| Status | Autorun name | Command | Description |
| U | Support.com Scheduler and Command Dispatcher | tgcmd.exe | Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers, fix faults, etc. Also see the TgAddServer entry. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation" |
| X | supporter5 | supporter5.exe | Part of eScorcher anti-virus software- responsible for updates of new virus bases each time you logon to the web. Used to collect information about the user and therefore treated as spyware - now the web-site is dead |
| X | Supports RAS Connections | svhost.exe | Added by the RBOT-GXH WORM! |
| U | SureCleanProfessional | SRClean.exe | SureClean PC and Internet tracks cleaner |
| U | Sureshotpopupkiller | Stopthepop.exe | Stop-the-Pop-Up popup blocker |
| U | Sureshotpopupkiller | pusak.exe | Stop-the-Pop-Up popup blocker |
| X | SurfAccuracy | sacc.exe | SurfAccuracy adware |
| X | SurfBuddy | rundll32 [path] sbuddy.dll | SurfBuddy adware - not to be confused with the legitimate SurfBuddy application by SurfApps!. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| U | SurfChoice | SCMan.exe | SCMan is a utility that can control services on WinNT from the command line. This utility can create, start, pause, stop, delete services. Furthermore it can retrieve a service's current state, get the displayname for a service and vice versa |
| X | Surfer lptt01 | surfer.exe | RapidBlaster variant (in a "mssurfer" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | Surfer ml097e | surfer.exe | RapidBlaster variant (in a "mssurfer" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| U | SurfHelper | SurfHelp.exe | Related to SurfHelper - a free tool to remove popup windows, clear history, control window properties of IE, and more |
| U | SurfinGuard Pro | winsfcm.exe | SurfinGuard Pro from Finjan - internet protection software, protects against all malicious code delivered through executables, scripting files, ActiveX and Java |
| U | SurfSecret | ss2-full.exe | Privacy Protector from SurfSecret - internet history and file cleaner "is an easy and powerful tool for users who hold their online privacy sacred" |
| X | SurfSideKick | Ssk.exe | SurfSideKick adware |
| X | SurfSideKick 2 | Ssk.exe | SurfSideKick adware |
| X | SurfSideKick 3 | Ssk.exe | SurfSideKick adware |
| U | SurfStream | SurfStream.exe | Conceiva "SurfStream lets you surf the Web faster. It contains a fully featured proxy server that lets you surf the Web significantly faster. It also blocks all pop-up windows and banner ads from Web pages. An intelligent tune-up tool automatically analyzes and optimizes your computer's Internet connection and TCP/IP settings" |
| X | Surs | awab.exe | PurityScan adware |
| N | Surveysa | surveysa.exe | Found on Sony laptops, it brings up a prompt to take a survey. It goes away if you fill out the survey or you choose "never prompt me again" but keeps popping if you either exit out of it or select "take survey later" |
| N | suScheduler | UCLauncher.exe | Scheduler for versions of ThinkVantage System Update (for software updates) found on IBM/Lenovo ThinkCentre/ThinkStation desktops and Thinkpad notebooks |
| X | Susp | Susp.exe | VX2.Transponder parasite updater/installer related |
| X | SuspenzorPC | GDC.exe | SuspenzorPC Czech rogue privacy tool - not recommended. A member of the PCPrivacyTool family |
| X | susse | hpsw.exe | LinkMaker adware |
| X | Sustem | explorer.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! |
| X | SustemUpdate | explorer.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! |
| X | SV00LSV | SV00LSV.EXE | Added by the GRAYBIRD-C TROJAN! |
| X | SVA Player | SVAplayer.exe | SVAPlayer parasite |
| X | Svc | svc.exe | ClientMan parasite variant |
| U | SVC | svchost.exe | ElfSpy keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | svc | expseny.exe | Added by the PWS-ANG TROJAN! |
| X | SVC Service | svcinit.exe | Added by the SINIT TROJAN! |
| X | SVC Service | svcinit.exe | CoolWebSearch parasite variant |
| X | SVC Service | svcpack.exe | CoolWebSearch Svcinit parasite variant |
| X | SVC Service | svc32.pif | Added by the RBOT-ASC WORM! |
| X | SVC Socks | mstaskm.exe | CoolWebSearch parasite variant |
| X | svc32 | svc32.exe | Identified as a variant of the Banker-EQC/DLoader.GPJI malware |
| X | svcdata.exe | svcdata.exe | Added by the SPYBOT.ZIF WORM! |
| X | Svced | Svced.exe | Added by the DELF.F TROJAN! |
| X | SvcH0st | msexploren.exe | Added by the BACKDOOR-CGZ TROJAN! |
| X | SvcH0st | SHCH.EXE | Added by the BDOOR-EB BACKDOOR! |
| X | SvcH0st | SVCHST.EXE | Added by the BDOOR-EB BACKDOOR! |
| X | SvcH0st | WINAGENT.EXE | Added by the BDOOR-EB BACKDOOR! |
| X | SVCH0ST | spoo1sv.exe | Added by the VB-HF TROJAN! |
| X | SVCH0ST | SVCH0ST.EXE | Added by the VB-IK TROJAN! Note - the filename has the digit 0 rather then the uppercase "o" |
| X | SvcH0st | msnexploren.exe | Added by the TACTSLAY.B TROJAN! |
| X | SvcH0st | sdhch.exe | Added by the TACTSLAY.B TROJAN! |
| X | SVCH0ST.EXE | SVCH0ST.EXE | Added by the BANCBAN-HT TROJAN! |
| X | SVCH0TS | sp00lvs.exe | Added by the LINEAGE-AZ TROJAN! |
| X | svchast | svchast.exe | Added by the LINEAGE-AV TROJAN! |
| X | svchctrl | svchctrl.exe | Added by the NURECH TROJAN! |
| X | svchos | svchos.exe | Added by the EZIBOT-B TROJAN! |
| X | svchosd | [path to trojan] | Added by the BANCOS-BCX TROJAN! |
| X | SVCHOSI | SVCHOSI.EXE | Added by the VBBOT-AA WORM! |
| X | SVCHOST | scvhost.exe | Added by the MYTOB.E or MYTOB.G WORMS! |
| X | SVCHOST | taskgmr.exe | Added by the MYTOB.F or MYTOB.H WORMS! |
| X | svchost | olehelp.exe | Added by the BOOKMARKER.G TROJAN! |
| X | SVCHOST | updater32.exe | Added by the RANTS.A WORM! |
| X | SVCHOST | SPOOLSV.EXE | Added by the BAITAP-A WORM! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir% |
| X | SvcHost | svchost32.exe | Added by the AGOBOT-TM WORM! |
| X | svchost | svchost.exe | Added by the BANCBAN-HL TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\config |
| X | SVCHOST | MDM.EXE | Added by the LCJUMP-A WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or %System% (Me only). This one is located in %Windir% |
| X | svchost | [path to explorer.exe] | Added by the UNREAL-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! |
| X | svchost | rundll16.exe | Added by the STARTPA-PB TROJAN! |
| X | Svchost | svchost.exe | Added by the ADCLICK-AM TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Internet Explorer |
| X | svchost | svchost.exe | Added by the BDOOR-ES BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "Microsoft" subfolder |
| X | svchost | svchost.exe | Added by the DLOADER-EV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles% |
| X | svchost | winhelp.exe | Added by the GAOBOT.GEN!POLY WORM! |
| X | Svchost | svchots.exe | Added by the RBOT.ADK WORM! |
| X | svchost | ying.exe | Constructor VC2000 malware |
| X | svchost | inetinfo.scr | Added by the ODELUD WORM! |
| X | SVCHOST | svchost64.exe | Added by the STARTP-G TROJAN! |
| X | svchost | svchost.com | Added by the BANLOA-ABL TROJAN! |
| X | svchost | win.exe | Added by the VBSAUTO-A WORM! |
| U | svchost | svchost.exe | Infine Keylogger surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup. This one is located in an "svc" subfolder |
| X | svchost | logon.exe | Added by the SLEGON WORM! |
| X | svchost | svcst.exe | Added by the AGENT-LIL WORM! |
| X | svchost | svchost.exe | Added by the VB-EOK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "MsDtds" sub-directory |
| X | svchost | windowsrx.exe | Added by the AGOBOT-MZ WORM! |
| X | SVCHOST | SERVlCES.EXE | Added by the DELF-LF BACKDOOR! Note that the filename has a lower case "L" in place of an upper case "i" |
| X | Svchost | winprint.exe | Added by the AGENT-PGT TROJAN! |
| X | svchost | conhost.exe | Added by variants of the BACKDOOR-EXI.GEN.E TROJAN! See examples here and here. Note - this is not the legitimate Microsoft Windows 7 process with the same filename which is used to host the cmd.exe console window and is located in %System%. This one is located in %AppData%\Microsoft |
| X | svchost | svchost.exe | 2Search adware. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\2search |
| X | Svchost | taskmmgr.EXE | Added by the AUTORUN-F WORM! |
| X | SVCHOST | svchost.exe | System1060 homepage hi-jacker. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\System1060 |
| X | svchost | svchost.exe | Added by many TROJANS amd WORMS, such as MORB or TARNO. Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup! |
| X | SVCHOST | mrowyekdc.exe | Added by the GOTORM WORM! |
| X | svchost | Svch0st.exe | Added by the GRAYBIRD and GRAYBIRD.B TROJANS! Note - the filename has the digit 0 rather then the uppercase "o" |
| X | svchost | [path to trojan] | Added by the HAZZER TROJAN! |
| X | svchost | ADMAGIC.EXE | Added by the SMIBAG WORM! |
| X | Svchost | winhost.exe | Added by the LOLAWEB.A TROJAN! |
| X | Svchost | svchost.exe | Added by the MOZE-A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | SVCHOST | var.txt.exe | Added by the LDPINCH.C TROJAN! |
| X | Svchost | svchosl.pif | Added by the INZAE.A or INZAE.B WORMS! |
| X | svchost | [path] SETUP.EXE | Added by the SETCLO WORM! |
| X | svchost Agent | svchost.exe | Added by the AUTORUN-DB WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "28463" sub-folder |
| X | svchost connection monitor | svchost32.exe | Added by a variant of the SDBOT WORM! |
| X | SVCHOST Generic application | svchost.exe | Added by the DAEMONI-K TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | svchost Netware Manager | svchost.exe | Added by the EXVID.A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | SVCHost Protocol32 | scvhost32.exe | Added by a variant of the IRCBOT TROJAN! |