Index Introduction Database Detailed Entries Updates Concise List HJT Forums Rogues Message Board

Windows startup programs - Database search

If you're frustrated with the time it takes your Windows 7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.

See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.

Last database update :- 29th Apr, 2013
31819 items listed

You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.

Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:

A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z

NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.

Please click on the Search button

5034 results found for S

Startup Item or Name Status Command or Data Description Tested
sysguardnXsSpyware Protect 2009 rogue spyware remover - not recommended, removal instructions hereNo
Microsoft Intell ManagementXs.exeDetected by McAfee as W32/Sdbot.worm!lq and by Malwarebytes Anti-Malware as Backdoor.MessaNo
scainXs030109.Stub.exeDelfin Media Viewer adware relatedNo
WindowsDXs1.exeAdded by the MSNDIABLO.A WORM!No
syXs2.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
S24EvMon?S24EvMon.exeEvent Monitor - supports driver extensions to NIC Driver for wireless adapters. Is it required?No
S3apphkNS3apphk.exeA tool installed alongside the drivers for your S3 video output device. It is not necessary but should be allowed to run unless it is causing problemsNo
S3 Internal ChipXs3chip3.exeAdded by the AGOBOT-FW WORM!No
S3 InternalXs3chip4.exeAdded by the AGOBOT-FQ BACKDOOR!No
S3HotkeyUs3hotkey.exeHotkey system tray icon to enable switching between monitors. Found on laptops with an S3 Twister integrated graphics cardNo
S3 Chip3Xs3int.exeAdded by the AGOBOT.LM BACKDOOR!No
S3Mon?S3Mon.exeS3DuoVue multi-monitor taskbar helper by S3 Graphics. What does it do and is it required?No
S3 Internal ChipXs3serv.exeAdded by the AGOBOT-DD WORM!No
S3TRAYUS3Tray.exeS3 display configuration taskbar utility for S3 chipset based graphics cards. Can be run from Start→ Settings → Control Panel → DisplayNo
s3tray2?s3tray2.exeS3 display configuration taskbar utility for S3 chipset based graphics cards?No
S3TRAYHP?S3trayhp.exeS3 Video driver related. What does it do and is it required?No
S3TraypUS3trayp.exeS3 display configuration taskbar utility for S3 chipset based graphics cards. Can be run from Start→ Settings → Control Panel → DisplayNo
My Search Bar EqXS4BAREQ.EXEMySearch parasiteNo
S4FUS4F.exeFilterPak from S4F, Inc - internet filtering softwareNo
s4helperXs4helper.exeSearchcentrix hijackerNo
s8kxmrxc7dXs8kxmrxc7d.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%No
[random name]Xs?chost.exePurityScan adwareNo
T81Z627Xsa-200622.exeDetected by Symantec as W32.Rontokbro@mm. The file is located in %Windir%No
T81Z627Xsa-310632.exeDetected by Kaspersky as Virus.Win32.Sality.bh. The file is located in %Windir%No
T81Z627Xsa-310733.exeDetected by Kaspersky as Virus.Win32.Virut.q and by Malwarebytes Anti-Malware as Worm.AutoRun. The file is located in %Windir%No
T14Z840Xsa-532055.exeDetected by McAfee as W32/MoonLight.worm and by Malwarebytes Anti-Malware as Worm.VB.UI. The file is located in %Windir%No
Spellex AnywhereNsa.exeSpellex-Anywhere - adds spell checking functionality to almost any Window program. Create a shortcut and run manually before it's to be usedNo
StayAliveUsa.exeStayAlive from TFI Technology. "This top-notch tool intercepts crashes when they happen, keeping your programs running so you can save your work."No
ttoolXsa23sl.exeAdded by the BCKDR-QZZ TROJAN!No
SA?Sa3.exeLogitech QuickCam driver. Is it required?No
Aureal A3D Interactive AudioYsa3dsrv.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabledNo
Sa3dsrvNSa3dsrv.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabledNo
sAaAVcAvvOACSXsAaAVcAvvOACS.exeWindowsFixDisk rogue security software - not recommended, removal instructions hereNo
saapXsaap.exe180solutions adwareNo
Sabre ServerUsabserv.exePart of the Sabre computer reservations system/global distribution system (GDS) - used by airlines, railways, hotels, travel agents and other travel companies for reservations and ticketingNo
SabreserverUSABSERV.EXEPart of the Sabre computer reservations system/global distribution system (GDS) - used by airlines, railways, hotels, travel agents and other travel companies for reservations and ticketingNo
Sabre Printing StartUSabstart.exePart of the Sabre computer reservations system/global distribution system (GDS) - used by airlines, railways, hotels, travel agents and other travel companies for reservations and ticketingNo
Sabre Task Tray IconUSabstart.exePart of the Sabre computer reservations system/global distribution system (GDS) - used by airlines, railways, hotels, travel agents and other travel companies for reservations and ticketingNo
sacXsac.exe180Search adwareNo
SACCXsacc.exeDetected by Symantec as Adware.SurfAccuracy and by Malwarebytes Anti-Malware as Adware.SurfAccuracyNo
SurfAccuracyXsacc.exeDetected by Symantec as Adware.SurfAccuracy and by Malwarebytes Anti-Malware as Adware.SurfAccuracyNo
Onluna SarviceXsachost.exeAdded by the TOFGER-AA TROJAN!No
Onlune SarviceXsachost.exeAdded by the DAEMONI-J TROJAN!No
HostSrvXsachostx.exeAdded by the LOOKSKY.H WORM! Drops multiple files in %System%No
HostSrvXsachostx.exe...Added by the LOOKSKY.E WORM!No
MicroSoft ssas3s1XSADASDA.exeAdded by the RBOT.URF WORM!No
SuperAdBlockerUSAdBlock.exeSuperAdBlockerNo
NAV Auto UpdateXSadness.exeAdded by the SPYBOT-E WORM!No
Microsoft Driver SetupXsadrive32.exeDetected by Sophos as W32/Autorun-VNNo
REMOTE REGISTRY SERVICEXsafari.exeDetected by McAfee as RDN/Generic Dropper!bo and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
Windows Service BaseXsafari.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %System%No
SafeCareXSafeCare.exeSafeCare rogue security software - not recommended, removal instructions hereNo
NetScreen-RemoteUSafeCfg.exeNetScreen Remote VPN client softwareNo
SafeDrvsssXSafeDrvsss.exeDetected by Malwarebytes Anti-Malware as Spyware.Agent. The file is located in %CommonFiles%No
SafeFighterXSafeFighter.exeSafeFighter rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
Safeguard.exeXSafeguard.exeSuper Spyware Killer rogue spyware remover - not recommendedNo
SafeInstall.exeNSAFEIN~1.EXEMonitors a download and ensures an newer version of a file isn't replaced by an older oneNo
Microsoft Safe Mode ManagerXsafemode.exeAdded by the IRCBOT.HM BACKDOOR!No
SafeMyWebXsafemyweb.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%\My UserProgramsNo
SafeOFFNSafeOff.exeProvides protection that if user accidentally presses the power switch a dialog will pop up for confirmationNo
SafePcAvXSafePcAv.exeSafePcAv rogue security software - not recommended, removal instructions here. A member of the AntiAID familyNo
SafePrivacyXSafePrivacy.exeSafePrivacy rogue security software - not recommended, removal instructions hereNo
SafePrivateXSafePrivate.exeSafePrivate rogue security software - not recommended, removal instructions hereNo
SaferScanXSaferScan.exeSaferScan rogue security software - not recommendedNo
SafeSearchXsafesearch.exeSafeSearch adwareNo
UnshareXSafeShare.exeSafeShare peer-to-peer (P2P) file-sharing client often bundled with adware or spywareNo
CertificateRegistrationUSafeSignCertReg.exeSafeSign Certificate Registration Utility for Microsoft Crypto applicationsNo
SafeSpaceYSafeSpaceSysTray.exePart of SafeSpace (from Artificial Dynamics) which "protects computers from Internet malware infection without the need for signature updates or regular maintenance"No
SafeStripXSafeStrip.exeSafeStrip rogue security software - not recommended, removal instructions hereNo
SafeStripReminderXSafeStripReminder.exeSafeStrip rogue security software - not recommended, removal instructions hereNo
SafeSysXSafeSys.exeAdded by the AUTORUN.DMI WORM!No
SafeterraXSafeTerraUpdate.exeDetected by Symantec as Adware.SafeTerra and by Malwarebytes Anti-Malware as Adware.AgentNo
Safety Anti-Spyware 3XSafety Anti-Spyware 3.exeSafety Anti-Spyware rogue security software - not recommended, removal instructions hereNo
SafetyKeeperXSafetyKeeper.exeSafetyKeeper rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
SafetyPCXsafetypcup.exeSafetyPC rogue security software - not recommended, removal instructions hereNo
SafeXSafeWin.exeAdded by the FOCOSENHA TROJAN!No
Sagate Security FirewallXsagate.exeAdded by the GAOBOT.BOW WORM!No
Laptop AccessXSage.exeAdded by the SDBOT-NB WORM!No
SystemAgentUSage.exe"Microsoft Plus! System Agent automatically tunes your system, performing tasks such as disk optimization and error correction. It can also run any application at prescheduled times"No
SagemMonitorUSagemMonitor.exeMonitor for the Sagem F@st 1200 high speed ADSL routerNo
SAGENTSERVICEUSagent.exeTinySpyAgent commercial keystroke logger. Uninstall this software if you did not install it yourselfNo
SAgent2ExePathNSAgent2.exeSeiko Epson printer status agent. Disable if printer is not used oftenNo
sagntXsagnt.exeAdware web downloaderNo
PrevxHomeYSAGUI.exePrevX behaviour-based malware protectionNo
PrevxProYSAGUI.exePrevX behaviour-based malware protectionNo
SAHagentXSahagent.exeShopAtHomeSelect parasiteNo
SaitekAutoConfigureUsaicnfig.exeConfiguration for Saitek game controllersNo
saieXsaie.exe180solutions adwareNo
saihoiXsaihoi.exeAdded by the MDROP-CUT TROJAN!No
SmartAudioUSAIICpl.exeConexant SmartAudio PC audio chipset software - typically available on notebooks with built-in microphonesNo
Configuration SoftwareNSaiMfd.exeSaitek MFD File System Driver - associated with the Saitek SST (Saitek Smart Technology) configuration software for their game controllers. Create a shortcut and run manually when requiredYes
SaiMfdNSaiMfd.exeSaitek MFD File System Driver - associated with the Saitek SST (Saitek Smart Technology) configuration software for their game controllers. Create a shortcut and run manually when requiredYes
SAIMONUSaiMon.exeSaitek joystick driverNo
Write DVD-R!Usaimon.exeSaimon's WriteDVD! "gives total support for DVD-RAM drives. It provides many functions such as setting partitions on DVD-RAM disks and FixDVD! can diagnose and repair UDF formatted disks"No
sainXsain.exe180Search adwareNo
saisXsais.exe180solutions adwareNo
SaiSmartUSaiSmart.exe"Smart Button Special Sauce" - included with support software for some of the Saitek game controllers. Related to the "S", "Shift" or "Smart" button and gives gamers extra features on the buttons. Only required if you use this featureNo
SakoraXSakora.exeAdded by the GOWELES.A TROJAN!No
SalaatTimeNSalaatTime.exe"Salaat Time is a FREE multi-function Islamic application that calculates the prescribed five daily Muslim prayer times as well as Qiblah direction for anywhere in the world"No
salmXsalm.exe180Search adwareNo
smsofterXsalss.exeDetected by McAfee as RDN/Downloader.a!p and by Malwarebytes Anti-Malware as Trojan.ChinAdNo
msvcc25Xsalvage.exeAdded by a variant of W32/Sdbot.wormNo
salyXsaly*****.exeAdded by a variant of the AW.AWK TROJAN!No
Sam-sungXSam-sung.exeAdded by a variant of W32/Sdbot.wormNo
SAMcalUSAMcal.exeSamCal - calendar/reminder programNo
SamSvcDllXSamHostDll.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Trojan.MSILNo
BluetoothXsample.exeAdded by the AGENT-OSH TROJAN!No
CCGLOGXsample.exeDetected by McAfee as RDN/Generic BackDoor!p and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
chrome.exeXsample.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Temp%No
javaXsample.exeDetected by Malwarebytes Anti-Malware as Worm.Ainslot. The file is located in %Temp%No
msconfigXsample.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Temp%No
svchostXsample.exeDetected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %UserTemp%No
testing.exeXsample.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Temp%No
tmp_upXsample.exeQuickBar adwareNo
Win UpdateXsample.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserTemp%No
Windows FirewallXsample.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Temp%No
Windows Rundll32Xsample.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Temp%No
Security Accounts Manager SMXsamsm.exeAdded by the WOOTBOT.BC WORM!No
SamsongXSamsong.exeAdded by the SDBOT.BNE WORM!No
YeppStudioAgentNSamsungMediaStudioAgent.exeSamsung Media Studio MP3 player file management software - see here for an exampleNo
SamsungXSamsungs.exeAdded by a variant of the IRCBOT BACKDOOR!No
PersSamDllXSamTrayConf.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Trojan.MSILNo
FireWire DriverXsamx.exeAdded by the SDBOT.AE WORM!No
Adobe Gama LoaderXsan.exeDetected by McAfee as RDN/Generic PWS.y!l and by Malwarebytes Anti-Malware as Backdoor.MessaNo
SancMediaXSancMedia.exeDetected by Sophos as Troj/Mdrop-EYG and by Malwarebytes Anti-Malware as Trojan.Dropper.MSNo
SandIconNSandIcon.exeSanDisk ImageMate CompactFlash card reader SDDR-31 (USB). Very little use except to place the Sandisk icon beside its drive designation in Windows Explorer. The reader itself will work fine without it. The simplest thing is to just unplug the reader when you're not using it. It may slow the startup by a few nanoseconds, but once the software sees there's no reader, you get back the resourcesNo
SanDiskSecureAccess_Manager.exeUSanDiskSecureAccess_Manager.exe"SanDisk® SecureAccess™ Manager is an application installed on your computer desktop to help launch the SanDisk SecureAccess software, automatically and transparently, whenever you connect the SanDisk USB flash drive to your computer." Required if you regularly use a supported driveNo
SansaDispatchUSansaDispatch.exeSansa Updater - "The Sansa Firmware Updater is an application designed to deliver the latest firmware, software support, User Manuals right to your desktop"No
SANS ServiceXsansv.exeAdded by the VANEBOT-AH WORM!No
Santa Bastards BitchXSANTAS.BITCH.txtAdded by the ATNAS.A WORM!No
System Applications ProfileXsap.exeAdded by the RBOT-QF WORM!No
sappXsapp.exeNCase adwareNo
[various names]XSAPSTR.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
BeawverXsaqevre.exeAdded by a variant of Backdoor.Ranky. The file is located in %System%No
Microsft UpdtesXsarvice.exeAdded by a variant of W32/Sdbot.wormNo
SA Service?SAservice.exeAssociated with Cyber Trio and Warner troubleshooting software from G-Tek Technologies and pre-installed on some Packard Bell and NEC PCs. What function does this perform and is it required?No
Syntax ScriptXsaskatcw.exeAdded by the SDBOT-TE WORM!No
SaskTel Accelerated Dial-upUsasktelgui.exe"Experience faster surfing, downloading and e-mail by adding SaskTel Accelerated Dial-up Internet"No
usbXSASS.EXEAdded by the FUNSTA-A TROJAN!No
sast32Xsast32-2.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Root%No
ScanDiscXsatan.exeAdded by the GREGSTAR TROJAN!No
SATARaidUSATARaid.exeRAID driver for serial ATA disks on some motherboards such as the DFI Lanparty range. Only loaded if one is using RAID support on SATA drivesNo
satmatXsatmat.exeVX2.Transponder parasite updater/installer relatedNo
sauXsau.exe180Search adwareNo
sauobexXsauobex.exeDetected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %UserProfile%No
ATTBroadbandUpdateUSAUpdate.exeBig Brother from Quest Software. System and network monitorNo
SAUpdateUSAUpdate.exeBig Brother from Quest Software. System and network monitorNo
SAutoLaunchExeUSAutoLaunchExe.exeSharp Zaurus PDA related, needed to synchronize information with a Desktop or NotebookNo
AntivirusXsav.exeSystem Antivirus 2008 rogue security software - not recommended, removal instructions hereNo
SAVAgentYSAVAgent.exePart of Sophos anti-virus software. Required for centrally administered Sophos updates to work correctly, e.g. automatically updating PCs used by dial-in home or out-of-office usersNo
SaveXSave.exeSaveNow adwareNo
WhenUSaveXSave.exeSaveNow adwareNo
SaveArmorXSaveArmor.exeSaveArmor rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
SaveComXSaveCom.exeSaveCom rogue security software - not recommended, removal instructions hereNo
SaveDefenderXSaveDefender.exeSaveDefender rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
SaveDefenseXSaveDefense.exeSaveDefense rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
SaveKeepXSaveKeep.exeSaveKeep rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
SaveKeeperXSaveKeeper.exeSaveKeeper rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
SaveMyWorkUSaveMyWork.exeSaveMyWork keystroke logger/monitoring program - remove unless you installed it yourself!No
SavenowXSaveNow.exeSaveNow adwareNo
SaveSoldierXSaveSoldier.exeSaveSoldier rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
SaveDateXSaveStartDate.ExeUnidentified adwareNo
Microsoft Security CenterXsavservices.exeAdded by the RBOT-ANU WORM!No
SAWXsaw.exeSmartAdware adwareNo
Say The Time 5.0USAYTIME.EXEThis program has audio cues for the system clock in male and female voices, customizes the appearance of the system clock, and can synchronize it to a time server regularlyNo
Security AntivirusXSA[random].exeSecurity Antivirus rogue security software - not recommended, removal instructions hereNo
smXsa_exe.exeAdded by the OLFEB.A TROJAN!No
SBUSB.exeAcer Soft Button on Acer Tablet PCsNo
CDLoaderUsb32mon.exePart of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!No
RegUpdateUsb32mon.exePart of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!No
ScanSys32Usb32mon.exePart of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!No
SysCheck32Usb32mon.exePart of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!No
System32Usb32mon.exePart of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!No
SystemcheckUsb32mon.exePart of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!No
Trunk32Usb32mon.exePart of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!No
WinSysCheckUsb32mon.exePart of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!No
SBAMTrayYSBAMTray.exeSystem Tray access to and notifications for the VIPRE (and older CounterSpy) range of security software from GFI Software (was Sunbelt Software)No
SBAutoUpdateUsbautoupdate.exeSpywareBlaster auto-updaterNo
SBC RoamingClientUSBCFL.exePart of AT&T FreedomLink Wi-Fi connection softwareNo
SBCSTrayYSBCSTray.exeSystem Tray access to Sunbelt CounterSpy antispyware software - now discontinued with users recommended to switch to VIPRENo
SBDrvDetUSBDrv.exeDetects the "Easy Front-Panel Audio Connectivity Drive Internal Drive Bay" on the Sound Blaster Audigy 2 Platinium eX. Can be disabled if you don't have oneNo
SBDrvDetNSBDrvDet.exeChecks to see if Creative sound card driver should be updatedNo
SBHCXsbhc.exeSuperBar parasiteNo
Windows bypass security SMSS ServiceXSbiCvy.exeAdded by the RBOT-GRF WORM!No
SandboxieControlUSbieCtrl.exe"SandBoxie runs your programs in an isolated space which prevents them from making permanent changes to other programs and data in your computer"No
[various names]Xsbin.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
Spam Blocker for Outlook ExpressXSBInst.exeSpam Blocker Utility adware by the people who provide the Hotbar adwareNo
Windows System Restore ConfigurationXSblhost.exeAdded by a variant of the SPYBOT WORM!No
startXsbmntr.exeAdded by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machine. Various directories and filenames are used - see the link for details. This particular one is "NetProject"No
SBMPOPXSBMPop.exeSearchByMedia adwareNo
SBMXNsbmx.exeSoundMAX MPU401 MIDI device emulator for x86 VM DOS games/apps (for Win9x only)No
SpamBlockerXSbOEAddOn.exeSpam Blocker Utility adware by the people who provide the Hotbar adwareNo
Microsoft Service BootXsboot.exeAdded by a variant of the IRCBOT BACKDOOR!No
SBoxSearchBarOSXSBoxSearchBar.exeDetected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\ShareBox\SBoxSearchBarNo
SBoxSearchBarXSBoxSearchBarU.exeDetected by AVG as OpenShopper.A and by Malwarebytes Anti-Malware as Adware.K.ShareBox. The file is located in %ProgramFiles%\ShareBox\SBoxSearchBarNo
MSRegScanUSBPDemo.exeSpyBoss Pro surveillance software. Uninstall this software unless you put it there yourselfNo
SystemBooster2009Xsbr_updater.exeSystemBooster2009 rogue system suite - not recommended, removal instructions hereNo
SYSTEM.MANAGEMENTXsbscmp20_mscorlib.exeDetected by McAfee as RDN/Generic Dropper!d and by Malwarebytes Anti-Malware as Trojan.AgentNo
ScriptBlockingYSBServ.exePart of the "Script Blocking" feature for older versions of Symantec's Norton AntiVirus which monitors script-based (ie, JavaScript, VB Script) viruses and alerts you of virus-like malicious behavior, stopping these viruses before they can infect your system. Runs as a service on an NT based OS (such as Windows 7/Vista/XP)No
EapcisetupNsbsetup.exeRockwell RipTide soundcard application software. Sound works without itNo
sbss LauncherXsbss.exeSideBySide adwareNo
SBUSAXSBUSA.exeSpam Blocker Utility adware by the people who provide the Hotbar adwareNo
SB WatchdogXSBWatchdog.exeSpyware utility installed by the manufacturers of some laptops (Sony) used to monitor browsing habits and send them back to whoever installed it - released by SoftBankNo
WeatherOnTrayXSbWeatherOnTray.exeSpam Blocker Utility adware by the people who provide the Hotbar adwareNo
6-susilo bXsby.exeAdded by the BRONTOK-CR WORM!No
scUsc.exeWatchdog 2.0 Software - monitoring programNo
sc23exec?sc23exec.exePossibly related to a digital cameraNo
SC3300CCYSC3300CC.exeSiPix digital camera Twain device driverNo
USB Electronic ScaleUScaleRelated to a USB Electronic Scale - manufacturer currently unknownNo
WINDOWS SYSTEM SCALPEXscalpe91.exeAdded by the MYTOB-HI WORM!No
Driver32XScam32.exeDetected by Symantec as W32.Sircam.Worm@mmNo
Scan&Repair2006.exeXScan&Repair2006.exeScan&Repair Utilities 2006 rogue system utility - not recommendedNo
antispyXscan.exeIE AntiVirus rogue security software - not recommended, removal instructions hereNo
TotalSecure2009Xscan.exeTotal Secure 2009 rogue security software - not recommended, removal instructions hereNo
Scan119XScan119.exeScan119 rogue security software - not recommended, removal instructions hereNo
1455 Scan2PCUScan2pc.exeScan to PC application for the scanning function of the Samsung SCX1455 multifunction printerNo
2335dn Scan2PCUScan2pc.exeScan to PC application for the scanning function of the Dell 2335 multifunction laser printerNo
3170 Scan2PCUScan2pc.exeScan to PC application for the scanning function of the Samsung CLX3170 multifunction laser printerNo
4x26 Scan2PCUScan2pc.exeScan to PC application for the scanning function of the Samsung SCX4x26 multifunction laser printersNo
4x28 Scan2PCUScan2pc.exeScan to PC application for the scanning function of the Samsung SCX4x28 multifunction laser printersNo
6200 Scan2PCUScan2pc.exeScan to PC application for the scanning function of the Samsung CLX6200 multifunction laser printerNo
ELBERT_S2PUScan2pc.exeScan to PC application for the scanning function of the Samsung SCX-5x30 Series multifunction printersNo
ELBERTRicoh_S2PUScan2pc.exeScan to PC application for the scanning function of the Ricoh MFP Type 104 multifunction printerNo
IRIS_S2PUScan2pc.exeScan to PC application for the scanning function of the Samsung CLX-3160 Series multifunction laser printerNo
IRIS_XRX_S2PUScan2pc.exeScan to PC application for the scanning function of the Xerox Phaser 6110MFP multifunction laser printerNo
Logan_S2PUScan2pc.exeScan to PC application for the scanning function of the Samsung SCX-4500 Series multifunction printerNo
Maple_S2PUScan2pc.exeScan to PC application for the scanning function of the Samsung CLX-216x Series multifunction printersNo
MFP1815_S2PUScan2pc.exeScan to PC application for the scanning function of the Dell Laser MFP 1815 multifunction printerNo
R2Plus_S2PUScan2pc.exeScan to PC application for the scanning function of the Samsung SCX-4x20 Series multifunction printersNo
R2Ricoh_S2PUScan2pc.exeScan to PC application for the scanning function of the Ricoh MFP Type 103 multifunction printerNo
Scan2pcUScan2pc.exeScan to PC application for the scanning function of multiple multifunction printers from Dell, Samsung, Xerox, Ricoh and othersNo
WHITNEY_S2PUScan2pc.exeScan to PC application for the scanning function of the Samsung SCX-4x21 Series multifunction printersNo
Whitney2_S2PUScan2pc.exeScan to PC application for the scanning function of the Samsung SCX-4725 Series photocopierNo
WHITNEY2_XRX_S2PUScan2pc.exeScan to PC application for the scanning function of the Xerox Phaser 3200MFP multifunction laser printerNo
WhitneyXerox_S2PUScan2pc.exeScan to PC application for the scanning function of the Xerox WorkCentre PE220 Series multifunction laser printerNo
Win32GXScandisk.comAdded by the ESTRELLA TROJAN!No
ScanDiskXScanDisk.exeAdded by the GANDA.A WORM! Note - this is not the valid "ScanDisk" Win9x/Me standard disk error checkerNo
scands32.exeXscands32.exeAdded by a variant of the ADCLICKER TROJAN!No
Scandsk2Xscandsk2.exeAdded by the AGOBOT-PK WORM!No
scandskx.exeXscandskx.exeDetected by Sophos as Troj/Dloadr-ARMNo
MessengerUSCANMSG.EXEPart of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. Enables the "Quick Heal messenger service which provides important information about latest threats, updates and other information related to Quick Heal." Also included by vendors who use the Quick Heal engine such as Omniquad and iQonYes
Quick Heal AntiVirusUSCANMSG.EXEPart of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. Enables the "Quick Heal messenger service which provides important information about latest threats, updates and other information related to Quick Heal." Also included by vendors who use the Quick Heal engine such as Omniquad and iQonYes
SCANMSGUSCANMSG.EXEPart of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. Enables the "Quick Heal messenger service which provides important information about latest threats, updates and other information related to Quick Heal." Also included by vendors who use the Quick Heal engine such as Omniquad and iQonYes
ScanSpywareXScanner.exeScanSpyware rogue security software - not recommended, removal instructions here. Also see hereNo
ScanSpyware v3.2XScanner.exeScanSpyware rogue security software - not recommended, removal instructions here. Also see hereNo
ScanSpyware v3.5XScanner.exeScanSpyware rogue security software - not recommended, removal instructions here. Also see hereNo
hpScannerFirstBoot?scannerfb.exeHP scanner relatedNo
Microtek Scanner FinderUScannerFinder.exeMonitors whether a scanner is present. Provided with Microtek scannersNo
ScanPanel?ScanPanel.exeTrust Easy Webscan scanner related - what does it do and is it required?No
Reg_WFTXscanreg32.comAdded by the SENNASPY-F TROJAN!No
ScanRegistryXscanregv.exeAdded by the MASTERLOCK TROJAN!. Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as scanregv.exe not scanregw.exeNo
[random name]Xscanregw.exePurityScan adware. Note - do not confuse this with the legitimate scanregw.exe which is always found in %Windir% on Win9x/ME machinesNo
ScanRegistryXscanregw.exeDetected by Sophos as W32/Nyxem-D. Note - do not confuse this with the legitimate Windows process scanregw.exe which is always found in the Windows folder on Win9x/ME machines. This worm file is found in %System%No
ScanRegistryXScanregw.exeDetected by Symantec as W32.Stator@mm. Note - do not confuse this with the legitimate scanregw.exe which is always found in %Windir% on Win9x/ME machines. This one is located in %System%No
ScanRegistryYScanregw.exeScans the WinMe/98 system registry and makes back-ups at start-up - important should the registry become corrupt. Located in %Windir%No
Microsoft Disk ScannerXscansdisk.exeAdded by the WOOTBOT.DT WORM!No
[various names]XscanSYS.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
P3000x_S2PUScanToPc.exeDell Laser MFP 1600N network application for scanning files to the PCNo
Windows ServiceXScanvegw.exeAdded by the DELF BACKDOOR!No
scAppXscApp.exeAdded by the STANDO-E WORM!No
TwkSCardSrvNSCardS32.ExeUsed with Towitoko SmartCard Readers for card recognitionNo
SCardSvrNscardsvr.exeRelated to SmartCard readers and sometimes uses lots of system resourcesNo
Smart Card ServiceNScardSvr.exeFor Smart Card readers. Known to cause problems, especially for Windows 2000 users - see here. Probably not required unless you use such a device regularlyNo
NavAgent32XSCardSvr32.ExeDetected by Trend Micro as WORM_MOFEI.BNo
SCardSvrXSCardSvr32.ExeDetected by Trend Micro as WORM_MOFEI.BNo
SearchEnhancementXscbar.exeSCBar/SearchEnhancement foistwareNo
Compaq Computer Corp SCCenter ModuleNSCCENTER.EXEFor Compaq PC's. Part of BackwebNo
Service ConnectionNsccenter.exeFor Compaq PC's. Part of BackwebNo
Alive SYstemXscchost.exeAdded by the TOFDROP-B TROJAN!No
Key NameXscchost.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%\windowexplorerNo
Services HostXScchost.exeAdded by the DONK WORM!No
SystemsXscchost.exeAdded by the DAEMOZ.A TROJAN!No
Alive SYstemXscchostc.exeAdded by the TOFDROP-B TROJAN!No
Microsoft Windows UpdateXsccvhost.exeAdded by a variant of W32/Sdbot.wormNo
SCDEmuApp.exeUSCDEmuApp.exeRelated to PowerISO - CD/DVD image file processing toolNo
Configuration DriverXscghost.exeAdded by the SDBOT-DLA WORM!No
MS Windows UpdateXscguard.exeAdded by the RBOT-YZ WORM!No
Backup NOW! SchedulerUSchdlr32.exeScheduled backups for the NTI Backup Now archiving utility. If a backup job has been scheduled, this entry places an icon in the System Tray and will automatically load the main program and execute the backup at the set time - as long as the backup media is presentYes
NTI Backup NOW! SchedulerUSchdlr32.exeScheduled backups for the NTI Backup Now archiving utility. If a backup job has been scheduled, this entry places an icon in the System Tray and will automatically load the main program and execute the backup at the set time - as long as the backup media is presentYes
Schdlr32USchdlr32.exeScheduled backups for the NTI Backup Now archiving utility. If a backup job has been scheduled, this entry places an icon in the System Tray and will automatically load the main program and execute the backup at the set time - as long as the backup media is presentYes
Windows ServicesXscheb.exeDetected by Sophos as Troj/Agent-QVV and by Malwarebytes Anti-Malware as Backdoor.Agent.GenNo
Windows UpdateXscheb.exeDetected by Sophos as Troj/Agent-QVV and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
Windows Update SystemXscheb.exeDetected by Microsoft as Backdoor:Win32/IRCbot.FJ and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
scheck45Xscheck45.exeRelated to unknown malware - hidden installer associated with itNo
Acronis Scheduler HelperUschedhlp.exeScheduler for Acronis True Image backup software. From Acronis (courtesy of AnswersThatWork: "The program monitors the logons and logoffs on your PC and notifies the Acronis Scheduling system about them. It is started when a user logs into the system and terminates when the user logs off. Acronis True Image uses this program to schedule tasks on user logon/logoff and to run non-scheduled "Image creation" operation". Not required if you do not have scheduled jobs. Also included in Seagate's DiscWizard and BlackArmor Backup implementations of True ImageNo
Acronis Scheduler2 ServiceUschedhlp.exeScheduler for Acronis True Image backup software. From Acronis (courtesy of AnswersThatWork: "The program monitors the logons and logoffs on your PC and notifies the Acronis Scheduling system about them. It is started when a user logs into the system and terminates when the user logs off. Acronis True Image uses this program to schedule tasks on user logon/logoff and to run non-scheduled "Image creation" operation". Not required if you do not have scheduled jobsNo
schedhlpUschedhlp.exeScheduler for Acronis True Image backup software. From Acronis (courtesy of AnswersThatWork: "The program monitors the logons and logoffs on your PC and notifies the Acronis Scheduling system about them. It is started when a user logs into the system and terminates when the user logs off. Acronis True Image uses this program to schedule tasks on user logon/logoff and to run non-scheduled "Image creation" operation". Not required if you do not have scheduled jobs. Also included in Seagate's DiscWizard and BlackArmor Backup implementations of True ImageNo
Seagate Scheduler2 ServiceUschedhlp.exeScheduler for Seagate's DiscWizard and BlackArmor Backup - their implementation of the Acronis True Image backup software. From Acronis (courtesy of AnswersThatWork: "The program monitors the logons and logoffs on your PC and notifies the Acronis Scheduling system about them. It is started when a user logs into the system and terminates when the user logs off. Acronis True Image uses this program to schedule tasks on user logon/logoff and to run non-scheduled "Image creation" operation". Not required if you do not have scheduled jobsNo
WTIndicatorUSchedInd.exeWinTask - software that automates a variety of routine tasks quickly and simplyNo
schedlXschedl.exeAdded by the VB-DVW WORM!No
schedmUschedm.exePart of Antivir PersonalEdition Classic anti-virusNo
Task Scheduler EngineXschedsvc32.exeAdded by the RBOT-ASJ WORM!No
ScheduleUSchedule.exeScheduler for Mercury Ez View TV Tuner CardNo
TvrScheduleUSchedule.exeScheduler for Mercury Ez View TV Tuner CardNo
Center AgentUScheduled.exeScheduler for HyperMedia Center from Kworld - "an integrated multimedia application that allows you to enjoy all of your digital entertainment - TV, home videos and photos. HyperMedia Center is especially designed for turning your PC/Laptop into an entertainment solution"No
Scheduled MaintenanceNScheduled_Maintenance.exeScheduler for Iolo System Mechanic tweaking utility. It can cleans your registry and deletes temporary files at defined intervals. Available via Start → ProgramsNo
SchedulerUScheduler daemon.exeTenebril GhostSurf or SpyCatcher related scheduler - you can schedule daily, weekly, monthly or one-time only cleaningsNo
DSSchedulerUScheduler.exeScheduler for Dynamic Submission by Apex Pacific - "Web site Promotion and Internet Marketing Software that allows you to perform automated search engine submission, Web site submission, and search engine optimization (SEO)"No
MRU-Blaster SchedulerUscheduler.exeScheduler for MRU-Blaster from Brightfort (formerly Javacool Software) - which "is a program made to do one large task - detect and clean MRU (most recently used) lists on your computer"No
Scheduling AgentXScheduler.exeDetected by Symantec as Backdoor.SubwooferNo
Service SchedulerXscheduler.exeAdded by the AGOBOT-PH WORM!No
Staffcop SchedulerUscheduler.exeStaffCop surveillance software. Uninstall this software unless you put it there yourselfNo
Windows Scheduler!Xscheduler.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
XemiComputers SchedulerUScheduler.exeSmooth Program Scheduler from XemiComputers "will start any program you want at a scheduled time"No
scheduler_proxy ApplicationUscheduler_proxy.exeFound on IBM/Lenovo ThinkCentre/ThinkStation desktops and Thinkpad notebooks. Included with versions of ThinkVantage System Update (for software updates), Rescue and Recovery (backup and system recovery), Message Center Plus and maybe others. It's exact function isn't known but if disabled, the "plan updates" button in the IBM System Update software will no longer be available, though the software will continue run properlyYes
TVT Scheduler ProxyUscheduler_proxy.exeFound on IBM/Lenovo ThinkCentre/ThinkStation desktops and Thinkpad notebooks. Included with versions of ThinkVantage System Update (for software updates), Rescue and Recovery (backup and system recovery), Message Center Plus and maybe others. It's exact function isn't known but if disabled, the "plan updates" button in the IBM System Update software will no longer be available, though the software will continue run properlyYes
AdwareKiller_schedulesXschedules.exeEAdwareKiller rogue spyware remover - not recommendedNo
Laplink PDASync 3.1 - ScheduleSyncUScheduleSync.exeLaplink PDASync for ScheduleSync - PDA synchronisation utilityNo
GroupWise PDA Connect - ScheduleSyncUSCHEDU~1.EXEScheduleSync specific translator for the GroupWise PDA Connect PDA synchronisation utility from NovellNo
XTNDConnect PC - ScheduleSyncUSCHEDU~1.EXEScheduleSync specific translator for XTNDConnect PC - "award-winning desktop-sync application that enables you to easily synchronize your contacts, calendar, tasks, email and notes between your mobile devices and popular PC applications"No
JavaUpdateSchedsXschedzs.exeDetected by Malwarebytes Anti-Malware as Backdoor.Xtrat. The file is located in %Windir%No
SCHelper.exeNSCHelper.exeSpyware Cease spyware remover. Previous versions were regarded as a rogue (see here) because it reported false or exaggerated system security threats but the latest version tested (6.5.1) has a new interface and produces no exaggerated threats on a clean system. Not recommended due to the past historyYes
NovastorSchedulerdUSCHENGD.EXENovaStor NovaBACKUP Scheduler - back-up utility. If you don't have regularly scheduled back-ups you don't need itNo
SchmailiUSchmaili.exeSchmaili - insert animated smilies into your e-mailNo
a2abfc2cbc7857ee33ac527ade190621XSchost.exeDetected by Malwarebytes Anti-Malware as Trojan.Dropper. The file is located in %Temp%No
Generic Host ProcessXSCHOST.EXEAdded by the RBOT-NC WORM!No
IntranetXschost.exeAdded by the RBOT.SV BACKDOOR!No
MicrosoftXschost.exeAdded by the RBOT.FEH BACKDOOR!No
Microsoft Manage ServicesXschost.exeDetected by PCTools as Worm.Slenfbot.BNo
Update InstallXSchost.exeDetected by Symantec as W32.HLLW.Gaobot.AONo
Windows Service HostXschost.exeAdded by a variant of W32.HLLW.Gaobot.gen. The file is located in %Windir%No
WinManager?schost.exe??No
AVSchedScanYSCHSC9X.EXEScheduler for Command AntiVirus for 9x/Me by Command Software Systems, Inc (who became Authentium and are now Commtouch)No
Home Theater SchSvrUSchSvr.exeScheduler installed with the Home Theater Remote Control for older versions of the WinDVD software DVD player from Intervideo (now Corel). Required if you want to schedule recordings from your TV tuner cardNo
Intervideo WinSchedulerUSchSvr.exeScheduler installed with the WinDVD Remote Control for older versions of the WinDVD software DVD player from Intervideo (now Corel). Required if you want to schedule recordings from your TV tuner cardNo
SchSvrUSchSvr.exeScheduler installed with the Home Theater Remote Control or WinDVD Remote Control for older versions of the WinDVD software DVD player from Intervideo (now Corel). Required if you want to schedule recordings from your TV tuner cardNo
WinDVR SchSvrUSchSvr.exeScheduler installed with the WinDVD Remote Control for older versions of the WinDVD software DVD player from Intervideo (now Corel). Required if you want to schedule recordings from your TV tuner cardNo
Microsoft Update 64 BITXschvost.exeAdded by the RBOT.CAU WORM!No
schvostXschvost.exeDetected by McAfee as RDN/Generic.bfr!d and by Malwarebytes Anti-Malware as Trojan.VBKryptNo
CSScheduleCheckYSCHWIZEX.EXEPart of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-bootNo
SCHWIZEXYSCHWIZEX.EXEPart of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-bootNo
SecureCleanIECleanNSCIEClean.exeSecureClean - scans your system for hidden temporary files, deleted email messages, Internet histories and cachesNo
someXscit.exeAdded by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machine. Various directories and filenames are used - see the link for details. This particular one is "NetProject"No
SybaseCentral43Uscjview.exeRelated to SQL Anywhere from Sybase. A comprehensive package providing data management and data exchange technologiesNo
ServicesXscks32.exeAdded by a variant of Trojan-Proxy. The file is located in %Root%No
sclauncherNsclauncher.exeSimpleCenter digital media player/manager that supports the iPod, Sony PSP, Xbox 360, some of the Nokia N-series mobile phones and othersNo
sclickXsclick.exeAdded by the FAKEALERT TROJAN!No
Service Control ManagerXscm.exeAdded by the AGOBOT-GD BACKDOOR!No
SOS SQL DatabaseNscm.exeSQL Server Service Control Manager - part of Microsoft SQL Server. Available via Start → ProgramsNo
SQL ServerNscm.exeSQL Server Service Control Manager - part of Microsoft SQL Server. Available via Start → ProgramsNo
Stardust Screen Saver Control 2003USCMain.exeScreen Saver Control 2003 from Stardust Software - "is a standalone version of our popular screen saver add-on. It allows you to control and configure all your screen savers directly from the system tray"Yes
ScManagerXscman.exeAdded by the FORBOT-CW WORM!No
SurfChoiceUSCMan.exeSCMan is a utility that can control services on WinNT from the command line. This utility can create, start, pause, stop, delete services. Furthermore it can retrieve a service's current state, get the displayname for a service and vice versaNo
CHIPDRIVESmartcardManagerUSCMgr.exeChipDrive Smartcard softwareNo
Spore.bXScmhlpr.vbsAdded by the SORPE.B WORM!No
Smart Connect MonitorUSCMon.exeAppears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote VaioNo
Windows ServicesXscmsg.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.Gen. The file is located in %System%No
Security PatchXscmss.exeDetected by Sophos as W32/Rbot-ZWNo
ScopedllXscopedll.exeAdded by the GEMA TROJAN!No
MCX UpdteXscorti.exeAdded by the RBOT-ARP WORM!No
Mi7sft sdceXscorti.exeAdded by the RBOT.ELC BACKDOOR!No
StartupCop ProUscp.exeStartup Cop Pro startup program manager from PC MagazineNo
dorkXTrojan.BankerDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %Root%No
SC2Xscprot4.exeAdded by the AGENT.APP TROJAN!No
ScrXscr.scrAdded by the OPASERV.T WORM!No
W32.ScranXScran.exeAdded by the NARCS WORM!No
ScrapPadNScrappad.exeScrapPad allows you to quickly and easily record notes, thoughts, messages, and just about anything you want. Use it like you use scrap paperNo
Micro CRC ProtocolXscrc32.exeAdded by a variant of W32/Sdbot.worm. The file is located in %System%No
Screen CalendarUscrcal.exeScreen Calendar allows you to create custom desktop wallpapers with built in active calendar and schedulerNo
WMI Standard Event Consumer - ScriptingXscrcons32.exeAdded by the RBOT-GRD WORM!No
WMI Standard Event Consumer - hostingXscrcs.exeAdded by the IRCBOT.ATP WORM!No
Microsoft Synchronization ManagerXscreen.exeAdded by the SDBOT-ACO WORM!No
cursorNScreendragon_VS_Taskbar.exeScreenDragon video playerNo
ScreenHunter 4.0 FreeNScreenHunter.exeScreenHunter by Wisdom Software Inc - "award-winning screen capture solution to capture your screen, print and edit." Free versionNo
Wisdom-soft ScreenHunter 5.1 FreeNScreenHunter.exeScreenHunter by Wisdom Software Inc - "award-winning screen capture solution to capture your screen, print and edit." Free versionNo
Wisdom-soft ScreenHunter 5.1 ProNScreenHunter.exeScreenHunter by Wisdom Software Inc - "award-winning screen capture solution to capture your screen, print and edit." Pro versionNo
ScreenPrint32NScreenPrint32.exeScreenPrint32 screen capture software - can be launched manuallyNo
screenSHUUscreenSHU.exeScreenSHU screen capture utility - required if you want to use the save to cloud featureNo
ScreenViewXScreenView.exeScreenView spywareNo
SecureClean4RegManagerNscregmanager4.exeWhiteCanyon SecureClean 4 disk cleaner - clean hard drive data, MRUs, temp files and more. Can be started manuallyNo
Microsoft RestoreXscrgrd.exeDetected by Trend Micro as WORM_SPYBOT.BRNo
scrhosh.exe1Xscrhosh.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%No
Microsoft Windows UpdateXscrhost.exeAdded by the RBOT-AOW WORM!No
WindowSystemMonitorXscrhost.exeAdded by the TILEBOT-DV WORM!No
Auto File System Conversion UtilityXscricon.exeAdded by the SDBOT.EYB WORM!No
RAX SYSTEMXscrigz.exeDetected by Trend Micro as WORM_MYTOB.KRNo
Windows UpdateXscrigz.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %System%No
script?script.batMaybe associated with DOS on a Win9x machineNo
mozilaXScript.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\mozillaNo
mozillaXScript.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\mozillaNo
ScriptSentryYScriptsentry.exeScript Sentry from Jason's Toolbox. Blocks malicious scripts and allows safe scripts to run. Only required if you want it to check the file associations it guards at startup. It will function regardless. No longer availableNo
VelocidadSimpleXscrmain.exeVelocidadSimple rogue optimization utility - not recommendedNo
CrnsavaXscrnsave.pifAdded by the SDBOT-ZV WORM!No
Screen SaverXscrnsaver.scrAdded by the RBOT-AGP WORM!No
CrnsavsundXscrnsund.pifAdded by the SDBOT-AJQ WORM!No
Scroll-In-Mouse V2.0USCROLL.EXEToolkit for the Lynx-3D Net scroll mouse from QTronix. Required if you use the special featuresNo
MS Screen SaverXscrsave.scrAdded by the RBOT-AGT WORM!No
scrssXscrss.exeAdded by the HACDEF-R TROJAN!No
scrsvcXscrsvc.exeAdded by the AGENT-DS TROJAN!No
ScrSvrXScrSvr.exeAdded by the OPASERV WORM!No
ScrSvrOldXScrSvr.exeAdded by the OPASERV WORM!No
System CSRSS PatchXscrtkfg.exeAdded by the RBOT-ADA WORM!No
SystemOPsvXscrtvc32.exeAdded by a variant of the SPYBOT WORM!No
scNscrubxp.exeScrubXP - utility that deletes safe to remove files, cookies, browsing history, etcNo
screxe?scruser2k.exe??No
scsaXscsa.exeDetected by Dr.Web as Trojan.Inject1.153 and by Malwarebytes Anti-Malware as Worm.IMP.Trace. Note - this entry loads from the Windows Startup folder and the file is located in %AppData%\Win88E6680FNo
scsaXscsa.exeDetected by McAfee as Generic Downloader.x and by Malwarebytes Anti-Malware as Worm.IMP.Trace. Note - this entry loads from the Windows Startup folder and the file is located in %AppData%\Win74630177No
Smart Connect SetupUSCSetup.exeAppears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote VaioNo
ScsiYScsi.exeSCSI Miniport driverNo
Windows SpaceXscsrs.exeDetected by McAfee as RDN/Generic Dropper!d and by Malwarebytes Anti-Malware as Backdoor.AgentNo
WinlogonXscssrr.exeDetected by Sophos as Troj/Agent-LXB and by Malwarebytes Anti-Malware as Worm.AutorunNo
SecondChanceUsctray.exePower Quest Second Chance. Sets checkpoints for saving a backup copy of the registry to a disk so you can restore it if you have a crashNo
SecureClean4TrayNsctray4.exeWhiteCanyon SecureClean 4 disk cleaner - clean hard drive data, MRUs, temp files and more. Can be started manuallyNo
LogoffYSCTUINotify.exePart of Windows SteadyState, which is designed to make life easier for people who set up and maintain shared computers - enabling the system administrator to prevent users from making changes to the system configuration, windows desktop, restricting program access, etc. It's intended for shared user environments such as internet cafés, libraries and schools but can be used in any environment. This entry displays the timeout messages on the restricted computer/account - which warns users how long they have until automatic log-off when they log-in and when there are only 2 minutes leftYes
SCTUINotifyYSCTUINotify.exePart of Windows SteadyState, which is designed to make life easier for people who set up and maintain shared computers - enabling the system administrator to prevent users from making changes to the system configuration, windows desktop, restricting program access, etc. It's intended for shared user environments such as internet cafés, libraries and schools but can be used in any environment. This entry displays the timeout messages on the restricted computer/account - which warns users how long they have until automatic log-off when they log-in and when there are only 2 minutes leftYes
Windows SteadyState - Session Timer Notify (UI)YSCTUINotify.exePart of Windows SteadyState, which is designed to make life easier for people who set up and maintain shared computers - enabling the system administrator to prevent users from making changes to the system configuration, windows desktop, restricting program access, etc. It's intended for shared user environments such as internet cafés, libraries and schools but can be used in any environment. This entry displays the timeout messages on the restricted computer/account - which warns users how long they have until automatic log-off when they log-in and when there are only 2 minutes leftYes
OmniPassUscureapp.exeOmniPass from Softex Inc. - secure password management softwareNo
ttoolXscvc.exeAdded by the BCKDR-OWM BACKDOOR!No
Nortons AV SYSTEMXscvchost.exeDetected by Trend Micro as WORM_RBOT.AMKNo
Configuration LoaderXscvh0st.exeAdded by the AGOBOT-AX WORM!No
Windows FrameworkXscvh0st.exeMalware installed by different rogue security software including SpyKillerPro and the XP AntiVirus seriesNo
(Default)Xscvhost.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.Gen. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %System%No
AntiVirXscvhost.exeAdded by the AGENT-DSF TROJAN!No
Config LoaderXscvhost.exeDetected by Symantec as W32.HLLW.Gaobot.AE or W32.HLLW.Gaobot.AONo
Configuration LoaderXscvhost.exeAdded by the AGOBOT-AAE and SDBOT.AR WORMS!No
Generic Host ProcessXscvhost.exeDetected by Kaspersky as Backdoor.Win32.Ciadoor.13.hx and by Malwarebytes Anti-Malware as Malware.Packer.T. The file is located in %System%No
HKCUXScvhost.exeDetected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Backdoor.HMCPol.GenNo
HKLMXScvhost.exeDetected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Backdoor.HMCPol.GenNo
icq liteXscvhost.exeAdded by the AGENT-DSF TROJAN!No
Internet Explorer HelperXscvhost.exeDetected by Trend Micro as TSPY_BANKER.BYK and by Malwarebytes Anti-Malware as Trojan.BankerNo
loadXScvhost.exeAdded by the AUTORUN-AJ WORM!No
Macromedia Flash UpdateXscvhost.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
Microsoft machineXscvhost.exeAdded by the RBOT.AEU TROJAN!No
microsoft scvhost for windowsXscvhost.exeAdded by the RANDEX-S WORM!No
Microsoft Task ManagerXscvhost.exeAdded by the MYTOB-IT WORM!No
Microsoft TCP ServiceXscvhost.exeAdded by the AGOBOT-L WORM!No
Microsoft UpdateXscvhost.exeAdded by the RBOT-AEM WORM!No
Microsoft Update MachineXscvhost.exeAdded by the RBOT-GS WORM!No
Microsoft Update ManagerXscvhost.exeDetected by Trend Micro as WORM_AGOBOT.AXJNo
Microsoft Windows UpdataXscvhost.exeAdded by the RBOT.CEM BACKDOOR!No
msconfigXscvhost.exeAdded by the AGENT-DSF TROJAN!No
MSNXscvhost.exeAdded by the IRCBOT-ZW WORM!No
MSStartOptimizerXSCVHOST.EXEDetected by Sophos as Troj/Dasmin-FamNo
MsWinLibraryXscvhost.exeAdded by the BANKER-CLI TROJAN!No
NTSF MICROSOFT SYSTEMXscvhost.exeDetected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %System%No
only23XSCVHOST.exeAdded by the BCKDR-PUQ BACKDOOR!No
Personal ComputerXscvhost.exeAdded by the RBOT-AJE WORM!No
PoliciesXScvhost.exeDetected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Backdoor.Agent.PgenNo
RAS Connection ServerXscvhost.exeAdded by the SDBOT.TOO BACKDOOR!No
regsrvXscvhost.exeDetected by Trend Micro as BKDR_AGOBOT.ENo
scvhostUscvhost.exeWiretap surveillance software - the file is located in %ProgramFiles%\Wiretap Professional. Uninstall this software unless you put it there yourselfNo
scvhostXscvhost.exeDetected by Kaspersky as Trojan.Win32.Mepaow.nfa and by Malwarebytes Anti-Malware as Backdoor.Delf. The file is located in %Windir%No
scvhostXscvhost.exeDetected by Sophos as W32/Agobot-LI. The file is located in %System%No
scvhost.exeXscvhost.exeAdded by the LOHAV-N BACKDOOR!No
Scvhost.exeXScvhost.exeDetected by Malwarebytes Anti-Malware as Trojan.Keylogger.KG. The file is located in %System%\ScvhostNo
Security CenterXscvhost.exeAdded by the RBOT-TG WORM!No
startkeyXscvhost.exeAdded by the BIFROSE-PM TROJAN!No
SunJavaUpdateSchedXscvhost.exeAdded by the SDBOT-AVX WORM!No
SVCHOSTXscvhost.exeAdded by the MYTOB.E or MYTOB.G WORMS!No
svchost.exeXscvhost.exeDetected by McAfee as Generic.dx!bh3g and by Malwarebytes Anti-Malware as Backdoor.BotNo
SvchostsXSCVHOST.EXEAdded by the AGOBOT-RQ BACKDOOR!No
System HostXscvhost.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
SystemWindowsXscvhost.exeAdded by the SILLYFDC-CG WORM!No
Update CheckerXscvhost.exeAdded by the AGENT-DSF TROJAN!No
Windows FirewalllXscvhost.exeAdded by the RBOT-EK WORM!No
Windows Service HostXscvhost.exeAdded by the SDBOT.N TROJAN!No
Windows SQL management 1.33Xscvhost.exeAdded by the SPYBOT-OB WORM!No
Windows UDP Control CenterXscvhost.exeAdded by the PUSHBOT.EH WORM!No
Windows UpdateXscvhost.exeDetected by Sophos as W32/Sdbot-XT and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
Winmgr.exeXscvhost.exeDetected by Trend Micro as WORM_AGOBOT.AFGNo
Winsock DriverXscvhost.exeAdded by the RBOT.AEU BACKDOOR!No
WINTASKXscvhost.exeAdded by the MYTOB-I WORM!No
Yahoo MessenggerXSCVHOST.exeAdded by the SOHANA-V WORM!No
Generic Host Process2 System BackupXscvhost2.exeAdded by the RBOT-BAH WORM!No
Microsoft LSASS386 ProtocolXscvhost32.exeAdded by a variant of the SPYBOT WORM!No
Microsoft SCVHOST32 ProtocolXscvhost32.exeDetected by Trend Micro as WORM_RBOT.ADPNo
SVCHost Protocol32Xscvhost32.exeAdded by a variant of the IRCBOT BACKDOOR!No
Generic Host Process326a System BackupXscvhost326a.exeAdded by a variant of W32/Sdbot.wormNo
Windows ServicesXscvhoste.exeDetected by Symantec as W32.Spybot.OBZ and by Malwarebytes Anti-Malware as Backdoor.Agent.GenNo
StarterXscvhosting.exeAdded by the SDBOT.RU WORM!No
starterXscvhostingg.exeAdded by the FORBOT-FB WORM!No
AntiVirXscvhosts.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.SVCGen. The file is located in %Windir%No
ICQ LiteXscvhosts.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.SVCGen. The file is located in %Windir%No
Internet Explorer HelperXscvhosts.exeAdded by a variant of TSPY_BANKER.BYK and detected by Malwarebytes Anti-Malware as Trojan.BankerNo
MsconfigXscvhosts.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.SVCGen. The file is located in %Windir%No
spoolsvXscvhosts.exeAdded by the SMALL-AW TROJAN!No
Update CheckerXscvhosts.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.SVCGen. The file is located in %Windir%No
Windows Host ServiceXscvhosts.exeAdded by the SPYBOT.NLI WORM!No
Windows Print Spooler?SCVHOSTS.EXESuspicious due to the similarity to the valid "svchost.exe" fileNo
Windows UpdateXscvhosts.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.SVCGen. The file is located in %Windir%No
Yahoo MessenggerXscvhosts.exeAdded by the SOHANNA-AH WORM!No
2941976dbb3ddf392f5f388f8fd2e055Xscvhot.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.SVRNo
QQKAVXscvhsot.exeDetected by Sophos as W32/QQRob-ABXNo
Yahoo MessenggerXSCVHSOT.exeAdded by the HAKAG-A WORM!No
Microsoft Office StudioXscvhvst.exeAdded by the RANDEX.CST WORM!No
Microsoft Update ManagerXscvideo.exeAdded by the SDBOT-CVP WORM!No
SYS1Xscvost.comAdded by the AUTOIT-JY WORM!No
Yahoo MessenggerXscvshosts.exeAdded by the TRAX-A WORM!No
SCVSHTOXSCVSHTO.exeDetected by Trend Micro as TROJ_VB.FPW and by Malwarebytes Anti-Malware as Email.Worm.NTONo
Scvsrv32Xscvsrv32.exeAdded by the AGOBOT-PM BACKDOOR!No
VprocessXscvtw32.exeAdded by the AGOBOT-FR BACKDOOR!No
Microsoft Windows UpdateXscvvhost.exeDetected by Sophos as W32/Forbot-DHNo
Winsock2 wqr1sXSCVVHOST.EXEDetected by Sophos as W32/Rbot-FSNNo
Yahoo MessenggerXSCVVHSOT.exeAdded by the SILLYFDC-AE WORM!No
ScxaxsXScxaxs.exeAdded by the RUSKILL.CX BACKDOOR!No
Adobe Acrobat Speed LauncherNSC_Acrobat.exeSpeeds up the time it takes to load older versions of the Adobe Acrobat PDF creation/editing utility. Loads "acrobat_sl.exe" which quickly opens and closes all of the files that Acrobat will use when the application starts - allowing virus protection software to check these programs and add them to the list of safe files. Not required for Acrobat to function properlyYes
MonitorUSD Monitor.exe"Transfer data quickly between your memory card and your computer with SanDisk's Readers, Writers and Adapters"No
SystemDoctor 2006 FreeXsd2006.exeSystemDoctor rogue security software - not recommended, removal instructions hereNo
Sd32infoXsd32info.exeAdded by the CRYPTER.A TROJAN!No
SDaemonUsdaemon.exePC Security™ from Tropical Software - "is the ultimate in computer security, offering multiple locking systems for the windows environment and internet. Lock files, monitor programs activities, even detect intruders!"No
vccacAXsdaxzl.exeAdded by the SDBOT-RP WORM!No
SpyDefenseYsdc.exeSpyDefense spyware remover by Everest Labs - no longer availableNo
startXsdcc.exeAdded by the AGENT.CSX TROJAN!No
Direct settingsXsdchost.exeAdded by the DAEMONI-I TROJAN!No
Spybot-SD CleaningYSDCleaner.exeGenerated by Spybot - Search & Destroy 2 from Safer-Networking Ltd if it encounters files that cannot be deleted during runtime because they are locked by other processesNo
SDClientMonitorUsdclientmonitor.exeLANDesk® Management Suite software componentNo
Stardock CentralNsdctray.exeStardock Central from Stardock Corporation - "is an enhanced download manager that enables users to install and manage Stardock's software products." Now replaced by the Impulse digital distribution platformNo
Call Function System32Xsddriver.exeAdded by a variant of the SDBOT BACKDOOR!No
Scanner DetectorNSDetect.exeScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the "GO" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the "GO" buttonNo
SDetectNSDetect.exeScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the "GO" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the "GO" buttonNo
serverXsdfdsfsdf.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\SpynetNo
strkjhkXsdflkj3.exeAdded by an unidentified WORM or TROJAN - see hereNo
Start Network Scanner ToolUsdFTP.exePart of Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents"No
MsnExplorerXsdhch.exeAdded by the TACTSLAY.B TROJAN!No
SchedulerXsdhch.exeAdded by the TACTSLAY.B TROJAN!No
SvcH0stXsdhch.exeAdded by the TACTSLAY.B TROJAN!No
WinAmpAgentXsdhch.exeAdded by the TACTSLAY.B TROJAN!No
Server Daemon Host ManagerXsdhost.exeAdded by the RBOT-GWC WORM!No
SDIN AdapterXsdin.exeAdded by the FORBOT-AP WORM!No
Winsock2 driverXSDJOIJE.EXEAdded by the SPYBOT.DR TROJAN!No
Sdk**.exe [* = random char]XSdk**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this logNo
Sdk**32.exe [* = random char]XSdk**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this logNo
sdkupdate22XSDK0mCORE.exeAdded by the FORBOT-DT WORM!No
SDKcore Update Components2XSDKC0R3.exeAdded by the RBOT-ABA WORM!No
SDKCprordsXSDKc55rezzz.exeAdded by the RBOT.VD WORM!No
SDKz0rXSDKc55rezzz2.exeAdded by the SDBOT-UN WORM!No
SDK Core ComponentXsdkcore.exeAdded by the SDBOT-WC WORM!No
SDK Codre Function22Xsdkimddprovment2.exeAdded by the SDBOT-YJ WORM!No
SDK Core FunctionXsdkimprovment.exeDetected by Trend Micro as WORM_RBOT.BHLNo
SDK Core Function2Xsdkimprovment2.exeAdded by the SPYBOT.OGX WORM!No
Mascro soft SDK updates2XSDKrepair2.exeAdded by the SDBOT.BXM WORM!No
Microsoft sdk tempXsdktemp.exeAdded by the RBOT-ANP WORM!No
sdllxxxxxx.exeXsdllxxxxxx.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Root%\sdllxxxxxx.exeNo
MonitorSDUSDMonitor.exeSpyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see hereNo
Files DriverXsdphost.exeAdded by the SDBOT-DKZ WORM!No
SDPhotoBar.exeNSDPhotoBar.exeSmartDraw Photo (now FotoFinsh) - "organize, enhance, print, and share your photos. It's also a powerful graphic editor for creating images and web graphics"No
StartSecurDocUSDPin.exeSecurDoc from WinMagic Inc - "Provides full disk encryption to protect sensitive information stored on laptops, desktops and PDAs"No
wqdfadadsXsdqdad.exeAdded by the MULDROP.F TROJAN!No
genserv pathXsdqdqg.exeAdded by the SDBOT-RF WORM!No
sdrssXsdrss.exeAdded by the SDBOT-SQ WORM!No
sadsXsdsa.exeAdded by the RBOT-PA WORM!No
SSOmonXsdserver.exeDetected by Malwarebytes Anti-Malware as Trojan.Vasdek. The file is located in %Temp%No
cvmsyslpdXsdservss.exeAdded by the MAILBOT-BY TROJAN!No
FlashPath MonitorNSDSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start → ProgramsNo
FlashPath StatusNSDSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start → ProgramsNo
Windows UpdaterXsdsys.exeDetected by Sophos as W32/Forbot-JG and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
Windows Updater 32Xsdsys.exeDetected by Trend Micro as WORM_WOOTBOT.JG and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
SystemTraySDUSDSystemTray.exeSpyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see hereNo
SDTrayUsdtray.exeSystem Tray access to RSA Keon Standalone Desktop (was Web PassPort) from RSA Security - which "makes it easy for our data center staff members to protect confidential customer financial data files with proven RSA Security encryption while locking down each of their individual PC desktops." The file is located in either %ProgramFiles%\RSA Security\RSA Keon Desktop\System or %ProgramFiles%\RSA Security\Web PassPort\Plug-In\systemNo
SDTrayYSDTray.exeSystem Tray access to and notifications for Spybot - Search & Destroy 2 from Safer-Networking Ltd. The file is located in %ProgramFiles%\Spybot - Search & Destroy 2Yes
Spybot - Search & DestroyYSDTray.exeSystem Tray access to and notifications for Spybot - Search & Destroy 2 from Safer-Networking Ltd. The file is located in %ProgramFiles%\Spybot - Search & Destroy 2Yes
TFS DesktopTrayUSDTray.exeSystem Tray access to the older TFS Desktop (which became BoKS Desktop and is now FoxT DesktopControl) from TFS Technology, Inc. (now Fox Technologies). Access management software which "allows for you to take control of local accounts on your Windows Desktop systems"No
SDTrayYSDTrayApp.exeSystem Tray access to an older version of Spyware Doctor antispyware from PC ToolsNo
MSN HomeXsdwd.exeAdded by the SDBOT.NR TROJAN!No
PC Dynamics SdwMon32Usdwmon32.exeSafeHouse "Personal Privacy" protects and hides your private and personal photos, videos, files and folders by making them "invisible" and encryptedNo
SafeHouseSystemTrayUSDWTRAY.EXESafeHouse "Personal Privacy" system tray icon - PP protects and hides your private and personal photos, videos, files and folders by making them "invisible" and encryptedNo
PSAXLSLXsdxl.exeDetected by McAfee as RDN/Generic.dx!w and by Malwarebytes Anti-Malware as Trojan.Agent.TBUNo
sdxsys32Xsdxsys32.exeAdded by the BROGGER-A TROJAN!No
spXse.dll,DllInstallSTARTPAGE.M hijackerNo
Search-ExeXSE.exeSearch-Exe hijackerNo
Security essentials 2010XSE2010.exeSecurity Essentials 2010 rogue security software - not recommended, removal instructions hereNo
updatesstXSE2010.exeSecurity Essentials 2011 rogue security software - not recommended, removal instructions hereNo
Se4nHWIDGenXSE4NHWIDGEN.exeDetected by Dr.Web as Trojan.DownLoader8.18651 and by Malwarebytes Anti-Malware as Backdoor.Agent.SWDNo
st5h5ss5e4XTrojan.Agent.WNLDetected by Malwarebytes Anti-Malware as Trojan.Agent.WNL. The file is located in %AppData%No
s5retys5er5XTrojan.Agent.WNLDetected by Malwarebytes Anti-Malware as Trojan.Agent.WNL. The file is located in %Windir%No
[random name]Xse?vices.exePurityScan adwareNo
Seagate 2GHK2Q3E Product RegistrationNSeagate 2GHK2Q3E Product Registration.exeLeaderTech's PowerREGISTER registration reminder for Seagate storage productsNo
Seagate Product RegistrationNSeagate Product Registration.exeLeaderTech's PowerREGISTER registration reminder for Seagate storage productsNo
SeahawksScreenServerUSeahawksScreenServer.exeScreensaver for the Seattle Seahawks NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supportedNo
SeahawksScreenServerSvcUSeahawksScreenServer.exeScreensaver for the Seattle Seahawks NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supportedNo
sealmonUsealmon.exeSealedMedia enables you to combine document protection and control with your existing applications - such as Microsoft Word, Microsoft Excel, Microsoft PowerPoint and EmailNo
SearchAndDestroyMFCXSearch And Destroy.exeSearch And Destroy rogue security software - not recommended, removal instructions hereNo
searchXsearch.cmdDetected by Sophos as Troj/DwnLdr-KLV and by Malwarebytes Anti-Malware as Trojan.Tophos. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
search.cmd_Xsearch.cmd_.exeDetected by Malwarebytes Anti-Malware as Trojan.Cossta. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
MoveSearchXSearch.exeDetected by Symantec as Adware.PigSearch and by Malwarebytes Anti-Malware as Adware.PigSearch. The file is located in %ProgramFiles%\wsearchNo
WhenUSearchXSearch.exeWhenUSearch adwareNo
SearchAndDestroySchedulerXSearchAndDestroy.exeSearch And Destroy rogue security software - not recommended, removal instructions hereNo
SearchAndDestroyTXSearchAndDestroy.exeSearch And Destroy rogue security software - not recommended, removal instructions hereNo
mswsplXsearchbarcash.exeSearchBarCash adwareNo
Search DefenderXSearchDefender.exeInstalled by SpeedItUp without permission, along with PC-Checker. Detected by DrWeb as the STARTPAGE.ORIGIN TROJAN!No
SearchEngineProtection?SearchEngineProtection.exeInstalled with an older version of the Oberon Gamesbar from Oberon Media which is provided to "help fans of casual games have a quick and easy access to all the new games available to play. Part of Internet Explorer, the Gamesbar will keep your games at your fingertips." Powered by Google this probably protected the default search engine usedNo
SearchEye SE.exeXSearchEye SE.exeSearchEye adwareNo
FBSearchXSearchGuardPlus.exeFast Browser Search/Search Guard Plus parasite - installed with "Make the Web Better" applications such as My Web Tattoo, My Face LOL and Google Easy Money Kit. See here and here for more informationNo
Microsoft ConfigXsearchindex.exeDetected by Malwarebytes Anti-Malware as Trojan.Dropper. The file is located in %UserTemp%No
WANTIVIRSERVICEXSearchIndexer.exeDetected by McAfee as Ransom and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Windows Search (SearchIndexer.exe) service which runs a service and is located in %System%. This one is located in %AppData%\MicrosoftNo
SearchLiteXSearchLite.exeDetected by McAfee as Generic.bfrNo
searchnavXsearchnav.exeSearchNav adware - IEFeatures/Popnav variantNo
SearchNavVersionXsearchnavversion.exeSearchNav adware - IEFeatures/Popnav variantNo
SSLXSearchNDestrou.exeAdded by the SDBOT-WG WORM!No
Search OnXsearchon.exeSearch On adwareNo
search OnXsearchon.exeDetected by McAfee as Generic.bfr!ep and by Malwarebytes Anti-Malware as Adware.SearchOnNo
SearchPotXSearchPot.exeSearchPot adwareNo
Search ProtectionUSearchProtection.exe"Yahoo! Search Protection will alert you if an attempt is made to change your default browser search engine from Yahoo!"No
SearchProtectionUSearchProtection.exe"Yahoo! Search Protection will alert you if an attempt is made to change your default browser search engine from Yahoo!"No
YSearchProtectionUSearchProtection.exe"Yahoo! Search Protection will alert you if an attempt is made to change your default browser search engine from Yahoo!"No
SearchSetterXsearchsetter[1].exeBrowser hijacker - redirecting to FindWhateverNow.comNo
SearchSettingsXSearchSettings.exeVendio "Search Settings" foistware - reportedly installed without notice, see here and hereNo
SearchSpyXSearchSpyMenu.exeSearchSpy rogue spyware remover - not recommended, removal instructions hereNo
SearchSquire[number]XSearchSquire[number].exeSearchSquire adwareNo
searchtolbaXsearchtolba.exeDetected by McAfee as Generic.dx!bh3c and by Malwarebytes Anti-Malware as Backdoor.AgentNo
searchtolba.exeXsearchtolba.exeDetected by McAfee as Generic.dx!bh3c and by Malwarebytes Anti-Malware as Backdoor.AgentNo
SearchUpgraderXSearchUpgrader.exeKeenValue adwareNo
INWVIPGRHHAPVAHRVACEIYMAOQXSearchWin.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker.SWGen. The file is located in %Temp%No
KYSPXETYVHNCFPQGBAUVASFEWFXSearchWin.exeDetected by McAfee as Generic Downloader.x and by Malwarebytes Anti-Malware as Trojan.Banker.SWGenNo
NCFHKGQVRCPYSMTXKTCDIUTEUÞXSearchWin.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker.SWGen. The file is located in %Temp%No
vagrdqegymkroaaofugmxemqagXSearchWin.exeDetected by Dr.Web as Trojan.DownLoader7.12457 and by Malwarebytes Anti-Malware as Trojan.Banker.SWGenNo
vqqlxplxkloopbkhgfpvlwvjĂdXSearchWin.exeDetected by Dr.Web as Trojan.DownLoader7.27975 and by Malwarebytes Anti-Malware as Trojan.Banker.SWGenNo
XEQCUUIRBTBMXLWGBMENPYCQFXSearchWin.exeDetected by McAfee as PWS-Banker and by Malwarebytes Anti-Malware as Trojan.Banker.SWGenNo
SecureExpertCleanerXsec.exeSecure Expert Cleaner rogue privacy program - not recommended, removal instructions hereNo
run=Xsec5dec.exeAdded by the ATAK.G WORM!No
Second CopyUSecCopy.exeSecond Copy® by Centered Systems - "is the perfect automatic backup software designed for Windows XP and above. It makes a backup of your data files to another directory, internal or external hard disk or to a computer across the network"No
Second Copy 2000USecCopy.exeSecond Copy® by Centered Systems - "is the perfect automatic backup software designed for Windows XP and above. It makes a backup of your data files to another directory, internal or external hard disk or to a computer across the network"No
*Security CenterXsecctr.exeAdded by the SDBOT.BRO WORM!No
secdrive.exeXsecdrive.exeAdded by a variant of the SPYBOT WORM! See hereNo
SecretXSecret.exeAdded by the DELF-LW TROJAN!No
SECRETMAKERUsecretmaker.exeSecretmaker is a combination of eight privacy-defending programs, including Spam Fighter Pro, Worm Hunter, Pop-Up Killer, Banner Blocker, Cookie Eraser, Privacy Protector, History Cleaner, and Garbage CleanerNo
Windows UpdateXSecretStub.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %Windir%No
secserv.exeXsecserv.exeDetected by Panda as an EasySearch adware variant. Note - EasySearch modifies the Internet Explorer settings and may download programs onto the infected computerNo
Security Server DBXsecserver.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
Security Service DBXsecservice.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
secsrvrcXsecsrvrc.exeDetected by Kaspersky as Trojan-Spy.Win32.SCKeyLog.auNo
Network SecurityXsecsvc.exeAdded by the RBOT-ALX WORM!No
Security ServiceXsecsvc.exeAdded by the RBOT-GGF WORM!No
System Event ManagerXsecsvc.exeDetected by Trend Micro as WORM_RBOT.BMYNo
secsvc32Xsecsvcnt.exeAdded by the GLOBAL PATROL TROJAN!No
SecsysUSecsys.exeUltraSoft Key Interceptor surveillance software - uninstall this unless you put it there yourself!No
Security AgentXsecurag.exeDetected by Sophos as Troj/Bancban-FNo
BatXsecure2.batAdded by the ZCREW.C TROJAN!No
Compaq Computer Security?Secure32.exe??No
Win32 Security ProtocolXsecure32.exeAdded by the RBOT-ETI WORM!No
Winsecure AntivirusXSecureantivirus.exeAdded by a variant of the SPYBOT WORM!No
MicrosoftCorpXsecurebind.exeAdded by the INJECT TROJAN!No
MicrosoftNAPCXsecurebind.exeAdded by the INJECT TROJAN!No
SecureCleanerXSecureCleaner.exeSecureCleaner rogue spyware remover - not recommended, removal instructions hereNo
SecureFighterXSecureFighter.exeSecureFighter rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
SecureItProUSecureitpro470p.exeSecureIt Pro - lock your computer when you're not there, to stop malicious users from accessing your desktopNo
SecureKeeperXSecureKeeper.exeSecureKeeper rogue security software - not recommended, removal instructions here. A member of the AntiAID familyNo
Security MonitorXsecuremon.exeAdded by the SLENFBOT.ABH WORM!No
Microsoft InformationXsecurenet.exeAdded by the SDBOT.AJM WORM!No
SecurePcAvXSecurePcAv.exeSecurePcAv rogue security software - not recommended, removal instructions here. A member of the AntiAID familyNo
Security Center DistributionXsecuresec.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
Security SystemXsecuresys.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
2kowmeuswvw3Xsecuretystudio.exeSecurity Inspector 2010 rogue security software - not recommended, removal instructions hereNo
SecureVeteranXSecureVeteran.exeSecureVeteran rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
SecureWarriorXSecureWarrior.exeSecureWarrior rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
[random characters]Xsecurewinload32x.exeAdded by the OPTIXP-N TROJAN!No
Security CentralXSecurity Central.exeSecurity Central rogue security software - not recommended, removal instructions hereNo
Security iGuardXSecurity iGuard.exeSecurity iGuard rogue spyware remover - not recommended, removal instructions hereNo
Security MonitorXSecurity Monitor.exeSecurity Monitor 2012 rogue security software - not recommended, removal instructions hereNo
Security Solution 2011XSecurity Solution.exeSecurity Solution 2011 rogue security software - not recommended, removal instructions hereNo
2kowmeuswvw3Xsecurity.exeAntiVirus Solution 2010 rogue security software - not recommended, removal instructions hereNo
Disk KeeperXsecurity.exeDaosearch adwareNo
Windows SecurityXsecurity.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Temp%No
Security 2009XSecurity2009.exeSecurity 2009 rogue security suite - not recommended, removal instructions hereNo
Microsoft Security UpdateXsecurity32.exeAdded by the DELF-JJ TROJAN!No
Windows Security UpdateXsecurity32.exeAffilred adwareNo
SecurityBoanXSecurityBoan.exeSecurityBoan rogue security software - not recommended, removal instructions hereNo
Aluria Security CenterNSecurityCenter.exeAluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see hereNo
SecurityCenterXsecuritycenter.exeEntry added by Desktop Security 2010, Antivirus Studio 2010 and other rogue security software - not recommendedNo
Microsoft Secure Messenger.NET ServiceXsecuritychk.exeDetected by Trend Micro as WORM_WOOTBOT.KNo
DCPstrAppYSecurityDeviceInfoSetRegistryString.exePart of the Dell ControlPoint Security Manager - which "provides access to your security, user identification, fingerprint readers, and smartcard security technology". Dell ControlPoint is "designed to simplify and unify the execution of what should be simple system functions" and "integrates best-of-breed software and utility solutions into one helpful solution"No
SecurityFighterXSecurityFighter.exeSecurityFighter rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
2kowmeuswvw3Xsecurityhelper.exeAntiVirus System 2011 rogue security software - not recommended, removal instructions hereNo
Antivirus Protection 2012 SHXsecurityhelper.exeAntivirus Protection 2012 rogue security software - not recommended, removal instructions hereNo
AntiVirus AntiSpyware 2011 SecurityXsecuritymanager.exeAntivirus AntiSpyware 2011 rogue security software - not recommended, removal instructions hereNo
Antivirus Protection 2012 SMXsecuritymanager.exeAntivirus Protection 2012 rogue security software - not recommended, removal instructions hereNo
Security ManagerUSecurityManager.exeA ComCast Internet software suite that provides a variety of features (firewall, popup blocker, parental controls, etc) to help ensure your computer is secure, and your information is kept private. Located in %ProgramFiles%\Comcast\Security Manager\appNo
Security ManagerXsecuritymanager.exeAntiVirus System 2011 rogue security software - not recommended, removal instructions here. Note - this is not the valid Comcast security program typically located in %ProgramFiles%\Comcast\Security Manager\app. This one is located in %AppData%\AntiVirus System 2011No
Security Monitor 2012 SecurityXsecuritymanager.exeSecurity Monitor 2012 rogue security software - not recommended, removal instructions hereNo
Security Solution 2011 SecurityXsecuritymanager.exeSecurity Solution 2011 rogue security software - not recommended, removal instructions hereNo
SecuritySoldierXSecuritySoldier.exeSecuritySoldier rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
Security Inspector 2010XSecurity_Inspector_2010.exeSecurity Inspector 2010 rogue security software - not recommended, removal instructions hereNo
SECWIZ98YSECWIZ98.EXESecurity Wizard 98 by Chris Farmer. Offers you a variety of ways to restrict access to many of the programs and settings on your PC. Available hereNo
CLSIDXsed.exeOnlineDirect - Switch dialer and hijacker variant, see hereNo
SESyncXSED.exeDownloadWare adwareNo
gqvqevsXseeffkme.exeAdded by the SDBOT-QD WORM!No
seekmoXseekmo.exeSeekmo Search Assistant adwareNo
SeekmoSAXSeekmoSA.exeSeekmo Search Assistant adwareNo
seeveXseeve.exeMedload adwareNo
SelectRebatesXSelectRebates.exeSelectRebates adwareNo
FriendlyWebQuick-LaunchNSELFCERT.EXEselfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as wellNo
SelfPrivacyXSelfPrivacy.exeSelfPrivacy rogue security software - not recommended, removal instructions hereNo
[various names]Xseli.exeMediaMotor adwareNo
selmodevolXselmodevol.exeDetected by Kaspersky as Trojan-PSW.Win32.LdPinch.angmNo
RoflcopteurXseman.exeAdded by an unidentified WORM or TROJAN!No
SemanticInsightXSemanticInsight.exeRXToolbar adware. Software that displays pop-up/pop-under advertisements when the primary user interface is not visibleNo
Bron-SpizaetusXsempalong.exeAdded by the BRONTOK-E WORM!No
SeMSUSeMS.exePCsms - tool that enables you to send sms text messages from your PC to any UK mobile phoneNo
senderXsender.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %Windir%\helpNo
SendMailUSendMail.exePart of the MySuperSPy surveillance software. Uninstall this software unless you put it there yourself. Located in %ProgramFiles%\MyssNo
QQXsendmess.exeAdded by the SEMES TROJAN!No
System Error NotificationXsenr32.exeAdded by the POISON-BT TROJAN!No
SensivaUSensiva.exeSymbol Commander from Sensiva - makes the use of your PC, laptop, Tablet PC, and Pocket PC much easier and much faster. It recognizes your handwriting with unparalled performance and executes commands in a snap. Just by using your mouse, pen, or touchpad, simply draw symbols to execute actions instantlyNo
SENS Keyboard V4 LauncherUSENSKBD.EXEHot-key manager for some Samsung notebooks - required if you use the keysNo
SENS Keyboard V6 LauncherUSENSKBD.EXEHot-key manager for some Samsung notebooks - required if you use the keysNo
Quick Heal AntiVirusYsensor.exePart of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. Optionally scans the system boot area for programs trying to automatically execute before Windows loads and keeps a watch on some system files which are commonly patched (or replaced) by malware. Feature not supported on Windows 7/Vista systems. Also included by vendors who use the Quick Heal engine such as Omniquad and iQonYes
SensorYsensor.exePart of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. Optionally scans the system boot area for programs trying to automatically execute before Windows loads and keeps a watch on some system files which are commonly patched (or replaced) by malware. Feature not supported on Windows 7/Vista systems. Also included by vendors who use the Quick Heal engine such as Omniquad and iQonYes
Startup ScanYsensor.exePart of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. Optionally scans the system boot area for programs trying to automatically execute before Windows loads and keeps a watch on some system files which are commonly patched (or replaced) by malware. Feature not supported on Windows 7/Vista systems. Also included by vendors who use the Quick Heal engine such as Omniquad and iQonYes
sentinelmonUsentinelmon.exePCSentinel's Smoking Gun! surveillance software. Uninstall this software unless you put it there yourselfNo
CrisysTec SentryXSentry.exeCrisysTec Sentry rogue privacy program - not recommendedNo
SENTRYXSENTRY.exeFrom IP Insight. Allows website owners "to instantly determine the precise geographic location, connection speed and detailed demographics of every visitor to your website". Will be detected by most firewalls and the majority of home users should disable itNo
RNBOStartUsentstrt.exeProgram used to initialise the VxD virtual driver for Sentinel drivers associated with Rainbow H/W keys that plug-in to the parallel port. These are usually supplied with workplace design tools and restrict the use of the software only to the machine to which the H/W key is connected. Required if you have such toolsNo
Sepate Security FirewallXsepate.exeAdded by the RBOT.BLC BACKDOOR!No
SEPCSuiteNSEPCSuite.exeSystem Tray access to Sony Ericsson PC Suite (now replaced by PC Companion) which "connects your phone to your computer and expands the capabilities of your phone". Run manually via the Start Menu (or optional desktop shortcut) before connecting the phoneYes
Sony Ericsson PC SuiteNSEPCSuite.exeSystem Tray access to Sony Ericsson PC Suite (now replaced by PC Companion) which "connects your phone to your computer and expands the capabilities of your phone". Run manually via the Start Menu (or optional desktop shortcut) before connecting the phoneYes
septpop06apseptXseptpop06apsept.exeMediaMotor.Popupwithcast adwareNo
Windows Live FamilyXSEPWDN.EXEDetected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Trojan.Agent.DPTNo
avnortXserbw.exeAdded by the SERFLOG.A WORM!No
ltwobXserbw.exeAdded by the SERFLOG.A WORM!No
serpeXserbw.exeAdded by the SERFLOG.A WORM!No
mservXseres.exeAdded by the AGENT-LIL WORM!No
36OSafeUpdateXseria.exeDetected by Kaspersky as Trojan.Win32.Agent.fajkNo
SerialsXserials.exeAny one of a variety of worms and trojansNo
SERIAL UPDATE2013XSerials2013.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.SR. The file is located in %AppData%No
System ServiceXserious.exeAdded by the RBOT-FMV WORM! Note - deactivates the Microsoft Internet Connection Firewall (ICF)No
ToolBarXseriusdat.exeDetected by Microsoft as TrojanSpy:Win32/Bancos.ACJNo
Microsoft WinUpdatesXserm32.exeAdded by the RBOT.GE WORM!No
SErmYcVkqxTXSErmYcVkqxT.exeAdded by the CEEINJEC-K TROJAN!No
serrdctl.exeYserrdctl.exe"Shared Modem Service Client Event Viewer" - used when a number of PCs have access to a number of modems. Required to be running on each PC for access to the modemsNo
serrvXserrv.exeAdded by the WAREZOV.DC WORM!No
Microsoft Windows ServicesXSersices.exeAdded by the SDBOT-NO WORM!No
Configuration LoaderXseru32.exeAdded by the SDBOT-VR WORM!No
ISTRATORXSeruice.exeDetected by Malwarebytes Anti-Malware as Trojan.StartPage. The file is located in %Root%No
Serv-U® File ServerUServ-U-Tray.exeSystem Tray access for the Serv-U FTP server which allows the user to (amongst others) start the Management Console, stop the server and display notificationsYes
Serv-U-TrayUServ-U-Tray.exeSystem Tray access for the Serv-U FTP server which allows the user to (amongst others) start the Management Console, stop the server and display notificationsYes
ServUTrayIconUServ-U-Tray.exeSystem Tray access for the Serv-U FTP server which allows the user to (amongst others) start the Management Console, stop the server and display notificationsYes
Serv-UNserv-u32.exeFTP serverNo
Generic Service ProcessXserv1ces.exeAdded by the AGOBOT-JK WORM!No
Service ManagerXserv3manager.exeAdded by the SDBOT-AGO WORM!No
Rout111Xserv454.exeAdded by the WOOTBOT.DB BACKDOOR!No
Services Management ClientsXservc.exeAdded by a variant of Backdoor.Rizo.A. The file is located in %System%\inetsrvNo
WINDOWS SYSTEMXservce.exeAdded by the MYTOB-EI WORM!No
ServicerXservcr.exeDetected by Trend Micro as TROJ_SDBOT.BAHNo
Microsoft Windows UpdateXservcs.exeAdded by the SDBOT.AL BACKDOOR!No
Services ManagementsXservcs.exeAdded by the RBOT-GUC WORM!No
Windows UpdateXservcshost.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %CommonFiles%\SystemNo
Key2?serve.exe??No
NDIS AdapterXServenxp.exeAdded by the SPYBOT.LY WORM!No
NDIS AdapterXservenxpp.exeAdded by the FORBOT-GP WORM!No
serverXserverDetected by Malwarebytes Anti-Malware as Stolen.Data. The file is located in %AppData%No
Win32RXServer.comAdded by the ESTRELLA TROJAN!No
sysserXserver.dllAdded by the RAHACK WORM!No
(Default)Xserver.exeDetected by Malwarebytes Anti-Malware as Trojan.FakeMS. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %AppData%No
9bc84f151ed2d9df584248737dda5319Xserver.exeDetected by Dr.Web as Trojan.DownLoader7.9156 and by Malwarebytes Anti-Malware as Trojan.MSILNo
Adobe UpdatesXServer.exeDetected by Kaspersky as Trojan-Spy.MSIL.Keylogger.hfu. Note - this is not a legitimate Adobe entryNo
babe8364d0b44de2ea6e4bcccd70281eXserver.exeDetected by McAfee as RDN/Generic PWS.y!lt and by Malwarebytes Anti-Malware as Trojan.MSILNo
bead739c11b6815884fb1a13a48ced96XServer.exeDetected by Dr.Web as Trojan.DownLoader7.9439 and by Malwarebytes Anti-Malware as Trojan.MSILNo
bead739c11b6815884fb1a13a48ced96XServer.exeDetected by Dr.Web as Trojan.DownLoader7.9439 and by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Temp%No
CAMFROGXserver.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. Note - this is not the legitimate Camfrog video chat software by Camshare Inc. The file is located in %System%\InstallNo
CerberusXserver.exeDetected by McAfee as W32/Pate.bNo
CesarFTP FTP ServerNserver.exeCesarFTPd - FTP serverNo
ctfmonXserver.exeDetected by Malwarebytes Anti-Malware as Trojan.Passwords. The file is located in %UserTemp%No
dreamsXserver.exeAdded by a variant of W32/Sdbot.wormNo
easyServXServer.exeAdded by the EASYSERV TROJAN!No
EXPLORERXServer.exeDetected by Malwarebytes Anti-Malware as Trojan.VBAgent. The file is located in %Windir%No
EXPLORERSXServer.exeDetected by McAfee as RDN/Generic.dx!bc and by Malwarebytes Anti-Malware as Backdoor.AgentNo
FaceXserver.exeDetected by Malwarebytes Anti-Malware as Backdoor.Poison. The file is located in %UserTemp%No
fileXserver.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor.DF. The file is located in %Windir%No
HKCUXserver.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %AppData%\svchost.exeNo
HKCUXserver.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %ProgramFiles%\installNo
HKCUXserver.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\dir\install\WinUpdateNo
HKCUXserver.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\installNo
HKCUXserver.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\svchost.exeNo
HKCUXServer.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %UserTemp%\InstallDirNo
HKCUXserver.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor. The file is located in %System%No
HKCUXServer.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %System%\%tamp%No
HKCUXserver.exeDetected by Malwarebytes Anti-Malware as Worm.Autorun. The file is located in %System%\SystemNo
HKCUXserver.exeDetected by Kaspersky as Trojan-Dropper.MSIL.Agent.nws and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\installNo
HKCUXserver.exeDetected by Kaspersky as Trojan-Dropper.Win32.Agent.dvyh and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\installNo
HKCUXserver.exeDetected by Kaspersky as Trojan.Win32.Buzus.gpnn and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\dir\install\installNo
HKCUXServer.exeDetected by Kaspersky as Trojan-Ransom.Win32.PornoBlocker.jmd and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\WinDirNo
HKCUXserver.exeDetected by Kaspersky as Trojan-Spy.Win32.Zbot.bhjn and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\directory\CyberGate\installNo
HKCUXserver.exeDetected by Kaspersky as Trojan-Spy.Win32.Zbot.bjhg and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\dir\install\spynetNo
HKCUXServer.exeDetected by Kaspersky as Backdoor.Win32.Xtreme.bid and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %ProgramFiles%\InstallDirNo
HKCUXserver.exeDetected by McAfee as Generic PWS.y!1xx and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\LargeNo
HKCUXserver.exeDetected by McAfee as PWS-Zbot.gen.lm and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Temp%\tempNo
HKCUXserver.exeDetected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\dir\install\msnmgr.exe\installNo
HKCUXServer.exeDetected by McAfee as Generic.bfr!cs and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\WinDirNo
HKCUXServer.exeDetected by McAfee as Generic.bfr!dd and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\WinlogNo
HKCUXServer.exeDetected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\WinDirNo
HKCUXserver.exeDetected by Sophos as Troj/Agent-NLT and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\installNo
HKCUXserver.exeDetected by Sophos as Troj/Inject-XD and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\InstallDirNo
HKCUXserver.exeDetected by Sophos as W32/Rebhip-U and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\spynetNo
HKCUXserver.exeDetected by Trend Micro as TROJ_LETHIC.SMA and by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Windir%\InstallDirNo
HKLMXserver.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %AppData%\installNo
HKLMXserver.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %AppData%\svchost.exeNo
HKLMXserver.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %ProgramFiles%\installNo
HKLMXserver.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\dir\install\WinUpdateNo
HKLMXserver.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\svchost.exeNo
HKLMXServer.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %UserTemp%\InstallDirNo
HKLMXserver.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor. The file is located in %System%No
HKLMXserver.exeDetected by Malwarebytes Anti-Malware as Worm.Autorun. The file is located in %System%\SystemNo
HKLMXserver.exeDetected by Kaspersky as Trojan-Dropper.MSIL.Agent.nws and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\installNo
HKLMXserver.exeDetected by Kaspersky as Trojan-Dropper.Win32.Agent.dvyh and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\installNo
HKLMXserver.exeDetected by Kaspersky as Trojan.Win32.Buzus.gpnn and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\dir\install\installNo
HKLMXServer.exeDetected by Kaspersky as Trojan-Ransom.Win32.PornoBlocker.jmd and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\WinDirNo
HKLMXserver.exeDetected by Kaspersky as Trojan-Spy.Win32.Zbot.bhjn and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\directory\CyberGate\installNo
HKLMXserver.exeDetected by Kaspersky as Trojan-Spy.Win32.Zbot.bjhg and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\dir\install\spynetNo
HKLMXServer.exeDetected by Kaspersky as Backdoor.Win32.Xtreme.bid and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %ProgramFiles%\InstallDirNo
HKLMXserver.exeDetected by McAfee as Generic PWS.y!1xx and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\LargeNo
HKLMXserver.exeDetected by McAfee as PWS-Zbot.gen.lm and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Temp%\tempNo
HKLMXserver.exeDetected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\dir\install\msnmgr.exe\installNo
HKLMXServer.exeDetected by McAfee as Generic.bfr!cs and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Root%\WinDirNo
HKLMXServer.exeDetected by McAfee as Generic.bfr!dd and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\WinlogNo
HKLMXServer.exeDetected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\WinDirNo
HKLMXserver.exeDetected by Sophos as Troj/Agent-NLT and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\installNo
HKLMXserver.exeDetected by Sophos as Troj/Inject-XD and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\InstallDirNo
HKLMXserver.exeDetected by Sophos as W32/Rebhip-U and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\spynetNo
HKLMXserver.exeDetected by Trend Micro as TROJ_LETHIC.SMA and by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Windir%\InstallDirNo
hvytirdt eudXserver.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %System%\installNo
jfjbgyeey eurXserver.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %System%\installNo
Key NameXServer.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserTemp%No
killXserver.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor.SVR. The file is located in %Windir%No
microsoftXServer.exeDetected by Sophos as W32/Rebhip-N and by Malwarebytes Anti-Malware as Trojan.Backdoor.XTR. The file is located in %Windir%\InstallDirNo
MicroUpdateXserver.exeDetected by McAfee as PWS-FAHB!EF21253AD423 and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
msnmgrXServer.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\InstallDirNo
pcServerXserver.exeSsppyy spywareNo
PoliciesXserver.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %AppData%\svchost.exeNo
PoliciesXserver.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %ProgramFiles%\installNo
PoliciesXserver.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Root%\dir\install\WinUpdateNo
PoliciesXserver.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Root%\svchost.exeNo
PoliciesXserver.exeDetected by Malwarebytes Anti-Malware as Trojan.VirTool. The file is located in %ProgramFiles%\LargeNo
PoliciesXserver.exeDetected by Malwarebytes Anti-Malware as Worm.Autorun. The file is located in %System%\SystemNo
PoliciesXserver.exeDetected by Kaspersky as Trojan-Dropper.MSIL.Agent.nws and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Root%\installNo
PoliciesXserver.exeDetected by Kaspersky as Trojan-Dropper.Win32.Agent.dvyh and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\installNo
PoliciesXserver.exeDetected by Kaspersky as Trojan.Win32.Buzus.gpnn and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Root%\dir\install\installNo
PoliciesXServer.exeDetected by Kaspersky as Trojan-Ransom.Win32.PornoBlocker.jmd and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\WinDirNo
PoliciesXserver.exeDetected by Kaspersky as Trojan-Spy.Win32.Zbot.bhjn and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Root%\directory\CyberGate\installNo
PoliciesXserver.exeDetected by Kaspersky as Trojan-Spy.Win32.Zbot.bjhg and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Root%\dir\install\spynetNo
PoliciesXserver.exeDetected by McAfee as Generic PWS.y!1xx and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\LargeNo
PoliciesXserver.exeDetected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Root%\dir\install\msnmgr.exe\installNo
PoliciesXserver.exeDetected by McAfee as RDN/Generic.bfr!z and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Windir%\LargeNo
PoliciesXServer.exeDetected by McAfee as Generic.bfr!cs and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Root%\WinDirNo
PoliciesXServer.exeDetected by McAfee as Generic.bfr!dd and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\WinlogNo
PoliciesXServer.exeDetected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Windir%\WinDirNo
PoliciesXserver.exeDetected by Sophos as Troj/Agent-NLT and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Windir%\installNo
PoliciesXserver.exeDetected by Sophos as W32/Rebhip-U and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\spynetNo
PoliciesXserver.exeDetected by Symantec as W32.Spyrat and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Root%\Dir\installNo
PolicuesXserver.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %System%\installNo
ProtectionXserver.exeDetected by Sophos as Mal/VBInject-ASNo
Protection2Xserver.exeDetected by Sophos as Mal/VBInject-ASNo
RegistryKeyXserver.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %ProgramFiles%No
RegistryKeyXserver.exeDetected by Kaspersky as Trojan.Win32.Scar.bdjh and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System%No
RegistryKeyXserver.exeDetected by Kaspersky as Trojan.Win32.Scar.bwha and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %LocalAppData%No
RegistryKeyXserver.exeDetected by Kaspersky as Trojan.Win32.LogonInvader.a and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%No
RegistryKeyXserver.exeDetected by McAfee as Generic.mfr and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Windir%No
RunProgXServer.exeDetected by Trend Micro as BKDR_OPTIX.04.A and by Malwarebytes Anti-Malware as Trojan.AgentNo
scvhostXServer.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\InstallDirNo
SerXServer.exeDetected by Malwarebytes Anti-Malware as Backdoor.SpyNet. The file is located in %AppData%\SpyNet - see hereNo
ServerXServer.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\hosterNo
ServerXServer.exeDetected by Malwarebytes Anti-Malware as Backdoor.SpyNet. The file is located in %AppData%\SpyNet - see hereNo
ServerXServer.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor.DF. The file is located in %ProgramFiles%\Windaws MessengerNo
ServerXserver.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence here ensures it runs when Windows startsNo
serverXserver.exeDetected by Dr.Web as Trojan.MulDrop4.26221 and by Malwarebytes Anti-Malware as Trojan.AgentNo
ServerXServer.exeDetected by Kaspersky as Backdoor.Win32.Xtreme.bid. The file is located in %ProgramFiles%\InstallDirNo
ServerXServer.exeDetected by McAfee as Generic BackDoor!fqc and by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Windir%\InstallDirNo
ServerXServer.exeDetected by McAfee as Keylog-Spynet.gen.g and by Malwarebytes Anti-Malware as Backdoor.SpyNet. The file is located in %System%\SpyNetNo
ServerXServer.exeDetected by McAfee as RDN/Generic BackDoor!p and by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %System%\InstallDirNo
ServerXServer.exeDetected by McAfee as RDN/Generic.dx!dq and by Malwarebytes Anti-Malware as Trojan.Sasfis. The file is located in %Temp%No
ServerXServer.exeDetected by McAfee as RDN/Generic.dx!ev and by Malwarebytes Anti-Malware as Backdoor.SpyNet. The file is located in %Windir%\SpyNetNo
ServerXserver.exeDetected by McAfee as PWS-FAHB!EF21253AD423 and by Malwarebytes Anti-Malware as Trojan.Sasfis. The file is located in %UserProfile%\Cookies\InstallDirNo
serverXserver.exeDetected by Sophos as Troj/Singu-Q and by Malwarebytes Anti-Malware as Trojan.Sasfis. The file is located in %Windir%No
serverXserver.exeDetected by Trend Micro as WORM_DELTAD.A. The file is located in %Windir% and %System%No
SERVER.EXEXSERVER.EXEAdded by the BUSHTRO122 or SMOKODOOR TROJANS!No
server.exe1Xserver.exeDetected by Kaspersky as Backdoor.Win32.Bifrose.ahrh and by Malwarebytes Anti-Malware as Trojan.AgentNo
SESTIEMSXServer.exeDetected by McAfee as RDN/Generic.dx!bc and by Malwarebytes Anti-Malware as Backdoor.AgentNo
Spy-NetXserver.exeDetected by Trend Micro as BKDR_POISON.IM. The file is located in %System%\Spy-NetNo
SQLXserver.exeAdded by the PUNYA-B WORM!No
sservicesXserver.exeDetected by McAfee as Generic PWS.diNo
startkeyXserver.exeDetected by Sophos as Troj/Bifrose-DB and by Malwarebytes Anti-Malware as Trojan.Backdoor.NRNo
svchost.exeXserver.exeDetected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %UserTemp%No
SystemXserver.exeDetected by Malwarebytes Anti-Malware as Trojan.Inject.DF. The file is located in %AppData%No
System Services MonitorXserver.exeBifrost malwareNo
testXserver.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor.DF. The file is located in %Windir%No
Win32Xserver.exeDetected by Kaspersky as Trojan.Win32.Llac.bsvc and by Malwarebytes Anti-Malware as Worm.Autorun. The file is located in %System%\installNo
WINLOGONXServer.exeDetected by McAfee as Generic.bfr!dd. The file is located in %Root%\WinDirNo
WO99g66W99qYXserver.exeDetected by Malwarebytes Anti-Malware as Trojan.VBInject. The file is located in %System%\installNo
serverexXServer.txt.vbsDetected by Trend Micro as WORM_DELTAD.ANo
winserverXServer.txt.vbsDetected by Trend Micro as WORM_DELTAD.ANo
ZtgServerSwitchXserver.vbsZTGServerswitch is part of Sony's Vaio support agent - designed by Support.com. Not required if the user does not wish to use the Vaio support agent and regarded as spywareNo
Server BackboneXserver05.exeAdded by the RBOT-ZM WORM!No
QUEMAJUNBINOPOLISXServer1.exeDetected by McAfee as Generic VB.n and by Malwarebytes Anti-Malware as Backdoor.AgentNo
Windows DefenderXServer1.exeDetected by McAfee as Generic Dropper.acj and by Malwarebytes Anti-Malware as Trojan.Agent.GenNo
Server201112RXServer201112R.exeDetected by Sophos as Troj/DotNet-G and by Malwarebytes Anti-Malware as Backdoor.BotNo
HKCMXserver32.exeDetected by Malwarebytes Anti-Malware as Wor.Rebhip. The file is located in %System%\LargeNo
HKLMXserver32.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\LargeNo
PoliciesXserver32.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\LargeNo
Server4PCYServer4PC.exeSatellite receiver control program that is responsible for handling TV, radio and internet - on systems from TechniSat for exampleNo
WindowsAPI.DLLXServer5.exeAdded by the "Fear and Hope" TROJAN!No
[random name]XServere.exeAdded by the LEGMIR-AQM TROJAN!No
HKCU OKOKOXservero.exeDetected by McAfee as Generic PWS.diNo
HKLM OOKOXservero.exeDetected by McAfee as Generic PWS.diNo
PoliciesXservero.exeDetected by McAfee as Generic PWS.di and by Malwarebytes Anti-Malware as Backdoor.Agent.PgenNo
ServerxXServerx.exeAdded by the MADANGEL VIRUS!No
PoliciesXserverz.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Windir%\installNo
Server_1XServer_1.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
SearchNet_UpXServeUp.exeSearchNet adwareNo
run windowsXservic.batAdded by the REBOOT-AP TROJAN!No
Microsoft .Net FrameworkXservic.exeDetected by Sophos as Troj/Agent-GUUNo
Microsoft Update 32Xservic.exeAdded by the RBOT-AXN WORM!No
Sygate Personal Firewall StartXservic.exeDetected by Sophos as W32/Rbot-RYNo
WINDOWS SYSTEMnXservicces.exeAdded by the MYTOB-EL WORM!No
services.exeXservice.batAdded by the MDROP-BSW TROJAN!No
12ZFG94-F641-2SF-K31P-5N1ER6H6L2Xservice.exeDetected by Trend Micro as WORM_SILLY.LCNo
AdobeReaderProXservice.exeAdded by the RBOT-BCA WORM!No
antivirusXservice.exeDetected by Dr.Web as Trojan.Inject1.19802 and by Malwarebytes Anti-Malware as Trojan.Agent.AVNo
ConfigXservice.exeAdded by the ISRAZ.B WORM!No
Configuration LoaderXService.exeDetected by Symantec as W32.HLLW.Gaobot.AONo
itunes.exeXService.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Temp%\AppLaunchNo
MDNSXservice.exeMirar adware variantNo
MICROSOFTXservice.exeDetected by McAfee as Generic.bfr!ehNo
Microsoft Security Monitor ProcessXservice.exeAdded by the DELF.BERW BACKDOOR!No
Microsoft ServiceXservice.exeAdded by the IRCBOT-XX BACKDOOR!No
Microsoft UpdateXservice.exeAdded by a variant of the RBOT WORM! See hereNo
Microsoft UpdatesXservice.exeAdded by the POISON.HPT BACKDOOR!No
MSN BETAXservice.exeDetected by Trend Micro as WORM_RBOT.AUUNo
MyappXservice.exeHomepage hijackerNo
r_serverXservice.exeAdded by the MULTIDR-CP TROJAN!No
Registry Value NameXservice.exeAdded by the RBOT-AHT WORM!No
RunServicesXservice.exeDetected by Symantec as W32.VebispNo
SecurenetXservice.exeDetected by Malwarebytes Anti-Malware as Spyware.Keylogger. The file is located in %Root%\Drivers\chipsetNo
ServiceXService.exeDetected by Malwarebytes Anti-Malware as Trojan.VB. The file is located in %Windir%No
Service ControllerXservice.exeAdded by the PREVERT TROJAN!No
service managerXservice.exeAdded by the DONBOMB.A TROJAN!No
Service ProcessXservice.exeAdded by the DCMBOT-C TROJAN!No
Service.exeXService.exe"servedby.advertising" popup generatorNo
service.exeXservice.exeDetected by Malwarebytes Anti-Malware as Spyware.Passwords. The file is located in %UserProfile%\DesktopNo
servicemngXservice.exeAdded by the TAME-C WORM!No
shellXservice.exeDetected by Dr.Web as Trojan.DownLoader6.9480 and by Malwarebytes Anti-Malware as Trojan.Agent.cnNo
SYS_CLEANXService.exeAdded by the FLOPCOPY WORM!No
System ServiceXService.exeDetected by Dr.Web as Trojan.Inject.63084 and by Malwarebytes Anti-Malware as Worm.AutoRunNo
System Service ApplicationXservice.exeDetected by Dr.Web as Win32.HLLW.SpyBot.662No
systr2XSERVICE.exeAdded by the VB-DQY WORM!No
VMGOATPOSTREBOOTANALYSISXservice.exeDetected by McAfee as Scar.gen.c and by Malwarebytes Anti-Malware as Trojan.AgentNo
Win32 USB2.0 DriverXservice.exeAdded by the SDBOT-QF WORM!No
WinDLL (service.exe)Xservice.exeAdded by the AGENT.BX WORM! The "service.exe" file is found in %System%No
Windows Net CfgXservice.exeAdded by a variant of the RBOT WORM!No
Windows ScreensaverXService.exeAdded by the KELVIR.P WORM!No
Windows ServiceXservice.exeAdded by the IRCBOT-ACV WORM!No
Windows ServicesXservice.exeDetected by Symantec as W32.Randex.R and by Malwarebytes Anti-Malware as Backdoor.Agent.GenNo
Windows svchostXservice.exeAdded by the PUSHBOT.DU WORM!No
Windows TaskmanagerXservice.exeAdded by the PUSHBOT.OR WORM!No
Windows Updates SvcsXservice.exeDetected by Dr.Web as BackDoor.IRC.Bot.1050No
Windows_SerivceXSERVICE.exeAdded by the WOOTBOT.AH WORM!No
WindowsServiceXservice.exeAdded by the AUTORUN-VPC WORM!No
WindowsServicesXservice.exeDetected by Symantec as W32.Folmess and by Malwarebytes Anti-Malware as Backdoor.AgentNo
WinPatrolXservice.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not a legitimate WinPatrol entry and the file is located in %Windir%\services\rc0No
Clean upXservice.exe cleanup.batAdded by the AGENT-FPY TROJAN!No
Windows smss serviceXservice.exe smss.exeAdded by the AGENT-FPY TROJAN!No
ServiceXService.pifAdded by the ASSIRAL-C WORM!No
Service2XService2.exeIdentified as a variant of the Win32.Iroffer malware. Located in %Windir%\Drivers\IntelNo
Windows ServicesXservice2.exeDetected by Sophos as Mal/VB-ZH and by Malwarebytes Anti-Malware as Backdoor.Agent.GenNo
Windows UpdateXservice2.exeDetected by Sophos as Mal/VB-ZH and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
ICU-SuckerXService32.exeDetected by Kaspersky as Trojan-Notifier.Win32.IllNotifier.dNo
Kernel ServicesXservice32.exeAdded by the PRX-B TROJAN!No
Microsoft Service ManagerXservice32.exeAdded by the IRCBOT.WDW BACKDOOR!No
service32Xservice32.exeAdded by the AGOBOT-ST WORM!No
Configuration LoaderXservice5.exeAdded by the GAOBOT.AF WORM!No
MS Security HotfixXservice5.exeAdded by the GAOBOT.AG WORM!No
pushbotXservice52.exeAdded by a variant of the PUSHBOT WORM! A family of worms that spread using MSN MessengerNo
Windows svchostXserviceaaa.exeAdded by the PUSHBOT.ER WORM!No
Windows svchostXserviceam.exeAdded by the PUSHBOT.EY WORM!No
Windows svchostXservicean.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
WinLsassXservicec.exeAdded by the SCANE WORM!No
BredbandsbolagetYservicecenter.exeRelated to the Brebband Swedish Broadband providerNo
serviceconnectXserviceconnect.exeAdded by the AGOBOT.AIR WORM!No
WindowsServicesHXservicedhs.exeAdded by the AGOBOT-JD WORM!No
Microsoft DLL ServiceXservicedll.exeAdded by the IRCBOT.OX BACKDOOR!No
1516b75c7179ba2f46b75e97c37e84fcXservicee.exeDetected by Dr.Web as Trojan.DownLoader8.37194 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJNo
Windows UpdaterXServiceHost.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %Windir%No
servicelayerXservicelayer.exeAdded by the RENOS.FJ TROJAN! Note - do not confuse this with the Nokia service of the same name which resides in %CommonFiles%\PCSuite\Services or %Program Files%\PC Connectivity Solution. This one is located in %Windir%No
Windows Service ExecXServiceLayer.exeAdded by the SPYBOT-OI WORM! Note - do not confuse this with the Nokia service of the same name which resides in %CommonFiles%\PCSuite\Services or %Program Files%\PC Connectivity Solution. This one is located in %Windir%No
USB DeviceXservicelog.exeDetected by Trend Micro as WORM_WOOTBOT.CBNo
Wind Logd FileXservicelogd.exeAdded by a variant of Win32/RbotNo
Service ManagerXSERVICEMGR.EXEAdded by the PASSMAIL-D VIRUS!No
Microsoft Servicez ManagerXservicemgrz.exeAdded by the RBOT-ASN WORM!No
System ServiceXservicent.exeAdded by the RBOT-AJI WORM!No
MicrosoftXP Service Pack 2Xservicepack2.exeAdded by the RBOT.EMC BACKDOOR!No
[various names]XServiceprocess.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
SVEEHOSTXservicesDetected by Malwarebytes Anti-Malware as Backdoor.AgentNo
SVEEHOST.EXEXservicesDetected by Malwarebytes Anti-Malware as Backdoor.AgentNo
WindowsNT ServicesXServices.comDetected by Bitdefender as the DELF.OFC TROJAN! See hereNo
 WinCheckXservices.exeDetected by Symantec as W32.Sober.V@mm and by Malwarebytes Anti-Malware as Email.Worm.SB. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft and note the space at the beginning of the "Startup Item" fieldNo
 WinDataXservices.exeAdded by the SOBER-AD WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\PoolData and note the space at the beginning of the "Startup Item" fieldNo
 WindowsXservices.exeAdded by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\WinSecurity and note the space at the beginning of the "Startup Item" fieldNo
 WinINetXservices.exeAdded by the SOBER.R WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus and note the space at the beginning of the "Startup Item" fieldNo
 WinStartXservices.exeAdded by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Connection Wizard\Status and note the space at the beginning of the "Startup Item" fieldNo
.ProgXservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!No
[random name]Xservices.exePurityScan adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!No
_SystemBootXservices.exeAdded by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help\HelpNo
_WinCheckXservices.exeDetected by Symantec as W32.Sober.V@mm and by Malwarebytes Anti-Malware as Email.Worm.SB. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\MicrosoftNo
_WinDataXservices.exeAdded by the SOBER-AD WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\PoolDataNo
_WindowsXservices.exeAdded by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\WinSecurityNo
_WinINetXservices.exeAdded by the SOBER.R WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatusNo
_WinStartXservices.exeAdded by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Connection Wizard\StatusNo
{357AA41A-B7A8-4632-A27D-5B980B25CF43}Xservices.exeFakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the "inetsrv" subfolderNo
AdRotator.ApplicationXservices.exeFakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the "inetsrv" subfolderNo
Amie Release V6.9DXservices.exeAdded by the VB-EAN TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
AutoAdministratorXSERVICES.EXEDetected by Sophos as W32/Punya-A. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\Application Data\WINDOWSNo
AutoUpdate32Xservices.exeAdded by WINSPY.88! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64No
b60511fd42ef6c7d1c6ac6218d09f059Xservices.exeDetected by Dr.Web as Trojan.DownLoader8.32059 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%No
BaRloNdDiLhepXservices.exeAdded by the AUTORUN.DIB WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolderNo
BuildLabXservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!No
ccAppsXservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!No
ComMessenger32Xservices.exeDetected by Dr.Web as Trojan.PWS.Siggen.40403 and by Malwarebytes Anti-Malware as Backdoor.Agent. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\dataNo
ConfigVirXservices.exeAdded by the AUTORUN-DV WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolderNo
DDXPPXCEXservices.exeDetected by Sophos as Mal/Autorun-AHNo
DHCP32Xservices.exeDetected by Kaspersky as Trojan-Spy.Win32.WinSpy.ag. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\displayNo
execXservices.exeAdded by the AGENT-ZJ MALWARE! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\fontsNo
Flash MediaXservices.exeDetected by Symantec as Backdoor.IRC.Bot. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserTemp%No
FriendlyTypeNameXservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!No
GolumXservices.exeAdded by the GOLUM.A TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!No
golummXservices.exeAdded by the DLOADER-ET TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "golumm" subfolderNo
KernelXservices.exeAdded by the FOOZ-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
LiveUpdate32Xservices.exeAdded by the VB.BAU BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isasNo
Local ServiceXservices.exeAdded by the P2PWORM-T WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\CursorsNo
Microsoft (R) Windows Protected Content Restoration ServiceXservices.exeDetected by Trend Micro as BKDR_AGENT.AGV. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\etcNo
Microsoft (R) Windows TCP/IP Socket LayerXservices.exeAdded by the RBOT.ARM BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\winsockNo
Microsoft Service ControllerXservices.exeAdded by the KALEL-D WORM! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!No
Microsoft ServicesXservices.exeAdded by the ALETS TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
Microsoft UpdatXservices.exeAdded by the MSIL.ELASROFAH TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Internet ExplorerNo
Microsoft Visual SourceSafeXservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!No
Microsoft WindowsXservices.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
Microsoft Windows Update ClientXservices.exeAdded by the AUTORUN.DVE WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
MicrosoftsXservices.exeDetected by Dr.Web as Trojan.Inject.62622. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\MicrosoftsNo
MSN32Xservices.exeDetected by McAfee as Generic PWS.y. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msappsNo
MSOfficeXservices.exeAdded by the DLOADER-EU TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an "MSOffice" subfolderNo
msservicesXservices.exeMsnSpyMaster surveillance software. Uninstall this software unless you put it there yourself! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an "msystem" sub-directoryNo
MSWUpdateXservices.exeAdded by the VB-FDP TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
NetXservices.exeAdded by the BRAVO-C TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
Norton Auto-ProtectXSERVICES.exeAdded by the AHKER.B WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%. Also, this is not part of Norton AVNo
NTSet32Xservices.exeAdded by the WINSPY-C TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\dll32No
PagefileManagerXservices.exeDetected by Dr.Web as BackDoor.Poison.9892 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\Pagefile System VolumeNo
RegDoneXservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!No
RPCser32gXservices.exeAdded by the RITDOOR-C WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
RPCser32g1Xservices.exeAdded by the PREX.D WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
RPCser32g3Xservices.exeAdded by the PREXOT.D BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
RPCser32g4Xservices.exeAdded by the PREXOT.E BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
RPCserv32Xservices.exeAdded by the MYDOOM.AL WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
RPCserv32gXSERVICES.EXEDetected by Trend Micro as WORM_BOBAX.AD. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
runXservices.exeDetected by Sophos as Troj/Krepper-N and variants and by Malwarebytes Anti-Malware as Trojan.Downloader. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\inet10066No
runservicesXservices.exeDetected by McAfee as BackDoor-DUM. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
scssrr.exeXServices.exeAdded by the VB-EMX TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
Service<user>XSERVICES.EXEDetected by Sophos as W32/Brontok-BH. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%\WINDOWSNo
ServiceAdministratorXSERVICES.EXEDetected by Symantec as W32.Korron.B. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%\WINDOWSNo
SERVICEADMINISTRATOR.[ComputerName]XSERVICES.EXEDetected by McAfee as Generic VB.i and by Malwarebytes Anti-Malware as Trojan.FakeAlert. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%\WINDOWSNo
ServiceControlAppXservices.exeDetected by Symantec as W32.SillyFDC.BDO. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%No
ServiceeXservices.exeAdded by the AGENT.DEI TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
Servicerepclient1XSERVICES.EXEDetected by Sophos as W32/Brontok-BT and variants! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%\WINDOWSNo
ServicesXservices.exeAdded by a number of VIRUSES, WORMS and TROJANS! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup!No
servicesXServices.exeDetected by Malwarebytes Anti-Malware as Worm.Spambot. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\1C110F2ANo
servicesXservices.exeDetected by Dr.Web as Trojan.DownLoader6.3759 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\MicrosoftNo
ServicesXServices.exeDetected by Symantec as Trojan.Syginre. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
Services Control ManagerXservices.exeAdded by the DELF-CGI TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!No
Services ControllerXservices.exeAdded by the CIADOOR-F TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
Services LogonXservices.exeDetected by Symantec as W32.Crowt.A@mm. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Templates%No
Services NetworkXServices.exeAdded by the SWISYN-E WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!No
Services ProcessXservices.exeSpyware - detected by Kaspersky as the SMALL.X TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!No
Services StartupXservices.exeAdded by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %CommonFiles%No
services.exeXservices.exeDetected by Malwarebytes Anti-Malware as Trojan.VBKrypt. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% and loads from the HKLM\Run keyNo
Services.EXEXservices.exeDetected by Symantec as W32.HLLW.Kazping. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% and loads from the HKLM\Run & HKLM\RunServices keysNo
Services++Xservices.exeAdded by the SILLYFDC.BDM WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\RECYCLERNo
ServicesAdministratorXSERVICES.EXEDetected by Sophos as W32/Punya-B and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%\WINDOWSNo
ServicesaraXservices.exeDetected by Sophos as W32/Brontok-BS and by Malwarebytes Anti-Malware as Backdoor.Agent. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%\WINDOWSNo
Spooler de ImpressXservices.exeAdded by the AGENT-NEX TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %User%No
sservicesXservices.exeSpyOnePro spyware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\sopdirNo
SuperBar.ComponentXservices.exeAdded by the SMALL-AQ TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the "inetsrv" subfolderNo
sysinitXservices.exeAdded by the NEWLFRM-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\golummNo
SysServiceUSERVICES.EXENSKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\NSkeyloggerNo
SysServicesXSERVICES.EXEAdded by the DELF-EY TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
systemXservices.exeAdded by the DELF-LQ TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\HELPNo
System Update2Xservices.exeDetected by Sophos as Troj/Autotroj-C. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!No
SystemBootXservices.exeAdded by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help\HelpNo
SystemCheckXservices.exeAdded by the SOBER-M WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Config\systemNo
TaskhostXservices.exeDetected by Dr.Web as Trojan.Packed.23496 and by Malwarebytes Anti-Malware as Trojan.Buterat. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
TEXTCONVXservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!No
Torjan ProgramXservices.exeAdded by the AUTEX.C WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
ttplayXservices.exeDetected by Malwarebytes Anti-Malware as Trojan.ChinAd. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %CommonFiles%\TencentNo
upDpacketoXservices.exeDetected by Sophos as W32/Nafbot-A and by Malwarebytes Anti-Malware as Worm.P2P. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
WinCheckXservices.exeAdded by the SOBER.S WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\MicrosoftNo
WindowsXservices.exeAdded by the DLOADR-GW TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "Windows" subfolderNo
WindowsXservices.exeAdded by the SOBER-Z WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\WinSecurityNo
Windows DesktopXservices.exeAdded by the DWNLDR-JAN TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
Windows Logon ApplicationXservices.exeAdded by the CIADOOR-L TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
Windows ServiceXservices.exeDetected by Sophos as W32/Kalel-A. Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!No
Windows Service ControllerXservices.exeAdded by the KALEL-B WORM! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!No
Windows Service HostXservices.exeDetected by Sophos as Mal/Autorun-BB and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\microsoftNo
Windows ServicesXservices.exeDetected by Sophos as Troj/Agent-MVC and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
WINDQ32_TRLVXservices.exeDetected by McAfee as Generic VB.z and by Malwarebytes Anti-Malware as Trojan.Downloader. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Winqows PublrlvNo
winsrv3Xservices.exeDetected by Sophos as W32/Nafbot-A and by Malwarebytes Anti-Malware as Worm.P2P. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
WMAudioXservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!No
WSVCSUSERVICES.EXEWSLogger keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a WALI\SVCS sub-directoryNo
xp_systemXservices.exeDetected by Sophos as Troj/Krepper-N and variants and by Malwarebytes Anti-Malware as Trojan.Downloader. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The one is located in a %Windir%\inet***** - where ***** varies dependent upon the variant, examples are 10066, 20001, 20088No
xpsystemXservices.exeCoolWebSearch parasite variant. Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!No
XpsystemXSERVICES.EXEAdded by the DAEMOZ.A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\SERVICESNo
ServiceXservices.exe -servAdded by the NETSKY or NETSKY.B WORMS! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
Windows StartupXservices21.exeAdded by the AGOBOT-MX WORM!No
Microsoft System DebugXservices32.exeDetected by Trend Micro as WORM_RBOT.AKHNo
Sygate Personal Firewall StartXservices32.exeAdded by the RBOT-MB WORM!No
system32.exeXservices32.exeAdded by a variant of the IRCBOT TROJAN!No
Win ServicesXServices32.exeAdded by the SYGINRE TROJAN!No
Wins Update 32Xservices32.exeAdded by the FORBOT-FN WORM!No
System33Xservices33.exeAdded by the RBOT-VQ WORM!No
MSNXservices51651.exeAdded by the IRCBOT-AAL TROJAN!No
win32servXservicesetup.exeAdded by a variant of the PUSHBOT WORM! A family of worms that spread using MSN MessengerNo
ServicesNotifyUServicesNotify.exeDefender Pro AntispyNo
Configuration LoaderXServicess.exeDetected by Symantec as W32.HLLW.Gaobot.AONo
HKCUXServicess.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\installNo
PoliciesXServicess.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\installNo
services.exeXservicess.exeAdded by the MSNSPY-B TROJAN!No
capricornXservicest.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.CPR. The file is located in %ProgramFiles%\D360SHADSYSNo
servicestub.exeXservicestub.exeAdded by the RBOT.CN BACKDOOR!No
Camra UpdatesXserviceswu.exeDetected by Trend Micro as WORM_RBOT.BPQNo
usbdrvXservicetask.exeAdded by a variant of the SDBOT BACKDOOR!No
PoliciesXServiceUpdate.exeDetected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.Agent.PGenNo
TestXServiceUpdate.exeDetected by McAfee as Generic.bfrNo
Microsoft Update MachineXservicez.exeAdded by the SPYBOT.BI WORM!No
Serices HostinXservicez.exeAdded by the SLENFBOT.MF WORM!No
System ServiceXservicez.exeAdded by the RBOT-AOY WORM!No
Windows ServicesXservicez.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.Gen. The file is located in %Windir%No
servicoXservico.exeAdded by the BANKER-DKE TROJAN!No
ASP.NET State ServiceXservicos..exeAdded by the DADOBRA-I TROJAN!No
servicsXservics.exeAdded by the SINGU-J TROJAN!No
k3ym4nXservicsmjr.exeAdded by the RBOT-RW WORM!No
Microsoft Update MachineXservicz.exeAdded by the RBOT-HU WORM!No
ryan1918Xservidevice.exeAdded by the RBOT-GVR WORM!No
serviecaXservieca.vbeDetected by Dr.Web as Trojan.DownLoader8.16780 and by Malwarebytes Anti-Malware as Trojan.Banker. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
servieca.vbeXservieca.vbeDetected by Dr.Web as Trojan.DownLoader8.16780 and by Malwarebytes Anti-Malware as Trojan.BankerNo
Windows Server InformationXservinfo.exeAdded by the FORBOT-EN WORM!No
ashcapXservirsess.exeSpySure spywareNo
NvCplDeamonXservise.exeAdded by the AUTORUN-BNY WORM!No
Windows ServserXserviser.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
servisesXservises.exeDetected by Sophos as Troj/Agent-JUJNo
WINDOWS SYSTEMXservises.exeAdded by the ZOTOB-I WORM!No
Microsoft Update MachineXserviz.exeAdded by a variant of the RBOT WORM!No
MicroUpdateXservizi.exeDetected by McAfee as Generic Dropper and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
serviziXservizi.exeDetected by McAfee as RDN/Generic Dropper!ga and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
SERVlCEXSERVlCE.EXEAdded by the AGOBOT-UB WORM!No
SVCHOSTXSERVlCES.EXEAdded by the DELF-LF BACKDOOR! Note that the filename has a lower case "L" in place of an upper case "i"No
Server Application for MFP ServerYServoApp.exeMulti Function Printer (MFP) server agent for products such as Belkin's Wireless G All-in-One Print Server and ZyXEL's NPS-520 which allow multiple computers to use networked all-in-one printers. Required for the MFP Server Agent (MFPAgent.exe) to run properly - whether it's set to start manually or automaticallyYes
ServoAppYServoApp.exeMulti Function Printer (MFP) server agent for products such as Belkin's Wireless G All-in-One Print Server and ZyXEL's NPS-520 which allow multiple computers to use networked all-in-one printers. Required for the MFP Server Agent (MFPAgent.exe) to run properly - whether it's set to start manually or automaticallyYes
Windows USB MonitorXservupdate.exeAdded by the IRCBRUTE.AQ TROJAN!No
ServUTrayIconNServUTray.exeSystem Tray access for the Serv-U FTP server which allows the user to (amongst others) start the Management Console, stop the server and display notificationsNo
SystemXserwin.exeAdded by the LDPINCH-BN TROJAN!No
Session ClientUsescli.exeSurfSpy keystroke logger/monitoring program - remove unless you installed it yourself!No
sctrlmgrXsescmgr.exeAdded by the SDBOT.CNS BACKDOOR!No
SystemsXsescmgr.exeAdded by the DWNLDR-GAH TROJAN!No
Driver Control Manager v8.1Xsesdessetri.exeAdded by the ZXC-Q TROJAN!No
PPK Setup(Server)USEServe.exeProgrammable Power Key on Sony Vaio laptops. "Using the Programmable Power Key (PPK) button, collect your e-mail automatically with one key stroke. You can also program your PPK to turn on your SuperSlim Notebook at a predetermined time and perform simple tasks - completely unattended"No
Driver Control Manager v7.7Xsesnaesttoo.exeAdded by the AUTOINF-CU WORM!No
Windows NT Session ManagerXsess.exeAdded by a variant of Win32/RbotNo
irc sessionXsessionmgr.exeAdded by the SDBOT-ACE WORM!No
QWS3270 SessionsUsessions.exeQWS3270 Secure terminal emulation softwareNo
SessMgrXsessmgr.exe /waitserviceDetected by Microsoft as TrojanDownloader:Win32/Horst.Q. Note - this is not the legitimate sessmgr.exe which is always located in %System%. This one is located in either %Windir%, %Windir%\System, %Temp%, %AppData%, %AppData%\Microsoft or %System%\driversNo
SES ServiceXsesvc.exeAdded by the SDBOT-CZU WORM!No
HPLJ ConfigYSetConfig.exeConnects system to networked HP printer.No
Update local?SetCPQLC.exeRunning on a Compaq desktop. Any ideas?No
Microsoft ActiveX Debugger NTXsetdebugnt.exeAdded by the BANCOS-DO TROJAN!No
Microsoft« ActiveX Debugger NTXsetdebugnt.exeAdded by the BANCOS-CZ TROJAN!No
setdefprtNsetdefprt.exeUsed to set a Brother MFC printer/copier/scanner as the default printer after installationNo
UniPrintUSetDfltSettings.exeDrivers for Uniprint, a printing help for Terminal Services and Citrix which recieves downloaded files from a Uniprint enabled server and prints them locally allowing for truly universal printing through Terminal Services or CitrixNo
Microsoft SetDLL32Xsetdll32.exeAdded by the RBOT.OZ WORM!No
GammaHotKeysUsetgamma.exePart of the RadeonTweaker program for adjusting ATI Radeon graphics cards. Allows you to adjust the gamma (or brightness) when playing a full-screen game without switching back to the desktopNo
MediaFace IntegrationNSethook.exeFellowes Neato® cd label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar"No
SetHookNSethook.exeFellowes Neato® cd label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar"No
SETI@homeNSETI@home.exeSETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope dataNo
seticlientNSETI@home.exeSETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope dataNo
SetIconNSetIcon.exeInstalled by a 6-in-1 (4 Media Card slots, a floppy drive and a USB connection) device. Constantly updates the icons for the four Media Card slots that it has and is a resource hogNo
setingsc.exeXsetingsc.exeDetected by McAfee as Generic VB.i and by Malwarebytes Anti-Malware as Trojan.BankerNo
SetiQueueNSetiqu~1.exeProvides work unit buffering for Seti@Home clients - see here for more detailsNo
SetiSpyNSetiSpy.exeSETI Spy is a little program to "spy" on the progress and performance of the SETI@home client. Called a "spy" because it is unobtrusive as possibleNo
EDRestoreUSetpoint.exeSet Point from Easy Desk Software - "small utility that automatically sets System Restore points for WinME/XP"No
EvtMgr6USetpoint.exeLogitech SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice, trackballs, etc). Required if you want to use the advanced features, modify the default settings or be notified of low battery status (for wireless devices). Located in %ProgramFiles%\Logitech\SetpointYes
Logitech SetPointUSetpoint.exeLogitech SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice, trackballs, etc). Required if you want to use the advanced features, modify the default settings or be notified of low battery status (for wireless devices). Located in %ProgramFiles%\Logitech\SetpointYes
SetPointXSetPoint.exeAdded by the RBOT-BWI WORM! Note - this is not the valid Logitech Setpoint mouse and keyboard entry that uses the same filename and is located in %ProgramFiles%\Logitech\Setpoint or Set Point from Easy Desk Software which is located in %ProgramFiles%\Easy Desk Utilities\Set Point. This one is located in %System%No
SetPointUSetpoint.exeLogitech SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice, trackballs, etc) - required if you want to use the advanced features or modify the default settings of these devices and located in %ProgramFiles%\Logitech\Setpoint. Or Set Point from Easy Desk Software - a "small utility that automatically sets System Restore points for WinME/XP" which is located in %ProgramFiles%\Easy Desk Utilities\Set PointYes
Microsoft UpdateXSetPoints.exeAdded by a variant of the IRCBOT BACKDOOR!No
SetRefreshUSetRefresh.exeFound on some Compaq & HP PCs. SetRefresh is a utility which attempts to optimize the monitor's refresh rate, and in some cases the resolution, for the best user experience. See "here for more infoNo
settdebugx.exeXsettdebugx.exeAdded by the FAKEAV.SMSS TROJAN!No
hao123SettingXSetting.exeDetected by Dr.Web as Trojan.StartPage.51763 and by Malwarebytes Anti-Malware as Trojan.StartPageNo
settingXsetting.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %LocalAppData%No
JAVAXsettings.exeDetected by Malwarebytes Anti-Malware as Trojan.Inject. The file is located in %AppData%\JavaNo
Logitech Desktop MessengerNsetup-8876480.exeInstaller for Logitech Desktop Messenger included with older versions of the software for Logitech products - which automatically checks for software upgrades and new products, services and special offers from LogitechNo
30fa035dbe87c6e209452c1147d1cdb9Xsetup.exeDetected by Dr.Web as Trojan.DownLoader7.6835 and by Malwarebytes Anti-Malware as Trojan.MSILNo
bf8feb67afc2238269222493247f1c23XSetup.exeDetected by McAfee as Generic.dx!bh3h and by Malwarebytes Anti-Malware as Trojan.MSILNo
chromeXsetup.exeDetected by Malwarebytes Anti-Malware as Trojan.StartPage.AI. Note - this is not a legitimate file for the Google Chrome browser and it is located in %Windir%No
InstallNAIProduct?SETUP.EXECould be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error?No
MCAFEEIPSXsetup.exeAdded by the WHITEWELL TROJAN!No
MM Install?setup.exePossibly Money Manager from Moneysoft?No
MyVBAppXsetup.exeDetected by Kaspersky as the Trojan-Dropper.Win32.VB.kb. The file is located in %Root%No
RjLyraInstaller?setup.exe??No
ServiceApplicationXSetup.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Root%\Users\Public\Pictures\Sample PicturesNo
setupXsetup.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence here ensures it runs when Windows startsNo
setup.exeXsetup.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %AppData% and %UserStartup% and its presence there ensures it runs when Windows startsNo
setup.exeXsetup.exeDetected by Sophos as Troj/Goldun-GB. The file is located in %Windir%No
SigmaTel AudioNsetup.exeSigmatel audio driverNo
SkypeXSetup.exeDetected by Malwarebytes Anti-Malware as Trojan.Hijacker.URL. Note - this is not a legitimate entry for the popular Skype VOIP software and the file is located in %UserTemp%No
Sweep95YSETUP.EXEPart of an older version of Sophos anti-virus softwareNo
Tango?Setup.exeTango Broadband access software. Is it required?No
WindowsXsetup.exeDetected by Dr.Web as Worm.Siggen.6969 and by Malwarebytes Anti-Malware as Trojan.AgentNo
Windows AcceleratorsUsetup.exeKeySpy keystroke logger/monitoring program - remove unless you installed it yourself!No
zzzhpsetup?setup.exe??No
zzzCamlnSuitelll?setup.exe 46***??No
OESETXsetup60.exeDetected by AhnLab as Win-Trojan/Warezdl.28672No
HighspeeddownloaderXSetupClickHere.EXEHomepage hijacker, redirecting to "turbo-search101.com" - see hereNo
C:\WINDOWS\system32\SetupCmd.exeXSetupCmd.exeDetected by Kaspersky as the AGENT.AAW TROJAN!No
[various names]XSetupExeDll.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
MemConfigXSetupIE.comAdded by the TAPLAK WORM!No
shareXsetupmsxs.exeDetected by McAfee as Generic.bfr!cvNo
explorerXsetupsvc.exeDetected by McAfee as Generic VB.i and by Malwarebytes Anti-Malware as Trojan.DropperNo
setupsvcs.exeXsetupsvcs.exeDetected by McAfee as Generic.bfr!cvNo
setupwid.exeXsetupwid.exeDetected by McAfee as Generic VB.i and by Malwarebytes Anti-Malware as Spyware.BankerNo
win32XSetup_32.exeAdded by the EVILBOT.B TROJAN!No
NI.UGESU_0001_N122M0303Xsetup_de.exeInstaller for the SysKontroller rogue security software - see hereNo
NI.UGES_0001_N108M2006Xsetup_en.exeInstaller for the MyContentAssistant rogue privacy toolNo
NI.UGEST_0001_N122M0303Xsetup_it.exeInstaller for the SysLibero rogue security software - see hereNo
setuzp?setuzp.exe??No
_SetvXSetv.comAdded by the BESAM WORM!No
Windows secureXsetver32.exeDetected by Trend Micro as WORM_SPYBOT.EPNo
SetVrcXsetvrc.exeAdded by the HUNTOCX WORM!No
Sysctrls32Xsevchost.exeAdded by the RBOT.ADF BACKDOOR!No
SevenUpXsevenup.exeAdded by the DELF TROJAN!No
(Default)Xsever.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %Windir%\SHELLNEWNo
360[foreign characters]Xsever.exeDetected by Dr.Web as Trojan.PWS.Gamania.38730 and by Malwarebytes Anti-Malware as Backdoor.Agent.SNNo
alligtXsevere.exeAdded by the SLURK.A WORM!No
jusodlXsevere.exeAdded by the QQPASS.48436 TROJAN!No
Configuration ServecieXsewins.exeAdded by the SDBOT-COH WORM!No
2880e9d41a6a19b545538f21ddb48fa2Xsex me.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserTemp%No
eda912e4c272fd6ecf04f273e3f1b428Xsex.exeDetected by Dr.Web as Trojan.DownLoader7.21112 and by Malwarebytes Anti-Malware as Backdoor.BotNo
hsimXsexgame.exeUnidentified malwareNo
SexnowXSexnow.exeAdded by the SENOW-B premium rate adult content diallerNo
Sygate Personal FirewallXsexy.exeAdded by the RBOT-XY WORM!No
c828544720dd92f1c08f71a9bce7a42dXSexy22.exeDetected by Dr.Web as Trojan.DownLoader8.37112 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJNo
LOFUTDSXsexyfr.exeDetected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.AgentNo
LOVEFSDXsexyfr.exeDetected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.AgentNo
ULOVEJFXsexyfr.exeDetected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.AgentNo
SystemTasksXsexypicz.exeAdult content diallerNo
Sexy_BlondesXSexy_Blondes.exePremium rate adult content dialler - see hereNo
Sexy_sgXSexy_sg.exePremium rate adult content diallerNo
sfXsf.exeSurfEnhance adwareNo
Safeguard 2009Xsf2009.exeSafeguard 2009 rogue spyware remover - not recommended, removal instructions hereNo
Snappy FaxNsf4.exeSnappy Fax desktop fax program with an extensive set of features - version 4No
SPAMfighter AgentUSFAgent.exeSPAMfighter anti email spam filterNo
cftmonXsfcmonit.exeAdded by a variant of the AGENT.ERG TROJAN!No
MSConfigXsfcmtmaf.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% - see hereNo
HotKeyXSFCsrvc.pifAdded by the AUTOIT-OC WORM!No
Files DriverXsfdhost.exeAdded by the AGOBOT-AJC BACKDOOR!No
Audio Device ManagerXsfhgj.exeAdded by the IRCBOT-ZA BACKDOOR!No
SFIGUINSFIGUI.EXESonic Focus - "enhances music, movie and game sound by analyzing compressed audio streams in realtime, then restoring and enriching audio back to its original performance qualities"No
SonicFocusNSFIGUI.EXESonic Focus - "enhances music, movie and game sound by analyzing compressed audio streams in realtime, then restoring and enriching audio back to its original performance qualities"No
sfitaXsfita.exeAdded by the FAVADD-H TROJAN!No
mssfosXsfool.exeAdded by the RANDEX.EUS WORM!No
Snappy Fax Printer Agent?sfpagent.exeRelated to the Snappy Fax desktop fax program. What does it do and is it required?No
Snappy Fax Printer virtual printer agent?sfpagent.exeRelated to the Snappy Fax desktop fax program. What does it do and is it required?No
sfpcUsfpc.exeSpy4PC surveillance software. Uninstall this software unless you put it there yourselfNo
srMaEKdMpIEyiFifcXsFpoAkPxnMmSYBXjD.exeDetected by Sophos as Troj/Mdrop-EVT and by Malwarebytes Anti-Malware as Backdoor.AgentNo
Microsoft PC Health Remote Assistance File Open & Save controlsXsfrcdlg32.exeAdded by the RBOT-AVY WORM!No
SoftGridTrayUSFTTray.exeSystem Tray access to SoftGrid from Microsoft - "the only virtualization solution that delivers applications that are never installed and dynamically delivered, on demand"No
SfWinStartInfoUsfWinStartupInfo.exeSFIRM32 Online Banking softwareNo
smXsf_exe.exeAdded by the OLFEB.A TROJAN!No
SgecryptYSGECRYPT.exeSafeGuard Easy from Sophos (formerly by Utimaco) - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks"No
Microsoft UpdateXsghost.exeAdded by the SDBOT.AKV WORM!No
sginstUsginst.exeeAcceleration Stop-Sign security software related - previously not recommended (see here). It has now been delisted, so make sure you have the latest version - hence the "U" recommendationNo
sgkAJEXsgkAJE.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor.XTR. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
SpywareGuardYsgmain.exe"SpywareGuard provides a real-time protection solution against spyware"No
Screen Guard Message ScanUsgms.exePart of Access Denied security and privacy softwareNo
MSRegScanUSGP.exeSpyGator surveillance software. Uninstall this software unless you put it there yourselfNo
SGPUpdaterXsgpUpdaters.exeFast Browser Search/Search Guard Plus parasite - installed with "Make the Web Better" applications such as My Web Tattoo, My Face LOL and Google Easy Money Kit. See here and here for more informationNo
SyGateServiceUsgserv95.exeSyGate is a useful little program that lets you share an internet connection over an intranet. Is it needed - it saves a lot of headache to just let SyGate load at startup. Available via Start → ProgramsNo
SGTBox?SGTBox.exeCanon scanner driver. Is it required?No
sgtrayUsgtray.exeStorageGuard from Veritas (now Symantec). Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backupsNo
StorageGuardUsgtray.exeStorageGuard from Veritas (now Symantec). Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backupsNo
StoreGridYSGTray.exeSystem Tray access to StoreGrid online backup and data protection software from Vembu Technologies Pvt. Ltd. Required for scheduling to workNo
UpdateManagerUsgtray.exeStorageGuard from Veritas (now Symantec). Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups. This version by SonicNo
Security GuardXSG[random characters].exeSecurity Guard rogue security software - not recommended, removal instructions hereNo
shell32.dllXsh32.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.SHGen. The file is located in %System%No
WindowsMNGXShades.exeDetected by Dr.Web as Trojan.DownLoader4.16266 and by Malwarebytes Anti-Malware as Backdoor.MessaNo
ShadowYShadow.exe"NTI Shadow 3 is an award-winning easy-to-use backup application that automatically protects your photo, music, video, and various data files. It makes data restoration as easy as dragging and dropping files from one place to another"No
hp center UINShadowBar.exeUser Interface for HP Center - see the BACKWEB-******.exe entryNo
ShadowUser Pro EditionUShadowUser.exeStorageCraft ShadowUser™ "provides easy to use desktop security and protection for Windows operating systems. ShadowUser is the best way to prevent unwanted changes to PCs and laptops." No longer available - see hereNo
[various names]XShaitan1678.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
CorpFireXShakar.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %ProgramFiles%No
CorpSoftXShakar.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %ProgramFiles%No
win32XShakira_1997_Part_1_.Mpeg_.scrAdded by the MYLIFE.N WORM!No
load=Xshambl3r.exeAdded by the REMABL WORM!No
shambl3r*Xshambl3r.exeAdded by the REMABL WORM! where * is 2 to 11No
(Default)XShania.vbsAdded by the SHANIA BACKDOOR! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
SHAProcXSHAProc.exeAdded by the WINKO.AO WORM!No
ShareazaNShareaza.exeShareaza P2P clientNo
ShareBoxXShareBoxC.exeDetected by AVG as OpenShopper.A and by Malwarebytes Anti-Malware as Adware.K.ShareBox. The file is located in %ProgramFiles%\ShareBoxNo
Parallels Shared Internet Applications?sharedintapp.exePart of Parallel Tools utility suite for guest operating systems included with virtualization software from Parallels - such as Parallels WorkstationNo
SharedInternetApplication?sharedintapp.exePart of Parallel Tools utility suite for guest operating systems included with virtualization software from Parallels - such as Parallels WorkstationNo
sharedpremXsharedprem.exeAdded by the MAKECALL TROJAN!No
SharpTrayUSharpTray.exePart of the Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents"No
[various names]Xshch.exePremium rate adult content diallerNo
MsnExplorerXshch.exeDetected by Sophos as Troj/Bdoor-EBNo
NeroXshch.exePremium rate adult content diallerNo
QuicktimeXshch.exePremium rate adult content diallerNo
ScheduIeXshch.exeAdded by a variant of Troj/Bdoor-EBNo
ScheduIrXshch.exeAdded by a variant of Troj/Bdoor-EBNo
SheduIerXshch.exeDetected by Sophos as Troj/Bdoor-EBNo
SvcH0stXshch.exeDetected by Sophos as Troj/Bdoor-EBNo
WinAmpAgentXshch.exeDetected by Sophos as Troj/Bdoor-EBNo
WIN_DRIVR32Xshchostv.exeAdded by a TROJAN - see hereNo
ShellCommandXshcmp32.exeAdded by the REMCON-A TROJAN!No
shdefXshdef.exeAdded by the VB-DVS TROJAN!No
FHPageXshdochp.exeAdded by the WINHOUND TROJAN!No
FHStartXshdocsvc.exeAdded by the WINHOUND TROJAN!No
Windows Service ProcessorXshdocvw.exePcPrivacyCleaner rogue security software - not recommendedNo
frguk?shdrkmck.exe??No
UPDATEXsheikh dark final v2.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData%No
(Default)XShell.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor.ZE. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %System%No
Office Source EngineXshell.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserTemp%No
Shell.exeXShell.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserTemp%No
Shell.exeXShell.exeDetected by Trend Micro as WORM_EMERLEOX.S and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System%No
Windows ShellXshell.exeAdded by the MYTOB-CA WORM!No
WOOKIT?Shell.exe appLaunchClientZone.shlRelated to the Wanadoo broadband ISP (now rebranded as Orange). What does it do and is it required?No
Shell32.dllXshell32Detected by Kaspersky as Backdoor.Win32.DarkKomet.eku and by Malwarebytes Anti-Malware as Backdoor.Agent.DCRSAGenNo
Secure32XShell32.com StartUpAdded by the BRONTOK-CJ WORM!No
defaultXshell32.exeAdded by the BINGHE TROJAN!No
LTSMSGXShell32.exeAdded by the LEMIR.B TROJAN!No
ROOT2Xshell32.exeDetected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %Windir%\systemNo
ShellXShell32.exeAdded by the BADSECTOR TROJAN!No
Shell32.exeXShell32.exeDetected by Dr.Web as Trojan.DownLoader5.11870 and by Malwarebytes Anti-Malware as Backdoor.HupigonNo
Shell32XShell32.vbsAdded by the SCAFENE WORM!No
Shellapi32XShellapi32.exeAdded by the NETDEVIL (or NERTE.76.B) BACKDOOR!No
MicrosoftShellXShellcomm.exeDetected by Sophos as Troj/Bancban-QGNo
ShelldaemonXShelldaemon.exeAdded by a variant of the AGENT.ALN TROJAN!No
wesspellXshelldm.exeAdded by the LETHIC TROJAN!No
ShellExXShellEx.exeAdded by the ANAKHA TROJAN!No
SMSERIALWORKERSTARTXshellexcon.exeAdded by the FAKEALERT-AH TROJAN! Installed with the SpyBurner spyware remover - which is not recommended, see hereNo
shell updateXshellexec.exeAdded by the RBOT-ANC WORM!No
ExplorerXshellexp.exeAdded by the AGENT-ZY TROJAN!No
ExplorerXshellexpl.exeAdded by the SHELDOR TROJAN!No
ShellApiXSHELLMSN.EXEAdded by the NETDEV.B BACKDOOR!No
shellsystemXshellsystem.exeAdded by the UPCHAN TROJAN!No
Shell Tray WindowXShellTraywnd.exeAdded by the STULTDOR-A TROJAN!No
W5SHFAXshfacvs.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.FA. The file is located in %AppData%\sdchfaNo
Microsoft® Windows® Operating SystemXshfusion.exeDetected by Sophos as Mal/Agent-AIP and by Malwarebytes Anti-Malware as Backdoor.MessaNo
shginaXshgina.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%\shginaNo
shhostXshhost.exeAdded by the AGENT.CE BACKDOOR!No
shicoxpNshicoxp.exeInstalled with the drivers for multi card readers of various brands. To differentiate between the various card slots on multi slot readers the shicoxp.exe file assigns and loads unique drive icons for the various card slots that are displayed in Windows ExplorerNo
Shield SecurityXshield.exeAdded by a variant of Backdoor.Rizo.A. The file is located in %System%\ComNo
SpyWare ShieldUShield.exeAcronis Privacy Expert Spyware Shield prevents spyware and other suspicious programs from being installed on PCsNo
Shield32 SecurityXshield32.exeAdded by a variant of Backdoor.Rizo.A. The file is located in %System%\ComNo
media playerXshield32.exe.exeDetected by Kaspersky as Trojan.Win32.VB.qnz. The file is located in %System%\adobe ActiveXNo
msnmsgerXshield32.exe.exeDetected by Kaspersky as Trojan.Win32.VB.qnz. The file is located in %System%\adobe ActiveXNo
Windows ExplorerXshield32.exe.exeDetected by Kaspersky as Trojan.Win32.VB.qnz. The file is located in %System%\adobe ActiveXNo
ShieldSafenessXShieldSafeness.exeShieldSafeness rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
MilShieldSlaveUShieldWorker.exeMil Shield from Mil Incorporated. It protects your privacy by removing all tracks from your online or offline computer activitiesNo
ShineXShine.exeAdded by the HAPPYLOW (or NISHE-A) VIRUS!No
TigerXShine.exeAdded by the HAPPYLOW (or NISHE-A) VIRUS!No
SHINITV?shinitv.exe??No
Run RunOnceNShipUPS.EXEOlder version of the UPS WorldShip utility used to create and manage your UPS shipmentsNo
gameXshit.exeAdded by the Netclap Gold backdoor TROJAN!No
TESTNAME.EXEXshit.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%\windirNo
WinSrvXSHIZZLE.EXEDetected by Trend Micro as WORM_HOBBIT.CNo
ShortKeys LiteUshklite.exeShortKeys Lite from Insight Software Solutions, Inc. A macro utility to automate a task that you perform repeatedly or on a regular basisNo
shellbnXshlext32.exeMalware installed by different rogue security software including SpyKillerPro and the XP AntiVirus seriesNo
MSOfficeCfgXshman.exePremium rate adult content dialerNo
NAVCheckXshman.exePremium rate adult content dialerNo
QTSvcXshman.exePremium rate adult content diallerNo
SystemServiceXshman.exePremium rate adult content diallerNo
paint.exeXshnlog.exeAdded by the PUPER-A TROJAN!No
SAHBundleXshop1003.exeShopAtHomeSelect parasiteNo
shopbaconXshopbacon.exeDetected by Malwarebytes Anti-Malware as Adware.K.ShopBacon. The file is located in %ProgramFiles%\shopbaconNo
ShopSafeNShopSafe.exeCreated by Orbiscom for MNBA (now Bank of America) - ShopSafe creates a temporary card number each time you make an online purchaseNo
Shop To WinXShopToWin.exeJackpotRewards.ShopToWin adwareNo
ShoreTel Personal Call ManagerUShoreTel.exeShorTel Personal Call Manager - allows you to "use your PC or laptop to manage voice communications with co-workers, customers and business associates"No
ShortKeys 99NSHORTKEY.EXEShortKeys from Insight Software Solutions - allows you to program keys with text stringsNo
hellodollyXshost.exeAdded by the YODO WORM!No
rpc Win32Xshost32.exeAdded by the RBOT-ABL WORM!No
shosts..exeXshosts..exeDetected by McAfee as Generic Downloader.x!fza and by Malwarebytes Anti-Malware as Trojan.FakeMSNo
shostss..exeXshostss..exeDetected by Malwarebytes Anti-Malware as Malware.Packer.T. The file is located in %UserProfile%\IENo
shotjumbXshotjumb.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %AppData%\shotjumbNo
sHotKeyYsHotKey.exeSpecial function key manager for Chicony keyboards - see hereNo
ShottyNShotty.exeShotty by Thomas Baumann - "is an application to take pictures from your computers screen (called screenshots) or from one application only. Unlike other applications that does this Shotty provides various other features that are useful to modify the taken screenshot"Yes
Shotty - Tiny but impressive screenshot utilityNShotty.exeShotty by Thomas Baumann - "is an application to take pictures from your computers screen (called screenshots) or from one application only. Unlike other applications that does this Shotty provides various other features that are useful to modify the taken screenshot"Yes
ShowBatteryBarUShowBatteryBar.exeBatteryBar by Osiris Development - "is a simple, straight-forward, battery meter that monitors the status of your battery and displays your battery's status in the taskbar"No
ShowbehindXSHOWBEHIND.EXEAdvertisement display which can be stopped hereNo
ShowFFXShowFF.exeFFToolBar adware toolbarNo
Cyber TrioUshowmode.exeFrom G-Tek Technologies. Allows you to set the PC in one of three modes, Standard, Enhanced and Kiddo. Standard is full function, Enhanced prevents accidental damage and Kiddo is a play environment for kids. Pre-installed on some Packard Bell PCsNo
ShowWndUShowWnd.exeFound on Gateway computers (and maybe others) - see here. "Showwnd is included with the Chicony keyboard software and is used by the software to stop the keyboard driver's taskbar entry from reappearing. It is not necessary to remove the keyboard software, however if you wish it can be removed through Add or Remove Programs"No
SHPC32USHPC32.exePort monitor for Lexmark printers on a USB connection. Ties in with the Printer Control Program. Features like cancelling a print are unavailable if disabledNo
DelayShredNShrCL.EXEMcAfee Shredder - not required at startup. You can run it manually via McAfee Security CenterNo
MicosoftartupXshrl.exeAdded by the SDBOT-JQ WORM!No
RHSI SHSUSHS.exe"Rogers Self Help Software is a free suite of tools and utilities for your computer that keeps your system running properly, and makes your Hi-Speed Internet experience smooth and trouble-free"No
Rogers SHSUshs.exe"Rogers Self Help Software is a free suite of tools and utilities for your computer that keeps your system running properly, and makes your Hi-Speed Internet experience smooth and trouble-free"No
SHSUSHS.exe"Rogers Self Help Software is a free suite of tools and utilities for your computer that keeps your system running properly, and makes your Hi-Speed Internet experience smooth and trouble-free"No
ShStatEXEYSHSTAT.EXEPart of McAfee's VirusScan Enterprise corporate anti-virus and anti-spyware security toolNo
HD Audio ProcessXshswsc.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserProfile%No
Windows Update 63Xshupd64.exeDetected by Sophos as W32/Forbot-GA and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
ShutdownawareUshutdownaware.exeLoaded by the SWEEX 6-in-1 Media Card Reader to properly manage the reader while it is connected to your systemNo
ShutDownProUShutDownPro.exeShutDownPro - shutdown, reboot, logoff your System with one mouse clickNo
ShuttlePRO HelperYShuttlePRO Helper.exeDriver/support for the Contour ShuttlePRO - "an editing tool that will have you wondering why you even need a keyboard"No
explorerXshvcsetxs.exeDetected by McAfee as Generic.bfr!cvNo
ProtectUSHVRTF.EXEPC Angel takes a 5-second snapshot of the current system registry each time the PC boots up. In the event of a crash, PC ANGEL will retrieve everything up to the minute before the crash or the last known stable registryNo
KYE_Showicon?shwicon.exeCard reader for memory cards from digital cameras. Is it required? No
ShowIcon_Justrams_USB Product Driver v2.12r012?shwicon.exeRelated to Just Rams USB product driver. Is it required?No
ShowIcon_PNY_PNY AttachéUshwicon.exePNY Attaché USB flash memory stick System Tray icon - shows when the device is plugged inNo
ShowIcon_SmartDisk Corporation_USB Card Reader v1.14e051?shwicon.exeCard reader for memory cards from digital cameras. Is it required? No
Sunkist2kUshwicon2k.exeCard reader for memory cards from digital cameras, etcNo
SunkistUshwicon98.exeCard reader for memory cards from digital cameras, etcNo
SunKistEMUshwiconem.exeCard reader for memory cards from digital cameras, etcNo
File-Sharing WizardXshwizard.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
MicrosoftXShyFx.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.MSGen. The file is located in %System%No
DesktopX WidgetUSI2992~1.exeSilica Volume Control widget included with the DesktopX desktop utility from Stardock Corporation. Displays a slider to control the speaker volume on the desktop. Once started, Silica Volume Control.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 MSConfig entry where "Silica Volume Control.exe" is shown as "SI2992~1.exe"Yes
Silica Volume ControlUSI2992~1.exeSilica Volume Control widget included with the DesktopX desktop utility from Stardock Corporation. Displays a slider to control the speaker volume on the desktop. Once started, Silica Volume Control.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Silica Volume Control.exe" is shown as "SI2992~1.exe"Yes
DesktopX WidgetUSI39E3~1.exeSilica Weather widget included with the DesktopX desktop utility from Stardock Corporation. Displays the current weather and forecast for up to 5 days for the selected location on the desktop. Once started, Silica Weather.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 MSConfig entry where "Silica Weather.exe" is shown as "SI39E3~1.exe"Yes
Silica WeatherUSI39E3~1.exeSilica Weather widget included with the DesktopX desktop utility from Stardock Corporation. Displays the current weather and forecast for up to 5 days for the selected location on the desktop. Once started, Silica Weather.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Silica Weather.exe" is shown as "SI39E3~1.exe"Yes
DesktopX WidgetUSI90AE~1.exeSilica To-Do List widget included with the DesktopX desktop utility from Stardock Corporation. Adds a "to do" task list on the desktop. Once started, Silica To-Do List.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 MSConfig entry where "Silica To-Do List.exe" is shown as "SI90AE~1.exe"Yes
Silica ToDo ListUSI90AE~1.exeSilica To-Do List widget included with the DesktopX desktop utility from Stardock Corporation. Adds a "to do" task list on the desktop. Once started, Silica To-Do List.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Silica To-Do List.exe" is shown as "SI90AE~1.exe"Yes
DesktopX WidgetUSI985F~1.exeSilica Word of the Day widget included with the DesktopX desktop utility from Stardock Corporation. Displays the "Word of the Day" from Wordsmith.org on the desktop. Once started, Silica Word of the Day.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 MSConfig entry where "Silica Word of the Day.exe" is shown as "SI985F~1.exe"Yes
Silica Word of the Day.exeUSI985F~1.exeSilica Word of the Day widget included with the DesktopX desktop utility from Stardock Corporation. Displays the "Word of the Day" from Wordsmith.org on the desktop. Once started, Silica Word of the Day.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Silica Word of the Day.exe" is shown as "SI985F~1.exe"Yes
SIAPRO6Usia.exeOlder version of Steganos Internet Anonym privacy softwareNo
SIA2006USIA2006.exeOlder version of Steganos Internet Anonym privacy softwareNo
SIAPRO7USIAPRO7.exeOlder version of Steganos Internet Anonym privacy softwareNo
sicasisyhifhXsicasisyhifh.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
Yahoo MessenggerXSICHOST.exeDetected by McAfee as W32/Yahlover.worm.gen.k and by Malwarebytes Anti-Malware as Backdoor.BotNo
Sick BeardUSickBeard.exeSick Beard - is an internet "PVR (Personal Video Recorder) for newsgroup users (with limited torrent support). It watches for new episodes of your favorite shows and when they are posted it downloads them, sorts and renames them, and optionally generates metadata for them"No
SicomXSicom.exeAdded by the NETLIP WORM!No
SideACT!USideACT.exeTo-Do list add-on for the Sage ACT! contact managerNo
Microsoft Windows SidebarUSidebar.exeWindows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijackerYes
Microsoft® Windows® Operating SystemUSidebar.exeWindows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijackerYes
SidebarUSidebar.exeWindows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijackerYes
Murbak HelperXsidebarmgr.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %LocalAppData%No
SideGreenXSideGreen.exeSideGreen adware. File located in %Program Files%\SideGreenNo
SideOnXSideOn.exeDetected by Microsoft as Adware:Win32/Bonuscash and by Malwarebytes Anti-Malware as Adware.SideOn. The file is located in %ProgramFiles%\SideOnNo
SideTabXSideTab.exeDetected by Microsoft as Adware:Win32/SideTabNo
SIECACST?siecacst.exeRelated to a Siemens card reader. Is it required?No
DesktopX WidgetUSIF08B~1.exeSilica Unit Converter widget included with the DesktopX desktop utility from Stardock Corporation. Provides a unit conversion utility on the desktop. Once started, Silica Unit Converter.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 entry where "Silica Unit Converter.exe" is shown as "SIF08B~1.exe"Yes
Silica Unit ConverterUSIF08B~1.exeSilica Unit Converter widget included with the DesktopX desktop utility from Stardock Corporation. Provides a unit conversion utility on the desktop. Once started, Silica Unit Converter.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Silica Unit Converter.exe" is shown as "SIF08B~1.exe"Yes
Install Pending Files?sifxinst.exeUninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see here. Is it required?No
SightSpeedUSightSpeed.exeSightSpeed Video Chat - "lets you connect with all your friends and family easily. Make video calls, phone calls, and send video mails and text messages to everyone in your network, anywhere in the world"No
Intel(R) Turbo Boost Technology Monitor 2.0USignalIslandUi.exeDesktop gadget for Intel® Turbo Boost Monitor - which "is a Windows 7 application designed to display processor frequency activity and highlight energy saver mode. The Turbo Boost Monitor only runs on PCs with Intel® Turbo™ Boost Technology capable processors" - such as the Core i7, i5 and i3Yes
Intel® Turbo Boost Technology Monitor 2.0USIGNAL~1.EXEDesktop gadget for Intel® Turbo Boost Monitor - which "is a Windows 7 application designed to display processor frequency activity and highlight energy saver mode. The Turbo Boost Monitor only runs on PCs with Intel® Turbo™ Boost Technology capable processors" - such as the Core i7, i5 and i3Yes
signkeyXsignkey.exeDetected by Sophos as Troj~DwnLdr-KKT and by Malwarebytes Anti-Malware as Adware.KorAdNo
signkey3Xsignkey2.exeDetected by Malwarebytes Anti-Malware as Adware.Korad. The file is located in %AppData%\tempNo
signup3Xsignup2.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader.K. The file is located in %AppData%\tempNo
File Signature VerificationXsigverifui.exeDetected by Dr.Web as Trojan.DownLoader8.32054 and by Malwarebytes Anti-Malware as Trojan.AgentNo
SigXUsigx.exeSigX is a "dynamic signature image generated based on whatever data your computer sends it though our SigX program. It can display your current Mp3, current OS, Free Ram, your current time and more"No
SigXCUSigX.exeSigX is a "dynamic signature image generated based on whatever data your computer sends it though our SigX program. It can display your current Mp3, current OS, Free Ram, your current time and more"No
sihemigexuhyXsihemigexuhy.exeDetected by McAfee as PWS-Zbot.gen.ary and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
EleFunAnimatedWallpaperUSilent Lagoon.exeSilent Lagoon animated wallpaper fromNo
Compaq Knowledge CenterUsilent.exe"Compaq Knowledge Center integrates self-help assistance features from Compaq and Microsoft with the efficiencies of the Internet for the fastest time to solution"No
SilentSoftechXSilentSo.exeAdded by the AUTORUN-ANU WORM!No
Silica CalculatorUSilica Calculator.exeSilica Calculator widget for the DesktopX desktop utility from Stardock Corporation. Once started, Silica Calculator.exe loads a file called "DXWidget.exe" and exitsNo
DesktopX WidgetUSilica Calendar.exeSilica Calender widget included with the DesktopX desktop utility from Stardock Corporation. Displays a calendar on the desktop. Once started, Silica Calendar.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entryYes
Silica CalenderUSilica Calendar.exeSilica Calender widget included with the DesktopX desktop utility from Stardock Corporation. Displays a calendar on the desktop. Once started, Silica Calendar.exe loads a file called "DXWidget.exe" and exitsYes
DesktopX WidgetUSilica Clock.exeSilica Clock widget included with the DesktopX desktop utility from Stardock Corporation. Displays a clock on the desktop. Once started, Silica Clock.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entryYes
DesktopX WidgetUSilica Clock.exeSilica Clock widget included with the DesktopX desktop utility from Stardock Corporation. Displays a clock on the desktop. Once started, Silica Clock.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 MSConfig entry where "Silica Clock.exe" is shown as "SILICA~2.EXE"Yes
Silica ClockUSilica Clock.exeSilica Clock widget included with the DesktopX desktop utility from Stardock Corporation. Displays a clock on the desktop. Once started, Silica Clock.exe loads a file called "DXWidget.exe" and exitsYes
Silica ClockUSilica Clock.exeSilica Clock widget included with the DesktopX desktop utility from Stardock Corporation. Displays a clock on the desktop. Once started, Silica Clock.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Silica Clock.exe" is shown as "SILICA~2.EXE"Yes
Silica CPU MeterUSilica CPU meter.exeSilica CPU Meter widget for the DesktopX desktop utility from Stardock Corporation. Displays a CPU usage meter on the desktop. Once started, Silica CPU meter.exe loads a file called "DXWidget.exe" and exitsNo
Silica Dictionary SearchUSilica Dictionary Search.exeSilica Dictionary Search widget for the DesktopX desktop utility from Stardock Corporation. Once started, Silica Dictionary Search.exe loads a file called "DXWidget.exe" and exitsNo
Silica Drive MeterUSilica Drive Meter.exeSilica Drive Meter widget for the DesktopX desktop utility from Stardock Corporation. Displays a hard disk usage meter on the desktop. Once started, Silica Drive Meter.exe loads a file called "DXWidget.exe" and exitsNo
Silica Memory MeterUSilica Memory Meter.exeSilica Memory Meter widget for the DesktopX desktop utility from Stardock Corporation. Displays a memory usage meter on the desktop. Once started, Silica Memory Meter.exe loads a file called "DXWidget.exe" and exitsNo
Silica Network MonitorUSilica Network Monitor.exeSilica Network Monitor widget for the DesktopX desktop utility from Stardock Corporation. Once started, Silica Network Monitor.exe loads a file called "DXWidget.exe" and exitsNo
DesktopX WidgetUSilica Picture Frame.exeSilica Picture Frame widget included with the DesktopX desktop utility from Stardock Corporation. Displays either a static user selected picture or slide show in a resizable picture frame on the desktop. Once started, Silica Picture Frame.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entryYes
Silica Picture FrameUSilica Picture Frame.exeSilica Picture Frame widget included with the DesktopX desktop utility from Stardock Corporation. Displays either a static user selected picture or slide show in a resizable picture frame on the desktop. Once started, Silica Picture Frame.exe loads a file called "DXWidget.exe" and exitsYes
DesktopX WidgetUSilica Search.exeSilica Search widget included with the DesktopX desktop utility from Stardock Corporation. Provides a search box powered by Google on the desktop. Once started, Silica Search.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entryYes
Silica SearchUSilica Search.exeSilica Search widget included with the DesktopX desktop utility from Stardock Corporation. Provides a search box powered by Google on the desktop. Once started, Silica Search.exe loads a file called "DXWidget.exe" and exitsYes
DesktopX WidgetUSilica To-Do List.exeSilica To-Do List widget included with the DesktopX desktop utility from Stardock Corporation. Adds a "to do" task list on the desktop. Once started, Silica To-Do List.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entryYes
Silica ToDo ListUSilica To-Do List.exeSilica To-Do List widget included with the DesktopX desktop utility from Stardock Corporation. Adds a "to do" task list on the desktop. Once started, Silica To-Do List.exe loads a file called "DXWidget.exe" and exitsYes
DesktopX WidgetUSilica Unit Converter.exeSilica Unit Converter widget included with the DesktopX desktop utility from Stardock Corporation. Provides a unit conversion utility on the desktop. Once started, Silica Unit Converter.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entryYes
Silica Unit ConverterUSilica Unit Converter.exeSilica Unit Converter widget included with the DesktopX desktop utility from Stardock Corporation. Provides a unit conversion utility on the desktop. Once started, Silica Unit Converter.exe loads a file called "DXWidget.exe" and exitsYes
DesktopX WidgetUSilica Volume Control.exeSilica Volume Control widget included with the DesktopX desktop utility from Stardock Corporation. Displays a slider to control the speaker volume on the desktop. Once started, Silica Volume Control.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entryYes
Silica Volume ControlUSilica Volume Control.exeSilica Volume Control widget included with the DesktopX desktop utility from Stardock Corporation. Displays a slider to control the speaker volume on the desktop. Once started, Silica Volume Control.exe loads a file called "DXWidget.exe" and exitsYes
DesktopX WidgetUSilica Weather.exeSilica Weather widget included with the DesktopX desktop utility from Stardock Corporation. Displays the current weather and forecast for up to 5 days for the selected location on the desktop. Once started, Silica Weather.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entryYes
Silica WeatherUSilica Weather.exeSilica Weather widget included with the DesktopX desktop utility from Stardock Corporation. Displays the current weather and forecast for up to 5 days for the selected location on the desktop. Once started, Silica Weather.exe loads a file called "DXWidget.exe" and exitsYes
DesktopX WidgetUSilica Word of the Day.exeSilica Word of the Day widget included with the DesktopX desktop utility from Stardock Corporation. Displays the "Word of the Day" from Wordsmith.org on the desktop. Once started, Silica Word of the Day.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entryYes
Silica Word of the Day.exeUSilica Word of the Day.exeSilica Word of the Day widget included with the DesktopX desktop utility from Stardock Corporation. Displays the "Word of the Day" from Wordsmith.org on the desktop. Once started, Silica Word of the Day.exe loads a file called "DXWidget.exe" and exitsYes
DesktopX WidgetUSILICA~1.EXESilica Calender widget included with the DesktopX desktop utility from Stardock Corporation. Displays a calendar on the desktop. Once started, Silica Calendar.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 MSConfig entry where "Silica Calendar.exe" is shown as "SILICA~1.EXE"Yes
Silica CalenderUSILICA~1.EXESilica Calender widget included with the DesktopX desktop utility from Stardock Corporation. Displays a calendar on the desktop. Once started, Silica Calendar.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Silica Calendar.exe" is shown as "SILICA~1.EXE"Yes
DesktopX WidgetUSILICA~3.EXESilica Picture Frame widget included with the DesktopX desktop utility from Stardock Corporation. Displays either a static user selected picture or slide show in a resizable picture frame on the desktop. This is the Vista/7 MSConfig entry where "Silica Picture Frame.exe" is shown as "SILICA~3.EXE"Yes
Silica Picture FrameUSILICA~3.EXESilica Picture Frame widget included with the DesktopX desktop utility from Stardock Corporation. Displays either a static user selected picture or slide show in a resizable picture frame on the desktop. Once started, Silica Picture Frame.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Silica Picture Frame.exe" is shown as "SILICA~3.EXE"Yes
DesktopX WidgetUSILICA~4.exeSilica Search widget included with the DesktopX desktop utility from Stardock Corporation. Provides a search box powered by Google on the desktop. This is the Vista/7 MSConfig entry where "Silica Search.exe" is shown as "SILICA~4.EXE"Yes
Silica SearchUSILICA~4.exeSilica Search widget included with the DesktopX desktop utility from Stardock Corporation. Provides a search box powered by Google on the desktop. Once started, Silica Search.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Silica Search.exe" is shown as "SILICA~4.EXE"Yes
SimcastNSimcastAlerts.exeSimcast is a free service that allows you to subscribe to information on a large variety of topics. Alerts will appear on your desktop when a channel that you have subscribed to has something to sayNo
cpntmgcXsimcss.exeAdded by the MAGICON.A TROJAN!No
apyginapyginXsimenu.exeAdded by the SDBOT.BTR WORM!No
SakemsneqlXsimenu.exeAdded by the SDBOT.BTO WORM!No
Si MeterNSIMETER.EXESi Meter - keep track of things like CPU activity, network activity and speed, hard-drive activity, hard-drive space, system memory, running processes, or just date and timeNo
simpcvtXsimpcvt.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %AppData%\simpcvtNo
Simplify MediaNSimplifyMedia.exeSimplify Media media manager - "enjoy songs from home while at work or from any WiFi location. Explore friends' music while they are online"No
SimpUSimpLite-AIM.exeSimpLite encryption add-on for AIM from Secway - encrypts messages before they're sent, preventing eavesdroppers from reading your AIM conversationsNo
SimpUSimpLite-ICQ-AIM.exeSimpLite encryption add-on for ICQ/AIM from Secway - encrypts messages before they're sent, preventing eavesdroppers from reading your ICQ/AIM conversationsNo
SimpUSimpLite-ICQ.exeSimpLite encryption add-on for ICQ from Secway - encrypts messages before they're sent, preventing eavesdroppers from reading your ICQ conversationsNo
SimpUSimpLite-Jabber.exeSimpLite encryption add-on for the open source Jabber instant messaging service from Secway - encrypts messages before they're sent, preventing eavesdroppers from reading your Jabber conversationsNo
SimpUSimpLite-MSN.exeSimpLite encryption add-on for MSN Messenger from Secway - encrypts messages before they're sent, preventing eavesdroppers from reading your MSN Messenger conversationsNo
SimpLite-MSNUSimpLite-MSN.exeSimpLite encryption add-on for MSN Messenger from Secway - encrypts messages before they're sent, preventing eavesdroppers from reading your MSN Messenger conversationsNo
SimpUSimpLite-Yahoo.exeSimpLite encryption add-on for Yahoo! Messenger from Secway - encrypts messages before they're sent, preventing eavesdroppers from reading your Yahoo! Messenger conversationsNo
SimpmsnXSimpmsn.exeDetected by Ikarus as Email-Worm.Win32.VB.fn and by Malwarebytes Anti-Malware as PasswordStealer.Agent. The file is located in %System%No
SimpUSimpPro.exeSimpPro encryption add-on for popular instant messengers from Secway - encrypts messages before they're sent, preventing eavesdroppers from reading your conversationsNo
CMARPXsimrp.exeDetected by McAfee as RDN/Generic.bfr!a and by Malwarebytes Anti-Malware as Trojan.Agent.SPRNo
SIDEBARSXsimrp.exeDetected by McAfee as RDN/Generic.bfr!a and by Malwarebytes Anti-Malware as Trojan.Agent.SPRNo
sims2serverXSims3server.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %ProgramFiles%\ratNo
sims3server1XSims3server.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %ProgramFiles%\ratNo
scoupaXsincra.exeAdded by the SDBOT-ST WORM!No
SingaporeXsingapore.exeAdds a blue crescent to the taskbar and when double-clicked displays an adult-content web-site. Also known to drop your internet connection and dial an international telephone number. See here for more information. Must be disabled in MSCONFIG before un-installing or it re-instates itselfNo
siocoXsioco.exeAdded by the AGENT-MOD TROJAN!No
SipDiscountNSipDiscount.exeSipDiscount - internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular SkypeYes
sipgate X-LiteNsipgateXLite.exe"sipgate x-Lite makes telephone calling possible directly over your PC. You only need a microphone and a sound card and/or a headset"No
XSC SIP ClientNsipgateXLite.exe"sipgate x-Lite makes telephone calling possible directly over your PC. You only need a microphone and a sound card and/or a headset"No
SIPPSUSIPPS.exeWeb.de Internet phone utilityNo
siren114SXsiren114U.exeSiren114 rogue security software - not recommended. One of the OneScan family of rogue scanner programsNo
SiS 6326 AcceleratorXsis6326m.exeAdded by the MSIC BACKDOOR!No
SISAM10MXSISAM10M.exeAdware pop-up generatorNo
SiS7012UtilityYSiSAudUt.exeSiS Corporation sound card driverNo
siService.exeUsiService.exeSpam Inspector - anti email spam softwareNo
SiSSetCDfmt?SiSSetCDfmt.exeRelated to a Silicon Integrated Systems Corp (SiS) product?No
SiSSWLEDUsisswled.exeSystem Tray utility for SiS 900 network cardsNo
PoliciesXSistem servidor.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Windir%\twain_32\WindowsNo
SistemXSistem servidor.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Windir%\twain_32\WindowsNo
Sistema operacionalXSistem servidor.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Windir%\twain_32\WindowsNo
sistemXsistem.exeDetected by Kaspersky as Trojan.Win32.Rina.q. The file is located in %System%No
sistemXsistem.exeDetected by McAfee as PWS-Zbot.gen.lm and by Malwarebytes Anti-Malware as Backdoor.XTRat. The file is located in %Windir%\InstallDirNo
sistemXsistem.exeDetected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Trojan.MSIL.genNo
sistemXsistem.exeDetected by McAfee as Generic.bfr!ck. The file is located in %Windir%No
sistem.exeXsistem.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %System%No
sistem.exeXsistem.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %UserProfile%No
Windows Baþlangýç DosyasýXsistem.exeAdded by the MUZK WORM!No
sistrai.exeXsistrai.exeAdded by the PROVA TROJAN!No
SiS (R) Compatible Super VGA SiSTray applicationUsistray.exeSystem Tray access to display settings for Silicon Integrated Systems (SiS) based graphics chipsets. Located in %System%Yes
SiS TrayUsistray.exeSystem Tray icon for SiS based graphics. Located in %System%No
sistrayXsistray.exeAdded by the PROVA TROJAN! Located in %Windir%\commandNo
SiSTrayUSiSTray.exeSystem Tray icon for SiS based graphics. Located in %ProgramFiles%\SiS VGA UtilitiesNo
sistrayUsistray.exeSystem Tray icon for SiS based graphics. Located in %System%No
Utility TrayUsistray.exeSystem Tray access to display settings for Silicon Integrated Systems (SiS) based graphics chipsets. Located in %System%Yes
sistryXsistry.exeAdded by the CEBE WORM!No
SiSUSBRGNSiSUSBrg.exeSiS USB Registry Patch File - fixes the undetectable problem with SiS USB controller on Windows XPNo
SiteAdvUSiteAdv.exePreloads the McAfee SiteAdvisor browser plug-in for Internet Explorer and Firefox. "With SiteAdvisor software installed, your browser will look a little different than before. We add small site rating icons to your search results as well as a browser button and optional search box. Together, these alert you to potentially risky sites and help you find safer alternatives". Not required as it will load with your browserYes
SiteAdvisorUSiteAdv.exePreloads the McAfee SiteAdvisor browser plug-in for Internet Explorer and Firefox. "With SiteAdvisor software installed, your browser will look a little different than before. We add small site rating icons to your search results as well as a browser button and optional search box. Together, these alert you to potentially risky sites and help you find safer alternatives". Not required as it will load with your browserYes
SiteAdware.exeXSiteAdware.exeSiteAdware rogue security software - not recommended, removal instructions here. A member of the AntiAID familyNo
SiteAdvisorUSiteAv.exeRefer to the "SiteAdv.exe" entry. This entry only appears to originate from version 2.0.0.75 (Build 4295) of SiteAdvisor and the registry entry incorrectly points to the invalid filename "SiteAv.exe" - when it should be "SiteAdv.exe"Yes
SiteAvUSiteAv.exeRefer to the "SiteAdv.exe" entry. This entry only appears to originate from version 2.0.0.75 (Build 4295) of SiteAdvisor and the registry entry incorrectly points to the invalid filename "SiteAv.exe" - when it should be "SiteAdv.exe"Yes
[various names]Xsitebar.exeAdded by an unidentified TROJAN!No
SiteRankerUSiteRankTray.exe"SiteRanker brings you ratings and reviews of websites while you browse and allows you to post your own ratings and reviews. By posting your ratings and reviews youll help other users stay away from websites you found to be dangerous, recommend an eshop whose services you were satisfied with, etc." Not available for download, it's usually distributed together with other productsNo
SiteVillainXSiteVillain.exeSiteVillain rogue security software - not recommended. A member of the AntiAID familyNo
Six EngineUSixEngine.exePower management utility included with some ASUS motherboards. "The new ASUS EPU (Energy Processing Unit) - the world's first power saving engine, has been upgraded to a new 6 engine version, which provides total system power savings by detecting current PC loadings and intelligently moderating power in real-time"No
sixtysixXsixtypopsix.exeMedload adwareNo
Windows Service AgentXsjbsm.exeAdded by the SMALLTRO.II TROJAN!No
Windows Service AgentXsjbsmgm.exeAdded by the IRCBOT.AHX WORM!No
Java ExpressXsjehost.exeAdded by the SDBOT-DNJ WORM!No
MChkXsjzkp.exeAdded by the MDROP-CSP TROJAN!No
Hot Key Kbd 2690 DaemonUSK2690DM.EXEMulti-function keyboard driver. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keysNo
SK51USK51.EXESaveKeys keystroke logger/monitoring program - remove unless you installed it yourself!No
SK60USK60.EXESaveKeys keystroke logger/monitoring program - remove unless you installed it yourself!No
Hot Key Kbd 9910 DaemonUSK9910DM.EXEMulti-function keyboard driver. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keysNo
SK9910DMUSK9910DM.EXEMulti-function keyboard driver. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keysNo
666XSka.exeAdded by the PIPES TROJAN!No
USB Hub Keyboard Patch?SKBPATCH.EXEUSB HUB UpdateNo
Hot Key Kbd DaemonUSKDAEMON.EXEMulti-function keyboard driver. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keysNo
SKDAEMONUSKDAEMON.EXEMulti-function keyboard driver. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keysNo
KERNEL 32XSKERNEL32.comAdded by the SEMAPI-A WORMNo
SkeyAgentXSkeyAgent.exeSmartKeyword adwareNo
BBC News alertsUskinkers.exeBBC News Desktop Alerts service - see here. Desktop alert and breaking news e-mail services let you find out about all the latest news as it happensNo
HalifaxHowardClusterUskinkers.exe"Howard the Weatherman" desktop client from Halifax by Skinkers - marketing/messaging tool. Leave enabled if you want to receive messagesNo
skinkersUskinkers.exeSelection of desktop messaging/marketing tools with celebrity tie-ins including MTV's "Desktop Ozzy" and Arsenal's "Desktop Wenger" - see here. Leave enabled if you want to receive messagesNo
SkySportsClusterUskinkers.exeSky Sports Alerter desktop client from Sky Sports by Skinkers - "delivers all the breaking sports news stories straight to your PC." Leave enabled if you want to receive messagesNo
SkipeTurnsXSkipeTurns.exeDetected by Sophos as W32/Ainslot-ADNo
Spy-KeyloggerUskl.exeSpyKeylogger keystroke logger/monitoring program - remove unless you installed it yourself!No
sysAppUsklgr.exeSuperKeylogger surveillance software. Uninstall this software unless you put it there yourselfNo
Windows Network Data Management System ServiceXskp66.exeAdded by the AGENT.WNDM TROJAN!No
SkraXSkra.exeIdentified as a variant of the TrojanDownloader.Matcash malwareNo
sks-32Usks32proc.exeSpyKeySpy surveillance software. Uninstall this software unless you put it there yourselfNo
sks-32USKS32P~1.EXESpyKeySpy surveillance software. Uninstall this software unless you put it there yourselfNo
SkunkXSkunk.exeDetected by Sophos as W32/Sunk-ANo
Flash MediaXskxs��'�'%''msn'�%'fix''.exeAdded by the AGENT.ZOY TROJAN!No
WINDOWS SKYXsky.exeAdded by the MYTOB.CH WORM!No
WINDOWS SYSTEMXsky.exeDetected by Trend Micro as WORM_MYTOB.LBNo
WINDOWS SYSTEMXskybot.exeAdded by the MYTOB-CX WORM!No
WINDOWS SYSTEMXskybot.exeAdded by the MYTOB.EB WORM!No
WDNS SYSTEMXskybotx.exeAdded by the MYTOB-BY WORM!No
WINDOWS SYSTEMXskybotx.exeAdded by the MYTOB-BY WORM!No
skynetave.exeXskynetave.exeAdded by the SASSER.D WORM!No
Skype StartupXskyp.exeAdded by the VANBOT-C WORM!No
82b36685c0f383d104a799283e3fd80cXskypc.exeDetected by Dr.Web as Trojan.DownLoader8.37131 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJNo
Skype pro.exeXSkype pro.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %ProgramFiles%No
8e3bc91142bd8d798a10a1667ae4d2beXSkype.exeDetected by McAfee as RDN/Generic.dx!bh and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %Temp%No
9975759809ee69cc2d0562054d998149Xskype.exeDetected by Dr.Web as Trojan.DownLoader7.8951 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %Temp%No
HKCUXskype.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %System%\SkypeNo
HKCUXSkype.exeDetected by McAfee as Generic BackDoor!fqg and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %Windir%\InstallDirNo
HKLMXskype.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %System%\SkypeNo
HKLMXSkype.exeDetected by McAfee as Generic BackDoor!fqg and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %Windir%\InstallDirNo
MicroUpdateXskype.exeDetected by Dr.Web as Trojan.DownLoader6.34482 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %MyDocuments%\SkypeNo
Plus7XSkype.exeDetected by McAfee as RDN/Generic BackDoor!k and by Malwarebytes Anti-Malware as Backdoor.Agent. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %System%\messegerNo
PoliciesXskype.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %System%\SkypeNo
SkypeNSkype.exeSkype is "free calls, video calls and instant messaging over the internet. Plus great value calls to phones anywhere in the world"Yes
skypeXskype.exeAdded by the MAHATO.AO TROJAN! Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %Windir%No
SkypeXSkype.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %Windir%\InstallDirNo
SkypeXSkype.exeDetected by McAfee as RDN/Generic BackDoor!k and by Malwarebytes Anti-Malware as Backdoor.Agent. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %System%\messegerNo
SkypeXSkype.exeDetected by McAfee as RDN/Generic.dx. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %AppData%\Skype\PhoneNo
Skype UpdateXskype.exeDetected by Dr.Web as Trojan.KillProc.22324 and by Malwarebytes Anti-Malware as Trojan.MPGen.nps. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %AppData%\SkypeNo
SkypeStartupXSkype.exeAdded by the PYKSE-A WORM!No
TASKMGRXskype.exeDetected by McAfee as Generic.grp!mq and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %AppData%No
VoiceXskype.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.SK. Note - this is not the legitimate Skype VOIP software which is normally located in %ProgramFiles%\Skype\Phone. This one is located in %System%\SYSTEM32No
skypeeXskypee.exeDetected by Sophos as Troj/Rombrast-A and by Malwarebytes Anti-Malware as Trojan.FakeSkypeNo
SkypeMateNSkypeMate.exeSkypeMate acts as a bridge between networks of VoIP and PSTNNo
59259b3fd2189ff57405beed4f893feaXskypemc.exeDetected by Dr.Web as Trojan.DownLoader8.31878 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJNo
Microsoft Update 2.5XSkypePlugin.exeDetected by McAfee as RDN/PWS-Banker and by Malwarebytes Anti-Malware as Backdoor.BotNo
SkypePMXSkypePM.exeDetected by Sophos as Troj/Bdoor-BDY and by Malwarebytes Anti-Malware as Trojan.ObfuscatedNo
SkypeupdateXSkypeupdate.exeDetected by Malwarebytes Anti-Malware as Trojan.MPGen.BMS. Note - this is not a legitimate entry for the popular Skype VOIP software. The file is located in %MyDocuments%\ServicesNo
Realtek Voice ManagerUSkytel.exeRealtek Voice Manager, installed with the drivers for on-board Realtek HD audio codecs. On an ALC885 based test system it doesn't run after the drivers have been installed and the startup entry is then removed. Disabling it appears to have no ill effects but it's exact purpose is unknown - hence the "U" recommendationYes
SkytelUSkytel.exeRealtek Voice Manager, installed with the drivers for on-board Realtek HD audio codecs. On an ALC885 based test system it doesn't run after the drivers have been installed and the startup entry is then removed. Disabling it appears to have no ill effects but it's exact purpose is unknown - hence the "U" recommendationYes
[various names]Xslamm.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
RA ServerXSlave.exeAdded by the RA TROJAN!No
Slayhacker734Xslay7383.exeAdded by the SIKBOT-A TROJAN!No
Systems RestartXslchost.exeAdded by the MULTIDROP.C TROJAN!No
xcxdsaa7Xslcskxsdl7.exeAdded by the ONLINEG-K TROJAN!No
Select serverXslcsvr.exeAdded by the DLOADER-WD TROJAN!No
Streamload DownloaderNSlDB.exeDownloader for MediaMax (was Streamload) - "gives you a private and secure place to upload, store, access, and share your personal videos, photos, movies, music, and files"No
SleepManagerNSleepMgr.exeThis program locates free contiguous disk spaces and allocates them for storing BASE MEMORY, EXTENDED MEMORY, VIDEO MEMORY, and SM RAM. It helps the computer come out of hibernate modeNo
SelfHostUtil?slefhost.exe??No
Microsoft Synchronization ManagerXslhost.exeAdded by the SDBOT.YH WORM!No
Slibe.comUSliber.EXESliber - freeware screen capturing & online sharing toolNo
SlimCleanerUSlimCleaner.exeSlimCleaner from SlimWare Utilities, Inc. Community driven system cleaner and optimization utility which includes a startup/service manager, shredder, uninstaller and access to Windows system toolsYes
SlimCleaner ApplicationUSlimCleaner.exeSlimCleaner from SlimWare Utilities, Inc. Community driven system cleaner and optimization utility which includes a startup/service manager, shredder, uninstaller and access to Windows system toolsYes
SlimComputerUSlimComputer.exeSlimComputer from SlimWare Utilities, Inc. Community driven system optimization utility which includes a startup/service manager, uninstaller and access to Windows system toolsYes
SlimComputer ApplicationUSlimComputer.exeSlimComputer from SlimWare Utilities, Inc. Community driven system optimization utility which includes a startup/service manager, uninstaller and access to Windows system toolsYes
slimp3NSliMP3 Server.exeSlimp3 Server - "presents an entirely new way of accessing and enjoying your music collection. Instead of storing your music on CDs or memory cards, the SliMP3 uses your home network to access the music stored on your PC"No
SlingshotNSLINGS~1.EXEAtomica Slingshot - "reference tool with access to dictionary and encyclopedia terms, bios, technical terms, history, geography, and much more". Now superseed by 1-Click AnswersNo
slipcoreYslipcore.exeCore module for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet, Wanadoo, Terra, OnSpeed, United Online and AOL Canada. Required if the user's account is locked in to that proxy serverNo
SlipStreamYslipcore.exeCore module for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet, Wanadoo, Terra, OnSpeed, United Online and AOL Canada. Required if the user's account is locked in to that proxy serverNo
ISP.COM High SpeedYslipgui.exeUser interface for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet, Wanadoo, Terra, OnSpeed, United Online and AOL Canada. Required if the user's account is locked in to that proxy serverNo
slipguiYslipgui.exeUser interface for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet, Wanadoo, Terra, OnSpeed, United Online and AOL Canada. Required if the user's account is locked in to that proxy serverNo
[random filename]Xslk8x2peu.exeQuickLinks adwareNo
slmssXslmss.exeDetected by Trend Micro as ADW_SECTHOUGHT.ANo
sloadXsload.exeWin SynchroAd adware, also detected as DLOADER-QG TROJAN!No
sloadXsload32.exeAdded by the SDBOT-OY WORM!No
EGTSOFT System LockerUslocker.exeActive System Locker by Sowsoft, LLC - "a handy utility that allows you to protect your personal computer from unauthorized access". Originally released as "EGTSOFT System Locker" by EGTSOFTNo
LTM2Xslogan.exeAdded by the LITMUS.203 BACKDOOR!No
Internal Configuration Serving StateXsloka.exeDetected by Dr.Web as Trojan.DownLoader5.57797 and by Malwarebytes Anti-Malware as Trojan.VirToolNo
Windows Svchost AuthorityXslsass.exeAdded by the RBOT-UA WORM!No
System LifeGuard SchedulerUSlsched.exeSystem LifeGuard schedulerNo
Windows ServiceXslserv32.exeAdded by the RBOT-KO WORM!No
NAV Auto UpdatesXslserver.exeAdded by the SDBOT.LT BACKDOOR!No
NAV Auto UpdatesXslserves.exeAdded by the RBOT.COI BACKDOOR!No
27Xslsorve.exeAdded by the SLSORVE-A TROJAN!No
msoft-updater23Xslssystem.exeDetected by Sophos as W32/Rbot-ASRNo
Windows Update 32Xslsys.exeDetected by Sophos as W32/Forbot-FT and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
slvchost32Xslvchost32.exeAdded by an unidentified VIRUS, WORM or TROJAN!No
Logical VolumeXslvhost.exeAdded by the SDBOT.FWC BACKDOOR!No
HollabackXslvhosts.exeAdded by the SDBOT.BMO WORM!No
SLZ.mp3XSLZ.mp3.exeDetected by Dr.Web as Win32.HLLW.Autoruner1.14180 and by Malwarebytes Anti-Malware as Worm.AutoRun.SLNo
Web ServiceXsm.exeAdded by the BUBE-F VIRUS!No
SM1BGNSM1BG.EXEUSB driver for downloading from within Napster and iTunes to portable MP3 players. Only required at startup if you use it all the time - otherwise start it manually when requiredNo
SM1NINTNSM1NINT.exeCypress USB Mass Storage Driver Notification Icon Application - tray notification for Cypress base memory sticks and external storage devices for Win98No
SM56ACLNsm56hlpr.exeHelper utility for Motorola based SM56 software modems - resides in the System TrayNo
SMSERIALNsm56hlpr.exeHelper utility for Motorola based SM56 software modems - resides in the System TrayNo
smaUsma.exeSmartKeylogger keystroke logger/monitoring program - remove unless you installed it yourself!No
SManagerXsmanager.6.exeAdded by the AGENT.BJO TROJAN!No
SManagerXsmanager.7.exeAdded by the DWNLDR-GVG TROJAN!No
smapcore17Xsmapcore17.exeDetected by McAfee as Downloader.a!cz3 and by Malwarebytes Anti-Malware as Trojan.AgentNo
Smart Antivirus-2009.exeXSmart Antivirus-2009.exeSmart Antivirus 2009 rogue security software - not recommended, removal instructions hereNo
Smart SecurityXsmart.exeSmart Security rogue security software - not recommended, removal instructions hereNo
Windows Smart ManagerXsmart.exeAdded by the RBOT-SL WORM!No
dRMON SmartAgentUSmartAgt.exePart of the network monitoring program group for 3Com NIC cards. See here for more infoNo
SmartAudioUSmartAudio.exeConexant SmartAudio PC audio chipset software - typically available on notebooks with built-in microphonesNo
smartbarupdateXSmartBarUpdate.exeSmartBar adwareNo
SmartBarXPNSmartBarXP.exeSmartBarXP is a bar that runs down the side of your screen, and can be configured to display interactive panels known as 'panes'. These panes include media players, slideshow and image viewing panes, a virtual desktop manager, and live news, weather and stock feeds to mention but a fewNo
SmartBoanXSmartBoan.exeSmartBoan rogue security software - not recommended, removal instructions hereNo
SmartCopy?SmartCopy.exeRelated to SmartCopy from Northstar Systems Corp. What does it do and is it required?No
Lotus SmartCenterNsmartctr.exeLotus SmartSuite central application, called SmartCenter, which runs on the Windows desktop. SmartCenter toolbar stretches across the top or, optionally, the bottom of the screen. Uses a lot of resources. Available via Start → ProgramsNo
sMaRTcaPsNSMARTC~1.EXEsMaRTcaPs from Phoebus LLC - enables you to configure the time needed to depress Caps Lock, Num Lock & Insert keysNo
ASUS SmartDoctorUSmartDoctor.exe"ASUS SmartDoctor is a group of special tools to help users make the most of their ASUS graphics cards. It monitors the Fan RPM, AGP Power Level, GPU and RAM temperature, and has a slide bar for easy manual overclocking"No
BootCleanXsmartdrv.exeAdded by the LURKA-A VIRUS!No
SmartExNSmartEx.exeSmartException from Stardock Corporation - "is a utility that can be used to help gather additional information about an application that has crashed". Run manually via the Start menu if you experience problems with an application crashingYes
SmartExceptionNSmartEx.exeSmartException from Stardock Corporation - "is a utility that can be used to help gather additional information about an application that has crashed". Run manually via the Start menu if you experience problems with an application crashingYes
SmartFaceVWatcherYSmartFaceVWatcher.exeToshiba's Face Recognition that allows the user login to their laptop hands-free via the built-in webcam on some modelsNo
TOSHIBA Face Recognition WatcherYSmartFaceVWatcher.exeToshiba's Face Recognition that allows the user login to their laptop hands-free via the built-in webcam on some modelsNo
SmartfixerXSmartFixer.exeSmartFixer rogue system error and cleaning utility - not recommendedNo
Smart KeyboardUSmartkbd.exeNetropa Smart Keyboard driverNo
SmartLauncher?SmartLauncher.exeRelated to SmartLauncher from Northstar Systems Corp. What does it do and is it required?No
SmartMenuYSmartMenu.exeIncluded on most HP Pavilion desktop and laptop PCs. "Used to launch the MediaSmart application from keyboards and remote controls. Do not disable this program" - see hereNo
Smart Protector ProUSmartProtector-Pro.exeSmart Protector Pro internet eraser from SmartSoft - "keeps out prying eyes and protects your private data on all Windows systems"Yes
SmartProtector-ProUSmartProtector-Pro.exeSmart Protector Pro internet eraser from SmartSoft - "keeps out prying eyes and protects your private data on all Windows systems"Yes
SPSTEALTUSmartProtector-Pro.exeSmart Protector Pro internet eraser from SmartSoft - "keeps out prying eyes and protects your private data on all Windows systems"Yes
smartprotectorXsmartprotector.exeSmart Protector rogue security software - not recommended, removal instructions hereNo
SPSTEALTUSmartProtectorPro.exeSmart Protector Pro - internet privacy tool that erases tracks, MRU lists, etcNo
smartprotectXsmartprotect_up.exeSmartProtect rogue security software - not recommended, removal instructions hereNo
SmartRankingXSmartRanking.exeDetected by Malwarebytes Anti-Malware as Adware.Korad. The file is located in %ProgramFiles%\SmartRankingNo
SmartSecurityXSmartSecurity.exeSmart Security rogue security software - not recommended, removal instructions hereNo
SmartSoft PDF Printer AgentNSmartSoft PDF Printer Agent.exeVirtual printer agent for Smart PDF Creator from SmartSoftNo
Extend-Supporter-totalvaccineXsmartsupporter_totalvaccineEx.exeTotalVaccine rogue security software - not recommendedNo
SmartSync ProUSmartSync.exeRelated to CompanionLink Software Inc. Synchronization solutions for ACT!, GoldMine, Lotus Notes and Microsoft OutlookNo
SmartToolXSmartTool.exeDetected by Kaspersky as AdWare.NSIS.SideTab.aNo
smartvaccineXsmartvaccineu.exeDetected by Malwarebytes Anti-Malware as Rogue.K.SmartVaccine - not recommended. One of the OneScan family of rogue scanner programsNo
SmartWebXsmartweb.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%\My UserProgramsNo
SkySurfer Management ServiceYSmaServ.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this systemNo
SmartAudioUSMAUDIO.EXEConexant SmartAudio PC audio chipset software - typically available on notebooks with built-in microphonesNo
SmAudioUSmAudio.exeConexant SmartAudio PC audio chipset software - typically available on notebooks with built-in microphonesNo
Smax4NSmax4.exeSystem Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control PanelYes
SoundMAXNSmax4.exeSystem Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control PanelYes
SoundMAX Control PanelNSmax4.exeSystem Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control PanelYes
SMax4PNPUSMax4PNP.exeAnalog Devices SoundMax integrated soundcard utility. Brings up the SoundMAX Control Panel when it detects if new audio devices (such as microphones, headphones, speakers, etc.) are plugged in - giving the user the option to configure them. Also required if you have custom settings for your sound, such as effects and environmentsYes
SMax4PNP ApplicationUSMax4PNP.exeAnalog Devices SoundMax integrated soundcard utility. Brings up the SoundMAX Control Panel when it detects if new audio devices (such as microphones, headphones, speakers, etc.) are plugged in - giving the user the option to configure them. Also required if you have custom settings for your sound, such as effects and environmentsYes
SoundMAXPnPUSMax4PNP.exeAnalog Devices SoundMax integrated soundcard utility. Brings up the SoundMAX Control Panel when it detects if new audio devices (such as microphones, headphones, speakers, etc.) are plugged in - giving the user the option to configure them. Also required if you have custom settings for your sound, such as effects and environmentsYes
Windows SMB ManagerXsmb32.exeAdded by the RBOT-BHZ WORM!No
smbdpmi?smbdpmi.exeIBM Netfinity Director and Universal Management Services related. What does it do and is it required?No
Backup OneXsmbguard.exeAdded by the SDBOT-MI WORM!No
SMBHelperXSMBHelper.exeDetected by Malwarebytes Anti-Malware as Trojan.Ransom. The file is located in %AppData%\Microsoft\Windows\4481No
Microsoft Internel CorporatXsmbvhost.exeAdded by a variant of the IRCBOT BACKDOOR!No
smcXsmc.exeAdded by the EBOD TROJAN! Note - this is not the valid (but now discontinued) Sygate Personal Firewall which has the same filename and is normally located in %ProgramFiles%\Sygate\SPF. This one is located in %System%No
smcYsmc.exeSygate FirewallNo
SMC ServiceYsmc.exeSygate FirewallNo
SmcServiceYsmc.exeSygate FirewallNo
SmcServicesYsmc.exeSygate FirewallNo
Sygate Personal FirewallXsmc.exeAdded by the RBOT-AZY WORM! Note - this is not the valid (but now discontinued) Sygate Personal Firewall which has the same filename and is normally located in %ProgramFiles%\Sygate\SPF. This one is located in %System%No
Sygate Personal FirewallYsmc.exeSygate Personal Firewall - now discontinuedNo
System Microsoft CoreXsmc.exeDetected by AhnLab as Win32/IRCBot.worm.23102. The file is located in %System%\inetsrvNo
Windows Update ServiceXsmcg.exeDetected by Trend Micro as WORM_SDBOT.QY and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
sacmemdsXsmcntlwio.exeAdded by the MAILBOT-BZ TROJAN!No
smcssXsmcss.exeAdded by the SCLOG-AJ TROJAN!No
System Messaging QueueXSMCSS.EXEAdded by a variant of Win32/Rbot. The file is located in %System%No
System Startup ManagerXsmcss.exeAdded by the RBOT.AMD WORM!No
Smcsta.exe?Smcsta.exeSMC Networks wireless PCI card driver. Is it required?No
SmcSVRXSmcSVR.exeAdded by the LEGMIR.JU TROJAN!No
control panelNsmctrlw.exeSystem Tray icon for a Silicon Motion LynxEM based PCI Graphics CardNo
cpssystemXsmdlsset.exeAdded by the SLAPER.P TROJAN!No
smgrXsmgr.exeAdded by an unidentified WORM or TROJAN!No
RPCall_[ComputerName]Xsmhost.exeAdded by the REDPLUT-B TROJAN!No
Smss HostXsmhost.exeAdded by the IRCBOT-ACC TROJAN!No
Spooler HostXsmhost.exeAdded by the IRCBOT.BSQ BACKDOOR!No
Microsoft Internet ExplorerXsmiissm.exeAdded by the DELF-KK TROJAN!No
SmileboxTrayNSmileboxTray.exeSystem Tray access to Smilebox photo sharing/printing serviceNo
SmileyconsNsmileycons.exeSmileycons - free smileys, emoticons and animations packageNo
Smith Micro tryNsmiptray.exeSmith Micro shared files. Comes with D-Link web camNo
SMSI LoaderNSMLoader.exeSmith Micro HotFax - fax softwareNo
Windows System Configuration LoaderXsmls.exeDetected by Trend Micro as WORM_AGOBOT.RPNo
38cb851033610a7fdb771b3c6c8b90e1Xsmm.exeDetected by Dr.Web as Trojan.DownLoader7.13935 and by Malwarebytes Anti-Malware as Trojan.MSILNo
AwoaXsmmo.exePurityScan adwareNo
smmsXsmms.exeDetected by Dr.Web as Trojan.MulDrop4.26985 and by Malwarebytes Anti-Malware as Trojan.Agent.RNDNo
Client Server Runtime ProcessXsmmss.exeBackdoor TROJAN! Possible SDBOT-GEN variantNo
Smart SecurityXSMM[random characters].exeSmart Security rogue security software - not recommended, removal instructions here. The filename is typically in the form "SM***_***.exe"No
blah serviceXsmnp.exeDetected by Trend Micro as WORM_RBOT.IZNo
WINDOWS SYSTEMXsmoc.exeAdded by the MYTOB.FU WORM!No
smodulUsmodule.exeUserMonitor from Neuber. Teachers can broadcast screen to other screens, see students screens in a network and detect unauthorized softwareNo
MicroedSoft ToolbarXSmoked.exeAdded by the RBOT-ALN WORM!No
SmoothViewNSmoothView.exeTOSHIBA Zooming Utility - allows "automatic" zoom feature in some appications, like IE, MS-Office, WMPlayer, Adobe Reader and also desktop iconsNo
SMPAutoStartUsmpdemo.exeSmart Phone Recorder demo from KenGolf.com. Answering Machine, Caller ID, Call RecordingNo
ELNKProxyXsmproxy.exeSurfmonkey adwareNo
SmpcSysUSmpSys.exe"Set Up My PC" utility supplied with some Packard Bell computersNo
ShockmachineReminderNSmReminder.exeMacromedia Shockmachine is a stand-alone application that lets users collect Macromedia Shockwave and Flash titles and play them offline. Now discontinued. Could be a registration reminder for the trial version?No
smresXsmres.exeAdded by the AGOBOT-UA WORM!No
Ethernet DriversXsmrrs.exeAdded by the RBOT-AAK WORM!No
vsadminXsmrs.exeAdded by the AGOBOT-RC WORM!No
smrssXsmrss.exeAdded by the BANPAES-B TROJAN!No
Smart Defender PROXsmrtdefp.exeSmart Defender PRO rogue security software - not recommended, removal instructions hereNo
smrtprtXsmrtprt.exeSmart Protector rogue security software - not recommended, removal instructions hereNo
1234Xsms.exeDetected by Dr.Web as Trojan.DownLoader1.53350 and by Malwarebytes Anti-Malware as Trojan.Agent.GenNo
(Default)Xsms.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.SM. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %AppData%No
ConnectorXsms.EXEAdded by the ExDial-B premium rate adult content dialerNo
KernelFaultChkXsms.exeAdded by the DEADHAT WORM! Do not confuse with the valid "kernelfaultcheck" which runs "dumprep 0 -k"No
Microsoft Virual MachineXsms.exeAdded by the RBOT-SP WORM!No
RunOnceExXsms.exeIESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!No
Windows Messages ControlerXsms.exeDetected by Dr.Web as Trojan.StartPage.47023 and by Malwarebytes Anti-Malware as Backdoor.Agent.WMCNo
smsaXsmsa.exeDetected by Dr.Web as Trojan.Inject1.153 and by Malwarebytes Anti-Malware as Worm.IMP.Trace. Note - this entry loads from the Windows Startup folder and the file is located in %AppData%\Win88E6680FNo
smsaXsmsa.exeDetected by McAfee as Generic Downloader.x and by Malwarebytes Anti-Malware as Worm.IMP.Trace. Note - this entry loads from the Windows Startup folder and the file is located in %AppData%\Win74630177No
Configuration LoaderXsmsai.exeAdded by the SDBOT-YE WORM!No
ApplicationProtocolRunXsmsbvl32.exeAdded by the IRCBOT-CX TROJAN!No
ShellXsmsc.exeAdded by the BANCBAN-OY TROJAN!No
Sonic RecordNow!Xsmsc.exeAdded by a variant of W32/Sdbot.wormNo
System Management ServiceXsmsc.exeAdded by the RBOT-ANN WORM!No
Win32 USB2 DriverXsmsc.exeDetected by Trend Micro as WORM_SDBOT.FONo
Windows ServicesXsmsc.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.GenNo
WINDOWS SYSTEMXsmsc.exeAdded by the MYTOB-BR WORM!No
Windows System ManagerXsmsc.exeAdded by a variant of Win32/RbotNo
WSSVCXsmsc.exeAdded by the AUTORUN-AGA WORM!No
EventApplicationCmdXsmschk.exeAdded by the IRCBOT-AO TROJAN!No
SmsDiscountNSmsDiscount.exeSmsDiscount - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular SkypeYes
GLSetT32Xsmsiexec.exeAdded by the OPTIX-D TROJAN!No
Windows System Manager LoaderXsmsls.exeDetected by Trend Micro as WORM_AGOBOT.TFNo
smsmXsmsm.exeAdded by the BANKER-CO TROJAN!No
SMS Win9x Message AgentUSMSMsg.exeThis program assigns a user to a Systems Management Server siteNo
WINTASK DLL32Xsmsrss.exeAdded by the MYTOB.BS WORM!No
run=Ysmsrun16.exeMicrosoft Systems Management Server (SMS) related - program that reads SMSRUN16.INI on clients running Win 3.1, Windows for Workgroups, Win95, or OS/2 to create program groups on the client and then launch SMS client programsNo
smsrvXsmsrv.exeAdded by the AGOBOT-SX WORM!No
 Services.dllXsmss.exeAdded by the SOBER-L WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\system and note the space at the beginning of the "Startup Item" fieldNo
 winsystem.sysXsmss.exeAdded by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\win32 and note the space at the beginning of the "Startup Item" fieldNo
.nvsvcXsmss.exeAdded by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!No
_Services.dllXsmss.exeAdded by the SOBER-L WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\systemNo
_winsystem.sysXsmss.exeAdded by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\win32No
ac81fa871a4336b2440cb3826cd12647Xsmss.exeDetected by Dr.Web as Trojan.DownLoader7.21651 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%No
AntiVirXsmss.exeDetected by Sophos as Troj/DwnLdr-GWE and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%No
AutoUpdateXsmss.exeAdded by WINSPY.88! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64No
baiduXsmss.exeAdded by the AGENT-FV MALWARE! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\dmczNo
BreakPoint SoftwareXsmss.exeDetected by Dr.Web as Trojan.Siggen.13737 and by Malwarebytes Anti-Malware as Backdoor.Agent.SF. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Windows NTNo
ChromeXsmss.exeDetected by McAfee as Generic BackDoor!fpl and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\InstallDirNo
DebugXSMSS.exeDetected by Symantec as Adware.DreamAd. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
DHCPXsmss.exeDetected by Kaspersky as Monitor.Win32.WinSpy.88. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\displayNo
ExplorerXsmss.exeDetected by McAfee as Generic BackDoor!fpl and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\InstallDirNo
fa3c99036e85131dab81f132665aa15aXsmss.exeDetected by Dr.Web as Trojan.DownLoader7.23039 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
flashgetXsmss.exeAdded by the DROPPR.SMAB TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\20111027\255qlw2anwq2ewte and note the space at the beginning of the "Startup Item" fieldNo
FrameWorkServiceXsmss.exeAdded by the KUKOO-A WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\InfNo
HKCUXsmss.exeDetected by McAfee as RDN/Generic.bfr!h and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "schost" sub-folderNo
HKLMXsmss.exeDetected by McAfee as RDN/Generic.bfr!h and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "schost" sub-folderNo
infoXsmss.exeAdded by the VB.EIW WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\inetsrvNo
INTELXsmss.exeDetected by McAfee as Generic.IL and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
InteliSysXsmss.exeAdvertisingvision adware. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
internetXsmss.exeAdded by the MIFENG-K TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!No
Kernel Safe ModeXsmss.exeAdded by the 78CRACK-A TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
KernellApps32Xsmss.exeDetected by Sophos as Troj/Bancban-AN and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!No
LiveUpdateXsmss.exeAdded by the VB.BAU BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isasNo
MDSA Sentinel XUsmss.exeSentinelX surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the smss.exe process which is always located in %System%. This one is located in %ProgramFiles%\MDSA SoftwareNo
Microsoft Session Manager SubsystemXsmss.exeAdded by the KALEL-D WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!No
Microsoft Windows Session Manager SubsystemXsmss.exeAdded by the PROXYSER-R TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
MULTIMEDIA KEYBOARD88Xsmss.exeAdded by the SILLYFDC WORM! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!No
NarmonVirusAntiXsmss.exeAdded by the AUTORUN-DV WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolderNo
NT_AuthorityXsmss.exeAdded by the SILLYFDC-EY WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
PoliciesXsmss.exeDetected by McAfee as RDN/Generic.bfr!h and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "schost" sub-folderNo
Remove 54tr10Xsmss.exeDetected by Sophos as W32/Brontok-CH and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%No
RPCserv32gXSMSS.EXEDetected by Trend Micro as WORM_BOBAX.AD. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
Service ProcessXsmss.exeAdded by the DCMBOT-E TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "config" subfolderNo
Services ProcessXsmss.exeAdded by the SMALL-EK TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "config" subfolderNo
smssXsmss.exeAdded by the AGENT-TR TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
smssXsmss.exeAdded by the BOROBOT-J TROJAN and variants! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!No
SMSSXsmss.exeAdded by the FLOOD.F BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "Catroot" subfolderNo
smssXsmss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\MicrosoftNo
smssXsmss.exeDetected by Dr.Web as Trojan.DownLoader6.24391 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
smssXsmss.exeDetected by Microsoft as Worm:Win32/Racos.A and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\fontsNo
smssXsmss.exeDetected by Symantec as Trojan.Syginre and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%No
Smss.exeXsmss.exeDetected by Symantec as W32.Dalbug.Worm. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
smssLevel4Xsmss.exeUnidentified malware! ! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Windows Media Player\Skins\WindowsMediaSkin\Data\Level4No
Spooler Subsystem ApplicationXsmss.exeAdded by the IRCBOT-ZO TROJAN! Note - the legitimate smss.exe process should not normally figure in Msconfig/Startup!No
ssystemsXsmss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
SystemXsmss.exeAdded by the AGENT.EP BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
SYSTEM MONITORINGXSMSS.EXEDetected by McAfee as Generic VB.i and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%\WINDOWSNo
System Session ManagerXsmss.exeAdded by the KALEL-E WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!No
SysUtilsXsmss.exeAdded by the AUTORUN-AWW WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%No
Tok-CirrhatusXsmss.exeDetected by Sophos as W32/Brontok-A and variants! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%No
Tok-Cirrhatus-2784Xsmss.exeDetected by Sophos as W32/Brontok-S. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%No
Torjan ProgramXsmss.exeAdded by the WOWCRAFT.B TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
userinitXsmss.exeDetected by Sophos as Troj/Dloadr-B and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
VB and VBA Program SettingsXsmss.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
VirscannerXsmss.exeDetected by Sophos as Troj/DwnLdr-GWE and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
WindowsXsmss.exeAdded by the BANCBAN-QF TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
WindowsXsmss.exeAdded by the AUTOIT.AQH TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
Windows Font ManagerXsmss.exeAdded by the ZANAYAT.B WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\fontsNo
Windows Media CenterXsmss.exeAdded by the WARBOT TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
Windows Session Manager SubsystemXsmss.exeAdded by the KALEL-B WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!No
WinDOwsUPdateXsmss.exeAdded by the AUTORUN.DIB WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolderNo
winsmssXsmss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
zsmsXsmss.exeAdded by the BANCOS-CK TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
zsmssXsmss.exeAdded by the BANCOS-DD TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
Configuration LoaderXsmss32.exeAdded by the AGOBOT.MB WORM!No
Graphic DriverXsmss32.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
loadMefsXsmss32.exeAdded by the FLOOD-EL TROJAN!No
Microsoft DirectXXSMSS32.exeAdded by the SDBOT-FP WORM!No
Microsoft Internet ServicesXsmss32.exeAdded by the RBOT.MS WORM!No
Microsoft ServicesXSmss32.exeAdded by the RBOT-AD WORM!No
Microsoft UpdateXSmss32.exeAdded by the RBOT-CB WORM!No
MSConfig32Xsmss32.exeAdded by the FLOOD-EL TROJAN!No
smss32.exeXsmss32.exeAdded by the FAKEAV-ATH TROJAN!No
UsbDXsmss32.exeAdware - detected by Kaspersky as the AGENT.CJ TROJAN!No
Windows Session ManagerXsmss32.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
Session Manager SubsystemXsmssa.exeAdded by the RBOT-AGS WORM!No
.nvsvcbXsmssb.exeAdded by the BOXED.CG TROJAN!No
Windows UpdateXsmsscr.exeDetected by Sophos as Troj/Banker-DK and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
SMS ServerXsmsserv.exeAdded by the RBOT-4 WORM!No
System Config ManagerXsmssl.exeAdded by the AGOBOT-ZJ WORM!No
MSNXsmsss.exeAdded by the BUZUS-D WORM!No
SMSSSXsmsss.exeAdded by the SDBOT.ZD WORM!No
SMSSS LoaderXsmsss.exeDetected by Trend Micro as WORM_AGOBOT.MQNo
start uploadingXsmsss.exeAdded by a variant of the SDBOT BACKDOOR!No
SMSSUXSMSSU.EXEAdded by the STARTPAGE.O TROJAN!No
Audoi Device LoaderXsmssv.exeAdded by the AGOBOT-ZY WORM!No
eczsorsXsmssvc.exeDetected by McAfee as Generic Dropper and by Malwarebytes Anti-Malware as Trojan.AgentNo
My AppXSMSSvc.exeAdded by the NEGASMS.A TROJAN!No
Sms System32XSmsSystem32.exeUnidentified malwareNo
[random]Xsmssz.exeDetected by Malwarebytes Anti-Malware as Spyware.OnlineGames.SMGen. The file is located in %System% - see examples here and hereNo
Startup ManagerUsmstartUp manager.exeStartup Manager from the Advanced System Optimizer utility suite by Systweak IncNo
SMSTrayUSMSTray.exeSystem tray access to the Emodio (or the older Samsung Media Studio) management application for Samsung MP3 playersNo
SMSvc32Xsmsvc32.exeAdded by the AGOBOT-OL WORM!No
AhnLab V3Lite Update ProcessXSMSvcHost.exeDetected by McAfee as RDN/Generic.bfr!y and by Malwarebytes Anti-Malware as Trojan.Zbot.DTGen. Note - this is not a legitimate AhnLab V3 entryNo
Windows serverXsmsvr.exeDetected by Trend Micro as WORM_MEPAOW.LXNo
SMSystemAnalyzerUSMSystemAnalyzer.exePart of the Iolo System Mechanic optimization toolNo
sms_msnXsms_msn.exeAdded by an unknown WORM or TROJAN!No
sms_msn40Xsms_msn40.exeAdded by an unknown WORM or TROJAN infectionNo
SmtUSMT.exeWin-Spy keyboard logger/monitoring software - remove unless you installed it yourselfNo
SMToolbarNSMToolbar.exeStartMake.com toolbarNo
SMTP32 Mailing ProtocolXsmtp32.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
SmappXSmtray.exeDetected by Dr.Web as Win32.HLLW.Autoruner1.27603 and by Malwarebytes Anti-Malware as Trojan.Kryptik. Note - this is not the legitimate System Tray icon for Analog Devices SoundMax integrated soundcards which is typically located in %ProgramFiles%\Analog Devices\SoundMAX. This one is located in %AppData%\SoundMAXNo
SmappNSmtray.exeSystem Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel. Typically located in %ProgramFiles%\Analog Devices\SoundMAXYes
SMTrayNSmtray.exeSystem Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel. Typically located in %ProgramFiles%\Analog Devices\SoundMAXYes
SoundMAX Integrated Digital AudioNSmtray.exeSystem Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel. Typically located in %ProgramFiles%\Analog Devices\SoundMAXYes
iolo Utility BarNSMUtilityBar.exeUtility Bar from older versions of Iolo's System Mechanic tune-up utility suiteNo
ActiveXUpdateXsmvss.exeAdded by the DEDLER-C TROJAN!No
devenvXsmvss.exeAdded by the HORST TROJAN!No
MicrosoftOEMXsmvss.exeAdded by the DEDLER-G TROJAN!No
MSInstallXsmvss.exeAdded by the DEDLER-G TROJAN!No
OfficeGuardUIXsmvss.exeAdded by the DEDLER-C TROJAN!No
SoundControlXsmvss.exeAdded by the DEDLER-C TROJAN!No
SoundMixerXsmvss.exeAdded by the DEDLER-G TROJAN!No
SunJavaUpdateXsmvss.exeAdded by the DEDLER-G TROJAN!No
CM-SmWizard?SmWizard.exeSmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required?No
SmWizard?SmWizard.exeSmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required?No
csrssXsmxss.exeDetected by Microsoft as TrojanDownloader:Win32/CoinMiner.E and by Malwarebytes Anti-Malware as Trojan.AgentNo
LocalSysXsmxss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Root%\Users\PublicNo
Security Master AVXSM[random characters].exeSecurity Master AV rogue security software - not recommended, removal instructions hereNo
Smart EngineXSM[random characters].exeSmart Engine rogue security software - not recommended, removal instructions here. The filename is typically in the form "SM***_***.exe"No
Smart Virus EliminatorXSM[random characters].exeSmart Virus Eliminator rogue security software - not recommended, removal instructions hereNo
smXsm_exe.exeAdded by the OLFEB.A TROJAN!No
SnagIt 10NSnagIt32.exe"SnagIt by TechSmith - lets you capture, edit, and share exactly what you see on your screen - fast"No
SnagIt 5NSnagIt32.exe"SnagIt by TechSmith - lets you capture, edit, and share exactly what you see on your screen - fast"No
SnagIt 6NSnagIt32.exe"SnagIt by TechSmith - lets you capture, edit, and share exactly what you see on your screen - fast"No
SnagIt 7NSnagIt32.exe"SnagIt by TechSmith - lets you capture, edit, and share exactly what you see on your screen - fast"No
SnagIt 8NSnagIt32.exe"SnagIt by TechSmith - lets you capture, edit, and share exactly what you see on your screen - fast"No
SnagIt 9NSnagIt32.exe"SnagIt by TechSmith - lets you capture, edit, and share exactly what you see on your screen - fast"No
SnakingXSnaking.VBSDetected by Kaspersky as Trojan-Dropper.Win32.Snak and by Malwarebytes Anti-Malware as Trojan.Agent.VBSNo
Snapfish Media DetectorUSnapfishMediaDetector.exeSnapfish Media Detector - "Upload your photos to Snapfish, where you can store and share your photos for free on line"No
SnapfishMediaDetectorUSnapfishMediaDetector.exeSnapfish Media Detector - "Upload your photos to Snapfish, where you can store and share your photos for free on line"No
snappleXsnapple.exeAdded by the FORBOT-EG WORM!No
snappydeeSAXsnappydeeSA.exeDetected by Malwarebytes Anti-Malware as Adware.HotBar.CP. The file is located in %AppData%\snappydeeSA\bin\[version]No
snbr?snbr.exe??No
snbuptXsnbupt.exeUpSpiralBar adwareNo
sncntrXsncntr.exeAdded by the DLUCA-I TROJAN!No
Windows AudioXsnd.exeAdded by the ACKANTTA.C WORM!No
Windows Sound EmulatorXsnd32_win.exeAdded by the ATNAS.A WORM!No
snd332Xsnd332.exeAdded by the B1LD0 AIM WORM!No
sounddrvXsndbdrv3104.exeCoolWebSearch parasite variantNo
MS Sound Config 16bitXsndcfg16.exeAdded by the SDBOT.AN WORM!No
WinProfileXsndcfg16.exeDetected by Total Defense as Win32.Sndc.ANo
SndcompatXSndcompat.exeAdded by the GEMA TROJAN!No
Ac97SoundXsnddrv.exeAdded by the VB.AXG TROJAN!No
microsystemXsnddrv.exeAdded by the VB.AXG TROJAN!No
Sound LoaderXsndloader.exeDetected by Trend Micro as WORM_AGOBOT.CCNo
SoundMax Audio DriversXSndMAX.exeAdded by a variant of W32/Sdbot.wormNo
Windows Audio ServiceXsndmic32.exeAdded by the ACKANTTA.C WORM!No
SNDMonYSNDMon.exePart of Symantec's LiveUpate for older versions of Symantec's security products including Norton Internet Security, Norton AntiVirus and the now discontinued Norton SystemWorks suite. Leave alone to ensure virus definitions are updated. Also, if SNDMon is disabled on one of the computers on a small office network then other computers disappear from the network for this computer, including shared devices like printers and scannersNo
Symantec NetDriver MonitorYSNDMon.exePart of Symantec's LiveUpate for older versions of Symantec's security products including Norton Internet Security, Norton AntiVirus and the now discontinued Norton SystemWorks suite. Leave alone to ensure virus definitions are updated. Also, if SNDMon is disabled on one of the computers on a small office network then other computers disappear from the network for this computer, including shared devices like printers and scannersNo
Windows Sound ManagerXSndMon16.exeAdded by a variant of the FORBOT WORM!No
Windows Sound DriverXSndMon32.exeAdded by a variant of the SPYBOT WORM!No
Windows Sound ManagerXSndMon32.exeAdded by the FORBOT-BU WORM!No
SndsaverXSndsaver.exeAdded by the GEMA TROJAN!No
SNDSrvcYSNDSRVC.EXECommon process for older versions of Symantec's security products including Norton Internet Security and the now discontinued Norton AntiSpam and Norton SystemWorks suite. Used for the scanning of incoming POP3 emails for viruses, threats or spam. Runs as a service on an NT based OS (such as Windows 7/Vista/XP)No
Auto StartXsndvol32.exeAdded by the SLINBOT.AX BACKDOOR! Note - the is not the legitimate MS volume control utility which is always located in %System% and should not normally figure in Msconfig/Startup!No
update driverXSNDVOL32.EXEAdded by the SPYBOT-CU BACKDOOR!No
SND VolumesXsndvolumes.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
Symantec NetDriver WarningUSNDWarn.exePart of Symantec Live Update - displays the warning when you need to update the firewall databaseNo
runXsnhcwb.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Windir%\apppatchNo
SystemWizard SnifferUSniffer.exeSystemWizard for Win98/ME from SystemSoft - diagnoses and solves hardware and software problems on a PCNo
SnippetUSnippingTool.exeThe Snipping Tool (part of the Experience Pack for Tablet PC) allows you to easily "cut out" anything on screen and share it with other people. The whole screen becomes an "inkable" surface that you can add comments to and mark up however you like. You can then save that annotated image to use later, or send it to someone else in an E-mail messageNo
Microsoft UpdateXsnlogsvc.exeAdded by the SDBOT.CN BACKDOOR!No
SNMUSNM.exeSpyNoMore spyware remover - previously not recommended, see hereNo
InomXsnmoo.exeAdded by the RBOT-DPM WORM!No
SysTrayXSnnpapi.exeDetected by SUPERAntiSpyware as Trojan.SNNPAPI.Process. The file is located in %System%No
SnoopUSnoop.exeSnoop surveillance software. Uninstall this software unless you put it there yourselfNo
SystempXsnoop.exeDetected by Dr.Web as Trojan.Siggen4.1076 and by Malwarebytes Anti-Malware as Trojan.AgentNo
SnoopFreeUIUSnoopFreeUI.exeSnoopFree Privacy Shield SnoopFree Software - anti-keylogging softwareNo
Snow.exeXSnow.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.Gen. The file is located in %AppData%No
snqpuXsnqpu.exeDetected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\plusupNo
SnsiconNSnsicon.exeLaunches a screensaver program from Second NatureNo
SNSS.EXEXSNSS.EXENunci premium rate dialerNo
stryvertionXsnss.exeDetected by Dr.Web as Trojan.DownLoader8.21719 and by Malwarebytes Anti-Malware as Trojan.DownloaderNo
Dot.net NetworkingXSNSS32.EXEDetected by Trend Micro as WORM_RBOT.BOINo
ClassesXsnt.exeQuickPage - Switch dialer and hijacker variant, see here. Also detected as the SWITCH-A TROJAN!No
DiskstartXSnt.exeStartportal - Switch dialer and hijacker variant, see here. Also detected as the DELF-JE TROJAN!No
OpenMstartXSnt.exeMStart2Page - Switch dialer and hijacker variant, see here. Also detected as the SWITCH-E TROJAN!No
Windows Event SectionXsntsvc.exeAdded by a variant of the IRCBOT TROJAN! See hereNo
SysnetXsnuninst.exeUnidentified adwareNo
snvcXsnvc.exeAdded by an unidentified WORM or TROJAN!No
Application In SystemXSnxmsh.exeAdded by the AGENT-LNV TROJAN!No
SNyOgdLFyXub.exeXSNyOgdLFyXub.exeDetected by Malwarebytes Anti-Malware as Trojan.Foury. The file is located in %CommonAppData%No
SecureOnlineAccountNumbersUSOAN.exeRelated to Secure Online Account Numbers by Discover(R) Card from Orbiscom Ltd. Secure and innovative payment solutionsNo
System Soap ProXsoap.exeSystem Soap Pro internet cleaning software. Bundles foistware like Httper and Zipclix - best avoidedNo
Norton Live UpdaterXSochost.exeDetected by Symantec as W32.HLLW.Gaobot.AONo
Social.IMNSocialChat.exeSocial.IM Facebook instant messenger by iSkoot Inc - no longer availableNo
ZoneAlarm SocialGuardUSocialGuard.exeZoneAlarm SocialGuard advanced security for Facebook - "scans millions of records using a unique algorithm to determine threats and sends warnings to you the minute they happen, not just once a day like the competition"Yes
ZoneAlarm SocialGuardUSOCIAL~1.EXEZoneAlarm SocialGuard advanced security for Facebook - "scans millions of records using a unique algorithm to determine threats and sends warnings to you the minute they happen, not just once a day like the competition"Yes
Sock32Xsock32.exeAdded by the SDBOT BACKDOOR!No
Socket UtilityXsocket.exeAdded by the DAEMONI-E TROJAN!No
Microsoft standard protectorXsocks.exeDetected by Spybot-S&D as Tibs.vq. The file is located in %Windir%\inet200[2 digits]No
servicesXsocks.exeAdded by the WIN32.SMALL.N TROJAN!No
ASocksrvXSocksA.exeAdded by the VB.CBW WORM!No
blah serviceXsocksxt.exeAdded by a variant of Win32/RbotNo
ServicesXsockys32.exeAdded by the RANKY.L TROJAN!No
SoDA StartupYSodaStartup.exeUsed by the IBM Rational SoDA project management tool. Unsure of it's actual purpose but it's recommended you leave it enabled if you use the softwareNo
Microsoftf DDEs ControlXsoff.pifAdded by the RBOT-AKH WORM!No
sofficeNSOFFICE.EXEPart of StarOffice by StarDivision - a proprietary office suite and the predecessor of OpenOffice. Displays the quick start applet in the System Tray. Right clicking on the icon allows rapid starting up of components of the StarOffice suite. Automatically started when any StarOffice component is run from the Start menu and is a resource hog (it uses more than 16 MB of memory)No
soft2PCXsoft2pc.exeDetected by Malwarebytes Anti-Malware as Adware.EoRezoNo
SoftAuto.exeNSoftAuto.exeAuto-updater for Creative Labs softwareNo
SoftBarrierXSoftBarrier.exeSoftBarrier rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
SoftCopXSoftCop.exeSoftCop rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
SoftDiscNsoftdisc.exeSoftDisc by EZB Systems, Inc - "is an image file creating/editing/managing tool. It also lets you emulate a virtual CD or directly burn a CD image file - that is handy when you, for example, need a CD in use when playing a game"No
Service SystemXsoftdwind.exeAdded by the BANCOS-JS TROJAN!No
hErcUnesXsofthost.exeAdded by the GARROCH WORM!No
Software InformerNsoftinfo.exeSoftware Informer Client by Informer Technologies, Inc - "is a program that has been specially designed for those users who care to keep their applications functional and ready for any task that may arise. Its primary aim is to give you up-to-date information about the software you actually use"No
SoftloadXsoftload.exeAdded by the SDBOT-SV WORM!No
aaLDSoftMonUSoftMon.EXELANDesk® Management Suite software componentNo
csoftokXsoftok.exeAdded by the QQPASS.G TROJAN!No
SoftSafenessXSoftSafeness.exeSoftSafeness rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
SoftSoldierXSoftSoldier.exeSoftSoldier rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
SoftStrongholdXSoftStronghold.exeSoftStronghold rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
SoftStuff Wallpaper ChangerUsoftstrt.exeAzureBay wallpaper changerNo
SoftVeteranXSoftVeteran.exeSoftVeteran rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
SoftwareXsoftware.exeAdded by the CRABTON-B TROJAN!No
HelperXsoftwareHP.exeDetected by Malwarebytes Anti-Malware as Adware.EoRezo. The file is located in %AppData%\Soft2PC\SoftwareNo
UpdateTuto4PCHPXSoftwareHP.exeDetected by McAfee as Adware-Tuto4PC and by Malwarebytes Anti-Malware as Adware.EoRezoNo
Modulo UpdateXSoftwareUpdateHP.exeDetected by Malwarebytes Anti-Malware as Adware.EoRezo. The file is located in %AppData%\EoRezo\EoRezoNo
SoftwareHelperXSoftwareUpdateHP.exeDetected by Malwarebytes Anti-Malware as Adware.EoRezo. The file is typically located in %AppData%\EoRezo\EoRezo or %AppData%\EoRezo\SoftwareUpdateNo
BALLXSogou.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.SG. The file is located in %CommonFiles%No
BallXSogou.exeDetected by Dr.Web as Trojan.DownLoader7.24194 and by Malwarebytes Anti-Malware as Trojan.ChinAdNo
hao567XSogou.exeDetected by Dr.Web as Trojan.DownLoader6.62518 and by Malwarebytes Anti-Malware as Backdoor.ZegostNo
systenXSogou.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor. The file is located in %CommonFiles%No
xiaoyuXSogou.exeDetected by Dr.Web as Trojan.DownLoader7.26386No
IDO PortXSogouPinyinUp.exeDetected by McAfee as BackDoor-AWQNo
Iomega StorCenter?sohoclient.exeRelated to the Iomega StorCenter range of networked storage productsNo
SO5 Integrator Pass One?sointgr.exePart of StarOffice 5 by StarDivision - a proprietary office suite and the predecessor of OpenOfficeNo
SO5 Integrator Pass Two?sointgr.exePart of StarOffice 5 by StarDivision - a proprietary office suite and the predecessor of OpenOfficeNo
CHIPDRIVEPinManagerUsokscmpn.exeChipDrive Smartcard softwareNo
MsconfigeXsolari.exeAdded by the AUTORUN-GU WORM!No
SolidCaptureNsolidcapture.exeSolidCapture - screen capture and image sharing toolkitNo
Solid Key LoggerUSolidKeyLogger.exeSolid Key Logger keystroke logger/monitoring program - remove unless you installed it yourself!No
SoloScheduleUSolocfg.exeScheduler for Solo Antivirus. Leave enabled unless you scan manually on a regular basisNo
Solo SentryYSolosent.exeSolo AntivirusNo
somaticXsomatic.exeSearchcentrix hijackerNo
BLABXsomi3.exeDetected by Malwarebytes Anti-Malware as Backdoor.Messa. The file is located in %AppData%\soni3No
msn.exeXson.exeAdded by the STARTPA-GS TROJAN!No
sbitunesagentNsongbirditunesagent.exe"Manage you music and videos, build playlists, browse, search, and sort. Then sync your music to your portable music player or phone. Songbird makes it simpleNo
songsXsongs.exeAdded by the AGENT-SEG TROJAN!No
E-Color RegistrationNSonnReg.exeRegistration for Colorific® and 3Deep® monitor calibration software from E-Color. Now superseded by ColorWizzard™ and 3DxWizzard™No
SonnRegNSonnReg.exeRegistration for Colorific® and 3Deep® monitor calibration software from E-Color. Now superseded by ColorWizzard™ and 3DxWizzard™No
Ci ServsXSontiwin.exeAdded by the VB-PD MALWARE!No
SonudManXSonudMan.exeAdded by the STARTPAGE.Q TROJAN!No
SonudMonXSonudMon.exeAdded by the LEWOR-J TROJAN!No
Image TransferNSonyTray.exeSony Image Transfer software provides direct image transfer from your digital camera to a PC - can be started manuallyNo
Picture Package MenuNSonyTray.exeSystem Tray access to Sony "Picture Package®" software for their range of Digital Handycam video camerasNo
SonyVaioXSonyVaio.exeDetected by Malwarebytes Anti-Malware as Trojan.VBKrypt. The file is located in %AppData%No
sophagnt?sophagnt.exePossibly related to Sophocles Screenwriting Software?No
MqNrGCelXZpXSorIPhcHBDl.exeDetected by McAfee as Generic.dx!bhdr and by Malwarebytes Anti-Malware as Trojan.MSILNo
REGRUNXsory.exeAdware downloader - detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!No
NasisoXsos.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%No
SOSXSOS.exeAdded by the PHILIS VIRUS!No
sos.exeXsos.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %System%No
NTSF MICROSOFT SYSTEMXsoscks32.exeDetected by Malwarebytes Anti-Malware as Backdoor.BotNo
NasisoXsosx.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.WDR. The file is located in %Windir% - see hereNo
SoSyncMonitor?SoSyncMonitor.exeSuperOffice related. What does it do and is it required?No
[Chinese characters]Xsougou.exeDetected by Dr.Web as Trojan.StartPage.45465 and by Malwarebytes Anti-Malware as Trojan.Agent.CNGen. The file is located in %Windir%\WebNo
SOUNDMAN Microsoft HelpXsoun.pifDetected by Sophos as W32/Rbot-AIUNo
AUDIOXSOUND.exeAdded by the PLOYB-A TROJAN!No
Microsoft Server ApplicationXSound.exeAdded by the RBOT-NE WORM!No
rgservsXsound.exeDetected by Dr.Web as Win32.HLLW.Autoruner1.24962 and by Malwarebytes Anti-Malware as Backdoor.Agent. The file is normally located in %AppData%No
rgservsXsound.exeDetected by Kaspersky as Worm.Win32.AutoRun.cemy and by Malwarebytes Anti-Malware as Backdoor.Agent. The file is normally located in %UserTemp%No
ServicioXsound.exeAdded by the BAMKER-FFT TROJAN!No
SoundXSound.exeDetected by McAfee as RDN/Ransom!br and by Malwarebytes Anti-Malware as Trojan.AgentNo
Sound.exe EspanhaXSound.exeAdded by the AGENT-OUD TROJAN!No
Windows Sound ManagerXsound.exeDetected by Microsoft as Worm:Win32/Gaobot.FCNo
Microsoft Sound DriverXsound32.exeAdded by a variant of the SPYBOT WORM!No
Sound servicesXSOUND32.EXEDetected by Trend Micro as WORM_AGOBOT.GGNo
[various names]Xsound64.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
Micr UpdateXsoundblaster.exeDetected by Trend Micro as WORM_SDBOT.NPNo
Logitech CameraXSoundcane.exeAdded by the SDBOT.MUC WORM!No
SoundcardAudiocodecXSoundcardAudiocodec.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%No
Configuration LoaderXsoundconf.exeAdded by the AGOBOT-MH WORM!No
soundcontrlXsoundcontrl.exeAdded by the GAOBOT.AFJ WORM!No
Compaq Sound Drivers For WINDOWSXsounddr.exeAdded by the SDBOT-XG WORM!No
Intel (R) Sound DriverXSoundDriver.exeDetected by Dr.Web as Trojan.MulDrop4.170 and by Malwarebytes Anti-Malware as Backdoor.BotNo
Microsoft Windows Sound DriversXsounddrivers.exeAdded by the SLENFBOT.ABU WORM!No
Windows Stand Sound DriversXSounddrv.exeAdded by the SDBOT-XF WORM!No
Microsoft SoundsXsoundman.exeAdded by the RBOT-GCI WORM!No
mysysXsoundman.exeAdded by the AGENT.DCJH TROJAN!No
Realtek HD Sound ManagerUSOUNDMAN.EXERealtek Sound Manager, installed with the drivers for on-board Realtek HD audio codecs. On an ALC885 based test system it doesn't run after the drivers have been installed and the startup entry is then removed. Disabling it appears to have no ill effects but it's exact purpose is unknown - hence the "U" recommendationYes
SISSoundman?Soundman.exeRelated to a Silicon Integrated Systems Corp (SiS) product?No
SoundManXsoundman.exeAdded by the AGOBOT.HM WORM! Note - this is not the legitimate SiS or Realtek file of the same name that is located in %Windir%, this one is located in %System%No
SOUNDMANXSOUNDMAN.exeDetected by Dr.Web as Trojan.MulDrop4.31106 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate SiS or Realtek file of the same name that is located in %Windir%, this one is located in %System%\dllcacheNo
SoundManUSOUNDMAN.EXERealtek Sound Manager, installed with the drivers for on-board Realtek HD and AC97 audio codecs. On an AC97 based system it gives System Tray access to the audio control panel (which is also available via the system Control Panel). On an ALC885 HD based test system it doesn't run after the drivers have been installed and the startup entry is then removed - disabling it appears to have no ill effects but it's exact purpose is unknownYes
soundman.exeXsoundman.exeAdded by the AGENT-HKD TROJAN! Note - this is not the legitimate SiS or Realtek file of the same name that is located in %Windir%, this one is located in %System%No
TaskmanXsoundman.exeAdded by the VB-ETL TROJAN! Note - this is not the legitimate SiS or Realtek file of the same name that is located in %Windir%, this one is located in the "Help" sub-folderNo
Windows Sound DriverXsoundman.exeDetected by Kaspersky as Backdoor.Win32.Rbot.gen. The file is located in %System%No
SoundMaxXSoundmax.exeAdded by the MALAS-A VIRUS! Note - this file is located in %ProgramFiles%\Sound Utility and has NO relation to SoundMax sound cards!No
SoundMAXXSoundMAX.exeAdded by the RIZON-A WORM! Note - this file is placed in the Startup folder itself, and has NO relation to SoundMax sound cards!No
SoundMAXNsoundmax.exeSystem Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel. Located in %ProgramFiles%\Analog Devices\SoundMAXNo
SoundMax.exeXSoundMax.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. Note - this file is located in %LocalAppData% and has NO relation to SoundMax sound cards!No
soundmixXsoundmix.exeDetected by Trend Micro as WORM_AGENT.PGVNo
SoundmxXSoundmx.exeCoolWebSearch Tapicfg parasite variantNo
BLUESTACKSXsounds.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.BLS. Note - this is not a legitimate BlueStacks entry and the file is located in %Windir%No
MotherBoard SoundsXSounds.exeAdded by the RBOT-AAP WORM!No
Microsoft Intrenet ExplorerXSoundsyst.exeAdded by the RBOT-AQU WORM!No
soundtaskXsoundtask.exeAdded by the AGOBOT-MD WORM!No
soundtasksXsoundtasks.exeAdded by a variant of the CRYPTER.C TROJAN!No
soundtctrlsXsoundtctrls.exeAdded by the AGOBOT-ZV WORM!No
Sound ViewXSoundView.exeDetected by Dr.Web as Trojan.MulDrop4.1089 and by Malwarebytes Anti-Malware as Trojan.MSILNo
MicrosoftXsoundvol32.exeAdded by the RBOT.CIJ BACKDOOR!No
sounoftsXsounofts.exeAdded by the AGOBOT-ND WORM!No
sountskmanagerXsountaskmgrAdded by an unidentified WORM or TROJAN!No
SP TimeSyncUSP TimeSync.exeSP TimeSync lets you synchronize your computer's clock with any Internet atomic clock (time server)No
spXsp.exeDetected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Trojan.AgentNo
spXsp.regIE search hijacker - changes the default search to http://www.gocybersearch.com/No
nwssUSp0.exeSpyOutside surveillance software. Uninstall this software unless you put it there yourselfNo
Windows Update ServiceXSP00ISS.exeDetected by Sophos as W32/Sdbot-ZH and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
huigeziXSP00LSV.EXEAdded by the GRAYBIRD.J BACKDOOR! Note the digit "0" in the commandNo
SP00LSVXSp00lsv.exeAdded by the GRAYBIRD.E TROJAN!No
(L4r1$$4) (4nt1) (V1ruz)XSP00Lsv32.pifAdded by the ASSIRAL.B WORM!No
SVCH0TSXsp00lvs.exeAdded by the LINEAGE-AZ TROJAN!No
SP1 Critical UpdateXsp1update.exeAdded by the WOOTBOT.BG WORM!No
SP1-UpdateXsp1update.exeAdded by the RBOT-JG WORM!No
FirewallXSP2 UPDATE.exeAdded by the ELITPER.E WORM!No
Fdr Command ModuleXsp2.exeAdded by the SDBOT.WP WORM!No
Microsoft Update MachineXSP2.exeAdded by the SPYBOT.FP WORM!No
WindowsSp2Xsp2.exeAdded by the POSSE WORM!No
sp2chk.exeXsp2chk.exeAdded by an unidentified WORM or TROJAN!No
SP2 Connection PatcherUSP2ConnPatcher.exeChanges the limit of concurrent TCP connections attempts imposed with Windows XP SP2 onwards. Typically installed with peer-to-peer (P2P) file-sharing clients such as Warez P2P, BearShare and LimeWireNo
SP2ConnPatcherUsp2connpatcher.exeChanges the limit of concurrent TCP connections attempts imposed with Windows XP SP2 onwards. Typically installed with peer-to-peer (P2P) file-sharing clients such as Warez P2P, BearShare and LimeWireNo
sp2ctrXsp2ctr.exeAdded by the DLUCA-M TROJAN!No
Microsoft Security ManagementXsp2fix.exeAdded by the RBOT.UB WORM!No
sp2fwxpXsp2fwxp.exeAdded by the SMALL.ABW TROJAN!No
Win SSLXSP2s.exeDetected by Trend Micro as WORM_RBOT.BBINo
sp2svcXsp2svc.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
ATIVIRUSUPDATEBXSp2SYs.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %System%\msSP2No
sdfsdfsdfXsp2update.exeAdded by a variant of the SPYBOT WORM!No
sp2updateXsp2update.exeSP2Update adware! Tracks URLs visited and search terms entered into Internet ExplorerNo
Windows SP2 UpdateXSp2update.exeAdded by the WOOTBOT.BS WORM!No
Microsoft (R) Windows Network Latency ControllerXsp2vc.exeAdded by a generic password stealer TROJAN - see hereNo
WINTASKMGRXsp2winfix.exeAdded by the MYTOB.KJ WORM!No
Winsock32driverXsp2XPupdate.exeAdded by the HACKARMY.S BACKDOOR!No
Win386Xsp32.dllHomepage hijacker. Not a dll but a regfile in disguiseNo
Microsoft Updates 5 USBXsp3fixer.exeAdded by the RBOT-ADS WORM!No
GBSpaceManYSpaceMan.exeGreenBorder - secure your browsing activities on the internetNo
NegativeXspain.exeAdded by the BANKER-EXJ TROJAN!No
spamihilatorUspamihilator.exeSpamihilator - spam filterNo
MSKExeUspamkiller.exeMcAfee SpamKiller - a rule-based and list-based spam filterNo
Spam MonitorUSpamMonitor.ExeSystem Tray access to Spam Monitor from PC Tools - which "is an easy-to-use spam filter that detects and isolates unsolicited junk mail sent to your mailbox. Designed for computer users, not experts, Spam Monitor's step-by-step wizard configures your PC with the safest anti-spam settings automatically"Yes
SpamMonitorUSpamMonitor.ExeSystem Tray access to Spam Monitor from PC Tools - which "is an easy-to-use spam filter that detects and isolates unsolicited junk mail sent to your mailbox. Designed for computer users, not experts, Spam Monitor's step-by-step wizard configures your PC with the safest anti-spam settings automatically"Yes
SpamMonitor ApplicationUSpamMonitor.ExeSystem Tray access to Spam Monitor from PC Tools - which "is an easy-to-use spam filter that detects and isolates unsolicited junk mail sent to your mailbox. Designed for computer users, not experts, Spam Monitor's step-by-step wizard configures your PC with the safest anti-spam settings automatically"Yes
SpamPalUspampal.exeSpamPal - anti-spam toolNo
Spam SleuthUSpamSleuth.exeSpam Sleuth E-mail spam detection programNo
spamsubtractUSpamSub.exeInterMute™ SpamSubtract - junk email detection and removal program. InterMute™ is now part of Trend Micro and their products are no longer supportedNo
SpamSubtractUSpamSubtract.exeIntermute SpamSubtract - junk email detection and removal programNo
Anti Spam ServiceXspamsvc.exeAdded by the MYTOB-BK WORM!No
Spare BackupUSpareBackup.exeSpare Backup - "Once Spare Backup is installed, backups are automatic. With Spare Backup it's easy, you don't even have to select files for backup, Spare Backup does it for you"No
SparkUSpark.exeSpark instant messaging clientNo
SparVoipNSparVoip.exeSparVoip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular SkypeYes
NasisoXspcezof.exeDetected by Dr.Web as Trojan.Inject1.11387 and by Malwarebytes Anti-Malware as Trojan.AgentNo
Systems RestartXspchost.exeAdded by an unidentified WORM or TROJAN!No
TaskListXSPCHOSTS.EXEDetected by Dr.Web as Trojan.DownLoader5.45485No
Speaking Clock DeluxeUSpClDlx.exeSpeaking Clock Deluxe - turns your computer into a speaking clock with several languages. It can also keep track of up to 50 alarms that can be set to a time and a date, and be repeated daily, weekly, monthly and yearlyNo
Service Pack DLL RuntimeXspdll32.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
SPD DriverXspdpool.exeAdded by the BCKDR-REA BACKDOOR!No
SpdstartNSpdstart.exeNorton Utilities Speed Start. "This feature optimizes the start up speed of launching applications, such as Word and Excel."No
DSL MonitorNspdstrm.exeComes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system trayNo
pcEXPLODEXspecialfile.exeDetected by Trend Micro as WORM_RBOT.RHNo
specialguardstart.exeXspecialguardstart.exeSpecialGuard rogue security software - not recommended, removal instructions hereNo
SpecialOffersXSpecialOffers*.exe [* = digit]SpecialOffers adwareNo
SpecialOffersXSpecialOffers.exeSpecialOffers adwareNo
specialvaccinestart.exeXspecialvaccinestart.exeSpecialVaccine rogue security software - not recommended, removal instructions hereNo
specificXspecixic.exeAdded by a variant of W32/Sdbot.wormNo
FastTrack AcceleratorNSPEED UP.EXEFastTrack Accelerator - "speedup" utility for programs that use the FastTrack network such as KaZaA Media Desktop, Grokster and MorpheusNo
d9bae609eb51f8ca1766366d36a7ee5dXSpeeD-UP.exeDetected by McAfee as RDN/Generic PUP.x!qk and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJNo
4d1b0684289ba8306488bf50cb53da98Xspeed.exeDetected by Dr.Web as Trojan.DownLoader7.4194 and by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Temp%No
DRIVER_XSPEED.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %Windir%No
SDStartXspeeddownupgrade.exeDetected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %AppData%\speeddownNo
SDup2StartXspeeddownuphp.exeDetected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %AppData%\speeddownNo
SpeedItUpUSPEEDITUP.EXESpeed It Up - "all in one Speed Booster designed to significantly increase the speed of your computer and boost your PC available memory". Installs PC-Checkup and Search Defender (which is detected by DrWeb as the STARTPAGE.ORIGIN TROJAN) without permissionNo
SpeedItUpEXUSpeedItUpEx.exe"Speed-It-Up Extreme is designed to speed of your computer up to 3 times faster and boost your PC available memory"No
Microsoft Intellitype ProUspeedkey.exeAdditional keyboard shortcuts on MS programmable keyboardNo
SpeedkeyUSPEEDKEY.EXEAdditional keyboard shortcuts on MS programmable keyboardNo
SpeedMeterUSpeedMeter.exeApplication measuring upload and download speedNo
T-DSL SpeedMgrNspeedmgr.exeT-Online ISP SpeedManager - shows upload and download speed. Also checks for updates automaticallyNo
SpeedRunnerXSpeedRunner.exeIdentified as a variant of the TrojanDownloader.Matcash malwareNo
SpeedswitchXPUSpeedswitchXP.exeSpeedswitchXP is a CPU frequency control for notebooks running Windows XPNo
Speed TecUspeedtec.exeAccel SpeedTec from Montana Software speeds up your modem. SpeedTec modifies the Internet Protocol settings in the Windows registry to speed downloads on all modems. If you find this improves your connectivity and download speeds leave this enabledNo
SpeedUpMyPCUspeedupmypc.exeOlder version of SpeedUpMyPC from Uniblue Systems Limited - which "lets you monitor and control all your PC resources with easy, one click instructions. System settings, internet usage, disk clutter, RAM and CPU are all automatically scanned, cleaned and optimized for peak performance"Yes
Uniblue SpeedUpMyPCUSpeedUpMyPC.exeOlder version of SpeedUpMyPC from Uniblue Systems Limited - which "lets you monitor and control all your PC resources with easy, one click instructions. System settings, internet usage, disk clutter, RAM and CPU are all automatically scanned, cleaned and optimized for peak performance"No
SpeedUpMyPCUSPEEDU~1.EXEOlder version of SpeedUpMyPC from Uniblue Systems Limited - which "lets you monitor and control all your PC resources with easy, one click instructions. System settings, internet usage, disk clutter, RAM and CPU are all automatically scanned, cleaned and optimized for peak performance"Yes
Systam13Xspeedwin.exeAdded by the RBOT.GVH BACKDOOR!No
Spees2XSpeedy.batAdded by the OPASERV.AD WORM!No
Spees3XSpeedy.pifAdded by the OPASERV.AD WORM!No
Spees1Xspeedy.scrAdded by the OPASERV.Y WORM!No
SpeenusXspeenusup.exeDetected by Dr.Web as Trojan.DownLoader6.2897 and by Malwarebytes Anti-Malware as Adware.K.LineLinkNo
WindowsxpXSpeicher-77.exeDetected by Dr.Web as Trojan.MulDrop4.14463 and by Malwarebytes Anti-Malware as Trojan.DropperNo
FileProtectorXspfirewall.exeDetected by McAfee as MultiDropper-SG and by Malwarebytes Anti-Malware as Trojan.AvkillNo
spywarefighterguardUspfprc.exeSpyware Fighter - anti spyware programNo
smcYspfsmc.exeSygate FirewallNo
SMC ServiceYspfsmc.exeSygate FirewallNo
SmcServicesYspfsmc.exeSygate FirewallNo
zSPGuardUSpguard.exe"StartPage Guard (SPG) protects your PC from cyberscam, by detecting and preventing any unauthorized changes to your internet browser's Start and Search pages. It is also capable of removing automatically most of known 'invaders'."No
Windows FirewalllXsphost.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
SpiceworksUspicetray_silent.exeSystem Tray access to Spiceworks - which "combines everything you need to manage IT in one easy-to-use application"No
SpIDerMailYspiderml.exeDrWeb antivirus Spider Mail e-mail scannerNo
SpiffyUspiffy.exeSpiffy Gmail notifier - email notification utilityNo
Spinner PlusNspinner.exe"Spinner Plus lets you listen to over 100 channels of music broadcast from Spinner.com. Spinner Plus uses RealNetwork's G2 technology to provide high-quality online audio. The technology adjusts the audio streaming to match your Internet connection speed, which helps eliminate sound distortion or choppiness". Available via Start → ProgramsNo
MVS SplashNSplash.exeSplash screen for the now obsolete McAfee Managed VirusScan anti-virus and anti-spyware security tool for small businessesNo
myCIO.com SplashNSplash.exeSplash screen for the now obsolete McAfee VirusScan ASaP online anti-virus and anti-spyware security tool for small businessesNo
Introducing Media ManagerNSPLASHA.EXEMS Media Manager tour. Not requiredNo
TabletWizardUSPLSHWRP.EXEMicrosoft Tablet PC ComponentNo
StationPlaylistStudioUSPLStudio.exeStationPlaylist Studio - "simple to use on-air broadcast playback software for the studio and/or DJ" for small to medium sized radio broadcasters, and internet webcastersNo
splwow32Xsplwow32.exeAdded by the DLDR-FC TROJAN!No
SSS6_SPM?spm.exePart of the Security Suite 6 set of data protection utilities from Steganos - now superseded by Privacy SuiteNo
SonyPowerCfgUSPMgr.exeRelated to Sony VAIO Power Management Module installed on laptops and provides additional configuration options for these devicesNo
PC Speed MaximizerUSPMLauncher.exePC Speed Maximizer optimization utility from Avanquest Software S.A.No
ChangeICONUSPMSMON.EXECard reader related program. Note - may cause problems with My Computer loading at startup. Disabling through MsConfig seems to solve the problemNo
hozjnvdxhqXspnikeo.exeDetected by Dr.Web as Trojan.DownLoader6.53107No
qjtzXspnikeo.exeDetected by Malwarebytes Anti-Malware as Adware.SanctionedMedia. The file is located in %System%No
SPntXSPnt.exePremium rate adult content diallerNo
SpeedOptimizerUspo.exeSpeedOptimizer is designed to optimize and speed-up your Internet data transmission including browsing, streaming, downloading, uploading and e-mail communicationNo
spoolsvXspoclsv.exeAdded by the FUJACKS-M WORM!No
svcshareXspoclsv.exeAdded by the FUJACKS-A VIRUS!No
SpokeSysTrayUSpokeSysTray.exeSpoke Software client application. Spoke "uses data in your e-mail and other enterprise information systems to discover the existing relationships of people in your enterprise. It then builds a private, secure relationship network for each user without any additional manual data entry"No
helpmanagerXspoler.exeAdded by the RANDEX.J WORM!No
Shell ExtensionXspollsv.exeAdded by the LOVGATE.Z WORM!No
Print ServicesXspolserv32.exeAdded by the RBOT.ZP WORM!No
MicrosoftXspolsv.exeAdded by the PWS-BOO TROJAN!No
SpoolServiceXspolsv.exeAdded by the AGOBOT-CS WORM!No
Winsock2 driverXSPOLSV.EXEAdded by the SPYBOT-CM WORM!No
(Default)Xspolsvr2.exeAdded by the EVILSOCK.10 TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
sponsormatchXsponsormatch.exeDetected by Symantec as SponsorKeyword and by Malwarebytes Anti-Malware as Adware.K.SponsorMatchNo
sponsormatchXsponsormatchagent.exeDetected by Symantec as SponsorKeyword and by Malwarebytes Anti-Malware as Adware.K.SponsorMatchNo
sPoNVCXsPoNVC.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.Agent.ZAD. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
spoo1svXspoo1sv.exeAdded by the SOULJET TROJAN!No
SVCH0STXspoo1sv.exeAdded by the VB-HF TROJAN!No
SpoolerSubSystemProcessXSpooI32.exeAdded by the EHKS.21 keylogger! Note - the "I" between "o" and "3" is a capital "i" not a lower case "L"No
Spooler SubSystem AppXspooIsv.exeAdded by the LINKBOT.M WORM!No
Microsoft Spool ** ServiceXspool**.exeAdded by a variant of W32.IRCBot - where ** represents a 2 digit number. The file is located in %System%No
autoloadXspool.exeDetected by Sophos as Troj/Agent-GSGNo
Microsoft UpdateXspool.exeDetected by Sophos as Troj/Agent-GJCNo
ntuserXspool.exeAdded by the DLOADER.DYA TROJAN!No
Print SpoolerXspool.exeAdded by the BDOOR-IS BACKDOOR!No
Printer ServicesXspool.exeAdded by the RBOT-Y WORM!No
Printer spool ServiceXspool.exeAdded by the RBOT-ACP WORM!No
spoolXspool.exeDetected by Malwarebytes Anti-Malware as Backdoor.Poison.ai. The file is located in %Windir%\installNo
Spool LoaderXspool.exeAdded by a variant of the RBOT WORM!No
Spool lptt01Xspool.exeRapidBlaster variant (in a "spool" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove itNo
Spool ml097eXspool.exeRapidBlaster variant (in a "spool" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove itNo
Windows Spooler ServicesXspool.exeAdded by the AGOBOT-AMO WORM!No
WindowsXp SecurityXspool.exeAdded by the RBOT-GRK WORM!No
Windows ServicesXspool32.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.Gen. The file is located in %System%No
Windows SpoolaPrint ServiceXspoolasrv.exeAdded by the SDBOT-AYD WORM!No
dumprepXspoolc.exeDetected by Kaspersky as a variant of the AGENT.CXF TROJAN!No
system serviceXspoolcrv.cplAdded by the INSPIR.11 TROJAN!No
Printer SpoolerXspooler.exeAdded by the DELF-JJ TROJAN!No
rudll32Xspooler.exeAdded by the VB-EZJ WORM!No
Windows ConfigurationXwinupdate32.exeAdded by the SDBOT BACKDOOR!No
Windows System Gateway XSPOOLER.EXEAdded by a variant of Win32/Rbot. Note the space at the end of the "Startup Item" fieldNo
Windows SpoolPrint ServiceXspoolersrv.exeAdded by the SDBOT-ZT WORM!No
System Tray ServicesXspooles32.exeDetected by Trend Micro as WORM_AGOBOT.ZHNo
autoloadX