| Status | Autorun name | Command | Description |
| ? | SynSetup | SynTP.tmp RunOnce.exe | Probably associated Synaptics touchpads on laptops as for the SynTPEnh and SynTPLpr entries but what does it do and is it required? |
| X | Syntax | windows32.exe | Added by the SDBOT.CQ WORM! |
| X | Syntax Script | systacq.exe | Added by the SDBOT.AI WORM! |
| X | Syntax Script | saskatcw.exe | Added by the SDBOT-TE WORM! |
| U | SynTPEnh | SynTPEnh.exe | Synaptics TouchPad Enhancements - included with drivers for Synaptics based TouchPads, which are common on many laptops. Required to display the System Tray icon and support enhanced features such as Tap Zones, Virtual Scrolling and EdgeMotion. If you don't use these features this can safely be disabled. Required on IBM Thinkpads with UnltraNav (pointstick and touchpad combo) if you don't want to loose the advanced pointstick features such as scroll |
| U | SynTPLpr | SynTPLpr.exe | Synaptics TouchPad driver helper - included with drivers for Synaptics based TouchPads, which are common on many laptops. Works in conjunction with SynTPEnh and is required if you use any of the enhanced features such as Tap Zones, Virtual Scrolling and EdgeMotion |
| U | SynTPStart | SynTPStart.exe | Synaptics Pointing Device starter belonging to Synaptics Pointing Device Driver |
| X | syre32 | syre32.exe | Added by the VBNA.B WORM! |
| X | sys | regedit /s sys.reg | Raxmus adware. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file "sys.reg" is located in %Windir% |
| X | sys | regedit sysdllwm.reg | CoolWebSearch parasite variant - also detected as the FEMAD-L TROJAN! |
| X | sys | Fonts.exe | Added by the AUTORUN.BUK WORM! |
| X | sys | rundll32.exe | Added by the LINEAG-G TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir%\Intel |
| X | Sys Ren | SysRen.exe | Part of FlashEnhancer adware |
| X | Sys**.exe [* = random char] | Sys**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | Sys**32.exe [* = random char] | Sys**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | Sys-Stat | wuapdxe.exe | Added by the SDBOT.HK WORM! |
| X | sys[random numbers] | [path to file] | WinBo adware |
| X | SYS_CLEAN | Service.exe | Added by the FLOPCOPY WORM! |
| U | Sys_Kl | sys_kl.exe | SysKeylog surveillance software. Uninstall this software unless you put it there yourself |
| X | Sys_Run | ghost.exe | Added by the LINEAGE-N TROJAN! |
| X | sys_Runtt1 | explorer.exe | Added by the LINEAGE-M TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles% |
| X | sys_up1 | svchostsys.exe | Added by the MULTIDR-FL TROJAN! |
| X | sys008 | sys008.exe | Hijacker, also detected as the STARTPA-GK TROJAN! |
| X | sys009 | sys009.exe | Added by the STARTPA-ZB TROJAN! |
| X | SYS1 | system.exe | Added by the SILLYFDC-AP WORM! |
| X | SYS1 | explorar.exe | Added by the SILLYFDC.BDJ WORM! |
| X | SYS1 | scvost.com | Added by the AUTOIT-JY WORM! |
| X | SYS2 | bad1.exe | Added by the SILLYFDC-AP WORM! |
| X | sys201 | sys209.exe | Added by the STARTPA-ZY TROJAN! |
| X | Sys29 | win***32.exe [* = random char] | EliteBar adware |
| X | SYS3 | bad2.exe | Added by the SILLYFDC-AP WORM! |
| X | sys32 | SYS32.EXE | Added by the FLUX.E BACKDOOR! The file is located in %System% |
| X | sys32 | sysx32.exe | Added by the KVEX-A VIRUS! |
| X | Sys32 | Sys32.exe | Added by the AUTORUN-KL WORM! The file is located in %Windir% |
| X | sys32_nov | sys32_nov.exe | Added by the AGENT-LAX TROJAN! |
| U | sys32cmd | sys32win.exe | Active Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | sys32dll | sys32dll.exe | Added by the AIMDES.B WORM! |
| U | sys32sql | sys32win.exe | Active Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! |
| U | Sys32V2Contoller | mw2mmgr32.exe | FamilyKeyLogger.a keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | sys33 | sys33.exe | Added by the AGOBOT-WJ WORM! |
| X | SYS4 | bad3.exe | Added by the SILLYFDC-AP WORM! |
| X | sys64_nov | sys64_nov.exe | Added by the MUTANT.FKA TROJAN! |
| X | SysA | win***32.exe [* = random char] | EliteBar adware |
| U | SysAgent | SysAgent.exe | SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of |
| X | SysAI | SysAI.exe | AproposMedia adware |
| X | sysalgg | sysalgg.exe | Added by the TIBS.BF WORM! |
| X | Sysanalysing | myrvc.exe | Added by the AUTORUN-RD WORM! |
| X | SysAntivirus 2009 | sysav.exe | SysAntivirus 2009 rogue security software - not recommended, removal instructions here |
| U | sysApp | sklgr.exe | SuperKeylogger surveillance software. Uninstall this software unless you put it there yourself |
| X | SysATW | sysatw.exe | Added by the VANEBOT-AM WORM! |
| X | sysav | winav.exe | WinPC Antivirus rogue security software - not recommended, removal instructions here |
| U | SysBkup | [path to file] | Keyspy keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | SysBoot | syskernel.exe | Added by the AUTORUN-EY WORM! |
| U | Sysbot | sysbot.exe | Spector - spying (or monitoring) software to record internet activity |
| X | Syscenter | syscenter.exe | Added by the CRYPTER TROJAN! |
| X | syscfg | syscfg32.exe | Added by the KWBOT.S WORM! |
| X | syscfg34.exe | syscfg34.exe | Added by the ELECTRON WORM! |
| X | Syscheck | win.hta | Browser hijacker |
| X | syscheck | iexplorer.exe | Added by the AGENT.DM TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
| U | SysCheck32 | sb32mon.exe | Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself! |
| X | SysCleaner | SysCleaner.exe | SysCleaner rogue cleaning utility - not recommended, removal instructions here |
| X | sysclx | ntldrt.exe | Added by the JLOK-A WORM! |
| X | syscm | Syscm.exe | Vanish adware |
| X | SysCom | msnmsgr.exe | Added by the BANK-AF TROJAN! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %Windir%\system |
| ? | SysComp | mssdnl.com | Unknown but suspect as *.com are not usually run at start up and the name isn't recognized |
| X | syscon | syscon.exe | Added by the APRILCONE.A WORM! |
| X | syscon lptt01 | syscon.exe | RapidBlaster variant (in a "syscon" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | syscon ml097e | syscon.exe | RapidBlaster variant (in a "syscon" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | sysconf | sysconf.exe | Added by the AGOBOT-IW WORM! |
| X | sysconfig | iexplorer.exe | Added by the CULT.C WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
| X | SysConfig | syscfg35.exe | Added by the KAZMOR.C WORM! |
| X | SysConfig | wincfg32.exe | Added by the SDBOT.ZD WORM! |
| U | Sysconfig | Stealth KeySpy.exe | StealthKeySpy - keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | sysconfig32 | sysconfig32.exe | Added by the AGENT-MSP TROJAN! |
| U | SysConn_Start | svcwinra.exe | System Surveillance Pro surveillance software. Uninstall this software unless you put it there yourself |
| X | Syscpy | Syscpy.exe | Firewall-bypassing, proxied spam relayer. Detected by Symantec as the HOGLE TROJAN! |
| X | SysCtl | sysctl.exe | Added by the AOK TROJAN! |
| X | Sysctrls | procdll.exe | Added by the WEEDBOTZ.14 BACKDOOR! |
| X | Sysctrls | winupdate.exe | Added by an unidentified WORM or TROJAN! |
| X | Sysctrls | mscntrl.exe | Added by the KOLABC.BB WORM! |
| X | Sysctrls | Sysctrls.exe | Added by the AGENT.AWZ TROJAN! |
| X | Sysctrls | win32dll.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Sysctrls32 | sevchost.exe | Added by the RBOT.ADF BACKDOOR! |
| X | SysCVMS.exe | SysCVMS.exe | Added by the SMALL.CBA TROJAN! |
| X | sysdat.dll | sysdat.dll.exe | Added by the NISHICA 1.1 TROJAN! |
| X | SysData | [path to file] | Added by the RANCK-BA TROJAN! |
| X | SysDefence.exe | SysDefence.exe | SysDefence rogue security software - not recommended, removal instructions here. A member of the AntiAID family |
| X | SysDefenders | SysDefenders.exe | SysDefenders rogue security software - not recommended, removal instructions here. A member of the AntiAID family |
| X | SysDepannage | SysRep.exe | SysDepannage, French rogue system error and cleaning utility - not recommended. A member of the ErrClean family |
| X | SysDesk | svchoxt.exe | Added by the DELF-EDE TROJAN! |
| X | SysDeskqqfx | qqfx.exe | Added by the QQPASS.H TROJAN! |
| X | SysDeskqqfx | Runddll32.exe | Added by the CHANGGAME TROJAN! |
| X | SysDesktop | fswanQQ.exe | Added by the QQSEND-A TROJAN! |
| X | sysdiag64.exe | sysdiag64.exe | Added by the AUTOINF-AB WORM! |
| X | sysdir | winrun.exe | Added by the WINBUR.B WORM! |
| X | sysdll | windll.exe | Added by the AUTORUN.ECT WORM! |
| X | sysdll | [trojan filename] | Added by the HUGESOT TROJAN! |
| X | Sysdpt | sysdpt.exe | Added by the CRYPT TROJAN! |
| X | SysDriver | sysdriver.exe | Added by the CARRIER.JC WORM! |
| X | SysDrv | [trojan filename] | Added by the AGENT-GOT TROJAN! |