| Status | Autorun name | Command | Description |
| X | WinSetBrowse | BasicUpdate.dll.vbs | Added by the BISCUIT.A WORM! |
| X | winsfc | winsfc.exe | Added by the WISFC VIRUS! |
| X | Winshell | remote.exe | Added by the MYTOB.LJ WORM! |
| X | winshell | windll32lib.exe | Added by the BAGLE-DM WORM! |
| ? | Winshoe | wuadfdqr.exe | Probably an unidentified VIRUS! Adds itself to 3 registry "Run" keys and prevents Task Manager being displayed. This is not the Winshoe IRC Client as the visitor did not have it installed |
| X | winshost.exe | winshost.exe | Added by the TOOSO WORM and variants! |
| X | winshow | [path to trojan] | Added by the VB-DXP TROJAN! |
| X | WinShowUpdate | copy [path] winshow.new [path] winshow.dll | Winshow parasiate related - from the "RunOnce" keys it replaces "winshow.dll" with a new version |
| X | WinSig | NetXP.exe | Added by the BANKER-FN TROJAN! |
| X | WinSistem | Tunggul.vbs | Added by the VBS.STEMCLOVER WORM! |
| X | Winsk system Loader | winsk.exe | Added by the AGOBOT-IZ WORM! |
| X | winskype | winskype.exe | Added by the BROGGER-C TROJAN! |
| U | WinSL | WinSL.exe | StarLogger keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | winsock | svch0st.exe | Added by the SAGE-A WORM! Note - the filename has the digit 0 rather then the uppercase "o" |
| X | Winsock driver | winnt update.exe | Added by the SPYBOT-DM TROJAN! |
| X | Winsock driver | winnt64.exe | Added by the SPYBOT-DR WORM! |
| X | Winsock Driver | nvscv32.exe | Added by the AGOBOT-FD WORM! |
| X | Winsock Driver | scvhost.exe | Added by the RBOT.AEU BACKDOOR! |
| X | Winsock driver | win.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Winsock driver | tcpmngr.exe | Added by the SPYBOT-CK WORM! |
| X | Winsock driver | winupdate32.exe | Added by the SPYBOT-JZ TROJAN! |
| X | Winsock Startup | Main2.exe | Added by a variant of the SDBOT WORM! |
| X | winsock.client | winsock.exe | Added by the DIABLO-M TROJAN! |
| X | winsock2 | netsvr.exe | Added by the AGOBOT.LY WORM! |
| X | Winsock2 dlls | W32DLL.EXE | Added by the SPYBOT-CS BACKDOOR! |
| X | Winsock2 driver | SVCHOSTS.EXE | Added by the SPYBOT-BW BACKDOOR! |
| X | Winsock2 driver | Win32.exe | Added by the SPYBOT-G WORM! |
| X | Winsock2 driver | WINDATE.EXE | Added by the SPYBOT WORM! |
| X | Winsock2 driver | SDJOIJE.EXE | Added by the SPYBOT.DR TROJAN! |
| X | Winsock2 driver | MIRC32.exe | Added by the SPYBUZZ TROJAN! |
| X | Winsock2 driver | kgzgjkpcw.exe | Added by the SDBOT.T TROJAN! |
| X | Winsock2 driver | ZONEALARM.EXE | Added by the SDBOT.T TROJAN! Note - ZONEALARM.EXE is not the valid Zone Labs firewall program |
| X | Winsock2 driver | wincfg.scr | Added by the SPYBOT-E TROJAN! |
| X | Winsock2 driver | winupdate.exe | Added by the SPYBOT-BX WORM! |
| X | Winsock2 driver | SPOLSV.EXE | Added by the SPYBOT-CM WORM! |
| X | Winsock2 driver | [random filename] | Added by members of the SPYBOT family of WORMS! Note - the random filename is located in %System% |
| X | Winsock2 driver | sysreq.exe | Added by the SPYBOT-CC WORM! |
| X | Winsock2 driver | WUAUMQR.EXE | Added by the SPYBOT-DP WORM! |
| X | Winsock2 driver | wincfg.exe | Added by the SPYBOT.CO WORM! |
| X | Winsock2 driver | svchorsst.exe | Added by the SPYBOT-EE WORM! |
| X | Winsock2 driver | SYSTEM32.EXE | Added by the SPYBOT-EG WORM! |
| X | Winsock2 driver | dllcfg32.exe | Added by the SPYBOT.AG WORM! |
| X | Winsock2 driver | CFTMON.EXE | Added by a variant of the IRCBOT BACKDOOR! |
| X | Winsock2 driver | ntsys32.exe | Added by the SPYBOT-DD WORM! |
| X | Winsock2 driver | WINNT32.EXE | Added by the SPYBOT-CN WORM! |
| X | Winsock2 driver | PAC.EXE | Added by the SPYBOT-ET WORM! |
| X | Winsock2 driver | winsock2.exe | Added by the SPYBOT-CT BACKDOOR! |
| X | Winsock2 driver | mmtask5.exe | Added by the SPYBOT-CD WORM! |
| X | Winsock2 driver | WWEUMQR.EXE | Added by the SPYBOT-BY WORM! |
| X | Winsock2 driver | IEXPLORE .EXE | Added by the SPYBOT-AU WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the ".exe" |
| X | Winsock2 driver | WINSOUND.EXE | Added by the SPYBOT-H WORM! |
| X | Winsock2 driver | CSRSC.EXE | Added by the SPYBOT-CF WORM! |
| X | Winsock2 Loader | WICONF.EXE | Added by the SDBOT-LA WORM! |
| X | Winsock2 wqr1s | WUAUMQR1.EXE | Added by the SPYBOT.KD WORM! |
| X | Winsock2.dll | WINLODR.SCR | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Winsock32 driver | TESTING.EXE | Added by the SPYBOT-B WORM! |
| X | Winsock32 driver | system32.exe | Added by the IRCBOT-VT TROJAN! |
| X | Winsock32driver | win32server.scr | Added by the HACARMY TROJAN! |
| X | Winsock32driver | sp2XPupdate.exe | Added by the HACKARMY.S BACKDOOR! |
| X | Winsock32driver | win32server.exe | Added by the BACKDOOR-AZV TROJAN! |
| X | Winsock32driver | ZoneAlarmPr0.exe | Added by the HACKARMY-B TROJAN! |
| X | Winsock32driver | ZoneLockup.exe | Added by the HACARMY.D TROJAN! |
| X | Winsock32driver | win32server.exe | Added by the HACARMY.F TROJAN! |
| X | Winsock32driver | winXPupdate.exe | Added by the HACKARMY.9728 TROJAN! |
| X | Winsock32driver | svchhost.exe | Added by the HACKARMY.I BACKDOOR! |
| X | Winsock32driver | svshost.exe | Added by the HACKARMY.I BACKDOOR! |
| X | Winsock6 MIC driver | ieservicesupd.exe | Added by the SPYBOT.AFZ WORM! |
| X | winsockdriver | tskmg.exe | Added by the WARPIGS.C WORM! |
| X | winsockdriver | winsock2.2.exe | Added by a variant of the SPYBOT WORM! |
| X | winsockdriver | iexplor.exe | Added by the BLATIC.A WORM! |
| X | winsockdriver | winsock3.exe | Added by the SPYBOT-DO WORM! |
| X | winsockdriver | bot.exe | Added by the WARPIGS-D WORM! |
| X | winsockdriver | winsock4.1.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | winsockdriver | winsock2.exe | Added by the SPYBOT-AC WORM! |
| X | WinSocketComponent | nthost.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | winsocks | msnmess.exe | Added by the PWS-ABU TROJAN! |
| X | Winsocks2 driver | mznmgr.exe | Added by a variant of the SDBOT WORM! |
| U | WINSOS VERIFY | WINSOS.EXE | WinSOS - "deletes spyware, optimizes your computer - backs up selected data" |
| X | WinSP | [path] REGEDIT.EXE -s [path] sysreg.reg | Added by the STARTPA-ME TROJAN! |
| X | WINSP00L | WINSP00L.EXE | Added by the AGENT.XAB TROJAN! Notice the digit "0" in both columns rather than the upper case "o" |
| X | winsp1up.exe | winsp1up.exe | HDD Defragmenter rogue system utility - not recommended, removal instructions here |
| X | winsp2up.exe | winsp2up.exe | Smart Defragmenter rogue system utility - not recommended, removal instructions here |
| X | winspd32dll | winspd32.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | WinSPF | windrv32.exe | Added by the MYDOOM.T WORM! |
| X | WinSPF | winspf32.exe | Added by the MYDOOM.S WORM! |
| X | Winspl | winsplx.exe | Added by a variant of the TROLL-A TROJAN! |
| X | winsplog | wsmmlog.exe | Added by the MAILBOT-CA TROJAN! |
| X | Winspool | spoolsvr.exe | Added by a variant of the SDBOT WORM! |
| X | WinSpyControl | pgs.exe | WinSpyControl rogue security software - not recommended. A member of the AVSystemCare family |
| X | WinSpyDemo | WinSpyDemo.exe | WinSpy rogue spyware remover - not recommended |
| X | WinSpyKiller | WinSpyKiller.exe | WinSpyKiller rogue spyware remover - not recommended, removal instructions here |
| X | WinSpywareProtect | WinSpywareProtect.exe | WinSpywareProtect rogue security software - not recommended, removal instructions here |
| X | WinSpywareProtect (ver. 5.1) | WinSpywareProtect.exe | WinSpywareProtect rogue security software - not recommended, removal instructions here |
| X | WinSrv | kn0x.exe | Added by the HOBBIT.F WORM! |
| X | WinSrv | SHIZZLE.EXE | Added by the HOBBIT.C WORM! |
| X | Winsrv | winsrv.exe | Added by the OPASERV.T WORM! |
| X | winsrv | winsrv.exe | Added by the NETSNAK-B TROJAN! |
| X | winsrv3 | services.exe | Added by the NAFBOT-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| Y | winssnotify | winssnotify.exe | System Tray access to and notifications from Windows Live OneCare - now superseded by Microsoft Security Essentials. "OneCare helps keep your PC safe and secure while making your life easier. From virus scanning and file backups, to automatic printer sharing of all the PCs in your household, OneCare helps manage all of this. Delivered to you in a smooth, hassle-free package" |
| X | WinsSystem | [path to backdoor] | Added by the DELF.IG BACKDOOR! The most common filename seen is "syssmss.exe" located in %ProgramFiles%\Internet Explorer |