Welcome Guest (Log In | Create Account)
New Member? Join for free.
Name Filename Status Description
{9311b8a8-0fd7-f849-5b42-67bbb89472f7} C:\windows:schost.exe
X
Identified as a variant of the Troj/Poison-K backdoor and keylogger. It is advised that once you remove this infection you immediately change all of ... Read More
{B9BA1F0E-091E-ECF9-0A09-CC4C2EE29C62} task.exe
X
Identified as a variant of the Troj/Poison-K backdoor and keylogger. It is advised that once you remove this infection you immediately change all of ... Read More
USB Hardware32c Monitoring USBHARDWARE32C.EXE
X
Added by the W32/Rbot-UU worm. When started, this infection connects to an IRC server where it waits for remote commands. ... Read More
Windows Service Manager userint32.exe
X
Added by the W32/Oscabot-C worm. When started, this infection connects to an IRC where it waits for remote commands to execute. ... Read More
w0rmname.exe w0rmname.exe
X
Added by the W32/Woned-C worm.
winrun z W1NT45K.exe
X
Added by W32.Mytob.BL WORM! ... Read More
Windows Updtee Mgnr W1NT45K.exe
X
Added by the W32.Mytob.DC@mm worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
w32 Wayang w32 Wayang.exe
X
Added by the W32.Yadurna.A worm. The user is presented with a password recovery dialogue once the malicious program is downloaded. ... Read More
w32 w32.exe
X
Added by the SOKEVEN TROJAN!
WIN ID SYS64 w3264.exe
X
Added by the W32/Mytob-BO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Application Extension W32AppSrv.exe
X
Added by the Troj/GrayBrd-AX backdoor Trojan.
Windows Updates w32dns.exe
X
Added by the W32/Sdbot-BFW worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Windows Services w32edus.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Systray w32explorer.exe
X
Added by the W32/Rbot-AJY worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Visual Studio w32mvs.exe
X
Identified by VBA32 as a variant of the Backdoor.Win32.Agent.cjo malware.
A New Windows Updater w32NTupdt.exe
X
added by the W32/Mytob-AG WORM, which has IRC channel backdoor trojan functionality. ... Read More
W32PT W32PT.dll.vbs
X
Identified by Kaspersky as a variant of the Worm.VBS.Solow.a worm.
Windoxs Update Center W32RfSA.exe
X
Added by a variant of the W32/SDBOT WORM!
windows update center W32RSA.exe
X
Added by an unidentified WORM or TROJAN!
Windows Services w32service.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Services w32services.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
w32sup w32sup.exe
X
Adult content dialler
Windows Network Firewall w32svc.exe
X
Added by the W32/Sdbot.worm!811a7027 worm and IRC backdoor.
W32SYS w32sys.exe
X
Added by the W32/Jambu-A worm. W32/Jambu-A is a mass mailer for the Windows platform that also targets peer-to-peer file sharing networks and local sh ... Read More
W32Time w32t.dll
X
Added by the Backdoor.Fuwudoor backdoor.
w32tcomr w32tcomr.dll
X
Added by the WORM_STRATION.RE worm.
W32Time w32time.exe
X
Added by the Troj/Bckdr-HLO backdoor Trojan. If there is another service called W32Time it will replace it. ... Read More
Secboot w32tm.exe
X
Added by the Backdoor.Haxdoor.D backdoor. Found in the Windows system directory. ... Read More
Win32 USB2.0 Driver w32usb2.exe
X
Added by the SPYBOT.DN WORM!
win32 w32word.exe
X
Added by the Trojan.Gared Trojan that overwrites or deletes Word documents.
mjd w32_mjd.dll
X
Identified as a variant of the W32.Mimbot malware.
secboot w32_ss.exe
X
Added by the HaxDoor.B rootkit/backdoor Trojan.
Microsoftf DDEs Control w33s.exe
X
Identified as a variant of the RBot family of worms and IRC backdoors.
Pervasive.SQL Workgroup Engine W3dbsmgr.exe
U
Database Service Manager for Pervasive SQL 2000 Workgroup edition. Required if you use Pervasive SQL but it's recommended you start it manually before ... Read More
<not used> w3sskbda.dll
X
Added by the W32/Stration-AG worm.
w4y4n9 w4y4n9.exe
X
Added by the W32.Yadurna.A worm. The user is presented with a password recovery dialogue once the malicious program is downloaded. ... Read More
W7.exe Nacional W7.exe
X
Added by the Troj/Agent-ODZ Trojan.
W75P2PSERVER W75P2PS.EXE
Y
Printer utility which is required in order to make the printer work correctly
Microsoft Driver Setup w7services.exe
X
Added by the W32/AutoRun-ARJ removable media worm.
w7zip w7zip.exe
X
Added by the Troj/Bancban-PX online banking information stealing Trojan. If you are infected with this, you should contact your banks and change any ... Read More
W815DM W815DM.exe
?
??
Client agent for ARCserve W95AGENT.EXE
?
Part of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required? ... Read More
drmu W95Mm.exe
X
Homepage hijacker installing a toolbar: http://tdko.com/. Lop.com in disguise. See this thread ... Read More
w98Eject w98Eject.exe
?
Related to USB support for Sigmatel MP3 audio decoder -what does it do, and is it required? ... Read More
[random name] w?auboot.exe
X
[random name] w?auclt.exe
X
[random name] w?nlogon.exe
X
PurityScan adware variant.
[random name] w?nword.exe
X
PurityScan adware variant.
wab.exe wab.exe
X
A variant of the SDBot.bhk family of worms and IRC backdoor Trojans.
EXPLORER wab32res.exe
X
Added by the W32.Fubalca.B worm. W32.Fubalca.B is a worm that spreads through removable media and infects various file types, including .exe and .html ... Read More
TabletServiceWacom Wacom_Tablet.exe
?
Legitimate Windows service related to Wacom Tablets.
Wacom Professional Touch Service Wacom_TouchService.exe
?
Legitimate Windows service related to Wacom Tablets.
AA2014 WaDprnV7.exe
X
Added by the Attentive Antivirus rogue anti-spyware program.
Mlcr0s0ftf DDEs C0ntr0i WAed.pif
X
Added by the W32/Rbot-BJW worm and IRC backdoor.
Microsoftf DDEs Control waes.exe
X
Identified as a variant of the RBot family of worms and IRC backdoors.
Windows Advance Firewall Protection Service wafps.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Advanced GFX Devolping Software wagfxds.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
wait4ip wait4IP.exe
U
Packard Bell net2Plug allows you to network PCs anywhere in your house ... Read More
WebArmyKnife WAK.exe
N
Web Army Knife - a suite of web site developer's tools
DomPlayer Service wakeservice.exe
X
Added by the DomPlayer. DomPlayer is a potentially unwanted application that may download another program and other security risks. ... Read More
flaxen wakjs.dll
X
Zlob Trojan which installs the VirusTrigger rogue anti-spyware program. This program displays fake security alerts stating that your computer has a s ... Read More
Wakoopa Wakoopa.exe
N
Wakoopa is a new social network that, when using this software, tracks what software and games you use on your computer. This information will then b ... Read More
WinRegork Walcult.exe
X
Identified by Dr. Web as a variant of the Trojan.PWS.Banker.origin Trojan.
Windows Application Layer Gateway walg32.exe
X
Added by the W32/Agobot-AAZ worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
windows application layer walg32.exe
X
Added by the AGOBOT.ATN WORM! ... Read More
wallchgr.exe wstart Wallchgr.exe
U
Blue Tree Software ... Read More
run= wallflip.exe
?
Desktop wallpaper changer?
wallpaperchanger Wallpaper.exe
U
A wallpaper changer and manager utility. There is the Freeware version and the Pro version. The freeware version is completely free. The Pro version i ... Read More
axel wam.exe
X
Added by the W32/Melo-E worm.
Microsoft Updating WAMQUARD.EXE
X
Added by the W32/Rbot-BX trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Wanadoo Messenger.exe Wanadoo Messenger.exe
N
Wanadoo ISP instant messenger client
<not used> wandrv.exe
X
Added by the Troj/Bckdr-QHR backdoor Trojan.
Microsoft Update wangard.exe
X
Added by the W32/Rbot-LH trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
wanman.exe wanman.exe
X
A variant of the Win32/Rbot.HDO family of worms and IRC backdoor Trojans.
WanMPSvc WanMPSvc.exe
Y
An AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling ... Read More
quicken Waol.exe
X
CoolWebSearch parasite variant
WTSS wap***.exe [* = random char]
X
won update WAPDATE.EXE
X
Added by the WIN32.RBOT.N WORM! ... Read More
win update wapdate.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
WTSI wapisvit.exe
X
WTST wapisvtr.exe
X
Wapp Wapp.exe
X
Added by the Troj/Banker-EIK information-stealing Trojan for online banks. If you are infected with this file you should immediately change your onli ... Read More
war-ftpd.exe WAR-FTPD.EXE
N
War FTP Daemon from JGAA's Internet - FTP client
WARSVR war-ftpd.exe
N
"War FTP Daemon - the original free FTP server for windows"
WareOut WareOut.exe
X
Malware masquerading as a spyware and dialer remover, see here
warez warez.exe
N
Warez P2P client
ExeName32 Warm.scr
X
Added by the SCOLD WORM!
SKRSpyWarn Warn.exe
U
Added by the Smart Keystroke Recorder keylogger and surveillance software. This program should be removed if it is found on your computer without you ... Read More
0190 Warner WARN0190.EXE
X
Anti-dialer program (Germany)
0900 Warner WARN0900.EXE
X
Anti-dialer program (Germany)
Warner warner.exe
U
Also known as "CyberWarner". From G-Tek Technologies and pre-installed on some Packard Bell PCs. Protects critical files ... Read More
Warnet warnet.exe
U
Warnet - system cleanup software
WarReg_PopUp WarReg_PopUp.exe
N
Displays a popup asking you to register your Acert product.
SECURE SHELL access driver wartamd.sys
X
A variant of the Haxdoor Trojan rootkit.
wartamll wartamll.dll
X
Added by a variant of the Haxdoor Trojan family. This infection utilizes the wartamd.sys rootkit to hide itself. ... Read More
war ftpd tray icon wartray.exe
N
War-ftpd - FTP server
useful-soft wartsrv.exe
X
Added by the Troj/StartPa-WB IE startpage hijacker. This infection hijackthis your startpage to www.teengb.com. ... Read More
winantispyware 2005 was5.exe
X
WinAntiSpyware: MALWARE, posing as a spyware remover - for more information, search the Spywarewarrior_List of non-Recommended anti parasite sit ... Read More
WinAntiSpyware 2007 was7.exe
X
Added by the rogue anti-spyware program WinAntiSpyware.
was7cw was7cw.exe
X
Added by the rogue anti-spyware program WinAntiSpyware.
wasfsd wasfsd.sys
X
Trojan that create fake alerts and popups advertising rogue anti-spyware program. Though the guide below is not for this particular infection, it wil ... Read More
Washer washer.exe
U
Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Pr ... Read More
Washerie.exe washerie.exe
N
Cookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer, specific for cleaning the IE cache and cookies. Available ... Read More
washindex washidx.exe
U
Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Pr ... Read More
Index Washer WashIdx.exe
U
Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Pr ... Read More
Wast wast.exe
X
Grokster ads updater
wast wast2.exe
X
Grokster ads updater
system checking wasul.exe
X
Added by the RBOT.BHM WORM! ... Read More
Windows Activation Technologies Service WatAdminSvc.exe
Y
Microsoft service that periodically determines if your Windows Product ID is valid, and if not, displays warnings that your copy of Windows may not be ... Read More
DLHelperEXE WATCH.exe
N
Download helper distributed with some software that allows the software installation to redirect download locations. Not required once the installatio ... Read More
Eicon NetworksLAN_DAEMON watch.exe
U
Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) ... Read More
Eicon TechnologyLAN_DAEMON watch.exe
U
Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) ... Read More
Restart Watch Watch.exe
?
Associated with an Eicon Networks Diva ISDN or ADSL modem. What does it do and is it required? ... Read More
Watch watch.exe
N
Found to be used by scanners for auto starting the scanning software when the lid is lifted.  Used by various scanners, file location and command will ... Read More
Woowatch Watch.exe
N
Wanadoo ISP software, not required
Regrun2 WatchDog.exe
Y
Greatis Software's RegRun 3 Security Suite which amongst other things replaces MSCONFIG. The WatchDog check for registry changes caused by trojan's, v ... Read More
Watch Dog Program watchdog.exe
N
For Compaq PC's. Associated with Compaq's internet services. Not required if you don't use services provided by them and may not be required even if y ... Read More
Watchdog Watchdog.exe
N
Definitely part of the Mustek scanner drivers and software (for 600 III EP Plus and maybe others), launches from the Startup folder in the Start Menu, ... Read More
WatchDog watchdog.exe
?
Part of Motorola "Mobile Phone Tools" v3 - in a "Mobiile Phone Tools" sub-directory of Program Files ... Read More
LoadWatcher watcher.exe
U
Added by the Watcher surveillance software. Spyware.Watcher is a remote surveillance application that can use a computer's webcam to secretly monitor ... Read More
YOW tuner WatchPNM.exe
?
??
WATCHPNP_Xerox watchPnp.exe
U
Printer software used by Xerox printers.
WATCHPNP_Samsung watchPnp.exe
U
Printer software used by Samsung printers.
<not used> watermark.exe
X
Added by the Troj/Zbot-ADH Trojan.
Windows Account Alternation wauclt.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Generic Host wauclt.exe
X
Added by the W32/Sdbot-DNL worm and IRC backdoor.
sndpnpmix wauctlxp4.exe
X
Added by the WIN32.MUDROP.N TROJAN!
Windows Update AutoUpdate Client waucult.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Update wauguard.exe
X
Added by the RBOT.AEE WORM!
Windows Auto Update Tool wault.exe
X
Added by the W32/Tilebot-JQ worm with IRC backdoor Trojan functionality.
waults waults.exe
X
Added by the Backdoor.Bifrose.L backdoor.
system update wauluclt.exe
X
Added by the SDBOT.EF WORM! ... Read More
waumgr waumgr.exe
X
A variant of the W32/Sdbot.BNM family of worms and IRC backdoor Trojans.
Windows Guard WAUMGRD.EXE
X
Added by the W32/Rbot-GY trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
*windows update waurclt.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Antivirus wav.exe
X
Added by the Windows Antivirus 2008 rogue anti-spyware program.
mIRC Exchanger wavasdw.exe
X
Added by the W32/Sdbot-UO worm. When connected this infections connects to an IRC server where it waits for remote commands to execute. ... Read More
Bose Wave/PC Monitor wavepcmonitor.exe
N
System Tray access for this system (more info on the system here). Available via Start -> Programs ... Read More
WaveTop Launcher WaveTop.exe
N
WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in ... Read More
waxw2k waxw2k.dll
X
A variant of the Troj/Haxdor-Fam Trojan.
[not used] wb.com
X
Added by the Backdoor.Beasty.E backdoor. This backdoor listens on port 666.
[not used] wb.com
X
Added by the Backdoor.Beasty.F backdoor. This backdoor listens on port 666.
Webcam Go Sti Service Application wbcgosvc.exe
?
Control software for the portable Creative Video Blaster Webcam Go digital camera/PC web cam. What does it do and is it required? ... Read More
djuka wbchha.dll
X
Zlob Trojan that infects you with the VirusHeat rogue anti-spyware program. Please use the guide below to remove this infection. ... Read More
Wbcmgr wbcmgr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Messenger Panel wbcsvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F} wbeconm.dll
X
Added by the Adware.TopAV which replaces the Windows wallpaper with a fake virus alert message containing links to topantivirus.biz or Spyaxe and issu ... Read More
Server Runtime Process wbemstest.exe
X
Added by the W32/Sdbot-DDB worm and IRC backdoor.
Wbiff Wbiff.exe
N
Wbiff! E-mail checker - automatically checks your e-mail and notifies you if any new e-mail has been received ... Read More
{10388970-0592-BCC4-1BCB-3147DA75A2F6} wblinds.exe
X
A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote serv ... Read More
WindowBlinds wbload.exe
U
WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object De ... Read More
wbqxfpgl wbqxfpgl.dll
X
Added by the VAC, or Trojan.Win32.Vapsup.kfp Trojan.
WinBackup Scheduler Wbsched.exe
U
LIUtilities WinBackup scheduler - backup software
wbsecsvc wbsecsvc.exe
?
Winbond Seurity Support Service related to Winbond Wireless LAN Adapters.
twhe wbta.exe
X
PurityScan delivers advertisements to your computer.
Wbutton Wbutton.exe
?
Related to the Wacom Penabled driver on Acer Tablet PCs. Appears to do nothing so is it required? ... Read More
Video Camera Frog wcamfrog.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MSMSGNER wcbi.exe
X
Added by the Troj/Bckdr-QMS backdoor Trojan.
OWCWebCamDV wcdvtray.exe
U
WebCamDV from Orange Micro, Inc - enables the user to use a DV camera connected via Firewire as a Webcam ... Read More
WCESMngr WCEMNGR.EXE
X
The W32/Agobot-QX WORM/backdoor Trojan adds this, modifying the HOSTS file and terminating security-related/anti-virus processes also. ... Read More
ActiveSync wcescom32.exe
X
Added by the Troj/MancSyn-E Trojan.
H/PC Connection Agent WCESCOMM.EXE
U
Active sync for use with Windows CE based palm PC
WCESCOMM WCESCOMM.EXE
N
Active sync for use with Windows CE based palm PC
Windows Client Login Identafacation System wclis.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
stardust wallpaper control 2003 WCMain.exe
N
Related to Stardust_Software Screen Saver Control 2003 ... Read More
Woods Inc wcmd.exe
X
Added by the Troj/KillFil-O Trojan.
wcmdmgr wcmdmgr.exe
N
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note th ... Read More
wcmdmgr wcmdmgrl.exe
U
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note th ... Read More
wcmdmgrl wcmdmgrl.exe
U
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note th ... Read More
WildTangent Web Driver updater wcmdmgrl.exe
U
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note th ... Read More
Windows Connection Extension wcmsvc.exe
X
A variant of the SDBot family of worms and IRC backdoor Trojans.
Micsorosft Security Center wcnsfty.exe
X
Added by the W32/Rbot-AHU worm. When infected your computer will become an open mail relay which will allow your computer to be used to send out spam. ... Read More
Windows Logical Connection wcnsvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
system32 wcntfy.exe
X
Added by the Troj/Banker-CSY Internet banking Trojan. If you have this infection you should immediately change all of your online banking account inf ... Read More
WINT wcp****.exe [* = random char]
X
WINT wcpcc.exe
X
Registry Integritycheck WCPDT.EXE
X
Added by the W32/Agobot-RF WORM.
WINT wcpsvit.exe
X
some wcs.exe
X
Identified as a variant of the Adware/Netproject malware. Typically bundled with rogue anti-spyware programs and fake codecs. ... Read More
smile wcs.exe
X
Identified as a variant of the FakeAlert/Zlob malware.
hyperproduction wcscqa.dll
X
Zlob Trojan that infects you with the VirusHeat rogue anti-spyware program. Please use the guide below to remove this infection. ... Read More
Microsoft Update Services wcsnfty.exe
X
Added by the W32/Rbot-AGK worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft wcsntfy.exe
X
Added by the W32/Agobot-AHT worm and IRC backdoor.
Windows Client/Server Runtime Server Subsystem wcsrss.exe
X
Added by the W32/Tilebot-DA worm and IRC backdoor.
wcsys wcsys.exe
X
Added by the Troj/Keylog-AP keylogging Trojan.
Microsoft Intrenet Explorer wcumrg.exe
X
Added by the W32/Sdbot-AFD worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
wnxpupdate wcupshell.exe
X
Added by the W32/Combra-I mass-mailing worm.
Worm Detector wd.exe
U
Worm Detector - antivirus add-on for Outlook 2K or XP for handling worms and spam ... Read More
Windows Defender Adds wda*.exe
X
A variant of the Trojan.Fakealert malware. This infection displays fake Windows Defender alerts which link to spyware-kicker.com. ... Read More
WD Button Manager WDBtnMgr.exe
U
Button manager installed with a western digital external disk drive. Allows you to back up your system with one click ... Read More
Windows Defender wdc*.exe
X
A variant of the Trojan.Fakealert malware. This infection displays fake Windows Defender alerts which link to spyware-kicker.com. ... Read More
Wdc Wdc.exe
U
Added by the Spyware.Watchdog surveillance software. Spyware.WatchDog is a spyware program that logs keystrokes. It monitors Instant Messenger convers ... Read More
wdcs wdcs.exe
X
A variant of the W32/SDBot.AWGW family of worms and IRC backdoor Trojans.
{4F12545B-1212-1314-5679-4512ACEF8904} wddpri.dll
X
Added by the Troj/QQPass-AOZ Trojan.
WinDefender 2008 WDefDemo.exe
X
Added by the WinDefender 2008 rogue privacy program.
microsoft web device wdevice.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
windows dll loader wdevice.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Webroot Desktop Firewall WDF.exe
Y
wdfmgr32 wdfmfr32.exe
X
Added by the Troj/Pindow-A downloader Trojan.
MS_Update Check wdfmgr.exe
X
Added by the W32/Agobot-TB worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
wdfmgr.exe wdfmgr.exe
X
A variant of the Backdoor.Win32.SdBot.bti family of worms and IRC backdoor Trojans. ... Read More
TBMonEx wdfmgr.exe
X
Added by the W32/MumaWow malware.
TBMExe wdfmgr.exe
X
Added by the W32.Notong.A virus. W32.Notong.A is a virus that spreads by infecting executable files. ... Read More
wdfmgr32 wdfmgr32.exe
X
Added by the Troj/Dloadr-AOT Trojan.
Windows User Mode Driver Manager wdfmrg.exe
X
Added by the W32/Sdbot-ZN worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
micromedia flash update wdfmrg.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Webroot Desktop Firewall network service wdfsvc.exe
Y
Related to the Webroot Desktop Firewall.
Microsoft MicroP Protocol wdgmr32.exe
X
Added by a variant of the WIN32.RBOT WORM!
WDInfo wdinfo.exe
X
Adult content dialler
MSN wdlrss.exe
X
Identified as a variant of the Backdoor.Win32.SdBot.cwm worm and IRC backdoor.
Windows Defender Monitor wdm*.exe
X
A variant of the Trojan.Fakealert malware. This infection displays fake Windows Defender alerts which link to spyware-kicker.com. ... Read More
wdmon wdmon.exe
X
Added by the Infostealer.Ldpinch Trojan. Infostealer.Ldpinch is a password-stealing Trojan horse that attempts to steal information from an infected c ... Read More
WINDOWS SYSTEM wdns33.exe
X
Added by the W32/Mytob-BY worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
WDNS SYSTEM wdns33.exe
X
Added by the W32/Mytob-BY worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
wdpoefan wdpoefan.dll
X
Identified as a variant of the Adware.Agent malware.
Win32 DRK Driver wdrk32.exe
X
Added by the WOOTBOT.CY WORM!
Windows Startup Wdrun32.exe
X
Added by the GAOBOT.AO WORM!
IE-Security wdscan.exe
X
Added by the IE-Security rogue anti-spyware program.
wdskctl wdskctl.exe
X
IEPlugin spyware
vbc wdt.exe
X
Added by the Mal/MsilDyn-L malware.
Windows Taskmanager wdtsvc.exe
X
Unknown malware.
Windows Defender Updater wdu*.exe
X
A variant of the Trojan.Fakealert malware. This infection displays fake Windows Defender alerts which link to spyware-kicker.com. ... Read More
windvrctrl WDVRCtrl.exe
Y
Driver task installed by the drivers for some TV capture cards; no further information available, so best left alone. ... Read More
wdwctrl wdwctrl.exe
X
Added by the DLUCA.E TROJAN!
http://www.lienvandekelder.be We Love Lien Van de Kelder.exe
X
Added by the W32/Mytob-CV email worm and backdoor IRC trojan.
Enterprise Suite WE345d.exe
X
Added by the Remove Enterprise Suite (Uninstall Guide) rogue anti-spyware program. ... Read More
Windows Enterprise Suite WE83b.exe
X
Added by the Windows Enterprise Suite rogue anti-spyware program.
WEATHER WEATHER.EXE
N
Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs ... Read More
WeatherCast Weather.exe
N
Weather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight ... Read More
Daily Weather Forecast WEATHER.EXE
X
Added by Troj/Dloader-IP TROJAN to the Windows program folder.
Tray Temperature Weatherbug.exe
N
Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs ... Read More
windows java update weatherBug32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
WeatherEye WeatherEye.exe
N
The Weather Network's taskbar weather monitoring software.
WeatherOnTray WeatherOnTray.exe
X
Hotbar's Weather Forecast tool for your desktop - adware
weatherscope Weatherscope.exe
X
WeatherScope software - bundles Gain/Gator adware ... Read More
MS-Connect web.exe
X
Adult content dialler - see here
UPSUtl web.exe
X
CoolWebSearch parasite variant
web2pop Web2Pop.exe
U
Web2Pop allows you to retrieve your web-based accounts messages to read them in your favorite e-mail client. ... Read More
web3trap web3trap.exe
Y
PC-Cillin 2000 anti-virus software -> ActiveX filter. Guards against malicious ActiveX programs, etc  ... Read More
Website Administrator Info webadmin.exe
X
W32/Forbot-FY will connect to an IRC server and establish a new service named "Connection Reset", with the display name "Website Administrator Info". ... Read More
Connection Reset webadmin.exe
X
A new service is set by W32/Forbot-FY with a display name of "Website Administrator Info" ... Read More
webalize webalize.exe
X
Searchcentrix hijacker
webassist webassist.exe
X
Adware popup generator
WebBuying Webbuying.exe
X
Added by the Adware.Webbuy adware. Adware.Webbuy is a Browser Helper Object that displays advertisements. ... Read More
WebCake Desktop WebCakeDesktop.exe
X
WebCake adware that display ads in search result pages.
WebCakeUpdater WebCakeDesktop.Updater.exe
X
WebCake adware that display ads in search result pages.
webcam webcam.exe
X
Added by the Troj/Monad-A backdoor Trojan.
WebcamRT.exe WEBCAMRT.exe
N
For Logitech Web Cams. Not required - camera works fine without it
icqbeta webcamupdate.exe
X
Added by an unidentified TROJAN!
Webcelerator webcel.exe
X
Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if yo ... Read More
System Update2 webcheck.exe
X
Added by the AUTOTROJ-C TROJAN!
WebCheck WebCheck.pif
X
Added by the CONE.C or CONE.F WORMS!
Mobipocket Web Companion webcomp.exe
U
Installed by Mobipocket Reader to create readable documents from RSS or eNews feeds on the web. ... Read More
WebConfig WebConfig.exe
X
An adware detected by ESET Anti-virus as a variant of the Win32/Adware.Smarthink.A malware. ... Read More
Microsoft CP Web Manager webcp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Web CP Manager webcp32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WebCpr0 WebCpr0.exe
X
Webdav.exe webdav.exe
X
IRC DDoS bot which gives the hacker full control over your system
WindowsUpdate webdev.exe
X
Added by the Troj/Agent-RYU Trojan.
Win32Host Process webemir.exe
X
Added by the Troj/Turgen-A password-stealing trojan.
Cyclope Internet Filtering Proxy WebFilterAccess.exe
Y
Related to the Cyclope Internet Filtering Proxy Internet site and content filtering software. ... Read More
WebInstall WebInstall.exe
X
ClipGenie adware downloader
WebInstall2 WebInstall.exe
X
ClipGenie adware downloader
WebKey WebKey.exe
N
WebKey from JB Utilities. Utility to keep track of login data required when browsing the internet ... Read More
weblink WebLink.exe
N
Softex WebLink is a "cost-effective way to provide software updates, technical support or new product information to specific end-users - it can sile ... Read More
Microsoft Update webm.exe
X
Added by the SDBOT.WK WORM!
1wincfg32 WebMailSpy.exe
X
Added by WebMailSpy SPYWARE! ... Read More
Microsoft web update webmsn.exe
X
Added by the W32/Rbot-EMQ worm and IRC backdoor.
Web Live Information Messenger webmsn.exe
X
Added by the W32/Sdbot-CWA worm and IRC backdoor.
mobiswing webp.exe
X
Identified by Kaspersky as a variant of the AdWare.Win32.Agent.bzo malware.
WEP Manager for NT webpmgr.exe
X
Added by the WORM_QQPASS.A worm.
WebPrint webprint.exe
X
Added by the Troj/Bckdr-QHH backdoor Trojan.
Printer Monitor webprinter.exe
X
A TROJAN, Troj/IRCBot-Z adds this file to the Windows system folder.
WebRebates0 WebRebates0.exe
X
WebRebates adware
websaverlive websaverlive.exe
U
WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your ... Read More
WebSavingsFromEbates0 WebSavingsFromEbates0.exe
X
Web Savings From Ebates Software, a shopping tool that opens pop-up windows
WebSavingsfromEbates WebSavingsfromEbatesrun.exe
X
Web Savings From Ebates Software, a shopping tool that opens pop-up windows
McAfeeWebscanX WebScanX.exe
Y
From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guar ... Read More
WebScanX WebScanX.exe
Y
From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guar ... Read More
WebSecureAlert WebSecureAlert.exe
X
WebSecureAlert. "Can help protect your browser security and privacy". However, it's by GAIN Publishing, and will display pop up ads on your computer s ... Read More
WebShell webshell.dll
X
Added by the Backdoor.Bebshell Trojan horse with backdoor capabilities.
Webshots Webshots Tray.exe
N
Screensaver program that automatically downloads from the webshots web site
Webshots websho~1.exe
N
Screensaver program that automatically downloads from the webshots web site
Microsoft Windows Express websploit.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
WebSpyShield WebSpyShield.exe
X
Added by the WebSpyShield rogue security software. WebSpyShield is a misleading application that may give exaggerated reports of threats on the comput ... Read More
websrvx websrvx.exe
X
Added by the WORM_KOOBFACE.EY worm.
microsoft updating client websvc.exe
X
Added by the RBOT.AQ WORM! ... Read More
Windows Web Services websvc.exe
X
Added by the Troj/Dloader-NY trojan.
WebTime WebTime.exe
X
Added by the Troj/SleepSrv-A Trojan.
WebTime WebTime.exe
N
Added by the WebTime time synchronization program. WebTime 2000 is a small utility program that will synchronize your PC's internal clock with one of ... Read More
ChicoSys webtmr.exe
U
Added by the Child Control parental control software.
Webtrap webtrap.exe
Y
Part of PC-Cillin anti-virus software. Checks web-sites for malicious Java and ActiveX elements in a similar way to McAfee WebScanX. A few users find ... Read More
WebTrapNT.exe WebTrapNT.exe
Y
Part of PC-Cillin Anti-Virus software. Checks visited web-sites for malicious Java and ActiveX elements ... Read More
webwork webwork.dll
X
Added by the Webwork downloader/updater DLL which is known to download and install advertising software. The adware applications Boran and Yokgug may ... Read More
Windows Services weccom.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Event Detection wecsvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
microsoftf ddes control wees.exe
X
Added by a variant of the the RBOT.BOF WORM! ... Read More
weirdontheweb WeirdOnTheWeb.exe
X
Added by the Adware.WeirdOnTheWeb ... Read More
SystemTray wekls4.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Welcome Welcome.exe
N
Launches the Welcome to Windows tutorial on boot up
wemwpxpjdb wemwpxpjdb.exe
X
Added by the Troj/Agent-GQB Trojan.
WEPstat Wepstat.exe
?
Cisco Aironet 340 Series PC Card driver. If it can be started manually it shouldn't be required if you don't use the PC card facility regularily - hen ... Read More
werasqlp werasqlp.cur
X
Added by the Backdoor.Rustock backdoor rootkit.
AvpWx WErcx.exe
X
Identified by Kaspersky antivirus as a variant of the Backdoor.IRC.Agent.a malware. ... Read More
Application Layer Gateway WeRecl.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Application Layer Service weRecv.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Service System wernell87.exe
X
Added by the Troj/Bancos-FJ Internet Banking Trojan. If you have this infection you should change the passwords to all your online banking accounts. ... Read More
wetkadmr wetkadmr.dll
X
Identified as a variant of the Adware.Agent malware.
WetSock wetsock.exe
N
RoboMagic Wetsock - weather reporting in the System Tray
Windows Event Log wevtsvc.dll
Y
This service manages events and event logs. It supports logging events, querying events, subscribing to events, archiving event logs, and managing eve ... Read More
WinFire WF.exe
X
Added by the Troj/Delf-SY keylogging Trojan.
Winfast_2K WF2k.exe
U
System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start ... Read More
WinFoxV2 WF2k.exe
U
System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start ... Read More
rndc test wf32b.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
RNBz Test wf32vbc.exe
X
Added by the W32/Rbot-AEY worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
RNBc Test wf32vbs.exe
X
Added by the W32/Rbot-AGR worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
{9af8f31b-b778-4413-b8ed-ae63a62e1f7d} wfcof.dll
X
Zlob Trojan that installs VirusProtectPro 3.3 and shows fake security alerts from your Windows taskbar. ... Read More
LSA wfdmgr.exe
X
Added by the W32/MyDoom-BG WORM! File is found in the Windows system folder.
Windows File XP Manager wfdmgr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Default Server wfdmgrsp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
wfexqnrp wfexqnrp.dll
X
Identified as a variant of the VideoAccessCodec adware.
WFGStartup WFGStartup.exe
N
World Weather. "This midlet displays the current weather conditions for major cities around the world. This version is for memory limited mobile phone ... Read More
windows sp2 firewall wfirewall7.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
{0c7416f0-dd23-420f-97f5-aae352ea2bf1} wfkduei.dll
X
A file used by the rogue antispyware app, SpywareQuake, to issue fake security alerts on your taskbar. ... Read More
WFPService WFPService.exe
U
Added by Microsoft's Windows Feedback Program utility.
Windows Firewall Service wfsvc.exe
X
Added by the W32/IRCBot-YL worm and IRC backdoor.
Microsoft Update Machine wftestb.exe
X
Added by the W32//Rbot-AFZ worm. When started, this infection connects to an IRC server where it waits for remote commands to execute. ... Read More
Windows File Verification Service wfvs.exe
X
Identified as a variant of the Backdoor.Ranky malware.
WinFast Schedule Wfwiz.exe
U
Leadtek WinFast TV tuner scheduler
Windows Firewall Exception List Management Subsystem wfwmss.exe
X
Added by the Troj/Ranck-EH HTTP proxy server Trojan.
winfixer 2005 wfx5.exe
X
"Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here ... Read More
Controller WFXCTL32.EXE
N
From Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and display ... Read More
WFXCTL32.EXE WFXCTL32.EXE
N
From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displa ... Read More
WinFax PRO Controller WFXCTL32.EXE
N
From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displa ... Read More
winfixer helper wfxcwr.exe
X
WinFixer web installer - Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, generall ... Read More
WindowFX wfxload.exe
U
Stardock WindowFX - "Allows you to add an unprecedented number of special effects to windows" ... Read More
Device Manager wfxmgr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
wfxsnt40 wfxsnt40.exe
Y
WinFax 10.0 and maybe earlier versions. The program that opens the port for WinFax and not normally in the start menu. Needed if you want to run WinFa ... Read More
WinFaxAppPortStarter wfxsnt40.exe
Y
WinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application. ... Read More
WinFax PRO WFXSVC.EXE
U
This service handles many of the automated tasks of Winfax Pro such as receiving faxes. Disabling this service will impair the functioning of this pr ... Read More
WFXSwtch WFXSWTCH.exe
U
Related to WinFax. Allows you to use Winfax as a virtual printer so that you can print directly to the application. ... Read More
wise-ftp scheduler WF_Scheduler.exe
U
WISE-FTP file transfer software scheduler ... Read More
NETGEAR WG111v2 Smart Wizard WG111v2.exe
N
Setup and diagnostics program for the Netgear WG111v2 wireless USB adapter.
NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver wg111v2.sys
Y
Driver for the Netgear WG111 USB wireless adapter.
WG511WLU WG511WLU.exe
Y
Netgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card ... Read More
{10388970-0592-BCC4-1BCB-3147DA75A2F6} wga.exe
X
A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote serv ... Read More
microsoft updates 2 usb wgafixer.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
WgaLogon WgaLogon.dll
Y
This file is a legitimate Windows oeprating system file. It used as part of Windows Genuine Advantage and alerts when you are using an unvalidated Mi ... Read More
Windows Genuine Advantage Registration Service wgareg.exe
X
Added by the W32/Cuebot-L worm and IRC backdoor.
<not used> WgaTrays.exe
X
Added by the W32.SillyDC worm.
Windows Genuine Advantage Validation Monitor wgavm.exe
X
Added by the W32/Cuebot-M worm and IRC backdoor.
Windows Genuine Advantage Validation Notification wgavn.exe
X
Identified as W32/Cuebot-K instant messaging worm and IRC backdoor.
Microsoft Updates wgcptsud.exe
X
Added by the W32/Rbot-GTF worm and IRC backdoor.
wgeax wgeax.exe
X
Added by the W32/IRCBot-TM worm and IRC backdoor.
WinGate Engine Monitor wgengmon.exe
U
WinGate Internet Client Dialup Monitor - component of WinGate proxy server software. Displays the status of the WinGate engine, and appears in the sys ... Read More
Winguard WGFE95.EXE
Y
Dr Solomon's Virex antivirus
Windows Service Agent wgl23.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
WinGuard Pro wgp.exe
U
WinGuage Pro WGPRO32.EXE
N
Part of McAfee Nuts & Bolts. "WinGauge is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to ... Read More
Microsoft UpdateS Machine wgrd.exe
X
Added by the W32/Rbot-FI trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This ... Read More
wgs3 wgs3.exe
X
Added by the Troj/LegMir-AQH password-stealing Trojan.
_WGAw WgsDisp.exe
X
Added by the Troj/Small-CSJ Trojan.
WGWLocalManager WGWLocalManager.exe
U
Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performan ... Read More
NettGain2000 WgwMngr.exe
Y
Required for Starband satellite service.
WebHancer Agent whagent.exe
X
System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find ... Read More
whagent whagent.exe
X
System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find ... Read More
WhatPulse WhatPulse.exe
U
WhatPulse sends statistics on how much you type on your computer and ranks you based on that. It does not log your keystrokes, but only the counts of ... Read More
[Various Names] WhatsNewBot.exe
X
Part of the Wareout infection as described here.
Whistler whismng.exe
X
Added by the Troj/Whistler-F. It also creates a file at C:WXP to copy over other files and deletes files. ... Read More
Whitman Software whitsoft.exe
X
Added by the W32/Rbot-AUB worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
WhenUSearchWHSE whse.exe
X
SaveNow adware
webHancer Survey Companion whSurvey.exe
X
WebHancer foistware - traffic measurement service that uses a client agent that is stealth installed on user machines, gathering detailed data about s ... Read More
Whvlxd Whvlxd.exe
X
Added by the W32.LXD.MIRC TROJAN!
Microsoftf DDEs Control why-.exe
X
Added by the W32/Rbot-AMV worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
wupdate wi32.exe
X
Added by a new variant of Trojan.Abwiz.
Additional Guard WI339.exe
X
Added by the Additional Guard rogue anti-spyware program.
Windows Protection Suite WI345d.exe
X
Added by the Windows Protection Suite rogue anti-spyware program.
Windows Additional Guard WI345d.exe
X
Added by the Windows Additional Guard rogue anti-spyware program.
mspp system update 64 wiaadmgr.exe
X
Reported by Kaspersky Anti-Virus as Trojan-Proxy.Win32.Ranky.gen.
Windows Image Acquisition (WIASC) WIAcs.exe
X
A variant of the Backdoor.Rizo.A backdoor worm.
Windows Image Acquisition (WIASSC) WIAcss.exe
X
A variant of the Backdoor.Rizo.A backdoor worm.
MS NET Service wiadss.exe
X
Identified as a variant of the Net-Worm.Win32.Kolabc.b worm.
{C1A2FDA2-2A5B-2C8A-F2A2-BA2DB3A2C31C} wiatwain.dll
X
Added by a rogue antispyware program who's affiliates install files that replaces the Windows wallpaper with a fake virus alert message and issues fak ... Read More
Windows Input Service wibsvc.exe
X
A variant of the Backdoor.Win32.SdBot.bzc family of worms and IRC backdoor Trojans. ... Read More
WinDefender wicfte.exe
X
Added by the Troj/Scar-AG Trojan.
Windows Icons Manager wicomgr.exe
X
Added by the W32/Rbot-AIF worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Winsock2 Loader WICONF.EXE
X
Added by the W32/Sdbot-LC worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
WINDOWS ID SYSTEM wID32.exe
X
Added by the W32/Mytob-FA worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. ... Read More
blah service. widows.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
widuxngq widuxngq.sys
X
Added by the Backdoor.Rustock backdoor rootkit.
wifeman wifeman.exe
X
Unidentified malware
Wifi Boot wifiboot.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Booter wifibooter.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Connection wificon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Configuration wificonfig.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Configuration! wificonfigs.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Connection! wificonnect.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Debug wifidebug.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Loader wifiload.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Loader! wifiloader.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WAWifiMessage WiFiMsg.exe
?
Wireless utility bundled with HP laptops. Anyone know if this is required?
Wifi Setup wifisetup.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WSWNA3100 WifiSvc.exe
Y
Part of the driver for the Netgear N300 Wireless USB Adapter.
system wiinlogon.exe
X
Added by the W32/Rbot-AVG ... Read More
Windows Database wiinsvc.exe
X
Added by the W32/Agobot-RU. When started this infection connects to an IRC server where it waits for remote commands. It can log key strokes, list o ... Read More
Microsoft Update 32 wiit.exe
X
Added by the W32/Rbot-AMS worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
WildFlics WildFlics.exe
X
Added by the Dial/Direct-B premium rate dialer.
Willow Road WillowRoad.exe
N
Willow Road Screen Saver
Microsof Winlog Host wilogon32.exe
X
Added by the RBOT.XC WORM!
Module WinMeter wimmtre.exe
X
Added by the W32/Sdbot-BE backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execut ... Read More
iRiS AntiVirus Active Monitor WIMMUN32.exe
N
Iris Antivirus - discontinued, replace with good alternative
Microsoft Windows Media Player wimp.exe
X
Added by the RBOT-FN WORM!
Miosf Update wimsqaad.exe
X
Added by the SDBOT.AG TROJAN!
Win Antivir 2008 Win Antivir 2008.exe
X
Added by the Win Antiv 2008 rogue antivirus program.
Win Antivirus 2008 Win Antivirus 2008.exe
X
Added by the Win Antivirus 2008 rogue antivirus program.
Hrxmp Win Const.exe
X
win_supp00.exe Win Const.exe
X
Added by the Troj/Assasin-H Trojan.
WIN HOST PROCESS WIN HOST PROCESS.EXE
X
Added by the KEYLOGGER.CLONE TROJAN!
win***32 win***32.dll
X
Added by the Trojan.Nebuler Trojan. Trojan.Nebuler is a Trojan horse that attempts to download and execute files from remote sites. It also sends info ... Read More
Sys29 win***32.exe [* = random char]
X
EliteBar adware
SysA win***32.exe [* = random char]
X
EliteBar adware
WIN-BUGSFIX WIN-BUGSFIX.EXE
X
Added by the LOVELETTER (I LOVE YOU) VIRUS!
microsoft windows update logon win-logon.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft Update win-mang.exe
X
Added by the W32/Rbot-AFK worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Sistray32 win.bat
X
The W32/Jupir-A is spread via MIRC. The file can be found in the Windows system directory. ... Read More
Microsoft Synchronization Manager win.exe
X
Added by the SDBOT.AK WORM!
Remote Procedure Calls win.exe
X
Added by the SDBOT-QI WORM!
Winhost win.exe
X
Added by the DLOADER-AP TROJAN!
Distributed File System win.exe
X
Added by the W32/Myfip-L WORM, which also creates a new service/displayname called Distributed Link Tracking Extensions. ... Read More
System Information Manager win.exe
X
Added by the W32/Sdbot-MU worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
runing win.exe
X
Added by the Troj/Delf-LC Trojan.
WinLoad win.exe
X
Added by the Troj/Asb-A backdoor Trojan.
WinXP win.exe
X
Added by the Troj/Gaduka-G backdoor Trojan.
Windows LoL Layer win.exe
X
Added by the W32/Rbot-FTO worm and IRC backdoor.
Win Critical File win.exe
X
A variant of the W32/IRCbot.BGA.worm family of worms and IRC backdoor Trojans.
smsger Win.exe
X
A variant of the W32/SDBot.BGIU family of worms and IRC backdoor Trojans.
Windows32 win.exe
X
Added by the Troj/Banker-EKI Trojan.
Winsock2 driver win.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Winexec32 win.exe
X
Added by the Troj/Banker-ELQ information stealing Trojan for online banking.
Winsock driver win.exe
X
A variant of the W32.Spybot.Worm family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
regdiit win.exe
X
Added by the W32/VBSAuto-A worm and IRC backdoor.
CTFMON win.exe
X
Added by the VBS.Runauto.G worm. VBS.Runauto.G is a worm that spreads through removable drives and network shares. The worm also opens a back door on ... Read More
WINDOWS SYSTEM win.exe.exe
X
Added by the W32.Mytob.FA@mm worm. When started, this infection connects to a remote IRC server and waits for commands to execute. ... Read More
Syscheck win.hta
X
Browser hijacker
run= win.ini
?
??
Windows Security win.pif
X
Added by the W32/Rbot-APT worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
REPCLIENT1 win.pif
X
Added by the W32/AutoRun-DO removable media worm.
vbe win.vbe
X
Added by the Bat/LoseSlp-A worm.
windows 128 module win128.exe
X
Added by the W32/FORBOT-ES WORM! ... Read More
Win Microsoft 98 win14.exe
X
Added by the W32/Rbot-AKX worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
srv32win win16dll.exe
U
Screenspy captures screenshots silently. If you didn't install this yourself, remove it. ... Read More
win16.dll win16dll.exe
U
Screenspy captures screenshots silently. If you didn't install this yourself, remove it. ... Read More
KAVFOX win1ogoin.exe
X
Added by the Troj/GWGhost-M key logging Trojan.
SystemKey WIN2000.EXE
X
Added by the Troj/QQify-A. It also copies itself as nsconfig.exe, msconfig.exe, regedita.exe and regedit.exe to %Windir%. ... Read More
win23.exe win23.exe
X
A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote serv ... Read More
win24 win24.exe
X
Added by the WORM_KIDALA.A network worm.
MStask win2sys.dll
X
Added by the Troj/Dropper-BS dropper Trojan.
Microsoft Intranet WIN31.EXE
X
Added by the W32/Rbot-FD trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This ... Read More
Sygate Personal Firewall win31243.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
mcafee Win32.dll.vbs
X
Added by the W32/Catcher-B worm. W32/Catcher-B spreads by copying itself to the root of all mapped drives. ... Read More
WIN32 WIN32.EXE
X
Added by the RATEGA TROJAN!
Win32 Win32.exe
X
Added by the ISRAZ.A and the W32/Mytob-AB WORMS!
win32.exe win32.exe
X
Added by the STARTPAGE TROJAN!
winprotect win32.exe
X
Added by the MUGLY.E WORM!
Microsoft SpA Service win32.exe
X
This is a SDBot variant backdoor infection. When run this infection connects to an IRC server, d-3.biz. ... Read More
DNS Config service win32.exe
X
Added by the W32/Rbot-TL WORM/IRC backdoor trojan!
wupd win32.exe
X
Added by the Troj/Orse-C trojan.
registry oidet win32.exe
X
Added by the RBOT.BMT WORM! ... Read More
Microsoft win32.exe
X
Added by the Backdoor.Darkmoon backdoor Trojan. It also adds the following files as part of the infection:

%System%\Yxgunlzu.d1l
% ... Read More
Blah Service win32.exe
X
Added by the W32/Rbot-AXO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
windows_update win32.exe
X
Added by the TROJ_SMALL.FAR Trojan.
startkey win32.exe
X
Added by a variant of the Backdoor.Bifrose family of Trojans. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a ... Read More
Win32 Critical File Win32.exe
X
Added by the W32/Rbot-GUB worm and IRC backdoor.
Microsoft Update win32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
auto win32.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Small.hpb malware.
win32 socket win325b.exe
X
Added by the W32/Tilebot-GE worm and IRC backdoor.
(*)Run win32API.exe
X
Homepage hijacker. (* = any digit)
windows system 32-bat service win32bat.exe
X
Added by the W32.Mytob.FI(AT)mm ... Read More
WindowsMessenger win32boot.exe
X
Added by the W32/Tilebot-GF worm and backdoor Trojan.
Windows Core Kernel Update win32bootcfg.exe
X
Added by the Troj/Ranck-EL proxy Trojan.
WinReg win32cfg.exe
X
Added by the Troj/Sdbot-CR backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execu ... Read More
msupdates win32chk.exe
X
A variant of the Backdoor.Win32.SdBot.aad family of worms and IRC backdoor Trojans. ... Read More
win32clf win32clf.exe
X
Added by an unidentified VIRUS, WORM or TROJAN!
win32client win32client.exe
X
Added by the Troj/Restarter trojan.
Microsoft Windows Config 32 win32conf.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
NTSF MICROSOFT SYSTEM win32db.exe
X
Added by a variant of the RBOT WORM!
win32 debug manager Win32Debug.exe
X
Added by a variant of the W32/WOOTBOT WORM! ... Read More
win32debug win32debug.exe
X
Added by the W32.Gudeb worm.
Win32dll Win32dll.exe
X
Added by the BANPAES TROJAN!
Services32 Startup win32dll.exe
X
Added by the W32/Sdbot-XO. When started this infection connects to an IRC server where it waits for remote commands, able to steal CD game keys, pe ... Read More
winconfig.exe win32dll.exe
X
Added by the W32/Kassbot-P worm and IRC backdoor.
Zone Labs Client win32dll.exe
X
Added by the Trojan.Syginre Trojan. Trojan.Syginre is a Trojan horse that disables the Windows Firewall and may delete some files from the compromised ... Read More
MSN win32dll.exe
X
Added by the Troj/Jenny-A Trojan.
Sysctrls win32dll.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Win32DLL Win32DLL.vbs
X
Added by the LOVELETTER (I LOVE YOU) VIRUS!
windows 32 editor Win32edit.exe
X
Added by the WOOTBOT.GQ WORM! ... Read More
service win32ev.exe
X
Added by the Troj/Bckdr-QKR backdoor Trojan.
winbin32 win32exe.exe
X
Added by the W32/Rbot-ZL WORM/IRC backdoor!
load= win32exec.exe
X
Added by the BITTER WORM!
Configuration Loader win32exec.exe
X
Added by the W32/Sdbot-LA worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
blah service win32exec.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
win32gb win32gb.exe
X
All-In-One-Telcom (adult content dialler) variant
Win32 Help32 Service win32help.exe
X
Added by the W32/Delbot-U worm and IRC backdoor.
Windows Logon Application win32help.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Runtime Help win32hlp.exe
X
Added by a variant of the AIMVISION TROJAN!
Win32 Kernel Update win32host.exe
X
Added by the W32/Tilebot-FE worm and IRC backdoor.
startkey win32i.exe
X
Added by the Troj/Bifrose-R Trojan.
WINDOWS SYSTEM Win32IMAPSVR.exe
X
Added by the W32/Mytob-FQ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
win32info win32info.exe
X
Adult content dialler
<not used> win32ipzip.dll
X
Added by the Trojan.Goldun Trojan.
win32k.sys win32k.sys:1
X
The ZeroAccess rootkit. This rootkit terminates any program that scans its processes or files and then changes the permissions on them so you can no ... Read More
win32k.sys win32k.sys:2
X
The ZeroAccess rootkit. This rootkit terminates any program that scans its processes or files and then changes the permissions on them so you can no ... Read More
Win32 Device Loader Win32ldr.exe
X
Added by a variant of the AGOBOT/GAOBOT WORM!
Microsoft Standard Executions Library win32lib.exe
X
Added by the W32/Rbot-AUK worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
win_shell win32lib.exe
X
Added by the W32/Bagle-DO mass-mailing and peer to peer worm.
win32napp win32napp.exe
X
Added by the W32/Smelles-A virus.
Winnup win32nls.exe
X
Added by a variant of the SPYBOT WORM!
[unknown] WIN32OP.EXE
X
Added by the W32/SdBot-U worm. When started, this infection connects to a remote IRC server and waits for commands to execute. ... Read More
Microsoft Plug n Play win32pnp.exe
X
Added by the W32/Mytob-GW worm and IRC backdoor.
Windows 32 Rescue win32resc.exe
X
Added by the W32/Forbot-EU worm. When started this infection connects to an IRC server where it waits for remote commands to executed. ... Read More
Windows 32 Rescue win32resc.exe
X
Added by the W32/Forbot-EU worm. When started this infection connects to an IRC server where it waits for remote commands to executed. This startup ... Read More
Win32System win32s.exe
X
Added by the MYDOOM.V WORM!
Winsock32driver win32scs.exe
X
Added by the Troj/Hackarmy-C backdoor.
Winsock32driver win32server.exe
X
Added by the BACKDOOR-AZV TROJAN!
Winsock32driver win32server.exe
X
Added by the HACARMY.F TROJAN!
Winsock32driver win32server.scr
X
Added by the HACARMY TROJAN!
WIN32SL Win32sl.exe
Y
Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the ... Read More
SOUNDM win32smd.exe
X
Added by the Troj/WOW-JA spyware Trojan. This infection utilizes the npf.sys rootkit to hide itself. ... Read More
MICROSOFT UPDATE CONFIGURATION WIN32SNC.EXE
X
Added by the RBOT-AI WORM!
[various names] win32snd.exe
X
Added by the RBOT-DQ WORM!
windef Win32sp.vbs
X
Added by the ANPES WORM!
Win32 Src Service win32src.exe
X
Added by the RBOT-SX WORM!
ImagePath win32ssr.exe
X
Added by the W32/Tilebot-CW worm and IRC backdoor.
Win32Sr win32ssr.exe
X
Added by the W32/Sdbot-AOT worm and IRC backdoor.
Platform SDK Enviroment win32ssr.exe
X
Added by the W32/Rbot-BSD worm and IRC backdoor.
SMSERIALSTARTER win32st.exe
X
Trojan installed with the SpyBurner rogue anti-spyware program.
Win32 service WIN32SVC.EXE
X
Added by the Backdoor.Selka backdoor.
(default) win32sys.exe
X
Identifed as the Sdbot.KIN worm and IRC backdoor.
Windows 32bit System Manager win32sys.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
win32beta win32sys4.exe
X
Added by the Troj/Banker-DA password-stealing trojan for Brazilian banks.
WinSysmc Win32Sysmc.exe
X
Added by the Troj/Dloadr-BLU Trojan.
win32 usb3 driver win32tool.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
MS Unix Binary win32ttb.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Windows Updater win32upd.exe
X
Added by the RBOT-EC WORM!
WSAConfiguration win32upd.exe
X
Added by a variant of the RBOT WORM!
MS Unix Binary Win32Update.exe
X
Added by the W32/Rbot-BAS trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Win32 Kernel Update win32update.exe
X
Added by the Troj/Proxy-BS backdoor Trojan.
Microsoft Windows 32 Update win32update.exe
X
Part of the IRCBot family of worms and backdoors.
Windows Update win32update.exe
X
A variant of the Worm.SdBot.FTK family of worms and IRC backdoor Trojans.
win32us win32us.exe
X
All-In-One-Telcom (adult content dialler) variant
USB Device win32usb.exe
X
Added by the FORBOT-BQ WORM!
Win32 USB2 Driver win32usb.exe
X
Added by the SPYBOT.DHV WORM!
Windows Service Agent win32wins.exe
X
Added by the W32/Rbot-LOL worm and IRC backdoor.
Sygate Personal Firewall Win32x.exe
X
Added by the RBOT-KZ WORM!
mismo win32x.exe
X
Added by the W32/Rbot-JP trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This ... Read More
microsoft xp systems loaders win32xpsys.exe
X
Added by the W32.SPYBOT.NYT WORM! ... Read More
win32_i lptt01 win32_i.exe
X
Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use Rapi ... Read More
win32_i ml097e win32_i.exe
X
Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use Rapi ... Read More
g_rkt win32_rkt.sys
X
Identified as a variant of the Win32.Rootkit.Agent.MO rootkit.
Win386 Win386.exe
X
Added by the GOSUSUB VIRUS!
Microsoft IT Update win43.exe
X
Added by the RBOT-SA WORM!
w32s win442.dll
X
A variant of the Backdoor.Win32.IRCBot.bam family of worms and IRC backdoor Trojans. ... Read More
Microsoft IT Update win64.exe
X
Added by the RBOT.GA WORM!
windows run-time 64bit win64rt.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Windows Updater win64tyt.exe
X
Added by the W32/Sdbot-CNH worm and IRC backdoor.
Win7 AV Win7 AV.exe
X
Added by the Win7 AV rogue anti-spyware program.
Windows shell win70.exe
?
??
WinInit Win86.exe
X
Added by the Troj/Small-PB TROJAN!
Microsoft Synchronization Manager WIN932.EXE
X
Added by the W32/Sdbot-IL worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
windows network controller Win9x.exe
X
Added by the WOOTBOT.I WORM! ... Read More
WinDSNX Win????.exe
X
Added by the DNSX TROJAN!
WinAmp Agent Full wina.exe
X
Identified by Kaspersky Anti-Virus as Trojan-Downloader.Win32.Banload.bfb. If you are infected with this file you should immediately change all of yo ... Read More
wina wina.exe
X
Identified as a variant of the Mal/BankSpy-C malware.
Winamp Media Player winaamp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
KernelFaultCheck winabc3.exe
X
Added by the W32/Nubys-A EXE virus.
WinAble winable.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Adload.lv malware.
NTSF MICROSOFT SYSTEM WinAbring.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WIN3S2SNDS winabsmod.exe
X
Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" ... Read More
winacsr Winacsr.exe
U
AceScreenSpy keystroke logger/monitoring program - remove unless you installed it yourself! ... Read More
winactive WINACTIVE.EXE
X
Active variant of LOP.com hijacker - see here
WinActiveJ WinActiveJ.exe
X
Added by the ROTARRAN VIRUS!
Winad Client Winad.exe
X
WinAd adware by eXact Advertising
WinAdCnt.exe WinAdCnt.exe
X
Added by Troj/Banker-BU to compromise online banking sites.
WinAdCnt16.exe WinAdCnt16.exe
X
Added by the Troj/Banker-AT TROJAN!
Windows AdControl WinAdCtl.exe
X
Windupdates adware variant
Display Device Driver winadll.exe
X
Unidentified malware.
winadm winadm.exe
X
Browser hijacker - redirecting to Search-World.net. Related to the SMALL.LR TROJAN! ... Read More
_winadm winadm.exe
U
Parents Friend - "Log any activity and protect programs with a password. Further more you can lock the pc any hour in the week you want with the main ... Read More
Windows AdService WinAdServ.exe
X
Windupdates adware variant
Windows AdTools WinAdTools.exe
X
Windupdates adware variant
winafg32 winafg32.dll
X
Added by the Troj/Nebuler-G Trojan.
MsnExplorer winagent.exe
X
Added by Troj/Bdoor-EQ, a backdoor TROJAN found in the Windows folder.
SvcH0st WINAGENT.EXE
X
Added by the TROJ/BDOOR-EB TROJAN!
winagent WinAgent.exe
?
Standard Life Insurance program. Note: This file is legitimate. It is not known if it needs to run at startup. ... Read More
WinAmpAgent winagent.exe
X
Added by the Win32.Tactslay backdoor Trojan.
Scheduler winagent.exe
X
Added by the Win32.Tactslay backdoor Trojan.
Microsoft Internet Agent winagent.exe
X
Malware bundled with rogue anti-spyware programs.
Winahlp.exe Winahlp.exe
X
Added by a variant of the VAGRNOCKER TROJAN!
winakd32 winakd32.dll
X
Added by the Troj/Nebuler-V Trojan.
Windows Alerter WinAlert.exe
X
Added by the Win32/Wecykler removable media worm.
{7B587C5A-28E3-4763-A5B5-CC19D89DFD22} winall.dll
X
Added by the Troj/Lineag-H password-stealing Trojan for the online game Lineage. ... Read More
winallap winallap.exe
X
Added by the DELF.E TROJAN!
winallapu winallapu.exe
X
Added by the DELF.E TROJAN!
SystemW Winalx.bat
X
Added by the Virus.Win32.HLLW.Anirak virus/worm.
Winamp Media Player winamap.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
ServiceOptionMP3 winamp.dll.exe
X
Added by the Troj/Samson-A Trojan.
Winamp winamp.exe
X
Added by the AGOBOT-MC WORM! Note - this is NOT the Winamp Media Player (WinAmpa.exe) ... Read More
Winamp Agent winamp.exe
X
Added by the W32/Poebot-I WORM! This file is found in the Windows system folder. ... Read More
win winamp winamp.exe
X
Added by the RBOT.AGF WORM! NOTE - this is NOT the Winamp Media Player executable (WinAmpa.exe) ... Read More
System Update winamp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Winamp Media Player winamp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Winamp winamp.hta
X
Hijacker - re-directing to adult content sites. Note - this isn't the real Winamp ... Read More
Microsoft System winamp1.exe
X
Added by the W32/Sdbot-UF worm. When started, this infection connects to an IRC server where it waits for remote commands. ... Read More
Video winamp32.exe
X
Added by the AGOBOT-NG WORM!
Configuration32 Loader32 winamp32.exe
X
Added by the W32/Sdbot-BIC worm. When started, this infection connects to a remote IRC server and waits for commands to execute. ... Read More
Winamp Player 6 Winamp6.exe
X
A variant of the W32.Spybot.Worm family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
microsoft winupdate Winamp61.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
WinAMP winamp62.exe
X
Added by the W32/Sdbot-WN WORM/IRC backdoor Trojan!
Taskmon driver winampa.exe
X
Added by the LOONY-I TROJAN!
Win l5oahder winampa.exe
X
Added by the SPYBOTER.GEN VIRUS! Not the valid Winamp Agent which uses the same filename. This resides in the System32 sub-folder wheras real one is l ... Read More
Winampa WINAMPa.exe
U
Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take ... Read More
Winampa winampa.exe
X
Added by the AGOBOT-GS WORM!
Winampa Agent WINAMPA.EXE
X
Added by the SPYBOT-BR WORM! Note - this is NOT the Winamp Media Player
WinampAgent WINAMPa.exe
U
Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take ... Read More
Messenger WINAMPA.EXE
X
Added by the Troj/Ranck-CG trojan.
WinampPlugin winampa.exe
X
Added by the W32/Sdbot-CNF worm and IRC backdoor.
Windows Default Server winampa.exe
X
Added by the WORM_IRCBOT.AUN worm and IRC backdoor.
Microsoft winampaa.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
msnnt winampb.exe
X
Identified as a variant of the Trojan.Win32.Agent.tl malware.
WinAmp Player winampp.exe
X
Added by the W32/Rbot-AQI worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
winamp to google talk winamptogoogletalk.exe
U
Winamp to Google Talk, available here shows your current Winamp track in your Google_Talk status ... Read More
startkey winampXP.exe
X
Added by the Troj/Bifrose-OY backdoor Trojan.
WinAntispyware2008 WinAntispyware2008.exe
X
Added by the WinAntispyware2008 rogue anti-spyware program.
ASC-AntiSpyware WinAntivirus.exe
X
Added by the Win Antivirus Vista/XP rogue anti-spyware program.
ni.uwa6p_0001_n56m1001 WinAntiVirusPro2006Installer.exe
X
Related to the WinAntivirus programs: bogus, stealth installed "Spyware remover" - see the SpywareWarrior_List of Rogue/Suspect Anti-Spyware Products ... Read More
ni.uwa6p_0001_n69m0303 WinAntiVirusPro2006Installer[1].exe
X
Related to the WinAntivirus programs: bogus, stealth installed "Spyware remover" - see the SpywareWarrior_List of Rogue/Suspect Anti-Spyware Products ... Read More
Winamp media player winapa.exe
X
Added by an unidentified VIRUS, WORM or TROJAN!
registry value name winapi32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
APIMon winapix.exe
X
Added by a variant of the TIBSER.A downloader TROJAN!
WinApi winapix.exe
X
Added by a variant of the TIBSER.A downloader TROJAN!
WINAPLOGUPD WINAPLOGUPD.EXE
X
Added by the W32/Capside-C WORM, which exploits typical P2P program folders, and spreads via IRC clients and through netwerk shares. ... Read More
Winapp32.exe Winapp32.exe
X
Added by the Backdoor.GF.13 backdoor trojan!
Windows Application Security winappp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Video Proces winaps.exe
X
Added by the AGOBOT.HD WORM!
NvCplScan winasp.exe
X
Added by a variant of the RBOT WORM!
Video Process winasp.exe
X
Added by the AGOBOT-IS WORM!
WindowsNT winat.exe
X
Added by the W32/Tilebot-AZ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
WINDOWS SYSTEM winaup.exe
X
Added by the W32/Mytob-DN worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Microsoft Verifier winauth23.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
WinAntiVirusPro2006 WinAV.exe
X
Part of WinAntivirus Pro. This program is fake, stealth installed, and bundled with other malware. It is also on the Rogue anti-spyware list. ... Read More
WinAntiVirus Pro 2007 WinAV.exe
X
Startup program associated with WinAntiVirus Pro 2007. WinAntiVirus Pro 2007 is a rogue anti-spyware program that displays fake alerts, and downloads ... Read More
sysav winav.exe
X
Added by the WinPC Antivirus rogue anti-spyware program.
Windows Update WinAV.exe
X
Added by the Troj/Mdrop-EFH Trojan.
AndromedaAvDriver winav.sys
X
Added by the Andromeda AntiVirus rogue anti-spyware program.
Microsoft AntiVirus winav32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft DLL Verifier winavguard.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Anti Virus Control Center winavscan.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WinAVX WinAvX.exe
X
Malware related to and installed with the rogue anti-spyware program called WinAntiSpyware 2006 or WinAntiSpyware 2007. This Trojan is responsible for ... Read More
WinAVX WinAvXX.exe
X
Malware related to and installed with different rogue anti-spyware programs including WinAntiSpyware 2006 or WinAntiSpyware 2007. This Trojan is respo ... Read More
WinAwk WinAwk.exe
X
Added by the W32/Sdbot-AYF worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
winazs32 winazs32.dll
X
Identified as a variant of the Trojan.Win32.Dialer.qn dialer.
RegistryChk winbackup.exe
X
Added by the MERTIAN WORM!
RegRun WinBait winbait.exe
U
Part of RegRun - used to detect unknown viruses. RegRun compares winbait.exe with the original copy called winbait.org and warns if the files are ... Read More
WinBar WinBar.exe
U
"WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls" ... Read More
winbas12 winbas12.exe
X
Adware, probably CoolWebSearch parasite related - recognized by Kaspersky antivirus as TrojanDownloader.Win32.VB.du ... Read More
[] winbas12.exe
X
Adware, probably CoolWebSearch parasite related - recognized by Kaspersky antivirus as TrojanDownloader.Win32.VB.du ... Read More
[unknown name] WINBASICS32.EXE
X
Added by the Troj/Sdbot-JH worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
winbeans winbeans.exe
X
Added by the W32/Sdbot-BZB worm and IRC backdoor.
Winbed winbed.exe
X
Hijacker
KernelCheck winbery.exe
X
Added by the Troj/LegMir-CG password stealing Trojan for the online game Legend of Mir. ... Read More
winbfi32 winbfi32.dll
X
Identified as a variant of the Trojan.Win32.Agent.qt Trojan.
KernelFaultCheck winbin.exe
X
Added by the Troj/Dloadr-AAX downloader Trojan.
Win32 Bios Winbios.exe
X
Added by the W32/Semapi-A. This mass-mailing worm may display a message: "Unable to locate 'semapi.dll' reinstalling this application may fix this ... Read More
winbjv32 winbjv32.dll
X
A variant of the Trojan.Win32.Agent.qt Trojan.
WinBlueSoft WinBlueSoft.exe
X
Added by the WinBlueSoft rogue anti-spyware program.
winbo32.exe winbo32.exe
X
Added by the W32/Rbot-GRU worm and IRC backdoor.
windows cpu host winbog32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Windows Bool Service WinBool32.exe
X
Added by the Troj/Agent-GCV Trojan.
winboot winboot.exe
X
Added by the Troj/Banload-W Trojan.
Windows Boot winboot.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Reg Services Winboot32.exe
X
Added by the RBOT.PB WORM!
Windows Booter! winbooter.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Loader winBoot_INI.pif
X
Added by the PWSteal.Marlap information-stealing Trojan.
Winbot winbot.exe
X
Added by the Troj/Midrug-A backdoor trojan.
Windows Config winbot.exe
X
Identified as an IRCbot variant.
windows winbows.exe
X
Added by the W32/Autorun-AAI removable media worm.
winbug32 winbug32.dll
X
A variant of the Trojan.Win32.Agent.qt Trojan.
WinButler WinButler.exe
X
Identified as a variant of the Trojan-Dropper.Agent.DKN malware.
winbyq32 winbyq32.dll
X
Added by the Troj/Agent-DMC Trojan.
getwin winB_.exe
X
Added by the Troj/Banker-HS password-stealing Trojan.
Win32Usr WinCab.exe
X
Added by the W32/Dedmir-A worm.
ytghyuiokjnmvrq wincab.sys
X
Added by the Mal/RootKit-A rootkit. The service and display name are typically random. ... Read More
calc microsoft windows wincalc.exe
X
Added by an unidentied WORM or TROJAN!
logservice wincalc.exe
X
Added by the BACKDOOR.PAPROXY TROJAN! ... Read More
Security Fixers WINCAT32.EXE
X
Added by the W32/Sdbot-NR worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Wincbr.exe Wincbr.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
Configuration Loader wincffg.exe
X
Added by the AGOBOT.A3 WORM!
Wincfg.exe Wincfg.exe
X
Winsock2 driver WINCFG.SCR
X
Added by a variant of the SPYBOT WORM!
microsoft internet wincfg16.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
SysConfig wincfg32.exe
X
Added by the SDBOT.ZD WORM!
Windows Config Loader Wincfg32.exe
X
Added by the SILVERFTP TROJAN!
Microsoft Update Debugger wincfg32.exe
X
Added by the W32/Rbot-DT trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
WinCfg32 WinCfg32.exe
X
Added by the W32/Ronoper-A worm/backdoor trojan.
Windows Configuration wincfg32.exe
X
Added by the W32.Mytob.ED@mm mass-mailing worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Windows System Configuration WINCFG32.EXE
X
Added by the W32/Agobot-TE worm.
Windows DLL Loader WINCFG32.EXE
X
Added by the W32/Agobot-TE worm.
spoolsvs wincfy.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WINCHAT WINCHAT.EXE
X
Added by the Backdoor.Specfix backdoor.
WinCheck WinCheck.exe
X
Added by the PWS-CY TROJAN!
mscheck wincheck071008.dll
X
Identified as a variant of the Trojan-Spy.Win32.Agent.adq malware.
Win Chimes winchi~1.exe
U
WinChimes - enhancement software for the system clock that runs in the system tray ... Read More
winchk winchk.exe
U
Added by the Spyware.RemoteSpy surveillance software.
winchoice Winchoice.exe
X
Korean malware identified as SPR/SearchHook.A by Avira.
winchoiceupdate WinchoiceUpdate.exe run
X
Korean malware identified as SPR/SearchHook.A by Avira.
winchost winchost.exe
X
Added by the Troj/Dloader-PO downloader trojan.
Intervideo Win Cinema Manager WinCinemaMgr.exe
N
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs ... Read More
Intervideo WinCinema Manager WinCinemaMgr.exe
N
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs ... Read More
WinCinemaMgr WinCinemaMgr.exe
N
WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs ... Read More
Intervideo Win Cinema Manager WINCIN~1.EXE
N
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs ... Read More
Intervideo WinCinema Manager WINCIN~1.EXE
N
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs ... Read More
WINCINEMAMGR WINCIN~1.EXE
N
WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs ... Read More
Windows Registry Cleaner winclean.exe
X
Added by a variant of the SPYBOT WORM!
winclean winclean.exe
X
Added by the Troj/Cimuz-BO spyware Trojan. Troj/Cimuz-BO may also steal information such as email account usernames and passwords, and create screensh ... Read More
Windows Cleaner Service winclean.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
ASC-AntiSpyware WinCleaner.exe
X
Added by the WinCleaner 2009 rogue anti-spyware program. WinCleaner 2009 displays false results and utilizes Trojans to promote itself. ... Read More
NetPatrol winclient.exe
U
NetPatrol network monitoring software
run32dll WINClock.exe
X
Added by an unidentified VIRUS, WORM or TROJAN!
wincls wincls.dll
X
Added by the W32/Akbot-AR worm. W32/Akbot-AR spreads to other network computers infected with W32/Sasser and to other network computers by exploiting ... Read More
wincmap wincmapp.exe
X
CasClient adware variant - also known as Trojan.Cmapp ... Read More
windows command wincmd.exe
X
Added by the RBOT.ANV WORM! ... Read More
microsoft command line wincmd.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
MicroSoft Windows Command wincmdXP.exe
X
Added by the W32/Tilebot-CC worm and IRC backdoor.
SystemAdministration Wincmp32.exe
X
Added by the ASYLUM TROJAN!
wincms wincms.exe
X
Added by the RBOT.CBR WORM! - NOTE: this malware actually changes the default value data of the Registry "Run" key in order to force Windows to lau ... Read More
MS Dns Service wincntrl.exe
X
Added by the W32/Tilebot-BR worm and IRC backdoor.
wincom32 wincom32.sys
X
Added by the Trojan.Peacomm downloader Trojan. This infection contains rootkit functionality that enables it to hide some of its associated files. ... Read More
Win Comm WinComm.exe
X
WebRebates related adware
Windows Communicator wincomm.exe
X
Added by the AGOBOT-BH WORM!
Microsoft Windows Communicator for NT/XP wincomm.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
cpntmgc wincomp.exe
X
MagicControl downloader trojan variant
WinCon (wincon net driver) wincon.exe
X
Added by the W32/Sdbot-DJB worm and IRC backdoor.
MicroMix32 WinCon.exe
X
Added by the Troj/VB-ECC Trojan.
Windows Config Manager winconf.exe
X
Added by the W32/Rbot-AIT worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Windows Configurator winconf.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Config winconfig.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Win Config winconfig.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
winconfig winconfig.js
X
Added by the Trojan.Chafpin Trojan. Trojan.Chafpin is a Trojan horse that downloads files on to the compromised computer. Please note that c:\Windows ... Read More
Windows Configuration Service WinConfSrv.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
ctfmon WinConst.exe
X
Added by the Troj/Assasin-G backdoor trojan and keylogger.
windows_protect wincontrol32.exe
X
Added by the W32/Rbot-ADK ... Read More
Tour wincool.exe
N
Component of WinME that's annoying as hell. Pop's up a prompt to play the C:\WINDOWS\Application Data\Microsoft\INTRO\CONTENT.HTA that plays a full sc ... Read More
Wintercooler Pro WINCOOL.EXE
N
Wintercooler Pro - utility that monitors CPU usage, RAM consumption and Internet connection speed ... Read More
WinCore32.exe WinCore32.exe
X
Added by the Troj/Clicker-EN Trojan.
wincx wincore332.exe
X
Added by the W32/AGOBOT-MG WORM! ... Read More
[random name] wincpu.exe
X
Added by an unidentified VIRUS, WORM or TROJAN!
wincqt32 wincqt32.dll
X
Added by the Troj/Bckdr-JCK backdoor Trojan.
microsoft crs fix serv wincrs.exe
X
Added by the SDBOT.BWF WORM! ... Read More
Windows Critical Alert wincrt.exe
X
Trojan that display fake security warnings on your computer. This Trojan is part of the Smitfraud family of malware. You should use the guide below t ... Read More
Configuration Loader wincrt32.exe
X
Added by the GAOBOT.BF WORM!
Video Process wincrt32.exe
X
Added by the W32/Agobot-GR WORM/IRC Backdoor. File is found in the Windows system folder. ... Read More
WinCRT32 wincrt32.exe
X
Added by the W32/Dogbot-D worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Decrypt manager wincrypt32.exe
X
Added by the W32/Tilebot-GC worm and IRC backdoor.
Microsoft Outlook wincsrss.exe
X
Added by the Troj/Agent-OUY Trojan.
WinCTL winctl.dll
X
Added by the Troj/Small-EJG Trojan downloader.
winctl winctl.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows ControlAd WinCtlAd.exe
X
Windupdates adware variant
WinCtrl32 WinCtrl32.dll
X
Added by a variant of the Trojan-Downloader.Win32.Mutant.yf Trojan.
wind.exe wind.exe
X
Added by the MITGLIEDER.BD TROJAN!
the wind0s.exe
X
Added by an unidentified WORM or TROJAN!
Microsoft DLL Verifier wind0w.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
WIND0WS WIND0WS.exe
X
Added by the SPYBOT.DQ WORM!
Erfgddfk wind2ll2.exe
X
Added by the WORM_BAGLE.BX mass-mailing worm.
Win32 USB2 Driver wind32.exe
X
Added by the FORBOT-AH WORM!
Windows Registry Startup wind32.exe
X
Added by the AGOBOT-BZ WORM!
System wind32.exe
X
Added by an unknown malware.
Wind32 Wind32.exe
X
Identified as a variant of the Backdoor.Win32.Poison.avs malware.
Win32reg.dll Wind32reg.dll.exe
X
Added by the W32/Rackum-A worm/keylogger. This infection attempts to delete the regedit.exe file and logs keystrokes in the Winsck32.sys.Txt file. ... Read More
global startup WinDash.EXE
X
Reported by Kaspersky Anti-Virus as IM-Worm.Win32.VB.q, may be related to the W32/Attech-C ... Read More
WINDOWS SYSTEM By FEnR windasz-updote.exe
X
Added by the W32/Mytob-EZ worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. ... Read More
Windows Database WinDat.exe
X
Added by an unidentified WORM or TROJAN!
Windows Archiver windat.exe
X
Added by the W32/Tilebot-BA worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Update SP3 Windat.EXE
X
Added by the W32/Rbot-GTS worm and IRC backdoor.
Microsoft Windows Loader windat32.exe
X
Added by the W32/Rbot-LU trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Win windata.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Winsock2 driver WINDATE.EXE
X
Added by the W32.Spybot.Worm worm and IRC backdoor.
Msn Updater windatemanager.exe
X
Added by the SDBOT.TS WORM!
WinDates windates.exe
N
WinDates is a calendar, date organizer and event reminder program from Rockin' Software ... Read More
Microsoft Windows Updater WINDATES.EXE
X
Added by the W32/Rbot-H trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
scNine windates.exe
X
Unknown malware.
Windows Debugger windbg.exe
X
Added by an unidentified VIRUS, WORM or TROJAN!
Windows Debugger windbg32.exe
X
Added by the W32.Zotob.L worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
windbg48 windbg48.sys
X
Added by the Troj/RKAgen-A rootkit.
NB Windows Patterns WINDBKGND.EXE
N
Part of McAfee Nuts & Bolts. With Background Patterns, you can change background patterns of wizard and dialog windows ... Read More
Network DDE DSDM WinDDE.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows DDE Loader windde32.exe
X
Added by the W32/Sdbot-UZ WORM! Found in the Windows system folder.
Winde winde.exe
X
Added by the DLUCA TROJAN!
FireFly WinDeBug.exe
X
Added by the Troj/FireFly-A Trojan.
Multimedia windebug.exe
X
Added by the W32/VB-ERB worm.
windef windef.exe
X
Added by the W32/Wurmark-O mass-mailing worm.
WinDefender2009 windef.exe
X
Added by the WinDefender 2009 rogue anti-spyware program.
AFAFilter windefault.exe
U
AFAFilter - internet filter software
windefend windefend.exe
X
Related to the WinAntivirus rogue anti-spyware program.
Windows Defender Windefend.exe
X
Added by the Troj/FakeAV-EIE Trojan.
windefender.exe windefender.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Agent.byh Trojan.
Windows Defender windefender.exe
X
Added by the Troj/FakeAV-CYT fake alert malware.
Win Defrag! windefrag.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Desktop Controler windesktop.exe
X
Added by the W32/Sdbot-XH WORM/IRC backdoor trojan!
Microsoft Windows windets.com
X
Added by the Troj/Flood-EQ backdoor Trojan.
windev-4a8c-4822 windev-4a8c-4822.sys
X
Added by the Troj/Dorf-C Trojan.
windev-b51-433 windev-b51-433.sys
X
Added by the Troj/Dorf-H rootkit.
Microsoft Windows Runtime DLL Services WINDEV.EXE
X
Added by the W32/Randex-M worm. When started, this infection connects to an IRC server where it waits for remote commands to execute. ... Read More
WinDevils WinDevils.exe
X
Added by the W32/Brontok-BS worm.
Configuration Loader windex.exe
X
Added by the GAOBOT.BZ WORM!
WindowsRegKey update XP windexv1.exe
X
Added by the W32/Rbot-ABM worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infectio ... Read More
DF windf.exe
X
Added by the Win32/Windage.A password-stealing Trojan.
DLINK dfe drivers for Windows NT windfe.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
atisrc2 windfind.exe
X
Adult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), mmxrun (msosa.exe) and RegCompres (REGCPM3 ... Read More
Win Defrag windfrag.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows DHCP Service windhcp.ocx
X
Added by the Troj/Agent-DWU Trojan. Do not delete C:\Windows\system32\rundll32.exe as that is a legitimate file. ... Read More
Winexec32 windhelp32.exe
X
Added by the Troj/Agent-HKU Trojan.
Winexec32 windhelp32.exe
X
Added by the TROJ_BANKER.FRU online banking Trojan.
windhost.exe windhost.exe
X
Added by Troj/Banker-BV or Troj/PWSAgent-A trojans.
Microsotufed Update 32 windinit.exe
X
Added by the W32/Rbot-CTJ worm and IRC backdoor.
(04ED35B6-9A10-4EB3-9C1E-66B2CFA5AC77) windir32.dll
X
Added by the Troj/Lineage-JA Trojan.
Microsoft Windows DLL Services Configuration windir32.exe
X
Added by the W32/Sdbot-ABM worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
microsoft windows dll services configuration windir32a.exe
X
Added by a variant of the SDBOT.BHF WORM! ... Read More
win_upd.exe WINdirect.exe
X
Added by the MITGLIEDER.M TROJAN!
win_upd2.exe WINdirect.exe
X
Added by the BEAGLE.AO WORM!
Windows Disk Defender windiskdefend.exe
X
Added by the Win7 AV rogue anti-spyware program.
Microsoft windl32.exe
X
Added by the W32/Sdbot-DCZ worm and IRC backdoor.
erghgjhjgdr windlhhl.exe
X
Added by the BEAGLE.BG mass-mailing worm!
erghgjhgdr windlhhl.exe
X
Added by the W32.Beagle.BG or W32.Beagle.BH or W32.Beagle.BI or W32.Beagle.BJ WORM! ... Read More
erthgdr windll.exe
X
Added by the BEAGLE.AO or BEAGLE.AQ WORMS!
KavRuns Windll.exe
X
Added by the TRYNOMA TROJAN!
Microsoft Dll Management windll.exe
X
Added by the RBOT-MT WORM!
Windll Windll.exe
X
Added by the TRYNOMA TROJAN!
Windll.exe Windll.exe
X
Added by the STEALER TROJAN!
Winlme windll.exe
X
Added by the GOP.F WORM!
MicrosoftUpdate windll.exe
X
Added by the W32/Rbot-IH trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This i ... Read More
Graphics adapter service windll.exe
X
Added by the W32.Atnas.A worm. W32.Atnas.A is a worm that performs distributed denial of service attacks and spreads through file-sharing programs. ... Read More
erthegdr windll2.exe
X
Added by the W32.Beagle.CG@mm mass-mailing worm.
windll windll32.exe
X
Added by the ASTEF or RESPAN WORMS!
Windll32 Windll32.exe
X
Added by the MSNPWS TROJAN!
windows dynamic loading header winDLL32.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Microsoft Windows DLL Services Configuration windll32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
winshell windll32lib.exe
X
Added by the W32/Bagle-DM mass-mailing and P2P worm.
Microsoft Updaters Pros WINDLL32XP.EXE
X
Added by the SPYBOTTER.GEN VIRUS!
Windows DLL Verifier windlls.exe
X
Added by the W32/Rbot-AZQ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
windllsys32.exe windllsys32.exe
X
Added by a variant of the MITGLIEDER.BY TROJAN!
windows download manager windlmngr.exe
X
Added by an unidentified TROJAN!
Microsoft wd windmrg.exe
X
Added by the W32/Rbot-EEF worm and IRC backdoor.
SYSTEM windmupdr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Domain Name Drivers windns.exe
X
Added by the W32/Forbot-EP WORM/IRC backdoor Trojan to thee Windows system folder,and is as a new service called "IEXPLORER-Drivers" with a display na ... Read More
IEXPLORER-Drivers windns.exe
X
A service is created by the W32/Forbot-EP WORM, and run using the display name of "Windows Domain Name Drivers". ... Read More
Windows DNS windns.exe
X
Added by the W32/Sdbot-XU worm. When started this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
msn messeng windns.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
WinDLL (windns32.dll) windns32.dll
X
Identified as a variant of the Backdoor.Win32.Akbot.e malware.
WinDNS windns32.exe
X
Added by the GAOBOT.WX WORM!
Windows DNS Daemon windnsd.exe
X
Added by the WOOTBOT.AS WORM!
DRIVESYS1 windo.exe
X
Added by the W32/Autorun-SR removable media worm.
Microsoft Update windoc.exe
X
Added by the WORM_SDBOT.PF worm and IRC backdoor.
Microsoft Windows Secure windocs.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windoguide windoguide.exe
X
Korean adware identified by Ahnlab as PUP/Win32.Addenbar.
windoguideagent windoguideagent.exe
X
Korean adware identified by Ahnlab as PUP/Win32.Addenbar.
windoguideopt windopt.exe
X
Korean adware identified by Ahnlab as PUP/Win32.Addenbar.
Wind Optimizer WindOptimizer.exe
X
Added by the Wind Optimizer rogue Windows optimization software.
Microsoft Rundll windos.exe
X
Added by the W32/Sdbot-WF WORM/IRC backdoor!
REMOVE ME windos.exe
X
Added by the Troj/Sdbot-JC worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
S-1-5-21-1635847982-2902227367-3824404516-500} windoskey.exe
X
Added by the Troj/Dropin-A Trojan.
WindosSysDrivers WindosSysDrivers.dll
X
Added by the Troj/PWS-BOB Trojan. Please note that C:\Windows\System32\rundll32.exe is a legitimate Windows file and should not be deleted. ... Read More
windll windotnetsrv.exe
X
Added by the W32/Autorun-ANO removable media worm.
window.exe window.exe
X
Added by the MITGLIEDER.H or MITGLIEDER.J TROJANS!
Windows Service Loader window.exe
X
An Rbot variant. This infections connects to an IRC server where it awaits commands from a remote user. ... Read More
Windows modez Verifier Window2.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Security Accounts Center windowo.exe
X
Added by the Troj/Bckdr-AWQ Trojan.
windowplus windowplus.exe
X
A Korean rogue anti-spyware program.
Symantec Antivirus professional windows .exe
X
Identified as Backdoor.Win32.Rbot.ckj.
windows clean-up pro WINDOWS CLEAN-UP PRO.Exe
X
WINDOWS CLEAN-UP PRO Rogue anti-spyware program. ... Read More
Explorer Windows Explorer.exe
X
Added by the W32/SillyFDC-I worm. This infection should not be confused with the legitimate C:\Windows\explorer.exe file. ... Read More
Windows Genuine Check Windows Genuine Check.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Update Windows Update.exe
X
Added by the Troj/Banker-BIQ Trojan.
Winconfig Windows Update.exe
X
Added by the Troj/Banker-BUM information-stealing Trojan for online banking sites. If you are infected with this you should immediately change all yo ... Read More
GrayPigeon_Hacker.com.cn windows update.exe
X
Added by the Troj/GrayBrd-CE backdoor Trojan.
Microsoft Windows Update Windows Update.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windows xp sp2 keygen Windows XP SP2 KeyGen.exe
X
Added by the W32/TIBICK-C WORM! ... Read More
Windows modez Verifier Windows-.exe
X
Added by the W32/Rbot-DIO worm and IRC backdoor.
Windows modez Verifier Windows-.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Anti Verifier Windows-Anti.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows mod Verifier Windows-mod.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows spyware remover Windows-spyware.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windows 32 update Windows-Update.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
windows.bat windows.bat
X
Added by the Troj/Bckdr-MSY backdoor Trojan.
Windows Load windows.com
?
??
Microsoft IT Update windows.exe
X
Added by the RBOT-GL WORM!
NDIS Adapter windows.exe
X
Added by the FORBOT-BR WORM!
Rundll32 Windows.exe
X
Added by the QQPASS.E TROJAN!
Windows Windows.exe
X
Added by the KAZMOR, BOBBINS & ALADINZ.D TROJANS!
Windows Update windows.exe
X
Added by the RBOT-RB WORM!
System Servers windows.exe
X
Added by the Troj/GrayBrd-L Trojan.
WIN windows.exe
X
Added by the W32/Lebreat-B worm.
GrayPigeon_Hacker.com.cn windows.exe
X
Added by the Troj/GrayBrd-BA backdoor Trojan.
Microsoft Windows System Windows.exe
X
Added by the W32/Zotob-L mass-mailing worm and IRC backdoor.
InternetExplorer2 windows.exe
X
Added by the W32/Sdbot-CZP worm and IRC backdoor.
blah service Windows.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
gpmce windows.exe
X
Added by the W32/SillyFDC-HO worm.
Windows Utilities Manager Windows.exe
X
A variant of the Sdbot family of worms and IRC backdoor Trojans.
Microsoft Windows Updata windows.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windows.exe windows.exe
X
Added by the W32/SillyP2P-A worm.
Windows Services windows.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WRMVan Windows.exe
X
Added by the W32/AutoRun-BGD removable media worm.
Windows Login access windows.exe
X
Added by the Troj/DwnLdr-JDP Trojan.
Windows Security Service windows.pif
X
Added by the W32/Rbot-AMG worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Start windows.vbs
X
Homepage hijacker
Windows modez Verifier Windows12.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windows16 windows16.exe
X
Added by the Troj/VB-XU trojan.
systems usb driver Windows2.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Update windows24.exe
X
Added by a variant of the WIN32.RBOT WORM!
Windows Manager windows31.exe
X
Added by the W32/Sdbot-DY backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execut ... Read More
Microsoft Internet windows32.exe
X
Added by the SDBOT-F WORM!
[various names] Windows32.exe
X
Added by any of a number of WORM or TROJAN variants
syntax windows32.exe
X
Added by the SDBOT.CQ WORM! ... Read More
Windows32 Windows32.exe
X
Added by the Troj/Resod-C trojan.
services windows32.exe
X
Added by the W32/FlyVB-C worm.
Microsoft Update windows32.exe
X
Added by the W32/Rbot-BHQ worm and IRC backdoor.
Windows System32 windows32.exe
X
Added by the W32/Rbot-FPB worm and IRC backdoor.

W32/Rbot-FPB spreads to other network computers by exploiting common buffer overflow v ... Read More
windows32 windows32.exe
X
Added by the W32/Rbot-FUK worm and IRC backdoor.

W32/Rbot-FUK spreads to other network computers by:

- exploiting common ... Read More
MicrosoftWindows windows32.exe
X
Added by the Troj/PWS-BOQ Trojan.
UpdateFirewall32 Windows32Shield.exe
X
Added by the W32/Autorun-BEG worm.
Windows Mode Verifier WindowsActivation.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WindowsAgent WindowsAgent.exe
X
Added by the GOP.G WORM!
Microsoft Windows Update windowsapp.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
windowsbackup WINDOWSBACKUP.EXE
X
Added by the W32.Stang WORM! ... Read More
Windows Boot windowsboot.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Conf windowsconf.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
FTH2004 WindowsDAT.exe
X
Added by the Backdoor.Futh backdoor. This infection listens on TCP ports 7896 and 7897 awaiting commands. ... Read More
Windows Defender windowsdefender.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Enterprise Defender WindowsEDefender.exe
X
Added by the Windows Enterprise Defender rogue anti-spyware program.
Windows Firewall WindowsFirewall.exe
X
Added by the W32/Mytob-X WORM/IRC backdoor trojan!
Windowsfw windowsfw.exe
X
Added by the W32/Agobot-TA backdoor worm.
Windows Guard Pro WindowsGP.exe
X
Added by the Windows Guard Pro rogue anti-spyware program.
Currency windowsintd.exe
U
Added by the Spyware.Intruder surveillance software. If this program was not installed by you it should be uninstalled immediately. ... Read More
Windows Live WindowsLive.exe
X
Added by the W32/RealBot-A worm and IRC backdoor.
Windows Messenger Live Startup windowslivemsn.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windows WindowsMediaPlayer.exe
X
Added by the Backdoor.Sekorbdal backdoor Trojan.
Windows Memory Manager windowsmem.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windowsmp windowsmp.exe
X
Added by the W32/Autorun-DP removable media worm.
Windows Messenger Live Startup windowsmsnlive.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WindowsNetsDll WindowsNetsDll.dll
X
Added by the Troj/Mdrop-DEK Trojan.
Win32 Info windowsnfo.exe
X
A variant of the W32/Spybot.SLI family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
System Information Manager windowsNt.com
X
Added by the W32/Sdbot-ND worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
windows system32 windowsp.exe
X
Added by the MYTOB.GD WORM! ... Read More
winnt dns ident windowsp.exe
X
Added by the RBOT.BAL WORM! ... Read More
Microsoft Update 32 windowsp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Desktop Search WindowsSearch.exe
U
Main executable for Windows Desktop Search.
Windows Search WindowsSearch.exe
U
Windows Search adds support for indexing encrypted files, and enables PC-to-PC search on every operating system where Windows Search 4.0 runs-while an ... Read More
SysSupport WindowsServerService.exe
X
Added by the W32.Degnax@mm worm. W32.Degnax@mm is a mass-mailing worm that gathers email addresses from the compromised computer. It also spreads via ... Read More
Microsoft Service Pack WindowsSP.exe
X
Added by the W32/Rbot-RF worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
Windows Service Pack 2 WindowsSP2.exe
X
Added by the W32/Sdbot-TQ worm/backdoor.
Windowssyesm Windowssyesm
X
Added by the Troj/GrayBir-I backdoor Trojan.
windows windowssys.exe
X
Added by the Troj/Banloa-FK Trojan.
Auto Updat WindowsSys32.exe
X
Added by a variant of the FORBOT WORM!
WindowsUpdates WindowsSystem.exe
X
Added by the W32/Autorun-BLA removable media worm.
windowstatus windowstatus.exe
X
A Korean malware called Stickads. Identified by Kaspersky Anti-virus as a variant of the Trojan.Win32.Scar.hhna malware. ... Read More
windowstime.exe windowstime.exe
X
Added by the Troj/Dloadr-AQV downloading Trojan.
Windows Time Keeper windowstime.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Clock Configuration windowstm.exe
X
Added by the W32/Sdbot-DB backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execut ... Read More
Microsoft Update Machine windowsu.exe
X
Added by a variant of the RBOT WORM!
WindowsRegKey update windowsup.EXE
X
Added by the W32/Rbot-FV trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Windows Update Service WindowsUP.exe
X
Added by the W32/Sdbot-CRV worm and backdoor.

W32/Sdbot-CRV is capable of spreading to network shares protected by weak passwords. The ... Read More
SystemTray Windowsupd.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WindowsUpd1 WindowsUpd1.exe
X
VirtuMonde adware
SysUpd WindowsUpd1.exe
X
VirtuMonde adware
windowsupd1.exe WindowsUpd1.exe
X
VirtuMonde adware ... Read More
WindowsUpd2 WindowsUpd2.exe
X
VirtuMonde adware
windowsupd2.exe WindowsUpd2.exe
X
VirtuMonde adware
WindowsUpd WindowsUpd4.exe
X
VirtuMonde adware
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run windowsupdate.exe
X
Added by the FORBOT-BJ WORM! (where HKLMRun represents HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun) ... Read More
Windows drivers update windowsupdate.exe
X
Added by the W32/Rbot-ACE worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
DRam prosessor WindowsUpdate.exe
X
Added by the W32/Rbot-BBZ worm and IRC backdoor.
Microsoft Update Machine WINDOWSUPDATE.exe
X
A variant of the Rbot.bwj family of worms and IRC backdoor Trojans.
WindowsUpdate.exe WindowsUpdate.exe
X
Identified as a SpamTrojan malware.
autoload windowsupdate.exe
X
Identified as a variant of the WORM_SOCKS.D malware.
windowsupdate windowsupdate.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Security Monitor Process windowsupdate.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Update WindowsUpdate.exe
X
Added by the Troj/Bdoor-AOH backdoor Trojan.
Windows Firewall Updater windowsupdate.exe
X
Added by the W32.Spybot.AVEO worm. W32.Spybot.AVEO is a worm that attempts to exploit a number of vulnerabilities in order to spread. It may also spre ... Read More
WindowsUpdate WindowsUpdate.scr
X
Added by the W32/Scrapkut-A worm.
WINDOWS SYSTEM 32 windowsupdated32.exe
X
Added by the WORM_MYTOB.NS worm and IRC backdoor.
Windows Update Manager WindowsUpdateManager.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
ad-aware-6 WINDOWSUPDATER.EXE
X
Added by an unidentified WORM or TROJAN!
Windows Updates WindowsUpdates.exe
X
Added by the WORM_SDBOT.CLU worm and IRC backdoor. This infection is also bundled the rdriv.sys rootkit. ... Read More
Secure WindowsUpdates.exe
X
Identified as AdWare.Win32.Agent.bm.
Windows Update windowsupdats.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows USB Driver Support Windowsusb.exe
X
Added by a variant of the W32.SPYBOT WORM!
Windows Update windowsx.exe
X
Added by the Troj/Bancd-A password-stealing Trojan.
Service System windowsXP.exe
X
Added by the Troj/Bancos-EL Internet banking Trojan which attempts to capture confidential banking information and send it to a remote location. ... Read More
WindowsXP Update windowsxpupdate.exe
X
Added by the RBOT-PB WORM!
blah service windowsXT.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
Windowsxxx windowsxxx.exe
X
Added by the Troj/DuBing-A Trojan.
system32 master windowsys.com
X
Added by the W32/Sdbot-DIE worm and IRC backdoor.
WindowsCriticalUpdate windows_critical_update.exe
X
Added by the ASTEF or RESPAN WORMS!
Microsoft Kernel Windows_kernel32.exe
X
Added by the NETSKY.AE WORM!
WindowsUpdate windows_update.exe
X
Added by the LOFNI WORM!
winlog windowxs.exe
X
Added by the W32/Sdbot-KT worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
Microsoft Windows GUI Windowz.exe
X
Added by the RANDEX.AEV WORM!
Windows Service windowz.exe
X
Added by the W32/Sdbot-AYI worm and IRC backdoor. This infection utilizes stealth rootkit technology to protect itself via the c:\Windows\System32\ms ... Read More
Microsoft Corp SSL Certificates windowz.exe
X
Added by the W32/Rbot-GCZ worm and IRC backdoor.
Microsoft Problem Doctor windr128.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Problem Doctor windr32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Problem Doctor windr64.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Automatic Updater windrg.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WinDrg32 windrg32.exe
X
Added by the W32/Dogbot-A worm/backdoor. This file may be found in other directories as well. ... Read More
WinDriv32 WinDriv32.exe
X
Added by the SMALL-BA TROJAN!
windows driver manager windriv32.exe
X
Added by the W32/Tilebot-CY worm and IRC backdoor.
Micrsoft Driver windrive.exe
X
Added by the SDBOT.AF TROJAN!
Windows Driver windrive.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Driver! windriver.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WinRunners WinDrivers.exe
X
Added by the DULOAD.C WORM!
Audio Device Manager windrivers.exe
X
A variant of the Backdoor.Win32.IRCBot.afc family of worms and IRC backdoor Trojans. ... Read More
Windows Drivers windrivers.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Systems Backups windrives.exe
X
Added by an Agobot WORM/IRC backdoor variant, also creating a new service, servicename "Restoreds" and a displayname "Systems Backups". ... Read More
Restoreds windrives.exe
X
A new service added by the W32/Agobot-RB WORM/IRC backdoor, it's displayname is Systems Backups . ... Read More
WinDrives WinDrives.EXE
X
Added by the W32/Small-DHR worm.
Windows Workstation Service [5.1-2600] windrm.exe
X
Added by the W32/Rbot-CNY worm and IRC backdoor. This infection also utilizes the rootkit msdirectx.sys to hide itself and associated registry entrie ... Read More
InterU WINDRV.EXE
X
Added by the IRCINTER.A TROJAN!
SystemDriver windrv.exe
X
Identified by Kaspersky Anti-Virus as Trojan-Clicker.Win32.Delf.fj.
ADriver windrv.exe
X
Identified by Kaspersky Anti-Virus as Trojan-Clicker.Win32.Delf.fj.
CDriver windrv.exe
X
Identified by Kaspersky Anti-Virus as Trojan-Clicker.Win32.Delf.fj.
DDriver windrv.exe
X
Identified by Kaspersky Anti-Virus as Trojan-Clicker.Win32.Delf.fj.
FDriver windrv.exe
X
Identified by Kaspersky Anti-Virus as Trojan-Clicker.Win32.Delf.fj.
Microsoft Windows Drivers windrv.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windrv windrv32.exe
X
Added by an unidentified VIRUS, WORM or TROJAN! - possibly a strain of OBLIVION or BIONET ... Read More
WinSPF windrv32.exe
X
Added by the MYDOOM.T WORM!
Microsoft Update WinDrv32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WinDriver Configuration windrvconf.exe
X
Added by the AGOBOT-LX TROJAN!
Windows Update Client Service windrvl32.exe
X
Added by the AGOBOT-MM TROJAN!
windows drivers32 windrvrs32.exe
X
Added by the W32/Tilebot-AG worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
WinDrv windrvx.exe
X
Added by a variant of the TIBSER.A downloader TROJAN!
MICROSOFT WINDOWS SYSTEM 2 winds.exe
X
Added by the WORM_MYTOB.OD mass-mailing worm and IRC backdoor.
System32 winds32.exe
X
Identified as a variant of the Trojan:Win32/Tibs.FZ malware.
Microsoft Windows DLL Services Configuration winDSL.exe
X
Added by the W32/Sdbot-ZG worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
WinDSL MTU-Adjust WinDSL_MTU.exe
U
Adjusts the registry setting of the DUN-Adapters (MTU) and the TCP/IP-Protocol (RWIN) by ENGEL Technologieberatung ... Read More
WinDSL_MTU WinDSL_MTU.exe
?
May be realted to Tiscali broadband, if so is it required?
WINDOWS SYSTEM Dns windsns.exe
X
Added by the W32.Mytob.EY@mm worm. When started, this infection connects to a remote IRC server and waits for commands to execute. ... Read More
Microsoft Display Driver windsp.exe
X
Identified by Kaspersky antivirus as the Backdoor.Win32.Rbot.aeu worm and IRC backdoor. ... Read More
DsplObjects windspl.exe
X
Added by the W32/Bagle-CF mass-mailing worm and backdoor Trojan.
DsplObjects windspl.exe
X
Added by the W32/Bagle-CK mass-mailing worm and backdoor Trojan.
HOT FIX windsys2.exe
X
Identified as a variant of the Forbot worm.
Windows Process Dump windumper32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windowsregkeys update windup.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Start Upping windupds.exe
X
Added by the SDBOT.AFH WORM!
start upping windupdts.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Windows Drivers Version WinDV.exe
X
A variant of the SDBot family of worms and IRC backdoor Trojans.
dvd98 windvd98.exe
X
Added by the CULT.P WORM!
Microsoft Windows DVR windvr.exe
X
Added by the W32/Rbot-AXD worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
WinDVRCtrl WinDVRCtrl.exe
N
Control center software for an AOpen VA1000 TV tuner card
Windows Driver Sup windvrhost.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MicrosoftOfficeTools Winece.exe
X
Added by the Troj/Docscar-A Trojan.
Firewall Update System1 WinedowsUpdater1.exe
X
Added by the W32/Rbot-ARU worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. ... Read More
EnGenius Network Analysis Tool winegne.exe
X
Added by the W32/Rbot-GRC worm and IRC backdoor.
wineij32 wineij32.dll
X
Identified as a variant of the Trojan.Win32.Dialer.yz malware.
Windows Email winemail.exe
X
Added by the W32/Mytob-JI worm. W32/Mytob-JI is a mass-mailing worm and backdoor Trojan that can be controlled through the Internet Relay Chat (IRC) n ... Read More
winemx32 winemx32.dll
X
Identified as a variant of the Trojan.Win32.Dialer.yz malware.
winenv winenv.exe
X
A variant of the Backdoor:W32/SdBot.BZY family of worms and IRC backdoor Trojans. ... Read More
winepi32 winepi32.dll
X
Identified as Win32/Nebuler variants.
ssgrate.exe winerdir.exe
X
Added by the MITGLIEDER.O TROJAN!
Wins Service Driver winet.exe
X
Added by the W32/Rbot-APV worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
winetn32 winetn32.dll
X
Added by the BackDoor-CVT malware.
WinetWork WinetWork.exe
X
Added by the Troj/Banker-BQQ Internet banking Trojan.
wineula wineula.dll
X
Added by the Trojan.Vundo.B adware/redirector.
{5EE30F07-BB1C-4067-9BFB-7D5B11389506} winewtpas.dll
X
Added by the Troj/Lineage-PO password-stealing Trojan for the online game Lineage. ... Read More
WindowEnhancer Winex.exe
X
SCbar foistware variant
WinExec WinExec.exe
X
Added by the W32/Falus-A worm.
_winmain winexec.exe
X
Malware - detected by Kaspersky antivirus as Trojan-Downloader.Win32.Agent.ts ... Read More
WinExec Winexec.exe.vbs
X
Added by the AINESEY.A WORM!
Microsoft NT Update winexec32.exe
X
Added by a variant of the RBOT WORM!
Windows Explorer Shell Winexec32.exe
X
Added by the REDIST.B WORM!
WinExec32 WinExec32.exe
X
Added by the KAZWIN WORM!
mysoft winexplor.exe
X
Homepage hijacker
Microsoft Windows XP/2K Explorer winexplorer.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
winexy32 winexy32.dll
X
Identified as a variant of the Trojan.Win32.Agent.qt malware.
Folding@home WINFAH.EXE
N
Folding@Home is a distributed computing project which studies protein folding, misfolding, aggregation, and related diseases - must be running in orde ... Read More
Folding@Home 5.03 winfah.exe
N
Folding@Home is a distributed computing project which studies protein folding, mis-folding, aggregation, and related diseases. This program must be r ... Read More
Windows FAT 32 WINFAT32B.exe
X
Added by the W32/Spybot-AGT worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
WinFavorites WinFavorites.exe1
X
Loudmarketing.com adware downloader
<not used> WINFBI32.dll
X
Added by the Backdoor.Ginwui.F backdoor. Backdoor.Ginwui.F is a Trojan horse that opens a back door and uses rootkit techniques to hide its presence. ... Read More
Rund1l32 Winfi1e32.exe
X
Added by the MERTIAN WORM!
winFile winFile.exe
X
Added by the Troj/Banker-FDB Trojan.
Yahoo Messengger winfiles.exe
X
Added by the W32/Autorun-BCY removable media worm.
atisrc2 winfind.exe
X
Adult content dialler - see here . This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), mmxrun (msosa.exe) and RegCompres (REGCP ... Read More
msennger winfix.com
X
Added by the Troj/IRCFlood-R Trojan. When used with an IRC client, it can be used to provide DDoS attacks. ... Read More
Microsoft Windows Updater WINFIX.EXE
X
Added by the W32/Rbot-CM trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Configuration Loader winfix.exe
X
Added by the W32/Sdbot-MA worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Windows Fixer winfix.exe
X
Added by the W32/Virut-I virus and backdoor Trojan.

W32/Virut-I runs continuously in the background, providing a backdoor server which ... Read More
Windows WMF Fix winfix.exe
X
Added by the W32/Rbot-FTQ worm and IRC backdoor. W32/Rbot-FTQ spreads to other network computers by exploiting common buffer overflow vulnerabilities, ... Read More
FIX WinFIX1.0.vbs
X
Added by the VBS.Gormlez@mm infection! Found in the Windows directory.
regrun winfix22490.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Windows Fix Services winfix32.exe
X
Added by the W32/Tilebot-EW worm and IRC backdoor.
microsoft updater resources WinFixd32.exe
X
Added by the SPYBOT.CA WORM! ... Read More
Microsoft Updates Resources WinFixIDs.exe
X
Added by a variant of the RBOT WORM!
WinFk winfk32.dll
X
Added by the Backdoor.Ginwui.E backdoor Trojan.
<not used> winfkhide.dll
X
Added by the Backdoor.Ginwui.E rootkit.
WinFlyer32.dll WinFlyer32.dll
X
Identified as Trojan.Downloader-WinFlyer.Process.
winfont winfont.exe
X
Added by the DEATH TROJAN!
Windows FormatAd WinForm.exe
X
Windupdates adware variant
winform winform.exe
X
Added by the Troj/PWS-ALB password-stealing Trojan.
WinForm WinForm.exe
X
Added by the Troj/PWS-ANN password-stealing Trojan.
Audio Device Manager winfp.exe
X
Added by the W32/IRCBot-XS worm.
Windows System Configuration WINFRW.EXE
X
Added by the W32/Domwis-H WORM/IRC backdoor Trojan, it will grant an attacker remote access to perform a wide variety of actions. ... Read More
windows security updater WINFRW.exe
X
Added by the Solufina TROJAN! ... Read More
Microsoft Update Machine winftp32.exe
X
Added by the W32/Rbot-JX trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
etunnel winfw.exe
X
Added by an unidentified TROJAN!
win32 firewall driver winfw.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
winfws winfws.exe
X
Added by the W32/Sdbot-ABA worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
System Service WinFx.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Intec Service Drivers wing32.exe
X
A variant of the W32/Rbot-BCR family of worms and IRC backdoor Trojans.
Patches Value WinGamed.exe
X
Added by the SDBOT.BR WORM!
Windows Gamma Display wingamma.exe
X
Added by the Antivirus 2010 rogue anti-spyware program.
Patches Value WinGasys.exe
X
Added by the W32/Rbot-GD trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
WinGate WinGate.exe
X
Added by a variant of the LOVGATE WORM!
WinGate initialize WinGate.exe
X
Added by a variant of the LOVGATE WORM!
wingerver2.0.exe wingerver2.0.exe
X
Added by the Troj/GrayBrd-AE backdoor Trojan.
winghy32 winghy32.dll
X
Identified by Kaspersky antivirus as a variant of the Trojan.Win32.Dialer.yz malware. ... Read More
Windll wingmnt.exe
X
Added by Backdoor.Cmjspy.B.
Wingmnt wingmnt.exe
X
Added by Backdoor.Cmjspy.B.
System Drivers wingmt.exe
X
Added by the W32/SDBOT-MG WORM!
Windows Network Controller wingmt.exe
X
Added by a variant of the W32/SDBOT WORM!
Windows GMT32 wingmt32.exe
X
Added by the W32/Mytob-EN worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
wingo wingo.exe
X
Added by the BEAGLE.AW or BEAGLE.AV WORMS!
Asus Protocol Driver Control wingptd.exe
X
Identified as a variant of the Trojan.Rootkit.Gen malware.
Windows Graphics Loaders wingraphics.exe
X
Added by the SPYBOT.JG WORM!
win98 dns wingrd.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft Update wingrd32.exe
X
Added by the W32/Rbot-DW trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Windows System32 wingrd32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
winguard wingrd32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
wingsa32 wingsa32.dll
X
Identified as a variant of the Trojan.Win32.Dialer.yz malware.
wingsc32 wingsc32.dll
X
Added by the Troj/Bckdr-PNH backdoor.
microsofts media wingtp.exe
X
Added by the W32/RBOT-VO WORM! ... Read More
winusb.dll winguard.exe
X
Added by the FORBOT-CN WORM!
MS Unix Binary WinGuard.exe
X
Added by the W32/Rbot-ACL worm. When started, this infection connects to an IRC where it waits for remote commands to execute. ... Read More
Windows Guardian WinGuard.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
[not used] WINGUIS.DLL
X
Added by the Troj/Oscor-B backdoor Trojan.
wingvd32 wingvd32.dll
X
Added by the Troj/Bckdr-PNT backdoor Trojan.
Winhelp winhe1p.exe
X
Added by the QQPASS.E TROJAN!
<not used> winhe1p.exe
X
Added by the Troj/Agent-DFT Trojan.
winhelp winhelp.dll
X
Added by the Troj/Mdrop-DCW Trojan. Please note that c:\windows\system32\rundll32.exe is a legitimate Windows file and should not be deleted. ... Read More
(default) winhelp.exe
X
Added by the BLACKMAL.C WORM!
WinHelp WinHelp.exe
X
Added by a variant of the LOVGATE WORM! Note - "winhelp.exe" resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\Syst ... Read More
Windows help Manager winhelp.exe
X
Added by the W32.Scrimge.G worm. W32.Scrimge.G is a worm that spreads through Microsoft instant messaging clients and opens a back door on the comprom ... Read More
Windows Helper winhelp.exe
X
Identified as a variant of the Trojan-Spy.Win32.Banker.ape malware.
system Winhelp.exe
X
Added by the W32.Imaut.CN worm. W32.Imaut.CN is a worm that spreads through Yahoo! Instant Messenger and network shares. It may also download potentia ... Read More
dynamic dns binary WinHelpcfn.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
configuration loader WinHelper.exe
X
Added by a variant of the AGOBOT/GAOBOT WORM!
Windows Help File winhelper32.exe
X
Added by the SDBOT-QK TROJAN!
Windows Help Service winhelpsv.exe
X
Added by the RBOT-LP WORM!
winhld32 winhld32.dll
X
Identified as a variant of the Trojan.Agent.qt malware.
Windows Help winhlep.exe
X
Added by the Troj/Hupigon-SM Trojan.
winhlp.exe winhlp.exe
X
Added by the PWSteal.Formglieder Infection! Found in the Windows directory.
Windows Help Service winhlp.pif
X
Added by the W32/Rbot-AKW worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
winhlp3.exe winhlp3.exe
X
Added by a variant of the EASTO.A TROJAN!
winhlp32.exe winhlp32.exe
X
Added by a variant of the EASTO.A TROJAN! This should not be confused with the legitimate winhlp32.exe file residing in your C:\Windows directory. ... Read More
Windows Winhlp32 Stub Service winhlp32.pif
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WINDOWS winhlpapi.exe
X
Added by the W32/Mytob-QG mass-mailing worm and IRC backdoor.
Registry Loader winhlpp32.exe
X
Added by the GAOBOT.AO WORM!
winhlpp32.exe winhlpp32.exe
X
Added by the GAOBOT.SY WORM!
winhoq32 winhoq32.dll
X
Identified as a variant of the Trojan.Win32.Dialer.yz malware.
Microsoft Update Machine winhost.exe
X
Added by the RBOT-GK WORM!
Svchost winhost.exe
X
Added by the LOLAWEB.A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! ... Read More
win32 winhost.exe
X
Added by the Bropia.F worm.
Winhost winhost.exe
X
Added by the Troj/Delf-JL TROJAN!
winhost.exe winhost.exe
X
Added by the roj/Lohav-R proxy server and downloader trojan. Machines that are infected with this can be used by the remote user to send Internet tra ... Read More
windows host winhost.exe
X
Added by the BACKDOOR.PRYSAT TROJAN! ... Read More
WindowsRegKey update winhost.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Registry winhost.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MicroUpdate winhost.exe
X
Added by the Troj/Mdrop-EIC Trojan.
winhost32.exe winhost32.exe
X
Added by the TABDIM TROJAN!
Microsoft Command C winhost32.exe
X
Added by the W32/Sdbot-BBA worm and IRC backdoor.
Microsoft Hosting Service WINHOSTING.EXE
X
Added by the RBOT.AEV WORM!
(3B354F63-A696-424c-9E88-7F6BDFBA5CA5) winhosts.dll
X
Added by the Troj/Lineage-AH password-stealing Trojan for the online games Lineage. ... Read More
Windows Hosts winhosts.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WinHound WinHound.exe
X
Rogue antispyware/AV app which issues fake virus alert messages.
1 winhp32.exe
X
Added by the Troj/Clckr-KY Trojan.
Hardware Shell Detection WinHSD.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows HTTP services winhttps.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
RunProg wini.exe
X
Added by the OPTIX.04.D TROJAN!
AdAware wini.exe
X
Added by the W32/Rbot-XN WORM/IRC backdoor.
virtual wini.exe
X
Added by the W32/Rbot-YX WORM/IRC backdoor Trojan!
xpstart wini.exe
X
Added by the W32/Rbot-ABC. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infections are ... Read More
IE Runtime wini.exe
X
Added by the W32/Rbot-ABK worm. When started this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
IE Runtime wini.exe
X
Added by the W32/Rbot-ADM worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
WiniBlueSoft WiniBlueSoft.exe
X
Added by the WiniBlueSoft rogue anti-spyware program.
configuration loader winicfg32.exe
X
Added by the GAOBOT.GEN!POLY WORM!
winierun winierun.exe
X
Added by the Troj/RNWatch-A ... Read More
WiniFighter WiniFighter.exe
X
Added by the WiniFighter rogue anti-spyware program.
WiniFighter Security Service WiniFighterSvc.exe
X
Added by the WiniFighter rogue anti-spyware program.
WinIFixer WinIFixer.exe
X
Added by the WinIFixer rogue anti-spyware program.
WiniGuard WiniGuard.exe
X
Added by the WiniGuard rogue anti-spyware program.
Win32 Servermgr12345 winimgr.exe
X
Added by the W32/Tiotua-M worm.
windows imessenger messenger winimsg.exe
X
Added by the W32.ALLIM.A WORM! ... Read More
Microsoft Update 32 winin.exe
X
Added by the W32/Rbot-ARR worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. ... Read More
System Update2 wininet.exe
X
Added by the AUTOTROJ-C TROJAN!
wininet wininet.exe
X
Added by the W32/Stubbot-C worm and backdoor Trojan.
Windows Internet Service wininet.exe
X
Added by the W32/Rbot-AUX worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
AdobeUpdate Wininet.exe
X
Added by the TROJ_DROPPER.WTH Trojan.
wininet32 wininet32.exe
X
Added by the RAZNEW-A TROJAN!
Plug and Play wininet32.exe
X
Added by the Troj/Raznew-B trojan proxy server. This infection allows remote computers to use the Internet through your computer to hide their tracks ... Read More
wininetd wininetd.exe
X
Added by the WINET TROJAN!
,main drive Loader wininfo.exe
X
Suspected malware as it appears in 3 different registry locations - see here
Windows Update wininfo.exe
X
Added by the W32.Mytob.GA@mm worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Update Machine winini.exe
X
Added by the RBOT-KV WORM!
AdobeReaderPro winini.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
{8169E97B-3F20-C6CB-E19B-C29D99B4F767} WinIni.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Delf.cxm malware.
Winini.dll winini.vbs
X
Added by the VBS.Lido virus and worm.
Microsoft Update Machine WININI2.EXE
X
Added by the W32/Rbot-FR trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update Machine wininigo.exe
X
Added by a variant of the RBOT WORM!
Bymer.Scanner Wininit.exe
X
Added by the W32.HLLW.Bymer worm! Please note that this infection should not be confused with the legitimate Windows file located at %System%\wininit. ... Read More
wininit wininit.exe
X
Added by the WOLLF.16 TROJAN! Please note that this infection should not be confused with the legitimate Windows file located at %System%\wininit.exe. ... Read More
Microsoft Update 32 wininit.exe
X
Added by the W32/Rbot-AKD worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. Please note that ... Read More
Microsoft Update wininit.exe
X
Added by the W32/Rbot-AKR worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. Please note that ... Read More
WINDOWS INIT wininit.exe
X
Added by the W32/Zotob-K worm and IRC backdoor. Please note that this infection should not be confused with the legitimate Windows file located at %Sy ... Read More
Microsoft Security Process wininit.exe
X
Added by the W32/Rbot-FKM worm and IRC backdoor. Please note that this infection should not be confused with the legitimate Windows file located at %S ... Read More
agony wininit.sys
X
Added by the NTRootKit-K rootkit.
SysInit wininit32.exe
X
Added by the XABOT WORM!
SysInit wininit32.exe
X
Added by the W32/Sdbot-NA worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection ... Read More
Microsoft Update 64 BIT wininit32.exe
X
Added by the W32/Rbot-AHE worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Update 32 wininit32.exe
X
Added by the W32/Rbot-AKJ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
[Various Names] WinInitDll.exe
X
Part of the Wareout infection as described here.
softIce Update 32 wininits.exe
X
Added by the W32/Rbot-ANB worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Installer Manager winins.exe
X
Added by the W32/Sdbot-DHP worm and IRC backdoor.
winint winint.exe
X
Added by the W32/Sdbot-ADA worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
System Process Analization wininxt.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
winIogom winIogom.exe
X
Added by the Troj/Bancban-ML Internet banking Trojan.
Windows Logon Application WinIogon.exe
X
Added by the "Cruel Intentionz" backdoor TROJAN!
Microsoft System Service winIogon2.exe
X
A variant of the IRCbot family of backdoor worms.
Windows Sound Verifier WinIp32.exe
X
Added by the W32/Rbot-FMO worm and IRC backdoor.

W32/Rbot-FMO runs continuously in the background, providing a backdoor server
w ... Read More
IPTable Configuration Winipcfgs.exe
X
Added by a variant of the RBOT WORM!
WIP Config GUI Winipcfgs.exe
X
Added by the RBOT-CN WORM!
System winipck.exe
X
Added by the W32/Rbot-TK WORM/backdoor trojan!
WIN3S2SNDS winiprtx.exe
X
Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" ... Read More
winipsec winipsec.exe
X
Unidentified malware
WindowsIPRelay winipsvc.exe
X
Added by the W32/IRCBot-AAA worm and IRC backdoor.
winirxhelper WinIRXHelper.exe
U
MSI™ Media Center Deluxe software - see here ... Read More
win-xp winis.exe
X
Added by the W32/Rbot-BBD WORM! Found in the Windows system folder.
update winis.exe
X
Added by the Rbot-VD worm. This infections connects to an IRC server where it waits for remote commands. ... Read More
xp winis.exe
X
Added by the W32/Rbot-WO worm. When started this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
winis winis.exe
X
Added by the W32/RBOT-WI WORM! ... Read More
IE Runtimes winis.exe
X
Added by the W32/Rbot-ADZ worm. When started this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
winis winis.exe
X
Identified as a variant of the Net-Worm.Win32.Kolab malware.
WiniShield WiniShield.exe
X
Added by the WiniShield rogue anti-spyware program.
WiniShield Security Service WiniShieldSvc.exe
X
Added by the WiniShield rogue anti-spyware program.
upddateit winit.exe
X
Added by the RBOT-MS WORM!
virtual winit.exe
X
Added by the MUGLY.A or MUGLY.B WORMS!
Microsoft Updates winit.exe
X
Added by the W32/Sdbot-CSB worm and IRC backdoor.
windows system init winit32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Win32 Wmls Driver winitr32.exe
X
Added by the WOOTBOT.B WORM!
microsoft update 32 winitXP32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft Windows Updater WINIUPDATES.EXE
X
Added by the RBOT-KK WORM!
microsoft machine winjava.exe
X
Added by a variant of the AGOBOT/GAOBOT WORM! ... Read More
neroupdater6.8 winjava.exe
X
Added by the AGOBOT.AMK WORM! ... Read More
Enables Java Support winjava.exe
X
Added by the W32/Codbot-AA backdoor worm.
Compaq Jes Drivers winjes.exe
X
Added by the W32/Sdbot-XR worm. When started this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Systems16 winjews16.exe
X
Added by the W32/Sdbot-CXT worm and IRC backdoor.
winjne32 winjne32.dll
X
Added by the Troj/Agent-CIK Trojan Trojan.
CTFMON winjpg.jpg
X
Added by the W32/Autorun-ALB removable media worm. Please note that the C:\Windows\System32\wscript.exe file is legitimate and should not be deleted. ... Read More
Windows JavaScript Daemon Winjsd.exe
X
Added by the WOOTBOT.AF WORM!
winjvd32 winjvd32.dll
X
Identified as the Trojan.Agent.qt/Win32/Nebuler.BW malware.
Wink*.exe Wink*.exe [* = random char]
X
Added by a variant of the KLEZ WORM!
ValueWin Wink2sk7.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
T4skM4n4g3r Wink3sk9.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Winkb6 winkb6.exe
U
Part of We-Blocker, works in tandem with syswb6. Both files are needed to run WeBlocker. Required if We-Blocker is installed ... Read More
WinKernel WinKer.exe
X
Added by the MIRAB or SERVIDOR TROJANS!
systhread winkernal.exe
X
Added by the LIAMED WORM!
windowsnetwork winkernel32.exe
X
Added by the W32/Tilebot-BM worm and IRC backdoor. This infection will also install the rdriv.sys rootkit. ... Read More
Windows Kernel Log WinKettle.exe
X
Added by the Troj/Agent-HFA Trojan.
WinKey winkey.exe
U
Loads Copernic's WinKey. Used to map out Windows key hotkey combinations. Not required for the system, but is necessary for this to be running if you ... Read More
Microsoft Winedows startup WinKey.exe
X
Identified as a variant of the Net-Worm.Win32.Kolabc.bzi malware.
WinKey WinKey.exe
X
Korean malware that is identified by Ahnlab as a variant of the Win-PUP/Helper.Winkey malware. ... Read More
Windows Keyboard Services winkeyboard.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Keyboard Services winkeybrd.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WinTasks DLL Library (32-bits) winkll.exe
X
Added by the W32/Rbot-AJZ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Windows Kernel Services winkrnl386.exe
X
Added by the ZEBROXY TROJAN!
Windows Services Layer winl0g0.exe
X
Added by the W32/Rbot-FZQ worm and IRC backdoor.
Windows NT Update Manager WINL0G0N.exe
X
Added by the AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital "o" ... Read More
System WINL0G0N.EXE
X
Added by the Troj/Bancos-DB trojan.
Windows modez Verifier winl0g0z.exe
X
Added by the W32/Rbot-FNB worm and IRC backdoor.

W32/Rbot-FNB spreads to other network computers by exploiting common buffer overflow v ... Read More
Windows modez Verifier winl0g0z.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WINLOGON WINL0GON.exe
X
The Troj/Nethief-K TROJAN adds the file, which you'll note contains "zero" instead of "o". ... Read More
KSD2Service winl0gon.exe
X
Added by the Troj/Dloadr-AXH Trojan.
Microsoft Update 64 BIT winl32xe.exe
X
Added by the W32/Rbot-AQO worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
winla winla.exe
X
Added by the Troj/Dloadr-AQL Trojan.
security patches WinLab32.exe
X
Added by the W32/SDBOT-KB WORM! ... Read More
Google Online Search Service winlagons.exe
X
Identified by Bitdefender as a variant of the Trojan.Downloader.Small.AAJM Trojan. ... Read More
Google Online Search Service winlast.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
LoghDriver winlde.exe
X
Identified as a variant of the IRCBot family of worms and backdoors.
[not used] winldr.exe
X
Added by the W32/Bagle-AK worm.
load32 winldra.exe
X
Added by the Troj/Dumaru-AT TROJAN!

These files are known to be part of an infection that transmits information about your bank accounts, ... Read More
microfot update winldx32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Touch Manager WinLED.exe
U
Dell keyboard utility. Disabling can result in loss of screen saver and power saver functionality ... Read More
1Google Online Search Service winlegal.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Winlagons.an malware.
.service winlgon.exe
X
Added by the Troj/Bdoor-BX trojan backdoor.
winlgz2 winlgz2.exe
X
Added by the Troj/KillFil-Q trojan.
Microsoft DLL Library winlib32.exe
X
Added by the W32.Atnas.A worm. W32.Atnas.A is a worm that performs distributed denial of service attacks and spreads through file-sharing programs. ... Read More
winlibs.exe winlibs.exe
X
Added by the EVAMAN.C WORM!
winpsd.exe winlibs.exe
X
Added by the Mydoom.S WORM! Located in the Windows system directory.
winlig32 winlig32.dll
X
Added by the Troj/Geezo-F Trojan.
(default) winligom.exe
X
Added by the W32/Rbot-GAI worm and IRC backdoor. W32/Rbot-GAI spreads to other network computers by exploiting common buffer overflow vulnerabilities, ... Read More
SystemTray winligom.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WINDOWS SYSTEM winligon.exe
X
Added by the W32/Mytob-FD worm. When started, this infection connects to a remote IRC server and waits for commands to execute. ... Read More
Microsoft winline.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Winlink winlink32.exe
X
Added by the GAOBOT.AAY WORM!
PPPOEOE WINLITE.EXE
X
Added by the W32/Rbot-AAN WORM/IRC backdoor trojan!
Local area connection winlive.exe
X
Added by the W32/Rbot-FPH worm and IRC backdoor.

W32/Rbot-FPH spreads to other network computers by:

- exploiting common ... Read More
Windows UDP Control Center winlive32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Live Manager winlivemgr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows MSN Live Messenger winlivemsn.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Messenger Live MSN winlivemsnmessenger.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
SpyEx Winllogo.exe
X
Added by the W32/PrsKey-A password-stealing and keylogging worm. The worm will store the logged keystrokes into the file C:text.txt. ... Read More
winltmpv winln.exe
X
Added by the TCXMEDI-C TROJAN!
{2BDEC973-B5AC-4e5b-8AB3-5A0500880DA2} winload.dll
X
Identified as a variant of the Infostealer.Nuklus Trojan. Infostealer.Nuklus is a Trojan horse that steals sensitive information from the compromised ... Read More
WinLoad Winload.exe
U
Added by the Spyware.PCTattletale surveillance software. If you did not install this software, then uninstall it immediately.

NOTE TO V ... Read More
windows subsys winload.exe
X
Added by the NETSPREE.C WORM! ... Read More
updater32 winload32.exe
X
Added by the CULT.M WORM!
GenericHostXP WinLoaderXP.exe
X
Added by the Troj/Bdoor-ACX Trojan.
d2 winloadhh.dll
X
Added by the Troj/Labrap-A downloader trojan.
Winsock2.dll WINLODR.SCR
X
Added by an unidentified VIRUS, WORM or TROJAN!
Logon winlog.com
X
Added by the W32.Rungbu.C virus. W32.Rungbu.C is a virus that replaces Word Documents with a copy of the virus. ... Read More
Login winlog.exe
U
Salfeld Child Control 2003 - parental control software
Windows Logger winlog.exe
X
added by the Backdoor.Netshadow backdoor.
windows firewall log winlog.exe
X
Added by an unidentified WORM or TROJAN!
windows msconfig startup logger winlog.exe
X
Added by the RBOT.BCU WORM! ... Read More
Windows Login Service winlog.exe
X
Added by the W32/Rbot-AFN worm. This infection when started, connects to a remote IRC server where it waits for commands to execute. ... Read More
winlog manager winlog.exe
X
Added by the Trojan.Spexta trojan. When infected your computer will become an open mail relay which will allow your computer to be used to send out s ... Read More
[not used] winlog.exe
X
Added by the Troj/Sharp-J Trojan.
key2 winlog.exe
X
Added by the Trojan.Lodav.C Trojan that lowers security settings on your computer. ... Read More
Windows Update winlog.exe
X
Added by the Troj/IRCBot-TJ Trojan.
msconfig winlog.exe
X
Added by the Troj/IRCBot-TJ Trojan.
icq lite winlog.exe
X
Added by the Troj/IRCBot-TJ Trojan.
Update Checker winlog.exe
X
Added by the Troj/IRCBot-TJ Trojan.
AntiVir winlog.exe
X
Added by the Troj/IRCBot-TJ Trojan.
Microsoft winlog.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft windows log service winlog.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
winlog winlog.exe
X
Added by the Backdoor.Win32.Bifrose.acs backdoor Trojan.
winlog.exe winlog.exe
X
Added by the Troj/Bckdr-RBJ backdoor Trojan.
Windows Update Manager Winlog0n.exe
X
Added by the AGENT-BO TROJAN!
WINLOG0N WINLOG0N.EXE
X
Added by the W32.MYDOOM.BI WORM!
9m winlog0n.exe
X
Added by the Troj/LegMir-AQK password-stealing Trojan for the Legend of Mir.
MSN winlog32.exe
X
A variant of the Backdoor.IRCBot.acd family of worms and IRC backdoor Trojans.
<random name> winlogan.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Small.gdv malware.
jkdfj94kgdftdf winlogan.exe
X
Identified by Trend Micro as a variant of the PE_VIRUT.XV spamming Trojan.
Windows logging winlogd.exe
X
Added by the RBOT-ON WORM!
Windows debug logging winlogg.exe
X
Added by the RBOT-OY WORM!
Windows debug logging winloggs.exe
X
Added by the RBOT-QN WORM!
virtual-ie winlogi.exe
X
Malware - detected by Kaspersky antivirus as Trojan-Dropper.Win32.WinAD.h ... Read More
NDplDeamon winlogin.exe
X
Added by the RANDEX.E WORM!
Windows Logon winlogin.exe
X
Added by the SPYBOT-C TROJAN!
WinLogin winlogin.exe
X
Added by the AGOBOT-IX WORM!
winlogon winlogin.exe
X
Added by the RANDEX.E WORM!
virtual-machine winlogin.exe
X
Added by W32/Rbot-VU
BossIdea winlogin.exe
X
Added by the Troj/Lineage-I TROJAN!
Windows Update winlogin.exe
X
Added by the Troj/Banker-DV password-stealing trojan.
Microsoft Login winlogin.exe
X
Added by the W32/Rbot-AJP worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Win Login winlogin.exe
X
Added by the W32/Rbot-AWE worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. Please do not con ... Read More
Winlogun winlogin.exe
X
Added by the W32/P2Load-C worm.
winlogin.exe winlogin.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
Windows Login Screen winlogin.exe
X
A variant of the Backdoor.Rizo.A backdoor worm.
Windows Login Manager winlogin.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Service Login Manager winlogin.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Messanger Control Center winlogin.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Login Service winlogin.pif
X
Added by the W32/Sdbot-ACU worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Login Security winlogin.pif or random name
X
Added by the W32/Rbot-AKL worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
winlogin save server winlogin.scr
X
Added by the Mal/EncPk-VD malware.
Cpanel WINLOGIN32.EXE
X
Added by the WORM_SPYBOT.MO worm and IRC backdoor.
MS-Windows Login Service winlogin32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Synchronization Manager WinLoginnn.exe
X
Added by the SPYBOT.FO WORM!
xpstat winlogins.exe
X
Added by the W32/Rbot-AAR WORM/IRC backdoor trojan!
Windows Logins Screen winlogins.exe
X
A variant of the Backdoor.Rizo.A backdoor worm.
Adsl Not-A-Virus winlogn.exe
X
Added by the W32/Rbot-GUU worm and IRC backdoor.
IE Runtime winlogo.exe
X
Added by the W32/Rbot-AMJ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Internet/Server winlogo.exe
X
Added by the Troj/GrayBrd-AC Trojan.
Winlogo Winlogo.EXE
X
Added by the Troj/GrayBir-CQ backdoor Trojan.
Winsock2 driver WINLOGO.EXE
X
A variant of the W32.Spybot.Worm family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
winlogoff winlogoff.exe
X
Added by the W32/AGOBOT-TR WORM! ... Read More
Internet winlogom.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft winlogom.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Updade Windows winlogom.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows modez Verifier winlogom.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
localhost winlogom.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
SadNet winlogon.cab.exe
X
Added by the WORM_NETSAD.A worm.
winlogon winlogon.dll
X
Identified as the Trojan.Popuper malware.
.Prog winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! ... Read More
BuildLab winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! ... Read More
ccApps winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! ... Read More
FriendlyTypeName winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! ... Read More
ICQ Net winlogon.exe
X
Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should NOT appear in Msconfig/Startup! ... Read More
Microsoft Visual SourceSafe winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup or the Microsoft Visual ... Read More
RegDone winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! ... Read More
System Update2 winlogon.exe
X
Added by the AUTOTROJ-C TROJAN!
TEXTCONV winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! ... Read More
WinAuth winlogon.exe
X
Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the valid winlogon.exe process ... Read More
winlogon winlogon.exe
Y
Windows Logon Process - handles user logons described here
winlogon winlogon.exe
X
Hijacker or adult content dialler - file is located in C:\Windows or C:\Winnt, and not in it's System or System32 subdirectory, as is the case with th ... Read More
winlogon winlogon.exe
X
Added by the TRODAL TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! File is located in C: ... Read More
WMAudio winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! ... Read More
xp_system winlogon.exe
X
KREPPER-G trojan, a CoolWebSearch parasite variant. Note - this is NOT the legitimate winlogon.exe process, which should NOT figure in Msconfig/Startu ... Read More
winsystem.sys WINLOGON.EXE
X
Added by the W32/Sober-K infection! File will be found in the %WINDIR%msagentwin32 folder. ... Read More
_winsystem.sys WINLOGON.EXE
X
Added by the W32/Sober-K infection! File will be found in the %WINDIR%msagentwin32 folder. ... Read More
Windows Logon Application winlogon.exe
X
Added by Backdoor.Dsklite. This infection listens on port 890 awaiting commands. ... Read More
ICQNet winlogon.exe
X
Added by the W32/Netsky-C mass-mailing worm.
Network Client winlogon.exe
X
Added by the Trojan.Boxed.E Trojan.
ROOT_Machine winlogon.exe
X
Added by the Troj/Banker-FI Trojan.
userinit winlogon.exe
X
Added by the Troj/Dloader-TP Trojan.
NTP winlogon.exe
X
Added by the Troj/Jtram-D IRC backdoor Trojan.
RPCserr32g winlogon.exe
X
Added by the W32/Ritdoor-B backdoor worm.
(default) WINLOGON.EXE
X
Added by the Troj/Delf-LP information stealing Trojan.
Microsoft Windows Logon Process winlogon.exe
X
Added by the Troj/Proxyser-R proxy Trojan. This malware is also commonly bundled with rogue anti-spyware program. ... Read More
msn winlogon.exe
X
Added by the BKDR_PROSTI.A backdoor. This infection should not be confused with the legitimate microsoft file C:\Windows\System32\winlogon.exe. ... Read More
Torjan Program WINLOGON.EXE
X
Added by the Troj/WoW-EA password stealing Trojan targetting of the World of Warcraft online computer game. This infection should not be confused with ... Read More
nvchost winlogon.exe
X
Added by the Troj/Klone-J Trojan. This infection should not be confused with the legitimate file C:\Windows\System32\winlogon.exe. ... Read More
MSMSGS winlogon.exe
X
Added by the W32/Brontok-BS worm. This infection should notbe confused with the legitimate C:\Windows\System32\winlogon.exe program. ... Read More
WindowsLogon winlogon.exe
X
Added by the W32/Todnab-A worm. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
System Event Notificat winlogon.exe
X
Added by the Troj/Hupigo-SA Trojan. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe. ... Read More
Firewall auto setup winlogon.exe
X
Added by the Troj/Agent-EDB Trojan. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
CueX44_stil_here WINLOGON.EXE
X
Added by the W32/Punya-A worm. This infection should not be confused with the legitimate C:\Windows\System32\WINLOGON.EXE file. ... Read More
SmansaApp winlogon.exe
X
Added by the W32/Romario-A mass-mailing worm. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe. ... Read More
urudjeffni winlogon.exe
X
Added by the W32/Romario-A mass-mailing worm. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe. ... Read More
MSWinlogon Winlogon.exe
X
Added by the Troj/Small-EJW Trojan.
xem winlogon.exe
X
Identified as a variant of the Trojan-Downloader.Win32.CWS.am downloader Trojan. This infection should not be confused with the legitimate C:\Windows\ ... Read More
Windows Logon Screen winlogon.exe
X
A variant of the Backdoor.Rizo.A backdoor worm.
Winservices winlogon.exe
X
Added by the Troj/KeyLog-JQ keylogging Trojan. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
UserLogon winlogon.exe
X
Added by the W32/VB-DYF worm. This infection should not be confused with the legitmate C:\Windows\System32\winlogon.exe. ... Read More
LoggonAdministrator WINLOGON.EXE
X
Added by the W32.Korron.A worm. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
Flash Driver winlogon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Streams Drivers winlogon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
runwinlogon winlogon.exe
X
Identified as a variant of the SpamTool.Win32.Agent.gj malware.
Windows NT application winlogon.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
PaRaY_VM winlogon.exe
X
Added by the W32/Autorun-DV removable media worm. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
Windows NT Logon Application winlogon.exe
X
Unknown malware. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
Windows ARP Detectionc winlogon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Messanger Control Center winlogon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Services winlogon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows ARP Detectioncx winlogon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Generic Host Process for Win32 Services winlogon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans. This infection should not be confused with the legitimate C:\Windows\System32\winlog ... Read More
Windows Logon Applicationedc winlogon.exe
X
Added by the Troj/DwnLdr-HGR Trojan.
CTEMON.EXE winlogon.exe
X
Added by the Troj/FakeAv-FU Trojan. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
Windows Logon Applicatonedc winlogon.exe
X
Added by the Troj/VB-EBV Trojan. This infection should not be confused with the legitmate C:\Windows\System32\winlogon.exe file. ... Read More
screws winlogon.exe
X
Added by the W32/VB-DWN worm. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
Window UDP Control Servic winlogon.exe
X
Identified as a variant of the TR/Dropper.Gen malware.
Window UDP Control Servic winlogon.exe
X
Added by the W32/Rbot-GXN worm and IRC backdoor.
MSMSGS WINLOGON.EXE
X
Added by the W32.Korron.B worm. W32.Korron.B is a worm that replaces some file types with a copy of itself. It also copies itself to all accessible dr ... Read More
NVIDIA Media Center Library winlogon.exe
X
Added by the W32/AutoRun-AZK removable media worm.
Windows Security Center winlogon.exe
X
Added by the W32/Autorun-BEX removable media worm.
Windows SafeAssist winlogon.exe
X
Added by the Troj/VB-FGB Trojan. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
Service winlogon.exe
X
Unknown malware. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe program. ... Read More
Windows Logon Service winlogon.pif
X
Added by the W32/Rbot-AOU worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
SkynetRevenge winlogon.scr
X
Added by the NETSKY.AA WORM!
Windows NT Logon Application WINLOGON.SCR
X
Added by the W32/Rbot-ALP worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
ooocromosomasgenetics Winlogon.vbs
X
Added by the VBS.Wisfidix worm. VBS.Wisfidix is a worm that spreads to preconfigured mapped drives on the compromised computer. Please note that the ... Read More
[various names] winlogon32.exe
X
Added by an unidentified WORM or TROJAN!
winlogon winlogon32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Updates winlogon32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
<not used> winlogon32.exe
X
Fake AV Trojan. When fixing this entry, please be careful. If you do not change the userinit key to point back to userinit.exe, then your computer wil ... Read More
<not used> winlogon86.exe
X
Identified by BitDefender as a variant of the Gen:Trojan.Heur.PT.cqW@bCL2Eje malware. ... Read More
Windows Update winlogonEvt.exe
X
Added by the Troj/VB-DXM Trojan.
Windows mangement winlogonn.exe
X
Added by the RANDEX.FC WORM!
WinLogonnd winlogonnd.exe
X
Added by the Troj/Agent-NNQ Trojan.
windows logon procedure winlogonpc.exe
X
Added by the "WinLogon" TROJAN! ... Read More
Win32 Drivers winlogons.exe
X
Added by the W32/Forbot-FG worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Windows Update 32 winlogons.exe
X
Added by the W32/Forbot-FI worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Logons Screen winlogons.exe
X
A variant of the Backdoor.Rizo.A backdoor worm.
<not used> winlogons.EXE
X
Added by the W32.SillyFDC.BDN worm.
Windows NT Login Application winlogons.exe
X
Added by the Troj/BitCDl-A Trojan.
Windows winlogons.exe
X
Added by the W32/AutoIt-OQ worm.
startup WinlogonStartup
X
Unidentified malware
Microsoft winlogonsys.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
{E22DC74F-B084-F0F8-1BCE-00C8AF63188D} winlogon_patchv1.dll
X
Added by the Troj/BeastPWS-C keylogging Trojan.
Windxs mxzez Vexifier winlogos.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Logon Service winlogoservice.exe
X
Added by the W32.Spybot.ANOO worm and IRC backdoor.
<random name> winlogun.exe
X
Identified as a variant of the Trojan.Fakealert.ALU malware.
gadcom winlogun.exe
X
Identified as a variant of the Trojan:Win32/Matcash.HZ malware. The * in the command represents a random number. ... Read More
Windows Services Layer winlogz2.exe
X
Added by the W32/Rbot-FZE worm and IRC backdoor.

W32/Rbot-FZE spreads to other network computers by:
- exploiting common buffer ... Read More
Windows LoL Layer winlolx.exe
X
Added by the W32/Rbot-FOR worm and IRC backdoor.
Windows Lord Anti-Virus winlord32.EXE
X
Added by the Troj/SdBot-GW worm. When started, this infection connects to an IRC server where it waits for remote commands to execute. ... Read More
SCNDmem WINLOW.SYS
X
Added by the Troj/Haxdoor-CN rootkit infection. This file is installed as system driver and is used to hide processes, files, and registry keys from ... Read More
winltmpv WINLTMPV.EXE
X
Added by the TCXMEDI-C TROJAN!
1Google Online Search Service winlugan.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Winlagons.ak malware.
winluj32 winluj32.dll
X
Added by the Troj/Nebuler-L Trojan.
winm32 winm32.dll
X
Added by the Troj/Haxdoor-BQ backdoor Trojan. This infection utilizes the winm64.sys and the winm32.sys rootkit. ... Read More
winm TCP winm32.sys
X
Troj/Haxdor-Gen rootkit utilized by the Troj/Haxdoor family.
winm64 TCP winm64.sys
X
Troj/Haxdor-Gen rootkit utilized by the Troj/Haxdoor family.
Windows Mail Services WinMailSrv.exe
X
Added by the Troj/Hupigo-VY Trojan.
Winmain winmain.exe
X
One of the first of a new breed of malware. When run it immediately loads MSHTA.EXE from the Windows folder, placing it on "hot standby", ready to acc ... Read More
winservice winmain.exe
X
porn related malware
(default) winmain.exe
X
Added by the Troj/LdPinch-RC Spyware Trojan.
autorun winmain.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Delf.cns malware.
userinit winmain.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Delf.cns malware.
Windows Maintenance WINMAINT.EXE
X
Identified by VBA32 antivirus as Trojan-Dropper.Agent.35.
Microsoft Update 64 BIT winman32.exe
X
Added by the W32/Rbot-AKI worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Tweak Manager WinManager.Exe
?
WinGuides Tweak Manager. Is this required for the live updates feature and/or if settings are changed? ... Read More
Win Manager winmanager.sys
X
Added by the Troj/Bancos-BEQ Trojan.
Windows Manager winmants.exe
X
Added by the MANTAS WORM!
Microsoft Update Machine winmanwan.exe
X
A variant of the RBot family of worms and IRC backdoor Trojans.
windows media ap winmapp.exe
X
Added by an unidentified WORM or TROJAN!
winmatrix.exe WinMatrixXP.exe
U
WinMatrix XP - wallpaper replacement that shows different matrix effects (including flowing matrix codes from 'The Matrix' movie) on your desktop ... Read More
WinMenssage winmax.exe
X
Added by the BANCOS.B TROJAN!
winme winme.exe
X
Added by the W32.Rahiwi.B worm.
(32A43994-9CDC-4633-A2F4-3152097D404D) winme32.dll
X
Added by the Troj/Lineage-MO password-stealing Trojan for the online game Lineage. ... Read More
WinMed winmed.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Agent.ktf malware.
Windows Media Player winmedia.exe
X
Added by the Troj/Banker-AVX password-stealing Trojan.
SystemMigration WinMedia.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MSN winmedia.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WinMedia32 winmedia32.exe
X
Added by the Troj/Agent-UF Trojan. This infection also creates the file %Temp%removeMe290233.bat. ... Read More
Microsofts MediaScope winmedplay.exe
X
Added by a variant of the WIN32.RBOT WORM!
WinMem WinMem.exe
U
WinMem Cleaner - part of Ultra WinCleaner Utility Suite. Makes more memory available for your programs and the Operating System. It also defragments y ... Read More
winMem winMem.exe
X
Added by the W32.Hocgaly.A@mm worm.
Microsofts MediaScope winmep.exe
X
Added by the W32/Rbot-WB worm. When started this infection connects to a remote IRC server where it waits for commands to execute. These infections ... Read More
KernelCheck winmer.exe
X
Added by the Troj/LegMir-XG password-stealing Trojan for the online game the Legends of Mir. ... Read More
Microsoft MediaScope winmes.exe
X
Added by the W32/Rbot-XU WORM/backdoor, it's file will allow a remote attacker to create new accounts, terminate processes, record keysrokes and other ... Read More
Windows MSN Live Messenger winmessengerlive.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
winmfu32 winmfu32.dll
X
Identified as the Trojan.Win32.Agent.qt/BackDoor-CVT malware.
Microsoft Genuine Advantage winmga.exe
X
Identified by Kaspersky as the Backdoor.Win32.VanBot.dk worm and IRC backdoor.
Microsoft Update WINMGARD.EXE
X
Added by the W32/Rbot-BI trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
[not used] winmgd.win
X
Added by the VBS_GEDZA.A worm.
WindowsMGM Winmgm32.exe
X
Added by the SOBIG WORM and LALA.C TROJAN!
MMCWINMGMT winmgmt.exe
N
Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer he ... Read More
WinMgmt WinMgmt.exe
N
Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer he ... Read More
Windows-Management Service WinMgmt.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Still Image Instrumenta WinMgnt.exe
X
Added by the Troj/Feutel-AP backdoor Trojan. This infection also creates the files c:\windows\WinMgnt.DLL, c:\windows\WinMgntKey.DLL, and c:\windows\ ... Read More
Microsoft Update Machine winmgr.exe
X
Added by a variant of the RBOT WORM!
Windows Time winmgr.exe
X
The W32/Rbot-XC WORM/backdoor Trojan adds this and allows malicious remote access by way of the IRC network. ... Read More
252 winmgr.exe
X
Added by the Troj/Mugger-A Trojan.
windows pc winmgr.exe
X
Added by the W32/BIBOT-A WORM! ... Read More
Microsoft Windows Man Service winmgr.exe
X
Added by the W32/Sdbot-DTL worm and IRC backdoor. W32/Sdbot-DTL spreads to other network computers over network shares and by exploiting common buffer ... Read More
Windows Security Center winmgr.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
WinMgr32 winmgr32.exe
X
Added by the MIMAIL.P WORM!
Windows Service Manager winmgr32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
cpntmgc winmgts.exe
X
MagicControl downloader trojan variant
Windows Update winmguard.exe
X
Added by the RBOT-EM WORM!
WINP winmic.exe
X
Added by the W32/Spybot-EB worm. When started, this infection connects to a remote IRC server where it waits for commands to execute ... Read More
l44sys33 winmine.exe
X
Added by the VBS.Lido virus and worm. The winmine.exe program is actually a legitimate Windows game bundled with the OS, but in this is case, is being ... Read More
Monitor Infrared Output WinMIO.exe
X
Identified as Rbot.cnk family of worms and IRC backdoor Trojans.
Monitor Infrared System WinMIS.exe
X
A variant of the RBot family of backdoor worms. Identified as Backdoor.Win32.Rbot.bll by Kaspersky Antivirus. ... Read More
SpywareGuardPlus winmm64.exe
X
StartPage.ht homepage hijacker
Windows Network Controller winmms32.exe.exe
X
Added by the W32/Forbot-ED wORM! It is found in the Windows system directory. ... Read More
WinMan winmngr.exe
X
Added by the W32/Tilebot-BY worm and IRC backdoor.
Mims service winmngr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows SYN Control Center winmnon32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Gerenciamento de arquivos do Windows Winmod32.exe
X
Added by the Troj/Dloader-WG downloader Trojan.
Windows Monitor winmon.exe
X
Added by the SDBOT.VB WORM!
Windows Monitoring Service winmon.exe
X
Added by a variant of the SDBOT WORM!
Windows Security winmon.exe
X
Added by the W32/Sdbot-SR worm. When started, this infection will connect to a remote IRC server and wait for commands to execute. ... Read More
WINDOWS SYSTEM winmon.exe
X
Added by the W32.Mytob.GB@mm worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
iRis Active Monitor winmon32.exe
N
Iris Antivirus - discontinued, replace with good alternative
Window Monitor winmon32.exe
X
Added by the SDBOT.RT WORM!
Winmon32 winmon32.exe
X
Added by the W32/Rbot-OQ trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These ... Read More
Windows Monitor Services winmonitor.exe
X
The W32/Rbot-XX WORM/IRC backdoor Trojan adds this, allowing unauthorized remote access and termination of processes, DoS attack participation, and do ... Read More
wmv winmonv.exe
X
Added by the Troj/Agent-DG TROAJAN/backdoor.
Windows Mouse Services winmouse.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Mouse Services winmouse64.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
winmovieplugin WinMoviePlugIn.exe
X
Sfonditalia adult content premium rate dialer ... Read More
MSIdll winmp.exe
X
Added by a variant of the RBOT WORM!
Windows System Security winmp.exe
X
Added by the RBOT.IV WORM!
Microsofts media winmplayd.exe
X
Added by an undidentified WORM or TROJAN!
Microsoft media services winmplayer.exe
X
Added by the RBOT.ZO WORM!
Microsoft media winmplayers.exe
X
Added by a variant of the SPYBOT WORM!
Quicktime Mediaplayer winmplyer32.exe
X
Added by the RBOT-PM WORM!
winmrg winmrg.exe
X
Added by the Backdoor.AntiLam.20 backdoor.
Microsoft Windows Storage Machine Service winms.exe
X
Added by the W32/Rbot-AHK WORM/IRC backdoor trojan!
Windows Update Firewall System winmsfw.exe
X
Added by the W32/Rbot-EEO worm and IRC backdoor.
Windows Update Firewall System winmsfws.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windows messenger messenger winmsg.exe
X
Added by W32.Velkbot.A WORM! ... Read More
Microsoft Updote winmsg.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
winmsg.exe winmsg.exe
X
Added by the W32/Blehs-A worm.
Msgw32 WINMSG32.EXE
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WinMsg winmsgr.exe
X
Added by the Troj/Dloadr-AS downloading Trojan.
antivirusdll winmsgslive.exe
X
Added by the W32/Sdbot-CXQ worm and IRC backdoor.
Microsoft Update Machine Winmsixp32.exe
X
Added by the RBOT.DN WORM!
Compaq Service Drivers winmsn.exe
X
Added by a variant of the W32/Sdbot WORM/IRC backdoor Trojan, it also drops a file named msdirectx.sys in your %UserProfile% which acts as a rootkit. ... Read More
Messanger modix Configuration winmsn.exe
X
A variant of the Backdoor.Win32.Rbot.aie family of worms and IRC backdoor Trojans. ... Read More
Windows UDP Control Center winmsn.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Plugin winmsn.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windows sq drivers winmsn32.exe
X
Added by the W32/Rbot-ADI ... Read More
WindowsDriverControl winmsnliv.exe
X
Added by the Troj/Agent-PME Trojan.
WinMsrv32 WinMsrv32.exe
X
Added by the GAOBOT.AFJ WORM!
ELSA WINman Suite Winmsuit.exe
U
Allows you to totally customize your ELSA graphics card settings, including overclocking the GPU ... Read More
Windows MSX drivers winmsx.exe
X
Added by the W32/Rbot-AYG worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
windows firewalll winmu.exe
X
Added by a variant of the RBOT WORM!
CFDStart WinMuschi.exe
X
WINMUSCHI dialler
ZPoint winmuse.exe
X
Added by the Troj/Dloadr-VJ Trojan.
Microsoft Windows TCP Analysis winmwta.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
WinMX WinMX.exe
N
WinMX file sharing application
Microsoft CONFIG winmx.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MICROSFT MX UPDATE SUPPORT winmx32.EXE
X
Added by the W32/Rbot-BFU worm and IRC backdoor.
winmxw32 winmxw32.dll
X
Identified as a variant of the Trojan.Win32.Dialer.yz malware.
Windows Executable winmys.exe
X
Added by the W32/Rbot-ABO worm. When started, this infection connects to an IRC server where it waits for commands to execute. ... Read More
winmysqladmin winmysqladmin.exe
N
Starts the MySQL database admin tool
WinMySQLadmin Tool winmysqladmin.exe
N
Starts the MySQL database admin tool
[not used] Winn.exe
X
Added by the Snob.IRCworm IRC worm.
ssms.exe winn.exe
X
Added by the W32/Sdbot-DHE worm and IRC backdoor.
Microsoft IT Update winn43.exe
X
Added by a variant of the RBOT WORM!
MSWinupd winnampis.exe
X
Added by the TROJ_BANLOAD.BEX Trojan.
Reg Service WinnConfig.exe
X
Added by the W32/Agobot-PF network worm.
System winnet.dll
X
Added by the BKDR_AGENT.XZMS backdoor.
Windows Nets WinNET.exe
X
Added by the RBOT-MO WORM!
winnet winnet.exe
X
CommonName Toolbar spyware. To uninstall see here
Windows System Configuration WinNeth.exe
X
Added by the W32/Rethe-A worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Network Services winnetwork.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Network Services winnetwork32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Network Services winnetwork64.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Update Machine winnie.exe
X
Added by the W32/Rbot-ACD worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
Microsoft Update 32