Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Servicesara services.exe"Added by the BRONTOK-BS WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
X ServicesLoad lsass.exe"Added by the DEARIS-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X ServicesLog ccapp32.exe"Added by the RBOT-AMX WORM!"
U ServicesNotify ServicesNotify.exe"Defender Pro Antispy"
X servicestub.exe servicestub.exe"Added by the RBOT.CN BACKDOOR!"
X Servicewin Hide32.exe"Added by the MSNVB-D WORM!"
X Servicing hostd.exe"Added by the SDBOT.BUI WORM!"
X Servicio Local svhost.exe"Added by the SPYBOT.BGX WORM!"
X servico servico.exe"Added by the BANKER-DKE TROJAN!"
X Servicos AdobeLanc.exe"Added by the BANKER-EHR TROJAN!"
X Servicos System.exe"Added by the BANCOS-BCM TROJAN!"
X servics servics.exe"Added by the SINGU-J TROJAN!"
X servises servises.exe"Added by the AGENT-JUJ WORM!"
X SERVlCE SERVlCE.EXE"Added by the AGOBOT-UB WORM!"
X ServRun srss32.exe"Added by the AGOBOT.ABS WORM!"
? ServUTrayIcon ServUTray.exe"System Tray icon for Serv-U FTP server. Is it required?"
X SES Service sesvc.exe"Added by the SDBOT-CZU WORM!"
U Session Client sescli.exe"SurfSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
X Session Manager Subsystem smssa.exe"Added by the RBOT-AGS WORM!"
X SessionMngr dirlock.exe"Added by the DAPROSY WORM!"
X SESync sed.exe"DownloadWare adware"
? SetCacheMode "rundll32.exe ptipbmf.dll SetWriteCacheMode"
? SetDefaultMIDI MIDIDef.exe"Related to a Soundblaster Audigy soundcards. What does it do and is it required?"
Y SetDefaultPrinter cloaker.exeUsed by HP and Compaq computers to hide the windows of programs passed as arguments to it
N setdefprt setdefprt.exeUsed to set a Brother MFC printer/copier/scanner as the default printer after installation
N SetDefPrt BrStDvPt.exeUsed to set a Brother MFC printer/copier/scanner as the default printer after installation
U SetecCertUtil Certutil.exe"Setec Web and Email Security. Setec PKI smart card software. The PKI technology enables secure and reliable user identification in services offered through Internet
X setFTPBack createsw.exe"Added by the FTP_BMAIL TROJAN!"
N SetHook Sethook.exe"Fellowes Neato® cd label design software. ""Launch NEATO's MediaFACE II label making software directly from the productname toolbar"""
N SETI@home SETI@home.exeSETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data
N seticlient SETI@home.exeSETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data
N SetIcon SetIcon.exe"Installed by a 6-in-1 (4 Media Card slots
N SetiQueue Setiqu~1.exe"Provides work unit buffering for Seti@Home clients - see here for more details"
N SetiSpy SetiSpy.exe"SETI Spy is a little program to ""spy"" on the progress and performance of the SETI@home client. Called a ""spy"" because it is unobtrusive as possible"
X SetPoint SetPoint.exe"Added by the RBOT-BWI WORM! Note - this is not the valid Logitech Setpoint mouse and keyboard entry that uses the same filename and is located in %ProgramFiles%\Logitech\Setpoint. This one is located in %System%"
U SetPoint Setpoint.exe"Logitech SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice
X SETPOINT Logitech Inc KHALMNP.exe"Added by the RBOT-AAX WORM!"
U SetRefresh SetRefresh.exe"Found on some Compaq & HP PCs. SetRefresh is a utility which attempts to optimize the monitor's refresh rate
X Setting sysweb.exe"Added by the SDBOT.GEN TROJAN!"
N setup hphprld.exe ....setup.exeHP DeskJet Setup - printers function normally without it
X Setup [path to trojan]"Added by the DROPPER.EAT TROJAN!"
X Setup experation svchost.exe"Added by the TOFGER-AW TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X setup.exe setup.exe"Added by the GOLDUN-GB TROJAN!"
X setupa runt32.exe"Added by the QQPASS-K TROJAN!"
X setupdata rnll32.exe"Added by the QQPASS-AC TROJAN!"
N SetupICWDesktop icwconn1.exeAppears to be the "Internet Connection Wizard" from Internet Explorer being set-up as a desktop shortcut. Appears under the RunOnce registry key but is available under Start -> Programs -> Accessories -> Communication (or similar) anyway
X setupuser regedit.exe setupuser.log"Regfile in disguise - another CoolWebSearch parasite variant"
? setuzp setuzp.exe"??"
X SetVrc setvrc.exe"Added by the HUNTOCX WORM!"
X Sevice winconfig.exe"Added by the GIP.113.B1 TROJAN!"
X Sex Teris st01b.exe"Added by the REPAD WORM!"
X Sexnow Sexnow.exe"Added by the SENOW-B premium rate adult content dialler"
X Sexy_Blondes Sexy_Blondes.exe"Added by the Sexy DIALER! Related also to Hot Tarts DIALER!"
X Sexy_sg Sexy_sg.exePremium rate adult content dialler
X sf sf.exe"SurfEnhance adware component"
N SFIGUI SFIGUI.EXE"Sonic Focus - ""enhances music
X sfita sfita.exe"Added by the FAVADD-H TROJAN! Also known as SurfEnhance adware"
X SfKg6w rayiou.exe"Added by the AGENT.BUO WORM!"
X SfKg6wIP [random filename]Identified as a variant of the TrojanDownloader.Matcash malware
X SfKg6wIPu [random filename]Identified as a variant of the TrojanDownloader.Matcash malware
N SFP vzSFPWin.EXEVerizon Online Support Center - prompts for online updates
U sfpc sfpc.exe"Spy4PC surveillance software. Uninstall this software unless you put it there yourself"
X SFtrb Service cftrb32.exe"Added by the SOBIG.D WORM!"
U SfWinStartInfo sfWinStartupInfo.exeSFIRM32 Online Banking software
U Sgecrypt Sgecrypt.exe"SafeGuard Easy - ""provides total company-wide protection for sensitive information on laptops and workstations. Boot protection
U Sgeecview Ecview.exe"SafeGuard Easy - ""provides total company-wide protection for sensitive information on laptops and workstations. Boot protection
U sginst sginst.exe"eAcceleration Stop-Sign security software related. Previously not recommended
X SGPUpdater sgpUpdaters.exe"Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo
? SGTBox SGTBox.exe"Canon scanner driver. Is it required?"
U sgtray sgtray.exe"StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop)
Y Shadow Shadow.exe"""NTI Shadow 3 is an award-winning easy-to-use backup application that automatically protects your photo
U ShadowUser Pro Edition ShadowUser.exe"""StorageCraft™ ShadowUser™ provides easy to use desktop security and protection for Windows operating systems. ShadowUser is the best way to prevent unwanted changes to PCs and laptops"""
X shambl3r cnf.bat"Added by the REMABL WORM!"
X shambl3r* shambl3r.exe"Added by the REMABL WORM! where * is 2 to 11"
X SHAProc SHAProc.exe"Added by the WINKO.AO WORM!"
N Share-to-Web Namespace Daemon hpgs2wnd.exe"Share-to-Web - HP-created software and Internet-based application that enables easy uploading and sharing of photos via affiliated photo-sharing Web sites. Available via Start → Programs"
N Shareaza Shareaza.exe"Shareaza P2P client"
U Shareaza bindata.exe"Shareaza P2P client related"
X sharedprem sharedprem.exe"Added by the MAKECALL TROJAN!"
X ShareSearcher [path to trojan]"Added by the AGENT-FPE TROJAN!"
X ShareSearcher wsusupd.exe"Added by the ENCLAG-A TROJAN!"
Y Sharing and Mapping Software DShmap.exe"Intel AnyPoint internet sharing software. Now discontinued"
N SharkEject AEJCT32.exe"Allows you to eject a disk from the Avatar Shark drive from the system tray. When loaded
U SharpTray SharpTray.exe"Part of the Sharpdesk from Sharp Electronics. ""A desktop-based
X shccde winssled.exe"Added by the BUZUS.CQMU TROJAN!"
N Shcenter chcenter.exe"IMSI HiJaak - ""the easiest way to convert
X shdef shdef.exe"Added by the VB-DVS TROJAN!"
X SheduIer svchst.exePremium rate adult content dialler
X SheduIer shch.exe"Added by the BDOOR-EB BACKDOOR!"
X SheduIer winagent.exe"Added by the BDOOR-EB BACKDOOR!"
X Shedule Connection arpo412.exe"Added by the PPDOOR-R WORM!"
X Sheduler nerocheck.exe"Added by the TACTSLAY.B TROJAN!"
X Shell Shell32.exe"Added by the BADSECTOR TROJAN!"
X Shell ray.exeHomepage hijacker re-directing browsers to adult content websites
X Shell Tray.exeHomepage hijacker re-directing browsers to adult content websites
X Shell wmedia16.exe"Added by the GOLDUN TROJAN!"
X Shell Open32.exe"Added by the SMALL-DL TROJAN!"
X Shell Explorer.exe sound_drive16.exe"Added by the GP BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""sound_drive16.exe"" file is located in %System%"
X Shell "Explorer.exe msmsgs.exe"
X Shell Explorer.exe svchost.exe"Added by the DOYORG BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The legitimate svchost.exe process is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X shell explorer.exe"Added by the KAKKEYS TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X Shell Explorer.exe iexplore.exe"Added by the KIPIS-U WORM! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The legitimate Internet Explorer (iexplore.exe) is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%\Microsoft"
X Shell ibm0000*.exe [* = digit]"Added by the TORPIG-C and TORPIG-J TROJANS! Filenames spotted include ibm00001.exe
X Shell taskmrg.exe"Added by the BANCBAN-FT TROJAN!"
X Shell Explorer.exe winupdate.exe"Added by the AGENT-FD TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""winupdate.exe"" file is located in %System%"
X Shell Explorer.exe [path] ibm[RANDOM 5 DIGIT NUMBER].exe"Added by the ANSERIN TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files"
X Shell svchost.exe"Added by the GOLDSPY-B TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X Shell ibm00001.dll"Added by the TORPIG-Q TROJAN!"
X Shell wmedia32.exe"Added by the AGENT-BR TROJAN!"
X Shell Explorer.exe winsys32.exe"Added by the DELF.CP BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""winsys32.exe"" file is located in %Windir%"
X Shell Win32.dll.exe"Added by the VB.BTX TROJAN!"
X Shell taskmam.exe"Added by the BANCBAN-OL TROJAN!"
X Shell explorer.exe msbnc.exe"Added by the AGENT-PL BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""msbnc.exe"" file is located in %System%"
X Shell Explorer.exe kbdsys.exe"Added by the DAPROSY WORM! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""kbdsys.exe"" file is located in %AppData%\Microsoft\Keyboard"
X Shell smsc.exe"Added by the BANCBAN-OY TROJAN!"
X Shell Explorer.exe init32m.exe"Added by the DLSW-B TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""init32m.exe"" file is located in %System%"
X Shell Explorer.exe smssnt.exe"Added by the AGOBOT.EE TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""smssnt.exe"" file is located in %System%"
X Shell API32 svcnet.exe"Added by the TIBICK.C WORM!"
X Shell Extension spollsv.exe"Added by the LOVGATE.Z WORM!"
X Shell Tray Window ShellTraywnd.exe"Added by the STULTDOR-A TROJAN!"
X shell update shellexec.exe"Added by the RBOT-ANC WORM!"
X Shell.exe Shell.exe"Added by the EMERLEOX.S WORM!"
X Shell32 Shell32.vbs"Added by the SCAFENE WORM!"
X shell32 ntldrt.exe"Added by the JLOK-A WORM!"
X Shell32 iexplore.exe"Added by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X Shell32 explorer.exe"Added by the SDBOT-NF WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X ShellApi SHELLMSN.EXE"Added by the NETDEV.B TROJAN!"
X Shellapi32 Shellapi32.exe"Added by the NETDEVIL (or NERTE) TROJAN!"
X Shellapi32 mcvsrte.exeAdded by an unidentified WORM! Note - do not confuse with the McAfee SecurityCenter file of the same name
X shellbn [random].dll"SoftStop rogue security software - not recommended"
X shellbn shlext32.exe"Malware installed by different rogue security software including SpyKillerPro and the XP AntiVirus series"
X ShellCommand [path to file]"Added by the REMCON-A TROJAN!"
X Shelldaemon Shelldaemon.exeAdded by a variant of the AGENT.ALN TROJAN!
X ShellEx ShellEx.exe"Added by the ANAKHA TROJAN!"
X ShellN isca.exe"Added by the IBILL.Z TROJAN!"
X ShellOS A+++.exeAdded by the AV TROJAN!
X ShellRun lexplore_.exe"Added by the MSNOPT-A TROJAN!"
X ShellRun32 iexplore.exe"Added by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X Shellspl lsas.exe"Added by the YALER-A TROJAN!"
X Shellspl spools.exe"Added by the PROXAGE-A TROJAN!"
X shellsystem shellsystem.exe"Added by the UPCHAN TROJAN!"
X shhost shhost.exe"Added by the AGENT.CE TROJAN!"
N shicoxp shicoxp.exeInstalled with the drivers for multi card readers of various brands. To differentiate between the various card slots on multi slot readers the shicoxp.exe file assigns and loads unique drive icons for the various card slots that are displayed in Windows Explorer
X Shield Security shield.exe"Added by the RIZO.A TROJAN!"
X Shield32 Security shield32.exe"Added by the RIZO.A TROJAN!"
X ShieldSafeness ShieldSafeness.exe"ShieldSafeness rogue security software - not recommended
X Shine Shine.exe"Added by the HAPPYLOW (or NISHE-A) VIRUS!"
? SHINITV shinitv.exe"??"
X Shmgrate.exe ibot4.exe"Added by the GASTER TROJAN!"
N ShockmachineReminder SmReminder.exe"""Shockmachine is a stand-alone application that lets users collect Macromedia Shockwave and Flash titles and play them offline"". Could be a registration reminder for the trial version"
X Shockwave csrss.exe"Added by the SNDOG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
N Shockwave Init SWINIT.EXEPart of Macromedia Shockwave. Controls the Shockwave Remote Control Panel. The Remote Control can be activated manually from the Start Menu by locating and selecting Shockwave and then Shockwave Remote under Programs
X Shockwave Support FlashPlayer.exe"Added by the DELF-DRA WORM!"
X shoket svchs0t.exe"Added by the WOWPWS-E TROJAN!"
N ShopSafe ShopSafe.exe"Created by Orbiscom for MNBA (now Bank of America) - ShopSafe creates a temporary card number each time you make an online purchase"
N ShortKeys 99 SHORTKEY.EXE"ShortKeys from Insight Software Solutions - allows you to program keys with text strings"
U ShortKeys Lite shklite.exe"ShortKeys Lite from Insight Software Solutions
Y sHotKey sHotKey.exe"Special function key manager for Chicony keyboards - see here"
X Showbehind SHOWBEHIND.EXE"Advertisement display which can be stopped here"
X ShowFF ShowFF.exe"FFToolBar adware toolbar"
? ShowIcon_Justrams_USB Product Driver v2.12r012 shwicon.exe"Related to Just Rams USB product driver. Is it required?"
U ShowIcon_PNY_PNY Attaché shwicon.exe"PNY Attaché USB flash memory stick System Tray icon - shows when the device is plugged in"
? ShowIcon_SmartDisk Corporation_USB Card Reader v1.14e051 shwicon.exe"Card reader for memory cards from digital cameras. Is it required? "
U ShowLOMControl [strange symbol]"Note that there is a strange symbol in the command field and in logs it's shown as ""O4 - HKLM\..\Run: [ShowLOMControl] [strange symbol]"". Additional registry information for the entry is ""Reg_DWORD 0x00000001 (1)"". It means Show ""LAN on Motherboard"" Control. On systems where you can install an external LAN interface
X Showme Ruden.vbs"Added by the HANDLE-A VIRUS!"
U ShowWnd ShowWnd.exe"Found on Gateway computers (and maybe others) - see here. ""Showwnd is included with the Chicony keyboard software and is used by the software to stop the keyboard driver's taskbar entry from reappearing. It is not necessary to remove the keyboard software
U SHPC32 SHPC32.exePort monitor for Lexmark printers on a USB connection. Ties in with the Printer Control Program. Features like cancelling a print are unavailable if disabled
Y ShStatEXE SHSTAT.EXEPart of McAfee's VirusScan Enterprise corporate anti-virus and anti-spyware security tool
U Shutdownaware shutdownaware.exe"Loaded by the SWEEX 6-in-1 Media Card Reader to properly manage the reader while it is connected to your system"
U ShutDownPro ShutDownPro.exe"ShutDownPro - shutdown
X ShutDownWindows "Rundll32.exe UserExitWindows"
X ShutdownWithoutLjiasvt.exe [path to trojan]"Added by the BIFROSE.F BACKDOOR!"
X shv antit.exe"Added by the AGENT-JKU TROJAN!"
N Si Meter SIMETER.EXE"
X si91e44b "rundll32.exe si91e44b.dll EnableRunDLL32"
U SIA2006 SIA2006.exe"Part of Steganos Internet Anonym privacy software"
U SIAPRO6 sia.exe"Steganos Internet Anonym privacy software"
X SichererAntivirus pgs.exe"SichererAntivirus
X SichererSchutz pgs.exe"SichererSchutz
X SicherheitsTool SysRep.exe"SicherheitsTool
X Sicom Sicom.exe"Added by the NETLIP WORM!"
U SideACT SideACT.exe"SideACT organizer software"
U Sidebar Sidebar.exe"Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijacker"
N SIDEBAR dsidebar.exe"""Desktop Sidebar provides you with instant access to the information you most desire by grabbing data from your PC and the internet. The result is a dynamic visual display you configure and control"""
X SideGreen SideGreen.exe"SideGreen adware. File located in %Program Files%\SideGreen"
N SideWinderTrayV4 SWTrayV4.exeMS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs
U SightSpeed SightSpeed.exe"SightSpeed Video Chat - ""lets you connect with all your friends and family easily. Make video calls
N SigmaTel Audio setup.exe"Sigmatel audio driver"
N SigmaTel StacMon stacmon.exeInstalled with the drivers for a SigmaTel C-Major Audio card (on a Dell Inspiron 600m PC for example). Appears as though it can be disabled with no ill effects
N SigmatelSysTrayApp stsystra.exeSystem tray program for the Sigmatel Audio sound card. Often found on Dell computers
N SigmatelSysTrayApp sttray.exeSystem tray program for the Sigmatel Audio sound card. Often found on Dell computers
U SigX sigx.exe"SigX is a ""dynamic signature image generated based on whatever data your computer sends it though our SigX program. It can display your current Mp3
U SigXC SigX.exe"SigX is a ""dynamic signature image generated based on whatever data your computer sends it though our SigX program. It can display your current Mp3
X SilentSoftech [worm filename]"Added by the SILLYFDC-BL WORM!"
X SilentSoftech SilentSo.exe"Added by the AUTORUN-ANU WORM!"
N Simcast SimcastAlerts.exe"Simcast is a free service that allows you to subscribe to information on a large variety of topics. Alerts will appear on your desktop when a channel that you have subscribed to has something to say"
N Simple Star PhotoShow Media Manager mssysmgr.exe"Simple Star PhotoShow photo editing and organizing software
N Simplify Media SimplifyMedia.exe"Simplify Media media manager - ""enjoy songs from home while at work or from any WiFi location. Explore friends' music while they are online"""
U SimpLite-MSN SimpLite-MSN.exeRequired if you use the SimpLite add-on to MSN Messenger (SimpLite adds encryption to the instant messaging service)
X sInErA .exe"Added by the SILLYFDC-AB WORM!"
X Singapore singapore.exe"Adds a blue crescent to the taskbar and when double-clicked displays an adult-content web-site. Also known to drop your internet connection and dial an international telephone number. See here for more information. Must be disabled in MSCONFIG before un-installing or it re-instates itself"
U Sinus 1054 data WLAN Manager Wifiusb.exeWireless management utility for the T-Com Sinus 1054 Data WLAN adapter
X sioco sioco.exe"Added by the AGENT-MOD TROJAN!"
N SipDiscount SipDiscount.exe"SipDiscount - internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
U SIPPS SIPPS.exeWeb.de Internet phone utility
U SiS (R) Compatible Super VGA SiSTray application sistray.exeSystem Tray access to display settings for Silicon Integrated Systems (SiS) based graphics chipsets. Located in %System%
X SiS 6326 Accelerator sis6326m.exe"Added by the MSIC BACKDOOR!"
U SiS Compatible Super VGA Keyboard Daemon keyhook.exe"Hotkey manager for Silicon Integrated Systems (SiS) based graphics chipsets - disable unless you use hotkeys"
X SiS Dns dnssvc.exe"Added by the DLOADER-UE TROJAN!"
N SiS KHooker khooker.exeSiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required
X SiS Mpc Service mpcsvc.exe"Added by the CIADOOR-CJ TROJAN!"
U SiS Tray sistray.exeSystem Tray icon for SiS based graphics. Located in %System%
U SiS Windows KeyHook keyhook.exe"Hotkey manager for Silicon Integrated Systems (SiS) based graphics chipsets - disable unless you use hotkeys"
X sis32 winsos.exe"Added by the QQPASS.IA WORM!"
Y SiS7012Utility SiSAudUt.exeSiS Corporation sound card driver
? SISAM10M SISAM10M.exe"??"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list