| X | systemdrv | ms32sys.exe | Added by an unidentified WORM or TROJAN - most likely GAOBOT variant |
| X | SystemEmergency | [various filenames] | SmartSearch - a CoolWebSearch parasite variant |
| X | SystemExplorer | explore.exe | Homepage hijacker - file located in the "Services" folder in Common Files |
| X | SystemFTP | VSENMB.exe | Malware (ie, malicious software). Also changes the system.ini Shell line to read Shell=Explorer.exe VSENMB.exe, and it hacks the Winstart.bat as well |
| X | SystemInit | iservc.exe | Added by the FIZZER WORM! |
| X | Systemiom Updater | Systemiom.exe | Added by the SPYBOT.TY WORM! |
| X | SystemLoad32 | sysload32.exe | Added by the MIMAIL.E WORM! |
| X | SystemManager | Sysman32.exe | Added by the DOWNLOADER-BW.B TROJAN! |
| X | SystemMap32 | Netisp32.vbs | Added by the REDIST.C WORM! |
| X | SystemMD | md.exe | Homepage hijacker |
| X | SystemMonitor | Sysmon32.exe | Added by the AIDID.A WORM! |
| X | SystemNetwork | NETSERV.EXE | Added by the NETCONTROL VIRUS! |
| ? | SystemReg | PROCES.EXE | ?? |
| X | SystemReg | svchost.exe | Added by the DEWIN.E TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | SystemReg | WINREG.EXE | Added by the DEWIN.A TROJAN! |
| X | Systems | scchost.exe | Added by the DAEMOZ.A TROJAN! |
| X | Systems Restart | slchost.exe | Added by the BANCOS.RF TROJAN! |
| X | Systems Restart | spchost.exe | Added by a variant of the BANCOS.RF TROJAN! |
| X | Systems Restart | Rundll32.exe beem.dll, DllRegisterServer | Browser hijacker - the file serves to register a dll implemented as a browser plugin |
| X | Systems Restart | Rundll32.exe snim.dll, DllRegisterServer | Added by the Startpage.I hijacker |
| U | Systems.exe | Systems.exe | Keyboard Spectator - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
| U | SystemSafe | Syssafe.exe | System Safety Monitor - system monitoring tool with additional application firewalling |
| X | SYSTEMSars32 | csrss.exe | Added by the AHLEM.A WORM! Note - this is not the legitimate csrss.exe process which should NOT appear in Msconfig/Startup! |
| X | SystemSAS | System32.exe | Added by the KWBOT.C WORM! |
| X | SystemSearch | regedit.exe -s c:ie.reg | Installs a Seachxl.com browser page hijack |
| X | SystemSearch | regedit.exe -s c:sys.reg | Installs a i--search.com browser page hijack |
| X | SystemService | msocfg.exe | Premium rate adult content dialler |
| X | SystemService | navchk.exe | Premium rate adult content dialler |
| X | SystemService | qservice.exe | Premium rate adult content dialler |
| X | SystemService | shman.exe | Premium rate adult content dialler |
| X | SystemSettingf | TRUG.vbs | Added by the TRUG.B MACRO! |
| U | SystemSuite Task Manager | MXTASK.EXE | vcom (nee Ontrack) SystemSuite - PC maintenance and security. Use the program's configuration options to enable only the parts you want running all the time - such as Virusscanner Pro |
| X | SystemTasks | filez.exe | Adult content dialler |
| X | SystemTasks | sexypicz.exe | Adult content dialler |
| X | SystemTasks | loaded.exe | Adult content dialler |
| X | Systemtra | Systra.exe | Added by a variant of the LOVGATE WORM! |
| X | SystemTra | CDPlay.EXE | Added by a variant of the LOVGATE WORM! |
| U | SystemTray | SysTray.Exe | SYSTRAY.EXE - System Tray Services. Provides the Volume Control, PC Card Status, Power Management and other icons that reside in the System Tray (see here). SYSTRAY.EXE may be disabled if none of these services are required. It will launch as and when required if you later enable the icons. If you need these items they're available via Start -> Settings -> Control Panel |
| X | SystemTray | SystemTray.exe | Added by the BIGFOOT TROJAN! Note - this is not the valid SystemTray (SysTray.exe) |
| X | SystemTray | SysTray.exe | Added by the ALADINZ.P TROJAN! Note - this is not the valid System Tray (systray.exe) which resides in C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP). If you right-click on the real systray.exe the "Properties" reveal it to be a Microsoft file |
| N | SystemUpd | SystemUpd.exe | Updater for Swapoo.com, a kind of Napster for games |
| X | SystemWideHook for Windows NT | %WinHook32.exe | Added by the MYDOOM.AC WORM! |
| U | SystemWizard Sniffer | Sniffer.exe | SystemWizard for Win98/ME from SystemSoft - diagnoses and solves hardware and software problems on a PC |
| X | systemyom Updater | systemyom.exe | Added by a variant of the BACKDOOR.IRC.BOT TROJAN! |
| X | SYSTEMZ Patch | SYSZ.exe | Added by the ALADINZ.P TROJAN! |
| U | System_Messages | pprsen.exe | TerminatorX - "offers an easy and effective method of stopping users running predetermined file sharing programs like KaZaA, messenger programs, chat rooms and the like" |
| X | Systesms.exe | systesms.exe | Added by the RBOT-HI WORM! |
| N | Systest | Systest.exe | Clean Space temp files cleaner |
| X | systhread | winkernal.exe | Added by the LIAMED WORM! |
| X | SysTime | systime.exe | CoolWebSearch parasite variant |
| X | Systmesy | Systmesy.exe | Added by the RBOT-KQ WORM! |
| X | Systoan32 | systoan.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| ? | systr32 | systr32.exe | ?? |
| ? | systrax | systrax.exe | ?? |
| X | Systray | Systray_.Exe | Added by the KERGEZ.A WORM! |
| X | Systray | [filename.exe] | Winfavorites adware |
| X | SYSTRAY | UNMT.EXE | Added by the SDBOT WORM! |
| U | SysTray | SysTray.Exe | SYSTRAY.EXE - System Tray Services. Provides the Volume Control, PC Card Status, Power Management and other icons that reside in the System Tray (see here). SYSTRAY.EXE may be disabled if none of these services are required. It will launch as and when required if you later enable the icons. If you need these items they're available via Start -> Settings -> Control Panel |
| X | SysTray | Snnpapi.exe | Added by an unidentified TROJAN! |
| X | Systray driver | systray.exe | Added by the MUTEBOT TROJAN! Note - this is not the real SystemTray which shares the same filename |
| X | SystrayServices | Msxpw.exe | Added by the CITOR WORM! |
| X | systree | systree | Added by the BANCOS.L TROJAN! |
| X | Systry | [path to worm] | Added by the AUTEX WORM! |
| X | SYStry | spoolsvr.exe | Added by the SDBOT.GN WORM! |
| X | Systryt | [path to worm] | Added by the AUTEX WORM! |
| X | sysu | sysu.exe | Dynamic Desktop Media adware - see here |
| X | SysUpd | Sysupd.exe | VirtuMonde adware |
| X | Sysvupex | Sysvupex.exe | Added by the MEDIAS TROJAN! |
| U | SysW8 | csta.exe | Clean Space - privacy and perfomance enhancer |
| U | SYSWB6 | SYSWB6.exe | We-Blocker - gives parents the opportunity to monitor their children's Internet access and provide them with age-appropriate content, while filtering out sites that contain adult content |
| X | SysWin | SysWin.exe | Added by the IRCCONTACT TROJAN! |
| X | syswin32 | syswin32.exe | Added by a variant of the SPYBOT WORM! |
| X | Syswindow | Syswindow.exe | Added by the COW TROJAN! |
| X | SYS_CLEAN | Service.exe | Added by the FLOPCOPY WORM! |
| U | SZMsgSvc.exe | SZMsgSvc.exe | StopZilla! - pop-up killer |