| Status | Autorun name | Aufruf | Beschreibung |
| X | Microsoft Windows XP/2K Explorer | winexplorer.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Microsoft Winedows startup | WinKey.exe | Added by a variant of the SDBOT WORM! See here |
| X | Microsoft Winedows Updateing | NinKey.exe | Added by a variant of the SPYBOT WORM! See here |
| X | Microsoft Winedows WinServ | iPodFix.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft WINGS32 Protocol | WinSGR32.exe | Added by the RBOT-APU WORM! |
| X | Microsoft WinRaR | winrar.exe | Added by the RBOT-AEC WORM! |
| X | Microsoft Winsock | mswinsck.exe | Added by the RBOT-ANK WORM! |
| X | Microsoft Winsock Service | msusvc.exe | Added by the RBOT-ANS WORM! |
| X | Microsoft Winsock Wrapper | ws2_32s.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Winsock32 System | winsock32.exe | Added by the SPYBOT.AKKC WORM! |
| X | Microsoft WinSound | [random filename] | Added by a variant of the RBOT WORM! |
| X | Microsoft winsupdater | WINSUPDATER.EXE | Added by the SPYBOTER.FB BACKDOOR! |
| X | Microsoft WinUpdate | mntcgf032.exe | Added by the RBOT-PF WORM! |
| X | Microsoft WinUpdate | svh0st.exe | Added by the SPYBOT.DL WORM! |
| X | Microsoft WinUpdate | syslx32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Microsoft WinUpdate | syswin32.exe | Added by the RBOT-HO WORM! |
| X | Microsoft WinUpdate | spfix.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft WinUpdate | Winamp61.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft WinUpdate | Winupd32.exe | Added by the RBOT.MQ WORM! |
| X | Microsoft WinUpdate | WinNTinit32.exe | Added by the RBOT.VS WORM! |
| X | Microsoft WinUpdate | msupdte.exe | Added by an unidentified TROJAN! See examples here& here |
| X | Microsoft WinUpdates | serm32.exe | Added by the RBOT.GE WORM! |
| X | Microsoft WM | mswm32.exe | Added by the BCKDR-AM BACKDOOR! |
| X | Microsoft Word | BootSector.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Microsoft Word Profissional | csrss.exe | Added by the BANCBAN-DB TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "s1613" subfolder |
| X | Microsoft Word Profissional | Java Plug In close.exe | Added by the BANKER-EL TROJAN! |
| X | Microsoft Word Profissional | csrss.exe | Added by the BANKER-DJ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "protect" subfolder |
| X | Microsoft Word Profissional | csrss.exe | Added by the BANKER-DP TROJAN! ! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "JavaVM" subfolder |
| X | Microsoft Word System | sysword.exe | Added by the SDBOT-ALY WORM! |
| N | Microsoft Works Calendar Reminders | wkcalrem.exe | If you schedule an event at any time in Microsoft Works Calendar and set a reminder then a shortcut will be added to Start → All Programs → Startup so this reminder service loads every time Windows starts |
| N | Microsoft Works Portfolio | WksSb.exe | The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program. The Works Portfolio provides a location where you can store items you want to later put into a document or other file. Can be prevented from starting from a setting within Portfolio |
| N | Microsoft Works Update Detection | wkdetect.exe | Checks for updates to MS Works |
| N | Microsoft Works Update Detection | WkUFind.exe | MS Works Update Detection. MS Picture It! (versions 7 to current) use this automatic update feature during the log on process. It can also cause your system to automatically dial into your ISP as it tries to access the internet, if you have your system set to automatically dial when the internet is invoked. To manually update, go to Microsoft's Office/Works update site. You can also turn of the automatic update feature within Picture It! |
| X | Microsoft World Service | winworld.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Microsoft WPCEmail | [path to trojan] | Added by the SNIFFER-N TROJAN! |
| X | Microsoft WWW | [path to trojan] | Added by the AGENT-DRI TROJAN! |
| X | Microsoft Wxdate | Syswu32.exe | Added by the SPYBOT.HZ WORM! |
| X | Microsoft X Update | wuamkoppnp.exe | Added by the RBOT-ANI WORM! |
| X | microsoft xdaemon 2.0 | xdaemon.exe | Added by the DELF.D TROJAN! |
| X | Microsoft XML Parsing Service | msxml32.exe | Added by the RBOT.EDT BACKDOOR! |
| X | Microsoft XML Service | msxmlx.exe | Added by the RBOT.KS WORM! |
| X | Microsoft Xp Systems loader | winsystem32xp.exe | Added by the KELVIR.W WORM! |
| X | Microsoft Xp Systems loaders | win32xpsys.exe | Added by the SPYBOT.NYT WORM! |
| X | Microsoft XPSP Protocol | xp386.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft xpsp2 | Networksystem.exe | Added by a variant of the SDBOT WORM! |
| X | Microsoft xpsp2 | xpsp2.exe | Added by the SDBOT-YQ WORM! |
| X | Microsoft's System Module | Sysmodule.exe | Added by the BDOOR-FJ BACKDOOR! |
| U | Microsoft(R) Pinyin IME 2007 | IMSCMIG.EXE | Associated with Microsoft's Input Method Editor for Asian languages which is used to both display and enable the input of characters in e-mails, documents and other files - should you need to (e.g. Chinese, Hindi, Japanese, etc) |
| X | Microsoft(R) System Manager | sysmgr.exe | Added by the AGENT.QTR TROJAN! |
| X | Microsoft--Updates | sxvhost.exe | Added by the RBOT-FH WORM! |
| X | Microsoft-software | ****.exe [* = random char] | Added by a variant of the RBOT WORM! |
| X | Microsoft-Update | wngard.exe | Added by the RBOT-JV WORM! |
| X | Microsoft-Updates | svxhost.exe | Added by the RBOT-CT WORM! |
| X | Microsoft.exe | [random].exe | Added by a variant of the IRCBOT TROJAN! |
| X | microsoft.exe | microsoft.exe | Added by the GOLDUN-GB TROJAN! |
| X | Microsoft? Operating System: | svchost.exe | Added by the AGENT-PAF TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Microsoft© | iexplore.exe | Added by the IRCBOT-ACO TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%\dllcache |
| X | Microsoft© PID Lex | PIDLex.exe | Added by the NIOVADOOR TROJAN! |
| X | Microsoft© System Mapper | SysMap.exe | Added by the MAPSY TROJAN! |
| X | Microsoft« ActiveX Debugger NT | setdebugnt.exe | Added by the BANCOS-CZ TROJAN! |
| X | Microsoft® Update Service | winrsvn.exe | Added by the PHORPIEX.A WORM! |
| U | Microsoft® Windows Mobile® Device Center | wmdc.exe | Windows Mobile Device Center - mobile device management/synchronization software for Windows7/Vista, supporting mobile devices based upon Windows Mobile 2003 or later |
| U | Microsoft® Windows® Operating System | Sidebar.exe | Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijacker |
| U | Microsoft® Windows® Operating System | ehTray.exe | Media Center Tray Applet - part of Windows Media Center on XP MCE, Vista and Windows 7 (where it doesn't run as a startup). Allows Windows Media Center to be started by pressing the green button on a remote control and also displays System Tray notifications, such as recording status (successful or non-successful), EPG download notification, etc |
| N | Microsoft® Windows® Operating System | RunDLL32.exe ehuihlp.dll,BootMediaCenter | Starts Windows Media Center every time Vista (Home Premium or Ultimate) or Windows 7 (Home Premium, Professional or Ultimate) boots. Disable by unchecking the "Start Windows Media Center when Windows Starts" option via Windows Media Center → Tasks → Settings → General → Startup and Window Behaviour |
| N | Microsoft® Windows® Operating System | rundll32.exe oobefldr.dll,ShowWelcomeCenter | Shows the Welcome Center every time you boot into Windows Vista - which "pulls all the tasks you'll most likely want to complete when you set up your computer into a single location" |
| N | Microsoft® Windows® Operating System | p2phost.exe | Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that "identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer." Available via Start → Control Panel |
| N | Microsoft® Windows® Operating System | stikynot.exe | Microsoft Sticky Notes - virtual sticky notes tool from Windows Vista. This implementation of the popular yellow "Post-It" tool is part of the Tablet PC features and allows you to enter either handwriting (via a pen or mouse) or record a voice note. AVailable via Start → All Programs |
| U | Microsoft® Windows® Operating System | WMPNSCFG.exe | Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music, videos, and pictures to others on the network. This entry is used to notify users when new media rendering devices are found on the network (including media players and other PCs running Windows Media Player 11) - see here for a more detailed explanation |
| N | Microsoft® Windows® Operating System | browserchoice.exe | In the European Union, Microsoft had to provide the "Browser Choice update to comply with a legal settlement with the European Commission. Microsoft is required to inform customers who currently use Internet Explorer as their default browser that there are other web browser choices available. You can use the Browser Choice update to select and install the web browser you want to use on your computer" - see here for more information |
| N | Microsoft® Works 7.0 | wkcalrem.exe | If you schedule an event at any time in Microsoft Works Calendar and set a reminder then a shortcut will be added to Start → All Programs → Startup so this reminder service loads every time Windows starts |
| N | Microsoft® Works 8 | wkcalrem.exe | If you schedule an event at any time in Microsoft Works Calendar and set a reminder then a shortcut will be added to Start → All Programs → Startup so this reminder service loads every time Windows starts |
| X | Microsoft32 | win32sys.exe | Added by an unidentified WORM or TROJAN! |
| X | microsoft420 | microsoft420.exe | Added by the MENACE.B WORM! |
| X | Microsoft64 | antiv.exe | Added by the SOBER WORM! |
| Y | MicrosoftAntiSpywareCleaner | gcASCleaner.exe | Microsoft Antipsyware - now superseded by Microsoft's Windows Defender |
| X | MicrosoftCorp | flashsplayer.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | MicrosoftCorp | javaw.exe | Added by the BUZUS.BULO TROJAN! |
| X | MicrosoftCorp | msnrmgs.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | MicrosoftCorp | regtray.exe | Added by the POISON.AHNW BACKDOOR! |
| X | MicrosoftCorp | securebind.exe | Added by the INJECT TROJAN! |
| X | MicrosoftCorp | sysdiag64.exe | Added by the AUTOINF-AB WORM! |
| X | MicrosoftCorp | traymgr.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | MicrosoftCorp | update.exe | Added by the AUTORUN-ASG WORM! |
| X | MicrosoftCorp | wupdate.exe | Added by the AGENT-LAY TROJAN! |
| X | MicrosoftCorp | Windipz.exe | Added by the AUTORUN-AYF WORM! |
| X | MicrosoftCorp | systems.exe | Added by the BUZUS.CRVA TROJAN! |
| X | MicrosoftDriverService32 | drsys32.exe | Added by the IRCBOT.AKX BACKDOOR! |
| X | Microsoftf DDEs ContDLL | rune.pif | Added by the RBOT-AGF WORM! |
| X | Microsoftf DDEs ContrDL | runm.pif | Added by the RBOT-AFQ WORM! |
| X | Microsoftf DDEs Control | lxes.exe | Added by the RBOT.BOF WORM! |
| X | Microsoftf DDEs Control | wees.exe | Added by a variant of the RBOT WORM! |
| X | Microsoftf DDEs Control | soff.pif | Added by the RBOT-AKH WORM! |
| X | Microsoftf DDEs Control | why-.exe | Added by the RBOT-AMV WORM! |
| X | Microsoftf DDEs Control | msnn.exe | Added by the RBOT-AXT WORM! |
| X | Microsoftf DDEs Control | FEnR.exe | Added by the RBOT-AIM WORM! |
| X | Microsoftf DDEs Control | w33s.exe | Added by a variant of the RBOT WORM! |
| X | Microsoftf DDEs Control | waes.exe | Added by a variant of the RBOT WORM! |
| X | Microsoftkeysd | systemproc.exe | Added by the FORBOT-BI WORM! |
| X | Microsoftkeysd | systemwin32s.exe | Added by the WOOTBOT.CO WORM! |