| Name |
Filename |
Status |
Description |
|
avast! Web Scanner
|
AvastSvc.exe
|
Y
|
Implements mail scanning for avast! antivirus.
|
|
avast! Mail Scanner
|
AvastSvc.exe
|
Y
|
Implements mail scanning for avast! antivirus.
|
|
avast! Antivirus
|
AvastSvc.exe
|
Y
|
Manages and implements avast! antivirus services for this computer. This includes the resident protection, the virus chest and the scheduler.
|
|
Windows Audio Endpoint Builder
|
Audiosrv.dll
|
Y
|
Microsoft service that manages audio devices for the Windows Audio service. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start
Please note that this service is launched by svchost.exe, but the actual application is what is listed as the filename.
|
|
Application Management
|
appmgmts.dll
|
Y
|
Microsoft service that processes installation, removal, and enumeration requests for software deployed through Group Policy. If the service is disabled, users will be unable to install, remove, or enumerate software deployed through Group Policy. If this service is disabled, any services that explicitly depend on it will fail to start.
Please note that this service is launched by svchost.exe, but the actual application is what is listed as the filename.
|
|
Application Identity
|
appinfo.dll
|
Y
|
Microsoft service that facilitates the running of interactive applications with additional administrative privileges. If this service is stopped, users will be unable to launch applications with the additional administrative privileges they may require to perform desired user tasks.
Please note that this service is launched by svchost.exe, but the actual application is what is listed as the filename.
|
|
Application Identity
|
appidsvc.dll
|
Y
|
A Microsoft Service that is used by AppLocker to determine and verify the identity of an applicaiton.
Please note that this service is launched by svchost.exe, but the actual application is what is listed as the filename.
|
|
ArcSoft Connect Daemon
|
ACService.exe
|
N
|
ArcSoft Connect provides product management and helpful updates for ArcSoft applications, which enables a better user experience. ArcSoft Connect will be automatically launched while running ArcSoft product, and its tray icon will display in system tray which locates at bottom right corner of the screen. You can click on this icon to view the ArcSoft Connect menu of each module.
|
|
AtapiDrv
|
AtapiDrv.sys
|
X
|
Identified by Kaspersky Anti-virus as a variant of the Trojan.Win32.Inject.aogp malware.
|
|
DHCP Client DhcpVSS
|
actmovier.exe
|
X
|
Added by the Troj/Agent-MVX.
|
|
Server for NFS
|
nfssvc.exe
|
X
|
Added by the Troj/ServU-FZ backdoor FTP program.
|
|
Print Spooler
|
spoolsv.exe
|
Y
|
Windows service that loads files to memory for later printing.
|
|
Net Logon
|
lsass.exe
|
Y
|
Microsoft service that supports pass-through authentication of account logon events for computers in a domain.
|
|
Virtual PC Host Bus Service
|
vpchbus.sys
|
Y
|
Virtual PC Host Bus Service driver.
|
|
Storage volumes
|
volsnap.sys
|
Y
|
Windows driver related to Storage volumes.
|
|
@%SystemRoot%\system32\drivers\volmgrx.sys,-100
|
volmgrx.sys
|
Y
|
Windows driver related to volume management.
|
|
Volume Manager Driver
|
volmgr.sys
|
Y
|
Windows driver for managing Windows volumes.
|
|
VMware vmx86
|
vmx86.sys
|
Y
|
VMware Virtualization Driver.
|
|
VMware NAT Service
|
vmnat.exe
|
Y
|
VMware service that provides Network address translation for virtual networks.
|
|
VMware USB Arbitration Service
|
vmware-usbarbitrator.exe
|
Y
|
VMware USB Arbitration Service. Allows USB devices plugged into the HOST to be usable by the guest.
|
|
VMware VMparport
|
VMparport.sys
|
Y
|
VMware Parallel Port Driver. Allows VMware guests to print through the host's printer.
|
|
VMware Network Application Interface
|
vmnetuserif.sys
|
Y
|
Allows VMware applications to use virtual networks.
|
|
VMware DHCP Service
|
vmnetdhcp.exe
|
Y
|
Vmware DHCP service for virtual networks. This allows your Vmware guests to receive an IP address via DHCP.
|
|
VMware Bridge Protocol
|
vmnetbridge.sys
|
Y
|
VMware Bridge Protocol driver.
|
|
VMware kbd
|
VMkbd.sys
|
Y
|
VMware Keyboard Driver.
|
|
VMware vmci
|
vmci.sys
|
Y
|
VMware Virtual Machine Communication Interface (VMCI) Driver.
|
|
VMware Authorization Service
|
vmware-authd.exe
|
Y
|
Vmware Driver that acts as a authorization and authentication service for starting and accessing virtual machines.
|
|
TabQuery Service
|
tabquery119.exe
|
X
|
Research indicates that this program is adware.
|
|
peersvc Service
|
PeerSvc.exe
|
X
|
Identified as a variant of the W32/Virut.n.gen virus.
|
|
Update Service
|
svchost.exe
|
X
|
Added by the Your PC Protector rogue anti-spyware program. This infection should not be confused with the legitimate C:\Windows\System32\svchost.exe
|
|
PIXMA Extended Survey Program
|
IJPLMSVC.EXE
|
N
|
Added by Canon printer software. This software will collect information such as printer's id number, installation date and time, ink use information, number of sheets printers, etc. It will then send this information to Canon after a certain amount of time.
|
|
Inkjet Printer/Scanner Extended Survey Program
|
IJPLMSVC.EXE
|
N
|
Added by Canon printer software. This software will collect information such as printer's id number, installation date and time, ink use information, number of sheets printers, etc. It will then send this information to Canon after a certain amount of time.
|
|
Kaspersky Anti-Virus
|
avp.exe
|
Y
|
|
|
Live Enterprise Suite
|
IAPro.exe
|
X
|
Added by the Live Enterprise Suite rogue anti-spyware program.
|
|
Guard Service
|
services.exe
|
X
|
Added by the Live Enterprise Suite rogue anti-spyware program.
|
|
Mseu
|
Mseu.sys
|
X
|
Added by the W32.Zimuse.B worm. W32.Zimuse.B is a worm that deletes files and overwrites the master boot record of the compromised computer.
|
|
Mstart
|
Mstart.sys
|
X
|
Added by the W32.Zimuse.B worm. W32.Zimuse.B is a worm that deletes files and overwrites the master boot record of the compromised computer.
|
|
Self extract service
|
Mseus.exe
|
X
|
Added by the W32.Zimuse.B worm. W32.Zimuse.B is a worm that deletes files and overwrites the master boot record of the compromised computer.
|
|
Kernel Debug Service
|
kernelx86.sys
|
X
|
Added by the W32.Rixobot worm. W32.Rixobot is a worm that spreads through removable drives and instant messaging programs. It also opens a back door on the compromised computer.
|
|
Zwunzi Service
|
zwunzi122.exe
|
X
|
Added by the Adware.Zwunzi adware.
|
|
SSHNAS
|
sshnas.dll
|
X
|
Identified as a variant of the TR/ATRAPS.Gen malware. This service is launched by svchost.exe, which is a legitimate Windows executable that should not be deleted.
|
|
svlost Service
|
svlostSrv.exe
|
X
|
Unidentified MSN Messenger worm.
|
|
HTTP Security Services Helper
|
Iasex.dll
|
X
|
Added by the Troj/Catl-A Trojan.
|
|
DQLWinService
|
DQLWinService.exe
|
?
|
This file is a service associated with Intel Viiv Software which is installed on certain computers designed for digital media entertainment.
|
|
Portrait Displays Display Tune Service
|
dtsrvc.exe
|
U
|
This file is preinstalled on many computers, is in many monitor software packages, and is involved in adjusting monitor display settings by using a mouse instead of the monitor buttons. EzTune, MagicTune, ImageTune, and forteManager are just a few of the software products this file is found in. If using the monitor buttons is sufficient for you, you can disable the service. Unknown at this time if setting the service to manual would cause the program to not work.
|
|
tdifw_drv
|
tdifw_drv.sys
|
X
|
Added by the Desktop Defender 2010 rogue anti-spyware program. This driver is potentially legitimate, but is commonly bundled with malware programs.
|
|
WDefend
|
svohost.exe
|
X
|
Part of the Windows Police Pro rogue anti-spyware infection.
|
|
GbpSvc
|
GbpKms.sys
|
X
|
Added by the nfostealer.Bancos.BB Trojan. Infostealer.Bancos.BB is a Trojan horse that attempts to steal information from the compromised computer.
|
|
User Profile Hive Cleanup
|
uphclean.exe
|
Y
|
When users experience logoff or other profile problems in certain Windows operating systems, the solution is to install the User Profile Hive Cleanup Service by Microsoft Corporation.
|
|
LVCOMSer
|
LVComSer.exe
|
Y
|
Installed with older Logitech WebCams, this file communicates with the camera driver. It will show twice, once by system and once by user.
|
|
Microsoft USB Bus Controller
|
usbctl.exe
|
X
|
Added by the WORM_ASPXOR.AB worm.
|
|
SecureWarrior Security Service
|
SecureWarriorSvc.exe
|
X
|
Added by the SecureWarrior rogue anti-spyware program.
|
|
AntiPol
|
svchast.exe
|
X
|
Added by the Windows Police Pro rogue anti-spyware program.
|
|
SecureFighter Security Service
|
SecureFighterSvc.exe
|
X
|
Added by the SecureFighter rogue anti-spyware program.
|
|
SecureVeteran Security Service
|
SecureVeteranSvc.exe
|
X
|
Added by the SecureVeteran rogue anti-spyware program.
|
|
SecuritySoldier Security Service
|
SecuritySoldierSvc.exe
|
X
|
Added by the SecuritySoldier rogue anti-spyware program.
|
|
SecurityFighter Security Service
|
SecurityFighterSvc.exe
|
X
|
Added by the SecurityFighter rogue anti-spyware program.
|
|
SaveArmor Security Service
|
SaveArmorSvc.exe
|
X
|
Added by the SaveArmor rogue anti-spyware program.
|
|
sofatnet Service
|
sofatnet.exe
|
X
|
Identified by Comodo as Backdoor.Win32.Refpron.~B.
|
|
Net_Login
|
svchust.exe
|
X
|
Identified as a variant of the Trojan-Clicker.Win32.Delf.cpm malware.
|
|
Net Login
|
svchost.exe
|
X
|
Identified as a variant of the Trojan-Clicker.Win32.Delf.cps malware.
|
|
SaveDefender Security Service
|
SaveDefenderSvc.exe
|
X
|
Added by the SaveDefender rogue anti-spyware program.
|
|
TrustWarrior Security Service
|
TrustWarriorSvc.exe
|
X
|
Added by the TrustWarrior rogue anti-spyware program.
|
|
SoftSafeness Security Service
|
SoftSafenessSvc.exe
|
X
|
Added by the SoftSafeness rogue anti-spyware program.
|
|
McAfee SiteAdvisor Service
|
McSACore.exe
|
Y
|
Added by the McAfee SiteAdvisor software. This software will alert you when you are visiting a web site that is considered fraudulent or harmful.
|
|
Alerter AlerterALG
|
<random>.exe
|
X
|
Added by the W32/Backdr-AR backdoor.
|
|
SafetyKeeper Security Service
|
SafetyKeeperSvc.exe
|
X
|
Added by the SafetyKeeper rogue security program.
|
|
SaveKeeper Security Service
|
SaveKeeperSvc.exe
|
X
|
Added by the SaveKeeper rogue anti-spyware program.
|
|
QuickHealCleaner Security Service
|
QuickHealCleanerSvc.exe
|
X
|
Added by the QuickHealCleaner rogue anti-spyware program.
|
|
SQL Server VSS Writer
|
sqlwriter.exe
|
Y
|
Provides the interface to backup/restore Microsoft SQL server through the Windows VSS infrastructure.
|
|
SystemCop Security Service
|
SystemCopSvc.exe
|
X
|
Added by the SystemCop rogue anti-spyware program.
|
|
AntipyProex
|
svchasts.exe
|
X
|
Added by the Windows Police Pro rouge anti-spyware program.
|
|
BlockDefense Security Service
|
BlockDefenseSvc.exe
|
X
|
Added by the BlockDefense rogue anti-spyware program.
|
|
SaveDefense Security Service
|
SaveDefenseSvc.exe
|
X
|
Added by the SaveDefense rogue anti-spyware program.
|
|
TrustNinja Security Service
|
TrustNinjaSvc.exe
|
X
|
Added by the TrustNinja rogue anti-spyware program.
|
|
SaveSoldier Security Service
|
SaveSoldierSvc.exe
|
X
|
Added by the SaveSoldier rogue anti-spyware program.
|
|
SaveKeep Security Service
|
SaveKeepSvc.exe
|
X
|
Added by the SaveKeep rogue anti-spyware program.
|
|
WiniShield Security Service
|
WiniShieldSvc.exe
|
X
|
Added by the WiniShield rogue anti-spyware program.
|
|
Google Update Service (gupdate<numbers and characters>)
|
GoogleUpdate.exe
|
N
|
This startup is used by Google products such as Picasa and Chrome, among others, to check for new updates.
|
|
NDISRD
|
ndisrd.sys
|
X
|
Added by the Trojan.Interrupdate Trojan. Trojan.Interrupdate is a Trojan horse that lowers security settings.
|
|
AntipyPro_12
|
svchast.exe
|
X
|
Added by the Windows Antivirus Pro rogue anti-spyware program.
|
|
VMware Virtual Ethernet Adapter Driver
|
vmnetadapter.sys
|
Y
|
Driver for VMware's Virtual Ethernet Adapters.
|
|
stllssvr
|
stllssvr.exe
|
N
|
This file is a service installed with the program SureThing Labelflash Disc Printer also known as SureThing CD Labeler made by MicroVision Development, Inc. It doesn't need to run at startup, so set the service to manual. If you disable it, you won't be able to print CD labels.
|
|
Genesis Streaming Service
|
WPGApplicationLauncher.exe
|
U
|
Allows you to communicate with projectors via wireless.
|
|
AuthenTec Fingerprint Service
|
AtService.exe
|
U
|
Used by IBM Thinkpad's fingerprint identification software.
|
|
Data Transfer Service
|
DTS.exe
|
U
|
Used by IBM Thinkpad's fingerprint identification software.
|
|
Firewall Client Agent
|
FwcAgent.exe
|
Y
|
|
|
Web Management Service
|
WMSvc.exe
|
U
|
Allows you to manage Microsoft Internet Information Services (IIS) via the web.
|
|
IDrive WebManager
|
IDriveWebM.exe
|
U
|
Added by the IDrive online backup solution. IDrive offers a free 2GB online backup of your local files and a paid solution if you need more space. This service allows you to control your backup settings from the web.
|
|
IDriveE Service
|
IDriveE Service.exe
|
U
|
Added by the IDrive online backup solution. IDrive offers a free 2GB online backup of your local files and a paid solution if you need more space.
|
|
WiniFighter Security Service
|
WiniFighterSvc.exe
|
X
|
Added by the WiniFighter rogue anti-spyware program.
|
|
ComodoBackupService
|
CmdBkSvc.exe
|
Y
|
|
|
MRSVSS Service
|
mrsvss.exe
|
X
|
Added by the W32/IRCBot-AES worm and IRC backdoor.
|
|
podmena
|
Podmena.dll
|
X
|
Added by the Podmena malware. Please note that C:\Windows\System32\svchost.exe is a legitimate program and should not be deleted.
|
|
podmenadrv
|
podmena.sys
|
X
|
Added by the Podmena malware.
|
|
<various characters>
|
QQmusic.exe
|
X
|
Identified by Kaspersky as a variant of the Trojan-Downloader.Win32.Agent.afen malware.
|
|
COM+ Windows System
|
winsyscom.exe
|
X
|
Identified by Symantec as a variant of the Backdoor.Trojan malware.
|
|
HNC Engine Service
|
hnceng.exe
|
U
|
Added by the Green Dam-Youth Escort surveillance program. This program is an Internet filtering software that the Chinese government will require to be installed on all new computers sold in China after July 1, 2009.
|
|
MsPowerSvc
|
MPSvcC.exe
|
U
|
Added by the Green Dam-Youth Escort surveillance program. This program is an Internet filtering software that the Chinese government will require to be installed on all new computers sold in China after July 1, 2009.
|
|
DrvFltIp
|
Drvfltip.sys
|
X
|
Added by the UnVirex rogue anti-virus program.
|