| X | Win startup | mscfg32.exe | "Added by the SPYBOT-AE WORM!"
|
| X | Win Startup | WINCFG32.EXE | "Added by the SPYBOT-CL WORM!"
|
| X | Win32KernelStart | microsoft.exe | "Added by the DELF-EWZ TROJAN!"
|
| X | Windeows NetStart Service2 | tesakrmger.exe | "Added by the RBOT-AMY WORM!"
|
| X | WinDLL (start0s.exe) | "rundll32.exe start0s.exe | start" |
| X | Windows Audio Startup | nndsvc.exe | "Added by the IRCBOT-AAE TROJAN!"
|
| X | Windows Autostart Loader | notepad32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows CODE Fix Msy Startups | msyh32.exe | "Added by the AGOBOT.AKK WORM!"
|
| X | Windows Host32 Starter | hostserv.exe | "Added by the SDBOT-WU WORM!"
|
| X | Windows Loader | wstart32.exe | "Added by the GAOBOT.CA WORM!"
|
| X | Windows Messenger Live Startup | windowslivemsn.exe | "Added by an unidentified WORM or TROJAN! See here"
|
| X | Windows Messenger Live Startup | windowsmsnlive.exe | "Added by the DELF.DAX TROJAN!"
|
| X | Windows Messenger Starter | wmvsvc.exe | "Added by the DELF.DAX TROJAN!"
|
| X | Windows MSConfig Startup Logger | winlog.exe | "Added by the RBOT.BCU WORM!"
|
| X | Windows NetStart Service | winsN2S.exe | "Added by the RBOT-ZX WORM!"
|
| X | Windows NetStart Service2 | winsN2S.exe | "Added by the RBOT-ABN WORM!"
|
| X | Windows NetStart Service2 | winsN2SD.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Registry Startup | wind32.exe | "Added by the AGOBOT-BZ WORM!"
|
| X | Windows Service | dstart4.exe | Added by an unidentified TROJAN!
|
| X | Windows Start Server 2000 | traficy.exe | "Added by the RBOT-AHM WORM!"
|
| X | Windows Startup | winsta~1.exe | "GoHip foistware"
|
| X | Windows Startup | winstartup.exe | "GoHip foistware"
|
| X | Windows Startup | Wdrun32.exe | "Added by the GAOBOT.AO WORM!"
|
| X | Windows Startup | services21.exe | "Added by the AGOBOT-MX WORM!"
|
| X | Windows Startup | Winsys32.exe | "Added by the RBOT.AAB WORM!"
|
| X | Windows Startup 32 Bits | sysrun32.exe | Added by a variant of the DARKSUN TROJAN!
|
| X | Windows User Starter | winuser32.exe | "Added by the RBOT.SN WORM!"
|
| X | Windows Workstation Start Service | mslanmgr.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows32KernelStart | wks.exe | "Added by the LAPURD TROJAN!"
|
| X | WindowsServicesStartup | svchost.exe | "Added by the ECUP WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
|
| Y | WinFaxAppPortStarter | wfxsnt40.exe | WinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application.
|
| X | Winsock Startup | Main2.exe | "Added by a variant of the SDBOT WORM!"
|
| X | WinStart | services.exe | "Added by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Connection Wizard\Status and note the space at the beginning of the ""Startup Item"" field"
|
| X | WinStart | WinStart.exe | "From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words |
| X | WinStart | Wscript.exe WinStart.vbs | "Added by the CIAN.C WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""WinStart.vbs"" file is located in %System%"
|
| X | WinStart | winstart32.exe | "Added by the PUROL WORM!"
|
| X | WinStart | WinStart.pif | "Added by the CONE.E WORM!"
|
| X | winstart | winstart.exe | "Added by the SCKEYLO-AB TROJAN!"
|
| X | WinStart001 | WinStart001.exe | "From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words |
| X | WinStart001.EXE | WinStart001.exe | "From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words |
| X | WinSysStartUpWKbLw | TaskSystemDll.Exe | "Added by the BACKZAT.G WORM!"
|
| U | WireLessMouse | StartAutorun.exe MouseDrv.exe | "Related to WireLess Mouse Multimedia Combo Set by SANSUN Industries"
|
| X | wormexe | winstart.exe | "Added by the EARLYBIRD WORM!"
|
| ? | xkstartup | "RunDll32 InstZ82.dll | SetUsbPrinterPort" |
| X | xmstart | xuming.exe | "Added by the GMIN-A WORM!"
|
| X | xpstart | wini.exe | "Added by the PICRATE.A WORM!"
|
| X | Xupiter Startup | XupiterStartup.exe | "Xupiter - adware and homepage hijacker. Use Spybot S&D |
| X | xupiterstartup2003 | xupiterstartup2003.exe | "Xupiter - adware and homepage hijacker. Use Spybot S&D |
| X | Zekio Startups | znksvc32.exe | "Added by the AGOBOT-AGI WORM!"
|
| X | Zekio Startups | condll.exe | "Added by the AGOBOT-AGD WORM!"
|
| X | ZStart | [various filenames] | "VX2.Transponder parasite updater/installer related"
|
| X | Zstart | cxdxregt.exe | "ZenoSearch adware"
|
| X | Z_Start | [random filename] | "ZenoSearch adware"
|
| X | [Randomly chosen existing folder name] | _start.exe | "Added by the ANTINNY-L WORM!"
|
| X | [various names] | dstart2.exe | "Adware - detected by Kaspersky as the SMALL.ALW TROJAN!"
|
| X | [various names] | StartCpl.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | startman.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | _WinStart | services.exe | "Added by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Connection Wizard\Status"
|