| Status | Autorun name | Command | Description |
| X | WindowsSystem32 | msnmssgr.exe | Added by the AGENT.ALY BACKDOOR! |
| X | WindowsSystem32 | msn_kilo.exe | Added by the AGENT.ALY BACKDOOR! |
| X | WindowsSystem32 | msnmgaer.exe | Added by the AGENT.ALY BACKDOOR! |
| X | WindowsSystem32 | molox.exe | Added by the RBOT.WBG BACKDOOR! |
| X | windowstime.exe | windowstime.exe | Added by the DLOADR-AQV TROJAN! |
| U | WindowsTranslator | DWinTrsl.exe | Micropower Delta Translator English <> Portugese (Brazilian) version - "an automatic, bi-directional machine translation software system that quickly and automatically translates multiple pages, paragraphs, sentences, phrases or just individual words in documents, letters, memos, faxes, reports, manuals, booklets, publications, spreadsheets, e-mail and even web pages as you browse the Internet" |
| U | WindowsTranslator_Espanhol | DWinTrsl.exe | Micropower Delta Translator - Spanish <> Portugese (Brazilian) version - "an automatic, bi-directional machine translation software system that quickly and automatically translates multiple pages, paragraphs, sentences, phrases or just individual words in documents, letters, memos, faxes, reports, manuals, booklets, publications, spreadsheets, e-mail and even web pages as you browse the Internet" |
| X | WindowsUpd | WindowsUpd4.exe | VirtuMonde adware |
| X | WindowsUpd1 | WindowsUpd1.exe | VirtuMonde adware |
| X | WindowsUpd2 | WindowsUpd2.exe | VirtuMonde adware |
| X | WindowsUpdate | windows_update.exe | Added by the LOFNI WORM! |
| X | WindowsUpdate | svchost.exe | Added by the ASTEF or RESPAN WORMS or AGENT-V TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | windowsupdate | RPC[RANDOM CHARACTERS].exe | Added by the IRCBOT.B TROJAN! |
| X | WindowsUpdate | USRINIT.EXE | Added by the MADDIS.B WORM! |
| X | windowsupdate | winupdate.exe | Added by the WARPI WORM! |
| X | WindowsUpdate | svchost.exe | Added by the BDOOR-IK BACKDOOR! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | WindowsUpdate | winnnint.exe | Added by an unidentified WORM or TROJAN! |
| X | WindowsUpdate | [path to file] | Added by the DUPA-B TROJAN! |
| X | WindowsUpdate | svchostw.exe | Added by the NURECH TROJAN! |
| X | WindowsUpdate | Nzil.exe | Added by the CULLER-C WORM! |
| X | WindowsUpdate | Strad.exe | Added by the CULLER-D WORM! |
| X | Windowsupdate | Windowsupdate.exe | Added by the BANKER.ARK TROJAN! |
| X | Windowsupdate | wupdmgr98.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | WinDOwsUPdate | smss.exe | Added by the AUTORUN.DIB WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder |
| X | windowsupdate | autoupdate.exe | Added by the IRCBOT-P BACKDOOR! |
| X | WindowsUpdate | svdhost.exe | Added by the AGOBOT-BP WORM! |
| X | WindowsUpdate | twain.exe | Added by the AGENT.BEA TROJAN! |
| X | WindowsUpdate renew | iexplore.exe | Added by the AGENT.QG TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | WindowsUpdate Service | wuautlc.exe | Added by the RBOT-NR WORM! |
| X | Windowsupdate Service | csrss.exe | Added by the BABA-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root folder (ie, C:\) |
| X | WindowsUpdatecrss | crss.exe | Added by a variant of the AGENT-HZ TROJAN! |
| X | WindowsUpdateDirect | dupadirect.exe | Added by the DUPA-C TROJAN! |
| X | WindowsUpdatelsasss | lsasss.exe | Added by a variant of the AGENT-HZ TROJAN! |
| X | WindowsUpdatem1 | [path to file] | Added by the AGENT-AAJ TROJAN! |
| X | WindowsUpdatem2 | svchost.exe | Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
| X | WindowsUpdateManager | wupdmng.exe | Added by the IRCBOT.OE BACKDOOR! |
| X | WindowsUpdateNT | svwhost.exe | Added by the SHELLOT-B TROJAN! |
| X | WindowsUpdateR | regserv.exe | Added by the NURECH TROJAN! |
| X | WindowsUpdates | WindowsSystem.exe | Added by the AUTORUN-BLA WORM! |
| X | WindowsUpdatesvchostss | svchostss.exe | Added by the AGENT-HZ TROJAN! |
| X | WindowsUpdatev4 | w32gins.exe | Added by an unidentified WORM or TROJAN! Located in the Root folder (C:\), (D:\), etc |
| X | WindowsUpdatewinsec | winsec.exe | Added by a variant of the AGENT-HZ TROJAN! |
| N | WindowsWelcomeCenter | rundll32.exe oobefldr.dll,ShowWelcomeCenter | Shows the Welcome Center every time you boot into Windows Vista - which "pulls all the tasks you'll most likely want to complete when you set up your computer into a single location" |
| X | WindowsXP Module | DirectX3D.exe | Malware, reportedly a keylogger - see here |
| X | WindowsXp Security | spool.exe | Added by the RBOT-GRK WORM! |
| X | WindowsXP Update | windowsxpupdate.exe | Added by the RBOT-PB WORM! |
| X | WindowsXPserv | svcnxp32.exe | Added by the NANINF-A TROJAN! |
| X | windowsxxx | windowsxxx.exe | Added by the DUBING-A TROJAN! |
| X | windowsxxx2 | windowsxxx2.exe | Added by the DUBING-A TROJAN! |
| X | Windowz | [original worm filename].vbs | Added by the NUKIP WORM! |
| X | Windowz Update V2.0 | Explorer.exe | Added by the YODO WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System% |
| X | Windowz Update V2.0 | updater.exe | Added by the YODO-C WORM! |
| X | Windoxs Update Center | W32RfSA.exe | Added by a variant of the SDBOT WORM! |
| X | WinDrg32 | windrg32.exe | Added by the DRUDGEBOT.A WORM! |
| X | WinDriv32 | WinDriv32.exe | Added by the SMALL-BA TROJAN! |
| X | WinDriver Configuration | windrvconf.exe | Added by the AGOBOT-LX TROJAN! |
| X | WinDrives | WinDrives.EXE | Added by the WINDRIVES.B WORM! |
| X | WINDRUN | taskgmrs.exe | Added by the MYTOB-BT WORM! |
| X | windrv | windrv32.exe | Added by an unidentified VIRUS, WORM or TROJAN! - possibly a strain of OBLIVION or BIONET |
| X | WinDrv | windrvx.exe | Added by a variant of the TIBSER.A downloader TROJAN! |
| X | Winds Sers Agts | [5 random letters].exe | Added by a variant of the RBOT WORM! |
| X | Winds Sersc Agts | rzrzncrtz.exe | Added by the RBOT-GTV WORM! |
| U | WinDSL MTU-Adjust | WinDSL_MTU.exe | Adjusts the registry setting of the DUN-Adapters (MTU) and the TCP/IP-Protocol (RWIN) by ENGEL Technologieberatung |
| ? | WinDSL_MTU | WinDSL_MTU.exe | May be realted to Tiscali broadband, if so is it required? |
| X | WinDSNX | Win****.exe [* = random char] | Added by the DSNX TROJAN! |
| U | Windstream Broadband Check-up Center | matcli.exe | Part of the Windstream Broadband service from AllTel. "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". Windstream Broadband Check-up Center is required to run with the Help and Support program. If you uncheck it and then run Help and Support it will add another in the startup menu. If you remove Windstream Broadband Check-up Center via add/remove programs some menus in Help and Support will not be available. You decide |
| U | Windstream_BCUC_McciTrayApp | McciTrayApp.exe | System tray access to Motive's broadband configuration and repair utility - for Windstream users |
| X | windtbs | winsysvc | Added by the AGOBOT-NH WORM! |
| X | WindUpdates | [path to trojan] | Added by the AGENT.BF TROJAN! |
| X | WindUpdates | WinUpdt.exe | WindUpdates adware |
| U | WINDVDpatch | CTHELPER.EXE | CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative's sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a "leave alone" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it |
| N | WinDVR SchSvr | SchSvr.exe | WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs |
| N | WinDVRCtrl | WinDVRCtrl.exe | Control center software for an AOpen VA1000 TV tuner card |
| X | windwos | 1.tmp | Added by the POISON.PG BACKDOOR! |
| X | Windws Configuration Loader | LEXPLORE.exe | Added by the SODABOT WORM! |
| X | WinDynManager | amsnmsg.exe | Added by the SDBOT-IA BACKDOOR! |
| X | winenv | winenv.exe | Added by a variant of the SDBOT WORM! |
| X | WinEssential | Keyhost.exe | Hijacker - hailing from jraun.com |
| X | WinEssential | keyword.exe | Jraun adware |
| X | WineWork | WineWork.exe | Added by the BANCOS.AB TROJAN! |
| X | WinEx | lexplore_.exe | Added by the MSNOPT-A TROJAN! |
| X | WinExec | Winexec.exe.vbs | Added by the AINESEY.A WORM! |
| X | WinExec | WinExec.exe | Added by the FALUS-A WORM! |
| X | WinExec | Lsass.exe | Added by the CRUTLE-B WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | WinExec32 | WinExec32.exe | Added by the KAZWIN WORM! |
| X | Winexec32 | windhelp32.exe | Added by the AGENT-HKU TROJAN! |
| X | winexecs | winexecs.exe | Added by the SILLYFDC.BBB WORM! |
| U | WinFast Schedule | Wfwiz.exe | Leadtek WinFast TV tuner scheduler and remote control driver - required if you use the latter |
| U | Winfast_2K | WF2K.EXE | System Tray application that starts up the Winfox utility for a Leadtek Winfast graphics card to restore settings. Can be started manually via Start → Control Panel → Display. Only needed if you wish to run things like the hardware monitor or overclock your card |
| U | WinFast_Gamma | Rundll32.exe wfcpl.dll, DllLoadGammaRampSettings | Loads if you change the gamma settings on Leadtek WinFast graphics cards |
| U | WinFast_Taskbar | rundll32.exe wftask.dll, WFDllLoadDefaultSettings | Loads default settings for Leadtek WinFast graphics cards |
| U | Winfast2KLoadDefault | rundll32.exe wf2kcpl.dll,DllLoadDefaultSettings | Loads default settings for Leadtek Winfast graphics cards |
| U | WinFastDTV | DTVSchdl.exe | Scheduler for WinFast DTV digital TV cards from Leadtek Research Inc |
| X | WinFavorites | WinFavorites.exe1 | Loudmarketing.com adware downloader |
| N | WinFax PRO | FAXMNG32.EXE | WinFax PRO from Symantec - fax management software |
| N | WinFax PRO Controller | WFXCTL32.EXE | From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs |
| Y | WinFaxAppPortStarter | wfxsnt40.exe | WinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application. |
| X | winFile | winFile.exe | Added by the BANKER-FDB TROJAN! |
| X | WinFire | WF.exe | Added by the DELF-SY TROJAN! |
| X | WinFix service | rsswjzgp.exe | Added by the RBOT-FAE WORM! |