| Status | Autorun name | Command | Description |
| X | Windows Kernel 64 | kernal64.exe | Added by the YIMP-B WORM! |
| X | Windows Kernel Log | WinKettle.exe | Added by the AGENT-HFA TROJAN! |
| X | Windows Kernel System Service | [filename].exe | Added by the RBOT-FLL WORM! Common filenames include "wkssvr.exe", "winsys.exe" and "wkssvc.exe" and they are located in %System% |
| X | Windows kev Messenger | mskev.exe | Added by the SDBOT-XV WORM! |
| X | Windows Keyboard Services | winkeyboard.exe | Added by the IRCBOT.AFS WORM! |
| X | Windows Keyboard Services | winkeybrd.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Keyboard Services | winkeybrd32.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Live | msgnms.exe | Added by the XPACK.AV TROJAN! |
| X | Windows Live | WindowsLive.exe | Added by the REALBOT-A WORM! |
| X | Windows Live Care.exe | WindowsLiveCare.exe | Added by unidentfied MALWARE - see here! Do not confuse with Microsoft's Windows Live OneCare security software which is found in %ProgramFiles%\Microsoft Windows OneCare Live. This one is found in %System% and runs from both the HKLM\Run & HKLM\RunServices registry keys |
| X | Windows Live Client | msnclient.exe | Added by a variant of the IRCBOT TROJAN! See here |
| U | Windows Live Family Safety Filter | fsui.exe | System Tray access to and notifications from Windows Live Family Safety - optionally installed as part of Windows Live Essentials. "With Family Safety, you decide how your kids experience the Internet. Limit searches, monitor and block or allow websites, and decide who your kids can communicate with in Windows Live Spaces, Messenger, or Hotmail". Note - disabling this entry does not disable Family Safety and prevent it monitoring a users activity or restricting access |
| X | Windows Live Manager | winlivemgr.exe | Added by the SHEUR.EB TROJAN! |
| X | Windows Live Messages | msgnlive.exe | Added by the AGENT.AYH WORM! |
| X | Windows Live Messenger | msnmsgr.exe | Added by a variant of the RBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System% |
| X | Windows live Messenger | msn.com | Added by the IRCBOT-AAV WORM! |
| X | Windows Live Messenger | msnlive.exe | Added by the RBOT.BMV BACKDOOR! |
| X | windows Live Messenger | iexplore.exe | Added by the BCKDR-QTS BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| N | Windows Live Messenger | msnmsgr.exe | Windows Live Messenger (was MSN Messenger) utility - available via the Start menu. Disable by clicking on the "Show menu" icon and select Tools → Options → Sign In → deselect "Automatically run Windows Live Messenger when I log on to Windows". This is the Windows Defender/Vista MSConfig entry for version 14.* |
| X | Windows Live Messenger | [random].exe | Added by the RBOT-GVL WORM! |
| X | Windows Live Messenger | msnd.exe | Added by the BCKDR-QQQ BACKDOOR! |
| X | Windows Live Messenger 8.12 | ctfmon.exe | Added by the LIPARK-A WORM! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %UserProfile% |
| X | Windows Live Messenger Addon | wllivemsngr.exe | Added by a variant of the SDBOT WORM! See here |
| X | Windows Live Messenger Servicer | msmgslive.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Live Messenger Services | msgrlive.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Live Messenger! | livemsngr.exe | Added by the IRCBOT.AWE BACKDOOR! |
| X | Windows Live Messenger! | msgrlive.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Live Msgs | wlivemsg.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Live Msgs! | wlivemsgs.exe | Added by a variant of the IRCBOT TROJAN! See here |
| Y | Windows Live OneCare | winssnotify.exe | System Tray access to and notifications from Windows Live OneCare - now superseded by Microsoft Security Essentials. "OneCare helps keep your PC safe and secure while making your life easier. From virus scanning and file backups, to automatic printer sharing of all the PCs in your household, OneCare helps manage all of this. Delivered to you in a smooth, hassle-free package" |
| X | Windows Live Service | msnlive.exe | Added by the SLENFBOT.DI WORM! |
| X | Windows Live Servicer | usrserv.exe | Added by the SMALL.LU BACKDOOR! |
| X | Windows live Support | wlmsngr.exe | Added by the RBOT-BKL WORM! |
| U | Windows Live Sync | WindowsLiveSync.exe | Windows Live Sync from Microsoft (formerly known as Windows Live FolderShare) - "a free-to-use internet-based file synchronization application by Microsoft that is designed to allow files and folders between two or more computers be in sync with each other on Windows (Vista and later) and Mac OS X based computers" |
| U | Windows Live™ OneCare™ Family Safety | fssui.exe | System Tray access to and notifications from Windows Live OneCare Family Safety - part of the Live OneCare range and now superseded by Windows Live Family Safety which is part of Windows Live Essentials. Allows you to decide how your kids experience the Internet by limiting searches, monitoring and blocking/allowing websites and deciding who your kids can communicate with in Messenger or Hotmail. Note - disabling this entry does not disable Family Safety and prevent it monitoring a users activity or restricting access |
| ? | Windows Load | windows.com | ?? |
| X | Windows Loader | wstart32.exe | Added by the GAOBOT.CA WORM! |
| X | Windows Loader | winServices.pif | Detected by Kaspersky as the CARDSPY.D TROJAN! |
| X | Windows Loader | SysUpdate.exe | Added by a variant of the SDBOT WORM! |
| X | Windows Loader Service | civsc.exe | Added by a variant of the RBOT WORM! |
| X | windows Loadxm | Win_.exe | Added by the FODDER-A TROJAN! |
| X | Windows Local ISP | winthcr.exe | Added by the SDBOT.ENZ BACKDOOR! |
| X | Windows Local Services | svcrun.exe | Added by the DLOADER-NY TROJAN! |
| X | Windows Local Services | tcpsvc.exe | Added by the DLOADER-NY TROJAN! |
| X | Windows Local Services | websvc.exe | Added by the DLOADER-NY TROJAN! |
| X | Windows Local Services | localsvc.exe | Added by the DLOADER-NY TROJAN! |
| X | Windows Local Services | netsvc.exe | Added by the DLOADER-NY TROJAN! |
| X | Windows Local Services | spoolsvc.exe | Added by the DLOADER-NY TROJAN! |
| X | Windows Local Services | svcadmin.exe | Added by the DLOADER-NY TROJAN! |
| X | Windows Local Services | svcman.exe | Added by the DLOADER-NY TROJAN! |
| X | Windows Local Spooler | lssas.exe | Added by the RBOT.BXQ WORM! |
| X | Windows Locator | wsass.exe | Added by the IRCBOT.N TROJAN! |
| X | Windows Log Agent | winlogon.exe | Added by the KEYLOGGER.AVK TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files |
| X | Windows Logger | winlog.exe | Added by the NSHADOW-B TROJAN! |
| X | Windows logging | winlogd.exe | Added by the RBOT-ON WORM! |
| X | Windows logging | asgasg.exe | Added by a variant of the IRCBOT TROJAN! |
| X | Windows Logical Adapter | wsrsvc.exe | Added by the IRCBOT.ARU BACKDOOR! |
| X | Windows Logical Connection | wcnsvc.exe | Added by the VIRUT.AO VIRUS! |
| X | Windows Login | explored.exe | Added by the GAOBOT.SY WORM! |
| X | Windows Login | winlog.exe | Added by the AGOBOT.MG WORM! |
| X | Windows Login | lmss.exe | Added by the AGOBOT-JA WORM! |
| X | Windows Login | msnmsgr.exe | Added by the AGOBOT-UC WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System% |
| X | Windows Login | login.exe | Detected by Eset's NOD32 antivirus as a variant of the BIFROSE TROJAN! |
| X | Windows Login | lms.exe | Added by the AGOBOT-IC WORM! |
| X | Windows Login Folder | winzep.exe | Added by the AGOBOT-TZ WORM! |
| X | Windows Login Manager | winlogin.exe | Added by a variant of the SDBOT WORM! |
| X | Windows Login Security | winlogin.pif | Added by an unidentified WORM or TROJAN! |
| X | Windows Login Service | winlog.exe | Added by the RBOT-AFN WORM! |
| X | Windows Login Service | winlogin.pif | Added by the SDBOT-ACU WORM! |
| X | Windows Login Services | winlogon.exe | Added by the AUTORUN-AVS WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\S85-28348346-HAT83-E3-62366-HASG-1732735 |
| X | Windows Logon | winlogin.exe | Added by the SPYBOT-C TROJAN! |
| X | Windows Logon | winlogon.exe | Added by the VB.HE VIRUS! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\system |
| X | Windows Logon | login.exe | Added by the SDBOT-DGQ WORM! |
| X | Windows Logon Application | WinIogon.exe | Added by the LINKBOT.M WORM! |
| X | Windows Logon Application | logon.exe | Added by the POEBOT-J WORM! |
| X | Windows Logon Application | services.exe | Added by the CIADOOR-L TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Windows Logon Application | win32help.exe | Added by the DELBOT-X WORM! |
| X | Windows Logon Application | winlogon.exe | Added by the POEBOT-KW WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
| X | Windows Logon Application | winamp.exe | Added by the POEBOT-LR WORM! Note - this is NOT the popular Winamp media player which is located in %ProgramFiles%\Winamp. This one is located in %System% |
| X | Windows Logon Applicationedc | winlogon.exe | Added by the DWNLDR-HGR TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile% |
| X | Windows Logon Applicatonedc | winlogon.exe | Added by the VB-EBV TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile% |
| X | Windows Logon Manager | logon.exe | Added by a variant of the RBOT WORM! |
| X | Windows Logon Procedure | Svchoste.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows Logon Procedure | Svchosta.exe | Added by a variant of the SPYBOT WORM! |
| X | windows logon procedure | winlogonpc.exe | Added by the WINLOGON TROJAN! |
| X | Windows Logon Service | winlogon.pif | Added by the RBOT-AOU WORM! |
| X | Windows Logon Service | napi32.exe | Added by the SPYBOT.ANDM WORM! |
| X | Windows Logon Service | winlogoservice.exe | Added by the SPYBOT.ANOO WORM! |
| X | Windows Logon Service | micropoft.exe | Added by the RBOT-FZY WORM! |
| X | Windows Logon Servicer | winlogon.exe | Added by the BLAZEBOT.A WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\WinNT |
| X | Windows LoL Layer | gqwdcr.exe | Added by the AGOBOT-AHS WORM! |
| X | Windows LoL Layer | win.exe | Added by the RBOT-FTO WORM! |
| X | Windows LoL Layer | [random filename].exe | Added by the RBOT-GMD WORM! |
| X | Windows LoL Layer | pyvnpt.exe | Added by the RBOT-GKV WORM! |
| X | Windows LoL Layer | winlolx.exe | Added by the RBOT-FOR WORM! |
| X | Windows LoL Layer | azypbrx.exe | Added by the RBOT-GMZ WORM! |
| X | Windows LoL Layer | blvpnmcny.exe | Added by the RBOT-GOR WORM! |
| X | Windows LoL Layer | ymllh.exe | Added by the RBOT-FSU WORM! |
| X | Windows Lord Anti-Virus | winlord32.exe | Added by the SDBOT-GW WORM! |
| X | Windows Management Informant | wmmiexe.exe | Added by the IRCBOT-V BACKDOOR! |