| Status | Autorun name | Command | Description |
| X | sysdxvid | sysdxvid.exe | Added by the DLUCA-S TROJAN! |
| X | sysemls | sysem.exe | Added by a variant of the SDBOT WORM! |
| X | SysEQ | svclgx32.exe | Added by the IRCBOT-AC TROJAN! |
| X | sysfbtray | bill102.exe | Added by the VB-ENI TROJAN! |
| X | sysfbtray | bill106.exe | Added by the MDROP-CLV TROJAN! |
| X | sysfbtray | bill117.exe | Added by the VBKRYPT-E TROJAN! |
| X | sysfbtray | bill103.exe | Added by the MDROP-CLF TROJAN! |
| X | sysfbtray | bill104.exe | Added by the MDROP-CLO TROJAN! |
| X | sysfbtray | bill108.exe | Added by the MDROP-CMW TROJAN! |
| X | sysfiler | sysfiler.exe | Added by the RETSAM TROJAN! |
| X | SYSfit | SYSfit.exe | AdShooter adware variant |
| X | sysflg32 | sysflg32.exe | Added by a variant of the CRYPTER.C TROJAN! |
| X | sysformat | sysformat.exe | Added by the BAGLE-BK WORM! |
| X | sysfrcx | sysfrcx.exe | Added by the KEYLOG-SCLOG TROJAN! |
| X | sysftray2 | bolivar19.exe | Added by the KOOBFACE.I WORM! |
| X | Sysgate Personal Firewall | syst3ms.exe | Added by a variant of the IRCBOT TROJAN! |
| X | Sysgate Personal Firewall | win32s.exe | Added by the SDBOT.YZB WORM! |
| X | sysguard | sysguard.exe | Added by the FAKEAV-KI TROJAN! |
| X | sysguardn | s | Spyware Protect 2009 rogue spyware remover - not recommended, removal instructions here |
| X | syshelp | syshelp.exe | Added by the LOVGATE.C WORM! |
| X | syshost | syshost.exe | Added by the VB-DVZ TROJAN! |
| X | sysin | [path to file] | Added by the DSRC-A TROJAN! |
| X | sysinfo | sysinfo.exe | Added by the BEDRILL TROJAN! |
| X | sysinfo.exe | sysinfo.exe | Added by the BEAGLE.V WORM! |
| X | SysInit | wininit32.exe | Added by the XABOT WORM! |
| X | sysinit | services.exe | Added by the NEWLFRM-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\golumm |
| X | Sysino | lsess.exe | Added by the FORBOT-BF WORM! |
| X | sysint16 | sysint16.exe | Added by the CRYPTER.A TROJAN! |
| X | sysinter | ADIRSS.EXE | Added by the AGENT.JVJ TROJAN! |
| X | sysj32.exe | sysj32.exe | Added by the IRCBOT-AHH BACKDOOR! |
| X | Syskey | sysinit.exe | Added by the BEAGLE.AX WORM! |
| X | sysldtray | ld02.exe | Added by the KOOBFACE.BG WORM! |
| X | sysldtray | ld03.exe | Added by the KOOBFACE.CA WORM! |
| X | sysldtray | ld11.exe | Added by the KOOBFACE.JG WORM! |
| X | sysLDtray | ld08.exe | Added by the AGENT-JSV TROJAN! |
| X | sysldtray | ld09.exe | Added by the AGENT-KFI TROJAN! |
| X | sysldtray | ld10.exe | Added by the FAKEAV-UD TROJAN! |
| X | sysldtray | ld12.exe | Added by the KOOBFACE.V WORM! |
| X | sysldtray | ld01.exe | Added by the KOOBFACE.I WORM! |
| X | sysldtray | ld15.exe | Added by the AGENT-LNH TROJAN! |
| X | sysldtray | ld04.exe | Added by the KOOBFACE WORM! |
| X | sysldtray | ld06.exe | Added by the KOOBFACE WORM! |
| X | sysldtray | ld07.exe | Added by the KOOBFACE WORM! |
| X | sysldtray | ld14.exe | Added by the VIRUT.CE VIRUS! |
| X | sysldtray | ld16.exe | Added by the AGENT-MMO TROJAN! |
| X | Syslib | Syslib.exe | Adult content related downloader trojan |
| X | SysLive | SysLive.exe | Added by the EXPICHU WORM! |
| U | syslog | syslog.exe | EZKeylogger keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | Syslog lptt01 | Syslog.exe | RapidBlaster variant (in a "syslog" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | Syslog ml097e | Syslog.exe | RapidBlaster variant (in a "syslog" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | syslogin.exe | syslogin.exe | Added by the BAGZ-B WORM! |
| X | syslogon | syslogon.exe | Added by the SPYBOT-EP WORM! |
| X | SysMain | buff.exe | Added by the AGENT-ECW TROJAN! |
| U | Sysman | Sysman.exe | KeyTrap is a surveillance software program that records all keyboard activities. Uninstall this software unless you put it there yourself |
| X | SysManager | Manager.EXE | Added by the DAGGER.140 BACKDOOR! |
| X | sysme | sysme.exe | Added by the PSW.STEALER.C TROJAN! |
| X | sysmem | mmsete.exe | Added by the NOPIR.C WORM! |
| X | sysmem | outlookrem.exe | Added by the NOPIR-C WORM! |
| X | SysMemory manager | mdms.exe | Added by the CIMUZ-D TROJAN! |
| U | SysMetrix | SysMetrix.exe | SysMetrix - skinnable clock and metering application. It monitors and reports on a great number of statistics |
| X | sysMett1 | explorer.exe | Added by the LEGMIR-Y TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles% |
| X | sysmini | sysmini.exe | Added by the ADLOAD.DD TROJAN! |
| X | sysmngr32 | sys64mnger.exe | Added by a variant of the RBOT WORM! |
| X | sysmntrc | sysmntrc.exe | Added by the BANCOS-FX TROJAN! |
| X | sysmod | sysmod.exe | Added by the SPYBOT-DU WORM! |
| X | sysmon | sysmon.exe | Added by the BIZEX WORM! |
| X | Sysmon | rpcmon.exe | Added by the RANDEX.ATX WORM! |
| X | sysmon | sysmon44.exe | Added by a variant of the BACKDOOR-CBA TROJAN! |
| X | SysMon | wowexece.exe | Added by the MULAN-A TROJAN! |
| X | Sysmon | SystemMonitor.exe | Added by the NUJAMA-A WORM! |
| X | Sysmon | msnmssgs.exe | Added by the SDBOT.FK WORM! |
| X | sysmon12 | [various filenames] | Wareout - malware masquerading as a spyware and dialer remover |
| X | SysmonLog | mslog.exe | Added by the AGENT.AOV TROJAN! |
| X | sysmonnt | sysmonnt.exe | SearchPounder sends keywords typed into HTML forms and popular Internet search engines to a remote server |
| X | SysMonXP | SysMonXP.exe | Added by the NETSKY.Q WORM! |
| X | Sysmppcvppp | SysTdSvr.dll | Generic2.PQG adware |
| X | sysmss | sysems.exe | Added by a variant of the SLAPER TROJAN! |
| X | sysnate | sysnate.exe | Added by the MEDIAS TROJAN! |
| X | Sysnet | snuninst.exe | Unidentified adware |
| X | sysnet | sysnet.exe | CasClient adware - also detected as the CMAPP TROJAN! |
| X | sysobj.exe | sysobj.exe | Wareout - malware masquerading as a spyware and dialer remover |
| X | SysOps | SysOps | Added by the MSNCORRUPT TROJAN! |
| X | syspare | syspare.exe | Added by the BIFROSE-AN TROJAN! |
| X | syspath | drv.exe | Added by the SOBER WORM! |
| X | sysPersonalFirewall | msnmssgr.exe | Added by a variant of the RBOT WORM! |
| X | sysPersonalFirewall | system.exe | Added by the WOOTBOT.FH WORM! |
| X | sysPersonalFirewall | tskm0nitor.exe | Added by the SDBOT.APC WORM! |
| U | SysPilot | fdxxl.exe | G Data "PC Spion". PC monitoring and surveilling software, captures all users activity on the PC, see here. Disable/remove if you didn't install it yourself! |
| X | sysPnP | bootconf.exe | Homepage hijacker, redirecting to coolwwwsearch.com; see for example here |
| X | SysPnP | rundll32 setupapi, InstallHinfSection [varies] oemsyspnp.inf | CoolWebSearch PnP parasite variant |
| Y | SysPool | Mssvc.exe | StealthDisk - hides folders, files and applications. Will also encrypt them for better protection |
| X | SysPool | MSSVC32.EXE | Added by the BANCBAN-IO TROJAN! |
| X | SySPower | [path to trojan] | Added by the BANCBAN-OC TROJAN! |
| U | sysproc | sysproc.exe | Keyboard Logger keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | SysProtect | System.exe | Added by the NETSPY TROJAN! |
| X | SysProtect | syp.exe | SysProtect rogue security software, associated with WinFixer - not recommended, see here |
| X | SysProtect | USYP.exe | SysProtect rogue security software, associated with WinFixer - not recommended |
| X | SysProtect Free | USYP.exe | SysProtect rogue security software, associated with WinFixer - not recommended |
| X | SysProtector | SysProtector.exe | SysProtector rogue security software - not recommended, removal instructions here. A member of the AntiAID family |
| X | syspw32.exe | syspw32.exe | Added by the APPFLET.A WORM! |