| Status | Autorun name | Command | Description |
| U | SDaemon | sdaemon.exe | PC Security from Tropical Software - "is the ultimate in computer security, offering multiple locking systems for the windows environment and internet. Lock files, monitor programs activities, even detect intruders!" |
| U | SDAutoLiveupdate | LiveUpdateSD.exe | Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here |
| X | SDAv | csnss.exe | Added by the SERFLOG.C WORM! |
| X | SDAv | svhost.exe | Added by the SERFLOG.C WORM! |
| X | sdchosts32 | vbdd.exe | Added by the RANKY.AG TROJAN! |
| U | SDClientMonitor | sdclientmonitor.exe | LANDesk® Management Suite software component |
| N | SDetect | SDetect.exe | ScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the "GO" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the "GO" button |
| X | sdfgsdfg | hey.exe | Added by the AGOBOT-OR WORM! |
| X | sdfsdfsdf | sp2update.exe | Added by a variant of the SPYBOT WORM! |
| X | sdfwfq | mxxcva.exe | Added by the SDBOT-QN WORM! |
| X | SDIN Adapter | sdin.exe | Added by the FORBOT-AP WORM! |
| ? | SDJobCheck | triggusr.exe | Part of CA Unicenter Software Delivery - manage software across various systems, from desktops and servers to PDAs and mobile phones, in a controlled and standardized way - is it required at startup? |
| X | SDK Codre Function22 | sdkimddprovment2.exe | Added by the SDBOT-YJ WORM! |
| X | SDK Core Component | sdkcore.exe | Added by the SDBOT-WC WORM! |
| X | SDK Core Function | sdkimprovment.exe | Added by the RBOT.BHL WORM! |
| X | SDK Core Function2 | sdkimprovment2.exe | Added by the SPYBOT.OGX WORM! |
| X | Sdk**.exe [* = random char] | Sdk**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | Sdk**32.exe [* = random char] | Sdk**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | SDKcore Update Components2 | SDKC0R3.exe | Added by the RBOT-ABA WORM! |
| X | SDKCprords | SDKc55rezzz.exe | Added by the RBOT.VD WORM! |
| X | sdkupdate22 | SDK0mCORE.exe | Added by the FORBOT-DT WORM! |
| X | SDKz0r | SDKc55rezzz2.exe | Added by the SDBOT-UN WORM! |
| ? | SDMSSplash | launcher.exe | Part of HP's Smart Desktop Management System - "Preloaded on select business desktops, SDMS features automatic remote backup and disaster recovery via secure offsite storage and helps detect and remove PC security threats." Is this just the "splash" screen shown when the program lauches and is it therefore required? |
| N | SDPhotoBar.exe | SDPhotoBar.exe | SmartDraw Photo (now FotoFinsh) - "organize, enhance, print, and share your photos. It's also a powerful graphic editor for creating images and web graphics" |
| X | SDR6_Check | udcsdr.exe | Part of the DriveCleaner rogue security software - not recommended, removal instructions here |
| X | SDR6V_Check | udcsdr.exe | Part of the DriveCleaner rogue security software - not recommended, removal instructions here |
| X | sdrss | sdrss.exe | Added by the SDBOT-SQ WORM! |
| U | sds20 | svchost.exe | InlookExpress logs keystrokes and captures screenshots. If you didn't install this yourself remove it. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\sds20 |
| X | SdScans** | stup_tmp.#32 | Added by the SDSCAN.A TROJAN - where ** are random upper case letters |
| U | SDTray | sdtray.exe | RSA Keon Web PassPort - software that allows organizations to use digital certificates in a Web-based environment to help ensure that their transactions are authentic, confidential and digitally signed |
| Y | SDTray | SDTrayApp.exe | System Tray access to an older version of Spyware Doctor antispyware from PC Tools |
| X | sdxsys32 | sdxsys32.exe | Added by the BROGGER-A TROJAN! |
| N | Seagate 2GHK2Q3E Product Registration | Seagate 2GHK2Q3E Product Registration.exe | LeaderTech's PowerREGISTER registration reminder for Seagate storage products |
| N | Seagate Product Registration | Seagate Product Registration.exe | LeaderTech's PowerREGISTER registration reminder for Seagate storage products |
| U | SeahawksScreenServer | SeahawksScreenServer.exe | Screensaver for the Seattle Seahawks NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supported |
| U | SeahawksScreenServerSvc | SeahawksScreenServer.exe | Screensaver for the Seattle Seahawks NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supported |
| U | sealmon | sealmon.exe | SealedMedia enables you to combine document protection and control with your existing applications - such as Microsoft Word, Microsoft Excel, Microsoft PowerPoint and Email |
| X | Search Bar | taskbar.exe | Added by the OPANKI-F WORM! |
| X | Search Defender | SearchDefender.exe | Installed by SpeedItUp without permission, along with PC-Checker. Detected by DrWeb as the STARTPAGE.ORIGIN TROJAN! |
| ? | Search Hook | srchhook.exe | ?? |
| X | Search Page | http://find.naupoint.com | Naupoint browser hijacker |
| U | Search Protection | SearchProtection.exe | "Yahoo! Search Protection will alert you if an attempt is made to change your default browser search engine from Yahoo!" |
| X | Search-Exe | SE.exe | Search-Exe hijacker |
| X | SearchAndDestroyMFC | Search And Destroy.exe | Search And Destroy rogue security software - not recommended, removal instructions here |
| X | SearchAndDestroyScheduler | SearchAndDestroy.exe | Search And Destroy rogue security software - not recommended, removal instructions here |
| X | SearchAndDestroyT | SearchAndDestroy.exe | Search And Destroy rogue security software - not recommended, removal instructions here |
| X | searchbar | vnmispoisn downloader.exe | SearchBarCash adware variant |
| X | SearchClick | [trojan filename] | Added by the AGENT-DWR TROJAN! |
| ? | SearchEngineProtection | SearchEngineProtection.exe | Installed with an older version of the Oberon Gamesbar from Oberon Media which is provided to "help fans of casual games have a quick and easy access to all the new games available to play. Part of Internet Explorer, the Gamesbar will keep your games at your fingertips." Powered by Google this probably protected the default search engine used |
| X | SearchEnhancement | scbar.exe | SCBar/SearchEnhancement foistware |
| X | SearchMP3 | rundll32.exe MSA64CHK.dll,DllMostrar | MatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% |
| X | searchnav | searchnav.exe | SearchNav adware - IEFeatures/Popnav variant |
| X | SearchNavVersion | searchnavversion.exe | SearchNav adware - IEFeatures/Popnav variant |
| X | SearchNet_Up | ServeUp.exe | SearchNet adware |
| U | SearchProtection | SearchProtection.exe | "Yahoo! Search Protection will alert you if an attempt is made to change your default browser search engine from Yahoo!" |
| X | SearchSetter | searchsetter[1].exe | Browser hijacker - redirecting to FindWhateverNow.com |
| X | SearchSettings | SearchSettings.exe | Vendio "Search Settings" foistware - reportedly installed without notice, see here and here |
| X | SearchSpy | SearchSpyMenu.exe | SearchSpy rogue spyware remover - not recommended, removal instructions here |
| X | SearchSquire[number] | SearchSquire[number].exe | SearchSquire adware |
| X | SearchUpgrader | SearchUpgrader.exe | Hijacker |
| X | Secboot | w32tm.exe | Added by the HAXDOOR.D TROJAN! |
| X | secboot | mszx23.exe | Added by a variant of the HAXDOOR.BC TROJAN! |
| X | secboot | vtd 16.exe | Added by the HAXDOOR-AE TROJAN! |
| X | secdrive.exe | secdrive.exe | Added by a variant of the SPYBOT WORM! See here |
| U | Second Copy 2000 | SecCopy.exe | Related to Second Copy? - a files/folders backup utility |
| U | SecondChance | sctray.exe | Power Quest Second Chance. Sets checkpoints for saving a backup copy of the registry to a disk so you can restore it if you have a crash |
| X | Secret | Secret.exe | Added by the DELF-LW TROJAN! |
| X | Secret-Crush | start.exe | Hijacker that may reset your browser's home page and/or search settings to point to undesired sites |
| U | SECRETMAKER | secretmaker.exe | Secretmaker is a combination of eight privacy-defending programs, including Spam Fighter Pro, Worm Hunter, Pop-Up Killer, Banner Blocker, Cookie Eraser, Privacy Protector, History Cleaner, and Garbage Cleaner |
| U | SecretSmileys | ss.exe | "Secret Smileys is an add-on for AIM that provides users access to 1000's of new Smileys that can be viewed by anyone using a current version of AIM. Secret Smileys also adds other features such as logging of IM conversations, and it gets rid of that annoying advertisement on your buddy list window" |
| X | secserv.exe | secserv.exe | Detected by Panda as an EasySearch adware variant. Note - EasySearch modifies the Internet Explorer settings and may download programs onto the infected computer |
| X | secsvc32 | secsvcnt.exe | Added by the GLOBAL PATROL TROJAN! |
| U | Secsys | Secsys.exe | UltraSoft Key Interceptor surveillance software - uninstall this unless you put it there yourself! |
| U | SecurDisc | NBHGui.exe | SecurDisc support for the Nero InCD packet writing utility. "SecureDisc includes special protection properties, such as data integrity, rebuilding, encryption and duplication protection". If you don't use InCD or your optical drive doesn't support SecureDisc you can disable this |
| X | secure | [random].exe | DealHelper adware |
| X | secure | svshost.exe | Added by the RBOT-AFO WORM! |
| X | Secure AntiVirus Pro | av.exe | Secure AntiVirus Pro rogue security software - not recommended, removal instructions here |
| X | secure socket layer | wins32a.exe | Added by an IRCBOT TROJAN! |
| X | Secure Socket Layer Certification | sslcert.exe | Added by the VANEBOT-AN WORM! |
| X | Secure System | integitor.exe | Added by the AGOBOT.ACI WORM! |
| X | Secure32 | Shell32.com StartUp | Added by the BRONTOK-CJ WORM! |
| X | Secure64 | Regedit32.com StartUp | Added by the BRONTOK-CJ WORM! |
| N | SecureClean4RegManager | scregmanager4.exe | WhiteCanyon SecureClean 4 disk cleaner - clean hard drive data, MRUs, temp files and more. Can be started manually |
| N | SecureClean4Tray | sctray4.exe | WhiteCanyon SecureClean 4 disk cleaner - clean hard drive data, MRUs, temp files and more. Can be started manually |
| X | SecureCleaner | SecureCleaner.exe | SecureCleaner rogue spyware remover - not recommended, removal instructions here |
| N | SecureCleanIEClean | SCIEClean.exe | SecureClean - scans your system for hidden temporary files, deleted email messages, Internet histories and caches |
| X | SecureExpertCleaner | sec.exe | Secure Expert Cleaner rogue privacy program - not recommended, removal instructions here |
| X | SecureFighter | SecureFighter.exe | SecureFighter rogue security software - not recommended, removal instructions here. A member of the WiniGuard family |
| U | SecureItPro | Secureitpro470p.exe | SecureIt Pro - lock your computer when you're not there, to stop malicious users from accessing your desktop |
| X | SecureKeeper | SecureKeeper.exe | SecureKeeper rogue security software - not recommended, removal instructions here. A member of the AntiAID family |
| X | SecureLogin | Mslg32.exe | Added by the REDZED WORM! |
| U | SecureOnlineAccountNumbers | SOAN.exe | Related to Secure Online Account Numbers by Discover(R) Card from Orbiscom Ltd. Secure and innovative payment solutions |
| X | SecurePcAv | SecurePcAv.exe | SecurePcAv rogue security software - not recommended, removal instructions here. A member of the AntiAID family |
| X | SecurePCCleaner | GDC.exe | SecurePCCleaner rogue privacy tool - not recommended, removal instructions here. A member of the PCPrivacyTool family |
| U | SecurePCSolutionsBootCheck | BootCheck.exe | 1 Click Fixer PLUS from Secure PC Solutions "takes the guesswork out of locating and solving problems in the Windows registry" |
| X | securer | syshost.exe | Added by the BDOOR-DU BACKDOOR! |
| X | secures23 | mssecure.exe | Added by the AGOBOT-ABY WORM! |
| X | SecureVeteran | SecureVeteran.exe | SecureVeteran rogue security software - not recommended, removal instructions here. A member of the WiniGuard family |
| X | SecureWarrior | SecureWarrior.exe | SecureWarrior rogue security software - not recommended, removal instructions here. A member of the WiniGuard family |
| X | Security | WindowsSecurityUpdate.exe | Added by a variant of the SDBOT WORM! |