| Status | Autorun name | Command | Description |
| X | Win32 Services Config | winwkys.exe | Added by the RBOT.BKY WORM! |
| X | Win32 Services1 | wuamngr1.exe | Added by the SDBOT-PV WORM! |
| X | Win32 Src Service | win32src.exe | Added by the RBOT-SX WORM! |
| X | Win32 SSL Driver | winssv.exe | Added by the FORBOT-BH WORM! |
| X | Win32 Svchosts Driver | svchosts.exe | Added by the FORBOT-FO WORM! |
| X | Win32 System Kernel | winservice.exe | Added by the SDBOT.KIN WORM! |
| X | win32 system server | winserver.exe | Added by the DERMON-A TROJAN! |
| X | Win32 System Spool | spoolsvc.exe | Added by the SDBOT.UK WORM! |
| X | Win32 Test | bleatest.exe | Added by a variant of the RBOT WORM! |
| X | Win32 Update | svchosts.exe | Added by a variant of the SDBOT WORM! |
| X | Win32 Update | dl32.exe | Added by an unidentified WORM or TROJAN! |
| X | win32 update service | svchostt.exe | Added by a variant of the SDBOT WORM! |
| X | Win32 USB Driver | winxpinit.exe | Added by the SDBOT.AA TROJAN! |
| X | Win32 USB Driver | mvsecn.exe | Added by the FORBOT-BK WORM! |
| X | Win32 Usb Driver | svhosint32.exe | Added by the FORBOT-BE or FORBOT-J WORMS! |
| X | Win32 Usb Driver | usb32.exe | Added by the SDBOT-OV WORM! |
| X | Win32 Usb Driver | AvpG.exe | Added by the FORBOT-BX WORM! |
| X | Win32 USB Driver | rundll.exe | Added by the FORBOT-BN WORM! Note - this is NOT the Win9x/Me system file of the same name as described here |
| X | Win32 USB2 | wins32.exe | Added by a variant of the RBOT WORM! |
| X | Win32 USB2 Driver | win32usb.exe | Added by the SPYBOT.DHV WORM! |
| X | Win32 USB2 Driver | smsc.exe | Added by the SDBOT.FO WORM! |
| X | Win32 USB2 Driver | svchosting.exe | Added by the FORBOT-J or SDBOT.HU WORM! |
| X | Win32 USB2 Driver | sys32.exe | Added by the WOOTBOT.X WORM! |
| X | Win32 USB2 Driver | sys32snd.exe | Added by the FORBOT-AN WORM! |
| X | Win32 USB2 Driver | wind32.exe | Added by the FORBOT-AH WORM! |
| X | Win32 USB2 Driver | winupdate.exe | Added by the AGOBOT.YE WORM! |
| X | Win32 USB2 Driver | updatemgr.exe | Added by a variant of the FORBOT WORM! |
| X | Win32 USB2 Driver | winsnd32.exe | Added by a variant of the SDBOT WORM! |
| X | Win32 USB2 Driver | msn.exe | Added by the FORBOT-EX WORM! |
| X | Win32 USB2 Driver | syscfg32.exe | Added by the FORBOT-R WORM! |
| X | Win32 USB2 Driver | algg.exe | Added by the TIBS.BF WORM! |
| X | Win32 USB2 Driver | usb2.exe | Added by the FORBOT-Y WORM! |
| X | Win32 USB2 Driver | winusb32.exe | Added by the FORBOT-M WORM! |
| X | Win32 USB2.0 Driver | 386.exe | Added by the IRCBOT.D WORM! |
| X | Win32 USB2.0 Driver | rundll16.exe | Added by the WOOTBOT.H WORM! |
| X | Win32 USB2.0 Driver | w32usb2.exe | Added by the SPYBOT.DN WORM! |
| X | Win32 USB2.0 Driver | service.exe | Added by the SDBOT-QF WORM! |
| X | Win32 USB3 Driver | win32tool.exe | Added by a variant of the RBOT WORM! |
| X | Win32 Wmls Driver | winitr32.exe | Added by the WOOTBOT.B WORM! |
| X | Win32 Word Services | msword32.exe | Added by a variant of the RBOT WORM! |
| X | Win32.exe | Win32.exe | Added by the AWQ.A BAKCDOOR! |
| X | Win32.Exploit.mzH | mzrun.exe | Added by the PAINTER TROJAN! |
| X | Win32.Pozarevac | Pozarevac.exe | Added by the DELF-FBN TROJAN! |
| X | Win32.Trojan.Downloader | netstat2.exe | Added by the PAINTER TROJAN! |
| X | WIN32[random numbers] | [path to file] | WinBo adware |
| X | win32_i lptt01 | win32_i.exe | RapidBlaster variant (in a "win32_i" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | win32_i ml097e | win32_i.exe | RapidBlaster variant (in a "win32_i" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | win3208022-1336687 | win3208022-1336687.exe | Added by the VB-CFG TROJAN! |
| X | Win32BaseServiceMOD | Wintask.exe | Added by the NAVIDAD WORM! |
| X | win32beta | win32sys4.exe | Added by the BANKER-DA TROJAN! |
| X | win32clf | win32clf.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | win32debug | win32debug.exe | Added by the GUDEB WORM! |
| X | Win32DLL | Win32DLL.vbs | Added by the LOVELETTER (I LOVE YOU) VIRUS! |
| X | Win32dll | Win32dll.exe | Added by the BANPAES TROJAN! |
| X | WIN32DS | clienttimer.exe | Eziin adware |
| X | Win32G | Kernel32.com | Added by the ESTRELLA TROJAN! |
| X | Win32G | Scandisk.com | Added by the ESTRELLA TROJAN! |
| X | win32gb | win32gb.exe | Added by the DLUCA-F TROJAN! |
| X | Win32Host Process | webemir.exe | Added by the TURGEN -A TROJAN! |
| X | win32info | win32info.exe | Adult content dialler |
| X | win32ini | systroy.exe | Added by the IRC.ALADINZ.C TROJAN! |
| X | WIN32io | clienttimer.exe | Eziin adware |
| X | win32Kernel | findx.exe | Added by the BANLOA-EY TROJAN! |
| X | Win32KernelStart | microsoft.exe | Added by the DELF-EWZ TROJAN! |
| X | Win32load | [random].exe | Added by the LODELIT TROJAN! Note - the file is located in %AppData% |
| X | Win32load | nscagent.exe | Added by the DOWNLOADER-BON TROJAN! |
| X | Win32load | ptssvc.exe | Added by the FAKEAV-MK TROJAN! |
| X | Win32load | sysrc32.exe | Added by the DOWNLOADER-BON TROJAN! |
| X | Win32Mgr | [path to trojan] | Added by the AIMSPY TROJAN! |
| X | Win32R | Server.com | Added by the ESTRELLA TROJAN! |
| X | WIn32S Java DLL | kavsvx.exe | Added by the AGOBOT-RZ WORM! |
| X | win32serv | devicer.exe | Added by the CHECKOUT WORM! |
| X | win32serv | servicesetup.exe | Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger |
| X | win32serv | systemdevices.exe | Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger |
| X | win32servv | load.exe | iSearch adware |
| X | win32servv | ms1.exe | iSearch adware |
| Y | WIN32SL | Win32sl.exe | Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. The specific function of this is to load MIF's in order for Dell OpenManage Client to work |
| X | WIN32SNDS | banc.exe | Added by an unidentified WORM or TROJAN! |
| X | Win32system | [random filename] | Added by the DDV.B WORM! |
| X | Win32System | win32s.exe | Added by the MYDOOM.V WORM! |
| X | Win32SystemMonitor | [random filename] | Added by the AGENT.IT TROJAN! |
| X | Win32SysV | xin.exe | Added by the FORBOT-EO WORM! |
| X | Win32Update | [malware filename] | Added by the MOMIBOT BACKDOOR! |
| X | win32update | win32update.exe | Added by the GENOME.AQUV TROJAN! |
| X | Win32Updater | KERNAL32.EXE | Added by the SPYBOT-OK WORM! |
| X | win32us | win32us.exe | All-In-One-Telcom (adult content dialler) variant |
| X | win32usbd | ssrs.exe | Added by the RBOT-RA WORM! |
| X | Win32Usr | WinCab.exe | Added by the DEDMIR-A WORM! |
| X | WIN32WN | system_wc.exe | Eziin adware |
| X | Win386 | Win386.exe | Added by the GOSUSUB VIRUS! |
| X | Win386 | sp32.dll | Homepage hijacker. Not a dll but a regfile in disguise |
| X | WIN3S2SNDS | winabsmod.exe | Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" |
| X | WIN3S2SNDS | winiprtx.exe | Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" |
| X | Win64 Compatibility Check | load win64.drv | CoolWebSearch parasite variant |
| X | Win7 AV | Win7 AV.exe | Win7 AV rogue security software - not recommended, removal instructions here |
| X | WIN95DEFVIEW | [path to file] | Added by the DEDLER-D TROJAN! The most common filenames seen are "csmss.exe" and "csmrs.exe", located in %System% |
| X | win98 DNS | wingrd.exe | Added by a variant of the RBOT WORM! |
| X | winabc | rundll32.exe [Temp]\[ORIGFILENAME].DLL,InstallLaunchEv | Added by the LINEAGE-PN TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | WinAble | winable.exe | Added by the MATCASH.BG TROJAN! |
| X | WinAC v4 | klsuicbn.exe | Added by the FORBOT-CS WORM! |