| Status | Autorun name | Command | Description |
| U | StrokeIt | strokeit.exe | StrokeIt is an "advanced mouse gesture recognition engine and command processor" |
| X | strpmon | strpmon.exe | Part of BugsDestroyer, ProtectingTool and other members of the ErrClean rogue system error and cleaning utility and other members of this family. See here for more examples |
| X | strtas | lock1.exe | Added by the SDBOT-ADQ WORM! |
| X | strtas | lockx.exe | Added by the SDBOT-AEB WORM! |
| X | strtas | l074.exe | Added by the AGENT-II TROJAN! |
| X | strtas | loc1.exe | Added by the RBOT-AZU TROJAN! |
| X | strtas | lo71.exe | Added by the SDBOT-AGT WORM! |
| X | strto | strto.exe | Added by the KILLPROC-F TROJAN! |
| X | strto | [path to trojan] | Added by the KILLAV-AP TROJAN! |
| Y | strtupap | strtupap.exe | Launcher for the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. Replaces the individual startup entries from older versions - such as Email Protection (EMLPROUI.EXE), Update Scheduler (UPSCHD.EXE), On-Line Protection (CATEYE.EXE) and Messenger (SCANMSG.EXE) |
| X | Sts | iwnujdss2.exe | Added by the SDBOT-YI WORM! |
| X | Stubbish | Stubbish.exe | Added by the STUBBOT-A WORM! |
| X | StubPath | Sservice.exe | Added by the PRORAT TROJAN! |
| X | stup | 138762763.exe | Added by the FIRESPY-A TROJAN! It will attempt to register the dropped component as a Firefox plugin and begin monitoring the user's browsing habits, stealing information including monitoring and logging information from Web forms |
| X | stup | [path to trojan] | Added by the AGENT-CIL TROJAN! |
| X | stup.exe | stup.exe | Added by the QQROB.LE TROJAN! |
| X | stup1db0t | _win.exe | Added by a variant of the IRCBOT BACKDOOR! |
| N | StupAssist | StupAssist.exe | Associated with Nikon digital cameras |
| X | STV | winscrne.exe | Added by a variant of the SDBOT WORM! |
| U | StxMenuMgr | StxMenuMgr.exe | Status manager for the Seagate range of external hard drives. It monitors your PC to see if you have connected any supported drives to launch the backup utility |
| X | stxrmsgms | mstats.exe | Added by the IRCBOT-AE TROJAN! |
| U | StxTrayMenu | StxMenuMgr.exe | Status manager for the Seagate range of external hard drives. It monitors your PC to see if you have connected any supported drives to launch the backup utility |
| U | StyleXP | StyleXP.exe | StyleXP allows you customize the way WinXP looks. If disabled via msconfig it re-instates itself at reboot, therefore uninstall it if you don't want it |
| X | suapafjj | kgejbaytssd.exe | Added by the AGENT-MXH TROJAN! |
| X | SubAH | SubAH.exe | Added by the SUBAH TROJAN! |
| U | Subliminal Power | Subliminal.exe | Subliminal Power - displays subliminal messages of your choice on your computer screen |
| N | Subtract the Ads | AdSub.exe | Removes adverts from web pages. Although useful - not required |
| X | suck | l0ad.exe | PurityScan adware |
| X | suicide | tempfile2.bat | Personal Protector rogue security software - not recommended, removal instructions here |
| U | Suitcase Startup | Suitcase.exe | Suitcase - system font manager start up utility. Used for dynamic managment of fonts on your system |
| X | Suite | SuiteOffices.exe | Added by the LAZAR TROJAN! |
| X | SULFNBJ.EXE | SULFNBJ.EXE | Added by the PE_MAGISTR.DAM VIRUS! |
| X | Sun Java Console for Windows NT & XP | jconsole.exe | Added by the VANEBOT-C WORM! |
| X | Sun Java Updater | stacsv.exe | Added by the BUZUS.DBFM TROJAN! |
| X | Sun Java Updater v5 | javajre.exe | Added by the AUTORUN-XI WORM! |
| X | Sun Java Updater v7.11 | jucshed.exe | Added by the AUTORUN-ABH WORM! |
| X | Sun Java Updater v7.4 | javawx.exe | Added by the ACKANTTA.B WORM! |
| U | sunasDTServ | sunasDtServ.exe | CounterSpy by GFI Software (formerly Sunbelt Software) - adware/spyware protection |
| U | sunasServ | sunasServ.exe | CounterSpy by GFI Software (formerly Sunbelt Software) - adware/spyware protection |
| X | Sunjava | javasmart.exe | Added by the AGENT.AHV TROJAN! |
| X | SunJava Updater v7 | javale.exe | Added by the ACKANTTA.B WORM! |
| X | SunJavaMdb | svchosf.exe | Added by the BANBRA.GQU TROJAN! The file is typically located in %UserProfile%\InstallShield Installation Information\{A5BA14E0-7384-5991B8648CBE70A4} |
| X | SunJavaSched | ccEvtMngr.exe | Added by the SDBOT-YP WORM! |
| X | SunJavaSched Updater | avamx.exe | Added by the RBOT-ABJ WORM! |
| X | SunJavaUpdate | smvss.exe | Added by the DEDLER-G TROJAN! |
| X | SunJavaUpdater | javaw.exe | Added by the MYTOB.QR WORM! Note - this is not the legitimate Oracle (was Sun Microsystems) file of the same name located in %ProgramFiles%\Java which is used to view Java applications. This one is located in %System% |
| X | SunJavaUpdaterv12 | javajar.exe | Added by the VBINJECT-D MALWARE! |
| X | SunJavaUpdaterv13 | javaupdater.exe | Added by the ROUTROBOT WORM! |
| N | SunJavaUpdateSched | jusched.exe | Checks with Oracle's (was Sun Micrsosystems) Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now |
| X | SunJavaUpdateSched | [path to trojan] | Added by the BANKER-AU TROJAN! |
| X | SunJavaUpdateSched | scvhost.exe | Added by the SDBOT-AVX WORM! |
| X | SunJavaUpdateSched | javamx.exe | Added by the SDBOT-WI WORM! |
| X | SunJavaUpdateSched | javaupd.exe | Added by the SISCOS.VA TROJAN! |
| X | SunJavaUpdateSched | jusched.exe | Added by the AGENT.ETQ TROJAN! Note that this is not the legitimate Oracle (was Sun Microsystems) file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %ProgramFiles%\Common Files |
| X | SunJavaUpdateSched | rundll32.exe | Added by the VBKRYPT.FNL TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (Windows 7/Vista/XP/2K/NT). This one is located in %AppData% |
| X | SunJavaUpdateSched v2 | jushed.exe | Added by the ACKNATTA.B WORM! |
| X | SunJavaUpdateSched v3 | jucshed.exe | Added by the AUTORUN-ABC WORM! |
| X | SunJavaUpdateSched v3.3 | jushed.exe | Added by the BUZUS.ASUU WORM! |
| X | SunJavaUpdateSched v3.4 | jshed.exe | Added by the BUZUS.AUUB TROJAN! |
| X | SunJavaUpdateSched v3.5 | javacq.exe | Added by the PROLACO-A WORM! |
| X | SunJavaUpdateSched10 | jushed.exe | Added by the ACKANTTA.F WORM! |
| X | SunJavaUpdateSched132 | jschd.exe | Added by the AUTORUN-AQY WORM! |
| X | SunJavaUpdateSched16 | jvshed.exe | Added by the ACKANTTA.G WORM! |
| X | SunJavaUpdatSched | spoolsv.exe | Added by the BANCBAN-NP TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %ProgramFiles%\MSN Messenger |
| U | Sunkist | shwicon98.exe | Card reader for memory cards from digital cameras, etc |
| U | Sunkist2k | shwicon2k.exe | Card reader for memory cards from digital cameras, etc |
| U | SunKistEM | shwiconem.exe | Used by your computer to communicate with your Alcor Micro Multimedia Card Reader - necessary if you're using this software |
| U | SuNotification | suatshut.exe | ShadowSurfer - "provides a safe computing environment by creating a virtual twin of your PC. Restore the pre-ShadowMode system state no matter what changes have occurred to your PC" |
| Y | SunProtectionServer | SunProtectionServer.exe | CounterSpy antispyware software |
| Y | SunServer | SunServer.exe | CounterSpy antispyware software |
| U | Sup_SmartRAM | Sup_SmartRAM.exe | SmartRAM - the memory management part of the Advanced SystemCare 3 optimization utility from IObit - which "monitors you system in the background and frees up memory whenever needed to increase the performance of your computer." Note - in November 2009 IObit were accused of stealing database information from Malwarebytes' Anti-Malware and others so review the links on the Wikipedia page and make your own mind up |
| U | Sup_SmartRAM.exe | Sup_SmartRAM.exe | SmartRAM - the memory management part of the Advanced SystemCare 3 optimization utility from IObit - which "monitors you system in the background and frees up memory whenever needed to increase the performance of your computer." Note - in November 2009 IObit were accused of stealing database information from Malwarebytes' Anti-Malware and others so review the links on the Wikipedia page and make your own mind up |
| ? | SupaDial | SupaDial.exe | SupaNet.com modem driver related - is it required? |
| N | Supastatus | status.exe | Supanet ISP software |
| X | supdate | supdate.exe | Added by the MALWARE.D TROJAN! |
| X | supdate2.dll | rundll32.exe supdate2.dll,Run | Added by the ZLOB-VL TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "supdate2.dll" file is found in %System% |
| X | supdate2.dll | regsvr32.exe /s supdate2.dll | Added by the ZLOB-VL TROJAN! Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The "supdate2.dll" file is found in %System% |
| X | super | fuckbx.exe | Added by the LINEAGE-H TROJAN! |
| X | super | super.exe | Added by the AGOBOT-QT WORM! |
| U | Super Popup Blocker | popkill.exe | Saga Super Popup Blocker - pop-up stopper |
| U | Super X Desktop Version 3.4 | SXDesk.exe | Super X Desktop - virtual desktop manager |
| U | SuperAdBlocker | SAdBlock.exe | SuperAdBlocker |
| Y | SUPERAntiSpyware | SUPERAntiSpyware.exe | SUPERAntiSpyware - spyware, malware and other threat remover |
| X | SuperBar.Component | services.exe | FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an "Inetsrv" subfolder |
| X | SuperBar.Component | [path to services.exe] | Added by the SMALL-AQ TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\Inetsrv |
| U | Supercleaner | Supercleaner.exe | Supercleaner - all in one disk cleaner for your computer |
| U | SuperCool Compress Backup | Main.exe | "SuperCool Zip Backup software is a data backup, restore and file synchronization program" |
| U | SuperCopier2.exe | SuperCopier2.exe | "SuperCopier replaces windows explorer file copy and adds many features" |
| X | SuperHeissSex | SuperHeissSex.exe | HeissSex premium rate adult content dialer! |
| X | supernews12 | newsd32.exe | Adware, also detected as the DLOADER-JN TROJAN! |
| X | Supernova | [worm filename] | Added by the SURNOVA.A (or SUPOVA) WORM! |
| X | Supernova | Blaargh.exe | Added by the SUPOVA.E WORM! |
| X | superproxy | superproxy.exe | Added by the DELBACK-B TROJAN! |
| U | SuperRam | SuperRam.exe | SuperRam memory manager. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See SuperRam article and make up your own mind |
| X | superslut | msslut32.exe | Added by the SLUTER-A WORM! |
| U | SuperSpamKiller Pro | Ssk.exe | SuperSpamKiller Pro email spam blocker |
| X | SuperVaccineMain | SuperVaccine.exe | SuperVaccine rogue security software - not recommended, removal instructions here |
| X | Supervise.exe | Supervise.exe | Added by the DELF-DZX TROJAN! |
| X | Supervisor.exe | Supervisor.exe | Has been reported to be associated with various antitrojan software like ATS and PC Doorguard. If so it's required in Startup - any further information is welcome |
| X | support-reverse-smileys | [trojan filename] | Added by the LITEBOT TROJAN! |