X |
Scr |
scr.scr | "Added by the OPASERV.T WORM!"
|
N |
ScrapPad |
Scrappad.exe | "ScrapPad allows you to quickly and easily record notes |
X |
scrbmk |
[path to trojan] | "Added by the DLOADER-VP TROJAN!"
|
U |
Screen Calendar |
scrcal.exe | "Screen Calendar allows you to create custom desktop wallpapers with built in active calendar and scheduler"
|
U |
Screen Guard |
launch.exe | "Part of Access Denied security and privacy software"
|
U |
Screen Guard Message Scan |
sgms.exe | "Part of Access Denied security and privacy software"
|
X |
Screen Saver |
scrnsaver.scr | "Added by the RBOT-AGP WORM!"
|
N |
Screen Saver Control |
FSScrCtl.exe | Installs as part of the Hubble Space Telescope screen saver (and possibly others). Lets you control your installed screensavers from a System Tray icon
|
N |
ScreenHunter 4.0 Free |
ScreenHunter.exe | """ScreenHunter 4.0 Free is a completely free screen capture software for you to easily take screenshots"""
|
N |
ScreenPrint32 |
ScreenPrint32.exe | "ScreenPrint32 screen capture software - can be launched manually"
|
X |
ScreenSaverPlus |
"rundll32.exe MSA64CHK.dll | DllMostrar" |
? |
screxe |
scruser2k.exe | "??"
|
? |
script |
script.bat | "Maybe associated with DOS on a Win9x machine"
|
Y |
ScriptBlocking |
SBServ.exe | "Update to Norton AntiVirus 2001. Detects certain types of script-based viruses without the need for specific virus definitions - such as JavaScript and VBScript. This will help protect you from these viruses even before virus definitions are available. Note - some users complain of problems once the update is installed - refer here for more information"
|
Y |
ScriptSentry |
Scriptsentry.exe | "Script Sentry from Jason's Toolbox. Blocks malicious scripts and allows safe scripts to run. Only required if you want it to check the file associations it guards at startup. It will function regardlessly"
|
U |
Scroll-In-Mouse V2.0 |
SCROLL.EXE | "Toolkit for the Lynx-3D Net scroll mouse from QTronix. Required if you use the special features"
|
X |
scroller |
fpapli.exe | "CoolWebSearch parasite variant"
|
X |
scrss |
scrss.exe | "Added by the HACDEF-R TROJAN!"
|
X |
scrsvc |
scrsvc.exe | "Added by the AGENT-DS TROJAN!"
|
X |
ScrSvr |
ScrSvr.exe | "Added by the OPASERV WORM!"
|
X |
ScrSvrOld |
[worm filename] | "Added by the OPASERV WORM!"
|
Y |
Scsi |
Scsi.exe | SCSI Miniport driver
|
X |
scssrr.exe |
Services.exe | "Added by the VB-EMX TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X |
sctrlmgr |
sescmgr.exe | "Added by a variant of the DWNLDR-GAH TROJAN!"
|
Y |
SCTUINotify |
SCTUINotify.exe | "Part of Windows SteadyState |
X |
scvhost |
svzhost.exe | "Added by a variant of the SPYBOT WORM!"
|
U |
scvhost |
scvhost.exe | "Wiretap surveillance software. Uninstall this software unless you put it there yourself"
|
X |
scvhost |
scvhost.exe | "Added by the AGOBOT-LI WORM!"
|
X |
scvhost loader |
ixplore.exe | "Added by the SDBOT-CY TROJAN!"
|
X |
scvhost.exe |
scvhost.exe | "Added by the LOHAV-N TROJAN!"
|
X |
Scvsrv32 |
scvsrv32.exe | "Added by the AGOBOT-PM BACKDOOR!"
|
X |
sd32info |
sd32info.exe | "Added by the CRYPTER.A TROJAN!"
|
U |
SDaemon |
sdaemon.exe | "PC Security from Tropical Software - ""is the ultimate in computer security |
U |
SDAutoLiveupdate |
LiveUpdateSD.exe | "Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here"
|
X |
SDAv |
csnss.exe | "Added by the SERFLOG.C WORM!"
|
X |
SDAv |
svhost.exe | "Added by the SERFLOG.C WORM!"
|
X |
sdchosts32 |
vbdd.exe | Added by the RANKY.AG TROJAN!
|
? |
SDClientMonitor |
sdclientmonitor.exe | "Related to LANDesk Management Suite from LANDesk Software Ltd. What does it do and is it required?"
|
N |
SDetect |
SDetect.exe | "ScanSuite Scanner Detector - part of ScanWizard |
X |
sdfgsdfg |
hey.exe | "Added by the AGOBOT-OR WORM!"
|
X |
sdfsdfsdf |
sp2update.exe | "Added by a variant of the SPYBOT WORM!"
|
X |
SDIN Adapter |
sdin.exe | "Added by the FORBOT-AP WORM!"
|
? |
SDJobCheck |
triggusr.exe | "Part of CA Unicenter Software Delivery - manage software across various systems |
X |
SDK Codre Function22 |
sdkimddprovment2.exe | "Added by the SDBOT-YJ WORM!"
|
X |
SDK Core Component |
sdkcore.exe | "Added by the SDBOT-WC WORM!"
|
X |
SDK Core Function |
sdkimprovment.exe | "Added by the RBOT.BHL WORM!"
|
X |
SDK Core Function2 |
sdkimprovment2.exe | "Added by the SPYBOT.OGX WORM!"
|
X |
Sdk**.exe [* = random char] |
Sdk**.exe [* = random char] | "CoolWebSearch/HomeSearch adware - for examples |
X |
Sdk**32.exe [* = random char] |
Sdk**32.exe [* = random char] | "CoolWebSearch/HomeSearch adware - for examples |
X |
SDKcore Update Components2 |
SDKC0R3.exe | "Added by the RBOT-ABA WORM!"
|
X |
SDKCprords |
SDKc55rezzz.exe | "Added by the RBOT.VD WORM!"
|
X |
sdkupdate22 |
SDK0mCORE.exe | "Added by the FORBOT-DT WORM!"
|
X |
SDKz0r |
SDKc55rezzz2.exe | "Added by the SDBOT-UN WORM!"
|
? |
SDMSSplash |
launcher.exe | "Part of HP's Smart Desktop Management System - ""Preloaded on select business desktops |
N |
SDPhotoBar.exe |
SDPhotoBar.exe | "SmartDraw Photo (now FotoFinsh) - ""organize |
X |
SDR6V_Check |
udcsdr.exe | "Part of the DriveCleaner rogue security software - not recommended |
X |
SDR6_Check |
udcsdr.exe | "Part of the DriveCleaner rogue security software - not recommended |
X |
sdrss |
sdrss.exe | "Added by the SDBOT-SQ WORM!"
|
U |
sds20 |
svchost.exe | "InlookExpress logs keystrokes and captures screenshots. If you didn't install this yourself remove it. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\sds20"
|
X |
SdScans** |
stup_tmp.#32 | "Added by the SDSCAN.A TROJAN - where ** are random upper case letters"
|
U |
SDTray |
sdtray.exe | "RSA Keon Web PassPort - software that allows organizations to use digital certificates in a Web-based environment to help ensure that their transactions are authentic |
Y |
SDTray |
SDTrayApp.exe | "System Tray access to an older version of Spyware Doctor antispyware from PC Tools"
|
X |
sdxsys32 |
sdxsys32.exe | "Added by the BROGGER-A TROJAN!"
|
U |
sealmon |
sealmon.exe | "SealedMedia enables you to combine document protection and control with your existing applications - such as Microsoft Word |
X |
Search Bar |
taskbar.exe | "Added by the OPANKI-F WORM!"
|
X |
Search Defender |
SearchDefender.exe | "Installed by SpeedItUp without permission |
? |
Search Hook |
srchhook.exe | "??"
|
X |
Search Page |
http://find.naupoint.com | "Naupoint browser hijacker"
|
U |
Search Protection |
SearchProtection.exe | """Yahoo! Search Protection will alert you if an attempt is made to change your default browser search engine from Yahoo!"""
|
X |
Search-Exe |
SE.exe | "Search-Exe hijacker"
|
X |
Search.vbs |
| Hijacker
|
X |
SearchAndDestroyMFC |
Search And Destroy.exe | "Search And Destroy rogue security software - not recommended |
X |
SearchAndDestroyScheduler |
SearchAndDestroy.exe | "Search And Destroy rogue security software - see here and here"
|
X |
SearchAndDestroyT |
SearchAndDestroy.exe | "Search And Destroy rogue security software - see here and here"
|
X |
searchbar |
vnmispoisn downloader.exe | SearchBarCash adware variant
|
X |
SearchClick |
[trojan filename] | "Added by the AGENT-DWR TROJAN!"
|
X |
SearchEnhancement |
scbar.exe | "SCBar foistware"
|
X |
SearchMP3 |
"rundll32.exe MSA64CHK.dll | DllMostrar" |
X |
searchnav |
searchnav.exe | SearchNav adware - IEFeatures/Popnav variant
|
X |
SearchNavVersion |
searchnavversion.exe | SearchNav adware - IEFeatures/Popnav variant
|
X |
SearchNet_Up |
ServeUp.exe | "SearchNet adware"
|
U |
SearchProtection |
SearchProtection.exe | """Yahoo! Search Protection will alert you if an attempt is made to change your default browser search engine from Yahoo!"""
|
X |
SearchSetter |
searchsetter[1].exe | Browser hijacker - redirecting to FindWhateverNow.com
|
X |
SearchSettings |
SearchSettings.exe | "Vendio ""Search Settings"" foistware - reportedly installed without notice |
X |
SearchSpy |
SearchSpyMenu.exe | "SearchSpy rogue spyware remover - not recommended"
|
X |
SearchSquire[number] |
SearchSquire[number].exe | "SearchSquire adware"
|
X |
SearchUpgrader |
SearchUpgrader.exe | Hijacker
|
X |
Secboot |
w32tm.exe | "Added by the HAXDOOR.D TROJAN!"
|
X |
secboot |
mszx23.exe | "Added by a variant of the HAXDOOR.BC TROJAN!"
|
X |
secboot |
vtd 16.exe | "Added by the HAXDOOR-AE TROJAN!"
|
X |
secdrive.exe |
secdrive.exe | "Added by a variant of the SPYBOT WORM! See here"
|
U |
Second Copy 2000 |
SecCopy.exe | "Related to Second Copy? - a files/folders backup utility"
|
U |
SecondChance |
sctray.exe | "Power Quest Second Chance. Sets checkpoints for saving a backup copy of the registry to a disk so you can restore it if you have a crash"
|
X |
Secret |
Secret.exe | "Added by the DELF-LW TROJAN!"
|
X |
Secret-Crush |
start.exe | Hijacker that may reset your browser's home page and/or search settings to point to undesired sites
|
U |
SECRETMAKER |
secretmaker.exe | "Secretmaker is a combination of eight privacy-defending programs |
U |
SecretSmileys |
ss.exe | """Secret Smileys is an add-on for AIM that provides users access to 1000's of new Smileys that can be viewed by anyone using a current version of AIM. Secret Smileys also adds other features such as logging of IM conversations |
X |
secserv.exe |
secserv.exe | "Detected by Panda as an EasySearch adware variant. Note - EasySearch modifies the Internet Explorer settings and may download programs onto the infected computer"
|
X |
secsvc32 |
secsvcnt.exe | "Added by the GLOBAL PATROL TROJAN!"
|
U |
Secsys |
Secsys.exe | "UltraSoft Key Interceptor surveillance software - uninstall this unless you put it there yourself!"
|
U |
SecurDisc |
NBHGui.exe | "Part of the Nero multimedia suite backup function - ""Recover your data quickly and easily and create discs that are password protected. SecurDisc technology gives you peace of mind"""
|
X |
secure |
[random].exe | "DealHelper adware"
|
X |
secure |
svshost.exe | "Added by the RBOT-AFO WORM!"
|
X |
Secure AntiVirus Pro |
av.exe | "Secure AntiVirus Pro rogue security software - not recommended |
X |
secure socket layer |
wins32a.exe | "Added by an IRCBOT TROJAN!"
|
X |
Secure Socket Layer Certification |
sslcert.exe | "Added by the VANEBOT-AN WORM!"
|
X |
Secure System |
integitor.exe | "Added by the AGOBOT.ACI WORM!"
|
X |
Secure32 |
Shell32.com StartUp | "Added by the BRONTOK-CJ WORM!"
|
X |
Secure64 |
Regedit32.com StartUp | "Added by the BRONTOK-CJ WORM!"
|
N |
SecureClean4RegManager |
scregmanager4.exe | "WhiteCanyon SecureClean 4 disk cleaner - clean hard drive data |
N |
SecureClean4Tray |
sctray4.exe | "WhiteCanyon SecureClean 4 disk cleaner - clean hard drive data |
X |
SecureCleaner |
SecureCleaner.exe | "SecureCleaner spyware remover - not recommended |
N |
SecureCleanIEClean |
SCIEClean.exe | "SecureClean - scans your system for hidden temporary files |
X |
SecureExpertCleaner |
sec.exe | "Secure Expert Cleaner rogue privacy program - not recommended |
X |
SecureFighter |
SecureFighter.exe | "SecureFighter rogue security software - not recommended |
U |
SecureItPro |
Secureitpro470p.exe | "SecureIt Pro - lock your computer when you're not there |
X |
SecureKeeper |
SecureKeeper.exe | "SecureKeeper rogue security software - not recommended |
X |
SecureLogin |
Mslg32.exe | "Added by the REDZED WORM!"
|
U |
SecureOnlineAccountNumbers |
SOAN.exe | "Related to Secure Online Account Numbers by Discover(R) Card from Orbiscom Ltd. Secure and innovative payment solutions"
|
X |
SecurePcAv |
SecurePcAv.exe | "SecurePcAv rogue security software - not recommended |
X |
SecurePCCleaner |
GDC.exe | "SecurePCCleaner rogue privacy tool - not recommended |
U |
SecurePCSolutionsBootCheck |
BootCheck.exe | "1 Click Fixer PLUS from Secure PC Solutions ""takes the guesswork out of locating and solving problems in the Windows registry"""
|