|
The table below includes any files beginning with w, from which further information can be found by clicking on the process title. The icon beside the information can be used to quickly determine if this is a safe file in combination with the key below:
[#] [A] [B] [C] [D] [E] [F] [G] [H] [I] [J] [K] [L] [M] [N] [O] [P] [Q] [R] [S] [T] [U] [V] [W] [X] [Y] [Z] |
Files beginning with w:
| File Type | File Name | Process Name and Information |
![]() |
winrecon.exe |
!NoLoad
WinRecon keystroke logger/monitoring program - remove unless you installed it yourself! |
![]() |
winSOCKS.exe |
(*)API Machine
Homepage hijacker, see here (* = any digit) |
![]() |
win32API.exe |
(*)Run
Homepage hijacker, see here (* = any digit) |
![]() |
wstcl.exe |
*Microsoft Update
Added by the STMU TROJAN! |
![]() |
wucxt.exe |
*Microsoft Update
Added by the STMU TROJAN! |
![]() |
wuytc.exe |
*Microsoft Update
Added by the STMU TROJAN! |
![]() |
wrauclt.exe |
*windows update
Added by the RBOT-QU WORM! |
![]() |
wuanclt.exe |
*windows update
Added by the RBOT-PG WORM! |
![]() |
wuaucrlt.exe |
*windows update
Added by the SPYBOT.HUR WORM! |
![]() |
wuraclt.exe |
*windows update
Added by the RBOT-PO WORM! |
![]() |
wurauclt.exe |
*windows update
Added by the RBOT-SY WORM! |
![]() |
wsctl.exe |
*windows update
Added by the SPYBOT.PR WORM! |
![]() |
wkmst.exe |
*windows update
Added by the SDBOT.AVD WORM! |
![]() |
wscxt.exe |
*windows update
Added by the RBOT.AOS WORM! |
![]() |
waurclt.exe |
*windows update
Added by a variant of the RBOT WORM! |
![]() |
winstats.exe |
*winstats
Added by the GARGAFX TROJAN! |
![]() |
w****.exe [* = random char] |
*wuauclt.exe
Added by a variant of the RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe, wtmsv.exe, wxmst.exe, wmsvc.exe and so on... |
![]() |
wininfo.exe |
,main drive Loader
Suspected malware as it appears in 3 different registry locations - see here |
![]() |
winlogon.exe |
.Prog
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
![]() |
WARN0190.EXE |
0190 Warner
Anti-dialer program (Germany) |
![]() |
WARN0900.EXE |
0900 Warner
Anti-dialer program (Germany) |
![]() |
WebMailSpy.exe |
1WinCfg32
WebMailSpy spyware |
![]() |
winmgr.exe |
252
Added by the LEGMIR-AT TROJAN! |
![]() |
winlog0n.exe |
9m
Added by the LEGMIR-AQK TROJAN! |
![]() |
w32NTupdt.exe |
A New Windows Updater
Added by MYTOB.BM WORM! |
![]() |
winpppoverethernet.exe |
a-winpoet-service
WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking |
![]() |
winsto.exe |
Access Control App
Detected by Kaspersky as the AGENT.DGO TROJAN! See here |
![]() |
wcescom32.exe |
ActiveSync
Added by the MANCSYN-E TROJAN! |
![]() |
wini.exe |
AdAware
Added by the RBOT-XN WORM! |
![]() |
winlogon.exe |
Administrator
Added by the RUBBLE-C WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
![]() |
windrv.exe |
ADriver
Added by the DELF.WG TROJAN! |
![]() |
windefault.exe |
AFAFilter
AFAFilter - internet filter software |
![]() |
WinServ.exe |
AKEYNAME
Added by the EVILBOT.C TROJAN! |
![]() |
winoff.exe |
AMP WinOFF
WinOFF is " a utility designed to shut down Windows computers automatically, in a fully configurable way" |
![]() |
WZCSLDR2.exe |
ANIWZCS2Service
ALPHA Networks wireless driver |
![]() |
WZCSLDR.exe |
ANIWZCSService
D-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity |
![]() |
winsp3.exe |
Anti-Virus Update Scheduler
Malware - detected by Kaspersky as the AGENT.FP TROJAN! |
![]() |
winlog.exe |
AntiVir
Added by the IRCBOT-TJ TROJAN! |
![]() |
winapix.exe |
APIMon
Added by a variant of the TIBSER.A downloader TROJAN! |
![]() |
WN511B.exe |
AS00_WN511B
Netgear RangeMax NEXT wireless adapter configuration utility |
![]() |
WPN511.exe |
AS00_WPN511
NetgearRev MFC Application - software for Netgear wireless network cards - what does it do and is it required in startup? |
![]() |
windfind.exe |
atisrc2
Added by the WINDFIND-A TROJAN! |
![]() |
winfp.exe |
Audio Device Manager
Detected by PCTools as the IRCBOT.BIV TROJAN! See here |
![]() |
WinNT.exe |
Audio Device Manager
Added by the BANKER.BTG TROJAN! |
![]() |
WNDXP.exe |
Audio Device Manager
Detected by Kaspersky as the IRCBOT.AJL TROJAN! See here |
![]() |
wintmr.exe |
Authentic-ID Toolbar
System Tray access to Child Control parental control software by Salfield |
![]() |
win32.exe |
auto
Added by the SMALL!SD5 TROJAN! |
![]() |
WindowsSys32.exe |
Auto Updat
Added by a variant of the FORBOT WORM! |
![]() |
windowsupdate.exe |
autoload
Detected by Trend Micro as the POLYCRYP.DY TROJAN! See here |
![]() |
wauclt.exe |
Automated Windows Updates
Added by the GAOBOT.AJD WORM! |
![]() |
winmain.exe |
autorun
Added by a variant of the DLEF.CNS TROJAN! |
![]() |
WINUP2DATE.DLL, SHStart |
autoupdate
Unidentified adware - detected by Panda antivirus as the CLICKER.CY TROJAN! |
![]() |
wlangui.exe |
AVMWlanClient
Related to broadband products from avm.de |
![]() |
win*.tmp.exe [* is a number] |
avp
Added by a variant of the ALPHABET TROJAN! |
![]() |
WErcx.exe |
AvpWx
Detected by Kaspersky as a variant of the AGENT.A TROJAN! |
![]() |
winupdate.exe |
blah service
Added by the GAOBOT.BIA WORM! |
![]() |
winsysengine.exe |
blah service
Added by the RBOT-KI WORM! |
![]() |
win32.exe |
blah service
Added by the RBOT-AXO WORM! |
![]() |
WLANmon.exe |
Blitzz BWI715
Blitzz Technology BWI715 Wireless PC modem connection monitor |
![]() |
wscript.exe [path] All Users.vbs |
BootsCfg
Added by the SPILTRON WORM! |
![]() |
wscript.exe [path] All Users.vbe |
BootsCfg
Added by the SPILTRON WORM! |
![]() |
wscript.exe [path] Install.log.vbs |
BootsCfg
Added by the YPSAN.E WORM! |
![]() |
wavepcmonitor.exe |
Bose Wave/PC Monitor
System Tray access for this system (more info on the system here). Available via Start -> Programs |
![]() |
winlogin.exe |
BossIdea
Added by the LINEAGE-I TROJAN! |
![]() |
wltray.exe |
Broadcom Wireless Manager UI
System tray access to wireless LAN card configuration options |
![]() |
winlogon.exe |
BuildLab
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
![]() |
Wininit.exe |
Bymer.Scanner
Added by the BYMER WORM! |
![]() |
WinTask.exe |
C:WINDOWSWinTask.exe
Pop Marketing adware |
![]() |
WindowsSec.exe |
Cable Modem Adapter
Added by the WOOTBOT.A WORM! |
![]() |
wincalc.exe |
Calc Microsoft Windows
Added by an unidentied WORM or TROJAN! |
![]() |
WMADZ.EXE |
ccApp
Added by the RBOT-LJ WORM! |
![]() |
winlogon.exe |
ccApps
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
![]() |
wintmr.exe |
CCWinTray
System Tray access to Child Control parental control software by Salfield |
![]() |
windrv.exe |
CDriver
Added by the DELF.WG TROJAN! |
![]() |
wsot.exe |
CEPA
?? |
![]() |
WinMuschi.exe |
CFDStart
WINMUSCHI dialler |
![]() |
wiseupdt.exe |
Check for One Touch Update
Checks for updates for Visioneer OneTouch scanners |
![]() |
WiseUpdt.exe |
Check for TWS Updates
Interactive Brokers - check for update to their standalone Java-based trading platform |
![]() |
webtmr.exe |
ChicoSys
Child Control parental control software |
![]() |
W95AGENT.EXE |
Client agent for ARCserve
Part of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required? |
![]() |
wup.exe |
Client Update
Added by a variant of the OPANKI-A WORM! |
![]() |
winjes.exe |
Compaq Jes Drivers
Added by the SDBOT-XR WORM! |
![]() |
wincmd.exe |
Compaq Service Drivers
Added by the RBOT.ATV WORM! |
![]() |
wind32.exe |
Compaq Service Drivers
Added by a variant of the SDBOT WORM! |
![]() |
winmsn.exe |
Compaq Service Drivers
Added by a variant of the SDBOT WORM! |
![]() |
winsvc.exe |
Compaq Service Drivers
Added by the SDBOT-AGD WORM! |
![]() |
wstray.exe |
ComTry Web Searcher
Comtry MP3 Downloader related - spyware |
![]() |
WinService32.exe |
Config
Added by the CRUTCHA-A TROJAN! |
![]() |
winsys32.exe |
Config Loadr
Added by the AGOBOT-HN WORM! |
![]() |
Wuxat.exe |
Configuration Default
Added by the SPYBOT-CA WORM! |
![]() |
Winset32.exe |
Configuration File
Added by the FLUX.101 TROJAN! |
![]() |
wupdated.exe |
Configuration Loaded
Added by the MOEGA or MOEGA.AG or MOEGA.AP WORMS! |
![]() |
wincrt32.exe |
Configuration Loader
Added by the GAOBOT.BF WORM! |
![]() |
windex.exe |
Configuration Loader
Added by the GAOBOT.BZ WORM! |
![]() |
Winreg.exe |
Configuration Loader
Added by the GAOBOT.AO WORM! |
![]() |
winicfg32.exe |
configuration loader
Added by the GAOBOT.RQ WORM! |
![]() |
wincffg.exe |
Configuration Loader
Added by the AGOBOT.A3 WORM! |
![]() |
WinHelper.exe |
Configuration Loader
Added by a variant of the AGOBOT/GAOBOT WORM! |
![]() |
wincore.exe |
Configuration Loader
Added by the SDBOT.BHE WORM! |
![]() |
Winsys32.exe |
Configuration Loader Service
Added by the RBOT-YV WORM! |
![]() |
wscel.exe |
Configuration Loading Service
Added by the SDBOT-WJ WORM! |
![]() |
wlanutil.exe |
Configuration Utility
NetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards) |
![]() |
winamp32.exe |
Configuration32 Loader32
Added by the SDBOT-BIC WORM! |
![]() |
winservn.exe |
ContentService
Homepage hijacker |
![]() |
WFXCTL32.EXE |
Controller
From Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs |
![]() |
winlogin32.exe |
cpanel
Added by the RBOT-FOY WORM! |
![]() |
wincomp.exe |
cpntmgc
Added by the WINTRIM_A TROJAN! |
![]() |
winmgts.exe |
cpntmgc
Added by the WINTRIM-B TROJAN! |
![]() |
wuitgurd.exe |
CPU Temp Control
Added by the RBOT-AHV WORM! |
![]() |
world_cup_.bat |
cqlyg
Added by the WCUP.A WORM! |
![]() |
Wucrtupd.exe |
CriticalUpdate
MS Windows Critical Update Notification. If you want to keep Windows up-to-date, check the Windows Update site |
![]() |
wucrtupd.exe |
CriticalUpdate
Added by the NOALA.B WORM! Note - this file is located in the Windows or Winnt folder, and must not be confused with the legitimate Windows process of the same name as described here |
![]() |
WinConst.exe |
ctfmon
Added by the ASSASIN-G TROJAN! |
![]() |
WINLOGON.EXE |
CueX44_stil_here
Added by the PUNYA-A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
![]() |
WLANMON.exe |
D-Link AirPlus DWL-650+ Utility
D-Link Air Plus Wireless PC modem connection monitor |
![]() |
weather.exe |
Daily Weather Forecast
Added by the DLOADER-IP TROJAN! |
![]() |
W815DM.EXE |
ddhelper
Enuff Parental Control Software by Akrontech |
![]() |
windrv.exe |
DDriver
Added by the DELF.WG TROJAN! |
![]() |
worm.exe |
Delete Me
Added by the DOOMHUNTER WORM! |
![]() |
WLTRAY |
Dell Wireless Manager UI
Installed alongside Dell Wireless WLAN Card and provides additional configuration options for these devices |
![]() |
wltray.exe |
Dell Wireless Manager UI
System tray access to wireless LAN card configuration options |
![]() |
wfxmgr.exe |
Device Manager
Added by the RBOT.AJU WORM! |
![]() |
win.exe |
Distributed File System
Added by the MYFIP.AB WORM! |
![]() |
WATCH.exe |
DLHelperEXE
Download helper distributed with some software that allows the software installation to redirect download locations. Not required once the installation is finished |
![]() |
windfe.exe |
DLINK dfe drivers for Windows NT
Added by the RANDEX.AK WORM! |
![]() |
wakeservice.exe |
DomPlayer Service
DomPlayer adware |
![]() |
WindowsUpdate.exe |
DRam prosessor
Added by the RBOT-BBZ WORM! |
![]() |
winupdaterar.exe |
DRam rar proc
Added by a variant of the IRC.BOT TROJAN! |
![]() |
W95Mm.exe |
drmu
Homepage hijacker installing a toolbar: http://tdko.com/. Lop.com in disguise |
![]() |
windspl.exe |
DsplObjects
Added by the BEAGLE.DN WORM! |
![]() |
windrv.exe |
DSystemDriver
Added by the DELF.WG TROJAN! |
![]() |
weather.exe |
Dulux WeatherShield WeatherDesk
Dulux WeatherShield WeatherDesk - latest weather information from across Australia |
![]() |
windvd98.exe |
dvd98
Added by the CULT.P WORM! |
![]() |
wsxsvc.exe |
Dvx
Delfin Media Viewer or "Promulgate" adware variant |
![]() |
Weather.exe |
DW4
Desktop Weather |
![]() |
winxp34.exe |
Dynamic Dns Binary
Added by a variant of the RBOT WORM! |
![]() |
WinHelpcfn.exe |
Dynamic Dns Binary
Added by a variant of the RBOT WORM! |
![]() |
wizard.exe |
EAPCISETUP
Part of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation |
![]() |
wjview ...Code |
EbatesMoeMoneyMaker
Ebates adware |
![]() |
watch.exe |
Eicon NetworksLAN_DAEMON
Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually |
![]() |
watch.exe |
Eicon TechnologyLAN_DAEMON
Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually |
![]() |
Winmsuit.exe |
ELSA WINman Suite
Allows you to totally customize your ELSA graphics card settings, including overclocking the GPU |
![]() |
wintr.com |
encapsulated command tool
?? |
![]() |
WMENCAGT.EXE |
Encoder Agent
MS Windows Media Encoder, which already has a shortcut in the Start Menu if installed |
![]() |
wsys.exe |
Enumerate Service
Added by the MANIFEST TROJAN! |
![]() |
wind2ll2.exe |
erfgddfk
Added by the BEAGLE.CQ WORM! |
![]() |
windlhhl.exe |
erghgjhgdr
Added by the BEAGLE.BG WORM! |
![]() |
windlhhl.exe |
erghgjhjgdr
Added by the BEAGLE.BG or BEAGLE.BH or BEAGLE.BI or BEAGLE.BJ WORMS! |
![]() |
windll2.exe |
erthegdr
Added by the BEAGLE.CG WORM! |
![]() |
windll.exe |
erthgdr
Added by the BEAGLE.AO or BEAGLE.AQ WORMS! |
![]() |
winfw.exe |
eTunnel
Added by an unidentified TROJAN! |
![]() |
Warm.scr |
ExeName32
Added by the SCOLD WORM! |
![]() |
wscript.exe [filename] |
explorer
Sneaky way to start any VBS script. Many viruses use VBS files |
![]() |
Windows Explorer.exe |
Explorer
Added by the SILLYFDC-I WORM! |
![]() |
winset.exe |
exporet
Added by the QQPASS-I TROJAN! |
![]() |
wo.exe |
eZWO
eZula TopText adware |
![]() |
wincfg.exe |
Fantasia injector
Added by the AGOBOT.US WORM! |
![]() |
windrv.exe |
FDriver
Added by the DELF.WG TROJAN! |
![]() |
wmiprvsc.exe |
File System Service
Added by the AGOBOT-HZ TROJAN! |
![]() |
wtm.exe |
FileFreedom_Plugin
FileFreedom peer-to-peer sharing program |
![]() |
Wscript.exe ..ChkMgr32.vbs |
FileManager32
Added by the NOTUP.A WORM! |
![]() |
Wscript.exe UpdataFiles.vbs |
FileSoft
Added by the SST.B WORM! |
![]() |
wuaclt.exe |
FireFox Startup Drivers
Added by the RBOT.BYX WORM! |
![]() |
wmlaunch .exe |
Firewall
Added by the ELIPTER.A or ELIPTER.B WORMS! |
![]() |
wmlaunch .exe |
Firewall
Added by the ELIPTER.D WORM! |
![]() |
winlogon.exe |
Firewall auto setup
Added by a TROJAN - see here. Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
![]() |
WinedowsUpdater1.exe |
Firewall Update System1
Added by the RBOT-ARU WORM! |
![]() |
WinFIX1.0.vbs |
FIX
Added by the GORMLEZ-A WORM! |
![]() |
wssdtu.exe |
Folder Service
Added by the MANIFEST TROJAN! |
![]() |
WINFAH.EXE |
Folding@home
Folding@Home is a distributed computing project which studies protein folding, misfolding, aggregation, and related diseases - must be running in order to access the internet to upload to the servers. Available via Start -> Programs |
![]() |
winlogon.exe |
FriendlyTypeName
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
![]() |
winpopup.exe |
Fromine WinPopup
Instant Messenger program |
![]() |
winsvc.exe |
Generic Host Process for Win32 Services
Added by the SDBOT-O WORM! |
![]() |
winsvc32.exe |
Generic Host Process for Win32 Services
Added by the SDBOT-P WORM! |
![]() |
WinLoaderXP.exe |
GenericHostXP
Added by the BDOOR-ACX TROJAN! |
![]() |
Winmod32.exe |
Gerenciamento de arquivos do Windows
Added by the DLOADER-WG TROJAN! |
![]() |
winsystems.exe |
german.exe
Added by the BAGLEDl-AE TROJAN! |
![]() |
wintems.exe |
german.exe
Added by the BAGLE-AS TROJAN! |
![]() |
wakeservice.exe |
Get-Torrent Service
Get-Torrent bittorrent client - Installs LOP adware |
![]() |
winB_.exe |
getwin
Added by the BANKER-HS TROJAN! |
![]() |
WinDash.EXE |
Global Startup
Detected by Kaspersky as the VB.Q WORM! |
![]() |
window.exe |
gpmce
Detected by Kaspersky as the VB.CK WORM! See here |
![]() |
windll.exe |
Graphics adapter service
Added by the ATNAS.A WORM! |
![]() |
wscript.exe gpremier.vbs |
gremier
Added by the GPREMIER WORM! |
![]() |
WCESCOMM.EXE |
H/PC Connection Agent
Active sync for use with Windows CE based palm PC |
![]() |
WinHSD.exe |
Hardware Shell Detection
Added by a variant of the RBOT WORM! |
![]() |
Wizardnil.exe |
Help
Added by the BANCOS-BCZ TROJAN! |
![]() |
windowsupdate.exe |
HKLMRun
Added by the FORBOT-BJ WORM! (where HKLMRun represents HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun) |
![]() |
wiz98.exe |
hostserv
Added by a variant of the SDBOT WORM! |
![]() |
winHostsEdit.exe |
HostsFileMgr
AdBin from Gilmore Software Development. An easy solution to managing your Window's hosts file |
![]() |
We Love Lien Van de Kelder.exe |
http://www.lienvandekelder.be
Added by the MYTOB-CV WORM! |
![]() |
winsys.exe |
I am not Ranky. I am eTunnel!
Added by an unidentified WORM or TROJAN! |
![]() |
winlog.exe |
icq lite
Added by the IRCBOT-TJ TROJAN! |
![]() |
winlogon.exe |
ICQ Net
Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup! |
![]() |
webcamupdate.exe |
IcqBeta
Added by an unidentified TROJAN! |
![]() |
winlogon.exe |
ICQNet
Added by the NETSKY-C WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder |
![]() |
wini.exe |
IE Runtime
Added by the PICRATE.B WORM! |
![]() |
winis.exe |
IE Runtimes
Added by the RBOT-ADZ TROJAN! |
![]() |
wkstmg.exe |
IE6
Added by a variant of the SDBOT WORM! |
![]() |
winsnt.exe |
IE6
Added by the RBOT-GOV WORM! |
![]() |
WinSock.exe |
IExplorerService
Detected by Kaspersky as the AGENT.KIU TROJAN! See here |
![]() |
WashIdx.exe |
Index Washer
Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
![]() |
wsock32.exe |
InetServices
Added by the WOCK32-A TROJAN! |
![]() |
wmplayer.exe |
infamous.exe
Added by unknown malware. WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup. Infamous.exe is identified by Panda antivirus as Trj/Briss.A |
![]() |
WUSB11cfg.exe |
Instant Wireless Configuration Utility
Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration |
![]() |
WPC11Cfg.exe |
Instant Wireless Configuration Utility
Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration |
![]() |
wing32.exe |
Intec Service Drivers
Added by the RBOT.HAZ WORM! |
![]() |
winrvc.exe |
Intec Services Driverrs
Added by a variant of the SDBOT WORM! |
![]() |
winnook.exe |
Intel system tool
Added by the SPYRE-C TROJAN! |
![]() |
WinSocks5.exe |
internct
Added by the GRAYBIRD.F TROJAN! |
![]() |
winlogom.exe |
Internet
Added by a variant of the SDBOT WORM! |
![]() |
winsas32.exe |
internet
Added by a variant of the SDBOT WORM! |
![]() |
winz32.exe |
INTERNET SERVISES
Added by the KWBOT.Z WORM! |
![]() |
wkfix.exe |
Internet2 Optimizer
Added by a variant of the RBOT WORM! |
![]() |
windows.exe |
InternetExplorer2
Added by the SDBOT-CZP WORM! |
![]() |
winz32.exe |
INTERNET_SERVISES
Added by the SDBOT.Q TROJAN! |
![]() |
WINDRV.EXE |
InterU
Added by the IRCINTER.A TROJAN! |
![]() |
WinCinemaMgr.exe |
Intervideo Win Cinema Manager
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
![]() |
WINCIN~1.EXE |
Intervideo Win Cinema Manager
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
![]() |
WinCinemaMgr.exe |
Intervideo WinCinema Manager
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
![]() |
WINCIN~1.EXE |
Intervideo WinCinema Manager
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
![]() |
WinScheduler.exe |
Intervideo WinScheduler
WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs |
![]() |
wnmgre.exe |
IPC Spool Manager
Added by the SDBOT-ZC WORM! |
![]() |
winspec.exe |
IPC Spool Manager
Added by the SDBOT-BLU WORM! |
![]() |
Winipcfgs.exe |
IPTable Configuration
Added by a variant of the RBOT WORM! |
![]() |
winmon32.exe |
iRis Active Monitor
Iris Antivirus - discontinued, replace with good alternative |
![]() |
WIMMUN32.exe |
iRiS AntiVirus Active Monitor
Iris Antivirus - discontinued, replace with good alternative |
![]() |
winlogan.exe |
jkdfj94kgdftdf
Added by the ZLOB.BZ TROJAN! |
![]() |
winxp2.exe |
Jufualt
Added by the SDBOT-AAB WORM! |
![]() |
win1ogoin.exe |
KAVFOX
Added by GWGHOST-M TROJAN! |
![]() |
wscntfy.exe |
KAVPersonal90
Added by the BANKER-FZ TROJAN! |
![]() |
Windll.exe |
KavRuns
Added by the TRYNOMA TROJAN! |
![]() |
winser.exe |
KernelCheck
Added by the TSPY_LMIR.SL TROJAN! |
![]() |
wmiprvse.exe |
Kernel_check
Added by the SONEBOT-B WORM! Note - this is not the legitimate wmiprvse.exe process which is always located in the System32wbem folder and should not normally figure in Msconfig/Startup! |
![]() |
winxp.exe |
key
Added by the BEAGLE.AG WORM! |
![]() |
winlog.exe |
key2
Added by the BAGLEDI-AL TROJAN! |
![]() |
wppewafaj.exe |
KnowledgeBase GUI
Added by the RBOT-GRZ WORM! |
![]() |
word.EXE |
KV2005
Added by the IW TROJAN! |
![]() |
winmine |
l44sys**
Added by the VBS.LIDO WORM - where ** is a number between 33 and 44 |
![]() |
win32.exe |
Load
Added by the RUBBLE-A WORM! |
![]() |
Wscript.exe LGuarg.exe.vbs |
Load-Guard
Added by the YENO.B and YENO.C WORMS! |
![]() |
winldra.exe |
load32
Added by the BACKDOOR.NIBU.J or DUMARU-BI TROJANS! Note - also known as Srv.SSA-KeyLogger by Sunbelt Software which has developed a free removal tool for this keylogger |
![]() |
WPSLOAD.EXE |
load=
Windows printing system that comes with the setup for Canon BJC series on the manufacturer's disk |
![]() |
WINOSCFG.EXE |
load=
Could it be something to do with configuring Windows on a new PC from an OEM supplier? |
![]() |
wpshrc.exe |
load=
Required to prevent configuration errors on a Compaq LBP-660 and LBP-460 parallel port laser printers (and maybe others) |
![]() |
wtfeat.exe |
Load=
Associated with the Wintab Digitizer |
![]() |
win32exec.exe |
load=
Added by the BITTER WORM! |
![]() |
WMPLAYER.EXE |
loader
Unknown baddie - WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup |
![]() |
wmimgr.exe |
LoadPFW
Added by the QEDS-B WORM! |
![]() |
watcher.exe |
LoadWatcher
Watcher spyware |
![]() |
winset.exe |
loadwin
Added by the QQPASS-I TROJAN! |
![]() |
winsys.exe |
loadwin
Added by the QQPASS-J TROJAN! |
![]() |
winlog.exe |
Login
Salfeld Child Control - parental control software |
![]() |
wrcam.exe |
Logitech Desktop Controller
Added by a variant of the RBOT WORM! |
![]() |
wincalc.exe |
LogService
Added by the PAPROXY TROJAN! |
![]() |
WIWT.EXE |
longos
Added by the BANKER-CD TROJAN! |
![]() |
wfdmgr.exe |
LSA
Added by the MYTOB.C WORM! |
![]() |
woekd.exe |
Lsass
Added by an unidentified WORM or TROJAN! |
![]() |
winupdate.exe |
LTM2
Added by the LITMUS.203 TROJAN! |
![]() |
winscan.exe |
LTM2
Added by the LITMUS-B TROJAN! |
![]() |
winvers16.exe |
LTM2
Added by the SMALL.ND TROJAN! |
![]() |
wusas.exe |
Machine Update Soft
Added by an unidfentified WORM! |
![]() |
WMIPRVSW.exe |
machine-debugger
Added by the AGOBOT.U WORM! |
![]() |
wintrims.exe |
MC
Added by the WINTRIM TROJAN! |
![]() |
WINTRIM.EXE |
MC
Added by the WINTRIM_A TROJAN! |
![]() |
Win32.dll.vbs |
mcafee
Added by the CATCHER-B WORM! |
![]() |
WebScanX.exe |
McAfeeWebscanX
From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc |
![]() |
wisp.exe |
MCX Update
Added by the RBOT-AQH WORM! |
![]() |
winy.exe |
MD IE Plugin
Adware |
![]() |
wmplayer.exe |
Media Player
Added by the AGOBOT-BM WORM! |
![]() |
wowdache.exe |
Meeting Connection
Added by the PPDOOR-D TROJAN! |
![]() |
Wmsngr.exe |
Messenger
Added by a variant of the RBOT WORM! |
![]() |
winldx32.exe |
Microfot Update
Added by a variant of the RBOT WORM! |
![]() |
winssx.exe |
Microft Update 32
Added by the RBOT-AQS WORM! |
![]() |
wdfmrg.exe |
Micromedia Flash Update
Added by a variant of the SDBOT WORM! |
![]() |
winmx32.EXE |
MICROSFT MX UPDATE SUPPORT
Added by the IRCBOT-FD WORM! |
![]() |
wilogon32.exe |
Microsof Winlog Host
Added by the RBOT.XC WORM! |
![]() |
win32.exe |
Microsoft
Added by the DARKMOON TROJAN! |
![]() |
wuauclt.exe |
Microsoft
Added by the QQROB-AQ TROJAN! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup! |
![]() |
wcsntfy.exe |
Microsoft
Added by the AGOBOT-AHT WORM! |
![]() |
windl32.exe |
Microsoft
Added by the SDBOT-DCZ WORM! |
![]() |
WinSecUp.exe |
Microsoft
Added by the RBOT-GPL WORM! |
![]() |
wsim32.exe |
Microsoft
Added by the RBOT-GTL WORM! |
![]() |
wplayer.exe |
Microsoft
Detected by Kaspersky as the RBOT.DYU TROJAN! See here |
![]() |
wuauclt.exe |
Microsoft (R) Windows Update Service
Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup! |
![]() |
wuapdate16.exe |
Microsoft 16Bit Update
Added by the RBOT.CZ WORM! |
![]() |
wupdt64.exe |
Microsoft 64 Bit Runtime Updater
Added by a variant of the RBOT WORM! |
![]() |
winupdate.exe |
Microsoft auto update
Added by the BMBOT TROJAN! |
![]() |
WINHLP16.EXE |
Microsoft Auto Update
Added by the RBOT.GY WORM! |
![]() |
wuauclt.exe |
Microsoft auto update
Added by the CULT-B TROJAN! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup! |
![]() |
wincmd.exe |
Microsoft Command Line
Added by a variant of the RBOT WORM! |
![]() |





