PC Review
Startup Files Database
Letter s
Startup Files Database
Letter s
Startup Files Database
[#] [A] [B] [C] [D] [E] [F] [G] [H] [I] [J] [K] [L] [M] [N] [O] [P] [Q] [R] [S] [T] [U] [V] [W] [X] [Y] [Z]
Yes |
No |
Users Choice |
Warning |
Unknown |
| Normally leave to run at startup | Not Required, often infrequently run tasks that can be run manually. | Depends if the task is deemed necessary | Typically viruses, spyware, adware and resource hogs | An unknown item |
| Required | Process Name / Details | Startup File |
![]() |
Added by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a HelpHelp subfolder of the Windows or Winnt folder |
services.exe |
![]() |
Added by the AGOBOT-LN WORM! |
svhost.exe |
![]() |
Added by the LOVGATE.AB WORM! Note - the filename has the digit 0 rather then the uppercase "o" |
svch0st.exe |
![]() |
Event Monitor - supports driver extensions to NIC Driver for wireless adapters. Is it required? |
S24EvMon.exe |
![]() |
Added by the AGOBOT-DD WORM! |
s3serv.exe |
![]() |
A tool installed alongside the drivers for your S3 video output device. It is not necessary but should be allowed to run unless it is causing problems |
S3apphk.exe |
![]() |
Hotkey system tray icon to enable switching between monitors. Found on laptops with an S3 Twister integrated graphics card |
s3hotkey.exe |
![]() |
S3DuoVue multi-monitor taskbar helper by S3 Graphics. What does it do and is it required? |
S3Mon.exe |
![]() |
S3 display configuration taskbar utility for S3 chipset based graphics cards. Can be run from Start-> Settings -> Control Panel -> Display |
S3Tray.exe |
![]() |
Same as the s3tray entry in this table? |
s3tray2.exe |
![]() |
S3 Video driver related. What does it do and is it required? |
S3trayhp.exe |
![]() |
FilterPak from S4F, Inc - internet filtering software |
S4F.exe |
![]() |
Searchcentrix hijacker |
s4helper.exe |
![]() |
Logitech QuickCam driver. Is it required? |
Sa3.exe |
![]() |
Associated with Cyber Trio and Warner troubleshooting software from G-Tek Technologies and pre-installed on some Packard Bell and NEC PCs. What function does this perform and is it required? |
SAservice.exe |
![]() |
3D sound extension for Windows |
Sa3dsrv.exe |
![]() |
NCase adware |
saap.exe |
![]() |
Airline reservation software from Sabre. Available via Start -> Programs |
SABSERV.EXE |
![]() |
NCase adware |
sac.exe |
![]() |
SurfAccuracy adware |
sacc.exe |
![]() |
AT&T or ComCast BBClient - monitors system and network-delivered services for availability. Your current network status is displayed on a color-coded web page in near-real time. When problems are detected, you're immediately notified by e-mail, pager, or text messaging |
RegCon.exe |
![]() |
Added by the MAILBOT-BZ TROJAN! |
smcntlwio.exe |
![]() |
Added by the FOCOSENHA TROJAN! |
SafeWin.exe |
![]() |
Added by the BANKER-DT TROJAN! |
[path to trojan] |
![]() |
SafeguardProtect/Veevo hijacker |
regsvr32 [path] sfgupd.dll |
![]() |
SafeguardProtect/Veevo hijacker |
regsvr32 [path] sfg****.dll [* = ramdom char] |
![]() |
SafeguardProtect/Veevo hijacker |
regsvr32 [path] sfg****.dll [* = random char] |
![]() |
SafeguardProtect/Veevo hijacker |
regsvr32 [path] PDF****.dll [* = random char] |
![]() |
SafeHouse "Personal Privacy" system tray icon - PP protects and hides your private and personal photos, videos, files and folders by making them "invisible" and encrypted |
SDWTRAY.EXE |
![]() |
Monitors a download and ensures an newer version of a file isn't replaced by an older one |
SAFEIN~1.EXE |
![]() |
Provides protection that if user accidentally presses the power switch a dialog will pop up for confirmation |
SafeOff.exe |
![]() |
SafeSearch.A adware |
safesearch.exe |
![]() |
MoneyTree parasite - ActiveX control used to download premium-rate dialers |
SSUpdate.exe |
![]() |
Safety.Net from Netveda - "offers Internet security, content security and advanced Internet firewall protection for all your LAN computers, and trust controls to block unwanted or harmful applications from accessing the network" |
ipcTray.exe |
![]() |
Safety.Net from Netveda - "offers Internet security, content security and advanced Internet firewall protection for all your LAN computers, and trust controls to block unwanted or harmful applications from accessing the network" |
ipcLn.exe |
![]() |
SafeWorld Internet Security - now no longer available |
Freedom.exe |
![]() |
Added by the GAOBOT.BOW WORM! |
sagate.exe |
![]() |
Seiko Epson printer status agent. Disable if printer is not used often |
SAgent2.exe |
![]() |
TinySpyAgent commercial keystroke logger. Uninstall this software if you did not install it yourself |
Sagent.exe |
![]() |
Adware web downloader |
sagnt.exe |
![]() |
ShopAtHomeSelect parasite |
Sahagent.exe |
![]() |
ShopAtHomeSelect parasite |
bundle.exe |
![]() |
ShopAtHomeSelect parasite |
shop1003.exe |
![]() |
NCase adware |
saie.exe |
![]() |
Configuration software for Saitek game controllers |
SaiMfd.exe |
![]() |
Saitek joystick driver |
SaiMon.exe |
![]() |
NCase adware |
sain.exe |
![]() |
NCase adware |
sais.exe |
![]() |
Smart Button Special Sauce - included with the latest software for Saitek game controllers. Related to the "S", "Shift" or "Smart" button and gives gamers extra features on the buttons. Only required if you use this feature |
SaiSmart.exe |
![]() |
Configuration for Saitek game controllers |
saicnfig.exe |
![]() |
Added by the SDBOT.BTO WORM! |
simenu.exe |
![]() |
WinAntiSpyware misleading spyware remover - not recommended, see here |
WAS7Mon.exe |
![]() |
180Search adware |
salm.exe |
![]() |
NCase adware |
salm.exe |
![]() |
Added by a variant of the SDBOT WORM! |
Sam-sung.exe |
![]() |
Added by the VBS.LIDO WORM! |
[WORM FILE NAME].vbs |
![]() |
SamCal - calendar/reminder program |
SAMcal.exe |
![]() |
IBM Lotus Sametime - instant messaging and Web conferencing software |
Connect.exe |
![]() |
Added by the SDBOT.BNE WORM! |
Samsong.exe |
![]() |
Added by an IRC TROJAN variant! |
Samsungs.exe |
![]() |
SandBoxie - allows data to be read from the hard drive by an application but never written back unless you allow it |
Control.exe |
![]() |
SanDisk ImageMate CompactFlash card reader SDDR-31 (USB). Very little use except to place the Sandisk icon beside its drive designation in Windows Explorer. The reader itself will work fine without it. The simplest thing is to just unplug the reader when you're not using it. It may slow the startup by a few nanoseconds, but once the software sees there's no reader, you get back the resources |
SandIcon.exe |
![]() |
Added by the VANEBOT-AH WORM! |
sansv.exe |
![]() |
NCase adware |
sapp.exe |
![]() |
Experience faster surfing, downloading and e-mail by adding SaskTel Accelerated Dial-up Internet |
sasktelgui.exe |
![]() |
Added by the DABBER.B WORM! |
package.exe |
![]() |
Browser hijacker - redirecting to Searchant.com |
rundll32.exe sasync.dll, SyncWait |
![]() |
RAID driver for serial ATA disks on some motherboards such as the DFI Lanparty range. Only loaded if one is using RAID support on SATA drives |
SATARaid.exe |
![]() |
VX2.Transponder parasite updater/installer related |
satmat.exe |
![]() |
180Solutions adware related |
sau.exe |
![]() |
Big Brother from Quest Software. System and network monitor |
SAUpdate.exe |
![]() |
Sharp Zaurus PDA related, needed to synchronize information with a Desktop or Notebook |
SAutoLaunchExe.exe |
![]() |
Part of Sophos anti-virus software. Required for centrally administered Sophos updates to work correctly, e.g. automatically updating PCs used by dial-in home or out-of-office users |
SAVAgent.exe |
![]() |
WhenU.Save adware |
Save.exe |
![]() |
Unidentified adware |
SaveStartDate.Exe |
![]() |
WhenU.Save adware |
SaveNow.exe |
![]() |
Added by the SPREDA.B VIRUS! |
savenow.exe |
![]() |
SmartAdware adware |
saw.exe |
![]() |
This program has audio cues for the system clock in male and female voices, customizes the appearance of the system clock, and can synchronize it to a time server regularly |
SAYTIME.EXE |
![]() |
Acer Soft Button on Acer Tablet PCs |
SB.exe |
![]() |
Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search function |
/l:eng |
![]() |
Spyware utility installed by the manufacturers of some laptops (Sony) used to monitor browsing habits and send them back to whoever installed it - released by SoftBank |
SBWatchdog.exe |
![]() |
Added by the SPYBOT-EJ WORM! |
RYZO32.EXE |
![]() |
SpywareBlaster auto-updater |
sbautoupdate.exe |
![]() |
Part of AT&T FreedomLink Wi-Fi connection software |
SBCFL.exe |
![]() |
matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file. The SBC Self Support Tool is required to run with the Help and Support program. If you uncheck SBC and and then run Help and Support it will add another SBC entry in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decide |
matcli.exe |
![]() |
Used to create and connect your SBC Yahoo DSL connection. This program has been reported to cause problems for some users. If you find that it causes you pc to become slow or unstable you should uninstall it (using Add/Remove programs) and manually connect your DSL connection |
ConnectionManager.exe |
![]() |
System Tray access to CounterSpy anti-spyware from Sunbelt Software |
SBCSTray.exe |
![]() |
Detects the "Easy Front-Panel Audio Connectivity Drive Internal Drive Bay" on the Sound Blaster Audigy 2 Platinium eX. Can be disabled if you don't have one |
SBDrv.exe |
![]() |
Checks to see if Creative sound card driver should be updated |
sbdrvdet.exe |
![]() |
SuperBar parasite - uninstall available here |
sbhc.exe |
![]() |
SearchByMedia adware |
SBMPop.exe |
![]() |
SoundMAX MPU401 MIDI device emulator for x86 VM DOS games/apps (for Win9x only) |
sbmx.exe |
![]() |
SideBySide adware |
sbss.exe |
![]() |
Control for Soundblaster MP3 external (USB) sound card |
RunDll32 sbusbdll.dll, RCMonitor |
![]() |
ScrubXP - utility that deletes safe to remove files, cookies, browsing history, etc |
scrubxp.exe |
![]() |
Watchdog 2.0 Software - monitoring program |
sc.exe |
![]() |
All-In-One_SPY stealth monitoring software - allows monitoring and recording of all actions performed on a computer. It records all keystrokes, remembers addresses of Internet pages visited, and maintains a log file listing all applicationsrun on the computer. It can create screenshots and record sounds from the computer's microphone to a sound file |
run.exe |
![]() |
Possibly related to a digital camera |
sc23exec.exe |
![]() |
SiPix digital camera Twain device driver |
SC3300CC.exe |
![]() |
Delfin Media Viewer adware related |
s030109.Stub.exe |
![]() |
Added by the LEWOR.D WORM! |
SVOHOST.exe |
![]() |
ClientMan parasite variant |
mscman.exe |
![]() |
Associated with PrimaScan scanners. Is it required? |
Pmxdetect.exe |
![]() |
Added by the RBOT-AT WORM! |
ssms.exe |
![]() |
Associated with ScanWizard as supplied with Microtek scanners - see also Scanner Detector or SDetect. What does it do and is it required? |
button.exe |
![]() |
Added by the GREGSTAR TROJAN! |
satan.exe |
![]() |
Added by the GANDA.A WORM! Note - this is not the valid "ScanDisk" Win9x/Me standard disk error checker |
ScanDisk.exe |
![]() |
Added by a variant of the ADCLICKER TROJAN! |
scands32.exe |
![]() |
Added by the AGOBOT-PK WORM! |
scandsk2.exe |
![]() |
Added by the DLOADR-ARM TROJAN! |
scandskx.exe |
![]() |
?? |
?? |
![]() |
Part of Panda Antivirus. Responsible for scanning the boot sector of your disk and your memory at startup to check for viruses that try and load and act before your anti-virus is fully operational. It only adds a fraction of a second to start-up time and is worth leaving active |
Inicio.exe |
![]() |
ScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the "GO" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the "GO" button |
SDetect.exe |
![]() |
Kycocera Mita network copier/printer/scanner process to dump scanned documents onto a workstation |
NsCatCom.exe |
![]() |
Trust Easy Webscan scanner related - what does it do and is it required? |
ScanPanel.exe |
![]() |
Added by the QQPASS.E TROJAN! |
[filename] |
![]() |
Added by the NERTE TROJAN! Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as nsrvnt.exe not scanregw.exe |
nsrvnt.exe |
![]() |
Added by the MASTERLOCK TROJAN!. Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as scanregv.exe not scanregw.exe |
scanregv.exe |
![]() |
Scans the system registry and makes back-ups at start-up. Important should the registry become corrupt. The executable "Scanregw.exe" is located in %windir% (where %windir% is the Windows directory - C:Windows or C:Winnt) |
Scanregw.exe |
![]() |
Added by the STATOR WORM! Not to be confused with the legitimate ScanRegistry entry - which is a vital Windows file. The executable "Scanregw.exe" is located in %windir%System (where %windir% is the Windows directory - C:Windows or C:Winnt). Runs from the registry RunServices key as opposed to the Run key |
Scanregw.exe |
![]() |
Added by the DINOXI or DINOXI.B WORMS! |
N/A |
![]() |
Added by the NYXEM-D WORM! Note - do not confuse this with the legitimate Windows process scanregw.exe which is always found in the Windows folder on Win9x/ME machines. This worm file is found in the System (9x/ME) or System32 (NT/2K/XP) folder |
scanregw.exe |
![]() |
Added by the DWNLDR-FZY TROJAN! |
update.exe |
![]() |
Spyware remover (where * = the version number) - not recommended, see here |
Scanner.exe |
![]() |
Added by the STANDO-E WORM! |
scApp.exe |
![]() |
Added by the ACNATT.A WORM! |
suchost.exe |
![]() |
Related to SmartCard readers and sometimes uses lots of system resources |
scardsvr.exe |
![]() |
Added by the MOFEI.B WORM! |
SCardSvr32.Exe |
![]() |
Related to PowerISO - CD/DVD image file processing tool |
SCDEmuApp.exe |
![]() |
Related to unknown malware - hidden installer associated with it |
scheck45.exe |
![]() |
Added by the VB-DVW WORM! |
schedl.exe |
![]() |
Part of Antivir PersonalEdition Classic anti-virus |
schedm.exe |
![]() |
Premium rate adult content dialler |
nrchk.exe |
![]() |
Added by a variant of the SDBOT WORM! |
msexploren.exe |
![]() |
Added by a variant of the SDBOT WORM! |
shch.exe |
![]() |
Added by a variant of the SDBOT WORM! |
svchst.exe |
![]() |
Added by a variant of the SDBOT WORM! |
winagent.exe |
![]() |
Scheduler for Mercury Ez View TV Tuner Card |
Schedule.exe |
![]() |
Scheduler for Iolo System Mechanic tweaking utility. It can cleans your registry and deletes temporary files at defined intervals. Available via Start -> Programs |
Scheduled_Maintenance.exe |
![]() |
Added by the TACTSLAY.A TROJAN! |
expIorer.exe |
![]() |
Added by the HOSTBANK-A TROJAN! Note - this particular msmsgs.exe file is located in the WindowsSystem32Config or WinntSystem32Config folder, and should not be mistaken for the MSN Messenger file of the same name! |
MSMSGS.EXE |
![]() |
Added by the TACTSLAY.A TROJAN! |
outIook.exe |
![]() |
Added by the TACTSLAY.A TROJAN! |
svcrhost.exe |
![]() |
Added by the TACTSLAY.A TROJAN! |
svcshost.exe |
![]() |
Added by the TACTSLAY.B TROJAN! |
winagent.exe |
![]() |
Tenebril GhostSurf or SpyCatcher related scheduler - you can schedule daily, weekly, monthly or one-time only cleanings |
Scheduler daemon.exe |
![]() |
Added by the TACTSLAY.B TROJAN! |
msnexploren.exe |
![]() |
Added by the TACTSLAY.B TROJAN! |
sdhch.exe |
![]() |
Added by the TACTSLAY.B TROJAN! |
svchst.exe |
![]() |
Added by the LIOTEN.KX WORM! |
wsass.exe |
![]() |
Premium rate adult content dialer |
navchk.exe |
![]() |
Added by the SUBWOOFER TROJAN! Note - this is not the real MS Scheduling agent as the executable is incorrect |
Scheduler.exe |
![]() |
Added by the YAB.A TROJAN! Not the valid MusicMatch Jukebox which has the same filename |
MMTASK.EXE |
![]() |
MS Scheduling Agent displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting, ScanDisk, etc. Required if you have regularily scheduled events such as weekly virus scans |
mstask.exe |
![]() |
MS Scheduling Agent displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting, ScanDisk, etc. Required if you have regularily scheduled events such as weekly virus scans |
mstinit.exe |
![]() |
Added by the DINOXI or DINOXI.B WORMS! |
N/A |
![]() |
Schmaili - insert animated smilies into your e-mail |
Schmaili.exe |
![]() |
Added by the TJSERV.D TROJAN! |
[path to trojan] |
![]() |
WinScheduler is installed with Home Theater or WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs |
SchSvr.exe |
![]() |
Part of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot |
SCHWIZEX.EXE |
![]() |
Added by a variant of the MAILBOT TROJAN! |
helpsyss.exe |
![]() |
Added by the FAKEALERT TROJAN! |
sclick.exe |
![]() |
Added by the FORBOT-CW WORM! |
scman.exe |
![]() |
Added by a variant of the CRYPTER.C TROJAN! |
scopedll.exe |
![]() |
Scotia OnLine Security Software provided by Entrust for Scotiabank. Provides trusted secure access to Scotia OnLine Secure Web sites. *.* represents the version number. Now obsolete after Scotiabank modernised their login process |
etdirrcv.exe |
![]() |
Scotia OnLine Security Software provided by Entrust for Scotiabank. Provides trusted secure access to Scotia OnLine Secure Web sites. *.* represents the version number. Now obsolete after Scotiabank modernised their login process |
etdirrcv.exe |
![]() |
Added by the OPASERV.T WORM! |
scr.scr |
![]() |
ScrapPad allows you to quickly and easily record notes, thoughts, messages, and just about anything you want. Use it like you use scrap paper |
Scrappad.exe |
![]() |
Added by the DLOADER-VP TROJAN! |
[path to trojan] |
![]() |
Screen Calendar allows you to create custom desktop wallpapers with built in active calendar and scheduler |
scrcal.exe |
![]() |
Part of Access Denied security and privacy software |
launch.exe |
![]() |
Part of Access Denied security and privacy software |
sgms.exe |
![]() |
Added by the RBOT-AGP WORM! |
scrnsaver.scr |
![]() |
Installs as part of the Hubble Space Telescope screen saver (and possibly others). Lets you control your installed screensavers from a System Tray icon |
FSScrCtl.exe |
![]() |
ScreenHunter 4.0 Free is a completely free screen capture software for you to easily take screenshots |
ScreenHunter.exe |
![]() |
ScreenPrint32 screen capture software - can be launched manually |
ScreenPrint32.exe |
![]() |
?? |
scruser2k.exe |
![]() |
Maybe associated with DOS on a Win9x machine |
script.bat |
![]() |
Update to Norton AntiVirus 2001. Detects certain types of script-based viruses without the need for specific virus definitions - such as JavaScript and VBScript. This will help protect you from these viruses even before virus definitions are available. Note - some users complain of problems once the update is installed - refer here for more information |
SBServ.exe |
![]() |
Script Sentry from Jason's Toolbox. Blocks malicious scripts and allows safe scripts to run. Only required if you want it to check the file associations it guards at startup. It will function regardlessly |
Scriptsentry.exe |
![]() |
Toolkit for the Lynx-3D Net scroll mouse from QTronix. Required if you use the special features |
SCROLL.EXE |
![]() |
Added by the HACDEF-R TROJAN! |
scrss.exe |
![]() |
Added by the AGENT-DS TROJAN! |
scrsvc.exe |
![]() |
Added by the OPASERV WORM! |
ScrSvr.exe |
![]() |
Added by the OPASERV WORM! |
[worm filename] |
![]() |
SCSI Miniport driver |
Scsi.exe |
![]() |
Added by a variant of the DWNLDR-GAH TROJAN! |
sescmgr.exe |
![]() |
Added by a variant of the SPYBOT WORM! |
svzhost.exe |
![]() |
Wiretap surveillance software. Uninstall this software unless you put it there yourself |
scvhost.exe |
![]() |
Added by the SDBOT-CY TROJAN! |
ixplore.exe |
![]() |
Added by the LOHAV-N TROJAN! |
scvhost.exe |
![]() |
Added by the CRYPTER.A TROJAN! |
sd32info.exe |
![]() |
PC Security from Tropical Software. 'PC Security(tm) 5.1 is the ultimate in computer security, offering multiple locking systems for the Windows environment and internet. Lock files, monitor programs' activities, even detect intruders! PC Security(tm) offers flexible and complete password protection, "Drag and Drop" support, plus many other handy features' |
sdaemon.exe |
![]() |
Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here |
LiveUpdateSD.exe |
![]() |
Added by the SERFLOG.C WORM! |
csnss.exe |
![]() |
Added by the SERFLOG.C WORM! |
svhost.exe |
![]() |
Added by the RANKY.AG TROJAN! |
vbdd.exe |
![]() |
Related to LANDesk Management Suite from LANDesk Software Ltd. What does it do and is it required? |
sdclientmonitor.exe |
![]() |
ScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the "GO" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the "GO" button |
SDetect.exe |
![]() |
Added by a variant of the SPYBOT WORM! |
sp2update.exe |
![]() |
Added by the FORBOT-AP WORM! |
sdin.exe |
![]() |
Part of CA Unicenter Software Delivery - manage software across various systems, from desktops and servers to PDAs and mobile phones, in a controlled and standardized way - is it required at startup? |
triggusr.exe |
![]() |
Added by the SDBOT-YJ WORM! |
sdkimddprovment2.exe |
![]() |
Added by the SDBOT-WC WORM! |
sdkcore.exe |
![]() |
Added by the RBOT.BHL WORM! |
sdkimprovment.exe |
![]() |
Added by the SPYBOT.OGX WORM! |
sdkimprovment2.exe |
![]() |
Sdk**.exe [* = random char] |
Sdk**.exe [* = random char] |
![]() |
CoolWebSearch/HomeSearch adware - for examples, see this log |
Sdk**.exe [* = random char] |
![]() |
CoolWebSearch/HomeSearch adware - for examples, see this log |
Sdk**32.exe [* = random char] |
![]() |
Added by the RBOT-ABA WORM! |
SDKC0R3.exe |
![]() |
Added by the FORBOT-DT WORM! |
SDK0mCORE.exe |
![]() |
SmartDraw Photo (now FotoFinsh) - "organize, enhance, print, and share your photos. It's also a powerful graphic editor for creating images and web graphics" |
SDPhotoBar.exe |
![]() |
DriveCleaner is a security assesment tool which gives exaggerated reports of security and privacy risks on a computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported risks |
udcsdr.exe |
![]() |
Added by the SDBOT-SQ WORM! |
sdrss.exe |
![]() |
InlookExpress logs keystrokes and captures screenshots. If you didn't install this yourself remove it. Note - this should not be confused with the svchost.exe system process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder! This file is located in a "sds20" folder |
svchost.exe |
![]() |
RSA Keon Web PassPort - software that allows organizations to use digital certificates in a Web-based environment to help ensure that their transactions are authentic, confidential and digitally signed |
sdtray.exe |
![]() |
Spyware Doctor spyware remover - system tray access |
SDTrayApp.exe |
![]() |
Added by the BROGGER-A TROJAN! |
sdxsys32.exe |
![]() |
SealedMedia enables you to combine document protection and control with your existing applications - such as Microsoft Word, Microsoft Excel, Microsoft PowerPoint and Email |
sealmon.exe |
![]() |
Added by the OPANKI-F WORM! |
taskbar.exe |
![]() |
?? |
srchhook.exe |
![]() |
Naupoint browser hijacker |
http://find.naupoint.com |
![]() |
Search-Exe hijacker |
SE.exe |
![]() |
Hijacker |
|
![]() |
SearchBarCash adware variant |
vnmispoisn downloader.exe |
![]() |
SCBar foistware |
scbar.exe |
![]() |
SearchNav adware - IEFeatures/Popnav variant |
searchnav.exe |
![]() |
SearchNav adware - IEFeatures/Popnav variant |
searchnavversion.exe |
![]() |
SearchNet adware |
ServeUp.exe |
![]() |
Browser hijacker - redirecting to FindWhateverNow.com |
searchsetter[1].exe |
![]() |
SearchSpy misleading spyware remover - not recommended, see here |
SearchSpy.exe |
![]() |
SearchSquire adware |
SearchSquire[number].exe |
![]() |
Hijacker |
SearchUpgrader.exe |
![]() |
Added by the HAXDOOR.D TROJAN! |
w32tm.exe |
![]() |
Added by a variant of the HAXDOOR.BC TROJAN! |
mszx23.exe |
![]() |
Added by the HAXDOOR-AE TROJAN! |
vtd 16.exe |
![]() |
Related to Second Copy(r) - a files/folders backup utility |
SecCopy.exe |
![]() |
Power Quest Second Chance. Sets checkpoints for saving a backup copy of the registry to a disk so you can restore it if you have a crash |
sctray.exe |
![]() |
Added by the DELF-LW TROJAN! |
Secret.exe |
![]() |
Hijacker that may reset your browser's home page and/or search settings to point to undesired sites |
start.exe |
![]() |
Secretmaker is a combonation of eight privacy-defending programs, including Spam Fighter Pro, Worm Hunter, Pop-Up Killer, Banner Blocker, Cookie Eraser, Privacy Protector, History Cleaner, and Garbage Cleaner |
secretmaker.exe |
![]() |
Secret Smileys is an add-on for AIM that provides users access to 1000's of new Smileys that can be viewed by anyone using a current version of AIM. Secret Smileys also adds other features such as logging of IM conversations, and it gets rid of that annoying advertisement on your buddy list window |
ss.exe |
![]() |
Reported by Panda as an EasySearch Adware variant. Note - EasySearch modifies the Internet Explorer settings and may download programs onto the infected computer |
secserv.exe |
![]() |
Added by the GLOBAL PATROL TROJAN! |
secsvcnt.exe |
![]() |
UltraSoft Key Interceptor surveillance software - uninstall this unless you put it there yourself! |
Secsys.exe |
![]() |
DealHelper adware |
secure.exe |
![]() |
Added by the RBOT-AFO WORM! |
svshost.exe |
![]() |
Added by an IRCBOT TROJAN! |
wins32a.exe |
![]() |
Added by the VANEBOT-AN WORM! |
sslcert.exe |
![]() |
Added by the AGOBOT.ACI WORM! |
integitor.exe |
![]() |
WhiteCanyon SecureClean 4 disk cleaner - clean hard drive data, MRUs, temp files and more. Can be started manually |
scregmanager4.exe |
![]() |
WhiteCanyon SecureClean 4 disk cleaner - clean hard drive data, MRUs, temp files and more. Can be started manually |
sctray4.exe |
![]() |
SecureClean - scans your system for hidden temporary files, deleted email messages, Internet histories and caches |
SCIEClean.exe |
![]() |
SecureIt Pro - lock your computer when you're not there, to stop malicious users from accessing your desktop |
Secureitpro470p.exe |
![]() |
Added by the REDZED WORM! |
Mslg32.exe |
![]() |
Related to Secure Online Account Numbers by Discover(R) Card from Orbiscom Ltd. Secure and innovative payment solutions |
SOAN.exe |
![]() |
SecurePCCleaner misleading security program - not recommend, see here |
GDC.exe |
![]() |
Added by a variant of the SDBOT WORM! |
WindowsSecurityUpdate.exe |
![]() |
Added by the SPYBOT.JE WORM! |
samsm.exe |
![]() |
Added by the BANCBAN-F TROJAN! |
securag.exe |
![]() |
Added by the RBOT-SV WORM! |
mssams.exe |
![]() |
Added by the SDBOT.CFT WORM! |
AppControl.exe |
![]() |
Spyware remover - not recommended, see here |
Security iGuard.exe |
![]() |
A ComCast Internet software suite that provides a variety of features (firewall, popup blocker, parental controls etcetera) to help ensure your computer is secure, and your information is kept private |
SecurityManager.exe |
![]() |
Added by the RBOT-ZW WORM! |
scmss.exe |
![]() |
Added by the SDBOT-BM WORM! |
WinUpdate32.exe |
![]() |
Added by the RBOT.WW WORM! |
msnkn.exe |
![]() |
Added by the SDBOT-KB WORM! |
WinLab32.exe |
![]() |
Added by an unidentified WORM or TROJAN! |
syss.exe |
![]() |
Added by the RBOT-GGF WORM! |
secsvc.exe |
![]() |
Added by the AGOBOT-LC WORM! |
svhost.exe |
![]() |
Added by the NOPIR.A WORM! |
Nctrup.exe |
![]() |
Security Wizard 98 by Chris Farmer. Offers you a variety of ways to restrict access to many of the programs and settings on your PC. Available here |
SECWIZ98.EXE |
![]() |
Seekmo Search, a 180Solutions adware variant - also see here |
seekmo.exe |
![]() |
180solutions/Seekmo adware |
${HOOKOE_FILE} |
![]() |
Medload adware |
seeve.exe |
![]() |
Added by the DLOADER-WD TROJAN! |
slcsvr.exe |
![]() |
?? |
slefhost.exe |
![]() |
Added by the LOWZONE-AS TROJAN! |
[path to file] |
![]() |
Added by RXToolbar ADAWARE! Software that displays pop-up/pop-under advertisements when the primary user interface is not visible |
SemanticInsight.exe |
![]() |
PCsms - tool that enables you to send sms text messages from your PC to any UK mobile phone |
SeMS.exe |
![]() |
Detected by Kaspersky as PurityScan.ah |
tlii.exe |
![]() |
Symbol Commander makes the use of your PC, laptop, Tablet PC, and Pocket PC much easier and much faster. It recognizes your handwriting with unparalled performance and executes commands in a snap. Just by using your mouse, pen, or touchpad, simply draw symbols to execute actions instantly |
Sensiva.exe |
![]() |
From IP Insight. Allows website owners "to instantly determine the precise geographic location, connection speed and detailed demographics of every visitor to your website". Will be detected by most firewalls and the majority of home users should disable it |
SENTRY.exe |
![]() |
Added by a variant of the RBOT WORM! |
sepate.exe |
![]() |
MediaMotor.Popupwithcast adware |
septpop06apsept.exe |
![]() |
Any one of a variety of worms and trojans |
serials.exe |
![]() |
Added by the BANCBAN-BJ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "D5133" subfolder |
csrss.exe |
![]() |
Added by the SERFLOG.A WORM! |
formatsys.exe |
![]() |
Added by the SERFLOG.A WORM! |
msmbw.exe |
![]() |
Added by the SERFLOG.A WORM! |
serbw.exe |
![]() |
Shared Modem Service Client Event Viewer - used when a number of PCs have access to a number of modems. Required to be running on each PC for access to the modems |
serrdctl.exe |
![]() |
Added by the WAREZOV.DC WORM! |
serrv.exe |
![]() |
Added by the SDBOT-ACP WORM! |
nerx.exe |
![]() |
FTP server |
serv-u32.exe |
![]() |
Added by the MANIFEST TROJAN! |
wssdsu.exe |
![]() |
Added by the DELTAD.A WORM! |
server.exe |
![]() |
Added by the METHS-A TROJAN! |
system.exe |
![]() |
Added by the SINGU-Q TROJAN! |
server.exe |
![]() |
Added by the RBOT-ZM WORM! |
server05.exe |
![]() |
Added by the SDBOT-DFA WORM! |
unsec.exe |
![]() |
Added by the SDBOT-DDB WORM! |
wbemstest.exe |
![]() |
Added by the BUSHTRO122 or SMOKODOOR TROJANS! |
SERVER.EXE |
![]() |
Added by the DELTAD.A WORM! |
Server.txt.vbs |
![]() |
Added by the MADANGEL VIRUS! |
Serverx.exe |
![]() |
Added by the ALADINZ.H TROJAN! |
service.exe |
![]() |
Added by the KAITEX.E TROJAN! |
[trojan filename] |
![]() |
Added by the NETSKY or NETSKY.B WORMS! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
services.exe |
![]() |
Added by the CHA TROJAN! |
SYSNT.exe |
![]() |
Added by the ASSIRAL-C WORM! |
Service.pif |
![]() |
Added by a variant of the RBOT WORM! |
wN2S.exe |
![]() |
Added by the RBOT.BRH WORM! |
filen.exe |
![]() |
For Compaq PC's. Part of Backweb |
sccenter.exe |
![]() |
For Compaq PC's. Part of Backweb |
bwtray.exe |
![]() |
Added by the GAOBOT.AO WORM! |
Csrrs.exe |
![]() |
Added by the PREVERT TROJAN! |
service.exe |
![]() |
Added by the RBOT.BMD WORM! |
msnpg.exe |
![]() |
Added by the SDBOT-WK WORM! |
PC.EXE |
![]() |
Added by the RBOT-ZJ WORM! |
Compt.exe |
![]() |
Added by the SDBOT-YX WORM! |
abl.exe |
![]() |
Added by a variant of the RBOT WORM! |
MSNMEssenger.exe |
![]() |
Added by the TORVEL.B WORM! |
[filename].exe |
![]() |
Added by the TORVEL WORM! |
spoolxx.exe |
![]() |
Added by the DAOSER-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Services{C922CCC4-CF61-4589-A0D1-828160704853} subfolder |
svchost.exe |
![]() |
Added by the DAOSER-C TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Services[random] subfolder |
svchost.exe |
![]() |
Added by the TORVEL WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
svchost.exe |
![]() |
Added by the HITON TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
svchost.exe |
![]() |
Added by the GAOBOT.GEN!POLY WORM! |
spoolsvc.exe |
![]() |
SQL Server Service Manager - provides tray access to SQL server, the server agent and MSDTC. Available via Start -> Programs |
sqlmangr.exe |
![]() |
Added by the PASSMAIL-D VIRUS! |
SERVICEMGR.EXE |
![]() |
Added by the PROXY-GRIC TROJAN! |
dxsound.exe |
![]() |
Added by the DONBOMB.A TROJAN! |
service.exe |
![]() |
Added by the RBOT-ALE WORM! |
msnfilen.exe |
![]() |
Added by the DELF-NK TROJAN! |
javams32.exe |
![]() |
Added by the SDBOT-AFO WORM! |
javams64.exe |
![]() |
Added by the SPYBOT.YQW WORM! |
msnserve.exe |
![]() |
Added by the RBOT-AQJ WORM! |
WinOcx.exe |
![]() |
Added by the RBOT.EEH WORM! |
csnss.exe |
![]() |
Added by a variant of the RBOT WORM! |
filen.exe |
![]() |
Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe, common.pif, common.scr, Sexo.exe, Sexo.jpg.pif, ini_file__.pif, load_me__.tmp, msfile.pif, system_load_.pif or zipped.rar.pif |
[various filenames] |
![]() |
Added by the VXGAME.Z TROJAN! Note - the filename is random - see the link. Typical examples are vexg6ame4.exe, vexga3me2.exe, vexga4m1et4.exe, etc |
[random filename] |
![]() |
Added by a variant of the RBOT WORM! |
spdll32.exe |
![]() |
Added by the DARKER WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
SVCHOST.EXE |
![]() |
Added by a variant of the SPYBOT WORM! |
winset.exe |
![]() |
Added by the DCMBOT-C TROJAN! |
service.exe |
![]() |
Added by the DCMBOT-E TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "config" subfolder |
smss.exe |
![]() |
Added by the DCMBOT-E TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in "config" subfolder |
smss.exe |
![]() |
Added by the DCMBOT-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "config" subfolder |
svchost.exe |
![]() |
Added by the BANCOS-CG TROJAN! |
jdbgmgrnt.exe |
![]() |
Added by the BANCOS-BY TROJAN! |
taskmgrnt.exe |
![]() |
Added by the BANCOS-BM TROJAN! |
regeditnt.exe |
![]() |
Added by the AGOBOT-PH WORM! |
scheduler.exe |
![]() |
Added by the BANCOS-DA TROJAN! |
kernels32.exe |
![]() |
Added by the BANCOS-EL TROJAN! |
windowsXP.exe |
![]() |
Added by the BANCOS-FS TROJAN! |
kgbfsm344.exe |
![]() |
Added by the BANCOS-FJ TROJAN! |
wernell87.exe |
![]() |
Added by an unidentified VIRUS, WORM or TROJAN! - probably a SPYBOT variant |
qualityz.exe |
![]() |
servedby.advertising popup generator |
Service.exe |
![]() |
Added by the AGOBOT-ST WORM! |
service32.exe |
![]() |
Added by the DLOADR-AYX TORJAN! |
[path to trojan] |
![]() |
Comcast Transition Wizard. On June 30th, 2003 it will migrate E-mail and web pages from AT&T Broadband Internet to Comcast High-Speed Internet. Until then it will run at startup and then terminate - hence the U recommendation |
ispbeg.exe |
![]() |
Added by the AGOBOT.AIR WORM! |
serviceconnect.exe |
![]() |
Nokia Connectivity Library support task that is needed by NCLTRAY and by the Nokia Connection Manager for either to work properly |
ServiceLayer.exe |
![]() |
Added by the TAME-C WORM! |
service.exe |
![]() |
Added by the ZCREW TROJAN! |
start.bat |
![]() |
Added by the METEORSHELL TROJAN! |
[path to trojan] |
![]() |
Added by an unidentified VIRUS, WORM or TROJAN! Back32.exe is the baddie whose purpose is to HIDE the MIRC32 server in service.exe |
back32.exe ...service.exe |
![]() |
Added by a number of VIRUSES, WORMS and TROJANS! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup! |
services.exe |
![]() |
Added by an unidentified VIRUS, WORM or TROJAN! |
winread.exe |
![]() |
Added by a variant of the RBOT WORM! |
windns.exe |
![]() |
Added by the LANFILT-J TROJAN! |
mshost.exe |
![]() |
Added by the SDBOT.N WORM! |
Svchosts.exe |
![]() |
Added by a variant of the RANKY.U TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
csrss.exe |
![]() |
Added by a Proxy Trojan variant |
scks32.exe |
![]() |
Added by the RANKY.L TROJAN! |
sockys32.exe |
![]() |
Added by a Proxy Trojan variant |
sys.exe |
![]() |
Added by the FLYVB-C WORM! |
windows32.exe |
![]() |
Added by the WIN32.SMALL.N TROJAN! |
socks.exe |
![]() |
Added by the ZINCITE.A TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
services.exe |
![]() |
Added by the RANCK-DB TROJAN! |
[path to trojan] |
![]() |
Added by the MOGI WORM! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder |
iexplore.exe |
![]() |
Added by the REPER-B WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
svchost.exe |
![]() |
Added by a variant of the SDBOT WORM! |
sysamp.exe |
![]() |
Added by an unidentified WORM or TROJAN! |
prosys32.exe |
![]() |
Added by an unidentified WORM or TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
iexplorer.exe |
![]() |
Added by the RANCK-LT TROJAN! |
iexploler.exe |
![]() |
Added by the RANCK.LU TROJAN! |
iexpolere.exe |
![]() |
Added by a variant of the RANKY TROJAN! |
sample.exe |
![]() |
Added by the DLOADER-NY TROJAN! |
localsvc.exe |
![]() |
Added by the DLOADER-NY TROJAN! |
netsvc.exe |
![]() |
Added by the DLOADER-NY TROJAN! |
spoolsvc.exe |
![]() |
Added by the DLOADER-NY TROJAN! |
svcadmin.exe |
![]() |
Added by the DLOADER-NY TROJAN! |
svcman.exe |
![]() |
Added by the DLOADER-NY TROJAN! |
svcrun.exe |
![]() |
Added by the DLOADER-NY TROJAN! |
tcpsvc.exe |
![]() |
Added by the DLOADER-NY TROJAN! |
websvc.exe |
![]() |
Added by the CIADOOR.122 VIRUS! |
lsassa.exe |
![]() |
Added by the CIADOOR-F TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
services.exe |
![]() |
Added by the DONK WORM! |
Scchost.exe |
![]() |
Added by the AGOBOT-TG WORM! |
svchost32.exe |
![]() |
Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! By default this file is located in Documents and Settings[user name]Templates |
services.exe |
![]() |
Spyware - detected by Kaspersky as the SMALL.X TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
services.exe |
![]() |
Added by the SMALL-EK TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "config" subfolder |
smss.exe |
![]() |
Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! By default this file is located in Documents and Settings[user name]Templates |
services.exe |
![]() |
Added by a variant of the RBOT WORM! |
svhost33.exe |
![]() |
Added by the SOBER-L WORM! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a msagentsystem subfolder of the Winnt or Windows folder |
smss.exe |
![]() |
Added by the KAZPING WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
services.exe |
![]() |
Added by the CIADOOR-F TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
Services.exe |
![]() |
Added by the MSNSPY-B TROJAN! |
servicess.exe |
![]() |
Added by the BUGBROS WORM! |
[worm filename] |
![]() |
Added by the TrojanDownloader.Agent.rv TROJAN! |
mc-110-12-0000079.exe |
![]() |
Shorty adware - also detected as the AGENT.FD TROJAN! |
mc-58-12-0000120.exe |
![]() |
Shorty adware - also detected as the AGENT.FD TROJAN! |
mc-58-12-0000140.exe |
![]() |
Added by the SDBOT-XO WORM! |
win32dll.exe |
![]() |
Added by the PUNYA-B WORM! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
SERVICES.EXE |
![]() |
Added by the DEARIS-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
lsass.exe |
![]() |
Added by the RBOT-AMX WORM! |
ccapp32.exe |
![]() |
Defender Pro Antispy |
ServicesNotify.exe |
![]() |
Added by the MSNVB-D WORM! |
Hide32.exe |
![]() |
Added by the SDBOT.BUI WORM! |
hostd.exe |
![]() |
Added by the SPYBOT.BGX WORM! |
svhost.exe |
![]() |
Added by the BANKER-EHR TROJAN! |
AdobeLanc.exe |
![]() |
Added by the BANCOS-BCM TROJAN! |
System.exe |
![]() |
Added by the SINGU-J TROJAN! |
servics.exe |
![]() |
Added by the AGOBOT-UB WORM! |
SERVlCE.EXE |
![]() |
System Tray icon for Serv-U FTP server. Is it required? |
ServUTray.exe |
![]() |
Added by the SDBOT-CZU WORM! |
sesvc.exe |
![]() |
SurfSpy keystroke logger/monitoring program - remove unless you installed it yourself! |
sescli.exe |
![]() |
Added by the RBOT-AGS WORM! |
smssa.exe |
![]() |
DownloadWare adware |
sed.exe |
![]() |
Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. May be necessary in order to maintain preferences applied to the RAID array connected to the Promise controller |
rundll32.exe ptipbmf.dll, SetWriteCacheMode |
![]() |
Related to a Soundblaster Audigy soundcards. What does it do and is it required? |
MIDIDef.exe |
![]() |
Used by HP and Compaq computers to hide the windows of programs passed as arguments to it |
cloaker.exe |
![]() |
Used to set a Brother MFC printer/copier/scanner as the default printer after installation |
setdefprt.exe |
![]() |
Used to set a Brother MFC printer/copier/scanner as the default printer after installation |
BrStDvPt.exe |
![]() |
Setec Web and Email Security. Setec PKI smart card software. The PKI technology enables secure and reliable user identification in services offered through Internet, mobile handsets and digital TV |
Certutil.exe |
![]() |
Added by the FTP_BMAIL TROJAN! |
createsw.exe |
![]() |
Fellowes Neato CD label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar" |
SetHook.exe |
![]() |
SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data |
SETI@home.exe |
![]() |
SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data |
SETI@home.exe |
![]() |
Installed by a 6-in-1 (4 Media Card slots, a floppy drive and a USB connection) device. Constantly updates the icons for the four Media Card slots that it has and is a resource hog |
SetIcon.exe |
![]() |
Provides work unit buffering for Seti@Home clients - see here for more details |
Setiqu~1.exe |
![]() |
SETI Spy is a little program to "spy" on the progress and performance of the SETI@home client. Called a "spy" because it is unobtrusive as possible |
SetiSpy.exe |
![]() |
Added by the RBOT-BWI WORM! Note - this is not the valid Logitech Setpoint mouse and keyboard entry that uses the same filename and is located in the LogitechSetpoint sub-folder of Program Files. This file is located in the System (9x/Me) or System32 (NT/2K/XP/Vista) folder |
SetPoint.exe |
![]() |
Logitech SetPoint Event Manager for their range of mice and keyboards. Required if you want to use the advanced features of these devices and is located in the LogitechSetpoint sub-folder of Program Files |
Setpoint.exe |
![]() |
Added by the RBOT-AAX WORM! |
KHALMNP.exe |
![]() |
Found on a Compaq PC. Video refresh rate utility? Is it required? |
SetRefresh.exe |
![]() |
Added by the SDBOT.GEN TROJAN! |
sysweb.exe |
![]() |
HP DeskJet Setup - printers function normally without it |
hphprld.exe ....setup.exe |
![]() |
Added by the TOFGER-AW TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
svchost.exe |
![]() |
Added by the QQPASS-K TROJAN! |
runt32.exe |
![]() |
Added by the QQPASS-AC TROJAN! |
rnll32.exe |
![]() |
Appears to be the "Internet Connection Wizard" from Internet Explorer being set-up as a desktop shortcut. Appears under the RunOnce registry key but is available under Start -> Programs -> Accessories -> Communication (or similar) anyway |
icwconn1.exe |
![]() |
Regfile in disguise - another CoolWebSearch parasite variant |
regedit.exe setupuser.log |
![]() |
?? |
setuzp.exe |
![]() |
Added by the HUNTOCX WORM! |
setvrc.exe |
![]() |
Added by the REPAD WORM! |
st01b.exe |
![]() |
Added by the SENOW-B premium rate adult content dialler |
Sexnow.exe |
![]() |
Added by the Sexy DIALER! Related also to Hot Tarts DIALER! |
Sexy_Blondes.exe |
![]() |
Premium rate adult content dialler |
Sexy_sg.exe |
![]() |
SurfEnhance adware component |
sf.exe |
![]() |
Sonic Focus - "enhances music, movie and game sound by analyzing compressed audio streams in realtime, then restoring and enriching audio back to its original performance qualities" |
SFIGUI.EXE |
![]() |
Added by the FAVADD-H TROJAN! Also known as SurfEnhance adware |
sfita.exe |
![]() |
Added by the AGENT.BUO WORM! |
rayiou.exe |
![]() |
Verizon Online Support Center - prompts for online updates |
vzSFPWin.EXE |
![]() |
Spy4PC surveillance software. Uninstall this software unless you put it there yourself |
sfpc.exe |
![]() |
Added by the SOBIG.D WORM! |
cftrb32.exe |
![]() |
SFIRM32 Online Banking software |
sfWinStartupInfo.exe |
![]() |
SafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks" |
Sgecrypt.exe |
![]() |
SafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks" |
Ecview.exe |
![]() |
eAcceleration Stop-Sign security software related. Previously not recommended, see here |
sginst.exe |
![]() |
Canon scanner driver. Is it required? |
SGTBox.exe |
![]() |
StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups |
sgtray.exe |
![]() |
NTI Shadow 3 is an award-winning easy-to-use backup application that automatically protects your photo, music, video, and various data files. It makes data restoration as easy as dragging and dropping files from one place to another |
Shadow.exe |
![]() |
StorageCraft(tm) ShadowUser(tm) provides easy to use desktop security and protection for Windows operating systems. ShadowUser is the best way to prevent unwanted changes to PCs and laptops |
ShadowUser.exe |
![]() |
Added by the REMABL WORM! |
cnf.bat |
![]() |
Added by the REMABL WORM! where * is 2 to 11 |
shambl3r.exe |
![]() |
Added by the SHANIA VIRUS! - NOTE: this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot. Name field may be empty |
Shania.vbs |
![]() |
HP's exclusive Share-to-Web software makes it easy to share content with others through our affiliate Internet websites. In other words an application that allows users to upload scanned images to their personal webpages if desired. Available via Start -> Programs |
hpgs2wnd.exe |
![]() |
Shareaza P2P client |
Shareaza.exe |
![]() |
Shareaza P2P client related |
bindata.exe |
![]() |
Added by the MAKECALL TROJAN! |
sharedprem.exe |
![]() |
Added by the AGENT-FPE TROJAN! |
[path to trojan] |
![]() |
Intel AnyPoint internet sharing software. Now discontinued |
DShmap.exe |
![]() |
Allows you to eject a disk from the Avatar Shark drive from the system tray. When loaded, there is a desktop icon so this isn't required |
AEJCT32.exe |
![]() |
Part of Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents" |
SharpTray.exe |
![]() |
IMSI HiJaak - "the easiest way to convert, capture, and manage all your graphic files" |
chcenter.exe |
![]() |
Added by the VB-DVS TROJAN! |
shdef.exe |
![]() |
Premium rate adult content dialler |
svchst.exe |
![]() |
Added by the EB TROJAN! |
shch.exe |
![]() |
Added by the EB TROJAN! |
winagent.exe |
![]() |
Added by the PPDOOR-R WORM! |
arpo412.exe |
![]() |
Added by the TACTSLAY.B TROJAN! |
nerocheck.exe |
![]() |
Added by the BADSECTOR TROJAN! |
Shell32.exe |
![]() |
Homepage hijacker re-directing browsers to adult content websites |
ray.exe |
![]() |
Homepage hijacker re-directing browsers to adult content websites |
Tray.exe |
![]() |
Added by the GOLDUN TROJAN! |
wmedia16.exe |
![]() |
Added by the SMALL-DL TROJAN! |
Open32.exe |
![]() |
Added by the GP TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System subfolder |
Explorer.exe sound_drive16.exe |
![]() |
Added by the ZLOB TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System (9x/Me) or System32 (NT/2K/XP) folder |
Explorer.exe, msmsgs.exe |
![]() |
Added by the DOYORG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder |
Explorer.exe [path] svchost.exe |
![]() |
Added by the KAKKEYS TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System32 subfolder |
explorer.exe |
![]() |
Added by the KIPIS-U TROJAN! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in a "Microsoft" subfolder |
iexplore.exe |
![]() |
Added by the TORPIG-C and TORPIG-J TROJANS! Filenames spotted include ibm00001.exe, ibm00002.exe, ibm00005.exe and so on |
ibm0000*.exe [* = digit] |
![]() |
Added by the BANCBAN-FT TROJAN! |
taskmrg.exe |
![]() |
Added by the AGENT-FD TROJAN! |
Explorer.exe winupdate.exe |
![]() |
Added by the ANSERIN TROJAN! |
ibm[RANDOM 5 DIGIT NUMBER].exe |
![]() |
Added by the GOLDSPY-B TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
svchost.exe |
![]() |
Added by the TORPIG-Q TROJAN! |
ibm00001.dll |
![]() |
Added by the AGENT-BR TROJAN! |
wmedia32.exe |
![]() |
Added by the TIBICK.C WORM! |
svcnet.exe |
![]() |
Added by a variant of the LOVGATE WORM! |
spollsv.exe |
![]() |
Added by the STULTDOR-A TROJAN! |
ShellTraywnd.exe |
![]() |
Added by the AGOBOT-TH WORM! |
shellexec.exe |
![]() |
Added by the EMERLEOX.S WORM! |
Shell.exe |
![]() |
Added by the SCAFENE WORM! |
Shell32.vbs |
![]() |
Added by the JLOK-A WORM! |
ntldrt.exe |
![]() |
Added by the IRCBOT-AY TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup unless you add it manually! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder |
iexplore.exe |
![]() |
Added by the NETDEV.B TROJAN! |
SHELLMSN.EXE |
![]() |
Added by the NETDEVIL (or NERTE) TROJAN! |
Shellapi32.exe |
![]() |
Added by an unidentified WORM! Note - do not confuse with the McAfee SecurityCenter file of the same name |
mcvsrte.exe |
![]() |
Added by the REMCON-A TROJAN! |
[path to file] |
![]() |
Added by a variant of the AGENT.ALN TROJAN! |
Shelldaemon.exe |
![]() |
Added by the ANAKHA TROJAN! |
ShellEx.exe |
![]() |
Added by the IBILL.Z TROJAN! |
isca.exe |
![]() |
Added by the AV TROJAN! |
A+++.exe |
![]() |
Added by the MSNOPT-A TROJAN! |
lexplore_.exe |
![]() |
Added by the IRCBOT-AY TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup unless you add it manually! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder |
iexplore.exe |
![]() |
Added by the YALER-A TROJAN! |
lsas.exe |
![]() |
Added by the PROXAGE-A TROJAN! |
spools.exe |
![]() |
Added by the UPCHAN TROJAN! |
shellsystem.exe |
![]() |
Added by the AGENT.CE TROJAN! |
shhost.exe |
![]() |
Installed with the drivers for multi card readers of various brands. To differentiate between the various card slots on multi slot readers the shicoxp.exe file assigns and loads unique drive icons for the various card slots that are displayed in Windows Explorer |
shicoxp.exe |
![]() |
Added by the HAPPYLOW (or NISHE-A) VIRUS! |
Shine.exe |
![]() |
?? |
shinitv.exe |
![]() |
Added by the GASTER TROJAN! |
ibot4.exe |
![]() |
Shockmachine is a stand-alone application that lets users collect Macromedia Shockwave and Flash titles and play them offline. Could be a registration reminder for the trial version |
SmReminder.exe |
![]() |
Added by the SNDOG WORM! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
csrss.exe |
![]() |
Part of Macromedia Shockwave. Controls the Shockwave Remote Control Panel. The Remote Control can be activated manually from the Start Menu by locating and selecting Shockwave and then Shockwave Remote under Programs |
SWINIT.EXE |
![]() |
Added by the DELF-DRA WORM! |
FlashPlayer.exe |
![]() |
ShortKeys from Insight Software Solutions - allows you to program keys with text strings |
SHORTKEY.EXE |
![]() |
ShortKeys Lite from Insight Software Solutions, Inc. A macro utility to automate a task that you perform repeatedly or on a regular basis |
shklite.exe |
![]() |
Special function key manager for Chicony keyboards - see here |
sHotKey.exe |
![]() |
Advertisement display which can be stopped here |
SHOWBEHIND.EXE |
![]() |
Added by the Adware.FFToolBar adware toolbar |
ShowFF.exe |
![]() |
Related to Just Rams USB product driver. Is it required? |
shwicon.exe |
![]() |
PNY Attach‚ USB flash memory stick System Tray icon - shows when the device is plugged in |
shwicon.exe |
![]() |
Card reader for memory cards from digital cameras. Is it required? |
shwicon.exe |
![]() |
Note that there is a strange symbol in the command field. HKLMSoftwareMicrosoftWindowsCurrent VersionRunShowLOMControl Reg_DWORD 0x00000001 (1) LOM = LAN on Motherboard.It mean Show "LAN on Motherboard" Control.On systems where you can install an external LAN interface, it will warn you that you already have a built-in LAN interface. Appears to be a feature on certain Dell systems |
[strange symbol] |
![]() |
Added by the HANDLE-A VIRUS! |
Ruden.vbs |
![]() |
Found on Gateway computers (and maybe others) - see here. "Showwnd is included with the Chicony keyboard software and is used by the software to stop the keyboard driver's taskbar entry from reappearing. It is not necessary to remove the keyboard software, however if you wish it can be removed through Add or Remove Programs" |
ShowWnd.exe |
![]() |
Port monitor for Lexmark printers on a USB connection. Ties in with the Printer Control Program. Features like cancelling a print are unavailable if disabled |
SHPC32.exe |
![]() |
From McAfee VirusScan NT 4.x. Handles program communication among VShield components, displays VShield icon. Can be started automatically or available via Start -> Programs |
SHSTAT.EXE |
![]() |
Loaded by the SWEEX 6-in-1 Media Card Reader to properly manage the reader while it is connected to your system |
shutdownaware.exe |
![]() |
ShutDownPro - shutdown, reboot, logoff your System with one mouse click |
ShutDownPro.exe |
![]() |
Si Meter - keep track of things like CPU activity, network activity and speed, hard-drive activity, hard-drive space, system memory, running processes, or just date and time |
SIMETER.EXE |
![]() |
LZIO.com adware downloader |
rundll32.exe [path] si91e44b.dll, EnableRunDLL32 |
![]() |
Part of Steganos Internet Anonym privacy software |
SIA2006.exe |
![]() |
Steganos Internet Anonym privacy software |
sia.exe |
![]() |
Added by the NETLIP WORM! |
Sicom.exe |
![]() |
SideACT organizer software |
SideACT.exe |
![]() |
Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. But on other versions of Windows it can be a part of the Searchcentrix hijacker |
Sidebar.exe |
![]() |
Desktop Sidebar provides you with instant access to the information you most desire by grabbing data from your PC and the internet. The result is a dynamic visual display you configure and control |
dsidebar.exe |
![]() |
MS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs |
SWTrayV4.exe |
![]() |
Sigmatel audio driver |
setup.exe |
![]() |
System tray program for the Sigmatel Audio sound card. Often found on Dell computers |
stsystra.exe |
![]() |
System tray program for the Sigmatel Audio sound card. Often found on Dell computers |
sttray.exe |
![]() |
?? |
sigx.exe |
![]() |
SigX is a "dynamic signature image generated based on whatever data your computer sends it though our SigX program. It can display your current Mp3, current OS, Free Ram, your current time and more" |
SigX.exe |
![]() |
Simcast is a free service that allows you to subscribe to information on a large variety of topics. Alerts will appear on your desktop when a channel that you have subscribed to has something to say |
SimcastAlerts.exe |
![]() |
Simple Star PhotoShow photo editing and organizing software, makes it easy to send and share digital photos. Bundled with software from Nero, ComCast, SnapFish, MacroMedia and others |
mssysmgr.exe |
![]() |
Required if you use the SimpLite add-on to MSN Messenger (SimpLite adds encryption to the instant messaging service) |
SimpLite-MSN.exe |
![]() |
Added by the SILLYFDC-AB WORM! |
.exe |
![]() |
Adds a blue crescent to the taskbar and when double-clicked displays an adult-content web-site. Also known to drop your internet connection and dial an international telephone number. See here for more information. Must be disabled in MSCONFIG before un-installing or it re-instates itself |
singapore.exe |
![]() |
Web.de Internet phone utility |
SIPPSSIPPS.exe |
![]() |
Added by the DLOADER-UE TROJAN! |
dnssvc.exe |
![]() |
SiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required |
khooker.exe |
![]() |
Added by an unidentified WORM or TROJAN! |
mpcsvc.exe |
![]() |
Added by the CIAFOOR-CJ TROJAN! |
mpcsvc.exe |
![]() |
System Tray icon for SiS based graphics. Note - this resides in C:WindowsSystem |
sistray.exe |
![]() |
SIS graphics cards related: "Super VGA Keyboard Daemon" - hooks into the keyboard processing chain in order to enable hotkey settings |
keyhook.exe |
![]() |
SiS Corporation sound card driver |
SiSAudUt.exe |
![]() |
?? |
SISAM10M.exe |
![]() |
WinME patch for an older SiS 961 chipset FERR bug. Enable if you have audio problems |
MP_S3.exe |
![]() |
Probably on-board graphics related based upon the SiS chipsets. Has been seen on ASUS motherboards with SiS chipsets and known to cause conflicts if you choose another graphics card and disable the on-board |
color.exe |
![]() |
Spam Inspector - anti email spam software |
siService.exe |
![]() |
Responsible for power management for SIS chipsets - is it required? |
Rundll32.exe SiSPower.dll, ModeAgent |
![]() |
Related to the SIS Raid system from Silicon Integrated Systems |
SRaid.exe |
![]() |
Related to a Silicon Integrated Systems Corp (SiS) product? |
SiSSetCDfmt.exe |
![]() |
Related to a Silicon Integrated Systems Corp (SiS) product? |
Soundman.exe |
![]() |
System Tray utility for SiS 900 network cards |
sisswled.exe |
![]() |
Added by the PROVA TROJAN! |
sistrai.exe |
![]() |
Added by the PROVA TROJAN! |
sistray.exe |
![]() |
System Tray icon for SiS based graphics. Note - this resides in C:WindowsSystem |
sistray.exe |
![]() |
Added by the HOLCAS.A WORM! |
remotehost.pif |
![]() |
Added by the JUMPRED.A WORM! |
win.bat |
![]() |
Added by the TOMETA-C TROJAN! |
virus.exe |
![]() |
Added by the CEBE WORM! |
sistry.exe |
![]() |
SiS USB Registry Patch File - fixes the undetectable problem with SiS USB controller on Windows XP |
SiSUSBrg.exe |
![]() |
SiteAdvisor from McAfee warns you before you interact with a dangerous Web site |
SiteAdv.exe |
![]() |
Added by the HANSAH-A WORM! |
ntoskernel.exe |
![]() |
Added by an unidentified WORM or TROJAN! |
sscc.exe |
![]() |
Medload adware |
sixtypopsix.exe |
![]() |
SaveKeys keystroke logger/monitoring program - remove unless you installed it yourself! |
SK51.EXE |
![]() |
SaveKeys keystroke logger/monitoring program - remove unless you installed it yourself! |
SK60.EXE |
![]() |
Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys |
SK9910DM.EXE |
![]() |
Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys |
SKDAEMON.EXE |
![]() |
Selection of desktop messaging/marketing tools with celebrity tie-ins including MTV's "Desktop Ozzy" and Arsenal's "Desktop Wenger" - see here. Leave enabled if you want to receive messages |
skinkers.exe |
![]() |
SpyKeySpy logs keystrokes and sends the stolen information to a configurable email address |
SKS32P~1.EXE |
![]() |
Added by the SUNK-A WORM! Note - this file is found in the root folder (C:), (D:), etc |
Skunk.exe |
![]() |
For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system |
SSFSch.exe |
![]() |
Added by the SASSER.D WORM! |
skynetave.exe |
![]() |
Added by the NETSKY.AA WORM! |
winlogon.scr |
![]() |
Skype is free and simple software that will enable you to make free calls anywhere in the world in minutes |
Skype.exe |
![]() |
Added by the VANBOT-C WORM! |
skyp.exe |
![]() |
SkypeMate acts as a bridge between networks of VoIP and PSTN |
SkypeMate.exe |
![]() |
Added by the PYKSE-A WORM! |
Skype.exe |
![]() |
For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system |
SmaServ.exe |
![]() |
Process associated with Realtek Voice Manager for some of their audio chipsets |
SkyTel.exe |
![]() |
Added by the SDBOT-QC WORM! |
rbot32.exe |
![]() |
Added by a variant of the SDBOT WORM! |
mfcee.exe |
![]() |
Added by the SIKBOT-A TROJAN! |
slay7383.exe |
![]() |
This program locates free contiguous disk spaces and allocates them for storing BASE MEMORY, EXTENDED MEMORY, VIDEO MEMORY, and SM RAM. It helps the computer come out of hibernate mode |
SleepMgr.exe |
![]() |
Sliber - freeware screen capturing & online sharing tool |
Sliber.EXE |
![]() |
SlickRun is a floating command line utility for Windows. It gives you almost instant access to any program or website. SlickRun allows you to create command aliases (known as MagicWords), so C:Program FilesOutlook Expressmsimn.exe becomes MAIL |
sr.exe |
![]() |
Added by the GASLIDE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
Iexplore.exe |
![]() |
Slimp3 Server - "presents an entirely new way of accessing and enjoying your music collection. Instead of storing your music on CDs or memory cards, the SliMP3 uses your home network to access the music stored on your PC" |
SliMP3 Server.exe |
![]() |
Atomica Slingshot - "reference tool with access to dictionary and encyclopedia terms, bios, technical terms, history, geography, and much more". Now superseed by 1-Click Answers |
SLINGS~1.EXE |
![]() |
Core module for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet, Wanadoo, Terra, OnSpeed, United Online and AOL Canada. Required if the user's account is locked in to that proxy server |
slipcore.exe |
![]() |
User interface for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet, Wanadoo, Terra, OnSpeed, United Online and AOL Canada. Required if the user's account is locked in to that proxy server |
slipgui.exe |
![]() |
Core module for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet, Wanadoo, Terra, OnSpeed, United Online and AOL Canada. Required if the user's account is locked in to that proxy server |
slipcore.exe |
![]() |
SeekSeek search hijacker related - see here |
slmss.exe |
![]() |
Win SynchroAd adware, also detected as DLOADER-QG TROJAN! |
sload.exe |
![]() |
Added by an unidentified VIRUS, WORM or TROJAN! |
slvchost32.exe |
![]() |
Added by the OLFEB.A TROJAN! |
sa_exe.exe |
![]() |
Added by the OLFEB.A TROJAN! |
sf_exe.exe |
![]() |
Added by the OLFEB.A TROJAN! |
sm_exe.exe |
![]() |
Added by the LUKUSPAM TROJAN! |
sr_exe.exe |
![]() |
Added by the IROFFER.CT TROJAN! |
iro.bat |
![]() |
USB driver for downloading from within Napster and iTunes to portable MP3 players. Only required at startup if you use it all the time - otherwise start it manually when required |
SM1BG.EXE |
![]() |
Cypress USB Mass Storage Driver Notification Icon Application - tray notification for Cypress base memory sticks and external storage devices for Win98 |
SM1NINT.exe |
![]() |
Helper utility for Motorola based SM56 software modems - resides in the System Tray |
sm56hlpr.exe |
![]() |
Helper utility for Motorola based SM56 software modems - resides in the System Tray |
sm56hlpr.exe |
![]() |
Unidentified adware |
app***.tmp [* = digit] |
![]() |
Added by the AGENT.BJO TROJAN! |
smanager.*.exe [* = digit] |
![]() |
Added by the DWNLDR-GVG TROJAN! |
smanager.7.exe |
![]() |
Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder |
winlogon.exe |
![]() |
System Tray access for the Compaq/ADI SoundMAX integrated digital audio controller |
smtray.exe |
![]() |
For Smart Card readers. Known to cause problems, especially for Windows 2000 users - see here. Probably not required unless you use such a device regularly |
ScardSvr.exe |
![]() |
Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio |
SCMon.exe |
![]() |
Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio |
SCSetup.exe |
![]() |
Netropa Smart Keyboard driver |
Smartkbd.exe |
![]() |
Part of the printer software for the smart-label printer made by Seiko. Can be disabled safely |
ssloserv.exe |
![]() |
Part of the printer software for the smart-label printer made by Seiko. Can be disabled safely |
SSLFVIEW.EXE |
![]() |
Part of Presto! Mr.Photo - "an ideal program for creating, sharing, and manag-ing digital images and videos" |
PnPDetect.exe |
![]() |
Related to Plustek OpticSlim scanner |
STouch.exe |
![]() |
Smart Type Assistant - a complex typing automation tool, intended to make your work faster and safer |
sta.exe |
![]() |
Smartalec PC Accelerator - system optimization utility |
pcaccel.exe |
![]() |
Conexant SmartAudio PC audio chipset software - typically available on HP notebooks with built-in microphones |
SmartAudio.exe |
![]() |
SmartBarXP is a bar that runs down the side of your screen, and can be configured to display interactive panels known as 'panes'. These panes include media players, slideshow and image viewing panes, a virtual desktop manager, and live news, weather and stock feeds to mention but a few |
SmartBarXP.exe |
![]() |
sMaRTcaPs from Phoebus LLC - enables you to configure the time needed to depress Caps Lock, Num Lock & Insert keys |
SMARTC~1.EXE |
![]() |
IObit SmartDefrag helps defragment your hard drive more efficiently than any other product on the market - free or not |
IObit SmartDefrag.exe |
![]() |
Samsung smarthru software, used with Lexmark Z82 or Samsung multifunction printers |
QS.exe |
![]() |
Smartalec PC Accelerator - system optimization utility |
pcaccel.exe |
![]() |
Related to CompanionLink Software Inc. Synchronization solutions for ACT!, GoldMine, Lotus Notes and Microsoft Outlook |
SmartSync.exe |
![]() |
System Tray icon for SoundMax integrated sound. Sound properties can be accessed through the Start Menu or Control Panel |
SMax4.exe |
![]() |
SoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments |
SMax4PNP.exe |
![]() |
IBM Netfinity Director and Universal Management Services related. What does it do and is it required? |
smbdpmi.exe |
![]() |
Sygate Firewall |
smc.exe |
![]() |
Sygate Firewall |
spfsmc.exe |
![]() |
Sygate Firewall |
smc.exe |
![]() |
Sygate Firewall |
spfsmc.exe |
![]() |
Added by the AGOBOT-OU WORM! |
winsrv.exe |
![]() |
Sygate Firewall |
smc.exe |
![]() |
Sygate Firewall |
smc.exe |
![]() |
Sygate Firewall |
spfsmc.exe |
![]() |
Added by the SCLOG-AJ TROJAN! |
smcss.exe |
![]() |
SMC Networks wireless PCI card driver. Is it required? |
Smcsta.exe |
![]() |
Added by the LEGMIR.JU TROJAN! |
SmcSVR.exe |
![]() |
Covert Sys Exec malware variant |
mgrs.exe |
![]() |
Added by an unidentified WORM or TROJAN! |
smgr.exe |
![]() |
Smiley District adware |
plugin.exe |
![]() |
Smith Micro shared files. Comes with D-Link web cam |
smiptray.exe |
![]() |
UserMonitor from Neuber. Teachers can broadcast screen to other screens, see students screens in a network and detect unauthorized software |
smodule.exe |
![]() |
TOSHIBA Zooming Utility - allows "automatic" zoom feature in some appications, like IE, MS-Office, WMPlayer, Adobe Reader and also desktop icons |
SmoothView.exe |
![]() |
Smart Phone Recorder demo from KenGolf.com. Answering Machine, Caller ID, Call Recording |
smpdemo.exe |
![]() |
Set Up My PC utility supplied with some Packard Bell computers |
SmpSys.exe |
![]() |
Added by the AGOBOT-UA WORM! |
smres.exe |
![]() |
Added by the IROFFER.CT TROJAN! |
iro.bat |
![]() |
Microsoft Systems Management Server - used to manage computers on a network remotely |
LAUNCH32.EXE |
![]() |
When the SMS Client service starts on a domain controller, the Client service modifies the SMSCliToknAcct & user account group membership, user rights, and account comment. The Client service then waits for the synchronization of the comment to verify that the account and user rights are properly set for this account. This account is used to obtain a token to start the SMS Client processes, such as the Software Inventory and Software Distribution agents (MS Systems Management Server) |
clisvc95.exe |
![]() |
Unidentified malware |
SmsSystem32.exe |
![]() |
This program assigns a user to a Systems Management Server site |
?? |
![]() |
This program assigns a user to a Systems Management Server site |
SMSMsg.exe |
![]() |
Helper utility for Motorola based SM56 software modems - resides in the System Tray |
sm56hlpr.exe |
![]() |
Smith Micro HotFax - fax software |
SMLoader.exe |
![]() |
Added by the BANKER-CO TROJAN! |
smsm.exe |
![]() |
Added by the AGOBOT-SX WORM! |
smsrv.exe |
![]() |
Added by the FLOOD.F TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "Catroot" subfolder |
smss.exe |
![]() |
Added by the ALADINZ.F TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup! |
[path to smss.exe] |
![]() |
Added by the AGENT-TR TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
smss.exe |
![]() |
Added by the BOROBOT-J TROJAN and variants! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup! |
smss.exe |
![]() |
Added by the RBOT.OP WORM! |
ssms.exe |
![]() |
Added by the DALBUG WORM! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
csrss.exe |
![]() |
Unidentified malware! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in Program FilesWindows Media PlayerSkinsWindowsMediaSkinDataLevel4 folder |
smss.exe |
![]() |
Added by the SDBOT.ZD WORM! |
smsss.exe |
![]() |
Added by the AGOBOT.MQ WORM! |
smsss.exe |
![]() |
Hijacker, detected by Norton antivirus as Trojan.StartPage.O |
SMSSU.EXE |
![]() |
Added by the CLICKER-C TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in a "Template" subfolder |
Explorer.exe |
![]() |
Adult content dialler |
vi.exe |
![]() |
Part of the Iolo System Mechanic optimization tool |
SMSystemAnalyzer.exe |
![]() |
Added by an unknown WORM or TROJAN! |
sms_msn.exe |
![]() |
Added by an unknown WORM or TROJAN infection |
sms_msn40.exe |
![]() |
Win-Spy keyboard logger/monitoring software - remove unless you installed it yourself |
SMT.exe |
![]() |
StartMake.com toolbar |
SMToolbar.exe |
![]() |
Added by a variant of the RBOT WORM! |
smtp32.exe |
![]() |
SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required? |
SmWizard.exe |
![]() |
Added by the RBOT-AVP WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility |
msnmsgr.exe |
![]() |
SnagIt lets you capture, edit, and share exactly what you see on your screen - fast |
SnagIt32.exe |
![]() |
Added by the FORBOT-EG WORM! |
snapple.exe |
![]() |
?? |
snbr.exe |
![]() |
UpSpiralBar adware |
snbupt.exe |
![]() |
Added by the DLUCA-I TROJAN! |
sncntr.exe |
![]() |
Unidentified "Snapshot Viewer"- what does it do and is it required? |
vsnct511.exe |
![]() |
Added by the B1LD0 AIM WORM! |
snd332.exe |
![]() |
Added by the GEMA TROJAN! |
Sndcompat.exe |
![]() |
Driver for DualCam cameras - that combine the best features of a digital still camera and a webcam |
vsndmi13.exe |
![]() |
Part of Symantec's LiveUpate (eg, Norton). Not required if you run manual updates but probably require if you leave them to run automatically. Also, if one runs a small office network and SNDMon is disabled on one of the computers - then other computers disappear from the network for this computer, including shared devices like printers and scanners. Hence the "U" recommendation |
SNDMon.exe |
![]() |
Added by the GEMA TROJAN! |
Sndsaver.exe |
![]() |
Part of Norton Personal Firewall and Norton Internet Security - what does it do and is it required? |
SNDSRVC.EXE |
![]() |
Spy Sheriff/SpywareNO malware, also detected as the SPYHOAX-A TROJAN, pretends to be a spyware remover! - file names spotted sofar include VXH8JKDQ2.EXE, NS6281400.so, CVXH8JKDQ2.EXE, down3.exe, sefe.exe, winstall.exe, and tool2.exe |
[various filenames] |
![]() |
The Snipping Tool (part of the Experience Pack for Tablet PC) allows you to easily "cut out" anything on screen and share it with other people. The whole screen becomes an "inkable" surface that you can add comments to and mark up however you like. You can then save that annotated image to use later, or send it to someone else in an E-mail message |
SnippingTool.exe |
![]() |
SpyNoMore anti-spyware |
SNM.exe |
![]() |
Anti-keylogging software made by SnoopFree Software |
SnoopFreeUI.exe |
![]() |
Added by the ZAPCHAS-O TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
svchost.exe |
![]() |
Digital camera related |
vsnp2std.exe |
![]() |
Sonix PC Camera Monitor MFC Application. What does it do and is it required? |
vsnpstd.exe |
![]() |
CameraMonitor MFC Application. Appears to be related to a USB connection to a digital camera -is it required? |
vsnpstd2.exe |
![]() |
Sonix Inc. Camera Monitor MFC Application |
vsnpstd3.exe |
![]() |
Launches a screensaver program from Second Nature |
Snsicon.exe |
![]() |
Added by the Nunci premium rate dialer |
SNSS.EXE |
![]() |
Added by an unidentified WORM or TROJAN! |
snvc.exe |
![]() |
StarOffice 5. See here for more details |
sointgr.exe |
![]() |
StarOffice 5. See here for more details |
sointgr.exe |
![]() |
PurityScan/Clickspring adware |
Rwon.exe |
![]() |
Added by a variant of the RBOT WORM! |
rpcxsocsa.exe |
![]() |
Added by the SDBOT TROJAN! |
sock32.exe |
![]() |
Added by the DAEMONI-E TROJAN! |
svchostz.exe |
![]() |
Added by the DAEMONI-E TROJAN! |
socket.exe |
![]() |
Added by the DAEMONI-E TROJAN! |
svchostz.exe |
![]() |
Used by the IBM Rational SoDA project management tool. Unsure of it's actual purpose but it's recommended you leave it enabled if you use the software |
SodaStartup.exe |
![]() |
Displays StarOffice quick start applet in System tray. Right clicking on the icon allows rapid starting up of components of the StarOffice 6.0 suite. Available via Start -> Programs. Automatically started when any StarOffice 6.0 component is started from the Start -> Programs. A resource hog (it eats > 16 MB of memory). |
SOFFICE.EXE |
![]() |
Added by a variant of the LOVGATE WORM! |
hxdef.exe... |
![]() |
Added by the KARDPHISHER TROJAN! |
********.exe [* = random digit] |
![]() |
Added by the RBOT-ANB WORM! |
wininits.exe |
![]() |
Softick PPP is a Microsoft Windows driver that allows to establish PPP session between Palm powered devices and Microsoft Windows desktop computer |
PPPGate.exe |
![]() |
For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out |
N/A |
![]() |
AzureBay wallpaper changer |
softstrt.exe |
![]() |
Added by the CRABTON-B TROJAN! |
software.exe |
![]() |
eAcceleration Stop-Sign security software related. Previously not recommended, see here |
station.exe |
![]() |
Solo Antivirus |
Solosent.exe |
![]() |
Scheduler for Solo Antivirus. Leave enabled unless you scan manually on a regular basis |
Solocfg.exe |
![]() |
Solo antivirus System Integrity Check - Monitors system registry, system.ini, win.ini and startup to protect you from new Internet Worms and Backdoors |
Syscheck.exe |
![]() |
Searchcentrix hijacker |
somatic.exe |
![]() |
Sound related options |
vrtxctrl.exe |
![]() |
Added by a variant of the SDBOT WORM! |
smsc.exe |
![]() |
Sonic Focus - "enhances music, movie and game sound by analyzing compressed audio streams in realtime, then restoring and enriching audio back to its original performance qualities" |
SFIGUI.EXE |
![]() |
Quickstart for the discontinued Sonique audio player. Available via Start -> Programs |
sqstart.exe |
![]() |
Now superseeded by ColorWizzard - 3Deep corrected lighting, shading and color for all your 2D and 3D games. Possibly a registration reminder? |
SonnReg.exe |
![]() |
Added by the STARTPAGE.Q TROJAN! |
SonudMan.exe |
![]() |
Added by the QQROB-DC TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
WNILOGON.exe |
![]() |
Added by the LEWOR-J TROJAN! |
SonudMon.exe |
![]() |
Application launcher from the Sony Ericsson PC Suite for their mobile phones |
Application Launcher.exe |
![]() |
Related to Sony VAIO Power Management Module installed on laptops and provides additional configuration options for these devices. This program is non-essential process to the running of the system, but should not be terminated unless suspected to be causing problems |
SPMgr.exe |
![]() |
?? |
rcea.exe |
![]() |
Possibly related to Sophocles Screenwriting Software? |
sophagnt.exe |
![]() |
Advertising by SoftwareOnline - monitors your browsing habits and distributes the data back to the author's servers for analysis |
rundll32 shell32.dll, ShellExec_RunDLL [path] soproc.exe |
![]() |
Added by the PHILIS VIRUS! |
SOS.exe |
![]() |
SuperOffice related. What does it do and is it required? |
SoSyncMonitor.exe |
![]() |
Added by the AGOBOT-BV WORM! |
sndloader.exe |
![]() |
Added by the AGOBOT.GG WORM! |
SOUND32.EXE |
![]() |
Added by an unidentified VIRUS, WORM or TROJAN! |
WinSound1.exe |
![]() |
Added by the GAOBOT.AFJ WORM! |
soundcontrl.exe |
![]() |
CoolWebSearch parasite variant |
sndbdrv3104.exe |
![]() |
Control panel item for the Terratec DMX Xfire 1024 soundcard (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time? |
rundll32 cwcprops.cpl |
![]() |
Control panel item for Hercules Fortissimo soundcards (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time? |
rundll32 hercplgs.cpl, BootEntryPoint |
![]() |
Control panel item for a Terratec soundcard (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time? |
RunDll32 cwaprops.cpl, C25CrystalControlWnd |
![]() |
Added by the QQROB-AAL TROJAN! |
SVOHOST.exe |
![]() |
System Tray icon for the Realtek AC97 Audio Sound Manager for AC97 onboard audio. Available via Start -> Settings-> Control Panel |
soundman.exe |
![]() |
Added by the RBOT-AIU WORM! |
soun.pif |
![]() |
System Tray icon for SoundMax integrated sound. Sound properties can be accessed through the Start Menu or Control Panel |
SMax4.exe |
![]() |
Added by the RIZON-A WORM! Note - this file is placed in the Startup folder itself, and has NO relation to SoundMax sound cards! |
SoundMAX.exe |
![]() |
Added by a variant of the SDBOT WORM! |
SndMAX.exe |
![]() |
SoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments |
SMax4PNP.exe |
![]() |
Added by the AGENT.PGV WORM! |
soundmix.exe |
![]() |
Added by the DEDLER-G TROJAN! |
smvss.exe |
![]() |
Added by the STRATION-FW WORM! |
[path to worm] |
![]() |
CoolWebSearch Tapicfg parasite variant |
Soundmx.exe |
![]() |
Added by the AGOBOT-MD WORM! |
soundtask.exe |
![]() |
Added by a variant of the CRYPTER.C TROJAN! |
soundtasks.exe |
![]() |
Added by the AGOBOT-ZV WORM! |
soundtctrls.exe |
![]() |
Trojan downloader |
msdview32.exe |
![]() |
Added by the AGOBOT-ND WORM! |
sounofts.exe |
![]() |
Added by an unidentified WORM or TROJAN! |
sountaskmgr |
![]() |
Used to update Gateway registry settings for System Restoration Kit and Web update programs |
gwreg.exe |
![]() |
IE search hijacker - changes the default search to http://www.gocybersearch.com/ |
sp.reg |
![]() |
Malicious javascript annoyance that changes the default search engine in IE to one of many including "topsearcher". See here for more and a fix |
regedit-s .... sp.dll |
![]() |
Added by the Startpage.M hijacker |
se.dll, DllInstall |
![]() |
Added by the ABLANK-W and ABLANK-Z TROJANS! |
rundll32 (Path to Trojan DLL), DllInstall |
![]() |
SP TimeSync lets you synchronize your computer's clock with any Internet atomic clock (time server) |
SP TimeSync.exe |
![]() |
Added by the GRAYBIRD.E TROJAN! |
Sp00lsv.exe |
![]() |
Changes limit of concurrent TCP connections of Windows Service Pack 2 |
SP2ConnPatcher.exe |
![]() |
Added by a variant of the RANDON.AN WORM! |
[path] repcale.exe [path] apc.exe |
![]() |
Added by the RBOT.BJO WORM! |
crssrs.exe |
![]() |
Added by the ALUROOT.A TROJAN! |
sp2chk.exe |
![]() |
Added by the DLUCA-M TROJAN! |
sp2ctr.exe |
![]() |
Added by the SMALL.ABW TROJAN! |
sp2fwxp.exe |
![]() |
SP2Update adware! Tracks URLs visited and search terms entered into Internet Explorer |
sp2update.exe |
![]() |
HotBar related |
SBInst.exe |
![]() |
Added by the SDBOT.AOU WORM! |
mfirewall.exe |
![]() |
Spam Sleuth E-mail spam detection program |
SpamSleuth.exe |
![]() |
Related to Hotbar's Weather Forecast tool for your desktop |
SbOEAddOn.exe |
![]() |
SPAMfighter anti email spam filter |
SFAgent.exe |
![]() |
Spamihilator - spam filter |
spamihilator.exe |
![]() |
SpamPal - anti-spam tool |
spampal.exe |
![]() |
Intermute SpamSubtract - junk email detection and removal program |
SpamSubtract.exe |
![]() |
Spark instant messaging server |
Spark.exe |
![]() |
NetZero Search Enhancement related |
hcm.exe |
![]() |
NetZero Search Enhancement related |
blspc.exe |
![]() |
NetZero Search Enhancement related |
nzspc.exe |
![]() |
Norton Utilities Speed Start. "This feature optimizes the start up speed of launching applications, such as Word and Excel." |
Spdstart.exe |
![]() |
Speaking Clock Deluxe - turns your computer into a speaking clock with several languages. It can also keep track of up to 50 alarms that can be set to a time and a date, and be repeated daily, weekly, monthly and yearly |
SpClDlx.exe |
![]() |
Added by the NETSKY.G WORM! |
avguard.exe |
![]() |
SpecialOffers adware |
SpecialOffers*.exe [* = digit] |
![]() |
SpecialOffers adware |
SpecialOffers.exe |
![]() |
Added by a variant of the SDBOT WORM! |
specixic.exe |
![]() |
Software for a Creative sound card |
CTSRReg.exe |
![]() |
Accel SpeedTec from Montana Software speeds up your modem. SpeedTec modifies the Internet Protocol settings in the Windows registry to speed downloads on all modems. If you find this improves your connectivity and download speeds leave this enabled |
speedtec.exe |
![]() |
Added by the OPASERV.AD WORM! |
[worm filename] |
![]() |
Speed It Up - "all in one Speed Booster designed to significantly increase the speed of your computer and boost your PC available memory" |
SPEEDITUP.EXE |
![]() |
Speed-It-Up Extreme is designed to speed of your computer up to 3 times faster and boost your PC available memory |
SpeedItUpEx.exe |
![]() |
Additional keyboard shortcuts on MS programmable keyboard |
SPEEDKEY.EXE |
![]() |
Application measuring upload and download speed |
SpeedMeter.exe |
![]() |
SpeedOptimizer is designed to optimize and speed-up your Internet data transmission including browsing, streaming, downloading, uploading and e-mail communication |
spo.exe |
![]() |
SpeedswitchXP is a CPU frequency control for notebooks running Windows XP |
SpeedswitchXP.exe |
![]() |
For an external Alcatel ADSL high-speed modem. A diagnostic tool and can be run from the Start menu when required. The only reason it might be useful on startup is if you like seeing an 'at-a-glance' status indicator on the taskbar (the icon is a different colour depending on the status of the device/line) |
Dragdiag.exe |
![]() |
SpeedUpMyPC "automatically fine-tunes all your resources including hardware, system settings and internet usage to operate at peak performance at all times" |
SpeedUpMyPC.exe |
![]() |
Added by the OPASERV.Y WORM! |
speedy.scr |
![]() |
Added by the OPASERV.AD WORM! |
Speedy.bat |
![]() |
Added by the OPASERV.AD WORM! |
SPEEDY.PIF |
![]() |
Spellex-Anywhere - adds spell checking functionality to almost any Window program. Create a shortcut and run manually before it's to be used |
sa.exe |
![]() |
DrWeb antivirus Spider Mail e-mail scanner |
spiderml.exe |
![]() |
Spinner Plus lets you listen to over 100 channels of music broadcast from Spinner.com. Spinner Plus uses RealNetwork's G2 technology to provide high-quality online audio. The technology adjusts the audio streaming to match your Internet connection speed, which helps eliminate sound distortion or choppiness. Available via Start -> Programs |
spinner.exe |
![]() |
Added by the YENO.B and YENO.C WORMS! |
Wscript.exe OXNEY.B.VBS |
![]() |
Related to Creative audio products. What does it do and is it required? |
Rundll32 SPIRun.dll, RunDLLEntry |
![]() |
Premium rate adult content dialler |
SPnt.exe |
![]() |
Spoke Software client application. Spoke "uses data in your e-mail and other enterprise information systems to discover the existing relationships of people in your enterprise. It then builds a private, secure relationship network for each user without any additional manual data entry" |
SpokeSysTray.exe |
![]() |
Added by the EVILSOCK.10 TROJAN! Note - this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot. Name field may be empty |
spolsvr2.exe |
![]() |
Added by the SOULJET TROJAN! |
spoo1sv.exe |
![]() |
Added by the RANKY.R TROJAN! |
[path to trojan] |
![]() |
WhileUSurf adware |
wys.exe |
![]() |
Added by the SDBOT-KD WORM! |
spoolsvc.exe |
![]() |
Added by a variant of the RBOT WORM! |
spool.exe |
![]() |
Added by a variant of the RBOT WORM! |
spoolv.exe |
![]() |
RapidBlaster variant (in a "spool" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
spool.exe |
![]() |
Added by the BANKER-FR TROJAN! |
spoolsrv.exe |
![]() |
RapidBlaster variant (in a "spool" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
spool.exe |
![]() |
Added by the ASSASIN-F TROJAN! |
pool32.exe |
![]() |
Added by the PERDA-D TROJAN! |
[path to trojan] |
![]() |
Added by the JOINER.C1 TROJAN! |
Spoolsrv.exe |
![]() |
Added by the YAB.A TROJAN! |
SPOOL32.EXE |
![]() |
Added by the SDBOT-ABG TROJAN! |
spoolsub.exe |
![]() |
Added by the POEBOT-J WORM! |
spoolsvc.exe |
![]() |
Added by the LINKBOT.M WORM! |
spooIsv.exe |
![]() |
Added by the DLOADER-NY TROJAN! |
localsvc.exe |
![]() |
Added by the DLOADER-NY TROJAN! |
netsvc.exe |
![]() |
Added by the DLOADER-NY TROJAN! |
spoolsvc.exe |
![]() |
Added by the DLOADER-NY TROJAN! |
svcadmin.exe |
![]() |
Added by the DLOADER-NY TROJAN! |
svcman.exe |
![]() |
Added by the DLOADER-NY TROJAN! |
svcrun.exe |
![]() |
Added by the DLOADER-NY TROJAN! |
tcpsvc.exe |
![]() |
Added by the DLOADER-NY TROJAN! |
websvc.exe |
![]() |
Added by the SDBOT-MM WORM! |
spoolsvc.exe |
![]() |
Added by the EHKS.21 keylogger! Note - the "I" between "o" and "3" is a capital "i" not a lower case "L" |
SpooI32.exe |
![]() |
Added by the KASSBOT-C WORM! |
spools.exe |
![]() |
Added by the SDBOT-PN WORM! |
spoolserv.exe |
![]() |

Main Page 



