
Added by the GAOBOT.AG WORM! |
 |
sndcfg16.exe |
MS Sound Config 16bit
Added by the SDBOT.MB TROJAN! |
 |
sysrestore.exe |
MS SyS Restore
Added by the RBOT.XM WORM! |
 |
syshost.exe |
MS Update
Added by the EVAMAN-F WORM! |
 |
syshosts.exe |
MS Updates
Added by the MYDOOM.Y WORM! |
 |
Svhots.exe |
Ms Valud Loader
Added by the AGOBOT-SP WORM! |
 |
scguard.exe |
MS Windows Update
Added by the RBOT-YZ WORM! |
 |
suge.exe |
MSChoExE
Added by a variant of the RBOT WORM! |
 |
scvhost.exe |
msconfig
Added by the AGENT-DSF TROJAN! |
 |
syscnfg.exe |
MSCORE
Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
 |
syscnfg.exe |
MSDLL
Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
 |
Syss.exe |
msgserv_
Added by the FANTA TROJAN! |
 |
sys16.exe |
Msgtray
Added by an unknown VIRUS! |
 |
smvss.exe |
MSInstall
Added by the DEDLER-G TROJAN! |
 |
System.exe 4820 |
MSkernel32
Added by the TUXDER TROJAN! |
 |
spamkiller.exe |
MSKExe
McAfee Spamkiller |
 |
system32.exe |
msn
Added by the KITRO.A WORM! |
 |
scvhost.exe |
MSN
Added by the IRCBOT-ZW WORM! |
 |
systems.exe |
MSN
Identified as a variant of the Backdoor.PosionIvy keylogging malware |
 |
service.exe |
MSN BETA
Added by the RBOT.AUU WORM! |
 |
son.exe |
msn.exe
Added by the STARTPA-GS TROJAN! |
 |
svchostt.exe |
msnager32
Added by the WOMANIZ.E TROJAN! |
 |
SHCH.EXE |
MsnExplorer
Added by the EB TROJAN! |
 |
SVCHST.EXE |
MsnExplorer
Added by the EB TROJAN! |
 |
sdhch.exe |
MsnExplorer
Added by the TACTSLAY.B TROJAN! |
 |
sssasasb32.exe |
msnmsgq32
Added by the TACTSLAY.F TROJAN! |
 |
swef.bat |
MSNMSGRE
IRC backdoor TROJAN or WORM! |
 |
swin.bat |
MSNMSGRR
IRC backdoor TROJAN or WORM! |
 |
swe.bat |
MSNMSGRS
IRC worm or backdoor trojan! |
 |
swiss.bat |
MSNMSGRS
IRC worm or backdoor trojan! |
 |
swed.bat |
MSNMSGRS1
IRC backdoor TROJAN or WORM! |
 |
sagate.exe |
MSNPluginSrvcs
Added by the SDBOT.AKJ WORM! |
 |
services.exe |
MSOffice
Added by the DLOADER-EU TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an "MSOffice" subfolder |
 |
shman.exe |
MSOfficeCfg
Premium rate adult content dialer |
 |
ssvr.exe |
MSOfficeCfg
Premium rate adult content dialer |
 |
slssystem.exe |
msoft-updater23
Added by the RBOT-ASR WORM! |
 |
SGP.exe |
MSRegScan
SpyGator surveillance software. Uninstall this software unless you put it there yourself |
 |
SSDemo.exe |
MSRegScan
Supremespy spyware |
 |
sfool.exe |
mssfos
Added by the RANDEX.EUS WORM! |
 |
SCVHOST.EXE |
MSStartOptimizer
Added by the DASMIN-E TROJAN! |
 |
svcsys.exe |
MSSVC
Added by the FATOOS-C TROJAN! |
 |
svcsys.exe |
MSSYSTEM
Added by the FATOOS-C TROJAN! |
 |
svchost.exe |
MStask
Added by the LDPINCH-BV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
svchosthlp.exe |
MSUpdate
Added by the BLASTER.T WORM! |
 |
svchosts.exe |
Msupdate
Added by a variant of the TACTSLAY TROJAN! |
 |
svcrhost.exe |
Msupdate
Added by the TACTSLAY.A TROJAN! |
 |
svcshost.exe |
Msupdate
Added by the TACTSLAY.A TROJAN! |
 |
sys32dll.exe |
MsVBdll
Added by the AIMDES.B or AIMDES.C WORMS! |
 |
svcchost.exe |
msvcc25
Added by a variant of the SDBOT WORM! |
 |
salvage.exe |
msvcc25
Added by a variant of the SDBOT WORM! |
 |
svcchost.exe |
msvcc25
Added by the SDBOT-CSE WORM! |
 |
svcchosst.exe |
msvccc66
Added by the RBOT-GLS WORM! |
 |
sysmsvc.exe |
MsWindows SysDate
Added by the SPYBOT.FCD WORM! |
 |
Systern.exe |
MSWindowsUpdate
Added by the RBOT-AFD WORM! |
 |
SynCor.exe |
MSWinlogon
Added by the AGENT-FZL TROJAN! |
 |
searchbarcash.exe |
mswspl
SearchBarCash adware |
 |
Sys32Smm.exe |
MutexServiceEx
Webroot Sofware's discontinued "Privacy Master" |
 |
SMSSvc.exe |
My App
Added by the NEGASMS.A TROJAN! |
 |
S4BAREQ.EXE |
My Search Bar Eq
MySearch parasite |
 |
service.exe |
Myapp
Homepage hijacker |
 |
Splash.exe |
myCIO.com Splash
Splash screen for McAfee VirusScan ASaP on-line scanner |
 |
SysNT.exe |
MyVBApp
ReferAd adware |
 |
setup.exe |
MyVBApp
Detected by Kaspersky as the VB.KB TROJAN! File location is in the Root folder (C:), (D:), etc |
 |
svchost.exe |
nano
Added by the NANO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
systems.exe |
NAV Agent
Added by the TARNO.C TROJAN! Note - this is not the valid Norton Antivirus entry of the same name |
 |
slserves.exe |
NAV Auto Updates
Added by a variant of the SDBOT WORM! |
 |
SCardSvr32.Exe |
NavAgent32
Added by the MOFEI.B WORM! |
 |
shman.exe |
NAVCheck
Premium rate adult content dialer |
 |
sysnav32.exe |
navman_20
Hijacker, possibly a CoolWebSearch parasite variant |
 |
STARTM.EXE |
NB Start Menu
Part of McAfee Nuts & Bolts. Provides the same control as MSCONFIG and can be used instead if you have N&B |
 |
svhost.exe |
NDAv
Added by the SERFLOG.C WORM! |
 |
servenxpp.exe |
NDIS Adapter
Added by the FORBOT-GP WORM! |
 |
Servenxp.exe |
NDIS Adapter
Added by the SPYBOT.LY WORM! |
 |
svchosttt.exe |
NDIS Adapter
Added by the WOOTBOT.AN WORM! |
 |
shch.exe |
Nero
Added by a variant of the EB TROJAN! |
 |
svhost.exe |
net32
Added by a variant of the Trojan.Clicker family |
 |
svhoster.exe |
net64
Detected by PCTools as the AGENT.JVF TROJAN! See here |
 |
svc.exe |
netc
Detected by Bitdefender as DROPPER.LDPINCH.Q malware |
 |
Starter.exe |
NetPanel
Gemius surveillance software. Uninstall this software unless you put it there yourself |
 |
SafeCfg.exe |
NetScreen-Remote
NetScreen Remote VPN client software |
 |
svchostn.exe |
netservices
Added by the SDBOT.GI WORM! |
 |
svchost.exe |
NetStart
Added by the MKAR-A VIRUS! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "NETSTART" subfolder |
 |
sv.exe |
netsv32
Detected by PCTools as the DELF.CCD TROJAN! See here |
 |
svw.exe |
netw
Detected by Bitdefender as a variant of DROPPER.LDPINCH.Q malware |
 |
svchost.exe |
Network maneger
Detected by Trend Micro as the AGENT.BX BACKDOOR! See here. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
secsvc.exe |
Network Security
Added by the RBOT-ALX WORM! |
 |
svchost.exe |
Network Service
Added by the STARTPA-CC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
svhost.exe |
Network Service
Added by the HACDEF-K TROJAN! |
 |
svx.exe |
netx
Detected by Bitdefender as a variant of DROPPER.LDPINCH.Q malware |
 |
svzip.exe |
netzip
Detected by PCTools as the DELF.ZWL TROJAN! See here |
 |
sstray.exe |
nForce Tray Options
nVidia nForce Taskbar Utility - quick access to the nForce2 "Sound Storm" control panel and related utilitys |
 |
setup_en.exe |
NI.UGES_0001_N108M2006
MyContentAssistant security program, not recommend - see here |
 |
sysregi.exe |
Nod32 Runtime
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
sys.exe |
NoooH
Added by the ALNUH WORM! |
 |
SYMANTECAV2.EXE |
Norton Antivirus 2004
Added by the SPYBOT-DY WORM! Note - this is not the real Norton AV! |
 |
SERVICES.exe |
Norton Auto-Protect
Added by the Ahker.B WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder. Also, this is not part of Norton AV |
 |
Sochost.exe |
Norton Live Updater
Added by the GAOBOT.AO WORM! |
 |
Sysdoc32.exe |
Norton System Doctor
Norton Disk Doctor from Norton Utilities. Automatically runs at start-up, major resource hog and best started manually form Start -> Programs. Delete the shortcut in the Start -> Programs -> Startup folder as well |
 |
scvchost.exe |
Nortons AV SYSTEM
Added by a variant of the RBOT WORM! |
 |
svchost.exe |
NortonVPlus
Added by the ROAMER-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
SCHENGD.EXE |
NovastorSchedulerd
NovaStor NovaBACKUP Scheduler - back-up utility. If you don't have regularly scheduled back-ups you don't need it |
 |
Symmon.exe |
NSystemMonitor
Norton Uninstall Deluxe - monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging |
 |
Syslog32.exe |
NT Logging Service
Added by the DONK.B WORM and variants! |
 |
services.exe |
NTSet32
Added by the WINSPY-C TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\dll32 |
 |
scvhost.exe |
NTSF MICROSOFT SYSTEM
Added by a variant of the RBOT WORM! |
 |
sysman.exe |
NTSF MICROSOFT SYSTEM
Added by the RBOT.EDP WORM! |
 |
spool.exe |
ntuser
Detected by Symantec as the SILLYFDC WORM! See here |
 |
spools.exe |
ntuser
Detected by Symantec as the SILLYFDC WORM! See here |
 |
svchost.exe |
ntuser
Added by a variant of the WORM_SOCKS.D WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "driver" sub-folder |
 |
svchost.exe |
NvClipRsv
Added by the DUMARU-K WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
swchost.exe |
NvClipRsv
Added by the DUMARU-AK WORM! |
 |
Sp0.exe |
nwss
SpyOutside surveillance software. Uninstall this software unless you put it there yourself |
 |
sprtcmd.exe /P nxpclient |
nxpclient
NetExpert - "India's first ever automated Broadband care technology." Identifies and automatically fixes typical problems that may occur with your high-speed internet service |
 |
SYSCNTR.EXE |
OD
HotVideo dialler |
 |
sres32.exe |
OEM32 Tools
Added by a variant of the SPYBOT WORM! |
 |
setup60.exe |
OESET
Added by the WAREZDL.28672 TROJAN! |
 |
svch.exe |
Office Monitor Word Exel R
Added by the DWNLDR-GWW TROJAN! |
 |
svcrhost.exe |
OfficeAgent
Added by the TACTSLAY.A TROJAN! |
 |
svcshost.exe |
OfficeAgent
Added by the TACTSLAY.A TROJAN! |
 |
svcss.exe |
OfficeGuardUI
Added by the DEDLER-C TROJAN! |
 |
Szchost.exe |
Olive System
Added by the MERCURYCAS.A TROJAN! |
 |
scureapp.exe |
OmniPass
OmniPass from Softex Inc. - secure password management software |
 |
svchost.exe |
Online Service
Added by the HOSTIDEL.B or HOSTIDEL.C or TARNO.B TROJANS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
 |
SS.exe |
OnlinePCfix SmoothSurfer
Smooth-Surfer - blocks banners, ads, popups, and cleans MRU and Recent file lists |
 |
sachost.exe |
Onluna Sarvice
Added by the TOFGER-AA TROJAN! |
 |
sachost.exe |
Onlune Sarvice
Added by the DAEMONI-J TROJAN! |
 |
SCVHOST.exe |
only23
Added by the PUQ TROJAN! |
 |
syslaunch.exe |
Outwar
Outwar adware downloader |
 |
svchost.exe |
P0w3rF1Y
Added by the MM TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
ScanToPc.exe |
P3000x_S2P
Dell Laser MFP 1600N network application for scanning files to the PC |
 |
shnlog.exe |
paint.exe
Added by the PUPER-A TROJAN! |
 |
sdwmon32.exe |
PC Dynamics SdwMon32
SafeHouse "Personal Privacy" protects and hides your private and personal photos, videos, files and folders by making them "invisible" and encrypted |
 |
SysCleaner.exe |
PCCleaner
SysCleaner spyware remover - not recommended, see here |
 |
specialfile.exe |
PcEXPLODE
Added by the RBOT.RH WORM! |
 |
STUpdate.exe |
PCHEasySearch
PCH EasySearch bar |
 |
server.exe |
pcServer
Ssppyy spyware |
 |
stisvc32.exe |
PDA Commander
Added by the AGOBOT-TX WORM! |
 |
svchost.exe |
Perfomance Settings
Added by the TOFGER-AP TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
 |
scvhost.exe |
Personal Computer
Added by the RBOT-AJE WORM! |
 |
svchost.exe |
Photoshop
Added by the CDOPEN-E TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the "Program Files" folder |
 |
SPUVolumeWatcher.exe |
Picture Motion Browser Media Check Tool
Part of the Sony Picture Uility software supplied with Sony camera/camcorder products. What does it do and is it required? |
 |
swtray.exe |
pictureBUZZTray
System Tray access to PictureBUZZ on-line printing software from Streetwise Software. If you use the software set the page you use as a favourite in your browser and run it manually |
 |
SysUtil.exe |
Piracy
Software Piracy Alert feature bundled with PGWare software. Cries foul when it detects an 'illegal' version. The alerts are reported to disappear as soon as the software is correctly registered. There are privacy issues though: "The Software includes a feature that assigns a unique order number to GameGain based on purchase information. The Software reports this number to us via the internet either when you run the Software or enter the registration number, or both. The Software may also identify and report to us your IP address, date and time of installation, registration and/or use. We use this information strictly to count the number of installations, detect unauthorized access or piracy of the Software, and develop rough statistical data regarding the geographic location of our users" |
 |
srvhandle.exe |
Pluto! Pager
Added by the REDPLUT VIRUS! |
 |
startsvs.exe |
pnpsvc_lock
Browser hijacker |
 |
Svchost.exe |
PowerManager
Added by the JEEFO VIRUS! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
 |
SEServe.exe |
PPK Setup(Server)
Programmable Power Key on Sony Vaio laptops. "Using the Programmable Power Key (PPK) button, collect your e-mail automatically with one key stroke. You can also program your PPK to turn on your SuperSlim Notebook at a predetermined time and perform simple tasks - completely unattended" |
 |
starter.exe |
precpop2
PrecisionPop adware |
 |
SAGUI.exe |
PrevxHome
PrevX Home intrusion prevention software |
 |
SAGUI.exe |
PrevxPro
PrevX Home intrusion prevention software |
 |
spolserv32.exe |
Print Services
Added by the RBOT.ZP WORM! |
 |
start.bat |
print sharing
Added by the ZCREW TROJAN! |
 |
Spoolsv.exe |
Print Spooler
Added by the CIADOOR.B TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir% |
 |
spoolsvc32.exe |
Print Spooler
Added by the SDBOT.BB TROJAN! |
 |
spools.exe |
Print Spooler
Added by the RBOT-LD WORM! |
 |
spool.exe |
Print Spooler
Added by the IS TROJAN! |
 |
spoolsv32.exe |
Print Spooler
Added by the RBOT.SW WORM! |
 |
Spyassault.exe |
Printer
SpyAssault spyware remover - not recommended, see here |
 |
SpyAssaultScanner.exe |
printer
SpyAssault spyware remover - not recommended, see here |
 |
sysprinter.exe |
printer
Added by the SMALL.ZY TROJAN! |
 |
spool.exe |
Printer spool Service
Added by the RBOT-ACP WORM! |
 |
spooler.exe |
Printer Spooler
Added by the DELF-JJ TROJAN! |
 |
spoolss.exe |
Printer Spooler Subsystem
Added by a variant of the RBOT WORM! - Note - this is NOT the legitimate Windows spoolss.exe process, located in the Winnt/System32 or WindowsSystem32 folder, and which should NOT figure in Msconfig/Startup! |
 |
system.exe |
PrintMngr
Added by an unidentified TROJAN! |
 |
System.exe |
PrintSpoolSv
Added by the BDOOR-S TROJAN! |
 |
SpySheriff.exe |
pro
Added by the SPYWAD-I TROJAN! |
 |
ssmaze.scr |
Prote??o de tela
Added by the BANCBAN-FB TROJAN! |
 |
SHVRTF.EXE |
Protect
PC Angel takes a 5-second snapshot of the current system registry each time the PC boots up. In the event of a crash, PC ANGEL will retrieve everything up to the minute before the crash or the last known stable registry |
 |
ssrms.exe |
ProtocolDiskChk
Added by the ML TROJAN! |
 |
svcvlw32.exe |
ProtocolDiskChk
Added by the STINX-Y TROJAN! |
 |
sttool32.exe |
PSC main
Added by the OBFUSCATED.EV TROJAN! |
 |
svcnow32.exe |
PService
Added by the SPYBOT-DJ TROJAN! |
 |
service5.exe |
pushbot
Added by a variant of the PUSBOT WORM! A family of worms that spread using MSN Messenger |
 |
service52.exe |
pushbot
Added by a variant of the PUSBOT WORM! A family of worms that spread using MSN Messenger |
 |
sendmess.exe |
QQ
Added by the SEMES TROJAN! |
 |
scvhsot.exe |
QQKAV
Added by the QQROB.ARQ WORM! |
 |
SwiftBtn.EXE |
QT4StBtn
SwiftBtn - installed alongside the system drivers on Fujitsu Siemens notebooks and allows extra keyboard support |
 |
shman.exe |
QTSvc
Premium rate adult content dialler |
 |
ssvr.exe |
QTSvc
Premium rate adult content dialler |
 |
sprtcmd.exe /P QUICKCARE |
QUICKCARE
Qwest Broadband QuickCare (provided by SupportSoft, Inc) is a free self-help tool for Qwest DSL users. Identifies and automatically fixes typical problems that may occur with your high-speed internet service |
 |
shch.exe |
Quicktime
Added by a variant of the EB TROJAN! |
 |
sessions.exe |
QWS3270 Sessions
QWS3270 Secure terminal emulation software |
 |
Slave.exe |
RA Server
Added by the RA TROJAN! |
 |
svch0st.exe |
Ravshell
Added by the NSPM.PU TROJAN! |
 |
svch0st.exe |
ravtask
Added by the LINEAG-AIN TROJAN! |
 |
scrigz.exe |
RAX SYSTEM
Added by the MYTOB.KR WORM! |
 |
svchast.exe |
Recoveru system
Added by a variant of the LINEAGE-AV TROJAN! |
 |
svchost.exe |
Recoveru systems
Added by a variant of the SDBOT WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! ! This file is located in the "temp" folder |
 |
system.exe |
Recycle Bin Handler 2005
Added by the HO TROJAN! |
 |
Systen.exe |
reg run
Added by the BANCOS-BS TROJAN! |
 |
SVCH0ST.EXE |
reg2.0
eSpyNow surveillance software. Uninstall this software unless you put it there yourself. Note - the filename has the digit 0 rather then the uppercase "o" |
 |
SYSio32.exe |
RegCleaner
Added by an unidentified VIRUS, WORM or TROJAN! Note - do not confuse this with the popular RegCleaner registry cleaner freeware |
 |
services.exe |
RegDone
Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
 |
svchost.exe ccRegVfy |
regedit
Added by the HOTWORD.B TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup! |
 |
spoolserv.exe |
reggsdg
Added by the SDBOT-MS WORM! |
 |
svchosts.exe |
RegHelp
SpyGraphica spy software - "Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world." |
 |
SystemReg16.exe |
Registry System16 Checkup Monitor
Added by a variant of the RBOT WORM! |
 |
SystemReg166.exe |
Registry System166 Checkup Monitor
Added by a variant of the RBOT WORM! |
 |
service.exe |
Registry Value Name
Added by the RBOT-AHT WORM! |
 |
syswinxp.exe |
Registry Value Name
Added by the RBOT.BTZWORM! |
 |
sysfade.exe |
RegistryMonitor
Added by the SYSFADE TROJAN! |
 |
sory.exe |
REGRUN
Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS! |
 |
scvhost.exe |
regsrv
Added by the AGOBOT.E WORM! |
 |
scanreg32.com |
Reg_WFT
Added by the SENNASPY-F TROJAN! |
 |
Synchost.exe |
Remote Access Slave
Added by the RIPJAC TROJAN! |
 |
svchost.exe |
renascimento
Detected by Kaspersky as the BANKER.GAX TROJAN! See here. Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the "Help" sub-folder of the Winnt or Windows folder |
 |
svchost.exe |
reseurce
Added by the LINEAGE-FV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
svchots.exe |
Restore Operation
Added by a variant of the RBOT WORM! |
 |
SHS.exe |
RHSI SHS
Rogers Hi-Speed Internet software. "Should you ever lose access to your Rogers Hi-Speed Internet connection or e-mail, the Self-Healing Software (SHS.exe) will automatically repair your settings to get you up and running in a flash" |
 |
setup.exe |
RjLyraInstaller
?? |
 |
sentstrt.exe |
RNBOStart
Program used to initialise the VxD virtual driver for Sentinel drivers associated with Rainbow H/W keys that plug-in to the parallel port. These are usually supplied with workplace design tools and restrict the use of the software only to the machine to which the H/W key is connected. Required if you have such tools |
 |
seman.exe |
Roflcopteur
Added by an unidentified WORM or TROJAN! |
 |
svosm.exe |
rollbk
Added by the SERFLOG.B WORM! |
 |
sysup.exe |
rollbk
Added by the SERFLOG.B WORM! |
 |
shost32.exe |
rpc Win32
Added by the RBOT-ABL WORM! |
 |
spoolscv.exe |
rpc Win32
Added by a variant of the RBOT WORM! |
 |
smhost.exe |
RPCall_[ComputerName]
Added by the REDPLUT-B TROJAN! |
 |
services.exe |
RPCser32g
Added by the RITDOOR-C WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
services.exe |
RPCser32g1
Added by the PREXOT.D TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
services.exe |
RPCser32g3
Added by the PREXOT.D TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
services.exe |
RPCser32g4
Added by the PREXOT.E TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
services.exe |
RPCserv32
Added by the MYDOOM.AL WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
services.exe |
RPCserv32g
Added by the BOBAX.AA WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
system32.exe |
ruin
Added by the DELF-JM TROJAN! |
 |
spoolsvc.exe |
Run Services as Application
Added by the DLOADER-NY TROJAN! |
 |
svcadmin.exe |
Run Services as Application
Added by the DLOADER-NY TROJAN! |
 |
svcman.exe |
Run Services as Application
Added by the DLOADER-NY TROJAN! |
 |
svcrun.exe |
Run Services as Application
Added by the DLOADER-NY TROJAN! |
 |
StartupMonitor.exe |
Run StartupMonitor
Mike Lin's StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu |
 |
servic.bat |
run windows
Added by the REBOOT-AP TROJAN! |
 |
svcinit.exe |
run=
CoolWebSearch parasite variant |
 |
smsrun16.exe |
run=
Microsoft Systems Management Server (SMS) related - program that reads SMSRUN16.INI on clients running Win 3.1, Windows for Workgroups, Win95, or OS/2 to create program groups on the client and then launch SMS client programs |
 |
sec5dec.exe |
run=
Added by the ATAK.G WORM! |
 |
svhost.exe |
run=
Added by the ADMINCASH.B TROJAN! |
 |
services.exe |
run=
Added by the KREPPER-N TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "inet10066" subfolder of the Windows or Winnt folder |
 |
svchost.exe |
Runner
Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
sms.exe |
RunOnceEx
Identified as the DELF.LF by Ewido Security Suite |
 |
Server.exe |
RunProg
Added by the OPTIX.04.A TROJAN! |
 |
services.exe |
runservices
Identified as a variant of the SMALL.QO TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
syscnfg.exe |
Run[0]
Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
 |
servidevice.exe |
ryan1918
Added by the RBOT-GVR WORM! |
 |
service.exe |
r_server
Added by the MULTIDR-CP TROJAN! |
 |
svhost.exe |
S
Added by the AGOBOT-LN WORM! |
 |
svch0st.exe |
S0undMan
Added by the LOVGATE.AB WORM! Note - the filename has the digit 0 rather then the uppercase "o" |
 |
S24EvMon.exe |
S24EvMon
Event Monitor - supports driver extensions to NIC Driver for wireless adapters. Is it required? |
 |
s3serv.exe |
S3 Internal Chip
Added by the AGOBOT-DD WORM! |
 |
S3apphk.exe |
S3apphk
A tool installed alongside the drivers for your S3 video output device. It is not necessary but should be allowed to run unless it is causing problems |
 |
s3hotkey.exe |
S3Hotkey
Hotkey system tray icon to enable switching between monitors. Found on laptops with an S3 Twister integrated graphics card |
 |
S3Mon.exe |
S3Mon
S3DuoVue multi-monitor taskbar helper by S3 Graphics. What does it do and is it required? |
 |
S3Tray.exe |
S3TRAY
S3 display configuration taskbar utility for S3 chipset based graphics cards. Can be run from Start-> Settings -> Control Panel -> Display |
 |
s3tray2.exe |
s3tray2
Same as the s3tray entry in this table? |
 |
S3trayhp.exe |
S3TRAYHP
S3 Video driver related. What does it do and is it required? |
 |
S3trayp.exe |
S3Trayp
S3 display configuration taskbar utility for S3 chipset based graphics cards. Can be run from Start-> Settings -> Control Panel -> Display |
 |
S4F.exe |
S4F
FilterPak from S4F, Inc - internet filtering software |
 |
s4helper.exe |
s4helper
Searchcentrix hijacker |
 |
Sa3.exe |
SA
Logitech QuickCam driver. Is it required? |
 |
SAservice.exe |
SA Service
Associated with Cyber Trio and Warner troubleshooting software from G-Tek Technologies and pre-installed on some Packard Bell and NEC PCs. What function does this perform and is it required? |
 |
Sa3dsrv.exe |
Sa3dsrv
3D sound extension for Windows |
 |
saap.exe |
saap
NCase adware |
 |
SABSERV.EXE |
Sabreserver
Airline reservation software from Sabre. Available via Start -> Programs |
 |
sac.exe |
sac
NCase adware |
 |
sacc.exe |
SACC
SurfAccuracy adware |
 |
smcntlwio.exe |
sacmemds
Added by the MAILBOT-BZ TROJAN! |
 |
SafeWin.exe |
Safe
Added by the FOCOSENHA TROJAN! |
 |
SDWTRAY.EXE |
SafeHouseSystemTray
SafeHouse "Personal Privacy" system tray icon - PP protects and hides your private and personal photos, videos, files and folders by making them "invisible" and encrypted |
 |
SAFEIN~1.EXE |
SafeInstall.exe
Monitors a download and ensures an newer version of a file isn't replaced by an older one |
 |
SafeOff.exe |
SafeOFF
Provides protection that if user accidentally presses the power switch a dialog will pop up for confirmation |
 |
safesearch.exe |
SafeSearch
SafeSearch.A adware |
 |
SafeSpaceSysTray.exe |
SafeSpace
Part of SafeSpace (from Artificial Dynamics) which "protects computers from Internet malware infection without the need for signature updates or regular maintenance" |
 |
SafeStrip.exe |
SafeStrip
SafeStrip spyware remover - not recommended, see here |
 |
SafeStripReminder.exe |
SafeStripReminder
SafeStrip spyware remover - not recommended, see here |
 |
SSUpdate.exe |
SafeSurfingUpdate
MoneyTree parasite - ActiveX control used to download premium-rate dialers |
 |
sagate.exe |
Sagate Security Firewall
Added by the GAOBOT.BOW WORM! |
 |
SAgent2.exe |
SAgent2ExePath
Seiko Epson printer status agent. Disable if printer is not used often |
 |
Sagent.exe |
SAGENTSERVICE
TinySpyAgent commercial keystroke logger. Uninstall this software if you did not install it yourself |
 |
sagnt.exe |
sagnt
Adware web downloader |
 |
Sahagent.exe |
SAHagent
ShopAtHomeSelect parasite |
 |
shop1003.exe |
SAHBundle
ShopAtHomeSelect parasite |
 |
saie.exe |
saie
NCase adware |
 |
SaiMfd.exe |
SaiMfd
Saitek MFD File System Driver - associated with the Saitek SST (Saitek Smart Technolgy) configuration software for their game controllers. Create a shortcut and run manually when required |
 |
SaiMon.exe |
SAIMON
Saitek joystick driver |
 |
sain.exe |
sain
NCase adware |
 |
sais.exe |
sais
NCase adware |
 |
SaiSmart.exe |
SaiSmart
"Smart Button Special Sauce" - included with the latest software for Saitek game controllers. Related to the "S", "Shift" or "Smart" button and gives gamers extra features on the buttons. Only required if you use this feature |
 |
saicnfig.exe |
SaitekAutoConfigure
Configuration for Saitek game controllers |
 |
simenu.exe |
Sakemsneql
Added by the SDBOT.BTO WORM! |
 |
Sakora.exe |
Sakora
Detected by Microsoft as the GOWELES.A TROJAN! See here |
 |
SalaatTime.exe |
SalaatTime
"Salaat Time is a FREE multi-function Islamic application that calculates the prescribed five daily Muslim prayer times as well as Qiblah direction for anywhere in the world" |
 |
stm.exe |
Salestart
WinAnonymous spyware remover - not recommended, see here |
 |
strpmon.exe |
Salestart
Misleading security software such as WinPCDoctor, StorageProtector, ErrClean and SystemErrorFixer - not recommended |
 |
salm.exe |
salm
NCase adware |
 |
saly*****.exe |
saly
Added by a variant of the AW.AWK TROJAN! |
 |
Sam-sung.exe |
Sam-sung
Added by a variant of the SDBOT WORM! |
 |
SAMcal.exe |
SAMcal
SamCal - calendar/reminder program |
 |
Samsong.exe |
Samsong
Added by the SDBOT.BNE WORM! |
 |
Samsungs.exe |
Samsung
Added by an IRC TROJAN variant! |
 |
SbieCtrl.exe |
SandboxieControl
"SandBoxie runs your programs in an isolated space which prevents them from making permanent changes to other programs and data in your computer" |
 |
SandIcon.exe |
SandIcon
SanDisk ImageMate CompactFlash card reader SDDR-31 (USB). Very little use except to place the Sandisk icon beside its drive designation in Windows Explorer. The reader itself will work fine without it. The simplest thing is to just unplug the reader when you're not using it. It may slow the startup by a few nanoseconds, but once the software sees there's no reader, you get back the resources |
 |
sansv.exe |
SANS Service
Added by the VANEBOT-AH WORM! |
 |
SansaDispatch.exe |
SansaDispatch
Sansa Updater - "The Sansa Updater is an application that checks for the latest firmware updates then downloads and installs the firmware to your Sansa device" |
 |
SANTAS.BITCH.txt |
Santa Bastards Bitch
Added by the ATNAS.A WORM! |
 |
sapp.exe |
sapp
NCase adware |
 |
sasktelgui.exe |
SaskTel Accelerated Dial-up
"Experience faster surfing, downloading and e-mail by adding SaskTel Accelerated Dial-up Internet" |
 |
SATARaid.exe |
SATARaid
RAID driver for serial ATA disks on some motherboards such as the DFI Lanparty range. Only loaded if one is using RAID support on SATA drives |
 |
satmat.exe |
satmat
VX2.Transponder parasite updater/installer related |
 |
sau.exe |
sau
180Solutions adware related |
 |
SAUpdate.exe |
SAUpdate
Big Brother from Quest Software. System and network monitor |
 |
SAutoLaunchExe.exe |
SAutoLaunchExe
Sharp Zaurus PDA related, needed to synchronize information with a Desktop or Notebook |
 |
SAVAgent.exe |
SAVAgent
Part of Sophos anti-virus software. Required for centrally administered Sophos updates to work correctly, e.g. automatically updating PCs used by dial-in home or out-of-office users |
 |
Save.exe |
Save
WhenU.Save adware |
 |
SaveStartDate.Exe |
SaveDate
Unidentified adware |
 |
SaveNow.exe |
Savenow
WhenU.Save adware |
 |
savenow.exe |
Savenow
Added by the SPREDA.B VIRUS! |
 |
saw.exe |
SAW
SmartAdware adware |
 |
SAYTIME.EXE |
Say The Time 5.0
This program has audio cues for the system clock in male and female voices, customizes the appearance of the system clock, and can synchronize it to a time server regularly |
 |
SB.exe |
SB
Acer Soft Button on Acer Tablet PCs |
 |
SpywareBomber.exe |
SB
SpywareBomber spyware remover - not recommended, see here |
 |
SBWatchdog.exe |
SB Watchdog
Spyware utility installed by the manufacturers of some laptops (Sony) used to monitor browsing habits and send them back to whoever installed it - released by SoftBank |
 |
sbautoupdate.exe |
SBAutoUpdate
SpywareBlaster auto-updater |
 |
SBCFL.exe |
SBC RoamingClient
Part of AT&T FreedomLink Wi-Fi connection software |
 |
SBCSTray.exe |
SBCSTray
System Tray access to CounterSpy anti-spyware from Sunbelt Software |
 |
SBDrv.exe |
SBDrvDet
Detects the "Easy Front-Panel Audio Connectivity Drive Internal Drive Bay" on the Sound Blaster Audigy 2 Platinium eX. Can be disabled if you don't have one |
 |
sbdrvdet.exe |
sbdrvdet
Checks to see if Creative sound card driver should be updated |
 |
sbhc.exe |
SBHC
SuperBar parasite - uninstall available here |
 |
SBMPop.exe |
SBMPOP
SearchByMedia adware |
 |
sbmx.exe |
SBMX
SoundMAX MPU401 MIDI device emulator for x86 VM DOS games/apps (for Win9x only) |
 |
sbss.exe |
sbss Launcher
SideBySide adware |
 |
scrubxp.exe |
sc
ScrubXP - utility that deletes safe to remove files, cookies, browsing history, etc |
 |
sc.exe |
sc
Watchdog 2.0 Software - monitoring program |
 |
scprot4.exe |
SC2
Added by the AGENT.APP TROJAN! |
 |
sc23exec.exe |
sc23exec
Possibly related to a digital camera |
 |
SC3300CC.exe |
SC3300CC
SiPix digital camera Twain device driver |
 |
s030109.Stub.exe |
scain
Delfin Media Viewer adware related |
 |
SVOHOST.exe |
ScamDisk
Added by the LEWOR.D WORM! |
 |
ssms.exe |
Scan Register
Added by the RBOT-AT WORM! |
 |
satan.exe |
ScanDisc
Added by the GREGSTAR TROJAN! |
 |
ScanDisk.exe |
ScanDisk
Added by the GANDA.A WORM! Note - this is not the valid "ScanDisk" Win9x/Me standard disk error checker |
 |
scands32.exe |
scands32.exe
Added by a variant of the ADCLICKER TROJAN! |
 |
scandsk2.exe |
Scandsk2
Added by the AGOBOT-PK WORM! |
 |
scandskx.exe |
scandskx.exe
Added by the DLOADR-ARM TROJAN! |
 |
SDetect.exe |
Scanner Detector
ScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the "GO" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the "GO" button |
 |
ScanPanel.exe |
ScanPanel
Trust Easy Webscan scanner related - what does it do and is it required? |
 |
scanregv.exe |
ScanRegistry
Added by the MASTERLOCK TROJAN!. Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as scanregv.exe not scanregw.exe |
 |
Scanregw.exe |
ScanRegistry
Scans the system registry and makes back-ups at start-up. Important should the registry become corrupt. The executable "Scanregw.exe" is located in %windir% (where %windir% is the Windows directory - C:Windows or C:Winnt) |
 |
Scanregw.exe |
ScanRegistry
Added by the STATOR WORM! Note - this is not legitimate ScanRegistry entry - which is a vital Windows file. The executable "Scanregw.exe" is located in %System%. Runs from the registry RunServices key as opposed to the Run key |
 |
scanregw.exe |
ScanRegistry
Added by the NYXEM-D WORM! Note - do not confuse this with the legitimate Windows process scanregw.exe which is always found in the Windows folder on Win9x/ME machines. This worm file is found in the System (9x/ME) or System32 (NT/2K/XP) folder |
 |
Scanner.exe |
ScanSpyware v *
ScanSpyware spyware remover (where * = the version number) - not recommended, see here |
 |
scApp.exe |
scApp
Added by the STANDO-E WORM! |
 |
suchost.exe |
scApp
Added by the ACNATT.A WORM! |
 |
scardsvr.exe |
SCardSvr
Related to SmartCard readers and sometimes uses lots of system resources |
 |
SCardSvr32.Exe |
SCardSvr
Added by the MOFEI.B WORM! |
 |
SCDEmuApp.exe |
SCDEmuApp.exe
Related to PowerISO - CD/DVD image file processing tool |
 |
scheck45.exe |
scheck45
Related to unknown malware - hidden installer associated with it |
 |
schedl.exe |
schedl
Added by the VB-DVW WORM! |
 |
schedm.exe |
schedm
Part of Antivir PersonalEdition Classic anti-virus |
 |
shch.exe |
ScheduIr
Added by a variant of the SDBOT WORM! |
 |
svchst.exe |
ScheduIr
Added by a variant of the SDBOT WORM! |
 |
Schedule.exe |
Schedule
Scheduler for Mercury Ez View TV Tuner Card |
 |
Scheduled_Maintenance.exe |
Scheduled Maintenance
Scheduler for Iolo System Mechanic tweaking utility. It can cleans your registry and deletes temporary files at defined intervals. Available via Start -> Programs |
 |
svcrhost.exe |
Scheduler
Added by the TACTSLAY.A TROJAN! |
 |
svcshost.exe |
Scheduler
Added by the TACTSLAY.A TROJAN! |
 |
Scheduler daemon.exe |
Scheduler
Tenebril GhostSurf or SpyCatcher related scheduler - you can schedule daily, weekly, monthly or one-time only cleanings |
 |
sdhch.exe |
Scheduler
Added by the TACTSLAY.B TROJAN! |
 |
svchst.exe |
Scheduler
Added by the TACTSLAY.B TROJAN! |
 |
Scheduler.exe |
Scheduling Agent
Added by the SUBWOOFER TROJAN! Note - this is not the real MS Scheduling agent as the executable is incorrect |
 |
Schmaili.exe |
Schmaili
Schmaili - insert animated smilies into your e-mail |
 |
SchSvr.exe |
SchSvr
WinScheduler is installed with Home Theater or WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs |
 |
SCHWIZEX.EXE |
SCHWIZEX
Part of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot |
 |
sclick.exe |
sclick
Added by the FAKEALERT TROJAN! |
 |
scman.exe |
ScManager
Added by the FORBOT-CW WORM! |
 |
scopedll.exe |
scopedll
Added by a variant of the CRYPTER.C TROJAN! |
 |
scr.scr |
Scr
Added by the OPASERV.T WORM! |
 |
Scrappad.exe |
ScrapPad
ScrapPad allows you to quickly and easily record notes, thoughts, messages, and just about anything you want. Use it like you use scrap paper |
 |
scrcal.exe |
Screen Calendar
Screen Calendar allows you to create custom desktop wallpapers with built in active calendar and scheduler |
 |
sgms.exe |
Screen Guard Message Scan
Part of Access Denied security and privacy software |
 |
scrnsaver.scr |
Screen Saver
Added by the RBOT-AGP WORM! |
 |
ScreenHunter.exe |
ScreenHunter 4.0 Free
"ScreenHunter 4.0 Free is a completely free screen capture software for you to easily take screenshots" |
 |
ScreenPrint32.exe |
ScreenPrint32
ScreenPrint32 screen capture software - can be launched manually |
 |
scruser2k.exe |
screxe
?? |
 |
script.bat |
script
Maybe associated with DOS on a Win9x machine |
 |
SBServ.exe |
ScriptBlocking
Update to Norton AntiVirus 2001. Detects certain types of script-based viruses without the need for specific virus definitions - such as JavaScript and VBScript. This will help protect you from these viruses even before virus definitions are available. Note - some users complain of problems once the update is installed - refer here for more information |
 |
Scriptsentry.exe |
ScriptSentry
Script Sentry from Jason's Toolbox. Blocks malicious scripts and allows safe scripts to run. Only required if you want it to check the file associations it guards at startup. It will function regardlessly |
 |
SCROLL.EXE |
Scroll-In-Mouse V2.0
Toolkit for the Lynx-3D Net scroll mouse from QTronix. Required if you use the special features |
 |
scrss.exe |
scrss
Added by the HACDEF-R TROJAN! |
 |
scrsvc.exe |
scrsvc
Added by the AGENT-DS TROJAN! |
 |
ScrSvr.exe |
ScrSvr
Added by the OPASERV WORM! |
 |
Scsi.exe |
Scsi
SCSI Miniport driver |
 |
sescmgr.exe |
sctrlmgr
Added by a variant of the DWNLDR-GAH TROJAN! |
 |
svzhost.exe |
scvhost
Added by a variant of the SPYBOT WORM! |
 |
scvhost.exe |
scvhost
Wiretap surveillance software. Uninstall this software unless you put it there yourself |
 |
scvhost.exe |
scvhost.exe
Added by the LOHAV-N TROJAN! |
 |
sd32info.exe |
sd32info
Added by the CRYPTER.A TROJAN! |
 |
sdaemon.exe |
SDaemon
PC Security from Tropical Software. 'PC Security? 5.1 is the ultimate in computer security, offering multiple locking systems for the Windows environment and internet. Lock files, monitor programs' activities, even detect intruders! PC Security? offers flexible and complete password protection, "Drag and Drop" support, plus many other handy features' |
 |
svhost.exe |
SDAv
Added by the SERFLOG.C WORM! |
 |
sdclientmonitor.exe |
SDClientMonitor
Related to LANDesk Management Suite from LANDesk Software Ltd. What does it do and is it required? |
 |
SDetect.exe |
SDetect
ScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the "GO" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the "GO" button |
 |
sp2update.exe |
sdfsdfsdf
Added by a variant of the SPYBOT WORM! |
 |
sdin.exe |
SDIN Adapter
Added by the FORBOT-AP WORM! |
 |
sdkimddprovment2.exe |
SDK Codre Function22
Added by the SDBOT-YJ WORM! |
 |
sdkcore.exe |
SDK Core Component
Added by the SDBOT-WC WORM! |
 |
sdkimprovment.exe |
SDK Core Function
Added by the RBOT.BHL WORM! |
 |
sdkimprovment2.exe |
SDK Core Function2
Added by the SPYBOT.OGX WORM! |
 |
Sdk**.exe [* = random char] |
Sdk**.exe [* = random char]
CoolWebSearch/HomeSearch adware - for examples, see this log |
 |
Sdk**32.exe [* = random char] |
Sdk**32.exe [* = random char]
CoolWebSearch/HomeSearch adware - for examples, see this log |
 |
SDKC0R3.exe |
SDKcore Update Components2
Added by the RBOT-ABA WORM! |
 |
SDK0mCORE.exe |
sdkupdate22
Added by the FORBOT-DT WORM! |
 |
SDPhotoBar.exe |
SDPhotoBar.exe
SmartDraw Photo (now FotoFinsh) - "organize, enhance, print, and share your photos. It's also a powerful graphic editor for creating images and web graphics" |
 |
sdrss.exe |
sdrss
Added by the SDBOT-SQ WORM! |
 |
svchost.exe |
sds20
InlookExpress logs keystrokes and captures screenshots. If you didn't install this yourself remove it. Note - this should not be confused with the svchost.exe system process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder! This file is located in a "sds20" folder |
 |
sdtray.exe |
SDTray
RSA Keon Web PassPort - software that allows organizations to use digital certificates in a Web-based environment to help ensure that their transactions are authentic, confidential and digitally signed |
 |
SDTrayApp.exe |
SDTray
Spyware Doctor spyware remover - system tray access |
 |
sdxsys32.exe |
sdxsys32
Added by the BROGGER-A TROJAN! |
 |
sealmon.exe |
sealmon
SealedMedia enables you to combine document protection and control with your existing applications - such as Microsoft Word, Microsoft Excel, Microsoft PowerPoint and Email |
 |
SearchDefender.exe |
Search Defender
Installed by SpeedItUp without permission, along with PC-Checker. Detected by DrWeb as the STARTPAGE.ORIGIN TROJAN! |
 |
srchhook.exe |
Search Hook
?? |
 |
SE.exe |
Search-Exe
Search-Exe hijacker |
 |
Search And Destroy.exe |
SearchAndDestroyMFC
Search And Destroy rogue security software - not recommended, see here |
 |
SearchAndDestroy.exe |
SearchAndDestroyScheduler
Search And Destroy rogue security software - not recommended, see here |
 |
SearchAndDestroy.exe |
SearchAndDestroyT
Search And Destroy rogue security software - not recommended, see here |
 |
scbar.exe |
SearchEnhancement
SCBar foistware |
 |
searchnav.exe |
searchnav
SearchNav adware - IEFeatures/Popnav variant |
 |
searchnavversion.exe |
SearchNavVersion
SearchNav adware - IEFeatures/Popnav variant |
 |
ServeUp.exe |
SearchNet_Up
SearchNet adware |
 |
searchsetter[1].exe |
SearchSetter
Browser hijacker - redirecting to FindWhateverNow.com |
 |
SearchSettings.exe |
SearchSettings
Vendio "Search Settings" foistware - reportedly installed without notice, see here and here |
 |
SearchSpy.exe |
SearchSpy
SearchSpy spyware remover - not recommended, see here |
 |
SearchSquire[number].exe |
SearchSquire[number]
SearchSquire adware |
 |
SearchUpgrader.exe |
SearchUpgrader
Hijacker |
 |
secdrive.exe |
secdrive.exe
Added by a variant of the SPYBOT WORM! See here |
 |
SecCopy.exe |
Second Copy 2000
Related to Second Copy? - a files/folders backup utility |
 |
sctray.exe |
SecondChance
Power Quest Second Chance. Sets checkpoints for saving a backup copy of the registry to a disk so you can restore it if you have a crash |
 |
Secret.exe |
Secret
Added by the DELF-LW TROJAN! |
 |
start.exe |
Secret-Crush
Hijacker that may reset your browser's home page and/or search settings to point to undesired sites |
 |
secretmaker.exe |
SECRETMAKER
Secretmaker is a combination of eight privacy-defending programs, including Spam Fighter Pro, Worm Hunter, Pop-Up Killer, Banner Blocker, Cookie Eraser, Privacy Protector, History Cleaner, and Garbage Cleaner |
 |
ss.exe |
SecretSmileys
"Secret Smileys is an add-on for AIM that provides users access to 1000's of new Smileys that can be viewed by anyone using a current version of AIM. Secret Smileys also adds other features such as logging of IM conversations, and it gets rid of that annoying advertisement on your buddy list window" |
 |
secserv.exe |
secserv.exe
Reported by Panda as an EasySearch Adware variant. Note - EasySearch modifies the Internet Explorer settings and may download programs onto the infected computer |
 |
secsvcnt.exe |
secsvc32
Added by the GLOBAL PATROL TROJAN! |
 |
Secsys.exe |
Secsys
UltraSoft Key Interceptor surveillance software - uninstall this unless you put it there yourself! |
 |
secure.exe |
secure
DealHelper adware |
 |
svshost.exe |
secure
Added by the RBOT-AFO WORM! |
 |
sslcert.exe |
Secure Socket Layer Certification
Added by the VANEBOT-AN WORM! |
 |
Shell32.com |
Secure32
Detected by Symantec as the SILLYFDC WORM! See here |
 |
scregmanager4.exe |
SecureClean4RegManager
WhiteCanyon SecureClean 4 disk cleaner - clean hard drive data, MRUs, temp files and more. Can be started manually |
 |
sctray4.exe |
SecureClean4Tray
WhiteCanyon SecureClean 4 disk cleaner - clean hard drive data, MRUs, temp files and more. Can be started manually |
 |
SecureCleaner.exe |
SecureCleaner
SecureCleaner spyware remover - not recommended, see here |
 |
SCIEClean.exe |
SecureCleanIEClean
SecureClean - scans your system for hidden temporary files, deleted email messages, Internet histories and caches |
 |
Secureitpro470p.exe |
SecureItPro
SecureIt Pro - lock your computer when you're not there, to stop malicious users from accessing your desktop |
 |
SOAN.exe |
SecureOnlineAccountNumbers
Related to Secure Online Account Numbers by Discover(R) Card from Orbiscom Ltd. Secure and innovative payment solutions |
 |
samsm.exe |
Security Accounts Manager SM
Added by the SPYBOT.JE WORM! |
 |
securag.exe |
Security Agent
Added by the BANCBAN-F TROJAN! |
 |
securesec.exe |
Security Center Distribution
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
Security iGuard.exe |
Security iGuard
Security iGuard spyware remover - not recommended, see here |
 |
SecurityManager.exe |
Security Manager
A ComCast Internet software suite that provides a variety of features (firewall, popup blocker, parental controls etcetera) to help ensure your computer is secure, and your information is kept private |
 |
securemon.exe |
Security Monitor
Detected by Kaspersky as the AUTORUN.LPF WORM! See here |
 |
scmss.exe |
Security Patch
Added by the RBOT-ZW WORM! |
 |
secserver.exe |
Security Server DB
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
syss.exe |
security service
Added by an unidentified WORM or TROJAN! |
 |
secsvc.exe |
Security Service
Added by the RBOT-GGF WORM! |
 |
secservice.exe |
Security Service DB
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
svhost.exe |
Security Service Process
Added by the AGOBOT-LC WORM! |
 |
securesys.exe |
Security System
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
SECWIZ98.EXE |
SECWIZ98
Security Wizard 98 by Chris Farmer. Offers you a variety of ways to restrict access to many of the programs and settings on your PC. Available here |
 |
seekmo.exe |
seekmo
Seekmo Search, a 180Solutions adware variant - also see here |
 |
SeekmoSA.exe |
SeekmoSA
180Solutions.Zango adware |
 |
seeve.exe |
seeve
Medload adware |
 |
slcsvr.exe |
Select server
Added by the DLOADER-WD TROJAN! |
 |
slefhost.exe |
SelfHostUtil
?? |
 |
SemanticInsight.exe |
SemanticInsight
RXToolbar adware. Software that displays pop-up/pop-under advertisements when the primary user interface is not visible |
 |
SeMS.exe |
SeMS
PCsms - tool that enables you to send sms text messages from your PC to any UK mobile phone |
 |
Sensiva.exe |
Sensiva
Symbol Commander makes the use of your PC, laptop, Tablet PC, and Pocket PC much easier and much faster. It recognizes your handwriting with unparalled performance and executes commands in a snap. Just by using your mouse, pen, or touchpad, simply draw symbols to execute actions instantly |
 |
SENTRY.exe |
SENTRY
From IP Insight. Allows website owners "to instantly determine the precise geographic location, connection speed and detailed demographics of every visitor to your website". Will be detected by most firewalls and the majority of home users should disable it |
 |
sepate.exe |
Sepate Security Firewall
Added by a variant of the RBOT WORM! |
 |
septpop06apsept.exe |
septpop06apsept
MediaMotor.Popupwithcast adware |
 |
serials.exe |
Serials
Any one of a variety of worms and trojans |
 |
servicez.exe |
Serices Hostin
Detected by Trend Micro as the IRCBOT.AUA BACKDOOR! See here |
 |
serbw.exe |
serpe
Added by the SERFLOG.A WORM! |
 |
serrdctl.exe |
serrdctl.exe
"Shared Modem Service Client Event Viewer" - used when a number of PCs have access to a number of modems. Required to be running on each PC for access to the modems |
 |
serrv.exe |
serrv
Added by the WAREZOV.DC WORM! |
 |
serv-u32.exe |
Serv-U
FTP server |
 |
server.exe |
server
Added by the DELTAD.A WORM! |
 |
system.exe |
server
Added by the METHS-A TROJAN! |
 |
server.exe |
server
Added by the SINGU-Q TROJAN! |
 |
ServoApp.exe |
Server Application for MFP Server
Multi Function Printer (MFP) Server Agent for Belkin's Wirless G All-in-One Print Server and ZyXEL's NPS-520 |
 |
server05.exe |
Server Backbone
Added by the RBOT-ZM WORM! |
 |
sdhost.exe |
Server Daemon Host Manager
Added by the RBOT-GWC WORM! |
 |
SERVER.EXE |
SERVER.EXE
Added by the BUSHTRO122 or SMOKODOOR TROJANS! |
 |
Server.txt.vbs |
serverex
Added by the DELTAD.A WORM! |
 |
Serverx.exe |
Serverx
Added by the MADANGEL VIRUS! |
 |
service.exe |
Service
Added by the ALADINZ.H TROJAN! |
 |
services.exe |
Service
Added by the NETSKY or NETSKY.B WORMS! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
SYSNT.exe |
Service
Added by the CHA TROJAN! |
 |
Service.pif |
Service
Added by the ASSIRAL-C WORM! |
 |
sccenter.exe |
Service Connection
For Compaq PC's. Part of Backweb |
 |
service.exe |
Service Controller
Added by the PREVERT TROJAN! |
 |
svchost.exe |
Service Host
Added by the TORVEL WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
 |
spoolxx.exe |
Service Host
Added by the TORVEL WORM! |
 |
svchost.exe |
Service Host
Added by the DAOSER-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Services{C922CCC4-CF61-4589-A0D1-828160704853} subfolder |
 |
svchost.exe |
Service Host
Added by the DAOSER-C TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Services[random] subfolder |
 |
svchost.exe |
Service Host Driver
Added by the HITON TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
 |
spoolsvc.exe |
Service Host Process
Added by the GAOBOT.GEN!POLY WORM! |
 |
sqlmangr.exe |
Service Manager
SQL Server Service Manager - provides tray access to SQL server, the server agent and MSDTC. Available via Start → Programs |
 |
SERVICEMGR.EXE |
Service Manager
Added by the PASSMAIL-D VIRUS! |
 |
service.exe |
service manager
Added by the DONBOMB.A TROJAN! |
 |
spdll32.exe |
Service Pack DLL Runtime
Added by a variant of the RBOT WORM! |
 |
SVCHOST.EXE |
Service Process
Added by the DARKER WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
 |
service.exe |
Service Process
Added by the DCMBOT-C TROJAN! |
 |
smss.exe |
Service Process
Added by the DCMBOT-E TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "config" subfolder |
 |
svchost.exe |
Service Process
Added by the DCMBOT-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "config" subfolder |
 |
scheduler.exe |
Service Scheduler
Added by the AGOBOT-PH WORM! |
 |
svcupdcli.exe |
Service Update Client
Added by an unidentified WORM or TROJAN! See here |
 |
Service.exe |
Service.exe
"servedby.advertising" popup generator |
 |
Service2.exe |
Service2
Identified as a variant of the Win32.Iroffer malware. Located in %Windir%\Drivers\Intel |
 |
service32.exe |
service32
Added by the AGOBOT-ST WORM! |
 |
serviceconnect.exe |
serviceconnect
Added by the AGOBOT.AIR WORM! |
 |
services.exe |
Servicee
Detected by Trend Micro as the AGENT.DEI TROJAN! See here. Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
ServiceLayer.exe |
ServiceLayer
Nokia Connectivity Library support task that is needed by NCLTRAY and by the Nokia Connection Manager for either to work properly |
 |
service.exe |
servicemng
Added by the TAME-C WORM! |
 |
servcr.exe |
Servicer
Added by the SDBOT.BAH TROJAN! |
 |
start.bat |
services
Added by the ZCREW TROJAN! |
 |
services.exe |
Services
Added by a number of VIRUSES, WORMS and TROJANS! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup! |
 |
Svchosts.exe |
services
Added by the SDBOT.N WORM! |
 |
scks32.exe |
Services
Added by a Proxy Trojan variant |
 |
sockys32.exe |
Services
Added by the RANKY.L TROJAN! |
 |
sys.exe |
Services
Added by a Proxy Trojan variant |
 |
socks.exe |
services
Added by the WIN32.SMALL.N TROJAN! |
 |
services.exe |
Services
Added by the ZINCITE.A TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
svchost.exe |
Services
Added by the REPER-B WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
sysamp.exe |
Services
Added by a variant of the SDBOT WORM! |
 |
sample.exe |
services
Added by a variant of the RANKY TROJAN! |
 |
spoolsvc.exe |
Services Administrator
Added by the DLOADER-NY TROJAN! |
 |
svcadmin.exe |
Services Administrator
Added by the DLOADER-NY TROJAN! |
 |
svcman.exe |
Services Administrator
Added by the DLOADER-NY TROJAN! |
 |
svcrun.exe |
Services Administrator
Added by the DLOADER-NY TROJAN! |
 |
services.exe |
Services Controller
Added by the CIADOOR-F TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
srvdll.exe |
Services DLL Loader
Detected by Trend Micro as the IRCBOT.AYN BACKDOOR! See here |
 |
Scchost.exe |
Services Host
Added by the DONK WORM! |
 |
svchost32.exe |
Services Host
Added by the AGOBOT-TG WORM! |
 |
services.exe |
Services Logon
Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! By default this file is located in Documents and Settings[user name]Templates |
 |
servc.exe |
Services Management Clients
Added by the RIZO.A TROJAN! |
 |
servcs.exe |
Services Managements
Added by the RBOT-GUC WORM! |
 |
svsmanager.exe |
Services Manager
Added by an unidentified TROJAN! See here |
 |
svmanager.exe |
Services Manager!
Detected by Trend Micro as the IRCBOT.ATZ TROJAN! See here |
 |
svcmanager.exe |
Services Managers
Added by a variant of the IRCBOT TROJAN! See here |
 |
services.exe |
Services Process
Spyware - detected by Kaspersky as the SMALL.X TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
 |
smss.exe |
Services Process
Added by the SMALL-EK TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "config" subfolder |
 |
services.exe |
Services Startup
Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! By default this file is located in Documents and Settings[user name]Templates |
 |
svhost33.exe |
Services Startup
Added by a variant of the RBOT WORM! |
 |
smss.exe |
Services.dll
Added by the SOBER-L WORM! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a msagentsystem subfolder of the Winnt or Windows folder |
 |
services.exe |
Services.EXE
Added by the KAZPING WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
Services.exe |
services.exe
Added by the CIADOOR-F TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
servicess.exe |
services.exe
Added by the MSNSPY-B TROJAN! |
 |
SERVICES.EXE |
ServicesAdministrator
Added by the PUNYA-B WORM! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
 |
ServicesNotify.exe |
ServicesNotify
Defender Pro Antispy |
 |
servicestub.exe |
servicestub.exe
Detected by Trend Micro as the RBOT.CN TROJAN! See here |
 |
svhost.exe |
Servicio Local
Added by the SPYBOT.BGX WORM! |
 |
System.exe |
Servicos
Added by the BANCOS-BCM TROJAN! |
 |
servics.exe |
servics
Added by the SINGU-J TROJAN! |
 |
SERVlCE.EXE |
SERVlCE
Added by the AGOBOT-UB WORM! |
 |
ServUTray.exe |
ServUTrayIcon
System Tray icon for Serv-U FTP server. Is it required? |
 |
sesvc.exe |
SES Service
Added by the SDBOT-CZU WORM! |
 |
sescli.exe |
Session Client
SurfSpy keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
smssa.exe |
Session Manager Subsystem
Added by the RBOT-AGS WORM! |
 |
sed.exe |
SESync
DownloadWare adware |
 |
setdefprt.exe |
setdefprt
Used to set a Brother MFC printer/copier/scanner as the default printer after installation |
 |
SetHook.exe |
SetHook
Fellowes Neato CD label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar" |
 |
SETI@home.exe |
SETI@home
SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data |
 |
SETI@home.exe |
seticlient
SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data |
 |
SetIcon.exe |
SetIcon
Installed by a 6-in-1 (4 Media Card slots, a floppy drive and a USB connection) device. Constantly updates the icons for the four Media Card slots that it has and is a resource hog |
 |
Setiqu~1.exe |
SetiQueue
Provides work unit buffering for Seti@Home clients - see here for more details |
 |
SetiSpy.exe |
SetiSpy
SETI Spy is a little program to "spy" on the progress and performance of the SETI@home client. Called a "spy" because it is unobtrusive as possible |
 |
SetPoint.exe |
SetPoint
Added by the RBOT-BWI WORM! Note - this is not the valid Logitech Setpoint mouse and keyboard entry that uses the same filename and is located in the LogitechSetpoint sub-folder of Program Files. This file is located in the System (9x/Me) or System32 (NT/2K/XP/Vista) folder |
 |
Setpoint.exe |
SetPoint
Logitech SetPoint Event Manager for their range of mice and keyboards. Required if you want to use the advanced features of these devices and is located in the LogitechSetpoint sub-folder of Program Files |
 |
SetRefresh.exe |
SetRefresh
Video refresh rate utility found on some HP and Compaq PCs. Recommended for CRTs but not LCDs |
 |
sysweb.exe |
Setting
Added by the SDBOT.GEN TROJAN! |
 |
svchost.exe |
Setup experation
Added by the TOFGER-AW TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
 |
setuzp.exe |
setuzp
?? |
 |
setvrc.exe |
SetVrc
Added by the HUNTOCX WORM! |
 |
st01b.exe |
Sex Teris
Added by the REPAD WORM! |
 |
Sexnow.exe |
Sexnow
Added by the SENOW-B premium rate adult content dialler |
 |
Sexy_Blondes.exe |
Sexy_Blondes
Added by the Sexy DIALER! Related also to Hot Tarts DIALER! |
 |
Sexy_sg.exe |
Sexy_sg
Premium rate adult content dialler |
 |
sf.exe |
sf
SurfEnhance adware component |
 |
SFIGUI.EXE |
SFIGUI
Sonic Focus - "enhances music, movie and game sound by analyzing compressed audio streams in realtime, then restoring and enriching audio back to its original performance qualities" |
 |
sfita.exe |
sfita
Added by the FAVADD-H TROJAN! Also known as SurfEnhance adware |
 |
sfpc.exe |
sfpc
Spy4PC surveillance software. Uninstall this software unless you put it there yourself |
 |
sfWinStartupInfo.exe |
SfWinStartInfo
SFIRM32 Online Banking software |
 |
Sgecrypt.exe |
Sgecrypt
SafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks" |
 |
sginst.exe |
sginst
eAcceleration Stop-Sign security software related. Previously not recommended, see here |
 |
SGTBox.exe |
SGTBox
Canon scanner driver. Is it required? |
 |
sgtray.exe |
sgtray
StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups |
 |
Shadow.exe |
Shadow
"NTI Shadow 3 is an award-winning easy-to-use backup application that automatically protects your photo, music, video, and various data files. It makes data restoration as easy as dragging and dropping files from one place to another" |
 |
ShadowUser.exe |
ShadowUser Pro Edition
"StorageCraft? ShadowUser? provides easy to use desktop security and protection for Windows operating systems. ShadowUser is the best way to prevent unwanted changes to PCs and laptops" |
 |
shambl3r.exe |
shambl3r*
Added by the REMABL WORM! where * is 2 to 11 |
 |
SHAProc.exe |
SHAProc
Added by the WINKO.AO WORM! |
 |
Shareaza.exe |
Shareaza
Shareaza P2P client |
 |
sharedprem.exe |
sharedprem
Added by the MAKECALL TROJAN! |
 |
SharpTray.exe |
SharpTray
Part of Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents" |
 |
shdef.exe |
shdef
Added by the VB-DVS TROJAN! |
 |
svchst.exe |
SheduIer
Premium rate adult content dialler |
 |
shch.exe |
SheduIer
Added by the EB TROJAN! |
 |
svchost.exe |
Shell
Added by the GOLDSPY-B TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
Shell32.exe |
Shell
Added by the BADSECTOR TROJAN! |
 |
svcnet.exe |
Shell API32
Added by the TIBICK.C WORM! |
 |
spollsv.exe |
Shell Extension
Added by the LOVGATE.Z WORM! |
 |
ShellTraywnd.exe |
Shell Tray Window
Added by the STULTDOR-A TROJAN! |
 |
shellexec.exe |
shell update
Added by the AGOBOT-TH WORM! |
 |
Shell.exe |
Shell.exe
Added by the EMERLEOX.S WORM! |
 |
Shell32.vbs |
Shell32
Added by the SCAFENE WORM! |
 |
SHELLMSN.EXE |
ShellApi
Added by the NETDEV.B TROJAN! |
 |
Shellapi32.exe |
Shellapi32
Added by the NETDEVIL (or NERTE) TROJAN! |
 |
Shelldaemon.exe |
Shelldaemon
Added by a variant of the AGENT.ALN TROJAN! |
 |
ShellEx.exe |
ShellEx
Added by the ANAKHA TROJAN! |
 |
spools.exe |
Shellspl
Added by the PROXAGE-A TROJAN! |
 |
shellsystem.exe |
shellsystem
Added by the UPCHAN TROJAN! |
 |
shhost.exe |
shhost
Added by the AGENT.CE TROJAN! |
 |
shicoxp.exe |
shicoxp
Installed with the drivers for multi card readers of various brands. To differentiate between the various card slots on multi slot readers the shicoxp.exe file assigns and loads unique drive icons for the various card slots that are displayed in Windows Explorer |
 |
shield.exe |
Shield Security
Added by the RIZO.A TROJAN! |
 |
shield32.exe |
Shield32 Security
Added by the RIZO.A TROJAN! |
 |
Shine.exe |
Shine
Added by the HAPPYLOW (or NISHE-A) VIRUS! |
 |
shinitv.exe |
SHINITV
?? |
 |
SmReminder.exe |
ShockmachineReminder
"Shockmachine is a stand-alone application that lets users collect Macromedia Shockwave and Flash titles and play them offline". Could be a registration reminder for the trial version |
 |
SWINIT.EXE |
Shockwave Init
Part of Macromedia Shockwave. Controls the Shockwave Remote Control Panel. The Remote Control can be activated manually from the Start Menu by locating and selecting Shockwave and then Shockwave Remote under Programs |
 |
ShopSafe.exe |
ShopSafe
Created by Orbiscom for MNBA (now Bank of America) - ShopSafe creates a temporary card number each time you make an online purchase |
 |
SHORTKEY.EXE |
ShortKeys 99
ShortKeys from Insight Software Solutions - allows you to program keys with text strings |
 |
shklite.exe |
ShortKeys Lite
ShortKeys Lite from Insight Software Solutions, Inc. A macro utility to automate a task that you perform repeatedly or on a regular basis |
 |
sHotKey.exe |
sHotKey
Special function key manager for Chicony keyboards - see here |
 |
SHOWBEHIND.EXE |
Showbehind
Advertisement display which can be stopped here |
 |
ShowFF.exe |
ShowFF
FFToolBar adware toolbar |
 |
shwicon.exe |
ShowIcon_Justrams_USB Product Driver v2.12r012
Related to Just Rams USB product driver. Is it required? |
 |
shwicon.exe |
ShowIcon_PNY_PNY Attach
PNY Attach? USB flash memory stick System Tray icon - shows when the device is plugged in |
 |
shwicon.exe |
ShowIcon_SmartDisk Corporation_USB Card Reader v1.14e051
Card reader for memory cards from digital cameras. Is it required? |
 |
ShowWnd.exe |
ShowWnd
Found on Gateway computers (and maybe others) - see here. "Showwnd is included with the Chicony keyboard software and is used by the software to stop the keyboard driver's taskbar entry from reappearing. It is not necessary to remove the keyboard software, however if you wish it can be removed through Add or Remove Programs" |
 |
SHPC32.exe |
SHPC32
Port monitor for Lexmark printers on a USB connection. Ties in with the Printer Control Program. Features like cancelling a print are unavailable if disabled |
 |
SHSTAT.EXE |
ShStatEXE
From McAfee VirusScan NT 4.x. Handles program communication among VShield components, displays VShield icon. Can be started automatically or available via Start -> Programs |
 |
shutdownaware.exe |
Shutdownaware
Loaded by the SWEEX 6-in-1 Media Card Reader to properly manage the reader while it is connected to your system |
 |
ShutDownPro.exe |
ShutDownPro
ShutDownPro - shutdown, reboot, logoff your System with one mouse click |
 |
SIMETER.EXE |
Si Meter
Si Meter - keep track of things like CPU activity, network activity and speed, hard-drive activity, hard-drive space, system memory, running processes, or just date and time |
 |
SIA2006.exe |
SIA2006
Part of Steganos Internet Anonym privacy software |
 |
sia.exe |
SIAPRO6
Steganos Internet Anonym privacy software |
 |
Sicom.exe |
Sicom
Added by the NETLIP WORM! |
 |
SideACT.exe |
SideACT
SideACT organizer software |
 |
Sidebar.exe |
Sidebar
Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. But on other versions of Windows it can be a part of the Searchcentrix hijacker |
 |
SWTrayV4.exe |
SideWinderTrayV4
MS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs |
 |
SightSpeed.exe |
SightSpeed
SightSpeed Video Chat - "lets you connect with all your friends and family easily. Make video calls, phone calls, and send video mails and text messages to everyone in your network, anywhere in the world" |
 |
setup.exe |
SigmaTel Audio
Sigmatel audio driver |
 |
stsystra.exe |
SigmatelSysTrayApp
System tray program for the Sigmatel Audio sound card. Often found on Dell computers |
 |
sttray.exe |
SigmatelSysTrayApp
System tray program for the Sigmatel Audio sound card. Often found on Dell computers |
 |
sigx.exe |
SigX
?? |
 |
SigX.exe |
SigXC
SigX is a "dynamic signature image generated based on whatever data your computer sends it though our SigX program. It can display your current Mp3, current OS, Free Ram, your current time and more" |
 |
SimcastAlerts.exe |
Simcast
Simcast is a free service that allows you to subscribe to information on a large variety of topics. Alerts will appear on your desktop when a channel that you have subscribed to has something to say |
 |
SimplifyMedia.exe |
Simplify Media
Simplify Media media manager - "enjoy songs from home while at work or from any WiFi location. Explore friends' music while they are online" |
 |
SimpLite-MSN.exe |
SimpLite-MSN
Required if you use the SimpLite add-on to MSN Messenger (SimpLite adds encryption to the instant messaging service) |
 |
singapore.exe |
Singapore
Adds a blue crescent to the taskbar and when double-clicked displays an adult-content web-site. Also known to drop your internet connection and dial an international telephone number. See here for more information. Must be disabled in MSCONFIG before un-installing or it re-instates itself |
 |
SipDiscount.exe |
SipDiscount
FreeCall - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype |
 |
SIPPSSIPPS.exe |
SIPPS
Web.de Internet phone utility |
 |
sistray.exe |
SiS Tray
System Tray icon for SiS based graphics. Note - this resides in C:WindowsSystem |
 |
SiSAudUt.exe |
SiS7012Utility
SiS Corporation sound card driver |
 |
SISAM10M.exe |
SISAM10M
?? |
 |
siService.exe |
siService.exe
Spam Inspector - anti email spam software |
 |
SRaid.exe |
SiSRaid
Related to the SIS Raid system from Silicon Integrated Systems |
 |
SiSSetCDfmt.exe |
SiSSetCDfmt
Related to a Silicon Integrated Systems Corp (SiS) product? |
 |
Soundman.exe |
SISSoundman
Related to a Silicon Integrated Systems Corp (SiS) product? |
 |
sisswled.exe |
SiSSWLED
System Tray utility for SiS 900 network cards |
 |
sistrai.exe |
sistrai.exe
Added by the PROVA TROJAN! |
 |
sistray.exe |
sistray
Added by the PROVA TROJAN! |
 |
sistray.exe |
sistray
System Tray icon for SiS based graphics. Note - this resides in C:WindowsSystem |
 |
sistry.exe |
sistry
Added by the CEBE WORM! |
 |
SiSUSBrg.exe |
SiSUSBRG
SiS USB Registry Patch File - fixes the undetectable problem with SiS USB controller on Windows XP |
 |
SiteAdv.exe |
SiteAdvisor
SiteAdvisor from McAfee warns you before you interact with a dangerous Web site |
 |
sscc.exe |
sixer566
Added by an unidentified WORM or TROJAN! |
 |
sixtypopsix.exe |
sixtysix
Medload adware |
 |
SK51.EXE |
SK51
SaveKeys keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
SK60.EXE |
SK60
SaveKeys keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
SK9910DM.EXE |
SK9910DM
Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys |
 |
SKDAEMON.EXE |
SKDAEMON
Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys |
 |
skinkers.exe |
skinkers
Selection of desktop messaging/marketing tools with celebrity tie-ins including MTV's "Desktop Ozzy" and Arsenal's "Desktop Wenger" - see here. Leave enabled if you want to receive messages |
 |
Skra.exe |
Skra
Identified as a variant of the TrojanDownloader.Matcash malware |
 |
SKS32P~1.EXE |
sks-32
SpyKeySpy logs keystrokes and sends the stolen information to a configurable email address |
 |
Skunk.exe |
Skunk
Added by the SUNK-A WORM! Note - this file is found in the root folder (C:), (D:), etc |
 |
SSFSch.exe |
SkyBlaster Scheduler
For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system |
 |
skynetave.exe |
skynetave.exe
Added by the SASSER.D WORM! |
 |
Skype.exe |
Skype
"Skype is free and simple software that will enable you to make free calls anywhere in the world in minutes" |
 |
skyp.exe |
Skype Startup
Added by the VANBOT-C WORM! |
 |
SkypeMate.exe |
SkypeMate
SkypeMate acts as a bridge between networks of VoIP and PSTN |
 |
Skype.exe |
SkypeStartup
Added by the PYKSE-A WORM! |
 |
SmaServ.exe |
SkySurfer Management Service
For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system |
 |
SkyTel.exe |
SkyTel
Process associated with Realtek Voice Manager for some of their audio chipsets |
 |
slay7383.exe |
Slayhacker734
Added by the SIKBOT-A TROJAN! |
 |
SleepMgr.exe |
SleepManager
This program locates free contiguous disk spaces and allocates them for storing BASE MEMORY, EXTENDED MEMORY, VIDEO MEMORY, and SM RAM. It helps the computer come out of hibernate mode |
 |
Sliber.EXE |
Slibe.com
Sliber - freeware screen capturing & online sharing tool |
 |
sr.exe |
SlickRun
"SlickRun is a floating command line utility for Windows. It gives you almost instant access to any program or website. SlickRun allows you to create command aliases (known as MagicWords), so C:Program FilesOutlook Expressmsimn.exe becomes MAIL" |
 |
SliMP3 Server.exe |
slimp3
Slimp3 Server - "presents an entirely new way of accessing and enjoying your music collection. Instead of storing your music on CDs or memory cards, the SliMP3 uses your home network to access the music stored on your PC" |
 |
SLINGS~1.EXE |
Slingshot
Atomica Slingshot - "reference tool with access to dictionary and encyclopedia terms, bios, technical terms, history, geography, and much more". Now superseed by 1-Click Answers |
 |
slipcore.exe |
slipcore
Core module for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet, Wanadoo, Terra, OnSpeed, United Online and AOL Canada. Required if the user's account is locked in to that proxy server |
 |
slipgui.exe |
slipgui
User interface for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet, Wanadoo, Terra, OnSpeed, United Online and AOL Canada. Required if the user's account is locked in to that proxy server |
 |
slipcore.exe |
SlipStream
Core module for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet, Wanadoo, Terra, OnSpeed, United Online and AOL Canada. Required if the user's account is locked in to that proxy server |
 |
slmss.exe |
slmss
SeekSeek search hijacker related - see here |
 |
sload.exe |
sload
Win SynchroAd adware, also detected as DLOADER-QG TROJAN! |
 |
slvchost32.exe |
slvchost32
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
sa_exe.exe |
sm
Added by the OLFEB.A TROJAN! |
 |
sf_exe.exe |
sm
Added by the OLFEB.A TROJAN! |
 |
sm_exe.exe |
sm
Added by the OLFEB.A TROJAN! |
 |
sr_exe.exe |
sm
Added by the LUKUSPAM TROJAN! |
 |
SM1BG.EXE |
SM1BG
USB driver for downloading from within Napster and iTunes to portable MP3 players. Only required at startup if you use it all the time - otherwise start it manually when required |
 |
SM1NINT.exe |
SM1NINT
Cypress USB Mass Storage Driver Notification Icon Application - tray notification for Cypress base memory sticks and external storage devices for Win98 |
 |
sm56hlpr.exe |
SM56 Helper Win32 Utility
Helper utility for Motorola based SM56 software modems - resides in the System Tray |
 |
sm56hlpr.exe |
Sm56acl
Helper utility for Motorola based SM56 software modems - resides in the System Tray |
 |
smanager.*.exe [* = digit] |
SManager
Added by the AGENT.BJO TROJAN! |
 |
smanager.7.exe |
SManager
Added by the DWNLDR-GVG TROJAN! |
 |
smtray.exe |
Smapp
System Tray access for the Compaq/ADI SoundMAX integrated digital audio controller |
 |
ScardSvr.exe |
Smart Card Service
For Smart Card readers. Known to cause problems, especially for Windows 2000 users - see here. Probably not required unless you use such a device regularly |
 |
SCMon.exe |
Smart Connect Monitor
Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio |
 |
SCSetup.exe |
Smart Connect Setup
Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio |
 |
Smartkbd.exe |
Smart Keyboard
Netropa Smart Keyboard driver |
 |
ssloserv.exe |
Smart Label O Server
Part of the printer software for the smart-label printer made by Seiko. Can be disabled safely |
 |
SSLFVIEW.EXE |
Smart Label RFViewer
Part of the printer software for the smart-label printer made by Seiko. Can be disabled safely |
 |
STouch.exe |
Smart Touch
Related to Plustek OpticSlim scanner |
 |
sta.exe |
Smart Type Assistant
Smart Type Assistant - a complex typing automation tool, intended to make your work faster and safer |
 |
SmartAudio.exe |
SmartAudio
Conexant SmartAudio PC audio chipset software - typically available on HP notebooks with built-in microphones |
 |
SmartBarXP.exe |
SmartBarXP
SmartBarXP is a bar that runs down the side of your screen, and can be configured to display interactive panels known as 'panes'. These panes include media players, slideshow and image viewing panes, a virtual desktop manager, and live news, weather and stock feeds to mention but a few |
 |
SMARTC~1.EXE |
sMaRTcaPs
sMaRTcaPs from Phoebus LLC - enables you to configure the time needed to depress Caps Lock, Num Lock & Insert keys |
 |
SmartSync.exe |
SmartSync Pro
Related to CompanionLink Software Inc. Synchronization solutions for ACT!, GoldMine, Lotus Notes and Microsoft Outlook |
 |
SMax4.exe |
SMax4
System Tray icon for SoundMax integrated sound. Sound properties can be accessed through the Start Menu or Control Panel |
 |
SMax4PNP.exe |
SMax4PNP
SoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments |
 |
smbdpmi.exe |
smbdpmi
IBM Netfinity Director and Universal Management Services related. What does it do and is it required? |
 |
smc.exe |
smc
Sygate Firewall |
 |
spfsmc.exe |
smc
Sygate Firewall |
 |
smc.exe |
SMC Service
Sygate Firewall |
 |
spfsmc.exe |
SMC Service
Sygate Firewall |
 |
smc.exe |
SmcService
Sygate Firewall |
 |
smc.exe |
SmcServices
Sygate Firewall |
 |
spfsmc.exe |
SmcServices
Sygate Firewall |
 |
smcss.exe |
smcss
Added by the SCLOG-AJ TROJAN! |
 |
Smcsta.exe |
Smcsta.exe
SMC Networks wireless PCI card driver. Is it required? |
 |
SmcSVR.exe |
SmcSVR
Added by the LEGMIR.JU TROJAN! |
 |
smgr.exe |
smgr
Added by an unidentified WORM or TROJAN! |
 |
SmileboxTray.exe |
SmileboxTray
System Tray access to Smilebox photo sharing/printing service |
 |
smiptray.exe |
Smith Micro try
Smith Micro shared files. Comes with D-Link web cam |
 |
smodule.exe |
smodul
UserMonitor from Neuber. Teachers can broadcast screen to other screens, see students screens in a network and detect unauthorized software |
 |
SmoothView.exe |
SmoothView
TOSHIBA Zooming Utility - allows "automatic" zoom feature in some appications, like IE, MS-Office, WMPlayer, Adobe Reader and also desktop icons |
 |
smpdemo.exe |
SMPAutoStart
Smart Phone Recorder demo from KenGolf.com. Answering Machine, Caller ID, Call Recording |
 |
SmpSys.exe |
SmpcSys
"Set Up My PC" utility supplied with some Packard Bell computers |
 |
smres.exe |
smres
Added by the AGOBOT-UA WORM! |
 |
SmsSystem32.exe |
Sms System32
Unidentified malware |
 |
SMSMsg.exe |
SMS Win9x Message Agent
This program assigns a user to a Systems Management Server site |
 |
SmsDiscount.exe |
SmsDiscount
SmsDiscount - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype |
 |
sm56hlpr.exe |
Smserial
Helper utility for Motorola based SM56 software modems - resides in the System Tray |
 |
shellexcon.exe |
SMSERIALWORKERSTART
Detected by McAfee as the FAKEALERT-AH TROJAN! See here. Installed with the SpyBurner spyware remover - which is not recommended, see here |
 |
SMLoader.exe |
SMSI Loader
Smith Micro HotFax - fax software |
 |
smsm.exe |
smsm
Added by the BANKER-CO TROJAN! |
 |
smsrv.exe |
smsrv
Added by the AGOBOT-SX WORM! |
 |
smss.exe |
SMSS
Added by the FLOOD.F TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "Catroot" subfolder |
 |
smss.exe |
smss
Added by the AGENT-TR TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
smss.exe |
smss
Added by the BOROBOT-J TROJAN and variants! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup! |
 |
ssms.exe |
Smss
Added by the RBOT.OP WORM! |
 |
smhost.exe |
Smss Host
Added by the IRCBOT-ACC TROJAN! |
 |
smss.exe |
smssLevel4
Unidentified malware! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in Program FilesWindows Media PlayerSkinsWindowsMediaSkinDataLevel4 folder |
 |
smsss.exe |
SMSSS
Added by the SDBOT.ZD WORM! |
 |
smsss.exe |
SMSSS Loader
Added by the AGOBOT.MQ WORM! |
 |
SMSSU.EXE |
SMSSU
Hijacker, detected by Norton antivirus as Trojan.StartPage.O |
 |
SMSystemAnalyzer.exe |
SMSystemAnalyzer
Part of the Iolo System Mechanic optimization tool |
 |
sms_msn.exe |
sms_msn
Added by an unknown WORM or TROJAN! |
 |
sms_msn40.exe |
sms_msn40
Added by an unknown WORM or TROJAN infection |
 |
SMT.exe |
Smt
Win-Spy keyboard logger/monitoring software - remove unless you installed it yourself |
 |
SMToolbar.exe |
SMToolbar
StartMake.com toolbar |
 |
smtp32.exe |
SMTP32 Mailing Protocol
Added by a variant of the RBOT WORM! |
 |
SmWizard.exe |
SmWizard
SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required? |
 |
SnagIt32.exe |
SnagIt 8
"SnagIt lets you capture, edit, and share exactly what you see on your screen - fast" |
 |
SnapfishMediaDetector.exe |
Snapfish Media Detector
Snapfish Media Detector - "Upload your photos to Snapfish, where you can store and share your photos for free on line" |
 |
SnapfishMediaDetector.exe |
SnapfishMediaDetector
Snapfish Media Detector - "Upload your photos to Snapfish, where you can store and share your photos for free on line" |
 |
snapple.exe |
snapple
Added by the FORBOT-EG WORM! |
 |
snbr.exe |
snbr
?? |
 |
snbupt.exe |
snbupt
UpSpiralBar adware |
 |
sncntr.exe |
sncntr
Added by the DLUCA-I TROJAN! |
 |
sndvolumes.exe |
SND Volumes
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
snd332.exe |
snd332
Added by the B1LD0 AIM WORM! |
 |
Sndcompat.exe |
Sndcompat
Added by the GEMA TROJAN! |
 |
SNDMon.exe |
SNDMon
Part of Symantec's LiveUpate (eg, Norton). Not required if you run manual updates but probably require if you leave them to run automatically. Also, if one runs a small office network and SNDMon is disabled on one of the computers ? then other computers disappear from the network for this computer, including shared devices like printers and scanners. Hence the "U" recommendation |
 |
Sndsaver.exe |
Sndsaver
Added by the GEMA TROJAN! |
 |
SNDSRVC.EXE |
sndsrvc
Part of Norton Personal Firewall and Norton Internet Security - what does it do and is it required? |
 |
SnippingTool.exe |
Snippet
The Snipping Tool (part of the Experience Pack for Tablet PC) allows you to easily "cut out" anything on screen and share it with other people. The whole screen becomes an "inkable" surface that you can add comments to and mark up however you like. You can then save that annotated image to use later, or send it to someone else in an E-mail message |
 |
SNM.exe |
SNM
SpyNoMore anti-spyware |
 |
SnoopFreeUI.exe |
SnoopFreeUI
Anti-keylogging software made by SnoopFree Software |
 |
svchost.exe |
SNP Generic Host Process
Added by the ZAPCHAS-O TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
 |
Snsicon.exe |
Snsicon
Launches a screensaver program from Second Nature |
 |
SNSS.EXE |
SNSS.EXE
Added by the Nunci premium rate dialer |
 |
snvc.exe |
snvc
Added by an unidentified WORM or TROJAN! |
 |
sointgr.exe |
SO5 Integrator Pass One
StarOffice 5. See here for more details |
 |
sointgr.exe |
SO5 Integrator Pass Two
StarOffice 5. See here for more details |
 |
sock32.exe |
Sock32
Added by the SDBOT TROJAN! |
 |
svchostz.exe |
Socket Utility
Added by the DAEMONI-E TROJAN! |
 |
socket.exe |
Socket Utility
Added by the DAEMONI-E TROJAN! |
 |
SodaStartup.exe |
SoDA Startup
Used by the IBM Rational SoDA project management tool. Unsure of it's actual purpose but it's recommended you leave it enabled if you use the software |
 |
SOFFICE.EXE |
soffice
Displays StarOffice quick start applet in System tray. Right clicking on the icon allows rapid starting up of components of the StarOffice 6.0 suite. Available via Start -> Programs. Automatically started when any StarOffice 6.0 component is started from the Start -> Programs. A resource hog (it eats > 16 MB of memory). |
 |
SFTTray.exe |
SoftGridTray
System Tray access to SoftGrid from Microsoft - "the only virtualization solution that delivers applications that are never installed and dynamically delivered, on demand" |
 |
softstrt.exe |
SoftStuff Wallpaper Changer
AzureBay wallpaper changer |
 |
software.exe |
Software
Added by the CRABTON-B TROJAN! |
 |
Spyware Soft Stop.exe |
Software Soft Stop
SoftStop misleading security software - not recommended, see here |
 |
station.exe |
SoftwareStation
eAcceleration Stop-Sign security software related. Previously not recommended, see here |
 |
swBOEngine.exe |
SolidWorks Task Scheduler Engine
Task scheduler for SolidWorks 3D CAD software |
 |
Solosent.exe |
Solo Sentry
Solo Antivirus |
 |
Solocfg.exe |
SoloSchedule
Scheduler for Solo Antivirus. Leave enabled unless you scan manually on a regular basis |
 |
Syscheck.exe |
SoloSysCheck
Solo antivirus System Integrity Check - Monitors system registry, system.ini, win.ini and startup to protect you from new Internet Worms and Backdoors |
 |
somatic.exe |
somatic
Searchcentrix hijacker |
 |
scit.exe |
some
Netproject malware |
 |
smsc.exe |
Sonic RecordNow!
Added by a variant of the SDBOT WORM! |
 |
SFIGUI.EXE |
SonicFocus
Sonic Focus - "enhances music, movie and game sound by analyzing compressed audio streams in realtime, then restoring and enriching audio back to its original performance qualities" |
 |
sqstart.exe |
SoniqueQuickStart
Quickstart for the discontinued Sonique audio player. Available via Start -> Programs |
 |
SonnReg.exe |
SonnReg
Now superseeded by ColorWizzard - 3Deep corrected lighting, shading and color for all your 2D and 3D games. Possibly a registration reminder? |
 |
SonudMan.exe |
SonudMan
Added by the STARTPAGE.Q TROJAN! |
 |
SonudMon.exe |
SonudMon
Added by the LEWOR-J TROJAN! |
 |
SPMgr.exe |
SonyPowerCfg
Related to Sony VAIO Power Management Module installed on laptops and provides additional configuration options for these devices. This program is non-essential process to the running of the system, but should not be terminated unless suspected to be causing problems |
 |
sophagnt.exe |
sophagnt
Possibly related to Sophocles Screenwriting Software? |
 |
SOS.exe |
SOS
Added by the PHILIS VIRUS! |
 |
SoSyncMonitor.exe |
SoSyncMonitor
SuperOffice related. What does it do and is it required? |
 |
sndloader.exe |
Sound Loader
Added by the AGOBOT-BV WORM! |
 |
SOUND32.EXE |
Sound services
Added by the AGOBOT.GG WORM! |
 |
svchosI.exe |
Sound Volume
Added by a variant of the IRCBOT TROJAN! See here |
 |
soundcontrl.exe |
soundcontrl
Added by the GAOBOT.AFJ WORM! |
 |
sndbdrv3104.exe |
sounddrv
CoolWebSearch parasite variant |
 |
SVOHOST.exe |
SoundMam
Added by the QQROB-AAL TROJAN! |
 |
soundman.exe |
soundman
System Tray icon for the Realtek AC97 Audio Sound Manager for AC97 onboard audio. Available via Start -> Settings-> Control Panel |
 |
soundman.exe |
SoundMan
Added by the AGOBOT.HM WORM! Note - this is not the legitimate SiS or Realtek file of the same name that is located in the Windows or WINNT directory |
 |
soun.pif |
SOUNDMAN Microsoft Help
Added by the RBOT-AIU WORM! |
 |
SMax4.exe |
SoundMAX
System Tray icon for SoundMax integrated sound. Sound properties can be accessed through the Start Menu or Control Panel |
 |
SoundMAX.exe |
SoundMAX
Added by the RIZON-A WORM! Note - this file is placed in the Startup folder itself, and has NO relation to SoundMax sound cards! |
 |
SndMAX.exe |
SoundMax Audio Drivers
Added by a variant of the SDBOT WORM! |
 |
SMax4PNP.exe |
SoundMAXPnP
SoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments |
 |
soundmix.exe |
soundmix
Added by the AGENT.PGV WORM! |
 |
smvss.exe |
SoundMixer
Added by the DEDLER-G TROJAN! |
 |
Soundmx.exe |
Soundmx
CoolWebSearch Tapicfg parasite variant |
 |
soundtask.exe |
soundtask
Added by the AGOBOT-MD WORM! |
 |
soundtasks.exe |
soundtasks
Added by a variant of the CRYPTER.C TROJAN! |
 |
soundtctrls.exe |
soundtctrls
Added by the AGOBOT-ZV WORM! |
 |
sounofts.exe |
sounofts
Added by the AGOBOT-ND WORM! |
 |
sountaskmgr |
sountskmanager
Added by an unidentified WORM or TROJAN! |
 |
sp.reg |
sp
IE search hijacker - changes the default search to http://www.gocybersearch.com/ |
 |
se.dll, DllInstall |
sp
Added by the Startpage.M hijacker |
 |
SP TimeSync.exe |
SP TimeSync
SP TimeSync lets you synchronize your computer's clock with any Internet atomic clock (time server) |
 |
Sp00lsv.exe |
SP00LSV
Added by the GRAYBIRD.E TROJAN! |
 |
SP2ConnPatcher.exe |
SP2 Connection Patcher
Changes limit of concurrent TCP connections of Windows Service Pack 2 |
 |
sp2chk.exe |
sp2chk.exe
Added by the ALUROOT.A TROJAN! |
 |
sp2ctr.exe |
sp2ctr
Added by the DLUCA-M TROJAN! |
 |
sp2fwxp.exe |
sp2fwxp
Added by the SMALL.ABW TROJAN! |
 |
sp2svc.exe |
sp2svc
Added by a variant of the RBOT WORM! |
 |
sp2update.exe |
sp2update
SP2Update adware! Tracks URLs visited and search terms entered into Internet Explorer |
 |
SBInst.exe |
Spam Blocker for Outlook Express
Hotbar adware |
 |
SpamSleuth.exe |
Spam Sleuth
Spam Sleuth E-mail spam detection program |
 |
SbOEAddOn.exe |
SpamBlocker
Hotbar adware |
 |
SFAgent.exe |
SPAMfighter Agent
SPAMfighter anti email spam filter |
 |
spamihilator.exe |
spamihilator
Spamihilator - spam filter |
 |
spampal.exe |
SpamPal
SpamPal - anti-spam tool |
 |
SpamSubtract.exe |
SpamSubtract
Intermute SpamSubtract - junk email detection and removal program |
 |
SpamSub.exe |
spamsubtract
InterMute™ SpamSubtract - junk email detection and removal program. InterMute™ is now part of Trend Micro and their products are no longer supported |
 |
SpareBackup.exe |
Spare Backup
Spare Backup - "Once Spare Backup is installed, backups are automatic. With Spare Backup it's easy, you don't even have to select files for backup, Spare Backup does it for you" |
 |
Spark.exe |
Spark
Spark instant messaging client |
 |
SparVoip.exe |
SparVoip
SparVoip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype |
 |
Spdstart.exe |
Spdstart
Norton Utilities Speed Start. "This feature optimizes the start up speed of launching applications, such as Word and Excel." |
 |
SpClDlx.exe |
Speaking Clock Deluxe
Speaking Clock Deluxe - turns your computer into a speaking clock with several languages. It can also keep track of up to 50 alarms that can be set to a time and a date, and be repeated daily, weekly, monthly and yearly |
 |
SpecialOffers*.exe [* = digit] |
SpecialOffers
SpecialOffers adware |
 |
SpecialOffers.exe |
SpecialOffers
SpecialOffers adware |
 |
specixic.exe |
specific
Added by a variant of the SDBOT WORM! |
 |
speedtec.exe |
Speed Tec
Accel SpeedTec from Montana Software speeds up your modem. SpeedTec modifies the Internet Protocol settings in the Windows registry to speed downloads on all modems. If you find this improves your connectivity and download speeds leave this enabled |
 |
SPEEDITUP.EXE |
SpeedItUp
Speed It Up - "all in one Speed Booster designed to significantly increase the speed of your computer and boost your PC available memory" |
 |
SPEEDITUP.EXE |
SpeedItUp
Installs PC-Checkup and Search Defender (which is detected by DrWeb as the STARTPAGE.ORIGIN TROJAN) without permission |
 |
SpeedItUpEx.exe |
SpeedItUpEX
"Speed-It-Up Extreme is designed to speed of your computer up to 3 times faster and boost your PC available memory" |
 |
SPEEDKEY.EXE |
Speedkey
Additional keyboard shortcuts on MS programmable keyboard |
 |
SpeedMeter.exe |
SpeedMeter
Application measuring upload and download speed |
 |
spo.exe |
SpeedOptimizer
SpeedOptimizer is designed to optimize and speed-up your Internet data transmission including browsing, streaming, downloading, uploading and e-mail communication |
 |
SpeedRunner.exe |
SpeedRunner
Identified as a variant of the TrojanDownloader.Matcash malware |
 |
SpeedswitchXP.exe |
SpeedswitchXP
SpeedswitchXP is a CPU frequency control for notebooks running Windows XP |
 |
speedupmypc.exe |
SpeedUpMyPC
Older version of SpeedUpMyPC from Uniblue - which "lets you monitor and control all your PC resources with easy, one click instructions. System settings, internet usage, disk clutter, RAM and CPU are all automatically scanned, cleaned and optimized for peak performance" |
 |
speedy.scr |
Spees1
Added by the OPASERV.Y WORM! |
 |
Speedy.bat |
Spees2
Added by the OPASERV.AD WORM! |
 |
SPEEDY.PIF |
Spees3
Added by the OPASERV.AD WORM! |
 |
sa.exe |
Spellex Anywhere
Spellex-Anywhere - adds spell checking functionality to almost any Window program. Create a shortcut and run manually before it's to be used |
 |
spicetray_silent.exe |
Spiceworks
System Tray access to Spiceworks - which "combines everything you need to manage IT in one easy-to-use application" |
 |
spiderml.exe |
SpIDerMail
DrWeb antivirus Spider Mail e-mail scanner |
 |
spinner.exe |
Spinner Plus
"Spinner Plus lets you listen to over 100 channels of music broadcast from Spinner.com. Spinner Plus uses RealNetwork's G2 technology to provide high-quality online audio. The technology adjusts the audio streaming to match your Internet connection speed, which helps eliminate sound distortion or choppiness". Available via Start -> Programs |
 |
SPnt.exe |
SPnt
Premium rate adult content dialler |
 |
SpokeSysTray.exe |
SpokeSysTray
Spoke Software client application. Spoke "uses data in your e-mail and other enterprise information systems to discover the existing relationships of people in your enterprise. It then builds a private, secure relationship network for each user without any additional manual data entry" |
 |
spoo1sv.exe |
spoo1sv
Added by the SOULJET TROJAN! |
 |
spoolsvc.exe |
SPOOL Configuration
Added by the SDBOT-KD WORM! |
 |
spool.exe |
Spool Loader
Added by a variant of the RBOT WORM! |
 |
spoolv.exe |
Spool LoadKIt
Added by a variant of the RBOT WORM! |
 |
spool.exe |
Spool lptt01
RapidBlaster variant (in a "spool" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
spoolsrv.exe |
Spool Manager
Added by the BANKER-FR TROJAN! |
 |
spool.exe |
Spool ml097e
RapidBlaster variant (in a "spool" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
smhost.exe |
Spooler Host
Detected by PCTools as the IRCBOT.BSQ TROJAN! See here |
 |
Spoolsrv.exe |
Spooler Service
Added by the JOINER.C1 TROJAN! |
 |
spoolsub.exe |
Spooler Subsystem
Added by the SDBOT-ABG TROJAN! |
 |
spoolsvc.exe |
Spooler SubSystem App
Added by the POEBOT-J WORM! |
 |
spooIsv.exe |
Spooler SubSystem App
Added by the LINKBOT.M WORM! |
 |
spoolsvc.exe |
Spooler SubSystem Application
Added by the DLOADER-NY TROJAN! |
 |
svcadmin.exe |
Spooler SubSystem Application
Added by the DLOADER-NY TROJAN! |
 |
svcman.exe |
Spooler SubSystem Application
Added by the DLOADER-NY TROJAN! |
 |
svcrun.exe |
Spooler SubSystem Application
Added by the DLOADER-NY TROJAN! |
 |
spoolsvc.exe |
Spooler Subsytem App
Added by the SDBOT-MM WORM! |
 |
SpooI32.exe |
SpoolerSubSystemProcess
Added by the EHKS.21 keylogger! Note - the "I" between "o" and "3" is a capital "i" not a lower case "L" |
 |
spoolms.exe |
spoolms
Added by the LEGMIR-ARO TROJAN! |
 |
spools.exe |
Spools Service Controller
Added by the KASSBOT-C WORM! |
 |
spoolserv.exe |
spoolserv
Added by the SDBOT-PN WORM! |
 |
spolsv.exe |
SpoolService
Added by the AGOBOT-CS WORM! |
 |
spoolsrv.exe |
spoolsrv.exe
Added by an unidentified WORM or TROJAN! Located in %System% |
 |
Spoolsv.exe |
Spoolsv
Added by the CIADOOR.121 VIRUS! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir% |
 |
scvhosts.exe |
spoolsv
Added by the SMALL-AW TROJAN! |
 |
svchost.exe |
spoolsv
Added by the DLOADER-FI TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "HELP" subfolder of the Winnt or Windows folder |
 |
spoclsv.exe |
spoolsv
Added by the FUJACKS-M WORM! |
 |
spoolsv.exe |
spoolsv
Added by the ZAPCHAS-EE TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%\Temp\spoolsv |
 |
spoolvs.exe |
spoolsv
Identified by Kaspersky antivirus as a variant of the QHOST.AES TROJAN! |
 |
SpoolMgr.exe |
spoolsv manager
Added by the ASSIRAL WORM! |
 |
spoolsv32.exe |
spoolsv service
Added by the RBOT-AHP WORM! |
 |
SPOOLSV32.EXE |
SPOOLSV32
Added by the CWS-I or HAZIF-B TROJANS! |
 |
spoolsvc.exe |
spoolsvc
Added by the DROPPER-AT TROJAN! |
 |
spoolsvs.exe |
spoolsvs.exe
Added by the DLOADER-RK TROJAN! |
 |
SPOOLSVU.EXE |
SPOOLSVU
Added by the STARTPAGE.K hijacker |
 |
spoolsvv.exe |
spoolsvv
Searchcentrix hijacker |
 |
spoolvs.exe |
Spoolvs
Added by the SDBOT.AUS WORM! |
 |
Scmhlpr.vbs |
Spore.b
Added by the SPORE.B WORM! |
 |
sppbridge.exe |
sppbridge
Associated with an Anycom bluetooth wireless card on laptops - used for printing to portable printers for example. Is it required or can it be started manually? |
 |
SprintPortA.exe |
SprintPort
Novatel wireless modem related. What does it do and is it required? |
 |
SpriteService.exe |
SpriteService
Sprite Backup is a backup application for Windows Mobile Pocket PC or Smartphone |
 |
sproc32.exe |
Sproc32
Added by the SPROCIT TROJAN! |
 |
sprof.exe |
sprof
Detected by Kaspersky as the FRAUDLOAD.VATF TROJAN! See here |
 |
sprtcmd.exe |
sprtcmd
Self-help support tool for a number of high-speed internet providers and computer suppliers such as Comcast, Qwest and Dell. Identifies and automatically fixes typical problems that may occur with your high-speed internet service. Provided by SupportSoft, Inc |
 |
Spruce.exe |
Spruce - Auto Update
Rabio "Search Enhancer" adware variant |
 |
SmartProtectorPro.exe |
SPSTEALT
Smart Protector Pro - internet privacy tool that erases tracks, MRU lists, etc |
 |
storesp.exe |
spstore
Softprobe - program designed to provide managers with an analysis of an individuals computer use who are under their supervision. This program is NOT related to Winpup |
 |
spyblocker.exe |
Spy Blocker
SpyBlocker blocks the communications of spyware installed on a PC so spyware runs but can't exchange data with the server to which it should report. Ensuring spyware can't communicate is important, as you may find after using Ad-Aware that some applications containing spyware subsystems may not run correctly or at all |
 |
SpyProtector.exe |
Spy Protector
Included in the full version of Security Task Manager, Spy Protector prevents keyboard and mouse monitoring, warns when the registry is changed and eliminates internet activity and work traces |
 |
Spy-Control.exe |
Spy-Control
Spy-Control spyware remover - not recommended, see here |
 |
skl.exe |
Spy-Keylogger
SpyKeylogger keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
spyaway.exe |
SpyAway
SpyAway spyware remover - not recommended, see here |
 |
spyaxe.exe |
SpyAxe
SpyAxe spyware remover - not recommended, see here. For removal instructions see here |
 |
SpyBan.exe |
SpyBan
SpyBan spyware remover - not recommended, see here |
 |
SpyBlast.exe |
SpyBlast
Spyware killer that is in effect autoinstalled foistware, targeted by SpyBot, among others |
 |
spyblocker.exe |
SpyBlocker
SpyBlocker blocks the communications of spyware installed on a PC so spyware runs but can't exchange data with the server to which it should report. Ensuring spyware can't communicate is important, as you may find after using Ad-Aware that some applications containing spyware subsystems may not run correctly or at all |
 |
SpyBlocs.exe |
SpyBlocs
SpyBlocs spyware remover - not recommended, see here |
 |
SpyBlocs3.0.exe |
SpyBlocs3.0
SpyBlocs spyware remover - not recommended, see herea> |
 |
Spybotsd.exe |
SpyBotSnD
Spybot - Search & Destroy - free multi-spyware removal tool from Safer Networking Ltd. |
 |
spybott.exe |
Spybott lptt01
RapidBlaster variant (in a "Spybott" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
spybott.exe |
Spybott ml097e
RapidBlaster variant (in a "Spybott" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
SpyBurner.exe |
SpyBurner
SpyBurner spyware remover - not recommended, see here |
 |
SpyClean.exe |
SpyClean
SpyClean spyware remover - not recommended, see here |
 |
SpyEmergency.exe |
SpyEmergency
SpyEmergency security software from Netgate |
 |
SpyFighter.exe |
SpyFighterMonitor
SpyFighter spyware remover - not recommended, see here |
 |
spyguarder.exe |
SpyGuarder
SpyGuarder spyware remover - not recommended, see here |
 |
SpyHealer.exe |
SpyHealer
Spyware remover - not recommended, see here |
 |
SpyHeals.exe |
SpyHeals
Smitfraud variant |
 |
SpyHunter.exe |
SpyHunter
Enigma SpyHunter - not recommended, see note |
 |
Spykiller.exe |
Spykiller
Spyware remover - older versions are not recommended, see here |
 |
SpyLax.exe |
SpyLax
SpyLax spyware remover - not recommended, see here |
 |
SpyLocked.exe |
SpyLocked
SpyLocked spyware remover - not recommended, see here |
 |
SpyLocked 4.3.exe |
SpyLocked 4.3
SpyLocked spyware remover - not recommended, see here |
 |
SpyMaxx.exe |
SpyMaxx
SpyMaxx spyware remover - not recommended, see here |
 |
SpyMedic.exe |
SpyMedic
SpyMedic spyware remover - not recommended, see here |
 |
Spynuker.exe |
SpyNuker
A "spyware removal program" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers 'TrekData' and 'Blue Haven Media', who distribute spyware through ActiveX drive-by-download on web pages |
 |
SpyOnThisMonitor.exe |
SpyOnThis Monitor
SpyOnThis Monitor spyware remover - not recommended, see here |
 |
spydetector.exe |
spyprodetector
Spyware Process Detector misleading security software - not recommended |
 |
SpyPry.exe |
SpyPry
SpyPry spyware remover - not recommended, see here |
 |
Spy-Quake2.exe |
SpyQuake2.com
SpyQuake2 spyware remover - not recommended, see here |
 |
Spy-Rid.exe |
SpyRid
SpyRid spyware remover - not recommended, see here |
 |
SpySheriff.exe |
SpySheriff
SpySheriff malware |
 |
SpyShredder.exe |
SpyShredder
SpyShredder spyware remover - not recommended, see here |
 |
SpySpotter.exe |
SpySpotter
SpySpotter spyware remover - not recommended, see here |
 |
spystopper.exe |
SpyStopper
SpyStopper - blocks intrusive spyware, Web bugs, worms, scripts, advertisements, and cookies. Protects you from being profiled and tracked |
 |
SpySub.exe |
SpySubtract
SpySubtract - multi spyware removal tool |
 |
SpySweeper.exe |
SpySweeper
Spy Sweeper - detects and removes spyware |
 |
SpySweeperUI.exe |
SpySweeper
Spy Sweeper - detects and removes spyware |
 |
SpySweeperUI.exe |
SpySweeperEnterprise
User interface for Spy Sweeper Enterprise edition - "a centrally managed, scalable enterprise solution that provides best of breed protection against all types of malicious spyware, adware, and other harmful intruders" |
 |
SpyTrooper.exe |
SpyTrooper
SpyTrooper - malware posing as a spyware remover, see here |
 |
Spyware.exe |
Spyware
BPS spyware remover - not recommended, see here |
 |
SpywareBeGone.exe |
Spyware Begone
Spyware BeGone - spyware removal utility. Previously not recommended, see here |
 |
spydoctor.exe |
Spyware Doctor
Spyware Doctor spyware remover |
 |
swdoctor.exe |
Spyware Doctor
Spyware Doctor spyware remover |
 |
spywar~1.exe |
Spyware Guard Control Panel
"SpywareGuard provides a real-time protection solution against spyware" |
 |
swn2.exe |
Spyware Nuker
Spyware removal program by TrekBlue. Previously not recommended but the latest version was delisted here |
 |
SpywareNukerInstaller.exe |
Spyware Nuker Installer
Spyware removal program by TrekBlue. Previously not recommended but the latest version was delisted here |
 |
Shield.exe |
SpyWare Shield
Acronis Privacy Expert Spyware Shield prevents spyware and other suspicious programs from being installed on PCs |
 |
SpywareSlayer.Exe |
Spyware Slayer
Spyware Slayer spyware remover - not recommended, see here |
 |
Spyware Soft Stop.exe |
Spyware Soft Stop
SoftStop misleading security software - not recommended, see here |
 |
SpywareStormer.Exe |
Spyware Stormer
Spyware Stormer spyware remover - not recommended, see here |
 |
SpywareStriker.exe |
Spyware Striker Pro
Ascentive Spyware Striker Pro rogue spyware remover - not recommended, see here |
 |
SpywareSweeper.exe |
Spyware Sweeper
SpywareSweeper spyware remover - not recommended, see here |
 |
SpywareX.exe |
Spyware X-terminator
Spyware X-terminator - spyware remover |
 |
Spyware-Cop.exe |
Spyware-Cop
Spyware-Cop spyware remover - not recommended, see here |
 |
SpywareBomb.exe |
SpywareBomb
SpywareBomb spyware remover - not recommended, see here |
 |
SpywareBot.exe |
SpywareBot
SpywareBot spyware remover - not recommended, see here |
 |
spfprc.exe |
spywarefighterguard
Spyware Fighter - anti spyware program |
 |
sgmain.exe |
SpywareGuard
"SpywareGuard provides a real-time protection solution against spyware" |
 |
Spywareguard.exe |
Spywareguard lptt01
RapidBlaster variant (in a "Spyguard" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
Spywareguard.exe |
Spywareguard ml097e
RapidBlaster variant (in a "Spyguard" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
spywareisolator.exe |
spywareisolator
SpywareIsolator spyware remover - not recommended, see here |
 |
SpywareKilla.exe |
SpywareKilla
SpywareKilla spyware remover - not recommended, see here |
 |
SpywareLocked.exe |
SpywareLocked
SpywareLocked spyware remover - not recommended, see here |
 |
SpywareLocked 3.5.exe |
SpywareLocked 3.5
SpywareLocked spyware remover - not recommended, see here |
 |
SpywareNo.exe |
SpywareNo
SpywareNo spyware remover - not recommended, see here |
 |
SpywareQuake.exe |
SpywareQuake
SpywareQuake spyware remover - not recommended, see here |
 |
SpywareRemover.exe |
SpywareRemover
SpywareRemover spyware remover - not recommended, see here |
 |
SpywareStrike.exe |
SpywareStrike
SpywareStrike spyware remover - not recommended, see here |
 |
SpywareSweeper.exe |
SpywareSweeper
SpywareSweeper spyware remover - not recommended, see here |
 |
SpywareTerminatorShield.exe |
SpywareTerminator
Spyware Terminator - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here |
 |
SpyWatch.exe |
SPYWATCH
BPS spyware remover - not recommended, see here |
 |
SpyWatchE.exe |
SpyWatchE
SpyWatchE spyware remover - not recommended, see here |
 |
SQInstaller.exe |
SQInstaller
Xupiter SQWire toolbar related. Use Spybot S&D, Adware or similar to detect and remove and to prevent it re-installing in the future see here |
 |
server.exe |
SQL
Added by the PUNYA-B WORM! |
 |
scm.exe |
SQL Server
SQL Server Service Control Manager. Available via Start -> Programs |
 |
sql.exe |
SQL Server Service
Added by the RBOT-ADF |
 |
sqvynikp.exe |
sqvynikp
Free_Scratch_Cards foistware |
 |
SrLogon.exe |
Sr Agent
Related to Secure Resolutions - desktop virus protection |
 |
srchupdt.exe |
SrchfstUpdate
SearchFast adware downloader |
 |
srmclean.exe |
Srmclean
Srmclean helps in the installation and execution of the SoundMax SoftPaq for Compaq/ADI SoundMax Integrated Digital Audio. According to Compaq - "If you disable the entry from loading into startup, then you will not be able to use the features of the sound card" |
 |
srng.exe |
SRNG
ShopNavSearch.Srng search hijacker |
 |
srrpro.exe |
SRP Startup
System Restore Remover Pro allows you to safely and easily remove System Restore and various other Windows Millennium "features". This is enabled if you tick the "Remove unnecessary System Restore information on startup" box. Available via Start -> Settings -> Control Panel |
 |
SrsTray.Exe |
SRS Applet
S3 Sonic Vibes sound card drivers - if disabled you loose sound |
 |
SRSSSC.exe |
SRS Audio Sandbox
SRS Audio Sandbox "provide amazing audio immersion and maximum thump for a personalized audio experience!" |
 |
srshost.exe |
srshost.exe
Added by a variant of the RBOT-ASW WORM! |
 |
srvhost.exe |
Srv Host
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
Srv32.exe |
Srv32
Added by the OPASERV.J WORM! |
 |
Srv32.exe |
Srv32
Added by the OPASERV.S WORM! |
 |
spoolsrv32.exe |
Srv32 spool service
Added by the SPYRE.B TROJAN! |
 |
Srv325.exe |
Srv325
Added by the AGOBOT-PR WORM! |
 |
SpyAgent4.exe |
Srv32Win
SpyAgent - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
 |
Svchost.exe |
Srv32Win
Realtime-Spy keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the svchost.exe process that normally doesn't appear in Msconfig/Startup! |
 |
sysdiag.exe |
Srv32Win
SpyAgent surveillance software. Uninstall this software unless you put it there yourself |
 |
svcpack.exe |
Srvce Pack Updte
Added by a variant of the RBOT WORM! |
 |
srvexc.exe |
srvexc.exe
Added by the SERVSAX TROJAN! |
 |
srvprc.exe |
srvprc
ActMon surveillance software. Uninstall this software unless you put it there yourself |
 |
srxTray.exe |
srxTray
Titan FTP Server - FTP server |
 |
SsAAD.exe |
SsAAD.exe
Sony's SonicStage digital music manager for their range of MP3 players. It monitors your HDD for newly added music tracks and automatically offers to add them to your playlist when you connect your player |
 |
SSBkgdupdate.exe |
SSBkgdUpdate
ScanSoft OmniPage auto updater. Can be disabled using the main program's options. Note - if you have a Soundblaster Audigy2 ZS soundcard installed on your computer and the volume of your soundsystem is turned on extremely high disabling this will solve the problem |
 |
ssc_serv.exe |
SSC Service Utility
SSC Service Utility is a printer utility for refilled Epson cartridges |
 |
SSCFBTN.EXE |
SSCFBTN.EXE
Samsung smarthru software,used with Lexmark Z82 or Samsung multifunction printers |
 |
SSCRun.exe |
sscRun
AOL's firewall |
 |
Std.exe |
Ssd
Stealthdisk - file and folder hiding/locking utility |
 |
ssdiag.exe |
ssdiag
Equinox (now Avocent) "Configuration and DOS Diagnostic for DOS and Windows platforms" |
 |
ssdpsrv.exe |
SSDPSRV
Simple Service Discovery Protocol (SSDP) and General Event Notification Architecture (GENA) services for network plug and play functionality. Starts up a web server on port 5000. Used by Universal Plug and Play (for network device discovery). To remove this program, open Add/Remove Programs, select either Communications (Me) or Networking Services (XP), and remove the checkmark next to Universal Plug and Play |
 |
system.exe |
ssgrate.exe
Added by the MITGLIEDER.C TROJAN! |
 |
sysdoor.exe |
ssgrate.exe
Added by the MITGLIEDER.N TROJAN! |
 |
SSh32.exe |
SSh32
2Spy keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
svchost.exe |
SSL
Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
 |
SSLDyn.exE |
SSLDyn
FRETHOG.MM spyware |
 |
ssmmgr.exe |
ssmmgr
Samsung printer monitor - for checking ink levels, etc. |
 |
SSMS.EXE |
ssms.exe
Added by the GISMOR WORM! |
 |
SSYTEM.EXE |
SSPY
SurfingSpy keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
SSS7.exe |
SSS7
Steganos Security Suite 7 - "A comprehensive collection of methods to prevent your data falling into the wrong hands, and highly recommended if you have anything you feel you need to hide" |
 |
sssasasb32.exe |
sssasasb32
Added by the TACTSLAY.F TROJAN! |
 |
SStb.exe |
SStb.exe
Adpowerzone.com "ServerSide" keyword hijacker |
 |
sstray.exe |
sstray
nVidia nForce Taskbar Utility - quick access to the nForce2 "Sound Storm" control panel and related utilitys |
 |
SSUpdate.exe |
SSUpdate
MoneyTree parasite - ActiveX control used to download premium-rate dialers |
 |
ssvchost.exe |
ssvchost
Added by the HELIOS.B TROJAN! |
 |
Stacmon.exe |
Stacmon
Installed with the drivers for a SigmaTel C-Major Audio card (on a Dell Inspiron 600m PC for example). Appears as though it can be disabled with no ill effects |
 |
StacSysTray.exe |
StacSysTray
System Tray control panel for SigmaTel C-Major on-board audio - as used on some Dell and Packard Bell PCs |
 |
standalone.exe |
standalone.exe
Added by the AGOBOT-ADS WORM! |
 |
starskin.exe |
StarSkin
StarSkin allows you to change the view and appearance of your Windows XP box with the use of publically available themes |
 |
start.exe |
start
?? |
 |
sdcc.exe |
start
Added by the AGENT.CSX TROJAN! |
 |
sbmntr.exe |
start
Netproject malware |
 |
spoolvse.exe |
start extracting
Added by the RBOT-XF WORM! |
 |
spoolvs.exe |
start extracting
Added by the RBOT.BAN WORM! |
 |
svchosets.exe |
Start It Upping
Added by a variant of the RBOT WORM! |
 |
sdFTP.exe |
Start Network Scanner Tool
Part of Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents" |
 |
svcnt32.exe |
Start Page
Homepage hijacker, also detected as Trojan-Downloader.Win32.Delf.ks |
 |
startcop.exe |
Start Up Cop
StartUp Cop - startup manager |
 |
smsss.exe |
start uploading
Added by a variant of the SDBOT WORM! |
 |
SVCHOSTES.EXE |
Start Upping
Added by the RBOT-NB WORM! |
 |
spoolnt.exe |
Start Upping
Added by the RBOT-TM WORM! |
 |
svcchosts.exe |
Start Uppings
Added by the SDBOT.VY WORM! |
 |
startacc.exe |
Startacc
Launches Webroot's Accelerate 2000 software that "speeds up your Internet connection by up to 300%". Leave enabled if you find it improves internet connection |
 |
startdrv.exe |
startdrv
Added by the DROPRK-A TROJAN! |
 |
StartEAK.exe |
StartEAK
Easy Access Button Support for Compaq PCs. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keys |
 |
scvhosting.exe |
Starter
Added by the SDBOT.RU WORM! |
 |
scvhostingg.exe |
starter
Added by the FORBOT-FB WORM! |
 |
StartFoxie.exe |
StartFoxie
Foxie Suite from Softonic International. "This suite of free tools comes in the form of an Internet Explorer add-on and includes a mix of powerful security enhancements" |
 |
svcmgr.exe |
startkey
Added by the HIPPER-B TROJAN! |
 |
scvhost.exe |
startkey
Added by the BIFROSE-PM TROJAN! |
 |
server.exe |
startkey
Added by the BIFROSE-DB TROJAN! |
 |
svchost32.exe |
startkey
Added by a variant of the SDBOT WORM! |
 |
svchost.exe |
startkey
Added by the AGENT-FPL TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
startl.exe |
startl.exe
Lingocom LingoWare - translates any application into your language |
 |
s_menu.exe |
StartMenu
Added by the TACTSLAY.C TROJAN! |
 |
startpage.exe |
startpage
Browser hijacker - redirecting to pages2start.com |
 |
start1.exe |
STARTPAGE
NoSpy.org - prevents spyware from changing your startpage and other browser properties. The start1.exe file is located in a NOSPY.ORG folder |
 |
SDPin.exe |
StartSecurDoc
SecurDoc from WinMagic Inc - "Provides full disk encryption to protect sensitive information stored on laptops, desktops and PDAs" |
 |
STARTSTOP.EXE |
StartStop
StartStop from TFI Technology - startup manager |
 |
STARTS.exe |
StartSurfing
Start Surfing allows you to protect your privacy while surfing and searching the Internet by acting as a "filter" between you and the website you are visiting. Startsurfing acts as your shield from Pop Up Windows, Mouse Traps, Window Resizing, and scripts that attempt to record your personal information. Available via Start -> Programs |
 |
StartupMonitor.exe |
Startup Manager Scanner
Startup-Mechanic Startup monitor - offers boot protection of your PC from harmful trojans, adult-dialers, and other scumware |
 |
Sensor.EXE |
Startup Scan
AntiVirus Quick Heal - scheduling agent |
 |
StartupMonitor.exe |
StartupMonitor
Mike Lin's StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu |
 |
startwin.exe |
startwin
Added by the ANTIMAN.A WORM! |
 |
StatnPerf.exe |
Stat 'n' Perf
Stat 'n' Perf monitors your internet connection and displays information about sent and received bytes |
 |
STATBAR.exe |
StatBar
StatBar (system status bar) allows you to quickly get an overview of your system's condition (memory, CPU, uptime, and much more). Due to the sheer number of resources (over 60%) consumed by this program, it is unsuitable for Windows 9x/Me |
 |
SPLStudio.exe |
StationPlaylistStudio
StationPlaylist Studio - "simple to use on-air broadcast playback software for the studio and/or DJ" for small to medium sized radio broadcasters, and internet webcasters |
 |
statslist.exe |
Statistics
Added by the OPANKI-S WORM! |
 |
StatusClient.exe |
StatusClient
Part of Hewlett Packard network printer drivers |
 |
StatusClient.exe |
StatusClient 2.6
Part of Hewlett Packard network printer drivers |
 |
StatusView.exe |
StatusView
Status View intra-office messaging |
 |
StayCon.exe |
Stay Connected!
More than just a pinger, actually simulates online activity. Supports AOL, NetZero, MSN, ATT WorldNet, CompuServe and many other ISPs as well. Available via Start -> Programs |
 |
StayAlive.Exe |
StayAlive
Part of RealSPEED - tweaking utility to speed-up your internet connection. Stay connected even after a period of inactivity on the net |
 |
sa.exe |
StayAlive
StayAlive from TFI Technology. "This top-notch tool intercepts crashes when they happen, keeping your programs running so you can save your work." |
 |
STBVisn.exe |
STBVision
Related to the STB Velocity graphics card. What does it do and is it required? |
 |
STBWEBTV.EXE |
STBWEBTV
Used to display TV on your PC |
 |
stcloader.exe |
stcloader
Popup adware by 2ndThought software |
 |
STCLOA~1.exe |
stcloader
Popup adware by 2ndThought software |
 |
stcloader.exe |
STCLOA~1
Popup adware by 2ndThought software |
 |
STCLOA~1.exe |
STCLOA~1
Popup adware by 2ndThought software |
 |
STCPO.exe |
STCPO
Sophos Sweep antivirus software |
 |
stdafx.exe |
StdAFX
Added by the DELBOT-AF WORM! |
 |
STDSB.exe |
STDSB
Scrollbar driver for notebooks. If taken out of the Startup, it will not provide scrolling |
 |
stealth25.exe |
Stealth Anonymizer 2.5
Now named Stealther - proxy server agent that lets you travel the Internet with maximum possible privacy |
 |
stealth.dcom.exe |
stealth.dcom.exe
Added by the THEALS.A WORM! |
 |
stealth.ddos.exe |
stealth.ddos.exe
Added by the THEALS.A WORM! |
 |
stealth.exe |
stealth.exe
Added by the THEALS.A WORM! |
 |
stealth.injector.exe |
stealth.injector.exe
Added by the THEALS.A WORM! |
 |
stealth.stat.exe |
stealth.stat.exe
Added by the THEALS.A WORM! |
 |
stealth.wm.exe |
stealth.wm.exe
Added by the THEALS.A WORM! |
 |
stealth.worm.exe |
stealth.worm.exe
Added by the THEALS.A WORM! |
 |
steam.exe |
Steam
Valve Software's STEAM broadband game client. Steam is Valve's new way of getting games into your hands ASAP. Games like Half-Life, Counter-Strike, and Counter-Strike: Condition Zero are all being made available through Steam. Steam games are automatically kept up-to-date with the latest content and revisions. Steam also includes an instant-message client which even works while you're in-game |
 |
steam.exe |
steam
Added by the RBOT-AJT WORM! Note - the file steam.exe will be found in the WindowsSystem folder and is not associated with Valve Software's game client |
 |
SteFanie.vbs |
SteFanie
Added by the STEFAN WORM! Note - make sure you check the hyperlink as this one copies it's self to numerous dirves and folders |
 |
Stickies.exe |
Stickies
Stickies - "lets you put yellow sticky notes on your Windows desktop, much like the popular Mac OS application. It is very simple, very customizable, and completely free!". Available via Start → Programs |
 |
stikynot.exe |
Sticky Notes
Microsoft Sticky Notes - virtual sticky notes tool |
 |
StickyPad.exe |
Sticky Pad
Sticky Pad from Green Eclipse. Place sticky notes on your desktop |
 |
StickyNote.exe |
StickyNote
Utility that allows you to put yellow "Post-It" type messages on your desktop. Available via Start -> Programs |
 |
Stimon.exe |
StillImageMonitor
Stimon.exe enables a USB still-image device (such as a scanner) to initiate data transfer to a program. For example, if your scanning device has a scan button, it may start a program and begin scanning when you press it. Create a shortcut and start it manually when needed if your scanner otherwise fails to scan. May be required for your USB scanner to work - including all HP scanners and some of their SCSI scanners |
 |
stisrv.exe |
stisrv
Added by the RBOT.BQF WORM! |
 |
stonedrv.exe |
stonedrv
Added by the COSIMA-K TROJAN! |
 |
sstsmon.dll, VerifyStatus |
StopSignSsTsMon
eAcceleration Stop-Sign security software related. Previously not recommended, see here |
 |
stopsinfo.dll |
StopSignStatus
eAcceleration Stop-Sign security software related. Previously not recommended, see here |
 |
Stopzilla.exe |
STOPzilla
StopZilla! - pop-up killer |
 |
SZNTSVC.EXE |
STOPzilla Service
StopZilla! - pop-up killer |
 |
sgtray.exe |
StorageGuard
StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups |
 |
SysRep.exe |
StorageProtector
StorageProtector misleading security software - not recommended, see here |
 |
StormSet.exe |
StormCodec_Helper
Storm Codec is a codec pack for Windows |
 |
STPMGR.EXE |
STPMGR
Part of SafeTP which is transparent FTP security software. Does it need to be running permanently or can it be started manually via Start -> Programs |
 |
SlDB.exe |
Streamload Downloader
Downloader for MediaMax (was Streamload) - "gives you a private and secure place to upload, store, access, and share your personal videos, photos, movies, music, and files" |
 |
StreamMgr.exe |
Streamload Uploader
Uploader for MediaMax (was Streamload) - "gives you a private and secure place to upload, store, access, and share your personal videos, photos, movies, music, and files" |
 |
StrgSync.exe |
StrgSync.exe
SimpleTech Inc's StorageSync backup software - backs up an entire PC, or selected files and folders |
 |
sdflkj3.exe |
strkjhk
Added by an unidentified WORM or TROJAN - see here |
 |
strngbox.exe |
Strng32
Added by the STRANO WORM! |
 |
strokeit.exe |
StrokeIt
StrokeIt is an "advanced mouse gesture recognition engine and command processor" |
 |
strto.exe |
strto
Added by the KILLPROC-F TROJAN! |
 |
Stubbish.exe |
Stubbish
Added by the STUBBOT-A WORM! |
 |
Sservice.exe |
StubPath
Added by the PRORAT TROJAN! |
 |
StupAssist.exe |
StupAssist
Associated with Nikon digital cameras |
 |
StyleXP.exe |
StyleXP
StyleXP allows you customize the way WinXP looks. If disabled via msconfig it re-instates itself at reboot, therefore uninstall it if you don't want it |
 |
SubAH.exe |
SubAH
Added by the SUBAH TROJAN! |
 |
Subliminal.exe |
Subliminal Power
Subliminal Power - displays subliminal messages of your choice on your computer screen |
 |
Suitcase.exe |
Suitcase Startup
Suitcase - system font manager start up utility. Used for dynamic managment of fonts on your system |
 |
SuiteOffices.exe |
Suite
Added by the LAZAR TROJAN! |
 |
SULFNBJ.EXE |
SULFNBJ.EXE
Added by the PE_MAGISTR.DAM VIRUS! |
 |
Sunasdtserv.exe |
Sunasdtserv
CounterSpy by Sunbelt Software - adware/spyware protection |
 |
sunasServ.exe |
sunasServ
CounterSpy by Sunbelt Software - adware/spyware protection |
 |
smvss.exe |
SunJavaUpdate
Added by the DEDLER-G TROJAN! |
 |
scvhost.exe |
SunJavaUpdateSched
Added by the SDBOT-AVX WORM! |
 |
shwicon98.exe |
Sunkist
Card reader for memory cards from digital cameras, etc |
 |
shwicon2k.exe |
Sunkist2k
Card reader for memory cards from digital cameras, etc |
 |
shwiconem.exe |
SunKistEM
Used by your computer to communicate with your Alcor Micro Multimedia Card Reader - necessary if you're using this software |
 |
suatshut.exe |
SuNotification
ShadowSurfer - "provides a safe computing environment by creating a virtual twin of your PC. Restore the pre-ShadowMode system state no matter what changes have occurred to your PC" |
 |
SunProtectionServer.exe |
SunProtectionServer
CounterSpy antispyware software |
 |
SunServer.exe |
SunServer
CounterSpy antispyware software |
 |
SupaDial.exe |
SupaDial
SupaNet.com modem driver related - is it required? |
 |
status.exe |
Supastatus
Supanet ISP software |
 |
supdate.exe |
supdate
Added by the MALWARE.D TROJAN! |
 |
super.exe |
super
Added by the AGOBOT-QT WORM! |
 |
SXDesk.exe |
Super X Desktop Version 3.4
Super X Desktop - virtual desktop manager |
 |
SAdBlock.exe |
SuperAdBlocker
SuperAdBlocker |
 |
SUPERAntiSpyware.exe |
SUPERAntiSpyware
"SUPERAntiSpyware is the most thorough scanner on the market. Our Multi-Dimensional Scanning and Process Interrogation Technology will detect spyware that other products miss! SUPERAntiSpyware will remove ALL the Spyware, NOT just the easy ones!" |
 |
services.exe |
SuperBar.Component
FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in an "Inetsrv" subfolder |
 |
Supercleaner.exe |
Supercleaner
Supercleaner - all in one disk cleaner for your computer |
 |
SuperHeissSex.exe |
SuperHeissSex
Added by the HeissSex premium rate adult content dialer! |
 |
superproxy.exe |
superproxy
Added by the DELBACK-B TROJAN! |
 |
SuperRam.exe |
SuperRam
SuperRam memory manager. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See SuperRam article and make up your own mind |
 |
Ssk.exe |
SuperSpamKiller Pro
SuperSpamKiller Pro email spam blocker |
 |
Supervisor.exe |
Supervisor.exe
Has been reported to be associated with various antitrojan software like ATS and PC Doorguard. If so it's required in Startup - any further information is welcome |
 |
supporter5.exe |
supporter5
Part of eScorcher anti-virus software- responsible for updates of new virus bases each time you logon to the web. Used to collect information about the user and therefore treated as spyware - now the web-site is dead |
 |
SRClean.exe |
SureCleanProfessional
SureClean PC and Internet tracks cleaner |
 |
Stopthepop.exe |
Sureshotpopupkiller
Stop-the-Pop-Up popup blocker |
 |
sacc.exe |
SurfAccuracy
SurfAccuracy adware |
 |
SCMan.exe |
SurfChoice
SCMan is a utility that can control services on WinNT from the command line. This utility can create, start, pause, stop, delete services. Furthermore it can retrieve a service's current state, get the displayname for a service and vice versa |
 |
surfer.exe |
Surfer lptt01
RapidBlaster variant (in a "mssurfer" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
surfer.exe |
Surfer ml097e
RapidBlaster variant (in a "mssurfer" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
SurfHelp.exe |
SurfHelper
Related to SurfHelper - a free tool to remove popup windows, clear history, control window properties of IE, and more |
 |
ss2-full.exe |
SurfSecret
"House-cleaning utility that enables you to keep your computer usage to yourself. Runs quietly from the system tray, eliminating tell-tale files at a regular interval of your choosing. You can set it to clear your Internet cache files, cookies, history, temp folder, etc. It can also clear the history of your Run and Find menus, in addition to the AOL cache" |
 |
Ssk.exe |
SurfSideKick 2
SurfSideKick adware |
 |
Ssk.exe |
SurfSideKick 3
SurfSideKick adware |
 |
SurfStream.exe |
SurfStream
Conceiva "SurfStream lets you surf the Web faster. It contains a fully featured proxy server that lets you surf the Web significantly faster. It also blocks all pop-up windows and banner ads from Web pages. An intelligent tune-up tool automatically analyzes and optimizes your computer's Internet connection and TCP/IP settings" |
 |
surveysa.exe |
Surveysa
Found on Sony laptops, it brings up a prompt to take a survey. It goes away if you fill out the survey or you choose "never prompt me again" but keeps popping if you either exit out of it or select "take survey later" |
 |
Susp.exe |
Susp
VX2.Transponder parasite updater/installer related |
 |
SV00LSV.EXE |
SV00LSV
Added by the GRAYBIRD-C TROJAN! |
 |
SVAplayer.exe |
SVA Player
QuickFlicks Streaming Player malware |
 |
svc.exe |
Svc
ClientMan parasite variant |
 |
svchost.exe |
SVC
ElfSpy keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the svchost.exe process that normally doesn't appear in Msconfig/Startup! |
 |
svcinit.exe |
SVC Service
Added by the SINIT TROJAN! |
 |
svcinit.exe |
SVC Service
CoolWebSearch parasite variant |
 |
svcpack.exe |
SVC Service
CoolWebSearch Svcinit parasite variant |
 |
svc32.pif |
SVC Service
Added by the RBOT-ASC WORM! |
 |
svc32.exe |
svc32
Identified as a variant of the Banker-EQC/DLoader.GPJI malware |
 |
Svced.exe |
Svced
Added by the DELF.F TROJAN! |
 |
SHCH.EXE |
SvcH0st
Added by the EB TROJAN! |
 |
SVCHST.EXE |
SvcH0st
Added by the EB TROJAN! |
 |
spoo1sv.exe |
SVCH0ST
Added by the HF TROJAN! |
 |
SVCH0ST.EXE |
SVCH0ST
Added by the IK TROJAN! Note - the filename has the digit 0 rather then the uppercase "o" |
 |
sdhch.exe |
SvcH0st
Added by the TACTSLAY.B TROJAN! |
 |
sp00lvs.exe |
SVCH0TS
Added by the LINEAGE-AZ TROJAN! |
 |
svchast.exe |
svchast
Added by the LINEAGE-AV TROJAN! |
 |
svchctrl.exe |
svchctrl
Added by the COBFINN TROJAN! |
 |
svchos.exe |
svchos
Added by the EZIBOT-B TROJAN! |
 |
SVCHOSI.EXE |
SVCHOSI
Added by the VBBOT-AA WORM! |
 |
svchost.exe |
SVCHOST
System1060 homepage hi-jacker. Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "System1060" subfolder of the Winnt or Windows folder |
 |
svchost.exe |
svchost
Added by many TROJANS amd WORMS, such as MORB or TARNO. Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup! |
 |
Svch0st.exe |
svchost
Added by the GRAYBIRD and GRAYBIRD.B TROJANS! Note - the filename has the digit 0 rather then the uppercase "o" |
 |
svchost.exe |
Svchost
Added by the MOZE-A WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
 |
svchosl.pif |
Svchost
Added by the INZAE.A or INZAE.B WORMS! |
 |
scvhost.exe |
SVCHOST
Added by the MYTOB.E or MYTOB.G WORMS! |
 |
SPOOLSV.EXE |
SVCHOST
Added by the BAITAP-A WORM! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir% |
 |
svchost32.exe |
SvcHost
Added by the AGOBOT-TM WORM! |
 |
svchost.exe |
svchost
Added by the BANCBAN-HL TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "config" subfolder of the Winnt or Windows folder |
 |
svchost.exe |
Svchost
Added by the ADCLICK-AX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Program FilesInternet Explorer folder |
 |
svchost.exe |
svchost
Added by the ES TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "Microsoft" subfolder |
 |
svchost.exe |
svchost
Added by the DLOADER-EV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "Arquivos de programas" folder |
 |
svchots.exe |
Svchost
Added by the RBOT.ADK WORM! |
 |
svchost64.exe |
SVCHOST
Added by the STARTP-G TROJAN! |
 |
svchost32.exe |
svchost connection monitor
Added by a variant of the SDBOT WORM! |
 |
svchost.exe |
SVCHOST Generic application
Added by the DAEMONI-K TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
 |
svchost.exe |
svchost Netware Manager
Added by the EXVID.A WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
scvhost32.exe |
SVCHost Protocol32
Added by a variant of the IRCBOT TROJAN! |
 |
svchost.exe |
Svchost Service
Added by the VB-DVQ WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Help subfolder of the Winnt or Windows folder |
 |
svhost.exe |
Svchost Windows Remote Services
Added by the IRCBOT-IV WORM! |
 |
svchost32.exe |
svchost.exe
CoolWebSearch Svchost32 parasite variant |
 |
SVCHOST.EXE |
SVCHOST.EXE
Added by the WRMSCAN-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
 |
svchost.exe |
svchost.exe
Added by the ZAPCHAS-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "drivers" subfolder |
 |
swchost.exe |
svchost.exe
Added by the SADELPHI-A TROJAN! |
 |
svchost1.exe |
svchost1
Added by the AGOBOT.ZZ WORM! |
 |
svchost32.exe |
SvcHost32
Added by the MIMAIL.I or MIMAIL.J WORMS! |
 |
svchost32.exe |
svchost32.exe
Added by the ASSASIN.20B BACKDOOR! |
 |
svchost64.exe |
svchost64
Added by the SDBOTER.G VIRUS! |
 |
svchosta.exe |
svchosta
Added by the SNIFFER-I TROJAN! |
 |
svchostb.exe |
svchostb
Added by the SNIFFER-J TROJAN! |
 |
svchost32.exe |
SvcHostDHCP
Added by the ASSASIN.20B BACKDOOR! |
 |
svchostdll.scr |
svchostdll.scr
Added by the BANCBAN-FM TROJAN! |
 |
svchostr.exe |
svchostr
Added by an unidentified WORM or TROJAN! |
 |
svchosts.exe |
svchosts
Added by the BANCBAN-DC or BANKER-ED TROJANS! |
 |
svchosts.exe |
svchosts.exe
Added by the AGOBOT-JN WORM! |
 |
svchosts.scr |
svchosts.scr
Added by the BANCBAN-DQ TROJAN and variants! |
 |
SVCHOT.exe |
SVCHOT
Added by the QQROB-U TROJAN! |
 |
svchst.exe |
svchst
Added by the KBROY-C TROJAN! |
 |
svcinfo.exe |
svcinfo
Added by the CRYPTER.A TROJAN! |
 |
svcchost.exe |
Svclhost
Added by an unidentified WORM or TROJAN! |
 |
spoolvs3.exe |
SvcManager
Added by an unidentified WORM or TROJAN! |
 |
svcmon.exe |
svcmon
PersonInspect surveillance software. Uninstall this software unless you put it there yourself |
 |
Svconr.exe |
Svconr
WaveRevenue-lBann adware |
 |
svcroot.exe |
svcroot
Added by the KEYLOG-AC TROJAN! |
 |
spoclsv.exe |
svcshare
Added by the FUJACKS-A VIRUS! |
 |
svcsysreg.exe |
Svcsys Registry Manager
Detected by Kaspersky as the AGENT.CV TROJAN! |
 |
svcsys32.exe |
svcsys32
Added by the AGOBOT-LL WORM! |
 |
svctask.exe |
svctask
Added by the CHUCKYB-A TROJAN! |
 |
svghost.exe |
SVGA Adapter
Added by a variant of the SPYBOT WORM! See here |
 |
svhcost.exe |
svhcost
OpenSearch adware |
 |
svhost.exe |
SVHOST
Added by the MYDOOM.I WORM! |
 |
SVHOST.EXE |
SVHOST
Added by the ZORI.A VIRUS! |
 |
svshost.exe |
Svhost Loader
Added by the AGOBOT.G WORM! |
 |
Svhost.exe |
svhost updates
Added by a variant of the RBOT WORM! |
 |
svhost8.exe |
svhost windows services
Added by the RBOT-WQ WORM! |
 |
SVIDC32M.exe |
SVIDC32M
?? |
 |
sviload32.exe |
sviload32
Added by the RBOT-AAS WORM! |
 |
svmpop.exe |
SVM Pop
?? |
 |
svnlitup32.exe |
svnlitup32
Added by the RBOT.CBJ WORM! |
 |
svnload32.exe |
svnloader
Added by the RBOT-ACU WORM! |
 |
svphost.exe |
svphost.exe
Added by the AGENT.CS TROJAN! |
 |
SVPWUTIL.exe SVPwUTIL |
SVPWUTIL
Part of Toshiba Hardware Setup |
 |
svrrun.exe |
svrrun
Adware hailing from Deskwizz.com |
 |
svsekt.exe |
svsekin
Added by the QQPASS.G TROJAN! |
 |
svshost.exe |
svshost
Added by the CHODE-H WORM! |
 |
svcbind.exe |
Svshost Update Service
Added by the MYTOB.LH WORM! |
 |
svshost32.exe |
svshost32
Added by a variant of the SDBOT WORM! |
 |
svshost.exe |
svshostdriver
Added by the SDBOT-HN TROJAN! |
 |
svxhost.exe |
SVX Control Service
Added by the FORBOT-K WORM! |
 |
sw20.exe |
SW20
Related to MSI's Dynamic Overclocking Technology |
 |
sw24.exe |
SW24
Related to MSI's Dynamic Overclocking Technology |
 |
SWcaller.exe |
SWCaller
Swporta homepage hijacker |
 |
Swcaller2.exe |
SWCaller
Swporta homepage hijacker |
 |
Swhost.exe |
Swchost
Added by the MP TROJAN! |
 |
swsys.exe |
SWClient
ActivMonAgent keyboard logger/monitoring program - remove unless you installed it yourself |
 |
swcroot.exe |
swcroot
Added by the SOLENO-A TROJAN! |
 |
SweetIM.exe |
SweetIM
vSweetIM - send fancier smiley-faces and IM graphics to friends who are using MSN Messenger. They are only able to see these advanced smiley-faces if they also have SweetIM installed |
 |
SwimSuitNetwork.exe |
SwimSuitNetwork
Advertising spyware |
 |
SWINGSYS.EXE |
swingsys
Added by the BANCOS-CX TROJAN! |
 |
swoff.exe |
Switch Off
Switch Off - tray-based system utility that can automatically perform various frequently used operations like shutdown or restart your computer, disconnect your current dialup connection, lock workstation, etc |
 |
Switcher.exe |
Switcher
"On a Sony laptop with built in wireless it allows the user to select which wireless services they want to run (i.e. Wireless LAN, Bluetooth, both) when turning the wireless switch on if disabled)" |
 |
switpa.exe |
switp
OfferAgent adware component |
 |
swnxt.exe |
SWN2
Spyware removal program by TrekBlue. Previously not recommended but the latest version was delisted here |
 |
SWTRAY.EXE |
SwTray
MS SideWinder game controller system tray icon. Available via Start -> Programs. May have the version number after it |
 |
SWTrayV4.exe |
SWTrayV4
MS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs |
 |
SwyxIt!.exe |
SwyxIt!
PC Based soft phone from Swyx - see here for more details |
 |
sxgdsenu.exe |
SXGDSENU
Yamaha SXG soundcard driver |
 |
sxgtkbar.exe |
SxgTkBar
Yamaha SXG soundcard utility - gives quick and easy access via the system tray bar to diagnostics and configuration |
 |
sxpstub.exe |
Sxplog
Part of CA Unicenter Software Delivery - manage software across various systems, from desktops and servers to PDAs and mobile phones, in a controlled and standardized way - is it required at startup? |
 |
sxrrv.pif |
sxrrv
Added by the VAX-A TROJAN! |
 |
s2.exe |
sy
Added by a variant of the RBOT WORM! |
 |
scjview.exe |
SybaseCentral43
Related to SQL Anywhere from Sybase. A comprehensive package providing data management and data exchange technologies |
 |
SyGate.exe |
Sygaete Personal Firewall
Added by the RBOT-GLX WORM! |
 |
Syga.exe |
Sygate Peral Firewall
Added by the RBOT-AQK WORM! |
 |
svrv.exe |
Sygate Personal 3
Added by the RBOT-XD WORM! |
 |
Studio.exe |
Sygate Personal Block
Added by the RBOT-TW WORM! |
 |
system32.exe |
Sygate Personal Firewall
Added by the RBOT.VI WORM! |
 |
sysgut.exe |
Sygate Personal Firewall
Added by the SDBOT.WM WORM! |
 |
Sygate.exe |
Sygate Personal Firewall
Added by the RBOT-PN WORM! |
 |
Sygate32.exe |
Sygate Personal Firewall
Added by the RBOT.ATW WORM! |
 |
service.exe |
Sygate Personal Firewall
Added by a variant of the RBOT WORM! |
 |
sexy.exe |
Sygate Personal Firewall
Added by the RBOT-XY WORM! |
 |
sys.exe |
Sygate Personal Firewall
Added by the RBOT-ZC WORM! |
 |
syserror.exe |
Sygate Personal Firewall
Added by the RBOT.UC WORM! |
 |
Sygat.exe |
Sygate Personal Firewall
Added by a variant of the RBOT WORM! |
 |
Syga.exe |
Sygate Personal Firewall
Added by the RBOT-AQD WORM! |
 |
svchots.exe |
Sygate Personal Firewall
Added by the RBOT.ABT WORM! |
 |
services32.exe |
Sygate Personal Firewall Start
Added by the RBOT-MB WORM! |
 |
servic.exe |
Sygate Personal Firewall Start
Added by the RBOT-RY WORM! |
 |
sgserv95.exe |
SyGateService
SyGate is a useful little program that lets you share an internet connection over an intranet. Is it needed - it saves a lot of headache to just let SyGate load at startup. Available via Start -> Programs |
 |
symantec32.exe |
Symantec Anti Virus
Added by a variant of the WOOTBOT WORM! |
 |
Symantex.exe |
Symantec Antivirus professional
Added by a variant of the FORBOT WORM! |
 |
symclient.exe |
Symantec Client Security
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
symlcsvc.exe |
Symantec Core LC
Part of Norton AntiVirus 2004. What does it do? |
 |
symdebugs.exe |
Symantec Debug Client
Added by the IRCBOT-ACM TROJAN! |
 |
SNDMon.exe |
Symantec NetDriver Monitor
Part of Symantec's LiveUpate (eg, Norton). Not required if you run manual updates but probably require if you leave them to run automatically. Also, if one runs a small office network and SNDMon is disabled on one of the computers ? then other computers disappear from the network for this computer, including shared devices like printers and scanners. Hence the "U" recommendation |
 |
SNDWarn.exe |
Symantec NetDriver Warning
Part of Symantec Live Update - displays the warning when you need to update the firewall database |
 |
svrhost.exe |
Symantec Secure Server
Added by the IRCBOT-UB TROJAN! |
 |
symantec32.exe |
Symantec Security
Added by the RANDEX.PR or RANDEX.YR WORMS! |
 |
svhost.exe |
SymantecFilterCheck
Added by the BANKER-EEO TROJAN! |
 |
SymAV.exe |
SymAV
Added by the NETSKY.U WORM! |
 |
symmec.exe |
Symmetrical Network
Added by the DELBOT-N WORM! |
 |
SYMTRAY.EXE |
SymTray - Norton SystemWorks
Keeps all System Tray icons for Norton SystemWorks together to reduce clutter. SystemWorks includes Norton Anti-Virus, Norton Utilities and Norton CleanSweep - mentioned elsewhere here. Personally I only have Norton eMail Protect running which doesn't need SymTray |
 |
SynTPEnh.exe |
Synaptics Pointing Device Driver
Synaptics touchpad tray icon. Displays status and provides quick launch to touchpad features such as scrolling and tap zones. Required on IBM Thinkpads with UnltraNav (pointstick and touchpad combo) if you don't want to loose the advanced pointstick features such as scroll |
 |
Syncit.exe |
Sync-It
Sync-It - synchronizes the system clock with time servers on the internet |
 |
syncagent.exe |
SyncAgent
Ghost Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
SynTP.tmp RunOnce.exe |
SynSetup
Probably associated Synaptics touchpads on laptops as for the SynTPEnh and SynTPLpr entries but what does it do and is it required? |
 |
systacq.exe |
Syntax Script
Added by the SDBOT.AI WORM! |
 |
syntpenh.exe |
SynTPEnh
Synaptics touchpad tray icon. Displays status and provides quick launch to touchpad features such as scrolling and tap zones. Required on IBM Thinkpads with UnltraNav (pointstick and touchpad combo) if you don't want to loose the advanced pointstick features such as scroll |
 |
syntplpr.exe |
SynTPLpr
Synaptics touchpad driver helper. Required for touchpad features to work |
 |
SynTPStart.exe |
SynTPStart
Synaptics Pointing Device starter belonging to Synaptics Pointing Device Driver |
 |
SysRen.exe |
Sys Ren
Part of FlashEnhancer adware |
 |
sys*************.exe [* = random digit] |
sys************* [* = random digit]
WINBO adware |
 |
Sys**.exe [* = random char] |
Sys**.exe [* = random char]
CoolWebSearch/HomeSearch adware - for examples, see this log |
 |
Sys**32.exe [* = random char] |
Sys**32.exe [* = random char]
CoolWebSearch/HomeSearch adware - for examples, see this log |
 |
sys008.exe |
sys008
Hijacker, also detected as the STARTPA-GK TROJAN! |
 |
sys009.exe |
sys009
Added by the STARTPA-ZB TROJAN! |
 |
sys209.exe |
sys201
Added by the STARTPA-ZY TROJAN! |
 |
sys32.exe |
sys32
Added by the FLUX.E TROJAN! |
 |
sysx32.exe |
sys32
Added by the KVEX-A VIRUS! |
 |
sys32win.exe |
sys32cmd
Active Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
sys32dll.exe |
sys32dll
Added by the AIMDES.B WORM! |
 |
sys32win.exe |
sys32sql
Active Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
sys33.exe |
sys33
Added by the AGOBOT-WJ WORM! |
 |
SysAgent.exe |
SysAgent
SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of |
 |
SysAI.exe |
SysAI
AproposMedia adware |
 |
sysatw.exe |
SysATW
Added by the VANEBOT-AM WORM! |
 |
sysbot.exe |
Sysbot
Spector - spying (or monitoring) software to record internet activity |
 |
syscfg32.exe |
syscfg
Added by the KWBOT.S WORM! |
 |
syscfg34.exe |
syscfg34.exe
Added by the ELECTRON WORM! |
 |
Syscm.exe |
syscm
Vanish adware |
 |
syscon.exe |
syscon
Added by the APRILCONE.A WORM! |
 |
syscon.exe |
syscon lptt01
RapidBlaster variant (in a "Syscon" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
syscon.exe |
syscon ml097e
RapidBlaster variant (in a "Syscon" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
syscfg35.exe |
SysConfig
Added by the KAZMOR.C WORM! |
 |
Stealth KeySpy.exe |
Sysconfig
StealthKeySpy - keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
Syscpy.exe |
Syscpy
Firewall-bypassing, proxied spam relayer. Detected by Symantec as the HOGLE TROJAN! |
 |
sysctl.exe |
SysCtl
Added by the AOK TROJAN! |
 |
Sysctrls.exe |
Sysctrls
Detected by Kaspersky as the AGENT.AWZ TROJAN! See here |
 |
sevchost.exe |
Sysctrls32
Detected by Kaspersky as the RBOT.ADF BACKDOOR! See here |
 |
SysCVMS.exe |
SysCVMS.exe
Added by the SMALL.CBA TROJAN! |
 |
sysdat.dll.exe |
sysdat.dll
Added by the NISHICA 1.1 TROJAN! |
 |
sysdpt.exe |
Sysdpt
CRYPT trojan downloader |
 |
sysdxvid.exe |
sysdxvid
Added by the DLUCA-S TROJAN! |
 |
sysem.exe |
sysemls
Added by a variant of the SDBOT WORM! |
 |
svclgx32.exe |
SysEQ
Added by the IRCBOT-AC TROJAN! |
 |
sysfiler.exe |
sysfiler
Added by the RETSAM TROJAN! |
 |
SYSfit.exe |
SYSfit
AdShooter adware variant |
 |
sysflg32.exe |
sysflg32
Added by a variant of the CRYPTER.C TROJAN! |
 |
sysformat.exe |
sysformat
Added by the BAGLE-BK WORM! |
 |
sysfrcx.exe |
sysfrcx
Added by the KEYLOG-SCLOG TROJAN! |
 |
syst3ms.exe |
Sysgate Personal Firewall
Added by a variant of the IRCBOT TROJAN! |
 |
syshelp.exe |
syshelp
Added by the LOVGATE.C WORM! |
 |
syshost.exe |
syshost
Added by the VB-DVZ TROJAN! |
 |
sysinfo.exe |
sysinfo
Added by the BEDRILL TROJAN! |
 |
sysinfo.exe |
sysinfo.exe
Added by the BEAGLE.V WORM! |
 |
svchost.exe |
SysInit
Added by the STARTPA-BD TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Program Files/Common Files folder |
 |
services.exe |
sysinit
Added by the NEWLFRM-A TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in an "golumm" subfolder |
 |
sysint16.exe |
sysint16
Added by the CRYPTER.A TROJAN! |
 |
sysinit.exe |
Syskey
Added by the BEAGLE.AX WORM! |
 |
Syslib.exe |
Syslib
Adult content related downloader trojan |
 |
Syslog.exe |
Syslog lptt01
RapidBlaster variant (in a "Syslog" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
Syslog.exe |
Syslog ml097e
RapidBlaster variant (in a "Syslog" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
syslogin.exe |
syslogin.exe
Added by the BAGZ-B WORM! |
 |
Sysman.exe |
Sysman
KeyTrap is a surveillance software program that records all keyboard activities. Uninstall this software unless you put it there yourself |
 |
sysme.exe |
sysme
Added by the PSW_STEALER_C TROJAN! |
 |
SysMetrix.exe |
SysMetrix
SysMetrix - skinnable clock and metering application. It monitors and reports on a great number of statistics |
 |
sysmini.exe |
sysmini
Added by the ADLOAD.DD TROJAN! |
 |
sys64mnger.exe |
sysmngr32
Added by a variant of the RBOT WORM! |
 |
sysmntrc.exe |
sysmntrc
Added by the BANCOS-FX TROJAN! |
 |
sysmod.exe |
sysmod
Added by the SPYBOT-DU WORM! |
 |
sysmon.exe |
sysmon
Added by the BIZEX WORM! |
 |
sysmon44.exe |
sysmon
Added by a variant of the BACKDOOR-CBA TROJAN! |
 |
SystemMonitor.exe |
Sysmon
Added by the NUJAMA-A WORM! |
 |
sysmonnt.exe |
sysmonnt
SearchPounder sends keywords typed into HTML forms and popular Internet search engines to a remote server |
 |
SysMonXP.exe |
SysMonXP
Added by the NETSKY.Q WORM! |
 |
SysTdSvr.dll |
Sysmppcvppp
Generic2.PQG adware |
 |
sysems.exe |
sysmss
Added by a variant of the SLAPER TROJAN! |
 |
sysnate.exe |
sysnate
Added by the MEDIAS TROJAN! |
 |
snuninst.exe |
Sysnet
Unidentified adware |
 |
sysnet.exe |
sysnet
CasClient adware - also detected as the CMAPP TROJAN! |
 |
sysobj.exe |
sysobj.exe
Wareout - malware masquerading as a spyware and dialer remover |
 |
SysOps |
SysOps
Added by the MSNCORRUPT TROJAN! |
 |
syspare.exe |
syspare
Added by the BIFROSE-AN TROJAN! |
 |
system.exe |
sysPersonalFirewall
Added by the WOOTBOT.FH WORM! |
 |
System.exe |
SysProtect
Added by the NETSPY TROJAN! |
 |
syp.exe |
SysProtect
SysProtect is detected as a "potentially unwanted program". It purports to be an system repair/maintenance application, but requires paid registration before any issues found can be fixed. Many of the "invalid" items found appear suspect. This has been reported to be distributed in wild via trojan Vundo. Other incarnations of this software exist with the same model and similar web presences (for example WinFixer). For more information see here |
 |
syspw32.exe |
syspw32.exe
Added by the APPFLET.A WORM! |
 |
sysmd.exe |
SysR
Ulubione adult content dialer |
 |
SysReg.exe |
SysReg
Added by the CHEKIN TROJAN! |
 |
SysReg.exe |
SysReg
SearchSeekFind textual marketing foistware |
 |
Sysres.exe |
Sysres
Added by the LOGMOD.A TROJAN! |
 |
sysrest32.exe |
sysrest32.exe
Added by the AGENT-GIN TROJAN! |
 |
sysrestore32.exe |
sysrestore32.exe
Unknown malware detected by McAfee. See here |
 |
SysSense.exe |
SysSense
"SysSense is your personal desktop Google AdSense monitor. It keeps your current Google AdSense information in the Windows system tray". Google AdSense account required |
 |
SysService.exe |
SysService
Added by the DELF family of TROJANS! |
 |
SERVICES.EXE |
SysService
NSKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
SysService32.exe |
SysService32
Added by the KINDAL VIRUS! |
 |
systask32l.exe |
SysService32l
Added by the THEUG WORM! |
 |
SYSsfitb.exe |
SYSsfitb
Searchforit browser hijacker |
 |
sysl.exe |
SySSL
Added by the RBOT-CKH WORM! |
 |
systemc.exe |
SysStrt
Added by the AGOBOT-QA TROJAN! |
 |
syst.exe |
syst
Added by the DUMB.A "Joke" virus |
 |
serwin.exe |
System
Added by the LDPINCH-BN TROJAN! |
 |
svch?st.exe |
System
Added by the LDPINCH-BF TROJAN! |
 |
system.exe (74295303) |
System
Added by the IU WORM! |
 |
SPOOLSU.EXE |
System
Added by the BANKER-FC TROJAN! |
 |
system23.exe |
System
Added by the LEBREAT-D WORM! |
 |
services.exe |
system
Added by the DELF-LQ TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "HELP" subfolder of the Windows or Winnt folder |
 |
smss.exe |
System
Added by the AGENT.AEP TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
 |
svcr.exe |
system
Added by the SPYONE TROJAN! |
 |
SystemFile.exe |
SYSTEM
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
system.exe |
System
Added by various WORMS and TROJANS! |
 |
systemsearch.hta |
system
Jetseeker.com hijacker |
 |
sysctrl.exe |
System
Added by WinGuardian. Note - this commercial keylogger is no longer made or sold by Webroot but older copies may still be in existance, those copies will be identified as spyware |
 |
svchost.exe |
System
Added by the LDPINCH-AU TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
 |
systray.exe |
System
Added by the PISABOY-A TROJAN! Note - this is not the legitimate systray.exe process |
 |
sys64dvr.exe |
System 64 Driver for Games
Added by the SDBOT TROJAN! |
 |
sap.exe |
System Applications Profile
Added by the RBOT-QF WORM! |
 |
sysload3.exe |
System Boot Check
Added by the FUBALCA WORM! |
 |
SysCache.exe |
System Cache
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
syscgmgr.exe |
System CGI Manager
Added by an unidentified WORM or TROJAN! See here |
 |
sysloadcnf.exe |
System Config
Added by a variant of the SDBOT WORM! See here |
 |
syscgboot.exe |
System Config Boot
Detected by Kaspersky as the AGENT.VWU TROJAN! See here |
 |
smssl.exe |
System Config Manager
Added by the AGOBOT-ZJ WORM! |
 |
syscfg32.exe |
System Configuration
Added by the MYTOB.EA WORM! |
 |
svchost.exe |
system configure
Added by the LINEAGE-C TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup! |
 |
syscoremem.exe |
System Core Memory
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
scrtkfg.exe |
System CSRSS Patch
Added by the RBOT-ADA WORM! |
 |
systemDA.exe |
System Database administration
Added by the DERDERO.B WORM! |
 |
sysdasp.exe |
System Database Administration Support Process
Added by the DERDERO.C WORM! |
 |
sysdbroot.exe |
System DataBase Root
Added by the QHOST-W TROJAN! |
 |
sysdbmg.exe |
System DB Manager
Added by an unidentified WORM or TROJAN! See here |
 |
sysdiag32.exe |
System Diagnostics
Added by the SDBOT.GEN TROJAN! |
 |
sysdll.exe |
System DLL Resources
SnapKey is a surveillance software program that records all keyboard activities. Uninstall this software unless you put it there yourself |
 |
SysMgr.exe |
System Download Manager
Added by the RBOT.CIG WORM! |
 |
svchostx.exe |
System Efficiency Monitor
Added by the KWBOT.E WORM! |
 |
secsvc.exe |
System Event Manager
Added by the RBOT.BMY WORM! |
 |
sys32.exe |
System File Startup
Detected by PCTools as the RBOT.OTL WORM! See here |
 |
System Files Updater.exe |
System Files Updater
System Files Updater from Flyakiteosx "will transform the look of an ordinary Windows XP system to resemble the look of Mac OS X" |
 |
srvhandle.exe |
system handler
Added by the REDPLUT VIRUS! |
 |
scvhost.exe |
System Host
Added by a variant of the RBOT WORM! |
 |
syshost.exe |
System Host Manager
Added by the BANWORM-C WORM! |
 |
svchost.exe |
System Host Service
Added by the CONE.F WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "tasks" subfolder of the Winnt or Windows folder |
 |
syspass.exe |
System Information Manager
Added by the SDBOT-MO WORM! |
 |
systeminit.exe |
System Init
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
systemip.exe |
System IP
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
system.exe |
System Kernal Support
Added by the SDBOT.BWV WORM! |
 |
Slsched.exe |
System LifeGuard Scheduler
System LifeGuard scheduler |
 |
smsc.exe |
System Management Service
Added by the RBOT-ANN WORM! |
 |
svchost.exe |
System Manager
Added by the BANKER-AE TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
 |
System.exe |
system manager
Added by the FORBOT-BO WORM! |
 |
sysmng.exe |
System Manager
Added by the TAME-C WORM! |
 |
sysmngr.exe |
System Manager
Added by a variant of the IRCBOT TROJAN! See here |
 |
SysMech4.exe /REREG: [path] Incinerator.dll |
System Mechanic Professional Update [Incinerator.dll]
Iolo System Mechanic "Incinerator" feature securely deletes files and folders from your PC so they can never be recovered again |
 |
StartupGuard.exe |
System Mechanic Startup Guard
System Mechanic Startup Guard protects the Window's startup locations from being modified by viruses, spyware, malware and other annoying programs |
 |
SMCSS.EXE |
System Messaging Queue
Added by a variant of the RBOT WORM! |
 |
SYSMSG32.EXE |
System Messenger
Added by the SPYBOT-DK WORM! |
 |
systgmgr32.exe |
System Messenger32
Added by the SDBOT.DF WORM! |
 |
smc.exe |
System Microsoft Core
Added by the RIZO.A TROJAN! |
 |
SYSMON.EXE |
System Monitor
Comes with some Aopen motherboards. Monitors CPU temp, voltage and fan speed. Warns if any become abnormal |
 |
Sysmon16.exe |
System Monitor
Added by the SDBOT TROJAN! |
 |
sys32.exe |
System Net
Added by the FORBOT-FX WORM! |
 |
sysnd.exe |
System Net Database
Added by the RBOT-AAW WORM! |
 |
sysnet.exe |
System Networking
Added by the RBOT.API WORM! |
 |
svcnost.exe |
System Power Managment
Added by the DREF-I WORM! |
 |
svchost.exe |
System Process
Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
 |
sysproc.exe |
System Process Analization
Added by a variant of the RBOT WORM! |
 |
system.exe |
System Process Analization Thread
Added by a variant of the RBOT WORM! |
 |
sysbho.exe |
System Redirect
Downloader trojan, "Melkosoft" adware related |
 |
sysrgmgr.exe |
System Registry Manager
Added by an unidentified WORM or TROJAN! See here |
 |
svcnet.exe |
System Restore
Added by the TIBICK WORM! |
 |
ssc.exe |
System Security Checker
Added by the IRCBOT-WI TROJAN! |
 |
spoolcrv.cpl |
system service
Added by the INSPIR.11 TROJAN! |
 |
systems.exe |
System Service
Added by the AGOBOT.VZ WORM! |
 |
servicent.exe |
System Service
Added by the RBOT-AJI WORM! |
 |
system.exe |
System service
Added by the BANCOS.AA TROJAN! |
 |
servicez.exe |
System Service
Added by the RBOT-AOY WORM! |
 |
serious.exe |
System Service
Added by the RBOT-FMV WORM! Note - deactivates the Microsoft Internet Connection Firewall (ICF) |
 |
svchelper.exe |
SYSTEM service helper
Added by the MONKBD-A WORM! |
 |
syshelp.exe |
SYSTEM service helper
Added by a variant of the MONKBD-A WORM! |
 |
svcsenes.exe |
System Services
Added by a variant of the RBOT WORM! |
 |
svcsenes32a.exe |
System Services
Added by the RBOT-AFG WORM! |
 |
ssms.exe |
System Services
Added by a variant of the RBOT WORM! |
 |
server.exe |
System Services Monitor
Bifrost malware |
 |
smss.exe |
System Session Manager
Added by the KALEL-E WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup! |
 |
soap.exe |
System Soap Pro
System Soap Pro internet cleaning software. Bundles foistware like Httper and Zipclix - best avoided |
 |
syspools.exe |
system spool
Added by the DREF-T WORM/VIRUS! |
 |
sys.exe |
System Startup
Added by a variant of the IRCBOT TROJAN! |
 |
smcss.exe |
System Startup Manager
Added by the RBOT.AMD WORM! |
 |
SystemStats.exe |
System Stats
Added by a variant of the WOOTBOT WORM! |
 |
syscfg.exe |
System Support
Added by the RBOT-AGQ WORM! |
 |
system32.exe |
System Support
Added by the RBOT-AHA WORM! |
 |
syssql.exe |
System Support
Added by the RBOT-AUH WORM! |
 |
SYSTEM2.EXE |
System Terminal
Added by the SPYBOT-BZ TROJAN! |
 |
Systools.exe |
System Toolkit
Added by the RONOPER-G WORM! |
 |
systray.exe |
System Tray
Added by the FAN-A WORM! |
 |
spooles32.exe |
System Tray Services
Added by the AGOBOT.ZH WORM! |
 |
SysTray32.exe |
System Tray32
Added by the REPAD WORM! |
 |
syscfg32.exe |
System Unix
Added by the RBOT-ZD WORM! |
 |
system.pif |
System Update Service
Added by the RBOT-ALL WORM! |
 |
services.exe |
System Update2
Added by the AUTOTROJ-C TROJAN!Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
 |
svchost.exe |
System Update2
Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
 |
system.exe |
System Update2
Added by the AUTOTROJ-C TROJAN! |
 |
system.exe |
System Updater Machine
Detected by Kaspersky as the CIADOOR.GN BACKDOOR! See here |
 |
szwi.exe |
System Updates
Added by the RBOT-AXE WORM! |
 |
SYSENTRY.EXE |
System Uptime Server
Added by the RBOT.LK WORM! |
 |
SYSENTRY32.EXE |
System Uptime Server
Added by the RBOT.LK WORM! |
 |
systats.exe |
System-Stat
Added by the SDBOT.RA WORM! |
 |
system..exe |
system.
Added by the OPTIXPRO.13.C TROJAN! |
 |
system...exe |
system...
Added by the OPTIXPRO.13.C TROJAN! |
 |
System.exe |
System.exe
Added by various WORMS and TROJANS! |
 |
system.exe |
system.exe
Added by the JAMPORK.E WORM! |
 |
system.exe |
system.exe
Added by a variant of the IRCBOT BACKDOOR! Located in %WINDIR%\pchealth\helpctr\binaries |
 |
system.exe |
System32
Added by the BUSHTRO122 TROJAN! |
 |
System32.exe |
System32
Added by any number of WORMS or TROJANS! |
 |
sysdiag.exe |
System32
SpyAgent surveillance software. Uninstall this software unless you put it there yourself |
 |
system32,1.exe |
System32
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
syspci32.exe |
System32 PCI Manager
Added by the RBOT-AFR WORM! |
 |
sysrs.exe |
System32 Runtime StartUp
Added by the AGOBOT.ANW WORM! |
 |
systcpm.exe |
System32 TCP Manager
Added by a variant of the RBOT WORM! |
 |
systerm.exe |
System32 TCP Manager
Added by the RBOT.AFD WORM! |
 |
systmp.exe |
System32 Temp Service
Added by the RBOT-AET WORM! |
 |
systeminit.exe |
system32.dll
CoolWebSearch parasite variant - re-directing to your-search.info |
 |
sysdll32.exe |
system32.dll
CoolWebSearch parasite variant. Redirecting to wholeworldmarket.com, most likely other domains as well |
 |
services32.exe |
system32.exe
Added by a variant of the IRCBOT TROJAN! |
 |
system32.exe |
system32.exe
Added by the GRAYBIRD.P TROJAN! |
 |
System32BLSJ.exe |
System32BLSJ Agent
Added by the MDROP-BPT TROJAN! |
 |
System32Ex.exe |
System32Ex
Added by the IRCCONTACT TROJAN! |
 |
sysdiag.exe |
System32kfvw
SpyAgent surveillance software. Uninstall this software unless you put it there yourself |
 |
system32WXBP.exe |
system32WXBP Agent
Detected by Trend Micro as TSPY_ARDAMAX.HR spyware. See here |
 |
system34.exe |
system34.exe
Added by the DWNLDR-FXY TROJAN! |
 |
Systemdll.exe |
System4224411
Added by the YUSUFALI-B WORM! |
 |
system43.exe |
system43.exe
Added by a variant of the SDBOT WORM! |
 |
Sage.exe |
SystemAgent
"Microsoft Plus! System Agent automatically tunes your system, performing tasks such as disk optimization and error correction. It can also run any application at prescheduled times" |
 |
systemb.exe |
systemb
Added by a variant of the IRCBOT TROJAN! |
 |
services.exe |
SystemBoot
Added by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a HelpHelp subfolder of the Windows or Winnt folder |
 |
Systemcheck.exe |
SystemCheck
Added by the LAVITS WORM! |
 |
services.exe |
SystemCheck
Added by the SOBER-M WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Configsystem subfolder of the Windows or Winnt folder |
 |
svchost.exe |
SystemCheck
Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a C:DriverLoad folder |
 |
SysCheckBop32.exe |
SystemCheck
WINBO adware |
 |
Syschk.exe |
SystemChecker
Added by the GALIL.F WORM! |
 |
SystemCONF98i.exe |
SystemCONF98i
Added by the GLITCH TROJAN! |
 |
Sysdeb32.exe |
SystemDebug
Added by the SYSBUG TROJAN! |
 |
SystemDefender.exe |
SystemDefender
SystemDefender spyware remover - not recommended, see here |
 |
SystemDll.exe |
SystemDll
Added by the LOXOSCAM TROJAN! |
 |
systemdll32.exe |
systemdll32.exe
Added by the FEUTEL-F TROJAN! |
 |
sd2006.exe |
SystemDoctor 2006 Free
SystemDoctor misleading security software - not recommended, see here |
 |
svchost.exe |
SystemDriverCheck
Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a C:DriverLoad folder |
 |
svchost.exe |
SystemDriverLoad
Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a C:DriverLoad folder |
 |
SysRep.exe |
SystemErrorFixer
SystemErrorFixer spyware remover - not recommended, see here |
 |
SystemFile.exe |
SystemFile
Added by the DULLDOOR-A TROJAN! |
 |
SystemGuardAlerter.exe |
SystemGuardAlerter
Part of the Iolo System Mechanic maintenance software. What does it do? |
 |
systeminit.exe |
systeminit
Added by the SILLYFDC-AN WORM! |
 |
Systemiom.exe |
Systemiom Updater
Added by the SPYBOT.TY WORM! |
 |
sysload32.exe |
SystemLoad32
Added by the MIMAIL.E WORM! |
 |
sysldr32.exe |
SystemLoader
Added by the DOWNLDR-NS TROJAN! |
 |
Sysman32.exe |
SystemManager
Added by the DOWNLOADER-BW.B TROJAN! |
 |
Sysmon32.exe |
SystemMonitor
Added by the AIDID.A WORM! |
 |
sysnet.exe |
SystemNetwork
Added by a variant of the RBOT WORM! |
 |
SystemNT.exe |
SystemNT
Added by the PWSVB-EG TROJAN! |
 |
scrtvc32.exe |
SystemOPsv
Added by a variant of the SPYBOT WORM! |
 |
svchost.exe |
SystemReg
Added by the DEWIN.E TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
 |
scchost.exe |
Systems
Added by the DAEMOZ.A TROJAN! |
 |
svch0st.exe |
Systems
Added by the MYDOOM.BI WORM! |
 |
Systems.exe |
Systems
Added by the BANKBOA-A TROJAN! |
 |
sescmgr.exe |
Systems
Added by the DWNLDR-GAH TROJAN! |
 |
spoolsvc.exe |
Systems
Added by the DLOADR-SW TROJAN! |
 |
sysmon.exe |
Systems
Added by the VIXUP-BI WORM! |
 |
slchost.exe |
Systems Restart
Added by the MULTIDROP.C TROJAN! |
 |
spchost.exe |
Systems Restart
Added by an unidentified WORM or TROJAN! |
 |
Systems.exe |
Systems.exe
Keyboard Spectator - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
 |
systems.exe |
systems.exe
KGBSpy is a commercial surveillance software program. It logs keystrokes, Web sites visited, and clipboard activity. It also has a screen capture logger and can be run automatically in a silent, undetectable mode |
 |
Syssafe.exe |
SystemSafe
System Safety Monitor - system monitoring tool with additional application firewalling |
 |
System32.exe |
SystemSAS
Added by the KWBOT.C WORM! |
 |
systembin.exe |
systemscroot
Added by a variant of the RBOT WORM! |
 |
shman.exe |
SystemService
Premium rate adult content dialler |
 |
sexypicz.exe |
SystemTasks
Adult content dialler |
 |
Systra.exe |
Systemtra
Added by the LOVGATE-W WORM! |
 |
SysTray.Exe |
SystemTray
SYSTRAY.EXE - System Tray Services. Provides the Volume Control, PC Card Status, Power Management and other icons that reside in the System Tray (see here). SYSTRAY.EXE may be disabled if none of these services are required. It will launch as and when required if you later enable the icons. If you need these items they're available via Start -> Settings -> Control Panel |
 |
SystemTray.exe |
SystemTray
Added by the BIGFOOT TROJAN! Note - this is not the legitimate systray.exe process |
 |
SysTray.exe |
SystemTray
Added by the ALADINZ.P TROJAN! Note - this is not the legitimate systray.exe process. If you right-click on the real systray.exe the "Properties" reveal it to be a Microsoft file |
 |
SysTraymon.exe |
SystemTray Monitor
Added by a variant of the SPYBOT WORM! See here |
 |
SDSystemTray.exe |
SystemTraySD
Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here |
 |
SRSystemTray.exe |
SystemTraySR
Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here |
 |
SystemUpd.exe |
SystemUpd
Updater for Swapoo.com, a kind of Napster for games |
 |
systemw32.exe |
systemw32
Added by a variant of the RBOT WORM! |
 |
Sniffer.exe |
SystemWizard Sniffer
SystemWizard for Win98/ME from SystemSoft - diagnoses and solves hardware and software problems on a PC |
 |
systemx32.exe |
systemx32
Added by a variant of the RBOT WORM! |
 |
systemyom.exe |
systemyom Updater
Added by a variant of the IRCBOT TROJAN! |
 |
SYSZ.exe |
SYSTEMZ Patch
Added by the ALADINZ.P TROJAN! |
 |
systen32.exe |
systen32.exe
Added by the AQP TROJAN! |
 |
systesms.exe |
Systesms.exe
Added by the RBOT-HI WORM! |
 |
Systest.exe |
Systest
Clean Space internet evidence eliminator |
 |
systime.exe |
SysTime
CoolWebSearch parasite variant - also detected as the STARTPA-FL TROJAN! |
 |
Systmesy.exe |
Systmesy
Added by the RBOT-KQ WORM! |
 |
systoan.exe |
Systoan32
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
SYSERVER.exe |
systr
Added by the VB-DQY WORM! |
 |
SERVICE.exe |
systr2
Added by the VB-DQY WORM! |
 |
systr32.exe |
systr32
?? |
 |
systrax.exe |
systrax
?? |
 |
Systray_.Exe |
Systray
Added by the KERGEZ.A WORM! |
 |
SysTray.Exe |
SysTray
SYSTRAY.EXE - System Tray Services. Provides the Volume Control, PC Card Status, Power Management and other icons that reside in the System Tray (see here). SYSTRAY.EXE may be disabled if none of these services are required. It will launch as and when required if you later enable the icons. If you need these items they're available via Start -> Settings -> Control Panel |
 |
Snnpapi.exe |
SysTray
Added by an unidentified TROJAN! |
 |
SteFanie.vbs |
Systray
Added by the STEFAN WORM! Note - make sure you check the hyperlink as this one copies it's self to numerous dirves and folders |
 |
svhost.exe |
SysTray
Added by the RAJILO-A WORM! |
 |
system.exe |
SysTray
Added by the DELF.E TROJAN! |
 |
systray.exe |
Systray driver
Added by the MUTEBOT TROJAN! Note - this is not the legitimate systray.exe process |
 |
SysTrayX.EXE |
SYSTRAYX
"SystrayX helps you hide some of the less used icons from the system tray (the hidden icons can still be seen and used in the special SysTrayX menu but will no longer permanently take precious space from your system tray)" |
 |
systree |
systree
Added by the BANCOS.L TROJAN! |
 |
spoolsvr.exe |
SYStry
Added by the SDBOT.GN WORM! |
 |
sysu.exe |
sysu
Dynamic Desktop Media adware - see here |
 |
sysug32.exe |
sysug32.exe
Added by an unidentified TROJAN or WORM! |
 |
Sysupd.exe |
SysUpd
VirtuMonde adware |
 |
Sysvupex.exe |
Sysvupex
Added by the MEDIAS TROJAN! |
 |
sysvx_.exe |
sysvx
Added by the LOOSKY-BX TROJAN! |
 |
SYSWB6.exe |
SYSWB6
Part of We-Blocker - gives parents the opportunity to monitor their children's Internet access and provide them with age-appropriate content, while filtering out sites that contain adult content. Works in conjunction with Winkb6 and both files are needed to run We-Blocker |
 |
SysWin.exe |
SysWin
Added by the IRCCONTACT TROJAN! |
 |
syswin32.exe |
syswin32
Added by a variant of the SPYBOT WORM! |
 |
Syswindow.exe |
Syswindow
Added by the COW TROJAN! |
 |
sys22.exe |
sysX3
Added by the RANTS.C WORM! |
 |
syscxd32.exe |
sysygm32
Added by the IRCBOT-PC TROJAN! |
 |
Service.exe |
SYS_CLEAN
Added by the FLOPCOPY WORM! |
 |
svchostsys.exe |
sys_up1
Added by the MULTIDR-FL TROJAN! |
 |
SZMsgSvc.exe |
SZMsgSvc.exe
StopZilla! - pop-up killer |
 |
speedmgr.exe |
T-DSL SpeedMgr
T-Online ISP SpeedManager - shows upload and download speed. Also checks for updates automatically |
 |
stte.exe |
Taba
PurityScan/Clickspring adware |
 |
SPLSHWRP.EXE |
TabletWizard
Microsoft Tablet PC Component |
 |
sprtcmd.exe /P TalkTalk |
TalkTalk
Self-help support tool for TalkTalk Broadband users (provided by SupportSoft, Inc). Identifies and automatically fixes typical problems that may occur with your high-speed internet service |
 |
Setup.exe |
Tango
Tango Broadband access software. Is it required? |
 |
sysdll.exe |
Task Debugger
Added by the RBOT-CQ WORM! |
 |
svchost.exe |
Task Manager
Added by the SOHANA-P WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup! |
 |
svhost32.exe |
Task Manager
Added by the TERMX.A WORM! |
 |
svchost.exe |
Task Monitoring Service
Added by the CONE.D WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "tasks" subfolder of the Winnt or Windows folder |
 |
schedsvc32.exe |
Task Scheduler Engine
Added by the RBOT-ASJ WORM! |
 |
system.exe |
Taskmgr
Added by the PAKES.G TROJAN! |
 |
spoolsvc.exe |
Tcp Application Manager
Added by the DLOADER-NY TROJAN! |
 |
svcadmin.exe |
Tcp Application Manager
Added by the DLOADER-NY TROJAN! |
 |
svcman.exe |
Tcp Application Manager
Added by the DLOADER-NY TROJAN! |
 |
svcrun.exe |
Tcp Application Manager
Added by the DLOADER-NY TROJAN! |
 |
services.exe |
TEXTCONV
Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
 |
spyguard.exe |
The Spy Guard
The SpyGuard spyware remover - not recommended, see here |
 |
spyguard_monitor.exe |
The Spy Guard Monitor
The SpyGuard spyware remover - not recommended, see here |
 |
Shine.exe |
Tiger
Added by the HAPPYLOW (or NISHE-A) VIRUS! |
 |
sample.exe |
tmp_up
QuickBar adware |
 |
smss.exe |
Tok-Cirrhatus
Added by the BRONTOK-A WORM and variants! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the "Documents and Settings[User]Local SettingsApplication Data"" folder |
 |
sv711224030r.exe |
Tok-Cirrhatus-1959sarc
Added by the BRONTOK-R WORM! |
 |
smss.exe |
Tok-Cirrhatus-2784
Added by the BRONTOK-S WORM! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the "Documents and Settings[User]Local SettingsApplication Data"" folder |
 |
smss.exe |
Torjan Program
Added by the WOWCRAFT.B TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
system32.exe |
Torrent Management Service
Added by a variant of the IRCBOT TROJAN! See here |
 |
STMonitor.exe |
Track4WinMonitor
Track4Win is a surveillance software program that takes screenshots and logs user activity such as URLs and currently running processes. It uploads the logs and screenshots to a preconfigured server. Uninstall this software unless you put it there yourself |
 |
stdhost.exe |
Transaction Tasker
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
spower.drv |
TSPower
Found on a Toshiba laptop. Related to power management? |
 |
scvc.exe |
ttool
Added by the OWM TROJAN! |
 |
System.Trubo.vbs |
TurBo
Added by the AUTOM-C WORM! |
 |
sps32.exe |
TURXP Protocol
Added by a variant of the SDBOT WORM! |
 |
Schedule.exe |
TvrSchedule
Scheduler for Mercury Ez View TV Tuner Card |
 |
scheduler_proxy.exe |
TVT Scheduler Proxy
Part of IBM ThinkPads SystemUpdate software. Is it required? |
 |
SCardS32.Exe |
TwkSCardSrv
Used with Towitoko SmartCard Readers for card recognition |
 |
SpyRem.exe |
TZ Spyware Remover
TZ Spyware Remover spyware remover - not recommended, see here |
 |
sybqnub.exe |
udjudwq
Added by the SILLYFDC-AH WORM! |
 |
sys****.exe |
Ulubione
Ulubione adware |
 |
SpeedUpMyPC.exe |
Uniblue SpeedUpMyPC
Older version of SpeedUpMyPC from Uniblue - which "lets you monitor and control all your PC resources with easy, one click instructions. System settings, internet usage, disk clutter, RAM and CPU are all automatically scanned, cleaned and optimized for peak performance" |
 |
spyeraser.exe |
Uniblue SpyEraser
SpyEraser from Uniblue. Spyware detection program |
 |
SetDfltSettings.exe |
UniPrint
Drivers for Uniprint, a printing help for Terminal Services and Citrix which recieves downloaded files from a Uniprint enabled server and prints them locally allowing for truly universal printing through Terminal Services or Citrix |
 |
svchost32.exe |
Universal USB Service
Added by the KELVIR.R WORM! |
 |
Sysupd.exe |
Update
Added by the SLACKBOT VIRUS! |
 |
svchost.exe |
Update
Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
scvhost.exe |
Update Checker
Added by the AGENT-DSF TROJAN! |
 |
Schost.exe |
Update Install
Added by the GAOBOT.AO WORM! |
 |
SetCPQLC.exe |
Update local
Running on a Compaq desktop. Any ideas? |
 |
svxhost.exe |
update service
Added by the RBOT-MG WORM! |
 |
Swap.exe |
Update ver 1.0
Added by the SWAP-C WORM! |
 |
sgtray.exe |
UpdateManager
StorageGuard from Veritas (this version by Sonic). Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups |
 |
svhost.exe |
UPDATEMSN
Added by an unidentified WORM or TROJAN! |
 |
svhost32.exe |
Updater Service Process
Added by the AGOBOT.TY WORM! |
 |
services.exe |
upDpacketo
Added by the NAFBOT-A TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "TEMPER" subfolder of the Windows or Winnt folder |
 |
sxchost.exe |
Upgrade Sarvice
Added by a variant of the TOFGER-I TROJAN! |
 |
sxchost.exe |
Upgrade Service
Added by the TOFGER-I TROJAN! |
 |
SASS.EXE |
usb
Added by the FUNSTA-A TROJAN! |
 |
Svcmm32.exe |
USB controller
SvcMM backdoor parasite downloader |
 |
servicelog.exe |
USB Device
Added by the WOOTBOT.CB WORM! |
 |
SKBPATCH.EXE |
USB Hub Keyboard Patch
USB HUB Update |
 |
smss32.exe |
UsbD
Adware - detected by Kaspersky as the AGENT.CJ TROJAN! |
 |
svhost32.exe |
UsbD
Added by the AGENT.IB TROJAN! |
 |
servicetask.exe |
usbdrv
Added by a variant of the SDBOT WORM! |
 |
sst4.exe |
USBHWDRV
Added by a variant of the LOWZONE-I TROJAN! |
 |
sst6.exe |
USBHWINFO
Added by the LOWZONE-I TROJAN! |
 |
svchst.exe |
useful-soft
Added by the STARTPA-HH TROJAN! |
 |
systems.com |
userd
Added by the OUTLAW-A WORM! |
 |
smss.exe |
userinit
Added by the DLOADR-B TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This trojan file is found in the Windows or Winnt folder |
 |
srv32.exe |
Userinterface Reporter
ISTBar adware |
 |
sscbltqu.exe |
ushli
Obtained from an MP3 search list site. Also generates random processes on reboot |
 |
syswrun4x.exe |
usrgtway.exe
Added by the MITGLIEDER.E TROJAN! |
 |
svchosts.exe |
valuename
Added by a variant of the SDBOT WORM! |
 |
stim11.exe |
Veo Velocity Connect
Support software for the Veo Velocity Connect webcam |
 |
svchost.exe |
Video Driver
Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
 |
sysconf.exe |
Video Process
Added by the GAOBOT.GEN!POLY or GAOBOT.UM or GAOBOT.ADX WORMS! |
 |
sys32.exe |
Video Services
Added by the AGOBOT.PS WORM! |
 |
svchosts.exe |
virtual-machine
Added by the RBOT-US WORM! |
 |
Spoolsvr.exe |
Vital Load Process
Added by the RBOT.AIF WORM! |
 |
smrs.exe |
vsadmin
Added by the AGOBOT-RC WORM! |
 |
spooll32.exe |
vscanner
Added by the OPTIXPRO.10 TROJAN! |
 |
Scran.exe |
W32.Scran
Added by the NARCS WORM! |
 |
syslaunch.exe |
Wardo
Added by the ADCLICKER.G TROJAN! |
 |
spoolsb.exe |
WCESMngr
Added by the AGOBOT-QZ WORM! |
 |
skybotx.exe |
WDNS SYSTEM
Added by the MYTOB-BY WORM! |
 |
SbWeatherOnTray.exe |
WeatherOnTray
Hotbar adware |
 |
sm.exe |
Web Service
Added by the BUBE-F VIRUS! |
 |
sttray.exe |
WebOutfitterTray
Intel WebOutfitter service System Tray icon |
 |
stopsignav.exe |
webscan
eAcceleration Stop-Sign security software related. Previously not recommended, see here |
 |
Save.exe |
WhenUSave
WhenU.Save adware |
 |
Search.exe |
WhenUSearch
WhenU.Save adware |
 |
ssvsol.exe |
whxpin service
Added by a variant of the SDBOT WORM! |
 |
sysin.pif |
Win CPU
Added by the RBOT-AXL WORM! |
 |
stat.exe |
win name
?? |
 |
SysUpdate.exe |
Win Update
Added by the AGOBOT-TN WORM! |
 |
Shakira_1997_Part_1_.Mpeg_.scr |
win32
Added by the MYLIFE.N WORM! |
 |
Setup_32.exe |
win32
Added by the EVILBOT.B TROJAN! |
 |
system32.vbs |
Win32
Added by the SWERUN VIRUS! |
 |
sysmon.exe |
Win32
Added by the MYTOB-HQ TROJAN! |
 |
svchosts.exe |
Win32 Driver
Added by the FORBOT-FD WORM! |
 |
secure32.exe |
Win32 Security Protocol
Added by the RBOT-ETI WORM! |
 |
svchosts.exe |
Win32 Svchosts Driver
Added by the FORBOT-FO WORM! |
 |
spoolsvc.exe |
Win32 System Spool
Added by the SDBOT.UK WORM! |
 |
svchosts.exe |
Win32 Update
Added by a variant of the SDBOT WORM! |
 |
svchostt.exe |
win32 update service
Added by a variant of the SDBOT WORM! |
 |
svhosint32.exe |
Win32 Usb Driver
Added by the FORBOT-BE or FORBOT-J WORMS! |
 |
smsc.exe |
Win32 USB2 Driver
Added by the SDBOT.FO WORM! |
 |
svchosting.exe |
Win32 USB2 Driver
Added by the FORBOT.J or SDBOT.HU WORM! |
 |
sys32.exe |
Win32 USB2 Driver
Added by the WOOTBOT.X WORM! |
 |
sys32snd.exe |
Win32 USB2 Driver
Added by the FORBOT-AN WORM! |
 |
syscfg32.exe |
Win32 USB2 Driver
Added by the FORBOT-R WORM! |
 |
service.exe |
Win32 USB2.0 Driver
Added by the SDBOT-QF WORM! |
 |
Scandisk.com |
Win32G
Added by the ESTRELLA TROJAN! |
 |
systroy.exe |
win32ini
Added by the IRC.ALADINZ.C TROJAN! |
 |
Server.com |
Win32R
Added by the ESTRELLA TROJAN! |
 |
ssrs.exe |
win32usbd
Added by the RBOT-RA WORM! |
 |
system_wc.exe |
WIN32WN
Eziin adware |
 |
sp32.dll |
Win386
Homepage hijacker. Not a dll but a regfile in disguise |
 |
Shch.exe |
WinAmpAgent
Added by the EB TROJAN! Note - this is NOT the popular Winamp media player which has a different filename |
 |
svchst.exe |
WinAmpAgent
Added by the EB TROJAN! Note - this is NOT the popular Winamp media player which has a different filename |
 |
sdhch.exe |
WinAmpAgent
Added by the TACTSLAY.B TROJAN! |
 |
svchost.exe |
WinAppLog
StingKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the svchost.exe process that normally doesn't appear in Msconfig/Startup! |
 |
swchost.exe |
Winbin
Added by the RBOT.CLS WORM! |
 |
services.exe |
WinCheck
Added by the SOBER-S WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "ConnectionStatusMicrosoft" subfolder of the Windows or Winnt folder |
 |
services.exe |
WinCheck
Added by the SOBER.S WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "ConnectionStatusMicrosoft" subfolder of the Windows or Winnt folder |
 |
servicelogd.exe |
Wind Logd File
Added by a variant of the RBOT WORM! |
 |
ssprotecter.exe |
Wind0ws Sharing
Added by the RBOT-AHW WORM! |
 |
services.exe |
WinData
Added by the SOBER.AA WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "PoolData" subfolder of the Windows or Winnt folder |
 |
service.exe |
WinDLL (service.exe)
Detected by Kaspersky as the AGENT.BX WORM! See here. The "service.exe" file is found in %System% |
 |
ssvchost.exe |
window2
Added by the IRCBOT.H TROJAN! |
 |
services.exe |
Windows
Added by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "WinSecurity" subfolder of the Windows or Winnt folder |
 |
system copy.exe |
windows
Added by the SALGA.A WORM! |
 |
system.exe |
Windows
Added by the SPYBOT.OBB WORM! |
 |
services.exe |
Windows
Added by the SOBER-Z WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! ! This file is located in a "WinSecurity" subfolder of the Windows or Winnt folder |
 |
services.exe |
Windows
Added by the DLOADR-GW TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "Windows" subfolder |
 |
smss.exe |
Windows
Added by the BANCBAN-QF TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
svchost.exe |
windows
Added by the SLOMIRC-A WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
spoovlss.exe |
Windows
Added by an unidentified WORM or TROJAN! See here |
 |
spoolsvc.exe |
Windows .Net Manager
Added by the DLOADER-NY TROJAN! |
 |
svcadmin.exe |
Windows .Net Manager
Added by the DLOADER-NY TROJAN! |
 |
svcman.exe |
Windows .Net Manager
Added by the DLOADER-NY TROJAN! |
 |
svcrun.exe |
Windows .Net Manager
Added by the DLOADER-NY TROJAN! |
 |
setup.exe |
Windows Accelerators
KeySpy keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
syssv.exe |
Windows Activate System
Added by a variant of the SPYBOT WORM! |
 |
sistem.exe |
Windows Ba?lang?? Dosyas?
Added by the MUZK WORM! |
 |
systemss.exe |
Windows backup
Added by a variant of the SPYBOT WORM! |
 |
Systemwks32.exe |
Windows Bootup
Added by a variant of the RBOT WORM! |
 |
SbiCvy.exe |
Windows bypass security SMSS Service
Added by the RBOT-GRF WORM! |
 |
SSYS.EXE |
Windows Config
Added by the SPYBOT-DA WORM! |
 |
svchost.exe |
Windows Default Configuration
Added by the DLOADER-U TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup! |
 |
SYSCFG16.EXE |
Windows DLL Loader
Added by the DOMWIS-N WORM! |
 |
svchost.exe |
Windows DLL Services
Added by the AGENT.H spyware! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
 |
system.exe |
Windows DLL Services
AGENT.H spyware |
 |
spoolsrv.exe |
Windows DLL Tracker
Added by a variant of the WOOTBOT WORM! |
 |
System32Driver32.exe |
Windows Drive Compatibility
Added by the SUPOVA.Z WORM! |
 |
svchost.exe |
Windows Driver Adapter
Added by the ANTINNY-K WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in a "drivers" subfolder |
 |
ssms.exe |
Windows Drivers
Added by the RBOT-AT WORM! |
 |
sntsvc.exe |
Windows Event Section
Added by a variant of the IRCBOT TROJAN! See here |
 |
svchostie.exe |
Windows Executer
Detected by Kaspersky as the EGGDROP.V BACKDOOR! See here |
 |
system32.exe |
Windows Explorer
Added by the RBOT-AJH WORM! |
 |
svchost.exe |
Windows Firewall
Added by the PROXY-HT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
scvhost.exe |
Windows Firewalll
Added by the RBOT-EK WORM! |
 |
sphost.exe |
Windows Firewalll
Added by a variant of the RBOT WORM! |
 |
svvhost.exe |
Windows Firewalll
Added by a variant of the RBOT WORM! |
 |
svghost.exe |
Windows Genuine
Added by a variant of the SPYBOT WORM! See here |
 |
svchost32.exe |
Windows Help Manager
Added by the RBOT-OZ WORM! |
 |
scvhosts.exe |
Windows Host Service
Added by the SPYBOT.NLI WORM! |
 |
svchoste.exe |
Windows Host Service
Added by the KELVIR.BF WORM! |
 |
svchosts32.exe |
Windows Host Service
Added by the KELVIR.AW WORM! |
 |
Sysconf32.exe |
Windows HTML file reader
Added by the NOOMY.A WORM! |
 |
sysays.exe |
Windows Identify
Added by a variant of the SPYBOT WORM! See here |
 |
svchost.exe |
Windows Internet Manager
Added by a variant of the IRCBOT TROJAN! See here. Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
SysUpdate.exe |
Windows Loader
Added by a variant of the SDBOT WORM! |
 |
spoolsvc.exe |
Windows Local Services
Added by the DLOADER-NY TROJAN! |
 |
svcadmin.exe |
Windows Local Services
Added by the DLOADER-NY TROJAN! |
 |
svcman.exe |
Windows Local Services
Added by the DLOADER-NY TROJAN! |
 |
svcrun.exe |
Windows Local Services
Added by the DLOADER-NY TROJAN! |
 |
services.exe |
Windows Logon Application
Added by the CIADOOR-L TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
Svchoste.exe |
Windows Logon Procedure
Added by a variant of the SPYBOT WORM! |
 |
Svchosta.exe |
Windows Logon Procedure
Added by a variant of the SPYBOT WORM! |
 |
Sygate32.exe |
Windows media service
Added by the RBOT.ADE WORM! |
 |
svchosl.exe |
Windows Messanger Control Center
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
svhost.exe |
Windows Messanger Control Center
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
sucker.exe |
Windows MS Update 32
Added by the FORBOT-GJ WORM! |
 |
swchost.exe |
Windows MSN2 XP
Detected by Trend Micro as the KOLAB.AA WORM! See here |
 |
service.exe |
Windows Net Cfg
Added by a variant of the RBOT WORM! |
 |
sysMGT.exe |
Windows Nivedia Driver
Added by a variant of the RBOT WORM! |
 |
sess.exe |
Windows NT Session Manager
Added by a variant of the RBOT WORM! |
 |
SCVHOSTS.EXE |
Windows Print Spooler
Suspicious due to the similarity to the valid "svchost.exe" file |
 |
SVEHOST.EXE |
Windows Print Spooler
Added by the SPYBOT.H WORM! |
 |
ssservice.exe |
Windows Reg Services
Added by the PRORAT-D TROJAN! |
 |
svmhost.exe |
Windows Register Settings
Added by a variant of the FORBOT WORM! |
 |
svhchosts.exe |
Windows Registery Center
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
svcdll.exe |
Windows Registry Scan
Added by the RBOT-TP WORM! |
 |
swchost.exe |
Windows report
Added by the SMALL-BD TROJAN! |
 |
system.exe |
windows run
Added by the ICPASS-A WORM! |
 |
scheduler.exe |
Windows Scheduler!
Added by a variant of the IRCBOT TROJAN! See here |
 |
Service.exe |
Windows Screensaver
Added by the KELVIR.P WORM! |
 |
ssaver.scr |
WINDOWS SCREENSAVER
Added by the SDBOT-YZ WORM! |
 |
setver32.exe |
Windows secure
Added by the SPYBOT.EP WORM! |
 |
ssms.exe |
Windows Secure Services
Added by the RBOT-GAR WORM! |
 |
sxe.exe |
Windows Security Center Notification Appls
Added by the RBOT-GKX WORM! |
 |
sxes.exe |
Windows Security Center Notification Applse
Added by the RBOT-GLR WORM! |
 |
sysecurex.exe |
Windows Security Center Notification Applsee
Added by a variant of the RBOT-GKX WORM! |
 |
svchost.exe |
Windows Security Manager
Added by the ANTINNY.AX WORM!! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "Microsoft" subfolder |
 |
svchosl.exe |
Windows Security Survy
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
security32.exe |
Windows Security Update
Affilred adware |
 |
syssrv.exe |
Windows Server Drivers
Added by a variant of the IRCBOT TROJAN! See here |
 |
servinfo.exe |
Windows Server Information
Added by the FORBOT-EN WORM! |
 |
svvhost.exe |
Windows Service
Added by the AGOBOT-HL WORM! |
 |
services.exe |
Windows Service
Added by the KALEL-A WORM! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
 |
services.exe |
Windows Service Controller
Added by the KALEL-B WORM! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
 |
scvhost.exe |
Windows Service Host
Added by the SDBOT.N TROJAN! |
 |
svchost.exe |
Windows Service Host
Added by the CONE.B WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
 |
svchost.exe |
Windows Service Host
Added by the KALEL-C WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
 |
schost.exe |
Windows Service Host
Added by the GAOBOT.AO WORM! |
 |
spoolsvc.exe |
Windows Service Manager
Added by the DLOADER-NY TROJAN! |
 |
svcadmin.exe |
Windows Service Manager
Added by the DLOADER-NY TROJAN! |
 |
svcman.exe |
Windows Service Manager
Added by the DLOADER-NY TROJAN! |
 |
svcmgr32.exe |
Windows Service Manager
Added by the OSCABOT-D WORM! |
 |
svcrun.exe |
Windows Service Manager
Added by the DLOADER-NY TROJAN! |
 |
svchhost.exe |
Windows Service Pack2
Added by a variant of the RBOT WORM! |
 |
SVSS32.EXE |
Windows Service Support Call
Added by the RBOT-XQ WORM! |
 |
sv32.exe |
Windows Service SV
Added by a variant of the IRCBOT TROJAN! |
 |
svcthreading.exe |
Windows Service Threads
Added by a variant of the IRCBOT TROJAN! See here |
 |
svcthreads.exe |
Windows Service Threads
Added by a variant of the IRCBOT TROJAN! See here |
 |
service.exe |
Windows Services
Added by the RANDEX.R WORM! |
 |
svchosts.exe |
Windows Services
Added by the AGOBOT-KL TROJAN! |
 |
scmsg.exe |
Windows Services
Added by a variant of the SDBOT WORM! |
 |
scvhoste.exe |
Windows Services
Added by the SPYBOT.OBZ WORM! |
 |
smsc.exe |
Windows Services
Added by a variant of the SDBOT WORM! |
 |
spoolsvc.exe |
Windows Services
Added by the SDBOT.CPZ WORM! |
 |
servicez.exe |
Windows Services
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
svcbrun.exe |
Windows Services B-Runner
Added by a variant of the IRCBOT TROJAN! See here |
 |
svcbrunner.exe |
Windows Services B-Runner
Added by a variant of the IRCBOT TROJAN! See here |
 |
svccert.exe |
Windows Services Certification
Added by a variant of the IRCBOT TROJAN! See here |
 |
svcguide.exe |
Windows Services Guide
Detected by Symantec as the SILLYIM WORM! See here |
 |
svcguides.exe |
Windows Services Guide
Added by the CHECKOUT WORM! See here |
 |
svchost.exe |
Windows Services Host
Added by the CONE or CONE.E WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
 |
svhosts.exe |
Windows Services Hosts
Added by the SDBOT-YH TROJAN! |
 |
svcjog.exe |
Windows Services Jog
Added by a variant of the IRCBOT TROJAN! See here |
 |
svcjogg.exe |
Windows Services Jog
Detected by Trend Micro as the AGENT.QAF WORM! See here |
 |
svcjoger.exe |
Windows Services Joger
Added by a variant of the IRCBOT TROJAN! See here |
 |
svcjogging.exe |
Windows Services Jogging
Added by a variant of the IRCBOT TROJAN! See here |
 |
svcjoging.exe |
Windows Services Joging
Detected by Trend Micro as the IRCBOT.AVI TROJAN! See here |
 |
sslms.exe |
Windows Services Layer
Added by the RBOT-GAH WORM! |
 |
svctowers.exe |
Windows Services Tower
Detected by Trend Micro as the IRCBOT.AGJ TROJAN! See here |
 |
svctowing.exe |
Windows Services Tower
Added by a variant of the IRCBOT TROJAN! See here |
 |
svch0st.exe |
Windows Services Update
Added by a variant of the RBOT WORM! Note - the filename has the digit 0 rather then the uppercase "o" |
 |
serviser.exe |
Windows Servser
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
smss32.exe |
Windows Session Manager
Added by a variant of the RBOT WORM! |
 |
smss.exe |
Windows Session Manager Subsystem
Added by the KALEL-B WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup! |
 |
shell.exe |
Windows Shell
Added by the MYTOB-CA WORM! |
 |
sky.exe |
WINDOWS SKY
Added by the MYTOB.CH WORM! |
 |
smart.exe |
Windows Smart Manager
Added by the RBOT-SL WORM! |
 |
service.exe |
Windows smss service
Added by the AGENT-FPY TROJAN! |
 |
svdhost.exe |
Windows Sound
Detected by PCTools as the RBOT.ABCC WORM! See here |
 |
SndMon32.exe |
Windows Sound Driver
Added by a variant of the SPYBOT WORM! |
 |
snd32_win.exe |
Windows Sound Emulator
Added by the ATNAS.A WORM! |
 |
SndMon32.exe |
Windows Sound Manager
Added by the FORBOT-BU WORM! |
 |
SndMon16.exe |
Windows Sound Manager
Added by a variant of the FORBOT WORM! |
 |
Sp2update.exe |
Windows SP2 Update
Added by the WOOTBOT.BS WORM! |
 |
spoolsrv.exe |
Windows Spool Server
Added by the SDBOT-ACT WORM! |
 |
spoolasrv.exe |
Windows SpoolaPrint Service
Added by the SDBOT-AYD WORM! |
 |
SPOOLSRV.EXE |
Windows Spooler
Added by the SPYBOT.P WORM! |
 |
spoolsv32.exe |
Windows Spooler
Added by an unidentified WORM or TROJAN! |
 |
spool.exe |
Windows Spooler Services
Added by the AGOBOT-AMO WORM! |
 |
spoolersrv.exe |
Windows SpoolPrint Service
Added by the SDBOT-ZT WORM! |
 |
spoolservr.exe |
Windows spoolservr Service
Added by the SDBOT-AAN WORM! |
 |
spoolsre.exe |
Windows Spoolsre Service
Added by the SDBOT-AAE WORM! |
 |
spoolmsv.exe |
Windows Spoolsrv Service
Added by the SDBOT-ZS WORM! |
 |
spoolssv.exe |
windows spoolsrv service
Added by the SDBOT-AWV WORM! |
 |
spoolsurf.exe |
Windows Spoolsurf Service
Added by the SDBOT-ZZ WORM! |
 |
spooltsrv.exe |
Windows SpooltPrint Service
Added by the SDBOT-AYE WORM! |
 |
spoolvvv.exe |
Windows Spoolvvv Service
Added by the SDBOT-AAW WORM! |
 |
scvhost.exe |
Windows SQL management 1.33
Added by the SPYBOT-OB WORM! |
 |
SSL32Dr.exe |
Windows SSL Secondary Drivers
Added by the SDBOT.ASQ WORM! |
 |
Sounddrv.exe |
Windows Stand Sound Drivers
Added by the SDBOT-XF WORM! |
 |
services21.exe |
Windows Startup
Added by the AGOBOT-MX WORM! |
 |
sysrun32.exe |
Windows Startup 32 Bits
Added by a variant of the DARKSUN TROJAN! |
 |
svchost.exe |
Windows Stortup
Added by the TOGER-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
service.exe |
Windows svchost
Detected by Kaspersky as the SDBOT BACKDOOR! See here |
 |
serviceaaa.exe |
Windows svchost
Detected by Trend Micro as the LAMER.AA BACKDOOR! See here |
 |
servicean.exe |
Windows svchost
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
svchost.exe |
Windows svchost
Added by the IRCBOT-ZQ WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
slsass.exe |
Windows Svchost Authority
Added by the RBOT-UA WORM! |
 |
svcsshost32.exe |
Windows Svshost Service Update 32
Added by the FORBOT-GD WORM! |
 |
SyncroAd.exe |
Windows SyncroAd
Windupdates adware variant |
 |
skybot.exe |
WINDOWS SYSTEM
Added by the MYTOB-CX WORM! |
 |
skybotx.exe |
WINDOWS SYSTEM
Added by the MYTOB-BY WORM! |
 |
smoc.exe |
WINDOWS SYSTEM
Added by the MYTOB.FU WORM! |
 |
smsc.exe |
WINDOWS SYSTEM
Added by the MYTOB-BR WORM! |
 |
skybot.exe |
WINDOWS SYSTEM
Added by the MYTOB.JU WORM! |
 |
servce.exe |
WINDOWS SYSTEM
Added by the MYTOB-EI WORM! |
 |
servises.exe |
WINDOWS SYSTEM
Added by the ZOTOB-I WORM! |
 |
sky.exe |
WINDOWS SYSTEM
Added by the MYTOB.LB WORM! |
 |
SysBackup.exe |
Windows System Backup
Unidentified malware |
 |
SYSCFG16.EXE |
Windows System Configuration
Added by the WISDOOR.Z TROJAN! |
 |
sysretain.exe |
Windows System Drivers
Added by a variant of the IRCBOT TROJAN! See here |
 |
SPOOLER.EXE |
Windows System Gateway
Added by a variant of the RBOT WORM! |
 |
sysconf.exe |
Windows System Manager
Added by the MYTOB.AL WORM! |
 |
smsc.exe |
Windows System Manager
Added by a variant of the RBOT WORM! |
 |
spoolsvc.exe |
WINDOWS SYSTEM MANAGER
Added by the MYTOB-LY WORM! |
 |
smsls.exe |
Windows System Manager Loader
Added by the AGOBOT.TF WORM! |
 |
Sblhost.exe |
Windows System Restore Configuration
Added by a variant of the SPYBOT WORM! |
 |
SystemRestorer.exe |
Windows System Restorer
Added by the DULOAD.C WORM! |
 |
scalpe91.exe |
WINDOWS SYSTEM SCALPE
Added by the MYTOB_HI WORM! |
 |
sys32.pif |
Windows System Security
Added by the RBOT-AOL WORM! |
 |
swhost.exe |
Windows System Tray
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
System32.exe |
Windows System32
Added by the SDBOT-ALI WORM! |
 |
system32.exe |
Windows System32 Kernel
Added by the SDBOT-AAT WORM! |
 |
servicces.exe |
WINDOWS SYSTEMn
Added by the MYTOB-EL WORM! |
 |
stagmr.exe |
Windows Systemnmg
Added by the MYTOB.S WORM! |
 |
service.exe |
Windows Taskmanager
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
svchost.exe |
Windows Taskmanager
Added by the IMBOT.AC WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
SVPHOST.exe |
Windows TM
Added by a variant of the RBOT WORM! |
 |
scvhost.exe |
Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! |
 |
sychost.exe |
windows update
Added by the LEOX.B WORM! |
 |
svchosts.exe |
Windows Update
Added by the FRUCTA TROJAN! |
 |
scvhost.exe |
Windows Update
Added by the SDBOT-XT WORM! |
 |
Sqltob.exe |
Windows Update
Added by the DASHER.A WORM! |
 |
SecretStub.exe |
Windows Update
Added by the SRAMLER.C WORM! |
 |
scrigz.exe |
Windows Update
Added by a variant of the IRCBOT BACKDOOR! |
 |
slsys.exe |
Windows Update 32
Added by a variant of the FORBOT WORM! |
 |
shupd64.exe |
Windows Update 63
Added by the FORBOT-GA WORM! |
 |
svthx.exe |
Windows Update Center
Added by the STUBBOT.A WORM! |
 |
syslodr.exe |
Windows Update Check
Added by the SMALL.LU TROJAN! |
 |
svhost.exe |
Windows update config
Added by the SDBOT-PF WORM! |
 |
svghost.exe |
windows update configurator
Added by a variant of the SPYBOT WORM! |
 |
smcg.exe |
Windows Update Service
Added by the SDBOT.QY WORM! |
 |
SP00ISS.exe |
Windows Update Service
Added by the SDBOT-ZH WORM! |
 |
systemupdate.exe |
Windows Update Service 2004/2005
Added by the RBOT-JE WORM! |
 |
system.exe |
Windows Update Software
Added by the TOFGER.BX TROJAN! |
 |
svhostcs32.exe |
Windows Update System Shell
Added by the RBOT-AAZ WORM! |
 |
spoolsae.exe |
Windows Updated
Added by the RBOT-APM WORM! |
 |
svigost.exe |
Windows Updater
Added by the RBOT-VS WORM! |
 |
sdsys.exe |
Windows Updater
Added by the FORBOT-JG WORM! |
 |
servupdate.exe |
Windows USB Monitor
Detected by Trend Micro as the IRCBRUTE.AQ TROJAN! See here |
 |
sysvers.exe |
Windows Version Service
Added by a variant of the IRCBOT TROJAN! See here |
 |
spoolsvc.exe |
Windows Web Services
Added by the DLOADER-NY TROJAN! |
 |
svcadmin.exe |
Windows Web Services
Added by the DLOADER-NY TROJAN! |
 |
svcman.exe |
Windows Web Services
Added by the DLOADER-NY TROJAN! |
 |
svcrun.exe |
Windows Web Services
Added by the DLOADER-NY TROJAN! |
 |
svchost.exe |
Windows Xp Service Pack 2
Added by the XPLOS-A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
 |
System32.exe |
Windows-System
Added by the LOGPOLE.C WORM! |
 |
system.exe |
Windows32
Unknown malware |
 |
sysexhook.exe |
WindowsAgent
Added by the GOP keyboard logger/TROJAN! |
 |
Server5.exe |
WindowsAPI.DLL
Added by the "Fear and Hope" TROJAN! |
 |
systemupd.exe |
WindowsAudio
Added by the AGENT-TH WORM! |
 |
s1.exe |
WindowsD
Added by the MSNDIABLO.A WORM! |
 |
svcsvh32.exe |
WindowsDiskEvt
Added by the NANINF.D TROJAN! |
 |
sqldata1.exe |
WINDOWSflashbrg
Added by a variant of the AGENT-IC TROJAN! |
 |
svchoosts.exe |
WindowsRegKey update
Added by the RBOT.ADB WORM! |
 |
svchostc.exe |
WindowsRegKey update
Added by the RBOT.IF WORM! |
 |
sp2.exe |
WindowsSp2
Added by the POSSE WORM! |
 |
svchosts.exe |
WindowsSystem32
Added by the AGENT-EDA TROJAN! |
 |
svchost.exe |
WindowsUpdate
Added by the ASTEF or RESPAN WORMS or AGENT-V TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
 |
svchost.exe |
WindowsUpdate
Added by the IK TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
 |
svchostw.exe |
WindowsUpdate
Added by the COBFINN_B TROJAN! |
 |
Strad.exe |
WindowsUpdate
Added by the CULLER-D WORM! |
 |
svchost.exe |
WindowsUpdatem2
Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
 |
svwhost.exe |
WindowsUpdateNT
Added by the SHELLOT-B TROJAN! |
 |
spool.exe |
WindowsXp Security
Added by the RBOT-GRK WORM! |
 |
svcnxp32.exe |
WindowsXPserv
Addee by the NANINF-A TROJAN! |
 |
SERVICE.exe |
Windows_Serivce
Added by the WOOTBOT.AH WORM! |
 |
svthost.exe |
Windows_Updates
Added by a variant of the SPYBOT WORM! |
 |
SchSvr.exe |
WinDVR SchSvr
WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs |
 |
services.exe |
WinINet
Added by the SOBER-P WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "ConnectionStatus" subfolder of the Windows or Winnt folder |
 |
steam.exe |
Winlogin.exe
Added by a variant of the AGENT.AH TROJAN! |
 |
system.exe |
winlogon
Added by a variant of the DELF.CNS TROJAN! |
 |
servicec.exe |
WinLsass
Added by the SCANE WORM! |
 |
schost.exe |
WinManager
?? |
 |
syshost.exe |
WinMessenger
Added by the OPANKI-E WORM! |
 |
scvhost.exe |
Winmgr.exe
Added by the AGOBOT.AFG WORM! |
 |
SysRep.exe |
WinPCDoctor
WinPCDoctor misleading security software - not recommended, see here |
 |
sndcfg16.exe |
WinProfile
Added by the SNDC.A WORM! |
 |
server.exe |
WinProt
Added by the CHUPACABRA TROJAN! |
 |
svchosst.exe |
winreg_32
Added by the BANCOS-CE TROJAN! |
 |
sysdll.exe |
winreg_32
Added by the DLOADER-IJ TROJAN! |
 |
svchost32.exe |
WINRUN
Added by the MYTOB-AI WORM! |
 |
services32.exe |
Wins Update 32
Added by the FORBOT-FN WORM! |
 |
Secureantivirus.exe |
Winsecure Antivirus
Added by a variant of the SPYBOT WORM! |
 |
ssmr.exe |
WinSecured32
Added by a variant of the FORBOT WORM! |
 |
Server.txt.vbs |
winserver
Added by the DELTAD.A WORM! |
 |
svchost.exe |
winservice
Added by the CVK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
ssmgr.exe |
WinService32
007 Spy Software - "stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP" |
 |
svchost.exe |
WinService32
007 Spy Software - "stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP" |
 |
svch0st.exe |
winsock
Added by the SAGE-A WORM! Note - the filename has the digit 0 rather then the uppercase "o" |
 |
scvhost.exe |
Winsock Driver
Detected by Kaspersky as the RBOT.AEU BACKDOOR! See here |
 |
SDJOIJE.EXE |
Winsock2 driver
Added by the SPYBOT.DR TROJAN! |
 |
SPOLSV.EXE |
Winsock2 driver
Added by the SPYBOT-CM WORM! |
 |
sysreq.exe |
Winsock2 driver
Added by the SPYBOT-CC WORM! |
 |
svchorsst.exe |
Winsock2 driver
Added by the SPYBOT-EE WORM! |
 |
SYSTEM32.EXE |
Winsock2 driver
Added by the SPYBOT-EG WORM! |
 |
Sdjoije.exe |
Winsock32 driver
Added by the SPYBOT.B WORM! |
 |
system32.exe |
Winsock32 driver
Added by the IRCBOT-VT TROJAN! |
 |
sp2XPupdate.exe |
Winsock32driver
Added by the HACKARMY.S TROJAN! |
 |
svchhost.exe |
Winsock32driver
Added by the HACKARMY.I TROJAN! |
 |
spoolsvr.exe |
Winspool
Added by a variant of the SDBOT WORM! |
 |
SHIZZLE.EXE |
WinSrv
Added by the HOBBIT.C WORM! |
 |
services.exe |
winsrv3
Added by the NAFBOT-A TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
syssmss.exe |
WinsSystem
Added by the DELF.IG TROJAN! |
 |
services.exe |
WinStart
Added by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Connection WizardStatus subfolder of the Windows or Winnt folder |
 |
syschost.exe |
winsys
Added by an unidentified TROJAN! |
 |
smss.exe |
winsystem.sys
Added by the SOBER.K TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a msagentwin32 subfolder of the Winnt or Windows folder |
 |
sys32.exe |
WINTASK
Added by the MYTOB.K WORM! |
 |
smsrss.exe |
WINTASK DLL32
Added by the MYTOB.BS WORM! |
 |
svchost.exe |
WinUp
Added by the SILLY.BR WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "4350" sub-folder |
 |
svhost.exe |
WinUpdate
Added by a variant of the SDBOT WORM! |
 |
svchots.exe |
WinUpdate
Added by the SMALL.GXJ TROJAN! |
 |
system.exe |
Win_api_driver
Added by the REVIRD TROJAN! |
 |
shchostv.exe |
WIN_DRIVR32
Added by a TROJAN - see here |
 |
Switcher.exe |
Wireless Switching Setting Utility
On a Sony laptop with built in wireless it allows the user to select which wireless services they want to run (i.e. Wireless LAN, Bluetooth, both) when turning the wireless switch on if disabled) |
 |
svchost.exe |
wlinles
Added by the LIJI-A WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the "spool" sub-folder |
 |
services.exe |
WMAudio
Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
 |
scrcons32.exe |
WMI Standard Event Consumer - Scripting
Added by the RBOT-GRD WORM! |
 |
svchost.exe |
wnddrv
Added by an unidentified TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
 |
spvspool.exe |
wnxpupdate
Added by the DABORA.B WORM! |
 |
Shell.exe appLaunchClientZone.shl |
WOOKIT
Related to the Wanadoo broadband ISP (now rebranded as Orange). What does it do and is it required? |
 |
syswork.exe |
Working System Analyzer
Added by the FORBOT-FZ WORM! |
 |
saimon.exe |
Write DVD-R!
Saimon's WriteDVD! "gives total support for DVD-RAM drives. It provides many functions such as setting partitions on DVD-RAM disks and FixDVD! can diagnose and repair UDF formatted disks" |
 |
svchst.exe |
ws2 32
Added by the VOKEN-A TROJAN! |
 |
svchostt.exe |
WSAConfiguration
Added by the AGOBOT.ZT WORM! |
 |
svchost.exe |
wsock32
Added by the HORST-A WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
 |
SERVICES.EXE |
WSVCS
WSLogger keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
SchedInd.exe |
WTIndicator
WinTask - software that automates a variety of routine tasks quickly and simply |
 |
symcsvc.exe |
wupd
Added by the ABWIZ.C TROJAN! |
 |
sswizard.exe |
X-Grabber
ScreenShot Wizard |
 |
slcskxsdl7.exe |
xcxdsaa7
Added by the ONLINEG-K TROJAN! |
 |
Scheduler.exe |
XemiComputers Scheduler
Smooth Program Scheduler from XemiComputers "will start any program you want at a scheduled time" |
 |
SrchAsst.exe |
XNSearchAssistant
iWon Search Assistant - spyware |
 |
svchost.exe |
xor
Added by the XORDOOR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in a "xor" subfolder |
 |
svshost.exe |
xor
Added by the AGENT.DC TROJAN! |
 |
systemxp.exe |
XP System
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
SERVICES.EXE |
Xpsystem
Added by the DAEMOZ.A TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in an "SERVICES" subfolder |
 |
services.exe |
xpsystem
CoolWebSearch parasite variant. Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
 |
services.exe |
xp_system
Added by the KREPPER-N TROJAN and variants! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! The file is located in a "inet*****" subfolder of the Windows or Winnt folder - where ***** varies dependent upon the variant, examples are 20088, 20001, 10066 |
 |
sys.exe |
xxcm
Added by the KRISWORM-A WORM! |
 |
svhost32.exe |
xy
Added by the DELF.FAI TROJAN! |
 |
svchost32.exe |
Yahoo Messenger
Added by the SOHANA-P WORM! |
 |
SVICHHOST.exe |
Yahoo Messengger
Added by the TIOTUA-C TROJAN! |
 |
SSVICHOSST.exe |
Yahoo Messengger
Added by the SOHANA-R WORM! |
 |
SCVHOST.exe |
Yahoo Messengger
Added by the SOHANA-V WORM! |
 |
SCVHSOT.exe |
Yahoo Messengger
Added by the HAKAG-A WORM! |
 |
SCVVHSOT.exe |
Yahoo Messengger
Added by the SILLYFDC-AE WORM! |
 |
SSCVIHOST.exe |
Yahoo Messengger
Added by the SOHANA-W WORM! |
 |
SSCVIIHOST.exe |
Yahoo Messengger
Added by the SOHANA-Y WORM! |
 |
sysmon.exe |
yemarvd
Added by the AGENT-CH TROJAN! |
 |
SamsungMediaStudioAgent.exe |
YeppStudioAgent
Samsung Media Studio MP3 player file management software - see here for an example |
 |
SearchProtection.exe |
YSearchProtection
Yahoo Search protection will alert you if an attempt is made to change your default browser search engine from Yahoo! |
 |
svchost.exe |
Zone Labs Client Ex
Added by the NETSKY.F WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
 |
szchost.exe |
Zone system
Added by the MULTIDR-AC TROJAN! |
 |
szsvc.exe |
zSecurity Service
Added by the SDBOT-DAB WORM! |
 |
smss.exe |
zsms
Added by the BANCOS-CK TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
smss.exe |
zsmss
Added by the BANCOS-DD TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
Spguard.exe |
zSPGuard
"StartPage Guard (SPG) protects your PC from cyberscam, by detecting and preventing any unauthorized changes to your internet browser's Start and Search pages. It is also capable of removing automatically most of known 'invaders'." |
 |
server.vbs |
ZtgServerSwitch
ZTGServerswitch is part of Sony's Vaio support agent - designed by Support.com. Not required if the user does not wish to use the Vaio support agent and regarded as spyware |
 |
svchost.exe |
zztp
Added by the TANNICK.B TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
 |
setup.exe 46*** |
zzzCamlnSuitelll
?? |
 |
setup.exe |
zzzhpsetup
?? |
 |
System.exe |
[Entry name]
Added by the NETHIEF-N TROJAN! |
 |
svchost.scr |
[filename]
Added by the BANKER-CC TROJAN! |
 |
svchost.scr |
[original filename]
Added by the BANCBAN-CX TROJAN! |
 |
securewinload32x.exe |
[random characters]
Added by the OPTIXP-N TROJAN! Note - this trojan file is found in the System (9x/Me) or System32 (NT/2K/XP) folder. The file system32dir2a.exe will also be found in the same folder and should be deleted |
 |
slk8x2peu.exe |
[random filename]
QuickLinks adware |
 |
Svchosts.exe |
[random name]
Added by the SDBOT.N TROJAN! |
 |
se?vices.exe |
[random name]
PurityScan/Clickspring adware |
 |
spoolsv.exe |
[random name]
PurityScan/Clickspring adware. Do not confuse with the legitimate Microsoft Printer Spooler Service (spoolsv.exe) |
 |
scanregw.exe |
[random name]
PurityScan/Clickspring adware |
 |
svchost.exe |
[random name]
Added by the BANCBAN-JC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "config" subfolder of the Winnt or Windows folder |
 |
Servere.exe |
[random name]
Added by the LEGMIR-AQM TROJAN! |
 |
stup_tmp.#32 |
[random name]
Detected by Panda as the SDSCAN.A TROJAN! |
 |
svchost.scr |
[random]
Added by the BANCBAN-CY TROJAN! |
 |
svchost.exe |
[trojan name]
Added by the BANCBAN-CL TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup! |
 |
svchostss.exe |
[various names]
Added by a variant of the RBOT WORM! |
 |
shch.exe |
[various names]
Premium rate adult content dialler |
 |
sitebar.exe |
[various names]
Added by an unidentified TROJAN! |
 |
SAPSTR.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
sbin.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
scanSYS.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
Serviceprocess.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
SetupExeDll.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
Shaitan1678.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
slamm.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
sound64.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
SpyElim.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
srbho.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
ssweeper.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
StartCpl.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
startman.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
StatusCheck.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
stuffmon.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
sysconf16.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
SysEntry.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
sysmon12.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
syspanel.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
SysSupport.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
SYSTRAV.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
seli.exe |
[various names]
MediaMotor adware |
 |
Setv.com |
_Setv
Added by the BESAM WORM! |
 |
svchost.com |
_svchost.con
Added by the ERKEZ.C WORM! |
 |
services.exe |
_SystemBoot
Added by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a HelpHelp subfolder of the Windows or Winnt folder |
 |
services.exe |
_WinCheck
Added by the SOBER.V WORM! |
 |
services.exe |
_WinData
Added by the SOBER.AA WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "PoolData" subfolder of the Windows or Winnt folder |
 |
services.exe |
_Windows
Added by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "WinSecurity" subfolder of the Windows or Winnt folder |
 |
services.exe |
_WinStart
Added by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Connection WizardStatus subfolder of the Windows or Winnt folder |
 |
smss.exe |
_winsystem.sys
Added by the SOBER.K TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a msagentwin32 subfolder of the Winnt or Windows folder |
 |
sysqyzwud.exe |
{05CD0D77-4947-4a56-94FA-0DF0DC644D7B}
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
 |
sysqkmwfedz.exe |
{157627A6-2A10-4aa1-B97F-90B8DC6F24AC}
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
 |
sxpgknrwva.exe |
{2C70168B-97CE-4f31-B85D-1FEC5002721D}
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
 |
sysavxjgdu.exe |
{2C70168B-97CE-4f31-B85D-1FEC5002721D}
Detected by McAfee as the FAKEALERT-AM TROJAN! See here |
 |
sysawpbkvnq.exe |
{2C70168B-97CE-4f31-B85D-1FEC5002721D}
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
 |
sysxhtcwbse.exe |
{2C70168B-97CE-4f31-B85D-1FEC5002721D}
Detected by McAfee as the FAKEALERT-AM TROJAN! See here |
 |
services.exe |
{357AA41A-B7A8-4632-A27D-5B980B25CF43}
FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in an "Inetsrv" subfolder |
 |
sysrswva.exe |
{42562052-EE17-4197-82C7-91CB2E4B0666}
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
 |
sxjecknqhu.exe |
{78B578D7-BCE1-4d83-9CD4-195BC34D8CB3}
Detected by McAfee as the FAKEALERT-AM TROJAN! See here |
 |
syspyukrazv.exe |
{78B578D7-BCE1-4d83-9CD4-195BC34D8CB3}
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
 |
syssfzvakqg.exe |
{78B578D7-BCE1-4d83-9CD4-195BC34D8CB3}
Detected by McAfee as the FAKEALERT-AM TROJAN! See here |
 |
sysahbecjh.exe |
{7DD4A7AC-A3F1-4495-884A-7947C5B89108}
Detected by McAfee as the FAKEALERT-AM TROJAN! See here |
 |
syszweuas.exe |
{9754B85A-3B34-4969-BE1F-CD03227E9470}
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
 |
sysatjsicj.exe |
{9754B85A-3B34-4969-BE1F-CD03227E9470}
Detected by McAfee as the FAKEALERT-AM TROJAN! See here |
 |
sxnwhbvrzc.exe |
{A4C928E8-0ABA-4fd3-83DF-23BE54ADF9A4}
Detected by McAfee as the FAKEALERT-AM TROJAN! See here |
 |
sysqrnxstju.exe |
{A4C928E8-0ABA-4fd3-83DF-23BE54ADF9A4}
Detected by McAfee as the FAKEALERT-AM TROJAN! See here |
 |
syssngbeh.exe |
{B081DB1F-4EE6-4021-9DD4-8B300F0D636D}
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
 |
sysjcyrq.exe |
{B3B48B54-C0EC-4705-8EE8-1981AEF656A7}
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
 |
sysawechod.exe |
{BAAA759D-56F0-428c-B8DA-827EA3B08C2C}
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
 |
sysfbdgv.exe |
{C2220120-1C24-4a79-BA7A-DDCBFC209DB3}
Detected by Trend Micro as the CLICKER,AGS TROJAN! See here |
 |
sysfdyev.exe |
{C599792D-C6D9-461d-93CA-B48BFF8E37B1}
Detected by Trend Micro as the CLICKER,AGT TROJAN! See here |
 |
sysutrnez.exe |
{DD651081-A909-45ad-BD71-2335B0ADE043}
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
 |
sysabmpmfr.exe |
{DD651081-A909-45ad-BD71-2335B0ADE043}
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
 |
sysnxcphmgy.exe |
{DD651081-A909-45ad-BD71-2335B0ADE043}
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
 |
sysrxmfdksp.exe |
{E4785213-3EFE-4c26-A9B4-332440E31F6F}
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
 |
sxpjbwvahn.exe |
{F758F78B-0885-490e-AA3C-4A38D28B0240}
Detected by McAfee as the FAKEALERT-AM TROJAN! See here |
 |
sysyeabdgfp.exe |
{F758F78B-0885-490e-AA3C-4A38D28B0240}
Detected by McAfee as the FAKEALERT-AM TROJAN! See here |