Windows Vista Tips


Processes beginning with s

The table below includes any process titles beginning with s, from which further information can be found by clicking on the process title. The icon beside the information can be used to quickly determine if this is a safe file in combination with the key below:



This file is normally safe to leave running. In most cases, this file is not required to run on startup and can be run manually. Warning, this file may be a virus, spyware, resource hog and running it is not recommended. This file may or may not be necessary to load on startup, depending on your circumstances. No information is available for this item.

[#] [A] [B] [C] [D] [E] [F] [G] [H] [I] [J] [K] [L] [M] [N] [O] [P] [Q] [R] [S] [T] [U] [V] [W] [X] [Y] [Z]

Processes beginning with s:

File Type Process Name and Information
S
Added by the AGOBOT-LN WORM!
S0undMan
Added by the LOVGATE.AB WORM! Note - the filename has the digit 0 rather then the uppercase "o"
S24EvMon
Event Monitor - supports driver extensions to NIC Driver for wireless adapters. Is it required?
S3 Internal Chip
Added by the AGOBOT-DD WORM!
S3apphk
A tool installed alongside the drivers for your S3 video output device. It is not necessary but should be allowed to run unless it is causing problems
S3Hotkey
Hotkey system tray icon to enable switching between monitors. Found on laptops with an S3 Twister integrated graphics card
S3Mon
S3DuoVue multi-monitor taskbar helper by S3 Graphics. What does it do and is it required?
S3TRAY
S3 display configuration taskbar utility for S3 chipset based graphics cards. Can be run from Start-> Settings -> Control Panel -> Display
s3tray2
Same as the s3tray entry in this table?
S3TRAYHP
S3 Video driver related. What does it do and is it required?
S3Trayp
S3 display configuration taskbar utility for S3 chipset based graphics cards. Can be run from Start-> Settings -> Control Panel -> Display
S4F
FilterPak from S4F, Inc - internet filtering software
s4helper
Searchcentrix hijacker
s9201
Antivirus 2008 XP rogue security software - not recommended, see here
SA
Logitech QuickCam driver. Is it required?
SA Service
Associated with Cyber Trio and Warner troubleshooting software from G-Tek Technologies and pre-installed on some Packard Bell and NEC PCs. What function does this perform and is it required?
Sa3dsrv
3D sound extension for Windows
saap
NCase adware
Sabreserver
Airline reservation software from Sabre. Available via Start -> Programs
sac
NCase adware
SACC
SurfAccuracy adware
SAClient
AT&T or ComCast BBClient - monitors system and network-delivered services for availability. Your current network status is displayed on a color-coded web page in near-real time. When problems are detected, you're immediately notified by e-mail, pager, or text messaging
sacmemds
Added by the MAILBOT-BZ TROJAN!
Safe
Added by the FOCOSENHA TROJAN!
Safe
Added by the BANKER-DT TROJAN!
SafeGuard Popup Blocker Updater
SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The "sfgupd.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
SafeGuard Popup Blocker Updater (required)
SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
SafeGuard Popup Updater (required)
SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
SafeGuard Popup Updater (required)
SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
SafeHouseSystemTray
SafeHouse "Personal Privacy" system tray icon - PP protects and hides your private and personal photos, videos, files and folders by making them "invisible" and encrypted
SafeInstall.exe
Monitors a download and ensures an newer version of a file isn't replaced by an older one
SafeOFF
Provides protection that if user accidentally presses the power switch a dialog will pop up for confirmation
SafeSearch
SafeSearch.A adware
SafeSpace
Part of SafeSpace (from Artificial Dynamics) which "protects computers from Internet malware infection without the need for signature updates or regular maintenance"
SafeStrip
SafeStrip spyware remover - not recommended, see here
SafeStripReminder
SafeStrip spyware remover - not recommended, see here
SafeSurfingUpdate
MoneyTree parasite - ActiveX control used to download premium-rate dialers
SafetyNet
Safety.Net from Netveda - "offers Internet security, content security and advanced Internet firewall protection for all your LAN computers, and trust controls to block unwanted or harmful applications from accessing the network"
SafetyNet_Notifier
Safety.Net from Netveda - "offers Internet security, content security and advanced Internet firewall protection for all your LAN computers, and trust controls to block unwanted or harmful applications from accessing the network"
Safeworld
SafeWorld Internet Security - now no longer available
Sagate Security Firewall
Added by the GAOBOT.BOW WORM!
SAgent2ExePath
Seiko Epson printer status agent. Disable if printer is not used often
SAGENTSERVICE
TinySpyAgent commercial keystroke logger. Uninstall this software if you did not install it yourself
sagnt
Adware web downloader
SAHagent
ShopAtHomeSelect parasite
SAHBundle
ShopAtHomeSelect parasite
SAHBundle
ShopAtHomeSelect parasite
saie
NCase adware
SaiMfd
Saitek MFD File System Driver - associated with the Saitek SST (Saitek Smart Technolgy) configuration software for their game controllers. Create a shortcut and run manually when required
SAIMON
Saitek joystick driver
sain
NCase adware
sais
NCase adware
SaiSmart
"Smart Button Special Sauce" - included with the latest software for Saitek game controllers. Related to the "S", "Shift" or "Smart" button and gives gamers extra features on the buttons. Only required if you use this feature
SaitekAutoConfigure
Configuration for Saitek game controllers
Sakemsneql
Added by the SDBOT.BTO WORM!
Sakora
Detected by Microsoft as the GOWELES.A TROJAN! See here
SalaatTime
"Salaat Time is a FREE multi-function Islamic application that calculates the prescribed five daily Muslim prayer times as well as Qiblah direction for anywhere in the world"
Salestart
WinAntiSpyware spyware remover - not recommended, see here
Salestart
Misleading security software such as AntiSpywareSuite, AntivirusPCSuite, SpyGuardPro, WinAntiVirus Pro 2006, WinSecureAv and WinSpyControl - not recommended, see here
Salestart
SystemDoctor misleading security software - not recommended, see here
Salestart
PrivacyProtector misleading security software - not recommended, see here
Salestart
OnlineHelpmate and ConfidentUser misleading security software - not recommended
Salestart
WinAnonymous spyware remover - not recommended, see here
Salestart
Misleading security software such as WinPCDoctor, StorageProtector, ErrClean and SystemErrorFixer - not recommended
salm
NCase adware
saly
Added by a variant of the AW.AWK TROJAN!
Sam-sung
Added by a variant of the SDBOT WORM!
SaMail
Added by the VBS.LIDO WORM!
SAMcal
SamCal - calendar/reminder program
Sametime Connect
IBM Lotus Sametime - instant messaging and Web conferencing software
Samsong
Added by the SDBOT.BNE WORM!
Samsung
Added by an IRC TROJAN variant!
SandboxieControl
SandBoxie - allows data to be read from the hard drive by an application but never written back unless you allow it
SandboxieControl
"SandBoxie runs your programs in an isolated space which prevents them from making permanent changes to other programs and data in your computer"
SandIcon
SanDisk ImageMate CompactFlash card reader SDDR-31 (USB). Very little use except to place the Sandisk icon beside its drive designation in Windows Explorer. The reader itself will work fine without it. The simplest thing is to just unplug the reader when you're not using it. It may slow the startup by a few nanoseconds, but once the software sees there's no reader, you get back the resources
SANS Service
Added by the VANEBOT-AH WORM!
SansaDispatch
Sansa Updater - "The Sansa Updater is an application that checks for the latest firmware updates then downloads and installs the firmware to your Sansa device"
Santa Bastards Bitch
Added by the ATNAS.A WORM!
sapp
NCase adware
SaskTel Accelerated Dial-up
"Experience faster surfing, downloading and e-mail by adding SaskTel Accelerated Dial-up Internet"
sasserfix
Added by the DABBER.B WORM!
saSyncMgr
Browser hijacker - redirecting to Searchant.com. Note - the real Tweak UI entry for this is "rundll32.exe tweakui.cpl, tweakmeup". Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
SATARaid
RAID driver for serial ATA disks on some motherboards such as the DFI Lanparty range. Only loaded if one is using RAID support on SATA drives
satmat
VX2.Transponder parasite updater/installer related
sau
180Solutions adware related
SAUpdate
Big Brother from Quest Software. System and network monitor
SAutoLaunchExe
Sharp Zaurus PDA related, needed to synchronize information with a Desktop or Notebook
SAVAgent
Part of Sophos anti-virus software. Required for centrally administered Sophos updates to work correctly, e.g. automatically updating PCs used by dial-in home or out-of-office users
Save
WhenU.Save adware
SaveDate
Unidentified adware
Savenow
WhenU.Save adware
Savenow
Added by the SPREDA.B VIRUS!
Savsvc
Added by the AKBOT.BE WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "savsvc.dll" file is found in %System%
SAW
SmartAdware adware
Say The Time 5.0
This program has audio cues for the system clock in male and female voices, customizes the appearance of the system clock, and can synchronize it to a time server regularly
SB
Acer Soft Button on Acer Tablet PCs
SB
SpywareBomber spyware remover - not recommended, see here
SB Audigy 2 Startup Menu
Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search function
SB Watchdog
Spyware utility installed by the manufacturers of some laptops (Sony) used to monitor browsing habits and send them back to whoever installed it - released by SoftBank
SB13mini
Added by the SPYBOT-EJ WORM!
SBAutoUpdate
SpywareBlaster auto-updater
SBC RoamingClient
Part of AT&T FreedomLink Wi-Fi connection software
SBC Self Support Tool
matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file. The SBC Self Support Tool is required to run with the Help and Support program. If you uncheck SBC and and then run Help and Support it will add another SBC entry in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decide
SBC Yahoo! Connection Manager
Used to create and connect your SBC Yahoo DSL connection. This program has been reported to cause problems for some users. If you find that it causes you pc to become slow or unstable you should uninstall it (using Add/Remove programs) and manually connect your DSL connection
SBCSTray
System Tray access to CounterSpy anti-spyware from Sunbelt Software
SBDrvDet
Detects the "Easy Front-Panel Audio Connectivity Drive Internal Drive Bay" on the Sound Blaster Audigy 2 Platinium eX. Can be disabled if you don't have one
sbdrvdet
Checks to see if Creative sound card driver should be updated
SBHC
SuperBar parasite - uninstall available here
SBI
Downloader for a variety of rogue anti-spyware programs
SBMPOP
SearchByMedia adware
SBMX
SoundMAX MPU401 MIDI device emulator for x86 VM DOS games/apps (for Win9x only)
sbss Launcher
SideBySide adware
SbUsb AudCtrl
Control for Soundblaster MP3 external (USB) sound card
sc
ScrubXP - utility that deletes safe to remove files, cookies, browsing history, etc
sc
Watchdog 2.0 Software - monitoring program
sc
All-In-One_SPY stealth monitoring software - allows monitoring and recording of all actions performed on a computer. It records all keystrokes, remembers addresses of Internet pages visited, and maintains a log file listing all applicationsrun on the computer. It can create screenshots and record sounds from the computer's microphone to a sound file
SC2
Added by the AGENT.APP TROJAN!
sc23exec
Possibly related to a digital camera
SC3300CC
SiPix digital camera Twain device driver
scain
Delfin Media Viewer adware related
ScamDisk
Added by the LEWOR.D WORM!
scan
ClientMan parasite variant
Scan Detector
Associated with PrimaScan scanners. Is it required?
Scan Register
Added by the RBOT-AT WORM!
Scan Wizard
Associated with ScanWizard as supplied with Microtek scanners - see also Scanner Detector or SDetect. What does it do and is it required?
ScanDisc
Added by the GREGSTAR TROJAN!
ScanDisk
Added by the GANDA.A WORM! Note - this is not the valid "ScanDisk" Win9x/Me standard disk error checker
scands32.exe
Added by a variant of the ADCLICKER TROJAN!
Scandsk2
Added by the AGOBOT-PK WORM!
scandskx.exe
Added by the DLOADR-ARM TROJAN!
ScanFile
??
ScanInicio
Part of Panda Antivirus. Responsible for scanning the boot sector of your disk and your memory at startup to check for viruses that try and load and act before your anti-virus is fully operational. It only adds a fraction of a second to start-up time and is worth leaving active
Scanner Detector
ScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the "GO" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the "GO" button
Scanner File Utility
Kycocera Mita network copier/printer/scanner process to dump scanned documents onto a workstation
ScanPanel
Trust Easy Webscan scanner related - what does it do and is it required?
Scanreg
Added by the QQPASS.E TROJAN!
ScanRegistry
Added by the NERTE TROJAN! Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as nsrvnt.exe not scanregw.exe
ScanRegistry
Added by the MASTERLOCK TROJAN!. Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as scanregv.exe not scanregw.exe
ScanRegistry
Scans the system registry and makes back-ups at start-up. Important should the registry become corrupt. The executable "Scanregw.exe" is located in %windir% (where %windir% is the Windows directory - C:Windows or C:Winnt)
ScanRegistry
Added by the STATOR WORM! Note - this is not legitimate ScanRegistry entry - which is a vital Windows file. The executable "Scanregw.exe" is located in %System%. Runs from the registry RunServices key as opposed to the Run key
ScanRegistry
Added by the DINOXI or DINOXI.B WORMS!
ScanRegistry
Added by the NYXEM-D WORM! Note - do not confuse this with the legitimate Windows process scanregw.exe which is always found in the Windows folder on Win9x/ME machines. This worm file is found in the System (9x/ME) or System32 (NT/2K/XP) folder
ScanRegistry
Added by the DWNLDR-FZY TROJAN!
ScanSpyware v *
ScanSpyware spyware remover (where * = the version number) - not recommended, see here
scApp
Added by the STANDO-E WORM!
scApp
Added by the ACNATT.A WORM!
SCardSvr
Related to SmartCard readers and sometimes uses lots of system resources
SCardSvr
Added by the MOFEI.B WORM!
SCDEmuApp.exe
Related to PowerISO - CD/DVD image file processing tool
scheck45
Related to unknown malware - hidden installer associated with it
schedl
Added by the VB-DVW WORM!
schedm
Part of Antivir PersonalEdition Classic anti-virus
ScheduIe
Premium rate adult content dialler
ScheduIr
Added by a variant of the SDBOT WORM!
ScheduIr
Added by a variant of the SDBOT WORM!
ScheduIr
Added by a variant of the SDBOT WORM!
ScheduIr
Added by a variant of the SDBOT WORM!
Schedule
Scheduler for Mercury Ez View TV Tuner Card
Scheduled Maintenance
Scheduler for Iolo System Mechanic tweaking utility. It can cleans your registry and deletes temporary files at defined intervals. Available via Start -> Programs
Scheduler
Added by the TACTSLAY.A TROJAN!
Scheduler
Added by the HOSTBANK-A TROJAN! Note - this particular msmsgs.exe file is located in the WindowsSystem32Config or WinntSystem32Config folder, and should not be mistaken for the MSN Messenger file of the same name!
Scheduler
Added by the TACTSLAY.A TROJAN!
Scheduler
Added by the TACTSLAY.A TROJAN!
Scheduler
Added by the TACTSLAY.A TROJAN!
Scheduler
Added by the TACTSLAY.B TROJAN!
Scheduler
Tenebril GhostSurf or SpyCatcher related scheduler - you can schedule daily, weekly, monthly or one-time only cleanings
Scheduler
Added by the TACTSLAY.B TROJAN!
Scheduler
Added by the TACTSLAY.B TROJAN!
Scheduler
Added by the TACTSLAY.B TROJAN!
Scheduler Service
Added by the LIOTEN.KX WORM!
SchedulerMgr
Premium rate adult content dialer
scheduler_monitor
Scheduler for ReaConverter advanced image converter
Scheduling Agent
Added by the SUBWOOFER TROJAN! Note - this is not the real MS Scheduling agent as the executable is incorrect
SchedulingAgant
Added by the YAB.A TROJAN! Not the valid MusicMatch Jukebox which has the same filename
SchedulingAgent
MS Scheduling Agent displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting, ScanDisk, etc. Required if you have regularily scheduled events such as weekly virus scans
SchedulingAgent
MS Scheduling Agent displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting, ScanDisk, etc. Required if you have regularily scheduled events such as weekly virus scans
SchedulingAgent
Added by the DINOXI or DINOXI.B WORMS!
Schmaili
Schmaili - insert animated smilies into your e-mail
schost
Added by the TJSERV.D TROJAN!
SchSvr
WinScheduler is installed with Home Theater or WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs
SCHWIZEX
Part of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot
sck121
Added by a variant of the MAILBOT TROJAN!
sclick
Added by the FAKEALERT TROJAN!
ScManager
Added by the FORBOT-CW WORM!
scopedll
Added by a variant of the CRYPTER.C TROJAN!
Scotia OnLine Recovery
Scotia OnLine Security Software provided by Entrust for Scotiabank. Provides trusted secure access to Scotia OnLine Secure Web sites. *.* represents the version number. Now obsolete after Scotiabank modernised their login process
Scotia OnLine Security v*.* Recovery
Scotia OnLine Security Software provided by Entrust for Scotiabank. Provides trusted secure access to Scotia OnLine Secure Web sites. *.* represents the version number. Now obsolete after Scotiabank modernised their login process
Scr
Added by the OPASERV.T WORM!
ScrapPad
ScrapPad allows you to quickly and easily record notes, thoughts, messages, and just about anything you want. Use it like you use scrap paper
scrbmk
Added by the DLOADER-VP TROJAN!
Screen Calendar
Screen Calendar allows you to create custom desktop wallpapers with built in active calendar and scheduler
Screen Guard
Part of Access Denied security and privacy software
Screen Guard Message Scan
Part of Access Denied security and privacy software
Screen Saver
Added by the RBOT-AGP WORM!
Screen Saver Control
Installs as part of the Hubble Space Telescope screen saver (and possibly others). Lets you control your installed screensavers from a System Tray icon
ScreenHunter 4.0 Free
"ScreenHunter 4.0 Free is a completely free screen capture software for you to easily take screenshots"
ScreenPrint32
ScreenPrint32 screen capture software - can be launched manually
ScreenSaverPlus
MatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder
screxe
??
script
Maybe associated with DOS on a Win9x machine
ScriptBlocking
Update to Norton AntiVirus 2001. Detects certain types of script-based viruses without the need for specific virus definitions - such as JavaScript and VBScript. This will help protect you from these viruses even before virus definitions are available. Note - some users complain of problems once the update is installed - refer here for more information
ScriptSentry
Script Sentry from Jason's Toolbox. Blocks malicious scripts and allows safe scripts to run. Only required if you want it to check the file associations it guards at startup. It will function regardlessly
Scroll-In-Mouse V2.0
Toolkit for the Lynx-3D Net scroll mouse from QTronix. Required if you use the special features
scroller
CoolWebSearch parasite variant
scrss
Added by the HACDEF-R TROJAN!
scrsvc
Added by the AGENT-DS TROJAN!
ScrSvr
Added by the OPASERV WORM!
ScrSvrOld
Added by the OPASERV WORM!
Scsi
SCSI Miniport driver
sctrlmgr
Added by a variant of the DWNLDR-GAH TROJAN!
scvhost
Added by a variant of the SPYBOT WORM!
scvhost
Wiretap surveillance software. Uninstall this software unless you put it there yourself
scvhost loader
Added by the SDBOT-CY TROJAN!
scvhost.exe
Added by the LOHAV-N TROJAN!
sd32info
Added by the CRYPTER.A TROJAN!
SDaemon
PC Security from Tropical Software. 'PC Security? 5.1 is the ultimate in computer security, offering multiple locking systems for the Windows environment and internet. Lock files, monitor programs' activities, even detect intruders! PC Security? offers flexible and complete password protection, "Drag and Drop" support, plus many other handy features'
SDAutoLiveupdate
Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here
SDAv
Added by the SERFLOG.C WORM!
SDAv
Added by the SERFLOG.C WORM!
sdchosts32
Added by the RANKY.AG TROJAN!
SDClientMonitor
Related to LANDesk Management Suite from LANDesk Software Ltd. What does it do and is it required?
SDetect
ScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the "GO" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the "GO" button
sdfsdfsdf
Added by a variant of the SPYBOT WORM!
SDIN Adapter
Added by the FORBOT-AP WORM!
SDJobCheck
Part of CA Unicenter Software Delivery - manage software across various systems, from desktops and servers to PDAs and mobile phones, in a controlled and standardized way - is it required at startup?
SDK Codre Function22
Added by the SDBOT-YJ WORM!
SDK Core Component
Added by the SDBOT-WC WORM!
SDK Core Function
Added by the RBOT.BHL WORM!
SDK Core Function2
Added by the SPYBOT.OGX WORM!
Sdk**.exe [* = random char]
CoolWebSearch/HomeSearch adware - for examples, see this log
Sdk**32.exe [* = random char]
CoolWebSearch/HomeSearch adware - for examples, see this log
SDKcore Update Components2
Added by the RBOT-ABA WORM!
sdkupdate22
Added by the FORBOT-DT WORM!
SDPhotoBar.exe
SmartDraw Photo (now FotoFinsh) - "organize, enhance, print, and share your photos. It's also a powerful graphic editor for creating images and web graphics"
SDR6_Check
DriveCleaner rogue security software - not recommended, see here
sdrss
Added by the SDBOT-SQ WORM!
sds20
InlookExpress logs keystrokes and captures screenshots. If you didn't install this yourself remove it. Note - this should not be confused with the svchost.exe system process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder! This file is located in a "sds20" folder
SDTray
RSA Keon Web PassPort - software that allows organizations to use digital certificates in a Web-based environment to help ensure that their transactions are authentic, confidential and digitally signed
SDTray
Spyware Doctor spyware remover - system tray access
sdxsys32
Added by the BROGGER-A TROJAN!
sealmon
SealedMedia enables you to combine document protection and control with your existing applications - such as Microsoft Word, Microsoft Excel, Microsoft PowerPoint and Email
Search Bar
Added by the OPANKI-F WORM!
Search Defender
Installed by SpeedItUp without permission, along with PC-Checker. Detected by DrWeb as the STARTPAGE.ORIGIN TROJAN!
Search Hook
??
Search Page
Naupoint browser hijacker
Search-Exe
Search-Exe hijacker
Search.vbs
Hijacker
SearchAndDestroyMFC
Search And Destroy rogue security software - not recommended, see here
SearchAndDestroyScheduler
Search And Destroy rogue security software - not recommended, see here
SearchAndDestroyT
Search And Destroy rogue security software - not recommended, see here
searchbar
SearchBarCash adware variant
SearchEnhancement
SCBar foistware
searchnav
SearchNav adware - IEFeatures/Popnav variant
SearchNavVersion
SearchNav adware - IEFeatures/Popnav variant
SearchNet_Up
SearchNet adware
SearchSetter
Browser hijacker - redirecting to FindWhateverNow.com
SearchSettings
Vendio "Search Settings" foistware - reportedly installed without notice, see here and here
SearchSpy
SearchSpy spyware remover - not recommended, see here
SearchSquire[number]
SearchSquire adware
SearchUpgrader
Hijacker
Secboot
Added by the HAXDOOR.D TROJAN!
secboot
Added by a variant of the HAXDOOR.BC TROJAN!
secboot
Added by the HAXDOOR-AE TROJAN!
secdrive.exe
Added by a variant of the SPYBOT WORM! See here
Second Copy 2000
Related to Second Copy? - a files/folders backup utility
SecondChance
Power Quest Second Chance. Sets checkpoints for saving a backup copy of the registry to a disk so you can restore it if you have a crash
Secret
Added by the DELF-LW TROJAN!
Secret-Crush
Hijacker that may reset your browser's home page and/or search settings to point to undesired sites
SECRETMAKER
Secretmaker is a combination of eight privacy-defending programs, including Spam Fighter Pro, Worm Hunter, Pop-Up Killer, Banner Blocker, Cookie Eraser, Privacy Protector, History Cleaner, and Garbage Cleaner
SecretSmileys
"Secret Smileys is an add-on for AIM that provides users access to 1000's of new Smileys that can be viewed by anyone using a current version of AIM. Secret Smileys also adds other features such as logging of IM conversations, and it gets rid of that annoying advertisement on your buddy list window"
secserv.exe
Reported by Panda as an EasySearch Adware variant. Note - EasySearch modifies the Internet Explorer settings and may download programs onto the infected computer
secsvc32
Added by the GLOBAL PATROL TROJAN!
Secsys
UltraSoft Key Interceptor surveillance software - uninstall this unless you put it there yourself!
SecurDisc
Part of the Nero multimedia suite backup function - "Recover your data quickly and easily and create discs that are password protected. SecurDisc technology gives you peace of mind"
secure
DealHelper adware
secure
Added by the RBOT-AFO WORM!
secure socket layer
Added by an IRCBOT TROJAN!
Secure Socket Layer Certification
Added by the VANEBOT-AN WORM!
Secure System
Added by the AGOBOT.ACI WORM!
Secure32
Detected by Symantec as the SILLYFDC WORM! See here
Secure64
Detected by Symantec as the SILLYFDC WORM! See here
SecureClean4RegManager
WhiteCanyon SecureClean 4 disk cleaner - clean hard drive data, MRUs, temp files and more. Can be started manually
SecureClean4Tray
WhiteCanyon SecureClean 4 disk cleaner - clean hard drive data, MRUs, temp files and more. Can be started manually
SecureCleaner
SecureCleaner spyware remover - not recommended, see here
SecureCleanIEClean
SecureClean - scans your system for hidden temporary files, deleted email messages, Internet histories and caches
SecureItPro
SecureIt Pro - lock your computer when you're not there, to stop malicious users from accessing your desktop
SecureLogin
Added by the REDZED WORM!
SecureOnlineAccountNumbers
Related to Secure Online Account Numbers by Discover(R) Card from Orbiscom Ltd. Secure and innovative payment solutions
SecurePCCleaner
SecurePCCleaner spyware remover - not recommended, see here
SecurePCSolutionsBootCheck
1 Click Fixer PLUS from Secure PC Solutions "takes the guesswork out of locating and solving problems in the Windows registry"
Security
Added by a variant of the SDBOT WORM!
Security Accounts Manager SM
Added by the SPYBOT.JE WORM!
Security Agent
Added by the BANCBAN-F TROJAN!
Security Agent Manager
Added by the RBOT-SV WORM!
Security Antivirus Xp 1
Added by the SDBOT.BAV WORM!
Security Center
Added by the SDBOT.CFT WORM!
Security Center Distribution
Added by a variant of the IRCBOT BACKDOOR! See here
Security iGuard
Security iGuard spyware remover - not recommended, see here
Security Manager
A ComCast Internet software suite that provides a variety of features (firewall, popup blocker, parental controls etcetera) to help ensure your computer is secure, and your information is kept private
Security Monitor
Detected by Kaspersky as the AUTORUN.LPF WORM! See here
Security Patch
Added by the RBOT-ZW WORM!
Security Patch
Added by the SDBOT-BM WORM!
Security Patches
Added by the RBOT.WW WORM!
Security Patches
Added by the SDBOT-KB WORM!
Security Server DB
Added by a variant of the IRCBOT BACKDOOR! See here
security service
Added by an unidentified WORM or TROJAN!
Security Service
Added by the RBOT-GGF WORM!
Security Service DB
Added by a variant of the IRCBOT BACKDOOR! See here
Security Service Process
Added by the AGOBOT-LC WORM!
Security System
Added by a variant of the IRCBOT BACKDOOR! See here
Security Update Service
Added by the AGOBOT.ZW WORM!
securw
Added by the NOPIR.A WORM!
SECWIZ98
Security Wizard 98 by Chris Farmer. Offers you a variety of ways to restrict access to many of the programs and settings on your PC. Available here
seekmo
Seekmo Search, a 180Solutions adware variant - also see here
SeekmoSA
180Solutions.Zango adware
SeekmoToolbar
180solutions/Seekmo adware
seeve
Medload adware
Select server
Added by the DLOADER-WD TROJAN!
SelfHostUtil
??
seli
Added by the LOWZONE-AS TROJAN!
SemanticInsight
RXToolbar adware. Software that displays pop-up/pop-under advertisements when the primary user interface is not visible
SeMS
PCsms - tool that enables you to send sms text messages from your PC to any UK mobile phone
Sen
Detected by Kaspersky as PurityScan.ah
Sensiva
Symbol Commander makes the use of your PC, laptop, Tablet PC, and Pocket PC much easier and much faster. It recognizes your handwriting with unparalled performance and executes commands in a snap. Just by using your mouse, pen, or touchpad, simply draw symbols to execute actions instantly
SENTRY
From IP Insight. Allows website owners "to instantly determine the precise geographic location, connection speed and detailed demographics of every visitor to your website". Will be detected by most firewalls and the majority of home users should disable it
Sepate Security Firewall
Added by a variant of the RBOT WORM!
septpop06apsept
MediaMotor.Popupwithcast adware
Serials
Any one of a variety of worms and trojans
Serices Hostin
Detected by Trend Micro as the IRCBOT.AUA BACKDOOR! See here
SernellApp.pcx
Added by the BANCBAN-BJ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "D5133" subfolder
serpe
Added by the SERFLOG.A WORM!
serpe
Added by the SERFLOG.A WORM!
serpe
Added by the SERFLOG.A WORM!
serrdctl.exe
"Shared Modem Service Client Event Viewer" - used when a number of PCs have access to a number of modems. Required to be running on each PC for access to the modems
serrv
Added by the WAREZOV.DC WORM!
SERV PacK2
Added by the SDBOT-ACP WORM!
Serv-U
FTP server
Serv-U
Added by the MANIFEST TROJAN!
server
Added by the DELTAD.A WORM!
server
Added by the METHS-A TROJAN!
server
Added by the SINGU-Q TROJAN!
Server Application for MFP Server
Multi Function Printer (MFP) Server Agent for Belkin's Wirless G All-in-One Print Server and ZyXEL's NPS-520
Server Backbone
Added by the RBOT-ZM WORM!
Server Daemon Host Manager
Added by the RBOT-GWC WORM!
Server Runtime Error
Added by the SDBOT-DFA WORM!
Server Runtime Process
Added by the SDBOT-DDB WORM!
SERVER.EXE
Added by the BUSHTRO122 or SMOKODOOR TROJANS!
serverex
Added by the DELTAD.A WORM!
Serverx
Added by the MADANGEL VIRUS!
Service
Added by the ALADINZ.H TROJAN!
Service
Added by the KAITEX.E TROJAN!
Service
Added by the NETSKY or NETSKY.B WORMS! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
Service
Added by the CHA TROJAN!
Service
Added by the ASSIRAL-C WORM!
service
Added by a variant of the RBOT WORM!
Service Cleaner
Added by the RBOT.BRH WORM!
Service Client
Added by an unidentified WORM or TROJAN! See here
Service Connection
For Compaq PC's. Part of Backweb
Service Connection
For Compaq PC's. Part of Backweb
Service Controller
Added by the GAOBOT.AO WORM!
Service Controller
Added by the PREVERT TROJAN!
Service Defender
Added by a variant of the ZLOB TROJAN! See here
Service Drivers
Added by the RBOT.BMD WORM!
Service Drivers
Added by the SDBOT-WK WORM!
Service Drivers
Added by the RBOT-ZJ WORM!
Service Drivers
Added by the SDBOT-YX WORM!
Service Drivers
Added by a variant of the RBOT WORM!
Service Host
Added by the TORVEL WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder
Service Host
Added by the TORVEL.B WORM!
Service Host
Added by the TORVEL WORM!
Service Host
Added by the DAOSER-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Services{C922CCC4-CF61-4589-A0D1-828160704853} subfolder
Service Host
Added by the DAOSER-C TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Services[random] subfolder
Service Host Driver
Added by the HITON TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder
Service Host Process
Added by the GAOBOT.GEN!POLY WORM!
Service Manager
SQL Server Service Manager - provides tray access to SQL server, the server agent and MSDTC. Available via Start → Programs
Service Manager
Added by the PASSMAIL-D VIRUS!
Service Manager
Added by the PROXY-GRIC TROJAN!
service manager
Added by the DONBOMB.A TROJAN!
Service Monitor
Added by the RBOT-ALE WORM!
Service Monitor
Added by the DELF-NK TROJAN!
Service Monitor
Added by the SDBOT-AFO WORM!
Service Monitor
Added by the SPYBOT.YQW WORM!
Service Monitor
Added by the RBOT-AQJ WORM!
Service Monitor
Added by the RBOT.EEH WORM!
Service Monitor
Added by a variant of the RBOT WORM!
Service Pack
Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe, common.pif, common.scr, Sexo.exe, Sexo.jpg.pif, ini_file__.pif, load_me__.tmp, msfile.pif, system_load_.pif or zipped.rar.pif
Service Pack 1
Added by the VXGAME.Z TROJAN! Note - the filename is random - see the link. Typical examples are vexg6ame4.exe, vexga3me2.exe, vexga4m1et4.exe, etc
Service Pack DLL Runtime
Added by a variant of the RBOT WORM!
Service PAck SFVP
Added by a variant of the RBOT WORM! The filename is 4 random characters
Service Process
Added by the DARKER WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder
Service Process
Added by a variant of the SPYBOT WORM!
Service Process
Added by the DCMBOT-C TROJAN!
Service Process
Added by the DCMBOT-E TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "config" subfolder
Service Process
Added by the DCMBOT-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "config" subfolder
Service Registry NT Save
Added by the BANCOS-CG TROJAN!
Service Registry NT Save
Added by the BANCOS-BY TROJAN!
Service Registry NT Save
Added by the BANCOS-BM TROJAN!
Service Scheduler
Added by the AGOBOT-PH WORM!
Service System
Added by the BANCOS-DA TROJAN!
Service System
Added by the BANCOS-EL TROJAN!
Service System
Added by the BANCOS-FS TROJAN!
Service System
Added by the BANCOS-FJ TROJAN!
service updaer
Added by an unidentified VIRUS, WORM or TROJAN! - probably a SPYBOT variant
Service Update Client
Added by an unidentified WORM or TROJAN! See here
Service.exe
"servedby.advertising" popup generator
Service2
Identified as a variant of the Win32.Iroffer malware. Located in %Windir%\Drivers\Intel
service32
Added by the AGOBOT-ST WORM!
service32.exe
Added by the DLOADR-AYX TROJAN!
ServiceConfig
Comcast Transition Wizard. On June 30th, 2003 it will migrate E-mail and web pages from AT&T Broadband Internet to Comcast High-Speed Internet. Until then it will run at startup and then terminate - hence the U recommendation
serviceconnect
Added by the AGOBOT.AIR WORM!
Servicee
Detected by Trend Micro as the AGENT.DEI TROJAN! See here. Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
ServiceLayer
Nokia Connectivity Library support task that is needed by NCLTRAY and by the Nokia Connection Manager for either to work properly
servicemng
Added by the TAME-C WORM!
Servicer
Added by the SDBOT.BAH TROJAN!
services
Added by the ZCREW TROJAN!
Services
Added by the METEORSHELL TROJAN!
Services
Added by an unidentified VIRUS, WORM or TROJAN! Back32.exe is the baddie whose purpose is to HIDE the MIRC32 server in service.exe
Services
Added by a number of VIRUSES, WORMS and TROJANS! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup!
Services
Added by an unidentified VIRUS, WORM or TROJAN!
Services
Added by a variant of the RBOT WORM!
Services
Added by the LANFILT-J TROJAN!
services
Added by the SDBOT.N WORM!
Services
Added by a variant of the RANKY.U TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!
Services
Added by a Proxy Trojan variant
Services
Added by the RANKY.L TROJAN!
Services
Added by a Proxy Trojan variant
services
Added by the FLYVB-C WORM!
services
Added by the WIN32.SMALL.N TROJAN!
Services
Added by the ZINCITE.A TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
Services
Added by the RANCK-DB TROJAN!
Services
Added by the MOGI WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%
Services
Added by the REPER-B WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
Services
Added by a variant of the SDBOT WORM!
Services
Added by an unidentified WORM or TROJAN!
Services
Added by an unidentified WORM or TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)
Services
Added by the RANCK-LT TROJAN!
Services
Added by the RANCK.LU TROJAN!
services
Added by a variant of the RANKY TROJAN!
Services Administrator
Added by the DLOADER-NY TROJAN!
Services Administrator
Added by the DLOADER-NY TROJAN!
Services Administrator
Added by the DLOADER-NY TROJAN!
Services Administrator
Added by the DLOADER-NY TROJAN!
Services Administrator
Added by the DLOADER-NY TROJAN!
Services Administrator
Added by the DLOADER-NY TROJAN!
Services Administrator
Added by the DLOADER-NY TROJAN!
Services Administrator
Added by the DLOADER-NY TROJAN!
Services Controller
Added by the CIADOOR.122 VIRUS!
Services Controller
Added by the CIADOOR-F TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
Services DLL Loader
Detected by Trend Micro as the IRCBOT.AYN BACKDOOR! See here
Services Host
Added by the DONK WORM!
Services Host
Added by the AGOBOT-TG WORM!
Services Logon
Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! By default this file is located in Documents and Settings[user name]Templates
Services Management Clients
Added by the RIZO.A TROJAN!
Services Managements
Added by the RBOT-GUC WORM!
Services Manager
Added by an unidentified TROJAN! See here
Services Manager!
Detected by Trend Micro as the IRCBOT.ATZ TROJAN! See here
Services Managers
Added by a variant of the IRCBOT TROJAN! See here
Services Process
Spyware - detected by Kaspersky as the SMALL.X TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
Services Process
Added by the SMALL-EK TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "config" subfolder
Services Start2
Added by the PYSKE-D WORM!
Services Startup
Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! By default this file is located in Documents and Settings[user name]Templates
Services Startup
Added by a variant of the RBOT WORM!
Services.dll
Added by the SOBER-L WORM! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a msagentsystem subfolder of the Winnt or Windows folder
Services.EXE
Added by the KAZPING WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
services.exe
Added by the CIADOOR-F TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
services.exe
Added by the MSNSPY-B TROJAN!
Services004
Added by the BUGBROS WORM!
services32
Added by the TrojanDownloader.Agent.rv TROJAN!
services32
"Shorty" adware - also detected as the AGENT.FD TROJAN!
services32
"Shorty" adware - also detected as the AGENT.FD TROJAN!
Services32 Startup
Added by the SDBOT-XO WORM!
ServicesAdministrator
Added by the PUNYA-B WORM! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
ServicesLoad
Added by the DEARIS-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
ServicesLog
Added by the RBOT-AMX WORM!
ServicesNotify
Defender Pro Antispy
servicestub.exe
Detected by Trend Micro as the RBOT.CN TROJAN! See here
Servicewin
Added by the MSNVB-D WORM!
Servicing
Added by the SDBOT.BUI WORM!
Servicio Local
Added by the SPYBOT.BGX WORM!
Servicos
Added by the BANKER-EHR TROJAN!
Servicos
Added by the BANCOS-BCM TROJAN!
servics
Added by the SINGU-J TROJAN!
SERVlCE
Added by the AGOBOT-UB WORM!
ServUTrayIcon
System Tray icon for Serv-U FTP server. Is it required?
SES Service
Added by the SDBOT-CZU WORM!
Session Client
SurfSpy keystroke logger/monitoring program - remove unless you installed it yourself!
Session Manager Subsystem
Added by the RBOT-AGS WORM!
SESync
DownloadWare adware
SetCacheMode
Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. May be necessary in order to maintain preferences applied to the RAID array connected to the Promise controller
SetDefaultMIDI
Related to a Soundblaster Audigy soundcards. What does it do and is it required?
SetDefaultPrinter
Used by HP and Compaq computers to hide the windows of programs passed as arguments to it
setdefprt
Used to set a Brother MFC printer/copier/scanner as the default printer after installation
SetDefPrt
Used to set a Brother MFC printer/copier/scanner as the default printer after installation
SetecCertUtil
Setec Web and Email Security. Setec PKI smart card software. The PKI technology enables secure and reliable user identification in services offered through Internet, mobile handsets and digital TV
setFTPBack
Added by the FTP_BMAIL TROJAN!
SetHook
Fellowes Neato CD label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar"
SETI@home
SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data
seticlient
SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data
SetIcon
Installed by a 6-in-1 (4 Media Card slots, a floppy drive and a USB connection) device. Constantly updates the icons for the four Media Card slots that it has and is a resource hog
SetiQueue
Provides work unit buffering for Seti@Home clients - see here for more details
SetiSpy
SETI Spy is a little program to "spy" on the progress and performance of the SETI@home client. Called a "spy" because it is unobtrusive as possible
SetPoint
Added by the RBOT-BWI WORM! Note - this is not the valid Logitech Setpoint mouse and keyboard entry that uses the same filename and is located in the LogitechSetpoint sub-folder of Program Files. This file is located in the System (9x/Me) or System32 (NT/2K/XP/Vista) folder
SetPoint
Logitech SetPoint Event Manager for their range of mice and keyboards. Required if you want to use the advanced features of these devices and is located in the LogitechSetpoint sub-folder of Program Files
SETPOINT Logitech Inc
Added by the RBOT-AAX WORM!
SetRefresh
Video refresh rate utility found on some HP and Compaq PCs. Recommended for CRTs but not LCDs
Setting
Added by the SDBOT.GEN TROJAN!
setup
HP DeskJet Setup - printers function normally without it
Setup experation
Added by the TOFGER-AW TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder
setupa
Added by the QQPASS-K TROJAN!
setupdata
Added by the QQPASS-AC TROJAN!
SetupICWDesktop
Appears to be the "Internet Connection Wizard" from Internet Explorer being set-up as a desktop shortcut. Appears under the RunOnce registry key but is available under Start -> Programs -> Accessories -> Communication (or similar) anyway
setupuser
Regfile in disguise - another CoolWebSearch parasite variant
setuzp
??
SetVrc
Added by the HUNTOCX WORM!
Sex Teris
Added by the REPAD WORM!
Sexnow
Added by the SENOW-B premium rate adult content dialler
Sexy_Blondes
Added by the Sexy DIALER! Related also to Hot Tarts DIALER!
Sexy_sg
Premium rate adult content dialler
sf
SurfEnhance adware component
SFIGUI
Sonic Focus - "enhances music, movie and game sound by analyzing compressed audio streams in realtime, then restoring and enriching audio back to its original performance qualities"
sfita
Added by the FAVADD-H TROJAN! Also known as SurfEnhance adware
SfKg6w
Added by the AGENT.BUO WORM!
SfKg6wIP
Identified as a variant of the TrojanDownloader.Matcash malware
SfKg6wIPu
Identified as a variant of the TrojanDownloader.Matcash malware
SFP
Verizon Online Support Center - prompts for online updates
sfpc
Spy4PC surveillance software. Uninstall this software unless you put it there yourself
SFtrb Service
Added by the SOBIG.D WORM!
SfWinStartInfo
SFIRM32 Online Banking software
Sgecrypt
SafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks"
Sgeecview
SafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks"
sginst
eAcceleration Stop-Sign security software related. Previously not recommended, see here
SGTBox
Canon scanner driver. Is it required?
sgtray
StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups
Shadow
"NTI Shadow 3 is an award-winning easy-to-use backup application that automatically protects your photo, music, video, and various data files. It makes data restoration as easy as dragging and dropping files from one place to another"
ShadowUser Pro Edition
"StorageCraft? ShadowUser? provides easy to use desktop security and protection for Windows operating systems. ShadowUser is the best way to prevent unwanted changes to PCs and laptops"
shambl3r
Added by the REMABL WORM!
shambl3r*
Added by the REMABL WORM! where * is 2 to 11
SHAProc
Added by the WINKO.AO WORM!
Share-to-Web Namespace Daemon
HP's exclusive Share-to-Web software makes it easy to share content with others through our affiliate Internet websites. In other words an application that allows users to upload scanned images to their personal webpages if desired. Available via Start -> Programs
Shareaza
Shareaza P2P client
Shareaza
Shareaza P2P client related
sharedprem
Added by the MAKECALL TROJAN!
ShareSearcher
Added by the AGENT-FPE TROJAN!
ShareSearcher
Added by the ENCLAG-A TROJAN!
Sharing and Mapping Software
Intel AnyPoint internet sharing software. Now discontinued
SharkEject
Allows you to eject a disk from the Avatar Shark drive from the system tray. When loaded, there is a desktop icon so this isn't required
SharpTray
Part of Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents"
Shcenter
IMSI HiJaak - "the easiest way to convert, capture, and manage all your graphic files"
shdef
Added by the VB-DVS TROJAN!
SheduIer
Premium rate adult content dialler
SheduIer
Added by the EB TROJAN!
SheduIer
Added by the EB TROJAN!
Shedule Connection
Added by the PPDOOR-R WORM!
Sheduler
Added by the TACTSLAY.B TROJAN!
Shell
Added by the GOLDSPY-B TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
Shell
Added by the TORPIG-Q TROJAN!
Shell
Added by the AGENT-BR TROJAN!
Shell
Added by the BADSECTOR TROJAN!
Shell
Homepage hijacker re-directing browsers to adult content websites
Shell
Homepage hijacker re-directing browsers to adult content websites
Shell
Added by the GOLDUN TROJAN!
Shell
Added by the SMALL-DL TROJAN!
Shell
Added by the GP TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System subfolder
Shell
Added by the ZLOB TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System (9x/Me) or System32 (NT/2K/XP) folder
Shell
Added by the DOYORG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder
shell
Added by the KAKKEYS TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
Shell
Added by the KIPIS-U WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%\Microsoft
Shell
Added by the TORPIG-C and TORPIG-J TROJANS! Filenames spotted include ibm00001.exe, ibm00002.exe, ibm00005.exe and so on
Shell
Added by the BANCBAN-FT TROJAN!
Shell
Added by the AGENT-FD TROJAN!
Shell
Added by the ANSERIN TROJAN!
Shell API32
Added by the TIBICK.C WORM!
Shell Extension
Added by the LOVGATE.Z WORM!
Shell Tray Window
Added by the STULTDOR-A TROJAN!
shell update
Added by the AGOBOT-TH WORM!
Shell.exe
Added by the EMERLEOX.S WORM!
Shell32
Added by the SCAFENE WORM!
shell32
Added by the JLOK-A WORM!
Shell32
Added by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%
ShellApi
Added by the NETDEV.B TROJAN!
Shellapi32
Added by the NETDEVIL (or NERTE) TROJAN!
Shellapi32
Added by an unidentified WORM! Note - do not confuse with the McAfee SecurityCenter file of the same name
shellbn
SoftStop misleading security software - not recommended, see here
ShellCommand
Added by the REMCON-A TROJAN!
Shelldaemon
Added by a variant of the AGENT.ALN TROJAN!
ShellEx
Added by the ANAKHA TROJAN!
ShellN
Added by the IBILL.Z TROJAN!
ShellOS
Added by the AV TROJAN!
ShellRun
Added by the MSNOPT-A TROJAN!
ShellRun32
Added by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%
Shellspl
Added by the YALER-A TROJAN!
Shellspl
Added by the PROXAGE-A TROJAN!
shellsystem
Added by the UPCHAN TROJAN!
shhost
Added by the AGENT.CE TROJAN!
shicoxp
Installed with the drivers for multi card readers of various brands. To differentiate between the various card slots on multi slot readers the shicoxp.exe file assigns and loads unique drive icons for the various card slots that are displayed in Windows Explorer
Shield Security
Added by the RIZO.A TROJAN!
Shield32 Security
Added by the RIZO.A TROJAN!
Shine
Added by the HAPPYLOW (or NISHE-A) VIRUS!
SHINITV
??
Shmgrate.exe
Added by the GASTER TROJAN!
ShockmachineReminder
"Shockmachine is a stand-alone application that lets users collect Macromedia Shockwave and Flash titles and play them offline". Could be a registration reminder for the trial version
Shockwave
Added by the SNDOG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
Shockwave Init
Part of Macromedia Shockwave. Controls the Shockwave Remote Control Panel. The Remote Control can be activated manually from the Start Menu by locating and selecting Shockwave and then Shockwave Remote under Programs
Shockwave Support
Added by the DELF-DRA WORM!
ShopSafe
Created by Orbiscom for MNBA (now Bank of America) - ShopSafe creates a temporary card number each time you make an online purchase
ShortKeys 99
ShortKeys from Insight Software Solutions - allows you to program keys with text strings
ShortKeys Lite
ShortKeys Lite from Insight Software Solutions, Inc. A macro utility to automate a task that you perform repeatedly or on a regular basis
sHotKey
Special function key manager for Chicony keyboards - see here
Showbehind
Advertisement display which can be stopped here
ShowFF
FFToolBar adware toolbar
ShowIcon_Justrams_USB Product Driver v2.12r012
Related to Just Rams USB product driver. Is it required?
ShowIcon_PNY_PNY Attach
PNY Attach? USB flash memory stick System Tray icon - shows when the device is plugged in
ShowIcon_SmartDisk Corporation_USB Card Reader v1.14e051
Card reader for memory cards from digital cameras. Is it required?
ShowLOMControl
Note that there is a strange symbol in the command field. HKLMSoftwareMicrosoftWindowsCurrent VersionRunShowLOMControl Reg_DWORD 0x00000001 (1) LOM = LAN on Motherboard.It mean Show "LAN on Motherboard" Control.On systems where you can install an external LAN interface, it will warn you that you already have a built-in LAN interface. Appears to be a feature on certain Dell systems
Showme
Added by the HANDLE-A VIRUS!
ShowWnd
Found on Gateway computers (and maybe others) - see here. "Showwnd is included with the Chicony keyboard software and is used by the software to stop the keyboard driver's taskbar entry from reappearing. It is not necessary to remove the keyboard software, however if you wish it can be removed through Add or Remove Programs"
SHPC32
Port monitor for Lexmark printers on a USB connection. Ties in with the Printer Control Program. Features like cancelling a print are unavailable if disabled
ShStatEXE
From McAfee VirusScan NT 4.x. Handles program communication among VShield components, displays VShield icon. Can be started automatically or available via Start -> Programs
Shutdownaware
Loaded by the SWEEX 6-in-1 Media Card Reader to properly manage the reader while it is connected to your system
ShutDownPro
ShutDownPro - shutdown, reboot, logoff your System with one mouse click
Si Meter
Si Meter - keep track of things like CPU activity, network activity and speed, hard-drive activity, hard-drive space, system memory, running processes, or just date and time
si91e44b
LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "si91e44b.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
SIA2006
Part of Steganos Internet Anonym privacy software
SIAPRO6
Steganos Internet Anonym privacy software
Sicom
Added by the NETLIP WORM!
SideACT
SideACT organizer software
Sidebar
Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. But on other versions of Windows it can be a part of the Searchcentrix hijacker
SIDEBAR
"Desktop Sidebar provides you with instant access to the information you most desire by grabbing data from your PC and the internet. The result is a dynamic visual display you configure and control"
SideWinderTrayV4
MS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs
SightSpeed
SightSpeed Video Chat - "lets you connect with all your friends and family easily. Make video calls, phone calls, and send video mails and text messages to everyone in your network, anywhere in the world"
SigmaTel Audio
Sigmatel audio driver
SigmatelSysTrayApp
System tray program for the Sigmatel Audio sound card. Often found on Dell computers
SigmatelSysTrayApp
System tray program for the Sigmatel Audio sound card. Often found on Dell computers
SigX
??
SigXC
SigX is a "dynamic signature image generated based on whatever data your computer sends it though our SigX program. It can display your current Mp3, current OS, Free Ram, your current time and more"
Simcast
Simcast is a free service that allows you to subscribe to information on a large variety of topics. Alerts will appear on your desktop when a channel that you have subscribed to has something to say
Simple Star PhotoShow Media Manager
Simple Star PhotoShow photo editing and organizing software, makes it easy to send and share digital photos. Bundled with software from Nero, ComCast, SnapFish, MacroMedia and others
Simplify Media
Simplify Media media manager - "enjoy songs from home while at work or from any WiFi location. Explore friends' music while they are online"
SimpLite-MSN
Required if you use the SimpLite add-on to MSN Messenger (SimpLite adds encryption to the instant messaging service)
sInErA
Added by the SILLYFDC-AB WORM!
Singapore
Adds a blue crescent to the taskbar and when double-clicked displays an adult-content web-site. Also known to drop your internet connection and dial an international telephone number. See here for more information. Must be disabled in MSCONFIG before un-installing or it re-instates itself
Sinus 1054 data WLAN Manager
Wireless management utility for the T-Com Sinus 1054 Data WLAN adapter
SipDiscount
FreeCall - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype
SIPPS
Web.de Internet phone utility
SiS Dns
Added by the DLOADER-UE TROJAN!
SiS KHooker
SiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required
SiS Mpc Service
Added by the CIADOOR-CJ TROJAN!
SiS Tray
System Tray icon for SiS based graphics. Note - this resides in C:WindowsSystem
SiS Windows KeyHook
SIS graphics cards related: "Super VGA Keyboard Daemon" - hooks into the keyboard processing chain in order to enable hotkey settings
sis32
Added by the QQPASS.IA WORM!
SiS7012Utility
SiS Corporation sound card driver
SISAM10M
??
SiSAudio
WinME patch for an older SiS 961 chipset FERR bug. Enable if you have audio problems
siscolor
Probably on-board graphics related based upon the SiS chipsets. Has been seen on ASUS motherboards with SiS chipsets and known to cause conflicts if you choose another graphics card and disable the on-board
siService.exe
Spam Inspector - anti email spam software
SiSPower
Responsible for power management for SIS chipsets - is it required?
SiSRaid
Related to the SIS Raid system from Silicon Integrated Systems
SiSSetCDfmt
Related to a Silicon Integrated Systems Corp (SiS) product?
SISSoundman
Related to a Silicon Integrated Systems Corp (SiS) product?
SiSSWLED
System Tray utility for SiS 900 network cards
sistrai.exe
Added by the PROVA TROJAN!
sistray
Added by the PROVA TROJAN!
sistray
System Tray icon for SiS based graphics. Note - this resides in C:WindowsSystem
Sistray32
Added by the HOLCAS.A WORM!
Sistray32
Added by the JUMPRED.A WORM!
Sistray32
Added by the TOMETA-C TROJAN!
sistry
Added by the CEBE WORM!
SiSUSBRG
SiS USB Registry Patch File - fixes the undetectable problem with SiS USB controller on Windows XP
SiteAdvisor
SiteAdvisor from McAfee warns you before you interact with a dangerous Web site
sittachasnahalbasya
Added by the HANSAH-A WORM!
sixer566
Added by an unidentified WORM or TROJAN!
sixtysix
Medload adware
sjduwiwx
Added by a variant of the ORCU.B TROJAN!
SK51
SaveKeys keystroke logger/monitoring program - remove unless you installed it yourself!
SK60
SaveKeys keystroke logger/monitoring program - remove unless you installed it yourself!
SK9910DM
Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
SKDAEMON
Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
SkinClock
Atomic Alarm Clock - "Alert yourself about important events with different alarms and replace your computer tray clock using different skins. Computer Alarm clock that will play any MP3 file. It can also run a program, log off, wake up, reboot, shut down, turn off etc..."
skinkers
Selection of desktop messaging/marketing tools with celebrity tie-ins including MTV's "Desktop Ozzy" and Arsenal's "Desktop Wenger" - see here. Leave enabled if you want to receive messages
Skra
Identified as a variant of the TrojanDownloader.Matcash malware
sks-32
SpyKeySpy logs keystrokes and sends the stolen information to a configurable email address
Skunk
Added by the SUNK-A WORM! Note - this file is found in the root folder (C:), (D:), etc
SkyBlaster Scheduler
For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
skynetave.exe
Added by the SASSER.D WORM!
SkynetRevenge
Added by the NETSKY.AA WORM!
Skype
"Skype is free and simple software that will enable you to make free calls anywhere in the world in minutes"
Skype Startup
Added by the VANBOT-C WORM!
SkypeMate
SkypeMate acts as a bridge between networks of VoIP and PSTN
SkypeStartup
Added by the PYKSE-A WORM!
SkySurfer Management Service
For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
SkyTel
Process associated with Realtek Voice Manager for some of their audio chipsets
sl4 rules
Added by the SDBOT-QC WORM!
slack12
Added by a variant of the SDBOT WORM!
Slayhacker734
Added by the SIKBOT-A TROJAN!
SleepManager
This program locates free contiguous disk spaces and allocates them for storing BASE MEMORY, EXTENDED MEMORY, VIDEO MEMORY, and SM RAM. It helps the computer come out of hibernate mode
Slibe.com
Sliber - freeware screen capturing & online sharing tool
SlickRun
"SlickRun is a floating command line utility for Windows. It gives you almost instant access to any program or website. SlickRun allows you to create command aliases (known as MagicWords), so C:Program FilesOutlook Expressmsimn.exe becomes MAIL"
slide
Added by the GASLIDE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!
slimp3
Slimp3 Server - "presents an entirely new way of accessing and enjoying your music collection. Instead of storing your music on CDs or memory cards, the SliMP3 uses your home network to access the music stored on your PC"
Slingshot
Atomica Slingshot - "reference tool with access to dictionary and encyclopedia terms, bios, technical terms, history, geography, and much more". Now superseed by 1-Click Answers
slipcore
Core module for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet, Wanadoo, Terra, OnSpeed, United Online and AOL Canada. Required if the user's account is locked in to that proxy server
slipgui
User interface for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet, Wanadoo, Terra, OnSpeed, United Online and AOL Canada. Required if the user's account is locked in to that proxy server
SlipStream
Core module for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet, Wanadoo, Terra, OnSpeed, United Online and AOL Canada. Required if the user's account is locked in to that proxy server
slmss
SeekSeek search hijacker related - see here
sload
Win SynchroAd adware, also detected as DLOADER-QG TROJAN!
slvchost32
Added by an unidentified VIRUS, WORM or TROJAN!
sm
Added by the OLFEB.A TROJAN!
sm
Added by the OLFEB.A TROJAN!
sm
Added by the OLFEB.A TROJAN!
sm
Added by the LUKUSPAM TROJAN!
SM
Added by the IROFFER.CT TROJAN!
SM1BG
USB driver for downloading from within Napster and iTunes to portable MP3 players. Only required at startup if you use it all the time - otherwise start it manually when required
SM1NINT
Cypress USB Mass Storage Driver Notification Icon Application - tray notification for Cypress base memory sticks and external storage devices for Win98
SM56 Helper Win32 Utility
Helper utility for Motorola based SM56 software modems - resides in the System Tray
Sm56acl
Helper utility for Motorola based SM56 software modems - resides in the System Tray
sman
Unidentified adware
SManager
Added by the AGENT.BJO TROJAN!
SManager
Added by the DWNLDR-GVG TROJAN!
SmansaApp
Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
Smapp
System Tray access for the Compaq/ADI SoundMAX integrated digital audio controller
Smart Card Service
For Smart Card readers. Known to cause problems, especially for Windows 2000 users - see here. Probably not required unless you use such a device regularly
Smart Connect Monitor
Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio
Smart Connect Setup
Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio
Smart Keyboard
Netropa Smart Keyboard driver
Smart Label O Server
Part of the printer software for the smart-label printer made by Seiko. Can be disabled safely
Smart Label RFViewer
Part of the printer software for the smart-label printer made by Seiko. Can be disabled safely
Smart Start UP
Part of Presto! Mr.Photo - "an ideal program for creating, sharing, and manag-ing digital images and videos"
Smart Touch
Related to Plustek OpticSlim scanner
Smart Type Assistant
Smart Type Assistant - a complex typing automation tool, intended to make your work faster and safer
Smartalec
Smartalec PC Accelerator - system optimization utility
SmartAudio
Conexant SmartAudio PC audio chipset software - typically available on HP notebooks with built-in microphones
SmartBarXP
SmartBarXP is a bar that runs down the side of your screen, and can be configured to display interactive panels known as 'panes'. These panes include media players, slideshow and image viewing panes, a virtual desktop manager, and live news, weather and stock feeds to mention but a few
sMaRTcaPs
sMaRTcaPs from Phoebus LLC - enables you to configure the time needed to depress Caps Lock, Num Lock & Insert keys
SmartDefrag
"IObit SmartDefrag helps defragment your hard drive more efficiently than any other product on the market - free or not"
Smarthruengine
Samsung smarthru software, used with Lexmark Z82 or Samsung multifunction printers
SmartPCXL
Smartalec PC Accelerator - system optimization utility
SmartRAM
Memory Cleaner - monitors your system in the background and frees up memory when ever need to increase the performance of your computer. Part of IOBit Advanced Windows Care Personal/Professional
SmartSync Pro
Related to CompanionLink Software Inc. Synchronization solutions for ACT!, GoldMine, Lotus Notes and Microsoft Outlook
SMax4
System Tray icon for SoundMax integrated sound. Sound properties can be accessed through the Start Menu or Control Panel
SMax4PNP
SoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments
smbdpmi
IBM Netfinity Director and Universal Management Services related. What does it do and is it required?
smc
Sygate Firewall
smc
Sygate Firewall
SMC Service
Sygate Firewall
SMC Service
Sygate Firewall
smcserv
Added by the AGOBOT-OU WORM!
SmcService
Sygate Firewall
SmcServices
Sygate Firewall
SmcServices
Sygate Firewall
smcss
Added by the SCLOG-AJ TROJAN!
Smcsta.exe
SMC Networks wireless PCI card driver. Is it required?
SmcSVR
Added by the LEGMIR.JU TROJAN!
smgr
Covert Sys Exec malware variant
smgr
Added by an unidentified WORM or TROJAN!
SmileboxTray
System Tray access to Smilebox photo sharing/printing service
Smiley District
Smiley District adware
Smith Micro try
Smith Micro shared files. Comes with D-Link web cam
smodul
UserMonitor from Neuber. Teachers can broadcast screen to other screens, see students screens in a network and detect unauthorized software
SmoothView
TOSHIBA Zooming Utility - allows "automatic" zoom feature in some appications, like IE, MS-Office, WMPlayer, Adobe Reader and also desktop icons
SMPAutoStart
Smart Phone Recorder demo from KenGolf.com. Answering Machine, Caller ID, Call Recording
SmpcSys
"Set Up My PC" utility supplied with some Packard Bell computers
smres
Added by the AGOBOT-UA WORM!
smrtdrv
Added by the AGOBOT.MT WORM!
SMS
Added by the IROFFER.CT TROJAN!
SMS Application Launcher
Microsoft Systems Management Server - used to manage computers on a network remotely
SMS Client Service
When the SMS Client service starts on a domain controller, the Client service modifies the SMSCliToknAcct & user account group membership, user rights, and account comment. The Client service then waits for the synchronization of the comment to verify that the account and user rights are properly set for this account. This account is used to obtain a token to start the SMS Client processes, such as the Software Inventory and Software Distribution agents (MS Systems Management Server)
Sms System32
Unidentified malware
SMS Win9x Message Agent
This program assigns a user to a Systems Management Server site
SmsDiscount
SmsDiscount - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype
Smserial
Helper utility for Motorola based SM56 software modems - resides in the System Tray
SMSERIALSTARTER
Detected by McAfee as the FAKEALERT-AH TROJAN! See here. Installed with the SpyBurner spyware remover - which is not recommended, see here
SMSERIALWORKERSTART
Detected by McAfee as the FAKEALERT-AH TROJAN! See here. Installed with the SpyBurner spyware remover - which is not recommended, see here
SMSERIALWORKERSTARTER
Added by an unidentified WORM or TROJAN! See here. Installed with the SpyBurner spyware remover - which is not recommended, see here
SMSERIALWORKSTARTER
Detected by McAfee as the FAKEALERT-AH TROJAN! See here. Installed with the SpyBurner spyware remover - which is not recommended, see here
smsger
Added by a variant of the SDBOT WORM!
SMSI Loader
Smith Micro HotFax - fax software
smsm
Added by the BANKER-CO TROJAN!
smsrv
Added by the AGOBOT-SX WORM!
SMSS
Added by the FLOOD.F TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "Catroot" subfolder
smss
Added by the ALADINZ.F TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!
smss
Added by the AGENT-TR TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
smss
Added by the BOROBOT-J TROJAN and variants! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!
Smss
Added by the RBOT.OP WORM!
Smss Host
Added by the IRCBOT-ACC TROJAN!
smss.exe
Added by the DALBUG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
smssLevel4
Unidentified malware! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in Program FilesWindows Media PlayerSkinsWindowsMediaSkinDataLevel4 folder
SMSSS
Added by the SDBOT.ZD WORM!
SMSSS Loader
Added by the AGOBOT.MQ WORM!
SMSSU
Hijacker, detected by Norton antivirus as Trojan.StartPage.O
smsys
Added by the CLICKER-C BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in a "Template" subfolder
smsys
Adult content dialler
SMSystemAnalyzer
Part of the Iolo System Mechanic optimization tool
sms_msn
Added by an unknown WORM or TROJAN!
sms_msn40
Added by an unknown WORM or TROJAN infection
Smt
Win-Spy keyboard logger/monitoring software - remove unless you installed it yourself
SMToolbar
StartMake.com toolbar
SMTP32 Mailing Protocol
Added by a variant of the RBOT WORM!
SmWizard
SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required?
SM_IAN
AdvancedCleaner misleading security software - not recommended, see here
SN Messenger
Added by the RBOT-AVP WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility
SnagIt 8
"SnagIt lets you capture, edit, and share exactly what you see on your screen - fast"
Snapfish Media Detector
Snapfish Media Detector - "Upload your photos to Snapfish, where you can store and share your photos for free on line"
SnapfishMediaDetector
Snapfish Media Detector - "Upload your photos to Snapfish, where you can store and share your photos for free on line"
snapple
Added by the FORBOT-EG WORM!
snbr
??
snbupt
UpSpiralBar adware
sncntr
Added by the DLUCA-I TROJAN!
SNCT511
Unidentified "Snapshot Viewer"- what does it do and is it required?
SND Volumes
Added by a variant of the IRCBOT BACKDOOR! See here
snd332
Added by the B1LD0 AIM WORM!
Sndcompat
Added by the GEMA TROJAN!
sndmi13
Driver for DualCam cameras - that combine the best features of a digital still camera and a webcam
SNDMon
Part of Symantec's LiveUpate (eg, Norton). Not required if you run manual updates but probably require if you leave them to run automatically. Also, if one runs a small office network and SNDMon is disabled on one of the computers ? then other computers disappear from the network for this computer, including shared devices like printers and scanners. Hence the "U" recommendation
Sndsaver
Added by the GEMA TROJAN!
sndsrvc
Part of Norton Personal Firewall and Norton Internet Security - what does it do and is it required?
SNInstall
Spy Sheriff/SpywareNO malware, also detected as the SPYHOAX-A TROJAN, pretends to be a spyware remover! - file names spotted sofar include VXH8JKDQ2.EXE, NS6281400.so, CVXH8JKDQ2.EXE, down3.exe, sefe.exe, winstall.exe, and tool2.exe
Snippet
The Snipping Tool (part of the Experience Pack for Tablet PC) allows you to easily "cut out" anything on screen and share it with other people. The whole screen becomes an "inkable" surface that you can add comments to and mark up however you like. You can then save that annotated image to use later, or send it to someone else in an E-mail message
SNM
SpyNoMore anti-spyware
SnoopFreeUI
Anti-keylogging software made by SnoopFree Software
SNP Generic Host Process
Added by the ZAPCHAS-O TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
snp2std
Digital camera related
snpstd
Sonix PC Camera Monitor MFC Application. What does it do and is it required?
SNPSTD2
CameraMonitor MFC Application. Appears to be related to a USB connection to a digital camera -is it required?
snpstd3
Sonix Inc. Camera Monitor MFC Application
Snsicon
Launches a screensaver program from Second Nature
SNSS.EXE
Added by the Nunci premium rate dialer
snvc
Added by an unidentified WORM or TROJAN!
SO5 Integrator Pass One
StarOffice 5. See here for more details
SO5 Integrator Pass Two
StarOffice 5. See here for more details
Soar
PurityScan/Clickspring adware
Social Security Agency
Added by a variant of the RBOT WORM!
Sock32
Added by the SDBOT TROJAN!
Socket Utility
Added by the DAEMONI-E TROJAN!
Socket Utility
Added by the DAEMONI-E TROJAN!
SoDA Startup
Used by the IBM Rational SoDA project management tool. Unsure of it's actual purpose but it's recommended you leave it enabled if you use the software
soffice
Displays StarOffice quick start applet in System tray. Right clicking on the icon allows rapid starting up of components of the StarOffice 6.0 suite. Available via Start -> Programs. Automatically started when any StarOffice 6.0 component is started from the Start -> Programs. A resource hog (it eats > 16 MB of memory).
Soft Profile Inc
Added by the LOVGATE.AO WORM!
Soft Profile Inc
Added by the LOVGATE.E WORM!
soft2
Added by the KARDPHISHER TROJAN!
Softany Monitor Control
Softany Monitor Control - "control your computer's monitor and screensaver"
SoftGridTray
System Tray access to SoftGrid from Microsoft - "the only virtualization solution that delivers applications that are never installed and dynamically delivered, on demand"
softIce Update 32
Added by the RBOT-ANB WORM!
SoftickPPP
Softick PPP is a Microsoft Windows driver that allows to establish PPP session between Palm powered devices and Microsoft Windows desktop computer
SOFTinst
For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
SoftStuff Wallpaper Changer
AzureBay wallpaper changer
Software
Added by the CRABTON-B TROJAN!
Software Soft Stop
SoftStop misleading security software - not recommended, see here
SoftwareStation
eAcceleration Stop-Sign security software related. Previously not recommended, see here
SolidWorks Task Scheduler Engine
Task scheduler for SolidWorks 3D CAD software
Solo Sentry
Solo Antivirus
SoloSchedule
Scheduler for Solo Antivirus. Leave enabled unless you scan manually on a regular basis
SoloSysCheck
Solo antivirus System Integrity Check - Monitors system registry, system.ini, win.ini and startup to protect you from new Internet Worms and Backdoors
somatic
Searchcentrix hijacker
some
Online Video Add-on - masquerades as a helper application for watching videos. In reality, though, it installs a rogue anti-spyware, or SmitFraud, application on your computer
some
Netproject malware
Sonic A3D Control
Sound related options
Sonic RecordNow!
Added by a variant of the SDBOT WORM!
SonicFocus
Sonic Focus - "enhances music, movie and game sound by analyzing compressed audio streams in realtime, then restoring and enriching audio back to its original performance qualities"
SoniqueQuickStart
Quickstart for the discontinued Sonique audio player. Available via Start -> Programs
SonnReg
Now superseeded by ColorWizzard - 3Deep corrected lighting, shading and color for all your 2D and 3D games. Possibly a registration reminder?
SonudMan
Added by the STARTPAGE.Q TROJAN!
SonudMan
Added by the QQROB-DC TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
SonudMon
Added by the LEWOR-J TROJAN!
Sony Ericsson PC Suite
Application launcher from the Sony Ericsson PC Suite for their mobile phones
SonyPowerCfg
Related to Sony VAIO Power Management Module installed on laptops and provides additional configuration options for these devices. This program is non-essential process to the running of the system, but should not be terminated unless suspected to be causing problems
Soot
??
sophagnt
Possibly related to Sophocles Screenwriting Software?
SOProc_RegSoAlertWxLiteNnAj
SoftwareOnline Intelligent Downloader - "Bundle engine to enable download of end user approved third party applications and reporting of installs for billing purposes only". Said to monitor user's browsing habits and display pop-up ads
SOS
Added by the PHILIS VIRUS!
SoSyncMonitor
SuperOffice related. What does it do and is it required?
Sound Loader
Added by the AGOBOT-BV WORM!
Sound services
Added by the AGOBOT.GG WORM!
Sound System
Added by an unidentified VIRUS, WORM or TROJAN!
Sound Volume
Added by a variant of the IRCBOT TROJAN! See here
soundcontrl
Added by the GAOBOT.AFJ WORM!
sounddrv
CoolWebSearch parasite variant
SoundFusion
Control panel item for the Terratec DMX Xfire 1024 soundcard (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time?
SoundFusion
Control panel item for Hercules Fortissimo soundcards (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time?
SoundFusion
Control panel item for a Terratec soundcard (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time?
SoundMam
Added by the QQROB-AAL TROJAN!
soundman
System Tray icon for the Realtek AC97 Audio Sound Manager for AC97 onboard audio. Available via Start -> Settings-> Control Panel
SoundMan
Added by the AGOBOT.HM WORM! Note - this is not the legitimate SiS or Realtek file of the same name that is located in the Windows or WINNT directory
SOUNDMAN Microsoft Help
Added by the RBOT-AIU WORM!
SoundMAX
System Tray icon for SoundMax integrated sound. Sound properties can be accessed through the Start Menu or Control Panel
SoundMAX
Added by the RIZON-A WORM! Note - this file is placed in the Startup folder itself, and has NO relation to SoundMax sound cards!
SoundMax Audio Drivers
Added by a variant of the SDBOT WORM!
SoundMAXPnP
SoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments
soundmix
Added by the AGENT.PGV WORM!
SoundMixer
Added by the DEDLER-G TROJAN!
SoundMnEx32
Added by the STRATION-FW WORM!
Soundmx
CoolWebSearch Tapicfg parasite variant
soundtask
Added by the AGOBOT-MD WORM!
soundtasks
Added by a variant of the CRYPTER.C TROJAN!
soundtctrls
Added by the AGOBOT-ZV WORM!
SoundView
Trojan downloader
sounofts
Added by the AGOBOT-ND WORM!
sountskmanager
Added by an unidentified WORM or TROJAN!
SourcePath
Used to update Gateway registry settings for System Restoration Kit and Web update programs
sp
IE search hijacker - changes the default search to http://www.gocybersearch.com/
sp
Malicious javascript annoyance that changes the default search engine in IE to one of many including "topsearcher". See here for more and a fix
sp
Added by the Startpage.M hijacker
sp
Added by the ABLANK-W and ABLANK-Z TROJANS!
SP TimeSync
SP TimeSync lets you synchronize your computer's clock with any Internet atomic clock (time server)
SP00LSV
Added by the GRAYBIRD.E TROJAN!
SP2 Connection Patcher
Changes limit of concurrent TCP connections of Windows Service Pack 2
SP2 data
Added by a variant of the RANDON.AN WORM!
SP2 Firewall/Internet Updater
Added by the RBOT.BJO WORM!
sp2chk.exe
Added by the ALUROOT.A TROJAN!
sp2ctr
Added by the DLUCA-M TROJAN!
sp2fwxp
Added by the SMALL.ABW TROJAN!
sp2svc
Added by a variant of the RBOT WORM!
sp2update
SP2Update adware! Tracks URLs visited and search terms entered into Internet Explorer
Spam Blocker for Outlook Express
Hotbar adware
SPAM FIREWALL
Added by the SDBOT.AOU WORM!
Spam Sleuth
Spam Sleuth E-mail spam detection program
SpamBlocker
Hotbar adware
SPAMfighter Agent
SPAMfighter anti email spam filter
spamihilator
Spamihilator - spam filter
SpamPal
SpamPal - anti-spam tool
SpamSubtract
Intermute SpamSubtract - junk email detection and removal program
spamsubtract
InterMute™ SpamSubtract - junk email detection and removal program. InterMute™ is now part of Trend Micro and their products are no longer supported
Spare Backup
Spare Backup - "Once Spare Backup is installed, backups are automatic. With Spare Backup it's easy, you don't even have to select files for backup, Spare Backup does it for you"
Spark
Spark instant messaging client
SparVoip
SparVoip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype
spa_start
IconAds adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "spads.dll" file is located in the Winnt or Windows folder
spa_start
AdRotator adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "sprt_ads.dll" file is located in the Winnt or Windows folder
spc_w
NetZero Search Enhancement related
spc_w
NetZero Search Enhancement related
spc_w
NetZero Search Enhancement related
Spdstart
Norton Utilities Speed Start. "This feature optimizes the start up speed of launching applications, such as Word and Excel."
Speaking Clock Deluxe
Speaking Clock Deluxe - turns your computer into a speaking clock with several languages. It can also keep track of up to 50 alarms that can be set to a time and a date, and be repeated daily, weekly, monthly and yearly
Special Firewall Service
Added by the NETSKY.G WORM!
SpecialOffers
SpecialOffers adware
SpecialOffers
SpecialOffers adware
specific
Added by a variant of the SDBOT WORM!
Speed racer
Software for a Creative sound card
Speed Tec
Accel SpeedTec from Montana Software speeds up your modem. SpeedTec modifies the Internet Protocol settings in the Windows registry to speed downloads on all modems. If you find this improves your connectivity and download speeds leave this enabled
SpeedBoss
Added by the OPASERV.AD WORM!
SpeedItUp
Speed It Up - "all in one Speed Booster designed to significantly increase the speed of your computer and boost your PC available memory"
SpeedItUp
Installs PC-Checkup and Search Defender (which is detected by DrWeb as the STARTPAGE.ORIGIN TROJAN) without permission
SpeedItUpEX
"Speed-It-Up Extreme is designed to speed of your computer up to 3 times faster and boost your PC available memory"
Speedkey
Additional keyboard shortcuts on MS programmable keyboard
SpeedMeter
Application measuring upload and download speed
SpeedOptimizer
SpeedOptimizer is designed to optimize and speed-up your Internet data transmission including browsing, streaming, downloading, uploading and e-mail communication
Speedport W 100 Stick WLAN Manager
Wireless management utility for the Speedport W 100 Stick WLAN USB stick
SpeedRunner
Identified as a variant of the TrojanDownloader.Matcash malware
SpeedswitchXP
SpeedswitchXP is a CPU frequency control for notebooks running Windows XP
Speedtouch USB Diagnostics
For an external Alcatel ADSL high-speed modem. A diagnostic tool and can be run from the Start menu when required. The only reason it might be useful on startup is if you like seeing an 'at-a-glance' status indicator on the taskbar (the icon is a different colour depending on the status of the device/line)
SpeedUpMyPC
Older version of SpeedUpMyPC from Uniblue - which "lets you monitor and control all your PC resources with easy, one click instructions. System settings, internet usage, disk clutter, RAM and CPU are all automatically scanned, cleaned and optimized for peak performance"
Spees1
Added by the OPASERV.Y WORM!
Spees2
Added by the OPASERV.AD WORM!
Spees3
Added by the OPASERV.AD WORM!
Spellex Anywhere
Spellex-Anywhere - adds spell checking functionality to almost any Window program. Create a shortcut and run manually before it's to be used
Spiceworks
System Tray access to Spiceworks - which "combines everything you need to manage IT in one easy-to-use application"
SpIDerMail
DrWeb antivirus Spider Mail e-mail scanner
Spinner Plus
"Spinner Plus lets you listen to over 100 channels of music broadcast from Spinner.com. Spinner Plus uses RealNetwork's G2 technology to provide high-quality online audio. The technology adjusts the audio streaming to match your Internet connection speed, which helps eliminate sound distortion or choppiness". Available via Start -> Programs
SPINX
Added by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "OXNEY.B.VBS" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
SPIRun
Related to Creative audio products. What does it do and is it required?
SPnt
Premium rate adult content dialler
SpokeSysTray
Spoke Software client application. Spoke "uses data in your e-mail and other enterprise information systems to discover the existing relationships of people in your enterprise. It then builds a private, secure relationship network for each user without any additional manual data entry"
spoo1sv
Added by the SOULJET TROJAN!
Spool
Added by the RANKY.R TROJAN!
Spool
WhileUSurf adware
SPOOL Configuration
Added by the SDBOT-KD WORM!
Spool Loader
Added by a variant of the RBOT WORM!
Spool LoadKIt
Added by a variant of the RBOT WORM!
Spool lptt01
RapidBlaster variant (in a "spool" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
Spool Manager
Added by the BANKER-FR TROJAN!
Spool ml097e
RapidBlaster variant (in a "spool" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
Spool32
Added by the ASSASIN-F TROJAN!
spoolax
Added by the PERDA-D TROJAN!
Spooler Host
Detected by PCTools as the IRCBOT.BSQ TROJAN! See here
Spooler Service
Added by the JOINER.C1 TROJAN!
Spooler Subsystem
Added by the SDBOT-ABG TROJAN!
Spooler SubSystem App
Added by the POEBOT-J WORM!
Spooler SubSystem App
Added by the LINKBOT.M WORM!
Spooler SubSystem Application
Added by the DLOADER-NY TROJAN!
Spooler SubSystem Application
Added by the DLOADER-NY TROJAN!
Spooler SubSystem Application
Added by the DLOADER-NY TROJAN!
Spooler SubSystem Application
Added by the DLOADER-NY TROJAN!
Spooler SubSystem Application
Added by the DLOADER-NY TROJAN!
Spooler SubSystem Application
Added by the DLOADER-NY TROJAN!
Spooler SubSystem Application
Added by the DLOADER-NY TROJAN!
Spooler SubSystem Application
Added by the DLOADER-NY TROJAN!
Spooler Subsytem App
Added by the SDBOT-MM WORM!
SpoolerSubSystemProcess
Added by the EHKS.21 keylogger! Note - the "I" between "o" and "3" is a capital "i" not a lower case "L"
spoolms
Added by the LEGMIR-ARO TROJAN!
Spools Service Controller
Added by the KASSBOT-C WORM!
spoolserv
Added by the SDBOT-PN WORM!
SpoolService
Added by the AGOBOT-CS WORM!
spoolsrv.exe
Added by an unidentified WORM or TROJAN! Located in %System%
Spoolsv
Added by the CIADOOR.121 VIRUS! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%
spoolsv
Added by the SMALL-AW TROJAN!
spoolsv
Added by the DLOADER-FI TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "HELP" subfolder of the Winnt or Windows folder
spoolsv
Added by the FUJACKS-M WORM!
spoolsv
Added by the ZAPCHAS-EE TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%\Temp\spoolsv
spoolsv
Identified by Kaspersky antivirus as a variant of the QHOST.AES TROJAN!
spoolsv manager
Added by the ASSIRAL WORM!
spoolsv service
Added by the RBOT-AHP WORM!
SPOOLSV32
Added by the CWS-I or HAZIF-B TROJANS!
spoolsvc
Added by the DROPPER-AT TROJAN!
spoolsvr32
Added by the AGENT-AU TROJAN!
spoolsvr32
Added by a variant of the AGENT-AU TROJAN!
spoolsvs
Added by the SDBOT.EGQ WORM!
spoolsvs
Added by a variant of the IRCBOT BACKDOOR!
spoolsvs.exe
Added by the DLOADER-RK TROJAN!
SPOOLSVU
Added by the STARTPAGE.K hijacker
spoolsvv
Searchcentrix hijacker
Spoolvs
Added by the SDBOT.AUS WORM!
Spore
Added by the SPORE.A WORM!
Spore.b
Added by the SPORE.B WORM!
SPP
??
spp
IE search hijacker - changes the default search to http://www.hotsearchbox.com/ie/
sppbridge
Associated with an Anycom bluetooth wireless card on laptops - used for printing to portable printers for example. Is it required or can it be started manually?
SprintPort
Novatel wireless modem related. What does it do and is it required?
SpriteService
Sprite Backup is a backup application for Windows Mobile Pocket PC or Smartphone
Sproc32
Added by the SPROCIT TROJAN!
sprof
Detected by Kaspersky as the FRAUDLOAD.VATF TROJAN! See here
sprtcmd
Self-help support tool for a number of high-speed internet providers and computer suppliers such as Comcast, Qwest and Dell. Identifies and automatically fixes typical problems that may occur with your high-speed internet service. Provided by SupportSoft, Inc
Spruce - Auto Update
Rabio "Search Enhancer" adware variant
SPSTEALT
Smart Protector Pro - internet privacy tool that erases tracks, MRU lists, etc
spstore
Softprobe - program designed to provide managers with an analysis of an individuals computer use who are under their supervision. This program is NOT related to Winpup
Spy Blocker
SpyBlocker blocks the communications of spyware installed on a PC so spyware runs but can't exchange data with the server to which it should report. Ensuring spyware can't communicate is important, as you may find after using Ad-Aware that some applications containing spyware subsystems may not run correctly or at all
Spy Protector
Included in the full version of Security Task Manager, Spy Protector prevents keyboard and mouse monitoring, warns when the registry is changed and eliminates internet activity and work traces
Spy-Control
Spy-Control spyware remover - not recommended, see here
Spy-Keylogger
SpyKeylogger keystroke logger/monitoring program - remove unless you installed it yourself!
SpyAway
SpyAway spyware remover - not recommended, see here
SpyAxe
SpyAxe spyware remover - not recommended, see here. For removal instructions see here
SpyBan
SpyBan spyware remover - not recommended, see here
SpyBlast
Spyware killer that is in effect autoinstalled foistware, targeted by SpyBot, among others
SpyBlocker
SpyBlocker blocks the communications of spyware installed on a PC so spyware runs but can't exchange data with the server to which it should report. Ensuring spyware can't communicate is important, as you may find after using Ad-Aware that some applications containing spyware subsystems may not run correctly or at all
SpyBlocs
SpyBlocs spyware remover - not recommended, see here
SpyBlocs3.0
SpyBlocs spyware remover - not recommended, see herea>
SpybotSD TeaTimer
TeaTimer is a permanent process and registry monitor of the Spybot S&D system protector which perpetually monitors the processes called/initiated. Detects processes wanting to start and gives you options on how to deal with this process in the future
SpyBotSnD
Spybot - Search & Destroy - free multi-spyware removal tool from Safer Networking Ltd.
Spybott lptt01
RapidBlaster variant (in a "Spybott" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
Spybott ml097e
RapidBlaster variant (in a "Spybott" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
SpyBurner
SpyBurner spyware remover - not recommended, see here
SpyClean
1 Click Spy Clean uses a database that was stolen from SpybotS&D. Not recommended, see here
SpyClean
SpyClean spyware remover - not recommended, see here
SpyCop ScanCheck
SpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan
SpyEmergency
SpyEmergency security software from Netgate
SpyEx
Added by the PRSKEY-A WORM!
SpyFighterMonitor
SpyFighter spyware remover - not recommended, see here
SpyFighterUpdate
SpyFighter spyware remover - not recommended, see here
SpyGuarder
SpyGuarder spyware remover - not recommended, see here
SpyHealer
Spyware remover - not recommended, see here
SpyHeals
Smitfraud variant
SpyHunter
Enigma SpyHunter - not recommended, see note
Spykiller
Spyware remover - older versions are not recommended, see here
SpyLax
SpyLax spyware remover - not recommended, see here
SpyLocked
SpyLocked spyware remover - not recommended, see here
SpyLocked 4.3
SpyLocked spyware remover - not recommended, see here
SpyMaxx
SpyMaxx spyware remover - not recommended, see here
SpyMedic
SpyMedic spyware remover - not recommended, see here
SpyNuker
A "spyware removal program" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers 'TrekData' and 'Blue Haven Media', who distribute spyware through ActiveX drive-by-download on web pages
SpyOnThis Monitor
SpyOnThis Monitor spyware remover - not recommended, see here
spyprodetector
Spyware Process Detector misleading security software - not recommended
SpyPry
SpyPry spyware remover - not recommended, see here
SpyQuake2.com
SpyQuake2 spyware remover - not recommended, see here
SpyRid
SpyRid spyware remover - not recommended, see here
SpySheriff
SpySheriff malware
SpyShredder
SpyShredder spyware remover - not recommended, see here
SpySpotter
SpySpotter spyware remover - not recommended, see here
SpySpotter System Defender
SpySpotter spyware remover - not recommended, see here
SpyStopper
SpyStopper - blocks intrusive spyware, Web bugs, worms, scripts, advertisements, and cookies. Protects you from being profiled and tracked
SpySubtract
SpySubtract - multi spyware removal tool
SpySweeper
Spy Sweeper - detects and removes spyware
SpySweeper
Spy Sweeper - detects and removes spyware
SpySweeperEnterprise
User interface for Spy Sweeper Enterprise edition - "a centrally managed, scalable enterprise solution that provides best of breed protection against all types of malicious spyware, adware, and other harmful intruders"
SpyTrooper
SpyTrooper - malware posing as a spyware remover, see here
Spyware
BPS spyware remover - not recommended, see here
Spyware Begone
Spyware BeGone - spyware removal utility. Previously not recommended, see here
Spyware Begone
Spyware BeGone - spyware removal utility. Previously not recommended, see here
Spyware Doctor
Spyware Doctor spyware remover
Spyware Doctor
Spyware Doctor spyware remover
Spyware Guard Control Panel
"SpywareGuard provides a real-time protection solution against spyware"
Spyware Nuker
Spyware removal program by TrekBlue. Previously not recommended but the latest version was delisted here
Spyware Nuker Installer
Spyware removal program by TrekBlue. Previously not recommended but the latest version was delisted here
Spyware remover
Unidentified, but not known to belong to any known spyware remover, and strongly suspected to be adware related!
Spyware Scanner
Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here and here
SpyWare Shield
Acronis Privacy Expert Spyware Shield prevents spyware and other suspicious programs from being installed on PCs
Spyware Slayer
Spyware Slayer spyware remover - not recommended, see here
Spyware Soft Stop
SoftStop misleading security software - not recommended, see here
Spyware Stormer
Spyware Stormer spyware remover - not recommended, see here
Spyware Striker Pro
Ascentive Spyware Striker Pro rogue spyware remover - not recommended, see here
Spyware Sweeper
SpywareSweeper spyware remover - not recommended, see here
Spyware Vanisher
Spyware Vanisher - spyware removal utility. Previously not recommended, see here
Spyware X-terminator
Spyware X-terminator - spyware remover
Spyware-Cop
Spyware-Cop spyware remover - not recommended, see here
SpywareBomb
SpywareBomb spyware remover - not recommended, see here
SpywareBot
SpywareBot spyware remover - not recommended, see here
spywarefighterguard
Spyware Fighter - anti spyware program
SpywareGuard
"SpywareGuard provides a real-time protection solution against spyware"
SpywareGuard
Startpage adware Trojan
SpywareGuard
Added by a variant of the Win32.Small TROJAN! - Do NOT confuse with the legitimate SpywareGuard application
Spywareguard lptt01
RapidBlaster variant (in a "Spyguard" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
Spywareguard ml097e
RapidBlaster variant (in a "Spyguard" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
SpywareGuardPlus
StartPage.ht homepage hijacker
spywareisolator
SpywareIsolator spyware remover - not recommended, see here
SpywareKilla
SpywareKilla spyware remover - not recommended, see here
SpywareLocked
SpywareLocked spyware remover - not recommended, see here
SpywareLocked 3.5
SpywareLocked spyware remover - not recommended, see here
SpywareNo
SpywareNo spyware remover - not recommended, see here
SpywareQuake
SpywareQuake spyware remover - not recommended, see here
SpywareRemover
SpywareRemover spyware remover - not recommended, see here
SpywareStrike
SpywareStrike spyware remover - not recommended, see here
SpywareSweeper
SpywareSweeper spyware remover - not recommended, see here
SpywareTerminator
Spyware Terminator - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here
SPYWATCH
BPS spyware remover - not recommended, see here
SpyWatchE
SpyWatchE spyware remover - not recommended, see here
SQConfigChecker
Xupiter SQWire toolbar related. Use Spybot S&D, Adware or similar to detect and remove and to prevent it re-installing in the future see here
SQInstaller
Xupiter SQWire toolbar related. Use Spybot S&D, Adware or similar to detect and remove and to prevent it re-installing in the future see here
SQL
Added by the PUNYA-B WORM!
SQL Server
SQL Server Service Control Manager. Available via Start -> Programs
SQL Server Service
Added by the RBOT-ADF
sqservices
Added by the PROGENT-B TROJAN!
SQUpdatesChecker
Xupiter SQWire toolbar related. Use Spybot S&D, Adware or similar to detect and remove and to prevent it re-installing in the future see here
sqvynikp
Free_Scratch_Cards foistware
SR Agent
Related to Secure Resolutions - desktop virus protection
Sr Agent
Related to Secure Resolutions - desktop virus protection
sr1exe
Found on a Dell computer, in a Documents and SettingsAll UsersApplication DataDellAlert2 subfolder
sr64
Added by the AGENT.X TROJAN!
SrchfstUpdate
SearchFast adware downloader
sre
CoolWebSearch parasite variant - also detected by Kaspersky as the AGENT.FC TROJAN!
srePostpone
Related to ZoneAlarm. What does it do and is it required?
SRFirstRun
Created by execution of the Windows XP sr.inf file, which installs the Windows XP System Restore feature, needed for example when installing System Restore into Windows Server 2003. Does this indeed need to run at every bootup?
Srmclean
Srmclean helps in the installation and execution of the SoundMax SoftPaq for Compaq/ADI SoundMax Integrated Digital Audio. According to Compaq - "If you disable the entry from loading into startup, then you will not be able to use the features of the sound card"
SRNG
ShopNavSearch.Srng search hijacker
SRP Startup
System Restore Remover Pro allows you to safely and easily remove System Restore and various other Windows Millennium "features". This is enabled if you tick the "Remove unnecessary System Restore information on startup" box. Available via Start -> Settings -> Control Panel
SRS Applet
S3 Sonic Vibes sound card drivers - if disabled you loose sound
SRS Audio Sandbox
SRS Audio Sandbox "provide amazing audio immersion and maximum thump for a personalized audio experience!"
srshost.exe
Added by a variant of the RBOT-ASW WORM!
SRUUninstall
Symantec Network Driver Update - part of LiveUpdate
Srv Host
Added by a variant of the IRCBOT BACKDOOR! See here
Srv RPCrom
Added by the WATSOON.A TROJAN!
Srv32
Added by the OPASERV.J WORM!
Srv32
Added by the OPASERV.S WORM!
Srv32 spool service
Topantispyware.com malware - detected by Kaspersky as the SPYRE.B TROJAN!
Srv32 spool service
Added by the SPYRE.B TROJAN!
Srv32 spool service
Added by the DLOADER-LB TROJAN!
Srv325
Added by the AGOBOT-PR WORM!
Srv32Old
Added by the OPASERV.J WORM!
Srv32Win
SpyAgent - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it
Srv32Win
Realtime-Spy keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the svchost.exe process that normally doesn't appear in Msconfig/Startup!
Srv32Win
SpyAgent surveillance software. Uninstall this software unless you put it there yourself
srv32win
Screenspy captures screenshots silently. If you didn't install this yourself remove it
Srvce Pack Updte
Added by a variant of the RBOT WORM!
srvexc.exe
Added by the SERVSAX TROJAN!
srvprc
ActMon surveillance software. Uninstall this software unless you put it there yourself
srxTray
Titan FTP Server - FTP server
SsAAD.exe
Sony's SonicStage digital music manager for their range of MP3 players. It monitors your HDD for newly added music tracks and automatically offers to add them to your playlist when you connect your player
ssate.exe
Added by the BEAGLE.J WORM!
ssate.exe
Added by the BEAGLE.K WORM!
SSBkgdUpdate
ScanSoft OmniPage auto updater. Can be disabled using the main program's options. Note - if you have a Soundblaster Audigy2 ZS soundcard installed on your computer and the volume of your soundsystem is turned on extremely high disabling this will solve the problem
SSC Service Utility
SSC Service Utility is a printer utility for refilled Epson cartridges
SSCFBTN.EXE
Samsung smarthru software,used with Lexmark Z82 or Samsung multifunction printers
sscRun
AOL's firewall
SSC_UserPrompt
Part of Symantec's AntiVirus suite and comes usually with a product update, if not on the system already. Required for essential applications to work properly
Ssd
Stealthdisk - file and folder hiding/locking utility
ssdiag
Equinox (now Avocent) "Configuration and DOS Diagnostic for DOS and Windows platforms"
SSDPSRV
Simple Service Discovery Protocol (SSDP) and General Event Notification Architecture (GENA) services for network plug and play functionality. Starts up a web server on port 5000. Used by Universal Plug and Play (for network device discovery). To remove this program, open Add/Remove Programs, select either Communications (Me) or Networking Services (XP), and remove the checkmark next to Universal Plug and Play
ssgrate.exe
Added by the MITGLIEDER.C TROJAN!
ssgrate.exe
Added by the MITGLIEDER.D TROJAN!
ssgrate.exe
Added by the MITGLIEDER.F TROJAN!
ssgrate.exe
Added by the MITGLIEDER.N TROJAN!
ssgrate.exe
Added by the MITGLIEDER.O TROJAN!
ssgrate.exe
Added by the BAGLEDL-J TROJAN!
ssgrate.exe
Added by the MITGLIEDER.Q TROJAN!
SSh32
2Spy keystroke logger/monitoring program - remove unless you installed it yourself!
SSK Service
Added by the SOBIG.E WORM!
SSL
Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
SSL Manager
Added by a variant of the SDBOT WORM!
SSLDyn
FRETHOG.MM spyware
ssmmgr
Samsung printer monitor - for checking ink levels, etc.
ssms.exe
Added by the GISMOR WORM!
SSPY
SurfingSpy keystroke logger/monitoring program - remove unless you installed it yourself!
SSS7
Steganos Security Suite 7 - "A comprehensive collection of methods to prevent your data falling into the wrong hands, and highly recommended if you have anything you feel you need to hide"
sssasasb32
Added by the TACTSLAY.F TROJAN!
sssasasb32
Added by the TACTSLAY.F TROJAN!
sstata
Added by the DASDA TROJAN!
sstata
Added by the RANCK-DF TROJAN!
SStb.exe
Adpowerzone.com "ServerSide" keyword hijacker
sstray
nVidia nForce Taskbar Utility - quick access to the nForce2 "Sound Storm" control panel and related utilitys
SSUpdate
MoneyTree parasite - ActiveX control used to download premium-rate dialers
ssvchost
Added by the HELIOS.B TROJAN!
SSWPlauncher
Comet Cursor adware
Stacmon
Installed with the drivers for a SigmaTel C-Major Audio card (on a Dell Inspiron 600m PC for example). Appears as though it can be disabled with no ill effects
StacSysTray
System Tray control panel for SigmaTel C-Major on-board audio - as used on some Dell and Packard Bell PCs
staeck12
Added by an unidentified WORM or TROJAN!
staeck122
Added by an unidentified WORM or TROJAN!
standalone.exe
Added by the AGOBOT-ADS WORM!
Stardock ObjectDock
Stardock ObjectDock is a program that enables users to organize their shortcuts, programs and running tasks into an attractive and fun animated Dock
StarSkin
StarSkin allows you to change the view and appearance of your Windows XP box with the use of publically available themes
Start
For a Nisis G6 USB Graphics Tablet. Re-enables itself if disabled therefore best left alone
Start
Homepage hijacker
start
??
start
Added by the AGENT.CSX TROJAN!
start
Online Video Add-on - masquerades as a helper application for watching videos. In reality, though, it installs a rogue anti-spyware, or SmitFraud, application on your computer
start
Netproject malware
Start aThx Roll
Added by the RBOT.AAV WORM!
Start CurePCSolution
CurePCSolution spyware remover - not recommended, see here
start extracting
Added by the RBOT-XF WORM!
start extracting
Added by the RBOT.BAN WORM!
start extracting
Detected by Kaspersky as the RBOT.FO BACKDOOR! See here. Note - this is not a valid McAfee program and is located in %System%
Start Getright
See Getright Tray Icon
Start It Upping
Added by a variant of the RBOT WORM!
Start Network Scanner Tool
Part of Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents"
Start Page
Naupoint browser hijacker
Start Page
Homepage hijacker, also detected as Trojan-Downloader.Win32.Delf.ks
Start RF Wireless Keyboard
Yuanxun Electronics RF wireless keyboard driver
Start RF Wireless Mouse
Yuanxun Electronics RF wireless mouse driver
Start Service
Cyber Power PowerPanelPlus software. "During a power failure the system automatically saves and closes open files within the battery backup time and safely powers down your computer"
Start Up Cop
StartUp Cop - startup manager
start uploading
Added by a variant of the SDBOT WORM!
Start Upping
Added by the RBOT-MA WORM!
Start Upping
Added by the RBOT-NB WORM!
Start Upping
Added by the RBOT-QK WORM!
Start Upping
Added by a variant of the SPYBOT WORM!
Start Upping
Added by the SDBOT.AFH WORM!
Start Upping
Added by a variant of the RBOT WORM!
Start Upping
Added by the SPYBOT.OY WORM!
Start Upping
Added by the RBOT-TM WORM!
Start Uppings
Added by the SDBOT.VY WORM!
Start Uppings
Added by a variant of the RBOT WORM!
Start Wingman Profiler
Logitech Wingman software required to operate Logitech joysticks and gamepads. Unless you're a hard-core gamer, it's best to leave it unchecked
Start Wingman Profiler
Logitech Wingman software required to operate Logitech joysticks and gamepads. Unless you're a hard-core gamer, it's best to leave it unchecked
Startacc
Launches Webroot's Accelerate 2000 software that "speeds up your Internet connection by up to 300%". Leave enabled if you find it improves internet connection
StartCCC
Puts the ATI Catalyst™ Control Center Icon/Shortcut on the System Tray - available via Start → Programs
startdrv
Added by the DROPRK-A TROJAN!
StartEAK
Easy Access Button Support for Compaq PCs. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keys
startemdoit
Added by the DLOADR-AVP TROJAN!
Starter
Added by the SDBOT.RU WORM!
starter
Added by the FORBOT-FB WORM!
starter
Added by the FORBOT-DU WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%
StartFoxie
Foxie Suite from Softonic International. "This suite of free tools comes in the form of an Internet Explorer add-on and includes a mix of powerful security enhancements"
startkey
Added by the HIPPER-B TROJAN!
startkey
Added by the BIFROSE-DG TROJAN!
startkey
Added by the BIFROSE-AO TROJAN!
startkey
Added by the MT TROJAN!
startkey
Added by the BIFROSE-HM TROJAN!
StartKey
Added by the BIFROSE.E TROJAN!
startkey
Added by a variant of the BIFROSE-LV TROJAN!
startkey
Added by the CEP TROJAN!
startkey
Added by the BCKDR-MLD BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
startkey
Added by the BIFROSE-OK TROJAN!
startkey
Added by the BIFROSE-S TROJAN!
startkey
Added by a variant of the SDBOT WORM!
startkey
Added by the EDEPOL-C TROJAN!
startkey
Added by the BIFROSE-PM TROJAN!
startkey
Added by the BIFROSE-DB TROJAN!
startkey
Added by the BIFROSE-R TROJAN!
startkey
Added by the BIFROSE-OY TROJAN!
startkey
Added by a variant of the SDBOT WORM!
startkey
Added by the BIFROSE-PM TROJAN!
startkey
Added by the BIFROSE-TO TROJAN!
startkey
Added by the AGENT-FPL TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
startl.exe
Lingocom LingoWare - translates any application into your language
StartMenu
Added by the TACTSLAY.C TROJAN!
StartMenu
Added by the TACTSLAY.C TROJAN!
StartMenu
Added by the TACTSLAY.C TROJAN!
StartMenu
Added by the DROWSY-C TROJAN!
startpage
Browser hijacker - redirecting to pages2start.com
STARTPAGE
NoSpy.org - prevents spyware from changing your startpage and other browser properties. The start1.exe file is located in a NOSPY.ORG folder
StartSecurDoc
SecurDoc from WinMagic Inc - "Provides full disk encryption to protect sensitive information stored on laptops, desktops and PDAs"
StartStop
StartStop from TFI Technology - startup manager
StartSurfing
Start Surfing allows you to protect your privacy while surfing and searching the Internet by acting as a "filter" between you and the website you are visiting. Startsurfing acts as your shield from Pop Up Windows, Mouse Traps, Window Resizing, and scripts that attempt to record your personal information. Available via Start -> Programs
Startup
Related to an Iomega drive
Startup
Unidentified malware
Startup
Added by the FLOOD-EU TROJAN! An uninstall option for mirc.exe can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as mIRC. This one puts 10 files in the Windows or Winnt folder
Startup Configuration
Added by the RBOT-ARV WORM!
Startup Configuration
Added by the RBOT-ASD WORM!
Startup Launcher GUI
Startup manager?
Startup Manager Scanner
Startup-Mechanic Startup monitor - offers boot protection of your PC from harmful trojans, adult-dialers, and other scumware
Startup Scan
AntiVirus Quick Heal - scheduling agent
Startup Update
Added by the GAOBOT.AO WORM!
StartupBin
Added by the SDBOT-XZ WORM!
StartupMonitor
Mike Lin's StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu
startwin
Added by the ANTIMAN.A WORM!
startwindowskeyuser
Added by the JAVAKILLER TROJAN!
Stat 'n' Perf
Stat 'n' Perf monitors your internet connection and displays information about sent and received bytes
StatBar
StatBar (system status bar) allows you to quickly get an overview of your system's condition (memory, CPU, uptime, and much more). Due to the sheer number of resources (over 60%) consumed by this program, it is unsuitable for Windows 9x/Me
State Service
Added by the DADOBRA-CP TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
StationPlaylistStudio
StationPlaylist Studio - "simple to use on-air broadcast playback software for the studio and/or DJ" for small to medium sized radio broadcasters, and internet webcasters
Statistics
Added by the OPANKI-S WORM!
Status Monitor
Brother scanner status monitor - can be started manually
Status Monitor CLJ1500
Status monitor for the HP Color LaserJet 1500 printer from Hewlett-Packard - for monitoring printer status, checking ink levels, etc
Status Monitor XE
The Xerox Document WorkCentre XE Series Status Monitor displays information about your printer and currently active or waiting print jobs. You can use it to control your printing environment and manage your printing operations. Available via Start -> Programs
StatusClient
Part of Hewlett Packard network printer drivers
StatusClient 2.6
Part of Hewlett Packard network printer drivers
StatusView
Status View intra-office messaging
Stay Connected!
More than just a pinger, actually simulates online activity. Supports AOL, NetZero, MSN, ATT WorldNet, CompuServe and many other ISPs as well. Available via Start -> Programs
StayAlive
Part of RealSPEED - tweaking utility to speed-up your internet connection. Stay connected even after a period of inactivity on the net
StayAlive
StayAlive from TFI Technology. "This top-notch tool intercepts crashes when they happen, keeping your programs running so you can save your work."
STBVision
Related to the STB Velocity graphics card. What does it do and is it required?
STBWEBTV
Used to display TV on your PC
stcinstaller
Added by the SCTHOUGHT.L TROJAN!
stcloader
Popup adware by 2ndThought software
stcloader
Popup adware by 2ndThought software
STCLOA~1
Popup adware by 2ndThought software
STCLOA~1
Popup adware by 2ndThought software
STCPO
Sophos Sweep antivirus software
StdAFX
Added by the DELBOT-AF WORM!
stdlib
Added by the PERDA-E TROJAN!
STDSB
Scrollbar driver for notebooks. If taken out of the Startup, it will not provide scrolling
Stealth Anonymizer 2.5
Now named Stealther - proxy server agent that lets you travel the Internet with maximum possible privacy
stealth.dcom.exe
Added by the THEALS.A WORM!
stealth.ddos.exe
Added by the THEALS.A WORM!
stealth.exe
Added by the THEALS.A WORM!
stealth.injector.exe
Added by the THEALS.A WORM!
stealth.stat.exe
Added by the THEALS.A WORM!
stealth.wm.exe
Added by the THEALS.A WORM!
stealth.worm.exe
Added by the THEALS.A WORM!
Steam
Valve Software's STEAM broadband game client. Steam is Valve's new way of getting games into your hands ASAP. Games like Half-Life, Counter-Strike, and Counter-Strike: Condition Zero are all being made available through Steam. Steam games are automatically kept up-to-date with the latest content and revisions. Steam also includes an instant-message client which even works while you're in-game
steam
Added by the RBOT-AJT WORM! Note - the file steam.exe will be found in the WindowsSystem folder and is not associated with Valve Software's game client
SteFanie
Added by the STEFAN WORM! Note - make sure you check the hyperlink as this one copies it's self to numerous dirves and folders
stgclean
Related to IBM Standard Software Installer. What does it do and is it required?
Stickies
Stickies - "lets you put yellow sticky notes on your Windows desktop, much like the popular Mac OS application. It is very simple, very customizable, and completely free!". Available via Start → Programs
Sticky Notes
Microsoft Sticky Notes - virtual sticky notes tool
Sticky Pad
Sticky Pad from Green Eclipse. Place sticky notes on your desktop
StickyNote
Utility that allows you to put yellow "Post-It" type messages on your desktop. Available via Start -> Programs
StillImageMonitor
Stimon.exe enables a USB still-image device (such as a scanner) to initiate data transfer to a program. For example, if your scanning device has a scan button, it may start a program and begin scanning when you press it. Create a shortcut and start it manually when needed if your scanner otherwise fails to scan. May be required for your USB scanner to work - including all HP scanners and some of their SCSI scanners
stisrv
Added by the RBOT.BQF WORM!
stlbdist
Hijacker pointing to www.searchandclick.com
stlbupdt
BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
STManager
Dr. SpeedTouch is some sort of diagnostics software which sends out information to a server which then relays the information back to the program to test the network to see if the SpeedTouch ADSL modem connection is working properly. Not required if connected via Ethernet (and probably USB). Can cause a slow down in Win2K - see here
stmha
Added by the SPETH WORM!
stonedrv
Added by the COSIMA-K TROJAN!
StopSignSsTsMon
eAcceleration Stop-Sign security software related. Previously not recommended, see here
StopSignStatus
eAcceleration Stop-Sign security software related. Previously not recommended, see here
STOPzilla
StopZilla! - pop-up killer
STOPzilla Service
StopZilla! - pop-up killer
StorageGuard
StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups
StorageProtector
StorageProtector misleading security software - not recommended, see here
StormCodec_Helper
Storm Codec is a codec pack for Windows
STPMGR
Part of SafeTP which is transparent FTP security software. Does it need to be running permanently or can it be started manually via Start -> Programs
stratas
Added by the RBOT-AHR WORM!
stratas
Added by the SDBOT-ADD WORM!
Stratas
Added by the OPANKI.W WORM!
StreamAppliance
Added by the RBOT-GMB WORM!
StreamAppliance
Added by the RBOT-GME WORM!
Streamload Downloader
Downloader for MediaMax (was Streamload) - "gives you a private and secure place to upload, store, access, and share your personal videos, photos, movies, music, and files"
Streamload Uploader
Uploader for MediaMax (was Streamload) - "gives you a private and secure place to upload, store, access, and share your personal videos, photos, movies, music, and files"
Streams Drivers
Detected by Trend Micro as the RESTARTER.E TROJAN! See here
StreamZap Remote
StreamZap PC Remote - control Windows Media Player, iTunes, RealPlayer, Winamp, PowerPoint, MusicMatch Jukebox, and many other multimedia applications
StrgSync.exe
SimpleTech Inc's StorageSync backup software - backs up an entire PC, or selected files and folders
strkjhk
Added by an unidentified WORM or TROJAN - see here
strmsnmgrs
Added by the SDBOT.JDR WORM!
strmsnmsgr
Added by the RBOT-ACQ WORM!
strmsnmsgrs
Added by a variant of the RBOT WORM!
strmsnnms
Added by the SDBOT-YU TROJAN!
strmsnnrs
Added by the RBOT-ACT TROJAN!
strmsoums
Added by the SDBOT-ZK TROJAN!
Strng32
Added by the STRANO WORM!
StrokeIt
StrokeIt is an "advanced mouse gesture recognition engine and command processor"
strtas
Added by the SDBOT-ADQ WORM!
strtas
Added by the SDBOT-AEB WORM!
strtas
Added by the AGENT-II TROJAN!
strtas
Added by the RBOT-AZU TROJAN!
strto
Added by the KILLPROC-F TROJAN!
strto
Added by the KILLAV-AP TROJAN!
Sts
Added by the SDBOT-YI WORM!
Stubbish
Added by the STUBBOT-A WORM!
StubPath
Added by the PRORAT TROJAN!
stup
Added by the FIRESPY-A TROJAN! It will attempt to register the dropped component as a Firefox plugin and begin monitoring the user's browsing habits, stealing information including monitoring and logging information from Web forms
stup1db0t
Added by a variant of the IRCBOT BACKDOOR!
StupAssist
Associated with Nikon digital cameras
STV
Added by a variant of the SDBOT WORM!
stxrmsgms
Added by the IRCBOT-AE TROJAN!
StyleXP
StyleXP allows you customize the way WinXP looks. If disabled via msconfig it re-instates itself at reboot, therefore uninstall it if you don't want it
SubAH
Added by the SUBAH TROJAN!
Subliminal Power
Subliminal Power - displays subliminal messages of your choice on your computer screen
Subtract the Ads
Removes adverts from web pages. Although useful - not required
suck
PurityScan/Clickspring adware
Suitcase Startup
Suitcase - system font manager start up utility. Used for dynamic managment of fonts on your system
Suite
Added by the LAZAR TROJAN!
SULFNBJ.EXE
Added by the PE_MAGISTR.DAM VIRUS!
Sun Java Console for Windows NT & XP
Added by the VANEBOT-C WORM!
Sunasdtserv
CounterSpy by Sunbelt Software - adware/spyware protection
sunasServ
CounterSpy by Sunbelt Software - adware/spyware protection
Sunjava
Added by the AGENT.AHV TROJAN!
SunJavaSched
Added by the SDBOT-YP WORM!
SunJavaSched Updater
Added by the RBOT-ABJ WORM!
SunJavaUpdate
Added by the DEDLER-G TROJAN!
SunJavaUpdateSched
Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now
SunJavaUpdateSched
Added by the SDBOT-AVX WORM!
SunJavaUpdateSched
Added by the SDBOT-WI WORM!
Sunkist
Card reader for memory cards from digital cameras, etc
Sunkist2k
Card reader for memory cards from digital cameras, etc
SunKistEM
Used by your computer to communicate with your Alcor Micro Multimedia Card Reader - necessary if you're using this software
SuNotification
ShadowSurfer - "provides a safe computing environment by creating a virtual twin of your PC. Restore the pre-ShadowMode system state no matter what changes have occurred to your PC"
SunProtectionServer
CounterSpy antispyware software
SunServer
CounterSpy antispyware software
SupaDial
SupaNet.com modem driver related - is it required?
Supastatus
Supanet ISP software
supdate
Added by the MALWARE.D TROJAN!
supdate2.dll
Added by the ZLOB-VL TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "supdate2.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
super
Added by the LINEAGE-H TROJAN!
super
Added by the AGOBOT-QT WORM!
Super Popup Blocker
Saga Super Popup Blocker - pop-up stopper
Super X Desktop Version 3.4
Super X Desktop - virtual desktop manager
SuperAdBlocker
SuperAdBlocker
SUPERAntiSpyware
"SUPERAntiSpyware is the most thorough scanner on the market. Our Multi-Dimensional Scanning and Process Interrogation Technology will detect spyware that other products miss! SUPERAntiSpyware will remove ALL the Spyware, NOT just the easy ones!"
SuperBar.Component
Added by the SMALL-AQ TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in an "Inetsrv" subfolder
SuperBar.Component
FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in an "Inetsrv" subfolder
Supercleaner
Supercleaner - all in one disk cleaner for your computer
SuperCool Compress Backup
"SuperCool Zip Backup software is a data backup,restore and file synchronization program"
SuperHeissSex
Added by the HeissSex premium rate adult content dialer!
supernews12
Adware, also detected as the DLOADER-JN TROJAN!
Supernova
Added by the SURNOVA (or SUPOVA) WORM!
superproxy
Added by the DELBACK-B TROJAN!
SuperRam
SuperRam memory manager. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See SuperRam article and make up your own mind
superslut
Added by the SLUTER-A WORM!
SuperSpamKiller Pro
SuperSpamKiller Pro email spam blocker
Supervisor.exe
Has been reported to be associated with various antitrojan software like ATS and PC Doorguard. If so it's required in Startup - any further information is welcome
support-reverse-smileys
Added by the LITEBOT TROJAN!
supporter5
Part of eScorcher anti-virus software- responsible for updates of new virus bases each time you logon to the web. Used to collect information about the user and therefore treated as spyware - now the web-site is dead
SureCleanProfessional
SureClean PC and Internet tracks cleaner
Sureshotpopupkiller
Stop-the-Pop-Up popup blocker
Sureshotpopupkiller
Stop-the-Pop-Up popup blocker
SurfAccuracy
SurfAccuracy adware
SurfBuddy
SurfBuddy adware - not to be confused with the legitimate SurfBuddy application by SurfApps!. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
SurfChoice
SCMan is a utility that can control services on WinNT from the command line. This utility can create, start, pause, stop, delete services. Furthermore it can retrieve a service's current state, get the displayname for a service and vice versa
Surfer lptt01
RapidBlaster variant (in a "mssurfer" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
Surfer ml097e
RapidBlaster variant (in a "mssurfer" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
SurfHelper
Related to SurfHelper - a free tool to remove popup windows, clear history, control window properties of IE, and more
SurfinGuard Pro
SurfinGuard Pro from Finjan - internet protection software, protects against all malicious code delivered through executables, scripting files, ActiveX and Java
SurfSecret
"House-cleaning utility that enables you to keep your computer usage to yourself. Runs quietly from the system tray, eliminating tell-tale files at a regular interval of your choosing. You can set it to clear your Internet cache files, cookies, history, temp folder, etc. It can also clear the history of your Run and Find menus, in addition to the AOL cache"
SurfSideKick 2
SurfSideKick adware
SurfSideKick 3
SurfSideKick adware
SurfStream
Conceiva "SurfStream lets you surf the Web faster. It contains a fully featured proxy server that lets you surf the Web significantly faster. It also blocks all pop-up windows and banner ads from Web pages. An intelligent tune-up tool automatically analyzes and optimizes your computer's Internet connection and TCP/IP settings"
Surs
PurityScan/Clickspring adware
Surveysa
Found on Sony laptops, it brings up a prompt to take a survey. It goes away if you fill out the survey or you choose "never prompt me again" but keeps popping if you either exit out of it or select "take survey later"
suScheduler
Related to Lenovo ThinkVantage Technologies. ThinkVantage Technologies help make ThinkPad/ThinkCentre PCs less dependent on IT staff
Susp
VX2.Transponder parasite updater/installer related
susse
LinkMaker adware
Sustem
Added by an unidentified VIRUS, WORM or TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!
SustemUpdate
Added by an unidentified VIRUS, WORM or TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!
SV00LSV
Added by the GRAYBIRD-C TROJAN!
SVA Player
QuickFlicks Streaming Player malware
Svc
ClientMan parasite variant
SVC
ElfSpy keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the svchost.exe process that normally doesn't appear in Msconfig/Startup!
svc
Added by the PWS-ANG TROJAN!
SVC Service
Added by the SINIT TROJAN!
SVC Service
CoolWebSearch parasite variant
SVC Service
CoolWebSearch Svcinit parasite variant
SVC Service
Added by the RBOT-ASC WORM!
SVC Socks
CoolWebSearch parasite variant
svc32
Identified as a variant of the Banker-EQC/DLoader.GPJI malware
Svced
Added by the DELF.F TROJAN!
SvcH0st
Added by the BACKDOOR-CGZ TROJAN!
SvcH0st
Added by the EB TROJAN!
SvcH0st
Added by the EB TROJAN!
SvcH0st
Added by the EB TROJAN!
SVCH0ST
Added by the HF TROJAN!
SVCH0ST
Added by the IK TROJAN! Note - the filename has the digit 0 rather then the uppercase "o"
SvcH0st
Added by the TACTSLAY.B TROJAN!
SvcH0st
Added by the TACTSLAY.B TROJAN!
SVCH0TS
Added by the LINEAGE-AZ TROJAN!
svchast
Added by the LINEAGE-AV TROJAN!
svchctrl
Added by the COBFINN TROJAN!
svchos
Added by the EZIBOT-B TROJAN!
svchosd
Added by the BANCOS-BCX TROJAN!
SVCHOSI
Added by the VBBOT-AA WORM!
SVCHOST
System1060 homepage hi-jacker. Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "System1060" subfolder of the Winnt or Windows folder
svchost
Added by many TROJANS amd WORMS, such as MORB or TARNO. Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!
SVCHOST
Added by the GOTORM WORM!
svchost
Added by the GRAYBIRD and GRAYBIRD.B TROJANS! Note - the filename has the digit 0 rather then the uppercase "o"
svchost
Added by the HAZZER TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
svchost
Added by the SMIBAG WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Svchost
Added by the LOLAWEB.A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Svchost
Added by the MOZE-A WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder
SVCHOST
Added by the LDPINCH.C TROJAN!
Svchost
Added by the INZAE.A or INZAE.B WORMS!
svchost
Added by the SETCLO WORM!
SVCHOST
Added by the MYTOB.E or MYTOB.G WORMS!
SVCHOST
Added by the MYTOB.F or MYTOB.H WORMS!
svchost
Added by the BOOKMARKER.G TROJAN!
SVCHOST
Added by the RANTS.A WORM!
SVCHOST
Added by the BAITAP-A WORM! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%
SvcHost
Added by the AGOBOT-TM WORM!
svchost
Added by the BANCBAN-HL TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "config" subfolder of the Winnt or Windows folder
svchost
Added by the UNREAL-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!
svchost
Added by the STARTPA-PB TROJAN!
Svchost
Added by the ADCLICK-AX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Program FilesInternet Explorer folder
svchost
Added by the ES TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "Microsoft" subfolder
svchost
Added by the DLOADER-EV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "Arquivos de programas" folder
svchost
Added by the GAOBOT.GEN!POLY WORM!
SVCHOST
Added by the LCJUMP-A WORM! Note - this is not the valid Machine Debug Manager which shares the same filename
Svchost
Added by the RBOT.ADK WORM!
svchost
Constructor VC2000 malware
svchost
Added by the ODELUD WORM!
SVCHOST
Added by the STARTP-G TROJAN!
svchost connection monitor
Added by a variant of the SDBOT WORM!
SVCHOST Generic application
Added by the DAEMONI-K TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder
svchost Netware Manager
Added by the EXVID.A WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
SVCHost Protocol32
Added by a variant of the IRCBOT TROJAN!
Svchost Service
Added by the VB-DVQ WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Help subfolder of the Winnt or Windows folder
Svchost Windows Remote Services
Added by the IRCBOT-IV WORM!
svchost.exe
CoolWebSearch Svchost32 parasite variant
SVCHOST.EXE
Added by the WRMSCAN-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder
svchost.exe
Added by the BANKER-MO TROJAN!
svchost.exe
Added by the ZAPCHAS-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "drivers" subfolder
svchost.exe
Added by the SADELPHI-A TROJAN!
svchost1
Added by the AGOBOT.ZZ WORM!
SvcHost32
Added by the MIMAIL.I or MIMAIL.J WORMS!
svchost32.exe
Added by the ASSASIN.20B BACKDOOR!
svchost64
Added by the SDBOTER.G VIRUS!
svchosta
Added by the SNIFFER-I TROJAN!
svchostb
Added by the SNIFFER-J TROJAN!
SvcHostDHCP
Added by the ASSASIN.20B BACKDOOR!
svchostdll.scr
Added by the BANCBAN-FM TROJAN!
SvcHosto
Added by the AGOBOT-TK WORM!
svchostr
Added by an unidentified WORM or TROJAN!
svchosts
Added by the BANCBAN-DC or BANKER-ED TROJANS!
svchosts.exe
Added by the AGOBOT-JN WORM!
svchosts.scr
Added by the BANCBAN-DQ TROJAN and variants!
SVCHOT
Added by the QQROB-U TROJAN!
svchst
Added by the KBROY-C TROJAN!
svcinfo
Added by the CRYPTER.A TROJAN!
Svclhost
Added by an unidentified WORM or TROJAN!
SvcManager
Added by the AGENT-DSS TROJAN!
SvcManager
Added by an unidentified WORM or TROJAN!
svcmon
PersonInspect surveillance software. Uninstall this software unless you put it there yourself
Svconr
WaveRevenue-lBann adware
svcroot
Added by the KEYLOG-AC TROJAN!
svcshare
Added by the FUJACKS-J VIRUS!
svcshare
Added by the FUJACKS-A VIRUS!
svcshare
Added by the FUJACKS-AJ WORM!
svcshare
Added by the FUJACKS-Z WORM!
SvcSys
Added by the BANCOS.Z TROJAN!
Svcsys Registry Manager
Detected by Kaspersky as the AGENT.CV TROJAN!
svcsys32
Added by the AGOBOT-LL WORM!
svctask
Added by the CHUCKYB-A TROJAN!
svcwinprocess32
Added by the UPERING WORM!
SVGA Adapter
Added by a variant of the SPYBOT WORM! See here
svhcost
OpenSearch adware
svhoost
Added by a downloader TROJAN of Chinese origin!
SVHOST
Added by the MYDOOM.I WORM!
SVHOST
Added by the ZORI.A VIRUS!
Svhost Loader
Added by the AGOBOT.G WORM!
svhost updates
Added by a variant of the RBOT WORM!
svhost windows services
Added by the RBOT-WQ WORM!
SVIDC32M
??
sVideo2
"Switch-D" premium rate adult content dialler
sviload32
Added by the RBOT-AAS WORM!
SVM Pop
??
svnlitup32
Added by the RBOT.CBJ WORM!
svnloader
Added by the RBOT-ACU WORM!
svphost.exe
Added by the AGENT.CS TROJAN!
SVPWUTIL
Part of Toshiba Hardware Setup
svrrun
Adware hailing from Deskwizz.com
svsekin
Added by the QQPASS.G TROJAN!
svshost
Added by the CHODE-H WORM!
svshost
Added by the LOONY-G TROJAN!
Svshost Update Service
Added by the MYTOB.LH WORM!
svshost32
Added by the RANKY.AJ TROJAN!
svshost32
Added by a variant of the SDBOT WORM!
svshostdriver
Added by the SDBOT-HN TROJAN!
svtcin
Added by the N20050308 TROJAN!
svwin32
Added by the AGOBOT-NF WORM!
SVX Control Service
Added by the FORBOT-K WORM!
SW20
Related to MSI's Dynamic Overclocking Technology
SW24
Related to MSI's Dynamic Overclocking Technology
Swap Nut
javaw.exe can be loaded by other programs at startup but in this instance it's SwapNut, a peer-to-peer file sharing and searching utility developed and marketed by File Metrics, Inc. Users can search for and find almost any type of digital file (audio, video, photos etc.) through a secure peer-to-peer network
SWCaller
Swporta homepage hijacker
SWCaller
Swporta homepage hijacker
Swchost
Added by the MP TROJAN!
SWClient
ActivMonAgent keyboard logger/monitoring program - remove unless you installed it yourself
swcroot
Added by the SOLENO-A TROJAN!
SWd
PC Security from Tropical Software - lock files, password protect, etc
Sweep95
Part of Sophos ant-virus sofware
SweetIM
vSweetIM - send fancier smiley-faces and IM graphics to friends who are using MSN Messenger. They are only able to see these advanced smiley-faces if they also have SweetIM installed
Swf32
Added by the MERKUR.E WORM!
Swf32
Added by the SYMTEN WORM!
swg
Companion to the Google Toolbar that lets you keep Google as your default search engine and prevents this setting from being changed without your consent. Shouldn't remain in memory after the feature is disabled as it's a bug - see here
SwimSuitNetwork
Advertising spyware
swingsys
Added by the BANCOS-CX TROJAN!
Switch Off
Switch Off - tray-based system utility that can automatically perform various frequently used operations like shutdown or restart your computer, disconnect your current dialup connection, lock workstation, etc
Switchboard.com Toolbar
Toolbar for the on-line version of Yellow Pages in the US - Switchboard.com
Switcher
"On a Sony laptop with built in wireless it allows the user to select which wireless services they want to run (i.e. Wireless LAN, Bluetooth, both) when turning the wireless switch on if disabled)"
switp
OfferAgent adware component
SWL
StealthWeblog surveillance software. Uninstall this software unless you put it there yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
SWN2
Spyware removal program by TrekBlue. Previously not recommended but the latest version was delisted here
sws.exe
Haldex type adult content dialler
sws.exe
Globaldialer adult content premium rate dialer
SwTray
MS SideWinder game controller system tray icon. Available via Start -> Programs. May have the version number after it
SWTrayV4
MS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs
SwyxIt!
PC Based soft phone from Swyx - see here for more details
SX Virtual Link
SX Virtual Link from Silex Technology America, Inc. Utility to connect USB devices
SXGDSENU
Yamaha SXG soundcard driver
SxgTkBar
Yamaha SXG soundcard utility - gives quick and easy access via the system tray bar to diagnostics and configuration
Sxplog
Part of CA Unicenter Software Delivery - manage software across various systems, from desktops and servers to PDAs and mobile phones, in a controlled and standardized way - is it required at startup?
sxrrv
Added by the VAX-A TROJAN!
sy
Added by a variant of the RBOT WORM!
SybaseCentral43
Related to SQL Anywhere from Sybase. A comprehensive package providing data management and data exchange technologies
SyBot v2.1 By Sky-Dancer
Added by the ZOTOB.I WORM!
SYDNEY
Added by the SYNEY WORM!
syelimS-esreveR-troppuS
Added by the LITBOT.C TROJAN!
Syga432te Pe432rsonal Firewall
Added by the RBOT-AQY WORM!
Sygaete Personal Firewall
Added by the RBOT-GLX WORM!
Sygate Peral Firewall
Added by the RBOT-AQK WORM!
Sygate Personal 3
Added by the RBOT-XD WORM!
Sygate Personal Block
Added by the RBOT-TW WORM!
Sygate Personal Firewall
Added by the RBOT-KZ WORM!
Sygate Personal Firewall
Added by the RBOT.VI WORM!
Sygate Personal Firewall
Added by the SDBOT.WM WORM!
Sygate Personal Firewall
Added by the RBOT-PN WORM!
Sygate Personal Firewall
Added by the RBOT.YN WORM!
Sygate Personal Firewall
Added by the RBOT.ATW WORM!
Sygate Personal Firewall
Added by a variant of the RBOT WORM!
Sygate Personal Firewall
Added by a variant of the RBOT WORM!
Sygate Personal Firewall
Added by the RBOT-VP WORM!
Sygate Personal Firewall
Added by the RBOT.ALD WORM!
Sygate Personal Firewall
Added by the RBOT-XY WORM!
Sygate Personal Firewall
Added by the RBOT-ZC WORM!
Sygate Personal Firewall
Added by the RBOT.UC WORM!
Sygate Personal Firewall
Added by the RBOT.BKO WORM!
Sygate Personal Firewall
Added by the RBOT.XN WORM!
Sygate Personal Firewall
Added by a variant of the RBOT WORM!
Sygate Personal Firewall
Added by the RBOT.AOB WORM!
Sygate Personal Firewall
Added by a variant of the RBOT WORM!
Sygate Personal Firewall
Added by the RBOT-AQD WORM!
Sygate Personal Firewall
Added by the RBOT.ABT WORM!
Sygate Personal Firewall
Added by a variant of the IRCBOT TROJAN!
Sygate Personal Firewall Start
Added by the RBOT-MB WORM!
Sygate Personal Firewall Start
Added by the RBOT-RY WORM!
Sygate Personal Port
Added by the RBOT-PX WORM!
Sygate Personal Port Blocker
Added by a variant of the RBOT WORM!
Sygate Personal Port Blocker
Added by a variant of the RBOT WORM!
Sygate Personals Firewalls
Added by a variant of the RBOT WORM!
SyGateService
SyGate is a useful little program that lets you share an internet connection over an intranet. Is it needed - it saves a lot of headache to just let SyGate load at startup. Available via Start -> Programs
Symantec
Added by the REATLE WORM! Note - this is not a Symantec file
Symantec Anti Virus
Added by a variant of the WOOTBOT WORM!
Symantec Antivirus professional
Added by a variant of the FORBOT WORM!
Symantec Antivirus professional
Added by a variant of the FORBOT WORM!
Symantec Antivirus professional
Added by a variant of the FORBOT WORM!
Symantec Antivirus professional
Added by the FORBOT-GT WORM!
Symantec Antivirus professional
Added by a variant of the FORBOT WORM!
Symantec Antivirus professional
Added by a variant of the FORBOT WORM!
Symantec Antivirus professional
Added by a variant of the FORBOT WORM!
Symantec Antivirus professional
Added by a variant of the FORBOT WORM!
Symantec Antivirus professional
Added by a variant of the FORBOT WORM!
Symantec Antivirus professional
Added by a variant of the FORBOT WORM!
Symantec Antivirus professional
Added by a variant of the WOOTBOT WORM! See here
Symantec Antivirus professional
Added by a variant of the FORBOT WORM!
Symantec Autoscan
Added by the RBOT-AJO WORM!
Symantec Client Security
Added by a variant of the IRCBOT BACKDOOR! See here
Symantec Configuration Loader
Added by a variant of the GAOBOT WORM!
Symantec Core LC
Part of Norton AntiVirus 2004. What does it do?
Symantec Debug Client
Added by the IRCBOT-ACM TROJAN!
Symantec Fax Starter Edition Port
Offers a virtual printer as a fax machine. Can be run via a desktop shortcut
Symantec NetDriver Monitor
Part of Symantec's LiveUpate (eg, Norton). Not required if you run manual updates but probably require if you leave them to run automatically. Also, if one runs a small office network and SNDMon is disabled on one of the computers ? then other computers disappear from the network for this computer, including shared devices like printers and scanners. Hence the "U" recommendation
Symantec NetDriver Warning
Part of Symantec Live Update - displays the warning when you need to update the firewall database
Symantec PIF AlertEng
Symantec LiveUpdate Notice Service
Symantec Secure Server
Added by the IRCBOT-UB TROJAN!
Symantec Security
Added by the RANDEX.PR or RANDEX.YR WORMS!
Symantec Security Addon
Added by a variant of the AGOBOT/GAOBOT WORM! Note - do NOT confuse with the legitimate NVIDIA Driver Helper Service file of the same name as described here
Symantec Security Routine Addon for Microsoft Windows
Added by the AGOBOT-GJ TROJAN!
Symantec Service
Added by the AKHER.D WORM! Note - this is also not the valid Norton AV file with the same filename
SymantecFilterCheck
Added by the BANKER-EEO TROJAN!
SymAV
Added by the NETSKY.U WORM!
SymKeepAlive
Part of Norton SystemWorks 2003 - keeps a dial-up modem connection alive
Symlcs
Added by the YASPY-A TROJAN!
Symmetrical Network
Added by the DELBOT-N WORM!
SymRun
Added by the KANGAROO-A TROJAN!
SymRun
Added by the KAGEN-A TROJAN!
SymTray - Norton SystemWorks
Keeps all System Tray icons for Norton SystemWorks together to reduce clutter. SystemWorks includes Norton Anti-Virus, Norton Utilities and Norton CleanSweep - mentioned elsewhere here. Personally I only have Norton eMail Protect running which doesn't need SymTray
Synaptics Pointing Device Driver
Synaptics touchpad tray icon. Displays status and provides quick launch to touchpad features such as scrolling and tap zones. Required on IBM Thinkpads with UnltraNav (pointstick and touchpad combo) if you don't want to loose the advanced pointstick features such as scroll
Sync Data
Pocket Real Estate - mobile synchronization manager
Sync Server
Added by the WATSOON.A TROJAN!
Sync-It
Sync-It - synchronizes the system clock with time servers on the internet
SyncAgent
Ghost Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!
Synchronization Manage
Added by the FORBOT-FM WORM!
Synchronization Manager
Find more information about its use here
syncman
Added by the MANCSYN-A TROJAN!
SyncManager
Added by a variant of the TACTSLAY TROJAN!
SyncMon
Added by the CLUNKY-A TROJAN!
SyncMon
Added by the CLUNKY-B TROJAN!
SynSetup
Probably associated Synaptics touchpads on laptops as for the SynTPEnh and SynTPLpr entries but what does it do and is it required?
Syntax
Added by the SDBOT.CQ WORM!
Syntax Script
Added by the SDBOT.AI WORM!
SynTPEnh
Synaptics touchpad tray icon. Displays status and provides quick launch to touchpad features such as scrolling and tap zones. Required on IBM Thinkpads with UnltraNav (pointstick and touchpad combo) if you don't want to loose the advanced pointstick features such as scroll
SynTPLpr
Synaptics touchpad driver helper. Required for touchpad features to work
SynTPStart
Synaptics Pointing Device starter belonging to Synaptics Pointing Device Driver
sys
Hijacker
sys
CoolWebSearch parasite variant - also detected as the FEMAD-L TROJAN!
Sys Ren
Part of FlashEnhancer adware
sys************* [* = random digit]
WINBO adware
Sys**.exe [* = random char]
CoolWebSearch/HomeSearch adware - for examples, see this log
Sys**32.exe [* = random char]
CoolWebSearch/HomeSearch adware - for examples, see this log
Sys-Stat
Added by the SDBOT.HK WORM!
sys008
Hijacker, also detected as the STARTPA-GK TROJAN!
sys009
Added by the STARTPA-ZB TROJAN!
sys201
Added by the STARTPA-ZY TROJAN!
Sys29
EliteBar adware
sys32
Added by the FLUX.E TROJAN!
sys32
Added by the KVEX-A VIRUS!
sys32cmd
Active Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!
sys32dll
Added by the AIMDES.B WORM!
sys32sql
Active Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!
sys33
Added by the AGOBOT-WJ WORM!
SysA
EliteBar adware
SysAgent
SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of
SysAI
AproposMedia adware
SysATW
Added by the VANEBOT-AM WORM!
SysBkup
Keyspy keystroke logger/monitoring program - remove unless you installed it yourself!
Sysbot
Spector - spying (or monitoring) software to record internet activity
syscfg
Added by the KWBOT.S WORM!
syscfg34.exe
Added by the ELECTRON WORM!
Syscheck
Browser hijacker
syscheck
Added by the AGENT.DM TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)
sysclx
Added by the JLOK-A WORM!
syscm
Vanish adware
SysComp
Unknown but suspect as *.com are not usually run at start up and the name isn't recognized
syscon
Added by the APRILCONE.A WORM!
syscon lptt01
RapidBlaster variant (in a "Syscon" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
syscon ml097e
RapidBlaster variant (in a "Syscon" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
sysconfig
Added by the CULT.C WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)
SysConfig
Added by the KAZMOR.C WORM!
SysConfig
Added by the SDBOT.ZD WORM!
Sysconfig
StealthKeySpy - keystroke logger/monitoring program - remove unless you installed it yourself!
Syscpy
Firewall-bypassing, proxied spam relayer. Detected by Symantec as the HOGLE TROJAN!
SysCtl
Added by the AOK TROJAN!
Sysctrls
Added by the WEEDBOTZ.14 TROJAN!
Sysctrls
Added by an unidentified WORM or TROJAN!
Sysctrls
Detected by Kaspersky as the KOLABC.BB WORM! See here
Sysctrls
Detected by Kaspersky as the AGENT.AWZ TROJAN! See here
Sysctrls
Added by a variant of the IRCBOT BACKDOOR! See here
Sysctrls32
Detected by Kaspersky as the RBOT.ADF BACKDOOR! See here
SysCVMS.exe
Added by the SMALL.CBA TROJAN!
sysdat.dll
Added by the NISHICA 1.1 TROJAN!
SysData
Added by the RANCK-BA TROJAN!
SysDeskqqfx
Added by the QQPASS.H TROJAN!
SysDeskqqfx
Added by the CHANGGAME TROJAN!
SysDesktop
Added by the QQSEND-A TROJAN!
sysdir
Added by the WINBUR.B WORM!
sysdll
Added by the HUGESOT TROJAN!
Sysdpt
CRYPT trojan downloader
sysdxvid
Added by the DLUCA-S TROJAN!
sysemls
Added by a variant of the SDBOT WORM!
SysEQ
Added by the IRCBOT-AC TROJAN!
sysfiler
Added by the RETSAM TROJAN!
SYSfit
AdShooter adware variant
sysflg32
Added by a variant of the CRYPTER.C TROJAN!
sysformat
Added by the BAGLE-BK WORM!
sysfrcx
Added by the KEYLOG-SCLOG TROJAN!
Sysgate Personal Firewall
Added by a variant of the IRCBOT TROJAN!
syshelp
Added by the LOVGATE.C WORM!
syshost
Added by the VB-DVZ TROJAN!
sysin
Added by the DSRC-A TROJAN!
sysinfo
Added by the BEDRILL TROJAN!
sysinfo.exe
Added by the BEAGLE.V WORM!
SysInit
Added by the STARTPA-BD TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Program Files/Common Files folder
SysInit
Added by the XABOT WORM!
sysinit
Added by the NEWLFRM-A TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in an "golumm" subfolder
Sysino
Added by the FORBOT-BF WORM!
sysint16
Added by the CRYPTER.A TROJAN!
sysinter
Added by the AGENT.JVJ TROJAN!
Syskey
Added by the BEAGLE.AX WORM!
Syslib
Adult content related downloader trojan
Syslog lptt01
RapidBlaster variant (in a "Syslog" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
Syslog ml097e
RapidBlaster variant (in a "Syslog" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
syslogin.exe
Added by the BAGZ-B WORM!
Sysman
KeyTrap is a surveillance software program that records all keyboard activities. Uninstall this software unless you put it there yourself
SysManager
Added by the DAGGER.140 TROJAN!
sysme
Added by the PSW_STEALER_C TROJAN!
sysmem
Added by the NOPIR.C WORM!
sysmem
Added by the NOPIR-C WORM!
SysMemory manager
Added by the CIMUZ-D TROJAN!
SysMetrix
SysMetrix - skinnable clock and metering application. It monitors and reports on a great number of statistics
sysMett1
Added by the LEGMIR-Y TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%
sysmini
Added by the ADLOAD.DD TROJAN!
sysmngr32
Added by a variant of the RBOT WORM!
sysmntrc
Added by the BANCOS-FX TROJAN!
sysmod
Added by the SPYBOT-DU WORM!
sysmon
Added by the BIZEX WORM!
Sysmon
Added by the RANDEX.ATX WORM!
sysmon
Added by a variant of the BACKDOOR-CBA TROJAN!
SysMon
Added by the MULAN-A TROJAN!
Sysmon
Added by the NUJAMA-A WORM!
sysmon12
Wareout - malware masquerading as a spyware and dialer remover
SysmonLog
Added by the AGENT.AOV TROJAN!
sysmonnt
SearchPounder sends keywords typed into HTML forms and popular Internet search engines to a remote server
SysMonXP
Added by the NETSKY.Q WORM!
Sysmppcvppp
Generic2.PQG adware
sysmss
Added by a variant of the SLAPER TROJAN!
sysnate
Added by the MEDIAS TROJAN!
Sysnet
Unidentified adware
sysnet
CasClient adware - also detected as the CMAPP TROJAN!
sysobj.exe
Wareout - malware masquerading as a spyware and dialer remover
SysOps
Added by the MSNCORRUPT TROJAN!
syspare
Added by the BIFROSE-AN TROJAN!
syspath
Added by the SOBER WORM!
sysPersonalFirewall
Added by a variant of the RBOT WORM!
sysPersonalFirewall
Added by the WOOTBOT.FH WORM!
sysPersonalFirewall
Added by a variant of the RBOT WORM!
SysPilot
G Data "PC Spion". PC monitoring and surveilling software, captures all users activity on the PC, see here. Disable/remove if you didn't install it yourself!
sysPnP
Homepage hijacker, redirecting to coolwwwsearch.com; see for example here
SysPnP
CoolWebSearch PnP parasite variant
SysPool
StealthDisk - hides folders, files and applications. Will also encrypt them for better protection
SysPool
Added by the BANCBAN-IO TROJAN!
SysProtect
Added by the NETSPY TROJAN!
SysProtect
SysProtect is detected as a "potentially unwanted program". It purports to be an system repair/maintenance application, but requires paid registration before any issues found can be fixed. Many of the "invalid" items found appear suspect. This has been reported to be distributed in wild via trojan Vundo. Other incarnations of this software exist with the same model and similar web presences (for example WinFixer). For more information see here
syspw32.exe
Added by the APPFLET.A WORM!
Sysqq
Added by the FORBOT-BF WORM!
SysR
Ulubione adult content dialer
SysReg
Added by the CHEKIN TROJAN!
SysReg
SearchSeekFind textual marketing foistware
Sysres
Added by the LOGMOD.A TROJAN!
SysRes
Added by the ELIPTER.A or ELIPTER.B WORMS!
SysRes
Added by the ELIPTER.D WORM!
SysRes
Added by the ELITPER.E WORM!
sysrest32.exe
Added by the AGENT-GIN TROJAN!
sysrestore32.exe
Unknown malware detected by McAfee. See here
Syss
EHU adware
SysScan
Added by the AUTOUPDER TROJAN!
SysSearch
Added by the STARTPAGE-FN TROJAN! Note that regedit.exe is a legitimate Microsoft file and shouldn't be deleted. The "pcsearch.reg" file is located in the Winnt or Windows folder
SysSearch
Added by the STARTPA-ME TROJAN! Note that regedit.exe is a legitimate Microsoft file and shouldn't be deleted. The "sysreg.reg" file is located in the Winnt or Windows folder
SysSense
"SysSense is your personal desktop Google AdSense monitor. It keeps your current Google AdSense information in the Windows system tray". Google AdSense account required
sysser
Added by the RAHACK WORM!
SysService
Added by the DELF family of TROJANS!
SysService
NSKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!
SysService32
Added by the KINDAL VIRUS!
SysService32
Added by the KINDAL VIRUS!
SysService32l
Added by the THEUG WORM!
SYSsfitb
Searchforit browser hijacker
SySSL
Added by the RBOT-CKH WORM!
SysStart
ZenoSearch adware
SysStrt
Added by the AGOBOT-QA TROJAN!
syst
Added by the DUMB.A "Joke" virus
Systam13
Added by the IRCBOT-YM WORM!
System
Added by an unidentified TROJAN!
System
Added by the LDPINCH-BN TROJAN!
System
Added by the LDPINCH-BF TROJAN!
System
Added by the IU WORM!
System
Added by the BANCOS-DB TROJAN!
System
Added by a variant of the RBOT WORM!
System
Added by the BANKER-FC TROJAN!
System
Added by the LEBREAT-D WORM!
System
Added by a variant of the RBOT WORM!
SYSTEM
Added by the MYTOB.LP WORM!
System
Added by the PARDROP-A TROJAN!
system
Added by the DELF-LQ TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "HELP" subfolder of the Windows or Winnt folder
SYSTEM
Added by the RBOT-AWW TROJAN!
SYSTEM
Added by the RBOT-AVG WORM!
System
Added by the VIXUP-S TROJAN!
system
Added by the SATILOLER.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Program FilesCommon Filessystem folder
System
Added by the AGENT.AEP TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
System
Added by a variant of the SDBOT WORM!
system
Added by an unidentified WORM or TROJAN!
System
Added by a variant of the SDBOT WORM!
System
Added by a variant of the SDBOT WORM!
SYSTEM
Added by a variant of the RBOT WORM!
system
Added by the SPYONE TROJAN!
System
Added by the TIBS-PP TROJAN!
System
Added by the TIBS.AI TROJAN!
System
Added by the AGUI WORM!
System
Added by the QQHELP-DX TROJAN!
System
Added by the MSNVB-D WORM!
System
Added by the SILLYFDC-AL WORM!
System
Added by the CULLER-C WORM!
System
Added by the DLOADR-AOL TROJAN!
System
Added by the VXIDL.FT TROJAN!
System
Added by the CULLER-D WORM!
System
Added by the DLOADER.DJD TROJAN!
SYSTEM
Added by a variant of the IRCBOT BACKDOOR! See here
System
Added by the LANFILT TROJAN!
System
Added by various WORMS and TROJANS!
system
Homepage hijacker
system
Jetseeker.com hijacker
System
Added by the CIREBOT TROJAN!
system
Added by the GRAYBIRD BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
System
Added by the JUNTADOR.K TROJAN! Note - this is not Yahoo! Messenger
system
Added by the MIMAIL.Q WORM! Note that the valid MS Outlook executeable is located in the Program FilesMicrosoft OfficeOffice directory wheras this one is found in the Windows or Winnt directory
System
Added by the KOTIRA VIRUS!
SYSTEM
Added by the SPYBOT.CJ WORM!
System
Added by the DLOADER-FC TROJAN!
System
Added by WinGuardian. Note - this commercial keylogger is no longer made or sold by Webroot but older copies may still be in existance, those copies will be identified as spyware
System
Added by the LDPINCH.E TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
System
Added by the LDPINCH-AU TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder
system
Added by the RBOT-YL WORM!
System
Added by the PISABOY-A TROJAN! Note - this is not the legitimate systray.exe process
System
Added by the HARWIG-B WORM!
System 64 Driver for Games
Added by the SDBOT TROJAN!
System Applications Profile
Added by the RBOT-QF WORM!
System Backup
Adult content dialler
System backup
Added by the ADMINCASH.B TROJAN! Note - multiple different file names have been spotted, examples: web.exe, soft.exe, msxmidi.exe, wmplayer.exe, as well as completely random ones such as 9a2de006.exe, 36c75e3c.exe and so on
System Backup Services
Added by a variant of the RBOT WORM!
System Boot Check
Added by the FUBALCA WORM!
System Buffer Application
Added by the SDBOT-UD WORM!
System Cache
Added by an unidentified VIRUS, WORM or TROJAN!
System CGI Manager
Added by an unidentified WORM or TROJAN! See here
System Check
XPCSpy Pro keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
system check
Unidentified adware downloader
System Check
Added by the DELF-DRA WORM!
System Checking
Added by the RBOT.BHM WORM!
System Config
Added by the SPYBOT-DT WORM!
System Config
Added by a variant of the SDBOT WORM! See here
System Config Boot
Detected by Kaspersky as the AGENT.VWU TROJAN! See here
System Config Manager
Added by the AGOBOT.GH WORM!
System Config Manager
Added by the AGOBOT-ZJ WORM!
System Configuration
Added by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%
System Configuration
Added by the MYTOB.EA WORM!
system configure
Added by the LINEAGE-C TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!
System Core Memory
Added by a variant of the IRCBOT BACKDOOR! See here
System CPL manager
Added by the RBOT-SR WORM!
System CSRSS Patch
Added by the RBOT-ADA WORM!
System Database administration
Added by the DERDERO.B WORM!
System Database Administration Support Process
Added by the DERDERO.C WORM!
System DataBase Root
Added by the QHOST-W TROJAN!
System DB Manager
Added by an unidentified WORM or TROJAN! See here
System Diagnostics
Added by the SDBOT.GEN TROJAN!
System DLF
Compaq Diagnostic record system utility which allow you to view information about your computer's hardware and software configuration. Available via Start -> Programs
System DLL Resources
SnapKey is a surveillance software program that records all keyboard activities. Uninstall this software unless you put it there yourself
System Document Application
Added by the SDBOT-ABB WORM!
System Document Application
Added by the RANDEX.COX WORM!
System Document Application
Added by the SDBOT.AUB WORM!
System Download Manager
Added by the RBOT.CIG WORM!
System driver
Added by the WOOTBOT.GI WORM!
System Drivers
Added by the SDBOT-MG WORM!
System Drivers
Added by the SDBOT.AXH WORM!
System Efficiency Monitor
Added by the SDBOT.P TROJAN!
System Efficiency Monitor
Added by the KWBOT.P WORM!
System Efficiency Monitor
Added by the STEPH-B WORM!
System Efficiency Monitor
Added by the KWBOT.E WORM!
System Event Manager
Added by the RBOT.BMY WORM!
System Executable DLL Library
Added by the RANDEX.AZ WORM!
System Failure Statistic
Added by the RBOT-LF WORM!
System File Drivers
Added by the AGOBOT.WJ WORM!
System File Startup
Detected by PCTools as the RBOT.OTL WORM! See here
System Files Updater
System Files Updater from Flyakiteosx "will transform the look of an ordinary Windows XP system to resemble the look of Mac OS X"
system firewall
Added by the AGOBOT-PS WORM!
System Firewalls
Added by the RBOT.BJT WORM!
System Guard
Added by the RBOT-AGU WORM!
System Handler
Added by the NIMOS WORM! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
system handler
Added by the REDPLUT VIRUS!
System handler
Added by the BHARAT.A WORM!
System Host
Added by a variant of the RBOT WORM!
System Host Manager
Added by the BANWORM-C WORM!
System Host Service
Added by the CONE.F WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "tasks" subfolder of the Winnt or Windows folder
System Information Manager
Added by the SDBOT-QB WORM!
System Information Manager
Added by a variant of the IRCBOT TROJAN!
System Information Manager
Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%
System Information Manager
Detected by Kaspersky as the DELF.AKO TROJAN! See here
System Information Manager
Added by the SPYBOT.NO WORM!
System Information Manager
Added by the SDBOT-MO WORM!
System Information Manager
Added by the SDBOT-MU WORM!
System Information Manager
Added by the SDBOT-ND WORM!
System Init
Added by a variant of the IRCBOT BACKDOOR! See here
System Initialization
Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS!
System Initialization
Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS!
System IP
Added by a variant of the IRCBOT BACKDOOR! See here
System Kernal Support
Added by the SDBOT.BWV WORM!
System Kernel
Added by the VBBOT-G TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
System LifeGuard Scheduler
System LifeGuard scheduler
System Log Event
Added by the AGOBOT-JI WORM!
System Management Service
Added by the RBOT-ANN WORM!
System Manager
Added by the BANKER-AE TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder
system manager
Added by the FORBOT-BO WORM!
System Manager
Added by an unidentified WORM or TROJAN!
System Manager
Added by the TAME-C WORM!
System Manager
Added by a variant of the IRCBOT TROJAN! See here
System Manager
Added by a variant of the IRCBOT BACKDOOR!
System Manager Updates
Added by the AGOBOT.AEM WORM!
System Mechanic Popup Blocker
Popup blocker part of Iolo System Mechanic utility suite
System Mechanic Popup Stopper
Popup stopper part of Iolo System Mechanic utility suite
System Mechanic Professional Update [Incinerator.dll]
Iolo System Mechanic "Incinerator" feature securely deletes files and folders from your PC so they can never be recovered again
System Mechanic Startup Guard
System Mechanic Startup Guard protects the Window's startup locations from being modified by viruses, spyware, malware and other annoying programs
SYSTEM MESSAGER
Added by the MYTOB.ES WORM!
System Messaging Queue
Added by a variant of the RBOT WORM!
System Messenger
Added by the SPYBOT-DK WORM!
System Messenger32
Added by the SDBOT.DF WORM!
System Microsoft Core
Added by the RIZO.A TROJAN!
System Monitor
Comes with some Aopen motherboards. Monitors CPU temp, voltage and fan speed. Warns if any become abnormal
System Monitor
Added by the SDBOT TROJAN!
System Monitoring
Added by the RAHIWI.A WORM!
System Monitoring
Added by the BHARAT.A WORM!
System MScvb
Added by the SOBIG.C WORM!
System Net
Added by the FORBOT-FX WORM!
System Net Database
Added by the RBOT-AAW WORM!
System Networking
Added by the RBOT.API WORM!
System Power Managment
Added by the DREF-I WORM!
System Presets
Added by the HOSTINF-A WORM!
System Process
Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
System Process
Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
System Process
Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder
System Process
Added by the AGOBOT-SQ WORM!
System Process Analization
Added by a variant of the RBOT WORM!
System Process Analization Thread
Added by a variant of the RBOT WORM!
System Profile
Added by a variant of the OPTIX TROJAN!
System Reboot
Added by the RBOT-WU WORM!
System Redirect
Downloader trojan, "Melkosoft" adware related
System Registry Manager
Added by an unidentified WORM or TROJAN! See here
System Restore
Added by the TIBICK WORM!
System Restore Data
Added by the RANDON.AN WORM!
System Security Checker
Added by the IRCBOT-WI TROJAN!
System Service
Added by the AML TROJAN!
system service
Added by the INSPIR.11 TROJAN!
System Service
Added by the AGOBOT.VZ WORM!
System Service
Added by the RBOT-ALD WORM!
System Service
Added by a variant of the RBOT WORM!
System Service
Added by the RBOT-AJI WORM!
System service
Added by the BANCOS.AA TROJAN!
System Service
Added by the SPYBOT.YCL WORM!
System Service
Added by the RBOT-AOY WORM!
System Service
Added by the RBOT-AUA WORM!
System Service
Added by the RBOT-AUV WORM!
System Service
Added by the PACKBOT.AA WORM!
System Service
Added by the RBOT-FMV WORM! Note - deactivates the Microsoft Internet Connection Firewall (ICF)
SYSTEM service helper
Added by the MONKBD-A WORM!
SYSTEM service helper
Added by a variant of the MONKBD-A WORM!
System service**
EliteBar adware - where ** represents the numbers 61 to 79
System service78
Added by the ELITEBAR-T and ELITEBAR-U TROJANS!
System service79
Added by the ELITEBAR-V TROJAN!
System Services
Added by a variant of the RBOT WORM!
System Services
Added by an unidentified WORM or TROJAN!
System Services
Added by a variant of the RBOT WORM!
System Services
Added by the RBOT-AFG WORM!
System Services
Added by a variant of the RBOT WORM!
System Services Monitor
Bifrost malware
System Session Manager
Added by the KALEL-E WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!
System settings
Added by the SDBOT-ZO WORM!
System Setup
Added by an unidentified WORM or TROJAN!
System Soap Pro
System Soap Pro internet cleaning software. Bundles foistware like Httper and Zipclix - best avoided
system spool
Added by the DREF-T WORM/VIRUS!
System startup
Only required if using an oriental language
System Startup
Added by the RBOT.NJ WORM!
System Startup
Added by a variant of the RBOT WORM!
System Startup
Added by a variant of the IRCBOT TROJAN!
System Startup Manager
Added by the RBOT.AMD WORM!
System Stats
Added by a variant of the WOOTBOT WORM!
System Support
Added by the RBOT-AGQ WORM!
System Support
Added by the RBOT-AHA WORM!
System Support
Added by the RBOT-AUH WORM!
System Support
Added by a variant of the RBOT WORM!
System Task Manager
Added by a variant of the SPYBOT WORM! See here
System Terminal
Added by the SPYBOT-BZ TROJAN!
System time updator
Added by the RANDEX.S WORM!
System Toolkit
Added by the RONOPER-G WORM!
System Tray
Added by the SOBIG.B WORM! Warning - spreading via infected E-mail attachments with the sender address faked as support@microsoft.com! Note - this is not the legitimate systray.exe process
System Tray
Added by the FAN-A WORM!
System Tray Monitor
Detected by PCTools as the RBOT.UXR WORM! See here
System Tray Services
Added by the AGOBOT.ZH WORM!
System Tray32
Added by the REPAD WORM!
System Unix
Added by the RBOT-ZD WORM!
system updata
Added by the LINEAGE-C TROJAN!
System Update
CoolWebSearch parasite variant
System Update
Added by the KORGO.W or KORGO.X WORMS!
System Update
Added by the SOROMO-A TROJAN!
System Update
Added by the SOROMO-A TROJAN!
System Update
Added by the SDBOT.EF WORM!
System Update
Added by the AUTOTROJ-D TROJAN!
System Update
Added by the RBOT.DLC WORM!
System Update Application
Added by the SDBOT.AFF WORM!
System Update Service
Added by the AGOBOT-RG TROJAN!
System Update Service
Added by the ADTODA-A TROJAN!
System Update Service
Added by the RBOT-ALL WORM!
System Update Service
Added by the SPYBOT.WOE WORM!
System Update Service
Added by the AGOBOT.YG WORM!
System Update2
Added by the AUTOTROJ-C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
System Update2
Added by the AUTOTROJ-C TROJAN!Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
System Update2
Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
System Update2
Added by the AUTOTROJ-C TROJAN!
System Update2
Added by the AUTOTROJ-C TROJAN!
System Update2
Added by the AUTOTROJ-C TROJAN!
System Update2
Added by the AUTOTROJ-C TROJAN!
System Update2
Added by the AUTOTROJ-C TROJAN!
System Update2
Added by the AUTOTROJ-C TROJAN!
System Update2
Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
System Update2
Added by the AUTOTROJ-C TROJAN!
System Update2
Added by the AUTOTROJ-C TROJAN!
System Updater Machine
Added by the CIADOOR-DQ TROJAN!
System Updater Machine
Detected by Kaspersky as the CIADOOR.GN BACKDOOR! See here
System Updater Service
Added by the GAOBOT.AFC WORM!
System Updates
Added by a variant of the RBOT WORM!
System Updates
Added by the RBOT-AXE WORM!
System Updates
Added by the RBOT-AWG TROJAN!
System Updates
Added by the RBOT-AYJ WORM!
System Updates 4
Added by the RBOT-ADU WORM!
System Updates Manager
Added by the AGOBOT-AGA WORM!
System Updates Service
Added by the RBOT-AMA WORM!
System Uptime Server
Added by the RBOT.LK WORM!
System Uptime Server
Added by the RBOT.LK WORM!
system xp
Added by the SALGA.A WORM!
System-Config
Added by the LIOTEN.FA WORM!
System-Service
Added by the BENJAMIN.A WORM! KaZaA file-sharing users beware!
System-Stat
Added by the SDBOT.RA WORM!
system.
Added by the OPTIXPRO.13.C TROJAN!
system...
Added by the OPTIXPRO.13.C TROJAN!
System.exe
Added by various WORMS and TROJANS!
system.exe
Added by the JAMPORK.E WORM!
system.exe
Added by a variant of the IRCBOT BACKDOOR! Located in %WINDIR%\pchealth\helpctr\binaries
System132
Added by the LANFILT-I TROJAN!
system23
Added by the ESTEEMS.D TROJAN!
System32
Added by the BUSHTRO122 TROJAN!
System32
Added by any number of WORMS or TROJANS!
System32
SpyAgent surveillance software. Uninstall this software unless you put it there yourself
System32
Added by an unidentified VIRUS, WORM or TROJAN!
system32
Added by the AGOBOT-LJ WORM!
System32
Added by the RBOT-XW WORM!
System32
Added by the RBOT.BLY WORM!
system32
Added by the QQPASS-AC TROJAN!
System32
Added by the NAUTICAL-A WORM!
System32
Added by the DWNLDR-HFY TROJAN!
System32 PCI Manager
Added by the RBOT-AFR WORM!
System32 Runtime StartUp
Added by the AGOBOT.ANW WORM!
System32 TCP Manager
Added by a variant of the RBOT WORM!
System32 TCP Manager
Added by the RBOT.AFD WORM!
System32 Temp Service
Added by the RBOT-AET WORM!
system32.dll
CoolWebSearch parasite variant - re-directing to your-search.info
system32.dll
CoolWebSearch parasite variant. Redirecting to wholeworldmarket.com, most likely other domains as well
system32.exe
Added by a variant of the IRCBOT TROJAN!
system32.exe
Added by the GRAYBIRD.P TROJAN!
System32BLSJ Agent
Added by the MDROP-BPT TROJAN!
System32Check
Added by the CHAST-A TROJAN!
System32Dll
Added by the SPYBOT-CZ WORM!
System32Ex
Added by the IRCCONTACT TROJAN!
System32kfvw
SpyAgent surveillance software. Uninstall this software unless you put it there yourself
System32Root
Added by a variant of the IRCBOT TROJAN! Note - doe not confuse with the Polish language Instant Messaging client also called Gadu-Gadu
system32WXBP Agent
Detected by Trend Micro as TSPY_ARDAMAX.HR spyware. See here
System33
Added by the NICHELLO-A WORM!
system34.exe
Added by the DWNLDR-FXY TROJAN!
System4224411
Added by the CAGER.A WORM!
System4224411
Added by the YUSUFALI-B WORM!
system43.exe
Added by a variant of the SDBOT WORM!
System64
Added by the DENGLE-A TROJAN!
SystemAdministration
Added by the ASYLUM TROJAN!
SystemAgent
"Microsoft Plus! System Agent automatically tunes your system, performing tasks such as disk optimization and error correction. It can also run any application at prescheduled times"
SystemB
MessStopper adware
systemb
Added by a variant of the IRCBOT TROJAN!
SystemBackup
Added by the MTX VIRUS/WORM!
SystemBackup
Added by the MICROLOG.A TROJAN!
SystemBoot
Added by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a HelpHelp subfolder of the Windows or Winnt folder
SystemBoot
Unknown but sounds very suspicious??
SystemBoot
Adult content dialler
Systemboot
Added by a variant of the RBOT WORM!
SystemCheck
Added by the LAVITS WORM!
SystemCheck
Added by the SOBER-M WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Configsystem subfolder of the Windows or Winnt folder
SystemCheck
Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a C:DriverLoad folder
SystemCheck
WINBO adware
SystemChecker
Added by the GALIL.F WORM!
SystemCONF98i
Added by the GLITCH TROJAN!
SystemDebug
Added by the SYSBUG TROJAN!
SystemDefender
SystemDefender spyware remover - not recommended, see here
SystemDll
Added by the LOXOSCAM TROJAN!
systemdll32.exe
Added by the FEUTEL-F TROJAN!
SystemDoctor 2006 Free
SystemDoctor misleading security software - not recommended, see here
SystemDriver
Added by the ASCETIC.B TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\addins\explorer
SystemDriverCheck
Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a C:DriverLoad folder
SystemDriverLoad
Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a C:DriverLoad folder
systemdrv
Added by an unidentified WORM or TROJAN - most likely GAOBOT variant
SystemEmergency
CoolWebSearch Smartsearch parasite variant
SystemErrorFixer
SystemErrorFixer spyware remover - not recommended, see here
SystemExplorer
Homepage hijacker - file located in the "Services" folder in Common Files
SystemFile
Added by the DULLDOOR-A TROJAN!
SystemFTP
Malware (ie, malicious software). Also changes the system.ini Shell line to read Shell=Explorer.exe VSENMB.exe, and it hacks the Winstart.bat as well
SystemGent
Added by the BRONTOK-H WORM!
SystemGuardAlerter
Part of the Iolo System Mechanic maintenance software. What does it do?
SystemInit
Added by the FIZZER WORM!
systeminit
Added by the SILLYFDC-AN WORM!
Systemiom Updater
Added by the SPYBOT.TY WORM!
SystemKey
Stealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
SystemLoad32
Added by the MIMAIL.E WORM!
SystemLoader
Added by the DOWNLDR-NS TROJAN!
SystemManager
Added by the DOWNLOADER-BW.B TROJAN!
SystemMap32
Added by the REDIST.C WORM!
SystemMD
Homepage hijacker
SystemMgr
Added by the MAGANIA-OU TROJAN!
SystemMigration
Added by the KELVIR.EI WORM!
SystemMonitor
Added by the AIDID.A WORM!
SystemNetwork
Added by the NETCONTROL VIRUS!
SystemNetwork
Added by a variant of the RBOT WORM!
SystemNT
Added by the PWSVB-EG TROJAN!
SystemOPsv
Added by a variant of the SPYBOT WORM!
SystemProcEvent
Added by the IRCBOT.I TROJAN!
systemr
Added by the GX TROJAN!
systemr
Added by the ADCLICK-AQ TROJAN!
SystemReg
??
SystemReg
Added by the DEWIN.E TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder
SystemReg
Added by the DEWIN.A TROJAN!
Systems
Added by the DAEMOZ.A TROJAN!
Systems
Added by the MYDOOM.BI WORM!
Systems
Added by the BANKBOA-A TROJAN!
Systems
Added by the DLOADER-PP TROJAN!
Systems
Added by the DWNLDR-GAH TROJAN!
Systems
Added by the DLOADR-SW TROJAN!
Systems
Added by the VIXUP-BI WORM!
Systems Backups
Added by the AGOBOT-RB WORM!
Systems Restart
Added by the MULTIDROP.C TROJAN!
Systems Restart
Added by an unidentified WORM or TROJAN!
Systems Restart
Browser hijacker - the file serves to register a dll implemented as a browser plugin. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
Systems Restart
Added by the STARTPAGE.I TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
Systems Restart
Added by a variant of the STARTPAGE TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
Systems Restart
Added by the STARTPAGE.J TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
Systems Service
Added by a variant of the RBOT WORM!
systems usb driver
Added by a variant of the RBOT WORM!
Systems.exe
Keyboard Spectator - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it
systems.exe
KGBSpy is a commercial surveillance software program. It logs keystrokes, Web sites visited, and clipboard activity. It also has a screen capture logger and can be run automatically in a silent, undetectable mode
SystemSafe
System Safety Monitor - system monitoring tool with additional application firewalling
SYSTEMSars32
Added by the AHLEM.A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
SystemSAS
Added by the KWBOT.C WORM!
systemscroot
Added by a variant of the RBOT WORM!
SystemSearch
Installs a Seachxl.com browser page hijack
SystemSearch
Installs a i--search.com browser page hijack
SystemService
Premium rate adult content dialler
SystemService
Premium rate adult content dialler
SystemService
Premium rate adult content dialler
SystemService
Premium rate adult content dialler
SystemService
NiceSpy keystroke logger/monitoring program - remove unless you installed it yourself!
SystemSettingf
Added by the TRUG.B MACRO!
SystemSuite Task Manager
vcom (nee Ontrack) SystemSuite - PC maintenance and security. Use the program's configuration options to enable only the parts you want running all the time - such as Virusscanner Pro
SystemSv12
Added by the TIBS-TS TROJAN!
SystemSv121
Detected by PCTools as the TIBS.JT TROJAN! See here
SystemTasks
Adult content dialler
SystemTasks
Adult content dialler
SystemTasks
Adult content dialler
SystemTools
Added by the DLOADER-FC TROJAN!
SystemTools
Added by the SMALL.DGK TROJAN!
SystemTools
Added by the FNG TROJAN!
SystemTools
Added by the TIBS-PP TROJAN!
Systemtra
Added by the LOVGATE-W WORM!
SystemTra
Added by the LOVGATE.Z WORM!
SystemTra
Added by the LOVGATE.E WORM!
SystemTray
SYSTRAY.EXE - System Tray Services. Provides the Volume Control, PC Card Status, Power Management and other icons that reside in the System Tray (see here). SYSTRAY.EXE may be disabled if none of these services are required. It will launch as and when required if you later enable the icons. If you need these items they're available via Start -> Settings -> Control Panel
SystemTray
Added by the BIGFOOT TROJAN! Note - this is not the legitimate systray.exe process
SystemTray
Added by the ALADINZ.P TROJAN! Note - this is not the legitimate systray.exe process. If you right-click on the real systray.exe the "Properties" reveal it to be a Microsoft file
SystemTray
Added by a variant of the SPYBOT WORM!
SystemTray
Added by a variant of the IRCBOT TROJAN!
SystemTray
Added by a variant of the IRCBOT TROJAN!
SystemTray
Added by a variant of the IRCBOT TROJAN!
SystemTray Monitor
Added by a variant of the SPYBOT WORM! See here
SystemTraySD
Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here
SystemTraySR
Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here
SystemUpd
Updater for Swapoo.com, a kind of Napster for games
SystemUpdate
Added by the CULLER-C WORM!
SystemUpdate
Added by the CULLER-D WORM!
systemw32
Added by a variant of the RBOT WORM!
SystemWeb
StealthWeblog surveillance software. Uninstall this software unless you put it there yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
SystemWideHook for Windows NT
Added by the MYDOOM.AC WORM!
SystemWizard Sniffer
SystemWizard for Win98/ME from SystemSoft - diagnoses and solves hardware and software problems on a PC
SystemX
Added by a variant of the RBOT WORM!
systemx32
Added by a variant of the RBOT WORM!
systemyom Updater
Added by a variant of the IRCBOT TROJAN!
SYSTEMZ Patch
Added by the ALADINZ.P TROJAN!
System_Messages
TerminatorX - "offers an easy and effective method of stopping users running predetermined file sharing programs like KaZaA, messenger programs, chat rooms and the like"
systen32.exe
Added by the AQP TROJAN!
Systes
Added by the RBOT-ADC WORM!
Systesms.exe
Added by the RBOT-HI WORM!
Systest
Clean Space internet evidence eliminator
SysteZ
Added by the MSNDIABLO.A WORM!
systhread
Added by the LIAMED WORM!
SysTime
CoolWebSearch parasite variant - also detected as the STARTPA-FL TROJAN!
Systmesy
Added by the RBOT-KQ WORM!
Systoan32
Added by an unidentified VIRUS, WORM or TROJAN!
systr
Added by the VB-DQY WORM!
systr2
Added by the VB-DQY WORM!
systr32
??
systrans
Added by the STARTPA-GZ TROJAN!
systrax
??
Systray
Added by the KERGEZ.A WORM!
Systray
Winfavorites adware
SYSTRAY
Added by the DLOADER-LQ TROJAN!
SysTray
SYSTRAY.EXE - System Tray Services. Provides the Volume Control, PC Card Status, Power Management and other icons that reside in the System Tray (see here). SYSTRAY.EXE may be disabled if none of these services are required. It will launch as and when required if you later enable the icons. If you need these items they're available via Start -> Settings -> Control Panel
SysTray
Added by an unidentified TROJAN!
Systray
Added by the RBOT-AJY WORM!
Systray
Added by the STEFAN WORM! Note - make sure you check the hyperlink as this one copies it's self to numerous dirves and folders
Systray
Added by the SOAD-D WORM!
SysTray
Added by the RAJILO-A WORM!
SysTray
Added by the DELF.E TROJAN!
Systray driver
Added by the MUTEBOT TROJAN! Note - this is not the legitimate systray.exe process
SystrayServices
Added by the CITOR WORM!
SYSTRAYX
"SystrayX helps you hide some of the less used icons from the system tray (the hidden icons can still be seen and used in the special SysTrayX menu but will no longer permanently take precious space from your system tray)"
systree
Added by the BANCOS.L TROJAN!
Systry
Added by the AUTEX WORM!
SYStry
Added by the SDBOT.GN WORM!
Systryt
Added by the AUTEX WORM!
SystUphes
Added by the QQPASS-AM TROJAN!
Systweak Ad and Popup Blocker
Ad and popup blocker part of Advanced System Optimizer from Systweak
Systweak Memory Optimizer
Part of SysTweak Advanced System Optimizer
sysu
Dynamic Desktop Media adware - see here
sysug32.exe
Added by an unidentified TROJAN or WORM!
SysUpd
VirtuMonde adware
sysupdate
Added by a variant of the SDBOT WORM!
Sysvupex
Added by the MEDIAS TROJAN!
sysvx
Added by the LOOSKY-BX TROJAN!
SysW8
Clean Space internet evidence eliminator
SYSWB6
Part of We-Blocker - gives parents the opportunity to monitor their children's Internet access and provide them with age-appropriate content, while filtering out sites that contain adult content. Works in conjunction with Winkb6 and both files are needed to run We-Blocker
SysWin
Added by the IRCCONTACT TROJAN!
syswin
Added by the AGENT-ECM TROJAN!
syswin.txt
Added by a variant of the SPYBOT WORM! See here
syswin32
Added by a variant of the SPYBOT WORM!
Syswindow
Added by the COW TROJAN!
SysWy
Added by the LINEAGE-JH TROJAN! Note - this file is found in the C:WindowsSystem folder, and is not to be confused with the legitimate rundll32.exe file, always located in the Windows folder on Win98/ME systems, and in the WinntSystem32 or WindowsSystem32 folder in WinXP/NT/2K!
sysX3
Added by the RANTS.C WORM!
sysygm32
Added by the IRCBOT-PC TROJAN!
sysygm64
Added by the IRCBOT-RK TROJAN!
SYS_CLEAN
Added by the FLOPCOPY WORM!
Sys_Run
Added by the LINEAGE-N TROJAN!
sys_Runtt1
Added by the LINEAGE-M TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%
sys_up1
Added by the MULTIDR-FL TROJAN!
SyZ
Added by the MSNDIABLO.A WORM!
SyztMy
Added by the LINEAG-AIN TROJAN!
SZMsgSvc.exe
StopZilla! - pop-up killer
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59