| Status | Autorun name | Command | Description |
| X | Services | iexplorer.exe | Added by an unidentified WORM or TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
| X | Services | iexploler.exe | Added by the RANCK-LT TROJAN! |
| X | Services | iexpolere.exe | Added by the RANCK.LU TROJAN! |
| X | services | sample.exe | Added by a variant of the RANKY TROJAN! |
| X | Services | csrss32.exe | Added by the ANACON-D VIRUS! |
| X | Services | anacon32.exe | Added by the ANACON-C WORM! |
| X | Services | Winuoa.exe | Added by the PROXY-FBSR MALWARE! |
| X | Services Administrator | localsvc.exe | Added by the DLOADER-NY TROJAN! |
| X | Services Administrator | netsvc.exe | Added by the DLOADER-NY TROJAN! |
| X | Services Administrator | spoolsvc.exe | Added by the DLOADER-NY TROJAN! |
| X | Services Administrator | svcadmin.exe | Added by the DLOADER-NY TROJAN! |
| X | Services Administrator | svcman.exe | Added by the DLOADER-NY TROJAN! |
| X | Services Administrator | svcrun.exe | Added by the DLOADER-NY TROJAN! |
| X | Services Administrator | tcpsvc.exe | Added by the DLOADER-NY TROJAN! |
| X | Services Administrator | websvc.exe | Added by the DLOADER-NY TROJAN! |
| X | Services Control Manager | services.exe | Added by the DELF-CGI TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | Services Controller | lsassa.exe | Added by the CIADOOR.122 VIRUS! |
| X | Services Controller | services.exe | Added by the CIADOOR-F TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| Y | Services de sécurité Vidéotron | Rps.exe | Main program for the Vidéotron Security Services internet security suite for Vidéotron ISP customers - sourced by Radialpoint |
| X | Services DLL Loader | srvdll.exe | Added by the SLENFBOT.ZS WORM! |
| X | Services Host | Scchost.exe | Added by the DONK WORM! |
| X | Services Host | svchost32.exe | Added by the AGOBOT-TG WORM! |
| X | Services host | svchost.com | Added by the RBOT-EU WORM! |
| X | Services Logon | services.exe | Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Templates |
| X | Services Management Clients | servc.exe | Added by the RIZO.A TROJAN! |
| X | Services Managements | servcs.exe | Added by the RBOT-GUC WORM! |
| X | Services Manager | svsmanager.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Services Manager! | svmanager.exe | Added by the IRCBOT.ATZ BACKDOOR! |
| X | Services Managers | svcmanager.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Services Network | Services.exe | Added by the SWISYN-E WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
| X | Services Process | services.exe | Spyware - detected by Kaspersky as the SMALL.X TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | Services Process | smss.exe | Added by the SMALL-EK TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "config" subfolder |
| X | Services Start2 | odcwinst.exe | Added by the PYSKE-D WORM! |
| X | Services Startup | services.exe | Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files |
| X | Services Startup | svhost33.exe | Added by a variant of the RBOT WORM! |
| X | Services++ | services.exe | Added by the SILLYFDC.BDM WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\RECYCLER |
| X | Services.EXE | services.exe | Added by the KAZPING WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | services.exe | servicess.exe | Added by the MSNSPY-B TROJAN! |
| X | services.exe | service.bat | Added by the MDROP-BSW TROJAN! |
| X | Services004 | [worm filename] | Added by the BUGBROS WORM! |
| X | services32 | mc-110-12-0000079.exe | Added by the TrojanDownloader.Agent.rv TROJAN! |
| X | services32 | mc-58-12-0000120.exe | "Shorty" adware - also detected as the AGENT.FD TROJAN! |
| X | services32 | mc-58-12-0000140.exe | "Shorty" adware - also detected as the AGENT.FD TROJAN! |
| U | services32 | [random filename] | Director adware |
| X | Services32 Startup | win32dll.exe | Added by the SDBOT-XO WORM! |
| X | ServicesActive | cssrs.exe | Added by the AGOBOT-GB BACKDOOR! |
| X | ServicesAdministrator | SERVICES.EXE | Added by the PUNYA-B WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Documents and Settings\Administrator\Local Settings\Application Data\WINDOWS |
| X | Servicesara | services.exe | Added by the BRONTOK-BS WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS |
| X | ServicesLoad | lsass.exe | Added by the DEARIS-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | ServicesLog | ccapp32.exe | Added by the RBOT-AMX WORM! |
| U | ServicesNotify | ServicesNotify.exe | Defender Pro Antispy |
| X | servicestub.exe | servicestub.exe | Added by the RBOT.CN BACKDOOR! |
| X | Servicewin | Hide32.exe | Added by the MSNVB-D WORM! |
| X | Servicing | hostd.exe | Added by the SDBOT.BUI WORM! |
| X | Servicio Local | svhost.exe | Added by the SPYBOT.BGX WORM! |
| X | servico | servico.exe | Added by the BANKER-DKE TROJAN! |
| X | Servicos | AdobeLanc.exe | Added by the BANKER-EHR TROJAN! |
| X | Servicos | System.exe | Added by the BANCOS-BCM TROJAN! |
| X | servics | servics.exe | Added by the SINGU-J TROJAN! |
| X | servises | servises.exe | Added by the AGENT-JUJ WORM! |
| X | SERVlCE | SERVlCE.EXE | Added by the AGOBOT-UB WORM! |
| Y | ServoApp | ServoApp.exe | Multi Function Printer (MFP) server agent for products such as Belkin's Wireless G All-in-One Print Server and ZyXEL's NPS-520 which allow multiple computers to use networked all-in-one printers. Required for the MFP Server Agent (MFPAgent.exe) to run properly - whether it's set to start manually or automatically |
| X | ServRun | srss32.exe | Added by the AGOBOT.ABS WORM! |
| N | ServUTrayIcon | ServUTray.exe | System Tray access for the Serv-U FTP server which allows the user to (amongst others) start the Management Console, stop the server and display notifications |
| U | ServUTrayIcon | Serv-U-Tray.exe | System Tray access for the Serv-U FTP server which allows the user to (amongst others) start the Management Console, stop the server and display notifications |
| X | SES Service | sesvc.exe | Added by the SDBOT-CZU WORM! |
| U | Session Client | sescli.exe | SurfSpy keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | Session Manager Subsystem | smssa.exe | Added by the RBOT-AGS WORM! |
| X | SessionInit | init.exe | Added by the FAKEAV-BRZ TROJAN! |
| X | SessionMngr | dirlock.exe | Added by the DAPROSY WORM! |
| X | SessMgr | sessmgr.exe /waitservice | Added by the HORST.Q TROJAN! Note - this is not the legitimate sessmgr.exe which is always located in %System%. This one is located in either %Windir%, %Windir%\System, %Temp%, %AppData%, %AppData%\Microsoft or %System%\drivers |
| X | SESync | sed.exe | DownloadWare adware |
| ? | SetCacheMode | rundll32.exe ptipbmf.dll, SetWriteCacheMode | Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. May be necessary in order to maintain preferences applied to the RAID array connected to the Promise controller |
| ? | SetDefaultMIDI | MIDIDef.exe | Related to a Soundblaster Audigy soundcards. What does it do and is it required? |
| Y | SetDefaultPrinter | cloaker.exe | Used by HP and Compaq computers to hide the windows of programs passed as arguments to it |
| N | setdefprt | setdefprt.exe | Used to set a Brother MFC printer/copier/scanner as the default printer after installation |
| N | SetDefPrt | BrStDvPt.exe | Used to set a Brother MFC printer/copier/scanner as the default printer after installation |
| U | SetecCertUtil | Certutil.exe | Setec Web and Email Security. Setec PKI smart card software. The PKI technology enables secure and reliable user identification in services offered through Internet, mobile handsets and digital TV |
| X | setFTPBack | createsw.exe | Added by the FTP_BMAIL TROJAN! |
| N | SetHook | Sethook.exe | Fellowes Neato® cd label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar" |
| N | SETI@home | SETI@home.exe | SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data |
| N | seticlient | SETI@home.exe | SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data |
| N | SetIcon | SetIcon.exe | Installed by a 6-in-1 (4 Media Card slots, a floppy drive and a USB connection) device. Constantly updates the icons for the four Media Card slots that it has and is a resource hog |
| N | SetiQueue | Setiqu~1.exe | Provides work unit buffering for Seti@Home clients - see here for more details |
| N | SetiSpy | SetiSpy.exe | SETI Spy is a little program to "spy" on the progress and performance of the SETI@home client. Called a "spy" because it is unobtrusive as possible |
| ? | SetPanel | APanel.cmd | Display configuration utility for some Acer laptops. Is it required? |
| X | SetPoint | SetPoint.exe | Added by the RBOT-BWI WORM! Note - this is not the valid Logitech Setpoint mouse and keyboard entry that uses the same filename and is located in %ProgramFiles%\Logitech\Setpoint. This one is located in %System% |
| U | SetPoint | Setpoint.exe | Logitech SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice, trackballs, etc). Required if you want to use the advanced features or modify the default settings of these devices and located in %ProgramFiles%\Logitech\Setpoint |
| X | SETPOINT Logitech Inc | KHALMNP.exe | Added by the RBOT-AAX WORM! |
| U | SetRefresh | SetRefresh.exe | Found on some Compaq & HP PCs. SetRefresh is a utility which attempts to optimize the monitor's refresh rate, and in some cases the resolution, for the best user experience. See "here for more info |
| X | settdebugx.exe | settdebugx.exe | Added by the FAKEAV.SMSS TROJAN! |
| X | Setting | sysweb.exe | Added by the SDBOT.W BACKDOOR! |
| X | Setting | Webprint.exe | Added by the SDBOT.W BACKDOOR! |
| N | setup | hphprld.exe ....setup.exe | HP DeskJet Setup - printers function normally without it |
| X | Setup | [path to trojan] | Added by the DROPPER.EAT TROJAN! |
| X | Setup experation | svchost.exe | Added by the TOFGER-AW TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | setup.exe | setup.exe | Added by the GOLDUN-GB TROJAN! |
| X | setupa | runt32.exe | Added by the QQPASS-K TROJAN! |
| X | setupdata | rnll32.exe | Added by the QQPASS-AC TROJAN! |
| X | setupuser | regedit.exe setupuser.log | Regfile in disguise - another CoolWebSearch parasite variant |