| Status | Autorun name | Command | Description |
| X | Winsta~1 | winsta~1.exe | GoHip foistware |
| X | WinStabilizer | WinStabilizer.exe | Added by the AGOBOT-SW WORM! |
| X | WinStar | IEXPL0RE.exe | Added by the WOSRIST A TROJAN! |
| X | WinStart | WinStart.exe | FromIGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge |
| X | WinStart | Wscript.exe WinStart.vbs | Added by the CIAN.C WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "WinStart.vbs" file is located in %System% |
| X | WinStart | winstart32.exe | Added by the PUROL WORM! |
| X | WinStart | WinStart.pif | Added by the CONE.E WORM! |
| X | winstart | winstart.exe | Added by the SCKEYLO-AB TROJAN! |
| X | WinStart001 | WinStart001.exe | IGetNet adware |
| X | WinStart001.EXE | WinStart001.exe | IGetNet adware |
| X | winstats | winstats.exe | Added by the GARGAFX TROJAN! |
| X | WinSth16 | WinSth16.exe | Added by the CAKE WORM! |
| X | Winstos | SVCH0S.EXE | Added by the AUTORUN-EA WORM! |
| X | winstro | RUN32DLL.exe | Added by the FTP_ANA TROJAN! |
| X | winsupdate | svchost.exe | Added by the AGENT-RHZ TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AllUserProfile% |
| X | winsupdater | winsupdater.exe | Added by the ALCRA-F WORM! |
| X | winsupdatesysmngr64 | winsys64mnger.exe | Added by the RBOT-BAG WORM! |
| X | WinSvc16.exe | WinSvc16.exe | Added by the SDBOT.FQ BACKDOOR! |
| X | winsvc32 | winsvc32.exe | Added by the IRCBOT-AEG WORM! |
| X | winsvc32.exe | winsvc32.exe | Added by the GREPAGE TROJAN! |
| X | Winsvr | msupd******.exe [*= random digit] | Added by the INJECT.163 TROJAN! |
| X | Winsvr | [random filename].exe | Added by the ADCLICK-DK TROJAN! |
| X | Winsvr manager | DDEsvr.exe | Added by the TIRBOT-C WORM! |
| X | winsy32.exe | winsy32.exe | CoolWebSearch parasite variant |
| X | winsync | [random].exe reg_run | Added by the QOOLAID-R TROJAN! |
| X | Winsys | SysWindows.exe | Added by the RIMECUD-BD WORM! |
| U | Winsys | Winsys.exe | Win-Spy keyboard logger/monitoring software - remove unless you installed it yourself |
| X | WINSYS | [path to trojan] | Added by the GOLDPLAY TROJAN! |
| X | winsys | syschost.exe | Added by an unidentified TROJAN! |
| X | WinSys | winmgmt.com | Added by the VB.EIW WORM! |
| X | WinSys | system.exe | Added by the DAPROSY WORM! |
| X | WinSYs startup | windowsmedia.exe | Added by the GAOBOT.ZP WORM! |
| X | WinSys32 | Winsys32.exe | Added by the CIGIVIP TROJAN or RECKUS WORM! |
| X | winsys32 Driver | winsys32.exe | Added by the LOONY-O TROJAN! |
| U | WinSysAppMon | WinSysRM.exe | Home & Family Content Filter related. See here |
| X | winsysban | [path to trojan] | Added by the CLICKER-CD TROJAN! |
| U | WinSysCheck | sb32mon.exe | Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself! |
| X | winsyslog lptt01 | winsyslog.exe | RapidBlaster variant (in a "winsyslog" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | WinSysM | 371662M.exe | Added by the WINKO.AO WORM! |
| X | WinSysModule | [path to trojan] | Added by the AGENT-DIQ TROJAN! |
| X | WinSysStartUpWKbLw | TaskSystemDll.Exe | Added by the BACKZAT.G WORM! |
| X | WinSyst32 | winsyst32.exe | Added by the MORB WORM! |
| X | WinSystem | winsystem.exe | Added by the WHITEBAIT WORM! |
| U | WinSystem | WinSystems.exe | CMKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | Winsystem | Freevideo5.EXE | Added by the AGENT.FZS WORM! |
| X | WinSystems | winsystems16.exe | Added by the SDBOT-CZT WORM! |
| X | Winsystems | miefotoieri.EXE | Added by the DELF-DVT WORM! |
| X | winsystems25 | winsystems.exe | Added by the RBOT-CNZ WORM! |
| X | winsysupd | [path to trojan] | Added by the STARTPA-NI TROJAN! |
| X | WinSysW | 371662L.exe | Added by the WINKO.AO WORM! |
| X | WINT | wcp****.exe [* = random char] | PurityScan adware |
| X | WINT | wcp**.exe [* = random char] | PurityScan adware |
| X | WinTask | Wintask.exe | Added by the HIPO or LEMIR.F TROJANS! |
| X | WINTASK | taskgmr.exe | Added by the MYTOB.I WORM and variants! |
| X | WINTASK | taskgamr.exe | Added by the MYTOB.AU WORM! |
| X | WINTASK | sys32.exe | Added by the MYTOB.K WORM! |
| X | WINTASK | msmgrxp.exe | Added by the MYTOB.AQ WORM! |
| X | WINTASK | iexplorer.exe | Added by the MYTOB-CH WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
| X | WINTASK | taskgmr32.exe | Added by the MYTOB.BU WORM! |
| X | WINTASK | msvhost.exe | Added by the MYTOB-AR WORM! |
| X | WINTASK | t4skmgr.exe | Added by the MYTOB-AK WORM! |
| X | WINTASK | taskfile.exe | Added by the MYTOB.EF WORM! |
| X | WINTASK | taskgm.exe | Added by the MYTOB-AO WORM! |
| X | WINTASK | taskgmrs.exe | Added by the MYTOB.DH WORM! |
| X | WINTASK | yahooicons.exe | Added by the MYTOB-HM WORM! |
| X | WINTASK | t4skgmr.exe | Added by the MYTOB.CM WORM! |
| X | WINTASK | scvhost.exe | Added by the MYTOB-I WORM! |
| X | WINTASK | msvhost.exe | Added by the MYTOB-AR WORM! |
| X | WINTASK DLL | jusched32.exe | Added by the MYTOB.AI WORM! |
| X | WINTASK DLL32 | smsrss.exe | Added by the MYTOB.BS WORM! |
| X | WINTASK DLL32 | updatewin | Added by the MYTOB.NI WORM! |
| X | WinTask driver | wintask.exe | Added by the DLOADER-NA TROJAN! |
| X | WINTASK32 | taskgmr32.exe | Added by the MYTOB.BN WORM! |
| X | WINTASK32 | taskgmrr.exe | Added by the MYTOB.FX WORM! |
| X | wintask32 | Jwintask.com | Added by the NAFBOT-A WORM! |
| X | WINTASKMANAGER | taskgmr.exe | Added by the MYTOB-AF WORM! |
| X | WINTASKMGR | ccsrs.exe | Added by the MYTOB.Q WORM! |
| X | WINTASKMGR | sp2winfix.exe | Added by the MYTOB.KJ WORM! |
| X | WINTASKS | taskgmr.exe | Added by the MYTOB.BO WORM! |
| X | WINTASKS | winxpro.exe | Added by the MYTOB.EZ WORM! |
| X | WinTasks DLL Library (32-bits) | winkll.exe | Added by the RBOT-AJZ WORM! |
| U | WinTasks Traybar | wintasks.exe | WinTasks - "Efficient Resource and Task Management is absolutely critical if you want to achieve the highest system performance levels possible. WinTasks 4 will not only help you achieve this task, but will actually make your system run faster and more smoothly than ever before" |
| X | wintasks.exe | wintasks.exe | Added by the EVAMAN WORM! |
| X | Wintbp.exe | wintbp.exe | Added by the ZOTOB.E WORM! |
| X | Wintbpx.exe | wintbpx.exe | Added by the ZOTOB.F WORM! |
| U | wintective | wintective.exe | Wintective logs keystrokes, captures screenshots, and monitors Internet activity. The gathered information can be sent to a predetermined email address. If you didn't install this yourself remove it |
| X | WintelUpdate | [path to trojan] | Added by the SMALL-EKW TROJAN! |
| X | winter | happy.exe | Added by the SDBOT-YF WORM! |
| N | Wintercooler Pro | WINCOOL.EXE | Wintercooler Pro - utility that monitors CPU usage, RAM consumption and Internet connection speed |
| X | winthelp | winthelp.exe | Associated with the AdvancedCleaner rogue security software - see here. Removal instructions here |
| N | WinTidy | WinTidy.exe | Desktop icon manager from PC Magazine (Ziff-Davis). Available via Start -> Programs |
| X | Wintime | Wintime.exe | Added by the HARNIG TROJAN! |
| U | WinTime | wintime.exe | WinTime - change desktop icons' color and font |
| N | Wintime Wtxpload | Wxpload.exe Wintime | Part of the software to support a Dexxa USB graphics tablet. From a visitor - "This gets started anyway when you plug in the USB connector for the graphics tablet, if it's not already running. It then starts an application which manages the tablet messages. Since I leave the tablet unplugged unless I need to use it, I don't need this running at startup. I suspect that this program monitors a number of windows messages, so that when it's loaded, my regular mouse slows down - it acts like it 'sticks' entering and leaving windows. Certainly my performance returned to what I expected when I removed this item using MSCONFIG" |
| X | WinTimer | msupdate.cmd | Hijacker - detected by Kaspersky as the STARTPAGE.TJ TROJAN! |
| X | Wintl | msdred.exe | Identified as a variant of the Trojan-Spy.Win32.Agent.cch malware |
| X | wintnask32.exe | wintnask32.exe | Added by the RBOT-AFP WORM! |
| X | wintnl.exe | wintnl.exe | Added by a variant of the ZOTOB.K WORM! |
| X | wintnpx.exe | wintnpx.exe | Added by the ZOTOB.H WORM! |
| X | WinTools | WToolsA.exe | Wintools adware |