| Status | Autorun name | Command | Description |
| X | Service Scheduler | scheduler.exe | Added by the AGOBOT-PH WORM! |
| X | Service System | kernels32.exe | Added by the BANCOS-DA TROJAN! |
| X | Service System | windowsXP.exe | Added by the BANCOS-EL TROJAN! |
| X | Service System | kgbfsm344.exe | Added by the BANCOS-FS TROJAN! |
| X | Service System | wernell87.exe | Added by the BANCOS-FJ TROJAN! |
| X | Service System | softdwind.exe | Added by the BANCOS-JS TROJAN! |
| X | service updaer | qualityz.exe | Added by an unidentified VIRUS, WORM or TROJAN! - probably a SPYBOT variant |
| X | Service Update Client | svcupdcli.exe | Added by an unidentified WORM or TROJAN! See here |
| X | Service.exe | Service.exe | "servedby.advertising" popup generator |
| X | Service | SERVICES.EXE | Added by the BRONTOK-BH WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS |
| X | Service2 | Service2.exe | Identified as a variant of the Win32.Iroffer malware. Located in %Windir%\Drivers\Intel |
| X | service32 | service32.exe | Added by the AGOBOT-ST WORM! |
| X | service32.exe | [path to trojan] | Added by the DLOADR-AYX TROJAN! |
| X | ServiceAdministrator | SERVICES.EXE | Added by the KORRON.B WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS |
| U | ServiceConfig | ispbeg.exe | Comcast Transition Wizard. On June 30th, 2003 it will migrate E-mail and web pages from AT&T Broadband Internet to Comcast High-Speed Internet. Until then it will run at startup and then terminate - hence the U recommendation |
| X | serviceconnect | serviceconnect.exe | Added by the AGOBOT.AIR WORM! |
| X | ServiceControlApp | services.exe | Added by the SILLYFDC.BDO WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root directory (i.e. C:\ or D:\) |
| X | Servicee | services.exe | Added by the AGENT.DEI TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | ServiceHost | svch0st.exe | Added by the VB.HE VIRUS! |
| X | ServiceHst | svcnost.exe | Added by the AGOBOT-RS WORM! |
| X | servicelayer | servicelayer.exe | Added by the RENOS.FJ TROJAN! Note - do not confuse this with the Nokia service of the same name which resides in %ProgramFiles%\Common Files\PCSuite\Services or %Program Files%\PC Connectivity Solution. This one is located in %Windir% |
| X | servicemng | service.exe | Added by the TAME-C WORM! |
| X | ServiceOptionMP3 | winamp.dll.exe | Added by the SAMSON-A TROJAN! |
| X | Servicer | servcr.exe | Added by the SDBOT.BAH TROJAN! |
| X | Servicerepclient1 | SERVICES.EXE | Added by the BRONTOK-BT WORM and variants! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS |
| X | services | start.bat | Added by the ZCREW TROJAN! |
| X | Services | [path to trojan] | Added by the METEORSHELL TROJAN! |
| X | Services | back32.exe ...service.exe | Added by an unidentified VIRUS, WORM or TROJAN! Back32.exe is the baddie whose purpose is to HIDE the MIRC32 server in service.exe |
| X | Services | services.exe | Added by a number of VIRUSES, WORMS and TROJANS! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup! |
| X | Services | winread.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Services | windns.exe | Added by a variant of the RBOT WORM! |
| X | Services | mshost.exe | Added by the LANFILT-J TROJAN! |
| X | services | Svchosts.exe | Added by the SDBOT-N TROJAN! |
| X | Services | csrss.exe | Added by a variant of the RANKY.U TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
| X | Services | scks32.exe | Added by a Trojan-Proxy variant. The file is located in %Root% (i.e. C:\ D:\, etc) |
| X | Services | sockys32.exe | Added by the RANKY.L TROJAN! |
| X | Services | sys.exe | Added by a Trojan-Proxy variant. The file is located in %Root% (i.e. C:\ D:\, etc) |
| X | services | windows32.exe | Added by the FLYVB-C WORM! |
| X | services | socks.exe | Added by the WIN32.SMALL.N TROJAN! |
| X | Services | services.exe | Added by the ZINCITE.A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Services | [path to trojan] | Added by the RANCK-DB TROJAN! |
| X | Services | iexplore.exe | Added by the MOGI WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
| X | Services | svchost.exe | Added by the REPER-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Services | sysamp.exe | Added by a variant of the SDBOT WORM! |
| X | Services | prosys32.exe | Added by an unidentified WORM or TROJAN! |
| X | Services | iexplorer.exe | Added by an unidentified WORM or TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
| X | Services | iexploler.exe | Added by the RANCK-LT TROJAN! |
| X | Services | iexpolere.exe | Added by the RANCK.LU TROJAN! |
| X | services | sample.exe | Added by a variant of the RANKY TROJAN! |
| X | Services | csrss32.exe | Added by the ANACON-D VIRUS! |
| X | Services | anacon32.exe | Added by the ANACON-C WORM! |
| X | Services | Winuoa.exe | Added by the PROXY-FBSR MALWARE! |
| X | Services Administrator | localsvc.exe | Added by the DLOADER-NY TROJAN! |
| X | Services Administrator | netsvc.exe | Added by the DLOADER-NY TROJAN! |
| X | Services Administrator | spoolsvc.exe | Added by the DLOADER-NY TROJAN! |
| X | Services Administrator | svcadmin.exe | Added by the DLOADER-NY TROJAN! |
| X | Services Administrator | svcman.exe | Added by the DLOADER-NY TROJAN! |
| X | Services Administrator | svcrun.exe | Added by the DLOADER-NY TROJAN! |
| X | Services Administrator | tcpsvc.exe | Added by the DLOADER-NY TROJAN! |
| X | Services Administrator | websvc.exe | Added by the DLOADER-NY TROJAN! |
| X | Services Control Manager | services.exe | Added by the DELF-CGI TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | Services Controller | lsassa.exe | Added by the CIADOOR.122 VIRUS! |
| X | Services Controller | services.exe | Added by the CIADOOR-F TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| Y | Services de sécurité Vidéotron | Rps.exe | Main program for the Vidéotron Security Services internet security suite for Vidéotron ISP customers - sourced by Radialpoint |
| X | Services DLL Loader | srvdll.exe | Added by the SLENFBOT.ZS WORM! |
| X | Services Host | Scchost.exe | Added by the DONK WORM! |
| X | Services Host | svchost32.exe | Added by the AGOBOT-TG WORM! |
| X | Services host | svchost.com | Added by the RBOT-EU WORM! |
| X | Services Logon | services.exe | Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Templates |
| X | Services Management Clients | servc.exe | Added by the RIZO.A TROJAN! |
| X | Services Managements | servcs.exe | Added by the RBOT-GUC WORM! |
| X | Services Manager | svsmanager.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Services Manager! | svmanager.exe | Added by the IRCBOT.ATZ BACKDOOR! |
| X | Services Managers | svcmanager.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Services Network | Services.exe | Added by the SWISYN-E WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
| X | Services Process | services.exe | Spyware - detected by Kaspersky as the SMALL.X TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | Services Process | smss.exe | Added by the SMALL-EK TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "config" subfolder |
| X | Services Start2 | odcwinst.exe | Added by the PYSKE-D WORM! |
| X | Services Startup | services.exe | Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files |
| X | Services Startup | svhost33.exe | Added by a variant of the RBOT WORM! |
| X | Services++ | services.exe | Added by the SILLYFDC.BDM WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\RECYCLER |
| X | Services.EXE | services.exe | Added by the KAZPING WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | services.exe | servicess.exe | Added by the MSNSPY-B TROJAN! |
| X | services.exe | service.bat | Added by the MDROP-BSW TROJAN! |
| X | Services004 | [worm filename] | Added by the BUGBROS WORM! |
| X | services32 | mc-110-12-0000079.exe | Added by the TrojanDownloader.Agent.rv TROJAN! |
| X | services32 | mc-58-12-0000120.exe | "Shorty" adware - also detected as the AGENT.FD TROJAN! |
| X | services32 | mc-58-12-0000140.exe | "Shorty" adware - also detected as the AGENT.FD TROJAN! |
| U | services32 | [random filename] | Director adware |
| X | Services32 Startup | win32dll.exe | Added by the SDBOT-XO WORM! |
| X | ServicesActive | cssrs.exe | Added by the AGOBOT-GB BACKDOOR! |
| X | ServicesAdministrator | SERVICES.EXE | Added by the PUNYA-B WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Documents and Settings\Administrator\Local Settings\Application Data\WINDOWS |
| X | Servicesara | services.exe | Added by the BRONTOK-BS WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS |
| X | ServicesLoad | lsass.exe | Added by the DEARIS-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | ServicesLog | ccapp32.exe | Added by the RBOT-AMX WORM! |
| U | ServicesNotify | ServicesNotify.exe | Defender Pro Antispy |
| X | servicestub.exe | servicestub.exe | Added by the RBOT.CN BACKDOOR! |
| X | Servicewin | Hide32.exe | Added by the MSNVB-D WORM! |
| X | Servicing | hostd.exe | Added by the SDBOT.BUI WORM! |
| X | Servicio Local | svhost.exe | Added by the SPYBOT.BGX WORM! |