| Status | Autorun name | Command | Description |
| X | Sysqq | LSESS.exe | Added by the FORBOT-BF WORM! |
| X | Sysqq | weiba.exe | Added by the DELF-CFX TROJAN! |
| X | SysR | sysmd.exe | Ulubione adult content dialer |
| X | SysReg | SysReg.exe | Added by the CHEKIN TROJAN! |
| X | SysReg | SysReg.exe | SearchSeekFind textual marketing foistware |
| X | Sysres | Sysres.exe | Added by the LOGMOD.A TROJAN! |
| X | SysRes | TASKMANAGER.exe | Added by the ELIPTER.A or ELIPTER.B WORMS! |
| X | SysRes | WWE DIVAS.exe | Added by the ELIPTER.D WORM! |
| X | SysRes | IExpIore .exe | Added by the ELITPER.E WORM! |
| X | sysrest32.exe | sysrest32.exe | Added by the AGENT-GIN TROJAN! |
| X | sysrestore32.exe | sysrestore32.exe | Unknown malware detected by McAfee - see here |
| X | Syss | ehuupdate.exe | EHU adware |
| X | SysScan | bvt.exe | Added by the AUTOUPDER TROJAN! |
| X | SysSearch | Regedit.exe -s pcsearch.reg | Added by the STARTPAGE-FN TROJAN! Note that regedit.exe is a legitimate Microsoft file and shouldn't be deleted. The "pcsearch.reg" file is located in %Windir% |
| X | SysSearch | Regedit.exe -s sysreg.reg | Added by the STARTPA-ME TROJAN! Note that regedit.exe is a legitimate Microsoft file and shouldn't be deleted. The "sysreg.reg" file is located in %Windir% |
| U | SysSense | SysSense.exe | "SysSense is your personal desktop Google AdSense monitor. It keeps your current Google AdSense information in the Windows system tray". Google AdSense account required |
| X | sysser | [path to file] | Added by the RAHACK WORM! |
| X | SysService | SysService.exe | Added by the BDFORM-A BACKDOOR! |
| U | SysService | SERVICES.EXE | NSKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\NSkeylogger |
| X | SysService32 | SysService32.exe | Added by the KINDAL VIRUS! |
| X | SysService32 | ln32k.dll | Added by the KINDAL VIRUS! |
| X | SysService32l | systask32l.exe | Added by the THEUG WORM! |
| X | SysServices | SERVICES.EXE | Added by the DELF-EY TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | SYSsfitb | SYSsfitb.exe | AdShooter adware |
| X | SySSL | sysl.exe | Added by the RBOT-CKH WORM! |
| X | SySSL | syssl.exe | Added by the RBOT-DAA WORM! |
| X | SysStart | [random filename] | ZenoSearch adware |
| X | SysStart | syswin.exe 1 | Added by the AUTORUN-EY WORM! |
| X | SysStrt | systemc.exe | Added by the AGOBOT-QA TROJAN! |
| X | syssvc.exe | syssvc.exe | Added by the AGENT-QQM TROJAN! |
| X | syst | syst.exe | Added by the BANLOAD.BEJ TROJAN! |
| X | syst32 | syst32.exe | Added by the AUTORUN-AFL WORM! |
| X | Systam13 | f1r5st83.exe | Added by the IRCBOT-YM WORM! |
| X | Systam13 | exp.exe | Added by the RBOT.ESD BACKDOOR! |
| X | Systam13 | first.exe | Added by the RBOT.GND BACKDOOR! |
| X | Systam13 | resx.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Systam13 | speedwin.exe | Added by the RBOT.GVH BACKDOOR! |
| X | system | wscript.exe [path to worm script] | Added by the AUTORUN-FG WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted |
| X | system | wind.exe | Added by the AUTORUN.BND WORM! |
| X | System | nav32.exe | Added by the RBOT-BHV WORM! |
| X | SYSTEM | wuamgre.exe | Added by the RBOT-WA WORM! |
| X | System | wmplayer.exe | Added by the LASY-A WORM! Note - this is not the valid Windows Media Player as the file is located in %Windir% rather than %ProgramFiles%\Windows Media Player |
| X | System | run322.exe | Added by the LANFILT TROJAN! |
| X | System | system.exe | Added by various WORMS and TROJANS! |
| X | system | regedit -s system.dll | Homepage hijacker |
| X | system | systemsearch.hta | Jetseeker.com hijacker |
| X | System | dcomx.exe | Added by the CIREBOT TROJAN! |
| X | system | Explorer.exe | Added by the GRAYBIRD BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System% |
| X | System | YPager.exe | Added by the JUNTADOR.K TROJAN! Note - this is not the older version of Yahoo! Messenger which shares the same filename and is located on %ProgramFiles%\Yahoo!\Messenger |
| X | system | outlook.exe | Added by the MIMAIL.Q WORM! Note that the valid Microsoft Outlook executeable is located in %ProgramFiles%\Microsoft Office\Office whereas this one is located in %Windir% |
| X | System | Atira.exe | Added by the KOTIRA VIRUS! |
| X | SYSTEM | lsas.exe | Added by the SPYBOT.CJ WORM! |
| X | System | kernels32.exe | Added by the DLOADER-FC TROJAN! |
| U | System | sysctrl.exe | Added by WinGuardian. Note - this commercial keylogger is no longer made or sold by Webroot but older copies may still be in existance, those copies will be identified as spyware |
| X | System | csrss.exe | Added by the LDPINCH.E TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | System | SVCHOST.EXE | Added by the LDPINCH-AU TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | system | lsasse.exe | Added by the RBOT-YL WORM! |
| X | System | systray.exe | Added by the PISABOY-A TROJAN! Note - this is not the legitimate systray.exe process |
| X | System | abcdefg.exe | Added by the HARWIG-B WORM! |
| X | System | cber.exe | Added by an unidentified TROJAN! |
| X | System | serwin.exe | Added by the LDPINCH-BN TROJAN! |
| X | System | svchîst.exe | Added by the LDPINCH-BF TROJAN! |
| X | System | system.exe (74295303) | Added by the VB-IU WORM! |
| X | System | WINL0G0N.EXE | Added by the BANCOS-DB TROJAN! |
| X | System | wumgrd32.exe | Added by a variant of the RBOT WORM! |
| X | System | SPOOLSU.EXE | Added by the BANKER-FC TROJAN! |
| X | System | system23.exe | Added by the LEBREAT-D WORM! |
| X | System | windowsps.exe | Added by a variant of the RBOT WORM! |
| X | SYSTEM | d.exe | Added by the MYTOB.LP WORM! |
| X | System | inetinfo.exe | Added by the PARDROP-A TROJAN! |
| X | system | services.exe | Added by the DELF-LQ TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\HELP |
| X | SYSTEM | VSSMON.exe | Added by the RBOT-AWW TROJAN! |
| X | SYSTEM | wiinlogon.exe | Added by the RBOT-AVG WORM! |
| X | System | kernels64.exe | Added by the VIXUP-S TROJAN! |
| X | system | lsass.exe | Added by the SATILOLER.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System |
| X | System | smss.exe | Added by the AGENT.EP BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | System | winupd.exe | Added by a variant of the SDBOT WORM! |
| X | system | messenger.exe | Added by an unidentified WORM or TROJAN! |
| X | System | kernels1118.exe | Added by a variant of the SDBOT WORM! |
| X | System | wsscntfy.exe | Added by a variant of the SDBOT WORM! |
| X | SYSTEM | windmupdr.exe | Added by a variant of the RBOT WORM! |
| X | system | svcr.exe | Added by the SPYONE TROJAN! |
| X | System | kernels88.exe | Added by the TIBS-PP TROJAN! |
| X | System | kernels8.exe | Added by the TIBS.AI TROJAN! |
| X | System | OeApi.vbs | Added by the AGUI WORM! |
| X | System | Updaterun.exe | Added by the QQHELP-DX TROJAN! |
| X | System | Zap.exe | Added by the MSNVB-D WORM! |
| X | System | BrO_AcT.exe | Added by the SILLYFDC-AL WORM! |
| X | System | Juegs.exe | Added by the CULLER-C WORM! |
| X | System | kernel8.exe | Added by the DLOADR-AOL TROJAN! |
| X | System | kernelwind32.exe | Added by the VXIDL.FT TROJAN! |
| X | System | Xsfr.exe | Added by the CULLER-D WORM! |
| X | System | kernelwind64.exe | Added by the DLOADER.DJD TROJAN! |
| X | SYSTEM | SystemFile.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | system | ssclie.exe | Added by the AGENT.LW BACKDOOR! |
| X | system | Winhelp.exe | Added by the IMAUT.CN WORM! |
| X | system | kernel32.ini | Added by the SILLYFDC.CJ WORM! |
| X | System | testtestt.exe | Added by the DWNLDR-ZLC TROJAN! |
| X | system | Microsoft Office.exe | Added by the BANCBAN-LH TROJAN! |
| X | System | IEXPL0RE.EXE | Added by the VB.KS WORM! Note the number "0" in the filename |