 |
winrecon.exe |
!NoLoad
WinRecon keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
winSOCKS.exe |
(*)API Machine
Homepage hijacker, see here (* = any digit) |
 |
win32API.exe |
(*)Run
Homepage hijacker, see here (* = any digit) |
 |
winhelp.exe |
(Default)
Added by the BLACKMAL.C WORM! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank |
 |
winbas12.exe |
(Default)
Adware, CoolWebSearch parasite related - detected by Kaspersky as the VB.DU TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank |
 |
winlog.exe |
(Default)
Unidentified adware. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank |
 |
winligom.exe |
(Default)
Added by the RBOT-GAI WORM! Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run, HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank |
 |
wstcl.exe |
*Microsoft Update
Added by the STMU TROJAN! |
 |
wucxt.exe |
*Microsoft Update
Added by the STMU TROJAN! |
 |
wuytc.exe |
*Microsoft Update
Added by the STMU TROJAN! |
 |
WerFault.exe |
*WerKernelReporting
Part of Windows Error Reporting technology (WER) for Vista. WER captures software crash and hang data from end-users who agree to report it - see here |
 |
wrauclt.exe |
*windows update
Added by the RBOT-QU WORM! |
 |
wuanclt.exe |
*windows update
Added by the RBOT-PG WORM! |
 |
wuaucrlt.exe |
*windows update
Added by the SPYBOT.HUR WORM! |
 |
wuraclt.exe |
*windows update
Added by the RBOT-PO WORM! |
 |
wurauclt.exe |
*windows update
Added by the RBOT-SY WORM! |
 |
wsctl.exe |
*windows update
Added by the SPYBOT.PR WORM! |
 |
wkmst.exe |
*windows update
Added by the SDBOT.AVD WORM! |
 |
wscxt.exe |
*windows update
Added by the RBOT.AOS WORM! |
 |
waurclt.exe |
*windows update
Added by a variant of the RBOT WORM! |
 |
winstats.exe |
*winstats
Added by the GARGAFX TROJAN! |
 |
w****.exe [* = random char] |
*wuauclt.exe
Added by a variant of the RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe, wtmsv.exe, wxmst.exe, wmsvc.exe and so on... |
 |
wininfo.exe |
,main drive Loader
Suspected malware as it appears in 3 different registry locations - see here |
 |
winlogon.exe |
.Prog
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
WARN0190.EXE |
0190 Warner
Anti-dialer program (Germany) |
 |
WARN0900.EXE |
0900 Warner
Anti-dialer program (Germany) |
 |
WebMailSpy.exe |
1WinCfg32
WebMailSpy spyware |
 |
winmgr.exe |
252
Added by the LEGMIR-AT TROJAN! |
 |
winlog0n.exe |
9m
Added by the LEGMIR-AQK TROJAN! |
 |
wincms.exe |
@
Added by the RBOT.CBR WORM! |
 |
w32NTupdt.exe |
A New Windows Updater
Added by the MYTOB.BM WORM! |
 |
winpppoverethernet.exe |
a-winpoet-service
WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking |
 |
winsto.exe |
Access Control App
Detected by Kaspersky as the AGENT.DGO TROJAN! See here |
 |
wcescom32.exe |
ActiveSync
Added by the MANCSYN-E TROJAN! |
 |
wini.exe |
AdAware
Added by the RBOT-XN WORM! |
 |
winlogon.exe |
Administrator
Added by the RUBBLE-C WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
windrv.exe |
ADriver
Added by the DELF.WG TROJAN! |
 |
windefault.exe |
AFAFilter
AFAFilter - internet filter software |
 |
WinServ.exe |
AKEYNAME
Added by the EVILBOT.C TROJAN! |
 |
winoff.exe |
AMP WinOFF
WinOFF is " a utility designed to shut down Windows computers automatically, in a fully configurable way" |
 |
WZCSLDR2.exe |
ANIWZCS2Service
ALPHA Networks wireless driver |
 |
WZCSLDR.exe |
ANIWZCSService
D-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity |
 |
winsp3.exe |
Anti-Virus Update Scheduler
Malware - detected by Kaspersky as the AGENT.FP TROJAN! |
 |
winlog.exe |
AntiVir
Added by the IRCBOT-TJ TROJAN! |
 |
winapix.exe |
APIMon
Added by a variant of the TIBSER.A downloader TROJAN! |
 |
WN511B.exe |
AS00_WN511B
Netgear RangeMax NEXT wireless adapter configuration utility |
 |
WPN511.exe |
AS00_WPN511
NetgearRev MFC Application - software for Netgear wireless network cards - what does it do and is it required in startup? |
 |
windfind.exe |
atisrc2
Added by the WINDFIND-A TROJAN! |
 |
winfp.exe |
Audio Device Manager
Detected by PCTools as the IRCBOT.BIV TROJAN! See here |
 |
WinNT.exe |
Audio Device Manager
Added by the BANKER.BTG TROJAN! |
 |
WNDXP.exe |
Audio Device Manager
Detected by Kaspersky as the IRCBOT.AJL TROJAN! See here |
 |
wintmr.exe |
Authentic-ID Toolbar
System Tray access to Child Control parental control software by Salfield |
 |
win32.exe |
auto
Added by the SMALL!SD5 TROJAN! |
 |
WindowsSys32.exe |
Auto Updat
Added by a variant of the FORBOT WORM! |
 |
windowsupdate.exe |
autoload
Detected by Trend Micro as the POLYCRYP.DY TROJAN! See here |
 |
wauclt.exe |
Automated Windows Updates
Added by the GAOBOT.AJD WORM! |
 |
winmain.exe |
autorun
Added by a variant of the DELF.CNS TROJAN! |
 |
WINUP2DATE.DLL, SHStart |
autoupdate
Unidentified adware - detected by Panda antivirus as the CLICKER.CY TROJAN! |
 |
wlangui.exe |
AVMWlanClient
Related to broadband products from avm.de |
 |
win*.tmp.exe [* is a number] |
avp
Added by a variant of the ALPHABET TROJAN! |
 |
WErcx.exe |
AvpWx
Detected by Kaspersky as a variant of the AGENT.A TROJAN! |
 |
winupdate.exe |
blah service
Added by the GAOBOT.BIA WORM! |
 |
winsysengine.exe |
blah service
Added by the RBOT-KI WORM! |
 |
win32.exe |
blah service
Added by the RBOT-AXO WORM! |
 |
WLANmon.exe |
Blitzz BWI715
Blitzz Technology BWI715 Wireless PC modem connection monitor |
 |
wscript.exe [path] Date.POP.vbs |
BootsCfg
Added by the KUULLIO WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted |
 |
wscript.exe [path] All Users.vbs |
BootsCfg
Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted |
 |
wscript.exe [path] All Users.vbe |
BootsCfg
Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted |
 |
wscript.exe Install.log.vbs |
BootsCfg
Added by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "Install.log.vbs" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
wavepcmonitor.exe |
Bose Wave/PC Monitor
System Tray access for this system (more info on the system here). Available via Start -> Programs |
 |
winlogin.exe |
BossIdea
Added by the LINEAGE-I TROJAN! |
 |
wltray.exe |
Broadcom Wireless Manager UI
System tray access to wireless LAN card configuration options |
 |
winlogon.exe |
BuildLab
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
Wininit.exe |
Bymer.Scanner
Added by the BYMER WORM! |
 |
WinTask.exe |
C:WINDOWSWinTask.exe
"Pop Marketing" adware |
 |
WindowsSec.exe |
Cable Modem Adapter
Added by the WOOTBOT.A WORM! |
 |
wincalc.exe |
Calc Microsoft Windows
Added by an unidentied WORM or TROJAN! |
 |
WMADZ.EXE |
ccApp
Added by the RBOT-LJ WORM! |
 |
winlogon.exe |
ccApps
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
wintmr.exe |
CCWinTray
System Tray access to Child Control parental control software by Salfield |
 |
windrv.exe |
CDriver
Added by the DELF.WG TROJAN! |
 |
wsot.exe |
CEPA
?? |
 |
WinMuschi.exe |
CFDStart
WINMUSCHI dialler |
 |
wiseupdt.exe |
Check for One Touch Update
Checks for updates for Visioneer OneTouch scanners |
 |
WiseUpdt.exe |
Check for TWS Updates
Interactive Brokers - check for update to their standalone Java-based trading platform |
 |
webtmr.exe |
ChicoSys
Child Control parental control software |
 |
W95AGENT.EXE |
Client agent for ARCserve
Part of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required? |
 |
wup.exe |
Client Update
Added by the OPANKI.O WORM! |
 |
winjes.exe |
Compaq Jes Drivers
Added by the SDBOT-XR WORM! |
 |
wincmd.exe |
Compaq Service Drivers
Added by the RBOT.ATV WORM! |
 |
wind32.exe |
Compaq Service Drivers
Added by a variant of the SDBOT WORM! |
 |
winmsn.exe |
Compaq Service Drivers
Added by a variant of the SDBOT WORM! |
 |
winsvc.exe |
Compaq Service Drivers
Added by the SDBOT-AGD WORM! |
 |
wstray.exe |
ComTry Web Searcher
Comtry MP3 Downloader related - spyware |
 |
WinService32.exe |
Config
Added by the CRUTCHA-A TROJAN! |
 |
winsys32.exe |
Config Loadr
Added by the AGOBOT-HN WORM! |
 |
Wuxat.exe |
Configuration Default
Added by the SPYBOT-CA WORM! |
 |
Winset32.exe |
Configuration File
Added by the FLUX.101 TROJAN! |
 |
wupdated.exe |
Configuration Loaded
Added by the MOEGA or MOEGA.AG or MOEGA.AP WORMS! |
 |
wincrt32.exe |
Configuration Loader
Added by the GAOBOT.BF WORM! |
 |
windex.exe |
Configuration Loader
Added by the GAOBOT.BZ WORM! |
 |
Winreg.exe |
Configuration Loader
Added by the GAOBOT.AO WORM! |
 |
winicfg32.exe |
configuration loader
Added by the GAOBOT.RQ WORM! |
 |
wincffg.exe |
Configuration Loader
Added by the AGOBOT.A3 WORM! |
 |
WinHelper.exe |
Configuration Loader
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
wincore.exe |
Configuration Loader
Added by the SDBOT.BHE WORM! |
 |
Winsys32.exe |
Configuration Loader Service
Added by the RBOT-YV WORM! |
 |
wscel.exe |
Configuration Loading Service
Added by the SDBOT-WJ WORM! |
 |
wlanutil.exe |
Configuration Utility
NetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards) |
 |
winamp32.exe |
Configuration32 Loader32
Added by the SDBOT-BIC WORM! |
 |
winservn.exe |
ContentService
Homepage hijacker |
 |
WFXCTL32.EXE |
Controller
From Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs |
 |
winlogin32.exe |
cpanel
Added by the RBOT-FOY WORM! |
 |
wincomp.exe |
cpntmgc
Added by the WINTRIM_A TROJAN! |
 |
winmgts.exe |
cpntmgc
Added by the WINTRIM-B TROJAN! |
 |
wuitgurd.exe |
CPU Temp Control
Added by the RBOT-AHV WORM! |
 |
world_cup_.bat |
cqlyg
Added by the WCUP.A WORM! |
 |
Wucrtupd.exe |
CriticalUpdate
MS Windows Critical Update Notification. If you want to keep Windows up-to-date, check the Windows Update site |
 |
wucrtupd.exe |
CriticalUpdate
Added by the NOALA.B WORM! Note - this file is located in the Windows or Winnt folder, and must not be confused with the legitimate Windows process of the same name as described here |
 |
WinConst.exe |
ctfmon
Added by the ASSASIN-G TROJAN! |
 |
WINLOGON.EXE |
CueX44_stil_here
Added by the PUNYA-A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
WLANMON.exe |
D-Link AirPlus DWL-650+ Utility
D-Link Air Plus Wireless PC modem connection monitor |
 |
weather.exe |
Daily Weather Forecast
Added by the DLOADER-IP TROJAN! |
 |
W815DM.EXE |
ddhelper
Enuff Parental Control Software by Akrontech |
 |
windrv.exe |
DDriver
Added by the DELF.WG TROJAN! |
 |
worm.exe |
Delete Me
Added by the DOOMHUNTER WORM! |
 |
wltray.exe |
Dell Wireless Manager UI
System tray access to wireless LAN card configuration options |
 |
wfxmgr.exe |
Device Manager
Added by the RBOT.AJU WORM! |
 |
win.exe |
Distributed File System
Added by the MYFIP.AB WORM! |
 |
WATCH.exe |
DLHelperEXE
Download helper distributed with some software that allows the software installation to redirect download locations. Not required once the installation is finished |
 |
windfe.exe |
DLINK dfe drivers for Windows NT
Added by the RANDEX.AK WORM! |
 |
wakeservice.exe |
DomPlayer Service
DomPlayer adware |
 |
WindowsUpdate.exe |
DRam prosessor
Added by the RBOT-BBZ WORM! |
 |
winupdaterar.exe |
DRam rar proc
Added by a variant of the IRCBOT TROJAN! |
 |
W95Mm.exe |
drmu
Homepage hijacker installing a toolbar: http://tdko.com/. Lop.com in disguise |
 |
windspl.exe |
DsplObjects
Added by the BEAGLE.DN WORM! |
 |
windrv.exe |
DSystemDriver
Added by the DELF.WG TROJAN! |
 |
weather.exe |
Dulux WeatherShield WeatherDesk
Dulux WeatherShield WeatherDesk - latest weather information from across Australia |
 |
windvd98.exe |
dvd98
Added by the CULT.P WORM! |
 |
wsxsvc.exe |
Dvx
Delfin Media Viewer or "Promulgate" adware variant |
 |
Weather.exe |
DW4
Desktop Weather |
 |
winxp34.exe |
Dynamic Dns Binary
Added by a variant of the RBOT WORM! |
 |
WinHelpcfn.exe |
Dynamic Dns Binary
Added by a variant of the RBOT WORM! |
 |
wizard.exe |
EAPCISETUP
Part of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation |
 |
wjview ...Code |
EbatesMoeMoneyMaker
Ebates adware |
 |
watch.exe |
Eicon NetworksLAN_DAEMON
Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually |
 |
watch.exe |
Eicon TechnologyLAN_DAEMON
Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually |
 |
Winmsuit.exe |
ELSA WINman Suite
Allows you to totally customize your ELSA graphics card settings, including overclocking the GPU |
 |
wintr.com |
encapsulated command tool
?? |
 |
WMENCAGT.EXE |
Encoder Agent
MS Windows Media Encoder, which already has a shortcut in the Start Menu if installed |
 |
wsys.exe |
Enumerate Service
Added by the MANIFEST TROJAN! |
 |
wind2ll2.exe |
erfgddfk
Added by the BEAGLE.CQ WORM! |
 |
windlhhl.exe |
erghgjhgdr
Added by the BEAGLE.BG WORM! |
 |
windlhhl.exe |
erghgjhjgdr
Added by the BEAGLE.BG or BEAGLE.BH or BEAGLE.BI or BEAGLE.BJ WORMS! |
 |
windll2.exe |
erthegdr
Added by the BEAGLE.CG WORM! |
 |
windll.exe |
erthgdr
Added by the BEAGLE.AO or BEAGLE.AQ WORMS! |
 |
winfw.exe |
eTunnel
Added by an unidentified TROJAN! |
 |
Warm.scr |
ExeName32
Added by the SCOLD WORM! |
 |
wscript.exe [filename] |
explorer
Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted |
 |
Windows Explorer.exe |
Explorer
Added by the SILLYFDC-I WORM! |
 |
winset.exe |
exporet
Added by the QQPASS-I TROJAN! |
 |
wo.exe |
eZWO
eZula TopText adware |
 |
wincfg.exe |
Fantasia injector
Added by the AGOBOT.US WORM! |
 |
windrv.exe |
FDriver
Added by the DELF.WG TROJAN! |
 |
wmiprvsc.exe |
File System Service
Added by the AGOBOT-HZ TROJAN! |
 |
wtm.exe |
FileFreedom_Plugin
FileFreedom peer-to-peer sharing program |
 |
Wscript.exe ChkMgr32.vbs |
FileManager32
Added by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "ChkMgr32.vbs" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
Wscript.exe UpdataFiles.vbs |
FileSoft
Added by the SST.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "UpdataFiles.vbs" file is located in the Winnt or Windows folder |
 |
wuaclt.exe |
FireFox Startup Drivers
Added by the RBOT.BYX WORM! |
 |
wmlaunch .exe |
Firewall
Added by the ELIPTER.A or ELIPTER.B WORMS! |
 |
wmlaunch .exe |
Firewall
Added by the ELIPTER.D WORM! |
 |
winlogon.exe |
Firewall auto setup
Added by a TROJAN - see here. Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
WinedowsUpdater1.exe |
Firewall Update System1
Added by the RBOT-ARU WORM! |
 |
WinFIX1.0.vbs |
FIX
Added by the GORMLEZ-A WORM! |
 |
wssdtu.exe |
Folder Service
Added by the MANIFEST TROJAN! |
 |
WINFAH.EXE |
Folding@home
Folding@Home is a distributed computing project which studies protein folding, misfolding, aggregation, and related diseases - must be running in order to access the internet to upload to the servers. Available via Start -> Programs |
 |
winlogon.exe |
FriendlyTypeName
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
winpopup.exe |
Fromine WinPopup
Instant Messenger program |
 |
winsvc.exe |
Generic Host Process for Win32 Services
Added by the SDBOT-O WORM! |
 |
winsvc32.exe |
Generic Host Process for Win32 Services
Added by the SDBOT-P WORM! |
 |
winlogon.exe |
Generic Host Process for Win32 Services
Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
WinLoaderXP.exe |
GenericHostXP
Added by the BDOOR-ACX TROJAN! |
 |
Winmod32.exe |
Gerenciamento de arquivos do Windows
Added by the DLOADER-WG TROJAN! |
 |
winsystems.exe |
german.exe
Added by the BAGLEDl-AE TROJAN! |
 |
wintems.exe |
german.exe
Added by the BAGLE-AS TROJAN! |
 |
wakeservice.exe |
Get-Torrent Service
Get-Torrent bittorrent client - Installs LOP adware |
 |
winB_.exe |
getwin
Added by the BANKER-HS TROJAN! |
 |
WinDash.EXE |
Global Startup
Detected by Kaspersky as the VB.Q WORM! |
 |
window.exe |
gpmce
Detected by Kaspersky as the VB.CK WORM! See here |
 |
windll.exe |
Graphics adapter service
Added by the ATNAS.A WORM! |
 |
wscript.exe gpremier.vbs |
gremier
Added by the GPREMIER WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "gpremier.vbs" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
WCESCOMM.EXE |
H/PC Connection Agent
Active sync for use with Windows CE based palm PC |
 |
WinHSD.exe |
Hardware Shell Detection
Added by a variant of the RBOT WORM! |
 |
Wizardnil.exe |
Help
Added by the BANCOS-BCZ TROJAN! |
 |
windowsupdate.exe |
HKLMRun
Added by the FORBOT-BJ WORM! (where HKLMRun represents HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun) |
 |
wiz98.exe |
hostserv
Added by a variant of the SDBOT WORM! |
 |
winHostsEdit.exe |
HostsFileMgr
AdBin from Gilmore Software Development. An easy solution to managing your Window's hosts file |
 |
We Love Lien Van de Kelder.exe |
http://www.lienvandekelder.be
Added by the MYTOB-CV WORM! |
 |
winsys.exe |
I am not Ranky. I am eTunnel!
Added by an unidentified WORM or TROJAN! |
 |
winlog.exe |
icq lite
Added by the IRCBOT-TJ TROJAN! |
 |
winlogon.exe |
ICQ Net
Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup! |
 |
webcamupdate.exe |
IcqBeta
Added by an unidentified TROJAN! |
 |
winlogon.exe |
ICQNet
Added by the NETSKY-C WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder |
 |
wini.exe |
IE Runtime
Added by the PICRATE.B WORM! |
 |
winis.exe |
IE Runtimes
Added by the RBOT-ADZ TROJAN! |
 |
wkstmg.exe |
IE6
Added by a variant of the SDBOT WORM! |
 |
winsnt.exe |
IE6
Added by the RBOT-GOV WORM! |
 |
WinSock.exe |
IExplorerService
Detected by Kaspersky as the AGENT.KIU TROJAN! See here |
 |
WashIdx.exe |
Index Washer
Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
 |
wsock32.exe |
InetServices
Added by the WOCK32-A TROJAN! |
 |
wmplayer.exe |
infamous.exe
Added by unknown malware. WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup. Infamous.exe is identified by Panda antivirus as Trj/Briss.A |
 |
WUSB11cfg.exe |
Instant Wireless Configuration Utility
Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration |
 |
WPC11Cfg.exe |
Instant Wireless Configuration Utility
Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration |
 |
wing32.exe |
Intec Service Drivers
Added by the RBOT.HAZ WORM! |
 |
winrvc.exe |
Intec Services Driverrs
Added by a variant of the SDBOT WORM! |
 |
winnook.exe |
Intel system tool
Added by the SPYRE-C TROJAN! |
 |
WinSocks5.exe |
internct
Added by the GRAYBIRD.F TROJAN! |
 |
winlogom.exe |
Internet
Added by a variant of the SDBOT WORM! |
 |
winsas32.exe |
internet
Added by a variant of the SDBOT WORM! |
 |
wins.exe |
Internet
Detected by PCTools as the RBOT.AAYF WORM! See here |
 |
winz32.exe |
INTERNET SERVISES
Added by the KWBOT.Z WORM! |
 |
wkfix.exe |
Internet2 Optimizer
Added by a variant of the RBOT WORM! |
 |
windows.exe |
InternetExplorer2
Added by the SDBOT-CZP WORM! |
 |
winz32.exe |
INTERNET_SERVISES
Added by the SDBOT.Q TROJAN! |
 |
WINDRV.EXE |
InterU
Added by the IRCINTER.A TROJAN! |
 |
WinCinemaMgr.exe |
Intervideo Win Cinema Manager
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
 |
WINCIN~1.EXE |
Intervideo Win Cinema Manager
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
 |
WinCinemaMgr.exe |
Intervideo WinCinema Manager
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
 |
WINCIN~1.EXE |
Intervideo WinCinema Manager
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
 |
WinScheduler.exe |
Intervideo WinScheduler
WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs |
 |
wnmgre.exe |
IPC Spool Manager
Added by the SDBOT-ZC WORM! |
 |
winspec.exe |
IPC Spool Manager
Added by the SDBOT-BLU WORM! |
 |
Winipcfgs.exe |
IPTable Configuration
Added by a variant of the RBOT WORM! |
 |
winmon32.exe |
iRis Active Monitor
Iris Antivirus - discontinued, replace with good alternative |
 |
WIMMUN32.exe |
iRiS AntiVirus Active Monitor
Iris Antivirus - discontinued, replace with good alternative |
 |
wintmp.exe |
ISPSERVICE
Detected by Trend Micro as the FLOOD.BC BACKDOOR! See here |
 |
winlogan.exe |
jkdfj94kgdftdf
Added by the ZLOB.BZ TROJAN! |
 |
winxp2.exe |
Jufualt
Added by the SDBOT-AAB WORM! |
 |
win1ogoin.exe |
KAVFOX
Added by the GWGHOST-M TROJAN! |
 |
wscntfy.exe |
KAVPersonal90
Added by the BANKER-FZ TROJAN! |
 |
Windll.exe |
KavRuns
Added by the TRYNOMA TROJAN! |
 |
winser.exe |
KernelCheck
Added by the TSPY_LMIR.SL TROJAN! |
 |
wmiprvse.exe |
Kernel_check
Added by the SONEBOT-B WORM! Note - this is not the legitimate wmiprvse.exe process which is always located in the System32wbem folder and should not normally figure in Msconfig/Startup! |
 |
winxp.exe |
key
Added by the BEAGLE.AG WORM! |
 |
winlog.exe |
key2
Added by the BAGLEDI-AL TROJAN! |
 |
wppewafaj.exe |
KnowledgeBase GUI
Added by the RBOT-GRZ WORM! |
 |
word.EXE |
KV2005
Added by the IW TROJAN! |
 |
winmine |
l44sys**
Added by the VBS.LIDO WORM - where ** is a number between 33 and 44 |
 |
wllmsngr.exe |
Live Messanger
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
win32.exe |
Load
Added by the RUBBLE-A WORM! |
 |
Wscript.exe LGuarg.exe.vbs |
Load-Guard
Added by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "LGuarg.exe.vbs" file is located in the Winnt or Windows folder |
 |
winldra.exe |
load32
Added by the NIBU.J BACKDOOR or DUMARU-BI TROJAN! Note - also known as Srv.SSA-KeyLogger by Sunbelt Software which has developed a free removal tool for this keylogger |
 |
WPSLOAD.EXE |
load=
Windows printing system that comes with the setup for Canon BJC series on the manufacturer's disk |
 |
WINOSCFG.EXE |
load=
Could it be something to do with configuring Windows on a new PC from an OEM supplier? |
 |
wpshrc.exe |
load=
Required to prevent configuration errors on a Compaq LBP-660 and LBP-460 parallel port laser printers (and maybe others) |
 |
wtfeat.exe |
Load=
Associated with the Wintab Digitizer |
 |
win32exec.exe |
load=
Added by the BITTER WORM! |
 |
WMPLAYER.EXE |
loader
Unknown baddie - WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup |
 |
wmimgr.exe |
LoadPFW
Added by the QEDS-B WORM! |
 |
watcher.exe |
LoadWatcher
Watcher spyware |
 |
winset.exe |
loadwin
Added by the QQPASS-I TROJAN! |
 |
winsys.exe |
loadwin
Added by the QQPASS-J TROJAN! |
 |
winlog.exe |
Login
Salfeld Child Control - parental control software |
 |
wrcam.exe |
Logitech Desktop Controller
Added by a variant of the RBOT WORM! |
 |
wincalc.exe |
LogService
Added by the PAPROXY TROJAN! |
 |
WIWT.EXE |
longos
Added by the BANKER-CD TROJAN! |
 |
wfdmgr.exe |
LSA
Added by the MYTOB.C WORM! |
 |
woekd.exe |
Lsass
Added by an unidentified WORM or TROJAN! |
 |
winupdate.exe |
LTM2
Added by the LITMUS.203 TROJAN! |
 |
winscan.exe |
LTM2
Added by the LITMUS-B TROJAN! |
 |
winvers16.exe |
LTM2
Added by the SMALL.ND TROJAN! |
 |
wusas.exe |
Machine Update Soft
Added by an unidfentified WORM! |
 |
WMIPRVSW.exe |
machine-debugger
Added by the AGOBOT.U WORM! |
 |
wintrims.exe |
MC
Added by the WINTRIM TROJAN! |
 |
WINTRIM.EXE |
MC
Added by the WINTRIM_A TROJAN! |
 |
Win32.dll.vbs |
mcafee
Added by the CATCHER-B WORM! |
 |
WebScanX.exe |
McAfeeWebscanX
From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc |
 |
wisp.exe |
MCX Update
Added by the RBOT-AQH WORM! |
 |
winy.exe |
MD IE Plugin
Adware |
 |
wmplayer.exe |
Media Player
Added by the AGOBOT-BM WORM! |
 |
wowdache.exe |
Meeting Connection
Added by the PPDOOR-D TROJAN! |
 |
Wmsngr.exe |
Messenger
Added by a variant of the RBOT WORM! |
 |
winldx32.exe |
Microfot Update
Added by a variant of the RBOT WORM! |
 |
winssx.exe |
Microft Update 32
Added by the RBOT-AQS WORM! |
 |
wdfmrg.exe |
Micromedia Flash Update
Added by a variant of the SDBOT WORM! |
 |
winmx32.EXE |
MICROSFT MX UPDATE SUPPORT
Added by the IRCBOT-FD WORM! |
 |
wilogon32.exe |
Microsof Winlog Host
Added by the RBOT.XC WORM! |
 |
winampaa.exe |
Microsoft
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
winline.exe |
Microsoft
Detected by Kaspersky as the AGENT.KT TROJAN! See here |
 |
wplayer.exe |
Microsoft
Detected by Kaspersky as the RBOT.GHZ BACKDOOR! See here |
 |
win32.exe |
Microsoft
Added by the DARKMOON TROJAN! |
 |
wuauclt.exe |
Microsoft
Added by the QQROB-AQ TROJAN! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup! |
 |
wcsntfy.exe |
Microsoft
Added by the AGOBOT-AHT WORM! |
 |
windl32.exe |
Microsoft
Added by the SDBOT-DCZ WORM! |
 |
WinSecUp.exe |
Microsoft
Added by the RBOT-GPL WORM! |
 |
wsim32.exe |
Microsoft
Added by the RBOT-GTL WORM! |
 |
wplayer.exe |
Microsoft
Detected by Kaspersky as the RBOT.DYU TROJAN! See here |
 |
wuauclt.exe |
Microsoft (R) Windows Update Service
Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup! |
 |
wuapdate16.exe |
Microsoft 16Bit Update
Added by the RBOT.CZ WORM! |
 |
wupdt64.exe |
Microsoft 64 Bit Runtime Updater
Added by a variant of the RBOT WORM! |
 |
winupdate.exe |
Microsoft auto update
Added by the BMBOT TROJAN! |
 |
WINHLP16.EXE |
Microsoft Auto Update
Added by the RBOT.GY WORM! |
 |
wuauclt.exe |
Microsoft auto update
Added by the CULT-B TROJAN! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup! |
 |
wincmd.exe |
Microsoft Command Line
Added by a variant of the RBOT WORM! |
 |
wurmgrd32.exe |
Microsoft ConfgKeys
Added by the RBOT-ARX WORM! |
 |
windowz.exe |
Microsoft Corp SSL Certificates
Added by the RBOT-GCZ WORM! |
 |
wupdates.exe |
Microsoft Corp Updates
Added by the RBOT-AUU WORM! |
 |
webcp.exe |
Microsoft CP Web Manager
Added by the IRCBOT.HP TROJAN! |
 |
wincrs.exe |
Microsoft Crs Fix Serv
Added by the SDBOT.BWF WORM! |
 |
wupades.exe |
Microsoft DDE Control
Added by a variant of the SDBOT WORM! |
 |
wuamgrd.exe |
Microsoft DirectX
Added by the SDBOT.MY WORM! |
 |
wkssr.exe |
Microsoft dll Host Service
Added by a variant of the SDBOT WORM! |
 |
winlib32.exe |
Microsoft DLL Library
Added by the ATNAS.A WORM! |
 |
windll.exe |
Microsoft Dll Management
Added by the RBOT-MT WORM! |
 |
winavguard.exe |
Microsoft DLL Verifier
Added by the SDBOT.AAD WORM! |
 |
windrv.exe |
Microsoft Driver Control
Added by the SDBOT.FW WORM! |
 |
WSconf.exe |
Microsoft Drivers
Added by a variant of the SDBOT WORM! |
 |
wserb32.exe |
Microsoft ErgoPack
Added by the RBOT-RI WORM! |
 |
wuamngr32.exe |
Microsoft Excell
Added by the RBOT-QH WORM! |
 |
wmgrdf.exe |
Microsoft File Demand Manager
Added by a variant of the RBOT WORM! |
 |
wnpzjpuw.exe |
Microsoft FixUp
Added by a variant of the SDBOT WORM! |
 |
wupdate.exe |
Microsoft Generic Update Manager
Added by the RBOT-AWC TROJAN! |
 |
WINHOSTING.EXE |
Microsoft Hosting Service
Added by the RBOT.AEV WORM! |
 |
windows32.exe |
Microsoft Internet
Added by the SDBOT-F WORM! |
 |
wincfg16.exe |
Microsoft Internet
Added by a variant of the SDBOT WORM! |
 |
wcumrg.exe |
Microsoft Intrenet Explorer
Added by the SDBOT-AFD WORM! |
 |
win64.exe |
Microsoft IT Update
Added by the RBOT.GA WORM! |
 |
winn43.exe |
Microsoft IT Update
Added by a variant of the RBOT WORM! |
 |
win43.exe |
Microsoft IT Update
Added by the RBOT-SA WORM! |
 |
windows.exe |
Microsoft IT Update
Added by the RBOT-GL WORM! |
 |
winsyst32.exe |
Microsoft IT Update
Added by the RBOT-FC WORM! |
 |
winscr32.exe |
Microsoft Java Virtual Machine
Added by a variant of the WOOTBOT WORM! |
 |
Windows_kernel32.exe |
Microsoft Kernel
Added by the NETSKY.AE WORM! |
 |
winlogin.exe |
Microsoft Login
Added by the RBOT-AJP WORM! |
 |
wintcp32.exe |
Microsoft Lsass Service
Added by a variant of the IRCBOT TROJAN! |
 |
winjava.exe |
Microsoft Machine
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
winmplayers.exe |
Microsoft media
Added by a variant of the SPYBOT WORM! |
 |
winmplayer.exe |
Microsoft media services
Added by the RBOT.ZO WORM! |
 |
winmes.exe |
Microsoft MediaScope
Added by the RBOT-XU WORM! |
 |
wdgmr32.exe |
Microsoft MicroP Protocol
Added by a variant of the RBOT WORM! |
 |
winexec32.exe |
Microsoft NT Update
Added by a variant of the RBOT WORM! |
 |
winupdates.exe |
Microsoft Office Start
Added by the GAOBOT.BC WORM! |
 |
windr128.exe |
Microsoft Problem Doctor
Added by the SMALLTRO.EF TROJAN! |
 |
windr32.exe |
Microsoft Problem Doctor
Added by a variant of the SMALLTRO.EF TROJAN! |
 |
windr64.exe |
Microsoft Problem Doctor
Added by a variant of the SMALLTRO.EF TROJAN! |
 |
windos.exe |
Microsoft Rundll
Added by the SDBOT-WF WORM! |
 |
winService.exe |
Microsoft Security
Added by a variant of the RBOT WORM! |
 |
wcsntfy.exe |
Microsoft Security Center
Added by the SDBOT.BYD WORM! |
 |
winnt.exe |
Microsoft Security Management
Added by the RBOT-MQ WORM! |
 |
winserv.exe |
Microsoft Security Management
Added by the RBOT-MJ WORM! |
 |
winamp.exe |
Microsoft Security Management
Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of the Program Files directory |
 |
wuauct1.exe |
Microsoft Security Management
Added by a variant of the RBOT WORM! |
 |
winamp.exe |
Microsoft Security Manager
Added by the RBOT WORM! Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of the Program Files directory. This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
windowsupdate.exe |
Microsoft Security Monitor Process
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
windowsupdate.exe |
Microsoft Security Monitor Process
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
wininit.exe |
Microsoft Security Process
Added by the RBOT-FKM WORM! |
 |
wuauct1.exe |
Microsoft Server Applacations
Added by a variant of the RBOT WORM! |
 |
winsvc.exe |
Microsoft Service
Added by the SPYBOT-DB WORM! |
 |
winlogin.exe |
Microsoft Service Login Manager
Added by a variant of the IRCBOT TROJAN! |
 |
winsvc.exe |
Microsoft Service Manager
Added by a variant of the RBOT WORM! See here |
 |
WindowsSP.exe |
Microsoft Service Pack
Added by the RBOT-RF WORM! |
 |
winsound.exe |
Microsoft Sound Technology
Added by the RBOT-AGG WORM! |
 |
win32.exe |
Microsoft SpA Service
Added by the RBOT.ATS WORM! |
 |
Winupd32.exe |
Microsoft SpA Service
Added by the RBOT.LT WORM! |
 |
win32lib.exe |
Microsoft Standard Executions Library
Added by the RBOT-AUK WORM! |
 |
winsocks5.exe |
Microsoft standard protector
Added by the SMALL.CF TROJAN! |
 |
wmpIayer.exe |
Microsoft startup
Added by the IRCBOT.ACI TROJAN! |
 |
winslogin.exe |
Microsoft Stuff you know
Added by a variant of the SDBOT WORM! |
 |
winoem.exe |
Microsoft Svchost local services
Added by the RBOT-FPE WORM! |
 |
WinLoginnn.exe |
Microsoft Synchronization Manager
Added by the SPYBOT.FO WORM! |
 |
winupdate.exe |
Microsoft Synchronization Manager
Added by the SDBOT.ER WORM! |
 |
win.exe |
Microsoft Synchronization Manager
Added by the SDBOT.AK WORM! |
 |
winlogon32.exe |
Microsoft Synchronization Manager
Added by the SDBOT.AEU WORM! |
 |
wincfg32.exe |
Microsoft Synchronization Manager
Added by the SDBOT.DO WORM! |
 |
wmedia.exe |
Microsoft Synchronization Manager
Added by the SDBOT.BFC WORM! |
 |
win932.exe |
Microsoft Synchronization Manager
Added by the SDBOT.AH WORM! |
 |
Wnetlib.exe |
Microsoft System Checkup
Added by the DONK.C WORM! |
 |
wnetmgr.exe |
Microsoft System Checkup
Added by the DONK.Q WORM! |
 |
windir32.exe |
Microsoft System DLL Services Configuration
Added by the SDBOT-ACY TROJAN! |
 |
winIogon2.exe |
Microsoft System Service
Added by a variant of the IRCBOT TROJAN! |
 |
wintcp32.exe |
Microsoft TCP Protocol
Added by a variant of the IRCBOT TROJAN! |
 |
winupn.exe |
Microsoft Telecoms Center
Added by a variant of the SDBOT WORM! |
 |
wuamkopxp.exe |
Microsoft U
Added by the RBOT-AHC WORM! |
 |
winrarx.exe |
MICROSOFT UNPACK SYSTEM
Added by a variant of the RBOT WORM! |
 |
winsys32.exe |
Microsoft Update
Added by a variant of the RBOT WORM! |
 |
wuamgrd.exe |
Microsoft Update
Added by the RBOT-LK WORM! |
 |
wuammgr32.exe |
Microsoft Update
Added by the RBOT-AW WORM! |
 |
wudmate.exe |
Microsoft Update
Added by the RBOT.AP WORM! |
 |
wuamgrd32.exe |
Microsoft Update
Added by the RBOT.ZB WORM! |
 |
webm.exe |
Microsoft Update
Added by the SDBOT.WK WORM! |
 |
wuagrd.exe |
Microsoft Update
Added by the RBOT-FK WORM! |
 |
wauguard.exe |
Microsoft Update
Added by the RBOT.AEE WORM! |
 |
winscv.exe |
Microsoft Update
Added by the RBOT-BH WORM! |
 |
winsys.exe |
Microsoft Update
Added by the RBOT-GV WORM! |
 |
wserv32.exe |
Microsoft Update
Added by the RBOT.AF WORM! |
 |
wtm32.exe |
Microsoft Update
Added by the RBOT-AQ WORM! |
 |
wumgrd.exe |
Microsoft Update
Added by the SDBOT-KY WORM! |
 |
wuampd.exe |
Microsoft Update
Added by the RBOT-UT WORM! |
 |
windows24.exe |
Microsoft Update
Added by a variant of the RBOT WORM! |
 |
wingrd32.exe |
Microsoft Update
Added by the RBOT-DW WORM! |
 |
wssvr.exe |
Microsoft Update
Added by the RBOT-OD WORM! |
 |
wuamagr32.exe |
Microsoft Update
Added by the SPYBOT.CG WORM! |
 |
WinUpdate32.exe |
Microsoft Update
Added by the RBOT-TI WORM! |
 |
wkfix.exe |
Microsoft Update
Added by the RBOT-ABZ WORM! |
 |
winamp.exe |
Microsoft Update
Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player |
 |
win-mang.exe |
Microsoft Update
Added by the RBOT-AFK WORM! |
 |
winupdater.exe |
Microsoft Update
Added by the RBOT.BIN WORM! |
 |
wuamk0032.exe |
Microsoft Update
Added by a variant of the RBOT WORM! |
 |
wuamk032.exe |
Microsoft Update
Added by the RBOT-AHD WORM! |
 |
wuamk0p32.exe |
Microsoft Update
Added by a variant of the RBOT WORM! |
 |
wuamkop.exe |
Microsoft Update
Added by the RBOT-AFI WORM! |
 |
wuamkop32.exe |
Microsoft Update
Added by the RBOT.BGU WORM! |
 |
wuampkd.exe |
Microsoft Update
Added by the SDBOT.BBX WORM! |
 |
win32.exe |
Microsoft Update
Added by a variant of the SDBOT WORM! |
 |
wininit.exe |
Microsoft Update
Added by the RBOT-AKR WORM! |
 |
wuamgrd3.exe |
Microsoft Update
Added by the RBOT-AMC WORM! |
 |
Wudates.exe |
Microsoft Update
Added by a variant of the RBOT WORM! |
 |
wuagmsd.exe |
Microsoft Update
Added by the RBOT-AX WORM! |
 |
wuamgrb.exe |
Microsoft Update
Added by the RBOT-AZE WORM! |
 |
WINDOC.EXE |
Microsoft Update
Added by the SDBOT.PF WORM! |
 |
WinDrv32.exe |
Microsoft Update
Added by the RBOT.EGW WORM! |
 |
winupdate.exe |
Microsoft update
Added by a variant of the RBOT WORM! |
 |
wangard.exe |
Microsoft Update
Added by the RBOT-LH WORM! |
 |
wuamgrdx.exe |
Microsoft Update
Added by a variant of the SPYBOT WORM! See here |
 |
wutr.exe |
Microsoft Update
Added by the SPYBOT.AAR WORM! |
 |
wininit.exe |
Microsoft Update 32
Added by the RBOT-ANY WORM! |
 |
wininit32.exe |
Microsoft Update 32
Added by a variant of the RBOT WORM! |
 |
winitXP32.exe |
Microsoft Update 32
Added by a variant of the RBOT WORM! |
 |
wiit.exe |
Microsoft Update 32
Added by the RBOT-AMS WORM! |
 |
winin.exe |
Microsoft Update 32
Added by the RBOT-ARR WORM! |
 |
wuinit.exe |
Microsoft Update 32
Added by the AGOBOT-UE WORM! |
 |
wininit32.exe |
Microsoft Update 64 BIT
Added by the RBOT-AHE WORM! |
 |
winman32.exe |
Microsoft Update 64 BIT
Added by the RBOT-AKI WORM! |
 |
winl32xe.exe |
Microsoft Update 64 BIT
Added by the RBOT-AQO WORM! |
 |
WIN32SNC.EXE |
MICROSOFT UPDATE CONFIGURATION
Added by the RBOT-AI WORM! |
 |
wincfg32.exe |
Microsoft Update Debugger
Added by the SPYBOT.ZC WORM! |
 |
wuauclt.exe |
Microsoft Update Device Drivers
Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup! |
 |
winusers.exe |
Microsoft Update Loaders 2005
Added by the RBOT-AIQ WORM! |
 |
winusersystem32.exe |
Microsoft Update Loaders 2006
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
wuawx.exe |
Microsoft Update Machine
Added by the RBOT-CE WORM! |
 |
winupdt.exe |
Microsoft Update Machine
Added by the RBOT-FP WORM! |
 |
wuamgd.exe |
Microsoft Update Machine
Added by the SDBOT.HQ WORM! |
 |
wupdt32x.exe |
Microsoft Update Machine
Added by a variant of the SDBOT WORM! |
 |
windowsu.exe |
Microsoft Update Machine
Added by a variant of the RBOT WORM! |
 |
wininigo.exe |
Microsoft Update Machine
Added by a variant of the RBOT WORM! |
 |
winmgr.exe |
Microsoft Update Machine
Added by a variant of the RBOT WORM! |
 |
Winmsixp32.exe |
Microsoft Update Machine
Added by the RBOT.DN WORM! |
 |
Winregs32.exe |
Microsoft Update Machine
Added by the RBOT.DN WORM! |
 |
winxpini.exe |
Microsoft Update Machine
Added by the RBOT-OB WORM! |
 |
wuamgrd.exe |
Microsoft Update Machine
Added by the RBOT-HE WORM! |
 |
wuagrd.exe |
Microsoft Update Machine
Added by the RBOT-GF WORM! |
 |
winhost.exe |
Microsoft Update Machine
Added by the RBOT-GK WORM! |
 |
winss.exe |
Microsoft Update Machine
Added by the RBOT.JU WORM! |
 |
WUAMGRDXS.EXE |
Microsoft Update Machine
Added by the RBOT-GL WORM! |
 |
windowsup.exe |
Microsoft Update Machine
Added by the RBOT-FV WORM! |
 |
wuamgard.exe |
Microsoft Update Machine
Added by the SPYBOT.CS WORM! |
 |
wupdate32.exe |
Microsoft Update Machine
Added by a variant of the RBOT WORM! |
 |
winnie.exe |
Microsoft Update Machine
Added by the RBOT-ACD WORM! |
 |
winortho.exe |
Microsoft Update Machine
Added by the RBOT-NW WORM! |
 |
wins32.exe |
Microsoft Update Machine
Added by the RBOT.EZ WORM! |
 |
wftestb.exe |
Microsoft Update Machine
Added by the RBOT-AFZ WORM! |
 |
Win32.exe |
Microsoft Update Machine
Added by the SDBOT.UV WORM! |
 |
windns.exe |
Microsoft Update Machine
Added by the RBOT.EF WORM! |
 |
WINSVC32.EXE |
Microsoft Update Machine
Added by the RBOT.CU WORM! |
 |
winupdte.exe |
Microsoft Update Machine
Added by the RBOT-GKL WORM! |
 |
wlimyc.exe |
Microsoft Update Machine
Added by the RBOT-GQN WORM! |
 |
winini.exe |
Microsoft Update Machine
Added by the RBOT-KV WORM! |
 |
WINRLS.EXE |
Microsoft Update Manager
Added by the RBOT-AF WORM! |
 |
wmipcvse.exe |
Microsoft Update Process
Added by the AGOBOT-JF TROJAN! |
 |
wcsnfty.exe |
Microsoft Update Services
Added by the RBOT-AGK WORM! |
 |
wsnfty.exe |
Microsoft Update Services
Added by the RBOT-AFU WORM! |
 |
wuam.exe |
Microsoft Update Time
Added by the RBOT-M WORM! |
 |
wuammgrd32.exe |
Microsoft Update USB2
Added by the RBOT-ADT WORM! |
 |
winupdate32a.exe |
Microsoft Update Win32a
Added by the RBOT-LO WORM! |
 |
winupdate32x.exe |
Microsoft Update Win32x
Added by the RBOT-AJN WORM! |
 |
Winsys32.exe |
Microsoft Updater
Added by a variant of the RBOT WORM! |
 |
wuamgrds.exe |
Microsoft Updater
Added by the RBOT.A WORM! |
 |
WinFixd32.exe |
Microsoft Updater Resources
Added by the SPYBOT.CA WORM! |
 |
WINDLL32XP.EXE |
Microsoft Updaters Pros
Added by the SPYBOTTER.GEN VIRUS! |
 |
wkssvr.exe |
Microsoft Updates
Added by the RBOT.R WORM! |
 |
wkssvrs.exe |
Microsoft Updates
Added by the RBOT-EB WORM! |
 |
wuamgrd.exe |
Microsoft Updates
Added by the RBOT-CO WORM! |
 |
wtemp32.exe |
Microsoft Updates
Added by the RBOT-AHQ WORM! |
 |
wgafixer.exe |
Microsoft Updates 2 USB
Added by a variant of the RBOT WORM! |
 |
WinFixIDs.exe |
Microsoft Updates Resources
Added by a variant of the RBOT WORM! |
 |
wuamguards.exe |
Microsoft Updating
Added by the RBOT-BY WORM! |
 |
websvc.exe |
Microsoft Updating Client
Added by the RBOT.AQ WORM! |
 |
winlogon.exe |
Microsoft Visual SourceSafe
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
webcp32.exe |
Microsoft Web CP Manager
Added by a variant of the SDBOT WORM! See here |
 |
wdevice.exe |
Microsoft Web Device
Added by a variant of the SDBOT WORM! |
 |
webmsn.exe |
Microsoft web update
Added by the RBOT-EMQ WORM! |
 |
winsupdater.exe |
MicroSoft Wind0ws Updater
Added by a variant of the RBOT WORM! |
 |
Winupdsdgm.exe |
Microsoft Windows 2000
Added by the GAOBOT.AO WORM! |
 |
win32update.exe |
Microsoft Windows 32 Update
Added by a variant of the IRCBOT TROJAN! |
 |
wincomm.exe |
Microsoft Windows Communicator for NT/XP
Added by the RBOT.ATH WORM! |
 |
win32conf.exe |
Microsoft Windows Config 32
Added by a variant of the RBOT WORM! |
 |
windir32.exe |
Microsoft Windows DLL Services Configuration
Added by the SDBOT.BHF WORM! |
 |
windir32a.exe |
Microsoft Windows DLL Services Configuration
Added by a variant of the SDBOT.BHF WORM! |
 |
windll32.exe |
Microsoft Windows DLL Services Configuration
Added by the SDBOT.BHD WORM! |
 |
winDSL.exe |
Microsoft Windows DLL Services Configuration
Added by the SDBOT-ZG WORM! |
 |
windrv.exe |
Microsoft Windows Drivers
Added by a variant of the SDBOT WORM! |
 |
windvr.exe |
Microsoft Windows DVR
Added by the RBOT-AXD WORM! |
 |
websploit.exe |
Microsoft Windows Express
Added by a variant of the SPYBOT WORM! See here |
 |
windowslogonb.exe |
Microsoft Windows Express
Detected by PCTools as the SDBOT.ABOO WORM! See here |
 |
Windowz.exe |
Microsoft Windows GUI
Added by the RANDEX.AEV WORM! |
 |
winkrnl386.exe |
Microsoft Windows Kernel Services
Added by the ZEBROXY TROJAN! |
 |
wloader.exe |
Microsoft Windows Loader
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
winlogon.exe |
Microsoft Windows Logon Process
Added by the PROXYSER-R TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This worm file is placed in the Winnt or Windows folder |
 |
wimp.exe |
Microsoft Windows Media Player
Added by the RBOT-FN WORM! |
 |
wregistry.exe |
Microsoft Windows Registry Service
Added by the AGOBOT.AKG WORM! |
 |
windocs.exe |
Microsoft Windows Secure
Added by a variant of the SDBOT WORM! |
 |
windocs.exe |
Microsoft Windows Secure
Added by a variant of the SDBOT WORM! |
 |
wurguar.exe |
Microsoft Windows Securety
Added by the RBOT-KY WORM! |
 |
wscndrives.exe |
Microsoft Windows Security
Added by the RBOT-AJK WORM! |
 |
winsys.exe |
Microsoft Windows Service
Added by the RBOT-ADP WORM! |
 |
winspkn.exe |
Microsoft Windows Service Pack
Added by the RBOT-AYD WORM! |
 |
winsockx32.exe |
Microsoft Windows Socketx32 Services
Added by the RBOT-FWT WORM! |
 |
winms.exe |
Microsoft Windows Storage Machine Service
Added by the RBOT-AHK WORM! |
 |
winsvc.exe |
Microsoft Windows System Service Manager
Added by the SPYBOT.LR WORM! |
 |
windows.exe |
Microsoft Windows Updata
Added by a variant of the RBOT WORM! |
 |
windowsupdate.exe |
Microsoft Windows Update
Added by the AGOBOT.ON WORM! |
 |
wuap.exe |
Microsoft Windows Update Application
Added by a variant of the RBOT WORM! |
 |
win-logon.exe |
Microsoft Windows Update Logon
Added by a variant of the RBOT WORM! |
 |
wupdmgr32.exe |
Microsoft Windows Update Service
Added by the DOS.AUTOCAT TROJAN! |
 |
windates.exe |
Microsoft Windows Updater
Added by the SDBOT.TE WORM! |
 |
winupdgm.exe |
Microsoft Windows Updater
Added by the GAOBOT.BI WORM! |
 |
WINIUPDATES.EXE |
Microsoft Windows Updater
Added by the RBOT-KK WORM! |
 |
WINUPDATE.EXE |
Microsoft Windows Updater
Added by the SDBOT-PU WORM! |
 |
win32upd.exe |
Microsoft Windows Updater
Added by the RBOT-EC WORM! |
 |
wsap32.exe |
Microsoft Windows Updates
Added by a variant of the SDBOT WORM! |
 |
winsass.exe |
Microsoft Windows WinSaSS Management
Added by the RBOT-APW WORM! |
 |
winexplorer.exe |
Microsoft Windows XP/2K Explorer
Added by a variant of the IRCBOT TROJAN! See here |
 |
WinKey.exe |
Microsoft Winedows startup
Added by a variant of the SDBOT WORM! See here |
 |
WinSGR32.exe |
Microsoft WINGS32 Protocol
Added by the RBOT-APU WORM! |
 |
winrar.exe |
Microsoft WinRaR
Added by the RBOT-AEC WORM! |
 |
ws2_32s.exe |
Microsoft Winsock Wrapper
Added by a variant of the SPYBOT WORM! |
 |
Winamp61.exe |
Microsoft WinUpdate
Added by a variant of the RBOT WORM! |
 |
Winupd32.exe |
Microsoft WinUpdate
Added by the RBOT.MQ WORM! |
 |
WinNTinit32.exe |
Microsoft WinUpdate
Added by the RBOT.VS WORM! |
 |
wkcalrem.exe |
Microsoft Works Calendar Reminders
Produces a pop-up reminder of events scheduled using the MS Works Calendar |
 |
WksSb.exe |
Microsoft Works Portfolio
The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program.Can be prevented from starting from a setting within Portfolio |
 |
wkdetect.exe |
Microsoft Works Update Detection
Checks for updates to MS Works |
 |
winworld.exe |
Microsoft World Service
Added by an unidentified IRC worm with backdoor capability! |
 |
wuamkoppnp.exe |
Microsoft X Update
Added by the RBOT-ANI WORM! |
 |
winsystem32xp.exe |
Microsoft Xp Systems loader
Added by the KELVIR.W WORM! |
 |
win32xpsys.exe |
Microsoft Xp Systems loaders
Added by the SPYBOT.NYT WORM! |
 |
wngard.exe |
Microsoft-Update
Added by the RBOT-JV WORM! |
 |
win32sys.exe |
Microsoft32
Added by an unidentified WORM or TROJAN! |
 |
wees.exe |
Microsoftf DDEs Control
Added by a variant of the RBOT WORM! |
 |
why-.exe |
Microsoftf DDEs Control
Added by the RBOT-AMV WORM! |
 |
w33s.exe |
Microsoftf DDEs Control
Added by a variant of the RBOT WORM! |
 |
waes.exe |
Microsoftf DDEs Control
Added by a variant of the RBOT WORM! |
 |
winmplayd.exe |
Microsofts media
Added by an undidentified WORM or TROJAN! |
 |
wingtp.exe |
Microsofts media
Added by the RBOT-VO WORM! |
 |
winmep.exe |
Microsofts MediaScope
Added by the RBOT-WB WORM! |
 |
winmedplay.exe |
Microsofts MediaScope
Added by a variant of the RBOT WORM! |
 |
Wintsk32.exe |
MicrosoftServiceManager
Added by the YAHA.U WORM! |
 |
WinUp32.exe |
MicrosoftUpdate
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
windll.exe |
MicrosoftUpdate
Added by the RBOT-IH WORM! |
 |
windrive.exe |
Micrsoft Driver
Added by the SDBOT.AF TROJAN! |
 |
wcnsfty.exe |
Micsorosft Security Center
Added by the RBOT-AHU WORM! |
 |
wimsqaad.exe |
Miosf Update
Added by the SDBOT.AG TROJAN! |
 |
wuampkd.exe |
Mircosoft Update
Added by a variant of the SDBOT WORM! |
 |
win32x.exe |
Mismo
Added by the RBOT-JP WORM! |
 |
WAed.pif |
Mlcr0s0ftf DDEs C0ntr0i
Added by the RBOT-BJW WORM! |
 |
winmgmt.exe |
MMCWINMGMT
Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here |
 |
webcomp.exe |
Mobipocket Web Companion
Related to Mobipocket eBook Reader |
 |
wuaclt.exe |
Modifiet Amateur HTPB
Detected by Trend Micro as the IRCBOT.AYS WORM! See here |
 |
Wupated.exe |
Ms Builders
Added by the AGOBOT-SS WORM! |
 |
wrapper.exe |
MS Java Service Wrapper for Windows NT & XP
Added by the VANEBOT-D WORM! |
 |
winPE.exe |
ms ownage
Added by the RBOT-AJL WORM! |
 |
wpad.exe |
MS PLUS INC
Added by the MYTOB-AN WORM! |
 |
winscv.exe |
MS Service Drivers
Added by the SDBOT-COG WORM! |
 |
winser.exe |
Ms sock for Windows NT
Added by a variant of the SDBOT WORM! |
 |
win32ttb.exe |
MS Unix Binary
Added by the SPYBOT.OQ WORM! |
 |
Win32Update.exe |
MS Unix Binary
Added by the RBOT-BAS WORM! |
 |
WinGuard.exe |
MS Unix Binary
Added by the RBOT-ACL WORM! |
 |
winservnt32.exe |
Ms Update WinServices NT/XP
Added by the VANEBOT-G WORM! |
 |
windriver.exe |
MS Win32 Network Services
Added by the AGOBOT.ADH WORM! |
 |
web.exe |
MS-Connect
Adult content dialler - see here |
 |
winlog.exe |
msconfig
Added by the IRCBOT-TJ TROJAN! |
 |
winnsyst.exe |
MSControl31
Added by the RBOT.CFY WORM! |
 |
winmp.exe |
MSIdll
Added by a variant of the RBOT WORM! |
 |
winlogon.exe |
MSMSGS
Added by the RAHIWI.A WORM! |
 |
wdlrss.exe |
MSN
Added by a variant of the SDBOT TROJAN! |
 |
wkssvr.exe |
MSN
Added by the PUSHBOT.S WORM! |
 |
wkssvrs.exe |
MSN
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
wksvr.exe |
MSN
Added by the IRCBOT-XU WORM! |
 |
wmev.exe |
MSN
Added by a variant of the SPYBOT WORM! See here |
 |
winntmsn.exe |
MSN Messanger Live
Added by the RBOT-FSO WORM! |
 |
windns.exe |
Msn Messeng
Added by a variant of the RBOT WORM! |
 |
winproc.exe |
MSN Service Updates
Added by the KELVIR-BB WORM! |
 |
windatemanager.exe |
Msn Updater
Added by the SDBOT.TS WORM! |
 |
winagent.exe |
MsnExplorer
Added by the EQ TROJAN! |
 |
winampb.exe |
msnnt
Chinese originated adware - detected by Kaspersky as the AGENT.TL TROJAN! |
 |
winampf.exe |
msnnt
Added by the SMALL.DTS TROJAN! |
 |
winss.exe |
MSOleath32
Added by the KATHER TROJAN! |
 |
wiaadmgr.exe |
MSPP System Update 64
Detected by Kaspersky as the RANKY.GEN TROJAN! |
 |
winupdate.exe |
mssonfig
Added by a variant of the SDBOT WORM! |
 |
WINUPD.EXE |
MSStartOptimizer
Added by the DASMIN-E TROJAN! |
 |
wstask32.exe |
MsTask
Added by the MYTOB-FE WORM! |
 |
wupd.exe |
MSUpdate
Added by the ALADINZ.M TROJAN! |
 |
wsdrt32.exe |
MsWindows DRT Drivers
Added by the RBOT.ALT WORM! |
 |
winlogon.exe |
MSWinlogon
Added by the AGENT-FZM TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
winupd.exe |
MSWinupd
Added by the DLOADER-YE or DLOADR-AAA or DLOADER-ZF TROJANS - and others |
 |
winupdate.exe |
MSWinupdate
Added by the DLOADR-AAW TROJAN! |
 |
wdfmgr.exe |
MS_Update Check
Added by the AGOBOT-TB WORM! |
 |
wjview ...MyPointsPointAlertrun.exe |
MyPointsPointAlert
"With MyPoints you can earn rewards from name-brand merchants. You can even earn vacations and frequent flyer miles". Dubious privacy policy |
 |
winexplor.exe |
mysoft
Browser hijacker, also detected as the STARTPA-JR TROJAN! |
 |
winsnav.vbs |
NAV Agent
Added by the ANPES WORM! |
 |
wmilib32.exe |
NAV Agent
Added by the VB-XU TROJAN! |
 |
WINDBKGND.EXE |
NB Windows Patterns
Part of McAfee Nuts & Bolts. With Background Patterns, you can change background patterns of wizard and dialog windows |
 |
winntsrv -l -p10001 -d -e cmd.exe -L |
NC1565
Added by the NEWLEY-A WORM! |
 |
windows.exe |
NDIS Adapter
Added by the FORBOT-BR WORM! |
 |
Winman.exe |
NDIS Adapter
Added by the WOOTBOT.AG WORM! |
 |
winlogin.exe |
NDplDeamon
Added by the RANDEX.E WORM! |
 |
wmp9.exe |
Nero Updater.6.12
Added by the AGOBOT-AAG WORM! |
 |
winjava.exe |
NeroUpdater6.8
Added by the AGOBOT.AMK WORM! |
 |
WINREG.EXE |
Net
Added by the ASSASIN.D TROJAN! |
 |
winserv.exe |
NetApp
Added by the SHADOWTHIEF TROJAN! |
 |
wlan111t.exe |
NETGEAR WG111T Smart Wizard
Configuration utility for the Netgear WG111T multi-rate Wireless USB 2.0 Adapter that "provides wireless access to your desktop or notebook PC through the computer's USB port" |
 |
winclient.exe |
NetPatrol
NetPatrol network monitoring software |
 |
WgwMngr.exe |
NettGain2000
Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so |
 |
wunit32.exe |
Netunit32
Added by an unidentified WORM or TROJAN! |
 |
winssh.exe |
Network Access
Added by a variant of the SDBOT WORM! |
 |
wuamgrd.exe |
Network Protocol Service
Added by the RBOT.EA WORM! |
 |
wintcp.exe |
Network protocol service
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
WinNPS.exe |
Network Provisioning Service
Added by an unidentified WORM/TROJAN! |
 |
WinAntiVirusPro2006Installer.exe |
NI.UWA6P_0001_N56M1001
WinAntiVirus Pro 2006 misleading virus software - not recommended, see here |
 |
WinAntiVirusPro2006Installer[1].exe |
NI.UWA6P_0001_N69M0303
WinAntiVirus Pro 2006 misleading virus software - not recommended, see here |
 |
WinAntiVirusPro2006FreeInstall.exe |
NI.UWA6P_0001_N73M1004
WinAntiVirus Pro 2006 misleading virus software - not recommended, see here |
 |
winantiviruspro2006freeinstall[1].exe |
NI.UWA6P_0001_N91M1807
WinAntiVirus Pro 2006 misleading virus software - not recommended, see here |
 |
winantiviruspro2007freeinstall[1].exe |
NI.UWA7P_0001_N91M0809
WinAntiVirus Pro 2007 misleading virus software - not recommended, see here |
 |
wsul.exe |
Norton Service Driver
Added by the RBOT-ABI WORM! |
 |
winsvc.exe |
Norton Update
Added by the AGOBOT.ALP WORM! |
 |
winset.exe |
Norton Updater
Added by a variant of the SPYBOT WORM! |
 |
wtta.exe |
Notn
PurityScan/Clickspring adware |
 |
WinNTLM.exe |
NT LM Security Support Provider
Added by a variant of the SDBOT WORM! |
 |
wntsf.exe |
NTSF MICROSOFT SYSTEM
Added by the RBOT.ATC WORM! |
 |
winsis32.exe |
NTSF MICROSOFT SYSTEM
Added by a variant of the RBOT WORM! |
 |
winlogon.exe |
nvchost
Added by the KLONE-J TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
windowsp.exe |
NvCpl
Added by a variant of the SDBOT WORM! |
 |
winasp.exe |
NvCplScan
Added by the FORBOT.BZ WORM! |
 |
wuauqmr.exe |
NvCpTDaemon
Added by the CULT-B WORM! |
 |
winoeinit.exe |
OEPowerPlugs
?? |
 |
winxp_sp3.exe |
Offica Monitor Secura Systeme
Added by a variant of the RBOT WORM! |
 |
winutade.exe |
OKGO
Added by the BANKER-EHZ TROJAN! |
 |
winssnotify.exe |
OneCareUI
Related to Windows OneCare Live from Microsoft |
 |
webtogo.exe |
Oracle Web-to-Go
"Oracle Web-to-go, a component of Oracle9i Lite, consists of a collection of modules and services that facilitate development, deployment, and management of mobile Web applications" |
 |
winword.exe |
OSA
Added by the KANGAROO-A TROJAN! |
 |
wcdvtray.exe |
OWCWebCamDV
WebCamDV from Orange Micro, Inc - enables the user to use a DV camera connected via Firewire as a Webcam |
 |
WinGamed.exe |
Patches Value
Added by the SDBOT.BR WORM! |
 |
WinPTTP.exe |
Performs peer to peer connection
Added by the RBOT-GMI WORM! |
 |
W3dbsmgr.exe |
Pervasive.SQL Workgroup Engine
Database Service Manager for Pervasive SQL 2000 Workgroup edition. Required if you use Pervasive SQL but it's recommended you start it manually before using it as it has a tendancy to crash/freeze if loaded with other applications at startup |
 |
wpctrl.exe |
PivotSoftware
PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
 |
winsrvc.exe |
Pmedia
Internet marketing sofware from Permissioned Media Inc as used in E-Card FriendGreetings foistware - see here. Treated by Trend as the FRIENDGRT.B WORM! |
 |
wuaaclt.exe |
PNP
Added by the LILBRE-A WORM! |
 |
WinTask.exe |
PopMark
"Pop Marketing" adware |
 |
webprinter.exe |
Printer Monitor
Added by the IRCBOT-Z TROJAN! |
 |
wqxfne.exe |
Proc993
Added by the IXBOT-D WORM! |
 |
wsript.exe Q152404.VBS |
Q152404
Appears to run Scandisk at bootup on NEC PCs |
 |
Winrar.exe |
quicken
CoolWebSearch Therealsearch parasite variant. Note - this is not the file zipping utility also known as WinRAR! |
 |
Waol.exe |
quicken
CoolWebSearch Therealsearch parasite variant |
 |
winmplyer32.exe |
Quicktime Mediaplayer
Added by the RBOT-PM WORM! |
 |
wnmplyr.exe |
Quicktime Mediaplayr
Added by a variant of the RBOT WORM! |
 |
winuodps.exe |
Quicktime Pro 3.0
Added by the GAOBOT.BH WORM! |
 |
Winrsm.exe |
Real Spy Monitor
Realspy keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
winsy.exe |
Reg Service
Added by a variant of the SPYBOT WORM! |
 |
winslogon.exe |
Reg Service
Added by the AGOBOT-SC WORM! |
 |
WinnConfig.exe |
Reg Service
Added by the AGOBOT-PF WORM! |
 |
Winboot32.exe |
Reg Services
Added by the RBOT.PB WORM! |
 |
winlogon.exe |
RegDone
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
wscript.exe ShakiraPics.jpg.vbs |
Registry
Added by the VBSWG.AQ WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "ShakiraPics.jpg.vbs" file is located in the Winnt or Windows folder |
 |
winreg.exe |
Registry Checkup
Added by an unidentified WORM or TROJAN! |
 |
Winregs326a.exe |
Registry Checkup System326a Monitor
Added by a variant of the SDBOT WORM! |
 |
WCPDT.EXE |
Registry Integritycheck
Added by the AGOBOT-RF WORM! |
 |
winhlpp32.exe |
Registry Loader
Added by the GAOBOT.AO WORM! |
 |
win32.exe |
Registry oidet
Added by the RBOT.BMT WORM! |
 |
winapi32.exe |
Registry Value Name
Added by a variant of the RBOT WORM! |
 |
winbackup.exe |
RegistryChk
Added by the MERTIAN WORM! |
 |
winservice.exe |
Regkey for autostart
Added by the RBOT-NU WORM! |
 |
winfix22490.exe |
REGRUN
Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS! |
 |
winbait.exe |
RegRun WinBait
Part of RegRun - used to detect unknown viruses. RegRun compares winbait.exe with the original copy called winbait.org and warns if the files are different.. |
 |
WatchDog.exe |
Regrun2
Greatis Software's RegRun security suite which amongst other things replaces MSCONFIG. The WatchDog check for registry changes caused by trojan's, viruses, etc |
 |
WinRDH.exe |
Remote Desktop Help Session Manager
Added by a variant of the SDBOT WORM! |
 |
winrpc.exe |
Remote Procedure Call
Added by the RBOT-KM WORM! |
 |
winsysrpc.exe |
Remote Procedure Call
Added by the SDBOT-PS WORM! |
 |
win.exe |
Remote Procedure Calls
Added by the SDBOT-QI WORM! |
 |
windos.exe |
REMOVE ME
Added by the SDBOT.EE WORM! |
 |
Watch.exe |
Restart Watch
Associated with an Eicon Networks Diva ISDN or ADSL modem. What does it do and is it required? |
 |
wscrestp.exe |
Restart WSC Setting
WinStart Commander - part of Ultra WinCleaner Utility Suite. Starts Windows faster and controls hidden programs to boost performance and prevent system slow downs and crashes |
 |
wf32vbs.exe |
RNBc Test
Added by the RBOT-AGR WORM! |
 |
wf32vbc.exe |
RNBz Test
Added by the RBOT-AEY WORM! |
 |
wf32b.exe |
RNDc Test
Added by a variant of the SDBOT WORM! |
 |
winlogon.exe |
ROOT_Machine
Added by the BANKER-FI TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This worm file is placed in the Windowsinf or Winntinf folder |
 |
winlogon.exe |
RPCserr32g
Added by the RITDOOR-B WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder |
 |
WINLOGON.EXE |
RPCserv32g
Added by the BOBAX.AD WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder |
 |
wandrv.exe |
run
Added by the BCKDR-QHR TROJAN! |
 |
wscript MSupdt32.vbs |
Run MSupdt32
Added by the CASER WORM! |
 |
wperl.exe |
Run POPFile in background
POPFile - E-mail spam blocker |
 |
websvc.exe |
Run Services as Application
Added by the DLOADER-NY TROJAN! |
 |
WINClock.exe |
run32dll
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
wallflip.exe |
run=
Desktop wallpaper changer? |
 |
win.ini |
run=
?? |
 |
wswpd.exe |
run=
Used with some models of Panasonic, Epson and NEC printers - required for printer to work |
 |
wmplayer.exe |
run=
CoolWebSearch Smartsearch parasite variant |
 |
Winfi1e32.exe |
Rund1l32
Added by the MERTIAN WORM! |
 |
winupdate.exe |
RunDLL32
Added by an unidentified TROJAN! - possibly a BMBOT variant |
 |
Windows.exe |
Rundll32
Added by the QQPASS.E TROJAN! |
 |
win.exe |
runing
Added by the DELF-LC TROJAN! |
 |
wini.exe |
RunProg
Added by the OPTIX.04.D TROJAN! |
 |
winlogon.exe |
runwinlogon
Detected by Trend Micro as the AGENT.TQY TROJAN! See here. Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
WAS7Mon.exe |
Salestart
WinAntiSpyware spyware remover - not recommended, see here |
 |
winagent.exe |
ScheduIr
Added by a variant of the SDBOT WORM! |
 |
winagent.exe |
Scheduler
Added by the TACTSLAY.B TROJAN! |
 |
wsass.exe |
Scheduler Service
Added by the LIOTEN.KX WORM! |
 |
w32tm.exe |
Secboot
Added by the HAXDOOR.D TROJAN! |
 |
wins32a.exe |
secure socket layer
Added by an IRCBOT TROJAN! |
 |
WindowsSecurityUpdate.exe |
Security
Added by a variant of the SDBOT WORM! |
 |
WinUpdate32.exe |
Security Patch
Added by the SDBOT-BM WORM! |
 |
WinLab32.exe |
Security Patches
Added by the SDBOT-KB WORM! |
 |
wmiprvce.exe |
Security Update Service
Added by the AGOBOT.ZW WORM! |
 |
wssdsu.exe |
Serv-U
Added by the MANIFEST TROJAN! |
 |
wbemstest.exe |
Server Runtime Process
Added by the SDBOT-DDB WORM! |
 |
wN2S.exe |
service
Added by a variant of the RBOT WORM! |
 |
winsvcli.exe |
Service Client
Added by an unidentified WORM or TROJAN! See here |
 |
WinOcx.exe |
Service Monitor
Added by the RBOT-AQJ WORM! |
 |
winset.exe |
Service Process
Added by a variant of the SPYBOT WORM! |
 |
windowsXP.exe |
Service System
Added by the BANCOS-EL TROJAN! |
 |
wernell87.exe |
Service System
Added by the BANCOS-FJ TROJAN! |
 |
winread.exe |
Services
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
windns.exe |
Services
Added by a variant of the RBOT WORM! |
 |
windows32.exe |
services
Added by the FLYVB-C WORM! |
 |
websvc.exe |
Services Administrator
Added by the DLOADER-NY TROJAN! |
 |
win32dll.exe |
Services32 Startup
Added by the SDBOT-XO WORM! |
 |
wsusupd.exe |
ShareSearcher
Added by the ENCLAG-A TROJAN! |
 |
winagent.exe |
SheduIer
Added by the EB TROJAN! |
 |
wmedia32.exe |
Shell
Added by the AGENT-BR TROJAN! |
 |
wmedia16.exe |
Shell
Added by the GOLDUN TROJAN! |
 |
Wifiusb.exe |
Sinus 1054 data WLAN Manager
Wireless management utility for the T-Com Sinus 1054 Data WLAN adapter |
 |
winsos.exe |
sis32
Added by the QQPASS.IA WORM! |
 |
win.bat |
Sistray32
Added by the JUMPRED.A WORM! |
 |
winlogon.scr |
SkynetRevenge
Added by the NETSKY.AA WORM! |
 |
winlogon.exe |
SmansaApp
Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder |
 |
winsrv.exe |
smcserv
Added by the AGOBOT-OU WORM! |
 |
win32st.exe |
SMSERIALSTARTER
Detected by McAfee as the FAKEALERT-AH TROJAN! See here. Installed with the SpyBurner spyware remover - which is not recommended, see here |
 |
winstrse.exe |
SMSERIALWORKERSTARTER
Added by an unidentified WORM or TROJAN! See here. Installed with the SpyBurner spyware remover - which is not recommended, see here |
 |
Win.exe |
smsger
Added by a variant of the SDBOT WORM! |
 |
wininits.exe |
softIce Update 32
Added by the RBOT-ANB WORM! |
 |
WNILOGON.exe |
SonudMan
Added by the QQROB-DC TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
WinSound1.exe |
Sound System
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
Wifiusb.exe |
Speedport W 100 Stick WLAN Manager
Wireless management utility for the Speedport W 100 Stick WLAN USB stick |
 |
Wscript.exe OXNEY.B.VBS |
SPINX
Added by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "OXNEY.B.VBS" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
wys.exe |
Spool
WhileUSurf adware |
 |
websvc.exe |
Spooler SubSystem Application
Added by the DLOADER-NY TROJAN! |
 |
wintre.exe |
spoolsvs
Added by the SDBOT.EGQ WORM! |
 |
wincfy.exe |
spoolsvs
Added by a variant of the IRCBOT BACKDOOR! |
 |
Winllogo.exe |
SpyEx
Added by the PRSKEY-A WORM! |
 |
winproc32.exe |
SpywareGuard
Startpage adware Trojan |
 |
winmm64.exe |
SpywareGuardPlus
StartPage.ht homepage hijacker |
 |
wins32.exe |
sqservices
Added by the PROGENT-B TROJAN! |
 |
win16dll.exe |
srv32win
Screenspy captures screenshots silently. If you didn't install this yourself remove it |
 |
winsys.exe |
ssate.exe
Added by the BEAGLE.K WORM! |
 |
winerdir.exe |
ssgrate.exe
Added by the MITGLIEDER.O TROJAN! |
 |
winsystems.exe |
ssgrate.exe
Added by the BAGLEDL-J TROJAN! |
 |
wintems.exe |
ssgrate.exe
Added by the MITGLIEDER.Q TROJAN! |
 |
winssk32.exe |
SSK Service
Added by the SOBIG.E WORM! |
 |
windows.vbs |
Start
Homepage hijacker |
 |
windupds.exe |
Start Upping
Added by the SDBOT.AFH WORM! |
 |
windupdts.exe |
Start Upping
Added by a variant of the RBOT WORM! |
 |
win32i.exe |
startkey
Added by the BIFROSE-R TROJAN! |
 |
winampXP.exe |
startkey
Added by the BIFROSE-OY TROJAN! |
 |
winlogin.exe |
startkey
Added by the BIFROSE-PM TROJAN! |
 |
WinlogonStartup |
Startup
Unidentified malware |
 |
wztoid.exe |
Startup Configuration
Added by the RBOT-ASD WORM! |
 |
w32main2.exe |
stgclean
Related to IBM Standard Software Installer. What does it do and is it required? |
 |
wkfxi.js |
stmha
Added by the SPETH WORM! |
 |
wuauclt14.exe |
StreamAppliance
Added by the RBOT-GMB WORM! |
 |
wuauclt16.exe |
StreamAppliance
Added by the RBOT-GME WORM! |
 |
winscrne.exe |
STV
Added by a variant of the SDBOT WORM! |
 |
winsfcm.exe |
SurfinGuard Pro
SurfinGuard Pro from Finjan - internet protection software, protects against all malicious code delivered through executables, scripting files, ActiveX and Java |
 |
WINAGENT.EXE |
SvcH0st
Added by the EB TROJAN! |
 |
winhost.exe |
Svchost
Added by the LOLAWEB.A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
 |
winhelp.exe |
svchost
Added by the GAOBOT.GEN!POLY WORM! |
 |
winampXP.exe |
svcshare
Added by the FUJACKS-J VIRUS! |
 |
winwd.exe |
SWd
PC Security from Tropical Software - lock files, password protect, etc |
 |
Win32x.exe |
Sygate Personal Firewall
Added by the RBOT-KZ WORM! |
 |
wins.exe |
Sygate Personal Firewall
Added by the RBOT.AOB WORM! |
 |
winxpstat.exe |
Sygate Personal Firewall
Added by a variant of the RBOT WORM! |
 |
win31243.exe |
Sygate Personal Firewall
Added by a variant of the IRCBOT TROJAN! |
 |
winupdate.exe |
Sygate Personal Port Blocker
Added by a variant of the RBOT WORM! |
 |
windows .exe |
Symantec Antivirus professional
Added by a variant of the FORBOT WORM! |
 |
Winhp32.exe |
Symantec Antivirus professional
Added by a variant of the FORBOT WORM! |
 |
winudp.exe |
Symantec Antivirus professional
Added by a variant of the WOOTBOT WORM! See here |
 |
winsync.exe |
syncman
Added by the MANCSYN-A TROJAN! |
 |
windows32.exe |
Syntax
Added by the SDBOT.CQ WORM! |
 |
wuapdxe.exe |
Sys-Stat
Added by the SDBOT.HK WORM! |
 |
win***32.exe [* = random char] |
Sys29
EliteBar adware |
 |
win***32.exe [* = random char] |
SysA
EliteBar adware |
 |
win.hta |
Syscheck
Browser hijacker |
 |
wincfg32.exe |
SysConfig
Added by the SDBOT.ZD WORM! |
 |
winupdate.exe |
Sysctrls
Added by an unidentified WORM or TROJAN! |
 |
win32dll.exe |
Sysctrls
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
winrun.exe |
sysdir
Added by the WINBUR.B WORM! |
 |
wininit32.exe |
SysInit
Added by the XABOT WORM! |
 |
wowexece.exe |
SysMon
Added by the MULAN-A TROJAN! |
 |
WWE DIVAS.exe |
SysRes
Added by the ELIPTER.D WORM! |
 |
WINL0G0N.EXE |
System
Added by the BANCOS-DB TROJAN! |
 |
wumgrd32.exe |
System
Added by a variant of the RBOT WORM! |
 |
windowsps.exe |
System
Added by a variant of the RBOT WORM! |
 |
wiinlogon.exe |
SYSTEM
Added by the RBOT-AVG WORM! |
 |
winupd.exe |
System
Added by a variant of the SDBOT WORM! |
 |
wsscntfy.exe |
System
Added by a variant of the SDBOT WORM! |
 |
windmupdr.exe |
SYSTEM
Added by a variant of the RBOT WORM! |
 |
win_klr32.exe |
System Check
Added by the DELF-DRA WORM! |
 |
wasul.exe |
System Checking
Added by the RBOT.BHM WORM! |
 |
wins.exe |
System Document Application
Added by the SDBOT.AUB WORM! |
 |
wingmt.exe |
System Drivers
Added by the SDBOT-MG WORM! |
 |
win.exe |
System Information Manager
Added by the SDBOT-MU WORM! |
 |
windowsNt.com |
System Information Manager
Added by the SDBOT-ND WORM! |
 |
winsrv32.exe |
System Manager
Added by an unidentified WORM or TROJAN! |
 |
winsvc.exe |
System Manager Updates
Added by the AGOBOT.AEM WORM! |
 |
wmisg.exe |
SYSTEM MESSAGER
Added by the MYTOB.ES WORM! |
 |
wupdmgr.exe |
System Update
Added by the SOROMO-A TROJAN! |
 |
wauluclt.exe |
System Update
Added by the SDBOT.EF WORM! |
 |
wmiprvsa.exe |
System Update Service
Added by the AGOBOT-RG TROJAN! |
 |
winupd32.exe |
System Update Service
Added by the ADTODA-A TROJAN! |
 |
wmiprvsv.exe |
System Update Service
Added by the AGOBOT.YG WORM! |
 |
webcheck.exe |
System Update2
Added by the AUTOTROJ-C TROJAN! |
 |
wininet.exe |
System Update2
Added by the AUTOTROJ-C TROJAN! |
 |
winlogon.exe |
System Update2
Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
winspool.exe |
System Update2
Added by the AUTOTROJ-C TROJAN! |
 |
wupdmgr.exe |
System Update2
Added by the AUTOTROJ-C TROJAN! |
 |
wmiprvsw.exe |
System Updater Service
Added by the GAOBOT.AFC WORM! |
 |
winsci.exe |
System Updates
Added by a variant of the RBOT WORM! |
 |
wmkl.exe |
System Updates
Added by the RBOT-AYJ WORM! |
 |
winserv32.exe |
System Updates Manager
Added by the AGOBOT-AGA WORM! |
 |
winds32.exe |
System32
Added by the DWNLDR-HFY TROJAN! |
 |
Wincmp32.exe |
SystemAdministration
Added by the ASYLUM TROJAN! |
 |
WinMedia.exe |
SystemMigration
Added by the KELVIR.EI WORM! |
 |
WINREG.EXE |
SystemReg
Added by the DEWIN.A TROJAN! |
 |
windrives.exe |
Systems Backups
Added by the AGOBOT-RB WORM! |
 |
Windows2.exe |
systems usb driver
Added by a variant of the RBOT WORM! |
 |
wekls4.exe |
SystemTray
Added by a variant of the IRCBOT TROJAN! |
 |
Windowsupd.exe |
SystemTray
Added by a variant of the IRCBOT TROJAN! |
 |
winkernal.exe |
systhread
Added by the LIAMED WORM! |
 |
w32explorer.exe |
Systray
Added by the RBOT-AJY WORM! |
 |
winrxd64.exe |
sysygm64
Added by the IRCBOT-RK TROJAN! |
 |
Wink3sk9.exe |
T4skM4n4g3r
Added by a variant of the IRCBOT TROJAN! |
 |
wualcts.exe |
Task Help
Added by a variant of the RBOT WORM! |
 |
winampa.exe |
Taskmon driver
Added by the LOONY-I TROJAN! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of the Program Files directory whereas this file is located in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
websvc.exe |
Tcp Application Manager
Added by the DLOADER-NY TROJAN! |
 |
winlogon.exe |
TEXTCONV
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
wind0s.exe |
ThE
Added by an unidentified WORM or TROJAN! |
 |
wscript zshell.js |
Time Zone Synchronization
Added by the NETDEX-A TROJAN! |
 |
Watcher.exe |
Tiny Watcher Logon Time
Tiny Watcher detects changes to your system. It will not prevent your system from being modified or corrupted. It will only tell you that something suspicious happened. Think of it as an early CAT scan against system tumors. Better to install a tool that will detect and remove bad items |
 |
WINLOGON.EXE |
Torjan Program
Added by the WOWCRAFT.D TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! This trojan file is found in the Windows or Winnt folder |
 |
WinLED.exe |
Touch Manager
Dell keyboard utility. Disabling can result in loss of screen saver and power saver functionality |
 |
wincool.exe |
Tour
Component of WinME that's annoying as hell. Pop's up a prompt to play the C:WINDOWSApplication DataMicrosoftINTROCONTENT.HTA that plays a full screen version of the WinME product preview Windows Media video file that cannot be stopped to my knowledge until it finishes. That prompt will keep popping up after an install/reinstall of WinME until you give in and watch the thing. It also puts a task scheduler entry to run that annoying thing every 30 minutes, and don't bother deleting that entry, Windows puts it right back. Not only should you disable it from running, you should delete the thing altogether, as it, somehow can re-enable itself. Apparently you can try setting the file to read only |
 |
Weatherbug.exe |
Tray Temperature
Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs |
 |
winppr32.exe |
TrayX
Added by the SOBIG.F WORM! |
 |
wins32.exe |
Tsk Mng Hlp
Added by the AGOBOT-JB WORM! |
 |
WinManager.Exe |
Tweak Manager
WinGuides Tweak Manager. Is this required for the live updates feature and/or if settings are changed? |
 |
winter.exe |
Undefined
Added by the KILLAV.LW TROJAN! |
 |
WinUPPD.exe |
Universal Plug & Play devices
Added by an unidentified WORM/TROJAN! |
 |
winlogom.exe |
Updade Windows
Added by the TONAX-A TROJAN! |
 |
wupdata.exe |
UpData
Added by the IRCBOT-AA TROJAN! |
 |
winis.exe |
update
Added by the RBOT-VD WORM! |
 |
WinUpdater5.0.vbs |
UPDATE
Added by the GORMLEZ-A WORM! |
 |
winlog.exe |
Update Checker
Added by the IRCBOT-TJ TROJAN! |
 |
WiseUpdt.exe |
Update Grokster
Automatically updates the Grokster file sharing software. Beware of adware and spyware when using this type of program, for instance, Grokster contains CyDoor |
 |
winu32.exe |
Update Service
Added by the RBOT-MG WORM! |
 |
winx.exe |
update service
Added by a variant of the RBOT WORM! |
 |
WiseUpdt.exe |
Update TUT
?? |
 |
winstall.exe |
UpdateCheck
Added by the SPYBOT-CY WORM! |
 |
wupdater.exe |
updater
eUniverse/KeenValue adware |
 |
wisvc.exe |
updater
Added by the ORSE-A TROJAN! |
 |
winload32.exe |
updater32
Added by the CULT.M WORM! |
 |
wservice.exe |
UpdateService
Added by the DREF-K WORM! |
 |
winit.exe |
upddateit
Added by the RBOT-MS WORM! |
 |
winupd.exe |
Upgrade Service
Added by the TOFGER-U TROJAN! |
 |
WinSVCservice.exe |
UPNPService
Added by the AGOBOT.UN WORM! |
 |
wjview ...Code |
UpromiseRemindU
Part of the Upromise saving scheme but associated with Ebates MoneyMaker adware so the choice is yours |
 |
web.exe |
UPSUtl
CoolWebSearch parasite variant |
 |
WinUp.exe |
UpTimes service
Added by the RBOT-AKB WORM! |
 |
winlogon.exe |
urudjeffni
Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder |
 |
Winsys32.exe |
USB 2.0 Driver
Added by the AGOBOT-QM WORM! |
 |
winsystem.exe |
USB 2.0 Driver
Added by the AGOBOT-QS WORM! |
 |
winupdate1.exe |
USB 2.1 Driver
Added by a variant of the RBOT WORM! |
 |
win32usb.exe |
USB Device
Added by the FORBOT-BQ WORM! |
 |
wuservices.exe |
USB Fix 1.1
Added by a variant of the SDBOT WORM! |
 |
wuafix.exe |
USB Fixes
Added by the RBOT-ABV TROJAN! |
 |
wugfixx.exe |
USB Updates 2
Added by a variant of the RBOT WORM! |
 |
wmmndir.exe |
USBConfigration2
Added by the AGOBOT-SV WORM! |
 |
winlogon.exe |
userinit
Added by the DLOADER-TP TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder |
 |
WMPVer.EXE |
v
Dritek System Inc. 3D Mouse related. Is it required? |
 |
WebLifeDisk.exe |
VDrive2
EarthLink WebLife Disk - "Consumers can quickly save files from their desktop into WebLife Disk, and then easily access them from any Internet connection without taking a laptop on the road or keeping up with a USB key" |
 |
winamp32.exe |
Video
Added by the AGOBOT-NG WORM! |
 |
wcamfrog.exe |
Video Camera Frog
Added by a variant of the IRCBOT TROJAN! See here |
 |
winaps.exe |
Video Proces
Added by the AGOBOT.HD WORM! |
 |
winasp.exe |
Video Process
Added by the AGOBOT-IS WORM! |
 |
wincert32.exe |
Video Process
Added by the AGOBOT.JT WORM! |
 |
winit.exe |
virtual
Added by the MUGLY.A or MUGLY.B WORMS! |
 |
winprotect.exe |
virtual
Added by the MUGLY.C WORM! |
 |
wini.exe |
virtual
Added by the RBOT-YX WORM! |
 |
winlogi.exe |
virtual-ie
Malware - detected by Kaspersky as the WINAD.H TROJAN! |
 |
winlogin.exe |
virtual-machine
Added by the RBOT-VU WORM! |
 |
wini.exe |
virtual-machine
Added by the RBOT-WR WORM! |
 |
winxpsock.exe |
Vsample
Added by the SDBOT.BLK WORM! |
 |
WINLOGON .exe |
W1N32.DLL
Added by the DROPPERFL.A TROJAN! |
 |
w32.exe |
w32
Added by the SOKEVEN TROJAN! |
 |
wiper.exe |
W32PluginsDownloaderXMLHTTPSelfClearing7520
Added by the PROXYSER-M TROJAN! |
 |
w32sup.exe |
w32sup
Adult content dialler |
 |
w32sys.exe |
W32SYS
Added by the JAMBU-A WORM! |
 |
WTC32.scr |
W32Tc
Added by the VOTE.D or VOTE.K WORMS! |
 |
W75P2PS.EXE |
W75P2PSERVER
Printer utility which is required in order to make the printer work correctly |
 |
w7zip.exe |
w7zip
Added by the BANCBAN-QB TROJAN! |
 |
W815DM.exe |
W815DM
Enuff Parental Control Software by Akrontech |
 |
w98Eject.exe |
w98Eject
Related to USB support for Sigmatel MP3 audio palyer (and others such as SanDisk). It's intent is to "put away" the "disk" before you unplug it from the USB port, ostensibly to avoid "losing" data |
 |
wab.exe |
wab.exe
Added by a variant of the SDBOT WORM! |
 |
wait4IP.exe |
wait4IP
Packard Bell net2Plug allows you to network PCs anywhere in your house |
 |
Wallchgr.exe |
wallchgr.exe wstart
WallChanger - wallpaper changer from Blue Tree Software |
 |
wallmast.exe |
WallMaster
WallMaster - "The free and easiest way to master your desktop wallpaper!" |
 |
WALLPA~1.EXE |
WallPaper
Wallpaper Changer - wallpaper manager that can change your background images on every startup |
 |
Wallpaper.exe |
WallpaperChanger
A wallpaper changer and manager utility. There is the Freeware version and the Pro version. The freeware version is completely free. The Pro version is 30-day trialware, and after the 30 days some of the more advanced features will be disabled unless you register it |
 |
WallpaperSS.exe |
WallpaperSS
Wallpaper Slideshow LT from gPhotoShow.com - "a great utility for displaying your favorite photos as your desktop wallpaper" |
 |
Wanadoo Messenger.exe |
Wanadoo Messenger.exe
Wanadoo ISP instant messenger client |
 |
wanman.exe |
wanman.exe
Added by the RBOT.HDO WORM! |
 |
WanMPSvc.exe |
WanMPSvc
An AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling AOL doesn't help |
 |
wts**.exe [* = random char] |
WAPI
PurityScan/Clickspring adware |
 |
wartray.exe |
War FTPD Tray Icon
War-ftpd - FTP server |
 |
WAR-FTPD.EXE |
war-ftpd.exe
War FTP Daemon from JGAA's Internet - FTP client |
 |
WareOut.exe |
WareOut
Wareout - malware masquerading as a spyware and dialer remover |
 |
warez.exe |
warez
Warez P2P client |
 |
warner.exe |
Warner
Also known as "CyberWarner". From G-Tek Technologies and pre-installed on some Packard Bell PCs. Protects critical files |
 |
warnet.exe |
Warnet
Warnet - system cleanup software |
 |
WarReg_PopUp.exe |
WarReg_PopUp
Acer warranty registration popup |
 |
war-ftpd.exe |
WARSVR
"War FTP Daemon - the original free FTP server for windows" |
 |
washer.exe |
Washer
Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
 |
washerie.exe |
Washerie.exe
Cookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer, specific for cleaning the IE cache and cookies. Available via Start -> Programs |
 |
washidx.exe |
washindex
Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
 |
wast.exe |
Wast
Grokster ads updater |
 |
watch.exe |
Watch
Found to be used by a Trust USB scanner for auto starting the scanning software when the lid is lifted |
 |
watchdog.exe |
Watch Dog Program
For Compaq PC's. Associated with Compaq's internet services. Not required if you don't use services provided by them and may not be required even if you do |
 |
Watchdog.exe |
Watchdog
Definitely part of the Mustek scanner drivers and software (for 600 III EP Plus and maybe others), launches from the Startup folder in the Start Menu, but not required as they give instructions on removing it on their webpage |
 |
watchdog.exe |
WatchDog
Part of Motorola "Mobile Phone Tools" v3 - in a "Mobiile Phone Tools" sub-directory of Program Files |
 |
WatchWAN.exe |
WatchWAN
WatchWAN keeps an accurate account of the data that is flowing between your computer and the Internet at any given moment. This readout is presented in both numerical and graphical format, in real time |
 |
waumgr.exe |
waumgr
Added by a variant of the IRCBOT TROJAN! |
 |
WaveFramer.exe |
WaveFramer
Part of SafeSpace (from Artificial Dynamics) which "protects computers from Internet malware infection without the need for signature updates or regular maintenance" |
 |
WaveTop.exe |
WaveTop Launcher
WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
 |
WiFiMsg.exe |
WAWifiMessage
"HP Wireless Assistant is a user application that provides a method for controlling the enablement of individual wireless devices (such as Bluetooth or WLAN devices) and that shows the state of the radios for these wireless devices" |
 |
wbcmgr.exe |
Wbcmgr
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
wben.exe |
wben
Appears to be related to Desktop Notifier from Starfield Technologies. What does it do and is it required? |
 |
Wbiff.exe |
Wbiff
Wbiff! E-mail checker - automatically checks your e-mail and notifies you if any new e-mail has been received |
 |
Wbutton.exe |
Wbutton
Turns on and off the integrated WiFi on Acer (and other laptops) |
 |
WCESCOMM.EXE |
WCESCOMM
Active sync for use with Windows CE based palm PC |
 |
WCEMNGR.EXE |
WCESMngr
Added by the AGOBOT-QX WORM! |
 |
WCheckUp.exe |
WCheckUp
Barok keylogger and password stealer |
 |
wcmdmgrl.exe |
wcmdmgr
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
 |
wcmdmgr.exe |
wcmdmgr.exe
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
 |
wcmdmgrl.exe |
wcmdmgrl
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
 |
wintsvcc.exe |
WCPC
?? |
 |
wintsvit.exe |
WCPI
PurityScan/Clickspring adware |
 |
Wint**.exe [* = random char] |
WCPS
PurityScan/Clickspring adware |
 |
wintsvtr.exe |
WCPT
PurityScan/Clickspring adware |
 |
wcsys.exe |
wcsys
Added by the KEYLOG-AP TROJAN! |
 |
WDBtnMgr.exe |
WD Button Manager
Button manager installed with a western digital external disk drive. Allows you to back up your system with one click |
 |
wdfmgr32.exe |
wdfmgr32.exe
Added by the DWNLDR-FVL TROJAN! |
 |
wdinfo.exe |
WDInfo
Added by the DLUCA.B TROJAN! |
 |
wdmon.exe |
wdmon
Detected as the BUZUS.DVE TROJAN! |
 |
wdns33.exe |
WDNS SYSTEM
Added by the MYTOB-BY WORM! |
 |
wdskctl.exe |
wdskctl
IEPlugin spyware |
 |
wdwctrl.exe |
wdwctrl
Added by the DLUCA.E TROJAN! |
 |
WD_SRT.EXE |
WD_SRT
Western Digital USB disk driver |
 |
WEATHER.EXE |
WEATHER
Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs |
 |
weatherpulse.exe |
Weather Pulse
Weather Pulse from Tropic Designs. "Display popular Satellite images and video from around the globe, share images with your friends and family, stay updated on current and expected weather conditions, it's just plain fun!" |
 |
Weather.exe |
WeatherCast
Weather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight |
 |
WeatherEye.exe |
WeatherEye
WeatherEye - desktop weather from TheWeatherNetwork |
 |
WeatherOnTray.exe |
WeatherOnTray
Hotbar adware |
 |
Weatherscope.exe |
Weatherscope
WeatherScope - "displays your current local temperature in the system tray of your computer (near the clock) whenever you are online!" Not recommended as it bundles GAIN adware. You can get the adware free version for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here |
 |
WeatherStudio Desktop.exe |
WeatherStudio Desktop
WeatherStudio adware |
 |
ww.exe |
WeatherWatcher
WeatherWatcher - weather reporting in the System Tray |
 |
Web2Pop.exe |
Web2Pop
Web2Pop allows you to retrieve your web-based accounts messages to read them in your favorite e-mail client |
 |
web3trap.exe |
web3trap
PC-Cillin 2000 anti-virus software → ActiveX filter. Guards against malicious ActiveX programs, etc |
 |
webalize.exe |
webalize
Searchcentrix hijacker |
 |
WAK.exe |
WebArmyKnife
Web Army Knife - a suite of web site developer's tools |
 |
webassist.exe |
webassist
Adware popup generator |
 |
webbuying.exe |
WebBuying
WebBuying adware |
 |
WebCallDirect.exe |
WebCallDirect
WebCallDirect - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype |
 |
webcam.exe |
webcam
Added by the MONAD-A TROJAN! Note - this malware actually changes the default value data of the Registry Run and RunServices keys in order to force Windows to launch it at boot. Name field may be empty |
 |
wbcgosvc.exe |
Webcam Go Sti Service Application
Control software for the portable Creative Webcam Go digital camera/PC web cam. What does it do and is it required? |
 |
WEBCAMRT.exe |
WebcamRT.exe
For Logitech Web Cams. Not required - camera works fine without it |
 |
webcel.exe |
Webcelerator
Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Now no longer available and supported and when available was classed as spyware - see here |
 |
WebCheck.pif |
WebCheck
Added by the CONE.C or CONE.F WORMS! |
 |
WebCpr0.exe |
WebCpr0
WebRebates adware |
 |
webdav.exe |
Webdav.exe
IRC DDoS bot which gives the hacker full control over your system |
 |
whagent.exe |
WebHancer Agent
System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here |
 |
whSurvey.exe |
webHancer Survey Companion
WebHancertrackware - traffic measurement service that uses a client agent that is stealth installed on user machines, gathering detailed data about sites visited, their performance and, most important, what the user actually does while there |
 |
WebInstall.exe |
WebInstall
ClipGenie adware downloader |
 |
WebInstall.exe |
WebInstall2
ClipGenie adware downloader |
 |
WebKey.exe |
WebKey
WebKey from JB Utilities. Utility to keep track of login data required when browsing the internet |
 |
WebLink.exe |
WebLink
Softex is a "cost-effective way to provide software updates, technical support or new product information to specific end-users - it can silently provide end-users with software updates, technical support and new product information customized to their specific needs through a persistent link" |
 |
wpsche~1.exe |
Webposition Gold 2
Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines |
 |
WebRebates0.exe |
WebRebates0
WebRebates adware |
 |
WDF.exe |
Webroot Desktop Firewall
Webroot Desktop Firewall |
 |
websaverlive.exe |
websaverlive
WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your computer is idle |
 |
WebSavingsfromEbatesrun.exe |
WebSavingsfromEbates
Web Savings From Ebates Software, a shopping tool that opens pop-up windows |
 |
WebSavingsFromEbates0.exe |
WebSavingsFromEbates0
Web Savings From Ebates Software, a shopping tool that opens pop-up windows |
 |
WebScanX.exe |
WebScanX
From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc |
 |
wjview ...websearch.exe |
websearch
"Web Savings" From Ebates Software, a shopping tool that opens pop-up windows |
 |
WebSecureAlert.exe |
WebSecureAlert
WebSecureAlert - "helps to protect your browser security by monitoring for unauthorized tampering with Internet Explorer's security settings, and can help to protect your privacy by deleting your web surfing history on a regular basis". Not recommended as it bundles GAIN adware. You can get the adware free version for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here |
 |
Webshots Tray.exe |
Webshots
Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web |
 |
websho~1.exe |
Webshots
Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web |
 |
WebshotsTray.exe |
Webshots
Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web |
 |
webadmin.exe |
Website Administrator Info
Added by the FORBOT-FY WORM! |
 |
wupda.exe |
WebSUpdater
Detected by Kaspersky as the STARTPAGE.C TROJAN! See here |
 |
webtrap.exe |
Webtrap
Part of PC-Cillin anti-virus software. Checks web-sites for malicious Java and ActiveX elements in a similar way to McAfee WebScanX. A few users find it infuriating |
 |
WebTrapNT.exe |
WebTrapNT.exe
Part of PC-Cillin Anti-Virus software. Checks visited web-sites for malicious Java and ActiveX elements |
 |
wwasher.exe |
WebWasher
Free Pop-up/ad/javascript filter program from Siemens. If not running then browsers will not be protected but will still work. Available via Start -> Programs |
 |
WeirdOnTheWeb.exe |
WeirdOnTheWeb
Added by the WeirdOnTheWeb adware |
 |
Welcome.exe |
Welcome
Launches the Welcome to Windows tutorial on boot up |
 |
Wepstat.exe |
WEPstat
Cisco Aironet 340 Series PC Card driver. If it can be started manually it shouldn't be required if you don't use the PC card facility regularily - hence the status could be "U". Can anybody confirm this? |
 |
wiustv.exe |
wesumu
Added by the QQPASS-L TROJAN! |
 |
wetsock.exe |
WetSock
RoboMagic Wetsock - weather reporting in the System Tray |
 |
WFGStartup.exe |
WFGStartup
World Weather. "This midlet displays the current weather conditions for major cities around the world. This version is for memory limited mobile phones" |
 |
WFXCTL32.EXE |
WFXCTL32.EXE
From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs |
 |
wfxsnt40.exe |
wfxsnt40
WinFax 10.0 and maybe earlier versions. The program that opens the port for WinFax and not normally in the start menu. Needed if you want to run WinFax |
 |
WFXSWTCH.exe |
WFXSwtch
Related to WinFax. What does it do and is it required? |
 |
WG511WLU.exe |
WG511WLU
Netgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card |
 |
wgeax.exe |
wgeax
Added by the IRCBOT-TM WORM! |
 |
wgs3.exe |
wgs3
Added by the LEGMIR-AQH TROJAN! |
 |
WGV.exe |
WGV
Added by the ZIPPIE TROJAN! |
 |
WGWLocalManager.exe |
WGWLocalManager
Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so. It could be started by creating a shortcut, running it only when connecting to the internet. If internet is used often, it's recommended to leave it in startup so it starts with the system |
 |
WgwMngr.exe |
WgwMngr
Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so |
 |
whagent.exe |
whagent
System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here |
 |
WHATPU~1.EXE |
WhatPulse
WhatPulse keeps track of your keystrokes, allowing you to find out just how much you type a day |
 |
whse.exe |
WhenUSearchWHSE
WhenU.Save adware |
 |
whismng.exe |
Whistler
Added by the WHISTLER-F TROJAN! |
 |
Whvlxd.exe |
Whvlxd
Added by the ZAPCHAS-CS TROJAN! |
 |
wiascr.exe |
wiascr
Added by the AGENT.AM TROJAN! Note - example names include "XviD", "Winamp Remote", "Windows Media Player" and "Futuremark" |
 |
wifeman.exe |
wifeman
Unidentified malware |
 |
wifiboot.exe |
Wifi Boot
Added by a variant of the IRCBOT TROJAN! See here |
 |
wifibooter.exe |
Wifi Booter
Detected by Trend Micro as the IRCBOT.GP TROJAN! See here |
 |
wificonfig.exe |
Wifi Configuration
Added by the CHECKOUT WORM! See here |
 |
wificonfigs.exe |
Wifi Configuration!
Added by the CHECKOUT WORM! See here |
 |
wificon.exe |
Wifi Connection
Detected by Trend Micro as the SLENFBOT.AC TROJAN! See here |
 |
wificonnect.exe |
Wifi Connection!
Added by the CHECKOUT WORM! See here |
 |
wifidebug.exe |
Wifi Debug
Added by a variant of the IRCBOT TROJAN! See here |
 |
wifiload.exe |
Wifi Loader
Detected by Trend Micro as the IRCBOT.AVG TROJAN! See here |
 |
wifiloader.exe |
Wifi Loader!
Added by a variant of the IRCBOT TROJAN! See here |
 |
wifisetup.exe |
Wifi Setup
Added by a variant of the IRCBOT TROJAN! See here |
 |
WildFlics.exe |
WildFlics
Direct-B premium rate adult content dialler |
 |
wcmdmgrl.exe |
WildTangent Web Driver updater
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
 |
WWMon.exe |
Wildwire Monitor
This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem |
 |
WillowRoad.exe |
Willow Road
Willow Road Screen Saver |
 |
WillPolo.vbs |
WillPolo
Added by the VBS_SOLOW.AF VIRUS! |
 |
windows.exe |
WIN
Added by the REATLE.C WORM! |
 |
Win Antivir 2008.exe |
Win Antivir 2008
Win Antivir 2008 rogue security software - not recommended, see here |
 |
Win Antivirus 2008.exe |
Win Antivirus 2008
Win Antivirus 2008 rogue security software - not recommended, see here |
 |
winchi~1.exe |
Win Chimes
WinChimes - enhancement software for the system clock that runs in the system tray |
 |
WinComm.exe |
Win Comm
Added by the WINCOM TROJAN! |
 |
winconfig.exe |
Win Config
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
wuctl.exe |
win ctl app
Added by a variant of the SDBOT WORM! |
 |
windfrag.exe |
Win Defrag
Added by a variant of the SDBOT WORM! See here |
 |
windefrag.exe |
Win Defrag!
Added by a variant of the SDBOT WORM! See here |
 |
WIN HOST PROCESS.EXE |
WIN HOST PROCESS
Added by the KEYLOGGER.CLONE TROJAN! |
 |
winampa.exe |
Win l5oahder
Added by a variant of the RBOT WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of the Program Files directory |
 |
winlogin.exe |
Win Login
Added by the RBOT-AWE WORM! Note - this trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder |
 |
win14.exe |
Win Microsoft 98
Added by the RBOT-AKX WORM! |
 |
winupdates.exe |
Win Process Updates
Added by a variant of the SDBOT WORM! |
 |
winsecure.exe |
Win Security
Detected by Trend Micro as the IRCBOT.AVE BACKDOOR! See here |
 |
winserv.exe |
Win Server
Added by the IMISERV.A TROJAN! |
 |
wupdt.exe |
Win Server Updt
Added by the IMISERV.A TROJAN! |
 |
winserver.exe |
Win Server Updt
Added by a variant of the IMISERV TROJAN! |
 |
winsyncupx.exe |
Win Sync montr
Detected by Kaspersky as the RBOT.BYJ TROJAN! See here |
 |
wupda32.exe |
win update
Added by the SDBOT.J WORM! |
 |
wapdate.exe |
win update
Added by a variant of the RBOT WORM! |
 |
WINUPDATER.EXE |
Win Updater
Added by the RBOT.IP WORM! |
 |
winusb.exe |
WIN USB 2.0
Added by a variant of the RBOT WORM! |
 |
winamp.exe |
Win WinAmp
Added by the RBOT.AGF WORM! Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of the Program Files directory. This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
win*************.exe [* = random digit] |
win************* [* = random digit]
WINBO adware |
 |
WIN-BUGSFIX.EXE |
WIN-BUGSFIX
Added by the LOVELETTER (I LOVE YOU) VIRUS! |
 |
winis.exe |
win-xp
Added by the BROPIA.N WORM! |
 |
win.exe |
win.exe
Added by the PODROP-C TROJAN! |
 |
win16dll.exe |
win16.dll
Screenspy captures screenshots silently. If you didn't install this yourself, remove it |
 |
win23.exe |
win23.exe
Detected by Kaspersky as the BIFROSE.BSJ TROJAN! See here |
 |
WIN32.EXE |
WIN32
Added by the RATEGA TROJAN! |
 |
Win32.exe |
Win32
Added by the ISRAZ.A WORM! |
 |
winsrv32.exe |
win32
Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites |
 |
WinSetup.exe |
win32
Added by the EVILBOT.B TROJAN! |
 |
winhost.exe |
win32
Added by the BROPIA.J WORM! |
 |
winnnit.exe |
Win32
Added by a variant of the SDBOT WORM! |
 |
Winbios.exe |
Win32 Bios
Added by the SEMAPI-A WORM! |
 |
Win32.exe |
Win32 Critical File
Added by the RBOT-GUB WORM! |
 |
Win32Debug.exe |
Win32 Debug Manager
Added by a variant of the WOOTBOT WORM! |
 |
Win32ldr.exe |
Win32 Device Loader
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
winlogons.exe |
Win32 Drivers
Added by the FORBOT-FG WORM! |
 |
wdrk32.exe |
Win32 DRK Driver
Added by the WOOTBOT.CY WORM! |
 |
winstr32.exe |
Win32 exe file
Added by a variant of the SPYBOT WORM! |
 |
winfw.exe |
Win32 Firewall Driver
Added by a variant of the RBOT WORM! |
 |
win32help.exe |
Win32 Help32 Service
Added by the DELBOT-U WORM! |
 |
windowsnfo.exe |
Win32 Info
Added by a variant of the IRCBOT TROJAN! |
 |
winserver.exe |
win32 internet server
Added by the DERMON-D TROJAN! |
 |
win32update.exe |
Win32 Kernel Update
Added by the PROXY-BS TROJAN! |
 |
winwkys.exe |
Win32 Services Config
Added by the RBOT.BKY WORM! |
 |
wuamngr1.exe |
Win32 Services1
Added by the SDBOT-PV WORM! |
 |
win32src.exe |
Win32 Src Service
Added by the RBOT-SX WORM! |
 |
winssv.exe |
Win32 SSL Driver
Added by the FORBOT-BH WORM! |
 |
winservice.exe |
Win32 System Kernel
Added by the SDBOT.KIN WORM! |
 |
winserver.exe |
win32 system server
Added by the DERMON-A TROJAN! |
 |
winxpinit.exe |
Win32 USB Driver
Added by the SDBOT.AA TROJAN! |
 |
wins32.exe |
Win32 USB2
Added by a variant of the RBOT WORM! |
 |
win32usb.exe |
Win32 USB2 Driver
Added by the SPYBOT.DHV WORM! |
 |
wind32.exe |
Win32 USB2 Driver
Added by the FORBOT-AH WORM! |
 |
winupdate.exe |
Win32 USB2 Driver
Added by the AGOBOT.YE WORM! |
 |
winsnd32.exe |
Win32 USB2 Driver
Added by a variant of the SDBOT WORM! |
 |
w32usb2.exe |
Win32 USB2.0 Driver
Added by the SPYBOT.DN WORM! |
 |
win32tool.exe |
Win32 USB3 Driver
Added by a variant of the RBOT WORM! |
 |
winitr32.exe |
Win32 Wmls Driver
Added by the WOOTBOT.B WORM! |
 |
win32.exe |
win32.exe
Added by the STARTPAGE TROJAN! |
 |
Win32.exe |
Win32.exe
Added by the AWQ.A TROJAN! |
 |
Wintask.exe |
Win32BaseServiceMOD
Added by the NAVIDAD WORM! |
 |
win32sys4.exe |
win32beta
Added by the BANKER-DA TROJAN! |
 |
win32clf.exe |
win32clf
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
win32debug.exe |
win32debug
Added by the GUDEB WORM! |
 |
Win32DLL.vbs |
Win32DLL
Added by the LOVELETTER (I LOVE YOU) VIRUS! |
 |
Win32dll.exe |
Win32dll
Added by the BANPAES TROJAN! |
 |
win32gb.exe |
win32gb
Added by the DLUCA-F TROJAN! |
 |
webemir.exe |
Win32Host Process
Added by the TURGEN -A TROJAN! |
 |
win32info.exe |
win32info
Adult content dialler |
 |
Win32sl.exe |
WIN32SL
Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. The specific function of this is to load MIF's in order for Dell OpenManage Client to work |
 |
win32s.exe |
Win32System
Added by the MYDOOM.V WORM! |
 |
win32us.exe |
win32us
All-In-One-Telcom (adult content dialler) variant |
 |
WinCab.exe |
Win32Usr
Added by the DEDMIR-A WORM! |
 |
win32_i.exe |
win32_i lptt01
RapidBlaster variant (in a "win32_i" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
win32_i.exe |
win32_i ml097e
RapidBlaster variant (in a "win32_i" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
Win386.exe |
Win386
Added by the GOSUSUB VIRUS! |
 |
winabsmod.exe |
WIN3S2SNDS
Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" |
 |
winiprtx.exe |
WIN3S2SNDS
Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" |
 |
wingrd.exe |
win98 DNS
Added by a variant of the RBOT WORM! |
 |
winable.exe |
WinAble
Added by the MATCASH.BG TROJAN! |
 |
Winacsr.exe |
Winacsr
AceScreenSpy keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
WINACTIVE.EXE |
winactive
WinActive of the LOP.com hijacker |
 |
WinActiveJ.exe |
WinActiveJ
Added by the ROTARRAN VIRUS! |
 |
Winad.exe |
Winad Client
WinAd adware by eXact Advertising |
 |
WinAdCnt.exe |
WinAdCnt.exe
Added by the BANKER-BU TROJAN! |
 |
winadm.exe |
winadm
Browser hijacker - redirecting to Search-World.net. Related to the SMALL.AEX TROJAN! |
 |
WinAgent.exe |
WinAgent
Standard Life Insurance program. Is it required at startup? |
 |
Winahlp.exe |
Winahlp.exe
Added by a variant of the VAGRNOCKER TROJAN! |
 |
winallap.exe |
winallap
Added by the DELF.E TROJAN! |
 |
winallapu.exe |
winallapu
Added by the DELF.E TROJAN! |
 |
winamp.hta |
Winamp
Hijacker - re-directing to adult content sites. Note - this isn't the real Winamp |
 |
winamp.exe |
Winamp
Added by the AGOBOT.XI WORM! Note - this is NOT the popular Winamp media player |
 |
winamp62.exe |
WinAMP
Added by the SDBOT-WN WORM! |
 |
winamp.exe |
Winamp
Winamp media player. Resides in a "Winamp" subdirectory of the Program Files directory |
 |
winamp.exe |
Winamp Agent
Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player. The valid filename for the Winamp Agent is "winampa.exe" - see here |
 |
winapa.exe |
Winamp media player
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
winamap.exe |
Winamp Media Player
Detected by PCTools as the SDBOT.ACJM BACKDOOR! See here |
 |
winamp.exe |
Winamp Media Player
Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of %ProgramFiles% |
 |
winampp.exe |
WinAmp Player
Added by the RBOT-AQI WORM! Note - this is NOT the popular Winamp media player which has a different filename |
 |
Winamp6.exe |
Winamp Player 6
Added by a variant of the SPYBOT WORM! |
 |
winamptogoogletalk.exe |
Winamp to Google Talk
Winamp to Google Talk, available here shows your current Winamp track in your Google Talk status |
 |
WINAMPa.exe |
Winampa
Loads the System Tray icon for the popular Winamp media player - see here. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs. Resides in a "Winamp" subdirectory of the Program Files directory |
 |
winampa.exe |
Winampa
Added by the AGOBOT-GS TROJAN! ! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of the Program Files directory whereas this file is located in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
WINAMPA.EXE |
Winampa Agent
Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player. The valid filename for the Winamp Agent is "winampa.exe" - see here |
 |
WINAMPa.exe |
WinampAgent
Loads the System Tray icon for the popular Winamp media player - see here. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs. Resides in a "Winamp" subdirectory of the Program Files directory |
 |
Winagent.exe |
WinAmpAgent
Added by the EB TROJAN! Note - this is NOT the popular Winamp media player which has a different filename |
 |
was5.exe |
WinAntiSpyware 2005
WinAntiSpyware 2005 spyware remover - not recommended, see here |
 |
was7.exe |
WinAntiSpyware 2007
WinAntiSpyware 2007 spyware remover - not recommended, see here |
 |
WinAntispyware2008.exe |
WinAntispyware2008
WinAntispyware2008 rogue spyware remover - not recommeded, see here |
 |
WinAV.exe |
WinAntiVirus Pro 2007
WinAntiVirus Pro 2007 misleading virus software - not recommended, see here |
 |
winapix.exe |
WinApi
Added by a variant of the TIBSER.A downloader TROJAN! |
 |
WINAPLOGUPD.EXE |
WINAPLOGUPD
Added by the CAPSIDE-C WORM! |
 |
winpup32.exe |
Winapp
Produces popup ads to adult content sites |
 |
winlogon.exe |
WinAuth
Hijacker, also indentified as the STRTPAGE.BE TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder |
 |
WinAvXX.exe |
WinAVX
Added by the FAKEAVALERT TROJAN! |
 |
WinAvX.exe |
WinAvX
WinAntiSpyware spyware remover - not recommended, see here |
 |
WinAwk.exe |
WinAwk
Added by the SDBOT-AYF WORM! |
 |
Wbsched.exe |
WinBackup Scheduler
LIUtilities WinBackup scheduler - backup software |
 |
WinBar.exe |
WinBar
"WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls" |
 |
winbed.exe |
Winbed
Hijacker |
 |
win32exe.exe |
winbin32
Added by the RBOT-ZL WORM! |
 |
winbo32.exe |
winbo32
Added by the RBOT-GRU WORM! |
 |
winboot.exe |
winboot
Added by the BANLOAD-W TROJAN! |
 |
winbot.exe |
winbot
Added by the MIDRUG-A TROJAN! |
 |
winbrush.exe |
WinBrush
WinBrush - "handy tool that keep your privacy and make your system clean. It works by cleaning up your tracks (document histories, recent opened files from popular software, cookies, temporary internet files, etc)" |
 |
WinButler.exe |
WinButler
Identified as a variant of the Trojan-Dropper.Agent.DKN malware |
 |
WinCheck.exe |
WinCheck
Added by the PWS-CY TROJAN! |
 |
winchost.exe |
winchost
Added by the DLOADER-PO TROJAN! |
 |
WINCIN~1.EXE |
WINCINEMAMGR
WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
 |
WinCinemaMgr.exe |
WinCinemaMgr
WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
 |
WinRemote.exe |
WINCINEMAMGR
InterVideo WinCinema Manager - needed for the use of WinDVD Remote Control |
 |
winclean.exe |
winclean
Added by the AGENT.GXR TROJAN! |
 |
wincmapp.exe |
wincmap
CasClient adware variant - also detected as the CMAPP TROJAN! |
 |
WinColorReminder.exe |
WinColorReminder
The Microsoft Color Control Panel Applet for Windows XP "helps you manage Windows color settings in one place." Part of the Pro Imaging Powertoys |
 |
WinCore32.exe |
WinCore32.exe
Added by the CLICKER-EN TROJAN! |
 |
wincrt32.exe |
WinCRT32
Added by the DOGBOT-D WORM! |
 |
winctl.exe |
winctl
Added by the IRCBOT-YI TROJAN! |
 |
wincore332.exe |
WINCX
Added by the AGOBOT-MG WORM! |
 |
wind.exe |
wind.exe
Added by the MITGLIEDER.BD TROJAN! |
 |
WIND0WS.exe |
WIND0WS
Added by the SPYBOT.DQ WORM! |
 |
wordpad.exe |
Wind0ws
Added by the AGOBOT-TL WORM! Note - this is not the legitimate Windows application wordpad.exe (which is found in the Program FilesAccessories folder) which should not normally be seen in Msconfig or as a Startup item. This file is loacted in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
Wind32.exe |
Wind32
Identified as a variant of the Backdoor.Win32.Poison.avs malware |
 |
windates.exe |
WinDates
WinDates is a calendar, date organizer and event reminder program from Rockin' Software |
 |
winxtc.exe |
windbs
Added by the AGOBOT-WD WORM! |
 |
winde.exe |
Winde
Added by the DLUCA TROJAN! |
 |
Win32sp.vbs |
windef
Added by the ANPES WORM! |
 |
windef.exe |
windef
Added by the WURMARK-O WORM! |
 |
windefender.exe |
windefender
Added by the AGENT.BYH TROJAN! |
 |
windhost.exe |
windhost.exe
Added by the BANKER-BV TROJAN! |
 |
winos.exe |
windhost.exe
Added by the PWSAGENT-A WORM! |
 |
winrun.exe |
windir
Added by the WINBUR.B WORM! |
 |
wuaumqr1.exe |
Windir Working
Added by a variant of the IRCBOT TROJAN! |
 |
Windll.exe |
Windll
Added by the TRYNOMA TROJAN! |
 |
WSYS.EXE |
WINDLL
STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes, all passwords transacted even if they weren't keyed in, all web sites visited, every program launched including the path to that program, and more" |
 |
windll32.exe |
windll
Added by the ASTEF or RESPAN WORMS! |
 |
Windll.exe |
Windll.exe
Added by the STEALER TROJAN! |
 |
Windll32.exe |
Windll32
Added by the MSNPWS TROJAN! |
 |
windllsys32.exe |
windllsys32.exe
Added by a variant of the MITGLIE-A TROJAN! |
 |
windns32.exe |
WinDNS
Added by the GAOBOT.WX WORM! |
 |
winmon32.exe |
Window Monitor
Added by the SDBOT.RT WORM! |
 |
wwDisp.exe |
Window Washer
Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
 |
window.exe |
window.exe
Added by the MITGLIEDER.H or MITGLIEDER.J TROJANS! |
 |
wbload.exe |
WindowBlinds
WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins |
 |
Winex.exe |
WindowEnhancer
SCBar foistware variant |
 |
winupdatr.exe |
Windowfdgfds DasdLL Verifier
Detected by Trend Micro as the AGOBOT.HZ WORM! See here |
 |
Windowsdldfglcheckkk.exe |
Windowfdgfds DLL fgfdg Verifier
Added by the RBOT.CSP WORM! |
 |
winsecure.exe |
Windowfdgfds DLL fgfdg Verifier
Added by a variant of the RBOT WORM! |
 |
wfxload.exe |
WindowFX
Stardock WindowFX - "Allows you to add an unprecedented number of special effects to windows" |
 |
wiusyt.exe |
windown
Added by the QQPASS-M TROJAN! |
 |
wins.exe |
WindowRegKey update
Added by the SPYBOT.I WORM! |
 |
Windows.exe |
Windows
Added by the KAZMOR.A, BOBBINS & ALADINZ.D TROJANS! |
 |
windows.exe |
WINDOWS
Added by the MONBOT-A TROJAN! |
 |
WICleaner.exe |
Windows & Internet Cleaner Pro
Windows & Internet Cleaner Pro - "Powerful and easy to use internet surfing privacy protection & PC security software" |
 |
websvc.exe |
Windows .Net Manager
Added by the DLOADER-NY TROJAN! |
 |
win128.exe |
Windows 128 Module
Added by the FORBOT-ES WORM! |
 |
Win32edit.exe |
Windows 32 Editor
Added by the WOOTBOT.GQ WORM! |
 |
win32resc.exe |
Windows 32 Rescue
Added by the FORBOT-EU WORM! |
 |
Windows-Update.exe |
Windows 32 Update
Added by a variant of the RBOT WORM! |
 |
wauclt.exe |
Windows Account Alternation
Added by a variant of the IRCBOT TROJAN! See here |
 |
WinAdCtl.exe |
Windows AdControl
Windupdates adware variant |
 |
WinAdServ.exe |
Windows AdService
Windupdates adware variant |
 |
WinStat.exe |
Windows AdStatus
Added by the BLESHARE!DR VIRUS! |
 |
WinAdTools.exe |
Windows AdTools
Windupdates adware variant |
 |
Windows-Anti.exe |
Windows Anti Verifier
Added by the RBOT.ETT WORM! |
 |
winavscan.exe |
Windows Anti Virus Control Center
Added by a variant of the IRCBOT BACKDOOR! |
 |
walg32.exe |
Windows Application Layer
Added by the AGOBOT.ATN WORM! |
 |
walg32.exe |
Windows Application Layer Gateway
Added by the AGOBOT-AAZ WORM! |
 |
winlogon.exe |
Windows ARP Detectionc
Detected by Trend Micro as the RBOT.EAB WORM! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
winlogon.exe |
Windows ARP Detectioncx
Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
winupdater.exe |
Windows Auto Update
Added by the SDBOT.TF WORM! |
 |
WINDOWSUPDATE.EXE |
Windows Auto Updater
Added by the SDBOT.PB WORM! Note that there is a space at the beginning of the filename, ie, " WINDOWSUPDATE.EXE" |
 |
wuamgrder.exe |
Windows Automatic Update
Added by a variant of the RBOT WORM! |
 |
windrg.exe |
Windows Automatic Updater
Added by a variant of the RBOT WORM! |
 |
winboot.exe |
Windows Boot
Detected by Trend Micro as the AGENT.HBD TROJAN! See here |
 |
windowsboot.exe |
Windows Boot
Added by a variant of the IRCBOT TROJAN! See here |
 |
winboot.exe |
Windows Booter
Added by a variant of the IRCBOT TROJAN! |
 |
winbooter.exe |
Windows Booter!
Added by a variant of the IRCBOT TROJAN! See here |
 |
WINDOWS CLEAN-UP PRO.Exe |
Windows Clean-Up Pro
Windows Clean-Up Pro spyware remover - not recommended, see here |
 |
winclean.exe |
Windows Cleaner Service
Added by a variant of the IRCBOT TROJAN! See here |
 |
wincmd.exe |
Windows Command
Added by the RBOT.ANV WORM! |
 |
wincomm.exe |
Windows Communicator
Added by the AGOBOT-BH WORM! |
 |
windowsconf.exe |
Windows Conf
Added by a variant of the IRCBOT TROJAN! See here |
 |
wins.exe |
Windows Config
Added by the SPYBOT.JR WORM! |
 |
winconfig.exe |
Windows Config
Detected by Trend Micro as the IRCBOT.BAP BACKDOOR! See here |
 |
Wincfg32.exe |
Windows Config Loader
Added by the SILVERFTP TROJAN! |
 |
winconf.exe |
Windows Config Manager
Added by the RBOT-AIT WORM! |
 |
wsys32.exe |
Windows Configuration
Added by the GAOBOT.FB WORM! |
 |
wincfg32.exe |
Windows Configuration
Added by the MYTOB.ED WORM! |
 |
winxupdate.exe |
Windows Configuration Utility
Added by the AGOBOT.LW WORM! |
 |
winconf.exe |
Windows Configurator
Added by a variant of the IRCBOT TROJAN! |
 |
wkssvc.exe |
Windows Console
Added by the SDBOT-DJX WORM! |
 |
wrasvc.exe |
Windows Console Component
Added by a variant of the IRCBOT TROJAN! See here |
 |
wnbsvc.exe |
Windows Console Norms
Added by a variant of the IRCBOT TROJAN! See here |
 |
wnbsvc.exe |
Windows Console Source
Added by a variant of the IRCBOT TROJAN! See here |
 |
WinCtlAd.exe |
Windows ControlAd
Windupdates adware variant |
 |
win32bootcfg.exe |
Windows Core Kernel Update
Added by the RANCK-EL TROJAN! |
 |
winbog32.exe |
Windows CPU host
Added by a variant of the RBOT WORM! |
 |
wincrt.exe |
Windows Critical Alert
Added by the ALEDO-A TROJAN! |
 |
WinDat.exe |
Windows Database
Added by an unidentified WORM or TROJAN! |
 |
wiinsvc.exe |
Windows Database
Added by the AGOBOT-RU WORM! |
 |
windde32.exe |
Windows DDE Loader
Added by the SDBOT-UZ WORM! |
 |
winlogg.exe |
Windows debug logging
Added by the RBOT-OY WORM! |
 |
winloggs.exe |
Windows debug logging
Added by the RBOT-QN WORM! |
 |
windbg.exe |
Windows Debugger
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
windbg32.exe |
Windows Debugger
Added by the ZOTOB.L WORM! |
 |
wfdmgrsp.exe |
Windows Default Server
Detected by Kaspersky as the IRCBOT.BCX TROJAN! See here |
 |
winampa.exe |
Windows Default Server
Added by the IRCBOT.AUN WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of the Program Files directory |
 |
wdc*.exe |
Windows Defender
Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com |
 |
wda*.exe |
Windows Defender Adds
Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com |
 |
wdm*.exe |
Windows Defender Monitor
Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com |
 |
wdu*.exe |
Windows Defender Updater
Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com |
 |
windesktop.exe |
Windows Desktop Controler
Added by the SDBOT-XH WORM! |
 |
winpadg.exe |
Windows Desktop Daemon
Added by a variant of the SPYBOT WORM! |
 |
WindowsSearch.exe |
Windows Desktop Search
Windows Desktop Search from Microsoft |
 |
wpabaln32.exe |
Windows Disk Defragmenter
Added by the BANCOS-ASJ TROJAN! |
 |
winupd32.exe |
Windows DLL host
Added by a variant of the SPYBOT WORM! |
 |
wdevice.exe |
Windows DLL Loader
Added by a variant of the SDBOT WORM! |
 |
WINCFG32.EXE |
Windows DLL Loader
Added by the AGOBOT-TE WORM! |
 |
winsvc32.exe |
Windows DLL Services
Added by the RBOT-ZF WORM! |
 |
windlls.exe |
Windows DLL Verifier
Added by the RBOT-AZQ WORM! |
 |
windns.exe |
Windows DNS
Added by the SDBOT-XU WORM! |
 |
windnsd.exe |
Windows DNS Daemon
Added by the WOOTBOT.AS WORM! |
 |
windns.exe |
Windows Domain Name Drivers
Added by the FORBOT-EP WORM! |
 |
windlmngr.exe |
Windows Download Manager
Added by an unidentified TROJAN! |
 |
winxpdriver.exe |
Windows Driver
Added by the WOOTBOT.EE WORM! |
 |
windrive.exe |
Windows Driver
Added by a variant of the IRCBOT TROJAN! See here |
 |
windvrhost.exe |
Windows Driver Sup
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
windrive.exe |
Windows Driver!
Added by a variant of the IRCBOT TROJAN! See here |
 |
windriver.exe |
Windows Driver!
Added by a variant of the IRCBOT TROJAN! See here |
 |
windowsupdate.exe |
Windows drivers update
Added by the RBOT-ACE WORM! |
 |
winDLL32.exe |
Windows Dynamic Loading Header
Added by a variant of the SDBOT WORM! |
 |
wmserv.exe |
Windows Email Server
Added by the FOUNDU-AWORM! |
 |
wecsvc.exe |
Windows Event Detection
Added by a variant of the IRCBOT TROJAN! See here |
 |
wposvc.exe |
Windows Event Provider
Added by a variant of the IRCBOT TROJAN! See here |
 |
winserv.exe |
Windows Event Service
Detected by Kaspersky as the SDBOT.XD TROJAN! See here |
 |
winmys.exe |
Windows Executable
Added by the RBOT-ABO WORM! |
 |
Winexec32.exe |
Windows Explorer Shell
Added by the REDIST.B WORM! |
 |
WINRE16.EXE |
Windows Explorer-3212
Added by the HARDOC WORM! |
 |
winprgs32.exe |
Windows Extensions for Win32
Added by the SDBOT.AFA WORM! |
 |
WINFAT32B.exe |
Windows FAT 32
Added by the SPYBOT-AGT WORM! |
 |
winprotect.exe |
Windows File Protection
Added by the AGOBOT.JB WORM! |
 |
wfvs.exe |
Windows File Verification Service
Added by the RANKY.AC TROJAN! |
 |
wfdmgr.exe |
Windows File XP Manager
Added by the SDBOT.XD TROJAN! |
 |
WindowsFirewall.exe |
Windows Firewall
Added by the MYTOB.AO WORM! |
 |
winlog.exe |
Windows Firewall Log
Added by an unidentified WORM or TROJAN! |
 |
wfsvc.exe |
Windows Firewall Service
Added by the IRCBOT-YL WORM! |
 |
winmu.exe |
Windows Firewalll
Added by a variant of the RBOT WORM! |
 |
WinForm.exe |
Windows FormatAd
Windupdates adware variant |
 |
winservicessss.exe |
Windows Genuine Validate
Detected by PCTools as the IRCBOT.UUI BACKDOOR! See here |
 |
wingmt32.exe |
Windows GMT32
Added by the MYTOB.KM WORM! |
 |
wingraphics.exe |
Windows Graphics Loaders
Added by the SPYBOT.JG WORM! |
 |
WAUMGRD.EXE |
Windows Guard
Added by the RBOT-GY WORM! |
 |
winhelper32.exe |
Windows Help File
Added by the SDBOT-QK TROJAN! |
 |
winhelpsv.exe |
Windows Help Service
Added by the RBOT-LP WORM! |
 |
winhlp.pif |
Windows Help Service
Added by the RBOT-AKW WORM! |
 |
winhelp.exe |
Windows Helper
Detected by Kaspersky as the BANKER.APE TROJAN! See here |
 |
wsctnfy.exe |
Windows Helper
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
winhost.exe |
Windows Host
Added by the PRYSAT TROJAN! |
 |
winhosts.exe |
Windows Hosts
Added by a variant of the IRCBOT TROJAN! |
 |
winhttps.exe |
Windows HTTP services
Added by a variant of the SDBOT WORM! See here |
 |
wicomgr.exe |
Windows Icons Manager
Added by the RBOT-AIF WORM! |
 |
wID32.exe |
WINDOWS ID SYSTEM
Added by the MYTOB.LN WORM! |
 |
wintimage.exe |
Windows Image
Detected by Avast as the SDBOT-GEN44 WORM! |
 |
WIAcs.exe |
Windows Image Acquisition (WIASC)
Added by the RIZO.A TROJAN! |
 |
WIAcss.exe |
Windows Image Acquisition (WIASSC)
Added by the RIZO.A TROJAN! |
 |
winimsg.exe |
Windows iMessenger Messenger
Added by the ALLIM.A WORM! |
 |
winstall.exe |
Windows installer
SpySheriff malware. For more information on registry key changes see SPYWAD-E |
 |
winstruct32.exe |
Windows Instruction Services
Added by a variant of the IRCBOT TROJAN! See here |
 |
winproc32.exe |
Windows Internet Protocol
CoolWebSearch Winproc32 parasite variant - also detected as the STARTPA-BF TROJAN! |
 |
wininet.exe |
Windows Internet Service
Added by the RBOT-AUX WORM! |
 |
wipv6.exe |
Windows IPv6 Drivers
Added by the SDBOT-VJ WORM! |
 |
weatherBug32.exe |
Windows Java Update
Added by a variant of the RBOT WORM! |
 |
Winjsd.exe |
Windows JavaScript Daemon
Added by the WOOTBOT.AF WORM! |
 |
wkssvr.exe |
Windows Kernel System Service
Added by a variant of the RANDEX.GEL WORM! |
 |
winkeyboard.exe |
Windows Keyboard Services
Detected by Trend Micro as the IRCBOT.AFS WORM! See here |
 |
winkeybrd.exe |
Windows Keyboard Services
Added by a variant of the IRCBOT TROJAN! See here |
 |
winkeybrd32.exe |
Windows Keyboard Services
Added by a variant of the IRCBOT TROJAN! See here |
 |
winlivemgr.exe |
Windows Live Manager
Detected by Trend Micro as the SHEUR.EB WORM! See here |
 |
wllivemsngr.exe |
Windows Live Messenger Addon
Added by a variant of the SDBOT WORM! See here |
 |
wlivemsg.exe |
Windows Live Msgs
Added by a variant of the IRCBOT TROJAN! See here |
 |
wlivemsgs.exe |
Windows Live Msgs!
Added by a variant of the IRCBOT TROJAN! See here |
 |
wlmsngr.exe |
Windows live Support
Added by the RBOT-BKL WORM! |
 |
windows.com |
Windows Load
?? |
 |
wstart32.exe |
Windows Loader
Added by the GAOBOT.CA WORM! |
 |
winServices.pif |
Windows Loader
Reported by Kaspersky Anti-Virus as the CARDSPY.D TROJAN! |
 |
Win_.exe |
windows Loadxm
Added by the FODDER-A TROJAN! |
 |
winthcr.exe |
Windows Local ISP
Detected by Trend Micro as the SDBOT.ENZ BACKDOOR! See here |
 |
websvc.exe |
Windows Local Services
Added by the DLOADER-NY TROJAN! |
 |
wsass.exe |
Windows Locator
Added by the IRCBOT.N TROJAN! |
 |
winlogon.exe |
Windows Log Agent
Added by the KEYLOGGER.AVK TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files |
 |
winlog.exe |
Windows Logger
Added by the NSHADOW-B TROJAN! |
 |
winlogd.exe |
Windows logging
Added by the RBOT-ON WORM! |
 |
wsrsvc.exe |
Windows Logical Adapter
Detected by Kaspersky as the IRCBOT.ARU TROJAN! See here |
 |
wcnsvc.exe |
Windows Logical Connection
Detected by Kaspersky as the VIRUT.AO VIRUS! See here |
 |
winlog.exe |
Windows Login
Added by the AGOBOT.MG WORM! |
 |
winzep.exe |
Windows Login Folder
Added by the AGOBOT-TZ WORM! |
 |
winlogin.exe |
Windows Login Manager
Added by a variant of the SDBOT WORM! |
 |
winlogin.pif |
Windows Login Security
Added by an unidentified WORM or TROJAN! |
 |
winlog.exe |
Windows Login Service
Added by the RBOT-AFN WORM! |
 |
winlogin.pif |
Windows Login Service
Added by the SDBOT-ACU WORM! |
 |
winlogin.exe |
Windows Logon
Added by the SPYBOT-C TROJAN! |
 |
WinIogon.exe |
Windows Logon Application
Added by the LINKBOT.M WORM! |
 |
win32help.exe |
Windows Logon Application
Added by the DELBOT-X WORM! |
 |
winlogon.exe |
Windows Logon Application
Added by the POEBOT-KW WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
winamp.exe |
Windows Logon Application
Added by the POEBOT-LR WORM! Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of the Program Files directory |
 |
winlogon.exe |
Windows Logon Applicationedc
Added by the DWNLDR-HGR TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile% |
 |
winlogonpc.exe |
windows logon procedure
Added by the WINLOGON TROJAN! |
 |
winlogon.pif |
Windows Logon Service
Added by the RBOT-AOU WORM! |
 |
winlolx.exe |
Windows LoL Layer
Added by the RBOT-FOR WORM! |
 |
win.exe |
Windows LoL Layer
Added by the RBOT-FTO WORM! |
 |
wm1exe.exe |
WINDOWS MANAGEMENT SYSTEM
Added by the RBOT-VT WORM! |
 |
winmants.exe |
Windows Manager
Added by the MANTAS WORM! |
 |
winsrv.exe |
Windows Manager
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
winlogonn.exe |
Windows mangement
Added by the RANDEX.FC WORM! |
 |
winmapp.exe |
Windows Media AP
Added by an unidentified WORM or TROJAN! |
 |
wmapp.exe |
Windows Media APP
Added by an unidentified WORM or TROJAN! |
 |
WMCCFG.exe |
Windows Media Connect 2
Windows Media Connect from Microsoft - stream digital media files on your computer to digital media receivers (DMRs) that are connected to your home network |
 |
wmloader.exe |
Windows Media Loader
Added by a variant of the GAOBOT WORM! |
 |
wmediaplayer.exe |
Windows Media Player
Added by the AGOBOT-NQ WORM! |
 |
wmplayer.exe |
Windows Media Player
Added by the KELVIR.G WORM or variants! Note - this is not the valid Windows Media Player as the executeable resides is C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP) rather than C:Program FilesWindows Media Player |
 |
wmpa36.exe |
Windows Media Player 3.6
Added by a variant of the RBOT WORM! |
 |
WMPA36B.EXE |
Windows Media Player 3.6b
Added by the RBOT-VV WORM! |
 |
wmpa36d.exe |
Windows Media Player 3.6d
Added by the RBOT-YA WORM! |
 |
wmpa36.exe |
Windows Media Player 3.9
Added by a variant of the RBOT WORM! |
 |
wmedia.exe |
Windows Media Player Service
Added by the RBOT.213504 WORM! |
 |
wmserv.exe |
Windows Media Server
Added by a variant of the IRCBOT TROJAN! See here |
 |
wmserver.exe |
Windows Media Server!
Added by a variant of the IRCBOT TROJAN! See here |
 |
wmediautil.exe |
Windows Media Utility
Added by a variant of the SPYBOT WORM! |
 |
windowsmem.exe |
Windows Memory Manager
Added by a variant of the IRCBOT TROJAN! See here |
 |
winlogin.exe |
Windows Messanger Control Center
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
winlogon.exe |
Windows Messanger Control Center
Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
winsys.exe |
Windows Messanger Control Center
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
wmdsvc.exe |
Windows Messenger Connect
Detected by Trend Micro as the SLENFBOT.S WORM! See here |
 |
wivsvc.exe |
Windows Messenger Fileshare
Detected by Symantec as the SILLYIM WORM! See here |
 |
winlivemsnmessenger.exe |
Windows Messenger Live MSN
Added by a variant of the IRCBOT BACKDOOR! |
 |
windowslivemsn.exe |
Windows Messenger Live Startup
Added by an unidentified WORM or TROJAN! See here |
 |
windowsmsnlive.exe |
Windows Messenger Live Startup
Detected by Kaspersky as the DELF.DAX TROJAN! See here |
 |
winmsg.exe |
Windows Messenger Messenger
Added by the VELKBOT.A WORM! |
 |
wbcsvc.exe |
Windows Messenger Panel
Detected by Trend Micro as the IRCBOT.ADA TROJAN! See here |
 |
winsmsgr.exe |
Windows Messenger Service
Added by the RBOT-VW WORM! |
 |
wmssvc.exe |
Windows Messenger Share
Added by a variant of the IRCBOT TROJAN! See here |
 |
wmvsvc.exe |
Windows Messenger Starter
Detected by Trend Micro as the SLENFBOT.T WORM! See here |
 |
wupdates32.exe |
Windows Micro Drivers
Added by the RBOT-AEH WORM! |
 |
wintask32.exe |
Windows Microsoft Update
Added by a variant of the SDBOT WORM! |
 |
winauth23.exe |
Windows Microsoft Verifier
Added by a variant of the RBOT WORM! |
 |
wmdc.exe |
Windows Mobile Device Center
Windows Mobile Device Center for Windows Vista. Replaces Microsoft ActiveSync and provides overall device management features for your Windows Mobile powered devices for Windows Vista |
 |
wmdSync.exe |
Windows Mobile-based device management
Part of Windows Mobile Device Center in Vista. Microsoft Windows Mobile Device Center enables you to set up new partnerships, synchronize content and manage music, pictures and video with Windows Mobile powered devices (Windows Mobile 2003 or later) |
 |
wmdc.exe |
Windows Mobile-based device management
Windows Mobile Device Center for Windows Vista. Replaces Microsoft ActiveSync and provides overall device management features for your Windows Mobile powered devices for Windows Vista |
 |
Windows-mod.exe |
Windows mod Verifier
Added by the RBOT.DSU WORM! |
 |
w1nz0zz0.exe |
Windows modez Verifier
Added by a variant of the SDBOT WORM! |
 |
Window2.exe |
Windows modez Verifier
Added by a variant of the RBOT WORM! |
 |
WindowsLogon.exe |
Windows modez Verifier
Added by a variant of the SDBOT WORM! |
 |
Wwuamguard.exe |
Windows modez Verifier
Added by the RBOT.EZJ WORM! |
 |
winlogom.exe |
Windows modez Verifier
Added by a variant of the RBOT WORM! |
 |
Windows-.exe |
Windows modez Verifier
Added by the RBOT-DIO WORM! |
 |
winl0g0z.exe |
Windows modez Verifier
Added by the RBOT-FNB WORM! |
 |
wuamguard.exe |
Windows modez Verifier
Detected by Kaspersky as the RBOT.CYA TROJAN! See here |
 |
winmon.exe |
Windows Monitor
Added by the SDBOT.VB WORM! |
 |
winmonitor.exe |
Windows Monitor Services
Added by the RBOT-XX WORM! |
 |
winmon.exe |
Windows Monitoring Service
Added by a variant of the SDBOT WORM! |
 |
winmouse.exe |
Windows Mouse Services
Added by the CHECKOUT WORM! See here |
 |
winmouse64.exe |
Windows Mouse Services
Detected by Trend Micro as the IRCBOT.AIA TROJAN! See here |
 |
winlog.exe |
Windows MSConfig Startup Logger
Added by the RBOT.BCU WORM! |
 |
wmsnlive.exe |
Windows MSN Live Messanger
Detected by Kaspersky as the RBOT.BMV TROJAN! See here |
 |
winlivemsn.exe |
Windows MSN Live Messenger
Added by an unidentified WORM or TROJAN! See here |
 |
winmessengerlive.exe |
Windows MSN Live Messenger
Detected by Kaspersky as the IRCBOT.EAD BACKDOOR! See here |
 |
wnd32.exe |
Windows MSN Updates
Added by the IRCBOT-ABA TROJAN! |
 |
winmsx.exe |
Windows MSX drivers
Added by the RBOT-AYG TROJAN! |
 |
wrmana32.exe |
Windows NetDDe
Added by the MYTOB.IM WORM! |
 |
WinNET.exe |
Windows Nets
Added by the RBOT-MO WORM! |
 |
winsN2S.exe |
Windows NetStart Service
Added by the RBOT-ZX WORM! |
 |
winsN2S.exe |
Windows NetStart Service2
Added by the RBOT-ABN WORM! |
 |
winsN2SD.exe |
Windows NetStart Service2
Added by a variant of the RBOT WORM! |
 |
WinxPupd.exe |
Windows Network Controller
Added by the FORBOT-DK WORM! |
 |
winmms32.exe |
Windows Network Controller
Added by the FORBOT-ED WORM! |
 |
wingmt.exe |
Windows Network Controller
Added by a variant of the SDBOT WORM! |
 |
Win9x.exe |
Windows Network Controller
Added by the WOOTBOT.I WORM! |
 |
winvc32.exe |
Windows Network Service
Added by the RBOT.RY WORM! |
 |
winnetwork.exe |
Windows Network Services
Added by a variant of the IRCBOT TROJAN! See here |
 |
winnetwork128.exe |
Windows Network Services
Added by the CHECKOUT WORM! See here |
 |
winnetwork32.exe |
Windows Network Services
Added by a variant of the IRCBOT TROJAN! See here |
 |
winnetwork64.exe |
Windows Network Services
Added by a variant of the IRCBOT TROJAN! See here |
 |
winsys32.exe |
Windows Networking
Added by the GAOBOT.FL WORM! |
 |
WNSM.EXE |
Windows NT Login Session Manager
Added by the RBOT.BIV WORM! |
 |
winlogon.scr |
Windows NT Logon Application
Added by the RBOT-ALP WORM! |
 |
winshock.exe |
Windows NT Service Name
Added by the RBOT-PK WORM! |
 |
WINL0G0N.exe |
Windows NT Update Manager
Added by the AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital "o" |
 |
winres32.exe |
Windows OEM Tools
Added by the SPYBOT.FD WORM! |
 |
winmgr.exe |
Windows Pc
Added by the BIBOT-A WORM! |
 |
winpdg.exe |
Windows PDG
Added by the RBOT-ADW WORM! |
 |
wmscupd.exe |
Windows Performance Monitor
Added by the IRCBOT_GEN WORM! |
 |
winpnp.exe |
Windows PNP
Added by the RBOT-AKN WORM! |
 |
winpo32.exe |
Windows Population Logger
Added by the AGENT.YKR WORM! |
 |
WinPrint.exe |
Windows Printing Driver
Added by a variant of the RBOT WORM! |
 |
WinSpooler.exe |
Windows Printing Driver
Added by an unknown malware |
 |
win_update.exe |
Windows Process
Added by the LASTWORD WORM! |
 |
winproc.exe |
Windows Process Manager
Added by an unidentified WORM or TROJAN! |
 |
WinSecure32.exe |
Windows Proffesional Security
Added by the AGOBOT.VA WORM |
 |
wservice.exe |
Windows Reg Services
Added by the PRORAT-O TROJAN! |
 |
winservicess.exe |
Windows Registers
Added by a variant of the SDBOT WORM! |
 |
winhost.exe |
Windows Registry
Added by a variant of the RBOT WORM! |
 |
winclean.exe |
Windows Registry Cleaner
Added by a variant of the SPYBOT WORM! |
 |
winreg.exe |
Windows Registry Control
Added by a variant of the IRCBOT TROJAN! See here |
 |
winregdll.exe |
Windows Registry DLL
Detected by Trend Micro as the IRCBOT.FB TROJAN! See here |
 |
winses.exe |
Windows Registry Name
Added by the RBOT-ADB WORM! |
 |
winmedia.exe |
Windows Registry Scan
Added by the SPYBOT.GK WORM! |
 |
wind32.exe |
Windows Registry Startup
Added by the AGOBOT-BZ WORM! |
 |
winxptdl.exe |
Windows Registry XP
Added by the IRCBOT.AUN WORM! |
 |
wnpcgs.exe |
Windows Remote Addressing
Added by the DELF-EZN TROJAN! |
 |
wnpmcs.exe |
Windows Remote Launcher
Detected by Kaspersky as the IRCBOT.ASX TROJAN! See here |
 |
winsto.exe |
Windows Rescue System
Detected by Kaspersky as the SUURCH.CG TROJAN! See here |
 |
winrvp.exe |
Windows Reverse Preperation
Added by a variant of the IRCBOT TROJAN! See here |
 |
winrsvp.exe |
Windows Reversed Virus Protection
Added by a variant of the IRCBOT TROJAN! See here |
 |
win64rt.exe |
Windows Run-Time 64bit
Added by a variant of the RBOT WORM! |
 |
win32hlp.exe |
Windows Runtime Help
Added by a variant of the AIMVISION TROJAN! |
 |
WinRunHelp.wrh |
Windows Runtime Help
Added by a variant of the AIMVISION TROJAN! |
 |
wmscheduler.exe |
Windows Scheduler
Added by a variant of the SDBOT WORM! See here |
 |
winsc.exe |
Windows Secure Connection
Added by the SDBOT.BTN WORM! |
 |
winupser.exe |
Windows Secure Update
Added by the RBOT-GCG WORM! |
 |
WinSecUp.exe |
Windows Secure Update
Added by the RBOT-GCD WORM! |
 |
wingrd.exe |
WINDOWS SECURITY
Added by a variant of the RBOT WORM! |
 |
win.pif |
Windows Security
Added by the RBOT-APT WORM! |
 |
winscure.exe |
Windows Security
Added by the RBOT-BAF WORM! |
 |
winsec.exe |
Windows Security Assistant
CoolWebSearch parasite variant |
 |
wscnfty.exe |
Windows Security Center Notification App
Added by a variant of the RBOT WORM! |
 |
winsecurity.exe |
Windows Security Manager
Added by the AGOBOT-KI WORM! |
 |
winsecure.exe |
Windows Security Manager
Affilred adware |
 |
windows.pif |
Windows Security Service
Added by the RBOT-AMG WORM! |
 |
WinServAd.exe |
Windows ServeAd
Windupdates adware variant |
 |
winserv.exe |
Windows Server
Detected by Trend Micro as the IRCBOT.AVM TROJAN! See here |
 |
wscvs.exe |
Windows Server Client Verification Service
Added by the AGENT.AWC TROJAN! |
 |
wsivs.exe |
Windows Server IP Verification Service
Added by an unidentified WORM or TROJAN! See here |
 |
wspvs.exe |
Windows Server Peer Verification Service
Added by a variant of the RANKY TROJAN! |
 |
winsvr.exe |
Windows Server!
Added by a variant of the IRCBOT TROJAN! See here |
 |
winsy.exe |
Windows Servic2
Added by the RBOT-AIA WORM! |
 |
wuamgrd.exe |
Windows service
Added by the RBOT-QW WORM! |
 |
WINSVC.EXE |
Windows Service
Added by the SPYBOT-DH TROJAN! |
 |
windowz.exe |
Windows Service
Added by the SDBOT-AYI WORM! Note - dissables the automatic startup of other software and deactivates the Microsoft Internet Connection Firewall (ICF) |
 |
win32wins.exe |
Windows Service Agent
Added by the RBOT-LOL WORM! |
 |
winup32.exe |
Windows Service Agent
Added by the RBOT-GQX WORM! |
 |
winupds32.exe |
Windows Service Agent
Added by the RBOT-GQT WORM! |
 |
wit.exe |
Windows Service Agent
Added by the RBOT-GQV WORM! |
 |
wmscc.exe |
Windows Service Agent
Added by the RBOT-GQP WORM! |
 |
Window.exe |
Windows Service Loader
Added by the RBOT-XO WORM! |
 |
websvc.exe |
Windows Service Manager
Added by the DLOADER-NY TROJAN! |
 |
WindowsSP2.exe |
Windows Service Pack 2
Added by the SDBOT-TQ WORM! |
 |
winworks.exe |
Windows Service Pack Auto Update
Adware downloader, identified by eScan antivirus as Trojan-Clicker.Agent.bt |
 |
WIN43.EXE |
Windows Service Pack2
Added by the GAOBOT.G WORM! |
 |
winsupply.exe |
Windows Service Supply
Detected by Kaspersky as the IRCBOT.BFB TROJAN! See here |
 |
winsrvc.exe |
Windows Service Utitity
Added by the RBOT-ASI WORM! |
 |
winsvc32.exe |
Windows Services
Added by the MYTOB-CB WORM! |
 |
w32edus.exe |
Windows Services
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
w32service.exe |
Windows Services
Added by the AUTORUN-FU WORM! |
 |
w32services.exe |
Windows Services
Added by the AUTORUN-FT WORM! |
 |
winlogon.exe |
Windows Services
Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
winsysdll.exe |
Windows Services
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
winsyssrv.exe |
Windows Services
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
winudp.exe |
Windows Services
Added by a variant of the IRCBOT BACKDOOR! |
 |
wsiptis.exe |
Windows Services Ink Platform Tablet Input Subsystem
Added by the RBOT.APC WORM! |
 |
winlogz2.exe |
Windows Services Layer
Added by the RBOT-FZE WORM! |
 |
winl0g0.exe |
Windows Services Layer
Added by the RBOT-FZQ WORM! |
 |
win70.exe |
Windows shell
?? |
 |
WinSock32.exe |
Windows Socket Procedure
Added by the RBOT-FMX WORM! |
 |
WinIp32.exe |
Windows Sound Verifier
Added by the RBOT-FMO WORM! |
 |
wfirewall7.exe |
Windows SP2 Firewall
Added by a variant of the RBOT WORM! |
 |
wuauclt32.exe |
Windows SP2 Version Load
Added by the GAOBOT.CX WORM! |
 |
winspool.exe |
Windows Spool
Added by a variant of the IRCBOT TROJAN! |
 |
winsplr.exe |
Windows Spooler
Detected by Trend Micro as the SHEUR.ANX TROJAN! See here |
 |
winsv.exe |
Windows Spools SV
Added by the RBOT-AUQ WORM! |
 |
Windows-spyware.exe |
Windows spyware remover
Added by the SystemPoser TROJAN! |
 |
winmsn32.exe |
Windows sq Drivers
Added by the RBOT-ADI WORM! |
 |
winsql32.exe |
Windows Sql Service For Windows 32 Bit
Added by the FORBOT-FC WORM! |
 |
winssh.exe |
Windows SSH Client
Added by the RBOT-AXC WORM! |
 |
winssv.exe |
Windows SSL File
Added by the WOOTBOT.CA WORM! |
 |
winsta~1.exe |
Windows Startup
GoHip foistware |
 |
winstartup.exe |
Windows Startup
GoHip foistware |
 |
Wdrun32.exe |
Windows Startup
Added by the GAOBOT.AO WORM! |
 |
winload.exe |
Windows Subsys
Added by the NETSPREE.C WORM! |
 |
winsvc.exe |
WINDOWS SVC
Added by the MYTOB-EY WORM! |
 |
winmnon32.exe |
Windows SYN Control Center
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
wdns33.exe |
WINDOWS SYSTEM
Added by the MYTOB-BY WORM! |
 |
win.exe.exe |
WINDOWS SYSTEM
Added by the MYTOB.FA WORM! |
 |
winaup.exe |
WINDOWS SYSTEM
Added by the MYTOB-DN WORM! |
 |
winligon.exe |
WINDOWS SYSTEM
Added by the MYTOB.EP WORM! |
 |
winmon.exe |
WINDOWS SYSTEM
Added by the MYTOB.GB WORM! |
 |
winNTsys32.exe |
WINDOWS SYSTEM
Added by the MYTOB-DM WORM! |
 |
winsvc32.exe |
WINDOWS SYSTEM
Added by the MYTOB.HH WORM! |
 |
WINSYS.exe |
Windows System
Added by the RBOT-AEF WORM! |
 |
winsys33.exe |
WINDOWS SYSTEM
Added by the MYTOB.EK WORM! |
 |
winvnc.exe |
WINDOWS SYSTEM
Added by the MYTOB.EU WORM! |
 |
winxpserv.exe |
WINDOWS SYSTEM
Added by the MYTOB-BQ WORM! |
 |
winsys32.exe |
Windows System
Added by the MYTOB-IS WORM! |
 |
Win32IMAPSVR.exe |
WINDOWS SYSTEM
Added by the MYTOB-FQ or MYTOB-FU WORMS! |
 |
winsvc.exe |
WINDOWS SYSTEM
Added by the MYTOB.LM WORM! |
 |
winsys_32.exe |
Windows System 32
Added by the RBOT-FTR WORM! |
 |
win32bat.exe |
Windows System 32-Bat Service
Added by the MYTOB.FI WORM! |
 |
windasz-updote.exe |
WINDOWS SYSTEM By FEnR
Added by the MYTOB.LR WORM! |
 |
WinNeth.exe |
Windows System Configuration
Added by the RETHE-A WORM! |
 |
Winfrw.exe |
Windows System Configuration
Added by the SOLUFINA TROJAN or the DOMWIS-J WORM! |
 |
wincfg.exe |
Windows System Configuration
Added by the AGOBOT.OP WORM! |
 |
WINCFG32.EXE |
Windows System Configuration
Added by the AGOBOT-TE WORM! |
 |
windsns.exe |
WINDOWS SYSTEM Dns
Added by the MYTOB.EY WORM! |
 |
winload.exe |
WINDOWS SYSTEM FILE
Added by the MYTOB.DK WORM! |
 |
winit32.exe |
Windows System Init
Added by a variant of the RBOT WORM! |
 |
winsystem.exe |
Windows System Manager
Added by the RBOT-AN WORM! |
 |
winsysmgr.exe |
Windows System Manager
Detected by Trend Micro as the IRCBOT.BJG TROJAN! See here |
 |
winsmc.exe |
Windows System Manager Proc
Added by the RBOT.JH WORM! |
 |
wnpsm.exe |
windows system notepad
Added by a variant of the RBOT WORM! |
 |
winmp.exe |
Windows System Security
Added by the RBOT.IV WORM! |
 |
winserv.exe |
Windows System Serivce
Added by the RBOT.ACA WORM! |
 |
winsock.exe |
windows system service
Added by the RBOT-MR WORM! |
 |
wnuserv.exe |
Windows System Service
Added by the SPYBOT.ANDM WORM! |
 |
windowsp.exe |
Windows System32
Added by the MYTOB.GD WORM! |
 |
winsys32.exe |
Windows System32
Added by the SDBOT-AHS WORM! |
 |
wingrd32.exe |
Windows System32
Added by a variant of the RBOT WORM! |
 |
winjews16.exe |
Windows Systems16
Added by a variant of the SDBOT WORM! |
 |
winshvc.exe |
Windows Sz Host
Added by a variant of the SDBOT WORM! |
 |
Wintaskad.exe |
Windows TaskAd
Windupdates adware variant |
 |
winpifviewer.exe |
Windows Taskmanager
Added by a variant of the IRCBOT TROJAN! See here |
 |
wdtsvc.exe |
Windows Taskmanager
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
winpifviewer.exe |
Windows Taskmanager
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
winrl.exe |
Windows Taskmanager
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
wintcp.exe |
Windows TCP/IP
Added by the AGOBOT-ZH WORM! |
 |
wintel.exe |
Windows Telnet Server
Added by the AGOBOT-MW WORM! |
 |
wintmp.exe |
Windows Temperate Services
Detected by Trend Micro as the SLENFBOT.AT WORM! See here |
 |
winmgr.exe |
Windows Time
Added by the RBOT-XC WORM! |
 |
winscrvs.exe |
Windows Time Service Diagnostic Tool
Detected by Trend Micro as the RBOT.FTV BACKDOOR! See here |
 |
windowssys32.exe |
Windows TM
Added by a variant of the RBOT WORM! |
 |
WinxSys.exe |
Windows TM
Added by a variant of the RBOT WORM! |
 |
winudspm.exe |
Windows UDP Control
Added by a variant of the SDBOT WORM! See here |
 |
winlive32.exe |
Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
winmsn.exe |
Windows UDP Control Center
Detected by Kaspersky as the SDBOT.EBA BACKDOOR! See here |
 |
winrofl32.exe |
Windows UDP Control Center
Added by the LDPINCH-RZ TROJAN! |
 |
winudpmg.exe |
Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
winudpmgr.exe |
Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
winudpmgrs.exe |
Windows UDP Control Center
Detected by Trend Micro as the DROPPER.CMV TROJAN! See here |
 |
winudpmsgr.exe |
Windows UDP Control Center
Detected by Trend Micro as the SDBOT.GAV WORM! See here |
 |
winupmgr.exe |
Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
winuscn32.exe |
Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
wksvcsc.exe |
Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
winudpmgr.exe |
Windows UDP Control Manager
Added by a variant of the SPYBOT WORM! See here |
 |
wksvcsc.exe |
Windows UDP Control Services
Added by the ANTIAV-C TROJAN! |
 |
wudate.exe |
Windows Update
Added by the AGOBOT.ML WORM! |
 |
wupdate.exe |
Windows Update
Wengs adware |
 |
Wuamgrd.exe |
Windows Update
Added by a variant of the SPYBOT WORM! |
 |
WindowsUpdate.exe |
Windows Update
Added by the BAYROB-A TROJAN! |
 |
wuraclt.exe |
windows update
Added by the RBOT-PO WORM! |
 |
Wuanclt.exe |
windows update
Added by the RBOT.XZ WORM! |
 |
windows.exe |
Windows Update
Added by the RBOT-RB WORM! |
 |
wuaurlt.exe |
windows update
Added by the RBOT.ADG WORM! |
 |
winmguard.exe |
Windows Update
Added by the RBOT-EM WORM! |
 |
wuampd.exe |
Windows Update
Added by the RBOT.UM WORM! |
 |
wuarclt.exe |
windows update
Added by the RBOT-OF WORM! |
 |
winupdate.exe |
Windows Update
Added by the SDBOT-WS WORM! |
 |
wininfo.exe |
Windows Update
Added by the MYTOB.GA WORM! |
 |
winlogin.exe |
Windows Update
Added by the BANKER-DV TROJAN! |
 |
windowsx.exe |
Windows Update
Added by the BANCD-A TROJAN! |
 |
wudupdate.exe |
Windows update
Adware downloader - Istbar related |
 |
wupdmgr.exe |
Windows Update
Added by the BANCBAN-FC TROJAN and variants! |
 |
Winload.exe |
Windows Update
Added by the DEDMIR-A WORM! |
 |
win32update.exe |
Windows Update
Detected by PCTools as the SDBOT.FTK WORM! See here |
 |
winsc.exe |
Windows Update
Detected by Kaspersky as the BUZUS.RYI TROJAN! See here |
 |
winlogons.exe |
Windows Update 32
Added by the FORBOT-FI WORM! |
 |
WinV.exe |
Windows Update 64
Added by the FORBOT-FP WORM! |
 |
wuaumgr.exe |
Windows Update Auto Update
Added by a variant of the SPYBOT WORM! |
 |
winuptdate.exe |
Windows Update Automation
Added by a variant of the RBOT WORM! |
 |
waucult.exe |
Windows Update AutoUpdate Client
Added by a variant of the RBOT WORM! |
 |
wuauclt.exe |
Windows Update AutoUpdate Client
Added by the LAZAR.B TROJAN! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup! |
 |
wuauct.exe |
Windows Update AutoUpdate Client Product
Added by the AGOBOT.ACL WORM! |
 |
W32RSA.exe |
Windows Update Center
Added by an unidentified WORM or TROJAN! |
 |
wuclient.exe |
Windows Update Client
Added by the SMALL-RN TROJAN! |
 |
windrvl32.exe |
Windows Update Client Service
Added by the AGOBOT-MM TROJAN! |
 |
winmsfw.exe |
Windows Update Firewall System
Added by the RBOT-EEO WORM! |
 |
wupdategux32.exe |
Windows Update GUI Executable x32x
Added by the RBOT.CXY WORM! |
 |
winupsvc.exe |
Windows Update Host
Added by a variant of the SDBOT WORM! |
 |
WIN32IPV6.EXE |
Windows Update IPv6 Layer
Added by the RBOT.DUD WORM! |
 |
wupdmngr.exe |
Windows Update Manager
Added by the RANDEX.BTB WORM! |
 |
Winlog0n.exe |
Windows Update Manager
Added by the AGENT-BO TROJAN! |
 |
wupdate.exe |
Windows Update Manager
Added by a variant of the RBOT WORM! |
 |
WindowsUpdateManager.exe |
Windows Update Manager
Added by a variant of the IRCBOT TROJAN! |
 |
wupdmgr32.exe |
Windows Update Manager for NT
Added by the SDBOT.AH WORM! |
 |
winupdt.exe |
Windows Update Monitoring Service
Added by the RBOT-PL WORM! |
 |
wmiprvsc.exe |
Windows Update Process
Added by the SDBOT-CB WORM! |
 |
wmiprvse32.exe |
Windows Update Service
Added by the AGOBOT.NI WORM! |
 |
wins32svcs.exe |
Windows Update services
Added by a variant of the RBOT WORM! |
 |
winupdate32.exe |
Windows Update Services
Added by a variant of the RBOT WORM! |
 |
wupdmgr32.exe |
Windows Updater
Added by a variant of the DOS.AUTOCAT TROJAN! |
 |
wupdate.exe |
Windows Updater
Added by the WOOTBOT.AJ WORM! |
 |
winupdatexx.exe |
Windows Updater Online
Added by a variant of the RBOT WORM! |
 |
winupdatr.exe |
Windows Updater Service Manager
Added by a variant of the IRCBOT BACKDOOR! |
 |
winupd32.exe |
Windows Updates
Added by the MYTOB.CE WORM! |
 |
w32dns.exe |
Windows Updates
Added by the SDBOT-BFW WORM! |
 |
winupdate.exe |
Windows Updates Agent
Detected by Trend Micro as the SPYBOT.HW WORM! See here |
 |
W1NT45K.exe |
Windows Updtee Mgnr
Added by the MYTOB.DC WORM! |
 |
winusb.exe |
Windows USB controler
Added by the RBOT-HR WORM! |
 |
Windowsusb.exe |
Windows USB Driver Support
Added by a variant of the SPYBOT WORM! |
 |
wsvc.exe |
Windows USB v3
Added by a variant of the SDBOT WORM! |
 |
wdfmrg.exe |
Windows User Mode Driver Manager
Added by the SDBOT-ZN WORM! |
 |
winuser32.exe |
Windows User Starter
Added by the RBOT.SN WORM! |
 |
wvsvc.exe |
Windows Video Acquisition (WVA)
Added by the AGOBOT.YM WORM! |
 |
wvcsvc.exe |
Windows Video Component
Added by a variant of the IRCBOT TROJAN! |
 |
winvirtual.exe |
Windows Virtual Services
Detected by Trend Micro as the SLENFBOT.V WORM! See here |
 |
winvirtual32.exe |
Windows Virtual Services
Detected by Trend Micro as the SLENFBOT.U WORM! See here |
 |
winvsvc.exe |
Windows Virus Scanner
Added by a variant of the IRCBOT TROJAN! See here |
 |
winxp_sp3.exe |
Windows Vista Corparation Agent Services
Added by a variant of the IRCBOT TROJAN! |
 |
websvc.exe |
Windows Web Services
Added by the DLOADER-NY TROJAN! |
 |
winhlp32.pif |
Windows Winhlp32 Stub Service
Added by the AIMBOT.AH TROJAN! |
 |
wsass.exe |
Windows WKS
Added by the SDBOT-DK WORM! |
 |
wkssvr1.exe |
Windows WKS Services
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
winfix.exe |
Windows WMF Fix
Added by the RBOT-FTQ WORM! |
 |
wkssvc.exe |
Windows Workstation Service
Added by the IRCBOT-AAI WORM! |
 |
wkssvc32.exe |
Windows Workstation Service (32-bits)
Added by a variant of the SDBOT WORM! |
 |
Wins.exe |
Windows xp
Detected by Trend Micro as the RBOT.VH TROJAN! See here |
 |
wXPupdate.exe |
Windows XP Automatic Update
Added by the RBOT-AFC WORM! |
 |
Windows XP SP2 KeyGen.exe |
Windows XP SP2 KeyGen
Added by the TIBICK-C WORM! |
 |
windows16.exe |
windows16
Added by the XU TROJAN! |
 |
windows32.exe |
windows32
Added by the XU TROJAN! |
 |
wuuaclt.exe |
Windows32
Added by the BRATLE.B WORM! |
 |
winser32.exe |
Windows32 Serivces
Added by the SPYBOT.AAF WORM! |
 |
WindowsAgent.exe |
WindowsAgent
Added by the GOP.G WORM! |
 |
WINDOWSBACKUP.EXE |
WindowsBackup
Added by the STANG WORM! |
 |
wscrc.exe |
WindowsCRC
Added by the SDBOT-VU WORM! |
 |
windows_critical_update.exe |
WindowsCriticalUpdate
Added by the ASTEF or RESPAN WORMS! |
 |
winsfs32.exe |
WindowsFileSystem
Added by the RBOT-FMQ WORM! |
 |
winsvcup.exe |
WindowsFirewallSvc
Added by a variant of the SDBOT WORM! |
 |
wp.exe |
WindowsFY
Part of a "Security IGuard" parasite infestation - also detected as DESKTOPHIJACK |
 |
winipsvc.exe |
WindowsIPRelay
Added by the IRCBOT-AAA WORM! |
 |
Winmgm32.exe |
WindowsMGM
Added by the SOBIG.A WORM and LALA.C TROJAN! |
 |
winupdate.exe |
WindowsRegKey update
Added by the RBOT-QJ WORM! |
 |
windns.exe |
WindowsRegKey update
Added by the RBOT.IE WORM! |
 |
winupdatexx.exe |
WindowsRegKey update
Added by the RBOT.LW WORM! |
 |
wdnupdate.exe |
WindowsRegKey update
Added by the SDBOT.QX WORM! |
 |
Windowsup.exe |
WindowsRegKey update
Added by the SDBOT.PU WORM! |
 |
WINUPDATES.EXE |
WindowsRegKey update
Added by the RBOT-MM WORM! |
 |
winsys.exe |
WindowsRegKey update
Added by the RBOT-JY WORM! |
 |
winupdat32.exe |
WindowsRegKey update
Added by the RBOT-AGW WORM! |
 |
windexv1.exe |
WindowsRegKey update XP
Added by the RBOT-ABM WORM! |
 |
winsysi.exe |
WindowsRegKeys update
Added by the SDBOT.WE WORM! |
 |
windowstime.exe |
windowstime.exe
Added by the AQV TROJAN! |
 |
WindowsUpd4.exe |
WindowsUpd
VirtuMonde adware |
 |
WindowsUpd1.exe |
WindowsUpd1
VirtuMonde adware |
 |
WindowsUpd2.exe |
WindowsUpd2
VirtuMonde adware |
 |
windows_update.exe |
WindowsUpdate
Added by the LOFNI WORM! |
 |
winupdate.exe |
windowsupdate
Added by the WARPI WORM! |
 |
winnnint.exe |
WindowsUpdate
Added by an unidentified WORM or TROJAN! |
 |
Windowsupdate .exe |
Windowsupdate
Detected by Kaspersky as the BANKER.ARK TROJAN! See here |
 |
wupdmgr98.exe |
Windowsupdate
Added by a variant of the IRCBOT BACKDOOR! |
 |
wuautlc.exe |
WindowsUpdate Service
Added by the RBOT-NR WORM! |
 |
wupdmng.exe |
WindowsUpdateManager
Detected by Trend Micro as the AGENT.VUX TROJAN! See here |
 |
windowsxpupdate.exe |
WindowsXP Update
Added by the RBOT-PB WORM! |
 |
windowsxxx.exe |
windowsxxx
Added by the DUBING-A TROJAN! |
 |
windowsxxx2.exe |
windowsxxx2
Added by the DUBING-A TROJAN! |
 |
winsystem.exe |
Windows_Protect
Added by a variant of the RBOT WORM! |
 |
winregal.exe |
Windows_Protect
Added by a variant of the RBOT WORM! |
 |
wincontrol32.exe |
Windows_Protect
Added by the RBOT-ADK WORM! |
 |
W32RfSA.exe |
Windoxs Update Center
Added by a variant of the SDBOT WORM! |
 |
windrg32.exe |
WinDrg32
Added by the DRUDGEBOT.A WORM! |
 |
WinDriv32.exe |
WinDriv32
Added by the SMALL-BA TROJAN! |
 |
windrvconf.exe |
WinDriver Configuration
Added by the AGOBOT-LX TROJAN! |
 |
WinDrives.EXE |
WinDrives
Added by the SMALL.DIG WORM! |
 |
windrv32.exe |
windrv
Added by an unidentified VIRUS, WORM or TROJAN! - possibly a strain of OBLIVION or BIONET |
 |
windrvx.exe |
WinDrv
Added by a variant of the TIBSER.A downloader TROJAN! |
 |
WinDSL_MTU.exe |
WinDSL MTU-Adjust
Adjusts the registry setting of the DUN-Adapters (MTU) and the TCP/IP-Protocol (RWIN) by ENGEL Technologieberatung |
 |
WinDSL_MTU.exe |
WinDSL_MTU
May be realted to Tiscali broadband, if so is it required? |
 |
Win????.exe |
WinDSNX
Added by the DSNX TROJAN! |
 |
WinUpdt.exe |
WindUpdates
Windupdates adware variant |
 |
WinDVRCtrl.exe |
WinDVRCtrl
Control center software for an AOpen VA1000 TV tuner card |
 |
winenv.exe |
winenv
Added by a variant of the SDBOT WORM! |
 |
Winexec.exe.vbs |
WinExec
Added by the AINESEY.A WORM! |
 |
WinExec.exe |
WinExec
Added by the FALUS-A WORM! |
 |
WinExec32.exe |
WinExec32
Added by the KAZWIN WORM! |
 |
Wfwiz.exe |
WinFast Schedule
Leadtek WinFast TV tuner scheduler and remote control driver - required if you use the latter |
 |
WF2k.exe |
Winfast_2K
System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card |
 |
WinFavorites.exe1 |
WinFavorites
Loudmarketing.com adware downloader |
 |
WFXCTL32.EXE |
WinFax PRO Controller
From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs |
 |
wfxsnt40.exe |
WinFaxAppPortStarter
WinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application. |
 |
WF.exe |
WinFire
Added by the DELF-SY TROJAN! |
 |
wfx5.exe |
WinFixer 2005
WinFixer web installer. Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here |
 |
wfxcwr.exe |
WinFixer helper
WinAntiSpyware 2005 by Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here |
 |
WinFlyer32.dll |
WinFlyer32.dll
Added by the WINFLYER TROJAN! |
 |
winfont.exe |
winfont
Added by the DEATH TROJAN! |
 |
winform.exe |
winform
Added by the PWS-ALB TROJAN! |
 |
WF2k.exe |
WinFoxV2
System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card |
 |
wgengmon.exe |
WinGate Engine Monitor
WinGate Internet Client Dialup Monitor - component of WinGate proxy server software. Displays the status of the WinGate engine, and appears in the system tray of each workstation on the network reassuring clients that their workstations have connectivity with the WinGate Server |
 |
WinGate.exe |
WinGate initialize
Added by the LOVGATE.F WORM! |
 |
wingerver2.0.exe |
wingerver2.0.exe
Added by the GRAYBRD-AE TROJAN! |
 |
wingo.exe |
wingo
Added by the BEAGLE.AW or BEAGLE.AV WORMS! |
 |
WGPRO32.EXE |
WinGuage Pro
Part of McAfee Nuts & Bolts. "WinGauge is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious". Resource hog. Available via Start -> Programs |
 |
WGFE95.EXE |
Winguard
Dr Solomon's Virex antivirus |
 |
wingrd32.exe |
winguard
Added by a variant of the RBOT WORM! |
 |
wgp.exe |
WinGuard Pro
Winguard Pro |
 |
winhe1p.exe |
Winhelp
Added by the QQPASS.E TROJAN! |
 |
WinHelp.exe |
WinHelp
Added by the LOVGATE.F WORM! Note - this file is located in %System% whereas the valid one is located in %Windir% |
 |
winhlp.exe |
winhlp.exe
Added by the FORMGLIEDER TROJAN! |
 |
winhlp3.exe |
winhlp3.exe
Added by a variant of the EASTO.A TROJAN! |
 |
Wscript.exe ..Msexec32.vbs |
Winhlp32
Added by the GANT.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "Msexec32.vbs" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
winhlp32.exe |
winhlp32.exe
Added by the EASTO.A TROJAN! |
 |
winhlpp32.exe |
winhlpp32.exe
Added by the GAOBOT.SY WORM! |
 |
wintt.exe |
Winhost
Added by the LOLAWEB.B TROJAN! |
 |
win.exe |
Winhost
Added by the DLOADER-AP TROJAN! |
 |
winhost.exe |
Winhost
Added by the REATLE.F WORM! |
 |
winhost.exe |
winhost.exe
Added by the LOHAV-R TROJAN! |
 |
winhost32.exe |
winhost32.exe
Added by the TABDIM TROJAN! |
 |
WinHound.exe |
WinHound
WinHound spyware remover - not recommended, see here |
 |
winierun.exe |
WinIeRun
Added by the RNWATCH-A WORM! |
 |
WinIFixer.exe |
WinIFixer
WinIFixer spyware remover - not recommended, see here |
 |
wvsvc.exe |
winimage
Added by the RBOT.TX WORM! |
 |
wininet.exe |
wininet
Added by the STUBBOT-C WORM! |
 |
wininet32.exe |
wininet32
Added by the RAZNEW-A TROJAN! |
 |
wininetd.exe |
wininetd
Added by the WINET TROJAN! |
 |
winini.vbs |
Winini.dll
Added by the STARTP-M TROJAN! |
 |
wininit.exe |
wininit
Added by the WOLLF.16 TROJAN! |
 |
Win86.exe |
WinInit
Added by the SMALL-PB TROJAN! |
 |
winint.exe |
winint
Added by the SDBOT-ADA WORM! |
 |
winipsec.exe |
winipsec
Unidentified malware |
 |
WinIRXHelper.exe |
WinIRXHelper
MSI Media Center Deluxe software - see here |
 |
winis.exe |
winis
Added by the RBOT-WI WORM! |
 |
Wink*.exe [* = random char] |
Wink*.exe
Added by a variant of the KLEZ WORM! |
 |
winkb6.exe |
Winkb6
Part of We-Blocker - gives parents the opportunity to monitor their children's Internet access and provide them with age-appropriate content, while filtering out sites that contain adult content. Works in conjunction with Winkb6 and both files are needed to run We-Blocker |
 |
WinKer.exe |
WinKernel
Added by the MIRAB or SERVIDOR TROJANS! |
 |
wWin32.com |
winkernel32
Added by the BANSAP TROJAN! |
 |
winkey.exe |
WinKey
Loads Copernic's WinKey. Used to map out Windows key hotkey combinations. Not required for the system, but is necessary for this to be running if you use these hotkey combos |
 |
winla.exe |
winla
Added by the DLOADR-AQL TROJAN! |
 |
winsplg.exe |
winlgn
Related to the Sentry Parental Controls software |
 |
winlgz2.exe |
winlgz2
Added by the KILLFIL-Q TROJAN! |
 |
winlibs.exe |
winlibs.exe
Added by the EVAMAN.C WORM! |
 |
winlink32.exe |
Winlink
Added by the GAOBOT.AAY WORM! |
 |
windll.exe |
Winlme
Added by the GOP.F WORM! |
 |
Winload.exe |
WinLoad
PCTattletale is a surveillance software program that monitors user activity, logs keystrokes, and takes screenshots. Uninstall this software unless you put it there yourself |
 |
winlog.exe |
winlog
Added by the GAOBOT_DF WORM! |
 |
winlog.exe |
winlog manager
Added by the DONBOMB.A TROJAN! |
 |
WINLOG0N.EXE |
WINLOG0N
Added by the MYDOOM.BI WORM! |
 |
winlogin.exe |
WinLogin
Added by the AGOBOT-IX WORM! |
 |
win32x.exe |
winlogin
Browser hijacker, also detetected as the STARTPA-DF TROJAN! |
 |
winlogoff.exe |
winlogoff
Added by the AGOBOT-TR WORM! |
 |
winlogon.exe |
winlogon
Hijacker or adult content dialler! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder |
 |
winlogin.exe |
winlogon
Added by the RANDEX.E WORM! |
 |
winlogon.exe |
winlogon
Added by the TRODAL TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder |
 |
winlogon32.exe |
winlogon
Added by the MASLAN.C WORM! |
 |
wpwlogon.exe |
winlogon
Added by an unidentified WORM or TROJAN! |
 |
wscript.exe WINLOGON.vbs |
WINLOGON
Added by the YSPAN.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "WinStart.vbs" file is found in %System% |
 |
WINLOGON.EXE |
Winlogon
Added by the PUNYA-B WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
winlogin.exe |
Winlogun
Added by the P2LOAD-C WORM! |
 |
winln.exe |
winltmpv
Added by the TCXMEDI-C TROJAN! |
 |
wutop.exe |
winltmpv
Added by the TCXMEDI-C TROJAN! |
 |
winmain.exe |
Winmain
One of the first of a new breed of malware. When run it immediately loads MSHTA.EXE from the Windows folder, placing it on "hot standby", ready to accept HTA scripting within a web page and then EXECUTE what is embedded IN the page as a program! In other words, it's possible for a "rogue" website to actually embed trojans, worms and/or viruses directly into a web page. NSClean's HTA Stop offers an easy way to toggle this capabiltity, or rather vulnerability, on and off. I suggest you leave it disabled! |
 |
wmanage.exe |
WinManage
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
WinMatrixXP.exe |
winmatrix.exe
WinMatrix XP - wallpaper replacement that shows different matrix effects (including flowing matrix codes from 'The Matrix' movie) on your desktop |
 |
winmed.exe |
WinMed
Detected by Trend Micro as the AGENT.AIRF TROJAN! See here |
 |
winmedia32.exe |
WinMedia32
Added by the YABE.F TROJAN! |
 |
WinMem.exe |
WinMem
WinMem Cleaner - part of Ultra WinCleaner Utility Suite. Makes more memory available for your programs and the Operating System. It also defragments your system |
 |
winmax.exe |
WinMenssage
Added by the BANCOS.B TROJAN! |
 |
WinMgmt.exe |
WinMgmt
Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here |
 |
winmgmt32.exe |
winmgmt32.exe
Added by the LUZIA.AD TROJAN! |
 |
winmgr32.exe |
WinMgr32
Added by the MIMAIL.P WORM! |
 |
wmexe.exe |
winmodem
Software for software based modems. Required if you have one of these. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information |
 |
winmon32.exe |
Winmon32
Added by the RBOT-OQ WORM! |
 |
WinMoviePlugIn.exe |
WinMoviePlugIn
Sfonditalia adult content premium rate dialer |
 |
winwork.exe |
Winmsg
Added by the GAOBOT.GEN!POLY WORM! |
 |
winmsgr.exe |
WinMsg
Added by the DLOADR-AS TROJAN! |
 |
WinMsrv32.exe |
WinMsrv32
Added by the GAOBOT.AFJ WORM! |
 |
WinMX.exe |
WinMX
WinMX file sharing application |
 |
winmysqladmin.exe |
winmysqladmin
Starts the MySQL database admin tool |
 |
winmysqladmin.exe |
WinMySQLadmin Tool
Starts the MySQL database admin tool |
 |
winnet.exe |
winnet
CommonName Toolbar spyware. To uninstall see here |
 |
winnload.COM |
winnload
Added by the DOWNLD-ABG TROJAN! |
 |
WnvMenu.Exe |
Winnov Menu
Winnov Video Capture Card related. What does it do and is it required? |
 |
WnvRsvr.Exe |
Winnov Remote
Winnov Video Capture Card related. What does it do and is it required? |
 |
WvStatus.Exe |
Winnov Status
Winnov Video Capture Card related. What does it do and is it required? |
 |
winnt.exe |
winnt
Added by the MONA-E WORM! |
 |
WinNT.com |
WinNT
Added by the AUTOSKY WORM! |
 |
wuamgrd32.exe |
winnt DNS ident
Added by the RBOT-BAU WORM! |
 |
windowxp.exe |
winnt DNS ident
Added by a variant of the RBOT WORM! |
 |
Winupd32.exe |
winnt DNS ident
Added by the RBOT.AVU WORM! |
 |
winupdate32.exe |
winnt DNS ident
Added by a variant of the RBOT WORM! |
 |
wuamgrd33.exe |
winnt DNS ident
Added by a variant of the RBOT WORM! |
 |
windowsp.exe |
Winnt DNS ident
Added by the RBOT.BAL WORM! |
 |
wupgrd.exe |
winNT updatc
Added by a variant of the RBOT WORM! |
 |
WinntBB.exe |
WinNtBB
Added by the DULOAD.C WORM! |
 |
win32nls.exe |
Winnup
Added by a variant of the SPYBOT WORM! |
 |
winocx32.exe |
winocx32
Added by the PROTORIDE.I WORM! |
 |
winnt.exe |
WINOWS SYSTEM
Added by the MYTOB.ID WORM! |
 |
winmic.exe |
WINP
Added by the SPYBOT-EB WORM! |
 |
winpack.exe |
Winpack
Adware - detected by Kaspersky as the AGENT.GG TROJAN! |
 |
winpatch.exe |
WinPatch Protection
Added by an unidentified WORM or TROJAN! |
 |
WinPatrol.exe |
WinPatrol
WinPatrol - "Manage Startup programs, tasks, cookies; will sniff out Worms, Trojan horses, Cookies, Adware, Spyware, Klez, Assumption and other malicious programs" |
 |
WinPatrolEx.exe |
WinPatrol Explorer
Part of WinPatrol |
 |
winpipe.exe |
winpipe
Browser hijacker redirecting to wow-access.com |
 |
WinPlosion.exe |
WinPLOSION
"WinPLOSION allows you to immediately view and select from all the windows running on your computer, just those of the active application, or to minimise all windows and display a clear desktop" |
 |
WinPPPoverEthernet.exe |
WinPoet
WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking |
 |
winpol.exe |
winpol
Added by the AGENT.IWD TROJAN! |
 |
Winpooch.exe |
Winpooch
"Winpooch is a Windows watchdog, free and open source. Anti spyware and anti trojan, it gives a full protection against local or external attacks by scanning the activity of programs in real time. Associated with ClamWin antivirus, Winpooch keeps safe your computer against virus" |
 |
winpop.exe |
WinPop
Brudevic A adware |
 |
WINPOPUP.EXE |
WinPopup
Intranet chat software provided by windows for chat on small networks. Handy little LAN messaging utility. Has been included in Windows since 95, and maybe in WFWG 3.11. Normally it won't set itself up to run unless the user specifically adds it to startup |
 |
winupie.exe |
winpopup
Adware by Tradeexit.com |
 |
Winpower.exe |
Winpower
Part of InstallAnywhere from Zero G Software, now owned by Macrovision |
 |
winprocer32.exe |
Winprocer32 Update
Added by the RBOT.GW WORM! |
 |
winprocessor.exe |
winprocessor Update
Added by the RBOT.IO WORM! |
 |
Winprot.exe |
WinProt
Added by the CHUPACABRA TROJAN! |
 |
win32.exe |
winprotect
Added by the MUGLY.E WORM! |
 |
winprotect.exe |
winprotect
Added by the SDBOT-SB WORM! |
 |
WinProxy.EXE |
WinProxy
"WinProxy is the world-first proxy server and a firewall with integrated mail server for Windows 95/98/ME/NT/2000/XP" |
 |
WINPROXY.EXE |
Winproxy Personal
Added by the SDBOT.BMF WORM! |
 |
winpsd.exe |
winpsd
Added by the MYDOOM.Q WORM! |
 |
wpwdmgr.exe |
WinPWD Manager
Added by the RBOT-AUT WORM! |
 |
winrapid.exe |
winrapid
Added by a variant of the RBOT WORM! |
 |
winrar.exe |
winrar
CoolWebSearch Therealsearch parasite variant. Note - this is not the file zipping utility also known as WinRAR! |
 |
WinrarCO.com |
WinRaR Service
Added by an unidentified WORM/TROJAN! |
 |
winrarshell32.exe |
winrarshell
Added by the SALIRA TROJAN! |
 |
WinReanimator.exe |
WinReanimator
WinReanimator spyware remover - not recommended, see here |
 |
winReg.exe |
winReg
Added by the YAHA.H or YAHA.J WORMS! |
 |
winregsrv.exe |
winregsrv
Added by the SYNRG TROJAN! |
 |
WinRemote.exe |
WINREMOTE
InterVideo WinCinema Manager - needed for the use of WinDVD Remote Control |
 |
winrestore.exe |
winrestore1
Added by the KILLFIL-Q TROJAN! |
 |
winreups.exe |
winreups
Added by a variant of the RBOT WORM! |
 |
winsn.exe |
winroot
Added by the QQPASS.IA WORM! |
 |
winroute.exe |
winroute
Win-Route 4.27. WinRoute Tray Icon for starting and stopping the WrCtrl.exe process, also to log in to the console to view logs and change settings. Can be unchecked and the engine still runs and functions normally. Can then use provided shortcuts for administration of the program. Loaded in SERVICES on Windows 2k |
 |
winrpcmx.exe |
WinRPC
Added by the BANKER-EEI TROJAN! |
 |
W1NT45K.exe |
WINRUN z
Added by the MYTOB.BL WORM! |
 |
WinDrivers.exe |
WinRunners
Added by the DULOAD.C WORM! |
 |
winet.exe |
Wins Service Driver
Added by the RBOT-APV WORM! |
 |
winsmc.exe |
WinScMngr
Added by the SDBOT-BPZ WORM! |
 |
winsec16.exe |
WinSec
Added by the AGOBOT.ZF WORM! |
 |
winsecure.exe |
winsecure
Browser hijacker, redirecting to specificsearches.com |
 |
Winserv.ila |
Winserv
Added by the NODMIN WORM! |
 |
winmain.exe |
Winservice
Adult content related malware |
 |
WinServ.exe |
WinService
Added by the SKOWOR-O WORM! |
 |
WinServices.exe |
WinServices
Added by the YAHA.K or YAHA.M WORMS! |
 |
winservn.exe |
winservn
PurityScan/Clickspring adware |
 |
winservs.exe |
winservs
PurityScan/Clickspring adware |
 |
winsfc.exe |
winsfc
Added by the WISFC VIRUS! |
 |
wuadfdqr.exe |
Winshoe
Probably an unidentified VIRUS! Adds itself to 3 registry "Run" keys and prevents Task Manager being displayed. This is not the Winshoe IRC Client as the visitor did not have it installed |
 |
winshost.exe |
winshost.exe
Added by the TOOSO WORM and variants! |
 |
winskype.exe |
winskype
Added by the BROGGER-C TROJAN! |
 |
winnt update.exe |
Winsock driver
Added by the SPYBOT-DM TROJAN! |
 |
winnt64.exe |
Winsock driver
Added by the SPYBOT-DR WORM! |
 |
win.exe |
Winsock driver
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
winsock.exe |
winsock.client
Added by the DIABLO-M TROJAN! |
 |
WINCFG.SCR |
Winsock2 driver
Added by a variant of the SPYBOT WORM! |
 |
winupdate.exe |
Winsock2 driver
Added by the SPYBOT-BX WORM! |
 |
WUAUMQR.EXE |
Winsock2 driver
Added by the SPYBOT-DP WORM! |
 |
wincfg.exe |
Winsock2 driver
Added by the SPYBOT.CO WORM! |
 |
WUAUMQR1.EXE |
Winsock2 wqr1s
Added by the SPYBOT.KD WORM! |
 |
WINLODR.SCR |
Winsock2.dll
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
win32server.scr |
Winsock32driver
Added by the HACARMY TROJAN! |
 |
win32server.exe |
Winsock32driver
Added by the BACKDOOR-AZV TROJAN! |
 |
win32server.exe |
Winsock32driver
Added by the HACARMY.F TROJAN! |
 |
winXPupdate.exe |
Winsock32driver
Added by the HACKARMY.9728 TROJAN! |
 |
winsock2.2.exe |
winsockdriver
Added by a variant of the SPYBOT WORM! |
 |
winsock3.exe |
winsockdriver
Added by the SPYBOT-DO WORM! |
 |
winsock4.1.exe |
winsockdriver
Added by a variant of the IRCBOT TROJAN! See here |
 |
WINSOS.EXE |
WINSOS VERIFY
WinSOS - "deletes spyware, optimizes your computer - backs up selected data" |
 |
winspd32.exe |
winspd32dll
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
windrv32.exe |
WinSPF
Added by the MYDOOM.T WORM! |
 |
winspf32.exe |
WinSPF
Added by the MYDOOM.S WORM! |
 |
winsplx.exe |
Winspl
Added by a variant of the TROLL-A TROJAN! |
 |
wsmmlog.exe |
winsplog
Added by the MAILBOT-CA TROJAN! |
 |
WinSpywareProtect.exe |
WinSpywareProtect
WinSpywareProtect rogue spyware remover - not recommended, see here |
 |
WinSpywareProtect.exe |
WinSpywareProtect (ver. 5.1)
WinSpywareProtect rogue spyware remover - not recommended, see here |
 |
winsrv.exe |
Winsrv
Added by the OPASERV.T WORM! |
 |
winsrv.exe |
winsrv
Added by the NETSNAK-B TROJAN! |
 |
WinStabilizer.exe |
WinStabilizer
Added by the AGOBOT-SW WORM! |
 |
WinStart.exe |
WinStart
From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge |
 |
Wscript.exe WinStart.vbs |
WinStart
Added by the CIAN.C WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "WinStart.vbs" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
winstart32.exe |
WinStart
Added by the PUROL WORM! |
 |
WinStart.pif |
WinStart
Added by the CONE.E WORM! |
 |
winstart.exe |
winstart
Added by the SCKEYLO-AB TROJAN! |
 |
WinStart001.exe |
WinStart001
From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge |
 |
WinStart001.exe |
WinStart001.EXE
From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge |
 |
winstats.exe |
winstats
Added by the GARGAFX TROJAN! |
 |
winsta~1.exe |
Winsta~1
GoHip foistware |
 |
WinSth16.exe |
WinSth16
Added by the CAKE WORM! |
 |
winsys64mnger.exe |
winsupdatesysmngr64
Added by the RBOT-BAG WORM! |
 |
WinSvc16.exe |
WinSvc16.exe
Added by the SDBOT.FQ TROJAN! |
 |
Winsvc32.exe |
Winsvc32
Homepage hijacker |
 |
winsvc32.exe |
winsvc32.exe
Added by the GREPAGE TROJAN! |
 |
winsy32.exe |
winsy32.exe
CoolWebSearch parasite variant |
 |
Winsys.exe |
Winsys
Win-Spy keyboard logger/monitoring software - remove unless you installed it yourself |
 |
Winsys32.exe |
WinSys32
Added by the CIGIVIP TROJAN or RECKUS WORM! |
 |
winsys32.exe |
winsys32 Driver
Added by the LOONY-O TROJAN! |
 |
WinSysRM.exe |
WinSysAppMon
Home & Family Content Filter related. See here |
 |
winsyslog.exe |
winsyslog lptt01
RapidBlaster variant (in a "Winsyslog" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
winsyst32.exe |
WinSyst32
Added by the MORB WORM! |
 |
winsystem.exe |
WinSystem
Added by the WHITEBAIT WORM! |
 |
WinSystems.exe |
WinSystem
CMKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
winsystems16.exe |
WinSystems
Added by the SDBOT-CZT WORM! |
 |
winsystems.exe |
winsystems25
Added by the RBOT-CNZ WORM! |
 |
wcp****.exe [* = random char] |
WINT
PurityScan/Clickspring adware |
 |
wcpcc.exe |
WINT
PurityScan/Clickspring adware |
 |
wcpsvit.exe |
WINT
PurityScan/Clickspring adware |
 |
Wintask.exe |
WinTask
Added by the HIPO or LEMIR.F TROJANS! |
 |
wintask.exe |
WinTask driver
Added by the DLOADER-NA TROJAN! |
 |
winxpro.exe |
WINTASKS
Added by the MYTOB.EZ WORM! |
 |
winkll.exe |
WinTasks DLL Library (32-bits)
Added by the RBOT-AJZ WORM! |
 |
wintasks.exe |
WinTasks Traybar
WinTasks - "Efficient Resource and Task Management is absolutely critical if you want to achieve the highest system performance levels possible. WinTasks 4 will not only help you achieve this task, but will actually make your system run faster and more smoothly than ever before" |
 |
wintasks.exe |
wintasks.exe
Added by the EVAMAN WORM! |
 |
wintbp.exe |
Wintbp.exe
Added by the ZOTOB.E WORM! |
 |
wintbpx.exe |
Wintbpx.exe
Added by the ZOTOB.F WORM! |
 |
wintective.exe |
wintective
Wintective logs keystrokes, captures screenshots, and monitors Internet activity. The gathered information can be sent to a predetermined email address. If you didn't install this yourself remove it |
 |
WINCOOL.EXE |
Wintercooler Pro
Wintercooler Pro - utility that monitors CPU usage, RAM consumption and Internet connection speed |
 |
winthelp.exe |
winthelp
AdvancedCleaner misleading security software - not recommended, see here |
 |
WinTidy.exe |
WinTidy
Desktop icon manager from PC Magazine (Ziff-Davis). Available via Start -> Programs |
 |
Wintime.exe |
Wintime
Added by the HARNIG TROJAN! |
 |
wintime.exe |
WinTime
WinTime - change desktop icons' color and font |
 |
Wxpload.exe Wintime |
Wintime Wtxpload
Part of the software to support a Dexxa USB graphics tablet. From a visitor - "This gets started anyway when you plug in the USB connector for the graphics tablet, if it's not already running. It then starts an application which manages the tablet messages. Since I leave the tablet unplugged unless I need to use it, I don't need this running at startup. I suspect that this program monitors a number of windows messages, so that when it's loaded, my regular mouse slows down - it acts like it 'sticks' entering and leaving windows. Certainly my performance returned to what I expected when I removed this item using MSCONFIG" |
 |
wintnask32.exe |
wintnask32.exe
Added by the RBOT-AFP WORM! |
 |
wintnl.exe |
wintnl.exe
Added by a variant of the ZOTOB.K WORM! |
 |
wintnpx.exe |
wintnpx.exe
Added by the ZOTOB.H WORM! |
 |
WToolsA.exe |
WinTools
Wintools adware |
 |
WinTouch.exe |
WinTouch
Detected by Kaspersky as the AGENT.BUO TROJAN! |
 |
wintray.exe |
WinTray
Added by the LEGUARDIEN.B TROJAN! |
 |
wintsk32dll.exe |
wintsk32dll
Added by the RBOT-AAJ WORM! |
 |
winudll.exe |
winudll.exe
Added by the MITGLIE-CE TROJAN! |
 |
winupated.exe |
winupated.exe
Added by a variant of the SDBOT WORM! |
 |
winupd.exe |
winupd
SearchNew adware |
 |
winupd.exe |
winupd.exe
Added by the BEAGLE.M or BEAGLE.N WORMS! |
 |
winupdat.exe |
winupdat
Added by the CANBOT.A WORM! |
 |
wmbem.exe |
WinUpdate
Added by the REVCUSS.B TROJAN! |
 |
winupdate.exe |
winupdate
Added by the ALCAN.B WORM! |
 |
wupeng.exe |
Winupdate Engine
MalwareCrush spyware remover - not recommended, see here |
 |
winupdate.exe |
winupdate.exe
Added by the RADO TROJAN! |
 |
winupdate.exe |
winupdate.reg
Added by the SPYBOT.EAS WORM! |
 |
winupdates.exe |
winupdates
Added by the ALCRA-B WORM! |
 |
WinUpdating.exe |
WinUpdating
Added by the AGENT-GSC TROJAN! |
 |
winupdbc.exe |
WinUPDbc
Added by the BANKER-DSN TROJAN! |
 |
winupdsv.exe |
WinUpdsv
Added by the DROPO MACRO! |
 |
winupdtl.exe |
winupdtl
SecondThought adware variant |
 |
winrun.exe |
winur
Added by the WINUR.B WORM! |
 |
winguard.exe |
winusb.dll
Added by the FORBOT-CN WORM! |
 |
WinUsr.exe K1S2 |
WinUsr
Added by the CLUNK.A WORM! |
 |
winversion.exe |
winversion
Browser hijacker, redirecting to specificsearches.com |
 |
WinVNC.exe |
WinVNC
WinVNC is an application that allows you to remote control your PC from another PC somewhere on the internet. Now superseeded by RealVNC |
 |
winvxd32.exe |
winvxd32
Added by the GABLOLIZ.A WORM! |
 |
winwan.exe |
winwan lptt01
RapidBlaster variant (in a "Winwan" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
winwan.exe |
winwan ml097e
RapidBlaster variant (in a "Winwan" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
winword.exe |
winword
Added by the TORPID-C TROJAN! |
 |
WINWORD.exe |
WINWORD.exe
Added by the DRIVUS TROJAN! Note - this is not the legitimate MS Word process of the same name, which is always located in the Program Files folder. This one is found in System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
 |
winwsl.exe |
winwsl.exe
Added by the ZOTOB-J WORM! |
 |
WinXDefender.exe |
WinXDefender
WinXDefender rogue spyware remover - not recommended, see here |
 |
WinxDiagUpdate |
WinxDiagUpdate
Detected by Kaspersky as the RBOT.BWQ TROJAN! See here |
 |
winxp.exe |
winxp
Added by the BRONTOK-DN WORM! |
 |
winxp32.exe |
WinXp Updater
Added by the RBOT-HG WORM! |
 |
winxpdll32.exe |
winxpdll32.exe
Added by a variant of the SMALL downloader TROJAN! |
 |
WinXProtector.exe |
WinXProtector
WinXProtector rogue security software - not recommeded, see here |
 |
WinXpUpdate32.exe |
WinXpUpdate32
Added by the AGENT.YWL WORM! |
 |
winxp64.exe |
winxpusbd
Added by a variant of the RBOT WORM! |
 |
winystems.exe |
winystems25
Added by a variant of the SDBOT WORM! |
 |
winzbp.exe |
WinZap Check
Added by the RBOT-AWZ WORM! |
 |
winzip.exe |
winzip
Added by the RBOT.BDAWORM! Note - this is not part of the popular WinZip file compression utility |
 |
winzip81.exe |
Winzip Application
Added by the RBOT-BKZ WORM! |
 |
WZQKPICK.EXE |
WinZip Quick Pick
Added with WinZip version 8.1. "The new WinZip Quick Pick taskbar tray icon gives you instant access to WinZip and your Zip files. Just left click the icon to open WinZip, or right click it to instantly reopen recently used Zip files, access your Favorite Zip Folders, open WinZip Help, or start WinZip itself.". You can right-click and close it - choosing to not re-load it at start-up |
 |
WinZip.exe |
WinZip Update
Added by a variant of the RBOT WORM! Note - this is not part of the popular WinZip file compression utility |
 |
wakeservice.exe |
WinZix Service
WinZix adware |
 |
win_spool2.exe |
win_spool2
Added by the SCKEYLOG.B TROJAN! |
 |
Win Const.exe |
win_supp00.exe
Added by the ASSASIN-H TROJAN! |
 |
WINdirect.exe |
win_upd.exe
Added by the MITGLIEDER.M TROJAN! |
 |
WINdirect.exe |
win_upd2.exe
Added by the BEAGLE.AO WORM! |
 |
Win_vader.vbs |
Win_vader
Added by the INVASION.A VIRUS! |
 |
Winipcfgs.exe |
WIP Config GUI
Added by the RBOT-CN WORM! |
 |
wirelesscm.exe |
Wireless Connection Manager
Wireless adapter configuration utility for D-Link's range |
 |
wcourier.exe |
Wireless Console
ASUS Wireless Console - installed alongside ASUS wireless components and provides additional configuration options for these devices |
 |
WMP11Cfg.exe |
Wireless PCI Card Configuration Utility
Utility used by the LINKSYS wireless PCI card (WMP11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration |
 |
wpsvr.exe |
Wireless Provider Server
Added by the FORBOT-AD WORM! |
 |
WPC54CFG.EXE |
Wireless-G Notebook Adapter Utility
Utility used by the LINKSYS Wireless-G Notebook Adapter (WPC54G) |
 |
wjview.exe |
wjview
MS tool used to view window-based Java applications from the command line |
 |
wkcalrem.exe |
wkcalrem
Produces a pop-up reminder of events scheduled using the MS Works Calendar |
 |
WkDetect.exe |
WkDetect
Checks for updates to MS Works |
 |
wkfud.exe |
wkfud
A marketing program for MS Works |
 |
WksSb.exe |
WksSb
The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program. The Works Portfolio provides a location where you can store items you want to later put into a document or other file |
 |
WkUFind.exe |
WkUFind
MS Works Update Detection. MS Picture It! (versions 7 to current) use this automatic update feature during the log on process. It can also cause your system to automatically dial into your ISP as it tries to access the internet, if you have your system set to automatically dial when the internet is invoked. To manually update, go to Microsoft's Office/Works update site. You can also turn of the automatic update feature within Picture It! - see here |
 |
Winusb2.exe |
Wlan Drier
Added by the WOOTBOT.DC WORM! |
 |
WLANManager.exe |
WLAN Manager
Wireless management utility for the T-Com Speedport W 100 Card WLAN PCMCIA card |
 |
WLANSTA.EXE |
WLAN Status Tray Applet
System Tray icon for checking the status of a Wireless LAN |
 |
wlancfg.exe |
wlancfg
Inventel wireless router related - required in order to automatically connect to the Net at bootup |
 |
wlancfg5.exe |
wlancfg5
NetGear WG311v3 wireless PCI adapter driver - required in order to automatically connect to the wireless router/gateway at bootup. Note - may not install correctly on Windows9x/ME computers which have Slipstream accelerator installed. Uninstall Slipstream first, disabling slipcore and slipgui are insufficient |
 |
WLANSTA.EXE |
WLANSTA.EXE
System Tray icon for checking the status of a Wireless LAN |
 |
WLAN_Cfg.exe |
WLAN_Cfg.exe
Linksys Instant Wireless USB Network Adapter driver |
 |
wlsass.exe |
wlsass
Added by the RANKY.CY TROJAN! |
 |
wltray.exe |
wltray
System tray access to wireless LAN card configuration options |
 |
WINSYS.EXE |
WLWin
Added by the NAVER.A WORM! |
 |
WMVCR.exe |
WM VCR
WM Recorder allows you to record Windows Media(tm) streaming Video or Audio content. Can be accessed via Start Menu -> Programs |
 |
Wm24Pan.Exe |
Wm24Pan
ESI external sound card driver |
 |
winlogon.exe |
WMAudio
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
wmedia32.exe |
WMedia32
Added by the BANGER TROJAN! |
 |
wmiapi.exe |
WMI Application Interface
Added by the SPYBOT.RBY WORM! |
 |
wmiapsrvs.exe |
WMI Performance Adapter Services
Detected by Kaspersky as the RBOT.COU WORM! See here |
 |
wmiexe.exe |
WMIEXE.exe
NT component, used by Windows Millennium to detect Plug and Play-compliant IEEE 1394 devices during the startup process. Since this is important for the computer to work properly if you have these, Windows Millennium protects wmiexe.exe and will restore the file even if it's deleted or renamed |
 |
Wminf.exe |
Wminf
Added by the GEMA TROJAN! |
 |
Wminfo.exe |
Wminfo
Added by the GEMA TROJAN! |
 |
wmiprv.exe |
wmiprv
Added by the RBOT-WM WORM! |
 |
wmisrv.exe |
wmisrv
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
WINMEDUP.EXE |
WMP Auto Update
Added by the RBOT.CF WORM! |
 |
WMP54Gv4.exe |
WMP54Gv4
Linksys WMP54Gv4 wireless PCI adapter driver - required in order to automatically connect to the wireless router/gateway at bootup. Note - may not install correctly on Windows9x/ME computers which have Slipstream accelerator installed. Uninstall Slipstream first, disabling slipcore and slipgui are insufficient |
 |
wmplayer.exe |
wmplayer.exe
Added by the BANCBAN-CZ TROJAN! |
 |
wmpnscfg.exe |
wmpnscfg
"Microsoft Windows uses wmpnscfg.exe to alert users when media rendering devices are found on the network. Wmpnscfg starts the Windows Media Player Network Sharing Service (NSS) and then waits for notifications from the service. When wmpnscfg is notified that a new media device is available on the network, it displays a popup in the system tray that informs the user about the availability of the new device. If the user clicks the popup, wmpnscfg launches Windows Media Player, which displays a dialog box that asks the user to either allow or deny sharing with the new device." - see here |
 |
wms3.exe |
wms3
Added by the LEGMIR-AQG TROJAN! |
 |
wmsys32.exe |
wmsys32
Added by the BANPAES.B TROJAN! |
 |
WMUAgent.exe |
WMUAgent.exe
"WakeMeUp! is an advanced alarm clock for computers with Windows 2000, XP or Server 2003" |
 |
winmonv.exe |
wmv
Added by the AGENT-DG TROJAN! |
 |
wnsvc.exe |
WN Services
Added by the KBBOT-A TROJAN! |
 |
WNAD.EXE |
WNAD
Spyware added as a result of running a program called "Yo Mama Osama" (osama.exe). See here for more and how to get rid of it. There are other ways this can show up on your system, and it will manifest itself by periodically opening a new browser window with advertising for copy DVD software and the like |
 |
WNILOGON.exe |
WNILOGON
Added by the LEWOR-M TROJAN! |
 |
wns*****.exe [* = random char] |
WNSC
PurityScan/Clickspring adware |
 |
wlogf.exe |
Wnsck2 driver
Added by the SPYBOT-AF WORM! |
 |
wnscp**.exe [* = random char] |
WNSI
PurityScan/Clickspring adware |
 |
WNSO.exe |
WNSO
Baidu.SoBar adware |
 |
wns*****.exe [* = random char] |
WNST
PurityScan/Clickspring adware |
 |
wntlgns.exe |
wntlgns
CoolWebSearch parasite variant |
 |
WAPDATE.EXE |
won update
Added by the RBOT.N WORM! |
 |
WonderFrog.exe |
WonderFrog
Wonder Frog typing monitor |
 |
wcmd.exe |
Woods Inc
Added by the KILLFIL-O TROJAN! |
 |
winamp.exe |
woopie
Added by the AGOBOT.XV WORM! Note - this is NOT the popular Winamp media player |
 |
Watch.exe |
Woowatch
Wanadoo broadband ISP (now rebranded as Orange) related - not required |
 |
WordQcrs.exe |
WordQ carat flag
Related to WordQ Writing Aid Software |
 |
Words.exe |
Words
Added by the AGENT.GIT TROJAN! |
 |
wweb32.exe |
WordWeb
WordWeb - free theasaurus and dictionary. Start manually |
 |
workflow.exe |
Workflo
Related to BroadJump Client Foundation - broadband troubleshooting software installed by various companies. Is it required? |
 |
workpace.exe |
WorkPace 3.0
WorkPace - stress injury prevention software |
 |
wkcalrem.exe |
Works Calendar Reminder
Produces a pop-up reminder of events scheduled using the MS Works Calendar |
 |
wkfud.exe |
WorksFUD
A marketing program for MS Works |
 |
wm95.exe |
Workstation Scheduler
Desktop Management Scheduler. Part of Novell's Netware Client. Schedueles NDS events. If events have been schedueled, it is required, otherwise, it is useless and a memory hog |
 |
wrkstn.exe |
Workstation Services
Added by the RBOT-OJ WORM! |
 |
worldantispy.exe |
WorldAntiSpy
WorldAntiSpy, "rogue" spyware remover, installed as part of this scam |
 |
wd.exe |
Worm Detector
Worm Detector - antivirus add-on for Outlook 2K or XP for handling worms and spam |
 |
winstart.exe |
wormexe
Added by the EARLYBIRD WORM! |
 |
wovax.exe |
wovax
Added by the DAQA.A TROJAN! |
 |
wwf.exe |
wow
Added by the LINEAGE-Y TROJAN! |
 |
wpctrlnt.exe |
Wpctrl
WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
 |
wpctrl95.exe |
Wpctrl
WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
 |
wpctrlnt.exe |
wpctrl95
WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
 |
wpctrl95.exe |
wpctrl95
WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
 |
WpcUmi.exe |
WPCUMI
Windows Vista Parental Control Notifications from Microsoft Corporation |
 |
WpCycleWin.exe |
WPCycle.exe
Added when selecting Mplayer2 to open media files. Forces other codes to Wait for Previous instructions to end, preventing instability of your CPU (freezing) |
 |
wwnrot.exe |
wpds.exe
Added by the BAGLEDI-D TROJAN! |
 |
WPlayer.exe |
WPlayer
Identified as a variant of the LDPinch.A malware |
 |
wpnsc.exe |
WPSVC Services
Added by a variant of the IRCBOT BACKDOOR! |
 |
wpwmgrs.exe |
wpwmgrs
Added by the MYTOB-DH WORM! |
 |
WQK.exe |
WQK
Added by the KLEZ.H WORM! |
 |
WR.EXE |
wr
?? |
 |
wr.exe |
WR Command
?? |
 |
WrCtrl.exe |
WrCtrl
Win-Route 4.27 NAT engine on Win2k Pro for connection sharing and security using Win-Route by Tiny Software. A connection sharing/Firewall Application. If service is disabled the program does not work, but you can manually start/stop the service with a shortcut the program installs at any time |
 |
WrDialer.exe |
WRDialer
WinPoet DSL dialler |
 |
wregbios.exe |
WregBios
Desktop Management BIOS (DMI BIOS) related. Apparently invokes the DosBios.exe file. Is it required? |
 |
wrexec.exe |
wrexec
Watch Right - monitoring program, part of the PowerTools add-on for AOL. Records instant messages, E-mail, chat. Watch Right appears to be, and functions as an online clock updater which connects with the U.S. National Institute of Standards and Technology. It was designed for parents who wish to keep an eye on what their children are doing online |
 |
wriste.exe |
wriste
?? |
 |
WrtMon.exe |
WrtMon.exe
Related to Presto PageManager which is bundled with Canon Scanners |
 |
ws2help.exe |
ws2help
Added by a variant of the SMALL.AN TROJAN! |
 |
ws2_64.exe |
ws2_64.exe
Added by an unidentified TROJAN! See here |
 |
wmon32.exe |
WSAConfiguration
Added by the GAOBOT.BAJ WORM! |
 |
win32upd.exe |
WSAConfiguration
Added by a variant of the RBOT WORM! |
 |
winlogon32.exe |
WSAConfiguration
Added by the AGOBOT-WC WORM! |
 |
winmon32.exe |
WSAConfiguration
Added by the AGOBOT.TM WORM! |
 |
wsass32.exe |
wsass32
Added by the BANKEM-V TROJAN! |
 |
wsbklite.exe |
wsbklite
Related to the Acer Soft Button on Acer Tablet PCs. Appears to do nothing so is it required? |
 |
WScheduler.exe |
WScheduler
Windows Scheduler - "schedule unattended running of applications, batch files, scripts and much more. Also, you can schedule popup reminders so you'll never forget reminders, tasks and other events." |
 |
wscnfty.exe |
wscnfty
Added by a variant of the RBOT WORM! |
 |
wsscntfy.exe |
wscntfys
Added by the SDBOT-TN WORM! |
 |
wscsvc.exe |
wscsvc.exe
Added by a password stealing BANKER TROJAN! |
 |
wsctf.exe |
wsctf.exe
Added by the JAMPORK.E WORM! |
 |
WSconf.exe |
Wsdata service
Added by the SDBOT.ZU WORM! |
 |
wserv.exe |
wserv
Added by a variant of the SDBOT WORM! |
 |
wserver.exe |
wserver
Added by the NETSKY.AC or SASSER.G WORMS! |
 |
WService.exe |
WService
Tablet client Driver for UC-Logic Pen/Graphics Tablet |
 |
wsg32.exe |
wsg32
GoldenKeylog keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
wskrnl.exe |
wskrnl
ActMon surveillance software. Uninstall this software unless you put it there yourself |
 |
WSockDrv32.exe |
WSockDrv32
Added by the WINKO.AO WORM! |
 |
wsrv32.exe |
wsrv32
Detected by Kaspersky as the AGENT.EP TROJAN! |
 |
wmmon32.exe |
WSSAConfiguration
Added by the AGOBOT-KC WORM! |
 |
wssys.exe |
wssys
WebPI logs keystrokes and captures screenshots. If you didn't install this yourself remove it |
 |
Wstat32.exe |
Wstat32 driver
Added by the LOONBOT TROJAN! |
 |
wstimeb.exe |
wstimeb
Used with NEC printers. You can disable it before printing but it re-loads itself when printing so you may as well leave it |
 |
wsttrs.exe |
wsttrs
Added by the LDPINCH-QS TROJAN! |
 |
wsvbs.exe |
wsvbs
Added by the PWS-AEB TROJAN! |
 |
wswpd.exe |
wswpd
Used with some models of Panasonic, Epson and NEC printers. Some older drivers known to have a "memory leak". Needed for printing to work |
 |
wsys.exe |
wsys.exe
SpyloPCMonitor is a surviellance software program that monitors user activity, logs keystrokes, and takes screenshots. It ends the processes of anti-spyware programs. If you didn't install this yourself remove it |
 |
ws32.exe |
ws_d
Added by the LEGMIR-RL TROJAN! |
 |
wtgamechannel.exe |
WT Game Channel
WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
 |
wtgamechannel.exe |
WT GameChannel
WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
 |
wtftest.exe |
WTF Test
Added by the RBOT-ACM WORM! |
 |
wapisvit.exe |
WTSI
PurityScan/Clickspring adware |
 |
wap***.exe [* = random char] |
WTSS
PurityScan/Clickspring adware |
 |
wapisvtr.exe |
WTST
PurityScan/Clickspring adware |
 |
WU713STA.EXE |
WU713STA.EXE
Blitzz Technology wireless NIC adapter driver |
 |
wuanguard32.exe |
wuanguard
Added by the RBOT-AAF WORM! |
 |
WudfSvc.exe |
WudfSvc
Added by the SHEUR.BBB TROJAN! |
 |
WUOLService9x.exe |
WUOLService
Remote wakeup status agent. Part of Novell's ZenWorks. Processes Wake-up on LAN requests (turn on a computer remotely on LAN) |
 |
wuosdial.exe |
wuosdial
Added by a variant of the RBOT WORM! |
 |
win32.exe |
wupd
Added by the ORSE-C TROJAN! |
 |
wisvccz.exe |
wupdate
Added by the ORSE-B TROJAN! |
 |
wi32.exe |
wupdate
Downloader trojan, detected by Panda antivirus as Adware/Trustbid |
 |
WUpdates.exe |
WUpdates
Added by the SWEPDAT TROJAN! |
 |
Wupdm32.exe |
Wupdm32
Added by the MIDLAK WORM! |
 |
wupdmgr32.exe |
wupdmgr32.exe
Added by the CERTIF-I TROJAN! |
 |
wupdt.exe |
wupdt
Added by the IMISERV.A TROJAN! |
 |
wupftp.exe |
Wupftp
Added by the AGOBOT.AKV WORM! |
 |
WUSB11B.exe |
WUSB11B.exe
Linksys WUSB11 WLAN USB adapter |
 |
WUSB54Gv4.exe |
WUSB54Gv4
Wireless-G USB Wireless Network Adapter related - would appear to be required |
 |
wuviewer.exe |
wuviewer
Added by a Proxy Trojan variant |
 |
wsass.exe |
WWKS
Added by the SDBOT-BT WORM! |
 |
WXprocMgr.exe |
WXProcMgr Module
TVTonic from Wavexpress - "enjoy 3 full-screen, DVD-quality video channels for FREE". Allows data content to be downloaded and synchronized on your system |
 |
WZCBDL9X.exe |
WZCBDLService
WZCBDLService Launcher from D-Link - configuration/drivers |
 |
wzdmg.exe |
wzdmg
Added by a generic downloader TROJAN - see here |
 |
wzhelper.exe |
wzhelper
Searchcentrix hijacker |
 |
WTHRTRAY.EXE |
X10Weax
WeatherCheck - "bring the latest local weather to your desktop". Not recommended as it reportedly pops ads, and contains no uninstaller |
 |
wdfsctl.exe |
X4ALLNL
XS4All Webdisk - web space management utility for the Dutch ISP |
 |
wmsdkns.exe |
XMLmedia 10.0
Added by the FAKEALERT TROJAN! |
 |
wuauclt10.exe |
Xordate
Added by the RBOT-GKN WORM! |
 |
wuauclt11.exe |
Xordate
Added by the RBOT-GLI WORM! |
 |
wuauclt12.exe |
Xordate
Added by the RBOT-GLQ WORM! |
 |
wuauclt13.exe |
Xordate
Added by the RBOT-GLM WORM! |
 |
winis.exe |
xp
Added by the RBOT-WO WORM! |
 |
wini.exe |
xpstart
Added by the PICRATE.A WORM! |
 |
winlogins.exe |
xpstat
Added by the RBOT-AAR WORM! |
 |
winlogon.exe |
xp_system
Added by the KREPPER-G TROJAN! - a CoolWebSearch parasite variant. Note - this is not the legitimate winlogon.exe, which should not figure in Msconfig/Startup! |
 |
winxtn.exe |
XTN Service Drivers
Added by the SDBOT-YK WORM! |
 |
WatchPNM.exe |
YOW tuner
?? |
 |
WrDialer.exe |
z-WrDialer
WinPoet DSL dialer |
 |
winmuse.exe |
ZPoint
Added by the VJ TROJAN! |
 |
wincpu.exe |
[random name]
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
w?auboot.exe |
[random name]
PurityScan/Clickspring adware |
 |
w?auclt.exe |
[random name]
PurityScan/Clickspring adware |
 |
w?crtupd.exe |
[random name]
PurityScan/Clickspring adware |
 |
w?wexec.exe |
[random name]
PurityScan/Clickspring adware |
 |
w?nlogon.exe |
[random name]
PurityScan/Clickspring adware |
 |
w?nword.exe |
[random name]
PurityScan/Clickspring adware |
 |
w?aclt.exe |
[random name]
PurityScan/Clickspring adware |
 |
wucrtupd.exe |
[random name]
PurityScan/Clickspring adware. Do not confuse with the legitimate Windows Critical Update Notification (wucrtupd.exe) |
 |
wuauboot.exe |
[random name]
PurityScan/Clickspring adware. Note - do not confuse with the legitimate wuauboot.exe file, which should not figure in Msconfig/Startup! |
 |
w?nspool.exe |
[random name]
PurityScan/Clickspring adware |
 |
Windows32.exe |
[various names]
Added by any of a number of WORM or TROJAN variants |
 |
winlogon32.exe |
[various names]
Added by an unidentified WORM or TROJAN! |
 |
win32snd.exe |
[various names]
Added by the RBOT-DQ WORM! |
 |
WhatsNewBot.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
WinInitDll.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
wormexe.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
WTFCTF.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
winadm.exe |
_winadm
Parents Friend - "Log any activity and protect programs with a password. Further more you can lock the pc any hour in the week you want with the main password. You can also give users allowed programs in their program-lists and you can limit the maximal daily hours and maximal weekly hours user spend on the PC" |
 |
winexec.exe |
_WinMain
Added by the DLOADER-XX TROJAN! |