| Status Code | Name | Command | Description |
| X | Windows HTML file reader | Sysconf32.exe | Added by the NOOMY.A WORM! |
| ? | Windows Help System | Help.pif | ?? |
| X | Windows Host Device | hostsvc.exe | Added by the ZOOTY-A WORM! |
| X | Windows Help Service | winhelpsv.exe | Added by the RBOT-LP WORM! |
| X | Windows Help Manager | svchost32.exe | Added by the RBOT-OZ WORM!
|
| X | Windows Help File | winhelper32.exe | Added by the SDBOT-QK TROJAN!
|
| U | Windows Guardian | thehel1iawgrd32.exe | Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes |
| U | Windows Guardian | Fawgrd32.exe | Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes |
| N | Windows Eyes | ?? | For blind people, gives a voice description of items on the screen. Windows application which gives you total control over what you hear, when you hear it, and how you hear it. Available via Start -> Programs |
| X | Windows Explorer-3212 | WINRE16.EXE | Added by the HARDOC WORM! |
| X | Windows Explorer Update Build 1142 | EXPLORER32.EXE | Added by the KaZaA based KWBOT or KWBOT.Y WORMS! |
| X | Windows Explorer Shell | Winexec32.exe | Added by the REDIST.B WORM! |
| X | Windows Explorer | olecom32.exe | Added by an unidentified WORM or TROJAN! |
| X | Windows Explorer | Lsas.exe | Added by the GAOBOT.AO WORM! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | Windows Explorer | [filename].exe | Added by the SDBOT TROJAN! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | Windows Driver Services | msdrvs32.exe | Added by the WOOTBOT.L WORM! |
| X | Windows Drive Compatibility | System32Driver32.exe | Added by the SUPOVA.Z WORM! |
| X | Windows DNS Daemon | windnsd.exe | Added by the WOOTBOT.AS WORM! |
| X | Windows DLL Loader | defragfat32pi.exe | Added by the RBOT-QQ WORM! |
| X | Windows DLL Loader | rundll32.exe | Added by the WHIPSER-B WORM! Note - rundll32.exe file is placed in the WindowsSystem folder, wheras the legitimate rundll32.exe is located in the C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP)
|
| X | Windows DLL Loader | defragfat32z.exe | Added by the LINKBOT.A WORM!
|
| X | Windows DLL Loader | RUNDLL16.EXE | Added by the DOMWIS TROJAN! |
| X | Windows Debugger | windbg.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Windows debug logging | winloggs.exe | Added by the RBOT-QN WORM! |
| X | Windows debug logging | winlogg.exe | Added by the RBOT-OY WORM!
|
| X | Windows Dcom2 Fix | mscom32.exe | Added by the RBOT-QT WORM! |
| X | Windows Control | Control.exe | Browser hijacker. NOTE - On Win9x systems it will overwrite the Windows file of the same name in the Windows directory, so therefore it will be necessary to extract a fresh copy of the file from the Windows setup cabs! |
| X | Windows Data Server | autodisc.exe | Added by the SPYBOT-CB WORM!
|
| X | Windows Configuration | wsys32.exe | Added by the GAOBOT.FB WORM! |
| X | Windows Config | SSYS.EXE | Added by the SPYBOT-DA WORM! |
| X | Windows Config Loader | Wincfg32.exe | Added by the SILVERFTP TROJAN! |
| X | Windows Compliant | [random filename] | Added by the RBOT-IR WORM! |
| X | Windows Ba?lang?? Dosyas? | sistem.exe | Added by the MUZK WORM! |
| X | Windows Communicator | wincomm.exe | Added by the AGOBOT-BH WORM!
|
| X | Windows Backup Configuration | IEXPLORER.exe | Added by the GAOBOT.AZ WORM! |
| X | Windows Automation | msdspr.exe | Added by the SOLAME.A WORM! |
| X | Windows backup | systemss.exe | Added by a variant of the SPYBOT WORM! |
| X | windows automation | mslaugh.exe | Added by the BLASTER.E WORM! |
| X | Windows Automatic Updates | dvldr.exe | Added by the RBOT.MF WORM!
|
| X | windows auto update | msblast.exe | Added by the BLASTER.B WORM! |
| X | Windows Automatic Update | wuamgrder.exe | Added by a variant of the RBOT WORM! |
| X | windows auto update | penis32.exe | Added by the BLASTER (or MSBLAST.A) WORM! |
| X | Windows AdTools | WinAdTools.exe | Windupdates adware variant |
| X | Windows AdService | WinAdServ.exe | Windupdates adware variant |
| X | Windows AdControl | WinAdCtl.exe | Windupdates adware variant
|
| U | Windows Accelerators | setup.exe | KeySpy keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove |
| X | Windows (random character) | diskcheck.exe | Added by the SINGU.B TROJAN!
|
| X | windows | system copy.exe | Added by the SALGA.A WORM! |
| X | windows | hkey.exe | Added by the GAOBOT.AFW WORM! |
| X | windows | [path to trojan] | Added by the AIMWIN TROJAN! |
| X | Windows | explorer.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | Windows | Windows.exe | Added by the KAZMOR, BOBBINS & ALADINZ.D TROJANS! |
| X | Windows | msdos98.exe | Added by the PWSTEAL TROJAN! |
| X | Windows | Kernel32.exe | Added by the TENDOOLF WORM! |
| U | WindowFX | wfxload.exe | Stardock WindowFX - "Allows you to add an unprecedented number of special effects to windows" |
| X | WindowEnhancer | Winex.exe | SCbar foistware variant |
| U | WindowBlinds | wbload.exe | WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins |
| X | window2 | ssvchost.exe | Added by the IRCBOT.H TROJAN! |
| X | window.exe | window.exe | Added by the MITGLIEDER.H or MITGLIEDER.J TROJANS! |
| U | Window Washer | wwDisp.exe | Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
| X | Window Monitor | winmon32.exe | Added by the SDBOT.RT WORM! |
| X | Window Loader | Dos32.exe | Added by the GAOBOT.AO WORM! |
| X | Window | explore.exe | Added by the GAOBOT.ADW WORM! |
| X | Windoes Kernel | kernel32.exe | Added by the KICKIN.A (or CYDOG.C) WORM! |
| X | WinDNS | windns32.exe | Added by the GAOBOT.WX WORM! |
| X | Windll32 | Windll32.exe | Added by the MSNPWS TROJAN! |
| X | windllsys32.exe | windllsys32.exe | Added by a variant of the MITGLIEDER.BY TROJAN! |
| X | Windll.exe | Windll.exe | Added by the STEALER TROJAN! |
| U | WINDLL | WSYS.EXE | STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes, all passwords transacted even if they weren't keyed in, all web sites visited, every program launched including the path to that program, and more" |
| X | windll | windll32.exe | Added by the ASTEF or RESPAN WORMS! |
| X | Windll | Windll.exe | Added by the TRYNOMA TROJAN! |
| X | windir | winrun.exe | Added by the WINBUR.B WORM! |
| X | windef | Win32sp.vbs | Added by the ANPES WORM!
|
| X | Winde | winde.exe | Added by the DLUCA TROJAN! |
| X | windbs | winxtc.exe | Added by the AGOBOT-WD WORM! |
| N | WinDates | windates.exe | WinDates is a calendar, date organizer and event reminder program from Rockin' Software |
| X | WIND0WS | WIND0WS.exe | Added by the SPYBOT.DQ WORM! |
| X | WinCSRSS | MSGRT32.EXE | Added by the REWINDO-A TROJAN!
|
| X | wind.exe | wind.exe | Added by the MITGLIEDER.BD TROJAN! |
| N | WinCinemaMgr | WinCinemaMgr.exe | WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
| N | WINCINEMAMGR | WINCIN~1.EXE | WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
| X | WinCheck | WinCheck.exe | Added by the PWS-CY TROJAN! |
| X | Winbed | winbed.exe | Hijacker |
| U | WinBar | WinBar.exe | "WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls" |
| U | WinBackup Scheduler | Wbsched.exe | LIUtilities WinBackup scheduler - backup software |
| X | WinAuth | winlogon.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the valid winlogon.exe process |
| X | Winapp | winpup32.exe | Produces popup ads to adult content sites |
| X | WinApp32 | msapp.exe | Added by the RSBOT TROJAN! |
| X | WinApi | winapix.exe | Added by a variant of the TIBSER.A downloader TROJAN! |
| U | WinampAgent | WINAMPa.exe | Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs |
| X | Winampa Agent | WINAMPA.EXE | Added by the SPYBOT-BR WORM! Note - this is NOT the Winamp Media Player
|
| X | Winampa | winampa.exe | Added by the AGOBOT-GS WORM!
|
| U | Winampa | WINAMPa.exe | Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs |
| X | Winamp media player | winapa.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Winamp | winamp.hta | Hijacker - re-directing to adult content sites. Note - this isn't the real Winamp |
| X | winallapu | winallapu.exe | Added by the DELF.E TROJAN! |
| X | winallap | winallap.exe | Added by the DELF.E TROJAN! |
| X | Winahlp.exe | Winahlp.exe | Added by a variant of the VAGRNOCKER TROJAN! |
| X | winadm | winadm.exe | Browser hijacker - redirecting to Search-World.net. Related to the SMALL.LR TROJAN!
|
| X | Winad Client | Winad.exe | WinAd adware by eXact Advertising |
| X | winactive | WINACTIVE.EXE | Active variant of LOP.com hijacker - see here |
| X | WinActiveJ | WinActiveJ.exe | Added by the ROTARRAN VIRUS! |
| X | WIN3S2SNDS | winabsmod.exe | Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" |
| X | WIN3S2SNDS | winiprtx.exe | Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" |
| X | Win64 Compatibility Check | load win64.drv | CoolWebSearch parasite variant |
| X | Win386 | Win386.exe | Added by the GOSUSUB VIRUS! |
| X | Win386 | sp32.dll | Homepage hijacker. Not a dll but a regfile in disguise |
| X | win32_i ml097e | win32_i.exe | Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | win32_i lptt01 | win32_i.exe | Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | win32us | win32us.exe | All-In-One-Telcom (adult content dialler) variant |
| X | win32usbd | ssrs.exe | Added by the RBOT-RA WORM! |
| X | Win32SystemMonitor | ***.exe [* = random char] | Browser hijacker
|
| X | Win32System | win32s.exe | Added by the MYDOOM.V WORM! |
| X | Win32system | [random filename] | Added by the DDV.B WORM! |
| X | WIN32SNDS | banc.exe | Added by an unidentified WORM or TROJAN! |
| Y | WIN32SL | Win32sl.exe | Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. The specific function of this is to load MIF's in order for Dell OpenManage Client to work |
| X | win32ini | systroy.exe | Added by the IRC.ALADINZ.C TROJAN! |
| X | Win32R | Server.com | Added by the ESTRELLA TROJAN! |
| X | win32info | win32info.exe | Adult content dialler |
| X | win32gb | win32gb.exe | All-In-One-Telcom (adult content dialler) variant |
| X | Win32G | Kernel32.com | Added by the ESTRELLA TROJAN! |
| X | Win32G | Scandisk.com | Added by the ESTRELLA TROJAN |
| X | Win32dll | Win32dll.exe | Added by the BANPAES TROJAN! |
| X | Win32DLL | Win32DLL.vbs | Added by the LOVELETTER (I LOVE YOU) VIRUS! |
| X | win32clf | win32clf.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Win32BaseServiceMOD | Wintask.exe | Added by the NAVIDAD WORM! |
| X | win32.exe | win32.exe | Added by the STARTPAGE TROJAN! |
| X | Win32 Wmls Driver | winitr32.exe | Added by the WOOTBOT.B WORM! |
| X | Win32 USB2.0 Driver | service.exe | Added by the SDBOT-QF WORM!
|
| X | Win32 USB2.0 Driver | w32usb2.exe | Added by the SPYBOT.DN WORM! |
| X | Win32 USB2.0 Driver | rundll16.exe | Added by the WOOTBOT.H WORM! |
| X | Win32 USB2.0 Driver | 386.exe | Added by the IRCBOT.D WORM! |
| X | Win32 USB2 Driver | winupdate.exe | Added by the AGOBOT.YE WORM! |
| X | Win32 USB2 Driver | wind32.exe | Added by the FORBOT-AH WORM! |
| X | Win32 USB2 Driver | sys32snd.exe | Added by the FORBOT-AN WORM! |
| X | Win32 USB2 Driver | sys32.exe | Added by the WOOTBOT.X WORM! |
| X | Win32 USB2 Driver | svchosting.exe | Added by the FORBOT.J or SDBOT.HU WORM! |
| X | Win32 USB2 Driver | win32usb.exe | Added by the SPYBOT.DHV WORM! |
| X | Win32 USB2 Driver | smsc.exe | Added by the SDBOT.FO WORM! |
| X | Win32 Usb Driver | svhosint32.exe | Added by the FORBOT-BE or FORBOT-J WORMS!
|
| X | Win32 USB Driver | mvsecn.exe | Added by the FORBOT-BK WORM!
|
| X | Win32 USB Driver | winxpinit.exe | Added by the SDBOT.AA TROJAN! |
| X | Win32 SSL Driver | winssv.exe | Added by the FORBOT-BH WORM!
|
| X | Win32 System Spool | spoolsvc.exe | Added by the SDBOT.UK WORM! |
| X | Win32 Services1 | wuamngr1.exe | Added by the SDBOT-PV WORM! |
| X | Win32 Rundll Loader | Rundll32.exe | Added by the SDBOT.A TROJAN! Note: Rundll32.exe is a valid Windows application called "Run a DLL as an App" and stored in the C:Windows directory. The version created by this virus is saved in the C:WindowsSystem directory |
| X | Win32 Ms Auto Updater | AutomsUPD.exe | Added by a variant of the RBOT WORM! |
| X | win32 regedit | msn32.exe | Added by an unidentified WORM or TROJAN! |
| X | Win32 FRT Driver | msfr32.exe | Added by a variant of the FORBOT WORM! |
| X | Win32 Kernel core component | Kernel32.pif | Added by the MOKS VIRUS! |
| X | Win32 Explorer | Explorer32.exe | StartPa-MN homepage hijacker |
| X | Win32 exe file | winstr32.exe | Added by a variant of the SPYBOT WORM! |
| X | Win32 DRK Driver | wdrk32.exe | Added by the WOOTBOT.CY WORM! |
| X | Win32 Device Loader | Win32ldr.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Win32 Configuration | dllhelp.exe | Added by the SDBOT.UL WORM! |
| X | Win32 Configuration | videosd32.exe | Added by the SDBOT.TT WORM! |
| X | win32 | WinSetup.exe | Added by the EVILBOT.B TROJAN! |
| X | win32 | winsrv32.exe | Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites |
| X | Win32 | Win32.exe | Added by the ISRAZ.A WORM! |
| X | win32 | Setup_32.exe | Added by the EVILBOT.B TROJAN! |
| X | win32 | Shakira_1997_Part_1_.Mpeg_.scr | Added by the MYLIFE.N WORM! |
| X | WIN32 | WIN32.EXE | Added by the RATEGA TROJAN! |
| X | Win2Drv | [worm filename] | Added by the WINTOO WORM! |
| X | Win USB 2.0 USB Driver | HPPrint.exe | Added by the SPYBOT.DNB WORM! |
| X | WIN-BUGSFIX | WIN-BUGSFIX.EXE | Added by the LOVELETTER (I LOVE YOU) VIRUS! |
| X | win update | wupda32.exe | Added by the SDBOT.J WORM! |
| X | Win Server Updt | wupdt.exe | Added by the IMISERV.A TROJAN! |
| X | Win Server | winserv.exe | Added by the IMISERV.A TROJAN! |
| ? | win name | stat.exe | ?? |
| X | Win l5oahder | winampa.exe | Added by the SPYBOTER.GEN VIRUS! Not the valid Winamp Agent which uses the same filename. This resides in the System32 sub-folder wheras real one is located in the winamp folder |
| X | WIN HOST PROCESS | WIN HOST PROCESS.EXE | Added by the KEYLOGGER.CLONE TROJAN! |
| X | Win Command | command32.exe | Added by the AGOBOT.XQ WORM! |
| X | Win Command | command32.exe | Added by the AGOBOT.XQ WORM! |
| X | Win Comm | WinComm.exe | WebRebates related adware
|
| U | Win Chimes | winchi~1.exe | WinChimes - enhancement software for the system clock that runs in the system tray |
| X | win | xwinxrpc32.exe | Added by the AGOBOT-MV WORM! |
| N | Willow Road | WillowRoad.exe | Willow Road Screen Saver |
| X | win | regedit -s ..win.dll | Added by the SEEKER.K TROJAN! |
| N | Wildwire Monitor | WWMon.exe | This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem |
| U | WildTangent Web Driver updater | wcmdmgrl.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| N | WIAWizardMenu | RUNDLL32.EXE sti_ci.dll, WiaCreateWizardMenu | Still Image Class Installer - installed with a webcam |
| ? | WildTangent CDA | RUNDLL32.exe cdaEngine0400.dll,cdaEngineMain | Part of the WildTangent on-line games system. What does it do and is it required? |
| X | WhenUSearch | Search.exe | WhenUSearch adware |
| X | Whvlxd | Whvlxd.exe | Added by the W32.LXD.MIRC TROJAN! |
| X | WhenUSave | Save.exe | Rebranded version of SaveNow advertising spyware |
| U | WheelMouse | AMOUMAIN.EXE | A4Tech wireless mouse driver and utility - required if you use non-standard Windows driver features |
| U | WheelMouse | 4DMAIN.EXE | Mouse software for "Fellowes" Wheelman mouse. Has caused some users problems but shouldn't be needed if you don't use any enhanced features it may provide |
| X | whagent | whagent.exe | System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here |
| U | WGWLocalManager | WGWLocalManager.exe | Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so. It could be started by creating a shortcut, running it only when connecting to the internet. If internet is used often, it's recommended to leave it in startup so it starts with the system |
| Y | WG511WLU | WG511WLU.exe | Netgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card
|
| ? | WFXSwtch | WFXSWTCH.exe | Related to WinFax. What does it do and is it required? |
| Y | wfxsnt40 | wfxsnt40.exe | WinFax 10.0 and maybe earlier versions. The program that opens the port for WinFax and not normally in the start menu. Needed if you want to run WinFax |
| N | WFXCTL32.EXE | WFXCTL32.EXE | From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs |
| U | wfips | iphider.exe | ICQ (messaging/chat program) anti-bomb software. "WFIPS is anti-bomb software for safeguarding ICQ Bomb before the bombing. 'ICQ Defoolder' is a tool for removing ICQ bomb after being exposed." For more information about ICQ bombs see here |
| N | WFGStartup | WFGStartup.exe | World Weather. "This midlet displays the current weather conditions for major cities around the world. This version is for memory limited mobile phones" |
| N | WetSock | wetsock.exe | RoboMagic Wetsock - weather reporting in the System Tray |
| X | wersds | doriot.exe | Added by the JECT.C TROJAN! |
| ? | WEPstat | Wepstat.exe | Cisco Aironet 340 Series PC Card driver. If it can be started manually it shouldn't be required if you don't use the PC card facility regularily - hence the status could be "U". Can anybody confirm this? |
| N | Welcome | Welcome.exe | Launches the Welcome to Windows tutorial on boot up |
| U | WebWasher | wwasher.exe | Free Pop-up/ad/javascript filter program from Siemens. If not running then browsers will not be protected but will still work. Available via Start -> Programs |
| Y | WebTrapNT.exe | WebTrapNT.exe | Part of PC-Cillin Anti-Virus software. Checks visited web-sites for malicious Java and ActiveX elements |
| Y | Webtrap | webtrap.exe | Part of PC-Cillin anti-virus software. Checks web-sites for malicious Java and ActiveX elements in a similar way to McAfee WebScanX. A few users find it infuriating |
| X | WebSpecials | rundll32 [path] webspec.dll | WebSpecials spyware
|
| X | Websx | Int*****.exe | Adult content dialler - where ***** are random |
| N | Webshots | websho~1.exe | Screensaver program that automatically downloads from the webshots web site |
| N | Webshots | Webshots Tray.exe | Screensaver program that automatically downloads from the webshots web site |
| X | WebSecureAlert | WebSecureAlert.exe | WebSecureAlert. "Can help protect your browser security and privacy". However, it's by GAIN Publishing, and will display pop up ads on your computer screen based on your online Web surfing behavior |
| ? | WebServer | VBI_SE~1.EXE | Related to a Pinnacle sound card. What does it do and is it needed? |
| X | websearch | wjview ...websearch.exe | "Web Savings" From Ebates Software, a shopping tool that opens pop-up windows |
| Y | WebScanX | WebScanX.exe | From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc |
| N | webscan | stopsignav.exe | eAcceleration Stop-Sign related - not recommended, see note |
| X | WebScan | DEFSCANGUI.EXE | Stop-Sign from eAccelerration. Detects spyware, malware, viruses and keyloggers and stops popups. Spyware in itself - see their privacy statement here |
| X | WebSavingsFromEbates0 | WebSavingsFromEbates0.exe | Web Savings From Ebates Software, a shopping tool that opens pop-up windows
|
| X | WebSavingsfromEbates | WebSavingsfromEbatesrun.exe | Web Savings From Ebates Software, a shopping tool that opens pop-up windows |
| U | websaverlive | websaverlive.exe | WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your computer is idle |
| X | WebRebates0 | WebRebates0.exe | WebRebates adware |
| N | Webposition Gold 2 | wpsche~1.exe | Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines |
| N | WebOutfitterTray | sttray.exe | Intel WebOutfitter service System Tray icon |
| N | WebKey | WebKey.exe | WebKey from JB Utilities. Utility to keep track of login data required when browsing the internet |
| X | WebInstall | WebInstall.exe | ClipGenie adware downloader |
| X | WebInstall2 | WebInstall.exe | ClipGenie adware downloader |
| X | WebHancer Agent | whagent.exe | System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here |
| X | webHancer Survey Companion | whSurvey.exe | WebHancer foistware - traffic measurement service that uses a client agent that is stealth installed on user machines, gathering detailed data about sites visited, their performance and, most important, what the user actually does while there |
| X | Webdav.exe | webdav.exe | IRC DDoS bot which gives the hacker full control over your system |
| X | WebCpr0 | WebCpr0.exe | Web_CPR/TopMoxie adware |
| X | WebCheck | WebCheck.pif | Added by the CONE.C or CONE.F WORMS! |
| N | WebcamRT.exe | WEBCAMRT.exe | For Logitech Web Cams. Not required - camera works fine without it |
| X | Webcelerator | webcel.exe | Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Spyware and troublesome - see here |
| X | webassist | webassist.exe | Adware popup generator |
| ? | Webcam Go Sti Service Application | wbcgosvc.exe | Control software for the portable Creative Video Blaster Webcam Go digital camera/PC web cam. What does it do and is it required? |
| N | WebArmyKnife | WAK.exe | Web Army Knife - a suite of web site developer's tools |
| Y | web3trap | web3trap.exe | PC-Cillin 2000 anti-virus software -> ActiveX filter. Guards against malicious ActiveX programs, etc |
| X | webalize | webalize.exe | Searchcentrix hijacker |
| ? | Web Search | ?? | ?? |
| X | web | ******.exe [* = random char] | Added by a variant of the EASTO.A TROJAN! |
| N | WeatherWatcher | ww.exe | WeatherWatcher - weather reporting in the System Tray |
| X | WeatherOnTray | WeatherOnTray.exe | Hotbar's Weather Forecast tool for your desktop - adware |
| N | WEATHER | WEATHER.EXE | Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs |
| N | WeatherCast | Weather.exe | Weather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight |
| X | wdwctrl | wdwctrl.exe | Added by the DLUCA.E TROJAN! |
| X | wdskctl | wdskctl.exe | IEPlugin spyware
|
| X | WDInfo | wdinfo.exe | Adult content dialler |
| U | WD Button Manager | WDBtnMgr.exe | Button manager installed with a western digital external disk drive. Allows you to back up your system with one click
|
| X | WCPT | wintsvtr.exe | PurityScan/Clickspring adware |
| X | WCPS | Wint**.exe [* = random char] | PurityScan/Clickspring adware
|
| X | WCPI | wintsvit.exe | PurityScan/Clickspring adware |
| ? | WCPC | wintsvcc.exe | ?? |
| U | WCOLOREAL | coloreal.exe | Makes colours sharper and brighter, but will only work with coloreal capable monitors |
| U | wcmdmgrl | wcmdmgrl.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| N | wcmdmgr.exe | wcmdmgr.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| U | wcmdmgr | wcmdmgrl.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
|
| N | WCESCOMM | WCESCOMM.EXE | Active sync for use with Windows CE based palm PC |
| ? | Wbutton | Wbutton.exe | Related to the Wacom Penabled driver on Acer Tablet PCs. Appears to do nothing so is it required? |
| N | Wbiff | Wbiff.exe | Wbiff! E-mail checker - automatically checks your e-mail and notifies you if any new e-mail has been received |
| N | WaveTop Upload Manager | N/A | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
| N | WaveTop Receiver 2 | N/A | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
| N | WaveTop Receiver 1 | N/A | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
| N | WaveTop Launcher | WaveTop.exe | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
| N | Watchdog | Watchdog.exe | Definitely part of the Mustek scanner drivers and software (for 600 III EP Plus and maybe others), launches from the Startup folder in the Start Menu, but not required as they give instructions on removing it on their webpage |
| N | Watch Dog Program | watchdog.exe | For Compaq PC's. Associated with Compaq's internet services. Not required if you don't use services provided by them and may not be required even if you do |
| ? | Watch | 1200UBWATCH.EXE | ?? |
| X | Wast | wast.exe | Grokster ads updater |
| N | Watch | watch.exe | Found to be used by a Trust USB scanner for auto starting the scanning software when the lid is lifted |
| U | washindex | washidx.exe | Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
| N | Washerie.exe | washerie.exe | Cookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer, specific for cleaning the IE cache and cookies. Available via Start -> Programs |
| U | Washer | washer.exe | Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
| U | WashAndGo - Cleanup of old Backupfiles | checker.exe | WashAndGo - temp file cleaner |
| N | WARSVR | war-ftpd.exe | "War FTP Daemon - the original free FTP server for windows" |
| U | Warning: do not remove it! | fpplock.exe | Part of Folder Password Expert by ZQS Software Team - "a software program to restrict access to the folders that contain your sensitive data" |
| U | Warnet | warnet.exe | Warnet - system cleanup software |
| U | Warner | warner.exe | Also known as "CyberWarner". From G-Tek Technologies and pre-installed on some Packard Bell PCs. Protects critical files |
| N | warez | warez.exe | Warez P2P client |
| X | Wardo | syslaunch.exe | Added by the ADLCICKER.G TROJAN! |
| N | war-ftpd.exe | WAR-FTPD.EXE | War FTP Daemon from JGAA's Internet - FTP client |
| X | WAPI | wts**.exe [* = random char] | PurityScan/Clickspring adware
|
| Y | WanMPSvc | WanMPSvc.exe | An AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling AOL doesn?t help |
| N | Wanadoo Messenger.exe | Wanadoo Messenger.exe | Wanadoo ISP instant messenger client |
| ? | W815DM | W815DM.exe | ?? |
| Y | W75P2PSERVER | W75P2PS.EXE | Printer utility which is required in order to make the printer work correctly |
| X | W3KNetwork | rundll32.exe w3knet.dll, dllinitrun | Advertising spyware. Check here for more info on this particular one |
| X | w32sup | w32sup.exe | Adult content dialler |
| X | W32Tc | WTC32.scr | Added by the VOTE.D or VOTE.K WORMS! |
| X | w32alanis | mope.scr | Added by the SINALA WORM! |
| X | W32Load | [random filename].scr | Added by the CASPID WORM! |
| X | w32 | w32.exe | Added by the SOKEVEN TROJAN! |
| X | W32.Scran | Scran.exe | Added by the NARCS WORM!
|
| X | Windows Internet Protocol | winproc32.exe | CoolWebSearch parasite variant |
| X | Windows JavaScript Daemon | Winjsd.exe | Added by the WOOTBOT.AF WORM! |
| ? | Windows Load | windows.com | ?? |
| X | Windows Loader | wstart32.exe | Added by the GAOBOT.CA WORM! |
| X | Windows logging | winlogd.exe | Added by the RBOT-ON WORM!
|
| X | Windows Login | explored.exe | Added by the GAOBOT.SY WORM! |
| X | Windows Logon | winlogin.exe | Added by the SPYBOT-C TROJAN! |
| X | Windows Logon Procedure | Svchoste.exe | Added by a variant of the SPYBOT WORM!
|
| X | Windows Management Instrumentation | mwd.exe | Added by the GRAPS WORM!
|
| X | Windows Manager | winmants.exe | Added by the MANTAS WORM! |
| X | Windows mangement | winlogonn.exe | Added by the RANDEX.FC WORM! |
| X | Windows Media Player | wmediaplayer.exe | Added by the AGOBOT-NQ WORM!
|
| X | Windows Media Player | WMP23.exe | Added by a variant of the RBOT WORM!
|
| X | Windows Media Player | MediaPIayer.exe | Added by the SDBOT-QO TROJAN! - note, the executable is called 'MediapIayer', with an 'i' !)
|
| X | Windows Media Player | msass43.exe | Added by a variant of the RBOT WORM! |
| N | Windows Media Powerpoint Helper | NSPPTHLP.EXE | German software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start -> Programs |
| X | Windows media service | crvss.exe | Added by the SDBOT.VP WORM! |
| X | Windows media services | cvrsss.exe | Added by the RBOT-MW WORM!
|
| X | Windows Media SP.2.37 | [random filename] | Added by the LEMIR.C TROJAN! |
| X | Windows MeTaLRoCk service | metalrock.exe | Added by the TASTYRED TROJAN! |
| X | Windows Monitor | winmon.exe | Added by the SDBOT.VB WORM! |
| X | Windows Monitoring Service | winmon.exe | Added by a variant of the SDBOT WORM! |
| X | Windows Nets | WinNET.exe | Added by the RBOT-MO WORM!
|
| X | Windows Network Service | winvc32.exe | Added by the RBOT.RY WORM!
|
| X | Windows Networking | winsys32.exe | Added by the GAOBOT.FL WORM! |
| X | Windows Nivedia Driver | sysMGT.exe | Added by a variant of the RBOT WORM! |
| X | Windows NNT | [path to trojan] | Added by the RANKY.E TROJAN! |
| X | Windows NT 32 | ntlogin32.exe | Added by the RANDEX.BRD WORM!
|
| X | Windows NT Login | ntlogin32.exe | Added by the SDBOT.WG WORM! |
| X | Windows NT Service Name | winshock.exe | Added by the RBOT-PK WORM!
|
| X | Windows OEM Tools | winres32.exe | Added by the SPYBOT.FD WORM! |
| X | Windows OLE Automation Server | ole32aut.vbe | CoolWebSearch parasite related browser hijacker |
| ? | Windows Print Spooler | SCVHOSTS.EXE | Suspicious due to the similarity to the valid "svchost.exe" file |
| X | Windows Print Spooler | NavAgent32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Windows Print Spooler | SVEHOST.EXE | Added by the SPYBOT.H WORM! |
| X | Windows Registry | msnmsg.exe | Added by a variant of the RBOT WORM! |
| X | Windows Registry Cleaner | winclean.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows Registry Express Loader | regexpress.exe | Added by the FORBOT-CJ WORM! |
| X | Windows Registry Scan | regscan32.exe | Added by the RBOT.KE WORM! |
| X | Windows Registry Security | crss.exe | Added by a variant of the IRC.BOT TROJAN! |
| X | Windows Registry Startup | wind32.exe | Added by the AGOBOT-BZ WORM! |
| X | Windows report | swchost.exe | Added by the SMALL.GV VIRUS! |
| X | Windows Runtime Help | win32hlp.exe | Added by a variant of the AIMVISION TROJAN! |
| X | Windows Runtime Help | WinRunHelp.wrh | Added by a variant of the AIMVISION TROJAN! |
| X | Windows SA | omniscient.exe | BLAZEFIND adware |
| X | Windows secure | setver32.exe | Added by the SPYBOT.EP WORM! |
| X | Windows Security Assistant | rundll32.vbe | CoolWebSearch parasite variant |
| X | Windows Security Assistant | winsec.exe | CoolWebSearch parasite variant |
| X | Windows Security Module | module.exe | Added by a variant of the RBOT WORM!
|
| X | Windows Service Host | scvhost.exe | Added by the SDBOT.N TROJAN! |
| X | Windows Service Host | svchost.exe | Added by the CONE.B WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | Windows Services | service.exe | Added by the RANDEX.R WORM! |
| X | Windows Services Host | svchost.exe | Added by the CONE or CONE.E WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | Windows Services Update | svch0st.exe | Added by a variant of the RBOT WORM!
|
| ? | |