Windows Vista Tips


Files beginning with w

The table below includes any files beginning with w, from which further information can be found by clicking on the process title. The icon beside the information can be used to quickly determine if this is a safe file in combination with the key below:



This file is normally safe to leave running. In most cases, this file is not required to run on startup and can be run manually. Warning, this file may be a virus, spyware, resource hog and running it is not recommended. This file may or may not be necessary to load on startup, depending on your circumstances. No information is available for this item.

[#] [A] [B] [C] [D] [E] [F] [G] [H] [I] [J] [K] [L] [M] [N] [O] [P] [Q] [R] [S] [T] [U] [V] [W] [X] [Y] [Z]

Files beginning with w:

File Type File Name Process Name and Information
winrecon.exe !NoLoad
WinRecon keystroke logger/monitoring program - remove unless you installed it yourself!
winSOCKS.exe (*)API Machine
Homepage hijacker, see here (* = any digit)
win32API.exe (*)Run
Homepage hijacker, see here (* = any digit)
winhelp.exe (Default)
Added by the BLACKMAL.C WORM! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank
winbas12.exe (Default)
Adware, CoolWebSearch parasite related - detected by Kaspersky as the VB.DU TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank
winlog.exe (Default)
Unidentified adware. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank
winligom.exe (Default)
Added by the RBOT-GAI WORM! Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run, HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank
wstcl.exe *Microsoft Update
Added by the STMU TROJAN!
wucxt.exe *Microsoft Update
Added by the STMU TROJAN!
wuytc.exe *Microsoft Update
Added by the STMU TROJAN!
WerFault.exe *WerKernelReporting
Part of Windows Error Reporting technology (WER) for Vista. WER captures software crash and hang data from end-users who agree to report it - see here
wrauclt.exe *windows update
Added by the RBOT-QU WORM!
wuanclt.exe *windows update
Added by the RBOT-PG WORM!
wuaucrlt.exe *windows update
Added by the SPYBOT.HUR WORM!
wuraclt.exe *windows update
Added by the RBOT-PO WORM!
wurauclt.exe *windows update
Added by the RBOT-SY WORM!
wsctl.exe *windows update
Added by the SPYBOT.PR WORM!
wkmst.exe *windows update
Added by the SDBOT.AVD WORM!
wscxt.exe *windows update
Added by the RBOT.AOS WORM!
waurclt.exe *windows update
Added by a variant of the RBOT WORM!
winstats.exe *winstats
Added by the GARGAFX TROJAN!
w****.exe [* = random char] *wuauclt.exe
Added by a variant of the RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe, wtmsv.exe, wxmst.exe, wmsvc.exe and so on...
wininfo.exe ,main drive Loader
Suspected malware as it appears in 3 different registry locations - see here
winlogon.exe .Prog
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
WARN0190.EXE 0190 Warner
Anti-dialer program (Germany)
WARN0900.EXE 0900 Warner
Anti-dialer program (Germany)
WebMailSpy.exe 1WinCfg32
WebMailSpy spyware
winmgr.exe 252
Added by the LEGMIR-AT TROJAN!
winlog0n.exe 9m
Added by the LEGMIR-AQK TROJAN!
wincms.exe @
Added by the RBOT.CBR WORM!
w32NTupdt.exe A New Windows Updater
Added by the MYTOB.BM WORM!
winpppoverethernet.exe a-winpoet-service
WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking
winsto.exe Access Control App
Detected by Kaspersky as the AGENT.DGO TROJAN! See here
wcescom32.exe ActiveSync
Added by the MANCSYN-E TROJAN!
wini.exe AdAware
Added by the RBOT-XN WORM!
winlogon.exe Administrator
Added by the RUBBLE-C WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
windrv.exe ADriver
Added by the DELF.WG TROJAN!
windefault.exe AFAFilter
AFAFilter - internet filter software
WinServ.exe AKEYNAME
Added by the EVILBOT.C TROJAN!
winoff.exe AMP WinOFF
WinOFF is " a utility designed to shut down Windows computers automatically, in a fully configurable way"
WZCSLDR2.exe ANIWZCS2Service
ALPHA Networks wireless driver
WZCSLDR.exe ANIWZCSService
D-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity
winsp3.exe Anti-Virus Update Scheduler
Malware - detected by Kaspersky as the AGENT.FP TROJAN!
winlog.exe AntiVir
Added by the IRCBOT-TJ TROJAN!
winapix.exe APIMon
Added by a variant of the TIBSER.A downloader TROJAN!
WN511B.exe AS00_WN511B
Netgear RangeMax NEXT wireless adapter configuration utility
WPN511.exe AS00_WPN511
NetgearRev MFC Application - software for Netgear wireless network cards - what does it do and is it required in startup?
windfind.exe atisrc2
Added by the WINDFIND-A TROJAN!
winfp.exe Audio Device Manager
Detected by PCTools as the IRCBOT.BIV TROJAN! See here
WinNT.exe Audio Device Manager
Added by the BANKER.BTG TROJAN!
WNDXP.exe Audio Device Manager
Detected by Kaspersky as the IRCBOT.AJL TROJAN! See here
wintmr.exe Authentic-ID Toolbar
System Tray access to Child Control parental control software by Salfield
win32.exe auto
Added by the SMALL!SD5 TROJAN!
WindowsSys32.exe Auto Updat
Added by a variant of the FORBOT WORM!
windowsupdate.exe autoload
Detected by Trend Micro as the POLYCRYP.DY TROJAN! See here
wauclt.exe Automated Windows Updates
Added by the GAOBOT.AJD WORM!
winmain.exe autorun
Added by a variant of the DELF.CNS TROJAN!
WINUP2DATE.DLL, SHStart autoupdate
Unidentified adware - detected by Panda antivirus as the CLICKER.CY TROJAN!
wlangui.exe AVMWlanClient
Related to broadband products from avm.de
win*.tmp.exe [* is a number] avp
Added by a variant of the ALPHABET TROJAN!
WErcx.exe AvpWx
Detected by Kaspersky as a variant of the AGENT.A TROJAN!
winupdate.exe blah service
Added by the GAOBOT.BIA WORM!
winsysengine.exe blah service
Added by the RBOT-KI WORM!
win32.exe blah service
Added by the RBOT-AXO WORM!
WLANmon.exe Blitzz BWI715
Blitzz Technology BWI715 Wireless PC modem connection monitor
wscript.exe [path] Date.POP.vbs BootsCfg
Added by the KUULLIO WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted
wscript.exe [path] All Users.vbs BootsCfg
Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted
wscript.exe [path] All Users.vbe BootsCfg
Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted
wscript.exe Install.log.vbs BootsCfg
Added by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "Install.log.vbs" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
wavepcmonitor.exe Bose Wave/PC Monitor
System Tray access for this system (more info on the system here). Available via Start -> Programs
winlogin.exe BossIdea
Added by the LINEAGE-I TROJAN!
wltray.exe Broadcom Wireless Manager UI
System tray access to wireless LAN card configuration options
winlogon.exe BuildLab
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
Wininit.exe Bymer.Scanner
Added by the BYMER WORM!
WinTask.exe C:WINDOWSWinTask.exe
"Pop Marketing" adware
WindowsSec.exe Cable Modem Adapter
Added by the WOOTBOT.A WORM!
wincalc.exe Calc Microsoft Windows
Added by an unidentied WORM or TROJAN!
WMADZ.EXE ccApp
Added by the RBOT-LJ WORM!
winlogon.exe ccApps
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
wintmr.exe CCWinTray
System Tray access to Child Control parental control software by Salfield
windrv.exe CDriver
Added by the DELF.WG TROJAN!
wsot.exe CEPA
??
WinMuschi.exe CFDStart
WINMUSCHI dialler
wiseupdt.exe Check for One Touch Update
Checks for updates for Visioneer OneTouch scanners
WiseUpdt.exe Check for TWS Updates
Interactive Brokers - check for update to their standalone Java-based trading platform
webtmr.exe ChicoSys
Child Control parental control software
W95AGENT.EXE Client agent for ARCserve
Part of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required?
wup.exe Client Update
Added by the OPANKI.O WORM!
winjes.exe Compaq Jes Drivers
Added by the SDBOT-XR WORM!
wincmd.exe Compaq Service Drivers
Added by the RBOT.ATV WORM!
wind32.exe Compaq Service Drivers
Added by a variant of the SDBOT WORM!
winmsn.exe Compaq Service Drivers
Added by a variant of the SDBOT WORM!
winsvc.exe Compaq Service Drivers
Added by the SDBOT-AGD WORM!
wstray.exe ComTry Web Searcher
Comtry MP3 Downloader related - spyware
WinService32.exe Config
Added by the CRUTCHA-A TROJAN!
winsys32.exe Config Loadr
Added by the AGOBOT-HN WORM!
Wuxat.exe Configuration Default
Added by the SPYBOT-CA WORM!
Winset32.exe Configuration File
Added by the FLUX.101 TROJAN!
wupdated.exe Configuration Loaded
Added by the MOEGA or MOEGA.AG or MOEGA.AP WORMS!
wincrt32.exe Configuration Loader
Added by the GAOBOT.BF WORM!
windex.exe Configuration Loader
Added by the GAOBOT.BZ WORM!
Winreg.exe Configuration Loader
Added by the GAOBOT.AO WORM!
winicfg32.exe configuration loader
Added by the GAOBOT.RQ WORM!
wincffg.exe Configuration Loader
Added by the AGOBOT.A3 WORM!
WinHelper.exe Configuration Loader
Added by a variant of the AGOBOT/GAOBOT WORM!
wincore.exe Configuration Loader
Added by the SDBOT.BHE WORM!
Winsys32.exe Configuration Loader Service
Added by the RBOT-YV WORM!
wscel.exe Configuration Loading Service
Added by the SDBOT-WJ WORM!
wlanutil.exe Configuration Utility
NetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards)
winamp32.exe Configuration32 Loader32
Added by the SDBOT-BIC WORM!
winservn.exe ContentService
Homepage hijacker
WFXCTL32.EXE Controller
From Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
winlogin32.exe cpanel
Added by the RBOT-FOY WORM!
wincomp.exe cpntmgc
Added by the WINTRIM_A TROJAN!
winmgts.exe cpntmgc
Added by the WINTRIM-B TROJAN!
wuitgurd.exe CPU Temp Control
Added by the RBOT-AHV WORM!
world_cup_.bat cqlyg
Added by the WCUP.A WORM!
Wucrtupd.exe CriticalUpdate
MS Windows Critical Update Notification. If you want to keep Windows up-to-date, check the Windows Update site
wucrtupd.exe CriticalUpdate
Added by the NOALA.B WORM! Note - this file is located in the Windows or Winnt folder, and must not be confused with the legitimate Windows process of the same name as described here
WinConst.exe ctfmon
Added by the ASSASIN-G TROJAN!
WINLOGON.EXE CueX44_stil_here
Added by the PUNYA-A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
WLANMON.exe D-Link AirPlus DWL-650+ Utility
D-Link Air Plus Wireless PC modem connection monitor
weather.exe Daily Weather Forecast
Added by the DLOADER-IP TROJAN!
W815DM.EXE ddhelper
Enuff Parental Control Software by Akrontech
windrv.exe DDriver
Added by the DELF.WG TROJAN!
worm.exe Delete Me
Added by the DOOMHUNTER WORM!
wltray.exe Dell Wireless Manager UI
System tray access to wireless LAN card configuration options
wfxmgr.exe Device Manager
Added by the RBOT.AJU WORM!
win.exe Distributed File System
Added by the MYFIP.AB WORM!
WATCH.exe DLHelperEXE
Download helper distributed with some software that allows the software installation to redirect download locations. Not required once the installation is finished
windfe.exe DLINK dfe drivers for Windows NT
Added by the RANDEX.AK WORM!
wakeservice.exe DomPlayer Service
DomPlayer adware
WindowsUpdate.exe DRam prosessor
Added by the RBOT-BBZ WORM!
winupdaterar.exe DRam rar proc
Added by a variant of the IRCBOT TROJAN!
W95Mm.exe drmu
Homepage hijacker installing a toolbar: http://tdko.com/. Lop.com in disguise
windspl.exe DsplObjects
Added by the BEAGLE.DN WORM!
windrv.exe DSystemDriver
Added by the DELF.WG TROJAN!
weather.exe Dulux WeatherShield WeatherDesk
Dulux WeatherShield WeatherDesk - latest weather information from across Australia
windvd98.exe dvd98
Added by the CULT.P WORM!
wsxsvc.exe Dvx
Delfin Media Viewer or "Promulgate" adware variant
Weather.exe DW4
Desktop Weather
winxp34.exe Dynamic Dns Binary
Added by a variant of the RBOT WORM!
WinHelpcfn.exe Dynamic Dns Binary
Added by a variant of the RBOT WORM!
wizard.exe EAPCISETUP
Part of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation
wjview ...Code EbatesMoeMoneyMaker
Ebates adware
watch.exe Eicon NetworksLAN_DAEMON
Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually
watch.exe Eicon TechnologyLAN_DAEMON
Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually
Winmsuit.exe ELSA WINman Suite
Allows you to totally customize your ELSA graphics card settings, including overclocking the GPU
wintr.com encapsulated command tool
??
WMENCAGT.EXE Encoder Agent
MS Windows Media Encoder, which already has a shortcut in the Start Menu if installed
wsys.exe Enumerate Service
Added by the MANIFEST TROJAN!
wind2ll2.exe erfgddfk
Added by the BEAGLE.CQ WORM!
windlhhl.exe erghgjhgdr
Added by the BEAGLE.BG WORM!
windlhhl.exe erghgjhjgdr
Added by the BEAGLE.BG or BEAGLE.BH or BEAGLE.BI or BEAGLE.BJ WORMS!
windll2.exe erthegdr
Added by the BEAGLE.CG WORM!
windll.exe erthgdr
Added by the BEAGLE.AO or BEAGLE.AQ WORMS!
winfw.exe eTunnel
Added by an unidentified TROJAN!
Warm.scr ExeName32
Added by the SCOLD WORM!
wscript.exe [filename] explorer
Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted
Windows Explorer.exe Explorer
Added by the SILLYFDC-I WORM!
winset.exe exporet
Added by the QQPASS-I TROJAN!
wo.exe eZWO
eZula TopText adware
wincfg.exe Fantasia injector
Added by the AGOBOT.US WORM!
windrv.exe FDriver
Added by the DELF.WG TROJAN!
wmiprvsc.exe File System Service
Added by the AGOBOT-HZ TROJAN!
wtm.exe FileFreedom_Plugin
FileFreedom peer-to-peer sharing program
Wscript.exe ChkMgr32.vbs FileManager32
Added by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "ChkMgr32.vbs" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
Wscript.exe UpdataFiles.vbs FileSoft
Added by the SST.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "UpdataFiles.vbs" file is located in the Winnt or Windows folder
wuaclt.exe FireFox Startup Drivers
Added by the RBOT.BYX WORM!
wmlaunch .exe Firewall
Added by the ELIPTER.A or ELIPTER.B WORMS!
wmlaunch .exe Firewall
Added by the ELIPTER.D WORM!
winlogon.exe Firewall auto setup
Added by a TROJAN - see here. Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
WinedowsUpdater1.exe Firewall Update System1
Added by the RBOT-ARU WORM!
WinFIX1.0.vbs FIX
Added by the GORMLEZ-A WORM!
wssdtu.exe Folder Service
Added by the MANIFEST TROJAN!
WINFAH.EXE Folding@home
Folding@Home is a distributed computing project which studies protein folding, misfolding, aggregation, and related diseases - must be running in order to access the internet to upload to the servers. Available via Start -> Programs
winlogon.exe FriendlyTypeName
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
winpopup.exe Fromine WinPopup
Instant Messenger program
winsvc.exe Generic Host Process for Win32 Services
Added by the SDBOT-O WORM!
winsvc32.exe Generic Host Process for Win32 Services
Added by the SDBOT-P WORM!
winlogon.exe Generic Host Process for Win32 Services
Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!
WinLoaderXP.exe GenericHostXP
Added by the BDOOR-ACX TROJAN!
Winmod32.exe Gerenciamento de arquivos do Windows
Added by the DLOADER-WG TROJAN!
winsystems.exe german.exe
Added by the BAGLEDl-AE TROJAN!
wintems.exe german.exe
Added by the BAGLE-AS TROJAN!
wakeservice.exe Get-Torrent Service
Get-Torrent bittorrent client - Installs LOP adware
winB_.exe getwin
Added by the BANKER-HS TROJAN!
WinDash.EXE Global Startup
Detected by Kaspersky as the VB.Q WORM!
window.exe gpmce
Detected by Kaspersky as the VB.CK WORM! See here
windll.exe Graphics adapter service
Added by the ATNAS.A WORM!
wscript.exe gpremier.vbs gremier
Added by the GPREMIER WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "gpremier.vbs" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
WCESCOMM.EXE H/PC Connection Agent
Active sync for use with Windows CE based palm PC
WinHSD.exe Hardware Shell Detection
Added by a variant of the RBOT WORM!
Wizardnil.exe Help
Added by the BANCOS-BCZ TROJAN!
windowsupdate.exe HKLMRun
Added by the FORBOT-BJ WORM! (where HKLMRun represents HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun)
wiz98.exe hostserv
Added by a variant of the SDBOT WORM!
winHostsEdit.exe HostsFileMgr
AdBin from Gilmore Software Development. An easy solution to managing your Window's hosts file
We Love Lien Van de Kelder.exe http://www.lienvandekelder.be
Added by the MYTOB-CV WORM!
winsys.exe I am not Ranky. I am eTunnel!
Added by an unidentified WORM or TROJAN!
winlog.exe icq lite
Added by the IRCBOT-TJ TROJAN!
winlogon.exe ICQ Net
Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!
webcamupdate.exe IcqBeta
Added by an unidentified TROJAN!
winlogon.exe ICQNet
Added by the NETSKY-C WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
wini.exe IE Runtime
Added by the PICRATE.B WORM!
winis.exe IE Runtimes
Added by the RBOT-ADZ TROJAN!
wkstmg.exe IE6
Added by a variant of the SDBOT WORM!
winsnt.exe IE6
Added by the RBOT-GOV WORM!
WinSock.exe IExplorerService
Detected by Kaspersky as the AGENT.KIU TROJAN! See here
WashIdx.exe Index Washer
Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
wsock32.exe InetServices
Added by the WOCK32-A TROJAN!
wmplayer.exe infamous.exe
Added by unknown malware. WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup. Infamous.exe is identified by Panda antivirus as Trj/Briss.A
WUSB11cfg.exe Instant Wireless Configuration Utility
Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration
WPC11Cfg.exe Instant Wireless Configuration Utility
Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration
wing32.exe Intec Service Drivers
Added by the RBOT.HAZ WORM!
winrvc.exe Intec Services Driverrs
Added by a variant of the SDBOT WORM!
winnook.exe Intel system tool
Added by the SPYRE-C TROJAN!
WinSocks5.exe internct
Added by the GRAYBIRD.F TROJAN!
winlogom.exe Internet
Added by a variant of the SDBOT WORM!
winsas32.exe internet
Added by a variant of the SDBOT WORM!
wins.exe Internet
Detected by PCTools as the RBOT.AAYF WORM! See here
winz32.exe INTERNET SERVISES
Added by the KWBOT.Z WORM!
wkfix.exe Internet2 Optimizer
Added by a variant of the RBOT WORM!
windows.exe InternetExplorer2
Added by the SDBOT-CZP WORM!
winz32.exe INTERNET_SERVISES
Added by the SDBOT.Q TROJAN!
WINDRV.EXE InterU
Added by the IRCINTER.A TROJAN!
WinCinemaMgr.exe Intervideo Win Cinema Manager
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
WINCIN~1.EXE Intervideo Win Cinema Manager
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
WinCinemaMgr.exe Intervideo WinCinema Manager
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
WINCIN~1.EXE Intervideo WinCinema Manager
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
WinScheduler.exe Intervideo WinScheduler
WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs
wnmgre.exe IPC Spool Manager
Added by the SDBOT-ZC WORM!
winspec.exe IPC Spool Manager
Added by the SDBOT-BLU WORM!
Winipcfgs.exe IPTable Configuration
Added by a variant of the RBOT WORM!
winmon32.exe iRis Active Monitor
Iris Antivirus - discontinued, replace with good alternative
WIMMUN32.exe iRiS AntiVirus Active Monitor
Iris Antivirus - discontinued, replace with good alternative
wintmp.exe ISPSERVICE
Detected by Trend Micro as the FLOOD.BC BACKDOOR! See here
winlogan.exe jkdfj94kgdftdf
Added by the ZLOB.BZ TROJAN!
winxp2.exe Jufualt
Added by the SDBOT-AAB WORM!
win1ogoin.exe KAVFOX
Added by the GWGHOST-M TROJAN!
wscntfy.exe KAVPersonal90
Added by the BANKER-FZ TROJAN!
Windll.exe KavRuns
Added by the TRYNOMA TROJAN!
winser.exe KernelCheck
Added by the TSPY_LMIR.SL TROJAN!
wmiprvse.exe Kernel_check
Added by the SONEBOT-B WORM! Note - this is not the legitimate wmiprvse.exe process which is always located in the System32wbem folder and should not normally figure in Msconfig/Startup!
winxp.exe key
Added by the BEAGLE.AG WORM!
winlog.exe key2
Added by the BAGLEDI-AL TROJAN!
wppewafaj.exe KnowledgeBase GUI
Added by the RBOT-GRZ WORM!
word.EXE KV2005
Added by the IW TROJAN!
winmine l44sys**
Added by the VBS.LIDO WORM - where ** is a number between 33 and 44
wllmsngr.exe Live Messanger
Added by a variant of the IRCBOT BACKDOOR! See here
win32.exe Load
Added by the RUBBLE-A WORM!
Wscript.exe LGuarg.exe.vbs Load-Guard
Added by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "LGuarg.exe.vbs" file is located in the Winnt or Windows folder
winldra.exe load32
Added by the NIBU.J BACKDOOR or DUMARU-BI TROJAN! Note - also known as Srv.SSA-KeyLogger by Sunbelt Software which has developed a free removal tool for this keylogger
WPSLOAD.EXE load=
Windows printing system that comes with the setup for Canon BJC series on the manufacturer's disk
WINOSCFG.EXE load=
Could it be something to do with configuring Windows on a new PC from an OEM supplier?
wpshrc.exe load=
Required to prevent configuration errors on a Compaq LBP-660 and LBP-460 parallel port laser printers (and maybe others)
wtfeat.exe Load=
Associated with the Wintab Digitizer
win32exec.exe load=
Added by the BITTER WORM!
WMPLAYER.EXE loader
Unknown baddie - WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup
wmimgr.exe LoadPFW
Added by the QEDS-B WORM!
watcher.exe LoadWatcher
Watcher spyware
winset.exe loadwin
Added by the QQPASS-I TROJAN!
winsys.exe loadwin
Added by the QQPASS-J TROJAN!
winlog.exe Login
Salfeld Child Control - parental control software
wrcam.exe Logitech Desktop Controller
Added by a variant of the RBOT WORM!
wincalc.exe LogService
Added by the PAPROXY TROJAN!
WIWT.EXE longos
Added by the BANKER-CD TROJAN!
wfdmgr.exe LSA
Added by the MYTOB.C WORM!
woekd.exe Lsass
Added by an unidentified WORM or TROJAN!
winupdate.exe LTM2
Added by the LITMUS.203 TROJAN!
winscan.exe LTM2
Added by the LITMUS-B TROJAN!
winvers16.exe LTM2
Added by the SMALL.ND TROJAN!
wusas.exe Machine Update Soft
Added by an unidfentified WORM!
WMIPRVSW.exe machine-debugger
Added by the AGOBOT.U WORM!
wintrims.exe MC
Added by the WINTRIM TROJAN!
WINTRIM.EXE MC
Added by the WINTRIM_A TROJAN!
Win32.dll.vbs mcafee
Added by the CATCHER-B WORM!
WebScanX.exe McAfeeWebscanX
From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc
wisp.exe MCX Update
Added by the RBOT-AQH WORM!
winy.exe MD IE Plugin
Adware
wmplayer.exe Media Player
Added by the AGOBOT-BM WORM!
wowdache.exe Meeting Connection
Added by the PPDOOR-D TROJAN!
Wmsngr.exe Messenger
Added by a variant of the RBOT WORM!
winldx32.exe Microfot Update
Added by a variant of the RBOT WORM!
winssx.exe Microft Update 32
Added by the RBOT-AQS WORM!
wdfmrg.exe Micromedia Flash Update
Added by a variant of the SDBOT WORM!
winmx32.EXE MICROSFT MX UPDATE SUPPORT
Added by the IRCBOT-FD WORM!
wilogon32.exe Microsof Winlog Host
Added by the RBOT.XC WORM!
win32.exe Microsoft
Added by the DARKMOON TROJAN!
wuauclt.exe Microsoft
Added by the QQROB-AQ TROJAN! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup!
wcsntfy.exe Microsoft
Added by the AGOBOT-AHT WORM!
windl32.exe Microsoft
Added by the SDBOT-DCZ WORM!
WinSecUp.exe Microsoft
Added by the RBOT-GPL WORM!
wsim32.exe Microsoft
Added by the RBOT-GTL WORM!
wplayer.exe Microsoft
Detected by Kaspersky as the RBOT.DYU TROJAN! See here
winampaa.exe Microsoft
Added by a variant of the IRCBOT BACKDOOR! See here
winline.exe Microsoft
Detected by Kaspersky as the AGENT.KT TROJAN! See here
wplayer.exe Microsoft
Detected by Kaspersky as the RBOT.GHZ BACKDOOR! See here
wuauclt.exe Microsoft (R) Windows Update Service
Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup!
wuapdate16.exe Microsoft 16Bit Update
Added by the RBOT.CZ WORM!
wupdt64.exe Microsoft 64 Bit Runtime Updater
Added by a variant of the RBOT WORM!
winupdate.exe Microsoft auto update
Added by the BMBOT TROJAN!
WINHLP16.EXE Microsoft Auto Update
Added by the RBOT.GY WORM!
wuauclt.exe Microsoft auto update
Added by the CULT-B TROJAN! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup!
wincmd.exe Microsoft Command Line
Added by a variant of the RBOT WORM!
wurmgrd32.exe Microsoft ConfgKeys
Added by the RBOT-ARX WORM!
windowz.exe Microsoft Corp SSL Certificates
Added by the RBOT-GCZ WORM!
wupdates.exe Microsoft Corp Updates
Added by the RBOT-AUU WORM!
webcp.exe Microsoft CP Web Manager
Added by the IRCBOT.HP TROJAN!
wincrs.exe Microsoft Crs Fix Serv
Added by the SDBOT.BWF WORM!
wupades.exe Microsoft DDE Control
Added by a variant of the SDBOT WORM!
wuamgrd.exe Microsoft DirectX
Added by the SDBOT.MY WORM!
wkssr.exe Microsoft dll Host Service
Added by a variant of the SDBOT WORM!
winlib32.exe Microsoft DLL Library
Added by the ATNAS.A WORM!
windll.exe Microsoft Dll Management
Added by the RBOT-MT WORM!
winavguard.exe Microsoft DLL Verifier
Added by the SDBOT.AAD WORM!
windrv.exe Microsoft Driver Control
Added by the SDBOT.FW WORM!
WSconf.exe Microsoft Drivers
Added by a variant of the SDBOT WORM!
wserb32.exe Microsoft ErgoPack
Added by the RBOT-RI WORM!
wuamngr32.exe Microsoft Excell
Added by the RBOT-QH WORM!
wmgrdf.exe Microsoft File Demand Manager
Added by a variant of the RBOT WORM!
wnpzjpuw.exe Microsoft FixUp
Added by a variant of the SDBOT WORM!
wupdate.exe Microsoft Generic Update Manager
Added by the RBOT-AWC TROJAN!
WINHOSTING.EXE Microsoft Hosting Service
Added by the RBOT.AEV WORM!
windows32.exe Microsoft Internet
Added by the SDBOT-F WORM!
wincfg16.exe Microsoft Internet
Added by a variant of the SDBOT WORM!
wcumrg.exe Microsoft Intrenet Explorer
Added by the SDBOT-AFD WORM!
win64.exe Microsoft IT Update
Added by the RBOT.GA WORM!
winn43.exe Microsoft IT Update
Added by a variant of the RBOT WORM!
win43.exe Microsoft IT Update
Added by the RBOT-SA WORM!
windows.exe Microsoft IT Update
Added by the RBOT-GL WORM!
winsyst32.exe Microsoft IT Update
Added by the RBOT-FC WORM!
winscr32.exe Microsoft Java Virtual Machine
Added by a variant of the WOOTBOT WORM!
Windows_kernel32.exe Microsoft Kernel
Added by the NETSKY.AE WORM!
winlogin.exe Microsoft Login
Added by the RBOT-AJP WORM!
wintcp32.exe Microsoft Lsass Service
Added by a variant of the IRCBOT TROJAN!
winjava.exe Microsoft Machine
Added by a variant of the AGOBOT/GAOBOT WORM!
winmplayers.exe Microsoft media
Added by a variant of the SPYBOT WORM!
winmplayer.exe Microsoft media services
Added by the RBOT.ZO WORM!
winmes.exe Microsoft MediaScope
Added by the RBOT-XU WORM!
wdgmr32.exe Microsoft MicroP Protocol
Added by a variant of the RBOT WORM!
winexec32.exe Microsoft NT Update
Added by a variant of the RBOT WORM!
winupdates.exe Microsoft Office Start
Added by the GAOBOT.BC WORM!
windr128.exe Microsoft Problem Doctor
Added by the SMALLTRO.EF TROJAN!
windr32.exe Microsoft Problem Doctor
Added by a variant of the SMALLTRO.EF TROJAN!
windr64.exe Microsoft Problem Doctor
Added by a variant of the SMALLTRO.EF TROJAN!
windos.exe Microsoft Rundll
Added by the SDBOT-WF WORM!
winService.exe Microsoft Security
Added by a variant of the RBOT WORM!
wcsntfy.exe Microsoft Security Center
Added by the SDBOT.BYD WORM!
winnt.exe Microsoft Security Management
Added by the RBOT-MQ WORM!
winserv.exe Microsoft Security Management
Added by the RBOT-MJ WORM!
winamp.exe Microsoft Security Management
Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of the Program Files directory
wuauct1.exe Microsoft Security Management
Added by a variant of the RBOT WORM!
winamp.exe Microsoft Security Manager
Added by the RBOT WORM! Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of the Program Files directory. This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
windowsupdate.exe Microsoft Security Monitor Process
Added by a variant of the IRCBOT BACKDOOR! See here
windowsupdate.exe Microsoft Security Monitor Process
Added by a variant of the IRCBOT BACKDOOR! See here
wininit.exe Microsoft Security Process
Added by the RBOT-FKM WORM!
wuauct1.exe Microsoft Server Applacations
Added by a variant of the RBOT WORM!
winsvc.exe Microsoft Service
Added by the SPYBOT-DB WORM!
winlogin.exe Microsoft Service Login Manager
Added by a variant of the IRCBOT TROJAN!
winsvc.exe Microsoft Service Manager
Added by a variant of the RBOT WORM! See here
WindowsSP.exe Microsoft Service Pack
Added by the RBOT-RF WORM!
winsound.exe Microsoft Sound Technology
Added by the RBOT-AGG WORM!
win32.exe Microsoft SpA Service
Added by the RBOT.ATS WORM!
Winupd32.exe Microsoft SpA Service
Added by the RBOT.LT WORM!
win32lib.exe Microsoft Standard Executions Library
Added by the RBOT-AUK WORM!
winsocks5.exe Microsoft standard protector
Added by the SMALL.CF TROJAN!
wmpIayer.exe Microsoft startup
Added by the IRCBOT.ACI TROJAN!
winslogin.exe Microsoft Stuff you know
Added by a variant of the SDBOT WORM!
winoem.exe Microsoft Svchost local services
Added by the RBOT-FPE WORM!
WinLoginnn.exe Microsoft Synchronization Manager
Added by the SPYBOT.FO WORM!
winupdate.exe Microsoft Synchronization Manager
Added by the SDBOT.ER WORM!
win.exe Microsoft Synchronization Manager
Added by the SDBOT.AK WORM!
winlogon32.exe Microsoft Synchronization Manager
Added by the SDBOT.AEU WORM!
wincfg32.exe Microsoft Synchronization Manager
Added by the SDBOT.DO WORM!
wmedia.exe Microsoft Synchronization Manager
Added by the SDBOT.BFC WORM!
win932.exe Microsoft Synchronization Manager
Added by the SDBOT.AH WORM!
Wnetlib.exe Microsoft System Checkup
Added by the DONK.C WORM!
wnetmgr.exe Microsoft System Checkup
Added by the DONK.Q WORM!
windir32.exe Microsoft System DLL Services Configuration
Added by the SDBOT-ACY TROJAN!
winIogon2.exe Microsoft System Service
Added by a variant of the IRCBOT TROJAN!
wintcp32.exe Microsoft TCP Protocol
Added by a variant of the IRCBOT TROJAN!
winupn.exe Microsoft Telecoms Center
Added by a variant of the SDBOT WORM!
wuamkopxp.exe Microsoft U
Added by the RBOT-AHC WORM!
winrarx.exe MICROSOFT UNPACK SYSTEM
Added by a variant of the RBOT WORM!
winsys32.exe Microsoft Update
Added by a variant of the RBOT WORM!
wuamgrd.exe Microsoft Update
Added by the RBOT-LK WORM!
wuammgr32.exe Microsoft Update
Added by the RBOT-AW WORM!
wudmate.exe Microsoft Update
Added by the RBOT.AP WORM!
wuamgrd32.exe Microsoft Update
Added by the RBOT.ZB WORM!
webm.exe Microsoft Update
Added by the SDBOT.WK WORM!
wuagrd.exe Microsoft Update
Added by the RBOT-FK WORM!
wauguard.exe Microsoft Update
Added by the RBOT.AEE WORM!
winscv.exe Microsoft Update
Added by the RBOT-BH WORM!
winsys.exe Microsoft Update
Added by the RBOT-GV WORM!
wserv32.exe Microsoft Update
Added by the RBOT.AF WORM!
wtm32.exe Microsoft Update
Added by the RBOT-AQ WORM!
wumgrd.exe Microsoft Update
Added by the SDBOT-KY WORM!
wuampd.exe Microsoft Update
Added by the RBOT-UT WORM!
windows24.exe Microsoft Update
Added by a variant of the RBOT WORM!
wingrd32.exe Microsoft Update
Added by the RBOT-DW WORM!
wssvr.exe Microsoft Update
Added by the RBOT-OD WORM!
wuamagr32.exe Microsoft Update
Added by the SPYBOT.CG WORM!
WinUpdate32.exe Microsoft Update
Added by the RBOT-TI WORM!
wkfix.exe Microsoft Update
Added by the RBOT-ABZ WORM!
winamp.exe Microsoft Update
Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player
win-mang.exe Microsoft Update
Added by the RBOT-AFK WORM!
winupdater.exe Microsoft Update
Added by the RBOT.BIN WORM!
wuamk0032.exe Microsoft Update
Added by a variant of the RBOT WORM!
wuamk032.exe Microsoft Update
Added by the RBOT-AHD WORM!
wuamk0p32.exe Microsoft Update
Added by a variant of the RBOT WORM!
wuamkop.exe Microsoft Update
Added by the RBOT-AFI WORM!
wuamkop32.exe Microsoft Update
Added by the RBOT.BGU WORM!
wuampkd.exe Microsoft Update
Added by the SDBOT.BBX WORM!
win32.exe Microsoft Update
Added by a variant of the SDBOT WORM!
wininit.exe Microsoft Update
Added by the RBOT-AKR WORM!
wuamgrd3.exe Microsoft Update
Added by the RBOT-AMC WORM!
Wudates.exe Microsoft Update
Added by a variant of the RBOT WORM!
wuagmsd.exe Microsoft Update
Added by the RBOT-AX WORM!
wuamgrb.exe Microsoft Update
Added by the RBOT-AZE WORM!
WINDOC.EXE Microsoft Update
Added by the SDBOT.PF WORM!
WinDrv32.exe Microsoft Update
Added by the RBOT.EGW WORM!
winupdate.exe Microsoft update
Added by a variant of the RBOT WORM!
wangard.exe Microsoft Update
Added by the RBOT-LH WORM!
wuamgrdx.exe Microsoft Update
Added by a variant of the SPYBOT WORM! See here
wutr.exe Microsoft Update
Added by the SPYBOT.AAR WORM!
wininit.exe Microsoft Update 32
Added by the RBOT-ANY WORM!
wininit32.exe Microsoft Update 32
Added by a variant of the RBOT WORM!
winitXP32.exe Microsoft Update 32
Added by a variant of the RBOT WORM!
wiit.exe Microsoft Update 32
Added by the RBOT-AMS WORM!
winin.exe Microsoft Update 32
Added by the RBOT-ARR WORM!
wuinit.exe Microsoft Update 32
Added by the AGOBOT-UE WORM!
wininit32.exe Microsoft Update 64 BIT
Added by the RBOT-AHE WORM!
winman32.exe Microsoft Update 64 BIT
Added by the RBOT-AKI WORM!
winl32xe.exe Microsoft Update 64 BIT
Added by the RBOT-AQO WORM!
WIN32SNC.EXE MICROSOFT UPDATE CONFIGURATION
Added by the RBOT-AI WORM!
wincfg32.exe Microsoft Update Debugger
Added by the SPYBOT.ZC WORM!
wuauclt.exe Microsoft Update Device Drivers
Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup!
winusers.exe Microsoft Update Loaders 2005
Added by the RBOT-AIQ WORM!
winusersystem32.exe Microsoft Update Loaders 2006
Added by a variant of the AGOBOT/GAOBOT WORM!
winini.exe Microsoft Update Machine
Added by the RBOT-KV WORM!
wuawx.exe Microsoft Update Machine
Added by the RBOT-CE WORM!
winupdt.exe Microsoft Update Machine
Added by the RBOT-FP WORM!
wuamgd.exe Microsoft Update Machine
Added by the SDBOT.HQ WORM!
wupdt32x.exe Microsoft Update Machine
Added by a variant of the SDBOT WORM!
windowsu.exe Microsoft Update Machine
Added by a variant of the RBOT WORM!
wininigo.exe Microsoft Update Machine
Added by a variant of the RBOT WORM!
winmgr.exe Microsoft Update Machine
Added by a variant of the RBOT WORM!
Winmsixp32.exe Microsoft Update Machine
Added by the RBOT.DN WORM!
Winregs32.exe Microsoft Update Machine
Added by the RBOT.DN WORM!
winxpini.exe Microsoft Update Machine
Added by the RBOT-OB WORM!
wuamgrd.exe Microsoft Update Machine
Added by the RBOT-HE WORM!
wuagrd.exe Microsoft Update Machine
Added by the RBOT-GF WORM!
winhost.exe Microsoft Update Machine
Added by the RBOT-GK WORM!
winss.exe Microsoft Update Machine
Added by the RBOT.JU WORM!
WUAMGRDXS.EXE Microsoft Update Machine
Added by the RBOT-GL WORM!
windowsup.exe Microsoft Update Machine
Added by the RBOT-FV WORM!
wuamgard.exe Microsoft Update Machine
Added by the SPYBOT.CS WORM!
wupdate32.exe Microsoft Update Machine
Added by a variant of the RBOT WORM!
winnie.exe Microsoft Update Machine
Added by the RBOT-ACD WORM!
winortho.exe Microsoft Update Machine
Added by the RBOT-NW WORM!
wins32.exe Microsoft Update Machine
Added by the RBOT.EZ WORM!
wftestb.exe Microsoft Update Machine
Added by the RBOT-AFZ WORM!
Win32.exe Microsoft Update Machine
Added by the SDBOT.UV WORM!
windns.exe Microsoft Update Machine
Added by the RBOT.EF WORM!
WINSVC32.EXE Microsoft Update Machine
Added by the RBOT.CU WORM!
winupdte.exe Microsoft Update Machine
Added by the RBOT-GKL WORM!
wlimyc.exe Microsoft Update Machine
Added by the RBOT-GQN WORM!
WINRLS.EXE Microsoft Update Manager
Added by the RBOT-AF WORM!
wmipcvse.exe Microsoft Update Process
Added by the AGOBOT-JF TROJAN!
wcsnfty.exe Microsoft Update Services
Added by the RBOT-AGK WORM!
wsnfty.exe Microsoft Update Services
Added by the RBOT-AFU WORM!
wuam.exe Microsoft Update Time
Added by the RBOT-M WORM!
wuammgrd32.exe Microsoft Update USB2
Added by the RBOT-ADT WORM!
winupdate32a.exe Microsoft Update Win32a
Added by the RBOT-LO WORM!
winupdate32x.exe Microsoft Update Win32x
Added by the RBOT-AJN WORM!
Winsys32.exe Microsoft Updater
Added by a variant of the RBOT WORM!
wuamgrds.exe Microsoft Updater
Added by the RBOT.A WORM!
WinFixd32.exe Microsoft Updater Resources
Added by the SPYBOT.CA WORM!
WINDLL32XP.EXE Microsoft Updaters Pros
Added by the SPYBOTTER.GEN VIRUS!
wkssvr.exe Microsoft Updates
Added by the RBOT.R WORM!
wkssvrs.exe Microsoft Updates
Added by the RBOT-EB WORM!
wuamgrd.exe Microsoft Updates
Added by the RBOT-CO WORM!
wtemp32.exe Microsoft Updates
Added by the RBOT-AHQ WORM!
wgafixer.exe Microsoft Updates 2 USB
Added by a variant of the RBOT WORM!
WinFixIDs.exe Microsoft Updates Resources
Added by a variant of the RBOT WORM!
wuamguards.exe Microsoft Updating
Added by the RBOT-BY WORM!
websvc.exe Microsoft Updating Client
Added by the RBOT.AQ WORM!
winlogon.exe Microsoft Visual SourceSafe
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
webcp32.exe Microsoft Web CP Manager
Added by a variant of the SDBOT WORM! See here
wdevice.exe Microsoft Web Device
Added by a variant of the SDBOT WORM!
webmsn.exe Microsoft web update
Added by the RBOT-EMQ WORM!
winsupdater.exe MicroSoft Wind0ws Updater
Added by a variant of the RBOT WORM!
Winupdsdgm.exe Microsoft Windows 2000
Added by the GAOBOT.AO WORM!
win32update.exe Microsoft Windows 32 Update
Added by a variant of the IRCBOT TROJAN!
wincomm.exe Microsoft Windows Communicator for NT/XP
Added by the RBOT.ATH WORM!
win32conf.exe Microsoft Windows Config 32
Added by a variant of the RBOT WORM!
windir32.exe Microsoft Windows DLL Services Configuration
Added by the SDBOT.BHF WORM!
windir32a.exe Microsoft Windows DLL Services Configuration
Added by a variant of the SDBOT.BHF WORM!
windll32.exe Microsoft Windows DLL Services Configuration
Added by the SDBOT.BHD WORM!
winDSL.exe Microsoft Windows DLL Services Configuration
Added by the SDBOT-ZG WORM!
windrv.exe Microsoft Windows Drivers
Added by a variant of the SDBOT WORM!
windvr.exe Microsoft Windows DVR
Added by the RBOT-AXD WORM!
websploit.exe Microsoft Windows Express
Added by a variant of the SPYBOT WORM! See here
windowslogonb.exe Microsoft Windows Express
Detected by PCTools as the SDBOT.ABOO WORM! See here
Windowz.exe Microsoft Windows GUI
Added by the RANDEX.AEV WORM!
winkrnl386.exe Microsoft Windows Kernel Services
Added by the ZEBROXY TROJAN!
wloader.exe Microsoft Windows Loader
Added by a variant of the AGOBOT/GAOBOT WORM!
winlogon.exe Microsoft Windows Logon Process
Added by the PROXYSER-R TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This worm file is placed in the Winnt or Windows folder
wimp.exe Microsoft Windows Media Player
Added by the RBOT-FN WORM!
wregistry.exe Microsoft Windows Registry Service
Added by the AGOBOT.AKG WORM!
windocs.exe Microsoft Windows Secure
Added by a variant of the SDBOT WORM!
windocs.exe Microsoft Windows Secure
Added by a variant of the SDBOT WORM!
wurguar.exe Microsoft Windows Securety
Added by the RBOT-KY WORM!
wscndrives.exe Microsoft Windows Security
Added by the RBOT-AJK WORM!
winsys.exe Microsoft Windows Service
Added by the RBOT-ADP WORM!
winspkn.exe Microsoft Windows Service Pack
Added by the RBOT-AYD WORM!
winsockx32.exe Microsoft Windows Socketx32 Services
Added by the RBOT-FWT WORM!
winms.exe Microsoft Windows Storage Machine Service
Added by the RBOT-AHK WORM!
winsvc.exe Microsoft Windows System Service Manager
Added by the SPYBOT.LR WORM!
windows.exe Microsoft Windows Updata
Added by a variant of the RBOT WORM!
windowsupdate.exe Microsoft Windows Update
Added by the AGOBOT.ON WORM!
wuap.exe Microsoft Windows Update Application
Added by a variant of the RBOT WORM!
win-logon.exe Microsoft Windows Update Logon
Added by a variant of the RBOT WORM!
wupdmgr32.exe Microsoft Windows Update Service
Added by the DOS.AUTOCAT TROJAN!
winupdgm.exe Microsoft Windows Updater
Added by the GAOBOT.BI WORM!
WINIUPDATES.EXE Microsoft Windows Updater
Added by the RBOT-KK WORM!
WINUPDATE.EXE Microsoft Windows Updater
Added by the SDBOT-PU WORM!
win32upd.exe Microsoft Windows Updater
Added by the RBOT-EC WORM!
windates.exe Microsoft Windows Updater
Added by the SDBOT.TE WORM!
wsap32.exe Microsoft Windows Updates
Added by a variant of the SDBOT WORM!
winsass.exe Microsoft Windows WinSaSS Management
Added by the RBOT-APW WORM!
winexplorer.exe Microsoft Windows XP/2K Explorer
Added by a variant of the IRCBOT TROJAN! See here
WinKey.exe Microsoft Winedows startup
Added by a variant of the SDBOT WORM! See here
WinSGR32.exe Microsoft WINGS32 Protocol
Added by the RBOT-APU WORM!
winrar.exe Microsoft WinRaR
Added by the RBOT-AEC WORM!
ws2_32s.exe Microsoft Winsock Wrapper
Added by a variant of the SPYBOT WORM!
Winamp61.exe Microsoft WinUpdate
Added by a variant of the RBOT WORM!
Winupd32.exe Microsoft WinUpdate
Added by the RBOT.MQ WORM!
WinNTinit32.exe Microsoft WinUpdate
Added by the RBOT.VS WORM!
wkcalrem.exe Microsoft Works Calendar Reminders
Produces a pop-up reminder of events scheduled using the MS Works Calendar
WksSb.exe Microsoft Works Portfolio
The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program.Can be prevented from starting from a setting within Portfolio
wkdetect.exe Microsoft Works Update Detection
Checks for updates to MS Works
winworld.exe Microsoft World Service
Added by an unidentified IRC worm with backdoor capability!
wuamkoppnp.exe Microsoft X Update
Added by the RBOT-ANI WORM!
winsystem32xp.exe Microsoft Xp Systems loader
Added by the KELVIR.W WORM!
win32xpsys.exe Microsoft Xp Systems loaders
Added by the SPYBOT.NYT WORM!
wngard.exe Microsoft-Update
Added by the RBOT-JV WORM!
win32sys.exe Microsoft32
Added by an unidentified WORM or TROJAN!
wees.exe Microsoftf DDEs Control
Added by a variant of the RBOT WORM!
why-.exe Microsoftf DDEs Control
Added by the RBOT-AMV WORM!
w33s.exe Microsoftf DDEs Control
Added by a variant of the RBOT WORM!
waes.exe Microsoftf DDEs Control
Added by a variant of the RBOT WORM!
winmplayd.exe Microsofts media
Added by an undidentified WORM or TROJAN!
wingtp.exe Microsofts media
Added by the RBOT-VO WORM!
winmep.exe Microsofts MediaScope
Added by the RBOT-WB WORM!
winmedplay.exe Microsofts MediaScope
Added by a variant of the RBOT WORM!
Wintsk32.exe MicrosoftServiceManager
Added by the YAHA.U WORM!
WinUp32.exe MicrosoftUpdate
Added by an unidentified VIRUS, WORM or TROJAN!
windll.exe MicrosoftUpdate
Added by the RBOT-IH WORM!
windrive.exe Micrsoft Driver
Added by the SDBOT.AF TROJAN!
wcnsfty.exe Micsorosft Security Center
Added by the RBOT-AHU WORM!
wimsqaad.exe Miosf Update
Added by the SDBOT.AG TROJAN!
wuampkd.exe Mircosoft Update
Added by a variant of the SDBOT WORM!
win32x.exe Mismo
Added by the RBOT-JP WORM!
WAed.pif Mlcr0s0ftf DDEs C0ntr0i
Added by the RBOT-BJW WORM!
winmgmt.exe MMCWINMGMT
Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here
webcomp.exe Mobipocket Web Companion
Related to Mobipocket eBook Reader
wuaclt.exe Modifiet Amateur HTPB
Detected by Trend Micro as the IRCBOT.AYS WORM! See here
Wupated.exe Ms Builders
Added by the AGOBOT-SS WORM!
wrapper.exe MS Java Service Wrapper for Windows NT & XP
Added by the VANEBOT-D WORM!
winPE.exe ms ownage
Added by the RBOT-AJL WORM!
wpad.exe MS PLUS INC
Added by the MYTOB-AN WORM!
winscv.exe MS Service Drivers
Added by the SDBOT-COG WORM!
winser.exe Ms sock for Windows NT
Added by a variant of the SDBOT WORM!
win32ttb.exe MS Unix Binary
Added by the SPYBOT.OQ WORM!
Win32Update.exe MS Unix Binary
Added by the RBOT-BAS WORM!
WinGuard.exe MS Unix Binary
Added by the RBOT-ACL WORM!
winservnt32.exe Ms Update WinServices NT/XP
Added by the VANEBOT-G WORM!
windriver.exe MS Win32 Network Services
Added by the AGOBOT.ADH WORM!
web.exe MS-Connect
Adult content dialler - see here
winlog.exe msconfig
Added by the IRCBOT-TJ TROJAN!
winnsyst.exe MSControl31
Added by the RBOT.CFY WORM!
winmp.exe MSIdll
Added by a variant of the RBOT WORM!
winlogon.exe MSMSGS
Added by the RAHIWI.A WORM!
wdlrss.exe MSN
Added by a variant of the SDBOT TROJAN!
wkssvr.exe MSN
Added by the PUSHBOT.S WORM!
wkssvrs.exe MSN
Added by a variant of the IRCBOT BACKDOOR! See here
wksvr.exe MSN
Added by the IRCBOT-XU WORM!
wmev.exe MSN
Added by a variant of the SPYBOT WORM! See here
winntmsn.exe MSN Messanger Live
Added by the RBOT-FSO WORM!
windns.exe Msn Messeng
Added by a variant of the RBOT WORM!
winproc.exe MSN Service Updates
Added by the KELVIR-BB WORM!
windatemanager.exe Msn Updater
Added by the SDBOT.TS WORM!
winagent.exe MsnExplorer
Added by the EQ TROJAN!
winampb.exe msnnt
Chinese originated adware - detected by Kaspersky as the AGENT.TL TROJAN!
winampf.exe msnnt
Added by the SMALL.DTS TROJAN!
winss.exe MSOleath32
Added by the KATHER TROJAN!
wiaadmgr.exe MSPP System Update 64
Detected by Kaspersky as the RANKY.GEN TROJAN!
winupdate.exe mssonfig
Added by a variant of the SDBOT WORM!
WINUPD.EXE MSStartOptimizer
Added by the DASMIN-E TROJAN!
wstask32.exe MsTask
Added by the MYTOB-FE WORM!
wupd.exe MSUpdate
Added by the ALADINZ.M TROJAN!
wsdrt32.exe MsWindows DRT Drivers
Added by the RBOT.ALT WORM!
winlogon.exe MSWinlogon
Added by the AGENT-FZM TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!
winupd.exe MSWinupd
Added by the DLOADER-YE or DLOADR-AAA or DLOADER-ZF TROJANS - and others
winupdate.exe MSWinupdate
Added by the DLOADR-AAW TROJAN!
wdfmgr.exe MS_Update Check
Added by the AGOBOT-TB WORM!
wjview ...MyPointsPointAlertrun.exe MyPointsPointAlert
"With MyPoints you can earn rewards from name-brand merchants. You can even earn vacations and frequent flyer miles". Dubious privacy policy
winexplor.exe mysoft
Browser hijacker, also detected as the STARTPA-JR TROJAN!
winsnav.vbs NAV Agent
Added by the ANPES WORM!
wmilib32.exe NAV Agent
Added by the VB-XU TROJAN!
WINDBKGND.EXE NB Windows Patterns
Part of McAfee Nuts & Bolts. With Background Patterns, you can change background patterns of wizard and dialog windows
winntsrv -l -p10001 -d -e cmd.exe -L NC1565
Added by the NEWLEY-A WORM!
windows.exe NDIS Adapter
Added by the FORBOT-BR WORM!
Winman.exe NDIS Adapter
Added by the WOOTBOT.AG WORM!
winlogin.exe NDplDeamon
Added by the RANDEX.E WORM!
wmp9.exe Nero Updater.6.12
Added by the AGOBOT-AAG WORM!
winjava.exe NeroUpdater6.8
Added by the AGOBOT.AMK WORM!
WINREG.EXE Net
Added by the ASSASIN.D TROJAN!
winserv.exe NetApp
Added by the SHADOWTHIEF TROJAN!
wlan111t.exe NETGEAR WG111T Smart Wizard
Configuration utility for the Netgear WG111T multi-rate Wireless USB 2.0 Adapter that "provides wireless access to your desktop or notebook PC through the computer's USB port"
winclient.exe NetPatrol
NetPatrol network monitoring software
WgwMngr.exe NettGain2000
Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so
wunit32.exe Netunit32
Added by an unidentified WORM or TROJAN!
winssh.exe Network Access
Added by a variant of the SDBOT WORM!
wuamgrd.exe Network Protocol Service
Added by the RBOT.EA WORM!
wintcp.exe Network protocol service
Added by a variant of the AGOBOT/GAOBOT WORM!
WinNPS.exe Network Provisioning Service
Added by an unidentified WORM/TROJAN!
WinAntiVirusPro2006Installer.exe NI.UWA6P_0001_N56M1001
WinAntiVirus Pro 2006 misleading virus software - not recommended, see here
WinAntiVirusPro2006Installer[1].exe NI.UWA6P_0001_N69M0303
WinAntiVirus Pro 2006 misleading virus software - not recommended, see here
WinAntiVirusPro2006FreeInstall.exe NI.UWA6P_0001_N73M1004
WinAntiVirus Pro 2006 misleading virus software - not recommended, see here
winantiviruspro2006freeinstall[1].exe NI.UWA6P_0001_N91M1807
WinAntiVirus Pro 2006 misleading virus software - not recommended, see here
winantiviruspro2007freeinstall[1].exe NI.UWA7P_0001_N91M0809
WinAntiVirus Pro 2007 misleading virus software - not recommended, see here
wsul.exe Norton Service Driver
Added by the RBOT-ABI WORM!
winsvc.exe Norton Update
Added by the AGOBOT.ALP WORM!
winset.exe Norton Updater
Added by a variant of the SPYBOT WORM!
wtta.exe Notn
PurityScan/Clickspring adware
WinNTLM.exe NT LM Security Support Provider
Added by a variant of the SDBOT WORM!
wntsf.exe NTSF MICROSOFT SYSTEM
Added by the RBOT.ATC WORM!
winsis32.exe NTSF MICROSOFT SYSTEM
Added by a variant of the RBOT WORM!
winlogon.exe nvchost
Added by the KLONE-J TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
windowsp.exe NvCpl
Added by a variant of the SDBOT WORM!
winasp.exe NvCplScan
Added by the FORBOT.BZ WORM!
wuauqmr.exe NvCpTDaemon
Added by the CULT-B WORM!
winoeinit.exe OEPowerPlugs
??
winxp_sp3.exe Offica Monitor Secura Systeme
Added by a variant of the RBOT WORM!
winutade.exe OKGO
Added by the BANKER-EHZ TROJAN!
winssnotify.exe OneCareUI
Related to Windows OneCare Live from Microsoft
webtogo.exe Oracle Web-to-Go
"Oracle Web-to-go, a component of Oracle9i Lite, consists of a collection of modules and services that facilitate development, deployment, and management of mobile Web applications"
winword.exe OSA
Added by the KANGAROO-A TROJAN!
wcdvtray.exe OWCWebCamDV
WebCamDV from Orange Micro, Inc - enables the user to use a DV camera connected via Firewire as a Webcam
WinGamed.exe Patches Value
Added by the SDBOT.BR WORM!
WinPTTP.exe Performs peer to peer connection
Added by the RBOT-GMI WORM!
W3dbsmgr.exe Pervasive.SQL Workgroup Engine
Database Service Manager for Pervasive SQL 2000 Workgroup edition. Required if you use Pervasive SQL but it's recommended you start it manually before using it as it has a tendancy to crash/freeze if loaded with other applications at startup
wpctrl.exe PivotSoftware
PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties
winsrvc.exe Pmedia
Internet marketing sofware from Permissioned Media Inc as used in E-Card FriendGreetings foistware - see here. Treated by Trend as the FRIENDGRT.B WORM!
wuaaclt.exe PNP
Added by the LILBRE-A WORM!
WinTask.exe PopMark
"Pop Marketing" adware
webprinter.exe Printer Monitor
Added by the IRCBOT-Z TROJAN!
wqxfne.exe Proc993
Added by the IXBOT-D WORM!
wsript.exe Q152404.VBS Q152404
Appears to run Scandisk at bootup on NEC PCs
Winrar.exe quicken
CoolWebSearch Therealsearch parasite variant. Note - this is not the file zipping utility also known as WinRAR!
Waol.exe quicken
CoolWebSearch Therealsearch parasite variant
winmplyer32.exe Quicktime Mediaplayer
Added by the RBOT-PM WORM!
wnmplyr.exe Quicktime Mediaplayr
Added by a variant of the RBOT WORM!
winuodps.exe Quicktime Pro 3.0
Added by the GAOBOT.BH WORM!
Winrsm.exe Real Spy Monitor
Realspy keystroke logger/monitoring program - remove unless you installed it yourself!
winsy.exe Reg Service
Added by a variant of the SPYBOT WORM!
winslogon.exe Reg Service
Added by the AGOBOT-SC WORM!
WinnConfig.exe Reg Service
Added by the AGOBOT-PF WORM!
Winboot32.exe Reg Services
Added by the RBOT.PB WORM!
winlogon.exe RegDone
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
wscript.exe ShakiraPics.jpg.vbs Registry
Added by the VBSWG.AQ WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "ShakiraPics.jpg.vbs" file is located in the Winnt or Windows folder
winreg.exe Registry Checkup
Added by an unidentified WORM or TROJAN!
Winregs326a.exe Registry Checkup System326a Monitor
Added by a variant of the SDBOT WORM!
WCPDT.EXE Registry Integritycheck
Added by the AGOBOT-RF WORM!
winhlpp32.exe Registry Loader
Added by the GAOBOT.AO WORM!
win32.exe Registry oidet
Added by the RBOT.BMT WORM!
winapi32.exe Registry Value Name
Added by a variant of the RBOT WORM!
winbackup.exe RegistryChk
Added by the MERTIAN WORM!
winservice.exe Regkey for autostart
Added by the RBOT-NU WORM!
winfix22490.exe REGRUN
Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!
winbait.exe RegRun WinBait
Part of RegRun - used to detect unknown viruses. RegRun compares winbait.exe with the original copy called winbait.org and warns if the files are different..
WatchDog.exe Regrun2
Greatis Software's RegRun security suite which amongst other things replaces MSCONFIG. The WatchDog check for registry changes caused by trojan's, viruses, etc
WinRDH.exe Remote Desktop Help Session Manager
Added by a variant of the SDBOT WORM!
winrpc.exe Remote Procedure Call
Added by the RBOT-KM WORM!
winsysrpc.exe Remote Procedure Call
Added by the SDBOT-PS WORM!
win.exe Remote Procedure Calls
Added by the SDBOT-QI WORM!
windos.exe REMOVE ME
Added by the SDBOT.EE WORM!
Watch.exe Restart Watch
Associated with an Eicon Networks Diva ISDN or ADSL modem. What does it do and is it required?
wscrestp.exe Restart WSC Setting
WinStart Commander - part of Ultra WinCleaner Utility Suite. Starts Windows faster and controls hidden programs to boost performance and prevent system slow downs and crashes
wf32vbs.exe RNBc Test
Added by the RBOT-AGR WORM!
wf32vbc.exe RNBz Test
Added by the RBOT-AEY WORM!
wf32b.exe RNDc Test
Added by a variant of the SDBOT WORM!
winlogon.exe ROOT_Machine
Added by the BANKER-FI TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This worm file is placed in the Windowsinf or Winntinf folder
winlogon.exe RPCserr32g
Added by the RITDOOR-B WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
WINLOGON.EXE RPCserv32g
Added by the BOBAX.AD WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
wandrv.exe run
Added by the BCKDR-QHR TROJAN!
wscript MSupdt32.vbs Run MSupdt32
Added by the CASER WORM!
wperl.exe Run POPFile in background
POPFile - E-mail spam blocker
websvc.exe Run Services as Application
Added by the DLOADER-NY TROJAN!
WINClock.exe run32dll
Added by an unidentified VIRUS, WORM or TROJAN!
wallflip.exe run=
Desktop wallpaper changer?
win.ini run=
??
wswpd.exe run=
Used with some models of Panasonic, Epson and NEC printers - required for printer to work
wmplayer.exe run=
CoolWebSearch Smartsearch parasite variant
Winfi1e32.exe Rund1l32
Added by the MERTIAN WORM!
winupdate.exe RunDLL32
Added by an unidentified TROJAN! - possibly a BMBOT variant
Windows.exe Rundll32
Added by the QQPASS.E TROJAN!
win.exe runing
Added by the DELF-LC TROJAN!
wini.exe RunProg
Added by the OPTIX.04.D TROJAN!
winlogon.exe runwinlogon
Detected by Trend Micro as the AGENT.TQY TROJAN! See here. Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
WAS7Mon.exe Salestart
WinAntiSpyware spyware remover - not recommended, see here
winagent.exe ScheduIr
Added by a variant of the SDBOT WORM!
winagent.exe Scheduler
Added by the TACTSLAY.B TROJAN!
wsass.exe Scheduler Service
Added by the LIOTEN.KX WORM!
w32tm.exe Secboot
Added by the HAXDOOR.D TROJAN!
wins32a.exe secure socket layer
Added by an IRCBOT TROJAN!
WindowsSecurityUpdate.exe Security
Added by a variant of the SDBOT WORM!
WinUpdate32.exe Security Patch
Added by the SDBOT-BM WORM!
WinLab32.exe Security Patches
Added by the SDBOT-KB WORM!
wmiprvce.exe Security Update Service
Added by the AGOBOT.ZW WORM!
wssdsu.exe Serv-U
Added by the MANIFEST TROJAN!
wbemstest.exe Server Runtime Process
Added by the SDBOT-DDB WORM!
wN2S.exe service
Added by a variant of the RBOT WORM!
winsvcli.exe Service Client
Added by an unidentified WORM or TROJAN! See here
WinOcx.exe Service Monitor
Added by the RBOT-AQJ WORM!
winset.exe Service Process
Added by a variant of the SPYBOT WORM!
windowsXP.exe Service System
Added by the BANCOS-EL TROJAN!
wernell87.exe Service System
Added by the BANCOS-FJ TROJAN!
winread.exe Services
Added by an unidentified VIRUS, WORM or TROJAN!
windns.exe Services
Added by a variant of the RBOT WORM!
windows32.exe services
Added by the FLYVB-C WORM!
websvc.exe Services Administrator
Added by the DLOADER-NY TROJAN!
win32dll.exe Services32 Startup
Added by the SDBOT-XO WORM!
wsusupd.exe ShareSearcher
Added by the ENCLAG-A TROJAN!
winagent.exe SheduIer
Added by the EB TROJAN!
wmedia16.exe Shell
Added by the GOLDUN TROJAN!
wmedia32.exe Shell
Added by the AGENT-BR TROJAN!
Wifiusb.exe Sinus 1054 data WLAN Manager
Wireless management utility for the T-Com Sinus 1054 Data WLAN adapter
winsos.exe sis32
Added by the QQPASS.IA WORM!
win.bat Sistray32
Added by the JUMPRED.A WORM!
winlogon.scr SkynetRevenge
Added by the NETSKY.AA WORM!
winlogon.exe SmansaApp
Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
winsrv.exe smcserv
Added by the AGOBOT-OU WORM!
win32st.exe SMSERIALSTARTER
Detected by McAfee as the FAKEALERT-AH TROJAN! See here. Installed with the SpyBurner spyware remover - which is not recommended, see here
winstrse.exe SMSERIALWORKERSTARTER
Added by an unidentified WORM or TROJAN! See here. Installed with the SpyBurner spyware remover - which is not recommended, see here
Win.exe smsger
Added by a variant of the SDBOT WORM!
wininits.exe softIce Update 32
Added by the RBOT-ANB WORM!
WNILOGON.exe SonudMan
Added by the QQROB-DC TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
WinSound1.exe Sound System
Added by an unidentified VIRUS, WORM or TROJAN!
Wifiusb.exe Speedport W 100 Stick WLAN Manager
Wireless management utility for the Speedport W 100 Stick WLAN USB stick
Wscript.exe OXNEY.B.VBS SPINX
Added by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "OXNEY.B.VBS" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
wys.exe Spool
WhileUSurf adware
websvc.exe Spooler SubSystem Application
Added by the DLOADER-NY TROJAN!
wintre.exe spoolsvs
Added by the SDBOT.EGQ WORM!
wincfy.exe spoolsvs
Added by a variant of the IRCBOT BACKDOOR!
Winllogo.exe SpyEx
Added by the PRSKEY-A WORM!
winproc32.exe SpywareGuard
Startpage adware Trojan
winmm64.exe SpywareGuardPlus
StartPage.ht homepage hijacker
wins32.exe sqservices
Added by the PROGENT-B TROJAN!
win16dll.exe srv32win
Screenspy captures screenshots silently. If you didn't install this yourself remove it
winsys.exe ssate.exe
Added by the BEAGLE.K WORM!
winerdir.exe ssgrate.exe
Added by the MITGLIEDER.O TROJAN!
winsystems.exe ssgrate.exe
Added by the BAGLEDL-J TROJAN!
wintems.exe ssgrate.exe
Added by the MITGLIEDER.Q TROJAN!
winssk32.exe SSK Service
Added by the SOBIG.E WORM!
windows.vbs Start
Homepage hijacker
windupds.exe Start Upping
Added by the SDBOT.AFH WORM!
windupdts.exe Start Upping
Added by a variant of the RBOT WORM!
win32i.exe startkey
Added by the BIFROSE-R TROJAN!
winampXP.exe startkey
Added by the BIFROSE-OY TROJAN!
winlogin.exe startkey
Added by the BIFROSE-PM TROJAN!
WinlogonStartup Startup
Unidentified malware
wztoid.exe Startup Configuration
Added by the RBOT-ASD WORM!
w32main2.exe stgclean
Related to IBM Standard Software Installer. What does it do and is it required?
wkfxi.js stmha
Added by the SPETH WORM!
wuauclt14.exe StreamAppliance
Added by the RBOT-GMB WORM!
wuauclt16.exe StreamAppliance
Added by the RBOT-GME WORM!
winscrne.exe STV
Added by a variant of the SDBOT WORM!
winsfcm.exe SurfinGuard Pro
SurfinGuard Pro from Finjan - internet protection software, protects against all malicious code delivered through executables, scripting files, ActiveX and Java
WINAGENT.EXE SvcH0st
Added by the EB TROJAN!
winhost.exe Svchost
Added by the LOLAWEB.A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
winhelp.exe svchost
Added by the GAOBOT.GEN!POLY WORM!
winampXP.exe svcshare
Added by the FUJACKS-J VIRUS!
winwd.exe SWd
PC Security from Tropical Software - lock files, password protect, etc
Win32x.exe Sygate Personal Firewall
Added by the RBOT-KZ WORM!
wins.exe Sygate Personal Firewall
Added by the RBOT.AOB WORM!
winxpstat.exe Sygate Personal Firewall
Added by a variant of the RBOT WORM!
win31243.exe Sygate Personal Firewall
Added by a variant of the IRCBOT TROJAN!
winupdate.exe Sygate Personal Port Blocker
Added by a variant of the RBOT WORM!
windows .exe Symantec Antivirus professional
Added by a variant of the FORBOT WORM!
Winhp32.exe Symantec Antivirus professional
Added by a variant of the FORBOT WORM!
winudp.exe Symantec Antivirus professional
Added by a variant of the WOOTBOT WORM! See here
winsync.exe syncman
Added by the MANCSYN-A TROJAN!
windows32.exe Syntax
Added by the SDBOT.CQ WORM!
wuapdxe.exe Sys-Stat
Added by the SDBOT.HK WORM!
win***32.exe [* = random char] Sys29
EliteBar adware
win***32.exe [* = random char] SysA
EliteBar adware
win.hta Syscheck
Browser hijacker
wincfg32.exe SysConfig
Added by the SDBOT.ZD WORM!
winupdate.exe Sysctrls
Added by an unidentified WORM or TROJAN!
win32dll.exe Sysctrls
Added by a variant of the IRCBOT BACKDOOR! See here
winrun.exe sysdir
Added by the WINBUR.B WORM!
wininit32.exe SysInit
Added by the XABOT WORM!
wowexece.exe SysMon
Added by the MULAN-A TROJAN!
WWE DIVAS.exe SysRes
Added by the ELIPTER.D WORM!
WINL0G0N.EXE System
Added by the BANCOS-DB TROJAN!
wumgrd32.exe System
Added by a variant of the RBOT WORM!
windowsps.exe System
Added by a variant of the RBOT WORM!
wiinlogon.exe SYSTEM
Added by the RBOT-AVG WORM!
winupd.exe System
Added by a variant of the SDBOT WORM!
wsscntfy.exe System
Added by a variant of the SDBOT WORM!
windmupdr.exe SYSTEM
Added by a variant of the RBOT WORM!
win_klr32.exe System Check
Added by the DELF-DRA WORM!
wasul.exe System Checking
Added by the RBOT.BHM WORM!
wins.exe System Document Application
Added by the SDBOT.AUB WORM!
wingmt.exe System Drivers
Added by the SDBOT-MG WORM!
win.exe System Information Manager
Added by the SDBOT-MU WORM!
windowsNt.com System Information Manager
Added by the SDBOT-ND WORM!
winsrv32.exe System Manager
Added by an unidentified WORM or TROJAN!
winsvc.exe System Manager Updates
Added by the AGOBOT.AEM WORM!
wmisg.exe SYSTEM MESSAGER
Added by the MYTOB.ES WORM!
wupdmgr.exe System Update
Added by the SOROMO-A TROJAN!
wauluclt.exe System Update
Added by the SDBOT.EF WORM!
wmiprvsa.exe System Update Service
Added by the AGOBOT-RG TROJAN!
winupd32.exe System Update Service
Added by the ADTODA-A TROJAN!
wmiprvsv.exe System Update Service
Added by the AGOBOT.YG WORM!
webcheck.exe System Update2
Added by the AUTOTROJ-C TROJAN!
wininet.exe System Update2
Added by the AUTOTROJ-C TROJAN!
winlogon.exe System Update2
Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
winspool.exe System Update2
Added by the AUTOTROJ-C TROJAN!
wupdmgr.exe System Update2
Added by the AUTOTROJ-C TROJAN!
wmiprvsw.exe System Updater Service
Added by the GAOBOT.AFC WORM!
winsci.exe System Updates
Added by a variant of the RBOT WORM!
wmkl.exe System Updates
Added by the RBOT-AYJ WORM!
winserv32.exe System Updates Manager
Added by the AGOBOT-AGA WORM!
winds32.exe System32
Added by the DWNLDR-HFY TROJAN!
Wincmp32.exe SystemAdministration
Added by the ASYLUM TROJAN!
WinMedia.exe SystemMigration
Added by the KELVIR.EI WORM!
WINREG.EXE SystemReg
Added by the DEWIN.A TROJAN!
windrives.exe Systems Backups
Added by the AGOBOT-RB WORM!
Windows2.exe systems usb driver
Added by a variant of the RBOT WORM!
wekls4.exe SystemTray
Added by a variant of the IRCBOT TROJAN!
Windowsupd.exe SystemTray
Added by a variant of the IRCBOT TROJAN!
winkernal.exe systhread
Added by the LIAMED WORM!
w32explorer.exe Systray
Added by the RBOT-AJY WORM!
winrxd64.exe sysygm64
Added by the IRCBOT-RK TROJAN!
Wink3sk9.exe T4skM4n4g3r
Added by a variant of the IRCBOT TROJAN!
wualcts.exe Task Help
Added by a variant of the RBOT WORM!
winampa.exe Taskmon driver
Added by the LOONY-I TROJAN! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of the Program Files directory whereas this file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
websvc.exe Tcp Application Manager
Added by the DLOADER-NY TROJAN!
winlogon.exe TEXTCONV
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
wind0s.exe ThE
Added by an unidentified WORM or TROJAN!
wscript zshell.js Time Zone Synchronization
Added by the NETDEX-A TROJAN!
Watcher.exe Tiny Watcher Logon Time
Tiny Watcher detects changes to your system. It will not prevent your system from being modified or corrupted. It will only tell you that something suspicious happened. Think of it as an early CAT scan against system tumors. Better to install a tool that will detect and remove bad items
WINLOGON.EXE Torjan Program
Added by the WOWCRAFT.D TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! This trojan file is found in the Windows or Winnt folder
WinLED.exe Touch Manager
Dell keyboard utility. Disabling can result in loss of screen saver and power saver functionality
wincool.exe Tour
Component of WinME that's annoying as hell. Pop's up a prompt to play the C:WINDOWSApplication DataMicrosoftINTROCONTENT.HTA that plays a full screen version of the WinME product preview Windows Media video file that cannot be stopped to my knowledge until it finishes. That prompt will keep popping up after an install/reinstall of WinME until you give in and watch the thing. It also puts a task scheduler entry to run that annoying thing every 30 minutes, and don't bother deleting that entry, Windows puts it right back. Not only should you disable it from running, you should delete the thing altogether, as it, somehow can re-enable itself. Apparently you can try setting the file to read only
Weatherbug.exe Tray Temperature
Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs
winppr32.exe TrayX
Added by the SOBIG.F WORM!
wins32.exe Tsk Mng Hlp
Added by the AGOBOT-JB WORM!
WinManager.Exe Tweak Manager
WinGuides Tweak Manager. Is this required for the live updates feature and/or if settings are changed?
winter.exe Undefined
Added by the KILLAV.LW TROJAN!
WinUPPD.exe Universal Plug & Play devices
Added by an unidentified WORM/TROJAN!
winlogom.exe Updade Windows
Added by the TONAX-A TROJAN!
wupdata.exe UpData
Added by the IRCBOT-AA TROJAN!
winis.exe update
Added by the RBOT-VD WORM!
WinUpdater5.0.vbs UPDATE
Added by the GORMLEZ-A WORM!
winlog.exe Update Checker
Added by the IRCBOT-TJ TROJAN!
WiseUpdt.exe Update Grokster
Automatically updates the Grokster file sharing software. Beware of adware and spyware when using this type of program, for instance, Grokster contains CyDoor
winu32.exe Update Service
Added by the RBOT-MG WORM!
winx.exe update service
Added by a variant of the RBOT WORM!
WiseUpdt.exe Update TUT
??
winstall.exe UpdateCheck
Added by the SPYBOT-CY WORM!
wupdater.exe updater
eUniverse/KeenValue adware
wisvc.exe updater
Added by the ORSE-A TROJAN!
winload32.exe updater32
Added by the CULT.M WORM!
wservice.exe UpdateService
Added by the DREF-K WORM!
winit.exe upddateit
Added by the RBOT-MS WORM!
winupd.exe Upgrade Service
Added by the TOFGER-U TROJAN!
WinSVCservice.exe UPNPService
Added by the AGOBOT.UN WORM!
wjview ...Code UpromiseRemindU
Part of the Upromise saving scheme but associated with Ebates MoneyMaker adware so the choice is yours
web.exe UPSUtl
CoolWebSearch parasite variant
WinUp.exe UpTimes service
Added by the RBOT-AKB WORM!
winlogon.exe urudjeffni
Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
Winsys32.exe USB 2.0 Driver
Added by the AGOBOT-QM WORM!
winsystem.exe USB 2.0 Driver
Added by the AGOBOT-QS WORM!
winupdate1.exe USB 2.1 Driver
Added by a variant of the RBOT WORM!
win32usb.exe USB Device
Added by the FORBOT-BQ WORM!
wuservices.exe USB Fix 1.1
Added by a variant of the SDBOT WORM!
wuafix.exe USB Fixes
Added by the RBOT-ABV TROJAN!
wugfixx.exe USB Updates 2
Added by a variant of the RBOT WORM!
wmmndir.exe USBConfigration2
Added by the AGOBOT-SV WORM!
winlogon.exe userinit
Added by the DLOADER-TP TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
WMPVer.EXE v
Dritek System Inc. 3D Mouse related. Is it required?
WebLifeDisk.exe VDrive2
EarthLink WebLife Disk - "Consumers can quickly save files from their desktop into WebLife Disk, and then easily access them from any Internet connection without taking a laptop on the road or keeping up with a USB key"
winamp32.exe Video
Added by the AGOBOT-NG WORM!
wcamfrog.exe Video Camera Frog
Added by a variant of the IRCBOT TROJAN! See here
winaps.exe Video Proces
Added by the AGOBOT.HD WORM!
winasp.exe Video Process
Added by the AGOBOT-IS WORM!
wincert32.exe Video Process
Added by the AGOBOT.JT WORM!
winit.exe virtual
Added by the MUGLY.A or MUGLY.B WORMS!
winprotect.exe virtual
Added by the MUGLY.C WORM!
wini.exe virtual
Added by the RBOT-YX WORM!
winlogi.exe virtual-ie
Malware - detected by Kaspersky as the WINAD.H TROJAN!
winlogin.exe virtual-machine
Added by the RBOT-VU WORM!
wini.exe virtual-machine
Added by the RBOT-WR WORM!
winxpsock.exe Vsample
Added by the SDBOT.BLK WORM!
WINLOGON .exe W1N32.DLL
Added by the DROPPERFL.A TROJAN!
w32.exe w32
Added by the SOKEVEN TROJAN!
wiper.exe W32PluginsDownloaderXMLHTTPSelfClearing7520
Added by the PROXYSER-M TROJAN!
w32sup.exe w32sup
Adult content dialler
w32sys.exe W32SYS
Added by the JAMBU-A WORM!
WTC32.scr W32Tc
Added by the VOTE.D or VOTE.K WORMS!
W75P2PS.EXE W75P2PSERVER
Printer utility which is required in order to make the printer work correctly
w7zip.exe w7zip
Added by the BANCBAN-QB TROJAN!
W815DM.exe W815DM
Enuff Parental Control Software by Akrontech
w98Eject.exe w98Eject
Related to USB support for Sigmatel MP3 audio palyer (and others such as SanDisk). It's intent is to "put away" the "disk" before you unplug it from the USB port, ostensibly to avoid "losing" data
wab.exe wab.exe
Added by a variant of the SDBOT WORM!
wait4IP.exe wait4IP
Packard Bell net2Plug allows you to network PCs anywhere in your house
Wallchgr.exe wallchgr.exe wstart
WallChanger - wallpaper changer from Blue Tree Software
wallmast.exe WallMaster
WallMaster - "The free and easiest way to master your desktop wallpaper!"
WALLPA~1.EXE WallPaper
Wallpaper Changer - wallpaper manager that can change your background images on every startup
Wallpaper.exe WallpaperChanger
A wallpaper changer and manager utility. There is the Freeware version and the Pro version. The freeware version is completely free. The Pro version is 30-day trialware, and after the 30 days some of the more advanced features will be disabled unless you register it
WallpaperSS.exe WallpaperSS
Wallpaper Slideshow LT from gPhotoShow.com - "a great utility for displaying your favorite photos as your desktop wallpaper"
Wanadoo Messenger.exe Wanadoo Messenger.exe
Wanadoo ISP instant messenger client
wanman.exe wanman.exe
Added by the RBOT.HDO WORM!
WanMPSvc.exe WanMPSvc
An AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling AOL doesn't help
wts**.exe [* = random char] WAPI
PurityScan/Clickspring adware
wartray.exe War FTPD Tray Icon
War-ftpd - FTP server
WAR-FTPD.EXE war-ftpd.exe
War FTP Daemon from JGAA's Internet - FTP client
WareOut.exe WareOut
Wareout - malware masquerading as a spyware and dialer remover
warez.exe warez
Warez P2P client
warner.exe Warner
Also known as "CyberWarner". From G-Tek Technologies and pre-installed on some Packard Bell PCs. Protects critical files
warnet.exe Warnet
Warnet - system cleanup software
WarReg_PopUp.exe WarReg_PopUp
Acer warranty registration popup
war-ftpd.exe WARSVR
"War FTP Daemon - the original free FTP server for windows"
washer.exe Washer
Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
washerie.exe Washerie.exe
Cookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer, specific for cleaning the IE cache and cookies. Available via Start -> Programs
washidx.exe washindex
Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
wast.exe Wast
Grokster ads updater
watch.exe Watch
Found to be used by a Trust USB scanner for auto starting the scanning software when the lid is lifted
watchdog.exe Watch Dog Program
For Compaq PC's. Associated with Compaq's internet services. Not required if you don't use services provided by them and may not be required even if you do
Watchdog.exe Watchdog
Definitely part of the Mustek scanner drivers and software (for 600 III EP Plus and maybe others), launches from the Startup folder in the Start Menu, but not required as they give instructions on removing it on their webpage
watchdog.exe WatchDog
Part of Motorola "Mobile Phone Tools" v3 - in a "Mobiile Phone Tools" sub-directory of Program Files
WatchWAN.exe WatchWAN
WatchWAN keeps an accurate account of the data that is flowing between your computer and the Internet at any given moment. This readout is presented in both numerical and graphical format, in real time
waumgr.exe waumgr
Added by a variant of the IRCBOT TROJAN!
WaveFramer.exe WaveFramer
Part of SafeSpace (from Artificial Dynamics) which "protects computers from Internet malware infection without the need for signature updates or regular maintenance"
WaveTop.exe WaveTop Launcher
WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
WiFiMsg.exe WAWifiMessage
"HP Wireless Assistant is a user application that provides a method for controlling the enablement of individual wireless devices (such as Bluetooth or WLAN devices) and that shows the state of the radios for these wireless devices"
wbcmgr.exe Wbcmgr
Added by a variant of the IRCBOT BACKDOOR! See here
wben.exe wben
Appears to be related to Desktop Notifier from Starfield Technologies. What does it do and is it required?
Wbiff.exe Wbiff
Wbiff! E-mail checker - automatically checks your e-mail and notifies you if any new e-mail has been received
Wbutton.exe Wbutton
Turns on and off the integrated WiFi on Acer (and other laptops)
WCESCOMM.EXE WCESCOMM
Active sync for use with Windows CE based palm PC
WCEMNGR.EXE WCESMngr
Added by the AGOBOT-QX WORM!
WCheckUp.exe WCheckUp
Barok keylogger and password stealer
wcmdmgrl.exe wcmdmgr
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
wcmdmgr.exe wcmdmgr.exe
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
wcmdmgrl.exe wcmdmgrl
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
wintsvcc.exe WCPC
??
wintsvit.exe WCPI
PurityScan/Clickspring adware
Wint**.exe [* = random char] WCPS
PurityScan/Clickspring adware
wintsvtr.exe WCPT
PurityScan/Clickspring adware
wcsys.exe wcsys
Added by the KEYLOG-AP TROJAN!
WDBtnMgr.exe WD Button Manager
Button manager installed with a western digital external disk drive. Allows you to back up your system with one click
wdfmgr32.exe wdfmgr32.exe
Added by the DWNLDR-FVL TROJAN!
wdinfo.exe WDInfo
Added by the DLUCA.B TROJAN!
wdmon.exe wdmon
Detected as the BUZUS.DVE TROJAN!
wdns33.exe WDNS SYSTEM
Added by the MYTOB-BY WORM!
wdskctl.exe wdskctl
IEPlugin spyware
wdwctrl.exe wdwctrl
Added by the DLUCA.E TROJAN!
WD_SRT.EXE WD_SRT
Western Digital USB disk driver
WEATHER.EXE WEATHER
Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs
weatherpulse.exe Weather Pulse
Weather Pulse from Tropic Designs. "Display popular Satellite images and video from around the globe, share images with your friends and family, stay updated on current and expected weather conditions, it's just plain fun!"
Weather.exe WeatherCast
Weather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight
WeatherEye.exe WeatherEye
WeatherEye - desktop weather from TheWeatherNetwork
WeatherOnTray.exe WeatherOnTray
Hotbar adware
Weatherscope.exe Weatherscope
WeatherScope - "displays your current local temperature in the system tray of your computer (near the clock) whenever you are online!" Not recommended as it bundles GAIN adware. You can get the adware free version for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here
WeatherStudio Desktop.exe WeatherStudio Desktop
WeatherStudio adware
ww.exe WeatherWatcher
WeatherWatcher - weather reporting in the System Tray
Web2Pop.exe Web2Pop
Web2Pop allows you to retrieve your web-based accounts messages to read them in your favorite e-mail client
web3trap.exe web3trap
PC-Cillin 2000 anti-virus software → ActiveX filter. Guards against malicious ActiveX programs, etc
webalize.exe webalize
Searchcentrix hijacker
WAK.exe WebArmyKnife
Web Army Knife - a suite of web site developer's tools
webassist.exe webassist
Adware popup generator
webbuying.exe WebBuying
WebBuying adware
WebCallDirect.exe WebCallDirect
WebCallDirect - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype
webcam.exe webcam
Added by the MONAD-A TROJAN! Note - this malware actually changes the default value data of the Registry Run and RunServices keys in order to force Windows to launch it at boot. Name field may be empty
wbcgosvc.exe Webcam Go Sti Service Application
Control software for the portable Creative Webcam Go digital camera/PC web cam. What does it do and is it required?
WEBCAMRT.exe WebcamRT.exe
For Logitech Web Cams. Not required - camera works fine without it
webcel.exe Webcelerator
Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Now no longer available and supported and when available was classed as spyware - see here
WebCheck.pif WebCheck
Added by the CONE.C or CONE.F WORMS!
WebCpr0.exe WebCpr0
WebRebates adware
webdav.exe Webdav.exe
IRC DDoS bot which gives the hacker full control over your system
whagent.exe WebHancer Agent
System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here
whSurvey.exe webHancer Survey Companion
WebHancertrackware - traffic measurement service that uses a client agent that is stealth installed on user machines, gathering detailed data about sites visited, their performance and, most important, what the user actually does while there
WebInstall.exe WebInstall
ClipGenie adware downloader
WebInstall.exe WebInstall2
ClipGenie adware downloader
WebKey.exe WebKey
WebKey from JB Utilities. Utility to keep track of login data required when browsing the internet
WebLink.exe WebLink
Softex is a "cost-effective way to provide software updates, technical support or new product information to specific end-users - it can silently provide end-users with software updates, technical support and new product information customized to their specific needs through a persistent link"
wpsche~1.exe Webposition Gold 2
Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines
WebRebates0.exe WebRebates0
WebRebates adware
WDF.exe Webroot Desktop Firewall
Webroot Desktop Firewall
websaverlive.exe websaverlive
WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your computer is idle
WebSavingsfromEbatesrun.exe WebSavingsfromEbates
Web Savings From Ebates Software, a shopping tool that opens pop-up windows
WebSavingsFromEbates0.exe WebSavingsFromEbates0
Web Savings From Ebates Software, a shopping tool that opens pop-up windows
WebScanX.exe WebScanX
From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc
wjview ...websearch.exe websearch
"Web Savings" From Ebates Software, a shopping tool that opens pop-up windows
WebSecureAlert.exe WebSecureAlert
WebSecureAlert - "helps to protect your browser security by monitoring for unauthorized tampering with Internet Explorer's security settings, and can help to protect your privacy by deleting your web surfing history on a regular basis". Not recommended as it bundles GAIN adware. You can get the adware free version for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here
Webshots Tray.exe Webshots
Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web
websho~1.exe Webshots
Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web
WebshotsTray.exe Webshots
Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web
webadmin.exe Website Administrator Info
Added by the FORBOT-FY WORM!
wupda.exe WebSUpdater
Detected by Kaspersky as the STARTPAGE.C TROJAN! See here
webtrap.exe Webtrap
Part of PC-Cillin anti-virus software. Checks web-sites for malicious Java and ActiveX elements in a similar way to McAfee WebScanX. A few users find it infuriating
WebTrapNT.exe WebTrapNT.exe
Part of PC-Cillin Anti-Virus software. Checks visited web-sites for malicious Java and ActiveX elements
wwasher.exe WebWasher
Free Pop-up/ad/javascript filter program from Siemens. If not running then browsers will not be protected but will still work. Available via Start -> Programs
WeirdOnTheWeb.exe WeirdOnTheWeb
Added by the WeirdOnTheWeb adware
Welcome.exe Welcome
Launches the Welcome to Windows tutorial on boot up
Wepstat.exe WEPstat
Cisco Aironet 340 Series PC Card driver. If it can be started manually it shouldn't be required if you don't use the PC card facility regularily - hence the status could be "U". Can anybody confirm this?
wiustv.exe wesumu
Added by the QQPASS-L TROJAN!
wetsock.exe WetSock
RoboMagic Wetsock - weather reporting in the System Tray
WFGStartup.exe WFGStartup
World Weather. "This midlet displays the current weather conditions for major cities around the world. This version is for memory limited mobile phones"
WFXCTL32.EXE WFXCTL32.EXE
From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
wfxsnt40.exe wfxsnt40
WinFax 10.0 and maybe earlier versions. The program that opens the port for WinFax and not normally in the start menu. Needed if you want to run WinFax
WFXSWTCH.exe WFXSwtch
Related to WinFax. What does it do and is it required?
WG511WLU.exe WG511WLU
Netgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card
wgeax.exe wgeax
Added by the IRCBOT-TM WORM!
wgs3.exe wgs3
Added by the LEGMIR-AQH TROJAN!
WGV.exe WGV
Added by the ZIPPIE TROJAN!
WGWLocalManager.exe WGWLocalManager
Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so. It could be started by creating a shortcut, running it only when connecting to the internet. If internet is used often, it's recommended to leave it in startup so it starts with the system
WgwMngr.exe WgwMngr
Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so
whagent.exe whagent
System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here
WHATPU~1.EXE WhatPulse
WhatPulse keeps track of your keystrokes, allowing you to find out just how much you type a day
whse.exe WhenUSearchWHSE
WhenU.Save adware
whismng.exe Whistler
Added by the WHISTLER-F TROJAN!
Whvlxd.exe Whvlxd
Added by the ZAPCHAS-CS TROJAN!
wiascr.exe wiascr
Added by the AGENT.AM TROJAN! Note - example names include "XviD", "Winamp Remote", "Windows Media Player" and "Futuremark"
wifeman.exe wifeman
Unidentified malware
wifiboot.exe Wifi Boot
Added by a variant of the IRCBOT TROJAN! See here
wifibooter.exe Wifi Booter
Detected by Trend Micro as the IRCBOT.GP TROJAN! See here
wificonfig.exe Wifi Configuration
Added by the CHECKOUT WORM! See here
wificonfigs.exe Wifi Configuration!
Added by the CHECKOUT WORM! See here
wificon.exe Wifi Connection
Detected by Trend Micro as the SLENFBOT.AC TROJAN! See here
wificonnect.exe Wifi Connection!
Added by the CHECKOUT WORM! See here
wifidebug.exe Wifi Debug
Added by a variant of the IRCBOT TROJAN! See here
wifiload.exe Wifi Loader
Detected by Trend Micro as the IRCBOT.AVG TROJAN! See here
wifiloader.exe Wifi Loader!
Added by a variant of the IRCBOT TROJAN! See here
wifisetup.exe Wifi Setup
Added by a variant of the IRCBOT TROJAN! See here
WildFlics.exe WildFlics
Direct-B premium rate adult content dialler
wcmdmgrl.exe WildTangent Web Driver updater
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
WWMon.exe Wildwire Monitor
This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem
WillowRoad.exe Willow Road
Willow Road Screen Saver
WillPolo.vbs WillPolo
Added by the VBS_SOLOW.AF VIRUS!
windows.exe WIN
Added by the REATLE.C WORM!
Win Antivir 2008.exe Win Antivir 2008
Win Antivir 2008 rogue security software - not recommended, see here
Win Antivirus 2008.exe Win Antivirus 2008
Win Antivirus 2008 rogue security software - not recommended, see here
winchi~1.exe Win Chimes
WinChimes - enhancement software for the system clock that runs in the system tray
WinComm.exe Win Comm
Added by the WINCOM TROJAN!
winconfig.exe Win Config
Added by a variant of the IRCBOT BACKDOOR! See here
wuctl.exe win ctl app
Added by a variant of the SDBOT WORM!
windfrag.exe Win Defrag
Added by a variant of the SDBOT WORM! See here
windefrag.exe Win Defrag!
Added by a variant of the SDBOT WORM! See here
WIN HOST PROCESS.EXE WIN HOST PROCESS
Added by the KEYLOGGER.CLONE TROJAN!
winampa.exe Win l5oahder
Added by a variant of the RBOT WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of the Program Files directory
winlogin.exe Win Login
Added by the RBOT-AWE WORM! Note - this trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder
win14.exe Win Microsoft 98
Added by the RBOT-AKX WORM!
winupdates.exe Win Process Updates
Added by a variant of the SDBOT WORM!
winsecure.exe Win Security
Detected by Trend Micro as the IRCBOT.AVE BACKDOOR! See here
winserv.exe Win Server
Added by the IMISERV.A TROJAN!
wupdt.exe Win Server Updt
Added by the IMISERV.A TROJAN!
winserver.exe Win Server Updt
Added by a variant of the IMISERV TROJAN!
winsyncupx.exe Win Sync montr
Detected by Kaspersky as the RBOT.BYJ TROJAN! See here
wupda32.exe win update
Added by the SDBOT.J WORM!
wapdate.exe win update
Added by a variant of the RBOT WORM!
WINUPDATER.EXE Win Updater
Added by the RBOT.IP WORM!
winusb.exe WIN USB 2.0
Added by a variant of the RBOT WORM!
winamp.exe Win WinAmp
Added by the RBOT.AGF WORM! Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of the Program Files directory. This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
win*************.exe [* = random digit] win************* [* = random digit]
WINBO adware
WIN-BUGSFIX.EXE WIN-BUGSFIX
Added by the LOVELETTER (I LOVE YOU) VIRUS!
winis.exe win-xp
Added by the BROPIA.N WORM!
win.exe win.exe
Added by the PODROP-C TROJAN!
win16dll.exe win16.dll
Screenspy captures screenshots silently. If you didn't install this yourself, remove it
win23.exe win23.exe
Detected by Kaspersky as the BIFROSE.BSJ TROJAN! See here
WIN32.EXE WIN32
Added by the RATEGA TROJAN!
Win32.exe Win32
Added by the ISRAZ.A WORM!
winsrv32.exe win32
Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites
WinSetup.exe win32
Added by the EVILBOT.B TROJAN!
winhost.exe win32
Added by the BROPIA.J WORM!
winnnit.exe Win32
Added by a variant of the SDBOT WORM!
Winbios.exe Win32 Bios
Added by the SEMAPI-A WORM!
Win32.exe Win32 Critical File
Added by the RBOT-GUB WORM!
Win32Debug.exe Win32 Debug Manager
Added by a variant of the WOOTBOT WORM!
Win32ldr.exe Win32 Device Loader
Added by a variant of the AGOBOT/GAOBOT WORM!
winlogons.exe Win32 Drivers
Added by the FORBOT-FG WORM!
wdrk32.exe Win32 DRK Driver
Added by the WOOTBOT.CY WORM!
winstr32.exe Win32 exe file
Added by a variant of the SPYBOT WORM!
winfw.exe Win32 Firewall Driver
Added by a variant of the RBOT WORM!
win32help.exe Win32 Help32 Service
Added by the DELBOT-U WORM!
windowsnfo.exe Win32 Info
Added by a variant of the IRCBOT TROJAN!
winserver.exe win32 internet server
Added by the DERMON-D TROJAN!
win32update.exe Win32 Kernel Update
Added by the PROXY-BS TROJAN!
winwkys.exe Win32 Services Config
Added by the RBOT.BKY WORM!
wuamngr1.exe Win32 Services1
Added by the SDBOT-PV WORM!
win32src.exe Win32 Src Service
Added by the RBOT-SX WORM!
winssv.exe Win32 SSL Driver
Added by the FORBOT-BH WORM!
winservice.exe Win32 System Kernel
Added by the SDBOT.KIN WORM!
winserver.exe win32 system server
Added by the DERMON-A TROJAN!
winxpinit.exe Win32 USB Driver
Added by the SDBOT.AA TROJAN!
wins32.exe Win32 USB2
Added by a variant of the RBOT WORM!
win32usb.exe Win32 USB2 Driver
Added by the SPYBOT.DHV WORM!
wind32.exe Win32 USB2 Driver
Added by the FORBOT-AH WORM!
winupdate.exe Win32 USB2 Driver
Added by the AGOBOT.YE WORM!
winsnd32.exe Win32 USB2 Driver
Added by a variant of the SDBOT WORM!
w32usb2.exe Win32 USB2.0 Driver
Added by the SPYBOT.DN WORM!
win32tool.exe Win32 USB3 Driver
Added by a variant of the RBOT WORM!
winitr32.exe Win32 Wmls Driver
Added by the WOOTBOT.B WORM!
win32.exe win32.exe
Added by the STARTPAGE TROJAN!
Win32.exe Win32.exe
Added by the AWQ.A TROJAN!
Wintask.exe Win32BaseServiceMOD
Added by the NAVIDAD WORM!
win32sys4.exe win32beta
Added by the BANKER-DA TROJAN!
win32clf.exe win32clf
Added by an unidentified VIRUS, WORM or TROJAN!
win32debug.exe win32debug
Added by the GUDEB WORM!
Win32DLL.vbs Win32DLL
Added by the LOVELETTER (I LOVE YOU) VIRUS!
Win32dll.exe Win32dll
Added by the BANPAES TROJAN!
win32gb.exe win32gb
Added by the DLUCA-F TROJAN!
webemir.exe Win32Host Process
Added by the TURGEN -A TROJAN!
win32info.exe win32info
Adult content dialler
Win32sl.exe WIN32SL
Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. The specific function of this is to load MIF's in order for Dell OpenManage Client to work
win32s.exe Win32System
Added by the MYDOOM.V WORM!
win32us.exe win32us
All-In-One-Telcom (adult content dialler) variant
WinCab.exe Win32Usr
Added by the DEDMIR-A WORM!
win32_i.exe win32_i lptt01
RapidBlaster variant (in a "win32_i" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
win32_i.exe win32_i ml097e
RapidBlaster variant (in a "win32_i" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
Win386.exe Win386
Added by the GOSUSUB VIRUS!
winabsmod.exe WIN3S2SNDS
Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well"
winiprtx.exe WIN3S2SNDS
Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well"
wingrd.exe win98 DNS
Added by a variant of the RBOT WORM!
winable.exe WinAble
Added by the MATCASH.BG TROJAN!
Winacsr.exe Winacsr
AceScreenSpy keystroke logger/monitoring program - remove unless you installed it yourself!
WINACTIVE.EXE winactive
WinActive of the LOP.com hijacker
WinActiveJ.exe WinActiveJ
Added by the ROTARRAN VIRUS!
Winad.exe Winad Client
WinAd adware by eXact Advertising
WinAdCnt.exe WinAdCnt.exe
Added by the BANKER-BU TROJAN!
winadm.exe winadm
Browser hijacker - redirecting to Search-World.net. Related to the SMALL.AEX TROJAN!
WinAgent.exe WinAgent
Standard Life Insurance program. Is it required at startup?
Winahlp.exe Winahlp.exe
Added by a variant of the VAGRNOCKER TROJAN!
winallap.exe winallap
Added by the DELF.E TROJAN!
winallapu.exe winallapu
Added by the DELF.E TROJAN!
winamp.hta Winamp
Hijacker - re-directing to adult content sites. Note - this isn't the real Winamp
winamp.exe Winamp
Added by the AGOBOT.XI WORM! Note - this is NOT the popular Winamp media player
winamp62.exe WinAMP
Added by the SDBOT-WN WORM!
winamp.exe Winamp
Winamp media player. Resides in a "Winamp" subdirectory of the Program Files directory
winamp.exe Winamp Agent
Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player. The valid filename for the Winamp Agent is "winampa.exe" - see here
winapa.exe Winamp media player
Added by an unidentified VIRUS, WORM or TROJAN!
winamap.exe Winamp Media Player
Detected by PCTools as the SDBOT.ACJM BACKDOOR! See here
winamp.exe Winamp Media Player
Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of %ProgramFiles%
winampp.exe WinAmp Player
Added by the RBOT-AQI WORM! Note - this is NOT the popular Winamp media player which has a different filename
Winamp6.exe Winamp Player 6
Added by a variant of the SPYBOT WORM!
winamptogoogletalk.exe Winamp to Google Talk
Winamp to Google Talk, available here shows your current Winamp track in your Google Talk status
WINAMPa.exe Winampa
Loads the System Tray icon for the popular Winamp media player - see here. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs. Resides in a "Winamp" subdirectory of the Program Files directory
winampa.exe Winampa
Added by the AGOBOT-GS TROJAN! ! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of the Program Files directory whereas this file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
WINAMPA.EXE Winampa Agent
Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player. The valid filename for the Winamp Agent is "winampa.exe" - see here
WINAMPa.exe WinampAgent
Loads the System Tray icon for the popular Winamp media player - see here. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs. Resides in a "Winamp" subdirectory of the Program Files directory
Winagent.exe WinAmpAgent
Added by the EB TROJAN! Note - this is NOT the popular Winamp media player which has a different filename
was5.exe WinAntiSpyware 2005
WinAntiSpyware 2005 spyware remover - not recommended, see here
was7.exe WinAntiSpyware 2007
WinAntiSpyware 2007 spyware remover - not recommended, see here
WinAntispyware2008.exe WinAntispyware2008
WinAntispyware2008 rogue spyware remover - not recommeded, see here
WinAV.exe WinAntiVirus Pro 2007
WinAntiVirus Pro 2007 misleading virus software - not recommended, see here
winapix.exe WinApi
Added by a variant of the TIBSER.A downloader TROJAN!
WINAPLOGUPD.EXE WINAPLOGUPD
Added by the CAPSIDE-C WORM!
winpup32.exe Winapp
Produces popup ads to adult content sites
winlogon.exe WinAuth
Hijacker, also indentified as the STRTPAGE.BE TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
WinAvX.exe WinAvX
WinAntiSpyware spyware remover - not recommended, see here
WinAvXX.exe WinAVX
Added by the FAKEAVALERT TROJAN!
WinAwk.exe WinAwk
Added by the SDBOT-AYF WORM!
Wbsched.exe WinBackup Scheduler
LIUtilities WinBackup scheduler - backup software
WinBar.exe WinBar
"WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls"
winbed.exe Winbed
Hijacker
win32exe.exe winbin32
Added by the RBOT-ZL WORM!
winbo32.exe winbo32
Added by the RBOT-GRU WORM!
winboot.exe winboot
Added by the BANLOAD-W TROJAN!
winbot.exe winbot
Added by the MIDRUG-A TROJAN!
winbrush.exe WinBrush
WinBrush - "handy tool that keep your privacy and make your system clean. It works by cleaning up your tracks (document histories, recent opened files from popular software, cookies, temporary internet files, etc)"
WinButler.exe WinButler
Identified as a variant of the Trojan-Dropper.Agent.DKN malware
WinCheck.exe WinCheck
Added by the PWS-CY TROJAN!
winchost.exe winchost
Added by the DLOADER-PO TROJAN!
WINCIN~1.EXE WINCINEMAMGR
WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
WinCinemaMgr.exe WinCinemaMgr
WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
WinRemote.exe WINCINEMAMGR
InterVideo WinCinema Manager - needed for the use of WinDVD Remote Control
winclean.exe winclean
Added by the AGENT.GXR TROJAN!
wincmapp.exe wincmap
CasClient adware variant - also detected as the CMAPP TROJAN!
WinColorReminder.exe WinColorReminder
The Microsoft Color Control Panel Applet for Windows XP "helps you manage Windows color settings in one place." Part of the Pro Imaging Powertoys
WinCore32.exe WinCore32.exe
Added by the CLICKER-EN TROJAN!
wincrt32.exe WinCRT32
Added by the DOGBOT-D WORM!
winctl.exe winctl
Added by the IRCBOT-YI TROJAN!
wincore332.exe WINCX
Added by the AGOBOT-MG WORM!
wind.exe wind.exe
Added by the MITGLIEDER.BD TROJAN!
WIND0WS.exe WIND0WS
Added by the SPYBOT.DQ WORM!
wordpad.exe Wind0ws
Added by the AGOBOT-TL WORM! Note - this is not the legitimate Windows application wordpad.exe (which is found in the Program FilesAccessories folder) which should not normally be seen in Msconfig or as a Startup item. This file is loacted in the System (9x/Me) or System32 (NT/2K/XP) folder
Wind32.exe Wind32
Identified as a variant of the Backdoor.Win32.Poison.avs malware
windates.exe WinDates
WinDates is a calendar, date organizer and event reminder program from Rockin' Software
winxtc.exe windbs
Added by the AGOBOT-WD WORM!
winde.exe Winde
Added by the DLUCA TROJAN!
Win32sp.vbs windef
Added by the ANPES WORM!
windef.exe windef
Added by the WURMARK-O WORM!
windefender.exe windefender
Added by the AGENT.BYH TROJAN!
windhost.exe windhost.exe
Added by the BANKER-BV TROJAN!
winos.exe windhost.exe
Added by the PWSAGENT-A WORM!
winrun.exe windir
Added by the WINBUR.B WORM!
wuaumqr1.exe Windir Working
Added by a variant of the IRCBOT TROJAN!
Windll.exe Windll
Added by the TRYNOMA TROJAN!
WSYS.EXE WINDLL
STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes, all passwords transacted even if they weren't keyed in, all web sites visited, every program launched including the path to that program, and more"
windll32.exe windll
Added by the ASTEF or RESPAN WORMS!
Windll.exe Windll.exe
Added by the STEALER TROJAN!
Windll32.exe Windll32
Added by the MSNPWS TROJAN!
windllsys32.exe windllsys32.exe
Added by a variant of the MITGLIE-A TROJAN!
windns32.exe WinDNS
Added by the GAOBOT.WX WORM!
winmon32.exe Window Monitor
Added by the SDBOT.RT WORM!
wwDisp.exe Window Washer
Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
window.exe window.exe
Added by the MITGLIEDER.H or MITGLIEDER.J TROJANS!
wbload.exe WindowBlinds
WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins
Winex.exe WindowEnhancer
SCBar foistware variant
winupdatr.exe Windowfdgfds DasdLL Verifier
Detected by Trend Micro as the AGOBOT.HZ WORM! See here
Windowsdldfglcheckkk.exe Windowfdgfds DLL fgfdg Verifier
Added by the RBOT.CSP WORM!
winsecure.exe Windowfdgfds DLL fgfdg Verifier
Added by a variant of the RBOT WORM!
wfxload.exe WindowFX
Stardock WindowFX - "Allows you to add an unprecedented number of special effects to windows"
wiusyt.exe windown
Added by the QQPASS-M TROJAN!
wins.exe WindowRegKey update
Added by the SPYBOT.I WORM!
Windows.exe Windows
Added by the KAZMOR.A, BOBBINS & ALADINZ.D TROJANS!
windows.exe WINDOWS
Added by the MONBOT-A TROJAN!
WICleaner.exe Windows & Internet Cleaner Pro
Windows & Internet Cleaner Pro - "Powerful and easy to use internet surfing privacy protection & PC security software"
websvc.exe Windows .Net Manager
Added by the DLOADER-NY TROJAN!
win128.exe Windows 128 Module
Added by the FORBOT-ES WORM!
Win32edit.exe Windows 32 Editor
Added by the WOOTBOT.GQ WORM!
win32resc.exe Windows 32 Rescue
Added by the FORBOT-EU WORM!
Windows-Update.exe Windows 32 Update
Added by a variant of the RBOT WORM!
wauclt.exe Windows Account Alternation
Added by a variant of the IRCBOT TROJAN! See here
WinAdCtl.exe Windows AdControl
Windupdates adware variant
WinAdServ.exe Windows AdService
Windupdates adware variant
WinStat.exe Windows AdStatus
Added by the BLESHARE!DR VIRUS!
WinAdTools.exe Windows AdTools
Windupdates adware variant
Windows-Anti.exe Windows Anti Verifier
Added by the RBOT.ETT WORM!
winavscan.exe Windows Anti Virus Control Center
Added by a variant of the IRCBOT BACKDOOR!
walg32.exe Windows Application Layer
Added by the AGOBOT.ATN WORM!
walg32.exe Windows Application Layer Gateway
Added by the AGOBOT-AAZ WORM!
winlogon.exe Windows ARP Detectionc
Detected by Trend Micro as the RBOT.EAB WORM! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
winlogon.exe Windows ARP Detectioncx
Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!
winupdater.exe Windows Auto Update
Added by the SDBOT.TF WORM!
WINDOWSUPDATE.EXE Windows Auto Updater
Added by the SDBOT.PB WORM! Note that there is a space at the beginning of the filename, ie, " WINDOWSUPDATE.EXE"
wuamgrder.exe Windows Automatic Update
Added by a variant of the RBOT WORM!
windrg.exe Windows Automatic Updater
Added by a variant of the RBOT WORM!
winboot.exe Windows Boot
Detected by Trend Micro as the AGENT.HBD TROJAN! See here
windowsboot.exe Windows Boot
Added by a variant of the IRCBOT TROJAN! See here
winboot.exe Windows Booter
Added by a variant of the IRCBOT TROJAN!
winbooter.exe Windows Booter!
Added by a variant of the IRCBOT TROJAN! See here
WINDOWS CLEAN-UP PRO.Exe Windows Clean-Up Pro
Windows Clean-Up Pro spyware remover - not recommended, see here
winclean.exe Windows Cleaner Service
Added by a variant of the IRCBOT TROJAN! See here
wincmd.exe Windows Command
Added by the RBOT.ANV WORM!
wincomm.exe Windows Communicator
Added by the AGOBOT-BH WORM!
windowsconf.exe Windows Conf
Added by a variant of the IRCBOT TROJAN! See here
wins.exe Windows Config
Added by the SPYBOT.JR WORM!
winconfig.exe Windows Config
Detected by Trend Micro as the IRCBOT.BAP BACKDOOR! See here
Wincfg32.exe Windows Config Loader
Added by the SILVERFTP TROJAN!
winconf.exe Windows Config Manager
Added by the RBOT-AIT WORM!
wsys32.exe Windows Configuration
Added by the GAOBOT.FB WORM!
wincfg32.exe Windows Configuration
Added by the MYTOB.ED WORM!
winxupdate.exe Windows Configuration Utility
Added by the AGOBOT.LW WORM!
winconf.exe Windows Configurator
Added by a variant of the IRCBOT TROJAN!
wkssvc.exe Windows Console
Added by the SDBOT-DJX WORM!
wrasvc.exe Windows Console Component
Added by a variant of the IRCBOT TROJAN! See here
wnbsvc.exe Windows Console Norms
Added by a variant of the IRCBOT TROJAN! See here
wnbsvc.exe Windows Console Source
Added by a variant of the IRCBOT TROJAN! See here
WinCtlAd.exe Windows ControlAd
Windupdates adware variant
win32bootcfg.exe Windows Core Kernel Update
Added by the RANCK-EL TROJAN!
winbog32.exe Windows CPU host
Added by a variant of the RBOT WORM!
wincrt.exe Windows Critical Alert
Added by the ALEDO-A TROJAN!
WinDat.exe Windows Database
Added by an unidentified WORM or TROJAN!
wiinsvc.exe Windows Database
Added by the AGOBOT-RU WORM!
windde32.exe Windows DDE Loader
Added by the SDBOT-UZ WORM!
winlogg.exe Windows debug logging
Added by the RBOT-OY WORM!
winloggs.exe Windows debug logging
Added by the RBOT-QN WORM!
windbg.exe Windows Debugger
Added by an unidentified VIRUS, WORM or TROJAN!
windbg32.exe Windows Debugger
Added by the ZOTOB.L WORM!
wfdmgrsp.exe Windows Default Server
Detected by Kaspersky as the IRCBOT.BCX TROJAN! See here
winampa.exe Windows Default Server
Added by the IRCBOT.AUN WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of the Program Files directory
wdc*.exe Windows Defender
Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com
wda*.exe Windows Defender Adds
Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com
wdm*.exe Windows Defender Monitor
Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com
wdu*.exe