| Status | Autorun name | Command | Description |
| U | SendMail | SendMail.exe | Part of the MySuperSPy surveillance software. Uninstall this software unless you put it there yourself. Located in %ProgramFiles%\Myss |
| U | SENS Keyboard V4 Launcher | SENSKBD.EXE | Hot-key manager for some Samsung notebooks - required if you use the keys |
| U | SENS Keyboard V6 Launcher | SENSKBD.EXE | Hot-key manager for some Samsung notebooks - required if you use the keys |
| U | Sensiva | Sensiva.exe | Symbol Commander makes the use of your PC, laptop, Tablet PC, and Pocket PC much easier and much faster. It recognizes your handwriting with unparalled performance and executes commands in a snap. Just by using your mouse, pen, or touchpad, simply draw symbols to execute actions instantly |
| Y | Sensor | sensor.exe | Part of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. Optionally scans the system boot area for programs trying to automatically execute before Windows loads and keeps a watch on some system files which are commonly patched (or replaced) by malware. Feature not supported on Windows 7/Vista systems. Also included by vendors who use the Quick Heal engine such as Omniquad and iQon |
| U | sentinelmon | sentinelmon.exe | PCSentinel's Smoking Gun! surveillance software. Uninstall this software unless you put it there yourself |
| X | SENTRY | SENTRY.exe | From IP Insight. Allows website owners "to instantly determine the precise geographic location, connection speed and detailed demographics of every visitor to your website". Will be detected by most firewalls and the majority of home users should disable it |
| X | Sepate Security Firewall | sepate.exe | Added by the RBOT.BLC BACKDOOR! |
| N | SEPCSuite | SEPCSuite.exe | System Tray access to Sony Ericsson PC Suite which "connects your phone to your computer and expands the capabilities of your phone". Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone |
| X | septpop06apsept | septpop06apsept.exe | MediaMotor.Popupwithcast adware |
| X | Serials | serials.exe | Any one of a variety of worms and trojans |
| X | Serices Hostin | servicez.exe | Added by the SLENFBOT.MF WORM! |
| X | SErmYcVkqxT | SErmYcVkqxT.exe | Added by the CEEINJEC-K TROJAN! |
| X | SernellApp.pcx | csrss.exe | Added by the BANCBAN-BJ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "D5133" subfolder |
| X | serpe | formatsys.exe | Added by the SERFLOG.A WORM! |
| X | serpe | msmbw.exe | Added by the SERFLOG.A WORM! |
| X | serpe | serbw.exe | Added by the SERFLOG.A WORM! |
| Y | serrdctl.exe | serrdctl.exe | "Shared Modem Service Client Event Viewer" - used when a number of PCs have access to a number of modems. Required to be running on each PC for access to the modems |
| X | serrv | serrv.exe | Added by the WAREZOV.DC WORM! |
| X | Serv | SYS.VBS | Added by the AUTORUN-BNQ WORM! |
| X | SERV PacK2 | nerx.exe | Added by the SDBOT-ACP WORM! |
| N | Serv-U | serv-u32.exe | FTP server |
| X | Serv-U | wssdsu.exe | Added by the MANIFEST TROJAN! |
| U | Serv-U-Tray | Serv-U-Tray.exe | System Tray access for the Serv-U FTP server which allows the user to (amongst others) start the Management Console, stop the server and display notifications |
| U | Serv-U® File Server | Serv-U-Tray.exe | System Tray access for the Serv-U FTP server which allows the user to (amongst others) start the Management Console, stop the server and display notifications |
| X | server | server.exe | Added by the DELTAD.A WORM! |
| X | server | system.exe | Added by the METHS-A TROJAN! |
| X | server | server.exe | Added by the SINGU-Q TROJAN! |
| Y | Server Application for MFP Server | ServoApp.exe | Multi Function Printer (MFP) server agent for products such as Belkin's Wireless G All-in-One Print Server and ZyXEL's NPS-520 which allow multiple computers to use networked all-in-one printers. Required for the MFP Server Agent (MFPAgent.exe) to run properly - whether it's set to start manually or automatically |
| X | Server Backbone | server05.exe | Added by the RBOT-ZM WORM! |
| X | Server Daemon Host Manager | sdhost.exe | Added by the RBOT-GWC WORM! |
| X | Server Registry | regsrv32.exe | Added by the VB-EJD TROJAN! |
| X | Server Registry | regscr32.exe | Added by the BIFROSE-ZB TROJAN! |
| X | Server Runtime Error | unsec.exe | Added by the SDBOT-DFA WORM! |
| X | Server Runtime Process | wbemstest.exe | Added by the SDBOT-DDB WORM! |
| X | SERVER.EXE | SERVER.EXE | Added by the BUSHTRO122 or SMOKODOOR TROJANS! |
| X | serverex | Server.txt.vbs | Added by the DELTAD.A WORM! |
| X | Serverx | Serverx.exe | Added by the MADANGEL VIRUS! |
| X | Service | service.exe | Added by the ALADINZ.H TROJAN! |
| X | Service | [trojan filename] | Added by the KAITEX.E TROJAN! |
| X | Service | services.exe -serv | Added by the NETSKY or NETSKY.B WORMS! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Service | SYSNT.exe | Added by the CHA TROJAN! |
| X | Service | Service.pif | Added by the ASSIRAL-C WORM! |
| X | service | wN2S.exe | Added by a variant of the RBOT WORM! |
| U | service | msview32.exe | BestIdol adware |
| X | Service ares | conmysys.exe | Added by the VBINJ-V WORM! |
| X | Service ares | tanga.exe | Added by the IRCBOT-AHO TROJAN! |
| U | Service Centre | launcher.exe | Management tool for the Open Networks iConnect series of products - as used by Australian ISP's such as iiNet and Hotkey |
| X | Service Cleaner | filen.exe | Added by the RBOT.BRH WORM! |
| X | Service Client | winsvcli.exe | Added by an unidentified WORM or TROJAN! See here |
| N | Service Connection | sccenter.exe | For Compaq PC's. Part of Backweb |
| N | Service Connection | bwtray.exe | For Compaq PC's. Part of Backweb |
| X | Service Control Manager | scm.exe | Added by the AGOBOT-GD BACKDOOR! |
| X | Service Controller | Csrrs.exe | Added by the GAOBOT.AO WORM! |
| X | Service Controller | service.exe | Added by the PREVERT TROJAN! |
| X | Service Defender | [random filename] | Added by a variant of the ZLOB TROJAN! See here |
| X | Service Drivers | msnpg.exe | Added by the RBOT.BMD WORM! |
| X | Service Drivers | PC.EXE | Added by the SDBOT-WK WORM! |
| X | Service Drivers | Compt.exe | Added by the RBOT-ZJ WORM! |
| X | Service Drivers | abl.exe | Added by the SDBOT-YX WORM! |
| X | Service Drivers | MSNMEssenger.exe | Added by a variant of the RBOT WORM! |
| X | Service Host | svchost.exe | Added by the TORVEL WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Service Host | [filename].exe | Added by the TORVEL.B WORM! |
| X | Service Host | spoolxx.exe | Added by the TORVEL WORM! |
| X | Service Host | svchost.exe | Added by the DAOSER-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\Services\{C922CCC4-CF61-4589-A0D1-828160704853} |
| X | Service Host | svchost.exe | Added by the DAOSER-C TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\Services\[random] |
| X | Service Host | svchosts.exe | PornCleanser spyware |
| X | Service Host | tm32.exe | Added by the POISON-AG TROJAN! |
| X | Service Host Driver | svchost.exe | Added by the HITON TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Service Host Manager | svchost.exe | Added by the AUTORUN-CQ WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile% |
| X | Service Host Process | spoolsvc.exe | Added by the GAOBOT.GEN!POLY WORM! |
| N | Service Manager | sqlmangr.exe | SQL Server Service Manager - provides tray access to SQL server, the server agent and MSDTC. Available via Start → Programs |
| X | Service Manager | SERVICEMGR.EXE | Added by the PASSMAIL-D VIRUS! |
| X | Service Manager | dxsound.exe | Added by the PROXY-GRIC TROJAN! |
| X | service manager | service.exe | Added by the DONBOMB.A TROJAN! |
| X | Service Manager | serv3manager.exe | Added by the SDBOT-AGO WORM! |
| X | Service Monitor | msnfilen.exe | Added by the RBOT-ALE WORM! |
| X | Service Monitor | javams32.exe | Added by the DELF-NK TROJAN! |
| X | Service Monitor | javams64.exe | Added by the SDBOT-AFO WORM! |
| X | Service Monitor | msnserve.exe | Added by the SPYBOT.YQW WORM! |
| X | Service Monitor | WinOcx.exe | Added by the RBOT-AQJ WORM! |
| X | Service Monitor | csnss.exe | Added by the RBOT.EEH BACKDOOR! |
| X | Service Monitor | filen.exe | Added by a variant of the RBOT WORM! |
| X | Service Monitor | winxpser.exe | Added by the RBOT-BDF WORM! |
| X | Service Noits | winservl.exe | Added by the MDROP-DKO TROJAN! |
| X | Service Nouts | winservi.exe | Added by the AGENT-RDZ TROJAN! |
| X | Service Pack | [various filenames] | Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe, common.pif, common.scr, Sexo.exe, Sexo.jpg.pif, ini_file__.pif, load_me__.tmp, msfile.pif, system_load_.pif or zipped.rar.pif |
| X | Service Pack 1 | [random filename] | Added by the VXGAME.Z TROJAN! Note - the filename is random - see the link. Typical examples are vexg6ame4.exe, vexga3me2.exe, vexga4m1et4.exe, etc |
| X | Service Pack 1 | SPY_NET_RAT.exe | Added by the AGENT-LRO TROJAN! |
| X | Service Pack 2 | SPY_NET_RAT.exe | Added by a variant of the AGENT-LRO TROJAN! See here and here |
| X | Service Pack DLL Runtime | spdll32.exe | Added by a variant of the RBOT WORM! |
| X | Service PAck SFVP | [worm filename].exe | Added by a variant of the RBOT WORM! The filename is 4 random characters |
| X | Service Process | SVCHOST.EXE | Added by the DARKER WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Service Process | winset.exe | Added by a variant of the SPYBOT WORM! |
| X | Service Process | service.exe | Added by the DCMBOT-C TROJAN! |
| X | Service Process | smss.exe | Added by the DCMBOT-E TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "config" subfolder |
| X | Service Process | svchost.exe | Added by the DCMBOT-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "config" subfolder |
| X | Service Registry NT Save | jdbgmgrnt.exe | Added by the BANCOS-CG TROJAN! |
| X | Service Registry NT Save | taskmgrnt.exe | Added by the BANCOS-BY TROJAN! |
| X | Service Registry NT Save | regeditnt.exe | Added by the BANCOS-BM TROJAN! |