| Status Code | Name | Command | Description |
| U | SZMsgSvc.exe | SZMsgSvc.exe | StopZilla! - pop-up killer |
| X | SYS_CLEAN | Service.exe | Added by the FLOPCOPY WORM! |
| X | Syswindow | Syswindow.exe | Added by the COW TROJAN! |
| X | syswin32 | syswin32.exe | Added by a variant of the SPYBOT WORM! |
| X | SysWin | SysWin.exe | Added by the IRCCONTACT TROJAN! |
| U | SYSWB6 | SYSWB6.exe | We-Blocker - gives parents the opportunity to monitor their children's Internet access and provide them with age-appropriate content, while filtering out sites that contain adult content |
| U | SysW8 | csta.exe | Clean Space - privacy and perfomance enhancer |
| X | Sysvupex | Sysvupex.exe | Added by the MEDIAS TROJAN! |
| X | SysUpd | Sysupd.exe | VirtuMonde adware |
| X | Systryt | [path to worm] | Added by the AUTEX WORM! |
| X | sysu | sysu.exe | Dynamic Desktop Media adware - see here |
| X | Systry | [path to worm] | Added by the AUTEX WORM! |
| X | systree | systree | Added by the BANCOS.L TROJAN! |
| X | SystrayServices | Msxpw.exe | Added by the CITOR WORM! |
| X | Systray driver | systray.exe | Added by the MUTEBOT TROJAN! Note - this is not the real SystemTray which shares the same filename |
| U | SysTray | SysTray.Exe | SYSTRAY.EXE - System Tray Services. Provides the Volume Control, PC Card Status, Power Management and other icons that reside in the System Tray (see here). SYSTRAY.EXE may be disabled if none of these services are required. It will launch as and when required if you later enable the icons. If you need these items they're available via Start -> Settings -> Control Panel |
| X | SYSTRAY | UNMT.EXE | Added by the SDBOT WORM! |
| X | Systray | [filename.exe] | Winfavorites adware |
| X | Systray | Systray_.Exe | Added by the KERGEZ.A WORM! |
| ? | systrax | systrax.exe | ?? |
| ? | systr32 | systr32.exe | ?? |
| X | Systoan32 | systoan.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Systmesy | Systmesy.exe | Added by the RBOT-KQ WORM! |
| X | SysTime | systime.exe | CoolWebSearch parasite variant |
| N | Systest | Systest.exe | Clean Space temp files cleaner |
| X | systhread | winkernal.exe | Added by the LIAMED WORM! |
| X | Systesms.exe | systesms.exe | Added by the RBOT-HI WORM! |
| U | System_Messages | pprsen.exe | TerminatorX - "offers an easy and effective method of stopping users running predetermined file sharing programs like KaZaA, messenger programs, chat rooms and the like" |
| X | SYSTEMZ Patch | SYSZ.exe | Added by the ALADINZ.P TROJAN! |
| U | SystemWizard Sniffer | Sniffer.exe | SystemWizard for Win98/ME from SystemSoft - diagnoses and solves hardware and software problems on a PC |
| X | SystemWideHook for Windows NT | %WinHook32.exe | Added by the MYDOOM.AC WORM! |
| N | SystemUpd | SystemUpd.exe | Updater for Swapoo.com, a kind of Napster for games |
| X | SystemTray | SysTray.exe | Added by the ALADINZ.P TROJAN! Note - this is not the valid System Tray (systray.exe) which resides in C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP). If you right-click on the real systray.exe the "Properties" reveal it to be a Microsoft file |
| X | SystemTray | SystemTray.exe | Added by the BIGFOOT TROJAN! Note - this is not the valid SystemTray (SysTray.exe) |
| U | SystemTray | SysTray.Exe | SYSTRAY.EXE - System Tray Services. Provides the Volume Control, PC Card Status, Power Management and other icons that reside in the System Tray (see here). SYSTRAY.EXE may be disabled if none of these services are required. It will launch as and when required if you later enable the icons. If you need these items they're available via Start -> Settings -> Control Panel |
| X | SystemTra | CDPlay.EXE | Added by a variant of the LOVGATE WORM! |
| X | SystemTasks | filez.exe | Adult content dialler |
| X | SystemTasks | sexypicz.exe | Adult content dialler |
| X | SystemTasks | loaded.exe | Adult content dialler |
| X | Systemtra | Systra.exe | Added by a variant of the LOVGATE WORM! |
| X | SystemService | shman.exe | Premium rate adult content dialler |
| X | SystemSettingf | TRUG.vbs | Added by the TRUG.B MACRO! |
| U | SystemSuite Task Manager | MXTASK.EXE | vcom (nee Ontrack) SystemSuite - PC maintenance and security. Use the program's configuration options to enable only the parts you want running all the time - such as Virusscanner Pro |
| X | SystemService | qservice.exe | Premium rate adult content dialler |
| X | SystemService | navchk.exe | Premium rate adult content dialler |
| X | SystemService | msocfg.exe | Premium rate adult content dialler |
| X | SystemSearch | regedit.exe -s c:ie.reg | Installs a Seachxl.com browser page hijack |
| X | SystemSAS | System32.exe | Added by the KWBOT.C WORM! |
| X | SYSTEMSars32 | csrss.exe | Added by the AHLEM.A WORM! Note - this is not the legitimate csrss.exe process which should NOT appear in Msconfig/Startup! |
| U | SystemSafe | Syssafe.exe | System Safety Monitor - system monitoring tool with additional application firewalling |
| U | Systems.exe | Systems.exe | Keyboard Spectator - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
| X | Systems Restart | spchost.exe | Added by a variant of the BANCOS.RF TROJAN!
|
| X | Systems Restart | slchost.exe | Added by the BANCOS.RF TROJAN!
|
| X | Systems | scchost.exe | Added by the DAEMOZ.A TROJAN! |
| X | SystemReg | WINREG.EXE | Added by the DEWIN.A TROJAN! |
| X | SystemReg | svchost.exe | Added by the DEWIN.E TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| ? | SystemReg | PROCES.EXE | ?? |
| X | SystemNetwork | NETSERV.EXE | Added by the NETCONTROL VIRUS! |
| X | SystemMD | md.exe | Homepage hijacker |
| X | SystemMonitor | Sysmon32.exe | Added by the AIDID.A WORM! |
| X | SystemMap32 | Netisp32.vbs | Added by the REDIST.C WORM! |
| X | SystemManager | Sysman32.exe | Added by the DOWNLOADER-BW.B TROJAN! |
| X | SystemLoad32 | sysload32.exe | Added by the MIMAIL.E WORM! |
| X | Systemiom Updater | Systemiom.exe | Added by the SPYBOT.TY WORM! |
| X | SystemInit | iservc.exe | Added by the FIZZER WORM! |
| X | SystemExplorer | explore.exe | Homepage hijacker - file located in the "Services" folder in Common Files |
| X | SystemFTP | VSENMB.exe | Malware (ie, malicious software). Also changes the system.ini Shell line to read Shell=Explorer.exe VSENMB.exe, and it hacks the Winstart.bat as well |
| X | SystemEmergency | [various filenames] | SmartSearch - a CoolWebSearch parasite variant |
| X | SystemDll | SystemDll.exe | Added by the LOXOSCAM TROJAN! |
| X | systemdrv | ms32sys.exe | Added by an unidentified WORM or TROJAN - most likely GAOBOT variant |
| X | SystemDebug | Sysdeb32.exe | Added by the SYSBUG TROJAN! |
| X | SystemCONF98i | SystemCONF98i.exe | Added by the GLITCH BOT TROJAN! |
| X | SystemChecker | Syschk.exe | Added by the GALIL.F WORM! |
| X | SystemCheck | Systemcheck.exe | Added by the LAVITS WORM! |
| ? | SystemBoot | ladies.htm | Unknown but sounds very suspicious?? |
| X | SystemBoot | Mshta.exe ...filename.hta | Adult content dialler |
| X | SystemBackup | MicroLog.exe | Added by the MICROLOG.A TROJAN! |
| X | SystemBackup | mtx.exe | Added by the MTX VIRUS/WORM! |
| U | SystemAgent | Sage.exe | "Microsoft Plus! System Agent automatically tunes your system, performing tasks such as disk optimization and error correction. It can also run any application at prescheduled times" |
| X | SystemAdministration | Wincmp32.exe | Added by the ASYLUM TROJAN! |
| X | System33 | FB_PNU.EXE | Added by the NICHELLO-A WORM! |
| X | System32Ex | System32Ex.exe | Added by the IRCCONTACT TROJAN! |
| X | System32Dll | DLL32SYS.EXE | Added by the SPYBOT-CZ WORM! |
| X | system32.dll | sysdll32.exe | CoolWebSearch parasite related. Redirecting to wholeworldmarket.com, most likely other domains as well |
| X | system32.dll | systeminit.exe | CoolWebSearch hijacker re-directing to your-search.info |
| X | System32 | system32,1.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | system32 | NeT-BoT.exe | Added by the AGOBOT-LJ WORM!
|
| X | System32 | sysdiag.exe | SpyAgent.B spyware |
| X | System32 | system.exe | Added by the BUSHTRO122 TROJAN! |
| X | System32 | System32.exe | Added by any number of WORMS or TROJANS! |
| X | System.exe | System.exe | Added by various WORMS and TROJANS! |
| X | system... | system...exe | Added by the OPTIXPRO.13.C TROJAN! |
| X | system. | system..exe | Added by the OPTIXPRO.13.C TROJAN! |
| X | System-Service | EXPLORER.SCR | Added by the BENJAMIN WORM! KaZaA file-sharing users beware! |
| X | System-Config | msptmf32.com | Added by the LIOTEN.FA WORM! |
| X | system xp | acdsee demo.exe | Added by the SALGA.A WORM! |
| X | System Uptime Server | SYSENTRY32.EXE | Added by the RBOT.LK WORM! |
| X | System Uptime Server | SYSENTRY.EXE | Added by the RBOT.LK WORM! |
| X | System Updater Service | wmiprvsw.exe | Added by the GAOBOT.AFC WORM! |
| X | System Update2 | wupdmgr.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | winspool.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | winlogon.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | wininet.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | webcheck.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | taskmon.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | update.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | taskman.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | system.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | svchost.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | services.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update2 | explorer.exe | Added by the AUTOTROJ-C TROJAN! |
| X | System Update | wupdmgr.exe | Added by the SOROMO-A TROJAN! |
| X | System Update | [random filename] | Added by the KORGO.W or KORGO.X WORMS! |
| X | System Update | [filename].exe | CoolWebSearch parasite variant |
| X | System Tray32 | SysTray32.exe | Added by the REPAD WORM! |
| X | System Toolkit | Systools.exe | Added by the RONOPER-G WORM! |
| X | System Tray | msccn32.exe | Added by the PALYH.A WORM! Warning - spreading via infected E-mail attachments with the sender address faked as support@microsoft.com. Note - this is not the valid SystemTray (SysTray.exe) |
| X | System time updator | CSysTime.exe | Added by the RANDEX.S WORM! |
| X | System Terminal | SYSTEM2.EXE | Added by the SPYBOT-BZ TROJAN! |
| X | System Stats | SystemStats.exe | Added by a variant of the WOOTBOT WORM! |
| X | System Startup | Voltio.exe | Added by the RBOT.NJ WORM! |
| U | System startup | charmapx.exe | Only required if using an oriental language |
| X | System Soap Pro | soap.exe | System Soap Pro internet cleaning software. Bundles foistware like HTTPER and Zipclix - best avoided |
| X | system service | spoolcrv.cpl | Added by the INSPIR.11 TROJAN! |
| X | System Service | systems.exe | Added by the AGOBOT.VZ WORM! |
| X | System Service | MSREXE.EXE | Added by the AML TROJAN! |
| X | System Restore Data | [path] repcale.exe [path] beird.exe | Added by the RANDON.AN WORM! |
| X | System Restore | svcnet.exe | Added by the TIBICK WORM! |
| X | System Profile | Regsrv.exe | Added by a variant of the OPTIX TROJAN! |
| X | System MScvb | mscvb32.exe | Added by the SOBIG.C WORM! |
| X | System Monitor | Sysmon16.exe | Added by the SDBOT TROJAN! |
| U | System Monitor | SYSMON.EXE | Comes with some Aopen motherboards. Monitors CPU temp, voltage and fan speed. Warns if any become abnormal |
| U | System Mechanic Popup Stopper | Popupstopper.exe | Iolo "System Mechanic" popup stopper |
| X | system manager | System.exe | Added by the FORBOT-BO WORM!
|
| X | System Manager | svchost.exe | Added by the BANKER-AE TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | System Log Event | csrss32.exe | Added by the AGOBOT-JI WORM! |
| U | System LifeGuard Scheduler | Slsched.exe | System LifeGuard scheduler |
| X | System Initialization | payload.dat | Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS! |
| X | System Information Manager | Navcpe.exe | Added by the SDBOT-QB WORM! |
| X | System Initialization | msmsgri32.exe | Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS! |
| X | System Host Service | svchost.exe | Added the the CONE.F WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | System Handler | LSASS.EXE | Added by the NIMOS WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup! |
| X | System File Drivers | nvsysvc32.exe | Added by the AGOBOT.WJ WORM! |
| X | System Failure Statistic | cnstat.exe | Added by the RBOT-LF WORM! |
| X | System Executable DLL Library | EXECDLL32.exe | Added by the RANDEX.AZ WORM! |
| X | System Efficiency Monitor | mscommand.exe | Added by the KWBOT.P WORM! |
| X | System driver | Messenger.exe | Added by a variant of the SMALL.BJ TROJAN!
|
| X | System Efficiency Monitor | mscedit32.exe | Added by the SDBOT.P TROJAN! |
| X | System Document Application | nmod.exe | Added by the SDBOT-ABB WORM! |
| N | System DLF | cpqdiaga.exe | Compaq Diagnostic record system utility which allow you to view information about your computer's hardware and software configuration. Available via Start -> Programs |
| X | System Diagnostics | sysdiag32.exe | Added by the SDBOT.GEN TROJAN! |
| X | System Configuration | iexplore.exe | Added by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
| X | System Config Manager | crss.exe | Added by the AGOBOT.GH WORM! |
| X | system check | updater.exe | Unidentified adware downloader |
| U | System Check | Rundll32.exe SysDll32.dll, SystemCheck | XPCSpy Pro keylogger, surveillance and monitoring software |
| X | System Backup | msystem.exe | Adult content dialler |
| X | System Cache | SysCache.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | System 64 Driver for Games | sys64dvr.exe | Added by the SDBOT TROJAN! |
| X | System Applications Profile | sap.exe | Added by the RBOT-QF WORM! |
| X | SYSTEM | lsas.exe | Added by the SPYBOT.CJ WORM! |
| X | System | Atira.exe | Added by the KOTIRA VIRUS! |
| X | system | outlook.exe | Added by the MIMAIL.Q WORM! Note that Microsoft's outlook.exe resides in the Program Files sub-directory wheras this resides in C:Windows or C:Winnt |
| X | System | YPager.exe | Added by the JUNTADOR.K TROJAN! Note - this is not Yahoo! Messenger |
| X | system | Explorer.exe | Added by the GRAYBIRD TROJAN! Note - this is located in this is located in C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K), or C:WindowsSystem32 (WinXP) rather than the valid Windows Explorer which is located in C:Windows or C:Winnt |
| X | System | dcomx.exe | Added by the CIREBOT TROJAN! |
| X | system | systemsearch.hta | Jetseeker.com hijacker |
| X | system | regedit -s system.dll | Homepage hijacker |
| X | System | system.exe | Added by various WORMS and TROJANS! |
| X | System | run322.exe | Added by the LANFILT TROJAN! |
| X | SYSsfitb | SYSsfitb.exe | Searchforit browser hijacker |
| X | SysService32l | systask32l.exe | Added by the THEUG WORM! |
| X | SysService32 | ln32k.dll | Added by the KINDAL VIRUS! |
| X | SysService32 | SysService32.exe | Added by the KINDAL VIRUS! |
| X | SysService | SysService.exe | Added by the DELF family of TROJANS! |
| X | SysSearch | Regedit.exe -s [path] pcsearch.reg | Added by the StartPage-FN browser hijacker |
| X | SysScan | bvt.exe | Added by the AUTOUPDER TROJAN! |
| X | Sysres | Sysres.exe | Added by the LOGMOD TROJAN! |
| X | SysReg | SysReg.exe | Added by the CHEKIN TROJAN! |
| X | SysReg | SysReg.exe | SearchSeekFind textual marketing foistware |
| X | SysR | sysmd.exe | Adult content based "foistware" (adds hidden components to your system) |
| X | SysProtect | System.exe | Added by the NETSPY TROJAN! |
| Y | SysPool | Mssvc.exe | StealthDisk - hides folders, files and applications. Will also encrypt them for better protection |
| X | SysPnP | rundll32 setupapi, InstallHinfSection.... oemsyspnp.inf | Search hijacker - see here |
| X | sysPnP | bootconf.exe | Homepage hijacker, redirecting to coolwwwsearch.com; see for example here |
| U | SysPilot | fdxxl.exe | G Data "PC Spion" - monitoring and surveillance software, captures all users activity on the PC, see here. Disable/remove if you didn't install it yourself!
|
| X | syspath | drv.exe | Added by the SOBER WORM! |
| X | SysOps | SysOps | Added by the MSNCORRUPT TROJAN! |
| X | SysMonXP | SysMonXP.exe | Added by the NETSKY.Q WORM! |
| X | sysnate | sysnate.exe | Added by the MEDIAS TROJAN! |
| X | sysmon | sysmon44.exe | Added by a variant of the BACKDOOR-CBA TROJAN! |
| X | Sysmon | rpcmon.exe | Added by the RANDEX.ATX WORM! |
| X | sysmon | sysmon.exe | Added by the BIZEX WORM! |
| U | SysMetrix | SysMetrix.exe | SysMetrix - skinnable clock and metering application. It monitors and reports on a great number of statistics |
| X | syslogin.exe | syslogin.exe | Added by the BAGZ-B WORM! |
| X | Syslog ml097e | Syslog.exe | Variant of the RapidBlaster parasite (in a "Syslog" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | Syslib | Syslib.exe | Adult content related downloader trojan |
| X | Syslog lptt01 | Syslog.exe | Variant of the RapidBlaster parasite (in a "Syslog" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | Syskey | sysinit.exe | Added by the BEAGLE.AX WORM! |
| X | sysint16 | sysint16.exe | Added by the CRYPTER.A TROJAN! |
| X | Sysino | lsess.exe | Added by the FORBOT-BF WORM! |
| X | sysinit | services.exe | Added by the NEWLFRM-A TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | SysInit | wininit32.exe | Added by the XABOT WORM! |
| X | sysinfo.exe | sysinfo.exe | Added by the BEAGLE.V WORM! |
| X | sysinfo | sysinfo.exe | Added by the BEDRILL TROJAN! |
| X | syshelp | syshelp.exe | Added by a variant of the LOVGATE WORM! |
| X | sysfiler | sysfiler.exe | Added by the RETSAM TROJAN! |
| X | sysflg32 | sysflg32.exe | Added by a variant of the CRYPTER.C TROJAN! |
| X | Sysdpt | sysdpt.exe | Win32.Crypt trojan downloader |
| X | sysdir | winrun.exe | Added by the WINBUR.B WORM! |
| X | Sysctrls | procdll.exe | Added by the WEEDBOTZ.14 TROJAN! |
| X | SysCtl | sysctl.exe | Added by the AOK TROJAN! |
| X | Syscpy | Syscpy.exe | Firewall-bypassing, proxied spam relayer. Detected by Symantec as the HOGLE TROJAN! |
| X | SysConfig | syscfg35.exe | Added by the KAZMOR.C WORM! |
| X | sysconfig | iexplorer.exe | Added by the CULT.H WORM! |
| X | sysconfig | iexplorer.exe | Added by the CULT.C WORM! |
| X | syscon ml097e | syscon.exe | Variant of the RapidBlaster parasite (in a "Syscon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | syscon lptt01 | syscon.exe | Variant of the RapidBlaster parasite (in a "Syscon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | Syscheck | win.hta | Browser hijacker |
| X | syscheck | iexplorer.exe | Added by the AGENT.DM TROJAN! |
| X | syscm | Syscm.exe | Vanish adware |
| ? | SysComp | mssdnl.com | Unknown but suspect as *.com are not usually run at start up and the name isn't recognized |
| X | syscfg34.exe | syscfg34.exe | Added by the ELECTRON WORM! |
| X | syscfg | syscfg32.exe | Added by the KWBOT.S WORM! |
| U | Sysbot | sysbot.exe | Spector - spying (or monitoring) software to record internet activity |
| X | SysAI | SysAI.exe | AproposMedia adware - also creates SysAI folder in Program Files where the SysAI.exe is also located |
| U | SysAgent | SysAgent.exe | SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of |
| X | SysA | win***32.exe [* = random char] | EliteBar adware |
| U | sys32cmd | sys32win.exe | Active Keylogger monitoring software - also see here. From the Symantec article: "This spyware program must be manually installed. However, there are several known programs that have Spyware.ActiveKeylog within them and that install it as the program itself is installed". Disable/remove if you didn't install it |
| X | sys32 | sys32.exe | Added by the FLUX.E TROJAN!
|
| X | Sys Ren | SysRen.exe | Unidentified malware |
| X | Sys29 | win***32.exe [* = random char] | EliteBar adware |
| X | sys | sysdllwm.reg | CoolWebSearch parasite variant |
| X | sys | regedit /s sys.reg | Hijacker |
| Y | SynTPLpr | syntplpr.exe | Synaptics touchpad driver helper. Required for touchpad features to work |
| ? | SynSetup | SynTP.tmp RunOnce.exe | Probably associated Synaptics touchpads on laptops as for the SynTPEnh and SynTPLpr entries but what does it do and is it required? |
| U | SynTPEnh | syntpenh.exe | Synaptics touchpad tray icon. Displays status and provides quick launch to touchpad features such as scrolling and tap zones. Required on IBM Thinkpads with UnltraNav (pointstick and touchpad combo) if you don't want to loose the advanced pointstick features such as scroll |
| N | Synchronization Manager | mobsync.exe | Find more information about its use here |
| U | Sync-It | Syncit.exe | Sync-It - synchronizes the system clock with time servers on the internet |
| U | SyncAgent | syncagent.exe | Ghost Keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove |
| U | Sync Data | Hndsync.exe | Pocket Real Estate - mobile synchronization manager |
| X | Sync Server | drwatsoon.exe | Added by the WATSOON.A TROJAN! |
| N | SymTray - Norton SystemWorks | SYMTRAY.EXE | Keeps all System Tray icons for Norton SystemWorks together to reduce clutter. SystemWorks includes Norton Anti-Virus, Norton Utilities and Norton CleanSweep - mentioned elsewhere here. Personally I only have Norton eMail Protect running which doesn't need SymTray |
| U | SymKeepAlive | CKA.exe | Part of Norton SystemWorks 2003 - keeps a dial-up modem connection alive |
| X | SymAV | SymAV.exe | Added by the NETSKY.U WORM! |
| X | Symantec Security Addon | nvsvc.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Symantec Security | symantec32.exe | Added by the RANDEX.PR or RANDEX.YR WORMS! |
| U | Symantec NetDriver Monitor | SNDMon.exe | Part of Symantec's LiveUpate (eg, Norton). Not required if you run manual upadtes but probably require if you leave them to run automatically. Also, if one runs a small office network and SNDMon is disabled on one of the computers ? then other computers disappear from the network for this computer, including shared devices like printers and scanners. Hence the "U" recommendation |
| Y | Symantec Core LC | symlcsvc.exe | Part of Norton AntiVirus 2004. What does it do? |
| N | Symantec Fax Starter Edition Port | OLFSNT40.EXE | Offers a virtual printer as a fax machine. Can be run via a desktop shortcut |
| X | Symantec Configuration Loader | ccApp32.exe | Added by a variant of the GAOBOT WORM! |
| U | SyGateService | sgserv95.exe | SyGate is a useful little program that lets you share an internet connection over an intranet. Is it needed - it saves a lot of headache to just let SyGate load at startup. Available via Start -> Programs |
| X | Sygate Personal Firewall Start | services32.exe | Added by the RBOT-MB WORM! |
| X | Sygate Personal Firewall | Mcafeeupdate.exe | Added by the RBOT.YN WORM! |
| X | Sygate Personal Firewall | Sygate.exe | Added by the RBOT-PN WORM!
|
| X | Sygate Personal Firewall | sysgut.exe | Added by the SDBOT.WM WORM!
|
| X | Sygate Personal Firewall | system32.exe | Added by a variant of the RBOT WORM!
|
| X | Sygate Personal Firewall | Win32x.exe | Added by the RBOT-KZ WORM! |
| X | SYDNEY | [file path] | Added by the SYNEY WORM! |
| ? | Sxplog | sxpstub.exe | Part of CA Unicenter Software Delivery - manage software across various systems, from desktops and servers to PDAs and mobile phones, in a controlled and standardized way - is it required at startup? |
| ? | SxgTkBar | sxgtkbar.exe | Yamaha SXG soundcard driver |
| ? | SXGDSENU | sxgdsenu.exe | Yamaha SXG soundcard driver |
| N | SWTrayV4 | SWTrayV4.exe | MS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs |
| N | SwTray | SWTRAY.EXE | MS SideWinder game controller system tray icon. Available via Start -> Programs. May have the version number after it |
| X | sws.exe | [random filename] | Haldex type adult content dialler |
| N | Switchboard.com Toolbar | AtHoc.exe | Toolbar for the on-line version of Yellow Pages in the US - Switchboard.com |
| X | SwimSuitNetwork | SwimSuitNetwork.exe | Advertising spyware |
| U | Switch Off | swoff.exe | Switch Off - tray-based system utility that can automatically perform various frequently used operations like shutdown or restart your computer, disconnect your current dialup connection, lock workstation, etc |
| X | Swf32 | _backup.exe | Added by the SYMTEN WORM! |
| X | Swf32 | AVupdate.exe | Added by the MERKUR WORM! |
| Y | Sweep95 | ICLOAD95.EXE | Part of Sophos ant-virus sofware |
| N | SWd | winwd.exe | PC Security from Tropical Software - lock files, password protect, etc |
| X | SWCaller | SWcaller.exe | Homepage hijacker - see here |
| X | SWCaller | Swcaller2.exe | Homepage hijacker - see here |
| N | Swap Nut | javaw.exe | SwapNut is a peer-to-peer file sharing and searching utility developed and marketed by File Metrics, Inc. Users can search for and find almost any type of digital file (audio, video, photos etc.) through a secure peer-to-peer network |
| X | SVX Control Service | svxhost.exe | Added by the FORBOT-K WORM! |
| X | svwin32 | unninst32.exe | Added by the AGOBOT-NF WORM!
|
| X | svshostdriver | svshost.exe | Added by the SDBOT-HN TROJAN!
|
| X | svshost32 | msgrsv32.exe | Added by the RANKY.AJ TROJAN! |
| X | svrrun | svrrun.exe | Adware hailing from Deskwizz.com
|
| X | svshost | svshost.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| ? | SVM Pop | svmpop.exe | ?? |
| ? | SVIDC32M | SVIDC32M.exe | ?? |
| X | Svhost Loader | svshost.exe | Added by the AGOBOT.G WORM!
|
| X | SVHOST | svhost.exe | Added by the MYDOOM.I WORM! |
| X | svcwinprocess32 | [path to worm] | Added by the UPERING WORM! |
| X | svchostr | svchostr.exe | Added by an unidentified WORM or TROJAN!
|
| X | svcinfo | svcinfo.exe | Added by the CRYPTER.A TROJAN! |
| X | SvcHost32 | svchost32.exe | Added by the MIMAIL.I or MIMAIL.J WORMS! |
| X | svchost64 | svchost64.exe | Added by the SDBOTER.G VIRUS! |
| X | svchost.exe | svchost32.exe | CoolWebSearch parasite related. Note - this is not the valid svchost.exe as described here |
| X | svchost1 | svchost1.exe | Added by the AGOBOT.ZZ WORM! |
| X | Svchost | svchosl.pif | Added by the INZAE.A or INZAE.B WORMS! |
| X | svchost | [path] SETUP.EXE | Added by the SETCLO WORM! |
| X | SVCHOST | var.txt.exe | Added by the LDPINCH.C TROJAN! |
| X | Svchost | svchost.exe | Added by the MOXE-A WORM! This is not the valid svchost.exe as described here |
| X | Svchost | winhost.exe | Added by the LOLAWEB.A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | svchost | ADMAGIC.EXE | Added by the SMIBAG WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | svchost | [path to trojan] | Added by the HAZZER TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | svchost | Svch0st.exe | Added by the GRAYBIRD TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | SVCHOST | mrowyekdc.exe | Added by the GOTORM WORM! |
| X | svchost | svchost.exe | Added by the MORB WORM or TARNO TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | SVCHOST | svchost.exe | System1060 homepage hi-jacker. Found in a WindowsSystem1060 directory. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | svchost | Svch0st.exe | Added by the GRAYBIRD.B TROJAN!
|
| X | SvcH0st | msexploren.exe | Added by the BACKDOOR-CGZ TROJAN! |
| X | Svced | Svced.exe | Added by the DELF.F TROJAN! |
| X | SVC Socks | mstaskm.exe | CoolWebSearch parasite variant |
| X | SVC Service | svcpack.exe | CoolWebSearch parasite variant |
| X | SVC Service | svcinit.exe | Added by the SINIT TROJAN! |
| X | SVC Service | svcinit.exe | CoolWebSearch parasite variant |
| X | SVA Player | SVAplayer.exe | QuickFlicks Streaming Player - regarded as spyware. See here for details of how to disable or uninstall it |
| X | Svc | svc.exe | Hijacker, Clientman parasite variant, redirecting to madfinder.com. Detected by Symantec as the MADFIND TROJAN! |
| X | SustemUpdate | explorer.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | Sustem | explorer.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | Susp | Susp.exe | Transponder based malware by abetterinternet.com |
| ? | Surveysa | surveysa.exe | Found in the SonyVaiosurvey directory on a Sony Vaio PC. What does it do and is it required? |
| X | Surs | awab.exe | PurityScan/Clickspring adware
|
| U | SurfStream | SurfStream.exe | Conceiva "SurfStream lets you surf the Web faster. It contains a fully featured proxy server that lets you surf the Web significantly faster. It also blocks all pop-up windows and banner ads from Web pages. An intelligent tune-up tool automatically analyzes and optimizes your computer's Internet connection and TCP/IP settings" |
| X | SurfSideKick 2 | Ssk.exe | SurfSideKick adware |
| U | SurfSecret | ss2-full.exe | "House-cleaning utility that enables you to keep your computer usage to yourself. Runs quietly from the system tray, eliminating tell-tale files at a regular interval of your choosing. You can set it to clear your Internet cache files, cookies, history, temp folder, etc. It can also clear the history of your Run and Find menus, in addition to the AOL cache" |
| U | SurfinGuard Pro | winsfcm.exe | SurfinGuard Pro - internet protection software |
| X | Surfer ml097e | surfer.exe | Variant of the RapidBlaster parasite (in a "mssurfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | Surfer lptt01 | surfer.exe | Variant of the RapidBlaster parasite (in a "mssurfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| U | SurfChoice | SCMan.exe | SCMan is a utility that can control services on WinNT from the command line. This utility can create, start, pause, stop, delete services. Furthermore it can retrieve a service's current state, get the displayname for a service and vice versa |
| U | Sureshotpopupkiller | Stopthepop.exe | Stop-the-Pop-Up popup blocker |
| U | SureCleanProfessional | SRClean.exe | SureClean PC and Internet tracks cleaner
|
| X | supporter5 | supporter5.exe | Part of eScorcher anti-virus software- responsible for updates of new virus bases each time you logon to the web. Used to collect information about the user and therefore treated as spyware - now the web-site is dead |
| X | Supervisor.exe | Supervisor.exe | Has been reported to be associated with various antitrojan software like ATS and PC Doorguard. If so it's required in Startup - any further information is welcome |
| U | SuperSpamKiller Pro | Ssk.exe | SuperSpamKiller Pro email spam blocker
|
| X | superslut | msslut32.exe | Added by the SLUTER-A WORM! |
| X | Supernova | [worm filename] | Added by the SURNOVA (or SUPOVA) WORM! |
| U | SuperCool Compress Backup | Main.exe | "SuperCool Zip Backup software is a data backup,restore and file synchronization program" |
| U | SuperAdBlocker | SAdBlock.exe | SuperAdBlocker |
| U | Supercleaner | Supercleaner.exe | Supercleaner - all in one disk cleaner for your computer |
| U | Super Popup Blocker | popkill.exe | Saga Super Popup Blocker - pop-up stopper |
| N | Supastatus | status.exe | Supanet ISP software |
| ? | SupaDial | SupaDial.exe | SupaNet.com modem driver related - is it required? |
| U | Sunkist2k | shwicon2k.exe | Card reader for memory cards from digital cameras, etc |
| U | Sunkist | shwicon98.exe | Card reader for memory cards from digital cameras, etc |
| N | SunJavaUpdateSched | jusched.exe | Checks with Sun's Java updates site to see if newer Java versions are available. Visit http://java.sun.com or just run the Java Plug-In Control Panel |
| X | SULFNBJ.EXE | SULFNBJ.EXE | Added by the PE_MAGISTR.DAM VIRUS! |
| U | Suitcase Startup | Suitcase.exe | Suitcase. System font manager start up utility. Used for dynamic managment of fonts on your system |
| N | Subtract the Ads | AdSub.exe | Removes adverts from web pages. Although useful - not required |
| X | StubPath | Sservice.exe | Added by the PRORAT TROJAN! |
| U | StyleXP | StyleXP.exe | StyleXP allows you customiz |