Name Filename Status Description
N/A system32.exe X Added by the AGOBOT-KU WORM! Note - has a blank entry under the Startup Item/Name field
(Default) Shania.vbs X Added by the SHANIA TROJAN!
*StateMgr statemgr.exe Y Windows ME default for System Restore. Do NOT disable!
.NET config sysmon32.exe ? ??
.Prog services.exe X Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
1Srv32 SpyAgent4.exe U SpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC."
1Win32Cfg SpyBuddy.exe U SpyBuddy monitoring software
666 Ska.exe X Added by the PIPES TROJAN!
Acronis Scheduler2 Service schedhlp.exe U Part of Acronis True Image - backup software. Co-operates with the "schedul2.exe" servuce to perform backup/restore tasks correctly. Required if you want to use TrueImage to do some real backup/restore tasks - not if you only want to explore/mount images.
ActiveDesktop systray32.exe X Added by the DABOOM WORM!
Adobe sysconfig.exe X Added by an unidentified WORM or TROJAN!
Adobe sysbat32.exe X Added by the LOWZONES.T TROJAN!
All Aboard Status stswin.exe U All Aboard! Internet Connection Sharing status icon
ANONYMIZER_SPYWAREKILLER SpyWareKiller.exe U Anonymizer Spyware Killer
ATTBroadbandUpdate SAUpdate.exe U Big Brother from Quest Software. System and network monitor
Aureal A3D Interactive Audio sa3dsrv.exe Y For Aureal based 3D soundcards. A3D sound features won't work with this disabled
Automatic Microsoft Windows Updater suchost.exe X Added by the RBOT-EQ WORM!
Bart Station station.sbrt ? Related to PeoplePC ISP. May be a dialler for dial-up accounts?
Bat secure2.bat X Added by the ZCREW.C TROJAN!
blah service smnp.exe X Added by the RBOT.IZ WORM!
BookMarkSink syncit.exe N Bookmark synchronization utility
BookMarkSync syncit.exe N Bookmark synchronization utility
BookMarkSync2It sync2it.exe N Sync2IT BookMarkSync - "real-time automatic synchronization service that allows you to access your bookmarks, favorites and favorite files from any computer or any browser"
BuildLab services.exe X Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
CashToolbar svchost.exe X CashToolbar Downloader-MY adware. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
ccAppr svcrhost.exe X Premium rate adult content dialler
ccApps services.exe X Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
CCWC7s stealth.exe U Moleculesoft Cache, Cookie & Windows Cleaner Ver. 7
Classes srv.exe X "Switch" adult content dialler
Classes srv2.exe X "Switch" adult content dialler
ClockSync Sync.exe X ClockSynck - synchronizes your system clock with an internet time server. It's by WhenU, the makers of the Save Now spyware, and they're usually seen in tandem, so it's advised to replace it with one of may spyware free alternatives available
CLSID sed.exe X Adult content dialler
CM-SmWizard SmWizard.exe ? SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required?
Coldlife -icmp Systray.exe X Added by the FLOOD.AV TROJAN! Note - this is not the legitimate SysTray.exe
COM++ System suchost.exe X Added by a variant of the LOVGATE WORM!
COM++ System svchost.exe... X Added by a variant of the LOVGATE WORM!
COMDRV32 svdhost.exe U Orvell Monitoring 2003 - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it. Note - asks for permission to contact the IP address of http://www.protectcom.com/
Command system.exe X Added by the GATECRASH.A or GATECRASH.B TROJANS!
Compaq Computer Corp SCCenter Module SCCENTER.EXE N For Compaq PC's. Part of Backweb
Compaq Knowledge Center silent.exe&matcli.exe U "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file while silent.exe executes matcli.exe quietly in the background. Compaq Knowledge Center is required to run with the Help and Support program. If you uncheck Compaq Knowledge Center and and then run help and Support it will add another Compaq Knowledge Center in the startup menu. If you remove the Compaq Knowledge Center in the add/remove program some help menus in help and support will not be available like Fix my Presario, Preference, and Contact Technical Support". You decide
Config service.exe X Added by the ISRAZ.B WORM!
Config Loader svchosl.exe X Added by the GAOBOT.P WORM!
Config Loader sysldr32.exe X Added by the GAOBOT WORM!
Config Loader scvhost.exe X Added by the GAOBOT.AE or GAOBOT.AO WORMS!
Configuration Loader service5.exe X Added by the GAOBOT.AF WORM!
Configuration Loader sycfg34.exe X Added by the GAOBOT.AN WORM!
Configuration Loader Service.exe X Added by the GAOBOT.AO WORM!
Configuration Loader Servicess.exe X Added by the GAOBOT.AO WORM!
Configuration Loader sw32.exe X Added by the AGOBOT.BQ WORM!
Configuration Loader System.exe X Added by the GAOBOT.AO WORM!
Configuration Loader sysinfo.exe X Added by the GAOBOT.FQ WORM!
Configuration Loader svhst.exe X Added by the GAOBOT.YC WORM!
Configuration Loader systemry.exe X Added by a variant of the AGOBOT/GAOBOT WORM!
Configuration Loader smss32.exe X Added by the AGOBOT.MB WORM!
Configuration Loader syscfg32.exe X Added by the SDBOT.B TROJAN!
Configuration Loading svchos1.exe X Added by the GAOBOT.DK WORM!
Configuration Service suchost.exe X Added by the TREB TROJAN!
ConfLoader sysconf16.exe X Added by the SDBOT-FB TROJAN!
control panel smctrlw.exe N System Tray icon for a Silicon Motion LynxEM based PCI Graphics Card
Control Panel System.exe X Added by the DANI TROJAN!
cpntmgc simcss.exe X MagicControl downloader trojan variant
CPQSTUTFIX stutfix.exe Y For Compaq PC's. Fixes audio stutter problems for ESS Maestro soundcards. You can download it here. This is a Compaq originated file and has been verified as free from viruses by McAfree/Norton
CRC Value Verifier svchost32.exe X Added by the RBOT-OA WORM!
Creative PCI Audio Configuration Utility starter.exe N System Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on this special page. Similar to EnsoniqMixer
csaRem spqmdmui.exe N Compaq modem country selection
CSScheduleCheck SCHWIZEX.EXE Y Part of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot
cursor Screendragon_VS_Taskbar.exe N ScreenDragon video player
Cyber Trio showmode.exe U From G-Tek Technologies. Allows you to set the PC in one of three modes, Standard, Enhanced and Kiddo. Standard is full function, Enhanced prevents accidental damage and Kiddo is a play environment for kids. Pre-installed on some Packard Bell PCs
Data System.dat.vbs X Added by the BISCUIT.A WORM!
spyban SpyBan.exe X "Spyware remover" of dubious repute - see this list of non-Recommended anti parasite software
Direct settings sdchost.exe X Added by the DAEMONI-I TROJAN!
directx Sqlexploit.exe X Added by the SDBOT.D TROJAN!
DirectX for Microsoft Windows Sservice.exe X Added by the PRORAT TROJAN!
Diskstart Snt.exe X Adult content dialler
spy-control Spy-Control.exe X "Spyware remover" of dubious repute - see this list of non-recommended anti parasite software
Driver32 Scam32.exe X Added by the SIRCAM WORM!
dRMON SmartAgent SmartAgt.exe U Part of the network monitoring program group for 3Com NIC cards. See here for more info
DSL Monitor spdstrm.exe N Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
DwlClient support.exe N Download manager for Dell support alerts
Dx sys*.exe [* = random number] X Added by the DEXTER.A WORM!
eanth_critical_update_alert sys_alert.exe N eAcceleration Stop-Sign related; not recommended; see note
eanth_system_patcher sys_alert.exe N eAcceleration Stop-Sign related - not recommended, see note
Eapcisetup sbsetup.exe N Rockwell RipTide soundcard application software. Sound works without it
easyServ Server.exe X Added by the EASYSERV TROJAN!
ENCSurf surfboard.exe ? ??
EnsoniqMixer starter.exe U Puts the Ensoniq mixer in system tray. From Ensoniq Technologies "Our mixer is a critical part of the soundcard as it fixes sound problems and replaces the MS mixer which can no longer be used". If you find you don't need it - try one of the solutions on this special page. Similar to Creative PCI Audio Configuration Utility
EPSON Background Monitor STMS.EXE N Supposed to keep an Epson printer ready for quick printing.  Users report little difference whether it is on or not
Explorer shellexpl.exe X Added by the GPIX and SHELDOR VIRUSES!
Explorer shellexp.exe X Added by a variant of the SHELDOR TROJAN!
FastTrack Accelerator SPEED UP.EXE N FastTrack Accelerator - "speedup" utility for programs that use the FastTrack network such as KaZaA Media Desktop, Grokster and Morpheus
fegoze SVCH0ST.EXE X Added by the GRAYBIRD.D TROJAN!
FieldForms Sync SyncService.exe U Resco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run, on a wide range of mobile devices. Supports Microsoft Access databases, and provides for synchronization of other data as well
FireWire Driver samx.exe X Added by the SDBOT.AE WORM!
FlashPath Monitor SDSTAT.EXE N System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
FlashPath Status SDSTAT.EXE N System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
France svchost.exe X Added by the MIMAIL.L WORM!. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
frguk shdrkmck.exe ? ??
FriendlyTypeName services.exe X Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
FriendlyWebQuick-Launch SELFCERT.EXE N selfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as well
Games Acceleration svshost.exe X EasySearch adware
GammaHotKeys setgamma.exe U Part of the RadeonTweaker program for adjusting ATI Radeon graphics cards. Allows you to adjust the gamma (or brightness) when playing a full-screen game without switching back to the desktop
Generic host proccess for windows SVCHOSTS.EXE X Added by an unidentified VIRUS, WORM or TROJAN!
Generic Host Process SCHOST.EXE X Added by the RBOT-NC WORM!
GLSetT32 smsiexec.exe X Added by the OPTIX-D TROJAN!
golumm services.exe X CoolWebSearch parasite variant. Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
HalifaxHowardCluster skinkers.exe U Howard the Weatherman desktop client from Halifax by Skinkers - marketing/messaging tool. Leave enabled if you want to receive messages
hellodolly shost.exe X Added by the YODO WORM!
helpmanager spoler.exe X Added by the RANDEX.J WORM!
hErcUnes softhost.exe X Added by the GARROCH WORM!
Hot Key Kbd 2690 Daemon SK9910DM.exe U Multimedia keyboard manager - required if you use any special keys
Hot Key Keybd 9910 Daemon SK9910DM.exe U Multimedia keyboard manager - required if you use any special keys
Hotfix Updat svdhost32.exe X Added by the GAOBOT.ZW WORM!
hp center UI ShadowBar.exe X User Interface for HP Center
HP Internet Center SURFBRD.EXE N Loads the HP Internet center surfboard on startup. HP Internet Center allows you to customize the multimedia keys on the fly without having to go the Control Panel --> Keyboards to change them
HPLJ Config SetConfig.exe Y Connects system to networked HP printer.
hpScannerFirstBoot scannerfb.exe ? HP scanner related
hsim sexgame.exe X Unidentified malware
IC_KEY_3 spvic.exe N Instant Chess related
Iehelper syslaunch.exe X Outwar adware downloader
iIWiper Systemwiper.exe N System Wiper from iI Software - allows you to clear the history of your activites from you computer. Run manually on a regular basis
farfel sifxinst.exe ? Uninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. The company's web site is not available anymore.
InstallNAIProduct SETUP.EXE ? Could be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error?
InteliSys smss.exe X Advertisingvision adware. This infection should not be confused with the legitimate C:\Windows\System32\smss.exe.
Internat systray.exe X Added by the ALADINZ.P TROJAN! Note - this is not the legitimate systray.exe process
Internet Config svchosts.exe X Added by the SDBOT TROJAN!
Internet Connection Wizard stisvsq.exe X EasySearch adware
internet service syscfg32.exe X Added by the RBOT-QS WORM!
Internet Services systemdev.exe X Added by the SDBOT-PW WORM!
Internet Sweeper Sweeper.exe N Internet Sweeper - removes unnecessart left over files after browsing the internet
Intervideo WinScheduler SchSvr.exe N WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs
Introducing Media Manager SPLASHA.EXE N MS Media Manager tour. Not required
IPConfig svcxnv32.exe X Added by the HACARMY.E TROJAN!
irc session sessionmgr.exe X Added by the SDBOT-ACE WORM!
KernelFaultChk sms.exe X Added by the DEADHAT WORM! Do not confuse with the valid "kernelfaultcheck" which runs "dumprep 0 -k" or "dumprep 0 -u"
Kernell systems.exe X Added by the TARNO.C TROJAN!
key sysxp.exe X Added by the BEAGLE.AB WORM!
key sys_xp.exe X Added by the BEAGLE.AC WORM!
Key2 serve.exe ? ??
load32 swchost.exe X Added by the TURTA.A WORM!
load= shambl3r.exe X Added by the REMABL WORM!
<not used> Spoolsv.exe X Added by the CIADOOR.B TROJAN!
firewall spoolsv.exe X Added by the W32.Dizan.F virus. W32.Dizan.F is a virus that spreads by infecting executable files. It also opens a back door on the compromised computer.
loads.exe suploads.exe X Popuppers.com adware downloader
Lotus QuickStart smartctr.exe N Lotus central application, called SmartCenter, which runs on the Windows desktop. SmartCenter toolbar stretches across the top or, optionally, the bottom of the screen. Uses a lot of resources. Available via Start -> Programs
Lotus SuiteStart suitest.exe U Puts the individual Lotus components in the system tray taskbar when you start Windows. Can be disabled via MSCONFIG -> Startup as "Lotus SuiteStart 97 Edition". All individual components available via Start -> Programs
lsass start.bat X Added by the ZCREW TROJAN!
LTSMSG Shell32.exe X Added by the LEMIR.B TROJAN!
M1cr0s0ft S3rcurity systemconfig.exe X Added by the RBOT.BKB WORM!
Media service SYSTEM64.EXE X Added by the RBOT.QV WORM!
MediaFace Integration Sethook.exe N Fellowes Neato™ cd label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar"
media_stub stub.exe X Mini-Player,  IMESH related foistware.
MemConfig SetupIE.com X Added by the TAPLAK WORM!
MessagerStarter Freeserve StartMessager.exe N Freeserve Messenger
Micr Update soundblaster.exe X Added by the SDBOT.NP WORM!
Microsof Windows Host svhost32.exe X Added by the RBOT.ADY WORM!
Microsofot x386 System Monitor system32.exe X Added by the WOOTBOT.M WORM!
microsoft svchost.exe X Added by the ASTEF or RESPAN WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Microsoft AutoUpdater svhost.exe X Added by the RBOT.QG WORM!
Microsoft Conf Ldr sysconf.exe X Added by a variant of the SDBOT TROJAN!
Microsoft DirectX Spoolserv.exe X Added by the DINFOR WORM!
Microsoft IIS syshost.exe X Added by the FRANCETTE WORM!
Microsoft Intellitype Pro speedkey.exe U Additional keyboard shortcuts on MS programmable keyboard
Microsoft Internet Services Smss32.exe X Added by the RBOT.MS WORM!
Microsoft IPC system.exe X Added by the NULLBOT TROJAN!
Microsoft IPC svshost.exe X Added by an unidentified VIRUS, WORM or TROJAN!
Microsoft IT Update svchsst.exe X Added by the RBOT-DH WORM!
Microsoft LSASS386 Protocol scvhost32.exe X Added by a variant of the SPYBOT WORM!
Microsoft MSUPDATE SpoolSvc.exe X Added by the SXTB-A TROJAN!
Microsoft RDLL sysconf32.exe X Added by a variant of the SDBOT TROJAN!
Microsoft Restore scrgrd.exe X Added by the SPYBOT.BR WORM!
Microsoft SCVHOST32 Protocol scvhost32.exe X Added by a variant of the RBOT WORM!
Microsoft Secure Messenger.NET Service securitychk.exe X Added by the SDBOT.VT WORM!
Microsoft Server Application Sound.exe X Added by the RBOT-NE WORM!
Microsoft Services services.exe X Added by the ALETS TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
Microsoft Services svshost.exe X Added by the ALETS.B TROJAN!
Microsoft Sidewinder Game Controller Software SWTRAY.EXE N MS SideWinder game controller system tray icon. Available via Start -> Programs
Microsoft Software sysinfo33.exe X Added by the RBOT.LS WORM!
Microsoft Sound Driver sound32.exe X Added by a variant of the SPYBOT WORM!
Microsoft Spool Server for Win32 spoolsrv.exe X Added by the RANDEX.H WORM!
Microsoft SSISVRI32 Protocol ssisvri.exe X Added by a variant of the SPYBOT WORM!
Microsoft Synchronization Manager slhost.exe X Added by the SDBOT.YH WORM!
Microsoft Synchronization Manager svhost.exe X Added by the SDBOT-PY WORM!
Microsoft System Checkup sysmgr.exe X Added by the SDBOT-OO TROJAN!
Microsoft Update Smss32.exe X Added by the RBOT.CB WORM!
Microsoft Update sys32cfg.exe X Added by a variant of the SPYBOT WORM!
Microsoft Update systemi32.exe X Added by a variant of the SPYBOT WORM!
Microsoft Update snlogsvc.exe X Added by a variant of the RBOT WORM!
Microsoft Update svhost.exe X Added by the RBOT-PI WORM!
Microsoft Update Machine servicz.exe X Added by the RBOT-HU WORM!
Microsoft Update Machine SP2.exe X Added by the SPYBOT.FP WORM!
Microsoft Update Machine system03.exe X Added by the RBOT-NM WORM!
Microsoft Update Machine systemll.exe X Added by the RBOT-JT WORM!
Microsoft Update Machine svshost.exe X Added by the RBOT.AK WORM!
Microsoft Update Machine scvhost.exe X Added by the RBOT-GS WORM!
Microsoft update service systemm.exe X Added by a variant of the SDBOT WORM!
Microsoft Updates systemc32.exe X Added by the RBOT-GR WORM!
Microsoft Virual Machine sms.exe X Added by the RBOT-SP WORM!
Microsoft Visual SourceSafe services.exe X Added by the NEVEG.B or NEVEG.C WORMS!. Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup or the Microsoft Visual SourceSafe program
Microsoft Webserver svctrl.exe U Personal web server program which enables you to create and host a web server from your computer. Not required for most people
Microsoft Windows Security spvsper.exe X Added by a variant of the SDBOT WORM!
Microsoft Windows Update spools.exe X Added by the SDBOT.TD WORM!
Microsoft Windows Update svchos.exe X Added by the SDBOT.AC WORM!
Microsoft Windows Update svcshost.exe X Added by the FORBOT-CF WORM!
Microsoft Windows Update svmhost.exe X Added by the FORBOT-CH WORM!
Microsoft Windows Update svshost.exe X Added by the WOOTBOT.CJ WORM!
Microsoft Windows Update scvvhost.exe X Added by the FORBOT-DH WORM!
Microsoft Windows Updater svchostz.exe X Added by the DAEMONI-E TROJAN!
Microsoft WinUpdate svh0st.exe X Added by the SPYBOT.DL WORM!
Microsoft WinUpdate syslx32.exe X Added by an unidentified VIRUS, WORM or TROJAN!
Microsoft WinUpdate syswin32.exe X Added by a variant of the SDBOT WORM!
Microsoft WinUpdates serm32.exe X Added by the RBOT.GE WORM!
Microsoft Wxdate Syswu32.exe X Added by the SPYBOT.HZ WORM!
Microsoft--Updates sxvhost.exe X Added by the RBOT-FH WORM!
Microsoft-Updates svxhost.exe X Added by the RBOT-CT WORM!
Microsoftkeysd systemproc.exe X Added by the FORBOT-BI WORM!
Microsoftkeysd systemwin32s.exe X Added by the WOOTBOT.CO WORM!
MicrosoftOEM smvss.exe X Added by the DEDLER-G TROJAN!
MicrosoftUpdate syshelper.exe X Added by an unidentified VIRUS, WORM or TROJAN!
MicrosoftValue syscnfg.exe X Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside
Microsoftvirus sysoverload.exe X Added by the FORBOT-AL WORM!
Microsoft® System Mapper SysMap.exe X Added by the MAPSY TROJAN!
Microszoft Update Mach1nezs svchst.exe X Added by the RBOT-ED WORM!
MM Install setup.exe ? Possibly Money Manager from Moneysoft?
ModularConfig syscnfg.exe X Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside
Monitoring Service svchost.exe X Added by the CONE.C WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
MRU-Blaster Scheduler scheduler.exe U MRU-Blaster scheduler - detects and cleans MRU (most recently used) lists on your computer
MS Config Loader svchos1.exe X Added by the AGOBOT.R WORM!
MS Security Hotfix service5.exe X Added by the GAOBOT.AG WORM!
MS Sound Config 16bit sndcfg16.exe X Added by the SDBOT.MB TROJAN!
MS SyS Restore sysrestore.exe X Added by the RBOT.XM WORM!
MS Update syshost.exe X Added by the EVAMAN-F WORM!
MS Updates syshosts.exe X Added by the MYDOOM.Y WORM!
MSChoExE suge.exe X Added by a variant of the RBOT WORM!
MSCORE syscnfg.exe X Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside
MSDLL syscnfg.exe X Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside
msgserv_ Syss.exe X Added by the FANTA TROJAN!
Msgtray sys16.exe X Added by an unknown VIRUS!
MSInstall smvss.exe X Added by the DEDLER-G TROJAN!
MSkernel32 System.exe 4820 X Added by the TUXDER TROJAN!
MSKExe spamkiller.exe U McAfee SpamKiller
msn system32.exe X Added by the KITRO.A WORM!
MSNMSGRE swef.bat X IRC backdoor TROJAN or WORM!
MSNMSGRR swin.bat X IRC backdoor TROJAN or WORM!
MSNMSGRS1 swed.bat X IRC backdoor TROJAN or WORM!
MSOffice services.exe X Browser hijacker. The file is placed in a newly created MSOffice folder in System32. Note - this is NOT the legitimate services.exe process, which should NOT figure in Msconfig/Startup!
MSSVC svcsys.exe X Added by the FATOOS-C TROJAN!
MSSYSTEM svcsys.exe X Added by the FATOOS-C TROJAN!
MSUpdate svchosthlp.exe X Added by the BLASTER.T WORM!
MsWindows SysDate sysmsvc.exe X Added by the SPYBOT.FCD WORM!
mswspl searchbarcash.exe X SearchBarCash adware
MutexServiceEx Sys32Smm.exe N Webroot Sofware's discontinued "Privacy Master"
My App SMSSvc.exe X Added by the NEGASMS.A TROJAN!
My Search Bar Eq S4BAREQ.EXE X MySearch bar parasite
Myapp service.exe X Homepage hijacker
myCIO.com Splash Splash.exe N Splash screen for McAfee VirusScan ASaP on-line scanner
NAV Agent systems.exe X Added by the TARNO.C TROJAN! Note - this is not the valid Norton Antivirus entry of the same name
NavAgent32 SCardSvr32.Exe X Added by the MOFEI.B WORM!
navman_20 sysnav32.exe X Hijacker, possibly a CoolWebSearch variant
NB Start Menu STARTM.EXE N Part of McAfee Nuts & Bolts. Provides the same control as MSCONFIG and can be used instead if you have N&B
Network Service svchost.exe X CoolWebSearch parasite related. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
nForce Tray Options sstray.exe N nVidia nForce Taskbar Utility - quick access to the nForce2 "Sound Storm" control panel and related utilitys
Norton Live Updater Sochost.exe X Added by the GAOBOT.AO WORM!
Norton System Doctor Sysdoc32.exe N Norton Disk Doctor from Norton Utilities. Automatically runs at start-up, major resource hog and best started manually form Start -> Programs. Delete the shortcut in the Start -> Programs -> Startup folder as well
NovastorSchedulerd SCHENGD.EXE U NovaStor NovaBACKUP Scheduler - back-up utility. If you don't have regularly scheduled back-ups you don't need it
NSystemMonitor Symmon.exe N Norton Uninstall Deluxe - monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging
NT Logging Service Syslog32.exe X Added by the DONK.B or  DONK.C or DONK.L or DONK.M or DONK.O WORMS!
NvClipRsv svchost.exe X Added by the DUMARU-AK WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
NvClipRsv swchost.exe X Added by the DUMARU-AK WORM!
OD SYSCNTR.EXE X HotVideo dialler
OEM32 Tools sres32.exe X Added by a variant of the SPYBOT WORM!
Olive System Szchost.exe X Added by the MERCURYCAS.A TROJAN!
OmniPass scureapp.exe U OmniPass from Softex Inc. - secure password management software
Online Service svchost.exe X Added by the HOSTIDEL.B or HOSTIDEL.C or TARNO.B TROJANS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
OnlinePCfix SmoothSurfer SS.exe U Smooth-Surfer - blocks banners, ads, popups, and cleans MRU and Recent file lists
Outwar syslaunch.exe X Outwar adware downloader
PcEXPLODE specialfile.exe X Added by the RBOT.RH WORM!
PCHEasySearch STUpdate.exe X PCH EasySearch bar
pictureBUZZTray swtray.exe N System Tray access to PictureBUZZ on-line printing software from Streetwise Software. If you use the software set the page you use as a favourite in your browser and run it manually
Piracy SysUtil.exe N Software Piracy Alert feature bundled with PGWare software. Cries foul when it detects an 'illegal' version. The alerts are reported to disappear as soon as the software is correctly registered. There are privacy issues though: "The Software includes a feature that assigns a unique order number to GameGain based on purchase information. The Software reports this number to us via the internet either when you run the Software or enter the registration number, or both. The Software may also identify and report to us your IP address, date and time of installation, registration and/or use. We use this information strictly to count the number of installations, detect unauthorized access or piracy of the Software, and develop rough statistical data regarding the geographic location of our users"
pnpsvc_lock startsvs.exe X Browser hijacker
PowerManager Svchost.exe X Added by the JEEFO VIRUS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
PPK Setup(Server) SEServe.exe U Programmable Power Key on Sony Vaio laptops. "Using the Programmable Power Key (PPK) button, collect your e-mail automatically with one key stroke. You can also program your PPK to turn on your SuperSlim Notebook at a predetermined time and perform simple tasks - completely unattended"
precpop2 starter.exe X PrecisionPop adware
PrevxHome SAGUI.exe Y PrevX Home intrusion prevention software
print sharing start.bat X Added by the ZCREW TROJAN!
Print Spooler Spoolsv.exe X Added by the CIADOOR.B TROJAN! Note - "Spoolsv.exe" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file
Print Spooler spoolsvc32.exe X Added by the SDBOT.BB TROJAN!
Print Spooler spools.exe X Added by the RBOT-LD WORM!
Printer Spyassault.exe X Spyware remover" of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites
Printer spool Service spool.exe X Added by a variant of the SDBOT WORM!
PrintSpoolSv System.exe X Added by the BDOOR-S TROJAN!
QQ sendmess.exe X Added by the SEMES TROJAN!
QTSvc shman.exe X Premium rate adult content dialler
QTSvc ssvr.exe X Premium rate adult content dialler
QWS3270 Sessions sessions.exe U QWS3270 Secure terminal emulation software
RA Server Slave.exe X Added by the Troj/Bdoor-ABJ backdoor Trojan.
RegCleaner SYSio32.exe X Added by an unidentified VIRUS, WORM or TROJAN! Note - do not confuse this with the popular RegCleaner registry cleaner freeware
RegDone services.exe X Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
reggsdg spoolserv.exe X Added by the SDBOT-MS WORM!
Registry System16 Checkup Monitor SystemReg16.exe X Added by a variant of the RBOT WORM!
Remote Access Slave Synchost.exe X Added by the RIPJAC TROJAN!
RHSI SHS SHS.exe N Rogers Hi-Speed Internet software. "Should you ever lose access to your Rogers Hi-Speed Internet connection or e-mail, the Self-Healing Software (SHS.exe) will automatically repair your settings to get you up and running in a flash"
RjLyraInstaller setup.exe ? ??
RNBOStart sentstrt.exe U Program used to initialise the VxD virtual driver for Sentinel drivers associated with Rainbow H/W keys that plug-in to the parallel port. These are usually supplied with workplace design tools and restrict the use of the software only to the machine to which the H/W key is connected. Required if you have such tools
Run StartupMonitor StartupMonitor.exe U Mike Lin's StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu
run= svcinit.exe X CoolWebSearch parasite variant
run= smsrun16.exe Y Microsoft Systems Management Server (SMS) related - program that reads SMSRUN16.INI on clients running Win 3.1, Windows for Workgroups, Win95, or OS/2 to create program groups on the client and then launch SMS client programs
run= sec5dec.exe X Added by the ATAK.G WORM!
RunProg Server.exe X Added by the OPTIX.04.A TROJAN!
Run[0] syscnfg.exe X Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside
S0undMan svch0st.exe X Added by the LOVGATE.AB WORM!
farfel S24EvMon.exe Y Event Monitor that supports communication between the drivers and wireless adapters.
S3 Internal Chip s3serv.exe X Added by the AGOBOT-DD WORM!
S3apphk S3apphk.exe ? S3 graphics related?
S3Hotkey s3hotkey.exe ? S3 Video driver related. What does it do and is it required?
S3Mon S3Mon.exe ? S3DuoVue multi-monitor taskbar helper by S3 Graphics. What does it do and is it required?
S3TRAY S3Tray.exe N S3 display configuration taskbar utility for S3 chipset based graphics cards. Can be run from Start-> Settings -> Control Panel -> Display
s3tray2 s3tray2.exe ? Same as the s3tray entry in this table?
S3TRAYHP S3trayhp.exe ? S3 Video driver related. What does it do and is it required?
S4F S4F.exe U S4F internet filtering software
s4helper s4helper.exe X Searchcentrix hijacker
SA Sa3.exe ? Logitech QuickCam driver. Is it required?
SAService SAservice.exe ? Associated with Cyber Trio and Warner troubleshooting software from G-Tek Technologies and pre-installed on some Packard Bell and NEC PCs. What function does this perform and is it required? The entry corresponding to Site Advisor can be found here.
Sa3dsrv Sa3dsrv.exe N 3D sound extension for Windows
saap saap.exe X 180Solutions/N-Case adware variant
Sabreserver SABSERV.EXE N Airline reservation software from Sabre. Available via Start -> Programs
Safe SafeWin.exe X Added by the FOCOSENHA TROJAN!
SafeInstall.exe SAFEIN~1.EXE N Monitors a download and ensures an newer version of a file isn't replaced by an older one
SafeOFF SafeOff.exe N Provides protection that if user accidentally presses the power switch a dialog will pop up for confirmation
SafeSearch safesearch.exe X AutoSearch parasite variant
SafeSurfingUpdate SSUpdate.exe X DyFuCa/MoneyTree parasite variant
Sagate Security Firewall sagate.exe X Added by the GAOBOT.BOW WORM!
SAgent2ExePath SAgent2.exe N Seiko Epson printer status agent. Disable if printer is not used often
sagnt sagnt.exe X Adware web downloader
SAHagent Sahagent.exe X ShopAtHomeSelect parasite
saie saie.exe X 180Solutions/N-Case adware variant
SAIMON SaiMon.exe U Saitek joystick driver
sain sain.exe X 180Solutions/N-Case adware variant
sais sais.exe X 180Solutions/N-Case adware variant
SaiSmart SaiSmart.exe ? "Smart Button Special Sauce" - included with the latest software for Saitek game controllers. Related to the "S", "Shift" or "Smart" button. What does it do and is it required?
SaitekAutoConfigure saicnfig.exe U Configuration for Saitek game controllers
salm salm.exe X 180Search adware
salm salm.exe X 180Solutions/N-Case adware variant
SAMcal SAMcal.exe U SamCal - calendar/reminder program
SandIcon SandIcon.exe N SanDisk ImageMate CompactFlash card reader SDDR-31 (USB). Very little use except to place the Sandisk icon beside its drive designation in Windows Explorer. The reader itself will work fine without it. The simplest thing is to just unplug the reader when you're not using it. It may slow the startup by a few nanoseconds, but once the software sees there's no reader, you get back the resources
sapp sapp.exe X 180Solutions/N-Case adware variant
SATARaid SATARaid.exe U RAID driver for serial ATA disks on some motherboards such as the DFI Lanparty range. Only loaded if one is using RAID support on SATA drives
satmat satmat.exe X Transponder parasite updater/installer
SAUpdate SAUpdate.exe U Big Brother from Quest Software. System and network monitor
SAVAgent SAVAgent.exe Y Part of Sophos anti-virus software. Required for centrally administered Sophos updates to work correctly, e.g. automatically updating PCs used by dial-in home or out-of-office users
Save Save.exe X Rebranded version of SaveNow advertising spyware
SaveDate SaveStartDate.Exe X Unidentified adware
Savenow SaveNow.exe X Advertising spyware. Installed as part of the Kazaa Media Desktop bundle for example
Savenow savenow.exe X Added by the SPREDA.B VIRUS!
Say The Time 5.0 SAYTIME.EXE U This program has audio cues for the system clock in male and female voices, customizes the appearance of the system clock, and can synchronize it to a time server regularly
SB SB.exe U Acer Soft Button on Acer Tablet PCs
SB Watchdog SBWatchdog.exe X Spyware utility installed by the manufacturers of some laptops (Sony) used to monitor browsing habits and send them back to whoever installed it - released by SoftBank. See here for more information
SBAutoUpdate sbautoupdate.exe U SpywareBlaster auto-updater
SBDrvDet SBDrv.exe U Detects the "Easy Front-Panel Audio Connectivity Drive Internal Drive Bay" on the Sound Blaster Audigy 2 Platinium eX. Can be disabled if you don't have one
SBHC sbhc.exe X SuperBar parasite - uninstall available here
SBMX sbmx.exe N SoundMAX MPU401 MIDI device emulator for x86 VM DOS games/apps (for Win9x only)
sc scrubxp.exe N ScrubXP - utility that deletes safe to remove files, cookies, browsing history, etc
sc sc.exe U Watchdog 2.0 Software - monitoring program
sc23exec sc23exec.exe ? Possibly related to a digital camera
SC3300CC SC3300CC.exe Y SiPix digital camera Twain device driver
ScanDisk ScanDisk.exe X Added by the GANDA.A WORM! Note - this is not the valid "ScanDisk" Win9x/Me standard disk error checker
scands32.exe scands32.exe X Added by a variant of the Adclicker TROJAN!
Scanner Detector SDetect.exe N ScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the "GO" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the "GO" button
ScanRegistry scanregv.exe X Added by the MASTERLOCK TROJAN!. Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as scanregv.exe not scanregw.exe
ScanRegistry Scanregw.exe Y Scans the system registry and makes back-ups at start-up. Important should the registry become corrupt. The executable "Scanregw.exe" is located in %windir% (where %windir% is the Windows directory - C:\Windows or C:\Winnt)
ScanRegistry Scanregw.exe X Added by the STATOR WORM! Not to be confused with the legitimate ScanRegistry entry - which is a vital Windows file. The executable "Scanregw.exe" is located in %windir%System (where %windir% is the Windows directory - C:\Windows or C:\Winnt). Runs from the registry RunServices key as opposed to the Run key
ScanSpyware v * Scanner.exe X Spyware remover (where * = the version number) of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites
SCardSvr scardsvr.exe N Related to SmartCard readers and sometimes uses lots of system resources
SCardSvr SCardSvr32.Exe X Added by the MOFEI.B WORM!
Scheduled Maintenance Scheduled_Maintenance.exe N Scheduler for Iolo System Mechanic tweaking utility. It can cleans your registry and deletes temporary files at defined intervals. Available via Start -> Programs
Scheduling Agent Scheduler.exe X Added by the SUBWOOFER TROJAN! Note - this is not the real MS Scheduling agent as the executable is incorrect
Schmaili Schmaili.exe U Schmaili - insert animated smilies into your e-mail
SCHWIZEX SCHWIZEX.EXE Y Part of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot
ScManager scman.exe X Added by the FORBOT-CW WORM!
scopedll scopedll.exe X Added by a variant of the CRYPTER.C TROJAN!
Scr scr.scr X Added by the OPASERV.T WORM!
ScrapPad Scrappad.exe N ScrapPad allows you to quickly and easily record notes, thoughts, messages, and just about anything you want. Use it like you use scrap paper
Screen Calendar scrcal.exe U Screen Calendar allows you to create custom desktop wallpapers with built in active calendar and scheduler
Screen Guard Message Scan sgms.exe U Part of Access Denied security and privacy software
ScreenPrint32 ScreenPrint32.exe N ScreenPrint32 screen capture software - can be launched manually
screxe scruser2k.exe ? ??
script script.bat ? Maybe associated with DOS on a Win9x machine
ScriptBlocking SBServ.exe Y Update to Norton AntiVirus 2001. Detects certain types of script-based viruses without the need for specific virus definitions - such as JavaScript and VBScript. This will help protect you from these viruses even before virus definitions are available. Note - some users complain of problems once the update is installed - refer here for more information
ScriptSentry Scriptsentry.exe Y Script Sentry from Jason's Toolbox. Blocks malicious scripts and allows safe scripts to run. Only required if you want it to check the file associations it guards at startup. It will function regardlessly
Scroll-In-Mouse V2.0 SCROLL.EXE U Toolkit for the Lynx-3D Net scroll mouse from QTronix. Required if you use the special features
ScrSvr ScrSvr.exe X Added by the OPASERV WORM!
Scsi Scsi.exe Y SCSI Miniport driver
scvhost svzhost.exe X Added by a variant of the SPYBOT WORM!
scvhost.exe scvhost.exe X Added by the LOHAV-N TROJAN!
sd32info sd32info.exe X Added by the CRYPTER.A TROJAN!
SDaemon sdaemon.exe U PC Security from Tropical Software. 'PC Security™ 5.1 is the ultimate in computer security, offering multiple locking systems for the Windows environment and internet. Lock files, monitor programs' activities, even detect intruders! PC Security offers flexible and complete password protection, "Drag and Drop" support, plus many other handy features'
SDetect SDetect.exe N ScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the "GO" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the "GO" button
sdfsdfsdf sp2update.exe X Added by a variant of the SPYBOT WORM!
SDIN Adapter sdin.exe X Added by the FORBOT-AP WORM!
SDPhotoBar.exe SDPhotoBar.exe N SmartDraw Photo - "organize, enhance, print, and share your photos. It's also a powerful graphic editor for creating images and web graphics"
sdrss sdrss.exe X Added by the SDBOT-SQ WORM!
sealmon sealmon.exe U SealedMedia enables you to combine document protection and control with your existing applications - such as Microsoft Word, Microsoft Excel, Microsoft PowerPoint and Email
Search Hook srchhook.exe ? ??
Search-Exe SE.exe X Search-Exe hijacker
SearchEnhancement scbar.exe X IE search hijacker
searchnav searchnav.exe X SearchNav adware - IEFeatures/Popnav variant
SearchNavVersion searchnavversion.exe X SearchNav adware - IEFeatures/Popnav variant
SearchSetter searchsetter[1].exe X Browser hijacker - redirecting to FindWhateverNow.com
SearchSquire33 SearchUpdate33.exe X SearchSquire parasite
SearchUpgrader SearchUpgrader.exe X Hijacker
SecondChance sctray.exe U Power Quest Second Chance. Sets checkpoints for saving a backup copy of the registry to a disk so you can restore it if you have a crash
Secret-Crush start.exe X Hijacker that may reset your browser's home page and/or search settings to point to undesired sites
Secsys Secsys.exe U Key Interceptor - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it
secure secure.exe X DealHelper adware
SecureCleanIEClean SCIEClean.exe N SecureClean - scans your system for hidden temporary files, deleted email messages, Internet histories and caches
SecureItPro Secureitpro470p.exe U SecureIt Pro - lock your computer when you're not there, to stop malicious users from accessing your desktop
Security Accounts Manager SM samsm.exe X Added by the SPYBOT.JE WORM!
Security iGuard Security iGuard.exe N Spyware remover of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites
Security Manager SecurityManager.exe U A ComCast Internet software suite that provides a variety of features (firewall, popup blocker, parental controls etcetera) to help ensure your computer is secure, and your information is kept private
security service syss.exe X Added by an unidentified WORM or TROJAN!
SECWIZ98 SECWIZ98.EXE Y Security Wizard 98 by Chris Farmer. Offers you a variety of ways to restrict access to many of the programs and settings on your PC. Available here
SelfHostUtil slefhost.exe ? ??
SeMS SeMS.exe U

PCsms - tool that enables you to send sms text messages from your PC to any UK mobile phone

Sensiva Sensiva.exe U Symbol Commander makes the use of your PC, laptop, Tablet PC, and Pocket PC much easier and much faster. It recognizes your handwriting with unparalled performance and executes commands in a snap. Just by using your mouse, pen, or touchpad, simply draw symbols to execute actions instantly
SENTRY SENTRY.exe X From IP Insight. Allows website owners "to instantly determine the precise geographic location, connection speed and detailed demographics of every visitor to your website". Will be detected by most firewalls and the majority of home users should disable it 
Sepate Security Firewall sepate.exe X Added by a variant of the RBOT WORM!
Serials serials.exe X Any one of a variety of worms and trojans
serrdctl.exe serrdctl.exe Y "Shared Modem Service Client Event Viewer" - used when a number of PCs have access to a number of modems. Required to be running on each PC for access to the modems
Serv-U serv-u32.exe N FTP server
server server.exe X Added by the DELTAD.A WORM!
SERVER.EXE SERVER.EXE X Added by the BUSHTRO122 or SMOKODOOR TROJANS!
serverex Server.txt.vbs X Added by the DELTAD.A WORM!
Service service.exe U Added by the ALADINZ.H TROJAN!
Service services.exe X Added by the NETSKY or NETSKY.B WORMS! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup!
Service Connection sccenter.exe N For Compaq PC's. Part of Backweb
Service Host spoolxx.exe X Added by the TORVEL WORM!
Service Host svchost.exe X Added by the TORVEL WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Service Host Driver svchost.exe X Added by the HITON TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Service Manager sqlmangr.exe N SQL Server Service Manager - provides tray access to SQL server, the server agent and MSDTC. Available via Start -> Programs
Service Process SVCHOST.EXE X Added by the DARKER WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Service.exe Service.exe X "servedby.advertising" popup generator
ServiceLayer ServiceLayer.exe Y Nokia Connectivity Library support task that is needed by NCLTRAY and by the Nokia Connection Manager for either to work properly
services start.bat X Added by the ZCREW TROJAN!
Services services.exe X A variant of the IRC.bot malware. This should not be confused with the legitimate C:\Windows\System32\services.exe file.
SessMgr sessmgr.exe X Identified as Trojan:Win32/Rodecap.A by Microsoft.
Services Host Scchost.exe X Added by the DONK WORM!
Services Process services.exe X Added by unidentified spyware - recognized by Kaspersky antivirus as Small.X TROJAN!
Services.EXE services.exe X Added by the KAZPING WORM! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup!
services.exe Services.exe X Added by the CIADOOR-F TROJAN! Note - this is NOT the legitimate services.exe process, which should NOT figure in Msconfig/Startup!
ServUTrayIcon ServUTray.exe ? System Tray icon for Serv-U FTP server. Is it required?
SESync sed.exe X Downloadware/SED adware downloader
setdefprt setdefprt.exe N Sets the Brother Printer to be the default printer after installation of the printer software.
SetHook SetHook.exe N Fellowes Neato CD label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar"
SETI@home SETI@home.exe N SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data
seticlient SETI@home.exe N SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data
SetIcon SetIcon.exe N Installed by a 6-in-1 (4 Media Card slots, a floppy drive and a USB connection) device. Constantly updates the icons for the four Media Card slots that it has and is a resource hog
SetiQueue Setiqu~1.exe N Provides work unit buffering for Seti@Home clients - see here for more details
SetiSpy SetiSpy.exe N From the site - 'SETI Spy is a little program I wrote to "spy" on the progress and performance of the SETI@home client. I call it a "spy" because I tried to make it as unobtrusive as possible'
SetRefresh SetRefresh.exe ? Found on a Compaq PC. Video refresh rate utility? Is it required?
Setting sysweb.exe X Added by the SDBOT.GEN TROJAN!
Setup experation svchost.exe X Added by the TOFGER-AW TROJAN! Note - this is not the legitimate svchost.exe process, which NOT appear in Msconfig/Startup!
setuzp setuzp.exe ? ??
SetVrc setvrc.exe X Added by the HUNTOCX WORM!
Sex Teris st01b.exe X Added by the REPAD WORM!
Sexy_sg Sexy_sg.exe X Premium rate adult content dialler
SfWinStartInfo sfWinStartupInfo.exe U

SFIRM32 Online Banking software

Sgecrypt Sgecrypt.exe U SafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks"
sginst sginst.exe N eAcceleration Stop-Sign related - not recommended, see note
SGTBox SGTBox.exe ? Canon scanner driver. Is it required?
sgtray sgtray.exe U StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups
shambl3r* shambl3r.exe X Added by the REMABL WORM! where * is 2 to 11
Shareaza Shareaza.exe N Shareaza P2P client
sharedprem sharedprem.exe X Added by the MAKECALL TROJAN!
SheduIer svchst.exe X Premium rate adult content dialler
Shell Shell32.exe X Added by the BADSECTOR TROJAN!
Shell Extension spollsv.exe X Added by a variant of the LOVGATE WORM!
ShellApi SHELLMSN.EXE X Added by the NETDEV.B TROJAN!
Shellapi32 Shellapi32.exe X Added by the NETDEVIL (or NERTE) TROJAN!
ShellEx ShellEx.exe X Added by the ANAKHA TROJAN!
shellsystem shellsystem.exe X Added by the UPCHAN TROJAN!
shicoxp shicoxp.exe N Installed with the drivers for multi card readers of various brands. To differentiate between the various card slots on multi slot readers the shicoxp.exe file assigns and loads unique drive icons for the various card slots that are displayed in Windows Explorer
Shine Shine.exe X Added by the HAPPYLOW (or NISHE-A) VIRUS!
SHINITV shinitv.exe ? ??
ShockmachineReminder SmReminder.exe N Shockmachine is an entertainment playback device that lets you save your favorite Shockwave.com titles and play them back in full-screen mode, off-line, anytime. Could be a registration reminder for the trial version
Shockwave Init SWINIT.EXE N Part of Macromedia Shockwave. Controls the Shockwave Remote Control Panel. The Remote Control can be activated manually from the Start Menu by locating and selecting Shockwave and then Shockwave Remote under Programs
ShortKeys 99 SHORTKEY.EXE N ShortKeys from Insight Software Solutions - allows you to program keys with text strings
Showbehind SHOWBEHIND.EXE X Advertisement display which can be stopped here
ShowIcon_SmartDisk Corporation_USB Card Reader v1.14e051 shwicon.exe ? Card reader for memory cards from digital cameras. Is it required?
SHPC32 SHPC32.exe U Port monitor for Lexmark printers on a USB connection. Ties in with the Printer Control Program. Features like cancelling a print are unavailable if disabled
ShStatEXE SHSTAT.EXE Y From McAfee VirusScan NT 4.x. Handles program communication among VShield components, displays VShield icon. Can be started automatically or available via Start -> Programs
Shutdownaware shutdownaware.exe U Loaded by the SWEEX 6-in-1 Media Card Reader to properly manage the reader while it is connected to your system
ShutDownPro ShutDownPro.exe U ShutDownPro - shutdown, reboot, logoff your System with one mouse click
Si Meter SIMETER.EXE ? ??
Sicom Sicom.exe X Added by the NETLIP WORM!
SideACT SideACT.exe U SideACT organizer software
Sidebar Sidebar.exe X Searchcentrix hijacker
SideWinderTrayV4 SWTrayV4.exe N MS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs
SigX sigx.exe ? ??
SigXC SigX.exe X SigX is a "dynamic signature image generated based on whatever data your computer sends it though our SigX program. It can display your current Mp3, current OS, Free Ram, your current time and more"
Simcast SimcastAlerts.exe N Simcast is a free service that allows you to subscribe to information on a large variety of topics. Alerts will appear on your desktop when a channel that you have subscribed to has something to say
SimpLite-MSN SimpLite-MSN.exe U Required if you use the SimpLite add-on to MSN Messenger (SimpLite adds encryption to the instant messaging service)
Singapore singapore.exe X Adds a blue crescent to the taskbar and when double-clicked displays an adult-content web-site. Also known to drop your internet connection and dial an international telephone number. See here for more information. Must be disabled in MSCONFIG before un-installing or it re-instates itself
SIPPS SIPPS\SIPPS.exe U Web.de Internet phone utility
SiS Tray sistray.exe U System Tray icon for SiS based graphics. Note - this resides in C:\Windows\System
SISAM10M SISAM10M.exe ? ??
siService.exe siService.exe U Spam Inspector - anti email spam software
SiSSetCDfmt SiSSetCDfmt.exe ? Related to a Silicon Integrated Systems Corp (SiS) product?
SISSoundman Soundman.exe ? Related to a Silicon Integrated Systems Corp (SiS) product?
SiSSWLED sisswled.exe U System Tray utility for SiS 900 network cards
sistrai.exe sistrai.exe X Added by the PROVA TROJAN!
sistray sistray.exe X Added by the PROVA TROJAN!
sistray sistray.exe U System Tray icon for SiS based graphics. Note - this resides in C:\Windows\System
sistry sistry.exe X Added by the CEBE WORM!
SiSUSBRG SiSUSBrg.exe N SiS USB Registry Patch File - fixes the undetectable problem with SiS USB controller on Windows XP
SK9910DM SK9910DM.EXE U Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
SKDAEMON SKDAEMON.EXE U Multi-function keyboard driver. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keys.
skinkers skinkers.exe U Selection of desktop messaging/marketing tools with celebrity tie-ins including MTV's "Desktop Ozzy" and Arsenal's "Desktop Wenger" - see here. Leave enabled if you want to receive messages
SkyBlaster Scheduler SSFSch.exe Y For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
skynetave.exe skynetave.exe X Added by the SASSER.D WORM!
Skype Skype.exe N "Skype is free and simple software that will enable you to make free calls anywhere in the world in minutes"
SkySurfer Management Service SmaServ.exe Y For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
SleepManager SleepMgr.exe N This program locates free contiguous disk spaces and allocates them for storing BASE MEMORY, EXTENDED MEMORY, VIDEO MEMORY, and SM RAM. It helps the computer come out of hibernate mode
SlickRun sr.exe U "SlickRun is a floating command line utility for Windows. It gives you almost instant access to any program or website. SlickRun allows you to create command aliases (known as MagicWords), so C:\Program Files\Outlook Express\msimn.exe becomes MAIL"
slimp3 SliMP3 Server.exe N Slimp3 Server - "presents an entirely new way of accessing and enjoying your music collection. Instead of storing your music on CDs or memory cards, the SliMP3 uses your home network to access the music stored on your PC"
Slingshot SLINGS~1.EXE N Atomica Slingshot - "reference tool with access to dictionary and encyclopedia terms, bios, technical terms, history, geography, and much more"
slmss slmss.exe X SeekSeek search hijacker related - as seen here
slvchost32 slvchost32.exe X Added by an unidentified VIRUS, WORM or TROJAN!
SM1BG SM1BG.EXE ? USB driver for downloading from within Napster to portable MP3 players. Is it required to run at startup or can it be run manually?
Sm56acl sm56hlpr.exe N Helper utility for Motorola based SM56 software modems - resides in the System Tray
Smapp smtray.exe N System Tray access for the Compaq/ADI SoundMAX integrated digital audio controller
Smart Card Service ScardSvr.exe N For Smart Card readers. Known to cause problems, especially for Windows 2000 users - see here. Probably not required unless you use such a device regularly
Smart Connect Monitor SCMon.exe U Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio
Smart Connect Setup SCSetup.exe U Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio
Smart Label O Server ssloserv.exe N Part of the printer software for the smart-label printer made by Seiko. Can be disabled safely
Smart Label RFViewer SSLFVIEW.EXE N Part of the printer software for the smart-label printer made by Seiko. Can be disabled safely
Smart Type Assistant sta.exe N Smart Type Assistant - a complex typing automation tool, intended to make your work faster and safer
SmartBarXP SmartBarXP.exe N SmartBarXP is a bar that runs down the side of your screen, and can be configured to display interactive panels known as 'panes'. These panes include media players, slideshow and image viewing panes, a virtual desktop manager, and live news, weather and stock feeds to mention but a few
sMaRTcaPs SMARTC~1.EXE N sMaRTcaPs from Phoebus LLC - enables you to configure the time needed to depress Caps Lock, Num Lock & Insert keys
SMax4 SMax4.exe N System Tray icon for SoundMax integrated sound. Sound properties can be accessed through the Start Menu or Control Panel
SMax4PNP SMax4PNP.exe U SoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments
smbdpmi smbdpmi.exe ? IBM Netfinity Director and Universal Management Services related. What does it do and is it required?
smc smc.exe Y Sygate Firewall
smc spfsmc.exe Y Sygate Firewall
SMC Service smc.exe Y Sygate Firewall
SMC Service spfsmc.exe Y Sygate Firewall
SmcServices smc.exe Y Sygate Firewall
SmcServices spfsmc.exe Y Sygate Firewall
Smcsta.exe Smcsta.exe ? SMC Networks wireless PCI card driver. Is it required?
Smith Micro try smiptray.exe N Smith Micro shared files. Comes with D-Link web cam
SMS Win9x Message Agent SMSMsg.exe U This program assigns a user to a Systems Management Server site
Smserial sm56hlpr.exe Y Motorola based modem driver
SMSI Loader SMLoader.exe N Smith Micro HotFax - fax software
SMSS smss.exe X Added by the FLOOD.F Trojan. This infection should not be confused with the legitimate C:\Windows\System32\smss.exe.
SMSSS smsss.exe X Added by the SDBOT.ZD WORM!
SMSSS Loader smsss.exe X Added by the AGOBOT.MQ WORM!
SMToolbar SMToolbar.exe N StartMake.com toolbar
SmWizard SmWizard.exe ? SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required?
snbr snbr.exe ? ??
sncntr sncntr.exe X Adult content dialler
Sndcompat Sndcompat.exe X Added by the GEMA TROJAN!
SNDMon SNDMon.exe U Part of Symantec's LiveUpate (eg, Norton). Not required if you run manual upadtes but probably require if you leave them to run automatically. Also, if one runs a small office network and SNDMon is disabled on one of the computers – then other computers disappear from the network for this computer, including shared devices like printers and scanners. Hence the "U" recommendation
Sndsaver Sndsaver.exe X Added by the GEMA TROJAN!
Symantec Network Drivers Service SNDSRVC.EXE U Part of Norton Personal Firewall and Norton Internet Security. Sndsrvc.exe is the module controlling the send scan for outbound email if the optioin is selected to integrate into the mail client. It is not necessary if you do not scan outbound email
Snsicon Snsicon.exe N Launches a screensaver program from Second Nature
SO5 Integrator Pass One sointgr.exe ? StarOffice 5. See here for more details
SO5 Integrator Pass Two sointgr.exe ? StarOffice 5. See here for more details
Sock32 sock32.exe X Added by the SDBOT TROJAN!
SoDA Startup SodaStartup.exe Y Used by the Rational SoDA project management tool. Unsure of it's actual purpose but it's recommended you leave it enabled if you use the software
soffice SOFFICE.EXE N Displays StarOffice quick start applet in System tray. Right clicking on the icon allows rapid starting up of components of the StarOffice 6.0 suite. Available via Start -> Programs. Automatically started when any StarOffice 6.0 component is started from the Start -> Programs. A resource hog (it eats > 16 MB of memory).
Software software.exe X Added by the CRABTON-B TROJAN!
Solo Sentry Solosent.exe Y Solo Antivirus
SoloSchedule Solocfg.exe U Scheduler for Solo Antivirus. Leave enabled unless you scan manually on a regular basis
SoloSysCheck Syscheck.exe U Solo antivirus System Integrity Check - Monitors system registry, system.ini, win.ini and startup to protect you from new Internet Worms and Backdoors
somatic somatic.exe X Searchcentrix hijacker
SoniqueQuickStart sqstart.exe N Quickstart for Sonique audio player. Available via Start -> Programs
SonnReg SonnReg.exe ? Part of E-Color 3Deep for color calibration. Possibly a registration reminder?
sophagnt sophagnt.exe ? Possibly related to Sophocles Screenwriting Software?
SOS SOS.exe X Added by the PHILIS VIRUS!
SoSyncMonitor SoSyncMonitor.exe ? SuperOffice related. What does it do and is it required?
Sound Loader sndloader.exe X Added by the AGOBOT-BV WORM!
Sound services SOUND32.EXE X Added by the AGOBOT.GG WORM!
soundcontrl soundcontrl.exe X Added by the GAOBOT.AFJ WORM!
sounddrv sndbdrv3104.exe X CoolWebSearch parasite variant
soundman soundman.exe N System Tray icon for the Realtek AC97 Audio Sound Manager for AC97 onboard audio. Available via Start -> Settings-> Control Panel
SoundMAX SMax4.exe N System Tray icon for SoundMax integrated sound. Sound properties can be accessed through the Start Menu or Control Panel
SoundMAXPnP SMax4PNP.exe U SoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments
SoundMixer smvss.exe X Added by the DEDLER-G TROJAN!
Soundmx Soundmx.exe X CoolWebSearch parasite variant
soundtask soundtask.exe X Added by the AGOBOT-MD WORM!
soundtasks soundtasks.exe X Added by a variant of the CRYPTER.C TROJAN!
soundtctrls soundtctrls.exe X Added by the AGOBOT-ZV WORM!
sounofts sounofts.exe X Added by the AGOBOT-ND WORM!
sp sp.reg X IE search hijacker - changes the default search to http://www.gocybersearch.com/
SP TimeSync SP TimeSync.exe U SP TimeSync lets you synchronize your computer's clock with any Internet atomic clock (time server)
SP00LSV Sp00lsv.exe X Added by the GRAYBIRD.E TROJAN!
sp2ctr sp2ctr.exe X Added by the DLUCA-M TROJAN!
Spam Sleuth SpamSleuth.exe U Spam Sleuth E-mail spam detection program
spamihilator spamihilator.exe U Spamihilator - spam filter
SpamPal spampal.exe U SpamPal - anti-spam tool
SpamSubtract SpamSubtract.exe U Intermute SpamSubtract - junk email detection and removal program
Spdstart Spdstart.exe N Norton Utilities Speed Start. "This feature optimizes the start up speed of launching applications, such as Word and Excel."
Speaking Clock Deluxe SpClDlx.exe U Speaking Clock Deluxe - turns your computer into a speaking clock with several languages. It can also keep track of up to 50 alarms that can be set to a time and a date, and be repeated daily, weekly, monthly and yearly
SpecialOffers SpecialOffers*.exe [* = digit] X Specialoffersnetworks.com adware. "Special Offers is a state of the art advertising product that delivers to you contextually relevant web offers including discounts and coupons"
SpecialOffers SpecialOffers.exe X Specialoffersnetworks.com adware. "Special Offers is a state of the art advertising product that delivers to you contextually relevant web offers including discounts and coupons"
Speed Tec speedtec.exe U Accel SpeedTec from Montana Software speeds up your modem. SpeedTec modifies the Internet Protocol settings in the Windows registry to speed downloads on all modems. If you find this improves your connectivity and download speeds leave this enabled
Speedkey SPEEDKEY.EXE U Additional keyboard shortcuts on MS programmable keyboard
SpeedMeter SpeedMeter.exe U Application measuring upload and download speed
SpeedOptimizer spo.exe U SpeedOptimizer is designed to optimize and speed-up your Internet data transmission including browsing, streaming, downloading, uploading and e-mail communication
Spees1 speedy.scr X Added by the OPASERV.Y WORM!
Spees2 Speedy.bat X Added by the OPASERV.AD WORM!
Spees3 SPEEDY.PIF X Added by the OPASERV.AD WORM!
Spellex Anywhere sa.exe N Spellex-Anywhere - adds spell checking functionality to almost any Window program. Create a shortcut and run manually before it's to be used
SpIDerMail spiderml.exe Y DrWeb antivirus Spider Mail e-mail scanner
Spinner Plus spinner.exe N "Spinner Plus lets you listen to over 100 channels of music broadcast from Spinner.com. Spinner Plus uses RealNetwork's G2 technology to provide high-quality online audio. The technology adjusts the audio streaming to match your Internet connection speed, which helps eliminate sound distortion or choppiness". Available via Start -> Programs
SPnt SPnt.exe X Premium rate adult content dialler
SpokeSysTray SpokeSysTray.exe U Spoke Software client application. Spoke "uses data in your e-mail and other enterprise information systems to discover the existing relationships of people in your enterprise. It then builds a private, secure relationship network for each user without any additional manual data entry"
spoo1sv spoo1sv.exe X Added by the SOULJET TROJAN!
SPOOL Configuration spoolsvc.exe X Added by the SDBOT-KD WORM!
Spool lptt01 spool.exe X Variant of the RapidBlaster parasite (in a "spool" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Spool ml097e spool.exe X Variant of the RapidBlaster parasite (in a "spool" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Spooler Service Spoolsrv.exe X Added by the JOINER.C1 TROJAN!
Spooler Sub System Process SPOOL32.EXE X Added by the YAB.A TROJAN!
Spooler Subsytem App spoolsvc.exe X Added by the SDBOT-MM WORM!
SpoolerSubSystemProcess SpooI32.exe X Added by the EHKS.21 keylogger! Note - the "I" between "o" and "3" is a captial "i" not a lower case "L"
spoolserv spoolserv.exe X Added by the SDBOT-PN WORM!
SpoolService spolsv.exe X Added by the AGOBOT-CS WORM!
Spoolsv Spoolsv.exe X Added by the CIADOOR.121 VIRUS! Note - "Spoolsv.exe" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file
spoolsv scvhosts.exe X Added by the SMALL-AW TROJAN!
spoolsvv spoolsvv.exe X Searchcentrix hijacker
Spore.b Scmhlpr.vbs X Added by the SPORE.B WORM!
sppbridge sppbridge.exe ? Associated with an Anycom bluetooth wireless card on laptops - used for printing to portable printers for example. Is it required or can it be started manually? 
SprintPort SprintPortA.exe ? Novatel wireless modem related. What does it do and is it required?
SPSTEALT SmartProtectorPro.exe U Smart Protector Pro - internet privacy tool that erases tracks, MRU lists, etc
spstore storesp.exe ? Softprobe - program designed to provide managers with an analysis of an individuals computer use who are under their supervision. This program is NOT related to Winpup
Spy Blocker spyblocker.exe U SpyBlocker blocks the communications of spyware installed on a PC so spyware runs but can't exchange data with the server to which it should report. Ensuring spyware can't communicate is important, as you may find after using Ad-Aware that some applications containing spyware subsystems may not run correctly or at all
SpyBlast SpyBlast.exe X Spyware killer that is in effect autoinstalled foistware, targeted by SpyBot, among others
SpyBlocs SpyBlocs.exe X Rogue anti-spyware program
SpyBotSnD Spybotsd.exe U Spybot - Search & Destroy - free multi-spyware removal tool from Patrick Kolla
Spybott lptt01 spybott.exe X Variant of the RapidBlaster parasite (in a "Spybott" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Spybott ml097e spybott.exe X Variant of the RapidBlaster parasite (in a "Spybott" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
SpyHunter SpyHunter.exe N SpyHunter - spyware remover of somewhat dubious repute, see note
Spykiller Spykiller.exe U Shareware "Spyware remover" of questionable quality and repute. There are better alternatives that are freeware to boot
SpyNuker Spynuker.exe X A "spyware removal program" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers ‘TrekData’ and ‘Blue Haven Media’, who distribute spyware through ActiveX drive-by-download on web pages
SpySpotter SpySpotter.exe X Spyware remover of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites. SpySpotter is a security risk that may give exaggerated reports of threats on the computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported threats.
SpyStopper spystopper.exe U SpyStopper - blocks intrusive spyware, Web bugs, worms, scripts, advertisements, and cookies. Protects you from being profiled and tracked
SpySubtract SpySub.exe U SpySubtract - multi spyware removal tool
SpySweeper SpySweeper.exe U Spy Sweeper anti-spyware program.
Spyware Spyware.exe X

BPS Spyware Remover - reportedly uses an old, "borrowed" SpyBot database. Read this and this. Do not support these guys!

Spyware Begone SpywareBeGone.exe N Spyware BeGone - free spyware removal utility. Not recommended - see note
Spyware Doctor spydoctor.exe U Spyware Doctor spyware remover
Spyware Doctor swdoctor.exe U Spyware Doctor spyware remover
Spyware Guard Control Panel spywar~1.exe U

"SpywareGuard provides a real-time protection solution against spyware"

Spyware Nuker Installer SpywareNukerInstaller.exe X

A "spyware removal program" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers ‘TrekData’ and ‘Blue Haven Media’, who distribute spyware through ActiveX drive-by-download on web pages

Spyware Slayer SpywareSlayer.Exe X Spyware remover of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites
Spyware Stormer SpywareStormer.Exe N SpywareStormer spyware remover. Not recommended - see here
SpywareGuard sgmain.exe U

"SpywareGuard provides a real-time protection solution against spyware"

Spywareguard lptt01 Spywareguard.exe X Variant of the RapidBlaster parasite (in a "Spyguard" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Spywareguard ml097e Spywareguard.exe X Variant of the RapidBlaster parasite (in a "Spyguard" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
SpywareKilla SpywareKilla.exe N Spyware remover of ill repute. For more info about it do a search for 'SpyareKilla' at this web page on "Rogue/Suspect Anti-Spyware Products & Web Sites"
SPYWATCH SpyWatch.exe U

BPS Spyware Remover - reportedly uses an old, "borrowed" SpyBot database. Read this and this. Do not support these guys!

SQInstaller SQInstaller.exe X Xupiter hijacker
SQL Server scm.exe N SQL Server Service Control Manager. Available via Start -> Programs
sqvynikp sqvynikp.exe X Free_Scratch_Cards foistware
SrchfstUpdate srchupdt.exe X SearchFast adware downloader
SRFirstRun srclient.dll U Created by execution of the Windows XP sr.inf file, which installs the Windows XP System Restore feature, needed for example when installing System Restore into Windows Server 2003. This file should only be found on initial installs/re-installs. It is required for Windows to function on first boot.
Srmclean srmclean.exe U Srmclean helps in the installation and execution of the SoundMax SoftPaq for Compaq/ADI SoundMax Integrated Digital Audio. According to Compaq - "If you disable the entry from loading into startup, then you will not be able to use the features of the sound card"
SRNG srng.exe X Added by the Spyware.2020search search hijacker.
SRP Startup srrpro.exe U System Restore Remover Pro allows you to safely and easily remove System Restore and various other Windows Millennium "features." This is enabled if you tick the "Remove unnecessary System Restore information on startup" box. Available via Start -> Settings -> Control Panel
SRS Applet SrsTray.Exe Y S3 Sonic Vibes sound card drivers - if disabled you loose sound
Srv32 Srv32.exe X Added by the OPASERV.J WORM!
Srv32 Srv32.exe X Added by the OPASERV.S WORM!
Srv32 spool service spoolsrv32.exe X Topantispyware.com malware, recognized by Kaspersky antivirus as Trojan-Clicker.Win32.Spyre.b
Srv32Win SpyAgent4.exe U SpyAgent - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it
Srv32Win Svchost.exe U Realtime-Spy keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove
Srv32Win sysdiag.exe X NetVizor keystroke logger
srvexc.exe srvexc.exe X Added by the SERVSAX TROJAN!
SSBkgdUpdate SSBkgdupdate.exe N ScanSoft OmniPage auto updater. Can be disabled using the main program's options. This program is also installed with other Nuance products.
Ssd Std.exe Y Stealthdisk - file and folder hiding/locking utility
ssdiag ssdiag.exe U It's a shared driver components used by Sonic DLA. If DLA is enabled you can use it to burn information to a CD as if it was a floppy drive or other removable drive. Can be disabled if you do not use this feature.
SSDPSRV ssdpsrv.exe U Simple Service Discovery Protocol (SSDP) and General Event Notification Architecture (GENA) services for network plug and play functionality. Starts up a web server on port 5000. Used by Universal Plug and Play (for network device discovery). To remove this program, open Add/Remove Programs, select either Communications (Me) or Networking Services (XP), and remove the checkmark next to Universal Plug and Play
ssgrate.exe system.exe X Added by the MITGLIEDER.C TROJAN!
ssgrate.exe sysdoor.exe X Added by the MITGLIEDER.N TROJAN!
SSL svchost.exe X Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
ssmmgr ssmmgr.exe U Samsung printer monitor - for checking ink levels, etc.
SStb.exe SStb.exe X Adpowerzone.com "ServerSide" keyword hijacker
sstray sstray.exe N nVidia nForce Taskbar Utility - quick access to the nForce2 "Sound Storm" control panel and related utilitys
SSUpdate SSUpdate.exe X DyFuCa/MoneyTree parasite variant
ssvchost ssvchost.exe X Added by the HELIOS.B TROJAN!
Stacmon Stacmon.exe N Installed with the drivers for a SigmaTel C-Major Audio card (on a Dell Inspiron 600m PC for example). Appears as though it can be disabled with no ill effects
start start.exe ? ??
Start Up Cop startcop.exe U StartUp Cop - startup manager
start uploading smsss.exe X Added by a variant of the SDBOT WORM!
Start Upping SVCHOSTES.EXE X Added by the RBOT-NB WORM!
Start Uppings svcchosts.exe X Added by the SDBOT.VY WORM!
Startacc startacc.exe U Launches Webroot's Accelerate 2000 software that "speeds up your Internet connection by up to 300%". Leave enabled if you find it improves internet connection
StartEAK StartEAK.exe Y Easy Access Button Support for Compaq PCs. Required if you use these
starter scvhosting.exe X Added by the IRCBOT.E TROJAN!
Starter scvhosting.exe X Added by the SDBOT.RU WORM!
startl.exe startl.exe N Lingocom LingoWare - translates any application into your language
StartMenu s_menu.exe X Added by a variant of the DELF-A TROJAN!
startpage startpage.exe X Browser hijacker - redirecting to pages2start.com
STARTPAGE start1.exe U NoSpy.org - prevents spyware from changing your startpage and other browser properties. The start1.exe file is located in a NOSPY.ORG folder
StartStop STARTSTOP.EXE U StartStop from TFI Technology - startup manager
StartSurfing STARTS.exe U Start Surfing allows you to protect your privacy while surfing and searching the Internet by acting as a "filter" between you and the website you are visiting. Startsurfing acts as your shield from Pop Up Windows, Mouse Traps, Window Resizing, and scripts that attempt to record your personal information. Available via Start -> Programs
StartupMonitor StartupMonitor.exe U Mike Lin's StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu
Stat 'n' Perf StatnPerf.exe N Stat 'n' Perf monitors your internet connection and displays information about sent and received bytes
StatBar STATBAR.exe U StatBar (system status bar) allows you to quickly get an overview of your system
StatusClient 2.6 StatusClient.exe ? Part of Hewlett Packard network printer drivers.
Stay Connected! StayCon.exe N More than just a pinger, actually simulates online activity. Supports AOL, NetZero, MSN, ATT WorldNet, CompuServe and many other ISPs as well. Available via Start -> Programs
StayAlive sa.exe U StayAlive from TFI Technology. "This top-notch tool intercepts crashes when they happen, keeping your programs running so you can save your work."
STBVision STBVisn.exe ? Related to the STB Velocity graphics card. What does it do and is it required?
STBWEBTV STBWEBTV.EXE N Used to display TV on your PC
stcloader stcloader.exe X Popup adware by 2ndThought software
stcloader STCLOA~1.exe X Popup adware by 2ndThought software
STCLOA~1 stcloader.exe X Popup adware by 2ndThought software
STCLOA~1 STCLOA~1.exe X Popup adware by 2ndThought software
STCPO STCPO.exe Y Sophos Sweep antivirus software
Stealth Anonymizer 2.5 stealth25.exe U Now named Stealther - proxy server agent that lets you travel the Internet with maximum possible privacy
Steam steam.exe N Valve Software's STEAM broadband game client. Steam is Valve's new way of getting games into your hands ASAP. Games like Half-Life, Counter-Strike, and Counter-Strike: Condition Zero are all being made available through Steam. Steam games are automatically kept up-to-date with the latest content and revisions. Steam also includes an instant-message client which even works while you're in-game
Stickies STICKIES.EXE N Stickies - utility that allows you to put yellow "Post-It" type messages on your desktop and can be used to set reminders. Available via Start -> Programs
Sticky Notes stikynot.exe N Microsoft Sticky Notes - virtual sticky notes tool
StickyNote StickyNote.exe N Utility that allows you to put yellow "Post-It" type messages on your desktop. Available via Start -> Programs
StillImageMonitor Stimon.exe U Stimon.exe enables a USB still-image device (such as a scanner) to initiate data transfer to a program. For example, if your scanning device has a scan button, it may start a program and begin scanning when you press it. Create a shortcut and start it manually when needed if your scanner otherwise fails to scan. May be required for your USB scanner to work - including all HP scanners and some of their SCSI scanners
StopSignStatus stopsinfo.dll N eAcceleration Stop-Sign related - not recommended, see note
STOPzilla Stopzilla.exe U StopZilla! - pop-up killer
STOPzilla Service SZNTSVC.EXE U StopZilla! - pop-up killer
StorageGuard sgtray.exe U StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups
STPMGR STPMGR.EXE ? Part of SafeTP which is transparent FTP security software. Does it need to be running permanently or can it be started manually via Start -> Programs
Strng32 strngbox.exe X Added by the STRANO WORM!
StubPath Sservice.exe X Added by the PRORAT TROJAN!
StyleXP StyleXP.exe U StyleXP allows you customize the way WinXP looks. If disabled via msconfig it re-instates itself at reboot, therefore uninstall it if you don't want it
Suitcase Startup Suitcase.exe U Suitcase. System font manager start up utility. Used for dynamic managment of fonts on your system
SULFNBJ.EXE SULFNBJ.EXE X Added by the PE_MAGISTR.DAM VIRUS!
SunJavaUpdate smvss.exe X Added by the DEDLER-G TROJAN!
Sunkist shwicon98.exe U Card reader for memory cards from digital cameras, etc
Sunkist2k shwicon2k.exe U Card reader for memory cards from digital cameras, etc
SupaDial SupaDial.exe ? SupaNet.com modem driver related - is it required?
Supastatus status.exe N Supanet ISP software
SuperAdBlocker SAdBlock.exe U SuperAdBlocker
Supercleaner Supercleaner.exe U Supercleaner - all in one disk cleaner for your computer
SuperSpamKiller Pro Ssk.exe U SuperSpamKiller Pro email spam blocker
Supervisor.exe Supervisor.exe ? Has been reported to be associated with various antitrojan software like ATS and PC Doorguard. If so it's required in Startup - any further information is welcome
supporter5 supporter5.exe X Part of eScorcher anti-virus software- responsible for updates of new virus bases each time you logon to the web. Used to collect information about the user and therefore treated as spyware - now the web-site is dead
SureCleanProfessional SRClean.exe U SureClean PC and Internet tracks cleaner
Sureshotpopupkiller Stopthepop.exe U Stop-the-Pop-Up popup blocker
SurfChoice SCMan.exe U SCMan is a utility that can control services on WinNT from the command line. This utility can create, start, pause, stop, delete services. Furthermore it can retrieve a service's current state, get the displayname for a service and vice versa
Surfer lptt01 surfer.exe X Variant of the RapidBlaster parasite (in a "mssurfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Surfer ml097e surfer.exe X Variant of the RapidBlaster parasite (in a "mssurfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
SurfSecret ss2-full.exe U "House-cleaning utility that enables you to keep your computer usage to yourself. Runs quietly from the system tray, eliminating tell-tale files at a regular interval of your choosing. You can set it to clear your Internet cache files, cookies, history, temp folder, etc. It can also clear the history of your Run and Find menus, in addition to the AOL cache"
SurfSideKick 2 Ssk.exe X Added by the Adware.SurfSideKick adware.
SurfStream SurfStream.exe U Conceiva "SurfStream lets you surf the Web faster. It contains a fully featured proxy server that lets you surf the Web significantly faster. It also blocks all pop-up windows and banner ads from Web pages. An intelligent tune-up tool automatically analyzes and optimizes your computer's Internet connection and TCP/IP settings"
Surveysa surveysa.exe N Utility installed on Sony laptops that prompt you to take surveys. It will disappear after you will out a survey or specify to never prompt you again.
Susp Susp.exe X Transponder parasite updater/installer
SVA Player SVAplayer.exe X QuickFlicks Streaming Player - regarded as spyware. See here for details of how to disable or uninstall it
Svc svc.exe X Hijacker, Clientman parasite variant, redirecting to madfinder.com. Detected by Symantec as the MADFIND TROJAN!
SVC Service svcinit.exe X Added by the SINIT TROJAN!
SVC Service svcinit.exe X CoolWebSearch parasite variant
SVC Service svcpack.exe X CoolWebSearch parasite variant
Svced Svced.exe X Added by the DELF.F TROJAN!
svchost Svch0st.exe X Added by the GRAYBIRD.B TROJAN!
SVCHOST svchost.exe X System1060 homepage hi-jacker. Found in a Windows\System\1060 directory. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
svchost svchost.exe X Added by the MORB WORM or TARNO TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
svchost Svch0st.exe X Added by the GRAYBIRD TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Svchost svchost.exe X Added by the MOXE-A WORM! This is not the valid svchost.exe as described here
Svchost svchosl.pif X Added by the INZAE.A or INZAE.B WORMS!
svchost.exe svchost32.exe X CoolWebSearch parasite related. Note - this is not the valid svchost.exe as described here
svchost1 svchost1.exe X Added by the AGOBOT.ZZ WORM!
SvcHost32 svchost32.exe X Added by the MIMAIL.I or MIMAIL.J WORMS!
svchost64 svchost64.exe X Added by the SDBOTER.G VIRUS!
svchostr svchostr.exe X Added by an unidentified WORM or TROJAN!
svcinfo svcinfo.exe X Added by the CRYPTER.A TROJAN!
svcroot svcroot.exe X Added by the KEYLOG-AC TROJAN!
svcsys32 svcsys32.exe X Added by the AGOBOT-LL WORM!
Svhost Svhost.exe X Added by the W32/VB-ASG worm.
Svhost Loader svshost.exe X Added by the AGOBOT.G WORM!
SVIDC32M SVIDC32M.exe ? ??
SVM Pop svmpop.exe ? ??
svphost.exe svphost.exe X Added by the AGENT.CS TROJAN!
svrrun svrrun.exe X Adware hailing from Deskwizz.com
svshost svshost.exe X Added by the W32/Chode-H instant messenger worm.
svshostdriver svshost.exe X Added by the SDBOT-HN TROJAN!
SVX Control Service svxhost.exe X Added by the FORBOT-K WORM!
SWCaller SWcaller.exe X Homepage hijacker - see here
SWCaller Swcaller2.exe X Homepage hijacker - see here
SwimSuitNetwork SwimSuitNetwork.exe X Advertising spyware
Switch Off swoff.exe U Switch Off - tray-based system utility that can automatically perform various frequently used operations like shutdown or restart your computer, disconnect your current dialup connection, lock workstation, etc
SwTray SWTRAY.EXE N MS SideWinder game controller system tray icon. Available via Start -> Programs. May have the version number after it
SWTrayV4 SWTrayV4.exe N MS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs
SXGDSENU sxgdsenu.exe ? Yamaha SXG soundcard driver
SxgTkBar sxgtkbar.exe ? Yamaha SXG soundcard driver
Sxplog sxpstub.exe ? Part of CA Unicenter Software Delivery - manage software across various systems, from desktops and servers to PDAs and mobile phones, in a controlled and standardized way - is it required at startup?
Sygate Personal Firewall system32.exe X Added by the RBOT.VI WORM!
Sygate Personal Firewall sysgut.exe X Added by the SDBOT.WM WORM!
Sygate Personal Firewall Sygate.exe X Added by the RBOT-PN WORM!
Sygate Personal Firewall Start services32.exe X Added by the RBOT-MB WORM!
Sygate Personal Firewall Start servic.exe X Added by the RBOT-RY WORM!
SyGateService sgserv95.exe U SyGate is a useful little program that lets you share an internet connection over an intranet. Is it needed - it saves a lot of headache to just let SyGate load at startup. Available via Start -> Programs
Symantec Anti Virus symantec32.exe X Added by a variant of the WOOTBOT WORM!
Symantec Core LC symlcsvc.exe Y Part of Norton AntiVirus 2004. What does it do?
Symantec NetDriver Monitor SNDMon.exe U Part of Symantec's LiveUpate (eg, Norton). Not required if you run manual upadtes but probably require if you leave them to run automatically. Also, if one runs a small office network and SNDMon is disabled on one of the computers – then other computers disappear from the network for this computer, including shared devices like printers and scanners. Hence the "U" recommendation
Symantec Security symantec32.exe X Added by the RANDEX.PR or RANDEX.YR WORMS!
SymAV SymAV.exe X Added by the NETSKY.U WORM!
SymTray - Norton SystemWorks SYMTRAY.EXE N Keeps all System Tray icons for Norton SystemWorks together to reduce clutter. SystemWorks includes Norton Anti-Virus, Norton Utilities and Norton CleanSweep - mentioned elsewhere here. Personally I only have Norton eMail Protect running which doesn't need SymTray
Sync-It Syncit.exe U Sync-It - synchronizes the system clock with time servers on the internet
SyncAgent syncagent.exe U Ghost Keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove
SynSetup SynTP.tmp RunOnce.exe ? Probably associated Synaptics touchpads on laptops as for the SynTPEnh and SynTPLpr entries but what does it do and is it required?
Syntax Script systacq.exe X Added by the SDBOT.AI WORM!
SynTPEnh syntpenh.exe U Synaptics touchpad tray icon. Displays status and provides quick launch to touchpad features such as scrolling and tap zones. Required on IBM Thinkpads with UnltraNav (pointstick and touchpad combo) if you don't want to loose the advanced pointstick features such as scroll
SynTPLpr syntplpr.exe Y Synaptics touchpad driver helper. Required for touchpad features to work
sys sysdllwm.reg X CoolWebSearch parasite variant
Sys Ren SysRen.exe X Part of FlashEnhancer adware
sys32 sys32.exe X Added by the FLUX.E TROJAN!
sys32sql sys32win.exe U Active Keylogger monitoring software - also see here. From the Symantec article: "This spyware program must be manually installed. However, there are several known programs that have Spyware.ActiveKeylog within them and that install it as the program itself is installed". Disable/remove if you didn't install it
SysAgent SysAgent.exe U SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of
SysAI SysAI.exe X AproposMedia adware - also creates SysAI folder in Program Files where the SysAI.exe is also located
Sysbot sysbot.exe U Spector - spying (or monitoring) software to record internet activity
syscfg syscfg32.exe X Added by the KWBOT.S WORM!
syscfg34.exe syscfg34.exe X Added by the ELECTRON WORM!
syscm Syscm.exe X Vanish adware
syscon lptt01 syscon.exe X Variant of the RapidBlaster parasite (in a "Syscon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
syscon ml097e syscon.exe X Variant of the RapidBlaster parasite (in a "Syscon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
SysConfig syscfg35.exe X Added by the KAZMOR.C WORM!
Syscpy Syscpy.exe X Firewall-bypassing, proxied spam relayer. Detected by Symantec as the HOGLE TROJAN!
SysCtl sysctl.exe X Added by the AOK TROJAN!
Sysdpt sysdpt.exe X Win32.Crypt trojan downloader
sysfiler sysfiler.exe X Added by the RETSAM TROJAN!
SYSfit SYSfit.exe X AdShooter adware variant
sysflg32 sysflg32.exe X Added by a variant of the CRYPTER.C TROJAN!
syshelp syshelp.exe X Added by a variant of the LOVGATE WORM!
sysinfo sysinfo.exe X Added by the BEDRILL TROJAN!
sysinfo.exe sysinfo.exe X Added by the BEAGLE.V WORM!
sysinit services.exe X Added by the NEWLFRM-A TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
sysint16 sysint16.exe X Added by the CRYPTER.A TROJAN!
Syskey sysinit.exe X Added by the BEAGLE.AX WORM!
Syslib Syslib.exe X Adult content related downloader trojan
Syslog lptt01 Syslog.exe X Variant of the RapidBlaster parasite (in a "Syslog" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Syslog ml097e Syslog.exe X Variant of the RapidBlaster parasite (in a "Syslog" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
syslogin.exe syslogin.exe X Added by the BAGZ-B WORM!
SysMetrix SysMetrix.exe U SysMetrix - skinnable clock and metering application. It monitors and reports on a great number of statistics
sysmon sysmon.exe X Added by the BIZEX WORM!
sysmon sysmon44.exe X Added by a variant of the BACKDOOR-CBA TROJAN!
SysMonXP SysMonXP.exe X Added by the NETSKY.Q WORM!
sysnate sysnate.exe X Added by the MEDIAS TROJAN!
SysOps SysOps X Added by the MSNCORRUPT TROJAN!
SysProtect System.exe X Added by the NETSPY TROJAN!
SysR sysmd.exe X Adult content based "foistware" (adds hidden components to your system)
SysReg SysReg.exe X Added by the CHEKIN TROJAN!
SysReg SysReg.exe X SearchSeekFind textual marketing foistware
Sysres Sysres.exe X Added by the LOGMOD TROJAN!
sysser syshid.exe X Added by the RAHACK WORM!
SysService SysService.exe X Added by the DELF family of TROJANS!
SysService32 SysService32.exe X Added by the KINDAL VIRUS!
SysService32l systask32l.exe X Added by the THEUG WORM!
SYSsfitb SYSsfitb.exe X Searchforit browser hijacker
SysStrt systemc.exe X Added by the AGOBOT-QA TROJAN!
System system.exe X Added by various WORMS and TROJANS!
system systemsearch.hta X Jetseeker.com hijacker
System 64 Driver for Games sys64dvr.exe X Added by the SDBOT TROJAN!
System Applications Profile sap.exe X Added by the RBOT-QF WORM!
System Cache SysCache.exe X Added by an unidentified VIRUS, WORM or TROJAN!
System Diagnostics sysdiag32.exe X Added by the SDBOT.GEN TROJAN!
System Host Service svchost.exe X Added the the CONE.F WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
System LifeGuard Scheduler Slsched.exe U System LifeGuard scheduler
System Manager svchost.exe X Added by the BANKER-AE TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
system manager System.exe X Added by the FORBOT-BO WORM!
System Monitor SYSMON.EXE U Comes with some Aopen motherboards. Monitors CPU temp, voltage and fan speed. Warns if any become abnormal
System Monitor Sysmon16.exe X Added by the SDBOT TROJAN!
System Restore svcnet.exe X Added by the TIBICK WORM!
system service spoolcrv.cpl X Added by the INSPIR.11 TROJAN!
System Service systems.exe X Added by the AGOBOT.VZ WORM!
System Soap Pro soap.exe X System Soap Pro internet cleaning software. Bundles foistware like HTTPER and Zipclix - best avoided
System Stats SystemStats.exe X Added by a variant of the WOOTBOT WORM!
System Terminal SYSTEM2.EXE X Added by the SPYBOT-BZ TROJAN!
System Toolkit Systools.exe X Added by the RONOPER-G WORM!
System Tray Services spooles32.exe X Added by the AGOBOT.ZH WORM!
System Tray32 SysTray32.exe X Added by the REPAD WORM!
System Update2 services.exe X Added by the AUTOTROJ-C TROJAN!
System Update2 svchost.exe X Added by the AUTOTROJ-C TROJAN!
System Update2 system.exe X Added by the AUTOTROJ-C TROJAN!
System Uptime Server SYSENTRY.EXE X Added by the RBOT.LK WORM!
System Uptime Server SYSENTRY32.EXE X Added by the RBOT.LK WORM!
system. system..exe X Added by the OPTIXPRO.13.C TROJAN!
system... system...exe X Added by the OPTIXPRO.13.C TROJAN!
System.exe System.exe X Added by various WORMS and TROJANS!
System32 system.exe X Added by the BUSHTRO122 TROJAN!
System32 System32.exe X Added by any number of WORMS or TROJANS!
System32 sysdiag.exe X SpyAgent.B spyware
System32 system32,1.exe X Added by an unidentified VIRUS, WORM or TROJAN!
system32.dll systeminit.exe X CoolWebSearch hijacker re-directing to your-search.info
system32.dll sysdll32.exe X CoolWebSearch parasite related. Redirecting to wholeworldmarket.com, most likely other domains as well
system32.exe services32.exe X Added by a variant of the BACKDOOR.IRC.BOT TROJAN!
System32Ex System32Ex.exe X Added by the IRCCONTACT TROJAN!
SystemAgent Sage.exe U "Microsoft Plus! System Agent automatically tunes your system, performing tasks such as disk optimization and error correction. It can also run any application at prescheduled times"
SystemCheck Systemcheck.exe X Added by the LAVITS WORM!
SystemChecker Syschk.exe X Added by the GALIL.F WORM!
SystemCONF98i SystemCONF98i.exe X Added by the GLITCH BOT TROJAN!
SystemDebug Sysdeb32.exe X Added by the SYSBUG TROJAN!
SystemDll SystemDll.exe X Added by the LOXOSCAM TROJAN!
Systemiom Updater Systemiom.exe X Added by the SPYBOT.TY WORM!
SystemLoad32 sysload32.exe X Added by the MIMAIL.E WORM!
SystemManager Sysman32.exe X Added by the DOWNLOADER-BW.B TROJAN!
SystemMonitor Sysmon32.exe X Added by the AIDID.A WORM!
SystemReg svchost.exe X Added by the DEWIN.E TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Systems scchost.exe X Added by the DAEMOZ.A TROJAN!
Systems Restart slchost.exe X Added by the BANCOS.RF TROJAN!
Systems Restart spchost.exe X Added by a variant of the BANCOS.RF TROJAN!
Systems.exe Systems.exe U Keyboard Spectator - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it
SystemSafe Syssafe.exe U System Safety Monitor - system monitoring tool with additional application firewalling
SystemSAS System32.exe X Added by the KWBOT.C WORM!
SystemService shman.exe X Premium rate adult content dialler
SystemTasks sexypicz.exe X Adult content dialler
Systemtra Systra.exe X Added by a variant of the LOVGATE WORM!
SystemTray SysTray.Exe U SYSTRAY.EXE - System Tray Services. Provides the Volume Control, PC Card Status, Power Management and other icons that reside in the System Tray (see here). SYSTRAY.EXE may be disabled if none of these services are required. It will launch as and when required if you later enable the icons. If you need these items they're available via Start -> Settings -> Control Panel
SystemTray SystemTray.exe X Added by the BIGFOOT TROJAN! Note - this is not the valid SystemTray (SysTray.exe)
SystemTray SysTray.exe X Added by the ALADINZ.P TROJAN! Note - this is not the valid System Tray (systray.exe) which resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K) or C:\Windows\System32 (WinXP). If you right-click on the real systray.exe the "Properties" reveal it to be a Microsoft file
SystemUpd SystemUpd.exe N Updater for Swapoo.com, a kind of Napster for games
SystemWizard Sniffer Sniffer.exe U SystemWizard for Win98/ME from SystemSoft - diagnoses and solves hardware and software problems on a PC
systemyom Updater systemyom.exe X Added by a variant of the BACKDOOR.IRC.BOT TROJAN!
SYSTEMZ Patch SYSZ.exe X Added by the ALADINZ.P TROJAN!
Systesms.exe systesms.exe X Added by the RBOT-HI WORM!
Systest Systest.exe N Clean Space temp files cleaner
SysTime systime.exe X CoolWebSearch parasite variant
Systmesy Systmesy.exe X Added by the RBOT-KQ WORM!
Systoan32 systoan.exe X Added by an unidentified VIRUS, WORM or TROJAN!
systr32 systr32.exe ? ??
systrax systrax.exe ? ??
Systray Systray_.Exe X Added by the KERGEZ.A WORM!
SysTray SysTray.Exe U SYSTRAY.EXE - System Tray Services. Provides the Volume Control, PC Card Status, Power Management and other icons that reside in the System Tray (see here). SYSTRAY.EXE may be disabled if none of these services are required. It will launch as and when required if you later enable the icons. If you need these items they're available via Start -> Settings -> Control Panel
SysTray Snnpapi.exe X Added by an unidentified TROJAN!
Systray driver systray.exe X Added by the MUTEBOT TROJAN! Note - this is not the real SystemTray which shares the same filename
systree systree X Added by the BANCOS.L TROJAN!
SYStry spoolsvr.exe X Added by the SDBOT.GN WORM!
sysu sysu.exe X Dynamic Desktop Media adware - see here
SysUpd Sysupd.exe X VirtuMonde adware
Sysvupex Sysvupex.exe X Added by the MEDIAS TROJAN!
SYSWB6 SYSWB6.exe U We-Blocker - gives parents the opportunity to monitor their children's Internet access and provide them with age-appropriate content, while filtering out sites that contain adult content
SysWin SysWin.exe X Added by the IRCCONTACT TROJAN!
syswin32 syswin32.exe X Added by a variant of the SPYBOT WORM!
Syswindow Syswindow.exe X Added by the COW TROJAN!
SYS_CLEAN Service.exe X Added by the FLOPCOPY WORM!
SZMsgSvc.exe SZMsgSvc.exe U StopZilla! - pop-up killer
T-DSL SpeedMgr speedmgr.exe N T-Online ISP SpeedManager - shows upload and download speed. Also checks for updates automatically
Taba stte.exe X Clickspring spyware
Tango Setup.exe ? Tango Broadband access software. Is it required?
Task Monitoring Service svchost.exe X Added by the CONE.D WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
TEXTCONV services.exe X Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
Tiger Shine.exe X Added by the HAPPYLOW (or NISHE-A) VIRUS!
tjstartup svchost.exe X Added by the CURDEAL TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
TSPower spower.drv ? Found on a Toshiba laptop. Related to power management?
TwkSCardSrv SCardS32.Exe N Used with Towitoko SmartCard Readers for card recognition
Ulubione sys****.exe X Search Hijacker, redirecting to maxxxhosters.com - where **** are random characters
Update Sysupd.exe X Added by the SLACKBOT VIRUS!
Update Install Schost.exe X Added by the GAOBOT.AO WORM!
Update local SetCPQLC.exe ? Running on a Compaq desktop. Any ideas?
update service svxhost.exe X Added by the RBOT-MG WORM!
Update ver 1.0 Swap.exe X Added by the SWAP-C WORM!
UpdateManager sgtray.exe U StorageGuard from Veritas (this version by Sonic). Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups
Updater Service Process svhost32.exe X Added by the AGOBOT.TY WORM!
USB controller Svcmm32.exe X Ouchvideo.com 'n-Lite' spyware
USB Device servicelog.exe X Added by the WOOTBOT.CB WORM!
USB Hub Keyboard Patch SKBPATCH.EXE ? USB HUB Update
UsbD smss32.exe X Adware downloader - recognized by Kaspersky antivirus as Trojan-Proxy.Win32.Agent.cj
UsbD svhost32.exe X Added by the AGENT.IB TROJAN!
usbdrv servicetask.exe X Added by a variant of the SDBOT WORM!
ushli sscbltqu.exe X Obtained from an MP3 search list site. Also generates random processes on reboot
usrgtway.exe syswrun4x.exe X Added by the MITGLIEDER.E TROJAN!
Microsoft Driver Setup sysmngsr322.exe X Added by the Troj/Buzus-AS Trojan.
Video Process sysconf.exe X Added by the GAOBOT.GEN!POLY or GAOBOT.UM or GAOBOT.ADX WORMS!
Video Services sys32.exe X Added by the AGOBOT.PS WORM!
vscanner spooll32.exe X Added by the OPTIXPRO.10 TROJAN!
W32.Scran Scran.exe X Added by the NARCS WORM!
Wardo syslaunch.exe X Added by the ADLCICKER.G TROJAN!
WebOutfitterTray sttray.exe N Intel WebOutfitter service System Tray icon
webscan stopsignav.exe N eAcceleration Stop-Sign related - not recommended, see note
WhenUSave Save.exe X Rebranded version of SaveNow advertising spyware
WhenUSearch Search.exe X WhenUSearch adware
win name stat.exe ? ??
win32 Shakira_1997_Part_1_.Mpeg_.scr X Added by the MYLIFE.N WORM!
win32 Setup_32.exe X Added by the EVILBOT.B TROJAN!
Win32 System Spool spoolsvc.exe X Added by the SDBOT.UK WORM!
Win32 Usb Driver svhosint32.exe X Added by the FORBOT-BE or FORBOT-J WORMS!
Win32 USB2 Driver smsc.exe X Added by the SDBOT.FO WORM!
Win32 USB2 Driver svchosting.exe X Added by the FORBOT.J or SDBOT.HU WORM!
Win32 USB2 Driver sys32.exe X Added by the WOOTBOT.X WORM!
Win32 USB2 Driver sys32snd.exe X Added by the FORBOT-AN WORM!
Win32 USB2.0 Driver service.exe X Added by the SDBOT-QF WORM!
Win32G Scandisk.com X Added by the ESTRELLA TROJAN
win32ini systroy.exe X Added by the IRC.ALADINZ.C TROJAN!
Win32R Server.com X Added by the ESTRELLA TROJAN!
win32usbd ssrs.exe X Added by the RBOT-RA WORM!
Win386 sp32.dll X Homepage hijacker. Not a dll but a regfile in disguise
window2 ssvchost.exe X Added by the IRCBOT.H TROJAN!
windows system copy.exe X Added by the SALGA.A WORM!
Windows Accelerators setup.exe U KeySpy keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove
Windows backup systemss.exe X Added by a variant of the SPYBOT WORM!
Windows Baþlangýç Dosyasý sistem.exe X Added by the MUZK WORM!
Windows Config SSYS.EXE X Added by the SPYBOT-DA WORM!
Windows Drive Compatibility System32Driver32.exe X Added by the SUPOVA.Z WORM!
Windows Help Manager svchost32.exe X Added by the RBOT-OZ WORM!
Windows HTML file reader Sysconf32.exe X Added by the NOOMY.A WORM!
Windows Logon Procedure Svchoste.exe X Added by a variant of the SPYBOT WORM!
Windows Nivedia Driver sysMGT.exe X Added by a variant of the RBOT WORM!
Windows Print Spooler SCVHOSTS.EXE ? Suspicious due to the similarity to the valid "svchost.exe" file
Windows Print Spooler SVEHOST.EXE X Added by the SPYBOT.H WORM!
Windows report swchost.exe X Added by the SMALL-BD TROJAN!
Windows secure setver32.exe X Added by the SPYBOT.EP WORM!
Windows Service Host scvhost.exe X Added by the SDBOT.N TROJAN!
Windows Service Host svchost.exe X Added by the CONE.B WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Windows Services service.exe X Added by the RANDEX.R WORM!
Windows Services svchosts.exe X Added by the AGOBOT-KL TROJAN!
Windows Services Host svchost.exe X Added by the CONE or CONE.E WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Windows Services Update svch0st.exe X Added by a variant of the RBOT WORM!
Windows Smart Manager smart.exe X Added by the RBOT-SL WORM!
Windows Sound Driver SndMon32.exe X Added by a variant of the SPYBOT WORM!
Windows Sound Manager SndMon32.exe X Added by the FORBOT-BU WORM!
Windows SP2 Update Sp2update.exe X Added by the WOOTBOT.BS WORM!
Windows Spooler SPOOLSRV.EXE X Added by the SPYBOT.P WORM!
Windows Startup services21.exe X Added by the AGOBOT-MX WORM!
Windows Startup 32 Bits sysrun32.exe X Added by a variant of the DARKSUN TROJAN!
Windows SyncroAd SyncroAd.exe X Windupdates adware variant
Windows System Configuration SYSCFG16.EXE X Added by the WISDOOR.Z TROJAN!
Windows System Restore Configuration Sblhost.exe X Added by a variant of the SPYBOT WORM!
Windows System Restorer SystemRestorer.exe X Added by the DULOAD.C WORM!
Windows System Tray swhost.exe X Added by an unidentified VIRUS, WORM or TROJAN!
windows update sychost.exe X Added by the LEOX.B WORM!
Windows update config svhost.exe X Added by the SDBOT-PF WORM!
windows update configurator svghost.exe X Added by a variant of the SPYBOT WORM!
Windows Update Service smcg.exe X Added by the SDBOT.QY WORM!
Windows Update Service 2004/2005 systemupdate.exe X Added by the RBOT-JE WORM!
Windows-System System32.exe X Added by the LOGPOLE.C WORM!
WindowsAPI.DLL Server5.exe X Added by the "Fear and Hope" TROJAN!
WindowsUpdate svchost.exe X Added by the ASTEF or RESPAN WORMS or AGENT-V TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Windows_Serivce SERVICE.exe X Added by the WOOTBOT.AH WORM!
Windows_Updates svthost.exe X Added by a variant of the SPYBOT WORM!
WinDVR SchSvr SchSvr.exe N WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs
Winlogin.exe steam.exe X Added by a variant of the AGENT.AH TROJAN!
WinLsass servicec.exe X Added by the SCANE WORM!
scanregg scanregg.exe X Added by the Troj/ScKeylog-A keylogger.
WinManager schost.exe ? ??
WinProfile sndcfg16.exe X Added by the SNDC.A WORM!
WinProt server.exe X Added by the CHUPACABRA TROJAN!
WinSecured32 ssmr.exe X Added by a variant of the FORBOT WORM!
winserver Server.txt.vbs X Added by the DELTAD.A WORM!
WinService32 ssmgr.exe U 007 Spy Software - "stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP"
winsock svch0st.exe X Added by the SAGE-A WORM!
Winsock2 driver SDJOIJE.EXE X Added by the SPYBOT.DR TROJAN!
Winsock2 driver SPOLSV.EXE X Added by the SPYBOT-CM WORM!
Winsock32 driver Sdjoije.exe X Added by the SPYBOT.B WORM!
Winsock32driver sp2XPupdate.exe X Added by an unidentified VIRUS, WORM or TROJAN!
Winspool spoolsvr.exe X Added by a variant of the SDBOT WORM!
WinSrv SHIZZLE.EXE X Added by the HOBBIT.C WORM!
Win_api_driver system.exe X Added by the REVIRD TROJAN!
WMAudio services.exe X Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
WSAConfiguration svchostt.exe X Added by the AGOBOT.ZT WORM!
WTIndicator SchedInd.exe U WinTask - software that automates a variety of routine tasks quickly and simply
X-Grabber sswizard.exe N ScreenShot Wizard
XNSearchAssistant SrchAsst.exe X iWon Search Assistant - spyware
xor svchost.exe X Added by the XORDOOR TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Xpsystem SERVICES.EXE X Added by the DAEMOZ.A TROJAN! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup!
xpsystem services.exe X CoolWebSearch parasite variant
xp_system services.exe X Added by the KREPPER-G TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
Zone Labs Client Ex svchost.exe X Added by the NETSKY.F WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Zone system szchost.exe X Added by the MULTIDR-AC TROJAN!
zSPGuard Spguard.exe U "StartPage Guard (SPG) protects your PC from cyberscam, by detecting and preventing any unauthorized changes to your internet browser's Start and Search pages. It is also capable of removing automatically most of known 'invaders'."
ZtgServerSwitch server.vbs X ZTGServerswitch is part of Sony's Vaio support agent - designed by Support.com. Not required if the user does not wish to use the Vaio support agent and regarded as spyware
zzzCamlnSuitelll setup.exe 46*** ? ??
zzzhpsetup setup.exe ? ??
[random name] Svchosts.exe X Added by the SDBOT.N TROJAN!
[various names] svchostss.exe X Added by a variant of the RBOT WORM!
[various names] shch.exe X Premium rate adult content dialler
bot loader svchostt.exe X Added by the W32.GAOBOT.ALV WORM!
DriverLoad svchost.exe X Added by the Troj/Delf-KR trojan.
_svchost.con svchost.com X Added by the ERKEZ.C WORM!
{12EE7A5E-0674-42f9-A76B-000000004D00} stlb2.dll X BrowserAid/Startium parasite
®Windows Update svchosts.exe X Added by the FRUCTA TROJAN!
Unshare SafeShare.exe X P2P Program typically installed with adware or spyware. Typically found in C:\Program Files\safe-share.
WindowsXPserv svcnxp32.exe X Added by the Troj/Naninf-A trojan. Located in the Windows system directory.
securer syshost.exe X Troj/Bdoor-DU is a backdoor Trojan for the Windows platform. It is located in the directory securersyshost.exe.
Windows Updater svigost.exe X W32/Rbot-VS is classified as a worm.
Windows Update sdvhost.exe X W32/Agobot-AEU is a network worm with backdoor functionality.
Security Center scvhost.exe X W32/Rbot-TG is a network worm with IRC backdoor functionality. File is located in the Windows system directory.
SystemRegistry SysReg.vbs X Added by VBS/Ediboy-C. File is located in the Windows System directory. Also see WUpdate_35253825.vbs
Srv325 Srv325.exe X Added by W32/Agobot-PR. Found in the Windows system folder.
ruin system32.exe X Added by the Troj/Delf-JM Trojan!
random filename svchost.scr X Added by Troj/Bancban-BK. This infections attempts to steal passwords for certain Brazilian banking sites. Found in the %System%of Windows.
sysformat sysformat.exe X Added by Bagle.AY WORM!. This infections scans your hard drive for email addresses to send itself to.
Norton Auto-Protect SERVICES.EXE X Added by the Anker e-mail WORM!
Windows Service SERVICES.EXE X Added by the Anker e-mail WORM!
RPCserv32 SERVICES.EXE X Added by the MyDoom.AN WORM! File is found in the Windows directory.
Selene Selene.exe X Added by the Trojan.Eneles infection!
Microsoft Windows Update servcs.exe X Backdoor.Sdbot.A backdoor Infection! Found in the Windows system directory.
Services Startup services.exe X Added by the W32.Crowt.A@mm infection. Found in c:\program files\common files.
Services Logon services.exe X Added by the W32.Crowt.A@mm infection. Found in C:\Documents and Settings\[user name]\Templates folder.
zztp svchost.exe X Added by the Trojan.Tannick.B infection.
Win32 system32.vbs X Added by the VBS.Swerun Infection! Found in the Windows directory.
Bcvsrv32 system2.exe X Added by the W32/Agobot-PU IRC backdoor Trojan/WORM! Found in the WIndows system folder.
System Icons shell16.exe X Added by the W32/Sdbot-VD WORM! Found in the Windows system folder.
Win32 Loader svhost.exe X Added by the W32/Sdbot-VH WORM. Found in the Windows system folder.
spoolsv manager SpoolMgr.exe X Added by the W32/Assiral-A Infection! File is found in the Windows folder.
StartupFaster StrpFstCfg.exe ? Startup Faster 2004
MSN Beta SVCHOSTdll.exe X Added by the W32/Rbot-WF WORM! File is found in the Windows system folder.
stone stone.exe X Added by the W32/Agobot-PX WORM! File is found in the Windows system folder.W32/Agobot-PX is capable of spreading to computers on the local network protected by weak passwords after receiving the appropriate backdoor command.
Runner svchost.exe X Added by the Troj/AdClick-AG Trojan! File is found in the Windows folder.
Update svchost.exe X Added by the Troj/AdClick-AG Trojan! File is found in the Windows folder.
System Process svchost.exe X Added by the Troj/AdClick-AG Trojan! File is found in the Windows folder.
Printer Spooler spooler.exe X Added by the Troj/Delf-JJ Trojan! File is found in the root of the C: drive.
Microsoft Security Update security32.exe X Added by the Troj/Delf-JJ Trojan! File is found in the Windows system folder.
_winsystem.sys smss.exe X Added by the W32/Sober-K infection.
winsystem.sys smss.exe X Added by the W32/Sober-K infection. This infection should not be confused with the legitimate C:\Windows\System32\smss.exe.
System Networking SYSNET.EXE X Added by the W32/Rbot-WJ infection. File is found in the Windows system folder.
SVCHOST Generic application svchost.exe X Added by the Troj/Daemoni-AT TROJAN!
SysTry svchosts.exe X Added by the Troj/Banker-BD password stealing Trojan! The file is found in the Windows system folder. If you have this file on your computer, it is recommended that you change your online banking passwords and pins.
Microsoft Office Studio scvhvst.exe X Added by the W32/Sdbot-VQ WORM/Backdoor! File is found in the Windows system folder.
Computing Technologie Firewall svcauth.exe X Added as a WORM with backdoor functionality, W32/Sdbot-VO copies itself to the Windows system folder as svcauth.exe and creates registry entries.
Microsoft Internet Explorer smiissm.exe X Added by the Troj/Delf-KK Trojan! The infection creates a folder called SYS in the Windows folder and copies itself there.
winreg_32 Sysdll.exe X Added by the Troj/Dloader-IJ Trojan! File is found in the Windows folder.
System SPOOLSU.EXE X Added by the Troj/Banker-BJ password stealing Trojan! File is found in the Windows folder.
.mscsbl SVCHOST.EXE X Added by the Troj/Borobot-A infection! It is found in either the Windows system folder or the Application DataMicrosoftInternet Explorer folder.
svhost windows services Svhost8.exe X Added by a WORM, W32/Rbot-WQ, with backdoor Trojan functionality and found in the Windows system folder.
Auth Starter Ident startauth.exe X Added by the W32/Rbot-WP WORM!
Sub Connections shmyga.exe X Added by an unknown Trojan Downloader. It installs itself as a service with a servicename of Pro. Shmyga.exe is located in the Windows system folder. When executed it downloads zalupen.exe from a website which then copies two files, serve.exe and serve.dll to the Windows system folder and starts serve.exe. Serve.exe listens on port 80 and udp port 53 and appears to be a backdoor.
Configuration Loader seru32.exe X Added by the 32/Forbot-EL WORM! File is found in the Windows system folder.
spkrmon spkrmon.exe ? SoundMAX SpeakerMonitor service.
sysinfer sysinfer.exe X Added by the Adware.Adtest browser hijacker. Found in the Windows system folder.
{357AA41A-B7A8-4632-A27D-5B980B25CF43} services.exe X Added by the Adware.Clickbank adware. This should not be confused with the legitimate C:\Windows\System32\svchost.exe.
SuperBar.Component services.exe X Added by the Adware.Clickbank adware. File is found in the %windir%system32inetsrv folder.
AdRotator.Application services.exe X Added by the Adware.Clickbank adware. File is found in the %windir%system32inetsrv folder.
xp_system services.exe X Added by the Adware.CWSConyc hijacker.
run services.exe X Added by the Adware.CWSConyc hijacker. Found in the %WINDIR%inet10050services.exe folder.
value systimer.exe X Added by Adware.Downreceive. File is found in the C:\Program Files\Acceleration Software folder.
Debug SMSS.exe X Added by the Adware.DreamAd adware.
System Messenger SYSMSG32.EXE X Added by W32/Spybot-DK, a WORM!
boot_reg svchot.exe X Added by Troj/Bancban-BQ, a TROJAN. It is found in the Windows system folder.
PService svcnow32.exe X Added by Troj/Spybot-DJ, a TROJAN, and found in the Windows system folder.
virtual-machine svchosts.exe X Added by W32/Rbot-US, a WORM/backdoor IRC Trojan, found in the Windows system folder.
sxprv sxprv.pif X The TROJAN Troj/Dloader-IT adds this to the Windows system folder.
Working System Analyzer syswork.exe X This is a SDBot variant infection. These types of infections are backdoor trojans. It also creates a Windows Service.
Working System Analyzer syswork.exe X This is a SDBot variant infection. These types of infections are backdoor trojans. It also creates Run registry entries to start this file.
[not used] svchost.exe X A WORM/backdoor, W32/Kipis-J, opens notepad.exe and copies itself to the Windows folder as regedit.com and installs to it's newly created folder. A variety of anti-virus and security related processes may be terminated and backdoor opened on port TCP/9413.
STCPE STCPE.exe ? Used to allow access to UCLA computer systems.
_Services.dll SMSS.EXE X Added by the W32/Sober-L worm. This infection should not be confused with the legitimate C:\Windows\System32\smss.exe.
MSN BETA SERVICE.EXE X Added by the W32/Rbot-WZ WORM/backdoor Trojan to the Windows system folder.
ALG32 SPOOLSVU.EXE X The Troj/Agent-CJ TROJAN drops this file, alg32.exe and htass.dll into the Windows folder.
Microsoft smssdriver.exe X The Troj/Roneve-A TROJAN places the file into the Program files folder, creating a sub-folder it calls Xerox.nt when doing so.
Oesi srts.exe X PurityScan delivers advertisements to your computer.
Sygate Personal 3 svrv.exe X Added by the W32/Rbot-XD WORM/backdoor Trojan, which attempts to modify network shares and users and terminate processes.
start extracting spoolvse.exe X Added by the W32/Rbot-XF WORM/backdoor Trojan. It allows unauthorized access by malicious user(s) of the IRC network, killing processes and participating in DoS attacks among other activities.
Wut Nigga syswork.exe X A service created by W32/Forbot-FZ and bearing the display name of Working System Analyzer.
[not used] svohost.exe X This dumaru variant attempts to terminate antivirus programs so that it remains undetected. It is a mass-mailing worm with backdoor and keylogging capabilities.
Shellapi32 svcnet.exe X Added by W32/Tibick-C, a P2P WORM with limited backdoor functionality.
MSLARISSA SP00Lsv32.pif X Added by the W32/Assiral-B WORM! This worm will also install and run a file C:\WINDOWS\WinVBS.vbs to restrict user activity and terminate processes.
Cinnabd Prompt32 SP00Lsv32.pif X Added by the W32/Assiral-B WORM! This worm will also install and run a file C:\WINDOWS\WinVBS.vbs to restrict user activity and terminate processes.
(L4r1$$4) (4nt1) (V1ruz) SP00Lsv32.pif X Added by the W32/Assiral-B WORM! This worm will terminate processes and also install/run a file C:\WINDOWS\WinVBS.vbs to restrict user activity.
Windows Server Information servinfo.exe X Added by the W32/Forbot-EN WORM/IRC backdoor Trojan, which also starts a new service "Windows ExplorerTM" with a display name of "Windows Server Information".
Windows ExplorerTM servinfo.exe X A service initiated by the W32/Forbot-EN, with a display name of "Windows Server Information" on NT systems.
super super.exe X Added by the W32/Agobot-QT WORM/IRC backdoor, which changes the HOSTS file and allows an attacker access - making possible several other actions.
Systems Systems.exe X Added by the Troj/Bankboa-A TROJAN, it targets a specific website and steals passwords.
System Net sys32.exe X Added by the W32/Forbot-FX WORM, which also creates a new service called "Win32", with the display name "System Net".
Win32 sys32.exe X A service created by W32/Forbot-FX with a display name of "System Net" allows remote attack via IRC channel, deletion of files, modification of data and ternination of processes.
MsVBdll sys32dll.exe X Added by the W32/Aimdes-C WORM to insure automatically running, it will exploit AOL instant messenger and harvest email addresses.
Windows DLL Loader syscfg16.exe X Added by the W32/Domwis-G worm. This infections uses IRC to receive commandsa and to send and receive files.
svshots svshots.exe X The Troj/Botget-A TROJAN opens a backdoor, and via IRC channels will attempt to download and run C:gdc.exe also.
ws2_32 svchst.exe X Added by the Troj/Voken-A TROJAN, it will terminate anti-virus and security-related processes.
Windows Spooler Services spool.exe X The W32/Agobot-AMO WORM adds this to corrupt the HOSTS file, terminate processes,and open a backdoor on the infected computer.
Windows Service Support Call SVSS32.EXE X This R-Bot WORM varaiant adds the file to allow unauthorized access to an attacker through an open IRC channel.
AdminSoft sysfile.vbs X Added by the VBS/Stargrub-A WORM, by way of an email attachment. It will attempt to add a user name, change proxies and copy additional files to hard drive(s).
Sygate Personal Firewall sexy.exe X An Rbot WORM variant adds the file to download additional files, steal CD keys and become involved in DoS attacks via an IRC channel and remote attacker.
Spooler SubSystem App spoolsvc.exe X Added by the W32/Poebot-J WORM/IRC backdoor!
WCESMngr spoolsb.exe X An Agobot WORM/IRC backdoor variant adds this to provide unauthorised access which will allow multiple actions to occur.
Sony SPTI Service Sptisrv.exe N Legitimate service from Sony. Possibly for video on demand from Sony Pictures Television International (SPTI)
SymWMI Service SymWSC.exe Y Installed by Norton Internet Security Center. This program is essential to operation of this program when installed on your computer. Disabling this service may affect Internet access.
Default shell32.exe X Added by the BINGHE backdoor Trojan! It has the ability to log your keystrokes, steal data, and execute commands.
Suite SuiteOffices.exe X Added by the LAZAR trojan downloader.
Home Theater SchSvr SchSvr.exe N WinScheduler is installed with Home Theater Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs
IMClass Svhosl.exe X Added by an unidentified WORM or TROJAN!
MS Windows Update scguard.exe X Added by a variant of the RBOT WORM!
Winmgr.exe scvhost.exe X Added by the AGOBOT.AFG WORM!
MSNPluginSrvcs sagate.exe X Added by the SDBOT.AKJ WORM!
PrevxPro SAGUI.exe Y Pro version of PrevX Home intrusion prevention software
Services Startup svhost33.exe X Added by a variant of the RBOT WORM!
sp2chk.exe sp2chk.exe X Added by the ALUROOT.A TROJAN!
SpyBlocker spyblocker.exe U SpyBlocker blocks the communications of spyware installed on a PC so spyware runs but cant exchange data with the server to which it should report. Ensuring spyware cant communicate is important, as you may find after using Ad-Aware that some applications containing spyware subsystems may not run correctly or at all.
(357AA41A-B7A8-4632-A27D-5B980B25CF43) svchost.exe X Added by the Troj/Small-AQ trojan!
StatusClient StatusClient.exe ? Part of Hewlett Packard network printer drivers
System Config Manager smssl.exe X Added by the AGOBOT-ZJ WORM!
UniPrint SetDfltSettings.exe U Drivers for Uniprint, a printing help for Terminal Services and Citrix which recieves downloaded files from a Uniprint enabled server and prints them locally allowing for truly universal printing through Terminal Services or Citrix
Windows Logon Procedure Svchosta.exe X Added by a variant of the SPYBOT WORM!
Sun svchost32.exe X Added by the Troj/Banker-BP TROJAN!
Local runole service srvc32.exe X A TROJAN, Troj/Small-DP uses this file, after first downloading C:t.exe, C:n.exe or C:m.exe. It will also try to modify the Windows Explorer files.
SSC Service Utility ssc_serv.exe U SSC Service Utility is a printer utility for refilled Epson cartridges
Media Player Sysdll.exe X Added by a Troj/Banker variant!
reg_run Systen.exe X Added by the Troj/Bancos-BS TROJAN!
r_server SERVICE.EXE X Added by the Troj/Multidr-CP TROJAN! A new service is set also, with the displayname of Remote Administrator Service and servicename r_server.
Remote Administrator Service SERVICE.EXE X A service displayname set by the Troj/Multidr-CP with a servicename of reg_run.
Softload softload.exe X A SDBot WORM/IRC backdoor variant adds this. The filename buds.exe and the filename forcepog.exe may also be involved.
Webservice svchost.exe X Added as a new service by the Troj/Feutel-B TROJAN, using the same displayname.
SystemNT SystemNT.exe X Added by the Troj/PWSVB-EG TROJAN to steal passwords!
Shell svchost.exe X Added by the Troj/Goldspy-B TROJAN!
Microsoft's System Module Sysmodule.exe X The Troj/Bdoor-FJ backdoor TROJAN adds the file to allow an attacker unauthorized remote access.
AvG svchost323.exe X Added by the W32/Rbot-ZA WORM/backdoor!
Microsoft Sum32 sum32.exe X Added by the W32/Rbot-YW WORM/IRC backdoor!
vsadmin smrs.exe X Added by the W32/Agobot-RC WORM/IRC backdoor Trojan!
NDIS Adapter servenxpp.exe X The W32/Forbot-GP WORM/Backdoor Trojan adds this, also creating a new service. The service is named "NDIS TCP Layer Transport Device", it's displayname is "NDIS Adapter".
NDIS TCP Layer Transport Device servenxpp.exe X The service is added by the W32/Forbot-GP WORM using this file, it's displayname is NDIS Adapter.
System Unix syscfg32.exe X Added by a Rbot WORM variant!
SDK Core Component sdkcore.exe X Added by the W32/Sdbot-WC WORM/IRC backdoor Trojan!
Sygate Personal Firewall sys.exe X Added by the W32/Rbot-ZC WORM/IRC backdoor Trojan!
SVHOST SVCHOST.EXE X Added by the W32/Zori-A VIRUS!
SSL SearchNDestrou.exe X Added by the W32/Sdbot-WG WORM/IRC backdoor Trojan to the Windows system folder.
Shell32 Shell32.vbs X Added by the VBS.Scafene WORM!
regsvc systune.exe U Added by AceSpy SPYWARE! ** Treat as an X if it wasn't intentionally installed.
sys32dll sys32dll.exe X Added by the W32.Aimdes.B WORM!
System Database Administration Support Process sysdasp.exe X Added by the W32.Derdero.C WORM!
System Database administration systemDA.exe X Added by the W32.Derdero.B WORM!
[random name] se?vices.exe X PurityScan adware variant.
swcroot swcroot.exe X Unidentified adware
Samsung Samsungs.exe X Added by an IRC_TROJAN variant!
Sygate Personal Firewall sys.exe X Added by a Rbot variant.
Nortons AV SYSTEM scvchost.exe X Added by a Rbot variant infection.
Microsoft Update sysdll32.exe X Added by a Rbot variant infection.
Server Backbone server05.exe X Added by the W32/Rbot-ZM worm.
WINTASK sys32.exe X Added by a variant of the Mytob mass-mailing WORM/IRC backdoor Trojan!
Windows Systemnmg stagmr.exe X Added by the W32/Mytob-J mass-mailing WORM/IRC backdoor!
windows svchost.exe X Added by the W32/Slomirc-A WORM/IRC backdoor Trojan!
c svchost.scr X Added by the Troj/Bancban-BX TROJAN!
System systray.exe X Added by the Troj/Pisaboy-A TROJAN/backdoor! MSN Messenger users are targeted.
Microsoft Service Host Process svchost.exe X Added by the W32/Krynos-B WORM! It will send itself to email addresses it has identified on the infected computer. Found in the Windows Help folder.
Steganos Live Encryption Engine (Version 401) [Service] SLEE401.exe Y This is part of the Steganos Security Suite and involved in handling real-time encryption.
StyleXPService StyleXPService.exe Y "How sleek is your desktop? Style XP unleashes the full potential of your Windows XP desktop by allowing you to download and install XP themes."
sxmrv sxmrv.pif X Added by the Troj/Dloader-KE TROJAN!
Firewall SP2 UPDATE.exe X Added by the W32/Elitper-E WORM, and it will exploit P2P applications. Many additional files are created in varios folders found in Documents and Settings and Program Files locations.
GNP Generic Host Process svchost.exe X Added by the Troj/Zapchas-F TROJAN/IRC backdoor!
SunJavaUpdateSched scvhost.exe X Added by the W32/Sdbot-AVX WORM/IRC backdoor Trojan!
Stubbish Stubbish.exe X Added by the W32/Stubbot-A WORM/IRC backdoor!
sms sms.exe X Added by the Troj/Dloader-KR TROJAN!
Systems svch0st.exe X Added by the W32.MYDOOM.BI WORM!
Spyware Nuker swn2.exe U Part of the Spyware Nuker 2004 program.
svrhost Svrhost.exe X Added by the Adware.Satbo adware.
MSWindows spool16.exe X Added by the Avkiller.Trojan.
MS Scandisk Scandisk.exe X Added by the Backdoor.AntiLam backdoor.
NAV Auto Updates slserves.exe X Added by a variant of the W32/SDBOT WORM!
Snow Sk.exe X Added by Backdoor.Blizzard
tunelling sys64.exe X Added by Backdoor.Checkesp. This infection listens on TCP port 666.
SysArchive SysArchive.exe X Added by Backdoor.DarkSky.B. This infection listens on ports 5418 and 5419 awaiting commands.
SVGA Adapter svgainit.exe X Added by Backdoor.Deftcode. This infection connects to an IRC server where it awaits commands.
Windows Service Scanvegw.exe X Added by the Backdoor.Delf backdoor. This infection will attempt to protect itself by terminating known antivirus programs.
System-Time systimeupdate.exe X Added by Backdoor.Denwp.
sysyemdl sysedit.exe X Added by Backdoor.Evilbot. This infection connects to an IRC server where it awaits remote commands.
Snow swon4.exe X Added by Backdoor.Fxdoor.
Security Patch scmss.exe X Added by the W32/Rbot-ZW WORM/IRC backdoor Trojan.
SPOOLSV32 SPOOLSV32.EXE X Added by the Troj/CWS-I Trojan dropper.
MSConfig32 smss32.exe X Added by the Troj/Flood-EL TROJAN/backdoor.
(default) SYSDLL32.exe X Added by the Backdoor.G_Door backdoor.
command shell12.exe X Added by the Backdoor.Ghoice.12 backdoor. This infections listens on TCP port 1001.
huigezi SP00LSV.EXE X Added by Backdoor.Graybird.J
Windows Bootup SystemLogin32.exe X Added by a variant of the RBOT WORM! This variant connects to an IRC server at lol.selectgex.com. It also creates a mutex called TehHaxScanall64.
svchost svchost.scr X Added by Troj/Bancos-CB.
SuNotification suatshut.exe U ShadowSurfer - "provides a safe computing environment by creating a virtual twin of your PC. Restore the pre-ShadowMode™ system state no matter what changes have occurred to your PC."
SCVHOST SCVHOST X Added by the Troj/Feutel-D TROJAN as a new service using the same name as a displayname.
pnpsvc svchost.exe -k netsvcs X Added by Troj/StartPa-FP as a new service, using "Plug and Play svc service" as a displayname.
Svchost svchost.exe X Added by Troj/AdClick-AM, a TROJAN that copies itself to the C:\Program Files\Internet Explorer" folder.
strto strto.exe X Added by Troj/Killav-AD to terminates anti-virus and security related applications and delete all files found in their folders.
spoolsvc spoolsvc.exe X Added by the Troj/Dropper-AT.
SCVHOST SCVHOST.EXE X Added by W32/Agobot-RK.
syshost Syshost.exe X Added by the Troj/Banworm-B TROJAN!
SmartLinkService slserv.exe U Associated with SmartLink modem and is used to show a tray icon that gives connection information.
System SVCHOST.EXE X Added by the Troj/LdPinch-AU TROJAN!
MotherBoard Sounds SOUNDS.EXE X Added by the W32/Rbot-AAP WORM/IRC backdoor trojan!
svhost System svhost.exe X Added as a new service by the Troj/Xrat-A TROJAN, using a servicename of svhost.
servisec servisec.exe X Added as a new service by the Troj/Xrat-B TROJAN, using a displayname of the same.
Compaq Service Drivers systeminfos.exe X Added by the W32/Sdbot-XC WORM/IRC backdoor trojan!
winreg_32 svchosst.exe X added by the Troj/Bancos-CE TROJAN!
Mircrosoft Svchost32 svchost32.exe X Added by the W32/Rbot-AZW WORM/IRC backdoor trojan!
Ethernet Drivers smrrs.exe X Added by the W32/Rbot-AAK WORM/IRC backdoor trojan!
svchostb svchostb.exe X Added by the Troj/Sniffer-J TROJAN!
svchosta svchosta.exe X Added by the Troj/Sniffer-I.
Smart Card Client SCardClnt.exe X Added as a new service by the W32/Codbot-K WORM/IRC backdoor, using SCardClnt as a servicename.
Sys32DLL Sys32DLL.vbs X Added by the VBS/Ediboy-A WORM!
Syntax Script saskatcw.exe X Added by the W32/Sdbot-TE WORM/IRC backdoor trojan!
RegistrySettings SystemReg.vbs X Added by the VBS/Ediboy-B WORM!
Start It Uping svchosets31.exe X Added by a SDBot variant.
SAutoLaunchExe SAutoLaunchExe.exe U Sharp Zaurus PDA related, needed to synchronize information with a Desktop or Notebook.
pcServer server.exe X Ssppyy spyware
SDK Core Component SDKC0RE.exe X Added by the W32/SDBOT-WC WORM!
windows sound manager SndMon16.exe X Added by a variant of the W32/FORBOT WORM!
Microsoft Update Machine servicez.exe X Added by the SPYBOT.BI WORM
Servicio Local svhost.exe X Added by a variant of the WIN32.RBOT WORM!
Srvce Pack Updte svcpack.exe X Added by a variant of the WIN32.RBOT WORM!
Generic Host Process326a System Backup scvhost326a.exe X Added by a variant of the W32/SDBOT WORM!
SvcH0st SHCH.EXE X Added by the TROJ/BDOOR-EB TROJAN!
SvcH0st SVCHST.EXE X Added by the TROJ/BDOOR-EB TROJAN!
SMTP32 Mailing Protocol smtp32.exe X Added by a variant of the WIN32.RBOT WORM!
Windows DLL Tracker spoolsrv.exe X Added by a variant of the W32/WOOTBOT WORM!
.mscsbl svhost.exe X Added by the BACKDOOR-CMQ TROJAN!
sssasasb32 sssasasb32.exe X Adware trojan - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Agent.ig
Windows Firewalll sphost.exe X Added by a variant of the WIN32.RBOT WORM!
Microsoft Windows Update swwhost.exe X Added by a variant of the WIN32.RBOT WORM!
Microsoft Services svssshost.exe X Added by a variant of the WIN32.RBOT WORM!
MsnExplorer SHCH.EXE X Added by the TROJ/BDOOR-EB TROJAN
MsnExplorer SVCHST.EXE X Added by the TROJ/BDOOR-EB TROJAN
start extracting spoolvs.exe X Added by a variant of the WIN32.RBOT WORM!
Winsock2 driver sysreq.exe X Added by the W32/SPYBOT-CC WORM
Windows Screensaver Service.exe X Added by the W32.KELVIR.P WORM!
Sygate Personal Firewall service.exe X Added by a variant of the WIN32.RBOT WORM!
Sygate Personal Block Studio.exe X Added by the W32/RBOT-TW WORM!
syst syst.exe X Added by the JOKE_DUMB.A "Joke" virus
Sms System32 SmsSystem32.exe X Unidentified malware
Windows TM SVPHOST.exe X Added by a variant of the WIN32.RBOT WORM!
Windows Service svvhost.exe X Added by the W32/AGOBOT-HL WORM!
Windows Firewalll svvhost.exe X Added by a variant of the WIN32.RBOT WORM!
Start Upping spoolnt.exe X Added by the W32/Rbot-TM WORM/IRC backdoor trojan!
Windows Registry Scan svcdll.exe X Added by the W32/Rbot-TP WORM/IRC backdoor trojan!
Norton System svchosts.exe X Added by the Troj/Dloader-GB.
Service Scheduler scheduler.exe X Added by the W32/Agobot-OA infection.
System Net Database sysnd.exe X Added by the W32/Rbot-AAW WORM/IRC backdoor trojan!
Microsoft Windows Update svzhost.exe X Added by the W32/Forbot-EV WORM/IRC backdoor trojan, which also installs a new service called Microsoft Update.
svchostBB svchostBB.scr X Added by the Troj/Dloader-MC TROJAN!
svchostBD svchostBD.scr X Added by the Troj/Dloader-MC TROJAN!
svchostCX svchostCX.scr X Added by the Troj/Dloader-MC TROJAN!
svchostIT svchostIT.scr X Added by the Troj/Dloader-MC TROJAN!
svchostBN svchostBN.scr X Added by the Troj/Dloader-MC TROJAN!
svchostRE svchostRE.scr X Added by the Troj/Dloader-MC TROJAN!
svchostBDJU svchostBDJU.scr X Added by the Troj/Dloader-MC TROJAN!
svchostUN svchostUN.scr X Added by the Troj/Dloader-MC TROJAN!
_SystemCheck services.exe X Added by the W32/Sober-M WORM!
DriverDB svcmdx32.exe X Added by the Troj/IRCBot-AR TROJAN/IRC backdoor!
Windows Security Update secupd.exe X Added by the Troj/Sepuc-B TROJAN, which installs a service with both service & displaynames being Windows Security Update.
sviload32 sviload32.exe X Added by the W32/Rbot-AAS WORM/IRC backdoor trojan!
Compaq Sound Drivers For WINDOWS sounddr.exe X Added by the W32/Sdbot-XG WORM/IRC backdoor trojan!
Windows Stand Sound Drivers Sounddrv.exe X Added by the W32/Sdbot-XF WORM/IRC backdoor trojan!
Microsoft Services SMSS32.EXE X Added by the W32/Rbot-AD trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
ine svchosts.exe X Added by the W32/Rbot-AIZ trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.

Patches for exploits it uses to infect your machine can be found here:

http://www.microsoft.com/technet/security/bulletin/ms04-012.mspx
http://www.microsoft.com/technet/security/bulletin/ms03-039.mspx
http://www.microsoft.com/technet/security/bulletin/ms03-007.mspx
http://www.microsoft.com/technet/security/bulletin/ms01-059.mspx
Microsoft Update sys.exe X Added by the W32/Rbot-AJ trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Scan Register SSMS.EXE X Added by the W32/Rbot-AT trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Machine systemse.exe X Added by the W32/Rbot-BD trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Task Debugger sysdll.exe X Added by the W32/Rbot-CQ trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Updaters SYSCONFIGS.EXE X Added by the W32/Rbot-DF trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
load svchost.exe X Added by the Troj/Lineage-K Trojan.
Shell svghost.exe X Added by the Troj/Lineage-J.
Windows Update System Shell svhostcs32.exe X Added by the W32/Rbot-AAZ WORM/IRC backdoor trojan!
Recycle Bin Handler 2005 system.exe X Added by the Troj/Bdoor-HO .
svshost32 svshost32.exe X Added by a variant of the Rbot worm. This worm, when started, connects to IRC servers where it sits in a desginated channel waiting for commands from a remote user.
zsms smss.exe X Added by the Troj/Bancos-CK Trojan. This infection should not be confused with the legitimate C:\Windows\System32\smss.exe.
ServiceHst svcnost.exe X Added by the W32/Agobot-RS WORM/IRC backdoor trojan!
SDKcore Update Components2 SDKC0R3.exe X Added by the W32/Rbot-ABA WORM/IRC backdoor trojan!
System Startup Service svcproc.exe X This infection is identified as Trojan.Win32.Stervis.b. It is usually bundled with nail.exe, a Abetterinternet adware variant. It is notoriously difficult to remove and is usually bundled with other malware that are hard to remove as well. One method that we have found that is able to remove this infection and the other malware that are bundled with it is the ewido security suite which you can download and try for free.
Disk Keeper SECURITY.EXE X Added by the Troj/Daoser-A trojan downloader.
Service Host SVCHOST.EXE X Added by the Troj/Daoser-A trojan downloader. This should not be confused with the valid svchost.exe that is found in the Windows\system32 directory.
SSCFBTN.EXE SSCFBTN.EXE ? Samsung Scanner or Printer related - what does it do and is it required?
RegHelp svchosts.exe U SpyGraphica spy software - "Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world."
STDSB STDSB.exe Y Scrollbar driver for notebooks. If taken out of the Startup, it will not provide scrolling.
SsAAD.exe SsAAD.exe N The item is added during the installation of Sony's Digital Music Manager software that comes with Sony MP3 players. It monitors your HDD for newly added music tracks and automatically offers to add them to your playlist when you connect your MP3 player.
Microszoft Update Mach1nezs SVCOHST.EXE X Added by the W32/Rbot-EG trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windows Firewalll scvhost.exe X Added by the W32/Rbot-EK trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection also attempts to terminate various processes including other infections.
MicrosoftUpdate svhest.exe X Added by the W32/Rbot-ES trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Services host svchost.com X Added by the W32/Rbot-EU trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection also attempts to terminate various processes including other infections.
SDKcore Update Components2 SDKC0R3.exe X This is an Rbot variant. This infection connects to an IRC server where it will await commands from a remote user.
Microsoft Update sysdat.exe X Added by the W32/Rbot-GH trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection also attempt to send back cd keys of applications and games that may be installed on your computer.
Windows Registers Svchosts.exe X Added by the W32/Rbot-HV trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection will also attempt to harvest keystrokes and cd keys from your computer.
SP1-Update sp1update.exe X Added by the W32/Rbot-JG trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windows Service slserv32.exe X Added by the W32/Rbot-KO trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection can will terminate antivirus programs to avoid detection.
WINRUN svchost32.exe X Added by the W32/Mytob-AI, a worm that harvests email addresses from files and the Windows Address Book. It also has backdoor trojan functionality.
csoftok softok.exe X Added by the Troj/QQPass-H to log key presses & steal passwords.
serpe serbw.exe X Added by the W32.Serflog.A worm. This worms spreads through file sharing networks and MSN messenger.
ltwob serbw.exe X Added by the W32.Serflog.A worm. This worms spreads through file sharing networks and MSN messenger.
avnort serbw.exe X Added by the W32.Serflog.A worm. This worms spreads through file sharing networks and MSN messenger.
AvSer sysup.exe X Added by the W32.Serflog.B worm. This worms spreads through file-sharing networks and MSN Messenger.
DsmSer sysup.exe X Added by the W32.Serflog.B worm. This worms spreads through file-sharing networks and MSN Messenger.
rollbk sysup.exe X Added by the W32.Serflog.B worm. This worms spreads through file-sharing networks and MSN Messenger.
AvSer svosm.exe X Added by the W32.Serflog.B worm. This worms spreads through file-sharing networks and MSN Messenger.
DsmSer svosm.exe X Added by the W32.Serflog.B worm. This worms spreads through file-sharing networks and MSN Messenger.
rollbk svosm.exe X Added by the W32.Serflog.B worm. This worms spreads through file-sharing networks and MSN Messenger.
[not used] svchost.exe X Added by the W32/Tex-A mass-mailing worm.
Service Service.pif X Added by the W32/Assiral-C email worm.
SDAv SVHOST.EXE X Added by the W32/Sumom-C instant messenger and P2P worm.
NDAv SVHOST.EXE X Added by the W32/Sumom-C instant messenger and P2P worm.
[not used] sound_drive16.exe X Added by the Troj/Bdoor-GP backdoor trojan.
[not used] sys16.exe X Added by the Troj/Bancos-BZ password stealing trojan. This trojan attempts to steal the account information of Brazilian bankes.
KeSDM Sdmapi.sys X Added by the HaxDoor.B rootkit/backdoor Trojan. This service is installed as a system driver and is part of the rootkit functionality of this infection.
Windows NT Service Name svchcst.exe X Added by the W32/Rbot-NV trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infections are usually capable of logging keystrokes, retrieve cd keys, and flood other computers.
Media Software UPdater sscs.exe X Added by the W32/Rbot-ABE. When started this infection connects to an IRC server where it waits for commands, and tries to delete the computer's I$ network shares every 2 minutes.
windows run system.exe X Added by the W32/Icpass-A worm. Using zip programs installed on the infected computer, it can send the infected files to people as they join the IRC channels involved.
Spools Service Controller spools.exe X Added by the W32/Kassbot-C. It will modify the HOSTS file in an attempt to block access to anti-virus related websites, attempt to spread by exploiting LSASS (MS04-011) or DCOM (MS04-012) vulnerabilities, and monitor a user's internet access. If certain internet banking and finance sites are accessed, the worm will redirect the user to a Russian website with fake login pages or email the stolen details to a Russian email address.
Windows Svchost Authority slsass.exe X Added by the W32/Rbot-UA network worm and IRC backdoor. When started this infection connects to an IRC server where it waits for remote commands to execute.
SV00LSV SV00LSV.EXE X Added by the Troj/GrayBird-C backdoor trojan.
Performance Logs and Alerts smlogsvc.exe N This is a Microsoft services that collects performance data from various applications running on a Windows computer. This service should be set to manual as it will start and stop as needed.
SYSMSG SYSMSG332.EXE X Added by the W32/Vampire-C worm. This worm spreads via ICQ. To remove, reboot into safe mode and delete this file.
sdkupdate22 SDK0mCORE.exe X Added by the W32/Forbot-DT network worm. When started this infections connects to an IRC server where it waits for remote commands.
sdkupdate22 SDK0mCORE.exe X Added by the W32/Forbot-DT network worm. When started this infections connects to an IRC server where it waits for remote commands.
USBHWINFO sst6.exe X Added by the Troj/LowZone-I trojan.
Anthrax serious.exe X Added by the W32/Mirsa-B mass-mailing worm.
Justice serious.exe X Added by the W32/Mirsa-B mass-mailing worm.
Four serious.exe X Added by the W32/Mirsa-B mass-mailing worm.
Ebola serious.exe X Added by the W32/Mirsa-B mass-mailing worm.
Fathers serious.exe X Added by the W32/Mirsa-B mass-mailing worm.
F4J serious.exe X Added by the W32/Mirsa-B mass-mailing worm.
Service Control Application system.exe X Added by the worm. This worms spreads via the LSASS exploit.
SDKz0r SDKc55rezzz2.exe X Added by the W32/Sdbot-UN worm. When connected this infections connects to an IRC server where it waits for remote commands to execute.
Winsecure Antivirus SecureAntivirus.exe X Added by a Spybot worm variant. Attempts to connect to the IRC server bckup7.rioxx.ms to wait for commands.
scsrs scsrs.exe X Added by the W32/Rbot-VF worm. When started this infection connects to a remote IRC server where it waits for commands to execute.
Scandsk2 scandsk2.exe X Added by the W32/Agobot-PK trojan. When started this infection connects to a remote IRC server where it waits for commands to execute.
Windows Update scvhost.exe X Added by the W32/Sdbot-XT WORM.
rpc Win32 shost32.exe X Added by the W32/Rbot-ABL worm. When started this infection connects to a remote IRC server where it waits for commands to execute.
syscfgx32 syscfgx32.exe X Added by the W32/SdBot-GB worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
Microsoft Explorer svapache.exe X Added by the W32/Rbot-VR worm. When started this infection connects to a remote IRC server where it waits for commands to execute. These infections also log keystrokes, so if you are infected you should change all your passwords.
snapple snapple.exe X Added by the W32/Forbot-EG worm. When started this infection connects to a remote IRC server where it waits for commands to execute.
yemarvd sysmon.exe X Added by the Troj/Agent-CH backdoor trojan. This infection modifies your HOSTS file to disable the connection to various antivirus software update sites.
Logical Disk Manager Provider spool.exe X Added by the Troj/Agent-DA trojan.
DllName status.dll X Added by the Troj/Haxdoor-R rootkit. This infection makes it so you can not see certain processes, files, or registry keys on your computer. It is usually installed in conjunction with other malware.
SonyPowerCfg SPMgr.exe ? Related to Sony Power Management for VAIO Computers - is it required?
WinStart services.exe X Added by the W32/Sober.p@MM worm. To remove this infection, reboot into safe mode and delete C:\WINDOWS\Connection Wizard\Status\services.exe. Then reboot back to normal mode. This will stop the infection but there will be leftover files behind that will not be causing harm. Visit the link in this description for more information on what other files to delete.
SoundMAX SoundMAX.exe X Added by the W32/Rizon-A worm.
seeve seeve.exe X A media-motors.net adware variant. Will cause popups to appear on your computer.
Web Service sm.exe X Added by the Troj/Psyme-BQ downloader trojan.
spoolsvc spoolsvc.dll X Added by the Troj/Dropper-AT trojan dropper. The presence of this infection usually means there is other malware installed on your computer.
Windows Shell shell.exe X Added by the W32/Mytob-CA worm.
SMSSU SMSSU.EXE X Added by the Troj/Small-EI trojan dropper.
winsys syschost.exe X Added by an unidentified TROJAN!
Shellspl spools.exe X Added by an unidentified TROJAN!
Microsoft Office svxhost.exe X Added by a variant of the WIN32.RBOT WORM!
SVCHOST.EXE SVCHOST.EXE X Added by the Troj/Wrmscan-A . It modifies any files named "mirc.ini", then creates a file named "server.mrc" in the same folder which causes the IRC program to periodically send a message directing the recipient to a particular website.
Windows Service Host Process svchost.exe X Added by the W32.Ezio.A@mm WORM.
Firewall Sp2 system sys32Conf.exe X Added by the W32/Rbot-ABT worm. This infection connects to an IRC server on startup where it waits for remote commands to execute.
ControlPanel systemctrl.exe. X Added by the Troj/StartPa-FX trojan.
180clientstubinstall stubinstaller4528.exe X 180Solutions/N-Case adware related
activexupdate svcss.exe X Added by a variant of the DEDLER.C TROJAN!
chipdrivepinmanager sokscmpn.exe U ChipDrive Smartcard software
chipdrivesmartcardmanager SCMgr.exe U ChipDrive Smartcard software
dot.net networking Snss32.exe X Added by a variant of the IRC_TROJAN !
dx sys#.exe X Added as a result of the DEXTER.A VIRUS! where # is a random number
logitech camera Soundcane.exe X Added by an unidentified WORM or TROJAN!
microsoft updating machine sysc0de.exe X Added by the RBOT.RB WORM!
microsoftkeysd systemwin32.exe X Added by a variant of the WIN32.RBOT WORM!
microsoftupdates syshelped.exe X Added as result of a W32/Forbot-AZ worm infection
msnmsgrs swiss.bat X IRC worm or backdoor trojan!
officeguardui svcss.exe X Added by the DEDLER-C TROJAN!
printer sysprinter.exe X Added by the TROJ_SMALL.ZY TROJAN!
registry system166 checkup monitor SystemReg166.exe X Added by a variant of the WIN32.RBOT WORM!
regsvc systune U Added by AceSpy SPYWARE! ** Treat as an X if it wasn't intentionally installed.
schoolpop0 Schoolpop0.exe U Schoolpop Shopping Buddy
service SYSNT.exe X Added by the BACKDOOR-CHA TROJAN!
sf sf.exe X Added by the WIN32.FAVADD.O TROJAN!
sfita sfita.exe X Added by the FAVADD.O TROJAN!
shhost shhost.exe X Added by the BACKDOOR.WIN32.AGENT.CE TROJAN!
sixtysix sixtypopsix.exe X Unidentified adware
spool server daemon SPOOLSVD32.EXE X Win32.Rbot worm variant
sunasdtserv sunasDTServ.exe U SunBelt CounterSpy spyware detection and removal software
sunasserv sunasServ.exe U SunBelt CounterSpy spyware detection and removal software
svcsys registry manager svcsysreg.exe X Added by a TROJAN.CLICKER - identified by Kaspersky antivirus as Trojan-Clicker.Win32.Agent.cv
sysconfig Stealth KeySpy.exe U Added by StealthKeySpy Commercial Keylogger ** Note Product must be manually installed.
sysdxvid sysdxvid.exe X Premium rate adult content dialer
sysmonnt sysmonnt X Transponder parasite related
sysobj.exe sysobj.exe X Added by a NTRootKit TROJAN variant!
sysprocessor update sysprocessor.exe X Win32.Rbot worm variant
systemcheck SysCheckBop32.exe X Added by the WIN32.VB.TG TROJAN!
systemidle stemIdle.exe X Added as a result of the WOOTBOT.AO VIRUS!
taskmrg schwoch.exe X Added as result of a Troj/LDPinch-Y trojan infection
windows service pack2 svchhost.exe X Added by a variant of the WIN32.RBOT WORM!
winsock32driver svchhost.exe X Added by the BKDR_HACKARMY.I TROJAN!
KERNEL 32 SKERNEL32.com X Added by the W32/Semapi-A. This mass-mailing worm may display a message: "Unable to locate 'semapi.dll' reinstalling this application may fix this problem."
xxcm sys.exe X Added by the W32/Krisworm-A worm, it will be found in the %Windir%Fonts folder.
sads sdsa.exe X Added by the W32/Rbot-PA worm. This infection connects to an IRC server where it waits for remote commands.
Micro SVC src.exe X Added by the W32/Rbot-Q worm. This infection connects to an IRC server where it waits for remote commands.
Printer Services spool.exe X Added by the W32/Rbot-RL worm. This infection connects to an IRC server where it waits for remote commands.
k3ym4n servicsmjr.exe X Added by the W32/Rbot-RW worm. This infection connects to an IRC server where it waits for remote commands.
Microsoft Intrenet Explorer systemR.com X Added by the W32/Rbot-SH worm. This infection connects to an IRC server where it waits for remote commands.
System33 services33.exe X Added by the W32/Rbot-VQ worm. This infection connects to an IRC server where it waits for remote commands.
SystemTray system.bat X Added by the W32/Resdoc-A worm.
paint.exe shnlog.exe X Added by the Troj/Puper-A trojan.
Windows system.exe X Added by the W32/Rbot-ACB worm. This infection connects to an IRC server where it waits for remote commands.
Configuration Loader smsai.exe X Added by the W32/Sdbot-YE worm. This infection connects to an IRC server on startup where it waits for remote commands to execute.
Winlogon Shell svchost.exe X Added by the W32.Kipis.M WORM!
sys008 sys008.exe X Hijacker, also detected as the TROJ/STARTPA-GK TROJAN!
sysnet snuninst.exe X Unidentified adware
spywareno SpywareNo.exe X Bogus "Spyware remover" - see the SpywareWarrior_List of Rogue/Suspect Anti-Spyware Products & Web Sites
Windows LAN Service Manager svchost.exe U Added by the Spyware.ComSurveilSys surveillance software. If this was not installed by you, you should uninstall it.
speedupmypc SpeedUpMyPC.exe U SpeedUpMyPC "automatically fine-tunes all your resources including hardware, system settings and internet usage to operate at peak performance at all times."
helper sweden.exe X AsdPlug premium rate adult content dialer variant
print services spolserv32.exe X Added by the RBOT.ZP WORM!
printer spooler subsystem spoolss.exe X Added by a variant of the WIN32.RBOT WORM! - Note - this is NOT the legitimate Windows spoolss.exe process, located in the Winnt\System32 or Windows\System32 folder, and which should NOT figure in Msconfig/Startup!
sagentservice Sagent.exe U Added by TinySpyAgent **Note this application must be manually installed.
secretmaker secretmaker.exe U SECRETMAKER is a combonation of eight privacy-defending programs, including Spam Fighter Pro, Worm Hunter, Pop-Up Killer, Banner Blocker, Cookie Eraser, Privacy Protector, History Cleaner, and Garbage Cleaner.
showwnd ShowWnd.exe U Showwnd is included with the Chicony keyboard software and is used by the software to stop the keyboard driver's taskbar entry from reappearing. This program has an uninstall entry in the Add or Remove Programs control panel called Multimedia Keyboard Driver.
smoothview SmoothView.exe N TOSHIBA Zooming Utility - allows "automatic" zoom feature in some appications, like IE, MS-Office, WMPlayer, Adobe-Reader and also desktop icons.
spamfighter agent SFAgent.exe U SPAMfighter anti email spam filter
faststart svcnut.exe X Browser hijacker - a variant of the STARTPAGE.L TROJAN!
spyware-cop Spyware-Cop.exe X Spyware-Cop alias SpywareKilla - "Spyware remover" of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites
startwin startwin.exe X Added by the W32.ANTIMAN.A WORM!
Spooler SubSystem App spooIsv.exe X Added by the W32.Linkbot.M worm.
SDK Codre Function22 sdkimddprovment2.exe X Added by the W32/Sdbot-YJ worm. When started this infection connects to an IRC server where it waits for remote commands.
windowsflashbrg sqldata1.exe X Added by a variant of the AGENT-IC TROJAN!
adupdater sysupudt.exe X Unidentified adware downloader/updater
aluria security center SecurityCenter.exe N Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here and here
Web Service soft.exe X Added by the W32/Bube-F virus. This infection also displays popups in Internet Explorer.
windows system backup SysBackup.exe X Unidentified malware
avschedscan SCHSC9X.EXE Y Command antivirus related
sern Sernet32.exe X Added by the Troj/Bancos-CV password-stealing trojan. If you were infected with this trojan you should immediately change all your passwords for your online banking programs.
SunKistEM shwiconem.exe U Used by your computer to communicate with your Alcor_Micro Multimedia Card Reader - necessary if you're using this software
strgsync.exe StrgSync.exe U SimpleTech Inc's StorageSync backup software - backs up an entire PC, or selected files and folders.
faststart svcnut32.exe X Browser hijacker - a variant of the STARTPAGE.L TROJAN!
netservices svchostn.exe X Added by the SDBOT.GI WORM!
netscreen-remote SafeCfg.exe U NetScreen_Remote VPN Client Software
sdk core function2 sdkimprovment2.exe X Added by the W32.SPYBOT.OGX WORM!
serviceconnect serviceconnect.exe X Added by the AGOBOT.AIR WORM!
symantec netdriver warning SNDWarn.exe U Part of Symantec Live Update - displays the warning when you need to update the firewall database.
system csrss patch scrtkfg.exe X Added by a variant of the WIN32.RBOT WORM!
system services svcsenes.exe X Added by a variant of the WIN32.RBOT WORM!
usbhwdrv sst4.exe X Added by a variant of the TROJ/LOWZONE-I TROJAN!
sdktemp SDKTEMP.EXE X Added by the W32/Tilebot-A worm. When started this infection connects to an IRC server where it waits for remote commands.
windows services scmsg.exe X Added by a variant of the W32/SDBOT WORM!
windows system manager loader smsls.exe X Added by the AGOBOT.TF WORM!
wintask dll32 smsrss.exe X Added by the W32.MYTOB.BS WORM!
rp Systry.exe X Added by the Troj/RevPack521 trojan.
Sproc32 sproc32.exe. X Added by the Troj/Rightu-A trojan.
Dll Service Manager. SVSHOST.EXE X Added by the W32/Robot-A backdoor trojan. When started this infection connects to an IRC server where it waits for remote commands.
SYSSRV SYSSRV.EXE X Added by the W32/Rolog-A worm.
system.vbs system.vbs X Added by the RAHACK WORM!
microsoft scvhost for windows scvhost.exe X Added by the W32/Randex-S worm. When started, this infection connects to an IRC server where it waits for remote commands to execute.
Mmsystem Sachiel.sys.bat X Added by the W32/Sachiel-D worm.
MSSVC SVCHOST.EXE X Added by the Troj/Sandor-C backdoor trojan.
Service Manager SERVICEMGR.EXE X Added by the W32/PassMail-D worm.
COMsys32 systemdll32.exe X Added by the Troj/Feutel-F backdoor trojan.
Microsoft uptime Service sysuptime.exe X Added by the W32/Rbot-ACG worm. This worm connects to an IRC server on startup where it waits for remote commands.
27 slsorve.exe X Added by the Troj/Slsorve-A trojan. Using it's own own SMTP engine it sends email to a remote address and will terminate anti-virus related processes.
systemdll32.exe systemdll32.exe X Added by the Troj/Feutel-F backdoor trojan.
Sexnow Sexnow.exe X Added by the Dial/Senow-B premium rate porn dialer.
sm sr_exe.exe X Added by the LUKUSPAM TROJAN!
svsekin svsekt.exe X Added by the TROJAN.PWS.QQPASS.G TROJAN!
browser s_menu.exe X Added by the WIN32.TACTSLAY.C TROJAN!
cpl s_menu.exe X Added by the WIN32.TACTSLAY.C TROJAN!
fdr command module sp2.exe X Added by the SDBOT.WP WORM!
golum services.exe X Added by the GOLUM.A TROJAN! - Note - this services.exe file is placed in a Winnt\System32\Golum or Windows\System32\Golum subdirectory, and should NOT be confused with the legitimate Windows services.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
msn updates spoolsv32.exe X Added by a variant of the WIN32.RBOT WORM!
msofficecfg ssvr.exe X Premium rate adult material dialer
navcheck shman.exe X Adult material premium rate dialer
officeagent svcshost.exe X Added by the WIN32.TACTSLAY.A TROJAN!
quicktime shch.exe X Added by a variant of the TROJ/BDOOR-EB TROJAN!
scheck scheck**.exe X Added as a result of the KETCH VIRUS! where ** represents a number
services.dll smss.exe X Added by the W32/SOBER-L worm. This infection should not be confused with the legitimate C:\Windows\System32\smss.exe.
shell api32 svcnet.exe X Added by the WIN32.TIBICK.C WORM!
smcservice smc.exe Y Sygate Personal Firewall
sos sql database scm.exe N SQL Server Service Control Manager. Available via Start -> Programs
spool loader spool.exe X Added by a variant of the WIN32.RBOT WORM!
spoolsvu SPOOLSVU.EXE X Added by the StartPage.K TROJAN!
ssms.exe SSMS.EXE X Added by the W32.GISMOR WORM!
startup manager scanner StartupMonitor.exe U Startup-Mechanic Startup monitor - offers boot protection of your PC from harmful trojans, adult-dialers, and other scumware.
svchosts.exe svchosts.exe X Added by the W32/AGOBOT-JN WORM!
svhost updates Svhost.exe X Added by a variant of the WIN32.RBOT WORM!
syscon syscon.exe X Added by the W32.APRILCONE.A WORM!
systune systune.exe U Added by AceSpy SPYWARE! ** Treat as an X if it wasn't intentionally installed.
universal usb service svchost32.exe X Added by the W32.KELVIR.R WORM!
windows register settings svmhost.exe X Added by a variant of the W32/FORBOT WORM!
windows system gateway SPOOLER.EXE X Added by a variant of the WIN32.RBOT WORM!
windows update software system.exe X Added by the TOFGER.BX TROJAN!
_winstart services.exe X Added by the W32.SOBER.O WORM! - Note - this file is placed in a "%Windir%\Connection Wizard\Status folder, and should NOT be confused with the legitimate Windows services.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
SystemBoot services.exe X Added by the Sober.Q mass-mailing worm. This worm does not spread itself via email but rather sends out political messages in German or English depending on your email address. Sober.Q infects those machines with the Sober.P infection via an upgrade feature.
_SystemBoot services.exe X Added by the Sober.Q mass-mailing worm. This worm does not spread itself via email but rather sends out political messages in German or English depending on your email address. Sober.Q infects those machines with the Sober.P infection via an upgrade feature.
[not used] svcmgr32.exe.exe X Added by the W32/Oscabot-D worm. When started, this infection connects to an IRC where it waits for remote commands to execute.
WINDOWS SKY sky.exe X Added by the W32/Mytob-CJ worm. This infection when started connects to a remote IRC server where it waits for commands to execute.
adslsystemtray SystemtrayV100B.exe ? Apparently Annex A ADSL modem related - what does it do and is it required?
configuration loader svupdate.exe X Added by the W32.RANDEX.DXP WORM!
fritz!dsl startcenter StCenter.exe ? FRITZ! ISP software "StartCenter" User interface that allows you to manage, tweak and diagnose many aspects of your internet connection - is it required?
generic service process serv1ces.exe X Added by the W32/Agobot-JK WORM!
printer SpyAssaultScanner.exe U SpyAssault keystroke logger/monitoring program - remove unless you installed it yourself!
sac sac.exe X 180Solutions/N-Case adware variant
sbdrvdet sbdrvdet.exe N Detects the "Easy Front-Panel Audio Connectivity Drive Internal Drive Bay" that comes with certain Sound Blaster audio cards.. Can be disabled if you don't use the internal drive bay.
scheduler Scheduler daemon.exe U Tenebril GhostSurf or SpyCatcher related scheduler - you can schedule daily, weekly, monthly or one-time only cleanings.
session client sescli.exe U SurfSpy keystroke logger/monitoring program - remove unless you installed it yourself!
sk51 SK51.EXE U SaveKeys keystroke logger/monitoring program - remove unless you installed it yourself!
sm sf_exe.exe X Added by the OLFEB.A TROJAN!
snd332 snd332.exe X Added by an unidentified WORM!
snippet SnippingTool.exe U The Snipping Tool (part of the Experience_Pack for Tablet PC) allows you to easily "cut out" anything on screen and share it with other people. The whole screen becomes an "inkable" surface that you can add comments to and mark up however you like. You can then save that annotated image to use later, or send it to someone else in an e-mail message.
sountskmanager sountaskmgr X Added by an unidentified WORM or TROJAN!
ssh32 SSh32.exe U 2Spy keystroke logger/monitoring program - remove unless you installed it yourself!
sspy SSYTEM.EXE U SurfingSpy keystroke logger/monitoring program - remove unless you installed it yourself!
bbc news alerts skinkers.exe U BBC News Desktop Alerts service; see here - The BBC News desktop alert and breaking news e-mail services let you find out about all the latest news as it happens.
graphic driver smss32.exe X Added by a variant of the WIN32.RBOT WORM!
microsoft host protocol svhost.exe X Added by a variant of the WIN32.RBOT WORM!
printmngr system.exe X Added by an unidentified TROJAN!
winapplog svchost.exe U StingKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! - NOTE - this file is placed in a C:\Program Files\StingWare folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
secsrvrc secsrvrc.exe X Added by the Troj/SCKeyLog-G keylogger.
Spooler SubSystem App spoolv.exe X Added by the W32/Sdbot-BN backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute. This infection also steals cd keys from popular games and applications.
System-Config spoolv.exe X Added by the W32/Sdbot-Br backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute. This infection also steals cd keys from popular games and applications.
Windows Config for Spool Service SPOOLER32.EXE X Added by the W32/Sdbot-DX backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
Windows SYStry systry.exe X Added by the W32/SdBot-E backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
Microsoft Windows System Kernel Initializer SysInt32.exe X Added by the Troj/Sdbot-EK backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
[random] swpolws.exe X Added by the Troj/Sdbot-ER backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
default splvs.exe X Added by the WORM_SDBOT.FS backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
Microsong svchosts11.exe X Added by the Troj/Sdbot-EV backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
Microsoft DirectX SMSS32.exe X Added by the W32/SDBot-FP worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute. This infection may also listen on TCP port 1550 for commands.
[unknown] SYSCDCFG32.EXE X Added by the W32/SdBot-GI worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
Micosoft Startup systall.exe X Added by the W32/SdBot-GM worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
[unknown] SPOOLVLC.EXE X Added by the W32/Sdbot-HD worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
configuration loader svchost2.exe X Added by the AGOBOT.JR WORM!
microsoft service pack2.1 svchost2.exe X Added by a variant of the WIN32.RBOT WORM!
windows services hosts svhosts.exe X Added by the TROJ/SDBOT-YH TROJAN!
syseq svclgx32.exe X Added by the TROJ/IRCBOT-AC TROJAN!
windows update center svthx.exe X Added by the W32.STUBBOT.A WORM!
Windows Host Service svchoste.exe X Added by the W32/Kelvir-U instant messenger worm. This worm spreads using MSN Messenger.
wsock32 svchost.exe X Added by the Troj/Horst-A keylogging trojan. This infection logs your keystrokes to a file named c:\windows\system32\dll.txt
SysService SERVICES.EXE U Added by the Spyware.NSKeyLogger keylogger. This program has the ability to log keystrokes and capture screenshots. Uninstall if you did not intentionally install this program
Spy-Keylogger skl.exe U Added by the Spyware.SpyKeylogger keylogger. If this was not installed by you, you should uninstall it.
saw saw.exe X Added by the Adware.SmartAdware adware. This software delivers popups advertisements.
sm sm_exe.exe X Added by the OLFEB.A TROJAN! This infection allows spam to be sent through your computer.
sm sa_exe.exe X Added by the OLFEB.A TROJAN! This infection allows spam to be sent through your computer.
switp switpa.exe X Added by the Adware.OfferAgent adware. This program will display popups on your computer.
svnloader svnload32.exe X Added by the W32/Rbot-ACU worm. When started this infection connects to an IRC server where it waits for remote commands.
[unknown name] SRMER32.EXE X Added by the W32/Sdbot-IG worm. When started this infection connects to an IRC server where it waits for remote commands.
Micosoft Startup syscall.exe X Added by the W32/SdBot-JI worm. When started this infection connects to an IRC server where it waits for remote commands.
Micosoftartup shrl.exe X Added by the W32/Sdbot-JQ worm. When started this infection connects to an IRC server where it waits for remote commands.
MicosoftStartup syxall.exe X Added by the W32/Sdbot-JR worm. When started this infection connects to an IRC server where it waits for remote commands.
[unknown name] SERVSYS32.EXE X Added by the W32/Sdbot-KQ worm. When started this infection connects to an IRC server where it waits for remote commands.
Reg_WFT scanreg32.com X Added by the Troj/SennaSpy-F trojan.
hoge svchost.exe X Added by the Uploader-X trojan.
microsoft updates 5 usb sp3fixer.exe X Added by the W32/Rbot-ADS
ms valud loader Svhots.exe X Added by the W32/AGOBOT-SP WORM!
regedit svchost.exe ccRegVfy X Added by the Trojan.Rona
scrsvc scrsvc.exe X Added by the Troj/Agent-DS proxy trojan.
secureclean4regmanager scregmanager4.exe N WhiteCanyon SecureClean_4 disk cleaner - clean hard drive data, MRUs, temp files and more. Can be started manually
secureclean4tray sctray4.exe N WhiteCanyon SecureClean_4 disk cleaner - clean hard drive data, MRUs, temp files and more. Can be started manually
spyware x-terminator SpywareX.exe U Spyware_X-terminator spyware remover
sql server service sql.exe X Added by the W32/Rbot-ADF
sysug32.exe sysug32.exe X Added by an unidentified TROJAN or WORM!
i/o controllers svcnet.exe X Added by the TROJ/TIBIK-B TROJAN!
secretsmileys ss.exe U Secret_Smileys is an add-on for AIM® that provides users access to 1000's of new Smileys that can be viewed by anyone using a current version of AIM. Secret Smileys also adds other features such as logging of IM conversations, and it gets rid of that annoying advertisement on your buddy list window.
svchosts svchosts.exe X Added by the Troj/Bancban-DC
WINTASK scvhost.exe X Added by the W32/Mytob-I mass-mailing worm with IRC backdoor functionality..
System Kernal Support system.exe X Added by the W32/Rbot-ADN worm. When started this infection connects to an IRC server where it waits for remote commands.
Configuration Loader scvhost.exe X Added by the W32/Agobot-AAE worm.
Windows Service Manager svcman.exe X Added by the Troj/Dloader-NY trojan.
Run Services as Application svcrun.exe X Added by the Troj/Dloader-NY trojan.
Services Administrator svcadmin.exe X Added by the Troj/Dloader-NY trojan.
Spooler SubSystem Application spoolsvc.exe X Added by the Troj/Dloader-NY trojan.
Generic Host Process svchost.exe X Added by the Troj/Dloader-NX trojan downloader.
Microsoft DLL Extensions SystemDll.exe X Added by the W32/Rbot-ADV worm. When started this infection connects to an IRC server where it waits for remote commands.
HTML TCP IP system.exe X Added by the Backdoor.Greybird.L trojan backdoor..
WINDOWS SCREENSAVER ssaver.scr X Added by the W32/Sdbot-YZ worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
svchost.exe svchost.exe X Added by the Troj/PWSjx-A password stealing trojan. This infections attempts to steal your password for the game MuYangJX.
Microsoft Update scvhost.exe X Added by the W32/Rbot-AEM worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Sysman Sysman.exe U Added by the Spyware.KeyTrap keystroke logger. If you did not install this on your machine then you should remove it.
syspw32.exe syspw32.exe X Added by the W32.Appflet.A@mm mass-mailing worm.
Windows Service Controller services.exe X Added by the W32/Kalel-B mass-mailing worm and backdoor Trojan. Note: This file should not be confused with the legitimate %WinDir%System32services.exe.
swclient swsys.exe U ActivMonAgent Keyboard logger/monitoring program - remove unless you installed it yourself!
windows session manager subsystem smss.exe X Added by the W32/Kalel-B worm. This infection should not be confused with the legitimate C:\Windows\System32\smss.exe.
Coordinator System svchoct.exe X Added by the Troj/Sdbot-LI worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Synchronization Manager svchosts.exe X Added by the W32/Sdbot-LM worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
inet svhost.exe X Added by the Troj/Sdbot-M worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Backup One smbguard.exe X Added by the W32/Sdbot-MI worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
System Information Manager syspass.exe X Added by the W32/Sdbot-MO worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
SurfSideKick 3 Ssk.exe X Added by the Adware.SurfSideKick adware.
System32 Temp Service systmp.exe X Added by the W32/Rbot-AET worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
msn.exe son.exe X Added by the Troj/StartPa-GS trojan.
servics servics.exe X Added by the Troj/Singu-J password stealing backdoor trojan.
swingsys SWINGSYS.EXE X Added by the Troj/Bancos-CX trojan.
Microsoft IIS syshost.exe X Added by the W32/Francette-S worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
services svchosts.exe X Added by the Troj/Sdbot-N worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Laptop Access Sage.exe X Added by the W32/Sdbot-NB worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Com Port Manager svdhost.exe X Added by the W32/Sdbot-NI worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
System Updater sys.exe X Added by the W32/Sdbot-NK worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Windows Services Sersices.exe X Added by the W32/Sdbot-NO worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Configuration Loader SVSCHOST.EXE X Added by the W32/Sdbot-NS worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
ICQ syscdd2.exe X Added by the W32/Sdbot-ON worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
NT Logging Service sysmgr.exe X Added by the W32/Sdbot-OO worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
System Configurator systemconfig.exe X Added by the W32/Sdbot-OR worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
sload sload32.exe X Added by the W32/Sdbot-OY worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
System Services svcsenes32a.exe X Added by the W32/Rbot-AFGworm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
MSWindowsUpdate Systern.exe X Added by the W32/Rbot-AFDworm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
gqvqevs seeffkme.exe X Added by the W32/Sdbot-QDworm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
smsrv smsrv.exe X Added by the W32/Agobot-SX worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
System Configuration syscfg32.exe X Added by the W32/Mytob-AS worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
WINDOWS SYSTEM skybot.exe X Added by the W32.Mytob.EB@mm mass-mailing worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
SVCH0ST SVCH0ST.EXE X Added by the Troj/Lors-A trojan.
MainStart svcmfte32.exe X Added by the Troj/Stinx-A IRC backdoor.
WSVCS SERVICES.EXE U Added by the Spyware.WALogge surveillance program. If you did not install this program on your computer then it should be removed.
Windows Update Service SP00ISS.exe X Added by the W32/Sdbot-ZH worm. When started, this infection will connect to a remote IRC server and wait for commands to execute.
genserv path sdqdqg.exe X Added by the W32/Sdbot-RF worm. When started, this infection will connect to a remote IRC server and wait for commands to execute.
vccacA sdaxzl.exe X Added by the W32/Sdbot-RP worm. When started, this infection will connect to a remote IRC server and wait for commands to execute.
CTHELPER svhost.exe X Added by the W32/Sdbot-RZ worm. When started, this infection will connect to a remote IRC server and wait for commands to execute.
scoupa sincra.exe X Added by the W32/Sdbot-ST worm. When started, this infection will connect to a remote IRC server and wait for commands to execute.
secure svshost.exe X Added by the W32/Rbot-AFO worm. When started, this infection connects to a remote IRC server and waits for commands to execute.
[not used] setup32.exe X Added by the W32/Rbot-AFJ worm. When started, this infection connects to a remote IRC server and waits for commands to execute.
Microsoft« ActiveX Debugger NT setdebugnt.exe X Added by the Troj/Bancos-CZ Internet banking trojan. This infection targets Brazilian banks.
Anti Spam Service spamsvc.exe X Added by the W32/Mytob-BK worm. When started, this infection connects to a remote IRC server and waits for commands to execute.
Services Process smss.exe X Added by the Troj/Small-EK backdoor trojan.
Rwx svhosts.exe X Added by the Troj/Subzero-B trojan.
smsm smsm.exe X Added by the Troj/Banker-CO trojan. This infection attempts to steal information about your online banking.
System32 PCI Manager syspci32.exe X Added by the W32/Rbot-AFR worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
windows spoolsrv service spoolssv.exe X Added by the W32/Sdbot-AWV worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
Microsoft Session Manager Subsystem smss.exe X Added by the W32.Kalel.B@mm mass-mailing worm. This infection should not be confused with the legitimate C:\Windows\System32\smss.exe.
Microsoft Service Controller services.exe X Added by the W32.Kalel.B@mm mass-mailing worm. Be careful that you do not delete the legitimate file c:\windows\system32\services.exe.
regrun sory.exe X New Purityscan Variant
sks-32 sks32proc.exe U Added by the Spyware.SpyKeySpy surveillance software. If you did not install this software you should remove it immediately.
svrpcn.exe svrrec.exe U Added by the Spyware.Recon surveillance software. If you did not install this software you should remove it immediately.
Windows System skybotx.exe X Added by the W32.Mytob.FO@mm worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
sds20 svchost.exe U Added by the Spyware.InlookExpress surveillance software. If you did not install this software, then you should uninstall it immediately.
System Mld sysmlds.exe U See Here.
WinMessenger syshost.exe X Added by the W32/Opanki-E worm and IRC backdoor.
WINDOWS SYSTEM smsc.exe X Added by the W32/Mytob-BR worm. When started, this infection connects to a remote IRC server and waits for commands to execute.
Remote Administrator Service systemram.exe X Added by the Troj/Radnag-B backdoor trojan.
System DLL Resources sysdll.exe U Added by the Spyware.SnapKey surveillance software. If you did not install this you should uninstall it.
SpySheriff SpySheriff.exe X Rogue antispyware application. Should be uninstalled due to its false positives and sneaky way of installing.
AUDIO SOUND.exe X Added by the Dial/Ployb-A premium porn dialer.
Windows Spoolsrv Service spoolmsv.exe X Added by the W32/Sdbot-ZS worm. When started, this infection connects to a remote IRC server and waits for commands to execute.
Windows SpoolPrint Service spoolersrv.exe X Added by the W32/Sdbot-ZT worm. When started, this infection connects to a remote IRC server and waits for commands to execute.
smail smail.exe X Added by the W32/Sexer-C email worm.
INF0 SEXSPEED.EXE X Added by the Troj/Sexspeed trojan.
Registry ShakiraPics.jpg.vbs X Added by the VBS.VBSWG.AQ@mm worm.
Print Spooler spool.exe X Added by the Troj/Bdoor-IS backdoor trojan.
stchost.exe stchost.exe X Added by the Troj/Vixup-D trojan.
Windows SpooltPrint Service spooltsrv.exe X Added by the W32/Sdbot-AYE worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
Windows System Manager sysconf.exe X Added by the W32.Mytob.AL@mm worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
WINDOWS SYSTEM smoc.exe X Added by the W32.Mytob.FU@mm worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Windows Driver Adapter svchost.exe X Added by the W32/Antinny-K backdoor/worm.
Microsoft Synchronization Manager svxhost.exe X Added by the W32/Sdbot-ZU worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
sys009 sys009.exe X Added by the Troj/StartPa-ZB trojan.
Crnsava scrnsave.pif X Added by the W32/Sdbot-ZV worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
MSRegScan SGP.exe U Added by the Spyware.SpyGator surveillance program. If you did not install this program, you should uninstall it immediately.
Track4WinMonitor STMonitor.exe U Added by the Spyware.Track4Win surveillance program. If you did not install this program, you should uninstall it immediately.
Windows Host Service svchosts32.exe X Added by the W32/Kelvir-AK MSN messenger worm.
Windows SpoolaPrint Service spoolasrv.exe X Added by the W32/Sdbot-AYD worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
System svchost.EXE X Added by the Troj/Bckdr-CST backdoor trojan.
Service Process service.exe X Added by the Troj/Dcmbot-C backdoor trojan.
System Support syscfg.exe X Added by the W32/Rbot-AGQ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
KAVPersonal svchost.exe X Added by the Troj/Lineage-V password-stealing trojan for the online game Lineage.
System svchîst.exe X Added by the Troj/LdPinch-BF password-stealing trojan.
Screen Saver scrnsaver.scr X Added by the W32/Rbot-AGP worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
MS Screen Saver scrsave.scr X Added by the W32/Rbot-AGT worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Snoop Snoop.exe U Added by the Spyware.Snoop surveillance program. You should uninstall this program immediately if you did not install it yourself.
SACC sacc.exe X Added by the Adware.SurfAccuracy adware.
Session Manager Subsystem smssa.exe X Added by the W32/Rbot-AGS worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
SVCH0ST spoo1sv.exe X Added by the Troj/VB-HF trojan.
Mp3 Loader Sysdata.EXE X Added by the W32/Avette-A MP3 virus.
Auto Updates svchost.exe X Added by the Troj/Cheuko-A trojan.
Windows Spoolsurf Service spoolsurf.exe X Added by the W32/Sdbot-ZZ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
DrefIW SysDrefIWv2.exe X Added by the W32/Dref-C Internet worm.
firefox service drivers ssmss.exe X Added by a variant of the W32/SDBOT WORM!
internet suspention story.exe X Added by the WOOTBOT.HV WORM!
microsoft system update sysupdate.exe X Added by the SDBOT.DG WORM!
scheck45 scheck45.exe X Related to unknown Malware - hidden installer associated with it
secsvc32 secsvcnt.exe X Added by the Global_Patrol TROJAN!
sfpc sfpc.exe U Spy4PC is a spyware program that monitors user activity, logs keystrokes, and takes screenshots. If you didn't install this yourself remove it.
spyware shield Shield.exe U Acronis Privacy Expert Spyware_Shield prevents spyware and other suspicious programs from being installed on desktop PCs and laptops.
sys201 sys209.exe X Added by the Troj/StartPa-ZY
sysman Sysman U KeyTrap is a spyware program that records all keyboard activities. If you didn't install it yourself remove it.
sysmonnt sysmonnt.exe X SearchPounder sends keywords typed into HTML forms and popular Internet search engines to a remote server
system event manager secsvc.exe X Added by the RBOT.BMY WORM!
system32 tcp manager systcpm.exe X Added by a variant of the WIN32.RBOT WORM!
systemfile SystemFile.exe X Added by the Troj/Dulldoor-A
System Support system32.exe X Added by the W32/Rbot-AHA worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
DriverCheck svchost.exe X Added by the Troj/Delf-KR trojan.
RPCserv32g services.exe X Added by the W32.Bobax.AA mass-mailing worm.
Windows Updata Server server.exe X Added by the Backdoor.Graybird.N backdoor.
Shell Tray Window ShellTraywnd.exe X Added by the Troj/Stultdor-A backdoor trojan.
Windows Spoolsre Service spoolsre.exe X Added by the W32/Sdbot-AAE worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
zsmss smss.exe X Added by the Troj/Bancos-DD trojan.
Microsoft Support sys32ms.exe X Added by the W32/Rbot-AHI worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
svcmon svcmon.exe U Added by the Spyware.PersonInspect surveillance software. Uninstall this software if it was not installed by yourself.
sbss Launcher sbss.exe X Added by the Adware.SideBySide search hijacker to sidebysidesearch.com.
SNSS.EXE SNSS.EXE X Added by the Dialer.Nunci premium dialer.
Connector SYS.EXE X Added by the Dialer.Nunci premium dialer.
svchosts.scr svchosts.scr X Added by the Troj/Bancban-DQ password-stealing trojan.
starter scvhostingg.exe X Added by the W32/Forbot-FB worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
SetPoint SetPoint.exe X Added by the W32/Rbot-BWI worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
spoolsv service spoolsv32.exe X Added by the W32/Rbot-AHP worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
ctfnom.exe SVOHOST.exe X Added by the Troj/Digidor-A trojan.
ShowFF ShowFF.exe X Added by the Adware.FFToolBar adware toolbar.
[not used] svhost32.exe X Added by the Troj/Lineage-AB trojan.
Registry Value Name service.exe X Added by the W32/Rbot-AHT worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
service manager service.exe X Added by the Trojan.Spexta trojan. When infected your computer will become an open mail relay which will allow your computer to be used to send out spam.
scvhost scvhost.exe U Added by the Spyware.Wiretap surveillance software. Uninstall this software if you did not install it yourself.
syspare syspare.exe X Added by the Troj/Bifrose-AN Trojan.
System serwin.exe X Added by the Troj/LdPinch-BN password-stealing and backdoor trojan.
Wind0ws Sharing ssprotecter.exe X Added by the W32/Rbot-AHW worm. When infected your computer will become an open mail relay which will allow your computer to be used to send out spam.
srvprc srvprc.exe U Added by the Spyware.ActMon surveillance software. Uninstall this software if it was not installed by yourself.
Windows spoolservr Service spoolservr.exe X Added by the W32/Sdbot-AAN worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
Universal Serial Bus Control Protocol smrs.exe X Added by the Troj/Bdoor-JD backdoor Trojan.
Microsoft uptime Service sycuptime.exe X Added by the W32/Rbot-AHY worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
Micrcoft Updat spoolsae.exe X Added by the W32/Rbot-AIB worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
sxrrv sxrrv.pif X Added by the Troj/Vax-A trojan.
Win32 Driver svchosts.exe X Added by the W32/Forbot-FD worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
Fast Start svcnt.exe X Identified by numerous Antivirus products as Delf.KS. When run this trojan will install a variety of other applications such as antivirus gold, ps guard, hookdump.exe, intel32.exe etc. All of these files are malware and should be removed.
*security center secctr.exe X Added by the SDBOT.BRO WORM!
elnkproxy smproxy.exe X Surfmonkey adware
game shit.exe X Added by the Netclap Gold backdoor TROJAN!
snbupt snbupt.exe X UpSpiralBar adware component
smt SMT.exe U Win-Spy keyboard logger/monitoring software - remove unless you installed it yourself!
sks-32 SKS32P~1.EXE X SpyKeySpy logs keystrokes and sends the stolen information to a configurable email address.
sload sload.exe X Win SynchroAd adware, also detected as TROJ/DLOADER-QG TROJAN!
ipconfig svcxnw32.exe X Added by a variant of the HACARMY.E TROJAN!
mascro soft sdk updates2 SDKrepair2.exe X Added by a variant of the W32/SDBOT.W WORM!
microsoft update machine serviz.exe X Added by a variant of the WIN32.RBOT WORM!
sdtray sdtray.exe U RSA Keon Web_PassPort - software that allows organizations to use digital certificates in a Web-based environment to help ensure that their transactions are authentic, confidential and digitally signed.
scandisc satan.exe X Added by the GregStar backdoor TROJAN!
sdk core function sdkimprovment.exe X Added by the RBOT.BHL WORM!
windowsagent sysexhook.exe X Added by the GOP keyboard logger/TROJAN!
rpc win32 spoolscv.exe X Added by a variant of the WIN32.RBOT WORM!
sam-sung Sam-sung.exe X Added by a variant of the W32/SDBOT WORM!
samsong Samsong.exe X Added by the SDBOT.BNE WORM!
spyblocs3.0 SpyBlocs3.0.exe X Rogue anti-spyware program.
starskin starskin.exe U StarSkin allows you to change the view and appearance of your Windows XP box with the use of publically available themes.
stisrv stisrv.exe X Added by the RBOT.BQF WORM!
subah SubAH.exe X Added by the SubAH backdoor TROJAN!
sysdat.dll sysdat.dll.exe X Added by the Nishica 1.1 backdoor TROJAN!
system service helper svchelper.exe X Added by the W32/MONKBD-A WORM!
windows bootup Systemwks32.exe X Added by a variant of the WIN32.RBOT WORM!
wupd symcsvc.exe X Adware downloader/installer, CoolWebSearch parasite related
svctask svctask.exe X Added by the Troj/Chuckyb-A backdoor trojan.
SystemDriverLoad svchost.exe X Added by the Troj/Delf-KR trojan.
SystemDriverCheck svchost.exe X Added by the Troj/Delf-KR trojan.
SystemCheck svchost.exe X Added by the Troj/Delf-KR trojan.
microsoft windows updata scvhost.exe X Added by a variant of the WIN32.RBOT WORM!
msnager32 svchostt.exe X Added by the WOMANIZ.E TROJAN!
smsslevel4 smss.exe X Unidentified malware. This infection should not be confused with the legitimate C:\Windows\System32\smss.exe.
spolsvr2 spolsvr2.exe X Added by the Win32/Evilsock.10 TROJAN! - NOTE: this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot. Name field may be empty.
spool loadkit spoolv.exe X Added by a variant of the WIN32.RBOT WORM!
spoolvs spoolvs.exe X Added by the SDBOT.AUS WORM!
surfaccuracy sacc.exe X SurfAccuracy adware
wnddrv svchost.exe X Aded by an unidentified TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
System system.exe X Added by the W32/VB-IU worm.
reg2.0 SVCH0ST.EXE U Added by the Spyware.eSpyNow surveillance software. Uninstall this software if it was not installed by yourself.
Windows Logon Application services.exe X Added by the Troj/Ciadoor-L trojan.
erthgdr svc.exe X Added by the W32.Beagle.BW@mm worm.
sau sau.exe X Added by the Adware.180Search adware.
Auto Update svchost.exe X Added by the Troj/DumarDl-A trojan.
Windows System32 Kernel system32.exe X Added by the W32/Sdbot-AAT worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Registro svchostt.exe X Added by the Troj/Bancos-DH password-stealing trojan. If you are infected with this infection you should change any online banking passwords.
SWL SWL.dll U Added by the Spyware.StealthWeblog surveillance software. Uninstall this software if it was not installed by yourself.
internet smss.exe X Added by the Troj/Mifeng-B password-stealing trojan.
Windows Spoolvvv Service spoolvvv.exe X Added by the W32/Sdbot-AAW worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
System Host Manager syshost.exe X Added by the W32/Banworm-C worm.
Modulo 00FE0F01 Host Internet syschost.exe X Added by the Troj/Delf-KW backdoor Trojan.
SOUNDMAN Microsoft Help soun.pif X Added by the W32/Rbot-AIU worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
sysX3 sys22.exe X Added by the W32.Rants.C@mm mass-mailing worm.
SVKP SVKP.sys Y Svkp.sys is a clean driver used in anticracking software & several legitimate programs. Disabling this software will cause the legitimate programs to no longer work. Unfortunately, this driver can also be installed by malware that is packed by it, so it should be judged on case by case basis. Please ask in the forums if you are unsure.
Onlune Sarvice sachost.exe X Added by the Troj/Multidr-E Trojan.
Perfomance Settings svchost.exe X Added by the Troj/Tofger-AP backdoor Trojan.
Spooler Subsystem spoolsub.exe X Added by the W32/Sdbot-ABG worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft ActiveX Debugger NT setdebugnt.exe X Added by the Troj/Bancos- Trojan. If you are infected with this infection you should immediately change all passwords to any online banking sites that you use.
spoolsvs.exe spoolsvs.exe X Added by the Troj/Dloader-RK downloader Trojan.
Micrcoft Updat spoolsaex.exe X Added by the W32/Rbot-AJM worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windows Explorer system32.exe X Added by the W32/Rbot-AJH worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
MicrosoftSys SPOOLSYS.exe X Added by the PWSteal.Tarno.N password-stealing Trojan.
start it upping svchosets.exe X Added by a variant of the WIN32.RBOT WORM!
speedswitchxp SpeedswitchXP.exe U SpeedswitchXP is a CPU frequency control for notebooks running Windows XP
specific specixic.exe X Added by a variant of the W32/SDBOT WORM!
sp2connpatcher sp2connpatcher.exe ? Unidentified - possibly part of the "Warez" P2P client software what does it do and is it required?
softstuff wallpaper changer softstrt.exe U AzureBay wallpaper changer
sp2 connection patcher SP2ConnPatcher.exe U Changes limit of concurrent TCP connections of Windows Service Pack 2.
gate personal firewall Systpl.exe X Added by the RBOT.ADC worm. This is not the same file created by the developer Tlapia.
sk60 SK60.EXE U Added by the SaveKeys surveillance software. Uninstall this software unless you put it there yourself.
services socks.exe X Added by the WIN32.SMALL.N Proxy TROJAN! - A PT is a backdoor trojan which allows a remote hacker to connect to other systems via the compromised system.
service32 service32.exe X Added by the W32/AGOBOT-ST WORM!
scanpanel ScnPanel.exe ? Trust Easy_Webscan scanner related - what does it do and is it required?
internet service ssvhost.exe X Added by a variant of the WIN32.RBOT WORM!
scain s030109.Stub.exe X Adware downloader/installer, Delphin_Media_Viewer related - also detected as the DELMED.A TROJAN!
iolo utility bar SMUtilityBar.exe N Iolo "System Mechanic" Utility_Bar - can be launched manually.
kernel services service32.exe X Added by the TROJ/PRX-B TROJAN!
sunprotectionserver SunProtectionServer.exe U CounterSpy antispyware software
sunserver SunServer.exe U CounterSpy antispyware software
switcher.exe Switcher.exe U Sony VAIO Wireless Switch Setting Utility. This program allows you to use a switch to activate and deactivate the wireless lan or bluetooth adapter.
system system23.exe X Added by the W32/Lebreat-D
windows reg services ssservice.exe X Added by the TROJ/PRORAT-D TROJAN
aupd symcsvc.exe X Added by the Troj/Orse-E Trojan.
svchost svchost.exe X Added by the Adware.2Search spyware/adware.
System service system.exe X Added by the PWSteal.Bancos.AA password-stealing Trojan.
steam steam.exe X Added by the W32/Rbot-AJT worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Windows Xp Service Pack 2 svchost.exe X Added by the Troj/Xplos-A backdoor Trojan.
system32 system32.exe X Added by the Troj/Graybird-G Trojan.
System Service servicent.exe X Added by the W32/Rbot-AJI worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
sys32 sysx32.exe X Added by the W32/Kvex-A virus.
Connector sms.EXE X Added by the Dial/ExDial-B premium rate porn dialer.
sp2update sp2update.exe X Added by the Adware.SP2Update adware and spyware.
MyVBApp SysNT.exe X Added by the Adware.ReferAd adware.
SurfSideKick Ssk.exe X Added by the Adware.SurfSideKick adware.
ControlPanel svcc.exe X Added by the Adware.WorldSearch browser hijacker.
Service Sequence services32.exe X Added by the W32/Tilebot-C worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Events services.exe X Added by the Backdoor.EggHead backdoor.
svchost svchost.exe X Added as part of a new potential CWS infection. This program is part of a suite of programs that installs a web server, php, ftp server, socks, and mail server on your computer without your knowledge.

These files are known to be part of an infection that transmits information about your bank accounts, passwords, and other financial information. It should be deleted immediately and you should enable your firewall.

The shttps directory should be removed in its entirety from safe mode and then you should contact your financial services and report the issue and have passwords changed.
Sysctl Desktop Handler systr.dll X This file will hijack Internet Explorer to show the start page of jimbutt.com or globolook.com.
STOPzilla Service SZServer.exe U Part of STOPzilla.
[not used] svchsot.exe X Added by the Troj/GWGhost-N Trojan.
reseurce svchost.exe X Added by the Troj/Lineage-AI password-stealing Trojan for the online game Lineage. This infection should be confused with the legitimate file found at C:\Windows\System32\svchost.exe.
Personal Computer scvhost.exe X Added by the W32/Rbot-AJE worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Microsoftf DDEs Control soff.pif X Added by the W32/Rbot-AKH worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Sysnet sysnet.exe X Added by the Trojan.Cmapp Trojan.
erthgdr2 svc23.exe X Added by the W32.Beagle.CE@mm mass-mailing worm.
Micrcoft Exploerer spoolsal.exe X Added by the W32/Rbot-AKK worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
System Messenger Service smsc.exe X Added by the W32/Tilebot-F worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
WIN32 Sound Drivers. sounddv.exe X Added by the W32/Tilebot-Z worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Microsoft New Game 2 svehost32.exe X Added by the W32/Tilebot-I worm.
NTSet32 services.exe X Added by the Troj/WinSpy-C Trojan.
WindowsService service.exe X Added by the W32/Tilebot-K worm.
server system.exe X Added by the Troj/Meths-A Trojan.
sfool.exe sfool.exe X Added by the W32.Randex.EUS worm.
MS Software Generic Host Process for Win32 Services svchost.exe U Added by the Spyware.AdvancedKey surveillance software. This software should be uninstalled if it was not installed by yourself. Note: This is not the legitimate svchost.exe file found in the Windows system32 directory.
shdde shdde.exe X Added by the Backdoor.Masteseq backdoor.
System Monitor ssys.exe U STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes, all passwords transacted even if they weren't keyed in, all web sites visited, every program launched including the path to that program, and more". This software should be uninstalled if it was not installed by yourself.
Compaq Networks svchost.exe X Added by the Backdoor.XTS.B backdoor. Note: This is not the legitimate svchost.exe found in the Windows system32 directory.
Event Monitor spoolcll.exe X Added by the W32.Spybot.IVQ worm.
SuperHeissSex SuperHiessSex.exe X Added by the Dialer.HeissSex premium adult dialer.
[Various Names] Svchost.exe X Added by the W32.Welchia.K worm.
Windows Desktop Security svcagnt.exe U Added by the Spyware.DesktopScout surveillance software. Uninstall this software if it was not installed by yourself.
NetBios Ext services.exe X Added by the W32.Mydoom.AB@mm worm. Note: This should not be confused with the legitimate windows file, services.exe, found in the Windows System32 folder.
srxtray srxTray.exe N Titan FTP Server - FTP server
changeicon SPMSMON.EXE U Card reader related program. Note: May cause problems with My Computer loading at startup. Disabling through MsConfig seems to solve the problem.
ieaccess surfya.exe X IEAccess premium rate adult content dialer variant
nwss Sp0.exe U Added by the SpyOutside surveillance software. Uninstall this software unless you put it there yourself.
protect SHVRTF.EXE U PC_Angel takes a 5-second snapshot of the current system registry each time the PC boots up. In the event of a crash, PC ANGEL will retrieve everything up to the minute before the crash or the last known stable registry.
secserv.exe secserv.exe X Reported by Panda as an EasySearch Adware variant. Note: EasySearch modifies the Internet Explorer settings and may download programs onto the infected computer.
SigmatelSysTrayApp stsystra.exe N System tray program for the Sigmatel Audio sound card. Often found on Dell computers.
svnlitup32 svnlitup32.exe X Added by the RBOT.CBJ WORM!
system redirect sysbho.exe X Downloader trojan, "Melkosoft" adware related
Microsoft SSL ssl.exe X Added by the W32/Cuebot-D worm.
NetBios Ext32 services.exe X Added by the W32.Mydoom.AN@mm worm.
change me please sysdat.exe X Added by the W32/Tilebot-L worm.
sysmod sysmod.exe X Added by the W32/Spybot-DU worm.
DrefIW SysDref.exe X Added by the W32/Dref-D worm.
[not used] STFU.exe X Added by the W32/Rirc-E worm and IRC backdoor.
IE6 ssmss.exe X Added by the W32.Gaobot.DXO worm.
internew system.exe X Added by the Troj/Cmjspy-BN backdoor Trojan.
System Update Service system.pif X Added by the W32/Rbot-ALL worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Microsoft Synchronization Manager screen.exe X Added by the W32/Sdbot-ACO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
MicroedSoft Toolbar Smoked.exe X Added by the W32/Rbot-ALN worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
MStask svchost.exe X Added by the Troj/LdPinch-BV password-stealing Trojan.
System Server smss.exe X Added by the Troj/Feutel-T backdoor Trojan. This should not be confused with the legitimate file found in the Windows system directory.
SysConnect sysconnect.dll X Added by the Trojan.Sconato Trojan.
SvcSys svcsys.dll X Added by the PWSteal.Bancos.Y password-stealing Trojan.
System ssmc.dll X Added by the Backdoor.Berbew.R Trojan.
Reload Browse svchosts.dll X Added by the Adware.TopAV which replaces the Windows wallpaper with a fake virus alert message containing links to topantivirus.biz or Spyaxe and issues fake virus alerts.
OLE Module smp.dll X Added by the Trojan.SpBot Trojan.
Network Security secsvc.exe X Added by the W32/Rbot-ALX worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Microft Exploerer spoolsac.exe X Added by the W32/Rbot-AMD worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
(Default) Systrsy.exe X Added by the Trojan.Cdtray Trojan which causes your cd tray to open and close repeatedly.
Secret Secret.exe X Added by the Troj/Delf-LW Trojan. This infection will attempt to delete every file on your computer.
syslnfo.hlp svchost.exe X Added by the Troj/Aolog-A keylogging Trojan.
image transfer SonyTray.exe N Sony Image Transfer software provides direct image transfer from your digital camera to a PC - can be started manually.
sahbundle shop1003.exe X ShopAtHomeSelect adware
sbmpop SBMPop.exe X SearchByMedia adware
service pack dll runtime spdll32.exe X Added by a variant of the WIN32.RBOT WORM!
sis7012utility SiSAudUt.exe Y SiS Corporation sound card driver
spam blocker for outlook express SBInst.exe X HotBar related
start page svcnt32.exe X Homepage hijacker, also detected as Trojan-Downloader.Win32.Delf.ks
superheisssex SuperHeissSex.exe X Added by the HeissSex premium rate adult content dialer!
svclhost svcchost.exe X Added by an unidentified WORM or TROJAN!
sysug32.exe sysug32.ex X Added by an unidentified TROJAN or WORM!
Windows Spool Server spoolsrv.exe X Added by the W32/Sdbot-ACT worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
useful-soft svchst.exe X Added by the Troj/StartPa-H Internet Explorer start page hijacker.
Instance 001 sys[randomnumbers].exe X Added by the W32/Alasrou-A email address harvesting worm. When installed it also created the files %Temp%file1.exe and %System%searchpage.htm.
VMWare Authorization Servicec Server.exe X Added by the Backdoor.Graybird.O backdoor Trojan. This infection also drops the file %System%8g.DLL.
SAVScan SAVScan.exe Y This process is part of the real-time scanning engine for Norton Antivirus and associated products.
SymTray - Norton SystemWorks Symtrdr.exe N The tray icon for Norton System Works to keep all icons related to the various programs included in System Works in one place.
WINDOWS SYSTEM servises.exe X Added by the W32/Zotob-I worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
services32.exe services32.exe X Added by the W32/Forbot-FN worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Microsoft Windows system.exe X Added by the W32/Rbot-AMQ worm and IRC backdoor.
stealth.exe stealth.exe X Added by the W32.Theals.A@mm mass-mailing worm.
stealth.dcom.exe stealth.dcom.exe X Added by the W32.Theals.A@mm mass-mailing worm.
stealth.ddos.exe stealth.ddos.exe X Added by the W32.Theals.A@mm mass-mailing worm.
stealth.injector.exe stealth.injector.exe X Added by the W32.Theals.A@mm mass-mailing worm.
stealth.stat.exe stealth.stat.exe X Added by the W32.Theals.A@mm mass-mailing worm.
stealth.wm.exe stealth.wm.exe X Added by the W32.Theals.A@mm mass-mailing worm.
Print Spool Handler spooler.exe X Added by the W32/Codbot-X worm.
shell update shellexec.exe X Added by the W32/Rbot-ANC worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Services Host svchost32.exe X Added by the W32/Agobot-TG worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
system configure svchost.exe X Added by the Troj/Lineage-C password-stealing Trojan for the online game Lineage.
Hwp system_wc.exe X Added by the Adware.Eziin homepage hijacker.
WIN32WN system_wc.exe X Added by the Adware.Eziin homepage hijacker.
Win32 Svchosts Driver svchosts.exe X Added by the W32/Forbot-FO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
NortonVPlus svchost.exe X Added by the Troj/Roamer-A Trojan.
System Management Service smsc.exe X Added by the W32/Rbot-ANN worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Windows Kernel svchost.exe X Added by the W32/Rbot-ANO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. Note: This should not be confused with the legitimate svchost.exe file in the Windows system folder.
SVCHOST SERVlCES.EXE X Added by the Troj/Delf-LF backdoor Trojan.
WINDOWS SYSTEM servce.exe X Added by the W32/Mytob-EI worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Microsoft sdk temp sdktemp.exe X Added by the W32/Rbot-ANP worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
[not used] svcroot.exe X Added by the Troj/Heles-B keylogger Trojan.
(default) syspol.exe X Added by the Troj/Dremn-B keylogging Trojan.
Microsoft Security Center savservices.exe X Added by the W32/Rbot-ANU worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
Gestionnaire de disques universel sysoobe.exe X Added by the Troj/Toader-A backdoor Trojan.
DirectX shell driver sammp32.exe X Added by the Troj/MarktMan-B Trojan.
DNS Server svchost.exe X Added by the Troj/Feutel-Y backdoor Trojab.
SVC Module svchost.exe X Added by the W32/Sdbot-ADG worm. This file should not be confused with the legitimate Windows file of the same name located in the Windows %System% folder.
Windows Update 32 slsys.exe X Added by the W32/Forbot-FT worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
apyginapygin simenu.exe X Added by the SDBOT.BTR WORM!
aupd sysvcs.exe X Added by the ABWIZ.C TROJAN!
fast search svcnv.exe X Homepage, Startpage hijacker. Possible variant of Trojan-Downloader.Win32.Delf
hollaback slvhosts.exe X Added by the SDBOT.BMO WORM!
microsoft intrenet explorer Soundsyst.exe X Added by a variant of the WIN32.RBOT WORM!
microsoft update 64 bit schvost.exe X Added by the RBOT.CAU WORM!
microsoft windows updater suvhost.exe X Added by a variant of the W32/SDBOT WORM!
monitorsd SDMonitor.exe U Max Spyware Detector
pc dynamics sdwmon32 sdwmon32.exe U SafeHouse "Personal Privacy" protects and hides your private and personal photos, videos, files and folders by making them "invisible" and encrypted.
proteção de tela ssmaze.scr X Added by the BANCBAN-FB TROJAN!
run windows servic.bat X Added by the REBOOT-AP TROJAN!
safehousesystemtray SDWTRAY.EXE U SafeHouse "Personal Privacy" system tray icon - PP protects and hides your private and personal photos, videos, files and folders by making them "invisible" and encrypted.
sakemsneql simenu.exe X Added by the SDBOT.BTO WORM!
spytrooper SpyTrooper.exe X SpyTrooper, malware, posing as a spyware remover - alse see here
sysmngr32 sys64mnger.exe X Added by a variant of the WIN32.RBOT WORM!
systemtraysd SDSystemTray.exe U Spyware Detector, Adware/Spyware remover. The latest version has been significantly improved since older versions thus having it removed from Spyware Warrior's rogue anti-spyware list. See note: here
upgrade sarvice sxchost.exe X Added by a variant of the TROJ/TOFGER-I TROJAN!
wind logd file servicelogd.exe X Added by a variant of the WIN32.RBOT WORM!
windows system security sys32.pif X Added by the W32/Rbot-AOL
winssystem syssmss.exe X Added by the BKDR_DELF.IG TROJAN!
WINDOWS SYSTEMn servicces.exe X Added by the W32/Mytob-EL worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
[not used] svchsto.exe X Added by the Troj/GWGhost-R information stealing Trojan.
Microsoft Windows Update scrhost.exe X Added by the W32/Rbot-AOW worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
SvcHost svchost32.exe X Added by the W32/Agobot-TM worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
System Service servicez.exe X Added by the W32/Rbot-AOY worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Torjan Program services.exe X Added by the W32.Autex.C shared folder/drive worm. This should not be confused with the legitimate Microsoft file located in the Windows %System% folder.
Win Update SysUpdate.exe X Added by the W32/Agobot-TN worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
svchostdll.scr svchostdll.scr X Added by the Troj/Bancban-FM password-stealing Trojan of certain bank web sites.
spsvc spsvc.exe U Added by the Hacktool.Spagent surveillance tool. If you did not install this software it should be removed.
Services services.exe X Added by the W32.Mydoom.CI@mm mass-mailing worm.
microsoft windows update sccvhost.exe X Added by a variant of the W32/SDBOT WORM!
spyware cleaner SpywareCleaner.Exe X "Spyware remover" of dubious repute - see the SpywareWarrior_List of Rogue/Suspect Anti-Spyware Products & Web Sites
stefanie SteFanie.vbs X Added by the VBS.Stefan
strokeit strokeit.exe U StrokeIt is an "advanced mouse gesture recognition engine and command processor".
systemtraysr SRSystemTray.exe U Spyware Detector, Adware/Spyware remover. The latest version has been significantly improved since older versions thus having it removed from Spyware Warrior's rogue anti-spyware list. See note: here
systray SteFanie.vbs X Added by the VBS.Stefan
BoolTern svch0st.exe X Added by the W32/Tilebot-U worm and IRC backdoor.
Windows Spooler spool.exe X Added by the W32/Sdbot-ADP worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windows Updated spoolsae.exe X Added by the W32/Rbot-APM worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
svchast