| Status | Autorun name | Command | Description |
| X | Runonce | runouce.exe | Added by the CHIR-B WORM! |
| X | RunOnce | [path to trojan] | Added by the BANCBAN-P TROJAN! |
| X | RunOnce | [path to mstask32.exe] | Added by the DELF-IA TROJAN! |
| X | RunOnce2Upd | [path to trojan] | Added by the MURLO.FI TROJAN! |
| X | RunOnceEx | sms.exe | IESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN! |
| X | RunProg | Server.exe | Added by the OPTIX.04.A BACKDOOR! |
| X | RunProg | wini.exe | Added by the OPTIX.04.D TROJAN! |
| X | runreper | viewer.exe | Added by the REPER.A VIRUS! |
| X | runs | run.exe | Added by the RBOT-BWF WORM! |
| X | RunSearvices | tread.exe | IESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN! |
| X | RunServices | runsvc32.exe | Added by the AGOBOT.QJ WORM! |
| X | runservices | services.exe | Identified as a variant of the SMALL.QO TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | RunServices | service.exe | Added by the VEBISP VIRUS! |
| X | runsql | runsql.exe | Added by the DELF.ZWK TROJAN! |
| X | runSubvalues | [path to file] | Added by the DLOADER-QY TROJAN! |
| X | runsvc | runsvc.exe | Added by the SMALL-CF TROJAN! |
| U | RunSysd32 | RunSysd32.exe | DesktopShield2000 by Stéphane Groleau. Locks the desktop at bootup so that users cannot bypass the Windows screensaver password. Only essential if using the program and is an optional setting. It can be disabled from within |
| X | Runtime Process | Csrss.exe | Added by the CIADOOR-J BACKDOOR! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Runtime Server Subsystem | csrss.exe | Added by the IRCBOT-XV WORM! |
| X | runtime.exe | runtime.exe | Added by a variant of the Tibs malware |
| X | Runtt1 | Internat.exe | Added by the LINEAGE-R TROJAN! |
| X | Runtt1 | Internet.exe | Added by the LINEAGE-Q TROJAN! |
| X | RunWin | [path to file] | Added by the BANKER-ES TROJAN! |
| X | runwin32 | runwin32.exe | Added by the ESEARCH-A TROJAN! |
| X | RUNWIN32 | runwin32.exe | Added by the VB-AET TROJAN! |
| X | RunWindowsUpdate | uptodate.exe | BrowserAid/BrowserPal foistware |
| X | runwinlogon | winlogon.exe | Added by the AGENT.TQY TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
| U | Rupsw32 | Rupsw32.exe | MegaTec Rups, UPS monitoring software - monitor and control DB9 UPS running on either Windows & Novell NetWare (with RUPS 2000) or Unix (with RUPS for Unix / Plus) operating systems |
| ? | RUSBHOLoader | rundll32.exe RUSBHOLoader.dll, AutoRegister | ?? |
| X | RVC6Player | tskdbg.exe | Added by the ZAPCHAS-M TROJAN! |
| X | RVCHOST.EXE | Rvchost.exe | Added by the DELF-AC BACKDOOR! |
| X | rvde | N/A | Related to li-speed**** |
| X | RVP | bpc.exe | BroadcastPC adware |
| X | rw service | alg32.exe | LOOPAD.A adware |
| X | rx | rundll32.exe | Added by the LINEAGE-BP TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir% |
| X | rx | explore.exe | Added by the ZHENGTU-A TROJAN! |
| N | RxMon | rxmon9x.exe | Part of Dell Resolution Assistant - "a diagnostic program that allows you to contact Dell. When factory-installed by Dell, it allowed you to perform hardware and software diagnostics that provided alerts to potential problems and enabled real-time communication with Dell RA techs. You can now use RA only to contact Dell by e-mail" |
| X | rxres32 | ati2vid.exe | Added by the RBOT-FL WORM! |
| N | RxUser | RxUser.exe | Part of Dell Resolution Assistant - "a diagnostic program that allows you to contact Dell. When factory-installed by Dell, it allowed you to perform hardware and software diagnostics that provided alerts to potential problems and enabled real-time communication with Dell RA techs. You can now use RA only to contact Dell by e-mail" |
| X | ryan1918 | servidevice.exe | Added by the RBOT-GVR WORM! |
| X | rydanmxe.exe | rydanmxe.exe | Added by the DLOADR-AZZ TROJAN! |
| X | ryiixhp | ryiixhp.exe | Added by the IRCBOT-ABR BACKDOOR! |
| X | ryy | rundl132.exe | Added by the PWS-ANA TROJAN! |
| X | rz.scr | rz.scr | Added by the SILLYFDC-AY WORM! |
| X | rzt | rundll32.exe | Added by the LINEAGE.BDP TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP/Vista/7). This one is located in %Windir%\Intel |
| X | S | svhost.exe | Added by the AGOBOT-LN WORM! |
| X | S0undMan | svch0st.exe | Added by the LOVGATE.AB WORM! Note - the filename has the digit 0 rather then the uppercase "o" |
| ? | S24EvMon | S24EvMon.exe | Event Monitor - supports driver extensions to NIC Driver for wireless adapters. Is it required? |
| X | S3 Chip3 | s3int.exe | Added by the AGOBOT.LM BACKDOOR! |
| X | S3 Internal | s3chip4.exe | Added by the AGOBOT-FQ BACKDOOR! |
| X | S3 Internal Chip | s3serv.exe | Added by the AGOBOT-DD WORM! |
| X | S3 Internal Chip | s3chip3.exe | Added by the AGOBOT-FW WORM! |
| N | S3apphk | S3apphk.exe | A tool installed alongside the drivers for your S3 video output device. It is not necessary but should be allowed to run unless it is causing problems |
| U | S3Hotkey | s3hotkey.exe | Hotkey system tray icon to enable switching between monitors. Found on laptops with an S3 Twister integrated graphics card |
| ? | S3Mon | S3Mon.exe | S3DuoVue multi-monitor taskbar helper by S3 Graphics. What does it do and is it required? |
| U | S3TRAY | S3Tray.exe | S3 display configuration taskbar utility for S3 chipset based graphics cards. Can be run from Start-> Settings -> Control Panel -> Display |
| ? | s3tray2 | s3tray2.exe | S3 display configuration taskbar utility for S3 chipset based graphics cards? |
| ? | S3TRAYHP | S3trayhp.exe | S3 Video driver related. What does it do and is it required? |
| U | S3Trayp | S3trayp.exe | S3 display configuration taskbar utility for S3 chipset based graphics cards. Can be run from Start-> Settings -> Control Panel -> Display |
| U | S4F | S4F.exe | FilterPak from S4F, Inc - internet filtering software |
| X | s4helper | s4helper.exe | Searchcentrix hijacker |
| N | S60 PC Suite Tray | PCSuite.exe | System Tray access to SAMSUNG PC Studio (by Nokia) - with which "you can use easily to manage personal data and multimedia file by connecting a Samsung Electronics Mobile hone(GSM/GPRS/UMTS) to your PC". This allows you (amongst other options) to backup your devices contents to your PC, use it to connect to the internet, transfer files and synchronize contacts, etc. Available from the start menu |
| X | s9201 | av2008xp.exe | Antivirus 2008 XP rogue security software - not recommended, removal instructions here |
| X | s9201 | as2008xp.exe | AntiSpyware XP 2008 rogue spyware remover - not recommended, removal instructions here |
| X | s9201 | asproxp.exe | AntiSpyware Pro XP rogue spyware remover - not recommended, removal instructions here |
| X | s9201 | wspwprtct.exe | WinSpywareProtect rogue security software - not recommended, removal instructions here |
| ? | SA | Sa3.exe | Logitech QuickCam driver. Is it required? |
| ? | SA Service | SAservice.exe | Associated with Cyber Trio and Warner troubleshooting software fromG-Tek Technologies and pre-installed on some Packard Bell and NEC PCs. What function does this perform and is it required? |
| N | Sa3dsrv | Sa3dsrv.exe | For Aureal based 3D soundcards. A3D sound features won't work with this disabled |
| X | saap | saap.exe | 180solutions adware |
| U | Sabre Printing Start | Sabstart.exe | Part of the Sabre computer reservations system/global distribution system (GDS) - used by airlines, railways, hotels, travel agents and other travel companies for reservations and ticketing |
| U | Sabre Server | sabserv.exe | Part of the Sabre computer reservations system/global distribution system (GDS) - used by airlines, railways, hotels, travel agents and other travel companies for reservations and ticketing |
| U | Sabre Task Tray Icon | Sabstart.exe | Part of the Sabre computer reservations system/global distribution system (GDS) - used by airlines, railways, hotels, travel agents and other travel companies for reservations and ticketing |
| U | Sabreserver | SABSERV.EXE | Part of the Sabre computer reservations system/global distribution system (GDS) - used by airlines, railways, hotels, travel agents and other travel companies for reservations and ticketing |
| X | sac | sac.exe | 180Search adware |
| X | SACC | sacc.exe | SurfAccuracy adware |
| N | SAClient | RegCon.exe | AT&T or ComCast BBClient - monitors system and network-delivered services for availability. Your current network status is displayed on a color-coded web page in near-real time. When problems are detected, you're immediately notified by e-mail, pager, or text messaging |
| X | sacmemds | smcntlwio.exe | Added by the MAILBOT-BZ TROJAN! |
| X | sads | sdsa.exe | Added by the RBOT-PA WORM! |
| X | Safe | SafeWin.exe | Added by the FOCOSENHA TROJAN! |
| X | Safe | [path to trojan] | Added by the BANKER-DT TROJAN! |
| X | SafeFighter | SafeFighter.exe | SafeFighter rogue security software - not recommended, removal instructions here. A member of the WiniGuard family |
| X | Safeguard 2009 | sf2009.exe | Safeguard 2009 rogue spyware remover - not recommended, removal instructions here |
| X | SafeGuard Popup Blocker Updater | regsvr32 sfgupd.dll | SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System% |
| X | SafeGuard Popup Blocker Updater (required) | regsvr32 sfg****.dll [* = ramdom char] | SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System% |
| X | SafeGuard Popup Updater (required) | regsvr32 sfg****.dll [* = random char] | SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System% |
| X | SafeGuard Popup Updater (required) | regsvr32 PDF****.dll [* = random char] | SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System% |
| X | Safeguard.exe | Safeguard.exe | Super Spyware Killer rogue spyware remover - not recommended |
| X | SafeHardDrive | SysRep.exe | SafeHardDrive rogue system error and cleaning utility - not recommended, removal instructions here. A member of the ErrClean family |
| U | SafeHouseSystemTray | SDWTRAY.EXE | SafeHouse "Personal Privacy" system tray icon - PP protects and hides your private and personal photos, videos, files and folders by making them "invisible" and encrypted |
| N | SafeInstall.exe | SAFEIN~1.EXE | Monitors a download and ensures an newer version of a file isn't replaced by an older one |
| N | SafeOFF | SafeOff.exe | Provides protection that if user accidentally presses the power switch a dialog will pop up for confirmation |
| X | SafePcAv | SafePcAv.exe | SafePcAv rogue security software - not recommended, removal instructions here. A member of the AntiAID family |
| X | SafePCTool | SysRep.exe | SafePCTool rogue system error and cleaning utility - not recommended, removal instructions here. A member of the ErrClean family |
| X | SafePrivate | SafePrivate.exe | SafePrivate rogue security software - not recommended, removal instructions here |
| X | SaferScan | SaferScan.exe | SaferScan rogue security software - not recommended |
| X | SafeSearch | safesearch.exe | SafeSearch.A adware |
| Y | SafeSpace | SafeSpaceSysTray.exe | Part of SafeSpace (from Artificial Dynamics) which "protects computers from Internet malware infection without the need for signature updates or regular maintenance" |
| X | SafeStrip | SafeStrip.exe | SafeStrip rogue security software - not recommended, removal instructions here |
| X | SafeStripReminder | SafeStripReminder.exe | SafeStrip rogue security software - not recommended, removal instructions here |