| Status | Autorun name | Command | Description |
| X | smgr | mgrs.exe | Covert Sys Exec malware variant |
| X | smgr | smgr.exe | Added by an unidentified WORM or TROJAN! |
| X | smile | wcs.exe | Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machine. Various directories and filenames are used - see the link for details |
| N | SmileboxTray | SmileboxTray.exe | System Tray access to Smilebox photo sharing/printing service |
| X | Smiley District | plugin.exe | Smiley District adware |
| X | SmileyApp | stbapp.exe | DoubleD adware |
| N | Smileycons | smileycons.exe | Smileycons - free smileys, emoticons and animations package |
| N | Smith Micro try | smiptray.exe | Smith Micro shared files. Comes with D-Link web cam |
| U | smodul | smodule.exe | UserMonitor from Neuber. Teachers can broadcast screen to other screens, see students screens in a network and detect unauthorized software |
| N | SmoothView | SmoothView.exe | TOSHIBA Zooming Utility - allows "automatic" zoom feature in some appications, like IE, MS-Office, WMPlayer, Adobe Reader and also desktop icons |
| U | SMPAutoStart | smpdemo.exe | Smart Phone Recorder demo from KenGolf.com. Answering Machine, Caller ID, Call Recording |
| U | SmpcSys | SmpSys.exe | "Set Up My PC" utility supplied with some Packard Bell computers |
| U | smr | cvshost.exe | Silent Monitoring surveillance software. Uninstall this software unless you put it there yourself |
| X | smres | smres.exe | Added by the AGOBOT-UA WORM! |
| X | smrss | smrss.exe | Added by the BANPAES-B TROJAN! |
| X | smrtdrv | runtime.exe | Added by the AGOBOT.MT WORM! |
| X | smrtprt | smrtprt.exe | Smart Protector rogue security software - not recommended, removal instructions here |
| X | SMS | iro.bat | Added by the IROFFER.CT BACKDOOR! |
| U | SMS Application Launcher | LAUNCH32.EXE | Microsoft Systems Management Server - used to manage computers on a network remotely |
| U | SMS Client Service | clisvc95.exe | When the SMS Client service starts on a domain controller, the Client service modifies the SMSCliToknAcct & user account group membership, user rights, and account comment. The Client service then waits for the synchronization of the comment to verify that the account and user rights are properly set for this account. This account is used to obtain a token to start the SMS Client processes, such as the Software Inventory and Software Distribution agents (MS Systems Management Server) |
| X | Sms System32 | SmsSystem32.exe | Unidentified malware |
| U | SMS Win9x Message Agent | SMSMsg.exe | This program assigns a user to a Systems Management Server site |
| X | sms_msn | sms_msn.exe | Added by an unknown WORM or TROJAN! |
| X | sms_msn40 | sms_msn40.exe | Added by an unknown WORM or TROJAN infection |
| N | SmsDiscount | SmsDiscount.exe | SmsDiscount - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype |
| N | Smserial | sm56hlpr.exe | Helper utility for Motorola based SM56 software modems - resides in the System Tray |
| X | SMSERIALSTARTER | win32st.exe | Added by the FAKEALERT-AH TROJAN! Installed with the SpyBurner spyware remover - which is not recommended, see here |
| X | SMSERIALWORKERSTART | shellexcon.exe | Added by the FAKEALERT-AH TROJAN! Installed with the SpyBurner spyware remover - which is not recommended, see here |
| X | SMSERIALWORKERSTARTER | winstrse.exe | Added by the RENOS.IC TROJAN! Installed with the SpyBurner spyware remover - which is not recommended, see here |
| X | SMSERIALWORKSTARTER | comsysobj.exe | Added by the FAKEALERT-AH TROJAN! Installed with the SpyBurner spyware remover - which is not recommended, see here |
| X | smsger | Win.exe | Added by a variant of the SDBOT WORM! |
| N | SMSI Loader | SMLoader.exe | Smith Micro HotFax - fax software |
| X | smsm | smsm.exe | Added by the BANKER-CO TROJAN! |
| X | smsrv | smsrv.exe | Added by the AGOBOT-SX WORM! |
| X | SMSS | smss.exe | Added by the FLOOD.F BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "Catroot" subfolder |
| X | smss | [path to smss.exe] | Added by the ALADINZ.F TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup! |
| X | smss | smss.exe | Added by the AGENT-TR TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | smss | smss.exe | Added by the BOROBOT-J TROJAN and variants! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup! |
| X | Smss | ssms.exe | Added by the RBOT.OP WORM! |
| X | Smss Host | smhost.exe | Added by the IRCBOT-ACC TROJAN! |
| X | smss.exe | csrss.exe | Added by the DALBUG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Smss.exe driver | winupd32.exe | Added by the SDBOT.MI BACKDOOR! |
| X | smss32.exe | smss32.exe | Added by the FAKEAV-ATH TROJAN! |
| X | smssLevel4 | smss.exe | Unidentified malware! ! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Windows Media Player\Skins\WindowsMediaSkin\Data\Level4 |
| X | SMSSS | smsss.exe | Added by the SDBOT.ZD WORM! |
| X | SMSSS Loader | smsss.exe | Added by the AGOBOT.MQ WORM! |
| X | SMSSU | SMSSU.EXE | Added by the STARTPAGE.O TROJAN! |
| U | SMSTray | SMSTray.exe | System tray access to Samsung Media Studio |
| X | SMSvc32 | smsvc32.exe | Added by the AGOBOT-OL WORM! |
| X | smsys | Explorer.exe | Added by the CLICKER-C BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in a "Template" subfolder |
| X | smsys | vi.exe | Adult content dialler |
| U | SMSystemAnalyzer | SMSystemAnalyzer.exe | Part of the Iolo System Mechanic optimization tool |
| U | Smt | SMT.exe | Win-Spy keyboard logger/monitoring software - remove unless you installed it yourself |
| N | SMToolbar | SMToolbar.exe | StartMake.com toolbar |
| X | SMTP32 Mailing Protocol | smtp32.exe | Added by a variant of the RBOT WORM! |
| N | SMTray | Smtray.exe | System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel |
| ? | SmWizard | SmWizard.exe | SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required? |
| X | smx4pnp | rundll32.exe [path] smx4pnp.dll | Added by the SASFIS.VR TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | SN Messenger | msnmsgr.exe | Added by the RBOT-AVP WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System% |
| U | SnagIt 8 | SnagIt32.exe | "SnagIt lets you capture, edit, and share exactly what you see on your screen - fast" |
| U | Snapfish Media Detector | SnapfishMediaDetector.exe | Snapfish Media Detector - "Upload your photos to Snapfish, where you can store and share your photos for free on line" |
| N | Snapfish PictureMover | PictureMover.exe | Snapfish PictureMover free application to get photos directly from your camera to Snapfish (and your computer), without the pain of uploading. "Snapfish by HP is the number one online photo service, with more than 70 million members in over 20 countries and 2 billion unique photos stored online". Run manually before connecting your camera |
| U | SnapfishMediaDetector | SnapfishMediaDetector.exe | Snapfish Media Detector - "Upload your photos to Snapfish, where you can store and share your photos for free on line" |
| X | snapple | snapple.exe | Added by the FORBOT-EG WORM! |
| N | Snappy Fax | sf4.exe | Snappy Fax desktop fax program with an extensive set of features - version 4 |
| ? | Snappy Fax Printer Agent | sfpagent.exe | Related to the Snappy Fax desktop fax program. What does it do and is it required? |
| ? | Snappy Fax Printer virtual printer agent | sfpagent.exe | Related to the Snappy Fax desktop fax program. What does it do and is it required? |
| N | Snarvei til egenskapsside for High Definition Audio | HDAShCut.exe | High definition audio page shortcut for Realtek audio devices - not required. Norwegian version |
| ? | snbr | snbr.exe | ?? |
| X | snbupt | snbupt.exe | UpSpiralBar adware |
| X | sncntr | sncntr.exe | Added by the DLUCA-I TROJAN! |
| ? | SNCT511 | vsnct511.exe | Unidentified "Snapshot Viewer"- what does it do and is it required? |
| X | SND Volumes | sndvolumes.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | snd332 | snd332.exe | Added by the B1LD0 AIM WORM! |
| X | Sndcompat | Sndcompat.exe | Added by the GEMA TROJAN! |
| U | sndmi13 | vsndmi13.exe | Driver for DualCam cameras - that combine the best features of a digital still camera and a webcam |
| Y | SNDMon | SNDMon.exe | Part of Symantec's LiveUpate for older versions of Symantec's security products including Norton Internet Security, Norton AntiVirus and the now discontinued Norton SystemWorks suite. Leave alone to ensure virus definitions are updated. Also, if SNDMon is disabled on one of the computers on a small office network then other computers disappear from the network for this computer, including shared devices like printers and scanners |
| X | Sndsaver | Sndsaver.exe | Added by the GEMA TROJAN! |
| Y | SNDSrvc | SNDSRVC.EXE | Common process for older versions of Symantec's security products including Norton Internet Security and the now discontinued Norton AntiSpam and Norton SystemWorks suite. Used for the scanning of incoming POP3 emails for viruses, threats or spam. Loads via the registry "Run" or "RunServices" keys in 98/Me and as a service in XP |
| U | Snelkoppeling naar eigenschappenvenster voor High Definition Audio | HDAudPropShortcut.exe | Realtek audio card related. Probably adds the odd feature to one of the "Sounds" Control Panel applet tabs - doesn't appear to be required. Dutch version |
| X | sniffer | _ex-08.exe | Added by the OFICLA-X TROJAN! |
| X | SNInstall | [various filenames] | Spy Sheriff/SpywareNO malware, also detected as the SPYHOAX-A TROJAN, pretends to be a spyware remover! - file names spotted sofar include VXH8JKDQ2.EXE, NS6281400.so, CVXH8JKDQ2.EXE, down3.exe, sefe.exe, winstall.exe, and tool2.exe |
| U | Snippet | SnippingTool.exe | The Snipping Tool (part of the Experience Pack for Tablet PC) allows you to easily "cut out" anything on screen and share it with other people. The whole screen becomes an "inkable" surface that you can add comments to and mark up however you like. You can then save that annotated image to use later, or send it to someone else in an E-mail message |
| U | SNM | SNM.exe | SpyNoMore spyware remover - previously not recommended, see here |
| U | Snoop | Snoop.exe | Snoop surveillance software. Uninstall this software unless you put it there yourself |
| U | SnoopFreeUI | SnoopFreeUI.exe | Anti-keylogging software made by SnoopFree Software |
| X | SNP Generic Host Process | svchost.exe | Added by the ZAPCHAS-O TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| N | snp2std | vsnp2std.exe | Digital camera related |
| ? | snp2uvc | vsnp2uvc.exe | Related to a CameraMonitor Application from Sonix. What does it do and is it required? |
| ? | snpstd | vsnpstd.exe | Sonix PC Camera Monitor MFC Application. What does it do and is it required? |
| ? | SNPSTD2 | vsnpstd2.exe | CameraMonitor MFC Application. Appears to be related to a USB connection to a digital camera -is it required? |
| Y | snpstd3 | vsnpstd3.exe | Sonix Inc. Camera Monitor MFC Application |
| N | Snsicon | Snsicon.exe | Launches a screensaver program from Second Nature |
| X | SNSS.EXE | SNSS.EXE | Nunci premium rate dialer |
| X | snvc | snvc.exe | Added by an unidentified WORM or TROJAN! |
| ? | SO5 Integrator Pass One | sointgr.exe | Part of StarOffice 5 by StarDivision - a proprietary office suite and the predecessor of OpenOffice |
| ? | SO5 Integrator Pass Two | sointgr.exe | Part of StarOffice 5 by StarDivision - a proprietary office suite and the predecessor of OpenOffice |
| X | Soar | Rwon.exe | PurityScan adware |
| X | Social Security Agency | rpcxsocsa.exe | Added by a variant of the RBOT WORM! |
| X | Sock32 | sock32.exe | Added by the SDBOT TROJAN! |