| Status | Autorun name | Aufruf | Beschreibung |
| X | Windows Auto Updater | WINDOWSUPDATE.EXE | Added by the SDBOT.PB WORM! Note the space at the beginning of the filename |
| X | Windows Automatic Update | wuamgrder.exe | Added by a variant of the RBOT WORM! |
| X | Windows Automatic Updater | windrg.exe | Added by a variant of the RBOT WORM! |
| X | Windows Automatic Updates | dvldr.exe | Added by the RBOT.MF WORM! |
| X | Windows Automatical Updater | dcz.exe | Added by the RBOT.CXS WORM! |
| X | Windows AutomaticUpdater | runddls.exe | Added by a variant of the RBOT WORM! |
| X | windows automation | mslaugh.exe | Added by the BLASTER.E WORM! |
| X | Windows Automation | msdspr.exe | Added by the SOLAME.A WORM! |
| X | Windows Autostart Loader | notepad32.exe | Added by a variant of the RBOT WORM! |
| X | Windows backup | systemss.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows Backup Configuration | IEXPLORER.exe | Added by the GAOBOT.AZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
| X | Windows Baþlangýç Dosyasý | sistem.exe | Added by the MUZK WORM! |
| X | Windows Boot | winboot.exe | Added by the AGENT.HBD TROJAN! |
| X | Windows Boot | windowsboot.exe | Added by the IRCBOT.AZT BACKDOOR! |
| X | Windows Booter | winboot.exe | Added by a variant of the IRCBOT TROJAN! |
| X | Windows Booter! | winbooter.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Windows Bootup | ms-wks32.exe | Added by the RBOT-AFM WORM! |
| X | Windows Bootup | Systemwks32.exe | Added by a variant of the RBOT WORM! |
| X | Windows Bootup | task-mngr.exe | Added by the RBOT-AWP WORM! |
| X | Windows Browser Services | browser128.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Browser Services | browser32.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Browser Services | browser64.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Browser Services | Browsr32.exe | Added by the IRCBOT.BUR BACKDOOR! |
| X | Windows Browser Services | browsr64.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows bypass security SMSS Service | SbiCvy.exe | Added by the RBOT-GRF WORM! |
| X | Windows cfg | ascv.exe | Added by the AGOBOT-SZ BACKDOOR! |
| X | Windows Clean-Up Pro | WINDOWS CLEAN-UP PRO.Exe | Windows Clean-Up Pro spyware remover - not recommended, see here |
| X | Windows Cleaner Service | winclean.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Client | client.exe | Added by the BACKDR-AM BACKDOOR! |
| X | Windows Client Service 32 | csrss.exe | Added by the RBOT-ALB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a drivers\winsdriver subfolder |
| X | Windows Client/Server Runtime Server | csrs.exe | Added by the RBOT.KD WORM! |
| X | Windows CODE Fix Msy Startups | msyh32.exe | Added by the AGOBOT.AKK WORM! |
| X | Windows Command | wincmd.exe | Added by the RBOT.ANV WORM! |
| X | Windows Common Files Manager | Commgr.exe | Added by the AUTORUN.HFP WORM! |
| X | Windows Communicator | wincomm.exe | Added by the AGOBOT-BH WORM! |
| X | Windows Communicator for NT/XP | osndyrn.exe | Added by the SDBOT-CPK WORM! Note - can terminate AV related processes |
| X | Windows Compliant | [random filename] | Added by the RBOT-IR WORM! |
| X | Windows Computer Browser | bcwsvc.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Conf | windowsconf.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Config | SSYS.EXE | Added by the SPYBOT-DA WORM! |
| X | Windows Config | wins.exe | Added by the SPYBOT.JR WORM! |
| X | Windows Config | RUNDLL.EXE | Added by the SPYBOT-DX WORM! Note - this is NOT the Win9x/Me system file of the same name as described here |
| X | Windows Config | pvphost.exe | Added by a variant of the SLAPER TROJAN! |
| X | Windows Config | winconfig.exe | Added by the IRCBOT.BAP BACKDOOR! |
| X | Windows Config | ZANBOR.EXE | Added by the SPYBOT-MH WORM! |
| X | Windows Config | antivirus32.exe | Added by the SPYBOT.DX WORM! |
| X | Windows Config Connection | msicll.exe | Added by the RBOT-EXQ WORM! |
| X | Windows Config Loader | Wincfg32.exe | Added by the SILVERFTP TROJAN! |
| X | Windows Config Manager | winconf.exe | Added by the RBOT-AIT WORM! |
| X | Windows Config Manager | Wincfgman32.exe | Added by the AGOBOT-AL BACKDOOR! |
| X | Windows Config System | config.exe | Added by a variant of the SDBOT WORM! |
| X | Windows Configuration | wsys32.exe | Added by the GAOBOT.FB WORM! |
| X | Windows Configuration | wincfg32.exe | Added by the MYTOB.ED WORM! |
| X | Windows Configuration | WINHUB.EXE | Added by the SPYBOT-CG WORM! |
| X | Windows Configuration Loader | asclt.exe | Added by the SDBOT-OA WORM! |
| X | Windows Configuration Loader | msgfix.exe | Added by the SDBOT-NP WORM! |
| X | Windows Configuration System | IExplore.exe | Added by the RBOT-DDG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
| X | Windows Configuration Utility | winxupdate.exe | Added by the AGOBOT.LW WORM! |
| X | Windows Configurator | winconf.exe | Added by a variant of the IRCBOT TROJAN! |
| X | Windows connection manager | Internet.exe | Added by the RBOT-APN WORM! Note - file is found in %Windir%. Make sure you check the link on this one, it copies it's self under three other file names and folder locations |
| X | Windows Console | wkssvc.exe | Added by the SDBOT-DJX WORM! |
| X | Windows Console Component | wrasvc.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Console Monitor | [path to worm] | Added by the KEDEBE WORM! |
| X | Windows Console Monitor | gcasAV32.exe | Added by the KEDEBE-A WORM! |
| X | Windows Console Norms | wnbsvc.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Console Source | wnbsvc.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Control | Control.exe | Added by the GREK.A TROJAN! If there is another file with the same file name in the Windows folder, this malware overwrites it with the dropped file |
| X | Windows Control Panel | spoolsv.exe | Added by the AGENT-NQJ TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %UserProfile%\Application Data |
| X | Windows ControlAd | WinCtlAd.exe | WindUpdates adware variant |
| X | Windows Controls Center | winudmr.exe | Added by the LAMER.AA BACKDOOR! |
| X | Windows Core Kernel Update | win32bootcfg.exe | Added by the RANCK-EL TROJAN! |
| X | Windows CPU host | winbog32.exe | Added by a variant of the RBOT WORM! |
| X | Windows Critical Alert | wincrt.exe | Added by the ALEDO-A TROJAN! |
| X | Windows Custom Services | CSRCS.EXE | Added by the SPYBOT-EI WORM! |
| X | Windows Data Serivce | [path to trojan] | Added by the VB-EKA TROJAN! |
| X | Windows Data Server | autodisc.exe | Added by the SPYBOT-CB WORM! |
| X | Windows Data Server | [random name].exe | Added by the SPYBOT-DS WORM! |
| X | Windows Database | WinDat.exe | Added by an unidentified WORM or TROJAN! |
| X | Windows Database | wiinsvc.exe | Added by the AGOBOT-RU WORM! |
| X | Windows Dcom2 Fix | mscom32.exe | Added by the RBOT-QT WORM! |
| X | Windows DDE Loader | windde32.exe | Added by the SDBOT-UZ WORM! |
| X | Windows debug logging | winlogg.exe | Added by the RBOT-OY WORM! |
| X | Windows debug logging | winloggs.exe | Added by the RBOT-QN WORM! |
| X | Windows Debugger | windbg.exe | Added by the FORBOT-BY WORM! |
| X | Windows Debugger | msdbg32.exe | Added by a variant of the RBOT WORM! |
| X | Windows Debugger | windbg32.exe | Added by the ZOTOB.L WORM! |
| X | Windows Debugging Tools | updatecfg.exe | Added by the RBOT-AXU WORM! |
| X | Windows Default Configuration | svchost.exe | Added by the DLOADER-U TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup! |
| X | Windows Default Server | wfdmgrsp.exe | Added by the IRCBOT.BCX BACKDOOR! |
| X | Windows Default Server | winampa.exe | Added by the IRCBOT.AUN WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of %ProgramFiles% whereas this file is located in %Windir% |
| Y | Windows Defender | MSASCui.exe | Main user interface for Microsoft's Windows Defender on XP/Vista - which "helps protect your computer against pop-ups, slow performance, and security threats caused by spyware and other unwanted software by detecting and removing known spyware from your computer". Used in conjunction with the associated service, this entry is always running and the user also has the option to always display the System Tray icon and monitor/control new startup programs |
| X | Windows Defender | wdc*.exe | Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com |
| X | Windows Defender | WinDefender.exe | Added by the FAKEAV-CLZ TROJAN! Note - this is not the legitimate Microsoft Windows Defender whose filename is MSASCui.exe |
| X | Windows Defender Adds | wda*.exe | Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com |
| X | Windows Defender Monitor | wdm*.exe | Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com |
| X | Windows Defender Updater | wdu*.exe | Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com |
| X | WINDOWS DENEME | deneme.exe | Added by the MYTOB-CR WORM! |
| X | Windows Desktop | services.exe | Added by the DWNLDR-JAN TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Windows Desktop Controler | windesktop.exe | Added by the SDBOT-XH WORM! |
| X | Windows Desktop Daemon | winpadg.exe | Added by a variant of the SPYBOT WORM! |