| Status | Autorun name | Command | Description |
| X | wincmap | wincmapp.exe | CasClient adware variant - also detected as the CMAPP TROJAN! |
| U | WinColorReminder | WinColorReminder.exe | The Microsoft Color Control Panel Applet for Windows XP "helps you manage Windows color settings in one place." Part of the Pro Imaging Powertoys |
| X | wincom | vbrun6win.exe | Added by the AGOBOT-AFK WORM! |
| X | winconfig | wscript winconfig.js | Added by the CHAFPIN TROJAN! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "winconfig.js" file is found in %Temp% |
| X | winconfig | wscript.exe winconfig.js | Added by the CHAFPIN TROJAN! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "winconfig.js" file is located in %Temp% |
| X | WinConfig9324 | wincfgkop9.exe | Added by the RBOT.BVD WORM! |
| X | winconn | vbrun6nt.exe | Added by the AGOBOT-AEI BACKDOOR! |
| X | WinCore32.exe | WinCore32.exe | Added by the CLICKER-EN TROJAN! |
| X | wincrt.exe | [path to worm] | Added by the STRATIO-HA WORM! |
| X | WinCRT32 | wincrt32.exe | Added by the DOGBOT-D WORM! |
| X | WinCSRSS | MSGRT32.EXE | Added by the REWINDO-A TROJAN! |
| X | winctl | winctl.exe | Added by the IRCBOT-YI TROJAN! |
| X | WINCX | wincore332.exe | Added by the AGOBOT-MG WORM! |
| X | Wind | Wind.exe | Added by an unidentified VIRUS, WORM or TROJAN! See here - the file is located in %Windir%\Debug |
| X | Wind Logd File | servicelogd.exe | Added by a variant of the RBOT WORM! |
| X | Wind Optimizer | WindOptimizer.exe | Wind Optimizer rogue system optimization tool - not recommended, removal instructions here |
| X | Wind River Systems | vxworks.exe | Added by the ACKANTTA WORM! Note that this is not related to the VxWorks platform from Wind River |
| X | Wind Security | mswi32.pif | Added by the RBOT-ARH WORM! |
| X | wind.exe | wind.exe | Added by the MITGLIEDER.BD TROJAN! |
| X | WIND0WS | WIND0WS.exe | Added by the SPYBOT.DQ WORM! |
| X | WIND0WS | mella.bat | Added by the ALLEM WORM! |
| X | Wind0ws | wordpad.exe | Added by the AGOBOT-TL WORM! Note - this is not the legitimate Windows application wordpad.exe (which is found in the %ProgramFiles%\Accessories folder) which should not normally be seen in Msconfig or as a Startup item. This one is Located in %System% |
| X | Wind0ws Ser7ice Agent | colwindos.exe | Added by the RBOT-GQO WORM! |
| X | Wind0ws Sharing | ssprotecter.exe | Added by the RBOT-AHW WORM! |
| X | Wind32 | Wind32.exe | Identified as a variant of the Backdoor.Win32.Poison.avs malware |
| X | windate | windate.exe | Added by the AGOBOT-ZC WORM! |
| N | WinDates | windates.exe | WinDates is a calendar, date organizer and event reminder program from Rockin' Software |
| X | windbs | winxtc.exe | Added by the AGOBOT-WD WORM! |
| X | Winde | winde.exe | Added by the DLUCA TROJAN! |
| X | windef | Win32sp.vbs | Added by the ANPES WORM! |
| X | windef | windef.exe | Added by the WURMARK-O WORM! |
| X | WinDefender | wicfte.exe | Added by the SCAR-AG TROJAN! |
| X | WinDefender 2008 | WDefDemo.exe | WinDefender 2008 rogue privacy program - not recommended, removal instructions here |
| X | windefender.exe | windefender.exe | Added by the AGENT.BYH TROJAN! |
| X | WinDefender2009 | windef.exe | WinDefender 2009 rogue security software - not recommended, removal instructions here |
| X | Windeows NetStart Service2 | tesakrmger.exe | Added by the RBOT-AMY WORM! |
| X | WinDevils | WinDevils.exe | Added by the BRONTOK-BS WORM! |
| X | windhost.exe | osrwin32.exe | Added by the BANKER-CB TROJAN! |
| X | windhost.exe | windhost.exe | Added by the BANKER-BV TROJAN! |
| X | windhost.exe | winos.exe | Added by the PWSAGENT-A WORM! |
| X | windir | winrun.exe | Added by the WINBUR.B WORM! |
| X | Windir Working | wuaumqr1.exe | Added by a variant of the IRCBOT TROJAN! |
| X | WinDirectories | tdirs.exe | Added by the VB-EPB VIRUS! |
| X | WinDirectories | ddcs.exe | Added by the VB-ETN WORM! |
| X | Windll | Windll.exe | Added by the TRYNOMA TROJAN! |
| U | WINDLL | WSYS.EXE | STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes, all passwords transacted even if they weren't keyed in, all web sites visited, every program launched including the path to that program, and more" |
| X | windll | windll32.exe | Added by the ASTEF or RESPAN WORMS! |
| X | windll | windotnetsrv.exe | Added by the AUTORUN-ANO WORM! |
| X | WinDLL (algs.exe) | rundll32.exe algs.exe,start | Added by the AKBOT.E BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "algs.exe" file is found in %System% |
| X | WinDLL (aqls32.exe) | aqls32.exe | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "aqls32.exe" file is found in %System% |
| X | WinDLL (asdfsa.exe) | rundll32.exe asdfsa.exe,start | Added by the SDBOT.GAV WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "asdfsa.exe" file is found in %System% |
| X | WinDLL (bee.dll) | rundll32.exe bee.dll,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "bee.dll" file is found in %System% |
| X | WinDLL (bix.exe) | rundll32.exe bix.exe,start | Added by the KOLAB.OL WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "Bix.exe" file is found in %System% |
| X | WinDLL (csmss.exe) | rundll32.exe CSMSS.EXE,start | Added by the AKBOT.U WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "CSMSS.EXE" file is found in %System% |
| X | WinDLL (ctfmonm.exe) | rundll32.exe ctfmonm.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ctfmonm.exe" file is found in %System% |
| X | WinDLL (dasda.com) | rundll32.exe dasda.com,start | Added by the SDBOT.GAV WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "dasda.com" file is found in %System% |
| X | WinDLL (diem.exe) | rundll32.exe diem.exe,start | Added by the AKBOT.E WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "diem.exe" file is found in %System% |
| X | WinDLL (dlfksdld.exe) | rundll32.exe dlfksdld.exe,start | Added by the IRCBOT.BPM BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "dlfksdld.exe" file is found in %System% |
| X | WinDLL (jbi32.dll) | rundll32.exe jbi32.dll,start | Added by the AKBOT.E WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "jbi32.dll" file is found in %System% |
| X | WinDLL (lcass.exe) | rundll32.exe lcass.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "lcass.exe" file is found in %System% |
| X | WinDLL (mysnlive.exe) | rundll32.exe mysnlive.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "mysnlive.exe" file is found in %System% |
| X | WinDLL (ProsFix.exe) | ProsFix.exe | Added by a variant of the IRCBOT BACKDOOR! The "ProsFix.exe" file is found in %System% |
| X | WinDLL (qwex.dll) | rundll32.exe qwex.dll,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "qwex.dll" file is found in %System% |
| X | WinDLL (redyLive.exe) | rundll32.exe redyLive.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "redyLive.exe" file is found in %System% |
| X | WinDLL (scvhost32.dll) | rundll32.exe scvhost32.dll,start | Added by the AKBOT.M WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "scvhost32.dll" file is found in %System% |
| X | WinDLL (service.exe) | service.exe | Added by the AGENT.BX WORM! The "service.exe" file is found in %System% |
| X | WinDLL (slmss.exe) | rundll32.exe slmss.exe,start | Added by the AKBOT.AW WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "slmss.exe" file is found in %System% |
| X | WinDLL (slsass.exe) | rundll32.exe slsass.exe,start | Added by the AKBOT.E BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "slsass.exe" file is found in %System% |
| X | WinDLL (smaprnter.exe) | rundll32.exe smaprnter.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "smaprnter.exe" file is found in %System% |
| X | WinDLL (smms.exe) | rundll32.exe smms.exe,start | Added by the AKBOT.E BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "smms.exe" file is found in %System% |
| X | WinDll (sslms.exe) | rundll32.exe sslms.exe,start | Added by the AKBOT-AS WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "sslms.exe" file is found in %System% |
| X | WinDLL (start0s.exe) | rundll32.exe start0s.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "start0s.exe" file is found in %System% |
| X | WinDLL (steam.dll) | rundll32.exe steam.dll,start | Added by the AKBOT.M WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "steam.dll" file is found in %System% |
| X | WinDLL (svc.exe) | rundll32.exe svc.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "svc.exe" file is found in %System% |
| X | WinDLL (svchost.dll) | rundll32.exe svchost.dll,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "svchost.dll" file is found in %System% |
| X | WinDLL (sysx32.dll) | rundll32.exe sysx32.dll,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "sysx32.dll" file is found in %System% |
| X | WinDLL (tepmlayer.exe) | rundll32.exe tepmlayer.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tepmlayer.exe" file is found in %System% |
| X | WinDLL (tmp.exe) | rundll32.exe tmp.exe,start | Added by the KOLAB.L WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tmp.exe" file is found in %System% |
| X | WinDLL (tock24.dll) | rundll32.exe tock24.dll,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tock24.dll" file is found in %System% |
| X | WinDLL (tqurity.exe) | rundll32.exe tqurity.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tqurity.exe" file is found in %System% |
| X | WinDLL (v4mon.dll) | rundll32.exe v4mon.dll,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "v4mon.dll" file is found in %System% |
| X | WinDLL (vdm32.dll) | rundll32.exe vdm32.dll,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "vdm32.dll" file is found in %System% |
| X | WinDLL (vxd32.dll) | rundll32.exe vxd32.dll,start | Added by the AKBOT.R WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "vxd32.dll" file is found in %System% |
| X | WinDLL (wchshield.exe) | rundll32.exe wchshield.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wchshield.exe" file is found in %System% |
| X | WinDLL (wimimi.exe) | rundll32.exe wimimi.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wimimi.exe" file is found in %System% |
| X | WinDLL (windns32.dll) | rundll32.exe windns32.dll,start | Added by the AKBOT.E BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "windns32.dll" file is found in %System% |
| X | WinDLL (wingatey32.exe) | rundll32.exe wingatey32.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wingatey32.exe" file is found in %System% |
| X | WinDLL (wintmp.exe) | rundll32.exe wintmp.exe,start | Added by the AKBOT.E BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wintmp.exe" file is found in %System% |
| X | WinDLL (Wseclayer.exe) | rundll32.exe Wseclayer.exe,start | Added by the AKBOT.E BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "Wseclayer.exe" file is found in %System% |
| X | WinDLL (wsync32.dll) | rundll32.exe wsync32.dll,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wsync32.dll" file is found in %System% |
| X | WinDLL (xvd32.dll) | rundll32.exe xvd32.dll,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "xvd32.dll" file is found in %System% |
| X | Windll.exe | Windll.exe | Added by the STEALER TROJAN! |
| X | Windll32 | Windll32.exe | Added by the MSNPWS TROJAN! |
| X | WinDll32 | _WIN32.EXE | Added by the LEGMIR.AQ TROJAN! |
| X | windllsys32.exe | windllsys32.exe | Added by a variant of the MITGLIE-A TROJAN! |
| X | WinDNS | windns32.exe | Added by the GAOBOT.WX WORM! |
| X | Windo Servic Agen | alirexe.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Windo Servic Agent 32 | xagw.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Windoes Kernel | kernel32.exe | Added by the KICKIN.A (or CYDOG.C) WORM! |
| X | WindoFix | WindoFix.exe | WindoFix rogue system error utility |