| Status | Autorun name | Command | Description |
| X | Windows Firewal | Lsess.exe | Added by a variant of the RBOT WORM! |
| X | Windows Firewall | WindowsFirewall.exe | Added by the MYTOB.AO WORM! |
| X | Windows Firewall | svchost.exe | Added by the PROXY-HT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Windows Firewall | ipservice32.exe | Added by a variant of the RBOT WORM! |
| X | Windows Firewall | rundll32.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Windows Firewall | msmsd.exe | Added by the VB-OG MALWARE! |
| X | Windows Firewall Log | winlog.exe | Added by an unidentified WORM or TROJAN! |
| X | Windows Firewall Manager | msfw.exe | Added by the RBOT.WR WORM! |
| X | Windows firewall manager | chh.exe | Added by a variant of the RANDEX.GEL WORM! |
| X | Windows firewall manager | msguard.exe | Added by a variant of the RANDEX.GEL WORM! |
| X | Windows Firewall Service | wfsvc.exe | Added by the IRCBOT-YL WORM! |
| X | Windows Firewall Updater | updatees.exe | Added by the RBOT-GBX WORM! |
| X | Windows Firewall Updater | cronos.exe | Added by the RBOT-GBY WORM! |
| X | Windows Firewall Updater | ctfcom.exe | Added by the RBOT-GCB WORM! |
| X | Windows Firewall Updater | windowsupdate.exe | Added by the SPYBOT.AVEO WORM! |
| X | Windows Firewalll | scvhost.exe | Added by the RBOT-EK WORM! |
| X | Windows Firewalll | sphost.exe | Added by a variant of the RBOT WORM! |
| X | Windows Firewalll | svvhost.exe | Added by a variant of the RBOT WORM! |
| X | Windows Firewalll | winmu.exe | Added by a variant of the RBOT WORM! |
| X | Windows Fix | integator.exe | Added by the SDBOT.ZAB WORM! |
| X | Windows Fixer | winfix.exe | Added by the VIRUT-I VIRUS! |
| X | Windows Fixes Systems | elite.exe | Added by the MYTOB.EG WORM! |
| X | Windows Font Manager | smss.exe | Added by the ZANAYAT.B WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\fonts |
| X | Windows FormatAd | WinForm.exe | WindUpdates Windows FormatAd adware |
| X | Windows Frame Works | frmwrks32.exe | Added by a variant of the RBOT WORM! |
| X | Windows Framework | frmwrk.exe | Added by the DWNLDR-GWV TROJAN! |
| X | Windows Framework | scvh0st.exe | Malware installed by different rogue security software including SpyKillerPro and the XP AntiVirus series |
| X | WINDOWS FUCK BY CLASIC | fuck.exe | Added by the ZOTOB.H or ZOTOB.J WORMS! |
| X | Windows Gamma Display | wingamma.exe | Antivirus 2010 rogue security software - not recommended, removal instructions here |
| X | Windows Generic Proc | procmsg.exe | Added by the ALLIM.B WORM! |
| X | Windows Generic Services | winsvc32.exe | Added by the AGOBOT-ZF BACKDOOR! |
| X | Windows Genuine | svghost.exe | Added by a variant of the SPYBOT WORM! See here |
| X | Windows Genuine Validate | winservicessss.exe | Added by the IRCBOT.UUI BACKDOOR! |
| X | Windows Global Init | ngpsvc.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Windows GMT32 | wingmt32.exe | Added by the MYTOB.KM WORM! |
| X | Windows Graphics Loaders | wingraphics.exe | Added by the SPYBOT.JG WORM! |
| X | Windows Gras Service | wingr32.exe | Added by the SPYBOT.IZ WORM! |
| X | Windows Guard | WAUMGRD.EXE | Added by the RBOT-GY WORM! |
| X | Windows Guard Pro | WindowsGP.exe | Windows Guard Pro rogue security software - not recommended, removal instructions here |
| U | Windows Guardian | thehel1iawgrd32.exe | Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes |
| U | Windows Guardian | Fawgrd32.exe | Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes |
| X | Windows haz Layer | [5 random letters].exe | Added by a variant of the RBOT WORM! |
| X | Windows Help | mailinfo.exe | Added by the MYTOB.JX WORM! |
| X | Windows Help | Stney.exe | Added by the AGOBOT-VI WORM! |
| X | Windows Help File | winhelper32.exe | Added by the SDBOT-QK WORM! |
| X | Windows Help Manager | svchost32.exe | Added by the RBOT-OZ WORM! |
| X | Windows Help Service | winhelpsv.exe | Added by the RBOT-LP WORM! |
| X | Windows Help Service | winhlp.pif | Added by the RBOT-AKW WORM! |
| ? | Windows Help System | Help.pif | ?? |
| X | Windows Helper | winhelp.exe | Added by the BANKER.APE TROJAN! |
| X | Windows Helper | wsctnfy.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Windows Hijack Protection | comngr.exe | Added by the AGENT-FYD TROJAN! |
| X | Windows Hijack Protection System | commngr.exe | Added by the AGENT-FYD TROJAN! |
| X | Windows his Layer | pilotGame.exe | Added by the RBOT.GLX WORM! |
| X | Windows Host | hosts.exe | Added by the KELVIR.U WORM! |
| X | Windows Host | winhost.exe | Added by the PRYSAT TROJAN! |
| X | Windows Host Booter | hostbooter.exe | Added by an unidentified WORM or TROJAN! See here |
| X | Windows Host Device | hostsvc.exe | Added by the ZOOTY-A WORM! |
| X | Windows Host Name | lmass.exe | Added by the GAOBOT.O WORM! |
| X | Windows Host Service | scvhosts.exe | Added by the SPYBOT.NLI WORM! |
| X | Windows Host Service | host.exe | Added by the KELVIR.AN WORM! |
| X | Windows Host Service | svchoste.exe | Added by the KELVIR.BF WORM! |
| X | Windows Host Service | svchosts32.exe | Added by the KELVIR.AW WORM! |
| X | Windows Host32 Starter | hostserv.exe | Added by the SDBOT-WU WORM! |
| X | Windows Hosts | hosts.exe | Added by the KELVIR-O TROJAN! |
| X | Windows Hosts | winhosts.exe | Added by a variant of the IRCBOT TROJAN! |
| X | Windows HP Drivers | hpdmws.exe | Added by the SDBOT.AQU WORM! |
| X | Windows HP Drivers | winhps.exe | Added by the SDBOT.ON BACKDOOR! |
| X | Windows HTML file reader | Sysconf32.exe | Added by the NOOMY.A WORM! |
| X | Windows HTTP services | winhttps.exe | Added by a variant of the SDBOT WORM! See here |
| X | Windows Icons Manager | wicomgr.exe | Added by the RBOT-AIF WORM! |
| X | WINDOWS ID SYSTEM | wID32.exe | Added by the MYTOB.LN WORM! |
| X | Windows Identify | sysays.exe | Added by a variant of the SPYBOT WORM! See here |
| X | Windows Image | wintimage.exe | Detected by Avast as the SDBOT-GEN44 WORM! |
| X | Windows Image Acquisition (WIASC) | WIAcs.exe | Added by the RIZO.A TROJAN! |
| X | Windows Image Acquisition (WIASSC) | WIAcss.exe | Added by the RIZO.A TROJAN! |
| X | Windows iMessenger Messenger | winimsg.exe | Added by the ALLIM.A WORM! |
| X | Windows Incontext | InSearch.exe | PacerD_Media/Pacimedia.com/Z-Quest adware installer |
| X | WINDOWS INIT | wininit.exe | Added by the ZOTOB-K WORM! Note - this is not the legitimate wininit.exe process from Vista/7 which is always located in %System% and should not normally figure in Msconfig/Startup! |
| X | Windows Insecure | [path to worm] | Added by the RBOT-FSM WORM! |
| X | Windows installer | winstall.exe | SpySheriff rogue spyware remover - not recommended, removal instructions here |
| X | Windows Installer | ntdll.exe | Added by an unidentified WORM or TROJAN! |
| X | Windows Installer 1 | msnconfig.exe | Added by the PURITYSCN.B TROJAN! |
| X | Windows Instruction Services | winstruct32.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Windows Interet Explorer 6 | wmidx32.exe | Added by the RBOT.AOW WORM! |
| X | Windows Internet Browser Services | internet.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Internet Browser Services | internet128.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Internet Browser Services | internet32.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Internet Browser Services | internet64.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Internet Explorer 6 | firefox.exe | Added by the SPYBOT.ANA WORM! Note - this is not the Mozilla Firefox web browser which is always located in %ProgramFiles%\Mozilla Firefox. This file is found in %System% |
| X | Windows Internet Manager | svchost.exe | Added by the IRCBOT-AAC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Windows Internet Protocol | winproc32.exe | CoolWebSearch Winproc32 parasite variant - also detected as the STARTPA-BF TROJAN! |
| X | Windows Internet Protocol | deinst_qfe001.exe | Added by a variant of the Win32.Small TROJAN! |
| X | Windows Internet Service | wininet.exe | Added by the RBOT-AUX WORM! |
| U | Windows IP Security | ipsec.exe | Related to the VPN IPSec utility - used to create Security Policy (SP) entries and Security Association (SA) entries in the kernel |
| X | Windows IP Security Service | ipsecs.exe | Added by the RBOT.BPW WORM! |
| X | Windows IPv6 Drivers | wipv6.exe | Added by the SDBOT-VJ WORM! |
| X | Windows Java Update | weatherBug32.exe | Added by a variant of the RBOT WORM! |
| X | Windows JavaScript Daemon | Winjsd.exe | Added by the WOOTBOT.AF WORM! |
| X | Windows Javascript Daemon | jsdaemon.exe | Added by the RBOT.EK BACKDOOR! |