Windows Vista Tips


Files beginning with w

The table below includes any files beginning with w, from which further information can be found by clicking on the process title. The icon beside the information can be used to quickly determine if this is a safe file in combination with the key below:



This file is normally safe to leave running. In most cases, this file is not required to run on startup and can be run manually. Warning, this file may be a virus, spyware, resource hog and running it is not recommended. This file may or may not be necessary to load on startup, depending on your circumstances. No information is available for this item.

[#] [A] [B] [C] [D] [E] [F] [G] [H] [I] [J] [K] [L] [M] [N] [O] [P] [Q] [R] [S] [T] [U] [V] [W] [X] [Y] [Z]

Files beginning with w:

File Type File Name Process Name and Information
winrecon.exe !NoLoad
WinRecon keystroke logger/monitoring program - remove unless you installed it yourself!
winSOCKS.exe (*)API Machine
Homepage hijacker, see here (* = any digit)
win32API.exe (*)Run
Homepage hijacker, see here (* = any digit)
winhelp.exe (Default)
Added by the BLACKMAL.C WORM! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank
winbas12.exe (Default)
Adware, CoolWebSearch parasite related - detected by Kaspersky as the VB.DU TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank
winlog.exe (Default)
Unidentified adware. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank
winligom.exe (Default)
Added by the RBOT-GAI WORM! Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run, HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank
wstcl.exe *Microsoft Update
Added by the STMU TROJAN!
wucxt.exe *Microsoft Update
Added by the STMU TROJAN!
wuytc.exe *Microsoft Update
Added by the STMU TROJAN!
WerFault.exe *WerKernelReporting
Part of Windows Error Reporting technology (WER) for Vista. WER captures software crash and hang data from end-users who agree to report it - see here
wrauclt.exe *windows update
Added by the RBOT-QU WORM!
wuanclt.exe *windows update
Added by the RBOT-PG WORM!
wuaucrlt.exe *windows update
Added by the SPYBOT.HUR WORM!
wuraclt.exe *windows update
Added by the RBOT-PO WORM!
wurauclt.exe *windows update
Added by the RBOT-SY WORM!
wsctl.exe *windows update
Added by the SPYBOT.PR WORM!
wkmst.exe *windows update
Added by the SDBOT.AVD WORM!
wscxt.exe *windows update
Added by the RBOT.AOS WORM!
waurclt.exe *windows update
Added by a variant of the RBOT WORM!
winstats.exe *winstats
Added by the GARGAFX TROJAN!
w****.exe [* = random char] *wuauclt.exe
Added by a variant of the RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe, wtmsv.exe, wxmst.exe, wmsvc.exe and so on...
wininfo.exe ,main drive Loader
Suspected malware as it appears in 3 different registry locations - see here
winlogon.exe .Prog
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
WARN0190.EXE 0190 Warner
Anti-dialer program (Germany)
WARN0900.EXE 0900 Warner
Anti-dialer program (Germany)
WebMailSpy.exe 1WinCfg32
WebMailSpy spyware
winmgr.exe 252
Added by the LEGMIR-AT TROJAN!
winlog0n.exe 9m
Added by the LEGMIR-AQK TROJAN!
wincms.exe @
Added by the RBOT.CBR WORM!
w32NTupdt.exe A New Windows Updater
Added by the MYTOB.BM WORM!
winpppoverethernet.exe a-winpoet-service
WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking
winsto.exe Access Control App
Detected by Kaspersky as the AGENT.DGO TROJAN! See here
wcescom32.exe ActiveSync
Added by the MANCSYN-E TROJAN!
wini.exe AdAware
Added by the RBOT-XN WORM!
winlogon.exe Administrator
Added by the RUBBLE-C WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
windrv.exe ADriver
Added by the DELF.WG TROJAN!
windefault.exe AFAFilter
AFAFilter - internet filter software
WinServ.exe AKEYNAME
Added by the EVILBOT.C TROJAN!
winoff.exe AMP WinOFF
WinOFF is " a utility designed to shut down Windows computers automatically, in a fully configurable way"
WZCSLDR2.exe ANIWZCS2Service
ALPHA Networks wireless driver
WZCSLDR.exe ANIWZCSService
D-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity
winsp3.exe Anti-Virus Update Scheduler
Malware - detected by Kaspersky as the AGENT.FP TROJAN!
winlog.exe AntiVir
Added by the IRCBOT-TJ TROJAN!
winapix.exe APIMon
Added by a variant of the TIBSER.A downloader TROJAN!
WN511B.exe AS00_WN511B
Netgear RangeMax NEXT wireless adapter configuration utility
WPN511.exe AS00_WPN511
NetgearRev MFC Application - software for Netgear wireless network cards - what does it do and is it required in startup?
windfind.exe atisrc2
Added by the WINDFIND-A TROJAN!
winfp.exe Audio Device Manager
Detected by PCTools as the IRCBOT.BIV TROJAN! See here
WinNT.exe Audio Device Manager
Added by the BANKER.BTG TROJAN!
WNDXP.exe Audio Device Manager
Detected by Kaspersky as the IRCBOT.AJL TROJAN! See here
wintmr.exe Authentic-ID Toolbar
System Tray access to Child Control parental control software by Salfield
win32.exe auto
Added by the SMALL!SD5 TROJAN!
WindowsSys32.exe Auto Updat
Added by a variant of the FORBOT WORM!
windowsupdate.exe autoload
Detected by Trend Micro as the POLYCRYP.DY TROJAN! See here
wauclt.exe Automated Windows Updates
Added by the GAOBOT.AJD WORM!
winmain.exe autorun
Added by a variant of the DELF.CNS TROJAN!
WINUP2DATE.DLL, SHStart autoupdate
Unidentified adware - detected by Panda antivirus as the CLICKER.CY TROJAN!
wlangui.exe AVMWlanClient
Related to broadband products from avm.de
win*.tmp.exe [* is a number] avp
Added by a variant of the ALPHABET TROJAN!
WErcx.exe AvpWx
Detected by Kaspersky as a variant of the AGENT.A TROJAN!
winupdate.exe blah service
Added by the GAOBOT.BIA WORM!
winsysengine.exe blah service
Added by the RBOT-KI WORM!
win32.exe blah service
Added by the RBOT-AXO WORM!
WLANmon.exe Blitzz BWI715
Blitzz Technology BWI715 Wireless PC modem connection monitor
wscript.exe [path] Date.POP.vbs BootsCfg
Added by the KUULLIO WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted
wscript.exe [path] All Users.vbs BootsCfg
Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted
wscript.exe [path] All Users.vbe BootsCfg
Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted
wscript.exe Install.log.vbs BootsCfg
Added by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "Install.log.vbs" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
wavepcmonitor.exe Bose Wave/PC Monitor
System Tray access for this system (more info on the system here). Available via Start -> Programs
winlogin.exe BossIdea
Added by the LINEAGE-I TROJAN!
wltray.exe Broadcom Wireless Manager UI
System tray access to wireless LAN card configuration options
winlogon.exe BuildLab
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
Wininit.exe Bymer.Scanner
Added by the BYMER WORM!
WinTask.exe C:WINDOWSWinTask.exe
"Pop Marketing" adware
WindowsSec.exe Cable Modem Adapter
Added by the WOOTBOT.A WORM!
wincalc.exe Calc Microsoft Windows
Added by an unidentied WORM or TROJAN!
WMADZ.EXE ccApp
Added by the RBOT-LJ WORM!
winlogon.exe ccApps
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
wintmr.exe CCWinTray
System Tray access to Child Control parental control software by Salfield
windrv.exe CDriver
Added by the DELF.WG TROJAN!
wsot.exe CEPA
??
WinMuschi.exe CFDStart
WINMUSCHI dialler
wiseupdt.exe Check for One Touch Update
Checks for updates for Visioneer OneTouch scanners
WiseUpdt.exe Check for TWS Updates
Interactive Brokers - check for update to their standalone Java-based trading platform
webtmr.exe ChicoSys
Child Control parental control software
W95AGENT.EXE Client agent for ARCserve
Part of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required?
wup.exe Client Update
Added by the OPANKI.O WORM!
winjes.exe Compaq Jes Drivers
Added by the SDBOT-XR WORM!
wincmd.exe Compaq Service Drivers
Added by the RBOT.ATV WORM!
wind32.exe Compaq Service Drivers
Added by a variant of the SDBOT WORM!
winmsn.exe Compaq Service Drivers
Added by a variant of the SDBOT WORM!
winsvc.exe Compaq Service Drivers
Added by the SDBOT-AGD WORM!
wstray.exe ComTry Web Searcher
Comtry MP3 Downloader related - spyware
WinService32.exe Config
Added by the CRUTCHA-A TROJAN!
winsys32.exe Config Loadr
Added by the AGOBOT-HN WORM!
Wuxat.exe Configuration Default
Added by the SPYBOT-CA WORM!
Winset32.exe Configuration File
Added by the FLUX.101 TROJAN!
wupdated.exe Configuration Loaded
Added by the MOEGA or MOEGA.AG or MOEGA.AP WORMS!
wincrt32.exe Configuration Loader
Added by the GAOBOT.BF WORM!
windex.exe Configuration Loader
Added by the GAOBOT.BZ WORM!
Winreg.exe Configuration Loader
Added by the GAOBOT.AO WORM!
winicfg32.exe configuration loader
Added by the GAOBOT.RQ WORM!
wincffg.exe Configuration Loader
Added by the AGOBOT.A3 WORM!
WinHelper.exe Configuration Loader
Added by a variant of the AGOBOT/GAOBOT WORM!
wincore.exe Configuration Loader
Added by the SDBOT.BHE WORM!
Winsys32.exe Configuration Loader Service
Added by the RBOT-YV WORM!
wscel.exe Configuration Loading Service
Added by the SDBOT-WJ WORM!
wlanutil.exe Configuration Utility
NetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards)
winamp32.exe Configuration32 Loader32
Added by the SDBOT-BIC WORM!
winservn.exe ContentService
Homepage hijacker
WFXCTL32.EXE Controller
From Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
winlogin32.exe cpanel
Added by the RBOT-FOY WORM!
wincomp.exe cpntmgc
Added by the WINTRIM_A TROJAN!
winmgts.exe cpntmgc
Added by the WINTRIM-B TROJAN!
wuitgurd.exe CPU Temp Control
Added by the RBOT-AHV WORM!
world_cup_.bat cqlyg
Added by the WCUP.A WORM!
Wucrtupd.exe CriticalUpdate
MS Windows Critical Update Notification. If you want to keep Windows up-to-date, check the Windows Update site
wucrtupd.exe CriticalUpdate
Added by the NOALA.B WORM! Note - this file is located in the Windows or Winnt folder, and must not be confused with the legitimate Windows process of the same name as described here
WinConst.exe ctfmon
Added by the ASSASIN-G TROJAN!
WINLOGON.EXE CueX44_stil_here
Added by the PUNYA-A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
WLANMON.exe D-Link AirPlus DWL-650+ Utility
D-Link Air Plus Wireless PC modem connection monitor
weather.exe Daily Weather Forecast
Added by the DLOADER-IP TROJAN!
W815DM.EXE ddhelper
Enuff Parental Control Software by Akrontech
windrv.exe DDriver
Added by the DELF.WG TROJAN!
worm.exe Delete Me
Added by the DOOMHUNTER WORM!
wltray.exe Dell Wireless Manager UI
System tray access to wireless LAN card configuration options
wfxmgr.exe Device Manager
Added by the RBOT.AJU WORM!
win.exe Distributed File System
Added by the MYFIP.AB WORM!
WATCH.exe DLHelperEXE
Download helper distributed with some software that allows the software installation to redirect download locations. Not required once the installation is finished
windfe.exe DLINK dfe drivers for Windows NT
Added by the RANDEX.AK WORM!
wakeservice.exe DomPlayer Service
DomPlayer adware
WindowsUpdate.exe DRam prosessor
Added by the RBOT-BBZ WORM!
winupdaterar.exe DRam rar proc
Added by a variant of the IRCBOT TROJAN!
W95Mm.exe drmu
Homepage hijacker installing a toolbar: http://tdko.com/. Lop.com in disguise
windspl.exe DsplObjects
Added by the BEAGLE.DN WORM!
windrv.exe DSystemDriver
Added by the DELF.WG TROJAN!
weather.exe Dulux WeatherShield WeatherDesk
Dulux WeatherShield WeatherDesk - latest weather information from across Australia
windvd98.exe dvd98
Added by the CULT.P WORM!
wsxsvc.exe Dvx
Delfin Media Viewer or "Promulgate" adware variant
Weather.exe DW4
Desktop Weather
winxp34.exe Dynamic Dns Binary
Added by a variant of the RBOT WORM!
WinHelpcfn.exe Dynamic Dns Binary
Added by a variant of the RBOT WORM!
wizard.exe EAPCISETUP
Part of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation
wjview ...Code EbatesMoeMoneyMaker
Ebates adware
watch.exe Eicon NetworksLAN_DAEMON
Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually
watch.exe Eicon TechnologyLAN_DAEMON
Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually
Winmsuit.exe ELSA WINman Suite
Allows you to totally customize your ELSA graphics card settings, including overclocking the GPU
wintr.com encapsulated command tool
??
WMENCAGT.EXE Encoder Agent
MS Windows Media Encoder, which already has a shortcut in the Start Menu if installed
wsys.exe Enumerate Service
Added by the MANIFEST TROJAN!
wind2ll2.exe erfgddfk
Added by the BEAGLE.CQ WORM!
windlhhl.exe erghgjhgdr
Added by the BEAGLE.BG WORM!
windlhhl.exe erghgjhjgdr
Added by the BEAGLE.BG or BEAGLE.BH or BEAGLE.BI or BEAGLE.BJ WORMS!
windll2.exe erthegdr
Added by the BEAGLE.CG WORM!
windll.exe erthgdr
Added by the BEAGLE.AO or BEAGLE.AQ WORMS!
winfw.exe eTunnel
Added by an unidentified TROJAN!
Warm.scr ExeName32
Added by the SCOLD WORM!
wscript.exe [filename] explorer
Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted
Windows Explorer.exe Explorer
Added by the SILLYFDC-I WORM!
winset.exe exporet
Added by the QQPASS-I TROJAN!
wo.exe eZWO
eZula TopText adware
wincfg.exe Fantasia injector
Added by the AGOBOT.US WORM!
windrv.exe FDriver
Added by the DELF.WG TROJAN!
wmiprvsc.exe File System Service
Added by the AGOBOT-HZ TROJAN!
wtm.exe FileFreedom_Plugin
FileFreedom peer-to-peer sharing program
Wscript.exe ChkMgr32.vbs FileManager32
Added by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "ChkMgr32.vbs" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
Wscript.exe UpdataFiles.vbs FileSoft
Added by the SST.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "UpdataFiles.vbs" file is located in the Winnt or Windows folder
wuaclt.exe FireFox Startup Drivers
Added by the RBOT.BYX WORM!
wmlaunch .exe Firewall
Added by the ELIPTER.A or ELIPTER.B WORMS!
wmlaunch .exe Firewall
Added by the ELIPTER.D WORM!
winlogon.exe Firewall auto setup
Added by a TROJAN - see here. Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
WinedowsUpdater1.exe Firewall Update System1
Added by the RBOT-ARU WORM!
WinFIX1.0.vbs FIX
Added by the GORMLEZ-A WORM!
wssdtu.exe Folder Service
Added by the MANIFEST TROJAN!
WINFAH.EXE Folding@home
Folding@Home is a distributed computing project which studies protein folding, misfolding, aggregation, and related diseases - must be running in order to access the internet to upload to the servers. Available via Start -> Programs
winlogon.exe FriendlyTypeName
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
winpopup.exe Fromine WinPopup
Instant Messenger program
winsvc.exe Generic Host Process for Win32 Services
Added by the SDBOT-O WORM!
winsvc32.exe Generic Host Process for Win32 Services
Added by the SDBOT-P WORM!
winlogon.exe Generic Host Process for Win32 Services
Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!
WinLoaderXP.exe GenericHostXP
Added by the BDOOR-ACX TROJAN!
Winmod32.exe Gerenciamento de arquivos do Windows
Added by the DLOADER-WG TROJAN!
winsystems.exe german.exe
Added by the BAGLEDl-AE TROJAN!
wintems.exe german.exe
Added by the BAGLE-AS TROJAN!
wakeservice.exe Get-Torrent Service
Get-Torrent bittorrent client - Installs LOP adware
winB_.exe getwin
Added by the BANKER-HS TROJAN!
WinDash.EXE Global Startup
Detected by Kaspersky as the VB.Q WORM!
window.exe gpmce
Detected by Kaspersky as the VB.CK WORM! See here
windll.exe Graphics adapter service
Added by the ATNAS.A WORM!
wscript.exe gpremier.vbs gremier
Added by the GPREMIER WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "gpremier.vbs" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
WCESCOMM.EXE H/PC Connection Agent
Active sync for use with Windows CE based palm PC
WinHSD.exe Hardware Shell Detection
Added by a variant of the RBOT WORM!
Wizardnil.exe Help
Added by the BANCOS-BCZ TROJAN!
windowsupdate.exe HKLMRun
Added by the FORBOT-BJ WORM! (where HKLMRun represents HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun)
wiz98.exe hostserv
Added by a variant of the SDBOT WORM!
winHostsEdit.exe HostsFileMgr
AdBin from Gilmore Software Development. An easy solution to managing your Window's hosts file
We Love Lien Van de Kelder.exe http://www.lienvandekelder.be
Added by the MYTOB-CV WORM!
winsys.exe I am not Ranky. I am eTunnel!
Added by an unidentified WORM or TROJAN!
winlog.exe icq lite
Added by the IRCBOT-TJ TROJAN!
winlogon.exe ICQ Net
Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!
webcamupdate.exe IcqBeta
Added by an unidentified TROJAN!
winlogon.exe ICQNet
Added by the NETSKY-C WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
wini.exe IE Runtime
Added by the PICRATE.B WORM!
winis.exe IE Runtimes
Added by the RBOT-ADZ TROJAN!
wkstmg.exe IE6
Added by a variant of the SDBOT WORM!
winsnt.exe IE6
Added by the RBOT-GOV WORM!
WinSock.exe IExplorerService
Detected by Kaspersky as the AGENT.KIU TROJAN! See here
WashIdx.exe Index Washer
Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
wsock32.exe InetServices
Added by the WOCK32-A TROJAN!
wmplayer.exe infamous.exe
Added by unknown malware. WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup. Infamous.exe is identified by Panda antivirus as Trj/Briss.A
WUSB11cfg.exe Instant Wireless Configuration Utility
Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration
WPC11Cfg.exe Instant Wireless Configuration Utility
Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration
wing32.exe Intec Service Drivers
Added by the RBOT.HAZ WORM!
winrvc.exe Intec Services Driverrs
Added by a variant of the SDBOT WORM!
winnook.exe Intel system tool
Added by the SPYRE-C TROJAN!
WinSocks5.exe internct
Added by the GRAYBIRD.F TROJAN!
winlogom.exe Internet
Added by a variant of the SDBOT WORM!
winsas32.exe internet
Added by a variant of the SDBOT WORM!
wins.exe Internet
Detected by PCTools as the RBOT.AAYF WORM! See here
winz32.exe INTERNET SERVISES
Added by the KWBOT.Z WORM!
wkfix.exe Internet2 Optimizer
Added by a variant of the RBOT WORM!
windows.exe InternetExplorer2
Added by the SDBOT-CZP WORM!
winz32.exe INTERNET_SERVISES
Added by the SDBOT.Q TROJAN!
WINDRV.EXE InterU
Added by the IRCINTER.A TROJAN!
WinCinemaMgr.exe Intervideo Win Cinema Manager
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
WINCIN~1.EXE Intervideo Win Cinema Manager
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
WinCinemaMgr.exe Intervideo WinCinema Manager
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
WINCIN~1.EXE Intervideo WinCinema Manager
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
WinScheduler.exe Intervideo WinScheduler
WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs
wnmgre.exe IPC Spool Manager
Added by the SDBOT-ZC WORM!
winspec.exe IPC Spool Manager
Added by the SDBOT-BLU WORM!
Winipcfgs.exe IPTable Configuration
Added by a variant of the RBOT WORM!
winmon32.exe iRis Active Monitor
Iris Antivirus - discontinued, replace with good alternative
WIMMUN32.exe iRiS AntiVirus Active Monitor
Iris Antivirus - discontinued, replace with good alternative
wintmp.exe ISPSERVICE
Detected by Trend Micro as the FLOOD.BC BACKDOOR! See here
winlogan.exe jkdfj94kgdftdf
Added by the ZLOB.BZ TROJAN!
winxp2.exe Jufualt
Added by the SDBOT-AAB WORM!
win1ogoin.exe KAVFOX
Added by the GWGHOST-M TROJAN!
wscntfy.exe KAVPersonal90
Added by the BANKER-FZ TROJAN!
Windll.exe KavRuns
Added by the TRYNOMA TROJAN!
winser.exe KernelCheck
Added by the TSPY_LMIR.SL TROJAN!
wmiprvse.exe Kernel_check
Added by the SONEBOT-B WORM! Note - this is not the legitimate wmiprvse.exe process which is always located in the System32wbem folder and should not normally figure in Msconfig/Startup!
winxp.exe key
Added by the BEAGLE.AG WORM!
winlog.exe key2
Added by the BAGLEDI-AL TROJAN!
wppewafaj.exe KnowledgeBase GUI
Added by the RBOT-GRZ WORM!
word.EXE KV2005
Added by the IW TROJAN!
winmine l44sys**
Added by the VBS.LIDO WORM - where ** is a number between 33 and 44
wllmsngr.exe Live Messanger
Added by a variant of the IRCBOT BACKDOOR! See here
win32.exe Load
Added by the RUBBLE-A WORM!
Wscript.exe LGuarg.exe.vbs Load-Guard
Added by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "LGuarg.exe.vbs" file is located in the Winnt or Windows folder
winldra.exe load32
Added by the NIBU.J BACKDOOR or DUMARU-BI TROJAN! Note - also known as Srv.SSA-KeyLogger by Sunbelt Software which has developed a free removal tool for this keylogger
WPSLOAD.EXE load=
Windows printing system that comes with the setup for Canon BJC series on the manufacturer's disk
WINOSCFG.EXE load=
Could it be something to do with configuring Windows on a new PC from an OEM supplier?
wpshrc.exe load=
Required to prevent configuration errors on a Compaq LBP-660 and LBP-460 parallel port laser printers (and maybe others)
wtfeat.exe Load=
Associated with the Wintab Digitizer
win32exec.exe load=
Added by the BITTER WORM!
WMPLAYER.EXE loader
Unknown baddie - WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup
wmimgr.exe LoadPFW
Added by the QEDS-B WORM!
watcher.exe LoadWatcher
Watcher spyware
winset.exe loadwin
Added by the QQPASS-I TROJAN!
winsys.exe loadwin
Added by the QQPASS-J TROJAN!
winlog.exe Login
Salfeld Child Control - parental control software
wrcam.exe Logitech Desktop Controller
Added by a variant of the RBOT WORM!
wincalc.exe LogService
Added by the PAPROXY TROJAN!
WIWT.EXE longos
Added by the BANKER-CD TROJAN!
wfdmgr.exe LSA
Added by the MYTOB.C WORM!
woekd.exe Lsass
Added by an unidentified WORM or TROJAN!
winupdate.exe LTM2
Added by the LITMUS.203 TROJAN!
winscan.exe LTM2
Added by the LITMUS-B TROJAN!
winvers16.exe LTM2
Added by the SMALL.ND TROJAN!
wusas.exe Machine Update Soft
Added by an unidfentified WORM!
WMIPRVSW.exe machine-debugger
Added by the AGOBOT.U WORM!
wintrims.exe MC
Added by the WINTRIM TROJAN!
WINTRIM.EXE MC
Added by the WINTRIM_A TROJAN!
Win32.dll.vbs mcafee
Added by the CATCHER-B WORM!
WebScanX.exe McAfeeWebscanX
From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc
wisp.exe MCX Update
Added by the RBOT-AQH WORM!
winy.exe MD IE Plugin
Adware
wmplayer.exe Media Player
Added by the AGOBOT-BM WORM!
wowdache.exe Meeting Connection
Added by the PPDOOR-D TROJAN!
Wmsngr.exe Messenger
Added by a variant of the RBOT WORM!
winldx32.exe Microfot Update
Added by a variant of the RBOT WORM!
winssx.exe Microft Update 32
Added by the RBOT-AQS WORM!
wdfmrg.exe Micromedia Flash Update
Added by a variant of the SDBOT WORM!
winmx32.EXE MICROSFT MX UPDATE SUPPORT
Added by the IRCBOT-FD WORM!
wilogon32.exe Microsof Winlog Host
Added by the RBOT.XC WORM!
winampaa.exe Microsoft
Added by a variant of the IRCBOT BACKDOOR! See here
winline.exe Microsoft
Detected by Kaspersky as the AGENT.KT TROJAN! See here
wplayer.exe Microsoft
Detected by Kaspersky as the RBOT.GHZ BACKDOOR! See here
win32.exe Microsoft
Added by the DARKMOON TROJAN!
wuauclt.exe Microsoft
Added by the QQROB-AQ TROJAN! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup!
wcsntfy.exe Microsoft
Added by the AGOBOT-AHT WORM!
windl32.exe Microsoft
Added by the SDBOT-DCZ WORM!
WinSecUp.exe Microsoft
Added by the RBOT-GPL WORM!
wsim32.exe Microsoft
Added by the RBOT-GTL WORM!
wplayer.exe Microsoft
Detected by Kaspersky as the RBOT.DYU TROJAN! See here
wuauclt.exe Microsoft (R) Windows Update Service
Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup!
wuapdate16.exe Microsoft 16Bit Update
Added by the RBOT.CZ WORM!
wupdt64.exe Microsoft 64 Bit Runtime Updater
Added by a variant of the RBOT WORM!
winupdate.exe Microsoft auto update
Added by the BMBOT TROJAN!
WINHLP16.EXE Microsoft Auto Update
Added by the RBOT.GY WORM!
wuauclt.exe Microsoft auto update
Added by the CULT-B TROJAN! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup!
wincmd.exe Microsoft Command Line
Added by a variant of the RBOT WORM!
wurmgrd32.exe Microsoft ConfgKeys
Added by the RBOT-ARX WORM!
windowz.exe Microsoft Corp SSL Certificates
Added by the RBOT-GCZ WORM!
wupdates.exe Microsoft Corp Updates
Added by the RBOT-AUU WORM!
webcp.exe Microsoft CP Web Manager
Added by the IRCBOT.HP TROJAN!
wincrs.exe Microsoft Crs Fix Serv
Added by the SDBOT.BWF WORM!
wupades.exe Microsoft DDE Control
Added by a variant of the SDBOT WORM!
wuamgrd.exe Microsoft DirectX
Added by the SDBOT.MY WORM!
wkssr.exe Microsoft dll Host Service
Added by a variant of the SDBOT WORM!
winlib32.exe Microsoft DLL Library
Added by the ATNAS.A WORM!
windll.exe Microsoft Dll Management
Added by the RBOT-MT WORM!
winavguard.exe Microsoft DLL Verifier
Added by the SDBOT.AAD WORM!
windrv.exe Microsoft Driver Control
Added by the SDBOT.FW WORM!
WSconf.exe Microsoft Drivers
Added by a variant of the SDBOT WORM!
wserb32.exe Microsoft ErgoPack
Added by the RBOT-RI WORM!
wuamngr32.exe Microsoft Excell
Added by the RBOT-QH WORM!
wmgrdf.exe Microsoft File Demand Manager
Added by a variant of the RBOT WORM!
wnpzjpuw.exe Microsoft FixUp
Added by a variant of the SDBOT WORM!
wupdate.exe Microsoft Generic Update Manager
Added by the RBOT-AWC TROJAN!
WINHOSTING.EXE Microsoft Hosting Service
Added by the RBOT.AEV WORM!
windows32.exe Microsoft Internet
Added by the SDBOT-F WORM!
wincfg16.exe Microsoft Internet
Added by a variant of the SDBOT WORM!
wcumrg.exe Microsoft Intrenet Explorer
Added by the SDBOT-AFD WORM!
win64.exe Microsoft IT Update
Added by the RBOT.GA WORM!
winn43.exe Microsoft IT Update
Added by a variant of the RBOT WORM!
win43.exe Microsoft IT Update
Added by the RBOT-SA WORM!
windows.exe Microsoft IT Update
Added by the RBOT-GL WORM!
winsyst32.exe Microsoft IT Update
Added by the RBOT-FC WORM!
winscr32.exe Microsoft Java Virtual Machine
Added by a variant of the WOOTBOT WORM!
Windows_kernel32.exe Microsoft Kernel
Added by the NETSKY.AE WORM!
winlogin.exe Microsoft Login
Added by the RBOT-AJP WORM!
wintcp32.exe Microsoft Lsass Service
Added by a variant of the IRCBOT TROJAN!
winjava.exe Microsoft Machine
Added by a variant of the AGOBOT/GAOBOT WORM!
winmplayers.exe Microsoft media
Added by a variant of the SPYBOT WORM!
winmplayer.exe Microsoft media services
Added by the RBOT.ZO WORM!
winmes.exe Microsoft MediaScope
Added by the RBOT-XU WORM!
wdgmr32.exe Microsoft MicroP Protocol
Added by a variant of the RBOT WORM!
winexec32.exe Microsoft NT Update
Added by a variant of the RBOT WORM!
winupdates.exe Microsoft Office Start
Added by the GAOBOT.BC WORM!
windr128.exe Microsoft Problem Doctor
Added by the SMALLTRO.EF TROJAN!
windr32.exe Microsoft Problem Doctor
Added by a variant of the SMALLTRO.EF TROJAN!
windr64.exe Microsoft Problem Doctor
Added by a variant of the SMALLTRO.EF TROJAN!
windos.exe Microsoft Rundll
Added by the SDBOT-WF WORM!
winService.exe Microsoft Security
Added by a variant of the RBOT WORM!
wcsntfy.exe Microsoft Security Center
Added by the SDBOT.BYD WORM!
winnt.exe Microsoft Security Management
Added by the RBOT-MQ WORM!
winserv.exe Microsoft Security Management
Added by the RBOT-MJ WORM!
winamp.exe Microsoft Security Management
Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of the Program Files directory
wuauct1.exe Microsoft Security Management
Added by a variant of the RBOT WORM!
winamp.exe Microsoft Security Manager
Added by the RBOT WORM! Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of the Program Files directory. This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
windowsupdate.exe Microsoft Security Monitor Process
Added by a variant of the IRCBOT BACKDOOR! See here
windowsupdate.exe Microsoft Security Monitor Process
Added by a variant of the IRCBOT BACKDOOR! See here
wininit.exe Microsoft Security Process
Added by the RBOT-FKM WORM!
wuauct1.exe Microsoft Server Applacations
Added by a variant of the RBOT WORM!
winsvc.exe Microsoft Service
Added by the SPYBOT-DB WORM!
winlogin.exe Microsoft Service Login Manager
Added by a variant of the IRCBOT TROJAN!
winsvc.exe Microsoft Service Manager
Added by a variant of the RBOT WORM! See here
WindowsSP.exe Microsoft Service Pack
Added by the RBOT-RF WORM!
winsound.exe Microsoft Sound Technology
Added by the RBOT-AGG WORM!
win32.exe Microsoft SpA Service
Added by the RBOT.ATS WORM!
Winupd32.exe Microsoft SpA Service
Added by the RBOT.LT WORM!
win32lib.exe Microsoft Standard Executions Library
Added by the RBOT-AUK WORM!
winsocks5.exe Microsoft standard protector
Added by the SMALL.CF TROJAN!
wmpIayer.exe Microsoft startup
Added by the IRCBOT.ACI TROJAN!
winslogin.exe Microsoft Stuff you know
Added by a variant of the SDBOT WORM!
winoem.exe Microsoft Svchost local services
Added by the RBOT-FPE WORM!
WinLoginnn.exe Microsoft Synchronization Manager
Added by the SPYBOT.FO WORM!
winupdate.exe Microsoft Synchronization Manager
Added by the SDBOT.ER WORM!
win.exe Microsoft Synchronization Manager
Added by the SDBOT.AK WORM!
winlogon32.exe Microsoft Synchronization Manager
Added by the SDBOT.AEU WORM!
wincfg32.exe Microsoft Synchronization Manager
Added by the SDBOT.DO WORM!
wmedia.exe Microsoft Synchronization Manager
Added by the SDBOT.BFC WORM!
win932.exe Microsoft Synchronization Manager
Added by the SDBOT.AH WORM!
Wnetlib.exe Microsoft System Checkup
Added by the DONK.C WORM!
wnetmgr.exe Microsoft System Checkup
Added by the DONK.Q WORM!
windir32.exe Microsoft System DLL Services Configuration
Added by the SDBOT-ACY TROJAN!
winIogon2.exe Microsoft System Service
Added by a variant of the IRCBOT TROJAN!
wintcp32.exe Microsoft TCP Protocol
Added by a variant of the IRCBOT TROJAN!
winupn.exe Microsoft Telecoms Center
Added by a variant of the SDBOT WORM!
wuamkopxp.exe Microsoft U
Added by the RBOT-AHC WORM!
winrarx.exe MICROSOFT UNPACK SYSTEM
Added by a variant of the RBOT WORM!
winsys32.exe Microsoft Update
Added by a variant of the RBOT WORM!
wuamgrd.exe Microsoft Update
Added by the RBOT-LK WORM!
wuammgr32.exe Microsoft Update
Added by the RBOT-AW WORM!
wudmate.exe Microsoft Update
Added by the RBOT.AP WORM!
wuamgrd32.exe Microsoft Update
Added by the RBOT.ZB WORM!
webm.exe Microsoft Update
Added by the SDBOT.WK WORM!
wuagrd.exe Microsoft Update
Added by the RBOT-FK WORM!
wauguard.exe Microsoft Update
Added by the RBOT.AEE WORM!
winscv.exe Microsoft Update
Added by the RBOT-BH WORM!
winsys.exe Microsoft Update
Added by the RBOT-GV WORM!
wserv32.exe Microsoft Update
Added by the RBOT.AF WORM!
wtm32.exe Microsoft Update
Added by the RBOT-AQ WORM!
wumgrd.exe Microsoft Update
Added by the SDBOT-KY WORM!
wuampd.exe Microsoft Update
Added by the RBOT-UT WORM!
windows24.exe Microsoft Update
Added by a variant of the RBOT WORM!
wingrd32.exe Microsoft Update
Added by the RBOT-DW WORM!
wssvr.exe Microsoft Update
Added by the RBOT-OD WORM!
wuamagr32.exe Microsoft Update
Added by the SPYBOT.CG WORM!
WinUpdate32.exe Microsoft Update
Added by the RBOT-TI WORM!
wkfix.exe Microsoft Update
Added by the RBOT-ABZ WORM!
winamp.exe Microsoft Update
Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player
win-mang.exe Microsoft Update
Added by the RBOT-AFK WORM!
winupdater.exe Microsoft Update
Added by the RBOT.BIN WORM!
wuamk0032.exe Microsoft Update
Added by a variant of the RBOT WORM!
wuamk032.exe Microsoft Update
Added by the RBOT-AHD WORM!
wuamk0p32.exe Microsoft Update
Added by a variant of the RBOT WORM!
wuamkop.exe Microsoft Update
Added by the RBOT-AFI WORM!
wuamkop32.exe Microsoft Update
Added by the RBOT.BGU WORM!
wuampkd.exe Microsoft Update
Added by the SDBOT.BBX WORM!
win32.exe Microsoft Update
Added by a variant of the SDBOT WORM!
wininit.exe Microsoft Update
Added by the RBOT-AKR WORM!
wuamgrd3.exe Microsoft Update
Added by the RBOT-AMC WORM!
Wudates.exe Microsoft Update
Added by a variant of the RBOT WORM!
wuagmsd.exe Microsoft Update
Added by the RBOT-AX WORM!
wuamgrb.exe Microsoft Update
Added by the RBOT-AZE WORM!
WINDOC.EXE Microsoft Update
Added by the SDBOT.PF WORM!
WinDrv32.exe Microsoft Update
Added by the RBOT.EGW WORM!
winupdate.exe Microsoft update
Added by a variant of the RBOT WORM!
wangard.exe Microsoft Update
Added by the RBOT-LH WORM!
wuamgrdx.exe Microsoft Update
Added by a variant of the SPYBOT WORM! See here
wutr.exe Microsoft Update
Added by the SPYBOT.AAR WORM!
wininit.exe Microsoft Update 32
Added by the RBOT-ANY WORM!
wininit32.exe Microsoft Update 32
Added by a variant of the RBOT WORM!
winitXP32.exe Microsoft Update 32
Added by a variant of the RBOT WORM!
wiit.exe Microsoft Update 32
Added by the RBOT-AMS WORM!
winin.exe Microsoft Update 32
Added by the RBOT-ARR WORM!
wuinit.exe Microsoft Update 32
Added by the AGOBOT-UE WORM!
wininit32.exe Microsoft Update 64 BIT
Added by the RBOT-AHE WORM!
winman32.exe Microsoft Update 64 BIT
Added by the RBOT-AKI WORM!
winl32xe.exe Microsoft Update 64 BIT
Added by the RBOT-AQO WORM!
WIN32SNC.EXE MICROSOFT UPDATE CONFIGURATION
Added by the RBOT-AI WORM!
wincfg32.exe Microsoft Update Debugger
Added by the SPYBOT.ZC WORM!
wuauclt.exe Microsoft Update Device Drivers
Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup!
winusers.exe Microsoft Update Loaders 2005
Added by the RBOT-AIQ WORM!
winusersystem32.exe Microsoft Update Loaders 2006
Added by a variant of the AGOBOT/GAOBOT WORM!
wuawx.exe Microsoft Update Machine
Added by the RBOT-CE WORM!
winupdt.exe Microsoft Update Machine
Added by the RBOT-FP WORM!
wuamgd.exe Microsoft Update Machine
Added by the SDBOT.HQ WORM!
wupdt32x.exe Microsoft Update Machine
Added by a variant of the SDBOT WORM!
windowsu.exe Microsoft Update Machine
Added by a variant of the RBOT WORM!
wininigo.exe Microsoft Update Machine
Added by a variant of the RBOT WORM!
winmgr.exe Microsoft Update Machine
Added by a variant of the RBOT WORM!
Winmsixp32.exe Microsoft Update Machine
Added by the RBOT.DN WORM!
Winregs32.exe Microsoft Update Machine
Added by the RBOT.DN WORM!
winxpini.exe Microsoft Update Machine
Added by the RBOT-OB WORM!
wuamgrd.exe Microsoft Update Machine
Added by the RBOT-HE WORM!
wuagrd.exe Microsoft Update Machine
Added by the RBOT-GF WORM!
winhost.exe Microsoft Update Machine
Added by the RBOT-GK WORM!
winss.exe Microsoft Update Machine
Added by the RBOT.JU WORM!
WUAMGRDXS.EXE Microsoft Update Machine
Added by the RBOT-GL WORM!
windowsup.exe Microsoft Update Machine
Added by the RBOT-FV WORM!
wuamgard.exe Microsoft Update Machine
Added by the SPYBOT.CS WORM!
wupdate32.exe Microsoft Update Machine
Added by a variant of the RBOT WORM!
winnie.exe Microsoft Update Machine
Added by the RBOT-ACD WORM!
winortho.exe Microsoft Update Machine
Added by the RBOT-NW WORM!
wins32.exe Microsoft Update Machine
Added by the RBOT.EZ WORM!
wftestb.exe Microsoft Update Machine
Added by the RBOT-AFZ WORM!
Win32.exe Microsoft Update Machine
Added by the SDBOT.UV WORM!
windns.exe Microsoft Update Machine
Added by the RBOT.EF WORM!
WINSVC32.EXE Microsoft Update Machine
Added by the RBOT.CU WORM!
winupdte.exe Microsoft Update Machine
Added by the RBOT-GKL WORM!
wlimyc.exe Microsoft Update Machine
Added by the RBOT-GQN WORM!
winini.exe Microsoft Update Machine
Added by the RBOT-KV WORM!
WINRLS.EXE Microsoft Update Manager
Added by the RBOT-AF WORM!
wmipcvse.exe Microsoft Update Process
Added by the AGOBOT-JF TROJAN!
wcsnfty.exe Microsoft Update Services
Added by the RBOT-AGK WORM!
wsnfty.exe Microsoft Update Services
Added by the RBOT-AFU WORM!
wuam.exe Microsoft Update Time
Added by the RBOT-M WORM!
wuammgrd32.exe Microsoft Update USB2
Added by the RBOT-ADT WORM!
winupdate32a.exe Microsoft Update Win32a
Added by the RBOT-LO WORM!
winupdate32x.exe Microsoft Update Win32x
Added by the RBOT-AJN WORM!
Winsys32.exe Microsoft Updater
Added by a variant of the RBOT WORM!
wuamgrds.exe Microsoft Updater
Added by the RBOT.A WORM!
WinFixd32.exe Microsoft Updater Resources
Added by the SPYBOT.CA WORM!
WINDLL32XP.EXE Microsoft Updaters Pros
Added by the SPYBOTTER.GEN VIRUS!
wkssvr.exe Microsoft Updates
Added by the RBOT.R WORM!
wkssvrs.exe Microsoft Updates
Added by the RBOT-EB WORM!
wuamgrd.exe Microsoft Updates
Added by the RBOT-CO WORM!
wtemp32.exe Microsoft Updates
Added by the RBOT-AHQ WORM!
wgafixer.exe Microsoft Updates 2 USB
Added by a variant of the RBOT WORM!
WinFixIDs.exe Microsoft Updates Resources
Added by a variant of the RBOT WORM!
wuamguards.exe Microsoft Updating
Added by the RBOT-BY WORM!
websvc.exe Microsoft Updating Client
Added by the RBOT.AQ WORM!
winlogon.exe Microsoft Visual SourceSafe
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
webcp32.exe Microsoft Web CP Manager
Added by a variant of the SDBOT WORM! See here
wdevice.exe Microsoft Web Device
Added by a variant of the SDBOT WORM!
webmsn.exe Microsoft web update
Added by the RBOT-EMQ WORM!
winsupdater.exe MicroSoft Wind0ws Updater
Added by a variant of the RBOT WORM!
Winupdsdgm.exe Microsoft Windows 2000
Added by the GAOBOT.AO WORM!
win32update.exe Microsoft Windows 32 Update
Added by a variant of the IRCBOT TROJAN!
wincomm.exe Microsoft Windows Communicator for NT/XP
Added by the RBOT.ATH WORM!
win32conf.exe Microsoft Windows Config 32
Added by a variant of the RBOT WORM!
windir32.exe Microsoft Windows DLL Services Configuration
Added by the SDBOT.BHF WORM!
windir32a.exe Microsoft Windows DLL Services Configuration
Added by a variant of the SDBOT.BHF WORM!
windll32.exe Microsoft Windows DLL Services Configuration
Added by the SDBOT.BHD WORM!
winDSL.exe Microsoft Windows DLL Services Configuration
Added by the SDBOT-ZG WORM!
windrv.exe Microsoft Windows Drivers
Added by a variant of the SDBOT WORM!
windvr.exe Microsoft Windows DVR
Added by the RBOT-AXD WORM!
websploit.exe Microsoft Windows Express
Added by a variant of the SPYBOT WORM! See here
windowslogonb.exe Microsoft Windows Express
Detected by PCTools as the SDBOT.ABOO WORM! See here
Windowz.exe Microsoft Windows GUI
Added by the RANDEX.AEV WORM!
winkrnl386.exe Microsoft Windows Kernel Services
Added by the ZEBROXY TROJAN!
wloader.exe Microsoft Windows Loader
Added by a variant of the AGOBOT/GAOBOT WORM!
winlogon.exe Microsoft Windows Logon Process
Added by the PROXYSER-R TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This worm file is placed in the Winnt or Windows folder
wimp.exe Microsoft Windows Media Player
Added by the RBOT-FN WORM!
wregistry.exe Microsoft Windows Registry Service
Added by the AGOBOT.AKG WORM!
windocs.exe Microsoft Windows Secure
Added by a variant of the SDBOT WORM!
windocs.exe Microsoft Windows Secure
Added by a variant of the SDBOT WORM!
wurguar.exe Microsoft Windows Securety
Added by the RBOT-KY WORM!
wscndrives.exe Microsoft Windows Security
Added by the RBOT-AJK WORM!
winsys.exe Microsoft Windows Service
Added by the RBOT-ADP WORM!
winspkn.exe Microsoft Windows Service Pack
Added by the RBOT-AYD WORM!
winsockx32.exe Microsoft Windows Socketx32 Services
Added by the RBOT-FWT WORM!
winms.exe Microsoft Windows Storage Machine Service
Added by the RBOT-AHK WORM!
winsvc.exe Microsoft Windows System Service Manager
Added by the SPYBOT.LR WORM!
windows.exe Microsoft Windows Updata
Added by a variant of the RBOT WORM!
windowsupdate.exe Microsoft Windows Update
Added by the AGOBOT.ON WORM!
wuap.exe Microsoft Windows Update Application
Added by a variant of the RBOT WORM!
win-logon.exe Microsoft Windows Update Logon
Added by a variant of the RBOT WORM!
wupdmgr32.exe Microsoft Windows Update Service
Added by the DOS.AUTOCAT TROJAN!
windates.exe Microsoft Windows Updater
Added by the SDBOT.TE WORM!
winupdgm.exe Microsoft Windows Updater
Added by the GAOBOT.BI WORM!
WINIUPDATES.EXE Microsoft Windows Updater
Added by the RBOT-KK WORM!
WINUPDATE.EXE Microsoft Windows Updater
Added by the SDBOT-PU WORM!
win32upd.exe Microsoft Windows Updater
Added by the RBOT-EC WORM!
wsap32.exe Microsoft Windows Updates
Added by a variant of the SDBOT WORM!
winsass.exe Microsoft Windows WinSaSS Management
Added by the RBOT-APW WORM!
winexplorer.exe Microsoft Windows XP/2K Explorer
Added by a variant of the IRCBOT TROJAN! See here
WinKey.exe Microsoft Winedows startup
Added by a variant of the SDBOT WORM! See here
WinSGR32.exe Microsoft WINGS32 Protocol
Added by the RBOT-APU WORM!
winrar.exe Microsoft WinRaR
Added by the RBOT-AEC WORM!
ws2_32s.exe Microsoft Winsock Wrapper
Added by a variant of the SPYBOT WORM!
Winamp61.exe Microsoft WinUpdate
Added by a variant of the RBOT WORM!
Winupd32.exe Microsoft WinUpdate
Added by the RBOT.MQ WORM!
WinNTinit32.exe Microsoft WinUpdate
Added by the RBOT.VS WORM!
wkcalrem.exe Microsoft Works Calendar Reminders
Produces a pop-up reminder of events scheduled using the MS Works Calendar
WksSb.exe Microsoft Works Portfolio
The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program.Can be prevented from starting from a setting within Portfolio
wkdetect.exe Microsoft Works Update Detection
Checks for updates to MS Works
winworld.exe Microsoft World Service
Added by an unidentified IRC worm with backdoor capability!
wuamkoppnp.exe Microsoft X Update
Added by the RBOT-ANI WORM!
winsystem32xp.exe Microsoft Xp Systems loader
Added by the KELVIR.W WORM!
win32xpsys.exe Microsoft Xp Systems loaders
Added by the SPYBOT.NYT WORM!
wngard.exe Microsoft-Update
Added by the RBOT-JV WORM!
win32sys.exe Microsoft32
Added by an unidentified WORM or TROJAN!
wees.exe Microsoftf DDEs Control
Added by a variant of the RBOT WORM!
why-.exe Microsoftf DDEs Control
Added by the RBOT-AMV WORM!
w33s.exe Microsoftf DDEs Control
Added by a variant of the RBOT WORM!
waes.exe Microsoftf DDEs Control
Added by a variant of the RBOT WORM!
winmplayd.exe Microsofts media
Added by an undidentified WORM or TROJAN!
wingtp.exe Microsofts media
Added by the RBOT-VO WORM!
winmep.exe Microsofts MediaScope
Added by the RBOT-WB WORM!
winmedplay.exe Microsofts MediaScope
Added by a variant of the RBOT WORM!
Wintsk32.exe MicrosoftServiceManager
Added by the YAHA.U WORM!
WinUp32.exe MicrosoftUpdate
Added by an unidentified VIRUS, WORM or TROJAN!
windll.exe MicrosoftUpdate
Added by the RBOT-IH WORM!
windrive.exe Micrsoft Driver
Added by the SDBOT.AF TROJAN!
wcnsfty.exe Micsorosft Security Center
Added by the RBOT-AHU WORM!
wimsqaad.exe Miosf Update
Added by the SDBOT.AG TROJAN!
wuampkd.exe Mircosoft Update
Added by a variant of the SDBOT WORM!
win32x.exe Mismo
Added by the RBOT-JP WORM!
WAed.pif Mlcr0s0ftf DDEs C0ntr0i
Added by the RBOT-BJW WORM!
winmgmt.exe MMCWINMGMT
Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here
webcomp.exe Mobipocket Web Companion
Related to Mobipocket eBook Reader
wuaclt.exe Modifiet Amateur HTPB
Detected by Trend Micro as the IRCBOT.AYS WORM! See here
Wupated.exe Ms Builders
Added by the AGOBOT-SS WORM!
wrapper.exe MS Java Service Wrapper for Windows NT & XP
Added by the VANEBOT-D WORM!
winPE.exe ms ownage
Added by the RBOT-AJL WORM!
wpad.exe MS PLUS INC
Added by the MYTOB-AN WORM!
winscv.exe MS Service Drivers
Added by the SDBOT-COG WORM!
winser.exe Ms sock for Windows NT
Added by a variant of the SDBOT WORM!
win32ttb.exe MS Unix Binary
Added by the SPYBOT.OQ WORM!
Win32Update.exe MS Unix Binary
Added by the RBOT-BAS WORM!
WinGuard.exe MS Unix Binary
Added by the RBOT-ACL WORM!
winservnt32.exe Ms Update WinServices NT/XP
Added by the VANEBOT-G WORM!
windriver.exe MS Win32 Network Services
Added by the AGOBOT.ADH WORM!
web.exe MS-Connect
Adult content dialler - see here
winlog.exe msconfig
Added by the IRCBOT-TJ TROJAN!
winnsyst.exe MSControl31
Added by the RBOT.CFY WORM!
winmp.exe MSIdll
Added by a variant of the RBOT WORM!
winlogon.exe MSMSGS
Added by the RAHIWI.A WORM!
wdlrss.exe MSN
Added by a variant of the SDBOT TROJAN!
wkssvr.exe MSN
Added by the PUSHBOT.S WORM!
wkssvrs.exe MSN
Added by a variant of the IRCBOT BACKDOOR! See here
wksvr.exe MSN
Added by the IRCBOT-XU WORM!
wmev.exe MSN
Added by a variant of the SPYBOT WORM! See here
winntmsn.exe MSN Messanger Live
Added by the RBOT-FSO WORM!
windns.exe Msn Messeng
Added by a variant of the RBOT WORM!
winproc.exe MSN Service Updates
Added by the KELVIR-BB WORM!
windatemanager.exe Msn Updater
Added by the SDBOT.TS WORM!
winagent.exe MsnExplorer
Added by the EQ TROJAN!
winampb.exe msnnt
Chinese originated adware - detected by Kaspersky as the AGENT.TL TROJAN!
winampf.exe msnnt
Added by the SMALL.DTS TROJAN!
winss.exe MSOleath32
Added by the KATHER TROJAN!
wiaadmgr.exe MSPP System Update 64
Detected by Kaspersky as the RANKY.GEN TROJAN!
winupdate.exe mssonfig
Added by a variant of the SDBOT WORM!
WINUPD.EXE MSStartOptimizer
Added by the DASMIN-E TROJAN!
wstask32.exe MsTask
Added by the MYTOB-FE WORM!
wupd.exe MSUpdate
Added by the ALADINZ.M TROJAN!
wsdrt32.exe MsWindows DRT Drivers
Added by the RBOT.ALT WORM!
winlogon.exe MSWinlogon
Added by the AGENT-FZM TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!
winupd.exe MSWinupd
Added by the DLOADER-YE or DLOADR-AAA or DLOADER-ZF TROJANS - and others
winupdate.exe MSWinupdate
Added by the DLOADR-AAW TROJAN!
wdfmgr.exe MS_Update Check
Added by the AGOBOT-TB WORM!
wjview ...MyPointsPointAlertrun.exe MyPointsPointAlert
"With MyPoints you can earn rewards from name-brand merchants. You can even earn vacations and frequent flyer miles". Dubious privacy policy
winexplor.exe mysoft
Browser hijacker, also detected as the STARTPA-JR TROJAN!
winsnav.vbs NAV Agent
Added by the ANPES WORM!
wmilib32.exe NAV Agent
Added by the VB-XU TROJAN!
WINDBKGND.EXE NB Windows Patterns
Part of McAfee Nuts & Bolts. With Background Patterns, you can change background patterns of wizard and dialog windows
winntsrv -l -p10001 -d -e cmd.exe -L NC1565
Added by the NEWLEY-A WORM!
windows.exe NDIS Adapter
Added by the FORBOT-BR WORM!
Winman.exe NDIS Adapter
Added by the WOOTBOT.AG WORM!
winlogin.exe NDplDeamon
Added by the RANDEX.E WORM!
wmp9.exe Nero Updater.6.12
Added by the AGOBOT-AAG WORM!
winjava.exe NeroUpdater6.8
Added by the AGOBOT.AMK WORM!
WINREG.EXE Net
Added by the ASSASIN.D TROJAN!
winserv.exe NetApp
Added by the SHADOWTHIEF TROJAN!
wlan111t.exe NETGEAR WG111T Smart Wizard
Configuration utility for the Netgear WG111T multi-rate Wireless USB 2.0 Adapter that "provides wireless access to your desktop or notebook PC through the computer's USB port"
winclient.exe NetPatrol
NetPatrol network monitoring software
WgwMngr.exe NettGain2000
Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so
wunit32.exe Netunit32
Added by an unidentified WORM or TROJAN!
winssh.exe Network Access
Added by a variant of the SDBOT WORM!
wuamgrd.exe Network Protocol Service
Added by the RBOT.EA WORM!
wintcp.exe Network protocol service
Added by a variant of the AGOBOT/GAOBOT WORM!
WinNPS.exe Network Provisioning Service
Added by an unidentified WORM/TROJAN!
WinAntiVirusPro2006Installer.exe NI.UWA6P_0001_N56M1001
WinAntiVirus Pro 2006 misleading virus software - not recommended, see here
WinAntiVirusPro2006Installer[1].exe NI.UWA6P_0001_N69M0303
WinAntiVirus Pro 2006 misleading virus software - not recommended, see here
WinAntiVirusPro2006FreeInstall.exe NI.UWA6P_0001_N73M1004
WinAntiVirus Pro 2006 misleading virus software - not recommended, see here
winantiviruspro2006freeinstall[1].exe NI.UWA6P_0001_N91M1807
WinAntiVirus Pro 2006 misleading virus software - not recommended, see here
winantiviruspro2007freeinstall[1].exe NI.UWA7P_0001_N91M0809
WinAntiVirus Pro 2007 misleading virus software - not recommended, see here
wsul.exe Norton Service Driver
Added by the RBOT-ABI WORM!
winsvc.exe Norton Update
Added by the AGOBOT.ALP WORM!
winset.exe Norton Updater
Added by a variant of the SPYBOT WORM!
wtta.exe Notn
PurityScan/Clickspring adware
WinNTLM.exe NT LM Security Support Provider
Added by a variant of the SDBOT WORM!
wntsf.exe NTSF MICROSOFT SYSTEM
Added by the RBOT.ATC WORM!
winsis32.exe NTSF MICROSOFT SYSTEM
Added by a variant of the RBOT WORM!
winlogon.exe nvchost
Added by the KLONE-J TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
windowsp.exe NvCpl
Added by a variant of the SDBOT WORM!
winasp.exe NvCplScan
Added by the FORBOT.BZ WORM!
wuauqmr.exe NvCpTDaemon
Added by the CULT-B WORM!
winoeinit.exe OEPowerPlugs
??
winxp_sp3.exe Offica Monitor Secura Systeme
Added by a variant of the RBOT WORM!
winutade.exe OKGO
Added by the BANKER-EHZ TROJAN!
winssnotify.exe OneCareUI
Related to Windows OneCare Live from Microsoft
webtogo.exe Oracle Web-to-Go
"Oracle Web-to-go, a component of Oracle9i Lite, consists of a collection of modules and services that facilitate development, deployment, and management of mobile Web applications"
winword.exe OSA
Added by the KANGAROO-A TROJAN!
wcdvtray.exe OWCWebCamDV
WebCamDV from Orange Micro, Inc - enables the user to use a DV camera connected via Firewire as a Webcam
WinGamed.exe Patches Value
Added by the SDBOT.BR WORM!
WinPTTP.exe Performs peer to peer connection
Added by the RBOT-GMI WORM!
W3dbsmgr.exe Pervasive.SQL Workgroup Engine
Database Service Manager for Pervasive SQL 2000 Workgroup edition. Required if you use Pervasive SQL but it's recommended you start it manually before using it as it has a tendancy to crash/freeze if loaded with other applications at startup
wpctrl.exe PivotSoftware
PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties
winsrvc.exe Pmedia
Internet marketing sofware from Permissioned Media Inc as used in E-Card FriendGreetings foistware - see here. Treated by Trend as the FRIENDGRT.B WORM!
wuaaclt.exe PNP
Added by the LILBRE-A WORM!
WinTask.exe PopMark
"Pop Marketing" adware
webprinter.exe Printer Monitor
Added by the IRCBOT-Z TROJAN!
wqxfne.exe Proc993
Added by the IXBOT-D WORM!
wsript.exe Q152404.VBS Q152404
Appears to run Scandisk at bootup on NEC PCs
Winrar.exe quicken
CoolWebSearch Therealsearch parasite variant. Note - this is not the file zipping utility also known as WinRAR!
Waol.exe quicken
CoolWebSearch Therealsearch parasite variant
winmplyer32.exe Quicktime Mediaplayer
Added by the RBOT-PM WORM!
wnmplyr.exe Quicktime Mediaplayr
Added by a variant of the RBOT WORM!
winuodps.exe Quicktime Pro 3.0
Added by the GAOBOT.BH WORM!
Winrsm.exe Real Spy Monitor
Realspy keystroke logger/monitoring program - remove unless you installed it yourself!
winsy.exe Reg Service
Added by a variant of the SPYBOT WORM!
winslogon.exe Reg Service
Added by the AGOBOT-SC WORM!
WinnConfig.exe Reg Service
Added by the AGOBOT-PF WORM!
Winboot32.exe Reg Services
Added by the RBOT.PB WORM!
winlogon.exe RegDone
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
wscript.exe ShakiraPics.jpg.vbs Registry
Added by the VBSWG.AQ WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "ShakiraPics.jpg.vbs" file is located in the Winnt or Windows folder
winreg.exe Registry Checkup
Added by an unidentified WORM or TROJAN!
Winregs326a.exe Registry Checkup System326a Monitor
Added by a variant of the SDBOT WORM!
WCPDT.EXE Registry Integritycheck
Added by the AGOBOT-RF WORM!
winhlpp32.exe Registry Loader
Added by the GAOBOT.AO WORM!
win32.exe Registry oidet
Added by the RBOT.BMT WORM!
winapi32.exe Registry Value Name
Added by a variant of the RBOT WORM!
winbackup.exe RegistryChk
Added by the MERTIAN WORM!
winservice.exe Regkey for autostart
Added by the RBOT-NU WORM!
winfix22490.exe REGRUN
Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!
winbait.exe RegRun WinBait
Part of RegRun - used to detect unknown viruses. RegRun compares winbait.exe with the original copy called winbait.org and warns if the files are different..
WatchDog.exe Regrun2
Greatis Software's RegRun security suite which amongst other things replaces MSCONFIG. The WatchDog check for registry changes caused by trojan's, viruses, etc
WinRDH.exe Remote Desktop Help Session Manager
Added by a variant of the SDBOT WORM!
winrpc.exe Remote Procedure Call
Added by the RBOT-KM WORM!
winsysrpc.exe Remote Procedure Call
Added by the SDBOT-PS WORM!
win.exe Remote Procedure Calls
Added by the SDBOT-QI WORM!
windos.exe REMOVE ME
Added by the SDBOT.EE WORM!
Watch.exe Restart Watch
Associated with an Eicon Networks Diva ISDN or ADSL modem. What does it do and is it required?
wscrestp.exe Restart WSC Setting
WinStart Commander - part of Ultra WinCleaner Utility Suite. Starts Windows faster and controls hidden programs to boost performance and prevent system slow downs and crashes
wf32vbs.exe RNBc Test
Added by the RBOT-AGR WORM!
wf32vbc.exe RNBz Test
Added by the RBOT-AEY WORM!
wf32b.exe RNDc Test
Added by a variant of the SDBOT WORM!
winlogon.exe ROOT_Machine
Added by the BANKER-FI TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This worm file is placed in the Windowsinf or Winntinf folder
winlogon.exe RPCserr32g
Added by the RITDOOR-B WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
WINLOGON.EXE RPCserv32g
Added by the BOBAX.AD WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
wandrv.exe run
Added by the BCKDR-QHR TROJAN!
wscript MSupdt32.vbs Run MSupdt32
Added by the CASER WORM!
wperl.exe Run POPFile in background
POPFile - E-mail spam blocker
websvc.exe Run Services as Application
Added by the DLOADER-NY TROJAN!
WINClock.exe run32dll
Added by an unidentified VIRUS, WORM or TROJAN!
wallflip.exe run=
Desktop wallpaper changer?
win.ini run=
??
wswpd.exe run=
Used with some models of Panasonic, Epson and NEC printers - required for printer to work
wmplayer.exe run=
CoolWebSearch Smartsearch parasite variant
Winfi1e32.exe Rund1l32
Added by the MERTIAN WORM!
winupdate.exe RunDLL32
Added by an unidentified TROJAN! - possibly a BMBOT variant
Windows.exe Rundll32
Added by the QQPASS.E TROJAN!
win.exe runing
Added by the DELF-LC TROJAN!
wini.exe RunProg
Added by the OPTIX.04.D TROJAN!
winlogon.exe runwinlogon
Detected by Trend Micro as the AGENT.TQY TROJAN! See here. Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
WAS7Mon.exe Salestart
WinAntiSpyware spyware remover - not recommended, see here
winagent.exe ScheduIr
Added by a variant of the SDBOT WORM!
winagent.exe Scheduler
Added by the TACTSLAY.B TROJAN!
wsass.exe Scheduler Service
Added by the LIOTEN.KX WORM!
w32tm.exe Secboot
Added by the HAXDOOR.D TROJAN!
wins32a.exe secure socket layer
Added by an IRCBOT TROJAN!
WindowsSecurityUpdate.exe Security
Added by a variant of the SDBOT WORM!
WinUpdate32.exe Security Patch
Added by the SDBOT-BM WORM!
WinLab32.exe Security Patches
Added by the SDBOT-KB WORM!
wmiprvce.exe Security Update Service
Added by the AGOBOT.ZW WORM!
wssdsu.exe Serv-U
Added by the MANIFEST TROJAN!
wbemstest.exe Server Runtime Process
Added by the SDBOT-DDB WORM!
wN2S.exe service
Added by a variant of the RBOT WORM!
winsvcli.exe Service Client
Added by an unidentified WORM or TROJAN! See here
WinOcx.exe Service Monitor
Added by the RBOT-AQJ WORM!
winset.exe Service Process
Added by a variant of the SPYBOT WORM!
windowsXP.exe Service System
Added by the BANCOS-EL TROJAN!
wernell87.exe Service System
Added by the BANCOS-FJ TROJAN!
winread.exe Services
Added by an unidentified VIRUS, WORM or TROJAN!
windns.exe Services
Added by a variant of the RBOT WORM!
windows32.exe services
Added by the FLYVB-C WORM!
websvc.exe Services Administrator
Added by the DLOADER-NY TROJAN!
win32dll.exe Services32 Startup
Added by the SDBOT-XO WORM!
wsusupd.exe ShareSearcher
Added by the ENCLAG-A TROJAN!
winagent.exe SheduIer
Added by the EB TROJAN!
wmedia32.exe Shell
Added by the AGENT-BR TROJAN!
wmedia16.exe Shell
Added by the GOLDUN TROJAN!
Wifiusb.exe Sinus 1054 data WLAN Manager
Wireless management utility for the T-Com Sinus 1054 Data WLAN adapter
winsos.exe sis32
Added by the QQPASS.IA WORM!
win.bat Sistray32
Added by the JUMPRED.A WORM!
winlogon.scr SkynetRevenge
Added by the NETSKY.AA WORM!
winlogon.exe SmansaApp
Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
winsrv.exe smcserv
Added by the AGOBOT-OU WORM!
win32st.exe SMSERIALSTARTER
Detected by McAfee as the FAKEALERT-AH TROJAN! See here. Installed with the SpyBurner spyware remover - which is not recommended, see here
winstrse.exe SMSERIALWORKERSTARTER
Added by an unidentified WORM or TROJAN! See here. Installed with the SpyBurner spyware remover - which is not recommended, see here
Win.exe smsger
Added by a variant of the SDBOT WORM!
wininits.exe softIce Update 32
Added by the RBOT-ANB WORM!
WNILOGON.exe SonudMan
Added by the QQROB-DC TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
WinSound1.exe Sound System
Added by an unidentified VIRUS, WORM or TROJAN!
Wifiusb.exe Speedport W 100 Stick WLAN Manager
Wireless management utility for the Speedport W 100 Stick WLAN USB stick
Wscript.exe OXNEY.B.VBS SPINX
Added by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "OXNEY.B.VBS" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
wys.exe Spool
WhileUSurf adware
websvc.exe Spooler SubSystem Application
Added by the DLOADER-NY TROJAN!
wintre.exe spoolsvs
Added by the SDBOT.EGQ WORM!
wincfy.exe spoolsvs
Added by a variant of the IRCBOT BACKDOOR!
Winllogo.exe SpyEx
Added by the PRSKEY-A WORM!
winproc32.exe SpywareGuard
Startpage adware Trojan
winmm64.exe SpywareGuardPlus
StartPage.ht homepage hijacker
wins32.exe sqservices
Added by the PROGENT-B TROJAN!
win16dll.exe srv32win
Screenspy captures screenshots silently. If you didn't install this yourself remove it
winsys.exe ssate.exe
Added by the BEAGLE.K WORM!
winerdir.exe ssgrate.exe
Added by the MITGLIEDER.O TROJAN!
winsystems.exe ssgrate.exe
Added by the BAGLEDL-J TROJAN!
wintems.exe ssgrate.exe
Added by the MITGLIEDER.Q TROJAN!
winssk32.exe SSK Service
Added by the SOBIG.E WORM!
windows.vbs Start
Homepage hijacker
windupds.exe Start Upping
Added by the SDBOT.AFH WORM!
windupdts.exe Start Upping
Added by a variant of the RBOT WORM!
win32i.exe startkey
Added by the BIFROSE-R TROJAN!
winampXP.exe startkey
Added by the BIFROSE-OY TROJAN!
winlogin.exe startkey
Added by the BIFROSE-PM TROJAN!
WinlogonStartup Startup
Unidentified malware
wztoid.exe Startup Configuration
Added by the RBOT-ASD WORM!
w32main2.exe stgclean
Related to IBM Standard Software Installer. What does it do and is it required?
wkfxi.js stmha
Added by the SPETH WORM!
wuauclt14.exe StreamAppliance
Added by the RBOT-GMB WORM!
wuauclt16.exe StreamAppliance
Added by the RBOT-GME WORM!
winscrne.exe STV
Added by a variant of the SDBOT WORM!
winsfcm.exe SurfinGuard Pro
SurfinGuard Pro from Finjan - internet protection software, protects against all malicious code delivered through executables, scripting files, ActiveX and Java
WINAGENT.EXE SvcH0st
Added by the EB TROJAN!
winhost.exe Svchost
Added by the LOLAWEB.A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
winhelp.exe svchost
Added by the GAOBOT.GEN!POLY WORM!
winampXP.exe svcshare
Added by the FUJACKS-J VIRUS!
winwd.exe SWd
PC Security from Tropical Software - lock files, password protect, etc
Win32x.exe Sygate Personal Firewall
Added by the RBOT-KZ WORM!
wins.exe Sygate Personal Firewall
Added by the RBOT.AOB WORM!
winxpstat.exe Sygate Personal Firewall
Added by a variant of the RBOT WORM!
win31243.exe Sygate Personal Firewall
Added by a variant of the IRCBOT TROJAN!
winupdate.exe Sygate Personal Port Blocker
Added by a variant of the RBOT WORM!
windows .exe Symantec Antivirus professional
Added by a variant of the FORBOT WORM!
Winhp32.exe Symantec Antivirus professional
Added by a variant of the FORBOT WORM!
winudp.exe Symantec Antivirus professional
Added by a variant of the WOOTBOT WORM! See here
winsync.exe syncman
Added by the MANCSYN-A TROJAN!
windows32.exe Syntax
Added by the SDBOT.CQ WORM!
wuapdxe.exe Sys-Stat
Added by the SDBOT.HK WORM!
win***32.exe [* = random char] Sys29
EliteBar adware
win***32.exe [* = random char] SysA
EliteBar adware
win.hta Syscheck
Browser hijacker
wincfg32.exe SysConfig
Added by the SDBOT.ZD WORM!
winupdate.exe Sysctrls
Added by an unidentified WORM or TROJAN!
win32dll.exe Sysctrls
Added by a variant of the IRCBOT BACKDOOR! See here
winrun.exe sysdir
Added by the WINBUR.B WORM!
wininit32.exe SysInit
Added by the XABOT WORM!
wowexece.exe SysMon
Added by the MULAN-A TROJAN!
WWE DIVAS.exe SysRes
Added by the ELIPTER.D WORM!
WINL0G0N.EXE System
Added by the BANCOS-DB TROJAN!
wumgrd32.exe System
Added by a variant of the RBOT WORM!
windowsps.exe System
Added by a variant of the RBOT WORM!
wiinlogon.exe SYSTEM
Added by the RBOT-AVG WORM!
winupd.exe System
Added by a variant of the SDBOT WORM!
wsscntfy.exe System
Added by a variant of the SDBOT WORM!
windmupdr.exe SYSTEM
Added by a variant of the RBOT WORM!
win_klr32.exe System Check
Added by the DELF-DRA WORM!
wasul.exe System Checking
Added by the RBOT.BHM WORM!
wins.exe System Document Application
Added by the SDBOT.AUB WORM!
wingmt.exe System Drivers
Added by the SDBOT-MG WORM!
win.exe System Information Manager
Added by the SDBOT-MU WORM!
windowsNt.com System Information Manager
Added by the SDBOT-ND WORM!
winsrv32.exe System Manager
Added by an unidentified WORM or TROJAN!
winsvc.exe System Manager Updates
Added by the AGOBOT.AEM WORM!
wmisg.exe SYSTEM MESSAGER
Added by the MYTOB.ES WORM!
wupdmgr.exe System Update
Added by the SOROMO-A TROJAN!
wauluclt.exe System Update
Added by the SDBOT.EF WORM!
wmiprvsa.exe System Update Service
Added by the AGOBOT-RG TROJAN!
winupd32.exe System Update Service
Added by the ADTODA-A TROJAN!
wmiprvsv.exe System Update Service
Added by the AGOBOT.YG WORM!
webcheck.exe System Update2
Added by the AUTOTROJ-C TROJAN!
wininet.exe System Update2
Added by the AUTOTROJ-C TROJAN!
winlogon.exe System Update2
Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
winspool.exe System Update2
Added by the AUTOTROJ-C TROJAN!
wupdmgr.exe System Update2
Added by the AUTOTROJ-C TROJAN!
wmiprvsw.exe System Updater Service
Added by the GAOBOT.AFC WORM!
winsci.exe System Updates
Added by a variant of the RBOT WORM!
wmkl.exe System Updates
Added by the RBOT-AYJ WORM!
winserv32.exe System Updates Manager
Added by the AGOBOT-AGA WORM!
winds32.exe System32
Added by the DWNLDR-HFY TROJAN!
Wincmp32.exe SystemAdministration
Added by the ASYLUM TROJAN!
WinMedia.exe SystemMigration
Added by the KELVIR.EI WORM!
WINREG.EXE SystemReg
Added by the DEWIN.A TROJAN!
windrives.exe Systems Backups
Added by the AGOBOT-RB WORM!
Windows2.exe systems usb driver
Added by a variant of the RBOT WORM!
wekls4.exe SystemTray
Added by a variant of the IRCBOT TROJAN!
Windowsupd.exe SystemTray
Added by a variant of the IRCBOT TROJAN!
winkernal.exe systhread
Added by the LIAMED WORM!
w32explorer.exe Systray
Added by the RBOT-AJY WORM!
winrxd64.exe sysygm64
Added by the IRCBOT-RK TROJAN!
Wink3sk9.exe T4skM4n4g3r
Added by a variant of the IRCBOT TROJAN!
wualcts.exe Task Help
Added by a variant of the RBOT WORM!
winampa.exe Taskmon driver
Added by the LOONY-I TROJAN! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of the Program Files directory whereas this file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
websvc.exe Tcp Application Manager
Added by the DLOADER-NY TROJAN!
winlogon.exe TEXTCONV
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
wind0s.exe ThE
Added by an unidentified WORM or TROJAN!
wscript zshell.js Time Zone Synchronization
Added by the NETDEX-A TROJAN!
Watcher.exe Tiny Watcher Logon Time
Tiny Watcher detects changes to your system. It will not prevent your system from being modified or corrupted. It will only tell you that something suspicious happened. Think of it as an early CAT scan against system tumors. Better to install a tool that will detect and remove bad items
WINLOGON.EXE Torjan Program
Added by the WOWCRAFT.D TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! This trojan file is found in the Windows or Winnt folder
WinLED.exe Touch Manager
Dell keyboard utility. Disabling can result in loss of screen saver and power saver functionality
wincool.exe Tour
Component of WinME that's annoying as hell. Pop's up a prompt to play the C:WINDOWSApplication DataMicrosoftINTROCONTENT.HTA that plays a full screen version of the WinME product preview Windows Media video file that cannot be stopped to my knowledge until it finishes. That prompt will keep popping up after an install/reinstall of WinME until you give in and watch the thing. It also puts a task scheduler entry to run that annoying thing every 30 minutes, and don't bother deleting that entry, Windows puts it right back. Not only should you disable it from running, you should delete the thing altogether, as it, somehow can re-enable itself. Apparently you can try setting the file to read only
Weatherbug.exe Tray Temperature
Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs
winppr32.exe TrayX
Added by the SOBIG.F WORM!
wins32.exe Tsk Mng Hlp
Added by the AGOBOT-JB WORM!
WinManager.Exe Tweak Manager
WinGuides Tweak Manager. Is this required for the live updates feature and/or if settings are changed?
winter.exe Undefined
Added by the KILLAV.LW TROJAN!
WinUPPD.exe Universal Plug & Play devices
Added by an unidentified WORM/TROJAN!
winlogom.exe Updade Windows
Added by the TONAX-A TROJAN!
wupdata.exe UpData
Added by the IRCBOT-AA TROJAN!
winis.exe update
Added by the RBOT-VD WORM!
WinUpdater5.0.vbs UPDATE
Added by the GORMLEZ-A WORM!
winlog.exe Update Checker
Added by the IRCBOT-TJ TROJAN!
WiseUpdt.exe Update Grokster
Automatically updates the Grokster file sharing software. Beware of adware and spyware when using this type of program, for instance, Grokster contains CyDoor
winu32.exe Update Service
Added by the RBOT-MG WORM!
winx.exe update service
Added by a variant of the RBOT WORM!
WiseUpdt.exe Update TUT
??
winstall.exe UpdateCheck
Added by the SPYBOT-CY WORM!
wupdater.exe updater
eUniverse/KeenValue adware
wisvc.exe updater
Added by the ORSE-A TROJAN!
winload32.exe updater32
Added by the CULT.M WORM!
wservice.exe UpdateService
Added by the DREF-K WORM!
winit.exe upddateit
Added by the RBOT-MS WORM!
winupd.exe Upgrade Service
Added by the TOFGER-U TROJAN!
WinSVCservice.exe UPNPService
Added by the AGOBOT.UN WORM!
wjview ...Code UpromiseRemindU
Part of the Upromise saving scheme but associated with Ebates MoneyMaker adware so the choice is yours
web.exe UPSUtl
CoolWebSearch parasite variant
WinUp.exe UpTimes service
Added by the RBOT-AKB WORM!
winlogon.exe urudjeffni
Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
Winsys32.exe USB 2.0 Driver
Added by the AGOBOT-QM WORM!
winsystem.exe USB 2.0 Driver
Added by the AGOBOT-QS WORM!
winupdate1.exe USB 2.1 Driver
Added by a variant of the RBOT WORM!
win32usb.exe USB Device
Added by the FORBOT-BQ WORM!
wuservices.exe USB Fix 1.1
Added by a variant of the SDBOT WORM!
wuafix.exe USB Fixes
Added by the RBOT-ABV TROJAN!
wugfixx.exe USB Updates 2
Added by a variant of the RBOT WORM!
wmmndir.exe USBConfigration2
Added by the AGOBOT-SV WORM!
winlogon.exe userinit
Added by the DLOADER-TP TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
WMPVer.EXE v
Dritek System Inc. 3D Mouse related. Is it required?
WebLifeDisk.exe VDrive2
EarthLink WebLife Disk - "Consumers can quickly save files from their desktop into WebLife Disk, and then easily access them from any Internet connection without taking a laptop on the road or keeping up with a USB key"
winamp32.exe Video
Added by the AGOBOT-NG WORM!
wcamfrog.exe Video Camera Frog
Added by a variant of the IRCBOT TROJAN! See here
winaps.exe Video Proces
Added by the AGOBOT.HD WORM!
winasp.exe Video Process
Added by the AGOBOT-IS WORM!
wincert32.exe Video Process
Added by the AGOBOT.JT WORM!
winit.exe virtual
Added by the MUGLY.A or MUGLY.B WORMS!
winprotect.exe virtual
Added by the MUGLY.C WORM!
wini.exe virtual
Added by the RBOT-YX WORM!
winlogi.exe virtual-ie
Malware - detected by Kaspersky as the WINAD.H TROJAN!
winlogin.exe virtual-machine
Added by the RBOT-VU WORM!
wini.exe virtual-machine
Added by the RBOT-WR WORM!
winxpsock.exe Vsample
Added by the SDBOT.BLK WORM!
WINLOGON .exe W1N32.DLL
Added by the DROPPERFL.A TROJAN!
w32.exe w32
Added by the SOKEVEN TROJAN!
wiper.exe W32PluginsDownloaderXMLHTTPSelfClearing7520
Added by the PROXYSER-M TROJAN!
w32sup.exe w32sup
Adult content dialler
w32sys.exe W32SYS
Added by the JAMBU-A WORM!
WTC32.scr W32Tc
Added by the VOTE.D or VOTE.K WORMS!
W75P2PS.EXE W75P2PSERVER
Printer utility which is required in order to make the printer work correctly
w7zip.exe w7zip
Added by the BANCBAN-QB TROJAN!
W815DM.exe W815DM
Enuff Parental Control Software by Akrontech
w98Eject.exe w98Eject
Related to USB support for Sigmatel MP3 audio palyer (and others such as SanDisk). It's intent is to "put away" the "disk" before you unplug it from the USB port, ostensibly to avoid "losing" data
wab.exe wab.exe
Added by a variant of the SDBOT WORM!
wait4IP.exe wait4IP
Packard Bell net2Plug allows you to network PCs anywhere in your house
Wallchgr.exe wallchgr.exe wstart
WallChanger - wallpaper changer from Blue Tree Software
wallmast.exe WallMaster
WallMaster - "The free and easiest way to master your desktop wallpaper!"
WALLPA~1.EXE WallPaper
Wallpaper Changer - wallpaper manager that can change your background images on every startup
Wallpaper.exe WallpaperChanger
A wallpaper changer and manager utility. There is the Freeware version and the Pro version. The freeware version is completely free. The Pro version is 30-day trialware, and after the 30 days some of the more advanced features will be disabled unless you register it
WallpaperSS.exe WallpaperSS
Wallpaper Slideshow LT from gPhotoShow.com - "a great utility for displaying your favorite photos as your desktop wallpaper"
Wanadoo Messenger.exe Wanadoo Messenger.exe
Wanadoo ISP instant messenger client
wanman.exe wanman.exe
Added by the RBOT.HDO WORM!
WanMPSvc.exe WanMPSvc
An AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling AOL doesn't help
wts**.exe [* = random char] WAPI
PurityScan/Clickspring adware
wartray.exe War FTPD Tray Icon
War-ftpd - FTP server
WAR-FTPD.EXE war-ftpd.exe
War FTP Daemon from JGAA's Internet - FTP client
WareOut.exe WareOut
Wareout - malware masquerading as a spyware and dialer remover
warez.exe warez
Warez P2P client
warner.exe Warner
Also known as "CyberWarner". From G-Tek Technologies and pre-installed on some Packard Bell PCs. Protects critical files
warnet.exe Warnet
Warnet - system cleanup software
WarReg_PopUp.exe WarReg_PopUp
Acer warranty registration popup
war-ftpd.exe WARSVR
"War FTP Daemon - the original free FTP server for windows"
washer.exe Washer
Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
washerie.exe Washerie.exe
Cookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer, specific for cleaning the IE cache and cookies. Available via Start -> Programs
washidx.exe washindex
Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
wast.exe Wast
Grokster ads updater
watch.exe Watch
Found to be used by a Trust USB scanner for auto starting the scanning software when the lid is lifted
watchdog.exe Watch Dog Program
For Compaq PC's. Associated with Compaq's internet services. Not required if you don't use services provided by them and may not be required even if you do
Watchdog.exe Watchdog
Definitely part of the Mustek scanner drivers and software (for 600 III EP Plus and maybe others), launches from the Startup folder in the Start Menu, but not required as they give instructions on removing it on their webpage
watchdog.exe WatchDog
Part of Motorola "Mobile Phone Tools" v3 - in a "Mobiile Phone Tools" sub-directory of Program Files
WatchWAN.exe WatchWAN
WatchWAN keeps an accurate account of the data that is flowing between your computer and the Internet at any given moment. This readout is presented in both numerical and graphical format, in real time
waumgr.exe waumgr
Added by a variant of the IRCBOT TROJAN!
WaveFramer.exe WaveFramer
Part of SafeSpace (from Artificial Dynamics) which "protects computers from Internet malware infection without the need for signature updates or regular maintenance"
WaveTop.exe WaveTop Launcher
WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
WiFiMsg.exe WAWifiMessage
"HP Wireless Assistant is a user application that provides a method for controlling the enablement of individual wireless devices (such as Bluetooth or WLAN devices) and that shows the state of the radios for these wireless devices"
wbcmgr.exe Wbcmgr
Added by a variant of the IRCBOT BACKDOOR! See here
wben.exe wben
Appears to be related to Desktop Notifier from Starfield Technologies. What does it do and is it required?
Wbiff.exe Wbiff
Wbiff! E-mail checker - automatically checks your e-mail and notifies you if any new e-mail has been received
Wbutton.exe Wbutton
Turns on and off the integrated WiFi on Acer (and other laptops)
WCESCOMM.EXE WCESCOMM
Active sync for use with Windows CE based palm PC
WCEMNGR.EXE WCESMngr
Added by the AGOBOT-QX WORM!
WCheckUp.exe WCheckUp
Barok keylogger and password stealer
wcmdmgrl.exe wcmdmgr
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
wcmdmgr.exe wcmdmgr.exe
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
wcmdmgrl.exe wcmdmgrl
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
wintsvcc.exe WCPC
??
wintsvit.exe WCPI
PurityScan/Clickspring adware
Wint**.exe [* = random char] WCPS
PurityScan/Clickspring adware
wintsvtr.exe WCPT
PurityScan/Clickspring adware
wcsys.exe wcsys
Added by the KEYLOG-AP TROJAN!
WDBtnMgr.exe WD Button Manager
Button manager installed with a western digital external disk drive. Allows you to back up your system with one click
wdfmgr32.exe wdfmgr32.exe
Added by the DWNLDR-FVL TROJAN!
wdinfo.exe WDInfo
Added by the DLUCA.B TROJAN!
wdmon.exe wdmon
Detected as the BUZUS.DVE TROJAN!
wdns33.exe WDNS SYSTEM
Added by the MYTOB-BY WORM!
wdskctl.exe wdskctl
IEPlugin spyware
wdwctrl.exe wdwctrl
Added by the DLUCA.E TROJAN!
WD_SRT.EXE WD_SRT
Western Digital USB disk driver
WEATHER.EXE WEATHER
Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs
weatherpulse.exe Weather Pulse
Weather Pulse from Tropic Designs. "Display popular Satellite images and video from around the globe, share images with your friends and family, stay updated on current and expected weather conditions, it's just plain fun!"
Weather.exe WeatherCast
Weather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight
WeatherEye.exe WeatherEye
WeatherEye - desktop weather from TheWeatherNetwork
WeatherOnTray.exe WeatherOnTray
Hotbar adware
Weatherscope.exe Weatherscope
WeatherScope - "displays your current local temperature in the system tray of your computer (near the clock) whenever you are online!" Not recommended as it bundles GAIN adware. You can get the adware free version for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here
WeatherStudio Desktop.exe WeatherStudio Desktop
WeatherStudio adware
ww.exe WeatherWatcher
WeatherWatcher - weather reporting in the System Tray
Web2Pop.exe Web2Pop
Web2Pop allows you to retrieve your web-based accounts messages to read them in your favorite e-mail client
web3trap.exe web3trap
PC-Cillin 2000 anti-virus software → ActiveX filter. Guards against malicious ActiveX programs, etc
webalize.exe webalize
Searchcentrix hijacker
WAK.exe WebArmyKnife
Web Army Knife - a suite of web site developer's tools
webassist.exe webassist
Adware popup generator
webbuying.exe WebBuying
WebBuying adware
WebCallDirect.exe WebCallDirect
WebCallDirect - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype
webcam.exe webcam
Added by the MONAD-A TROJAN! Note - this malware actually changes the default value data of the Registry Run and RunServices keys in order to force Windows to launch it at boot. Name field may be empty
wbcgosvc.exe Webcam Go Sti Service Application
Control software for the portable Creative Webcam Go digital camera/PC web cam. What does it do and is it required?
WEBCAMRT.exe WebcamRT.exe
For Logitech Web Cams. Not required - camera works fine without it
webcel.exe Webcelerator
Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Now no longer available and supported and when available was classed as spyware - see here
WebCheck.pif WebCheck
Added by the CONE.C or CONE.F WORMS!
WebCpr0.exe WebCpr0
WebRebates adware
webdav.exe Webdav.exe
IRC DDoS bot which gives the hacker full control over your system
whagent.exe WebHancer Agent
System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here
whSurvey.exe webHancer Survey Companion
WebHancertrackware - traffic measurement service that uses a client agent that is stealth installed on user machines, gathering detailed data about sites visited, their performance and, most important, what the user actually does while there
WebInstall.exe WebInstall
ClipGenie adware downloader
WebInstall.exe WebInstall2
ClipGenie adware downloader
WebKey.exe WebKey
WebKey from JB Utilities. Utility to keep track of login data required when browsing the internet
WebLink.exe WebLink
Softex is a "cost-effective way to provide software updates, technical support or new product information to specific end-users - it can silently provide end-users with software updates, technical support and new product information customized to their specific needs through a persistent link"
wpsche~1.exe Webposition Gold 2
Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines
WebRebates0.exe WebRebates0
WebRebates adware
WDF.exe Webroot Desktop Firewall
Webroot Desktop Firewall
websaverlive.exe websaverlive
WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your computer is idle
WebSavingsfromEbatesrun.exe WebSavingsfromEbates
Web Savings From Ebates Software, a shopping tool that opens pop-up windows
WebSavingsFromEbates0.exe WebSavingsFromEbates0
Web Savings From Ebates Software, a shopping tool that opens pop-up windows
WebScanX.exe WebScanX
From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc
wjview ...websearch.exe websearch
"Web Savings" From Ebates Software, a shopping tool that opens pop-up windows
WebSecureAlert.exe WebSecureAlert
WebSecureAlert - "helps to protect your browser security by monitoring for unauthorized tampering with Internet Explorer's security settings, and can help to protect your privacy by deleting your web surfing history on a regular basis". Not recommended as it bundles GAIN adware. You can get the adware free version for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here
Webshots Tray.exe Webshots
Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web
websho~1.exe Webshots
Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web
WebshotsTray.exe Webshots
Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web
webadmin.exe Website Administrator Info
Added by the FORBOT-FY WORM!
wupda.exe WebSUpdater
Detected by Kaspersky as the STARTPAGE.C TROJAN! See here
webtrap.exe Webtrap
Part of PC-Cillin anti-virus software. Checks web-sites for malicious Java and ActiveX elements in a similar way to McAfee WebScanX. A few users find it infuriating
WebTrapNT.exe WebTrapNT.exe
Part of PC-Cillin Anti-Virus software. Checks visited web-sites for malicious Java and ActiveX elements
wwasher.exe WebWasher
Free Pop-up/ad/javascript filter program from Siemens. If not running then browsers will not be protected but will still work. Available via Start -> Programs
WeirdOnTheWeb.exe WeirdOnTheWeb
Added by the WeirdOnTheWeb adware
Welcome.exe Welcome
Launches the Welcome to Windows tutorial on boot up
Wepstat.exe WEPstat
Cisco Aironet 340 Series PC Card driver. If it can be started manually it shouldn't be required if you don't use the PC card facility regularily - hence the status could be "U". Can anybody confirm this?
wiustv.exe wesumu
Added by the QQPASS-L TROJAN!
wetsock.exe WetSock
RoboMagic Wetsock - weather reporting in the System Tray
WFGStartup.exe WFGStartup
World Weather. "This midlet displays the current weather conditions for major cities around the world. This version is for memory limited mobile phones"
WFXCTL32.EXE WFXCTL32.EXE
From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
wfxsnt40.exe wfxsnt40
WinFax 10.0 and maybe earlier versions. The program that opens the port for WinFax and not normally in the start menu. Needed if you want to run WinFax
WFXSWTCH.exe WFXSwtch
Related to WinFax. What does it do and is it required?
WG511WLU.exe WG511WLU
Netgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card
wgeax.exe wgeax
Added by the IRCBOT-TM WORM!
wgs3.exe wgs3
Added by the LEGMIR-AQH TROJAN!
WGV.exe WGV
Added by the ZIPPIE TROJAN!
WGWLocalManager.exe WGWLocalManager
Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so. It could be started by creating a shortcut, running it only when connecting to the internet. If internet is used often, it's recommended to leave it in startup so it starts with the system
WgwMngr.exe WgwMngr
Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so
whagent.exe whagent
System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here
WHATPU~1.EXE WhatPulse
WhatPulse keeps track of your keystrokes, allowing you to find out just how much you type a day
whse.exe WhenUSearchWHSE
WhenU.Save adware
whismng.exe Whistler
Added by the WHISTLER-F TROJAN!
Whvlxd.exe Whvlxd
Added by the ZAPCHAS-CS TROJAN!
wiascr.exe wiascr
Added by the AGENT.AM TROJAN! Note - example names include "XviD", "Winamp Remote", "Windows Media Player" and "Futuremark"
wifeman.exe wifeman
Unidentified malware
wifiboot.exe Wifi Boot
Added by a variant of the IRCBOT TROJAN! See here
wifibooter.exe Wifi Booter
Detected by Trend Micro as the IRCBOT.GP TROJAN! See here
wificonfig.exe Wifi Configuration
Added by the CHECKOUT WORM! See here
wificonfigs.exe Wifi Configuration!
Added by the CHECKOUT WORM! See here
wificon.exe Wifi Connection
Detected by Trend Micro as the SLENFBOT.AC TROJAN! See here
wificonnect.exe Wifi Connection!
Added by the CHECKOUT WORM! See here
wifidebug.exe Wifi Debug
Added by a variant of the IRCBOT TROJAN! See here
wifiload.exe Wifi Loader
Detected by Trend Micro as the IRCBOT.AVG TROJAN! See here
wifiloader.exe Wifi Loader!
Added by a variant of the IRCBOT TROJAN! See here
wifisetup.exe Wifi Setup
Added by a variant of the IRCBOT TROJAN! See here
WildFlics.exe WildFlics
Direct-B premium rate adult content dialler
wcmdmgrl.exe WildTangent Web Driver updater
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
WWMon.exe Wildwire Monitor
This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem
WillowRoad.exe Willow Road
Willow Road Screen Saver
WillPolo.vbs WillPolo
Added by the VBS_SOLOW.AF VIRUS!
windows.exe WIN
Added by the REATLE.C WORM!
Win Antivir 2008.exe Win Antivir 2008
Win Antivir 2008 rogue security software - not recommended, see here
Win Antivirus 2008.exe Win Antivirus 2008
Win Antivirus 2008 rogue security software - not recommended, see here
winchi~1.exe Win Chimes
WinChimes - enhancement software for the system clock that runs in the system tray
WinComm.exe Win Comm
Added by the WINCOM TROJAN!
winconfig.exe Win Config
Added by a variant of the IRCBOT BACKDOOR! See here
wuctl.exe win ctl app
Added by a variant of the SDBOT WORM!
windfrag.exe Win Defrag
Added by a variant of the SDBOT WORM! See here
windefrag.exe Win Defrag!
Added by a variant of the SDBOT WORM! See here
WIN HOST PROCESS.EXE WIN HOST PROCESS
Added by the KEYLOGGER.CLONE TROJAN!
winampa.exe Win l5oahder
Added by a variant of the RBOT WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of the Program Files directory
winlogin.exe Win Login
Added by the RBOT-AWE WORM! Note - this trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder
win14.exe Win Microsoft 98
Added by the RBOT-AKX WORM!
winupdates.exe Win Process Updates
Added by a variant of the SDBOT WORM!
winsecure.exe Win Security
Detected by Trend Micro as the IRCBOT.AVE BACKDOOR! See here
winserv.exe Win Server
Added by the IMISERV.A TROJAN!
wupdt.exe Win Server Updt
Added by the IMISERV.A TROJAN!
winserver.exe Win Server Updt
Added by a variant of the IMISERV TROJAN!
winsyncupx.exe Win Sync montr
Detected by Kaspersky as the RBOT.BYJ TROJAN! See here
wupda32.exe win update
Added by the SDBOT.J WORM!
wapdate.exe win update
Added by a variant of the RBOT WORM!
WINUPDATER.EXE Win Updater
Added by the RBOT.IP WORM!
winusb.exe WIN USB 2.0
Added by a variant of the RBOT WORM!
winamp.exe Win WinAmp
Added by the RBOT.AGF WORM! Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of the Program Files directory. This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
win*************.exe [* = random digit] win************* [* = random digit]
WINBO adware
WIN-BUGSFIX.EXE WIN-BUGSFIX
Added by the LOVELETTER (I LOVE YOU) VIRUS!
winis.exe win-xp
Added by the BROPIA.N WORM!
win.exe win.exe
Added by the PODROP-C TROJAN!
win16dll.exe win16.dll
Screenspy captures screenshots silently. If you didn't install this yourself, remove it
win23.exe win23.exe
Detected by Kaspersky as the BIFROSE.BSJ TROJAN! See here
WIN32.EXE WIN32
Added by the RATEGA TROJAN!
Win32.exe Win32
Added by the ISRAZ.A WORM!
winsrv32.exe win32
Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites
WinSetup.exe win32
Added by the EVILBOT.B TROJAN!
winhost.exe win32
Added by the BROPIA.J WORM!
winnnit.exe Win32
Added by a variant of the SDBOT WORM!
Winbios.exe Win32 Bios
Added by the SEMAPI-A WORM!
Win32.exe Win32 Critical File
Added by the RBOT-GUB WORM!
Win32Debug.exe Win32 Debug Manager
Added by a variant of the WOOTBOT WORM!
Win32ldr.exe Win32 Device Loader
Added by a variant of the AGOBOT/GAOBOT WORM!
winlogons.exe Win32 Drivers
Added by the FORBOT-FG WORM!
wdrk32.exe Win32 DRK Driver
Added by the WOOTBOT.CY WORM!
winstr32.exe Win32 exe file
Added by a variant of the SPYBOT WORM!
winfw.exe Win32 Firewall Driver
Added by a variant of the RBOT WORM!
win32help.exe Win32 Help32 Service
Added by the DELBOT-U WORM!
windowsnfo.exe Win32 Info
Added by a variant of the IRCBOT TROJAN!
winserver.exe win32 internet server
Added by the DERMON-D TROJAN!
win32update.exe Win32 Kernel Update
Added by the PROXY-BS TROJAN!
winwkys.exe Win32 Services Config
Added by the RBOT.BKY WORM!
wuamngr1.exe Win32 Services1
Added by the SDBOT-PV WORM!
win32src.exe Win32 Src Service
Added by the RBOT-SX WORM!
winssv.exe Win32 SSL Driver
Added by the FORBOT-BH WORM!
winservice.exe Win32 System Kernel
Added by the SDBOT.KIN WORM!
winserver.exe win32 system server
Added by the DERMON-A TROJAN!
winxpinit.exe Win32 USB Driver
Added by the SDBOT.AA TROJAN!
wins32.exe Win32 USB2
Added by a variant of the RBOT WORM!
win32usb.exe Win32 USB2 Driver
Added by the SPYBOT.DHV WORM!
wind32.exe Win32 USB2 Driver
Added by the FORBOT-AH WORM!
winupdate.exe Win32 USB2 Driver
Added by the AGOBOT.YE WORM!
winsnd32.exe Win32 USB2 Driver
Added by a variant of the SDBOT WORM!
w32usb2.exe Win32 USB2.0 Driver
Added by the SPYBOT.DN WORM!
win32tool.exe Win32 USB3 Driver
Added by a variant of the RBOT WORM!
winitr32.exe Win32 Wmls Driver
Added by the WOOTBOT.B WORM!
win32.exe win32.exe
Added by the STARTPAGE TROJAN!
Win32.exe Win32.exe
Added by the AWQ.A TROJAN!
Wintask.exe Win32BaseServiceMOD
Added by the NAVIDAD WORM!
win32sys4.exe win32beta
Added by the BANKER-DA TROJAN!
win32clf.exe win32clf
Added by an unidentified VIRUS, WORM or TROJAN!
win32debug.exe win32debug
Added by the GUDEB WORM!
Win32DLL.vbs Win32DLL
Added by the LOVELETTER (I LOVE YOU) VIRUS!
Win32dll.exe Win32dll
Added by the BANPAES TROJAN!
win32gb.exe win32gb
Added by the DLUCA-F TROJAN!
webemir.exe Win32Host Process
Added by the TURGEN -A TROJAN!
win32info.exe win32info
Adult content dialler
Win32sl.exe WIN32SL
Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. The specific function of this is to load MIF's in order for Dell OpenManage Client to work
win32s.exe Win32System
Added by the MYDOOM.V WORM!
win32us.exe win32us
All-In-One-Telcom (adult content dialler) variant
WinCab.exe Win32Usr
Added by the DEDMIR-A WORM!
win32_i.exe win32_i lptt01
RapidBlaster variant (in a "win32_i" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
win32_i.exe win32_i ml097e
RapidBlaster variant (in a "win32_i" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
Win386.exe Win386
Added by the GOSUSUB VIRUS!
winabsmod.exe WIN3S2SNDS
Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well"
winiprtx.exe WIN3S2SNDS
Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well"
wingrd.exe win98 DNS
Added by a variant of the RBOT WORM!
winable.exe WinAble
Added by the MATCASH.BG TROJAN!
Winacsr.exe Winacsr
AceScreenSpy keystroke logger/monitoring program - remove unless you installed it yourself!
WINACTIVE.EXE winactive
WinActive of the LOP.com hijacker
WinActiveJ.exe WinActiveJ
Added by the ROTARRAN VIRUS!
Winad.exe Winad Client
WinAd adware by eXact Advertising
WinAdCnt.exe WinAdCnt.exe
Added by the BANKER-BU TROJAN!
winadm.exe winadm
Browser hijacker - redirecting to Search-World.net. Related to the SMALL.AEX TROJAN!
WinAgent.exe WinAgent
Standard Life Insurance program. Is it required at startup?
Winahlp.exe Winahlp.exe
Added by a variant of the VAGRNOCKER TROJAN!
winallap.exe winallap
Added by the DELF.E TROJAN!
winallapu.exe winallapu
Added by the DELF.E TROJAN!
winamp.hta Winamp
Hijacker - re-directing to adult content sites. Note - this isn't the real Winamp
winamp.exe Winamp
Added by the AGOBOT.XI WORM! Note - this is NOT the popular Winamp media player
winamp62.exe WinAMP
Added by the SDBOT-WN WORM!
winamp.exe Winamp
Winamp media player. Resides in a "Winamp" subdirectory of the Program Files directory
winamp.exe Winamp Agent
Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player. The valid filename for the Winamp Agent is "winampa.exe" - see here
winapa.exe Winamp media player
Added by an unidentified VIRUS, WORM or TROJAN!
winamap.exe Winamp Media Player
Detected by PCTools as the SDBOT.ACJM BACKDOOR! See here
winamp.exe Winamp Media Player
Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of %ProgramFiles%
winampp.exe WinAmp Player
Added by the RBOT-AQI WORM! Note - this is NOT the popular Winamp media player which has a different filename
Winamp6.exe Winamp Player 6
Added by a variant of the SPYBOT WORM!
winamptogoogletalk.exe Winamp to Google Talk
Winamp to Google Talk, available here shows your current Winamp track in your Google Talk status
WINAMPa.exe Winampa
Loads the System Tray icon for the popular Winamp media player - see here. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs. Resides in a "Winamp" subdirectory of the Program Files directory
winampa.exe Winampa
Added by the AGOBOT-GS TROJAN! ! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of the Program Files directory whereas this file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
WINAMPA.EXE Winampa Agent
Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player. The valid filename for the Winamp Agent is "winampa.exe" - see here
WINAMPa.exe WinampAgent
Loads the System Tray icon for the popular Winamp media player - see here. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs. Resides in a "Winamp" subdirectory of the Program Files directory
Winagent.exe WinAmpAgent
Added by the EB TROJAN! Note - this is NOT the popular Winamp media player which has a different filename
was5.exe WinAntiSpyware 2005
WinAntiSpyware 2005 spyware remover - not recommended, see here
was7.exe WinAntiSpyware 2007
WinAntiSpyware 2007 spyware remover - not recommended, see here
WinAntispyware2008.exe WinAntispyware2008
WinAntispyware2008 rogue spyware remover - not recommeded, see here
WinAV.exe WinAntiVirus Pro 2007
WinAntiVirus Pro 2007 misleading virus software - not recommended, see here
winapix.exe WinApi
Added by a variant of the TIBSER.A downloader TROJAN!
WINAPLOGUPD.EXE WINAPLOGUPD
Added by the CAPSIDE-C WORM!
winpup32.exe Winapp
Produces popup ads to adult content sites
winlogon.exe WinAuth
Hijacker, also indentified as the STRTPAGE.BE TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
WinAvXX.exe WinAVX
Added by the FAKEAVALERT TROJAN!
WinAvX.exe WinAvX
WinAntiSpyware spyware remover - not recommended, see here
WinAwk.exe WinAwk
Added by the SDBOT-AYF WORM!
Wbsched.exe WinBackup Scheduler
LIUtilities WinBackup scheduler - backup software
WinBar.exe WinBar
"WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls"
winbed.exe Winbed
Hijacker
win32exe.exe winbin32
Added by the RBOT-ZL WORM!
winbo32.exe winbo32
Added by the RBOT-GRU WORM!
winboot.exe winboot
Added by the BANLOAD-W TROJAN!
winbot.exe winbot
Added by the MIDRUG-A TROJAN!
winbrush.exe WinBrush
WinBrush - "handy tool that keep your privacy and make your system clean. It works by cleaning up your tracks (document histories, recent opened files from popular software, cookies, temporary internet files, etc)"
WinButler.exe WinButler
Identified as a variant of the Trojan-Dropper.Agent.DKN malware
WinCheck.exe WinCheck
Added by the PWS-CY TROJAN!
winchost.exe winchost
Added by the DLOADER-PO TROJAN!
WINCIN~1.EXE WINCINEMAMGR
WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
WinCinemaMgr.exe WinCinemaMgr
WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
WinRemote.exe WINCINEMAMGR
InterVideo WinCinema Manager - needed for the use of WinDVD Remote Control
winclean.exe winclean
Added by the AGENT.GXR TROJAN!
wincmapp.exe wincmap
CasClient adware variant - also detected as the CMAPP TROJAN!
WinColorReminder.exe WinColorReminder
The Microsoft Color Control Panel Applet for Windows XP "helps you manage Windows color settings in one place." Part of the Pro Imaging Powertoys
WinCore32.exe WinCore32.exe
Added by the CLICKER-EN TROJAN!
wincrt32.exe WinCRT32
Added by the DOGBOT-D WORM!
winctl.exe winctl
Added by the IRCBOT-YI TROJAN!
wincore332.exe WINCX
Added by the AGOBOT-MG WORM!
wind.exe wind.exe
Added by the MITGLIEDER.BD TROJAN!
WIND0WS.exe WIND0WS
Added by the SPYBOT.DQ WORM!
wordpad.exe Wind0ws
Added by the AGOBOT-TL WORM! Note - this is not the legitimate Windows application wordpad.exe (which is found in the Program FilesAccessories folder) which should not normally be seen in Msconfig or as a Startup item. This file is loacted in the System (9x/Me) or System32 (NT/2K/XP) folder
Wind32.exe Wind32
Identified as a variant of the Backdoor.Win32.Poison.avs malware
windates.exe WinDates
WinDates is a calendar, date organizer and event reminder program from Rockin' Software
winxtc.exe windbs
Added by the AGOBOT-WD WORM!
winde.exe Winde
Added by the DLUCA TROJAN!
Win32sp.vbs windef
Added by the ANPES WORM!
windef.exe windef
Added by the WURMARK-O WORM!
windefender.exe windefender
Added by the AGENT.BYH TROJAN!
windhost.exe windhost.exe
Added by the BANKER-BV TROJAN!
winos.exe windhost.exe
Added by the PWSAGENT-A WORM!
winrun.exe windir
Added by the WINBUR.B WORM!
wuaumqr1.exe Windir Working
Added by a variant of the IRCBOT TROJAN!
Windll.exe Windll
Added by the TRYNOMA TROJAN!
WSYS.EXE WINDLL
STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes, all passwords transacted even if they weren't keyed in, all web sites visited, every program launched including the path to that program, and more"
windll32.exe windll
Added by the ASTEF or RESPAN WORMS!
Windll.exe Windll.exe
Added by the STEALER TROJAN!
Windll32.exe Windll32
Added by the MSNPWS TROJAN!
windllsys32.exe windllsys32.exe
Added by a variant of the MITGLIE-A TROJAN!
windns32.exe WinDNS
Added by the GAOBOT.WX WORM!
winmon32.exe Window Monitor
Added by the SDBOT.RT WORM!
wwDisp.exe Window Washer
Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
window.exe window.exe
Added by the MITGLIEDER.H or MITGLIEDER.J TROJANS!
wbload.exe WindowBlinds
WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins
Winex.exe WindowEnhancer
SCBar foistware variant
winupdatr.exe Windowfdgfds DasdLL Verifier
Detected by Trend Micro as the AGOBOT.HZ WORM! See here
Windowsdldfglcheckkk.exe Windowfdgfds DLL fgfdg Verifier
Added by the RBOT.CSP WORM!
winsecure.exe Windowfdgfds DLL fgfdg Verifier
Added by a variant of the RBOT WORM!
wfxload.exe WindowFX
Stardock WindowFX - "Allows you to add an unprecedented number of special effects to windows"
wiusyt.exe windown
Added by the QQPASS-M TROJAN!
wins.exe WindowRegKey update
Added by the SPYBOT.I WORM!
Windows.exe Windows
Added by the KAZMOR.A, BOBBINS & ALADINZ.D TROJANS!
windows.exe WINDOWS
Added by the MONBOT-A TROJAN!
WICleaner.exe Windows & Internet Cleaner Pro
Windows & Internet Cleaner Pro - "Powerful and easy to use internet surfing privacy protection & PC security software"
websvc.exe Windows .Net Manager
Added by the DLOADER-NY TROJAN!
win128.exe Windows 128 Module
Added by the FORBOT-ES WORM!
Win32edit.exe Windows 32 Editor
Added by the WOOTBOT.GQ WORM!
win32resc.exe Windows 32 Rescue
Added by the FORBOT-EU WORM!
Windows-Update.exe Windows 32 Update
Added by a variant of the RBOT WORM!
wauclt.exe Windows Account Alternation
Added by a variant of the IRCBOT TROJAN! See here
WinAdCtl.exe Windows AdControl
Windupdates adware variant
WinAdServ.exe Windows AdService
Windupdates adware variant
WinStat.exe Windows AdStatus
Added by the BLESHARE!DR VIRUS!
WinAdTools.exe Windows AdTools
Windupdates adware variant
Windows-Anti.exe Windows Anti Verifier
Added by the RBOT.ETT WORM!
winavscan.exe Windows Anti Virus Control Center
Added by a variant of the IRCBOT BACKDOOR!
walg32.exe Windows Application Layer
Added by the AGOBOT.ATN WORM!
walg32.exe Windows Application Layer Gateway
Added by the AGOBOT-AAZ WORM!
winlogon.exe Windows ARP Detectionc
Detected by Trend Micro as the RBOT.EAB WORM! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
winlogon.exe Windows ARP Detectioncx
Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!
winupdater.exe Windows Auto Update
Added by the SDBOT.TF WORM!
WINDOWSUPDATE.EXE Windows Auto Updater
Added by the SDBOT.PB WORM! Note that there is a space at the beginning of the filename, ie, " WINDOWSUPDATE.EXE"
wuamgrder.exe Windows Automatic Update
Added by a variant of the RBOT WORM!
windrg.exe Windows Automatic Updater
Added by a variant of the RBOT WORM!
winboot.exe Windows Boot
Detected by Trend Micro as the AGENT.HBD TROJAN! See here
windowsboot.exe Windows Boot
Added by a variant of the IRCBOT TROJAN! See here
winboot.exe Windows Booter
Added by a variant of the IRCBOT TROJAN!
winbooter.exe Windows Booter!
Added by a variant of the IRCBOT TROJAN! See here
WINDOWS CLEAN-UP PRO.Exe Windows Clean-Up Pro
Windows Clean-Up Pro spyware remover - not recommended, see here
winclean.exe Windows Cleaner Service
Added by a variant of the IRCBOT TROJAN! See here
wincmd.exe Windows Command
Added by the RBOT.ANV WORM!
wincomm.exe Windows Communicator
Added by the AGOBOT-BH WORM!
windowsconf.exe Windows Conf
Added by a variant of the IRCBOT TROJAN! See here
wins.exe Windows Config
Added by the SPYBOT.JR WORM!
winconfig.exe Windows Config
Detected by Trend Micro as the IRCBOT.BAP BACKDOOR! See here
Wincfg32.exe Windows Config Loader
Added by the SILVERFTP TROJAN!
winconf.exe Windows Config Manager
Added by the RBOT-AIT WORM!
wsys32.exe Windows Configuration
Added by the GAOBOT.FB WORM!
wincfg32.exe Windows Configuration
Added by the MYTOB.ED WORM!
winxupdate.exe Windows Configuration Utility
Added by the AGOBOT.LW WORM!
winconf.exe Windows Configurator
Added by a variant of the IRCBOT TROJAN!
wkssvc.exe Windows Console
Added by the SDBOT-DJX WORM!
wrasvc.exe Windows Console Component
Added by a variant of the IRCBOT TROJAN! See here
wnbsvc.exe Windows Console Norms
Added by a variant of the IRCBOT TROJAN! See here
wnbsvc.exe Windows Console Source
Added by a variant of the IRCBOT TROJAN! See here
WinCtlAd.exe Windows ControlAd
Windupdates adware variant
win32bootcfg.exe Windows Core Kernel Update
Added by the RANCK-EL TROJAN!
winbog32.exe Windows CPU host
Added by a variant of the RBOT WORM!
wincrt.exe Windows Critical Alert
Added by the ALEDO-A TROJAN!
WinDat.exe Windows Database
Added by an unidentified WORM or TROJAN!
wiinsvc.exe Windows Database
Added by the AGOBOT-RU WORM!
windde32.exe Windows DDE Loader
Added by the SDBOT-UZ WORM!
winlogg.exe Windows debug logging
Added by the RBOT-OY WORM!
winloggs.exe Windows debug logging
Added by the RBOT-QN WORM!
windbg.exe Windows Debugger
Added by an unidentified VIRUS, WORM or TROJAN!
windbg32.exe Windows Debugger
Added by the ZOTOB.L WORM!
wfdmgrsp.exe Windows Default Server
Detected by Kaspersky as the IRCBOT.BCX TROJAN! See here
winampa.exe Windows Default Server
Added by the IRCBOT.AUN WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of the Program Files directory
wdc*.exe Windows Defender
Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com
wda*.exe Windows Defender Adds
Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com
wdm*.exe Windows Defender Monitor
Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com
wdu*.exe Windows Defender Updater
Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com
windesktop.exe Windows Desktop Controler
Added by the SDBOT-XH WORM!
winpadg.exe Windows Desktop Daemon
Added by a variant of the SPYBOT WORM!
WindowsSearch.exe Windows Desktop Search
Windows Desktop Search from Microsoft
wpabaln32.exe Windows Disk Defragmenter
Added by the BANCOS-ASJ TROJAN!
winupd32.exe Windows DLL host
Added by a variant of the SPYBOT WORM!
wdevice.exe Windows DLL Loader
Added by a variant of the SDBOT WORM!
WINCFG32.EXE Windows DLL Loader
Added by the AGOBOT-TE WORM!
winsvc32.exe Windows DLL Services
Added by the RBOT-ZF WORM!
windlls.exe Windows DLL Verifier
Added by the RBOT-AZQ WORM!
windns.exe Windows DNS
Added by the SDBOT-XU WORM!
windnsd.exe Windows DNS Daemon
Added by the WOOTBOT.AS WORM!
windns.exe Windows Domain Name Drivers
Added by the FORBOT-EP WORM!
windlmngr.exe Windows Download Manager
Added by an unidentified TROJAN!
winxpdriver.exe Windows Driver
Added by the WOOTBOT.EE WORM!
windrive.exe Windows Driver
Added by a variant of the IRCBOT TROJAN! See here
windvrhost.exe Windows Driver Sup
Added by a variant of the IRCBOT BACKDOOR! See here
windrive.exe Windows Driver!
Added by a variant of the IRCBOT TROJAN! See here
windriver.exe Windows Driver!
Added by a variant of the IRCBOT TROJAN! See here
windowsupdate.exe Windows drivers update
Added by the RBOT-ACE WORM!
winDLL32.exe Windows Dynamic Loading Header
Added by a variant of the SDBOT WORM!
wmserv.exe Windows Email Server
Added by the FOUNDU-AWORM!
wecsvc.exe Windows Event Detection
Added by a variant of the IRCBOT TROJAN! See here
wposvc.exe Windows Event Provider
Added by a variant of the IRCBOT TROJAN! See here
winserv.exe Windows Event Service
Detected by Kaspersky as the SDBOT.XD TROJAN! See here
winmys.exe Windows Executable
Added by the RBOT-ABO WORM!
Winexec32.exe Windows Explorer Shell
Added by the REDIST.B WORM!
WINRE16.EXE Windows Explorer-3212
Added by the HARDOC WORM!
winprgs32.exe Windows Extensions for Win32
Added by the SDBOT.AFA WORM!
WINFAT32B.exe Windows FAT 32
Added by the SPYBOT-AGT WORM!
winprotect.exe Windows File Protection
Added by the AGOBOT.JB WORM!
wfvs.exe Windows File Verification Service
Added by the RANKY.AC TROJAN!
wfdmgr.exe Windows File XP Manager
Added by the SDBOT.XD TROJAN!
WindowsFirewall.exe Windows Firewall
Added by the MYTOB.AO WORM!
winlog.exe Windows Firewall Log
Added by an unidentified WORM or TROJAN!
wfsvc.exe Windows Firewall Service
Added by the IRCBOT-YL WORM!
winmu.exe Windows Firewalll
Added by a variant of the RBOT WORM!
WinForm.exe Windows FormatAd
Windupdates adware variant
winservicessss.exe Windows Genuine Validate
Detected by PCTools as the IRCBOT.UUI BACKDOOR! See here
wingmt32.exe Windows GMT32
Added by the MYTOB.KM WORM!
wingraphics.exe Windows Graphics Loaders
Added by the SPYBOT.JG WORM!
WAUMGRD.EXE Windows Guard
Added by the RBOT-GY WORM!
winhelper32.exe Windows Help File
Added by the SDBOT-QK TROJAN!
winhelpsv.exe Windows Help Service
Added by the RBOT-LP WORM!
winhlp.pif Windows Help Service
Added by the RBOT-AKW WORM!
winhelp.exe Windows Helper
Detected by Kaspersky as the BANKER.APE TROJAN! See here
wsctnfy.exe Windows Helper
Added by a variant of the IRCBOT BACKDOOR! See here
winhost.exe Windows Host
Added by the PRYSAT TROJAN!
winhosts.exe Windows Hosts
Added by a variant of the IRCBOT TROJAN!
winhttps.exe Windows HTTP services
Added by a variant of the SDBOT WORM! See here
wicomgr.exe Windows Icons Manager
Added by the RBOT-AIF WORM!
wID32.exe WINDOWS ID SYSTEM
Added by the MYTOB.LN WORM!
wintimage.exe Windows Image
Detected by Avast as the SDBOT-GEN44 WORM!
WIAcs.exe Windows Image Acquisition (WIASC)
Added by the RIZO.A TROJAN!
WIAcss.exe Windows Image Acquisition (WIASSC)
Added by the RIZO.A TROJAN!
winimsg.exe Windows iMessenger Messenger
Added by the ALLIM.A WORM!
winstall.exe Windows installer
SpySheriff malware. For more information on registry key changes see SPYWAD-E
winstruct32.exe Windows Instruction Services
Added by a variant of the IRCBOT TROJAN! See here
winproc32.exe Windows Internet Protocol
CoolWebSearch Winproc32 parasite variant - also detected as the STARTPA-BF TROJAN!
wininet.exe Windows Internet Service
Added by the RBOT-AUX WORM!
wipv6.exe Windows IPv6 Drivers
Added by the SDBOT-VJ WORM!
weatherBug32.exe Windows Java Update
Added by a variant of the RBOT WORM!
Winjsd.exe Windows JavaScript Daemon
Added by the WOOTBOT.AF WORM!
wkssvr.exe Windows Kernel System Service
Added by a variant of the RANDEX.GEL WORM!
winkeyboard.exe Windows Keyboard Services
Detected by Trend Micro as the IRCBOT.AFS WORM! See here
winkeybrd.exe Windows Keyboard Services
Added by a variant of the IRCBOT TROJAN! See here
winkeybrd32.exe Windows Keyboard Services
Added by a variant of the IRCBOT TROJAN! See here
winlivemgr.exe Windows Live Manager
Detected by Trend Micro as the SHEUR.EB WORM! See here
wllivemsngr.exe Windows Live Messenger Addon
Added by a variant of the SDBOT WORM! See here
wlivemsg.exe Windows Live Msgs
Added by a variant of the IRCBOT TROJAN! See here
wlivemsgs.exe Windows Live Msgs!
Added by a variant of the IRCBOT TROJAN! See here
wlmsngr.exe Windows live Support
Added by the RBOT-BKL WORM!
windows.com Windows Load
??
wstart32.exe Windows Loader
Added by the GAOBOT.CA WORM!
winServices.pif Windows Loader
Reported by Kaspersky Anti-Virus as the CARDSPY.D TROJAN!
Win_.exe windows Loadxm
Added by the FODDER-A TROJAN!
winthcr.exe Windows Local ISP
Detected by Trend Micro as the SDBOT.ENZ BACKDOOR! See here
websvc.exe Windows Local Services
Added by the DLOADER-NY TROJAN!
wsass.exe Windows Locator
Added by the IRCBOT.N TROJAN!
winlogon.exe Windows Log Agent
Added by the KEYLOGGER.AVK TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files
winlog.exe Windows Logger
Added by the NSHADOW-B TROJAN!
winlogd.exe Windows logging
Added by the RBOT-ON WORM!
wsrsvc.exe Windows Logical Adapter
Detected by Kaspersky as the IRCBOT.ARU TROJAN! See here
wcnsvc.exe Windows Logical Connection
Detected by Kaspersky as the VIRUT.AO VIRUS! See here
winlog.exe Windows Login
Added by the AGOBOT.MG WORM!
winzep.exe Windows Login Folder
Added by the AGOBOT-TZ WORM!
winlogin.exe Windows Login Manager
Added by a variant of the SDBOT WORM!
winlogin.pif Windows Login Security
Added by an unidentified WORM or TROJAN!
winlog.exe Windows Login Service
Added by the RBOT-AFN WORM!
winlogin.pif Windows Login Service
Added by the SDBOT-ACU WORM!
winlogin.exe Windows Logon
Added by the SPYBOT-C TROJAN!
WinIogon.exe Windows Logon Application
Added by the LINKBOT.M WORM!
win32help.exe Windows Logon Application
Added by the DELBOT-X WORM!
winlogon.exe Windows Logon Application
Added by the POEBOT-KW WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
winamp.exe Windows Logon Application
Added by the POEBOT-LR WORM! Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of the Program Files directory
winlogon.exe Windows Logon Applicationedc
Added by the DWNLDR-HGR TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%
winlogonpc.exe windows logon procedure
Added by the WINLOGON TROJAN!
winlogon.pif Windows Logon Service
Added by the RBOT-AOU WORM!
winlolx.exe Windows LoL Layer
Added by the RBOT-FOR WORM!
win.exe Windows LoL Layer
Added by the RBOT-FTO WORM!
wm1exe.exe WINDOWS MANAGEMENT SYSTEM
Added by the RBOT-VT WORM!
winmants.exe Windows Manager
Added by the MANTAS WORM!
winsrv.exe Windows Manager
Added by a variant of the AGOBOT/GAOBOT WORM!
winlogonn.exe Windows mangement
Added by the RANDEX.FC WORM!
winmapp.exe Windows Media AP
Added by an unidentified WORM or TROJAN!
wmapp.exe Windows Media APP
Added by an unidentified WORM or TROJAN!
WMCCFG.exe Windows Media Connect 2
Windows Media Connect from Microsoft - stream digital media files on your computer to digital media receivers (DMRs) that are connected to your home network
wmloader.exe Windows Media Loader
Added by a variant of the GAOBOT WORM!
wmediaplayer.exe Windows Media Player
Added by the AGOBOT-NQ WORM!
wmplayer.exe Windows Media Player
Added by the KELVIR.G WORM or variants! Note - this is not the valid Windows Media Player as the executeable resides is C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP) rather than C:Program FilesWindows Media Player
wmpa36.exe Windows Media Player 3.6
Added by a variant of the RBOT WORM!
WMPA36B.EXE Windows Media Player 3.6b
Added by the RBOT-VV WORM!
wmpa36d.exe Windows Media Player 3.6d
Added by the RBOT-YA WORM!
wmpa36.exe Windows Media Player 3.9
Added by a variant of the RBOT WORM!
wmedia.exe Windows Media Player Service
Added by the RBOT.213504 WORM!
wmserv.exe Windows Media Server
Added by a variant of the IRCBOT TROJAN! See here
wmserver.exe Windows Media Server!
Added by a variant of the IRCBOT TROJAN! See here
wmediautil.exe Windows Media Utility
Added by a variant of the SPYBOT WORM!
windowsmem.exe Windows Memory Manager
Added by a variant of the IRCBOT TROJAN! See here
winlogin.exe Windows Messanger Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
winlogon.exe Windows Messanger Control Center
Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
winsys.exe Windows Messanger Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
wmdsvc.exe Windows Messenger Connect
Detected by Trend Micro as the SLENFBOT.S WORM! See here
wivsvc.exe Windows Messenger Fileshare
Detected by Symantec as the SILLYIM WORM! See here
winlivemsnmessenger.exe Windows Messenger Live MSN
Added by a variant of the IRCBOT BACKDOOR!
windowslivemsn.exe Windows Messenger Live Startup
Added by an unidentified WORM or TROJAN! See here
windowsmsnlive.exe Windows Messenger Live Startup
Detected by Kaspersky as the DELF.DAX TROJAN! See here
winmsg.exe Windows Messenger Messenger
Added by the VELKBOT.A WORM!
wbcsvc.exe Windows Messenger Panel
Detected by Trend Micro as the IRCBOT.ADA TROJAN! See here
winsmsgr.exe Windows Messenger Service
Added by the RBOT-VW WORM!
wmssvc.exe Windows Messenger Share
Added by a variant of the IRCBOT TROJAN! See here
wmvsvc.exe Windows Messenger Starter
Detected by Trend Micro as the SLENFBOT.T WORM! See here
wupdates32.exe Windows Micro Drivers
Added by the RBOT-AEH WORM!
wintask32.exe Windows Microsoft Update
Added by a variant of the SDBOT WORM!
winauth23.exe Windows Microsoft Verifier
Added by a variant of the RBOT WORM!
wmdc.exe Windows Mobile Device Center
Windows Mobile Device Center for Windows Vista. Replaces Microsoft ActiveSync and provides overall device management features for your Windows Mobile powered devices for Windows Vista
wmdSync.exe Windows Mobile-based device management
Part of Windows Mobile Device Center in Vista. Microsoft Windows Mobile Device Center enables you to set up new partnerships, synchronize content and manage music, pictures and video with Windows Mobile powered devices (Windows Mobile 2003 or later)
wmdc.exe Windows Mobile-based device management
Windows Mobile Device Center for Windows Vista. Replaces Microsoft ActiveSync and provides overall device management features for your Windows Mobile powered devices for Windows Vista
Windows-mod.exe Windows mod Verifier
Added by the RBOT.DSU WORM!
w1nz0zz0.exe Windows modez Verifier
Added by a variant of the SDBOT WORM!
Window2.exe Windows modez Verifier
Added by a variant of the RBOT WORM!
WindowsLogon.exe Windows modez Verifier
Added by a variant of the SDBOT WORM!
Wwuamguard.exe Windows modez Verifier
Added by the RBOT.EZJ WORM!
winlogom.exe Windows modez Verifier
Added by a variant of the RBOT WORM!
Windows-.exe Windows modez Verifier
Added by the RBOT-DIO WORM!
winl0g0z.exe Windows modez Verifier
Added by the RBOT-FNB WORM!
wuamguard.exe Windows modez Verifier
Detected by Kaspersky as the RBOT.CYA TROJAN! See here
winmon.exe Windows Monitor
Added by the SDBOT.VB WORM!
winmonitor.exe Windows Monitor Services
Added by the RBOT-XX WORM!
winmon.exe Windows Monitoring Service
Added by a variant of the SDBOT WORM!
winmouse.exe Windows Mouse Services
Added by the CHECKOUT WORM! See here
winmouse64.exe Windows Mouse Services
Detected by Trend Micro as the IRCBOT.AIA TROJAN! See here
winlog.exe Windows MSConfig Startup Logger
Added by the RBOT.BCU WORM!
wmsnlive.exe Windows MSN Live Messanger
Detected by Kaspersky as the RBOT.BMV TROJAN! See here
winlivemsn.exe Windows MSN Live Messenger
Added by an unidentified WORM or TROJAN! See here
winmessengerlive.exe Windows MSN Live Messenger
Detected by Kaspersky as the IRCBOT.EAD BACKDOOR! See here
wnd32.exe Windows MSN Updates
Added by the IRCBOT-ABA TROJAN!
winmsx.exe Windows MSX drivers
Added by the RBOT-AYG TROJAN!
wrmana32.exe Windows NetDDe
Added by the MYTOB.IM WORM!
WinNET.exe Windows Nets
Added by the RBOT-MO WORM!
winsN2S.exe Windows NetStart Service
Added by the RBOT-ZX WORM!
winsN2S.exe Windows NetStart Service2
Added by the RBOT-ABN WORM!
winsN2SD.exe Windows NetStart Service2
Added by a variant of the RBOT WORM!
WinxPupd.exe Windows Network Controller
Added by the FORBOT-DK WORM!
winmms32.exe Windows Network Controller
Added by the FORBOT-ED WORM!
wingmt.exe Windows Network Controller
Added by a variant of the SDBOT WORM!
Win9x.exe Windows Network Controller
Added by the WOOTBOT.I WORM!
winvc32.exe Windows Network Service
Added by the RBOT.RY WORM!
winnetwork.exe Windows Network Services
Added by a variant of the IRCBOT TROJAN! See here
winnetwork128.exe Windows Network Services
Added by the CHECKOUT WORM! See here
winnetwork32.exe Windows Network Services
Added by a variant of the IRCBOT TROJAN! See here
winnetwork64.exe Windows Network Services
Added by a variant of the IRCBOT TROJAN! See here
winsys32.exe Windows Networking
Added by the GAOBOT.FL WORM!
WNSM.EXE Windows NT Login Session Manager
Added by the RBOT.BIV WORM!
winlogon.scr Windows NT Logon Application
Added by the RBOT-ALP WORM!
winshock.exe Windows NT Service Name
Added by the RBOT-PK WORM!
WINL0G0N.exe Windows NT Update Manager
Added by the AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital "o"
winres32.exe Windows OEM Tools
Added by the SPYBOT.FD WORM!
winmgr.exe Windows Pc
Added by the BIBOT-A WORM!
winpdg.exe Windows PDG
Added by the RBOT-ADW WORM!
wmscupd.exe Windows Performance Monitor
Added by the IRCBOT_GEN WORM!
winpnp.exe Windows PNP
Added by the RBOT-AKN WORM!
winpo32.exe Windows Population Logger
Added by the AGENT.YKR WORM!
WinPrint.exe Windows Printing Driver
Added by a variant of the RBOT WORM!
WinSpooler.exe Windows Printing Driver
Added by an unknown malware
win_update.exe Windows Process
Added by the LASTWORD WORM!
winproc.exe Windows Process Manager
Added by an unidentified WORM or TROJAN!
WinSecure32.exe Windows Proffesional Security
Added by the AGOBOT.VA WORM
wservice.exe Windows Reg Services
Added by the PRORAT-O TROJAN!
winservicess.exe Windows Registers
Added by a variant of the SDBOT WORM!
winhost.exe Windows Registry
Added by a variant of the RBOT WORM!
winclean.exe Windows Registry Cleaner
Added by a variant of the SPYBOT WORM!
winreg.exe Windows Registry Control
Added by a variant of the IRCBOT TROJAN! See here
winregdll.exe Windows Registry DLL
Detected by Trend Micro as the IRCBOT.FB TROJAN! See here
winses.exe Windows Registry Name
Added by the RBOT-ADB WORM!
winmedia.exe Windows Registry Scan
Added by the SPYBOT.GK WORM!
wind32.exe Windows Registry Startup
Added by the AGOBOT-BZ WORM!
winxptdl.exe Windows Registry XP
Added by the IRCBOT.AUN WORM!
wnpcgs.exe Windows Remote Addressing
Added by the DELF-EZN TROJAN!
wnpmcs.exe Windows Remote Launcher
Detected by Kaspersky as the IRCBOT.ASX TROJAN! See here
winsto.exe Windows Rescue System
Detected by Kaspersky as the SUURCH.CG TROJAN! See here
winrvp.exe Windows Reverse Preperation
Added by a variant of the IRCBOT TROJAN! See here
winrsvp.exe Windows Reversed Virus Protection
Added by a variant of the IRCBOT TROJAN! See here
win64rt.exe Windows Run-Time 64bit
Added by a variant of the RBOT WORM!
win32hlp.exe Windows Runtime Help
Added by a variant of the AIMVISION TROJAN!
WinRunHelp.wrh Windows Runtime Help
Added by a variant of the AIMVISION TROJAN!
wmscheduler.exe Windows Scheduler
Added by a variant of the SDBOT WORM! See here
winsc.exe Windows Secure Connection
Added by the SDBOT.BTN WORM!
winupser.exe Windows Secure Update
Added by the RBOT-GCG WORM!
WinSecUp.exe Windows Secure Update
Added by the RBOT-GCD WORM!
wingrd.exe WINDOWS SECURITY
Added by a variant of the RBOT WORM!
win.pif Windows Security
Added by the RBOT-APT WORM!
winscure.exe Windows Security
Added by the RBOT-BAF WORM!
winsec.exe Windows Security Assistant
CoolWebSearch parasite variant
wscnfty.exe Windows Security Center Notification App
Added by a variant of the RBOT WORM!
winsecurity.exe Windows Security Manager
Added by the AGOBOT-KI WORM!
winsecure.exe Windows Security Manager
Affilred adware
windows.pif Windows Security Service
Added by the RBOT-AMG WORM!
WinServAd.exe Windows ServeAd
Windupdates adware variant
winserv.exe Windows Server
Detected by Trend Micro as the IRCBOT.AVM TROJAN! See here
wscvs.exe Windows Server Client Verification Service
Added by the AGENT.AWC TROJAN!
wsivs.exe Windows Server IP Verification Service
Added by an unidentified WORM or TROJAN! See here
wspvs.exe Windows Server Peer Verification Service
Added by a variant of the RANKY TROJAN!
winsvr.exe Windows Server!
Added by a variant of the IRCBOT TROJAN! See here
winsy.exe Windows Servic2
Added by the RBOT-AIA WORM!
wuamgrd.exe Windows service
Added by the RBOT-QW WORM!
WINSVC.EXE Windows Service
Added by the SPYBOT-DH TROJAN!
windowz.exe Windows Service
Added by the SDBOT-AYI WORM! Note - dissables the automatic startup of other software and deactivates the Microsoft Internet Connection Firewall (ICF)
win32wins.exe Windows Service Agent
Added by the RBOT-LOL WORM!
winup32.exe Windows Service Agent
Added by the RBOT-GQX WORM!
winupds32.exe Windows Service Agent
Added by the RBOT-GQT WORM!
wit.exe Windows Service Agent
Added by the RBOT-GQV WORM!
wmscc.exe Windows Service Agent
Added by the RBOT-GQP WORM!
Window.exe Windows Service Loader
Added by the RBOT-XO WORM!
websvc.exe Windows Service Manager
Added by the DLOADER-NY TROJAN!
WindowsSP2.exe Windows Service Pack 2
Added by the SDBOT-TQ WORM!
winworks.exe Windows Service Pack Auto Update
Adware downloader, identified by eScan antivirus as Trojan-Clicker.Agent.bt
WIN43.EXE Windows Service Pack2
Added by the GAOBOT.G WORM!
winsupply.exe Windows Service Supply
Detected by Kaspersky as the IRCBOT.BFB TROJAN! See here
winsrvc.exe Windows Service Utitity
Added by the RBOT-ASI WORM!
winsvc32.exe Windows Services
Added by the MYTOB-CB WORM!
w32edus.exe Windows Services
Added by a variant of the IRCBOT BACKDOOR! See here
w32service.exe Windows Services
Added by the AUTORUN-FU WORM!
w32services.exe Windows Services
Added by the AUTORUN-FT WORM!
winlogon.exe Windows Services
Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
winsysdll.exe Windows Services
Added by a variant of the IRCBOT BACKDOOR! See here
winsyssrv.exe Windows Services
Added by a variant of the IRCBOT BACKDOOR! See here
winudp.exe Windows Services
Added by a variant of the IRCBOT BACKDOOR!
wsiptis.exe Windows Services Ink Platform Tablet Input Subsystem
Added by the RBOT.APC WORM!
winlogz2.exe Windows Services Layer
Added by the RBOT-FZE WORM!
winl0g0.exe Windows Services Layer
Added by the RBOT-FZQ WORM!
win70.exe Windows shell
??
WinSock32.exe Windows Socket Procedure
Added by the RBOT-FMX WORM!
WinIp32.exe Windows Sound Verifier
Added by the RBOT-FMO WORM!
wfirewall7.exe Windows SP2 Firewall
Added by a variant of the RBOT WORM!
wuauclt32.exe Windows SP2 Version Load
Added by the GAOBOT.CX WORM!
winspool.exe Windows Spool
Added by a variant of the IRCBOT TROJAN!
winsplr.exe Windows Spooler
Detected by Trend Micro as the SHEUR.ANX TROJAN! See here
winsv.exe Windows Spools SV
Added by the RBOT-AUQ WORM!
Windows-spyware.exe Windows spyware remover
Added by the SystemPoser TROJAN!
winmsn32.exe Windows sq Drivers
Added by the RBOT-ADI WORM!
winsql32.exe Windows Sql Service For Windows 32 Bit
Added by the FORBOT-FC WORM!
winssh.exe Windows SSH Client
Added by the RBOT-AXC WORM!
winssv.exe Windows SSL File
Added by the WOOTBOT.CA WORM!
winsta~1.exe Windows Startup
GoHip foistware
winstartup.exe Windows Startup
GoHip foistware
Wdrun32.exe Windows Startup
Added by the GAOBOT.AO WORM!
winload.exe Windows Subsys
Added by the NETSPREE.C WORM!
winsvc.exe WINDOWS SVC
Added by the MYTOB-EY WORM!
winmnon32.exe Windows SYN Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
wdns33.exe WINDOWS SYSTEM
Added by the MYTOB-BY WORM!
win.exe.exe WINDOWS SYSTEM
Added by the MYTOB.FA WORM!
winaup.exe WINDOWS SYSTEM
Added by the MYTOB-DN WORM!
winligon.exe WINDOWS SYSTEM
Added by the MYTOB.EP WORM!
winmon.exe WINDOWS SYSTEM
Added by the MYTOB.GB WORM!
winNTsys32.exe WINDOWS SYSTEM
Added by the MYTOB-DM WORM!
winsvc32.exe WINDOWS SYSTEM
Added by the MYTOB.HH WORM!
WINSYS.exe Windows System
Added by the RBOT-AEF WORM!
winsys33.exe WINDOWS SYSTEM
Added by the MYTOB.EK WORM!
winvnc.exe WINDOWS SYSTEM
Added by the MYTOB.EU WORM!
winxpserv.exe WINDOWS SYSTEM
Added by the MYTOB-BQ WORM!
winsys32.exe Windows System
Added by the MYTOB-IS WORM!
Win32IMAPSVR.exe WINDOWS SYSTEM
Added by the MYTOB-FQ or MYTOB-FU WORMS!
winsvc.exe WINDOWS SYSTEM
Added by the MYTOB.LM WORM!
winsys_32.exe Windows System 32
Added by the RBOT-FTR WORM!
win32bat.exe Windows System 32-Bat Service
Added by the MYTOB.FI WORM!
windasz-updote.exe WINDOWS SYSTEM By FEnR
Added by the MYTOB.LR WORM!
WinNeth.exe Windows System Configuration
Added by the RETHE-A WORM!
Winfrw.exe Windows System Configuration
Added by the SOLUFINA TROJAN or the DOMWIS-J WORM!
wincfg.exe Windows System Configuration
Added by the AGOBOT.OP WORM!
WINCFG32.EXE Windows System Configuration
Added by the AGOBOT-TE WORM!
windsns.exe WINDOWS SYSTEM Dns
Added by the MYTOB.EY WORM!
winload.exe WINDOWS SYSTEM FILE
Added by the MYTOB.DK WORM!
winit32.exe Windows System Init
Added by a variant of the RBOT WORM!
winsystem.exe Windows System Manager
Added by the RBOT-AN WORM!
winsysmgr.exe Windows System Manager
Detected by Trend Micro as the IRCBOT.BJG TROJAN! See here
winsmc.exe Windows System Manager Proc
Added by the RBOT.JH WORM!
wnpsm.exe windows system notepad
Added by a variant of the RBOT WORM!
winmp.exe Windows System Security
Added by the RBOT.IV WORM!
winserv.exe Windows System Serivce
Added by the RBOT.ACA WORM!
winsock.exe windows system service
Added by the RBOT-MR WORM!
wnuserv.exe Windows System Service
Added by the SPYBOT.ANDM WORM!
windowsp.exe Windows System32
Added by the MYTOB.GD WORM!
winsys32.exe Windows System32
Added by the SDBOT-AHS WORM!
wingrd32.exe Windows System32
Added by a variant of the RBOT WORM!
winjews16.exe Windows Systems16
Added by a variant of the SDBOT WORM!
winshvc.exe Windows Sz Host
Added by a variant of the SDBOT WORM!
Wintaskad.exe Windows TaskAd
Windupdates adware variant
winpifviewer.exe Windows Taskmanager
Added by a variant of the IRCBOT TROJAN! See here
wdtsvc.exe Windows Taskmanager
Added by a variant of the IRCBOT BACKDOOR! See here
winpifviewer.exe Windows Taskmanager
Added by a variant of the IRCBOT BACKDOOR! See here
winrl.exe Windows Taskmanager
Added by a variant of the IRCBOT BACKDOOR! See here
wintcp.exe Windows TCP/IP
Added by the AGOBOT-ZH WORM!
wintel.exe Windows Telnet Server
Added by the AGOBOT-MW WORM!
wintmp.exe Windows Temperate Services
Detected by Trend Micro as the SLENFBOT.AT WORM! See here
winmgr.exe Windows Time
Added by the RBOT-XC WORM!
winscrvs.exe Windows Time Service Diagnostic Tool
Detected by Trend Micro as the RBOT.FTV BACKDOOR! See here
windowssys32.exe Windows TM
Added by a variant of the RBOT WORM!
WinxSys.exe Windows TM
Added by a variant of the RBOT WORM!
winudspm.exe Windows UDP Control
Added by a variant of the SDBOT WORM! See here
winlive32.exe Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
winmsn.exe Windows UDP Control Center
Detected by Kaspersky as the SDBOT.EBA BACKDOOR! See here
winrofl32.exe Windows UDP Control Center
Added by the LDPINCH-RZ TROJAN!
winudpmg.exe Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
winudpmgr.exe Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
winudpmgrs.exe Windows UDP Control Center
Detected by Trend Micro as the DROPPER.CMV TROJAN! See here
winudpmsgr.exe Windows UDP Control Center
Detected by Trend Micro as the SDBOT.GAV WORM! See here
winupmgr.exe Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
winuscn32.exe Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
wksvcsc.exe Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
winudpmgr.exe Windows UDP Control Manager
Added by a variant of the SPYBOT WORM! See here
wksvcsc.exe Windows UDP Control Services
Added by the ANTIAV-C TROJAN!
wudate.exe Windows Update
Added by the AGOBOT.ML WORM!
wupdate.exe Windows Update
Wengs adware
Wuamgrd.exe Windows Update
Added by a variant of the SPYBOT WORM!
WindowsUpdate.exe Windows Update
Added by the BAYROB-A TROJAN!
wuraclt.exe windows update
Added by the RBOT-PO WORM!
Wuanclt.exe windows update
Added by the RBOT.XZ WORM!
windows.exe Windows Update
Added by the RBOT-RB WORM!
wuaurlt.exe windows update
Added by the RBOT.ADG WORM!
winmguard.exe Windows Update
Added by the RBOT-EM WORM!
wuampd.exe Windows Update
Added by the RBOT.UM WORM!
wuarclt.exe windows update
Added by the RBOT-OF WORM!
winupdate.exe Windows Update
Added by the SDBOT-WS WORM!
wininfo.exe Windows Update
Added by the MYTOB.GA WORM!
winlogin.exe Windows Update
Added by the BANKER-DV TROJAN!
windowsx.exe Windows Update
Added by the BANCD-A TROJAN!
wudupdate.exe Windows update
Adware downloader - Istbar related
wupdmgr.exe Windows Update
Added by the BANCBAN-FC TROJAN and variants!
Winload.exe Windows Update
Added by the DEDMIR-A WORM!
win32update.exe Windows Update
Detected by PCTools as the SDBOT.FTK WORM! See here
winsc.exe Windows Update
Detected by Kaspersky as the BUZUS.RYI TROJAN! See here
winlogons.exe Windows Update 32
Added by the FORBOT-FI WORM!
WinV.exe Windows Update 64
Added by the FORBOT-FP WORM!
wuaumgr.exe Windows Update Auto Update
Added by a variant of the SPYBOT WORM!
winuptdate.exe Windows Update Automation
Added by a variant of the RBOT WORM!
waucult.exe Windows Update AutoUpdate Client
Added by a variant of the RBOT WORM!
wuauclt.exe Windows Update AutoUpdate Client
Added by the LAZAR.B TROJAN! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup!
wuauct.exe Windows Update AutoUpdate Client Product
Added by the AGOBOT.ACL WORM!
W32RSA.exe Windows Update Center
Added by an unidentified WORM or TROJAN!
wuclient.exe Windows Update Client
Added by the SMALL-RN TROJAN!
windrvl32.exe Windows Update Client Service
Added by the AGOBOT-MM TROJAN!
winmsfw.exe Windows Update Firewall System
Added by the RBOT-EEO WORM!
wupdategux32.exe Windows Update GUI Executable x32x
Added by the RBOT.CXY WORM!
winupsvc.exe Windows Update Host
Added by a variant of the SDBOT WORM!
WIN32IPV6.EXE Windows Update IPv6 Layer
Added by the RBOT.DUD WORM!
wupdmngr.exe Windows Update Manager
Added by the RANDEX.BTB WORM!
Winlog0n.exe Windows Update Manager
Added by the AGENT-BO TROJAN!
wupdate.exe Windows Update Manager
Added by a variant of the RBOT WORM!
WindowsUpdateManager.exe Windows Update Manager
Added by a variant of the IRCBOT TROJAN!
wupdmgr32.exe Windows Update Manager for NT
Added by the SDBOT.AH WORM!
winupdt.exe Windows Update Monitoring Service
Added by the RBOT-PL WORM!
wmiprvsc.exe Windows Update Process
Added by the SDBOT-CB WORM!
wmiprvse32.exe Windows Update Service
Added by the AGOBOT.NI WORM!
wins32svcs.exe Windows Update services
Added by a variant of the RBOT WORM!
winupdate32.exe Windows Update Services
Added by a variant of the RBOT WORM!
wupdmgr32.exe Windows Updater
Added by a variant of the DOS.AUTOCAT TROJAN!
wupdate.exe Windows Updater
Added by the WOOTBOT.AJ WORM!
winupdatexx.exe Windows Updater Online
Added by a variant of the RBOT WORM!
winupdatr.exe Windows Updater Service Manager
Added by a variant of the IRCBOT BACKDOOR!
winupd32.exe Windows Updates
Added by the MYTOB.CE WORM!
w32dns.exe Windows Updates
Added by the SDBOT-BFW WORM!
winupdate.exe Windows Updates Agent
Detected by Trend Micro as the SPYBOT.HW WORM! See here
W1NT45K.exe Windows Updtee Mgnr
Added by the MYTOB.DC WORM!
winusb.exe Windows USB controler
Added by the RBOT-HR WORM!
Windowsusb.exe Windows USB Driver Support
Added by a variant of the SPYBOT WORM!
wsvc.exe Windows USB v3
Added by a variant of the SDBOT WORM!
wdfmrg.exe Windows User Mode Driver Manager
Added by the SDBOT-ZN WORM!
winuser32.exe Windows User Starter
Added by the RBOT.SN WORM!
wvsvc.exe Windows Video Acquisition (WVA)
Added by the AGOBOT.YM WORM!
wvcsvc.exe Windows Video Component
Added by a variant of the IRCBOT TROJAN!
winvirtual.exe Windows Virtual Services
Detected by Trend Micro as the SLENFBOT.V WORM! See here
winvirtual32.exe Windows Virtual Services
Detected by Trend Micro as the SLENFBOT.U WORM! See here
winvsvc.exe Windows Virus Scanner
Added by a variant of the IRCBOT TROJAN! See here
winxp_sp3.exe Windows Vista Corparation Agent Services
Added by a variant of the IRCBOT TROJAN!
websvc.exe Windows Web Services
Added by the DLOADER-NY TROJAN!
winhlp32.pif Windows Winhlp32 Stub Service
Added by the AIMBOT.AH TROJAN!
wsass.exe Windows WKS
Added by the SDBOT-DK WORM!
wkssvr1.exe Windows WKS Services
Added by a variant of the IRCBOT BACKDOOR! See here
winfix.exe Windows WMF Fix
Added by the RBOT-FTQ WORM!
wkssvc.exe Windows Workstation Service
Added by the IRCBOT-AAI WORM!
wkssvc32.exe Windows Workstation Service (32-bits)
Added by a variant of the SDBOT WORM!
Wins.exe Windows xp
Detected by Trend Micro as the RBOT.VH TROJAN! See here
wXPupdate.exe Windows XP Automatic Update
Added by the RBOT-AFC WORM!
Windows XP SP2 KeyGen.exe Windows XP SP2 KeyGen
Added by the TIBICK-C WORM!
windows16.exe windows16
Added by the XU TROJAN!
windows32.exe windows32
Added by the XU TROJAN!
wuuaclt.exe Windows32
Added by the BRATLE.B WORM!
winser32.exe Windows32 Serivces
Added by the SPYBOT.AAF WORM!
WindowsAgent.exe WindowsAgent
Added by the GOP.G WORM!
WINDOWSBACKUP.EXE WindowsBackup
Added by the STANG WORM!
wscrc.exe WindowsCRC
Added by the SDBOT-VU WORM!
windows_critical_update.exe WindowsCriticalUpdate
Added by the ASTEF or RESPAN WORMS!
winsfs32.exe WindowsFileSystem
Added by the RBOT-FMQ WORM!
winsvcup.exe WindowsFirewallSvc
Added by a variant of the SDBOT WORM!
wp.exe WindowsFY
Part of a "Security IGuard" parasite infestation - also detected as DESKTOPHIJACK
winipsvc.exe WindowsIPRelay
Added by the IRCBOT-AAA WORM!
Winmgm32.exe WindowsMGM
Added by the SOBIG.A WORM and LALA.C TROJAN!
winupdate.exe WindowsRegKey update
Added by the RBOT-QJ WORM!
windns.exe WindowsRegKey update
Added by the RBOT.IE WORM!
winupdatexx.exe WindowsRegKey update
Added by the RBOT.LW WORM!
wdnupdate.exe WindowsRegKey update
Added by the SDBOT.QX WORM!
Windowsup.exe WindowsRegKey update
Added by the SDBOT.PU WORM!
WINUPDATES.EXE WindowsRegKey update
Added by the RBOT-MM WORM!
winsys.exe WindowsRegKey update
Added by the RBOT-JY WORM!
winupdat32.exe WindowsRegKey update
Added by the RBOT-AGW WORM!
windexv1.exe WindowsRegKey update XP
Added by the RBOT-ABM WORM!
winsysi.exe WindowsRegKeys update
Added by the SDBOT.WE WORM!
windowstime.exe windowstime.exe
Added by the AQV TROJAN!
WindowsUpd4.exe WindowsUpd
VirtuMonde adware
WindowsUpd1.exe WindowsUpd1
VirtuMonde adware
WindowsUpd2.exe WindowsUpd2
VirtuMonde adware
windows_update.exe WindowsUpdate
Added by the LOFNI WORM!
winupdate.exe windowsupdate
Added by the WARPI WORM!
winnnint.exe WindowsUpdate
Added by an unidentified WORM or TROJAN!
Windowsupdate .exe Windowsupdate
Detected by Kaspersky as the BANKER.ARK TROJAN! See here
wupdmgr98.exe Windowsupdate
Added by a variant of the IRCBOT BACKDOOR!
wuautlc.exe WindowsUpdate Service
Added by the RBOT-NR WORM!
wupdmng.exe WindowsUpdateManager
Detected by Trend Micro as the AGENT.VUX TROJAN! See here
windowsxpupdate.exe WindowsXP Update
Added by the RBOT-PB WORM!
windowsxxx.exe windowsxxx
Added by the DUBING-A TROJAN!
windowsxxx2.exe windowsxxx2
Added by the DUBING-A TROJAN!
winsystem.exe Windows_Protect
Added by a variant of the RBOT WORM!
winregal.exe Windows_Protect
Added by a variant of the RBOT WORM!
wincontrol32.exe Windows_Protect
Added by the RBOT-ADK WORM!
W32RfSA.exe Windoxs Update Center
Added by a variant of the SDBOT WORM!
windrg32.exe WinDrg32
Added by the DRUDGEBOT.A WORM!
WinDriv32.exe WinDriv32
Added by the SMALL-BA TROJAN!
windrvconf.exe WinDriver Configuration
Added by the AGOBOT-LX TROJAN!
WinDrives.EXE WinDrives
Added by the SMALL.DIG WORM!
windrv32.exe windrv
Added by an unidentified VIRUS, WORM or TROJAN! - possibly a strain of OBLIVION or BIONET
windrvx.exe WinDrv
Added by a variant of the TIBSER.A downloader TROJAN!
WinDSL_MTU.exe WinDSL MTU-Adjust
Adjusts the registry setting of the DUN-Adapters (MTU) and the TCP/IP-Protocol (RWIN) by ENGEL Technologieberatung
WinDSL_MTU.exe WinDSL_MTU
May be realted to Tiscali broadband, if so is it required?
Win????.exe WinDSNX
Added by the DSNX TROJAN!
WinUpdt.exe WindUpdates
Windupdates adware variant
WinDVRCtrl.exe WinDVRCtrl
Control center software for an AOpen VA1000 TV tuner card
winenv.exe winenv
Added by a variant of the SDBOT WORM!
Winexec.exe.vbs WinExec
Added by the AINESEY.A WORM!
WinExec.exe WinExec
Added by the FALUS-A WORM!
WinExec32.exe WinExec32
Added by the KAZWIN WORM!
Wfwiz.exe WinFast Schedule
Leadtek WinFast TV tuner scheduler and remote control driver - required if you use the latter
WF2k.exe Winfast_2K
System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card
WinFavorites.exe1 WinFavorites
Loudmarketing.com adware downloader
WFXCTL32.EXE WinFax PRO Controller
From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
wfxsnt40.exe WinFaxAppPortStarter
WinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application.
WF.exe WinFire
Added by the DELF-SY TROJAN!
wfx5.exe WinFixer 2005
WinFixer web installer. Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
wfxcwr.exe WinFixer helper
WinAntiSpyware 2005 by Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
WinFlyer32.dll WinFlyer32.dll
Added by the WINFLYER TROJAN!
winfont.exe winfont
Added by the DEATH TROJAN!
winform.exe winform
Added by the PWS-ALB TROJAN!
WF2k.exe WinFoxV2
System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card
wgengmon.exe WinGate Engine Monitor
WinGate Internet Client Dialup Monitor - component of WinGate proxy server software. Displays the status of the WinGate engine, and appears in the system tray of each workstation on the network reassuring clients that their workstations have connectivity with the WinGate Server
WinGate.exe WinGate initialize
Added by the LOVGATE.F WORM!
wingerver2.0.exe wingerver2.0.exe
Added by the GRAYBRD-AE TROJAN!
wingo.exe wingo
Added by the BEAGLE.AW or BEAGLE.AV WORMS!
WGPRO32.EXE WinGuage Pro
Part of McAfee Nuts & Bolts. "WinGauge is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious". Resource hog. Available via Start -> Programs
WGFE95.EXE Winguard
Dr Solomon's Virex antivirus
wingrd32.exe winguard
Added by a variant of the RBOT WORM!
wgp.exe WinGuard Pro
Winguard Pro
winhe1p.exe Winhelp
Added by the QQPASS.E TROJAN!
WinHelp.exe WinHelp
Added by the LOVGATE.F WORM! Note - this file is located in %System% whereas the valid one is located in %Windir%
winhlp.exe winhlp.exe
Added by the FORMGLIEDER TROJAN!
winhlp3.exe winhlp3.exe
Added by a variant of the EASTO.A TROJAN!
Wscript.exe ..Msexec32.vbs Winhlp32
Added by the GANT.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "Msexec32.vbs" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
winhlp32.exe winhlp32.exe
Added by the EASTO.A TROJAN!
winhlpp32.exe winhlpp32.exe
Added by the GAOBOT.SY WORM!
wintt.exe Winhost
Added by the LOLAWEB.B TROJAN!
win.exe Winhost
Added by the DLOADER-AP TROJAN!
winhost.exe Winhost
Added by the REATLE.F WORM!
winhost.exe winhost.exe
Added by the LOHAV-R TROJAN!
winhost32.exe winhost32.exe
Added by the TABDIM TROJAN!
WinHound.exe WinHound
WinHound spyware remover - not recommended, see here
winierun.exe WinIeRun
Added by the RNWATCH-A WORM!
WinIFixer.exe WinIFixer
WinIFixer spyware remover - not recommended, see here
wvsvc.exe winimage
Added by the RBOT.TX WORM!
wininet.exe wininet
Added by the STUBBOT-C WORM!
wininet32.exe wininet32
Added by the RAZNEW-A TROJAN!
wininetd.exe wininetd
Added by the WINET TROJAN!
winini.vbs Winini.dll
Added by the STARTP-M TROJAN!
wininit.exe wininit
Added by the WOLLF.16 TROJAN!
Win86.exe WinInit
Added by the SMALL-PB TROJAN!
winint.exe winint
Added by the SDBOT-ADA WORM!
winipsec.exe winipsec
Unidentified malware
WinIRXHelper.exe WinIRXHelper
MSI Media Center Deluxe software - see here
winis.exe winis
Added by the RBOT-WI WORM!
Wink*.exe [* = random char] Wink*.exe
Added by a variant of the KLEZ WORM!
winkb6.exe Winkb6
Part of We-Blocker - gives parents the opportunity to monitor their children's Internet access and provide them with age-appropriate content, while filtering out sites that contain adult content. Works in conjunction with Winkb6 and both files are needed to run We-Blocker
WinKer.exe WinKernel
Added by the MIRAB or SERVIDOR TROJANS!
wWin32.com winkernel32
Added by the BANSAP TROJAN!
winkey.exe WinKey
Loads Copernic's WinKey. Used to map out Windows key hotkey combinations. Not required for the system, but is necessary for this to be running if you use these hotkey combos
winla.exe winla
Added by the DLOADR-AQL TROJAN!
winsplg.exe winlgn
Related to the Sentry Parental Controls software
winlgz2.exe winlgz2
Added by the KILLFIL-Q TROJAN!
winlibs.exe winlibs.exe
Added by the EVAMAN.C WORM!
winlink32.exe Winlink
Added by the GAOBOT.AAY WORM!
windll.exe Winlme
Added by the GOP.F WORM!
Winload.exe WinLoad
PCTattletale is a surveillance software program that monitors user activity, logs keystrokes, and takes screenshots. Uninstall this software unless you put it there yourself
winlog.exe winlog
Added by the GAOBOT_DF WORM!
winlog.exe winlog manager
Added by the DONBOMB.A TROJAN!
WINLOG0N.EXE WINLOG0N
Added by the MYDOOM.BI WORM!
winlogin.exe WinLogin
Added by the AGOBOT-IX WORM!
win32x.exe winlogin
Browser hijacker, also detetected as the STARTPA-DF TROJAN!
winlogoff.exe winlogoff
Added by the AGOBOT-TR WORM!
winlogon.exe winlogon
Hijacker or adult content dialler! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
winlogin.exe winlogon
Added by the RANDEX.E WORM!
winlogon.exe winlogon
Added by the TRODAL TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
winlogon32.exe winlogon
Added by the MASLAN.C WORM!
wpwlogon.exe winlogon
Added by an unidentified WORM or TROJAN!
wscript.exe WINLOGON.vbs WINLOGON
Added by the YSPAN.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "WinStart.vbs" file is found in %System%
WINLOGON.EXE Winlogon
Added by the PUNYA-B WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
winlogin.exe Winlogun
Added by the P2LOAD-C WORM!
winln.exe winltmpv
Added by the TCXMEDI-C TROJAN!
wutop.exe winltmpv
Added by the TCXMEDI-C TROJAN!
winmain.exe Winmain
One of the first of a new breed of malware. When run it immediately loads MSHTA.EXE from the Windows folder, placing it on "hot standby", ready to accept HTA scripting within a web page and then EXECUTE what is embedded IN the page as a program! In other words, it's possible for a "rogue" website to actually embed trojans, worms and/or viruses directly into a web page. NSClean's HTA Stop offers an easy way to toggle this capabiltity, or rather vulnerability, on and off. I suggest you leave it disabled!
wmanage.exe WinManage
Added by a variant of the IRCBOT BACKDOOR! See here
WinMatrixXP.exe winmatrix.exe
WinMatrix XP - wallpaper replacement that shows different matrix effects (including flowing matrix codes from 'The Matrix' movie) on your desktop
winmed.exe WinMed
Detected by Trend Micro as the AGENT.AIRF TROJAN! See here
winmedia32.exe WinMedia32
Added by the YABE.F TROJAN!
WinMem.exe WinMem
WinMem Cleaner - part of Ultra WinCleaner Utility Suite. Makes more memory available for your programs and the Operating System. It also defragments your system
winmax.exe WinMenssage
Added by the BANCOS.B TROJAN!
WinMgmt.exe WinMgmt
Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here
winmgmt32.exe winmgmt32.exe
Added by the LUZIA.AD TROJAN!
winmgr32.exe WinMgr32
Added by the MIMAIL.P WORM!
wmexe.exe winmodem
Software for software based modems. Required if you have one of these. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information
winmon32.exe Winmon32
Added by the RBOT-OQ WORM!
WinMoviePlugIn.exe WinMoviePlugIn
Sfonditalia adult content premium rate dialer
winwork.exe Winmsg
Added by the GAOBOT.GEN!POLY WORM!
winmsgr.exe WinMsg
Added by the DLOADR-AS TROJAN!
WinMsrv32.exe WinMsrv32
Added by the GAOBOT.AFJ WORM!
WinMX.exe WinMX
WinMX file sharing application
winmysqladmin.exe winmysqladmin
Starts the MySQL database admin tool
winmysqladmin.exe WinMySQLadmin Tool
Starts the MySQL database admin tool
winnet.exe winnet
CommonName Toolbar spyware. To uninstall see here
winnload.COM winnload
Added by the DOWNLD-ABG TROJAN!
WnvMenu.Exe Winnov Menu
Winnov Video Capture Card related. What does it do and is it required?
WnvRsvr.Exe Winnov Remote
Winnov Video Capture Card related. What does it do and is it required?
WvStatus.Exe Winnov Status
Winnov Video Capture Card related. What does it do and is it required?
winnt.exe winnt
Added by the MONA-E WORM!
WinNT.com WinNT
Added by the AUTOSKY WORM!
wuamgrd32.exe winnt DNS ident
Added by the RBOT-BAU WORM!
windowxp.exe winnt DNS ident
Added by a variant of the RBOT WORM!
Winupd32.exe winnt DNS ident
Added by the RBOT.AVU WORM!
winupdate32.exe winnt DNS ident
Added by a variant of the RBOT WORM!
wuamgrd33.exe winnt DNS ident
Added by a variant of the RBOT WORM!
windowsp.exe Winnt DNS ident
Added by the RBOT.BAL WORM!
wupgrd.exe winNT updatc
Added by a variant of the RBOT WORM!
WinntBB.exe WinNtBB
Added by the DULOAD.C WORM!
win32nls.exe Winnup
Added by a variant of the SPYBOT WORM!
winocx32.exe winocx32
Added by the PROTORIDE.I WORM!
winnt.exe WINOWS SYSTEM
Added by the MYTOB.ID WORM!
winmic.exe WINP
Added by the SPYBOT-EB WORM!
winpack.exe Winpack
Adware - detected by Kaspersky as the AGENT.GG TROJAN!
winpatch.exe WinPatch Protection
Added by an unidentified WORM or TROJAN!
WinPatrol.exe WinPatrol
WinPatrol - "Manage Startup programs, tasks, cookies; will sniff out Worms, Trojan horses, Cookies, Adware, Spyware, Klez, Assumption and other malicious programs"
WinPatrolEx.exe WinPatrol Explorer
Part of WinPatrol
winpipe.exe winpipe
Browser hijacker redirecting to wow-access.com
WinPlosion.exe WinPLOSION
"WinPLOSION allows you to immediately view and select from all the windows running on your computer, just those of the active application, or to minimise all windows and display a clear desktop"
WinPPPoverEthernet.exe WinPoet
WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking
winpol.exe winpol
Added by the AGENT.IWD TROJAN!
Winpooch.exe Winpooch
"Winpooch is a Windows watchdog, free and open source. Anti spyware and anti trojan, it gives a full protection against local or external attacks by scanning the activity of programs in real time. Associated with ClamWin antivirus, Winpooch keeps safe your computer against virus"
winpop.exe WinPop
Brudevic A adware
WINPOPUP.EXE WinPopup
Intranet chat software provided by windows for chat on small networks. Handy little LAN messaging utility. Has been included in Windows since 95, and maybe in WFWG 3.11. Normally it won't set itself up to run unless the user specifically adds it to startup
winupie.exe winpopup
Adware by Tradeexit.com
Winpower.exe Winpower
Part of InstallAnywhere from Zero G Software, now owned by Macrovision
winprocer32.exe Winprocer32 Update
Added by the RBOT.GW WORM!
winprocessor.exe winprocessor Update
Added by the RBOT.IO WORM!
Winprot.exe WinProt
Added by the CHUPACABRA TROJAN!
win32.exe winprotect
Added by the MUGLY.E WORM!
winprotect.exe winprotect
Added by the SDBOT-SB WORM!
WinProxy.EXE WinProxy
"WinProxy is the world-first proxy server and a firewall with integrated mail server for Windows 95/98/ME/NT/2000/XP"
WINPROXY.EXE Winproxy Personal
Added by the SDBOT.BMF WORM!
winpsd.exe winpsd
Added by the MYDOOM.Q WORM!
wpwdmgr.exe WinPWD Manager
Added by the RBOT-AUT WORM!
winrapid.exe winrapid
Added by a variant of the RBOT WORM!
winrar.exe winrar
CoolWebSearch Therealsearch parasite variant. Note - this is not the file zipping utility also known as WinRAR!
WinrarCO.com WinRaR Service
Added by an unidentified WORM/TROJAN!
winrarshell32.exe winrarshell
Added by the SALIRA TROJAN!
WinReanimator.exe WinReanimator
WinReanimator spyware remover - not recommended, see here
winReg.exe winReg
Added by the YAHA.H or YAHA.J WORMS!
winregsrv.exe winregsrv
Added by the SYNRG TROJAN!
WinRemote.exe WINREMOTE
InterVideo WinCinema Manager - needed for the use of WinDVD Remote Control
winrestore.exe winrestore1
Added by the KILLFIL-Q TROJAN!
winreups.exe winreups
Added by a variant of the RBOT WORM!
winsn.exe winroot
Added by the QQPASS.IA WORM!
winroute.exe winroute
Win-Route 4.27. WinRoute Tray Icon for starting and stopping the WrCtrl.exe process, also to log in to the console to view logs and change settings. Can be unchecked and the engine still runs and functions normally. Can then use provided shortcuts for administration of the program. Loaded in SERVICES on Windows 2k
winrpcmx.exe WinRPC
Added by the BANKER-EEI TROJAN!
W1NT45K.exe WINRUN z
Added by the MYTOB.BL WORM!
WinDrivers.exe WinRunners
Added by the DULOAD.C WORM!
winet.exe Wins Service Driver
Added by the RBOT-APV WORM!
winsmc.exe WinScMngr
Added by the SDBOT-BPZ WORM!
winsec16.exe WinSec
Added by the AGOBOT.ZF WORM!
winsecure.exe winsecure
Browser hijacker, redirecting to specificsearches.com
Winserv.ila Winserv
Added by the NODMIN WORM!
winmain.exe Winservice
Adult content related malware
WinServ.exe WinService
Added by the SKOWOR-O WORM!
WinServices.exe WinServices
Added by the YAHA.K or YAHA.M WORMS!
winservn.exe winservn
PurityScan/Clickspring adware
winservs.exe winservs
PurityScan/Clickspring adware
winsfc.exe winsfc
Added by the WISFC VIRUS!
wuadfdqr.exe Winshoe
Probably an unidentified VIRUS! Adds itself to 3 registry "Run" keys and prevents Task Manager being displayed. This is not the Winshoe IRC Client as the visitor did not have it installed
winshost.exe winshost.exe
Added by the TOOSO WORM and variants!
winskype.exe winskype
Added by the BROGGER-C TROJAN!
winnt update.exe Winsock driver
Added by the SPYBOT-DM TROJAN!
winnt64.exe Winsock driver
Added by the SPYBOT-DR WORM!
win.exe Winsock driver
Added by a variant of the IRCBOT BACKDOOR! See here
winsock.exe winsock.client
Added by the DIABLO-M TROJAN!
WINCFG.SCR Winsock2 driver
Added by a variant of the SPYBOT WORM!
winupdate.exe Winsock2 driver
Added by the SPYBOT-BX WORM!
WUAUMQR.EXE Winsock2 driver
Added by the SPYBOT-DP WORM!
wincfg.exe Winsock2 driver
Added by the SPYBOT.CO WORM!
WUAUMQR1.EXE Winsock2 wqr1s
Added by the SPYBOT.KD WORM!
WINLODR.SCR Winsock2.dll
Added by an unidentified VIRUS, WORM or TROJAN!
win32server.scr Winsock32driver
Added by the HACARMY TROJAN!
win32server.exe Winsock32driver
Added by the BACKDOOR-AZV TROJAN!
win32server.exe Winsock32driver
Added by the HACARMY.F TROJAN!
winXPupdate.exe Winsock32driver
Added by the HACKARMY.9728 TROJAN!
winsock2.2.exe winsockdriver
Added by a variant of the SPYBOT WORM!
winsock3.exe winsockdriver
Added by the SPYBOT-DO WORM!
winsock4.1.exe winsockdriver
Added by a variant of the IRCBOT TROJAN! See here
WINSOS.EXE WINSOS VERIFY
WinSOS - "deletes spyware, optimizes your computer - backs up selected data"
winspd32.exe winspd32dll
Added by a variant of the AGOBOT/GAOBOT WORM!
windrv32.exe WinSPF
Added by the MYDOOM.T WORM!
winspf32.exe WinSPF
Added by the MYDOOM.S WORM!
winsplx.exe Winspl
Added by a variant of the TROLL-A TROJAN!
wsmmlog.exe winsplog
Added by the MAILBOT-CA TROJAN!
WinSpywareProtect.exe WinSpywareProtect
WinSpywareProtect rogue spyware remover - not recommended, see here
WinSpywareProtect.exe WinSpywareProtect (ver. 5.1)
WinSpywareProtect rogue spyware remover - not recommended, see here
winsrv.exe Winsrv
Added by the OPASERV.T WORM!
winsrv.exe winsrv
Added by the NETSNAK-B TROJAN!
WinStabilizer.exe WinStabilizer
Added by the AGOBOT-SW WORM!
WinStart.exe WinStart
From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge
Wscript.exe WinStart.vbs WinStart
Added by the CIAN.C WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "WinStart.vbs" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
winstart32.exe WinStart
Added by the PUROL WORM!
WinStart.pif WinStart
Added by the CONE.E WORM!
winstart.exe winstart
Added by the SCKEYLO-AB TROJAN!
WinStart001.exe WinStart001
From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge
WinStart001.exe WinStart001.EXE
From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge
winstats.exe winstats
Added by the GARGAFX TROJAN!
winsta~1.exe Winsta~1
GoHip foistware
WinSth16.exe WinSth16
Added by the CAKE WORM!
winsys64mnger.exe winsupdatesysmngr64
Added by the RBOT-BAG WORM!
WinSvc16.exe WinSvc16.exe
Added by the SDBOT.FQ TROJAN!
Winsvc32.exe Winsvc32
Homepage hijacker
winsvc32.exe winsvc32.exe
Added by the GREPAGE TROJAN!
winsy32.exe winsy32.exe
CoolWebSearch parasite variant
Winsys.exe Winsys
Win-Spy keyboard logger/monitoring software - remove unless you installed it yourself
Winsys32.exe WinSys32
Added by the CIGIVIP TROJAN or RECKUS WORM!
winsys32.exe winsys32 Driver
Added by the LOONY-O TROJAN!
WinSysRM.exe WinSysAppMon
Home & Family Content Filter related. See here
winsyslog.exe winsyslog lptt01
RapidBlaster variant (in a "Winsyslog" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
winsyst32.exe WinSyst32
Added by the MORB WORM!
winsystem.exe WinSystem
Added by the WHITEBAIT WORM!
WinSystems.exe WinSystem
CMKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!
winsystems16.exe WinSystems
Added by the SDBOT-CZT WORM!
winsystems.exe winsystems25
Added by the RBOT-CNZ WORM!
wcp****.exe [* = random char] WINT
PurityScan/Clickspring adware
wcpcc.exe WINT
PurityScan/Clickspring adware
wcpsvit.exe WINT
PurityScan/Clickspring adware
Wintask.exe WinTask
Added by the HIPO or LEMIR.F TROJANS!
wintask.exe WinTask driver
Added by the DLOADER-NA TROJAN!
winxpro.exe WINTASKS
Added by the MYTOB.EZ WORM!
winkll.exe WinTasks DLL Library (32-bits)
Added by the RBOT-AJZ WORM!
wintasks.exe WinTasks Traybar
WinTasks - "Efficient Resource and Task Management is absolutely critical if you want to achieve the highest system performance levels possible. WinTasks 4 will not only help you achieve this task, but will actually make your system run faster and more smoothly than ever before"
wintasks.exe wintasks.exe
Added by the EVAMAN WORM!
wintbp.exe Wintbp.exe
Added by the ZOTOB.E WORM!
wintbpx.exe Wintbpx.exe
Added by the ZOTOB.F WORM!
wintective.exe wintective
Wintective logs keystrokes, captures screenshots, and monitors Internet activity. The gathered information can be sent to a predetermined email address. If you didn't install this yourself remove it
WINCOOL.EXE Wintercooler Pro
Wintercooler Pro - utility that monitors CPU usage, RAM consumption and Internet connection speed
winthelp.exe winthelp
AdvancedCleaner misleading security software - not recommended, see here
WinTidy.exe WinTidy
Desktop icon manager from PC Magazine (Ziff-Davis). Available via Start -> Programs
Wintime.exe Wintime
Added by the HARNIG TROJAN!
wintime.exe WinTime
WinTime - change desktop icons' color and font
Wxpload.exe Wintime Wintime Wtxpload
Part of the software to support a Dexxa USB graphics tablet. From a visitor - "This gets started anyway when you plug in the USB connector for the graphics tablet, if it's not already running. It then starts an application which manages the tablet messages. Since I leave the tablet unplugged unless I need to use it, I don't need this running at startup. I suspect that this program monitors a number of windows messages, so that when it's loaded, my regular mouse slows down - it acts like it 'sticks' entering and leaving windows. Certainly my performance returned to what I expected when I removed this item using MSCONFIG"
wintnask32.exe wintnask32.exe
Added by the RBOT-AFP WORM!
wintnl.exe wintnl.exe
Added by a variant of the ZOTOB.K WORM!
wintnpx.exe wintnpx.exe
Added by the ZOTOB.H WORM!
WToolsA.exe WinTools
Wintools adware
WinTouch.exe WinTouch
Detected by Kaspersky as the AGENT.BUO TROJAN!
wintray.exe WinTray
Added by the LEGUARDIEN.B TROJAN!
wintsk32dll.exe wintsk32dll
Added by the RBOT-AAJ WORM!
winudll.exe winudll.exe
Added by the MITGLIE-CE TROJAN!
winupated.exe winupated.exe
Added by a variant of the SDBOT WORM!
winupd.exe winupd
SearchNew adware
winupd.exe winupd.exe
Added by the BEAGLE.M or BEAGLE.N WORMS!
winupdat.exe winupdat
Added by the CANBOT.A WORM!
wmbem.exe WinUpdate
Added by the REVCUSS.B TROJAN!
winupdate.exe winupdate
Added by the ALCAN.B WORM!
wupeng.exe Winupdate Engine
MalwareCrush spyware remover - not recommended, see here
winupdate.exe winupdate.exe
Added by the RADO TROJAN!
winupdate.exe winupdate.reg
Added by the SPYBOT.EAS WORM!
winupdates.exe winupdates
Added by the ALCRA-B WORM!
WinUpdating.exe WinUpdating
Added by the AGENT-GSC TROJAN!
winupdbc.exe WinUPDbc
Added by the BANKER-DSN TROJAN!
winupdsv.exe WinUpdsv
Added by the DROPO MACRO!
winupdtl.exe winupdtl
SecondThought adware variant
winrun.exe winur
Added by the WINUR.B WORM!
winguard.exe winusb.dll
Added by the FORBOT-CN WORM!
WinUsr.exe K1S2 WinUsr
Added by the CLUNK.A WORM!
winversion.exe winversion
Browser hijacker, redirecting to specificsearches.com
WinVNC.exe WinVNC
WinVNC is an application that allows you to remote control your PC from another PC somewhere on the internet. Now superseeded by RealVNC
winvxd32.exe winvxd32
Added by the GABLOLIZ.A WORM!
winwan.exe winwan lptt01
RapidBlaster variant (in a "Winwan" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
winwan.exe winwan ml097e
RapidBlaster variant (in a "Winwan" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
winword.exe winword
Added by the TORPID-C TROJAN!
WINWORD.exe WINWORD.exe
Added by the DRIVUS TROJAN! Note - this is not the legitimate MS Word process of the same name, which is always located in the Program Files folder. This one is found in System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
winwsl.exe winwsl.exe
Added by the ZOTOB-J WORM!
WinXDefender.exe WinXDefender
WinXDefender rogue spyware remover - not recommended, see here
WinxDiagUpdate WinxDiagUpdate
Detected by Kaspersky as the RBOT.BWQ TROJAN! See here
winxp.exe winxp
Added by the BRONTOK-DN WORM!
winxp32.exe WinXp Updater
Added by the RBOT-HG WORM!
winxpdll32.exe winxpdll32.exe
Added by a variant of the SMALL downloader TROJAN!
WinXProtector.exe WinXProtector
WinXProtector rogue security software - not recommeded, see here
WinXpUpdate32.exe WinXpUpdate32
Added by the AGENT.YWL WORM!
winxp64.exe winxpusbd
Added by a variant of the RBOT WORM!
winystems.exe winystems25
Added by a variant of the SDBOT WORM!
winzbp.exe WinZap Check
Added by the RBOT-AWZ WORM!
winzip.exe winzip
Added by the RBOT.BDAWORM! Note - this is not part of the popular WinZip file compression utility
winzip81.exe Winzip Application
Added by the RBOT-BKZ WORM!
WZQKPICK.EXE WinZip Quick Pick
Added with WinZip version 8.1. "The new WinZip Quick Pick taskbar tray icon gives you instant access to WinZip and your Zip files. Just left click the icon to open WinZip, or right click it to instantly reopen recently used Zip files, access your Favorite Zip Folders, open WinZip Help, or start WinZip itself.". You can right-click and close it - choosing to not re-load it at start-up
WinZip.exe WinZip Update
Added by a variant of the RBOT WORM! Note - this is not part of the popular WinZip file compression utility
wakeservice.exe WinZix Service
WinZix adware
win_spool2.exe win_spool2
Added by the SCKEYLOG.B TROJAN!
Win Const.exe win_supp00.exe
Added by the ASSASIN-H TROJAN!
WINdirect.exe win_upd.exe
Added by the MITGLIEDER.M TROJAN!
WINdirect.exe win_upd2.exe
Added by the BEAGLE.AO WORM!
Win_vader.vbs Win_vader
Added by the INVASION.A VIRUS!
Winipcfgs.exe WIP Config GUI
Added by the RBOT-CN WORM!
wirelesscm.exe Wireless Connection Manager
Wireless adapter configuration utility for D-Link's range
wcourier.exe Wireless Console
ASUS Wireless Console - installed alongside ASUS wireless components and provides additional configuration options for these devices
WMP11Cfg.exe Wireless PCI Card Configuration Utility
Utility used by the LINKSYS wireless PCI card (WMP11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration
wpsvr.exe Wireless Provider Server
Added by the FORBOT-AD WORM!
WPC54CFG.EXE Wireless-G Notebook Adapter Utility
Utility used by the LINKSYS Wireless-G Notebook Adapter (WPC54G)
wjview.exe wjview
MS tool used to view window-based Java applications from the command line
wkcalrem.exe wkcalrem
Produces a pop-up reminder of events scheduled using the MS Works Calendar
WkDetect.exe WkDetect
Checks for updates to MS Works
wkfud.exe wkfud
A marketing program for MS Works
WksSb.exe WksSb
The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program. The Works Portfolio provides a location where you can store items you want to later put into a document or other file
WkUFind.exe WkUFind
MS Works Update Detection. MS Picture It! (versions 7 to current) use this automatic update feature during the log on process. It can also cause your system to automatically dial into your ISP as it tries to access the internet, if you have your system set to automatically dial when the internet is invoked. To manually update, go to Microsoft's Office/Works update site. You can also turn of the automatic update feature within Picture It! - see here
Winusb2.exe Wlan Drier
Added by the WOOTBOT.DC WORM!
WLANManager.exe WLAN Manager
Wireless management utility for the T-Com Speedport W 100 Card WLAN PCMCIA card
WLANSTA.EXE WLAN Status Tray Applet
System Tray icon for checking the status of a Wireless LAN
wlancfg.exe wlancfg
Inventel wireless router related - required in order to automatically connect to the Net at bootup
wlancfg5.exe wlancfg5
NetGear WG311v3 wireless PCI adapter driver - required in order to automatically connect to the wireless router/gateway at bootup. Note - may not install correctly on Windows9x/ME computers which have Slipstream accelerator installed. Uninstall Slipstream first, disabling slipcore and slipgui are insufficient
WLANSTA.EXE WLANSTA.EXE
System Tray icon for checking the status of a Wireless LAN
WLAN_Cfg.exe WLAN_Cfg.exe
Linksys Instant Wireless USB Network Adapter driver
wlsass.exe wlsass
Added by the RANKY.CY TROJAN!
wltray.exe wltray
System tray access to wireless LAN card configuration options
WINSYS.EXE WLWin
Added by the NAVER.A WORM!
WMVCR.exe WM VCR
WM Recorder allows you to record Windows Media(tm) streaming Video or Audio content. Can be accessed via Start Menu -> Programs
Wm24Pan.Exe Wm24Pan
ESI external sound card driver
winlogon.exe WMAudio
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
wmedia32.exe WMedia32
Added by the BANGER TROJAN!
wmiapi.exe WMI Application Interface
Added by the SPYBOT.RBY WORM!
wmiapsrvs.exe WMI Performance Adapter Services
Detected by Kaspersky as the RBOT.COU WORM! See here
wmiexe.exe WMIEXE.exe
NT component, used by Windows Millennium to detect Plug and Play-compliant IEEE 1394 devices during the startup process. Since this is important for the computer to work properly if you have these, Windows Millennium protects wmiexe.exe and will restore the file even if it's deleted or renamed
Wminf.exe Wminf
Added by the GEMA TROJAN!
Wminfo.exe Wminfo
Added by the GEMA TROJAN!
wmiprv.exe wmiprv
Added by the RBOT-WM WORM!
wmisrv.exe wmisrv
Added by a variant of the IRCBOT BACKDOOR! See here
WINMEDUP.EXE WMP Auto Update
Added by the RBOT.CF WORM!
WMP54Gv4.exe WMP54Gv4
Linksys WMP54Gv4 wireless PCI adapter driver - required in order to automatically connect to the wireless router/gateway at bootup. Note - may not install correctly on Windows9x/ME computers which have Slipstream accelerator installed. Uninstall Slipstream first, disabling slipcore and slipgui are insufficient
wmplayer.exe wmplayer.exe
Added by the BANCBAN-CZ TROJAN!
wmpnscfg.exe wmpnscfg
"Microsoft Windows uses wmpnscfg.exe to alert users when media rendering devices are found on the network. Wmpnscfg starts the Windows Media Player Network Sharing Service (NSS) and then waits for notifications from the service. When wmpnscfg is notified that a new media device is available on the network, it displays a popup in the system tray that informs the user about the availability of the new device. If the user clicks the popup, wmpnscfg launches Windows Media Player, which displays a dialog box that asks the user to either allow or deny sharing with the new device." - see here
wms3.exe wms3
Added by the LEGMIR-AQG TROJAN!
wmsys32.exe wmsys32
Added by the BANPAES.B TROJAN!
WMUAgent.exe WMUAgent.exe
"WakeMeUp! is an advanced alarm clock for computers with Windows 2000, XP or Server 2003"
winmonv.exe wmv
Added by the AGENT-DG TROJAN!
wnsvc.exe WN Services
Added by the KBBOT-A TROJAN!
WNAD.EXE WNAD
Spyware added as a result of running a program called "Yo Mama Osama" (osama.exe). See here for more and how to get rid of it. There are other ways this can show up on your system, and it will manifest itself by periodically opening a new browser window with advertising for copy DVD software and the like
WNILOGON.exe WNILOGON
Added by the LEWOR-M TROJAN!
wns*****.exe [* = random char] WNSC
PurityScan/Clickspring adware
wlogf.exe Wnsck2 driver
Added by the SPYBOT-AF WORM!
wnscp**.exe [* = random char] WNSI
PurityScan/Clickspring adware
WNSO.exe WNSO
Baidu.SoBar adware
wns*****.exe [* = random char] WNST
PurityScan/Clickspring adware
wntlgns.exe wntlgns
CoolWebSearch parasite variant
WAPDATE.EXE won update
Added by the RBOT.N WORM!
WonderFrog.exe WonderFrog
Wonder Frog typing monitor
wcmd.exe Woods Inc
Added by the KILLFIL-O TROJAN!
winamp.exe woopie
Added by the AGOBOT.XV WORM! Note - this is NOT the popular Winamp media player
Watch.exe Woowatch
Wanadoo broadband ISP (now rebranded as Orange) related - not required
WordQcrs.exe WordQ carat flag
Related to WordQ Writing Aid Software
Words.exe Words
Added by the AGENT.GIT TROJAN!
wweb32.exe WordWeb
WordWeb - free theasaurus and dictionary. Start manually
workflow.exe Workflo
Related to BroadJump Client Foundation - broadband troubleshooting software installed by various companies. Is it required?
workpace.exe WorkPace 3.0
WorkPace - stress injury prevention software
wkcalrem.exe Works Calendar Reminder
Produces a pop-up reminder of events scheduled using the MS Works Calendar
wkfud.exe WorksFUD
A marketing program for MS Works
wm95.exe Workstation Scheduler
Desktop Management Scheduler. Part of Novell's Netware Client. Schedueles NDS events. If events have been schedueled, it is required, otherwise, it is useless and a memory hog
wrkstn.exe Workstation Services
Added by the RBOT-OJ WORM!
worldantispy.exe WorldAntiSpy
WorldAntiSpy, "rogue" spyware remover, installed as part of this scam
wd.exe Worm Detector
Worm Detector - antivirus add-on for Outlook 2K or XP for handling worms and spam
winstart.exe wormexe
Added by the EARLYBIRD WORM!
wovax.exe wovax
Added by the DAQA.A TROJAN!
wwf.exe wow
Added by the LINEAGE-Y TROJAN!
wpctrlnt.exe Wpctrl
WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties
wpctrl95.exe Wpctrl
WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties
wpctrlnt.exe wpctrl95
WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties
wpctrl95.exe wpctrl95
WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties
WpcUmi.exe WPCUMI
Windows Vista Parental Control Notifications from Microsoft Corporation
WpCycleWin.exe WPCycle.exe
Added when selecting Mplayer2 to open media files. Forces other codes to Wait for Previous instructions to end, preventing instability of your CPU (freezing)
wwnrot.exe wpds.exe
Added by the BAGLEDI-D TROJAN!
WPlayer.exe WPlayer
Identified as a variant of the LDPinch.A malware
wpnsc.exe WPSVC Services
Added by a variant of the IRCBOT BACKDOOR!
wpwmgrs.exe wpwmgrs
Added by the MYTOB-DH WORM!
WQK.exe WQK
Added by the KLEZ.H WORM!
WR.EXE wr
??
wr.exe WR Command
??
WrCtrl.exe WrCtrl
Win-Route 4.27 NAT engine on Win2k Pro for connection sharing and security using Win-Route by Tiny Software. A connection sharing/Firewall Application. If service is disabled the program does not work, but you can manually start/stop the service with a shortcut the program installs at any time
WrDialer.exe WRDialer
WinPoet DSL dialler
wregbios.exe WregBios
Desktop Management BIOS (DMI BIOS) related. Apparently invokes the DosBios.exe file. Is it required?
wrexec.exe wrexec
Watch Right - monitoring program, part of the PowerTools add-on for AOL. Records instant messages, E-mail, chat. Watch Right appears to be, and functions as an online clock updater which connects with the U.S. National Institute of Standards and Technology. It was designed for parents who wish to keep an eye on what their children are doing online
wriste.exe wriste
??
WrtMon.exe WrtMon.exe
Related to Presto PageManager which is bundled with Canon Scanners
ws2help.exe ws2help
Added by a variant of the SMALL.AN TROJAN!
ws2_64.exe ws2_64.exe
Added by an unidentified TROJAN! See here
wmon32.exe WSAConfiguration
Added by the GAOBOT.BAJ WORM!
win32upd.exe WSAConfiguration
Added by a variant of the RBOT WORM!
winlogon32.exe WSAConfiguration
Added by the AGOBOT-WC WORM!
winmon32.exe WSAConfiguration
Added by the AGOBOT.TM WORM!
wsass32.exe wsass32
Added by the BANKEM-V TROJAN!
wsbklite.exe wsbklite
Related to the Acer Soft Button on Acer Tablet PCs. Appears to do nothing so is it required?
WScheduler.exe WScheduler
Windows Scheduler - "schedule unattended running of applications, batch files, scripts and much more. Also, you can schedule popup reminders so you'll never forget reminders, tasks and other events."
wscnfty.exe wscnfty
Added by a variant of the RBOT WORM!
wsscntfy.exe wscntfys
Added by the SDBOT-TN WORM!
wscsvc.exe wscsvc.exe
Added by a password stealing BANKER TROJAN!
wsctf.exe wsctf.exe
Added by the JAMPORK.E WORM!
WSconf.exe Wsdata service
Added by the SDBOT.ZU WORM!
wserv.exe wserv
Added by a variant of the SDBOT WORM!
wserver.exe wserver
Added by the NETSKY.AC or SASSER.G WORMS!
WService.exe WService
Tablet client Driver for UC-Logic Pen/Graphics Tablet
wsg32.exe wsg32
GoldenKeylog keystroke logger/monitoring program - remove unless you installed it yourself!
wskrnl.exe wskrnl
ActMon surveillance software. Uninstall this software unless you put it there yourself
WSockDrv32.exe WSockDrv32
Added by the WINKO.AO WORM!
wsrv32.exe wsrv32
Detected by Kaspersky as the AGENT.EP TROJAN!
wmmon32.exe WSSAConfiguration
Added by the AGOBOT-KC WORM!
wssys.exe wssys
WebPI logs keystrokes and captures screenshots. If you didn't install this yourself remove it
Wstat32.exe Wstat32 driver
Added by the LOONBOT TROJAN!
wstimeb.exe wstimeb
Used with NEC printers. You can disable it before printing but it re-loads itself when printing so you may as well leave it
wsttrs.exe wsttrs
Added by the LDPINCH-QS TROJAN!
wsvbs.exe wsvbs
Added by the PWS-AEB TROJAN!
wswpd.exe wswpd
Used with some models of Panasonic, Epson and NEC printers. Some older drivers known to have a "memory leak". Needed for printing to work
wsys.exe wsys.exe
SpyloPCMonitor is a surviellance software program that monitors user activity, logs keystrokes, and takes screenshots. It ends the processes of anti-spyware programs. If you didn't install this yourself remove it
ws32.exe ws_d
Added by the LEGMIR-RL TROJAN!
wtgamechannel.exe WT Game Channel
WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
wtgamechannel.exe WT GameChannel
WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
wtftest.exe WTF Test
Added by the RBOT-ACM WORM!
wapisvit.exe WTSI
PurityScan/Clickspring adware
wap***.exe [* = random char] WTSS
PurityScan/Clickspring adware
wapisvtr.exe WTST
PurityScan/Clickspring adware
WU713STA.EXE WU713STA.EXE
Blitzz Technology wireless NIC adapter driver
wuanguard32.exe wuanguard
Added by the RBOT-AAF WORM!
WudfSvc.exe WudfSvc
Added by the SHEUR.BBB TROJAN!
WUOLService9x.exe WUOLService
Remote wakeup status agent. Part of Novell's ZenWorks. Processes Wake-up on LAN requests (turn on a computer remotely on LAN)
wuosdial.exe wuosdial
Added by a variant of the RBOT WORM!
win32.exe wupd
Added by the ORSE-C TROJAN!
wisvccz.exe wupdate
Added by the ORSE-B TROJAN!
wi32.exe wupdate
Downloader trojan, detected by Panda antivirus as Adware/Trustbid
WUpdates.exe WUpdates
Added by the SWEPDAT TROJAN!
Wupdm32.exe Wupdm32
Added by the MIDLAK WORM!
wupdmgr32.exe wupdmgr32.exe
Added by the CERTIF-I TROJAN!
wupdt.exe wupdt
Added by the IMISERV.A TROJAN!
wupftp.exe Wupftp
Added by the AGOBOT.AKV WORM!
WUSB11B.exe WUSB11B.exe
Linksys WUSB11 WLAN USB adapter
WUSB54Gv4.exe WUSB54Gv4
Wireless-G USB Wireless Network Adapter related - would appear to be required
wuviewer.exe wuviewer
Added by a Proxy Trojan variant
wsass.exe WWKS
Added by the SDBOT-BT WORM!
WXprocMgr.exe WXProcMgr Module
TVTonic from Wavexpress - "enjoy 3 full-screen, DVD-quality video channels for FREE". Allows data content to be downloaded and synchronized on your system
WZCBDL9X.exe WZCBDLService
WZCBDLService Launcher from D-Link - configuration/drivers
wzdmg.exe wzdmg
Added by a generic downloader TROJAN - see here
wzhelper.exe wzhelper
Searchcentrix hijacker
WTHRTRAY.EXE X10Weax
WeatherCheck - "bring the latest local weather to your desktop". Not recommended as it reportedly pops ads, and contains no uninstaller
wdfsctl.exe X4ALLNL
XS4All Webdisk - web space management utility for the Dutch ISP
wmsdkns.exe XMLmedia 10.0
Added by the FAKEALERT TROJAN!
wuauclt10.exe Xordate
Added by the RBOT-GKN WORM!
wuauclt11.exe Xordate
Added by the RBOT-GLI WORM!
wuauclt12.exe Xordate
Added by the RBOT-GLQ WORM!
wuauclt13.exe Xordate
Added by the RBOT-GLM WORM!
winis.exe xp
Added by the RBOT-WO WORM!
wini.exe xpstart
Added by the PICRATE.A WORM!
winlogins.exe xpstat
Added by the RBOT-AAR WORM!
winlogon.exe xp_system
Added by the KREPPER-G TROJAN! - a CoolWebSearch parasite variant. Note - this is not the legitimate winlogon.exe, which should not figure in Msconfig/Startup!
winxtn.exe XTN Service Drivers
Added by the SDBOT-YK WORM!
WatchPNM.exe YOW tuner
??
WrDialer.exe z-WrDialer
WinPoet DSL dialer
winmuse.exe ZPoint
Added by the VJ TROJAN!
wincpu.exe [random name]
Added by an unidentified VIRUS, WORM or TROJAN!
w?auboot.exe [random name]
PurityScan/Clickspring adware
w?auclt.exe [random name]
PurityScan/Clickspring adware
w?crtupd.exe [random name]
PurityScan/Clickspring adware
w?wexec.exe [random name]
PurityScan/Clickspring adware
w?nlogon.exe [random name]
PurityScan/Clickspring adware
w?nword.exe [random name]
PurityScan/Clickspring adware
w?aclt.exe [random name]
PurityScan/Clickspring adware
wucrtupd.exe [random name]
PurityScan/Clickspring adware. Do not confuse with the legitimate Windows Critical Update Notification (wucrtupd.exe)
wuauboot.exe [random name]
PurityScan/Clickspring adware. Note - do not confuse with the legitimate wuauboot.exe file, which should not figure in Msconfig/Startup!
w?nspool.exe [random name]
PurityScan/Clickspring adware
Windows32.exe [various names]
Added by any of a number of WORM or TROJAN variants
winlogon32.exe [various names]
Added by an unidentified WORM or TROJAN!
win32snd.exe [various names]
Added by the RBOT-DQ WORM!
WhatsNewBot.exe [various names]
Wareout - malware masquerading as a spyware and dialer remover
WinInitDll.exe [various names]
Wareout - malware masquerading as a spyware and dialer remover
wormexe.exe [various names]
Wareout - malware masquerading as a spyware and dialer remover
WTFCTF.exe [various names]
Wareout - malware masquerading as a spyware and dialer remover
winadm.exe _winadm
Parents Friend - "Log any activity and protect programs with a password. Further more you can lock the pc any hour in the week you want with the main password. You can also give users allowed programs in their program-lists and you can limit the maximal daily hours and maximal weekly hours user spend on the PC"
winexec.exe _WinMain
Added by the DLOADER-XX TROJAN!
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59