| Status | Autorun name | Command | Description |
| X | System | SVCHOST.EXE | Added by the LDPINCH-AU TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | system | lsasse.exe | Added by the RBOT-YL WORM! |
| X | System | systray.exe | Added by the PISABOY-A TROJAN! Note - this is not the legitimate systray.exe process |
| X | System | abcdefg.exe | Added by the HARWIG-B WORM! |
| X | System | cber.exe | Added by an unidentified TROJAN! |
| X | System | serwin.exe | Added by the LDPINCH-BN TROJAN! |
| X | System | svchîst.exe | Added by the LDPINCH-BF TROJAN! |
| X | System | system.exe (74295303) | Added by the VB-IU WORM! |
| X | System | WINL0G0N.EXE | Added by the BANCOS-DB TROJAN! |
| X | System | wumgrd32.exe | Added by a variant of the RBOT WORM! |
| X | System | SPOOLSU.EXE | Added by the BANKER-FC TROJAN! |
| X | System | system23.exe | Added by the LEBREAT-D WORM! |
| X | System | windowsps.exe | Added by a variant of the RBOT WORM! |
| X | SYSTEM | d.exe | Added by the MYTOB.LP WORM! |
| X | System | inetinfo.exe | Added by the PARDROP-A TROJAN! |
| X | system | services.exe | Added by the DELF-LQ TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\HELP |
| X | SYSTEM | VSSMON.exe | Added by the RBOT-AWW TROJAN! |
| X | SYSTEM | wiinlogon.exe | Added by the RBOT-AVG WORM! |
| X | System | kernels64.exe | Added by the VIXUP-S TROJAN! |
| X | system | lsass.exe | Added by the SATILOLER.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System |
| X | System | smss.exe | Added by the AGENT.EP BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | System | winupd.exe | Added by a variant of the SDBOT WORM! |
| X | system | messenger.exe | Added by an unidentified WORM or TROJAN! |
| X | System | kernels1118.exe | Added by a variant of the SDBOT WORM! |
| X | System | wsscntfy.exe | Added by a variant of the SDBOT WORM! |
| X | SYSTEM | windmupdr.exe | Added by a variant of the RBOT WORM! |
| X | system | svcr.exe | Added by the SPYONE TROJAN! |
| X | System | kernels88.exe | Added by the TIBS-PP TROJAN! |
| X | System | kernels8.exe | Added by the TIBS.AI TROJAN! |
| X | System | OeApi.vbs | Added by the AGUI WORM! |
| X | System | Updaterun.exe | Added by the QQHELP-DX TROJAN! |
| X | System | Zap.exe | Added by the MSNVB-D WORM! |
| X | System | BrO_AcT.exe | Added by the SILLYFDC-AL WORM! |
| X | System | Juegs.exe | Added by the CULLER-C WORM! |
| X | System | kernel8.exe | Added by the DLOADR-AOL TROJAN! |
| X | System | kernelwind32.exe | Added by the VXIDL.FT TROJAN! |
| X | System | Xsfr.exe | Added by the CULLER-D WORM! |
| X | System | kernelwind64.exe | Added by the DLOADER.DJD TROJAN! |
| X | SYSTEM | SystemFile.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | system | ssclie.exe | Added by the AGENT.LW BACKDOOR! |
| X | system | Winhelp.exe | Added by the IMAUT.CN WORM! |
| X | system | kernel32.ini | Added by the SILLYFDC.CJ WORM! |
| X | System | testtestt.exe | Added by the DWNLDR-ZLC TROJAN! |
| X | system | Microsoft Office.exe | Added by the BANCBAN-LH TROJAN! |
| X | System | IEXPL0RE.EXE | Added by the VB.KS WORM! Note the number "0" in the filename |
| X | system | sysnet.exe | Added by the VETOR-J WORM! |
| X | system | systemdb.exe | Barracuda Antivirus and Security Central rogue security software - not recommended, removal instructions here and here |
| X | System | winipck.exe | Added by the RBOT-TK WORM! |
| X | System | krln32.exe | Malware installed by different rogue security software including SpyKillerPro |
| X | system | system64.exe | Added by the BANCBAN-PP TROJAN! |
| X | System | antivirus.vbe | Added by the AUTORUN-AYI WORM! |
| X | SYSTEM | RUNDLL16.exe | Added by the DELF-EW BACKDOOR! |
| X | System | systemz.exe | Added by the VILSEL-B TROJAN! |
| X | System 64 Driver for Games | sys64dvr.exe | Added by the SDBOT TROJAN! |
| X | System Analyzer | lsass32.exe | Added by the SDBOT.CNI WORM! |
| X | System Applications Profile | sap.exe | Added by the RBOT-QF WORM! |
| X | System Auth | system52.exe | Identified as a variant of the Win32:Rizo-E malware |
| X | System Backup | msystem.exe | Adult content dialler |
| X | System backup | [random filename] | Added by the ADMINCASH.B TROJAN! Note - multiple different file names have been spotted, examples: web.exe, soft.exe, msxmidi.exe, wmplayer.exe, as well as completely random ones such as 9a2de006.exe, 36c75e3c.exe and so on |
| X | System Backup | sysbcp32.exe | Added by the AGOBOT-NP BACKDOOR! |
| X | System Backup Services | backups32.exe | Added by a variant of the RBOT WORM! |
| X | System Boot Check | sysload3.exe | Added by the FUBALCA WORM! |
| X | System Boot Loader | sysboot32.exe | Added by the SDBOT.PG WORM! |
| X | System Buffer Application | buffer32.exe | Added by the SDBOT-UD WORM! |
| X | System Cache | SysCache.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | System CGI Manager | syscgmgr.exe | Added by an unidentified WORM or TROJAN! See here |
| U | System Check | Rundll32.exe SysDll32.dll, SystemCheck | XPCSpy Pro keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | system check | updater.exe | Unidentified adware downloader |
| X | System Check | win_klr32.exe | Added by the DELF-DRA WORM! |
| X | System Checking | wasul.exe | Added by the RBOT.BHM WORM! |
| X | System Config | BF3.EXE | Added by the SPYBOT-DT WORM! |
| X | System Config | sysloadcnf.exe | Added by a variant of the SDBOT WORM! See here |
| X | System Config Boot | syscgboot.exe | Added by the AGENT.VWU TROJAN! |
| X | System Config Manager | crss.exe | Added by the AGOBOT.GH WORM! |
| X | System Config Manager | smssl.exe | Added by the AGOBOT-ZJ WORM! |
| X | System Configuration | iexplore.exe | Added by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
| X | System Configuration | syscfg32.exe | Added by the MYTOB.EA WORM! |
| X | System Configurator | systemconfig.exe | Added by the SDBOT-OR WORM! |
| X | System Configurator32 | SYSTEMCFG.EXE | Added by the AGOBOT-KS WORM! |
| X | system configure | svchost.exe | Added by the LINEAGE-C TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup! |
| X | System Core Memory | syscoremem.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | System CPL manager | [random filename] | Added by the RBOT-SR WORM! |
| X | System CSRSS Patch | scrtkfg.exe | Added by the RBOT-ADA WORM! |
| X | System Database administration | systemDA.exe | Added by the DERDERO.B WORM! |
| X | System Database Administration Support Process | sysdasp.exe | Added by the DERDERO.C WORM! |
| X | System DataBase Root | sysdbroot.exe | Added by the QHOST-W TROJAN! |
| X | System DB Manager | sysdbmg.exe | Added by an unidentified WORM or TROJAN! See here |
| X | System Defender | WS[random characters].exe | System Defender rogue security software - not recommended, removal instructions here |
| X | System Development Operations | sysdevop.exe | Added by the AGENT-OFQ TROJAN! |
| X | System Device | devices.exe | Added by the AGENT.AFIF WORM! |
| X | System Device Version | systemdv.exe | Added by a variant of the RBOT WORM! |
| X | System Diagnostics | sysdiag32.exe | Added by the SDBOT.GEN BACKDOOR! |
| X | System Directory Service | [trojan filename].exe | Added by the THROD.A TROJAN! The filename is a random combination the following: ms, svc, win, 16, 32, 64, mes, prn, reg - "ms16prn.exe", for example - and is located in %System% |
| N | System DLF | cpqdiaga.exe | Compaq Diagnostic record system utility which allow you to view information about your computer's hardware and software configuration. Available via Start -> Programs |
| U | System DLL Resources | sysdll.exe | SnapKey is a surveillance software program that records all keyboard activities. Uninstall this software unless you put it there yourself |
| X | System Doctor Free | systemdoc.exe | SystemDoctor rogue security software - not recommended, removal instructions here |
| X | System Document Application | nmod.exe | Added by the SDBOT-ABB WORM! |
| X | System Document Application | msdocument.exe | Added by the RANDEX.COX WORM! |
| X | System Document Application | wins.exe | Added by the SDBOT.AUB WORM! |
| X | System Document Application | winsvc32.exe | Added by the SDBOT-VA WORM! |