| Status | Autorun name | Command | Description |
| Y | SpywareTerminatorUpdate | SpywareTerminatorUpdate.exe | Automatic updates for Spyware Terminator. Initially not recommended due to false positives but the later versions have since improved - see here |
| X | SPYWATCH | SpyWatch.exe | BPS Spyware Remover rogue spyware remover - not recommended, removal instructions here |
| X | SpyWatchE | SpyWatchE.exe | SpyWatchE rogue security software - not recommended, removal instructions here |
| X | SQConfigChecker | cc.exe | Xupiter SQWire toolbar related. Use Spybot S&D, Adware or similar to detect and remove and to prevent it re-installing in the future see here |
| X | SQInstaller | SQInstaller.exe | Xupiter SQWire toolbar related. Use Spybot S&D, Adware or similar to detect and remove and to prevent it re-installing in the future see here |
| X | SQL | server.exe | Added by the PUNYA-B WORM! |
| N | SQL Server | scm.exe | SQL Server Service Control Manager. Available via Start -> Programs |
| X | SQL Server Service | sql.exe | Added by the RBOT-ADF |
| X | sqlpdro | providd.exe | Added by the AGENT-LXF TROJAN! |
| X | sqservices | wins32.exe | Added by the PROGENT-B TROJAN! |
| X | SQUpdatesChecker | uc.exe | Xupiter SQWire toolbar related. Use Spybot S&D, Adware or similar to detect and remove and to prevent it re-installing in the future see here |
| X | sqvynikp | sqvynikp.exe | Free_Scratch_Cards foistware |
| X | SQYJBiKnjSxs | SQYJBiKnjSxs.exe | Added by the DWNLDR-IYI TROJAN! |
| Y | SR Agent | AGENTSVC.EXE | Related to Secure Resolutions - desktop virus protection |
| Y | Sr Agent | SrLogon.exe | Related to Secure Resolutions - desktop virus protection |
| ? | sr1exe | updtSup3.exe | Found on a Dell computer in Documents and Settings\All Users\Application Data\DellAlert2 |
| X | sr64 | [path to trojan] | Added by the AGENT.X TROJAN! |
| X | SrchfstUpdate | srchupdt.exe | SearchFast adware downloader |
| X | sre | rundll32.exe sre.dll, Register | CoolWebSearch parasite variant - also detected by Kaspersky as the AGENT.FC TROJAN! |
| ? | srePostpone | rundll32.exe [path] srescan.dll, DoSpecialAction | Related to ZoneAlarm. What does it do and is it required? |
| ? | SRFirstRun | rundll32 srclient.dll, CreateFirstRunRp | Created by execution of the Windows XP sr.inf file, which installs the Windows XP System Restore feature, needed for example when installing System Restore into Windows Server 2003. Does this indeed need to run at every bootup? |
| U | Srmclean | srmclean.exe | Srmclean helps in the installation and execution of the SoundMax SoftPaq for Compaq/ADI SoundMax Integrated Digital Audio. According to Compaq - "If you disable the entry from loading into startup, then you will not be able to use the features of the sound card" |
| X | SRNG | srng.exe | ShopNavSearch.Srng search hijacker |
| U | SRP Startup | srrpro.exe | System Restore Remover Pro allows you to safely and easily remove System Restore and various other Windows Millennium "features". This is enabled if you tick the "Remove unnecessary System Restore information on startup" box. Available via Start -> Settings -> Control Panel |
| Y | SRS Applet | SrsTray.Exe | S3 Sonic Vibes sound card drivers - if disabled you loose sound |
| U | SRS Audio Sandbox | SRSSSC.exe | SRS Audio Sandbox "provide amazing audio immersion and maximum thump for a personalized audio experience!" |
| U | SRS Premium Sound | SRSPremiumSoundBig_Small.exe | Part of SRS Premium Sound technology by SRS Labs, Inc - which "delivers a superior audio experience for music, video and games on your PC regardless of audio environment - small internal notebook speakers, external desktop PC speakers or headphones" |
| X | srshost.exe | srshost.exe | Added by a variant of the RBOT-ASW WORM! |
| X | srtserv | [worm filename].exe | Added by the VERST.B WORM! |
| U | SRUUninstall | msiexec.exe | Symantec Network Driver Update - part of LiveUpdate |
| X | srv | winlogon.exe | Added by the SILLYFDC.BCA WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%\Local Settings\Application Data |
| X | Srv Host | srvhost.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Srv RPCrom | NClienti386.exe | Added by the WATSOON.A TROJAN! |
| X | Srv32 | Srv32.exe | Added by the OPASERV.J WORM! |
| X | Srv32 spool service | runsrv32.exe | Topantispyware adware |
| X | Srv32 spool service | spoolsrv32.exe | Added by the SPYRE-B TROJAN! |
| X | Srv32 spool service | [path to trojan] | Added by the DLOADER-LB TROJAN! |
| X | Srv325 | Srv325.exe | Added by the AGOBOT-PR WORM! |
| X | Srv32Old | [worm filename].PIF | Added by the OPASERV.J WORM! |
| U | Srv32Win | SpyAgent4.exe | SpyAgent - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
| U | Srv32Win | Svchost.exe | Realtime-Spy keystroke logger/monitoring program - remove unless you installed it yourself! |
| U | Srv32Win | sysdiag.exe | SpyAgent surveillance software. Uninstall this software unless you put it there yourself |
| U | srv32win | win16dll.exe | Screenspy captures screenshots silently. If you didn't install this yourself remove it |
| X | Srv32Win | KeyCaptor.exe | KeyCaptor surveillance software. Uninstall this software unless you put it there yourself |
| X | Srvce Pack Updte | svcpack.exe | Added by a variant of the RBOT WORM! |
| X | srvexc.exe | srvexc.exe | Added by the SERVSAX TROJAN! |
| X | srvhost | srvhost.exe | Added by the LIVUP.A BACKDOOR! |
| U | srvprc | srvprc.exe | ActMon surveillance software. Uninstall this software unless you put it there yourself |
| X | SRVState_[Server name] | svhost.exe | Added by the TODNAB-B WORM! |
| N | srxTray | srxTray.exe | Titan FTP Server - FTP server |
| Y | SSA.exe | SSA.exe | Bell Sympatico Security Advisor tool installed when you choose to install their internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabled |
| N | SsAAD | SsAAD.exe | Starts Sony's SonicStage CP digital music manager automatically when an ATRAC audio device is connected - such as a Walkman MP3 player or a PlayStation® Portable |
| N | SsAAD.exe | SsAAD.exe | Starts Sony's SonicStage CP digital music manager automatically when an ATRAC audio device is connected - such as a Walkman MP3 player or a PlayStation® Portable |
| X | ssate.exe | irun4.exe | Added by the BEAGLE.J WORM! |
| X | ssate.exe | winsys.exe | Added by the BEAGLE.K WORM! |
| N | SSBkgdUpdate | SSBkgdupdate.exe | Automatic updates for ScanSoft (now Nuance) products such as OmniPage and PaperPort. Can be disabled using the main program's options. Note - if you have a Soundblaster Audigy2 ZS soundcard installed on your computer and the volume of your sound system is turned on extremely high disabling this will solve the problem |
| U | SSC Service Utility | ssc_serv.exe | SSC Service Utility is a printer utility for refilled Epson cartridges |
| U | SSC_UserPrompt | UsrPrmpt.exe | Used in conjunction with Security Center on XP from SP2 onwards to warn user's that older versions of Symantec's security products including Norton Internet Security, Norton AntiVirus and the now discontinued Norton Personal Firewall are disabled |
| U | SSCFBTN.EXE | SSCFBTN.EXE | Samsung smarthru software,used with Lexmark Z82 or Samsung multifunction printers |
| Y | sscRun | SSCRun.exe | AOL's firewall |
| Y | Ssd | Std.exe | Stealthdisk - file and folder hiding/locking utility |
| ? | ssdiag | ssdiag.exe | Equinox (now Avocent) "Configuration and DOS Diagnostic for DOS and Windows platforms" |
| N | SSDPSRV | ssdpsrv.exe | Simple Service Discovery Protocol (SSDP) and General Event Notification Architecture (GENA) services for network plug and play functionality. Starts up a web server on port 5000. Used by Universal Plug and Play (for network device discovery). To remove this program, open Add/Remove Programs, select either Communications (Me) or Networking Services (XP), and remove the checkmark next to Universal Plug and Play |
| X | sserrvv | sserrvv.exe | Added by the STRATION.DB WORM! |
| X | ssgrate.exe | system.exe | Added by the MITGLIEDER.C TROJAN! |
| X | ssgrate.exe | irun.exe | Added by the MITGLIEDER.D TROJAN! |
| X | ssgrate.exe | irun4.exe | Added by the MITGLIEDER.F TROJAN! |
| X | ssgrate.exe | sysdoor.exe | Added by the MITGLIEDER.N TROJAN! |
| X | ssgrate.exe | winerdir.exe | Added by the MITGLIEDER.O TROJAN! |
| X | ssgrate.exe | winsystems.exe | Added by the BAGLEDL-J TROJAN! |
| X | ssgrate.exe | wintems.exe | Added by the MITGLIEDER.Q TROJAN! |
| U | SSh32 | SSh32.exe | 2Spy keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | SSK Service | winssk32.exe | Added by the SOBIG.E WORM! |
| X | SSL | svchost.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | SSL | SearchNDestrou.exe | Added by the SDBOT-WG WORM! |
| X | SSL Manager | amsnmsgs.exe | Added by a variant of the SDBOT WORM! |
| X | SSLDyn | SSLDyn.exE | FRETHOG.MM spyware |
| U | SSMMgr | SSMMgr.exe | Monitors ink levels, paper present and other parameters for Samsung, Xerox, Dell and other printers |
| X | ssms.exe | SSMS.EXE | Added by the GISMOR WORM! |
| X | ssms.exe | winn.exe | Added by the SDBOT-DHE WORM! |
| X | ssmss | ssmss.exe | Added by the AGENT-MOF TROJAN! |
| X | ssp2.exe | ssp2.exe | Added by the RBOT-BBK WORM! |
| U | SSPY | SSYTEM.EXE | SurfingSpy keystroke logger/monitoring program - remove unless you installed it yourself! |
| U | SSS7 | SSS7.exe | Steganos Security Suite 7 - "A comprehensive collection of methods to prevent your data falling into the wrong hands, and highly recommended if you have anything you feel you need to hide" |
| X | sssasasb32 | sssasasb32.exe | Added by the TACTSLAY.F TROJAN! |
| X | sssasasb32 | msnmsgq.exe | Added by the TACTSLAY.F TROJAN! |
| X | sstata | dwdas.exe | Added by the DASDA TROJAN! |
| X | sstata | [path to trojan] | Added by the RANCK-DF TROJAN! |
| X | SStb.exe | SStb.exe | Adpowerzone.com "ServerSide" keyword hijacker |
| N | sstray | sstray.exe | nVidia nForce Taskbar Utility - quick access to the nForce2 "Sound Storm" control panel and related utilitys |
| X | SSUpdate | SSUpdate.exe | MoneyTree parasite - ActiveX control used to download premium-rate dialers |
| X | ssvchost | ssvchost.exe | Added by the HELIOS.B TROJAN! |
| X | SSWPlauncher | comet.exe | Comet Cursor adware |
| X | sta | rundll32 fjzkp.dll | Added by the MDROP-CSP TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "fjzkp.dll" file is located in %System% |
| N | Stacmon | Stacmon.exe | Installed with the drivers for a SigmaTel C-Major Audio card (on a Dell Inspiron 600m PC for example). Appears as though it can be disabled with no ill effects |
| N | StacSysTray | StacSysTray.exe | System Tray control panel for SigmaTel C-Major on-board audio - as used on some Dell and Packard Bell PCs |
| X | staeck12 | mfcee.exe | Added by an unidentified WORM or TROJAN! |
| X | staeck122 | mfceee.exe | Added by an unidentified WORM or TROJAN! |
| U | Staffcop Scheduler | scheduler.exe | StaffCop surveillance software. Uninstall this software unless you put it there yourself |
| X | stagio | hot.exe | Added by the AGENT-NZS TROJAN! |