| Status | Autorun name | Command | Description |
| X | Winnup | win32nls.exe | Added by a variant of the SPYBOT WORM! |
| X | winocx32 | winocx32.exe | Added by the PROTORIDE.I WORM! |
| X | WinOpin | xopin2.exe | Added by the SDBOT-DA BACKDOOR! |
| X | WINOWS SYSTEM | winnt.exe | Added by the MYTOB.ID WORM! |
| X | WINP | winmic.exe | Added by the SPYBOT-EB WORM! |
| X | Winpack | winpack.exe | Adware - detected by Kaspersky as the AGENT.GG TROJAN! |
| X | WinPatch Protection | winpatch.exe | Added by an unidentified WORM or TROJAN! |
| U | WinPatrol | winpatrol.exe | WinPatrol - "Manage Startup programs, tasks, cookies; will sniff out Worms, Trojan horses, Cookies, Adware, Spyware, Klez, Assumption and other malicious programs" |
| Y | WinPatrol Explorer | WinPatrolEx.exe | Part of WinPatrol |
| U | WinPatrol Monitor | winpatrol.exe | WinPatrol - "Manage Startup programs, tasks, cookies; will sniff out Worms, Trojan horses, Cookies, Adware, Spyware, Klez, Assumption and other malicious programs" |
| X | WinPCDoctor | SysRep.exe | WinPCDoctor rogue system error and cleaning utility - not recommended, removal instructions here. A member of the ErrClean family |
| X | WinPerformance | WinPerformance.lnk | Windows Performance rogue optimization utility - not recommended |
| X | winphonics7536 | vbsystem35.exe setups.exe vb.vb | Added by a variant of the MUTIN-C TROJAN! |
| X | winpipe | winpipe.exe | Browser hijacker redirecting to wow-access.com |
| U | WinPLOSION | WinPlosion.exe | "WinPLOSION allows you to immediately view and select from all the windows running on your computer, just those of the active application, or to minimise all windows and display a clear desktop" |
| X | WinPN32 | winpn32.exe | Added by the AGOBOT-FJ WORM! |
| Y | WinPoet | WinPPPoverEthernet.exe | WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking |
| X | winpol | winpol.exe | Added by the AGENT.IWD TROJAN! |
| Y | Winpooch | Winpooch.exe | "Winpooch is a Windows watchdog, free and open source. Anti spyware and anti trojan, it gives a full protection against local or external attacks by scanning the activity of programs in real time. Associated with ClamWin antivirus, Winpooch keeps safe your computer against virus" |
| X | WinPop | winpop.exe | Brudevic A adware |
| N | WinPopup | WINPOPUP.EXE | Intranet chat software provided by windows for chat on small networks. Handy little LAN messaging utility. Has been included in Windows since 95, and maybe in WFWG 3.11. Normally it won't set itself up to run unless the user specifically adds it to startup |
| X | winpopup | winupie.exe | Adware by Tradeexit.com |
| N | Winpower | Winpower.exe | Part of InstallAnywhere from Zero G Software, now owned by Macrovision |
| X | WinProc32 | winproc32.exe | Added by the AGOBOT-4 WORM! |
| X | Winprocer32 Update | winprocer32.exe | Added by the RBOT.GW WORM! |
| X | winprocessor Update | winprocessor.exe | Added by the RBOT.IO WORM! |
| X | WinProfile | Command.exe | Added by the BUDDY.E TROJAN! |
| X | WinProfile | sndcfg16.exe | Added by the SNDC.A WORM! |
| X | winprofile | iexpiore.exe | Added by a variant of the MONCHER WORM! |
| X | WinProfile | iexpIore.exe | Added by the CHUM-C TROJAN! |
| X | WinProt | Winprot.exe | Added by the CHUPACABRA TROJAN! |
| X | WinProt | server.exe | Added by the CHUPACABRA TROJAN! |
| X | winprotect | win32.exe | Added by the MUGLY.E WORM! |
| X | winprotect | winprotect.exe | Added by the SDBOT-SB WORM! |
| X | winprotection | ccsrss.exe | Added by the SILLYFDC.BBT WORM! |
| X | WinProtector | WinProtector.exe | WinProtector rogue security software - not recommended, removal instructions here |
| U | WinProxy | WinProxy.EXE | "WinProxy is the world-first proxy server and a firewall with integrated mail server for Windows 95/98/ME/NT/2000/XP" |
| X | Winproxy Personal | WINPROXY.EXE | Added by the SDBOT.BMF WORM! |
| X | winpsd | winpsd.exe | Added by the MYDOOM.Q WORM! |
| X | WinPWD Manager | wpwdmgr.exe | Added by the RBOT-AUT WORM! |
| X | winrapid | winrapid.exe | Added by a variant of the RBOT WORM! |
| X | winrar | winrar.exe | CoolWebSearch Therealsearch parasite variant. Note - this is not the file zipping utility also known as WinRAR! |
| X | WinRaR Service | WinrarCO.com | Added by an unidentified WORM/TROJAN! |
| X | winrarshell | winrarshell32.exe | Added by the SALIRA TROJAN! |
| X | WinReader | read.exe | Added by the DELBOT-V WORM! |
| X | WinReanimator | WinReanimator.exe | WinReanimator rogue security software - not recommended, removal instructions here |
| X | winReg | winReg.exe | Added by the YAHA.H or YAHA.J WORMS! |
| X | WinReg | ournik.com | Added by the IRCFLOOD.AL BACKDOOR! |
| X | winreg_32 | svchosst.exe | Added by the BANCOS-CE TROJAN! |
| X | winreg_32 | [path to trojan] | Added by the BANKER-DB TROJAN! |
| X | winreg_32 | sysdll.exe | Added by the DLOADER-IJ TROJAN! |
| X | winreg_32 | Vc030405.exe | Added by the BANCOS-CT TROJAN! |
| X | WinReg32 service | holqdnoxpmeu.exe | Added by a variant of the SDBOT WORM! |
| X | WinRegPro | WinRegPro.exe | WinRegPro rogue security software - not recommended, removal instructions here |
| X | winregsrv | winregsrv.exe | Added by the SYNRG TROJAN! |
| U | WINREMOTE | WinRemote.exe | InterVideo WinCinema Manager - needed for the use of WinDVD Remote Control |
| X | Winres32vis | [path to worm] | Added by the THRAX.A WORM! |
| X | winrestore1 | winrestore.exe | Added by the KILLFIL-Q TROJAN! |
| X | winreups | winreups.exe | Added by a variant of the RBOT WORM! |
| U | WinRoll | winroll.exe | WinRoll - a small utility that allows you to "make a window roll into its title bar, send it to the back or make it stay on top. Minimize, maximize or close all visible windows, including minimizing to the tray area" |
| X | winroot | winsn.exe | Added by the QQPASS.IA WORM! |
| N | winroute | winroute.exe | Win-Route 4.27. WinRoute Tray Icon for starting and stopping the WrCtrl.exe process, also to log in to the console to view logs and change settings. Can be unchecked and the engine still runs and functions normally. Can then use provided shortcuts for administration of the program. Loaded in SERVICES on Windows 2k |
| X | WinRPC | winrpcmx.exe | Added by the BANKER-EEI TROJAN! |
| X | WINRUN | taskgmr.exe | Added by the MYTOB-BX WORM! |
| X | WinRun | AutoRun.ini | Added by the LOVELET-AD WORM! |
| X | WINRUN | TASKMGR32.exe | Added by the MYTOB.AX WORM! |
| X | winrun | msconfig.exe | Added by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrun |
| X | winrun | winrun.exe | Added by the WINBUR.B WORM! |
| X | WINRUN | taskgmr32.exe | Added by the MYTOB.AP WORM! |
| X | WINRUN | svchost32.exe | Added by the MYTOB-AI WORM! |
| X | WINRUN z | W1NT45K.exe | Added by the MYTOB.BL WORM! |
| X | WinRunners | WinDrivers.exe | Added by the DULOAD.C WORM! |
| X | Wins Loader5 | Gadu-Gadu.exe | Added by a variant of the IRCBOT TROJAN! Note - doe not confuse with the Polish language Instant Messaging client also called Gadu-Gadu |
| X | Wins Service | wmsncs.exe | Added by the BBJC.A TROJAN! |
| X | Wins Service Driver | winet.exe | Added by the RBOT-APV WORM! |
| X | Wins Update 32 | services32.exe | Added by the FORBOT-FN WORM! |
| X | Wins32 Online | cfgpwnz.exe | Added by the BROPIA.R WORM! |
| X | WinScMngr | winsmc.exe | Added by the SDBOT-BPZ WORM! |
| X | WinSec | winsec16.exe | Added by the AGOBOT.ZF WORM! |
| X | winsecure | winsecure.exe | Browser hijacker, redirecting to specificsearches.com |
| X | WinSecure | [random].exe | Added by the AGENT-LR TROJAN! |
| X | Winsecure Antivirus | Secureantivirus.exe | Added by a variant of the SPYBOT WORM! |
| X | WinSecureAv | pgs.exe | WinSecureAv rogue security software - not recommended, removal instructions here. A member of the AVSystemCare family |
| X | WinSecured32 | ssmr.exe | Added by a variant of the FORBOT WORM! |
| X | WinSecurity | uninstall.exe | Added by the SILLYFDC.BCJ WORM! |
| X | Winserv | Winserv.ila | Added by the NODMIN WORM! |
| X | WINSERV SERVICE | dc.exe | Added by the HAMWEQ.DQ WORM! |
| X | winserver | Server.txt.vbs | Added by the DELTAD.A WORM! |
| X | Winservice | winmain.exe | Adult content related malware |
| X | winservice | svchost.exe | Added by the CVK BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "services" sub-folder |
| X | WinService | hosth.exe | Added by the DWNLDR-FUX TROJAN! |
| X | WinService | Ttt.exe | Added by the MSNVB-D WORM! |
| X | WinService | WinServ.exe | Added by the SKOWOR-O WORM! |
| U | WinService32 | ssmgr.exe | 007 Spy Software - "stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP" |
| U | WinService32 | svchost.exe | 007 Spy Software - "stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP" |
| X | WinServices | WinServices.exe | Added by the YAHA.K or YAHA.M WORMS! |
| X | winservices | bootvfy.exe | Added by an unidentified WORM or TROJAN! |
| X | winservit | cassl.exe | Added by the RBOT.ASG WORM! |
| X | winservn | winservn.exe | PurityScan adware |
| X | winservs | winservs.exe | PurityScan adware |