| Status | Autorun name | Command | Description |
| X | SystemWarrior | SystemWarrior.exe | SystemWarrior rogue security software - not recommended, removal instructions here. A member of the WiniGuard family |
| U | SystemWeb | rundll32.exe [path] SystemWeb.dll rdl | StealthWeblog surveillance software. Uninstall this software unless you put it there yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | SystemWideHook for Windows NT | %WinHook32.exe | Added by the MYDOOM.AC WORM! |
| X | SystemWindows | scvhost.exe | Added by the SILLYFDC-CG WORM! |
| U | SystemWizard Sniffer | Sniffer.exe | SystemWizard for Win98/ME from SystemSoft - diagnoses and solves hardware and software problems on a PC |
| X | SystemX | nzm.exe | Added by a variant of the RBOT WORM! |
| X | systemx32 | systemx32.exe | Added by a variant of the RBOT WORM! |
| X | systemyom Updater | systemyom.exe | Added by a variant of the IRCBOT TROJAN! |
| X | SYSTEMZ Patch | SYSZ.exe | Added by the ALADINZ.P TROJAN! |
| X | systen32.exe | systen32.exe | Added by the DLOADR-AQP TROJAN! |
| X | Systes | jrdtifkkxbbsa.exe | Added by the RBOT-ADC WORM! |
| X | Systesms.exe | systesms.exe | Added by the RBOT-HI WORM! |
| U | Systest | Systest.exe | Clean Space internet evidence eliminator |
| X | SysteZ | d1.exe | Added by the MSNDIABLO.A WORM! |
| X | systhread | winkernal.exe | Added by the LIAMED WORM! |
| X | systhread | HELLO.EXE | Added by the WINKER.F BACKDOOR! |
| X | SysTime | systime.exe | CoolWebSearch parasite variant - also detected as the STARTPA-FL TROJAN! |
| X | Systmesy | Systmesy.exe | Added by the RBOT-KQ WORM! |
| X | SYSTMON.EXE | SYSTMON.EXE | Added by the SILLY-H WORM! |
| X | Systoan32 | systoan.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | systr | SYSERVER.exe | Added by the VB-DQY WORM! |
| X | systr2 | SERVICE.exe | Added by the VB-DQY WORM! |
| ? | systr32 | systr32.exe | ?? |
| X | systrans | [path to trojan] | Added by the STARTPA-GZ TROJAN! |
| X | systrasx | CONSOLES.EXE | Added by the SDBOT-NW WORM! |
| ? | systrax | systrax.exe | ?? |
| X | Systray | Systray_.Exe | Added by the KERGEZ.A WORM! |
| X | Systray | [filename.exe] | Winfavorites adware |
| X | SYSTRAY | UNMT.EXE | Added by the DLOADER-LQ TROJAN! |
| X | SysTray | SysTray.Exe | Added by the BANCBAN-JV TROJAN! Note - this is not the legitimate systray.exe process from Win9x/Me systems which would appear in the Name/Startup Item field as SystemTray in the registry "Run" keys and MSConfig. If you right-click on the real systray.exe the "Properties" reveal it to be a Microsoft file |
| X | SysTray | Snnpapi.exe | Added by an unidentified TROJAN! |
| X | Systray | w32explorer.exe | Added by the RBOT-AJY WORM! |
| X | Systray | SteFanie.vbs | Added by the STEFAN WORM! Note - make sure you check the hyperlink as this one copies it's self to numerous dirves and folders |
| X | Systray | KAT.vbs | Added by the SOAD-D WORM! |
| X | SysTray | svhost.exe | Added by the RAJILO-A WORM! |
| X | SysTray | system.exe | Added by the DELF.E TROJAN! |
| X | systray | system234.exe | Added by the AUTORUN.AEV WORM! |
| U | systray | winlogin.exe | KidControl surveillance software. Uninstall this software unless you put it there yourself |
| U | systray | systray.exe | Dell Mobile Broadband wireless configuration utility - located in %ProgramFiles%\Dell\Dell Mobile Broadband |
| X | Systray driver | systray.exe | Added by the MUTEBOT TROJAN! Note - this is not the legitimate systray.exe process |
| U | systray for fax applications | faxtray.exe | System Tray access to Fax-Internet software by AXMA |
| X | SystrayServices | Msxpw.exe | Added by the CITOR WORM! |
| U | SYSTRAYX | SysTrayX.EXE | "SystrayX helps you hide some of the less used icons from the system tray (the hidden icons can still be seen and used in the special SysTrayX menu but will no longer permanently take precious space from your system tray)" |
| X | systree | systree.exe | Added by the BANCOS.L TROJAN! |
| X | Systry | [path to worm] | Added by the AUTEX WORM! |
| X | Systryt | [path to worm] | Added by the AUTEX WORM! |
| X | SystUphes | algesetp.exe | Added by the QQPASS-AM TROJAN! |
| U | Systweak Ad and Popup Blocker | adblock.exe | Ad and popup blocker part of Advanced System Optimizer from Systweak |
| U | Systweak Memory Optimizer | memtuneup.exe | Part of SysTweak Advanced System Optimizer |
| X | systwtray | twitty**.exe [** = random digits] | Added by the KOOBFACE.C WORM! |
| X | sysu | sysu.exe | Dynamic Desktop Media adware - see here |
| X | sysug32.exe | sysug32.exe | Added by an unidentified TROJAN or WORM! |
| X | SysUpd | Sysupd.exe | VirtuMonde adware |
| X | sysupdate | cmman32.exe | Added by a variant of the SDBOT WORM! |
| X | SysUtils | smss.exe | Added by the AUTORUN-AWW WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile% |
| X | Sysvupex | Sysvupex.exe | Added by the MEDIAS TROJAN! |
| X | sysvx | sysvx_.exe | Added by the LOOSKY-BX TROJAN! |
| U | SysW8 | csta.exe | Clean Space internet evidence eliminator |
| U | SYSWB6 | SYSWB6.exe | Part of We-Blocker - gives parents the opportunity to monitor their children's Internet access and provide them with age-appropriate content, while filtering out sites that contain adult content. Works in conjunction with Winkb6 and both files are needed to run We-Blocker |
| X | SysWin | SysWin.exe | Added by the IRCCONTACT TROJAN! |
| X | syswin | v6.exe | Added by the AGENT-ECM TROJAN! |
| X | syswin.txt | [3 random letters].exe | Added by a variant of the SPYBOT WORM! See here |
| X | syswin32 | syswin32.exe | Added by a variant of the SPYBOT WORM! |
| X | Syswindow | Syswindow.exe | Added by the COW TROJAN! |
| X | SysWy | rundll32.exe | Added by the LINEAGE-JH TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP) |
| X | sysX3 | sys22.exe | Added by the RANTS.C WORM! |
| X | sysygm32 | syscxd32.exe | Added by the IRCBOT-PC TROJAN! |
| X | sysygm64 | winrxd64.exe | Added by the IRCBOT-RK TROJAN! |
| X | SyZ | f1.exe | Added by the MSNDIABLO.A WORM! |
| X | Syzmy3 | exp1orer.exe | Added by the LINEAG-AIO TROJAN! Note the number "1" in the filename |
| X | SyztMy | expiorer.exe | Added by the LINEAG-AIN TROJAN! |
| U | SZMsgSvc.exe | SZMsgSvc.exe | StopZilla! - pop-up killer |
| X | t | xclean.exe | FlashEnhancer adware |
| U | T-Com WLAN Manager | TS154USB.exe | Wireless management utility for the T-Com Sinus 154 Data II WLAN adapter |
| N | T-DSL SpeedMgr | speedmgr.exe | T-Online ISP SpeedManager - shows upload and download speed. Also checks for updates automatically |
| X | T2W | Memoria.exe | Added by the DROPPER.CYG TROJAN! |
| U | T3Console | T3Console.exe | Related to T3 Security Suite - prevents unauthorized or inappropriate access to your PC and data |
| X | T4skM4n4g3r | Wink3sk9.exe | Added by a variant of the IRCBOT TROJAN! |
| X | TA_Start | [random filename] | Zeno Think-Adz adware |
| U | Taakcontrole | taskmon.exe | Task Monitor (on Dutch language versions of Windows) - checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users, loading TaskMonitor will typically solve many, if not most, of those annoying IE scripting errors (per Symantec's Knowledgebase) |
| X | Taba | stte.exe | PurityScan adware |
| N | Tablet | Tablet.exe | Loads the tablet drivers for the Wacom Graphics Tablet. This can be unchecked in msconfig without problems if you don't need the tablet functional all the time. Create your own shortcut if you need to run it ad hoc. If you forget to run it before running Paint Shop Pro & Adobe Photo Shop) you may find the following: (1) Paint Shop Pro (version 7.04) - (a) Browse function will NOT work (program freezes) (b) On program exit, PSP does not terminate (you have to CTRL+ALT+DEL to close it) (2) Photo Shop (version 6.01) - (a) Program functions slowdown (d) On program exit it takes noticeably longer to shut down (like 30-45 seconds) |
| Y | tablet s | tablet s | Starts the Wacom Penabled driver on Acer Tablet PCs (tablet icon with a green check appears during startup if successful) |
| X | Tablet Task | tabletsk32.exe | Added by the RBOT-AJB WORM! |
| U | TabletTip | tabtip.exe | This is the Tablet PC Input Panel for Windows XP Tablet PC Edition. This utility allows you to use a pen (in conjunction with a touchscreen or tablet) to enter text into a document or input field (such as a URL in a browser) using either handwriting or the on-screen keyboard. This utility is also included with Windows 7 and Vista but only appears to run at startup if using the XP Tablet PC version. This cannot be confirmed at present |
| U | TabletWizard | SPLSHWRP.EXE | Microsoft Tablet PC Component |
| Y | TabletWorks | TWCP.exe | Tabletworks driver for digitizers from GTCO CalComp |
| Y | TabUserW | TabUserW.exe | Wacom pen tablet driver |
| ? | TAcelMgr | TAcelMgr.exe | TOSHIBA Acceleration Utilities related. What does it do and is it required? |
| N | Tad | tad.exe | From Turtle Beach's Santa Cruz on a Dell WinME system. Not required - works fine without it including keyboard hot controls for volume and mute |
| X | taengtae | AutoRun.bat | Added by the GATINA-B WORM! |
| X | Taesk managers | tase.pif | Added by the RBOT-AYK TROJAN! |
| X | taetae | Exit to DosPrompt.pif | Added by the GATINA-B WORM! |
| ? | TAG | tag.exe | ?? |
| N | Tahni Deskmate | Tahni.exe | Tahni Deskmate - "Interactive cartoon character that lives on your Windows desktop" |
| X | TakeMP3 | rundll32.exe MSA64CHK.dll,DllMostrar | MatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% |
| X | TAKSMGN | taskmr.exe | Added by the RBOT-AHS WORM! |
| X | talk | talk.bat | Added by the TIOTUA-G WORM! |
| N | TalkingReminder | TALKINGREMINDER.EXE | Talking Reminder from Software River Solutions - talking calendar reminder |
| ? | talknow | talknow.exe | Could it be related to this or something similar? |