| Status | Autorun name | Command | Description |
| X | System Loaderap | syst19b.exe | Added by the AGOBOT-AT BACKDOOR! |
| X | System Log Event | csrss32.exe | Added by the AGOBOT-JI WORM! |
| X | System Management Service | smsc.exe | Added by the RBOT-ANN WORM! |
| X | System Manager | svchost.exe | Added by the BANKER-AE TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | system manager | System.exe | Added by the FORBOT-BO WORM! |
| X | System Manager | winsrv32.exe | Added by an unidentified WORM or TROJAN! |
| X | System Manager | sysmng.exe | Added by the TAME-C WORM! |
| X | System Manager | sysmgr.exe | Added by the IRCBOT.AGW BACKDOOR! |
| X | System Manager | User Documents.exe | Added by the VB.GF VIRUS! |
| X | System Manager | sysmngr.exe | Added by the IRCBOT.BAQ BACKDOOR! |
| X | System Manager | ncvs32.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | System Manager Updates | winsvc.exe | Added by the AGOBOT.AEM WORM! |
| U | System Mechanic Popup Blocker | PopupBlocker.exe | Popup blocker part of Iolo System Mechanic utility suite |
| U | System Mechanic Popup Stopper | Popupstopper.exe | Popup stopper part of Iolo System Mechanic utility suite |
| N | System Mechanic Professional Update [Incinerator.dll] | SysMech4.exe /REREG: [path] Incinerator.dll | Iolo System Mechanic "Incinerator" feature securely deletes files and folders from your PC so they can never be recovered again |
| U | System Mechanic Startup Guard | StartupGuard.exe | System Mechanic Startup Guard protects the Window's startup locations from being modified by viruses, spyware, malware and other annoying programs |
| X | SYSTEM MESSAGER | wmisg.exe | Added by the MYTOB.ES WORM! |
| X | System Messaging Queue | SMCSS.EXE | Added by a variant of the RBOT WORM! |
| X | System Messenger | SYSMSG32.EXE | Added by the SPYBOT-DK WORM! |
| X | System Messenger32 | systgmgr32.exe | Added by the SDBOT.DF WORM! |
| X | System Microsoft Core | smc.exe | Added by the RIZO.A TROJAN! |
| U | System Monitor | SYSMON.EXE | Comes with some Aopen motherboards. Monitors CPU temp, voltage and fan speed. Warns if any become abnormal |
| X | System Monitor | Sysmon16.exe | Added by the SDBOT TROJAN! |
| X | System Monitoring | cute.exe | Added by the RAHIWI.A WORM! |
| X | System Monitoring | Mooks.EXE | Added by the BHARAT.A WORM! |
| X | System Monitoring | lsass.exe | Added by the BRONTOK-BS WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS |
| X | System MScvb | mscvb32.exe | Added by the SOBIG.C WORM! |
| X | System Net | sys32.exe | Added by the FORBOT-FX WORM! |
| X | System Net Database | sysnd.exe | Added by the RBOT-AAW WORM! |
| X | System Networking | sysnet.exe | Added by the RBOT.API WORM! |
| X | System Power Managment | svcnost.exe | Added by the DREF-I WORM! |
| X | System Presets | [temp name].exe | Added by the HOSTINF-A WORM! |
| X | System Process | csrss.exe | Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | System Process | lsass.exe | Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | System Process | svchost.exe | Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | System Process | CSRSR.exe | Added by the AGOBOT-SQ WORM! |
| X | System Process Analization | sysproc.exe | Added by a variant of the RBOT WORM! |
| X | System Process Analization Thread | system.exe | Added by a variant of the RBOT WORM! |
| X | System Process Uninstall | ccapp.exe | SystemProcess adware. Note - this is not the legitimate Symantec/Norton file normally located in %ProgramFiles%\Common Files\Symantec Shared. This one is located in %System% |
| X | System Profile | Regsrv.exe | Added by a variant of the OPTIX TROJAN! |
| X | System Protector | lsascs.exe | System Protector rogue security software - not recommended, removal instructions here |
| X | System RAID Manager | raid64.exe | Added by the AGENT-NNZ TROJAN! |
| X | System Reboot | rebootsys.exe | Added by the RBOT-WU WORM! |
| X | System Redirect | sysbho.exe | Downloader trojan, "Melkosoft" adware related |
| X | System Registry Manager | sysrgmgr.exe | Added by an unidentified WORM or TROJAN! See here |
| X | System Restore | svcnet.exe | Added by the TIBICK WORM! |
| X | System Restore | wscript.exe SysRes.vbs | Added by the AUTORUN-FM WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "SysRes.vbs" file is located in %Windir% |
| X | System Restore Data | [path] repcale.exe [path] beird.exe | Added by the RANDON.AN WORM! Both files are located in %System%\frbyjed |
| X | System Scanner | system.exe | Added by the AGOBOT-DI BACKDOOR! |
| X | System Security Checker | ssc.exe | Added by the IRCBOT-WI TROJAN! |
| X | System Security Updaters | vsmons.exe | Added by the RBOT-OW WORM! |
| X | System Service | servicent.exe | Added by the RBOT-AJI WORM! |
| X | System service | system.exe | Added by the BANCOS.AA TROJAN! |
| X | System Service | msnwindows.exe | Added by the SPYBOT.YCL WORM! |
| X | System Service | servicez.exe | Added by the RBOT-AOY WORM! |
| X | System Service | msnxpexe.exe | Added by the RBOT-AUA WORM! |
| X | System Service | teskmangr.exe | Added by the RBOT-AUV WORM! |
| X | System Service | backup.exe | Added by the PACKBOT.AA WORM! |
| X | System Service | serious.exe | Added by the RBOT-FMV WORM! Note - deactivates the Microsoft Internet Connection Firewall (ICF) |
| X | System Service | b4db0yz.exe | Added by the RBOT-CLO WORM! |
| X | System Service | MSREXE.EXE | Added by the AML TROJAN! |
| X | system service | spoolcrv.cpl | Added by the INSPIR.11 TROJAN! |
| X | System Service | systems.exe | Added by the AGOBOT.VZ WORM! |
| X | System Service | coderxt.exe | Added by the RBOT-ALD WORM! |
| X | System Service | exp0lrer.exe | Added by a variant of the RBOT WORM! |
| X | System Service Control | [trojan filename].exe | Added by the THROD.A TROJAN! The filename is a random combination the following: ms, svc, win, 16, 32, 64, mes, prn, reg - "ms16prn.exe", for example - and is located in %System% |
| X | SYSTEM service helper | svchelper.exe | Added by the MONKBD-A WORM! |
| X | SYSTEM service helper | syshelp.exe | Added by a variant of the MONKBD-A WORM! |
| X | System Service Manager | lsmas.exe | Added by the AGOBOT-IK BACKDOOR! |
| X | System Service Manager | norton.exe | Added by the GAOBOT.AJE WORM! |
| X | System Service Manager Device | svho.exe | Added by the RBOT.GCG BACKDOOR! |
| X | System service** | pokapoka**.exe | EliteBar adware - where ** represents the numbers 61 to 79 |
| X | System service78 | [path to file] | Added by the ELITEBAR-T and ELITEBAR-U TROJANS! |
| X | System service79 | [path to file] | Added by the ELITEBAR-V TROJAN! |
| X | System Services | [random file name] | Added by a variant of the RBOT WORM! |
| X | System Services | connection.exe | Added by an unidentified WORM or TROJAN! |
| X | System Services | svcsenes.exe | Added by a variant of the RBOT WORM! |
| X | System Services | svcsenes32a.exe | Added by the RBOT-AFG WORM! |
| X | System Services | ssms.exe | Added by a variant of the RBOT WORM! |
| X | System Services Monitor | server.exe | Bifrost malware |
| X | System Servlce | live.exe | Added by the IRCBOT-GX WORM! |
| X | System Session Manager | smss.exe | Added by the KALEL-E WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup! |
| X | System settings | burndl32.exe | Added by the SDBOT-ZO WORM! |
| X | System Setup | rpcxcmod.exe | Added by an unidentified WORM or TROJAN! |
| X | System Soap Pro | soap.exe | System Soap Pro internet cleaning software. Bundles foistware like Httper and Zipclix - best avoided |
| X | system spool | syspools.exe | Added by the DREF-T WORM/VIRUS! |
| X | System Spooler Subsystem | lssas.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| U | System startup | charmapx.exe | Only required if using an oriental language |
| X | System Startup | Voltio.exe | Added by the RBOT.NJ WORM! |
| X | System Startup | kimochi.exe | Added by a variant of the RBOT WORM! |
| X | System Startup | sys.exe | Added by a variant of the IRCBOT TROJAN! |
| X | System Startup Manager | smcss.exe | Added by the RBOT.AMD WORM! |
| X | System Stats | SystemStats.exe | Added by a variant of the WOOTBOT WORM! |
| X | System Support | syscfg.exe | Added by the RBOT-AGQ WORM! |
| X | System Support | system32.exe | Added by the RBOT-AHA WORM! |
| X | System Support | syssql.exe | Added by the RBOT-AUH WORM! |
| X | System Support | torrent.exe | Added by a variant of the RBOT WORM! |
| X | System Task Manager | taskmrg.exe | Added by a variant of the SPYBOT WORM! See here |
| X | System Terminal | SYSTEM2.EXE | Added by the SPYBOT-BZ TROJAN! |
| X | System time updator | CSysTime.exe | Added by the RANDEX.S WORM! |