| Status | Autorun name | Command | Description |
| X | Windows-TCP-IP | rfkampig.exe | Added by the GIPMA TROJAN! |
| X | Windows-Xdate | wuamclt32.exe | Added by the SPYBOT.AMUV WORM! |
| X | Windows-XP-Service-Pack | xpspz.exe | Added by the SDBOT-AAC WORM! |
| X | Windows_LowLevel_Security_Core | lsass.exe | Added by the PADMIN-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Repair |
| X | Windows_Protect | winsystem.exe | Added by a variant of the RBOT WORM! |
| X | Windows_Protect | winregal.exe | Added by a variant of the RBOT WORM! |
| X | Windows_Protect | lsas.exe | Added by the RBOT.ARO WORM! |
| X | Windows_Protect | wincontrol32.exe | Added by the RBOT-ADK WORM! |
| X | Windows_Serivce | SERVICE.exe | Added by the WOOTBOT.AH WORM! |
| X | windows_startup | [random].exe | Added by the NURECH TROJAN! |
| X | windows_startup | javawin.exe | Added by the NURECH TROJAN! |
| X | Windows_Updates | svthost.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows_VXD | user32.exe | Added by the PPORT TROJAN! |
| X | windows16 | windows16.exe | Added by the VB-XU TROJAN! |
| X | Windows32 | rundll.exe | Added by the AGOBOT-LK or AGOBOT-ND WORMS! Note - this is NOT the Win9x/Me system file of the same name as described here |
| X | windows32 | windows32.exe | Added by the VB-XU TROJAN! |
| X | Windows32 | wuuaclt.exe | Added by the BRATLE.B WORM! |
| X | Windows32 | win.exe | Added by the AGOBOT-KN WORM! |
| X | Windows32 | system.exe | Unknown malware |
| X | Windows32 Configuration Loader | msrf32.exe | Added by the SDBOT-ABX WORM! |
| X | Windows32 Messenger Service | msmsgv.exe | Added by the RBOT.ANS WORM! |
| X | Windows32 Net Database | msnd32.exe | Added by the RBOT-AAL WORM! |
| X | Windows32 Serivces | winser32.exe | Added by the SPYBOT.AAF WORM! |
| X | Windows32KernelStart | wks.exe | Added by the LAPURD TROJAN! |
| Y | Windows7FirewallControl | Windows7FirewallControl.exe | Windows 7 Firewall Control from Sphinx Software - "Protects your applications from undesirable network incoming and outgoing activity, controls applications internet access. Allows you to control personal information leakage via controlling application network traffic" |
| X | WindowsACEbar | acebarupdate.exe | BarACE adware |
| X | WindowsAgent | WindowsAgent.exe | Added by the GOP.G WORM! |
| X | WindowsAgent | sysexhook.exe | Added by the GOP keyboard logger/TROJAN! |
| X | WindowsAPI.DLL | Server5.exe | Added by the "Fear and Hope" TROJAN! |
| X | WindowsAudio | systemupd.exe | Added by the AGENT-TH WORM! |
| X | WindowsBackup | WINDOWSBACKUP.EXE | Added by the STANG WORM! |
| X | WindowsBool | aimplg.exe | Added by the SDBOT-CNG WORM! |
| X | WindowsCRC | wscrc.exe | Added by the SDBOT-VU WORM! |
| X | WindowsCriticalUpdate | windows_critical_update.exe | Added by the ASTEF or RESPAN WORMS! |
| X | WindowsD | s1.exe | Added by the MSNDIABLO.A WORM! |
| X | WindowsDiskEvt | svcsvh32.exe | Added by the NANINF.D TROJAN! |
| X | WindowsDiskLog | cstsm.exe | Added by the STINX-C or STINX-D TROJANS! |
| X | WindowsDriverControl | winmsnliv.exe | Added by the AGENT-PME TROJAN! |
| X | WindowsExplorer | csrss.exe | Messenger Blocker rogue security software - not recommended. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System |
| X | WindowsExplorer | svchost.exe | Messenger Blocker rogue security software - not recommended. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System |
| X | WindowsFileSystem | winsfs32.exe | Added by the RBOT-FMQ WORM! |
| X | WindowsFileSystem | cidaemon32.exe | Added by the RBOT-FSP WORM! |
| X | WindowsFirewall | lsass.exe | Messenger Blocker rogue security software - not recommended. Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System |
| X | WindowsFirewallSvc | winsvcup.exe | Added by a variant of the SDBOT WORM! |
| X | WINDOWSflashbrg | sqldata1.exe | Added by a variant of the AGENT-IC TROJAN! |
| X | WindowsFS | winfs.exe | Added by the AGOBOT-BO WORM! |
| X | Windowsfw | vssmf32.exe | Added by the SPIGOT BACKDOOR! |
| X | Windowsfw | windowsfw.exe | Added by the AGOBOT-TA WORM! |
| X | WindowsFY | wp.exe | Part of a "Security IGuard" parasite infestation - also detected as DESKTOPHIJACK |
| X | WindowsFY | bsw.exe | Added by a variant of the DESKTOPHIJACK TROJAN! For removal see here |
| X | WindowsFY | [path to trojan] | Added by the FAKEALE-E TROJAN! |
| X | WindowsFZ | [path to file] | Added by the DESKTOPHIJACK VIRUS! Also see DESKTOPHIJACK.B TROJAN! |
| X | WindowsFZ | A5281300.so | Variant of the SmitFraud alias FAKEALE-C TROJAN! |
| X | WindowsFZ | zloader3.exe | Variant of the SmitFraud alias FAKEALE-C TROJAN! |
| X | WindowsHive | rpcc.exe | Added by the DLENA-A TROJAN! |
| X | Windows�Updates | Update.exe | Added by the RBOT.TRA BACKDOOR! |
| X | WindowsInstaller | [path to file] | Added by the DEDLER-D TROJAN! The most common filenames seen are "csmss.exe" and "csmrs.exe", located in %System% |
| X | WindowsIPRelay | winipsvc.exe | Added by the IRCBOT-AAA WORM! |
| X | WindowsK | a1.exe | Added by the MSNDIABLO.A WORM! |
| X | WindowsKeyUpdate | master.exe | Added by the JOSAM WORM! |
| X | WindowsLiveMessenger | msngrpmsn.exe | Added by the AGENT-RQF TROJAN! |
| X | WindowsMGM | Winmgm32.exe | Added by the SOBIG.A WORM and LALA.C TROJAN! |
| X | windowsmp | windowsmp.exe | Added by the AUTORUN-DP WORM! |
| X | WindowsNetsDll | rundll32.exe WindowsNetsDll.dll | Added by the MDROP-DEK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "WindowsNetsDll.dll" file is located in %UserProfile%\Microsoft |
| X | WindowsNT CWServices | CWServices.com | Detected by Bitdefender as the AGENT.AGDK TROJAN! See here |
| X | WindowsNT Services | Services.com | Detected by Bitdefender as the DELF.OFC TROJAN! See here |
| X | windowspis | convertor.exe | Added by the GENOME.AKNH TROJAN! |
| X | WindowsProtocolLog | lsadst.exe | Added by the NANINF.C TROJAN! |
| X | WindowsReg% update | [random filename].exe | Added by the RBOT-HH WORM! |
| X | WindowsRegistration | [random filename] | Added by the RBOT-NO WORM! |
| X | WindowsRegKey Autoupdate | [random filename] | Added by a variant of the RBOT WORM! |
| X | WindowsRegKey upd4te2d4te | *********.exe [* = random char] | Added by the RBOT.XQ WORM! |
| X | WindowsRegKey update | winupdate.exe | Added by the RBOT-QJ WORM! |
| X | WindowsRegKey update | windns.exe | Added by the RBOT.IE WORM! |
| X | WindowsRegKey update | winupdatexx.exe | Added by the RBOT.LW WORM! |
| X | WindowsRegKey update | [random filename] | Added by the RBOT.QT WORM! |
| X | WindowsRegKey update | svchoosts.exe | Added by the RBOT.ADB WORM! |
| X | WindowsRegKey update | svchostc.exe | Added by the RBOT.IF WORM! |
| X | WindowsRegKey update | wdnupdate.exe | Added by the SDBOT.QX WORM! |
| X | WindowsRegKey update | Windowsup.exe | Added by the SDBOT.PU WORM! |
| X | WindowsRegKey update | WINUPDATES.EXE | Added by the RBOT-MM WORM! |
| X | WindowsRegKey update | rkbuouoxfl.exe | Added by the RBOT-OO WORM! |
| X | WindowsRegKey update | winsys.exe | Added by the RBOT-JY WORM! |
| X | WindowsRegKey update | winupdat32.exe | Added by the RBOT-AGW WORM! |
| X | WindowsRegKey update XP | windexv1.exe | Added by the RBOT-ABM WORM! |
| X | WindowsRegKey%$ update | msi332.exe | Added by the RBOT-IX WORM! |
| X | WindowsRegKey%update | ethernet32m.exe | Added by the RBOT-EN WORM! |
| X | WindowsRegKeys update | winsysi.exe | Added by the SDBOT.WE WORM! |
| X | Windowss Service Agent | mssngear.exe | Added by the RBOT.KGU BACKDOOR! |
| X | WindowsService | [random name].dll | Added by the VUNDO-X TROJAN! |
| X | WindowsService | service.exe | Added by the AUTORUN-VPC WORM! |
| X | WindowsServices | service.exe | Added by the FOLMESS WORM! |
| X | WindowsServices | WinServices.exe | Added by the SDBOT.CCD BACKDOOR! |
| X | WindowsServicesH | servicedhs.exe | Added by the AGOBOT-JD WORM! |
| X | WindowsServicesStartup | svchost.exe | Added by the ECUP WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp% |
| X | WindowsSetup | [path to trojan] | Added by the EZBOT TROJAN! |
| X | WindowsSp2 | sp2.exe | Added by the POSSE WORM! |
| X | WindowsSystem32 | asper.exe | Added by the AGENT-EFP TROJAN! |
| X | WindowsSystem32 | svchosts.exe | Added by the AGENT-EDA TROJAN! |
| X | WindowsSystem32 | [path to worm] | Added by the SDBOT-DFG WORM! |