| Status | Autorun name | Command | Description |
| X | syscfg | syscfg32.exe | Added by the KWBOT.S WORM! |
| X | syscfg34.exe | syscfg34.exe | Added by the ELECTRON WORM! |
| X | Syscheck | win.hta | Browser hijacker |
| X | syscheck | iexplorer.exe | Added by the AGENT.DM TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
| U | SysCheck32 | sb32mon.exe | Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself! |
| X | SysCleaner | SysCleaner.exe | SysCleaner rogue cleaning utility - not recommended, removal instructions here |
| X | sysclx | ntldrt.exe | Added by the JLOK-A WORM! |
| X | syscm | Syscm.exe | Vanish adware |
| X | SysCom | msnmsgr.exe | Added by the BANK-AF TROJAN! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %Windir%\system |
| ? | SysComp | mssdnl.com | Unknown but suspect as *.com are not usually run at start up and the name isn't recognized |
| X | syscon | syscon.exe | Added by the APRILCONE.A WORM! |
| X | syscon lptt01 | syscon.exe | RapidBlaster variant (in a "syscon" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | syscon ml097e | syscon.exe | RapidBlaster variant (in a "syscon" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | sysconf | sysconf.exe | Added by the AGOBOT-IW WORM! |
| X | sysconfig | iexplorer.exe | Added by the CULT.C WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
| X | SysConfig | syscfg35.exe | Added by the KAZMOR.C WORM! |
| X | SysConfig | wincfg32.exe | Added by the SDBOT.ZD WORM! |
| U | Sysconfig | Stealth KeySpy.exe | StealthKeySpy - keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | sysconfig32 | sysconfig32.exe | Added by the AGENT-MSP TROJAN! |
| U | SysConn_Start | svcwinra.exe | System Surveillance Pro surveillance software. Uninstall this software unless you put it there yourself |
| X | Syscpy | Syscpy.exe | Firewall-bypassing, proxied spam relayer. Detected by Symantec as the HOGLE TROJAN! |
| X | SysCtl | sysctl.exe | Added by the AOK TROJAN! |
| X | Sysctrls | procdll.exe | Added by the WEEDBOTZ.14 BACKDOOR! |
| X | Sysctrls | winupdate.exe | Added by an unidentified WORM or TROJAN! |
| X | Sysctrls | mscntrl.exe | Added by the KOLABC.BB WORM! |
| X | Sysctrls | Sysctrls.exe | Added by the AGENT.AWZ TROJAN! |
| X | Sysctrls | win32dll.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Sysctrls32 | sevchost.exe | Added by the RBOT.ADF BACKDOOR! |
| X | SysCVMS.exe | SysCVMS.exe | Added by the SMALL.CBA TROJAN! |
| X | sysdat.dll | sysdat.dll.exe | Added by the NISHICA 1.1 TROJAN! |
| X | SysData | [path to file] | Added by the RANCK-BA TROJAN! |
| X | SysDefence.exe | SysDefence.exe | SysDefence rogue security software - not recommended, removal instructions here. A member of the AntiAID family |
| X | SysDefenders | SysDefenders.exe | SysDefenders rogue security software - not recommended, removal instructions here. A member of the AntiAID family |
| X | SysDepannage | SysRep.exe | SysDepannage, French rogue system error and cleaning utility - not recommended. A member of the ErrClean family |
| X | SysDesk | svchoxt.exe | Added by the DELF-EDE TROJAN! |
| X | SysDeskqqfx | qqfx.exe | Added by the QQPASS.H TROJAN! |
| X | SysDeskqqfx | Runddll32.exe | Added by the CHANGGAME TROJAN! |
| X | SysDesktop | fswanQQ.exe | Added by the QQSEND-A TROJAN! |
| X | sysdiag64.exe | sysdiag64.exe | Added by the AUTOINF-AB WORM! |
| X | sysdir | winrun.exe | Added by the WINBUR.B WORM! |
| X | sysdll | windll.exe | Added by the AUTORUN.ECT WORM! |
| X | sysdll | [trojan filename] | Added by the HUGESOT TROJAN! |
| X | Sysdpt | sysdpt.exe | Added by the CRYPT TROJAN! |
| X | SysDriver | sysdriver.exe | Added by the CARRIER.JC WORM! |
| X | SysDrv | [trojan filename] | Added by the AGENT-GOT TROJAN! |
| X | sysdxvid | sysdxvid.exe | Added by the DLUCA-S TROJAN! |
| X | sysemls | sysem.exe | Added by a variant of the SDBOT WORM! |
| X | SysEQ | svclgx32.exe | Added by the IRCBOT-AC TROJAN! |
| X | sysfbtray | bill102.exe | Added by the VB-ENI TROJAN! |
| X | sysfbtray | bill106.exe | Added by the MDROP-CLV TROJAN! |
| X | sysfbtray | bill117.exe | Added by the VBKRYPT-E TROJAN! |
| X | sysfbtray | bill103.exe | Added by the MDROP-CLF TROJAN! |
| X | sysfbtray | bill104.exe | Added by the MDROP-CLO TROJAN! |
| X | sysfbtray | bill108.exe | Added by the MDROP-CMW TROJAN! |
| X | sysfiler | sysfiler.exe | Added by the RETSAM TROJAN! |
| X | SYSfit | SYSfit.exe | AdShooter adware variant |
| X | sysflg32 | sysflg32.exe | Added by a variant of the CRYPTER.C TROJAN! |
| X | sysformat | sysformat.exe | Added by the BAGLE-BK WORM! |
| X | sysfrcx | sysfrcx.exe | Added by the KEYLOG-SCLOG TROJAN! |
| X | sysftray2 | bolivar19.exe | Added by the KOOBFACE.I WORM! |
| X | Sysgate Personal Firewall | syst3ms.exe | Added by a variant of the IRCBOT TROJAN! |
| X | Sysgate Personal Firewall | win32s.exe | Added by the SDBOT.YZB WORM! |
| X | sysguard | sysguard.exe | Added by the FAKEAV-KI TROJAN! |
| X | sysguardn | s | Spyware Protect 2009 rogue spyware remover - not recommended, removal instructions here |
| X | syshelp | syshelp.exe | Added by the LOVGATE.C WORM! |
| X | syshost | syshost.exe | Added by the VB-DVZ TROJAN! |
| X | sysin | [path to file] | Added by the DSRC-A TROJAN! |
| X | sysinfo | sysinfo.exe | Added by the BEDRILL TROJAN! |
| X | sysinfo.exe | sysinfo.exe | Added by the BEAGLE.V WORM! |
| X | SysInit | wininit32.exe | Added by the XABOT WORM! |
| X | sysinit | services.exe | Added by the NEWLFRM-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\golumm |
| X | Sysino | lsess.exe | Added by the FORBOT-BF WORM! |
| X | sysint16 | sysint16.exe | Added by the CRYPTER.A TROJAN! |
| X | sysinter | ADIRSS.EXE | Added by the AGENT.JVJ TROJAN! |
| X | sysj32.exe | sysj32.exe | Added by the IRCBOT-AHH BACKDOOR! |
| X | Syskey | sysinit.exe | Added by the BEAGLE.AX WORM! |
| X | sysldtray | ld02.exe | Added by the KOOBFACE.BG WORM! |
| X | sysldtray | ld03.exe | Added by the KOOBFACE.CA WORM! |
| X | sysldtray | ld11.exe | Added by the KOOBFACE.JG WORM! |
| X | sysLDtray | ld08.exe | Added by the AGENT-JSV TROJAN! |
| X | sysldtray | ld09.exe | Added by the AGENT-KFI TROJAN! |
| X | sysldtray | ld10.exe | Added by the FAKEAV-UD TROJAN! |
| X | sysldtray | ld12.exe | Added by the KOOBFACE.V WORM! |
| X | sysldtray | ld01.exe | Added by the KOOBFACE.I WORM! |
| X | sysldtray | ld15.exe | Added by the AGENT-LNH TROJAN! |
| X | sysldtray | ld04.exe | Added by the KOOBFACE WORM! |
| X | sysldtray | ld06.exe | Added by the KOOBFACE WORM! |
| X | sysldtray | ld07.exe | Added by the KOOBFACE WORM! |
| X | sysldtray | ld14.exe | Added by the VIRUT.CE VIRUS! |
| X | sysldtray | ld16.exe | Added by the AGENT-MMO TROJAN! |
| X | Syslib | Syslib.exe | Adult content related downloader trojan |
| X | SysLive | SysLive.exe | Added by the EXPICHU WORM! |
| U | syslog | syslog.exe | EZKeylogger keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | Syslog lptt01 | Syslog.exe | RapidBlaster variant (in a "syslog" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | Syslog ml097e | Syslog.exe | RapidBlaster variant (in a "syslog" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | syslogin.exe | syslogin.exe | Added by the BAGZ-B WORM! |
| X | syslogon | syslogon.exe | Added by the SPYBOT-EP WORM! |
| X | SysMain | buff.exe | Added by the AGENT-ECW TROJAN! |
| U | Sysman | Sysman.exe | KeyTrap is a surveillance software program that records all keyboard activities. Uninstall this software unless you put it there yourself |
| X | SysManager | Manager.EXE | Added by the DAGGER.140 BACKDOOR! |