| Status | Autorun name | Command | Description |
| X | servico | servico.exe | Added by the BANKER-DKE TROJAN! |
| X | Servicos | AdobeLanc.exe | Added by the BANKER-EHR TROJAN! |
| X | Servicos | System.exe | Added by the BANCOS-BCM TROJAN! |
| X | servics | servics.exe | Added by the SINGU-J TROJAN! |
| X | servises | servises.exe | Added by the AGENT-JUJ WORM! |
| X | SERVlCE | SERVlCE.EXE | Added by the AGOBOT-UB WORM! |
| Y | ServoApp | ServoApp.exe | Multi Function Printer (MFP) server agent for products such as Belkin's Wireless G All-in-One Print Server and ZyXEL's NPS-520 which allow multiple computers to use networked all-in-one printers. Required for the MFP Server Agent (MFPAgent.exe) to run properly - whether it's set to start manually or automatically |
| X | ServRun | srss32.exe | Added by the AGOBOT.ABS WORM! |
| N | ServUTrayIcon | ServUTray.exe | System Tray access for the Serv-U FTP server which allows the user to (amongst others) start the Management Console, stop the server and display notifications |
| U | ServUTrayIcon | Serv-U-Tray.exe | System Tray access for the Serv-U FTP server which allows the user to (amongst others) start the Management Console, stop the server and display notifications |
| X | SES Service | sesvc.exe | Added by the SDBOT-CZU WORM! |
| U | Session Client | sescli.exe | SurfSpy keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | Session Manager Subsystem | smssa.exe | Added by the RBOT-AGS WORM! |
| X | SessionInit | init.exe | Added by the FAKEAV-BRZ TROJAN! |
| X | SessionMngr | dirlock.exe | Added by the DAPROSY WORM! |
| X | SessMgr | sessmgr.exe /waitservice | Added by the HORST.Q TROJAN! Note - this is not the legitimate sessmgr.exe which is always located in %System%. This one is located in either %Windir%, %Windir%\System, %Temp%, %AppData%, %AppData%\Microsoft or %System%\drivers |
| X | SESync | sed.exe | DownloadWare adware |
| ? | SetCacheMode | rundll32.exe ptipbmf.dll, SetWriteCacheMode | Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. May be necessary in order to maintain preferences applied to the RAID array connected to the Promise controller |
| ? | SetDefaultMIDI | MIDIDef.exe | Related to a Soundblaster Audigy soundcards. What does it do and is it required? |
| Y | SetDefaultPrinter | cloaker.exe | Used by HP and Compaq computers to hide the windows of programs passed as arguments to it |
| N | setdefprt | setdefprt.exe | Used to set a Brother MFC printer/copier/scanner as the default printer after installation |
| N | SetDefPrt | BrStDvPt.exe | Used to set a Brother MFC printer/copier/scanner as the default printer after installation |
| U | SetecCertUtil | Certutil.exe | Setec Web and Email Security. Setec PKI smart card software. The PKI technology enables secure and reliable user identification in services offered through Internet, mobile handsets and digital TV |
| X | setFTPBack | createsw.exe | Added by the FTP_BMAIL TROJAN! |
| N | SetHook | Sethook.exe | Fellowes Neato® cd label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar" |
| N | SETI@home | SETI@home.exe | SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data |
| N | seticlient | SETI@home.exe | SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data |
| N | SetIcon | SetIcon.exe | Installed by a 6-in-1 (4 Media Card slots, a floppy drive and a USB connection) device. Constantly updates the icons for the four Media Card slots that it has and is a resource hog |
| N | SetiQueue | Setiqu~1.exe | Provides work unit buffering for Seti@Home clients - see here for more details |
| N | SetiSpy | SetiSpy.exe | SETI Spy is a little program to "spy" on the progress and performance of the SETI@home client. Called a "spy" because it is unobtrusive as possible |
| ? | SetPanel | APanel.cmd | Display configuration utility for some Acer laptops. Is it required? |
| X | SetPoint | SetPoint.exe | Added by the RBOT-BWI WORM! Note - this is not the valid Logitech Setpoint mouse and keyboard entry that uses the same filename and is located in %ProgramFiles%\Logitech\Setpoint. This one is located in %System% |
| U | SetPoint | Setpoint.exe | Logitech SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice, trackballs, etc). Required if you want to use the advanced features or modify the default settings of these devices and located in %ProgramFiles%\Logitech\Setpoint |
| X | SETPOINT Logitech Inc | KHALMNP.exe | Added by the RBOT-AAX WORM! |
| U | SetRefresh | SetRefresh.exe | Found on some Compaq & HP PCs. SetRefresh is a utility which attempts to optimize the monitor's refresh rate, and in some cases the resolution, for the best user experience. See "here for more info |
| X | settdebugx.exe | settdebugx.exe | Added by the FAKEAV.SMSS TROJAN! |
| X | Setting | sysweb.exe | Added by the SDBOT.W BACKDOOR! |
| X | Setting | Webprint.exe | Added by the SDBOT.W BACKDOOR! |
| N | setup | hphprld.exe ....setup.exe | HP DeskJet Setup - printers function normally without it |
| X | Setup | [path to trojan] | Added by the DROPPER.EAT TROJAN! |
| X | Setup experation | svchost.exe | Added by the TOFGER-AW TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | setup.exe | setup.exe | Added by the GOLDUN-GB TROJAN! |
| X | setupa | runt32.exe | Added by the QQPASS-K TROJAN! |
| X | setupdata | rnll32.exe | Added by the QQPASS-AC TROJAN! |
| X | setupuser | regedit.exe setupuser.log | Regfile in disguise - another CoolWebSearch parasite variant |
| ? | setuzp | setuzp.exe | ?? |
| X | SetVrc | setvrc.exe | Added by the HUNTOCX WORM! |
| X | SevenSowrd | SysSevenSowrd.exe | Added by the AGENT-GIR TROJAN! |
| X | Sevice | winconfig.exe | Added by the GIP.113.B1 TROJAN! |
| X | Sex Teris | st01b.exe | Added by the REPAD WORM! |
| X | Sexnow | Sexnow.exe | Added by the SENOW-B premium rate adult content dialler |
| X | Sexy_Blondes | Sexy_Blondes.exe | Added by the Sexy DIALER! Related also to Hot Tarts DIALER! |
| X | Sexy_sg | Sexy_sg.exe | Premium rate adult content dialler |
| X | sf | sf.exe | SurfEnhance adware |
| N | SFIGUI | SFIGUI.EXE | Sonic Focus - "enhances music, movie and game sound by analyzing compressed audio streams in realtime, then restoring and enriching audio back to its original performance qualities" |
| X | sfita | sfita.exe | Added by the FAVADD-H TROJAN! |
| X | SfKg6w | [path to worm] | Added by the AGENT.BUO WORM! |
| X | SfKg6wIP | [random filename] | Identified as a variant of the TrojanDownloader.Matcash malware |
| X | SfKg6wIPu | [random filename] | Identified as a variant of the TrojanDownloader.Matcash malware |
| N | SFP | vzSFPWin.EXE | Verizon Online Support Center - prompts for online updates |
| U | sfpc | sfpc.exe | Spy4PC surveillance software. Uninstall this software unless you put it there yourself |
| X | SFtrb Service | cftrb32.exe | Added by the SOBIG.D WORM! |
| U | SfWinStartInfo | sfWinStartupInfo.exe | SFIRM32 Online Banking software |
| X | sfwjbbjd | midiwemshdw.exe | Added by the AGENT-OII TROJAN! |
| U | Sgecrypt | Sgecrypt.exe | SafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks" |
| U | Sgeecview | Ecview.exe | SafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks" |
| U | sginst | sginst.exe | eAcceleration Stop-Sign security software related - previously not recommended (see here). It has now been delisted, so make sure you have the latest version - hence the "U" recommendation |
| X | SGPUpdater | sgpUpdaters.exe | Fast Browser Search/Search Guard Plus parasite - installed with "Make the Web Better" applications such as My Web Tattoo, My Face LOL and Google Easy Money Kit. See here and here for more information |
| ? | SGTBox | SGTBox.exe | Canon scanner driver. Is it required? |
| U | sgtray | sgtray.exe | StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups |
| Y | Shadow | Shadow.exe | "NTI Shadow 3 is an award-winning easy-to-use backup application that automatically protects your photo, music, video, and various data files. It makes data restoration as easy as dragging and dropping files from one place to another" |
| U | ShadowUser Pro Edition | ShadowUser.exe | StorageCraft ShadowUser "provides easy to use desktop security and protection for Windows operating systems. ShadowUser is the best way to prevent unwanted changes to PCs and laptops." No longer available - see here |
| X | shambl3r | cnf.bat | Added by the REMABL WORM! |
| X | shambl3r* | shambl3r.exe | Added by the REMABL WORM! where * is 2 to 11 |
| X | SHAProc | SHAProc.exe | Added by the WINKO.AO WORM! |
| N | Share-to-Web Namespace Daemon | hpgs2wnd.exe | Share-to-Web - HP-created software and Internet-based application that enables easy uploading and sharing of photos via affiliated photo-sharing Web sites. Available via Start → Programs |
| N | Shareaza | Shareaza.exe | Shareaza P2P client |
| U | Shareaza | bindata.exe | Shareaza P2P client related |
| X | sharedprem | sharedprem.exe | Added by the MAKECALL TROJAN! |
| X | ShareSearcher | [path to trojan] | Added by the AGENT-FPE TROJAN! |
| X | ShareSearcher | wsusupd.exe | Added by the ENCLAG-A TROJAN! |
| Y | Sharing and Mapping Software | DShmap.exe | Intel AnyPoint internet sharing software. Now discontinued |
| N | SharkEject | AEJCT32.exe | Allows you to eject a disk from the Avatar Shark drive from the system tray. When loaded, there is a desktop icon so this isn't required |
| U | SharpTray | SharpTray.exe | Part of the Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents" |
| X | shccde | winssled.exe | Added by the BUZUS.CQMU TROJAN! |
| N | Shcenter | chcenter.exe | IMSI HiJaak - "the easiest way to convert, capture, and manage all your graphic files" |
| X | shdef | shdef.exe | Added by the VB-DVS TROJAN! |
| X | SheduIer | svchst.exe | Premium rate adult content dialler |
| X | SheduIer | shch.exe | Added by the BDOOR-EB BACKDOOR! |
| X | SheduIer | winagent.exe | Added by the BDOOR-EB BACKDOOR! |
| X | Shedule Connection | arpo412.exe | Added by the PPDOOR-R WORM! |
| X | Sheduler | nerocheck.exe | Added by the TACTSLAY.B TROJAN! Note - this is not the legitmate file of the same name from the Nero CD/DVD burning software which is usually located in %System% |
| X | Shell | Shell32.exe | Added by the BADSECTOR TROJAN! |
| X | Shell | ray.exe | Homepage hijacker re-directing browsers to adult content websites |
| X | Shell | Tray.exe | Homepage hijacker re-directing browsers to adult content websites |
| X | Shell | wmedia16.exe | Added by the GOLDUN TROJAN! |
| X | Shell | Open32.exe | Added by the SMALL-DL TROJAN! |
| X | Shell | Explorer.exe sound_drive16.exe | Added by the GP BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The "sound_drive16.exe" file is located in %System% |
| X | Shell | Explorer.exe, msmsgs.exe | Added by the ZLOB TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. This particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger |
| X | Shell | Explorer.exe svchost.exe | Added by the DOYORG BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The legitimate svchost.exe process is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |