| Status | Autorun name | Command | Description |
| ? | setuzp | setuzp.exe | ?? |
| X | SetVrc | setvrc.exe | Added by the HUNTOCX WORM! |
| X | SevenSowrd | SysSevenSowrd.exe | Added by the AGENT-GIR TROJAN! |
| X | Sevice | winconfig.exe | Added by the GIP.113.B1 TROJAN! |
| X | Sex Teris | st01b.exe | Added by the REPAD WORM! |
| X | Sexnow | Sexnow.exe | Added by the SENOW-B premium rate adult content dialler |
| X | Sexy_Blondes | Sexy_Blondes.exe | Added by the Sexy DIALER! Related also to Hot Tarts DIALER! |
| X | Sexy_sg | Sexy_sg.exe | Premium rate adult content dialler |
| X | sf | sf.exe | SurfEnhance adware |
| N | SFIGUI | SFIGUI.EXE | Sonic Focus - "enhances music, movie and game sound by analyzing compressed audio streams in realtime, then restoring and enriching audio back to its original performance qualities" |
| X | sfita | sfita.exe | Added by the FAVADD-H TROJAN! |
| X | SfKg6w | [path to worm] | Added by the AGENT.BUO WORM! |
| X | SfKg6wIP | [random filename] | Identified as a variant of the TrojanDownloader.Matcash malware |
| X | SfKg6wIPu | [random filename] | Identified as a variant of the TrojanDownloader.Matcash malware |
| N | SFP | vzSFPWin.EXE | Verizon Online Support Center - prompts for online updates |
| U | sfpc | sfpc.exe | Spy4PC surveillance software. Uninstall this software unless you put it there yourself |
| X | SFtrb Service | cftrb32.exe | Added by the SOBIG.D WORM! |
| U | SfWinStartInfo | sfWinStartupInfo.exe | SFIRM32 Online Banking software |
| X | sfwjbbjd | midiwemshdw.exe | Added by the AGENT-OII TROJAN! |
| U | Sgecrypt | Sgecrypt.exe | SafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks" |
| U | Sgeecview | Ecview.exe | SafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks" |
| U | sginst | sginst.exe | eAcceleration Stop-Sign security software related - previously not recommended (see here). It has now been delisted, so make sure you have the latest version - hence the "U" recommendation |
| X | SGPUpdater | sgpUpdaters.exe | Fast Browser Search/Search Guard Plus parasite - installed with "Make the Web Better" applications such as My Web Tattoo, My Face LOL and Google Easy Money Kit. See here and here for more information |
| ? | SGTBox | SGTBox.exe | Canon scanner driver. Is it required? |
| U | sgtray | sgtray.exe | StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups |
| Y | Shadow | Shadow.exe | "NTI Shadow 3 is an award-winning easy-to-use backup application that automatically protects your photo, music, video, and various data files. It makes data restoration as easy as dragging and dropping files from one place to another" |
| U | ShadowUser Pro Edition | ShadowUser.exe | StorageCraft ShadowUser "provides easy to use desktop security and protection for Windows operating systems. ShadowUser is the best way to prevent unwanted changes to PCs and laptops." No longer available - see here |
| X | shambl3r | cnf.bat | Added by the REMABL WORM! |
| X | shambl3r* | shambl3r.exe | Added by the REMABL WORM! where * is 2 to 11 |
| X | SHAProc | SHAProc.exe | Added by the WINKO.AO WORM! |
| N | Share-to-Web Namespace Daemon | hpgs2wnd.exe | Share-to-Web - HP-created software and Internet-based application that enables easy uploading and sharing of photos via affiliated photo-sharing Web sites. Available via Start → Programs |
| N | Shareaza | Shareaza.exe | Shareaza P2P client |
| U | Shareaza | bindata.exe | Shareaza P2P client related |
| X | sharedprem | sharedprem.exe | Added by the MAKECALL TROJAN! |
| X | ShareSearcher | [path to trojan] | Added by the AGENT-FPE TROJAN! |
| X | ShareSearcher | wsusupd.exe | Added by the ENCLAG-A TROJAN! |
| Y | Sharing and Mapping Software | DShmap.exe | Intel AnyPoint internet sharing software. Now discontinued |
| N | SharkEject | AEJCT32.exe | Allows you to eject a disk from the Avatar Shark drive from the system tray. When loaded, there is a desktop icon so this isn't required |
| U | SharpTray | SharpTray.exe | Part of the Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents" |
| X | shccde | winssled.exe | Added by the BUZUS.CQMU TROJAN! |
| N | Shcenter | chcenter.exe | IMSI HiJaak - "the easiest way to convert, capture, and manage all your graphic files" |
| X | shdef | shdef.exe | Added by the VB-DVS TROJAN! |
| X | SheduIer | svchst.exe | Premium rate adult content dialler |
| X | SheduIer | shch.exe | Added by the BDOOR-EB BACKDOOR! |
| X | SheduIer | winagent.exe | Added by the BDOOR-EB BACKDOOR! |
| X | Shedule Connection | arpo412.exe | Added by the PPDOOR-R WORM! |
| X | Sheduler | nerocheck.exe | Added by the TACTSLAY.B TROJAN! Note - this is not the legitmate file of the same name from the Nero CD/DVD burning software which is usually located in %System% |
| X | Shell | Shell32.exe | Added by the BADSECTOR TROJAN! |
| X | Shell | ray.exe | Homepage hijacker re-directing browsers to adult content websites |
| X | Shell | Tray.exe | Homepage hijacker re-directing browsers to adult content websites |
| X | Shell | wmedia16.exe | Added by the GOLDUN TROJAN! |
| X | Shell | Open32.exe | Added by the SMALL-DL TROJAN! |
| X | Shell | Explorer.exe sound_drive16.exe | Added by the GP BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The "sound_drive16.exe" file is located in %System% |
| X | Shell | Explorer.exe, msmsgs.exe | Added by the ZLOB TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. This particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger |
| X | Shell | Explorer.exe svchost.exe | Added by the DOYORG BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The legitimate svchost.exe process is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | shell | explorer.exe | Added by the KAKKEYS TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System% |
| X | Shell | Explorer.exe iexplore.exe | Added by the KIPIS-U WORM! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The legitimate Internet Explorer (iexplore.exe) is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%\Microsoft |
| X | Shell | ibm0000*.exe [* = digit] | Added by the TORPIG-C and TORPIG-J TROJANS! Filenames spotted include ibm00001.exe, ibm00002.exe, ibm00005.exe and so on |
| X | Shell | taskmrg.exe | Added by the BANCBAN-FT TROJAN! |
| X | Shell | Explorer.exe winupdate.exe | Added by the AGENT-FD TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The "winupdate.exe" file is located in %System% |
| X | Shell | Explorer.exe [path] ibm[RANDOM 5 DIGIT NUMBER].exe | Added by the ANSERIN TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files |
| X | Shell | svchost.exe | Added by the GOLDSPY-B TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Shell | ibm00001.dll | Added by the TORPIG-Q TROJAN! |
| X | Shell | wmedia32.exe | Added by the AGENT-BR TROJAN! |
| X | Shell | Explorer.exe winsys32.exe | Added by the DELF.CP BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The "winsys32.exe" file is located in %Windir% |
| X | Shell | Win32.dll.exe | Added by the VB.BTX TROJAN! |
| X | Shell | taskmam.exe | Added by the BANCBAN-OL TROJAN! |
| X | Shell | explorer.exe msbnc.exe | Added by the AGENT-PL BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The "msbnc.exe" file is located in %System% |
| X | Shell | Explorer.exe kbdsys.exe | Added by the DAPROSY WORM! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The "kbdsys.exe" file is located in %AppData%\Microsoft\Keyboard |
| X | Shell | smsc.exe | Added by the BANCBAN-OY TROJAN! |
| X | Shell | Explorer.exe init32m.exe | Added by the DLSW-B TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The "init32m.exe" file is located in %System% |
| X | Shell | Explorer.exe smssnt.exe | Added by the AGOBOT.EE TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The "smssnt.exe" file is located in %System% |
| X | Shell API32 | svcnet.exe | Added by the TIBICK.C WORM! |
| X | Shell Extension | spollsv.exe | Added by the LOVGATE.Z WORM! |
| X | Shell Tray Window | ShellTraywnd.exe | Added by the STULTDOR-A TROJAN! |
| X | shell update | shellexec.exe | Added by the RBOT-ANC WORM! |
| X | Shell.exe | Shell.exe | Added by the EMERLEOX.S WORM! |
| X | Shell32 | Shell32.vbs | Added by the SCAFENE WORM! |
| X | shell32 | ntldrt.exe | Added by the JLOK-A WORM! |
| X | Shell32 | iexplore.exe | Added by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
| X | Shell32 | explorer.exe | Added by the SDBOT-NF WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System% |
| X | ShellApi | SHELLMSN.EXE | Added by the NETDEV.B BACKDOOR! |
| X | Shellapi32 | Shellapi32.exe | Added by the NETDEVIL (or NERTE) TROJAN! |
| X | Shellapi32 | mcvsrte.exe | Added by an unidentified WORM! Note - do not confuse with the McAfee SecurityCenter file of the same name |
| X | shellbn | [random].dll | SoftStop rogue security software - not recommended |
| X | shellbn | shlext32.exe | Malware installed by different rogue security software including SpyKillerPro and the XP AntiVirus series |
| X | ShellCommand | [path to file] | Added by the REMCON-A TROJAN! |
| X | Shelldaemon | Shelldaemon.exe | Added by a variant of the AGENT.ALN TROJAN! |
| X | ShellEx | ShellEx.exe | Added by the ANAKHA TROJAN! |
| X | ShellN | isca.exe | Added by the IBILL.Z TROJAN! |
| X | ShellOS | A+++.exe | Added by the AV TROJAN! |
| X | ShellRun | lexplore_.exe | Added by the MSNOPT-A TROJAN! |
| X | ShellRun32 | iexplore.exe | Added by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
| X | Shellspl | lsas.exe | Added by the YALER-A TROJAN! |
| X | Shellspl | spools.exe | Added by the PROXAGE-A TROJAN! |
| X | shellsystem | shellsystem.exe | Added by the UPCHAN TROJAN! |
| X | shhost | shhost.exe | Added by the AGENT.CE BACKDOOR! |
| N | shicoxp | shicoxp.exe | Installed with the drivers for multi card readers of various brands. To differentiate between the various card slots on multi slot readers the shicoxp.exe file assigns and loads unique drive icons for the various card slots that are displayed in Windows Explorer |
| X | Shield Security | shield.exe | Added by the RIZO.A TROJAN! |
| X | Shield32 Security | shield32.exe | Added by the RIZO.A TROJAN! |