| X |
svchost |
svchost.exe | "Added by the DLOADER-EV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%" |
| X |
svchost |
winhelp.exe | "Added by the GAOBOT.GEN!POLY WORM!" |
| X |
SVCHOST |
MDM.EXE | "Added by the LCJUMP-A WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is always located in %ProgramFiles%\Microsoft Shared. This one is located in %Windir%" |
| X |
Svchost |
svchots.exe | "Added by the RBOT.ADK WORM!" |
| X |
svchost |
ying.exe | "Constructor VC2000 malware" |
| X |
svchost |
inetinfo.scr | "Added by the ODELUD WORM!" |
| X |
SVCHOST |
svchost64.exe | "Added by the STARTP-G TROJAN!" |
| X |
SVCHOST |
SPOOLSV.EXE | "Added by the BAITAP-A WORM! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%" |
| X |
svchost connection monitor |
svchost32.exe | "Added by a variant of the SDBOT WORM!" |
| X |
SVCHOST Generic application |
svchost.exe | "Added by the DAEMONI-K TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder" |
| X |
svchost Netware Manager |
svchost.exe | "Added by the EXVID.A WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder" |
| X |
SVCHost Protocol32 |
scvhost32.exe | "Added by a variant of the IRCBOT TROJAN!" |
| X |
Svchost Service |
svchost.exe | "Added by the VB-DVQ WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Help subfolder of the Winnt or Windows folder" |
| X |
Svchost Windows Remote Services |
svhost.exe | "Added by the IRCBOT-IV WORM!" |
| X |
svchost.exe |
svchost32.exe | "CoolWebSearch Svchost32 parasite variant" |
| X |
SVCHOST.EXE |
SVCHOST.EXE | "Added by the WRMSCAN-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder" |
| X |
svchost.exe |
[path to executeable] | "Added by the BANKER-MO TROJAN!" |
| X |
svchost.exe |
svchost.exe | "Added by the ZAPCHAS-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a ""drivers"" subfolder" |
| X |
svchost.exe |
swchost.exe | "Added by the SADELPHI-A TROJAN!" |
| X |
svchost1 |
svchost1.exe | "Added by the AGOBOT.ZZ WORM!" |
| X |
SvcHost32 |
svchost32.exe | "Added by the MIMAIL.I or MIMAIL.J WORMS!" |
| X |
svchost32.exe |
svchost32.exe | "Added by the ASSASIN.20B BACKDOOR!" |
| X |
svchost64 |
svchost64.exe | Added by the SDBOTER.G VIRUS! |
| X |
svchosta |
svchosta.exe | "Added by the SNIFFER-I TROJAN!" |
| X |
svchostb |
svchostb.exe | "Added by the SNIFFER-J TROJAN!" |
| X |
SvcHostDHCP |
svchost32.exe | "Added by the ASSASIN.20B BACKDOOR!" |
| X |
svchostdll.scr |
svchostdll.scr | "Added by the BANCBAN-FM TROJAN!" |
| X |
SvcHosto |
v1rg1n.exe | "Added by the AGOBOT-TK WORM!" |
| X |
svchostr |
svchostr.exe | Added by an unidentified WORM or TROJAN! |
| X |
svchosts |
svchosts.exe | "Added by the BANCBAN-DC or BANKER-ED TROJANS!" |
| X |
svchosts.exe |
svchosts.exe | "Added by the AGOBOT-JN WORM!" |
| X |
svchosts.scr |
svchosts.scr | "Added by the BANCBAN-DQ TROJAN and variants!" |
| X |
SVCHOT |
SVCHOT.exe | "Added by the QQROB-U TROJAN!" |
| X |
svchst |
svchst.exe | "Added by the KBROY-C TROJAN!" |
| X |
svcinfo |
svcinfo.exe | "Added by the CRYPTER.A TROJAN!" |
| X |
Svclhost |
svcchost.exe | Added by an unidentified WORM or TROJAN! |
| X |
SvcManager |
restore3.exe | "Added by the AGENT-DSS TROJAN!" |
| X |
SvcManager |
spoolvs3.exe | Added by an unidentified WORM or TROJAN! |
| U |
svcmon |
svcmon.exe | "PersonInspect surveillance software. Uninstall this software unless you put it there yourself" |
| X |
Svconr |
Svconr.exe | "WaveRevenue-lBann adware" |
| X |
svcroot |
svcroot.exe | "Added by the KEYLOG-AC TROJAN!" |
| X |
svcshare |
winampXP.exe | "Added by the FUJACKS-J VIRUS!" |
| X |
svcshare |
spoclsv.exe | "Added by the FUJACKS-A VIRUS!" |
| X |
svcshare |
CTMONTv.exe | "Added by the FUJACKS-AJ WORM!" |
| X |
svcshare |
nvscv32.exe | "Added by the FUJACKS-Z WORM!" |
| X |
SvcSys |
[path to file] | "Added by the BANCOS.Z TROJAN!" |
| X |
Svcsys Registry Manager |
svcsysreg.exe | "Detected by Kaspersky as the AGENT.CV TROJAN!" |
| X |
svcsys32 |
svcsys32.exe | "Added by the AGOBOT-LL WORM!" |
| X |
svctask |
svctask.exe | "Added by the CHUCKYB-A TROJAN!" |
| X |
svcwinprocess32 |
[path to worm] | "Added by the UPERING WORM!" |
| X |
SVGA Adapter |
svghost.exe | "Added by a variant of the SPYBOT WORM! See here" |
| X |
svhcost |
svhcost.exe | "OpenSearch adware" |
| X |
svhoost |
checksys.exe | Added by a downloader TROJAN of Chinese origin! |
| X |
SVHOST |
svhost.exe | "Added by the MYDOOM.I WORM!" |
| X |
SVHOST |
SVHOST.EXE | "Added by the ZORI.A VIRUS!" |
| X |
Svhost Loader |
svshost.exe | "Added by the AGOBOT.G WORM!" |
| X |
Svhost Service Server |
svhostser.exe | "Added by a variant of the RBOT WORM! See here" |
| X |
svhost updates |
Svhost.exe | "Added by a variant of the RBOT WORM!" |
| X |
svhost windows services |
svhost8.exe | "Added by the RBOT-WQ WORM!" |
| ? |
SVIDC32M |
SVIDC32M.exe | "??" |
| X |
sVideo2 |
[path to dialler] | """Switch-D"" premium rate adult content dialler" |
| X |
sviload32 |
sviload32.exe | "Added by the RBOT-AAS WORM!" |
| ? |
SVM Pop |
svmpop.exe | "??" |
| X |
svnlitup32 |
svnlitup32.exe | "Added by the RBOT.CBJ WORM!" |
| X |
svnloader |
svnload32.exe | "Added by the RBOT-ACU WORM!" |
| X |
svphost.exe |
svphost.exe | "Added by the AGENT.CS TROJAN!" |
| U |
SVPWUTIL |
SVPWUTIL.exe SVPwUTIL | Part of Toshiba Hardware Setup |
| X |
svrrun |
svrrun.exe | Adware hailing from Deskwizz.com |
| X |
svsekin |
svsekt.exe | "Added by the QQPASS.G TROJAN!" |
| X |
svshost |
svshost.exe | "Added by the CHODE-H WORM!" |
| X |
svshost |
messenger.exe | "Added by the LOONY-G TROJAN!" |
| X |
Svshost Update Service |
svcbind.exe | "Added by the MYTOB.LH WORM!" |
| X |
svshost32 |
msgrsv32.exe | Added by the RANKY.AJ TROJAN! |
| X |
svshost32 |
svshost32.exe | "Added by a variant of the SDBOT WORM!" |
| X |
svshostdriver |
svshost.exe | "Added by the SDBOT-HN TROJAN!" |
| X |
svtcin |
n20050308.a.Stub.EXE | "Added by the N20050308 TROJAN!" |
| X |
svwin32 |
unninst32.exe | "Added by the AGOBOT-NF WORM!" |
| X |
SVX Control Service |
svxhost.exe | "Added by the FORBOT-K WORM!" |
| U |
SW20 |
sw20.exe | "Related to MSI's Dynamic Overclocking Technology" |
| U |
SW24 |
sw24.exe | "Related to MSI's Dynamic Overclocking Technology" |
| N |
Swap Nut |
javaw.exe | javaw.exe can be loaded by other programs at startup but in this instance it's SwapNut a peer-to-peer file sharing and searching utility developed and marketed by File Metrics Inc. Users can search for and find almost any type of digital file (audio video photos etc.) through a secure peer-to-peer network |
| X |
SWCaller |
SWcaller.exe | "Swporta homepage hijacker" |
| X |
SWCaller |
Swcaller2.exe | "Swporta homepage hijacker" |
| X |
Swchost |
Swhost.exe | "Added by the BDOOR-MP BACKDOOR!" |
| U |
SWClient |
swsys.exe | "ActivMonAgent keyboard logger/monitoring program - remove unless you installed it yourself" |
| X |
swcroot |
swcroot.exe | "Added by the SOLENO-A TROJAN!" |
| N |
SWd |
winwd.exe | "PC Security from Tropical Software - lock files password protect etc" |
| Y |
Sweep95 |
ICLOAD95.EXE | "Part of Sophos ant-virus sofware" |
| N |
SweetIM |
SweetIM.exe | "vSweetIM - send fancier smiley-faces and IM graphics to friends who are using MSN Messenger. They are only able to see these advanced smiley-faces if they also have SweetIM installed" |
| X |
Swf32 |
AVupdate.exe | "Added by the MERKUR.E WORM!" |
| X |
Swf32 |
_backup.exe | "Added by the SYMTEN WORM!" |
| U |
swg |
GoogleToolbarNotifier.exe | "Companion to the Google Toolbar that lets you keep Google as your default search engine and prevents this setting from being changed without your consent. Shouldn't remain in memory after the feature is disabled as it's a bug - see here" |
| X |
SwimSuitNetwork |
SwimSuitNetwork.exe | Advertising spyware |
| X |
swingsys |
SWINGSYS.EXE | "Added by the BANCOS-CX TROJAN!" |
| U |
Switch Off |
swoff.exe | "Switch Off - tray-based system utility that can automatically perform various frequently used operations like shutdown or restart your computer disconnect your current dialup connection lock workstation etc" |
| N |
Switchboard.com Toolbar |
AtHoc.exe | "Toolbar for the on-line version of Yellow Pages in the US - Switchboard.com" |
| U |
Switcher |
Switcher.exe | """On a Sony laptop with built in wireless it allows the user to select which wireless services they want to run (i.e. Wireless LAN Bluetooth both) when turning the wireless switch on if disabled)""" |
| X |
switp |
switpa.exe | "OfferAgent adware" |
| U |
SWL |
rundll32.exe [path] SWL.dll rdl | "StealthWeblog surveillance software. Uninstall this software unless you put it there yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted" |
| U |
SWN2 |
swnxt.exe | "Spyware removal program by TrekBlue. Previously not recommended but the latest version was delisted here" |
| X |
sws.exe |
[random filename] | "Haldex type adult content dialler" |
| X |
sws.exe |
gd-dial.exe | "Globaldialer adult content premium rate dialer" |
| N |
SwTray |
SWTRAY.EXE | MS SideWinder game controller system tray icon. Available via Start -> Programs. May have the version number after it |
| N |
SWTrayV4 |
SWTrayV4.exe | MS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs |
| U |
SwyxIt! |
SwyxIt!.exe | "PC Based soft phone from Swyx - see here for more details" |
| U |
SX Virtual Link |
Connect.exe | "SX Virtual Link from Silex Technology America Inc. Utility to connect USB devices" |
| ? |
SXGDSENU |
sxgdsenu.exe | "Yamaha SXG soundcard driver" |
| N |
SxgTkBar |
sxgtkbar.exe | Yamaha SXG soundcard utility - gives quick and easy access via the system tray bar to diagnostics and configuration |
| ? |
Sxplog |
sxpstub.exe | "Part of CA Unicenter Software Delivery - manage software across various systems from desktops and servers to PDAs and mobile phones in a controlled and standardized way - is it required at startup?" |
| X |
sxrrv |
sxrrv.pif | "Added by the VAX-A TROJAN!" |
| X |
sy |
s2.exe | "Added by a variant of the RBOT WORM!" |