| Status | Autorun name | Command | Description |
| X | sysme | sysme.exe | Added by the PSW.STEALER.C TROJAN! |
| X | sysmem | mmsete.exe | Added by the NOPIR.C WORM! |
| X | sysmem | outlookrem.exe | Added by the NOPIR-C WORM! |
| X | SysMemory manager | mdms.exe | Added by the CIMUZ-D TROJAN! |
| U | SysMetrix | SysMetrix.exe | SysMetrix - skinnable clock and metering application. It monitors and reports on a great number of statistics |
| X | sysMett1 | explorer.exe | Added by the LEGMIR-Y TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles% |
| X | sysmini | sysmini.exe | Added by the ADLOAD.DD TROJAN! |
| X | sysmngr32 | sys64mnger.exe | Added by a variant of the RBOT WORM! |
| X | sysmntrc | sysmntrc.exe | Added by the BANCOS-FX TROJAN! |
| X | sysmod | sysmod.exe | Added by the SPYBOT-DU WORM! |
| X | sysmon | sysmon.exe | Added by the BIZEX WORM! |
| X | Sysmon | rpcmon.exe | Added by the RANDEX.ATX WORM! |
| X | sysmon | sysmon44.exe | Added by a variant of the BACKDOOR-CBA TROJAN! |
| X | SysMon | wowexece.exe | Added by the MULAN-A TROJAN! |
| X | Sysmon | SystemMonitor.exe | Added by the NUJAMA-A WORM! |
| X | Sysmon | msnmssgs.exe | Added by the SDBOT.FK WORM! |
| X | sysmon12 | [various filenames] | Wareout - malware masquerading as a spyware and dialer remover |
| X | SysmonLog | mslog.exe | Added by the AGENT.AOV TROJAN! |
| X | sysmonnt | sysmonnt.exe | SearchPounder sends keywords typed into HTML forms and popular Internet search engines to a remote server |
| X | SysMonXP | SysMonXP.exe | Added by the NETSKY.Q WORM! |
| X | Sysmppcvppp | SysTdSvr.dll | Generic2.PQG adware |
| X | sysmss | sysems.exe | Added by a variant of the SLAPER TROJAN! |
| X | sysnate | sysnate.exe | Added by the MEDIAS TROJAN! |
| X | Sysnet | snuninst.exe | Unidentified adware |
| X | sysnet | sysnet.exe | CasClient adware - also detected as the CMAPP TROJAN! |
| X | sysobj.exe | sysobj.exe | Wareout - malware masquerading as a spyware and dialer remover |
| X | SysOps | SysOps | Added by the MSNCORRUPT TROJAN! |
| X | syspare | syspare.exe | Added by the BIFROSE-AN TROJAN! |
| X | syspath | drv.exe | Added by the SOBER WORM! |
| X | sysPersonalFirewall | msnmssgr.exe | Added by a variant of the RBOT WORM! |
| X | sysPersonalFirewall | system.exe | Added by the WOOTBOT.FH WORM! |
| X | sysPersonalFirewall | tskm0nitor.exe | Added by the SDBOT.APC WORM! |
| U | SysPilot | fdxxl.exe | G Data "PC Spion". PC monitoring and surveilling software, captures all users activity on the PC, see here. Disable/remove if you didn't install it yourself! |
| X | sysPnP | bootconf.exe | Homepage hijacker, redirecting to coolwwwsearch.com; see for example here |
| X | SysPnP | rundll32 setupapi, InstallHinfSection [varies] oemsyspnp.inf | CoolWebSearch PnP parasite variant |
| Y | SysPool | Mssvc.exe | StealthDisk - hides folders, files and applications. Will also encrypt them for better protection |
| X | SysPool | MSSVC32.EXE | Added by the BANCBAN-IO TROJAN! |
| X | SySPower | [path to trojan] | Added by the BANCBAN-OC TROJAN! |
| U | sysproc | sysproc.exe | Keyboard Logger keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | SysProtect | System.exe | Added by the NETSPY TROJAN! |
| X | SysProtect | syp.exe | SysProtect rogue security software, associated with WinFixer - not recommended, see here |
| X | SysProtect | USYP.exe | SysProtect rogue security software, associated with WinFixer - not recommended |
| X | SysProtect Free | USYP.exe | SysProtect rogue security software, associated with WinFixer - not recommended |
| X | SysProtector | SysProtector.exe | SysProtector rogue security software - not recommended, removal instructions here. A member of the AntiAID family |
| X | syspw32.exe | syspw32.exe | Added by the APPFLET.A WORM! |
| X | Sysqq | LSESS.exe | Added by the FORBOT-BF WORM! |
| X | Sysqq | weiba.exe | Added by the DELF-CFX TROJAN! |
| X | SysR | sysmd.exe | Ulubione adult content dialer |
| X | SysReg | SysReg.exe | Added by the CHEKIN TROJAN! |
| X | SysReg | SysReg.exe | SearchSeekFind textual marketing foistware |
| X | Sysres | Sysres.exe | Added by the LOGMOD.A TROJAN! |
| X | SysRes | TASKMANAGER.exe | Added by the ELIPTER.A or ELIPTER.B WORMS! |
| X | SysRes | WWE DIVAS.exe | Added by the ELIPTER.D WORM! |
| X | SysRes | IExpIore .exe | Added by the ELITPER.E WORM! |
| X | sysrest32.exe | sysrest32.exe | Added by the AGENT-GIN TROJAN! |
| X | sysrestore32.exe | sysrestore32.exe | Unknown malware detected by McAfee - see here |
| X | Syss | ehuupdate.exe | EHU adware |
| X | SysScan | bvt.exe | Added by the AUTOUPDER TROJAN! |
| X | SysSearch | Regedit.exe -s pcsearch.reg | Added by the STARTPAGE-FN TROJAN! Note that regedit.exe is a legitimate Microsoft file and shouldn't be deleted. The "pcsearch.reg" file is located in %Windir% |
| X | SysSearch | Regedit.exe -s sysreg.reg | Added by the STARTPA-ME TROJAN! Note that regedit.exe is a legitimate Microsoft file and shouldn't be deleted. The "sysreg.reg" file is located in %Windir% |
| U | SysSense | SysSense.exe | "SysSense is your personal desktop Google AdSense monitor. It keeps your current Google AdSense information in the Windows system tray". Google AdSense account required |
| X | sysser | [path to file] | Added by the RAHACK WORM! |
| X | SysService | SysService.exe | Added by the BDFORM-A BACKDOOR! |
| U | SysService | SERVICES.EXE | NSKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\NSkeylogger |
| X | SysService32 | SysService32.exe | Added by the KINDAL VIRUS! |
| X | SysService32 | ln32k.dll | Added by the KINDAL VIRUS! |
| X | SysService32l | systask32l.exe | Added by the THEUG WORM! |
| X | SysServices | SERVICES.EXE | Added by the DELF-EY TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | SYSsfitb | SYSsfitb.exe | AdShooter adware |
| X | SySSL | sysl.exe | Added by the RBOT-CKH WORM! |
| X | SySSL | syssl.exe | Added by the RBOT-DAA WORM! |
| X | SysStart | [random filename] | ZenoSearch adware |
| X | SysStart | syswin.exe 1 | Added by the AUTORUN-EY WORM! |
| X | SysStrt | systemc.exe | Added by the AGOBOT-QA TROJAN! |
| X | syssvc.exe | syssvc.exe | Added by the AGENT-QQM TROJAN! |
| X | syst | syst.exe | Added by the BANLOAD.BEJ TROJAN! |
| X | syst32 | syst32.exe | Added by the AUTORUN-AFL WORM! |
| X | Systam13 | f1r5st83.exe | Added by the IRCBOT-YM WORM! |
| X | Systam13 | exp.exe | Added by the RBOT.ESD BACKDOOR! |
| X | Systam13 | first.exe | Added by the RBOT.GND BACKDOOR! |
| X | Systam13 | resx.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Systam13 | speedwin.exe | Added by the RBOT.GVH BACKDOOR! |
| X | system | wscript.exe [path to worm script] | Added by the AUTORUN-FG WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted |
| X | system | wind.exe | Added by the AUTORUN.BND WORM! |
| X | System | nav32.exe | Added by the RBOT-BHV WORM! |
| X | SYSTEM | wuamgre.exe | Added by the RBOT-WA WORM! |
| X | System | wmplayer.exe | Added by the LASY-A WORM! Note - this is not the valid Windows Media Player as the file is located in %Windir% rather than %ProgramFiles%\Windows Media Player |
| X | System | run322.exe | Added by the LANFILT TROJAN! |
| X | System | system.exe | Added by various WORMS and TROJANS! |
| X | system | regedit -s system.dll | Homepage hijacker |
| X | system | systemsearch.hta | Jetseeker.com hijacker |
| X | System | dcomx.exe | Added by the CIREBOT TROJAN! |
| X | system | Explorer.exe | Added by the GRAYBIRD BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System% |
| X | System | YPager.exe | Added by the JUNTADOR.K TROJAN! Note - this is not the older version of Yahoo! Messenger which shares the same filename and is located on %ProgramFiles%\Yahoo!\Messenger |
| X | system | outlook.exe | Added by the MIMAIL.Q WORM! Note that the valid Microsoft Outlook executeable is located in %ProgramFiles%\Microsoft Office\Office whereas this one is located in %Windir% |
| X | System | Atira.exe | Added by the KOTIRA VIRUS! |
| X | SYSTEM | lsas.exe | Added by the SPYBOT.CJ WORM! |
| X | System | kernels32.exe | Added by the DLOADER-FC TROJAN! |
| U | System | sysctrl.exe | Added by WinGuardian. Note - this commercial keylogger is no longer made or sold by Webroot but older copies may still be in existance, those copies will be identified as spyware |
| X | System | csrss.exe | Added by the LDPINCH.E TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |