| X | Svced | Svced.exe | Added by the DELF.F TROJAN! |
| X | SvcH0st | msexploren.exe | Added by the BACKDOOR-CGZ TROJAN! |
| X | svchost | Svch0st.exe | Added by the GRAYBIRD.B TROJAN! |
| X | SVCHOST | svchost.exe | System1060 homepage hi-jacker. Found in a WindowsSystem1060 directory. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | svchost | svchost.exe | Added by the MORB WORM or TARNO TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | SVCHOST | mrowyekdc.exe | Added by the GOTORM WORM! |
| X | svchost | Svch0st.exe | Added by the GRAYBIRD TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | svchost | [path to trojan] | Added by the HAZZER TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | svchost | ADMAGIC.EXE | Added by the SMIBAG WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | Svchost | winhost.exe | Added by the LOLAWEB.A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | Svchost | svchost.exe | Added by the MOXE-A WORM! This is not the valid svchost.exe as described here |
| X | SVCHOST | var.txt.exe | Added by the LDPINCH.C TROJAN! |
| X | Svchost | svchosl.pif | Added by the INZAE.A or INZAE.B WORMS! |
| X | svchost | [path] SETUP.EXE | Added by the SETCLO WORM! |
| X | svchost | [path] SETUP.EXE | Added by the SETCLO WORM! |
| X | SVCHOST | scvhost.exe | Added by the MYTOB.E and MYTOB.G WORMS! |
| X | SVCHOST | taskgmr.exe | Added by the MYTOB.F or MYTOB.H WORMS! |
| X | svchost.exe | svchost32.exe | CoolWebSearch parasite related. Note - this is not the valid svchost.exe as described here |
| X | svchost1 | svchost1.exe | Added by the AGOBOT.ZZ WORM! |
| X | SvcHost32 | svchost32.exe | Added by the MIMAIL.I or MIMAIL.J WORMS! |
| X | svchost64 | svchost64.exe | Added by the SDBOTER.G VIRUS! |
| X | svchostr | svchostr.exe | Added by an unidentified WORM or TROJAN! |
| X | svcinfo | svcinfo.exe | Added by the CRYPTER.A TROJAN! |
| X | svcroot | svcroot.exe | Added by the KEYLOG-AC TROJAN! |
| X | svcsys32 | svcsys32.exe | Added by the AGOBOT-LL WORM! |
| X | svcwinprocess32 | [path to worm] | Added by the UPERING WORM! |
| X | SVHOST | svhost.exe | Added by the MYDOOM.I WORM! |
| X | SVHOST | SVHOST.EXE | Added by the ZORI.A VIRUS! |
| X | Svhost Loader | svshost.exe | Added by the AGOBOT.G WORM! |
| ? | SVIDC32M | SVIDC32M.exe | ?? |
| X | sVideo2 | vxdrun6.exe | Switch premium rate adult content dialer |
| ? | SVM Pop | svmpop.exe | ?? |
| X | svphost.exe | svphost.exe | Added by the AGENT.CS TROJAN! |
| X | svrrun | svrrun.exe | Adware hailing from Deskwizz.com |
| X | svshost | svshost.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | svshost32 | msgrsv32.exe | Added by the RANKY.AJ TROJAN! |
| X | svshostdriver | svshost.exe | Added by the SDBOT-HN TROJAN! |
| X | svwin32 | unninst32.exe | Added by the AGOBOT-NF WORM! |
| X | SVX Control Service | svxhost.exe | Added by the FORBOT-K WORM! |
| N | Swap Nut | javaw.exe | SwapNut is a peer-to-peer file sharing and searching utility developed and marketed by File Metrics, Inc. Users can search for and find almost any type of digital file (audio, video, photos etc.) through a secure peer-to-peer network |
| X | SWCaller | SWcaller.exe | Homepage hijacker - see here |
| X | SWCaller | Swcaller2.exe | Homepage hijacker - see here |
| N | SWd | winwd.exe | PC Security from Tropical Software - lock files, password protect, etc |
| Y | Sweep95 | ICLOAD95.EXE | Part of Sophos ant-virus sofware |
| X | Swf32 | AVupdate.exe | Added by the MERKUR WORM! |
| X | Swf32 | _backup.exe | Added by the SYMTEN WORM! |
| X | SwimSuitNetwork | SwimSuitNetwork.exe | Advertising spyware |
| U | Switch Off | swoff.exe | Switch Off - tray-based system utility that can automatically perform various frequently used operations like shutdown or restart your computer, disconnect your current dialup connection, lock workstation, etc |
| N | Switchboard.com Toolbar | AtHoc.exe | Toolbar for the on-line version of Yellow Pages in the US - Switchboard.com |
| X | sws.exe | [random filename] | Haldex type adult content dialler |
| N | SwTray | SWTRAY.EXE | MS SideWinder game controller system tray icon. Available via Start -> Programs. May have the version number after it |
| N | SWTrayV4 | SWTrayV4.exe | MS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs |
| ? | SXGDSENU | sxgdsenu.exe | Yamaha SXG soundcard driver |
| ? | SxgTkBar | sxgtkbar.exe | Yamaha SXG soundcard driver |
| ? | Sxplog | sxpstub.exe | Part of CA Unicenter Software Delivery - manage software across various systems, from desktops and servers to PDAs and mobile phones, in a controlled and standardized way - is it required at startup? |
| X | SYDNEY | [file path] | Added by the SYNEY WORM! |
| X | Sygate Personal Firewall | Win32x.exe | Added by the RBOT-KZ WORM! |
| X | Sygate Personal Firewall | system32.exe | Added by the RBOT.VI WORM! |
| X | Sygate Personal Firewall | sysgut.exe | Added by the SDBOT.WM WORM! |
| X | Sygate Personal Firewall | Sygate.exe | Added by the RBOT-PN WORM! |
| X | Sygate Personal Firewall | Mcafeeupdate.exe | Added by the RBOT.YN WORM! |
| X | Sygate Personal Firewall | Sygate32.exe | Added by the SDBOT.WW WORM! |
| X | Sygate Personal Firewall Start | services32.exe | Added by the RBOT-MB WORM! |
| X | Sygate Personal Firewall Start | servic.exe | Added by the RBOT-RY WORM! |
| X | Sygate Personals Firewalls | ccsrn.exe | Added by a variant of the RBOT WORM! |
| U | SyGateService | sgserv95.exe | SyGate is a useful little program that lets you share an internet connection over an intranet. Is it needed - it saves a lot of headache to just let SyGate load at startup. Available via Start -> Programs |
| X | Symantec Anti Virus | symantec32.exe | Added by a variant of the WOOTBOT WORM! |
| X | Symantec Configuration Loader | ccApp32.exe | Added by a variant of the GAOBOT WORM! |
| Y | Symantec Core LC | symlcsvc.exe | Part of Norton AntiVirus 2004. What does it do? |
| N | Symantec Fax Starter Edition Port | OLFSNT40.EXE | Offers a virtual printer as a fax machine. Can be run via a desktop shortcut |
| U | Symantec NetDriver Monitor | SNDMon.exe | Part of Symantec's LiveUpate (eg, Norton). Not required if you run manual upadtes but probably require if you leave them to run automatically. Also, if one runs a small office network and SNDMon is disabled on one of the computers – then other computers disappear from the network for this computer, including shared devices like printers and scanners. Hence the "U" recommendation |
| X | Symantec Security | symantec32.exe | Added by the RANDEX.PR or RANDEX.YR WORMS! |
| X | Symantec Security Addon | nvsvc.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Symantec Security Routine Addon for Microsoft Windows | navpxaw32.exe | Added by the AGOBOT-GJ TROJAN! |
| X | Symantec Service | ccApp.exe | Added by the AKHER.D WORM! Note - this is also not the valid Norton AV file with the same filename |
| X | SymAV | SymAV.exe | Added by the NETSKY.U WORM! |
| U | SymKeepAlive | CKA.exe | Part of Norton SystemWorks 2003 - keeps a dial-up modem connection alive |
| N | SymTray - Norton SystemWorks | SYMTRAY.EXE | Keeps all System Tray icons for Norton SystemWorks together to reduce clutter. SystemWorks includes Norton Anti-Virus, Norton Utilities and Norton CleanSweep - mentioned elsewhere here. Personally I only have Norton eMail Protect running which doesn't need SymTray |
| U | Sync Data | Hndsync.exe | Pocket Real Estate - mobile synchronization manager |
| X | Sync Server | drwatsoon.exe | Added by the WATSOON.A TROJAN! |
| U | Sync-It | Syncit.exe | Sync-It - synchronizes the system clock with time servers on the internet |
| U | SyncAgent | syncagent.exe | Ghost Keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove |
| N | Synchronization Manager | mobsync.exe | Find more information about its use here |
| ? | SynSetup | SynTP.tmp RunOnce.exe | Probably associated Synaptics touchpads on laptops as for the SynTPEnh and SynTPLpr entries but what does it do and is it required? |
| X | Syntax Script | systacq.exe | Added by the SDBOT.AI WORM! |
| U | SynTPEnh | syntpenh.exe | Synaptics touchpad tray icon. Displays status and provides quick launch to touchpad features such as scrolling and tap zones. Required on IBM Thinkpads with UnltraNav (pointstick and touchpad combo) if you don't want to loose the advanced pointstick features such as scroll |
| Y | SynTPLpr | syntplpr.exe | Synaptics touchpad driver helper. Required for touchpad features to work |
| X | sys | regedit /s sys.reg | Hijacker |
| X | sys | sysdllwm.reg | CoolWebSearch parasite variant |
| X | Sys Ren | SysRen.exe | Unidentified malware |
| X | Sys29 | win***32.exe [* = random char] | EliteBar adware |
| X | sys32 | sys32.exe | Added by the FLUX.E TROJAN! |
| U | sys32cmd | sys32win.exe | Active Keylogger monitoring software - also see here. From the Symantec article: "This spyware program must be manually installed. However, there are several known programs that have Spyware.ActiveKeylog within them and that install it as the program itself is installed". Disable/remove if you didn't install it |
| X | sys32dll | sys32dll.exe | Added by the AIMDES.B WORM! |
| X | SysA | win***32.exe [* = random char] | EliteBar adware |
| U | SysAgent | SysAgent.exe | SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of |
| X | SysAI | SysAI.exe | AproposMedia adware - also creates SysAI folder in Program Files where the SysAI.exe is also located |
| U | Sysbot | sysbot.exe | Spector - spying (or monitoring) software to record internet activity |
| X | syscfg | syscfg32.exe | Added by the KWBOT.S WORM! |
| X | syscfg34.exe | syscfg34.exe | Added by the ELECTRON WORM! |
| X | Syscheck | win.hta | Browser hijacker |
| X | syscheck | iexplorer.exe | Added by the AGENT.DM TROJAN! |
| X | syscm | Syscm.exe | Vanish adware |
| ? | SysComp | mssdnl.com | Unknown but suspect as *.com are not usually run at start up and the name isn't recognized |
| X | syscon lptt01 | syscon.exe | Variant of the RapidBlaster parasite (in a "Syscon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | syscon ml097e | syscon.exe | Variant of the RapidBlaster parasite (in a "Syscon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | sysconfig | iexplorer.exe | Added by the CULT.C WORM! |
| X | SysConfig | syscfg35.exe | Added by the KAZMOR.C WORM! |
| X | sysconfig | iexplorer.exe | Added by the CULT.H WORM! |
| X | SysConfig | wincfg32.exe | Added by the SDBOT.ZD WORM! |
| U | Sysconfig | Stealth KeySpy.exe | Added by StealthKeySpy commercial keylogger |
| X | Syscpy | Syscpy.exe | Firewall-bypassing, proxied spam relayer. Detected by Symantec as the HOGLE TROJAN! |
| X | SysCtl | sysctl.exe | Added by the AOK TROJAN! |
| X | Sysctrls | procdll.exe | Added by the WEEDBOTZ.14 TROJAN! |
| X | sysdir | winrun.exe | Added by the WINBUR.B WORM! |
| X | Sysdpt | sysdpt.exe | Win32.Crypt trojan downloader |
| X | sysfiler | sysfiler.exe | Added by the RETSAM TROJAN! |
| X | SYSfit | SYSfit.exe | AdShooter adware variant |
| X | sysflg32 | sysflg32.exe | Added by a variant of the CRYPTER.C TROJAN! |
| X | syshelp | syshelp.exe | Added by a variant of the LOVGATE WORM! |
| X | sysinfo | sysinfo.exe | Added by the BEDRILL TROJAN! |
| X | sysinfo.exe | sysinfo.exe | Added by the BEAGLE.V WORM! |
| X | SysInit | wininit32.exe | Added by the XABOT WORM! |
| X | sysinit | services.exe | Added by the NEWLFRM-A TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |