WIN.INI
SYSTEM.INI
sysconfig
CONFIG.SYS
AUTOEXEC.BAT
Windows 95/98, Me, NT/2000/XP/2003 Floppy Boot Disk (MS-DOS)
COMMAND.COM
IO.SYS
MSDOS.SYS
Bootsect.dos
explorer.exe
lsass.exe
svchost.exe
iexplore.exe
csrss.exe
rundll32.exe
ctfmon.exe
services.exe
alg.exe
spoolsv.exe
services.exe
winsystem.sys
Added by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup! smss.exe
w32
Added by the SOKEVEN TROJAN! w32.exe
W32.Scran
Added by the NARCS WORM! Scran.exe
w32alanis
Added by the SINALA WORM! mope.scr
W32data
Added by a variant of the RBOT WORM! eworo.exe
W32Load
Added by the CASPID WORM! [random filename].scr
w32sup
Adult content dialler w32sup.exe
W32Tc
Added by the VOTE.D or VOTE.K WORMS! WTC32.scr
W3KNetwork
Advertising spyware. Check here for more info on this particular one rundll32.exe w3knet.dll, dllinitrun
W75P2PSERVER
Printer utility which is required in order to make the printer work correctly W75P2PS.EXE
W815DM
?? W815DM.exe
w98Eject
Related to USB support for Sigmatel MP3 audio palyer (and others such as SanDisk). It's intent is to "put away" the "disk" before you unplug it from the USB port, ostensibly to avoid "losing" data w98Eject.exe
wait4IP
Packard Bell net2Plug allows you to network PCs anywhere in your house wait4IP.exe
wallchgr.exe wstart
WallChanger - wallpaper changer from Blue Tree Software Wallchgr.exe
Wanadoo Messenger.exe
Wanadoo ISP instant messenger client Wanadoo Messenger.exe
WanMPSvc
An AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling AOL doesn't help WanMPSvc.exe
WAPI
PurityScan/Clickspring adware wts**.exe [* = random char]
War FTPD Tray Icon
War-ftpd - FTP server wartray.exe
war-ftpd.exe
War FTP Daemon from JGAA's Internet - FTP client WAR-FTPD.EXE
Wardo
Added by the ADLCICKER.G TROJAN! syslaunch.exe
WareOut
Malware masquerading as a spyware and dialer remover, see here WareOut.exe
warez
Warez P2P client warez.exe
Warner
Also known as "CyberWarner". From G-Tek Technologies and pre-installed on some Packard Bell PCs. Protects critical files warner.exe
Warnet
Warnet - system cleanup software warnet.exe
Warning: do not remove it!
Part of Folder Password Expert by ZQS Software Team - "a software program to restrict access to the folders that contain your sensitive data" fpplock.exe
WARSVR
War FTP Daemon - the original free FTP server for windows war-ftpd.exe
WashAndGo - Cleanup of old Backupfiles
WashAndGo - temp file cleaner checker.exe
Washer
Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG washer.exe
Washerie.exe
Cookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer, specific for cleaning the IE cache and cookies. Available via Start -> Programs washerie.exe
washindex
Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG washidx.exe
Wast
Grokster ads updater wast.exe
Watch
Found to be used by a Trust USB scanner for auto starting the scanning software when the lid is lifted watch.exe
Watch
?? 1200UBWATCH.EXE
Watch Dog Program
For Compaq PC's. Associated with Compaq's internet services. Not required if you don't use services provided by them and may not be required even if you do watchdog.exe
Watchdog
Definitely part of the Mustek scanner drivers and software (for 600 III EP Plus and maybe others), launches from the Startup folder in the Start Menu, but not required as they give instructions on removing it on their webpage Watchdog.exe
WatchDog
Part of Motorola "Mobile Phone Tools" v3 - in a "Mobiile Phone Tools" sub-directory of Program Files watchdog.exe
WaveTop Launcher
WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 WaveTop.exe
WaveTop Receiver 1
WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 N/A
WaveTop Receiver 2
WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 N/A
WaveTop Upload Manager
WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 N/A
Wbiff
Wbiff! E-mail checker - automatically checks your e-mail and notifies you if any new e-mail has been received Wbiff.exe
Wbutton
Turns on and off the integrated WiFi on Acer (and other laptops) Wbutton.exe
WCESCOMM
Active sync for use with Windows CE based palm PC WCESCOMM.EXE
WCESMngr
Added by the AGOBOT-QZ WORM! spoolsb.exe
WCESMngr
Added by the AGOBOT-QX WORM! WCEMNGR.EXE
wcmdmgr
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but wcmdmgrl.exe
wcmdmgr.exe
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but wcmdmgr.exe
wcmdmgrl
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but wcmdmgrl.exe
WCOLOREAL
Makes colours sharper and brighter, but will only work with coloreal capable monitors coloreal.exe
WCPC
?? wintsvcc.exe
WCPI
PurityScan/Clickspring adware wintsvit.exe
WCPS
PurityScan/Clickspring adware Wint**.exe [* = random char]
WCPT
PurityScan/Clickspring adware wintsvtr.exe
WD Button Manager
Button manager installed with a western digital external disk drive. Allows you to back up your system with one click WDBtnMgr.exe
WDInfo
Added by the DLUCA.B TROJAN! wdinfo.exe
WDNS SYSTEM
Added by the MYTOB-BY WORM! nibie.exe
WDNS SYSTEM
Added by the MYTOB-BY WORM! skybotx.exe
WDNS SYSTEM
Added by the MYTOB-BY WORM! wdns33.exe
wdskctl
IEPlugin spyware wdskctl.exe
wdwctrl
Added by the DLUCA.E TROJAN! wdwctrl.exe
WEATHER
Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs WEATHER.EXE
WeatherCast
Weather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight Weather.exe
WeatherOnTray
Hotbar's Weather Forecast tool for your desktop - adware WeatherOnTray.exe
Weatherscope
WeatherScope software - bundles Gator adware Weatherscope.exe
WeatherWatcher
WeatherWatcher - weather reporting in the System Tray ww.exe
web
Added by a variant of the EASTO.A TROJAN! ******.exe [* = random char]
WEB DRIVERS FOR WIN32
Added by a variant of the RBOT WORM! phqgh.exe
Web Search
?? ??
Web Service
Added by the ADMINCASH TROJAN! [random filename].exe
Web Service
Added by the BUBE-F VIRUS! sm.exe
web3trap
PC-Cillin 2000 anti-virus software -> ActiveX filter. Guards against malicious ActiveX programs, etc web3trap.exe
webalize
Searchcentrix hijacker webalize.exe
WebArmyKnife
Web Army Knife - a suite of web site developer's tools WAK.exe
webassist
Adware popup generator webassist.exe
Webcam Go Sti Service Application
Control software for the portable Creative Video Blaster Webcam Go digital camera/PC web cam. What does it do and is it required? wbcgosvc.exe
WebcamRT.exe
For Logitech Web Cams. Not required - camera works fine without it WEBCAMRT.exe
Webcelerator
Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Spyware and troublesome - see here webcel.exe
WebCheck
Added by the CONE.C or CONE.F WORMS! WebCheck.pif
WebCpr0
Web_CPR/TopMoxie adware WebCpr0.exe
Webdav.exe
IRC DDoS bot which gives the hacker full control over your system webdav.exe
WebHancer Agent
System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here whagent.exe
webHancer Survey Companion
WebHancer foistware - traffic measurement service that uses a client agent that is stealth installed on user machines, gathering detailed data about sites visited, their performance and, most important, what the user actually does while there whSurvey.exe
WebInstall
ClipGenie adware downloader WebInstall.exe
WebInstall2
ClipGenie adware downloader WebInstall.exe
WebKey
WebKey from JB Utilities. Utility to keep track of login data required when browsing the internet WebKey.exe
WebOutfitterTray
Intel WebOutfitter service System Tray icon sttray.exe
Webposition Gold 2
Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines wpsche~1.exe
WebRebates0
WebRebates adware WebRebates0.exe
WebRun
Added by the ADWARELOADER TROJAN! [random filename]
websaverlive
WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your computer is idle websaverlive.exe
WebSavingsfromEbates
Web Savings From Ebates Software, a shopping tool that opens pop-up windows WebSavingsfromEbatesrun.exe
WebSavingsFromEbates0
Web Savings From Ebates Software, a shopping tool that opens pop-up windows WebSavingsFromEbates0.exe
WebScan
eAcceleration Stop-Sign related - not recommended, see note DEFSCANGUI.EXE
webscan
eAcceleration Stop-Sign related - not recommended, see note stopsignav.exe
WebScanX
From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc WebScanX.exe
websearch
Web Savings From Ebates Software, a shopping tool that opens pop-up windows wjview ...websearch.exe
WebSecureAlert
WebSecureAlert software - bundles Gator adware WebSecureAlert.exe
WebServer
Related to a Pinnacle sound card. What does it do and is it needed? VBI_SE~1.EXE
Webshots
Screensaver program that automatically downloads from the webshots web site Webshots Tray.exe
Webshots
Screensaver program that automatically downloads from the webshots web site websho~1.exe
Website Administrator Info
Added by the FORBOT-FY WORM! webadmin.exe
WebSpecials
WebSpecials spyware rundll32 [path] webspec.dll
Websx
Adult content dialler - where ***** are random Int*****.exe
Webtrap
Part of PC-Cillin anti-virus software. Checks web-sites for malicious Java and ActiveX elements in a similar way to McAfee WebScanX. A few users find it infuriating webtrap.exe
WebTrapNT.exe
Part of PC-Cillin Anti-Virus software. Checks visited web-sites for malicious Java and ActiveX elements WebTrapNT.exe
WebWasher
Free Pop-up/ad/javascript filter program from Siemens. If not running then browsers will not be protected but will still work. Available via Start -> Programs wwasher.exe
WeirdOnTheWeb
Added by the WeirdOnTheWeb adware WeirdOnTheWeb.exe
Welcome
Launches the Welcome to Windows tutorial on boot up Welcome.exe
WEPstat
Cisco Aironet 340 Series PC Card driver. If it can be started manually it shouldn't be required if you don't use the PC card facility regularily - hence the status could be "U". Can anybody confirm this? Wepstat.exe
wersds
Added by the JECT.C TROJAN! doriot.exe
wesumu
Added by the QQPASS-L TROJAN! wiustv.exe
WetSock
RoboMagic Wetsock - weather reporting in the System Tray wetsock.exe
WFGStartup
World Weather. "This midlet displays the current weather conditions for major cities around the world. This version is for memory limited mobile phones" WFGStartup.exe
wfips
ICQ (messaging/chat program) anti-bomb software. "WFIPS is anti-bomb software for safeguarding ICQ Bomb before the bombing. 'ICQ Defoolder' is a tool for removing ICQ bomb after being exposed." For more information about ICQ bombs see here iphider.exe
WFXCTL32.EXE
From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs WFXCTL32.EXE
wfxsnt40
WinFax 10.0 and maybe earlier versions. The program that opens the port for WinFax and not normally in the start menu. Needed if you want to run WinFax wfxsnt40.exe
WFXSwtch
Related to WinFax. What does it do and is it required? WFXSWTCH.exe
WG511WLU
Netgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card WG511WLU.exe
WGWLocalManager
Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for WGWLocalManager.exe
whagent
System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here whagent.exe
WhatPulse
WhatPulse keeps track of your keystrokes, allowing you to find out just how much you type a day WHATPU~1.EXE
WheelMouse
Mouse software for "Fellowes" Wheelman mouse. Has caused some users problems but shouldn't be needed if you don't use any enhanced features it may provide 4DMAIN.EXE
WheelMouse
A4Tech wireless mouse driver and utility - required if you use non-standard Windows driver features AMOUMAIN.EXE
WhenUSave
SaveNow adware Save.exe
WhenUSearch
SaveNow adware Search.exe
WhenUSearchWHSE
SaveNow adware whse.exe
Whistler
Added by the WHISTLER-F TROJAN! whismng.exe
Whvlxd
Added by the W32.LXD.MIRC TROJAN! Whvlxd.exe
WIAWizardMenu
Still Image Class Installer - installed with a webcam RUNDLL32.EXE sti_ci.dll, WiaCreateWizardMenu
Widnows Xp Web scan
Added by a variant of the SDBOT WORM! xpscan.exe
wifeman
Unidentified malware wifeman.exe
WildTangent CDA
Part of the WildTangent on-line games system. What does it do and is it required? RUNDLL32.exe cdaEngine0400.dll,cdaEngineMain
WildTangent Web Driver updater
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but wcmdmgrl.exe
Wildwire Monitor
This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem WWMon.exe
Willow Road
Willow Road Screen Saver WillowRoad.exe
win
Added by the SEEKER.K TROJAN! regedit -s ..win.dll
win
Added by the AGOBOT-MV WORM! xwinxrpc32.exe
win
Added by the AGOBOT-MV WORM! xwinxrpc.exe
WIN
Added by the MYTOB-CQ WORM! ehshell.exe
WIN
Added by the REATLE.C WORM! windows.exe
Win Chimes
WinChimes - enhancement software for the system clock that runs in the system tray winchi~1.exe
Win Comm
WebRebates related adware WinComm.exe
Win Command
Added by the AGOBOT.XQ WORM! command32.exe
Win Command
Added by the AGOBOT.XQ WORM! command32.exe
win ctl app
Added by a variant of the SDBOT WORM! wuctl.exe
Win Drivers SSL
Added by the IRCBOT.67098 WORM! hpws.exe
Win Drivers SSL
Added by a variant of the RBOT WORM! TASKMAN4.exe
WIN HOST PROCESS
Added by the KEYLOGGER.CLONE TROJAN! WIN HOST PROCESS.EXE
Win l5oahder
Added by a variant of the AGOBOT/GAOBOT WORM! Note - this is NOT the popular Winamp media player which has the same filename winampa.exe
Win Microsoft 98
Added by the RBOT-AKX WORM! win14.exe
win name
?? stat.exe
Win Patch
Added by the SDBOT-GS WORM! ntldr.exe
Win Secure Update
Added by the RBOT-AGI WORM! [random filename]
Win Server
Added by the IMISERV.A TROJAN! winserv.exe
Win Server Updt
Added by the IMISERV.A TROJAN! wupdt.exe
Win Server Updt
Added by a variant of the IMISERV TROJAN! winserver.exe
Win Server Updt
IEPlugin adware pxckdla.exe
Win TaskLoader
Added by the MYTOB.L WORM! msgmr.exe
win update
Added by the SDBOT.J WORM! wupda32.exe
win update
Added by a variant of the RBOT WORM! wapdate.exe
Win Updater
Added by the RBOT.IP WORM! WINUPDATER.EXE
Win Updator Services
Added by a variant of the WOOTBOT WORM! ctfnom.exe
WIN USB 2.0
Added by an unidentified WORM of TROJAN! usbsystem.exe
WIN USB 2.0
Added by a variant of the RBOT WORM! winusb.exe
Win USB 2.0 USB Driver
Added by the SPYBOT.DNB WORM! HPPrint.exe
Win WinAmp
Added by the RBOT.AGF WORM! Note - this is not the Winamp media player executable (WinAmpa.exe) winamp.exe
WIN-BUGSFIX
Added by the LOVELETTER (I LOVE YOU) VIRUS! WIN-BUGSFIX.EXE
win-xp
Added by the BROPIA.N WORM! nvsc32.exe
win-xp
Added by the BROPIA.N WORM! winis.exe
win-xp
Added by the BROPIA.N WORM! winis.exe
win-xp
Added by the BROPIA.N WORM! nvsc32.exe
win16.dll
Screenspy captures screenshots silently. If you didn't install this yourself, remove it win16dll.exe
Win2Drv
Added by the WINTOO WORM! [worm filename]
WIN32
Added by the RATEGA TROJAN! WIN32.EXE
win32
Added by the MYLIFE.N WORM! Shakira_1997_Part_1_.Mpeg_.scr
win32
Added by the EVILBOT.B TROJAN! Setup_32.exe
Win32
Added by the ISRAZ.A WORM! Win32.exe
win32
Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites winsrv32.exe
win32
Added by the EVILBOT.B TROJAN! WinSetup.exe
Win32
Added by the SWERUN VIRUS! system32.vbs
Win32
Added by the SCAFENE WORM! Game.exe.vbs
Win32
Added by the SPAZBOX.A TROJAN! arsetup.exe
win32
Added by the BROPIA.J WORM! winhost.exe
Win32 Bios
Added by the SEMAPI-A WORM! Winbios.exe
Win32 Configuration
Added by the SDBOT.TT WORM! videosd32.exe
Win32 Configuration
Added by the SDBOT.UL WORM! dllhelp.exe
Win32 Configuration
Added by the FORBOT-BZ WORM! mplayer.exe
WIN32 DDOSSER
Added by the KELVIR.F WORM! dos.exe
Win32 Debug Manager
Added by a variant of the WOOTBOT WORM! Win32Debug.exe
Win32 Device Loader
Added by a variant of the AGOBOT/GAOBOT WORM! Win32ldr.exe
Win32 Driver
Added by the FORBOT-FD WORM! svchosts.exe
Win32 Drivers
Added by the FORBOT-FG WORM! winlogons.exe
Win32 DRK Driver
Added by the WOOTBOT.CY WORM! wdrk32.exe
Win32 exe file
Added by a variant of the SPYBOT WORM! winstr32.exe
Win32 Explorer
StartPa-MN homepage hijacker Explorer32.exe
Win32 FRT Driver
Added by a variant of the FORBOT WORM! msfr32.exe
win32 internet server
Added by the DERMON-D WORM! winserver.exe
Win32 Kernel core component
Added by the MOKS VIRUS! Kernel32.pif
Win32 LSA Driver
Added by the FORBOT-FJ WORM! lsa.exe
Win32 Ms Auto Updater
Added by a variant of the RBOT WORM! AutomsUPD.exe
Win32 Network Driver
Added by a variant of the AGOBOT/GAOBOT WORM! crss.exe
Win32 NT Adv Services
Added by the RBOT-ADE WORM! taskmngr.exe
Win32 nvc
Added by the RBOT-ABF WORM! nvcva.exe
Win32 NVIDIA Driver
Added by a variant of the WOOTBOT.Y WORM! MSPMSPSU.EXE
win32 regedit
Added by an unidentified WORM or TROJAN! msn32.exe
Win32 Rundll Loader
Added by the SDBOT.A TROJAN! Note: Rundll32.exe is a valid Windows application called "Run a DLL as an App" and stored in the C:Windows directory. The version created by this virus is saved in the C:WindowsSystem directory Rundll32.exe
Win32 Secure
Added by a variant of the SDBOT WORM! msconfigsvc.exe
Win32 Service
Added by the AHKER.E WORM! bazzi.exe
Win32 Services Config
Added by the RBOT.BKY WORM! winwkys.exe
Win32 Services1
Added by the SDBOT-PV WORM! wuamngr1.exe
Win32 Src Service
Added by the RBOT-SX WORM! win32src.exe
Win32 SSL Driver
Added by the FORBOT-BH WORM! winssv.exe
win32 system server
Added by the DERMON-A TROJAN! winserver.exe
Win32 System Spool
Added by the SDBOT.UK WORM! spoolsvc.exe
Win32 Test
Added by a variant of the RBOT WORM! bleatest.exe
Win32 USB Driver
Added by the SDBOT.AA TROJAN! winxpinit.exe
Win32 USB Driver
Added by the FORBOT-BK WORM! mvsecn.exe
Win32 Usb Driver
Added by the FORBOT-BE or FORBOT-J WORMS! svhosint32.exe
Win32 Usb Driver
Added by the SDBOT-OV WORM! usb32.exe
Win32 Usb Driver
Added by the FORBOT-BX WORM! AvpG.exe
Win32 USB2
Added by a variant of the RBOT WORM! wins32.exe
Win32 USB2 Driver
Added by the SPYBOT.DHV WORM! win32usb.exe
Win32 USB2 Driver
Added by the SDBOT.FO WORM! smsc.exe
Win32 USB2 Driver
Added by the FORBOT.J or SDBOT.HU WORM! svchosting.exe
Win32 USB2 Driver
Added by the WOOTBOT.X WORM! sys32.exe
Win32 USB2 Driver
Added by the FORBOT-AN WORM! sys32snd.exe
Win32 USB2 Driver
Added by the FORBOT-AH WORM! wind32.exe
Win32 USB2 Driver
Added by the AGOBOT.YE WORM! winupdate.exe
Win32 USB2 Driver
Added by a variant of the FORBOT WORM! updatemgr.exe
Win32 USB2 Driver
Added by a variant of the SDBOT WORM! winsnd32.exe
Win32 USB2 Driver
Added by the FORBOT-EX WORM! msn.exe
Win32 USB2 Driver
Added by the FORBOT-R WORM! syscfg32.exe
Win32 USB2.0 Driver
Added by the IRCBOT.D WORM! 386.exe
Win32 USB2.0 Driver
Added by the WOOTBOT.H WORM! rundll16.exe
Win32 USB2.0 Driver
Added by the SPYBOT.DN WORM! w32usb2.exe
Win32 USB2.0 Driver
Added by the SDBOT-QF WORM! service.exe
Win32 USB3 Driver
Added by a variant of the RBOT WORM! win32tool.exe
Win32 Wmls Driver
Added by the WOOTBOT.B WORM! winitr32.exe
Win32 Word Services
Added by a variant of the RBOT WORM! msword32.exe
win32.exe
Added by the STARTPAGE TROJAN! win32.exe
Win32.exe
Added by the AWQ.A TROJAN! Win32.exe
Win32BaseServiceMOD
Added by the NAVIDAD WORM! Wintask.exe
win32beta
Added by the BANKER-DA TROJAN! win32sys4.exe
win32clf
Added by an unidentified VIRUS, WORM or TROJAN! win32clf.exe
Win32DLL
Added by the LOVELETTER (I LOVE YOU) VIRUS! Win32DLL.vbs
Win32dll
Added by the BANPAES TROJAN! Win32dll.exe
Win32G
Added by the ESTRELLA TROJAN! Kernel32.com
Win32G
Added by the ESTRELLA TROJAN Scandisk.com
win32gb
All-In-One-Telcom (adult content dialler) variant win32gb.exe
Win32Host Process
Added by the TURGEN -A TROJAN! webemir.exe
win32info
Adult content dialler win32info.exe
win32ini
Added by the IRC.ALADINZ.C TROJAN! systroy.exe
Win32R
Added by the ESTRELLA TROJAN! Server.com
WIn32S Java DLL
Added by the AGOBOT-RZ WORM! kavsvx.exe
win32servv
Added by an unidentified TROJAN or adware load.exe
win32servv
Added by an unidentified trojan or adware ms1.exe
WIN32SL
Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and Win32sl.exe
WIN32SNDS
Added by an unidentified WORM or TROJAN! banc.exe
Win32system
Added by the DDV.B WORM! [random filename]
Win32System
Added by the MYDOOM.V WORM! win32s.exe
Win32SystemMonitor
Browser hijacker ***.exe [* = random char]
Win32SysV
Added by the FORBOT-EO WORM! xin.exe
win32us
All-In-One-Telcom (adult content dialler) variant win32us.exe
win32usbd
Added by the RBOT-RA WORM! ssrs.exe
win32_i lptt01
Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here win32_i.exe
win32_i ml097e
Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here win32_i.exe
Win386
Added by the GOSUSUB VIRUS! Win386.exe
Win386
Homepage hijacker. Not a dll but a regfile in disguise sp32.dll
WIN3S2SNDS
Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" winabsmod.exe
WIN3S2SNDS
Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" winiprtx.exe
Win64 Compatibility Check
CoolWebSearch parasite variant load win64.drv
WIN95DEFVIEW
Added by the DEDLER-D TROJAN! [path to file]
WIN95DEFVIEW
Added by the DEDLER-D TROJAN! csmss.exe
win98 DNS
Added by a variant of the RBOT WORM! wingrd.exe
WinAC v4
Added by the FORBOT-CS WORM! klsuicbn.exe
Winacsr
AceScreenSpy keystroke logger/monitoring program - remove unless you installed it yourself! Winacsr.exe
winactive
Active variant of LOP.com hijacker - see here WINACTIVE.EXE
WinActiveJ
Added by the ROTARRAN VIRUS! WinActiveJ.exe
Winad Client
WinAd adware by eXact Advertising Winad.exe
WinAdCnt.exe
Added by the BANKER-BU TROJAN! WinAdCnt.exe
winadm
Browser hijacker - redirecting to Search-World.net. Related to the SMALL.LR TROJAN! winadm.exe
WinAgent
Standard Life Insurance program. Is it required at startup? WinAgent.exe
Winahlp.exe
Added by a variant of the VAGRNOCKER TROJAN! Winahlp.exe
winallap
Added by the DELF.E TROJAN! winallap.exe
winallapu
Added by the DELF.E TROJAN! winallapu.exe
Winamp
Hijacker - re-directing to adult content sites. Note - this isn't the real Winamp winamp.hta
Winamp
Added by the AGOBOT-MC WORM! Note - this is NOT the popular Winamp media player which has the filename "winampa.exe" winamp.exe
WinAMP
Added by the SDBOT-WN WORM! winamp62.exe
Winamp Agent
Added by the POEBOT-I WORM! Note - this is NOT the popular Winamp media player which has the filename "winampa.exe" winamp.exe
Winamp media player
Added by an unidentified VIRUS, WORM or TROJAN! winapa.exe
Winamp Update
Added by the SDBOT-ACR WORM! yhn.exe
Winampa
Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs WINAMPa.exe
Winampa
Added by the AGOBOT-GS WORM! Note - this is NOT the popular Winamp media player which has the same filename winampa.exe
Winampa Agent
Added by the SPYBOT-BR WORM! Note - this is NOT the popular Winamp media player which has the same filename WINAMPA.EXE
WinampAgent
Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs WINAMPa.exe
WinAmpAgent
Added by the EB TROJAN! Note - this is NOT the popular Winamp media player which has a different filename Msexploren.exe
WinAmpAgent
Added by the EB TROJAN! Note - this is NOT the popular Winamp media player which has a different filename Shch.exe
WinAmpAgent
Added by the EB TROJAN! Note - this is NOT the popular Winamp media player which has a different filename svchst.exe
WinAmpAgent
Added by the EB TROJAN! Note - this is NOT the popular Winamp media player which has a different filename Winagent.exe
WinApi
Added by a variant of the TIBSER.A downloader TROJAN! winapix.exe
WINAPLOGUPD
Added by the CAPSIDE-C WORM! WINAPLOGUPD.EXE
Winapp
Produces popup ads to adult content sites winpup32.exe
WinApp32
Added by the RSBOT TROJAN! msapp.exe
WinAppLog
StingKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! svchost.exe
WinAuth
Hijacker, also indentified as the STRTPAGE.BE TROJAN! Note - this is not the valid winlogon.exe process winlogon.exe
WinAwk
Added by the SDBOT-AYF WORM! WinAwk.exe
WinBackup Scheduler
LIUtilities WinBackup scheduler - backup software Wbsched.exe
WinBar
WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls WinBar.exe
winbas12
Adware, CoolWebSearch parasite related - recognized by Kaspersky antivirus as TrojanDownloader.Win32.VB.du - Note - this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot. Name field m winbas12.exe
Winbed
Hijacker winbed.exe
winbin32
Added by the RBOT-ZL WORM! win32exe.exe
WinCheck
Added by the PWS-CY TROJAN! WinCheck.exe
winchost
Added by the DLOADER-PO TROJAN! winchost.exe
WINCINEMAMGR
WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs WINCIN~1.EXE
WinCinemaMgr
WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs WinCinemaMgr.exe
wincms
Added by the RBOT.CBR WORM! Note - this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot. Name field may be empty wincms.exe
WinCSRSS
Added by the REWINDO-A TROJAN! MSGRT32.EXE
WINCX
Added by the AGOBOT-MG WORM! wincore332.exe
wind.exe
Added by the MITGLIEDER.BD TROJAN! wind.exe
WIND0WS
Added by the SPYBOT.DQ WORM! WIND0WS.exe
WIND0WS
Added by the ALLEM WORM! mella.bat
Wind0ws Sharing
Added by the RBOT-AHW WORM! ssprotecter.exe
WinDates
WinDates is a calendar, date organizer and event reminder program from Rockin' Software windates.exe
windbs
Added by the AGOBOT-WD WORM! winxtc.exe
Winde
Added by the DLUCA TROJAN! winde.exe
windef
Added by the ANPES WORM! Win32sp.vbs
windhost.exe
Added by the BANKER-CB TROJAN! osrwin32.exe
windhost.exe
Added by the BANKER-BV TROJAN! windhost.exe
windhost.exe
Added by the PWSAGENT-A WORM! winos.exe
windir
Added by the WINBUR.B WORM! winrun.exe
Windll
Added by the TRYNOMA TROJAN! Windll.exe
WINDLL
STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes, all passwords transacted even if they weren't keyed in, all web sites visited, every program launched including the path to that program, and more" WSYS.EXE
windll
Added by the ASTEF or RESPAN WORMS! windll32.exe
Windll.exe
Added by the STEALER TROJAN! Windll.exe
Windll32
Added by the MSNPWS TROJAN! Windll32.exe
WinDll32
Added by the LEGMIR.AQ TROJAN! _WIN32.EXE
windllsys32.exe
Added by a variant of the MITGLIEDER.BY TROJAN! windllsys32.exe
WinDNS
Added by the GAOBOT.WX WORM! windns32.exe
Windoes Kernel
Added by the KICKIN.A (or CYDOG.C) WORM! kernel32.exe
Window
Added by the GAOBOT.ADW WORM! explore.exe
Window Loader
Added by the GAOBOT.AO WORM! Dos32.exe
Window Monitor
Added by the SDBOT.RT WORM! winmon32.exe
Window service
Added by the RBOT-ACH WORM! [random filename]
Window Washer
Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG wwDisp.exe
window.exe
Added by the MITGLIEDER.H or MITGLIEDER.J TROJANS! window.exe
window2
Added by the IRCBOT.H TROJAN! ssvchost.exe
WindowBlinds
WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties wbload.exe
WindowEnhancer
SCbar foistware variant Winex.exe
WindowFX
Stardock WindowFX - "Allows you to add an unprecedented number of special effects to windows" wfxload.exe
windown
Added by the QQPASS-M TROJAN! wiusyt.exe
WindowRegKey update
Added by the SPYBOT.I WORM! wins.exe
Windows
Added by the TENDOOLF WORM! Kernel32.exe
Windows
Added by the PWSTEAL TROJAN! msdos98.exe
Windows
Added by the KAZMOR, BOBBINS & ALADINZ.D TROJANS! Windows.exe
Windows
Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually explorer.exe
windows
Added by the AIMWIN TROJAN! [path to trojan]
windows
Added by the GAOBOT.AFW WORM! hkey.exe
windows
Added by the SALGA.A WORM! system copy.exe
Windows
Added by the STUBBOT-B TROJAN! gearsec.exe
Windows
Added by the SPYBOT.OFN WORM! run.exe
Windows
Added by the SPYBOT.OBB WORM! system.exe
WINDOWS
Added by the MONBOT-A TROJAN! windows.exe
Windows (random character)
Added by the SINGU.B TROJAN! diskcheck.exe
Windows .Net Manager
Added by the DLOADER-NY TROJAN! localsvc.exe
Windows .Net Manager
Added by the DLOADER-NY TROJAN! netsvc.exe
Windows .Net Manager
Added by the DLOADER-NY TROJAN! spoolsvc.exe
Windows .Net Manager
Added by the DLOADER-NY TROJAN! svcadmin.exe
Windows .Net Manager
Added by the DLOADER-NY TROJAN! svcman.exe
Windows .Net Manager
Added by the DLOADER-NY TROJAN! svcrun.exe
Windows .Net Manager
Added by the DLOADER-NY TROJAN! tcpsvc.exe
Windows .Net Manager
Added by the DLOADER-NY TROJAN! websvc.exe
Windows 128 Module
Added by the FORBOT-ES WORM! win128.exe
Windows 32 Editor
Added by the WOOTBOT.GQ WORM! Win32edit.exe
Windows 32 Rescue
Added by the FORBOT-EU WORM! win32resc.exe
Windows 32 Update
Added by a variant of the RBOT WORM! Windows-Update.exe
Windows Accelerators
KeySpy keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove setup.exe
Windows AdControl
Windupdates adware variant WinAdCtl.exe
Windows AdService
Windupdates adware variant WinAdServ.exe
Windows AdStatus
Added by the BLESHARE!DR VIRUS! WinStat.exe
Windows AdTools
Windupdates adware variant WinAdTools.exe
Windows Anti-Virus Built 32
Added by the SDBOT-BG WORM! AntiVirus32.exe
Windows API Control Task
Added by the MYTOB.HI WORM! apitsk32.exe
Windows Application Layer
Added by the AGOBOT.ATN WORM! walg32.exe
Windows Application Layer Gateway
Added by the AGOBOT-AAZ WORM! walg32.exe
windows auto update
Added by the BLASTER (or MSBLAST.A) WORM! penis32.exe
Windows Auto Update
Added by the SDBOT.TF WORM! winupdater.exe
Windows auto update
Added by the AHKER.E WORM! bazzi.exe
Windows auto update
Added by the AHKER.G WORM! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup! LSASS.exe
windows auto update
Added by the BLASTER.B WORM! msblast.exe
Windows Automatic Update
Added by a variant of the RBOT WORM! wuamgrder.exe
Windows Automatic Updates
Added by the RBOT.MF WORM! dvldr.exe
Windows AutomaticUpdater
Added by a variant of the RBOT WORM! runddls.exe
windows automation
Added by the BLASTER.E WORM! mslaugh.exe
Windows Automation
Added by the SOLAME.A WORM! msdspr.exe
Windows Autostart Loader
Added by a variant of the RBOT WORM! notepad32.exe
Windows backup
Added by a variant of the SPYBOT WORM! systemss.exe
Windows Backup Configuration
Added by the GAOBOT.AZ WORM! IEXPLORER.exe
Windows Baþlangýç Dosyasý
Added by the MUZK WORM! sistem.exe
Windows Bootup
Added by the RBOT-AFM WORM! ms-wks32.exe
Windows Bootup
Added by a variant of the RBOT WORM! Systemwks32.exe
Windows Client Service 32
Added by the RBOT-ALB WORM! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! csrss.exe
Windows Client/Server Runtime Server
Added by the RBOT.KD WORM! csrs.exe
Windows Command
Added by the RBOT.ANV WORM! wincmd.exe
Windows Communicator
Added by the AGOBOT-BH WORM! wincomm.exe
Windows Compliant
Added by the RBOT-IR WORM! [random filename]
Windows Config
Added by the SPYBOT-DA WORM! SSYS.EXE
Windows Config
Added by the SPYBOT.JR WORM! wins.exe
Windows Config Loader
Added by the SILVERFTP TROJAN! Wincfg32.exe
Windows Configuration
Added by the GAOBOT.FB WORM! wsys32.exe
Windows Configuration
Added by the MYTOB.ED WORM! wincfg32.exe
Windows Console Monitor
Added by KEDEBE WORM! [path to worm]
Windows Console Monitor
Added by the KEDEBE-A WORM! gcasAV32.exe
Windows Control
Browser hijacker. NOTE - On Win9x systems it will overwrite the Windows file of the same name in the Windows directory, so therefore it will be necessary to extract a fresh copy of the file from the Windows setup cabs! Control.exe
Windows ControlAd
Windupdates adware variant WinCtlAd.exe
Windows CPU host
Added by a variant of the RBOT WORM! winbog32.exe
Windows Data Server
Added by the SPYBOT-CB WORM! autodisc.exe
Windows Data Server
Added by the SPYBOT-DS WORM! [random name].exe
Windows Database
Added by an unidentified WORM or TROJAN! WinDat.exe
Windows Database
Added by the AGOBOT-RU WORM! wiinsvc.exe
Windows Dcom2 Fix
Added by the RBOT-QT WORM! mscom32.exe
Windows DDE Loader
Added by the SDBOT-UZ WORM! windde32.exe
Windows debug logging
Added by the RBOT-OY WORM! winlogg.exe
Windows debug logging
Added by the RBOT-QN WORM! winloggs.exe
Windows Debugger
Added by an unidentified VIRUS, WORM or TROJAN! windbg.exe
Windows Debugger
Added by a variant of the RBOT WORM! msdbg32.exe
Windows Debugger
Added by the ZOTOB.L WORM! windbg32.exe
WINDOWS DENEME
Added by the MYTOB-CR WORM! deneme.exe
Windows Desktop Controler
Added by the SDBOT-XH WORM! windesktop.exe
Windows Desktop Daemon
Added by a variant of the SPYBOT WORM! winpadg.exe
Windows Dialup Service
Added by the AGOBOT.AAH WORM! dialup.exe
Windows DLL host
Added by a variant of the SPYBOT WORM! winupd32.exe
Windows DLL Host
Added by an unidentified WORM or TROJAN! dllhost32.exe
Windows DLL Loader
Added by the DOMWIS TROJAN! RUNDLL16.EXE
Windows DLL Loader
Added by the LINKBOT.A WORM! defragfat32z.exe
Windows DLL Loader
Added by the WHIPSER-B WORM! Note - rundll32.exe file is placed in the WindowsSystem folder, wheras the legitimate rundll32.exe is located in the C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP) rundll32.exe
Windows DLL Loader
Added by the RBOT-QQ WORM! defragfat32pi.exe
Windows DLL Loader
Added by the POEBOT-C WORM! defragfat39.exe
Windows DLL Loader
Added by the LINKBOT.H WORM! defragfatz.exe
Windows DLL Loader
Added by the SDBOT-SS WORM! defragfat32.exe
Windows DLL Loader
Added by the RBOT-RG WORM! defragfat32abc.exe
Windows DLL Loader
Added by a variant of the SDBOT WORM! wdevice.exe
Windows DLL Loader
Added by the DOMWIS-N WORM! SYSCFG16.EXE
Windows DLL Loader
Added by the AGOBOT-TE WORM! WINCFG32.EXE
Windows DLL Services
Added by the RBOT-ZF WORM! winsvc32.exe
Windows DLL Services
Added by the AGENT.H spyware! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! svchost.exe
Windows DLL Services
Added by the AGENT.H spyware system.exe
Windows DLL Tracker
Added by a variant of the WOOTBOT WORM! spoolsrv.exe
Windows DNS
Added by the SDBOT-XU WORM! windns.exe
Windows DNS Daemon
Added by the WOOTBOT.AS WORM! windnsd.exe
Windows Domain Name Drivers
Added by the FORBOT-EP WORM! windns.exe
Windows Download Manager
Added by an unidentified TROJAN! windlmngr.exe
Windows Drive Compatibility
Added by the SUPOVA.Z WORM! System32Driver32.exe
Windows Driver
Added by the WOOTBOT.EE WORM! winxpdriver.exe
Windows Driver Adapter
Added by the ANTINNY-K WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! svchost.exe
Windows Driver Services
Added by the WOOTBOT.L WORM! msdrvs32.exe
Windows drivers update
Added by the RBOT-ACE WORM! windowsupdate.exe
Windows Dynamic Loading Header
Added by a variant of the SDBOT WORM! winDLL32.exe
Windows Executable
Added by the RBOT-ABO WORM! winmys.exe
Windows ExpIorer
Added by the RBOT-AKO WORM! [random filename]
Windows Explorer
Added by the SDBOT TROJAN! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually [filename].exe
Windows Explorer
Added by the GAOBOT.AO WORM! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually Lsas.exe
Windows Explorer
Added by an unidentified WORM or TROJAN! olecom32.exe
Windows Explorer
Added by a variant of the SPYBOT WORM! EEXPLORER.EXE
Windows Explorer
Added by the POEBOT-J WORM! Note - the valid "explorer.exe" will always be located in C:Windows or C:Winnt folder whereas this one is found in the C:WindowsSystem folder (Win98/ME) or in the C:WinntSystem32 or C:WindowsSystem32 subfolder (Win2K/XP) explorer.exe
Windows Explorer
Added by the RBOT-AID WORM! explorer.pif
Windows Explorer
Added by the RBOT-AJH WORM! system32.exe
Windows Explorer Shell
Added by the REDIST.B WORM! Winexec32.exe
Windows Explorer SP2
Added by the BANKER-DM TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! csrss.exe
Windows Explorer Update Build 1142
Added by the KaZaA based KWBOT or KWBOT.Y WORMS! EXPLORER32.EXE
Windows Explorer-3212
Added by the HARDOC WORM! WINRE16.EXE
Windows Eyes
For blind people, gives a voice description of items on the screen. Windows application which gives you total control over what you hear, when you hear it, and how you hear it. Available via Start -> Programs ??
Windows FAT 32
Added by the SPYBOT-AGT WORM! WINFAT32B.exe
Windows File Protection
Added by the AGOBOT.JB WORM! winprotect.exe
Windows Firewal
Added by a variant of the RBOT WORM! Lsess.exe
Windows Firewall
Added by the MYTOB.AO WORM! WindowsFirewall.exe
Windows Firewall Log
Added by an unidentified WORM or TROJAN! winlog.exe
Windows Firewall Manager
Added by the RBOT.WR WORM! msfw.exe
Windows Firewalll
Added by the RBOT-EK WORM! scvhost.exe
Windows Firewalll
Added by a variant of the RBOT WORM! sphost.exe
Windows Firewalll
Added by a variant of the RBOT WORM! svvhost.exe
Windows Firewalll
Added by a variant of the RBOT WORM! winmu.exe
Windows Fix
Added by the SDBOT.ZAB WORM! integator.exe
Windows Fixes Systems
Added by the MYTOB.EG WORM! elite.exe
Windows FormatAd
Windupdates adware variant WinForm.exe
WINDOWS **** BY CLASIC
Added by the ZOTOB.H or ZOTOB.J WORMS! ****.exe
Windows Generic Proc
Added by the ALLIM.B WORM! procmsg.exe
Windows Graphics Loaders
Added by the SPYBOT.JG WORM! wingraphics.exe
Windows Guardian
Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes thehel1iawgrd32.exe
Windows Guardian
Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes Fawgrd32.exe
Windows Help
Added by the MYTOB.JX WORM! mailinfo.exe
Windows Help File
Added by the SDBOT-QK TROJAN! winhelper32.exe
Windows Help Manager
Added by the RBOT-OZ WORM! svchost32.exe
Windows Help Service
Added by the RBOT-LP WORM! winhelpsv.exe
Windows Help Service
Added by the RBOT-AKW WORM! winhlp.pif
Windows Help System
?? Help.pif
Windows Host
Added by the KELVIR.U WORM! hosts.exe
Windows Host
Added by the PRYSAT TROJAN! winhost.exe
Windows Host Device
Added by the ZOOTY-A WORM! hostsvc.exe
Windows Host Name
Added by the GAOBOT.O WORM! lmass.exe
Windows Host Service
Added by the SPYBOT.NLI WORM! scvhosts.exe
Windows Host Service
Added by KELVIR.AN WORM! host.exe
Windows Host Service
Added by the KELVIR.BF WORM! svchoste.exe
Windows Host Service
Added by the KELVIR.AW WORM! svchosts32.exe
Windows Host32 Starter
Added by the SDBOT-WU WORM! hostserv.exe
Windows Hosts
Added by the KELVIR-O TROJAN! hosts.exe
Windows HTML file reader
Added by the NOOMY.A WORM! Sysconf32.exe
Windows Icons Manager
Added by the RBOT-AIF WORM! wicomgr.exe
Windows iMessenger Messenger
Added by the ALLIM.A WORM! winimsg.exe
Windows installer
SpySheriff malware winstall.exe
Windows Installer
Added by an unidentified WORM or TROJAN! ntdll.exe
Windows Internet Protocol
CoolWebSearch parasite variant winproc32.exe
Windows IPv6 Drivers
Added by the SDBOT-VJ WORM! wipv6.exe
Windows JavaScript Daemon
Added by the WOOTBOT.AF WORM! Winjsd.exe
Windows kev Messenger
Added by the SDBOT-XV WORM! mskev.exe
Windows Load
?? windows.com
Windows Loader
Added by the GAOBOT.CA WORM! wstart32.exe
Windows Loader Service
Added by a variant of the RBOT WORM! civsc.exe
windows Loadxm
Added by the FODDER-A TROJAN! Win_.exe
Windows Local Services
Added by the DLOADER-NY TROJAN! localsvc.exe
Windows Local Services
Added by the DLOADER-NY TROJAN! netsvc.exe
Windows Local Services
Added by the DLOADER-NY TROJAN! spoolsvc.exe
Windows Local Services
Added by the DLOADER-NY TROJAN! svcadmin.exe
Windows Local Services
Added by the DLOADER-NY TROJAN! svcman.exe
Windows Local Services
Added by the DLOADER-NY TROJAN! svcrun.exe
Windows Local Services
Added by the DLOADER-NY TROJAN! tcpsvc.exe
Windows Local Services
Added by the DLOADER-NY TROJAN! websvc.exe
Windows logging
Added by the RBOT-ON WORM! winlogd.exe
Windows Login
Added by the GAOBOT.SY WORM! explored.exe
Windows Login
Added by the AGOBOT.MG WORM! winlog.exe
Windows Login Security
Added by an unidentified WORM or TROJAN! winlogin.pif
Windows Login Service
Added by the RBOT-AFN WORM! winlog.exe
Windows Login Service
Added by the SDBOT-ACU WORM! winlogin.pif
Windows Logon
Added by the SPYBOT-C TROJAN! winlogin.exe
Windows Logon Application
Added by the LINKBOT.M WORM! WinIogon.exe
Windows Logon Application
Added by the POEBOT-J WORM! logon.exe
Windows Logon Application
Added by the CIADOOR-L TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! services.exe
Windows Logon Manager
Added by a variant of the RBOT WORM! logon.exe
Windows Logon Procedure
Added by a variant of the SPYBOT WORM! Svchoste.exe
Windows Logon Procedure
Added by a variant of the SPYBOT WORM! Svchosta.exe
windows logon procedure
Added by the WINLOGON TROJAN! winlogonpc.exe
Windows Management Instrumentation
Added by the GRAPS WORM! mwd.exe
Windows Management Instrumentation
Added by the QEDS-A VIRUS! [path to file]
WINDOWS MANAGEMENT SYSTEM
Added by the RBOT-VT WORM! wm1exe.exe
Windows Manager
Added by the MANTAS WORM! winmants.exe
Windows Manager
Added by a variant of the AGOBOT/GAOBOT WORM! winsrv.exe
Windows Manager Update Inc
Added by the SDBOT-ACM WORM! tgb.exe
Windows mangement
Added by the RANDEX.FC WORM! winlogonn.exe
Windows Media AP
Added by an unidentified WORM or TROJAN! winmapp.exe
Windows Media APP
Added by an unidentified WORM or TROJAN! wmapp.exe
Windows Media Driver
Added by a variant of the RBOT WORM! msnger.exe
Windows Media Player
Added by the AGOBOT-NQ WORM! wmediaplayer.exe
Windows Media Player
Added by the SDBOT-QO TROJAN! - note, the executable is called 'MediapIayer', with an 'i' !) MediaPIayer.exe
Windows Media Player
Added by a variant of the RBOT WORM! [random filename]
Windows Media Player
Added by the RBOT-SI WORM! msa.exe
Windows Media Player
Added by the RBOT-YO WORM! mcafe32.exe
Windows Media Player
Added by the KELVIR.G WORM or variants! Note - this is not the valid Windows Media Player as the executeable resides is C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP) rather than C:Program FilesWindows Media Player wmplayer.exe
Windows Media Player
Added by a variant of the RBOT WORM! 50cent.exe
Windows Media Player
Added by the RBOT-TT WORM! mpwe.exe
Windows Media Player
Added by the RBOT.AHR WORM! msams.exe
Windows Media Player 3.6
Added by a variant of the RBOT WORM! wmpa36.exe
Windows Media Player 3.6b
Added by the RBOT-VV WORM! WMPA36B.EXE
Windows Media Player 3.6d
Added by the RBOT-YA WORM! wmpa36d.exe
Windows Media Player 3.9
Added by a variant of the RBOT WORM! wmpa36.exe
Windows Media Player Update
Added by the RBOT-ET WORM! [random filename]
Windows Media Powerpoint Helper
German software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start -> Programs NSPPTHLP.EXE
Windows media service
Added by the SDBOT.VP WORM! crvss.exe
Windows media service
Added by the RBOT.ACY WORM! crsss.exe
Windows media services
Added by the RBOT-MW WORM! cvrsss.exe
Windows Media SP.2.37
Added by the LEMIR.C TROJAN! [random filename]
Windows Media Utility
Added by a variant of the SPYBOT WORM! wmediautil.exe
Windows messenger
Added by the MYTOB.EI WORM! messengers.exe
Windows Messenger
Added by a variant of the FORBOT WORM! msnsmgs.exe
Windows Messenger Messenger
Added by VELKBOT.A WORM! winmsg.exe
Windows Messenger Service
Added by the RBOT-VW WORM! winsmsgr.exe
Windows Messenger Service
Added by the MYTOB.HY WORM! kaspersky.exe
Windows MeTaLRoCk service
Added by the TASTYRED TROJAN! metalrock.exe
Windows Micro Drivers
Added by the RBOT-AEH WORM! wupdates32.exe
Windows Monitor
Added by the SDBOT.VB WORM! winmon.exe
Windows Monitor
Added by the SPAZBOX.A TROJAN! arsetup.exe
Windows Monitor Services
Added by the RBOT-XX WORM! winmonitor.exe
Windows Monitoring Service
Added by a variant of the SDBOT WORM! winmon.exe
Windows More Choice
ZQuest adware TopContext.exe
Windows Mouse Utilities
Added by the RBOT-ABU WORM! mouseutils.exe
Windows ms Drivers
Added by the SDBOT-AAL WORM! msnup32.exe
Windows MSConfig Startup Logger
Added by the RBOT.BCU WORM! winlog.exe
Windows NetDDe
Added by the MYTOB.IM WORM! wrmana32.exe
Windows Nets
Added by the RBOT-MO WORM! WinNET.exe
Windows NetStart Service
Added by the RBOT-ZX WORM! winsN2S.exe
Windows NetStart Service2
Added by the RBOT-ABN WORM! winsN2S.exe
Windows NetStart Service2
Added by a variant of the RBOT WORM! winsN2SD.exe
Windows Network Controller
Added by the FORBOT-CL WORM! Mqguard.exe
Windows Network Controller
Added by the FORBOT-DK WORM! WinxPupd.exe
Windows Network Controller
Added by the FORBOT-ED WORM! winmms32.exe
Windows Network Controller
Added by a variant of the SDBOT WORM! wingmt.exe
Windows Network Controller
Added by the WOOTBOT.I WORM! Win9x.exe
Windows Network Firewall
Added by the POEBOT-J WORM! firewall.exe
Windows Network Service
Added by the RBOT.RY WORM! winvc32.exe
Windows Networking
Added by the GAOBOT.FL WORM! winsys32.exe
Windows Networks
Added by the MYTOB.FH WORM! netcog.exe
Windows Nivedia Driver
Added by a variant of the RBOT WORM! sysMGT.exe
Windows NNT
Added by the RANKY.E TROJAN! [path to trojan]
Windows NT 32
Added by the RANDEX.BRD WORM! ntlogin32.exe
Windows NT Login
Added by the SDBOT.WG WORM! ntlogin32.exe
Windows NT Login Session Manager
Added by the RBOT.BIV WORM! WNSM.EXE
Windows NT Logon Application
Added by the RBOT-ALP WORM! winlogon.scr
Windows NT Service Name
Added by the RBOT-PK WORM! winshock.exe
Windows NT Update Manager
Added by the AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital "o" WINL0G0N.exe
Windows OEM Tools
Added by the SPYBOT.FD WORM! winres32.exe
Windows OLE Automation Server
CoolWebSearch parasite related browser hijacker ole32aut.vbe
Windows Online Updater
Added by the RBOT-TE WORM! dllman.exe
Windows PDG
Added by the RBOT-ADW WORM! winpdg.exe
Windows PNP
Added by the RBOT-AKN WORM! winpnp.exe
Windows PNP Server
Added by this variant of the SDBOT WORM! pnpsrv.exe
Windows Print Spooler
Suspicious due to the similarity to the valid "svchost.exe" file SCVHOSTS.EXE
Windows Print Spooler
Added by an unidentified VIRUS, WORM or TROJAN! NavAgent32.exe
Windows Print Spooler
Added by the SPYBOT.H WORM! SVEHOST.EXE
Windows Process Manager
Added by an unidentified WORM or TROJAN! winproc.exe
Windows Processe Manager
Added by a variant of the RBOT WORM! mspn32.exe
Windows Protectot
Added by a variant of the WOOTBOT WORM! boxide.exe
Windows Reg Services
Added by the REDRIVAL-A WORMW ffservice.exe
Windows Reg Services
Added by the PRORAT-D TROJAN! dservice.exe
Windows Reg Services
Added by the PRORAT-D TROJAN! fservice.exe
Windows Reg Services
Added by the PRORAT-D TROJAN! ssservice.exe
WINDOWS REGISTER EDIT
Added by an unidentified WORM or TROJAN! registr32.exe
Windows Register Settings
Added by a variant of the FORBOT WORM! svmhost.exe
Windows Registry
Added by a variant of the RBOT WORM! msnmsg.exe
Windows Registry
Added by a variant of the RBOT WORM! winhost.exe
Windows Registry Cleaner
Added by a variant of the SPYBOT WORM! winclean.exe
Windows Registry Express Loader
Added by the FORBOT-CJ WORM! regexpress.exe
Windows Registry Manager
Added by the MYTOB.ER WORM! tasksmanagers.exe
Windows Registry Name
Added by the RBOT-AEB WORM! [random filename]
Windows Registry Name
Added by the RBOT-ADB WORM! winses.exe
Windows Registry Scan
Added by the RBOT.KE WORM! regscan32.exe
Windows Registry Scan
Added by the SPYBOT.JE WORM! timeupdate.exe
Windows Registry Scan
Added by the RBOT-TP WORM! svcdll.exe
Windows Registry Security
Added by a variant of the IRC.BOT TROJAN! crss.exe
Windows Registry Startup
Added by the AGOBOT-BZ WORM! wind32.exe
Windows report
Added by the SMALL-BD TROJAN! swchost.exe
windows run
Added by the ICPASS-A WORM! system.exe
Windows Runtime Help
Added by a variant of the AIMVISION TROJAN! win32hlp.exe
Windows Runtime Help
Added by a variant of the AIMVISION TROJAN! WinRunHelp.wrh
Windows Runtime Proccess
Added by the SDBOT.QW WORM! 32RUNdll.exe
Windows SA
BLAZEFIND adware omniscient.exe
Windows Screensaver
Added by the KELVIR.P WORM! Service.exe
WINDOWS SCREENSAVER
Added by the SDBOT-YZ WORM! ssaver.scr
Windows secure
Added by the SPYBOT.EP WORM! setver32.exe
Windows Secure Connection
Added by a variant of the RBOT WORM! winsc.exe
Windows Secure Messaging System
Added by the RBOT-RE WORM! msnmsgrsrvc.exe
WINDOWS SECURITY
Added by a variant of the RBOT WORM! wingrd.exe
Windows Security Assistant
CoolWebSearch parasite variant rundll32.vbe
Windows Security Assistant
CoolWebSearch parasite variant winsec.exe
Windows Security Authority Service
Added by the KALEL-A WORM! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup! lsass.exe
Windows Security Manager
Added by the AGOBOT-KI WORM! winsecurity.exe
Windows Security Manager
Affilred.B adware winsecure.exe
Windows Security Module
Added by a variant of the RBOT WORM! module.exe
Windows Security Service
Added by the RBOT-ALV WORM! [random file name]
Windows Security Update
Affilred.B adware security32.exe
Windows Serv Patch
Added by a variant of the RBOT WORM! Mcaffe2005.exe
Windows ServeAd
Windupdates adware variant WinServAd.exe
Windows Server Information
Added by the FORBOT-EN WORM! servinfo.exe
Windows Servic2
Added by the RBOT-AIA WORM! winsy.exe
Windows service
Added by the RBOT-QW WORM! wuamgrd.exe
Windows Service
Identified by Kaspersky Labs as Dialer.Salc, also known to come with the Bube family trojans dddd.exe
Windows Service
Malware, recognized by Kaspersky antivirus as Trojan-Dropper.Win32.Small.rd prvdi.exe
Windows Service
Added by an unidentified TROJAN! video.exe
Windows Service
Added by the AGOBOT-HL WORM! svvhost.exe
Windows Service
Added by an unidentified TROJAN.CLICKER! private-zone.exe
Windows Service
Added by the SMALL.VZ TROJAN! pd7.exe
Windows Service
Added by an unidentified TROJAN! dstart4.exe
Windows Service
Adware, detected by TDS-3 as "TrojanDownloader.Win32.Delf.dg" pd14.exe
Windows Service
Added by the DOWNLOADER.SMALL.MY TROJAN! video2.exe
Windows Service
Added by the KALEL-A WORM! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! services.exe
Windows Service
Added by the SDBOT.CL WORM! WINSVC.EXE
Windows Service Controller
Added by the KALEL-B WORM! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! services.exe
Windows Service Host
Added by the SDBOT.N TROJAN! scvhost.exe
Windows Service Host
Added by the CONE.B WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! svchost.exe
Windows Service Host
Added by the KALEL-C WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup and is always located in the System32 folder. This worm file is found in the System folder svchost.exe
Windows Service Host Process
Added by the EZIO-A WORM! [path to file]
Windows Service Loader
Added by the RBOT-XO WORM! Window.exe
Windows Service Manager
Added by the OSCABOT-C WORM! userint32.exe
Windows Service Manager
Added by the DLOADER-NY TROJAN! localsvc.exe
Windows Service Manager
Added by the OSCABOT-E WORM! msgs.exe
Windows Service Manager
Added by the OSCABOT-G WORM! msnmrg.exe
Windows Service Manager
Added by the DLOADER-NY TROJAN! netsvc.exe
Windows Service Manager
Added by the DLOADER-NY TROJAN! spoolsvc.exe
Windows Service Manager
Added by the DLOADER-NY TROJAN! svcadmin.exe
Windows Service Manager
Added by the DLOADER-NY TROJAN! svcman.exe
Windows Service Manager
Added by the OSCABOT-D WORM! svcmgr32.exe
Windows Service Manager
Added by the DLOADER-NY TROJAN! svcrun.exe
Windows Service Manager
Added by the DLOADER-NY TROJAN! tcpsvc.exe
Windows Service Manager
Added by the DLOADER-NY TROJAN! websvc.exe
Windows Service Pack Auto Update
Adware downloader, identified by eScan antivirus as Trojan-Clicker.Agent.bt winworks.exe
Windows Service Pack Auto Update
Added by a TROJAN.CLICKER - identified by Kaspersky antivirus as Trojan-Clicker.Agent.bt figgaz.exe
Windows Service Pack Auto Update
Added by an unidentified WORM or TROJAN! ballin.exe
Windows Service Pack Auto Update
Adware, also detected as the LOWZONES.BH TROJAN! del-me.exe
Windows Service Pack2
Added by a variant of the RBOT WORM! svchhost.exe
Windows Service Support Call
Added by the RBOT-XQ WORM! SVSS32.EXE
Windows Service XP
Added by the MYTOB.AM WORM! XpFirewall.exe
Windows Services
Added by the RANDEX.R WORM! service.exe
Windows Services
Added by the AGOBOT-KL TROJAN! svchosts.exe
Windows Services
Added by the SDBOT-WT WORM! Note - the valid "explorer.exe" file is located in C:Windows or C:Winnt, whereas this one is located in the WindowsSystem32 or WinntSystem32 folder! Explorer.exe
Windows Services
Added by the RBOT-ACR WORM! NetworkDriver32.exe
Windows Services
Added by a variant of the SDBOT WORM! scmsg.exe
Windows Services
Added by SPYBOT.OBZ WORM! scvhoste.exe
Windows Services
Added by the MYTOB-CB WORM! winsvc32.exe
Windows Services
Added by the SDBOT-YO WORM! NetworkDrivers.exe
Windows Services
Added by a variant of the SDBOT WORM! smsc.exe
Windows Services Host
Added by the CONE or CONE.E WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! svchost.exe
Windows Services Hosts
Added by the SDBOT-YH TROJAN! svhosts.exe
Windows Services Ink Platform Tablet Input Subsystem
Added by the RBOT.APC WORM! wsiptis.exe
Windows Services Update
Added by a variant of the RBOT WORM! Note - the filename has the digit 0 rather then the uppercase "o" svch0st.exe
Windows Session Manager
Added by a variant of the RBOT WORM! smss32.exe
Windows Session Manager Subsystem
Added by the KALEL-B WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup! smss.exe
Windows shell
?? win70.exe
Windows Shell
Added by the MYTOB-CA WORM! shell.exe
Windows Shell
Added by the MYTOB.BV WORM! taskgmr.exe
Windows Shell Library Loader
CoolWebSearch parasite variant load shell.dll /c /set
windows shellext.32
Added by the BLASTER.K WORM! mschost.exe
WINDOWS SKY
Added by the MYTOB.CH WORM! sky.exe
Windows Smart Manager
Added by the RBOT-SL WORM! smart.exe
Windows Sound Driver
Added by a variant of the SPYBOT WORM! SndMon32.exe
Windows Sound Manager
Added by the FORBOT-BU WORM! SndMon32.exe
Windows Sound Manager
Added by a variant of the FORBOT WORM! SndMon16.exe
Windows SP2 Firewall
Added by a variant of the RBOT WORM! wfirewall7.exe
Windows SP2 Update
Added by the WOOTBOT.BS WORM! Sp2update.exe
Windows SP2 Version Load
Added by the GAOBOT.CX WORM! wuauclt32.exe
Windows SP4
Added by the RBOT-ACX WORM! directCC.exe
Windows Spool Server
Added by the SDBOT-ACT WORM!lder. spoolsrv.exe
Windows SpoolaPrint Service
Added by the SDBOT-AYD WORM! spoolasrv.exe
Windows Spooler
Added by the SPYBOT.P WORM! SPOOLSRV.EXE
Windows Spooler
Added by an unidentified WORM or TROJAN! spoolsv32.exe
Windows Spooler Services
Added by the AGOBOT-AMO WORM! spool.exe
Windows SpoolPrint Service
Added by the SDBOT-ZT WORM! spoolersrv.exe
Windows spoolservr Service
Added by the SDBOT-AAN WORM! spoolservr.exe
Windows Spoolsre Service
Added by the SDBOT-AAE WORM! spoolsre.exe
Windows Spoolsrv Service
Added by the SDBOT-ZS WORM! spoolmsv.exe
windows spoolsrv service
Added by the SDBOT-AWV WORM! spoolssv.exe
Windows Spoolsurf Service
Added by the SDBOT-ZZ WORM! spoolsurf.exe
Windows SpooltPrint Service
Added by the SDBOT-AYE WORM! spooltsrv.exe
Windows sq Drivers
Added by the RBOT-ADI WORM! winmsn32.exe
Windows Sql Service For Windows 32 Bit
Added by the FORBOT-FC WORM! winsql32.exe
Windows SSL File
Added by the WOOTBOT.CA WORM! winssv.exe
Windows Stand Sound Drivers
Added by the SDBOT-XF WORM! Sounddrv.exe
Windows Standard Securty
Added by the RBOT-ALF WORM! [random 3-letter filename]
Windows Start Server 2000
Added by the RBOT-AHM WORM! traficy.exe
Windows Startup
GoHip foistware winsta~1.exe
Windows Startup
GoHip foistware winstartup.exe
Windows Startup
Added by the GAOBOT.AO WORM! Wdrun32.exe
Windows Startup
Added by the AGOBOT-MX WORM! services21.exe
Windows Startup 32 Bits
Added by a variant of the DARKSUN TROJAN! sysrun32.exe
Windows Streams Server
Added by the SDBOT.LN WORM! localsrv.exe
Windows SyncroAd
Windupdates adware variant SyncroAd.exe
WINDOWS SYSTEM
Added by the MYTOB.DF WORM! beta.exe
WINDOWS SYSTEM
Added by the MYTOB.EO WORM! dcomuser.exe
WINDOWS SYSTEM
Added by the MYTOB.GC WORM! lf66prc.exe
WINDOWS SYSTEM
Added by the MYTOB.EH WORM! msdev32.exe
WINDOWS SYSTEM
Added by the MYTOB-L WORM or variants! nec.exe
WINDOWS SYSTEM
Added by the MYTOB-BY WORM! nibie.exe
WINDOWS SYSTEM
Added by the MYTOB-EP WORM! ninfoie.exe
WINDOWS SYSTEM
Added by the MYTOB-CX WORM! skybot.exe
WINDOWS SYSTEM
Added by the MYTOB-BY WORM! skybotx.exe
WINDOWS SYSTEM
Added by the MYTOB.FU WORM! smoc.exe
WINDOWS SYSTEM
Added by the MYTOB-BR WORM! smsc.exe
WINDOWS SYSTEM
Added by the MYTOB.DJ WORM! test.exe
WINDOWS SYSTEM
Added by the MYTOB.DJ WORM! test2.exe
WINDOWS SYSTEM
Added by the MYTOB.DV WORM! test3.exe
WINDOWS SYSTEM
Added by the MYTOB-BY WORM! wdns33.exe
WINDOWS SYSTEM
Added by the MYTOB.FA WORM! win.exe.exe
WINDOWS SYSTEM
Added by the MYTOB-DN WORM! winaup.exe
WINDOWS SYSTEM
Added by the MYTOB.EP WORM! winligon.exe
WINDOWS SYSTEM
Added by the MYTOB.GB WORM! winmon.exe
WINDOWS SYSTEM
Added by the MYTOB-DM WORM! winNTsys32.exe
WINDOWS SYSTEM
Added by the MYTOB.HH WORM! winsvc32.exe
Windows System
Added by the RBOT-AEF WORM! WINSYS.exe
WINDOWS SYSTEM
Added by the MYTOB.EK WORM! winsys33.exe
WINDOWS SYSTEM
Added by the MYTOB.EU WORM! winvnc.exe
WINDOWS SYSTEM
Added by the MYTOB-BQ WORM! winxpserv.exe
WINDOWS SYSTEM
Added by the MYTOB.CZ WORM! xxx.exe
WINDOWS SYSTEM
Added by the MYTOB.JU WORM! skybot.exe
WINDOWS SYSTEM
Added by the ZOTOB WORM! botzor.exe
WINDOWS SYSTEM
Added by the MYTOB.HU WORM! gothica.exe
WINDOWS SYSTEM
Added by the MYTOB.IK WORM! msnl.exe
WINDOWS SYSTEM
Added by the ZOTOB.C WORM! per.exe
WINDOWS SYSTEM
Added by the MYTOB-EG WORM! twunk_65.exe
Windows System 32-Bat Service
Added by the MYTOB.FI WORM! win32bat.exe
Windows System Backup
Unidentified malware SysBackup.exe
WINDOWS SYSTEM Cleaner
Added by the MYTOB.EQ WORM! h3.exe
WINDOWS SYSTEM CLEANER
Added by the MYTOB.ET WORM! iexplore.exe
Windows System Configuration
Added by the WISDOOR.Z TROJAN! SYSCFG16.EXE
Windows System Configuration
Added by the DOMWIS-E TROJAN! Passcfg16.exe
Windows System Configuration
Added by the BACKDOOR.SOLUFINA TROJAN or the DOMWIS-J WORM! Winfrw.exe
Windows System Configuration
Added by the AGOBOT.OP WORM! wincfg.exe
Windows System Configuration
Added by the AGOBOT-TE WORM! WINCFG32.EXE
Windows System Configuration
Added by the RETHE-A WORM! WinNeth.exe
WINDOWS SYSTEM Dns
Added by the MYTOB.EY WORM! windsns.exe
WINDOWS SYSTEM DNSPOOL
Added by the MYTOB.FW WORM! hbmail.exe
Windows System File
Added by the SPYBOT.KHO WORM! cmxp.exe
Windows System Gateway
Added by a variant of the RBOT WORM! SPOOLER.EXE
Windows System Init
Added by a variant of the RBOT WORM! winit32.exe
Windows System Manager
Added by the RBOT-AN WORM! winsystem.exe
Windows System Manager
Added by the MYTOB.AL WORM! sysconf.exe
Windows System Manager
Added by a variant of the RBOT WORM! smsc.exe
Windows System Manager
Added by the RBOT-AFH WORM! crssm.exe
Windows System Manager Loader
Added by the AGOBOT.TF WORM! smsls.exe
Windows System Manager Proc
Added by the RBOT.JH WORM! winsmc.exe
windows system notepad
Added by an unidentified WORM or TROJAN! wnpsm.exe
Windows System Restore Configuration
Added by a variant of the SPYBOT WORM! Sblhost.exe
Windows System Restorer
Added by the DULOAD.C WORM! SystemRestorer.exe
Windows System Security
Added by the RBOT.IV WORM! winmp.exe
Windows System Security Monitor
Added by the PINKTON.A WORM! [4 random letters].exe
Windows System Serivce
Added by a variant of the RBOT WORM! winserv.exe
windows system service
Added by the RBOT-MR WORM! winsock.exe
Windows System Tray
Iambigbrother monitoring software msni.exe
Windows System Tray
Added by an unidentified VIRUS, WORM or TROJAN! swhost.exe
WINDOWS SYSTEM UPDATE
Added by the MYOTB-EH WORM! xDcc.exe
Windows System32
Added by the MYTOB.GD WORM! windowsp.exe
Windows Systemnmg
Added by the MYTOB.S WORM! stagmr.exe
Windows Sz Host
Added by a variant of the SDBOT WORM! winshvc.exe
Windows Task Manager
Added by the QUATERS.A WORM! ACCOUNT_DETAILS.DOC.exe
Windows Task Manager
Unidentified malware, either a variant of the WIN32.RBOT WORM, or part of a Casino Palazzo foistware install taskmgn.exe
Windows Task Manager
Added by the MYTOB.AV WORM! taskmrg.exe
Windows Task Manager
Added by the MYTOB.BJ WORM! taskgmr.exe
Windows Task Manager
Browser hijacker - identified by DrWeb antivirus as "Trojan.StartPage.601" taskmg.exe
Windows Task Manager Emulator
Added by the SPYBOT-FA WORM! kennewr.exe
Windows TaskAd
Windupdates adware variant Wintaskad.exe
Windows Taskbar Manager
Added by the PROTORIDE-H WORM! internat.exe
Windows Taskbar Manager
Added by the PROTORIDE.B WORM! [path to file]
Windows Taskbar System
Added by a variant of the SDBOT WORM! tasksys.exe
Windows Taskmanager
Added by the KELVIR.E WORM! lsassx.exe
Windows TCP/IP
Added by the AGOBOT-ZH WORM! wintcp.exe
Windows Telnet Server
Added by the AGOBOT-MW WORM! wintel.exe
Windows Time
Added by a variant of the RBOT-YK WORM! tmservice.exe
Windows Time
Added by the RBOT-XC WORM! winmgr.exe
Windows Time Server
Added by the SPYBOT.DNC WORM! TimeSRV.exe
Windows TM
Added by a variant of the RBOT WORM! SVPHOST.exe
Windows TM
Added by a variant of the RBOT WORM! rundlI32.exe
Windows TM
Added by a variant of the RBOT WORM! windowssys32.exe
Windows TM
Added by a variant of the RBOT WORM! WinxSys.exe
Windows Upate
Added by the HAKO TROJAN! Note - this is NOT the Windows system file of the same name as described here rundll.exe
Windows Update
Added by the NORIO TROJAN! Acts as a hi-jacker redirecting to adult content sites [filename]
Windows Update
Added by the GAOBOT.AP WORM! iexplorere.exe
windows update
Added by the LEOX TROJAN! uddater.exe
Windows Update
Added by the AGOBOT.ML WORM! wudate.exe
Windows Update
Wengs adware wupdate.exe
windows update
Added by the LEOX.B WORM! sychost.exe
Windows Update
Added by a variant of the SPYBOT WORM! Wuamgrd.exe
Windows Update
Added by a variant of the AGOBOT/GAOBOT WORM! inetinf.exe
Windows Update
Added by the RBOT-GU WORM! host32.exe
windows update
Added by the RBOT-PO WORM! wuraclt.exe
windows update
Added by the RBOT.XZ WORM! Wuanclt.exe
Windows Update
Added by the GAOBOT.BUU WORM! ebay.exe
Windows Update
Added by the RBOT-RB WORM! windows.exe
windows update
Added by the RBOT.ADG WORM! wuaurlt.exe
Windows Update
Added by the DELF-FN TROJAN! Update.exe
Windows Update
Added by the RBOT-EM WORM! winmguard.exe
Windows Update
Added by the RBOT.UM WORM! wuampd.exe
windows update
Added by the RBOT-OF WORM! wuarclt.exe
Windows Update
Added by the SDBOT-WS WORM! winupdate.exe
Windows Update
Added by the RBOT-AAH WORM! msnwinsb.exe
Windows Update
Added by the SDBOT-XT WORM! scvhost.exe
windows update
Added by the LMIR.A TROJAN! Microsoft.exe
Windows Update
Added by the MOEGA WORM! mplupdate.exe
windows update
Added by the RBOT-AHN WORM! msnsever.exe
Windows Update
Added by the MYTOB-GZ WORM! taskmr.exe
Windows Update
Added by a variant of the RBOT WORM! update32.exe
Windows Update
Added by the MYTOB.GA WORM! wininfo.exe
Windows Update
Added by the BANKER-DV TROJAN! winlogin.exe
Windows Update
Added by the RBOT-ALK WORM! Note - this file has nothing to do with Windows updates or MSN msnupdates.exe
Windows Update
Added by the RBOT-AKU WORM! Note - do not confuse with the Quicken file of the same name as described here qtask.exe
windows update
Added by the LEGMIR-AU WORM! real.exe
Windows Update
Added by the BANCD-A TROJAN! windowsx.exe
Windows Update 32
Added by the FORBOT-FI WORM! winlogons.exe
Windows Update Auto Update
Added by a variant of the SPYBOT WORM! wuaumgr.exe
Windows Update AutoUpdate Client Product
Added by the AGOBOT.ACL WORM! wuauct.exe
Windows Update Center
Added by the STUBBOT.A WORM! svthx.exe
Windows Update Checker
Adware downloader trojan [random filename]
Windows Update Client
Added by the SMALL-RN TROJAN! wuclient.exe
Windows Update Client Service
Added by the AGOBOT-MM TROJAN! windrvl32.exe
Windows update config
Added by the SDBOT-PF WORM! svhost.exe
windows update configurator
Added by a variant of the SPYBOT WORM! svghost.exe
Windows Update Controller
Added by the BATTRY-A TROJAN! mwoffice.exe
Windows Update Files
Added by an unidentified VIRUS, WORM or TROJAN! Note - wupdmgr.exe is the real Windows Update dnetc.exe
Windows Update Manager
Added by the RANDEX.BTB WORM! wupdmngr.exe
Windows Update Manager
Added by the AGENT-BO TROJAN! Winlog0n.exe
Windows Update Manager
Added by a variant of the RBOT WORM! wupdate.exe
Windows Update Manager for NT
Added by the SDBOT.AH WORM! wupdmgr32.exe
Windows Update Monitoring Service
Added by the RBOT-PL WORM! winupdt.exe
Windows Update Process
Added by the SDBOT-CB WORM! wmiprvsc.exe
Windows Update Service
Added by the AGOBOT-NI WORM! csrs.exe
Windows Update Service
Added by the SDBOT.QY WORM! smcg.exe
Windows Update Service
Added by the SDBOT-ZH WORM! SP00ISS.exe
Windows Update Service
Added by the RBOT-ALC WORM! update32.pif
Windows Update Service 2004/2005
Added by the RBOT-JE WORM! systemupdate.exe
Windows Update services
Added by a variant of the RBOT WORM! wins32svcs.exe
Windows Update Software
Added by the TOFGER.BX TROJAN! system.exe
Windows Update System Shell
Added by the RBOT-AAZ WORM! svhostcs32.exe
Windows Update V6
Added by the RBOT-KT WORM! [random filename]
Windows Update.exe
Homepage hijacker, see here N/A
Windows Updater
Added by a variant of the DOS.AUTOCAT TROJAN! wupdmgr32.exe
Windows Updater
Added by the RBOT-TN WORM! iexplorerrs.exe
Windows Updater
Added by the RBOT-VS WORM! svigost.exe
Windows Updater
Added by the WOOTBOT.AJ WORM! wupdate.exe
Windows Updates
Added by a variant of the SDBOT WORM! lsassx.exe
Windows Updates
Added by the MYTOB.CE WORM! winupd32.exe
Windows Updates
Added by the SDBOT-BFW WORM! w32dns.exe
Windows Updating Service
Added by the RBOT-ALW WORM! updating.pif
Windows Updtee Mgnr
Added by the MYTOB.DC WORM! W1NT45K.exe
Windows USB controler
Added by the RBOT-HR WORM! winusb.exe
Windows USB Driver Support
Added by a variant of the SPYBOT WORM! Windowsusb.exe
Windows USB Service
Added by the MYTOB.AR WORM! 666.exe
Windows USBD
Added by an unidentified WORM or TROJAN! msifirewall.exe
Windows User Mode Driver Manager
Added by SDBOT-ZN WORM! wdfmrg.exe
Windows User Starter
Added by the RBOT.SN WORM! winuser32.exe
Windows Version Check
Version checker for CyberAudioLibrary ("A new way to exchange information through the Internet") ver_chk.exe
Windows video
Added by a variant of the AGOBOT/GAOBOT WORM! vide_32.exe
Windows Video Acquisition (WVA)
Added by the AGOBOT.YM WORM! wvsvc.exe
Windows Video Drivers
Added by the GAOBOT.AZT WORM! videons32.exe
Windows Web Services
Added by the DLOADER-NY TROJAN! localsvc.exe
Windows Web Services
Added by the DLOADER-NY TROJAN! netsvc.exe
Windows Web Services
Added by the DLOADER-NY TROJAN! spoolsvc.exe
Windows Web Services
Added by the DLOADER-NY TROJAN! svcadmin.exe
Windows Web Services
Added by the DLOADER-NY TROJAN! svcman.exe
Windows Web Services
Added by the DLOADER-NY TROJAN! svcrun.exe
Windows Web Services
Added by the DLOADER-NY TROJAN! tcpsvc.exe
Windows Web Services
Added by the DLOADER-NY TROJAN! websvc.exe
Windows Workstation
Added by a variant of the RBOT WORM! mpci.exe
Windows Workstation
Added by a variant of the SDBOT WORM! msup32a.exe
Windows Workstation Service (32-bits)
Added by a variant of the SDBOT WORM! wkssvc32.exe
Windows Workstation Start Service
Added by a variant of the RBOT WORM! mslanmgr.exe
Windows Xp
Added by the MYTOB-DZ WORM! nortonguard.exe
Windows XP Automatic Update
Added by the RBOT-AFC WORM! wXPupdate.exe
Windows Xp Service Pack 2
Added by the XPLOS-A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! svchost.exe
Windows-System
Added by the LOGPOLE.C WORM! System32.exe
Windows-TCP-IP
Added by the GIPMA TROJAN! rfkampig.exe
Windows-XP-Service-Pack
Added by the SDBOT-AAC WORM! xpspz.exe
windows16
Added by the XU TROJAN! windows16.exe
Windows32
Added by the AGOBOT-LK or AGOBOT-ND WORMS! rundll.exe
windows32
Added by the XU TROJAN! windows32.exe
Windows32
Added by the BRATLE.B WORM! wuuaclt.exe
Windows32 Configuration Loader
Added by the SDBOT-ABX WORM! msrf32.exe
Windows32 Messenger Service
Added by the RBOT.ANS WORM! msmsgv.exe
Windows32 Net Database
Added by the RBOT-AAL WORM! msnd32.exe
Windows32 Serivces
Added by the SPYBOT.AAF WORM! winser32.exe
WindowsAgent
Added by the GOP.G WORM! WindowsAgent.exe
WindowsAgent
Added by the GOP keyboard logger/TROJAN! sysexhook.exe
WindowsAPI.DLL
Added by the "Fear and Hope" TROJAN! Server5.exe
WindowsBackup
Added by the STANG WORM! WINDOWSBACKUP.EXE
WindowsCRC
Added by the SDBOT-VU WORM! wscrc.exe
WindowsCriticalUpdate
Added by the ASTEF or RESPAN WORMS! windows_critical_update.exe
WINDOWSflashbrg
Added by a variant of the AGENT-IC TROJAN! sqldata1.exe
WindowsFY
Part of a "Security IGuard" parasite infestation - also detected as DESKTOPHIJACK wp.exe
WindowsFY
Added by a variant of the DESKTOPHIJACK TROJAN! For removal see here bsw.exe
WindowsFZ
Added by the DESKTOPHIJACK VIRUS! Also see DESKTOPHIJACK.B TROJAN! [path to file]
WindowsFZ
Variant of the SmitFraud alias FAKEALE-C TROJAN! A5281300.so
WindowsFZ
Variant of the SmitFraud alias FAKEALE-C TROJAN! zloader3.exe
WindowsKeyUpdate
Added by the JOSAM WORM! master.exe
WindowsMGM
Added by the SOBIG WORM and LALA.C TROJAN! Winmgm32.exe
WindowsReg% update
Added by the RBOT-HH WORM! [random filename].exe
WindowsRegistration
Added by the RBOT-NO WORM! [random filename]
WindowsRegKey Autoupdate
Added by a variant of the RBOT WORM! [random filename]
WindowsRegKey upd4te2d4te
Added by the RBOT.XQ WORM! *********.exe [* = random char]
WindowsRegKey update
Added by a variant of the RBOT WORM! [random filename]
WindowsRegKey update
Added by the RBOT-QJ WORM! winupdate.exe
WindowsRegKey update
Added by the RBOT.IE WORM! windns.exe
WindowsRegKey update
Added by a variant of the RBOT WORM! 16winupdate32.exe
WindowsRegKey update
Added by the RBOT-AGW WORM! WinUpdate32.exe
WindowsRegKey update
Added by the RBOT.LW WORM! winupdatexx.exe
WindowsRegKey update
Added by the RBOT.QT WORM! [random filename]
WindowsRegKey update
Added by the RBOT.ADB WORM! svchoosts.exe
WindowsRegKey update
Added by the RBOT.IF WORM! svchostc.exe
WindowsRegKey update
Added by the SDBOT.QX WORM! wdnupdate.exe
WindowsRegKey update
Added by the SDBOT.PU WORM! Windowsup.exe
WindowsRegKey update
Added by the RBOT-MM WORM! WINUPDATES.EXE
WindowsRegKey update XP
Added by the RBOT-ABM WORM! windexv1.exe
WindowsRegKey%$ update
Added by the RBOT-IX WORM! msi332.exe
WindowsRegKey%update
Added by the RBOT-EN WORM! ethernet32m.exe
WindowsRegKeys update
Added by the SDBOT.WE WORM! winsysi.exe
WindowsRegKeys update
Added by a variant of the RBOT WORM! windup.exe
WindowsSetup
Added by the EZBOT TROJAN! [path to trojan]
WindowsUpd
VirtuMonde adware WindowsUpd4.exe
WindowsUpd1
VirtuMonde adware WindowsUpd1.exe
WindowsUpd2
VirtuMonde adware WindowsUpd2.exe
WindowsUpdate
Added by the LOFNI WORM! windows_update.exe
WindowsUpdate
Added by the ASTEF or RESPAN WORMS or AGENT-V TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! svchost.exe
windowsupdate
Added by the IRCBOT.B TROJAN! RPCX1sQ3.exe
WindowsUpdate
Added by the MADDIS.B WORM! USRINIT.EXE
windowsupdate
Added by the WARPI WORM! winupdate.exe
WindowsUpdate
Added by the IK TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! svchost.exe
WindowsUpdate Service
Added by the RBOT-NR WORM! wuautlc.exe
WindowsXP Module
Malware, reportedly a keylogger - see here DirectX3D.exe
WindowsXP Update
Added by the RBOT-PB WORM! windowsxpupdate.exe
WindowsXPserv
Addee by the NANINF-A TROJAN! svcnxp32.exe
Windows_Protect
Added by a variant of the RBOT WORM! winsystem.exe
Windows_Protect
Added by a variant of the RBOT WORM! winregal.exe
Windows_Protect
Added by the RBOT.ARO WORM! lsas.exe
Windows_Protect
Added by the RBOT-ADK WORM! wincontrol32.exe
Windows_Serivce
Added by the WOOTBOT.AH WORM! SERVICE.exe
Windows_Updates
Added by a variant of the SPYBOT WORM! svthost.exe
Windows_VXD
Added by the PWSTEAL.PPORT TROJAN! user32.exe
Windowz
Added by the NUKIP WORM! [original worm filename].vbs
Windowz Update V2.0
Added by the YODO WORM! Note - the valid "explorer.exe" is located in C:Windows or C:Winnt whereas this one is located in the System32 sub-directory Explorer.exe
Windoxs Update Center
Added by a variant of the SDBOT WORM! W32RfSA.exe
WinDrg32
Added by the DRUDGEBOT.A WORM! windrg32.exe
WinDriv32
Added by the SMALL-BA TROJAN! WinDriv32.exe
WinDriver Configuration
Added by the AGOBOT-LX TROJAN! windrvconf.exe
WINDRUN
Added by the MYTOB-BT WORM! taskgmrs.exe
windrv
Added by an unidentified VIRUS, WORM or TROJAN! - possibly a strain of OBLIVION or BIONET windrv32.exe
WinDrv
Added by a variant of the TIBSER.A downloader TROJAN! windrvx.exe
WinDSL MTU-Adjust
Adjusts the registry setting of the DUN-Adapters (MTU) and the TCP/IP-Protocol (RWIN) by ENGEL Technologieberatung WinDSL_MTU.exe
WinDSL_MTU
May be realted to Tiscali broadband, if so is it required? WinDSL_MTU.exe
WinDSNX
Added by the DNSX TROJAN! Win????.exe
WindUpdates
Added by the AGENT.BF TROJAN! [path to trojan]
WindUpdates
Windupdates adware variant WinUpdt.exe
WINDVDpatch
CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Crea CTHELPER.EXE
WinDVR SchSvr
WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs SchSvr.exe
WinDVRCtrl
Control center software for an AOpen VA1000 TV tuner card WinDVRCtrl.exe
Windws Configuration Loader
Added by the SODABOT WORM! LEXPLORE.exe
WinEssential
Hijacker - hailing from jraun.com Keyhost.exe
WinEssential
Jraun.com hijacker keyword.exe
WinExec
Added by the AINESEY.A WORM! Winexec.exe.vbs
WinExec
Added by the FALUS-A WORM! WinExec.exe
WinExec32
Added by the KAZWIN WORM! WinExec32.exe
WinFast Schedule
Leadtek WinFast TV tuner scheduler Wfwiz.exe
Winfast2KLoadDefault
Loads default settings for Leadtek Winfast graphics cards Rundll32.exe Wf2kcpl.dll, DllLoadDefaultSettings
Winfast_2K
System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or WF2k.exe
WinFast_Gamma
Loads if you change the gamma settings on Leadtek WinFast graphics cards Rundll32.exe wfcpl.dll, DllLoadGammaRampSettings
WinFast_Taskbar
Loads default settings for Leadtek WinFast graphics cards rundll32.exe wftask.dll, WFDllLoadDefaultSettings
WinFavorites
Loudmarketing.com adware downloader WinFavorites.exe1
WinFax PRO Controller
From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs WFXCTL32.EXE
WinFaxAppPortStarter
WinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application. wfxsnt40.exe
WinFire
Added by the DELF-SY TROJAN! WF.exe
WinFixer 2005
Foistware, pretending to be system optimization, protection and recovery software - stealth installed, see here wfx5.exe
winfont
Added by the DEATH TROJAN! winfont.exe
WinFoxV2
System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or WF2k.exe
WinFX
Added by the AGOBOT.FX WORM! cssrs.exe
WinGate
Added by a variant of the LOVGATE WORM! WinGate.exe
WinGate Engine Monitor
WinGate Internet Client Dialup Monitor - component of WinGate proxy server software. Displays the status of the WinGate engine, and appears in the system tray of each workstation on the network reassuring clients that their workstations have connectivity wgengmon.exe
WinGate initialize
Added by a variant of the LOVGATE WORM! WinGate.exe
wingo
Added by the BEAGLE.AW or BEAGLE.AV WORMS! wingo.exe
wingo
Added by the BAGLE-AU WORM! [various filenames]
WinGuage Pro
Part of McAfee Nuts & Bolts. "WinGauge is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious". Resource hog. Available via Start -> Programs WGPRO32.EXE
Winguard
Dr Solomon's Virex antivirus WGFE95.EXE
WinGuard Pro
Winguard Pro wgp.exe
WinHacker
Tweaking utility by Wedge Software. There are far better tweakers and, unlike WinHacker, most are free rundll32.exe wh95.dll, HackMe
Winhelp
Added by the QQPASS.E TROJAN! winhe1p.exe
WinHelp
Added by a variant of the LOVGATE WORM! Note - "winhelp.exe" resides in C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K), or C:WindowsSystem32 (WinXP) whereas the valid "winhelp.exe" resides in C:Windows or C:Winnt WinHelp.exe
WinHelp
Added by a variant of the LOVGATE WORM! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name realsched.exe
Winhelp
Added by a variant of the LOVGATE WORM! TkBellExe.exe...
winhelp
Added by the BLACKMAL.C WORM! Note - this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot. Name field may be empty winhelp.exe
winhelp
Added by a variant of the RBOT WORM! dns32.exe
winhelp
Added by the QQPASS-N TROJAN! Updadv.exe
winhlp.exe
Added by the FORMGLIEDER TROJAN! winhlp.exe
winhlp3.exe
Added by a variant of the EASTO.A TROJAN! winhlp3.exe
Winhlp32
Added by the GANT.B WORM! Wscript.exe ..Msexec32.vbs
winhlp32.exe
Added by a variant of the EASTO.A TROJAN! winhlp32.exe
winhlpp32.exe
Added by the GAOBOT.SY WORM! winhlpp32.exe
Winhost
Added by the LOLAWEB.B TROJAN! wintt.exe
Winhost
Added by the DLOADER-AP TROJAN! win.exe
Winhost
Added by the DELF-KM TROJAN! yahoo.exe
Winhost
Added by the REATLE.F WORM! winhost.exe
winhost.exe
Added by the LOHAV-R TROJAN! winhost.exe
winhost32.exe
Added by the TABDIM TROJAN! winhost32.exe
WinIeRun
Added by the RNWATCH-A WORM! winierun.exe
winimage
Added by the RBOT.TX WORM! wvsvc.exe
wininet32
Added by the RAZNEW-A TROJAN! wininet32.exe
wininetd
Added by the WINET TROJAN! wininetd.exe
wininit
Added by the WOLLF.16 TROJAN! wininit.exe
WinInit
Added by the SMALL-PB TROJAN! Win86.exe
winipsec
Unidentified malware winipsec.exe
WinIRXHelper
MSI(tm) Media Center Deluxe software - see here WinIRXHelper.exe
winis
Added by the RBOT-WI WORM! winis.exe
Wink*.exe
Added by a variant of the KLEZ WORM! Wink*.exe [* = random char]
Winkb6
Part of We-Blocker, works in tandem with syswb6. Both files are needed to run WeBlocker. Required if We-Blocker is installed winkb6.exe
WinKernel
Added by the MIRAB or SERVIDOR TROJANS! WinKer.exe
WinKernel
Added by the BIONET.31 or BIONET.310 [path to worm]
WinLibUpdate32
Added by the BIONET.405 TROJAN! libupdate32.exe
WinLibUpdte
Added by the BIONET.318 TROJAN! libupdte.exe
Winlink
Added by the GAOBOT.AAY WORM! winlink32.exe
Winlme
Added by the GOP.F WORM! windll.exe
WinLoad
PCTattletale is a surveillance software program that monitors user activity, logs keystrokes, and takes screenshots. If you didn't install this yourself remove it Winload.exe
WinLoader
Added by variants of the SUBSEVEN TROJAN! [random filename]
winlocatorupdate
Locator adult content toolbar related updatewinlocator.exe
winlog manager
Added by the DONBOMB.A TROJAN! winlog.exe
WINLOG0N
Added by the MYDOOM.BI WORM! WINLOG0N.EXE
WinLogin
Added by the AGOBOT-IX WORM! winlogin.exe
winlogin
Browser hijacker, also detetected as the STARTPA-DF TROJAN! win32x.exe
Winlogin.exe
Added by a variant of the AGENT.AH downloader TROJAN! log.exe
winlogin.exe
Added by the AGENT.AH TROJAN! logfile.exe
winlogin.exe
Added by a variant of the AGENT.AH TROJAN! mspaint.exe
Winlogin.exe
Added by a variant of the AGENT.AH TROJAN! steam.exe
winlogon
Windows Logon Process - handles user logons described here winlogon.exe
winlogon
Hijacker or adult content dialler - file is located in C:Windows or C:Winnt, and not in it's System or System32 subdirectory, as is the case with the legitimate Windows Logon (winlogon.exe) process winlogon.exe
winlogon
Added by the RANDEX.E WORM! winlogin.exe
winlogon
Added by the TRODAL TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! File is located in C:Windows or C:Winnt, and not in it's System or System32 subdirectory winlogon.exe
winlogon
Added by the SDBOT.EO WORM! msreg32.exe
winlogon
Added by the MASLAN.C WORM! winlogon32.exe
winlogon
Added by an unidentified WORM or TROJAN! wpwlogon.exe
WINLOGON
Added by the YPSAN.F WORM! wscript.exe [System or System32]WINLOGON.vbs
winlogon service
Added by the SPYBOT.EN WORM! urx.exe
Winlogon Shell
Added by the KIPIS.M WORM! Explorer.exe svchost.exe
Winlogon.exe
CoolWebSearch parasite related - resets home page to an adult content site N/A
winlogon.exe
Added by the FAKESPY-A TROJAN! helper.exe
winlogon.exe
Adware, also detected as the FAKESPY-B TROJAN! msole32.exe
winlogon32_
Added by the RULAND.A WORM! [path to file]
WinLsass
Added by the SCANE WORM! servicec.exe
WinLsass
Added by the SCANE WORM! [path to trojan]
winltmpv
Added by the TCXMEDI-C TROJAN! winln.exe
winltmpv
Added by the TCXMEDI-C TROJAN! wutop.exe
Winmain
One of the first of a new breed of malware. When run it immediately loads MSHTA.EXE from the Windows folder, placing it on "hot standby", ready to accept HTA scripting within a web page and then EXECUTE what is embedded IN the page as a program! In other winmain.exe
WinManager
?? schost.exe
winmatrix.exe
WinMatrix XP - wallpaper replacement that shows different matrix effects (including flowing matrix codes from 'The Matrix' movie) on your desktop WinMatrixXP.exe
WinMem
WinMem Cleaner - part of Ultra WinCleaner Utility Suite. Makes more memory available for your programs and the Operating System. It also defragments your system WinMem.exe
WinMenssage
Added by the BANCOS.B TROJAN! winmax.exe
WinMessenger
Added by the OPANKI-E WORM! syshost.exe
WinMgmt
Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here WinMgmt.exe
WINMGR
Added by the MYTOB.AN WORM! taskgmgr.exe
Winmgr.exe
Added by the AGOBOT.AFG WORM! scvhost.exe
WinMgr32
Added by the MIMAIL.P WORM! winmgr32.exe
WinMine
Added by the BISCUIT.A WORM! D4NG3.vbs
winmodem
Software for software based modems. Required if you have one of these. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information wmexe.exe
WinMoviePlugIn
Sfonditalia adult content premium rate dialer WinMoviePlugIn.exe
WinMsrv32
Added by the GAOBOT.AFJ WORM! WinMsrv32.exe
WinMX
WinMX file sharing application WinMX.exe
winmysqladmin
Starts the MySQL database admin tool winmysqladmin.exe
WinMySQLadmin Tool
Starts the MySQL database admin tool winmysqladmin.exe
winnet
CommonName Toolbar spyware. To uninstall see here winnet.exe
WinNetDDE
Added by the NETDEPIX.B TROJAN! [random characters].exe
WinNite
Added by the OPANKI.B WORM! niteaim.exe
Winnov Menu
Winnov Video Capture Card related. What does it do and is it required? WnvMenu.Exe
Winnov Remote
Winnov Video Capture Card related. What does it do and is it required? WnvRsvr.Exe
Winnov Status
Winnov Video Capture Card related. What does it do and is it required? WvStatus.Exe
winnt DNS ident
Added by the RBOT-BAU WORM! wuamgrd32.exe
winnt DNS ident
Added by a variant of the RBOT WORM! iexplorer.exe
winnt DNS ident
Added by the RBOT-ACY WORM! pidchk32.exe
winnt DNS ident
Added by a variant of the RBOT WORM! windowxp.exe
winnt DNS ident
Added by the RBOT.AVU WORM! Winupd32.exe
winnt DNS ident
Added by a variant of the RBOT WORM! winupdate32.exe
winnt DNS ident
Added by a variant of the RBOT WORM! wuamgrd33.exe
Winnt DNS ident
Added by the RBOT.BAL WORM! windowsp.exe
winNT updatc
Added by a variant of the RBOT WORM! wupgrd.exe
WinNtBB
Added by the DULOAD.C WORM! WinntBB.exe
Winnup
Added by a variant of the SPYBOT WORM! win32nls.exe
winocx32
Added by the PROTORIDE.I WORM! winocx32.exe
WINOWS SYSTEM
Added by the MYTOB.ID WORM! winnt.exe
Winpack
Adware downloader - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Agent.gg winpack.exe
WinPatrol
WinPatrol - "Manage Startup programs, tasks, cookies; will sniff out Worms, Trojan horses, Cookies, Adware, Spyware, Klez, Assumption and other malicious programs" WinPatrol.exe
winphonics7536
Added by a variant of the MUTIN-C TROJAN! vbsystem35.exe setups.exe vb.vb
winpipe
Browser hijacker redirecting to wow-access.com winpipe.exe
WinPLOSION
WinPLOSION allows you to immediately view and select from all the windows running on your computer, just those of the active application, or to minimise all windows and display a clear desktop WinPlosion.exe
WinPoet
WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet cu WinPPPoverEthernet.exe
WinPopup
Intranet chat software provided by windows for chat on small networks. Handy little LAN messaging utility. Has been included in Windows since 95, and maybe in WFWG 3.11. Normally it won't set itself up to run unless the user specifically adds it to startu WINPOPUP.EXE
winpopup
Adware by Tradeexit.com winupie.exe
Winprocer32 Update
Added by the RBOT.GW WORM! winprocer32.exe
winprocessor Update
Added by the RBOT.IO WORM! winprocessor.exe
WinProfile
Added by the BUDDY TROJAN! Command.exe
WinProfile
Added by the SNDC.A WORM! sndcfg16.exe
winprofile
Added by a variant of the MONCHER WORM! iexpiore.exe
WinProfile
Added by CHUM-C TROJAN! iexpIore.exe
WinProt
Added by the CHUPACABRA TROJAN! Winprot.exe
WinProt
Added by the CHUPACABRA TROJAN! server.exe
winprotect
Added by the MUGLY.E WORM! win32.exe
winprotect
Added by the SDBOT-SB WORM! winprotect.exe
WinProxy
WinProxy is the world-first proxy server and a firewall with integrated mail server for Windows 95/98/ME/NT/2000/XP WinProxy.EXE
Winproxy Personal
Added by the SDBOT.BMF WORM! WINPROXY.EXE
winpsd
Added by the MYDOOM.Q WORM! winpsd.exe
winrapid
Added by a variant of the RBOT WORM! winrapid.exe
winrar
CoolWebSearch parasite variant. Note - this is not the file zipping utility also known as WinRAR and it's located in C:Winnt or C:Windows winrar.exe
winrarshell
Added by the SALIRA TROJAN! winrarshell32.exe
winReg
Added by the YAHA.H or YAHA.J WORMS! winReg.exe
winregsrv
Added by the SYNRG TROJAN! winregsrv.exe
winreg_32
Added by the BANCOS-CE TROJAN! svchosst.exe
winreg_32
Added by the BANKER-DB TROJAN! [path to trojan]
winreg_32
Added by the DLOADER-IJ TROJAN! sysdll.exe
winreg_32
Added by the BANCOS-CT TROJAN! Vc030405.exe
Winres32vis
Added by the THRAX.A WORM! [path to worm]
winrestore1
Added by the KILLFIL-Q TROJAN! winrestore.exe
winreups
Added by a variant of the RBOT WORM! winreups.exe
winroute
Win-Route 4.27. WinRoute Tray Icon for starting and stopping the WrCtrl.exe process, also to log in to the console to view logs and change settings. Can be unchecked and the engine still runs and functions normally. Can then use provided shortcuts for adm winroute.exe
winrun
Added by the WINUR.A WORM! Note - this is not the real msconfig.exe as it's located in C:winrun msconfig.exe
winrun
Added by the WINBUR.B WORM! winrun.exe
WINRUN
Added by the MYTOB.AP WORM! taskgmr32.exe
WINRUN
Added by the MYTOB-AI WORM! svchost32.exe
WINRUN
Added by the MYTOB-BX WORM! taskgmr.exe
WINRUN z
Added by MYTOB.BL WORM! W1NT45K.exe
WinRunners
Added by the DULOAD.C WORM! WinDrivers.exe
Wins32 Online
Added by the BROPIA.R WORM! cfgpwnz.exe
WinScMngr
Added by the SDBOT-BPZ WORM! winsmc.exe
WinSec
Added by the AGOBOT.ZF WORM! winsec16.exe
winsecure
Browser hijacker, redirecting to specificsearches.com winsecure.exe
Winsecure Antivirus
Added by a variant of the SPYBOT WORM! Secureantivirus.exe
WinSecured32
Added by a variant of the FORBOT WORM! ssmr.exe
Winserv
Added by the NODMIN WORM! Winserv.ila
winserver
Added by the DELTAD.A WORM! Server.txt.vbs
Winservice
Adult content related malware winmain.exe
WinService32
007 Spy Software - "stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP" ssmgr.exe
WinService32
Added by the 007 Spy Software keystroke logger/monitoring program. remove unless self installed! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! svchost.exe
WinServices
Added by the YAHA.K or YAHA.M WORMS! WinServices.exe
winservit
Added by the RBOT.ASG WORM! cassl.exe
winservn
PurityScan/Clickspring adware winservn.exe
winservs
PurityScan/Clickspring adware winservs.exe
WinSetBrowse
Added by the BISCUIT.A WORM! BasicUpdate.dll.vbs
Winshoe
Probably an unidentified VIRUS! Adds itself to 3 registry "Run" keys and prevents Task Manager being displayed. This is not the Winshoe IRC Client as the visitor did not have it installed wuadfdqr.exe
winshost.exe
Added by the TOOSO WORM and variants! winshost.exe
WinShowUpdate
Winshow parasiate related - from the "RunOnce" keys it replaces "winshow.dll" with a new version copy C:WINDOWSwinshow.new C:WINDOWSwinshow.dll
WinSig
Added by the BANKER-FN TROJAN! NetXP.exe
winsock
Added by the SAGE-A WORM! Note - the filename has the digit 0 rather then the uppercase "o" svch0st.exe
Winsock driver
Added by the SPYBOT-DM TROJAN! winnt update.exe
Winsock driver
Added by the SPYBOT-DR WORM! winnt64.exe
winsock2
Added by the AGOBOT.LY WORM! netsvr.exe
Winsock2 driver
Added by the SPYBOT.DR TROJAN! SDJOIJE.EXE
Winsock2 driver
Added by the SPYBUZZ TROJAN! MIRC32.exe
Winsock2 driver
Added by the SDBOT.T TROJAN! kgzgjkpcw.exe
Winsock2 driver
Added by the SDBOT.T TROJAN! Note - ZONEALARM.EXE is not the valid Zone Labs firewall program ZONEALARM.EXE
Winsock2 driver
Added by a variant of the SPYBOT WORM! WINCFG.SCR
Winsock2 driver
Added by the SPYBOT-BX WORM! winupdate.exe
Winsock2 driver
Added by the SPYBOT-CM WORM! SPOLSV.EXE
Winsock2 driver
Added by a variant of the SPYBOT WORM! Zonealarmupdate.exe
Winsock2 driver
Added by the SPYBOT-CC WORM! sysreq.exe
Winsock2 driver
Added by a variant of the SPYBOT WORM! AMSNMGR.EXE
Winsock2 driver
Added by the SPYBOT-DP WORM! WUAUMQR.EXE
Winsock2 driver
Added by the SPYBOT.CO WORM! wincfg.exe
Winsock2.dll
Added by an unidentified VIRUS, WORM or TROJAN! WINLODR.SCR
Winsock32 driver
Added by the SPYBOT.B WORM! Testing.exe
Winsock32 driver
Added by the SPYBOT.B WORM! lcd.exe
Winsock32 driver
Added by the SPYBOT.B WORM! Sdjoije.exe
Winsock32driver
Added by the HACARMY TROJAN! win32server.scr
Winsock32driver
Added by the HACKARMY.S TROJAN! sp2XPupdate.exe
Winsock32driver
Added by the BACKDOOR-AZV TROJAN! win32server.exe
Winsock32driver
Added by the HACKARMY-B TROJAN! ZoneAlarmPr0.exe
Winsock32driver
Added by the HACARMY.D TROJAN! ZoneLockup.exe
Winsock32driver
Added by the HACARMY.F TROJAN! win32server.exe
Winsock32driver
Added by the HACKARMY.9728 TROJAN! winXPupdate.exe
Winsock32driver
Added by the HACKARMY.I TROJAN! svchhost.exe
winsockdriver
Added by the SDBOT.GEN TROJAN or WARPIGS.C WORM! tskmg.exe
winsockdriver
Added by a variant of the SPYBOT WORM! winsock2.2.exe
winsockdriver
Added by the BLATIC.A WORM! iexplor.exe
winsockdriver
Added by the SPYBOT-DO WORM! winsock3.exe
WinSocketComponent
Added by an unidentified VIRUS, WORM or TROJAN! nthost.exe
WINSOS VERIFY
WinSOS - "deletes spyware, optimizes your computer - backs up selected data" WINSOS.EXE
winspd32dll
Added by a variant of the AGOBOT/GAOBOT WORM! winspd32.exe
WinSPF
Added by the MYDOOM.T WORM! windrv32.exe
WinSPF
Added by the MYDOOM.S WORM! winspf32.exe
Winspl
Added by a variant of the TROLL-A TROJAN! winsplx.exe
Winspool
Added by a variant of the SDBOT WORM! spoolsvr.exe
WinSrv
Added by the HOBBIT.F WORM! kn0x.exe
WinSrv
Added by the HOBBIT.C WORM! SHIZZLE.EXE
Winsrv
Added by the OPASERV.T WORM! winsrv.exe
WinStabilizer
Added by the AGOBOT-SW WORM! WinStabilizer.exe
WinStart
From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge WinStart.exe
WinStart
Added by the CIAN.C WORM! Wscript.exe WinStart.vbs
WinStart
Added by the PUROL WORM! winstart32.exe
WinStart
Added by the CONE.E WORM! WinStart.pif
winstart
Added by the SCKEYLO-AB TROJAN! winstart.exe
WinStart001
From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge WinStart001.exe
WinStart001.EXE
From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge WinStart001.exe
winstats
Added by the GARGAFX TROJAN! winstats.exe
Winsta~1
GoHip foistware winsta~1.exe
WinSth16
Added by the CAKE WORM! WinSth16.exe
winstro
Added by the FTP_ANA TROJAN! RUN32DLL.exe
WinSvc16.exe
Added by the SDBOT.FQ TROJAN! WinSvc16.exe
Winsvc32
Homepage hijacker Winsvc32.exe
winsvc32.exe
Added by the GREPAGE TROJAN! winsvc32.exe
Winsvr manager
Added by the TIRBOT-C WORM! DDEsvr.exe
winsy32.exe
Trojan, CoolWebSearch parasite related winsy32.exe
winsync
Added by a variant of the QOOLOGIC TROJAN! ******.exe reg_run [* = random char]
Winsys
Win-Spy - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it Winsys.exe
WINSYS
Added by the GOLDPLAY TROJAN! [path to trojan]
winsys
Added by an unidentified TROJAN! syschost.exe
WinSys32
Added by the CIGIVIP TROJAN or RECKUS WORM! Winsys32.exe
winsys32 Driver
Added by the LOONY-O TROJAN! winsys32.exe
WinSysAppMon
Home & Family Content Filter related. See here WinSysRM.exe
winsyslog lptt01
Variant of the RapidBlaster parasite (in a "Winsyslog" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here winsyslog.exe
WinSysStartUpWKbLw
Added by the BACKZAT.G WORM! TaskSystemDll.Exe
WinSyst32
Added by the MORB WORM! winsyst32.exe
WinSystem
Added by the WHITEBAIT WORM! winsystem.exe
Winsystem
Added by the BANCOS.CR TROJAN! winsystem.exe
WinSystem
CMKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! WinSystems.exe
WINT
PurityScan/Clickspring adware wcp****.exe [* = random char]
WINT
PurityScan/Clickspring adware wcpcc.exe
WINT
PurityScan/Clickspring adware wcpsvit.exe
WinTask
Added by the HIPO or LEMIR.F TROJANS! Wintask.exe
WINTASK
Added by the MYTOB.I WORM and variants! taskgmr.exe
WINTASK
Added by the MYTOB.AU WORM! taskgamr.exe
WINTASK
Added by the MYTOB.K WORM! sys32.exe
WINTASK
Added by the MYTOB.AQ WORM! msmgrxp.exe
WINTASK
Added by the MYTOB-CH WORM! iexplorer.exe
WINTASK
Added by the MYTOB.BU WORM! taskgmr32.exe
WINTASK
Added by the MYTOB-AR WORM! msvhost.exe
WINTASK
Added by the MYTOB-AK WORM! t4skmgr.exe
WINTASK
Added by the MYTOB.EF WORM! taskfile.exe
WINTASK
Added by the MYTOB-AO WORM! taskgm.exe
WINTASK
Added by the MYTOB.DH WORM! taskgmrs.exe
WINTASK DLL
Added by the MYTOB.AI WORM! jusched32.exe
WINTASK DLL32
Added by the MYTOB.BS WORM! smsrss.exe
WinTask driver
Added by the DLOADER-NA TROJAN! wintask.exe
WINTASK32
Added by the MYTOB.BN WORM! taskgmr32.exe
WINTASK32
Added by the MYTOB.FX WORM! taskgmrr.exe
WINTASKMANAGER
Added by the MYTOB-AF WORM! taskgmr.exe
WINTASKMGR
Added by the MYTOB.Q WORM! ccsrs.exe
WINTASKS
Added by the MYTOB.BO WORM! taskgmr.exe
WINTASKS
Added by the MYTOB.EZ WORM! winxpro.exe
WinTasks DLL Library (32-bits)
Added by the RBOT-AJZ WORM! winkll.exe
WinTasks Traybar
WinTasks - "Efficient Resource and Task Management is absolutely critical if you want to achieve the highest system performance levels possible. WinTasks 4 will not only help you achieve this task, but will actually make your system run faster and more sm wintasks.exe
wintasks.exe
Added by the EVAMAN WORM! wintasks.exe
Wintbp.exe
Added by the ZOTOB.E WORM! wintbp.exe
Wintbpx.exe
Added by the ZOTOB.F WORM! wintbpx.exe
wintective
Wintective logs keystrokes, captures screenshots, and monitors Internet activity. The gathered information can be sent to a predetermined email address. If you didn't install this yourself remove it wintective.exe
winter
Added by the SDBOT-YF WORM! happy.exe
Wintercooler Pro
Wintercooler Pro - utility that monitors CPU usage, RAM consumption and Internet connection speed WINCOOL.EXE
WinTidy
Desktop icon manager from PC Magazine (Ziff-Davis) for Win95. Available via Start -> Programs WinTidy.exe
Wintime
Added by the HARNIG TROJAN! Wintime.exe
WinTime
Added by WinTime - change desktop icons' color and font wintime.exe
Wintime Wtxpload
Part of the software to support a Dexxa USB graphics tablet. From a visitor - "This gets started anyway when you plug in the USB connector for the graphics tablet, if it's not already running. It then starts an application which manages the tablet message Wxpload.exe Wintime
WinTimer
Hijacker, detected by Kaspersky antivirus as Trojan.Win32.StartPage.tj msupdate.cmd
wintnask32.exe
Added by the RBOT-AFP WORM! wintnask32.exe
wintnl
Added by a variant of the ZOTOB.K WORM! wintnl.exe
wintnl.exe
Added by the ZOTOB.K WORM! wintnl.exe
wintnpx.exe
Added by the ZOTOB.H WORM! wintnpx.exe
WinTools
Wintools adware WToolsA.exe
WinTOTAL Scheduler
WinTOTAL Real estate appraisal software related guru.exe
WinTray
Added by the LEGUARDIEN.B TROJAN! wintray.exe
wintsk32dll
Added by the RBOT-AAJ WORM! wintsk32dll.exe
winudll.exe
Added by the MITGLIE-CE TROJAN! winudll.exe
winupated.exe
Added by a variant of the SDBOT WORM! winupated.exe
winupd
Added by the MOTA.A WORM! RUNDLL32.EXE [random value].dll, _mainRD
winupd.exe
Added by the BEAGLE.M or BEAGLE.N WORMS! winupd.exe
WinUPD32
Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually explorer.exe
winupdat
Added by the CANBOT.A WORM! winupdat.exe
WinUpdate
Added by the VBSWG2B.A WORM! RBSKQQBO.EXE
WinUpdate
Added by the REVCUSS.B TROJAN! wmbem.exe
WinUpdate
Added by a variant of the RBOT WORM! updsys.exe
winupdate
Added by the ALCAN.B WORM! winupdate.exe
WinUpdate Loader
Added by the REVCUSS.C TROJAN! msnnm.exe
winupdate.exe
Added by the RADO TROJAN! winupdate.exe
winupdate.reg
Added by the SPYBOT.EAS WORM! winupdate.exe
winupdate2846
Added by a variant of the MUTIN-C TROJAN! vbsystem35.exe msvbrun.exe
WinUpdateB
Added by the BRATLE.AWORM! breatle.exe
winupdateconn
Added by the COMBRA-A WORM! [path to file]
winupdateconn_
Added by the COMBRA-B WORM! Explorer.EXE
winupdatefiv_
Added by the COMBRA.C WORM! [path to file]
WinUpdateProtection
EmployeeWatch is a commercial surveillance software program designed to monitor user activity on a computer csrss.exe
winupdates
Added by the ALCRA-B WORM! winupdates.exe
winupdate_
Added by the CONDOR.A WORM! [path to file]
WinUpdsv
Added by the DROPO MACRO! winupdsv.exe
winupdt
Added by the MABUT.A WORM! RUNDLL32.EXE [random.dll]
winupdtl
SecondThought adware variant winupdtl.exe
WinUpgrader
Added by the AGENT-DZ TROJAN! [path to trojan]
winur
Added by the WINBUR.B WORM! winrun.exe
winusb.dll
Added by the FORBOT-CN WORM! winguard.exe
WinUser32K
Added by the HK TROJAN! usr32wink.exe
WinUsr
Added by the CLUNK.A WORM! WinUsr.exe K1S2
Winux Piriax Service
Added by the RANDEX.G WORM! PH32.EXE
winversion
Browser hijacker, redirecting to specificsearches.com winversion.exe
WinVNC
WinVNC is an application that allows you to remote control your PC from another PC somewhere on the internet WinVNC.exe
WinVNC
Added by the EVIVINC VIRUS! iexplorer.exe
winvxd32
Added by the GABLOLIZ.A WORM! winvxd32.exe
winwan lptt01
Variant of the RapidBlaster parasite (in a "Winwan" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here winwan.exe
winwan ml097e
Variant of the RapidBlaster parasite (in a "Winwan" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here winwan.exe
winword
Added by the TORPID-C TROJAN! winword.exe
winXP
Added by the ANPES WORM! 33.exe
WinXP
Added by the Downloader-JW TROJAN! plugin1.exe
WinXP fix
Added by the RANKY.P TROJAN! [path to file]
WinXp Updater
Added by the RBOT-HG WORM! winxp32.exe
WinXP-98
Added by the BANKER-DS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! CSRSS.exe
winxpdll32.exe
Added by a variant of the SMALL downloader TROJAN! winxpdll32.exe
WinXPHome
Added by the malicious INOR.T script! plugin2.exe
WinXPLoad
Compaq hotkey related - required if you use the hotkeys Rundll32 LoadDll, LoadExe WinXPLoad.exe
winzip
Added by the BANCOS.G or BANCOS.K TROJANS! [path to trojan]
Winzip
Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe, common.pif, common.scr, Sexo.exe, Sexo.jpg.pif, ini_file__.pif, load_me__.tmp, msfile.pif, system_load_.pif or zipped.rar.pif [various filenames]
WinZip Quick Pick
Added with WinZip version 8.1. "The new WinZip Quick Pick taskbar tray icon gives you instant access to WinZip and your Zip files. Just left click the icon to open WinZip, or right click it to instantly reopen recently used Zip files, access your Favorite WZQKPICK.EXE
Win_api_driver
Added by the REVIRD TROJAN! system.exe
Win_Library
Added by the ANARCH WORM! INISvc.exe
win_spool2
Added by the SCKEYLOG.B TROJAN! win_spool2.exe
win_upd.exe
Added by the MITGLIEDER.M TROJAN! WINdirect.exe
win_upd2.exe
Added by the BEAGLE.AO WORM! WINdirect.exe
Win_vader
Added by the INVASION.A VIRUS! Win_vader.vbs
WIP Config GUI
Added by the RBOT-CN WORM! Winipcfgs.exe
Wireless PCI Card Configuration Utility
Utility used by the LINKSYS wireless PCI card (WMP11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration WMP11Cfg.exe
Wireless Provider Server
Added by the FORBOT-AD WORM! wpsvr.exe
Wireless-G Notebook Adapter Utility
Utility used by the LINKSYS Wireless-G Notebook Adapter (WPC54G) WPC54CFG.EXE
wjview
MS tool used to view window-based Java applications from the command line wjview.exe
wkcalrem
Produces a pop-up reminder of events scheduled using the MS Works Calendar wkcalrem.exe
WkDetect
Checks for updates to MS Works WkDetect.exe
wkfud
A marketing program for MS Works wkfud.exe
WksSb
The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program. The Works Portfolio provides a location where you can store items you want to later put into a document or other file WksSb.exe
WksSVC
Added by the MYTOB-BW WORM! Note - the valid "explorer.exe" will always be located in C:Windows or C:Winnt folder whereas this one is found in the C:WindowsSystem folder (Win98/ME) or in the C:WinntSystem32 or C:WindowsSystem32 subfolder (Win2K/XP) EXPLORER.exe
WkUFind
MS Works Update Detection. MS Picture It! (versions 7 to current) use this automatic update feature during the log on process. It can also cause your system to automatically dial into your ISP as it tries to access the internet, if you have your system se WkUFind.exe
Wlan Drier
Added by the WOOTBOT.DC WORM! Winusb2.exe
Wlan Driver
Added by the WOOTBOT.DH WORM! avscan.exe
WLAN Status Tray Applet
System Tray icon for checking the status of a Wireless LAN WLANSTA.EXE
wlancfg
Inventel wireless router related - required in order to automatically connect to the Net at bootup wlancfg.exe
WLANSTA.EXE
System Tray icon for checking the status of a Wireless LAN WLANSTA.EXE
WLAN_Cfg.exe
Linksys Instant Wireless USB Network Adapter driver WLAN_Cfg.exe
Wm24Pan
ESI external sound card driver Wm24Pan.Exe
wm41a398
LZIO.com adware downloader rundll32.exe [path] wm41a398.dll, EnableRunDLL32
WMAudio
Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! services.exe
WMAudio
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! winlogon.exe
WMBoot
Associated with Logitech Wingman game controllers. Not required but what does it do? N/A
wmcbaaca
LZIO.com adware downloader rundll32.exe [path] wmcbaaca.dll, EnableRunDLL32
WMI Application Interface
Added by the SPYBOT.RBY WORM! wmiapi.exe
WMIEXE.exe
NT component, used by Windows Millennium to detect Plug and Play-compliant IEEE 1394 devices during the startup process. Since this is important for the computer to work properly if you have these, Windows Millennium protects wmiexe.exe and will restore wmiexe.exe
Wminf
Added by the GEMA TROJAN! Wminf.exe
Wminfo
Added by the GEMA TROJAN! Wminfo.exe
wmiprv
Added by the RBOT-WM WORM! wmiprv.exe
wmon
Added by the AGOBOT-OW WORM! jusched.exe
WMP54Gv4
Linksys WMP54G Wireless-G PCI Adapter driver WMP54Gv4.exe
wmplayer.exe
Added by the BANCBAN-CZ TROJAN! wmplayer.exe
wmsys32
Added by the BANPAES.B TROJAN! wmsys32.exe
wmv
Added by the AGENT-DG TROJAN! winmonv.exe
WM_LOGIN
Part of McAfee Firewall. What is it for and is it needed? MSGLOGIN.EXE
WNAD
Spyware added as a result of running a program called "Yo Mama Osama" (osama.exe). See here for more and how to get rid of it. There are other ways this can show up on your system, and it will manifest itself by periodically opening a new browser window w WNAD.EXE
wnddrv
Added by an unidentified TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup and is always located in the System32 folder. This worm file is found in the Winnt or Windows folders svchost.exe
WNSC
PurityScan/Clickspring adware wns*****.exe [* = random char]
Wnsck2 driver
Added by the SPYBOT-AF WORM! wlogf.exe
WNSI
PurityScan/Clickspring adware wnscp**.exe [* = random char]
WNST
PurityScan/Clickspring adware wns*****.exe [* = random char]
wntlgns
CoolWebSearch parasite related wntlgns.exe
won update
Added by the RBOT.N WORM! WAPDATE.EXE
WooCnxMon
Wanadoo ISP software related - not required - here's how to bypass it CnxMon.exe
WOOTASKBARICON
Wanadoo ISP taskbar icon - not required TaskbarIcon.exe
Woowatch
Wanadoo ISP software, not required Watch.exe
word pair
Added by the SHED-A TROJAN! bopotsvr.exe
WordQ carat flag
Related to WordQ Writing Aid Software WordQcrs.exe
WordWeb
WordWeb - free theasaurus and dictionary. Start manually wweb32.exe
Workflo
Related to BroadJump Client Foundation - broadband troubleshooting software installed by various companies. Is it required? workflow.exe
Working System Analyzer
Added by the FORBOT-FZ WORM! syswork.exe
worknote1
Added by the MEETOT WORM! [filename]
Works Calendar Reminder
Produces a pop-up reminder of events scheduled using the MS Works Calendar wkcalrem.exe
WorksFUD
A marketing program for MS Works wkfud.exe
Workstation Scheduler
Desktop Management Scheduler. Part of Novell's Netware Client. Schedueles NDS events. If events have been schedueled, it is required, otherwise, it is useless and a memory hog wm95.exe
Workstation Services
Added by the RBOT-OJ WORM! wrkstn.exe
Workstation Ver 5.0
Added by the RBOT-AHB WORM! vmware.exe
Worm Detector
Worm Detector - antivirus add-on for Outlook 2K or XP for handling worms and spam wd.exe
wormexe
Added by the EARLYBIRD WORM! winstart.exe
wovax
Added by the DAQA.A TROJAN! wovax.exe
wow
PurityScan/Clickspring adware bar.exe
wow
Added by the LINEAGE-Y TROJAN! wwf.exe
Wpctrl
WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties wpctrlnt.exe
Wpctrl
WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties wpctrl95.exe
wpctrl95
WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties wpctrlnt.exe
wpctrl95
WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties wpctrl95.exe
WPCycle.exe
Added when selecting Mplayer2 to open media files. Forces other codes to Wait for Previous instructions to end, preventing instability of your CPU (freezing) WpCycleWin.exe
wpds.exe
Added by the SMALL-KY TROJAN! doriot.exe
wpwmgrs
Added by the MYTOB-DH WORM! wpwmgrs.exe
WQK
Added by a variant of the KLEZ WORM! WQK.exe
wr
?? WR.EXE
WR Command
?? wr.exe
WrCtrl
Win-Route 4.27 NAT engine on Win2k Pro for connection sharing and security using Win-Route by Tiny Software. A connection sharing/Firewall Application. If service is disabled the program does not work, but you can manually start/stop the service with a sh WrCtrl.exe
WRDialer
WinPoet DSL dialler WrDialer.exe
WRECK GUARD
?? ??
WregBios
Desktop Management BIOS (DMI BIOS) related. Apparently invokes the DosBios.exe file. Is it required? wregbios.exe
wrexec
Watch Right - monitoring program, part of the PowerTools add-on for AOL. Records instant messages, E-mail, chat. Watch Right appears to be, and functions as an online clock updater which connects with the U.S. National Institute of Standards and Technolog wrexec.exe
wriste
?? wriste.exe
ws2 32
Added by the VOKEN-A TROJAN! svchst.exe
ws2help
Added by a variant of the SMALL.AN TROJAN! ws2help.exe
WSAConfiguration
Added by the GAOBOT.BAJ WORM! wmon32.exe
WSAConfiguration
Added by the AGOBOT.ZT WORM! svchostt.exe
WSAConfiguration
Added by the AGOBOT.ABG WORM! rpcxmn32.exe
WSAConfiguration
Added by a variant of the RBOT WORM! win32upd.exe
WSAConfiguration
Added by a variant of the AGOBOT/GAOBOT WORM! drrss.exe
WSAConfiguration
Added by the AGOBOT-WC WORM! winlogon32.exe
WSAConfiguration
Added by a variant of the AGOBOT/GAOBOT WORM! ntguard32.exe
WSAConfiguration1
Added by the AGOBOT.WH WORM! csass.exe
wsbklite
Related to the Acer Soft Button on Acer Tablet PCs. Appears to do nothing so is it required? wsbklite.exe
WScheduler
Windows Scheduler - "schedule unattended running of applications, batch files, scripts and much more. Also, you can schedule popup reminders so you'll never forget reminders, tasks and other events." WScheduler.exe
wscript.exe
Added by the VABI VIRUS! vabian.vbs
Wsdata service
Added by the SDBOT.ZU WORM! WSconf.exe
wserver
Added by the NETSKY.AC or SASSER.G WORMS! wserver.exe
WService
Tablet client Driver for UC-Logic Pen/Graphics Tablet WService.exe
wsg32
GoldenKeylog keystroke logger/monitoring program - remove unless you installed it yourself! wsg32.exe
wskrnl
Added by the ActMon surveillance software. Uninstall this software unless you put it there yourself wskrnl.exe
wsock32
Added by the HORST-A WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! svchost.exe
WSSAConfiguration
Added by the AGOBOT-KC WORM! wmmon32.exe
wssys
WebPI logs keystrokes and captures screenshots. If you didn't install this yourself remove it wssys.exe
Wstat32 driver
Added by the LOONBOT TROJAN! Wstat32.exe
wstimeb
Used with NEC printers. You can disable it before printing but it re-loads itself when printing so you may as well leave it wstimeb.exe
WSVCS
WALogger is a surveillance software program that logs keystrokes. If you didn't install this yourself remove it SERVICES.EXE
wswpd
Used with some models of Panasonic, Epson and NEC printers. Some older drivers known to have a "memory leak". Needed for printing to work wswpd.exe
wsys.exe
SpyloPCMonitor is a surviellance software program that monitors user activity, logs keystrokes, and takes screenshots. It ends the processes of anti-spyware programs. If you didn't install this yourself remove it wsys.exe
WT Game Channel
WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case GameChannel.exe
WT Game Channel
WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case wtgamechannel.exe
WT GameChannel
WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case GameChannel.exe
WT GameChannel
WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case wtgamechannel.exe
WTF Test
Added by the RBOT-ACM WORM! wtftest.exe
WTIndicator
WinTask - software that automates a variety of routine tasks quickly and simply SchedInd.exe
WTSI
PurityScan/Clickspring adware wapisvit.exe
WTSS
PurityScan/Clickspring adware wap***.exe [* = random char]
WTST
PurityScan/Clickspring adware wapisvtr.exe
wuanguard
Added by the RBOT-AAF WORM! wuanguard32.exe
WUOLService
Remote wakeup status agent. Part of Novell's ZenWorks. Processes Wake-up on LAN requests (turn on a computer remotely on LAN) WUOLService9x.exe
wuosdial
Added by a variant of the RBOT WORM! wuosdial.exe
WUPD
Added by the TZET WORM! iglmtray.exe
wupd
Adware downloader/installer, CoolWebSearch parasite related symcsvc.exe
wupd
Added by the ORSE-C TROJAN! win32.exe
wupdate
Added by the ORSE-B TROJAN! wisvccz.exe
wupdate
Downloader trojan, detected by Panda antivirus as Adware/Trustbid wi32.exe
Wupdate driver
Added by a variant of the SPYBOT WORM! [various filenames]
Wupdm32
Added by the MIDLAK WORM! Wupdm32.exe
wupdt
Added by the IMISERV.A TROJAN! wupdt.exe
WUSB11B.exe
Linksys WUSB11 WLAN USB adapter WUSB11B.exe
WUSB54Gv4
Wireless-G USB Wireless Network Adapter related - would appear to be required WUSB54Gv4.exe
wuviewer
Added by a Proxy Trojan variant wuviewer.exe
WUx_RegSvr
x is any number?? RegSvr32.exe
wvsvc
Added by the AGOBOT.YM WORM! wvsvc.exe
WWKS
Added by the SDBOT-BT WORM! wsass.exe
www.hidro.4t.com
Added by the BLASTER.F WORM! enbiei.exe
www.symantec.com
Added by the MYDOOM.W WORM oz11111.exe
WXcmeinst
Added by the RANCK-CD TROJAN! [path to file]
Wxp4
Added by the ERKEZ.D WORM! Norton Update.exe
WXProcMgr Module
TVTonic from Wavexpress - "enjoy 3 full-screen, DVD-quality video channels for FREE". Allows data content to be downloaded and synchronized on your system WXprocMgr.exe
wzhelper
Searchcentrix hijacker wzhelper.exe
wzservice
Added by the HACKARMY.W TROJAN! hess.exe