| U | SpokeSysTray | SpokeSysTray.exe | Spoke Software client application. Spoke "uses data in your e-mail and other enterprise information systems to discover the existing relationships of people in your enterprise. It then builds a private, secure relationship network for each user without any additional manual data entry" |
| X | spoo1sv | spoo1sv.exe | Added by the SOULJET TROJAN! |
| X | Spool | [path to trojan] | Added by the RANKY.R TROJAN! |
| X | SPOOL Configuration | spoolsvc.exe | Added by the SDBOT-KD WORM! |
| X | Spool lptt01 | spool.exe | Variant of the RapidBlaster parasite (in a "spool" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | Spool ml097e | spool.exe | Variant of the RapidBlaster parasite (in a "spool" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | Spooler Service | Spoolsrv.exe | Added by the JOINER.C1 TROJAN! |
| X | Spooler Sub System Process | SPOOL32.EXE | Added by the YAB.A TROJAN! |
| X | Spooler Subsytem App | spoolsvc.exe | Added by the SDBOT-MM WORM! |
| X | SpoolerSubSystemProcess | SpooI32.exe | Added by the EHKS.21 keylogger! Note - the "I" between "o" and "3" is a captial "i" not a lower case "L" |
| X | spoolserv | spoolserv.exe | Added by the SDBOT-PN WORM! |
| X | SpoolService | spolsv.exe | Added by the AGOBOT-CS WORM! |
| X | Spoolsv | Spoolsv.exe | Added by the CIADOOR.121 VIRUS! Note - "Spoolsv.exe" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file |
| X | spoolsv | scvhosts.exe | Added by the SMALL-AW TROJAN! |
| X | spoolsv manager | SpoolMgr.exe | Added by the ASSIRAL WORM! |
| X | spoolsvr32 | csmss.exe | Added by the AGENT-AU TROJAN! |
| X | spoolsvr32 | csmss32.exe | Added by a variant of the AGENT-AU TROJAN! |
| X | SPOOLSVU | SPOOLSVU.EXE | Added by the Startpage.K hijacker |
| X | spoolsvv | spoolsvv.exe | Searchcentrix hijacker |
| X | Spore | MsNews.vbs | Added by the SPORE.A WORM! |
| X | Spore.b | Scmhlpr.vbs | Added by the SPORE.B WORM! |
| ? | SPP | run.exe | ?? |
| X | spp | regedit -s spp.reg | IE search hijacker - changes the default search to http://www.hotsearchbox.com/ie/ |
| ? | sppbridge | sppbridge.exe | Associated with an Anycom bluetooth wireless card on laptops - used for printing to portable printers for example. Is it required or can it be started manually? |
| ? | SprintPort | SprintPortA.exe | Novatel wireless modem related. What does it do and is it required? |
| U | SPSTEALT | SmartProtectorPro.exe | Smart Protector Pro - internet privacy tool that erases tracks, MRU lists, etc |
| ? | spstore | storesp.exe | Softprobe - program designed to provide managers with an analysis of an individuals computer use who are under their supervision. This program is NOT related to Winpup |
| U | Spy Blocker | spyblocker.exe | SpyBlocker blocks the communications of spyware installed on a PC so spyware runs but can't exchange data with the server to which it should report. Ensuring spyware can't communicate is important, as you may find after using Ad-Aware that some applications containing spyware subsystems may not run correctly or at all |
| X | SpyBlast | SpyBlast.exe | Spyware killer that is in effect autoinstalled foistware, targeted by SpyBot, among others |
| U | SpyBlocker | spyblocker.exe | SpyBlocker blocks the communications of spyware installed on a PC so spyware runs but can't exchange data with the server to which it should report. Ensuring spyware can't communicate is important, as you may find after using Ad-Aware that some applications containing spyware subsystems may not run correctly or at all |
| X | SpyBlocs | SpyBlocs.exe | Rogue anti-spyware program |
| U | SpybotSD TeaTimer | TeaTimer.exe | TeaTimer is a new tool of Spybot S&D - spam filter which perpetually monitors the processes called/initiated. It immediately detects known malicious processes wanting to start and terminates them giving you some options, how to deal with this process in the future |
| U | SpyBotSnD | Spybotsd.exe | Spybot - Search & Destroy - free multi-spyware removal tool from Patrick Kolla |
| X | Spybott lptt01 | spybott.exe | Variant of the RapidBlaster parasite (in a "Spybott" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | Spybott ml097e | spybott.exe | Variant of the RapidBlaster parasite (in a "Spybott" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| U | SpyCop ScanCheck | MAIN.EXE | SpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan |
| N | SpyHunter | SpyHunter.exe | SpyHunter - spyware remover of somewhat dubious repute, see note |
| U | Spykiller | Spykiller.exe | Shareware "Spyware remover" of questionable quality and repute. There are better alternatives that are freeware to boot |
| X | SpyNuker | Spynuker.exe | A "spyware removal program" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers ‘TrekData’ and ‘Blue Haven Media’, who distribute spyware through ActiveX drive-by-download on web pages |
| N | SpySpotter | SpySpotter.exe | Spyware remover of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites |
| U | SpyStopper | spystopper.exe | SpyStopper - blocks intrusive spyware, Web bugs, worms, scripts, advertisements, and cookies. Protects you from being profiled and tracked |
| U | SpySubtract | SpySub.exe | SpySubtract - multi spyware removal tool |
| U | SpySweeper | SpySweeper.exe | Spy Sweeper - detects and removes spyware |
| X | Spyware | Spyware.exe | BPS Spyware Remover - reportedly uses an old, "borrowed" SpyBot database. Read this and this. Do not support these guys! |
| N | Spyware Begone | SpywareBeGone.exe | Spyware BeGone - free spyware removal utility. Not recommended - see note |
| N | Spyware Begone | freescan.exe | Spyware BeGone - free spyware removal utility. Not recommended - see note |
| U | Spyware Doctor | spydoctor.exe | Spyware Doctor spyware remover |
| U | Spyware Doctor | swdoctor.exe | Spyware Doctor spyware remover |
| U | Spyware Guard Control Panel | spywar~1.exe | "SpywareGuard provides a real-time protection solution against spyware" |
| X | Spyware Nuker Installer | SpywareNukerInstaller.exe | A "spyware removal program" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers ‘TrekData’ and ‘Blue Haven Media’, who distribute spyware through ActiveX drive-by-download on web pages |
| X | Spyware remover | Remove_spyware.exe | Unidentified, but not known to belong to any known spyware remover, and strongly suspected to be adware related! |
| U | Spyware Scanner | AseScanner.exe | Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here and here |
| X | Spyware Slayer | SpywareSlayer.Exe | Spyware remover of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites |
| N | Spyware Stormer | SpywareStormer.Exe | SpywareStormer spyware remover. Not recommended - see here |
| X | Spyware Vanisher | FreeScanner.exe | Spyware remover of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites |
| U | SpywareGuard | sgmain.exe | "SpywareGuard provides a real-time protection solution against spyware" |
| X | SpywareGuard | winproc32.exe | Startpage adware Trojan |
| X | Spywareguard lptt01 | Spywareguard.exe | Variant of the RapidBlaster parasite (in a "Spyguard" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | Spywareguard ml097e | Spywareguard.exe | Variant of the RapidBlaster parasite (in a "Spyguard" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | SpywareGuardPlus | winmm64.exe | StartPage.ht homepage hijacker |
| N | SpywareKilla | SpywareKilla.exe | Spyware remover of ill repute. For more info about it do a search for 'SpyareKilla' at this web page on "Rogue/Suspect Anti-Spyware Products & Web Sites" |
| U | SPYWATCH | SpyWatch.exe | BPS Spyware Remover - reportedly uses an old, "borrowed" SpyBot database. Read this and this. Do not support these guys! |
| X | SQConfigChecker | cc.exe | Xupiter SQWire variant - adware and homepage hijacker. Note - cannot be removed via the Xupiter website in the same way as other Xupiter variants |
| X | SQInstaller | SQInstaller.exe | Xupiter hijacker |
| N | SQL Server | scm.exe | SQL Server Service Control Manager. Available via Start -> Programs |
| X | SQUpdatesChecker | uc.exe | Xupiter SQWire variant - adware and homepage hijacker. Note - cannot be removed via the Xupiter website in the same way as other Xupiter variants |
| X | sqvynikp | sqvynikp.exe | Free_Scratch_Cards foistware |
| ? | sr1exe | updtSup3.exe | Found on a Dell computer, in a Documents and SettingsAll UsersApplication DataDellAlert2 subfolder |
| X | sr64 | ********. exe | Adware, as yet unidentified |
| X | SrchfstUpdate | srchupdt.exe | SearchFast adware downloader |
| ? | SRFirstRun | rundll32 srclient.dll, CreateFirstRunRp | Created by execution of the Windows XP sr.inf file, which installs the Windows XP System Restore feature, needed for example when installing System Restore into Windows Server 2003. Does this indeed need to run at every bootup? |
| U | Srmclean | srmclean.exe | Srmclean helps in the installation and execution of the SoundMax SoftPaq for Compaq/ADI SoundMax Integrated Digital Audio. According to Compaq - "If you disable the entry from loading into startup, then you will not be able to use the features of the sound card" |
| X | SRNG | srng.exe | Search hijacker - see here |
| U | SRP Startup | srrpro.exe | System Restore Remover Pro allows you to safely and easily remove System Restore and various other Windows Millennium "features." This is enabled if you tick the "Remove unnecessary System Restore information on startup" box. Available via Start -> Settings -> Control Panel |
| Y | SRS Applet | SrsTray.Exe | S3 Sonic Vibes sound card drivers - if disabled you loose sound |
| X | Srv RPCrom | NClienti386.exe | Added by the WATSOON.A TROJAN! |
| X | Srv32 | Srv32.exe | Added by the OPASERV.J WORM! |
| X | Srv32 | Srv32.exe | Added by the OPASERV.S WORM! |
| X | Srv32 spool service | runsrv32.exe | Topantispyware.com malware, recognized by Kaspersky antivirus as Trojan-Clicker.Win32.Spyre.b |
| X | Srv32 spool service | spoolsrv32.exe | Topantispyware.com malware, recognized by Kaspersky antivirus as Trojan-Clicker.Win32.Spyre.b |
| X | Srv32Old | [worm filename].PIF | Added by the OPASERV.J WORM! |
| U | Srv32Win | SpyAgent4.exe | SpyAgent - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
| U | Srv32Win | Svchost.exe | Realtime-Spy keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove |
| X | Srv32Win | sysdiag.exe | NetVizor keystroke logger |
| X | srvexc.exe | srvexc.exe | Added by the SERVSAX TROJAN! |
| X | ssate.exe | irun4.exe | Added by the BEAGLE.J WORM! |
| X | ssate.exe | winsys.exe | Added by the BEAGLE.K WORM! |
| N | SSBkgdUpdate | SSBkgdupdate.exe | ScanSoft OmniPage auto updater. Can be disabled using the main program's options |
| ? | SSC_UserPrompt | UsrPrmpt.exe | Part of Symantec (Norton) Security Centre. What does it do, and is it required? |
| Y | Ssd | Std.exe | Stealthdisk - file and folder hiding/locking utility |
| ? | ssdiag | ssdiag.exe | Equinox "Configuration and DOS Diagnostic for DOS and Windows platforms" |
| N | SSDPSRV | ssdpsrv.exe | Simple Service Discovery Protocol (SSDP) and General Event Notification Architecture (GENA) services for network plug and play functionality. Starts up a web server on port 5000. Used by Universal Plug and Play (for network device discovery). To remove this program, open Add/Remove Programs, select either Communications (Me) or Networking Services (XP), and remove the checkmark next to Universal Plug and Play |
| X | ssgrate.exe | system.exe | Added by the MITGLIEDER.C TROJAN! |
| X | ssgrate.exe | irun.exe | Added by the MITGLIEDER.D TROJAN! |
| X | ssgrate.exe | irun4.exe | Added by the MITGLIEDER.F TROJAN! |
| X | ssgrate.exe | sysdoor.exe | Added by the MITGLIEDER.N TROJAN! |
| X | ssgrate.exe | winerdir.exe | Added by the MITGLIEDER.O TROJAN! |
| X | SSK Service | winssk32.exe | Added by the SOBIG.E WORM! |
| X | SSL | svchost.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| U | ssmmgr | ssmmgr.exe | Samsung printer monitor - for checking ink levels, etc. |
| X | sstata | dwdas.exe | Added by the DASDA TROJAN! |
| X | SStb.exe | SStb.exe | Adpowerzone.com "ServerSide" keyword hijacker |
| N | sstray | sstray.exe | nVidia nForce Taskbar Utility - quick access to the nForce2 "Sound Storm" control panel and related utilitys |
| X | SSUpdate | SSUpdate.exe | DyFuCa/MoneyTree parasite variant |
| X | ssvchost | ssvchost.exe | Added by the HELIOS.B TROJAN! |
| X | SSWPlauncher | comet.exe /app:SSWPlauncher | CometCursor by Comet Systems |
| N | Stacmon | Stacmon.exe | Installed with the drivers for a SigmaTel C-Major Audio card (on a Dell Inspiron 600m PC for example). Appears as though it can be disabled with no ill effects |
| Y | Start | Quick95.exe | For a Nisis G6 USB Graphics Tablet. Re-enables itself if disabled therefore best left alone |
| X | Start | windows.vbs | Homepage hijacker |
| ? | start | start.exe | ?? |
| X | start extracting | spoolvse.exe | Added by a variant of the RBOT WORM! |