| Name | Status | Filename | Description |
|---|
| System Update2 | X | explorer.exe | Added by the Autotroj-C TROJAN! |
| SiteAdvisor | U | SiteAdv.exe | Related to SiteAdvisor from McAfee SiteAdvisor warns you before you interact with a dangerous Web site. Note: Located in C:\Program Files\SiteAdvisor\...\ |
| SystemService | X | navchk.exe | Premium rate adult material dialer |
| Slayhacker734 | X | slay7383.exe | Added by the Troj/SikBot-A TROJAN! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. |
| SManager | X | smanager.7.exe | Added by the Troj/DwnLdr-GVG Trojan |
| Syswindow | X | Syswindow.exe | Added by the COW VIRUS! |
| svrrun | X | svrrun.exe | adware hailing from Deskwizz.com |
| screxe | ? | scruser2k.exe | ?? |
| Sygate Personal 3 | X | svrv.exe | Added by the W32/RBOT-XD WORM! |
| Spoolsv | X | Spoolsv.exe | Added by the CIADOOR.121 VIRUS! Note - "Spoolsv.exe" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file |
| System Services | X | svcsenes.exe | Added by a variant of the WIN32.RBOT WORM!
|
| Smartalec | U | pcaccel.exe | Smartalec PC Accelerator - system optimization utility |
| sys************* ( * = random digit) | X | sys*************.exe, ( * = random,digit) | WINBO adware component
|
| SVCHOST | X | SVCH0ST.EXE | Added by the Troj/MMThief-A
TROJAN!
Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number "0" in the executable filename, not a lower/upper case O. |
| Stratas | X | ggfig.exe | Added by the OPANKI.W
WORM!
Read the link, rootkit type stealth involved.
|
| SysDesktop | X | fswanQQ.exe | Added by the Troj/QQSend-A
TROJAN!
Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
|
| SYSTEMSars32 | X | csrss.exe | Added by the AHLEM.A VIRUS! Note - this is not the valid Client Server Runtime Subsystem (csrss.exe) process, which provides text window support, shutdown, and hard-error handling |
| startkey | X | RunWinRaR.exe | Added by a variant of Bifrose-LV as reported by VirusTotal. TROJAN! Note: Located in C:\Windows\ |
| SfKg6wIP | X | (RandomName).exe | Identified as a variant the Trojan-Downloader.Win32.Agent TROJAN! Note: Located in %AppData%\Microsoft\Windows\ Note: Use SDFix under supervision. |
| Sndcompat | X | Sndcompat.exe | Added by the GEMA TROJAN! |
| SunJavaUpdateSched | X | scvhost.exe | Added by the W32/SDBOT-AVX WORM! |
| spolsvr2 | X | spolsvr2.exe | Added by the Win32/Evilsock.10 TROJAN! - NOTE: this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot. Name field may be empty. |
| SpyGuarder | X | spyguarder.exe | Added by the SpyGuarder rogue anti-spyware program. Note: Located in \%userprofile%\ Note: Use SDFix under supervision. |
| Spyware Nuker | U | swn2.exe | A "spyware removal program" by TrekBlue, Previously found to be of dubious repute. SpywareWarrior_List It was delisted. Make sure you have the latest version |
| System service62 | X | pokapoka63.exe | EliteBar adware component |
| snpstd | ? | vsnpstd.exe | Sonix PC Camera Monitor MFC Application - what does it do and is it required? |
| Shell | X | taskmrg.exe | Added by the Troj/Bancban-FT
TROJAN!
Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. |
| SK51 | U | SK51.EXE | SaveKeys keystroke logger/monitoring program - remove unless you installed it yourself! |
| supernews12 | X | newsd32.exe | Adware, also detected as the TROJ/DLOADER-JN TROJAN! |
| SAHBundle | X | shop1003.exe | ShopAtHomeSelect adware |
| SVCH Service | X | svch32.pif | Added by the W32/Rbot-ASZ or W32/Rbot-ASY WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. |
| ServicesLog | X | ccapp32.exe | Added by the W32/Rbot-AMX
WORM!
Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. |
| SystemTray | X | SystemTray.exe | Added by the BIGFOOT TROJAN! Note - this is not the valid SystemTray ( SysTray.exe ) |
| spoolvs | X | spoolvs.exe | Identified by Kaspersky antivirus as a variant of the Trojan.Win32.Qhost.aes malware. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| strmsnnrs | X | msnmcgrs.exe | Added by the TROJ/RBOT-ACT TROJAN! |
| Service Process | X | SVCHOST.EXE | Added by the DARKER VIRUS! Note - not the valid svchost.exe as described here. Located in %Windir% not %Sysdir% |
| System Messaging Queue | X | SMCSS.EXE | Added by a variant of the WIN32.RBOT WORM!
|
| Switchboard.com Toolbar | N | AtHoc.exe | Toolbar for the on-line version of Yellow Pages in the US - Switchboard.com |
| sssasasb32 | X | sssasasb32.exe | Added by the WIN32.TACTSLAY.F TROJAN! |
| SpySpotter System Defender | X | Defender.exe | Added by SpySpotter Spyware remover of dubious repute. Aggressive/deceptive advertising. Note: Located in \%Program Files%\SpySpotter3\ |
| svchost | X | svchost.exe | Added by the MORB or TARNO VIRUSES!. This is not the valid svchost.exe as described here. Located in the Windows directory, and not in Windows\System32 |
| Suite | X | SuiteOffices.exe,/cleandb | Added by the Lazar TROJAN! |
| SysMon | X | wowexece.exe | Added by the Troj/Mulan-A
TROJAN!
|
| System Services | X | connection.exe | Added by an unidentified WORM or TROJAN! |
| Server Backbone | X | server05.exe | Added by the W32/RBOT-ZM WORM! Read the link, keylogger/password stealing trojan(s) involved. |
| SpyClean | X | SpyClean.exe | Added by Netcom3_Cleaner a rogue antispyware program that displays legitimate files and Windows Registry entries as malware on your computer. Note: Located in \%Program Files%\ Note: Use Malwarebytes' http://www.malwarebytes.org/rogueremover.php RogueRemover tool. |
| S | X | svhost.exe | Added by the AGOBOT-LN WORM!
|
| svctask | X | svctask.exe | Added by the Troj/Chuckyb-A
TROJAN!
|
| StatusClient | N | StatusClient.exe | Part of Hewlett Packard network printer drivers |
| Sdk**32.exe (* = random char) | X | Sdk**32.exe (*,= random char) | CoolWebSearch/HomeSearch adware component - for examples, see this log |
| SpywareQuake | X | SpywareQuake.exe | Bogus spyware remover - also known as the SmitFraud alias FAKEALE-C TROJAN! |
| System32Dll | X | DLL32SYS.EXE | Added by a W32/Spybot-CZ worm infection |
| SpyCop ScanCheck | U | MAIN.EXE | SpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan |
| SVGA Adapter | X | svghost.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| sms_msn40 | X | sms_msn40.exe | Added by an unknown WORM or TROJAN infection. |