| Status | Autorun name | Command | Description |
| U | Winacsr | Winacsr.exe | AceScreenSpy keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | winactive | winactive.exe | WinActive variant of the LOP.com hijacker |
| X | WinActiveJ | WinActiveJ.exe | Added by the ROTARRAN VIRUS! |
| X | Winad Client | Winad.exe | WinAd adware |
| X | WinAdCnt.exe | WinAdCnt.exe | Added by the BANKER-BU TROJAN! |
| X | winadm | winadm.exe | Browser hijacker - redirecting to Search-World.net. Related to the SMALL.AEX TROJAN! |
| ? | WinAgent | WinAgent.exe | Standard Life Insurance program. Is it required at startup? |
| X | Winahlp.exe | Winahlp.exe | Added by a variant of the VAGRNOCKER TROJAN! |
| X | winallap | winallap.exe | Added by the DELF.E TROJAN! |
| X | winallapu | winallapu.exe | Added by the DELF.E TROJAN! |
| X | Winammp | mccm.exe | Added by the IRCBOT-HH BACKDOOR! |
| X | Winamp | winamp.hta | Hijacker - re-directing to adult content sites. Note - this isn't the real Winamp |
| X | Winamp | winamp.exe | Added by the AGOBOT.XI WORM! Note - this is NOT the popular Winamp media player which is located in %ProgramFiles%\Winamp |
| X | WinAMP | winamp62.exe | Added by the SDBOT-WN WORM! |
| N | Winamp | winamp.exe | Winamp media player. Located in a %ProgramFiles%\Winamp |
| X | Winamp Agent | winamp.exe | Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player. The valid filename for the Winamp Agent is "winampa.exe" - see here |
| X | Winamp Agent | cvscc.exe | Added by the AGOBOT-GK WORM! |
| U | Winamp Agent | winampa.exe | Loads the optional System Tray icon and maintains file associations for the popular Winamp media player. If disabled, other media players like iTunes, QuickTime and RealPlayer could become the default player for various file types when you double-click on them in My Computer or Windows Explorer |
| X | Winamp Media | qmedia.exe | Added by the DIAZMON-A TROJAN! |
| X | Winamp media player | winapa.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Winamp Media Player | winamap.exe | Added by the SDBOT.ACJM BACKDOOR! |
| X | Winamp Media Player | winamp.exe | Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is NOT the popular Winamp media player which is located in %ProgramFiles%\Winamp. This one is located in %Windir% |
| X | WinAmp Player | winampp.exe | Added by the RBOT-AQI WORM! Note - this is NOT the popular Winamp media player which has a different filename |
| X | Winamp Player 6 | Winamp6.exe | Added by a variant of the SPYBOT WORM! |
| U | Winamp to Google Talk | winamptogoogletalk.exe | Winamp to Google Talk, available here shows your current Winamp track in your Google Talk status |
| X | Winamp Update | yhn.exe | Added by the SDBOT-ACR WORM! |
| U | winampa | winampa.exe | Loads the optional System Tray icon and maintains file associations for the popular Winamp media player. If disabled, other media players like iTunes, QuickTime and RealPlayer could become the default player for various file types when you double-click on them in My Computer or Windows Explorer |
| X | Winampa | winampa.exe | Added by the AGOBOT-GS TROJAN! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of %ProgramFiles% whereas this file is located in %System% |
| X | Winampa Agent | WINAMPA.EXE | Added by the SPYBOT-BR WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of %ProgramFiles% whereas this file is located in %System% |
| X | winampa.exe | winampa.exe | Added by the PINCAV.PRC TROJAN! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of %ProgramFiles% whereas this file is located in %Windir% |
| U | winampa.exe | winampa.exe | Loads the optional System Tray icon and maintains file associations for the popular Winamp media player. If disabled, other media players like iTunes, QuickTime and RealPlayer could become the default player for various file types when you double-click on them in My Computer or Windows Explorer. This is the Windows Defender entry for earlier versions |
| U | WinampAgent | winampa.exe | Loads the optional System Tray icon and maintains file associations for the popular Winamp media player. If disabled, other media players like iTunes, QuickTime and RealPlayer could become the default player for various file types when you double-click on them in My Computer or Windows Explorer |
| X | WinAmpAgent | Msexploren.exe | Added by the BDOOR-EB BACKDOOR! Note - this is NOT the popular Winamp media player which has a different filename |
| X | WinAmpAgent | Shch.exe | Added by the BDOOR-EB BACKDOOR! Note - this is NOT the popular Winamp media player which has a different filename |
| X | WinAmpAgent | svchst.exe | Added by the BDOOR-EB BACKDOOR! Note - this is NOT the popular Winamp media player which has a different filename |
| X | WinAmpAgent | Winagent.exe | Added by the BDOOR-EB BACKDOOR! Note - this is NOT the popular Winamp media player which has a different filename |
| X | WinAmpAgent | msnexploren.exe | Added by the TACTSLAY.B TROJAN! |
| X | WinAmpAgent | sdhch.exe | Added by the TACTSLAY.B TROJAN! |
| X | WinampPlugin | winampa.exe | Added by the SDBOT-CNF WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of %ProgramFiles% whereas this file is located in %System% |
| X | WinAnonymous | GDC.exe | WinAnonymous rogue privacy tool - not recommended, removal instructions here. A member of the PCPrivacyTool family |
| X | WinAntiSpyware 2005 | was5.exe | WinAntiSpyware 2005 rogue spyware remover - not recommended, removal instructions here |
| X | WinAntiSpyware 2006 | was6.exe | WinAntiSpyware 2006 rogue spyware remover - not recommended, removal instructions here |
| X | WinAntiSpyware 2006 Free | was6.exe | WinAntiSpyware 2006 rogue spyware remover - not recommended, removal instructions here |
| X | WinAntiSpyware 2006 Scanner | was6.exe | WinAntiSpyware 2006 rogue spyware remover - not recommended, removal instructions here |
| X | WinAntiSpyware 2007 | was7.exe | WinAntiSpyware 2007 rogue spyware remover - not recommended |
| X | WinAntiSpyware 2007 Free | was7.exe | WinAntiSpyware 2007 rogue spyware remover - not recommended |
| X | WinAntispyware2008 | WinAntispyware2008.exe | WinAntiSpyware 2008 rogue spyware remover - not recommended, removal instructions here |
| X | WinAntivirus | AVSVC.EXE | Part of the WinAntiVirus Pro 2005 rogue security software when installed in Win98/Me - not recommended, removal instructions here |
| X | WinAntiVirus Pro 2007 | WinAv.exe | WinAntiVirus Pro 2007 rogue security software - not recommended, removal instructions here |
| X | WinAntivirusPro | WinAntivirusPro.exe | WinAntivirusPro rogue security software - not recommended, removal instructions here |
| X | WinAntivirusPro | WinAntiVirusPROSetup.exe | WinAntivirusPro rogue security software - not recommended, removal instructions here |
| X | WinAntiVirusPro2006 | WinAV.exe | WinAntiVirus Pro 2006 rogue security software - not recommended, removal instructions here |
| X | WinApi | winapix.exe | Added by a variant of the TIBSER.A downloader TROJAN! |
| X | WINAPLOGUPD | WINAPLOGUPD.EXE | Added by the CAPSIDE-C WORM! |
| X | Winapp | winpup32.exe | Produces popup ads to adult content sites |
| X | WinApp32 | msapp.exe | Added by the RSBOT TROJAN! |
| U | WinAppLog | svchost.exe | StingKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | WinAuth | winlogon.exe | Added by the STRTPAGE.BE TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | WinAvX | WinAvX.exe | Added by the VIRANTIX TROJAN! |
| X | WinAvX | WinAvXX.exe | Malware installed by different rogue security software including SpyKillerPro. Also detected as the SPYWAD-AR TROJAN! |
| X | WinAwk | WinAwk.exe | Added by the SDBOT-AYF WORM! |
| U | WinBackup 2.0 | wbtray.exe | System Tray access to and backup status monitor for the WinBackup 2.0 backup utility from Uniblue Systems Limited - now discontinued |
| U | WinBackup Scheduler | Wbsched.exe | Scheduler for the WinBackup backup utility from LI Utilities (now Uniblue Systems Limited) - now discontinued. Required if you have regularly scheduled backup jobs |
| U | WinBar | WinBar.exe | "WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls" |
| X | winbar.pif | packe.pif | Added by the RBOT-AVI WORM! |
| X | Winbed | winbed.exe | Hijacker |
| X | Winbin | swchost.exe | Added by the RBOT.CLS WORM! |
| X | winbin32 | win32exe.exe | Added by the RBOT-ZL WORM! |
| X | WinBlueSoft | WinBlueSoft.exe | WinBlueSoft rogue spyware remover - not recommended, removal instructions here |
| X | winbo32 | winbo32.exe | Added by the RBOT-GRU WORM! |
| X | winboot | winboot.exe | Added by the BANLOAD-W TROJAN! |
| X | winbot | winbot.exe | Added by the MIDRUG-A TROJAN! |
| U | WinBrush | winbrush.exe | WinBrush - "handy tool that keep your privacy and make your system clean. It works by cleaning up your tracks (document histories, recent opened files from popular software, cookies, temporary internet files, etc)" |
| X | WinButler | WinButler.exe | Identified as a variant of the Trojan-Dropper.Agent.DKN malware |
| X | wincfg | syscnfg.exe | Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in %Windir%\fonts\font2 where no *.exe files should reside |
| X | WINCHAT | WINCHAT.EXE | Added by the SPECFIX BACKDOOR! |
| X | WinCheck | WinCheck.exe | Added by the PWS-CY TROJAN! |
| X | WinCheck | services.exe | Added by the SOBER.S WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft |
| X | WinCheck | check.exe | Added by the DELBOT-Y WORM! |
| U | winchk | winchk.exe | RemoteSpy surveillance software. Uninstall this software unless you put it there yourself |
| X | winchost | winchost.exe | Added by the DLOADER-PO TROJAN! |
| N | WinCinema Manager | WinCinemaMgr.exe | WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start → Programs |
| N | WINCINEMAMGR | WINCIN~1.EXE | WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
| N | WinCinemaMgr | WinCinemaMgr.exe | WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
| U | WINCINEMAMGR | WinRemote.exe | InterVideo WinCinema Manager - needed for the use of WinDVD Remote Control |
| X | winclean | winclean.exe | Added by the AGENT.GXR TROJAN! |
| X | wincls | rundll32.exe wincls.dll,start | Added by the AKBOT-AR WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wincls.dll" file is found in %System% |
| X | wincmap | wincmapp.exe | CasClient adware variant - also detected as the CMAPP TROJAN! |
| U | WinColorReminder | WinColorReminder.exe | The Microsoft Color Control Panel Applet for Windows XP "helps you manage Windows color settings in one place." Part of the Pro Imaging Powertoys |
| X | wincom | vbrun6win.exe | Added by the AGOBOT-AFK WORM! |
| X | winconfig | wscript winconfig.js | Added by the CHAFPIN TROJAN! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "winconfig.js" file is found in %Temp% |
| X | winconfig | wscript.exe winconfig.js | Added by the CHAFPIN TROJAN! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "winconfig.js" file is located in %Temp% |
| X | WinConfig9324 | wincfgkop9.exe | Added by the RBOT.BVD WORM! |
| X | winconn | vbrun6nt.exe | Added by the AGOBOT-AEI BACKDOOR! |
| X | WinCore32.exe | WinCore32.exe | Added by the CLICKER-EN TROJAN! |
| X | wincrt.exe | [path to worm] | Added by the STRATIO-HA WORM! |
| X | WinCRT32 | wincrt32.exe | Added by the DOGBOT-D WORM! |
| X | WinCSRSS | MSGRT32.EXE | Added by the REWINDO-A TROJAN! |
| X | winctl | winctl.exe | Added by the IRCBOT-YI TROJAN! |
| X | WINCX | wincore332.exe | Added by the AGOBOT-MG WORM! |