| Status | Autorun name | Command | Description |
| X | system | sysnet.exe | Added by the VETOR-J WORM! |
| X | system | systemdb.exe | Barracuda Antivirus and Security Central rogue security software - not recommended, removal instructions here and here |
| X | System | winipck.exe | Added by the RBOT-TK WORM! |
| X | System | krln32.exe | Malware installed by different rogue security software including SpyKillerPro |
| X | system | system64.exe | Added by the BANCBAN-PP TROJAN! |
| X | System | antivirus.vbe | Added by the AUTORUN-AYI WORM! |
| X | SYSTEM | RUNDLL16.exe | Added by the DELF-EW BACKDOOR! |
| X | System | systemz.exe | Added by the VILSEL-B TROJAN! |
| X | System 64 Driver for Games | sys64dvr.exe | Added by the SDBOT TROJAN! |
| X | System Analyzer | lsass32.exe | Added by the SDBOT.CNI WORM! |
| X | System Applications Profile | sap.exe | Added by the RBOT-QF WORM! |
| X | System Auth | system52.exe | Identified as a variant of the Win32:Rizo-E malware |
| X | System Backup | msystem.exe | Adult content dialler |
| X | System backup | [random filename] | Added by the ADMINCASH.B TROJAN! Note - multiple different file names have been spotted, examples: web.exe, soft.exe, msxmidi.exe, wmplayer.exe, as well as completely random ones such as 9a2de006.exe, 36c75e3c.exe and so on |
| X | System Backup | sysbcp32.exe | Added by the AGOBOT-NP BACKDOOR! |
| X | System Backup Services | backups32.exe | Added by a variant of the RBOT WORM! |
| X | System Boot Check | sysload3.exe | Added by the FUBALCA WORM! |
| X | System Boot Loader | sysboot32.exe | Added by the SDBOT.PG WORM! |
| X | System Buffer Application | buffer32.exe | Added by the SDBOT-UD WORM! |
| X | System Cache | SysCache.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | System CGI Manager | syscgmgr.exe | Added by an unidentified WORM or TROJAN! See here |
| U | System Check | Rundll32.exe SysDll32.dll, SystemCheck | XPCSpy Pro keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | system check | updater.exe | Unidentified adware downloader |
| X | System Check | win_klr32.exe | Added by the DELF-DRA WORM! |
| X | System Checking | wasul.exe | Added by the RBOT.BHM WORM! |
| X | System Config | BF3.EXE | Added by the SPYBOT-DT WORM! |
| X | System Config | sysloadcnf.exe | Added by a variant of the SDBOT WORM! See here |
| X | System Config Boot | syscgboot.exe | Added by the AGENT.VWU TROJAN! |
| X | System Config Manager | crss.exe | Added by the AGOBOT.GH WORM! |
| X | System Config Manager | smssl.exe | Added by the AGOBOT-ZJ WORM! |
| X | System Configuration | iexplore.exe | Added by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
| X | System Configuration | syscfg32.exe | Added by the MYTOB.EA WORM! |
| X | System Configurator | systemconfig.exe | Added by the SDBOT-OR WORM! |
| X | System Configurator32 | SYSTEMCFG.EXE | Added by the AGOBOT-KS WORM! |
| X | system configure | svchost.exe | Added by the LINEAGE-C TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup! |
| X | System Core Memory | syscoremem.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | System CPL manager | [random filename] | Added by the RBOT-SR WORM! |
| X | System CSRSS Patch | scrtkfg.exe | Added by the RBOT-ADA WORM! |
| X | System Database administration | systemDA.exe | Added by the DERDERO.B WORM! |
| X | System Database Administration Support Process | sysdasp.exe | Added by the DERDERO.C WORM! |
| X | System DataBase Root | sysdbroot.exe | Added by the QHOST-W TROJAN! |
| X | System DB Manager | sysdbmg.exe | Added by an unidentified WORM or TROJAN! See here |
| X | System Defender | WS[random characters].exe | System Defender rogue security software - not recommended, removal instructions here |
| X | System Development Operations | sysdevop.exe | Added by the AGENT-OFQ TROJAN! |
| X | System Device | devices.exe | Added by the AGENT.AFIF WORM! |
| X | System Device Version | systemdv.exe | Added by a variant of the RBOT WORM! |
| X | System Diagnostics | sysdiag32.exe | Added by the SDBOT.GEN BACKDOOR! |
| X | System Directory Service | [trojan filename].exe | Added by the THROD.A TROJAN! The filename is a random combination the following: ms, svc, win, 16, 32, 64, mes, prn, reg - "ms16prn.exe", for example - and is located in %System% |
| N | System DLF | cpqdiaga.exe | Compaq Diagnostic record system utility which allow you to view information about your computer's hardware and software configuration. Available via Start -> Programs |
| U | System DLL Resources | sysdll.exe | SnapKey is a surveillance software program that records all keyboard activities. Uninstall this software unless you put it there yourself |
| X | System Doctor Free | systemdoc.exe | SystemDoctor rogue security software - not recommended, removal instructions here |
| X | System Document Application | nmod.exe | Added by the SDBOT-ABB WORM! |
| X | System Document Application | msdocument.exe | Added by the RANDEX.COX WORM! |
| X | System Document Application | wins.exe | Added by the SDBOT.AUB WORM! |
| X | System Document Application | winsvc32.exe | Added by the SDBOT-VA WORM! |
| X | System Download Manager | SysMgr.exe | Added by the RBOT.CIG WORM! |
| X | System driver | Messenger.exe | Added by the WOOTBOT.GI WORM! |
| X | System Drivers | wingmt.exe | Added by the SDBOT-MG WORM! |
| X | System Drivers | cpsq32.exe | Added by the SDBOT.AXH WORM! |
| X | System Drivers | sysdrv32.exe | Added by the AGOBOT-ZX WORM! |
| X | System Efficiency Monitor | mscedit32.exe | Added by the SDBOT.P TROJAN! |
| X | System Efficiency Monitor | mscommand.exe | Added by the KWBOT.P WORM! |
| X | System Efficiency Monitor | msedit32.exe | Added by the STEPH-B WORM! |
| X | System Efficiency Monitor | svchostx.exe | Added by the KWBOT.E WORM! |
| X | System Error Notification | senr32.exe | Added by the POISON-BT TROJAN! |
| X | System Event Manager | secsvc.exe | Added by the RBOT.BMY WORM! |
| X | System Executable DLL Library | EXECDLL32.exe | Added by the RANDEX.AZ WORM! |
| N | System Explorer | SystemExplorer.exe | System Explorer by Mister Group - a "free, awards winning software for exploration and management of System Internals." Provides detailed information about tasks, processes, startups and services; suspicious file checking via VirusTotal, Jotti and their own database and other resources |
| X | System Failure Statistic | cnstat.exe | Added by the RBOT-LF WORM! |
| X | System File Drivers | nvsysvc32.exe | Added by the AGOBOT.WJ WORM! |
| X | System File Startup | sys32.exe | Added by the RBOT.OTL WORM! |
| U | System Files Updater | System Files Updater.exe | System Files Updater from Flyakiteosx "will transform the look of an ordinary Windows XP system to resemble the look of Mac OS X" |
| X | system firewall | makeini32.exe | Added by the AGOBOT-PS WORM! |
| X | System Firewall | sysfirewall.exe | Added by the AGOBOT-ACY WORM! |
| X | System Firewalls | commandprompt32.exe | Added by the RBOT.BJT WORM! |
| X | System Guard | mhguard.exe | Added by the RBOT-AGU WORM! |
| X | System handler | svhost.exe | Added by the TODNAB-B WORM! |
| X | System Handler | LSASS.EXE | Added by the NIMOS WORM! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup! |
| X | system handler | srvhandle.exe | Added by the REDPLUT VIRUS! |
| X | System handler | Pandawas.exe | Added by the BHARAT.A WORM! |
| X | System Host | scvhost.exe | Added by a variant of the RBOT WORM! |
| X | System Host Manager | syshost.exe | Added by the BANWORM-C WORM! |
| X | System Host Service | svchost.exe | Added by the CONE.F WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\tasks |
| X | System Information Manager | Navcpe.exe | Added by the SDBOT-QB WORM! |
| X | System Information Manager | Msbb.exe | Added by the SLINBOT.YR BACKDOOR! |
| X | System Information Manager | iexplore.exe | Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
| X | System Information Manager | mslog.exe | Added by the DELF.AKO TROJAN! |
| X | System Information Manager | no.exe | Added by the SPYBOT.NO WORM! |
| X | System Information Manager | syspass.exe | Added by the SDBOT-MO WORM! |
| X | System Information Manager | win.exe | Added by the SDBOT-MU WORM! |
| X | System Information Manager | windowsNt.com | Added by the SDBOT-ND WORM! |
| X | System Init | systeminit.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | System Initialization | msmsgri32.exe | Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS! |
| X | System Initialization | payload.dat | Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS! |
| X | System IP | systemip.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | System Kernal Support | system.exe | Added by the SDBOT.BWV WORM! |
| X | System Kernel | lsass.exe | Added by the VBBOT-G TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| U | System LifeGuard Scheduler | Slsched.exe | System LifeGuard scheduler |
| X | System Loader | systems.exe | Added by the AGOGBOT-FI WORM! |
| X | System Loader | syscfg.exe | Added by the AGOBOT-BS BACKDOOR! |