| Status Code | Name | Command | Description |
| X | Windows HTML file reader | Sysconf32.exe | Added by the NOOMY.A WORM! |
| ? | Windows Help System | Help.pif | ?? |
| X | Windows Host Device | hostsvc.exe | Added by the ZOOTY-A WORM! |
| X | Windows Help Service | winhelpsv.exe | Added by the RBOT-LP WORM! |
| X | Windows Help Manager | svchost32.exe | Added by the RBOT-OZ WORM!
|
| X | Windows Help File | winhelper32.exe | Added by the SDBOT-QK TROJAN!
|
| U | Windows Guardian | thehel1iawgrd32.exe | Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes |
| U | Windows Guardian | Fawgrd32.exe | Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes |
| N | Windows Eyes | ?? | For blind people, gives a voice description of items on the screen. Windows application which gives you total control over what you hear, when you hear it, and how you hear it. Available via Start -> Programs |
| X | Windows Explorer-3212 | WINRE16.EXE | Added by the HARDOC WORM! |
| X | Windows Explorer Update Build 1142 | EXPLORER32.EXE | Added by the KaZaA based KWBOT or KWBOT.Y WORMS! |
| X | Windows Explorer Shell | Winexec32.exe | Added by the REDIST.B WORM! |
| X | Windows Explorer | olecom32.exe | Added by an unidentified WORM or TROJAN! |
| X | Windows Explorer | Lsas.exe | Added by the GAOBOT.AO WORM! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | Windows Explorer | [filename].exe | Added by the SDBOT TROJAN! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | Windows Driver Services | msdrvs32.exe | Added by the WOOTBOT.L WORM! |
| X | Windows Drive Compatibility | System32Driver32.exe | Added by the SUPOVA.Z WORM! |
| X | Windows DNS Daemon | windnsd.exe | Added by the WOOTBOT.AS WORM! |
| X | Windows DLL Loader | defragfat32pi.exe | Added by the RBOT-QQ WORM! |
| X | Windows DLL Loader | rundll32.exe | Added by the WHIPSER-B WORM! Note - rundll32.exe file is placed in the WindowsSystem folder, wheras the legitimate rundll32.exe is located in the C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP)
|
| X | Windows DLL Loader | defragfat32z.exe | Added by the LINKBOT.A WORM!
|
| X | Windows DLL Loader | RUNDLL16.EXE | Added by the DOMWIS TROJAN! |
| X | Windows Debugger | windbg.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Windows debug logging | winloggs.exe | Added by the RBOT-QN WORM! |
| X | Windows debug logging | winlogg.exe | Added by the RBOT-OY WORM!
|
| X | Windows Dcom2 Fix | mscom32.exe | Added by the RBOT-QT WORM! |
| X | Windows Control | Control.exe | Browser hijacker. NOTE - On Win9x systems it will overwrite the Windows file of the same name in the Windows directory, so therefore it will be necessary to extract a fresh copy of the file from the Windows setup cabs! |
| X | Windows Data Server | autodisc.exe | Added by the SPYBOT-CB WORM!
|
| X | Windows Configuration | wsys32.exe | Added by the GAOBOT.FB WORM! |
| X | Windows Config | SSYS.EXE | Added by the SPYBOT-DA WORM! |
| X | Windows Config Loader | Wincfg32.exe | Added by the SILVERFTP TROJAN! |
| X | Windows Compliant | [random filename] | Added by the RBOT-IR WORM! |
| X | Windows Ba?lang?? Dosyas? | sistem.exe | Added by the MUZK WORM! |
| X | Windows Communicator | wincomm.exe | Added by the AGOBOT-BH WORM!
|
| X | Windows Backup Configuration | IEXPLORER.exe | Added by the GAOBOT.AZ WORM! |
| X | Windows Automation | msdspr.exe | Added by the SOLAME.A WORM! |
| X | Windows backup | systemss.exe | Added by a variant of the SPYBOT WORM! |
| X | windows automation | mslaugh.exe | Added by the BLASTER.E WORM! |
| X | Windows Automatic Updates | dvldr.exe | Added by the RBOT.MF WORM!
|
| X | windows auto update | msblast.exe | Added by the BLASTER.B WORM! |
| X | Windows Automatic Update | wuamgrder.exe | Added by a variant of the RBOT WORM! |
| X | windows auto update | penis32.exe | Added by the BLASTER (or MSBLAST.A) WORM! |
| X | Windows AdTools | WinAdTools.exe | Windupdates adware variant |
| X | Windows AdService | WinAdServ.exe | Windupdates adware variant |
| X | Windows AdControl | WinAdCtl.exe | Windupdates adware variant
|
| U | Windows Accelerators | setup.exe | KeySpy keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove |
| X | Windows (random character) | diskcheck.exe | Added by the SINGU.B TROJAN!
|
| X | windows | system copy.exe | Added by the SALGA.A WORM! |
| X | windows | hkey.exe | Added by the GAOBOT.AFW WORM! |
| X | windows | [path to trojan] | Added by the AIMWIN TROJAN! |
| X | Windows | explorer.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | Windows | Windows.exe | Added by the KAZMOR, BOBBINS & ALADINZ.D TROJANS! |
| X | Windows | msdos98.exe | Added by the PWSTEAL TROJAN! |
| X | Windows | Kernel32.exe | Added by the TENDOOLF WORM! |
| U | WindowFX | wfxload.exe | Stardock WindowFX - "Allows you to add an unprecedented number of special effects to windows" |
| X | WindowEnhancer | Winex.exe | SCbar foistware variant |
| U | WindowBlinds | wbload.exe | WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins |
| X | window2 | ssvchost.exe | Added by the IRCBOT.H TROJAN! |
| X | window.exe | window.exe | Added by the MITGLIEDER.H or MITGLIEDER.J TROJANS! |
| U | Window Washer | wwDisp.exe | Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
| X | Window Monitor | winmon32.exe | Added by the SDBOT.RT WORM! |
| X | Window Loader | Dos32.exe | Added by the GAOBOT.AO WORM! |
| X | Window | explore.exe | Added by the GAOBOT.ADW WORM! |
| X | Windoes Kernel | kernel32.exe | Added by the KICKIN.A (or CYDOG.C) WORM! |
| X | WinDNS | windns32.exe | Added by the GAOBOT.WX WORM! |
| X | Windll32 | Windll32.exe | Added by the MSNPWS TROJAN! |
| X | windllsys32.exe | windllsys32.exe | Added by a variant of the MITGLIEDER.BY TROJAN! |
| X | Windll.exe | Windll.exe | Added by the STEALER TROJAN! |
| U | WINDLL | WSYS.EXE | STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes, all passwords transacted even if they weren't keyed in, all web sites visited, every program launched including the path to that program, and more" |
| X | windll | windll32.exe | Added by the ASTEF or RESPAN WORMS! |
| X | Windll | Windll.exe | Added by the TRYNOMA TROJAN! |
| X | windir | winrun.exe | Added by the WINBUR.B WORM! |
| X | windef | Win32sp.vbs | Added by the ANPES WORM!
|
| X | Winde | winde.exe | Added by the DLUCA TROJAN! |
| X | windbs | winxtc.exe | Added by the AGOBOT-WD WORM! |
| N | WinDates | windates.exe | WinDates is a calendar, date organizer and event reminder program from Rockin' Software |
| X | WIND0WS | WIND0WS.exe | Added by the SPYBOT.DQ WORM! |
| X | WinCSRSS | MSGRT32.EXE | Added by the REWINDO-A TROJAN!
|
| X | wind.exe | wind.exe | Added by the MITGLIEDER.BD TROJAN! |
| N | WinCinemaMgr | WinCinemaMgr.exe | WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
| N | WINCINEMAMGR | WINCIN~1.EXE | WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
| X | WinCheck | WinCheck.exe | Added by the PWS-CY TROJAN! |
| X | Winbed | winbed.exe | Hijacker |
| U | WinBar | WinBar.exe | "WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls" |
| U | WinBackup Scheduler | Wbsched.exe | LIUtilities WinBackup scheduler - backup software |
| X | WinAuth | winlogon.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the valid winlogon.exe process |
| X | Winapp | winpup32.exe | Produces popup ads to adult content sites |
| X | WinApp32 | msapp.exe | Added by the RSBOT TROJAN! |
| X | WinApi | winapix.exe | Added by a variant of the TIBSER.A downloader TROJAN! |
| U | WinampAgent | WINAMPa.exe | Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs |
| X | Winampa Agent | WINAMPA.EXE | Added by the SPYBOT-BR WORM! Note - this is NOT the Winamp Media Player
|
| X | Winampa | winampa.exe | Added by the AGOBOT-GS WORM!
|
| U | Winampa | WINAMPa.exe | Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs |
| X | Winamp media player | winapa.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Winamp | winamp.hta | Hijacker - re-directing to adult content sites. Note - this isn't the real Winamp |
| X | winallapu | winallapu.exe | Added by the DELF.E TROJAN! |
| X | winallap | winallap.exe | Added by the DELF.E TROJAN! |
| X | Winahlp.exe | Winahlp.exe | Added by a variant of the VAGRNOCKER TROJAN! |
| X | winadm | winadm.exe | Browser hijacker - redirecting to Search-World.net. Related to the SMALL.LR TROJAN!
|
| X | Winad Client | Winad.exe | WinAd adware by eXact Advertising |
| X | winactive | WINACTIVE.EXE | Active variant of LOP.com hijacker - see here |
| X | WinActiveJ | WinActiveJ.exe | Added by the ROTARRAN VIRUS! |
| X | WIN3S2SNDS | winabsmod.exe | Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" |
| X | WIN3S2SNDS | winiprtx.exe | Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" |
| X | Win64 Compatibility Check | load win64.drv | CoolWebSearch parasite variant |
| X | Win386 | Win386.exe | Added by the GOSUSUB VIRUS! |
| X | Win386 | sp32.dll | Homepage hijacker. Not a dll but a regfile in disguise |
| X | win32_i ml097e | win32_i.exe | Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | win32_i lptt01 | win32_i.exe | Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | win32us | win32us.exe | All-In-One-Telcom (adult content dialler) variant |
| X | win32usbd | ssrs.exe | Added by the RBOT-RA WORM! |
| X | Win32SystemMonitor | ***.exe [* = random char] | Browser hijacker
|
| X | Win32System | win32s.exe | Added by the MYDOOM.V WORM! |
| X | Win32system | [random filename] | Added by the DDV.B WORM! |
| X | WIN32SNDS | banc.exe | Added by an unidentified WORM or TROJAN! |
| Y | WIN32SL | Win32sl.exe | Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. The specific function of this is to load MIF's in order for Dell OpenManage Client to work |
| X | win32ini | systroy.exe | Added by the IRC.ALADINZ.C TROJAN! |
| X | Win32R | Server.com | Added by the ESTRELLA TROJAN! |
| X | win32info | win32info.exe | Adult content dialler |
| X | win32gb | win32gb.exe | All-In-One-Telcom (adult content dialler) variant |
| X | Win32G | Kernel32.com | Added by the ESTRELLA TROJAN! |
| X | Win32G | Scandisk.com | Added by the ESTRELLA TROJAN |
| X | Win32dll | Win32dll.exe | Added by the BANPAES TROJAN! |
| X | Win32DLL | Win32DLL.vbs | Added by the LOVELETTER (I LOVE YOU) VIRUS! |
| X | win32clf | win32clf.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Win32BaseServiceMOD | Wintask.exe | Added by the NAVIDAD WORM! |
| X | win32.exe | win32.exe | Added by the STARTPAGE TROJAN! |
| X | Win32 Wmls Driver | winitr32.exe | Added by the WOOTBOT.B WORM! |
| X | Win32 USB2.0 Driver | service.exe | Added by the SDBOT-QF WORM!
|
| X | Win32 USB2.0 Driver | w32usb2.exe | Added by the SPYBOT.DN WORM! |
| X | Win32 USB2.0 Driver | rundll16.exe | Added by the WOOTBOT.H WORM! |
| X | Win32 USB2.0 Driver | 386.exe | Added by the IRCBOT.D WORM! |
| X | Win32 USB2 Driver | winupdate.exe | Added by the AGOBOT.YE WORM! |
| X | Win32 USB2 Driver | wind32.exe | Added by the FORBOT-AH WORM! |
| X | Win32 USB2 Driver | sys32snd.exe | Added by the FORBOT-AN WORM! |
| X | Win32 USB2 Driver | sys32.exe | Added by the WOOTBOT.X WORM! |
| X | Win32 USB2 Driver | svchosting.exe | Added by the FORBOT.J or SDBOT.HU WORM! |
| X | Win32 USB2 Driver | win32usb.exe | Added by the SPYBOT.DHV WORM! |
| X | Win32 USB2 Driver | smsc.exe | Added by the SDBOT.FO WORM! |
| X | Win32 Usb Driver | svhosint32.exe | Added by the FORBOT-BE or FORBOT-J WORMS!
|
| X | Win32 USB Driver | mvsecn.exe | Added by the FORBOT-BK WORM!
|
| X | Win32 USB Driver | winxpinit.exe | Added by the SDBOT.AA TROJAN! |
| X | Win32 SSL Driver | winssv.exe | Added by the FORBOT-BH WORM!
|
| X | Win32 System Spool | spoolsvc.exe | Added by the SDBOT.UK WORM! |
| X | Win32 Services1 | wuamngr1.exe | Added by the SDBOT-PV WORM! |
| X | Win32 Rundll Loader | Rundll32.exe | Added by the SDBOT.A TROJAN! Note: Rundll32.exe is a valid Windows application called "Run a DLL as an App" and stored in the C:Windows directory. The version created by this virus is saved in the C:WindowsSystem directory |
| X | Win32 Ms Auto Updater | AutomsUPD.exe | Added by a variant of the RBOT WORM! |
| X | win32 regedit | msn32.exe | Added by an unidentified WORM or TROJAN! |
| X | Win32 FRT Driver | msfr32.exe | Added by a variant of the FORBOT WORM! |
| X | Win32 Kernel core component | Kernel32.pif | Added by the MOKS VIRUS! |
| X | Win32 Explorer | Explorer32.exe | StartPa-MN homepage hijacker |
| X | Win32 exe file | winstr32.exe | Added by a variant of the SPYBOT WORM! |
| X | Win32 DRK Driver | wdrk32.exe | Added by the WOOTBOT.CY WORM! |
| X | Win32 Device Loader | Win32ldr.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Win32 Configuration | dllhelp.exe | Added by the SDBOT.UL WORM! |
| X | Win32 Configuration | videosd32.exe | Added by the SDBOT.TT WORM! |
| X | win32 | WinSetup.exe | Added by the EVILBOT.B TROJAN! |
| X | win32 | winsrv32.exe | Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites |
| X | Win32 | Win32.exe | Added by the ISRAZ.A WORM! |
| X | win32 | Setup_32.exe | Added by the EVILBOT.B TROJAN! |
| X | win32 | Shakira_1997_Part_1_.Mpeg_.scr | Added by the MYLIFE.N WORM! |
| X | WIN32 | WIN32.EXE | Added by the RATEGA TROJAN! |
| X | Win2Drv | [worm filename] | Added by the WINTOO WORM! |
| X | Win USB 2.0 USB Driver | HPPrint.exe | Added by the SPYBOT.DNB WORM! |
| X | WIN-BUGSFIX | WIN-BUGSFIX.EXE | Added by the LOVELETTER (I LOVE YOU) VIRUS! |
| X | win update | wupda32.exe | Added by the SDBOT.J WORM! |
| X | Win Server Updt | wupdt.exe | Added by the IMISERV.A TROJAN! |
| X | Win Server | winserv.exe | Added by the IMISERV.A TROJAN! |
| ? | win name | stat.exe | ?? |
| X | Win l5oahder | winampa.exe | Added by the SPYBOTER.GEN VIRUS! Not the valid Winamp Agent which uses the same filename. This resides in the System32 sub-folder wheras real one is located in the winamp folder |
| X | WIN HOST PROCESS | WIN HOST PROCESS.EXE | Added by the KEYLOGGER.CLONE TROJAN! |
| X | Win Command | command32.exe | Added by the AGOBOT.XQ WORM! |
| X | Win Command | command32.exe | Added by the AGOBOT.XQ WORM! |
| X | Win Comm | WinComm.exe | WebRebates related adware
|
| U | Win Chimes | winchi~1.exe | WinChimes - enhancement software for the system clock that runs in the system tray |
| X | win | xwinxrpc32.exe | Added by the AGOBOT-MV WORM! |
| N | Willow Road | WillowRoad.exe | Willow Road Screen Saver |
| X | win | regedit -s ..win.dll | Added by the SEEKER.K TROJAN! |
| N | Wildwire Monitor | WWMon.exe | This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem |
| U | WildTangent Web Driver updater | wcmdmgrl.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| N | WIAWizardMenu | RUNDLL32.EXE sti_ci.dll, WiaCreateWizardMenu | Still Image Class Installer - installed with a webcam |
| ? | WildTangent CDA | RUNDLL32.exe cdaEngine0400.dll,cdaEngineMain | Part of the WildTangent on-line games system. What does it do and is it required? |
| X | WhenUSearch | Search.exe | WhenUSearch adware |
| X | Whvlxd | Whvlxd.exe | Added by the W32.LXD.MIRC TROJAN! |
| X | WhenUSave | Save.exe | Rebranded version of SaveNow advertising spyware |
| U | WheelMouse | AMOUMAIN.EXE | A4Tech wireless mouse driver and utility - required if you use non-standard Windows driver features |
| U | WheelMouse | 4DMAIN.EXE | Mouse software for "Fellowes" Wheelman mouse. Has caused some users problems but shouldn't be needed if you don't use any enhanced features it may provide |
| X | whagent | whagent.exe | System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here |
| U | WGWLocalManager | WGWLocalManager.exe | Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so. It could be started by creating a shortcut, running it only when connecting to the internet. If internet is used often, it's recommended to leave it in startup so it starts with the system |
| Y | WG511WLU | WG511WLU.exe | Netgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card
|
| ? | WFXSwtch | WFXSWTCH.exe | Related to WinFax. What does it do and is it required? |
| Y | wfxsnt40 | wfxsnt40.exe | WinFax 10.0 and maybe earlier versions. The program that opens the port for WinFax and not normally in the start menu. Needed if you want to run WinFax |
| N | WFXCTL32.EXE | WFXCTL32.EXE | From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs |
| U | wfips | iphider.exe | ICQ (messaging/chat program) anti-bomb software. "WFIPS is anti-bomb software for safeguarding ICQ Bomb before the bombing. 'ICQ Defoolder' is a tool for removing ICQ bomb after being exposed." For more information about ICQ bombs see here |
| N | WFGStartup | WFGStartup.exe | World Weather. "This midlet displays the current weather conditions for major cities around the world. This version is for memory limited mobile phones" |
| N | WetSock | wetsock.exe | RoboMagic Wetsock - weather reporting in the System Tray |
| X | wersds | doriot.exe | Added by the JECT.C TROJAN! |
| ? | WEPstat | Wepstat.exe | Cisco Aironet 340 Series PC Card driver. If it can be started manually it shouldn't be required if you don't use the PC card facility regularily - hence the status could be "U". Can anybody confirm this? |
| N | Welcome | Welcome.exe | Launches the Welcome to Windows tutorial on boot up |
| U | WebWasher | wwasher.exe | Free Pop-up/ad/javascript filter program from Siemens. If not running then browsers will not be protected but will still work. Available via Start -> Programs |
| Y | WebTrapNT.exe | WebTrapNT.exe | Part of PC-Cillin Anti-Virus software. Checks visited web-sites for malicious Java and ActiveX elements |
| Y | Webtrap | webtrap.exe | Part of PC-Cillin anti-virus software. Checks web-sites for malicious Java and ActiveX elements in a similar way to McAfee WebScanX. A few users find it infuriating |
| X | WebSpecials | rundll32 [path] webspec.dll | WebSpecials spyware
|
| X | Websx | Int*****.exe | Adult content dialler - where ***** are random |
| N | Webshots | websho~1.exe | Screensaver program that automatically downloads from the webshots web site |
| N | Webshots | Webshots Tray.exe | Screensaver program that automatically downloads from the webshots web site |
| X | WebSecureAlert | WebSecureAlert.exe | WebSecureAlert. "Can help protect your browser security and privacy". However, it's by GAIN Publishing, and will display pop up ads on your computer screen based on your online Web surfing behavior |
| ? | WebServer | VBI_SE~1.EXE | Related to a Pinnacle sound card. What does it do and is it needed? |
| X | websearch | wjview ...websearch.exe | "Web Savings" From Ebates Software, a shopping tool that opens pop-up windows |
| Y | WebScanX | WebScanX.exe | From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc |
| N | webscan | stopsignav.exe | eAcceleration Stop-Sign related - not recommended, see note |
| X | WebScan | DEFSCANGUI.EXE | Stop-Sign from eAccelerration. Detects spyware, malware, viruses and keyloggers and stops popups. Spyware in itself - see their privacy statement here |
| X | WebSavingsFromEbates0 | WebSavingsFromEbates0.exe | Web Savings From Ebates Software, a shopping tool that opens pop-up windows
|
| X | WebSavingsfromEbates | WebSavingsfromEbatesrun.exe | Web Savings From Ebates Software, a shopping tool that opens pop-up windows |
| U | websaverlive | websaverlive.exe | WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your computer is idle |
| X | WebRebates0 | WebRebates0.exe | WebRebates adware |
| N | Webposition Gold 2 | wpsche~1.exe | Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines |
| N | WebOutfitterTray | sttray.exe | Intel WebOutfitter service System Tray icon |
| N | WebKey | WebKey.exe | WebKey from JB Utilities. Utility to keep track of login data required when browsing the internet |
| X | WebInstall | WebInstall.exe | ClipGenie adware downloader |
| X | WebInstall2 | WebInstall.exe | ClipGenie adware downloader |
| X | WebHancer Agent | whagent.exe | System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here |
| X | webHancer Survey Companion | whSurvey.exe | WebHancer foistware - traffic measurement service that uses a client agent that is stealth installed on user machines, gathering detailed data about sites visited, their performance and, most important, what the user actually does while there |
| X | Webdav.exe | webdav.exe | IRC DDoS bot which gives the hacker full control over your system |
| X | WebCpr0 | WebCpr0.exe | Web_CPR/TopMoxie adware |
| X | WebCheck | WebCheck.pif | Added by the CONE.C or CONE.F WORMS! |
| N | WebcamRT.exe | WEBCAMRT.exe | For Logitech Web Cams. Not required - camera works fine without it |
| X | Webcelerator | webcel.exe | Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Spyware and troublesome - see here |
| X | webassist | webassist.exe | Adware popup generator |
| ? | Webcam Go Sti Service Application | wbcgosvc.exe | Control software for the portable Creative Video Blaster Webcam Go digital camera/PC web cam. What does it do and is it required? |
| N | WebArmyKnife | WAK.exe | Web Army Knife - a suite of web site developer's tools |
| Y | web3trap | web3trap.exe | PC-Cillin 2000 anti-virus software -> ActiveX filter. Guards against malicious ActiveX programs, etc |
| X | webalize | webalize.exe | Searchcentrix hijacker |
| ? | Web Search | ?? | ?? |
| X | web | ******.exe [* = random char] | Added by a variant of the EASTO.A TROJAN! |
| N | WeatherWatcher | ww.exe | WeatherWatcher - weather reporting in the System Tray |
| X | WeatherOnTray | WeatherOnTray.exe | Hotbar's Weather Forecast tool for your desktop - adware |
| N | WEATHER | WEATHER.EXE | Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs |
| N | WeatherCast | Weather.exe | Weather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight |
| X | wdwctrl | wdwctrl.exe | Added by the DLUCA.E TROJAN! |
| X | wdskctl | wdskctl.exe | IEPlugin spyware
|
| X | WDInfo | wdinfo.exe | Adult content dialler |
| U | WD Button Manager | WDBtnMgr.exe | Button manager installed with a western digital external disk drive. Allows you to back up your system with one click
|
| X | WCPT | wintsvtr.exe | PurityScan/Clickspring adware |
| X | WCPS | Wint**.exe [* = random char] | PurityScan/Clickspring adware
|
| X | WCPI | wintsvit.exe | PurityScan/Clickspring adware |
| ? | WCPC | wintsvcc.exe | ?? |
| U | WCOLOREAL | coloreal.exe | Makes colours sharper and brighter, but will only work with coloreal capable monitors |
| U | wcmdmgrl | wcmdmgrl.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| N | wcmdmgr.exe | wcmdmgr.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| U | wcmdmgr | wcmdmgrl.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
|
| N | WCESCOMM | WCESCOMM.EXE | Active sync for use with Windows CE based palm PC |
| ? | Wbutton | Wbutton.exe | Related to the Wacom Penabled driver on Acer Tablet PCs. Appears to do nothing so is it required? |
| N | Wbiff | Wbiff.exe | Wbiff! E-mail checker - automatically checks your e-mail and notifies you if any new e-mail has been received |
| N | WaveTop Upload Manager | N/A | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
| N | WaveTop Receiver 2 | N/A | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
| N | WaveTop Receiver 1 | N/A | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
| N | WaveTop Launcher | WaveTop.exe | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
| N | Watchdog | Watchdog.exe | Definitely part of the Mustek scanner drivers and software (for 600 III EP Plus and maybe others), launches from the Startup folder in the Start Menu, but not required as they give instructions on removing it on their webpage |
| N | Watch Dog Program | watchdog.exe | For Compaq PC's. Associated with Compaq's internet services. Not required if you don't use services provided by them and may not be required even if you do |
| ? | Watch | 1200UBWATCH.EXE | ?? |
| X | Wast | wast.exe | Grokster ads updater |
| N | Watch | watch.exe | Found to be used by a Trust USB scanner for auto starting the scanning software when the lid is lifted |
| U | washindex | washidx.exe | Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
| N | Washerie.exe | washerie.exe | Cookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer, specific for cleaning the IE cache and cookies. Available via Start -> Programs |
| U | Washer | washer.exe | Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
| U | WashAndGo - Cleanup of old Backupfiles | checker.exe | WashAndGo - temp file cleaner |
| N | WARSVR | war-ftpd.exe | "War FTP Daemon - the original free FTP server for windows" |
| U | Warning: do not remove it! | fpplock.exe | Part of Folder Password Expert by ZQS Software Team - "a software program to restrict access to the folders that contain your sensitive data" |
| U | Warnet | warnet.exe | Warnet - system cleanup software |
| U | Warner | warner.exe | Also known as "CyberWarner". From G-Tek Technologies and pre-installed on some Packard Bell PCs. Protects critical files |
| N | warez | warez.exe | Warez P2P client |
| X | Wardo | syslaunch.exe | Added by the ADLCICKER.G TROJAN! |
| N | war-ftpd.exe | WAR-FTPD.EXE | War FTP Daemon from JGAA's Internet - FTP client |
| X | WAPI | wts**.exe [* = random char] | PurityScan/Clickspring adware
|
| Y | WanMPSvc | WanMPSvc.exe | An AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling AOL doesn?t help |
| N | Wanadoo Messenger.exe | Wanadoo Messenger.exe | Wanadoo ISP instant messenger client |
| ? | W815DM | W815DM.exe | ?? |
| Y | W75P2PSERVER | W75P2PS.EXE | Printer utility which is required in order to make the printer work correctly |
| X | W3KNetwork | rundll32.exe w3knet.dll, dllinitrun | Advertising spyware. Check here for more info on this particular one |
| X | w32sup | w32sup.exe | Adult content dialler |
| X | W32Tc | WTC32.scr | Added by the VOTE.D or VOTE.K WORMS! |
| X | w32alanis | mope.scr | Added by the SINALA WORM! |
| X | W32Load | [random filename].scr | Added by the CASPID WORM! |
| X | w32 | w32.exe | Added by the SOKEVEN TROJAN! |
| X | W32.Scran | Scran.exe | Added by the NARCS WORM!
|
| X | Windows Internet Protocol | winproc32.exe | CoolWebSearch parasite variant |
| X | Windows JavaScript Daemon | Winjsd.exe | Added by the WOOTBOT.AF WORM! |
| ? | Windows Load | windows.com | ?? |
| X | Windows Loader | wstart32.exe | Added by the GAOBOT.CA WORM! |
| X | Windows logging | winlogd.exe | Added by the RBOT-ON WORM!
|
| X | Windows Login | explored.exe | Added by the GAOBOT.SY WORM! |
| X | Windows Logon | winlogin.exe | Added by the SPYBOT-C TROJAN! |
| X | Windows Logon Procedure | Svchoste.exe | Added by a variant of the SPYBOT WORM!
|
| X | Windows Management Instrumentation | mwd.exe | Added by the GRAPS WORM!
|
| X | Windows Manager | winmants.exe | Added by the MANTAS WORM! |
| X | Windows mangement | winlogonn.exe | Added by the RANDEX.FC WORM! |
| X | Windows Media Player | wmediaplayer.exe | Added by the AGOBOT-NQ WORM!
|
| X | Windows Media Player | WMP23.exe | Added by a variant of the RBOT WORM!
|
| X | Windows Media Player | MediaPIayer.exe | Added by the SDBOT-QO TROJAN! - note, the executable is called 'MediapIayer', with an 'i' !)
|
| X | Windows Media Player | msass43.exe | Added by a variant of the RBOT WORM! |
| N | Windows Media Powerpoint Helper | NSPPTHLP.EXE | German software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start -> Programs |
| X | Windows media service | crvss.exe | Added by the SDBOT.VP WORM! |
| X | Windows media services | cvrsss.exe | Added by the RBOT-MW WORM!
|
| X | Windows Media SP.2.37 | [random filename] | Added by the LEMIR.C TROJAN! |
| X | Windows MeTaLRoCk service | metalrock.exe | Added by the TASTYRED TROJAN! |
| X | Windows Monitor | winmon.exe | Added by the SDBOT.VB WORM! |
| X | Windows Monitoring Service | winmon.exe | Added by a variant of the SDBOT WORM! |
| X | Windows Nets | WinNET.exe | Added by the RBOT-MO WORM!
|
| X | Windows Network Service | winvc32.exe | Added by the RBOT.RY WORM!
|
| X | Windows Networking | winsys32.exe | Added by the GAOBOT.FL WORM! |
| X | Windows Nivedia Driver | sysMGT.exe | Added by a variant of the RBOT WORM! |
| X | Windows NNT | [path to trojan] | Added by the RANKY.E TROJAN! |
| X | Windows NT 32 | ntlogin32.exe | Added by the RANDEX.BRD WORM!
|
| X | Windows NT Login | ntlogin32.exe | Added by the SDBOT.WG WORM! |
| X | Windows NT Service Name | winshock.exe | Added by the RBOT-PK WORM!
|
| X | Windows OEM Tools | winres32.exe | Added by the SPYBOT.FD WORM! |
| X | Windows OLE Automation Server | ole32aut.vbe | CoolWebSearch parasite related browser hijacker |
| ? | Windows Print Spooler | SCVHOSTS.EXE | Suspicious due to the similarity to the valid "svchost.exe" file |
| X | Windows Print Spooler | NavAgent32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Windows Print Spooler | SVEHOST.EXE | Added by the SPYBOT.H WORM! |
| X | Windows Registry | msnmsg.exe | Added by a variant of the RBOT WORM! |
| X | Windows Registry Cleaner | winclean.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows Registry Express Loader | regexpress.exe | Added by the FORBOT-CJ WORM! |
| X | Windows Registry Scan | regscan32.exe | Added by the RBOT.KE WORM! |
| X | Windows Registry Security | crss.exe | Added by a variant of the IRC.BOT TROJAN! |
| X | Windows Registry Startup | wind32.exe | Added by the AGOBOT-BZ WORM! |
| X | Windows report | swchost.exe | Added by the SMALL.GV VIRUS! |
| X | Windows Runtime Help | win32hlp.exe | Added by a variant of the AIMVISION TROJAN! |
| X | Windows Runtime Help | WinRunHelp.wrh | Added by a variant of the AIMVISION TROJAN! |
| X | Windows SA | omniscient.exe | BLAZEFIND adware |
| X | Windows secure | setver32.exe | Added by the SPYBOT.EP WORM! |
| X | Windows Security Assistant | rundll32.vbe | CoolWebSearch parasite variant |
| X | Windows Security Assistant | winsec.exe | CoolWebSearch parasite variant |
| X | Windows Security Module | module.exe | Added by a variant of the RBOT WORM!
|
| X | Windows Service Host | scvhost.exe | Added by the SDBOT.N TROJAN! |
| X | Windows Service Host | svchost.exe | Added by the CONE.B WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | Windows Services | service.exe | Added by the RANDEX.R WORM! |
| X | Windows Services Host | svchost.exe | Added by the CONE or CONE.E WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | Windows Services Update | svch0st.exe | Added by a variant of the RBOT WORM!
|
| ? | Windows shell | win70.exe | ?? |
| X | Windows Shell Library Loader | load shell.dll /c /set | CoolWebSearch parasite variant |
| X | windows shellext.32 | mschost.exe | Added by the BLASTER.K WORM! |
| X | Windows Sound Driver | SndMon32.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows Sound Manager | SndMon32.exe | Added by the FORBOT-BU WORM! |
| X | Windows SP2 Update | Sp2update.exe | Added by the WOOTBOT.BS WORM!
|
| X | Windows Spooler | SPOOLSRV.EXE | Added by the SPYBOT.P WORM! |
| X | Windows SSL File | winssv.exe | Added by the WOOTBOT.CA WORM! |
| X | Windows Startup | winsta~1.exe | GoHip foistware |
| X | Windows Startup | winstartup.exe | GoHip foistware |
| X | Windows Startup | Wdrun32.exe | Added by the GAOBOT.AO WORM! |
| X | Windows Startup | services21.exe | Added by the AGOBOT-MX WORM! |
| X | Windows Startup 32 Bits | sysrun32.exe | Added by a variant of the DARKSUN TROJAN! |
| X | Windows SyncroAd | SyncroAd.exe | BlazeFind "Windupdates" targeted advertizing |
| X | Windows System Configuration | SYSCFG16.EXE | Added by the WISDOOR.Z TROJAN! |
| X | Windows System Manager | winsystem.exe | Added by the RBOT-AN WORM! |
| X | Windows System Manager Proc | winsmc.exe | Added by the RBOT.JH WORM!
|
| X | Windows System Restore Configuration | Sblhost.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows System Restorer | SystemRestorer.exe | Added by the DULOAD.C WORM! |
| X | Windows System Serivce | winserv.exe | Added by a variant of the RBOT WORM!
|
| X | windows system service | winsock.exe | Added by the RBOT-MR WORM!
|
| U | Windows System Tray | msni.exe | Iambigbrother monitoring software |
| X | Windows System Tray | swhost.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Windows Task Manager | ACCOUNT_DETAILS.DOC.exe | Added by the QUATERS.A WORM! |
| X | Windows Task Manager | taskmgn.exe | Unidentified malware, either a variant of the WIN32.RBOT WORM, or part of a Casino Palazzo foistware install
|
| X | Windows TaskAd | Wintaskad.exe | Windupdates adware variant |
| X | Windows TCP/IP | wintcp.exe | Added by the AGOBOT-ZH WORM!
|
| X | Windows Telnet Server | wintel.exe | Added by the AGOBOT-MW WORM! |
| X | Windows Time Server | TimeSRV.exe | Added by the SPYBOT.DNC WORM! |
| X | Windows Update | [filename] | Added by the NORIO TROJAN! Acts as a hi-jacker redirecting to adult content sites |
| X | Windows Update | iexplorere.exe | Added by the GAOBOT.AP WORM! |
| X | windows update | uddater.exe | Added by the LEOX TROJAN! |
| X | Windows Update | wudate.exe | Added by the AGOBOT.ML WORM! |
| X | Windows Update | wupdate.exe | Wengs adware |
| X | windows update | sychost.exe | Added by the LEOX.B WORM! |
| X | Windows Update | Wuamgrd.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows Update | inetinf.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Windows Update | host32.exe | Added by the RBOT-GU WORM!
|
| X | windows update | wuraclt.exe | Added by the RBOT-PO WORM!
|
| X | windows update | Wuanclt.exe | Added by the RBOT.XZ WORM! |
| X | Windows Update | ebay.exe | Added by the GAOBOT.BUU WORM! |
| X | Windows Update | windows.exe | Added by the RBOT-RB WORM! |
| X | Windows Update AutoUpdate Client Product | wuauct.exe | Added by the AGOBOT.ACL WORM! |
| X | Windows Update Checker | [random filename] | Adware downloader trojan |
| X | Windows update config | svhost.exe | Added by the SDBOT-PF WORM! |
| X | windows update configurator | svghost.exe | Added by a variant of the SPYBOT WORM!
|
| X | Windows Update Files | dnetc.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - wupdmgr.exe is the real Windows Update |
| X | Windows Update Manager | wupdmngr.exe | Added by the RANDEX.BTB WORM!
|
| X | Windows Update Manager for NT | wupdmgr32.exe | Added by the SDBOT.AH WORM! |
| X | Windows Update Monitoring Service | winupdt.exe | Added by the RBOT-PL WORM!
|
| X | Windows Update Process | wmiprvsc.exe | Added by the SDBOT-CB WORM! |
| X | Windows Update Service | csrs.exe | Added by the AGOBOT-NI WORM! |
| X | Windows Update Service | smcg.exe | Added by the SDBOT.QY WORM! |
| X | Windows Update Service 2004/2005 | systemupdate.exe | Added by the RBOT-JE WORM! |
| X | Windows Update V6 | [random filename] | Added by the RBOT-KT WORM! |
| X | Windows Update.exe | N/A | Homepage hijacker, see here |
| X | Windows Updater | wupdmgr32.exe | Added by a variant of the DOS.AUTOCAT TROJAN! |
| N | Windows Version Check | ver_chk.exe | Version checker for CyberAudioLibrary ("A new way to exchange information through the Internet") |
| X | Windows video | vide_32.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Windows Video Acquisition (WVA) | wvsvc.exe | Added by the AGOBOT.YM WORM! |
| X | Windows Video Drivers | videons32.exe | Added by the GAOBOT.AZT WORM! |
| X | Windows-System | System32.exe | Added by the LOGPOLE.C WORM! |
| X | Windows-TCP-IP | rfkampig.exe | Added by the GIPMA TROJAN! |
| X | Windows32 | rundll.exe | Added by the AGOBOT-LK or AGOBOT-ND WORMS! |
| X | WindowsAgent | WindowsAgent.exe | Added by the GOP.G WORM! |
| X | WindowsAPI.DLL | Server5.exe | Added by the "Fear and Hope" TROJAN! |
| X | WindowsCriticalUpdate | windows_critical_update.exe | Added by the ASTEF or RESPAN WORMS! |
| X | WindowsKeyUpdate | master.exe | Added by the JOSAM WORM!
|
| X | WindowsMGM | Winmgm32.exe | Added by the SOBIG WORM and LALA.C TROJAN! |
| X | WindowsRegistration | [random filename] | Added by the RBOT-NO WORM!
|
| X | WindowsRegKey Autoupdate | [random filename] | Added by a variant of the RBOT WORM! |
| X | WindowsRegKey upd4te2d4te | *********.exe [* = random char] | Added by the RBOT.XQ WORM! |
| X | WindowsRegKey update | [random filename] | Added by a variant of the RBOT WORM! |
| X | WindowsRegKey%$ update | msi332.exe | Added by the RBOT-IX WORM! |
| X | WindowsRegKey%update | ethernet32m.exe | Added by the RBOT-EN WORM!
|
| X | WindowsRegKeys update | winsysi.exe | Added by the SDBOT.WE WORM! |
| X | WindowsSetup | [path to trojan] | Added by the EZBOT TROJAN! |
| X | WindowsUpd | WindowsUpd4.exe | VirtuMonde adware |
| X | WindowsUpd1 | WindowsUpd1.exe | VirtuMonde adware |
| X | WindowsUpd2 | WindowsUpd2.exe | VirtuMonde adware |
| X | WindowsUpdate | windows_update.exe | Added by the LOFNI WORM! |
| X | WindowsUpdate | svchost.exe | Added by the ASTEF or RESPAN WORMS or AGENT-V TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | windowsupdate | RPCX1sQ3.exe | Added by the IRCBOT.B TROJAN! |
| X | WindowsUpdate | USRINIT.EXE | Added by the MADDIS.B WORM! |
| X | WindowsUpdate Service | wuautlc.exe | Added by the RBOT-NR WORM!
|
| X | WindowsXP Update | windowsxpupdate.exe | Added by the RBOT-PB WORM!
|
| X | Windows_Serivce | SERVICE.exe | Added by the WOOTBOT.AH WORM! |
| X | Windows_Updates | svthost.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows_VXD | user32.exe | Added by the PWSTEAL.PPORT TROJAN! |
| X | Windowz Update V2.0 | Explorer.exe | Added by the YODO WORM! Note - the valid "explorer.exe" is located in C:Windows or C:Winnt whereas this one is located in the System32 sub-directory |
| X | WinDriv32 | WinDriv32.exe | Added by the SMALL-BA TROJAN! |
| X | windrv | windrv32.exe | Added by an unidentified VIRUS, WORM or TROJAN! - possibly a strain of OBLIVION or BIONET |
| X | WinDrv | windrvx.exe | Added by a variant of the TIBSER.A downloader TROJAN! |
| U | WinDSL MTU-Adjust | WinDSL_MTU.exe | Adjusts the registry setting of the DUN-Adapters (MTU) and the TCP/IP-Protocol (RWIN) by ENGEL Technologieberatung |
| ? | WinDSL_MTU | WinDSL_MTU.exe | May be realted to Tiscali broadband, if so is it required? |
| X | WinDSNX | Win????.exe | Added by the DNSX TROJAN! |
| X | WindUpdates | [path to trojan] | Added by the AGENT.BF TROJAN! |
| X | WindUpdates | WinUpdt.exe | BlazeFind "Windupdates" targeted advertizing |
| U | WINDVDpatch | CTHELPER.EXE | CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative?s sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a "leave alone" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it |
| N | WinDVR SchSvr | SchSvr.exe | WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs |
| N | WinDVRCtrl | WinDVRCtrl.exe | Control center software for an AOpen VA1000 TV tuner card |
| X | Windws Configuration Loader | LEXPLORE.exe | Added by the SODABOT WORM! |
| X | WinEssential | Keyhost.exe | Hijacker - hailing from jraun.com |
| X | WinEssential | keyword.exe | Jraun.com hijacker |
| X | WinExec | Winexec.exe.vbs | Added by the AINESEY.A WORM! |
| X | WinExec32 | WinExec32.exe | Added by the KAZWIN WORM! |
| U | WinFast Schedule | Wfwiz.exe | Leadtek WinFast TV tuner scheduler |
| U | Winfast2KLoadDefault | Rundll32.exe Wf2kcpl.dll, DllLoadDefaultSettings | Loads default settings for Leadtek Winfast graphics cards |
| U | Winfast_2K | WF2k.exe | System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card |
| U | WinFast_Gamma | Rundll32.exe wfcpl.dll, DllLoadGammaRampSettings | Loads if you change the gamma settings on Leadtek WinFast graphics cards |
| U | WinFast_Taskbar | rundll32.exe wftask.dll, WFDllLoadDefaultSettings | Loads default settings for Leadtek WinFast graphics cards |
| X | WinFavorites | WinFavorites.exe1 | Loudmarketing.com adware downloader |
| N | WinFax PRO Controller | WFXCTL32.EXE | From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs |
| Y | WinFaxAppPortStarter | wfxsnt40.exe | WinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application. |
| X | winfont | winfont.exe | Added by the DEATH TROJAN! |
| U | WinFoxV2 | WF2k.exe | System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card |
| X | WinFX | cssrs.exe | Added by the AGOBOT.FX WORM! |
| X | WinGate | WinGate.exe | Added by a variant of the LOVGATE WORM! |
| U | WinGate Engine Monitor | wgengmon.exe | WinGate Internet Client Dialup Monitor - component of WinGate proxy server software. Displays the status of the WinGate engine, and appears in the system tray of each workstation on the network reassuring clients that their workstations have connectivity with the WinGate Server
|
| X | WinGate initialize | WinGate.exe | Added by a variant of the LOVGATE WORM! |
| X | wingo | wingo.exe | Added by the BEAGLE.AW or BEAGLE.AV WORMS!
|
| N | WinGuage Pro | WGPRO32.EXE | Part of McAfee Nuts & Bolts. "WinGauge is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious". Resource hog. Available via Start -> Programs |
| Y | Winguard | WGFE95.EXE | Dr Solomon's Virex antivirus |
| U | WinGuard Pro | wgp.exe | Winguard Pro |
| N | WinHacker | rundll32.exe wh95.dll, HackMe | Tweaking utility by Wedge Software. There are far better tweakers and, unlike WinHacker, most are free |
| X | Winhelp | winhe1p.exe | Added by the QQPASS.E TROJAN! |
| X | WinHelp | WinHelp.exe | Added by a variant of the LOVGATE WORM! Note - "winhelp.exe" resides in C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K), or C:WindowsSystem32 (WinXP) whereas the valid "winhelp.exe" resides in C:Windows or C:Winnt |
| X | WinHelp | realsched.exe | Added by a variant of the LOVGATE WORM! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name |
| X | Winhelp | TkBellExe.exe... | Added by a variant of the LOVGATE WORM! |
| X | winhlp3.exe | winhlp3.exe | Added by a variant of the EASTO.A TROJAN! |
| X | Winhlp32 | Wscript.exe ..Msexec32.vbs | Added by the GANT.B WORM! |
| X | winhlp32.exe | winhlp32.exe | Added by a variant of the EASTO.A TROJAN! |
| X | winhlpp32.exe | winhlpp32.exe | Added by the GAOBOT.SY WORM! |
| X | Winhost | wintt.exe | Added by the LOLAWEB.B TROJAN! |
| X | Winhost | win.exe | Added by the DLOADER-AP TROJAN! |
| X | wininet32 | wininet32.exe | Added by the RAZNEW-A TROJAN! |
| X | wininetd | wininetd.exe | Added by the WINET TROJAN! |
| X | wininit | wininit.exe | Added by the WOLLF.16 TROJAN! |
| X | Wink*.exe | Wink*.exe [* = random char] | Added by a variant of the KLEZ WORM! |
| U | Winkb6 | winkb6.exe | Part of We-Blocker, works in tandem with syswb6. Both files are needed to run WeBlocker. Required if We-Blocker is installed |
| X | WinKernel | WinKer.exe | Added by the MIRAB or SERVIDOR TROJANS! |
| X | WinKernel | [path to worm] | Added by the PLEA VIRUS! |
| X | winkernel32 | wWin32.com | Added by the BANSAP TROJAN! |
| U | WinKey | winkey.exe | Loads Copernic's WinKey. Used to map out Windows key hotkey combinations. Not required for the system, but is necessary for this to be running if you use these hotkey combos |
| X | winlibs.exe | winlibs.exe | Added by the EVAMAN.C WORM! |
| X | WinLibUpdate | libupdate.exe | Added by the BIONET series of TROJANS such as BIONET.31 or BIONET.310 |
| X | WinLibUpdate32 | libupdate32.exe | Added by the BIONET.405 TROJAN! |
| X | WinLibUpdte | libupdte.exe | Added by the BIONET.318 TROJAN! |
| X | Winlink | winlink32.exe | Added by the GAOBOT.AAY WORM! |
| X | Winlme | windll.exe | Added by the GOP.F WORM! |
| X | WinLoader | [random filename] | Added by variants of the SUBSEVEN TROJAN! |
| X | winlocatorupdate | updatewinlocator.exe | Locator adult content toolbar related |
| X | WinLogin | winlogin.exe | Added by the AGOBOT-IX WORM!
|
| X | Winlogin.exe | log.exe | Added by a variant of the AGENT.AH downloader TROJAN! |
| X | winlogin.exe | logfile.exe | Added by the AGENT.AH TROJAN! |
| Y | winlogon | winlogon.exe | Windows Logon Process - handles user logons described here |
| X | winlogon | winlogon.exe | Hijacker or adult content dialler - file is located in C:Windows or C:Winnt, and not in it's System or System32 subdirectory, as is the case with the legitimate Windows Logon (winlogon.exe) process |
| X | winlogon | winlogin.exe | Added by the RANDEX.E WORM! |
| X | winlogon | winlogon.exe | Added by the TRODAL TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! File is located in C:Windows or C:Winnt, and not in it's System or System32 subdirectory |
| X | Winlogon.exe | N/A | CoolWebSearch parasite related - resets home page to an adult material site |
| X | WinLsass | servicec.exe | Added by the SCANE WORM! |
| X | WinLsass | [path to trojan] | Added by the SCANE WORM! |
| X | winltmpv | winln.exe | Added by the TCXMEDI-C TROJAN! |
| X | winltmpv | wutop.exe | Added by the TCXMEDI-C TROJAN! |
| X | Winmain | winmain.exe | One of the first of a new breed of malware. When run it immediately loads MSHTA.EXE from the Windows folder, placing it on "hot standby", ready to accept HTA scripting within a web page and then EXECUTE what is embedded IN the page as a program! In other words, it's possible for a "rogue" website to actually embed trojans, worms and/or viruses directly into a web page. BOClean's HTA Stop offers an easy way to toggle this capabiltity, or rather vulnerability, on and off. I suggest you leave it disabled! |
| ? | WinManager | schost.exe | ?? |
| U | winmatrix.exe | WinMatrixXP.exe | WinMatrix XP - wallpaper replacement that shows different matrix effects (including flowing matrix codes from 'The Matrix' movie) on your desktop |
| U | WinMem | WinMem.exe | WinMem Cleaner - part of Ultra WinCleaner Utility Suite. Makes more memory available for your programs and the Operating System. It also defragments your system
|
| X | WinMenssage | winmax.exe | Added by the BANCOS.B TROJAN! |
| N | WinMgmt | WinMgmt.exe | Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here |
| X | WinMgr32 | winmgr32.exe | Added by the MIMAIL.P WORM! |
| X | WinMine | D4NG3.vbs | Added by the BISCUIT.A WORM! |
| Y | winmodem | wmexe.exe | Software for software based modems. Required if you have one of these. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information |
| X | WinMsrv32 | WinMsrv32.exe | Added by the GAOBOT.AFJ WORM! |
| N | winmysqladmin | winmysqladmin.exe | Starts the MySQL database admin tool |
| N | WinMySQLadmin Tool | winmysqladmin.exe | Starts the MySQL database admin tool |
| X | winnet | winnet.exe | CommonName Toolbar spyware. To uninstall see here |
| ? | Winnov Menu | WnvMenu.Exe | Winnov Video Capture Card related. What does it do and is it required? |
| ? | Winnov Remote | WnvRsvr.Exe | Winnov Video Capture Card related. What does it do and is it required? |
| ? | Winnov Status | WvStatus.Exe | Winnov Video Capture Card related. What does it do and is it required? |
| X | WinNtBB | WinntBB.exe | Added by the DULOAD.C WORM! |
| X | winocx32 | winocx32.exe | Added by the PROTORIDE.I WORM!
|
| U | WinPatrol | WinPatrol.exe | WinPatrol - "Manage Startup programs, tasks, cookies; will sniff out Worms, Trojan horses, Cookies, Adware, Spyware, Klez, Assumption and other malicious programs" |
| X | winphonics7536 | vbsystem35.exe setups.exe vb.vb | Added by a variant of the MUTIN-C TROJAN! |
| Y | WinPoet | WinPPPoverEthernet.exe | WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking |
| N | WinPopup | WINPOPUP.EXE | Intranet chat software provided by windows for chat on small networks. Handy little LAN messaging utility. Has been included in Windows since 95, and maybe in WFWG 3.11. Normally it won't set itself up to run unless the user specifically adds it to startup |
| X | winpopup | winupie.exe | Adware by Tradeexit.com |
| X | WinProfile | Command.exe | Added by the BUDDY TROJAN! |
| X | WinProfile | sndcfg16.exe | Added by the SNDC.A WORM! |
| X | WinProt | Winprot.exe | Added by the CHUPACABRA TROJAN! |
| X | WinProt | server.exe | Added by the CHUPACABRA TROJAN! |
| U | WinProxy | WinProxy.EXE | "WinProxy is the world-first proxy server and a firewall with integrated mail server for Windows 95/98/ME/NT/2000/XP" |
| X | winpsd | winpsd.exe | Added by the MYDOOM.Q WORM! |
| X | winrar | winrar.exe | CoolWebSearch parasite variant. Note - this is not the file zipping utility also known as WinRAR and it's located in C:Winnt or C:Windows |
| X | winrarshell | winrarshell32.exe | Added by the SALIRA TROJAN! |
| X | winReg | winReg.exe | Added by the YAHA.H or YAHA.J WORMS! |
| X | winregsrv | winregsrv.exe | Added by the SYNRG TROJAN! |
| X | Winres32vis | [path to worm] | Added by the THRAX.A WORM! |
| N | winroute | winroute.exe | Win-Route 4.27. WinRoute Tray Icon for starting and stopping the WrCtrl.exe process, also to log in to the console to view logs and change settings. Can be unchecked and the engine still runs and functions normally. Can then use provided shortcuts for administration of the program. Loaded in SERVICES on Windows 2k |
| X | winrun | msconfig.exe | Added by the WINUR.A WORM! Note - this is not the real msconfig.exe as it's located in C:winrun |
| X | winrun | winrun.exe | Added by the WINBUR.B WORM!
|
| X | WinRunners | WinDrivers.exe | Added by the DULOAD.C WORM! |
| X | winsecure | winsecure.exe | Browser hijacker, redirecting to specificsearches.com |
| X | winserver | Server.txt.vbs | Added by the DELTAD.A WORM! |
| U | WinService32 | ssmgr.exe | 007 Spy Software - "stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP" |
| X | WinServices | WinServices.exe | Added by the YAHA.K or YAHA.M WORMS! |
| X | winservn | winservn.exe | PurityScan/Clickspring adware |
| X | winservs | winservs.exe | PurityScan/Clickspring adware |
| X | WinSetBrowse | BasicUpdate.dll.vbs | Added by the BISCUIT.A WORM! |
| ? | Winshoe | wuadfdqr.exe | Probably an unidentified VIRUS! Adds itself to 3 registry "Run" keys and prevents Task Manager being displayed. This is not the Winshoe IRC Client as the visitor did not have it installed |
| X | WinShowUpdate | copy C:WINDOWSwinshow.new C:WINDOWSwinshow.dll | Winshow parasiate related - from the "RunOnce" keys it replaces "winshow.dll" with a new version |
| X | WinSig | NetXP.exe | Added by the BANKER-FN TROJAN! |
| X | Winsock2 driver | SDJOIJE.EXE | Added by the SPYBOT.DR TROJAN! |
| X | Winsock2 driver | MIRC32.exe | Added by the SPYBUZZ TROJAN! |
| X | Winsock2 driver | kgzgjkpcw.exe | Added by the SDBOT.T TROJAN! |
| X | Winsock2 driver | ZONEALARM.EXE | Added by the SDBOT.T TROJAN! Note - ZONEALARM.EXE is not the valid Zone Labs firewall program |
| X | Winsock2 driver | WINCFG.SCR | Added by a variant of the SPYBOT WORM! |
| X | Winsock2 driver | winupdate.exe | Added by the SPYBOT-BX WORM! |
| X | Winsock2 driver | SPOLSV.EXE | Added by the SPYBOT-CM WORM!
|
| X | Winsock2 driver | Zonealarmupdate.exe | Added by a variant of the SPYBOT WORM!
|
| X | Winsock2.dll | WINLODR.SCR | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Winsock32 driver | Testing.exe | Added by the SPYBOT.B WORM! |
| X | Winsock32 driver | lcd.exe | Added by the SPYBOT.B WORM! |
| X | Winsock32 driver | Sdjoije.exe | Added by the SPYBOT.B WORM! |
| X | Winsock32driver | win32server.scr | Added by the HACARMY TROJAN! |
| X | Winsock32driver | sp2XPupdate.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Winsock32driver | win32server.exe | Added by the BACKDOOR-AZV TROJAN! |
| X | Winsock32driver | ZoneAlarmPr0.exe | Added by the HACKARMY-B TROJAN! |
| X | Winsock32driver | ZoneLockup.exe | Added by the HACARMY.D TROJAN! |
| X | Winsock32driver | win32server.exe | Added by the HACARMY.F TROJAN!
|
| X | Winsock32driver | winXPupdate.exe | Added by the HACKARMY.9728 TROJAN! |
| X | winsockdriver | tskmg.exe | Added by the SDBOT.GEN TROJAN or WARPIGS.C WORM! |
| X | winsockdriver | winsock2.2.exe | Added by a variant of the SPYBOT WORM! |
| X | WinSocketComponent | nthost.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | WinSPF | windrv32.exe | Added by the MYDOOM.T WORM! |
| X | WinSPF | winspf32.exe | Added by the MYDOOM.S WORM! |
| X | WinSrv | kn0x.exe | Added by the HOBBIT.F WORM! |
| X | WinSrv | SHIZZLE.EXE | Added by the HOBBIT.C WORM! |
| X | Winsrv | winsrv.exe | Added by the OPASERV.T WORM! |
| X | WinStart | WinStart.exe | From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge |
| X | WinStart | Wscript.exe WinStart.vbs | Added by the CIAN.C WORM! |
| X | WinStart | winstart32.exe | Added by the PUROL WORM! |
| X | WinStart | WinStart.pif | Added by the CONE.E WORM! |
| X | WinStart001 | WinStart001.exe | From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge |
| X | WinStart001.EXE | WinStart001.exe | From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge |
| X | Winsta~1 | winsta~1.exe | GoHip foistware |
| X | WinSth16 | WinSth16.exe | Added by the CAKE WORM! |
| X | winstro | RUN32DLL.exe | Added by the FTP_ANA TROJAN! |
| X | Winsvc32 | Winsvc32.exe | Homepage hijacker |
| U | Winsys | Winsys.exe | Win-Spy - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
| X | WINSYS | [path to trojan] | Added by the GOLDPLAY TROJAN! |
| X | WinSys32 | Winsys32.exe | Added by the CIGIVIP TROJAN or RECKUS WORM! |
| X | winsys32 Driver | winsys32.exe | Added by the LOONY-O TROJAN! |
| U | WinSysAppMon | WinSysRM.exe | Home & Family Content Filter related. See here |
| X | winsyslog lptt01
| winsyslog.exe | Variant of the RapidBlaster parasite (in a "Winsyslog" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | WinSysStartUpWKbLw | TaskSystemDll.Exe | Added by the BACKZAT.G WORM! |
| X | WinSyst32 | winsyst32.exe | Added by the MORB WORM! |
| X | WinSystem | winsystem.exe | Added by the WHITEBAIT WORM! |
| X | Winsystem | winsystem.exe | Added by the BANCOS.CR TROJAN! |
| X | WinTask | Wintask.exe | Added by the HIPO or LEMIR.F TROJANS! |
| X | WinTask driver | wintask.exe | Added by the SMALL.ABD downloader TROJAN! |
| U | WinTasks Traybar | wintasks.exe | WinTasks - "Efficient Resource and Task Management is absolutely critical if you want to achieve the highest system performance levels possible. WinTasks 4 will not only help you achieve this task, but will actually make your system run faster and more smoothly than ever before" |
| X | wintasks.exe | wintasks.exe | Added by the EVAMAN WORM! |
| N | Wintercooler Pro | WINCOOL.EXE | Wintercooler Pro - utility that monitors CPU usage, RAM consumption and Internet connection speed |
| N | WinTidy | WinTidy.exe | Desktop icon manager from PC Magazine (Ziff-Davis) for Win95. Available via Start -> Programs |
| X | Wintime | Wintime.exe | Added by the HARNIG TROJAN! |
| N | Wintime Wtxpload | Wxpload.exe Wintime | Part of the software to support a Dexxa USB graphics tablet. From a visitor - "This gets started anyway when you plug in the USB connector for the graphics tablet, if it's not already running. It then starts an application which manages the tablet messages. Since I leave the tablet unplugged unless I need to use it, I don't need this running at startup. I suspect that this program monitors a number of windows messages, so that when it's loaded, my regular mouse slows down - it acts like it 'sticks' entering and leaving windows. Certainly my performance returned to what I expected when I removed this item using MSCONFIG" |
| X | WinTools | WToolsA.exe | Wintools adware |
| N | WinTOTAL Scheduler | guru.exe | WinTOTAL Real estate appraisal software related |
| X | WinTray | wintray.exe | Added by the LEGUARDIEN.B TROJAN! |
| X | winupd | RUNDLL32.EXE [random value].dll, _mainRD | Added by the MOTA.A WORM! |
| X | winupd.exe | winupd.exe | Added by the BEAGLE.M or BEAGLE.N WORMS! |
| X | WinUPD32 | explorer.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | winupdat | winupdat.exe | Added by the CANBOT.A WORM! |
| X | WinUpdate | RBSKQQBO.EXE | Added by the VBSWG2B.A WORM! |
| X | WinUpdate | wmbem.exe | Added by the REVCUSS.B TROJAN! |
| X | WinUpdate Loader | msnnm.exe | Added by the REVCUSS.C TROJAN! |
| X | winupdate.exe | winupdate.exe | Added by the RADO TROJAN! |
| X | winupdate.reg | winupdate.exe | Added by the SPYBOT.EAS WORM!
|
| X | winupdate2846 | vbsystem35.exe msvbrun.exe | Added by a variant of the MUTIN-C TROJAN! |
| X | winupdt | RUNDLL32.EXE [random.dll] | Added by the MABUT.A WORM! |
| X | winupdtl | winupdtl.exe | SecondThought adware variant
|
| X | winur | winrun.exe | Added by the WINBUR.B WORM!
|
| X | Winux Piriax Service | PH32.EXE | Added by the RANDEX.G WORM! |
| X | winversion | winversion.exe | Browser hijacker, redirecting to specificsearches.com |
| U | WinVNC | WinVNC.exe | WinVNC is an application that allows you to remote control your PC from another PC somewhere on the internet |
| X | WinVNC | iexplorer.exe | Added by the EVIVINC VIRUS! |
| X | winwan lptt01 | winwan.exe | Variant of the RapidBlaster parasite (in a "Winwan" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | winwan ml097e | winwan.exe | Variant of the RapidBlaster parasite (in a "Winwan" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | winXP | 33.exe | Added by the ANPES WORM!
|
| X | WinXP | plugin1.exe | Added by the Downloader-JW TROJAN!
|
| X | winxpdll32.exe | winxpdll32.exe | Added by a variant of the SMALL downloader TROJAN! |
| U | WinXPLoad | Rundll32 LoadDll, LoadExe WinXPLoad.exe | Compaq hotkey related - required if you use the hotkeys |
| X | winzip | [path to trojan] | Added by the BANCOS.G or BANCOS.K TROJANS! |
| N | WinZip Quick Pick | WZQKPICK.EXE | Added with WinZip version 8.1. "The new WinZip Quick Pick taskbar tray icon gives you instant access to WinZip and your Zip files. Just left click the icon to open WinZip, or right click it to instantly reopen recently used Zip files, access your Favorite Zip Folders, open WinZip Help, or start WinZip itself.". You can right-click and close it - choosing to not re-load it at start-up |
| X | Win_api_driver | system.exe | Added by the REVIRD TROJAN! |
| X | Win_Library | INISvc.exe | Added by the ANARCH WORM! |
| X | win_upd.exe | WINdirect.exe | Added by the MITGLIEDER.M TROJAN! |
| X | win_upd2.exe | WINdirect.exe | Added by the BEAGLE.AO WORM! |
| X | Win_vader | Win_vader.vbs | Added by the INVASION.A VIRUS! |
| X | WIP Config GUI | Winipcfgs.exe | Added by the RBOT-CN WORM! |
| U | Wireless PCI Card Configuration Utility | WMP11Cfg.exe | Utility used by the LINKSYS wireless PCI card (WMP11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration |
| X | Wireless Provider Server | wpsvr.exe | Added by the FORBOT-AD WORM! |
| U | Wireless-G Notebook Adapter Utility | WPC54CFG.EXE | Utility used by the LINKSYS Wireless-G Notebook Adapter (WPC54G) |
| N | wjview | wjview.exe | MS tool used to view window-based Java applications from the command line |
| N | wkcalrem | wkcalrem.exe | Produces a pop-up reminder of events scheduled using the MS Works Calendar |
| N | WkDetect | WkDetect.exe | Checks for updates to MS Works |
| N | wkfud | wkfud.exe | A marketing program for MS Works |
| N | WksSb | WksSb.exe | The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program. The Works Portfolio provides a location where you can store items you want to later put into a document or other file |
| N | WkUFind | WkUFind.exe | MS Works Update Detection. MS Picture It! (versions 7 to current) use this automatic update feature during the log on process. It can also cause your system to automatically dial into your ISP as it tries to access the internet, if you have your system set to automatically dial when the internet is invoked. To manually update, go to Microsoft's Office/Works update site |
| X | Wlan Drier | Winusb2.exe | Added by the WOOTBOT.DC WORM! |
| X | Wlan Driver | avscan.exe | Added by the WOOTBOT.DH WORM! |
| N | WLAN Status Tray Applet | WLANSTA.EXE | System Tray icon for checking the status of a Wireless LAN |
| Y | WLAN_Cfg.exe | WLAN_Cfg.exe | Linksys Instant Wireless USB Network Adapter driver |
| X | wm41a398 | rundll32.exe [path] wm41a398.dll, EnableRunDLL32 | LZIO.com adware downloader |
| X | WMAudio | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | WMAudio | winlogon.exe | Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
| N | WMBoot | N/A | Associated with Logitech Wingman game controllers. Not required but what does it do? |
| U | WMIEXE.exe | wmiexe.exe | NT component, used by Windows Millennium to detect Plug and Play-compliant IEEE 1394 devices during the startup process. Since this is important for the computer to work properly if you have these, Windows Millennium protects wmiexe.exe and will restore the file even if it's deleted or renamed. Check here for some details on what to do to stop it loading |
| X | Wminf | Wminf.exe | Added by the GEMA TROJAN! |
| X | Wminfo | Wminfo.exe | Added by the GEMA TROJAN! |
| X | wmiprv | wmiprv.exe | Added by the RBOT-WM WORM! |
| Y | WMP54Gv4 | WMP54Gv4.exe | Linksys WMP54G Wireless-G PCI Adapter driver |
| X | wmsys32 | wmsys32.exe | Added by the BANPAES.B TROJAN! |
| ? | WM_LOGIN | MSGLOGIN.EXE | Part of McAfee Firewall. What is it for and is it needed? |
| X | WNAD | WNAD.EXE | Spyware added as a result of running a program called "Yo Mama Osama" (osama.exe). See here for more and how to get rid of it. There are other ways this can show up on your system, and it will manifest itself by periodically opening a new browser window with advertising for copy DVD software and the like |
| X | WNSC | wns*****.exe [* = random char] | PurityScan/Clickspring adware |
| U | WNSI | wnscp**.exe [* = random char] | PurityScan/Clickspring adware |
| X | WNSI | wnscpsu.exe | PurityScan/Clickspring adware |
| X | WNSI | wnscpsv.exe | PurityScan/Clickspring adware |
| X | WNST | wns*****.exe [* = random char] | PurityScan/Clickspring adware |
| N | Woowatch | Watch.exe | Wanadoo ISP software, not required |
| N | WordWeb | wweb32.exe | WordWeb - free theasaurus and dictionary. Start manually |
| ? | Workflo | workflow.exe | Related to BroadJump Client Foundation - broadband troubleshooting software installed by various companies. Is it required? |
| N | Works Calendar Reminder | wkcalrem.exe | Produces a pop-up reminder of events scheduled using the MS Works Calendar |
| N | WorksFUD | wkfud.exe | A marketing program for MS Works |
| U | Workstation Scheduler | wm95.exe | Desktop Management Scheduler. Part of Novell's Netware Client. Schedueles NDS events. If events have been schedueled, it is required, otherwise, it is useless and a memory hog |
| X | Workstation Services | wrkstn.exe | Added by the RBOT-OJ WORM!
|
| U | Worm Detector | wd.exe | Worm Detector - antivirus add-on for Outlook 2K or XP for handling worms and spam |
| X | wormexe | winstart.exe | Added by the EARLYBIRD WORM! |
| X | wovax | wovax.exe | Added by the DAQA.A TROJAN! |
| N | Wpctrl | wpctrlnt.exe | WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
| N | Wpctrl | wpctrl95.exe | WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
| N | wpctrl95 | wpctrlnt.exe | WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
| N | wpctrl95 | wpctrl95.exe | WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
| Y | WPCycle.exe | WpCycleWin.exe | Added when selecting Mplayer2 to open media files. Forces other codes to Wait for Previous instructions to end, preventing instability of your CPU (freezing) |
| X | wpds.exe | doriot.exe | Added by the SMALL-KY TROJAN!
|
| X | WQK | WQK.exe | Added by a variant of the KLEZ WORM! |
| ? | wr | WR.EXE | ?? |
| ? | WR Command | wr.exe | ?? |
| N | WrCtrl | WrCtrl.exe | Win-Route 4.27 NAT engine on Win2k Pro for connection sharing and security using Win-Route by Tiny Software. A connection sharing/Firewall Application. If service is disabled the program does not work, but you can manually start/stop the service with a shortcut the program installs at any time |
| X | WRDialer | WrDialer.exe | WinPoet DSL dialler |
| ? | WRECK GUARD | ?? | ?? |
| ? | WregBios | wregbios.exe | Desktop Management BIOS (DMI BIOS) related. Apparently invokes the DosBios.exe file. Is it required? |
| U | wrexec | wrexec.exe | Watch Right - monitoring program, part of the PowerTools add-on for AOL. Records instant messages, E-mail, chat. Watch Right appears to be, and functions as an online clock updater which connects with the U.S. National Institute of Standards and Technology. It was designed for parents who wish to keep an eye on what their children are doing online |
| ? | wriste | wriste.exe | ?? |
| X | ws2help | ws2help.exe | Added by a variant of the SMALL.AN TROJAN!
|
| X | WSAConfiguration | wmon32.exe | Added by the GAOBOT.BAJ WORM! |
| X | WSAConfiguration | svchostt.exe | Added by the AGOBOT.ZT WORM! |
| X | WSAConfiguration | rpcxmn32.exe | Added by the AGOBOT.ABG WORM! |
| ? | wsbklite | wsbklite.exe | Related to the Acer Soft Button on Acer Tablet PCs. Appears to do nothing so is it required? |
| U | WScheduler | WScheduler.exe | Windows Scheduler - "schedule unattended running of applications, batch files, scripts and much more. Also, you can schedule popup reminders so you'll never forget reminders, tasks and other events." |
| X | wscript.exe | vabian.vbs | Added by the VABI VIRUS! |
| X | wserver | wserver.exe | Added by the NETSKY.AC or SASSER.G WORMS! |
| U | WService | WService.exe | Tablet client Driver for UC-Logic Pen/Graphics Tablet |
| X | WSSAConfiguration | wmmon32.exe | Added by the AGOBOT-KC WORM! |
| X | Wstat32 driver | Wstat32.exe | Added by the LOONBOT TROJAN! |
| Y | wstimeb | wstimeb.exe | Used with NEC printers. You can disable it before printing but it re-loads itself when printing so you may as well leave it |
| Y | wswpd | wswpd.exe | Used with some models of Panasonic, Epson and NEC printers. Some older drivers known to have a "memory leak". Needed for printing to work |
| N | WT Game Channel | GameChannel.exe | WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| N | WT Game Channel | wtgamechannel.exe | WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| N | WT GameChannel | GameChannel.exe | WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| N | WT GameChannel | wtgamechannel.exe | WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| U | WTIndicator | SchedInd.exe | WinTask - software that automates a variety of routine tasks quickly and simply |
| X | WTSI | wapisvit.exe | PurityScan/Clickspring adware |
| X | WTSS | wap***.exe [* = random char] | PurityScan/Clickspring adware |
| X | WTSS | wapicc.exe | PurityScan/Clickspring adware |
| X | WTSS | wapiit.exe | PurityScan/Clickspring adware |
| X | WTSS | wapisu.exe | PurityScan/Clickspring adware |
| X | WTSS | wapisvsu.exe | PurityScan/Clickspring adware |
| X | WTST | wapisvtr.exe | PurityScan/Clickspring adware |
| Y | WUOLService | WUOLService9x.exe | Remote wakeup status agent. Part of Novell's ZenWorks. Processes Wake-up on LAN requests (turn on a computer remotely on LAN) |
| X | WUPD | iglmtray.exe | Added by the TZET WORM! |
| X | wupdt | wupdt.exe | Added by the IMISERV.A TROJAN! |
| Y | WUSB11B.exe | WUSB11B.exe | Linksys WUSB11 WLAN USB adapter |
| ? | WUx_RegSvr | RegSvr32.exe | x is any number?? |
| X | wvsvc | wvsvc.exe | Added by the AGOBOT.YM WORM! |
| X | www.hidro.4t.com | enbiei.exe | Added by the BLASTER.F WORM! |
| X | www.symantec.com | oz11111.exe | Added by the MYDOOM.W WORM |
| N | WXProcMgr Module | WXprocMgr.exe | TVTonic from Wavexpress - "enjoy 3 full-screen, DVD-quality video channels for FREE". Allows data content to be downloaded and synchronized on your system |
| X | wzhelper | wzhelper.exe | Searchcentrix hijacker |
| X | w32 | w32.exe | Added by the SOKEVEN TROJAN! |
| X | W32.Scran | Scran.exe | Added by the NARCS WORM!
|
| X | w32alanis | mope.scr | Added by the SINALA WORM! |
| X | W32Load | [random filename].scr | Added by the CASPID WORM! |
| X | w32sup | w32sup.exe | Adult content dialler |
| X | W32Tc | WTC32.scr | Added by the VOTE.D or VOTE.K WORMS! |
| X | W3KNetwork | rundll32.exe w3knet.dll, dllinitrun | Advertising spyware. Check here for more info on this particular one |
| Y | W75P2PSERVER | W75P2PS.EXE | Printer utility which is required in order to make the printer work correctly |
| ? | W815DM | W815DM.exe | ?? |
| N | Wanadoo Messenger.exe | Wanadoo Messenger.exe | Wanadoo ISP instant messenger client |
| Y | WanMPSvc | WanMPSvc.exe | An AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling AOL doesn?t help |
| X | WAPI | wts**.exe [* = random char] | PurityScan/Clickspring adware
|
| N | war-ftpd.exe | WAR-FTPD.EXE | War FTP Daemon from JGAA's Internet - FTP client |
| X | Wardo | syslaunch.exe | Added by the ADLCICKER.G TROJAN! |
| N | warez | warez.exe | Warez P2P client |
| U | Warner | warner.exe | Also known as "CyberWarner". From G-Tek Technologies and pre-installed on some Packard Bell PCs. Protects critical files |
| U | Warnet | warnet.exe | Warnet - system cleanup software |
| U | Warning: do not remove it! | fpplock.exe | Part of Folder Password Expert by ZQS Software Team - "a software program to restrict access to the folders that contain your sensitive data" |
| N | WARSVR | war-ftpd.exe | "War FTP Daemon - the original free FTP server for windows" |
| U | WashAndGo - Cleanup of old Backupfiles | checker.exe | WashAndGo - temp file cleaner |
| U | Washer | washer.exe | Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
| N | Washerie.exe | washerie.exe | Cookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer, specific for cleaning the IE cache and cookies. Available via Start -> Programs |
| U | washindex | washidx.exe | Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
| X | Wast | wast.exe | Grokster ads updater |
| N | Watch | watch.exe | Found to be used by a Trust USB scanner for auto starting the scanning software when the lid is lifted |
| ? | Watch | 1200UBWATCH.EXE | ?? |
| N | Watch Dog Program | watchdog.exe | For Compaq PC's. Associated with Compaq's internet services. Not required if you don't use services provided by them and may not be required even if you do |
| N | Watchdog | Watchdog.exe | Definitely part of the Mustek scanner drivers and software (for 600 III EP Plus and maybe others), launches from the Startup folder in the Start Menu, but not required as they give instructions on removing it on their webpage |
| N | WaveTop Launcher | WaveTop.exe | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
| N | WaveTop Receiver 1 | N/A | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
| N | WaveTop Receiver 2 | N/A | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
| N | WaveTop Upload Manager | N/A | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
| N | Wbiff | Wbiff.exe | Wbiff! E-mail checker - automatically checks your e-mail and notifies you if any new e-mail has been received |
| ? | Wbutton | Wbutton.exe | Related to the Wacom Penabled driver on Acer Tablet PCs. Appears to do nothing so is it required? |
| N | WCESCOMM | WCESCOMM.EXE | Active sync for use with Windows CE based palm PC |
| U | wcmdmgr | wcmdmgrl.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
|
| N | wcmdmgr.exe | wcmdmgr.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| U | wcmdmgrl | wcmdmgrl.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| U | WCOLOREAL | coloreal.exe | Makes colours sharper and brighter, but will only work with coloreal capable monitors |
| ? | WCPC | wintsvcc.exe | ?? |
| X | WCPI | wintsvit.exe | PurityScan/Clickspring adware |
| X | WCPS | Wint**.exe [* = random char] | PurityScan/Clickspring adware
|
| X | WCPT | wintsvtr.exe | PurityScan/Clickspring adware |
| U | WD Button Manager | WDBtnMgr.exe | Button manager installed with a western digital external disk drive. Allows you to back up your system with one click
|
| X | WDInfo | wdinfo.exe | Adult content dialler |
| X | wdskctl | wdskctl.exe | IEPlugin spyware
|
| X | wdwctrl | wdwctrl.exe | Added by the DLUCA.E TROJAN! |
| N | WEATHER | WEATHER.EXE | Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs |
| N | WeatherCast | Weather.exe | Weather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight |
| X | WeatherOnTray | WeatherOnTray.exe | Hotbar's Weather Forecast tool for your desktop - adware |
| N | WeatherWatcher | ww.exe | WeatherWatcher - weather reporting in the System Tray |
| X | web | ******.exe [* = random char] | Added by a variant of the EASTO.A TROJAN! |
| ? | Web Search | ?? | ?? |
| Y | web3trap | web3trap.exe | PC-Cillin 2000 anti-virus software -> ActiveX filter. Guards against malicious ActiveX programs, etc |
| X | webalize | webalize.exe | Searchcentrix hijacker |
| N | WebArmyKnife | WAK.exe | Web Army Knife - a suite of web site developer's tools |
| X | webassist | webassist.exe | Adware popup generator |
| ? | Webcam Go Sti Service Application | wbcgosvc.exe | Control software for the portable Creative Video Blaster Webcam Go digital camera/PC web cam. What does it do and is it required? |
| N | WebcamRT.exe | WEBCAMRT.exe | For Logitech Web Cams. Not required - camera works fine without it |
| X | Webcelerator | webcel.exe | Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Spyware and troublesome - see here |
| X | WebCheck | WebCheck.pif | Added by the CONE.C or CONE.F WORMS! |
| X | WebCpr0 | WebCpr0.exe | Web_CPR/TopMoxie adware |
| X | Webdav.exe | webdav.exe | IRC DDoS bot which gives the hacker full control over your system |
| X | WebHancer Agent | whagent.exe | System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here |
| X | webHancer Survey Companion | whSurvey.exe | WebHancer foistware - traffic measurement service that uses a client agent that is stealth installed on user machines, gathering detailed data about sites visited, their performance and, most important, what the user actually does while there |
| X | WebInstall | WebInstall.exe | ClipGenie adware downloader |
| X | WebInstall2 | WebInstall.exe | ClipGenie adware downloader |
| N | WebKey | WebKey.exe | WebKey from JB Utilities. Utility to keep track of login data required when browsing the internet |
| N | WebOutfitterTray | sttray.exe | Intel WebOutfitter service System Tray icon |
| N | Webposition Gold 2 | wpsche~1.exe | Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines |
| X | WebRebates0 | WebRebates0.exe | WebRebates adware |
| U | websaverlive | websaverlive.exe | WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your computer is idle |
| X | WebSavingsfromEbates | WebSavingsfromEbatesrun.exe | Web Savings From Ebates Software, a shopping tool that opens pop-up windows |
| X | WebSavingsFromEbates0 | WebSavingsFromEbates0.exe | Web Savings From Ebates Software, a shopping tool that opens pop-up windows
|
| X | WebScan | DEFSCANGUI.EXE | Stop-Sign from eAccelerration. Detects spyware, malware, viruses and keyloggers and stops popups. Spyware in itself - see their privacy statement here |
| N | webscan | stopsignav.exe | eAcceleration Stop-Sign related - not recommended, see note |
| Y | WebScanX | WebScanX.exe | From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc |
| X | websearch | wjview ...websearch.exe | "Web Savings" From Ebates Software, a shopping tool that opens pop-up windows |
| X | WebSecureAlert | WebSecureAlert.exe | WebSecureAlert. "Can help protect your browser security and privacy". However, it's by GAIN Publishing, and will display pop up ads on your computer screen based on your online Web surfing behavior |
| ? | WebServer | VBI_SE~1.EXE | Related to a Pinnacle sound card. What does it do and is it needed? |
| N | Webshots | Webshots Tray.exe | Screensaver program that automatically downloads from the webshots web site |
| N | Webshots | websho~1.exe | Screensaver program that automatically downloads from the webshots web site |
| X | WebSpecials | rundll32 [path] webspec.dll | WebSpecials spyware
|
| X | Websx | Int*****.exe | Adult content dialler - where ***** are random |
| Y | Webtrap | webtrap.exe | Part of PC-Cillin anti-virus software. Checks web-sites for malicious Java and ActiveX elements in a similar way to McAfee WebScanX. A few users find it infuriating |
| Y | WebTrapNT.exe | WebTrapNT.exe | Part of PC-Cillin Anti-Virus software. Checks visited web-sites for malicious Java and ActiveX elements |
| U | WebWasher | wwasher.exe | Free Pop-up/ad/javascript filter program from Siemens. If not running then browsers will not be protected but will still work. Available via Start -> Programs |
| N | Welcome | Welcome.exe | Launches the Welcome to Windows tutorial on boot up |
| ? | WEPstat | Wepstat.exe | Cisco Aironet 340 Series PC Card driver. If it can be started manually it shouldn't be required if you don't use the PC card facility regularily - hence the status could be "U". Can anybody confirm this? |
| X | wersds | doriot.exe | Added by the JECT.C TROJAN! |
| N | WetSock | wetsock.exe | RoboMagic Wetsock - weather reporting in the System Tray |
| N | WFGStartup | WFGStartup.exe | World Weather. "This midlet displays the current weather conditions for major cities around the world. This version is for memory limited mobile phones" |
| U | wfips | iphider.exe | ICQ (messaging/chat program) anti-bomb software. "WFIPS is anti-bomb software for safeguarding ICQ Bomb before the bombing. 'ICQ Defoolder' is a tool for removing ICQ bomb after being exposed." For more information about ICQ bombs see here |
| N | WFXCTL32.EXE | WFXCTL32.EXE | From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs |
| Y | wfxsnt40 | wfxsnt40.exe | WinFax 10.0 and maybe earlier versions. The program that opens the port for WinFax and not normally in the start menu. Needed if you want to run WinFax |
| ? | WFXSwtch | WFXSWTCH.exe | Related to WinFax. What does it do and is it required? |
| Y | WG511WLU | WG511WLU.exe | Netgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card
|
| U | WGWLocalManager | WGWLocalManager.exe | Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so. It could be started by creating a shortcut, running it only when connecting to the internet. If internet is used often, it's recommended to leave it in startup so it starts with the system |
| X | whagent | whagent.exe | System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here |
| U | WheelMouse | 4DMAIN.EXE | Mouse software for "Fellowes" Wheelman mouse. Has caused some users problems but shouldn't be needed if you don't use any enhanced features it may provide |
| U | WheelMouse | AMOUMAIN.EXE | A4Tech wireless mouse driver and utility - required if you use non-standard Windows driver features |
| X | WhenUSave | Save.exe | Rebranded version of SaveNow advertising spyware |
| X | WhenUSearch | Search.exe | WhenUSearch adware |
| X | Whvlxd | Whvlxd.exe | Added by the W32.LXD.MIRC TROJAN! |
| N | WIAWizardMenu | RUNDLL32.EXE sti_ci.dll, WiaCreateWizardMenu | Still Image Class Installer - installed with a webcam |
| ? | WildTangent CDA | RUNDLL32.exe cdaEngine0400.dll,cdaEngineMain | Part of the WildTangent on-line games system. What does it do and is it required? |
| U | WildTangent Web Driver updater | wcmdmgrl.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| N | Wildwire Monitor | WWMon.exe | This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem |
| N | Willow Road | WillowRoad.exe | Willow Road Screen Saver |
| X | win | regedit -s ..win.dll | Added by the SEEKER.K TROJAN! |
| X | win | xwinxrpc32.exe | Added by the AGOBOT-MV WORM! |
| U | Win Chimes | winchi~1.exe | WinChimes - enhancement software for the system clock that runs in the system tray |
| X | Win Comm | WinComm.exe | WebRebates related adware
|
| X | Win Command | command32.exe | Added by the AGOBOT.XQ WORM! |
| X | Win Command | command32.exe | Added by the AGOBOT.XQ WORM! |
| X | WIN HOST PROCESS | WIN HOST PROCESS.EXE | Added by the KEYLOGGER.CLONE TROJAN! |
| X | Win l5oahder | winampa.exe | Added by the SPYBOTER.GEN VIRUS! Not the valid Winamp Agent which uses the same filename. This resides in the System32 sub-folder wheras real one is located in the winamp folder |
| ? | win name | stat.exe | ?? |
| X | Win Server | winserv.exe | Added by the IMISERV.A TROJAN! |
| X | Win Server Updt | wupdt.exe | Added by the IMISERV.A TROJAN! |
| X | win update | wupda32.exe | Added by the SDBOT.J WORM! |
| X | Win USB 2.0 USB Driver | HPPrint.exe | Added by the SPYBOT.DNB WORM! |
| X | WIN-BUGSFIX | WIN-BUGSFIX.EXE | Added by the LOVELETTER (I LOVE YOU) VIRUS! |
| X | Win2Drv | [worm filename] | Added by the WINTOO WORM! |
| X | WIN32 | WIN32.EXE | Added by the RATEGA TROJAN! |
| X | win32 | Shakira_1997_Part_1_.Mpeg_.scr | Added by the MYLIFE.N WORM! |
| X | win32 | Setup_32.exe | Added by the EVILBOT.B TROJAN! |
| X | Win32 | Win32.exe | Added by the ISRAZ.A WORM! |
| X | win32 | winsrv32.exe | Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites |
| X | win32 | WinSetup.exe | Added by the EVILBOT.B TROJAN! |
| X | Win32 Configuration | videosd32.exe | Added by the SDBOT.TT WORM! |
| X | Win32 Configuration | dllhelp.exe | Added by the SDBOT.UL WORM! |
| X | Win32 Device Loader | Win32ldr.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Win32 DRK Driver | wdrk32.exe | Added by the WOOTBOT.CY WORM! |
| X | Win32 exe file | winstr32.exe | Added by a variant of the SPYBOT WORM! |
| X | Win32 Explorer | Explorer32.exe | StartPa-MN homepage hijacker |
| X | Win32 FRT Driver | msfr32.exe | Added by a variant of the FORBOT WORM! |
| X | Win32 Kernel core component | Kernel32.pif | Added by the MOKS VIRUS! |
| X | Win32 Ms Auto Updater | AutomsUPD.exe | Added by a variant of the RBOT WORM! |
| X | win32 regedit | msn32.exe | Added by an unidentified WORM or TROJAN! |
| X | Win32 Rundll Loader | Rundll32.exe | Added by the SDBOT.A TROJAN! Note: Rundll32.exe is a valid Windows application called "Run a DLL as an App" and stored in the C:Windows directory. The version created by this virus is saved in the C:WindowsSystem directory |
| X | Win32 Services1 | wuamngr1.exe | Added by the SDBOT-PV WORM! |
| X | Win32 SSL Driver | winssv.exe | Added by the FORBOT-BH WORM!
|
| X | Win32 System Spool | spoolsvc.exe | Added by the SDBOT.UK WORM! |
| X | Win32 USB Driver | winxpinit.exe | Added by the SDBOT.AA TROJAN! |
| X | Win32 USB Driver | mvsecn.exe | Added by the FORBOT-BK WORM!
|
| X | Win32 Usb Driver | svhosint32.exe | Added by the FORBOT-BE or FORBOT-J WORMS!
|
| X | Win32 USB2 Driver | win32usb.exe | Added by the SPYBOT.DHV WORM! |
| X | Win32 USB2 Driver | smsc.exe | Added by the SDBOT.FO WORM! |
| X | Win32 USB2 Driver | svchosting.exe | Added by the FORBOT.J or SDBOT.HU WORM! |
| X | Win32 USB2 Driver | sys32.exe | Added by the WOOTBOT.X WORM! |
| X | Win32 USB2 Driver | sys32snd.exe | Added by the FORBOT-AN WORM! |
| X | Win32 USB2 Driver | wind32.exe | Added by the FORBOT-AH WORM! |
| X | Win32 USB2 Driver | winupdate.exe | Added by the AGOBOT.YE WORM! |
| X | Win32 USB2.0 Driver | 386.exe | Added by the IRCBOT.D WORM! |
| X | Win32 USB2.0 Driver | rundll16.exe | Added by the WOOTBOT.H WORM! |
| X | Win32 USB2.0 Driver | w32usb2.exe | Added by the SPYBOT.DN WORM! |
| X | Win32 USB2.0 Driver | service.exe | Added by the SDBOT-QF WORM!
|
| X | Win32 Wmls Driver | winitr32.exe | Added by the WOOTBOT.B WORM! |
| X | win32.exe | win32.exe | Added by the STARTPAGE TROJAN! |
| X | Win32BaseServiceMOD | Wintask.exe | Added by the NAVIDAD WORM! |
| X | win32clf | win32clf.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Win32DLL | Win32DLL.vbs | Added by the LOVELETTER (I LOVE YOU) VIRUS! |
| X | Win32dll | Win32dll.exe | Added by the BANPAES TROJAN! |
| X | Win32G | Kernel32.com | Added by the ESTRELLA TROJAN! |
| X | Win32G | Scandisk.com | Added by the ESTRELLA TROJAN |
| X | win32gb | win32gb.exe | All-In-One-Telcom (adult content dialler) variant |
| X | win32info | win32info.exe | Adult content dialler |
| X | win32ini | systroy.exe | Added by the IRC.ALADINZ.C TROJAN! |
| X | Win32R | Server.com | Added by the ESTRELLA TROJAN! |
| Y | WIN32SL | Win32sl.exe | Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. The specific function of this is to load MIF's in order for Dell OpenManage Client to work |
| X | WIN32SNDS | banc.exe | Added by an unidentified WORM or TROJAN! |
| X | Win32system | [random filename] | Added by the DDV.B WORM! |
| X | Win32System | win32s.exe | Added by the MYDOOM.V WORM! |
| X | Win32SystemMonitor | ***.exe [* = random char] | Browser hijacker
|
| X | win32us | win32us.exe | All-In-One-Telcom (adult content dialler) variant |
| X | win32usbd | ssrs.exe | Added by the RBOT-RA WORM! |
| X | win32_i lptt01 | win32_i.exe | Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | win32_i ml097e | win32_i.exe | Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | Win386 | Win386.exe | Added by the GOSUSUB VIRUS! |
| X | Win386 | sp32.dll | Homepage hijacker. Not a dll but a regfile in disguise |
| X | WIN3S2SNDS | winabsmod.exe | Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" |
| X | WIN3S2SNDS | winiprtx.exe | Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" |
| X | Win64 Compatibility Check | load win64.drv | CoolWebSearch parasite variant |
| X | winactive | WINACTIVE.EXE | Active variant of LOP.com hijacker - see here |
| X | WinActiveJ | WinActiveJ.exe | Added by the ROTARRAN VIRUS! |
| X | Winad Client | Winad.exe | WinAd adware by eXact Advertising |
| X | winadm | winadm.exe | Browser hijacker - redirecting to Search-World.net. Related to the SMALL.LR TROJAN!
|
| X | Winahlp.exe | Winahlp.exe | Added by a variant of the VAGRNOCKER TROJAN! |
| X | winallap | winallap.exe | Added by the DELF.E TROJAN! |
| X | winallapu | winallapu.exe | Added by the DELF.E TROJAN! |
| X | Winamp | winamp.hta | Hijacker - re-directing to adult content sites. Note - this isn't the real Winamp |
| X | Winamp media player | winapa.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| U | Winampa | WINAMPa.exe | Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs |
| X | Winampa | winampa.exe | Added by the AGOBOT-GS WORM!
|
| X | Winampa Agent | WINAMPA.EXE | Added by the SPYBOT-BR WORM! Note - this is NOT the Winamp Media Player
|
| U | WinampAgent | WINAMPa.exe | Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs |
| X | WinApi | winapix.exe | Added by a variant of the TIBSER.A downloader TROJAN! |
| X | Winapp | winpup32.exe | Produces popup ads to adult content sites |
| X | WinApp32 | msapp.exe | Added by the RSBOT TROJAN! |
| X | WinAuth | winlogon.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the valid winlogon.exe process |
| U | WinBackup Scheduler | Wbsched.exe | LIUtilities WinBackup scheduler - backup software |
| U | WinBar | WinBar.exe | "WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls" |
| X | Winbed | winbed.exe | Hijacker |
| X | WinCheck | WinCheck.exe | Added by the PWS-CY TROJAN! |
| N | WINCINEMAMGR | WINCIN~1.EXE | WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
| N | WinCinemaMgr | WinCinemaMgr.exe | WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
| X | WinCSRSS | MSGRT32.EXE | Added by the REWINDO-A TROJAN!
|
| X | wind.exe | wind.exe | Added by the MITGLIEDER.BD TROJAN! |
| X | WIND0WS | WIND0WS.exe | Added by the SPYBOT.DQ WORM! |
| N | WinDates | windates.exe | WinDates is a calendar, date organizer and event reminder program from Rockin' Software |
| X | windbs | winxtc.exe | Added by the AGOBOT-WD WORM! |
| X | Winde | winde.exe | Added by the DLUCA TROJAN! |
| X | windef | Win32sp.vbs | Added by the ANPES WORM!
|
| X | windir | winrun.exe | Added by the WINBUR.B WORM! |
| X | Windll | Windll.exe | Added by the TRYNOMA TROJAN! |
| U | WINDLL | WSYS.EXE | STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes, all passwords transacted even if they weren't keyed in, all web sites visited, every program launched including the path to that program, and more" |
| X | windll | windll32.exe | Added by the ASTEF or RESPAN WORMS! |
| X | Windll.exe | Windll.exe | Added by the STEALER TROJAN! |
| X | Windll32 | Windll32.exe | Added by the MSNPWS TROJAN! |
| X | windllsys32.exe | windllsys32.exe | Added by a variant of the MITGLIEDER.BY TROJAN! |
| X | WinDNS | windns32.exe | Added by the GAOBOT.WX WORM! |
| X | Windoes Kernel | kernel32.exe | Added by the KICKIN.A (or CYDOG.C) WORM! |
| X | Window | explore.exe | Added by the GAOBOT.ADW WORM! |
| X | Window Loader | Dos32.exe | Added by the GAOBOT.AO WORM! |
| X | Window Monitor | winmon32.exe | Added by the SDBOT.RT WORM! |
| U | Window Washer | wwDisp.exe | Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
| X | window.exe | window.exe | Added by the MITGLIEDER.H or MITGLIEDER.J TROJANS! |
| X | window2 | ssvchost.exe | Added by the IRCBOT.H TROJAN! |
| U | WindowBlinds | wbload.exe | WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins |
| X | WindowEnhancer | Winex.exe | SCbar foistware variant |
| U | WindowFX | wfxload.exe | Stardock WindowFX - "Allows you to add an unprecedented number of special effects to windows" |
| X | Windows | Kernel32.exe | Added by the TENDOOLF WORM! |
| X | Windows | msdos98.exe | Added by the PWSTEAL TROJAN! |
| X | Windows | Windows.exe | Added by the KAZMOR, BOBBINS & ALADINZ.D TROJANS! |
| X | Windows | explorer.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | windows | [path to trojan] | Added by the AIMWIN TROJAN! |
| X | windows | hkey.exe | Added by the GAOBOT.AFW WORM! |
| X | windows | system copy.exe | Added by the SALGA.A WORM! |
| X | Windows (random character) | diskcheck.exe | Added by the SINGU.B TROJAN!
|
| U | Windows Accelerators | setup.exe | KeySpy keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove |
| X | Windows AdControl | WinAdCtl.exe | Windupdates adware variant
|
| X | Windows AdService | WinAdServ.exe | Windupdates adware variant |
| X | Windows AdTools | WinAdTools.exe | Windupdates adware variant |
| X | windows auto update | penis32.exe | Added by the BLASTER (or MSBLAST.A) WORM! |
| X | windows auto update | msblast.exe | Added by the BLASTER.B WORM! |
| X | Windows Automatic Update | wuamgrder.exe | Added by a variant of the RBOT WORM! |
| X | Windows Automatic Updates | dvldr.exe | Added by the RBOT.MF WORM!
|
| X | windows automation | mslaugh.exe | Added by the BLASTER.E WORM! |
| X | Windows Automation | msdspr.exe | Added by the SOLAME.A WORM! |
| X | Windows backup | systemss.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows Backup Configuration | IEXPLORER.exe | Added by the GAOBOT.AZ WORM! |
| X | Windows Ba?lang?? Dosyas? | sistem.exe | Added by the MUZK WORM! |
| X | Windows Communicator | wincomm.exe | Added by the AGOBOT-BH WORM!
|
| X | Windows Compliant | [random filename] | Added by the RBOT-IR WORM! |
| X | Windows Config | SSYS.EXE | Added by the SPYBOT-DA WORM! |
| X | Windows Config Loader | Wincfg32.exe | Added by the SILVERFTP TROJAN! |
| X | Windows Configuration | wsys32.exe | Added by the GAOBOT.FB WORM! |
| X | Windows Control | Control.exe | Browser hijacker. NOTE - On Win9x systems it will overwrite the Windows file of the same name in the Windows directory, so therefore it will be necessary to extract a fresh copy of the file from the Windows setup cabs! |
| X | Windows Data Server | autodisc.exe | Added by the SPYBOT-CB WORM!
|
| X | Windows Dcom2 Fix | mscom32.exe | Added by the RBOT-QT WORM! |
| X | Windows debug logging | winlogg.exe | Added by the RBOT-OY WORM!
|
| X | Windows debug logging | winloggs.exe | Added by the RBOT-QN WORM! |
| X | Windows Debugger | windbg.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Windows DLL Loader | RUNDLL16.EXE | Added by the DOMWIS TROJAN! |
| X | Windows DLL Loader | defragfat32z.exe | Added by the LINKBOT.A WORM!
|
| X | Windows DLL Loader | rundll32.exe | Added by the WHIPSER-B WORM! Note - rundll32.exe file is placed in the WindowsSystem folder, wheras the legitimate rundll32.exe is located in the C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP)
|
| X | Windows DLL Loader | defragfat32pi.exe | Added by the RBOT-QQ WORM! |
| X | Windows DNS Daemon | windnsd.exe | Added by the WOOTBOT.AS WORM! |
| X | Windows Drive Compatibility | System32Driver32.exe | Added by the SUPOVA.Z WORM! |
| X | Windows Driver Services | msdrvs32.exe | Added by the WOOTBOT.L WORM! |
| X | Windows Explorer | [filename].exe | Added by the SDBOT TROJAN! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | Windows Explorer | Lsas.exe | Added by the GAOBOT.AO WORM! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | Windows Explorer | olecom32.exe | Added by an unidentified WORM or TROJAN! |
| X | Windows Explorer Shell | Winexec32.exe | Added by the REDIST.B WORM! |
| X | Windows Explorer Update Build 1142 | EXPLORER32.EXE | Added by the KaZaA based KWBOT or KWBOT.Y WORMS! |
| X | Windows Explorer-3212 | WINRE16.EXE | Added by the HARDOC WORM! |
| N | Windows Eyes | ?? | For blind people, gives a voice description of items on the screen. Windows application which gives you total control over what you hear, when you hear it, and how you hear it. Available via Start -> Programs |
| U | Windows Guardian | thehel1iawgrd32.exe | Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes |
| U | Windows Guardian | Fawgrd32.exe | Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes |
| X | Windows Help File | winhelper32.exe | Added by the SDBOT-QK TROJAN!
|
| X | Windows Help Manager | svchost32.exe | Added by the RBOT-OZ WORM!
|
| X | Windows Help Service | winhelpsv.exe | Added by the RBOT-LP WORM! |
| ? | Windows Help System | Help.pif | ?? |
| X | Windows Host Device | hostsvc.exe | Added by the ZOOTY-A WORM! |
| X | Windows HTML file reader | Sysconf32.exe | Added by the NOOMY.A WORM! |
| X | Windows Internet Protocol | winproc32.exe | CoolWebSearch parasite variant |
| X | Windows JavaScript Daemon | Winjsd.exe | Added by the WOOTBOT.AF WORM! |
| ? | Windows Load | windows.com | ?? |
| X | Windows Loader | wstart32.exe | Added by the GAOBOT.CA WORM! |
| X | Windows logging | winlogd.exe | Added by the RBOT-ON WORM!
|
| X | Windows Login | explored.exe | Added by the GAOBOT.SY WORM! |
| X | Windows Logon | winlogin.exe | Added by the SPYBOT-C TROJAN! |
| X | Windows Logon Procedure | Svchoste.exe | Added by a variant of the SPYBOT WORM!
|
| X | Windows Management Instrumentation | mwd.exe | Added by the GRAPS WORM!
|
| X | Windows Manager | winmants.exe | Added by the MANTAS WORM! |
| X | Windows mangement | winlogonn.exe | Added by the RANDEX.FC WORM! |
| X | Windows Media Player | wmediaplayer.exe | Added by the AGOBOT-NQ WORM!
|
| X | Windows Media Player | WMP23.exe | Added by a variant of the RBOT WORM!
|
| X | Windows Media Player | MediaPIayer.exe | Added by the SDBOT-QO TROJAN! - note, the executable is called 'MediapIayer', with an 'i' !)
|
| X | Windows Media Player | msass43.exe | Added by a variant of the RBOT WORM! |
| N | Windows Media Powerpoint Helper | NSPPTHLP.EXE | German software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start -> Programs |
| X | Windows media service | crvss.exe | Added by the SDBOT.VP WORM! |
| X | Windows media services | cvrsss.exe | Added by the RBOT-MW WORM!
|
| X | Windows Media SP.2.37 | [random filename] | Added by the LEMIR.C TROJAN! |
| X | Windows MeTaLRoCk service | metalrock.exe | Added by the TASTYRED TROJAN! |
| X | Windows Monitor | winmon.exe | Added by the SDBOT.VB WORM! |
| X | Windows Monitoring Service | winmon.exe | Added by a variant of the SDBOT WORM! |
| X | Windows Nets | WinNET.exe | Added by the RBOT-MO WORM!
|
| X | Windows Network Service | winvc32.exe | Added by the RBOT.RY WORM!
|
| X | Windows Networking | winsys32.exe | Added by the GAOBOT.FL WORM! |
| X | Windows Nivedia Driver | sysMGT.exe | Added by a variant of the RBOT WORM! |
| X | Windows NNT | [path to trojan] | Added by the RANKY.E TROJAN! |
| X | Windows NT 32 | ntlogin32.exe | Added by the RANDEX.BRD WORM!
|
| X | Windows NT Login | ntlogin32.exe | Added by the SDBOT.WG WORM! |
| X | Windows NT Service Name | winshock.exe | Added by the RBOT-PK WORM!
|
| X | Windows OEM Tools | winres32.exe | Added by the SPYBOT.FD WORM! |
| X | Windows OLE Automation Server | ole32aut.vbe | CoolWebSearch parasite related browser hijacker |
| ? | Windows Print Spooler | SCVHOSTS.EXE | Suspicious due to the similarity to the valid "svchost.exe" file |
| X | Windows Print Spooler | NavAgent32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Windows Print Spooler | SVEHOST.EXE | Added by the SPYBOT.H WORM! |
| X | Windows Registry | msnmsg.exe | Added by a variant of the RBOT WORM! |
| X | Windows Registry Cleaner | winclean.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows Registry Express Loader | regexpress.exe | Added by the FORBOT-CJ WORM! |
| X | Windows Registry Scan | regscan32.exe | Added by the RBOT.KE WORM! |
| X | Windows Registry Security | crss.exe | Added by a variant of the IRC.BOT TROJAN! |
| X | Windows Registry Startup | wind32.exe | Added by the AGOBOT-BZ WORM! |
| X | Windows report | swchost.exe | Added by the SMALL.GV VIRUS! |
| X | Windows Runtime Help | win32hlp.exe | Added by a variant of the AIMVISION TROJAN! |
| X | Windows Runtime Help | WinRunHelp.wrh | Added by a variant of the AIMVISION TROJAN! |
| X | Windows SA | omniscient.exe | BLAZEFIND adware |
| X | Windows secure | setver32.exe | Added by the SPYBOT.EP WORM! |
| X | Windows Security Assistant | rundll32.vbe | CoolWebSearch parasite variant |
| X | Windows Security Assistant | winsec.exe | CoolWebSearch parasite variant |
| X | Windows Security Module | module.exe | Added by a variant of the RBOT WORM!
|
| X | Windows Service Host | scvhost.exe | Added by the SDBOT.N TROJAN! |
| X | Windows Service Host | svchost.exe | Added by the CONE.B WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | Windows Services | service.exe | Added by the RANDEX.R WORM! |
| X | Windows Services Host | svchost.exe | Added by the CONE or CONE.E WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | Windows Services Update | svch0st.exe | Added by a variant of the RBOT WORM!
|
| ? | Windows shell | win70.exe | ?? |
| X | Windows Shell Library Loader | load shell.dll /c /set | CoolWebSearch parasite variant |
| X | windows shellext.32 | mschost.exe | Added by the BLASTER.K WORM! |
| X | Windows Sound Driver | SndMon32.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows Sound Manager | SndMon32.exe | Added by the FORBOT-BU WORM! |
| X | Windows SP2 Update | Sp2update.exe | Added by the WOOTBOT.BS WORM!
|
| X | Windows Spooler | SPOOLSRV.EXE | Added by the SPYBOT.P WORM! |
| X | Windows SSL File | winssv.exe | Added by the WOOTBOT.CA WORM! |
| X | Windows Startup | winsta~1.exe | GoHip foistware |
| X | Windows Startup | winstartup.exe | GoHip foistware |
| X | Windows Startup | Wdrun32.exe | Added by the GAOBOT.AO WORM! |
| X | Windows Startup | services21.exe | Added by the AGOBOT-MX WORM! |
| X | Windows Startup 32 Bits | sysrun32.exe | Added by a variant of the DARKSUN TROJAN! |
| X | Windows SyncroAd | SyncroAd.exe | BlazeFind "Windupdates" targeted advertizing |
| X | Windows System Configuration | SYSCFG16.EXE | Added by the WISDOOR.Z TROJAN! |
| X | Windows System Manager | winsystem.exe | Added by the RBOT-AN WORM! |
| X | Windows System Manager Proc | winsmc.exe | Added by the RBOT.JH WORM!
|
| X | Windows System Restore Configuration | Sblhost.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows System Restorer | SystemRestorer.exe | Added by the DULOAD.C WORM! |
| X | Windows System Serivce | winserv.exe | Added by a variant of the RBOT WORM!
|
| X | windows system service | winsock.exe | Added by the RBOT-MR WORM!
|
| U | Windows System Tray | msni.exe | Iambigbrother monitoring software |
| X | Windows System Tray | swhost.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Windows Task Manager | ACCOUNT_DETAILS.DOC.exe | Added by the QUATERS.A WORM! |
| X | Windows Task Manager | taskmgn.exe | Unidentified malware, either a variant of the WIN32.RBOT WORM, or part of a Casino Palazzo foistware install
|
| X | Windows TaskAd | Wintaskad.exe | Windupdates adware variant |
| X | Windows TCP/IP | wintcp.exe | Added by the AGOBOT-ZH WORM!
|
| X | Windows Telnet Server | wintel.exe | Added by the AGOBOT-MW WORM! |
| X | Windows Time Server | TimeSRV.exe | Added by the SPYBOT.DNC WORM! |
| X | Windows Update | [filename] | Added by the NORIO TROJAN! Acts as a hi-jacker redirecting to adult content sites |
| X | Windows Update | iexplorere.exe | Added by the GAOBOT.AP WORM! |
| X | windows update | uddater.exe | Added by the LEOX TROJAN! |
| X | Windows Update | wudate.exe | Added by the AGOBOT.ML WORM! |
| X | Windows Update | wupdate.exe | Wengs adware |
| X | windows update | sychost.exe | Added by the LEOX.B WORM! |
| X | Windows Update | Wuamgrd.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows Update | inetinf.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Windows Update | host32.exe | Added by the RBOT-GU WORM!
|
| X | windows update | wuraclt.exe | Added by the RBOT-PO WORM!
|
| X | windows update | Wuanclt.exe | Added by the RBOT.XZ WORM! |
| X | Windows Update | ebay.exe | Added by the GAOBOT.BUU WORM! |
| X | Windows Update | windows.exe | Added by the RBOT-RB WORM! |
| X | Windows Update AutoUpdate Client Product | wuauct.exe | Added by the AGOBOT.ACL WORM! |
| X | Windows Update Checker | [random filename] | Adware downloader trojan |
| X | Windows update config | svhost.exe | Added by the SDBOT-PF WORM! |
| X | windows update configurator | svghost.exe | Added by a variant of the SPYBOT WORM!
|
| X | Windows Update Files | dnetc.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - wupdmgr.exe is the real Windows Update |
| X | Windows Update Manager | wupdmngr.exe | Added by the RANDEX.BTB WORM!
|
| X | Windows Update Manager for NT | wupdmgr32.exe | Added by the SDBOT.AH WORM! |
| X | Windows Update Monitoring Service | winupdt.exe | Added by the RBOT-PL WORM!
|
| X | Windows Update Process | wmiprvsc.exe | Added by the SDBOT-CB WORM! |
| X | Windows Update Service | csrs.exe | Added by the AGOBOT-NI WORM! |
| X | Windows Update Service | smcg.exe | Added by the SDBOT.QY WORM! |
| X | Windows Update Service 2004/2005 | systemupdate.exe | Added by the RBOT-JE WORM! |
| X | Windows Update V6 | [random filename] | Added by the RBOT-KT WORM! |
| X | Windows Update.exe | N/A | Homepage hijacker, see here |
| X | Windows Updater | wupdmgr32.exe | Added by a variant of the DOS.AUTOCAT TROJAN! |
| N | Windows Version Check | ver_chk.exe | Version checker for CyberAudioLibrary ("A new way to exchange information through the Internet") |
| X | Windows video | vide_32.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Windows Video Acquisition (WVA) | wvsvc.exe | Added by the AGOBOT.YM WORM! |
| X | Windows Video Drivers | videons32.exe | Added by the GAOBOT.AZT WORM! |
| X | Windows-System | System32.exe | Added by the LOGPOLE.C WORM! |
| X | Windows-TCP-IP | rfkampig.exe | Added by the GIPMA TROJAN! |
| X | Windows32 | rundll.exe | Added by the AGOBOT-LK or AGOBOT-ND WORMS! |
| X | WindowsAgent | WindowsAgent.exe | Added by the GOP.G WORM! |
| X | WindowsAPI.DLL | Server5.exe | Added by the "Fear and Hope" TROJAN! |
| X | WindowsCriticalUpdate | windows_critical_update.exe | Added by the ASTEF or RESPAN WORMS! |
| X | WindowsKeyUpdate | master.exe | Added by the JOSAM WORM!
|
| X | WindowsMGM | Winmgm32.exe | Added by the SOBIG WORM and LALA.C TROJAN! |
| X | WindowsRegistration | [random filename] | Added by the RBOT-NO WORM!
|
| X | WindowsRegKey Autoupdate | [random filename] | Added by a variant of the RBOT WORM! |
| X | WindowsRegKey upd4te2d4te | *********.exe [* = random char] | Added by the RBOT.XQ WORM! |
| X | WindowsRegKey update | [random filename] | Added by a variant of the RBOT WORM! |
| X | WindowsRegKey%$ update | msi332.exe | Added by the RBOT-IX WORM! |
| X | WindowsRegKey%update | ethernet32m.exe | Added by the RBOT-EN WORM!
|
| X | WindowsRegKeys update | winsysi.exe | Added by the SDBOT.WE WORM! |
| X | WindowsSetup | [path to trojan] | Added by the EZBOT TROJAN! |
| X | WindowsUpd | WindowsUpd4.exe | VirtuMonde adware |
| X | WindowsUpd1 | WindowsUpd1.exe | VirtuMonde adware |
| X | WindowsUpd2 | WindowsUpd2.exe | VirtuMonde adware |
| X | WindowsUpdate | windows_update.exe | Added by the LOFNI WORM! |
| X | WindowsUpdate | svchost.exe | Added by the ASTEF or RESPAN WORMS or AGENT-V TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | windowsupdate | RPCX1sQ3.exe | Added by the IRCBOT.B TROJAN! |
| X | WindowsUpdate | USRINIT.EXE | Added by the MADDIS.B WORM! |
| X | WindowsUpdate Service | wuautlc.exe | Added by the RBOT-NR WORM!
|
| X | WindowsXP Update | windowsxpupdate.exe | Added by the RBOT-PB WORM!
|
| X | Windows_Serivce | SERVICE.exe | Added by the WOOTBOT.AH WORM! |
| X | Windows_Updates | svthost.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows_VXD | user32.exe | Added by the PWSTEAL.PPORT TROJAN! |
| X | Windowz Update V2.0 | Explorer.exe | Added by the YODO WORM! Note - the valid "explorer.exe" is located in C:Windows or C:Winnt whereas this one is located in the System32 sub-directory |
| X | WinDriv32 | WinDriv32.exe | Added by the SMALL-BA TROJAN! |
| X | windrv | windrv32.exe | Added by an unidentified VIRUS, WORM or TROJAN! - possibly a strain of OBLIVION or BIONET |
| X | WinDrv | windrvx.exe | Added by a variant of the TIBSER.A downloader TROJAN! |
| U | WinDSL MTU-Adjust | WinDSL_MTU.exe | Adjusts the registry setting of the DUN-Adapters (MTU) and the TCP/IP-Protocol (RWIN) by ENGEL Technologieberatung |
| ? | WinDSL_MTU | WinDSL_MTU.exe | May be realted to Tiscali broadband, if so is it required? |
| X | WinDSNX | Win????.exe | Added by the DNSX TROJAN! |
| X | WindUpdates | [path to trojan] | Added by the AGENT.BF TROJAN! |
| X | WindUpdates | WinUpdt.exe | BlazeFind "Windupdates" targeted advertizing |
| U | WINDVDpatch | CTHELPER.EXE | CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative?s sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a "leave alone" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it |
| N | WinDVR SchSvr | SchSvr.exe | WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs |
| N | WinDVRCtrl | WinDVRCtrl.exe | Control center software for an AOpen VA1000 TV tuner card |
| X | Windws Configuration Loader | LEXPLORE.exe | Added by the SODABOT WORM! |
| X | WinEssential | Keyhost.exe | Hijacker - hailing from jraun.com |
| X | WinEssential | keyword.exe | Jraun.com hijacker |
| X | WinExec | Winexec.exe.vbs | Added by the AINESEY.A WORM! |
| X | WinExec32 | WinExec32.exe | Added by the KAZWIN WORM! |
| U | WinFast Schedule | Wfwiz.exe | Leadtek WinFast TV tuner scheduler |
| U | Winfast2KLoadDefault | Rundll32.exe Wf2kcpl.dll, DllLoadDefaultSettings | Loads default settings for Leadtek Winfast graphics cards |
| U | Winfast_2K | WF2k.exe | System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card |
| U | WinFast_Gamma | Rundll32.exe wfcpl.dll, DllLoadGammaRampSettings | Loads if you change the gamma settings on Leadtek WinFast graphics cards |
| U | WinFast_Taskbar | rundll32.exe wftask.dll, WFDllLoadDefaultSettings | Loads default settings for Leadtek WinFast graphics cards |
| X | WinFavorites | WinFavorites.exe1 | Loudmarketing.com adware downloader |
| N | WinFax PRO Controller | WFXCTL32.EXE | From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs |
| Y | WinFaxAppPortStarter | wfxsnt40.exe | WinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application. |
| X | winfont | winfont.exe | Added by the DEATH TROJAN! |
| U | WinFoxV2 | WF2k.exe | System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card |
| X | WinFX | cssrs.exe | Added by the AGOBOT.FX WORM! |
| X | WinGate | WinGate.exe | Added by a variant of the LOVGATE WORM! |
| U | WinGate Engine Monitor | wgengmon.exe | WinGate Internet Client Dialup Monitor - component of WinGate proxy server software. Displays the status of the WinGate engine, and appears in the system tray of each workstation on the network reassuring clients that their workstations have connectivity with the WinGate Server
|
| X | WinGate initialize | WinGate.exe | Added by a variant of the LOVGATE WORM! |
| X | wingo | wingo.exe | Added by the BEAGLE.AW or BEAGLE.AV WORMS!
|
| N | WinGuage Pro | WGPRO32.EXE | Part of McAfee Nuts & Bolts. "WinGauge is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious". Resource hog. Available via Start -> Programs |
| Y | Winguard | WGFE95.EXE | Dr Solomon's Virex antivirus |
| U | WinGuard Pro | wgp.exe | Winguard Pro |
| N | WinHacker | rundll32.exe wh95.dll, HackMe | Tweaking utility by Wedge Software. There are far better tweakers and, unlike WinHacker, most are free |
| X | Winhelp | winhe1p.exe | Added by the QQPASS.E TROJAN! |
| X | WinHelp | WinHelp.exe | Added by a variant of the LOVGATE WORM! Note - "winhelp.exe" resides in C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K), or C:WindowsSystem32 (WinXP) whereas the valid "winhelp.exe" resides in C:Windows or C:Winnt |
| X | WinHelp | realsched.exe | Added by a variant of the LOVGATE WORM! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name |
| X | Winhelp | TkBellExe.exe... | Added by a variant of the LOVGATE WORM! |
| X | winhlp3.exe | winhlp3.exe | Added by a variant of the EASTO.A TROJAN! |
| X | Winhlp32 | Wscript.exe ..Msexec32.vbs | Added by the GANT.B WORM! |
| X | winhlp32.exe | winhlp32.exe | Added by a variant of the EASTO.A TROJAN! |
| X | winhlpp32.exe | winhlpp32.exe | Added by the GAOBOT.SY WORM! |
| X | Winhost | wintt.exe | Added by the LOLAWEB.B TROJAN! |
| X | Winhost | win.exe | Added by the DLOADER-AP TROJAN! |
| X | wininet32 | wininet32.exe | Added by the RAZNEW-A TROJAN! |
| X | wininetd | wininetd.exe | Added by the WINET TROJAN! |
| X | wininit | wininit.exe | Added by the WOLLF.16 TROJAN! |
| X | Wink*.exe | Wink*.exe [* = random char] | Added by a variant of the KLEZ WORM! |
| U | Winkb6 | winkb6.exe | Part of We-Blocker, works in tandem with syswb6. Both files are needed to run WeBlocker. Required if We-Blocker is installed |
| X | WinKernel | WinKer.exe | Added by the MIRAB or SERVIDOR TROJANS! |
| X | WinKernel | [path to worm] | Added by the PLEA VIRUS! |
| X | winkernel32 | wWin32.com | Added by the BANSAP TROJAN! |
| U | WinKey | winkey.exe | Loads Copernic's WinKey. Used to map out Windows key hotkey combinations. Not required for the system, but is necessary for this to be running if you use these hotkey combos |
| X | winlibs.exe | winlibs.exe | Added by the EVAMAN.C WORM! |
| X | WinLibUpdate | libupdate.exe | Added by the BIONET series of TROJANS such as BIONET.31 or BIONET.310 |
| X | WinLibUpdate32 | libupdate32.exe | Added by the BIONET.405 TROJAN! |
| X | WinLibUpdte | libupdte.exe | Added by the BIONET.318 TROJAN! |
| X | Winlink | winlink32.exe | Added by the GAOBOT.AAY WORM! |
| X | Winlme | windll.exe | Added by the GOP.F WORM! |
| X | WinLoader | [random filename] | Added by variants of the SUBSEVEN TROJAN! |
| X | winlocatorupdate | updatewinlocator.exe | Locator adult content toolbar related |
| X | WinLogin | winlogin.exe | Added by the AGOBOT-IX WORM!
|
| X | Winlogin.exe | log.exe | Added by a variant of the AGENT.AH downloader TROJAN! |
| X | winlogin.exe | logfile.exe | Added by the AGENT.AH TROJAN! |
| Y | winlogon | winlogon.exe | Windows Logon Process - handles user logons described here |
| X | winlogon | winlogon.exe | Hijacker or adult content dialler - file is located in C:Windows or C:Winnt, and not in it's System or System32 subdirectory, as is the case with the legitimate Windows Logon (winlogon.exe) process |
| X | winlogon | winlogin.exe | Added by the RANDEX.E WORM! |
| X | winlogon | winlogon.exe | Added by the TRODAL TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! File is located in C:Windows or C:Winnt, and not in it's System or System32 subdirectory |
| X | Winlogon.exe | N/A | CoolWebSearch parasite related - resets home page to an adult material site |
| X | WinLsass | servicec.exe | Added by the SCANE WORM! |
| X | WinLsass | [path to trojan] | Added by the SCANE WORM! |
| X | winltmpv | winln.exe | Added by the TCXMEDI-C TROJAN! |
| X | winltmpv | wutop.exe | Added by the TCXMEDI-C TROJAN! |
| X | Winmain | winmain.exe | One of the first of a new breed of malware. When run it immediately loads MSHTA.EXE from the Windows folder, placing it on "hot standby", ready to accept HTA scripting within a web page and then EXECUTE what is embedded IN the page as a program! In other words, it's possible for a "rogue" website to actually embed trojans, worms and/or viruses directly into a web page. BOClean's HTA Stop offers an easy way to toggle this capabiltity, or rather vulnerability, on and off. I suggest you leave it disabled! |
| ? | WinManager | schost.exe | ?? |
| U | winmatrix.exe | WinMatrixXP.exe | WinMatrix XP - wallpaper replacement that shows different matrix effects (including flowing matrix codes from 'The Matrix' movie) on your desktop |
| U | WinMem | WinMem.exe | WinMem Cleaner - part of Ultra WinCleaner Utility Suite. Makes more memory available for your programs and the Operating System. It also defragments your system
|
| X | WinMenssage | winmax.exe | Added by the BANCOS.B TROJAN! |
| N | WinMgmt | WinMgmt.exe | Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here |
| X | WinMgr32 | winmgr32.exe | Added by the MIMAIL.P WORM! |
| X | WinMine | D4NG3.vbs | Added by the BISCUIT.A WORM! |
| Y | winmodem | wmexe.exe | Software for software based modems. Required if you have one of these. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information |
| X | WinMsrv32 | WinMsrv32.exe | Added by the GAOBOT.AFJ WORM! |
| N | winmysqladmin | winmysqladmin.exe | Starts the MySQL database admin tool |
| N | WinMySQLadmin Tool | winmysqladmin.exe | Starts the MySQL database admin tool |
| X | winnet | winnet.exe | CommonName Toolbar spyware. To uninstall see here |
| ? | Winnov Menu | WnvMenu.Exe | Winnov Video Capture Card related. What does it do and is it required? |
| ? | Winnov Remote | WnvRsvr.Exe | Winnov Video Capture Card related. What does it do and is it required? |
| ? | Winnov Status | WvStatus.Exe | Winnov Video Capture Card related. What does it do and is it required? |
| X | WinNtBB | WinntBB.exe | Added by the DULOAD.C WORM! |
| X | winocx32 | winocx32.exe | Added by the PROTORIDE.I WORM!
|
| U | WinPatrol | WinPatrol.exe | WinPatrol - "Manage Startup programs, tasks, cookies; will sniff out Worms, Trojan horses, Cookies, Adware, Spyware, Klez, Assumption and other malicious programs" |
| X | winphonics7536 | vbsystem35.exe setups.exe vb.vb | Added by a variant of the MUTIN-C TROJAN! |
| Y | WinPoet | WinPPPoverEthernet.exe | WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking |
| N | WinPopup | WINPOPUP.EXE | Intranet chat software provided by windows for chat on small networks. Handy little LAN messaging utility. Has been included in Windows since 95, and maybe in WFWG 3.11. Normally it won't set itself up to run unless the user specifically adds it to startup |
| X | winpopup | winupie.exe | Adware by Tradeexit.com |
| X | WinProfile | Command.exe | Added by the BUDDY TROJAN! |
| X | WinProfile | sndcfg16.exe | Added by the SNDC.A WORM! |
| X | WinProt | Winprot.exe | Added by the CHUPACABRA TROJAN! |
| X | WinProt | server.exe | Added by the CHUPACABRA TROJAN! |
| U | WinProxy | WinProxy.EXE | "WinProxy is the world-first proxy server and a firewall with integrated mail server for Windows 95/98/ME/NT/2000/XP" |
| X | winpsd | winpsd.exe | Added by the MYDOOM.Q WORM! |
| X | winrar | winrar.exe | CoolWebSearch parasite variant. Note - this is not the file zipping utility also known as WinRAR and it's located in C:Winnt or C:Windows |
| X | winrarshell | winrarshell32.exe | Added by the SALIRA TROJAN! |
| X | winReg | winReg.exe | Added by the YAHA.H or YAHA.J WORMS! |
| X | winregsrv | winregsrv.exe | Added by the SYNRG TROJAN! |
| X | Winres32vis | [path to worm] | Added by the THRAX.A WORM! |
| N | winroute | winroute.exe | Win-Route 4.27. WinRoute Tray Icon for starting and stopping the WrCtrl.exe process, also to log in to the console to view logs and change settings. Can be unchecked and the engine still runs and functions normally. Can then use provided shortcuts for administration of the program. Loaded in SERVICES on Windows 2k |
| X | winrun | msconfig.exe | Added by the WINUR.A WORM! Note - this is not the real msconfig.exe as it's located in C:winrun |
| X | winrun | winrun.exe | Added by the WINBUR.B WORM!
|
| X | WinRunners | WinDrivers.exe | Added by the DULOAD.C WORM! |
| X | winsecure | winsecure.exe | Browser hijacker, redirecting to specificsearches.com |
| X | winserver | Server.txt.vbs | Added by the DELTAD.A WORM! |
| U | WinService32 | ssmgr.exe | 007 Spy Software - "stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP" |
| X | WinServices | WinServices.exe | Added by the YAHA.K or YAHA.M WORMS! |
| X | winservn | winservn.exe | PurityScan/Clickspring adware |
| X | winservs | winservs.exe | PurityScan/Clickspring adware |
| X | WinSetBrowse | BasicUpdate.dll.vbs | Added by the BISCUIT.A WORM! |
| ? | Winshoe | wuadfdqr.exe | Probably an unidentified VIRUS! Adds itself to 3 registry "Run" keys and prevents Task Manager being displayed. This is not the Winshoe IRC Client as the visitor did not have it installed |
| X | WinShowUpdate | copy C:WINDOWSwinshow.new C:WINDOWSwinshow.dll | Winshow parasiate related - from the "RunOnce" keys it replaces "winshow.dll" with a new version |
| X | WinSig | NetXP.exe | Added by the BANKER-FN TROJAN! |
| X | Winsock2 driver | SDJOIJE.EXE | Added by the SPYBOT.DR TROJAN! |
| X | Winsock2 driver | MIRC32.exe | Added by the SPYBUZZ TROJAN! |
| X | Winsock2 driver | kgzgjkpcw.exe | Added by the SDBOT.T TROJAN! |
| X | Winsock2 driver | ZONEALARM.EXE | Added by the SDBOT.T TROJAN! Note - ZONEALARM.EXE is not the valid Zone Labs firewall program |
| X | Winsock2 driver | WINCFG.SCR | Added by a variant of the SPYBOT WORM! |
| X | Winsock2 driver | winupdate.exe | Added by the SPYBOT-BX WORM! |
| X | Winsock2 driver | SPOLSV.EXE | Added by the SPYBOT-CM WORM!
|
| X | Winsock2 driver | Zonealarmupdate.exe | Added by a variant of the SPYBOT WORM!
|
| X | Winsock2.dll | WINLODR.SCR | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Winsock32 driver | Testing.exe | Added by the SPYBOT.B WORM! |
| X | Winsock32 driver | lcd.exe | Added by the SPYBOT.B WORM! |
| X | Winsock32 driver | Sdjoije.exe | Added by the SPYBOT.B WORM! |
| X | Winsock32driver | win32server.scr | Added by the HACARMY TROJAN! |
| X | Winsock32driver | sp2XPupdate.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Winsock32driver | win32server.exe | Added by the BACKDOOR-AZV TROJAN! |
| X | Winsock32driver | ZoneAlarmPr0.exe | Added by the HACKARMY-B TROJAN! |
| X | Winsock32driver | ZoneLockup.exe | Added by the HACARMY.D TROJAN! |
| X | Winsock32driver | win32server.exe | Added by the HACARMY.F TROJAN!
|
| X | Winsock32driver | winXPupdate.exe | Added by the HACKARMY.9728 TROJAN! |
| X | winsockdriver | tskmg.exe | Added by the SDBOT.GEN TROJAN or WARPIGS.C WORM! |
| X | winsockdriver | winsock2.2.exe | Added by a variant of the SPYBOT WORM! |
| X | WinSocketComponent | nthost.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | WinSPF | windrv32.exe | Added by the MYDOOM.T WORM! |
| X | WinSPF | winspf32.exe | Added by the MYDOOM.S WORM! |
| X | WinSrv | kn0x.exe | Added by the HOBBIT.F WORM! |
| X | WinSrv | SHIZZLE.EXE | Added by the HOBBIT.C WORM! |
| X | Winsrv | winsrv.exe | Added by the OPASERV.T WORM! |
| X | WinStart | WinStart.exe | From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge |
| X | WinStart | Wscript.exe WinStart.vbs | Added by the CIAN.C WORM! |
| X | WinStart | winstart32.exe | Added by the PUROL WORM! |
| X | WinStart | WinStart.pif | Added by the CONE.E WORM! |
| X | WinStart001 | WinStart001.exe | From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge |
| X | WinStart001.EXE | WinStart001.exe | From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge |
| X | Winsta~1 | winsta~1.exe | GoHip foistware |
| X | WinSth16 | WinSth16.exe | Added by the CAKE WORM! |
| X | winstro | RUN32DLL.exe | Added by the FTP_ANA TROJAN! |
| X | Winsvc32 | Winsvc32.exe | Homepage hijacker |
| U | Winsys | Winsys.exe | Win-Spy - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
| X | WINSYS | [path to trojan] | Added by the GOLDPLAY TROJAN! |
| X | WinSys32 | Winsys32.exe | Added by the CIGIVIP TROJAN or RECKUS WORM! |
| X | winsys32 Driver | winsys32.exe | Added by the LOONY-O TROJAN! |
| U | WinSysAppMon | WinSysRM.exe | Home & Family Content Filter related. See here |
| X | winsyslog lptt01
| winsyslog.exe | Variant of the RapidBlaster parasite (in a "Winsyslog" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | WinSysStartUpWKbLw | TaskSystemDll.Exe | Added by the BACKZAT.G WORM! |
| X | WinSyst32 | winsyst32.exe | Added by the MORB WORM! |
| X | WinSystem | winsystem.exe | Added by the WHITEBAIT WORM! |
| X | Winsystem | winsystem.exe | Added by the BANCOS.CR TROJAN! |
| X | WinTask | Wintask.exe | Added by the HIPO or LEMIR.F TROJANS! |
| X | WinTask driver | wintask.exe | Added by the SMALL.ABD downloader TROJAN! |
| U | WinTasks Traybar | wintasks.exe | WinTasks - "Efficient Resource and Task Management is absolutely critical if you want to achieve the highest system performance levels possible. WinTasks 4 will not only help you achieve this task, but will actually make your system run faster and more smoothly than ever before" |
| X | wintasks.exe | wintasks.exe | Added by the EVAMAN WORM! |
| N | Wintercooler Pro | WINCOOL.EXE | Wintercooler Pro - utility that monitors CPU usage, RAM consumption and Internet connection speed |
| N | WinTidy | WinTidy.exe | Desktop icon manager from PC Magazine (Ziff-Davis) for Win95. Available via Start -> Programs |
| X | Wintime | Wintime.exe | Added by the HARNIG TROJAN! |
| N | Wintime Wtxpload | Wxpload.exe Wintime | Part of the software to support a Dexxa USB graphics tablet. From a visitor - "This gets started anyway when you plug in the USB connector for the graphics tablet, if it's not already running. It then starts an application which manages the tablet messages. Since I leave the tablet unplugged unless I need to use it, I don't need this running at startup. I suspect that this program monitors a number of windows messages, so that when it's loaded, my regular mouse slows down - it acts like it 'sticks' entering and leaving windows. Certainly my performance returned to what I expected when I removed this item using MSCONFIG" |
| X | WinTools | WToolsA.exe | Wintools adware |
| N | WinTOTAL Scheduler | guru.exe | WinTOTAL Real estate appraisal software related |
| X | WinTray | wintray.exe | Added by the LEGUARDIEN.B TROJAN! |
| X | winupd | RUNDLL32.EXE [random value].dll, _mainRD | Added by the MOTA.A WORM! |
| X | winupd.exe | winupd.exe | Added by the BEAGLE.M or BEAGLE.N WORMS! |
| X | WinUPD32 | explorer.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | winupdat | winupdat.exe | Added by the CANBOT.A WORM! |
| X | WinUpdate | RBSKQQBO.EXE | Added by the VBSWG2B.A WORM! |
| X | WinUpdate | wmbem.exe | Added by the REVCUSS.B TROJAN! |
| X | WinUpdate Loader | msnnm.exe | Added by the REVCUSS.C TROJAN! |
| X | winupdate.exe | winupdate.exe | Added by the RADO TROJAN! |
| X | winupdate.reg | winupdate.exe | Added by the SPYBOT.EAS WORM!
|
| X | winupdate2846 | vbsystem35.exe msvbrun.exe | Added by a variant of the MUTIN-C TROJAN! |
| X | winupdt | RUNDLL32.EXE [random.dll] | Added by the MABUT.A WORM! |
| X | winupdtl | winupdtl.exe | SecondThought adware variant
|
| X | winur | winrun.exe | Added by the WINBUR.B WORM!
|
| X | Winux Piriax Service | PH32.EXE | Added by the RANDEX.G WORM! |
| X | winversion | winversion.exe | Browser hijacker, redirecting to specificsearches.com |
| U | WinVNC | WinVNC.exe | WinVNC is an application that allows you to remote control your PC from another PC somewhere on the internet |
| X | WinVNC | iexplorer.exe | Added by the EVIVINC VIRUS! |
| X | winwan lptt01 | winwan.exe | Variant of the RapidBlaster parasite (in a "Winwan" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | winwan ml097e | winwan.exe | Variant of the RapidBlaster parasite (in a "Winwan" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | winXP | 33.exe | Added by the ANPES WORM!
|
| X | WinXP | plugin1.exe | Added by the Downloader-JW TROJAN!
|
| X | winxpdll32.exe | winxpdll32.exe | Added by a variant of the SMALL downloader TROJAN! |
| U | WinXPLoad | Rundll32 LoadDll, LoadExe WinXPLoad.exe | Compaq hotkey related - required if you use the hotkeys |
| X | winzip | [path to trojan] | Added by the BANCOS.G or BANCOS.K TROJANS! |
| N | WinZip Quick Pick | WZQKPICK.EXE | Added with WinZip version 8.1. "The new WinZip Quick Pick taskbar tray icon gives you instant access to WinZip and your Zip files. Just left click the icon to open WinZip, or right click it to instantly reopen recently used Zip files, access your Favorite Zip Folders, open WinZip Help, or start WinZip itself.". You can right-click and close it - choosing to not re-load it at start-up |
| X | Win_api_driver | system.exe | Added by the REVIRD TROJAN! |
| X | Win_Library | INISvc.exe | Added by the ANARCH WORM! |
| X | win_upd.exe | WINdirect.exe | Added by the MITGLIEDER.M TROJAN! |
| X | win_upd2.exe | WINdirect.exe | Added by the BEAGLE.AO WORM! |
| X | Win_vader | Win_vader.vbs | Added by the INVASION.A VIRUS! |
| X | WIP Config GUI | Winipcfgs.exe | Added by the RBOT-CN WORM! |
| U | Wireless PCI Card Configuration Utility | WMP11Cfg.exe | Utility used by the LINKSYS wireless PCI card (WMP11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration |
| X | Wireless Provider Server | wpsvr.exe | Added by the FORBOT-AD WORM! |
| U | Wireless-G Notebook Adapter Utility | WPC54CFG.EXE | Utility used by the LINKSYS Wireless-G Notebook Adapter (WPC54G) |
| N | wjview | wjview.exe | MS tool used to view window-based Java applications from the command line |
| N | wkcalrem | wkcalrem.exe | Produces a pop-up reminder of events scheduled using the MS Works Calendar |
| N | WkDetect | WkDetect.exe | Checks for updates to MS Works |
| N | wkfud | wkfud.exe | A marketing program for MS Works |
| N | WksSb | WksSb.exe | The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program. The Works Portfolio provides a location where you can store items you want to later put into a document or other file |
| N | WkUFind | WkUFind.exe | MS Works Update Detection. MS Picture It! (versions 7 to current) use this automatic update feature during the log on process. It can also cause your system to automatically dial into your ISP as it tries to access the internet, if you have your system set to automatically dial when the internet is invoked. To manually update, go to Microsoft's Office/Works update site |
| X | Wlan Drier | Winusb2.exe | Added by the WOOTBOT.DC WORM! |
| X | Wlan Driver | avscan.exe | Added by the WOOTBOT.DH WORM! |
| N | WLAN Status Tray Applet | WLANSTA.EXE | System Tray icon for checking the status of a Wireless LAN |
| Y | WLAN_Cfg.exe | WLAN_Cfg.exe | Linksys Instant Wireless USB Network Adapter driver |
| X | wm41a398 | rundll32.exe [path] wm41a398.dll, EnableRunDLL32 | LZIO.com adware downloader |
| X | WMAudio | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | WMAudio | winlogon.exe | Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
| N | WMBoot | N/A | Associated with Logitech Wingman game controllers. Not required but what does it do? |
| U | WMIEXE.exe | wmiexe.exe | NT component, used by Windows Millennium to detect Plug and Play-compliant IEEE 1394 devices during the startup process. Since this is important for the computer to work properly if you have these, Windows Millennium protects wmiexe.exe and will restore the file even if it's deleted or renamed. Check here for some details on what to do to stop it loading |
| X | Wminf | Wminf.exe | Added by the GEMA TROJAN! |
| X | Wminfo | Wminfo.exe | Added by the GEMA TROJAN! |
| X | wmiprv | wmiprv.exe | Added by the RBOT-WM WORM! |
| Y | WMP54Gv4 | WMP54Gv4.exe | Linksys WMP54G Wireless-G PCI Adapter driver |
| X | wmsys32 | wmsys32.exe | Added by the BANPAES.B TROJAN! |
| ? | WM_LOGIN | MSGLOGIN.EXE | Part of McAfee Firewall. What is it for and is it needed? |
| X | WNAD | WNAD.EXE | Spyware added as a result of running a program called "Yo Mama Osama" (osama.exe). See here for more and how to get rid of it. There are other ways this can show up on your system, and it will manifest itself by periodically opening a new browser window with advertising for copy DVD software and the like |
| X | WNSC | wns*****.exe [* = random char] | PurityScan/Clickspring adware |
| U | WNSI | wnscp**.exe [* = random char] | PurityScan/Clickspring adware |
| X | WNSI | wnscpsu.exe | PurityScan/Clickspring adware |
| X | WNSI | wnscpsv.exe | PurityScan/Clickspring adware |
| X | WNST | wns*****.exe [* = random char] | PurityScan/Clickspring adware |
| N | Woowatch | Watch.exe | Wanadoo ISP software, not required |
| N | WordWeb | wweb32.exe | WordWeb - free theasaurus and dictionary. Start manually |
| ? | Workflo | workflow.exe | Related to BroadJump Client Foundation - broadband troubleshooting software installed by various companies. Is it required? |
| N | Works Calendar Reminder | wkcalrem.exe | Produces a pop-up reminder of events scheduled using the MS Works Calendar |
| N | WorksFUD | wkfud.exe | A marketing program for MS Works |
| U | Workstation Scheduler | wm95.exe | Desktop Management Scheduler. Part of Novell's Netware Client. Schedueles NDS events. If events have been schedueled, it is required, otherwise, it is useless and a memory hog |
| X | Workstation Services | wrkstn.exe | Added by the RBOT-OJ WORM!
|
| U | Worm Detector | wd.exe | Worm Detector - antivirus add-on for Outlook 2K or XP for handling worms and spam |
| X | wormexe | winstart.exe | Added by the EARLYBIRD WORM! |
| X | wovax | wovax.exe | Added by the DAQA.A TROJAN! |
| N | Wpctrl | wpctrlnt.exe | WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
| N | Wpctrl | wpctrl95.exe | WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
| N | wpctrl95 | wpctrlnt.exe | WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
| N | wpctrl95 | wpctrl95.exe | WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
| Y | WPCycle.exe | WpCycleWin.exe | Added when selecting Mplayer2 to open media files. Forces other codes to Wait for Previous instructions to end, preventing instability of your CPU (freezing) |
| X | wpds.exe | doriot.exe | Added by the SMALL-KY TROJAN!
|
| X | WQK | WQK.exe | Added by a variant of the KLEZ WORM! |
| ? | wr | WR.EXE | ?? |
| ? | WR Command | wr.exe | ?? |
| N | WrCtrl | WrCtrl.exe | Win-Route 4.27 NAT engine on Win2k Pro for connection sharing and security using Win-Route by Tiny Software. A connection sharing/Firewall Application. If service is disabled the program does not work, but you can manually start/stop the service with a shortcut the program installs at any time |
| X | WRDialer | WrDialer.exe | WinPoet DSL dialler |
| ? | WRECK GUARD | ?? | ?? |
| ? | WregBios | wregbios.exe | Desktop Management BIOS (DMI BIOS) related. Apparently invokes the DosBios.exe file. Is it required? |
| U | wrexec | wrexec.exe | Watch Right - monitoring program, part of the PowerTools add-on for AOL. Records instant messages, E-mail, chat. Watch Right appears to be, and functions as an online clock updater which connects with the U.S. National Institute of Standards and Technology. It was designed for parents who wish to keep an eye on what their children are doing online |
| ? | wriste | wriste.exe | ?? |
| X | ws2help | ws2help.exe | Added by a variant of the SMALL.AN TROJAN!
|
| X | WSAConfiguration | wmon32.exe | Added by the GAOBOT.BAJ WORM! |
| X | WSAConfiguration | svchostt.exe | Added by the AGOBOT.ZT WORM! |
| X | WSAConfiguration | rpcxmn32.exe | Added by the AGOBOT.ABG WORM! |
| ? | wsbklite | wsbklite.exe | Related to the Acer Soft Button on Acer Tablet PCs. Appears to do nothing so is it required? |
| U | WScheduler | WScheduler.exe | Windows Scheduler - "schedule unattended running of applications, batch files, scripts and much more. Also, you can schedule popup reminders so you'll never forget reminders, tasks and other events." |
| X | wscript.exe | vabian.vbs | Added by the VABI VIRUS! |
| X | wserver | wserver.exe | Added by the NETSKY.AC or SASSER.G WORMS! |
| U | WService | WService.exe | Tablet client Driver for UC-Logic Pen/Graphics Tablet |
| X | WSSAConfiguration | wmmon32.exe | Added by the AGOBOT-KC WORM! |
| X | Wstat32 driver | Wstat32.exe | Added by the LOONBOT TROJAN! |
| Y | wstimeb | wstimeb.exe | Used with NEC printers. You can disable it before printing but it re-loads itself when printing so you may as well leave it |
| Y | wswpd | wswpd.exe | Used with some models of Panasonic, Epson and NEC printers. Some older drivers known to have a "memory leak". Needed for printing to work |
| N | WT Game Channel | GameChannel.exe | WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| N | WT Game Channel | |