| Status | Autorun name | Command | Description |
| X | winlog | windowxs.exe | Added by the SDBOT-KT BACKDOOR! |
| X | winlog | winsx.exe | Added by the SDBOT-MH BACKDOOR! |
| X | winlog manager | winlog.exe | Added by the DONBOMB.A TROJAN! |
| X | winlog.exe | winlog.exe | Added by the BCKDR-RBJ TROJAN! |
| X | WINLOG0N | WINLOG0N.EXE | Added by the MYDOOM.BI WORM! |
| X | WinLogin | winlogin.exe | Added by the AGOBOT-IX WORM! |
| X | winlogin | win32x.exe | Added by the STARTPA-DF TROJAN! |
| X | winlogin | ReadMe.exe | Added by the SILLYFDC.BBT WORM! |
| X | Winlogin.exe | log.exe | Added by a variant of the AGENT.AH TROJAN! |
| X | winlogin.exe | logfile.exe | Added by the AGENT.AH TROJAN! |
| X | winlogin.exe | mspaint.exe | Added by a variant of the AGENT.AH TROJAN! |
| X | Winlogin.exe | steam.exe | Added by a variant of the AGENT.AH TROJAN! |
| X | winlogins.exe | winlogins.exe | Added by the OPTIX.H BACKDOOR! |
| X | winlogoff | winlogoff.exe | Added by the AGOBOT-TR WORM! |
| X | winlogon | winlogin.exe | Added by the RANDEX.E WORM! |
| X | winlogon | winlogon.exe | Added by the TRODAL TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | winlogon | msreg32.exe | Added by the SDBOT.EO BACKDOOR! |
| X | winlogon | winlogon32.exe | Added by the MASLAN.C WORM! |
| X | winlogon | wpwlogon.exe | Added by an unidentified WORM or TROJAN! |
| X | WINLOGON | wscript.exe WINLOGON.vbs | Added by the YSPAN.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "WINLOGON.vbs" file is found in %System% |
| X | Winlogon | Lsass.exe | Added by the ALCOP-B WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | winlogon | nvchost.exe | Added by an unidentified WORM or TROJAN! |
| X | Winlogon | WINLOGON.EXE | Added by the PUNYA-B WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Documents and Settings\Administrator\Local Settings\Application Data\WINDOWS |
| X | winlogon | system.exe | Added by a variant of the DELF.CNS TROJAN! |
| X | winlogon | cleanmg.exe | Added by the AGENT-ICR TROJAN! |
| X | Winlogon | scssrr.exe | Added by the AGENT-LXB TROJAN! |
| X | winlogon | ircbsbot.exe | Added by the AGENT-RGJ TROJAN! |
| X | winlogon service | urx.exe | Added by the SPYBOT.EN WORM! |
| X | Winlogon Shell | Explorer.exe svchost.exe | Added by the KIPIS.M WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "1032" sub-folder |
| X | Winlogon.exe | N/A | CoolWebSearch parasite variant - resets home page to an adult content site |
| X | winlogon.exe | helper.exe | Added by the FAKESPY-A TROJAN! |
| X | winlogon.exe | msole32.exe | Adware, also detected as the FAKESPY-B TROJAN! |
| X | winlogon_user | ccIsass.exe | Added by the SILLYFDC.BBT WORM! |
| X | winlogon32_ | [path to file] | Added by the RULAND.A WORM! |
| X | WinLogonnd | winlogonnd.exe | Added by the AGENT-NNQ TROJAN! |
| X | Winlogun | winlogin.exe | Added by the P2LOAD-C WORM! |
| X | WinLsass | servicec.exe | Added by the SCANE WORM! |
| X | WinLsass | [path to trojan] | Added by the SCANE WORM! |
| X | winltmpv | winln.exe | Added by the TCXMEDI-C TROJAN! |
| X | winltmpv | wutop.exe | Added by the TCXMEDI-C TROJAN! |
| X | Winmain | winmain.exe | One of the first of a new breed of malware. When run it immediately loads MSHTA.EXE from the Windows folder, placing it on "hot standby", ready to accept HTA scripting within a web page and then EXECUTE what is embedded IN the page as a program! In other words, it's possible for a "rogue" website to actually embed trojans, worms and/or viruses directly into a web page. NSClean's HTA Stop offers an easy way to toggle this capabiltity, or rather vulnerability, on and off. I suggest you leave it disabled! |
| X | WinManage | wmanage.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| ? | WinManager | schost.exe | ?? |
| U | winmatrix.exe | WinMatrixXP.exe | WinMatrix XP - wallpaper replacement that shows different matrix effects (including flowing matrix codes from 'The Matrix' movie) on your desktop |
| X | WinMed | winmed.exe | Added by the AGENT.AIRF TROJAN! |
| X | WinMedia | [path to trojan] | Added by the ZEROBE-A TROJAN! |
| X | WinMedia | msupd******.exe [*= random digit] | Added by the INJECT.163 TROJAN! |
| X | WinMedia32 | winmedia32.exe | Added by the YABE.F TROJAN! |
| U | WinMem | WinMem.exe | WinMem Cleaner - part of Ultra WinCleaner Utility Suite. Makes more memory available for your programs and the Operating System. It also defragments your system |
| X | WinMenssage | winmax.exe | Added by the BANCOS.B TROJAN! |
| X | WinMenssage | winmaxy.exe | Added by the BANCOS TROJAN! |
| X | WinMessenger | syshost.exe | Added by the OPANKI-E WORM! |
| N | WinMgmt | WinMgmt.exe | Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here |
| X | winmgmt | wmiprvse.exe | Added by the AGENT-GHP TROJAN! |
| X | winmgmt32.exe | winmgmt32.exe | Added by the LUZIA.AD TROJAN! |
| X | WINMGR | taskgmgr.exe | Added by the MYTOB.AN WORM! |
| X | WinMgr | winmgr32.exe | Added by the VB-EDY TROJAN! |
| X | Winmgr.exe | scvhost.exe | Added by the AGOBOT.AFG WORM! |
| X | WinMgr32 | winmgr32.exe | Added by the MIMAIL.P WORM! |
| X | WinMine | D4NG3.vbs | Added by the BISCUIT.A WORM! |
| X | WinMngn | dllhost.exe | Added by the SIVION-A TROJAN! Note - this is not the legitimate dllhost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\system |
| X | winmngr.exe | [path to trojan] | Added by the AGENT-ZB TROJAN! |
| Y | winmodem | wmexe.exe | Software for software based modems. Required if you have one of these. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information |
| X | Winmon32 | winmon32.exe | Added by the RBOT-OQ WORM! |
| X | WinMoviePlugIn | WinMoviePlugIn.exe | Sfonditalia adult content premium rate dialer |
| X | Winmsg | winwork.exe | Added by the GAOBOT.GEN!POLY WORM! |
| X | WinMsg | winmsgr.exe | Added by the DLOADR-AS TROJAN! |
| X | Winmsg | winwork8.exe | Added by the AGOBOT-GC WORM! |
| X | WinMsrv32 | WinMsrv32.exe | Added by the GAOBOT.AFJ WORM! |
| N | WinMX | WinMX.exe | WinMX file sharing application |
| N | winmysqladmin | winmysqladmin.exe | Starts the MySQL database admin tool |
| N | WinMySQLadmin Tool | winmysqladmin.exe | Starts the MySQL database admin tool |
| X | winnet | winnet.exe | CommonName Toolbar spyware. To uninstall see here |
| X | WinNetDDE | [random characters].exe | Added by the NETDEPIX.B TROJAN! |
| X | WinNite | niteaim.exe | Added by the OPANKI.B WORM! |
| X | winnload | winnload.COM | Added by the DOWNLD-ABG TROJAN! |
| ? | Winnov Menu | WnvMenu.Exe | Winnov Video Capture Card related. What does it do and is it required? |
| ? | Winnov Remote | WnvRsvr.Exe | Winnov Video Capture Card related. What does it do and is it required? |
| ? | Winnov Status | WvStatus.Exe | Winnov Video Capture Card related. What does it do and is it required? |
| X | winnsvc | msvc.exe | Added by the PWS.O TROJAN! |
| X | winnt | winnt.exe | Added by the MONA-E WORM! |
| X | WinNT | WinNT.com | Added by the AUTOSKY WORM! |
| X | winnt DNS ident | pidchk32.exe | Added by the RBOT-ACY WORM! |
| X | winnt DNS ident | windowxp.exe | Added by a variant of the RBOT WORM! |
| X | winnt DNS ident | Winupd32.exe | Added by the RBOT.AVU WORM! |
| X | winnt DNS ident | winupdate32.exe | Added by a variant of the RBOT WORM! |
| X | winnt DNS ident | wuamgrd33.exe | Added by a variant of the RBOT WORM! |
| X | Winnt DNS ident | windowsp.exe | Added by the RBOT.BAL WORM! |
| X | Winnt DNS ident | msnmsrg.exe | Added by the RBOT.BVQ WORM! |
| X | winnt DNS ident | wuamgrd32.exe | Added by the RBOT-BAU WORM! |
| X | winnt DNS ident | iexplorer.exe | Added by a variant of the RBOT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
| X | winNT updatc | wupgrd.exe | Added by a variant of the RBOT WORM! |
| X | winnt2 | winnt2.exe | Added by the AGENT.CJZO TROJAN and variants |
| X | winnt3 | winnt3.exe | Added by the AGENT.CJZO TROJAN and variants |
| X | winnt4 | winnt4.exe | Added by the AGENT.CJZO TROJAN and variants |
| X | winnt5 | winnt5.exe | Added by the AGENT.CJZO TROJAN and variants |
| X | winnt6 | winnt6.exe | Added by the AGENT.CJZO TROJAN and variants |
| X | WinNtBB | WinntBB.exe | Added by the DULOAD.C WORM! |
| X | winntR1 | winntR1.exe | Added by the AGENT.CJZO TROJAN and variants |
| X | winntR2 | winntR2.exe | Added by the AGENT.CJZO TROJAN and variants |