Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help Forums Windows Startup Programs Database Spyware and Malware Removal Guides Computer Tutorials Uninstall Database File Database Computer Glossary Computer Resources
 

Alert!  Have a problem and would like to ask us for help? To learn how to ask your question Click Here!
Stop!  Do you have popups or other malware infecting your computer? If so, Start Here!
Question?  Are you having trouble using this site? Then you should visit the New User Orientation Center!



A    B    C    D    E    F    G    H    I    J    K    L    M    N    O    P    Q    R    S    T    U    V    W    X    Y    Z    Other   
HJT: F0, F1, F2, F3 · O4 · O20 · O21 · O22 · O23
Rootkit List · Submit a Startup · Top Submitters
 Startup Index · Newest Entries · Mozilla Search Tools · WebMaster Site Tools · Status Key
Startup Database Forum · Computer Help Forums · How to use the Startup Database

Enter the filename or keyword you would like to search for:
Advanced Search

Name Filename Status Description
Setup.exe
X
Added by the Trojan.Win32.VB.boo Trojan.
!SASWinLogon SASWINLO.dll
Y
Related to the SuperAntiSpyware anti-spyware program.
(357AA41A-B7A8-4632-A27D-5B980B25CF43) svchost.exe
X
Added by the Troj/Small-AQ trojan!
(378FCBD5-BE2B-AFC9-0401-111111111111) svcbost.exe
X
Added by the Troj/Keylog-ZZ keylogger Trojan.
(Default) Shania.vbs
X
Added by the SHANIA TROJAN!
(default) SYSDLL32.exe
X
Added by the Backdoor.G_Door backdoor.
(Default) Systrsy.exe
X
Added by the Trojan.Cdtray Trojan which causes your cd tray to open and close repeatedly. ... Read More
(default) syspol.exe
X
Added by the Troj/Dremn-B keylogging Trojan.
(Default) SYSEXPLR.EXE
X
Added by the Troj/GDoor-R backdoor Trojan.
(default) systemxz.exe
X
Added by the Troj/Hupigo-SH Trojan.
(default) scvhost.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
(Default) SystemMonitor.exe
X
Added by the W32.Nujama.B worm. W32.Nujama.B is a worm that spreads through mapped drives and shared folders, and lowers security settings on the comp ... Read More
(L4r1$$4) (4nt1) (V1ruz) SP00Lsv32.pif
X
Added by the W32/Assiral-B WORM! This worm will terminate processes and also install/run a file C:\WINDOWS\WinVBS.vbs to restrict user activity. ... Read More
(random filename) slk8x2peu.exe
X
Added by QuickLinks_Process ADAWARE! ... Read More
*security center secctr.exe
X
Added by the SDBOT.BRO WORM! ... Read More
*StateMgr statemgr.exe
Y
Windows ME default for System Restore. Do NOT disable!
.mscsbl SVCHOST.EXE
X
Added by the Troj/Borobot-A infection! It is found in either the Windows system folder or the Application DataMicrosoftInternet Explorer folder. ... Read More
.mscsbl svhost.exe
X
Added by the BACKDOOR-CMQ TROJAN!
.NET config sysmon32.exe
?
??
.NET Framework Service svchost.exe
X
Added by the ShopNav adware. This infection should not be confused with the legitimate C:\Windows\System32\svchost.exe file. ... Read More
.nvsvc smss.exe
X
Added by the TROJ_HORST.GF Trojan. This infection should not be confused with the legitimate C:\Windows\System32\smss.exe file. ... Read More
.nvsvcb smssb.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
.Prog services.exe
X
Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! ... Read More
1 Srvpl0.dll
X
Added by the W32.Wowlook@mm worm. W32.Wowlook@mm is a mass-mailing worm that spreads by sending itself as an attachment to email. The worm also steals ... Read More
1 smcmcr.exe
X
Added by the Troj/Bckdr-QIB backdoor Trojan.
1 system32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
1-sukarno sukarno.exe
X
Added by the W32/Brontok-CR worm.
100 svchost.exe
X
Added by the Troj/Gampass-O Trojan. This infection should not be confused with the legitimate C:\Windows\System32\svchost.exe file. ... Read More
1234klsjdc uiar924c af sxgnsvuxct.exe
X
Identified as a variant of the Trojan.CL.Agent.EDXZ malware.
1234klsjdc uiar924c af sysvtypkbjx.exe
X
Identified as a variant of the Trojan.CL.Agent.EDXZ malware.
180clientstubinstall stubinstaller4528.exe
X
180Solutions/N-Case adware related ... Read More
1Srv32 SpyAgent4.exe
U
SpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC." ... Read More
1Win32Cfg SpyBuddy.exe
U
SpyBuddy monitoring software
2-suharto suharto.exe
X
Added by the W32/Brontok-CR worm.
27 slsorve.exe
X
Added by the Troj/Slsorve-A trojan. Using it's own own SMTP engine it sends email to a remote address and will terminate anti-virus related processes ... Read More
32bit system bus driver sysbus32.sys
X
Added by the Troj/Dropper-EC dropper Trojan.
333 svchost.exe
X
Added by the Troj/JD-A password-stealing Trojan.
5T19I3B27A svchost.exe
X
Added by the Troj/Small-EKA Trojan. This infection should not be confused with the legitimate C:\Windows\System32\svchost.exe file. ... Read More
6-susilo b sby.exe
X
Added by the W32/Brontok-CR worm.
666 Ska.exe
X
Added by the PIPES TROJAN!
7X29C2X78Y syss_.exe
X
Added by the Troj/Agent-GMS Trojan.
<Date the program was installed> SSS.sys
X
Added by the XPAntiVirus rogue security software.
<not used> spooll.exe
X
Added by the Troj/Banker-DIO Internet banking Trojan. When selected banking websites are accessed, the Trojan will monitor user activity and send the ... Read More
<not used> sisbmsxb.dll
X
Added by the W32/Stration-H mass-mailing worm and backdoor Trojan. W32/Stration-H spreads by sending emails with itself as an attachment to email addr ... Read More
<not used> svichosst.exe
X
Added by the W32/Sohana-J worm. W32/Sohana-J may attempt to spread via instant messaging clients. ... Read More
<not used> setup_.exe
X
Added by the Troj/KGSpy-A key logging and information-stealing Trojan.
<not used> sbs.exe
X
Added by the Troj/Hacksaw-A Trojan. Troj/Hacksaw-A infects a system when a U3 USB drive loaded with it is connected to to a compatible system. ... Read More
<not used> systeminit.exe
X
Added by the W32.Solow worm. W32.Solow is a worm that attempts to spread via removable storage drives and copies itself as exe files with various name ... Read More
<not used> systems.dll
X
Added by the Troj/WLDrop-A Trojan.
<not used> services.scr
X
Added by the W32.Odelud worm. W32.Odelud is a worm that spreads via network shares and removable media and may infect executable files. ... Read More
<not used> sitta.exe
X
Added by the W32/Hansah-A worm.
<not used> SoDAHK.DLL
X
Added by the Adware.Sogou adware.
<not used> shchostv.exe
X
Unidentified malware.
<not used> spoolsrvc.exe
X
Unidentified malware.
<not used> svcvhost.exe
X
Unidentified malware.
<not used> svchctrl.exe
X
Unidentified malware.
<not used> systems.txt
X
Related to SmitFraud infections.
<not used> smsqolqo.dll
X
Added by the Troj/DwnLdr-GXT Trojan.
<not used> stdole32.dat
X
Trojan bundled with SmitFraud infections.
<not used> sulimo.dat
X
Related to the SmitFraud infection.
<not used> skuns.dat
X
Fakealert Trojan which shows fake security alerts on your computer.
<not used> salo.exe
X
Added by the W32/Mabezat-A virus dropper.
<not used> SVCHOTS.EXE
X
Added by the W32.HLLP.Arcer virus. W32.HLLP.Arcer is a virus that infects executable files and attempts to steal sensitive information from the compro ... Read More
<not used> SysWln74_3.dll
X
Added by the PSW.OnlineGames.NNM password-stealing Trojan.
<not used> swrcfzc.dll
X
Added by the PWS-OnlineGames.q password-stealing Trojan.
<not used> smsikfik.dll
X
Added by the Trojan.Goldun Trojan. Trojan.Goldun is a hidden process that steals personal information such as usernames and passwords for financial ac ... Read More
<not used> swggbzc.dll
X
Added by the PWS-OnlineGames.q.dll password-stealing Trojan.
<not used> sbwltbxa.exe
X
Identified as a variant of the Troj/Agent-GRP variant malware.
<not used> systemio.exe
X
Added by the W32/Autorun-DH removable media worm.
<not used> sys.vbs
X
Added by the W32/Autorun-EL removable media worm. Please note that C:\Wndows\System32\wscript.exe is a legitimate file and should not be deleted. ... Read More
<not used> soundmgr.exe
X
Identified as a variant of the TR/Proxy.Gen malware.
<not used> SecureGuard.vbs
X
Added by the VBS/Autorun-JP removable media worm. Do not delete C:\Windows\System32\wscript.exe as it is a legitimate program. ... Read More
<random characters> securewinload32x.exe
X
Added by the Troj/OptixP-N worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
<Random CLSID> ssvchost.com
X
Added by the Troj/BluEye-D backdoor Trojan.
<Random CLSID> sygate.exe
N
Added by the W32.Focelto.A worm. W32.Focelto.A is a worm that spreads through Microsoft instant messaging clients and uses Rootkit techniques. It open ... Read More
<random name> Servere.exe
X
Added by the Troj/LegMir-AQM password-stealing Trojan for the online game The Legend of Mir. ... Read More
<random name> systs.exe
X
Added by the Troj/Agent-GDC Trojan.
<random> svshost.exe
X
Added by the W32/Kelvir-AX instant messaging worm and backdoor Trojan.
<unknown> socket573.sys
X
Added by a variant of Goldun rootkit.
<unknown> scsipsrvc.sys
X
Added by a variant of the Troj/Haxdor-Gen rootkit.
<unknown> sbsrtyus.sys
X
Added by the Trojan.Mdropper.S Trojan.

Trojan.Mdropper.S is a Trojan horse program that exploits Microsoft Word Malformed Object Pointe ... Read More
<unknown> satad645.sys
X
Added by a variant of the Goldun.Fam rootkit.
<unknown> sysbl.exe
X
Added by the Troj/Dload-Y Trojan.
AAMSFree702 sys.exe
X
Identified as BackDoor-CPC or Mal/OptixPro.
abss system.exe
U
Added by the Spyware.ABSystemSpy surveillance software. If this program was not installed yourself you should uninstall it. ... Read More
abylonsoft Activate modules SAPDrive.EXE
Y
Added by the abylon CRYPTDRIVE file encryption software.
Ac97Sound snddrv.exe
X
Identified by Kaspersky Antivirus as Trojan.Win32.VB.axg.
Acronis Scheduler2 Service schedhlp.exe
U
Part of Acronis True Image - backup software. Co-operates with the "schedul2.exe" servuce to perform backup/restore tasks correctly. Required if you w ... Read More
Acronis Scheduler_Helper schedhlp.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
ActiveDesktop systray32.exe
X
Added by the DABOOM WORM!
activexupdate svcss.exe
X
Added by a variant of the DEDLER.C TROJAN! ... Read More
Adline Ssystem sichost.exe
X
Added by the Trojan-Dropper.Win32.Small.hy Trojan. This Trojan is designed to install and launch other programs on the victim machine without the user ... Read More
Administrator svchost.scr
X
Added by the Backdoor.Novacal backdoor.
AdminSoft sysfile.vbs
X
Added by the VBS/Stargrub-A WORM, by way of an email attachment. It will attempt to add a user name, change proxies and copy additional files to hard ... Read More
Adobe sysconfig.exe
X
Added by an unidentified WORM or TROJAN!
Adobe sysbat32.exe
X
Added by the LOWZONES.T TROJAN!
Adobe Acrobat Speed Launcher.lnk SC_Acrobat.exe
N
Added by Adobe Acrobat Reader Standard 7.0, and possibly other versions. This program preloads certain aspects of the program so that it will launch ... Read More
Adobe Plugins Reader svshost.exe
X
A variant of the Sdbot.awe family of worms and IRC backdoor Trojans.
AdobeReaderPro service.exe
X
Added by the W32/Rbot-BCA worm and IRC backdoor.
AdobeReaderPro spoolss.exe
X
Added by the W32/Sdbot-AKZ worm and IRC backdoor.
AdobeReaderPro subset.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
AdobeReaderPros sysmsn.exe
X
Added by the W32/Rbot-BGH worm and IRC backdoor.
AdRotator.Application services.exe
X
Added by the Adware.Clickbank adware. File is found in the %windir%system32inetsrv folder. ... Read More
adsblocker stopAds.exe
X
Reported as Win32/Dialer.DW by NOD32 ... Read More
adslsystemtray SystemtrayV100B.exe
?
Apparently Annex A ADSL modem related - what does it do and is it required? ... Read More
adupdater sysupudt.exe
X
Unidentified adware downloader/updater
Advanced DHTML Enable sooo2.exe
X
Identified by Kaspersky antivirus as a variant of the Trojan-Proxy.Win32.Agent.mf Trojan. ... Read More
Advanced Graphics Driver smvhost.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
aldoa swqzdtj.dll
X
Added by a Zlob Trojan which installs AntiVirgear 3.7 and display fake security alerts in your Windows taskbar. ... Read More
ALG32 SPOOLSVU.EXE
X
The Troj/Agent-CJ TROJAN drops this file, alg32.exe and htass.dll into the Windows folder. ... Read More
Alive SYstem scchost.exe
X
Added by the Troj/Tofdrop-B dropper Trojan.
alive system scchostc.exe
X
Added by the Troj/Tofdrop-B ... Read More
All Aboard Status stswin.exe
U
All Aboard! Internet Connection Sharing status icon
alligt severe.exe
X
Added by the W32.Slurk.A worm. W32.Slurk.A is a worm that copies itself to all removable and shared drives, and drops other threats on to the comprom ... Read More
alpha svchost.exe
X
Identified as a variant of the Trojan-Clicker.Win32.Delf.it malware. This infection should not be confused with the legitimate C:\Windows\System32\svc ... Read More
aluria security center SecurityCenter.exe
N
Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware co ... Read More
Amie Release V6.9D services.exe
X
Added by the Troj/VB-EAN Trojan. This infection should not be confused with the legitimate C:\Windows\System32\services.exe file. ... Read More
amircivil svchot.exe
X
Added by the W32.Amirecivel worm.
ANONYMIZER_SPYWAREKILLER SpyWareKiller.exe
U
Anonymizer Spyware Killer
Anthrax serious.exe
X
Added by the W32/Mirsa-B mass-mailing worm.
Anti Spam Service spamsvc.exe
X
Added by the W32/Mytob-BK worm. When started, this infection connects to a remote IRC server and waits for commands to execute. ... Read More
AntiClicker SVCHST32.EXE
X
Added by the BackDoor-CBH backdoor.
AntiMalwareSuite Shell Hook shellext.dll
X
Added by the AntiMalwareSuite rogue anti-spyware program.
Antivir svchst.exe
X
Added by the Troj/Ragruk-A backdoor Trojan.
AntiVir scvhost.exe
X
Added by the Troj/Bckdr-PUT Trojan.
AntiVir smss.exe
X
Added by the Troj/DwnLdr-GWE Trojan downloader. This infection should not be confused with the legitmate C:\Windows\system32\smss.exe file. ... Read More
AntiVir PersonalEdition Classic Scheduler sched.exe
Y
Service that manages the scheduled virus scans for the Avira AntiVir PersonalEdition Classic antivirus program. ... Read More
Antivirus sav.exe
X
Added by the System Antivirus 2008 rogue anti-spyware program.
Antivirus SPP.exe
X
Added by the Spyware Preventer rogue anti-spyware program.
aol software smss.exe
X
Added by the W32/Tilebot-FM worm and IRC backdoor.
AOLAspSunset2 sunsetAsp2.exe
?
Related to AOL.
AolSoftware spoolsv.exe
X
Added by the W32/Sdbot-BQY worm and IRC backdoor. This infection should not be confused with the legitimate Microsoft file c:\Windows\system32\spoolsv ... Read More
AolSoftware services.exe
X
Added by the W32/Tilebot-FA worm and IRC backdoor. This infection should not be confused with the legitimate Microsoft file c:\Windows\system32\servic ... Read More
aposiopetic shlahsd.dll
X
Zlob Trojan which installs the VirusProtect 3.9 rogue anti-spyware program. This program displays fake security alerts stating that your compute ... Read More
Application Management Browser smss.exe
X
Added by the Troj/Comhush-A Trojan. This infection should not be confused with the legitimate smss.exe found in the C:\Windows\System32 (%System%)fol ... Read More
applicationgateway svchost.exe
U
Added by the Spyware.PCProwler surveillance software. If this program was not installed by yourself, it should be uninstalled immediately. This progra ... Read More
ApplicationProtocolRun smsbvl32.exe
X
Added by the Troj/IRCBot-CX Trojan.
APVXDWIN syslogz.bat
X
Added by the Troj/DelFile-V Trojan.
apyginapygin simenu.exe
X
Added by the SDBOT.BTR WORM! ... Read More
armillifer siiyal.dll
X
Added by a Zlob Trojan which installs AntiVirgear 3.8 and display fake security alerts in your Windows taskbar. ... Read More
armonVirusAnti smss.exe
X
Added by the W32/Autorun-DV removable media worm. This infection should not be confused with the legitimate C:\Windows\System32\smss.exe file. ... Read More
asd ssm.com.cn.exe
X
Added by the Troj/Bckdr-QKC backdoor Trojan.
ashcap servirsess.exe
X
Added by the Spyware.SpySure Spyware. Spyware.SpySure is a spyware program that may steal sensitive information from the computer. ... Read More
ASocksrv SocksA.exe
X
Added by the Troj/QQRob-AAT Trojan.
ASP.NET State Service servicos..exe
X
Added by the Troj/Dadobra-I downloader Trojan.
ATI Video Driver Controls sys.exe
X
Added by the W32/Sdbot-DDS worm and IRC backdoor.
ATTBroadbandUpdate SAUpdate.exe
U
Big Brother from Quest Software. System and network monitor
AUDIO SOUND.exe
X
Added by the Dial/Ployb-A premium porn dialer.
Audio Device Manager sfhgj.exe
X
Added by the W32/IRCBot-ZA worm and IRC backdoor.
Audio Device Manager srn32.exe
X
Added by the W32.Spybot.Worm worm and IRC backdoor.
Audiodev SVCHOST.exe
U
Added by the Spyware.KeySpyware surveillance software. This program should not be confused with the legitimate file C:\Windows\System32\svchost.exe. ... Read More
aupd symcsvc.exe
X
Added by the Troj/Orse-E Trojan.
aupd sysvcs.exe
X
Added by the ABWIZ.C TROJAN! ... Read More
aupd sywsvcs.exe
X
Added by the Troj/Orse-L Trojan.
aupd symsvcsa.exe
X
Added by the Troj/Orse-Q Trojan.
Aureal A3D Interactive Audio sa3dsrv.exe
Y
For Aureal based 3D soundcards. A3D sound features won't work with this disabled ... Read More
Auther Service Manager svshost.exe
X
A variant of the SDBot.awe family of worms and IRC backdoor Trojans.
Auto File System Conversion Utility scricon.exe
X
A variant of the Backdoor.Win32.SdBot.yx family of worms and IRC backdoor Trojans. ... Read More
Auto Update svchost.exe
X
Added by the Troj/DumarDl-A trojan.
Auto Updates svchost.exe
X
Added by the Troj/Cheuko-A trojan.
AutoAdministrator SERVICES.EXE
X
Added by the W32/Punya-A worm. This infection should not be confused with the legitimate C:\Windows\System32\services.exe file. ... Read More
autoload svchost.exe
X
Related to SmitFraud infections. This infection should not be confused with the legitimate C:\Windows\System32\svchost.exe file. ... Read More
autoload spool.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Agent variant malware.
autoload spooll.exe
X
Identified as a variant of the Trojan-Dropper.Agent.snu malware.
AutomatedSurfer SurferClient.exe
?
According to the information found here, this program is supposed to simulate a web surfer that can click on links within a hidden IE window.
< ... Read More
Automatic Microsoft Windows Updater suchost.exe
X
Added by the RBOT-EQ WORM!
autorun svchost.exe
X
Related to SmitFraud infections. This infection should not be confused with the legitimate C:\Windows\System32\svchost.exe file. ... Read More
autorun sxs.exe
X
Added by the W32/SmallVBS-A worm.
autorundemo svchost.exe
X
Added by the Troj/Agent-FPX Trojan. This infection should not be confused with the legitimate C:\Windows\System32\svchost.exe file. ... Read More
AutoUpdate smss.exe
X
Identified as a variant of the Trojan-Spy.Win32.WinSpy.aa malware.
AutoUpdate32 services.exe
X
Identified as a variant of the Trojan-Spy.Win32.WinSpy.aa malware.
autoupdater sox.exe
X
Added by the Troj/LdPinch-DH password-stealing Trojan.
avast111111 smss55555.exe
X
Added by the Troj/Lmir-GH information stealing Trojan for the online game The Legend of Mir. ... Read More
AvG svchost323.exe
X
Added by the W32/Rbot-ZA WORM/backdoor!
avnort serbw.exe
X
Added by the W32.Serflog.A worm. This worms spreads through file sharing networks and MSN messenger. ... Read More
avptask svch0st.exe
X
Added by the Troj/Nofere-G Trojan. Troj/Nofere-G contains functionality to communicate with a remote server using HTTP, execute downloaded files, kill ... Read More
avschedscan SCHSC9X.EXE
Y
Command antivirus related ... Read More
AvSer sysup.exe
X
Added by the W32.Serflog.B worm. This worms spreads through file-sharing networks and MSN Messenger. ... Read More
AvSer svosm.exe
X
Added by the W32.Serflog.B worm. This worms spreads through file-sharing networks and MSN Messenger. ... Read More
AV_Update_Client svhost.exe
X
Added by the TROJ_ISPY.B information-stealing Trojan.
bab svchst32.exe
X
Added by the Trojan-Proxy.Win32.Agent.q Trojan.