| Status | Autorun name | Command | Description |
| X | [empty] | dllvirtual.exe | Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field |
| X | [empty] | dllvirtual.dll | Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field |
| X | [empty] | dllvirtual.js | Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field |
| X | [empty] | ne.exe | Added by the IRCBOT-ZL TROJAN! Note - has a blank entry under the Startup Item/Name field |
| X | [empty] | iexpl0re.exe | Added by the RBOT-SD WORM! Note - has a blank entry under the Startup Item/Name field |
| X | [Entry name] | System.exe | Added by the NETHIEF-N TROJAN! |
| X | [Ephemeral 2.4] by TreeHugger, | [path to worm] | Added by the LEMOOR-A WORM! |
| X | [Ephemeral 2.5] by TreeHugger, | [path to worm] | Added by the LEMOOR-C WORM! |
| X | [Ephemeral 2.x] by TreeHugger, | [path to worm] | Added by the LEMOOR.A WORM! where "x" represents 3 or 4 |
| X | [executed file name] | App.exe | Added by the WAXPOW WORM! |
| X | [executed file name] | Regsrv32.com | Added by the SOUTHGHOST WORM! |
| X | [filename] | svchost.scr | Added by the BANKER-CC TROJAN! |
| X | [number of current month] | [number of current month].exe hlmrun | Added by the AUTORUN-UN WORM! |
| X | [number of current year] | [number of current year].exe hcurun | Added by the AUTORUN-UN WORM! |
| X | [original filename] | svchost.scr | Added by the BANCBAN-CX TROJAN! |
| X | [original filename] | xphost.scr | Added by the BANCBAN-HM TROJAN! |
| X | [random characters] | rsbmsc.exe | Detected by AntiVir antivirus as the BDS/Agent.adt TROJAN! |
| X | [random characters] | _default[random].pif | Added by the BRONTOK-AI WORM and variants! |
| X | [random characters] | j[random].exe | Added by the BRONTOK-AI WORM and variants! |
| X | [random characters] | sv[random].exe | Added by the BRONTOK-AI WORM and variants! |
| X | [random characters] | yesbron.com | Added by the BRONTOK-AI WORM and variants! |
| X | [random characters] | systs.exe | Added by the AGENT-GDC TROJAN! |
| X | [random characters] | xvassdf.exe | Added by the AUTORUN-BAD WORM! |
| X | [random characters] | securewinload32x.exe | Added by the OPTIXP-N TROJAN! |
| X | [random filename] | slk8x2peu.exe | QuickLinks adware |
| X | [random hex digits] | report.exe | Added by the TATANARG TROJAN! |
| X | [random name] | ver.exe | Added by the VERTEXBOT BACKDOOR! |
| X | [random name] | Sys32Disp.exe.exe | Added by the SKOPVEL.A WORM! The most common name seen appears to be "System Display" |
| X | [random name] | wincpu.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | [random name] | m?dtc.exe | PurityScan adware |
| X | [random name] | ping.exe | PurityScan adware. Note - do not confuse with the Microsoft utility of the same name as described here |
| X | [random name] | CXTPLS_LOADER.EXE | AproposMedia adware |
| X | [random name] | ??plorer.exe | PurityScan adware |
| X | [random name] | ?hkdsk.exe | PurityScan adware |
| X | [random name] | ?hkntfs.exe | PurityScan adware |
| X | [random name] | l?gonui.exe | PurityScan adware |
| X | [random name] | m?iexec.exe | PurityScan adware |
| X | [random name] | r?gsvr32.exe | PurityScan adware |
| X | [random name] | t?skmgr.exe | PurityScan adware |
| X | [random name] | w?auboot.exe | PurityScan adware |
| X | [random name] | w?auclt.exe | PurityScan adware |
| X | [random name] | w?crtupd.exe | PurityScan adware |
| X | [random name] | w?wexec.exe | PurityScan adware |
| X | [random name] | ??erinit.exe | PurityScan adware |
| X | [random name] | d?dplay.exe | PurityScan adware |
| X | [random name] | n?tepad.exe | PurityScan adware |
| X | [random name] | ??chost.exe | PurityScan adware |
| X | [random name] | ??oolsv.exe | PurityScan adware |
| X | [random name] | ??xplore.exe | PurityScan adware |
| X | [random name] | r?ndll32.exe | PurityScan adware |
| X | [random name] | se?vices.exe | PurityScan adware |
| X | [random name] | w?nlogon.exe | PurityScan adware |
| X | [random name] | w?nword.exe | PurityScan adware |
| X | [random name] | ??anregw.exe | PurityScan adware |
| X | [random name] | ?ttrib.exe | PurityScan adware |
| X | [random name] | j?vaw.exe | PurityScan adware |
| X | [random name] | l?ass.exe | PurityScan adware |
| X | [random name] | m?config.exe | PurityScan adware |
| X | [random name] | n?lookup.exe | PurityScan adware |
| X | [random name] | n?pdb.exe | PurityScan adware |
| X | [random name] | ??ool32.exe | PurityScan adware |
| X | [random name] | ??rss.exe | PurityScan adware |
| X | [random name] | ??rvices.exe | PurityScan adware |
| X | [random name] | ?ti2evxx.exe | PurityScan adware |
| X | [random name] | d?xplore.exe | PurityScan adware |
| X | [random name] | chkdsk.exe | PurityScan adware. Note - the legitimate Windows chkdsk.exe will always be located in %System% and will NOT figure among the startups! |
| X | [random name] | dvdplay.exe | PurityScan adware |
| X | [random name] | spoolsv.exe | PurityScan adware. Note - this is not the legitimate spoolsv.exe which is always located in %System% |
| X | [random name] | w?aclt.exe | PurityScan adware |
| X | [random name] | wucrtupd.exe | PurityScan adware. Do not confuse with the legitimate Windows Critical Update Notification (wucrtupd.exe) process |
| X | [random name] | charmapnt.exe | Added by the BANCOS-DR TROJAN! |
| X | [random name] | n?tdde.exe | PurityScan adware |
| X | [random name] | r?gedit.exe | PurityScan adware |
| X | [random name] | r?ndll.exe | PurityScan adware |
| X | [random name] | scanregw.exe | PurityScan adware. Note - do not confuse this with the legitimate Windows process scanregw.exe which is always found in the Windows folder on Win9x/ME machines |
| X | [random name] | wuauboot.exe | PurityScan adware. Note - do not confuse with the legitimate wuauboot.exe process which should not figure in Msconfig/Startup! |
| X | [random name] | w?nspool.exe | PurityScan adware |
| X | [random name] | svchost.exe | Added by the BANCBAN-JC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\config |
| X | [random name] | [random name].dll | SearchNet adware |
| X | [random name] | iexpl0ra.exe | Added by the ULPM.BD TROJAN! |
| X | [random name] | rundl13a.exe | Added by the GAMPASS-L TROJAN! |
| X | [random name] | Servere.exe | Added by the LEGMIR-AQM TROJAN! |
| X | [random name] | explore3.exe | Added by the DELF.FAN TROJAN! |
| X | [random name] | taskmngr.exe | Added by the AGOBOT-CB WORM! |
| X | [random name] | netdde.exe | PurityScan adware. Do not confuse with the legitimate Network DDE - DDE Communication (netdde.exe) process which is always located in %System% and should not figure in Msconfig/Startup! |
| X | [random name] | chkntfs.exe | PurityScan adware. Do not confuse with the legitimate NTFS Volume Maitenance Utility (chkntfs.exe) process which is always located in %System% and should not figure in Msconfig/Startup! |
| X | [random name] | notepad.exe | PurityScan adware. Note - this is not Windows Notepad which has the same executable name |
| X | [random name] | services.exe | PurityScan adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
| X | [random name] | ntvdm.exe | PurityScan adware. Do not confuse with the legitimate ntvdm.exe process which is always located in %System% and should not figure in Msconfig/Startup! |
| X | [random name] | msiexec.exe | PurityScan adware. Do not confuse with the legitimate Windows® Installer (msiexec.exe) process which is always located in %System% and should not figure in Msconfig/Startup! |
| X | [random name] | userinit.exe | PurityScan adware. Do not confuse with the legitimate Userinit Logon Application (userinit.exe) process which is always located in %System% and should not figure in Msconfig/Startup! |
| X | [random name] | regedit.exe | PurityScan adware. Note - this is not the valid Windows registry editor which resides in %Windir% and will not figure in Msconfig/Startup! |
| X | [random name] | wuauclt.exe | PurityScan adware. Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup! |
| X | [random name] | ?ervices.exe | PurityScan adware |
| X | [random name] | s?chost.exe | PurityScan adware |
| X | [random name] | c?rss.exe | PurityScan adware |
| X | [random name] | mrgdll.exe | Nortel Antivirus rogue security software - not recommended |
| X | [random name] | wox.exe | Nortel Antivirus rogue security software - not recommended |
| X | [random name] | dropped.exe | Added by the VERTEXBOT BACKDOOR! |
| X | [random names] | eee2.exe | MediaMotor adware |