| Status | Autorun name | Aufruf | Beschreibung |
| X | Windows Firewall Updater | ctfcom.exe | Added by the RBOT-GCB WORM! |
| X | Windows Firewall Updater | windowsupdate.exe | Added by the SPYBOT.AVEO WORM! |
| X | Windows Firewalll | scvhost.exe | Added by the RBOT-EK WORM! |
| X | Windows Firewalll | sphost.exe | Added by a variant of the RBOT WORM! |
| X | Windows Firewalll | svvhost.exe | Added by a variant of the RBOT WORM! |
| X | Windows Firewalll | winmu.exe | Added by a variant of the RBOT WORM! |
| X | Windows Fix | integator.exe | Added by the SDBOT.ZAB WORM! |
| X | Windows Fixer | winfix.exe | Added by the VIRUT-I VIRUS! |
| X | Windows Fixes Systems | elite.exe | Added by the MYTOB.EG WORM! |
| X | Windows Font Manager | smss.exe | Added by the ZANAYAT.B WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\fonts |
| X | Windows FormatAd | WinForm.exe | WindUpdates Windows FormatAd adware |
| X | Windows Frame Works | frmwrks32.exe | Added by a variant of the RBOT WORM! |
| X | Windows Framework | frmwrk.exe | Added by the DWNLDR-GWV TROJAN! |
| X | Windows Framework | scvh0st.exe | Malware installed by different rogue security software including SpyKillerPro and the XP AntiVirus series |
| X | WINDOWS FUCK BY CLASIC | fuck.exe | Added by the ZOTOB.H or ZOTOB.J WORMS! |
| X | Windows Gamma Display | wingamma.exe | Antivirus 2010 rogue security software - not recommended, removal instructions here |
| X | Windows Generic Proc | procmsg.exe | Added by the ALLIM.B WORM! |
| X | Windows Generic Services | winsvc32.exe | Added by the AGOBOT-ZF BACKDOOR! |
| X | Windows Genuine | svghost.exe | Added by a variant of the SPYBOT WORM! See here |
| X | Windows Genuine Validate | winservicessss.exe | Added by the IRCBOT.UUI BACKDOOR! |
| X | Windows Global Init | ngpsvc.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Windows GMT32 | wingmt32.exe | Added by the MYTOB.KM WORM! |
| X | Windows Graphics Loaders | wingraphics.exe | Added by the SPYBOT.JG WORM! |
| X | Windows Gras Service | wingr32.exe | Added by the SPYBOT.IZ WORM! |
| X | Windows Guard | WAUMGRD.EXE | Added by the RBOT-GY WORM! |
| X | Windows Guard Pro | WindowsGP.exe | Windows Guard Pro rogue security software - not recommended, removal instructions here |
| U | Windows Guardian | thehel1iawgrd32.exe | Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes |
| U | Windows Guardian | Fawgrd32.exe | Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes |
| X | Windows haz Layer | [5 random letters].exe | Added by a variant of the RBOT WORM! |
| X | Windows Help | mailinfo.exe | Added by the MYTOB.JX WORM! |
| X | Windows Help | Stney.exe | Added by the AGOBOT-VI WORM! |
| X | Windows Help File | winhelper32.exe | Added by the SDBOT-QK WORM! |
| X | Windows Help Manager | svchost32.exe | Added by the RBOT-OZ WORM! |
| X | Windows Help Service | winhelpsv.exe | Added by the RBOT-LP WORM! |
| X | Windows Help Service | winhlp.pif | Added by the RBOT-AKW WORM! |
| ? | Windows Help System | Help.pif | ?? |
| X | Windows Helper | winhelp.exe | Added by the BANKER.APE TROJAN! |
| X | Windows Helper | wsctnfy.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Windows Hijack Protection | comngr.exe | Added by the AGENT-FYD TROJAN! |
| X | Windows Hijack Protection System | commngr.exe | Added by the AGENT-FYD TROJAN! |
| X | Windows his Layer | pilotGame.exe | Added by the RBOT.GLX WORM! |
| X | Windows Host | hosts.exe | Added by the KELVIR.U WORM! |
| X | Windows Host | winhost.exe | Added by the PRYSAT TROJAN! |
| X | Windows Host Booter | hostbooter.exe | Added by an unidentified WORM or TROJAN! See here |
| X | Windows Host Device | hostsvc.exe | Added by the ZOOTY-A WORM! |
| X | Windows Host Name | lmass.exe | Added by the GAOBOT.O WORM! |
| X | Windows Host Service | scvhosts.exe | Added by the SPYBOT.NLI WORM! |
| X | Windows Host Service | host.exe | Added by the KELVIR.AN WORM! |
| X | Windows Host Service | svchoste.exe | Added by the KELVIR.BF WORM! |
| X | Windows Host Service | svchosts32.exe | Added by the KELVIR.AW WORM! |
| X | Windows Host32 Starter | hostserv.exe | Added by the SDBOT-WU WORM! |
| X | Windows Hosts | hosts.exe | Added by the KELVIR-O TROJAN! |
| X | Windows Hosts | winhosts.exe | Added by a variant of the IRCBOT TROJAN! |
| X | Windows HP Drivers | hpdmws.exe | Added by the SDBOT.AQU WORM! |
| X | Windows HP Drivers | winhps.exe | Added by the SDBOT.ON BACKDOOR! |
| X | Windows HTML file reader | Sysconf32.exe | Added by the NOOMY.A WORM! |
| X | Windows HTTP services | winhttps.exe | Added by a variant of the SDBOT WORM! See here |
| X | Windows Icons Manager | wicomgr.exe | Added by the RBOT-AIF WORM! |
| X | WINDOWS ID SYSTEM | wID32.exe | Added by the MYTOB.LN WORM! |
| X | Windows Identify | sysays.exe | Added by a variant of the SPYBOT WORM! See here |
| X | Windows Image | wintimage.exe | Detected by Avast as the SDBOT-GEN44 WORM! |
| X | Windows Image Acquisition (WIASC) | WIAcs.exe | Added by the RIZO.A TROJAN! |
| X | Windows Image Acquisition (WIASSC) | WIAcss.exe | Added by the RIZO.A TROJAN! |
| X | Windows iMessenger Messenger | winimsg.exe | Added by the ALLIM.A WORM! |
| X | Windows Incontext | InSearch.exe | PacerD_Media/Pacimedia.com/Z-Quest adware installer |
| X | WINDOWS INIT | wininit.exe | Added by the ZOTOB-K WORM! Note - this is not the legitimate wininit.exe process from Vista/7 which is always located in %System% and should not normally figure in Msconfig/Startup! |
| X | Windows Insecure | [path to worm] | Added by the RBOT-FSM WORM! |
| X | Windows installer | winstall.exe | SpySheriff rogue spyware remover - not recommended, removal instructions here |
| X | Windows Installer | ntdll.exe | Added by an unidentified WORM or TROJAN! |
| X | Windows Installer 1 | msnconfig.exe | Added by the PURITYSCN.B TROJAN! |
| X | Windows Instruction Services | winstruct32.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Windows Interet Explorer 6 | wmidx32.exe | Added by the RBOT.AOW WORM! |
| X | Windows Internet Browser Services | internet.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Internet Browser Services | internet128.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Internet Browser Services | internet32.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Internet Browser Services | internet64.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Internet Explorer 6 | firefox.exe | Added by the SPYBOT.ANA WORM! Note - this is not the Mozilla Firefox web browser which is always located in %ProgramFiles%\Mozilla Firefox. This file is found in %System% |
| X | Windows Internet Manager | svchost.exe | Added by the IRCBOT-AAC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Windows Internet Protocol | winproc32.exe | CoolWebSearch Winproc32 parasite variant - also detected as the STARTPA-BF TROJAN! |
| X | Windows Internet Protocol | deinst_qfe001.exe | Added by a variant of the Win32.Small TROJAN! |
| X | Windows Internet Service | wininet.exe | Added by the RBOT-AUX WORM! |
| U | Windows IP Security | ipsec.exe | Related to the VPN IPSec utility - used to create Security Policy (SP) entries and Security Association (SA) entries in the kernel |
| X | Windows IP Security Service | ipsecs.exe | Added by the RBOT.BPW WORM! |
| X | Windows IPv6 Drivers | wipv6.exe | Added by the SDBOT-VJ WORM! |
| X | Windows Java Update | weatherBug32.exe | Added by a variant of the RBOT WORM! |
| X | Windows JavaScript Daemon | Winjsd.exe | Added by the WOOTBOT.AF WORM! |
| X | Windows Javascript Daemon | jsdaemon.exe | Added by the RBOT.EK BACKDOOR! |
| X | Windows Kernel 64 | kernal64.exe | Added by the YIMP-B WORM! |
| X | Windows Kernel Log | WinKettle.exe | Added by the AGENT-HFA TROJAN! |
| X | Windows Kernel System Service | [filename].exe | Added by the RBOT-FLL WORM! Common filenames include "wkssvr.exe", "winsys.exe" and "wkssvc.exe" and they are located in %System% |
| X | Windows kev Messenger | mskev.exe | Added by the SDBOT-XV WORM! |
| X | Windows Keyboard Services | winkeyboard.exe | Added by the IRCBOT.AFS WORM! |
| X | Windows Keyboard Services | winkeybrd.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Keyboard Services | winkeybrd32.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Windows Live | msgnms.exe | Added by the XPACK.AV TROJAN! |
| X | Windows Live | WindowsLive.exe | Added by the REALBOT-A WORM! |
| X | Windows Live Care.exe | WindowsLiveCare.exe | Added by unidentfied MALWARE - see here! Do not confuse with Microsoft's Windows Live OneCare security software which is found in %ProgramFiles%\Microsoft Windows OneCare Live. This one is found in %System% and runs from both the HKLM\Run & HKLM\RunServices registry keys |
| X | Windows Live Client | msnclient.exe | Added by a variant of the IRCBOT TROJAN! See here |
| U | Windows Live Family Safety Filter | fsui.exe | System Tray access to and notifications from Windows Live Family Safety - optionally installed as part of Windows Live Essentials. "With Family Safety, you decide how your kids experience the Internet. Limit searches, monitor and block or allow websites, and decide who your kids can communicate with in Windows Live Spaces, Messenger, or Hotmail". Note - disabling this entry does not disable Family Safety and prevent it monitoring a users activity or restricting access |
| X | Windows Live Manager | winlivemgr.exe | Added by the SHEUR.EB TROJAN! |