| Status | Autorun name | Command | Description |
| X | SvcH0st | msnexploren.exe | Added by the TACTSLAY.B TROJAN! |
| X | SvcH0st | sdhch.exe | Added by the TACTSLAY.B TROJAN! |
| X | SVCH0ST.EXE | SVCH0ST.EXE | Added by the BANCBAN-HT TROJAN! |
| X | SVCH0TS | sp00lvs.exe | Added by the LINEAGE-AZ TROJAN! |
| X | svchast | svchast.exe | Added by the LINEAGE-AV TROJAN! |
| X | svchctrl | svchctrl.exe | Added by the NURECH TROJAN! |
| X | svchos | svchos.exe | Added by the EZIBOT-B TROJAN! |
| X | svchosd | [path to trojan] | Added by the BANCOS-BCX TROJAN! |
| X | SVCHOSI | SVCHOSI.EXE | Added by the VBBOT-AA WORM! |
| X | SVCHOST | scvhost.exe | Added by the MYTOB.E or MYTOB.G WORMS! |
| X | SVCHOST | taskgmr.exe | Added by the MYTOB.F or MYTOB.H WORMS! |
| X | svchost | olehelp.exe | Added by the BOOKMARKER.G TROJAN! |
| X | SVCHOST | updater32.exe | Added by the RANTS.A WORM! |
| X | SVCHOST | SPOOLSV.EXE | Added by the BAITAP-A WORM! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir% |
| X | SvcHost | svchost32.exe | Added by the AGOBOT-TM WORM! |
| X | svchost | svchost.exe | Added by the BANCBAN-HL TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\config |
| X | SVCHOST | MDM.EXE | Added by the LCJUMP-A WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or %System% (Me only). This one is located in %Windir% |
| X | svchost | [path to explorer.exe] | Added by the UNREAL-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! |
| X | svchost | rundll16.exe | Added by the STARTPA-PB TROJAN! |
| X | Svchost | svchost.exe | Added by the ADCLICK-AM TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Internet Explorer |
| X | svchost | svchost.exe | Added by the BDOOR-ES BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "Microsoft" subfolder |
| X | svchost | svchost.exe | Added by the DLOADER-EV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles% |
| X | svchost | winhelp.exe | Added by the GAOBOT.GEN!POLY WORM! |
| X | Svchost | svchots.exe | Added by the RBOT.ADK WORM! |
| X | svchost | ying.exe | Constructor VC2000 malware |
| X | svchost | inetinfo.scr | Added by the ODELUD WORM! |
| X | SVCHOST | svchost64.exe | Added by the STARTP-G TROJAN! |
| X | svchost | svchost.com | Added by the BANLOA-ABL TROJAN! |
| X | svchost | win.exe | Added by the VBSAUTO-A WORM! |
| U | svchost | svchost.exe | Infine Keylogger surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup. This one is located in an "svc" subfolder |
| X | svchost | logon.exe | Added by the SLEGON WORM! |
| X | svchost | svcst.exe | Added by the AGENT-LIL WORM! |
| X | svchost | svchost.exe | Added by the VB-EOK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "MsDtds" sub-directory |
| X | svchost | windowsrx.exe | Added by the AGOBOT-MZ WORM! |
| X | SVCHOST | SERVlCES.EXE | Added by the DELF-LF BACKDOOR! Note that the filename has a lower case "L" in place of an upper case "i" |
| X | Svchost | winprint.exe | Added by the AGENT-PGT TROJAN! |
| X | svchost | conhost.exe | Added by variants of the BACKDOOR-EXI.GEN.E TROJAN! See examples here and here. Note - this is not the legitimate Microsoft Windows 7 process with the same filename which is used to host the cmd.exe console window and is located in %System%. This one is located in %AppData%\Microsoft |
| X | svchost | svchost.exe | 2Search adware. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\2search |
| X | Svchost | taskmmgr.EXE | Added by the AUTORUN-F WORM! |
| X | SVCHOST | svchost.exe | System1060 homepage hi-jacker. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\System1060 |
| X | svchost | svchost.exe | Added by many TROJANS amd WORMS, such as MORB or TARNO. Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup! |
| X | SVCHOST | mrowyekdc.exe | Added by the GOTORM WORM! |
| X | svchost | Svch0st.exe | Added by the GRAYBIRD and GRAYBIRD.B TROJANS! Note - the filename has the digit 0 rather then the uppercase "o" |
| X | svchost | [path to trojan] | Added by the HAZZER TROJAN! |
| X | svchost | ADMAGIC.EXE | Added by the SMIBAG WORM! |
| X | Svchost | winhost.exe | Added by the LOLAWEB.A TROJAN! |
| X | Svchost | svchost.exe | Added by the MOZE-A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | SVCHOST | var.txt.exe | Added by the LDPINCH.C TROJAN! |
| X | Svchost | svchosl.pif | Added by the INZAE.A or INZAE.B WORMS! |
| X | svchost | [path] SETUP.EXE | Added by the SETCLO WORM! |
| X | svchost Agent | svchost.exe | Added by the AUTORUN-DB WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "28463" sub-folder |
| X | svchost connection monitor | svchost32.exe | Added by a variant of the SDBOT WORM! |
| X | SVCHOST Generic application | svchost.exe | Added by the DAEMONI-K TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | svchost Netware Manager | svchost.exe | Added by the EXVID.A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | SVCHost Protocol32 | scvhost32.exe | Added by a variant of the IRCBOT TROJAN! |
| X | Svchost Service | svchost.exe | Added by the VB-DVQ WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\help |
| X | Svchost Windows Remote Services | svhost.exe | Added by the IRCBOT-IV WORM! |
| X | svchost.exe | svchost32.exe | CoolWebSearch Svchost32 parasite variant |
| X | SVCHOST.EXE | SVCHOST.EXE | Added by the WRMSCAN-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | svchost.exe | [path to executeable] | Added by the BANKER-MO TROJAN! |
| X | svchost.exe | svchost.exe | Added by the ZAPCHAS-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "drivers" subfolder |
| X | svchost.exe | swchost.exe | Added by the SADELPHI-A TROJAN! |
| X | svchost.exe | svchost.exe | Added by the VIRUT.CF WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "3361" subfolder |
| X | SVCHOST.EXE | svchost.exe | Added by the SILLYFDC.BBI WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "Conf" sub-directory |
| X | svchost.exe | svcnost.exe | Added by the MISLEAD-A TROJAN! |
| X | svchost.exe | csrsc.exe | Added by the BUZUS.AAUP TROJAN! |
| X | svchost1 | svchost1.exe | Added by the AGOBOT.ZZ WORM! |
| X | SVCHost2 | svchost2.exe | Added by the RBOT.BLC WORM! |
| X | SvcHost32 | svchost32.exe | Added by the MIMAIL.I or MIMAIL.J WORMS! |
| X | svchost32.exe | svchost32.exe | Added by the ASSASIN.20B BACKDOOR! |
| X | svchost64 | svchost64.exe | Added by the SDBOTER.G VIRUS! |
| X | svchosta | svchosta.exe | Added by the SNIFFER-I TROJAN! |
| X | svchostb | svchostb.exe | Added by the SNIFFER-J TROJAN! |
| X | SvcHostDHCP | svchost32.exe | Added by the ASSASIN.20B BACKDOOR! |
| X | svchostdll.scr | svchostdll.scr | Added by the BANCBAN-FM TROJAN! |
| X | svchostn.exe | svchosta.exe start4dalife | Added by the ZOMBIE.SM BACKDOOR! |
| X | svchostn.exe | svchosth.exe start4dalife | Added by the ZOMBIE.SM BACKDOOR! |
| X | SvcHosto | v1rg1n.exe | Added by the AGOBOT-TK WORM! |
| X | svchostr | svchostr.exe | Added by an unidentified WORM or TROJAN! |
| X | svchosts | svchosts.exe | Added by the BANCBAN-DC or BANKER-ED TROJANS! |
| X | Svchosts | SCVHOST.EXE | Added by the AGOBOT-RQ BACKDOOR! |
| X | svchosts.exe | svchosts.exe | Added by the AGOBOT-JN WORM! |
| X | svchosts.scr | svchosts.scr | Added by the BANCBAN-DQ TROJAN and variants! |
| X | SVCHOT | SVCHOT.exe | Added by the QQROB-U TROJAN! |
| X | svchst | svchst.exe | Added by the KBROY-C TROJAN! |
| X | svcinfo | svcinfo.exe | Added by the CRYPTER.A TROJAN! |
| X | Svclhost | svcchost.exe | Added by an unidentified WORM or TROJAN! |
| X | SvcManager | restore3.exe | Added by the AGENT-DSS TROJAN! |
| X | SvcManager | [path to trojan] | Added by the ZALON-A BACKDOOR! |
| X | SvcManager | mdmex2.exe | Added by the ZALON-B BACKDOOR! |
| U | svcmon | svcmon.exe | PersonInspect surveillance software. Uninstall this software unless you put it there yourself |
| X | Svcnost.exe | svcnost.exe | Added by the SELEX.B WORM! |
| X | Svconr | Svconr.exe | WaveRevenue-lBann adware |
| X | Svcphpwin | sslphp32.exe | Added by the AGOBOT-ABR WORM! |
| X | svcroot | svcroot.exe | Added by the KEYLOG-AC TROJAN! |
| X | svcroot | xffanl.exe | Added by the AGENT-BMF TROJAN! |
| X | svcs32 | svcs32.exe | Added by the AGENT-VE MALWARE! |
| X | svcshare | winampXP.exe | Added by the FUJACKS-J VIRUS! |
| X | svcshare | spoclsv.exe | Added by the FUJACKS-A VIRUS! |
| X | svcshare | CTMONTv.exe | Added by the FUJACKS-AJ WORM! |