| Status | Autorun name | Command | Description |
| X | Start Upping | taskmrg.exe | Added by the RBOT-MA WORM! |
| X | Start Upping | SVCHOSTES.EXE | Added by the RBOT-NB WORM! |
| X | Start Uppings | svcchosts.exe | Added by the SDBOT.VY WORM! |
| X | Start Uppings | mssupdate.exe | Added by a variant of the RBOT WORM! |
| N | Start Wingman Profiler | lwtest.exe | Logitech Wingman software required to operate Logitech joysticks and gamepads. Unless you're a hard-core gamer, it's best to leave it unchecked |
| N | Start Wingman Profiler | LWEMon.exe | Part of Logitech Gaming Software (formerly Wingman Software) for their range of game controllers. Starts the profiler (button configuration) and loads the last used profile at start-up - including System Tray access. Unless you're a hard-core gamer it's best to leave it disabled and load when needed |
| X | Start Xp Setup | msxp.exe | Added by the RBOT.AKK WORM! |
| U | Startacc | startacc.exe | Launches Webroot's Accelerate 2000 software that "speeds up your Internet connection by up to 300%". Leave enabled if you find it improves internet connection |
| N | StartCCC | CLIStart.exe | Puts the ATI Catalyst Control Center Icon/Shortcut on the System Tray - available via Start → Programs |
| X | startdrv | startdrv.exe | Added by the DROPRK-A TROJAN! |
| U | StartEAK | StartEAK.exe | Easy Access Button Support for Compaq PCs. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keys |
| U | StartEase | StartEase.exe | StartEase from PC Magazine - application launcher that managed programs in the Windows Start menu into an A-to-Z menu structure |
| X | startemdoit | [path to trojan] | Added by the DLOADR-AVP TROJAN! |
| X | Starter | scvhosting.exe | Added by the SDBOT.RU WORM! |
| X | starter | scvhostingg.exe | Added by the FORBOT-FB WORM! |
| X | starter | iexplore.exe | Added by the FORBOT-DU WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
| U | StartFoxie | StartFoxie.exe | Foxie Suite from Softonic International. "This suite of free tools comes in the form of an Internet Explorer add-on and includes a mix of powerful security enhancements" |
| X | Starting up | wvsvc.exe | Added by the RBOT-NF WORM! |
| X | startkey | svcmgr.exe | Added by the HIPPER-B TROJAN! |
| X | startkey | update.exe | Added by the BIFROSE-DG TROJAN! |
| X | startkey | XMCHAI.EXE | Added by the BIFROSE-AO TROJAN! |
| X | startkey | explore32.exe | Added by the BDOOR-MT BACKDOOR! |
| X | startkey | CKOTS.exe | Added by the BIFROSE-HM TROJAN! |
| X | StartKey | pligde.exe | Added by the BIFROSE.E TROJAN! |
| X | startkey | RunWinRaR.exe | Added by a variant of the BIFROSE-LV TROJAN! |
| X | startkey | Mysia.exe | Added by the CEP TROJAN! |
| X | startkey | explorer.exe | Added by the BCKDR-MLD BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System% |
| X | startkey | furzi.exe | Added by the BIFROSE-OK TROJAN! |
| X | startkey | krnl.exe | Added by the BIFROSE-S TROJAN! |
| X | startkey | royale.exe | Added by a variant of the SDBOT WORM! |
| X | startkey | rtfmsv.exe | Added by the EDEPOL-C TROJAN! |
| X | startkey | scvhost.exe | Added by the BIFROSE-PM TROJAN! |
| X | startkey | server.exe | Added by the BIFROSE-DB TROJAN! |
| X | startkey | win32i.exe | Added by the BIFROSE-R TROJAN! |
| X | startkey | winampXP.exe | Added by the BIFROSE-OY TROJAN! |
| X | startkey | svchost32.exe | Added by a variant of the SDBOT WORM! |
| X | startkey | winlogin.exe | Added by the BIFROSE-PM TROJAN! |
| X | startkey | antivir.exe | Added by the BIFROSE-TO TROJAN! |
| X | startkey | svchost.exe | Added by the AGENT-FPL TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | StartKey | msnmsie.exe | Added by the BIFROSE.M BACKDOOR! |
| N | startl.exe | startl.exe | Lingocom LingoWare - translates any application into your language |
| ? | StartMen Application | MUIStartMenu.exe | Part of various video and audio utilities from CyberLink - including (but not limited to) LabelPrint, Power2Go, DVD Suite, PowerProducer and PowerDirector. The exact purpose of this entry is unknown at present but it unloads from memory once run. The command line varies depending upon the product |
| X | StartMenu | deamon.exe | Added by the TACTSLAY.C TROJAN! |
| X | StartMenu | msgaol.exe | Added by the TACTSLAY.C TROJAN! |
| X | StartMenu | s_menu.exe | Added by the TACTSLAY.C TROJAN! |
| X | StartMenu | browse.exe | Added by the DROWSY-C TROJAN! |
| X | startpage | startpage.exe | Browser hijacker - redirecting to pages2start.com |
| U | STARTPAGE | start1.exe | NoSpy.org - prevents spyware from changing your startpage and other browser properties. The start1.exe file is located in a NOSPY.ORG folder |
| X | StartReplySystem | loadnewmessage.exe | Added by the HIDAGENT-B WORM! |
| U | StartSecurDoc | SDPin.exe | SecurDoc from WinMagic Inc - "Provides full disk encryption to protect sensitive information stored on laptops, desktops and PDAs" |
| U | StartStop | STARTSTOP.EXE | StartStop from TFI Technology - startup manager |
| U | StartSurfing | STARTS.exe | Start Surfing allows you to protect your privacy while surfing and searching the Internet by acting as a "filter" between you and the website you are visiting. Startsurfing acts as your shield from Pop Up Windows, Mouse Traps, Window Resizing, and scripts that attempt to record your personal information. Available via Start -> Programs |
| N | Startup | ?? | Related to an Iomega drive |
| X | Startup | WinlogonStartup | Unidentified malware |
| X | Startup | mirc.exe | Added by the FLOOD-EU TROJAN! An uninstall option for mirc.exe can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as mIRC. This one puts 10 files in %Windir% |
| X | Startup | svchost.exe | Added by the AGENT-QCK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft |
| U | Startup Agent | startupagent.exe | Startup Agent by KillerSoftware - "provides constant monitoring of the startup areas during your Windows session. If Startup Agent has detected changes to your registry or startup files, you will be displayed with a Warning Message and asked if you want to remove those new changes" |
| X | Startup Configuration | [six character filename] | Added by the RBOT-ARV WORM! |
| X | Startup Configuration | wztoid.exe | Added by the RBOT-ASD WORM! |
| ? | Startup Launcher GUI | GUI.exe | Startup manager? |
| U | Startup Manager Scanner | StartupMonitor.exe | Startup-Mechanic Startup monitor - offers boot protection of your PC from harmful trojans, adult-dialers, and other scumware |
| Y | Startup Scan | sensor.exe | Part of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. Optionally scans the system boot area for programs trying to automatically execute before Windows loads and keeps a watch on some system files which are commonly patched (or replaced) by malware. Feature not supported on Windows 7/Vista systems. Also included by vendors who use the Quick Heal engine such as Omniquad and iQon |
| X | Startup Update | Cvshost.exe | Added by the GAOBOT.AO WORM! |
| X | StartupBin | iwnujdss.exe | Added by the SDBOT-XZ WORM! |
| X | StartUpDate | [path to trojan] | Added by the BIFROSE.F BACKDOOR! |
| U | StartupMonitor | StartupMonitor.exe | Mike Lin's StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu |
| X | StartupOption | loadsysdisk.exe | Added by the HIDAGENT-B WORM! |
| X | Startwd | rundll32.exe wd081025.dll,Hook | Added by the AGENT.DE TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wd081025.dll" file is found in %System% |
| X | startwin | startwin.exe | Added by the ANTIMAN.A WORM! |
| X | startwindowskeyuser | rundle2.exe | Added by the JAVAKILLER TROJAN! |
| N | Stat 'n' Perf | StatnPerf.exe | Stat 'n' Perf monitors your internet connection and displays information about sent and received bytes |
| X | StatBar | STATBAR.exe | StatBar (system status bar) allows you to quickly get an overview of your system's condition (memory, CPU, uptime, and much more). Due to the sheer number of resources (over 60%) consumed by this program, it is unsuitable for Windows 9x/Me |
| X | State Service | csrss.exe | Added by the DADOBRA-CP TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| U | StationPlaylistStudio | SPLStudio.exe | StationPlaylist Studio - "simple to use on-air broadcast playback software for the studio and/or DJ" for small to medium sized radio broadcasters, and internet webcasters |
| X | Statistics | statslist.exe | Added by the OPANKI-S WORM! |
| X | statloads | pgjd83sa.exe | Added by the SDBOT-UM WORM! |
| N | Status Monitor | BrMfcWnd.exe | Brother scanner status monitor - can be started manually |
| U | Status Monitor CLJ1500 | HPPOUMUI.exe | Status monitor for the HP Color LaserJet 1500 printer from Hewlett-Packard - for monitoring printer status, checking ink levels, etc |
| N | Status Monitor XE | ENGSS.EXE | The Xerox Document WorkCentre XE Series Status Monitor displays information about your printer and currently active or waiting print jobs. You can use it to control your printing environment and manage your printing operations. Available via Start -> Programs |
| ? | StatusClient | StatusClient.exe | Part of Hewlett Packard network printer drivers |
| ? | StatusClient 2.6 | StatusClient.exe | Part of Hewlett Packard network printer drivers |
| N | StatusView | StatusView.exe | Status View intra-office messaging |
| N | Stay Connected! | StayCon.exe | More than just a pinger, actually simulates online activity. Supports AOL, NetZero, MSN, ATT WorldNet, CompuServe and many other ISPs as well. Available via Start -> Programs |
| U | StayAlive | StayAlive.Exe | Part of RealSPEED - tweaking utility to speed-up your internet connection. Stay connected even after a period of inactivity on the net |
| U | StayAlive | sa.exe | StayAlive from TFI Technology. "This top-notch tool intercepts crashes when they happen, keeping your programs running so you can save your work." |
| ? | STBVision | STBVisn.exe | Related to the STB Velocity graphics card. What does it do and is it required? |
| N | STBWEBTV | STBWEBTV.EXE | Used to display TV on your PC |
| X | stcinstaller | id53.exe | Added by the SCTHOUGHT.L TROJAN! |
| X | STCLOA~1 | STCLOA~1.EXE | SecondThought adware |
| X | stcloader | stcloader.exe | SecondThought adware |
| Y | STCPO | STCPO.exe | Sophos Sweep antivirus software |
| X | StdAFX | stdafx.exe | Added by the DELBOT-AF WORM! |
| X | stdlib | [filename] | Added by the PERDA-E TROJAN! |
| Y | STDSB | STDSB.exe | Scrollbar driver for notebooks. If taken out of the Startup, it will not provide scrolling |
| U | Stealth Anonymizer 2.5 | stealth25.exe | Now named Stealther - proxy server agent that lets you travel the Internet with maximum possible privacy |
| X | stealth.dcom.exe | stealth.dcom.exe | Added by the THEALS.A WORM! |
| X | stealth.ddos.exe | stealth.ddos.exe | Added by the THEALS.A WORM! |
| X | stealth.exe | stealth.exe | Added by the THEALS.A WORM! |
| X | stealth.injector.exe | stealth.injector.exe | Added by the THEALS.A WORM! |
| X | stealth.stat.exe | stealth.stat.exe | Added by the THEALS.A WORM! |