| Status | Autorun name | Command | Description |
| Y | ScanRegistry | Scanregw.exe | Scans the Win98/Me system registry and makes back-ups at start-up - important should the registry become corrupt. Located in %windir% |
| X | ScanRegistry | Scanregw.exe | Added by the STATOR WORM! Note - this is not legitimate ScanRegistry entry - which is a vital Windows file. The executable "Scanregw.exe" is located in %System%. Runs from the registry RunServices key as opposed to the Run key |
| X | ScanRegistry | N/A | Added by the DINOXI or DINOXI.B WORMS! |
| X | ScanRegistry | scanregw.exe | Added by the NYXEM-D WORM! Note - do not confuse this with the legitimate Windows process scanregw.exe which is always found in the Windows folder on Win9x/ME machines. This worm file is found in %System% |
| X | ScanRegistry | update.exe | Added by the DWNLDR-FZY TROJAN! |
| N | ScanSoft OmniPage SE 4.0-reminder | Ereg.exe ereg.ini | Registration reminder for Ominpage SE version 4 from Scansoft (now Nuance) |
| N | ScanSoft PaperPort 7 Registration Reminder | NAVBrowser.EXE | Registration reminder for PaperPort 7 from Scansoft (now Nuance) |
| N | ScanSoft PDF Professional 4-reminder | Ereg.exe Ereg.ini | Registration reminder for PDF Converter Professional version 4 from Scansoft (now Nuance) |
| X | ScanSpyware | Scanner.exe | ScanSpyware rogue security software - not recommended, removal instructions here. Also see here, here and here |
| X | ScanSpyware v3.2 | Scanner.exe | ScanSpyware rogue security software - not recommended, removal instructions here. Also see here, here and here |
| X | ScanSpyware v3.5 | Scanner.exe | ScanSpyware rogue security software - not recommended, removal instructions here. Also see here, here and here |
| U | ScanSys32 | sb32mon.exe | Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself! |
| X | scApp | scApp.exe | Added by the STANDO-E WORM! |
| X | scApp | suchost.exe | Added by the ACNATT.A WORM! |
| X | scApp | wmiprvse.exe | Added by the SILLYFDC-AW WORM! |
| N | SCardSvr | scardsvr.exe | Related to SmartCard readers and sometimes uses lots of system resources |
| X | SCardSvr | SCardSvr32.Exe | Added by the MOFEI.B WORM! |
| U | SCDEmuApp.exe | SCDEmuApp.exe | Related to PowerISO - CD/DVD image file processing tool |
| U | Schdlr32 | Schdlr32.exe | Scheduled backups for the NTI Backup Now archiving utility. If a backup job has been scheduled, this entry places an icon in the System Tray and will automatically load the main program and execute the backup at the set time - as long as the backup media is present |
| X | scheck45 | scheck45.exe | Related to unknown malware - hidden installer associated with it |
| X | schedl | schedl.exe | Added by the VB-DVW WORM! |
| U | schedm | schedm.exe | Part of Antivir PersonalEdition Classic anti-virus |
| X | ScheduIe | nrchk.exe | Premium rate adult content dialler |
| X | ScheduIr | msexploren.exe | Added by a variant of the SDBOT WORM! |
| X | ScheduIr | shch.exe | Added by a variant of the SDBOT WORM! |
| X | ScheduIr | svchst.exe | Added by a variant of the SDBOT WORM! |
| X | ScheduIr | winagent.exe | Added by a variant of the SDBOT WORM! |
| U | Schedule | Schedule.exe | Scheduler for Mercury Ez View TV Tuner Card |
| N | Scheduled Maintenance | Scheduled_Maintenance.exe | Scheduler for Iolo System Mechanic tweaking utility. It can cleans your registry and deletes temporary files at defined intervals. Available via Start -> Programs |
| X | Scheduler | expIorer.exe | Added by the TACTSLAY.A TROJAN! Note that the filename has a capital "i" in it |
| X | Scheduler | MSMSGS.EXE | Added by the HOSTBANK-A TROJAN! Note - this particular msmsgs.exe file is located in %System%\Config and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger |
| X | Scheduler | outIook.exe | Added by the TACTSLAY.A TROJAN! Note that the filename has a capital "i" in it |
| X | Scheduler | svcrhost.exe | Added by the TACTSLAY.A TROJAN! |
| X | Scheduler | svcshost.exe | Added by the TACTSLAY.A TROJAN! |
| X | Scheduler | winagent.exe | Added by the TACTSLAY.B TROJAN! |
| U | Scheduler | Scheduler daemon.exe | Tenebril GhostSurf or SpyCatcher related scheduler - you can schedule daily, weekly, monthly or one-time only cleanings |
| X | Scheduler | msnexploren.exe | Added by the TACTSLAY.B TROJAN! |
| X | Scheduler | sdhch.exe | Added by the TACTSLAY.B TROJAN! |
| X | Scheduler | svchst.exe | Added by the TACTSLAY.B TROJAN! |
| X | Scheduler Service | wsass.exe | Added by the LIOTEN.KX WORM! |
| U | scheduler_monitor | init_scheduler.exe | Scheduler for ReaConverter advanced image converter |
| U | scheduler_proxy Application | scheduler_proxy.exe | Found on IBM/Lenovo ThinkCentre/ThinkStation desktops and Thinkpad notebooks. Included with versions of ThinkVantage System Update (for software updates), Rescue and Recovery (backup and system recovery), Message Center Plus and maybe others. It's exact function isn't known but if disabled, the "plan updates" button in the IBM System Update software will no longer be available, though the software will continue run properly |
| X | SchedulerMgr | navchk.exe | Premium rate adult content dialer |
| X | Scheduling Agent | Scheduler.exe | Added by the SUBWOOFER TROJAN! Note - this is not the real MS Scheduling agent as the executable is incorrect |
| X | SchedulingAgant | MMTASK.EXE | Added by the YAB.A TROJAN! Note - this is not the legitimate MusicMatch Jukebox file which has the same filename and is normally located in %ProgramFiles%\Musicmatch\Musicmatch Jukebox. This one is located in %Windir% |
| U | SchedulingAgent | mstask.exe | MS Scheduling Agent in Win98/Me/2K - displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting, ScanDisk, etc. Required if you have regularily scheduled events such as weekly virus scans. Located in %System% and loads via the HKLM\RunServices registry key |
| U | SchedulingAgent | mstinit.exe | MS Scheduling Agent in WinNT - displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting, ScanDisk, etc. Required if you have regularily scheduled events such as weekly virus scans. Located in %System% and loads via the HKLM\Run registry key with "/firstlogon" appended. Can also appear in WinXP (based upon the number of examples in a Google search) and rarely in Win98/Me/2K but we haven't seen it |
| X | SchedulingAgent | N/A | Added by the DINOXI or DINOXI.B WORMS! |
| X | SchedulingAgent | mstask.exe | Added by unidentified MALWARE! Note - this is not the MS Scheduling Agent in Win98/Me/2K. This one also loads via the HKLM\RunServices registry key but is located in %System% on a WinXP machine - where a file of that name does not normally exist |
| X | SchedulingAgent | mstasks.exe | Added by the MSIC BACKDOOR! |
| N | SCHelper.exe | SCHelper.exe | Spyware Cease spyware remover. Previous versions were regarded as a rogue (see here) because it reported false or exaggerated system security threats but the latest version tested (6.5.1) has a new interface and produces no exaggerated threats on a clean system. Not recommended due to the past history |
| X | SchijfBewaker | SysRep.exe | SchijfBewaker, Dutch rogue system error and cleaning utility - not recommended. A member of the ErrClean family |
| X | SchijfControleur | GDC.exe | SchijfControleur Dutch rogue privacy tool - not recommended. A member of the PCPrivacyTool family |
| U | Schmaili | Schmaili.exe | Schmaili - insert animated smilies into your e-mail |
| X | schost | [path to trojan] | Added by the TJSERV.D TROJAN! |
| N | SchSvr | SchSvr.exe | WinScheduler is installed with Home Theater or WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs |
| Y | SCHWIZEX | SCHWIZEX.EXE | Part of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot |
| X | sck121 | helpsyss.exe | Added by a variant of the MAILBOT TROJAN! |
| N | sclauncher | sclauncher.exe | SimpleCenter digital media player/manager that supports the iPod, Sony PSP, Xbox 360, some of the Nokia N-series mobile phones and others |
| X | sclick | sclick.exe | Added by the FAKEALERT TROJAN! |
| X | ScManager | scman.exe | Added by the FORBOT-CW WORM! |
| X | scopedll | scopedll.exe | Added by a variant of the CRYPTER.C TROJAN! |
| N | Scotia OnLine Recovery | etdirrcv.exe | Scotia OnLine Security Software provided by Entrust for Scotiabank. Provides trusted secure access to Scotia OnLine Secure Web sites. *.* represents the version number. Now obsolete after Scotiabank modernised their login process |
| N | Scotia OnLine Security v*.* Recovery | etdirrcv.exe | Scotia OnLine Security Software provided by Entrust for Scotiabank. Provides trusted secure access to Scotia OnLine Secure Web sites. *.* represents the version number. Now obsolete after Scotiabank modernised their login process |
| X | scoupa | sincra.exe | Added by the SDBOT-ST WORM! |
| X | scoupas | [worm filename] | Added by the SDBOT.ALC WORM! The most common filename is "sincras.exe" |
| X | Scr | scr.scr | Added by the OPASERV.T WORM! |
| N | ScrapPad | Scrappad.exe | ScrapPad allows you to quickly and easily record notes, thoughts, messages, and just about anything you want. Use it like you use scrap paper |
| X | scrbmk | [path to trojan] | Added by the DLOADER-VP TROJAN! |
| U | Screen Calendar | scrcal.exe | Screen Calendar allows you to create custom desktop wallpapers with built in active calendar and scheduler |
| U | Screen Guard | launch.exe | Part of Access Denied security and privacy software |
| U | Screen Guard Message Scan | sgms.exe | Part of Access Denied security and privacy software |
| X | Screen Saver | scrnsaver.scr | Added by the RBOT-AGP WORM! |
| N | Screen Saver Control | FSScrCtl.exe | Screen saver control applet used by the "Stardust Screen Saver Toolkit", SolidWorks and Hubble Space Telescope screen savers (and possibly others). Lets you control your installed screensavers from a System Tray icon |
| N | ScreenHunter 4.0 Free | ScreenHunter.exe | "ScreenHunter 4.0 Free is a completely free screen capture software for you to easily take screenshots" |
| N | ScreenPrint32 | ScreenPrint32.exe | ScreenPrint32 screen capture software - can be launched manually |
| X | ScreenSaverPlus | rundll32.exe MSA64CHK.dll,DllMostrar | MatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% |
| X | ScreenView | ScreenView.exe | ScreenView spyware |
| ? | screxe | scruser2k.exe | ?? |
| ? | script | script.bat | Maybe associated with DOS on a Win9x machine |
| Y | ScriptBlocking | SBServ.exe | Part of the "Script Blocking" feature for older versions of Symantec's Norton AntiVirus which monitors script-based (ie, JavaScript, VB Script) viruses and alerts you of virus-like malicious behavior, stopping these viruses before they can infect your system. Loads via the registry "Run" or "RunServices" keys in 98/Me and as a service in XP |
| Y | ScriptSentry | Scriptsentry.exe | Script Sentry from Jason's Toolbox. Blocks malicious scripts and allows safe scripts to run. Only required if you want it to check the file associations it guards at startup. It will function regardlessly |
| U | Scroll-In-Mouse V2.0 | SCROLL.EXE | Toolkit for the Lynx-3D Net scroll mouse from QTronix. Required if you use the special features |
| X | scroller | fpapli.exe | CoolWebSearch parasite variant |
| X | scrss | scrss.exe | Added by the HACDEF-R TROJAN! |
| X | scrsvc | scrsvc.exe | Added by the AGENT-DS TROJAN! |
| X | ScrSvr | ScrSvr.exe | Added by the OPASERV WORM! |
| X | ScrSvrOld | [worm filename] | Added by the OPASERV WORM! |
| Y | Scsi | Scsi.exe | SCSI Miniport driver |
| X | scssrr.exe | Services.exe | Added by the VB-EMX TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | sctrlmgr | sescmgr.exe | Added by a variant of the DWNLDR-GAH TROJAN! |
| Y | SCTUINotify | SCTUINotify.exe | Part of Windows SteadyState, which is designed to make life easier for people who set up and maintain shared computers - enabling the system administrator to prevent users from making changes to the system configuration, windows desktop, restricting program access, etc. It's intended for shared user environments such as internet cafés, libraries and schools but can be used in any environment. This entry displays the timeout messages on the restricted computer/account - which warns users how long they have until automatic log-off when they log-in and when there are only 2 minutes left |
| X | scvhost | svzhost.exe | Added by a variant of the SPYBOT WORM! |
| U | scvhost | scvhost.exe | Wiretap surveillance software. Uninstall this software unless you put it there yourself |
| X | scvhost | scvhost.exe | Added by the AGOBOT-LI WORM! |
| U | scvhost | OverSpy.exe | OverSpy surveillance software. Uninstall this software unless you put it there yourself |
| X | scvhost loader | ixplore.exe | Added by the SDBOT-CY TROJAN! |
| X | scvhost.exe | scvhost.exe | Added by the LOHAV-N TROJAN! |
| X | Scvsrv32 | scvsrv32.exe | Added by the AGOBOT-PM BACKDOOR! |
| X | sd32info | sd32info.exe | Added by the CRYPTER.A TROJAN! |