| Status | Autorun name | Command | Description |
| X | systemguard | systemguard.exe | System Guard 2009 rogue security software - not recommended, removal instructions here |
| ? | SystemGuardAlerter | SystemGuardAlerter.exe | Part of the Iolo System Mechanic maintenance software. What does it do? |
| X | SystemGuardCenter | SystemGuardCenter.exe | System Guard Center rogue security suite - not recommended, removal instructions here |
| X | SystemHelp | RUNDLL32.EXE SystemHper.dll,Install | Added by the WOW.COK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "SystemHper.dll" file is found in %System% |
| X | SystemIL | SYSTEMIL.EXE | Added by the ABOC VIRUS! |
| X | SystemInit | iservc.exe | Added by the FIZZER WORM! |
| X | systeminit | systeminit.exe | Added by the SILLYFDC-AN WORM! |
| X | Systemiom Updater | Systemiom.exe | Added by the SPYBOT.TY WORM! |
| X | SystemIron | SystemIron.exe | SystemIron rogue security software - not recommended, removal instructions here. A member of the WiniGuard family |
| X | systemkernal.exe | systemkernal.exe | Added by the AGENT-KPQ TROJAN! |
| U | SystemKey | rundll32.exe [path] SystemKey.dll rdl | Stealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | systemks | systemks.exe | Added by the DKS.11.B TROJAN! |
| X | SystemLoad32 | sysload32.exe | Added by the MIMAIL.E WORM! |
| X | SystemLoader | sysldr32.exe | Added by the DOWNLDR-NS TROJAN! |
| X | SystemManager | Sysman32.exe | Added by the DOWNLOADER-BW.B TROJAN! |
| X | SystemManager | [random filename] | Added by the SETTEC ROOTKIT! |
| X | SystemMap32 | Netisp32.vbs | Added by the REDIST.C WORM! |
| X | SystemMD | md.exe | Homepage hijacker |
| X | SystemMessenger | rundll32.exe [path] SystemMessenger.dll | Stealth Chat Monitor spyware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | SystemMgr | Ir32_a.exe | Added by the MAGANIA-OU TROJAN! |
| X | SystemMigration | WinMedia.exe | Added by the KELVIR.EI WORM! |
| X | SystemMonitor | Sysmon32.exe | Added by the AIDID.A WORM! |
| X | SystemNetwork | NETSERV.EXE | Added by the NETCONTROL VIRUS! |
| X | SystemNetwork | sysnet.exe | Added by a variant of the RBOT WORM! |
| X | SystemNT | SystemNT.exe | Added by the PWSVB-EG TROJAN! |
| X | systemntfy | systemntfy.exe | Added by the MINUDAZASH WORM! |
| X | SystemOPsv | scrtvc32.exe | Added by a variant of the SPYBOT WORM! |
| X | SystemOptimizer2008 | main.exe | SystemOptimizer2008 rogue optimization utility - not recommended, removal instructions here |
| X | SystemOrdnare | SysRep.exe | SystemOrdnare, Swedish rogue system error and cleaning utility - not recommended. A member of the ErrClean family |
| X | SystemProcEvent | [trojan filename] | Added by the IRCBOT.I TROJAN! Filenames used are csrwnd.exe, csrwjd.exe & csrnvrt.exe |
| X | systemr | d11host.exe | Added by the VB-GX TROJAN! |
| X | systemr | gedit.exe | Added by the ADCLICK-AQ TROJAN! |
| X | systemr | [path to trojan] | Added by the VB-HD TROJAN! |
| ? | SystemReg | PROCES.EXE | ?? |
| X | SystemReg | svchost.exe | Added by the DEWIN.E BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | SystemReg | WINREG.EXE | Added by the DEWIN.A BACKDOOR! |
| X | SystemRegistryRepair | temp.exe | Added by the NOKPUDA WORM! |
| X | Systems | sescmgr.exe | Added by the DWNLDR-GAH TROJAN! |
| X | Systems | spoolsvc.exe | Added by the DLOADR-SW TROJAN! |
| X | Systems | sysmon.exe | Added by the VIXUP-BI WORM! |
| X | Systems | scchost.exe | Added by the DAEMOZ.A TROJAN! |
| X | Systems | svch0st.exe | Added by the MYDOOM.BI WORM! |
| X | Systems | Systems.exe | Added by the BANKBOA-A TROJAN! |
| X | Systems | itDDD.exe | Added by the DLOADER-PP TROJAN! |
| X | Systems Backups | windrives.exe | Added by the AGOBOT-RB WORM! |
| X | Systems Restart | slchost.exe | Added by the MULTIDROP.C TROJAN! |
| X | Systems Restart | spchost.exe | Added by an unidentified WORM or TROJAN! |
| X | Systems Restart | Rundll32.exe beem.dll, DllRegisterServer | Browser hijacker - the file serves to register a dll implemented as a browser plugin. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | Systems Restart | Rundll32.exe snim.dll, DllRegisterServer | Added by the STARTPAGE.I TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | Systems Restart | Rundll32.exe zolk.dll, DllRegisterServer | Added by a variant of the STARTPAGE TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | Systems Restart | Rundll32.exe boln.dll, DllRegisterServer | Added by the STARTPAGE.J TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | Systems Service | drivex.exe | Added by a variant of the RBOT WORM! |
| X | systems usb driver | Windows2.exe | Added by a variant of the RBOT WORM! |
| U | Systems.exe | Systems.exe | Keyboard Spectator - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
| U | systems.exe | systems.exe | KGBSpy is a commercial surveillance software program. It logs keystrokes, Web sites visited, and clipboard activity. It also has a screen capture logger and can be run automatically in a silent, undetectable mode |
| U | SystemSafe | Syssafe.exe | System Safety Monitor - system monitoring tool with additional application firewalling |
| X | SYSTEMSars32 | csrss.exe | Added by the AHLEM.A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | SystemSAS | System32.exe | Added by the KWBOT.C WORM! |
| X | systemscroot | systembin.exe | Added by a variant of the RBOT WORM! |
| X | SystemSearch | regedit.exe -s ie.reg | Installs a Seachxl.com browser page hijack. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file "ie.reg" is located in the root folder (ie, C:\) |
| X | SystemSearch | regedit.exe -s sys.reg | Installs a i--search.com browser page hijack. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file "sys.reg" is located in %Windir% |
| X | SystemSecurity | zprot32.exe | Added by the AGENT-FK TROJAN! |
| X | SystemService | msocfg.exe | Premium rate adult content dialler |
| X | SystemService | navchk.exe | Premium rate adult content dialler |
| X | SystemService | qservice.exe | Premium rate adult content dialler |
| X | SystemService | shman.exe | Premium rate adult content dialler |
| U | SystemService | nsserver.exe | NiceSpy keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | SystemSettingf | TRUG.vbs | Added by the TRUG.B MACRO! |
| X | systemStart | Ntfs.exe | Added by the AUTORUN-JM WORM! |
| X | SystemStart | ma2012.exe | Mega Antivirus 2012 rogue security software - not recommended, removal instructions here |
| U | SystemSuite Task Manager | MXTASK.EXE | vcom (nee Ontrack) SystemSuite - PC maintenance and security. Use the program's configuration options to enable only the parts you want running all the time - such as Virusscanner Pro |
| X | SystemSv12 | newmaxxsv234.exe | Added by the TIBS-TS TROJAN! |
| X | SystemSv121 | n2ewma1xxsv234.exe | Added by the TIBS.TJ TROJAN! |
| X | SystemTasks | filez.exe | Adult content dialler |
| X | SystemTasks | sexypicz.exe | Adult content dialler |
| X | SystemTasks | loaded.exe | Adult content dialler |
| X | SystemTools | kernels32.exe | Added by the DLOADER-FC TROJAN! |
| X | SystemTools | kernels1118.exe | Added by the SMALL.DGK TROJAN! |
| X | SystemTools | kernels8.exe | Added by the FNG TROJAN! |
| X | SystemTools | kernels88.exe | Added by the TIBS-PP TROJAN! |
| X | SystemTools | testtestt.exe | Added by the DWNLDR-ZLC TROJAN! |
| X | Systemtra | Systra.exe | Added by the LOVGATE-W WORM! |
| X | SystemTra | CDPlay.EXE | Added by the LOVGATE.Z WORM! |
| X | SystemTra | Video.EXE | Added by the LOVGATE.E WORM! |
| U | SystemTray | SysTray.Exe | For Win9x/Me - System Tray Services. Provides the Volume Control, PC Card Status, Power Management and other icons that reside in the System Tray (see here). SYSTRAY.EXE may be disabled if none of these services are required. It will launch as and when required if you later enable the icons. If you need these items they're available via Start → Settings → Control Panel |
| X | SystemTray | SystemTray.exe | Added by the BIGFOOT TROJAN! Note - this is not the legitimate systray.exe process |
| X | SystemTray | SysTray.exe | Added by the ALADINZ.P TROJAN! Note - this is not the legitimate systray.exe process. If you right-click on the real systray.exe the "Properties" reveal it to be a Microsoft file |
| X | SystemTray | lsvhostwinlk.exe | Added by a variant of the SPYBOT WORM! |
| X | SystemTray | mssgl2.exe | Added by a variant of the IRCBOT TROJAN! |
| X | SystemTray | wekls4.exe | Added by a variant of the IRCBOT TROJAN! |
| X | SystemTray | Windowsupd.exe | Added by a variant of the IRCBOT TROJAN! |
| X | SystemTray Monitor | SysTraymon.exe | Added by a variant of the SPYBOT WORM! See here |
| U | SystemTraySD | SDSystemTray.exe | Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here |
| U | SystemTraySR | SRSystemTray.exe | Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here |
| X | SystemTuner | SystemTuner.exe | System Tuner rogue system suite - not recommended, removal instructions here |
| N | SystemUpd | SystemUpd.exe | Updater for Swapoo.com, a kind of Napster for games |
| X | SystemUpdate | Negdo.exe | Added by the CULLER-C WORM! |
| X | SystemUpdate | Xeyu.exe | Added by the CULLER-D WORM! |
| X | SystemVeteran.exe | SystemVeteran.exe | SystemVeteran rogue security software - not recommended, removal instructions here. A member of the WiniGuard family |
| X | systemw32 | systemw32.exe | Added by a variant of the RBOT WORM! |