X |
startemdoit |
[path to trojan] | "Added by the DLOADR-AVP TROJAN!"
|
X |
Starter |
scvhosting.exe | "Added by the SDBOT.RU WORM!"
|
X |
starter |
scvhostingg.exe | "Added by the FORBOT-FB WORM!"
|
X |
starter |
iexplore.exe | "Added by the FORBOT-DU WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
U |
StartFoxie |
StartFoxie.exe | "Foxie Suite from Softonic International. ""This suite of free tools comes in the form of an Internet Explorer add-on and includes a mix of powerful security enhancements"""
|
X |
Starting up |
wvsvc.exe | "Added by the RBOT-NF WORM!"
|
X |
startkey |
svcmgr.exe | "Added by the HIPPER-B TROJAN!"
|
X |
startkey |
update.exe | "Added by the BIFROSE-DG TROJAN!"
|
X |
startkey |
XMCHAI.EXE | "Added by the BIFROSE-AO TROJAN!"
|
X |
startkey |
explore32.exe | "Added by the BDOOR-MT BACKDOOR!"
|
X |
startkey |
CKOTS.exe | "Added by the BIFROSE-HM TROJAN!"
|
X |
StartKey |
pligde.exe | "Added by the BIFROSE.E TROJAN!"
|
X |
startkey |
RunWinRaR.exe | Added by a variant of the BIFROSE-LV TROJAN!
|
X |
startkey |
Mysia.exe | Added by the CEP TROJAN!
|
X |
startkey |
explorer.exe | "Added by the BCKDR-MLD BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
X |
startkey |
furzi.exe | "Added by the BIFROSE-OK TROJAN!"
|
X |
startkey |
krnl.exe | "Added by the BIFROSE-S TROJAN!"
|
X |
startkey |
royale.exe | "Added by a variant of the SDBOT WORM!"
|
X |
startkey |
rtfmsv.exe | "Added by the EDEPOL-C TROJAN!"
|
X |
startkey |
scvhost.exe | "Added by the BIFROSE-PM TROJAN!"
|
X |
startkey |
server.exe | "Added by the BIFROSE-DB TROJAN!"
|
X |
startkey |
win32i.exe | "Added by the BIFROSE-R TROJAN!"
|
X |
startkey |
winampXP.exe | "Added by the BIFROSE-OY TROJAN!"
|
X |
startkey |
svchost32.exe | "Added by a variant of the SDBOT WORM!"
|
X |
startkey |
winlogin.exe | "Added by the BIFROSE-PM TROJAN!"
|
X |
startkey |
antivir.exe | "Added by the BIFROSE-TO TROJAN!"
|
X |
startkey |
svchost.exe | "Added by the AGENT-FPL TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X |
StartKey |
msnmsie.exe | "Added by the BIFROSE.M BACKDOOR!"
|
N |
startl.exe |
startl.exe | "Lingocom LingoWare - translates any application into your language"
|
X |
StartMenu |
deamon.exe | "Added by the TACTSLAY.C TROJAN!"
|
X |
StartMenu |
msgaol.exe | "Added by the TACTSLAY.C TROJAN!"
|
X |
StartMenu |
s_menu.exe | "Added by the TACTSLAY.C TROJAN!"
|
X |
StartMenu |
browse.exe | "Added by the DROWSY-C TROJAN!"
|
X |
startpage |
startpage.exe | Browser hijacker - redirecting to pages2start.com
|
U |
STARTPAGE |
start1.exe | "NoSpy.org - prevents spyware from changing your startpage and other browser properties. The start1.exe file is located in a NOSPY.ORG folder"
|
X |
StartReplySystem |
loadnewmessage.exe | "Added by the HIDAGENT-B WORM!"
|
U |
StartSecurDoc |
SDPin.exe | "SecurDoc from WinMagic Inc - ""Provides full disk encryption to protect sensitive information stored on laptops |
U |
StartStop |
STARTSTOP.EXE | "StartStop from TFI Technology - startup manager"
|
U |
StartSurfing |
STARTS.exe | "Start Surfing allows you to protect your privacy while surfing and searching the Internet by acting as a "filter" between you and the website you are visiting. Startsurfing acts as your shield from Pop Up Windows |
N |
Startup |
?? | Related to an Iomega drive
|
X |
Startup |
WinlogonStartup | Unidentified malware
|
X |
Startup |
mirc.exe | "Added by the FLOOD-EU TROJAN! An uninstall option for mirc.exe can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as mIRC. This one puts 10 files in the Windows or Winnt folder"
|
X |
Startup Configuration |
[six character filename] | "Added by the RBOT-ARV WORM!"
|
X |
Startup Configuration |
wztoid.exe | "Added by the RBOT-ASD WORM!"
|
? |
Startup Launcher GUI |
GUI.exe | "Startup manager?"
|
U |
Startup Manager Scanner |
StartupMonitor.exe | "Startup-Mechanic Startup monitor - offers boot protection of your PC from harmful trojans |
Y |
Startup Scan |
Sensor.EXE | "AntiVirus Quick Heal - scheduling agent"
|
X |
Startup Update |
Cvshost.exe | "Added by the GAOBOT.AO WORM!"
|
X |
StartupBin |
iwnujdss.exe | "Added by the SDBOT-XZ WORM!"
|
X |
StartUpDate |
[path to trojan] | "Added by the BIFROSE.F BACKDOOR!"
|
U |
StartupMonitor |
StartupMonitor.exe | "Mike Lin's StartupMonitor |
X |
StartupOption |
loadsysdisk.exe | "Added by the HIDAGENT-B WORM!"
|
X |
Startwd |
"rundll32.exe wd081025.dll | Hook" |
X |
startwin |
startwin.exe | "Added by the ANTIMAN.A WORM!"
|
X |
startwindowskeyuser |
rundle2.exe | "Added by the JAVAKILLER TROJAN!"
|
N |
Stat 'n' Perf |
StatnPerf.exe | "Stat 'n' Perf monitors your internet connection and displays information about sent and received bytes"
|
X |
StatBar |
STATBAR.exe | "StatBar (system status bar) allows you to quickly get an overview of your system's condition (memory |
X |
State Service |
csrss.exe | "Added by the DADOBRA-CP TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
U |
StationPlaylistStudio |
SPLStudio.exe | "StationPlaylist Studio - ""simple to use on-air broadcast playback software for the studio and/or DJ"" for small to medium sized radio broadcasters |
X |
Statistics |
statslist.exe | "Added by the OPANKI-S WORM!"
|
X |
statloads |
pgjd83sa.exe | "Added by the SDBOT-UM WORM!"
|
N |
Status Monitor |
BrMfcWnd.exe | Brother scanner status monitor - can be started manually
|
U |
Status Monitor CLJ1500 |
HPPOUMUI.exe | "Status monitor for the HP Color LaserJet 1500 printer from Hewlett-Packard - for monitoring printer status |
N |
Status Monitor XE |
ENGSS.EXE | The Xerox Document WorkCentre XE Series Status Monitor displays information about your printer and currently active or waiting print jobs. You can use it to control your printing environment and manage your printing operations. Available via Start -> Programs
|
? |
StatusClient |
StatusClient.exe | Part of Hewlett Packard network printer drivers
|
? |
StatusClient 2.6 |
StatusClient.exe | Part of Hewlett Packard network printer drivers
|
N |
StatusView |
StatusView.exe | "Status View intra-office messaging"
|
N |
Stay Connected! |
StayCon.exe | "More than just a pinger |
U |
StayAlive |
StayAlive.Exe | "Part of RealSPEED - tweaking utility to speed-up your internet connection. Stay connected even after a period of inactivity on the net"
|
U |
StayAlive |
sa.exe | "StayAlive from TFI Technology. "This top-notch tool intercepts crashes when they happen |
? |
STBVision |
STBVisn.exe | "Related to the STB Velocity graphics card. What does it do and is it required?"
|
N |
STBWEBTV |
STBWEBTV.EXE | Used to display TV on your PC
|
X |
stcinstaller |
id53.exe | "Added by the SCTHOUGHT.L TROJAN!"
|
X |
stcloader |
stcloader.exe | "SecondThought adware"
|
X |
STCLOA~1 |
STCLOA~1.EXE | "SecondThought adware"
|
Y |
STCPO |
STCPO.exe | Sophos Sweep antivirus software
|
X |
StdAFX |
stdafx.exe | "Added by the DELBOT-AF WORM!"
|
X |
stdlib |
[filename] | "Added by the PERDA-E TROJAN!"
|
Y |
STDSB |
STDSB.exe | "Scrollbar driver for notebooks. If taken out of the Startup |
U |
Stealth Anonymizer 2.5 |
stealth25.exe | "Now named Stealther - proxy server agent that lets you travel the Internet with maximum possible privacy"
|
X |
stealth.dcom.exe |
stealth.dcom.exe | "Added by the THEALS.A WORM!"
|
X |
stealth.ddos.exe |
stealth.ddos.exe | "Added by the THEALS.A WORM!"
|
X |
stealth.exe |
stealth.exe | "Added by the THEALS.A WORM!"
|
X |
stealth.injector.exe |
stealth.injector.exe | "Added by the THEALS.A WORM!"
|
X |
stealth.stat.exe |
stealth.stat.exe | "Added by the THEALS.A WORM!"
|
X |
stealth.wm.exe |
stealth.wm.exe | "Added by the THEALS.A WORM!"
|
X |
stealth.worm.exe |
stealth.worm.exe | "Added by the THEALS.A WORM!"
|
N |
Steam |
steam.exe | "Valve Corporation's STEAM broadband game client. Steam is Valve's new way of getting games into your hands ASAP. Games like Half-Life |
X |
steam |
steam.exe | "Added by the RBOT-AJT WORM! Note - the file steam.exe will be found in %System% and is not associated with Valve Software's game client"
|
X |
SteFanie |
SteFanie.vbs | "Added by the STEFAN WORM! Note - make sure you check the hyperlink as this one copies it's self to numerous dirves and folders"
|
? |
stgclean |
w32main2.exe | "Related to IBM Standard Software Installer. What does it do and is it required?"
|
N |
Stickies |
Stickies.exe | "Stickies - ""lets you put yellow sticky notes on your Windows desktop |
N |
Sticky Notes |
stikynot.exe | "Microsoft Sticky Notes - virtual sticky notes tool from Windows Vista. This implementation of the popular yellow ""Post-It"" tool is part of the Tablet PC features and allows you to enter either handwriting (via a pen or mouse) or record a voice note. AVailable via Start → All Programs"
|
U |
Sticky Pad |
StickyPad.exe | "Sticky Pad from Green Eclipse. Place sticky notes on your desktop"
|
N |
StickyNote |
StickyNote.exe | Utility that allows you to put yellow "Post-It" type messages on your desktop. Available via Start -> Programs
|
U |
StillImageMonitor |
Stimon.exe | "Stimon.exe enables a USB still-image device (such as a scanner) to initiate data transfer to a program. For example |
X |
stisrv |
stisrv.exe | "Added by the RBOT.BQF WORM!"
|
X |
stlbdist |
"rundll32exe stlbdist.DLL | DllRunMain" |
X |
stlbupdt |
"rundll32.exe stlbupdt.DLL | DllRunMain" |
N |
STManager |
drst.exe | "Dr. SpeedTouch is some sort of diagnostics software which sends out information to a server which then relays the information back to the program to test the network to see if the SpeedTouch ADSL modem connection is working properly. Not required if connected via Ethernet (and probably USB). Can cause a slow down in Win2K - see here"
|
X |
stmha |
wkfxi.js | "Added by the SPETH WORM!"
|
X |
stonedrv |
stonedrv.exe | "Added by the COSIMA-K TROJAN!"
|
X |
StopingSpy |
StopingSpy.exe | "StopingSpy rogue security software - not recommended |
U |
StopSignSsTsMon |
"sstsmon.dll | VerifyStatus" |
U |
StopSignStatus |
stopsinfo.dll | "eAcceleration Stop-Sign security software related. Previously not recommended |
U |
STOPzilla |
Stopzilla.exe | "StopZilla! - pop-up killer"
|
U |
STOPzilla Service |
SZNTSVC.EXE | "StopZilla! - pop-up killer"
|
U |
StorageGuard |
sgtray.exe | "StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop) |
X |
StorageProtector |
SysRep.exe | "StorageProtector rogue system error and cleaning utility - not recommended |
U |
StormCodec_Helper |
StormSet.exe | "Storm Codec is a codec pack for Windows"
|
? |
STPMGR |
STPMGR.EXE | "Part of SafeTP which is transparent FTP security software. Does it need to be running permanently or can it be started manually via Start -> Programs"
|
X |
stratas |
xmconfig.exe | "Added by the RBOT-AHR WORM!"
|
X |
stratas |
lockx.exe | "Added by the SDBOT-ADD WORM!"
|
X |
Stratas |
ggfig.exe | "Added by the OPANKI.W WORM!"
|
X |
StreamAppliance |
wuauclt14.exe | "Added by the RBOT-GMB WORM!"
|
X |
StreamAppliance |
wuauclt16.exe | "Added by the RBOT-GME WORM!"
|
N |
Streamload Downloader |
SlDB.exe | "Downloader for MediaMax (was Streamload) - ""gives you a private and secure place to upload |
N |
Streamload Uploader |
StreamMgr.exe | "Uploader for MediaMax (was Streamload) - ""gives you a private and secure place to upload |
X |
Streams Drivers |
[trojan filename] | "Added by the RESTARTER.E TROJAN!"
|
U |
StreamZap Remote |
zremote.exe | "StreamZap PC Remote - control Windows Media Player |
U |
StrgSync.exe |
StrgSync.exe | "SimpleTech Inc's StorageSync backup software - backs up an entire PC |
X |
strkjhk |
sdflkj3.exe | "Added by an unidentified WORM or TROJAN - see here"
|
X |
strmsnmgrs |
msnxmsgrsc.exe | "Added by the SDBOT.JDR WORM!"
|
X |
strmsnmsgr |
msnmsgrs.exe | "Added by the RBOT-ACQ WORM!"
|
X |
strmsnmsgrs |
msnmsgrsc.exe | "Added by a variant of the RBOT WORM!"
|
X |
strmsnnms |
msnmegrs.exe | "Added by the SDBOT-YU TROJAN!"
|
X |
strmsnnrs |
msnmcgrs.exe | "Added by the RBOT-ACT TROJAN!"
|
X |
strmsoums |
msnmegrse.exe | "Added by the SDBOT-ZK TROJAN!"
|
X |
Strng32 |
strngbox.exe | "Added by the STRANO WORM!"
|
U |
StrokeIt |
strokeit.exe | "StrokeIt is an ""advanced mouse gesture recognition engine and command processor"""
|
X |
strpmon |
strpmon.exe | "Part of BugsDestroyer |
X |
strtas |
lock1.exe | "Added by the SDBOT-ADQ WORM!"
|
X |
strtas |
lockx.exe | "Added by the SDBOT-AEB WORM!"
|
X |
strtas |
l074.exe | "Added by the AGENT-II TROJAN!"
|