Close Program/Task Manager
This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
Operating System Differences
A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Noeton eMail Protect" in the registry.
To avoid the list becoming too large, all VIRUSES are shown using the registry version which is common to all Windows versions.
Alternatively use your browsers search facility - Ctrl+F for IE users.
Key:
"Y" - Normally leave to run at start-up
"N" - Not required - typically infrequently used tasks that can be started manually if necessary
"U" - User's choice - depends whether a user deems it necessary
"X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
"?" - Unknown
Use your browsers search facility - Ctrl+F for IE users.
| X | S0undMan | svch0st.exe | Added by the LOVGATE.AB WORM! |
| ? | S24EvMon | S24EvMon.exe | Event Monitor - supports driver extensions to NIC Driver for wireless adapters. Is it required? |
| X | S3 Internal Chip | s3serv.exe | Added by the AGOBOT-DD WORM! |
| ? | S3apphk | S3apphk.exe | S3 graphics related? |
| ? | S3Hotkey | s3hotkey.exe | S3 Video driver related. What does it do and is it required? |
| ? | S3Mon | S3Mon.exe | S3DuoVue multi-monitor taskbar helper by S3 Graphics. What does it do and is it required? |
| N | S3TRAY | S3Tray.exe | S3 display configuration taskbar utility for S3 chipset based graphics cards. Can be run from Start-> Settings -> Control Panel -> Display |
| ? | s3tray2 | s3tray2.exe | Same as the s3tray entry in this table? |
| ? | S3TRAYHP | S3trayhp.exe | S3 Video driver related. What does it do and is it required? |
| U | S4F | S4F.exe | S4F internet filtering software |
| X | s4helper | s4helper.exe | Searchcentrix hijacker |
| ? | SA | Sa3.exe | Logitech QuickCam driver. Is it required? |
| ? | SA Service | SAservice.exe | Associated with Cyber Trio and Warner troubleshooting software from G-Tek Technologies and pre-installed on some Packard Bell and NEC PCs. What function does this perform and is it required? |
| N | Sa3dsrv | Sa3dsrv.exe | 3D sound extension for Windows |
| X | saap | saap.exe | 180Solutions/N-Case adware variant |
| N | Sabreserver | SABSERV.EXE | Airline reservation software from Sabre. Available via Start -> Programs |
| N | SAClient | RegCon.exe | AT&T or ComCast BBClient - monitors system and network-delivered services for availability. Your current network status is displayed on a color-coded web page in near-real time. When problems are detected, you're immediately notified by e-mail, pager, or text messaging |
| X | Safe | SafeWin.exe | Added by the FOCOSENHA TROJAN! |
| X | SafeGuard Popup Blocker Updater | regsvr32 [path] sfgupd.dll | SafeguardProtect/Veevo hijacker |
| X | SafeGuard Popup Blocker Updater (required) | regsvr32 [path] sfg****.dll [* = ramdom char/digit] | SafeGuard Protect/Veevo - hijacker |
| X | SafeGuard Popup Updater (required) | regsvr32 [path] sfg****.dll [* = ramdom char/digit] | SafeguardProtect/Veevo hijacker |
| X | SafeGuard Popup Updater (required) | regsvr32 [path] PDF****.dll [* = random char/digit] | SafeguardProtect/Veevo hijacker |
| N | SafeInstall.exe | SAFEIN~1.EXE | Monitors a download and ensures an newer version of a file isn't replaced by an older one |
| N | SafeOFF | SafeOff.exe | Provides protection that if user accidentally presses the power switch a dialog will pop up for confirmation |
| X | SafeSearch | safesearch.exe | AutoSearch parasite variant |
| X | SafeSurfingUpdate | SSUpdate.exe | DyFuCa/MoneyTree parasite variant |
| U | Safeworld | Freedom.exe | SafeWorld Internet Security |
| X | Sagate Security Firewall | sagate.exe | Added by the GAOBOT.BOW WORM! |
| N | SAgent2ExePath | SAgent2.exe | Seiko Epson printer status agent. Disable if printer is not used often |
| U | SAGENTSERVICE | Sagent.exe | Added by TinySpyAgent Note - this application must be manually installed |
| X | sagnt | sagnt.exe | Adware web downloader |
| X | SAHagent | Sahagent.exe | ShopAtHomeSelect parasite |
| X | SAHBundle | bundle.exe | ShopAtHomeSelect parasite related |
| X | saie | saie.exe | 180Solutions/N-Case adware variant |
| U | SAIMON | SaiMon.exe | Saitek joystick driver |
| X | sain | sain.exe | 180Solutions/N-Case adware variant |
| X | sais | sais.exe | 180Solutions/N-Case adware variant |
| ? | SaiSmart | SaiSmart.exe | "Smart Button Special Sauce" - included with the latest software for Saitek game controllers. Related to the "S", "Shift" or "Smart" button. What does it do and is it required? |
| U | SaitekAutoConfigure | saicnfig.exe | Configuration for Saitek game controllers |
| X | salm | salm.exe | 180Search adware |
| X | salm | salm.exe | 180Solutions/N-Case adware variant |
| U | SAMcal | SAMcal.exe | SamCal - calendar/reminder program |
| U | Sametime Connect | Connect.exe | IBM Lotus Instant Messaging and Conferencing software |
| N | SandIcon | SandIcon.exe | SanDisk ImageMate CompactFlash card reader SDDR-31 (USB). Very little use except to place the Sandisk icon beside its drive designation in Windows Explorer. The reader itself will work fine without it. The simplest thing is to just unplug the reader when you're not using it. It may slow the startup by a few nanoseconds, but once the software sees there's no reader, you get back the resources |
| X | sapp | sapp.exe | 180Solutions/N-Case adware variant |
| X | saSyncMgr | rundll32.exe sasync.dll, SyncWait | Browser hijacker - redirecting to Searchant.com |
| U | SATARaid | SATARaid.exe | RAID driver for serial ATA disks on some motherboards such as the DFI Lanparty range. Only loaded if one is using RAID support on SATA drives |
| X | satmat | satmat.exe | Transponder parasite updater/installer |
| U | SAUpdate | SAUpdate.exe | Big Brother from Quest Software. System and network monitor |
| Y | SAVAgent | SAVAgent.exe | Part of Sophos anti-virus software. Required for centrally administered Sophos updates to work correctly, e.g. automatically updating PCs used by dial-in home or out-of-office users |
| X | Save | Save.exe | SaveNow adware |
| X | SaveDate | SaveStartDate.Exe | Unidentified adware |
| X | Savenow | SaveNow.exe | SaveNow adware |
| X | Savenow | savenow.exe | Added by the SPREDA.B VIRUS! |
| U | Say The Time 5.0 | SAYTIME.EXE | This program has audio cues for the system clock in male and female voices, customizes the appearance of the system clock, and can synchronize it to a time server regularly |
| U | SB | SB.exe | Acer Soft Button on Acer Tablet PCs |
| N | SB Audigy 2 Startup Menu | /l:eng | Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search function |
| X | SB Watchdog | SBWatchdog.exe | Spyware utility installed by the manufacturers of some laptops (Sony) used to monitor browsing habits and send them back to whoever installed it - released by SoftBank. See here for more information |
| U | SBAutoUpdate | sbautoupdate.exe | SpywareBlaster auto-updater |
| U | SBC Self Support Tool | matcli.exe | matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file. The SBC Self Support Tool is required to run with the Help and Support program. If you uncheck SBC and and then run Help and Support it will add another SBC entry in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decide |
| U | SBDrvDet | SBDrv.exe | Detects the "Easy Front-Panel Audio Connectivity Drive Internal Drive Bay" on the Sound Blaster Audigy 2 Platinium eX. Can be disabled if you don't have one |
| X | SBHC | sbhc.exe | SuperBar parasite - uninstall available here |
| N | SBMX | sbmx.exe | SoundMAX MPU401 MIDI device emulator for x86 VM DOS games/apps (for Win9x only) |
| U | SbUsb AudCtrl | RunDll32 sbusbdll.dll, RCMonitor | Control for Soundblaster MP3 external (USB) sound card |
| N | sc | scrubxp.exe | ScrubXP - utility that deletes safe to remove files, cookies, browsing history, etc |
| U | sc | sc.exe | Watchdog 2.0 Software - monitoring program |
| U | sc | run.exe | All-In-One_SPY stealth monitoring software - allows monitoring and recording of all actions performed on a computer. It records all keystrokes, remembers addresses of Internet pages visited, and maintains a log file listing all applicationsrun on the computer. It can create screenshots and record sounds from the computer's microphone to a sound file |
| ? | sc23exec | sc23exec.exe | Possibly related to a digital camera |
| Y | SC3300CC | SC3300CC.exe | SiPix digital camera Twain device driver |
| X | scan | mscman.exe | Spyware/malware, included into the latest version of Grokster, among others. According to research by SpyBot's PMK, "able to trick ZoneAlarm, auto-clicking it to allow passing through the firewall!" |
| ? | Scan Detector | Pmxdetect.exe | Associated with PrimaScan scanners. Is it required? |
| ? | Scan Wizard | button.exe | Associated with ScanWizard as supplied with Microtek scanners - see also Scanner Detector or SDetect. What does it do and is it required? |
| X | ScanDisk | ScanDisk.exe | Added by the GANDA.A WORM! Note - this is not the valid "ScanDisk" Win9x/Me standard disk error checker |
| X | scands32.exe | scands32.exe | Added by a variant of the Adclicker TROJAN! |
| ? | ScanFile | ?? | ?? |
| ? | ScanInicio | Inicio.exe | Part of Panda Anti-Virus. Responsible for scanning the boot sector of your disk and your memory at startup to check for viruses that try and load and act before your anti-virus is fully operational. It only adds a fraction of a second to start-up time and is worth leaving active |
| N | Scanner Detector | SDetect.exe | ScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the "GO" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the "GO" button |
| X | Scanreg | [filename] | Added by the QQPASS.E TROJAN! |
| X | ScanRegistry | nsrvnt.exe | Added by the NERTE TROJAN!. Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as nsrvnt.exe not scanregw.exe |
| X | ScanRegistry | scanregv.exe | Added by the MASTERLOCK TROJAN!. Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as scanregv.exe not scanregw.exe |
| Y | ScanRegistry | Scanregw.exe | Scans the system registry and makes back-ups at start-up. Important should the registry become corrupt. The executable "Scanregw.exe" is located in %windir% (where %windir% is the Windows directory - C:Windows or C:Winnt) |
| X | ScanRegistry | Scanregw.exe | Added by the STATOR WORM! Not to be confused with the legitimate ScanRegistry entry - which is a vital Windows file. The executable "Scanregw.exe" is located in %windir%System (where %windir% is the Windows directory - C:Windows or C:Winnt). Runs from the registry RunServices key as opposed to the Run key |
| X | ScanSpyware v * | Scanner.exe | Spyware remover (where * = the version number) of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites |
| N | SCardSvr | scardsvr.exe | Related to SmartCard readers and sometimes uses lots of system resources |
| X | SCardSvr | SCardSvr32.Exe | Added by the MOFEI.B WORM! |
| N | Scheduled Maintenance | Scheduled_Maintenance.exe | Scheduler for Iolo System Mechanic tweaking utility. It can cleans your registry and deletes temporary files at defined intervals. Available via Start -> Programs |
| X | Scheduling Agent | Scheduler.exe | Added by the SUBWOOFER TROJAN! Note - this is not the real MS Scheduling agent as the executable is incorrect |
| X | SchedulingAgant | MMTASK.EXE | Added by the YAB.A TROJAN! Not the valid MusicMatch Jukebox which has the same filename |
| U | SchedulingAgent | mstask.exe | MS Scheduling Agent displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting, ScanDisk, etc. Required if you have regularily scheduled events such as weekly virus scans |
| U | SchedulingAgent | mstinit.exe | MS Scheduling Agent displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting, ScanDisk, etc. Required if you have regularily scheduled events such as weekly virus scans |
| U | Schmaili | Schmaili.exe | Schmaili - insert animated smilies into your e-mail |
| Y | SCHWIZEX | SCHWIZEX.EXE | Part of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot |
| X | ScManager | scman.exe | Added by the FORBOT-CW WORM! |
| X | scopedll | scopedll.exe | Added by a variant of the CRYPTER.C TROJAN! |
| N | Scotia OnLine Recovery | etdirrcv.exe | Scotia OnLine Security Software provided by Entrust for Scotiabank. Provides trusted secure access to Scotia OnLine Secure Web sites. *.* represents the version number. Now obsolete after Scotiabank modernised their login process |
| N | Scotia OnLine Security v*.* Recovery | etdirrcv.exe | Scotia OnLine Security Software provided by Entrust for Scotiabank. Provides trusted secure access to Scotia OnLine Secure Web sites. *.* represents the version number. Now obsolete after Scotiabank modernised their login process |
| X | Scr | scr.scr | Added by the OPASERV.T WORM! |
| N | ScrapPad | Scrappad.exe | ScrapPad allows you to quickly and easily record notes, thoughts, messages, and just about anything you want. Use it like you use scrap paper |
| U | Screen Calendar | scrcal.exe | Screen Calendar allows you to create custom desktop wallpapers with built in active calendar and scheduler |
| U | Screen Guard | launch.exe | Part of Access Denied security and privacy software |
| U | Screen Guard Message Scan | sgms.exe | Part of Access Denied security and privacy software |
| N | Screen Saver Control | FSScrCtl.exe | Installs as part of the Hubble Space Telescope screen saver (and possibly others). Lets you control your installed screensavers from a System Tray icon |
| N | ScreenPrint32 | ScreenPrint32.exe | ScreenPrint32 screen capture software - can be launched manually |
| ? | screxe | scruser2k.exe | ?? |
| ? | script | script.bat | Maybe associated with DOS on a Win9x machine |
| Y | ScriptBlocking | SBServ.exe | Update to Norton AntiVirus 2001. Detects certain types of script-based viruses without the need for specific virus definitions - such as JavaScript and VBScript. This will help protect you from these viruses even before virus definitions are available. Note - some users complain of problems once the update is installed - refer here for more information |
| Y | ScriptSentry | Scriptsentry.exe | Script Sentry from Jason's Toolbox. Blocks malicious scripts and allows safe scripts to run. Only required if you want it to check the file associations it guards at startup. It will function regardlessly |
| U | Scroll-In-Mouse V2.0 | SCROLL.EXE | Toolkit for the Lynx-3D Net scroll mouse from QTronix. Required if you use the special features |
| X | ScrSvr | ScrSvr.exe | Added by the OPASERV WORM! |
| X | ScrSvrOld | [worm filename] | Added by the OPASERV WORM! |
| Y | Scsi | Scsi.exe | SCSI Miniport driver |
| X | scvhost | svzhost.exe | Added by a variant of the SPYBOT WORM! |
| X | scvhost loader | ixplore.exe | Added by the SDBOT-CY TROJAN! |
| X | scvhost.exe | scvhost.exe | Added by the LOHAV-N TROJAN! |
| X | sd32info | sd32info.exe | Added by the CRYPTER.A TROJAN! |
| U | SDaemon | sdaemon.exe | PC Security from Tropical Software. 'PC Security™ 5.1 is the ultimate in computer security, offering multiple locking systems for the Windows environment and internet. Lock files, monitor programs' activities, even detect intruders! PC Security offers flexible and complete password protection, "Drag and Drop" support, plus many other handy features' |
| X | SDAv | csnss.exe | Added by the SERFLOG.C WORM! |
| X | SDAv | svhost.exe | Added by the SERFLOG.C WORM! |
| X | sdchosts32 | vbdd.exe | Added by the RANKY.AG TROJAN! |
| N | SDetect | SDetect.exe | ScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the "GO" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the "GO" button |
| X | sdfsdfsdf | sp2update.exe | Added by a variant of the SPYBOT WORM! |
| X | SDIN Adapter | sdin.exe | Added by the FORBOT-AP WORM! |
| ? | SDJobCheck | triggusr.exe | Part of CA Unicenter Software Delivery - manage software across various systems, from desktops and servers to PDAs and mobile phones, in a controlled and standardized way - is it required at startup? |
| X | sdkupdate22 | SDK0mCORE.exe | Added by the FORBOT-DT WORM! |
| N | SDPhotoBar.exe | SDPhotoBar.exe | SmartDraw Photo - "organize, enhance, print, and share your photos. It's also a powerful graphic editor for creating images and web graphics" |
| X | sdrss | sdrss.exe | Added by the SDBOT-SQ WORM! |
| U | sealmon | sealmon.exe | SealedMedia enables you to combine document protection and control with your existing applications - such as Microsoft Word, Microsoft Excel, Microsoft PowerPoint and Email |
| ? | Search Hook | srchhook.exe | ?? |
| X | Search Page | http://find.naupoint.com | Naupoint browser hijacker |
| X | Search-Exe | SE.exe | Search-Exe hijacker |
| X | Search.vbs | Hijacker | |
| X | SearchEnhancement | scbar.exe | IE search hijacker |
| X | searchnav | searchnav.exe | SearchNav adware - IEFeatures/Popnav variant |
| X | SearchNavVersion | searchnavversion.exe | SearchNav adware - IEFeatures/Popnav variant |
| X | SearchSetter | searchsetter[1].exe | Browser hijacker - redirecting to FindWhateverNow.com |
| X | SearchSquire33 | SearchUpdate33.exe | SearchSquire parasite |
| X | SearchUpgrader | SearchUpgrader.exe | Hijacker |
| X | Secboot | w32tm.exe | Added by the HAXDOOR.D TROJAN! |
| U | SecondChance | sctray.exe | Power Quest Second Chance. Sets checkpoints for saving a backup copy of the registry to a disk so you can restore it if you have a crash |
| X | Secret-Crush | start.exe | Hijacker that may reset your browser's home page and/or search settings to point to undesired sites |
| U | Secsys | Secsys.exe | Key Interceptor - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
| X | secure | secure.exe | DealHelper adware |
| N | SecureCleanIEClean | SCIEClean.exe | SecureClean - scans your system for hidden temporary files, deleted email messages, Internet histories and caches |
| U | SecureItPro | Secureitpro470p.exe | SecureIt Pro - lock your computer when you're not there, to stop malicious users from accessing your desktop |
| X | SecureLogin | Mslg32.exe | Added by the REDZED WORM! |
| X | Security Accounts Manager SM | samsm.exe | Added by the SPYBOT.JE WORM! |
| X | Security Agent Manager | mssams.exe | Added by the RBOT-SV WORM! |
| N | Security iGuard | Security iGuard.exe | Spyware remover of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites |
| U | Security Manager | SecurityManager.exe | A ComCast Internet software suite that provides a variety of features (firewall, popup blocker, parental controls etcetera) to help ensure your computer is secure, and your information is kept private |
| X | Security Patches | msnkn.exe | Added by the RBOT.WW WORM! |
| X | security service | syss.exe | Added by an unidentified WORM or TROJAN! |
| Y | SECWIZ98 | SECWIZ98.EXE | Security Wizard 98 by Chris Farmer. Offers you a variety of ways to restrict access to many of the programs and settings on your PC. Available here |
| ? | SelfHostUtil | slefhost.exe | ?? |
| U | SeMS | SeMS.exe | PCsms - tool that enables you to send sms text messages from your PC to any UK mobile phone |
| U | Sensiva | Sensiva.exe | Symbol Commander makes the use of your PC, laptop, Tablet PC, and Pocket PC much easier and much faster. It recognizes your handwriting with unparalled performance and executes commands in a snap. Just by using your mouse, pen, or touchpad, simply draw symbols to execute actions instantly |
| X | SENTRY | SENTRY.exe | From IP Insight. Allows website owners "to instantly determine the precise geographic location, connection speed and detailed demographics of every visitor to your website". Will be detected by most firewalls and the majority of home users should disable it |
| X | Sepate Security Firewall | sepate.exe | Added by a variant of the RBOT WORM! |
| X | Serials | serials.exe | Any one of a variety of worms and trojans |
| X | serpe | formatsys.exe | Added by the SERFLOG.A WORM! |
| X | serpe | msmbw.exe | Added by the SERFLOG.A WORM! |
| X | serpe | serbw.exe | Added by the SERFLOG.A WORM! |
| Y | serrdctl.exe | serrdctl.exe | "Shared Modem Service Client Event Viewer" - used when a number of PCs have access to a number of modems. Required to be running on each PC for access to the modems |
| N | Serv-U | serv-u32.exe | FTP server |
| X | Serv-U | wssdsu.exe | Added by the MANIFEST TROJAN! |
| X | server | server.exe | Added by the DELTAD.A WORM! |
| X | SERVER.EXE | SERVER.EXE | Added by the BUSHTRO122 or SMOKODOOR TROJANS! |
| X | serverex | Server.txt.vbs | Added by the DELTAD.A WORM! |
| U | Service | service.exe | Added by the ALADINZ.H TROJAN! |
| X | Service | services.exe | Added by the NETSKY or NETSKY.B WORMS! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup! |
| X | Service | [trojan filename] | Added by the KAITEX.E TROJAN! |
| X | Service | services.exe | Added by the NETSKY or NETSKY.B WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | Service | SYSNT.exe | Added by the CHA TROJAN! |
| N | Service Connection | sccenter.exe | For Compaq PC's. Part of Backweb |
| N | Service Connection | bwtray.exe | For Compaq PC's. Part of Backweb |
| X | Service Controller | Csrrs.exe | Added by the GAOBOT.AO WORM! |
| X | Service Host | [filename].exe | Added by the TORVEL.B WORM! |
| X | Service Host | spoolxx.exe | Added by the TORVEL WORM! |
| X | Service Host | svchost.exe | Added by the TORVEL WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | Service Host Driver | svchost.exe | Added by the HITON TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| N | Service Manager | sqlmangr.exe | SQL Server Service Manager - provides tray access to SQL server, the server agent and MSDTC. Available via Start -> Programs |
| X | Service Manager | dxsound.exe | Added by the PROXY-GRIC TROJAN! |
| X | Service Process | SVCHOST.EXE | Added by the DARKER WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | Service Process | winset.exe | Added by a variant of the SPYBOT WORM! |
| X | service updaer | qualityz.exe | Added by an unidentified VIRUS, WORM or TROJAN! - probably a SPYBOT variant |
| X | Service.exe | Service.exe | "servedby.advertising" popup generator |
| U | ServiceConfig | ispbeg.exe | Comcast Transition Wizard. On June 30th, 2003 it will migrate E-mail and web pages from AT&T Broadband Internet to Comcast High-Speed Internet. Until then it will run at startup and then terminate - hence the U recommendation |
| Y | ServiceLayer | ServiceLayer.exe | Nokia Connectivity Library support task that is needed by NCLTRAY and by the Nokia Connection Manager for either to work properly |
| X | services | start.bat | Added by the ZCREW TROJAN! |
| X | Services | [path to trojan] | Added by the METEORSHELL TROJAN! |
| X | Services | back32.exe ...service.exe | Added by an unidentified VIRUS, WORM or TROJAN! Back32.exe is the baddie whose purpose is to HIDE the MIRC32 server in service.exe |
| X | Services | services.exe | Added by a number of VIRUSES, WORMS and TROJANS! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup! |
| X | Services | winread.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Services | windns.exe | Added by a variant of the RBOT WORM! |
| X | Services Controller | lsassa.exe | Added by the CIADOOR.122 VIRUS! |
| X | Services Host | Scchost.exe | Added by the DONK WORM! |
| X | Services Logon | services.exe | Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | Services Process | services.exe | Added by unidentified spyware - recognized by Kaspersky antivirus as Small.X TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | Services Startup | services.exe | Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | Services Startup | svhost33.exe | Added by a variant of the RBOT WORM! |
| X | Services.EXE | services.exe | Added by the KAZPING WORM! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup! |
| X | services.exe | Services.exe | Added by the CIADOOR-F TROJAN! Note - this is NOT the legitimate services.exe process, which should NOT figure in Msconfig/Startup! |
| X | Services004 | [worm filename] | Added by the BUGBROS WORM! |
| ? | ServUTrayIcon | ServUTray.exe | System Tray icon for Serv-U FTP server. Is it required? |
| X | SESync | sed.exe | Downloadware/SED adware downloader |
| ? | SetDefaultMIDI | MIDIDef.exe | Related to a Soundblaster Audigy soundcards. What does it do and is it required? |
| ? | setdefprt | setdefprt.exe | Related to a Brother printer? |
| U | SetecCertUtil | Certutil.exe | Setec Web and Email Security. Setec PKI smart card software. The PKI technology enables secure and reliable user identification in services offered through Internet, mobile handsets and digital TV |
| X | setFTPBack | createsw.exe | Added by the FTP_BMAIL TROJAN! |
| N | SetHook | SetHook.exe | Fellowes Neato CD label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar" |
| N | SETI@home | SETI@home.exe | SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data |
| N | seticlient | SETI@home.exe | SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data |
| N | SetIcon | SetIcon.exe | Installed by a 6-in-1 (4 Media Card slots, a floppy drive and a USB connection) device. Constantly updates the icons for the four Media Card slots that it has and is a resource hog |
| N | SetiQueue | Setiqu~1.exe | Provides work unit buffering for Seti@Home clients - see here for more details |
| N | SetiSpy | SetiSpy.exe | From the site - 'SETI Spy is a little program I wrote to "spy" on the progress and performance of the SETI@home client. I call it a "spy" because I tried to make it as unobtrusive as possible' |
| ? | SetRefresh | SetRefresh.exe | Found on a Compaq PC. Video refresh rate utility? Is it required? |
| X | Setting | sysweb.exe | Added by the SDBOT.GEN TROJAN! |
| N | setup | hphprld.exe ....setup.exe | HP DeskJet Setup - printers function normally without it |
| X | Setup experation | svchost.exe | Added by the TOFGER-AW TROJAN! Note - this is not the legitimate svchost.exe process, which NOT appear in Msconfig/Startup! |
| N | SetupICWDesktop | icwconn1.exe | Appears to be the "Internet Connection Wizard" from Internet Explorer being set-up as a desktop shortcut. Appears under the RunOnce registry key but is available under Start -> Programs -> Accessories -> Communication (or similar) anyway |
| X | setupuser | regedit.exe setupuser.log | Regfile in disguise - another CoolWebSearch parasite variant |
| ? | setuzp | setuzp.exe | ?? |
| X | SetVrc | setvrc.exe | Added by the HUNTOCX WORM! |
| X | Sex Teris | st01b.exe | Added by the REPAD WORM! |
| X | Sexy_sg | Sexy_sg.exe | Premium rate adult content dialler |
| N | SFP | vzSFPWin.EXE | Verizon Online Support Center - prompts for online updates |
| X | SFtrb Service | cftrb32.exe | Added by the SOBIG.D WORM! |
| U | SfWinStartInfo | sfWinStartupInfo.exe | SFIRM32 Online Banking software |
| U | Sgecrypt | Sgecrypt.exe | SafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks" |
| U | Sgeecview | Ecview.exe | SafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks" |
| N | sginst | sginst.exe | eAcceleration Stop-Sign related - not recommended, see note |
| ? | SGTBox | SGTBox.exe | Canon scanner driver. Is it required? |
| U | sgtray | sgtray.exe | StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups |
| X | shambl3r | cnf.bat | Added by the REMABL WORM! |
| X | shambl3r* | shambl3r.exe | Added by the REMABL WORM! where * is 2 to 11 |
| N | Share-to-Web Namespace Daemon | hpgs2wnd.exe | "HP's exclusive Share-to-Web software makes it easy to share content with others through our affiliate Internet websites." In other words an application that allows users to upload scanned images to their personal webpages if desired. Available via Start -> Programs |
| N | Shareaza | Shareaza.exe | Shareaza P2P client |
| X | sharedprem | sharedprem.exe | Added by the MAKECALL TROJAN! |
| Y | Sharing and Mapping Software | DShmap.exe | Intel AnyPoint internet sharing software |
| N | SharkEject | AEJCT32.exe | Allows you to eject a disk from the Avatar Shark drive from the system tray. When loaded, there is a desktop icon so this isn't required |
| N | Shcenter | chcenter.exe | IMSI HiJaak - "the easiest way to convert, capture, and manage all your graphic files" |
| X | SheduIer | svchst.exe | Premium rate adult content dialler |
| X | Shell | Shell32.exe | Added by the BADSECTOR TROJAN! |
| X | Shell | ray.exe | Homepage hijacker re-directing browsers to adult content websites |
| X | Shell | Tray.exe | Homepage hijacker re-directing browsers to adult content websites |
| X | Shell | wmedia16.exe | Added by the GOLDUN TROJAN! |
| X | Shell | Open32.exe | Horseserver.net browser hijacker |
| X | Shell Extension | spollsv.exe | Added by a variant of the LOVGATE WORM! |
| X | Shell32 | Shell32.vbs | Added by the SCAFENE WORM! |
| X | ShellApi | SHELLMSN.EXE | Added by the NETDEV.B TROJAN! |
| X | Shellapi32 | Shellapi32.exe | Added by the NETDEVIL (or NERTE) TROJAN! |
| X | ShellCommand | [path to file] | Added by the REMCON-A TROJAN! |
| X | ShellEx | ShellEx.exe | Added by the ANAKHA TROJAN! |
| X | shellsystem | shellsystem.exe | Added by the UPCHAN TROJAN! |
| N | shicoxp | shicoxp.exe | Installed with the drivers for multi card readers of various brands. To differentiate between the various card slots on multi slot readers the shicoxp.exe file assigns and loads unique drive icons for the various card slots that are displayed in Windows Explorer |
| X | Shine | Shine.exe | Added by the HAPPYLOW (or NISHE-A) VIRUS! |
| ? | SHINITV | shinitv.exe | ?? |
| X | Shmgrate.exe | ibot4.exe | Added by the GASTER TROJAN! |
| N | ShockmachineReminder | SmReminder.exe | Shockmachine is an entertainment playback device that lets you save your favorite Shockwave.com titles and play them back in full-screen mode, off-line, anytime. Could be a registration reminder for the trial version |
| X | Shockwave | csrss.exe | Added by the SNDOG WORM! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
| N | Shockwave Init | SWINIT.EXE | Part of Macromedia Shockwave. Controls the Shockwave Remote Control Panel. The Remote Control can be activated manually from the Start Menu by locating and selecting Shockwave and then Shockwave Remote under Programs |
| N | ShortKeys 99 | SHORTKEY.EXE | ShortKeys from Insight Software Solutions - allows you to program keys with text strings |
| X | Showbehind | SHOWBEHIND.EXE | Advertisement display which can be stopped here |
| ? | ShowIcon_SmartDisk Corporation_USB Card Reader v1.14e051 | shwicon.exe | Card reader for memory cards from digital cameras. Is it required? |
| U | SHPC32 | SHPC32.exe | Port monitor for Lexmark printers on a USB connection. Ties in with the Printer Control Program. Features like cancelling a print are unavailable if disabled |
| Y | ShStatEXE | SHSTAT.EXE | From McAfee VirusScan NT 4.x. Handles program communication among VShield components, displays VShield icon. Can be started automatically or available via Start -> Programs |
| U | Shutdownaware | shutdownaware.exe | Loaded by the SWEEX 6-in-1 Media Card Reader to properly manage the reader while it is connected to your system |
| U | ShutDownPro | ShutDownPro.exe | ShutDownPro - shutdown, reboot, logoff your System with one mouse click |
| ? | Si Meter | SIMETER.EXE | ?? |
| X | si91e44b | rundll32.exe [path] si91e44b.dll, EnableRunDLL32 | LZIO.com adware downloader |
| X | Sicom | Sicom.exe | Added by the NETLIP WORM! |
| U | SideACT | SideACT.exe | SideACT organizer software |
| X | Sidebar | Sidebar.exe | Searchcentrix hijacker |
| N | SideWinderTrayV4 | SWTrayV4.exe | MS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs |
| ? | SigX | sigx.exe | ?? |
| X | SigXC | SigX.exe | SigX is a "dynamic signature image generated based on whatever data your computer sends it though our SigX program. It can display your current Mp3, current OS, Free Ram, your current time and more" |
| N | Simcast | SimcastAlerts.exe | Simcast is a free service that allows you to subscribe to information on a large variety of topics. Alerts will appear on your desktop when a channel that you have subscribed to has something to say |
| U | SimpLite-MSN | SimpLite-MSN.exe | Required if you use the SimpLite add-on to MSN Messenger (SimpLite adds encryption to the instant messaging service) |
| X | Singapore | singapore.exe | Adds a blue crescent to the taskbar and when double-clicked displays an adult-content web-site. Also known to drop your internet connection and dial an international telephone number. See here for more information. Must be disabled in MSCONFIG before un-installing or it re-instates itself |
| U | SIPPS | SIPPSSIPPS.exe | Web.de Internet phone utility |
| N | SiS KHooker | khooker.exe | SiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required |
| U | SiS Tray | sistray.exe | System Tray icon for SiS based graphics. Note - this resides in C:WindowsSystem |
| U | SiS Windows KeyHook | keyhook.exe | SIS graphics cards related: "Super VGA Keyboard Daemon" - hooks into the keyboard processing chain in order to enable hotkey settings |
| ? | SISAM10M | SISAM10M.exe | ?? |
| N | SiSAudio | MP_S3.exe | WinME patch for an older SiS 961 chipset FERR bug. Enable if you have audio problems |
| U | siscolor | color.exe | Probably on-board graphics related based upon the SiS chipsets. Has been seen on ASUS motherboards with SiS chipsets and known to cause conflicts if you choose another graphics card and disable the on-board |
| U | siService.exe | siService.exe | Spam Inspector - anti email spam software |
| ? | SiSSetCDfmt | SiSSetCDfmt.exe | Related to a Silicon Integrated Systems Corp (SiS) product? |
| ? | SISSoundman | Soundman.exe | Related to a Silicon Integrated Systems Corp (SiS) product? |
| U | SiSSWLED | sisswled.exe | System Tray utility for SiS 900 network cards |
| X | sistrai.exe | sistrai.exe | Added by the PROVA TROJAN! |
| X | sistray | sistray.exe | Added by the PROVA TROJAN! |
| U | sistray | sistray.exe | System Tray icon for SiS based graphics. Note - this resides in C:WindowsSystem |
| X | Sistray32 | remotehost.pif | Added by the HOLCAS.A WORM! |
| X | Sistray32 | win.bat | Added by the JUMPRED.A WORM! |
| X | sistry | sistry.exe | Added by the CEBE WORM! |
| N | SiSUSBRG | SiSUSBrg.exe | SiS USB Registry Patch File - fixes the undetectable problem with SiS USB controller on Windows XP |
| X | sixtysix | sixtypopsix.exe | Unidentified adware |
| U | SK9910DM | SK9910DM.EXE | Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys |
| U | SKDAEMON | SKDAEMON.EXE | Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys |
| U | skinkers | skinkers.exe | Selection of desktop messaging/marketing tools with celebrity tie-ins including MTV's "Desktop Ozzy" and Arsenal's "Desktop Wenger" - see here. Leave enabled if you want to receive messages |
| Y | SkyBlaster Scheduler | SSFSch.exe | For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system |
| X | skynetave.exe | skynetave.exe | Added by the SASSER.D WORM! |
| X | SkynetRevenge | winlogon.scr | Added by the NETSKY.AA WORM! |
| N | Skype | Skype.exe | "Skype is free and simple software that will enable you to make free calls anywhere in the world in minutes" |
| Y | SkySurfer Management Service | SmaServ.exe | For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system |
| N | SleepManager | SleepMgr.exe | This program locates free contiguous disk spaces and allocates them for storing BASE MEMORY, EXTENDED MEMORY, VIDEO MEMORY, and SM RAM. It helps the computer come out of hibernate mode |
| U | SlickRun | sr.exe | "SlickRun is a floating command line utility for Windows. It gives you almost instant access to any program or website. SlickRun allows you to create command aliases (known as MagicWords), so C:Program FilesOutlook Expressmsimn.exe becomes MAIL" |
| X | slide | Iexplore.exe | Added by the GASLIDE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
| N | slimp3 | SliMP3 Server.exe | Slimp3 Server - "presents an entirely new way of accessing and enjoying your music collection. Instead of storing your music on CDs or memory cards, the SliMP3 uses your home network to access the music stored on your PC" |
| N | Slingshot | SLINGS~1.EXE | Atomica Slingshot - "reference tool with access to dictionary and encyclopedia terms, bios, technical terms, history, geography, and much more" |
| X | slmss | slmss.exe | SeekSeek search hijacker related - as seen here |
| X | slvchost32 | slvchost32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| ? | SM1BG | SM1BG.EXE | USB driver for downloading from within Napster to portable MP3 players. Is it required to run at startup or can it be run manually? |
| N | Sm56acl | sm56hlpr.exe | Helper utility for Motorola based SM56 software modems - resides in the System Tray |
| N | Smapp | smtray.exe | System Tray access for the Compaq/ADI SoundMAX integrated digital audio controller |
| N | Smart Card Service | ScardSvr.exe | For Smart Card readers. Known to cause problems, especially for Windows 2000 users - see here. Probably not required unless you use such a device regularly |
| U | Smart Connect Monitor | SCMon.exe | Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio |
| U | Smart Connect Setup | SCSetup.exe | Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio |
| N | Smart Label O Server | ssloserv.exe | Part of the printer software for the smart-label printer made by Seiko. Can be disabled safely |
| N | Smart Label RFViewer | SSLFVIEW.EXE | Part of the printer software for the smart-label printer made by Seiko. Can be disabled safely |
| N | Smart Type Assistant | sta.exe | Smart Type Assistant - a complex typing automation tool, intended to make your work faster and safer |
| U | Smartalec | pcaccel.exe | Smartalec PC Accelerator - system optimization utility |
| N | SmartBarXP | SmartBarXP.exe | SmartBarXP is a bar that runs down the side of your screen, and can be configured to display interactive panels known as 'panes'. These panes include media players, slideshow and image viewing panes, a virtual desktop manager, and live news, weather and stock feeds to mention but a few |
| N | sMaRTcaPs | SMARTC~1.EXE | sMaRTcaPs from Phoebus LLC - enables you to configure the time needed to depress Caps Lock, Num Lock & Insert keys |
| ? | Smarthruengine | QS.exe | Unknown but disabled without problems |
| U | SmartPCXL | pcaccel.exe | Smartalec PC Accelerator - system optimization utility |
| N | SMax4 | SMax4.exe | System Tray icon for SoundMax integrated sound. Sound properties can be accessed through the Start Menu or Control Panel |
| U | SMax4PNP | SMax4PNP.exe | SoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments |
| ? | smbdpmi | smbdpmi.exe | IBM Netfinity Director and Universal Management Services related. What does it do and is it required? |
| Y | smc | smc.exe | Sygate Firewall |
| Y | smc | spfsmc.exe | Sygate Firewall |
| Y | SMC Service | smc.exe | Sygate Firewall |
| Y | SMC Service | spfsmc.exe | Sygate Firewall |
| X | smcserv | winsrv.exe | Added by the AGOBOT-OU WORM! |
| Y | SmcService | smc.exe | Sygate Firewall |
| Y | SmcServices | smc.exe | Sygate Firewall |
| Y | SmcServices | spfsmc.exe | Sygate Firewall |
| ? | Smcsta.exe | Smcsta.exe | SMC Networks wireless PCI card driver. Is it required? |
| N | Smith Micro try | smiptray.exe | Smith Micro shared files. Comes with D-Link web cam |
| U | SMS Application Launcher | LAUNCH32.EXE | Microsoft Systems Management Server - used to manage computers on a network remotely |
| U | SMS Client Service | clisvc95.exe | When the SMS Client service starts on a domain controller, the Client service modifies the SMSCliToknAcct & user account group membership, user rights, and account comment. The Client service then waits for the synchronization of the comment to verify that the account and user rights are properly set for this account. This account is used to obtain a token to start the SMS Client processes, such as the Software Inventory and Software Distribution agents (MS Systems Management Server) |
| U | SMS Win9x Message Agent | ?? | This program assigns a user to a Systems Management Server site |
| U | SMS Win9x Message Agent | SMSMsg.exe | This program assigns a user to a Systems Management Server site |
| Y | Smserial | sm56hlpr.exe | Motorola based modem driver |
| N | SMSI Loader | SMLoader.exe | Smith Micro HotFax - fax software |
| X | SMSS | smss.exe | Added by the FLOOD.F TROJAN! Note - this is not the legitimate Smss.exe system file should normally NOT figure in Msconfig/Startup! |
| X | smss | [path to smss.exe] | Added by the ALADINZ.F TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup! |
| X | SMSSS | smsss.exe | Added by the SDBOT.ZD WORM! |
| X | SMSSS Loader | smsss.exe | Added by the AGOBOT.MQ WORM! |
| X | smsys | Explorer.exe | Added by the CLICKER-C TROJAN! Note - the valid "explorer.exe" is located in C:Windows or C:Winnt whereas this one is located in a C:WindowsTemplate or C:WinntTemplate subdirectory |
| X | smsys | vi.exe | Adult content dialler |
| N | SMToolbar | SMToolbar.exe | StartMake.com toolbar |
| ? | SmWizard | SmWizard.exe | SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required? |
| X | snapple | snapple.exe | Added by the FORBOT-EG WORM! |
| ? | snbr | snbr.exe | ?? |
| X | sncntr | sncntr.exe | Added by the DLUCA-I TROJAN! |
| X | Sndcompat | Sndcompat.exe | Added by the GEMA TROJAN! |
| U | SNDMon | SNDMon.exe | Part of Symantec's LiveUpate (eg, Norton). Not required if you run manual upadtes but probably require if you leave them to run automatically. Also, if one runs a small office network and SNDMon is disabled on one of the computers – then other computers disappear from the network for this computer, including shared devices like printers and scanners. Hence the "U" recommendation |
| X | Sndsaver | Sndsaver.exe | Added by the GEMA TROJAN! |
| ? | sndsrvc | SNDSRVC.EXE | Part of Norton Personal Firewall and Norton Internet Security - what does it do and is it required? |
| N | Snsicon | Snsicon.exe | Launches a screensaver program from Second Nature |
| ? | SO5 Integrator Pass One | sointgr.exe | StarOffice 5. See here for more details |
| ? | SO5 Integrator Pass Two | sointgr.exe | StarOffice 5. See here for more details |
| X | Soar | Rwon.exe | PurityScan/Clickspring adware |
| X | Social Security Agency | rpcxsocsa.exe | Added by a variant of the RBOT WORM! |
| X | Sock32 | sock32.exe | Added by the SDBOT TROJAN! |
| Y | SoDA Startup | SodaStartup.exe | Used by the Rational SoDA project management tool. Unsure of it's actual purpose but it's recommended you leave it enabled if you use the software |
| N | soffice | SOFFICE.EXE | Displays StarOffice quick start applet in System tray. Right clicking on the icon allows rapid starting up of components of the StarOffice 6.0 suite. Available via Start -> Programs. Automatically started when any StarOffice 6.0 component is started from the Start -> Programs. A resource hog (it eats > 16 MB of memory). |
| X | Soft Profile Inc | hxdef.exe... | Added by a variant of the LOVGATE WORM! |
| Y | SOFTinst | N/A | For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out |
| X | Software | software.exe | Added by the CRABTON-B TROJAN! |
| Y | Solo Sentry | Solosent.exe | Solo Antivirus |
| U | SoloSchedule | Solocfg.exe | Scheduler for Solo Antivirus. Leave enabled unless you scan manually on a regular basis |
| U | SoloSysCheck | Syscheck.exe | Solo antivirus System Integrity Check - Monitors system registry, system.ini, win.ini and startup to protect you from new Internet Worms and Backdoors |
| X | somatic | somatic.exe | Searchcentrix hijacker |
| N | Sonic A3D Control | vrtxctrl.exe | Sound related options |
| N | SoniqueQuickStart | sqstart.exe | Quickstart for Sonique audio player. Available via Start -> Programs |
| ? | SonnReg | SonnReg.exe | Part of E-Color 3Deep for color calibration. Possibly a registration reminder? |
| ? | Soot | rcea.exe | ?? |
| ? | sophagnt | sophagnt.exe | Possibly related to Sophocles Screenwriting Software? |
| X | SOS | SOS.exe | Added by the PHILIS VIRUS! |
| ? | SoSyncMonitor | SoSyncMonitor.exe | SuperOffice related. What does it do and is it required? |
| X | Sound Loader | sndloader.exe | Added by the AGOBOT-BV WORM! |
| X | Sound services | SOUND32.EXE | Added by the AGOBOT.GG WORM! |
| X | Sound System | WinSound1.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | soundcontrl | soundcontrl.exe | Added by the GAOBOT.AFJ WORM! |
| X | sounddrv | sndbdrv3104.exe | CoolWebSearch parasite variant |
| ? | SoundFusion | rundll32 cwcprops.cpl | Control panel item for the Terratec DMX Xfire 1024 soundcard (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time? |
| ? | SoundFusion | rundll32 hercplgs.cpl, BootEntryPoint | Control panel item for Hercules Fortissimo soundcards (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time? |
| N | soundman | soundman.exe | System Tray icon for the Realtek AC97 Audio Sound Manager for AC97 onboard audio. Available via Start -> Settings-> Control Panel |
| N | SoundMAX | SMax4.exe | System Tray icon for SoundMax integrated sound. Sound properties can be accessed through the Start Menu or Control Panel |
| U | SoundMAXPnP | SMax4PNP.exe | SoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments |
| X | SoundMixer | smvss.exe | Added by the DEDLER-G TROJAN! |
| X | Soundmx | Soundmx.exe | CoolWebSearch parasite variant |
| X | soundtask | soundtask.exe | Added by the AGOBOT-MD WORM! |
| X | soundtasks | soundtasks.exe | Added by a variant of the CRYPTER.C TROJAN! |
| X | soundtctrls | soundtctrls.exe | Added by the AGOBOT-ZV WORM! |
| X | SoundView | msdview32.exe | Trojan downloader |
| X | sounofts | sounofts.exe | Added by the AGOBOT-ND WORM! |
| N | SourcePath | gwreg.exe | Used to update Gateway registry settings for System Restoration Kit and Web update programs |
| X | sp | sp.reg | IE search hijacker - changes the default search to http://www.gocybersearch.com/ |
| X | sp | regedit-s .... sp.dll | Malicious javascript annoyance that changes the default search engine in IE to one of many including "topsearcher". See here for more and a fix |
| X | sp | se.dll, DllInstall | Added by the Startpage.M hijacker |
| U | SP TimeSync | SP TimeSync.exe | SP TimeSync lets you synchronize your computer's clock with any Internet atomic clock (time server) |
| X | SP00LSV | Sp00lsv.exe | Added by the GRAYBIRD.E TROJAN! |
| X | sp2chk.exe | sp2chk.exe | Added by the ALUROOT.A TROJAN! |
| X | sp2ctr | sp2ctr.exe | Added by the DLUCA-M TROJAN! |
| U | Spam Sleuth | SpamSleuth.exe | Spam Sleuth E-mail spam detection program |
| U | spamihilator | spamihilator.exe | Spamihilator - spam filter |
| U | SpamPal | spampal.exe | SpamPal - anti-spam tool |
| U | SpamSubtract | SpamSubtract.exe | Intermute SpamSubtract - junk email detection and removal program |
| N | spc_w | hcm.exe | NetZero Search related |
| N | Spdstart | Spdstart.exe | Norton Utilities Speed Start. "This feature optimizes the start up speed of launching applications, such as Word and Excel." |
| U | Speaking Clock Deluxe | SpClDlx.exe | Speaking Clock Deluxe - turns your computer into a speaking clock with several languages. It can also keep track of up to 50 alarms that can be set to a time and a date, and be repeated daily, weekly, monthly and yearly |
| X | Special Firewall Service | avguard.exe | Added by the NETSKY.G WORM! |
| X | SpecialOffers | SpecialOffers*.exe [* = digit] | SpecialOffers adware |
| X | SpecialOffers | SpecialOffers.exe | SpecialOffers adware |
| N | Speed racer | CTSRReg.exe | Software for a Creative sound card |
| U | Speed Tec | speedtec.exe | Accel SpeedTec from Montana Software speeds up your modem. SpeedTec modifies the Internet Protocol settings in the Windows registry to speed downloads on all modems. If you find this improves your connectivity and download speeds leave this enabled |
| X | SpeedBoss | [worm filename] | Added by the OPASERV.AD WORM! |
| U | Speedkey | SPEEDKEY.EXE | Additional keyboard shortcuts on MS programmable keyboard |
| U | SpeedMeter | SpeedMeter.exe | Application measuring upload and download speed |
| U | SpeedOptimizer | spo.exe | SpeedOptimizer is designed to optimize and speed-up your Internet data transmission including browsing, streaming, downloading, uploading and e-mail communication |
| U | Speedtouch USB Diagnostics | Dragdiag.exe | For an external Alcatel ADSL high-speed modem. A diagnostic tool and can be run from the Start menu when required. The only reason it might be useful on startup is if you like seeing an 'at-a-glance' status indicator on the taskbar (the icon is a different colour depending on the status of the device/line) |
| X | Spees1 | speedy.scr | Added by the OPASERV.Y WORM! |
| X | Spees2 | Speedy.bat | Added by the OPASERV.AD WORM! |
| X | Spees3 | SPEEDY.PIF | Added by the OPASERV.AD WORM! |
| N | Spellex Anywhere | sa.exe | Spellex-Anywhere - adds spell checking functionality to almost any Window program. Create a shortcut and run manually before it's to be used |
| Y | SpIDerMail | spiderml.exe | DrWeb antivirus Spider Mail e-mail scanner |
| N | Spinner Plus | spinner.exe | "Spinner Plus lets you listen to over 100 channels of music broadcast from Spinner.com. Spinner Plus uses RealNetwork's G2 technology to provide high-quality online audio. The technology adjusts the audio streaming to match your Internet connection speed, which helps eliminate sound distortion or choppiness". Available via Start -> Programs |
| X | SPINX | Wscript.exe OXNEY.B.VBS | Added by the YENO.B and YENO.C WORMS! |
| X | SPnt | SPnt.exe | Premium rate adult content dialler |
| U | SpokeSysTray | SpokeSysTray.exe | Spoke Software client application. Spoke "uses data in your e-mail and other enterprise information systems to discover the existing relationships of people in your enterprise. It then builds a private, secure relationship network for each user without any additional manual data entry" |
| X | spoo1sv | spoo1sv.exe | Added by the SOULJET TROJAN! |
| X | Spool | [path to trojan] | Added by the RANKY.R TROJAN! |
| X | SPOOL Configuration | spoolsvc.exe | Added by the SDBOT-KD WORM! |
| X | Spool lptt01 | spool.exe | Variant of the RapidBlaster parasite (in a "spool" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | Spool ml097e | spool.exe | Variant of the RapidBlaster parasite (in a "spool" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | Spooler Service | Spoolsrv.exe | Added by the JOINER.C1 TROJAN! |
| X | Spooler Sub System Process | SPOOL32.EXE | Added by the YAB.A TROJAN! |
| X | Spooler Subsytem App | spoolsvc.exe | Added by the SDBOT-MM WORM! |
| X | SpoolerSubSystemProcess | SpooI32.exe | Added by the EHKS.21 keylogger! Note - the "I" between "o" and "3" is a captial "i" not a lower case "L" |
| X | spoolserv | spoolserv.exe | Added by the SDBOT-PN WORM! |
| X | SpoolService | spolsv.exe | Added by the AGOBOT-CS WORM! |
| X | Spoolsv | Spoolsv.exe | Added by the CIADOOR.121 VIRUS! Note - "Spoolsv.exe" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file |
| X | spoolsv | scvhosts.exe | Added by the SMALL-AW TROJAN! |
| X | spoolsv manager | SpoolMgr.exe | Added by the ASSIRAL WORM! |
| X | spoolsvr32 | csmss.exe | Added by the AGENT-AU TROJAN! |
| X | spoolsvr32 | csmss32.exe | Added by a variant of the AGENT-AU TROJAN! |
| X | SPOOLSVU | SPOOLSVU.EXE | Added by the Startpage.K hijacker |
| X | spoolsvv | spoolsvv.exe | Searchcentrix hijacker |
| X | Spore | MsNews.vbs | Added by the SPORE.A WORM! |
| X | Spore.b | Scmhlpr.vbs | Added by the SPORE.B WORM! |
| ? | SPP | run.exe | ?? |
| X | spp | regedit -s spp.reg | IE search hijacker - changes the default search to http://www.hotsearchbox.com/ie/ |
| ? | sppbridge | sppbridge.exe | Associated with an Anycom bluetooth wireless card on laptops - used for printing to portable printers for example. Is it required or can it be started manually? |
| ? | SprintPort | SprintPortA.exe | Novatel wireless modem related. What does it do and is it required? |
| U | SPSTEALT | SmartProtectorPro.exe | Smart Protector Pro - internet privacy tool that erases tracks, MRU lists, etc |
| ? | spstore | storesp.exe | Softprobe - program designed to provide managers with an analysis of an individuals computer use who are under their supervision. This program is NOT related to Winpup |
| U | Spy Blocker | spyblocker.exe | SpyBlocker blocks the communications of spyware installed on a PC so spyware runs but can't exchange data with the server to which it should report. Ensuring spyware can't communicate is important, as you may find after using Ad-Aware that some applications containing spyware subsystems may not run correctly or at all |
| X | SpyBlast | SpyBlast.exe | Spyware killer that is in effect autoinstalled foistware, targeted by SpyBot, among others |
| U | SpyBlocker | spyblocker.exe | SpyBlocker blocks the communications of spyware installed on a PC so spyware runs but can't exchange data with the server to which it should report. Ensuring spyware can't communicate is important, as you may find after using Ad-Aware that some applications containing spyware subsystems may not run correctly or at all |
| X | SpyBlocs | SpyBlocs.exe | Rogue anti-spyware program |
| U | SpybotSD TeaTimer | TeaTimer.exe | TeaTimer is a new tool of Spybot S&D - spam filter which perpetually monitors the processes called/initiated. It immediately detects known malicious processes wanting to start and terminates them giving you some options, how to deal with this process in the future |
| U | SpyBotSnD | Spybotsd.exe | Spybot - Search & Destroy - free multi-spyware removal tool from Patrick Kolla |
| X | Spybott lptt01 | spybott.exe | Variant of the RapidBlaster parasite (in a "Spybott" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | Spybott ml097e | spybott.exe | Variant of the RapidBlaster parasite (in a "Spybott" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| U | SpyCop ScanCheck | MAIN.EXE | SpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan |
| N | SpyHunter | SpyHunter.exe | SpyHunter - spyware remover of somewhat dubious repute, see note |
| U | Spykiller | Spykiller.exe | Shareware "Spyware remover" of questionable quality and repute. There are better alternatives that are freeware to boot |
| X | SpyNuker | Spynuker.exe | A "spyware removal program" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers ‘TrekData’ and ‘Blue Haven Media’, who distribute spyware through ActiveX drive-by-download on web pages |
| N | SpySpotter | SpySpotter.exe | Spyware remover of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites |
| U | SpyStopper | spystopper.exe | SpyStopper - blocks intrusive spyware, Web bugs, worms, scripts, advertisements, and cookies. Protects you from being profiled and tracked |
| U | SpySubtract | SpySub.exe | SpySubtract - multi spyware removal tool |
| U | SpySweeper | SpySweeper.exe | Spy Sweeper - detects and removes spyware |
| X | Spyware | Spyware.exe | BPS Spyware Remover - reportedly uses an old, "borrowed" SpyBot database. Read this and this. Do not support these guys! |
| N | Spyware Begone | SpywareBeGone.exe | Spyware BeGone - free spyware removal utility. Not recommended - see note |
| N | Spyware Begone | freescan.exe | Spyware BeGone - free spyware removal utility. Not recommended - see note |
| U | Spyware Doctor | spydoctor.exe | Spyware Doctor spyware remover |
| U | Spyware Doctor | swdoctor.exe | Spyware Doctor spyware remover |
| U | Spyware Guard Control Panel | spywar~1.exe | "SpywareGuard provides a real-time protection solution against spyware" |
| X | Spyware Nuker Installer | SpywareNukerInstaller.exe | A "spyware removal program" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers ‘TrekData’ and ‘Blue Haven Media’, who distribute spyware through ActiveX drive-by-download on web pages |
| X | Spyware remover | Remove_spyware.exe | Unidentified, but not known to belong to any known spyware remover, and strongly suspected to be adware related! |
| U | Spyware Scanner | AseScanner.exe | Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here and here |
| X | Spyware Slayer | SpywareSlayer.Exe | Spyware remover of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites |
| N | Spyware Stormer | SpywareStormer.Exe | SpywareStormer spyware remover. Not recommended - see here |
| X | Spyware Vanisher | FreeScanner.exe | Spyware remover of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites |
| U | SpywareGuard | sgmain.exe | "SpywareGuard provides a real-time protection solution against spyware" |
| X | SpywareGuard | winproc32.exe | Startpage adware Trojan |
| X | Spywareguard lptt01 | Spywareguard.exe | Variant of the RapidBlaster parasite (in a "Spyguard" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | Spywareguard ml097e | Spywareguard.exe | Variant of the RapidBlaster parasite (in a "Spyguard" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | SpywareGuardPlus | winmm64.exe | StartPage.ht homepage hijacker |
| N | SpywareKilla | SpywareKilla.exe | Spyware remover of ill repute. For more info about it do a search for 'SpyareKilla' at this web page on "Rogue/Suspect Anti-Spyware Products & Web Sites" |
| U | SPYWATCH | SpyWatch.exe | BPS Spyware Remover - reportedly uses an old, "borrowed" SpyBot database. Read this and this. Do not support these guys! |
| X | SQConfigChecker | cc.exe | Xupiter SQWire variant - adware and homepage hijacker. Note - cannot be removed via the Xupiter website in the same way as other Xupiter variants |
| X | SQInstaller | SQInstaller.exe | Xupiter hijacker |
| N | SQL Server | scm.exe | SQL Server Service Control Manager. Available via Start -> Programs |
| X | SQUpdatesChecker | uc.exe | Xupiter SQWire variant - adware and homepage hijacker. Note - cannot be removed via the Xupiter website in the same way as other Xupiter variants |
| X | sqvynikp | sqvynikp.exe | Free_Scratch_Cards foistware |
| ? | sr1exe | updtSup3.exe | Found on a Dell computer, in a Documents and SettingsAll UsersApplication DataDellAlert2 subfolder |
| X | sr64 | ********. exe | Adware, as yet unidentified |
| X | SrchfstUpdate | srchupdt.exe | SearchFast adware downloader |
| ? | SRFirstRun | rundll32 srclient.dll, CreateFirstRunRp | Created by execution of the Windows XP sr.inf file, which installs the Windows XP System Restore feature, needed for example when installing System Restore into Windows Server 2003. Does this indeed need to run at every bootup? |
| U | Srmclean | srmclean.exe | Srmclean helps in the installation and execution of the SoundMax SoftPaq for Compaq/ADI SoundMax Integrated Digital Audio. According to Compaq - "If you disable the entry from loading into startup, then you will not be able to use the features of the sound card" |
| X | SRNG | srng.exe | Search hijacker - see here |
| U | SRP Startup | srrpro.exe | System Restore Remover Pro allows you to safely and easily remove System Restore and various other Windows Millennium "features." This is enabled if you tick the "Remove unnecessary System Restore information on startup" box. Available via Start -> Settings -> Control Panel |
| Y | SRS Applet | SrsTray.Exe | S3 Sonic Vibes sound card drivers - if disabled you loose sound |
| X | Srv RPCrom | NClienti386.exe | Added by the WATSOON.A TROJAN! |
| X | Srv32 | Srv32.exe | Added by the OPASERV.J WORM! |
| X | Srv32 | Srv32.exe | Added by the OPASERV.S WORM! |
| X | Srv32 spool service | runsrv32.exe | Topantispyware.com malware, recognized by Kaspersky antivirus as Trojan-Clicker.Win32.Spyre.b |
| X | Srv32 spool service | spoolsrv32.exe | Topantispyware.com malware, recognized by Kaspersky antivirus as Trojan-Clicker.Win32.Spyre.b |
| X | Srv32Old | [worm filename].PIF | Added by the OPASERV.J WORM! |
| U | Srv32Win | SpyAgent4.exe | SpyAgent - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
| U | Srv32Win | Svchost.exe | Realtime-Spy keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove |
| X | Srv32Win | sysdiag.exe | NetVizor keystroke logger |
| X | srvexc.exe | srvexc.exe | Added by the SERVSAX TROJAN! |
| X | ssate.exe | irun4.exe | Added by the BEAGLE.J WORM! |
| X | ssate.exe | winsys.exe | Added by the BEAGLE.K WORM! |
| N | SSBkgdUpdate | SSBkgdupdate.exe | ScanSoft OmniPage auto updater. Can be disabled using the main program's options |
| ? | SSC_UserPrompt | UsrPrmpt.exe | Part of Symantec (Norton) Security Centre. What does it do, and is it required? |
| Y | Ssd | Std.exe | Stealthdisk - file and folder hiding/locking utility |
| ? | ssdiag | ssdiag.exe | Equinox "Configuration and DOS Diagnostic for DOS and Windows platforms" |
| N | SSDPSRV | ssdpsrv.exe | Simple Service Discovery Protocol (SSDP) and General Event Notification Architecture (GENA) services for network plug and play functionality. Starts up a web server on port 5000. Used by Universal Plug and Play (for network device discovery). To remove this program, open Add/Remove Programs, select either Communications (Me) or Networking Services (XP), and remove the checkmark next to Universal Plug and Play |
| X | ssgrate.exe | system.exe | Added by the MITGLIEDER.C TROJAN! |
| X | ssgrate.exe | irun.exe | Added by the MITGLIEDER.D TROJAN! |
| X | ssgrate.exe | irun4.exe | Added by the MITGLIEDER.F TROJAN! |
| X | ssgrate.exe | sysdoor.exe | Added by the MITGLIEDER.N TROJAN! |
| X | ssgrate.exe | winerdir.exe | Added by the MITGLIEDER.O TROJAN! |
| X | SSK Service | winssk32.exe | Added by the SOBIG.E WORM! |
| X | SSL | svchost.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| U | ssmmgr | ssmmgr.exe | Samsung printer monitor - for checking ink levels, etc. |
| X | sstata | dwdas.exe | Added by the DASDA TROJAN! |
| X | SStb.exe | SStb.exe | Adpowerzone.com "ServerSide" keyword hijacker |
| N | sstray | sstray.exe | nVidia nForce Taskbar Utility - quick access to the nForce2 "Sound Storm" control panel and related utilitys |
| X | SSUpdate | SSUpdate.exe | DyFuCa/MoneyTree parasite variant |
| X | ssvchost | ssvchost.exe | Added by the HELIOS.B TROJAN! |
| X | SSWPlauncher | comet.exe /app:SSWPlauncher | CometCursor by Comet Systems |
| N | Stacmon | Stacmon.exe | Installed with the drivers for a SigmaTel C-Major Audio card (on a Dell Inspiron 600m PC for example). Appears as though it can be disabled with no ill effects |
| Y | Start | Quick95.exe | For a Nisis G6 USB Graphics Tablet. Re-enables itself if disabled therefore best left alone |
| X | Start | windows.vbs | Homepage hijacker |
| ? | start | start.exe | ?? |
| X | start extracting | spoolvse.exe | Added by a variant of the RBOT WORM! |
| N | Start Getright | getright.exe | See Getright Tray Icon |
| X | Start Page | http://find.naupoint.com | Naupoint browser hijacker |
| Y | Start RF Wireless Keyboard | ktrexe.exe | Yuanxun Electronics RF wireless keyboard driver |
| Y | Start RF Wireless Mouse | cm20.exe | Yuanxun Electronics RF wireless mouse driver |
| U | Start Service | upssrv.exe | Cyber Power PowerPanelPlus software. "In the event of a power outage, PowerPanelPlus Software automatically saves and closes all open files, and then shuts down the computer system in an intelligent and orderly manner" |
| U | Start Up Cop | startcop.exe | StartUp Cop - startup manager |
| X | start uploading | smsss.exe | Added by a variant of the SDBOT WORM! |
| X | Start Upping | taskmrg.exe | Added by the RBOT-MA WORM! |
| X | Start Upping | SVCHOSTES.EXE | Added by the RBOT-NB WORM! |
| X | Start Upping | taksmgr.exe | Added by the RBOT-QK WORM! |
| X | Start Uppings | svcchosts.exe | Added by the SDBOT.VY WORM! |
| X | Start Uppings | mssupdate.exe | Added by a variant of the RBOT WORM! |
| N | Start Wingman Profiler | lwtest.exe | Logitech Wingman software required to operate Logitech joysticks and gamepads. Unless you're a hard-core gamer, it's best to leave it unchecked |
| N | Start Wingman Profiler | lwemon.exe | Logitech Wingman software required to operate Logitech joysticks and gamepads. Unless you're a hard-core gamer, it's best to leave it unchecked |
| U | Startacc | startacc.exe | Launches Webroot's Accelerate 2000 software that "speeds up your Internet connection by up to 300%". Leave enabled if you find it improves internet connection |
| Y | StartEAK | StartEAK.exe | Easy Access Button Support for Compaq PCs. Required if you use these |
| X | starter | scvhosting.exe | Added by the IRCBOT.E TROJAN! |
| X | Starter | scvhosting.exe | Added by the SDBOT.RU WORM! |
| N | startl.exe | startl.exe | Lingocom LingoWare - translates any application into your language |
| X | StartMenu | s_menu.exe | Added by a variant of the DELF-A TROJAN! |
| X | startpage | startpage.exe | Browser hijacker - redirecting to pages2start.com |
| U | STARTPAGE | start1.exe | NoSpy.org - prevents spyware from changing your startpage and other browser properties. The start1.exe file is located in a NOSPY.ORG folder |
| U | StartStop | STARTSTOP.EXE | StartStop from TFI Technology - startup manager |
| U | StartSurfing | STARTS.exe | Start Surfing allows you to protect your privacy while surfing and searching the Internet by acting as a "filter" between you and the website you are visiting. Startsurfing acts as your shield from Pop Up Windows, Mouse Traps, Window Resizing, and scripts that attempt to record your personal information. Available via Start -> Programs |
| N | Startup | ?? | Related to an Iomega drive |
| ? | Startup Launcher GUI | GUI.exe | Startup manager? |
| X | Startup Update | Cvshost.exe | Added by the GAOBOT.AO WORM! |
| U | StartupMonitor | StartupMonitor.exe | Mike Lin's StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu |
| X | startwindowskeyuser | rundle2.exe | Added by the JAVAKILLER TROJAN! |
| N | Stat 'n' Perf | StatnPerf.exe | Stat 'n' Perf monitors your internet connection and displays information about sent and received bytes |
| X | StatBar | STATBAR.exe | StatBar (system status bar) allows you to quickly get an overview of your system's condition (memory, CPU, uptime, and much more). Due to the sheer number of resources (over 60%) consumed by this program, it is unsuitable for Windows 95/98/SE/Me |
| N | Status Monitor | BrMfcWnd.exe | Brother scanner status monitor - can be started manually |
| N | Status Monitor XE | ENGSS.EXE | The Xerox Document WorkCentre XE Series Status Monitor displays information about your printer and currently active or waiting print jobs. You can use it to control your printing environment and manage your printing operations. Available via Start -> Programs |
| ? | StatusClient | StatusClient.exe | Part of Hewlett Packard network printer drivers |
| ? | StatusClient 2.6 | StatusClient.exe | Part of Hewlett Packard network printer drivers |
| N | Stay Connected! | StayCon.exe | More than just a pinger, actually simulates online activity. Supports AOL, NetZero, MSN, ATT WorldNet, CompuServe and many other ISPs as well. Available via Start -> Programs |
| U | StayAlive | sa.exe | StayAlive from TFI Technology. "This top-notch tool intercepts crashes when they happen, keeping your programs running so you can save your work." |
| ? | STBVision | STBVisn.exe | Related to the STB Velocity graphics card. What does it do and is it required? |
| N | STBWEBTV | STBWEBTV.EXE | Used to display TV on your PC |
| X | stcinstaller | id53.exe | Added by the SCTHOUGHT.L TROJAN! |
| X | stcloader | stcloader.exe | Popup adware by 2ndThought software |
| X | stcloader | STCLOA~1.exe | Popup adware by 2ndThought software |
| X | STCLOA~1 | stcloader.exe | Popup adware by 2ndThought software |
| X | STCLOA~1 | STCLOA~1.exe | Popup adware by 2ndThought software |
| Y | STCPO | STCPO.exe | Sophos Sweep antivirus software |
| U | Stealth Anonymizer 2.5 | stealth25.exe | Now named Stealther - proxy server agent that lets you travel the Internet with maximum possible privacy |
| N | Steam | steam.exe | Valve Software's STEAM broadband game client. Steam is Valve's new way of getting games into your hands ASAP. Games like Half-Life, Counter-Strike, and Counter-Strike: Condition Zero are all being made available through Steam. Steam games are automatically kept up-to-date with the latest content and revisions. Steam also includes an instant-message client which even works while you're in-game |
| N | Stickies | STICKIES.EXE | Stickies - utility that allows you to put yellow "Post-It" type messages on your desktop and can be used to set reminders. Available via Start -> Programs |
| N | Sticky Notes | stikynot.exe | Microsoft Sticky Notes - virtual sticky notes tool |
| N | StickyNote | StickyNote.exe | Utility that allows you to put yellow "Post-It" type messages on your desktop. Available via Start -> Programs |
| U | StillImageMonitor | Stimon.exe | Stimon.exe enables a USB still-image device (such as a scanner) to initiate data transfer to a program. For example, if your scanning device has a scan button, it may start a program and begin scanning when you press it. Create a shortcut and start it manually when needed if your scanner otherwise fails to scan. May be required for your USB scanner to work - including all HP scanners and some of their SCSI scanners |
| X | stlbdist | rundll32exe stlbdist.DLL, DllRunMain | Hijacker pointing to www.searchandclick.com |
| X | stlbupdt | rundll32.exe stlbupdt.DLL, DllRunMain | BrowserAid/Startium parasite |
| N | STManager | drst.exe | Dr. SpeedTouch is some sort of diagnostics software which sends out information to a server which then relays the information back to the program to test the network to see if the SpeedTouch ADSL modem connection is working properly. Not required if connected via Ethernet (and probably USB). Can cause a slow down in Win2K - see here |
| X | stmha | wkfxi.js | Added by the SPETH WORM! |
| N | StopSignStatus | stopsinfo.dll", VerifyStatus | eAcceleration Stop-Sign related - not recommended, see note |
| U | STOPzilla | Stopzilla.exe | StopZilla! - pop-up killer |
| U | STOPzilla Service | SZNTSVC.EXE | StopZilla! - pop-up killer |
| U | StorageGuard | sgtray.exe | StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups |
| ? | STPMGR | STPMGR.EXE | Part of SafeTP which is transparent FTP security software. Does it need to be running permanently or can it be started manually via Start -> Programs |
| X | Strng32 | strngbox.exe | Added by the STRANO WORM! |
| X | StubPath | Sservice.exe | Added by the PRORAT TROJAN! |
| U | StyleXP | StyleXP.exe | StyleXP allows you customize the way WinXP looks. If disabled via msconfig it re-instates itself at reboot, therefore uninstall it if you don't want it |
| N | Subtract the Ads | AdSub.exe | Removes adverts from web pages. Although useful - not required |
| U | Suitcase Startup | Suitcase.exe | Suitcase. System font manager start up utility. Used for dynamic managment of fonts on your system |
| X | Suite | SuiteOffices.exe | Added by the LAZAR TROJAN! |
| X | SULFNBJ.EXE | SULFNBJ.EXE | Added by the PE_MAGISTR.DAM VIRUS! |
| X | SunJavaUpdate | smvss.exe | Added by the DEDLER-G TROJAN! |
| N | SunJavaUpdateSched | jusched.exe | Checks with Sun's Java updates site to see if newer Java versions are available. Visit http://java.sun.com or just run the Java Plug-In Control Panel |
| U | Sunkist | shwicon98.exe | Card reader for memory cards from digital cameras, etc |
| U | Sunkist2k | shwicon2k.exe | Card reader for memory cards from digital cameras, etc |
| ? | SupaDial | SupaDial.exe | SupaNet.com modem driver related - is it required? |
| N | Supastatus | status.exe | Supanet ISP software |
| U | Super Popup Blocker | popkill.exe | Saga Super Popup Blocker - pop-up stopper |
| U | SuperAdBlocker | SAdBlock.exe | SuperAdBlocker |
| X | SuperBar.Component | [path to services.exe] | Added by the SMALL-AQ TROJAN! |
| U | Supercleaner | Supercleaner.exe | Supercleaner - all in one disk cleaner for your computer |
| U | SuperCool Compress Backup | Main.exe | "SuperCool Zip Backup software is a data backup,restore and file synchronization program" |
| X | supernews12 | newsd32.exe | Unidentified adware |
| X | Supernova | [worm filename] | Added by the SURNOVA (or SUPOVA) WORM! |
| X | superslut | msslut32.exe | Added by the SLUTER-A WORM! |
| U | SuperSpamKiller Pro | Ssk.exe | SuperSpamKiller Pro email spam blocker |
| X | Supervisor.exe | Supervisor.exe | Has been reported to be associated with various antitrojan software like ATS and PC Doorguard. If so it's required in Startup - any further information is welcome |
| X | supporter5 | supporter5.exe | Part of eScorcher anti-virus software- responsible for updates of new virus bases each time you logon to the web. Used to collect information about the user and therefore treated as spyware - now the web-site is dead |
| U | SureCleanProfessional | SRClean.exe | SureClean PC and Internet tracks cleaner |
| U | Sureshotpopupkiller | Stopthepop.exe | Stop-the-Pop-Up popup blocker |
| X | SurfBuddy | rundll32 [path] sbuddy.dll | SurfBuddy adware - not to be confused with the legitimate SurfBuddy application by SurfApps! |
| U | SurfChoice | SCMan.exe | SCMan is a utility that can control services on WinNT from the command line. This utility can create, start, pause, stop, delete services. Furthermore it can retrieve a service's current state, get the displayname for a service and vice versa |
| X | Surfer lptt01 | surfer.exe | Variant of the RapidBlaster parasite (in a "mssurfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | Surfer ml097e | surfer.exe | Variant of the RapidBlaster parasite (in a "mssurfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| U | SurfinGuard Pro | winsfcm.exe | SurfinGuard Pro - internet protection software |
| U | SurfSecret | ss2-full.exe | "House-cleaning utility that enables you to keep your computer usage to yourself. Runs quietly from the system tray, eliminating tell-tale files at a regular interval of your choosing. You can set it to clear your Internet cache files, cookies, history, temp folder, etc. It can also clear the history of your Run and Find menus, in addition to the AOL cache" |
| X | SurfSideKick 2 | Ssk.exe | SurfSideKick adware |
| U | SurfStream | SurfStream.exe | Conceiva "SurfStream lets you surf the Web faster. It contains a fully featured proxy server that lets you surf the Web significantly faster. It also blocks all pop-up windows and banner ads from Web pages. An intelligent tune-up tool automatically analyzes and optimizes your computer's Internet connection and TCP/IP settings" |
| X | Surs | awab.exe | PurityScan/Clickspring adware |
| ? | Surveysa | surveysa.exe | Found in the SonyVaiosurvey directory on a Sony Vaio PC. What does it do and is it required? |
| X | Susp | Susp.exe | Transponder parasite updater/installer |
| X | Sustem | explorer.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | SustemUpdate | explorer.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | SVA Player | SVAplayer.exe | QuickFlicks Streaming Player - regarded as spyware. See here for details of how to disable or uninstall it |
| X | Svc | svc.exe | Hijacker, Clientman parasite variant, redirecting to madfinder.com. Detected by Symantec as the MADFIND TROJAN! |
| X | SVC Service | svcinit.exe | Added by the SINIT TROJAN! |
| X | SVC Service | svcinit.exe | CoolWebSearch parasite variant |
| X | SVC Service | svcpack.exe | CoolWebSearch parasite variant |
| X | SVC Socks | mstaskm.exe | CoolWebSearch parasite variant |
| X | Svced | Svced.exe | Added by the DELF.F TROJAN! |
| X | SvcH0st | msexploren.exe | Added by the BACKDOOR-CGZ TROJAN! |
| X | svchost | Svch0st.exe | Added by the GRAYBIRD.B TROJAN! |
| X | SVCHOST | svchost.exe | System1060 homepage hi-jacker. Found in a WindowsSystem1060 directory. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | svchost | svchost.exe | Added by the MORB WORM or TARNO TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | SVCHOST | mrowyekdc.exe | Added by the GOTORM WORM! |
| X | svchost | Svch0st.exe | Added by the GRAYBIRD TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | svchost | [path to trojan] | Added by the HAZZER TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | svchost | ADMAGIC.EXE | Added by the SMIBAG WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | Svchost | winhost.exe | Added by the LOLAWEB.A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | Svchost | svchost.exe | Added by the MOXE-A WORM! This is not the valid svchost.exe as described here |
| X | SVCHOST | var.txt.exe | Added by the LDPINCH.C TROJAN! |
| X | Svchost | svchosl.pif | Added by the INZAE.A or INZAE.B WORMS! |
| X | svchost | [path] SETUP.EXE | Added by the SETCLO WORM! |
| X | svchost | [path] SETUP.EXE | Added by the SETCLO WORM! |
| X | SVCHOST | scvhost.exe | Added by the MYTOB.E and MYTOB.G WORMS! |
| X | SVCHOST | taskgmr.exe | Added by the MYTOB.F or MYTOB.H WORMS! |
| X | svchost.exe | svchost32.exe | CoolWebSearch parasite related. Note - this is not the valid svchost.exe as described here |
| X | svchost1 | svchost1.exe | Added by the AGOBOT.ZZ WORM! |
| X | SvcHost32 | svchost32.exe | Added by the MIMAIL.I or MIMAIL.J WORMS! |
| X | svchost64 | svchost64.exe | Added by the SDBOTER.G VIRUS! |
| X | svchostr | svchostr.exe | Added by an unidentified WORM or TROJAN! |
| X | svcinfo | svcinfo.exe | Added by the CRYPTER.A TROJAN! |
| X | svcroot | svcroot.exe | Added by the KEYLOG-AC TROJAN! |
| X | svcsys32 | svcsys32.exe | Added by the AGOBOT-LL WORM! |
| X | svcwinprocess32 | [path to worm] | Added by the UPERING WORM! |
| X | SVHOST | svhost.exe | Added by the MYDOOM.I WORM! |
| X | SVHOST | SVHOST.EXE | Added by the ZORI.A VIRUS! |
| X | Svhost Loader | svshost.exe | Added by the AGOBOT.G WORM! |
| ? | SVIDC32M | SVIDC32M.exe | ?? |
| X | sVideo2 | vxdrun6.exe | Switch premium rate adult content dialer |
| ? | SVM Pop | svmpop.exe | ?? |
| X | svphost.exe | svphost.exe | Added by the AGENT.CS TROJAN! |
| X | svrrun | svrrun.exe | Adware hailing from Deskwizz.com |
| X | svshost | svshost.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | svshost32 | msgrsv32.exe | Added by the RANKY.AJ TROJAN! |
| X | svshostdriver | svshost.exe | Added by the SDBOT-HN TROJAN! |
| X | svwin32 | unninst32.exe | Added by the AGOBOT-NF WORM! |
| X | SVX Control Service | svxhost.exe | Added by the FORBOT-K WORM! |
| N | Swap Nut | javaw.exe | SwapNut is a peer-to-peer file sharing and searching utility developed and marketed by File Metrics, Inc. Users can search for and find almost any type of digital file (audio, video, photos etc.) through a secure peer-to-peer network |
| X | SWCaller | SWcaller.exe | Homepage hijacker - see here |
| X | SWCaller | Swcaller2.exe | Homepage hijacker - see here |
| N | SWd | winwd.exe | PC Security from Tropical Software - lock files, password protect, etc |
| Y | Sweep95 | ICLOAD95.EXE | Part of Sophos ant-virus sofware |
| X | Swf32 | AVupdate.exe | Added by the MERKUR WORM! |
| X | Swf32 | _backup.exe | Added by the SYMTEN WORM! |
| X | SwimSuitNetwork | SwimSuitNetwork.exe | Advertising spyware |
| U | Switch Off | swoff.exe | Switch Off - tray-based system utility that can automatically perform various frequently used operations like shutdown or restart your computer, disconnect your current dialup connection, lock workstation, etc |
| N | Switchboard.com Toolbar | AtHoc.exe | Toolbar for the on-line version of Yellow Pages in the US - Switchboard.com |
| X | sws.exe | [random filename] | Haldex type adult content dialler |
| N | SwTray | SWTRAY.EXE | MS SideWinder game controller system tray icon. Available via Start -> Programs. May have the version number after it |
| N | SWTrayV4 | SWTrayV4.exe | MS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs |
| ? | SXGDSENU | sxgdsenu.exe | Yamaha SXG soundcard driver |
| ? | SxgTkBar | sxgtkbar.exe | Yamaha SXG soundcard driver |
| ? | Sxplog | sxpstub.exe | Part of CA Unicenter Software Delivery - manage software across various systems, from desktops and servers to PDAs and mobile phones, in a controlled and standardized way - is it required at startup? |
| X | SYDNEY | [file path] | Added by the SYNEY WORM! |
| X | Sygate Personal Firewall | Win32x.exe | Added by the RBOT-KZ WORM! |
| X | Sygate Personal Firewall | system32.exe | Added by the RBOT.VI WORM! |
| X | Sygate Personal Firewall | sysgut.exe | Added by the SDBOT.WM WORM! |
| X | Sygate Personal Firewall | Sygate.exe | Added by the RBOT-PN WORM! |
| X | Sygate Personal Firewall | Mcafeeupdate.exe | Added by the RBOT.YN WORM! |
| X | Sygate Personal Firewall | Sygate32.exe | Added by the SDBOT.WW WORM! |
| X | Sygate Personal Firewall Start | services32.exe | Added by the RBOT-MB WORM! |
| X | Sygate Personal Firewall Start | servic.exe | Added by the RBOT-RY WORM! |
| X | Sygate Personals Firewalls | ccsrn.exe | Added by a variant of the RBOT WORM! |
| U | SyGateService | sgserv95.exe | SyGate is a useful little program that lets you share an internet connection over an intranet. Is it needed - it saves a lot of headache to just let SyGate load at startup. Available via Start -> Programs |
| X | Symantec Anti Virus | symantec32.exe | Added by a variant of the WOOTBOT WORM! |
| X | Symantec Configuration Loader | ccApp32.exe | Added by a variant of the GAOBOT WORM! |
| Y | Symantec Core LC | symlcsvc.exe | Part of Norton AntiVirus 2004. What does it do? |
| N | Symantec Fax Starter Edition Port | OLFSNT40.EXE | Offers a virtual printer as a fax machine. Can be run via a desktop shortcut |
| U | Symantec NetDriver Monitor | SNDMon.exe | Part of Symantec's LiveUpate (eg, Norton). Not required if you run manual upadtes but probably require if you leave them to run automatically. Also, if one runs a small office network and SNDMon is disabled on one of the computers – then other computers disappear from the network for this computer, including shared devices like printers and scanners. Hence the "U" recommendation |
| X | Symantec Security | symantec32.exe | Added by the RANDEX.PR or RANDEX.YR WORMS! |
| X | Symantec Security Addon | nvsvc.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Symantec Security Routine Addon for Microsoft Windows | navpxaw32.exe | Added by the AGOBOT-GJ TROJAN! |
| X | Symantec Service | ccApp.exe | Added by the AKHER.D WORM! Note - this is also not the valid Norton AV file with the same filename |
| X | SymAV | SymAV.exe | Added by the NETSKY.U WORM! |
| U | SymKeepAlive | CKA.exe | Part of Norton SystemWorks 2003 - keeps a dial-up modem connection alive |
| N | SymTray - Norton SystemWorks | SYMTRAY.EXE | Keeps all System Tray icons for Norton SystemWorks together to reduce clutter. SystemWorks includes Norton Anti-Virus, Norton Utilities and Norton CleanSweep - mentioned elsewhere here. Personally I only have Norton eMail Protect running which doesn't need SymTray |
| U | Sync Data | Hndsync.exe | Pocket Real Estate - mobile synchronization manager |
| X | Sync Server | drwatsoon.exe | Added by the WATSOON.A TROJAN! |
| U | Sync-It | Syncit.exe | Sync-It - synchronizes the system clock with time servers on the internet |
| U | SyncAgent | syncagent.exe | Ghost Keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove |
| N | Synchronization Manager | mobsync.exe | Find more information about its use here |
| ? | SynSetup | SynTP.tmp RunOnce.exe | Probably associated Synaptics touchpads on laptops as for the SynTPEnh and SynTPLpr entries but what does it do and is it required? |
| X | Syntax Script | systacq.exe | Added by the SDBOT.AI WORM! |
| U | SynTPEnh | syntpenh.exe | Synaptics touchpad tray icon. Displays status and provides quick launch to touchpad features such as scrolling and tap zones. Required on IBM Thinkpads with UnltraNav (pointstick and touchpad combo) if you don't want to loose the advanced pointstick features such as scroll |
| Y | SynTPLpr | syntplpr.exe | Synaptics touchpad driver helper. Required for touchpad features to work |
| X | sys | regedit /s sys.reg | Hijacker |
| X | sys | sysdllwm.reg | CoolWebSearch parasite variant |
| X | Sys Ren | SysRen.exe | Unidentified malware |
| X | Sys29 | win***32.exe [* = random char] | EliteBar adware |
| X | sys32 | sys32.exe | Added by the FLUX.E TROJAN! |
| U | sys32cmd | sys32win.exe | Active Keylogger monitoring software - also see here. From the Symantec article: "This spyware program must be manually installed. However, there are several known programs that have Spyware.ActiveKeylog within them and that install it as the program itself is installed". Disable/remove if you didn't install it |
| X | sys32dll | sys32dll.exe | Added by the AIMDES.B WORM! |
| X | SysA | win***32.exe [* = random char] | EliteBar adware |
| U | SysAgent | SysAgent.exe | SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of |
| X | SysAI | SysAI.exe | AproposMedia adware - also creates SysAI folder in Program Files where the SysAI.exe is also located |
| U | Sysbot | sysbot.exe | Spector - spying (or monitoring) software to record internet activity |
| X | syscfg | syscfg32.exe | Added by the KWBOT.S WORM! |
| X | syscfg34.exe | syscfg34.exe | Added by the ELECTRON WORM! |
| X | Syscheck | win.hta | Browser hijacker |
| X | syscheck | iexplorer.exe | Added by the AGENT.DM TROJAN! |
| X | syscm | Syscm.exe | Vanish adware |
| ? | SysComp | mssdnl.com | Unknown but suspect as *.com are not usually run at start up and the name isn't recognized |
| X | syscon lptt01 | syscon.exe | Variant of the RapidBlaster parasite (in a "Syscon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | syscon ml097e | syscon.exe | Variant of the RapidBlaster parasite (in a "Syscon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | sysconfig | iexplorer.exe | Added by the CULT.C WORM! |
| X | SysConfig | syscfg35.exe | Added by the KAZMOR.C WORM! |
| X | sysconfig | iexplorer.exe | Added by the CULT.H WORM! |
| X | SysConfig | wincfg32.exe | Added by the SDBOT.ZD WORM! |
| U | Sysconfig | Stealth KeySpy.exe | Added by StealthKeySpy commercial keylogger |
| X | Syscpy | Syscpy.exe | Firewall-bypassing, proxied spam relayer. Detected by Symantec as the HOGLE TROJAN! |
| X | SysCtl | sysctl.exe | Added by the AOK TROJAN! |
| X | Sysctrls | procdll.exe | Added by the WEEDBOTZ.14 TROJAN! |
| X | sysdir | winrun.exe | Added by the WINBUR.B WORM! |
| X | Sysdpt | sysdpt.exe | Win32.Crypt trojan downloader |
| X | sysfiler | sysfiler.exe | Added by the RETSAM TROJAN! |
| X | SYSfit | SYSfit.exe | AdShooter adware variant |
| X | sysflg32 | sysflg32.exe | Added by a variant of the CRYPTER.C TROJAN! |
| X | syshelp | syshelp.exe | Added by a variant of the LOVGATE WORM! |
| X | sysinfo | sysinfo.exe | Added by the BEDRILL TROJAN! |
| X | sysinfo.exe | sysinfo.exe | Added by the BEAGLE.V WORM! |
| X | SysInit | wininit32.exe | Added by the XABOT WORM! |
| X | sysinit | services.exe | Added by the NEWLFRM-A TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | Sysino | lsess.exe | Added by the FORBOT-BF WORM! |
| X | sysint16 | sysint16.exe | Added by the CRYPTER.A TROJAN! |
| X | Syskey | sysinit.exe | Added by the BEAGLE.AX WORM! |
| X | Syslib | Syslib.exe | Adult content related downloader trojan |
| X | Syslog lptt01 | Syslog.exe | Variant of the RapidBlaster parasite (in a "Syslog" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | Syslog ml097e | Syslog.exe | Variant of the RapidBlaster parasite (in a "Syslog" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | syslogin.exe | syslogin.exe | Added by the BAGZ-B WORM! |
| U | SysMetrix | SysMetrix.exe | SysMetrix - skinnable clock and metering application. It monitors and reports on a great number of statistics |
| X | sysmon | sysmon.exe | Added by the BIZEX WORM! |
| X | Sysmon | rpcmon.exe | Added by the RANDEX.ATX WORM! |
| X | sysmon | sysmon44.exe | Added by a variant of the BACKDOOR-CBA TROJAN! |
| X | sysmonnt | sysmonnt.exe | Transponder parasite related |
| X | SysMonXP | SysMonXP.exe | Added by the NETSKY.Q WORM! |
| X | sysnate | sysnate.exe | Added by the MEDIAS TROJAN! |
| X | SysOps | SysOps | Added by the MSNCORRUPT TROJAN! |
| X | syspath | drv.exe | Added by the SOBER WORM! |
| U | SysPilot | fdxxl.exe | G Data "PC Spion" - monitoring and surveillance software, captures all users activity on the PC, see here. Disable/remove if you didn't install it yourself! |
| X | sysPnP | bootconf.exe | Homepage hijacker, redirecting to coolwwwsearch.com; see for example here |
| X | SysPnP | rundll32 setupapi, InstallHinfSection.... oemsyspnp.inf | Search hijacker - see here |
| Y | SysPool | Mssvc.exe | StealthDisk - hides folders, files and applications. Will also encrypt them for better protection |
| X | SysProtect | System.exe | Added by the NETSPY TROJAN! |
| X | SysR | sysmd.exe | Adult content based "foistware" (adds hidden components to your system) |
| X | SysReg | SysReg.exe | Added by the CHEKIN TROJAN! |
| X | SysReg | SysReg.exe | SearchSeekFind textual marketing foistware |
| X | Sysres | Sysres.exe | Added by the LOGMOD TROJAN! |
| X | SysRes | TASKMANAGER.exe | Added by the ELIPTER.A WORM! |
| X | SysRes | WWE DIVAS.exe | Added by the ELIPTER.D WORM! |
| X | SysScan | bvt.exe | Added by the AUTOUPDER TROJAN! |
| X | SysSearch | Regedit.exe -s [path] pcsearch.reg | Added by the StartPage-FN browser hijacker |
| X | SysSearch | REGEDIT.EXE -s [path] sysreg.reg | Added by the STARTPA-ME TROJAN! |
| X | sysser | [path to file] | Added by the RAHACK WORM! |
| X | SysService | SysService.exe | Added by the DELF family of TROJANS! |
| X | SysService32 | SysService32.exe | Added by the KINDAL VIRUS! |
| X | SysService32 | ln32k.dll | Added by the KINDAL VIRUS! |
| X | SysService32l | systask32l.exe | Added by the THEUG WORM! |
| X | SYSsfitb | SYSsfitb.exe | Searchforit browser hijacker |
| X | SysStrt | systemc.exe | Added by the AGOBOT-QA TROJAN! |
| X | System | run322.exe | Added by the LANFILT TROJAN! |
| X | System | system.exe | Added by various WORMS and TROJANS! |
| X | system | regedit -s system.dll | Homepage hijacker |
| X | system | systemsearch.hta | Jetseeker.com hijacker |
| X | System | dcomx.exe | Added by the CIREBOT TROJAN! |
| X | system | Explorer.exe | Added by the GRAYBIRD TROJAN! Note - this is located in this is located in C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K), or C:WindowsSystem32 (WinXP) rather than the valid Windows Explorer which is located in C:Windows or C:Winnt |
| X | System | YPager.exe | Added by the JUNTADOR.K TROJAN! Note - this is not Yahoo! Messenger |
| X | system | outlook.exe | Added by the MIMAIL.Q WORM! Note that Microsoft's outlook.exe resides in the Program Files sub-directory wheras this resides in C:Windows or C:Winnt |
| X | System | Atira.exe | Added by the KOTIRA VIRUS! |
| X | SYSTEM | lsas.exe | Added by the SPYBOT.CJ WORM! |
| X | System | kernels32.exe | Added by the DLOADER-FC TROJAN! |
| X | System | sysctrl.exe | Added by WinGuardian. Note - this commercial keylogger is no longer made or sold by Webroot but older copies may still be in existance, those copies will be identified as spyware |
| X | System 64 Driver for Games | sys64dvr.exe | Added by the SDBOT TROJAN! |
| X | System Applications Profile | sap.exe | Added by the RBOT-QF WORM! |
| X | System Backup | msystem.exe | Adult content dialler |
| X | System Cache | SysCache.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| U | System Check | Rundll32.exe SysDll32.dll, SystemCheck | XPCSpy Pro keylogger, surveillance and monitoring software |
| X | system check | updater.exe | Unidentified adware downloader |
| X | System Config Manager | crss.exe | Added by the AGOBOT.GH WORM! |
| X | System Config Manager | smssl.exe | Added by the AGOBOT-ZJ WORM! |
| X | System Configuration | iexplore.exe | Added by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
| X | System Database administration | systemDA.exe | Added by the DERDERO.B WORM! |
| X | System Database Administration Support Process | sysdasp.exe | Added by the DERDERO.C WORM! |
| X | System Diagnostics | sysdiag32.exe | Added by the SDBOT.GEN TROJAN! |
| N | System DLF | cpqdiaga.exe | Compaq Diagnostic record system utility which allow you to view information about your computer's hardware and software configuration. Available via Start -> Programs |
| X | System Document Application | nmod.exe | Added by the SDBOT-ABB WORM! |
| X | System Document Application | msdocument.exe | Added by the RANDEX.COX WORM! |
| X | System driver | Messenger.exe | Added by a variant of the SMALL.BJ TROJAN! |
| X | System Efficiency Monitor | mscedit32.exe | Added by the SDBOT.P TROJAN! |
| X | System Efficiency Monitor | mscommand.exe | Added by the KWBOT.P WORM! |
| X | System Executable DLL Library | EXECDLL32.exe | Added by the RANDEX.AZ WORM! |
| X | System Failure Statistic | cnstat.exe | Added by the RBOT-LF WORM! |
| X | System File Drivers | nvsysvc32.exe | Added by the AGOBOT.WJ WORM! |
| X | System Handler | LSASS.EXE | Added by the NIMOS WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup! |
| X | System Host Service | svchost.exe | Added the the CONE.F WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | System Information Manager | Navcpe.exe | Added by the SDBOT-QB WORM! |
| X | System Information Manager | Msbb.exe | Added by a variant of the BACKDOOR.IRC.BOT TROJAN! |
| X | System Initialization | msmsgri32.exe | Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS! |
| X | System Initialization | payload.dat | Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS! |
| U | System LifeGuard Scheduler | Slsched.exe | System LifeGuard scheduler |
| X | System Log Event | csrss32.exe | Added by the AGOBOT-JI WORM! |
| X | System Manager | svchost.exe | Added by the BANKER-AE TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | system manager | System.exe | Added by the FORBOT-BO WORM! |
| X | System Manager | winsrv32.exe | Added by an unidentified WORM or TROJAN! |
| U | System Mechanic Popup Stopper | Popupstopper.exe | Iolo "System Mechanic" popup stopper |
| U | System Monitor | SYSMON.EXE | Comes with some Aopen motherboards. Monitors CPU temp, voltage and fan speed. Warns if any become abnormal |
| X | System Monitor | Sysmon16.exe | Added by the SDBOT TROJAN! |
| X | System MScvb | mscvb32.exe | Added by the SOBIG.C WORM! |
| X | System Networking | sysnet.exe | Added by the RBOT.API WORM! |
| X | System Profile | Regsrv.exe | Added by a variant of the OPTIX TROJAN! |
| X | System Restore | svcnet.exe | Added by the TIBICK WORM! |
| X | System Restore Data | [path] repcale.exe [path] beird.exe | Added by the RANDON.AN WORM! |
| X | System Service | MSREXE.EXE | Added by the AML TROJAN! |
| X | system service | spoolcrv.cpl | Added by the INSPIR.11 TROJAN! |
| X | System Service | systems.exe | Added by the AGOBOT.VZ WORM! |
| X | System Soap Pro | soap.exe | System Soap Pro internet cleaning software. Bundles foistware like HTTPER and Zipclix - best avoided |
| U | System startup | charmapx.exe | Only required if using an oriental language |
| X | System Startup | Voltio.exe | Added by the RBOT.NJ WORM! |
| X | System Stats | SystemStats.exe | Added by a variant of the WOOTBOT WORM! |
| X | System Terminal | SYSTEM2.EXE | Added by the SPYBOT-BZ TROJAN! |
| X | System time updator | CSysTime.exe | Added by the RANDEX.S WORM! |
| X | System Toolkit | Systools.exe | Added by the RONOPER-G WORM! |
| X | System Tray | msccn32.exe | Added by the PALYH.A WORM! Warning - spreading via infected E-mail attachments with the sender address faked as support@microsoft.com. Note - this is not the valid SystemTray (SysTray.exe) |
| X | System Tray Services | spooles32.exe | Added by the AGOBOT.ZH WORM! |
| X | System Tray32 | SysTray32.exe | Added by the REPAD WORM! |
| X | System Update | [filename].exe | CoolWebSearch parasite variant |
| X | System Update | [random filename] | Added by the KORGO.W or KORGO.X WORMS! |
| X | System Update | wupdmgr.exe | Added by the SOROMO-A TROJAN! |
| X | System Update | [random filename] | Added by the SOROMO-A TROJAN! |
| X | System Update Service | wmiprvsa.exe | Added by the AGOBOT-RG TROJAN! |
| X | System Update2 | explorer.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | services.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | svchost.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | system.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | taskman.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | taskmon.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | update.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | webcheck.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | wininet.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | winlogon.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | winspool.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | wupdmgr.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Updater Service | wmiprvsw.exe | Added by the GAOBOT.AFC WORM! |
| X | System Uptime Server | SYSENTRY.EXE | Added by the RBOT.LK WORM! |
| X | System Uptime Server | SYSENTRY32.EXE | Added by the RBOT.LK WORM! |
| X | system xp | acdsee demo.exe | Added by the SALGA.A WORM! |
| X | System-Config | msptmf32.com | Added by the LIOTEN.FA WORM! |
| X | System-Service | EXPLORER.SCR | Added by the BENJAMIN WORM! KaZaA file-sharing users beware! |
| X | system. | system..exe | Added by the OPTIXPRO.13.C TROJAN! |
| X | system... | system...exe | Added by the OPTIXPRO.13.C TROJAN! |
| X | System.exe | System.exe | Added by various WORMS and TROJANS! |
| X | System32 | system.exe | Added by the BUSHTRO122 TROJAN! |
| X | System32 | System32.exe | Added by any number of WORMS or TROJANS! |
| X | System32 | sysdiag.exe | SpyAgent.B spyware |
| X | System32 | system32,1.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | system32 | NeT-BoT.exe | Added by the AGOBOT-LJ WORM! |
| X | system32.dll | systeminit.exe | CoolWebSearch hijacker re-directing to your-search.info |
| X | system32.dll | sysdll32.exe | CoolWebSearch parasite related. Redirecting to wholeworldmarket.com, most likely other domains as well |
| X | system32.exe | services32.exe | Added by a variant of the BACKDOOR.IRC.BOT TROJAN! |
| X | System32Dll | DLL32SYS.EXE | Added by the SPYBOT-CZ WORM! |
| X | System32Ex | System32Ex.exe | Added by the IRCCONTACT TROJAN! |
| X | System33 | FB_PNU.EXE | Added by the NICHELLO-A WORM! |
| X | SystemAdministration | Wincmp32.exe | Added by the ASYLUM TROJAN! |
| U | SystemAgent | Sage.exe | "Microsoft Plus! System Agent automatically tunes your system, performing tasks such as disk optimization and error correction. It can also run any application at prescheduled times" |
| X | SystemBackup | mtx.exe | Added by the MTX VIRUS/WORM! |
| X | SystemBackup | MicroLog.exe | Added by the MICROLOG.A TROJAN! |
| ? | SystemBoot | ladies.htm | Unknown but sounds very suspicious?? |
| X | SystemBoot | Mshta.exe ...filename.hta | Adult content dialler |
| X | SystemCheck | Systemcheck.exe | Added by the LAVITS WORM! |
| X | SystemChecker | Syschk.exe | Added by the GALIL.F WORM! |
| X | SystemCONF98i | SystemCONF98i.exe | Added by the GLITCH BOT TROJAN! |
| X | SystemDebug | Sysdeb32.exe | Added by the SYSBUG TROJAN! |
| X | SystemDll | SystemDll.exe | Added by the LOXOSCAM TROJAN! |
| X | systemdrv | ms32sys.exe | Added by an unidentified WORM or TROJAN - most likely GAOBOT variant |
| X | SystemEmergency | [various filenames] | SmartSearch - a CoolWebSearch parasite variant |
| X | SystemExplorer | explore.exe | Homepage hijacker - file located in the "Services" folder in Common Files |
| X | SystemFTP | VSENMB.exe | Malware (ie, malicious software). Also changes the system.ini Shell line to read Shell=Explorer.exe VSENMB.exe, and it hacks the Winstart.bat as well |
| X | SystemInit | iservc.exe | Added by the FIZZER WORM! |
| X | Systemiom Updater | Systemiom.exe | Added by the SPYBOT.TY WORM! |
| X | SystemLoad32 | sysload32.exe | Added by the MIMAIL.E WORM! |
| X | SystemManager | Sysman32.exe | Added by the DOWNLOADER-BW.B TROJAN! |
| X | SystemMap32 | Netisp32.vbs | Added by the REDIST.C WORM! |
| X | SystemMD | md.exe | Homepage hijacker |
| X | SystemMonitor | Sysmon32.exe | Added by the AIDID.A WORM! |
| X | SystemNetwork | NETSERV.EXE | Added by the NETCONTROL VIRUS! |
| ? | SystemReg | PROCES.EXE | ?? |
| X | SystemReg | svchost.exe | Added by the DEWIN.E TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | SystemReg | WINREG.EXE | Added by the DEWIN.A TROJAN! |
| X | Systems | scchost.exe | Added by the DAEMOZ.A TROJAN! |
| X | Systems Restart | slchost.exe | Added by the BANCOS.RF TROJAN! |
| X | Systems Restart | spchost.exe | Added by a variant of the BANCOS.RF TROJAN! |
| X | Systems Restart | Rundll32.exe beem.dll, DllRegisterServer | Browser hijacker - the file serves to register a dll implemented as a browser plugin |
| X | Systems Restart | Rundll32.exe snim.dll, DllRegisterServer | Added by the Startpage.I hijacker |
| U | Systems.exe | Systems.exe | Keyboard Spectator - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
| U | SystemSafe | Syssafe.exe | System Safety Monitor - system monitoring tool with additional application firewalling |
| X | SYSTEMSars32 | csrss.exe | Added by the AHLEM.A WORM! Note - this is not the legitimate csrss.exe process which should NOT appear in Msconfig/Startup! |
| X | SystemSAS | System32.exe | Added by the KWBOT.C WORM! |
| X | SystemSearch | regedit.exe -s c:ie.reg | Installs a Seachxl.com browser page hijack |
| X | SystemSearch | regedit.exe -s c:sys.reg | Installs a i--search.com browser page hijack |
| X | SystemService | msocfg.exe | Premium rate adult content dialler |
| X | SystemService | navchk.exe | Premium rate adult content dialler |
| X | SystemService | qservice.exe | Premium rate adult content dialler |
| X | SystemService | shman.exe | Premium rate adult content dialler |
| X | SystemSettingf | TRUG.vbs | Added by the TRUG.B MACRO! |
| U | SystemSuite Task Manager | MXTASK.EXE | vcom (nee Ontrack) SystemSuite - PC maintenance and security. Use the program's configuration options to enable only the parts you want running all the time - such as Virusscanner Pro |
| X | SystemTasks | filez.exe | Adult content dialler |
| X | SystemTasks | sexypicz.exe | Adult content dialler |
| X | SystemTasks | loaded.exe | Adult content dialler |
| X | Systemtra | Systra.exe | Added by a variant of the LOVGATE WORM! |
| X | SystemTra | CDPlay.EXE | Added by a variant of the LOVGATE WORM! |
| U | SystemTray | SysTray.Exe | SYSTRAY.EXE - System Tray Services. Provides the Volume Control, PC Card Status, Power Management and other icons that reside in the System Tray (see here). SYSTRAY.EXE may be disabled if none of these services are required. It will launch as and when required if you later enable the icons. If you need these items they're available via Start -> Settings -> Control Panel |
| X | SystemTray | SystemTray.exe | Added by the BIGFOOT TROJAN! Note - this is not the valid SystemTray (SysTray.exe) |
| X | SystemTray | SysTray.exe | Added by the ALADINZ.P TROJAN! Note - this is not the valid System Tray (systray.exe) which resides in C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP). If you right-click on the real systray.exe the "Properties" reveal it to be a Microsoft file |
| N | SystemUpd | SystemUpd.exe | Updater for Swapoo.com, a kind of Napster for games |
| X | SystemWideHook for Windows NT | %WinHook32.exe | Added by the MYDOOM.AC WORM! |
| U | SystemWizard Sniffer | Sniffer.exe | SystemWizard for Win98/ME from SystemSoft - diagnoses and solves hardware and software problems on a PC |
| X | systemyom Updater | systemyom.exe | Added by a variant of the BACKDOOR.IRC.BOT TROJAN! |
| X | SYSTEMZ Patch | SYSZ.exe | Added by the ALADINZ.P TROJAN! |
| U | System_Messages | pprsen.exe | TerminatorX - "offers an easy and effective method of stopping users running predetermined file sharing programs like KaZaA, messenger programs, chat rooms and the like" |
| X | Systesms.exe | systesms.exe | Added by the RBOT-HI WORM! |
| N | Systest | Systest.exe | Clean Space temp files cleaner |
| X | systhread | winkernal.exe | Added by the LIAMED WORM! |
| X | SysTime | systime.exe | CoolWebSearch parasite variant |
| X | Systmesy | Systmesy.exe | Added by the RBOT-KQ WORM! |
| X | Systoan32 | systoan.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| ? | systr32 | systr32.exe | ?? |
| ? | systrax | systrax.exe | ?? |
| X | Systray | Systray_.Exe | Added by the KERGEZ.A WORM! |
| X | Systray | [filename.exe] | Winfavorites adware |
| X | SYSTRAY | UNMT.EXE | Added by the SDBOT WORM! |
| U | SysTray | SysTray.Exe | SYSTRAY.EXE - System Tray Services. Provides the Volume Control, PC Card Status, Power Management and other icons that reside in the System Tray (see here). SYSTRAY.EXE may be disabled if none of these services are required. It will launch as and when required if you later enable the icons. If you need these items they're available via Start -> Settings -> Control Panel |
| X | SysTray | Snnpapi.exe | Added by an unidentified TROJAN! |
| X | Systray driver | systray.exe | Added by the MUTEBOT TROJAN! Note - this is not the real SystemTray which shares the same filename |
| X | SystrayServices | Msxpw.exe | Added by the CITOR WORM! |
| X | systree | systree | Added by the BANCOS.L TROJAN! |
| X | Systry | [path to worm] | Added by the AUTEX WORM! |
| X | SYStry | spoolsvr.exe | Added by the SDBOT.GN WORM! |
| X | Systryt | [path to worm] | Added by the AUTEX WORM! |
| X | sysu | sysu.exe | Dynamic Desktop Media adware - see here |
| X | SysUpd | Sysupd.exe | VirtuMonde adware |
| X | Sysvupex | Sysvupex.exe | Added by the MEDIAS TROJAN! |
| U | SysW8 | csta.exe | Clean Space - privacy and perfomance enhancer |
| U | SYSWB6 | SYSWB6.exe | We-Blocker - gives parents the opportunity to monitor their children's Internet access and provide them with age-appropriate content, while filtering out sites that contain adult content |
| X | SysWin | SysWin.exe | Added by the IRCCONTACT TROJAN! |
| X | syswin32 | syswin32.exe | Added by a variant of the SPYBOT WORM! |
| X | Syswindow | Syswindow.exe | Added by the COW TROJAN! |
| X | SYS_CLEAN | Service.exe | Added by the FLOPCOPY WORM! |
| U | SZMsgSvc.exe | SZMsgSvc.exe | StopZilla! - pop-up killer |