| Status | Autorun name | Command | Description |
| X | Service ares | conmysys.exe | Added by the VBINJ-V WORM! |
| X | Service ares | tanga.exe | Added by the IRCBOT-AHO TROJAN! |
| U | Service Centre | launcher.exe | Management tool for the Open Networks iConnect series of products - as used by Australian ISP's such as iiNet and Hotkey |
| X | Service Cleaner | filen.exe | Added by the RBOT.BRH WORM! |
| X | Service Client | winsvcli.exe | Added by an unidentified WORM or TROJAN! See here |
| N | Service Connection | sccenter.exe | For Compaq PC's. Part of Backweb |
| N | Service Connection | bwtray.exe | For Compaq PC's. Part of Backweb |
| X | Service Control Manager | scm.exe | Added by the AGOBOT-GD BACKDOOR! |
| X | Service Controller | Csrrs.exe | Added by the GAOBOT.AO WORM! |
| X | Service Controller | service.exe | Added by the PREVERT TROJAN! |
| X | Service Defender | [random filename] | Added by a variant of the ZLOB TROJAN! See here |
| X | Service Drivers | msnpg.exe | Added by the RBOT.BMD WORM! |
| X | Service Drivers | PC.EXE | Added by the SDBOT-WK WORM! |
| X | Service Drivers | Compt.exe | Added by the RBOT-ZJ WORM! |
| X | Service Drivers | abl.exe | Added by the SDBOT-YX WORM! |
| X | Service Drivers | MSNMEssenger.exe | Added by a variant of the RBOT WORM! |
| X | Service Host | svchost.exe | Added by the TORVEL WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Service Host | [filename].exe | Added by the TORVEL.B WORM! |
| X | Service Host | spoolxx.exe | Added by the TORVEL WORM! |
| X | Service Host | svchost.exe | Added by the DAOSER-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\Services\{C922CCC4-CF61-4589-A0D1-828160704853} |
| X | Service Host | svchost.exe | Added by the DAOSER-C TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\Services\[random] |
| X | Service Host | svchosts.exe | PornCleanser spyware |
| X | Service Host | tm32.exe | Added by the POISON-AG TROJAN! |
| X | Service Host Driver | svchost.exe | Added by the HITON TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Service Host Manager | svchost.exe | Added by the AUTORUN-CQ WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile% |
| X | Service Host Process | spoolsvc.exe | Added by the GAOBOT.GEN!POLY WORM! |
| N | Service Manager | sqlmangr.exe | SQL Server Service Manager - provides tray access to SQL server, the server agent and MSDTC. Available via Start → Programs |
| X | Service Manager | SERVICEMGR.EXE | Added by the PASSMAIL-D VIRUS! |
| X | Service Manager | dxsound.exe | Added by the PROXY-GRIC TROJAN! |
| X | service manager | service.exe | Added by the DONBOMB.A TROJAN! |
| X | Service Manager | serv3manager.exe | Added by the SDBOT-AGO WORM! |
| X | Service Monitor | msnfilen.exe | Added by the RBOT-ALE WORM! |
| X | Service Monitor | javams32.exe | Added by the DELF-NK TROJAN! |
| X | Service Monitor | javams64.exe | Added by the SDBOT-AFO WORM! |
| X | Service Monitor | msnserve.exe | Added by the SPYBOT.YQW WORM! |
| X | Service Monitor | WinOcx.exe | Added by the RBOT-AQJ WORM! |
| X | Service Monitor | csnss.exe | Added by the RBOT.EEH BACKDOOR! |
| X | Service Monitor | filen.exe | Added by a variant of the RBOT WORM! |
| X | Service Monitor | winxpser.exe | Added by the RBOT-BDF WORM! |
| X | Service Noits | winservl.exe | Added by the MDROP-DKO TROJAN! |
| X | Service Nouts | winservi.exe | Added by the AGENT-RDZ TROJAN! |
| X | Service Pack | [various filenames] | Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe, common.pif, common.scr, Sexo.exe, Sexo.jpg.pif, ini_file__.pif, load_me__.tmp, msfile.pif, system_load_.pif or zipped.rar.pif |
| X | Service Pack 1 | [random filename] | Added by the VXGAME.Z TROJAN! Note - the filename is random - see the link. Typical examples are vexg6ame4.exe, vexga3me2.exe, vexga4m1et4.exe, etc |
| X | Service Pack 1 | SPY_NET_RAT.exe | Added by the AGENT-LRO TROJAN! |
| X | Service Pack 2 | SPY_NET_RAT.exe | Added by a variant of the AGENT-LRO TROJAN! See here and here |
| X | Service Pack DLL Runtime | spdll32.exe | Added by a variant of the RBOT WORM! |
| X | Service PAck SFVP | [worm filename].exe | Added by a variant of the RBOT WORM! The filename is 4 random characters |
| X | Service Process | SVCHOST.EXE | Added by the DARKER WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Service Process | winset.exe | Added by a variant of the SPYBOT WORM! |
| X | Service Process | service.exe | Added by the DCMBOT-C TROJAN! |
| X | Service Process | smss.exe | Added by the DCMBOT-E TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "config" subfolder |
| X | Service Process | svchost.exe | Added by the DCMBOT-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "config" subfolder |
| X | Service Registry NT Save | jdbgmgrnt.exe | Added by the BANCOS-CG TROJAN! |
| X | Service Registry NT Save | taskmgrnt.exe | Added by the BANCOS-BY TROJAN! |
| X | Service Registry NT Save | regeditnt.exe | Added by the BANCOS-BM TROJAN! |
| X | Service Scheduler | scheduler.exe | Added by the AGOBOT-PH WORM! |
| X | Service System | kernels32.exe | Added by the BANCOS-DA TROJAN! |
| X | Service System | windowsXP.exe | Added by the BANCOS-EL TROJAN! |
| X | Service System | kgbfsm344.exe | Added by the BANCOS-FS TROJAN! |
| X | Service System | wernell87.exe | Added by the BANCOS-FJ TROJAN! |
| X | Service System | softdwind.exe | Added by the BANCOS-JS TROJAN! |
| X | service updaer | qualityz.exe | Added by an unidentified VIRUS, WORM or TROJAN! - probably a SPYBOT variant |
| X | Service Update Client | svcupdcli.exe | Added by an unidentified WORM or TROJAN! See here |
| X | Service.exe | Service.exe | "servedby.advertising" popup generator |
| X | Service | SERVICES.EXE | Added by the BRONTOK-BH WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS |
| X | Service2 | Service2.exe | Identified as a variant of the Win32.Iroffer malware. Located in %Windir%\Drivers\Intel |
| X | service32 | service32.exe | Added by the AGOBOT-ST WORM! |
| X | service32.exe | [path to trojan] | Added by the DLOADR-AYX TROJAN! |
| X | ServiceAdministrator | SERVICES.EXE | Added by the KORRON.B WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS |
| U | ServiceConfig | ispbeg.exe | Comcast Transition Wizard. On June 30th, 2003 it will migrate E-mail and web pages from AT&T Broadband Internet to Comcast High-Speed Internet. Until then it will run at startup and then terminate - hence the U recommendation |
| X | serviceconnect | serviceconnect.exe | Added by the AGOBOT.AIR WORM! |
| X | ServiceControlApp | services.exe | Added by the SILLYFDC.BDO WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root directory (i.e. C:\ or D:\) |
| X | Servicee | services.exe | Added by the AGENT.DEI TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | ServiceHost | svch0st.exe | Added by the VB.HE VIRUS! |
| X | ServiceHst | svcnost.exe | Added by the AGOBOT-RS WORM! |
| X | servicelayer | servicelayer.exe | Added by the RENOS.FJ TROJAN! Note - do not confuse this with the Nokia service of the same name which resides in %ProgramFiles%\Common Files\PCSuite\Services or %Program Files%\PC Connectivity Solution. This one is located in %Windir% |
| X | servicemng | service.exe | Added by the TAME-C WORM! |
| X | ServiceOptionMP3 | winamp.dll.exe | Added by the SAMSON-A TROJAN! |
| X | Servicer | servcr.exe | Added by the SDBOT.BAH TROJAN! |
| X | Servicerepclient1 | SERVICES.EXE | Added by the BRONTOK-BT WORM and variants! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS |
| X | services | start.bat | Added by the ZCREW TROJAN! |
| X | Services | [path to trojan] | Added by the METEORSHELL TROJAN! |
| X | Services | back32.exe ...service.exe | Added by an unidentified VIRUS, WORM or TROJAN! Back32.exe is the baddie whose purpose is to HIDE the MIRC32 server in service.exe |
| X | Services | services.exe | Added by a number of VIRUSES, WORMS and TROJANS! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup! |
| X | Services | winread.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Services | windns.exe | Added by a variant of the RBOT WORM! |
| X | Services | mshost.exe | Added by the LANFILT-J TROJAN! |
| X | services | Svchosts.exe | Added by the SDBOT-N TROJAN! |
| X | Services | csrss.exe | Added by a variant of the RANKY.U TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
| X | Services | scks32.exe | Added by a Trojan-Proxy variant. The file is located in %Root% (i.e. C:\ D:\, etc) |
| X | Services | sockys32.exe | Added by the RANKY.L TROJAN! |
| X | Services | sys.exe | Added by a Trojan-Proxy variant. The file is located in %Root% (i.e. C:\ D:\, etc) |
| X | services | windows32.exe | Added by the FLYVB-C WORM! |
| X | services | socks.exe | Added by the WIN32.SMALL.N TROJAN! |
| X | Services | services.exe | Added by the ZINCITE.A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Services | [path to trojan] | Added by the RANCK-DB TROJAN! |
| X | Services | iexplore.exe | Added by the MOGI WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
| X | Services | svchost.exe | Added by the REPER-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Services | sysamp.exe | Added by a variant of the SDBOT WORM! |
| X | Services | prosys32.exe | Added by an unidentified WORM or TROJAN! |