| Name | Status | Filename | Description |
|---|
| SonudMan | X | SonudMan.exe | Added by the Trojan.Startpage.Q or Troj/StartPa-HN TROJAN! Note: This trojan file is found in the Windows or Winnt folder. Should not be confused with (soundman.exe) which is a SIS and Realtek file. |
| salm | X | salm.exe | nCase Adware |
| Service Drivers | X | abl.exe | Added by the W32/Sdbot-YX
Worm!
|
| Shellapi32 | X | svcnet.exe | Added by the W32/TIBICK-C WORM! |
| Srv32Old | X | .PIF | Added by the OPASERV.J VIRUS! where <filename> is the original worm name |
| Services Start2 | X | odcwinst.exe | Added by the Worm/Skipi.C Worm |
| System | X | windowsps.exe | Added by a variant of the WIN32.RBOT WORM!
|
| SOFTinst | Y | N/A | For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out |
| SCDEmuApp.exe | U | SCDEmuApp.exe | Related to PowerISO Computing Inc. A CD/DVD image file processing tool. |
| System CSRSS Patch | X | SCRTKFG.EXE | Added by the W32/RBOT-ADA WORM! |
| System Monitor | X | Sysmon16.exe | Added by the SDBOT WORM! |
| SAHagent | X | Sahagent.exe | ShopAtHomeSelect adware |
| serrv | X | serrv.exe | Warezov.DC |
| setdefprt | N | setdefprt.exe | Used to set a Brother MFC printer/copier/scanner as the default printer after installation |
| svc | X | byetmr.exe | Added by the TROJ_ONLINEG.DCZ TROJAN! |
| securw | X | Nctrup.exe | Added by the W32.NOPIR.A WORM! |
| Scheduler | X | svcrhost.exe | Added by the WIN32.TACTSLAY.A TROJAN! |
| SYSWB6 | U | SYSWB6.exe | We-Blocker - gives parents the opportunity to monitor their children's Internet access and provide them with age-appropriate content, while filtering out sites that contain adult content |
| System Services | X | ssms.exe | Added by a variant of the WIN32.RBOT WORM!
|
| sixer566 | X | sscc.exe | Added by the Win32_Malware_gen Note: Located in \%WINDIR%\System32\ |
| Services.dll | X | smss.exe | Added by the W32/SOBER-L WORM! - NOTE - this file is placed in a %WinDir%\msagent\system folder, and should NOT be confused with the legitimate Windows smss.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
|
| System Mechanic Popup Stopper | U | Popupstopper.exe | Iolo "System Mechanic" popup stopper |
| Starter | X | scvhosting.exe | WORM_SDBOT.RU
|
| smcss | X | smcss.exe | Added by the Troj/SCLog-AJ Trojan Read the link, steals information |
| SSh32 | U | SSh32.exe | 2Spy keystroke logger/monitoring program - remove unless you installed it yourself! |
| System Service | X | coderxt.exe | Added by the W32/Rbot-ALD
WORM!
|
| ServicesAdministrator | X | SERVICES.EXE | Added by the W32/Punya-B Worm |
| SystemService | X | pokapoka62.exe | EliteBar adware component |
| Servicos | X | AdobeLanc.exe | Added by the Troj/Banker-EHR Trojan |
| SkyTel | U | SkyTel.EXE | Related to Voice_Manager from Realtek. Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| sp | X | regedit-s ....,sp.dll | Malicious javascript annoyance that changes the default search engine in IE to one of many including "topsearcher". See here for more and a fix |
| SysStart | X | ***sysi6.exe (*,= random char) | Added by ZenoSearch adware - filenames spotted include jdisysi6.exe, hjisysi6.exe, ffgsysi6.exe and more.
|
| StartupMonitor | U | StartupMonitor.exe | Mike Lin\'s StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu |
| system updata | X | updata.exe | Added by the Troj/Lineage-C
TROJAN!
|
| ServiceLayer | Y | ServiceLayer.exe | Nokia Connectivity Library support task that is needed by NCLTRAY and by the Nokia Connection Manager for either to work properly. |
| SafetyNet_Notifier | U | ipcLn.exe | Related to SafetyNet Traffic Management and Security Solutions |
| SetVrc | X | setvrc.exe | Added by the HUNTOCX VIRUS! |
| SysSearch | X | [path],REGEDIT.EXE -s,[path],sysreg.reg | Hijacker, also detected as the TROJ/STARTPA-ME TROJAN! |
| SVCHOST | X | mrowyekdc.exe | Added by the GOTORM VIRUS!. This is not the valid svchost.exe as described here |
| SystemDoctor Free | X | systemdoc.exe | Added by SystemDoctor A Rogue Security Program. Note: Located in \%Program Files%\System Doctor Free\ Note: Use SDFix under supervision. |
| SNM] | Y | SNM.exe | Related to SpyNoMore Anti-Spyware Software. Note: Located in C:\Program Files\SpyNoMore\ |
| switp | X | switpa.exe | OfferAgent adware component |
| systemdll32.exe | X | systemdll32.exe | Added by the FEUTEL-F TROJAN! |
| svctask | X | svctask.exe | Added by the Troj/Chuckyb-A
TROJAN!
|
| SmartSync Pro | U | SmartSync.exe | Related to CompanionLink Software Inc., Synchronization solutions for ACT!, GoldMine, Lotus Notes and Microsoft Outlook. |
| System Updates | X | szwi.exe | Added by the W32/Rbot-AXE
WORM!
Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
|
| SYSTEM | X | lsas.exe | Added by the SPYBOT.CJ worm |
| sssasasb32 | X | sssasasb32.exe | Added by the WIN32.TACTSLAY.F TROJAN! |
| SystrayServices | X | Msxpw.exe | Added by the CITOR VIRUS! |
| SysMemory manager | X | mdms.exe | Added by the Troj/Cimuz-D
TROJAN!
Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
|
| System-Stat | X | systats.exe | Added by the SDBOT.RA WORM!
|
| SmansaApp | X | winlogon.exe | Added by the W32/Romario-A Worm |
| Search Bar | X | taskbar.exe | Added by the W32/OPANKI-F WORM!
|
| snp2std | U | vsnp2std.exe | Digital camera related. |
| SheduIer | X | svchst.exe | Premium rate adult content dialer |