 |
winrecon.exe |
!NoLoad
WinRecon keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
winSOCKS.exe |
(*)API Machine
Homepage hijacker, see here (* = any digit) |
 |
win32API.exe |
(*)Run
Homepage hijacker, see here (* = any digit) |
 |
winhelp.exe |
(Default)
Added by the BLACKMAL.C WORM! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank |
 |
winbas12.exe |
(Default)
Adware, CoolWebSearch parasite related - detected by Kaspersky as the VB.DU TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank |
 |
winlog.exe |
(Default)
Unidentified adware. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank |
 |
winligom.exe |
(Default)
Added by the RBOT-GAI WORM! Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run, HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank |
 |
wstcl.exe |
*Microsoft Update
Added by the STMU TROJAN! |
 |
wucxt.exe |
*Microsoft Update
Added by the STMU TROJAN! |
 |
wuytc.exe |
*Microsoft Update
Added by the STMU TROJAN! |
 |
WerFault.exe |
*WerKernelReporting
Part of Windows Error Reporting technology (WER) for Vista. WER captures software crash and hang data from end-users who agree to report it - see here |
 |
wrauclt.exe |
*windows update
Added by the RBOT-QU WORM! |
 |
wuanclt.exe |
*windows update
Added by the RBOT-PG WORM! |
 |
wuaucrlt.exe |
*windows update
Added by the SPYBOT.HUR WORM! |
 |
wuraclt.exe |
*windows update
Added by the RBOT-PO WORM! |
 |
wurauclt.exe |
*windows update
Added by the RBOT-SY WORM! |
 |
wsctl.exe |
*windows update
Added by the SPYBOT.PR WORM! |
 |
wkmst.exe |
*windows update
Added by the SDBOT.AVD WORM! |
 |
wscxt.exe |
*windows update
Added by the RBOT.AOS WORM! |
 |
waurclt.exe |
*windows update
Added by a variant of the RBOT WORM! |
 |
winstats.exe |
*winstats
Added by the GARGAFX TROJAN! |
 |
w****.exe [* = random char] |
*wuauclt.exe
Added by a variant of the RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe, wtmsv.exe, wxmst.exe, wmsvc.exe and so on... |
 |
wininfo.exe |
,main drive Loader
Suspected malware as it appears in 3 different registry locations - see here |
 |
winlogon.exe |
.Prog
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
WARN0190.EXE |
0190 Warner
Anti-dialer program (Germany) |
 |
WARN0900.EXE |
0900 Warner
Anti-dialer program (Germany) |
 |
WebMailSpy.exe |
1WinCfg32
WebMailSpy spyware |
 |
winmgr.exe |
252
Added by the LEGMIR-AT TROJAN! |
 |
winlog0n.exe |
9m
Added by the LEGMIR-AQK TROJAN! |
 |
wincms.exe |
@
Added by the RBOT.CBR WORM! |
 |
w32NTupdt.exe |
A New Windows Updater
Added by the MYTOB.BM WORM! |
 |
winpppoverethernet.exe |
a-winpoet-service
WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking |
 |
winsto.exe |
Access Control App
Detected by Kaspersky as the AGENT.DGO TROJAN! See here |
 |
wcescom32.exe |
ActiveSync
Added by the MANCSYN-E TROJAN! |
 |
wini.exe |
AdAware
Added by the RBOT-XN WORM! |
 |
winlogon.exe |
Administrator
Added by the RUBBLE-C WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
windrv.exe |
ADriver
Added by the DELF.WG TROJAN! |
 |
windefault.exe |
AFAFilter
AFAFilter - internet filter software |
 |
WinServ.exe |
AKEYNAME
Added by the EVILBOT.C TROJAN! |
 |
winoff.exe |
AMP WinOFF
WinOFF is " a utility designed to shut down Windows computers automatically, in a fully configurable way" |
 |
WZCSLDR2.exe |
ANIWZCS2Service
ALPHA Networks wireless driver |
 |
WZCSLDR.exe |
ANIWZCSService
D-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity |
 |
winsp3.exe |
Anti-Virus Update Scheduler
Malware - detected by Kaspersky as the AGENT.FP TROJAN! |
 |
winlog.exe |
AntiVir
Added by the IRCBOT-TJ TROJAN! |
 |
winapix.exe |
APIMon
Added by a variant of the TIBSER.A downloader TROJAN! |
 |
WN511B.exe |
AS00_WN511B
Netgear RangeMax NEXT wireless adapter configuration utility |
 |
WPN511.exe |
AS00_WPN511
NetgearRev MFC Application - software for Netgear wireless network cards - what does it do and is it required in startup? |
 |
windfind.exe |
atisrc2
Added by the WINDFIND-A TROJAN! |
 |
winfp.exe |
Audio Device Manager
Detected by PCTools as the IRCBOT.BIV TROJAN! See here |
 |
WinNT.exe |
Audio Device Manager
Added by the BANKER.BTG TROJAN! |
 |
WNDXP.exe |
Audio Device Manager
Detected by Kaspersky as the IRCBOT.AJL TROJAN! See here |
 |
wintmr.exe |
Authentic-ID Toolbar
System Tray access to Child Control parental control software by Salfield |
 |
win32.exe |
auto
Added by the SMALL!SD5 TROJAN! |
 |
WindowsSys32.exe |
Auto Updat
Added by a variant of the FORBOT WORM! |
 |
windowsupdate.exe |
autoload
Detected by Trend Micro as the POLYCRYP.DY TROJAN! See here |
 |
wauclt.exe |
Automated Windows Updates
Added by the GAOBOT.AJD WORM! |
 |
winmain.exe |
autorun
Added by a variant of the DELF.CNS TROJAN! |
 |
WINUP2DATE.DLL, SHStart |
autoupdate
Unidentified adware - detected by Panda antivirus as the CLICKER.CY TROJAN! |
 |
wlangui.exe |
AVMWlanClient
Related to broadband products from avm.de |
 |
win*.tmp.exe [* is a number] |
avp
Added by a variant of the ALPHABET TROJAN! |
 |
WErcx.exe |
AvpWx
Detected by Kaspersky as a variant of the AGENT.A TROJAN! |
 |
winupdate.exe |
blah service
Added by the GAOBOT.BIA WORM! |
 |
winsysengine.exe |
blah service
Added by the RBOT-KI WORM! |
 |
win32.exe |
blah service
Added by the RBOT-AXO WORM! |
 |
WLANmon.exe |
Blitzz BWI715
Blitzz Technology BWI715 Wireless PC modem connection monitor |
 |
wscript.exe [path] Date.POP.vbs |
BootsCfg
Added by the KUULLIO WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted |
 |
wscript.exe [path] All Users.vbs |
BootsCfg
Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted |
 |
wscript.exe [path] All Users.vbe |
BootsCfg
Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted |
 |
wscript.exe Install.log.vbs |
BootsCfg
Added by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "Install.log.vbs" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
wavepcmonitor.exe |
Bose Wave/PC Monitor
System Tray access for this system (more info on the system here). Available via Start -> Programs |
 |
winlogin.exe |
BossIdea
Added by the LINEAGE-I TROJAN! |
 |
wltray.exe |
Broadcom Wireless Manager UI
System tray access to wireless LAN card configuration options |
 |
winlogon.exe |
BuildLab
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
Wininit.exe |
Bymer.Scanner
Added by the BYMER WORM! |
 |
WinTask.exe |
C:WINDOWSWinTask.exe
"Pop Marketing" adware |
 |
WindowsSec.exe |
Cable Modem Adapter
Added by the WOOTBOT.A WORM! |
 |
wincalc.exe |
Calc Microsoft Windows
Added by an unidentied WORM or TROJAN! |
 |
WMADZ.EXE |
ccApp
Added by the RBOT-LJ WORM! |
 |
winlogon.exe |
ccApps
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
wintmr.exe |
CCWinTray
System Tray access to Child Control parental control software by Salfield |
 |
windrv.exe |
CDriver
Added by the DELF.WG TROJAN! |
 |
wsot.exe |
CEPA
?? |
 |
WinMuschi.exe |
CFDStart
WINMUSCHI dialler |
 |
wiseupdt.exe |
Check for One Touch Update
Checks for updates for Visioneer OneTouch scanners |
 |
WiseUpdt.exe |
Check for TWS Updates
Interactive Brokers - check for update to their standalone Java-based trading platform |
 |
webtmr.exe |
ChicoSys
Child Control parental control software |
 |
W95AGENT.EXE |
Client agent for ARCserve
Part of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required? |
 |
wup.exe |
Client Update
Added by the OPANKI.O WORM! |
 |
winjes.exe |
Compaq Jes Drivers
Added by the SDBOT-XR WORM! |
 |
wincmd.exe |
Compaq Service Drivers
Added by the RBOT.ATV WORM! |
 |
wind32.exe |
Compaq Service Drivers
Added by a variant of the SDBOT WORM! |
 |
winmsn.exe |
Compaq Service Drivers
Added by a variant of the SDBOT WORM! |
 |
winsvc.exe |
Compaq Service Drivers
Added by the SDBOT-AGD WORM! |
 |
wstray.exe |
ComTry Web Searcher
Comtry MP3 Downloader related - spyware |
 |
WinService32.exe |
Config
Added by the CRUTCHA-A TROJAN! |
 |
winsys32.exe |
Config Loadr
Added by the AGOBOT-HN WORM! |
 |
Wuxat.exe |
Configuration Default
Added by the SPYBOT-CA WORM! |
 |
Winset32.exe |
Configuration File
Added by the FLUX.101 TROJAN! |
 |
wupdated.exe |
Configuration Loaded
Added by the MOEGA or MOEGA.AG or MOEGA.AP WORMS! |
 |
wincrt32.exe |
Configuration Loader
Added by the GAOBOT.BF WORM! |
 |
windex.exe |
Configuration Loader
Added by the GAOBOT.BZ WORM! |
 |
Winreg.exe |
Configuration Loader
Added by the GAOBOT.AO WORM! |
 |
winicfg32.exe |
configuration loader
Added by the GAOBOT.RQ WORM! |
 |
wincffg.exe |
Configuration Loader
Added by the AGOBOT.A3 WORM! |
 |
WinHelper.exe |
Configuration Loader
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
wincore.exe |
Configuration Loader
Added by the SDBOT.BHE WORM! |
 |
Winsys32.exe |
Configuration Loader Service
Added by the RBOT-YV WORM! |
 |
wscel.exe |
Configuration Loading Service
Added by the SDBOT-WJ WORM! |
 |
wlanutil.exe |
Configuration Utility
NetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards) |
 |
winamp32.exe |
Configuration32 Loader32
Added by the SDBOT-BIC WORM! |
 |
winservn.exe |
ContentService
Homepage hijacker |
 |
WFXCTL32.EXE |
Controller
From Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs |
 |
winlogin32.exe |
cpanel
Added by the RBOT-FOY WORM! |
 |
wincomp.exe |
cpntmgc
Added by the WINTRIM_A TROJAN! |
 |
winmgts.exe |
cpntmgc
Added by the WINTRIM-B TROJAN! |
 |
wuitgurd.exe |
CPU Temp Control
Added by the RBOT-AHV WORM! |
 |
world_cup_.bat |
cqlyg
Added by the WCUP.A WORM! |
 |
Wucrtupd.exe |
CriticalUpdate
MS Windows Critical Update Notification. If you want to keep Windows up-to-date, check the Windows Update site |
 |
wucrtupd.exe |
CriticalUpdate
Added by the NOALA.B WORM! Note - this file is located in the Windows or Winnt folder, and must not be confused with the legitimate Windows process of the same name as described here |
 |
WinConst.exe |
ctfmon
Added by the ASSASIN-G TROJAN! |
 |
WINLOGON.EXE |
CueX44_stil_here
Added by the PUNYA-A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
WLANMON.exe |
D-Link AirPlus DWL-650+ Utility
D-Link Air Plus Wireless PC modem connection monitor |
 |
weather.exe |
Daily Weather Forecast
Added by the DLOADER-IP TROJAN! |
 |
W815DM.EXE |
ddhelper
Enuff Parental Control Software by Akrontech |
 |
windrv.exe |
DDriver
Added by the DELF.WG TROJAN! |
 |
worm.exe |
Delete Me
Added by the DOOMHUNTER WORM! |
 |
wltray.exe |
Dell Wireless Manager UI
System tray access to wireless LAN card configuration options |
 |
wfxmgr.exe |
Device Manager
Added by the RBOT.AJU WORM! |
 |
win.exe |
Distributed File System
Added by the MYFIP.AB WORM! |
 |
WATCH.exe |
DLHelperEXE
Download helper distributed with some software that allows the software installation to redirect download locations. Not required once the installation is finished |
 |
windfe.exe |
DLINK dfe drivers for Windows NT
Added by the RANDEX.AK WORM! |
 |
wakeservice.exe |
DomPlayer Service
DomPlayer adware |
 |
WindowsUpdate.exe |
DRam prosessor
Added by the RBOT-BBZ WORM! |
 |
winupdaterar.exe |
DRam rar proc
Added by a variant of the IRCBOT TROJAN! |
 |
W95Mm.exe |
drmu
Homepage hijacker installing a toolbar: http://tdko.com/. Lop.com in disguise |
 |
windspl.exe |
DsplObjects
Added by the BEAGLE.DN WORM! |
 |
windrv.exe |
DSystemDriver
Added by the DELF.WG TROJAN! |
 |
weather.exe |
Dulux WeatherShield WeatherDesk
Dulux WeatherShield WeatherDesk - latest weather information from across Australia |
 |
windvd98.exe |
dvd98
Added by the CULT.P WORM! |
 |
wsxsvc.exe |
Dvx
Delfin Media Viewer or "Promulgate" adware variant |
 |
Weather.exe |
DW4
Desktop Weather |
 |
winxp34.exe |
Dynamic Dns Binary
Added by a variant of the RBOT WORM! |
 |
WinHelpcfn.exe |
Dynamic Dns Binary
Added by a variant of the RBOT WORM! |
 |
wizard.exe |
EAPCISETUP
Part of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation |
 |
wjview ...Code |
EbatesMoeMoneyMaker
Ebates adware |
 |
watch.exe |
Eicon NetworksLAN_DAEMON
Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually |
 |
watch.exe |
Eicon TechnologyLAN_DAEMON
Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually |
 |
Winmsuit.exe |
ELSA WINman Suite
Allows you to totally customize your ELSA graphics card settings, including overclocking the GPU |
 |
wintr.com |
encapsulated command tool
?? |
 |
WMENCAGT.EXE |
Encoder Agent
MS Windows Media Encoder, which already has a shortcut in the Start Menu if installed |
 |
wsys.exe |
Enumerate Service
Added by the MANIFEST TROJAN! |
 |
wind2ll2.exe |
erfgddfk
Added by the BEAGLE.CQ WORM! |
 |
windlhhl.exe |
erghgjhgdr
Added by the BEAGLE.BG WORM! |
 |
windlhhl.exe |
erghgjhjgdr
Added by the BEAGLE.BG or BEAGLE.BH or BEAGLE.BI or BEAGLE.BJ WORMS! |
 |
windll2.exe |
erthegdr
Added by the BEAGLE.CG WORM! |
 |
windll.exe |
erthgdr
Added by the BEAGLE.AO or BEAGLE.AQ WORMS! |
 |
winfw.exe |
eTunnel
Added by an unidentified TROJAN! |
 |
Warm.scr |
ExeName32
Added by the SCOLD WORM! |
 |
wscript.exe [filename] |
explorer
Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted |
 |
Windows Explorer.exe |
Explorer
Added by the SILLYFDC-I WORM! |
 |
winset.exe |
exporet
Added by the QQPASS-I TROJAN! |
 |
wo.exe |
eZWO
eZula TopText adware |
 |
wincfg.exe |
Fantasia injector
Added by the AGOBOT.US WORM! |
 |
windrv.exe |
FDriver
Added by the DELF.WG TROJAN! |
 |
wmiprvsc.exe |
File System Service
Added by the AGOBOT-HZ TROJAN! |
 |
wtm.exe |
FileFreedom_Plugin
FileFreedom peer-to-peer sharing program |
 |
Wscript.exe ChkMgr32.vbs |
FileManager32
Added by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "ChkMgr32.vbs" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
Wscript.exe UpdataFiles.vbs |
FileSoft
Added by the SST.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "UpdataFiles.vbs" file is located in the Winnt or Windows folder |
 |
wuaclt.exe |
FireFox Startup Drivers
Added by the RBOT.BYX WORM! |
 |
wmlaunch .exe |
Firewall
Added by the ELIPTER.A or ELIPTER.B WORMS! |
 |
wmlaunch .exe |
Firewall
Added by the ELIPTER.D WORM! |
 |
winlogon.exe |
Firewall auto setup
Added by a TROJAN - see here. Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
WinedowsUpdater1.exe |
Firewall Update System1
Added by the RBOT-ARU WORM! |
 |
WinFIX1.0.vbs |
FIX
Added by the GORMLEZ-A WORM! |
 |
wssdtu.exe |
Folder Service
Added by the MANIFEST TROJAN! |
 |
WINFAH.EXE |
Folding@home
Folding@Home is a distributed computing project which studies protein folding, misfolding, aggregation, and related diseases - must be running in order to access the internet to upload to the servers. Available via Start -> Programs |
 |
winlogon.exe |
FriendlyTypeName
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
winpopup.exe |
Fromine WinPopup
Instant Messenger program |
 |
winsvc.exe |
Generic Host Process for Win32 Services
Added by the SDBOT-O WORM! |
 |
winsvc32.exe |
Generic Host Process for Win32 Services
Added by the SDBOT-P WORM! |
 |
winlogon.exe |
Generic Host Process for Win32 Services
Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
WinLoaderXP.exe |
GenericHostXP
Added by the BDOOR-ACX TROJAN! |
 |
Winmod32.exe |
Gerenciamento de arquivos do Windows
Added by the DLOADER-WG TROJAN! |
 |
winsystems.exe |
german.exe
Added by the BAGLEDl-AE TROJAN! |
 |
wintems.exe |
german.exe
Added by the BAGLE-AS TROJAN! |
 |
wakeservice.exe |
Get-Torrent Service
Get-Torrent bittorrent client - Installs LOP adware |
 |
winB_.exe |
getwin
Added by the BANKER-HS TROJAN! |
 |
WinDash.EXE |
Global Startup
Detected by Kaspersky as the VB.Q WORM! |
 |
window.exe |
gpmce
Detected by Kaspersky as the VB.CK WORM! See here |
 |
windll.exe |
Graphics adapter service
Added by the ATNAS.A WORM! |
 |
wscript.exe gpremier.vbs |
gremier
Added by the GPREMIER WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "gpremier.vbs" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
WCESCOMM.EXE |
H/PC Connection Agent
Active sync for use with Windows CE based palm PC |
 |
WinHSD.exe |
Hardware Shell Detection
Added by a variant of the RBOT WORM! |
 |
Wizardnil.exe |
Help
Added by the BANCOS-BCZ TROJAN! |
 |
windowsupdate.exe |
HKLMRun
Added by the FORBOT-BJ WORM! (where HKLMRun represents HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun) |
 |
wiz98.exe |
hostserv
Added by a variant of the SDBOT WORM! |
 |
winHostsEdit.exe |
HostsFileMgr
AdBin from Gilmore Software Development. An easy solution to managing your Window's hosts file |
 |
We Love Lien Van de Kelder.exe |
http://www.lienvandekelder.be
Added by the MYTOB-CV WORM! |
 |
winsys.exe |
I am not Ranky. I am eTunnel!
Added by an unidentified WORM or TROJAN! |
 |
winlog.exe |
icq lite
Added by the IRCBOT-TJ TROJAN! |
 |
winlogon.exe |
ICQ Net
Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup! |
 |
webcamupdate.exe |
IcqBeta
Added by an unidentified TROJAN! |
 |
winlogon.exe |
ICQNet
Added by the NETSKY-C WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder |
 |
wini.exe |
IE Runtime
Added by the PICRATE.B WORM! |
 |
winis.exe |
IE Runtimes
Added by the RBOT-ADZ TROJAN! |
 |
wkstmg.exe |
IE6
Added by a variant of the SDBOT WORM! |
 |
winsnt.exe |
IE6
Added by the RBOT-GOV WORM! |
 |
WinSock.exe |
IExplorerService
Detected by Kaspersky as the AGENT.KIU TROJAN! See here |
 |
WashIdx.exe |
Index Washer
Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
 |
wsock32.exe |
InetServices
Added by the WOCK32-A TROJAN! |
 |
wmplayer.exe |
infamous.exe
Added by unknown malware. WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup. Infamous.exe is identified by Panda antivirus as Trj/Briss.A |
 |
WUSB11cfg.exe |
Instant Wireless Configuration Utility
Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration |
 |
WPC11Cfg.exe |
Instant Wireless Configuration Utility
Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration |
 |
wing32.exe |
Intec Service Drivers
Added by the RBOT.HAZ WORM! |
 |
winrvc.exe |
Intec Services Driverrs
Added by a variant of the SDBOT WORM! |
 |
winnook.exe |
Intel system tool
Added by the SPYRE-C TROJAN! |
 |
WinSocks5.exe |
internct
Added by the GRAYBIRD.F TROJAN! |
 |
winlogom.exe |
Internet
Added by a variant of the SDBOT WORM! |
 |
winsas32.exe |
internet
Added by a variant of the SDBOT WORM! |
 |
wins.exe |
Internet
Detected by PCTools as the RBOT.AAYF WORM! See here |
 |
winz32.exe |
INTERNET SERVISES
Added by the KWBOT.Z WORM! |
 |
wkfix.exe |
Internet2 Optimizer
Added by a variant of the RBOT WORM! |
 |
windows.exe |
InternetExplorer2
Added by the SDBOT-CZP WORM! |
 |
winz32.exe |
INTERNET_SERVISES
Added by the SDBOT.Q TROJAN! |
 |
WINDRV.EXE |
InterU
Added by the IRCINTER.A TROJAN! |
 |
WinCinemaMgr.exe |
Intervideo Win Cinema Manager
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
 |
WINCIN~1.EXE |
Intervideo Win Cinema Manager
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
 |
WinCinemaMgr.exe |
Intervideo WinCinema Manager
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
 |
WINCIN~1.EXE |
Intervideo WinCinema Manager
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
 |
WinScheduler.exe |
Intervideo WinScheduler
WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs |
 |
wnmgre.exe |
IPC Spool Manager
Added by the SDBOT-ZC WORM! |
 |
winspec.exe |
IPC Spool Manager
Added by the SDBOT-BLU WORM! |
 |
Winipcfgs.exe |
IPTable Configuration
Added by a variant of the RBOT WORM! |
 |
winmon32.exe |
iRis Active Monitor
Iris Antivirus - discontinued, replace with good alternative |
 |
WIMMUN32.exe |
iRiS AntiVirus Active Monitor
Iris Antivirus - discontinued, replace with good alternative |
 |
wintmp.exe |
ISPSERVICE
Detected by Trend Micro as the FLOOD.BC BACKDOOR! See here |
 |
winlogan.exe |
jkdfj94kgdftdf
Added by the ZLOB.BZ TROJAN! |
 |
winxp2.exe |
Jufualt
Added by the SDBOT-AAB WORM! |
 |
win1ogoin.exe |
KAVFOX
Added by the GWGHOST-M TROJAN! |
 |
wscntfy.exe |
KAVPersonal90
Added by the BANKER-FZ TROJAN! |
 |
Windll.exe |
KavRuns
Added by the TRYNOMA TROJAN! |
 |
winser.exe |
KernelCheck
Added by the TSPY_LMIR.SL TROJAN! |
 |
wmiprvse.exe |
Kernel_check
Added by the SONEBOT-B WORM! Note - this is not the legitimate wmiprvse.exe process which is always located in the System32wbem folder and should not normally figure in Msconfig/Startup! |
 |
winxp.exe |
key
Added by the BEAGLE.AG WORM! |
 |
winlog.exe |
key2
Added by the BAGLEDI-AL TROJAN! |
 |
wppewafaj.exe |
KnowledgeBase GUI
Added by the RBOT-GRZ WORM! |
 |
word.EXE |
KV2005
Added by the IW TROJAN! |
 |
winmine |
l44sys**
Added by the VBS.LIDO WORM - where ** is a number between 33 and 44 |
 |
wllmsngr.exe |
Live Messanger
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
win32.exe |
Load
Added by the RUBBLE-A WORM! |
 |
Wscript.exe LGuarg.exe.vbs |
Load-Guard
Added by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "LGuarg.exe.vbs" file is located in the Winnt or Windows folder |
 |
winldra.exe |
load32
Added by the NIBU.J BACKDOOR or DUMARU-BI TROJAN! Note - also known as Srv.SSA-KeyLogger by Sunbelt Software which has developed a free removal tool for this keylogger |
 |
WPSLOAD.EXE |
load=
Windows printing system that comes with the setup for Canon BJC series on the manufacturer's disk |
 |
WINOSCFG.EXE |
load=
Could it be something to do with configuring Windows on a new PC from an OEM supplier? |
 |
wpshrc.exe |
load=
Required to prevent configuration errors on a Compaq LBP-660 and LBP-460 parallel port laser printers (and maybe others) |
 |
wtfeat.exe |
Load=
Associated with the Wintab Digitizer |
 |
win32exec.exe |
load=
Added by the BITTER WORM! |
 |
WMPLAYER.EXE |
loader
Unknown baddie - WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup |
 |
wmimgr.exe |
LoadPFW
Added by the QEDS-B WORM! |
 |
watcher.exe |
LoadWatcher
Watcher spyware |
 |
winset.exe |
loadwin
Added by the QQPASS-I TROJAN! |
 |
winsys.exe |
loadwin
Added by the QQPASS-J TROJAN! |
 |
winlog.exe |
Login
Salfeld Child Control - parental control software |
 |
wrcam.exe |
Logitech Desktop Controller
Added by a variant of the RBOT WORM! |
 |
wincalc.exe |
LogService
Added by the PAPROXY TROJAN! |
 |
WIWT.EXE |
longos
Added by the BANKER-CD TROJAN! |
 |
wfdmgr.exe |
LSA
Added by the MYTOB.C WORM! |
 |
woekd.exe |
Lsass
Added by an unidentified WORM or TROJAN! |
 |
winupdate.exe |
LTM2
Added by the LITMUS.203 TROJAN! |
 |
winscan.exe |
LTM2
Added by the LITMUS-B TROJAN! |
 |
winvers16.exe |
LTM2
Added by the SMALL.ND TROJAN! |
 |
wusas.exe |
Machine Update Soft
Added by an unidfentified WORM! |
 |
WMIPRVSW.exe |
machine-debugger
Added by the AGOBOT.U WORM! |
 |
wintrims.exe |
MC
Added by the WINTRIM TROJAN! |
 |
WINTRIM.EXE |
MC
Added by the WINTRIM_A TROJAN! |
 |
Win32.dll.vbs |
mcafee
Added by the CATCHER-B WORM! |
 |
WebScanX.exe |
McAfeeWebscanX
From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc |
 |
wisp.exe |
MCX Update
Added by the RBOT-AQH WORM! |
 |
winy.exe |
MD IE Plugin
Adware |
 |
wmplayer.exe |
Media Player
Added by the AGOBOT-BM WORM! |
 |
wowdache.exe |
Meeting Connection
Added by the PPDOOR-D TROJAN! |
 |
Wmsngr.exe |
Messenger
Added by a variant of the RBOT WORM! |
 |
winldx32.exe |
Microfot Update
Added by a variant of the RBOT WORM! |
 |
winssx.exe |
Microft Update 32
Added by the RBOT-AQS WORM! |
 |
wdfmrg.exe |
Micromedia Flash Update
Added by a variant of the SDBOT WORM! |
 |
winmx32.EXE |
MICROSFT MX UPDATE SUPPORT
Added by the IRCBOT-FD WORM! |
 |
wilogon32.exe |
Microsof Winlog Host
Added by the RBOT.XC WORM! |
 |
win32.exe |
Microsoft
Added by the DARKMOON TROJAN! |
 |
wuauclt.exe |
Microsoft
Added by the QQROB-AQ TROJAN! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup! |
 |
wcsntfy.exe |
Microsoft
Added by the AGOBOT-AHT WORM! |
 |
windl32.exe |
Microsoft
Added by the SDBOT-DCZ WORM! |
 |
WinSecUp.exe |
Microsoft
Added by the RBOT-GPL WORM! |
 |
wsim32.exe |
Microsoft
Added by the RBOT-GTL WORM! |
 |
wplayer.exe |
Microsoft
Detected by Kaspersky as the RBOT.DYU TROJAN! See here |
 |
winampaa.exe |
Microsoft
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
winline.exe |
Microsoft
Detected by Kaspersky as the AGENT.KT TROJAN! See here |
 |
wplayer.exe |
Microsoft
Detected by Kaspersky as the RBOT.GHZ BACKDOOR! See here |
 |
wuauclt.exe |
Microsoft (R) Windows Update Service
Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup! |
 |
wuapdate16.exe |
Microsoft 16Bit Update
Added by the RBOT.CZ WORM! |
 |
wupdt64.exe |
Microsoft 64 Bit Runtime Updater
Added by a variant of the RBOT WORM! |
 |
winupdate.exe |
Microsoft auto update
Added by the BMBOT TROJAN! |
 |
WINHLP16.EXE |
Microsoft Auto Update
Added by the RBOT.GY WORM! |
 |
wuauclt.exe |
Microsoft auto update
Added by the CULT-B TROJAN! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup! |
 |
wincmd.exe |
Microsoft Command Line
Added by a variant of the RBOT WORM! |
 |
wurmgrd32.exe |
Microsoft ConfgKeys
Added by the RBOT-ARX WORM! |
 |
windowz.exe |
Microsoft Corp SSL Certificates
Added by the RBOT-GCZ WORM! |
 |
wupdates.exe |
Microsoft Corp Updates
Added by the RBOT-AUU WORM! |
 |
webcp.exe |
Microsoft CP Web Manager
Added by the IRCBOT.HP TROJAN! |
 |
wincrs.exe |
Microsoft Crs Fix Serv
Added by the SDBOT.BWF WORM! |
 |
wupades.exe |
Microsoft DDE Control
Added by a variant of the SDBOT WORM! |
 |
wuamgrd.exe |
Microsoft DirectX
Added by the SDBOT.MY WORM! |
 |
wkssr.exe |
Microsoft dll Host Service
Added by a variant of the SDBOT WORM! |
 |
winlib32.exe |
Microsoft DLL Library
Added by the ATNAS.A WORM! |
 |
windll.exe |
Microsoft Dll Management
Added by the RBOT-MT WORM! |
 |
winavguard.exe |
Microsoft DLL Verifier
Added by the SDBOT.AAD WORM! |
 |
windrv.exe |
Microsoft Driver Control
Added by the SDBOT.FW WORM! |
 |
WSconf.exe |
Microsoft Drivers
Added by a variant of the SDBOT WORM! |
 |
wserb32.exe |
Microsoft ErgoPack
Added by the RBOT-RI WORM! |
 |
wuamngr32.exe |
Microsoft Excell
Added by the RBOT-QH WORM! |
 |
wmgrdf.exe |
Microsoft File Demand Manager
Added by a variant of the RBOT WORM! |
 |
wnpzjpuw.exe |
Microsoft FixUp
Added by a variant of the SDBOT WORM! |
 |
wupdate.exe |
Microsoft Generic Update Manager
Added by the RBOT-AWC TROJAN! |
 |
WINHOSTING.EXE |
Microsoft Hosting Service
Added by the RBOT.AEV WORM! |
 |
windows32.exe |
Microsoft Internet
Added by the SDBOT-F WORM! |
 |
wincfg16.exe |
Microsoft Internet
Added by a variant of the SDBOT WORM! |
 |
wcumrg.exe |
Microsoft Intrenet Explorer
Added by the SDBOT-AFD WORM! |
 |
win64.exe |
Microsoft IT Update
Added by the RBOT.GA WORM! |
 |
winn43.exe |
Microsoft IT Update
Added by a variant of the RBOT WORM! |
 |
win43.exe |
Microsoft IT Update
Added by the RBOT-SA WORM! |
 |
windows.exe |
Microsoft IT Update
Added by the RBOT-GL WORM! |
 |
winsyst32.exe |
Microsoft IT Update
Added by the RBOT-FC WORM! |
 |
winscr32.exe |
Microsoft Java Virtual Machine
Added by a variant of the WOOTBOT WORM! |
 |
Windows_kernel32.exe |
Microsoft Kernel
Added by the NETSKY.AE WORM! |
 |
winlogin.exe |
Microsoft Login
Added by the RBOT-AJP WORM! |
 |
wintcp32.exe |
Microsoft Lsass Service
Added by a variant of the IRCBOT TROJAN! |
 |
winjava.exe |
Microsoft Machine
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
winmplayers.exe |
Microsoft media
Added by a variant of the SPYBOT WORM! |
 |
winmplayer.exe |
Microsoft media services
Added by the RBOT.ZO WORM! |
 |
winmes.exe |
Microsoft MediaScope
Added by the RBOT-XU WORM! |
 |
wdgmr32.exe |
Microsoft MicroP Protocol
Added by a variant of the RBOT WORM! |
 |
winexec32.exe |
Microsoft NT Update
Added by a variant of the RBOT WORM! |
 |
winupdates.exe |
Microsoft Office Start
Added by the GAOBOT.BC WORM! |
 |
windr128.exe |
Microsoft Problem Doctor
Added by the SMALLTRO.EF TROJAN! |
 |
windr32.exe |
Microsoft Problem Doctor
Added by a variant of the SMALLTRO.EF TROJAN! |
 |
windr64.exe |
Microsoft Problem Doctor
Added by a variant of the SMALLTRO.EF TROJAN! |
 |
windos.exe |
Microsoft Rundll
Added by the SDBOT-WF WORM! |
 |
winService.exe |
Microsoft Security
Added by a variant of the RBOT WORM! |
 |
wcsntfy.exe |
Microsoft Security Center
Added by the SDBOT.BYD WORM! |
 |
winnt.exe |
Microsoft Security Management
Added by the RBOT-MQ WORM! |
 |
winserv.exe |
Microsoft Security Management
Added by the RBOT-MJ WORM! |
 |
winamp.exe |
Microsoft Security Management
Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of the Program Files directory |
 |
wuauct1.exe |
Microsoft Security Management
Added by a variant of the RBOT WORM! |
 |
winamp.exe |
Microsoft Security Manager
Added by the RBOT WORM! Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of the Program Files directory. This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
windowsupdate.exe |
Microsoft Security Monitor Process
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
windowsupdate.exe |
Microsoft Security Monitor Process
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
wininit.exe |
Microsoft Security Process
Added by the RBOT-FKM WORM! |
 |
wuauct1.exe |
Microsoft Server Applacations
Added by a variant of the RBOT WORM! |
 |
winsvc.exe |
Microsoft Service
Added by the SPYBOT-DB WORM! |
 |
winlogin.exe |
Microsoft Service Login Manager
Added by a variant of the IRCBOT TROJAN! |
 |
winsvc.exe |
Microsoft Service Manager
Added by a variant of the RBOT WORM! See here |
 |
WindowsSP.exe |
Microsoft Service Pack
Added by the RBOT-RF WORM! |
 |
winsound.exe |
Microsoft Sound Technology
Added by the RBOT-AGG WORM! |
 |
win32.exe |
Microsoft SpA Service
Added by the RBOT.ATS WORM! |
 |
Winupd32.exe |
Microsoft SpA Service
Added by the RBOT.LT WORM! |
 |
win32lib.exe |
Microsoft Standard Executions Library
Added by the RBOT-AUK WORM! |
 |
winsocks5.exe |
Microsoft standard protector
Added by the SMALL.CF TROJAN! |
 |
wmpIayer.exe |
Microsoft startup
Added by the IRCBOT.ACI TROJAN! |
 |
winslogin.exe |
Microsoft Stuff you know
Added by a variant of the SDBOT WORM! |
 |
winoem.exe |
Microsoft Svchost local services
Added by the RBOT-FPE WORM! |
 |
WinLoginnn.exe |
Microsoft Synchronization Manager
Added by the SPYBOT.FO WORM! |
 |
winupdate.exe |
Microsoft Synchronization Manager
Added by the SDBOT.ER WORM! |
 |
win.exe |
Microsoft Synchronization Manager
Added by the SDBOT.AK WORM! |
 |
winlogon32.exe |
Microsoft Synchronization Manager
Added by the SDBOT.AEU WORM! |
 |
wincfg32.exe |
Microsoft Synchronization Manager
Added by the SDBOT.DO WORM! |
 |
wmedia.exe |
Microsoft Synchronization Manager
Added by the SDBOT.BFC WORM! |
 |
win932.exe |
Microsoft Synchronization Manager
Added by the SDBOT.AH WORM! |
 |
Wnetlib.exe |
Microsoft System Checkup
Added by the DONK.C WORM! |
 |
wnetmgr.exe |
Microsoft System Checkup
Added by the DONK.Q WORM! |
 |
windir32.exe |
Microsoft System DLL Services Configuration
Added by the SDBOT-ACY TROJAN! |
 |
winIogon2.exe |
Microsoft System Service
Added by a variant of the IRCBOT TROJAN! |
 |
wintcp32.exe |
Microsoft TCP Protocol
Added by a variant of the IRCBOT TROJAN! |
 |
winupn.exe |
Microsoft Telecoms Center
Added by a variant of the SDBOT WORM! |
 |
wuamkopxp.exe |
Microsoft U
Added by the RBOT-AHC WORM! |
 |
winrarx.exe |
MICROSOFT UNPACK SYSTEM
Added by a variant of the RBOT WORM! |
 |
winsys32.exe |
Microsoft Update
Added by a variant of the RBOT WORM! |
 |
wuamgrd.exe |
Microsoft Update
Added by the RBOT-LK WORM! |
 |
wuammgr32.exe |
Microsoft Update
Added by the RBOT-AW WORM! |
 |
wudmate.exe |
Microsoft Update
Added by the RBOT.AP WORM! |
 |
wuamgrd32.exe |
Microsoft Update
Added by the RBOT.ZB WORM! |
 |
webm.exe |
Microsoft Update
Added by the SDBOT.WK WORM! |
 |
wuagrd.exe |
Microsoft Update
Added by the RBOT-FK WORM! |
 |
wauguard.exe |
Microsoft Update
Added by the RBOT.AEE WORM! |
 |
winscv.exe |
Microsoft Update
Added by the RBOT-BH WORM! |
 |
winsys.exe |
Microsoft Update
Added by the RBOT-GV WORM! |
 |
wserv32.exe |
Microsoft Update
Added by the RBOT.AF WORM! |
 |
wtm32.exe |
Microsoft Update
Added by the RBOT-AQ WORM! |
 |
wumgrd.exe |
Microsoft Update
Added by the SDBOT-KY WORM! |
 |
wuampd.exe |
Microsoft Update
Added by the RBOT-UT WORM! |
 |
windows24.exe |
Microsoft Update
Added by a variant of the RBOT WORM! |
 |
wingrd32.exe |
Microsoft Update
Added by the RBOT-DW WORM! |
 |
wssvr.exe |
Microsoft Update
Added by the RBOT-OD WORM! |
 |
wuamagr32.exe |
Microsoft Update
Added by the SPYBOT.CG WORM! |
 |
WinUpdate32.exe |
Microsoft Update
Added by the RBOT-TI WORM! |
 |
wkfix.exe |
Microsoft Update
Added by the RBOT-ABZ WORM! |
 |
winamp.exe |
Microsoft Update
Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player |
 |
win-mang.exe |
Microsoft Update
Added by the RBOT-AFK WORM! |
 |
winupdater.exe |
Microsoft Update
Added by the RBOT.BIN WORM! |
 |
wuamk0032.exe |
Microsoft Update
Added by a variant of the RBOT WORM! |
 |
wuamk032.exe |
Microsoft Update
Added by the RBOT-AHD WORM! |
 |
wuamk0p32.exe |
Microsoft Update
Added by a variant of the RBOT WORM! |
 |
wuamkop.exe |
Microsoft Update
Added by the RBOT-AFI WORM! |
 |
wuamkop32.exe |
Microsoft Update
Added by the RBOT.BGU WORM! |
 |
wuampkd.exe |
Microsoft Update
Added by the SDBOT.BBX WORM! |
 |
win32.exe |
Microsoft Update
Added by a variant of the SDBOT WORM! |
 |
wininit.exe |
Microsoft Update
Added by the RBOT-AKR WORM! |
 |
wuamgrd3.exe |
Microsoft Update
Added by the RBOT-AMC WORM! |
 |
Wudates.exe |
Microsoft Update
Added by a variant of the RBOT WORM! |
 |
wuagmsd.exe |
Microsoft Update
Added by the RBOT-AX WORM! |
 |
wuamgrb.exe |
Microsoft Update
Added by the RBOT-AZE WORM! |
 |
WINDOC.EXE |
Microsoft Update
Added by the SDBOT.PF WORM! |
 |
WinDrv32.exe |
Microsoft Update
Added by the RBOT.EGW WORM! |
 |
winupdate.exe |
Microsoft update
Added by a variant of the RBOT WORM! |
 |
wangard.exe |
Microsoft Update
Added by the RBOT-LH WORM! |
 |
wuamgrdx.exe |
Microsoft Update
Added by a variant of the SPYBOT WORM! See here |
 |
wutr.exe |
Microsoft Update
Added by the SPYBOT.AAR WORM! |
 |
wininit.exe |
Microsoft Update 32
Added by the RBOT-ANY WORM! |
 |
wininit32.exe |
Microsoft Update 32
Added by a variant of the RBOT WORM! |
 |
winitXP32.exe |
Microsoft Update 32
Added by a variant of the RBOT WORM! |
 |
wiit.exe |
Microsoft Update 32
Added by the RBOT-AMS WORM! |
 |
winin.exe |
Microsoft Update 32
Added by the RBOT-ARR WORM! |
 |
wuinit.exe |
Microsoft Update 32
Added by the AGOBOT-UE WORM! |
 |
wininit32.exe |
Microsoft Update 64 BIT
Added by the RBOT-AHE WORM! |
 |
winman32.exe |
Microsoft Update 64 BIT
Added by the RBOT-AKI WORM! |
 |
winl32xe.exe |
Microsoft Update 64 BIT
Added by the RBOT-AQO WORM! |
 |
WIN32SNC.EXE |
MICROSOFT UPDATE CONFIGURATION
Added by the RBOT-AI WORM! |
 |
wincfg32.exe |
Microsoft Update Debugger
Added by the SPYBOT.ZC WORM! |
 |
wuauclt.exe |
Microsoft Update Device Drivers
Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup! |
 |
winusers.exe |
Microsoft Update Loaders 2005
Added by the RBOT-AIQ WORM! |
 |
winusersystem32.exe |
Microsoft Update Loaders 2006
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
winini.exe |
Microsoft Update Machine
Added by the RBOT-KV WORM! |
 |
wuawx.exe |
Microsoft Update Machine
Added by the RBOT-CE WORM! |
 |
winupdt.exe |
Microsoft Update Machine
Added by the RBOT-FP WORM! |
 |
wuamgd.exe |
Microsoft Update Machine
Added by the SDBOT.HQ WORM! |
 |
wupdt32x.exe |
Microsoft Update Machine
Added by a variant of the SDBOT WORM! |
 |
windowsu.exe |
Microsoft Update Machine
Added by a variant of the RBOT WORM! |
 |
wininigo.exe |
Microsoft Update Machine
Added by a variant of the RBOT WORM! |
 |
winmgr.exe |
Microsoft Update Machine
Added by a variant of the RBOT WORM! |
 |
Winmsixp32.exe |
Microsoft Update Machine
Added by the RBOT.DN WORM! |
 |
Winregs32.exe |
Microsoft Update Machine
Added by the RBOT.DN WORM! |
 |
winxpini.exe |
Microsoft Update Machine
Added by the RBOT-OB WORM! |
 |
wuamgrd.exe |
Microsoft Update Machine
Added by the RBOT-HE WORM! |
 |
wuagrd.exe |
Microsoft Update Machine
Added by the RBOT-GF WORM! |
 |
winhost.exe |
Microsoft Update Machine
Added by the RBOT-GK WORM! |
 |
winss.exe |
Microsoft Update Machine
Added by the RBOT.JU WORM! |
 |
WUAMGRDXS.EXE |
Microsoft Update Machine
Added by the RBOT-GL WORM! |
 |
windowsup.exe |
Microsoft Update Machine
Added by the RBOT-FV WORM! |
 |
wuamgard.exe |
Microsoft Update Machine
Added by the SPYBOT.CS WORM! |
 |
wupdate32.exe |
Microsoft Update Machine
Added by a variant of the RBOT WORM! |
 |
winnie.exe |
Microsoft Update Machine
Added by the RBOT-ACD WORM! |
 |
winortho.exe |
Microsoft Update Machine
Added by the RBOT-NW WORM! |
 |
wins32.exe |
Microsoft Update Machine
Added by the RBOT.EZ WORM! |
 |
wftestb.exe |
Microsoft Update Machine
Added by the RBOT-AFZ WORM! |
 |
Win32.exe |
Microsoft Update Machine
Added by the SDBOT.UV WORM! |
 |
windns.exe |
Microsoft Update Machine
Added by the RBOT.EF WORM! |
 |
WINSVC32.EXE |
Microsoft Update Machine
Added by the RBOT.CU WORM! |
 |
winupdte.exe |
Microsoft Update Machine
Added by the RBOT-GKL WORM! |
 |
wlimyc.exe |
Microsoft Update Machine
Added by the RBOT-GQN WORM! |
 |
WINRLS.EXE |
Microsoft Update Manager
Added by the RBOT-AF WORM! |
 |
wmipcvse.exe |
Microsoft Update Process
Added by the AGOBOT-JF TROJAN! |
 |
wcsnfty.exe |
Microsoft Update Services
Added by the RBOT-AGK WORM! |
 |
wsnfty.exe |
Microsoft Update Services
Added by the RBOT-AFU WORM! |
 |
wuam.exe |
Microsoft Update Time
Added by the RBOT-M WORM! |
 |
wuammgrd32.exe |
Microsoft Update USB2
Added by the RBOT-ADT WORM! |
 |
winupdate32a.exe |
Microsoft Update Win32a
Added by the RBOT-LO WORM! |
 |
winupdate32x.exe |
Microsoft Update Win32x
Added by the RBOT-AJN WORM! |
 |
Winsys32.exe |
Microsoft Updater
Added by a variant of the RBOT WORM! |
 |
wuamgrds.exe |
Microsoft Updater
Added by the RBOT.A WORM! |
 |
WinFixd32.exe |
Microsoft Updater Resources
Added by the SPYBOT.CA WORM! |
 |
WINDLL32XP.EXE |
Microsoft Updaters Pros
Added by the SPYBOTTER.GEN VIRUS! |
 |
wkssvr.exe |
Microsoft Updates
Added by the RBOT.R WORM! |
 |
wkssvrs.exe |
Microsoft Updates
Added by the RBOT-EB WORM! |
 |
wuamgrd.exe |
Microsoft Updates
Added by the RBOT-CO WORM! |
 |
wtemp32.exe |
Microsoft Updates
Added by the RBOT-AHQ WORM! |
 |
wgafixer.exe |
Microsoft Updates 2 USB
Added by a variant of the RBOT WORM! |
 |
WinFixIDs.exe |
Microsoft Updates Resources
Added by a variant of the RBOT WORM! |
 |
wuamguards.exe |
Microsoft Updating
Added by the RBOT-BY WORM! |
 |
websvc.exe |
Microsoft Updating Client
Added by the RBOT.AQ WORM! |
 |
winlogon.exe |
Microsoft Visual SourceSafe
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
webcp32.exe |
Microsoft Web CP Manager
Added by a variant of the SDBOT WORM! See here |
 |
wdevice.exe |
Microsoft Web Device
Added by a variant of the SDBOT WORM! |
 |
webmsn.exe |
Microsoft web update
Added by the RBOT-EMQ WORM! |
 |
winsupdater.exe |
MicroSoft Wind0ws Updater
Added by a variant of the RBOT WORM! |
 |
Winupdsdgm.exe |
Microsoft Windows 2000
Added by the GAOBOT.AO WORM! |
 |
win32update.exe |
Microsoft Windows 32 Update
Added by a variant of the IRCBOT TROJAN! |
 |
wincomm.exe |
Microsoft Windows Communicator for NT/XP
Added by the RBOT.ATH WORM! |
 |
win32conf.exe |
Microsoft Windows Config 32
Added by a variant of the RBOT WORM! |
 |
windir32.exe |
Microsoft Windows DLL Services Configuration
Added by the SDBOT.BHF WORM! |
 |
windir32a.exe |
Microsoft Windows DLL Services Configuration
Added by a variant of the SDBOT.BHF WORM! |
 |
windll32.exe |
Microsoft Windows DLL Services Configuration
Added by the SDBOT.BHD WORM! |
 |
winDSL.exe |
Microsoft Windows DLL Services Configuration
Added by the SDBOT-ZG WORM! |
 |
windrv.exe |
Microsoft Windows Drivers
Added by a variant of the SDBOT WORM! |
 |
windvr.exe |
Microsoft Windows DVR
Added by the RBOT-AXD WORM! |
 |
websploit.exe |
Microsoft Windows Express
Added by a variant of the SPYBOT WORM! See here |
 |
windowslogonb.exe |
Microsoft Windows Express
Detected by PCTools as the SDBOT.ABOO WORM! See here |
 |
Windowz.exe |
Microsoft Windows GUI
Added by the RANDEX.AEV WORM! |
 |
winkrnl386.exe |
Microsoft Windows Kernel Services
Added by the ZEBROXY TROJAN! |
 |
wloader.exe |
Microsoft Windows Loader
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
winlogon.exe |
Microsoft Windows Logon Process
Added by the PROXYSER-R TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This worm file is placed in the Winnt or Windows folder |
 |
wimp.exe |
Microsoft Windows Media Player
Added by the RBOT-FN WORM! |
 |
wregistry.exe |
Microsoft Windows Registry Service
Added by the AGOBOT.AKG WORM! |
 |
windocs.exe |
Microsoft Windows Secure
Added by a variant of the SDBOT WORM! |
 |
windocs.exe |
Microsoft Windows Secure
Added by a variant of the SDBOT WORM! |
 |
wurguar.exe |
Microsoft Windows Securety
Added by the RBOT-KY WORM! |
 |
wscndrives.exe |
Microsoft Windows Security
Added by the RBOT-AJK WORM! |
 |
winsys.exe |
Microsoft Windows Service
Added by the RBOT-ADP WORM! |
 |
winspkn.exe |
Microsoft Windows Service Pack
Added by the RBOT-AYD WORM! |
 |
winsockx32.exe |
Microsoft Windows Socketx32 Services
Added by the RBOT-FWT WORM! |
 |
winms.exe |
Microsoft Windows Storage Machine Service
Added by the RBOT-AHK WORM! |
 |
winsvc.exe |
Microsoft Windows System Service Manager
Added by the SPYBOT.LR WORM! |
 |
windows.exe |
Microsoft Windows Updata
Added by a variant of the RBOT WORM! |
 |
windowsupdate.exe |
Microsoft Windows Update
Added by the AGOBOT.ON WORM! |
 |
wuap.exe |
Microsoft Windows Update Application
Added by a variant of the RBOT WORM! |
 |
win-logon.exe |
Microsoft Windows Update Logon
Added by a variant of the RBOT WORM! |
 |
wupdmgr32.exe |
Microsoft Windows Update Service
Added by the DOS.AUTOCAT TROJAN! |
 |
winupdgm.exe |
Microsoft Windows Updater
Added by the GAOBOT.BI WORM! |
 |
WINIUPDATES.EXE |
Microsoft Windows Updater
Added by the RBOT-KK WORM! |
 |
WINUPDATE.EXE |
Microsoft Windows Updater
Added by the SDBOT-PU WORM! |
 |
win32upd.exe |
Microsoft Windows Updater
Added by the RBOT-EC WORM! |
 |
windates.exe |
Microsoft Windows Updater
Added by the SDBOT.TE WORM! |
 |
wsap32.exe |
Microsoft Windows Updates
Added by a variant of the SDBOT WORM! |
 |
winsass.exe |
Microsoft Windows WinSaSS Management
Added by the RBOT-APW WORM! |
 |
winexplorer.exe |
Microsoft Windows XP/2K Explorer
Added by a variant of the IRCBOT TROJAN! See here |
 |
WinKey.exe |
Microsoft Winedows startup
Added by a variant of the SDBOT WORM! See here |
 |
WinSGR32.exe |
Microsoft WINGS32 Protocol
Added by the RBOT-APU WORM! |
 |
winrar.exe |
Microsoft WinRaR
Added by the RBOT-AEC WORM! |
 |
ws2_32s.exe |
Microsoft Winsock Wrapper
Added by a variant of the SPYBOT WORM! |
 |
Winamp61.exe |
Microsoft WinUpdate
Added by a variant of the RBOT WORM! |
 |
Winupd32.exe |
Microsoft WinUpdate
Added by the RBOT.MQ WORM! |
 |
WinNTinit32.exe |
Microsoft WinUpdate
Added by the RBOT.VS WORM! |
 |
wkcalrem.exe |
Microsoft Works Calendar Reminders
Produces a pop-up reminder of events scheduled using the MS Works Calendar |
 |
WksSb.exe |
Microsoft Works Portfolio
The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program.Can be prevented from starting from a setting within Portfolio |
 |
wkdetect.exe |
Microsoft Works Update Detection
Checks for updates to MS Works |
 |
winworld.exe |
Microsoft World Service
Added by an unidentified IRC worm with backdoor capability! |
 |
wuamkoppnp.exe |
Microsoft X Update
Added by the RBOT-ANI WORM! |
 |
winsystem32xp.exe |
Microsoft Xp Systems loader
Added by the KELVIR.W WORM! |
 |
win32xpsys.exe |
Microsoft Xp Systems loaders
Added by the SPYBOT.NYT WORM! |
 |
wngard.exe |
Microsoft-Update
Added by the RBOT-JV WORM! |
 |
win32sys.exe |
Microsoft32
Added by an unidentified WORM or TROJAN! |
 |
wees.exe |
Microsoftf DDEs Control
Added by a variant of the RBOT WORM! |
 |
why-.exe |
Microsoftf DDEs Control
Added by the RBOT-AMV WORM! |
 |
w33s.exe |
Microsoftf DDEs Control
Added by a variant of the RBOT WORM! |
 |
waes.exe |
Microsoftf DDEs Control
Added by a variant of the RBOT WORM! |
 |
winmplayd.exe |
Microsofts media
Added by an undidentified WORM or TROJAN! |
 |
wingtp.exe |
Microsofts media
Added by the RBOT-VO WORM! |
 |
winmep.exe |
Microsofts MediaScope
Added by the RBOT-WB WORM! |
 |
winmedplay.exe |
Microsofts MediaScope
Added by a variant of the RBOT WORM! |
 |
Wintsk32.exe |
MicrosoftServiceManager
Added by the YAHA.U WORM! |
 |
WinUp32.exe |
MicrosoftUpdate
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
windll.exe |
MicrosoftUpdate
Added by the RBOT-IH WORM! |
 |
windrive.exe |
Micrsoft Driver
Added by the SDBOT.AF TROJAN! |
 |
wcnsfty.exe |
Micsorosft Security Center
Added by the RBOT-AHU WORM! |
 |
wimsqaad.exe |
Miosf Update
Added by the SDBOT.AG TROJAN! |
 |
wuampkd.exe |
Mircosoft Update
Added by a variant of the SDBOT WORM! |
 |
win32x.exe |
Mismo
Added by the RBOT-JP WORM! |
 |
WAed.pif |
Mlcr0s0ftf DDEs C0ntr0i
Added by the RBOT-BJW WORM! |
 |
winmgmt.exe |
MMCWINMGMT
Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here |
 |
webcomp.exe |
Mobipocket Web Companion
Related to Mobipocket eBook Reader |
 |
wuaclt.exe |
Modifiet Amateur HTPB
Detected by Trend Micro as the IRCBOT.AYS WORM! See here |
 |
Wupated.exe |
Ms Builders
Added by the AGOBOT-SS WORM! |
 |
wrapper.exe |
MS Java Service Wrapper for Windows NT & XP
Added by the VANEBOT-D WORM! |
 |
winPE.exe |
ms ownage
Added by the RBOT-AJL WORM! |
 |
wpad.exe |
MS PLUS INC
Added by the MYTOB-AN WORM! |
 |
winscv.exe |
MS Service Drivers
Added by the SDBOT-COG WORM! |
 |
winser.exe |
Ms sock for Windows NT
Added by a variant of the SDBOT WORM! |
 |
win32ttb.exe |
MS Unix Binary
Added by the SPYBOT.OQ WORM! |
 |
Win32Update.exe |
MS Unix Binary
Added by the RBOT-BAS WORM! |
 |
WinGuard.exe |
MS Unix Binary
Added by the RBOT-ACL WORM! |
 |
winservnt32.exe |
Ms Update WinServices NT/XP
Added by the VANEBOT-G WORM! |
 |
windriver.exe |
MS Win32 Network Services
Added by the AGOBOT.ADH WORM! |
 |
web.exe |
MS-Connect
Adult content dialler - see here |
 |
winlog.exe |
msconfig
Added by the IRCBOT-TJ TROJAN! |
 |
winnsyst.exe |
MSControl31
Added by the RBOT.CFY WORM! |
 |
winmp.exe |
MSIdll
Added by a variant of the RBOT WORM! |
 |
winlogon.exe |
MSMSGS
Added by the RAHIWI.A WORM! |
 |
wdlrss.exe |
MSN
Added by a variant of the SDBOT TROJAN! |
 |
wkssvr.exe |
MSN
Added by the PUSHBOT.S WORM! |
 |
wkssvrs.exe |
MSN
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
wksvr.exe |
MSN
Added by the IRCBOT-XU WORM! |
 |
wmev.exe |
MSN
Added by a variant of the SPYBOT WORM! See here |
 |
winntmsn.exe |
MSN Messanger Live
Added by the RBOT-FSO WORM! |
 |
windns.exe |
Msn Messeng
Added by a variant of the RBOT WORM! |
 |
winproc.exe |
MSN Service Updates
Added by the KELVIR-BB WORM! |
 |
windatemanager.exe |
Msn Updater
Added by the SDBOT.TS WORM! |
 |
winagent.exe |
MsnExplorer
Added by the EQ TROJAN! |
 |
winampb.exe |
msnnt
Chinese originated adware - detected by Kaspersky as the AGENT.TL TROJAN! |
 |
winampf.exe |
msnnt
Added by the SMALL.DTS TROJAN! |
 |
winss.exe |
MSOleath32
Added by the KATHER TROJAN! |
 |
wiaadmgr.exe |
MSPP System Update 64
Detected by Kaspersky as the RANKY.GEN TROJAN! |
 |
winupdate.exe |
mssonfig
Added by a variant of the SDBOT WORM! |
 |
WINUPD.EXE |
MSStartOptimizer
Added by the DASMIN-E TROJAN! |
 |
wstask32.exe |
MsTask
Added by the MYTOB-FE WORM! |
 |
wupd.exe |
MSUpdate
Added by the ALADINZ.M TROJAN! |
 |
wsdrt32.exe |
MsWindows DRT Drivers
Added by the RBOT.ALT WORM! |
 |
winlogon.exe |
MSWinlogon
Added by the AGENT-FZM TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
winupd.exe |
MSWinupd
Added by the DLOADER-YE or DLOADR-AAA or DLOADER-ZF TROJANS - and others |
 |
winupdate.exe |
MSWinupdate
Added by the DLOADR-AAW TROJAN! |
 |
wdfmgr.exe |
MS_Update Check
Added by the AGOBOT-TB WORM! |
 |
wjview ...MyPointsPointAlertrun.exe |
MyPointsPointAlert
"With MyPoints you can earn rewards from name-brand merchants. You can even earn vacations and frequent flyer miles". Dubious privacy policy |
 |
winexplor.exe |
mysoft
Browser hijacker, also detected as the STARTPA-JR TROJAN! |
 |
winsnav.vbs |
NAV Agent
Added by the ANPES WORM! |
 |
wmilib32.exe |
NAV Agent
Added by the VB-XU TROJAN! |
 |
WINDBKGND.EXE |
NB Windows Patterns
Part of McAfee Nuts & Bolts. With Background Patterns, you can change background patterns of wizard and dialog windows |
 |
winntsrv -l -p10001 -d -e cmd.exe -L |
NC1565
Added by the NEWLEY-A WORM! |
 |
windows.exe |
NDIS Adapter
Added by the FORBOT-BR WORM! |
 |
Winman.exe |
NDIS Adapter
Added by the WOOTBOT.AG WORM! |
 |
winlogin.exe |
NDplDeamon
Added by the RANDEX.E WORM! |
 |
wmp9.exe |
Nero Updater.6.12
Added by the AGOBOT-AAG WORM! |
 |
winjava.exe |
NeroUpdater6.8
Added by the AGOBOT.AMK WORM! |
 |
WINREG.EXE |
Net
Added by the ASSASIN.D TROJAN! |
 |
winserv.exe |
NetApp
Added by the SHADOWTHIEF TROJAN! |
 |
wlan111t.exe |
NETGEAR WG111T Smart Wizard
Configuration utility for the Netgear WG111T multi-rate Wireless USB 2.0 Adapter that "provides wireless access to your desktop or notebook PC through the computer's USB port" |
 |
winclient.exe |
NetPatrol
NetPatrol network monitoring software |
 |
WgwMngr.exe |
NettGain2000
Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so |
 |
wunit32.exe |
Netunit32
Added by an unidentified WORM or TROJAN! |
 |
winssh.exe |
Network Access
Added by a variant of the SDBOT WORM! |
 |
wuamgrd.exe |
Network Protocol Service
Added by the RBOT.EA WORM! |
 |
wintcp.exe |
Network protocol service
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
WinNPS.exe |
Network Provisioning Service
Added by an unidentified WORM/TROJAN! |
 |
WinAntiVirusPro2006Installer.exe |
NI.UWA6P_0001_N56M1001
WinAntiVirus Pro 2006 misleading virus software - not recommended, see here |
 |
WinAntiVirusPro2006Installer[1].exe |
NI.UWA6P_0001_N69M0303
WinAntiVirus Pro 2006 misleading virus software - not recommended, see here |
 |
WinAntiVirusPro2006FreeInstall.exe |
NI.UWA6P_0001_N73M1004
WinAntiVirus Pro 2006 misleading virus software - not recommended, see here |
 |
winantiviruspro2006freeinstall[1].exe |
NI.UWA6P_0001_N91M1807
WinAntiVirus Pro 2006 misleading virus software - not recommended, see here |
 |
winantiviruspro2007freeinstall[1].exe |
NI.UWA7P_0001_N91M0809
WinAntiVirus Pro 2007 misleading virus software - not recommended, see here |
 |
wsul.exe |
Norton Service Driver
Added by the RBOT-ABI WORM! |
 |
winsvc.exe |
Norton Update
Added by the AGOBOT.ALP WORM! |
 |
winset.exe |
Norton Updater
Added by a variant of the SPYBOT WORM! |
 |
wtta.exe |
Notn
PurityScan/Clickspring adware |
 |
WinNTLM.exe |
NT LM Security Support Provider
Added by a variant of the SDBOT WORM! |
 |
wntsf.exe |
NTSF MICROSOFT SYSTEM
Added by the RBOT.ATC WORM! |
 |
winsis32.exe |
NTSF MICROSOFT SYSTEM
Added by a variant of the RBOT WORM! |
 |
winlogon.exe |
nvchost
Added by the KLONE-J TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
windowsp.exe |
NvCpl
Added by a variant of the SDBOT WORM! |
 |
winasp.exe |
NvCplScan
Added by the FORBOT.BZ WORM! |
 |
wuauqmr.exe |
NvCpTDaemon
Added by the CULT-B WORM! |
 |
winoeinit.exe |
OEPowerPlugs
?? |
 |
winxp_sp3.exe |
Offica Monitor Secura Systeme
Added by a variant of the RBOT WORM! |
 |
winutade.exe |
OKGO
Added by the BANKER-EHZ TROJAN! |
 |
winssnotify.exe |
OneCareUI
Related to Windows OneCare Live from Microsoft |
 |
webtogo.exe |
Oracle Web-to-Go
"Oracle Web-to-go, a component of Oracle9i Lite, consists of a collection of modules and services that facilitate development, deployment, and management of mobile Web applications" |
 |
winword.exe |
OSA
Added by the KANGAROO-A TROJAN! |
 |
wcdvtray.exe |
OWCWebCamDV
WebCamDV from Orange Micro, Inc - enables the user to use a DV camera connected via Firewire as a Webcam |
 |
WinGamed.exe |
Patches Value
Added by the SDBOT.BR WORM! |
 |
WinPTTP.exe |
Performs peer to peer connection
Added by the RBOT-GMI WORM! |
 |
W3dbsmgr.exe |
Pervasive.SQL Workgroup Engine
Database Service Manager for Pervasive SQL 2000 Workgroup edition. Required if you use Pervasive SQL but it's recommended you start it manually before using it as it has a tendancy to crash/freeze if loaded with other applications at startup |
 |
wpctrl.exe |
PivotSoftware
PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
 |
winsrvc.exe |
Pmedia
Internet marketing sofware from Permissioned Media Inc as used in E-Card FriendGreetings foistware - see here. Treated by Trend as the FRIENDGRT.B WORM! |
 |
wuaaclt.exe |
PNP
Added by the LILBRE-A WORM! |
 |
WinTask.exe |
PopMark
"Pop Marketing" adware |
 |
webprinter.exe |
Printer Monitor
Added by the IRCBOT-Z TROJAN! |
 |
wqxfne.exe |
Proc993
Added by the IXBOT-D WORM! |
 |
wsript.exe Q152404.VBS |
Q152404
Appears to run Scandisk at bootup on NEC PCs |
 |
Winrar.exe |
quicken
CoolWebSearch Therealsearch parasite variant. Note - this is not the file zipping utility also known as WinRAR! |
 |
Waol.exe |
quicken
CoolWebSearch Therealsearch parasite variant |
 |
winmplyer32.exe |
Quicktime Mediaplayer
Added by the RBOT-PM WORM! |
 |
wnmplyr.exe |
Quicktime Mediaplayr
Added by a variant of the RBOT WORM! |
 |
winuodps.exe |
Quicktime Pro 3.0
Added by the GAOBOT.BH WORM! |
 |
Winrsm.exe |
Real Spy Monitor
Realspy keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
winsy.exe |
Reg Service
Added by a variant of the SPYBOT WORM! |
 |
winslogon.exe |
Reg Service
Added by the AGOBOT-SC WORM! |
 |
WinnConfig.exe |
Reg Service
Added by the AGOBOT-PF WORM! |
 |
Winboot32.exe |
Reg Services
Added by the RBOT.PB WORM! |
 |
winlogon.exe |
RegDone
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
wscript.exe ShakiraPics.jpg.vbs |
Registry
Added by the VBSWG.AQ WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "ShakiraPics.jpg.vbs" file is located in the Winnt or Windows folder |
 |
winreg.exe |
Registry Checkup
Added by an unidentified WORM or TROJAN! |
 |
Winregs326a.exe |
Registry Checkup System326a Monitor
Added by a variant of the SDBOT WORM! |
 |
WCPDT.EXE |
Registry Integritycheck
Added by the AGOBOT-RF WORM! |
 |
winhlpp32.exe |
Registry Loader
Added by the GAOBOT.AO WORM! |
 |
win32.exe |
Registry oidet
Added by the RBOT.BMT WORM! |
 |
winapi32.exe |
Registry Value Name
Added by a variant of the RBOT WORM! |
 |
winbackup.exe |
RegistryChk
Added by the MERTIAN WORM! |
 |
winservice.exe |
Regkey for autostart
Added by the RBOT-NU WORM! |
 |
winfix22490.exe |
REGRUN
Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS! |
 |
winbait.exe |
RegRun WinBait
Part of RegRun - used to detect unknown viruses. RegRun compares winbait.exe with the original copy called winbait.org and warns if the files are different.. |
 |
WatchDog.exe |
Regrun2
Greatis Software's RegRun security suite which amongst other things replaces MSCONFIG. The WatchDog check for registry changes caused by trojan's, viruses, etc |
 |
WinRDH.exe |
Remote Desktop Help Session Manager
Added by a variant of the SDBOT WORM! |
 |
winrpc.exe |
Remote Procedure Call
Added by the RBOT-KM WORM! |
 |
winsysrpc.exe |
Remote Procedure Call
Added by the SDBOT-PS WORM! |
 |
win.exe |
Remote Procedure Calls
Added by the SDBOT-QI WORM! |
 |
windos.exe |
REMOVE ME
Added by the SDBOT.EE WORM! |
 |
Watch.exe |
Restart Watch
Associated with an Eicon Networks Diva ISDN or ADSL modem. What does it do and is it required? |
 |
wscrestp.exe |
Restart WSC Setting
WinStart Commander - part of Ultra WinCleaner Utility Suite. Starts Windows faster and controls hidden programs to boost performance and prevent system slow downs and crashes |
 |
wf32vbs.exe |
RNBc Test
Added by the RBOT-AGR WORM! |
 |
wf32vbc.exe |
RNBz Test
Added by the RBOT-AEY WORM! |
 |
wf32b.exe |
RNDc Test
Added by a variant of the SDBOT WORM! |
 |
winlogon.exe |
ROOT_Machine
Added by the BANKER-FI TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This worm file is placed in the Windowsinf or Winntinf folder |
 |
winlogon.exe |
RPCserr32g
Added by the RITDOOR-B WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder |
 |
WINLOGON.EXE |
RPCserv32g
Added by the BOBAX.AD WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder |
 |
wandrv.exe |
run
Added by the BCKDR-QHR TROJAN! |
 |
wscript MSupdt32.vbs |
Run MSupdt32
Added by the CASER WORM! |
 |
wperl.exe |
Run POPFile in background
POPFile - E-mail spam blocker |
 |
websvc.exe |
Run Services as Application
Added by the DLOADER-NY TROJAN! |
 |
WINClock.exe |
run32dll
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
wallflip.exe |
run=
Desktop wallpaper changer? |
 |
win.ini |
run=
?? |
 |
wswpd.exe |
run=
Used with some models of Panasonic, Epson and NEC printers - required for printer to work |
 |
wmplayer.exe |
run=
CoolWebSearch Smartsearch parasite variant |
 |
Winfi1e32.exe |
Rund1l32
Added by the MERTIAN WORM! |
 |
winupdate.exe |
RunDLL32
Added by an unidentified TROJAN! - possibly a BMBOT variant |
 |
Windows.exe |
Rundll32
Added by the QQPASS.E TROJAN! |
 |
win.exe |
runing
Added by the DELF-LC TROJAN! |
 |
wini.exe |
RunProg
Added by the OPTIX.04.D TROJAN! |
 |
winlogon.exe |
runwinlogon
Detected by Trend Micro as the AGENT.TQY TROJAN! See here. Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
WAS7Mon.exe |
Salestart
WinAntiSpyware spyware remover - not recommended, see here |
 |
winagent.exe |
ScheduIr
Added by a variant of the SDBOT WORM! |
 |
winagent.exe |
Scheduler
Added by the TACTSLAY.B TROJAN! |
 |
wsass.exe |
Scheduler Service
Added by the LIOTEN.KX WORM! |
 |
w32tm.exe |
Secboot
Added by the HAXDOOR.D TROJAN! |
 |
wins32a.exe |
secure socket layer
Added by an IRCBOT TROJAN! |
 |
WindowsSecurityUpdate.exe |
Security
Added by a variant of the SDBOT WORM! |
 |
WinUpdate32.exe |
Security Patch
Added by the SDBOT-BM WORM! |
 |
WinLab32.exe |
Security Patches
Added by the SDBOT-KB WORM! |
 |
wmiprvce.exe |
Security Update Service
Added by the AGOBOT.ZW WORM! |
 |
wssdsu.exe |
Serv-U
Added by the MANIFEST TROJAN! |
 |
wbemstest.exe |
Server Runtime Process
Added by the SDBOT-DDB WORM! |
 |
wN2S.exe |
service
Added by a variant of the RBOT WORM! |
 |
winsvcli.exe |
Service Client
Added by an unidentified WORM or TROJAN! See here |
 |
WinOcx.exe |
Service Monitor
Added by the RBOT-AQJ WORM! |
 |
winset.exe |
Service Process
Added by a variant of the SPYBOT WORM! |
 |
windowsXP.exe |
Service System
Added by the BANCOS-EL TROJAN! |
 |
wernell87.exe |
Service System
Added by the BANCOS-FJ TROJAN! |
 |
winread.exe |
Services
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
windns.exe |
Services
Added by a variant of the RBOT WORM! |
 |
windows32.exe |
services
Added by the FLYVB-C WORM! |
 |
websvc.exe |
Services Administrator
Added by the DLOADER-NY TROJAN! |
 |
win32dll.exe |
Services32 Startup
Added by the SDBOT-XO WORM! |
 |
wsusupd.exe |
ShareSearcher
Added by the ENCLAG-A TROJAN! |
 |
winagent.exe |
SheduIer
Added by the EB TROJAN! |
 |
wmedia16.exe |
Shell
Added by the GOLDUN TROJAN! |
 |
wmedia32.exe |
Shell
Added by the AGENT-BR TROJAN! |
 |
Wifiusb.exe |
Sinus 1054 data WLAN Manager
Wireless management utility for the T-Com Sinus 1054 Data WLAN adapter |
 |
winsos.exe |
sis32
Added by the QQPASS.IA WORM! |
 |
win.bat |
Sistray32
Added by the JUMPRED.A WORM! |
 |
winlogon.scr |
SkynetRevenge
Added by the NETSKY.AA WORM! |
 |
winlogon.exe |
SmansaApp
Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder |
 |
winsrv.exe |
smcserv
Added by the AGOBOT-OU WORM! |
 |
win32st.exe |
SMSERIALSTARTER
Detected by McAfee as the FAKEALERT-AH TROJAN! See here. Installed with the SpyBurner spyware remover - which is not recommended, see here |
 |
winstrse.exe |
SMSERIALWORKERSTARTER
Added by an unidentified WORM or TROJAN! See here. Installed with the SpyBurner spyware remover - which is not recommended, see here |
 |
Win.exe |
smsger
Added by a variant of the SDBOT WORM! |
 |
wininits.exe |
softIce Update 32
Added by the RBOT-ANB WORM! |
 |
WNILOGON.exe |
SonudMan
Added by the QQROB-DC TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
WinSound1.exe |
Sound System
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
Wifiusb.exe |
Speedport W 100 Stick WLAN Manager
Wireless management utility for the Speedport W 100 Stick WLAN USB stick |
 |
Wscript.exe OXNEY.B.VBS |
SPINX
Added by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "OXNEY.B.VBS" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
wys.exe |
Spool
WhileUSurf adware |
 |
websvc.exe |
Spooler SubSystem Application
Added by the DLOADER-NY TROJAN! |
 |
wintre.exe |
spoolsvs
Added by the SDBOT.EGQ WORM! |
 |
wincfy.exe |
spoolsvs
Added by a variant of the IRCBOT BACKDOOR! |
 |
Winllogo.exe |
SpyEx
Added by the PRSKEY-A WORM! |
 |
winproc32.exe |
SpywareGuard
Startpage adware Trojan |
 |
winmm64.exe |
SpywareGuardPlus
StartPage.ht homepage hijacker |
 |
wins32.exe |
sqservices
Added by the PROGENT-B TROJAN! |
 |
win16dll.exe |
srv32win
Screenspy captures screenshots silently. If you didn't install this yourself remove it |
 |
winsys.exe |
ssate.exe
Added by the BEAGLE.K WORM! |
 |
winerdir.exe |
ssgrate.exe
Added by the MITGLIEDER.O TROJAN! |
 |
winsystems.exe |
ssgrate.exe
Added by the BAGLEDL-J TROJAN! |
 |
wintems.exe |
ssgrate.exe
Added by the MITGLIEDER.Q TROJAN! |
 |
winssk32.exe |
SSK Service
Added by the SOBIG.E WORM! |
 |
windows.vbs |
Start
Homepage hijacker |
 |
windupds.exe |
Start Upping
Added by the SDBOT.AFH WORM! |
 |
windupdts.exe |
Start Upping
Added by a variant of the RBOT WORM! |
 |
win32i.exe |
startkey
Added by the BIFROSE-R TROJAN! |
 |
winampXP.exe |
startkey
Added by the BIFROSE-OY TROJAN! |
 |
winlogin.exe |
startkey
Added by the BIFROSE-PM TROJAN! |
 |
WinlogonStartup |
Startup
Unidentified malware |
 |
wztoid.exe |
Startup Configuration
Added by the RBOT-ASD WORM! |
 |
w32main2.exe |
stgclean
Related to IBM Standard Software Installer. What does it do and is it required? |
 |
wkfxi.js |
stmha
Added by the SPETH WORM! |
 |
wuauclt14.exe |
StreamAppliance
Added by the RBOT-GMB WORM! |
 |
wuauclt16.exe |
StreamAppliance
Added by the RBOT-GME WORM! |
 |
winscrne.exe |
STV
Added by a variant of the SDBOT WORM! |
 |
winsfcm.exe |
SurfinGuard Pro
SurfinGuard Pro from Finjan - internet protection software, protects against all malicious code delivered through executables, scripting files, ActiveX and Java |
 |
WINAGENT.EXE |
SvcH0st
Added by the EB TROJAN! |
 |
winhost.exe |
Svchost
Added by the LOLAWEB.A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
 |
winhelp.exe |
svchost
Added by the GAOBOT.GEN!POLY WORM! |
 |
winampXP.exe |
svcshare
Added by the FUJACKS-J VIRUS! |
 |
winwd.exe |
SWd
PC Security from Tropical Software - lock files, password protect, etc |
 |
Win32x.exe |
Sygate Personal Firewall
Added by the RBOT-KZ WORM! |
 |
wins.exe |
Sygate Personal Firewall
Added by the RBOT.AOB WORM! |
 |
winxpstat.exe |
Sygate Personal Firewall
Added by a variant of the RBOT WORM! |
 |
win31243.exe |
Sygate Personal Firewall
Added by a variant of the IRCBOT TROJAN! |
 |
winupdate.exe |
Sygate Personal Port Blocker
Added by a variant of the RBOT WORM! |
 |
windows .exe |
Symantec Antivirus professional
Added by a variant of the FORBOT WORM! |
 |
Winhp32.exe |
Symantec Antivirus professional
Added by a variant of the FORBOT WORM! |
 |
winudp.exe |
Symantec Antivirus professional
Added by a variant of the WOOTBOT WORM! See here |
 |
winsync.exe |
syncman
Added by the MANCSYN-A TROJAN! |
 |
windows32.exe |
Syntax
Added by the SDBOT.CQ WORM! |
 |
wuapdxe.exe |
Sys-Stat
Added by the SDBOT.HK WORM! |
 |
win***32.exe [* = random char] |
Sys29
EliteBar adware |
 |
win***32.exe [* = random char] |
SysA
EliteBar adware |
 |
win.hta |
Syscheck
Browser hijacker |
 |
wincfg32.exe |
SysConfig
Added by the SDBOT.ZD WORM! |
 |
winupdate.exe |
Sysctrls
Added by an unidentified WORM or TROJAN! |
 |
win32dll.exe |
Sysctrls
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
winrun.exe |
sysdir
Added by the WINBUR.B WORM! |
 |
wininit32.exe |
SysInit
Added by the XABOT WORM! |
 |
wowexece.exe |
SysMon
Added by the MULAN-A TROJAN! |
 |
WWE DIVAS.exe |
SysRes
Added by the ELIPTER.D WORM! |
 |
WINL0G0N.EXE |
System
Added by the BANCOS-DB TROJAN! |
 |
wumgrd32.exe |
System
Added by a variant of the RBOT WORM! |
 |
windowsps.exe |
System
Added by a variant of the RBOT WORM! |
 |
wiinlogon.exe |
SYSTEM
Added by the RBOT-AVG WORM! |
 |
winupd.exe |
System
Added by a variant of the SDBOT WORM! |
 |
wsscntfy.exe |
System
Added by a variant of the SDBOT WORM! |
 |
windmupdr.exe |
SYSTEM
Added by a variant of the RBOT WORM! |
 |
win_klr32.exe |
System Check
Added by the DELF-DRA WORM! |
 |
wasul.exe |
System Checking
Added by the RBOT.BHM WORM! |
 |
wins.exe |
System Document Application
Added by the SDBOT.AUB WORM! |
 |
wingmt.exe |
System Drivers
Added by the SDBOT-MG WORM! |
 |
win.exe |
System Information Manager
Added by the SDBOT-MU WORM! |
 |
windowsNt.com |
System Information Manager
Added by the SDBOT-ND WORM! |
 |
winsrv32.exe |
System Manager
Added by an unidentified WORM or TROJAN! |
 |
winsvc.exe |
System Manager Updates
Added by the AGOBOT.AEM WORM! |
 |
wmisg.exe |
SYSTEM MESSAGER
Added by the MYTOB.ES WORM! |
 |
wupdmgr.exe |
System Update
Added by the SOROMO-A TROJAN! |
 |
wauluclt.exe |
System Update
Added by the SDBOT.EF WORM! |
 |
wmiprvsa.exe |
System Update Service
Added by the AGOBOT-RG TROJAN! |
 |
winupd32.exe |
System Update Service
Added by the ADTODA-A TROJAN! |
 |
wmiprvsv.exe |
System Update Service
Added by the AGOBOT.YG WORM! |
 |
webcheck.exe |
System Update2
Added by the AUTOTROJ-C TROJAN! |
 |
wininet.exe |
System Update2
Added by the AUTOTROJ-C TROJAN! |
 |
winlogon.exe |
System Update2
Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
winspool.exe |
System Update2
Added by the AUTOTROJ-C TROJAN! |
 |
wupdmgr.exe |
System Update2
Added by the AUTOTROJ-C TROJAN! |
 |
wmiprvsw.exe |
System Updater Service
Added by the GAOBOT.AFC WORM! |
 |
winsci.exe |
System Updates
Added by a variant of the RBOT WORM! |
 |
wmkl.exe |
System Updates
Added by the RBOT-AYJ WORM! |
 |
winserv32.exe |
System Updates Manager
Added by the AGOBOT-AGA WORM! |
 |
winds32.exe |
System32
Added by the DWNLDR-HFY TROJAN! |
 |
Wincmp32.exe |
SystemAdministration
Added by the ASYLUM TROJAN! |
 |
WinMedia.exe |
SystemMigration
Added by the KELVIR.EI WORM! |
 |
WINREG.EXE |
SystemReg
Added by the DEWIN.A TROJAN! |
 |
windrives.exe |
Systems Backups
Added by the AGOBOT-RB WORM! |
 |
Windows2.exe |
systems usb driver
Added by a variant of the RBOT WORM! |
 |
wekls4.exe |
SystemTray
Added by a variant of the IRCBOT TROJAN! |
 |
Windowsupd.exe |
SystemTray
Added by a variant of the IRCBOT TROJAN! |
 |
winkernal.exe |
systhread
Added by the LIAMED WORM! |
 |
w32explorer.exe |
Systray
Added by the RBOT-AJY WORM! |
 |
winrxd64.exe |
sysygm64
Added by the IRCBOT-RK TROJAN! |
 |
Wink3sk9.exe |
T4skM4n4g3r
Added by a variant of the IRCBOT TROJAN! |
 |
wualcts.exe |
Task Help
Added by a variant of the RBOT WORM! |
 |
winampa.exe |
Taskmon driver
Added by the LOONY-I TROJAN! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of the Program Files directory whereas this file is located in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
websvc.exe |
Tcp Application Manager
Added by the DLOADER-NY TROJAN! |
 |
winlogon.exe |
TEXTCONV
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
wind0s.exe |
ThE
Added by an unidentified WORM or TROJAN! |
 |
wscript zshell.js |
Time Zone Synchronization
Added by the NETDEX-A TROJAN! |
 |
Watcher.exe |
Tiny Watcher Logon Time
Tiny Watcher detects changes to your system. It will not prevent your system from being modified or corrupted. It will only tell you that something suspicious happened. Think of it as an early CAT scan against system tumors. Better to install a tool that will detect and remove bad items |
 |
WINLOGON.EXE |
Torjan Program
Added by the WOWCRAFT.D TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! This trojan file is found in the Windows or Winnt folder |
 |
WinLED.exe |
Touch Manager
Dell keyboard utility. Disabling can result in loss of screen saver and power saver functionality |
 |
wincool.exe |
Tour
Component of WinME that's annoying as hell. Pop's up a prompt to play the C:WINDOWSApplication DataMicrosoftINTROCONTENT.HTA that plays a full screen version of the WinME product preview Windows Media video file that cannot be stopped to my knowledge until it finishes. That prompt will keep popping up after an install/reinstall of WinME until you give in and watch the thing. It also puts a task scheduler entry to run that annoying thing every 30 minutes, and don't bother deleting that entry, Windows puts it right back. Not only should you disable it from running, you should delete the thing altogether, as it, somehow can re-enable itself. Apparently you can try setting the file to read only |
 |
Weatherbug.exe |
Tray Temperature
Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs |
 |
winppr32.exe |
TrayX
Added by the SOBIG.F WORM! |
 |
wins32.exe |
Tsk Mng Hlp
Added by the AGOBOT-JB WORM! |
 |
WinManager.Exe |
Tweak Manager
WinGuides Tweak Manager. Is this required for the live updates feature and/or if settings are changed? |
 |
winter.exe |
Undefined
Added by the KILLAV.LW TROJAN! |
 |
WinUPPD.exe |
Universal Plug & Play devices
Added by an unidentified WORM/TROJAN! |
 |
winlogom.exe |
Updade Windows
Added by the TONAX-A TROJAN! |
 |
wupdata.exe |
UpData
Added by the IRCBOT-AA TROJAN! |
 |
winis.exe |
update
Added by the RBOT-VD WORM! |
 |
WinUpdater5.0.vbs |
UPDATE
Added by the GORMLEZ-A WORM! |
 |
winlog.exe |
Update Checker
Added by the IRCBOT-TJ TROJAN! |
 |
WiseUpdt.exe |
Update Grokster
Automatically updates the Grokster file sharing software. Beware of adware and spyware when using this type of program, for instance, Grokster contains CyDoor |
 |
winu32.exe |
Update Service
Added by the RBOT-MG WORM! |
 |
winx.exe |
update service
Added by a variant of the RBOT WORM! |
 |
WiseUpdt.exe |
Update TUT
?? |
 |
winstall.exe |
UpdateCheck
Added by the SPYBOT-CY WORM! |
 |
wupdater.exe |
updater
eUniverse/KeenValue adware |
 |
wisvc.exe |
updater
Added by the ORSE-A TROJAN! |
 |
winload32.exe |
updater32
Added by the CULT.M WORM! |
 |
wservice.exe |
UpdateService
Added by the DREF-K WORM! |
 |
winit.exe |
upddateit
Added by the RBOT-MS WORM! |
 |
winupd.exe |
Upgrade Service
Added by the TOFGER-U TROJAN! |
 |
WinSVCservice.exe |
UPNPService
Added by the AGOBOT.UN WORM! |
 |
wjview ...Code |
UpromiseRemindU
Part of the Upromise saving scheme but associated with Ebates MoneyMaker adware so the choice is yours |
 |
web.exe |
UPSUtl
CoolWebSearch parasite variant |
 |
WinUp.exe |
UpTimes service
Added by the RBOT-AKB WORM! |
 |
winlogon.exe |
urudjeffni
Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder |
 |
Winsys32.exe |
USB 2.0 Driver
Added by the AGOBOT-QM WORM! |
 |
winsystem.exe |
USB 2.0 Driver
Added by the AGOBOT-QS WORM! |
 |
winupdate1.exe |
USB 2.1 Driver
Added by a variant of the RBOT WORM! |
 |
win32usb.exe |
USB Device
Added by the FORBOT-BQ WORM! |
 |
wuservices.exe |
USB Fix 1.1
Added by a variant of the SDBOT WORM! |
 |
wuafix.exe |
USB Fixes
Added by the RBOT-ABV TROJAN! |
 |
wugfixx.exe |
USB Updates 2
Added by a variant of the RBOT WORM! |
 |
wmmndir.exe |
USBConfigration2
Added by the AGOBOT-SV WORM! |
 |
winlogon.exe |
userinit
Added by the DLOADER-TP TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder |
 |
WMPVer.EXE |
v
Dritek System Inc. 3D Mouse related. Is it required? |
 |
WebLifeDisk.exe |
VDrive2
EarthLink WebLife Disk - "Consumers can quickly save files from their desktop into WebLife Disk, and then easily access them from any Internet connection without taking a laptop on the road or keeping up with a USB key" |
 |
winamp32.exe |
Video
Added by the AGOBOT-NG WORM! |
 |
wcamfrog.exe |
Video Camera Frog
Added by a variant of the IRCBOT TROJAN! See here |
 |
winaps.exe |
Video Proces
Added by the AGOBOT.HD WORM! |
 |
winasp.exe |
Video Process
Added by the AGOBOT-IS WORM! |
 |
wincert32.exe |
Video Process
Added by the AGOBOT.JT WORM! |
 |
winit.exe |
virtual
Added by the MUGLY.A or MUGLY.B WORMS! |
 |
winprotect.exe |
virtual
Added by the MUGLY.C WORM! |
 |
wini.exe |
virtual
Added by the RBOT-YX WORM! |
 |
winlogi.exe |
virtual-ie
Malware - detected by Kaspersky as the WINAD.H TROJAN! |
 |
winlogin.exe |
virtual-machine
Added by the RBOT-VU WORM! |
 |
wini.exe |
virtual-machine
Added by the RBOT-WR WORM! |
 |
winxpsock.exe |
Vsample
Added by the SDBOT.BLK WORM! |
 |
WINLOGON .exe |
W1N32.DLL
Added by the DROPPERFL.A TROJAN! |
 |
w32.exe |
w32
Added by the SOKEVEN TROJAN! |
 |
wiper.exe |
W32PluginsDownloaderXMLHTTPSelfClearing7520
Added by the PROXYSER-M TROJAN! |
 |
w32sup.exe |
w32sup
Adult content dialler |
 |
w32sys.exe |
W32SYS
Added by the JAMBU-A WORM! |
 |
WTC32.scr |
W32Tc
Added by the VOTE.D or VOTE.K WORMS! |
 |
W75P2PS.EXE |
W75P2PSERVER
Printer utility which is required in order to make the printer work correctly |
 |
w7zip.exe |
w7zip
Added by the BANCBAN-QB TROJAN! |
 |
W815DM.exe |
W815DM
Enuff Parental Control Software by Akrontech |
 |
w98Eject.exe |
w98Eject
Related to USB support for Sigmatel MP3 audio palyer (and others such as SanDisk). It's intent is to "put away" the "disk" before you unplug it from the USB port, ostensibly to avoid "losing" data |
 |
wab.exe |
wab.exe
Added by a variant of the SDBOT WORM! |
 |
wait4IP.exe |
wait4IP
Packard Bell net2Plug allows you to network PCs anywhere in your house |
 |
Wallchgr.exe |
wallchgr.exe wstart
WallChanger - wallpaper changer from Blue Tree Software |
 |
wallmast.exe |
WallMaster
WallMaster - "The free and easiest way to master your desktop wallpaper!" |
 |
WALLPA~1.EXE |
WallPaper
Wallpaper Changer - wallpaper manager that can change your background images on every startup |
 |
Wallpaper.exe |
WallpaperChanger
A wallpaper changer and manager utility. There is the Freeware version and the Pro version. The freeware version is completely free. The Pro version is 30-day trialware, and after the 30 days some of the more advanced features will be disabled unless you register it |
 |
WallpaperSS.exe |
WallpaperSS
Wallpaper Slideshow LT from gPhotoShow.com - "a great utility for displaying your favorite photos as your desktop wallpaper" |
 |
Wanadoo Messenger.exe |
Wanadoo Messenger.exe
Wanadoo ISP instant messenger client |
 |
wanman.exe |
wanman.exe
Added by the RBOT.HDO WORM! |
 |
WanMPSvc.exe |
WanMPSvc
An AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling AOL doesn't help |
 |
wts**.exe [* = random char] |
WAPI
PurityScan/Clickspring adware |
 |
wartray.exe |
War FTPD Tray Icon
War-ftpd - FTP server |
 |
WAR-FTPD.EXE |
war-ftpd.exe
War FTP Daemon from JGAA's Internet - FTP client |
 |
WareOut.exe |
WareOut
Wareout - malware masquerading as a spyware and dialer remover |
 |
warez.exe |
warez
Warez P2P client |
 |
warner.exe |
Warner
Also known as "CyberWarner". From G-Tek Technologies and pre-installed on some Packard Bell PCs. Protects critical files |
 |
warnet.exe |
Warnet
Warnet - system cleanup software |
 |
WarReg_PopUp.exe |
WarReg_PopUp
Acer warranty registration popup |
 |
war-ftpd.exe |
WARSVR
"War FTP Daemon - the original free FTP server for windows" |
 |
washer.exe |
Washer
Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
 |
washerie.exe |
Washerie.exe
Cookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer, specific for cleaning the IE cache and cookies. Available via Start -> Programs |
 |
washidx.exe |
washindex
Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
 |
wast.exe |
Wast
Grokster ads updater |
 |
watch.exe |
Watch
Found to be used by a Trust USB scanner for auto starting the scanning software when the lid is lifted |
 |
watchdog.exe |
Watch Dog Program
For Compaq PC's. Associated with Compaq's internet services. Not required if you don't use services provided by them and may not be required even if you do |
 |
Watchdog.exe |
Watchdog
Definitely part of the Mustek scanner drivers and software (for 600 III EP Plus and maybe others), launches from the Startup folder in the Start Menu, but not required as they give instructions on removing it on their webpage |
 |
watchdog.exe |
WatchDog
Part of Motorola "Mobile Phone Tools" v3 - in a "Mobiile Phone Tools" sub-directory of Program Files |
 |
WatchWAN.exe |
WatchWAN
WatchWAN keeps an accurate account of the data that is flowing between your computer and the Internet at any given moment. This readout is presented in both numerical and graphical format, in real time |
 |
waumgr.exe |
waumgr
Added by a variant of the IRCBOT TROJAN! |
 |
WaveFramer.exe |
WaveFramer
Part of SafeSpace (from Artificial Dynamics) which "protects computers from Internet malware infection without the need for signature updates or regular maintenance" |
 |
WaveTop.exe |
WaveTop Launcher
WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
 |
WiFiMsg.exe |
WAWifiMessage
"HP Wireless Assistant is a user application that provides a method for controlling the enablement of individual wireless devices (such as Bluetooth or WLAN devices) and that shows the state of the radios for these wireless devices" |
 |
wbcmgr.exe |
Wbcmgr
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
wben.exe |
wben
Appears to be related to Desktop Notifier from Starfield Technologies. What does it do and is it required? |
 |
Wbiff.exe |
Wbiff
Wbiff! E-mail checker - automatically checks your e-mail and notifies you if any new e-mail has been received |
 |
Wbutton.exe |
Wbutton
Turns on and off the integrated WiFi on Acer (and other laptops) |
 |
WCESCOMM.EXE |
WCESCOMM
Active sync for use with Windows CE based palm PC |
 |
WCEMNGR.EXE |
WCESMngr
Added by the AGOBOT-QX WORM! |
 |
WCheckUp.exe |
WCheckUp
Barok keylogger and password stealer |
 |
wcmdmgrl.exe |
wcmdmgr
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
 |
wcmdmgr.exe |
wcmdmgr.exe
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
 |
wcmdmgrl.exe |
wcmdmgrl
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
 |
wintsvcc.exe |
WCPC
?? |
 |
wintsvit.exe |
WCPI
PurityScan/Clickspring adware |
 |
Wint**.exe [* = random char] |
WCPS
PurityScan/Clickspring adware |
 |
wintsvtr.exe |
WCPT
PurityScan/Clickspring adware |
 |
wcsys.exe |
wcsys
Added by the KEYLOG-AP TROJAN! |
 |
WDBtnMgr.exe |
WD Button Manager
Button manager installed with a western digital external disk drive. Allows you to back up your system with one click |
 |
wdfmgr32.exe |
wdfmgr32.exe
Added by the DWNLDR-FVL TROJAN! |
 |
wdinfo.exe |
WDInfo
Added by the DLUCA.B TROJAN! |
 |
wdmon.exe |
wdmon
Detected as the BUZUS.DVE TROJAN! |
 |
wdns33.exe |
WDNS SYSTEM
Added by the MYTOB-BY WORM! |
 |
wdskctl.exe |
wdskctl
IEPlugin spyware |
 |
wdwctrl.exe |
wdwctrl
Added by the DLUCA.E TROJAN! |
 |
WD_SRT.EXE |
WD_SRT
Western Digital USB disk driver |
 |
WEATHER.EXE |
WEATHER
Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs |
 |
weatherpulse.exe |
Weather Pulse
Weather Pulse from Tropic Designs. "Display popular Satellite images and video from around the globe, share images with your friends and family, stay updated on current and expected weather conditions, it's just plain fun!" |
 |
Weather.exe |
WeatherCast
Weather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight |
 |
WeatherEye.exe |
WeatherEye
WeatherEye - desktop weather from TheWeatherNetwork |
 |
WeatherOnTray.exe |
WeatherOnTray
Hotbar adware |
 |
Weatherscope.exe |
Weatherscope
WeatherScope - "displays your current local temperature in the system tray of your computer (near the clock) whenever you are online!" Not recommended as it bundles GAIN adware. You can get the adware free version for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here |
 |
WeatherStudio Desktop.exe |
WeatherStudio Desktop
WeatherStudio adware |
 |
ww.exe |
WeatherWatcher
WeatherWatcher - weather reporting in the System Tray |
 |
Web2Pop.exe |
Web2Pop
Web2Pop allows you to retrieve your web-based accounts messages to read them in your favorite e-mail client |
 |
web3trap.exe |
web3trap
PC-Cillin 2000 anti-virus software → ActiveX filter. Guards against malicious ActiveX programs, etc |
 |
webalize.exe |
webalize
Searchcentrix hijacker |
 |
WAK.exe |
WebArmyKnife
Web Army Knife - a suite of web site developer's tools |
 |
webassist.exe |
webassist
Adware popup generator |
 |
webbuying.exe |
WebBuying
WebBuying adware |
 |
WebCallDirect.exe |
WebCallDirect
WebCallDirect - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype |
 |
webcam.exe |
webcam
Added by the MONAD-A TROJAN! Note - this malware actually changes the default value data of the Registry Run and RunServices keys in order to force Windows to launch it at boot. Name field may be empty |
 |
wbcgosvc.exe |
Webcam Go Sti Service Application
Control software for the portable Creative Webcam Go digital camera/PC web cam. What does it do and is it required? |
 |
WEBCAMRT.exe |
WebcamRT.exe
For Logitech Web Cams. Not required - camera works fine without it |
 |
webcel.exe |
Webcelerator
Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Now no longer available and supported and when available was classed as spyware - see here |
 |
WebCheck.pif |
WebCheck
Added by the CONE.C or CONE.F WORMS! |
 |
WebCpr0.exe |
WebCpr0
WebRebates adware |
 |
webdav.exe |
Webdav.exe
IRC DDoS bot which gives the hacker full control over your system |
 |
whagent.exe |
WebHancer Agent
System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here |
 |
whSurvey.exe |
webHancer Survey Companion
WebHancertrackware - traffic measurement service that uses a client agent that is stealth installed on user machines, gathering detailed data about sites visited, their performance and, most important, what the user actually does while there |
 |
WebInstall.exe |
WebInstall
ClipGenie adware downloader |
 |
WebInstall.exe |
WebInstall2
ClipGenie adware downloader |
 |
WebKey.exe |
WebKey
WebKey from JB Utilities. Utility to keep track of login data required when browsing the internet |
 |
WebLink.exe |
WebLink
Softex is a "cost-effective way to provide software updates, technical support or new product information to specific end-users - it can silently provide end-users with software updates, technical support and new product information customized to their specific needs through a persistent link" |
 |
wpsche~1.exe |
Webposition Gold 2
Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines |
 |
WebRebates0.exe |
WebRebates0
WebRebates adware |
 |
WDF.exe |
Webroot Desktop Firewall
Webroot Desktop Firewall |
 |
websaverlive.exe |
websaverlive
WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your computer is idle |
 |
WebSavingsfromEbatesrun.exe |
WebSavingsfromEbates
Web Savings From Ebates Software, a shopping tool that opens pop-up windows |
 |
WebSavingsFromEbates0.exe |
WebSavingsFromEbates0
Web Savings From Ebates Software, a shopping tool that opens pop-up windows |
 |
WebScanX.exe |
WebScanX
From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc |
 |
wjview ...websearch.exe |
websearch
"Web Savings" From Ebates Software, a shopping tool that opens pop-up windows |
 |
WebSecureAlert.exe |
WebSecureAlert
WebSecureAlert - "helps to protect your browser security by monitoring for unauthorized tampering with Internet Explorer's security settings, and can help to protect your privacy by deleting your web surfing history on a regular basis". Not recommended as it bundles GAIN adware. You can get the adware free version for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here |
 |
Webshots Tray.exe |
Webshots
Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web |
 |
websho~1.exe |
Webshots
Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web |
 |
WebshotsTray.exe |
Webshots
Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web |
 |
webadmin.exe |
Website Administrator Info
Added by the FORBOT-FY WORM! |
 |
wupda.exe |
WebSUpdater
Detected by Kaspersky as the STARTPAGE.C TROJAN! See here |
 |
webtrap.exe |
Webtrap
Part of PC-Cillin anti-virus software. Checks web-sites for malicious Java and ActiveX elements in a similar way to McAfee WebScanX. A few users find it infuriating |
 |
WebTrapNT.exe |
WebTrapNT.exe
Part of PC-Cillin Anti-Virus software. Checks visited web-sites for malicious Java and ActiveX elements |
 |
wwasher.exe |
WebWasher
Free Pop-up/ad/javascript filter program from Siemens. If not running then browsers will not be protected but will still work. Available via Start -> Programs |
 |
WeirdOnTheWeb.exe |
WeirdOnTheWeb
Added by the WeirdOnTheWeb adware |
 |
Welcome.exe |
Welcome
Launches the Welcome to Windows tutorial on boot up |
 |
Wepstat.exe |
WEPstat
Cisco Aironet 340 Series PC Card driver. If it can be started manually it shouldn't be required if you don't use the PC card facility regularily - hence the status could be "U". Can anybody confirm this? |
 |
wiustv.exe |
wesumu
Added by the QQPASS-L TROJAN! |
 |
wetsock.exe |
WetSock
RoboMagic Wetsock - weather reporting in the System Tray |
 |
WFGStartup.exe |
WFGStartup
World Weather. "This midlet displays the current weather conditions for major cities around the world. This version is for memory limited mobile phones" |
 |
WFXCTL32.EXE |
WFXCTL32.EXE
From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs |
 |
wfxsnt40.exe |
wfxsnt40
WinFax 10.0 and maybe earlier versions. The program that opens the port for WinFax and not normally in the start menu. Needed if you want to run WinFax |
 |
WFXSWTCH.exe |
WFXSwtch
Related to WinFax. What does it do and is it required? |
 |
WG511WLU.exe |
WG511WLU
Netgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card |
 |
wgeax.exe |
wgeax
Added by the IRCBOT-TM WORM! |
 |
wgs3.exe |
wgs3
Added by the LEGMIR-AQH TROJAN! |
 |
WGV.exe |
WGV
Added by the ZIPPIE TROJAN! |
 |
WGWLocalManager.exe |
WGWLocalManager
Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so. It could be started by creating a shortcut, running it only when connecting to the internet. If internet is used often, it's recommended to leave it in startup so it starts with the system |
 |
WgwMngr.exe |
WgwMngr
Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so |
 |
whagent.exe |
whagent
System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here |
 |
WHATPU~1.EXE |
WhatPulse
WhatPulse keeps track of your keystrokes, allowing you to find out just how much you type a day |
 |
whse.exe |
WhenUSearchWHSE
WhenU.Save adware |
 |
whismng.exe |
Whistler
Added by the WHISTLER-F TROJAN! |
 |
Whvlxd.exe |
Whvlxd
Added by the ZAPCHAS-CS TROJAN! |
 |
wiascr.exe |
wiascr
Added by the AGENT.AM TROJAN! Note - example names include "XviD", "Winamp Remote", "Windows Media Player" and "Futuremark" |
 |
wifeman.exe |
wifeman
Unidentified malware |
 |
wifiboot.exe |
Wifi Boot
Added by a variant of the IRCBOT TROJAN! See here |
 |
wifibooter.exe |
Wifi Booter
Detected by Trend Micro as the IRCBOT.GP TROJAN! See here |
 |
wificonfig.exe |
Wifi Configuration
Added by the CHECKOUT WORM! See here |
 |
wificonfigs.exe |
Wifi Configuration!
Added by the CHECKOUT WORM! See here |
 |
wificon.exe |
Wifi Connection
Detected by Trend Micro as the SLENFBOT.AC TROJAN! See here |
 |
wificonnect.exe |
Wifi Connection!
Added by the CHECKOUT WORM! See here |
 |
wifidebug.exe |
Wifi Debug
Added by a variant of the IRCBOT TROJAN! See here |
 |
wifiload.exe |
Wifi Loader
Detected by Trend Micro as the IRCBOT.AVG TROJAN! See here |
 |
wifiloader.exe |
Wifi Loader!
Added by a variant of the IRCBOT TROJAN! See here |
 |
wifisetup.exe |
Wifi Setup
Added by a variant of the IRCBOT TROJAN! See here |
 |
WildFlics.exe |
WildFlics
Direct-B premium rate adult content dialler |
 |
wcmdmgrl.exe |
WildTangent Web Driver updater
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
 |
WWMon.exe |
Wildwire Monitor
This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem |
 |
WillowRoad.exe |
Willow Road
Willow Road Screen Saver |
 |
WillPolo.vbs |
WillPolo
Added by the VBS_SOLOW.AF VIRUS! |
 |
windows.exe |
WIN
Added by the REATLE.C WORM! |
 |
Win Antivir 2008.exe |
Win Antivir 2008
Win Antivir 2008 rogue security software - not recommended, see here |
 |
Win Antivirus 2008.exe |
Win Antivirus 2008
Win Antivirus 2008 rogue security software - not recommended, see here |
 |
winchi~1.exe |
Win Chimes
WinChimes - enhancement software for the system clock that runs in the system tray |
 |
WinComm.exe |
Win Comm
Added by the WINCOM TROJAN! |
 |
winconfig.exe |
Win Config
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
wuctl.exe |
win ctl app
Added by a variant of the SDBOT WORM! |
 |
windfrag.exe |
Win Defrag
Added by a variant of the SDBOT WORM! See here |
 |
windefrag.exe |
Win Defrag!
Added by a variant of the SDBOT WORM! See here |
 |
WIN HOST PROCESS.EXE |
WIN HOST PROCESS
Added by the KEYLOGGER.CLONE TROJAN! |
 |
winampa.exe |
Win l5oahder
Added by a variant of the RBOT WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of the Program Files directory |
 |
winlogin.exe |
Win Login
Added by the RBOT-AWE WORM! Note - this trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder |
 |
win14.exe |
Win Microsoft 98
Added by the RBOT-AKX WORM! |
 |
winupdates.exe |
Win Process Updates
Added by a variant of the SDBOT WORM! |
 |
winsecure.exe |
Win Security
Detected by Trend Micro as the IRCBOT.AVE BACKDOOR! See here |
 |
winserv.exe |
Win Server
Added by the IMISERV.A TROJAN! |
 |
wupdt.exe |
Win Server Updt
Added by the IMISERV.A TROJAN! |
 |
winserver.exe |
Win Server Updt
Added by a variant of the IMISERV TROJAN! |
 |
winsyncupx.exe |
Win Sync montr
Detected by Kaspersky as the RBOT.BYJ TROJAN! See here |
 |
wupda32.exe |
win update
Added by the SDBOT.J WORM! |
 |
wapdate.exe |
win update
Added by a variant of the RBOT WORM! |
 |
WINUPDATER.EXE |
Win Updater
Added by the RBOT.IP WORM! |
 |
winusb.exe |
WIN USB 2.0
Added by a variant of the RBOT WORM! |
 |
winamp.exe |
Win WinAmp
Added by the RBOT.AGF WORM! Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of the Program Files directory. This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
win*************.exe [* = random digit] |
win************* [* = random digit]
WINBO adware |
 |
WIN-BUGSFIX.EXE |
WIN-BUGSFIX
Added by the LOVELETTER (I LOVE YOU) VIRUS! |
 |
winis.exe |
win-xp
Added by the BROPIA.N WORM! |
 |
win.exe |
win.exe
Added by the PODROP-C TROJAN! |
 |
win16dll.exe |
win16.dll
Screenspy captures screenshots silently. If you didn't install this yourself, remove it |
 |
win23.exe |
win23.exe
Detected by Kaspersky as the BIFROSE.BSJ TROJAN! See here |
 |
WIN32.EXE |
WIN32
Added by the RATEGA TROJAN! |
 |
Win32.exe |
Win32
Added by the ISRAZ.A WORM! |
 |
winsrv32.exe |
win32
Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites |
 |
WinSetup.exe |
win32
Added by the EVILBOT.B TROJAN! |
 |
winhost.exe |
win32
Added by the BROPIA.J WORM! |
 |
winnnit.exe |
Win32
Added by a variant of the SDBOT WORM! |
 |
Winbios.exe |
Win32 Bios
Added by the SEMAPI-A WORM! |
 |
Win32.exe |
Win32 Critical File
Added by the RBOT-GUB WORM! |
 |
Win32Debug.exe |
Win32 Debug Manager
Added by a variant of the WOOTBOT WORM! |
 |
Win32ldr.exe |
Win32 Device Loader
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
winlogons.exe |
Win32 Drivers
Added by the FORBOT-FG WORM! |
 |
wdrk32.exe |
Win32 DRK Driver
Added by the WOOTBOT.CY WORM! |
 |
winstr32.exe |
Win32 exe file
Added by a variant of the SPYBOT WORM! |
 |
winfw.exe |
Win32 Firewall Driver
Added by a variant of the RBOT WORM! |
 |
win32help.exe |
Win32 Help32 Service
Added by the DELBOT-U WORM! |
 |
windowsnfo.exe |
Win32 Info
Added by a variant of the IRCBOT TROJAN! |
 |
winserver.exe |
win32 internet server
Added by the DERMON-D TROJAN! |
 |
win32update.exe |
Win32 Kernel Update
Added by the PROXY-BS TROJAN! |
 |
winwkys.exe |
Win32 Services Config
Added by the RBOT.BKY WORM! |
 |
wuamngr1.exe |
Win32 Services1
Added by the SDBOT-PV WORM! |
 |
win32src.exe |
Win32 Src Service
Added by the RBOT-SX WORM! |
 |
winssv.exe |
Win32 SSL Driver
Added by the FORBOT-BH WORM! |
 |
winservice.exe |
Win32 System Kernel
Added by the SDBOT.KIN WORM! |
 |
winserver.exe |
win32 system server
Added by the DERMON-A TROJAN! |
 |
winxpinit.exe |
Win32 USB Driver
Added by the SDBOT.AA TROJAN! |
 |
wins32.exe |
Win32 USB2
Added by a variant of the RBOT WORM! |
 |
win32usb.exe |
Win32 USB2 Driver
Added by the SPYBOT.DHV WORM! |
 |
wind32.exe |
Win32 USB2 Driver
Added by the FORBOT-AH WORM! |
 |
winupdate.exe |
Win32 USB2 Driver
Added by the AGOBOT.YE WORM! |
 |
winsnd32.exe |
Win32 USB2 Driver
Added by a variant of the SDBOT WORM! |
 |
w32usb2.exe |
Win32 USB2.0 Driver
Added by the SPYBOT.DN WORM! |
 |
win32tool.exe |
Win32 USB3 Driver
Added by a variant of the RBOT WORM! |
 |
winitr32.exe |
Win32 Wmls Driver
Added by the WOOTBOT.B WORM! |
 |
win32.exe |
win32.exe
Added by the STARTPAGE TROJAN! |
 |
Win32.exe |
Win32.exe
Added by the AWQ.A TROJAN! |
 |
Wintask.exe |
Win32BaseServiceMOD
Added by the NAVIDAD WORM! |
 |
win32sys4.exe |
win32beta
Added by the BANKER-DA TROJAN! |
 |
win32clf.exe |
win32clf
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
win32debug.exe |
win32debug
Added by the GUDEB WORM! |
 |
Win32DLL.vbs |
Win32DLL
Added by the LOVELETTER (I LOVE YOU) VIRUS! |
 |
Win32dll.exe |
Win32dll
Added by the BANPAES TROJAN! |
 |
win32gb.exe |
win32gb
Added by the DLUCA-F TROJAN! |
 |
webemir.exe |
Win32Host Process
Added by the TURGEN -A TROJAN! |
 |
win32info.exe |
win32info
Adult content dialler |
 |
Win32sl.exe |
WIN32SL
Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. The specific function of this is to load MIF's in order for Dell OpenManage Client to work |
 |
win32s.exe |
Win32System
Added by the MYDOOM.V WORM! |
 |
win32us.exe |
win32us
All-In-One-Telcom (adult content dialler) variant |
 |
WinCab.exe |
Win32Usr
Added by the DEDMIR-A WORM! |
 |
win32_i.exe |
win32_i lptt01
RapidBlaster variant (in a "win32_i" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
win32_i.exe |
win32_i ml097e
RapidBlaster variant (in a "win32_i" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
Win386.exe |
Win386
Added by the GOSUSUB VIRUS! |
 |
winabsmod.exe |
WIN3S2SNDS
Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" |
 |
winiprtx.exe |
WIN3S2SNDS
Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" |
 |
wingrd.exe |
win98 DNS
Added by a variant of the RBOT WORM! |
 |
winable.exe |
WinAble
Added by the MATCASH.BG TROJAN! |
 |
Winacsr.exe |
Winacsr
AceScreenSpy keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
WINACTIVE.EXE |
winactive
WinActive of the LOP.com hijacker |
 |
WinActiveJ.exe |
WinActiveJ
Added by the ROTARRAN VIRUS! |
 |
Winad.exe |
Winad Client
WinAd adware by eXact Advertising |
 |
WinAdCnt.exe |
WinAdCnt.exe
Added by the BANKER-BU TROJAN! |
 |
winadm.exe |
winadm
Browser hijacker - redirecting to Search-World.net. Related to the SMALL.AEX TROJAN! |
 |
WinAgent.exe |
WinAgent
Standard Life Insurance program. Is it required at startup? |
 |
Winahlp.exe |
Winahlp.exe
Added by a variant of the VAGRNOCKER TROJAN! |
 |
winallap.exe |
winallap
Added by the DELF.E TROJAN! |
 |
winallapu.exe |
winallapu
Added by the DELF.E TROJAN! |
 |
winamp.hta |
Winamp
Hijacker - re-directing to adult content sites. Note - this isn't the real Winamp |
 |
winamp.exe |
Winamp
Added by the AGOBOT.XI WORM! Note - this is NOT the popular Winamp media player |
 |
winamp62.exe |
WinAMP
Added by the SDBOT-WN WORM! |
 |
winamp.exe |
Winamp
Winamp media player. Resides in a "Winamp" subdirectory of the Program Files directory |
 |
winamp.exe |
Winamp Agent
Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player. The valid filename for the Winamp Agent is "winampa.exe" - see here |
 |
winapa.exe |
Winamp media player
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
winamap.exe |
Winamp Media Player
Detected by PCTools as the SDBOT.ACJM BACKDOOR! See here |
 |
winamp.exe |
Winamp Media Player
Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of %ProgramFiles% |
 |
winampp.exe |
WinAmp Player
Added by the RBOT-AQI WORM! Note - this is NOT the popular Winamp media player which has a different filename |
 |
Winamp6.exe |
Winamp Player 6
Added by a variant of the SPYBOT WORM! |
 |
winamptogoogletalk.exe |
Winamp to Google Talk
Winamp to Google Talk, available here shows your current Winamp track in your Google Talk status |
 |
WINAMPa.exe |
Winampa
Loads the System Tray icon for the popular Winamp media player - see here. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs. Resides in a "Winamp" subdirectory of the Program Files directory |
 |
winampa.exe |
Winampa
Added by the AGOBOT-GS TROJAN! ! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of the Program Files directory whereas this file is located in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
WINAMPA.EXE |
Winampa Agent
Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player. The valid filename for the Winamp Agent is "winampa.exe" - see here |
 |
WINAMPa.exe |
WinampAgent
Loads the System Tray icon for the popular Winamp media player - see here. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs. Resides in a "Winamp" subdirectory of the Program Files directory |
 |
Winagent.exe |
WinAmpAgent
Added by the EB TROJAN! Note - this is NOT the popular Winamp media player which has a different filename |
 |
was5.exe |
WinAntiSpyware 2005
WinAntiSpyware 2005 spyware remover - not recommended, see here |
 |
was7.exe |
WinAntiSpyware 2007
WinAntiSpyware 2007 spyware remover - not recommended, see here |
 |
WinAntispyware2008.exe |
WinAntispyware2008
WinAntispyware2008 rogue spyware remover - not recommeded, see here |
 |
WinAV.exe |
WinAntiVirus Pro 2007
WinAntiVirus Pro 2007 misleading virus software - not recommended, see here |
 |
winapix.exe |
WinApi
Added by a variant of the TIBSER.A downloader TROJAN! |
 |
WINAPLOGUPD.EXE |
WINAPLOGUPD
Added by the CAPSIDE-C WORM! |
 |
winpup32.exe |
Winapp
Produces popup ads to adult content sites |
 |
winlogon.exe |
WinAuth
Hijacker, also indentified as the STRTPAGE.BE TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder |
 |
WinAvX.exe |
WinAvX
WinAntiSpyware spyware remover - not recommended, see here |
 |
WinAvXX.exe |
WinAVX
Added by the FAKEAVALERT TROJAN! |
 |
WinAwk.exe |
WinAwk
Added by the SDBOT-AYF WORM! |
 |
Wbsched.exe |
WinBackup Scheduler
LIUtilities WinBackup scheduler - backup software |
 |
WinBar.exe |
WinBar
"WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls" |
 |
winbed.exe |
Winbed
Hijacker |
 |
win32exe.exe |
winbin32
Added by the RBOT-ZL WORM! |
 |
winbo32.exe |
winbo32
Added by the RBOT-GRU WORM! |
 |
winboot.exe |
winboot
Added by the BANLOAD-W TROJAN! |
 |
winbot.exe |
winbot
Added by the MIDRUG-A TROJAN! |
 |
winbrush.exe |
WinBrush
WinBrush - "handy tool that keep your privacy and make your system clean. It works by cleaning up your tracks (document histories, recent opened files from popular software, cookies, temporary internet files, etc)" |
 |
WinButler.exe |
WinButler
Identified as a variant of the Trojan-Dropper.Agent.DKN malware |
 |
WinCheck.exe |
WinCheck
Added by the PWS-CY TROJAN! |
 |
winchost.exe |
winchost
Added by the DLOADER-PO TROJAN! |
 |
WINCIN~1.EXE |
WINCINEMAMGR
WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
 |
WinCinemaMgr.exe |
WinCinemaMgr
WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
 |
WinRemote.exe |
WINCINEMAMGR
InterVideo WinCinema Manager - needed for the use of WinDVD Remote Control |
 |
winclean.exe |
winclean
Added by the AGENT.GXR TROJAN! |
 |
wincmapp.exe |
wincmap
CasClient adware variant - also detected as the CMAPP TROJAN! |
 |
WinColorReminder.exe |
WinColorReminder
The Microsoft Color Control Panel Applet for Windows XP "helps you manage Windows color settings in one place." Part of the Pro Imaging Powertoys |
 |
WinCore32.exe |
WinCore32.exe
Added by the CLICKER-EN TROJAN! |
 |
wincrt32.exe |
WinCRT32
Added by the DOGBOT-D WORM! |
 |
winctl.exe |
winctl
Added by the IRCBOT-YI TROJAN! |
 |
wincore332.exe |
WINCX
Added by the AGOBOT-MG WORM! |
 |
wind.exe |
wind.exe
Added by the MITGLIEDER.BD TROJAN! |
 |
WIND0WS.exe |
WIND0WS
Added by the SPYBOT.DQ WORM! |
 |
wordpad.exe |
Wind0ws
Added by the AGOBOT-TL WORM! Note - this is not the legitimate Windows application wordpad.exe (which is found in the Program FilesAccessories folder) which should not normally be seen in Msconfig or as a Startup item. This file is loacted in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
Wind32.exe |
Wind32
Identified as a variant of the Backdoor.Win32.Poison.avs malware |
 |
windates.exe |
WinDates
WinDates is a calendar, date organizer and event reminder program from Rockin' Software |
 |
winxtc.exe |
windbs
Added by the AGOBOT-WD WORM! |
 |
winde.exe |
Winde
Added by the DLUCA TROJAN! |
 |
Win32sp.vbs |
windef
Added by the ANPES WORM! |
 |
windef.exe |
windef
Added by the WURMARK-O WORM! |
 |
windefender.exe |
windefender
Added by the AGENT.BYH TROJAN! |
 |
windhost.exe |
windhost.exe
Added by the BANKER-BV TROJAN! |
 |
winos.exe |
windhost.exe
Added by the PWSAGENT-A WORM! |
 |
winrun.exe |
windir
Added by the WINBUR.B WORM! |
 |
wuaumqr1.exe |
Windir Working
Added by a variant of the IRCBOT TROJAN! |
 |
Windll.exe |
Windll
Added by the TRYNOMA TROJAN! |
 |
WSYS.EXE |
WINDLL
STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes, all passwords transacted even if they weren't keyed in, all web sites visited, every program launched including the path to that program, and more" |
 |
windll32.exe |
windll
Added by the ASTEF or RESPAN WORMS! |
 |
Windll.exe |
Windll.exe
Added by the STEALER TROJAN! |
 |
Windll32.exe |
Windll32
Added by the MSNPWS TROJAN! |
 |
windllsys32.exe |
windllsys32.exe
Added by a variant of the MITGLIE-A TROJAN! |
 |
windns32.exe |
WinDNS
Added by the GAOBOT.WX WORM! |
 |
winmon32.exe |
Window Monitor
Added by the SDBOT.RT WORM! |
 |
wwDisp.exe |
Window Washer
Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
 |
window.exe |
window.exe
Added by the MITGLIEDER.H or MITGLIEDER.J TROJANS! |
 |
wbload.exe |
WindowBlinds
WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins |
 |
Winex.exe |
WindowEnhancer
SCBar foistware variant |
 |
winupdatr.exe |
Windowfdgfds DasdLL Verifier
Detected by Trend Micro as the AGOBOT.HZ WORM! See here |
 |
Windowsdldfglcheckkk.exe |
Windowfdgfds DLL fgfdg Verifier
Added by the RBOT.CSP WORM! |
 |
winsecure.exe |
Windowfdgfds DLL fgfdg Verifier
Added by a variant of the RBOT WORM! |
 |
wfxload.exe |
WindowFX
Stardock WindowFX - "Allows you to add an unprecedented number of special effects to windows" |
 |
wiusyt.exe |
windown
Added by the QQPASS-M TROJAN! |
 |
wins.exe |
WindowRegKey update
Added by the SPYBOT.I WORM! |
 |
Windows.exe |
Windows
Added by the KAZMOR.A, BOBBINS & ALADINZ.D TROJANS! |
 |
windows.exe |
WINDOWS
Added by the MONBOT-A TROJAN! |
 |
WICleaner.exe |
Windows & Internet Cleaner Pro
Windows & Internet Cleaner Pro - "Powerful and easy to use internet surfing privacy protection & PC security software" |
 |
websvc.exe |
Windows .Net Manager
Added by the DLOADER-NY TROJAN! |
 |
win128.exe |
Windows 128 Module
Added by the FORBOT-ES WORM! |
 |
Win32edit.exe |
Windows 32 Editor
Added by the WOOTBOT.GQ WORM! |
 |
win32resc.exe |
Windows 32 Rescue
Added by the FORBOT-EU WORM! |
 |
Windows-Update.exe |
Windows 32 Update
Added by a variant of the RBOT WORM! |
 |
wauclt.exe |
Windows Account Alternation
Added by a variant of the IRCBOT TROJAN! See here |
 |
WinAdCtl.exe |
Windows AdControl
Windupdates adware variant |
 |
WinAdServ.exe |
Windows AdService
Windupdates adware variant |
 |
WinStat.exe |
Windows AdStatus
Added by the BLESHARE!DR VIRUS! |
 |
WinAdTools.exe |
Windows AdTools
Windupdates adware variant |
 |
Windows-Anti.exe |
Windows Anti Verifier
Added by the RBOT.ETT WORM! |
 |
winavscan.exe |
Windows Anti Virus Control Center
Added by a variant of the IRCBOT BACKDOOR! |
 |
walg32.exe |
Windows Application Layer
Added by the AGOBOT.ATN WORM! |
 |
walg32.exe |
Windows Application Layer Gateway
Added by the AGOBOT-AAZ WORM! |
 |
winlogon.exe |
Windows ARP Detectionc
Detected by Trend Micro as the RBOT.EAB WORM! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
winlogon.exe |
Windows ARP Detectioncx
Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
winupdater.exe |
Windows Auto Update
Added by the SDBOT.TF WORM! |
 |
WINDOWSUPDATE.EXE |
Windows Auto Updater
Added by the SDBOT.PB WORM! Note that there is a space at the beginning of the filename, ie, " WINDOWSUPDATE.EXE" |
 |
wuamgrder.exe |
Windows Automatic Update
Added by a variant of the RBOT WORM! |
 |
windrg.exe |
Windows Automatic Updater
Added by a variant of the RBOT WORM! |
 |
winboot.exe |
Windows Boot
Detected by Trend Micro as the AGENT.HBD TROJAN! See here |
 |
windowsboot.exe |
Windows Boot
Added by a variant of the IRCBOT TROJAN! See here |
 |
winboot.exe |
Windows Booter
Added by a variant of the IRCBOT TROJAN! |
 |
winbooter.exe |
Windows Booter!
Added by a variant of the IRCBOT TROJAN! See here |
 |
WINDOWS CLEAN-UP PRO.Exe |
Windows Clean-Up Pro
Windows Clean-Up Pro spyware remover - not recommended, see here |
 |
winclean.exe |
Windows Cleaner Service
Added by a variant of the IRCBOT TROJAN! See here |
 |
wincmd.exe |
Windows Command
Added by the RBOT.ANV WORM! |
 |
wincomm.exe |
Windows Communicator
Added by the AGOBOT-BH WORM! |
 |
windowsconf.exe |
Windows Conf
Added by a variant of the IRCBOT TROJAN! See here |
 |
wins.exe |
Windows Config
Added by the SPYBOT.JR WORM! |
 |
winconfig.exe |
Windows Config
Detected by Trend Micro as the IRCBOT.BAP BACKDOOR! See here |
 |
Wincfg32.exe |
Windows Config Loader
Added by the SILVERFTP TROJAN! |
 |
winconf.exe |
Windows Config Manager
Added by the RBOT-AIT WORM! |
 |
wsys32.exe |
Windows Configuration
Added by the GAOBOT.FB WORM! |
 |
wincfg32.exe |
Windows Configuration
Added by the MYTOB.ED WORM! |
 |
winxupdate.exe |
Windows Configuration Utility
Added by the AGOBOT.LW WORM! |
 |
winconf.exe |
Windows Configurator
Added by a variant of the IRCBOT TROJAN! |
 |
wkssvc.exe |
Windows Console
Added by the SDBOT-DJX WORM! |
 |
wrasvc.exe |
Windows Console Component
Added by a variant of the IRCBOT TROJAN! See here |
 |
wnbsvc.exe |
Windows Console Norms
Added by a variant of the IRCBOT TROJAN! See here |
 |
wnbsvc.exe |
Windows Console Source
Added by a variant of the IRCBOT TROJAN! See here |
 |
WinCtlAd.exe |
Windows ControlAd
Windupdates adware variant |
 |
win32bootcfg.exe |
Windows Core Kernel Update
Added by the RANCK-EL TROJAN! |
 |
winbog32.exe |
Windows CPU host
Added by a variant of the RBOT WORM! |
 |
wincrt.exe |
Windows Critical Alert
Added by the ALEDO-A TROJAN! |
 |
WinDat.exe |
Windows Database
Added by an unidentified WORM or TROJAN! |
 |
wiinsvc.exe |
Windows Database
Added by the AGOBOT-RU WORM! |
 |
windde32.exe |
Windows DDE Loader
Added by the SDBOT-UZ WORM! |
 |
winlogg.exe |
Windows debug logging
Added by the RBOT-OY WORM! |
 |
winloggs.exe |
Windows debug logging
Added by the RBOT-QN WORM! |
 |
windbg.exe |
Windows Debugger
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
windbg32.exe |
Windows Debugger
Added by the ZOTOB.L WORM! |
 |
wfdmgrsp.exe |
Windows Default Server
Detected by Kaspersky as the IRCBOT.BCX TROJAN! See here |
 |
winampa.exe |
Windows Default Server
Added by the IRCBOT.AUN WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of the Program Files directory |
 |
wdc*.exe |
Windows Defender
Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com |
 |
wda*.exe |
Windows Defender Adds
Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com |
 |
wdm*.exe |
Windows Defender Monitor
Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com |
 |
wdu*.exe |
|