| Status | Autorun name | Command | Description |
| N | Windows Desktop Search | WindowsSearch.exe | System Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. On earlier versions this entry also runs the indexing function at startup which indexes files and e-mails items so you can quickly find words and phrases (replaced by a service in later versions). Disabling this entry does not affect the normal operation and indexing will occur when you next perform a search |
| X | Windows Dialup Service | dialup.exe | Added by the AGOBOT.AAH WORM! |
| X | Windows Disk Defragmenter | wpabaln32.exe | Added by the BANCOS-ASJ TROJAN! |
| X | Windows Disk Manager | cmnvc.exe | Added by a variant of the IRCBOT TROJAN! |
| X | Windows Display Coupler | display.exe | Added by the IRCBOT-YS TROJAN! |
| X | Windows DLL host | winupd32.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows DLL Host | dllhost32.exe | Added by an unidentified WORM or TROJAN! |
| X | Windows DLL Loader | rundll32.exe | Added by the WHIPSER-B WORM! Note - this is not the legitimate rundll32.exe process |
| X | Windows DLL Loader | defragfat32pi.exe | Added by the RBOT-QQ WORM! |
| X | Windows DLL Loader | defragfat39.exe | Added by the POEBOT-C WORM! |
| X | Windows DLL Loader | defragfatz.exe | Added by the LINKBOT.H WORM! |
| X | Windows DLL Loader | defragfat32.exe | Added by the SDBOT-SS WORM! |
| X | Windows DLL Loader | defragfat32abc.exe | Added by the RBOT-RG WORM! |
| X | Windows DLL Loader | wdevice.exe | Added by a variant of the SDBOT WORM! |
| X | Windows DLL Loader | SYSCFG16.EXE | Added by the DOMWIS-N WORM! |
| X | Windows DLL Loader | WINCFG32.EXE | Added by the AGOBOT-TE WORM! |
| X | Windows DLL Loader | defragfatx.exe | Added by the POEBOT-F WORM! |
| X | Windows DLL Loader | RUNDLL16.EXE | Added by the DOMWIS TROJAN! |
| X | Windows DLL Loader | defragfat32z.exe | Added by the LINKBOT.A WORM! |
| X | Windows DLL Services | winsvc32.exe | Added by the RBOT-ZF WORM! |
| X | Windows DLL Services | svchost.exe | AGENT.H spyware. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
| X | Windows DLL Services | system.exe | AGENT.H spyware |
| X | Windows DLL Tracker | spoolsrv.exe | Added by a variant of the WOOTBOT WORM! |
| X | Windows DLL Verifier | xptl.exe | Added by a variant of the RBOT WORM! |
| X | Windows DLL Verifier | windlls.exe | Added by the RBOT-AZQ WORM! |
| X | Windows DNS | windns.exe | Added by the SDBOT-XU WORM! |
| X | Windows DNS Daemon | windnsd.exe | Added by the WOOTBOT.AS WORM! |
| X | Windows Domain Name Drivers | windns.exe | Added by the FORBOT-EP WORM! |
| X | Windows DOS | dosw.exe | Added by the SALAY-A WORM! |
| X | Windows DotFix live | msdotfix.exe | Added by the IRCBOT.XGK BACKDOOR! |
| X | Windows Download Manager | windlmngr.exe | Added by an unidentified TROJAN! |
| X | Windows Drive Compatibility | System32Driver32.exe | Added by the SUPOVA.Z WORM! |
| X | Windows Driver | winxpdriver.exe | Added by the WOOTBOT.EE WORM! |
| X | Windows Driver | windrive.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Windows Driver Adapter | svchost.exe | Added by the ANTINNY-K WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "drivers" subfolder |
| X | Windows Driver Foundation | MTVSCMXT.EXE | Added by a variant of the RBOT WORM! |
| X | Windows Driver Services | msdrvs32.exe | Added by the WOOTBOT.L WORM! |
| X | Windows Driver Sup | windvrhost.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Windows driver update | dmsvc32.exe | Added by the SDBOT-GP BACKDOOR! |
| X | Windows driver update | Ipconfig32.exe | Added by the SDBOT-JV WORM! |
| X | Windows driver update | nmsmtp32.exe | Added by the SDBOT-JT WORM! |
| X | Windows Driver! | windriver.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Windows Drivers | ssms.exe | Added by the RBOT-AT WORM! |
| X | Windows drivers update | windowsupdate.exe | Added by the RBOT-ACE WORM! |
| X | Windows Dump Error | taskmgr.exe | Added by the PALEVO-X WORM! Note - this is not the legitimate taskmgr.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Windows Dynamic Library Cache | dllcache.exe | Added by the INJECT-HT TROJAN! |
| X | Windows Dynamic Loading Header | winDLL32.exe | Added by a variant of the SDBOT WORM! |
| X | Windows Email Server | wmserv.exe | Added by the FOUNDU-AWORM! |
| X | Windows Enterprise Defender | WindowsEDefender.exe | Windows Enterprise Defender rogue security software - not recommended, removal instructions here |
| X | Windows Enterprise Suite | WE[random characters].exe | Windows Enterprise Suite rogue security software - not recommended, removal instructions here |
| X | Windows Essensials | mvnesc.exe | Added by a variant of the IRCBOT TROJAN! |
| X | Windows Event Detection | wecsvc.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Event Provider | wposvc.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Event Section | sntsvc.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Event Service | winserv.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Windows Executable | winmys.exe | Added by the RBOT-ABO WORM! |
| X | Windows Executer | bling.exe | Added by the SDBOT-DFT WORM! |
| X | Windows Executer | svchostie.exe | Added by the EGGDROP.V BACKDOOR! |
| X | Windows ExpIorer | [random filename] | Added by the RBOT-AKO WORM! |
| X | Windows Explorer | [filename].exe | Added by the SDBOT TROJAN! |
| X | Windows Explorer | Lsas.exe | Added by the GAOBOT.AO WORM! |
| X | Windows Explorer | olecom32.exe | Added by an unidentified WORM or TROJAN! |
| X | Windows Explorer | EEXPLORER.EXE | Added by a variant of the SPYBOT WORM! |
| X | Windows Explorer | explorer.exe | Added by the POEBOT-J WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System% |
| X | Windows Explorer | explorer.pif | Added by the RBOT-AID WORM! |
| X | Windows Explorer | system32.exe | Added by the RBOT-AJH WORM! |
| X | Windows Explorer | explorer32.exe | Added by a variant of the SDBOT WORM! |
| X | Windows Explorer | Windows Explorer.EXE | Added by the VB-EBA WORM! |
| X | Windows Explorer | system.exe | Added by the STIRAUT WORM! |
| X | Windows Explorer Key | explorer.exe | Added by the IRCBOT-YB WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System% |
| X | Windows Explorer Services | exploresys.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Windows Explorer Shell | Winexec32.exe | Added by the REDIST.B WORM! |
| X | Windows Explorer SP2 | csrss.exe | Added by the BANKER-DM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "JavaBeans" subfolder |
| X | Windows Explorer Update Build 1142 | EXPLORER32.EXE | Added by the KaZaA based KWBOT or KWBOT.Y WORMS! |
| X | Windows Explorer-3212 | WINRE16.EXE | Added by the HARDOC WORM! |
| X | Windows Explorer.exe | Explorer.exe | Added by the FALTER-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System% |
| X | Windows Express | pci32b.exe | Added by the BUZUS.C TROJAN! |
| X | Windows Extensions for Win32 | winprgs32.exe | Added by the SDBOT.AFA WORM! |
| N | Windows Eyes | ?? | For blind people, gives a voice description of items on the screen. Windows application which gives you total control over what you hear, when you hear it, and how you hear it. Available via Start -> Programs |
| X | Windows FAT 32 | WINFAT32B.exe | Added by the SPYBOT-AGT WORM! |
| X | Windows File Migration Wizard | HIMENSYST.EXE | Added by the RBOT-EMO WORM! |
| X | Windows File Protection | winprotect.exe | Added by the AGOBOT.JB WORM! |
| X | Windows File System Frame | ntframe.exe | Added by an unidentified WORM or TROJAN! |
| X | Windows File Verification Service | wfvs.exe | Added by the RANKY.AC TROJAN! |
| X | Windows File XP Manager | wfdmgr.exe | Added by the SDBOT.XD TROJAN! |
| X | Windows FileSharing Service | mcwsvc.exe | Added by the IRCBOT.AJF BACKDOOR! |
| X | Windows Firevall Control C | rundll.exe | Added by the GAERTOB.A TROJAN! |
| X | Windows Firewal | Lsess.exe | Added by a variant of the RBOT WORM! |
| X | Windows Firewall | WindowsFirewall.exe | Added by the MYTOB.AO WORM! |
| X | Windows Firewall | svchost.exe | Added by the PROXY-HT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Windows Firewall | ipservice32.exe | Added by a variant of the RBOT WORM! |
| X | Windows Firewall | rundll32.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Windows Firewall | msmsd.exe | Added by the VB-OG MALWARE! |
| X | Windows Firewall Log | winlog.exe | Added by an unidentified WORM or TROJAN! |
| X | Windows Firewall Manager | msfw.exe | Added by the RBOT.WR WORM! |
| X | Windows firewall manager | chh.exe | Added by a variant of the RANDEX.GEL WORM! |
| X | Windows firewall manager | msguard.exe | Added by a variant of the RANDEX.GEL WORM! |
| X | Windows Firewall Service | wfsvc.exe | Added by the IRCBOT-YL WORM! |
| X | Windows Firewall Updater | updatees.exe | Added by the RBOT-GBX WORM! |
| X | Windows Firewall Updater | cronos.exe | Added by the RBOT-GBY WORM! |