| Status | Autorun name | Command | Description |
| X | WSAConfiguration | drrss.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | WSAConfiguration | winlogon32.exe | Added by the AGOBOT-WC WORM! |
| X | WSAConfiguration | ntguard32.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | WSAConfiguration | csrsvcs.exe | Added by the AGOBOT.VI WORM! |
| X | WSAConfiguration | winmx32.exe | Added by the AGOBOT-JE WORM! |
| X | WSAConfiguration | kernel32.exe | Added by the AGOBOT-KV WORM! |
| X | WSAConfiguration | winmon32.exe | Added by the AGOBOT.TM WORM! |
| X | WSAConfiguration | msnote30.exe | Added by the AGOBOT-KF BACKDOOR! |
| X | WSAConfiguration | syxtem32.exe | Added by the AGOBOT-MF BACKDOOR! |
| X | WSAConfiguration | svchostx.exe | Added by the AGOBOT-JV BACKDOOR! |
| X | WSAConfiguration1 | csass.exe | Added by the AGOBOT.WH WORM! |
| X | wsass32 | wsass32.exe | Added by the BANKEM-V TROJAN! |
| ? | wsbklite | wsbklite.exe | Related to the Acer Soft Button on Acer Tablet PCs. Appears to do nothing so is it required? |
| X | wsc | mstdl.exe | MaCatte Antivirus 2009 rogue security software - not recommended, removal instructions here |
| U | WScheduler | WScheduler.exe | Windows Scheduler - "schedule unattended running of applications, batch files, scripts and much more. Also, you can schedule popup reminders so you'll never forget reminders, tasks and other events." |
| X | wscmgr | wscmgr.exe | Added by the AUTORUN-AA WORM! |
| X | wscnfty | wscnfty.exe | Added by a variant of the RBOT WORM! |
| X | wscntfx | [path to trojan] | Added by the BANZ.CRI TROJAN! |
| X | wscntfy | wscntfy.exe | Added by the VBSP-A WORM! Note - this is not the legitimate Windows Security (wscntfy.exe) file which is located in %System%. This one is located in %Windir% |
| X | wscntfys | wsscntfy.exe | Added by the SDBOT-TN WORM! |
| X | WSConfiguration | spoolsc.exe | Added by the AGOBOT-HY WORM! |
| X | wscript.exe | vabian.vbs | Added by the VABI VIRUS! |
| X | wscsvc.exe | wscsvc.exe | Added by a password stealing BANKER TROJAN! |
| X | wscsvc32.exe | wscsvc32.exe | Antivirus rogue security software - not recommended, removal instructions here |
| X | wsctf.exe | wsctf.exe | Added by the JAMPORK.E WORM! |
| X | Wsdata service | WSconf.exe | Added by the SDBOT.ZU WORM! |
| X | Wsecurity | ldanw32.exe | Added by the AGENT-BUC TROJAN! |
| U | WSEP Status+Configuration | controldGUI.exe | User interface for the WatchGuard Security Event Processor (WSEP) Status/Configuration dialog box associated with the Firebox series of security products from Watchguard |
| X | wserv | wserv.exe | Added by a variant of the SDBOT WORM! |
| X | wserver | wserver.exe | Added by the NETSKY.AC or SASSER.G WORMS! |
| U | WService | WService.exe | Tablet client Driver for UC-Logic Pen/Graphics Tablet |
| U | wsg32 | wsg32.exe | GoldenKeylog keystroke logger/monitoring program - remove unless you installed it yourself! |
| U | wskrnl | wskrnl.exe | ActMon surveillance software. Uninstall this software unless you put it there yourself |
| X | wsock32 | svchost.exe | Added by the HORST-A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | WSock32 Protocol | wsock32p.exe | Added by the SDBOT.M BACKDOOR! |
| X | WSockDrv32 | WSockDrv32.exe | Added by the WINKO.AO WORM! |
| U | Wspn | wspn.exe | Espion surveillance software. Uninstall this software unless you put it there yourself |
| X | wsrv32 | wsrv32.exe | Detected by Kaspersky as the AGENT.EP TROJAN! |
| X | WSSAConfiguration | wmmon32.exe | Added by the AGOBOT-KC WORM! |
| X | WSSVC | smsc.exe | Added by the AUTORUN-AGA WORM! |
| U | wssys | wssys.exe | WebPI logs keystrokes and captures screenshots. If you didn't install this yourself remove it |
| X | Wstat32 driver | Wstat32.exe | Added by the LOONBOT TROJAN! |
| Y | wstimeb | wstimeb.exe | Used with NEC printers. You can disable it before printing but it re-loads itself when printing so you may as well leave it |
| X | wsttrs | wsttrs.exe | Added by the LDPINCH-QS TROJAN! |
| X | wsvbs | wsvbs.exe | Added by the PWS-AEB TROJAN! |
| X | WSVCHO | svhost.exe | Added by the SPYBOT-OQ WORM! |
| U | WSVCS | SERVICES.EXE | WSLogger keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a WALI\SVCS sub-directory |
| Y | wswpd | wswpd.exe | Used with some models of Panasonic, Epson and NEC printers. Some older drivers known to have a "memory leak". Needed for printing to work |
| U | wsys.exe | wsys.exe | SpyloPCMonitor - surveillance software. Uninstall this software unless you put it there yourself |
| N | WT Game Channel | GameChannel.exe | WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| N | WT Game Channel | wtgamechannel.exe | WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| N | WT GameChannel | GameChannel.exe | WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| N | WT GameChannel | wtgamechannel.exe | WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| X | WTF Test | wtftest.exe | Added by the RBOT-ACM WORM! |
| U | WTIndicator | SchedInd.exe | WinTask - software that automates a variety of routine tasks quickly and simply |
| X | WTSC | wapisvcc.exe | PurityScan adware |
| X | WTSI | wapisvit.exe | PurityScan adware |
| X | WTSS | wapi**.exe [* = random char] | PurityScan adware |
| X | WTST | wapisvtr.exe | PurityScan adware |
| X | wtzlank.dll | rundll32.exe wtzlank.dll,qttwuwc | DisableKey adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wtzlank.dll" file is found in %System% |
| Y | WU713STA.EXE | WU713STA.EXE | Blitzz Technology wireless NIC adapter driver |
| X | wuanguard | wuanguard32.exe | Added by the RBOT-AAF WORM! |
| X | wuaucldt | wuaucldt.exe | Added by the MDROP-CUS TROJAN! |
| X | wuauclt | wuauclt.exe | Added by the DWNLDR-ITZ TROJAN! Note - this is not the legitimate wuauclt.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft\wuauclt |
| X | WudfSvc | WudfSvc.exe | Added by the SHEUR.BBB TROJAN! |
| Y | WUOLService | WUOLService9x.exe | Remote wakeup status agent. Part of Novell's ZenWorks. Processes Wake-up on LAN requests (turn on a computer remotely on LAN) |
| X | wuosdial | wuosdial.exe | Added by a variant of the RBOT WORM! |
| X | WUPD | iglmtray.exe | Added by the TZET WORM! |
| X | wupd | symcsvc.exe | Added by the ABWIZ.C TROJAN! |
| X | wupd | win32.exe | Added by the ORSE-C TROJAN! |
| X | wupd32 | wupd.exe | Added by the STRATION.EL WORM! |
| X | wupdate | wisvccz.exe | Added by the ORSE-B TROJAN! |
| X | wupdate | wi32.exe | Detected by Panda as Trustbid spyware |
| X | WUpdate | 1037v.exe | Added by the CLAGGER-AR TROJAN! |
| X | wupdate | bro_exe.exe | Added by the DELF.GR TROJAN! |
| X | Wupdate driver | [various filenames] | Added by a variant of the SPYBOT WORM! |
| X | Wupdate driver | wupdadte.exe | Added by the SPYBOT-CQ WORM! |
| X | WUpdates | WUpdates.exe | Added by the SWEPDAT TROJAN! |
| X | Wupdm32 | Wupdm32.exe | Added by the MIDLAK WORM! |
| X | wupdmgr32.exe | wupdmgr32.exe | Added by the CERTIF-I TROJAN! |
| X | wupdt | wupdt.exe | Added by the IMISERV.A TROJAN! |
| X | Wupftp | wupftp.exe | Added by the AGOBOT.AKV WORM! |
| X | wupipenimi | Rundll32.exe jinorije.dll,s | Added by the VUNDO.JD.DLL TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "jinorije.dll" file is found in %System% |
| X | wupipenimi | Rundll32.exe luyenofe.dll,s | Added by the VUNDO.JD.DLL TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "luyenofe.dll" file is found in %System% |
| X | wupipenimi | Rundll32.exe poyimimu.dll,s | Added by the VUNDO.JD.DLL TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "poyimimu.dll" file is found in %System% |
| X | wupipenimi | Rundll32.exe siremase.dll,s | Added by the VUNDO.JD.DLL TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "siremase.dll" file is found in %System% |
| X | wupipenimi | Rundll32.exe tamuyiko.dll,s | Added by an unidentified VIRUS, WORM or TROJAN! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tamuyiko.dll" file is found in %System% |
| X | wupipenimi | Rundll32.exe fumitoga.dll,s | Added by the MONDER.BZEA TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "fumitoga.dll" file is found in %System% |
| X | wupipenimi | Rundll32.exe hupojoyu.dll,s | Added by the MONDER.BZEA TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "hupojoyu.dll" file is found in %System% |
| X | wupipenimi | Rundll32.exe tuduriro.dll,s | Added by the MONDER.BZEA TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tuduriro.dll" file is found in %System% |
| X | wupipenimi | Rundll32.exe vafefudo.dll,s | Added by the MONDER.BZEA TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "vafefudo.dll" file is found in %System% |
| X | wupipenimi | Rundll32.exe yidurufo.dll,s | Added by the VUNDO.HTI TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "yidurufo.dll" file is found in %System% |
| Y | WUSB11B.exe | WUSB11B.exe | Linksys WUSB11 WLAN USB adapter |
| Y | WUSB54GS | InvokeSvc3.exe | Wireless-G USB Wireless Network Adapter related - would appear to be required |
| Y | WUSB54Gv2 | InvokeSvc3.exe | Wireless-G USB Wireless Network Adapter related - would appear to be required |
| Y | WUSB54Gv4 | WUSB54Gv4.exe | Wireless-G USB Wireless Network Adapter related - would appear to be required |
| X | wuviewer | wuviewer.exe | Added by the PROXY.AN TROJAN! |
| X | wuweb | wuweb.exe | Added by the WUWO TROJAN! |
| ? | WUx_RegSvr | RegSvr32.exe | x is any number?? |
| X | WWKS | wsass.exe | Added by the SDBOT-BT WORM! |