| Index | Introduction | Database | Detailed Entries | Updates | Concise List | HJT Forums | Rogues | Message Board |
If you're frustrated with the time it takes your Windows 7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.
See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.
Last database update :- 29th Apr, 2013
31819 items listed
You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.
Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:
A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z
NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.
Please click on the Search button
5034 results found for S
| Startup Item or Name | Status | Command or Data | Description | Tested |
|---|---|---|---|---|
| sysguardn | X | s | Spyware Protect 2009 rogue spyware remover - not recommended, removal instructions here | No |
| Microsoft Intell Management | X | s.exe | Detected by McAfee as W32/Sdbot.worm!lq and by Malwarebytes Anti-Malware as Backdoor.Messa | No |
| scain | X | s030109.Stub.exe | Delfin Media Viewer adware related | No |
| WindowsD | X | s1.exe | Added by the MSNDIABLO.A WORM! | No |
| sy | X | s2.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| S24EvMon | ? | S24EvMon.exe | Event Monitor - supports driver extensions to NIC Driver for wireless adapters. Is it required? | No |
| S3apphk | N | S3apphk.exe | A tool installed alongside the drivers for your S3 video output device. It is not necessary but should be allowed to run unless it is causing problems | No |
| S3 Internal Chip | X | s3chip3.exe | Added by the AGOBOT-FW WORM! | No |
| S3 Internal | X | s3chip4.exe | Added by the AGOBOT-FQ BACKDOOR! | No |
| S3Hotkey | U | s3hotkey.exe | Hotkey system tray icon to enable switching between monitors. Found on laptops with an S3 Twister integrated graphics card | No |
| S3 Chip3 | X | s3int.exe | Added by the AGOBOT.LM BACKDOOR! | No |
| S3Mon | ? | S3Mon.exe | S3DuoVue multi-monitor taskbar helper by S3 Graphics. What does it do and is it required? | No |
| S3 Internal Chip | X | s3serv.exe | Added by the AGOBOT-DD WORM! | No |
| S3TRAY | U | S3Tray.exe | S3 display configuration taskbar utility for S3 chipset based graphics cards. Can be run from Start→ Settings → Control Panel → Display | No |
| s3tray2 | ? | s3tray2.exe | S3 display configuration taskbar utility for S3 chipset based graphics cards? | No |
| S3TRAYHP | ? | S3trayhp.exe | S3 Video driver related. What does it do and is it required? | No |
| S3Trayp | U | S3trayp.exe | S3 display configuration taskbar utility for S3 chipset based graphics cards. Can be run from Start→ Settings → Control Panel → Display | No |
| My Search Bar Eq | X | S4BAREQ.EXE | MySearch parasite | No |
| S4F | U | S4F.exe | FilterPak from S4F, Inc - internet filtering software | No |
| s4helper | X | s4helper.exe | Searchcentrix hijacker | No |
| s8kxmrxc7d | X | s8kxmrxc7d.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% | No |
| [random name] | X | s?chost.exe | PurityScan adware | No |
| T81Z627 | X | sa-200622.exe | Detected by Symantec as W32.Rontokbro@mm. The file is located in %Windir% | No |
| T81Z627 | X | sa-310632.exe | Detected by Kaspersky as Virus.Win32.Sality.bh. The file is located in %Windir% | No |
| T81Z627 | X | sa-310733.exe | Detected by Kaspersky as Virus.Win32.Virut.q and by Malwarebytes Anti-Malware as Worm.AutoRun. The file is located in %Windir% | No |
| T14Z840 | X | sa-532055.exe | Detected by McAfee as W32/MoonLight.worm and by Malwarebytes Anti-Malware as Worm.VB.UI. The file is located in %Windir% | No |
| Spellex Anywhere | N | sa.exe | Spellex-Anywhere - adds spell checking functionality to almost any Window program. Create a shortcut and run manually before it's to be used | No |
| StayAlive | U | sa.exe | StayAlive from TFI Technology. "This top-notch tool intercepts crashes when they happen, keeping your programs running so you can save your work." | No |
| ttool | X | sa23sl.exe | Added by the BCKDR-QZZ TROJAN! | No |
| SA | ? | Sa3.exe | Logitech QuickCam driver. Is it required? | No |
| Aureal A3D Interactive Audio | Y | sa3dsrv.exe | For Aureal based 3D soundcards. A3D sound features won't work with this disabled | No |
| Sa3dsrv | N | Sa3dsrv.exe | For Aureal based 3D soundcards. A3D sound features won't work with this disabled | No |
| sAaAVcAvvOACS | X | sAaAVcAvvOACS.exe | WindowsFixDisk rogue security software - not recommended, removal instructions here | No |
| saap | X | saap.exe | 180solutions adware | No |
| Sabre Server | U | sabserv.exe | Part of the Sabre computer reservations system/global distribution system (GDS) - used by airlines, railways, hotels, travel agents and other travel companies for reservations and ticketing | No |
| Sabreserver | U | SABSERV.EXE | Part of the Sabre computer reservations system/global distribution system (GDS) - used by airlines, railways, hotels, travel agents and other travel companies for reservations and ticketing | No |
| Sabre Printing Start | U | Sabstart.exe | Part of the Sabre computer reservations system/global distribution system (GDS) - used by airlines, railways, hotels, travel agents and other travel companies for reservations and ticketing | No |
| Sabre Task Tray Icon | U | Sabstart.exe | Part of the Sabre computer reservations system/global distribution system (GDS) - used by airlines, railways, hotels, travel agents and other travel companies for reservations and ticketing | No |
| sac | X | sac.exe | 180Search adware | No |
| SACC | X | sacc.exe | Detected by Symantec as Adware.SurfAccuracy and by Malwarebytes Anti-Malware as Adware.SurfAccuracy | No |
| SurfAccuracy | X | sacc.exe | Detected by Symantec as Adware.SurfAccuracy and by Malwarebytes Anti-Malware as Adware.SurfAccuracy | No |
| Onluna Sarvice | X | sachost.exe | Added by the TOFGER-AA TROJAN! | No |
| Onlune Sarvice | X | sachost.exe | Added by the DAEMONI-J TROJAN! | No |
| HostSrv | X | sachostx.exe | Added by the LOOKSKY.H WORM! Drops multiple files in %System% | No |
| HostSrv | X | sachostx.exe... | Added by the LOOKSKY.E WORM! | No |
| MicroSoft ssas3s1 | X | SADASDA.exe | Added by the RBOT.URF WORM! | No |
| SuperAdBlocker | U | SAdBlock.exe | SuperAdBlocker | No |
| NAV Auto Update | X | Sadness.exe | Added by the SPYBOT-E WORM! | No |
| Microsoft Driver Setup | X | sadrive32.exe | Detected by Sophos as W32/Autorun-VN | No |
| REMOTE REGISTRY SERVICE | X | safari.exe | Detected by McAfee as RDN/Generic Dropper!bo and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| Windows Service Base | X | safari.exe | Detected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %System% | No |
| SafeCare | X | SafeCare.exe | SafeCare rogue security software - not recommended, removal instructions here | No |
| NetScreen-Remote | U | SafeCfg.exe | NetScreen Remote VPN client software | No |
| SafeDrvsss | X | SafeDrvsss.exe | Detected by Malwarebytes Anti-Malware as Spyware.Agent. The file is located in %CommonFiles% | No |
| SafeFighter | X | SafeFighter.exe | SafeFighter rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| Safeguard.exe | X | Safeguard.exe | Super Spyware Killer rogue spyware remover - not recommended | No |
| SafeInstall.exe | N | SAFEIN~1.EXE | Monitors a download and ensures an newer version of a file isn't replaced by an older one | No |
| Microsoft Safe Mode Manager | X | safemode.exe | Added by the IRCBOT.HM BACKDOOR! | No |
| SafeMyWeb | X | safemyweb.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%\My UserPrograms | No |
| SafeOFF | N | SafeOff.exe | Provides protection that if user accidentally presses the power switch a dialog will pop up for confirmation | No |
| SafePcAv | X | SafePcAv.exe | SafePcAv rogue security software - not recommended, removal instructions here. A member of the AntiAID family | No |
| SafePrivacy | X | SafePrivacy.exe | SafePrivacy rogue security software - not recommended, removal instructions here | No |
| SafePrivate | X | SafePrivate.exe | SafePrivate rogue security software - not recommended, removal instructions here | No |
| SaferScan | X | SaferScan.exe | SaferScan rogue security software - not recommended | No |
| SafeSearch | X | safesearch.exe | SafeSearch adware | No |
| Unshare | X | SafeShare.exe | SafeShare peer-to-peer (P2P) file-sharing client often bundled with adware or spyware | No |
| CertificateRegistration | U | SafeSignCertReg.exe | SafeSign Certificate Registration Utility for Microsoft Crypto applications | No |
| SafeSpace | Y | SafeSpaceSysTray.exe | Part of SafeSpace (from Artificial Dynamics) which "protects computers from Internet malware infection without the need for signature updates or regular maintenance" | No |
| SafeStrip | X | SafeStrip.exe | SafeStrip rogue security software - not recommended, removal instructions here | No |
| SafeStripReminder | X | SafeStripReminder.exe | SafeStrip rogue security software - not recommended, removal instructions here | No |
| SafeSys | X | SafeSys.exe | Added by the AUTORUN.DMI WORM! | No |
| Safeterra | X | SafeTerraUpdate.exe | Detected by Symantec as Adware.SafeTerra and by Malwarebytes Anti-Malware as Adware.Agent | No |
| Safety Anti-Spyware 3 | X | Safety Anti-Spyware 3.exe | Safety Anti-Spyware rogue security software - not recommended, removal instructions here | No |
| SafetyKeeper | X | SafetyKeeper.exe | SafetyKeeper rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| SafetyPC | X | safetypcup.exe | SafetyPC rogue security software - not recommended, removal instructions here | No |
| Safe | X | SafeWin.exe | Added by the FOCOSENHA TROJAN! | No |
| Sagate Security Firewall | X | sagate.exe | Added by the GAOBOT.BOW WORM! | No |
| Laptop Access | X | Sage.exe | Added by the SDBOT-NB WORM! | No |
| SystemAgent | U | Sage.exe | "Microsoft Plus! System Agent automatically tunes your system, performing tasks such as disk optimization and error correction. It can also run any application at prescheduled times" | No |
| SagemMonitor | U | SagemMonitor.exe | Monitor for the Sagem F@st 1200 high speed ADSL router | No |
| SAGENTSERVICE | U | Sagent.exe | TinySpyAgent commercial keystroke logger. Uninstall this software if you did not install it yourself | No |
| SAgent2ExePath | N | SAgent2.exe | Seiko Epson printer status agent. Disable if printer is not used often | No |
| sagnt | X | sagnt.exe | Adware web downloader | No |
| PrevxHome | Y | SAGUI.exe | PrevX behaviour-based malware protection | No |
| PrevxPro | Y | SAGUI.exe | PrevX behaviour-based malware protection | No |
| SAHagent | X | Sahagent.exe | ShopAtHomeSelect parasite | No |
| SaitekAutoConfigure | U | saicnfig.exe | Configuration for Saitek game controllers | No |
| saie | X | saie.exe | 180solutions adware | No |
| saihoi | X | saihoi.exe | Added by the MDROP-CUT TROJAN! | No |
| SmartAudio | U | SAIICpl.exe | Conexant SmartAudio PC audio chipset software - typically available on notebooks with built-in microphones | No |
| Configuration Software | N | SaiMfd.exe | Saitek MFD File System Driver - associated with the Saitek SST (Saitek Smart Technology) configuration software for their game controllers. Create a shortcut and run manually when required | Yes |
| SaiMfd | N | SaiMfd.exe | Saitek MFD File System Driver - associated with the Saitek SST (Saitek Smart Technology) configuration software for their game controllers. Create a shortcut and run manually when required | Yes |
| SAIMON | U | SaiMon.exe | Saitek joystick driver | No |
| Write DVD-R! | U | saimon.exe | Saimon's WriteDVD! "gives total support for DVD-RAM drives. It provides many functions such as setting partitions on DVD-RAM disks and FixDVD! can diagnose and repair UDF formatted disks" | No |
| sain | X | sain.exe | 180Search adware | No |
| sais | X | sais.exe | 180solutions adware | No |
| SaiSmart | U | SaiSmart.exe | "Smart Button Special Sauce" - included with support software for some of the Saitek game controllers. Related to the "S", "Shift" or "Smart" button and gives gamers extra features on the buttons. Only required if you use this feature | No |
| Sakora | X | Sakora.exe | Added by the GOWELES.A TROJAN! | No |
| SalaatTime | N | SalaatTime.exe | "Salaat Time is a FREE multi-function Islamic application that calculates the prescribed five daily Muslim prayer times as well as Qiblah direction for anywhere in the world" | No |
| salm | X | salm.exe | 180Search adware | No |
| smsofter | X | salss.exe | Detected by McAfee as RDN/Downloader.a!p and by Malwarebytes Anti-Malware as Trojan.ChinAd | No |
| msvcc25 | X | salvage.exe | Added by a variant of W32/Sdbot.worm | No |
| saly | X | saly*****.exe | Added by a variant of the AW.AWK TROJAN! | No |
| Sam-sung | X | Sam-sung.exe | Added by a variant of W32/Sdbot.worm | No |
| SAMcal | U | SAMcal.exe | SamCal - calendar/reminder program | No |
| SamSvcDll | X | SamHostDll.exe | Detected by McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| Bluetooth | X | sample.exe | Added by the AGENT-OSH TROJAN! | No |
| CCGLOG | X | sample.exe | Detected by McAfee as RDN/Generic BackDoor!p and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| chrome.exe | X | sample.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Temp% | No |
| java | X | sample.exe | Detected by Malwarebytes Anti-Malware as Worm.Ainslot. The file is located in %Temp% | No |
| msconfig | X | sample.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Temp% | No |
| svchost | X | sample.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %UserTemp% | No |
| testing.exe | X | sample.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Temp% | No |
| tmp_up | X | sample.exe | QuickBar adware | No |
| Win Update | X | sample.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserTemp% | No |
| Windows Firewall | X | sample.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Temp% | No |
| Windows Rundll32 | X | sample.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Temp% | No |
| Security Accounts Manager SM | X | samsm.exe | Added by the WOOTBOT.BC WORM! | No |
| Samsong | X | Samsong.exe | Added by the SDBOT.BNE WORM! | No |
| YeppStudioAgent | N | SamsungMediaStudioAgent.exe | Samsung Media Studio MP3 player file management software - see here for an example | No |
| Samsung | X | Samsungs.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| PersSamDll | X | SamTrayConf.exe | Detected by McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| FireWire Driver | X | samx.exe | Added by the SDBOT.AE WORM! | No |
| Adobe Gama Loader | X | san.exe | Detected by McAfee as RDN/Generic PWS.y!l and by Malwarebytes Anti-Malware as Backdoor.Messa | No |
| SancMedia | X | SancMedia.exe | Detected by Sophos as Troj/Mdrop-EYG and by Malwarebytes Anti-Malware as Trojan.Dropper.MS | No |
| SandIcon | N | SandIcon.exe | SanDisk ImageMate CompactFlash card reader SDDR-31 (USB). Very little use except to place the Sandisk icon beside its drive designation in Windows Explorer. The reader itself will work fine without it. The simplest thing is to just unplug the reader when you're not using it. It may slow the startup by a few nanoseconds, but once the software sees there's no reader, you get back the resources | No |
| SanDiskSecureAccess_Manager.exe | U | SanDiskSecureAccess_Manager.exe | " | No |
| SansaDispatch | U | SansaDispatch.exe | Sansa Updater - "The Sansa Firmware Updater is an application designed to deliver the latest firmware, software support, User Manuals right to your desktop" | No |
| SANS Service | X | sansv.exe | Added by the VANEBOT-AH WORM! | No |
| Santa Bastards Bitch | X | SANTAS.BITCH.txt | Added by the ATNAS.A WORM! | No |
| System Applications Profile | X | sap.exe | Added by the RBOT-QF WORM! | No |
| sapp | X | sapp.exe | NCase adware | No |
| [various names] | X | SAPSTR.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Beawver | X | saqevre.exe | Added by a variant of Backdoor.Ranky. The file is located in %System% | No |
| Microsft Updtes | X | sarvice.exe | Added by a variant of W32/Sdbot.worm | No |
| SA Service | ? | SAservice.exe | Associated with Cyber Trio and Warner troubleshooting software from G-Tek Technologies and pre-installed on some Packard Bell and NEC PCs. What function does this perform and is it required? | No |
| Syntax Script | X | saskatcw.exe | Added by the SDBOT-TE WORM! | No |
| SaskTel Accelerated Dial-up | U | sasktelgui.exe | "Experience faster surfing, downloading and e-mail by adding SaskTel Accelerated Dial-up Internet" | No |
| usb | X | SASS.EXE | Added by the FUNSTA-A TROJAN! | No |
| sast32 | X | sast32-2.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Root% | No |
| ScanDisc | X | satan.exe | Added by the GREGSTAR TROJAN! | No |
| SATARaid | U | SATARaid.exe | RAID driver for serial ATA disks on some motherboards such as the DFI Lanparty range. Only loaded if one is using RAID support on SATA drives | No |
| satmat | X | satmat.exe | VX2.Transponder parasite updater/installer related | No |
| sau | X | sau.exe | 180Search adware | No |
| sauobex | X | sauobex.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %UserProfile% | No |
| ATTBroadbandUpdate | U | SAUpdate.exe | Big Brother from Quest Software. System and network monitor | No |
| SAUpdate | U | SAUpdate.exe | Big Brother from Quest Software. System and network monitor | No |
| SAutoLaunchExe | U | SAutoLaunchExe.exe | Sharp Zaurus PDA related, needed to synchronize information with a Desktop or Notebook | No |
| Antivirus | X | sav.exe | System Antivirus 2008 rogue security software - not recommended, removal instructions here | No |
| SAVAgent | Y | SAVAgent.exe | Part of Sophos anti-virus software. Required for centrally administered Sophos updates to work correctly, e.g. automatically updating PCs used by dial-in home or out-of-office users | No |
| Save | X | Save.exe | SaveNow adware | No |
| WhenUSave | X | Save.exe | SaveNow adware | No |
| SaveArmor | X | SaveArmor.exe | SaveArmor rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| SaveCom | X | SaveCom.exe | SaveCom rogue security software - not recommended, removal instructions here | No |
| SaveDefender | X | SaveDefender.exe | SaveDefender rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| SaveDefense | X | SaveDefense.exe | SaveDefense rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| SaveKeep | X | SaveKeep.exe | SaveKeep rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| SaveKeeper | X | SaveKeeper.exe | SaveKeeper rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| SaveMyWork | U | SaveMyWork.exe | SaveMyWork keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| Savenow | X | SaveNow.exe | SaveNow adware | No |
| SaveSoldier | X | SaveSoldier.exe | SaveSoldier rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| SaveDate | X | SaveStartDate.Exe | Unidentified adware | No |
| Microsoft Security Center | X | savservices.exe | Added by the RBOT-ANU WORM! | No |
| SAW | X | saw.exe | SmartAdware adware | No |
| Say The Time 5.0 | U | SAYTIME.EXE | This program has audio cues for the system clock in male and female voices, customizes the appearance of the system clock, and can synchronize it to a time server regularly | No |
| Security Antivirus | X | SA[random].exe | Security Antivirus rogue security software - not recommended, removal instructions here | No |
| sm | X | sa_exe.exe | Added by the OLFEB.A TROJAN! | No |
| SB | U | SB.exe | Acer Soft Button on Acer Tablet PCs | No |
| CDLoader | U | sb32mon.exe | Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself! | No |
| RegUpdate | U | sb32mon.exe | Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself! | No |
| ScanSys32 | U | sb32mon.exe | Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself! | No |
| SysCheck32 | U | sb32mon.exe | Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself! | No |
| System32 | U | sb32mon.exe | Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself! | No |
| Systemcheck | U | sb32mon.exe | Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself! | No |
| Trunk32 | U | sb32mon.exe | Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself! | No |
| WinSysCheck | U | sb32mon.exe | Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself! | No |
| SBAMTray | Y | SBAMTray.exe | System Tray access to and notifications for the VIPRE (and older CounterSpy) range of security software from GFI Software (was Sunbelt Software) | No |
| SBAutoUpdate | U | sbautoupdate.exe | SpywareBlaster auto-updater | No |
| SBC RoamingClient | U | SBCFL.exe | Part of AT&T FreedomLink Wi-Fi connection software | No |
| SBCSTray | Y | SBCSTray.exe | System Tray access to Sunbelt CounterSpy antispyware software - now discontinued with users recommended to switch to VIPRE | No |
| SBDrvDet | U | SBDrv.exe | Detects the "Easy Front-Panel Audio Connectivity Drive Internal Drive Bay" on the Sound Blaster Audigy 2 Platinium eX. Can be disabled if you don't have one | No |
| SBDrvDet | N | SBDrvDet.exe | Checks to see if Creative sound card driver should be updated | No |
| SBHC | X | sbhc.exe | SuperBar parasite | No |
| Windows bypass security SMSS Service | X | SbiCvy.exe | Added by the RBOT-GRF WORM! | No |
| SandboxieControl | U | SbieCtrl.exe | "SandBoxie runs your programs in an isolated space which prevents them from making permanent changes to other programs and data in your computer" | No |
| [various names] | X | sbin.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Spam Blocker for Outlook Express | X | SBInst.exe | Spam Blocker Utility adware by the people who provide the Hotbar adware | No |
| Windows System Restore Configuration | X | Sblhost.exe | Added by a variant of the SPYBOT WORM! | No |
| start | X | sbmntr.exe | Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machine. Various directories and filenames are used - see the link for details. This particular one is "NetProject" | No |
| SBMPOP | X | SBMPop.exe | SearchByMedia adware | No |
| SBMX | N | sbmx.exe | SoundMAX MPU401 MIDI device emulator for x86 VM DOS games/apps (for Win9x only) | No |
| SpamBlocker | X | SbOEAddOn.exe | Spam Blocker Utility adware by the people who provide the Hotbar adware | No |
| Microsoft Service Boot | X | sboot.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| SBoxSearchBarOS | X | SBoxSearchBar.exe | Detected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\ShareBox\SBoxSearchBar | No |
| SBoxSearchBar | X | SBoxSearchBarU.exe | Detected by AVG as OpenShopper.A and by Malwarebytes Anti-Malware as Adware.K.ShareBox. The file is located in %ProgramFiles%\ShareBox\SBoxSearchBar | No |
| MSRegScan | U | SBPDemo.exe | SpyBoss Pro surveillance software. Uninstall this software unless you put it there yourself | No |
| SystemBooster2009 | X | sbr_updater.exe | SystemBooster2009 rogue system suite - not recommended, removal instructions here | No |
| SYSTEM.MANAGEMENT | X | sbscmp20_mscorlib.exe | Detected by McAfee as RDN/Generic Dropper!d and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| ScriptBlocking | Y | SBServ.exe | Part of the "Script Blocking" feature for older versions of Symantec's Norton AntiVirus which monitors script-based (ie, JavaScript, VB Script) viruses and alerts you of virus-like malicious behavior, stopping these viruses before they can infect your system. Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| Eapcisetup | N | sbsetup.exe | Rockwell RipTide soundcard application software. Sound works without it | No |
| sbss Launcher | X | sbss.exe | SideBySide adware | No |
| SBUSA | X | SBUSA.exe | Spam Blocker Utility adware by the people who provide the Hotbar adware | No |
| SB Watchdog | X | SBWatchdog.exe | Spyware utility installed by the manufacturers of some laptops (Sony) used to monitor browsing habits and send them back to whoever installed it - released by SoftBank | No |
| WeatherOnTray | X | SbWeatherOnTray.exe | Spam Blocker Utility adware by the people who provide the Hotbar adware | No |
| 6-susilo b | X | sby.exe | Added by the BRONTOK-CR WORM! | No |
| sc | U | sc.exe | Watchdog 2.0 Software - monitoring program | No |
| sc23exec | ? | sc23exec.exe | Possibly related to a digital camera | No |
| SC3300CC | Y | SC3300CC.exe | SiPix digital camera Twain device driver | No |
| USB Electronic Scale | U | Scale | Related to a USB Electronic Scale - manufacturer currently unknown | No |
| WINDOWS SYSTEM SCALPE | X | scalpe91.exe | Added by the MYTOB-HI WORM! | No |
| Driver32 | X | Scam32.exe | Detected by Symantec as W32.Sircam.Worm@mm | No |
| Scan&Repair2006.exe | X | Scan&Repair2006.exe | Scan&Repair Utilities 2006 rogue system utility - not recommended | No |
| antispy | X | scan.exe | IE AntiVirus rogue security software - not recommended, removal instructions here | No |
| TotalSecure2009 | X | scan.exe | Total Secure 2009 rogue security software - not recommended, removal instructions here | No |
| Scan119 | X | Scan119.exe | Scan119 rogue security software - not recommended, removal instructions here | No |
| 1455 Scan2PC | U | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX1455 multifunction printer | No |
| 2335dn Scan2PC | U | Scan2pc.exe | Scan to PC application for the scanning function of the Dell 2335 multifunction laser printer | No |
| 3170 Scan2PC | U | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung CLX3170 multifunction laser printer | No |
| 4x26 Scan2PC | U | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX4x26 multifunction laser printers | No |
| 4x28 Scan2PC | U | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX4x28 multifunction laser printers | No |
| 6200 Scan2PC | U | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung CLX6200 multifunction laser printer | No |
| ELBERT_S2P | U | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX-5x30 Series multifunction printers | No |
| ELBERTRicoh_S2P | U | Scan2pc.exe | Scan to PC application for the scanning function of the Ricoh MFP Type 104 multifunction printer | No |
| IRIS_S2P | U | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung CLX-3160 Series multifunction laser printer | No |
| IRIS_XRX_S2P | U | Scan2pc.exe | Scan to PC application for the scanning function of the Xerox Phaser 6110MFP multifunction laser printer | No |
| Logan_S2P | U | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX-4500 Series multifunction printer | No |
| Maple_S2P | U | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung CLX-216x Series multifunction printers | No |
| MFP1815_S2P | U | Scan2pc.exe | Scan to PC application for the scanning function of the Dell Laser MFP 1815 multifunction printer | No |
| R2Plus_S2P | U | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX-4x20 Series multifunction printers | No |
| R2Ricoh_S2P | U | Scan2pc.exe | Scan to PC application for the scanning function of the Ricoh MFP Type 103 multifunction printer | No |
| Scan2pc | U | Scan2pc.exe | Scan to PC application for the scanning function of multiple multifunction printers from Dell, Samsung, Xerox, Ricoh and others | No |
| WHITNEY_S2P | U | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX-4x21 Series multifunction printers | No |
| Whitney2_S2P | U | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX-4725 Series photocopier | No |
| WHITNEY2_XRX_S2P | U | Scan2pc.exe | Scan to PC application for the scanning function of the Xerox Phaser 3200MFP multifunction laser printer | No |
| WhitneyXerox_S2P | U | Scan2pc.exe | Scan to PC application for the scanning function of the Xerox WorkCentre PE220 Series multifunction laser printer | No |
| Win32G | X | Scandisk.com | Added by the ESTRELLA TROJAN! | No |
| ScanDisk | X | ScanDisk.exe | Added by the GANDA.A WORM! Note - this is not the valid "ScanDisk" Win9x/Me standard disk error checker | No |
| scands32.exe | X | scands32.exe | Added by a variant of the ADCLICKER TROJAN! | No |
| Scandsk2 | X | scandsk2.exe | Added by the AGOBOT-PK WORM! | No |
| scandskx.exe | X | scandskx.exe | Detected by Sophos as Troj/Dloadr-ARM | No |
| Messenger | U | SCANMSG.EXE | Part of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. Enables the "Quick Heal messenger service which provides important information about latest threats, updates and other information related to Quick Heal." Also included by vendors who use the Quick Heal engine such as Omniquad and iQon | Yes |
| Quick Heal AntiVirus | U | SCANMSG.EXE | Part of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. Enables the "Quick Heal messenger service which provides important information about latest threats, updates and other information related to Quick Heal." Also included by vendors who use the Quick Heal engine such as Omniquad and iQon | Yes |
| SCANMSG | U | SCANMSG.EXE | Part of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. Enables the "Quick Heal messenger service which provides important information about latest threats, updates and other information related to Quick Heal." Also included by vendors who use the Quick Heal engine such as Omniquad and iQon | Yes |
| ScanSpyware | X | Scanner.exe | ScanSpyware rogue security software - not recommended, removal instructions here. Also see here | No |
| ScanSpyware v3.2 | X | Scanner.exe | ScanSpyware rogue security software - not recommended, removal instructions here. Also see here | No |
| ScanSpyware v3.5 | X | Scanner.exe | ScanSpyware rogue security software - not recommended, removal instructions here. Also see here | No |
| hpScannerFirstBoot | ? | scannerfb.exe | HP scanner related | No |
| Microtek Scanner Finder | U | ScannerFinder.exe | Monitors whether a scanner is present. Provided with Microtek scanners | No |
| ScanPanel | ? | ScanPanel.exe | Trust Easy Webscan scanner related - what does it do and is it required? | No |
| Reg_WFT | X | scanreg32.com | Added by the SENNASPY-F TROJAN! | No |
| ScanRegistry | X | scanregv.exe | Added by the MASTERLOCK TROJAN!. Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as scanregv.exe not scanregw.exe | No |
| [random name] | X | scanregw.exe | PurityScan adware. Note - do not confuse this with the legitimate scanregw.exe which is always found in %Windir% on Win9x/ME machines | No |
| ScanRegistry | X | scanregw.exe | Detected by Sophos as W32/Nyxem-D. Note - do not confuse this with the legitimate Windows process scanregw.exe which is always found in the Windows folder on Win9x/ME machines. This worm file is found in %System% | No |
| ScanRegistry | X | Scanregw.exe | Detected by Symantec as W32.Stator@mm. Note - do not confuse this with the legitimate scanregw.exe which is always found in %Windir% on Win9x/ME machines. This one is located in %System% | No |
| ScanRegistry | Y | Scanregw.exe | Scans the WinMe/98 system registry and makes back-ups at start-up - important should the registry become corrupt. Located in %Windir% | No |
| Microsoft Disk Scanner | X | scansdisk.exe | Added by the WOOTBOT.DT WORM! | No |
| [various names] | X | scanSYS.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| P3000x_S2P | U | ScanToPc.exe | Dell Laser MFP 1600N network application for scanning files to the PC | No |
| Windows Service | X | Scanvegw.exe | Added by the DELF BACKDOOR! | No |
| scApp | X | scApp.exe | Added by the STANDO-E WORM! | No |
| TwkSCardSrv | N | SCardS32.Exe | Used with Towitoko SmartCard Readers for card recognition | No |
| SCardSvr | N | scardsvr.exe | Related to SmartCard readers and sometimes uses lots of system resources | No |
| Smart Card Service | N | ScardSvr.exe | For Smart Card readers. Known to cause problems, especially for Windows 2000 users - see here. Probably not required unless you use such a device regularly | No |
| NavAgent32 | X | SCardSvr32.Exe | Detected by Trend Micro as WORM_MOFEI.B | No |
| SCardSvr | X | SCardSvr32.Exe | Detected by Trend Micro as WORM_MOFEI.B | No |
| SearchEnhancement | X | scbar.exe | SCBar/SearchEnhancement foistware | No |
| Compaq Computer Corp SCCenter Module | N | SCCENTER.EXE | For Compaq PC's. Part of Backweb | No |
| Service Connection | N | sccenter.exe | For Compaq PC's. Part of Backweb | No |
| Alive SYstem | X | scchost.exe | Added by the TOFDROP-B TROJAN! | No |
| Key Name | X | scchost.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%\windowexplorer | No |
| Services Host | X | Scchost.exe | Added by the DONK WORM! | No |
| Systems | X | scchost.exe | Added by the DAEMOZ.A TROJAN! | No |
| Alive SYstem | X | scchostc.exe | Added by the TOFDROP-B TROJAN! | No |
| Microsoft Windows Update | X | sccvhost.exe | Added by a variant of W32/Sdbot.worm | No |
| SCDEmuApp.exe | U | SCDEmuApp.exe | Related to PowerISO - CD/DVD image file processing tool | No |
| Configuration Driver | X | scghost.exe | Added by the SDBOT-DLA WORM! | No |
| MS Windows Update | X | scguard.exe | Added by the RBOT-YZ WORM! | No |
| Backup NOW! Scheduler | U | Schdlr32.exe | Scheduled backups for the NTI Backup Now archiving utility. If a backup job has been scheduled, this entry places an icon in the System Tray and will automatically load the main program and execute the backup at the set time - as long as the backup media is present | Yes |
| NTI Backup NOW! Scheduler | U | Schdlr32.exe | Scheduled backups for the NTI Backup Now archiving utility. If a backup job has been scheduled, this entry places an icon in the System Tray and will automatically load the main program and execute the backup at the set time - as long as the backup media is present | Yes |
| Schdlr32 | U | Schdlr32.exe | Scheduled backups for the NTI Backup Now archiving utility. If a backup job has been scheduled, this entry places an icon in the System Tray and will automatically load the main program and execute the backup at the set time - as long as the backup media is present | Yes |
| Windows Services | X | scheb.exe | Detected by Sophos as Troj/Agent-QVV and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen | No |
| Windows Update | X | scheb.exe | Detected by Sophos as Troj/Agent-QVV and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| Windows Update System | X | scheb.exe | Detected by Microsoft as Backdoor:Win32/IRCbot.FJ and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| scheck45 | X | scheck45.exe | Related to unknown malware - hidden installer associated with it | No |
| Acronis Scheduler Helper | U | schedhlp.exe | Scheduler for Acronis True Image backup software. From Acronis (courtesy of AnswersThatWork: "The program monitors the logons and logoffs on your PC and notifies the Acronis Scheduling system about them. It is started when a user logs into the system and terminates when the user logs off. Acronis True Image uses this program to schedule tasks on user logon/logoff and to run non-scheduled "Image creation" operation". Not required if you do not have scheduled jobs. Also included in Seagate's DiscWizard and BlackArmor Backup implementations of True Image | No |
| Acronis Scheduler2 Service | U | schedhlp.exe | Scheduler for Acronis True Image backup software. From Acronis (courtesy of AnswersThatWork: "The program monitors the logons and logoffs on your PC and notifies the Acronis Scheduling system about them. It is started when a user logs into the system and terminates when the user logs off. Acronis True Image uses this program to schedule tasks on user logon/logoff and to run non-scheduled "Image creation" operation". Not required if you do not have scheduled jobs | No |
| schedhlp | U | schedhlp.exe | Scheduler for Acronis True Image backup software. From Acronis (courtesy of AnswersThatWork: "The program monitors the logons and logoffs on your PC and notifies the Acronis Scheduling system about them. It is started when a user logs into the system and terminates when the user logs off. Acronis True Image uses this program to schedule tasks on user logon/logoff and to run non-scheduled "Image creation" operation". Not required if you do not have scheduled jobs. Also included in Seagate's DiscWizard and BlackArmor Backup implementations of True Image | No |
| Seagate Scheduler2 Service | U | schedhlp.exe | Scheduler for Seagate's DiscWizard and BlackArmor Backup - their implementation of the Acronis True Image backup software. From Acronis (courtesy of AnswersThatWork: "The program monitors the logons and logoffs on your PC and notifies the Acronis Scheduling system about them. It is started when a user logs into the system and terminates when the user logs off. Acronis True Image uses this program to schedule tasks on user logon/logoff and to run non-scheduled "Image creation" operation". Not required if you do not have scheduled jobs | No |
| WTIndicator | U | SchedInd.exe | WinTask - software that automates a variety of routine tasks quickly and simply | No |
| schedl | X | schedl.exe | Added by the VB-DVW WORM! | No |
| schedm | U | schedm.exe | Part of Antivir PersonalEdition Classic anti-virus | No |
| Task Scheduler Engine | X | schedsvc32.exe | Added by the RBOT-ASJ WORM! | No |
| Schedule | U | Schedule.exe | Scheduler for Mercury Ez View TV Tuner Card | No |
| TvrSchedule | U | Schedule.exe | Scheduler for Mercury Ez View TV Tuner Card | No |
| Center Agent | U | Scheduled.exe | Scheduler for HyperMedia Center from Kworld - "an integrated multimedia application that allows you to enjoy all of your digital entertainment - TV, home videos and photos. HyperMedia Center is especially designed for turning your PC/Laptop into an entertainment solution" | No |
| Scheduled Maintenance | N | Scheduled_Maintenance.exe | Scheduler for Iolo System Mechanic tweaking utility. It can cleans your registry and deletes temporary files at defined intervals. Available via Start → Programs | No |
| Scheduler | U | Scheduler daemon.exe | Tenebril GhostSurf or SpyCatcher related scheduler - you can schedule daily, weekly, monthly or one-time only cleanings | No |
| DSScheduler | U | Scheduler.exe | Scheduler for Dynamic Submission by Apex Pacific - "Web site Promotion and Internet Marketing Software that allows you to perform automated search engine submission, Web site submission, and search engine optimization (SEO)" | No |
| MRU-Blaster Scheduler | U | scheduler.exe | Scheduler for MRU-Blaster from Brightfort (formerly Javacool Software) - which "is a program made to do one large task - detect and clean MRU (most recently used) lists on your computer" | No |
| Scheduling Agent | X | Scheduler.exe | Detected by Symantec as Backdoor.Subwoofer | No |
| Service Scheduler | X | scheduler.exe | Added by the AGOBOT-PH WORM! | No |
| Staffcop Scheduler | U | scheduler.exe | StaffCop surveillance software. Uninstall this software unless you put it there yourself | No |
| Windows Scheduler! | X | scheduler.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| XemiComputers Scheduler | U | Scheduler.exe | Smooth Program Scheduler from XemiComputers "will start any program you want at a scheduled time" | No |
| scheduler_proxy Application | U | scheduler_proxy.exe | Found on IBM/Lenovo ThinkCentre/ThinkStation desktops and Thinkpad notebooks. Included with versions of ThinkVantage System Update (for software updates), Rescue and Recovery (backup and system recovery), Message Center Plus and maybe others. It's exact function isn't known but if disabled, the "plan updates" button in the IBM System Update software will no longer be available, though the software will continue run properly | Yes |
| TVT Scheduler Proxy | U | scheduler_proxy.exe | Found on IBM/Lenovo ThinkCentre/ThinkStation desktops and Thinkpad notebooks. Included with versions of ThinkVantage System Update (for software updates), Rescue and Recovery (backup and system recovery), Message Center Plus and maybe others. It's exact function isn't known but if disabled, the "plan updates" button in the IBM System Update software will no longer be available, though the software will continue run properly | Yes |
| AdwareKiller_schedules | X | schedules.exe | EAdwareKiller rogue spyware remover - not recommended | No |
| Laplink PDASync 3.1 - ScheduleSync | U | ScheduleSync.exe | Laplink PDASync for ScheduleSync - PDA synchronisation utility | No |
| GroupWise PDA Connect - ScheduleSync | U | SCHEDU~1.EXE | ScheduleSync specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell | No |
| XTNDConnect PC - ScheduleSync | U | SCHEDU~1.EXE | ScheduleSync specific translator for XTNDConnect PC - "award-winning desktop-sync application that enables you to easily synchronize your contacts, calendar, tasks, email and notes between your mobile devices and popular PC applications" | No |
| JavaUpdateScheds | X | schedzs.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Xtrat. The file is located in %Windir% | No |
| SCHelper.exe | N | SCHelper.exe | Spyware Cease spyware remover. Previous versions were regarded as a rogue (see here) because it reported false or exaggerated system security threats but the latest version tested (6.5.1) has a new interface and produces no exaggerated threats on a clean system. Not recommended due to the past history | Yes |
| NovastorSchedulerd | U | SCHENGD.EXE | NovaStor NovaBACKUP Scheduler - back-up utility. If you don't have regularly scheduled back-ups you don't need it | No |
| Schmaili | U | Schmaili.exe | Schmaili - insert animated smilies into your e-mail | No |
| a2abfc2cbc7857ee33ac527ade190621 | X | Schost.exe | Detected by Malwarebytes Anti-Malware as Trojan.Dropper. The file is located in %Temp% | No |
| Generic Host Process | X | SCHOST.EXE | Added by the RBOT-NC WORM! | No |
| Intranet | X | schost.exe | Added by the RBOT.SV BACKDOOR! | No |
| Microsoft | X | schost.exe | Added by the RBOT.FEH BACKDOOR! | No |
| Microsoft Manage Services | X | schost.exe | Detected by PCTools as Worm.Slenfbot.B | No |
| Update Install | X | Schost.exe | Detected by Symantec as W32.HLLW.Gaobot.AO | No |
| Windows Service Host | X | schost.exe | Added by a variant of W32.HLLW.Gaobot.gen. The file is located in %Windir% | No |
| WinManager | ? | schost.exe | ?? | No |
| AVSchedScan | Y | SCHSC9X.EXE | Scheduler for Command AntiVirus for 9x/Me by Command Software Systems, Inc (who became Authentium and are now Commtouch) | No |
| Home Theater SchSvr | U | SchSvr.exe | Scheduler installed with the Home Theater Remote Control for older versions of the WinDVD software DVD player from Intervideo (now Corel). Required if you want to schedule recordings from your TV tuner card | No |
| Intervideo WinScheduler | U | SchSvr.exe | Scheduler installed with the WinDVD Remote Control for older versions of the WinDVD software DVD player from Intervideo (now Corel). Required if you want to schedule recordings from your TV tuner card | No |
| SchSvr | U | SchSvr.exe | Scheduler installed with the Home Theater Remote Control or WinDVD Remote Control for older versions of the WinDVD software DVD player from Intervideo (now Corel). Required if you want to schedule recordings from your TV tuner card | No |
| WinDVR SchSvr | U | SchSvr.exe | Scheduler installed with the WinDVD Remote Control for older versions of the WinDVD software DVD player from Intervideo (now Corel). Required if you want to schedule recordings from your TV tuner card | No |
| Microsoft Update 64 BIT | X | schvost.exe | Added by the RBOT.CAU WORM! | No |
| schvost | X | schvost.exe | Detected by McAfee as RDN/Generic.bfr!d and by Malwarebytes Anti-Malware as Trojan.VBKrypt | No |
| CSScheduleCheck | Y | SCHWIZEX.EXE | Part of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot | No |
| SCHWIZEX | Y | SCHWIZEX.EXE | Part of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot | No |
| SecureCleanIEClean | N | SCIEClean.exe | SecureClean - scans your system for hidden temporary files, deleted email messages, Internet histories and caches | No |
| some | X | scit.exe | Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machine. Various directories and filenames are used - see the link for details. This particular one is "NetProject" | No |
| SybaseCentral43 | U | scjview.exe | Related to SQL Anywhere from Sybase. A comprehensive package providing data management and data exchange technologies | No |
| Services | X | scks32.exe | Added by a variant of Trojan-Proxy. The file is located in %Root% | No |
| sclauncher | N | sclauncher.exe | SimpleCenter digital media player/manager that supports the iPod, Sony PSP, Xbox 360, some of the Nokia N-series mobile phones and others | No |
| sclick | X | sclick.exe | Added by the FAKEALERT TROJAN! | No |
| Service Control Manager | X | scm.exe | Added by the AGOBOT-GD BACKDOOR! | No |
| SOS SQL Database | N | scm.exe | SQL Server Service Control Manager - part of Microsoft SQL Server. Available via Start → Programs | No |
| SQL Server | N | scm.exe | SQL Server Service Control Manager - part of Microsoft SQL Server. Available via Start → Programs | No |
| Stardust Screen Saver Control 2003 | U | SCMain.exe | Screen Saver Control 2003 from Stardust Software - "is a standalone version of our popular screen saver add-on. It allows you to control and configure all your screen savers directly from the system tray" | Yes |
| ScManager | X | scman.exe | Added by the FORBOT-CW WORM! | No |
| SurfChoice | U | SCMan.exe | SCMan is a utility that can control services on WinNT from the command line. This utility can create, start, pause, stop, delete services. Furthermore it can retrieve a service's current state, get the displayname for a service and vice versa | No |
| CHIPDRIVESmartcardManager | U | SCMgr.exe | ChipDrive Smartcard software | No |
| Spore.b | X | Scmhlpr.vbs | Added by the SORPE.B WORM! | No |
| Smart Connect Monitor | U | SCMon.exe | Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio | No |
| Windows Services | X | scmsg.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.Gen. The file is located in %System% | No |
| Security Patch | X | scmss.exe | Detected by Sophos as W32/Rbot-ZW | No |
| Scopedll | X | scopedll.exe | Added by the GEMA TROJAN! | No |
| MCX Updte | X | scorti.exe | Added by the RBOT-ARP WORM! | No |
| Mi7sft sdce | X | scorti.exe | Added by the RBOT.ELC BACKDOOR! | No |
| StartupCop Pro | U | scp.exe | Startup Cop Pro startup program manager from PC Magazine | No |
| dork | X | Trojan.Banker | Detected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %Root% | No |
| SC2 | X | scprot4.exe | Added by the AGENT.APP TROJAN! | No |
| Scr | X | scr.scr | Added by the OPASERV.T WORM! | No |
| W32.Scran | X | Scran.exe | Added by the NARCS WORM! | No |
| ScrapPad | N | Scrappad.exe | ScrapPad allows you to quickly and easily record notes, thoughts, messages, and just about anything you want. Use it like you use scrap paper | No |
| Micro CRC Protocol | X | scrc32.exe | Added by a variant of W32/Sdbot.worm. The file is located in %System% | No |
| Screen Calendar | U | scrcal.exe | Screen Calendar allows you to create custom desktop wallpapers with built in active calendar and scheduler | No |
| WMI Standard Event Consumer - Scripting | X | scrcons32.exe | Added by the RBOT-GRD WORM! | No |
| WMI Standard Event Consumer - hosting | X | scrcs.exe | Added by the IRCBOT.ATP WORM! | No |
| Microsoft Synchronization Manager | X | screen.exe | Added by the SDBOT-ACO WORM! | No |
| cursor | N | Screendragon_VS_Taskbar.exe | ScreenDragon video player | No |
| ScreenHunter 4.0 Free | N | ScreenHunter.exe | ScreenHunter by Wisdom Software Inc - "award-winning screen capture solution to capture your screen, print and edit." Free version | No |
| Wisdom-soft ScreenHunter 5.1 Free | N | ScreenHunter.exe | ScreenHunter by Wisdom Software Inc - "award-winning screen capture solution to capture your screen, print and edit." Free version | No |
| Wisdom-soft ScreenHunter 5.1 Pro | N | ScreenHunter.exe | ScreenHunter by Wisdom Software Inc - "award-winning screen capture solution to capture your screen, print and edit." Pro version | No |
| ScreenPrint32 | N | ScreenPrint32.exe | ScreenPrint32 screen capture software - can be launched manually | No |
| screenSHU | U | screenSHU.exe | ScreenSHU screen capture utility - required if you want to use the save to cloud feature | No |
| ScreenView | X | ScreenView.exe | ScreenView spyware | No |
| SecureClean4RegManager | N | scregmanager4.exe | WhiteCanyon SecureClean 4 disk cleaner - clean hard drive data, MRUs, temp files and more. Can be started manually | No |
| Microsoft Restore | X | scrgrd.exe | Detected by Trend Micro as WORM_SPYBOT.BR | No |
| scrhosh.exe1 | X | scrhosh.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData% | No |
| Microsoft Windows Update | X | scrhost.exe | Added by the RBOT-AOW WORM! | No |
| WindowSystemMonitor | X | scrhost.exe | Added by the TILEBOT-DV WORM! | No |
| Auto File System Conversion Utility | X | scricon.exe | Added by the SDBOT.EYB WORM! | No |
| RAX SYSTEM | X | scrigz.exe | Detected by Trend Micro as WORM_MYTOB.KR | No |
| Windows Update | X | scrigz.exe | Detected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %System% | No |
| script | ? | script.bat | Maybe associated with DOS on a Win9x machine | No |
| mozila | X | Script.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\mozilla | No |
| mozilla | X | Script.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\mozilla | No |
| ScriptSentry | Y | Scriptsentry.exe | Script Sentry from Jason's Toolbox. Blocks malicious scripts and allows safe scripts to run. Only required if you want it to check the file associations it guards at startup. It will function regardless. No longer available | No |
| VelocidadSimple | X | scrmain.exe | VelocidadSimple rogue optimization utility - not recommended | No |
| Crnsava | X | scrnsave.pif | Added by the SDBOT-ZV WORM! | No |
| Screen Saver | X | scrnsaver.scr | Added by the RBOT-AGP WORM! | No |
| Crnsavsund | X | scrnsund.pif | Added by the SDBOT-AJQ WORM! | No |
| Scroll-In-Mouse V2.0 | U | SCROLL.EXE | Toolkit for the Lynx-3D Net scroll mouse from QTronix. Required if you use the special features | No |
| MS Screen Saver | X | scrsave.scr | Added by the RBOT-AGT WORM! | No |
| scrss | X | scrss.exe | Added by the HACDEF-R TROJAN! | No |
| scrsvc | X | scrsvc.exe | Added by the AGENT-DS TROJAN! | No |
| ScrSvr | X | ScrSvr.exe | Added by the OPASERV WORM! | No |
| ScrSvrOld | X | ScrSvr.exe | Added by the OPASERV WORM! | No |
| System CSRSS Patch | X | scrtkfg.exe | Added by the RBOT-ADA WORM! | No |
| SystemOPsv | X | scrtvc32.exe | Added by a variant of the SPYBOT WORM! | No |
| sc | N | scrubxp.exe | ScrubXP - utility that deletes safe to remove files, cookies, browsing history, etc | No |
| screxe | ? | scruser2k.exe | ?? | No |
| scsa | X | scsa.exe | Detected by Dr.Web as Trojan.Inject1.153 and by Malwarebytes Anti-Malware as Worm.IMP.Trace. Note - this entry loads from the Windows Startup folder and the file is located in %AppData%\Win88E6680F | No |
| scsa | X | scsa.exe | Detected by McAfee as Generic Downloader.x and by Malwarebytes Anti-Malware as Worm.IMP.Trace. Note - this entry loads from the Windows Startup folder and the file is located in %AppData%\Win74630177 | No |
| Smart Connect Setup | U | SCSetup.exe | Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio | No |
| Scsi | Y | Scsi.exe | SCSI Miniport driver | No |
| Windows Space | X | scsrs.exe | Detected by McAfee as RDN/Generic Dropper!d and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| Winlogon | X | scssrr.exe | Detected by Sophos as Troj/Agent-LXB and by Malwarebytes Anti-Malware as Worm.Autorun | No |
| SecondChance | U | sctray.exe | Power Quest Second Chance. Sets checkpoints for saving a backup copy of the registry to a disk so you can restore it if you have a crash | No |
| SecureClean4Tray | N | sctray4.exe | WhiteCanyon SecureClean 4 disk cleaner - clean hard drive data, MRUs, temp files and more. Can be started manually | No |
| Logoff | Y | SCTUINotify.exe | Part of Windows SteadyState, which is designed to make life easier for people who set up and maintain shared computers - enabling the system administrator to prevent users from making changes to the system configuration, windows desktop, restricting program access, etc. It's intended for shared user environments such as internet cafés, libraries and schools but can be used in any environment. This entry displays the timeout messages on the restricted computer/account - which warns users how long they have until automatic log-off when they log-in and when there are only 2 minutes left | Yes |
| SCTUINotify | Y | SCTUINotify.exe | Part of Windows SteadyState, which is designed to make life easier for people who set up and maintain shared computers - enabling the system administrator to prevent users from making changes to the system configuration, windows desktop, restricting program access, etc. It's intended for shared user environments such as internet cafés, libraries and schools but can be used in any environment. This entry displays the timeout messages on the restricted computer/account - which warns users how long they have until automatic log-off when they log-in and when there are only 2 minutes left | Yes |
| Windows SteadyState - Session Timer Notify (UI) | Y | SCTUINotify.exe | Part of Windows SteadyState, which is designed to make life easier for people who set up and maintain shared computers - enabling the system administrator to prevent users from making changes to the system configuration, windows desktop, restricting program access, etc. It's intended for shared user environments such as internet cafés, libraries and schools but can be used in any environment. This entry displays the timeout messages on the restricted computer/account - which warns users how long they have until automatic log-off when they log-in and when there are only 2 minutes left | Yes |
| OmniPass | U | scureapp.exe | OmniPass from Softex Inc. - secure password management software | No |
| ttool | X | scvc.exe | Added by the BCKDR-OWM BACKDOOR! | No |
| Nortons AV SYSTEM | X | scvchost.exe | Detected by Trend Micro as WORM_RBOT.AMK | No |
| Configuration Loader | X | scvh0st.exe | Added by the AGOBOT-AX WORM! | No |
| Windows Framework | X | scvh0st.exe | Malware installed by different rogue security software including SpyKillerPro and the XP AntiVirus series | No |
| (Default) | X | scvhost.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.Gen. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %System% | No |
| AntiVir | X | scvhost.exe | Added by the AGENT-DSF TROJAN! | No |
| Config Loader | X | scvhost.exe | Detected by Symantec as W32.HLLW.Gaobot.AE or W32.HLLW.Gaobot.AO | No |
| Configuration Loader | X | scvhost.exe | Added by the AGOBOT-AAE and SDBOT.AR WORMS! | No |
| Generic Host Process | X | scvhost.exe | Detected by Kaspersky as Backdoor.Win32.Ciadoor.13.hx and by Malwarebytes Anti-Malware as Malware.Packer.T. The file is located in %System% | No |
| HKCU | X | Scvhost.exe | Detected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen | No |
| HKLM | X | Scvhost.exe | Detected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen | No |
| icq lite | X | scvhost.exe | Added by the AGENT-DSF TROJAN! | No |
| Internet Explorer Helper | X | scvhost.exe | Detected by Trend Micro as TSPY_BANKER.BYK and by Malwarebytes Anti-Malware as Trojan.Banker | No |
| load | X | Scvhost.exe | Added by the AUTORUN-AJ WORM! | No |
| Macromedia Flash Update | X | scvhost.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| Microsoft machine | X | scvhost.exe | Added by the RBOT.AEU TROJAN! | No |
| microsoft scvhost for windows | X | scvhost.exe | Added by the RANDEX-S WORM! | No |
| Microsoft Task Manager | X | scvhost.exe | Added by the MYTOB-IT WORM! | No |
| Microsoft TCP Service | X | scvhost.exe | Added by the AGOBOT-L WORM! | No |
| Microsoft Update | X | scvhost.exe | Added by the RBOT-AEM WORM! | No |
| Microsoft Update Machine | X | scvhost.exe | Added by the RBOT-GS WORM! | No |
| Microsoft Update Manager | X | scvhost.exe | Detected by Trend Micro as WORM_AGOBOT.AXJ | No |
| Microsoft Windows Updata | X | scvhost.exe | Added by the RBOT.CEM BACKDOOR! | No |
| msconfig | X | scvhost.exe | Added by the AGENT-DSF TROJAN! | No |
| MSN | X | scvhost.exe | Added by the IRCBOT-ZW WORM! | No |
| MSStartOptimizer | X | SCVHOST.EXE | Detected by Sophos as Troj/Dasmin-Fam | No |
| MsWinLibrary | X | scvhost.exe | Added by the BANKER-CLI TROJAN! | No |
| NTSF MICROSOFT SYSTEM | X | scvhost.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %System% | No |
| only23 | X | SCVHOST.exe | Added by the BCKDR-PUQ BACKDOOR! | No |
| Personal Computer | X | scvhost.exe | Added by the RBOT-AJE WORM! | No |
| Policies | X | Scvhost.exe | Detected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Backdoor.Agent.Pgen | No |
| RAS Connection Server | X | scvhost.exe | Added by the SDBOT.TOO BACKDOOR! | No |
| regsrv | X | scvhost.exe | Detected by Trend Micro as BKDR_AGOBOT.E | No |
| scvhost | U | scvhost.exe | Wiretap surveillance software - the file is located in %ProgramFiles%\Wiretap Professional. Uninstall this software unless you put it there yourself | No |
| scvhost | X | scvhost.exe | Detected by Kaspersky as Trojan.Win32.Mepaow.nfa and by Malwarebytes Anti-Malware as Backdoor.Delf. The file is located in %Windir% | No |
| scvhost | X | scvhost.exe | Detected by Sophos as W32/Agobot-LI. The file is located in %System% | No |
| scvhost.exe | X | scvhost.exe | Added by the LOHAV-N BACKDOOR! | No |
| Scvhost.exe | X | Scvhost.exe | Detected by Malwarebytes Anti-Malware as Trojan.Keylogger.KG. The file is located in %System%\Scvhost | No |
| Security Center | X | scvhost.exe | Added by the RBOT-TG WORM! | No |
| startkey | X | scvhost.exe | Added by the BIFROSE-PM TROJAN! | No |
| SunJavaUpdateSched | X | scvhost.exe | Added by the SDBOT-AVX WORM! | No |
| SVCHOST | X | scvhost.exe | Added by the MYTOB.E or MYTOB.G WORMS! | No |
| svchost.exe | X | scvhost.exe | Detected by McAfee as Generic.dx!bh3g and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| Svchosts | X | SCVHOST.EXE | Added by the AGOBOT-RQ BACKDOOR! | No |
| System Host | X | scvhost.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| SystemWindows | X | scvhost.exe | Added by the SILLYFDC-CG WORM! | No |
| Update Checker | X | scvhost.exe | Added by the AGENT-DSF TROJAN! | No |
| Windows Firewalll | X | scvhost.exe | Added by the RBOT-EK WORM! | No |
| Windows Service Host | X | scvhost.exe | Added by the SDBOT.N TROJAN! | No |
| Windows SQL management 1.33 | X | scvhost.exe | Added by the SPYBOT-OB WORM! | No |
| Windows UDP Control Center | X | scvhost.exe | Added by the PUSHBOT.EH WORM! | No |
| Windows Update | X | scvhost.exe | Detected by Sophos as W32/Sdbot-XT and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| Winmgr.exe | X | scvhost.exe | Detected by Trend Micro as WORM_AGOBOT.AFG | No |
| Winsock Driver | X | scvhost.exe | Added by the RBOT.AEU BACKDOOR! | No |
| WINTASK | X | scvhost.exe | Added by the MYTOB-I WORM! | No |
| Yahoo Messengger | X | SCVHOST.exe | Added by the SOHANA-V WORM! | No |
| Generic Host Process2 System Backup | X | scvhost2.exe | Added by the RBOT-BAH WORM! | No |
| Microsoft LSASS386 Protocol | X | scvhost32.exe | Added by a variant of the SPYBOT WORM! | No |
| Microsoft SCVHOST32 Protocol | X | scvhost32.exe | Detected by Trend Micro as WORM_RBOT.ADP | No |
| SVCHost Protocol32 | X | scvhost32.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| Generic Host Process326a System Backup | X | scvhost326a.exe | Added by a variant of W32/Sdbot.worm | No |
| Windows Services | X | scvhoste.exe | Detected by Symantec as W32.Spybot.OBZ and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen | No |
| Starter | X | scvhosting.exe | Added by the SDBOT.RU WORM! | No |
| starter | X | scvhostingg.exe | Added by the FORBOT-FB WORM! | No |
| AntiVir | X | scvhosts.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.SVCGen. The file is located in %Windir% | No |
| ICQ Lite | X | scvhosts.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.SVCGen. The file is located in %Windir% | No |
| Internet Explorer Helper | X | scvhosts.exe | Added by a variant of TSPY_BANKER.BYK and detected by Malwarebytes Anti-Malware as Trojan.Banker | No |
| Msconfig | X | scvhosts.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.SVCGen. The file is located in %Windir% | No |
| spoolsv | X | scvhosts.exe | Added by the SMALL-AW TROJAN! | No |
| Update Checker | X | scvhosts.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.SVCGen. The file is located in %Windir% | No |
| Windows Host Service | X | scvhosts.exe | Added by the SPYBOT.NLI WORM! | No |
| Windows Print Spooler | ? | SCVHOSTS.EXE | Suspicious due to the similarity to the valid "svchost.exe" file | No |
| Windows Update | X | scvhosts.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.SVCGen. The file is located in %Windir% | No |
| Yahoo Messengger | X | scvhosts.exe | Added by the SOHANNA-AH WORM! | No |
| 2941976dbb3ddf392f5f388f8fd2e055 | X | scvhot.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.SVR | No |
| QQKAV | X | scvhsot.exe | Detected by Sophos as W32/QQRob-ABX | No |
| Yahoo Messengger | X | SCVHSOT.exe | Added by the HAKAG-A WORM! | No |
| Microsoft Office Studio | X | scvhvst.exe | Added by the RANDEX.CST WORM! | No |
| Microsoft Update Manager | X | scvideo.exe | Added by the SDBOT-CVP WORM! | No |
| SYS1 | X | scvost.com | Added by the AUTOIT-JY WORM! | No |
| Yahoo Messengger | X | scvshosts.exe | Added by the TRAX-A WORM! | No |
| SCVSHTO | X | SCVSHTO.exe | Detected by Trend Micro as TROJ_VB.FPW and by Malwarebytes Anti-Malware as Email.Worm.NTO | No |
| Scvsrv32 | X | scvsrv32.exe | Added by the AGOBOT-PM BACKDOOR! | No |
| Vprocess | X | scvtw32.exe | Added by the AGOBOT-FR BACKDOOR! | No |
| Microsoft Windows Update | X | scvvhost.exe | Detected by Sophos as W32/Forbot-DH | No |
| Winsock2 wqr1s | X | SCVVHOST.EXE | Detected by Sophos as W32/Rbot-FSN | No |
| Yahoo Messengger | X | SCVVHSOT.exe | Added by the SILLYFDC-AE WORM! | No |
| Scxaxs | X | Scxaxs.exe | Added by the RUSKILL.CX BACKDOOR! | No |
| Adobe Acrobat Speed Launcher | N | SC_Acrobat.exe | Speeds up the time it takes to load older versions of the Adobe Acrobat PDF creation/editing utility. Loads "acrobat_sl.exe" which quickly opens and closes all of the files that Acrobat will use when the application starts - allowing virus protection software to check these programs and add them to the list of safe files. Not required for Acrobat to function properly | Yes |
| Monitor | U | SD Monitor.exe | "Transfer data quickly between your memory card and your computer with SanDisk's Readers, Writers and Adapters" | No |
| SystemDoctor 2006 Free | X | sd2006.exe | SystemDoctor rogue security software - not recommended, removal instructions here | No |
| Sd32info | X | sd32info.exe | Added by the CRYPTER.A TROJAN! | No |
| SDaemon | U | sdaemon.exe | PC Security from Tropical Software - "is the ultimate in computer security, offering multiple locking systems for the windows environment and internet. Lock files, monitor programs activities, even detect intruders!" | No |
| vccacA | X | sdaxzl.exe | Added by the SDBOT-RP WORM! | No |
| SpyDefense | Y | sdc.exe | SpyDefense spyware remover by Everest Labs - no longer available | No |
| start | X | sdcc.exe | Added by the AGENT.CSX TROJAN! | No |
| Direct settings | X | sdchost.exe | Added by the DAEMONI-I TROJAN! | No |
| Spybot-SD Cleaning | Y | SDCleaner.exe | Generated by Spybot - Search & Destroy 2 from Safer-Networking Ltd if it encounters files that cannot be deleted during runtime because they are locked by other processes | No |
| SDClientMonitor | U | sdclientmonitor.exe | LANDesk® Management Suite software component | No |
| Stardock Central | N | sdctray.exe | Stardock Central from Stardock Corporation - "is an enhanced download manager that enables users to install and manage Stardock's software products." Now replaced by the Impulse digital distribution platform | No |
| Call Function System32 | X | sddriver.exe | Added by a variant of the SDBOT BACKDOOR! | No |
| Scanner Detector | N | SDetect.exe | ScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the "GO" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the "GO" button | No |
| SDetect | N | SDetect.exe | ScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the "GO" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the "GO" button | No |
| server | X | sdfdsfsdf.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\Spynet | No |
| strkjhk | X | sdflkj3.exe | Added by an unidentified WORM or TROJAN - see here | No |
| Start Network Scanner Tool | U | sdFTP.exe | Part of Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents" | No |
| MsnExplorer | X | sdhch.exe | Added by the TACTSLAY.B TROJAN! | No |
| Scheduler | X | sdhch.exe | Added by the TACTSLAY.B TROJAN! | No |
| SvcH0st | X | sdhch.exe | Added by the TACTSLAY.B TROJAN! | No |
| WinAmpAgent | X | sdhch.exe | Added by the TACTSLAY.B TROJAN! | No |
| Server Daemon Host Manager | X | sdhost.exe | Added by the RBOT-GWC WORM! | No |
| SDIN Adapter | X | sdin.exe | Added by the FORBOT-AP WORM! | No |
| Winsock2 driver | X | SDJOIJE.EXE | Added by the SPYBOT.DR TROJAN! | No |
| Sdk**.exe [* = random char] | X | Sdk**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log | No |
| Sdk**32.exe [* = random char] | X | Sdk**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log | No |
| sdkupdate22 | X | SDK0mCORE.exe | Added by the FORBOT-DT WORM! | No |
| SDKcore Update Components2 | X | SDKC0R3.exe | Added by the RBOT-ABA WORM! | No |
| SDKCprords | X | SDKc55rezzz.exe | Added by the RBOT.VD WORM! | No |
| SDKz0r | X | SDKc55rezzz2.exe | Added by the SDBOT-UN WORM! | No |
| SDK Core Component | X | sdkcore.exe | Added by the SDBOT-WC WORM! | No |
| SDK Codre Function22 | X | sdkimddprovment2.exe | Added by the SDBOT-YJ WORM! | No |
| SDK Core Function | X | sdkimprovment.exe | Detected by Trend Micro as WORM_RBOT.BHL | No |
| SDK Core Function2 | X | sdkimprovment2.exe | Added by the SPYBOT.OGX WORM! | No |
| Mascro soft SDK updates2 | X | SDKrepair2.exe | Added by the SDBOT.BXM WORM! | No |
| Microsoft sdk temp | X | sdktemp.exe | Added by the RBOT-ANP WORM! | No |
| sdllxxxxxx.exe | X | sdllxxxxxx.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Root%\sdllxxxxxx.exe | No |
| MonitorSD | U | SDMonitor.exe | Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here | No |
| Files Driver | X | sdphost.exe | Added by the SDBOT-DKZ WORM! | No |
| SDPhotoBar.exe | N | SDPhotoBar.exe | SmartDraw Photo (now FotoFinsh) - "organize, enhance, print, and share your photos. It's also a powerful graphic editor for creating images and web graphics" | No |
| StartSecurDoc | U | SDPin.exe | SecurDoc from WinMagic Inc - "Provides full disk encryption to protect sensitive information stored on laptops, desktops and PDAs" | No |
| wqdfadads | X | sdqdad.exe | Added by the MULDROP.F TROJAN! | No |
| genserv path | X | sdqdqg.exe | Added by the SDBOT-RF WORM! | No |
| sdrss | X | sdrss.exe | Added by the SDBOT-SQ WORM! | No |
| sads | X | sdsa.exe | Added by the RBOT-PA WORM! | No |
| SSOmon | X | sdserver.exe | Detected by Malwarebytes Anti-Malware as Trojan.Vasdek. The file is located in %Temp% | No |
| cvmsyslpd | X | sdservss.exe | Added by the MAILBOT-BY TROJAN! | No |
| FlashPath Monitor | N | SDSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start → Programs | No |
| FlashPath Status | N | SDSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start → Programs | No |
| Windows Updater | X | sdsys.exe | Detected by Sophos as W32/Forbot-JG and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| Windows Updater 32 | X | sdsys.exe | Detected by Trend Micro as WORM_WOOTBOT.JG and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| SystemTraySD | U | SDSystemTray.exe | Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here | No |
| SDTray | U | sdtray.exe | System Tray access to RSA Keon Standalone Desktop (was Web PassPort) from RSA Security - which "makes it easy for our data center staff members to protect confidential customer financial data files with proven RSA Security encryption while locking down each of their individual PC desktops." The file is located in either %ProgramFiles%\RSA Security\RSA Keon Desktop\System or %ProgramFiles%\RSA Security\Web PassPort\Plug-In\system | No |
| SDTray | Y | SDTray.exe | System Tray access to and notifications for Spybot - Search & Destroy 2 from Safer-Networking Ltd. The file is located in %ProgramFiles%\Spybot - Search & Destroy 2 | Yes |
| Spybot - Search & Destroy | Y | SDTray.exe | System Tray access to and notifications for Spybot - Search & Destroy 2 from Safer-Networking Ltd. The file is located in %ProgramFiles%\Spybot - Search & Destroy 2 | Yes |
| TFS DesktopTray | U | SDTray.exe | System Tray access to the older TFS Desktop (which became BoKS Desktop and is now FoxT DesktopControl) from TFS Technology, Inc. (now Fox Technologies). Access management software which "allows for you to take control of local accounts on your Windows Desktop systems" | No |
| SDTray | Y | SDTrayApp.exe | System Tray access to an older version of Spyware Doctor antispyware from PC Tools | No |
| MSN Home | X | sdwd.exe | Added by the SDBOT.NR TROJAN! | No |
| PC Dynamics SdwMon32 | U | sdwmon32.exe | SafeHouse "Personal Privacy" protects and hides your private and personal photos, videos, files and folders by making them "invisible" and encrypted | No |
| SafeHouseSystemTray | U | SDWTRAY.EXE | SafeHouse "Personal Privacy" system tray icon - PP protects and hides your private and personal photos, videos, files and folders by making them "invisible" and encrypted | No |
| PSAXLSL | X | sdxl.exe | Detected by McAfee as RDN/Generic.dx!w and by Malwarebytes Anti-Malware as Trojan.Agent.TBU | No |
| sdxsys32 | X | sdxsys32.exe | Added by the BROGGER-A TROJAN! | No |
| sp | X | se.dll,DllInstall | STARTPAGE.M hijacker | No |
| Search-Exe | X | SE.exe | Search-Exe hijacker | No |
| Security essentials 2010 | X | SE2010.exe | Security Essentials 2010 rogue security software - not recommended, removal instructions here | No |
| updatesst | X | SE2010.exe | Security Essentials 2011 rogue security software - not recommended, removal instructions here | No |
| Se4nHWIDGen | X | SE4NHWIDGEN.exe | Detected by Dr.Web as Trojan.DownLoader8.18651 and by Malwarebytes Anti-Malware as Backdoor.Agent.SWD | No |
| st5h5ss5e4 | X | Trojan.Agent.WNL | Detected by Malwarebytes Anti-Malware as Trojan.Agent.WNL. The file is located in %AppData% | No |
| s5retys5er5 | X | Trojan.Agent.WNL | Detected by Malwarebytes Anti-Malware as Trojan.Agent.WNL. The file is located in %Windir% | No |
| [random name] | X | se?vices.exe | PurityScan adware | No |
| Seagate 2GHK2Q3E Product Registration | N | Seagate 2GHK2Q3E Product Registration.exe | LeaderTech's PowerREGISTER registration reminder for Seagate storage products | No |
| Seagate Product Registration | N | Seagate Product Registration.exe | LeaderTech's PowerREGISTER registration reminder for Seagate storage products | No |
| SeahawksScreenServer | U | SeahawksScreenServer.exe | Screensaver for the Seattle Seahawks NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supported | No |
| SeahawksScreenServerSvc | U | SeahawksScreenServer.exe | Screensaver for the Seattle Seahawks NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supported | No |
| sealmon | U | sealmon.exe | SealedMedia enables you to combine document protection and control with your existing applications - such as Microsoft Word, Microsoft Excel, Microsoft PowerPoint and Email | No |
| SearchAndDestroyMFC | X | Search And Destroy.exe | Search And Destroy rogue security software - not recommended, removal instructions here | No |
| search | X | search.cmd | Detected by Sophos as Troj/DwnLdr-KLV and by Malwarebytes Anti-Malware as Trojan.Tophos. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| search.cmd_ | X | search.cmd_.exe | Detected by Malwarebytes Anti-Malware as Trojan.Cossta. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| MoveSearch | X | Search.exe | Detected by Symantec as Adware.PigSearch and by Malwarebytes Anti-Malware as Adware.PigSearch. The file is located in %ProgramFiles%\wsearch | No |
| WhenUSearch | X | Search.exe | WhenUSearch adware | No |
| SearchAndDestroyScheduler | X | SearchAndDestroy.exe | Search And Destroy rogue security software - not recommended, removal instructions here | No |
| SearchAndDestroyT | X | SearchAndDestroy.exe | Search And Destroy rogue security software - not recommended, removal instructions here | No |
| mswspl | X | searchbarcash.exe | SearchBarCash adware | No |
| Search Defender | X | SearchDefender.exe | Installed by SpeedItUp without permission, along with PC-Checker. Detected by DrWeb as the STARTPAGE.ORIGIN TROJAN! | No |
| SearchEngineProtection | ? | SearchEngineProtection.exe | Installed with an older version of the Oberon Gamesbar from Oberon Media which is provided to "help fans of casual games have a quick and easy access to all the new games available to play. Part of Internet Explorer, the Gamesbar will keep your games at your fingertips." Powered by Google this probably protected the default search engine used | No |
| SearchEye SE.exe | X | SearchEye SE.exe | SearchEye adware | No |
| FBSearch | X | SearchGuardPlus.exe | Fast Browser Search/Search Guard Plus parasite - installed with "Make the Web Better" applications such as My Web Tattoo, My Face LOL and Google Easy Money Kit. See here and here for more information | No |
| Microsoft Config | X | searchindex.exe | Detected by Malwarebytes Anti-Malware as Trojan.Dropper. The file is located in %UserTemp% | No |
| WANTIVIRSERVICE | X | SearchIndexer.exe | Detected by McAfee as Ransom and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Windows Search (SearchIndexer.exe) service which runs a service and is located in %System%. This one is located in %AppData%\Microsoft | No |
| SearchLite | X | SearchLite.exe | Detected by McAfee as Generic.bfr | No |
| searchnav | X | searchnav.exe | SearchNav adware - IEFeatures/Popnav variant | No |
| SearchNavVersion | X | searchnavversion.exe | SearchNav adware - IEFeatures/Popnav variant | No |
| SSL | X | SearchNDestrou.exe | Added by the SDBOT-WG WORM! | No |
| Search On | X | searchon.exe | Search On adware | No |
| search On | X | searchon.exe | Detected by McAfee as Generic.bfr!ep and by Malwarebytes Anti-Malware as Adware.SearchOn | No |
| SearchPot | X | SearchPot.exe | SearchPot adware | No |
| Search Protection | U | SearchProtection.exe | "Yahoo! Search Protection will alert you if an attempt is made to change your default browser search engine from Yahoo!" | No |
| SearchProtection | U | SearchProtection.exe | "Yahoo! Search Protection will alert you if an attempt is made to change your default browser search engine from Yahoo!" | No |
| YSearchProtection | U | SearchProtection.exe | "Yahoo! Search Protection will alert you if an attempt is made to change your default browser search engine from Yahoo!" | No |
| SearchSetter | X | searchsetter[1].exe | Browser hijacker - redirecting to FindWhateverNow.com | No |
| SearchSettings | X | SearchSettings.exe | Vendio "Search Settings" foistware - reportedly installed without notice, see here and here | No |
| SearchSpy | X | SearchSpyMenu.exe | SearchSpy rogue spyware remover - not recommended, removal instructions here | No |
| SearchSquire[number] | X | SearchSquire[number].exe | SearchSquire adware | No |
| searchtolba | X | searchtolba.exe | Detected by McAfee as Generic.dx!bh3c and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| searchtolba.exe | X | searchtolba.exe | Detected by McAfee as Generic.dx!bh3c and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| SearchUpgrader | X | SearchUpgrader.exe | KeenValue adware | No |
| INWVIPGRHHAPVAHRVACEIYMAOQ | X | SearchWin.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker.SWGen. The file is located in %Temp% | No |
| KYSPXETYVHNCFPQGBAUVASFEWF | X | SearchWin.exe | Detected by McAfee as Generic Downloader.x and by Malwarebytes Anti-Malware as Trojan.Banker.SWGen | No |
| NCFHKGQVRCPYSMTXKTCDIUTEUÞ | X | SearchWin.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker.SWGen. The file is located in %Temp% | No |
| vagrdqegymkroaaofugmxemqag | X | SearchWin.exe | Detected by Dr.Web as Trojan.DownLoader7.12457 and by Malwarebytes Anti-Malware as Trojan.Banker.SWGen | No |
| vqqlxplxkloopbkhgfpvlwvjĂd | X | SearchWin.exe | Detected by Dr.Web as Trojan.DownLoader7.27975 and by Malwarebytes Anti-Malware as Trojan.Banker.SWGen | No |
| XEQCUUIRBTBMXLWGBMENPYCQF | X | SearchWin.exe | Detected by McAfee as PWS-Banker and by Malwarebytes Anti-Malware as Trojan.Banker.SWGen | No |
| SecureExpertCleaner | X | sec.exe | Secure Expert Cleaner rogue privacy program - not recommended, removal instructions here | No |
| run= | X | sec5dec.exe | Added by the ATAK.G WORM! | No |
| Second Copy | U | SecCopy.exe | Second Copy® by Centered Systems - "is the perfect automatic backup software designed for Windows XP and above. It makes a backup of your data files to another directory, internal or external hard disk or to a computer across the network" | No |
| Second Copy 2000 | U | SecCopy.exe | Second Copy® by Centered Systems - "is the perfect automatic backup software designed for Windows XP and above. It makes a backup of your data files to another directory, internal or external hard disk or to a computer across the network" | No |
| *Security Center | X | secctr.exe | Added by the SDBOT.BRO WORM! | No |
| secdrive.exe | X | secdrive.exe | Added by a variant of the SPYBOT WORM! See here | No |
| Secret | X | Secret.exe | Added by the DELF-LW TROJAN! | No |
| SECRETMAKER | U | secretmaker.exe | Secretmaker is a combination of eight privacy-defending programs, including Spam Fighter Pro, Worm Hunter, Pop-Up Killer, Banner Blocker, Cookie Eraser, Privacy Protector, History Cleaner, and Garbage Cleaner | No |
| Windows Update | X | SecretStub.exe | Detected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %Windir% | No |
| secserv.exe | X | secserv.exe | Detected by Panda as an EasySearch adware variant. Note - EasySearch modifies the Internet Explorer settings and may download programs onto the infected computer | No |
| Security Server DB | X | secserver.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| Security Service DB | X | secservice.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| secsrvrc | X | secsrvrc.exe | Detected by Kaspersky as Trojan-Spy.Win32.SCKeyLog.au | No |
| Network Security | X | secsvc.exe | Added by the RBOT-ALX WORM! | No |
| Security Service | X | secsvc.exe | Added by the RBOT-GGF WORM! | No |
| System Event Manager | X | secsvc.exe | Detected by Trend Micro as WORM_RBOT.BMY | No |
| secsvc32 | X | secsvcnt.exe | Added by the GLOBAL PATROL TROJAN! | No |
| Secsys | U | Secsys.exe | UltraSoft Key Interceptor surveillance software - uninstall this unless you put it there yourself! | No |
| Security Agent | X | securag.exe | Detected by Sophos as Troj/Bancban-F | No |
| Bat | X | secure2.bat | Added by the ZCREW.C TROJAN! | No |
| Compaq Computer Security | ? | Secure32.exe | ?? | No |
| Win32 Security Protocol | X | secure32.exe | Added by the RBOT-ETI WORM! | No |
| Winsecure Antivirus | X | Secureantivirus.exe | Added by a variant of the SPYBOT WORM! | No |
| MicrosoftCorp | X | securebind.exe | Added by the INJECT TROJAN! | No |
| MicrosoftNAPC | X | securebind.exe | Added by the INJECT TROJAN! | No |
| SecureCleaner | X | SecureCleaner.exe | SecureCleaner rogue spyware remover - not recommended, removal instructions here | No |
| SecureFighter | X | SecureFighter.exe | SecureFighter rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| SecureItPro | U | Secureitpro470p.exe | SecureIt Pro - lock your computer when you're not there, to stop malicious users from accessing your desktop | No |
| SecureKeeper | X | SecureKeeper.exe | SecureKeeper rogue security software - not recommended, removal instructions here. A member of the AntiAID family | No |
| Security Monitor | X | securemon.exe | Added by the SLENFBOT.ABH WORM! | No |
| Microsoft Information | X | securenet.exe | Added by the SDBOT.AJM WORM! | No |
| SecurePcAv | X | SecurePcAv.exe | SecurePcAv rogue security software - not recommended, removal instructions here. A member of the AntiAID family | No |
| Security Center Distribution | X | securesec.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| Security System | X | securesys.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| 2kowmeuswvw3 | X | securetystudio.exe | Security Inspector 2010 rogue security software - not recommended, removal instructions here | No |
| SecureVeteran | X | SecureVeteran.exe | SecureVeteran rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| SecureWarrior | X | SecureWarrior.exe | SecureWarrior rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| [random characters] | X | securewinload32x.exe | Added by the OPTIXP-N TROJAN! | No |
| Security Central | X | Security Central.exe | Security Central rogue security software - not recommended, removal instructions here | No |
| Security iGuard | X | Security iGuard.exe | Security iGuard rogue spyware remover - not recommended, removal instructions here | No |
| Security Monitor | X | Security Monitor.exe | Security Monitor 2012 rogue security software - not recommended, removal instructions here | No |
| Security Solution 2011 | X | Security Solution.exe | Security Solution 2011 rogue security software - not recommended, removal instructions here | No |
| 2kowmeuswvw3 | X | security.exe | AntiVirus Solution 2010 rogue security software - not recommended, removal instructions here | No |
| Disk Keeper | X | security.exe | Daosearch adware | No |
| Windows Security | X | security.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Temp% | No |
| Security 2009 | X | Security2009.exe | Security 2009 rogue security suite - not recommended, removal instructions here | No |
| Microsoft Security Update | X | security32.exe | Added by the DELF-JJ TROJAN! | No |
| Windows Security Update | X | security32.exe | Affilred adware | No |
| SecurityBoan | X | SecurityBoan.exe | SecurityBoan rogue security software - not recommended, removal instructions here | No |
| Aluria Security Center | N | SecurityCenter.exe | Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here | No |
| SecurityCenter | X | securitycenter.exe | Entry added by Desktop Security 2010, Antivirus Studio 2010 and other rogue security software - not recommended | No |
| Microsoft Secure Messenger.NET Service | X | securitychk.exe | Detected by Trend Micro as WORM_WOOTBOT.K | No |
| DCPstrApp | Y | SecurityDeviceInfoSetRegistryString.exe | Part of the Dell ControlPoint Security Manager - which "provides access to your security, user identification, fingerprint readers, and smartcard security technology". Dell ControlPoint is "designed to simplify and unify the execution of what should be simple system functions" and "integrates best-of-breed software and utility solutions into one helpful solution" | No |
| SecurityFighter | X | SecurityFighter.exe | SecurityFighter rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| 2kowmeuswvw3 | X | securityhelper.exe | AntiVirus System 2011 rogue security software - not recommended, removal instructions here | No |
| Antivirus Protection 2012 SH | X | securityhelper.exe | Antivirus Protection 2012 rogue security software - not recommended, removal instructions here | No |
| AntiVirus AntiSpyware 2011 Security | X | securitymanager.exe | Antivirus AntiSpyware 2011 rogue security software - not recommended, removal instructions here | No |
| Antivirus Protection 2012 SM | X | securitymanager.exe | Antivirus Protection 2012 rogue security software - not recommended, removal instructions here | No |
| Security Manager | U | SecurityManager.exe | A ComCast Internet software suite that provides a variety of features (firewall, popup blocker, parental controls, etc) to help ensure your computer is secure, and your information is kept private. Located in %ProgramFiles%\Comcast\Security Manager\app | No |
| Security Manager | X | securitymanager.exe | AntiVirus System 2011 rogue security software - not recommended, removal instructions here. Note - this is not the valid Comcast security program typically located in %ProgramFiles%\Comcast\Security Manager\app. This one is located in %AppData%\AntiVirus System 2011 | No |
| Security Monitor 2012 Security | X | securitymanager.exe | Security Monitor 2012 rogue security software - not recommended, removal instructions here | No |
| Security Solution 2011 Security | X | securitymanager.exe | Security Solution 2011 rogue security software - not recommended, removal instructions here | No |
| SecuritySoldier | X | SecuritySoldier.exe | SecuritySoldier rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| Security Inspector 2010 | X | Security_Inspector_2010.exe | Security Inspector 2010 rogue security software - not recommended, removal instructions here | No |
| SECWIZ98 | Y | SECWIZ98.EXE | Security Wizard 98 by Chris Farmer. Offers you a variety of ways to restrict access to many of the programs and settings on your PC. Available here | No |
| CLSID | X | sed.exe | OnlineDirect - Switch dialer and hijacker variant, see here | No |
| SESync | X | SED.exe | DownloadWare adware | No |
| gqvqevs | X | seeffkme.exe | Added by the SDBOT-QD WORM! | No |
| seekmo | X | seekmo.exe | Seekmo Search Assistant adware | No |
| SeekmoSA | X | SeekmoSA.exe | Seekmo Search Assistant adware | No |
| seeve | X | seeve.exe | Medload adware | No |
| SelectRebates | X | SelectRebates.exe | SelectRebates adware | No |
| FriendlyWebQuick-Launch | N | SELFCERT.EXE | selfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as well | No |
| SelfPrivacy | X | SelfPrivacy.exe | SelfPrivacy rogue security software - not recommended, removal instructions here | No |
| [various names] | X | seli.exe | MediaMotor adware | No |
| selmodevol | X | selmodevol.exe | Detected by Kaspersky as Trojan-PSW.Win32.LdPinch.angm | No |
| Roflcopteur | X | seman.exe | Added by an unidentified WORM or TROJAN! | No |
| SemanticInsight | X | SemanticInsight.exe | RXToolbar adware. Software that displays pop-up/pop-under advertisements when the primary user interface is not visible | No |
| Bron-Spizaetus | X | sempalong.exe | Added by the BRONTOK-E WORM! | No |
| SeMS | U | SeMS.exe | PCsms - tool that enables you to send sms text messages from your PC to any UK mobile phone | No |
| sender | X | sender.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %Windir%\help | No |
| SendMail | U | SendMail.exe | Part of the MySuperSPy surveillance software. Uninstall this software unless you put it there yourself. Located in %ProgramFiles%\Myss | No |
| X | sendmess.exe | Added by the SEMES TROJAN! | No | |
| System Error Notification | X | senr32.exe | Added by the POISON-BT TROJAN! | No |
| Sensiva | U | Sensiva.exe | Symbol Commander from Sensiva - makes the use of your PC, laptop, Tablet PC, and Pocket PC much easier and much faster. It recognizes your handwriting with unparalled performance and executes commands in a snap. Just by using your mouse, pen, or touchpad, simply draw symbols to execute actions instantly | No |
| SENS Keyboard V4 Launcher | U | SENSKBD.EXE | Hot-key manager for some Samsung notebooks - required if you use the keys | No |
| SENS Keyboard V6 Launcher | U | SENSKBD.EXE | Hot-key manager for some Samsung notebooks - required if you use the keys | No |
| Quick Heal AntiVirus | Y | sensor.exe | Part of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. Optionally scans the system boot area for programs trying to automatically execute before Windows loads and keeps a watch on some system files which are commonly patched (or replaced) by malware. Feature not supported on Windows 7/Vista systems. Also included by vendors who use the Quick Heal engine such as Omniquad and iQon | Yes |
| Sensor | Y | sensor.exe | Part of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. Optionally scans the system boot area for programs trying to automatically execute before Windows loads and keeps a watch on some system files which are commonly patched (or replaced) by malware. Feature not supported on Windows 7/Vista systems. Also included by vendors who use the Quick Heal engine such as Omniquad and iQon | Yes |
| Startup Scan | Y | sensor.exe | Part of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. Optionally scans the system boot area for programs trying to automatically execute before Windows loads and keeps a watch on some system files which are commonly patched (or replaced) by malware. Feature not supported on Windows 7/Vista systems. Also included by vendors who use the Quick Heal engine such as Omniquad and iQon | Yes |
| sentinelmon | U | sentinelmon.exe | PCSentinel's Smoking Gun! surveillance software. Uninstall this software unless you put it there yourself | No |
| CrisysTec Sentry | X | Sentry.exe | CrisysTec Sentry rogue privacy program - not recommended | No |
| SENTRY | X | SENTRY.exe | From IP Insight. Allows website owners "to instantly determine the precise geographic location, connection speed and detailed demographics of every visitor to your website". Will be detected by most firewalls and the majority of home users should disable it | No |
| RNBOStart | U | sentstrt.exe | Program used to initialise the VxD virtual driver for Sentinel drivers associated with Rainbow H/W keys that plug-in to the parallel port. These are usually supplied with workplace design tools and restrict the use of the software only to the machine to which the H/W key is connected. Required if you have such tools | No |
| Sepate Security Firewall | X | sepate.exe | Added by the RBOT.BLC BACKDOOR! | No |
| SEPCSuite | N | SEPCSuite.exe | System Tray access to Sony Ericsson PC Suite (now replaced by PC Companion) which "connects your phone to your computer and expands the capabilities of your phone". Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone | Yes |
| Sony Ericsson PC Suite | N | SEPCSuite.exe | System Tray access to Sony Ericsson PC Suite (now replaced by PC Companion) which "connects your phone to your computer and expands the capabilities of your phone". Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone | Yes |
| septpop06apsept | X | septpop06apsept.exe | MediaMotor.Popupwithcast adware | No |
| Windows Live Family | X | SEPWDN.EXE | Detected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Trojan.Agent.DPT | No |
| avnort | X | serbw.exe | Added by the SERFLOG.A WORM! | No |
| ltwob | X | serbw.exe | Added by the SERFLOG.A WORM! | No |
| serpe | X | serbw.exe | Added by the SERFLOG.A WORM! | No |
| mserv | X | seres.exe | Added by the AGENT-LIL WORM! | No |
| 36OSafeUpdate | X | seria.exe | Detected by Kaspersky as Trojan.Win32.Agent.fajk | No |
| Serials | X | serials.exe | Any one of a variety of worms and trojans | No |
| SERIAL UPDATE2013 | X | Serials2013.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.SR. The file is located in %AppData% | No |
| System Service | X | serious.exe | Added by the RBOT-FMV WORM! Note - deactivates the Microsoft Internet Connection Firewall (ICF) | No |
| ToolBar | X | seriusdat.exe | Detected by Microsoft as TrojanSpy:Win32/Bancos.ACJ | No |
| Microsoft WinUpdates | X | serm32.exe | Added by the RBOT.GE WORM! | No |
| SErmYcVkqxT | X | SErmYcVkqxT.exe | Added by the CEEINJEC-K TROJAN! | No |
| serrdctl.exe | Y | serrdctl.exe | "Shared Modem Service Client Event Viewer" - used when a number of PCs have access to a number of modems. Required to be running on each PC for access to the modems | No |
| serrv | X | serrv.exe | Added by the WAREZOV.DC WORM! | No |
| Microsoft Windows Services | X | Sersices.exe | Added by the SDBOT-NO WORM! | No |
| Configuration Loader | X | seru32.exe | Added by the SDBOT-VR WORM! | No |
| ISTRATOR | X | Seruice.exe | Detected by Malwarebytes Anti-Malware as Trojan.StartPage. The file is located in %Root% | No |
| Serv-U® File Server | U | Serv-U-Tray.exe | System Tray access for the Serv-U FTP server which allows the user to (amongst others) start the Management Console, stop the server and display notifications | Yes |
| Serv-U-Tray | U | Serv-U-Tray.exe | System Tray access for the Serv-U FTP server which allows the user to (amongst others) start the Management Console, stop the server and display notifications | Yes |
| ServUTrayIcon | U | Serv-U-Tray.exe | System Tray access for the Serv-U FTP server which allows the user to (amongst others) start the Management Console, stop the server and display notifications | Yes |
| Serv-U | N | serv-u32.exe | FTP server | No |
| Generic Service Process | X | serv1ces.exe | Added by the AGOBOT-JK WORM! | No |
| Service Manager | X | serv3manager.exe | Added by the SDBOT-AGO WORM! | No |
| Rout111 | X | serv454.exe | Added by the WOOTBOT.DB BACKDOOR! | No |
| Services Management Clients | X | servc.exe | Added by a variant of Backdoor.Rizo.A. The file is located in %System%\inetsrv | No |
| WINDOWS SYSTEM | X | servce.exe | Added by the MYTOB-EI WORM! | No |
| Servicer | X | servcr.exe | Detected by Trend Micro as TROJ_SDBOT.BAH | No |
| Microsoft Windows Update | X | servcs.exe | Added by the SDBOT.AL BACKDOOR! | No |
| Services Managements | X | servcs.exe | Added by the RBOT-GUC WORM! | No |
| Windows Update | X | servcshost.exe | Detected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %CommonFiles%\System | No |
| Key2 | ? | serve.exe | ?? | No |
| NDIS Adapter | X | Servenxp.exe | Added by the SPYBOT.LY WORM! | No |
| NDIS Adapter | X | servenxpp.exe | Added by the FORBOT-GP WORM! | No |
| server | X | server | Detected by Malwarebytes Anti-Malware as Stolen.Data. The file is located in %AppData% | No |
| Win32R | X | Server.com | Added by the ESTRELLA TROJAN! | No |
| sysser | X | server.dll | Added by the RAHACK WORM! | No |
| (Default) | X | server.exe | Detected by Malwarebytes Anti-Malware as Trojan.FakeMS. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %AppData% | No |
| 9bc84f151ed2d9df584248737dda5319 | X | server.exe | Detected by Dr.Web as Trojan.DownLoader7.9156 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| Adobe Updates | X | Server.exe | Detected by Kaspersky as Trojan-Spy.MSIL.Keylogger.hfu. Note - this is not a legitimate Adobe entry | No |
| babe8364d0b44de2ea6e4bcccd70281e | X | server.exe | Detected by McAfee as RDN/Generic PWS.y!lt and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| bead739c11b6815884fb1a13a48ced96 | X | Server.exe | Detected by Dr.Web as Trojan.DownLoader7.9439 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| bead739c11b6815884fb1a13a48ced96 | X | Server.exe | Detected by Dr.Web as Trojan.DownLoader7.9439 and by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Temp% | No |
| CAMFROG | X | server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. Note - this is not the legitimate Camfrog video chat software by Camshare Inc. The file is located in %System%\Install | No |
| Cerberus | X | server.exe | Detected by McAfee as W32/Pate.b | No |
| CesarFTP FTP Server | N | server.exe | CesarFTPd - FTP server | No |
| ctfmon | X | server.exe | Detected by Malwarebytes Anti-Malware as Trojan.Passwords. The file is located in %UserTemp% | No |
| dreams | X | server.exe | Added by a variant of W32/Sdbot.worm | No |
| easyServ | X | Server.exe | Added by the EASYSERV TROJAN! | No |
| EXPLORER | X | Server.exe | Detected by Malwarebytes Anti-Malware as Trojan.VBAgent. The file is located in %Windir% | No |
| EXPLORERS | X | Server.exe | Detected by McAfee as RDN/Generic.dx!bc and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| Face | X | server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Poison. The file is located in %UserTemp% | No |
| file | X | server.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor.DF. The file is located in %Windir% | No |
| HKCU | X | server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %AppData%\svchost.exe | No |
| HKCU | X | server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %ProgramFiles%\install | No |
| HKCU | X | server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\dir\install\WinUpdate | No |
| HKCU | X | server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\install | No |
| HKCU | X | server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\svchost.exe | No |
| HKCU | X | Server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %UserTemp%\InstallDir | No |
| HKCU | X | server.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor. The file is located in %System% | No |
| HKCU | X | Server.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %System%\%tamp% | No |
| HKCU | X | server.exe | Detected by Malwarebytes Anti-Malware as Worm.Autorun. The file is located in %System%\System | No |
| HKCU | X | server.exe | Detected by Kaspersky as Trojan-Dropper.MSIL.Agent.nws and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\install | No |
| HKCU | X | server.exe | Detected by Kaspersky as Trojan-Dropper.Win32.Agent.dvyh and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\install | No |
| HKCU | X | server.exe | Detected by Kaspersky as Trojan.Win32.Buzus.gpnn and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\dir\install\install | No |
| HKCU | X | Server.exe | Detected by Kaspersky as Trojan-Ransom.Win32.PornoBlocker.jmd and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\WinDir | No |
| HKCU | X | server.exe | Detected by Kaspersky as Trojan-Spy.Win32.Zbot.bhjn and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\directory\CyberGate\install | No |
| HKCU | X | server.exe | Detected by Kaspersky as Trojan-Spy.Win32.Zbot.bjhg and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\dir\install\spynet | No |
| HKCU | X | Server.exe | Detected by Kaspersky as Backdoor.Win32.Xtreme.bid and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %ProgramFiles%\InstallDir | No |
| HKCU | X | server.exe | Detected by McAfee as Generic PWS.y!1xx and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\Large | No |
| HKCU | X | server.exe | Detected by McAfee as PWS-Zbot.gen.lm and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Temp%\temp | No |
| HKCU | X | server.exe | Detected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\dir\install\msnmgr.exe\install | No |
| HKCU | X | Server.exe | Detected by McAfee as Generic.bfr!cs and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\WinDir | No |
| HKCU | X | Server.exe | Detected by McAfee as Generic.bfr!dd and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\Winlog | No |
| HKCU | X | Server.exe | Detected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\WinDir | No |
| HKCU | X | server.exe | Detected by Sophos as Troj/Agent-NLT and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\install | No |
| HKCU | X | server.exe | Detected by Sophos as Troj/Inject-XD and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\InstallDir | No |
| HKCU | X | server.exe | Detected by Sophos as W32/Rebhip-U and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\spynet | No |
| HKCU | X | server.exe | Detected by Trend Micro as TROJ_LETHIC.SMA and by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Windir%\InstallDir | No |
| HKLM | X | server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %AppData%\install | No |
| HKLM | X | server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %AppData%\svchost.exe | No |
| HKLM | X | server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %ProgramFiles%\install | No |
| HKLM | X | server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\dir\install\WinUpdate | No |
| HKLM | X | server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\svchost.exe | No |
| HKLM | X | Server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %UserTemp%\InstallDir | No |
| HKLM | X | server.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor. The file is located in %System% | No |
| HKLM | X | server.exe | Detected by Malwarebytes Anti-Malware as Worm.Autorun. The file is located in %System%\System | No |
| HKLM | X | server.exe | Detected by Kaspersky as Trojan-Dropper.MSIL.Agent.nws and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\install | No |
| HKLM | X | server.exe | Detected by Kaspersky as Trojan-Dropper.Win32.Agent.dvyh and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\install | No |
| HKLM | X | server.exe | Detected by Kaspersky as Trojan.Win32.Buzus.gpnn and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\dir\install\install | No |
| HKLM | X | Server.exe | Detected by Kaspersky as Trojan-Ransom.Win32.PornoBlocker.jmd and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\WinDir | No |
| HKLM | X | server.exe | Detected by Kaspersky as Trojan-Spy.Win32.Zbot.bhjn and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\directory\CyberGate\install | No |
| HKLM | X | server.exe | Detected by Kaspersky as Trojan-Spy.Win32.Zbot.bjhg and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\dir\install\spynet | No |
| HKLM | X | Server.exe | Detected by Kaspersky as Backdoor.Win32.Xtreme.bid and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %ProgramFiles%\InstallDir | No |
| HKLM | X | server.exe | Detected by McAfee as Generic PWS.y!1xx and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\Large | No |
| HKLM | X | server.exe | Detected by McAfee as PWS-Zbot.gen.lm and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Temp%\temp | No |
| HKLM | X | server.exe | Detected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\dir\install\msnmgr.exe\install | No |
| HKLM | X | Server.exe | Detected by McAfee as Generic.bfr!cs and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\WinDir | No |
| HKLM | X | Server.exe | Detected by McAfee as Generic.bfr!dd and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\Winlog | No |
| HKLM | X | Server.exe | Detected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\WinDir | No |
| HKLM | X | server.exe | Detected by Sophos as Troj/Agent-NLT and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\install | No |
| HKLM | X | server.exe | Detected by Sophos as Troj/Inject-XD and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\InstallDir | No |
| HKLM | X | server.exe | Detected by Sophos as W32/Rebhip-U and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\spynet | No |
| HKLM | X | server.exe | Detected by Trend Micro as TROJ_LETHIC.SMA and by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Windir%\InstallDir | No |
| hvytirdt eud | X | server.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %System%\install | No |
| jfjbgyeey eur | X | server.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %System%\install | No |
| Key Name | X | Server.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserTemp% | No |
| kill | X | server.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor.SVR. The file is located in %Windir% | No |
| microsoft | X | Server.exe | Detected by Sophos as W32/Rebhip-N and by Malwarebytes Anti-Malware as Trojan.Backdoor.XTR. The file is located in %Windir%\InstallDir | No |
| MicroUpdate | X | server.exe | Detected by McAfee as PWS-FAHB!EF21253AD423 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| msnmgr | X | Server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\InstallDir | No |
| pcServer | X | server.exe | Ssppyy spyware | No |
| Policies | X | server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %AppData%\svchost.exe | No |
| Policies | X | server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %ProgramFiles%\install | No |
| Policies | X | server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Root%\dir\install\WinUpdate | No |
| Policies | X | server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Root%\svchost.exe | No |
| Policies | X | server.exe | Detected by Malwarebytes Anti-Malware as Trojan.VirTool. The file is located in %ProgramFiles%\Large | No |
| Policies | X | server.exe | Detected by Malwarebytes Anti-Malware as Worm.Autorun. The file is located in %System%\System | No |
| Policies | X | server.exe | Detected by Kaspersky as Trojan-Dropper.MSIL.Agent.nws and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Root%\install | No |
| Policies | X | server.exe | Detected by Kaspersky as Trojan-Dropper.Win32.Agent.dvyh and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\install | No |
| Policies | X | server.exe | Detected by Kaspersky as Trojan.Win32.Buzus.gpnn and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Root%\dir\install\install | No |
| Policies | X | Server.exe | Detected by Kaspersky as Trojan-Ransom.Win32.PornoBlocker.jmd and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\WinDir | No |
| Policies | X | server.exe | Detected by Kaspersky as Trojan-Spy.Win32.Zbot.bhjn and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Root%\directory\CyberGate\install | No |
| Policies | X | server.exe | Detected by Kaspersky as Trojan-Spy.Win32.Zbot.bjhg and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Root%\dir\install\spynet | No |
| Policies | X | server.exe | Detected by McAfee as Generic PWS.y!1xx and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\Large | No |
| Policies | X | server.exe | Detected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Root%\dir\install\msnmgr.exe\install | No |
| Policies | X | server.exe | Detected by McAfee as RDN/Generic.bfr!z and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Windir%\Large | No |
| Policies | X | Server.exe | Detected by McAfee as Generic.bfr!cs and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Root%\WinDir | No |
| Policies | X | Server.exe | Detected by McAfee as Generic.bfr!dd and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\Winlog | No |
| Policies | X | Server.exe | Detected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Windir%\WinDir | No |
| Policies | X | server.exe | Detected by Sophos as Troj/Agent-NLT and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Windir%\install | No |
| Policies | X | server.exe | Detected by Sophos as W32/Rebhip-U and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\spynet | No |
| Policies | X | server.exe | Detected by Symantec as W32.Spyrat and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Root%\Dir\install | No |
| Policues | X | server.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %System%\install | No |
| Protection | X | server.exe | Detected by Sophos as Mal/VBInject-AS | No |
| Protection2 | X | server.exe | Detected by Sophos as Mal/VBInject-AS | No |
| RegistryKey | X | server.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %ProgramFiles% | No |
| RegistryKey | X | server.exe | Detected by Kaspersky as Trojan.Win32.Scar.bdjh and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System% | No |
| RegistryKey | X | server.exe | Detected by Kaspersky as Trojan.Win32.Scar.bwha and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %LocalAppData% | No |
| RegistryKey | X | server.exe | Detected by Kaspersky as Trojan.Win32.LogonInvader.a and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
| RegistryKey | X | server.exe | Detected by McAfee as Generic.mfr and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Windir% | No |
| RunProg | X | Server.exe | Detected by Trend Micro as BKDR_OPTIX.04.A and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| scvhost | X | Server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\InstallDir | No |
| Ser | X | Server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.SpyNet. The file is located in %AppData%\SpyNet - see here | No |
| Server | X | Server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\hoster | No |
| Server | X | Server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.SpyNet. The file is located in %AppData%\SpyNet - see here | No |
| Server | X | Server.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor.DF. The file is located in %ProgramFiles%\Windaws Messenger | No |
| Server | X | server.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence here ensures it runs when Windows starts | No |
| server | X | server.exe | Detected by Dr.Web as Trojan.MulDrop4.26221 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Server | X | Server.exe | Detected by Kaspersky as Backdoor.Win32.Xtreme.bid. The file is located in %ProgramFiles%\InstallDir | No |
| Server | X | Server.exe | Detected by McAfee as Generic BackDoor!fqc and by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Windir%\InstallDir | No |
| Server | X | Server.exe | Detected by McAfee as Keylog-Spynet.gen.g and by Malwarebytes Anti-Malware as Backdoor.SpyNet. The file is located in %System%\SpyNet | No |
| Server | X | Server.exe | Detected by McAfee as RDN/Generic BackDoor!p and by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %System%\InstallDir | No |
| Server | X | Server.exe | Detected by McAfee as RDN/Generic.dx!dq and by Malwarebytes Anti-Malware as Trojan.Sasfis. The file is located in %Temp% | No |
| Server | X | Server.exe | Detected by McAfee as RDN/Generic.dx!ev and by Malwarebytes Anti-Malware as Backdoor.SpyNet. The file is located in %Windir%\SpyNet | No |
| Server | X | server.exe | Detected by McAfee as PWS-FAHB!EF21253AD423 and by Malwarebytes Anti-Malware as Trojan.Sasfis. The file is located in %UserProfile%\Cookies\InstallDir | No |
| server | X | server.exe | Detected by Sophos as Troj/Singu-Q and by Malwarebytes Anti-Malware as Trojan.Sasfis. The file is located in %Windir% | No |
| server | X | server.exe | Detected by Trend Micro as WORM_DELTAD.A. The file is located in %Windir% and %System% | No |
| SERVER.EXE | X | SERVER.EXE | Added by the BUSHTRO122 or SMOKODOOR TROJANS! | No |
| server.exe1 | X | server.exe | Detected by Kaspersky as Backdoor.Win32.Bifrose.ahrh and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| SESTIEMS | X | Server.exe | Detected by McAfee as RDN/Generic.dx!bc and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| Spy-Net | X | server.exe | Detected by Trend Micro as BKDR_POISON.IM. The file is located in %System%\Spy-Net | No |
| SQL | X | server.exe | Added by the PUNYA-B WORM! | No |
| sservices | X | server.exe | Detected by McAfee as Generic PWS.di | No |
| startkey | X | server.exe | Detected by Sophos as Troj/Bifrose-DB and by Malwarebytes Anti-Malware as Trojan.Backdoor.NR | No |
| svchost.exe | X | server.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %UserTemp% | No |
| System | X | server.exe | Detected by Malwarebytes Anti-Malware as Trojan.Inject.DF. The file is located in %AppData% | No |
| System Services Monitor | X | server.exe | Bifrost malware | No |
| test | X | server.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor.DF. The file is located in %Windir% | No |
| Win32 | X | server.exe | Detected by Kaspersky as Trojan.Win32.Llac.bsvc and by Malwarebytes Anti-Malware as Worm.Autorun. The file is located in %System%\install | No |
| WINLOGON | X | Server.exe | Detected by McAfee as Generic.bfr!dd. The file is located in %Root%\WinDir | No |
| WO99g66W99qY | X | server.exe | Detected by Malwarebytes Anti-Malware as Trojan.VBInject. The file is located in %System%\install | No |
| serverex | X | Server.txt.vbs | Detected by Trend Micro as WORM_DELTAD.A | No |
| winserver | X | Server.txt.vbs | Detected by Trend Micro as WORM_DELTAD.A | No |
| ZtgServerSwitch | X | server.vbs | ZTGServerswitch is part of Sony's Vaio support agent - designed by Support.com. Not required if the user does not wish to use the Vaio support agent and regarded as spyware | No |
| Server Backbone | X | server05.exe | Added by the RBOT-ZM WORM! | No |
| QUEMAJUNBINOPOLIS | X | Server1.exe | Detected by McAfee as Generic VB.n and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| Windows Defender | X | Server1.exe | Detected by McAfee as Generic Dropper.acj and by Malwarebytes Anti-Malware as Trojan.Agent.Gen | No |
| Server201112R | X | Server201112R.exe | Detected by Sophos as Troj/DotNet-G and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| HKCM | X | server32.exe | Detected by Malwarebytes Anti-Malware as Wor.Rebhip. The file is located in %System%\Large | No |
| HKLM | X | server32.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\Large | No |
| Policies | X | server32.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\Large | No |
| Server4PC | Y | Server4PC.exe | Satellite receiver control program that is responsible for handling TV, radio and internet - on systems from TechniSat for example | No |
| WindowsAPI.DLL | X | Server5.exe | Added by the "Fear and Hope" TROJAN! | No |
| [random name] | X | Servere.exe | Added by the LEGMIR-AQM TROJAN! | No |
| HKCU OKOKO | X | servero.exe | Detected by McAfee as Generic PWS.di | No |
| HKLM OOKO | X | servero.exe | Detected by McAfee as Generic PWS.di | No |
| Policies | X | servero.exe | Detected by McAfee as Generic PWS.di and by Malwarebytes Anti-Malware as Backdoor.Agent.Pgen | No |
| Serverx | X | Serverx.exe | Added by the MADANGEL VIRUS! | No |
| Policies | X | serverz.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Windir%\install | No |
| Server_1 | X | Server_1.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| SearchNet_Up | X | ServeUp.exe | SearchNet adware | No |
| run windows | X | servic.bat | Added by the REBOOT-AP TROJAN! | No |
| Microsoft .Net Framework | X | servic.exe | Detected by Sophos as Troj/Agent-GUU | No |
| Microsoft Update 32 | X | servic.exe | Added by the RBOT-AXN WORM! | No |
| Sygate Personal Firewall Start | X | servic.exe | Detected by Sophos as W32/Rbot-RY | No |
| WINDOWS SYSTEMn | X | servicces.exe | Added by the MYTOB-EL WORM! | No |
| services.exe | X | service.bat | Added by the MDROP-BSW TROJAN! | No |
| 12ZFG94-F641-2SF-K31P-5N1ER6H6L2 | X | service.exe | Detected by Trend Micro as WORM_SILLY.LC | No |
| AdobeReaderPro | X | service.exe | Added by the RBOT-BCA WORM! | No |
| antivirus | X | service.exe | Detected by Dr.Web as Trojan.Inject1.19802 and by Malwarebytes Anti-Malware as Trojan.Agent.AV | No |
| Config | X | service.exe | Added by the ISRAZ.B WORM! | No |
| Configuration Loader | X | Service.exe | Detected by Symantec as W32.HLLW.Gaobot.AO | No |
| itunes.exe | X | Service.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Temp%\AppLaunch | No |
| MDNS | X | service.exe | Mirar adware variant | No |
| MICROSOFT | X | service.exe | Detected by McAfee as Generic.bfr!eh | No |
| Microsoft Security Monitor Process | X | service.exe | Added by the DELF.BERW BACKDOOR! | No |
| Microsoft Service | X | service.exe | Added by the IRCBOT-XX BACKDOOR! | No |
| Microsoft Update | X | service.exe | Added by a variant of the RBOT WORM! See here | No |
| Microsoft Updates | X | service.exe | Added by the POISON.HPT BACKDOOR! | No |
| MSN BETA | X | service.exe | Detected by Trend Micro as WORM_RBOT.AUU | No |
| Myapp | X | service.exe | Homepage hijacker | No |
| r_server | X | service.exe | Added by the MULTIDR-CP TROJAN! | No |
| Registry Value Name | X | service.exe | Added by the RBOT-AHT WORM! | No |
| RunServices | X | service.exe | Detected by Symantec as W32.Vebisp | No |
| Securenet | X | service.exe | Detected by Malwarebytes Anti-Malware as Spyware.Keylogger. The file is located in %Root%\Drivers\chipset | No |
| Service | X | Service.exe | Detected by Malwarebytes Anti-Malware as Trojan.VB. The file is located in %Windir% | No |
| Service Controller | X | service.exe | Added by the PREVERT TROJAN! | No |
| service manager | X | service.exe | Added by the DONBOMB.A TROJAN! | No |
| Service Process | X | service.exe | Added by the DCMBOT-C TROJAN! | No |
| Service.exe | X | Service.exe | "servedby.advertising" popup generator | No |
| service.exe | X | service.exe | Detected by Malwarebytes Anti-Malware as Spyware.Passwords. The file is located in %UserProfile%\Desktop | No |
| servicemng | X | service.exe | Added by the TAME-C WORM! | No |
| shell | X | service.exe | Detected by Dr.Web as Trojan.DownLoader6.9480 and by Malwarebytes Anti-Malware as Trojan.Agent.cn | No |
| SYS_CLEAN | X | Service.exe | Added by the FLOPCOPY WORM! | No |
| System Service | X | Service.exe | Detected by Dr.Web as Trojan.Inject.63084 and by Malwarebytes Anti-Malware as Worm.AutoRun | No |
| System Service Application | X | service.exe | Detected by Dr.Web as Win32.HLLW.SpyBot.662 | No |
| systr2 | X | SERVICE.exe | Added by the VB-DQY WORM! | No |
| VMGOATPOSTREBOOTANALYSIS | X | service.exe | Detected by McAfee as Scar.gen.c and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Win32 USB2.0 Driver | X | service.exe | Added by the SDBOT-QF WORM! | No |
| WinDLL (service.exe) | X | service.exe | Added by the AGENT.BX WORM! The "service.exe" file is found in %System% | No |
| Windows Net Cfg | X | service.exe | Added by a variant of the RBOT WORM! | No |
| Windows Screensaver | X | Service.exe | Added by the KELVIR.P WORM! | No |
| Windows Service | X | service.exe | Added by the IRCBOT-ACV WORM! | No |
| Windows Services | X | service.exe | Detected by Symantec as W32.Randex.R and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen | No |
| Windows svchost | X | service.exe | Added by the PUSHBOT.DU WORM! | No |
| Windows Taskmanager | X | service.exe | Added by the PUSHBOT.OR WORM! | No |
| Windows Updates Svcs | X | service.exe | Detected by Dr.Web as BackDoor.IRC.Bot.1050 | No |
| Windows_Serivce | X | SERVICE.exe | Added by the WOOTBOT.AH WORM! | No |
| WindowsService | X | service.exe | Added by the AUTORUN-VPC WORM! | No |
| WindowsServices | X | service.exe | Detected by Symantec as W32.Folmess and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| WinPatrol | X | service.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not a legitimate WinPatrol entry and the file is located in %Windir%\services\rc0 | No |
| Clean up | X | service.exe cleanup.bat | Added by the AGENT-FPY TROJAN! | No |
| Windows smss service | X | service.exe smss.exe | Added by the AGENT-FPY TROJAN! | No |
| Service | X | Service.pif | Added by the ASSIRAL-C WORM! | No |
| Service2 | X | Service2.exe | Identified as a variant of the Win32.Iroffer malware. Located in %Windir%\Drivers\Intel | No |
| Windows Services | X | service2.exe | Detected by Sophos as Mal/VB-ZH and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen | No |
| Windows Update | X | service2.exe | Detected by Sophos as Mal/VB-ZH and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| ICU-Sucker | X | Service32.exe | Detected by Kaspersky as Trojan-Notifier.Win32.IllNotifier.d | No |
| Kernel Services | X | service32.exe | Added by the PRX-B TROJAN! | No |
| Microsoft Service Manager | X | service32.exe | Added by the IRCBOT.WDW BACKDOOR! | No |
| service32 | X | service32.exe | Added by the AGOBOT-ST WORM! | No |
| Configuration Loader | X | service5.exe | Added by the GAOBOT.AF WORM! | No |
| MS Security Hotfix | X | service5.exe | Added by the GAOBOT.AG WORM! | No |
| pushbot | X | service52.exe | Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger | No |
| Windows svchost | X | serviceaaa.exe | Added by the PUSHBOT.ER WORM! | No |
| Windows svchost | X | serviceam.exe | Added by the PUSHBOT.EY WORM! | No |
| Windows svchost | X | servicean.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| WinLsass | X | servicec.exe | Added by the SCANE WORM! | No |
| Bredbandsbolaget | Y | servicecenter.exe | Related to the Brebband Swedish Broadband provider | No |
| serviceconnect | X | serviceconnect.exe | Added by the AGOBOT.AIR WORM! | No |
| WindowsServicesH | X | servicedhs.exe | Added by the AGOBOT-JD WORM! | No |
| Microsoft DLL Service | X | servicedll.exe | Added by the IRCBOT.OX BACKDOOR! | No |
| 1516b75c7179ba2f46b75e97c37e84fc | X | servicee.exe | Detected by Dr.Web as Trojan.DownLoader8.37194 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ | No |
| Windows Updater | X | ServiceHost.exe | Detected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %Windir% | No |
| servicelayer | X | servicelayer.exe | Added by the RENOS.FJ TROJAN! Note - do not confuse this with the Nokia service of the same name which resides in %CommonFiles%\PCSuite\Services or %Program Files%\PC Connectivity Solution. This one is located in %Windir% | No |
| Windows Service Exec | X | ServiceLayer.exe | Added by the SPYBOT-OI WORM! Note - do not confuse this with the Nokia service of the same name which resides in %CommonFiles%\PCSuite\Services or %Program Files%\PC Connectivity Solution. This one is located in %Windir% | No |
| USB Device | X | servicelog.exe | Detected by Trend Micro as WORM_WOOTBOT.CB | No |
| Wind Logd File | X | servicelogd.exe | Added by a variant of Win32/Rbot | No |
| Service Manager | X | SERVICEMGR.EXE | Added by the PASSMAIL-D VIRUS! | No |
| Microsoft Servicez Manager | X | servicemgrz.exe | Added by the RBOT-ASN WORM! | No |
| System Service | X | servicent.exe | Added by the RBOT-AJI WORM! | No |
| MicrosoftXP Service Pack 2 | X | servicepack2.exe | Added by the RBOT.EMC BACKDOOR! | No |
| [various names] | X | Serviceprocess.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| SVEEHOST | X | services | Detected by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| SVEEHOST.EXE | X | services | Detected by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| WindowsNT Services | X | Services.com | Detected by Bitdefender as the DELF.OFC TROJAN! See here | No |
| WinCheck | X | services.exe | Detected by Symantec as W32.Sober.V@mm and by Malwarebytes Anti-Malware as Email.Worm.SB. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft and note the space at the beginning of the "Startup Item" field | No |
| WinData | X | services.exe | Added by the SOBER-AD WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\PoolData and note the space at the beginning of the "Startup Item" field | No |
| Windows | X | services.exe | Added by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\WinSecurity and note the space at the beginning of the "Startup Item" field | No |
| WinINet | X | services.exe | Added by the SOBER.R WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus and note the space at the beginning of the "Startup Item" field | No |
| WinStart | X | services.exe | Added by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Connection Wizard\Status and note the space at the beginning of the "Startup Item" field | No |
| .Prog | X | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! | No |
| [random name] | X | services.exe | PurityScan adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! | No |
| _SystemBoot | X | services.exe | Added by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help\Help | No |
| _WinCheck | X | services.exe | Detected by Symantec as W32.Sober.V@mm and by Malwarebytes Anti-Malware as Email.Worm.SB. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft | No |
| _WinData | X | services.exe | Added by the SOBER-AD WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\PoolData | No |
| _Windows | X | services.exe | Added by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\WinSecurity | No |
| _WinINet | X | services.exe | Added by the SOBER.R WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus | No |
| _WinStart | X | services.exe | Added by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Connection Wizard\Status | No |
| {357AA41A-B7A8-4632-A27D-5B980B25CF43} | X | services.exe | FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the "inetsrv" subfolder | No |
| AdRotator.Application | X | services.exe | FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the "inetsrv" subfolder | No |
| Amie Release V6.9D | X | services.exe | Added by the VB-EAN TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| AutoAdministrator | X | SERVICES.EXE | Detected by Sophos as W32/Punya-A. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\Application Data\WINDOWS | No |
| AutoUpdate32 | X | services.exe | Added by WINSPY.88! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64 | No |
| b60511fd42ef6c7d1c6ac6218d09f059 | X | services.exe | Detected by Dr.Web as Trojan.DownLoader8.32059 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile% | No |
| BaRloNdDiLhep | X | services.exe | Added by the AUTORUN.DIB WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder | No |
| BuildLab | X | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! | No |
| ccApps | X | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! | No |
| ComMessenger32 | X | services.exe | Detected by Dr.Web as Trojan.PWS.Siggen.40403 and by Malwarebytes Anti-Malware as Backdoor.Agent. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\data | No |
| ConfigVir | X | services.exe | Added by the AUTORUN-DV WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder | No |
| DDXPPXCE | X | services.exe | Detected by Sophos as Mal/Autorun-AH | No |
| DHCP32 | X | services.exe | Detected by Kaspersky as Trojan-Spy.Win32.WinSpy.ag. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\display | No |
| exec | X | services.exe | Added by the AGENT-ZJ MALWARE! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\fonts | No |
| Flash Media | X | services.exe | Detected by Symantec as Backdoor.IRC.Bot. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserTemp% | No |
| FriendlyTypeName | X | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! | No |
| Golum | X | services.exe | Added by the GOLUM.A TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! | No |
| golumm | X | services.exe | Added by the DLOADER-ET TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "golumm" subfolder | No |
| Kernel | X | services.exe | Added by the FOOZ-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| LiveUpdate32 | X | services.exe | Added by the VB.BAU BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas | No |
| Local Service | X | services.exe | Added by the P2PWORM-T WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Cursors | No |
| Microsoft (R) Windows Protected Content Restoration Service | X | services.exe | Detected by Trend Micro as BKDR_AGENT.AGV. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\etc | No |
| Microsoft (R) Windows TCP/IP Socket Layer | X | services.exe | Added by the RBOT.ARM BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\winsock | No |
| Microsoft Service Controller | X | services.exe | Added by the KALEL-D WORM! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! | No |
| Microsoft Services | X | services.exe | Added by the ALETS TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Microsoft Updat | X | services.exe | Added by the MSIL.ELASROFAH TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Internet Explorer | No |
| Microsoft Visual SourceSafe | X | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! | No |
| Microsoft Windows | X | services.exe | Detected by Malwarebytes Anti-Malware as Backdoor.IRCBot. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData% | No |
| Microsoft Windows Update Client | X | services.exe | Added by the AUTORUN.DVE WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Microsofts | X | services.exe | Detected by Dr.Web as Trojan.Inject.62622. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsofts | No |
| MSN32 | X | services.exe | Detected by McAfee as Generic PWS.y. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msapps | No |
| MSOffice | X | services.exe | Added by the DLOADER-EU TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an "MSOffice" subfolder | No |
| msservices | X | services.exe | MsnSpyMaster surveillance software. Uninstall this software unless you put it there yourself! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an "msystem" sub-directory | No |
| MSWUpdate | X | services.exe | Added by the VB-FDP TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData% | No |
| Net | X | services.exe | Added by the BRAVO-C TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Norton Auto-Protect | X | SERVICES.exe | Added by the AHKER.B WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%. Also, this is not part of Norton AV | No |
| NTSet32 | X | services.exe | Added by the WINSPY-C TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\dll32 | No |
| PagefileManager | X | services.exe | Detected by Dr.Web as BackDoor.Poison.9892 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\Pagefile System Volume | No |
| RegDone | X | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! | No |
| RPCser32g | X | services.exe | Added by the RITDOOR-C WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| RPCser32g1 | X | services.exe | Added by the PREX.D WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| RPCser32g3 | X | services.exe | Added by the PREXOT.D BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| RPCser32g4 | X | services.exe | Added by the PREXOT.E BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| RPCserv32 | X | services.exe | Added by the MYDOOM.AL WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| RPCserv32g | X | SERVICES.EXE | Detected by Trend Micro as WORM_BOBAX.AD. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| run | X | services.exe | Detected by Sophos as Troj/Krepper-N and variants and by Malwarebytes Anti-Malware as Trojan.Downloader. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\inet10066 | No |
| runservices | X | services.exe | Detected by McAfee as BackDoor-DUM. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| scssrr.exe | X | Services.exe | Added by the VB-EMX TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Service<user> | X | SERVICES.EXE | Detected by Sophos as W32/Brontok-BH. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%\WINDOWS | No |
| ServiceAdministrator | X | SERVICES.EXE | Detected by Symantec as W32.Korron.B. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%\WINDOWS | No |
| SERVICEADMINISTRATOR.[ComputerName] | X | SERVICES.EXE | Detected by McAfee as Generic VB.i and by Malwarebytes Anti-Malware as Trojan.FakeAlert. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%\WINDOWS | No |
| ServiceControlApp | X | services.exe | Detected by Symantec as W32.SillyFDC.BDO. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root% | No |
| Servicee | X | services.exe | Added by the AGENT.DEI TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Servicerepclient1 | X | SERVICES.EXE | Detected by Sophos as W32/Brontok-BT and variants! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%\WINDOWS | No |
| Services | X | services.exe | Added by a number of VIRUSES, WORMS and TROJANS! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup! | No |
| services | X | Services.exe | Detected by Malwarebytes Anti-Malware as Worm.Spambot. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\1C110F2A | No |
| services | X | services.exe | Detected by Dr.Web as Trojan.DownLoader6.3759 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft | No |
| Services | X | Services.exe | Detected by Symantec as Trojan.Syginre. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Services Control Manager | X | services.exe | Added by the DELF-CGI TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! | No |
| Services Controller | X | services.exe | Added by the CIADOOR-F TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Services Logon | X | services.exe | Detected by Symantec as W32.Crowt.A@mm. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Templates% | No |
| Services Network | X | Services.exe | Added by the SWISYN-E WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! | No |
| Services Process | X | services.exe | Spyware - detected by Kaspersky as the SMALL.X TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! | No |
| Services Startup | X | services.exe | Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %CommonFiles% | No |
| services.exe | X | services.exe | Detected by Malwarebytes Anti-Malware as Trojan.VBKrypt. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% and loads from the HKLM\Run key | No |
| Services.EXE | X | services.exe | Detected by Symantec as W32.HLLW.Kazping. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% and loads from the HKLM\Run & HKLM\RunServices keys | No |
| Services++ | X | services.exe | Added by the SILLYFDC.BDM WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\RECYCLER | No |
| ServicesAdministrator | X | SERVICES.EXE | Detected by Sophos as W32/Punya-B and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%\WINDOWS | No |
| Servicesara | X | services.exe | Detected by Sophos as W32/Brontok-BS and by Malwarebytes Anti-Malware as Backdoor.Agent. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%\WINDOWS | No |
| Spooler de Impress | X | services.exe | Added by the AGENT-NEX TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %User% | No |
| sservices | X | services.exe | SpyOnePro spyware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\sopdir | No |
| SuperBar.Component | X | services.exe | Added by the SMALL-AQ TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the "inetsrv" subfolder | No |
| sysinit | X | services.exe | Added by the NEWLFRM-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\golumm | No |
| SysService | U | SERVICES.EXE | NSKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\NSkeylogger | No |
| SysServices | X | SERVICES.EXE | Added by the DELF-EY TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| system | X | services.exe | Added by the DELF-LQ TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\HELP | No |
| System Update2 | X | services.exe | Detected by Sophos as Troj/Autotroj-C. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! | No |
| SystemBoot | X | services.exe | Added by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help\Help | No |
| SystemCheck | X | services.exe | Added by the SOBER-M WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Config\system | No |
| Taskhost | X | services.exe | Detected by Dr.Web as Trojan.Packed.23496 and by Malwarebytes Anti-Malware as Trojan.Buterat. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData% | No |
| TEXTCONV | X | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! | No |
| Torjan Program | X | services.exe | Added by the AUTEX.C WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| ttplay | X | services.exe | Detected by Malwarebytes Anti-Malware as Trojan.ChinAd. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %CommonFiles%\Tencent | No |
| upDpacketo | X | services.exe | Detected by Sophos as W32/Nafbot-A and by Malwarebytes Anti-Malware as Worm.P2P. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| WinCheck | X | services.exe | Added by the SOBER.S WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft | No |
| Windows | X | services.exe | Added by the DLOADR-GW TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "Windows" subfolder | No |
| Windows | X | services.exe | Added by the SOBER-Z WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\WinSecurity | No |
| Windows Desktop | X | services.exe | Added by the DWNLDR-JAN TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Windows Logon Application | X | services.exe | Added by the CIADOOR-L TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Windows Service | X | services.exe | Detected by Sophos as W32/Kalel-A. Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! | No |
| Windows Service Controller | X | services.exe | Added by the KALEL-B WORM! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! | No |
| Windows Service Host | X | services.exe | Detected by Sophos as Mal/Autorun-BB and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\microsoft | No |
| Windows Services | X | services.exe | Detected by Sophos as Troj/Agent-MVC and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| WINDQ32_TRLV | X | services.exe | Detected by McAfee as Generic VB.z and by Malwarebytes Anti-Malware as Trojan.Downloader. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Winqows Publrlv | No |
| winsrv3 | X | services.exe | Detected by Sophos as W32/Nafbot-A and by Malwarebytes Anti-Malware as Worm.P2P. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| WMAudio | X | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! | No |
| WSVCS | U | SERVICES.EXE | WSLogger keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a WALI\SVCS sub-directory | No |
| xp_system | X | services.exe | Detected by Sophos as Troj/Krepper-N and variants and by Malwarebytes Anti-Malware as Trojan.Downloader. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The one is located in a %Windir%\inet***** - where ***** varies dependent upon the variant, examples are 10066, 20001, 20088 | No |
| xpsystem | X | services.exe | CoolWebSearch parasite variant. Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! | No |
| Xpsystem | X | SERVICES.EXE | Added by the DAEMOZ.A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\SERVICES | No |
| Service | X | services.exe -serv | Added by the NETSKY or NETSKY.B WORMS! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Windows Startup | X | services21.exe | Added by the AGOBOT-MX WORM! | No |
| Microsoft System Debug | X | services32.exe | Detected by Trend Micro as WORM_RBOT.AKH | No |
| Sygate Personal Firewall Start | X | services32.exe | Added by the RBOT-MB WORM! | No |
| system32.exe | X | services32.exe | Added by a variant of the IRCBOT TROJAN! | No |
| Win Services | X | Services32.exe | Added by the SYGINRE TROJAN! | No |
| Wins Update 32 | X | services32.exe | Added by the FORBOT-FN WORM! | No |
| System33 | X | services33.exe | Added by the RBOT-VQ WORM! | No |
| MSN | X | services51651.exe | Added by the IRCBOT-AAL TROJAN! | No |
| win32serv | X | servicesetup.exe | Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger | No |
| ServicesNotify | U | ServicesNotify.exe | Defender Pro Antispy | No |
| Configuration Loader | X | Servicess.exe | Detected by Symantec as W32.HLLW.Gaobot.AO | No |
| HKCU | X | Servicess.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\install | No |
| Policies | X | Servicess.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\install | No |
| services.exe | X | servicess.exe | Added by the MSNSPY-B TROJAN! | No |
| capricorn | X | servicest.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.CPR. The file is located in %ProgramFiles%\D360SHADSYS | No |
| servicestub.exe | X | servicestub.exe | Added by the RBOT.CN BACKDOOR! | No |
| Camra Updates | X | serviceswu.exe | Detected by Trend Micro as WORM_RBOT.BPQ | No |
| usbdrv | X | servicetask.exe | Added by a variant of the SDBOT BACKDOOR! | No |
| Policies | X | ServiceUpdate.exe | Detected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen | No |
| Test | X | ServiceUpdate.exe | Detected by McAfee as Generic.bfr | No |
| Microsoft Update Machine | X | servicez.exe | Added by the SPYBOT.BI WORM! | No |
| Serices Hostin | X | servicez.exe | Added by the SLENFBOT.MF WORM! | No |
| System Service | X | servicez.exe | Added by the RBOT-AOY WORM! | No |
| Windows Services | X | servicez.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.Gen. The file is located in %Windir% | No |
| servico | X | servico.exe | Added by the BANKER-DKE TROJAN! | No |
| ASP.NET State Service | X | servicos..exe | Added by the DADOBRA-I TROJAN! | No |
| servics | X | servics.exe | Added by the SINGU-J TROJAN! | No |
| k3ym4n | X | servicsmjr.exe | Added by the RBOT-RW WORM! | No |
| Microsoft Update Machine | X | servicz.exe | Added by the RBOT-HU WORM! | No |
| ryan1918 | X | servidevice.exe | Added by the RBOT-GVR WORM! | No |
| servieca | X | servieca.vbe | Detected by Dr.Web as Trojan.DownLoader8.16780 and by Malwarebytes Anti-Malware as Trojan.Banker. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| servieca.vbe | X | servieca.vbe | Detected by Dr.Web as Trojan.DownLoader8.16780 and by Malwarebytes Anti-Malware as Trojan.Banker | No |
| Windows Server Information | X | servinfo.exe | Added by the FORBOT-EN WORM! | No |
| ashcap | X | servirsess.exe | SpySure spyware | No |
| NvCplDeamon | X | servise.exe | Added by the AUTORUN-BNY WORM! | No |
| Windows Servser | X | serviser.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| servises | X | servises.exe | Detected by Sophos as Troj/Agent-JUJ | No |
| WINDOWS SYSTEM | X | servises.exe | Added by the ZOTOB-I WORM! | No |
| Microsoft Update Machine | X | serviz.exe | Added by a variant of the RBOT WORM! | No |
| MicroUpdate | X | servizi.exe | Detected by McAfee as Generic Dropper and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| servizi | X | servizi.exe | Detected by McAfee as RDN/Generic Dropper!ga and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| SERVlCE | X | SERVlCE.EXE | Added by the AGOBOT-UB WORM! | No |
| SVCHOST | X | SERVlCES.EXE | Added by the DELF-LF BACKDOOR! Note that the filename has a lower case "L" in place of an upper case "i" | No |
| Server Application for MFP Server | Y | ServoApp.exe | Multi Function Printer (MFP) server agent for products such as Belkin's Wireless G All-in-One Print Server and ZyXEL's NPS-520 which allow multiple computers to use networked all-in-one printers. Required for the MFP Server Agent (MFPAgent.exe) to run properly - whether it's set to start manually or automatically | Yes |
| ServoApp | Y | ServoApp.exe | Multi Function Printer (MFP) server agent for products such as Belkin's Wireless G All-in-One Print Server and ZyXEL's NPS-520 which allow multiple computers to use networked all-in-one printers. Required for the MFP Server Agent (MFPAgent.exe) to run properly - whether it's set to start manually or automatically | Yes |
| Windows USB Monitor | X | servupdate.exe | Added by the IRCBRUTE.AQ TROJAN! | No |
| ServUTrayIcon | N | ServUTray.exe | System Tray access for the Serv-U FTP server which allows the user to (amongst others) start the Management Console, stop the server and display notifications | No |
| System | X | serwin.exe | Added by the LDPINCH-BN TROJAN! | No |
| Session Client | U | sescli.exe | SurfSpy keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| sctrlmgr | X | sescmgr.exe | Added by the SDBOT.CNS BACKDOOR! | No |
| Systems | X | sescmgr.exe | Added by the DWNLDR-GAH TROJAN! | No |
| Driver Control Manager v8.1 | X | sesdessetri.exe | Added by the ZXC-Q TROJAN! | No |
| PPK Setup(Server) | U | SEServe.exe | Programmable Power Key on Sony Vaio laptops. "Using the Programmable Power Key (PPK) button, collect your e-mail automatically with one key stroke. You can also program your PPK to turn on your SuperSlim Notebook at a predetermined time and perform simple tasks - completely unattended" | No |
| Driver Control Manager v7.7 | X | sesnaesttoo.exe | Added by the AUTOINF-CU WORM! | No |
| Windows NT Session Manager | X | sess.exe | Added by a variant of Win32/Rbot | No |
| irc session | X | sessionmgr.exe | Added by the SDBOT-ACE WORM! | No |
| QWS3270 Sessions | U | sessions.exe | QWS3270 Secure terminal emulation software | No |
| SessMgr | X | sessmgr.exe /waitservice | Detected by Microsoft as TrojanDownloader:Win32/Horst.Q. Note - this is not the legitimate sessmgr.exe which is always located in %System%. This one is located in either %Windir%, %Windir%\System, %Temp%, %AppData%, %AppData%\Microsoft or %System%\drivers | No |
| SES Service | X | sesvc.exe | Added by the SDBOT-CZU WORM! | No |
| HPLJ Config | Y | SetConfig.exe | Connects system to networked HP printer. | No |
| Update local | ? | SetCPQLC.exe | Running on a Compaq desktop. Any ideas? | No |
| Microsoft ActiveX Debugger NT | X | setdebugnt.exe | Added by the BANCOS-DO TROJAN! | No |
| Microsoft« ActiveX Debugger NT | X | setdebugnt.exe | Added by the BANCOS-CZ TROJAN! | No |
| setdefprt | N | setdefprt.exe | Used to set a Brother MFC printer/copier/scanner as the default printer after installation | No |
| UniPrint | U | SetDfltSettings.exe | Drivers for Uniprint, a printing help for Terminal Services and Citrix which recieves downloaded files from a Uniprint enabled server and prints them locally allowing for truly universal printing through Terminal Services or Citrix | No |
| Microsoft SetDLL32 | X | setdll32.exe | Added by the RBOT.OZ WORM! | No |
| GammaHotKeys | U | setgamma.exe | Part of the RadeonTweaker program for adjusting ATI Radeon graphics cards. Allows you to adjust the gamma (or brightness) when playing a full-screen game without switching back to the desktop | No |
| MediaFace Integration | N | Sethook.exe | Fellowes Neato® cd label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar" | No |
| SetHook | N | Sethook.exe | Fellowes Neato® cd label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar" | No |
| SETI@home | N | SETI@home.exe | SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data | No |
| seticlient | N | SETI@home.exe | SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data | No |
| SetIcon | N | SetIcon.exe | Installed by a 6-in-1 (4 Media Card slots, a floppy drive and a USB connection) device. Constantly updates the icons for the four Media Card slots that it has and is a resource hog | No |
| setingsc.exe | X | setingsc.exe | Detected by McAfee as Generic VB.i and by Malwarebytes Anti-Malware as Trojan.Banker | No |
| SetiQueue | N | Setiqu~1.exe | Provides work unit buffering for Seti@Home clients - see here for more details | No |
| SetiSpy | N | SetiSpy.exe | SETI Spy is a little program to "spy" on the progress and performance of the SETI@home client. Called a "spy" because it is unobtrusive as possible | No |
| EDRestore | U | Setpoint.exe | Set Point from Easy Desk Software - "small utility that automatically sets System Restore points for WinME/XP" | No |
| EvtMgr6 | U | Setpoint.exe | Logitech SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice, trackballs, etc). Required if you want to use the advanced features, modify the default settings or be notified of low battery status (for wireless devices). Located in %ProgramFiles%\Logitech\Setpoint | Yes |
| Logitech SetPoint | U | Setpoint.exe | Logitech SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice, trackballs, etc). Required if you want to use the advanced features, modify the default settings or be notified of low battery status (for wireless devices). Located in %ProgramFiles%\Logitech\Setpoint | Yes |
| SetPoint | X | SetPoint.exe | Added by the RBOT-BWI WORM! Note - this is not the valid Logitech Setpoint mouse and keyboard entry that uses the same filename and is located in %ProgramFiles%\Logitech\Setpoint or Set Point from Easy Desk Software which is located in %ProgramFiles%\Easy Desk Utilities\Set Point. This one is located in %System% | No |
| SetPoint | U | Setpoint.exe | Logitech SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice, trackballs, etc) - required if you want to use the advanced features or modify the default settings of these devices and located in %ProgramFiles%\Logitech\Setpoint. Or Set Point from Easy Desk Software - a "small utility that automatically sets System Restore points for WinME/XP" which is located in %ProgramFiles%\Easy Desk Utilities\Set Point | Yes |
| Microsoft Update | X | SetPoints.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| SetRefresh | U | SetRefresh.exe | Found on some Compaq & HP PCs. SetRefresh is a utility which attempts to optimize the monitor's refresh rate, and in some cases the resolution, for the best user experience. See "here for more info | No |
| settdebugx.exe | X | settdebugx.exe | Added by the FAKEAV.SMSS TROJAN! | No |
| hao123Setting | X | Setting.exe | Detected by Dr.Web as Trojan.StartPage.51763 and by Malwarebytes Anti-Malware as Trojan.StartPage | No |
| setting | X | setting.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %LocalAppData% | No |
| JAVA | X | settings.exe | Detected by Malwarebytes Anti-Malware as Trojan.Inject. The file is located in %AppData%\Java | No |
| Logitech Desktop Messenger | N | setup-8876480.exe | Installer for Logitech Desktop Messenger included with older versions of the software for Logitech products - which automatically checks for software upgrades and new products, services and special offers from Logitech | No |
| 30fa035dbe87c6e209452c1147d1cdb9 | X | setup.exe | Detected by Dr.Web as Trojan.DownLoader7.6835 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| bf8feb67afc2238269222493247f1c23 | X | Setup.exe | Detected by McAfee as Generic.dx!bh3h and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| chrome | X | setup.exe | Detected by Malwarebytes Anti-Malware as Trojan.StartPage.AI. Note - this is not a legitimate file for the Google Chrome browser and it is located in %Windir% | No |
| InstallNAIProduct | ? | SETUP.EXE | Could be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error? | No |
| MCAFEEIPS | X | setup.exe | Added by the WHITEWELL TROJAN! | No |
| MM Install | ? | setup.exe | Possibly Money Manager from Moneysoft? | No |
| MyVBApp | X | setup.exe | Detected by Kaspersky as the Trojan-Dropper.Win32.VB.kb. The file is located in %Root% | No |
| RjLyraInstaller | ? | setup.exe | ?? | No |
| ServiceApplication | X | Setup.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Root%\Users\Public\Pictures\Sample Pictures | No |
| setup | X | setup.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence here ensures it runs when Windows starts | No |
| setup.exe | X | setup.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %AppData% and %UserStartup% and its presence there ensures it runs when Windows starts | No |
| setup.exe | X | setup.exe | Detected by Sophos as Troj/Goldun-GB. The file is located in %Windir% | No |
| SigmaTel Audio | N | setup.exe | Sigmatel audio driver | No |
| Skype | X | Setup.exe | Detected by Malwarebytes Anti-Malware as Trojan.Hijacker.URL. Note - this is not a legitimate entry for the popular Skype VOIP software and the file is located in %UserTemp% | No |
| Sweep95 | Y | SETUP.EXE | Part of an older version of Sophos anti-virus software | No |
| Tango | ? | Setup.exe | Tango Broadband access software. Is it required? | No |
| Windows | X | setup.exe | Detected by Dr.Web as Worm.Siggen.6969 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Windows Accelerators | U | setup.exe | KeySpy keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| zzzhpsetup | ? | setup.exe | ?? | No |
| zzzCamlnSuitelll | ? | setup.exe 46*** | ?? | No |
| OESET | X | setup60.exe | Detected by AhnLab as Win-Trojan/Warezdl.28672 | No |
| Highspeeddownloader | X | SetupClickHere.EXE | Homepage hijacker, redirecting to "turbo-search101.com" - see here | No |
| C:\WINDOWS\system32\SetupCmd.exe | X | SetupCmd.exe | Detected by Kaspersky as the AGENT.AAW TROJAN! | No |
| [various names] | X | SetupExeDll.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| MemConfig | X | SetupIE.com | Added by the TAPLAK WORM! | No |
| share | X | setupmsxs.exe | Detected by McAfee as Generic.bfr!cv | No |
| explorer | X | setupsvc.exe | Detected by McAfee as Generic VB.i and by Malwarebytes Anti-Malware as Trojan.Dropper | No |
| setupsvcs.exe | X | setupsvcs.exe | Detected by McAfee as Generic.bfr!cv | No |
| setupwid.exe | X | setupwid.exe | Detected by McAfee as Generic VB.i and by Malwarebytes Anti-Malware as Spyware.Banker | No |
| win32 | X | Setup_32.exe | Added by the EVILBOT.B TROJAN! | No |
| NI.UGESU_0001_N122M0303 | X | setup_de.exe | Installer for the SysKontroller rogue security software - see here | No |
| NI.UGES_0001_N108M2006 | X | setup_en.exe | Installer for the MyContentAssistant rogue privacy tool | No |
| NI.UGEST_0001_N122M0303 | X | setup_it.exe | Installer for the SysLibero rogue security software - see here | No |
| setuzp | ? | setuzp.exe | ?? | No |
| _Setv | X | Setv.com | Added by the BESAM WORM! | No |
| Windows secure | X | setver32.exe | Detected by Trend Micro as WORM_SPYBOT.EP | No |
| SetVrc | X | setvrc.exe | Added by the HUNTOCX WORM! | No |
| Sysctrls32 | X | sevchost.exe | Added by the RBOT.ADF BACKDOOR! | No |
| SevenUp | X | sevenup.exe | Added by the DELF TROJAN! | No |
| (Default) | X | sever.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %Windir%\SHELLNEW | No |
| 360[foreign characters] | X | sever.exe | Detected by Dr.Web as Trojan.PWS.Gamania.38730 and by Malwarebytes Anti-Malware as Backdoor.Agent.SN | No |
| alligt | X | severe.exe | Added by the SLURK.A WORM! | No |
| jusodl | X | severe.exe | Added by the QQPASS.48436 TROJAN! | No |
| Configuration Servecie | X | sewins.exe | Added by the SDBOT-COH WORM! | No |
| 2880e9d41a6a19b545538f21ddb48fa2 | X | sex me.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserTemp% | No |
| eda912e4c272fd6ecf04f273e3f1b428 | X | sex.exe | Detected by Dr.Web as Trojan.DownLoader7.21112 and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| hsim | X | sexgame.exe | Unidentified malware | No |
| Sexnow | X | Sexnow.exe | Added by the SENOW-B premium rate adult content dialler | No |
| Sygate Personal Firewall | X | sexy.exe | Added by the RBOT-XY WORM! | No |
| c828544720dd92f1c08f71a9bce7a42d | X | Sexy22.exe | Detected by Dr.Web as Trojan.DownLoader8.37112 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ | No |
| LOFUTDS | X | sexyfr.exe | Detected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| LOVEFSD | X | sexyfr.exe | Detected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| ULOVEJF | X | sexyfr.exe | Detected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| SystemTasks | X | sexypicz.exe | Adult content dialler | No |
| Sexy_Blondes | X | Sexy_Blondes.exe | Premium rate adult content dialler - see here | No |
| Sexy_sg | X | Sexy_sg.exe | Premium rate adult content dialler | No |
| sf | X | sf.exe | SurfEnhance adware | No |
| Safeguard 2009 | X | sf2009.exe | Safeguard 2009 rogue spyware remover - not recommended, removal instructions here | No |
| Snappy Fax | N | sf4.exe | Snappy Fax desktop fax program with an extensive set of features - version 4 | No |
| SPAMfighter Agent | U | SFAgent.exe | SPAMfighter anti email spam filter | No |
| cftmon | X | sfcmonit.exe | Added by a variant of the AGENT.ERG TROJAN! | No |
| MSConfig | X | sfcmtmaf.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% - see here | No |
| HotKey | X | SFCsrvc.pif | Added by the AUTOIT-OC WORM! | No |
| Files Driver | X | sfdhost.exe | Added by the AGOBOT-AJC BACKDOOR! | No |
| Audio Device Manager | X | sfhgj.exe | Added by the IRCBOT-ZA BACKDOOR! | No |
| SFIGUI | N | SFIGUI.EXE | Sonic Focus - "enhances music, movie and game sound by analyzing compressed audio streams in realtime, then restoring and enriching audio back to its original performance qualities" | No |
| SonicFocus | N | SFIGUI.EXE | Sonic Focus - "enhances music, movie and game sound by analyzing compressed audio streams in realtime, then restoring and enriching audio back to its original performance qualities" | No |
| sfita | X | sfita.exe | Added by the FAVADD-H TROJAN! | No |
| mssfos | X | sfool.exe | Added by the RANDEX.EUS WORM! | No |
| Snappy Fax Printer Agent | ? | sfpagent.exe | Related to the Snappy Fax desktop fax program. What does it do and is it required? | No |
| Snappy Fax Printer virtual printer agent | ? | sfpagent.exe | Related to the Snappy Fax desktop fax program. What does it do and is it required? | No |
| sfpc | U | sfpc.exe | Spy4PC surveillance software. Uninstall this software unless you put it there yourself | No |
| srMaEKdMpIEyiFifc | X | sFpoAkPxnMmSYBXjD.exe | Detected by Sophos as Troj/Mdrop-EVT and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| Microsoft PC Health Remote Assistance File Open & Save controls | X | sfrcdlg32.exe | Added by the RBOT-AVY WORM! | No |
| SoftGridTray | U | SFTTray.exe | System Tray access to SoftGrid from Microsoft - "the only virtualization solution that delivers applications that are never installed and dynamically delivered, on demand" | No |
| SfWinStartInfo | U | sfWinStartupInfo.exe | SFIRM32 Online Banking software | No |
| sm | X | sf_exe.exe | Added by the OLFEB.A TROJAN! | No |
| Sgecrypt | Y | SGECRYPT.exe | SafeGuard Easy from Sophos (formerly by Utimaco) - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks" | No |
| Microsoft Update | X | sghost.exe | Added by the SDBOT.AKV WORM! | No |
| sginst | U | sginst.exe | eAcceleration Stop-Sign security software related - previously not recommended (see here). It has now been delisted, so make sure you have the latest version - hence the "U" recommendation | No |
| sgkAJE | X | sgkAJE.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor.XTR. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| SpywareGuard | Y | sgmain.exe | "SpywareGuard provides a real-time protection solution against spyware" | No |
| Screen Guard Message Scan | U | sgms.exe | Part of Access Denied security and privacy software | No |
| MSRegScan | U | SGP.exe | SpyGator surveillance software. Uninstall this software unless you put it there yourself | No |
| SGPUpdater | X | sgpUpdaters.exe | Fast Browser Search/Search Guard Plus parasite - installed with "Make the Web Better" applications such as My Web Tattoo, My Face LOL and Google Easy Money Kit. See here and here for more information | No |
| SyGateService | U | sgserv95.exe | SyGate is a useful little program that lets you share an internet connection over an intranet. Is it needed - it saves a lot of headache to just let SyGate load at startup. Available via Start → Programs | No |
| SGTBox | ? | SGTBox.exe | Canon scanner driver. Is it required? | No |
| sgtray | U | sgtray.exe | StorageGuard from Veritas (now Symantec). Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups | No |
| StorageGuard | U | sgtray.exe | StorageGuard from Veritas (now Symantec). Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups | No |
| StoreGrid | Y | SGTray.exe | System Tray access to StoreGrid online backup and data protection software from Vembu Technologies Pvt. Ltd. Required for scheduling to work | No |
| UpdateManager | U | sgtray.exe | StorageGuard from Veritas (now Symantec). Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups. This version by Sonic | No |
| Security Guard | X | SG[random characters].exe | Security Guard rogue security software - not recommended, removal instructions here | No |
| shell32.dll | X | sh32.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.SHGen. The file is located in %System% | No |
| WindowsMNG | X | Shades.exe | Detected by Dr.Web as Trojan.DownLoader4.16266 and by Malwarebytes Anti-Malware as Backdoor.Messa | No |
| Shadow | Y | Shadow.exe | "NTI Shadow 3 is an award-winning easy-to-use backup application that automatically protects your photo, music, video, and various data files. It makes data restoration as easy as dragging and dropping files from one place to another" | No |
| hp center UI | N | ShadowBar.exe | User Interface for HP Center - see the BACKWEB-******.exe entry | No |
| ShadowUser Pro Edition | U | ShadowUser.exe | StorageCraft ShadowUser "provides easy to use desktop security and protection for Windows operating systems. ShadowUser is the best way to prevent unwanted changes to PCs and laptops." No longer available - see here | No |
| [various names] | X | Shaitan1678.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| CorpFire | X | Shakar.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %ProgramFiles% | No |
| CorpSoft | X | Shakar.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %ProgramFiles% | No |
| win32 | X | Shakira_1997_Part_1_.Mpeg_.scr | Added by the MYLIFE.N WORM! | No |
| load= | X | shambl3r.exe | Added by the REMABL WORM! | No |
| shambl3r* | X | shambl3r.exe | Added by the REMABL WORM! where * is 2 to 11 | No |
| (Default) | X | Shania.vbs | Added by the SHANIA BACKDOOR! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank | No |
| SHAProc | X | SHAProc.exe | Added by the WINKO.AO WORM! | No |
| Shareaza | N | Shareaza.exe | Shareaza P2P client | No |
| ShareBox | X | ShareBoxC.exe | Detected by AVG as OpenShopper.A and by Malwarebytes Anti-Malware as Adware.K.ShareBox. The file is located in %ProgramFiles%\ShareBox | No |
| Parallels Shared Internet Applications | ? | sharedintapp.exe | Part of Parallel Tools utility suite for guest operating systems included with virtualization software from Parallels - such as Parallels Workstation | No |
| SharedInternetApplication | ? | sharedintapp.exe | Part of Parallel Tools utility suite for guest operating systems included with virtualization software from Parallels - such as Parallels Workstation | No |
| sharedprem | X | sharedprem.exe | Added by the MAKECALL TROJAN! | No |
| SharpTray | U | SharpTray.exe | Part of the Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents" | No |
| [various names] | X | shch.exe | Premium rate adult content dialler | No |
| MsnExplorer | X | shch.exe | Detected by Sophos as Troj/Bdoor-EB | No |
| Nero | X | shch.exe | Premium rate adult content dialler | No |
| Quicktime | X | shch.exe | Premium rate adult content dialler | No |
| ScheduIe | X | shch.exe | Added by a variant of Troj/Bdoor-EB | No |
| ScheduIr | X | shch.exe | Added by a variant of Troj/Bdoor-EB | No |
| SheduIer | X | shch.exe | Detected by Sophos as Troj/Bdoor-EB | No |
| SvcH0st | X | shch.exe | Detected by Sophos as Troj/Bdoor-EB | No |
| WinAmpAgent | X | shch.exe | Detected by Sophos as Troj/Bdoor-EB | No |
| WIN_DRIVR32 | X | shchostv.exe | Added by a TROJAN - see here | No |
| ShellCommand | X | shcmp32.exe | Added by the REMCON-A TROJAN! | No |
| shdef | X | shdef.exe | Added by the VB-DVS TROJAN! | No |
| FHPage | X | shdochp.exe | Added by the WINHOUND TROJAN! | No |
| FHStart | X | shdocsvc.exe | Added by the WINHOUND TROJAN! | No |
| Windows Service Processor | X | shdocvw.exe | PcPrivacyCleaner rogue security software - not recommended | No |
| frguk | ? | shdrkmck.exe | ?? | No |
| UPDATE | X | sheikh dark final v2.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData% | No |
| (Default) | X | Shell.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor.ZE. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %System% | No |
| Office Source Engine | X | shell.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserTemp% | No |
| Shell.exe | X | Shell.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserTemp% | No |
| Shell.exe | X | Shell.exe | Detected by Trend Micro as WORM_EMERLEOX.S and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System% | No |
| Windows Shell | X | shell.exe | Added by the MYTOB-CA WORM! | No |
| WOOKIT | ? | Shell.exe appLaunchClientZone.shl | Related to the Wanadoo broadband ISP (now rebranded as Orange). What does it do and is it required? | No |
| Shell32.dll | X | shell32 | Detected by Kaspersky as Backdoor.Win32.DarkKomet.eku and by Malwarebytes Anti-Malware as Backdoor.Agent.DCRSAGen | No |
| Secure32 | X | Shell32.com StartUp | Added by the BRONTOK-CJ WORM! | No |
| default | X | shell32.exe | Added by the BINGHE TROJAN! | No |
| LTSMSG | X | Shell32.exe | Added by the LEMIR.B TROJAN! | No |
| ROOT2 | X | shell32.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %Windir%\system | No |
| Shell | X | Shell32.exe | Added by the BADSECTOR TROJAN! | No |
| Shell32.exe | X | Shell32.exe | Detected by Dr.Web as Trojan.DownLoader5.11870 and by Malwarebytes Anti-Malware as Backdoor.Hupigon | No |
| Shell32 | X | Shell32.vbs | Added by the SCAFENE WORM! | No |
| Shellapi32 | X | Shellapi32.exe | Added by the NETDEVIL (or NERTE.76.B) BACKDOOR! | No |
| MicrosoftShell | X | Shellcomm.exe | Detected by Sophos as Troj/Bancban-QG | No |
| Shelldaemon | X | Shelldaemon.exe | Added by a variant of the AGENT.ALN TROJAN! | No |
| wesspell | X | shelldm.exe | Added by the LETHIC TROJAN! | No |
| ShellEx | X | ShellEx.exe | Added by the ANAKHA TROJAN! | No |
| SMSERIALWORKERSTART | X | shellexcon.exe | Added by the FAKEALERT-AH TROJAN! Installed with the SpyBurner spyware remover - which is not recommended, see here | No |
| shell update | X | shellexec.exe | Added by the RBOT-ANC WORM! | No |
| Explorer | X | shellexp.exe | Added by the AGENT-ZY TROJAN! | No |
| Explorer | X | shellexpl.exe | Added by the SHELDOR TROJAN! | No |
| ShellApi | X | SHELLMSN.EXE | Added by the NETDEV.B BACKDOOR! | No |
| shellsystem | X | shellsystem.exe | Added by the UPCHAN TROJAN! | No |
| Shell Tray Window | X | ShellTraywnd.exe | Added by the STULTDOR-A TROJAN! | No |
| W5SHFA | X | shfacvs.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.FA. The file is located in %AppData%\sdchfa | No |
| Microsoft® Windows® Operating System | X | shfusion.exe | Detected by Sophos as Mal/Agent-AIP and by Malwarebytes Anti-Malware as Backdoor.Messa | No |
| shgina | X | shgina.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%\shgina | No |
| shhost | X | shhost.exe | Added by the AGENT.CE BACKDOOR! | No |
| shicoxp | N | shicoxp.exe | Installed with the drivers for multi card readers of various brands. To differentiate between the various card slots on multi slot readers the shicoxp.exe file assigns and loads unique drive icons for the various card slots that are displayed in Windows Explorer | No |
| Shield Security | X | shield.exe | Added by a variant of Backdoor.Rizo.A. The file is located in %System%\Com | No |
| SpyWare Shield | U | Shield.exe | Acronis Privacy Expert Spyware Shield prevents spyware and other suspicious programs from being installed on PCs | No |
| Shield32 Security | X | shield32.exe | Added by a variant of Backdoor.Rizo.A. The file is located in %System%\Com | No |
| media player | X | shield32.exe.exe | Detected by Kaspersky as Trojan.Win32.VB.qnz. The file is located in %System%\adobe ActiveX | No |
| msnmsger | X | shield32.exe.exe | Detected by Kaspersky as Trojan.Win32.VB.qnz. The file is located in %System%\adobe ActiveX | No |
| Windows Explorer | X | shield32.exe.exe | Detected by Kaspersky as Trojan.Win32.VB.qnz. The file is located in %System%\adobe ActiveX | No |
| ShieldSafeness | X | ShieldSafeness.exe | ShieldSafeness rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| MilShieldSlave | U | ShieldWorker.exe | Mil Shield from Mil Incorporated. It protects your privacy by removing all tracks from your online or offline computer activities | No |
| Shine | X | Shine.exe | Added by the HAPPYLOW (or NISHE-A) VIRUS! | No |
| Tiger | X | Shine.exe | Added by the HAPPYLOW (or NISHE-A) VIRUS! | No |
| SHINITV | ? | shinitv.exe | ?? | No |
| Run RunOnce | N | ShipUPS.EXE | Older version of the UPS WorldShip utility used to create and manage your UPS shipments | No |
| game | X | shit.exe | Added by the Netclap Gold backdoor TROJAN! | No |
| TESTNAME.EXE | X | shit.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%\windir | No |
| WinSrv | X | SHIZZLE.EXE | Detected by Trend Micro as WORM_HOBBIT.C | No |
| ShortKeys Lite | U | shklite.exe | ShortKeys Lite from Insight Software Solutions, Inc. A macro utility to automate a task that you perform repeatedly or on a regular basis | No |
| shellbn | X | shlext32.exe | Malware installed by different rogue security software including SpyKillerPro and the XP AntiVirus series | No |
| MSOfficeCfg | X | shman.exe | Premium rate adult content dialer | No |
| NAVCheck | X | shman.exe | Premium rate adult content dialer | No |
| QTSvc | X | shman.exe | Premium rate adult content dialler | No |
| SystemService | X | shman.exe | Premium rate adult content dialler | No |
| paint.exe | X | shnlog.exe | Added by the PUPER-A TROJAN! | No |
| SAHBundle | X | shop1003.exe | ShopAtHomeSelect parasite | No |
| shopbacon | X | shopbacon.exe | Detected by Malwarebytes Anti-Malware as Adware.K.ShopBacon. The file is located in %ProgramFiles%\shopbacon | No |
| ShopSafe | N | ShopSafe.exe | Created by Orbiscom for MNBA (now Bank of America) - ShopSafe creates a temporary card number each time you make an online purchase | No |
| Shop To Win | X | ShopToWin.exe | JackpotRewards.ShopToWin adware | No |
| ShoreTel Personal Call Manager | U | ShoreTel.exe | ShorTel Personal Call Manager - allows you to "use your PC or laptop to manage voice communications with co-workers, customers and business associates" | No |
| ShortKeys 99 | N | SHORTKEY.EXE | ShortKeys from Insight Software Solutions - allows you to program keys with text strings | No |
| hellodolly | X | shost.exe | Added by the YODO WORM! | No |
| rpc Win32 | X | shost32.exe | Added by the RBOT-ABL WORM! | No |
| shosts..exe | X | shosts..exe | Detected by McAfee as Generic Downloader.x!fza and by Malwarebytes Anti-Malware as Trojan.FakeMS | No |
| shostss..exe | X | shostss..exe | Detected by Malwarebytes Anti-Malware as Malware.Packer.T. The file is located in %UserProfile%\IE | No |
| shotjumb | X | shotjumb.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %AppData%\shotjumb | No |
| sHotKey | Y | sHotKey.exe | Special function key manager for Chicony keyboards - see here | No |
| Shotty | N | Shotty.exe | Shotty by Thomas Baumann - "is an application to take pictures from your computers screen (called screenshots) or from one application only. Unlike other applications that does this Shotty provides various other features that are useful to modify the taken screenshot" | Yes |
| Shotty - Tiny but impressive screenshot utility | N | Shotty.exe | Shotty by Thomas Baumann - "is an application to take pictures from your computers screen (called screenshots) or from one application only. Unlike other applications that does this Shotty provides various other features that are useful to modify the taken screenshot" | Yes |
| ShowBatteryBar | U | ShowBatteryBar.exe | BatteryBar by Osiris Development - "is a simple, straight-forward, battery meter that monitors the status of your battery and displays your battery's status in the taskbar" | No |
| Showbehind | X | SHOWBEHIND.EXE | Advertisement display which can be stopped here | No |
| ShowFF | X | ShowFF.exe | FFToolBar adware toolbar | No |
| Cyber Trio | U | showmode.exe | From G-Tek Technologies. Allows you to set the PC in one of three modes, Standard, Enhanced and Kiddo. Standard is full function, Enhanced prevents accidental damage and Kiddo is a play environment for kids. Pre-installed on some Packard Bell PCs | No |
| ShowWnd | U | ShowWnd.exe | Found on Gateway computers (and maybe others) - see here. "Showwnd is included with the Chicony keyboard software and is used by the software to stop the keyboard driver's taskbar entry from reappearing. It is not necessary to remove the keyboard software, however if you wish it can be removed through Add or Remove Programs" | No |
| SHPC32 | U | SHPC32.exe | Port monitor for Lexmark printers on a USB connection. Ties in with the Printer Control Program. Features like cancelling a print are unavailable if disabled | No |
| DelayShred | N | ShrCL.EXE | McAfee Shredder - not required at startup. You can run it manually via McAfee Security Center | No |
| Micosoftartup | X | shrl.exe | Added by the SDBOT-JQ WORM! | No |
| RHSI SHS | U | SHS.exe | "Rogers Self Help Software is a free suite of tools and utilities for your computer that keeps your system running properly, and makes your Hi-Speed Internet experience smooth and trouble-free" | No |
| Rogers SHS | U | shs.exe | "Rogers Self Help Software is a free suite of tools and utilities for your computer that keeps your system running properly, and makes your Hi-Speed Internet experience smooth and trouble-free" | No |
| SHS | U | SHS.exe | "Rogers Self Help Software is a free suite of tools and utilities for your computer that keeps your system running properly, and makes your Hi-Speed Internet experience smooth and trouble-free" | No |
| ShStatEXE | Y | SHSTAT.EXE | Part of McAfee's VirusScan Enterprise corporate anti-virus and anti-spyware security tool | No |
| HD Audio Process | X | shswsc.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserProfile% | No |
| Windows Update 63 | X | shupd64.exe | Detected by Sophos as W32/Forbot-GA and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| Shutdownaware | U | shutdownaware.exe | Loaded by the SWEEX 6-in-1 Media Card Reader to properly manage the reader while it is connected to your system | No |
| ShutDownPro | U | ShutDownPro.exe | ShutDownPro - shutdown, reboot, logoff your System with one mouse click | No |
| ShuttlePRO Helper | Y | ShuttlePRO Helper.exe | Driver/support for the Contour ShuttlePRO - "an editing tool that will have you wondering why you even need a keyboard" | No |
| explorer | X | shvcsetxs.exe | Detected by McAfee as Generic.bfr!cv | No |
| Protect | U | SHVRTF.EXE | PC Angel takes a 5-second snapshot of the current system registry each time the PC boots up. In the event of a crash, PC ANGEL will retrieve everything up to the minute before the crash or the last known stable registry | No |
| KYE_Showicon | ? | shwicon.exe | Card reader for memory cards from digital cameras. Is it required? | No |
| ShowIcon_Justrams_USB Product Driver v2.12r012 | ? | shwicon.exe | Related to Just Rams USB product driver. Is it required? | No |
| ShowIcon_PNY_PNY Attaché | U | shwicon.exe | PNY Attaché USB flash memory stick System Tray icon - shows when the device is plugged in | No |
| ShowIcon_SmartDisk Corporation_USB Card Reader v1.14e051 | ? | shwicon.exe | Card reader for memory cards from digital cameras. Is it required? | No |
| Sunkist2k | U | shwicon2k.exe | Card reader for memory cards from digital cameras, etc | No |
| Sunkist | U | shwicon98.exe | Card reader for memory cards from digital cameras, etc | No |
| SunKistEM | U | shwiconem.exe | Card reader for memory cards from digital cameras, etc | No |
| File-Sharing Wizard | X | shwizard.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| Microsoft | X | ShyFx.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.MSGen. The file is located in %System% | No |
| DesktopX Widget | U | SI2992~1.exe | Silica Volume Control widget included with the DesktopX desktop utility from Stardock Corporation. Displays a slider to control the speaker volume on the desktop. Once started, Silica Volume Control.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 MSConfig entry where "Silica Volume Control.exe" is shown as "SI2992~1.exe" | Yes |
| Silica Volume Control | U | SI2992~1.exe | Silica Volume Control widget included with the DesktopX desktop utility from Stardock Corporation. Displays a slider to control the speaker volume on the desktop. Once started, Silica Volume Control.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Silica Volume Control.exe" is shown as "SI2992~1.exe" | Yes |
| DesktopX Widget | U | SI39E3~1.exe | Silica Weather widget included with the DesktopX desktop utility from Stardock Corporation. Displays the current weather and forecast for up to 5 days for the selected location on the desktop. Once started, Silica Weather.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 MSConfig entry where "Silica Weather.exe" is shown as "SI39E3~1.exe" | Yes |
| Silica Weather | U | SI39E3~1.exe | Silica Weather widget included with the DesktopX desktop utility from Stardock Corporation. Displays the current weather and forecast for up to 5 days for the selected location on the desktop. Once started, Silica Weather.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Silica Weather.exe" is shown as "SI39E3~1.exe" | Yes |
| DesktopX Widget | U | SI90AE~1.exe | Silica To-Do List widget included with the DesktopX desktop utility from Stardock Corporation. Adds a "to do" task list on the desktop. Once started, Silica To-Do List.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 MSConfig entry where "Silica To-Do List.exe" is shown as "SI90AE~1.exe" | Yes |
| Silica ToDo List | U | SI90AE~1.exe | Silica To-Do List widget included with the DesktopX desktop utility from Stardock Corporation. Adds a "to do" task list on the desktop. Once started, Silica To-Do List.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Silica To-Do List.exe" is shown as "SI90AE~1.exe" | Yes |
| DesktopX Widget | U | SI985F~1.exe | Silica Word of the Day widget included with the DesktopX desktop utility from Stardock Corporation. Displays the "Word of the Day" from Wordsmith.org on the desktop. Once started, Silica Word of the Day.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 MSConfig entry where "Silica Word of the Day.exe" is shown as "SI985F~1.exe" | Yes |
| Silica Word of the Day.exe | U | SI985F~1.exe | Silica Word of the Day widget included with the DesktopX desktop utility from Stardock Corporation. Displays the "Word of the Day" from Wordsmith.org on the desktop. Once started, Silica Word of the Day.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Silica Word of the Day.exe" is shown as "SI985F~1.exe" | Yes |
| SIAPRO6 | U | sia.exe | Older version of Steganos Internet Anonym privacy software | No |
| SIA2006 | U | SIA2006.exe | Older version of Steganos Internet Anonym privacy software | No |
| SIAPRO7 | U | SIAPRO7.exe | Older version of Steganos Internet Anonym privacy software | No |
| sicasisyhifh | X | sicasisyhifh.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see here | No |
| Yahoo Messengger | X | SICHOST.exe | Detected by McAfee as W32/Yahlover.worm.gen.k and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| Sick Beard | U | SickBeard.exe | Sick Beard - is an internet "PVR (Personal Video Recorder) for newsgroup users (with limited torrent support). It watches for new episodes of your favorite shows and when they are posted it downloads them, sorts and renames them, and optionally generates metadata for them" | No |
| Sicom | X | Sicom.exe | Added by the NETLIP WORM! | No |
| SideACT! | U | SideACT.exe | To-Do list add-on for the Sage ACT! contact manager | No |
| Microsoft Windows Sidebar | U | Sidebar.exe | Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijacker | Yes |
| Microsoft® Windows® Operating System | U | Sidebar.exe | Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijacker | Yes |
| Sidebar | U | Sidebar.exe | Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijacker | Yes |
| Murbak Helper | X | sidebarmgr.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %LocalAppData% | No |
| SideGreen | X | SideGreen.exe | SideGreen adware. File located in %Program Files%\SideGreen | No |
| SideOn | X | SideOn.exe | Detected by Microsoft as Adware:Win32/Bonuscash and by Malwarebytes Anti-Malware as Adware.SideOn. The file is located in %ProgramFiles%\SideOn | No |
| SideTab | X | SideTab.exe | Detected by Microsoft as Adware:Win32/SideTab | No |
| SIECACST | ? | siecacst.exe | Related to a Siemens card reader. Is it required? | No |
| DesktopX Widget | U | SIF08B~1.exe | Silica Unit Converter widget included with the DesktopX desktop utility from Stardock Corporation. Provides a unit conversion utility on the desktop. Once started, Silica Unit Converter.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 entry where "Silica Unit Converter.exe" is shown as "SIF08B~1.exe" | Yes |
| Silica Unit Converter | U | SIF08B~1.exe | Silica Unit Converter widget included with the DesktopX desktop utility from Stardock Corporation. Provides a unit conversion utility on the desktop. Once started, Silica Unit Converter.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Silica Unit Converter.exe" is shown as "SIF08B~1.exe" | Yes |
| Install Pending Files | ? | sifxinst.exe | Uninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see here. Is it required? | No |
| SightSpeed | U | SightSpeed.exe | SightSpeed Video Chat - "lets you connect with all your friends and family easily. Make video calls, phone calls, and send video mails and text messages to everyone in your network, anywhere in the world" | No |
| Intel(R) Turbo Boost Technology Monitor 2.0 | U | SignalIslandUi.exe | Desktop gadget for Intel® Turbo Boost Monitor - which "is a Windows 7 application designed to display processor frequency activity and highlight energy saver mode. The Turbo Boost Monitor only runs on PCs with Intel® Turbo Boost Technology capable processors" - such as the Core i7, i5 and i3 | Yes |
| Intel® Turbo Boost Technology Monitor 2.0 | U | SIGNAL~1.EXE | Desktop gadget for Intel® Turbo Boost Monitor - which "is a Windows 7 application designed to display processor frequency activity and highlight energy saver mode. The Turbo Boost Monitor only runs on PCs with Intel® Turbo Boost Technology capable processors" - such as the Core i7, i5 and i3 | Yes |
| signkey | X | signkey.exe | Detected by Sophos as Troj~DwnLdr-KKT and by Malwarebytes Anti-Malware as Adware.KorAd | No |
| signkey3 | X | signkey2.exe | Detected by Malwarebytes Anti-Malware as Adware.Korad. The file is located in %AppData%\temp | No |
| signup3 | X | signup2.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader.K. The file is located in %AppData%\temp | No |
| File Signature Verification | X | sigverifui.exe | Detected by Dr.Web as Trojan.DownLoader8.32054 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| SigX | U | sigx.exe | SigX is a "dynamic signature image generated based on whatever data your computer sends it though our SigX program. It can display your current Mp3, current OS, Free Ram, your current time and more" | No |
| SigXC | U | SigX.exe | SigX is a "dynamic signature image generated based on whatever data your computer sends it though our SigX program. It can display your current Mp3, current OS, Free Ram, your current time and more" | No |
| sihemigexuhy | X | sihemigexuhy.exe | Detected by McAfee as PWS-Zbot.gen.ary and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
| EleFunAnimatedWallpaper | U | Silent Lagoon.exe | Silent Lagoon animated wallpaper from | No |
| Compaq Knowledge Center | U | silent.exe | "Compaq Knowledge Center integrates self-help assistance features from Compaq and Microsoft with the efficiencies of the Internet for the fastest time to solution" | No |
| SilentSoftech | X | SilentSo.exe | Added by the AUTORUN-ANU WORM! | No |
| Silica Calculator | U | Silica Calculator.exe | Silica Calculator widget for the DesktopX desktop utility from Stardock Corporation. Once started, Silica Calculator.exe loads a file called "DXWidget.exe" and exits | No |
| DesktopX Widget | U | Silica Calendar.exe | Silica Calender widget included with the DesktopX desktop utility from Stardock Corporation. Displays a calendar on the desktop. Once started, Silica Calendar.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entry | Yes |
| Silica Calender | U | Silica Calendar.exe | Silica Calender widget included with the DesktopX desktop utility from Stardock Corporation. Displays a calendar on the desktop. Once started, Silica Calendar.exe loads a file called "DXWidget.exe" and exits | Yes |
| DesktopX Widget | U | Silica Clock.exe | Silica Clock widget included with the DesktopX desktop utility from Stardock Corporation. Displays a clock on the desktop. Once started, Silica Clock.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entry | Yes |
| DesktopX Widget | U | Silica Clock.exe | Silica Clock widget included with the DesktopX desktop utility from Stardock Corporation. Displays a clock on the desktop. Once started, Silica Clock.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 MSConfig entry where "Silica Clock.exe" is shown as "SILICA~2.EXE" | Yes |
| Silica Clock | U | Silica Clock.exe | Silica Clock widget included with the DesktopX desktop utility from Stardock Corporation. Displays a clock on the desktop. Once started, Silica Clock.exe loads a file called "DXWidget.exe" and exits | Yes |
| Silica Clock | U | Silica Clock.exe | Silica Clock widget included with the DesktopX desktop utility from Stardock Corporation. Displays a clock on the desktop. Once started, Silica Clock.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Silica Clock.exe" is shown as "SILICA~2.EXE" | Yes |
| Silica CPU Meter | U | Silica CPU meter.exe | Silica CPU Meter widget for the DesktopX desktop utility from Stardock Corporation. Displays a CPU usage meter on the desktop. Once started, Silica CPU meter.exe loads a file called "DXWidget.exe" and exits | No |
| Silica Dictionary Search | U | Silica Dictionary Search.exe | Silica Dictionary Search widget for the DesktopX desktop utility from Stardock Corporation. Once started, Silica Dictionary Search.exe loads a file called "DXWidget.exe" and exits | No |
| Silica Drive Meter | U | Silica Drive Meter.exe | Silica Drive Meter widget for the DesktopX desktop utility from Stardock Corporation. Displays a hard disk usage meter on the desktop. Once started, Silica Drive Meter.exe loads a file called "DXWidget.exe" and exits | No |
| Silica Memory Meter | U | Silica Memory Meter.exe | Silica Memory Meter widget for the DesktopX desktop utility from Stardock Corporation. Displays a memory usage meter on the desktop. Once started, Silica Memory Meter.exe loads a file called "DXWidget.exe" and exits | No |
| Silica Network Monitor | U | Silica Network Monitor.exe | Silica Network Monitor widget for the DesktopX desktop utility from Stardock Corporation. Once started, Silica Network Monitor.exe loads a file called "DXWidget.exe" and exits | No |
| DesktopX Widget | U | Silica Picture Frame.exe | Silica Picture Frame widget included with the DesktopX desktop utility from Stardock Corporation. Displays either a static user selected picture or slide show in a resizable picture frame on the desktop. Once started, Silica Picture Frame.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entry | Yes |
| Silica Picture Frame | U | Silica Picture Frame.exe | Silica Picture Frame widget included with the DesktopX desktop utility from Stardock Corporation. Displays either a static user selected picture or slide show in a resizable picture frame on the desktop. Once started, Silica Picture Frame.exe loads a file called "DXWidget.exe" and exits | Yes |
| DesktopX Widget | U | Silica Search.exe | Silica Search widget included with the DesktopX desktop utility from Stardock Corporation. Provides a search box powered by Google on the desktop. Once started, Silica Search.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entry | Yes |
| Silica Search | U | Silica Search.exe | Silica Search widget included with the DesktopX desktop utility from Stardock Corporation. Provides a search box powered by Google on the desktop. Once started, Silica Search.exe loads a file called "DXWidget.exe" and exits | Yes |
| DesktopX Widget | U | Silica To-Do List.exe | Silica To-Do List widget included with the DesktopX desktop utility from Stardock Corporation. Adds a "to do" task list on the desktop. Once started, Silica To-Do List.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entry | Yes |
| Silica ToDo List | U | Silica To-Do List.exe | Silica To-Do List widget included with the DesktopX desktop utility from Stardock Corporation. Adds a "to do" task list on the desktop. Once started, Silica To-Do List.exe loads a file called "DXWidget.exe" and exits | Yes |
| DesktopX Widget | U | Silica Unit Converter.exe | Silica Unit Converter widget included with the DesktopX desktop utility from Stardock Corporation. Provides a unit conversion utility on the desktop. Once started, Silica Unit Converter.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entry | Yes |
| Silica Unit Converter | U | Silica Unit Converter.exe | Silica Unit Converter widget included with the DesktopX desktop utility from Stardock Corporation. Provides a unit conversion utility on the desktop. Once started, Silica Unit Converter.exe loads a file called "DXWidget.exe" and exits | Yes |
| DesktopX Widget | U | Silica Volume Control.exe | Silica Volume Control widget included with the DesktopX desktop utility from Stardock Corporation. Displays a slider to control the speaker volume on the desktop. Once started, Silica Volume Control.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entry | Yes |
| Silica Volume Control | U | Silica Volume Control.exe | Silica Volume Control widget included with the DesktopX desktop utility from Stardock Corporation. Displays a slider to control the speaker volume on the desktop. Once started, Silica Volume Control.exe loads a file called "DXWidget.exe" and exits | Yes |
| DesktopX Widget | U | Silica Weather.exe | Silica Weather widget included with the DesktopX desktop utility from Stardock Corporation. Displays the current weather and forecast for up to 5 days for the selected location on the desktop. Once started, Silica Weather.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entry | Yes |
| Silica Weather | U | Silica Weather.exe | Silica Weather widget included with the DesktopX desktop utility from Stardock Corporation. Displays the current weather and forecast for up to 5 days for the selected location on the desktop. Once started, Silica Weather.exe loads a file called "DXWidget.exe" and exits | Yes |
| DesktopX Widget | U | Silica Word of the Day.exe | Silica Word of the Day widget included with the DesktopX desktop utility from Stardock Corporation. Displays the "Word of the Day" from Wordsmith.org on the desktop. Once started, Silica Word of the Day.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entry | Yes |
| Silica Word of the Day.exe | U | Silica Word of the Day.exe | Silica Word of the Day widget included with the DesktopX desktop utility from Stardock Corporation. Displays the "Word of the Day" from Wordsmith.org on the desktop. Once started, Silica Word of the Day.exe loads a file called "DXWidget.exe" and exits | Yes |
| DesktopX Widget | U | SILICA~1.EXE | Silica Calender widget included with the DesktopX desktop utility from Stardock Corporation. Displays a calendar on the desktop. Once started, Silica Calendar.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 MSConfig entry where "Silica Calendar.exe" is shown as "SILICA~1.EXE" | Yes |
| Silica Calender | U | SILICA~1.EXE | Silica Calender widget included with the DesktopX desktop utility from Stardock Corporation. Displays a calendar on the desktop. Once started, Silica Calendar.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Silica Calendar.exe" is shown as "SILICA~1.EXE" | Yes |
| DesktopX Widget | U | SILICA~3.EXE | Silica Picture Frame widget included with the DesktopX desktop utility from Stardock Corporation. Displays either a static user selected picture or slide show in a resizable picture frame on the desktop. This is the Vista/7 MSConfig entry where "Silica Picture Frame.exe" is shown as "SILICA~3.EXE" | Yes |
| Silica Picture Frame | U | SILICA~3.EXE | Silica Picture Frame widget included with the DesktopX desktop utility from Stardock Corporation. Displays either a static user selected picture or slide show in a resizable picture frame on the desktop. Once started, Silica Picture Frame.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Silica Picture Frame.exe" is shown as "SILICA~3.EXE" | Yes |
| DesktopX Widget | U | SILICA~4.exe | Silica Search widget included with the DesktopX desktop utility from Stardock Corporation. Provides a search box powered by Google on the desktop. This is the Vista/7 MSConfig entry where "Silica Search.exe" is shown as "SILICA~4.EXE" | Yes |
| Silica Search | U | SILICA~4.exe | Silica Search widget included with the DesktopX desktop utility from Stardock Corporation. Provides a search box powered by Google on the desktop. Once started, Silica Search.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Silica Search.exe" is shown as "SILICA~4.EXE" | Yes |
| Simcast | N | SimcastAlerts.exe | Simcast is a free service that allows you to subscribe to information on a large variety of topics. Alerts will appear on your desktop when a channel that you have subscribed to has something to say | No |
| cpntmgc | X | simcss.exe | Added by the MAGICON.A TROJAN! | No |
| apyginapygin | X | simenu.exe | Added by the SDBOT.BTR WORM! | No |
| Sakemsneql | X | simenu.exe | Added by the SDBOT.BTO WORM! | No |
| Si Meter | N | SIMETER.EXE | Si Meter - keep track of things like CPU activity, network activity and speed, hard-drive activity, hard-drive space, system memory, running processes, or just date and time | No |
| simpcvt | X | simpcvt.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %AppData%\simpcvt | No |
| Simplify Media | N | SimplifyMedia.exe | Simplify Media media manager - "enjoy songs from home while at work or from any WiFi location. Explore friends' music while they are online" | No |
| Simp | U | SimpLite-AIM.exe | SimpLite encryption add-on for AIM from Secway - encrypts messages before they're sent, preventing eavesdroppers from reading your AIM conversations | No |
| Simp | U | SimpLite-ICQ-AIM.exe | SimpLite encryption add-on for ICQ/AIM from Secway - encrypts messages before they're sent, preventing eavesdroppers from reading your ICQ/AIM conversations | No |
| Simp | U | SimpLite-ICQ.exe | SimpLite encryption add-on for ICQ from Secway - encrypts messages before they're sent, preventing eavesdroppers from reading your ICQ conversations | No |
| Simp | U | SimpLite-Jabber.exe | SimpLite encryption add-on for the open source Jabber instant messaging service from Secway - encrypts messages before they're sent, preventing eavesdroppers from reading your Jabber conversations | No |
| Simp | U | SimpLite-MSN.exe | SimpLite encryption add-on for MSN Messenger from Secway - encrypts messages before they're sent, preventing eavesdroppers from reading your MSN Messenger conversations | No |
| SimpLite-MSN | U | SimpLite-MSN.exe | SimpLite encryption add-on for MSN Messenger from Secway - encrypts messages before they're sent, preventing eavesdroppers from reading your MSN Messenger conversations | No |
| Simp | U | SimpLite-Yahoo.exe | SimpLite encryption add-on for Yahoo! Messenger from Secway - encrypts messages before they're sent, preventing eavesdroppers from reading your Yahoo! Messenger conversations | No |
| Simpmsn | X | Simpmsn.exe | Detected by Ikarus as Email-Worm.Win32.VB.fn and by Malwarebytes Anti-Malware as PasswordStealer.Agent. The file is located in %System% | No |
| Simp | U | SimpPro.exe | SimpPro encryption add-on for popular instant messengers from Secway - encrypts messages before they're sent, preventing eavesdroppers from reading your conversations | No |
| CMARP | X | simrp.exe | Detected by McAfee as RDN/Generic.bfr!a and by Malwarebytes Anti-Malware as Trojan.Agent.SPR | No |
| SIDEBARS | X | simrp.exe | Detected by McAfee as RDN/Generic.bfr!a and by Malwarebytes Anti-Malware as Trojan.Agent.SPR | No |
| sims2server | X | Sims3server.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %ProgramFiles%\rat | No |
| sims3server1 | X | Sims3server.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %ProgramFiles%\rat | No |
| scoupa | X | sincra.exe | Added by the SDBOT-ST WORM! | No |
| Singapore | X | singapore.exe | Adds a blue crescent to the taskbar and when double-clicked displays an adult-content web-site. Also known to drop your internet connection and dial an international telephone number. See here for more information. Must be disabled in MSCONFIG before un-installing or it re-instates itself | No |
| sioco | X | sioco.exe | Added by the AGENT-MOD TROJAN! | No |
| SipDiscount | N | SipDiscount.exe | SipDiscount - internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype | Yes |
| sipgate X-Lite | N | sipgateXLite.exe | "sipgate x-Lite makes telephone calling possible directly over your PC. You only need a microphone and a sound card and/or a headset" | No |
| XSC SIP Client | N | sipgateXLite.exe | "sipgate x-Lite makes telephone calling possible directly over your PC. You only need a microphone and a sound card and/or a headset" | No |
| SIPPS | U | SIPPS.exe | Web.de Internet phone utility | No |
| siren114S | X | siren114U.exe | Siren114 rogue security software - not recommended. One of the OneScan family of rogue scanner programs | No |
| SiS 6326 Accelerator | X | sis6326m.exe | Added by the MSIC BACKDOOR! | No |
| SISAM10M | X | SISAM10M.exe | Adware pop-up generator | No |
| SiS7012Utility | Y | SiSAudUt.exe | SiS Corporation sound card driver | No |
| siService.exe | U | siService.exe | Spam Inspector - anti email spam software | No |
| SiSSetCDfmt | ? | SiSSetCDfmt.exe | Related to a Silicon Integrated Systems Corp (SiS) product? | No |
| SiSSWLED | U | sisswled.exe | System Tray utility for SiS 900 network cards | No |
| Policies | X | Sistem servidor.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Windir%\twain_32\Windows | No |
| Sistem | X | Sistem servidor.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Windir%\twain_32\Windows | No |
| Sistema operacional | X | Sistem servidor.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Windir%\twain_32\Windows | No |
| sistem | X | sistem.exe | Detected by Kaspersky as Trojan.Win32.Rina.q. The file is located in %System% | No |
| sistem | X | sistem.exe | Detected by McAfee as PWS-Zbot.gen.lm and by Malwarebytes Anti-Malware as Backdoor.XTRat. The file is located in %Windir%\InstallDir | No |
| sistem | X | sistem.exe | Detected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Trojan.MSIL.gen | No |
| sistem | X | sistem.exe | Detected by McAfee as Generic.bfr!ck. The file is located in %Windir% | No |
| sistem.exe | X | sistem.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %System% | No |
| sistem.exe | X | sistem.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %UserProfile% | No |
| Windows Baþlangýç Dosyasý | X | sistem.exe | Added by the MUZK WORM! | No |
| sistrai.exe | X | sistrai.exe | Added by the PROVA TROJAN! | No |
| SiS (R) Compatible Super VGA SiSTray application | U | sistray.exe | System Tray access to display settings for Silicon Integrated Systems (SiS) based graphics chipsets. Located in %System% | Yes |
| SiS Tray | U | sistray.exe | System Tray icon for SiS based graphics. Located in %System% | No |
| sistray | X | sistray.exe | Added by the PROVA TROJAN! Located in %Windir%\command | No |
| SiSTray | U | SiSTray.exe | System Tray icon for SiS based graphics. Located in %ProgramFiles%\SiS VGA Utilities | No |
| sistray | U | sistray.exe | System Tray icon for SiS based graphics. Located in %System% | No |
| Utility Tray | U | sistray.exe | System Tray access to display settings for Silicon Integrated Systems (SiS) based graphics chipsets. Located in %System% | Yes |
| sistry | X | sistry.exe | Added by the CEBE WORM! | No |
| SiSUSBRG | N | SiSUSBrg.exe | SiS USB Registry Patch File - fixes the undetectable problem with SiS USB controller on Windows XP | No |
| SiteAdv | U | SiteAdv.exe | Preloads the McAfee SiteAdvisor browser plug-in for Internet Explorer and Firefox. "With SiteAdvisor software installed, your browser will look a little different than before. We add small site rating icons to your search results as well as a browser button and optional search box. Together, these alert you to potentially risky sites and help you find safer alternatives". Not required as it will load with your browser | Yes |
| SiteAdvisor | U | SiteAdv.exe | Preloads the McAfee SiteAdvisor browser plug-in for Internet Explorer and Firefox. "With SiteAdvisor software installed, your browser will look a little different than before. We add small site rating icons to your search results as well as a browser button and optional search box. Together, these alert you to potentially risky sites and help you find safer alternatives". Not required as it will load with your browser | Yes |
| SiteAdware.exe | X | SiteAdware.exe | SiteAdware rogue security software - not recommended, removal instructions here. A member of the AntiAID family | No |
| SiteAdvisor | U | SiteAv.exe | Refer to the "SiteAdv.exe" entry. This entry only appears to originate from version 2.0.0.75 (Build 4295) of SiteAdvisor and the registry entry incorrectly points to the invalid filename "SiteAv.exe" - when it should be "SiteAdv.exe" | Yes |
| SiteAv | U | SiteAv.exe | Refer to the "SiteAdv.exe" entry. This entry only appears to originate from version 2.0.0.75 (Build 4295) of SiteAdvisor and the registry entry incorrectly points to the invalid filename "SiteAv.exe" - when it should be "SiteAdv.exe" | Yes |
| [various names] | X | sitebar.exe | Added by an unidentified TROJAN! | No |
| SiteRanker | U | SiteRankTray.exe | "SiteRanker brings you ratings and reviews of websites while you browse and allows you to post your own ratings and reviews. By posting your ratings and reviews youll help other users stay away from websites you found to be dangerous, recommend an eshop whose services you were satisfied with, etc." Not available for download, it's usually distributed together with other products | No |
| SiteVillain | X | SiteVillain.exe | SiteVillain rogue security software - not recommended. A member of the AntiAID family | No |
| Six Engine | U | SixEngine.exe | Power management utility included with some ASUS motherboards. "The new ASUS EPU (Energy Processing Unit) - the world's first power saving engine, has been upgraded to a new 6 engine version, which provides total system power savings by detecting current PC loadings and intelligently moderating power in real-time" | No |
| sixtysix | X | sixtypopsix.exe | Medload adware | No |
| Windows Service Agent | X | sjbsm.exe | Added by the SMALLTRO.II TROJAN! | No |
| Windows Service Agent | X | sjbsmgm.exe | Added by the IRCBOT.AHX WORM! | No |
| Java Express | X | sjehost.exe | Added by the SDBOT-DNJ WORM! | No |
| MChk | X | sjzkp.exe | Added by the MDROP-CSP TROJAN! | No |
| Hot Key Kbd 2690 Daemon | U | SK2690DM.EXE | Multi-function keyboard driver. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keys | No |
| SK51 | U | SK51.EXE | SaveKeys keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| SK60 | U | SK60.EXE | SaveKeys keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| Hot Key Kbd 9910 Daemon | U | SK9910DM.EXE | Multi-function keyboard driver. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keys | No |
| SK9910DM | U | SK9910DM.EXE | Multi-function keyboard driver. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keys | No |
| 666 | X | Ska.exe | Added by the PIPES TROJAN! | No |
| USB Hub Keyboard Patch | ? | SKBPATCH.EXE | USB HUB Update | No |
| Hot Key Kbd Daemon | U | SKDAEMON.EXE | Multi-function keyboard driver. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keys | No |
| SKDAEMON | U | SKDAEMON.EXE | Multi-function keyboard driver. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keys | No |
| KERNEL 32 | X | SKERNEL32.com | Added by the SEMAPI-A WORM | No |
| SkeyAgent | X | SkeyAgent.exe | SmartKeyword adware | No |
| BBC News alerts | U | skinkers.exe | BBC News Desktop Alerts service - see here. Desktop alert and breaking news e-mail services let you find out about all the latest news as it happens | No |
| HalifaxHowardCluster | U | skinkers.exe | "Howard the Weatherman" desktop client from Halifax by Skinkers - marketing/messaging tool. Leave enabled if you want to receive messages | No |
| skinkers | U | skinkers.exe | Selection of desktop messaging/marketing tools with celebrity tie-ins including MTV's "Desktop Ozzy" and Arsenal's "Desktop Wenger" - see here. Leave enabled if you want to receive messages | No |
| SkySportsCluster | U | skinkers.exe | Sky Sports Alerter desktop client from Sky Sports by Skinkers - "delivers all the breaking sports news stories straight to your PC." Leave enabled if you want to receive messages | No |
| SkipeTurns | X | SkipeTurns.exe | Detected by Sophos as W32/Ainslot-AD | No |
| Spy-Keylogger | U | skl.exe | SpyKeylogger keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| sysApp | U | sklgr.exe | SuperKeylogger surveillance software. Uninstall this software unless you put it there yourself | No |
| Windows Network Data Management System Service | X | skp66.exe | Added by the AGENT.WNDM TROJAN! | No |
| Skra | X | Skra.exe | Identified as a variant of the TrojanDownloader.Matcash malware | No |
| sks-32 | U | sks32proc.exe | SpyKeySpy surveillance software. Uninstall this software unless you put it there yourself | No |
| sks-32 | U | SKS32P~1.EXE | SpyKeySpy surveillance software. Uninstall this software unless you put it there yourself | No |
| Skunk | X | Skunk.exe | Detected by Sophos as W32/Sunk-A | No |
| Flash Media | X | skxs��'�'%''msn'�%'fix''.exe | Added by the AGENT.ZOY TROJAN! | No |
| WINDOWS SKY | X | sky.exe | Added by the MYTOB.CH WORM! | No |
| WINDOWS SYSTEM | X | sky.exe | Detected by Trend Micro as WORM_MYTOB.LB | No |
| WINDOWS SYSTEM | X | skybot.exe | Added by the MYTOB-CX WORM! | No |
| WINDOWS SYSTEM | X | skybot.exe | Added by the MYTOB.EB WORM! | No |
| WDNS SYSTEM | X | skybotx.exe | Added by the MYTOB-BY WORM! | No |
| WINDOWS SYSTEM | X | skybotx.exe | Added by the MYTOB-BY WORM! | No |
| skynetave.exe | X | skynetave.exe | Added by the SASSER.D WORM! | No |
| Skype Startup | X | skyp.exe | Added by the VANBOT-C WORM! | No |
| 82b36685c0f383d104a799283e3fd80c | X | skypc.exe | Detected by Dr.Web as Trojan.DownLoader8.37131 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ | No |
| Skype pro.exe | X | Skype pro.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %ProgramFiles% | No |
| 8e3bc91142bd8d798a10a1667ae4d2be | X | Skype.exe | Detected by McAfee as RDN/Generic.dx!bh and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %Temp% | No |
| 9975759809ee69cc2d0562054d998149 | X | skype.exe | Detected by Dr.Web as Trojan.DownLoader7.8951 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %Temp% | No |
| HKCU | X | skype.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %System%\Skype | No |
| HKCU | X | Skype.exe | Detected by McAfee as Generic BackDoor!fqg and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %Windir%\InstallDir | No |
| HKLM | X | skype.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %System%\Skype | No |
| HKLM | X | Skype.exe | Detected by McAfee as Generic BackDoor!fqg and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %Windir%\InstallDir | No |
| MicroUpdate | X | skype.exe | Detected by Dr.Web as Trojan.DownLoader6.34482 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %MyDocuments%\Skype | No |
| Plus7 | X | Skype.exe | Detected by McAfee as RDN/Generic BackDoor!k and by Malwarebytes Anti-Malware as Backdoor.Agent. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %System%\messeger | No |
| Policies | X | skype.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %System%\Skype | No |
| Skype | N | Skype.exe | Skype is "free calls, video calls and instant messaging over the internet. Plus great value calls to phones anywhere in the world" | Yes |
| skype | X | skype.exe | Added by the MAHATO.AO TROJAN! Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %Windir% | No |
| Skype | X | Skype.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %Windir%\InstallDir | No |
| Skype | X | Skype.exe | Detected by McAfee as RDN/Generic BackDoor!k and by Malwarebytes Anti-Malware as Backdoor.Agent. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %System%\messeger | No |
| Skype | X | Skype.exe | Detected by McAfee as RDN/Generic.dx. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %AppData%\Skype\Phone | No |
| Skype Update | X | skype.exe | Detected by Dr.Web as Trojan.KillProc.22324 and by Malwarebytes Anti-Malware as Trojan.MPGen.nps. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %AppData%\Skype | No |
| SkypeStartup | X | Skype.exe | Added by the PYKSE-A WORM! | No |
| TASKMGR | X | skype.exe | Detected by McAfee as Generic.grp!mq and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %AppData% | No |
| Voice | X | skype.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.SK. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %System%\SYSTEM32 | No |
| skypee | X | skypee.exe | Detected by Sophos as Troj/Rombrast-A and by Malwarebytes Anti-Malware as Trojan.FakeSkype | No |
| SkypeMate | N | SkypeMate.exe | SkypeMate acts as a bridge between networks of VoIP and PSTN | No |
| 59259b3fd2189ff57405beed4f893fea | X | skypemc.exe | Detected by Dr.Web as Trojan.DownLoader8.31878 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ | No |
| Microsoft Update 2.5 | X | SkypePlugin.exe | Detected by McAfee as RDN/PWS-Banker and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| SkypePM | X | SkypePM.exe | Detected by Sophos as Troj/Bdoor-BDY and by Malwarebytes Anti-Malware as Trojan.Obfuscated | No |
| Skypeupdate | X | Skypeupdate.exe | Detected by Malwarebytes Anti-Malware as Trojan.MPGen.BMS. Note - this is not a legitimate entry for the popular Skype VOIP software. The file is located in %MyDocuments%\Services | No |
| Realtek Voice Manager | U | Skytel.exe | Realtek Voice Manager, installed with the drivers for on-board Realtek HD audio codecs. On an ALC885 based test system it doesn't run after the drivers have been installed and the startup entry is then removed. Disabling it appears to have no ill effects but it's exact purpose is unknown - hence the "U" recommendation | Yes |
| Skytel | U | Skytel.exe | Realtek Voice Manager, installed with the drivers for on-board Realtek HD audio codecs. On an ALC885 based test system it doesn't run after the drivers have been installed and the startup entry is then removed. Disabling it appears to have no ill effects but it's exact purpose is unknown - hence the "U" recommendation | Yes |
| [various names] | X | slamm.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| RA Server | X | Slave.exe | Added by the RA TROJAN! | No |
| Slayhacker734 | X | slay7383.exe | Added by the SIKBOT-A TROJAN! | No |
| Systems Restart | X | slchost.exe | Added by the MULTIDROP.C TROJAN! | No |
| xcxdsaa7 | X | slcskxsdl7.exe | Added by the ONLINEG-K TROJAN! | No |
| Select server | X | slcsvr.exe | Added by the DLOADER-WD TROJAN! | No |
| Streamload Downloader | N | SlDB.exe | Downloader for MediaMax (was Streamload) - "gives you a private and secure place to upload, store, access, and share your personal videos, photos, movies, music, and files" | No |
| SleepManager | N | SleepMgr.exe | This program locates free contiguous disk spaces and allocates them for storing BASE MEMORY, EXTENDED MEMORY, VIDEO MEMORY, and SM RAM. It helps the computer come out of hibernate mode | No |
| SelfHostUtil | ? | slefhost.exe | ?? | No |
| Microsoft Synchronization Manager | X | slhost.exe | Added by the SDBOT.YH WORM! | No |
| Slibe.com | U | Sliber.EXE | Sliber - freeware screen capturing & online sharing tool | No |
| SlimCleaner | U | SlimCleaner.exe | SlimCleaner from SlimWare Utilities, Inc. Community driven system cleaner and optimization utility which includes a startup/service manager, shredder, uninstaller and access to Windows system tools | Yes |
| SlimCleaner Application | U | SlimCleaner.exe | SlimCleaner from SlimWare Utilities, Inc. Community driven system cleaner and optimization utility which includes a startup/service manager, shredder, uninstaller and access to Windows system tools | Yes |
| SlimComputer | U | SlimComputer.exe | SlimComputer from SlimWare Utilities, Inc. Community driven system optimization utility which includes a startup/service manager, uninstaller and access to Windows system tools | Yes |
| SlimComputer Application | U | SlimComputer.exe | SlimComputer from SlimWare Utilities, Inc. Community driven system optimization utility which includes a startup/service manager, uninstaller and access to Windows system tools | Yes |
| slimp3 | N | SliMP3 Server.exe | Slimp3 Server - "presents an entirely new way of accessing and enjoying your music collection. Instead of storing your music on CDs or memory cards, the SliMP3 uses your home network to access the music stored on your PC" | No |
| Slingshot | N | SLINGS~1.EXE | Atomica Slingshot - "reference tool with access to dictionary and encyclopedia terms, bios, technical terms, history, geography, and much more". Now superseed by 1-Click Answers | No |
| slipcore | Y | slipcore.exe | Core module for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet, Wanadoo, Terra, OnSpeed, United Online and AOL Canada. Required if the user's account is locked in to that proxy server | No |
| SlipStream | Y | slipcore.exe | Core module for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet, Wanadoo, Terra, OnSpeed, United Online and AOL Canada. Required if the user's account is locked in to that proxy server | No |
| ISP.COM High Speed | Y | slipgui.exe | User interface for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet, Wanadoo, Terra, OnSpeed, United Online and AOL Canada. Required if the user's account is locked in to that proxy server | No |
| slipgui | Y | slipgui.exe | User interface for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet, Wanadoo, Terra, OnSpeed, United Online and AOL Canada. Required if the user's account is locked in to that proxy server | No |
| [random filename] | X | slk8x2peu.exe | QuickLinks adware | No |
| slmss | X | slmss.exe | Detected by Trend Micro as ADW_SECTHOUGHT.A | No |
| sload | X | sload.exe | Win SynchroAd adware, also detected as DLOADER-QG TROJAN! | No |
| sload | X | sload32.exe | Added by the SDBOT-OY WORM! | No |
| EGTSOFT System Locker | U | slocker.exe | Active System Locker by Sowsoft, LLC - "a handy utility that allows you to protect your personal computer from unauthorized access". Originally released as "EGTSOFT System Locker" by EGTSOFT | No |
| LTM2 | X | slogan.exe | Added by the LITMUS.203 BACKDOOR! | No |
| Internal Configuration Serving State | X | sloka.exe | Detected by Dr.Web as Trojan.DownLoader5.57797 and by Malwarebytes Anti-Malware as Trojan.VirTool | No |
| Windows Svchost Authority | X | slsass.exe | Added by the RBOT-UA WORM! | No |
| System LifeGuard Scheduler | U | Slsched.exe | System LifeGuard scheduler | No |
| Windows Service | X | slserv32.exe | Added by the RBOT-KO WORM! | No |
| NAV Auto Updates | X | slserver.exe | Added by the SDBOT.LT BACKDOOR! | No |
| NAV Auto Updates | X | slserves.exe | Added by the RBOT.COI BACKDOOR! | No |
| 27 | X | slsorve.exe | Added by the SLSORVE-A TROJAN! | No |
| msoft-updater23 | X | slssystem.exe | Detected by Sophos as W32/Rbot-ASR | No |
| Windows Update 32 | X | slsys.exe | Detected by Sophos as W32/Forbot-FT and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| slvchost32 | X | slvchost32.exe | Added by an unidentified VIRUS, WORM or TROJAN! | No |
| Logical Volume | X | slvhost.exe | Added by the SDBOT.FWC BACKDOOR! | No |
| Hollaback | X | slvhosts.exe | Added by the SDBOT.BMO WORM! | No |
| SLZ.mp3 | X | SLZ.mp3.exe | Detected by Dr.Web as Win32.HLLW.Autoruner1.14180 and by Malwarebytes Anti-Malware as Worm.AutoRun.SL | No |
| Web Service | X | sm.exe | Added by the BUBE-F VIRUS! | No |
| SM1BG | N | SM1BG.EXE | USB driver for downloading from within Napster and iTunes to portable MP3 players. Only required at startup if you use it all the time - otherwise start it manually when required | No |
| SM1NINT | N | SM1NINT.exe | Cypress USB Mass Storage Driver Notification Icon Application - tray notification for Cypress base memory sticks and external storage devices for Win98 | No |
| SM56ACL | N | sm56hlpr.exe | Helper utility for Motorola based SM56 software modems - resides in the System Tray | No |
| SMSERIAL | N | sm56hlpr.exe | Helper utility for Motorola based SM56 software modems - resides in the System Tray | No |
| sma | U | sma.exe | SmartKeylogger keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| SManager | X | smanager.6.exe | Added by the AGENT.BJO TROJAN! | No |
| SManager | X | smanager.7.exe | Added by the DWNLDR-GVG TROJAN! | No |
| smapcore17 | X | smapcore17.exe | Detected by McAfee as Downloader.a!cz3 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Smart Antivirus-2009.exe | X | Smart Antivirus-2009.exe | Smart Antivirus 2009 rogue security software - not recommended, removal instructions here | No |
| Smart Security | X | smart.exe | Smart Security rogue security software - not recommended, removal instructions here | No |
| Windows Smart Manager | X | smart.exe | Added by the RBOT-SL WORM! | No |
| dRMON SmartAgent | U | SmartAgt.exe | Part of the network monitoring program group for 3Com NIC cards. See here for more info | No |
| SmartAudio | U | SmartAudio.exe | Conexant SmartAudio PC audio chipset software - typically available on notebooks with built-in microphones | No |
| smartbarupdate | X | SmartBarUpdate.exe | SmartBar adware | No |
| SmartBarXP | N | SmartBarXP.exe | SmartBarXP is a bar that runs down the side of your screen, and can be configured to display interactive panels known as 'panes'. These panes include media players, slideshow and image viewing panes, a virtual desktop manager, and live news, weather and stock feeds to mention but a few | No |
| SmartBoan | X | SmartBoan.exe | SmartBoan rogue security software - not recommended, removal instructions here | No |
| SmartCopy | ? | SmartCopy.exe | Related to SmartCopy from Northstar Systems Corp. What does it do and is it required? | No |
| Lotus SmartCenter | N | smartctr.exe | Lotus SmartSuite central application, called SmartCenter, which runs on the Windows desktop. SmartCenter toolbar stretches across the top or, optionally, the bottom of the screen. Uses a lot of resources. Available via Start → Programs | No |
| sMaRTcaPs | N | SMARTC~1.EXE | sMaRTcaPs from Phoebus LLC - enables you to configure the time needed to depress Caps Lock, Num Lock & Insert keys | No |
| ASUS SmartDoctor | U | SmartDoctor.exe | "ASUS SmartDoctor is a group of special tools to help users make the most of their ASUS graphics cards. It monitors the Fan RPM, AGP Power Level, GPU and RAM temperature, and has a slide bar for easy manual overclocking" | No |
| BootClean | X | smartdrv.exe | Added by the LURKA-A VIRUS! | No |
| SmartEx | N | SmartEx.exe | SmartException from Stardock Corporation - "is a utility that can be used to help gather additional information about an application that has crashed". Run manually via the Start menu if you experience problems with an application crashing | Yes |
| SmartException | N | SmartEx.exe | SmartException from Stardock Corporation - "is a utility that can be used to help gather additional information about an application that has crashed". Run manually via the Start menu if you experience problems with an application crashing | Yes |
| SmartFaceVWatcher | Y | SmartFaceVWatcher.exe | Toshiba's Face Recognition that allows the user login to their laptop hands-free via the built-in webcam on some models | No |
| TOSHIBA Face Recognition Watcher | Y | SmartFaceVWatcher.exe | Toshiba's Face Recognition that allows the user login to their laptop hands-free via the built-in webcam on some models | No |
| Smartfixer | X | SmartFixer.exe | SmartFixer rogue system error and cleaning utility - not recommended | No |
| Smart Keyboard | U | Smartkbd.exe | Netropa Smart Keyboard driver | No |
| SmartLauncher | ? | SmartLauncher.exe | Related to SmartLauncher from Northstar Systems Corp. What does it do and is it required? | No |
| SmartMenu | Y | SmartMenu.exe | Included on most HP Pavilion desktop and laptop PCs. "Used to launch the MediaSmart application from keyboards and remote controls. Do not disable this program" - see here | No |
| Smart Protector Pro | U | SmartProtector-Pro.exe | Smart Protector Pro internet eraser from SmartSoft - "keeps out prying eyes and protects your private data on all Windows systems" | Yes |
| SmartProtector-Pro | U | SmartProtector-Pro.exe | Smart Protector Pro internet eraser from SmartSoft - "keeps out prying eyes and protects your private data on all Windows systems" | Yes |
| SPSTEALT | U | SmartProtector-Pro.exe | Smart Protector Pro internet eraser from SmartSoft - "keeps out prying eyes and protects your private data on all Windows systems" | Yes |
| smartprotector | X | smartprotector.exe | Smart Protector rogue security software - not recommended, removal instructions here | No |
| SPSTEALT | U | SmartProtectorPro.exe | Smart Protector Pro - internet privacy tool that erases tracks, MRU lists, etc | No |
| smartprotect | X | smartprotect_up.exe | SmartProtect rogue security software - not recommended, removal instructions here | No |
| SmartRanking | X | SmartRanking.exe | Detected by Malwarebytes Anti-Malware as Adware.Korad. The file is located in %ProgramFiles%\SmartRanking | No |
| SmartSecurity | X | SmartSecurity.exe | Smart Security rogue security software - not recommended, removal instructions here | No |
| SmartSoft PDF Printer Agent | N | SmartSoft PDF Printer Agent.exe | Virtual printer agent for Smart PDF Creator from SmartSoft | No |
| Extend-Supporter-totalvaccine | X | smartsupporter_totalvaccineEx.exe | TotalVaccine rogue security software - not recommended | No |
| SmartSync Pro | U | SmartSync.exe | Related to CompanionLink Software Inc. Synchronization solutions for ACT!, GoldMine, Lotus Notes and Microsoft Outlook | No |
| SmartTool | X | SmartTool.exe | Detected by Kaspersky as AdWare.NSIS.SideTab.a | No |
| smartvaccine | X | smartvaccineu.exe | Detected by Malwarebytes Anti-Malware as Rogue.K.SmartVaccine - not recommended. One of the OneScan family of rogue scanner programs | No |
| SmartWeb | X | smartweb.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%\My UserPrograms | No |
| SkySurfer Management Service | Y | SmaServ.exe | For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system | No |
| SmartAudio | U | SMAUDIO.EXE | Conexant SmartAudio PC audio chipset software - typically available on notebooks with built-in microphones | No |
| SmAudio | U | SmAudio.exe | Conexant SmartAudio PC audio chipset software - typically available on notebooks with built-in microphones | No |
| Smax4 | N | Smax4.exe | System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel | Yes |
| SoundMAX | N | Smax4.exe | System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel | Yes |
| SoundMAX Control Panel | N | Smax4.exe | System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel | Yes |
| SMax4PNP | U | SMax4PNP.exe | Analog Devices SoundMax integrated soundcard utility. Brings up the SoundMAX Control Panel when it detects if new audio devices (such as microphones, headphones, speakers, etc.) are plugged in - giving the user the option to configure them. Also required if you have custom settings for your sound, such as effects and environments | Yes |
| SMax4PNP Application | U | SMax4PNP.exe | Analog Devices SoundMax integrated soundcard utility. Brings up the SoundMAX Control Panel when it detects if new audio devices (such as microphones, headphones, speakers, etc.) are plugged in - giving the user the option to configure them. Also required if you have custom settings for your sound, such as effects and environments | Yes |
| SoundMAXPnP | U | SMax4PNP.exe | Analog Devices SoundMax integrated soundcard utility. Brings up the SoundMAX Control Panel when it detects if new audio devices (such as microphones, headphones, speakers, etc.) are plugged in - giving the user the option to configure them. Also required if you have custom settings for your sound, such as effects and environments | Yes |
| Windows SMB Manager | X | smb32.exe | Added by the RBOT-BHZ WORM! | No |
| smbdpmi | ? | smbdpmi.exe | IBM Netfinity Director and Universal Management Services related. What does it do and is it required? | No |
| Backup One | X | smbguard.exe | Added by the SDBOT-MI WORM! | No |
| SMBHelper | X | SMBHelper.exe | Detected by Malwarebytes Anti-Malware as Trojan.Ransom. The file is located in %AppData%\Microsoft\Windows\4481 | No |
| Microsoft Internel Corporat | X | smbvhost.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| smc | X | smc.exe | Added by the EBOD TROJAN! Note - this is not the valid (but now discontinued) Sygate Personal Firewall which has the same filename and is normally located in %ProgramFiles%\Sygate\SPF. This one is located in %System% | No |
| smc | Y | smc.exe | Sygate Firewall | No |
| SMC Service | Y | smc.exe | Sygate Firewall | No |
| SmcService | Y | smc.exe | Sygate Firewall | No |
| SmcServices | Y | smc.exe | Sygate Firewall | No |
| Sygate Personal Firewall | X | smc.exe | Added by the RBOT-AZY WORM! Note - this is not the valid (but now discontinued) Sygate Personal Firewall which has the same filename and is normally located in %ProgramFiles%\Sygate\SPF. This one is located in %System% | No |
| Sygate Personal Firewall | Y | smc.exe | Sygate Personal Firewall - now discontinued | No |
| System Microsoft Core | X | smc.exe | Detected by AhnLab as Win32/IRCBot.worm.23102. The file is located in %System%\inetsrv | No |
| Windows Update Service | X | smcg.exe | Detected by Trend Micro as WORM_SDBOT.QY and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| sacmemds | X | smcntlwio.exe | Added by the MAILBOT-BZ TROJAN! | No |
| smcss | X | smcss.exe | Added by the SCLOG-AJ TROJAN! | No |
| System Messaging Queue | X | SMCSS.EXE | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| System Startup Manager | X | smcss.exe | Added by the RBOT.AMD WORM! | No |
| Smcsta.exe | ? | Smcsta.exe | SMC Networks wireless PCI card driver. Is it required? | No |
| SmcSVR | X | SmcSVR.exe | Added by the LEGMIR.JU TROJAN! | No |
| control panel | N | smctrlw.exe | System Tray icon for a Silicon Motion LynxEM based PCI Graphics Card | No |
| cpssystem | X | smdlsset.exe | Added by the SLAPER.P TROJAN! | No |
| smgr | X | smgr.exe | Added by an unidentified WORM or TROJAN! | No |
| RPCall_[ComputerName] | X | smhost.exe | Added by the REDPLUT-B TROJAN! | No |
| Smss Host | X | smhost.exe | Added by the IRCBOT-ACC TROJAN! | No |
| Spooler Host | X | smhost.exe | Added by the IRCBOT.BSQ BACKDOOR! | No |
| Microsoft Internet Explorer | X | smiissm.exe | Added by the DELF-KK TROJAN! | No |
| SmileboxTray | N | SmileboxTray.exe | System Tray access to Smilebox photo sharing/printing service | No |
| Smileycons | N | smileycons.exe | Smileycons - free smileys, emoticons and animations package | No |
| Smith Micro try | N | smiptray.exe | Smith Micro shared files. Comes with D-Link web cam | No |
| SMSI Loader | N | SMLoader.exe | Smith Micro HotFax - fax software | No |
| Windows System Configuration Loader | X | smls.exe | Detected by Trend Micro as WORM_AGOBOT.RP | No |
| 38cb851033610a7fdb771b3c6c8b90e1 | X | smm.exe | Detected by Dr.Web as Trojan.DownLoader7.13935 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| Awoa | X | smmo.exe | PurityScan adware | No |
| smms | X | smms.exe | Detected by Dr.Web as Trojan.MulDrop4.26985 and by Malwarebytes Anti-Malware as Trojan.Agent.RND | No |
| Client Server Runtime Process | X | smmss.exe | Backdoor TROJAN! Possible SDBOT-GEN variant | No |
| Smart Security | X | SMM[random characters].exe | Smart Security rogue security software - not recommended, removal instructions here. The filename is typically in the form "SM***_***.exe" | No |
| blah service | X | smnp.exe | Detected by Trend Micro as WORM_RBOT.IZ | No |
| WINDOWS SYSTEM | X | smoc.exe | Added by the MYTOB.FU WORM! | No |
| smodul | U | smodule.exe | UserMonitor from Neuber. Teachers can broadcast screen to other screens, see students screens in a network and detect unauthorized software | No |
| MicroedSoft Toolbar | X | Smoked.exe | Added by the RBOT-ALN WORM! | No |
| SmoothView | N | SmoothView.exe | TOSHIBA Zooming Utility - allows "automatic" zoom feature in some appications, like IE, MS-Office, WMPlayer, Adobe Reader and also desktop icons | No |
| SMPAutoStart | U | smpdemo.exe | Smart Phone Recorder demo from KenGolf.com. Answering Machine, Caller ID, Call Recording | No |
| ELNKProxy | X | smproxy.exe | Surfmonkey adware | No |
| SmpcSys | U | SmpSys.exe | "Set Up My PC" utility supplied with some Packard Bell computers | No |
| ShockmachineReminder | N | SmReminder.exe | Macromedia Shockmachine is a stand-alone application that lets users collect Macromedia Shockwave and Flash titles and play them offline. Now discontinued. Could be a registration reminder for the trial version? | No |
| smres | X | smres.exe | Added by the AGOBOT-UA WORM! | No |
| Ethernet Drivers | X | smrrs.exe | Added by the RBOT-AAK WORM! | No |
| vsadmin | X | smrs.exe | Added by the AGOBOT-RC WORM! | No |
| smrss | X | smrss.exe | Added by the BANPAES-B TROJAN! | No |
| Smart Defender PRO | X | smrtdefp.exe | Smart Defender PRO rogue security software - not recommended, removal instructions here | No |
| smrtprt | X | smrtprt.exe | Smart Protector rogue security software - not recommended, removal instructions here | No |
| 1234 | X | sms.exe | Detected by Dr.Web as Trojan.DownLoader1.53350 and by Malwarebytes Anti-Malware as Trojan.Agent.Gen | No |
| (Default) | X | sms.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.SM. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %AppData% | No |
| Connector | X | sms.EXE | Added by the ExDial-B premium rate adult content dialer | No |
| KernelFaultChk | X | sms.exe | Added by the DEADHAT WORM! Do not confuse with the valid "kernelfaultcheck" which runs "dumprep 0 -k" | No |
| Microsoft Virual Machine | X | sms.exe | Added by the RBOT-SP WORM! | No |
| RunOnceEx | X | sms.exe | IESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN! | No |
| Windows Messages Controler | X | sms.exe | Detected by Dr.Web as Trojan.StartPage.47023 and by Malwarebytes Anti-Malware as Backdoor.Agent.WMC | No |
| smsa | X | smsa.exe | Detected by Dr.Web as Trojan.Inject1.153 and by Malwarebytes Anti-Malware as Worm.IMP.Trace. Note - this entry loads from the Windows Startup folder and the file is located in %AppData%\Win88E6680F | No |
| smsa | X | smsa.exe | Detected by McAfee as Generic Downloader.x and by Malwarebytes Anti-Malware as Worm.IMP.Trace. Note - this entry loads from the Windows Startup folder and the file is located in %AppData%\Win74630177 | No |
| Configuration Loader | X | smsai.exe | Added by the SDBOT-YE WORM! | No |
| ApplicationProtocolRun | X | smsbvl32.exe | Added by the IRCBOT-CX TROJAN! | No |
| Shell | X | smsc.exe | Added by the BANCBAN-OY TROJAN! | No |
| Sonic RecordNow! | X | smsc.exe | Added by a variant of W32/Sdbot.worm | No |
| System Management Service | X | smsc.exe | Added by the RBOT-ANN WORM! | No |
| Win32 USB2 Driver | X | smsc.exe | Detected by Trend Micro as WORM_SDBOT.FO | No |
| Windows Services | X | smsc.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.Gen | No |
| WINDOWS SYSTEM | X | smsc.exe | Added by the MYTOB-BR WORM! | No |
| Windows System Manager | X | smsc.exe | Added by a variant of Win32/Rbot | No |
| WSSVC | X | smsc.exe | Added by the AUTORUN-AGA WORM! | No |
| EventApplicationCmd | X | smschk.exe | Added by the IRCBOT-AO TROJAN! | No |
| SmsDiscount | N | SmsDiscount.exe | SmsDiscount - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype | Yes |
| GLSetT32 | X | smsiexec.exe | Added by the OPTIX-D TROJAN! | No |
| Windows System Manager Loader | X | smsls.exe | Detected by Trend Micro as WORM_AGOBOT.TF | No |
| smsm | X | smsm.exe | Added by the BANKER-CO TROJAN! | No |
| SMS Win9x Message Agent | U | SMSMsg.exe | This program assigns a user to a Systems Management Server site | No |
| WINTASK DLL32 | X | smsrss.exe | Added by the MYTOB.BS WORM! | No |
| run= | Y | smsrun16.exe | Microsoft Systems Management Server (SMS) related - program that reads SMSRUN16.INI on clients running Win 3.1, Windows for Workgroups, Win95, or OS/2 to create program groups on the client and then launch SMS client programs | No |
| smsrv | X | smsrv.exe | Added by the AGOBOT-SX WORM! | No |
| Services.dll | X | smss.exe | Added by the SOBER-L WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\system and note the space at the beginning of the "Startup Item" field | No |
| winsystem.sys | X | smss.exe | Added by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\win32 and note the space at the beginning of the "Startup Item" field | No |
| .nvsvc | X | smss.exe | Added by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup! | No |
| _Services.dll | X | smss.exe | Added by the SOBER-L WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\system | No |
| _winsystem.sys | X | smss.exe | Added by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\win32 | No |
| ac81fa871a4336b2440cb3826cd12647 | X | smss.exe | Detected by Dr.Web as Trojan.DownLoader7.21651 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp% | No |
| AntiVir | X | smss.exe | Detected by Sophos as Troj/DwnLdr-GWE and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles% | No |
| AutoUpdate | X | smss.exe | Added by WINSPY.88! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64 | No |
| baidu | X | smss.exe | Added by the AGENT-FV MALWARE! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\dmcz | No |
| BreakPoint Software | X | smss.exe | Detected by Dr.Web as Trojan.Siggen.13737 and by Malwarebytes Anti-Malware as Backdoor.Agent.SF. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Windows NT | No |
| Chrome | X | smss.exe | Detected by McAfee as Generic BackDoor!fpl and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\InstallDir | No |
| Debug | X | SMSS.exe | Detected by Symantec as Adware.DreamAd. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| DHCP | X | smss.exe | Detected by Kaspersky as Monitor.Win32.WinSpy.88. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\display | No |
| Explorer | X | smss.exe | Detected by McAfee as Generic BackDoor!fpl and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\InstallDir | No |
| fa3c99036e85131dab81f132665aa15a | X | smss.exe | Detected by Dr.Web as Trojan.DownLoader7.23039 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData% | No |
| flashget | X | smss.exe | Added by the DROPPR.SMAB TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\20111027\255qlw2anwq2ewte and note the space at the beginning of the "Startup Item" field | No |
| FrameWorkService | X | smss.exe | Added by the KUKOO-A WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Inf | No |
| HKCU | X | smss.exe | Detected by McAfee as RDN/Generic.bfr!h and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "schost" sub-folder | No |
| HKLM | X | smss.exe | Detected by McAfee as RDN/Generic.bfr!h and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "schost" sub-folder | No |
| info | X | smss.exe | Added by the VB.EIW WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\inetsrv | No |
| INTEL | X | smss.exe | Detected by McAfee as Generic.IL and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData% | No |
| InteliSys | X | smss.exe | Advertisingvision adware. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| internet | X | smss.exe | Added by the MIFENG-K TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup! | No |
| Kernel Safe Mode | X | smss.exe | Added by the 78CRACK-A TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| KernellApps32 | X | smss.exe | Detected by Sophos as Troj/Bancban-AN and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup! | No |
| LiveUpdate | X | smss.exe | Added by the VB.BAU BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas | No |
| MDSA Sentinel X | U | smss.exe | SentinelX surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the smss.exe process which is always located in %System%. This one is located in %ProgramFiles%\MDSA Software | No |
| Microsoft Session Manager Subsystem | X | smss.exe | Added by the KALEL-D WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup! | No |
| Microsoft Windows Session Manager Subsystem | X | smss.exe | Added by the PROXYSER-R TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| MULTIMEDIA KEYBOARD88 | X | smss.exe | Added by the SILLYFDC WORM! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup! | No |
| NarmonVirusAnti | X | smss.exe | Added by the AUTORUN-DV WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder | No |
| NT_Authority | X | smss.exe | Added by the SILLYFDC-EY WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData% | No |
| Policies | X | smss.exe | Detected by McAfee as RDN/Generic.bfr!h and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "schost" sub-folder | No |
| Remove 54tr10 | X | smss.exe | Detected by Sophos as W32/Brontok-CH and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData% | No |
| RPCserv32g | X | SMSS.EXE | Detected by Trend Micro as WORM_BOBAX.AD. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Service Process | X | smss.exe | Added by the DCMBOT-E TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "config" subfolder | No |
| Services Process | X | smss.exe | Added by the SMALL-EK TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "config" subfolder | No |
| smss | X | smss.exe | Added by the AGENT-TR TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| smss | X | smss.exe | Added by the BOROBOT-J TROJAN and variants! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup! | No |
| SMSS | X | smss.exe | Added by the FLOOD.F BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "Catroot" subfolder | No |
| smss | X | smss.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft | No |
| smss | X | smss.exe | Detected by Dr.Web as Trojan.DownLoader6.24391 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData% | No |
| smss | X | smss.exe | Detected by Microsoft as Worm:Win32/Racos.A and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\fonts | No |
| smss | X | smss.exe | Detected by Symantec as Trojan.Syginre and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root% | No |
| Smss.exe | X | smss.exe | Detected by Symantec as W32.Dalbug.Worm. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| smssLevel4 | X | smss.exe | Unidentified malware! ! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Windows Media Player\Skins\WindowsMediaSkin\Data\Level4 | No |
| Spooler Subsystem Application | X | smss.exe | Added by the IRCBOT-ZO TROJAN! Note - the legitimate smss.exe process should not normally figure in Msconfig/Startup! | No |
| ssystems | X | smss.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| System | X | smss.exe | Added by the AGENT.EP BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| SYSTEM MONITORING | X | SMSS.EXE | Detected by McAfee as Generic VB.i and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%\WINDOWS | No |
| System Session Manager | X | smss.exe | Added by the KALEL-E WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup! | No |
| SysUtils | X | smss.exe | Added by the AUTORUN-AWW WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile% | No |
| Tok-Cirrhatus | X | smss.exe | Detected by Sophos as W32/Brontok-A and variants! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData% | No |
| Tok-Cirrhatus-2784 | X | smss.exe | Detected by Sophos as W32/Brontok-S. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData% | No |
| Torjan Program | X | smss.exe | Added by the WOWCRAFT.B TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| userinit | X | smss.exe | Detected by Sophos as Troj/Dloadr-B and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| VB and VBA Program Settings | X | smss.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData% | No |
| Virscanner | X | smss.exe | Detected by Sophos as Troj/DwnLdr-GWE and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Windows | X | smss.exe | Added by the BANCBAN-QF TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Windows | X | smss.exe | Added by the AUTOIT.AQH TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData% | No |
| Windows Font Manager | X | smss.exe | Added by the ZANAYAT.B WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\fonts | No |
| Windows Media Center | X | smss.exe | Added by the WARBOT TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Windows Session Manager Subsystem | X | smss.exe | Added by the KALEL-B WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup! | No |
| WinDOwsUPdate | X | smss.exe | Added by the AUTORUN.DIB WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder | No |
| winsmss | X | smss.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| zsms | X | smss.exe | Added by the BANCOS-CK TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| zsmss | X | smss.exe | Added by the BANCOS-DD TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Configuration Loader | X | smss32.exe | Added by the AGOBOT.MB WORM! | No |
| Graphic Driver | X | smss32.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| loadMefs | X | smss32.exe | Added by the FLOOD-EL TROJAN! | No |
| Microsoft DirectX | X | SMSS32.exe | Added by the SDBOT-FP WORM! | No |
| Microsoft Internet Services | X | smss32.exe | Added by the RBOT.MS WORM! | No |
| Microsoft Services | X | Smss32.exe | Added by the RBOT-AD WORM! | No |
| Microsoft Update | X | Smss32.exe | Added by the RBOT-CB WORM! | No |
| MSConfig32 | X | smss32.exe | Added by the FLOOD-EL TROJAN! | No |
| smss32.exe | X | smss32.exe | Added by the FAKEAV-ATH TROJAN! | No |
| UsbD | X | smss32.exe | Adware - detected by Kaspersky as the AGENT.CJ TROJAN! | No |
| Windows Session Manager | X | smss32.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| Session Manager Subsystem | X | smssa.exe | Added by the RBOT-AGS WORM! | No |
| .nvsvcb | X | smssb.exe | Added by the BOXED.CG TROJAN! | No |
| Windows Update | X | smsscr.exe | Detected by Sophos as Troj/Banker-DK and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| SMS Server | X | smsserv.exe | Added by the RBOT-4 WORM! | No |
| System Config Manager | X | smssl.exe | Added by the AGOBOT-ZJ WORM! | No |
| MSN | X | smsss.exe | Added by the BUZUS-D WORM! | No |
| SMSSS | X | smsss.exe | Added by the SDBOT.ZD WORM! | No |
| SMSSS Loader | X | smsss.exe | Detected by Trend Micro as WORM_AGOBOT.MQ | No |
| start uploading | X | smsss.exe | Added by a variant of the SDBOT BACKDOOR! | No |
| SMSSU | X | SMSSU.EXE | Added by the STARTPAGE.O TROJAN! | No |
| Audoi Device Loader | X | smssv.exe | Added by the AGOBOT-ZY WORM! | No |
| eczsors | X | smssvc.exe | Detected by McAfee as Generic Dropper and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| My App | X | SMSSvc.exe | Added by the NEGASMS.A TROJAN! | No |
| Sms System32 | X | SmsSystem32.exe | Unidentified malware | No |
| [random] | X | smssz.exe | Detected by Malwarebytes Anti-Malware as Spyware.OnlineGames.SMGen. The file is located in %System% - see examples here and here | No |
| Startup Manager | U | smstartUp manager.exe | Startup Manager from the Advanced System Optimizer utility suite by Systweak Inc | No |
| SMSTray | U | SMSTray.exe | System tray access to the Emodio (or the older Samsung Media Studio) management application for Samsung MP3 players | No |
| SMSvc32 | X | smsvc32.exe | Added by the AGOBOT-OL WORM! | No |
| AhnLab V3Lite Update Process | X | SMSvcHost.exe | Detected by McAfee as RDN/Generic.bfr!y and by Malwarebytes Anti-Malware as Trojan.Zbot.DTGen. Note - this is not a legitimate AhnLab V3 entry | No |
| Windows server | X | smsvr.exe | Detected by Trend Micro as WORM_MEPAOW.LX | No |
| SMSystemAnalyzer | U | SMSystemAnalyzer.exe | Part of the Iolo System Mechanic optimization tool | No |
| sms_msn | X | sms_msn.exe | Added by an unknown WORM or TROJAN! | No |
| sms_msn40 | X | sms_msn40.exe | Added by an unknown WORM or TROJAN infection | No |
| Smt | U | SMT.exe | Win-Spy keyboard logger/monitoring software - remove unless you installed it yourself | No |
| SMToolbar | N | SMToolbar.exe | StartMake.com toolbar | No |
| SMTP32 Mailing Protocol | X | smtp32.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| Smapp | X | Smtray.exe | Detected by Dr.Web as Win32.HLLW.Autoruner1.27603 and by Malwarebytes Anti-Malware as Trojan.Kryptik. Note - this is not the legitimate System Tray icon for Analog Devices SoundMax integrated soundcards which is typically located in %ProgramFiles%\Analog Devices\SoundMAX. This one is located in %AppData%\SoundMAX | No |
| Smapp | N | Smtray.exe | System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel. Typically located in %ProgramFiles%\Analog Devices\SoundMAX | Yes |
| SMTray | N | Smtray.exe | System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel. Typically located in %ProgramFiles%\Analog Devices\SoundMAX | Yes |
| SoundMAX Integrated Digital Audio | N | Smtray.exe | System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel. Typically located in %ProgramFiles%\Analog Devices\SoundMAX | Yes |
| iolo Utility Bar | N | SMUtilityBar.exe | Utility Bar from older versions of Iolo's System Mechanic tune-up utility suite | No |
| ActiveXUpdate | X | smvss.exe | Added by the DEDLER-C TROJAN! | No |
| devenv | X | smvss.exe | Added by the HORST TROJAN! | No |
| MicrosoftOEM | X | smvss.exe | Added by the DEDLER-G TROJAN! | No |
| MSInstall | X | smvss.exe | Added by the DEDLER-G TROJAN! | No |
| OfficeGuardUI | X | smvss.exe | Added by the DEDLER-C TROJAN! | No |
| SoundControl | X | smvss.exe | Added by the DEDLER-C TROJAN! | No |
| SoundMixer | X | smvss.exe | Added by the DEDLER-G TROJAN! | No |
| SunJavaUpdate | X | smvss.exe | Added by the DEDLER-G TROJAN! | No |
| CM-SmWizard | ? | SmWizard.exe | SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required? | No |
| SmWizard | ? | SmWizard.exe | SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required? | No |
| csrss | X | smxss.exe | Detected by Microsoft as TrojanDownloader:Win32/CoinMiner.E and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| LocalSys | X | smxss.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Root%\Users\Public | No |
| Security Master AV | X | SM[random characters].exe | Security Master AV rogue security software - not recommended, removal instructions here | No |
| Smart Engine | X | SM[random characters].exe | Smart Engine rogue security software - not recommended, removal instructions here. The filename is typically in the form "SM***_***.exe" | No |
| Smart Virus Eliminator | X | SM[random characters].exe | Smart Virus Eliminator rogue security software - not recommended, removal instructions here | No |
| sm | X | sm_exe.exe | Added by the OLFEB.A TROJAN! | No |
| SnagIt 10 | N | SnagIt32.exe | "SnagIt by TechSmith - lets you capture, edit, and share exactly what you see on your screen - fast" | No |
| SnagIt 5 | N | SnagIt32.exe | "SnagIt by TechSmith - lets you capture, edit, and share exactly what you see on your screen - fast" | No |
| SnagIt 6 | N | SnagIt32.exe | "SnagIt by TechSmith - lets you capture, edit, and share exactly what you see on your screen - fast" | No |
| SnagIt 7 | N | SnagIt32.exe | "SnagIt by TechSmith - lets you capture, edit, and share exactly what you see on your screen - fast" | No |
| SnagIt 8 | N | SnagIt32.exe | "SnagIt by TechSmith - lets you capture, edit, and share exactly what you see on your screen - fast" | No |
| SnagIt 9 | N | SnagIt32.exe | "SnagIt by TechSmith - lets you capture, edit, and share exactly what you see on your screen - fast" | No |
| Snaking | X | Snaking.VBS | Detected by Kaspersky as Trojan-Dropper.Win32.Snak and by Malwarebytes Anti-Malware as Trojan.Agent.VBS | No |
| Snapfish Media Detector | U | SnapfishMediaDetector.exe | Snapfish Media Detector - "Upload your photos to Snapfish, where you can store and share your photos for free on line" | No |
| SnapfishMediaDetector | U | SnapfishMediaDetector.exe | Snapfish Media Detector - "Upload your photos to Snapfish, where you can store and share your photos for free on line" | No |
| snapple | X | snapple.exe | Added by the FORBOT-EG WORM! | No |
| snappydeeSA | X | snappydeeSA.exe | Detected by Malwarebytes Anti-Malware as Adware.HotBar.CP. The file is located in %AppData%\snappydeeSA\bin\[version] | No |
| snbr | ? | snbr.exe | ?? | No |
| snbupt | X | snbupt.exe | UpSpiralBar adware | No |
| sncntr | X | sncntr.exe | Added by the DLUCA-I TROJAN! | No |
| Windows Audio | X | snd.exe | Added by the ACKANTTA.C WORM! | No |
| Windows Sound Emulator | X | snd32_win.exe | Added by the ATNAS.A WORM! | No |
| snd332 | X | snd332.exe | Added by the B1LD0 AIM WORM! | No |
| sounddrv | X | sndbdrv3104.exe | CoolWebSearch parasite variant | No |
| MS Sound Config 16bit | X | sndcfg16.exe | Added by the SDBOT.AN WORM! | No |
| WinProfile | X | sndcfg16.exe | Detected by Total Defense as Win32.Sndc.A | No |
| Sndcompat | X | Sndcompat.exe | Added by the GEMA TROJAN! | No |
| Ac97Sound | X | snddrv.exe | Added by the VB.AXG TROJAN! | No |
| microsystem | X | snddrv.exe | Added by the VB.AXG TROJAN! | No |
| Sound Loader | X | sndloader.exe | Detected by Trend Micro as WORM_AGOBOT.CC | No |
| SoundMax Audio Drivers | X | SndMAX.exe | Added by a variant of W32/Sdbot.worm | No |
| Windows Audio Service | X | sndmic32.exe | Added by the ACKANTTA.C WORM! | No |
| SNDMon | Y | SNDMon.exe | Part of Symantec's LiveUpate for older versions of Symantec's security products including Norton Internet Security, Norton AntiVirus and the now discontinued Norton SystemWorks suite. Leave alone to ensure virus definitions are updated. Also, if SNDMon is disabled on one of the computers on a small office network then other computers disappear from the network for this computer, including shared devices like printers and scanners | No |
| Symantec NetDriver Monitor | Y | SNDMon.exe | Part of Symantec's LiveUpate for older versions of Symantec's security products including Norton Internet Security, Norton AntiVirus and the now discontinued Norton SystemWorks suite. Leave alone to ensure virus definitions are updated. Also, if SNDMon is disabled on one of the computers on a small office network then other computers disappear from the network for this computer, including shared devices like printers and scanners | No |
| Windows Sound Manager | X | SndMon16.exe | Added by a variant of the FORBOT WORM! | No |
| Windows Sound Driver | X | SndMon32.exe | Added by a variant of the SPYBOT WORM! | No |
| Windows Sound Manager | X | SndMon32.exe | Added by the FORBOT-BU WORM! | No |
| Sndsaver | X | Sndsaver.exe | Added by the GEMA TROJAN! | No |
| SNDSrvc | Y | SNDSRVC.EXE | Common process for older versions of Symantec's security products including Norton Internet Security and the now discontinued Norton AntiSpam and Norton SystemWorks suite. Used for the scanning of incoming POP3 emails for viruses, threats or spam. Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| Auto Start | X | sndvol32.exe | Added by the SLINBOT.AX BACKDOOR! Note - the is not the legitimate MS volume control utility which is always located in %System% and should not normally figure in Msconfig/Startup! | No |
| update driver | X | SNDVOL32.EXE | Added by the SPYBOT-CU BACKDOOR! | No |
| SND Volumes | X | sndvolumes.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| Symantec NetDriver Warning | U | SNDWarn.exe | Part of Symantec Live Update - displays the warning when you need to update the firewall database | No |
| run | X | snhcwb.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Windir%\apppatch | No |
| SystemWizard Sniffer | U | Sniffer.exe | SystemWizard for Win98/ME from SystemSoft - diagnoses and solves hardware and software problems on a PC | No |
| Snippet | U | SnippingTool.exe | The Snipping Tool (part of the Experience Pack for Tablet PC) allows you to easily "cut out" anything on screen and share it with other people. The whole screen becomes an "inkable" surface that you can add comments to and mark up however you like. You can then save that annotated image to use later, or send it to someone else in an E-mail message | No |
| Microsoft Update | X | snlogsvc.exe | Added by the SDBOT.CN BACKDOOR! | No |
| SNM | U | SNM.exe | SpyNoMore spyware remover - previously not recommended, see here | No |
| Inom | X | snmoo.exe | Added by the RBOT-DPM WORM! | No |
| SysTray | X | Snnpapi.exe | Detected by SUPERAntiSpyware as Trojan.SNNPAPI.Process. The file is located in %System% | No |
| Snoop | U | Snoop.exe | Snoop surveillance software. Uninstall this software unless you put it there yourself | No |
| Systemp | X | snoop.exe | Detected by Dr.Web as Trojan.Siggen4.1076 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| SnoopFreeUI | U | SnoopFreeUI.exe | SnoopFree Privacy Shield SnoopFree Software - anti-keylogging software | No |
| Snow.exe | X | Snow.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.Gen. The file is located in %AppData% | No |
| snqpu | X | snqpu.exe | Detected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\plusup | No |
| Snsicon | N | Snsicon.exe | Launches a screensaver program from Second Nature | No |
| SNSS.EXE | X | SNSS.EXE | Nunci premium rate dialer | No |
| stryvertion | X | snss.exe | Detected by Dr.Web as Trojan.DownLoader8.21719 and by Malwarebytes Anti-Malware as Trojan.Downloader | No |
| Dot.net Networking | X | SNSS32.EXE | Detected by Trend Micro as WORM_RBOT.BOI | No |
| Classes | X | snt.exe | QuickPage - Switch dialer and hijacker variant, see here. Also detected as the SWITCH-A TROJAN! | No |
| Diskstart | X | Snt.exe | Startportal - Switch dialer and hijacker variant, see here. Also detected as the DELF-JE TROJAN! | No |
| OpenMstart | X | Snt.exe | MStart2Page - Switch dialer and hijacker variant, see here. Also detected as the SWITCH-E TROJAN! | No |
| Windows Event Section | X | sntsvc.exe | Added by a variant of the IRCBOT TROJAN! See here | No |
| Sysnet | X | snuninst.exe | Unidentified adware | No |
| snvc | X | snvc.exe | Added by an unidentified WORM or TROJAN! | No |
| Application In System | X | Snxmsh.exe | Added by the AGENT-LNV TROJAN! | No |
| SNyOgdLFyXub.exe | X | SNyOgdLFyXub.exe | Detected by Malwarebytes Anti-Malware as Trojan.Foury. The file is located in %CommonAppData% | No |
| SecureOnlineAccountNumbers | U | SOAN.exe | Related to Secure Online Account Numbers by Discover(R) Card from Orbiscom Ltd. Secure and innovative payment solutions | No |
| System Soap Pro | X | soap.exe | System Soap Pro internet cleaning software. Bundles foistware like Httper and Zipclix - best avoided | No |
| Norton Live Updater | X | Sochost.exe | Detected by Symantec as W32.HLLW.Gaobot.AO | No |
| Social.IM | N | SocialChat.exe | Social.IM Facebook instant messenger by iSkoot Inc - no longer available | No |
| ZoneAlarm SocialGuard | U | SocialGuard.exe | ZoneAlarm SocialGuard advanced security for Facebook - "scans millions of records using a unique algorithm to determine threats and sends warnings to you the minute they happen, not just once a day like the competition" | Yes |
| ZoneAlarm SocialGuard | U | SOCIAL~1.EXE | ZoneAlarm SocialGuard advanced security for Facebook - "scans millions of records using a unique algorithm to determine threats and sends warnings to you the minute they happen, not just once a day like the competition" | Yes |
| Sock32 | X | sock32.exe | Added by the SDBOT BACKDOOR! | No |
| Socket Utility | X | socket.exe | Added by the DAEMONI-E TROJAN! | No |
| Microsoft standard protector | X | socks.exe | Detected by Spybot-S&D as Tibs.vq. The file is located in %Windir%\inet200[2 digits] | No |
| services | X | socks.exe | Added by the WIN32.SMALL.N TROJAN! | No |
| ASocksrv | X | SocksA.exe | Added by the VB.CBW WORM! | No |
| blah service | X | socksxt.exe | Added by a variant of Win32/Rbot | No |
| Services | X | sockys32.exe | Added by the RANKY.L TROJAN! | No |
| SoDA Startup | Y | SodaStartup.exe | Used by the IBM Rational SoDA project management tool. Unsure of it's actual purpose but it's recommended you leave it enabled if you use the software | No |
| Microsoftf DDEs Control | X | soff.pif | Added by the RBOT-AKH WORM! | No |
| soffice | N | SOFFICE.EXE | Part of StarOffice by StarDivision - a proprietary office suite and the predecessor of OpenOffice. Displays the quick start applet in the System Tray. Right clicking on the icon allows rapid starting up of components of the StarOffice suite. Automatically started when any StarOffice component is run from the Start menu and is a resource hog (it uses more than 16 MB of memory) | No |
| soft2PC | X | soft2pc.exe | Detected by Malwarebytes Anti-Malware as Adware.EoRezo | No |
| SoftAuto.exe | N | SoftAuto.exe | Auto-updater for Creative Labs software | No |
| SoftBarrier | X | SoftBarrier.exe | SoftBarrier rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| SoftCop | X | SoftCop.exe | SoftCop rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| SoftDisc | N | softdisc.exe | SoftDisc by EZB Systems, Inc - "is an image file creating/editing/managing tool. It also lets you emulate a virtual CD or directly burn a CD image file - that is handy when you, for example, need a CD in use when playing a game" | No |
| Service System | X | softdwind.exe | Added by the BANCOS-JS TROJAN! | No |
| hErcUnes | X | softhost.exe | Added by the GARROCH WORM! | No |
| Software Informer | N | softinfo.exe | Software Informer Client by Informer Technologies, Inc - "is a program that has been specially designed for those users who care to keep their applications functional and ready for any task that may arise. Its primary aim is to give you up-to-date information about the software you actually use" | No |
| Softload | X | softload.exe | Added by the SDBOT-SV WORM! | No |
| aaLDSoftMon | U | SoftMon.EXE | LANDesk® Management Suite software component | No |
| csoftok | X | softok.exe | Added by the QQPASS.G TROJAN! | No |
| SoftSafeness | X | SoftSafeness.exe | SoftSafeness rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| SoftSoldier | X | SoftSoldier.exe | SoftSoldier rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| SoftStronghold | X | SoftStronghold.exe | SoftStronghold rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| SoftStuff Wallpaper Changer | U | softstrt.exe | AzureBay wallpaper changer | No |
| SoftVeteran | X | SoftVeteran.exe | SoftVeteran rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| Software | X | software.exe | Added by the CRABTON-B TROJAN! | No |
| Helper | X | softwareHP.exe | Detected by Malwarebytes Anti-Malware as Adware.EoRezo. The file is located in %AppData%\Soft2PC\Software | No |
| UpdateTuto4PCHP | X | SoftwareHP.exe | Detected by McAfee as Adware-Tuto4PC and by Malwarebytes Anti-Malware as Adware.EoRezo | No |
| Modulo Update | X | SoftwareUpdateHP.exe | Detected by Malwarebytes Anti-Malware as Adware.EoRezo. The file is located in %AppData%\EoRezo\EoRezo | No |
| SoftwareHelper | X | SoftwareUpdateHP.exe | Detected by Malwarebytes Anti-Malware as Adware.EoRezo. The file is typically located in %AppData%\EoRezo\EoRezo or %AppData%\EoRezo\SoftwareUpdate | No |
| BALL | X | Sogou.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.SG. The file is located in %CommonFiles% | No |
| Ball | X | Sogou.exe | Detected by Dr.Web as Trojan.DownLoader7.24194 and by Malwarebytes Anti-Malware as Trojan.ChinAd | No |
| hao567 | X | Sogou.exe | Detected by Dr.Web as Trojan.DownLoader6.62518 and by Malwarebytes Anti-Malware as Backdoor.Zegost | No |
| systen | X | Sogou.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor. The file is located in %CommonFiles% | No |
| xiaoyu | X | Sogou.exe | Detected by Dr.Web as Trojan.DownLoader7.26386 | No |
| IDO Port | X | SogouPinyinUp.exe | Detected by McAfee as BackDoor-AWQ | No |
| Iomega StorCenter | ? | sohoclient.exe | Related to the Iomega StorCenter range of networked storage products | No |
| SO5 Integrator Pass One | ? | sointgr.exe | Part of StarOffice 5 by StarDivision - a proprietary office suite and the predecessor of OpenOffice | No |
| SO5 Integrator Pass Two | ? | sointgr.exe | Part of StarOffice 5 by StarDivision - a proprietary office suite and the predecessor of OpenOffice | No |
| CHIPDRIVEPinManager | U | sokscmpn.exe | ChipDrive Smartcard software | No |
| Msconfige | X | solari.exe | Added by the AUTORUN-GU WORM! | No |
| SolidCapture | N | solidcapture.exe | SolidCapture - screen capture and image sharing toolkit | No |
| Solid Key Logger | U | SolidKeyLogger.exe | Solid Key Logger keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| SoloSchedule | U | Solocfg.exe | Scheduler for Solo Antivirus. Leave enabled unless you scan manually on a regular basis | No |
| Solo Sentry | Y | Solosent.exe | Solo Antivirus | No |
| somatic | X | somatic.exe | Searchcentrix hijacker | No |
| BLAB | X | somi3.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Messa. The file is located in %AppData%\soni3 | No |
| msn.exe | X | son.exe | Added by the STARTPA-GS TROJAN! | No |
| sbitunesagent | N | songbirditunesagent.exe | "Manage you music and videos, build playlists, browse, search, and sort. Then sync your music to your portable music player or phone. Songbird makes it simple | No |
| songs | X | songs.exe | Added by the AGENT-SEG TROJAN! | No |
| E-Color Registration | N | SonnReg.exe | Registration for Colorific® and 3Deep® monitor calibration software from E-Color. Now superseded by ColorWizzard and 3DxWizzard | No |
| SonnReg | N | SonnReg.exe | Registration for Colorific® and 3Deep® monitor calibration software from E-Color. Now superseded by ColorWizzard and 3DxWizzard | No |
| Ci Servs | X | Sontiwin.exe | Added by the VB-PD MALWARE! | No |
| SonudMan | X | SonudMan.exe | Added by the STARTPAGE.Q TROJAN! | No |
| SonudMon | X | SonudMon.exe | Added by the LEWOR-J TROJAN! | No |
| Image Transfer | N | SonyTray.exe | Sony Image Transfer software provides direct image transfer from your digital camera to a PC - can be started manually | No |
| Picture Package Menu | N | SonyTray.exe | System Tray access to Sony "Picture Package®" software for their range of Digital Handycam video cameras | No |
| SonyVaio | X | SonyVaio.exe | Detected by Malwarebytes Anti-Malware as Trojan.VBKrypt. The file is located in %AppData% | No |
| sophagnt | ? | sophagnt.exe | Possibly related to Sophocles Screenwriting Software? | No |
| MqNrGCelXZp | X | SorIPhcHBDl.exe | Detected by McAfee as Generic.dx!bhdr and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| REGRUN | X | sory.exe | Adware downloader - detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS! | No |
| Nasiso | X | sos.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
| SOS | X | SOS.exe | Added by the PHILIS VIRUS! | No |
| sos.exe | X | sos.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %System% | No |
| NTSF MICROSOFT SYSTEM | X | soscks32.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| Nasiso | X | sosx.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.WDR. The file is located in %Windir% - see here | No |
| SoSyncMonitor | ? | SoSyncMonitor.exe | SuperOffice related. What does it do and is it required? | No |
| [Chinese characters] | X | sougou.exe | Detected by Dr.Web as Trojan.StartPage.45465 and by Malwarebytes Anti-Malware as Trojan.Agent.CNGen. The file is located in %Windir%\Web | No |
| SOUNDMAN Microsoft Help | X | soun.pif | Detected by Sophos as W32/Rbot-AIU | No |
| AUDIO | X | SOUND.exe | Added by the PLOYB-A TROJAN! | No |
| Microsoft Server Application | X | Sound.exe | Added by the RBOT-NE WORM! | No |
| rgservs | X | sound.exe | Detected by Dr.Web as Win32.HLLW.Autoruner1.24962 and by Malwarebytes Anti-Malware as Backdoor.Agent. The file is normally located in %AppData% | No |
| rgservs | X | sound.exe | Detected by Kaspersky as Worm.Win32.AutoRun.cemy and by Malwarebytes Anti-Malware as Backdoor.Agent. The file is normally located in %UserTemp% | No |
| Servicio | X | sound.exe | Added by the BAMKER-FFT TROJAN! | No |
| Sound | X | Sound.exe | Detected by McAfee as RDN/Ransom!br and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Sound.exe Espanha | X | Sound.exe | Added by the AGENT-OUD TROJAN! | No |
| Windows Sound Manager | X | sound.exe | Detected by Microsoft as Worm:Win32/Gaobot.FC | No |
| Microsoft Sound Driver | X | sound32.exe | Added by a variant of the SPYBOT WORM! | No |
| Sound services | X | SOUND32.EXE | Detected by Trend Micro as WORM_AGOBOT.GG | No |
| [various names] | X | sound64.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Micr Update | X | soundblaster.exe | Detected by Trend Micro as WORM_SDBOT.NP | No |
| Logitech Camera | X | Soundcane.exe | Added by the SDBOT.MUC WORM! | No |
| SoundcardAudiocodec | X | SoundcardAudiocodec.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData% | No |
| Configuration Loader | X | soundconf.exe | Added by the AGOBOT-MH WORM! | No |
| soundcontrl | X | soundcontrl.exe | Added by the GAOBOT.AFJ WORM! | No |
| Compaq Sound Drivers For WINDOWS | X | sounddr.exe | Added by the SDBOT-XG WORM! | No |
| Intel (R) Sound Driver | X | SoundDriver.exe | Detected by Dr.Web as Trojan.MulDrop4.170 and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| Microsoft Windows Sound Drivers | X | sounddrivers.exe | Added by the SLENFBOT.ABU WORM! | No |
| Windows Stand Sound Drivers | X | Sounddrv.exe | Added by the SDBOT-XF WORM! | No |
| Microsoft Sounds | X | soundman.exe | Added by the RBOT-GCI WORM! | No |
| mysys | X | soundman.exe | Added by the AGENT.DCJH TROJAN! | No |
| Realtek HD Sound Manager | U | SOUNDMAN.EXE | Realtek Sound Manager, installed with the drivers for on-board Realtek HD audio codecs. On an ALC885 based test system it doesn't run after the drivers have been installed and the startup entry is then removed. Disabling it appears to have no ill effects but it's exact purpose is unknown - hence the "U" recommendation | Yes |
| SISSoundman | ? | Soundman.exe | Related to a Silicon Integrated Systems Corp (SiS) product? | No |
| SoundMan | X | soundman.exe | Added by the AGOBOT.HM WORM! Note - this is not the legitimate SiS or Realtek file of the same name that is located in %Windir%, this one is located in %System% | No |
| SOUNDMAN | X | SOUNDMAN.exe | Detected by Dr.Web as Trojan.MulDrop4.31106 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate SiS or Realtek file of the same name that is located in %Windir%, this one is located in %System%\dllcache | No |
| SoundMan | U | SOUNDMAN.EXE | Realtek Sound Manager, installed with the drivers for on-board Realtek HD and AC97 audio codecs. On an AC97 based system it gives System Tray access to the audio control panel (which is also available via the system Control Panel). On an ALC885 HD based test system it doesn't run after the drivers have been installed and the startup entry is then removed - disabling it appears to have no ill effects but it's exact purpose is unknown | Yes |
| soundman.exe | X | soundman.exe | Added by the AGENT-HKD TROJAN! Note - this is not the legitimate SiS or Realtek file of the same name that is located in %Windir%, this one is located in %System% | No |
| Taskman | X | soundman.exe | Added by the VB-ETL TROJAN! Note - this is not the legitimate SiS or Realtek file of the same name that is located in %Windir%, this one is located in the "Help" sub-folder | No |
| Windows Sound Driver | X | soundman.exe | Detected by Kaspersky as Backdoor.Win32.Rbot.gen. The file is located in %System% | No |
| SoundMax | X | Soundmax.exe | Added by the MALAS-A VIRUS! Note - this file is located in %ProgramFiles%\Sound Utility and has NO relation to SoundMax sound cards! | No |
| SoundMAX | X | SoundMAX.exe | Added by the RIZON-A WORM! Note - this file is placed in the Startup folder itself, and has NO relation to SoundMax sound cards! | No |
| SoundMAX | N | soundmax.exe | System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel. Located in %ProgramFiles%\Analog Devices\SoundMAX | No |
| SoundMax.exe | X | SoundMax.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. Note - this file is located in %LocalAppData% and has NO relation to SoundMax sound cards! | No |
| soundmix | X | soundmix.exe | Detected by Trend Micro as WORM_AGENT.PGV | No |
| Soundmx | X | Soundmx.exe | CoolWebSearch Tapicfg parasite variant | No |
| BLUESTACKS | X | sounds.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.BLS. Note - this is not a legitimate BlueStacks entry and the file is located in %Windir% | No |
| MotherBoard Sounds | X | Sounds.exe | Added by the RBOT-AAP WORM! | No |
| Microsoft Intrenet Explorer | X | Soundsyst.exe | Added by the RBOT-AQU WORM! | No |
| soundtask | X | soundtask.exe | Added by the AGOBOT-MD WORM! | No |
| soundtasks | X | soundtasks.exe | Added by a variant of the CRYPTER.C TROJAN! | No |
| soundtctrls | X | soundtctrls.exe | Added by the AGOBOT-ZV WORM! | No |
| Sound View | X | SoundView.exe | Detected by Dr.Web as Trojan.MulDrop4.1089 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| Microsoft | X | soundvol32.exe | Added by the RBOT.CIJ BACKDOOR! | No |
| sounofts | X | sounofts.exe | Added by the AGOBOT-ND WORM! | No |
| sountskmanager | X | sountaskmgr | Added by an unidentified WORM or TROJAN! | No |
| SP TimeSync | U | SP TimeSync.exe | SP TimeSync lets you synchronize your computer's clock with any Internet atomic clock (time server) | No |
| sp | X | sp.exe | Detected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| sp | X | sp.reg | IE search hijacker - changes the default search to http://www.gocybersearch.com/ | No |
| nwss | U | Sp0.exe | SpyOutside surveillance software. Uninstall this software unless you put it there yourself | No |
| Windows Update Service | X | SP00ISS.exe | Detected by Sophos as W32/Sdbot-ZH and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| huigezi | X | SP00LSV.EXE | Added by the GRAYBIRD.J BACKDOOR! Note the digit "0" in the command | No |
| SP00LSV | X | Sp00lsv.exe | Added by the GRAYBIRD.E TROJAN! | No |
| (L4r1$$4) (4nt1) (V1ruz) | X | SP00Lsv32.pif | Added by the ASSIRAL.B WORM! | No |
| SVCH0TS | X | sp00lvs.exe | Added by the LINEAGE-AZ TROJAN! | No |
| SP1 Critical Update | X | sp1update.exe | Added by the WOOTBOT.BG WORM! | No |
| SP1-Update | X | sp1update.exe | Added by the RBOT-JG WORM! | No |
| Firewall | X | SP2 UPDATE.exe | Added by the ELITPER.E WORM! | No |
| Fdr Command Module | X | sp2.exe | Added by the SDBOT.WP WORM! | No |
| Microsoft Update Machine | X | SP2.exe | Added by the SPYBOT.FP WORM! | No |
| WindowsSp2 | X | sp2.exe | Added by the POSSE WORM! | No |
| sp2chk.exe | X | sp2chk.exe | Added by an unidentified WORM or TROJAN! | No |
| SP2 Connection Patcher | U | SP2ConnPatcher.exe | Changes the limit of concurrent TCP connections attempts imposed with Windows XP SP2 onwards. Typically installed with peer-to-peer (P2P) file-sharing clients such as Warez P2P, BearShare and LimeWire | No |
| SP2ConnPatcher | U | sp2connpatcher.exe | Changes the limit of concurrent TCP connections attempts imposed with Windows XP SP2 onwards. Typically installed with peer-to-peer (P2P) file-sharing clients such as Warez P2P, BearShare and LimeWire | No |
| sp2ctr | X | sp2ctr.exe | Added by the DLUCA-M TROJAN! | No |
| Microsoft Security Management | X | sp2fix.exe | Added by the RBOT.UB WORM! | No |
| sp2fwxp | X | sp2fwxp.exe | Added by the SMALL.ABW TROJAN! | No |
| Win SSL | X | SP2s.exe | Detected by Trend Micro as WORM_RBOT.BBI | No |
| sp2svc | X | sp2svc.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| ATIVIRUSUPDATEB | X | Sp2SYs.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %System%\msSP2 | No |
| sdfsdfsdf | X | sp2update.exe | Added by a variant of the SPYBOT WORM! | No |
| sp2update | X | sp2update.exe | SP2Update adware! Tracks URLs visited and search terms entered into Internet Explorer | No |
| Windows SP2 Update | X | Sp2update.exe | Added by the WOOTBOT.BS WORM! | No |
| Microsoft (R) Windows Network Latency Controller | X | sp2vc.exe | Added by a generic password stealer TROJAN - see here | No |
| WINTASKMGR | X | sp2winfix.exe | Added by the MYTOB.KJ WORM! | No |
| Winsock32driver | X | sp2XPupdate.exe | Added by the HACKARMY.S BACKDOOR! | No |
| Win386 | X | sp32.dll | Homepage hijacker. Not a dll but a regfile in disguise | No |
| Microsoft Updates 5 USB | X | sp3fixer.exe | Added by the RBOT-ADS WORM! | No |
| GBSpaceMan | Y | SpaceMan.exe | GreenBorder - secure your browsing activities on the internet | No |
| Negative | X | spain.exe | Added by the BANKER-EXJ TROJAN! | No |
| spamihilator | U | spamihilator.exe | Spamihilator - spam filter | No |
| MSKExe | U | spamkiller.exe | McAfee SpamKiller - a rule-based and list-based spam filter | No |
| Spam Monitor | U | SpamMonitor.Exe | System Tray access to Spam Monitor from PC Tools - which "is an easy-to-use spam filter that detects and isolates unsolicited junk mail sent to your mailbox. Designed for computer users, not experts, Spam Monitor's step-by-step wizard configures your PC with the safest anti-spam settings automatically" | Yes |
| SpamMonitor | U | SpamMonitor.Exe | System Tray access to Spam Monitor from PC Tools - which "is an easy-to-use spam filter that detects and isolates unsolicited junk mail sent to your mailbox. Designed for computer users, not experts, Spam Monitor's step-by-step wizard configures your PC with the safest anti-spam settings automatically" | Yes |
| SpamMonitor Application | U | SpamMonitor.Exe | System Tray access to Spam Monitor from PC Tools - which "is an easy-to-use spam filter that detects and isolates unsolicited junk mail sent to your mailbox. Designed for computer users, not experts, Spam Monitor's step-by-step wizard configures your PC with the safest anti-spam settings automatically" | Yes |
| SpamPal | U | spampal.exe | SpamPal - anti-spam tool | No |
| Spam Sleuth | U | SpamSleuth.exe | Spam Sleuth E-mail spam detection program | No |
| spamsubtract | U | SpamSub.exe | InterMute SpamSubtract - junk email detection and removal program. InterMute is now part of Trend Micro and their products are no longer supported | No |
| SpamSubtract | U | SpamSubtract.exe | Intermute SpamSubtract - junk email detection and removal program | No |
| Anti Spam Service | X | spamsvc.exe | Added by the MYTOB-BK WORM! | No |
| Spare Backup | U | SpareBackup.exe | Spare Backup - "Once Spare Backup is installed, backups are automatic. With Spare Backup it's easy, you don't even have to select files for backup, Spare Backup does it for you" | No |
| Spark | U | Spark.exe | Spark instant messaging client | No |
| SparVoip | N | SparVoip.exe | SparVoip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype | Yes |
| Nasiso | X | spcezof.exe | Detected by Dr.Web as Trojan.Inject1.11387 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Systems Restart | X | spchost.exe | Added by an unidentified WORM or TROJAN! | No |
| TaskList | X | SPCHOSTS.EXE | Detected by Dr.Web as Trojan.DownLoader5.45485 | No |
| Speaking Clock Deluxe | U | SpClDlx.exe | Speaking Clock Deluxe - turns your computer into a speaking clock with several languages. It can also keep track of up to 50 alarms that can be set to a time and a date, and be repeated daily, weekly, monthly and yearly | No |
| Service Pack DLL Runtime | X | spdll32.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| SPD Driver | X | spdpool.exe | Added by the BCKDR-REA BACKDOOR! | No |
| Spdstart | N | Spdstart.exe | Norton Utilities Speed Start. "This feature optimizes the start up speed of launching applications, such as Word and Excel." | No |
| DSL Monitor | N | spdstrm.exe | Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray | No |
| pcEXPLODE | X | specialfile.exe | Detected by Trend Micro as WORM_RBOT.RH | No |
| specialguardstart.exe | X | specialguardstart.exe | SpecialGuard rogue security software - not recommended, removal instructions here | No |
| SpecialOffers | X | SpecialOffers*.exe [* = digit] | SpecialOffers adware | No |
| SpecialOffers | X | SpecialOffers.exe | SpecialOffers adware | No |
| specialvaccinestart.exe | X | specialvaccinestart.exe | SpecialVaccine rogue security software - not recommended, removal instructions here | No |
| specific | X | specixic.exe | Added by a variant of W32/Sdbot.worm | No |
| FastTrack Accelerator | N | SPEED UP.EXE | FastTrack Accelerator - "speedup" utility for programs that use the FastTrack network such as KaZaA Media Desktop, Grokster and Morpheus | No |
| d9bae609eb51f8ca1766366d36a7ee5d | X | SpeeD-UP.exe | Detected by McAfee as RDN/Generic PUP.x!qk and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ | No |
| 4d1b0684289ba8306488bf50cb53da98 | X | speed.exe | Detected by Dr.Web as Trojan.DownLoader7.4194 and by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Temp% | No |
| DRIVER_ | X | SPEED.exe | Detected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %Windir% | No |
| SDStart | X | speeddownupgrade.exe | Detected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %AppData%\speeddown | No |
| SDup2Start | X | speeddownuphp.exe | Detected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %AppData%\speeddown | No |
| SpeedItUp | U | SPEEDITUP.EXE | Speed It Up - "all in one Speed Booster designed to significantly increase the speed of your computer and boost your PC available memory". Installs PC-Checkup and Search Defender (which is detected by DrWeb as the STARTPAGE.ORIGIN TROJAN) without permission | No |
| SpeedItUpEX | U | SpeedItUpEx.exe | "Speed-It-Up Extreme is designed to speed of your computer up to 3 times faster and boost your PC available memory" | No |
| Microsoft Intellitype Pro | U | speedkey.exe | Additional keyboard shortcuts on MS programmable keyboard | No |
| Speedkey | U | SPEEDKEY.EXE | Additional keyboard shortcuts on MS programmable keyboard | No |
| SpeedMeter | U | SpeedMeter.exe | Application measuring upload and download speed | No |
| T-DSL SpeedMgr | N | speedmgr.exe | T-Online ISP SpeedManager - shows upload and download speed. Also checks for updates automatically | No |
| SpeedRunner | X | SpeedRunner.exe | Identified as a variant of the TrojanDownloader.Matcash malware | No |
| SpeedswitchXP | U | SpeedswitchXP.exe | SpeedswitchXP is a CPU frequency control for notebooks running Windows XP | No |
| Speed Tec | U | speedtec.exe | Accel SpeedTec from Montana Software speeds up your modem. SpeedTec modifies the Internet Protocol settings in the Windows registry to speed downloads on all modems. If you find this improves your connectivity and download speeds leave this enabled | No |
| SpeedUpMyPC | U | speedupmypc.exe | Older version of SpeedUpMyPC from Uniblue Systems Limited - which "lets you monitor and control all your PC resources with easy, one click instructions. System settings, internet usage, disk clutter, RAM and CPU are all automatically scanned, cleaned and optimized for peak performance" | Yes |
| Uniblue SpeedUpMyPC | U | SpeedUpMyPC.exe | Older version of SpeedUpMyPC from Uniblue Systems Limited - which "lets you monitor and control all your PC resources with easy, one click instructions. System settings, internet usage, disk clutter, RAM and CPU are all automatically scanned, cleaned and optimized for peak performance" | No |
| SpeedUpMyPC | U | SPEEDU~1.EXE | Older version of SpeedUpMyPC from Uniblue Systems Limited - which "lets you monitor and control all your PC resources with easy, one click instructions. System settings, internet usage, disk clutter, RAM and CPU are all automatically scanned, cleaned and optimized for peak performance" | Yes |
| Systam13 | X | speedwin.exe | Added by the RBOT.GVH BACKDOOR! | No |
| Spees2 | X | Speedy.bat | Added by the OPASERV.AD WORM! | No |
| Spees3 | X | Speedy.pif | Added by the OPASERV.AD WORM! | No |
| Spees1 | X | speedy.scr | Added by the OPASERV.Y WORM! | No |
| Speenus | X | speenusup.exe | Detected by Dr.Web as Trojan.DownLoader6.2897 and by Malwarebytes Anti-Malware as Adware.K.LineLink | No |
| Windowsxp | X | Speicher-77.exe | Detected by Dr.Web as Trojan.MulDrop4.14463 and by Malwarebytes Anti-Malware as Trojan.Dropper | No |
| FileProtector | X | spfirewall.exe | Detected by McAfee as MultiDropper-SG and by Malwarebytes Anti-Malware as Trojan.Avkill | No |
| spywarefighterguard | U | spfprc.exe | Spyware Fighter - anti spyware program | No |
| smc | Y | spfsmc.exe | Sygate Firewall | No |
| SMC Service | Y | spfsmc.exe | Sygate Firewall | No |
| SmcServices | Y | spfsmc.exe | Sygate Firewall | No |
| zSPGuard | U | Spguard.exe | "StartPage Guard (SPG) protects your PC from cyberscam, by detecting and preventing any unauthorized changes to your internet browser's Start and Search pages. It is also capable of removing automatically most of known 'invaders'." | No |
| Windows Firewalll | X | sphost.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| Spiceworks | U | spicetray_silent.exe | System Tray access to Spiceworks - which "combines everything you need to manage IT in one easy-to-use application" | No |
| SpIDerMail | Y | spiderml.exe | DrWeb antivirus Spider Mail e-mail scanner | No |
| Spiffy | U | spiffy.exe | Spiffy Gmail notifier - email notification utility | No |
| Spinner Plus | N | spinner.exe | "Spinner Plus lets you listen to over 100 channels of music broadcast from Spinner.com. Spinner Plus uses RealNetwork's G2 technology to provide high-quality online audio. The technology adjusts the audio streaming to match your Internet connection speed, which helps eliminate sound distortion or choppiness". Available via Start → Programs | No |
| MVS Splash | N | Splash.exe | Splash screen for the now obsolete McAfee Managed VirusScan anti-virus and anti-spyware security tool for small businesses | No |
| myCIO.com Splash | N | Splash.exe | Splash screen for the now obsolete McAfee VirusScan ASaP online anti-virus and anti-spyware security tool for small businesses | No |
| Introducing Media Manager | N | SPLASHA.EXE | MS Media Manager tour. Not required | No |
| TabletWizard | U | SPLSHWRP.EXE | Microsoft Tablet PC Component | No |
| StationPlaylistStudio | U | SPLStudio.exe | StationPlaylist Studio - "simple to use on-air broadcast playback software for the studio and/or DJ" for small to medium sized radio broadcasters, and internet webcasters | No |
| splwow32 | X | splwow32.exe | Added by the DLDR-FC TROJAN! | No |
| SSS6_SPM | ? | spm.exe | Part of the Security Suite 6 set of data protection utilities from Steganos - now superseded by Privacy Suite | No |
| SonyPowerCfg | U | SPMgr.exe | Related to Sony VAIO Power Management Module installed on laptops and provides additional configuration options for these devices | No |
| PC Speed Maximizer | U | SPMLauncher.exe | PC Speed Maximizer optimization utility from Avanquest Software S.A. | No |
| ChangeICON | U | SPMSMON.EXE | Card reader related program. Note - may cause problems with My Computer loading at startup. Disabling through MsConfig seems to solve the problem | No |
| hozjnvdxhq | X | spnikeo.exe | Detected by Dr.Web as Trojan.DownLoader6.53107 | No |
| qjtz | X | spnikeo.exe | Detected by Malwarebytes Anti-Malware as Adware.SanctionedMedia. The file is located in %System% | No |
| SPnt | X | SPnt.exe | Premium rate adult content dialler | No |
| SpeedOptimizer | U | spo.exe | SpeedOptimizer is designed to optimize and speed-up your Internet data transmission including browsing, streaming, downloading, uploading and e-mail communication | No |
| spoolsv | X | spoclsv.exe | Added by the FUJACKS-M WORM! | No |
| svcshare | X | spoclsv.exe | Added by the FUJACKS-A VIRUS! | No |
| SpokeSysTray | U | SpokeSysTray.exe | Spoke Software client application. Spoke "uses data in your e-mail and other enterprise information systems to discover the existing relationships of people in your enterprise. It then builds a private, secure relationship network for each user without any additional manual data entry" | No |
| helpmanager | X | spoler.exe | Added by the RANDEX.J WORM! | No |
| Shell Extension | X | spollsv.exe | Added by the LOVGATE.Z WORM! | No |
| Print Services | X | spolserv32.exe | Added by the RBOT.ZP WORM! | No |
| Microsoft | X | spolsv.exe | Added by the PWS-BOO TROJAN! | No |
| SpoolService | X | spolsv.exe | Added by the AGOBOT-CS WORM! | No |
| Winsock2 driver | X | SPOLSV.EXE | Added by the SPYBOT-CM WORM! | No |
| (Default) | X | spolsvr2.exe | Added by the EVILSOCK.10 TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank | No |
| sponsormatch | X | sponsormatch.exe | Detected by Symantec as SponsorKeyword and by Malwarebytes Anti-Malware as Adware.K.SponsorMatch | No |
| sponsormatch | X | sponsormatchagent.exe | Detected by Symantec as SponsorKeyword and by Malwarebytes Anti-Malware as Adware.K.SponsorMatch | No |
| sPoNVC | X | sPoNVC.exe | Detected by McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.Agent.ZAD. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| spoo1sv | X | spoo1sv.exe | Added by the SOULJET TROJAN! | No |
| SVCH0ST | X | spoo1sv.exe | Added by the VB-HF TROJAN! | No |
| SpoolerSubSystemProcess | X | SpooI32.exe | Added by the EHKS.21 keylogger! Note - the "I" between "o" and "3" is a capital "i" not a lower case "L" | No |
| Spooler SubSystem App | X | spooIsv.exe | Added by the LINKBOT.M WORM! | No |
| Microsoft Spool ** Service | X | spool**.exe | Added by a variant of W32.IRCBot - where ** represents a 2 digit number. The file is located in %System% | No |
| autoload | X | spool.exe | Detected by Sophos as Troj/Agent-GSG | No |
| Microsoft Update | X | spool.exe | Detected by Sophos as Troj/Agent-GJC | No |
| ntuser | X | spool.exe | Added by the DLOADER.DYA TROJAN! | No |
| Print Spooler | X | spool.exe | Added by the BDOOR-IS BACKDOOR! | No |
| Printer Services | X | spool.exe | Added by the RBOT-Y WORM! | No |
| Printer spool Service | X | spool.exe | Added by the RBOT-ACP WORM! | No |
| spool | X | spool.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Poison.ai. The file is located in %Windir%\install | No |
| Spool Loader | X | spool.exe | Added by a variant of the RBOT WORM! | No |
| Spool lptt01 | X | spool.exe | RapidBlaster variant (in a "spool" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| Spool ml097e | X | spool.exe | RapidBlaster variant (in a "spool" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| Windows Spooler Services | X | spool.exe | Added by the AGOBOT-AMO WORM! | No |
| WindowsXp Security | X | spool.exe | Added by the RBOT-GRK WORM! | No |
| Windows Services | X | spool32.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.Gen. The file is located in %System% | No |
| Windows SpoolaPrint Service | X | spoolasrv.exe | Added by the SDBOT-AYD WORM! | No |
| dumprep | X | spoolc.exe | Detected by Kaspersky as a variant of the AGENT.CXF TROJAN! | No |
| system service | X | spoolcrv.cpl | Added by the INSPIR.11 TROJAN! | No |
| Printer Spooler | X | spooler.exe | Added by the DELF-JJ TROJAN! | No |
| rudll32 | X | spooler.exe | Added by the VB-EZJ WORM! | No |
| Windows Configuration | X | winupdate32.exe | Added by the SDBOT BACKDOOR! | No |
| Windows System Gateway | X | SPOOLER.EXE | Added by a variant of Win32/Rbot. Note the space at the end of the "Startup Item" field | No |
| Windows SpoolPrint Service | X | spoolersrv.exe | Added by the SDBOT-ZT WORM! | No |
| System Tray Services | X | spooles32.exe | Detected by Trend Micro as WORM_AGOBOT.ZH | No |
| autoload | X |