Pc-processes > S > ADSL Geek
PC process registry
Find if your processes are spyware or a virus:[A][B][C][D][E][F][G][H][I][J][K][L][M][N][O][P][Q][R][S][T][U][V][W][X][Y][Z]Results for S:
| Process Name | Status | Startup Item Name | Comments |
|---|---|---|---|
| system32.exe | X | Added by the AGOBOT-KU WORM! Note - has a blank entry under the Startup Item/Name field | |
| svchost.exe | X | Added by the DELF-UX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder. Note - has a blank entry under the S | |
| services.exe | X | SystemBoot | Added by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a HelpHelp subfolder of the Windows or Winnt folder |
| services.exe | X | WinCheck | Added by the SOBER-S WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "ConnectionStatusMicrosoft" subfolder of the Windows or Winnt fo |
| services.exe | X | Windows | Added by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "WinSecurity" subfolder of the Windows or Winnt folder |
| services.exe | X | WinStart | Added by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Connection WizardStatus subfolder of the Windows or Winnt f |
| smss.exe | X | winsystem.sys | Added by the SOBER.K TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a msagentwin32 subfolder of the Winnt or Windows folder |
| Shania.vbs | X | (Default) | Added by the SHANIA BACKDOOR! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank |
| spolsvr2.exe | X | (Default) | Added by the EVILSOCK.10 TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank |
| Systrsy.exe | X | (Default) | Added by the CDTRAY TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank |
| syspol.exe | X | (Default) | Added by the DREMN-B TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank |
| SP00Lsv32.pif | X | (L4r1$$4) (4nt1) (V1ruz) | Added by the ASSIRAL.B WORM! |
| secctr.exe | X | *Security Center | Added by the SDBOT.BRO WORM! |
| statemgr.exe | Y | *StateMgr | Windows ME default for System Restore. Do NOT disable! |
| systemupd.exe | X | *WindowsAudio | Added by the AGENT-TH WORM! |
| svhost.exe | X | .mscsbl | Added by the CMQ TROJAN! |
| sysmon32.exe | ? | .NET config | ?? |
| smss.exe | X | .nvsvc | Added by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup! |
| smssb.exe | X | .nvsvcb | Added by the BOXED.CG TROJAN! |
| services.exe | X | .Prog | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| system32THotkey.exe | U | 00THotkey | For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev |
| svchost.scr | X | 1 | Added by the BANCOS.X TROJAN! |
| sysockeu.exe | X | 1029BB4B-16A9-4E77-AA3D-96930BD68EEC | Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
| sxgnsvuxct.exe | X | 1234klsjdc uiar924c af | Detected by McAfee as the FAKEALERT-AM TROJAN! See here |
| sysvtypkbjx.exe | X | 1234klsjdc uiar924c af | Detected by McAfee as the FAKEALERT-AM TROJAN! See here |
| stubinstaller****.exe [* = digit] | X | 180ClientStubInstall | 180Solutions adware related |
| SpyAgent4.exe | U | 1Srv32 | SpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC." |
| SpyBuddy.exe | U | 1Win32Cfg | SpyBuddy keystroke logger/monitoring program - remove unless you installed it yourself! |
| sysokuaw.exe | X | 2177F056-0AA6-4D6C-A944-13F71F341C29 | Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
| slsorve.exe | X | 27 | Added by the SLSORVE-A TROJAN! |
| svchost.exe | X | 333 | Added by the JD-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This one is located in a "Syswm1i" directory |
| Ska.exe | X | 666 | Added by the PIPES TROJAN! |
| sysoghcx.exe | X | 756349DC-6D9E-4F2A-9B24-269661F073C3 | Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
| sysodkcs.exe | X | 852EBF20-A95D-4F1F-B9C2-B2CD24350F3E | Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
| sys.exe | X | AAMSFree702 | Added by the BACKDOOR-CPC TROJAN! |
| snddrv.exe | X | Ac97Sound | Detected by Sophos as the SILLYFDC-A TROJAN! |
| schedhlp.exe | U | Acronis Scheduler Helper | Part of Acronis True Image backup software. Co-operates with the "schedul2.exe" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images |
| schedhlp.exe | U | Acronis Scheduler2 Service | Part of Acronis True Image - backup software. Co-operates with the "schedul2.exe" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images |
| systray32.exe | X | ActiveDesktop | Added by the DABOOM WORM! |
| svcss.exe | X | ActiveXUpdate | Added by a variant of the DEDLER.C TROJAN! |
| svchost.scr | X | Administrator | Added by the NOVACAL TROJAN! |
| sysfile.vbs | X | AdminSoft | Added by the STARGRUB-A WORM! |
| sysconfig.exe | X | Adobe | Added by an unidentified WORM or TROJAN! |
| sysbat32.exe | X | Adobe | Added by the LOWZONES.T TROJAN! |
| sysmsn.exe | X | AdobeReaderPros | Added by the RBOT-BGH WORM! |
| services.exe | X | AdRotator.Application | FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in an "Inetsrv" subfolder |
| stopAds.exe | X | AdsBlocker | Reported as DILAER.DW by NOD32 |
| SystemtrayV100B.exe | ? | ADSLSYSTEMTRAY | Apparently Annex A ADSL modem related. What does it do and is it required? |
| sysupudt.exe | X | AdUpdater | Unidentified adware downloader/updater |
| schedules.exe | X | AdwareKiller_schedules | EAdwareKiller spyware remover - not recommended, see here |
| scchost.exe | X | Alive SYstem | Added by the TOFDROP-B TROJAN! |
| scchostc.exe | X | Alive SYstem | Added by the TOFDROP-B TROJAN! |
| stswin.exe | U | All Aboard Status | All Aboard! Internet Connection Sharing status icon |
| svchost.exe | X | alpha | Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
| SecurityCenter.exe | N | Aluria Security Center | Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here |
Most of the data for these PC Process lists are kindly provided to the Internet community by the awesome guys from http://www.sysinfo.org/
"Y" - Normally leave to run at start-up"N" - Not required or not recommended - typically infrequently used tasks that can be started manually if necessary
"U" - User's choice - depends whether a user deems it necessary
"X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
"?" - Unknown
Variables:
%System%
- refers to the System folder; by default this is C:\Windows\System (9x/Me), C:\Winnt\System32 (NT/2K), or C:\Windows\System32 (XP/Vista)
%Windir%
- refers to the Windows installation folder; by default this is C:\Windows (9x/Me/XP/Vista) or C:\Winnt (NT/2K)
%UserProfile%
- refers to the current user's profile folder; by default this is C:\Documents and Settings\ (NT/2K/XP) or C:\Users\ (Vista)
%ProgramFiles%
- refers to the Program Files folder; typically the path is C:\Program Files