| Status | Autorun name | Command | Description |
| X | system34.exe | system34.exe | Added by the DWNLDR-FXY TROJAN! |
| X | System4224411 | Virus | Added by the CAGER.A WORM! |
| X | System4224411 | Systemdll.exe | Added by the YUSUFALI-B WORM! |
| X | system43.exe | system43.exe | Added by a variant of the SDBOT WORM! |
| X | System51616 | msnmsgesser.exe | Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger |
| X | System64 | inet.exe | Added by the DENGLE-A TROJAN! |
| X | SYSTEM798RUNNER.exe | SYSTEM798RUNNER.exe | Added by the VB-EYW TROJAN! |
| X | systemadd | sysdate32.exe | Added by the AUTORUN-AVN WORM! |
| X | SystemAdministration | Wincmp32.exe | Added by the ASYLUM TROJAN! |
| U | SystemAgent | Sage.exe | "Microsoft Plus! System Agent automatically tunes your system, performing tasks such as disk optimization and error correction. It can also run any application at prescheduled times" |
| X | SystemArmor | SystemArmor.exe | SystemArmor rogue security software - not recommended, removal instructions here |
| X | SystemB | MessengerStopper.exe | MessStopper adware |
| X | systemb | systemb.exe | Added by a variant of the IRCBOT TROJAN! |
| X | SystemBackup | mtx.exe | Added by the MTX VIRUS/WORM! |
| X | SystemBackup | MicroLog.exe | Added by the MICROLOG.A TROJAN! |
| X | SystemBooster2009 | sbr_updater.exe | SystemBooster2009 rogue system suite - not recommended, removal instructions here |
| ? | SystemBoot | ladies.htm | Unknown but sounds very suspicious?? |
| X | SystemBoot | Mshta.exe ...filename.hta | Adult content dialler |
| X | SystemBoot | services.exe | Added by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help\Help |
| X | Systemboot | msnsngr.exe | Added by a variant of the RBOT WORM! |
| X | SystemCheck | Systemcheck.exe | Added by the LAVITS WORM! |
| X | SystemCheck | services.exe | Added by the SOBER-M WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Config\system |
| X | SystemCheck | svchost.exe | Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "DriverLoad" sub-directory of the Root folder (C:\), (D:\), etc |
| X | SystemCheck | [path to file] | WinBo adware |
| U | Systemcheck | sb32mon.exe | Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself! |
| X | SystemChecker | Syschk.exe | Added by the GALIL.F WORM! |
| X | SystemCleaner | Clean2.exe | Added by the AUTORUN-AZE WORM! |
| X | SystemCleanerPRO | sysclpro.exe | SystemCleanerPro rogue security software - not recommended, removal instructions here |
| X | SystemCONF98i | SystemCONF98i.exe | Added by the GLITCH TROJAN! |
| X | SystemCop | SystemCop.exe | SystemCop rogue security software - not recommended, removal instructions here. A member of the WiniGuard family |
| X | SystemData | MBlocker.exe | Messenger Blocker rogue security software - not recommended |
| X | SystemDebug | Sysdeb32.exe | Added by the SYSBUG TROJAN! |
| X | SystemDefender | SystemDefender.exe | SystemDefender rogue spyware remover - not recommended, removal instructions here |
| X | SystemDevic | devic.exe | Added by the MIMBOT.A WORM! |
| X | SystemDll | SystemDll.exe | Added by the LOXOSCAM TROJAN! |
| X | systemdll.dll | winsys32.exe | Added by the DELF.CP BACKDOOR! |
| X | systemdll32.exe | systemdll32.exe | Added by the FEUTEL-F TROJAN! |
| X | SystemDoctor 2006 Free | sd2006.exe | SystemDoctor rogue security software - not recommended, removal instructions here |
| X | SystemDoctor Free | systemdoc.exe | SystemDoctor rogue security software - not recommended, removal instructions here |
| X | systemdrea | rundll32.exe [path] systemdrea.dll | Added by the AGENT-RKB TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "systemdrea.dll" file is located in %UserProfile%\Microsoft |
| X | SystemDrive | maxpaynow1.exe | Added by the TIBS.BKU TROJAN! |
| X | SystemDriver | csrss.exe | Added by the ASCETIC.B TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\addins\explorer |
| X | SystemDriverCheck | svchost.exe | Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "DriverLoad" sub-directory of the Root folder (C:\), (D:\), etc |
| X | SystemDriverLoad | svchost.exe | Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "DriverLoad" sub-directory of the Root folder (C:\), (D:\), etc |
| X | systemdrv | ms32sys.exe | Added by an unidentified WORM or TROJAN - most likely GAOBOT variant |
| X | SystemEmergency | [various filenames] | CoolWebSearch Smartsearch parasite variant. Also detected as the GOWEH.A WORM! Typical filenames include internet.exe, systeem.exe, explore.exe and directx.exe |
| X | SystemErrorFixer | SysRep.exe | SystemErrorFixer rogue system error and cleaning utility - not recommended. A member of the ErrClean family |
| X | SystemExplorer | explore.exe | Homepage hijacker - file located in the "Services" folder in Common Files |
| N | SystemExplorer | SystemExplorer.exe | System Explorer by Mister Group - a "free, awards winning software for exploration and management of System Internals." Provides detailed information about tasks, processes, startups and services; suspicious file checking via VirusTotal, Jotti and their own database and other resources |
| N | SystemExplorerAutoStart | SystemExplorer.exe | System Explorer by Mister Group - a "free, awards winning software for exploration and management of System Internals." Provides detailed information about tasks, processes, startups and services; suspicious file checking via VirusTotal, Jotti and their own database and other resources |
| X | Systemey | systemey.exe | Added by the SLINBOT.JF BACKDOOR! |
| X | SystemFighter | SystemFighter.exe | SystemFighter rogue security software - not recommended, removal instructions here. A member of the WiniGuard family |
| X | SystemFile | SystemFile.exe | Added by the DULLDOOR-A TROJAN! |
| X | SystemFTP | VSENMB.exe | Malware (ie, malicious software). Also changes the system.ini Shell line to read Shell=Explorer.exe VSENMB.exe, and it hacks the Winstart.bat as well |
| X | SystemGent | CVT.exe | Added by the BRONTOK-H WORM! |
| X | systemguard | systemguard.exe | System Guard 2009 rogue security software - not recommended, removal instructions here |
| ? | SystemGuardAlerter | SystemGuardAlerter.exe | Part of the Iolo System Mechanic maintenance software. What does it do? |
| X | SystemGuardCenter | SystemGuardCenter.exe | System Guard Center rogue security suite - not recommended, removal instructions here |
| X | SystemHelp | RUNDLL32.EXE SystemHper.dll,Install | Added by the WOW.COK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "SystemHper.dll" file is found in %System% |
| X | SystemIL | SYSTEMIL.EXE | Added by the ABOC VIRUS! |
| X | SystemInit | iservc.exe | Added by the FIZZER WORM! |
| X | systeminit | systeminit.exe | Added by the SILLYFDC-AN WORM! |
| X | Systemiom Updater | Systemiom.exe | Added by the SPYBOT.TY WORM! |
| X | SystemIron | SystemIron.exe | SystemIron rogue security software - not recommended, removal instructions here. A member of the WiniGuard family |
| X | systemkernal.exe | systemkernal.exe | Added by the AGENT-KPQ TROJAN! |
| U | SystemKey | rundll32.exe [path] SystemKey.dll rdl | Stealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | systemks | systemks.exe | Added by the DKS.11.B TROJAN! |
| X | SystemLoad32 | sysload32.exe | Added by the MIMAIL.E WORM! |
| X | SystemLoader | sysldr32.exe | Added by the DOWNLDR-NS TROJAN! |
| X | SystemManager | Sysman32.exe | Added by the DOWNLOADER-BW.B TROJAN! |
| X | SystemManager | [random filename] | Added by the SETTEC ROOTKIT! |
| X | SystemMap32 | Netisp32.vbs | Added by the REDIST.C WORM! |
| X | SystemMD | md.exe | Homepage hijacker |
| X | SystemMessenger | rundll32.exe [path] SystemMessenger.dll | Stealth Chat Monitor spyware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | SystemMgr | Ir32_a.exe | Added by the MAGANIA-OU TROJAN! |
| X | SystemMigration | WinMedia.exe | Added by the KELVIR.EI WORM! |
| X | SystemMonitor | Sysmon32.exe | Added by the AIDID.A WORM! |
| X | SystemNetwork | NETSERV.EXE | Added by the NETCONTROL VIRUS! |
| X | SystemNetwork | sysnet.exe | Added by a variant of the RBOT WORM! |
| X | SystemNT | SystemNT.exe | Added by the PWSVB-EG TROJAN! |
| X | systemntfy | systemntfy.exe | Added by the MINUDAZASH WORM! |
| X | SystemOPsv | scrtvc32.exe | Added by a variant of the SPYBOT WORM! |
| X | SystemOptimizer2008 | main.exe | SystemOptimizer2008 rogue optimization utility - not recommended, removal instructions here |
| X | SystemOrdnare | SysRep.exe | SystemOrdnare, Swedish rogue system error and cleaning utility - not recommended. A member of the ErrClean family |
| X | SystemProcEvent | [trojan filename] | Added by the IRCBOT.I TROJAN! Filenames used are csrwnd.exe, csrwjd.exe & csrnvrt.exe |
| X | systemr | d11host.exe | Added by the VB-GX TROJAN! |
| X | systemr | gedit.exe | Added by the ADCLICK-AQ TROJAN! |
| X | systemr | [path to trojan] | Added by the VB-HD TROJAN! |
| ? | SystemReg | PROCES.EXE | ?? |
| X | SystemReg | svchost.exe | Added by the DEWIN.E BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | SystemReg | WINREG.EXE | Added by the DEWIN.A BACKDOOR! |
| X | SystemRegistryRepair | temp.exe | Added by the NOKPUDA WORM! |
| X | Systems | sescmgr.exe | Added by the DWNLDR-GAH TROJAN! |
| X | Systems | spoolsvc.exe | Added by the DLOADR-SW TROJAN! |
| X | Systems | sysmon.exe | Added by the VIXUP-BI WORM! |
| X | Systems | scchost.exe | Added by the DAEMOZ.A TROJAN! |
| X | Systems | svch0st.exe | Added by the MYDOOM.BI WORM! |
| X | Systems | Systems.exe | Added by the BANKBOA-A TROJAN! |
| X | Systems | itDDD.exe | Added by the DLOADER-PP TROJAN! |
| X | Systems Backups | windrives.exe | Added by the AGOBOT-RB WORM! |