Windows Vista Tips


Processes beginning with w

The table below includes any process titles beginning with w, from which further information can be found by clicking on the process title. The icon beside the information can be used to quickly determine if this is a safe file in combination with the key below:



This file is normally safe to leave running. In most cases, this file is not required to run on startup and can be run manually. Warning, this file may be a virus, spyware, resource hog and running it is not recommended. This file may or may not be necessary to load on startup, depending on your circumstances. No information is available for this item.

[#] [A] [B] [C] [D] [E] [F] [G] [H] [I] [J] [K] [L] [M] [N] [O] [P] [Q] [R] [S] [T] [U] [V] [W] [X] [Y] [Z]

Processes beginning with w:

File Type Process Name and Information
w02db700.dll
ZenoSearch adware
W1N32.DLL
Added by the DROPPERFL.A TROJAN!
w32
Added by the SOKEVEN TROJAN!
W32.Scran
Added by the NARCS WORM!
w32alanis
Added by the SINALA WORM!
W32data
Added by a variant of the RBOT WORM!
W32Load
Added by the CASPID WORM!
W32PluginsDownloaderXMLHTTPSelfClearing7520
Added by the PROXYSER-M TROJAN!
w32sup
Adult content dialler
W32SYS
Added by the JAMBU-A WORM!
W32Tc
Added by the VOTE.D or VOTE.K WORMS!
W3KNetwork
Web3000 adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
W75P2PSERVER
Printer utility which is required in order to make the printer work correctly
w7zip
Added by the BANCBAN-QB TROJAN!
W815DM
Enuff Parental Control Software by Akrontech
w98Eject
Related to USB support for Sigmatel MP3 audio palyer (and others such as SanDisk). It's intent is to "put away" the "disk" before you unplug it from the USB port, ostensibly to avoid "losing" data
wab.exe
Added by a variant of the SDBOT WORM!
wait4IP
Packard Bell net2Plug allows you to network PCs anywhere in your house
wallchgr.exe wstart
WallChanger - wallpaper changer from Blue Tree Software
WallMaster
WallMaster - "The free and easiest way to master your desktop wallpaper!"
WallPaper
Added by the BANKER-GX TROJAN!
WallPaper
Wallpaper Changer - wallpaper manager that can change your background images on every startup
WallpaperChanger
A wallpaper changer and manager utility. There is the Freeware version and the Pro version. The freeware version is completely free. The Pro version is 30-day trialware, and after the 30 days some of the more advanced features will be disabled unless you register it
WallpaperSS
Wallpaper Slideshow LT from gPhotoShow.com - "a great utility for displaying your favorite photos as your desktop wallpaper"
Wanadoo Messenger.exe
Wanadoo ISP instant messenger client
wanman.exe
Added by the RBOT.HDO WORM!
WanMPSvc
An AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling AOL doesn't help
WAPI
PurityScan/Clickspring adware
War FTPD Tray Icon
War-ftpd - FTP server
war-ftpd.exe
War FTP Daemon from JGAA's Internet - FTP client
Wardo
Added by the ADCLICKER.G TROJAN!
WareOut
Wareout - malware masquerading as a spyware and dialer remover
warez
Warez P2P client
Warner
Also known as "CyberWarner". From G-Tek Technologies and pre-installed on some Packard Bell PCs. Protects critical files
Warnet
Warnet - system cleanup software
Warning: do not remove it!
Part of Folder Password Expert by ZQS Software Team - "a software program to restrict access to the folders that contain your sensitive data"
Warning: do not remove it! (system)
Folder Password Protect - a program that lets you set a password on folders of your choice
WarReg_PopUp
Acer warranty registration popup
WARSVR
"War FTP Daemon - the original free FTP server for windows"
WashAndGo - Cleanup of old Backupfiles
WashAndGo - temp file cleaner
Washer
Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
Washerie.exe
Cookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer, specific for cleaning the IE cache and cookies. Available via Start -> Programs
washindex
Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
Wast
Grokster ads updater
Watch
Found to be used by a Trust USB scanner for auto starting the scanning software when the lid is lifted
Watch
Button press monitor for the Mustek 1200 UB Scanner
Watch Dog Program
For Compaq PC's. Associated with Compaq's internet services. Not required if you don't use services provided by them and may not be required even if you do
Watchdog
Definitely part of the Mustek scanner drivers and software (for 600 III EP Plus and maybe others), launches from the Startup folder in the Start Menu, but not required as they give instructions on removing it on their webpage
WatchDog
Part of Motorola "Mobile Phone Tools" v3 - in a "Mobiile Phone Tools" sub-directory of Program Files
WatchDog
Related to an Intervideo program. What does it do and is it required in startup?
WatchWAN
WatchWAN keeps an accurate account of the data that is flowing between your computer and the Internet at any given moment. This readout is presented in both numerical and graphical format, in real time
waumgr
Added by a variant of the IRCBOT TROJAN!
WaveFramer
Part of SafeSpace (from Artificial Dynamics) which "protects computers from Internet malware infection without the need for signature updates or regular maintenance"
WaveTop Launcher
WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
WaveTop Receiver 1
WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
WaveTop Receiver 2
WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
WaveTop Upload Manager
WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
WAWifiMessage
"HP Wireless Assistant is a user application that provides a method for controlling the enablement of individual wireless devices (such as Bluetooth or WLAN devices) and that shows the state of the radios for these wireless devices"
Wbcmgr
Added by a variant of the IRCBOT BACKDOOR! See here
wben
Appears to be related to Desktop Notifier from Starfield Technologies. What does it do and is it required?
Wbiff
Wbiff! E-mail checker - automatically checks your e-mail and notifies you if any new e-mail has been received
wblogon
Added by the AGENT-HFI TROJAN!
Wbutton
Turns on and off the integrated WiFi on Acer (and other laptops)
WCESCOMM
Active sync for use with Windows CE based palm PC
WCESMngr
Added by the AGOBOT-QZ WORM!
WCESMngr
Added by the AGOBOT-QX WORM!
WCheckUp
Barok keylogger and password stealer
wcmdmgr
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
wcmdmgr.exe
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
wcmdmgrl
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
WCOLOREAL
Makes colours sharper and brighter, but will only work with coloreal capable monitors
WCPC
??
WCPI
PurityScan/Clickspring adware
WCPS
PurityScan/Clickspring adware
WCPT
PurityScan/Clickspring adware
wcsys
Added by the KEYLOG-AP TROJAN!
WD Backup Monitor
WD Backup - customized version of ArcSoft's TotalMedia Backup for Western Digital external drives (see here)
WD Button Manager
Button manager installed with a western digital external disk drive. Allows you to back up your system with one click
WD Spindown Utility
Spindown utility "for use with all Western Digital external hard drives except for the Media Center and the Dual-option Backup drives. It is designed to give greater user control over the spindown of the external drive"
wdfmgr32.exe
Added by the DWNLDR-FVL TROJAN!
WDInfo
Added by the DLUCA.B TROJAN!
wdmon
Detected as the BUZUS.DVE TROJAN!
WDNS SYSTEM
Added by the MYTOB-BY WORM!
WDNS SYSTEM
Added by the MYTOB-BY WORM!
WDNS SYSTEM
Added by the MYTOB-BY WORM!
wdskctl
IEPlugin spyware
wdwctrl
Added by the DLUCA.E TROJAN!
WD_SRT
Western Digital USB disk driver
WEATHER
Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs
Weather Pulse
Weather Pulse from Tropic Designs. "Display popular Satellite images and video from around the globe, share images with your friends and family, stay updated on current and expected weather conditions, it's just plain fun!"
WeatherCast
Weather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight
WeatherEye
WeatherEye - desktop weather from TheWeatherNetwork
WeatherOnTray
Hotbar adware
WeatherOnTray
Hotbar adware
Weatherscope
WeatherScope - "displays your current local temperature in the system tray of your computer (near the clock) whenever you are online!" Not recommended as it bundles GAIN adware. You can get the adware free version for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here
WeatherStudio Desktop
WeatherStudio adware
WeatherWatcher
WeatherWatcher - weather reporting in the System Tray
web
Added by a variant of the EASTO.A TROJAN!
WEB DRIVERS FOR WIN32
Added by a variant of the RBOT WORM!
Web Offer
eZula TopText adware
Web Offer
eZula TopText adware
Web Offer
eZula TopText adware
Web Offer
eZula TopText adware
Web Search
??
Web Service
Added by the ADMINCASH TROJAN!
Web Service
Added by the BUBE-F VIRUS!
Web Service
CoolWebSearch parasite variant, identified by Kaspersky as TrojanDropper.Win32.Small.cw
Web2Pop
Web2Pop allows you to retrieve your web-based accounts messages to read them in your favorite e-mail client
web3trap
PC-Cillin 2000 anti-virus software → ActiveX filter. Guards against malicious ActiveX programs, etc
webalize
Searchcentrix hijacker
WebArmyKnife
Web Army Knife - a suite of web site developer's tools
webassist
Adware popup generator
WebBuying
WebBuying adware
WebCallDirect
WebCallDirect - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype
webcam
Added by the MONAD-A TROJAN! Note - this malware actually changes the default value data of the Registry Run and RunServices keys in order to force Windows to launch it at boot. Name field may be empty
Webcam Go Sti Service Application
Control software for the portable Creative Webcam Go digital camera/PC web cam. What does it do and is it required?
WebcamRT.exe
For Logitech Web Cams. Not required - camera works fine without it
Webcelerator
Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Now no longer available and supported and when available was classed as spyware - see here
WebCheck
Added by the CONE.C or CONE.F WORMS!
WebCpr0
WebRebates adware
Webdav.exe
IRC DDoS bot which gives the hacker full control over your system
WebExRemoteAccessAgent
Related to Web Meetings from WebEx Communications, Inc. Share and present online with anyone, anywhere
WebHancer Agent
System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here
webHancer Survey Companion
WebHancertrackware - traffic measurement service that uses a client agent that is stealth installed on user machines, gathering detailed data about sites visited, their performance and, most important, what the user actually does while there
WebInstall
ClipGenie adware downloader
WebInstall2
ClipGenie adware downloader
WebKey
WebKey from JB Utilities. Utility to keep track of login data required when browsing the internet
WebLink
Softex is a "cost-effective way to provide software updates, technical support or new product information to specific end-users - it can silently provide end-users with software updates, technical support and new product information customized to their specific needs through a persistent link"
WebOutfitterTray
Intel WebOutfitter service System Tray icon
Webposition Gold 2
Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines
WebRebates0
WebRebates adware
Webroot Desktop Firewall
Webroot Desktop Firewall
WebRun
Added by the ADWARELOADER TROJAN!
websaverlive
WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your computer is idle
WebSavingsfromEbates
Web Savings From Ebates Software, a shopping tool that opens pop-up windows
WebSavingsFromEbates0
Web Savings From Ebates Software, a shopping tool that opens pop-up windows
WebScan
eAcceleration Stop-Sign security software related. Previously not recommended, see here
webscan
eAcceleration Stop-Sign security software related. Previously not recommended, see here
WebScanX
From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc
websearch
"Web Savings" From Ebates Software, a shopping tool that opens pop-up windows
WebSecureAlert
WebSecureAlert - "helps to protect your browser security by monitoring for unauthorized tampering with Internet Explorer's security settings, and can help to protect your privacy by deleting your web surfing history on a regular basis". Not recommended as it bundles GAIN adware. You can get the adware free version for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here
WebServer
Related to a Pinnacle sound card. What does it do and is it needed?
Webshots
Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web
Webshots
Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web
Webshots
Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web
Webshots
Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web
Website Administrator Info
Added by the FORBOT-FY WORM!
WebSpecials
WebSpecials spyware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
WebSUpdater
Detected by Kaspersky as the STARTPAGE.C TROJAN! See here
Websx
Adult content dialler - where ***** are random
Webtrap
Part of PC-Cillin anti-virus software. Checks web-sites for malicious Java and ActiveX elements in a similar way to McAfee WebScanX. A few users find it infuriating
WebTrapNT.exe
Part of PC-Cillin Anti-Virus software. Checks visited web-sites for malicious Java and ActiveX elements
WebWasher
Free Pop-up/ad/javascript filter program from Siemens. If not running then browsers will not be protected but will still work. Available via Start -> Programs
WeirdOnTheWeb
Added by the WeirdOnTheWeb adware
Welcome
Launches the Welcome to Windows tutorial on boot up
WEPstat
Cisco Aironet 340 Series PC Card driver. If it can be started manually it shouldn't be required if you don't use the PC card facility regularily - hence the status could be "U". Can anybody confirm this?
wersds
Added by the JECT.C TROJAN!
wersds.exe
Added by the BAGLEDI-A TROJAN!
wescmv
Added by a variant of the SLAPER TROJAN!
wesumu
Added by the QQPASS-L TROJAN!
WetSock
RoboMagic Wetsock - weather reporting in the System Tray
wextract_cleanup0
Wextract Cleanup0 is valid and legal software included or sold to help clean up temporary or cab files created by the installer software for a wide variety of software. It should disapear after a restart of the system. If not fix it
WFGStartup
World Weather. "This midlet displays the current weather conditions for major cities around the world. This version is for memory limited mobile phones"
wfips
ICQ (messaging/chat program) anti-bomb software. "WFIPS is anti-bomb software for safeguarding ICQ Bomb before the bombing. 'ICQ Defoolder' is a tool for removing ICQ bomb after being exposed." For more information about ICQ bombs see here
WFXCTL32.EXE
From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
wfxsnt40
WinFax 10.0 and maybe earlier versions. The program that opens the port for WinFax and not normally in the start menu. Needed if you want to run WinFax
WFXSwtch
Related to WinFax. What does it do and is it required?
WG111v2 Smart Wizard Wireless Setting
Configuration utility for the Netgear WG111 54 Mbps Wireless USB 2.0 Adapter that "provides wireless access to your desktop or notebook PC through the computer's USB port"
WG511WLU
Netgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card
wgeax
Added by the IRCBOT-TM WORM!
wgs3
Added by the LEGMIR-AQH TROJAN!
WGV
Added by the ZIPPIE TROJAN!
WGWLocalManager
Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so. It could be started by creating a shortcut, running it only when connecting to the internet. If internet is used often, it's recommended to leave it in startup so it starts with the system
WgwMngr
Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so
whagent
System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here
What Frenz
Added by the BHARAT.A WORM!
WhatPulse
WhatPulse keeps track of your keystrokes, allowing you to find out just how much you type a day
WheelMouse
Mouse software for "Fellowes" Wheelman mouse. Has caused some users problems but shouldn't be needed if you don't use any enhanced features it may provide
WheelMouse
A4Tech wireless mouse driver and utility - required if you use non-standard Windows driver features
WheelsMouse
Added by the SOCKSPR-D TROJAN!
WhenUSave
WhenU.Save adware
WhenUSearch
WhenU.Save adware
WhenUSearchWHSE
WhenU.Save adware
Whistler
Added by the WHISTLER-F TROJAN!
Whitechix
Added by a variant of the SDBOT WORM!
Whvlxd
Added by the ZAPCHAS-CS TROJAN!
whxpin service
Added by a variant of the SDBOT WORM!
wiascr
Added by the AGENT.AM TROJAN! Note - example names include "XviD", "Winamp Remote", "Windows Media Player" and "Futuremark"
WIAWizardMenu
Still Image Class Installer - installed with a webcam
Widnows Xp Web scan
Added by a variant of the SDBOT WORM!
wifeman
Unidentified malware
Wifi Boot
Added by a variant of the IRCBOT TROJAN! See here
Wifi Booter
Detected by Trend Micro as the IRCBOT.GP TROJAN! See here
Wifi Configuration
Added by the CHECKOUT WORM! See here
Wifi Configuration!
Added by the CHECKOUT WORM! See here
Wifi Connection
Detected by Trend Micro as the SLENFBOT.AC TROJAN! See here
Wifi Connection!
Added by the CHECKOUT WORM! See here
Wifi Debug
Added by a variant of the IRCBOT TROJAN! See here
Wifi Loader
Detected by Trend Micro as the IRCBOT.AVG TROJAN! See here
Wifi Loader!
Added by a variant of the IRCBOT TROJAN! See here
Wifi Setup
Added by a variant of the IRCBOT TROJAN! See here
WiFix service
Added by a variant of the SDBOT WORM!
WildFlics
Direct-B premium rate adult content dialler
WildTangent CDA
Part of the WildTangent on-line games system. What does it do and is it required?
WildTangent Web Driver updater
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
Wildwire Monitor
This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem
Willow Road
Willow Road Screen Saver
WillPolo
Added by the VBS_SOLOW.AF VIRUS!
win
Added by the SEEKER.K TROJAN!
win
Added by the AGOBOT-MV WORM!
win
Added by the AGOBOT-MV WORM!
WIN
Added by the MYTOB-CQ WORM!
WIN
Added by the REATLE.C WORM!
win
Related to the Sentry Parental Controls software
Win Antivir 2008
Win Antivir 2008 rogue security software - not recommended, see here
Win Antivirus 2008
Win Antivirus 2008 rogue security software - not recommended, see here
Win Chimes
WinChimes - enhancement software for the system clock that runs in the system tray
Win Comm
Added by the WINCOM TROJAN!
Win Command
Added by the AGOBOT.XQ WORM!
Win Config
Added by a variant of the IRCBOT BACKDOOR! See here
Win CPU
Added by the RBOT-AXL WORM!
win ctl app
Added by a variant of the SDBOT WORM!
Win Defrag
Added by a variant of the SDBOT WORM! See here
Win Defrag!
Added by a variant of the SDBOT WORM! See here
Win Defrags
Added by a variant of the IRCBOT TROJAN! See here
Win Drivers SSL
Added by the IRCBOT.67098 WORM!
Win Drivers SSL
Added by a variant of the RBOT WORM!
Win Drivers SSL32
Added by the SPYBOT.MAR WORM!
WIN HOST PROCESS
Added by the KEYLOGGER.CLONE TROJAN!
Win INI 32
Added by the RBOT-FZC WORM!
Win l5oahder
Added by a variant of the RBOT WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of the Program Files directory
Win Login
Added by the RBOT-AWE WORM! Note - this trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder
Win Microsoft 98
Added by the RBOT-AKX WORM!
win name
??
Win Net Wks32
Added by the RBOT.AA WORM!
Win Patch
Added by the SDBOT-GS WORM!
Win Process Updates
Added by a variant of the SDBOT WORM!
Win Prosess0r
Added by the RBOT-BIT WORM!
WIN prosessor16
Added by a variant of the SDBOT WORM!
Win Proxy32 Protocol
Added by a variant of the SDBOT WORM!
Win Secure Update
Added by the RBOT-AGI WORM!
Win Security
Added by the RBOT-AQT WORM!
Win Security
Detected by Trend Micro as the IRCBOT.AVE BACKDOOR! See here
Win Server
Added by the IMISERV.A TROJAN!
Win Server Updt
Added by the IMISERV.A TROJAN!
Win Server Updt
Added by a variant of the IMISERV TROJAN!
Win Server Updt
IEPlugin adware
Win Sync montr
Detected by Kaspersky as the RBOT.BYJ TROJAN! See here
Win TaskLoader
Added by the MYTOB.L WORM!
win update
Added by the SDBOT.J WORM!
win update
Added by a variant of the RBOT WORM!
Win Update
Added by the AGOBOT-TN WORM!
Win Update
Added by the AGENT-UY TROJAN!
Win Update
Added by the RBOT-GDP WORM!
Win Updater
Added by the RBOT.IP WORM!
Win Updator Services
Added by a variant of the WOOTBOT WORM!
WIN USB 2.0
Added by an unidentified WORM of TROJAN!
WIN USB 2.0
Added by a variant of the RBOT WORM!
Win USB 2.0 USB Driver
Added by the SPYBOT.DNB WORM!
WIN USB SUPPORT
Added by a variant of the RBOT WORM!
Win Validation Application
Added by the VBSILLY-A WORM!
Win WinAmp
Added by the RBOT.AGF WORM! Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of the Program Files directory. This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
win************* [* = random digit]
WINBO adware
WIN-BUGSFIX
Added by the LOVELETTER (I LOVE YOU) VIRUS!
win-xp
Added by the BROPIA.N WORM!
win-xp
Added by the BROPIA.N WORM!
win.exe
Added by the PODROP-C TROJAN!
win16.dll
Screenspy captures screenshots silently. If you didn't install this yourself, remove it
win23.exe
Detected by Kaspersky as the BIFROSE.BSJ TROJAN! See here
Win2Drv
Added by the WINTOO WORM!
WIN32
Added by the RATEGA TROJAN!
win32
Added by the MYLIFE.N WORM!
win32
Added by the EVILBOT.B TROJAN!
Win32
Added by the ISRAZ.A WORM!
win32
Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites
win32
Added by the EVILBOT.B TROJAN!
Win32
Added by the SWERUN VIRUS!
Win32
Added by the SCAFENE WORM!
Win32
Added by the SPAZBOX.A TROJAN!
win32
Added by the BROPIA.J WORM!
Win32
Added by a variant of the SDBOT WORM!
Win32
Added by a variant of the SDBOT WORM!
Win32
Added by the MYTOB-HQ TROJAN!
Win32
Added by the RBOT-GCE WORM!
Win32 Bios
Added by the SEMAPI-A WORM!
Win32 Configuration
Added by the SDBOT.TT WORM!
Win32 Configuration
Added by the SDBOT.UL WORM!
Win32 Configuration
Added by the FORBOT-BZ WORM!
Win32 Critical File
Added by the RBOT-GUB WORM!
WIN32 DDOSSER
Added by the KELVIR.F WORM!
Win32 Debug Manager
Added by a variant of the WOOTBOT WORM!
Win32 Debug Manager
Added by a variant of the WOOTBOT WORM!
Win32 Device Loader
Added by a variant of the AGOBOT/GAOBOT WORM!
Win32 Driver
Added by the FORBOT-FD WORM!
Win32 Drivers
Added by the FORBOT-FG WORM!
Win32 DRK Driver
Added by the WOOTBOT.CY WORM!
Win32 exe file
Added by a variant of the SPYBOT WORM!
Win32 Explorer
StartPa-MN homepage hijacker
Win32 Firewall Driver
Added by a variant of the RBOT WORM!
Win32 FireWire Driver
Added by the WOOTBOT TROJAN!
Win32 FRT Driver
Added by a variant of the FORBOT WORM!
Win32 Help32 Service
Added by the DELBOT-U WORM!
Win32 Info
Added by a variant of the IRCBOT TROJAN!
Win32 Information Service
Added by the RINBOT.Y WORM!
win32 internet server
Added by the DERMON-D TROJAN!
Win32 Kernel core component
Added by the MOKS VIRUS!
Win32 Kernel Update
Added by the PROXY-BS TROJAN!
Win32 LSA Driver
Added by the FORBOT-FJ WORM!
Win32 Ms Auto Updater
Added by a variant of the RBOT WORM!
Win32 NDIS
Added by the RBOT.AMG WORM!
Win32 NDIS Driver
Added by a variant of the RBOT WORM!
Win32 NDIS Driver
Added by the WOOTBOT.EU WORM!
Win32 Network Driver
Added by a variant of the AGOBOT/GAOBOT WORM!
Win32 NT Adv Services
Added by the RBOT-ADE WORM!
Win32 nvc
Added by the RBOT-ABF WORM!
Win32 NVIDIA Driver
Added by a variant of the WOOTBOT.Y WORM!
win32 regedit
Added by an unidentified WORM or TROJAN!
Win32 Rundll Loader
Added by the SDBOT.A TROJAN! Note - this is not to be confused with the legitimate rundll32.exe file!
Win32 Secure
Added by a variant of the SDBOT WORM!
Win32 Security Protocol
Added by the RBOT-ETI WORM!
Win32 Security Service
Added by the DELBOT-O WORM!
win32 security updates downloader
Added by a variant of the SDBOT WORM! See here
Win32 Service
Added by the AHKER.E WORM!
Win32 Services
Added by the SPYBOT-EK WORM!
Win32 Services Config
Added by the RBOT.BKY WORM!
Win32 Services1
Added by the SDBOT-PV WORM!
Win32 Src Service
Added by the RBOT-SX WORM!
Win32 SSL Driver
Added by the FORBOT-BH WORM!
Win32 Svchosts Driver
Added by the FORBOT-FO WORM!
Win32 System Kernel
Added by the SDBOT.KIN WORM!
win32 system server
Added by the DERMON-A TROJAN!
Win32 System Spool
Added by the SDBOT.UK WORM!
Win32 Test
Added by a variant of the RBOT WORM!
Win32 Update
Added by a variant of the SDBOT WORM!
Win32 Update
Added by an unidentified WORM or TROJAN!
win32 update service
Added by a variant of the SDBOT WORM!
Win32 USB Driver
Added by the SDBOT.AA TROJAN!
Win32 USB Driver
Added by the FORBOT-BK WORM!
Win32 Usb Driver
Added by the FORBOT-BE or FORBOT-J WORMS!
Win32 Usb Driver
Added by the SDBOT-OV WORM!
Win32 Usb Driver
Added by the FORBOT-BX WORM!
Win32 USB2
Added by a variant of the RBOT WORM!
Win32 USB2 Driver
Added by the SPYBOT.DHV WORM!
Win32 USB2 Driver
Added by the SDBOT.FO WORM!
Win32 USB2 Driver
Added by the FORBOT.J or SDBOT.HU WORM!
Win32 USB2 Driver
Added by the WOOTBOT.X WORM!
Win32 USB2 Driver
Added by the FORBOT-AN WORM!
Win32 USB2 Driver
Added by the FORBOT-AH WORM!
Win32 USB2 Driver
Added by the AGOBOT.YE WORM!
Win32 USB2 Driver
Added by a variant of the FORBOT WORM!
Win32 USB2 Driver
Added by a variant of the SDBOT WORM!
Win32 USB2 Driver
Added by the FORBOT-EX WORM!
Win32 USB2 Driver
Added by the FORBOT-R WORM!
Win32 USB2.0 Driver
Added by the IRCBOT.D WORM!
Win32 USB2.0 Driver
Added by the WOOTBOT.H WORM!
Win32 USB2.0 Driver
Added by the SPYBOT.DN WORM!
Win32 USB2.0 Driver
Added by the SDBOT-QF WORM!
Win32 USB3 Driver
Added by a variant of the RBOT WORM!
Win32 Wmls Driver
Added by the WOOTBOT.B WORM!
Win32 Word Services
Added by a variant of the RBOT WORM!
win32.exe
Added by the STARTPAGE TROJAN!
Win32.exe
Added by the AWQ.A TROJAN!
Win32.Exploit.mzH
Added by the PAINTER TROJAN!
Win32.Trojan.Downloader
Added by the PAINTER TROJAN!
Win32BaseServiceMOD
Added by the NAVIDAD WORM!
win32beta
Added by the BANKER-DA TROJAN!
win32clf
Added by an unidentified VIRUS, WORM or TROJAN!
win32debug
Added by the GUDEB WORM!
Win32DLL
Added by the LOVELETTER (I LOVE YOU) VIRUS!
Win32dll
Added by the BANPAES TROJAN!
WIN32DS
Eziin adware
Win32G
Added by the ESTRELLA TROJAN!
Win32G
Added by the ESTRELLA TROJAN!
win32gb
Added by the DLUCA-F TROJAN!
Win32Host Process
Added by the TURGEN -A TROJAN!
win32info
Adult content dialler
win32ini
Added by the IRC.ALADINZ.C TROJAN!
WIN32io
Eziin adware
win32Kernel
Added by the BANLOA-EY TROJAN!
Win32KernelStart
Added by the DELF-EWZ TROJAN!
Win32R
Added by the ESTRELLA TROJAN!
WIn32S Java DLL
Added by the AGOBOT-RZ WORM!
win32servv
iSearch adware
win32servv
iSearch adware
WIN32SL
Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. The specific function of this is to load MIF's in order for Dell OpenManage Client to work
WIN32SNDS
Added by an unidentified WORM or TROJAN!
Win32system
Added by the DDV.B WORM!
Win32System
Added by the MYDOOM.V WORM!
Win32SystemMonitor
Browser hijacker
Win32SysV
Added by the FORBOT-EO WORM!
win32us
All-In-One-Telcom (adult content dialler) variant
win32usbd
Added by the RBOT-RA WORM!
Win32Usr
Added by the DEDMIR-A WORM!
WIN32WN
Eziin adware
win32_i lptt01
RapidBlaster variant (in a "win32_i" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
win32_i ml097e
RapidBlaster variant (in a "win32_i" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
Win386
Added by the GOSUSUB VIRUS!
Win386
Homepage hijacker. Not a dll but a regfile in disguise
WIN3S2SNDS
Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well"
WIN3S2SNDS
Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well"
Win64 Compatibility Check
CoolWebSearch parasite variant
WIN95DEFVIEW
Added by the DEDLER-D TROJAN!
WIN95DEFVIEW
Added by the DEDLER-D TROJAN!
win98 DNS
Added by a variant of the RBOT WORM!
winabc
Added by the LINEAGE-PN TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
WinAble
Added by the MATCASH.BG TROJAN!
WinAC v4
Added by the FORBOT-CS WORM!
Winacsr
AceScreenSpy keystroke logger/monitoring program - remove unless you installed it yourself!
winactive
WinActive of the LOP.com hijacker
WinActiveJ
Added by the ROTARRAN VIRUS!
Winad Client
WinAd adware by eXact Advertising
WinAdCnt.exe
Added by the BANKER-BU TROJAN!
winadm
Browser hijacker - redirecting to Search-World.net. Related to the SMALL.AEX TROJAN!
WinAgent
Standard Life Insurance program. Is it required at startup?
Winahlp.exe
Added by a variant of the VAGRNOCKER TROJAN!
winallap
Added by the DELF.E TROJAN!
winallapu
Added by the DELF.E TROJAN!
Winamp
Hijacker - re-directing to adult content sites. Note - this isn't the real Winamp
Winamp
Added by the AGOBOT.XI WORM! Note - this is NOT the popular Winamp media player
WinAMP
Added by the SDBOT-WN WORM!
Winamp
Winamp media player. Resides in a "Winamp" subdirectory of the Program Files directory
Winamp Agent
Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player. The valid filename for the Winamp Agent is "winampa.exe" - see here
Winamp Media
Added by the DIAZMON-A TROJAN!
Winamp media player
Added by an unidentified VIRUS, WORM or TROJAN!
Winamp Media Player
Detected by PCTools as the SDBOT.ACJM BACKDOOR! See here
Winamp Media Player
Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of %ProgramFiles%
WinAmp Player
Added by the RBOT-AQI WORM! Note - this is NOT the popular Winamp media player which has a different filename
Winamp Player 6
Added by a variant of the SPYBOT WORM!
Winamp to Google Talk
Winamp to Google Talk, available here shows your current Winamp track in your Google Talk status
Winamp Update
Added by the SDBOT-ACR WORM!
Winampa
Loads the System Tray icon for the popular Winamp media player - see here. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs. Resides in a "Winamp" subdirectory of the Program Files directory
Winampa
Added by the AGOBOT-GS TROJAN! ! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of the Program Files directory whereas this file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
Winampa Agent
Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player. The valid filename for the Winamp Agent is "winampa.exe" - see here
WinampAgent
Loads the System Tray icon for the popular Winamp media player - see here. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs. Resides in a "Winamp" subdirectory of the Program Files directory
WinAmpAgent
Added by the EB TROJAN! Note - this is NOT the popular Winamp media player which has a different filename
WinAmpAgent
Added by the EB TROJAN! Note - this is NOT the popular Winamp media player which has a different filename
WinAmpAgent
Added by the EB TROJAN! Note - this is NOT the popular Winamp media player which has a different filename
WinAmpAgent
Added by the EB TROJAN! Note - this is NOT the popular Winamp media player which has a different filename
WinAmpAgent
Added by the TACTSLAY.B TROJAN!
WinAmpAgent
Added by the TACTSLAY.B TROJAN!
WinAnonymous
WinAnonymous spyware remover - not recommended, see here
WinAntiSpyware 2005
WinAntiSpyware 2005 spyware remover - not recommended, see here
WinAntiSpyware 2007
WinAntiSpyware 2007 spyware remover - not recommended, see here
WinAntispyware2008
WinAntispyware2008 rogue spyware remover - not recommeded, see here
WinAntiVirus Pro 2007
WinAntiVirus Pro 2007 misleading virus software - not recommended, see here
WinApi
Added by a variant of the TIBSER.A downloader TROJAN!
WINAPLOGUPD
Added by the CAPSIDE-C WORM!
Winapp
Produces popup ads to adult content sites
WinApp32
Added by the RSBOT TROJAN!
WinAppLog
StingKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the svchost.exe process that normally doesn't appear in Msconfig/Startup!
WinAuth
Hijacker, also indentified as the STRTPAGE.BE TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
WinAVX
Added by the FAKEAVALERT TROJAN!
WinAvX
WinAntiSpyware spyware remover - not recommended, see here
WinAwk
Added by the SDBOT-AYF WORM!
WinBackup Scheduler
LIUtilities WinBackup scheduler - backup software
WinBar
"WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls"
winbar.pif
Added by the RBOT-AVI WORM!
Winbed
Hijacker
Winbin
Added by the RBOT.CLS WORM!
winbin32
Added by the RBOT-ZL WORM!
winbo32
Added by the RBOT-GRU WORM!
winboot
Added by the BANLOAD-W TROJAN!
winbot
Added by the MIDRUG-A TROJAN!
WinBrush
WinBrush - "handy tool that keep your privacy and make your system clean. It works by cleaning up your tracks (document histories, recent opened files from popular software, cookies, temporary internet files, etc)"
WinButler
Identified as a variant of the Trojan-Dropper.Agent.DKN malware
WinCheck
Added by the SOBER-S WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "ConnectionStatusMicrosoft" subfolder of the Windows or Winnt folder
WinCheck
Added by the PWS-CY TROJAN!
WinCheck
Added by the SOBER.S WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "ConnectionStatusMicrosoft" subfolder of the Windows or Winnt folder
WinCheck
Added by the DELBOT-Y WORM!
winchost
Added by the DLOADER-PO TROJAN!
WINCINEMAMGR
WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
WinCinemaMgr
WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
WINCINEMAMGR
InterVideo WinCinema Manager - needed for the use of WinDVD Remote Control
winclean
Added by the AGENT.GXR TROJAN!
wincls
Added by the AKBOT-AR WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wincls.dll" file is found in %System%
wincmap
CasClient adware variant - also detected as the CMAPP TROJAN!
WinColorReminder
The Microsoft Color Control Panel Applet for Windows XP "helps you manage Windows color settings in one place." Part of the Pro Imaging Powertoys
WinCore32.exe
Added by the CLICKER-EN TROJAN!
wincrt.exe
Added by the STRATIO-HA WORM!
WinCRT32
Added by the DOGBOT-D WORM!
WinCSRSS
Added by the REWINDO-A TROJAN!
winctl
Added by the IRCBOT-YI TROJAN!
WINCX
Added by the AGOBOT-MG WORM!
Wind Logd File
Added by a variant of the RBOT WORM!
Wind Security
Added by the RBOT-ARH WORM!
wind.exe
Added by the MITGLIEDER.BD TROJAN!
WIND0WS
Added by the SPYBOT.DQ WORM!
WIND0WS
Added by the ALLEM WORM!
Wind0ws
Added by the AGOBOT-TL WORM! Note - this is not the legitimate Windows application wordpad.exe (which is found in the Program FilesAccessories folder) which should not normally be seen in Msconfig or as a Startup item. This file is loacted in the System (9x/Me) or System32 (NT/2K/XP) folder
Wind0ws Ser7ice Agent
Added by the RBOT-GQO TROJAN!
Wind0ws Sharing
Added by the RBOT-AHW WORM!
Wind32
Identified as a variant of the Backdoor.Win32.Poison.avs malware
WinData
Added by the SOBER.AA WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "PoolData" subfolder of the Windows or Winnt folder
WinDates
WinDates is a calendar, date organizer and event reminder program from Rockin' Software
windbs
Added by the AGOBOT-WD WORM!
Winde
Added by the DLUCA TROJAN!
windef
Added by the ANPES WORM!
windef
Added by the WURMARK-O WORM!
windefender
Added by the AGENT.BYH TROJAN!
Windeows NetStart Service2
Added by the RBOT-AMY WORM!
windhost.exe
Added by the BANKER-CB TROJAN!
windhost.exe
Added by the BANKER-BV TROJAN!
windhost.exe
Added by the PWSAGENT-A WORM!
windir
Added by the WINBUR.B WORM!
Windir Working
Added by a variant of the IRCBOT TROJAN!
Windll
Added by the TRYNOMA TROJAN!
WINDLL
STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes, all passwords transacted even if they weren't keyed in, all web sites visited, every program launched including the path to that program, and more"
windll
Added by the ASTEF or RESPAN WORMS!
WinDLL (algs.exe)
Detected by Kaspersky as the AKBOT.E BACKDOOR! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "algs.exe" file is found in %System%
WinDLL (aqls32.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "aqls32.exe" file is found in %System%
WinDLL (asdfsa.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "aqls32.exe" file is found in %System%
WinDLL (bee.dll)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "bee.dll" file is found in %System%
WinDLL (bix.exe)
Detected by Kaspersky as the KOLAB.OL WORM! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "bix.exe" file is found in %System%
WinDLL (csmss.exe)
Added by the AKBOT.U WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "CSMSS.EXE" file is found in %System%
WinDLL (ctfmonm.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ctfmonm.exe" file is found in %System%
WinDLL (dasda.com)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "dasda.com" file is found in %System%
WinDLL (diem.exe)
Added by the AKBOT.E WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "diem.exe" file is found in %System%
WinDLL (dlfksdld.exe)
Detected by Kaspersky as the IRCBOT.BPM TROJAN! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "dlfksdld.exe" file is found in %System%
WinDLL (jbi32.dll)
Added by the AKBOT.E WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "jbi32.dll" file is found in %System%
WinDLL (lcass.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "lcass.exe" file is found in %System%
WinDLL (mysnlive.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "mysnlive.exe" file is found in %System%
WinDLL (ProsFix.exe)
Added by a variant of the IRCBOT BACKDOOR! The "ProsFix.exe" file is found in %System%
WinDLL (qwex.dll)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "qwex.dll" file is found in %System%
WinDLL (redyLive.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "redyLive.exe" file is found in %System%
WinDLL (scvhost32.dll)
Added by the AKBOT.M WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "scvhost32.dll" file is found in %System%
WinDLL (service.exe)
Detected by Kaspersky as the AGENT.BX WORM! See here. The "service.exe" file is found in %System%
WinDLL (slmss.exe)
Added by the AKBOT.AW WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "slmss.exe" file is found in %System%
WinDLL (slsass.exe)
Detected by Kaspersky as the AKBOT.E TROJAN! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "slsass.exe" file is found in %System%
WinDLL (smaprnter.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "redyLive.exe" file is found in %System%
WinDll (sslms.exe)
Added by the AKBOT-AS WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "sslms.exe" file is found in %System%
WinDLL (start0s.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "start0s.exe" file is found in %System%
WinDLL (steam.dll)
Added by the AKBOT.M WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "steam.dll" file is found in %System%
WinDLL (svc.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "svc.exe" file is found in %System%
WinDLL (svchost.dll)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "svchost.dll" file is found in %System%
WinDLL (sysx32.dll)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "sysx32.dll" file is found in %System%
WinDLL (tepmlayer.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tepmlayer.exe" file is found in %System%
WinDLL (tmp.exe)
Detected by Kaspersky as the KOLAB.L WORM! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tmp.exe" file is found in %System%
WinDLL (tock24.dll)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tock24.dll" file is found in %System%
WinDLL (tqurity.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tqurity.exe" file is found in %System%
WinDLL (v4mon.dll)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "v4mon.dll" file is found in %System%
WinDLL (vdm32.dll)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "vdm32.dll" file is found in %System%
WinDLL (vxd32.dll)
Added by the AKBOT.R WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "vxd32.dll" file is found in %System%
WinDLL (wchshield.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wchshield.exe" file is found in %System%
WinDLL (wimimi.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wimimi.exe" file is found in %System%
WinDLL (windns32.dll)
Detected by Kaspersky as the AKBOT.E WORM! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tmp.exe" file is found in %System%
WinDLL (wingatey32.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wingatey32.exe" file is found in %System%
WinDLL (wintmp.exe)
Detected by Kaspersky as the AKBOT.E BACKDOOR! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wintmp.exe" file is found in %System%
WinDLL (wsync32.dll)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wsync32.dll" file is found in %System%
WinDLL (xvd32.dll)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "xvd32.dll" file is found in %System%
Windll.exe
Added by the STEALER TROJAN!
Windll32
Added by the MSNPWS TROJAN!
WinDll32
Added by the LEGMIR.AQ TROJAN!
windllsys32.exe
Added by a variant of the MITGLIE-A TROJAN!
WinDNS
Added by the GAOBOT.WX WORM!
Windo Servic Agen
Added by a variant of the IRCBOT BACKDOOR!
Windo Servic Agent 32
Added by a variant of the IRCBOT BACKDOOR!
Windoes Kernel
Added by the KICKIN.A (or CYDOG.C) WORM!
Windos Seres Agnts
Added by the RBOT-GUN WORM!
Window
Added by the GAOBOT.ADW WORM!
Window Loader
Added by the GAOBOT.AO WORM!
Window Monitor
Added by the SDBOT.RT WORM!
Window Msn Live Messanger
Detected by Kaspersky as the RBOT.BJD WORM! See here
Window service
Added by the RBOT-ACH WORM!
Window upadate
Added by a variant of the RBOT WORM!
Window Washer
Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
window.exe
Added by the MITGLIEDER.H or MITGLIEDER.J TROJANS!
window2
Added by the IRCBOT.H TROJAN!
WindowBlinds
WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins
WindowEnhancer
SCBar foistware variant
Windowfdgfds DasdLL Verifier
Detected by Trend Micro as the AGOBOT.HZ WORM! See here
Windowfdgfds DasdLL Verifiew
Added by the RBOT-GGX WORM!
Windowfdgfds DLL fgfdg Verifier
Added by the RBOT.CSP WORM!
Windowfdgfds DLL fgfdg Verifier
Added by a variant of the RBOT WORM!
WindowFX
Stardock WindowFX - "Allows you to add an unprecedented number of special effects to windows"
windown
Added by the QQPASS-M TROJAN!
WindowRegKey update
Added by the SPYBOT.I WORM!
Windows
Added by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "WinSecurity" subfolder of the Windows or Winnt folder
Windows
Added by the TENDOOLF.A WORM!
Windows
Added by the PWSTEAL TROJAN!
Windows
Added by the KAZMOR.A, BOBBINS & ALADINZ.D TROJANS!
Windows
Added by the POEBOT-J WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
windows
Added by the AIMWIN TROJAN!
windows
Added by the GAOBOT.AFW WORM!
windows
Added by the SALGA.A WORM!
Windows
Added by the STUBBOT-B TROJAN!
Windows
Added by the SPYBOT.OFN WORM!
Windows
Added by the SPYBOT.OBB WORM!
WINDOWS
Added by the MONBOT-A TROJAN!
Windows
Added by the SOBER-Z WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! ! This file is located in a "WinSecurity" subfolder of the Windows or Winnt folder
WINDOWS
Added by the MYTOB.MK WORM!
windows
Added by the RBOT-UM WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%
Windows
Added by the DLOADR-GW TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "Windows" subfolder
Windows
Added by the BANCBAN-QF TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
windows
Added by the SLOMIRC-A WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
WINDOWS
Added by the PS TROJAN! Note - deactivates the MicrosoftInternet Connection Firewall (ICF)
Windows
Added by a variant of the SDBOT WORM!
Windows
Added by the CULLER-C WORM!
Windows
Added by the CULLER-D WORM!
Windows
Added by an unidentified WORM or TROJAN! See here
Windows & Internet Cleaner Pro
Windows & Internet Cleaner Pro - "Powerful and easy to use internet surfing privacy protection & PC security software"
Windows (ICS) Spooler
Added by a variant of the RBOT WORM!
Windows (random character)
Added by the SINGU.B TROJAN!
Windows .Net Manager
Added by the DLOADER-NY TROJAN!
Windows .Net Manager
Added by the DLOADER-NY TROJAN!
Windows .Net Manager
Added by the DLOADER-NY TROJAN!
Windows .Net Manager
Added by the DLOADER-NY TROJAN!
Windows .Net Manager
Added by the DLOADER-NY TROJAN!
Windows .Net Manager
Added by the DLOADER-NY TROJAN!
Windows .Net Manager
Added by the DLOADER-NY TROJAN!
Windows .Net Manager
Added by the DLOADER-NY TROJAN!
Windows 128 Module
Added by the FORBOT-ES WORM!
Windows 2004
Added by the BANKER-DY TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Arquivos de programas\Windows 2004\Tools
Windows 32 Editor
Added by the WOOTBOT.GQ WORM!
Windows 32 Rescue
Added by the FORBOT-EU WORM!
Windows 32 Update
Added by a variant of the RBOT WORM!
Windows 32-bit DLL Integrity Verifier
Added by Remote Storm - a remote control tool that is a network application that allows users to manage and control PCs or networks from a remote location
Windows Accelerators
KeySpy keystroke logger/monitoring program - remove unless you installed it yourself!
Windows Account Alternation
Added by a variant of the IRCBOT TROJAN! See here
Windows Acer Service
Detected by PCTools as the IRCBOT.YFQ BACKDOOR! See here
Windows Action
Added by the SECCMU-A WORM!
Windows Activate System
Added by a variant of the SPYBOT WORM!
Windows AdControl
Windupdates adware variant
Windows AdService
Windupdates adware variant
Windows AdStatus
Added by the BLESHARE!DR VIRUS!
Windows AdTools
Windupdates adware variant
Windows Anti Verifier
Added by the RBOT.ETT WORM!
Windows Anti Virus Control Center
Added by a variant of the IRCBOT BACKDOOR!
Windows Anti Virus Control Center
Added by a variant of the IRCBOT BACKDOOR!
Windows Anti-Virus Built 32
Added by the SDBOT-BG WORM!
Windows APCI Verifier
Added by the RBOT-FON WORM! Note - Disables the automatic startup of other software and deactivates the Microsoft Internet Connection Firewall (ICF)
Windows API Control Task
Added by the MYTOB.HI WORM!
Windows Application Layer
Added by the AGOBOT.ATN WORM!
Windows Application Layer Gateway
Added by the AGOBOT-AAZ WORM!
Windows ARP Detectionc
Detected by Kaspersky as the AGENT.LMW BACKDOOR! See here
Windows ARP Detectionc
Detected by Trend Micro as the RBOT.EAB WORM! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
Windows ARP Detectioncx
Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!
Windows ASN Service
Added by the RBOT-AOK WORM!
Windows ASN Service
Added by the AGOBOT-TC WORM!
Windows Audio Components
Added by a variant of the IRCBOT TROJAN! See here
Windows Audio Control
Added by the HAM TROJAN!
Windows Audio Layer
Detected by Trend Micro as the IRCBOT.AFT TROJAN! See here
Windows Audio Panel
Added by a variant of the IRCBOT TROJAN! See here
Windows Audio Startup
Added by the IRCBOT-AAE TROJAN!
Windows Audio System
Added by a variant of the IRCBOT TROJAN! See here
Windows Authority Service
Added by the KALEL-E WORM! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!
windows auto update
Added by the BLASTER.B WORM!
windows auto update
Added by the BLASTER (or MSBLAST.A) WORM!
Windows Auto Update
Added by the SDBOT.TF WORM!
Windows auto update
Added by the AHKER.E WORM!
Windows auto update
Added by the AHKER.G WORM! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup!
Windows Auto Updater
Added by the SDBOT.PB WORM! Note that there is a space at the beginning of the filename, ie, " WINDOWSUPDATE.EXE"
Windows Automatic Update
Added by a variant of the RBOT WORM!
Windows Automatic Updater
Added by a variant of the RBOT WORM!
Windows Automatic Updates
Added by the RBOT.MF WORM!
Windows Automatical Updater
Added by the RBOT.CXS WORM!
Windows AutomaticUpdater
Added by a variant of the RBOT WORM!
windows automation
Added by the BLASTER.E WORM!
Windows Automation
Added by the SOLAME.A WORM!
Windows Autostart Loader
Added by a variant of the RBOT WORM!
Windows Ba?lang?? Dosyas?
Added by the MUZK WORM!
Windows backup
Added by a variant of the SPYBOT WORM!
Windows Backup Configuration
Added by the GAOBOT.AZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)
Windows Boot
Detected by Trend Micro as the AGENT.HBD TROJAN! See here
Windows Boot
Added by a variant of the IRCBOT TROJAN! See here
Windows Booter
Added by a variant of the IRCBOT TROJAN!
Windows Booter!
Added by a variant of the IRCBOT TROJAN! See here
Windows Bootup
Added by the RBOT-AFM WORM!
Windows Bootup
Added by a variant of the RBOT WORM!
Windows Bootup
Added by the RBOT-AWP WORM!
Windows Browser Services
Added by a variant of the IRCBOT TROJAN! See here
Windows Browser Services
Added by a variant of the IRCBOT TROJAN! See here
Windows Browser Services
Added by a variant of the IRCBOT TROJAN! See here
Windows Browser Services
Detected by Kaspersky as the IRCBOT.BUR TROJAN! See here
Windows Browser Services
Added by a variant of the IRCBOT TROJAN! See here
Windows bypass security SMSS Service
Added by the RBOT-GRF WORM!
Windows Clean-Up Pro
Windows Clean-Up Pro spyware remover - not recommended, see here
Windows Cleaner Service
Added by a variant of the IRCBOT TROJAN! See here
Windows Client Service 32
Added by the RBOT-ALB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a drivers&92;winsdriver subfolder
Windows Client/Server Runtime Server
Added by the RBOT.KD WORM!
Windows CODE Fix Msy Startups
Added by the AGOBOT.AKK WORM!
Windows Command
Added by the RBOT.ANV WORM!
Windows Communicator
Added by the AGOBOT-BH WORM!
Windows Communicator for NT/XP
Added by the SDBOT-CPK WORM! Note - can terminate AV related processes
Windows Compliant
Added by the RBOT-IR WORM!
Windows Computer Browser
Added by a variant of the IRCBOT TROJAN! See here
Windows Conf
Added by a variant of the IRCBOT TROJAN! See here
Windows Config
Added by the SPYBOT-DA WORM!
Windows Config
Added by the SPYBOT.JR WORM!
Windows Config
Added by the SPYBOT-DX WORM! Note - this is not the Windows system file of the same name as described here
Windows Config
Added by a variant of the SLAPER TROJAN!
Windows Config
Detected by Trend Micro as the IRCBOT.BAP BACKDOOR! See here
Windows Config Connection
Added by the RBOT-EXQ WORM!
Windows Config Loader
Added by the SILVERFTP TROJAN!
Windows Config Manager
Added by the RBOT-AIT WORM!
Windows Config System
Added by a variant of the SDBOT WORM!
Windows Configuration
Added by the GAOBOT.FB WORM!
Windows Configuration
Added by the MYTOB.ED WORM!
Windows Configuration Loader
Added by the SDBOT-OA WORM!
Windows Configuration Utility
Added by the AGOBOT.LW WORM!
Windows Configurator
Added by a variant of the IRCBOT TROJAN!
Windows connection manager
Added by the RBOT-APN WORM! Note - file is found in the Windows or Winnt folder. Make sure you check the link on this one, it copies it's self under three other file names and folder locations
Windows Console
Added by the SDBOT-DJX WORM!
Windows Console Component
Added by a variant of the IRCBOT TROJAN! See here
Windows Console Monitor
Added by the KEDEBE WORM!
Windows Console Monitor
Added by the KEDEBE-A WORM!
Windows Console Norms
Added by a variant of the IRCBOT TROJAN! See here
Windows Console Source
Added by a variant of the IRCBOT TROJAN! See here
Windows Control
Browser hijacker. NOTE - On Win9x systems it will overwrite the Windows file of the same name in the Windows directory, so therefore it will be necessary to extract a fresh copy of the file from the Windows setup cabs!
Windows ControlAd
Windupdates adware variant
Windows Core Kernel Update
Added by the RANCK-EL TROJAN!
Windows CPU host
Added by a variant of the RBOT WORM!
Windows Critical Alert
Added by the ALEDO-A TROJAN!
Windows Custom Services
Added by the SPYBOT-EI WORM!
Windows Data Server
Added by the SPYBOT-CB WORM!
Windows Data Server
Added by the SPYBOT-DS WORM!
Windows Database
Added by an unidentified WORM or TROJAN!
Windows Database
Added by the AGOBOT-RU WORM!
Windows Dcom2 Fix
Added by the RBOT-QT WORM!
Windows DDE Loader
Added by the SDBOT-UZ WORM!
Windows debug logging
Added by the RBOT-OY WORM!
Windows debug logging
Added by the RBOT-QN WORM!
Windows Debugger
Added by an unidentified VIRUS, WORM or TROJAN!
Windows Debugger
Added by a variant of the RBOT WORM!
Windows Debugger
Added by the ZOTOB.L WORM!
Windows Debugging Tools
Added by the RBOT-AXU WORM!
Windows Default Configuration
Added by the DLOADER-U TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!
Windows Default Server
Detected by Kaspersky as the IRCBOT.BCX TROJAN! See here
Windows Default Server
Added by the IRCBOT.AUN WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of the Program Files directory
Windows Defender
Related to Windows Defender Microsoft (anti-spyware) tool
Windows Defender
Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com
Windows Defender Adds
Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com
Windows Defender Monitor
Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com
Windows Defender Updater
Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com
WINDOWS DENEME
Added by the MYTOB-CR WORM!
Windows Desktop Controler
Added by the SDBOT-XH WORM!
Windows Desktop Daemon
Added by a variant of the SPYBOT WORM!
Windows Desktop Search
Windows Desktop Search from Microsoft
Windows Dialup Service
Added by the AGOBOT.AAH WORM!
Windows Disk Defragmenter
Added by the BANCOS-ASJ TROJAN!
Windows Disk Manager
Added by a variant of the IRCBOT TROJAN!
Windows Display Coupler
Added by the IRCBOT-YS TROJAN!
Windows DLL host
Added by a variant of the SPYBOT WORM!
Windows DLL Host
Added by an unidentified WORM or TROJAN!
Windows DLL Loader
Added by the DOMWIS TROJAN!
Windows DLL Loader
Added by the LINKBOT.A WORM!
Windows DLL Loader
Added by the WHIPSER-B WORM! Note - this is not the legitimate rundll32.exe process
Windows DLL Loader
Added by the RBOT-QQ WORM!
Windows DLL Loader
Added by the POEBOT-C WORM!
Windows DLL Loader
Added by the LINKBOT.H WORM!
Windows DLL Loader
Added by the SDBOT-SS WORM!
Windows DLL Loader
Added by the RBOT-RG WORM!
Windows DLL Loader
Added by a variant of the SDBOT WORM!
Windows DLL Loader
Added by the DOMWIS-N WORM!
Windows DLL Loader
Added by the AGOBOT-TE WORM!
Windows DLL Services
Added by the RBOT-ZF WORM!
Windows DLL Services
Added by the AGENT.H spyware! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Windows DLL Services
AGENT.H spyware
Windows DLL Tracker
Added by a variant of the WOOTBOT WORM!
Windows DLL Verifier
Added by a variant of the RBOT WORM!
Windows DLL Verifier
Added by the RBOT-AZQ WORM!
Windows DNS
Added by the SDBOT-XU WORM!
Windows DNS Daemon
Added by the WOOTBOT.AS WORM!
Windows Domain Name Drivers
Added by the FORBOT-EP WORM!
Windows DOS
Added by the SALAY-A WORM!
Windows DotFix live
Added by a variant of the IRCBOT TROJAN! See here
Windows Download Manager
Added by an unidentified TROJAN!
Windows Drive Compatibility
Added by the SUPOVA.Z WORM!
Windows Driver
Added by the WOOTBOT.EE WORM!
Windows Driver
Added by a variant of the IRCBOT TROJAN! See here
Windows Driver Adapter
Added by the ANTINNY-K WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in a "drivers" subfolder
Windows Driver Foundation
Added by a variant of the RBOT WORM!
Windows Driver Services
Added by the WOOTBOT.L WORM!
Windows Driver Sup
Added by a variant of the IRCBOT BACKDOOR! See here
Windows Driver!
Added by a variant of the IRCBOT TROJAN! See here
Windows Driver!
Added by a variant of the IRCBOT TROJAN! See here
Windows Drivers
Added by the RBOT-AT WORM!
Windows drivers update
Added by the RBOT-ACE WORM!
Windows Dynamic Loading Header
Added by a variant of the SDBOT WORM!
Windows Email Server
Added by the FOUNDU-AWORM!
Windows Essensials
Added by a variant of the IRCBOT TROJAN!
Windows Event Detection
Added by a variant of the IRCBOT TROJAN! See here
Windows Event Provider
Added by a variant of the IRCBOT TROJAN! See here
Windows Event Section
Added by a variant of the IRCBOT TROJAN! See here
Windows Event Service
Detected by Kaspersky as the SDBOT.XD TROJAN! See here
Windows Executable
Added by the RBOT-ABO WORM!
Windows Executer
Added by the SDBOT-DFT WORM!
Windows Executer
Detected by Kaspersky as the EGGDROP.V BACKDOOR! See here
Windows ExpIorer
Added by the RBOT-AKO WORM!
Windows Explorer
Added by the SDBOT TROJAN!
Windows Explorer
Added by the GAOBOT.AO WORM!
Windows Explorer
Added by an unidentified WORM or TROJAN!
Windows Explorer
Added by a variant of the SPYBOT WORM!
Windows Explorer
Added by the POEBOT-J WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
Windows Explorer
Added by the RBOT-AID WORM!
Windows Explorer
Added by the RBOT-AJH WORM!
Windows Explorer
Added by a variant of the SDBOT WORM!
Windows Explorer Services
Added by a variant of the IRCBOT TROJAN! See here
Windows Explorer Shell
Added by the REDIST.B WORM!
Windows Explorer SP2
Added by the BANKER-DM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "JavaBeans" subfolder
Windows Explorer Update Build 1142
Added by the KaZaA based KWBOT or KWBOT.Y WORMS!
Windows Explorer-3212
Added by the HARDOC WORM!
Windows Explorer.exe
Added by the FALTER-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
Windows Express
Detected by PCTools as the BUZUS.C TROJAN! See here
Windows Extensions for Win32
Added by the SDBOT.AFA WORM!
Windows Eyes
For blind people, gives a voice description of items on the screen. Windows application which gives you total control over what you hear, when you hear it, and how you hear it. Available via Start -> Programs
Windows FAT 32
Added by the SPYBOT-AGT WORM!
Windows File Protection
Added by the AGOBOT.JB WORM!
Windows File System Frame
Added by an unidentified WORM or TROJAN!
Windows File Verification Service
Added by the RANKY.AC TROJAN!
Windows File XP Manager
Added by the SDBOT.XD TROJAN!
Windows FileSharing Service
Detected by Trend Micro as the IRCBOT.AJF TROJAN! See here
Windows Firewal
Added by a variant of the RBOT WORM!
Windows Firewall
Added by the MYTOB.AO WORM!
Windows Firewall
Added by the PROXY-HT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
Windows Firewall
Added by a variant of the RBOT WORM!
Windows Firewall
Added by a variant of the IRCBOT BACKDOOR!
Windows Firewall Log
Added by an unidentified WORM or TROJAN!
Windows Firewall Manager
Added by the RBOT.WR WORM!
Windows firewall manager
Added by a variant of the RANDEX.GEL WORM!
Windows firewall manager
Added by a variant of the RANDEX.GEL WORM!
Windows Firewall Service
Added by the IRCBOT-YL WORM!
Windows Firewall Updater
Added by the RBOT-GX WORM!
Windows Firewall Updater
Added by the RBOT-GBY WORM!
Windows Firewall Updater
Added by the RBOT-GCB WORM!
Windows Firewalll
Added by the RBOT-EK WORM!
Windows Firewalll
Added by a variant of the RBOT WORM!
Windows Firewalll
Added by a variant of the RBOT WORM!
Windows Firewalll
Added by a variant of the RBOT WORM!
Windows Fix
Added by the SDBOT.ZAB WORM!
Windows Fixes Systems
Added by the MYTOB.EG WORM!
Windows FormatAd
Windupdates adware variant
Windows Frame Works
Added by a variant of the RBOT WORM!
Windows Framework
Added by the DWNLDR-GWV TROJAN!
WINDOWS FUCK BY CLASIC
Added by the ZOTOB.H or ZOTOB.J WORMS!
Windows Generic Proc
Added by the ALLIM.B WORM!
Windows Genuine
Added by a variant of the SPYBOT WORM! See here
Windows Genuine Validate
Detected by PCTools as the IRCBOT.UUI BACKDOOR! See here
Windows Global Init
Added by a variant of the IRCBOT TROJAN! See here
Windows GMT32
Added by the MYTOB.KM WORM!
Windows Graphics Loaders
Added by the SPYBOT.JG WORM!
Windows Guard
Added by the RBOT-GY WORM!
Windows Guardian
Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
Windows Guardian
Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
Windows haz Layer
Added by a variant of the RBOT WORM!
Windows Help
Added by the MYTOB.JX WORM!
Windows Help File
Added by the SDBOT-QK TROJAN!
Windows Help Manager
Added by the RBOT-OZ WORM!
Windows Help Service
Added by the RBOT-LP WORM!
Windows Help Service
Added by the RBOT-AKW WORM!
Windows Help System
??
Windows Helper
Detected by Kaspersky as the BANKER.APE TROJAN! See here
Windows Helper
Added by a variant of the IRCBOT BACKDOOR! See here
Windows Hijack Protection
Added by the AGENT-FYD TROJAN!
Windows Hijack Protection System
Added by a variant of the AGENT-FYD TROJAN!
Windows his Layer
Added by the RBOT.GLX WORM!
Windows Host
Added by the KELVIR.U WORM!
Windows Host
Added by the PRYSAT TROJAN!
Windows Host Booter
Added by an unidentified WORM or TROJAN! See here
Windows Host Device
Added by the ZOOTY-A WORM!
Windows Host Name
Added by the GAOBOT.O WORM!
Windows Host Service
Added by the SPYBOT.NLI WORM!
Windows Host Service
Added by the KELVIR.AN WORM!
Windows Host Service
Added by the KELVIR.BF WORM!
Windows Host Service
Added by the KELVIR.AW WORM!
Windows Host32 Starter
Added by the SDBOT-WU WORM!
Windows Hosts
Added by the KELVIR-O TROJAN!
Windows Hosts
Added by a variant of the IRCBOT TROJAN!
Windows HP Drivers
Added by the SDBOT.AQU WORM!
Windows HTML file reader
Added by the NOOMY.A WORM!
Windows HTTP services
Added by a variant of the SDBOT WORM! See here
Windows Icons Manager
Added by the RBOT-AIF WORM!
WINDOWS ID SYSTEM
Added by the MYTOB.LN WORM!
Windows Identify
Added by a variant of the SPYBOT WORM! See here
Windows Image
Detected by Avast as the SDBOT-GEN44 WORM!
Windows Image Acquisition (WIASC)
Added by the RIZO.A TROJAN!
Windows Image Acquisition (WIASSC)
Added by the RIZO.A TROJAN!
Windows iMessenger Messenger
Added by the ALLIM.A WORM!
Windows Incontext
PacerD_Media/Pacimedia.com/Z-Quest adware installer
Windows Insecure
Added by the RBOT-FSM WORM!
Windows installer
SpySheriff malware. For more information on registry key changes see SPYWAD-E
Windows Installer
Added by an unidentified WORM or TROJAN!
Windows Installer 1
Added by the PURITYSCN.B TROJAN!
Windows Instruction Services
Added by a variant of the IRCBOT TROJAN! See here
Windows Internet Browser Services
Added by a variant of the IRCBOT TROJAN! See here
Windows Internet Browser Services
Added by a variant of the IRCBOT TROJAN! See here
Windows Internet Browser Services
Added by a variant of the IRCBOT TROJAN! See here
Windows Internet Browser Services
Added by a variant of the IRCBOT TROJAN! See here
Windows Internet Manager
Added by a variant of the IRCBOT TROJAN! See here. Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
Windows Internet Protocol
CoolWebSearch Winproc32 parasite variant - also detected as the STARTPA-BF TROJAN!
Windows Internet Protocol
Added by a variant of the Win32.Small TROJAN!
Windows Internet Service
Added by the RBOT-AUX WORM!
Windows IP Security
Related to the VPN IPSec utility - used to create Security Policy (SP) entries and Security Association (SA) entries in the kernel
Windows IP Security Service
Added by the RBOT.BPW WORM!
Windows IPv6 Drivers
Added by the SDBOT-VJ WORM!
Windows Java Update
Added by a variant of the RBOT WORM!
Windows JavaScript Daemon
Added by the WOOTBOT.AF WORM!
Windows Kernel 64
Added by the YIMP-B WORM!
Windows Kernel System Service
Added by a variant of the RANDEX.GEL WORM!
Windows kev Messenger
Added by the SDBOT-XV WORM!
Windows Keyboard Services
Detected by Trend Micro as the IRCBOT.AFS WORM! See here
Windows Keyboard Services
Added by a variant of the IRCBOT TROJAN! See here
Windows Keyboard Services
Added by a variant of the IRCBOT TROJAN! See here
Windows Live
Detected by Trend Micro as the XPACK.AV TROJAN! See here
Windows Live Client
Added by a variant of the IRCBOT TROJAN! See here
Windows Live Manager
Detected by Trend Micro as the SHEUR.EB WORM! See here
Windows Live Messages
Detected by Trend Micro as the AGENT.AYH WORM! See here
Windows live Messenger
Added by the IRCBOT-AAV WORM!
Windows Live Messenger
Detected by Kaspersky as the RBOT.BMV TROJAN! See here
Windows Live Messenger Addon
Added by a variant of the SDBOT WORM! See here
Windows Live Messenger Servicer
Added by a variant of the IRCBOT TROJAN! See here
Windows Live Messenger Services
Added by a variant of the IRCBOT TROJAN! See here
Windows Live Messenger!
Added by a variant of the IRCBOT TROJAN! See here
Windows Live Messenger!
Added by a variant of the IRCBOT TROJAN! See here
Windows Live Msgs
Added by a variant of the IRCBOT TROJAN! See here
Windows Live Msgs!
Added by a variant of the IRCBOT TROJAN! See here
Windows Live Service
Added by a variant of the IRCBOT TROJAN! See here
Windows live Support
Added by the RBOT-BKL WORM!
Windows Load
??
Windows Loader
Added by the GAOBOT.CA WORM!
Windows Loader
Reported by Kaspersky Anti-Virus as the CARDSPY.D TROJAN!
Windows Loader
Added by a variant of the SDBOT WORM!
Windows Loader Service
Added by a variant of the RBOT WORM!
windows Loadxm
Added by the FODDER-A TROJAN!
Windows Local ISP
Detected by Trend Micro as the SDBOT.ENZ BACKDOOR! See here
Windows Local Services
Added by the DLOADER-NY TROJAN!
Windows Local Services
Added by the DLOADER-NY TROJAN!
Windows Local Services
Added by the DLOADER-NY TROJAN!
Windows Local Services
Added by the DLOADER-NY TROJAN!
Windows Local Services
Added by the DLOADER-NY TROJAN!
Windows Local Services
Added by the DLOADER-NY TROJAN!
Windows Local Services
Added by the DLOADER-NY TROJAN!
Windows Local Services
Added by the DLOADER-NY TROJAN!
Windows Locator
Added by the IRCBOT.N TROJAN!
Windows Log Agent
Added by the KEYLOGGER.AVK TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files
Windows Logger
Added by the NSHADOW-B TROJAN!
Windows logging
Added by the RBOT-ON WORM!
Windows logging
Added by a variant of the IRCBOT TROJAN!
Windows Logical Adapter
Detected by Kaspersky as the IRCBOT.ARU TROJAN! See here
Windows Logical Connection
Detected by Kaspersky as the VIRUT.AO VIRUS! See here
Windows Login
Added by the GAOBOT.SY WORM!
Windows Login
Added by the AGOBOT.MG WORM!
Windows Login
Added by the AGOBOT-JA WORM!
Windows Login
Detected by NOD32 as a variant of the BIFROSE TROJAN!
Windows Login Folder
Added by the AGOBOT-TZ WORM!
Windows Login Manager
Added by a variant of the SDBOT WORM!
Windows Login Security
Added by an unidentified WORM or TROJAN!
Windows Login Service
Added by the RBOT-AFN WORM!
Windows Login Service
Added by the SDBOT-ACU WORM!
Windows Logon
Added by the SPYBOT-C TROJAN!
Windows Logon Application
Added by the LINKBOT.M WORM!
Windows Logon Application
Added by the POEBOT-J WORM!
Windows Logon Application
Added by the CIADOOR-L TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
Windows Logon Application
Added by the DELBOT-X WORM!
Windows Logon Application
Added by the POEBOT-KW WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
Windows Logon Application
Added by the POEBOT-LR WORM! Note - this is NOT the popular Winamp media player which resides in a "Winamp" subdirectory of the Program Files directory
Windows Logon Applicationedc
Added by the DWNLDR-HGR TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%
Windows Logon Manager
Added by a variant of the RBOT WORM!
Windows Logon Procedure
Added by a variant of the SPYBOT WORM!
Windows Logon Procedure
Added by a variant of the SPYBOT WORM!
windows logon procedure
Added by the WINLOGON TROJAN!
Windows Logon Service
Added by the RBOT-AOU WORM!
Windows Logon Service
Added by the SPYBOT.ANDM WORM!
Windows LoL Layer
Added by the RBOT-FOR WORM!
Windows LoL Layer
Added by the RBOT-GMZ WORM!
Windows LoL Layer
Added by the RBOT-GOR WORM!
Windows LoL Layer
Added by the AGOBOT-AHS WORM!
Windows LoL Layer
Added by the RBOT-FTO WORM!
Windows LoL Layer
Added by the RBOT-GMD WORM!
Windows LoL Layer
Added by the RBOT-GKV WORM!
Windows Management Instrumentation
Added by the GRAPS WORM!
Windows Management Instrumentation
Added by the QEDS-A VIRUS!
WINDOWS MANAGEMENT SYSTEM
Added by the RBOT-VT WORM!
Windows Manager
Added by the MANTAS WORM!
Windows Manager
Added by a variant of the AGOBOT/GAOBOT WORM!
Windows Manager Update Inc
Added by the SDBOT-ACM WORM!
Windows mangement
Added by the RANDEX.FC WORM!
Windows Media AP
Added by an unidentified WORM or TROJAN!
Windows Media APP
Added by an unidentified WORM or TROJAN!
Windows Media Center
Starts Windows Media Center every time Windows Vista (Home Premium or Ultimate) boots. Disable by unchecking the "Start Windows Media Center when Windows Starts" option via Windows Media Center -> Tasks -> Settings -> General -> Startup and Window Behaviour
Windows Media Connect 2
Windows Media Connect from Microsoft - stream digital media files on your computer to digital media receivers (DMRs) that are connected to your home network
Windows Media Driver
Added by a variant of the RBOT WORM!
Windows Media Loader
Added by a variant of the GAOBOT WORM!
Windows Media Player
Added by the AGOBOT-NQ WORM!
Windows Media Player
Added by the SDBOT-QO TROJAN! Note - the executable is called 'MediapIayer', with an 'i'
Windows Media Player
Added by a variant of the RBOT WORM!
Windows Media Player
Added by the RBOT-SI WORM!
Windows Media Player
Added by the RBOT-YO WORM!
Windows Media Player
Added by the KELVIR.G WORM or variants! Note - this is not the valid Windows Media Player as the executeable resides is C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP) rather than C:Program FilesWindows Media Player
Windows Media Player
Added by a variant of the RBOT WORM!
Windows Media Player
Added by the RBOT-TT WORM!
Windows Media Player
Added by the RBOT.AHR WORM!
Windows Media Player 3.6
Added by a variant of the RBOT WORM!
Windows Media Player 3.6b
Added by the RBOT-VV WORM!
Windows Media Player 3.6d
Added by the RBOT-YA WORM!
Windows Media Player 3.9
Added by a variant of the RBOT WORM!
Windows Media Player Service
Added by the RBOT.213504 WORM!
Windows Media Player Update
Added by the RBOT-ET WORM!
Windows Media Powerpoint Helper
German software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start -> Programs
Windows Media Server
Added by a variant of the IRCBOT TROJAN! See here
Windows Media Server!
Added by a variant of the IRCBOT TROJAN! See here
Windows media service
Added by the SDBOT.VP WORM!
Windows media service
Added by the RBOT.ACY WORM!
Windows media service
Added by the RBOT.ADE WORM!
Windows media services
Added by the RBOT-MW WORM!
Windows Media SP.2.37
Added by the LEMIR.C TROJAN!
Windows Media Updater
Added by the RBOT-ATI WORM!
Windows Media Upgrade
Added by the RBOT.BMF TROJAN!
Windows Media Utility
Added by a variant of the SPYBOT WORM!
Windows Memory Drivers
Added by a variant of the IRCBOT TROJAN!
Windows Memory Manager
Added by a variant of the IRCBOT TROJAN! See here
Windows Memory Running Services
Detected by Kaspersky as the IRCBOT.BLL TROJAN! See here
Windows Memory Sharing
Added by a variant of the IRCBOT TROJAN!
Windows Memory Sharing
Detected by Trend Micro as the IRCBRUTE.AG TROJAN! See here
Windows Memory Sharing
Detected by PCTools as the IRCBOT.WCH TROJAN! See here
Windows Messanger Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
Windows Messanger Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
Windows Messanger Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
Windows Messanger Control Center
Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
Windows Messanger Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
Windows messenger
Added by the MYTOB.EI WORM!
Windows Messenger
Added by the RBOT-ANJ WORM!
Windows Messenger
Added by the SPYBOT.BV WORM!
Windows Messenger Connect
Detected by Trend Micro as the SLENFBOT.S WORM! See here
Windows Messenger Fileshare
Detected by Symantec as the SILLYIM WORM! See here
Windows Messenger Live MSN
Added by a variant of the IRCBOT BACKDOOR!
Windows Messenger Live Startup
Added by an unidentified WORM or TROJAN! See here
Windows Messenger Live Startup
Detected by Kaspersky as the DELF.DAX TROJAN! See here
Windows Messenger Messenger
Added by the VELKBOT.A WORM!
Windows Messenger Panel
Detected by Trend Micro as the IRCBOT.ADA TROJAN! See here
Windows Messenger Service
Added by the RBOT-VW WORM!
Windows Messenger Service
Added by the MYTOB.HY WORM!
Windows Messenger Share
Added by a variant of the IRCBOT TROJAN! See here
Windows Messenger Starter
Detected by Trend Micro as the SLENFBOT.T WORM! See here
Windows MeTaLRoCk service
Added by the TASTYRED TROJAN!
Windows Micro Drivers
Added by the RBOT-AEH WORM!
Windows Microsoft Service
Added by the AGENT-HCD TROJAN!
Windows Microsoft Services
Detected by Trend Micro as the KOLAB.AW WORM! See here for an example
Windows Microsoft Update
Added by a variant of the SDBOT WORM!
Windows Microsoft Verifier
Added by a variant of the RBOT WORM!
Windows Mobile Device Center
Windows Mobile Device Center for Windows Vista. Replaces Microsoft ActiveSync and provides overall device management features for your Windows Mobile powered devices for Windows Vista
Windows Mobile-based device management
Part of Windows Mobile Device Center in Vista. Microsoft Windows Mobile Device Center enables you to set up new partnerships, synchronize content and manage music, pictures and video with Windows Mobile powered devices (Windows Mobile 2003 or later)
Windows Mobile-based device management
Windows Mobile Device Center for Windows Vista. Replaces Microsoft ActiveSync and provides overall device management features for your Windows Mobile powered devices for Windows Vista
Windows mod Verifier
Added by the RBOT.DSU WORM!
Windows modez Verifier
Added by a variant of the SDBOT WORM!
Windows modez Verifier
Added by a variant of the RBOT WORM!
Windows modez Verifier
Added by a variant of the SDBOT WORM!
Windows modez Verifier
Added by the RBOT.EZJ WORM!
Windows modez Verifier
Added by a variant of the RBOT WORM!
Windows modez Verifier
Added by the RBOT-DIO WORM!
Windows modez Verifier
Added by a variant of the RBOT WORM!
Windows modez Verifier
Added by the RBOT-FNB WORM!
Windows modez Verifier
Detected by Kaspersky as the RBOT.CYA TROJAN! See here
Windows Monitor
Added by the SDBOT.VB WORM!
Windows Monitor
Added by the SPAZBOX.A TROJAN!
Windows Monitor Services
Added by the RBOT-XX WORM!
Windows Monitoring Service
Added by a variant of the SDBOT WORM!
Windows More Choice
ZQuest adware
Windows Mouse Services
Added by the CHECKOUT WORM! See here
Windows Mouse Services
Detected by Trend Micro as the IRCBOT.AIA TROJAN! See here
Windows Mouse Utilities
Added by the RBOT-ABU WORM!
Windows ms Drivers
Added by the SDBOT-AAL WORM!
Windows MS Update 32
Added by the IRCBOT.GEN WORM!
Windows MS Update 32
Added by the FORBOT-GJ WORM!
Windows MSConfig Startup Logger
Added by the RBOT.BCU WORM!
Windows MSN
Added by the TRIXCU.A WORM!
Windows Msn Live Messanger
Added by a variant of the SDBOT WORM!
Windows MSN Live Messanger
Detected by Kaspersky as the RBOT.BMV TROJAN! See here
Windows MSN Live Messanger
Detected by Kaspersky as the RBOT.BMV BACKDOOR! See here
Windows MSN Live Messenger
Added by an unidentified WORM or TROJAN! See here
Windows MSN Live Messenger
Detected by Kaspersky as the IRCBOT.EAD BACKDOOR! See here
Windows MSN Updates
Added by the IRCBOT-ABA TROJAN!
Windows MSN2 XP
Detected by Trend Micro as the KOLAB.AA WORM! See here
Windows MSX drivers
Added by the RBOT-AYG TROJAN!
Windows Net Cfg
Added by a variant of the RBOT WORM!
Windows NetDDe
Added by the MYTOB.IM WORM!
Windows Nets
Added by the RBOT-MO WORM!
Windows NetStart Service
Added by the RBOT-ZX WORM!
Windows NetStart Service2
Added by the RBOT-ABN WORM!
Windows NetStart Service2
Added by a variant of the RBOT WORM!
Windows Netsystem Layer
Added by the RBOT.BEI WORM!
Windows Network Controller
Added by the FORBOT-CL WORM!
Windows Network Controller
Added by the FORBOT-DK WORM!
Windows Network Controller
Added by the FORBOT-ED WORM!
Windows Network Controller
Added by a variant of the SDBOT WORM!
Windows Network Controller
Added by the WOOTBOT.I WORM!
Windows Network Firewall
Added by the POEBOT-J WORM!
Windows Network Logon
Detected by Trend Micro as the AGENT.ERZ TROJAN! See here
Windows Network Service
Added by the RBOT.RY WORM!
Windows Network Service
Added by a variant of the RBOT WORM!
Windows Network Services
Added by a variant of the IRCBOT TROJAN! See here
Windows Network Services
Added by the CHECKOUT WORM! See here
Windows Network Services
Added by a variant of the IRCBOT TROJAN! See here
Windows Network Services
Added by a variant of the IRCBOT TROJAN! See here
Windows Network Session
Added by a variant of the IRCBOT TROJAN! See here
Windows Networking
Added by the GAOBOT.FL WORM!
Windows Networking Monitor
Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is always located in %ProgramFiles%\Microsoft Shared. This one is located in %System%
Windows Networking Monitorin
Added by a variant of the IRCBOT BACKDOOR! See here
Windows Networking Monitoring
Added by the IRCBOT.AKZ WORM!
Windows Networks
Added by the MYTOB.FH WORM!
Windows Nivedia Driver
Added by a variant of the RBOT WORM!
Windows NNT
Added by the RANKY.E TROJAN!
Windows NT 32
Added by the RANDEX.BRD WORM!
Windows NT Login
Added by the SDBOT.WG WORM!
Windows NT Login Session Manager
Added by the RBOT.BIV WORM!
Windows NT Logon Application
Added by the RBOT-ALP WORM!
Windows NT Service Name
Added by the RBOT-PK WORM!
Windows NT Session Manager
Added by a variant of the RBOT WORM!
Windows NT Update Manager
Added by the AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital "o"
Windows NTFS Volume Manage
Detected by Kaspersky as the RBOT.EDL TROJAN! See here
Windows OEM Tools
Added by the SPYBOT.FD WORM!
Windows Offical Netvvorks
Added by a variant of the SDBOT WORM! See here
Windows Office Monitor
Detected by Trend Micro as the RBOT.GJO TROJAN! See here
Windows OLE Automation Server
CoolWebSearch parasite variant
Windows Online Updater
Added by the RBOT-TE WORM!
Windows Pc
Added by the BIBOT-A WORM!
Windows PDG
Added by the RBOT-ADW WORM!
Windows Performance Monitor
Added by the IRCBOT_GEN WORM!
Windows PNP
Added by the RBOT-AKN WORM!
Windows PNP Server
Added by the MS05-039 variant of the SDBOT WORM!
Windows Pool Manager
Detected by Trend Micro as the OBOT.CH WORM! See here
Windows Pool Setup
Added by the CHECKOUT WORM! See here
Windows Population Logger
Added by the AGENT.YKR WORM!
Windows Portable Device Drivers
Added by a TROJAN - see here
Windows Portable Devices
Added by the SPYBOT.APEO WORM!
Windows Print Monitor Daemon
Added by a variant of the SDBOT WORM!
Windows Print Spooler
Suspicious due to the similarity to the valid "svchost.exe" file
Windows Print Spooler
Added by an unidentified VIRUS, WORM or TROJAN!
Windows Print Spooler
Added by the SPYBOT.H WORM!
Windows Printing Driver
Added by a variant of the RBOT WORM!
Windows Printing Driver
Added by an unknown malware
Windows Process
Added by the LASTWORD WORM!
Windows Process Manager
Added by an unidentified WORM or TROJAN!
Windows Processe Manager
Added by a variant of the RBOT WORM!
Windows Proffesional Security
Added by the AGOBOT.VA WORM
Windows Protected Storage
Detected by Trend Micro as the IRCBOT.AUL TROJAN! See here
Windows Protectot
Added by a variant of the WOOTBOT WORM!
Windows Recavery Adware
Added by an unidentified TROJAN - see here. Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
Windows Recylinder Check
Added by the RBOT-EGJ WORM!
Windows Reg Services
Added by the DLOADER-PL or DLOADER-XM TROJANS!
Windows Reg Services
Added by the PRORAT-D TROJAN!
Windows Reg Services
Added by the PRORAT-D TROJAN!
Windows Reg Services
Added by the PRORAT-D TROJAN!
Windows Reg Services
Added by the PRORAT-O TROJAN!
Windows Reg Services
Added by the PRORAT-O TROJAN!
Windows Reg Services
Added by the PRORAT-O TROJAN!
WINDOWS REGISTER EDIT
Added by an unidentified WORM or TROJAN!
Windows Register Settings
Added by a variant of the FORBOT WORM!
Windows Registers
Added by a variant of the SDBOT WORM!
Windows Registery Center
Added by a variant of the IRCBOT BACKDOOR! See here
Windows Registry
Added by a variant of the RBOT WORM!
Windows Registry
Added by a variant of the RBOT WORM!
Windows Registry Cleaner
Added by a variant of the SPYBOT WORM!
Windows Registry Control
Added by a variant of the IRCBOT TROJAN! See here
Windows Registry DLL
Detected by Trend Micro as the IRCBOT.FB TROJAN! See here
Windows Registry Express Loader
Added by the FORBOT-CJ WORM!
Windows Registry Manager
Added by the MYTOB.ER WORM!
Windows Registry Name
Added by the RBOT-AEB WORM!
Windows Registry Name
Added by the RBOT-ADB WORM!
Windows Registry Repair Pro
Registry Repair Pro. "Scans the Windows Registry for invalid or obsolete information in the registry"
Windows Registry Scan
Added by the RBOT.KE WORM!
Windows Registry Scan
Added by the SPYBOT.JE WORM!
Windows Registry Scan
Added by the RBOT-TP WORM!
Windows Registry Scan
Added by a variant of the RBOT WORM!
Windows Registry Scan
Added by the RBOT-HA WORM!
Windows Registry Scan
Added by the SPYBOT.GK WORM!
Windows Registry Security
Added by a variant of the IRCBOT TROJAN!
Windows Registry Services
Added by a variant of the IRCBOT TROJAN! See here
Windows Registry Startup
Added by the AGOBOT-BZ WORM!
Windows Registry XP
Added by the IRCBOT.AUN WORM!
Windows Relay Service
Detected by PCTools as the DELFINJECT.F TROJAN! See here
Windows Relay Service
Detected by Trend Micro as the DROPPER.ACO TROJAN! See here
Windows Remote Addressing
Added by the DELF-EZN TROJAN!
Windows Remote Launcher
Detected by Kaspersky as the IRCBOT.ASX TROJAN! See here
Windows Repair
Added by the SDBOT-ADL WORM!
Windows report
Added by the SMALL-BD TROJAN!
Windows Rescue System
Detected by Kaspersky as the SUURCH.CG TROJAN! See here
Windows Reverse Preperation
Added by a variant of the IRCBOT TROJAN! See here
Windows Reversed Virus Protection
Added by a variant of the IRCBOT TROJAN! See here
windows run
Added by the ICPASS-A WORM!
Windows Run-Time 64bit
Added by a variant of the RBOT WORM!
Windows Running DLL Service
Added by a variant of the IRCBOT TROJAN! See here
Windows Running DLL Service
Added by a variant of the IRCBOT TROJAN! See here
Windows Runtime Help
Added by a variant of the AIMVISION TROJAN!
Windows Runtime Help
Added by a variant of the AIMVISION TROJAN!
Windows Runtime Proccess
Added by the SDBOT.QW WORM!
Windows SA
BLAZEFIND adware
Windows Scheduler
Added by a variant of the SDBOT WORM! See here
Windows Scheduler!
Added by a variant of the IRCBOT TROJAN! See here
Windows Screensaver
Added by the KELVIR.P WORM!
WINDOWS SCREENSAVER
Added by the SDBOT-YZ WORM!
Windows secure
Added by the SPYBOT.EP WORM!
Windows Secure Connection
Added by the SDBOT.BTN WORM!
Windows Secure Layer
Added by the RBOT.DRF WORM!
Windows Secure Messaging System
Added by the RBOT-RE WORM!
Windows Secure Services
Added by the RBOT-GAR WORM!
Windows Secure talal32
Detected by Kaspersky as the RBOT.HTP TROJAN! See here
Windows Secure Update
Added by the RBOT-GCG WORM!
Windows Secure Update
Added by the RBOT-GCD WORM!
Windows Secure Update
Added by the FORBOT-GU WORM!
WINDOWS SECURITY
Added by a variant of the RBOT WORM!
Windows Security
Added by the RBOT-APT WORM!
Windows Security
Added by the RBOT-ARN WORM!
Windows Security
Added by the RBOT-BAF WORM!
Windows Security Assistant
CoolWebSearch Alfasearch parasite variant - also detected as the STARTPA-U TROJAN!
Windows Security Assistant
CoolWebSearch parasite variant
Windows Security Authority Service
Added by the KALEL-A WORM! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup!
Windows Security Center Notification App
Added by a variant of the RBOT WORM!
Windows Security Center Notification Appls
Added by the RBOT-GKX WORM!
Windows Security Center Notification Applse
Added by the RBOT-GLR WORM!
Windows Security Center Notification Applse
Added by a variant of the RBOT-GLR WORM!
Windows Security Center Notification Applsee
Added by a variant of the RBOT-GKX WORM!
Windows Security Manager
Added by the AGOBOT-KI WORM!
Windows Security Manager
Affilred adware
Windows Security Manager
Added by the ANTINNY.AX WORM!! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "Microsoft" subfolder
Windows Security Module
Added by a variant of the RBOT WORM!
Windows Security Service
Added by the RBOT-ALV WORM!
Windows Security Service
Added by a variant of the RBOT WORM!
Windows Security Service
Added by the RBOT-AMG WORM!
Windows Security Survy
Added by a variant of the IRCBOT BACKDOOR! See here
Windows Security Update
Affilred adware
Windows Serv Patch
Added by a variant of the RBOT WORM!
Windows Servce Agent
Added by a variant of the IRCBOT TROJAN!
Windows Servcesc
Added by a variant of the SDBOT WORM! See here
Windows ServeAd
Windupdates adware variant
Windows Server
Detected by Trend Micro as the IRCBOT.AVM TROJAN! See here
Windows Server Client Verification Service
Added by the AGENT.AWC TROJAN!
Windows Server Drivers
Added by a variant of the IRCBOT TROJAN! See here
Windows Server Information
Added by the FORBOT-EN WORM!
Windows Server IP Verification Service
Added by an unidentified WORM or TROJAN! See here
Windows Server Peer Verification Service
Added by a variant of the RANKY TROJAN!
Windows Server!
Added by a variant of the IRCBOT TROJAN! See here
Windows Servic2
Added by the RBOT-AIA WORM!
Windows service
Added by the RBOT-QW WORM!
Windows Service
Identified by Kaspersky Labs as Dialer.Salc, also known to come with the Bube family trojans
Windows Service
Malware - detected by Kaspersky as the SMALL.RD TROJAN!
Windows Service
Added by an unidentified TROJAN!
Windows Service
Added by the AGOBOT-HL WORM!
Windows Service
Added by an unidentified WORM or TROJAN!
Windows Service
Added by the SMALL.VZ TROJAN!
Windows Service
Added by an unidentified TROJAN!
Windows Service
Adware, detected by DiamondCS TDS-3 anti-trojan as "TrojanDownloader.Win32.Delf.dg"
Windows Service
Added by the DOWNLOADER.SMALL.MY TROJAN!
Windows Service
Added by the KALEL-A WORM! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
Windows Service
Added by the SPYBOT-DH TROJAN!
Windows Service
Added by a variant of the SMALL.VZ TROJAN!
Windows Service
Added by the SDBOT-AYI WORM! Note - dissables the automatic startup of other software and deactivates the Microsoft Internet Connection Firewall (ICF)
Windows Service Ag3nt
Detected by Trend Micro as the SDBOT.EZX TROJAN! See here
Windows Service Agent
Added by the RBOT-GAJ WORM!
Windows Service Agent
Added by the IRCBOT-XE TROJAN!
Windows Service Agent
Added by the RBOT-GQU WORM!
Windows Service Agent
Added by the RBOT-GQY WORM!
Windows Service Agent
Added by the RBOT.MIRCO.BNG WORM!
Windows Service Agent
Added by a variant of the SLAPER TROJAN!
Windows Service Agent
Added by the RBOT-GMN WORM!
Windows Service Agent
Added by the RBOT-LOL WORM!
Windows Service Agent
Added by the RBOT-GQX WORM!
Windows Service Agent
Added by the RBOT-GQT WORM!
Windows Service Agent
Added by the RBOT-GQV WORM!
Windows Service Agent
Added by the RBOT-GQP WORM!
Windows Service Agent
Added by the RBOT.EOZ WORM!
Windows Service Agent
Detected by Kaspersky as the RBOT.KGU BACKDOOR! See here
Windows Service Agent 32
Added by the AGENT-GAQ TROJAN!
Windows Service Agnts
Detected by Trend Micro as the SDBOT.BCQ WORM! See here for an example
Windows Service Ajav
Detected by Kaspersky as the RBOT.BNG TROJAN! See here
Windows Service alge
Detected by Trend Micro as the RBOT.GJO TROJAN! See here
Windows Service Controller
Added by the KALEL-B WORM! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
Windows Service Controller Agent
Added by a variant of the IRCBOT BACKDOOR! See here
Windows Service DC
Added by the RBOT-GLY WORM!
Windows Service Host
Added by the SDBOT.N TROJAN!
Windows Service Host
Added by the CONE.B WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder
Windows Service Host
Added by the KALEL-C WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Windows Service Host
Added by the GAOBOT.AO WORM!
Windows Service Host Process
Added by the EZIO-A WORM!
Windows Service Hosting
Added by the GOMMER-A WORM!
Windows Service Layer
Added by the RBOT.DDJ WORM!
Windows Service Loader
Added by the RBOT-XO WORM!
Windows Service Manager
Added by the OSCABOT-C WORM!
Windows Service Manager
Added by the DLOADER-NY TROJAN!
Windows Service Manager
Added by the OSCABOT-E WORM!
Windows Service Manager
Added by the OSCABOT-G WORM!
Windows Service Manager
Added by the DLOADER-NY TROJAN!
Windows Service Manager
Added by the DLOADER-NY TROJAN!
Windows Service Manager
Added by the DLOADER-NY TROJAN!
Windows Service Manager
Added by the DLOADER-NY TROJAN!
Windows Service Manager
Added by the OSCABOT-D WORM!
Windows Service Manager
Added by the DLOADER-NY TROJAN!
Windows Service Manager
Added by the DLOADER-NY TROJAN!
Windows Service Manager
Added by the DLOADER-NY TROJAN!
Windows Service Manager
Detected as Trojan-Spy.Win32.IamBigBrother.91 by Kaspersky, possibly a commercial keylogger
Windows Service Manager
Added by the RBOT-BWT WORM!
Windows Service Pack 2
Added by the SDBOT-TQ WORM!
Windows Service Pack Auto Update
Adware downloader, identified by eScan antivirus as Trojan-Clicker.Agent.bt
Windows Service Pack Auto Update
Detected by Kaspersky as the AGENT.BT TROJAN!
Windows Service Pack Auto Update
Added by an unidentified WORM or TROJAN!
Windows Service Pack Auto Update
Adware, also detected as the LOWZONES.BH TROJAN!
Windows Service Pack2
Added by a variant of the RBOT WORM!
Windows Service Pack2
Added by the GAOBOT.G WORM!
Windows Service Supply
Detected by Kaspersky as the IRCBOT.BFB TROJAN! See here
Windows Service Support Call
Added by the RBOT-XQ WORM!
Windows Service SV
Added by a variant of the IRCBOT TROJAN!
Windows Service Threads
Added by a variant of the IRCBOT TROJAN! See here
Windows Service Threads
Added by a variant of the IRCBOT TROJAN! See here
Windows Service Update
Added by the SDBOT-DEY WORM!
Windows Service Utitity
Added by the RBOT-ASI WORM!
Windows Service XP
Added by the MYTOB.AM WORM!
Windows Servicer
Added by the SDBOT-DFB WORM!
Windows Services
Added by the RANDEX.R WORM!
Windows Services
Added by the AGOBOT-KL TROJAN!
Windows Services
Added by the SDBOT-WT WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
Windows Services
Added by the RBOT-ACR WORM!
Windows Services
Added by a variant of the SDBOT WORM!
Windows Services
Added by the SPYBOT.OBZ WORM!
Windows Services
Added by the MYTOB-CB WORM!
Windows Services
Added by the SDBOT-YO WORM!
Windows Services
Added by a variant of the SDBOT WORM!
Windows Services
Added by the SDBOT.CPZ WORM!
Windows Services
Added by the RBOT-WE WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%
Windows Services
Added by a variant of the IRCBOT BACKDOOR!
Windows Services
Added by a variant of the IRCBOT BACKDOOR! See here
Windows Services
Added by a variant of the IRCBOT BACKDOOR! See here
Windows Services
Added by the AUTORUN-FU WORM!
Windows Services
Added by the AUTORUN-FT WORM!
Windows Services
Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
Windows Services
Added by a variant of the IRCBOT BACKDOOR! See here
Windows Services
Added by a variant of the IRCBOT BACKDOOR! See here
Windows Services
Added by a variant of the IRCBOT BACKDOOR!
Windows Services Agant
Added by the SDBOT-DIK WORM!
Windows Services Aganters
Detected by Trend Micro as the RBOT.CUN WORM! See here for an example
Windows Services B-Runner
Added by a variant of the IRCBOT TROJAN! See here
Windows Services B-Runner
Added by a variant of the IRCBOT TROJAN! See here
Windows Services Certification
Added by a variant of the IRCBOT TROJAN! See here
Windows Services Guide
Detected by Symantec as the SILLYIM WORM! See here
Windows Services Guide
Added by the CHECKOUT WORM! See here
Windows Services Host
Added by the CONE or CONE.E WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Windows Services Hosts
Added by the SDBOT-YH TROJAN!
Windows Services Ink Platform Tablet Input Subsystem
Added by the RBOT.APC WORM!
Windows Services Jog
Added by a variant of the IRCBOT TROJAN! See here
Windows Services Jog
Detected by Trend Micro as the AGENT.QAF WORM! See here
Windows Services Joger
Added by a variant of the IRCBOT TROJAN! See here
Windows Services Jogging
Added by a variant of the IRCBOT TROJAN! See here
Windows Services Joging
Detected by Trend Micro as the IRCBOT.AVI TROJAN! See here
Windows Services Layer
Added by the RBOT-FZE WORM!
Windows Services Layer
Added by the RBOT-FZQ WORM!
Windows Services Layer
Added by the RBOT-GAH WORM!
Windows Services M7
Detected by Kaspersky as the AGENT.WOH TROJAN! See here
Windows Services Tower
Detected by Trend Micro as the IRCBOT.AGJ TROJAN! See here
Windows Services Tower
Added by a variant of the IRCBOT TROJAN! See here
Windows Services Update
Added by a variant of the RBOT WORM! Note - the filename has the digit 0 rather then the uppercase "o"
Windows Serviece Agents
Detected by Trend Micro as the AGENT.BHR TROJAN! See here for an example
Windows Servser
Added by a variant of the IRCBOT BACKDOOR! See here
Windows Session Manager
Added by a variant of the RBOT WORM!
Windows Session Manager Subsystem
Added by the KALEL-B WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!
Windows shell
??
Windows Shell
Added by the MYTOB-CA WORM!
Windows Shell
Added by the MYTOB.BV WORM!
Windows Shell Library Loader
CoolWebSearch parasite variant
windows shellext.32
Added by the BLASTER.K WORM!
WINDOWS SKY
Added by the MYTOB.CH WORM!
Windows Smart Manager
Added by the RBOT-SL WORM!
Windows smss service
Added by the AGENT-FPY TROJAN!
Windows Socket Procedure
Added by the RBOT-FMX WORM!
Windows Software
Added by the RBOT-GLL WORM!
Windows Sound
Detected by PCTools as the RBOT.ABCC WORM! See here
Windows Sound Driver
Added by a variant of the SPYBOT WORM!
Windows Sound Emulator
Added by the ATNAS.A WORM!
Windows Sound Manager
Added by the FORBOT-BU WORM!
Windows Sound Manager
Added by a variant of the FORBOT WORM!
Windows Sound Verifier
Added by the RBOT-FMO WORM!
Windows SP2 Firewall
Added by a variant of the RBOT WORM!
Windows SP2 Update
Added by the WOOTBOT.BS WORM!
Windows SP2 Version Load
Added by the GAOBOT.CX WORM!
Windows SP4
Added by the RBOT-ACX WORM!
Windows Spool
Added by a variant of the IRCBOT TROJAN!
Windows Spool Server
Added by the SDBOT-ACT WORM!
Windows SpoolaPrint Service
Added by the SDBOT-AYD WORM!
Windows Spooler
Added by the SPYBOT.P WORM!
Windows Spooler
Added by an unidentified WORM or TROJAN!
Windows Spooler
Detected by Trend Micro as the SHEUR.ANX TROJAN! See here
Windows Spooler Services
Added by the AGOBOT-AMO WORM!
Windows SpoolPrint Service
Added by the SDBOT-ZT WORM!
Windows Spools SV
Added by the RBOT-AUQ WORM!
Windows spoolservr Service
Added by the SDBOT-AAN WORM!
Windows Spoolsre Service
Added by the SDBOT-AAE WORM!
Windows Spoolsrv Service
Added by the SDBOT-ZS WORM!
windows spoolsrv service
Added by the SDBOT-AWV WORM!
Windows Spoolsurf Service
Added by the SDBOT-ZZ WORM!
Windows SpooltPrint Service
Added by the SDBOT-AYE WORM!
Windows Spoolvvv Service
Added by the SDBOT-AAW WORM!
Windows spyware remover
Added by the SystemPoser TROJAN!
Windows sq Drivers
Added by the RBOT-ADI WORM!
Windows SQL management 1.33
Added by the SPYBOT-OB WORM!
Windows Sql Service For Windows 32 Bit
Added by the FORBOT-FC WORM!
Windows SSH Client
Added by the RBOT-AXC WORM!
Windows SSL File
Added by the WOOTBOT.CA WORM!
Windows SSL Secondary Drivers
Added by the SDBOT.ASQ WORM!
Windows Stand Sound Drivers
Added by the SDBOT-XF WORM!
Windows Standard Securty
Added by the RBOT-ALF WORM!
Windows Start Server 2000
Added by the RBOT-AHM WORM!
Windows Startup
GoHip foistware
Windows Startup
GoHip foistware
Windows Startup
Added by the GAOBOT.AO WORM!
Windows Startup
Added by the AGOBOT-MX WORM!
Windows Startup 32 Bits
Added by a variant of the DARKSUN TROJAN!
Windows Storm-Memory Drivers
Added by a variant of the IRCBOT TROJAN! See here
Windows Stortup
Added by the TOGER-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
Windows Streams Server
Added by the SDBOT.LN WORM!
Windows Subsys
Added by the NETSPREE.C WORM!
WINDOWS SVC
Added by the MYTOB-EY WORM!
Windows svchost
Added by a variant of the IRCBOT BACKDOOR!
Windows svchost
Added by a variant of the SPYBOT WORM! See here
Windows svchost
Detected by Kaspersky as the IRCBOT.AYA BACKDOOR! See here
Windows svchost
Detected by Kaspersky as the SDBOT BACKDOOR! See here
Windows svchost
Detected by Trend Micro as the LAMER.AA BACKDOOR! See here
Windows svchost
Added by a variant of the IRCBOT BACKDOOR! See here
Windows svchost
Added by the IRCBOT-ZQ WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
Windows svchost
Detected by McAfee as the PUSHBOT.A WORM! See here
Windows svchost
Added by a variant of the IRCBOT BACKDOOR! See here
Windows Svchost Authority
Added by the RBOT-UA WORM!
Windows Svshost Service Update 32
Added by the FORBOT-GD WORM!
Windows SYN Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
Windows SyncroAd
Windupdates adware variant
WINDOWS SYSTEM
Added by the MYTOB.DF WORM!
WINDOWS SYSTEM
Added by the MYTOB.EO WORM!
WINDOWS SYSTEM
Added by the MYTOB.GC WORM!
WINDOWS SYSTEM
Added by the MYTOB.EH WORM!
WINDOWS SYSTEM
Added by the MYTOB-L WORM and variants!
WINDOWS SYSTEM
Added by the MYTOB-BY WORM!
WINDOWS SYSTEM
Added by the MYTOB-EP WORM!
WINDOWS SYSTEM
Added by the MYTOB-CX WORM!
WINDOWS SYSTEM
Added by the MYTOB-BY WORM!
WINDOWS SYSTEM
Added by the MYTOB.FU WORM!
WINDOWS SYSTEM
Added by the MYTOB-BR WORM!
WINDOWS SYSTEM
Added by the MYTOB.DJ WORM!
WINDOWS SYSTEM
Added by the MYTOB.DJ WORM!
WINDOWS SYSTEM
Added by the MYTOB.DV WORM!
WINDOWS SYSTEM
Added by the MYTOB-BY WORM!
WINDOWS SYSTEM
Added by the MYTOB.FA WORM!
WINDOWS SYSTEM
Added by the MYTOB-DN WORM!
WINDOWS SYSTEM
Added by the MYTOB.EP WORM!
WINDOWS SYSTEM
Added by the MYTOB.GB WORM!
WINDOWS SYSTEM
Added by the MYTOB-DM WORM!
WINDOWS SYSTEM
Added by the MYTOB.HH WORM!
Windows System
Added by the RBOT-AEF WORM!
WINDOWS SYSTEM
Added by the MYTOB.EK WORM!
WINDOWS SYSTEM
Added by the MYTOB.EU WORM!
WINDOWS SYSTEM
Added by the MYTOB-BQ WORM!
WINDOWS SYSTEM
Added by the MYTOB.CZ WORM!
Windows System
Added by the MYTOB-IS WORM!
WINDOWS SYSTEM
Added by the MYTOB.JU WORM!
WINDOWS SYSTEM
Added by the ZOTOB WORM!
WINDOWS SYSTEM
Added by the MYTOB.HU WORM!
WINDOWS SYSTEM
Added by the MYTOB.IK WORM!
WINDOWS SYSTEM
Added by the ZOTOB.C WORM!
WINDOWS SYSTEM
Added by the MYTOB-EG WORM!
WINDOWS SYSTEM
Added by the MYTOB-EI WORM!
WINDOWS SYSTEM
Added by the ZOTOB-I WORM!
WINDOWS SYSTEM
Added by the ZOTOB-G WORM!
WINDOWS SYSTEM
Added by the MYTOB-FI WORM! Note the upper case "i" and number "0" in the filename
WINDOWS SYSTEM
Added by the MYTOB-FX WORM!
WINDOWS SYSTEM
Added by the MYTOB.LB WORM!
WINDOWS SYSTEM
Added by the MYTOB-FQ or MYTOB-FU WORMS!
WINDOWS SYSTEM
Added by the MYTOB.LM WORM!
WINDOWS SYSTEM
Added by the MYTOB.DP WORM!
WINDOWS SYSTEM
Added by the MYTOB.IG WORM!
WINDOWS SYSTEM
Added by the MYTOB.IC WORM!
WINDOWS SYSTEM
Added by the MYTOB-KD WORM!
WINDOWS SYSTEM
Added by the MYTOB-KH WORM!
Windows System 32
Added by the RBOT-FTR WORM!
Windows System 32-Bat Service
Added by the MYTOB.FI WORM!
Windows System Backup
Unidentified malware
WINDOWS SYSTEM By FEnR
Added by the MYTOB.LR WORM!
WINDOWS SYSTEM Cleaner
Added by the MYTOB.EQ WORM!
WINDOWS SYSTEM CLEANER
Added by the MYTOB.ET WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%
Windows System Configuration
Added by the RETHE-A WORM!
Windows System Configuration
Added by the OPANKI-AB WORM!
Windows System Configuration
Added by the WISDOOR.Z TROJAN!
Windows System Configuration
Added by the DOMWIS-E TROJAN!
Windows System Configuration
Added by the SOLUFINA TROJAN or the DOMWIS-J WORM!
Windows System Configuration
Added by the AGOBOT.OP WORM!
Windows System Configuration
Added by the AGOBOT-TE WORM!
WINDOWS SYSTEM Dns
Added by the MYTOB.EY WORM!
WINDOWS SYSTEM DNSPOOL
Added by the MYTOB.FW WORM!
Windows System Drivers
Added by a variant of the IRCBOT TROJAN! See here
Windows System File
Added by the SPYBOT.KHO WORM!
WINDOWS SYSTEM FILE
Added by the MYTOB.DK WORM!
Windows System Gateway
Added by a variant of the RBOT WORM!
Windows System Init
Added by a variant of the RBOT WORM!
Windows System Manager
Added by the RBOT-AN WORM!
Windows System Manager
Added by the SDBOT.MG WORM!
Windows System Manager
Added by the MYTOB.AL WORM!
Windows System Manager
Added by a variant of the RBOT WORM!
Windows System Manager
Added by the RBOT-AFH WORM!
WINDOWS SYSTEM MANAGER
Added by the MYTOB-LY WORM!
Windows System Manager
Detected by Trend Micro as the IRCBOT.BJG TROJAN! See here
Windows System Manager Loader
Added by the AGOBOT.TF WORM!
Windows System Manager Proc
Added by the RBOT.JH WORM!
WINDOWS SYSTEM MEMORY LOADER
Added by the MYTOB-IN WORM!
WINDOWS SYSTEM mscdvvs
Added by the MYTOB.MD WORM!
windows system notepad
Added by a variant of the RBOT WORM!
Windows System Restore Configuration
Added by a variant of the SPYBOT WORM!
Windows System Restorer
Added by the DULOAD.C WORM!
WINDOWS SYSTEM SCALPE
Added by the MYTOB_HI WORM!
Windows System Security
Added by the RBOT.IV WORM!
Windows System Security
Added by the RBOT-AOL WORM!
Windows System Security Monitor
Added by the PINKTON.A WORM!
Windows System Serivce
Added by the RBOT.ACA WORM!
windows system service
Added by the RBOT-MR WORM!
Windows System Service
Added by the SPYBOT.ANDM WORM!
Windows System Tray
Iambigbrother monitoring software
Windows System Tray
Added by an unidentified VIRUS, WORM or TROJAN!
WINDOWS SYSTEM UPDATE
Added by the MYOTB-EH WORM!
Windows System Update Tools
Detected by Kaspersky as the VANBOT.CX TROJAN! See here
Windows System32
Added by the MYTOB.GD WORM!
Windows System32
Added by the SDBOT-AHS WORM!
Windows System32
Added by the RBOT-AZO WORM!
Windows System32
Added by the OPANKI-V WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is also copied to %System%
Windows System32
Added by the SDBOT-ALI WORM!
Windows SYSTEM32
Added by the SPYBOT.ZH WORM!
Windows System32
Added by a variant of the RBOT WORM!
Windows System32 Kernel
Added by the SDBOT-AAT WORM!
WINDOWS SYSTEMn
Added by the MYTOB-EL WORM!
Windows Systemnmg
Added by the MYTOB.S WORM!
Windows Systems16
Added by a variant of the SDBOT WORM!
Windows Sz Host
Added by a variant of the SDBOT WORM!
Windows Task Manager
Added by the QUATERS.A WORM!
Windows Task Manager
Unidentified malware, either a variant of the RBOT WORM or part of a Casino Palazzo foistware install
Windows Task Manager
Added by the MYTOB.AV WORM!
Windows Task Manager
Added by the MYTOB.BJ WORM!
Windows Task Manager
Browser hijacker - identified by DrWeb antivirus as "Trojan.StartPage.601"
Windows Task Manager
Added by the RBOT-ANM WORM!
Windows Task Manager Emulator
Added by the SPYBOT-FA WORM!
Windows Task Mgr
Detected by Trend Micro as the IRCBOT.UN TROJAN! See here
Windows Task Mgr!
Detected by Trend Micro as the IRCBOT.OE TROJAN! See here
Windows Task Scheduler
Added by an unidentified WORM or TROJAN!
Windows Task Service (32-bits)
Added by the DREFIR.D WORM!
Windows TaskAd
Windupdates adware variant
Windows Taskbar Manager
Added by the PROTORIDE-H WORM!
Windows Taskbar Manager
Added by the PROTORIDE.B WORM!
Windows Taskbar System
Added by a variant of the SDBOT WORM!
Windows Taskmanager
Added by the KELVIR.E WORM!
Windows Taskmanager
Added by a variant of the IRCBOT TROJAN! See here
Windows Taskmanager
Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe)
Windows Taskmanager
Added by a variant of the IRCBOT BACKDOOR! See here
Windows Taskmanager
Added by the IMBOT.AC WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
Windows Taskmanager
Added by a variant of the IRCBOT BACKDOOR! See here
Windows Taskmanager
Added by a variant of the IRCBOT BACKDOOR!
Windows Taskmanager
Detected by Kaspersky as the IRCBOT.DHR BACKDOOR! See here
Windows Taskmanager
Added by a variant of the IRCBOT BACKDOOR! See here
Windows Taskmanager
Added by a variant of the IRCBOT BACKDOOR! See here
Windows Taskmanager
Added by a variant of the IRCBOT BACKDOOR! See here
Windows TCP/IP
Added by the AGOBOT-ZH WORM!
Windows Telnet Server
Added by the AGOBOT-MW WORM!
Windows Temperate Services
Detected by Trend Micro as the SLENFBOT.AT WORM! See here
Windows Terminal Manager
Added by a variant of the IRCBOT TROJAN!
Windows Time
Added by a variant of the RBOT-YK WORM!
Windows Time
Added by the RBOT-XC WORM!
Windows Time Server
Added by the SPYBOT.DNC WORM!
Windows Time Service Diagnostic Tool
Detected by Trend Micro as the RBOT.FTV BACKDOOR! See here
Windows TM
Added by a variant of the RBOT WORM!
Windows TM
Added by a variant of the RBOT WORM!
Windows TM
Added by a variant of the RBOT WORM!
Windows TM
Added by a variant of the RBOT WORM!
Windows Tracking Client
Added by the AGENT-GMB TROJAN!
Windows UDP Control
Added by a variant of the SDBOT WORM! See here
Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
Windows UDP Control Center
Added by the AGENT-IEE TROJAN!
Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR!
Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
Windows UDP Control Center
Detected by Kaspersky as the SDBOT.EBA BACKDOOR! See here
Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR!
Windows UDP Control Center
Detected by Kaspersky as the AGENT.WOH TROJAN! See here
Windows UDP Control Center
Detected by Kaspersky as the SDBOT.EBA BACKDOOR! See here
Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
Windows UDP Control Center
Detected by Kaspersky as the SDBOT.EBA BACKDOOR! See here
Windows UDP Control Center
Added by the LDPINCH-RZ TROJAN!
Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
Windows UDP Control Center
Detected by Trend Micro as the DROPPER.CMV TROJAN! See here
Windows UDP Control Center
Detected by Trend Micro as the SDBOT.GAV WORM! See here
Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! See here
Windows UDP Control Manager
Added by a variant of the SPYBOT WORM! See here
Windows UDP Control Services
Added by the ANTIAV-C TROJAN!
Windows Upate
Added by the HAKO TROJAN! Note - this is NOT the Windows system file of the same name as described here
Windows Update
Added by the NORIO TROJAN! Acts as a hi-jacker redirecting to adult content sites
Windows Update
Added by the GAOBOT.AP WORM!
windows update
Added by the LEOX TROJAN!
Windows Update
Added by the AGOBOT.ML WORM!
Windows Update
Wengs adware
windows update
Added by the LEOX.B WORM!
Windows Update
Added by a variant of the SPYBOT WORM!
Windows Update
Added by a variant of the AGOBOT/GAOBOT WORM!
Windows Update
Added by the BAYROB-A TROJAN!
Windows Update
Added by the RBOT-GU WORM!
windows update
Added by the RBOT-PO WORM!
windows update
Added by the RBOT.XZ WORM!
Windows Update
Added by the FRUCTA TROJAN!
Windows Update
Added by the GAOBOT.BUU WORM!
Windows Update
Added by the RBOT-RB WORM!
windows update
Added by the RBOT.ADG WORM!
Windows Update
Added by the DELF-FN TROJAN!
Windows Update
Added by the RBOT-EM WORM!
Windows Update
Added by the RBOT.UM WORM!
windows update
Added by the RBOT-OF WORM!
Windows Update
Added by the SDBOT-WS WORM!
Windows Update
Added by the RBOT-AAH WORM!
Windows Update
Added by the SDBOT-XT WORM!
windows update
Added by the LMIR.A TROJAN!
Windows Update
Added by the MOEGA WORM!
windows update
Added by the RBOT-AHN WORM!
Windows Update
Added by the MYTOB-GZ WORM!
Windows Update
Added by a variant of the RBOT WORM!
Windows Update
Added by the MYTOB.GA WORM!
Windows Update
Added by the BANKER-DV TROJAN!
Windows Update
Added by the RBOT-ALK WORM! Note - this file has nothing to do with Windows updates or MSN
Windows Update
Added by the RBOT-AKU WORM! Note - do not confuse with the Quicken file of the same name as described here
windows update
Added by the LEGMIR-AU WORM!
Windows Update
Added by the BANCD-A TROJAN!
Windows update
Adware downloader - Istbar related
Windows Update
Added by the BANCBAN-FC TROJAN and variants!
Windows Update
Added by the BANKER-HM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
Windows Update
Added by the RBOT-AXS WORM!
Windows Update
Added by the BANCD-B TROJAN!
Windows Update
Added by the BANKER-IB TROJAN!
Windows Update
Added by the BANKER-XB TROJAN!
Windows Update
Added by the DASHER.A WORM!
windows update
Added by the LEGMIR-AO TROJAN!
Windows Update
Added by the RBOT-GJP WORM!
Windows Update
Added by a variant of the SDBOT WORM!
Windows Update
Added by the SPYBOT.AHC WORM!
Windows Update
Added by the SRAMLER.C WORM!
Windows Update
Added by the DEDMIR-A WORM!
Windows Update
Added by the KOBOT-C WORM!
Windows Update
Detected by PCTools as the SDBOT.FTK WORM! See here
Windows Update
Added by a variant of the RBOT WORM!
Windows Update
Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not a valid McAfee program
Windows Update
Added by an unidentified WORM or TROJAN! See here
Windows Update
Added by a variant of the SPYBOT WORM! See here
Windows Update
Added by a variant of the IRCBOT BACKDOOR! See here
Windows Update
Added by a variant of the IRCBOT BACKDOOR!
Windows Update
Detected by Kaspersky as the BUZUS.RYI TROJAN! See here
Windows Update 32
Added by the FORBOT-FI WORM!
Windows Update 32
Added by the FORBOT-FW WORM!
Windows Update 32
Added by a variant of the FORBOT WORM!
Windows Update 63
Added by the FORBOT-GA WORM!
Windows Update 64
Added by a variant of the FORBOT WORM!
Windows Update 64
Added by the FORBOT-FP WORM!
Windows Update Auto Update
Added by a variant of the SPYBOT WORM!
Windows Update Automation
Added by a variant of the RBOT WORM!
Windows Update AutoUpdate Client
Added by a variant of the RBOT WORM!
Windows Update AutoUpdate Client
Added by the LAZAR.B TROJAN! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup!
Windows Update AutoUpdate Client Product
Added by the AGOBOT.ACL WORM!
Windows Update Center
Added by the STUBBOT.A WORM!
Windows Update Center
Added by an unidentified WORM or TROJAN!
Windows Update Check
Added by the SMALL.LU TROJAN!
Windows Update Checker
Adware downloader trojan
Windows Update Checker
Added by the SDBOT-AEF WORM!
Windows Update Checker
Added by a variant of the Win32.Small TROJAN!
Windows Update Checker
Added by a variant of the Win32.Small TROJAN!
Windows Update Client
Added by the SMALL-RN TROJAN!
Windows Update Client Service
Added by the AGOBOT-MM TROJAN!
Windows update config
Added by the SDBOT-PF WORM!
windows update configurator
Added by a variant of the SPYBOT WORM!
Windows Update Controller
Added by the BATTRY-A TROJAN!
Windows Update Draven
Added by a variant of the SDBOT WORM!
Windows Update Drive
Added by a variant of the SDBOT WORM!
Windows Update Files
Added by an unidentified VIRUS, WORM or TROJAN! Note - wupdmgr.exe is the real Windows Update
Windows Update Firewall System
Added by the RBOT-GAN WORM!
Windows Update Firewall System
Added by the RBOT-EEO WORM!
Windows Update GUI Executable x32x
Added by the RBOT.CXY WORM!
Windows Update Host
Added by a variant of the SDBOT WORM!
Windows Update IPv6 Layer
Added by the RBOT.DUD WORM!
Windows update loader
Added by the BRAVE-A TROJAN!
Windows Update Manager
Added by the RANDEX.BTB WORM!
Windows Update Manager
Added by the AGENT-BO TROJAN!
Windows Update Manager
Added by a variant of the RBOT WORM!
Windows Update Manager
Added by the MYBOT WORM!
Windows Update Manager
Added by a variant of the IRCBOT TROJAN!
Windows Update Manager for NT
Added by the SDBOT.AH WORM!
Windows Update Monitoring Service
Added by the RBOT-PL WORM!
Windows Update Process
Added by the SDBOT-CB WORM!
Windows Update Service
Added by the AGOBOT-NI WORM!
Windows Update Service
Added by the SDBOT.QY WORM!
Windows Update Service
Added by the SDBOT-ZH WORM!
Windows Update Service
Added by the RBOT-ALC WORM!
Windows Update Service
Identified by BitDefender as a variant of the PEED TROJAN!
Windows Update Service
Added by the AGOBOT.NI WORM!
Windows Update Service 2004/2005
Added by the RBOT-JE WORM!
Windows Update services
Added by a variant of the RBOT WORM!
Windows Update Services
Added by a variant of the RBOT WORM!
Windows Update Software
Added by the TOFGER.BX TROJAN!
Windows Update Svc
Added by the AGENT.BTF TROJAN! Note - installs "ContraVirus", a misleading spyware remover using false positives as goad to purchase - see here
Windows Update System
Added by the IRCBOT.DN WORM!
Windows Update System Shell
Added by the RBOT-AAZ WORM!
Windows Update V6
Added by the RBOT-KT WORM!
Windows Update.exe
Homepage hijacker
Windows Updated
Added by the RBOT-APM WORM!
Windows Updated
Added by the RBOT-AYB WORM!
Windows Updater
Added by a variant of the DOS.AUTOCAT TROJAN!
Windows Updater
Added by the RBOT-TN WORM!
Windows Updater
Added by the RBOT-VS WORM!
Windows Updater
Added by the WOOTBOT.AJ WORM!
Windows Updater
Added by the FORBOT-JG WORM!
Windows Updater Online
Added by a variant of the RBOT WORM!
Windows Updater Servc
Added by the AGENT.BTF TROJAN! Note - installs "ContraVirus", a misleading spyware remover using false positives as goad to purchase - see here
Windows Updater Service Manager
Added by a variant of the IRCBOT BACKDOOR!
Windows Updater Services
Added by a variant of the RBOT WORM!
Windows Updates
Added by a variant of the SDBOT WORM!
Windows Updates
Added by the MYTOB.CE WORM!
Windows Updates
Added by the SDBOT-BFW WORM!
Windows Updates Agent
Detected by Trend Micro as the SPYBOT.HW WORM! See here
Windows Updating Service
Added by the RBOT-ALW WORM!
Windows Updtee Mgnr
Added by the MYTOB.DC WORM!
Windows USB 2.0 Driver
Added by the RBOT-BKG WORM!
Windows USB 2.0 Driver
Added by the RBOT-BIW WORM!
Windows USB Control Driver
Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%
Windows USB controler
Added by the RBOT-HR WORM!
Windows USB Driver Support
Added by a variant of the SPYBOT WORM!
Windows USB Monitor
Detected by Trend Micro as the IRCBRUTE.AQ TROJAN! See here
Windows USB Printer
Added by a variant of the RBOT WORM!
Windows USB Printer
Detected by Trend Micro as the RBOT.BKC TROJAN! See here
Windows USB Printer
Added by a variant of the SPYBOT WORM! See here
Windows USB Service
Added by the MYTOB.AR WORM!
Windows USB v3
Added by a variant of the SDBOT WORM!
Windows USBD
Added by an unidentified WORM or TROJAN!
Windows User Mode Driver Manager
Added by the SDBOT-ZN WORM!
Windows User Starter
Added by the RBOT.SN WORM!
Windows Version Check
Version checker for CyberAudioLibrary - "a new way to exchange information through the Internet"
Windows Version Service
Added by a variant of the IRCBOT TROJAN! See here
Windows video
Added by a variant of the AGOBOT/GAOBOT WORM!
Windows Video Acquisition (WVA)
Added by the AGOBOT.YM WORM!
Windows Video Component
Added by a variant of the IRCBOT TROJAN!
Windows Video Drivers
Added by the GAOBOT.AZT WORM!
Windows Video Input
Detected by Kaspersky as the SUURCH.CG TROJAN! See here
Windows Virtual Services
Detected by Trend Micro as the SLENFBOT.V WORM! See here
Windows Virtual Services
Detected by Trend Micro as the SLENFBOT.U WORM! See here
Windows Virus Control
Added by the SDBOT-ACZ WORM!
Windows Virus Scanner
Added by a variant of the IRCBOT TROJAN! See here
Windows Vista Corparation Agent Services
Added by a variant of the IRCBOT TROJAN!
Windows Volume Control
Added by a variant of the IRCBOT TROJAN! See here
Windows Web Services
Added by the DLOADER-NY TROJAN!
Windows Web Services
Added by the DLOADER-NY TROJAN!
Windows Web Services
Added by the DLOADER-NY TROJAN!
Windows Web Services
Added by the DLOADER-NY TROJAN!
Windows Web Services
Added by the DLOADER-NY TROJAN!
Windows Web Services
Added by the DLOADER-NY TROJAN!
Windows Web Services
Added by the DLOADER-NY TROJAN!
Windows Web Services
Added by the DLOADER-NY TROJAN!
Windows Winhlp32 Stub Service
Added by the AIMBOT.AH TROJAN!
Windows WKS
Added by the SDBOT-DK WORM!
Windows WKS Services
Added by a variant of the IRCBOT BACKDOOR! See here
Windows WMF Fix
Added by the RBOT-FTQ WORM!
Windows Workstation
Added by a variant of the RBOT WORM!
Windows Workstation
Added by a variant of the SDBOT WORM!
Windows Workstation Service
Added by unknown malware
Windows Workstation Service
Added by the IRCBOT-AAI WORM!
Windows Workstation Service (32-bits)
Added by a variant of the SDBOT WORM!
Windows Workstation Start Service
Added by a variant of the RBOT WORM!
Windows Xp
Added by the MYTOB-DZ WORM!
Windows xp
Detected by Trend Micro as the RBOT.VH TROJAN! See here
Windows XP Automatic Update
Added by the RBOT-AFC WORM!
Windows Xp Service Pack 2
Added by the XPLOS-A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
Windows XP SP2 KeyGen
Added by the TIBICK-C WORM!
Windows Zero Spooler
Detected by Kaspersky as the IRCBOT.ALO TROJAN! See here
Windows-System
Added by the LOGPOLE.C WORM!
Windows-TCP-IP
Added by the GIPMA TROJAN!
Windows-XP-Service-Pack
Added by the SDBOT-AAC WORM!
windows16
Added by the XU TROJAN!
Windows32
Added by the AGOBOT-LK or AGOBOT-ND WORMS! Note - this is NOT the Windows system file of the same name as described here
windows32
Added by the XU TROJAN!
Windows32
Added by the BRATLE.B WORM!
Windows32
Unknown malware
Windows32 Configuration Loader
Added by the SDBOT-ABX WORM!
Windows32 Messenger Service
Added by the RBOT.ANS WORM!
Windows32 Net Database
Added by the RBOT-AAL WORM!
Windows32 Serivces
Added by the SPYBOT.AAF WORM!
WindowsACEbar
BarACE adware
WindowsAgent
Added by the GOP.G WORM!
WindowsAgent
Added by the GOP keyboard logger/TROJAN!
WindowsAPI.DLL
Added by the "Fear and Hope" TROJAN!
WindowsAudio
Added by the AGENT-TH WORM!
WindowsBackup
Added by the STANG WORM!
WindowsBool
Added by the SDBOT-CNG WORM!
WindowsCRC
Added by the SDBOT-VU WORM!
WindowsCriticalUpdate
Added by the ASTEF or RESPAN WORMS!
WindowsD
Added by the MSNDIABLO.A WORM!
WindowsDiskEvt
Added by the NANINF.D TROJAN!
WindowsDiskLog
Added by the STINX-C or STINX-D TROJANS!
WindowsFileSystem
Added by the RBOT-FMQ WORM!
WindowsFirewallSvc
Added by a variant of the SDBOT WORM!
WINDOWSflashbrg
Added by a variant of the AGENT-IC TROJAN!
WindowsFY
Part of a "Security IGuard" parasite infestation - also detected as DESKTOPHIJACK
WindowsFY
Added by a variant of the DESKTOPHIJACK TROJAN! For removal see here
WindowsFY
Added by the FAKEALE-E TROJAN!
WindowsFZ
Added by the DESKTOPHIJACK VIRUS! Also see DESKTOPHIJACK.B TROJAN!
WindowsFZ
Variant of the SmitFraud alias FAKEALE-C TROJAN!
WindowsFZ
Variant of the SmitFraud alias FAKEALE-C TROJAN!
WindowsIPRelay
Added by the IRCBOT-AAA WORM!
WindowsK
Added by the MSNDIABLO.A WORM!
WindowsKeyUpdate
Added by the JOSAM WORM!
WindowsMGM
Added by the SOBIG.A WORM and LALA.C TROJAN!
WindowsProtocolLog
Added by the NANINF.C TROJAN!
WindowsReg% update
Added by the RBOT-HH WORM!
WindowsRegistration
Added by the RBOT-NO WORM!
WindowsRegKey Autoupdate
Added by a variant of the RBOT WORM!
WindowsRegKey upd4te2d4te
Added by the RBOT.XQ WORM!
WindowsRegKey update
Added by the RBOT-QJ WORM!
WindowsRegKey update
Added by the RBOT.IE WORM!
WindowsRegKey update
Added by the RBOT.LW WORM!
WindowsRegKey update
Added by the RBOT.QT WORM!
WindowsRegKey update
Added by the RBOT.ADB WORM!
WindowsRegKey update
Added by the RBOT.IF WORM!
WindowsRegKey update
Added by the SDBOT.QX WORM!
WindowsRegKey update
Added by the SDBOT.PU WORM!
WindowsRegKey update
Added by the RBOT-MM WORM!
WindowsRegKey update
Added by the RBOT-OO WORM!
WindowsRegKey update
Added by the RBOT-JY WORM!
WindowsRegKey update
Added by the RBOT-AGW WORM!
WindowsRegKey update XP
Added by the RBOT-ABM WORM!
WindowsRegKey%$ update
Added by the RBOT-IX WORM!
WindowsRegKey%update
Added by the RBOT-EN WORM!
WindowsRegKeys update
Added by the SDBOT.WE WORM!
WindowsService
Added by the VUNDO-X TROJAN!
WindowsSetup
Added by the EZBOT TROJAN!
WindowsSp2
Added by the POSSE WORM!
WindowsSystem32
Added by the AGENT-EFP TROJAN!
WindowsSystem32
Added by the AGENT-EDA TROJAN!
WindowsSystem32
Added by the SDBOT-DFG WORM!
WindowsSystem32
Detected by Kaspersky as the AGENT.ALY TROJAN! See here
windowstime.exe
Added by the AQV TROJAN!
WindowsTranslator
Delta Translator® English Portugese (Brazilian) version - "an automatic, bi-directional machine translation software system that quickly and automatically translates multiple pages, paragraphs, sentences, phrases or just individual words in documents, letters, memos, faxes, reports, manuals, booklets, publications, spreadsheets, e-mail and even web pages as you browse the Internet"
WindowsTranslator_Espanhol
Delta Translator® Spanish Portugese (Brazilian) version - "an automatic, bi-directional machine translation software system that quickly and automatically translates multiple pages, paragraphs, sentences, phrases or just individual words in documents, letters, memos, faxes, reports, manuals, booklets, publications, spreadsheets, e-mail and even web pages as you browse the Internet"
WindowsUpd
VirtuMonde adware
WindowsUpd1
VirtuMonde adware
WindowsUpd2
VirtuMonde adware
WindowsUpdate
Added by the LOFNI WORM!
WindowsUpdate
Added by the ASTEF or RESPAN WORMS or AGENT-V TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
windowsupdate
Added by the IRCBOT.B TROJAN!
WindowsUpdate
Added by the MADDIS.B WORM!
windowsupdate
Added by the WARPI WORM!
WindowsUpdate
Added by the IK TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
WindowsUpdate
Added by an unidentified WORM or TROJAN!
WindowsUpdate
Added by the DUPA-B TROJAN!
WindowsUpdate
Added by the COBFINN_B TROJAN!
WindowsUpdate
Added by the CULLER-C WORM!
WindowsUpdate
Added by the CULLER-D WORM!
Windowsupdate
Detected by Kaspersky as the BANKER.ARK TROJAN! See here
Windowsupdate
Added by a variant of the IRCBOT BACKDOOR!
WindowsUpdate renew
Added by the AGENT.QG TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%
WindowsUpdate Service
Added by the RBOT-NR WORM!
Windowsupdate Service
Added by the BABA-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root folder (ie, C:\)
WindowsUpdateDirect
Added by the DUPA-C TROJAN!
WindowsUpdatem1
Added by the AGENT-AAJ TROJAN!
WindowsUpdatem2
Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
WindowsUpdateManager
Detected by Trend Micro as the AGENT.VUX TROJAN! See here
WindowsUpdateNT
Added by the SHELLOT-B TROJAN!
WindowsUpdateR
Added by the COBFINN_B TROJAN!
WindowsWelcomeCenter
Shows the Welcome Center every time you boot into Windows Vista
WindowsXP Module
Malware, reportedly a keylogger - see here
WindowsXp Security
Added by the RBOT-GRK WORM!
WindowsXP Update
Added by the RBOT-PB WORM!
WindowsXPserv
Addee by the NANINF-A TROJAN!
windowsxxx
Added by the DUBING-A TROJAN!
windowsxxx2
Added by the DUBING-A TROJAN!
Windows_LowLevel_Security_Core
Added by the PADMIN-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "Repair" subfolder of the Winnt or Windows folder
Windows_Protect
Added by a variant of the RBOT WORM!
Windows_Protect
Added by a variant of the RBOT WORM!
Windows_Protect
Added by the RBOT.ARO WORM!
Windows_Protect
Added by the RBOT-ADK WORM!
Windows_Serivce
Added by the WOOTBOT.AH WORM!
Windows_Updates
Added by a variant of the SPYBOT WORM!
Windows_VXD
Added by the PPORT TROJAN!
Windowz
Added by the NUKIP WORM!
Windowz Update V2.0
Added by the YODO WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
Windowz Update V2.0
Added by the YODO-C WORM!
Windoxs Update Center
Added by a variant of the SDBOT WORM!
WinDrg32
Added by the DRUDGEBOT.A WORM!
WinDriv32
Added by the SMALL-BA TROJAN!
WinDriver Configuration
Added by the AGOBOT-LX TROJAN!
WinDrives
Added by the SMALL.DIG WORM!
WINDRUN
Added by the MYTOB-BT WORM!
windrv
Added by an unidentified VIRUS, WORM or TROJAN! - possibly a strain of OBLIVION or BIONET
WinDrv
Added by a variant of the TIBSER.A downloader TROJAN!
Winds Sers Agts
Added by a variant of the RBOT WORM!
WinDSL MTU-Adjust
Adjusts the registry setting of the DUN-Adapters (MTU) and the TCP/IP-Protocol (RWIN) by ENGEL Technologieberatung
WinDSL_MTU
May be realted to Tiscali broadband, if so is it required?
WinDSNX
Added by the DSNX TROJAN!
Windstream Broadband Check-up Center
Part of the Windstream Broadband service from AllTel. "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". ALLTEL Instant Support is required to run with the Help and Support program. If you uncheck it and and then run Help and Support it will add another ALLTEL Instant Support in the startup menu. If you remove ALLTEL Instant Support in add/remove programs some help menus in help and support will not be available. You decide
WindUpdates
Added by the AGENT.BF TROJAN!
WindUpdates
Windupdates adware variant
WINDVDpatch
CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative's sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a "leave alone" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it
WinDVR SchSvr
WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs
WinDVRCtrl
Control center software for an AOpen VA1000 TV tuner card
Windws Configuration Loader
Added by the SODABOT WORM! Note - the executable is spelt with a lower case "L" rather than an lower or upper case "i" which is the case with Internet Explorer
WinDynManager
Added by the SDBOT-IA BACKDOOR!
winenv
Added by a variant of the SDBOT WORM!
WinEssential
Hijacker - hailing from jraun.com
WinEssential
Jraun adware
WinEx
Added by the MSNOPT-A TROJAN!
WinExec
Added by the AINESEY.A WORM!
WinExec
Added by the FALUS-A WORM!
WinExec
Added by the CRUTLE-B WORM! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
WinExec32
Added by the KAZWIN WORM!
WinFast Schedule
Leadtek WinFast TV tuner scheduler and remote control driver - required if you use the latter
Winfast2KLoadDefault
Loads default settings for Leadtek Winfast graphics cards
WinFastDTV
Scheduler for WinFast DTV digital TV cards from Leadtek Research Inc
Winfast_2K
System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card
WinFast_Gamma
Loads if you change the gamma settings on Leadtek WinFast graphics cards
WinFast_Taskbar
Loads default settings for Leadtek WinFast graphics cards
WinFavorites
Loudmarketing.com adware downloader
WinFax PRO
WinFax PRO from Symantec - fax management software
WinFax PRO Controller
From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
WinFaxAppPortStarter
WinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application.
WinFire
Added by the DELF-SY TROJAN!
WinFix service
Added by the RBOT-FAE WORM!
WinFixer 2005
WinFixer web installer. Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
WinFixer helper
WinAntiSpyware 2005 by Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
WinFixer service
Added by a variant of the SDBOT WORM!
WinFixer2006
WinFixer web installer. Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
WinFlyer32.dll
Added by the WINFLYER TROJAN!
winfont
Added by the DEATH TROJAN!
winform
Added by the PWS-ALB TROJAN!
WinFoxV2
System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card
WinFX
Added by the AGOBOT.FX WORM!
WinGate Engine Monitor
WinGate Internet Client Dialup Monitor - component of WinGate proxy server software. Displays the status of the WinGate engine, and appears in the system tray of each workstation on the network reassuring clients that their workstations have connectivity with the WinGate Server
WinGate initialize
Added by the LOVGATE.F WORM!
wingerver2.0.exe
Added by the GRAYBRD-AE TROJAN!
wingo
Added by the BEAGLE.AW or BEAGLE.AV WORMS!
wingo
Added by the BAGLE-AU WORM!
WinGuage Pro
Part of McAfee Nuts & Bolts. "WinGauge is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious". Resource hog. Available via Start -> Programs
Winguard
Dr Solomon's Virex antivirus
winguard
Added by a variant of the RBOT WORM!
WinGuard Pro
Winguard Pro
WinHacker
WinHacker tweaking utility by Wedge Software. There are far better tweakers and, unlike WinHacker, most are free
Winhelp
Added by the QQPASS.E TROJAN!
WinHelp
Added by the LOVGATE.F WORM! Note - this file is located in %System% whereas the valid one is located in %Windir%
WinHelp
Added by the LOVGATE-F WORM! Note - this is not the legitimate RealPlayer (realsched.exe) application of the same name. This one is located in %System%
Winhelp
Added by the LOVGATE.Z WORM!
winhelp
Added by a variant of the RBOT WORM!
winhelp
Added by the QQPASS-N TROJAN!
Winhelp
Added by the LOVGATE.E WORM!
winhlp.exe
Added by the FORMGLIEDER TROJAN!
winhlp3.exe
Added by a variant of the EASTO.A TROJAN!
Winhlp32
Added by the GANT.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "Msexec32.vbs" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
winhlp32.exe
Added by the EASTO.A TROJAN!
winhlpp32.exe
Added by the GAOBOT.SY WORM!
Winhost
Added by the LOLAWEB.B TROJAN!
Winhost
Added by the DLOADER-AP TROJAN!
Winhost
Added by the DELF-KM TROJAN!
Winhost
Added by the REATLE.F WORM!
winhost.exe
Added by the LOHAV-R TROJAN!
winhost32.exe
Added by the TABDIM TROJAN!
WinHound
WinHound spyware remover - not recommended, see here
WinIeRun
Added by the RNWATCH-A WORM!
WinIFixer
WinIFixer spyware remover - not recommended, see here
winimage
Added by the RBOT.TX WORM!
WinINet
Added by the SOBER-P WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "ConnectionStatus" subfolder of the Windows or Winnt folder
wininet
Added by the STUBBOT-C WORM!
wininet32
Added by the RAZNEW-A TROJAN!
wininetd
Added by the WINET TROJAN!
Winini.dll
Added by the STARTP-M TROJAN!
wininit
Added by the WOLLF.16 TROJAN!
WinInit
Added by the SMALL-PB TROJAN!
winint
Added by the SDBOT-ADA WORM!
winipsec
Unidentified malware
WinIRXHelper
MSI Media Center Deluxe software - see here
winis
Added by the RBOT-WI WORM!
Winjava xml
Added by the HAXDOOR ROOTKIT!
Wink*.exe
Added by a variant of the KLEZ WORM!
Winkb6
Part of We-Blocker - gives parents the opportunity to monitor their children's Internet access and provide them with age-appropriate content, while filtering out sites that contain adult content. Works in conjunction with Winkb6 and both files are needed to run We-Blocker
WinKernel
Added by the MIRAB or SERVIDOR TROJANS!
WinKernel
Added by the PLEA VIRUS!
winkernel32
Added by the BANSAP TROJAN!
WinKey
Loads Copernic's WinKey. Used to map out Windows key hotkey combinations. Not required for the system, but is necessary for this to be running if you use these hotkey combos
winla
Added by the DLOADR-AQL TROJAN!
winldr
Added by the VIDLO-P TROJAN!
winldr
Added by the ACS TROJAN!
winlgn
Related to the Sentry Parental Controls software
winlgz2
Added by the KILLFIL-Q TROJAN!
winlibs.exe
Added by the EVAMAN.C WORM!
WinLibUpdate
Added by the BIONET series of TROJANS such as BIONET.31 or BIONET.310
WinLibUpdate32
Added by the BIONET.405 TROJAN!
WinLibUpdte
Added by the BIONET.318 TROJAN!
Winlink
Added by the GAOBOT.AAY WORM!
Winlme
Added by the GOP.F WORM!
WinLoad
PCTattletale is a surveillance software program that monitors user activity, logs keystrokes, and takes screenshots. Uninstall this software unless you put it there yourself
WinLoader
Added by variants of the SUBSEVEN TROJAN!
winlocatorupdate
Locator adult content toolbar related
winlog
Added by the GAOBOT_DF WORM!
winlog manager
Added by the DONBOMB.A TROJAN!
WINLOG0N
Added by the MYDOOM.BI WORM!
WinLogin
Added by the AGOBOT-IX WORM!
winlogin
Browser hijacker, also detetected as the STARTPA-DF TROJAN!
Winlogin.exe
Added by a variant of the AGENT.AH downloader TROJAN!
winlogin.exe
Added by the AGENT.AH TROJAN!
winlogin.exe
Added by a variant of the AGENT.AH TROJAN!
Winlogin.exe
Added by a variant of the AGENT.AH TROJAN!
winlogoff
Added by the AGOBOT-TR WORM!
winlogon
Hijacker or adult content dialler! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
winlogon
Added by the RANDEX.E WORM!
winlogon
Added by the TRODAL TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
winlogon
Added by the SDBOT.EO WORM!
winlogon
Added by the MASLAN.C WORM!
winlogon
Added by an unidentified WORM or TROJAN!
WINLOGON
Added by the YSPAN.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "WinStart.vbs" file is found in %System%
Winlogon
Added by the VB-EJ TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
Winlogon
Added by the FLOPPY-B VIRUS! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
winlogon
Added by an unidentified WORM or TROJAN!
Winlogon
Added by the PUNYA-B WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
winlogon
Added by a variant of the DELF.CNS TROJAN!
winlogon
Added by the AGENT-ICR TROJAN!
winlogon service
Added by the SPYBOT.EN WORM!
Winlogon Shell
Added by the KIPIS.M WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the "1032" sub-folder
Winlogon.exe
CoolWebSearch parasite variant - resets home page to an adult content site
winlogon.exe
Added by the FAKESPY-A TROJAN!
winlogon.exe
Adware, also detected as the FAKESPY-B TROJAN!
winlogon32_
Added by the RULAND.A WORM!
Winlogun
Added by the P2LOAD-C WORM!
WinLsass
Added by the SCANE WORM!
WinLsass
Added by the SCANE WORM!
winltmpv
Added by the TCXMEDI-C TROJAN!
winltmpv
Added by the TCXMEDI-C TROJAN!
Winmain
One of the first of a new breed of malware. When run it immediately loads MSHTA.EXE from the Windows folder, placing it on "hot standby", ready to accept HTA scripting within a web page and then EXECUTE what is embedded IN the page as a program! In other words, it's possible for a "rogue" website to actually embed trojans, worms and/or viruses directly into a web page. NSClean's HTA Stop offers an easy way to toggle this capabiltity, or rather vulnerability, on and off. I suggest you leave it disabled!
WinManage
Added by a variant of the IRCBOT BACKDOOR! See here
WinManager
??
winmatrix.exe
WinMatrix XP - wallpaper replacement that shows different matrix effects (including flowing matrix codes from 'The Matrix' movie) on your desktop
WinMed
Detected by Trend Micro as the AGENT.AIRF TROJAN! See here
WinMedia
Added by the ZEROBE-A TROJAN!
WinMedia
Added by the INJECT.163 TROJAN!
WinMedia32
Added by the YABE.F TROJAN!
WinMem
WinMem Cleaner - part of Ultra WinCleaner Utility Suite. Makes more memory available for your programs and the Operating System. It also defragments your system
WinMenssage
Added by the BANCOS.B TROJAN!
WinMessenger
Added by the OPANKI-E WORM!
WinMgmt
Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here
winmgmt32.exe
Added by the LUZIA.AD TROJAN!
WINMGR
Added by the MYTOB.AN WORM!
Winmgr.exe
Added by the AGOBOT.AFG WORM!
WinMgr32
Added by the MIMAIL.P WORM!
WinMine
Added by the BISCUIT.A WORM!
winmodem
Software for software based modems. Required if you have one of these. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information
Winmon32
Added by the RBOT-OQ WORM!
WinMoviePlugIn
Sfonditalia adult content premium rate dialer
Winmsg
Added by the GAOBOT.GEN!POLY WORM!
WinMsg
Added by the DLOADR-AS TROJAN!
WinMsrv32
Added by the GAOBOT.AFJ WORM!
WinMX
WinMX file sharing application
winmysqladmin
Starts the MySQL database admin tool
WinMySQLadmin Tool
Starts the MySQL database admin tool
winnet
CommonName Toolbar spyware. To uninstall see here
WinNetDDE
Added by the NETDEPIX.B TROJAN!
WinNite
Added by the OPANKI.B WORM!
winnload
Added by the DOWNLD-ABG TROJAN!
Winnov Menu
Winnov Video Capture Card related. What does it do and is it required?
Winnov Remote
Winnov Video Capture Card related. What does it do and is it required?
Winnov Status
Winnov Video Capture Card related. What does it do and is it required?
winnsvc
Added by the PWS.O TROJAN!
winnt
Added by the MONA-E WORM!
WinNT
Added by the AUTOSKY WORM!
winnt DNS ident
Added by the RBOT-BAU WORM!
winnt DNS ident
Added by a variant of the RBOT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)
winnt DNS ident
Added by the RBOT-ACY WORM!
winnt DNS ident
Added by a variant of the RBOT WORM!
winnt DNS ident
Added by the RBOT.AVU WORM!
winnt DNS ident
Added by a variant of the RBOT WORM!
winnt DNS ident
Added by a variant of the RBOT WORM!
Winnt DNS ident
Added by the RBOT.BAL WORM!
winNT updatc
Added by a variant of the RBOT WORM!
WinNtBB
Added by the DULOAD.C WORM!
Winnup
Added by a variant of the SPYBOT WORM!
winocx32
Added by the PROTORIDE.I WORM!
WINOWS SYSTEM
Added by the MYTOB.ID WORM!
WINP
Added by the SPYBOT-EB WORM!
Winpack
Adware - detected by Kaspersky as the AGENT.GG TROJAN!
WinPatch Protection
Added by an unidentified WORM or TROJAN!
WinPatrol
WinPatrol - "Manage Startup programs, tasks, cookies; will sniff out Worms, Trojan horses, Cookies, Adware, Spyware, Klez, Assumption and other malicious programs"
WinPatrol Explorer
Part of WinPatrol
WinPCDoctor
WinPCDoctor misleading security software - not recommended, see here
winphonics7536
Added by a variant of the MUTIN-C TROJAN!
winpipe
Browser hijacker redirecting to wow-access.com
WinPLOSION
"WinPLOSION allows you to immediately view and select from all the windows running on your computer, just those of the active application, or to minimise all windows and display a clear desktop"
WinPoet
WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking
winpol
Added by the AGENT.IWD TROJAN!
Winpooch
"Winpooch is a Windows watchdog, free and open source. Anti spyware and anti trojan, it gives a full protection against local or external attacks by scanning the activity of programs in real time. Associated with ClamWin antivirus, Winpooch keeps safe your computer against virus"
WinPop
Brudevic A adware
WinPopup
Intranet chat software provided by windows for chat on small networks. Handy little LAN messaging utility. Has been included in Windows since 95, and maybe in WFWG 3.11. Normally it won't set itself up to run unless the user specifically adds it to startup
winpopup
Adware by Tradeexit.com
Winpower
Part of InstallAnywhere from Zero G Software, now owned by Macrovision
Winprocer32 Update
Added by the RBOT.GW WORM!
winprocessor Update
Added by the RBOT.IO WORM!
WinProfile
Added by the BUDDY TROJAN!
WinProfile
Added by the SNDC.A WORM!
winprofile
Added by a variant of the MONCHER WORM!
WinProfile
Added by the CHUM-C TROJAN!
WinProt
Added by the CHUPACABRA TROJAN!
WinProt
Added by the CHUPACABRA TROJAN!
winprotect
Added by the MUGLY.E WORM!
winprotect
Added by the SDBOT-SB WORM!
WinProxy
"WinProxy is the world-first proxy server and a firewall with integrated mail server for Windows 95/98/ME/NT/2000/XP"
Winproxy Personal
Added by the SDBOT.BMF WORM!
winpsd
Added by the MYDOOM.Q WORM!
WinPWD Manager
Added by the RBOT-AUT WORM!
winrapid
Added by a variant of the RBOT WORM!
winrar
CoolWebSearch Therealsearch parasite variant. Note - this is not the file zipping utility also known as WinRAR!
WinRaR Service
Added by an unidentified WORM/TROJAN!
winrarshell
Added by the SALIRA TROJAN!
WinReader
Added by the DELBOT-V WORM!
WinReanimator
WinReanimator spyware remover - not recommended, see here
winReg
Added by the YAHA.H or YAHA.J WORMS!
WinReg32 service
Added by a variant of the SDBOT WORM!
winregsrv
Added by the SYNRG TROJAN!
winreg_32
Added by the BANCOS-CE TROJAN!
winreg_32
Added by the BANKER-DB TROJAN!
winreg_32
Added by the DLOADER-IJ TROJAN!
winreg_32
Added by the BANCOS-CT TROJAN!
WINREMOTE
InterVideo WinCinema Manager - needed for the use of WinDVD Remote Control
Winres32vis
Added by the THRAX.A WORM!
winrestore1
Added by the KILLFIL-Q TROJAN!
winreups
Added by a variant of the RBOT WORM!
winroot
Added by the QQPASS.IA WORM!
winroute
Win-Route 4.27. WinRoute Tray Icon for starting and stopping the WrCtrl.exe process, also to log in to the console to view logs and change settings. Can be unchecked and the engine still runs and functions normally. Can then use provided shortcuts for administration of the program. Loaded in SERVICES on Windows 2k
WinRPC
Added by the BANKER-EEI TROJAN!
winrun
Added by the WINUR WORM! Note - this is not the real msconfig.exe as it's located in C:winrun" X,winrun,winrun.exe,"Added by the WINBUR.B WORM!
WINRUN
Added by the MYTOB.AP WORM!
WINRUN
Added by the MYTOB-AI WORM!
WINRUN
Added by the MYTOB-BX WORM!
WinRun
Added by the LOVELET-AD WORM!
WINRUN z
Added by the MYTOB.BL WORM!
WinRunners
Added by the DULOAD.C WORM!
Wins Loader5
Added by a variant of the IRCBOT TROJAN! Note - doe not confuse with the Polish language Instant Messaging client also called Gadu-Gadu
Wins Service Driver
Added by the RBOT-APV WORM!
Wins Update 32
Added by the FORBOT-FN WORM!
Wins32 Online
Added by the BROPIA.R WORM!
WinScMngr
Added by the SDBOT-BPZ WORM!
WinSec
Added by the AGOBOT.ZF WORM!
winsecure
Browser hijacker, redirecting to specificsearches.com
WinSecure
Added by the AGENT-LR TROJAN!
Winsecure Antivirus
Added by a variant of the SPYBOT WORM!
WinSecureAv
WinSecureAv spyware remover - not recommended, see here
WinSecured32
Added by a variant of the FORBOT WORM!
Winserv
Added by the NODMIN WORM!
winserver
Added by the DELTAD.A WORM!
Winservice
Adult content related malware
winservice
Added by the CVK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
WinService
Added by the DWNLDR-FUX TROJAN!
WinService
Added by the MSNVB-D WORM!
WinService
Added by the SKOWOR-O WORM!
WinService32
007 Spy Software - "stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP"
WinService32
007 Spy Software - "stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP"
WinServices
Added by the YAHA.K or YAHA.M WORMS!
winservices
Added by an unidentified WORM or TROJAN!
winservit
Added by the RBOT.ASG WORM!
winservn
PurityScan/Clickspring adware
winservs
PurityScan/Clickspring adware
WinSetBrowse
Added by the BISCUIT.A WORM!
winsfc
Added by the WISFC VIRUS!
Winshell
Added by the MYTOB.LJ WORM!
Winshoe
Probably an unidentified VIRUS! Adds itself to 3 registry "Run" keys and prevents Task Manager being displayed. This is not the Winshoe IRC Client as the visitor did not have it installed
winshost.exe
Added by the TOOSO WORM and variants!
winshow
Added by the VB-DXP TROJAN!
WinShowUpdate
Winshow parasiate related - from the "RunOnce" keys it replaces "winshow.dll" with a new version
WinSig
Added by the BANKER-FN TROJAN!
winskype
Added by the BROGGER-C TROJAN!
winsock
Added by the SAGE-A WORM! Note - the filename has the digit 0 rather then the uppercase "o"
Winsock driver
Added by the SPYBOT-DM TROJAN!
Winsock driver
Added by the SPYBOT-DR WORM!
Winsock Driver
Detected by Kaspersky as the RBOT.AEU BACKDOOR! See here
Winsock driver
Added by a variant of the IRCBOT BACKDOOR! See here
Winsock Startup
Added by a variant of the SDBOT WORM!
winsock.client
Added by the DIABLO-M TROJAN!
winsock2
Added by the AGOBOT.LY WORM!
Winsock2 driver
Added by the SPYBOT.DR TROJAN!
Winsock2 driver
Added by the SPYBUZZ TROJAN!
Winsock2 driver
Added by the SDBOT.T TROJAN!
Winsock2 driver
Added by the SDBOT.T TROJAN! Note - ZONEALARM.EXE is not the valid Zone Labs firewall program
Winsock2 driver
Added by a variant of the SPYBOT WORM!
Winsock2 driver
Added by the SPYBOT-BX WORM!
Winsock2 driver
Added by the SPYBOT-CM WORM!
Winsock2 driver
Added by a variant of the SPYBOT WORM!
Winsock2 driver
Added by the SPYBOT-CC WORM!
Winsock2 driver
Added by a variant of the SPYBOT WORM!
Winsock2 driver
Added by the SPYBOT-DP WORM!
Winsock2 driver
Added by the SPYBOT.CO WORM!
Winsock2 driver
Added by the SPYBOT-DD WORM!
Winsock2 driver
Added by the SPYBOT-EE WORM!
Winsock2 driver
Added by the SPYBOT-EG WORM!
Winsock2 driver
Added by the SPYBOT.AG WORM!
Winsock2 driver
Added by a variant of the IRCBOT BACKDOOR!
Winsock2 wqr1s
Added by the SPYBOT.KD WORM!
Winsock2.dll
Added by an unidentified VIRUS, WORM or TROJAN!
Winsock32 driver
Added by the SPYBOT.B WORM!
Winsock32 driver
Added by the SPYBOT.B WORM!
Winsock32 driver
Added by the SPYBOT.B WORM!
Winsock32 driver
Added by the IRCBOT-VT TROJAN!
Winsock32driver
Added by the HACARMY TROJAN!
Winsock32driver
Added by the HACKARMY.S TROJAN!
Winsock32driver
Added by the BACKDOOR-AZV TROJAN!
Winsock32driver
Added by the HACKARMY-B TROJAN!
Winsock32driver
Added by the HACARMY.D TROJAN!
Winsock32driver
Added by the HACARMY.F TROJAN!
Winsock32driver
Added by the HACKARMY.9728 TROJAN!
Winsock32driver
Added by the HACKARMY.I TROJAN!
Winsock6 MIC driver
Added by the SPYBOT.AFZ WORM!
winsockdriver
Added by the SDBOT.GEN TROJAN or WARPIGS.C WORM!
winsockdriver
Added by a variant of the SPYBOT WORM!
winsockdriver
Added by the BLATIC.A WORM!
winsockdriver
Added by the SPYBOT-DO WORM!
winsockdriver
Added by the WARPIGS-D TROJAN!
winsockdriver
Added by a variant of the IRCBOT TROJAN! See here
WinSocketComponent
Added by an unidentified VIRUS, WORM or TROJAN!
Winsocks2 driver
Added by a variant of the SDBOT WORM!
WINSOS VERIFY
WinSOS - "deletes spyware, optimizes your computer - backs up selected data"
WinSP
Added by the STARTPA-ME TROJAN!
winspd32dll
Added by a variant of the AGOBOT/GAOBOT WORM!
WinSPF
Added by the MYDOOM.T WORM!
WinSPF
Added by the MYDOOM.S WORM!
Winspl
Added by a variant of the TROLL-A TROJAN!
winsplog
Added by the MAILBOT-CA TROJAN!
Winspool
Added by a variant of the SDBOT WORM!
WinSpyControl
WinSpyControl spyware remover - not recommended, see here
WinSpywareProtect
WinSpywareProtect rogue spyware remover - not recommended, see here
WinSpywareProtect (ver. 5.1)
WinSpywareProtect rogue spyware remover - not recommended, see here
WinSrv
Added by the HOBBIT.F WORM!
WinSrv
Added by the HOBBIT.C WORM!
Winsrv
Added by the OPASERV.T WORM!
winsrv
Added by the NETSNAK-B TROJAN!
winsrv3
Added by the NAFBOT-A TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
WinsSystem
Added by the DELF.IG TROJAN!
WinStabilizer
Added by the AGOBOT-SW WORM!
WinStart
Added by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Connection WizardStatus subfolder of the Windows or Winnt folder
WinStart
From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge
WinStart
Added by the CIAN.C WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "WinStart.vbs" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
WinStart
Added by the PUROL WORM!
WinStart
Added by the CONE.E WORM!
winstart
Added by the SCKEYLO-AB TROJAN!
WinStart001
From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge
WinStart001.EXE
From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge
winstats
Added by the GARGAFX TROJAN!
Winsta~1
GoHip foistware
WinSth16
Added by the CAKE WORM!
winstro
Added by the FTP_ANA TROJAN!
winsupdatesysmngr64
Added by the RBOT-BAG WORM!
WinSvc16.exe
Added by the SDBOT.FQ TROJAN!
Winsvc32
Homepage hijacker
winsvc32.exe
Added by the GREPAGE TROJAN!
Winsvr
Added by the INJECT.163 TROJAN!
Winsvr
Added by the ADCLICK-DK TROJAN!
Winsvr manager
Added by the TIRBOT-C WORM!
winsy32.exe
CoolWebSearch parasite variant
winsync
Added by a variant of the QOOLOGIC TROJAN!
Winsys
Win-Spy keyboard logger/monitoring software - remove unless you installed it yourself
WINSYS
Added by the GOLDPLAY TROJAN!
winsys
Added by an unidentified TROJAN!
WinSys32
Added by the CIGIVIP TROJAN or RECKUS WORM!
winsys32 Driver
Added by the LOONY-O TROJAN!
WinSysAppMon
Home & Family Content Filter related. See here
winsysban
Added by the CLICKER-CD TROJAN!
winsyslog lptt01
RapidBlaster variant (in a "Winsyslog" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
WinSysM
Added by the WINKO.AO WORM!
WinSysModule
Added by the AGENT-DIQ TROJAN!
WinSysStartUpWKbLw
Added by the BACKZAT.G WORM!
WinSyst32
Added by the MORB WORM!
WinSystem
Added by the WHITEBAIT WORM!
WinSystem
CMKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!
winsystem.sys
Added by the SOBER.K TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a msagentwin32 subfolder of the Winnt or Windows folder
WinSystems
Added by the SDBOT-CZT WORM!
winsystems25
Added by the RBOT-CNZ WORM!
winsysupd
Added by the STARTPA-NI TROJAN!
WinSysW
Added by the WINKO.AO WORM!
WINT
PurityScan/Clickspring adware
WINT
PurityScan/Clickspring adware
WINT
PurityScan/Clickspring adware
WinTask
Added by the HIPO or LEMIR.F TROJANS!
WINTASK
Added by the MYTOB.I WORM and variants!
WINTASK
Added by the MYTOB.AU WORM!
WINTASK
Added by the MYTOB.K WORM!
WINTASK
Added by the MYTOB.AQ WORM!
WINTASK
Added by the MYTOB-CH WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)
WINTASK
Added by the MYTOB.BU WORM!
WINTASK
Added by the MYTOB-AR WORM!
WINTASK
Added by the MYTOB-AK WORM!
WINTASK
Added by the MYTOB.EF WORM!
WINTASK
Added by the MYTOB-AO WORM!
WINTASK
Added by the MYTOB.DH WORM!
WINTASK
Added by the MYTOB-HM WORM!
WINTASK DLL
Added by the MYTOB.AI WORM!
WINTASK DLL32
Added by the MYTOB.BS WORM!
WINTASK DLL32
Added by the MYTOB.NI WORM!
WinTask driver
Added by the DLOADER-NA TROJAN!
WINTASK32
Added by the MYTOB.BN WORM!
WINTASK32
Added by the MYTOB.FX WORM!
wintask32
Added by the NAFBOT-A WORM!
WINTASKMANAGER
Added by the MYTOB-AF WORM!
WINTASKMGR
Added by the MYTOB.Q WORM!
WINTASKS
Added by the MYTOB.BO WORM!
WINTASKS
Added by the MYTOB.EZ WORM!
WinTasks DLL Library (32-bits)
Added by the RBOT-AJZ WORM!
WinTasks Traybar
WinTasks - "Efficient Resource and Task Management is absolutely critical if you want to achieve the highest system performance levels possible. WinTasks 4 will not only help you achieve this task, but will actually make your system run faster and more smoothly than ever before"
wintasks.exe
Added by the EVAMAN WORM!
Wintbp.exe
Added by the ZOTOB.E WORM!
Wintbpx.exe
Added by the ZOTOB.F WORM!
wintective
Wintective logs keystrokes, captures screenshots, and monitors Internet activity. The gathered information can be sent to a predetermined email address. If you didn't install this yourself remove it
WintelUpdate
Added by the SMALL-EKW TROJAN!
winter
Added by the SDBOT-YF WORM!
Wintercooler Pro
Wintercooler Pro - utility that monitors CPU usage, RAM consumption and Internet connection speed
winthelp
AdvancedCleaner misleading security software - not recommended, see here
WinTidy
Desktop icon manager from PC Magazine (Ziff-Davis). Available via Start -> Programs
Wintime
Added by the HARNIG TROJAN!
WinTime
WinTime - change desktop icons' color and font
Wintime Wtxpload
Part of the software to support a Dexxa USB graphics tablet. From a visitor - "This gets started anyway when you plug in the USB connector for the graphics tablet, if it's not already running. It then starts an application which manages the tablet messages. Since I leave the tablet unplugged unless I need to use it, I don't need this running at startup. I suspect that this program monitors a number of windows messages, so that when it's loaded, my regular mouse slows down - it acts like it 'sticks' entering and leaving windows. Certainly my performance returned to what I expected when I removed this item using MSCONFIG"
WinTimer
Hijacker - detected by Kaspersky as the STARTPAGE.TJ TROJAN!
Wintl
Identified as a variant of the Trojan-Spy.Win32.Agent.cch malware
wintnask32.exe
Added by the RBOT-AFP WORM!
wintnl.exe
Added by a variant of the ZOTOB.K WORM!
wintnpx.exe
Added by the ZOTOB.H WORM!
WinTools
Wintools adware
WinTOTAL Scheduler
WinTOTAL Real estate appraisal software related
WinTouch
Detected by Kaspersky as the AGENT.BUO TROJAN!
WinTray
Added by the LEGUARDIEN.B TROJAN!
wintsk32dll
Added by the RBOT-AAJ WORM!
winudll.exe
Added by the MITGLIE-CE TROJAN!
winui
Added by the KONDELI TROJAN!
WinUp
Added by the SILLY.BR WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "4350" sub-folder
winupated.exe
Added by a variant of the SDBOT WORM!
winupd
Added by the MOTA.A WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in the Windows or Winnt folder
winupd
SearchNew adware
winupd.exe
Added by the BEAGLE.M or BEAGLE.N WORMS!
WinUPD32
Added by an unidentified VIRUS, WORM or TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!
winupdat
Added by the CANBOT.A WORM!
WinUpdate
Added by the VBSWG2B.A WORM!
WinUpdate
Added by the REVCUSS.B TROJAN!
WinUpdate
Added by a variant of the RBOT WORM!
winupdate
Added by the ALCAN.B WORM!
WinUpdate
Added by a variant of the SDBOT WORM!
WinUpdate
Added by the SMALL.GXJ TROJAN!
winupdate
Added by the DWNLDR-FUX TROJAN! Note that this is not the legitimate Sun Microsystems file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %Windir%
Winupdate Engine
MalwareCrush spyware remover - not recommended, see here
WinUpdate Loader
Added by the REVCUSS.C TROJAN!
winupdate.exe
Added by the RADO TROJAN!
winupdate.reg
Added by the SPYBOT.EAS WORM!
winupdate2846
Added by a variant of the MUTIN-C TROJAN!
WinUpdateAdministrator
Added by the PUNYA-A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Application Data\WINDOWS
WinUpdateB
Added by the BRATLE.AWORM!
winupdateconn
Added by the COMBRA-A WORM!
winupdateconn_
Added by the COMBRA-B WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
winupdatefiv_
Added by the COMBRA.C WORM!
WinUpdateProtection
EmployeeWatch is a commercial surveillance software program designed to monitor user activity on a computer. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a subfolder of C:\windowsupdate\ufp
WinUpdater
Detected by Kaspersky as the STARTPAGE.C TROJAN! See here
winupdates
Added by the ALCRA-B WORM!
winupdate_
Added by the COMDOR.A WORM!
WinUpdating
Added by the AGENT-GSC TROJAN!
WinUPDbc
Added by the BANKER-DSN TROJAN!
WinUpdsv
Added by the DROPO MACRO!
winupdt
Added by the MABUT.A WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in the Windows or Winnt folder
winupdtl
SecondThought adware variant
WinUpgrader
Added by the AGENT-DZ TROJAN!
WinUPPD.exe
Added by an unidentified WORM/TROJAN!
winur
Added by the WINUR.B WORM!
winusb.dll
Added by the FORBOT-CN WORM!
WinUser32K
Added by the HK TROJAN!
WinUsr
Added by the CLUNK.A WORM!
WinUtilities Memory Optimizer
"WinUtilities Memory Optimizer optimizes the memory management of your system and boost-up its performance amazingly!" MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
Winux Piriax Service
Added by the RANDEX.G WORM!
winversion
Browser hijacker, redirecting to specificsearches.com
WinVNC
WinVNC is an application that allows you to remote control your PC from another PC somewhere on the internet. Now superseeded by RealVNC
WinVNC
Added by the EVIVINC BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe)
winvxd32
Added by the GABLOLIZ.A WORM!
winwan lptt01
RapidBlaster variant (in a "Winwan" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
winwan ml097e
RapidBlaster variant (in a "Winwan" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
winword
Added by the TORPID-C TROJAN!
WINWORD.exe
Added by the DRIVUS TROJAN! Note - this is not the legitimate MS Word process of the same name, which is always located in the Program Files folder. This one is found in System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
WinWorks
Added by the AGOBOT.ACJ WORM!
winwsl.exe
Added by the ZOTOB-J WORM!
WinXDefender
WinXDefender rogue spyware remover - not recommended, see here
WinxDiagUpdate
Detected by Kaspersky as the RBOT.BWQ TROJAN! See here
winXP
Added by the ANPES WORM!
WinXP
Added by the Downloader-JW TROJAN!
WinXP
Added by the BANCOS-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\WinXP\Tools
winxp
Added by the BRONTOK-DN WORM!
WinXP fix
Added by the RANKY.P TROJAN!
WinXP Processor Generator v1.2
Added by the SDBOT.LP WORM!
Winxp update
Added by the RBOT.DKO WORM!
WinXp Updater
Added by the RBOT-HG WORM!
WinXP-98
Added by the BANKER-DS TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Arquivos de programas\WinXP-98\Tools
winxpdll32.exe
Added by a variant of the SMALL downloader TROJAN!
WinXPHome
Added by the malicious INOR.T SCRIPT!
WinXPLoad
Compaq hotkey related - required if you use the hotkeys
WinXProtector
WinXProtector rogue security software - not recommeded, see here
WinXPService
Added by the ZAPCHAS-AS TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "Lavan" subfolder
WinXPService
Identified as a variant of the IRC/Flood.tool malware
WinXPService
Added by the MDROP-BPQ TROJAN!
WinXpUpdate32
Added by the AGENT.YWL WORM!
winxpusbd
Added by a variant of the RBOT WORM!
winystems25
Added by a variant of the SDBOT WORM!
Winz Firewall
Added by a variant of the SDBOT WORM!
WinZap Check
Added by the RBOT-AWZ WORM!
winzip
Added by the BANCOS.G or BANCOS.K TROJANS! Note - this is not part of the popular WinZip file compression utility
Winzip
Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe, common.pif, common.scr, Sexo.exe, Sexo.jpg.pif, ini_file__.pif, load_me__.tmp, msfile.pif, system_load_.pif or zipped.rar.pif
winzip
Added by the RBOT.BDAWORM! Note - this is not part of the popular WinZip file compression utility
Winzip Application
Added by the RBOT-BKZ WORM!
WinZip Quick Pick
Added with WinZip version 8.1. "The new WinZip Quick Pick taskbar tray icon gives you instant access to WinZip and your Zip files. Just left click the icon to open WinZip, or right click it to instantly reopen recently used Zip files, access your Favorite Zip Folders, open WinZip Help, or start WinZip itself.". You can right-click and close it - choosing to not re-load it at start-up
WinZip Update
Added by a variant of the RBOT WORM! Note - this is not part of the popular WinZip file compression utility
WinZix Service
WinZix adware
winzSystam
Added by a variant of the SDBOT WORM!
Win_api_driver
Added by the REVIRD TROJAN!
Win_BooT
Added by the BANKER-GI TROJAN!
WIN_DRIVR32
Added by a TROJAN - see here
win_drivr32
Added by the SMALL.CXO TROJAN!
Win_Library
Added by the ANARCH WORM!
win_spool2
Added by the SCKEYLOG.B TROJAN!
win_supp00.exe
Added by the ASSASIN-H TROJAN!
win_upd.exe
Added by the MITGLIEDER.M TROJAN!
win_upd2.exe
Added by the BEAGLE.AO WORM!
Win_vader
Added by the INVASION.A VIRUS!
WIP Config GUI
Added by the RBOT-CN WORM!
Wireless Connection Manager
Wireless adapter configuration utility for D-Link's range
Wireless Console
ASUS Wireless Console - installed alongside ASUS wireless components and provides additional configuration options for these devices
Wireless PCI Card Configuration Utility
Utility used by the LINKSYS wireless PCI card (WMP11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration
Wireless Provider Server
Added by the FORBOT-AD WORM!
Wireless Switching Setting Utility
On a Sony laptop with built in wireless it allows the user to select which wireless services they want to run (i.e. Wireless LAN, Bluetooth, both) when turning the wireless switch on if disabled)
Wireless-G Notebook Adapter
LinkSys Wireless-G Notebook Adapter driver
Wireless-G Notebook Adapter Utility
Utility used by the LINKSYS Wireless-G Notebook Adapter (WPC54G)
WireLessKeyboard
Related to WireLess Keyboard Multimedia Combo Set by SANSUN Industries
WireLessMouse
Related to WireLess Mouse Multimedia Combo Set by SANSUN Industries. Located in C:Program FilesMultimedia Combo Set
wise
Added by the LAZAR-A TROJAN!
WIZZ
Reported by Kaspersky Anti-Virus as DIALER.IS TROJAN!
wjview
MS tool used to view window-based Java applications from the command line
wkcalrem
Produces a pop-up reminder of events scheduled using the MS Works Calendar
WkDetect
Checks for updates to MS Works
wkfud
A marketing program for MS Works
WksSb
The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program. The Works Portfolio provides a location where you can store items you want to later put into a document or other file
WksSVC
Added by the MYTOB-BW WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
WkUFind
MS Works Update Detection. MS Picture It! (versions 7 to current) use this automatic update feature during the log on process. It can also cause your system to automatically dial into your ISP as it tries to access the internet, if you have your system set to automatically dial when the internet is invoked. To manually update, go to Microsoft's Office/Works update site. You can also turn of the automatic update feature within Picture It! - see here
Wkyo86
Added by the PITIN-A WORM!
Wlan Drier
Added by the WOOTBOT.DC WORM!
Wlan Driver
Added by the WOOTBOT.DH WORM!
WLAN Manager
Wireless management utility for the T-Com Speedport W 100 Card WLAN PCMCIA card
WLAN Status Tray Applet
System Tray icon for checking the status of a Wireless LAN
wlancfg
Inventel wireless router related - required in order to automatically connect to the Net at bootup
wlancfg5
NetGear WG311v3 wireless PCI adapter driver - required in order to automatically connect to the wireless router/gateway at bootup. Note - may not install correctly on Windows9x/ME computers which have Slipstream accelerator installed. Uninstall Slipstream first, disabling slipcore and slipgui are insufficient
WLANSTA.EXE
System Tray icon for checking the status of a Wireless LAN
WLAN_Cfg.exe
Linksys Instant Wireless USB Network Adapter driver
wlinles
Added by the LIJI-A WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the "spool" sub-folder
wlm
Added by the BANCOS-BCY TROJAN!
wlsass
Added by the RANKY.CY TROJAN!
wltray
System tray access to wireless LAN card configuration options
WLWin
Added by the NAVER.A WORM!
WM VCR
WM Recorder allows you to record Windows Media(tm) streaming Video or Audio content. Can be accessed via Start Menu -> Programs
Wm24Pan
ESI external sound card driver
wm41a398
LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wm41a398.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
WMAudio
Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
WMAudio
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
WMBoot
Associated with Logitech Wingman game controllers. Not required but what does it do?
wmcbaaca
LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wmcbaaca.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
WMC_RebootCheck
Corrects problems with installations of Windows Media Player from version 9 onwards - see here and search for "unregmp2.exe"
WMDM PMSP Service
Added by the KNOCKIT-A TROJAN!
WMedia32
Added by the BANGER TROJAN!
WMI Application Interface
Added by the SPYBOT.RBY WORM!
WMI Performance Adapter Services
Detected by Kaspersky as the RBOT.COU WORM! See here
WMI Standard Event Consumer - Scripting
Added by the RBOT-GRD WORM!
WMIEXE.exe
NT component, used by Windows Millennium to detect Plug and Play-compliant IEEE 1394 devices during the startup process. Since this is important for the computer to work properly if you have these, Windows Millennium protects wmiexe.exe and will restore the file even if it's deleted or renamed
Wminf
Added by the GEMA TROJAN!
Wminfo
Added by the GEMA TROJAN!
wmiprv
Added by the RBOT-WM WORM!
wmisrv
Added by a variant of the IRCBOT BACKDOOR! See here
wmon
Added by the AGOBOT-OW WORM! Note that this is not the legitimate Sun Microsystems file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %System%
WMP Auto Update
Added by the RBOT.CF WORM!
WMP54Gv4
Linksys WMP54Gv4 wireless PCI adapter driver - required in order to automatically connect to the wireless router/gateway at bootup. Note - may not install correctly on Windows9x/ME computers which have Slipstream accelerator installed. Uninstall Slipstream first, disabling slipcore and slipgui are insufficient
wmplayer.exe
Added by the BANCBAN-CZ TROJAN!
wmpnscfg
"Microsoft Windows uses wmpnscfg.exe to alert users when media rendering devices are found on the network. Wmpnscfg starts the Windows Media Player Network Sharing Service (NSS) and then waits for notifications from the service. When wmpnscfg is notified that a new media device is available on the network, it displays a popup in the system tray that informs the user about the availability of the new device. If the user clicks the popup, wmpnscfg launches Windows Media Player, which displays a dialog box that asks the user to either allow or deny sharing with the new device." - see here
wms3
Added by the LEGMIR-AQG TROJAN!
wmsys32
Added by the BANPAES.B TROJAN!
WMUAgent.exe
"WakeMeUp! is an advanced alarm clock for computers with Windows 2000, XP or Server 2003"
wmv
Added by the AGENT-DG TROJAN!
WM_LOGIN
Part of McAfee Firewall. What is it for and is it needed?
WN Services
Added by the KBBOT-A TROJAN!
WNAD
Spyware added as a result of running a program called "Yo Mama Osama" (osama.exe). See here for more and how to get rid of it. There are other ways this can show up on your system, and it will manifest itself by periodically opening a new browser window with advertising for copy DVD software and the like
wnddrv
Added by an unidentified TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder
WNILOGON
Added by the LEWOR-M TROJAN!
WNSC
PurityScan/Clickspring adware
Wnsck2 driver
Added by the SPYBOT-AF WORM!
WNSI
PurityScan/Clickspring adware
WNSO
Baidu.SoBar adware
WNST
PurityScan/Clickspring adware
wntlgns
CoolWebSearch parasite variant
wnxpupdate
Added by the DABORA.B WORM!
wnxupdate
Added by the COMBRA-G WORM!
won update
Added by the RBOT.N WORM!
WonderFrog
Wonder Frog typing monitor
WooCnxMon
Wanadoo ISP software related - not required - here's how to bypass it
Woods Inc
Added by the KILLFIL-O TROJAN!
WOOKIT
Wanadoo broadband ISP (now rebranded as Orange) related. What does it do and is it required?
WOOKIT
Related to the Wanadoo broadband ISP (now rebranded as Orange). What does it do and is it required?
woopie
Added by the AGOBOT.XV WORM! Note - this is NOT the popular Winamp media player
WOOTASKBARICON
Wanadoo broadband ISP (now rebranded as Orange) taskbar icon - not required
Woowatch
Wanadoo broadband ISP (now rebranded as Orange) related - not required
word pair
Added by the SHED-A TROJAN!
WordQ carat flag
Related to WordQ Writing Aid Software
Words
Added by the AGENT.GIT TROJAN!
WordWeb
WordWeb - free theasaurus and dictionary. Start manually
Workflo
Related to BroadJump Client Foundation - broadband troubleshooting software installed by various companies. Is it required?
Working System Analyzer
Added by the FORBOT-FZ WORM!
worknote1
Added by the MEETOT WORM!
WorkPace 3.0
WorkPace - stress injury prevention software
Works Calendar Reminder
Produces a pop-up reminder of events scheduled using the MS Works Calendar
WorksFUD
A marketing program for MS Works
Workstation Scheduler
Desktop Management Scheduler. Part of Novell's Netware Client. Schedueles NDS events. If events have been schedueled, it is required, otherwise, it is useless and a memory hog
Workstation Services
Added by the RBOT-OJ WORM!
Workstation Ver 5.0
Added by the RBOT-AHB WORM!
WorldAntiSpy
WorldAntiSpy, "rogue" spyware remover, installed as part of this scam
Worm Detector
Worm Detector - antivirus add-on for Outlook 2K or XP for handling worms and spam
wormexe
Added by the EARLYBIRD WORM!
Worms
Added by the DELMP3-A WORM!
wovax
Added by the DAQA.A TROJAN!
wow
PurityScan/Clickspring adware
wow
Added by the LINEAGE-Y TROJAN!
wow
Added by the DELF-DOR TROJAN!
wow
Added by the WOWPWS-KA TROJAN!
Wpctrl
WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties
Wpctrl
WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties
wpctrl95
WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties
wpctrl95
WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties
WPCUMI
Windows Vista Parental Control Notifications from Microsoft Corporation
WPCycle.exe
Added when selecting Mplayer2 to open media files. Forces other codes to Wait for Previous instructions to end, preventing instability of your CPU (freezing)
wpds.exe
Added by the SMALL-KY TROJAN!
wpds.exe
Added by the BAGLEDI-D TROJAN!
WPlayer
Identified as a variant of the LDPinch.A malware
WPSVC Services
Added by a variant of the IRCBOT BACKDOOR!
wpwmgrs
Added by the MYTOB-DH WORM!
wpxmls
Added by a variant of the SLAPER TROJAN!
WQK
Added by the KLEZ.H WORM!
wr
??
WR Command
??
wrclib
Added by the AKBOT-AH WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wrclib.dll" file is found in %System%
WrCtrl
Win-Route 4.27 NAT engine on Win2k Pro for connection sharing and security using Win-Route by Tiny Software. A connection sharing/Firewall Application. If service is disabled the program does not work, but you can manually start/stop the service with a shortcut the program installs at any time
WRDialer
WinPoet DSL dialler
WRECK GUARD
??
WregBios
Desktop Management BIOS (DMI BIOS) related. Apparently invokes the DosBios.exe file. Is it required?
wrexec
Watch Right - monitoring program, part of the PowerTools add-on for AOL. Records instant messages, E-mail, chat. Watch Right appears to be, and functions as an online clock updater which connects with the U.S. National Institute of Standards and Technology. It was designed for parents who wish to keep an eye on what their children are doing online
wriste
??
Write DVD-R!
Saimon's WriteDVD! "gives total support for DVD-RAM drives. It provides many functions such as setting partitions on DVD-RAM disks and FixDVD! can diagnose and repair UDF formatted disks"
WrtMon.exe
Related to Presto PageManager which is bundled with Canon Scanners
ws2 32
Added by the VOKEN-A TROJAN!
ws2help
Added by a variant of the SMALL.AN TROJAN!
ws2_64.exe
Added by an unidentified TROJAN! See here
WSAConfiguration
Added by the GAOBOT.BAJ WORM!
WSAConfiguration
Added by the AGOBOT.ZT WORM!
WSAConfiguration
Added by the AGOBOT.ABG WORM!
WSAConfiguration
Added by a variant of the RBOT WORM!
WSAConfiguration
Added by a variant of the AGOBOT/GAOBOT WORM!
WSAConfiguration
Added by the AGOBOT-WC WORM!
WSAConfiguration
Added by a variant of the AGOBOT/GAOBOT WORM!
WSAConfiguration
Added by the AGOBOT.VI WORM!
WSAConfiguration
Added by the AGOBOT.TM WORM!
WSAConfiguration1
Added by the AGOBOT.WH WORM!
wsass32
Added by the BANKEM-V TROJAN!
wsbklite
Related to the Acer Soft Button on Acer Tablet PCs. Appears to do nothing so is it required?
WScheduler
Windows Scheduler - "schedule unattended running of applications, batch files, scripts and much more. Also, you can schedule popup reminders so you'll never forget reminders, tasks and other events."
wscnfty
Added by a variant of the RBOT WORM!
wscntfys
Added by the SDBOT-TN WORM!
wscript.exe
Added by the VABI VIRUS!
wscsvc.exe
Added by a password stealing BANKER TROJAN!
wsctf.exe
Added by the JAMPORK.E WORM!
Wsdata service
Added by the SDBOT.ZU WORM!
wserv
Added by a variant of the SDBOT WORM!
wserver
Added by the NETSKY.AC or SASSER.G WORMS!
WService
Tablet client Driver for UC-Logic Pen/Graphics Tablet
wsg32
GoldenKeylog keystroke logger/monitoring program - remove unless you installed it yourself!
wskrnl
ActMon surveillance software. Uninstall this software unless you put it there yourself
wsock32
Added by the HORST-A WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder
WSockDrv32
Added by the WINKO.AO WORM!
wsrv32
Detected by Kaspersky as the AGENT.EP TROJAN!
WSSAConfiguration
Added by the AGOBOT-KC WORM!
wssys
WebPI logs keystrokes and captures screenshots. If you didn't install this yourself remove it
Wstat32 driver
Added by the LOONBOT TROJAN!
wstimeb
Used with NEC printers. You can disable it before printing but it re-loads itself when printing so you may as well leave it
wsttrs
Added by the LDPINCH-QS TROJAN!
wsvbs
Added by the PWS-AEB TROJAN!
WSVCS
WSLogger keystroke logger/monitoring program - remove unless you installed it yourself!
wswpd
Used with some models of Panasonic, Epson and NEC printers. Some older drivers known to have a "memory leak". Needed for printing to work
wsys.exe
SpyloPCMonitor is a surviellance software program that monitors user activity, logs keystrokes, and takes screenshots. It ends the processes of anti-spyware programs. If you didn't install this yourself remove it
ws_d
Added by the LEGMIR-RL TROJAN!
WT Game Channel
WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
WT Game Channel
WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
WT GameChannel
WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
WT GameChannel
WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
WTF Test
Added by the RBOT-ACM WORM!
WTIndicator
WinTask - software that automates a variety of routine tasks quickly and simply
WTSI
PurityScan/Clickspring adware
WTSS
PurityScan/Clickspring adware
WTST
PurityScan/Clickspring adware
WU713STA.EXE
Blitzz Technology wireless NIC adapter driver
wuanguard
Added by the RBOT-AAF WORM!
WudfSvc
Added by the SHEUR.BBB TROJAN!
WUOLService
Remote wakeup status agent. Part of Novell's ZenWorks. Processes Wake-up on LAN requests (turn on a computer remotely on LAN)
wuosdial
Added by a variant of the RBOT WORM!
WUPD
Added by the TZET WORM!
wupd
Added by the ABWIZ.C TROJAN!
wupd
Added by the ORSE-C TROJAN!
wupdate
Added by the ORSE-B TROJAN!
wupdate
Downloader trojan, detected by Panda antivirus as Adware/Trustbid
WUpdate
Added by the CLAGGER-AR TROJAN!
Wupdate driver
Added by a variant of the SPYBOT WORM!
WUpdates
Added by the SWEPDAT TROJAN!
Wupdm32
Added by the MIDLAK WORM!
wupdmgr32.exe
Added by the CERTIF-I TROJAN!
wupdt
Added by the IMISERV.A TROJAN!
Wupftp
Added by the AGOBOT.AKV WORM!
WUSB11B.exe
Linksys WUSB11 WLAN USB adapter
WUSB54GS
Linksys Wireless-G USB Wireless Network Monitor
WUSB54Gv2
Wireless-G USB Wireless Network Adapter related - would appear to be required
WUSB54Gv4
Wireless-G USB Wireless Network Adapter related - would appear to be required
wuviewer
Added by a Proxy Trojan variant
WUx_RegSvr
x is any number??
WWKS
Added by the SDBOT-BT WORM!
www.hidro.4t.com
Added by the BLASTER.F WORM!
www.symantec.com
Added by the MYDOOM.W WORM
WXcmeinst
Added by the RANCK-CD TROJAN!
Wxp4
Added by the ERKEZ.D WORM!
WXProcMgr Module
TVTonic from Wavexpress - "enjoy 3 full-screen, DVD-quality video channels for FREE". Allows data content to be downloaded and synchronized on your system
WZCBDLService
WZCBDLService Launcher from D-Link - configuration/drivers
wzdmg
Added by a generic downloader TROJAN - see here
wzhelper
Searchcentrix hijacker
wzservice
Added by the HACKARMY.W TROJAN!
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59