| Status | Autorun name | Command | Description |
| X | Socket Utility | svchostz.exe | Added by the DAEMONI-E TROJAN! |
| X | Socket Utility | socket.exe | Added by the DAEMONI-E TROJAN! |
| Y | SoDA Startup | SodaStartup.exe | Used by the IBM Rational SoDA project management tool. Unsure of it's actual purpose but it's recommended you leave it enabled if you use the software |
| N | soffice | SOFFICE.EXE | Part of StarOffice by StarDivision - a proprietary office suite and the predecessor of OpenOffice. Displays the quick start applet in the System Tray. Right clicking on the icon allows rapid starting up of components of the StarOffice suite. Automatically started when any StarOffice component is run from the Start menu and is a resource hog (it uses more than 16 MB of memory) |
| X | Soft Profile Inc | hxdef.exe... | Added by the LOVGATE.AO WORM! |
| X | Soft Profile Inc | hxdef.exe | Added by the LOVGATE.E WORM! |
| X | soft2 | ********.exe [* = random digit] | Added by the KARDPHISHER TROJAN! |
| U | Softany Monitor Control | MonitorControl.exe | Softany Monitor Control - "control your computer's monitor and screensaver" |
| N | SoftAuto.exe | SoftAuto.exe | Auto-updater for Creative Labs software |
| U | SoftBankBB_McciTrayApp | McciTrayApp.exe | System tray access to Motive's broadband configuration and repair utility - for SoftBankBB users |
| X | SoftBarrier | SoftBarrier.exe | SoftBarrier rogue security software - not recommended, removal instructions here. A member of the WiniGuard family |
| X | SoftCop | SoftCop.exe | SoftCop rogue security software - not recommended, removal instructions here. A member of the WiniGuard family |
| U | SoftGridTray | SFTTray.exe | System Tray access to SoftGrid from Microsoft - "the only virtualization solution that delivers applications that are never installed and dynamically delivered, on demand" |
| X | softIce Update 32 | wininits.exe | Added by the RBOT-ANB WORM! |
| U | SoftickPPP | PPPGate.exe | Softick PPP is a Microsoft Windows driver that allows to establish PPP session between Palm powered devices and Microsoft Windows desktop computer |
| Y | SOFTinst | N/A | For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out |
| U | SoftK56 Modem Driver | carpserv.exe | Associated with Zoltrix and Conexant modems - enables the internal modem speaker, allowing you to listen to the dial-up sounds for example |
| X | Softload | softload.exe | Added by the SDBOT-SV WORM! |
| X | SoftSafeness | SoftSafeness.exe | SoftSafeness rogue security software - not recommended, removal instructions here. A member of the WiniGuard family |
| X | SoftSoldier | SoftSoldier.exe | SoftSoldier rogue security software - not recommended, removal instructions here. A member of the WiniGuard family |
| X | SoftStronghold | SoftStronghold.exe | SoftStronghold rogue security software - not recommended, removal instructions here. A member of the WiniGuard family |
| U | SoftStuff Wallpaper Changer | softstrt.exe | AzureBay wallpaper changer |
| X | SoftVeteran | SoftVeteran.exe | SoftVeteran rogue security software - not recommended, removal instructions here. A member of the WiniGuard family |
| X | Software | software.exe | Added by the CRABTON-B TROJAN! |
| X | software | spools.exe | Added by the AUTORUN-CS WORM! |
| X | Software | cipsn.exe | Added by the FORBOT-DM WORM! |
| N | Software Manager | ISUSPM.exe | InstallShield is used by a number of software producers to install their programs and manage software updates. This entry searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis |
| X | Software Soft Stop | Spyware Soft Stop.exe | SoftStop rogue security software - not recommended |
| U | SoftwareStation | station.exe | eAcceleration Stop-Sign security software related - previously not recommended (see here). It has now been delisted, so make sure you have the latest version - hence the "U" recommendation |
| X | SolelunaAntiVirus | pgs.exe | SolelunaAntiVirus rogue security software - not recommended. A member of the AVSystemCare family |
| U | Solid Key Logger | SolidKeyLogger.exe | Solid Key Logger keystroke logger/monitoring program - remove unless you installed it yourself! |
| N | SolidCapture | solidcapture.exe | SolidCapture - screen capture and image sharing toolkit |
| U | SolidWorks Task Scheduler Engine | swBOEngine.exe | Task scheduler for SolidWorks 3D CAD software |
| Y | Solo Sentry | Solosent.exe | Solo Antivirus |
| U | SoloSchedule | Solocfg.exe | Scheduler for Solo Antivirus. Leave enabled unless you scan manually on a regular basis |
| U | SoloSysCheck | Syscheck.exe | Solo antivirus System Integrity Check - Monitors system registry, system.ini, win.ini and startup to protect you from new Internet Worms and Backdoors |
| X | SolutionReg | SysRep.exe | SolutionReg rogue system error and cleaning utility - not recommended. A member of the ErrClean family |
| X | somatic | somatic.exe | Searchcentrix hijacker |
| X | some | icthis.exe | Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machine. Various directories and filenames are used - see the link for details |
| X | some | scit.exe | Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machine. Various directories and filenames are used - see the link for details. This particular one is "NetProject" |
| X | some | wcs.exe | Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machine. Various directories and filenames are used - see the link for details |
| X | Somefox | [path to trojan] | Added by the DWNLDR-HHB TROJAN! |
| X | SondBlaster | lsass.exe | Added by the PROSTI.AA BACKDOOR! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Media |
| N | Sonic A3D Control | vrtxctrl.exe | Sound related options |
| X | Sonic RecordNow! | smsc.exe | Added by a variant of the SDBOT WORM! |
| N | SonicFocus | SFIGUI.EXE | Sonic Focus - "enhances music, movie and game sound by analyzing compressed audio streams in realtime, then restoring and enriching audio back to its original performance qualities" |
| N | SoniqueQuickStart | sqstart.exe | Quickstart for the discontinued Sonique audio player. Available via Start -> Programs |
| N | SonnReg | SonnReg.exe | Registration for Colorific® and 3Deep® monitor calibration software from E-Color. Now superseded by ColorWizzard and 3DxWizzard |
| X | SonudMan | SonudMan.exe | Added by the STARTPAGE.Q TROJAN! |
| X | SonudMan | WNILOGON.exe | Added by the QQROB-DC TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
| X | SonudMon | SonudMon.exe | Added by the LEWOR-J TROJAN! |
| N | Sony Auto Update Tray Application | CONNECTAUTrayApp.exe | System Tray access to change update settings for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP |
| N | Sony Ericsson PC Suite | Application Launcher.exe | System Tray access to Sony Ericsson PC Suite which "connects your phone to your computer and expands the capabilities of your phone". Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone |
| N | Sony Ericsson PC Suite | SEPCSuite.exe | System Tray access to Sony Ericsson PC Suite which "connects your phone to your computer and expands the capabilities of your phone". Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone |
| U | SonyPowerCfg | SPMgr.exe | Related to Sony VAIO Power Management Module installed on laptops and provides additional configuration options for these devices |
| ? | Soot | rcea.exe | ?? |
| ? | sophagnt | sophagnt.exe | Possibly related to Sophocles Screenwriting Software? |
| X | SOProc_RegSoAlertWxLiteNnAj | rundll32 shell32.dll, ShellExec_RunDLL [path] soproc.exe | SoftwareOnline Intelligent Downloader - "Bundle engine to enable download of end user approved third party applications and reporting of installs for billing purposes only". Said to monitor user's browsing habits and display pop-up ads |
| X | SOS | SOS.exe | Added by the PHILIS VIRUS! |
| ? | SoSyncMonitor | SoSyncMonitor.exe | SuperOffice related. What does it do and is it required? |
| X | Sound | [path to trojan] | Added by the DROPPER.EAT TROJAN! |
| X | Sound Loader | sndloader.exe | Added by the AGOBOT-BV WORM! |
| X | Sound services | SOUND32.EXE | Added by the AGOBOT.GG WORM! |
| X | Sound System | WinSound1.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Sound Volume | svchosI.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Sound.exe Espanha | Sound.exe | Added by the AGENT-OUD TROJAN! |
| X | soundcontrl | soundcontrl.exe | Added by the GAOBOT.AFJ WORM! |
| X | sounddrv | sndbdrv3104.exe | CoolWebSearch parasite variant |
| ? | SoundFusion | rundll32 cwcprops.cpl | Control panel item for the Terratec DMX Xfire 1024 soundcard (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time? |
| ? | SoundFusion | rundll32 hercplgs.cpl, BootEntryPoint | Control panel item for Hercules Fortissimo soundcards (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time? |
| ? | SoundFusion | RunDll32 cwaprops.cpl, C25CrystalControlWnd | Control panel item for a Terratec soundcard (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time? |
| X | SoundMam | SVOHOST.exe | Added by the QQROB-AAL TROJAN! |
| U | SoundMan | SOUNDMAN.EXE | Realtek Sound Manager, installed with the drivers for on-board Realtek HD and AC97 audio codecs. On an AC97 based system it gives System Tray access to the audio control panel (which is also available via the system Control Panel). On an ALC885 HD based test system it doesn't run after the drivers have been installed and the startup entry is then removed - disabling it appears to have no ill effects but it's exact purpose is unknown |
| X | SoundMan | soundman.exe | Added by the AGOBOT.HM WORM! Note - this is not the legitimate SiS or Realtek file of the same name that is located in %Windir%, this one is located in %System% |
| X | SOUNDMAN Microsoft Help | soun.pif | Added by the RBOT-AIU WORM! |
| X | soundman.exe | soundman.exe | Added by the AGENT-HKD TROJAN! Note - this is not the legitimate SiS or Realtek file of the same name that is located in %Windir%, this one is located in %System% |
| N | SoundMAX | Smax4.exe | System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel |
| X | SoundMAX | SoundMAX.exe | Added by the RIZON-A WORM! Note - this file is placed in the Startup folder itself, and has NO relation to SoundMax sound cards! |
| N | SoundMAX | soundmax.exe | System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel. Located in %ProgramFiles%\Analog Devices\SoundMAX |
| X | SoundMax | Soundmax.exe | Added by the MALAS-A VIRUS! Note - this file is located in %ProgramFiles%\Sound Utility and has NO relation to SoundMax sound cards! |
| X | SoundMax | startup.exe | Added by the MALAS-C WORM! |
| X | SoundMax Audio Drivers | SndMAX.exe | Added by a variant of the SDBOT WORM! |
| N | SoundMAX Control Panel | Smax4.exe | System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel |
| N | SoundMAX Integrated Digital Audio | Smtray.exe | System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel |
| U | SoundMAXPnP | SMax4PNP.exe | Analog Devices SoundMax integrated soundcard utility. Brings up the SoundMAX Control Panel when it detects if new audio devices (such as microphones, headphones, speakers, etc.) are plugged in - giving the user the option to configure them. Also required if you have custom settings for your sound, such as effects and environments |
| X | soundmix | soundmix.exe | Added by the AGENT.PGV WORM! |
| X | SoundMixer | smvss.exe | Added by the DEDLER-G TROJAN! |
| X | SoundMnEx32 | [path to worm] | Added by the STRATION-FW WORM! |
| X | Soundmx | Soundmx.exe | CoolWebSearch Tapicfg parasite variant |
| X | soundtask | soundtask.exe | Added by the AGOBOT-MD WORM! |
| X | soundtasks | soundtasks.exe | Added by a variant of the CRYPTER.C TROJAN! |
| X | soundtctrls | soundtctrls.exe | Added by the AGOBOT-ZV WORM! |
| X | SoundView | msdview32.exe | Trojan downloader |
| X | sounofts | sounofts.exe | Added by the AGOBOT-ND WORM! |
| X | sountskmanager | sountaskmgr | Added by an unidentified WORM or TROJAN! |
| N | SourcePath | gwreg.exe | Used to update Gateway registry settings for System Restoration Kit and Web update programs |
| X | sp | sp.reg | IE search hijacker - changes the default search to http://www.gocybersearch.com/ |
| X | sp | regedit -s sp.dll | Malicious javascript annoyance that changes the default search engine in IE to one of many including "topsearcher". See here for more and a fix. The "sp.dll" is located in %Windir% |
| X | sp | se.dll,DllInstall | STARTPAGE.M hijacker |
| X | sp | rundll32 (Path to Trojan DLL), DllInstall | Added by the ABLANK-W and ABLANK-Z TROJANS! |