Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
U Sureshotpopupkiller Stopthepop.exe"Stop-the-Pop-Up popup blocker"
U Sureshotpopupkiller pusak.exe"Stop-the-Pop-Up popup blocker"
X SurfAccuracy sacc.exe"SurfAccuracy adware"
X SurfBuddy rundll32 [path] sbuddy.dll"SurfBuddy adware - not to be confused with the legitimate SurfBuddy application by SurfApps!. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
U SurfChoice SCMan.exeSCMan is a utility that can control services on WinNT from the command line. This utility can create start pause stop delete services. Furthermore it can retrieve a service's current state get the displayname for a service and vice versa
X Surfer lptt01 surfer.exe"RapidBlaster variant (in a ""mssurfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X Surfer ml097e surfer.exe"RapidBlaster variant (in a ""mssurfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
U SurfHelper SurfHelp.exe"Related to SurfHelper - a free tool to remove popup windows clear history control window properties of IE and more"
U SurfinGuard Pro winsfcm.exe"SurfinGuard Pro from Finjan - internet protection software protects against all malicious code delivered through executables scripting files ActiveX and Java"
U SurfSecret ss2-full.exe"House-cleaning utility that enables you to keep your computer usage to yourself. Runs quietly from the system tray eliminating tell-tale files at a regular interval of your choosing. You can set it to clear your Internet cache files cookies history temp folder etc. It can also clear the history of your Run and Find menus in addition to the AOL cache"
X SurfSideKick Ssk.exe"SurfSideKick adware"
X SurfSideKick 2 Ssk.exe"SurfSideKick adware"
X SurfSideKick 3 Ssk.exe"SurfSideKick adware"
U SurfStream SurfStream.exe"Conceiva ""SurfStream lets you surf the Web faster. It contains a fully featured proxy server that lets you surf the Web significantly faster. It also blocks all pop-up windows and banner ads from Web pages. An intelligent tune-up tool automatically analyzes and optimizes your computer's Internet connection and TCP/IP settings"""
X Surs awab.exe"PurityScan/Clickspring adware"
N Surveysa surveysa.exe"Found on Sony laptops it brings up a prompt to take a survey. It goes away if you fill out the survey or you choose ""never prompt me again"" but keeps popping if you either exit out of it or select ""take survey later"""
U suScheduler UCLauncher.exeRelated to Lenovo ThinkVantage Technologies. ThinkVantage Technologies help make ThinkPad/ThinkCentre PCs less dependent on IT staff
X Susp Susp.exe"VX2.Transponder parasite updater/installer related"
X susse hpsw.exe"LinkMaker adware"
X Sustem explorer.exeAdded by an unidentified VIRUS WORM or TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!
X SustemUpdate explorer.exeAdded by an unidentified VIRUS WORM or TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!
X SV00LSV SV00LSV.EXE"Added by the GRAYBIRD-C TROJAN!"
X SVA Player SVAplayer.exe"SVAPlayer parasite"
X Svc svc.exe"ClientMan parasite variant"
U SVC svchost.exe"ElfSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
X svc expseny.exe"Added by the PWS-ANG TROJAN!"
X SVC Service svcinit.exe"Added by the SINIT TROJAN!"
X SVC Service svcinit.exe"CoolWebSearch parasite variant"
X SVC Service svcpack.exe"CoolWebSearch Svcinit parasite variant"
X SVC Service svc32.pif"Added by the RBOT-ASC WORM!"
X SVC Socks mstaskm.exe"CoolWebSearch parasite variant"
X svc32 svc32.exeIdentified as a variant of the Banker-EQC/DLoader.GPJI malware
X Svced Svced.exe"Added by the DELF.F TROJAN!"
X SvcH0st msexploren.exe"Added by the BACKDOOR-CGZ TROJAN!"
X SvcH0st SHCH.EXE"Added by the BDOOR-EB BACKDOOR!"
X SvcH0st SVCHST.EXE"Added by the BDOOR-EB BACKDOOR!"
X SvcH0st WINAGENT.EXE"Added by the BDOOR-EB BACKDOOR!"
X SVCH0ST spoo1sv.exe"Added by the VB-HF TROJAN!"
X SVCH0ST SVCH0ST.EXE"Added by the VB-IK TROJAN! Note - the filename has the digit 0 rather then the uppercase ""o"""
X SvcH0st msnexploren.exe"Added by the TACTSLAY.B TROJAN!"
X SvcH0st sdhch.exe"Added by the TACTSLAY.B TROJAN!"
X SVCH0TS sp00lvs.exe"Added by the LINEAGE-AZ TROJAN!"
X svchast svchast.exe"Added by the LINEAGE-AV TROJAN!"
X svchctrl svchctrl.exe"Added by the COBFINN TROJAN!"
X svchos svchos.exe"Added by the EZIBOT-B TROJAN!"
X svchosd [path to trojan]"Added by the BANCOS-BCX TROJAN!"
X SVCHOSI SVCHOSI.EXE"Added by the VBBOT-AA WORM!"
X SVCHOST svchost.exe"System1060 homepage hi-jacker. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\System1060"
X svchost svchost.exe"Added by many TROJANS amd WORMS such as MORB or TARNO. Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
X SVCHOST mrowyekdc.exe"Added by the GOTORM WORM!"
X svchost Svch0st.exe"Added by the GRAYBIRD and GRAYBIRD.B TROJANS! Note - the filename has the digit 0 rather then the uppercase ""o"""
X svchost [path to trojan]"Added by the HAZZER TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
X svchost ADMAGIC.EXE"Added by the SMIBAG WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
X Svchost winhost.exe"Added by the LOLAWEB.A TROJAN!"
X Svchost svchost.exe"Added by the MOZE-A WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder"
X SVCHOST var.txt.exe"Added by the LDPINCH.C TROJAN!"
X Svchost svchosl.pif"Added by the INZAE.A or INZAE.B WORMS!"
X svchost [path] SETUP.EXE"Added by the SETCLO WORM!"
X SVCHOST scvhost.exe"Added by the MYTOB.E or MYTOB.G WORMS!"
X SVCHOST taskgmr.exe"Added by the MYTOB.F or MYTOB.H WORMS!"
X svchost olehelp.exe"Added by the BOOKMARKER.G TROJAN!"
X SVCHOST updater32.exe"Added by the RANTS.A WORM!"
X SVCHOST SPOOLSV.EXE"Added by the BAITAP-A WORM! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%"
X SvcHost svchost32.exe"Added by the AGOBOT-TM WORM!"
X svchost svchost.exe"Added by the BANCBAN-HL TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a ""config"" subfolder of the Winnt or Windows folder"
X svchost [path to explorer.exe]"Added by the UNREAL-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!"
X svchost rundll16.exe"Added by the STARTPA-PB TROJAN!"
X Svchost svchost.exe"Added by the ADCLICK-AX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Program FilesInternet Explorer folder"
X svchost svchost.exe"Added by the BDOOR-ES BACKDOOR! Note - this is not the legitimate
X svchost svchost.exe"Added by the DLOADER-EV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%"
X svchost winhelp.exe"Added by the GAOBOT.GEN!POLY WORM!"
X SVCHOST MDM.EXE"Added by the LCJUMP-A WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is always located in %ProgramFiles%\Microsoft Shared. This one is located in %Windir%"
X Svchost svchots.exe"Added by the RBOT.ADK WORM!"
X svchost ying.exe"Constructor VC2000 malware"
X svchost inetinfo.scr"Added by the ODELUD WORM!"
X SVCHOST svchost64.exe"Added by the STARTP-G TROJAN!"
X SVCHOST SPOOLSV.EXE"Added by the BAITAP-A WORM! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%"
X svchost connection monitor svchost32.exe"Added by a variant of the SDBOT WORM!"
X SVCHOST Generic application svchost.exe"Added by the DAEMONI-K TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder"
X svchost Netware Manager svchost.exe"Added by the EXVID.A WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
X SVCHost Protocol32 scvhost32.exe"Added by a variant of the IRCBOT TROJAN!"
X Svchost Service svchost.exe"Added by the VB-DVQ WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Help subfolder of the Winnt or Windows folder"
X Svchost Windows Remote Services svhost.exe"Added by the IRCBOT-IV WORM!"
X svchost.exe svchost32.exe"CoolWebSearch Svchost32 parasite variant"
X SVCHOST.EXE SVCHOST.EXE"Added by the WRMSCAN-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder"
X svchost.exe [path to executeable]"Added by the BANKER-MO TROJAN!"
X svchost.exe svchost.exe"Added by the ZAPCHAS-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a ""drivers"" subfolder"
X svchost.exe swchost.exe"Added by the SADELPHI-A TROJAN!"
X svchost1 svchost1.exe"Added by the AGOBOT.ZZ WORM!"
X SvcHost32 svchost32.exe"Added by the MIMAIL.I or MIMAIL.J WORMS!"
X svchost32.exe svchost32.exe"Added by the ASSASIN.20B BACKDOOR!"
X svchost64 svchost64.exeAdded by the SDBOTER.G VIRUS!
X svchosta svchosta.exe"Added by the SNIFFER-I TROJAN!"
X svchostb svchostb.exe"Added by the SNIFFER-J TROJAN!"
X SvcHostDHCP svchost32.exe"Added by the ASSASIN.20B BACKDOOR!"
X svchostdll.scr svchostdll.scr"Added by the BANCBAN-FM TROJAN!"
X SvcHosto v1rg1n.exe"Added by the AGOBOT-TK WORM!"
X svchostr svchostr.exeAdded by an unidentified WORM or TROJAN!
X svchosts svchosts.exe"Added by the BANCBAN-DC or BANKER-ED TROJANS!"
X svchosts.exe svchosts.exe"Added by the AGOBOT-JN WORM!"
X svchosts.scr svchosts.scr"Added by the BANCBAN-DQ TROJAN and variants!"
X SVCHOT SVCHOT.exe"Added by the QQROB-U TROJAN!"
X svchst svchst.exe"Added by the KBROY-C TROJAN!"
X svcinfo svcinfo.exe"Added by the CRYPTER.A TROJAN!"
X Svclhost svcchost.exeAdded by an unidentified WORM or TROJAN!
X SvcManager restore3.exe"Added by the AGENT-DSS TROJAN!"
X SvcManager spoolvs3.exeAdded by an unidentified WORM or TROJAN!
U svcmon svcmon.exe"PersonInspect surveillance software. Uninstall this software unless you put it there yourself"
X Svconr Svconr.exe"WaveRevenue-lBann adware"
X svcroot svcroot.exe"Added by the KEYLOG-AC TROJAN!"
X svcshare winampXP.exe"Added by the FUJACKS-J VIRUS!"
X svcshare spoclsv.exe"Added by the FUJACKS-A VIRUS!"
X svcshare CTMONTv.exe"Added by the FUJACKS-AJ WORM!"
X svcshare nvscv32.exe"Added by the FUJACKS-Z WORM!"
X SvcSys [path to file]"Added by the BANCOS.Z TROJAN!"
X Svcsys Registry Manager svcsysreg.exe"Detected by Kaspersky as the AGENT.CV TROJAN!"
X svcsys32 svcsys32.exe"Added by the AGOBOT-LL WORM!"
X svctask svctask.exe"Added by the CHUCKYB-A TROJAN!"
X svcwinprocess32 [path to worm]"Added by the UPERING WORM!"
X SVGA Adapter svghost.exe"Added by a variant of the SPYBOT WORM! See here"
X svhcost svhcost.exe"OpenSearch adware"
X svhoost checksys.exeAdded by a downloader TROJAN of Chinese origin!
X SVHOST svhost.exe"Added by the MYDOOM.I WORM!"
X SVHOST SVHOST.EXE"Added by the ZORI.A VIRUS!"
X Svhost Loader svshost.exe"Added by the AGOBOT.G WORM!"
X Svhost Service Server svhostser.exe"Added by a variant of the RBOT WORM! See here"
X svhost updates Svhost.exe"Added by a variant of the RBOT WORM!"
X svhost windows services svhost8.exe"Added by the RBOT-WQ WORM!"
? SVIDC32M SVIDC32M.exe"??"
X sVideo2 [path to dialler]"""Switch-D"" premium rate adult content dialler"
X sviload32 sviload32.exe"Added by the RBOT-AAS WORM!"
? SVM Pop svmpop.exe"??"
X svnlitup32 svnlitup32.exe"Added by the RBOT.CBJ WORM!"
X svnloader svnload32.exe"Added by the RBOT-ACU WORM!"
X svphost.exe svphost.exe"Added by the AGENT.CS TROJAN!"
U SVPWUTIL SVPWUTIL.exe SVPwUTILPart of Toshiba Hardware Setup
X svrrun svrrun.exeAdware hailing from Deskwizz.com
X svsekin svsekt.exe"Added by the QQPASS.G TROJAN!"
X svshost svshost.exe"Added by the CHODE-H WORM!"
X svshost messenger.exe"Added by the LOONY-G TROJAN!"
X Svshost Update Service svcbind.exe"Added by the MYTOB.LH WORM!"
X svshost32 msgrsv32.exeAdded by the RANKY.AJ TROJAN!
X svshost32 svshost32.exe"Added by a variant of the SDBOT WORM!"
X svshostdriver svshost.exe"Added by the SDBOT-HN TROJAN!"
X svtcin n20050308.a.Stub.EXE"Added by the N20050308 TROJAN!"
X svwin32 unninst32.exe"Added by the AGOBOT-NF WORM!"
X SVX Control Service svxhost.exe"Added by the FORBOT-K WORM!"
U SW20 sw20.exe"Related to MSI's Dynamic Overclocking Technology"
U SW24 sw24.exe"Related to MSI's Dynamic Overclocking Technology"
N Swap Nut javaw.exejavaw.exe can be loaded by other programs at startup but in this instance it's SwapNut a peer-to-peer file sharing and searching utility developed and marketed by File Metrics Inc. Users can search for and find almost any type of digital file (audio video photos etc.) through a secure peer-to-peer network
X SWCaller SWcaller.exe"Swporta homepage hijacker"
X SWCaller Swcaller2.exe"Swporta homepage hijacker"
X Swchost Swhost.exe"Added by the BDOOR-MP BACKDOOR!"
U SWClient swsys.exe"ActivMonAgent keyboard logger/monitoring program - remove unless you installed it yourself"
X swcroot swcroot.exe"Added by the SOLENO-A TROJAN!"
N SWd winwd.exe"PC Security from Tropical Software - lock files password protect etc"
Y Sweep95 ICLOAD95.EXE"Part of Sophos ant-virus sofware"
N SweetIM SweetIM.exe"vSweetIM - send fancier smiley-faces and IM graphics to friends who are using MSN Messenger. They are only able to see these advanced smiley-faces if they also have SweetIM installed"
X Swf32 AVupdate.exe"Added by the MERKUR.E WORM!"
X Swf32 _backup.exe"Added by the SYMTEN WORM!"
U swg GoogleToolbarNotifier.exe"Companion to the Google Toolbar that lets you keep Google as your default search engine and prevents this setting from being changed without your consent. Shouldn't remain in memory after the feature is disabled as it's a bug - see here"
X SwimSuitNetwork SwimSuitNetwork.exeAdvertising spyware
X swingsys SWINGSYS.EXE"Added by the BANCOS-CX TROJAN!"
U Switch Off swoff.exe"Switch Off - tray-based system utility that can automatically perform various frequently used operations like shutdown or restart your computer disconnect your current dialup connection lock workstation etc"
N Switchboard.com Toolbar AtHoc.exe"Toolbar for the on-line version of Yellow Pages in the US - Switchboard.com"
U Switcher Switcher.exe"""On a Sony laptop with built in wireless it allows the user to select which wireless services they want to run (i.e. Wireless LAN Bluetooth both) when turning the wireless switch on if disabled)"""
X switp switpa.exe"OfferAgent adware"
U SWL rundll32.exe [path] SWL.dll rdl"StealthWeblog surveillance software. Uninstall this software unless you put it there yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
U SWN2 swnxt.exe"Spyware removal program by TrekBlue. Previously not recommended but the latest version was delisted here"
X sws.exe [random filename]"Haldex type adult content dialler"
X sws.exe gd-dial.exe"Globaldialer adult content premium rate dialer"
N SwTray SWTRAY.EXEMS SideWinder game controller system tray icon. Available via Start -> Programs. May have the version number after it
N SWTrayV4 SWTrayV4.exeMS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs
U SwyxIt! SwyxIt!.exe"PC Based soft phone from Swyx - see here for more details"
U SX Virtual Link Connect.exe"SX Virtual Link from Silex Technology America Inc. Utility to connect USB devices"
? SXGDSENU sxgdsenu.exe"Yamaha SXG soundcard driver"
N SxgTkBar sxgtkbar.exeYamaha SXG soundcard utility - gives quick and easy access via the system tray bar to diagnostics and configuration
? Sxplog sxpstub.exe"Part of CA Unicenter Software Delivery - manage software across various systems from desktops and servers to PDAs and mobile phones in a controlled and standardized way - is it required at startup?"
X sxrrv sxrrv.pif"Added by the VAX-A TROJAN!"
X sy s2.exe"Added by a variant of the RBOT WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list