Name Filename Status Description
!NoLoad winrecon.exe N WinRecon - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it
(*)API Machine winSOCKS.exe X Homepage hijacker. (* = any digit)
(*)Run win32API.exe X Homepage hijacker. (* = any digit)
(default) winhelp.exe X Added by the BLACKMAL.C WORM!
*windows update wrauclt.exe X Added by the RBOT-QU WORM!
*windows update wuanclt.exe X Added by the RBOT-PG WORM!
*windows update wuaucrlt.exe X Added by the SPYBOT.HUR WORM!
*windows update wuraclt.exe X Added by the RBOT-PO WORM!
,main drive Loader wininfo.exe X Suspected malware as it appears in 3 different registry locations - see here
.Prog winlogon.exe X Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
a-winpoet-service winpppoverethernet.exe Y WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking
AFAFilter windefault.exe U AFAFilter - internet filter software
AKEYNAME WinServ.exe X Added by the EVILBOT.C TROJAN!
ANIWZCSService WZCSLDR.exe ? D-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity
APIMon winapix.exe X Added by a variant of the TIBSER.A downloader TROJAN!
won update WAPDATE.EXE X Added by the WIN32.RBOT.N WORM!
atisrc2 windfind.exe X Adult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), mmxrun (msosa.exe) and RegCompres (REGCPM32.EXE), otherwise they return
Auto Updat WindowsSys32.exe X Added by a variant of the FORBOT WORM!
blah service winupdate.exe X Added by the GAOBOT.BIA WORM!
blah service winsysengine.exe X Added by the RBOT-KI WORM!
Bose Wave/PC Monitor wavepcmonitor.exe N System Tray access for this system (more info on the system here). Available via Start -> Programs
BuildLab winlogon.exe X Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
Bymer.Scanner Wininit.exe X Added by the W32.HLLW.Bymer worm! Please note that this infection should not be confused with the legitimate Windows file located at %System%\wininit.exe. You should only think this file is an infection if you also have a Run entry containing the name listed in this page.
ccApp WMADZ.EXE X Added by the RBOT-LJ WORM!
ccApps winlogon.exe X Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
CEPA wsot.exe ? ??
CFDStart WinMuschi.exe X WINMUSCHI dialler
Check for One Touch Update wiseupdt.exe N Checks for updates for Visioneer OneTouch scanners
Client agent for ARCserve W95AGENT.EXE ? Part of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required?
ComTry Web Searcher wstray.exe X Comtry MP3 Downloader related - spyware
Config Loadr winsys32.exe X Added by the AGOBOT-HN WORM!
Configuration Default Wuxat.exe X Added by the SPYBOT-CA WORM!
Configuration File Winset32.exe X Added by the FLUX.101 TROJAN!
Configuration Loaded wupdated.exe X Added by the MOEGA or MOEGA.AG or MOEGA.AP WORMS!
Configuration Loader wincrt32.exe X Added by the GAOBOT.BF WORM!
Configuration Loader windex.exe X Added by the GAOBOT.BZ WORM!
Configuration Loader Winreg.exe X Added by the GAOBOT.AO WORM!
configuration loader winicfg32.exe X Added by the GAOBOT.GEN!POLY WORM!
Configuration Loader wincffg.exe X Added by the AGOBOT.A3 WORM!
Configuration Utility wlanutil.exe U NetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards)
ContentService winservn.exe X Homepage hijacker
Controller WFXCTL32.EXE N From Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
cpntmgc wincomp.exe X MagicControl downloader trojan variant
cpntmgc winmgts.exe X MagicControl downloader trojan variant
cqlyg world_cup_.bat X Added by the WCUP.A WORM!
CriticalUpdate Wucrtupd.exe N MS Windows Critical Update Notification. If you want to keep Windows up-to-date, check the Windows Update site
D-Link AirPlus DWL-650+ Utility WLANMON.exe N D-Link Air Plus Wireless PC modem connection monitor
Delete Me worm.exe X Added by the DOOMHUNTER WORM!
DLHelperEXE WATCH.exe N Download helper distributed with some software that allows the software installation to redirect download locations. Not required once the installation is finished
drmu W95Mm.exe X Homepage hijacker installing a toolbar: http://tdko.com/. Lop.com in disguise. See this thread
dvd98 windvd98.exe X Added by the CULT.P WORM!
Dvx wsxsvc.exe X Delfin Media Viewer or "Promulgate" adware variant
EAPCISETUP wizard.exe N Part of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation
EbatesMoeMoneyMaker wjview ...Code N Ebates adware
Eicon NetworksLAN_DAEMON watch.exe U Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually
Eicon TechnologyLAN_DAEMON watch.exe U Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually
ELSA WINman Suite Winmsuit.exe U Allows you to totally customize your ELSA graphics card settings, including overclocking the GPU
encapsulated command tool wintr.com ? ??
Encoder Agent WMENCAGT.EXE N MS Windows Media Encoder, which already has a shortcut in the Start Menu if installed
Enumerate Service wsys.exe X Added by the MANIFEST TROJAN!
erthgdr windll.exe X Added by the BEAGLE.AO or BEAGLE.AQ WORMS!
ExeName32 Warm.scr X Added by the SCOLD WORM!
explorer wscript.exe [filename] X Sneaky way to start any VBS script. Many viruses use VBS files
eZWO wo.exe X Ezula "Web Offer" foistware
File System Service wmiprvsc.exe X Added by the AGOBOT-HZ TROJAN!
FileFreedom_Plugin wtm.exe N FileFreedom peer-to-peer sharing program
FileManager32 Wscript.exe ..ChkMgr32.vbs X Added by the NOTUP.A WORM!
FileSoft Wscript.exe UpdataFiles.vbs X Added by the SST.B WORM!
Folder Service wssdtu.exe X Added by the MANIFEST TROJAN!
Folding@home WINFAH.EXE N Folding@Home is a distributed computing project which studies protein folding, misfolding, aggregation, and related diseases - must be running in order to access the internet to upload to the servers.
FriendlyTypeName winlogon.exe X Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
Fromine WinPopup winpopup.exe N Instant Messenger program
Generic Host Process for Win32 Services winsvc.exe X Added by the SDBOT-O WORM!
gremier wscript.exe gpremier.vbs X Added by the GPREMIER WORM!
H/PC Connection Agent WCESCOMM.EXE U Active sync for use with Windows CE based palm PC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run windowsupdate.exe X Added by the FORBOT-BJ WORM! (where HKLMRun represents HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun)
ICQ Net winlogon.exe X Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should NOT appear in Msconfig/Startup!
Instant Wireless Configuration Utility WUSB11cfg.exe U Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration
internct WinSocks5.exe X Added by the GRAYBIRD.F TROJAN!
INTERNET SERVISES winz32.exe X Added by the KWBOT.Z WORM!
INTERNET_SERVISES winz32.exe X Added by the SDBOT.Q TROJAN!
InterU WINDRV.EXE X Added by the IRCINTER.A TROJAN!
Intervideo Win Cinema Manager WinCinemaMgr.exe N WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
Intervideo Win Cinema Manager WINCIN~1.EXE N WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
Intervideo WinCinema Manager WinCinemaMgr.exe N WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
Intervideo WinCinema Manager WINCIN~1.EXE N WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
Intervideo WinScheduler WinScheduler.exe N WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs
IPTable Configuration Winipcfgs.exe X Added by a variant of the RBOT WORM!
iRis Active Monitor winmon32.exe N Iris Antivirus - discontinued, replace with good alternative
iRiS AntiVirus Active Monitor WIMMUN32.exe N Iris Antivirus - discontinued, replace with good alternative
KavRuns Windll.exe X Added by the TRYNOMA TROJAN!
Kernel_check wmiprvse.exe X Added by the SONEBOT-B WORM!
key winxp.exe X Added by the BEAGLE.AG WORM!
Load-Guard Wscript.exe LGuarg.exe.vbs X Added by the YENO.B and YENO.C WORMS!
load= WPSLOAD.EXE ? Windows printing system that comes with the setup for Canon BJC series on the manufacturer's disk
<not used> WINOSCFG.EXE ? Could it be something to do with configuring Windows on a new PC from an OEM supplier?
[not used] wpshrc.exe Y Required to prevent configuration errors on a Compaq LBP-660 parallel port laser printer (and maybe others)
Load= wtfeat.exe ? Associated with the Wintab Digitizer
load= win32exec.exe X Added by the BITTER WORM!
loader WMPLAYER.EXE X Unknown malware. This infection replaces the legitimate wmplayer.exe file with an infection file of the same name.
Login winlog.exe U Salfeld Child Control 2003 - parental control software
LTM2 winupdate.exe X Added by the LITMUS.203 TROJAN!
MC wintrims.exe X Added by the WINTRIM TROJAN!
McAfeeWebscanX WebScanX.exe Y From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc
MD IE Plugin winy.exe X Adware
Media Player wmplayer.exe X Added by the AGOBOT-BM WORM!
Microsof Winlog Host wilogon32.exe X Added by the RBOT.XC WORM!
Microsoft 16Bit Update wuapdate16.exe X Added by the RBOT.CZ WORM!
Microsoft auto update winupdate.exe X Added by the BMBOT TROJAN!
Microsoft DirectX wuamgrd.exe X Added by the SDBOT.MY WORM!
Microsoft Dll Management windll.exe X Added by the RBOT-MT WORM!
Microsoft Drivers WSconf.exe X Added by a variant of the SDBOT WORM!
Microsoft ErgoPack wserb32.exe X Added by the RBOT-RI WORM!
Microsoft Excell wuamngr32.exe X Added by the RBOT-QH WORM!
Microsoft Internet windows32.exe X Added by the SDBOT-F WORM!
Microsoft IT Update win64.exe X Added by the RBOT.GA WORM!
Microsoft IT Update winn43.exe X Added by a variant of the RBOT WORM!
Microsoft IT Update win43.exe X Added by the RBOT-SA WORM!
Microsoft IT Update windows.exe X Added by the RBOT-GL WORM!
Microsoft Java Virtual Machine winscr32.exe X Added by a variant of the WOOTBOT WORM!
Microsoft Kernel Windows_kernel32.exe X Added by the NETSKY.AE WORM!
Microsoft media winmplayers.exe X Added by a variant of the SPYBOT WORM!
Microsoft media services winmplayer.exe X Added by the RBOT.ZO WORM!
Microsoft NT Update winexec32.exe X Added by a variant of the RBOT WORM!
Microsoft Office Start winupdates.exe X Added by the GAOBOT.BC WORM!
Microsoft Security Management winnt.exe X Added by the RBOT-MQ WORM!
Microsoft Security Management winserv.exe X Added by the RBOT-MJ WORM!
Microsoft Service winsvc.exe X Added by the SPYBOT-DB WORM!
Microsoft Synchronization Manager WinLoginnn.exe X Added by the SPYBOT.FO WORM!
Microsoft Synchronization Manager winupdate.exe X Added by the SDBOT.ER WORM!
Microsoft Synchronization Manager win.exe X Added by the SDBOT.AK WORM!
Microsoft System Checkup Wnetlib.exe X Added by the DONK.C WORM!
Microsoft Update winsys32.exe X Added by a variant of the RBOT WORM!
Microsoft Update wuamgrd.exe X Added by the RBOT-LK WORM!
Microsoft Update wuammgr32.exe X Added by the RBOT-AW WORM!
Microsoft Update wudmate.exe X Added by the RBOT.AP WORM!
Microsoft Update wuamgrd32.exe X Added by the RBOT.ZB WORM!
Microsoft Update webm.exe X Added by the SDBOT.WK WORM!
Microsoft Update wuagrd.exe X Added by the RBOT-FK WORM!
Microsoft Update wauguard.exe X Added by the RBOT.AEE WORM!
Microsoft Update winscv.exe X Added by the RBOT-BH WORM!
Microsoft Update winsys.exe X Added by the RBOT-GV WORM!
Microsoft Update wserv32.exe X Added by the RBOT.AF WORM!
Microsoft Update wtm32.exe X Added by the RBOT-AQ WORM!
Microsoft Update wumgrd.exe X Added by the SDBOT-KY WORM!
MICROSOFT UPDATE CONFIGURATION WIN32SNC.EXE X Added by the RBOT-AI WORM!
Microsoft Update Machine winini.exe X Added by the RBOT-KV WORM!
Microsoft Update Machine wuawx.exe X Added by the RBOT-CE WORM!
Microsoft Update Machine winupdt.exe X Added by the RBOT-FP WORM!
Microsoft Update Machine wuamgd.exe X Added by the SDBOT.HQ WORM!
Microsoft Update Machine wupdt32x.exe X Added by a variant of the SDBOT WORM!
Microsoft Update Machine windowsu.exe X Added by a variant of the RBOT WORM!
Microsoft Update Machine wininigo.exe X Added by a variant of the RBOT WORM!
Microsoft Update Machine winmgr.exe X Added by a variant of the RBOT WORM!
Microsoft Update Machine Winmsixp32.exe X Added by the RBOT.DN WORM!
Microsoft Update Machine Winregs32.exe X Added by the RBOT.DN WORM!
Microsoft Update Machine winxpini.exe X Added by the RBOT-OB WORM!
Microsoft Update Machine wuamgrd.exe X Added by the RBOT-HE WORM!
Microsoft Update Machine wuagrd.exe X Added by the RBOT-GF WORM!
Microsoft Update Machine winhost.exe X Added by the RBOT-GK WORM!
Microsoft Update Machine winss.exe X Added by the RBOT.JU WORM!
Microsoft Update Machine WUAMGRDXS.EXE X Added by the RBOT-GL WORM!
Microsoft Update Manager WINRLS.EXE X Added by the RBOT-AF WORM!
Microsoft Update Time wuam.exe X Added by the RBOT-M WORM!
Microsoft Update Win32a winupdate32a.exe X Added by the RBOT-LO WORM!
Microsoft Updaters Pros WINDLL32XP.EXE X Added by the SPYBOTTER.GEN VIRUS!
Microsoft Updates Resources WinFixIDs.exe X Added by a variant of the RBOT WORM!
Microsoft Visual SourceSafe winlogon.exe X Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup or the Microsoft Visual SourceSafe program
Microsoft Windows 2000 Winupdsdgm.exe X Added by the GAOBOT.AO WORM!
Microsoft Windows GUI Windowz.exe X Added by the RANDEX.AEV WORM!
Microsoft Windows Kernel Services winkrnl386.exe X Added by the ZEBROXY TROJAN!
Microsoft Windows Loader wloader.exe X Added by a variant of the AGOBOT/GAOBOT WORM!
Microsoft Windows Media Player wimp.exe X Added by the RBOT-FN WORM!
Microsoft Windows Securety wurguar.exe X Added by the RBOT-KY WORM!
Microsoft Windows Update Service wupdmgr32.exe X Added by the DOS.AUTOCAT TROJAN!
Microsoft Windows Updater winupdgm.exe X Added by the GAOBOT.BI WORM!
Microsoft Windows Updater WINIUPDATES.EXE X Added by the RBOT-KK WORM!
Microsoft Windows Updater WINUPDATE.EXE X Added by the SDBOT-PU WORM!
Microsoft Windows Updater win32upd.exe X Added by the RBOT-EC WORM!
Microsoft Winsock Wrapper ws2_32s.exe X Added by a variant of the SPYBOT WORM!
Microsoft Works Calendar Reminders wkcalrem.exe N Produces a pop-up reminder of events scheduled using the MS Works Calendar
Microsoft Works Portfolio WksSb.exe N The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program.Can be prevented from starting from a setting within Portfolio
Microsoft Works Update Detection wkdetect.exe N Checks for updates to MS Works
Microsoft World Service winworld.exe X Added by an unidentified IRC worm with backdoor capability!
Microsoft-Update wngard.exe X Added by the RBOT-JV WORM!
Microsofts media winmplayd.exe X Added by an undidentified WORM or TROJAN!
MicrosoftServiceManager Wintsk32.exe X Added by the YAHA.U WORM!
MicrosoftUpdate WinUp32.exe X Added by an unidentified VIRUS, WORM or TROJAN!
Micrsoft Driver windrive.exe X Added by the SDBOT.AF TROJAN!
Miosf Update wimsqaad.exe X Added by the SDBOT.AG TROJAN!
MMCWINMGMT winmgmt.exe N Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here
MS-Connect web.exe X Adult content dialler - see here
msconfig wins.exe X Added by an unidentified IRC WORM with backdoor trojan capabilities!
MSIdll winmp.exe X Added by a variant of the RBOT WORM!
MSOleath32 winss.exe X Added by the Kather Trojan. This infection should not be confused with the legitimate winss.exe used by Windows Live One Care.
MSStartOptimizer WINUPD.EXE X Adult content dialler - see here. This has to be cleared at the same time as RegCompres (REGCPM32.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), otherwise they return
MSUpdate wupd.exe X Added by the ALADINZ.M TROJAN!
MyPointsPointAlert wjview ...MyPointsPointAlertrun.exe X "With MyPoints you can earn rewards from name-brand merchants. You can even earn vacations and frequent flyer miles". Dubious privacy policy
mysoft winexplor.exe X Homepage hijacker
NAV Agent winsnav.vbs X Added by the ANPES WORM!
NB Windows Patterns WINDBKGND.EXE N Part of McAfee Nuts & Bolts. With Background Patterns, you can change background patterns of wizard and dialog windows
NDIS Adapter windows.exe X Added by the FORBOT-BR WORM!
NDplDeamon winlogin.exe X Added by the RANDEX.E WORM!
Net WINREG.EXE X Added by the ASSASIN.D TROJAN!
NetApp winserv.exe X Added by the SHADOWTHIEF TROJAN!
NetPatrol winclient.exe U NetPatrol network monitoring software
Netunit32 wunit32.exe X Added by an unidentified WORM or TROJAN!
Network Protocol Service wuamgrd.exe X Added by the RBOT.EA WORM!
Network protocol service wintcp.exe X Added by a variant of the AGOBOT/GAOBOT WORM!
Norton Updater winset.exe X Added by a variant of the SPYBOT WORM!
OEPowerPlugs winoeinit.exe ? ??
OWCWebCamDV wcdvtray.exe U WebCamDV from Orange Micro, Inc - enables the user to use a DV camera connected via Firewire as a Webcam
Patches Value WinGamed.exe X Added by the SDBOT.BR WORM!
Pervasive.SQL Workgroup Engine W3dbsmgr.exe U Database Service Manager for Pervasive SQL 2000 Workgroup edition. Required if you use Pervasive SQL but it's recommended you start it manually before using it as it has a tendancy to crash/freeze if loaded with other applications at startup
PivotSoftware wpctrl.exe N PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties
PMedia winsrvc.exe X Internet marketing sofware from PMedia as used in E-Card FriendGreetings foistware - see here. Treated by Trend as the FRIENDGRT.B WORM!
Q152404 wsript.exe Q152404.VBS N Appears to run Scandisk at bootup on NEC PCs
quicken Winrar.exe X CoolWebSearch parasite variant. Note - this is not the file zipping utility also known as WinRAR!
quicken Waol.exe X CoolWebSearch parasite variant
Quicktime Mediaplayer winmplyer32.exe X Added by the RBOT-PM WORM!
Quicktime Pro 3.0 winuodps.exe X Added by the GAOBOT.BH WORM!
Reg Service winsy.exe X Added by a variant of the SPYBOT WORM!
Reg Services Winboot32.exe X Added by the RBOT.PB WORM!
RegDone winlogon.exe X Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
Registry wscript.exe X Added by the VBSWG.AQ WORM!
Registry Checkup winreg.exe X Added by an unidentified WORM or TROJAN!
Registry Loader winhlpp32.exe X Added by the GAOBOT.AO WORM!
RegistryChk winbackup.exe X Added by the MERTIAN WORM!
Regrun2 WatchDog.exe Y Greatis Software's RegRun 3 Security Suite which amongst other things replaces MSCONFIG. The WatchDog check for registry changes caused by trojan's, viruses, etc 
Remote Procedure Call winrpc.exe X Added by the RBOT-KM WORM!
Remote Procedure Call winsysrpc.exe X Added by the SDBOT-PS WORM!
Remote Procedure Calls win.exe X Added by the SDBOT-QI WORM!
Restart Watch Watch.exe ? Associated with an Eicon Networks Diva ISDN or ADSL modem. What does it do and is it required?
Restart WSC Setting wscrestp.exe U WinStart Commander - part of Ultra WinCleaner Utility Suite. Starts Windows faster and controls hidden programs to boost performance and prevent system slow downs and crashes
Run MSupdt32 wscript MSupdt32.vbs X Added by the CASER WORM!
Run POPFile in background wperl.exe U POPFile - E-mail spam blocker
run32dll WINClock.exe X Added by an unidentified VIRUS, WORM or TROJAN!
run= wallflip.exe ? Desktop wallpaper changer?
run= win.ini ? ??
run= wswpd.exe Y Used with some models of Panasonic, Epson and NEC printers - required for printer to work
run= wmplayer.exe X CoolWebSearch parasite variant - Note: this is not the Windows Media Player executable!
Rund1l32 Winfi1e32.exe X Added by the MERTIAN WORM!
RunDLL32 winupdate.exe X Added by an unidentified TROJAN! - possibly a BMBOT variant
Rundll32 Windows.exe X Added by the QQPASS.E TROJAN!
RunProg wini.exe X Added by the OPTIX.04.D TROJAN!
Serv-U wssdsu.exe X Added by the MANIFEST TROJAN!
Service Process winset.exe X Added by a variant of the SPYBOT WORM!
Services winread.exe X Added by an unidentified VIRUS, WORM or TROJAN!
Shell wmedia16.exe X Added by the GOLDUN TROJAN!
SkynetRevenge winlogon.scr X Added by the NETSKY.AA WORM!
smcserv winsrv.exe X Added by the AGOBOT-OU WORM!
Sound System WinSound1.exe X Added by an unidentified VIRUS, WORM or TROJAN!
SPINX Wscript.exe OXNEY.B.VBS X Added by the YENO.B and YENO.C WORMS!
SpywareGuard winproc32.exe X Startpage adware Trojan
SpywareGuardPlus winmm64.exe X StartPage.ht homepage hijacker
ssate.exe winsys.exe X Added by the BEAGLE.K WORM!
ssgrate.exe winerdir.exe X Added by the MITGLIEDER.O TROJAN!
SSK Service winssk32.exe X Added by the SOBIG.E WORM!
Start windows.vbs X Homepage hijacker
stmha wkfxi.js X Added by the SPETH WORM!
SurfinGuard Pro winsfcm.exe U SurfinGuard Pro - internet protection software
Svchost winhost.exe X Added by the LOLAWEB.A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
SWd winwd.exe N PC Security from Tropical Software - lock files, password protect, etc
Sygate Personal Firewall Win32x.exe X Added by the RBOT-KZ WORM!
Sys29 win***32.exe [* = random char] X EliteBar adware
SysA win***32.exe [* = random char] X EliteBar adware
Syscheck win.hta X Browser hijacker
SysConfig wincfg32.exe X Added by the SDBOT.ZD WORM!
sysdir winrun.exe X Added by the WINBUR.B WORM!
SysInit wininit32.exe X Added by the XABOT WORM!
System Manager winsrv32.exe X Added by an unidentified WORM or TROJAN!
System Update wupdmgr.exe X Added by the SOROMO-A TROJAN!
System Update Service wmiprvsa.exe X Added by the AGOBOT-RG TROJAN!
System Update2 webcheck.exe X Added by the AUTOTROJ-C TROJAN!
System Update2 wininet.exe X Added by the AUTOTROJ-C TROJAN!
System Update2 winlogon.exe X Added by the AUTOTROJ-C TROJAN!
System Update2 winspool.exe X Added by the AUTOTROJ-C TROJAN!
System Update2 wupdmgr.exe X Added by the AUTOTROJ-C TROJAN!
System Updater Service wmiprvsw.exe X Added by the GAOBOT.AFC WORM!
SystemAdministration Wincmp32.exe X Added by the ASYLUM TROJAN!
SystemReg WINREG.EXE X Added by the DEWIN.A TROJAN!
systhread winkernal.exe X Added by the LIAMED WORM!
Taskmon driver winampa.exe X Added by the LOONY-I TROJAN!
TEXTCONV winlogon.exe X Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
Time Zone Synchronization wscript zshell.js X Added by the NETDEX-A TROJAN!
Touch Manager WinLED.exe U Dell keyboard utility. Disabling can result in loss of screen saver and power saver functionality
Tour wincool.exe N Component of WinME that's annoying as hell. Pop's up a prompt to play the C:\WINDOWS\Application Data\Microsoft\INTRO\CONTENT.HTA that plays a full screen version of the WinME product preview Windows Media video file that cannot be stopped to my knowledge until it finishes. That prompt will keep popping up after an install/reinstall of WinME until you give in and watch the thing. It also puts a task scheduler entry to run that annoying thing every 30 minutes, and don't bother deleting that entry, Windows puts it right back. Not only should you disable it from running, you should delete the thing altogether, as it, somehow can re-enable itself. Apparently you can try setting the file to read only
Tray Temperature Weatherbug.exe N Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs
TrayX winppr32.exe X Added by the SOBIG.F WORM!
Tweak Manager WinManager.Exe ? WinGuides Tweak Manager. Is this required for the live updates feature and/or if settings are changed?
Update Grokster WiseUpdt.exe N Automatically updates the Grokster file sharing software. Beware of adware and spyware when using this type of program, for instance, Grokster contains CyDoor
Update TUT WiseUpdt.exe ? ??
updater wupdater.exe X eUniverse KeenValue parasite related
updater32 winload32.exe X Added by the CULT.M WORM!
upddateit winit.exe X Added by the RBOT-MS WORM!
UPNPService WinSVCservice.exe X Added by the AGOBOT.UN WORM!
UPSUtl web.exe X CoolWebSearch parasite variant
USB 2.1 Driver winupdate1.exe X Added by a variant of the RBOT WORM!
USB Device win32usb.exe X Added by the FORBOT-BQ WORM!
Video winamp32.exe X Added by the AGOBOT-NG WORM!
Video Proces winaps.exe X Added by the AGOBOT.HD WORM!
virtual winit.exe X Added by the MUGLY.A or MUGLY.B WORMS!
virtual winprotect.exe X Added by the MUGLY.C WORM!
Windows Protection Suite WI345d.exe X Added by the Windows Protection Suite rogue anti-spyware program.
w32 w32.exe X Added by the SOKEVEN TROJAN!
w32sup w32sup.exe X Adult content dialler
W32Tc WTC32.scr X Added by the VOTE.D or VOTE.K WORMS!
W75P2PSERVER W75P2PS.EXE Y Printer utility which is required in order to make the printer work correctly
W815DM W815DM.exe ? ??
Wanadoo Messenger.exe Wanadoo Messenger.exe N Wanadoo ISP instant messenger client
WanMPSvc WanMPSvc.exe Y An AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling AOL doesn’t help
WAPI wts**.exe [* = random char] X PurityScan/Clickspring adware
war-ftpd.exe WAR-FTPD.EXE N War FTP Daemon from JGAA's Internet - FTP client
WareOut WareOut.exe X Malware masquerading as a spyware and dialer remover, see here
warez warez.exe N Warez P2P client
Warner warner.exe U Also known as "CyberWarner". From G-Tek Technologies and pre-installed on some Packard Bell PCs. Protects critical files
Warnet warnet.exe U Warnet - system cleanup software
WARSVR war-ftpd.exe N "War FTP Daemon - the original free FTP server for windows"
Washer washer.exe U Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
Washerie.exe washerie.exe N Cookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer, specific for cleaning the IE cache and cookies. Available via Start -> Programs
washindex washidx.exe U Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
Wast wast.exe X Grokster ads updater
Watch watch.exe N Found to be used by scanners for auto starting the scanning software when the lid is lifted.  Used by various scanners, file location and command will vary depending on scanner brand and model.

Sample file paths and commands:

%windows%\twain_32\S6U12BX\WATCH.exe

%program files%\pcl-3000\driver\watch.exe

%program files%\Mustek 1200 UB Plus\Driver\WATCH.exe
Watch Dog Program watchdog.exe N For Compaq PC's. Associated with Compaq's internet services. Not required if you don't use services provided by them and may not be required even if you do
Watchdog Watchdog.exe N Definitely part of the Mustek scanner drivers and software (for 600 III EP Plus and maybe others), launches from the Startup folder in the Start Menu, but not required as they give instructions on removing it on their webpage
WatchDog watchdog.exe ? Part of Motorola "Mobile Phone Tools" v3 - in a "Mobiile Phone Tools" sub-directory of Program Files
WaveTop Launcher WaveTop.exe N WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
Wbiff Wbiff.exe N Wbiff! E-mail checker - automatically checks your e-mail and notifies you if any new e-mail has been received
Wbutton Wbutton.exe ? Related to the Wacom Penabled driver on Acer Tablet PCs. Appears to do nothing so is it required?
WCESCOMM WCESCOMM.EXE N Active sync for use with Windows CE based palm PC
wcmdmgr wcmdmgrl.exe U Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
wcmdmgr wcmdmgr.exe N Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
wcmdmgrl wcmdmgrl.exe U Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
WCPC wintsvcc.exe ? ??
WCPI wintsvit.exe X PurityScan/Clickspring adware
WCPS Wint**.exe [* = random char] X PurityScan/Clickspring adware
WCPT wintsvtr.exe X PurityScan/Clickspring adware
WD Button Manager WDBtnMgr.exe U Button manager installed with a western digital external disk drive. Allows you to back up your system with one click
WDInfo wdinfo.exe X Adult content dialler
wdskctl wdskctl.exe X IEPlugin spyware
wdwctrl wdwctrl.exe X Added by the DLUCA.E TROJAN!
WEATHER WEATHER.EXE N Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs
WeatherCast Weather.exe N Weather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight
WeatherOnTray WeatherOnTray.exe X Hotbar's Weather Forecast tool for your desktop - adware
WeatherWatcher ww.exe N WeatherWatcher - weather reporting in the System Tray
web3trap web3trap.exe Y PC-Cillin 2000 anti-virus software -> ActiveX filter. Guards against malicious ActiveX programs, etc 
webalize webalize.exe X Searchcentrix hijacker
WebArmyKnife WAK.exe N Web Army Knife - a suite of web site developer's tools
webassist webassist.exe X Adware popup generator
Webcam Go Sti Service Application wbcgosvc.exe ? Control software for the portable Creative Video Blaster Webcam Go digital camera/PC web cam. What does it do and is it required?
WebcamRT.exe WEBCAMRT.exe N For Logitech Web Cams. Not required - camera works fine without it
Webcelerator webcel.exe X Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Spyware and troublesome - see here
WebCheck WebCheck.pif X Added by the CONE.C or CONE.F WORMS!
WebCpr0 WebCpr0.exe X Web_CPR/TopMoxie adware
Webdav.exe webdav.exe X IRC DDoS bot which gives the hacker full control over your system
WebHancer Agent whagent.exe X System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here
webHancer Survey Companion whSurvey.exe X WebHancer foistware - traffic measurement service that uses a client agent that is stealth installed on user machines, gathering detailed data about sites visited, their performance and, most important, what the user actually does while there
WebInstall WebInstall.exe X ClipGenie adware downloader
WebInstall2 WebInstall.exe X ClipGenie adware downloader
WebKey WebKey.exe N WebKey from JB Utilities. Utility to keep track of login data required when browsing the internet
Webposition Gold 2 wpsche~1.exe N Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines
WebRebates0 WebRebates0.exe X WebRebates adware
websaverlive websaverlive.exe U WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your computer is idle
WebSavingsfromEbates WebSavingsfromEbatesrun.exe X Web Savings From Ebates Software, a shopping tool that opens pop-up windows
WebSavingsFromEbates0 WebSavingsFromEbates0.exe X Web Savings From Ebates Software, a shopping tool that opens pop-up windows
WebScanX WebScanX.exe Y From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc
websearch wjview ...websearch.exe X "Web Savings" From Ebates Software, a shopping tool that opens pop-up windows
WebSecureAlert WebSecureAlert.exe X WebSecureAlert. "Can help protect your browser security and privacy". However, it's by GAIN Publishing, and will display pop up ads on your computer screen based on your online Web surfing behavior
Webshots Webshots Tray.exe N Screensaver program that automatically downloads from the webshots web site
Webshots websho~1.exe N Screensaver program that automatically downloads from the webshots web site
Webtrap webtrap.exe Y Part of PC-Cillin anti-virus software. Checks web-sites for malicious Java and ActiveX elements in a similar way to McAfee WebScanX. A few users find it infuriating
WebTrapNT.exe WebTrapNT.exe Y Part of PC-Cillin Anti-Virus software. Checks visited web-sites for malicious Java and ActiveX elements
WebWasher wwasher.exe U Free Pop-up/ad/javascript filter program from Siemens. If not running then browsers will not be protected but will still work. Available via Start -> Programs
Welcome Welcome.exe N Launches the Welcome to Windows tutorial on boot up
WEPstat Wepstat.exe ? Cisco Aironet 340 Series PC Card driver. If it can be started manually it shouldn't be required if you don't use the PC card facility regularily - hence the status could be "U". Can anybody confirm this?
WetSock wetsock.exe N RoboMagic Wetsock - weather reporting in the System Tray
WFGStartup WFGStartup.exe N World Weather. "This midlet displays the current weather conditions for major cities around the world. This version is for memory limited mobile phones"
WFXCTL32.EXE WFXCTL32.EXE N From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
wfxsnt40 wfxsnt40.exe Y WinFax 10.0 and maybe earlier versions. The program that opens the port for WinFax and not normally in the start menu. Needed if you want to run WinFax
WFXSwtch WFXSWTCH.exe U Related to WinFax. Allows you to use Winfax as a virtual printer so that you can print directly to the application.
WG511WLU WG511WLU.exe Y Netgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card
WGWLocalManager WGWLocalManager.exe U Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so. It could be started by creating a shortcut, running it only when connecting to the internet. If internet is used often, it's recommended to leave it in startup so it starts with the system
whagent whagent.exe X System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here
Whvlxd Whvlxd.exe X Added by the W32.LXD.MIRC TROJAN!
WildTangent Web Driver updater wcmdmgrl.exe U Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
Wildwire Monitor WWMon.exe N This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem
Willow Road WillowRoad.exe N Willow Road Screen Saver
Win Chimes winchi~1.exe U WinChimes - enhancement software for the system clock that runs in the system tray
Win Comm WinComm.exe X WebRebates related adware
WIN HOST PROCESS WIN HOST PROCESS.EXE X Added by the KEYLOGGER.CLONE TROJAN!
Win l5oahder winampa.exe X Added by the SPYBOTER.GEN VIRUS! Not the valid Winamp Agent which uses the same filename. This resides in the System32 sub-folder wheras real one is located in the winamp folder
Win Server winserv.exe X Added by the IMISERV.A TROJAN!
Win Server Updt wupdt.exe X Added by the IMISERV.A TROJAN!
win update wupda32.exe X Added by the SDBOT.J WORM!
WIN-BUGSFIX WIN-BUGSFIX.EXE X Added by the LOVELETTER (I LOVE YOU) VIRUS!
WIN32 WIN32.EXE X Added by the RATEGA TROJAN!
Win32 Win32.exe X Added by the ISRAZ.A and the W32/Mytob-AB WORMS!
win32 winsrv32.exe X Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites
win32 WinSetup.exe X Added by the EVILBOT.B TROJAN!
Win32 Device Loader Win32ldr.exe X Added by a variant of the AGOBOT/GAOBOT WORM!
Win32 DRK Driver wdrk32.exe X Added by the WOOTBOT.CY WORM!
Win32 exe file winstr32.exe X Added by a variant of the SPYBOT WORM!
Win32 Services1 wuamngr1.exe X Added by the SDBOT-PV WORM!
Win32 Src Service win32src.exe X Added by the RBOT-SX WORM!
Win32 SSL Driver winssv.exe X Added by the FORBOT-BH WORM!
Win32 USB Driver winxpinit.exe X Added by the SDBOT.AA TROJAN!
Win32 USB2 Driver win32usb.exe X Added by the SPYBOT.DHV WORM!
Win32 USB2 Driver wind32.exe X Added by the FORBOT-AH WORM!
Win32 USB2 Driver winupdate.exe X Added by the AGOBOT.YE WORM!
Win32 USB2 Driver winsnd32.exe X Added by a variant of the SDBOT WORM!
Win32 USB2.0 Driver w32usb2.exe X Added by the SPYBOT.DN WORM!
Win32 Wmls Driver winitr32.exe X Added by the WOOTBOT.B WORM!
win32.exe win32.exe X Added by the STARTPAGE TROJAN!
Win32BaseServiceMOD Wintask.exe X Added by the NAVIDAD WORM!
win32clf win32clf.exe X Added by an unidentified VIRUS, WORM or TROJAN!
Win32DLL Win32DLL.vbs X Added by the LOVELETTER (I LOVE YOU) VIRUS!
Win32dll Win32dll.exe X Added by the BANPAES TROJAN!
win32gb win32gb.exe X All-In-One-Telcom (adult content dialler) variant
win32info win32info.exe X Adult content dialler
WIN32SL Win32sl.exe Y Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. The specific function of this is to load MIF's in order for Dell OpenManage Client to work
Win32System win32s.exe X Added by the MYDOOM.V WORM!
win32us win32us.exe X All-In-One-Telcom (adult content dialler) variant
win32_i lptt01 win32_i.exe X Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
win32_i ml097e win32_i.exe X Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Win386 Win386.exe X Added by the GOSUSUB VIRUS!
WIN3S2SNDS winabsmod.exe X Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well"
WIN3S2SNDS winiprtx.exe X Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well"
winactive WINACTIVE.EXE X Active variant of LOP.com hijacker - see here
WinActiveJ WinActiveJ.exe X Added by the ROTARRAN VIRUS!
Winad Client Winad.exe X WinAd adware by eXact Advertising
winadm winadm.exe X Browser hijacker - redirecting to Search-World.net. Related to the SMALL.LR TROJAN!
Winahlp.exe Winahlp.exe X Added by a variant of the VAGRNOCKER TROJAN!
winallap winallap.exe X Added by the DELF.E TROJAN!
winallapu winallapu.exe X Added by the DELF.E TROJAN!
Winamp winamp.hta X Hijacker - re-directing to adult content sites. Note - this isn't the real Winamp
Winamp winamp.exe X Added by the AGOBOT-MC WORM! Note - this is NOT the Winamp Media Player (WinAmpa.exe)
Winamp media player winapa.exe X Added by an unidentified VIRUS, WORM or TROJAN!
Winampa WINAMPa.exe U Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs
Winampa winampa.exe X Added by the AGOBOT-GS WORM!
Winampa Agent WINAMPA.EXE X Added by the SPYBOT-BR WORM! Note - this is NOT the Winamp Media Player
WinampAgent WINAMPa.exe U Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs
WinApi winapix.exe X Added by a variant of the TIBSER.A downloader TROJAN!
Winapp winpup32.exe X Produces popup ads to adult content sites
WinAuth winlogon.exe X Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the valid winlogon.exe process
WinBackup Scheduler Wbsched.exe U LIUtilities WinBackup scheduler - backup software
WinBar WinBar.exe U "WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls"
winbas12 winbas12.exe X Adware, probably CoolWebSearch parasite related - recognized by Kaspersky antivirus as TrojanDownloader.Win32.VB.du
Winbed winbed.exe X Hijacker
WinCheck WinCheck.exe X Added by the PWS-CY TROJAN!
WINCINEMAMGR WINCIN~1.EXE N WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
WinCinemaMgr WinCinemaMgr.exe N WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
wind.exe wind.exe X Added by the MITGLIEDER.BD TROJAN!
WIND0WS WIND0WS.exe X Added by the SPYBOT.DQ WORM!
WinDates windates.exe N WinDates is a calendar, date organizer and event reminder program from Rockin' Software
windbs winxtc.exe X Added by the AGOBOT-WD WORM!
Winde winde.exe X Added by the DLUCA TROJAN!
windef Win32sp.vbs X Added by the ANPES WORM!
windir winrun.exe X Added by the WINBUR.B WORM!
Windll Windll.exe X Added by the TRYNOMA TROJAN!
WINDLL WSYS.EXE U STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes, all passwords transacted even if they weren't keyed in, all web sites visited, every program launched including the path to that program, and more"
windll windll32.exe X Added by the ASTEF or RESPAN WORMS!
Windll.exe Windll.exe X Added by the STEALER TROJAN!
Windll32 Windll32.exe X Added by the MSNPWS TROJAN!
windllsys32.exe windllsys32.exe X Added by a variant of the MITGLIEDER.BY TROJAN!
WinDNS windns32.exe X Added by the GAOBOT.WX WORM!
Window Monitor winmon32.exe X Added by the SDBOT.RT WORM!
Window Washer wwDisp.exe U Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
window.exe window.exe X Added by the MITGLIEDER.H or MITGLIEDER.J TROJANS!
WindowBlinds wbload.exe U WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins
WindowEnhancer Winex.exe X SCbar foistware variant
WindowFX wfxload.exe U Stardock WindowFX - "Allows you to add an unprecedented number of special effects to windows"
Windows Windows.exe X Added by the KAZMOR, BOBBINS & ALADINZ.D TROJANS!
Windows AdControl WinAdCtl.exe X Windupdates adware variant
Windows AdService WinAdServ.exe X Windupdates adware variant
Windows AdTools WinAdTools.exe X Windupdates adware variant
Windows Auto Update winupdater.exe X Added by the SDBOT.TF WORM!
Windows Automatic Update wuamgrder.exe X Added by a variant of the RBOT WORM!
Windows Communicator wincomm.exe X Added by the AGOBOT-BH WORM!
Windows Config Loader Wincfg32.exe X Added by the SILVERFTP TROJAN!
Windows Configuration wsys32.exe X Added by the GAOBOT.FB WORM!
Windows ControlAd WinCtlAd.exe X Windupdates adware variant
Windows Database WinDat.exe X Added by an unidentified WORM or TROJAN!
Windows debug logging winlogg.exe X Added by the RBOT-OY WORM!
Windows debug logging winloggs.exe X Added by the RBOT-QN WORM!
Windows Debugger windbg.exe X Added by an unidentified VIRUS, WORM or TROJAN!
Windows DNS Daemon windnsd.exe X Added by the WOOTBOT.AS WORM!
Windows Explorer Shell Winexec32.exe X Added by the REDIST.B WORM!
Windows Explorer-3212 WINRE16.EXE X Added by the HARDOC WORM!
Windows File Protection winprotect.exe X Added by the AGOBOT.JB WORM!
Windows Graphics Loaders wingraphics.exe X Added by the SPYBOT.JG WORM!
Windows Help File winhelper32.exe X Added by the SDBOT-QK TROJAN!
Windows Help Service winhelpsv.exe X Added by the RBOT-LP WORM!
Windows Internet Protocol winproc32.exe X CoolWebSearch parasite variant
Windows JavaScript Daemon Winjsd.exe X Added by the WOOTBOT.AF WORM!
Windows Load windows.com ? ??
Windows Loader wstart32.exe X Added by the GAOBOT.CA WORM!
Windows logging winlogd.exe X Added by the RBOT-ON WORM!
Windows Logon winlogin.exe X Added by the SPYBOT-C TROJAN!
Windows Manager winmants.exe X Added by the MANTAS WORM!
Windows mangement winlogonn.exe X Added by the RANDEX.FC WORM!
Windows Media Player wmediaplayer.exe X Added by the AGOBOT-NQ WORM!
Windows Monitor winmon.exe X Added by the SDBOT.VB WORM!
Windows Monitoring Service winmon.exe X Added by a variant of the SDBOT WORM!
Windows Nets WinNET.exe X Added by the RBOT-MO WORM!
Windows Network Service winvc32.exe X Added by the RBOT.RY WORM!
Windows Networking winsys32.exe X Added by the GAOBOT.FL WORM!
Windows NT Service Name winshock.exe X Added by the RBOT-PK WORM!
Windows NT Update Manager WINL0G0N.exe X Added by the AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital "o"
Windows OEM Tools winres32.exe X Added by the SPYBOT.FD WORM!
Windows Registry Cleaner winclean.exe X Added by a variant of the SPYBOT WORM!
Windows Registry Startup wind32.exe X Added by the AGOBOT-BZ WORM!
Windows Runtime Help win32hlp.exe X Added by a variant of the AIMVISION TROJAN!
Windows Runtime Help WinRunHelp.wrh X Added by a variant of the AIMVISION TROJAN!
Windows Security Assistant winsec.exe X CoolWebSearch parasite variant
Windows ServeAd WinServAd.exe X Windupdates adware variant
Windows service wuamgrd.exe X Added by the RBOT-QW WORM!
Windows shell win70.exe ? ??
Windows SSL File winssv.exe X Added by the WOOTBOT.CA WORM!
Windows Startup winsta~1.exe X GoHip foistware
Windows Startup winstartup.exe X GoHip foistware
Windows Startup Wdrun32.exe X Added by the GAOBOT.AO WORM!
Windows System Manager winsystem.exe X Added by the RBOT-AN WORM!
Windows System Manager Proc winsmc.exe X Added by the RBOT.JH WORM!
Windows System Security winmp.exe X Added by the RBOT.IV WORM!
Windows System Serivce winserv.exe X Added by a variant of the RBOT WORM!
windows system service winsock.exe X Added by the RBOT-MR WORM!
Windows TaskAd Wintaskad.exe X Windupdates adware variant
Windows TCP/IP wintcp.exe X Added by the AGOBOT-ZH WORM!
Windows Telnet Server wintel.exe X Added by the AGOBOT-MW WORM!
Windows Update wudate.exe X Added by the AGOBOT.ML WORM!
Windows Update wupdate.exe X Wengs adware
Windows Update Wuamgrd.exe X Added by a variant of the SPYBOT WORM!
windows update wuraclt.exe X Added by the RBOT-PO WORM!
windows update Wuanclt.exe X Added by the RBOT.XZ WORM!
Windows Update windows.exe X Added by the RBOT-RB WORM!
windows update wuaurlt.exe X Added by the RBOT.ADG WORM!
Windows Update winmguard.exe X Added by the RBOT-EM WORM!
Windows Update wuampd.exe X Added by the RBOT.UM WORM!
windows update wuarclt.exe X Added by the RBOT-OF WORM!
Windows Update AutoUpdate Client Product wuauct.exe X Added by the AGOBOT.ACL WORM!
Windows Update Client wuclient.exe X Added by the SMALL-RN TROJAN!
Windows Update Client Service windrvl32.exe X Added by the AGOBOT-MM TROJAN!
Windows Update Manager wupdmngr.exe X Added by the RANDEX.BTB WORM!
Windows Update Manager Winlog0n.exe X Added by the AGENT-BO TROJAN!
Windows Update Manager for NT wupdmgr32.exe X Added by the SDBOT.AH WORM!
Windows Update Monitoring Service winupdt.exe X Added by the RBOT-PL WORM!
Windows Update Process wmiprvsc.exe X Added by the SDBOT-CB WORM!
Windows Updater wupdmgr32.exe X Added by a variant of the DOS.AUTOCAT TROJAN!
Windows Video Acquisition (WVA) wvsvc.exe X Added by the AGOBOT.YM WORM!
WindowsAgent WindowsAgent.exe X Added by the GOP.G WORM!
WindowsCriticalUpdate windows_critical_update.exe X Added by the ASTEF or RESPAN WORMS!
WindowsMGM Winmgm32.exe X Added by the SOBIG WORM and LALA.C TROJAN!
WindowsRegKey update winupdate.exe X Added by the RBOT-QJ WORM!
WindowsRegKeys update winsysi.exe X Added by the SDBOT.WE WORM!
WindowsUpd WindowsUpd4.exe X VirtuMonde adware
WindowsUpd1 WindowsUpd1.exe X VirtuMonde adware
WindowsUpd2 WindowsUpd2.exe X VirtuMonde adware
WindowsUpdate windows_update.exe X Added by the LOFNI WORM!
WindowsUpdate Service wuautlc.exe X Added by the RBOT-NR WORM!
WindowsXP Update windowsxpupdate.exe X Added by the RBOT-PB WORM!
WinDriv32 WinDriv32.exe X Added by the SMALL-BA TROJAN!
WinDriver Configuration windrvconf.exe X Added by the AGOBOT-LX TROJAN!
windrv windrv32.exe X Added by an unidentified VIRUS, WORM or TROJAN! - possibly a strain of OBLIVION or BIONET
WinDrv windrvx.exe X Added by a variant of the TIBSER.A downloader TROJAN!
WinDSL MTU-Adjust WinDSL_MTU.exe U Adjusts the registry setting of the DUN-Adapters (MTU) and the TCP/IP-Protocol (RWIN) by ENGEL Technologieberatung
WinDSL_MTU WinDSL_MTU.exe ? May be realted to Tiscali broadband, if so is it required?
WinDSNX Win????.exe X Added by the DNSX TROJAN!
WindUpdates WinUpdt.exe X Windupdates adware
WinDVRCtrl WinDVRCtrl.exe N Control center software for an AOpen VA1000 TV tuner card
WinExec Winexec.exe.vbs X Added by the AINESEY.A WORM!
WinExec32 WinExec32.exe X Added by the KAZWIN WORM!
WinFast Schedule Wfwiz.exe U Leadtek WinFast TV tuner scheduler
Winfast_2K WF2k.exe U System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card
WinFavorites WinFavorites.exe1 X Loudmarketing.com adware downloader
WinFax PRO Controller WFXCTL32.EXE N From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
WinFaxAppPortStarter wfxsnt40.exe Y WinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application.
winfont winfont.exe X Added by the DEATH TROJAN!
WinFoxV2 WF2k.exe U System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card
WinGate WinGate.exe X Added by a variant of the LOVGATE WORM!
WinGate Engine Monitor wgengmon.exe U WinGate Internet Client Dialup Monitor - component of WinGate proxy server software. Displays the status of the WinGate engine, and appears in the system tray of each workstation on the network reassuring clients that their workstations have connectivity with the WinGate Server
WinGate initialize WinGate.exe X Added by a variant of the LOVGATE WORM!
wingo wingo.exe X Added by the BEAGLE.AW or BEAGLE.AV WORMS!
WinGuage Pro WGPRO32.EXE N Part of McAfee Nuts & Bolts. "WinGauge is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious". Resource hog. Available via Start -> Programs
Winguard WGFE95.EXE Y Dr Solomon's Virex antivirus
WinGuard Pro wgp.exe U Winguard Pro
Winhelp winhe1p.exe X Added by the QQPASS.E TROJAN!
WinHelp WinHelp.exe X Added by a variant of the LOVGATE WORM! Note - "winhelp.exe" resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) whereas the valid "winhelp.exe" resides in C:\Windows or C:\Winnt
winhlp3.exe winhlp3.exe X Added by a variant of the EASTO.A TROJAN!
Winhlp32 Wscript.exe ..Msexec32.vbs X Added by the GANT.B WORM!
winhlp32.exe winhlp32.exe X Added by a variant of the EASTO.A TROJAN! This should not be confused with the legitimate winhlp32.exe file residing in your C:\Windows directory.
winhlpp32.exe winhlpp32.exe X Added by the GAOBOT.SY WORM!
Winhost wintt.exe X Added by the LOLAWEB.B TROJAN!
Winhost win.exe X Added by the DLOADER-AP TROJAN!
winhost32.exe winhost32.exe X Added by the TABDIM TROJAN!
wininet32 wininet32.exe X Added by the RAZNEW-A TROJAN!
wininetd wininetd.exe X Added by the WINET TROJAN!
wininit wininit.exe X Added by the WOLLF.16 TROJAN! Please note that this infection should not be confused with the legitimate Windows file located at %System%\wininit.exe. You should only think this file is an infection if you also have a Run entry containing the name listed in this page.
Wink*.exe Wink*.exe [* = random char] X Added by a variant of the KLEZ WORM!
Winkb6 winkb6.exe U Part of We-Blocker, works in tandem with syswb6. Both files are needed to run WeBlocker. Required if We-Blocker is installed
WinKernel WinKer.exe X Added by the MIRAB or SERVIDOR TROJANS!
winkernel32 wWin32.com X Added by the BANSAP TROJAN!
WinKey winkey.exe U Loads Copernic's WinKey. Used to map out Windows key hotkey combinations. Not required for the system, but is necessary for this to be running if you use these hotkey combos
winlibs.exe winlibs.exe X Added by the EVAMAN.C WORM!
Winlink winlink32.exe X Added by the GAOBOT.AAY WORM!
Winlme windll.exe X Added by the GOP.F WORM!
WinLogin winlogin.exe X Added by the AGOBOT-IX WORM!
winlogon winlogon.exe Y Windows Logon Process - handles user logons described here
winlogon winlogon.exe X Hijacker or adult content dialler - file is located in C:\Windows or C:\Winnt, and not in it's System or System32 subdirectory, as is the case with the legitimate Windows Logon (winlogon.exe) process
winlogon winlogin.exe X Added by the RANDEX.E WORM!
winlogon winlogon.exe X Added by the TRODAL TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! File is located in C:\Windows or C:\Winnt, and not in it's System or System32 subdirectory
winltmpv winln.exe X Added by the TCXMEDI-C TROJAN!
winltmpv wutop.exe X Added by the TCXMEDI-C TROJAN!
Winmain winmain.exe X One of the first of a new breed of malware. When run it immediately loads MSHTA.EXE from the Windows folder, placing it on "hot standby", ready to accept HTA scripting within a web page and then EXECUTE what is embedded IN the page as a program! In other words, it's possible for a "rogue" website to actually embed trojans, worms and/or viruses directly into a web page. BOClean's HTA Stop offers an easy way to toggle this capabiltity, or rather vulnerability, on and off. I suggest you leave it disabled!
winmatrix.exe WinMatrixXP.exe U WinMatrix XP - wallpaper replacement that shows different matrix effects (including flowing matrix codes from 'The Matrix' movie) on your desktop
WinMem WinMem.exe U WinMem Cleaner - part of Ultra WinCleaner Utility Suite. Makes more memory available for your programs and the Operating System. It also defragments your system
WinMenssage winmax.exe X Added by the BANCOS.B TROJAN!
WinMgmt WinMgmt.exe N Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here
WinMgr32 winmgr32.exe X Added by the MIMAIL.P WORM!
winmodem wmexe.exe Y Software for software based modems. Required if you have one of these. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information
WinMsrv32 WinMsrv32.exe X Added by the GAOBOT.AFJ WORM!
WinMX WinMX.exe N WinMX file sharing application
winmysqladmin winmysqladmin.exe N Starts the MySQL database admin tool
WinMySQLadmin Tool winmysqladmin.exe N Starts the MySQL database admin tool
winnet winnet.exe X CommonName Toolbar spyware. To uninstall see here
Winnov Menu WnvMenu.Exe ? Winnov Video Capture Card related. What does it do and is it required?
Winnov Remote WnvRsvr.Exe ? Winnov Video Capture Card related. What does it do and is it required?
Winnov Status WvStatus.Exe ? Winnov Video Capture Card related. What does it do and is it required?
WinNtBB WinntBB.exe X Added by the DULOAD.C WORM!
Winnup win32nls.exe X Added by a variant of the SPYBOT WORM!
winocx32 winocx32.exe X Added by the PROTORIDE.I WORM!
Winpack winpack.exe X Adware downloader - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Agent.gg
WinPatrol WinPatrol.exe U WinPatrol - "Manage Startup programs, tasks, cookies; will sniff out Worms, Trojan horses, Cookies, Adware, Spyware, Klez, Assumption and other malicious programs"
winpipe winpipe.exe X Browser hijacker redirecting to wow-access.com
WinPoet WinPPPoverEthernet.exe Y WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking
WinPopup WINPOPUP.EXE N Intranet chat software provided by windows for chat on small networks. Handy little LAN messaging utility. Has been included in Windows since 95, and maybe in WFWG 3.11. Normally it won't set itself up to run unless the user specifically adds it to startup
winpopup winupie.exe X Adware by Tradeexit.com
WinProt Winprot.exe X Added by the CHUPACABRA TROJAN!
winprotect win32.exe X Added by the MUGLY.E WORM!
WinProxy WinProxy.EXE U "WinProxy is the world-first proxy server and a firewall with integrated mail server for Windows 95/98/ME/NT/2000/XP"
winpsd winpsd.exe X Added by the MYDOOM.Q WORM!
winrar winrar.exe X CoolWebSearch parasite variant. Note - this is not the file zipping utility also known as WinRAR and it's located in C:\Winnt or C:\Windows
winrarshell winrarshell32.exe X Added by the SALIRA TROJAN!
winReg winReg.exe X Added by the YAHA.H or YAHA.J WORMS!
winregsrv winregsrv.exe X Added by the SYNRG TROJAN!
winroute winroute.exe N Win-Route 4.27. WinRoute Tray Icon for starting and stopping the WrCtrl.exe process, also to log in to the console to view logs and change settings. Can be unchecked and the engine still runs and functions normally. Can then use provided shortcuts for administration of the program. Loaded in SERVICES on Windows 2k
winrun winrun.exe X Added by the WINBUR.B WORM!
WinRunners WinDrivers.exe X Added by the DULOAD.C WORM!
WinSec winsec16.exe X Added by the AGOBOT.ZF WORM!
winsecure winsecure.exe X Browser hijacker, redirecting to specificsearches.com
WinServices WinServices.exe X Added by the YAHA.K or YAHA.M WORMS!
winservn winservn.exe X PurityScan/Clickspring adware
winservs winservs.exe X PurityScan/Clickspring adware
Winshoe wuadfdqr.exe ? Probably an unidentified VIRUS! Adds itself to 3 registry "Run" keys and prevents Task Manager being displayed. This is not the Winshoe IRC Client as the visitor did not have it installed
Winsock2 driver WINCFG.SCR X Added by a variant of the SPYBOT WORM!
Winsock2 driver winupdate.exe X Added by the SPYBOT-BX WORM!
Winsock2.dll WINLODR.SCR X Added by an unidentified VIRUS, WORM or TROJAN!
Winsock32driver win32server.scr X Added by the HACARMY TROJAN!
Winsock32driver win32server.exe X Added by the BACKDOOR-AZV TROJAN!
Winsock32driver win32server.exe X Added by the HACARMY.F TROJAN!
Winsock32driver winXPupdate.exe X Added by the HACKARMY.9728 TROJAN!
winsockdriver winsock2.2.exe X Added by a variant of the SPYBOT WORM!
WinSPF windrv32.exe X Added by the MYDOOM.T WORM!
WinSPF winspf32.exe X Added by the MYDOOM.S WORM!
Winspl winsplx.exe X Added by a variant of the TROLL-A TROJAN!
Winsrv winsrv.exe X Added by the OPASERV.T WORM!
WinStart WinStart.exe X From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge
WinStart Wscript.exe WinStart.vbs X Added by the CIAN.C WORM!
WinStart winstart32.exe X Added by the PUROL WORM!
WinStart WinStart.pif X Added by the CONE.E WORM!
WinStart001 WinStart001.exe X From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge
WinStart001.EXE WinStart001.exe X From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge
Winsta~1 winsta~1.exe X GoHip foistware
WinSth16 WinSth16.exe X Added by the CAKE WORM!
Winsvc32 Winsvc32.exe X Homepage hijacker
Winsys Winsys.exe U Win-Spy - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it 
WinSys32 Winsys32.exe X Added by the CIGIVIP TROJAN or RECKUS WORM!
winsys32 Driver winsys32.exe X Added by the LOONY-O TROJAN!
WinSysAppMon WinSysRM.exe U Home & Family Content Filter related. See here
winsyslog lptt01 winsyslog.exe X Variant of the RapidBlaster parasite (in a "Winsyslog" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
WinSyst32 winsyst32.exe X Added by the MORB WORM!
WinSystem winsystem.exe X Added by the WHITEBAIT WORM!
Winsystem winsystem.exe X Added by the BANCOS.CR TROJAN!
WINT wcp****.exe [* = random char] X PurityScan/Clickspring adware
WINT wcpcc.exe X PurityScan/Clickspring adware
WINT wcpsvit.exe X PurityScan/Clickspring adware
WinTask Wintask.exe X Added by the HIPO or LEMIR.F TROJANS!
WinTask driver wintask.exe X Added by the SMALL.ABD downloader TROJAN!
WinTasks Traybar wintasks.exe U WinTasks - "Efficient Resource and Task Management is absolutely critical if you want to achieve the highest system performance levels possible. WinTasks 4 will not only help you achieve this task, but will actually make your system run faster and more smoothly than ever before"
wintasks.exe wintasks.exe X Added by the EVAMAN WORM!
Wintercooler Pro WINCOOL.EXE N Wintercooler Pro - utility that monitors CPU usage, RAM consumption and Internet connection speed
WinTidy WinTidy.exe N Desktop icon manager from PC Magazine (Ziff-Davis) for Win95. Available via Start -> Programs
Wintime Wintime.exe X Added by the HARNIG TROJAN!
Wintime Wtxpload Wxpload.exe Wintime N Part of the software to support a Dexxa USB graphics tablet. From a visitor - "This gets started anyway when you plug in the USB connector for the graphics tablet, if it's not already running. It then starts an application which manages the tablet messages. Since I leave the tablet unplugged unless I need to use it, I don't need this running at startup. I suspect that this program monitors a number of windows messages, so that when it's loaded, my regular mouse slows down - it acts like it 'sticks' entering and leaving windows. Certainly my performance returned to what I expected when I removed this item using MSCONFIG"
WinTools WToolsA.exe X Wintools adware
WinTray wintray.exe X Added by the LEGUARDIEN.B TROJAN!
winupated.exe winupated.exe X Added by a variant of the SDBOT WORM!
winupd.exe winupd.exe X Added by the BEAGLE.M or BEAGLE.N WORMS!
winupdat winupdat.exe X Added by the CANBOT.A WORM!
WinUpdate wmbem.exe X Added by the REVCUSS.B TROJAN!
winupdate.exe winupdate.exe X Added by the RADO TROJAN!
winupdate.reg winupdate.exe X Added by the SPYBOT.EAS WORM!
winupdtl winupdtl.exe X SecondThought adware variant
winur winrun.exe X Added by the WINBUR.B WORM!
winusb.dll winguard.exe X Added by the FORBOT-CN WORM!
winversion winversion.exe X Browser hijacker, redirecting to specificsearches.com
WinVNC WinVNC.exe U WinVNC is an application that allows you to remote control your PC from another PC somewhere on the internet
winwan lptt01 winwan.exe X Variant of the RapidBlaster parasite (in a "Winwan" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
winwan ml097e winwan.exe X Variant of the RapidBlaster parasite (in a "Winwan" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
winxpdll32.exe winxpdll32.exe X Added by a variant of the SMALL downloader TROJAN!
WinZip Quick Pick WZQKPICK.EXE N Added with WinZip version 8.1. "The new WinZip Quick Pick taskbar tray icon gives you instant access to WinZip and your Zip files. Just left click the icon to open WinZip, or right click it to instantly reopen recently used Zip files, access your Favorite Zip Folders, open WinZip Help, or start WinZip itself.". You can right-click and close it - choosing to not re-load it at start-up
win_spool2 win_spool2.exe X Added by the SCKEYLOG.B TROJAN!
win_upd.exe WINdirect.exe X Added by the MITGLIEDER.M TROJAN!
win_upd2.exe WINdirect.exe X Added by the BEAGLE.AO WORM!
Win_vader Win_vader.vbs X Added by the INVASION.A VIRUS!
WIP Config GUI Winipcfgs.exe X Added by the RBOT-CN WORM!
Wireless PCI Card Configuration Utility WMP11Cfg.exe U Utility used by the LINKSYS wireless PCI card (WMP11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration
Wireless Provider Server wpsvr.exe X Added by the FORBOT-AD WORM!
Wireless-G Notebook Adapter Utility WPC54CFG.EXE U Utility used by the LINKSYS Wireless-G Notebook Adapter (WPC54G)
wjview wjview.exe N MS tool used to view window-based Java applications from the command line
wkcalrem wkcalrem.exe N Produces a pop-up reminder of events scheduled using the MS Works Calendar
WkDetect WkDetect.exe N Checks for updates to MS Works
wkfud wkfud.exe N A marketing program for MS Works
WksSb WksSb.exe N The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program. The Works Portfolio provides a location where you can store items you want to later put into a document or other file
WkUFind WkUFind.exe N MS Works Update Detection. MS Picture It! (versions 7 to current) use this automatic update feature during the log on process. It can also cause your system to automatically dial into your ISP as it tries to access the internet, if you have your system set to automatically dial when the internet is invoked. To manually update, go to Microsoft's Office/Works update site
Wlan Drier Winusb2.exe X Added by the WOOTBOT.DC WORM!
WLAN Status Tray Applet WLANSTA.EXE N System Tray icon for checking the status of a Wireless LAN
WLAN_Cfg.exe WLAN_Cfg.exe Y Linksys Instant Wireless USB Network Adapter driver
WMAudio winlogon.exe X Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
WMIEXE.exe wmiexe.exe U NT component, used by Windows Millennium to detect  Plug and Play-compliant IEEE 1394 devices during the startup process. Since this is important for the computer to work properly if you have these, Windows Millennium protects wmiexe.exe and will restore the file even if it's deleted or renamed. Check here for some details on what to do to stop it loading
Wminf Wminf.exe X Added by the GEMA TROJAN!
Wminfo Wminfo.exe X Added by the GEMA TROJAN!
wmiprv wmiprv.exe X Added by the RBOT-WM WORM!
WMP54Gv4 WMP54Gv4.exe Y Linksys WMP54G Wireless-G PCI Adapter driver
wmsys32 wmsys32.exe X Added by the BANPAES.B TROJAN!
WNAD WNAD.EXE X Spyware added as a result of running a program called "Yo Mama Osama" (osama.exe). See here for more and how to get rid of it. There are other ways this can show up on your system, and it will manifest itself by periodically opening a new browser window with advertising for copy DVD software and the like
WNSC wns*****.exe [* = random char] X PurityScan/Clickspring adware
WNSI wnscp**.exe [* = random char] X PurityScan/Clickspring adware
WNST wns*****.exe [* = random char] X PurityScan/Clickspring adware
Woowatch Watch.exe N Wanadoo ISP software, not required
WordWeb wweb32.exe N WordWeb - free theasaurus and dictionary. Start manually
Workflo workflow.exe ? Related to BroadJump Client Foundation - broadband troubleshooting software installed by various companies. Is it required?
Works Calendar Reminder wkcalrem.exe N Produces a pop-up reminder of events scheduled using the MS Works Calendar
WorksFUD wkfud.exe N A marketing program for MS Works
Workstation Scheduler wm95.exe U Desktop Management Scheduler. Part of Novell's Netware Client. Schedueles NDS events. If events have been schedueled, it is required, otherwise, it is useless and a memory hog
Workstation Services wrkstn.exe X Added by the RBOT-OJ WORM!
Worm Detector wd.exe U Worm Detector - antivirus add-on for Outlook 2K or XP for handling worms and spam
wormexe winstart.exe X Added by the EARLYBIRD WORM!
wovax wovax.exe X Added by the DAQA.A TROJAN!
Wpctrl wpctrlnt.exe N WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties
Wpctrl wpctrl95.exe N WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties
wpctrl95 wpctrlnt.exe N WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties
wpctrl95 wpctrl95.exe N WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties
WPCycle.exe WpCycleWin.exe Y Added when selecting Mplayer2 to open media files. Forces other codes to Wait for Previous instructions to end, preventing instability of your CPU (freezing)
WQK WQK.exe X Added by a variant of the KLEZ WORM!
wr WR.EXE ? ??
WR Command wr.exe ? ??
WrCtrl WrCtrl.exe N Win-Route 4.27 NAT engine on Win2k Pro for connection sharing and security using Win-Route by Tiny Software. A connection sharing/Firewall Application. If service is disabled the program does not work, but you can manually start/stop the service with a shortcut the program installs at any time
WRDialer WrDialer.exe X WinPoet DSL dialler
WregBios wregbios.exe ? Desktop Management BIOS (DMI BIOS) related. Apparently invokes the DosBios.exe file. Is it required?
wrexec wrexec.exe U Watch Right - monitoring program, part of the PowerTools add-on for AOL. Records instant messages, E-mail, chat. Watch Right appears to be, and functions as an online clock updater which connects with the U.S. National Institute of Standards and Technology. It was designed for parents who wish to keep an eye on what their children are doing online
wriste wriste.exe ? ??
ws2help ws2help.exe X Added by a variant of the SMALL.AN TROJAN!
WSAConfiguration wmon32.exe X Added by the GAOBOT.BAJ WORM!
WSAConfiguration win32upd.exe X Added by a variant of the RBOT WORM!
wsbklite wsbklite.exe ? Related to the Acer Soft Button on Acer Tablet PCs. Appears to do nothing so is it required?
WScheduler WScheduler.exe U Windows Scheduler - "schedule unattended running of applications, batch files, scripts and much more. Also, you can schedule popup reminders so you'll never forget reminders, tasks and other events."
Wsdata service WSconf.exe X Added by the SDBOT.ZU WORM!
wserver wserver.exe X Added by the NETSKY.AC or SASSER.G WORMS!
WService WService.exe U Tablet client Driver for UC-Logic Pen/Graphics Tablet
WSSAConfiguration wmmon32.exe X Added by the AGOBOT-KC WORM!
Wstat32 driver Wstat32.exe X Added by the LOONBOT TROJAN!
wstimeb wstimeb.exe Y Used with NEC printers. You can disable it before printing but it re-loads itself when printing so you may as well leave it
wswpd wswpd.exe Y Used with some models of Panasonic, Epson and NEC printers. Some older drivers known to have a "memory leak". Needed for printing to work 
WT Game Channel wtgamechannel.exe N WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
WT GameChannel wtgamechannel.exe N WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
WTSI wapisvit.exe X PurityScan/Clickspring adware
WTSS wap***.exe [* = random char] X PurityScan/Clickspring adware
WTST wapisvtr.exe X PurityScan/Clickspring adware
WUOLService WUOLService9x.exe Y Remote wakeup status agent. Part of Novell's ZenWorks. Processes Wake-up on LAN requests (turn on a computer remotely on LAN)
wupdt wupdt.exe X Added by the IMISERV.A TROJAN!
WUSB11B.exe WUSB11B.exe Y Linksys WUSB11 WLAN USB adapter
wvsvc wvsvc.exe X Added by the AGOBOT.YM WORM!
WXProcMgr Module WXprocMgr.exe N TVTonic from Wavexpress - "enjoy 3 full-screen, DVD-quality video channels for FREE". Allows data content to be downloaded and synchronized on your system
wzhelper wzhelper.exe X Searchcentrix hijacker
X10Weax WTHRTRAY.EXE X WeatherCheck - "bring the latest local weather to your desktop". Not recommended as it reportedly pops ads, and contains no uninstaller
xp_system winlogon.exe X KREPPER-G trojan, a CoolWebSearch parasite variant. Note - this is NOT the legitimate winlogon.exe process, which should NOT figure in Msconfig/Startup!
YOW tuner WatchPNM.exe ? ??
z-WrDialer WrDialer.exe U WinPoet DSL dialer
[random name] wincpu.exe X Added by an unidentified VIRUS, WORM or TROJAN!
[various names] Windows32.exe X Added by any of a number of WORM or TROJAN variants
[various names] winlogon32.exe X Added by an unidentified WORM or TROJAN!
[various names] win32snd.exe X Added by the RBOT-DQ WORM!
[] winbas12.exe X Adware, probably CoolWebSearch parasite related - recognized by Kaspersky antivirus as TrojanDownloader.Win32.VB.du
_winadm winadm.exe U Parents Friend - "Log any activity and protect programs with a password. Further more you can lock the pc any hour in the week you want with the main password. You can also give users allowed programs in their program-lists and you can limit the maximal daily hours and maximal weekly hours user spend on the PC"
Windows AdStatus WinStat.exe X Unknown adware which causes popups. Can be removed via Add/Remove Programs in your control panel.
WINDOWS MANAGEMENT SYSTEM wm1exe.exe X W32/Rbot-VT is a network worm that has backdoor functionality. Located in the Window system directory.
*windows update wuaruclt.exe X Added by W32/Rbot-TF. File is found in the Windows system directory.
WindowsUpdate WUpdate_35253825.vbs X Added by VBS/Ediboy-C. File is located in the Windows directory. Also see SysReg.vbs
Windows Messenger Service winsmsgr.exe X Added by W32/Rbot-VW. Found in the Windows system folder.
virtual-machine winlogin.exe X Added by W32/Rbot-VU
ttfload wscript.exe %windir%\Fonts\ttfload.vbs X Added by the VBS/Mcon-G worm.
Windows DDE Loader windde32.exe X Added by the W32/Sdbot-UZ WORM! Found in the Windows system folder.
win32 winhost.exe X Added by the Bropia.F worm.
winpsd.exe winlibs.exe X Added by the Mydoom.S WORM! Located in the Windows system directory.
Windows Logger winlog.exe X added by the Backdoor.Netshadow backdoor.
FIX WinFIX1.0.vbs X Added by the VBS.Gormlez@mm infection! Found in the Windows directory.
UPDATE WinUpdater5.0.vbs X Added by the VBS.Gormlez@mm infection! Found in the Windows directory
Win32 Services1 wuamngr1.exe.exe X Added by the Backdoor.Sdbot.AN Backdoor! Found in the Windows system directory.
Secboot w32tm.exe X Added by the Backdoor.Haxdoor.D backdoor. Found in the Windows system directory.
Winserv Winserv.ila X Added by the W32.Nodmin@mm infection!. Found in the Windows directory.
winhlp.exe winhlp.exe X Added by the PWSteal.Formglieder Infection! Found in the Windows directory.
System Document Application winsvc32.exe X Added by the W32/Sdbot-VA WORM! Found in the Windows system folder.
Windows Network Controller winmms32.exe.exe X Added by the W32/Forbot-ED wORM! It is found in the Windows system directory.
SYSTEM wuamgre.exe X Added by the W32/Rbot-WA Backdoor/WORM! Found in the Windows system folder.
win-xp winis.exe X Added by the W32/Rbot-BBD WORM! Found in the Windows system folder.
Wireless Conections WireConnect.exe X Added by the W32/Sdbot-VF WORM! Found in the Windows system folder.
winprotect winprotect.exe X Added by the W32/Sdbot-SB worm! Found in the Windows system folder.
winupdtl winupdt.exe X Windupdates adware
Wireless Zero Daemon wzdsvc.exe X Added by the W32/Codbot-E WORM! This service loads in safe mode to make it more difficult to remove.
Windows IPv6 Drivers wipv6.exe X Added by the W32/Sdbot-VJ WORM! Found in the Windows system folder.
Sistray32 win.bat X The W32/Jupir-A is spread via MIRC. The file can be found in the Windows system directory.
Video Process wincrt32.exe X Added by the W32/Agobot-GR WORM/IRC Backdoor. File is found in the Windows system folder.
win32app Winpup32.exe X Added by the Troj/AdClick-N Trojan! File is found in the Windows system folder.
winsystem.sys WINLOGON.EXE X Added by the W32/Sober-K infection! File will be found in the %WINDIR%msagentwin32 folder.
_winsystem.sys WINLOGON.EXE X Added by the W32/Sober-K infection! File will be found in the %WINDIR%msagentwin32 folder.
Microsoft Update Engine wumgpds.exe X W32/Rbot-WK WORM! File is found in the Windows system folder.
LSA wfdmgr.exe X Added by the W32/MyDoom-BG WORM! File is found in the Windows system folder.
winltmpv WINLTMPV.EXE X Added by the TCXMEDI-C TROJAN!
Winamp Agent winamp.exe X Added by the W32/Poebot-I WORM! This file is found in the Windows system folder.
virtual-machine wini.exe X Added by the WORM W32/Rbot-WR, and found in the Windows system folder.
MsnExplorer winagent.exe X Added by Troj/Bdoor-EQ, a backdoor TROJAN found in the Windows folder.
down winhelp.exe X Added by a TROJAN/DOWNLOADER, Troj/Dloader-FQ, and is found in the Windows system folder.
winshost.exe winshost.exe X Added by the Troj/BagleDl-K Trojan. The file for this infection is found in the Windows system folder.
Novell ZfD Wake on LAN Status Agent WolSerNT.exe Y Part of the Novell Windows Client. The service name is Prometheus Wake-On-LAN Status Agent. It is found in the C:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent folder.
Workstation Manager wm.exe Y Part of the Novell Windows client. Found in the C:\Program Files\Novell\ZENworks folder.
Daily Weather Forecast WEATHER.EXE X Added by Troj/Dloader-IP TROJAN to the Windows program folder.
WindowsCRC wscrc.exe X Added by W32/Sdbot-VU, a WORM!
Firewall wmlaunch .exe X Added by a WORM, W32/Elitper-A. It will be found in the Windows Program Files folder.
Printer Monitor webprinter.exe X A TROJAN, Troj/IRCBot-Z adds this file to the Windows system folder.
Microsoft SpA Service win32.exe X This is a SDBot variant backdoor infection. When run this infection connects to an IRC server, d-3.biz.
Windows Domain Name Drivers windns.exe X Added by the W32/Forbot-EP WORM/IRC backdoor Trojan to thee Windows system folder,and is as a new service called "IEXPLORER-Drivers" with a display name of "Windows Domain Name Drivers".
IEXPLORER-Drivers windns.exe X A service is created by the W32/Forbot-EP WORM, and run using the display name of "Windows Domain Name Drivers".
twhe wbta.exe X PurityScan delivers advertisements to your computer.
WLTRYSVC WLTRYSVC.EXE Y Part of the Broadcom Corporation Wireless Network Tray Applet which allows you to change and see settings for the hardware.
Windows Time winmgr.exe X The W32/Rbot-XC WORM/backdoor Trojan adds this and allows malicious remote access by way of the IRC network.
128 Module win128.exe X Added by the W32/Forbot-ES WORM/backdoor Trojan, which allows unauthorized access to the PC using the IRC network and registration of a new service process "Windows 128 Module".
Website Administrator Info webadmin.exe X W32/Forbot-FY will connect to an IRC server and establish a new service named "Connection Reset", with the display name "Website Administrator Info".
Connection Reset webadmin.exe X A new service is set by W32/Forbot-FY with a display name of "Website Administrator Info"
NTSF MICROSOFT SYSTEM wntsf.exe X An Rbot variant. This infection connects to an IRC server where it will await commands from a remote user.
Windows Service Loader window.exe X An Rbot variant. This infections connects to an IRC server where it awaits commands from a remote user.
USB 2.0 Driver winsystem.exe X Added by the W32/Agobot-QS WORM/IRC backdoor, it kills a variety of processes relating to anti-virus and security related programs.
WINLOGON WINL0GON.exe X The Troj/Nethief-K TROJAN adds the file, which you'll note contains "zero" instead of "o".
Windows System Configuration WINFRW.EXE X Added by the W32/Domwis-H WORM/IRC backdoor Trojan, it will grant an attacker remote access to perform a wide variety of actions.
USB 2.0 Driver Winsys32.exe X W32/Agobot-QM WORM will add this file, resulting in unauthorised access, by way of an IRC channel, through a backdoor.
AdAware wini.exe X Added by the W32/Rbot-XN WORM/IRC backdoor.
WINAPLOGUPD WINAPLOGUPD.EXE X Added by the W32/Capside-C WORM, which exploits typical P2P program folders, and spreads via IRC clients and through netwerk shares.
UpData wupdata.exe X Troj/IRCBot-AA , a TROJAN/IRC backdoor, will allow an attacker to access and exploit the computer when this file is added.
Microsoft MediaScope winmes.exe X Added by the W32/Rbot-XU WORM/backdoor, it's file will allow a remote attacker to create new accounts, terminate processes, record keysrokes and other actions.
Windows Media Player wmplayer.exe X An R-bot variant adds this, opening a backdoor to a malicious user and allowing the start of a remote shell, and download/upload/execution of various files.
WCESMngr WCEMNGR.EXE X The W32/Agobot-QX WORM/backdoor Trojan adds this, modifying the HOSTS file and terminating security-related/anti-virus processes also.
Windows Monitor Services winmonitor.exe X The W32/Rbot-XX WORM/IRC backdoor Trojan adds this, allowing unauthorized remote access and termination of processes, DoS attack participation, and downloads/executes other files.
Windows Media Player 3.6d wmpa36d.exe X The W32/Rbot-YA WORM/backdoor places this to spread to network shares, and allow unauthorised remote access.
Microsoft Windows Registry Service wregistry.exe X A Rbot WORM/IRC backdoor variant adds the file, making possible DoS attacks, running of a file server, password theft or a remote command shell put into effect.
*windows update wurauclt.exe X Added by the RBOT-SY WORM! This file runs in safe mode as well making it slightly harder to remove.
0190 Warner WARN0190.EXE X Anti-dialer program (Germany)
0900 Warner WARN0900.EXE X Anti-dialer program (Germany)
erghgjhjgdr windlhhl.exe X Added by the BEAGLE.BG mass-mailing worm!
Index Washer WashIdx.exe U Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
WinSvc16.exe WinSvc16.exe X Added by the SDBOT.FQ TROJAN!
WLANSTA.EXE WLANSTA.EXE N System Tray icon for checking the status of a Wireless LAN
WUSB54Gv4 WUSB54Gv4.exe Y Wireless-G USB Wireless Network Adapter related - would appear to be required
NvCplScan winasp.exe X Added by a variant of the RBOT WORM!
Video Process winasp.exe X Added by the AGOBOT-IS WORM!
WhenUSearchWHSE whse.exe X SaveNow adware
Windows FormatAd WinForm.exe X Windupdates adware variant
Windows Network Controller WinxPupd.exe X Added by the FORBOT-DK WORM!
load32 winldra.exe X Added by the Troj/Dumaru-AT TROJAN!

These files are known to be part of an infection that transmits information about your bank accounts, passwords, and other financial information. It should be deleted immediately, enable your firewall, change your passwords, and contact your banks or other financial instituions.
LTM2 winscan.exe X Added by the Troj/Litmus-B TROJAN!
Winhost winhost.exe X Added by the Troj/Delf-JL TROJAN!
Configuration Loader Service winsys32.exe X Added by the W32/Rbot-YV WORM/IRC backdoor!
Windows Media Player wmplayer.exe X The W32/Rbot-YT WORM/IRC backdoor adds the file, a hidden, read-only, system file.
Systems Backups windrives.exe X Added by an Agobot WORM/IRC backdoor variant, also creating a new service, servicename "Restoreds" and a displayname "Systems Backups".
Restoreds windrives.exe X A new service added by the W32/Agobot-RB WORM/IRC backdoor, it's displayname is Systems Backups .
Microsoft Rundll windos.exe X Added by the W32/Sdbot-WF WORM/IRC backdoor!
[X] WUCMDEX.EXE X Added by the W32/Rbot-DO WORM/IRC backdoor Trojan!
WinInit Win86.exe X Added by the Troj/Small-PB TROJAN!
virtual wini.exe X Added by the W32/Rbot-YX WORM/IRC backdoor Trojan!
Windows Media Player wmplayer.exe X Added by the W32.Kelvir.G or W32.Kelvir.H or W32.Kelvir.I WORM!
update service winx.exe X Added by a variant of the WIN32.RBOT WORM!
Windows USB Driver Support Windowsusb.exe X Added by a variant of the W32.SPYBOT WORM!
*windows update wscxt.exe X Added by an unidentified WORM!
[random name] w?nlogon.exe X PurityScan adware variant.
[random name] w?nword.exe X PurityScan adware variant.
Microsoft MicroP Protocol wdgmr32.exe X Added by a variant of the WIN32.RBOT WORM!
Microsoft Updates wuamgrds.exe X Added by a Rbot variant.
Configuration Loading Service wscel.exe X Added by the W32/Sdbot-WJ WORM/IRC backdoor Trojan!
Winsock driver winnt update.exe X Added by the Troj/Spybot-DM TROJAN/IRC backdoor!
WinAMP winamp62.exe X Added by the W32/Sdbot-WN WORM/IRC backdoor Trojan!
Windows DLL Services winsvc32.exe X Added by the W32/Rbot-ZF WORM/IRC backdoor Trojan!
winmdgr winsvcmgr.exe X Added as a new service by the W32/Sdbot-WQ WORM/IRC backdoor, and uses a displayname of Microsoft Service Manager.
winbin32 win32exe.exe X Added by the W32/Rbot-ZL WORM/IRC backdoor!
[random name] w?auboot.exe X PurityScan/Clickspring adware
[random name] w?auclt.exe X PurityScan/Clickspring adware
ssgrate.exe winsystems.exe X Added by the TROJ/BAGLEDL-J TROJAN
WINLOG0N WINLOG0N.EXE X Added by the W32.MYDOOM.BI WORM!
Windows_Protect winregal.exe X Added by a variant of the WIN32.RBOT WORM!
NettGain2000 WgwMngr.exe Y Required for Starband satellite service.
couponsandoffers wjview.exe X Added by the Adware.TopMoxie adware. Not to be confused with the legitimate wjview.exe Microsoft file.
winmrg winmrg.exe X Added by the Backdoor.AntiLam.20 backdoor.
Hrxmp Win Const.exe X Added by Backdoor.Assasin.E Trojan
Internet Explorer Plugin WinStop32.exe X Added by the Backdoor.Backage backdoor.
Hello World WinPad.exe X Added by Backdoor.CHCP. This infection listens on TCP port 1145 awaiting remote connections.
Microsoft auto update wuauclt.exe X Added by BackDoor CLT. This infections connects to an IRC server where it awaits commands. If this infection is on a Windows XP, NT, 2000, 2003, or Vista box then it may have overwritten your legitimate file.
Windll wingmnt.exe X Added by Backdoor.Cmjspy.B.
Wingmnt wingmnt.exe X Added by Backdoor.Cmjspy.B.
Windows Logon Application winlogon.exe X Added by Backdoor.Dsklite. This infection listens on port 890 awaiting commands.
Wincfg.exe Wincfg.exe X Added by Backdoor.Elitem.
FTH2004 WindowsDAT.exe X Added by the Backdoor.Futh backdoor. This infection listens on TCP ports 7896 and 7897 awaiting commands.
MAT WliveUPdate.exe X Added by the Backdoor.Futh backdoor. This infection listens on TCP ports 7896 and 7897 awaiting commands.
NortonAVProtect WliveUPdate.exe X Added by the Backdoor.Futh backdoor. This infection listens on TCP ports 7896 and 7897 awaiting commands.
Player00997 WliveUPdate.exe X Added by the Backdoor.Futh backdoor. This infection listens on TCP ports 7896 and 7897 awaiting commands.
Shell2938 WliveUPdate.exe X Added by the Backdoor.Futh backdoor. This infection listens on TCP ports 7896 and 7897 awaiting commands.
QuickTask WliveUPdate.exe X Added by the Backdoor.Futh backdoor. This infection listens on TCP ports 7896 and 7897 awaiting commands.
Windows Update winupdate.exe X Added by the W32/Sdbot-WS WORM/IRC backdoor Trojan.
Winapp32.exe Winapp32.exe X Added by the Backdoor.GF.13 backdoor trojan!
Windows NetStart Service winsN2S.exe X Added by W32/Rbot-ZX.
Distributed File System win.exe X Added by the W32/Myfip-L WORM, which also creates a new service/displayname called Distributed Link Tracking Extensions.
WinAdCnt.exe WinAdCnt.exe X Added by Troj/Banker-BU to compromise online banking sites.
wuanguard wuanguard32.exe X Added by W32/Rbot-AAF. The WORM has IRC backdoor trojan functionality.
wmv winmonv.exe X Added by the Troj/Agent-DG TROAJAN/backdoor.
MicroSoft Window Updater winsupdater.exe X Added by W32/Rbot-ZZ.
Registry Integritycheck WCPDT.EXE X Added by the W32/Agobot-RF WORM.
updater wisvc.exe X Added by Troj/Orse-A, which also creates a service using the same name, with a displayname of Windows update Service.
windhost.exe windhost.exe X Added by Troj/Banker-BV or Troj/PWSAgent-A trojans.
winnt DNS ident wuamgrd32.exe X Added by an Rbot WORM variant.
wintsk32dll wintsk32dll.exe X Added by the W32/Rbot-AAJ WORM/IRC backdoor trojan!
Windows Firewall WindowsFirewall.exe X Added by the W32/Mytob-X WORM/IRC backdoor trojan!
longos WIWT.EXE X Added by the Troj/Banker-CD TROJAN!
xpstat winlogins.exe X Added by the W32/Rbot-AAR WORM/IRC backdoor trojan!
PPPOEOE WINLITE.EXE X Added by the W32/Rbot-AAN WORM/IRC backdoor trojan!
Shell wmedia32.exe X Added by the Troj/Goldun-B TROJAN!
winzip winzip.exe X Added by a variant of the RBOT WORM!
NTSF MICROSOFT SYSTEM win32db.exe X Added by a variant of the RBOT WORM!
Microsoft Update wssvr.exe X Added by the W32/RBOT-OD WORM!
Windows DLL host winupd32.exe X Added by a variant of the W32.SPYBOT WORM!
Update Service winu32.exe X Added by the W32/RBOT-MG WORM!
System Update Service winupd32.exe X Added by the ADTODA-A TROJAN!
Microsoft Update windows24.exe X Added by a variant of the WIN32.RBOT WORM!
Microsoft Update Machine wupdate32.exe X Added by a variant of the WIN32.RBOT WORM!
Registry Checkup System326a Monitor Winregs326a.exe X Added by a variant of the W32/SDBOT WORM!
Windows Logon Application WinIogon.exe X Added by the "Cruel Intentionz" backdoor TROJAN!
*windows update wkmst.exe X Added by the SDBOT.AVD WORM!
System Drivers wingmt.exe X Added by the W32/SDBOT-MG WORM!
Windows Network Controller wingmt.exe X Added by a variant of the W32/SDBOT WORM!
SvcH0st WINAGENT.EXE X Added by the TROJ/BDOOR-EB TROJAN!
Microsofts MediaScope winmedplay.exe X Added by a variant of the WIN32.RBOT WORM!
Microsoft Hosting Service WINHOSTING.EXE X Added by the RBOT.AEV WORM!
Start Upping windupds.exe X Added by the SDBOT.AFH WORM!
Windows Driver winxpdriver.exe X Added by the WOOTBOT.EE WORM!
Windows Update Auto Update wuaumgr.exe X Added by a variant of the W32.SPYBOT WORM!
Machine Update Soft wusas.exe X Added by an unidfentified WORM!
Msn Updater windatemanager.exe X Added by the SDBOT.TS WORM!
Task Help wualcts.exe X Added by a variant of the WIN32.RBOT WORM!
*wuauclt.exe wxmct.exe X Added by an unidentified WORM or TROJAN!
wuviewer wuviewer.exe X Added by a Proxy_Trojan variant
Microsoft Update wuamagr32.exe X Added by the SPYBOT.CG WORM!
msgina wuauclt2.exe X Added by the Troj/Iyus-H TROJAN!
Registry Checkup System32cd Monitor Winregs32cdn.exe X Added by the W32/Rbot-AAV WORM/IRC backdoor trojan!
*windows update wuruclt.exe X Added by the W32/Rbot-TA WORM/IRC backdoor trojan!
Microsoft SpAr Service winsbsd32.exe X Added by the W32/Rbot-TJ WORM/IRC backdoor trojan!
Microsoft Update winupdate32.exe X Added by the W32/Rbot-TI WORM/IRC backdoor trojan!
DNS Config service win32.exe X Added by the W32/Rbot-TL WORM/IRC backdoor trojan!
System winipck.exe X Added by the W32/Rbot-TK WORM/backdoor trojan!
Microsoft Windows Registry Updater wreg.exe X Added by the W32/Forbot-DN WORM/IRC backdoor trojan, while it creates a new service called wreg.
Microsoft Windows Storage Machine Service winms.exe X Added by the W32/Rbot-AHK WORM/IRC backdoor trojan!
WindowsFY wp.exe X Identified as Trojan.Win32.Agent.ct. When run this file extracts a bmp file to the c: folder and sets it as your desktop background.
WinAdCnt16.exe WinAdCnt16.exe X Added by the Troj/Banker-AT TROJAN!
Windows Desktop Controler windesktop.exe X Added by the W32/Sdbot-XH WORM/IRC backdoor trojan!
load wuauc1t.exe X Added by the Troj/Dloader-LY TROJAN!
wuauc1t.exe wuauc1t.exe X Added by the Troj/Clicker-DR TROJAN!
[unknown] WUAGMSD.EXE X Added by the W32/Rbot-AX trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
MS Unix Binary Win32Update.exe X Added by the W32/Rbot-BAS trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windowsxp Updater 16Bit winupdos.exe X Added by the W32/Rbot-BE trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Update WINMGARD.EXE X Added by the W32/Rbot-BI trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Update wuamgrd16.exe X Added by the W32/Rbot-BQ trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Update wuamgrb.exe X Added by the W32/Rbot-BS trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Update wssvrs.exe X Added by the W32/Rbot-BV trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Updating WAMQUARD.EXE X Added by the W32/Rbot-BX trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Updating WUAMGUARDS.EXE X Added by the W32/Rbot-BY trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
MICROSOFT UPDATE WUAGTRD.EXE X Added by the W32/Rbot-CJ trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Windows Updater WINFIX.EXE X Added by the W32/Rbot-CM trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Update winsyst.exe X Added by the W32/Rbot-DL trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Update Debugger wincfg32.exe X Added by the W32/Rbot-DT trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Update wingrd32.exe X Added by the W32/Rbot-DW trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Updates wkssvrs.exe X Added by the W32/Rbot-EB trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
A New Windows Updater w32NTupdt.exe X added by the W32/Mytob-AG WORM, which has IRC channel backdoor trojan functionality.
BossIdea winlogin.exe X Added by the Troj/Lineage-I TROJAN!
Meeting Connection wowdache.exe X Added by the Troj/PPdoor-D TROJAN!
Window_Protect winsi32.exe X Added by a variant of the Rbot worm. This worm, when started, connects to IRC servers where it sits in a desginated channel waiting for commands from a remote user.
wupdate wisvccz.exe X Added by the Troj/Orse-B TROJAN!
win update wupdate.exe X Added by the W32/Rbot-P worm. This infection connects to an IRC server where it waits for remote commands.
wlancfg wlancfg.exe U Inventel wireless router related - required in order to automatically connect to the Net at bootup.
Microsoft IT Update winsyst32.exe X Added by the W32/Rbot-FC trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection may also attempt to log keystrokes.
Microsoft Intranet WIN31.EXE X Added by the W32/Rbot-FD trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection may also attempt to log keystrokes to a file called test.crf.
[unknown] WUAPDCT32.EXE X Added by the W32/Rbot-FG trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft UpdateS Machine wgrd.exe X Added by the W32/Rbot-FI trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This application also collects the cd keys for popular games and applications.
Microsoft Update Machine WININI2.EXE X Added by the W32/Rbot-FR trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
WindowsRegKey update windowsup.EXE X Added by the W32/Rbot-FV trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Patches WUACMGRD.EXE X Added by the W32/Rbot-FX trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection also attempts to find cd keys for popular games and applications.
Patches Value WinGasys.exe X Added by the W32/Rbot-GD trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Update Emulator wuaddsff.exe X Added by the W32/Rbot-GX trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windows Guard WAUMGRD.EXE X Added by the W32/Rbot-GY trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Windows Updater WINDATES.EXE X Added by the W32/Rbot-H trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
WinXp Updater winxp32.exe X Added by the W32/Rbot-HG trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windows USB controler winusb.exe X Added by the W32/Rbot-HR trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Machine winxp43.exe X Added by the W32/Rbot-IA trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infections terminates other malware processes and attempts to find the cd keys of popular games.
MicrosoftUpdate windll.exe X Added by the W32/Rbot-IH trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infections attempts to log keys strokes and find cd keys for popular programs.
Security Patches wuamgrdr.exe X Added by the W32/Rbot-IN trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Security Patches wuamgrdk.exe X Added by the W32/Rbot-IQ trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Security Patches wuamgrdn.exe X Added by the W32/Rbot-JI trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Loader winsdnz.exe X Added by the W32/Rbot-JJ trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
mismo win32x.exe X Added by the W32/Rbot-JP trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This bot is capable of a wide array of functions including logging keystrokes and collecting cd keys.
Microsoft Update Machine winftp32.exe X Added by the W32/Rbot-JX trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
WindowsRegKey update winsys.exe X Added by the W32/Rbot-JY trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windows Update Service wuacltl.exe X Added by the W32/Rbot-KB trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection can log keystrokes and sniff traffic on your network.
MSN Service wuampskum.exe X Added by the W32/Rbot-KC trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection can log keystrokes and sniff traffic on your network.
Microsoft DirectX wupdate.exe X Added by the W32/Rbot-L trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Update wangard.exe X Added by the W32/Rbot-LH trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Windows Loader windat32.exe X Added by the W32/Rbot-LU trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
SCNDmem WINLOW.SYS X Added by the Troj/Haxdoor-CN rootkit infection. This file is installed as system driver and is used to hide processes, files, and registry keys from being seen.
secboot w32_ss.exe X Added by the HaxDoor.B rootkit/backdoor Trojan.
Starting up wvsvc.exe X Added by the W32/Rbot-NF trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infections are usually capable of logging keystrokes, retrieve cd keys, and flood other computers.
Regkey for autostart winservice.exe X Added by the W32/Rbot-NU trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infections are usually capable of logging keystrokes, retrieve cd keys, and flood other computers.
Microsoft Update Machine winortho.exe X Added by the W32/Rbot-NW trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infections are usually capable of logging keystrokes, retrieve cd keys, and flood other computers.
Winmon32 winmon32.exe X Added by the W32/Rbot-OQ trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infections are usually capable of logging keystrokes, retrieve cd keys, and flood other computers. The logged keystrokes are saved in a file called key.txt.
Sygate Personal Firewall Startup wint.exe X Added by the W32/Rbot-OV trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infections are usually capable of logging keystrokes, retrieve cd keys, and flood other computers.
.service winlgon.exe X Added by the Troj/Bdoor-BX trojan backdoor.
*wmstu wmstu.exe X Added by the W32/Rbot-TV worm. When started this infection connects to an IRC server where it waits for commands. This program starts in safe mode to make it more difficult to remove.
Windows Service Pack 2 WindowsSP2.exe X Added by the W32/Sdbot-TQ worm/backdoor.
xpstart wini.exe X Added by the W32/Rbot-ABC. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infections are usually capable of logging keystrokes, retrieve cd keys, and flood other computers.
IPC Spool Manager wnmgre.exe X Added by the W32/Sdbot-ZC. When started this infection connects to an IRC server where it waits for remote commands.
SystemKey WIN2000.EXE X Added by the Troj/QQify-A. It also copies itself as nsconfig.exe, msconfig.exe, regedita.exe and regedit.exe to %Windir%.
Windows Database wiinsvc.exe X Added by the W32/Agobot-RU. When started this infection connects to an IRC server where it waits for remote commands. It can log key strokes, list or terminate services and processes, harvest email addresses, flood a given IP address, locate product keys or execute arbitrary commands.
Services32 Startup win32dll.exe X Added by the W32/Sdbot-XO. When started this infection connects to an IRC server where it waits for remote commands, able to steal CD game keys, perform in distributed denial-of-service (DDoS) attacks, or download and run files from the internet.
Norton Service Driver wsul.exe X Added by the W32/Rbot-ABI. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infections are usually capable of logging keystrokes, retrieve cd keys, and flood other computers.
*wuauclt.exe wmsvc.exe X Added by the W32/Rbot-UG network worm. When started this infection connects to an IRC server where it waits for remote commands to execute.
System Updates Manager winserv32.exe X Added by the W32/Agobot-AGA network worm.
Reg Service WinnConfig.exe X Added by the W32/Agobot-PF network worm.
Windows System32 winsystem32.exe X Added by the W32/Rbot-UO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
wscntfys wsscntfy.exe X Added by the W32/Sdbot-TN. When started this infections connects to a remote IRC server where it waits for commands to execute.
Microsoft System winamp1.exe X Added by the W32/Sdbot-UF worm. When started, this infection connects to an IRC server where it waits for remote commands.
Windows Update winupupdate1.exe X Added by the W32/Rbot-UV worm. When started, this infection connects to an IRC server where it waits for remote commands.
mIRC Exchanger wavasdw.exe X Added by the W32/Sdbot-UO worm. When connected this infections connects to an IRC server where it waits for remote commands to execute.
update winis.exe X Added by the Rbot-VD worm. This infections connects to an IRC server where it waits for remote commands.
Messenger WINAMPA.EXE X Added by the Troj/Ranck-CG trojan.
Compaq Jes Drivers winjes.exe X Added by the W32/Sdbot-XR worm. When started this infection connects to a remote IRC server where it waits for commands to execute.
Windows NetStart Service2 winsN2S.exe X Added by the W32/Rbot-ABN trojan. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infections are usually capable of logging keystrokes, retrieve cd keys, and flood other computers.
IE Runtime wini.exe X Added by the W32/Rbot-ABK worm. When started this infection connects to a remote IRC server where it waits for commands to execute.
Windows DNS windns.exe X Added by the W32/Sdbot-XU worm. When started this infection connects to a remote IRC server where it waits for commands to execute.
WindowsRegKey update XP windexv1.exe X Added by the W32/Rbot-ABM worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infections are usually capable of logging keystrokes, they can retrieve cd keys, and flood other computers.
Windows Media Player 3.6b WMPA36B.EXE X Added by the W32/Rbot-VV worm. When started this infection connects to a remote IRC server where it waits for commands to execute. These infections also log keystrokes, so if you are infected you should change all your passwords.
Microsofts MediaScope winmep.exe X Added by the W32/Rbot-WB worm. When started this infection connects to a remote IRC server where it waits for commands to execute. These infections also log keystrokes, so if you are infected you should change all your passwords.
xp winis.exe X Added by the W32/Rbot-WO worm. When started this infection connects to a remote IRC server where it waits for commands to execute.
WMPVer WMPVer.EXE ? Dritek System Inc. 3D Mouse related - is it required?
w98Eject w98Eject.exe ? Related to USB support for Sigmatel MP3 audio decoder -what does it do, and is it required?
USB Fixes wuafix.exe X An SDBot variant. These infections connect to IRC servers and wait for remote commands to execute.
Windows 32 Rescue win32resc.exe X Added by the W32/Forbot-EU worm. When started this infection connects to an IRC server where it waits for remote commands to executed.
Windows 32 Rescue win32resc.exe X Added by the W32/Forbot-EU worm. When started this infection connects to an IRC server where it waits for remote commands to executed. This startup entry refers to the NT service that it creates.
wupdate wi32.exe X Added by a new variant of Trojan.Abwiz.
Windows Executable winmys.exe X Added by the W32/Rbot-ABO worm. When started, this infection connects to an IRC server where it waits for commands to execute.
winhost.exe winhost.exe X Added by the roj/Lohav-R proxy server and downloader trojan. Machines that are infected with this can be used by the remote user to send Internet traffic through.
RegRun WinBait winbait.exe U Part of RegRun - used to detect unknown viruses. RegRun compares winbait.exe with the original copy called winbait.org and warns if the files are different.
Dynamic Dns Binary winxp34.exe X Added by a variant of the WIN32.RBOT WORM!
Windoxs Update Center W32RfSA.exe X Added by a variant of the W32/SDBOT WORM!
winsy32.exe winsy32.exe X Trojan related to the CoolWebSearch group of malware.
winipsec winipsec.exe X Unidentified malware
1wincfg32 WebMailSpy.exe X Added by WebMailSpy SPYWARE!
acecad.wtxpload Wtxpload.exe Acecad Y driver for an AceCad USB Graphics Tablet
calc microsoft windows wincalc.exe X Added by an unidentied WORM or TROJAN!
BootsCfg wscript.exe C:\\WINDOWS\\Update\\Date.POP.vbs % X Added by the VBS.KUULLIO WORM!
logservice wincalc.exe X Added by the BACKDOOR.PAPROXY TROJAN!
microsoft update process wmipcvse.exe X Added by the TROJ/AGOBOT-JF TROJAN!
microsoft updater resources WinFixd32.exe X Added by the SPYBOT.CA WORM!
microsoft updating client websvc.exe X Added by the RBOT.AQ WORM!
microsoft windows services controller wservices.exe X Added by the WIN32.RBOT.FD WORM!
microsoft xp systems loader winsystem32xp.exe X Added by the W32.KELVIR.W WORM!
microsoft xp systems loaders win32xpsys.exe X Added by the W32.SPYBOT.NYT WORM!
microsofts media wingtp.exe X Added by the W32/RBOT-VO WORM!
regrun winfix22490.exe X Added by a variant of the WIN32.RBOT WORM!
sndpnpmix wauctlxp4.exe X Added by the WIN32.MUDROP.N TROJAN!
start upping windupdts.exe X Added by a variant of the WIN32.RBOT WORM!
system update wauluclt.exe X Added by the SDBOT.EF WORM!
uninstall_wintools WTuninst.exe U WinTools adware uninstaller. Should only need to run once in order to complete uninstall; when done, disable.
usb fix 1.1 wuservices.exe X Added by a variant of the W32/SDBOT WORM!
wast wast2.exe X Grokster ads updater
wifeman wifeman.exe X Unidentified malware
win microsoft config wnmsconfig.exe X Added by a variant of the WIN32.RBOT WORM!
win32 debug manager Win32Debug.exe X Added by a variant of the W32/WOOTBOT WORM!
win32 usb3 driver win32tool.exe X Added by a variant of the WIN32.RBOT WORM!
win98 dns wingrd.exe X Added by a variant of the WIN32.RBOT WORM!
windows network controller Win9x.exe X Added by the WOOTBOT.I WORM!
windows update services wservices.exe X Added by a variant of the WIN32.RBOT WORM!
windows32 serivces winser32.exe X Added by the SPYBOT.AAF WORM!
windvrctrl WDVRCtrl.exe Y Driver task installed by the drivers for some TV capture cards; no further information available, so best left alone.
winprocer32 update winprocer32.exe X Added by the RBOT.GW WORM!
winprocessor update winprocessor.exe X Added by the RBOT.IO WORM!
winprot Winprot.exeserver.exe X Added as a result of the CHUPACABRA VIRUS!
winscheduler WINSCH~1.EXE U InterVideo WinDVR scheduler
winupdsv winupdsv.exe X Added by the X97M.DROPO Macro VIRUS!
wise-ftp scheduler WF_Scheduler.exe U WISE-FTP file transfer software scheduler
wnsck2 driver wlogf.exe X Added by the W32/SPYBOT-AF WORM!
wordq carat flag WordQcrs.exe Y Related to WordQ Writing Aid Software
wuosdial wuosdial.exe X Added by a variant of the WIN32.RBOT WORM!
Win32 Bios Winbios.exe X Added by the W32/Semapi-A. This mass-mailing worm may display a message: "Unable to locate 'semapi.dll' reinstalling this application may fix this problem."
Windows Services winsvc32.exe X Added by the W32/Mytob-CB. This infection connects to an IRC server on startup where it waits for remote commands to execute.
windhost.exe winos.exe X Added by the Troj/PWSAgent-A trojan.
*windows update wuacrlt.exe X Added by the W32/Rbot-QI worm. This infection connects to an IRC server where it waits for remote commands.
*windows update wruaclt.exe X Added by the W32/Rbot-QP worm. This infection connects to an IRC server where it waits for remote commands.
Microsoft Service Pack WindowsSP.exe X Added by the W32/Rbot-RF worm. This infection connects to an IRC server where it waits for remote commands.
*windows update wruauclt.exe X Added by the W32/Rbot-SF worm. This infection connects to an IRC server where it waits for remote commands.
Windows Video wvidsvc.exe X Added by the W32/Rbot-SJ worm. This infection connects to an IRC server where it waits for remote commands.
WlN32 winsys.cer X Added by the Troj/Zikdow-B Trojan. This infections redirects your browser to use www.3241.com as it's start page.
win32client win32client.exe X Added by the Troj/Restarter trojan.
Whistler whismng.exe X Added by the Troj/Whistler-F. It also creates a file at C:WXP to copy over other files and deletes files.
Windows drivers update windowsupdate.exe X Added by the W32/Rbot-ACE worm. This infection connects to an IRC server where it waits for remote commands.
Microsoft Update Machine winnie.exe X Added by the W32/Rbot-ACD worm. This infection connects to an IRC server where it waits for remote commands.
windowsbackup WINDOWSBACKUP.EXE X Added by the W32.Stang WORM!
BootsCfg wscript.exe C:\WINDOWS\User\All Users.vbs % X Added by the VBS.Spiltron@mm mass-mailing worm.
wm24pan Wm24Pan.Exe Y ESI external sound card driver
intel system tool winnook.exe X Added by the Troj/Spyre-C trojan. This infection will display on your desktop a false message in the attempts to goad you into buying their software.
windowsregkeys update windup.exe X Added by a variant of the WIN32.RBOT WORM!
windows update services wins32svcs.exe X Added by a variant of the WIN32.RBOT WORM!
windows sp2 firewall wfirewall7.exe X Added by a variant of the WIN32.RBOT WORM!
windows 32 update Windows-Update.exe X Added by a variant of the WIN32.RBOT WORM!
win update wapdate.exe X Added by a variant of the WIN32.RBOT WORM!
logitech desktop controller wrcam.exe X Added by a variant of the WIN32.RBOT WORM!
System Servers windows.exe X Added by the Troj/GrayBrd-L Trojan.
Microsoft Synchronization Manager WIN932.EXE X Added by the W32/Sdbot-IL worm. When started this infection connects to an IRC server where it waits for remote commands.
microsoft update machine wins32.exe X Added by the RBOT.EZ WORM!
winlog windowxs.exe X Added by the W32/Sdbot-KT worm. When started this infection connects to an IRC server where it waits for remote commands.
Windows FAT 32 WINFAT32B.exe X Added by the W32/Spybot-AGT worm. When started this infection connects to an IRC server where it waits for remote commands.
*windows update waurclt.exe X Added by a variant of the WIN32.RBOT WORM!
MS PLUS INC wpad.exe X Added by the W32/Mytob-AN mass-mailing worm.
win32 system server winserver.exe X Added by an unidentified WORM or TROJAN!
windows services ink platform tablet input subsystem wsiptis.exe X Added by the RBOT.APC WORM!
windows sz host winshvc.exe X Added by a variant of the W32/SDBOT WORM!
wwks wsass.exe X Added by the W32/SDBOT-BT WORM!
XTN Service Drivers winxtn.exe X Added by the W32/Sdbot-YK worm. When started this infection connects to a remote IRC server where it waits for commands to execute.
winirxhelper WinIRXHelper.exe U MSI™ Media Center Deluxe software - see here
wmplayer.exe wmplayer.exe X Added by the Troj/Bancban-CT password-stealing trojan. If you were infected with this trojan you should immediately change all your passwords for your online banking programs.
sygate personal firewall winxpstat.exe X Added by a variant of the WIN32.RBOT WORM!
microsoft system checkup wnetmgr.exe X Added by the W32.DONK.Q WORM!
microsoft update machine wins32.exe X Added by the RBOT.EZ WORM!
microsoft winupdate Winamp61.exe X Added by a variant of the WIN32.RBOT WORM!
security patches WinLab32.exe X Added by the W32/SDBOT-KB WORM!
client update wup.exe X Added by a variant of the W32/OPANKI-A WORM!
tsk mng hlp wins32.exe X Added by the W32/AGOBOT-JB WORM!
wait4ip wait4IP.exe U Packard Bell net2Plug allows you to network PCs anywhere in your house
win server updt winserver.exe X Added by a variant of the WIN32.IMISERV TROJAN!
GenericHostXP WinLoaderXP.exe X Added by the Troj/Bdoor-ACX Trojan.
win32 usb2 wins32.exe X Added by a variant of the WIN32.RBOT WORM!
windows imessenger messenger winimsg.exe X Added by the W32.ALLIM.A WORM!
windows media player 3.6 wmpa36.exe X Added by a variant of the WIN32.RBOT WORM!
windows media player 3.9 wmpa36.exe X Added by a variant of the WIN32.RBOT WORM!
windows messenger messenger winmsg.exe X Added by W32.Velkbot.A WORM!
windows secure connection winsc.exe X Added by a variant of the WIN32.RBOT WORM!
windows security manager winsecurity.exe X Added by the W32/AGOBOT-KI WORM!
windows sp2 version load wuauclt32.exe X Added by the GAOBOT.CX WORM!
windows user starter winuser32.exe X Added by the RBOT.SN WORM!
windowsregkey update winupdatexx.exe X Added by a variant of the WIN32.RBOT WORM!
winnt updatc wupgrd.exe X Added by a variant of the WIN32.RBOT WORM!
winrun z W1NT45K.exe X Added by W32.Mytob.BL WORM!
winusr WinUsr.exe K1S2 X Added by the W32.CLUNK.A WORM!
winvxd32 winvxd32.exe X Added by the W32.Gabloliz.A WORM!
WinCfg32 WinCfg32.exe X Added by the W32/Ronoper-A worm/backdoor trojan.
win32napp win32napp.exe X Added by the W32/Smelles-A virus.
Win32reg.dll Wind32reg.dll.exe X Added by the W32/Rackum-A worm/keylogger. This infection attempts to delete the regedit.exe file and logs keystrokes in the Winsck32.sys.Txt file.
Windows Lord Anti-Virus winlord32.EXE X Added by the Troj/SdBot-GW worm. When started, this infection connects to an IRC server where it waits for remote commands to execute.
Microsoft Windows Runtime DLL Services WINDEV.EXE X Added by the W32/Randex-M worm. When started, this infection connects to an IRC server where it waits for remote commands to execute.
Work world.exe X Added by the W32/Randon-AE worm. This infection, when started, connects to an IRC server using a provided MIRC client to receive commands.
WinVM32 WINVM32.EXE X Added by the Troj/RasAsper-A dialer. This infection divers all numbers dialed via modem to a phone number preceded with 0190.
Plug and Play wininet32.exe X Added by the Troj/Raznew-B trojan proxy server. This infection allows remote computers to use the Internet through your computer to hide their tracks.
Thsys winrun.sys.pif X Added by the W32/Sachiel-D worm.
Microsoft Update wkfix.exe X Added by the W32/Rbot-ABZ. This worm connects to an IRC server on startup where it waits for remote commands.
Reg Service winslogon.exe X Added by the W32/Agobot-SC WORM!
Win32 Services Config winwkys.exe X Added by a new Rbot worm variant.
WTF Test wtftest.exe X Added by the W32/Rbot-ACM worm. When started this infection connects to an IRC server where it waits for remote commands to execute.
SysUpd WindowsUpd1.exe X VirtuMonde adware
erghgjhgdr windlhhl.exe X Added by the W32.Beagle.BG or W32.Beagle.BH or W32.Beagle.BI or W32.Beagle.BJ WORM!
bootscfg wscript.exe[path] Install.log.vbs X Added by the VBS.YPSAN.E WORM!
microsoft wind0ws updater winsupdater.exe X Added by a variant of the WIN32.RBOT WORM!
popmark WinTask.exe X "Pop Marketing" adware
syntax windows32.exe X Added by the SDBOT.CQ WORM!
win updater WINUPDATER.EXE X Added by the RBOT.IP WORM!
windows 128 module win128.exe X Added by the W32/FORBOT-ES WORM!
windows host winhost.exe X Added by the BACKDOOR.PRYSAT TROJAN!
windows security updater WINFRW.exe X Added by the Solufina TROJAN!
windowsupd1.exe WindowsUpd1.exe X VirtuMonde adware
windowsupd2.exe WindowsUpd2.exe X VirtuMonde adware
winis winis.exe X Added by the W32/RBOT-WI WORM!
winpup32 Winpup32.exe X Added as a result of the ADCLICKER VIRUS!
winsvc32.exe winsvc32.exe X Added by the GREPAGE TROJAN!
MS Unix Binary WinGuard.exe X Added by the W32/Rbot-ACL worm. When started, this infection connects to an IRC where it waits for remote commands to execute.
Windows Updates winupd32.exe X Added by the W32/Mytob-AY worm. When started, this infection connects to an IRC where it waits for remote commands to execute.
notn wtta.exe X PurityScan/Clickspring adware
real spy monitor Winrsm.exe U Realspy keystroke logger/monitoring program - remove unless you installed it yourself!
winacsr Winacsr.exe U AceScreenSpy keystroke logger/monitoring program - remove unless you installed it yourself!
wsg32 wsg32.exe U GoldenKeylog keystroke logger/monitoring program - remove unless you installed it yourself!
internet2 optimizer wkfix.exe X Added by a variant of the WIN32.RBOT WORM!
winscmngr winsmc.exe X Added by a variant of the W32/SDBOT WORM!
Windows Services winspsv.exe X Added by the Troj/Sdbot-BA backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
Module WinMeter wimmtre.exe X Added by the W32/Sdbot-BE backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute. This infection also steals cd keys from popular games and applications.
Security Patch WinUpdate32.exe X Added by the W32/SdBot-BM backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute. This infection also steals cd keys from popular games and applications.
WinReg win32cfg.exe X Added by the Troj/Sdbot-CR backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
Update WinUpdate.exe X Added by the W32/Sdbot-CV backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
Windows Clock Configuration windowstm.exe X Added by the W32/Sdbot-DB backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
Windows Manager windows31.exe X Added by the W32/Sdbot-DY backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
winlog wintask.exe X Added by the W32/Sdbot-GR worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
ipc spool manager winspec.exe X Added by the W32/SDBOT-BLU WORM!
startup WinlogonStartup X Unidentified malware
d2 winloadhh.dll X Added by the Troj/Labrap-A downloader trojan.
wintective wintective.exe U Added by the Spyware.Wintective keylogger and screen capture program. If you did not install this program, then you should uninstall it.
Windows Application Layer Gateway walg32.exe X Added by the W32/Agobot-AAZ worm. When started this infection connects to an IRC server where it waits for remote commands.
ICQNet winlogon.exe X Added by the W32/Netsky-C mass-mailing worm.
winsockdriver winsock3.exe X Added by the W32/Spybot-DO worm. When started this infection connects to an IRC server where it waits for remote commands.
MBsync WUAPDC.EXE X Added by the W32/Sdbot-IS worm. When started this infection connects to an IRC server where it waits for remote commands.
REMOVE ME windos.exe X Added by the Troj/Sdbot-JC worm. When started this infection connects to an IRC server where it waits for remote commands.
[unknown name] WINBASICS32.EXE X Added by the Troj/Sdbot-JH worm. When started this infection connects to an IRC server where it waits for remote commands.
InternetGetConnectedState winupdate.exe X Added by the W32/SdBot-JN worm. When started this infection connects to an IRC server where it waits for remote commands.
Win FTP wintftp.exe X Added by the W32/Sdbot-KA worm. When started this infection connects to an IRC server where it waits for remote commands.
winsys32mon winsysmon32.exe X Added by the SecurityRisk.SexxPass security risk. This infection adds certain sites to your IE trusted zone allowing software to install on your computer from these domains without your permission.
IE Runtimes winis.exe X Added by the W32/Rbot-ADZ worm. When started this infection connects to a remote IRC server where it waits for commands to execute.
Windows Registry Name winses.exe X Added by the W32/Rbot-ADB worm. When started this infection connects to a remote IRC server where it waits for commands to execute.
ms builders Wupated.exe X Added by the W32/AGOBOT-SS WORM!
updatecheck winstall.exe X Added by the W32/SPYBOT-CY WORM!
windows media utility wmediautil.exe X Added by a variant of the W32.SPYBOT WORM!
windows sq drivers winmsn32.exe X Added by the W32/Rbot-ADI
windows_protect wincontrol32.exe X Added by the W32/Rbot-ADK
winierun winierun.exe X Added by the Troj/RNWatch-A
winword winword.exe X Added by the Troj/Torpid-C
autoupdate WINUP2DATE.DLL,SHStart X Unidentified adware - detected by Panda antivirus as Trj/Clicker.CY
microsoft security winService.exe X Added by a variant of the WIN32.RBOT WORM!
microsoft windows service winsys.exe X Added by the W32/Rbot-ADP
random 10-character filename Winupdates.exe X Added as result of a W32/Rbot-MM worm infection
windowregkey update wins.exe X Added by the SPYBOT.I WORM!
windows firewall log winlog.exe X Added by an unidentified WORM or TROJAN!
windows msconfig startup logger winlog.exe X Added by the RBOT.BCU WORM!
winimage wvsvc.exe X Added by the RBOT.TX WORM!
winservice winmain.exe X porn related malware
IE Runtime wini.exe X Added by the W32/Rbot-ADM worm. When started this infection connects to an IRC server where it waits for remote commands.
Win Tmp Service wstmp.exe X Added by the W32/SdBot-YS. When started this infection connects to an IRC server where it waits for remote commands.
wupd win32.exe X Added by the Troj/Orse-C trojan.
Windows Web Services websvc.exe X Added by the Troj/Dloader-NY trojan.
Microsoft Update USB2 wuammgrd32.exe X Added by the W32/Rbot-ADT worm. When started this infection connects to an IRC server where it waits for remote commands.
USBConfigration2 wmmndir.exe X Added by the W32/Agobot-SV worm. When started this infection connects to an IRC server where it waits for remote commands.
Windows Management Instrumentation wmimgr.exe X Added by the W32.Qdens.A QQ messenger worm.
wineula wineula.dll X Added by the Trojan.Vundo.B adware/redirector.
Windows Workstation Service (32-bits) wkssvc32.exe X Identified as a SDBot variant.
Windows PDG winpdg.exe X Added by the W32/Rbot-ADW worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft WinRaR winrar.exe X Added by the W32/Rbot-AEC worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windows System WINSYS.exe X Added by the W32/Rbot-AEF worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windows Micro Drivers wupdates32.exe X Added by the W32/Rbot-AEH worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
WINLOGON wscript.exe %System%\WINLOGON.vbs % X Added by the VBS.Ypsan.F@mm mass-mailing worm. When cleaning this infection you only want to delete the %System%Winlogon.vbs file.
Lien Van de Kelder www.lienvandekelder.be.exe X Added by the W32.Mytob.DB@mm mass-mailing worm with backdoor capabilities.
Windows Updtee Mgnr W1NT45K.exe X Added by the W32.Mytob.DC@mm worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
http://www.lienvandekelder.be We Love Lien Van de Kelder.exe X Added by the W32/Mytob-CV email worm and backdoor IRC trojan.
win32beta win32sys4.exe X Added by the Troj/Banker-DA password-stealing trojan for Brazilian banks.
Nero Updater.6.12 wmp9.exe X Added by the W32/Agobot-AAG worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Configuration Loader win32exec.exe X Added by the W32/Sdbot-LA worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Winsock2 Loader WICONF.EXE X Added by the W32/Sdbot-LC worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Configuration Loader winfix.exe X Added by the W32/Sdbot-MA worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
winlog winsx.exe X Added by the W32/Sdbot-MH worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft video capture controls winshosts.exe X Added by the W32/Sdbot-MP worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
System Information Manager win.exe X Added by the W32/Sdbot-MU worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windows Updates w32dns.exe X Added by the W32/Sdbot-BFW worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
WinStabilizer WinStabilizer.exe X Added by the W32/Agobot-SW worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windows Update winlogin.exe X Added by the Troj/Banker-DV password-stealing trojan.
WINTASKS winxpro.exe X Added by the W32/Mytob-T worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Win32 Services wuamngr.exe X Added by the W32/Sdbot-N worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
SysInit wininit32.exe X Added by the W32/Sdbot-NA worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection may have the command of wininit32.exe -services or wininit32.exe -drivers.
System Information Manager windowsNt.com X Added by the W32/Sdbot-ND worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Security Fixers WINCAT32.EXE X Added by the W32/Sdbot-NR worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
RNBz Test wf32vbc.exe X Added by the W32/Rbot-AEY worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
wsys.exe wsys.exe U Added by the Spyware.SpyloPCMonitor surveillance software. If you did not install this software you should remove it immediately.
\Generic Host Process for Win32 Services winsvc32.exe X Added by the W32/Sdbot-Pworm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
win-update wiupdat.exe X Added by the W32/Sdbot-QPworm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windows XP Automatic Update wXPupdate.exe X Added by the W32/Rbot-AFC worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Update win-mang.exe X Added by the W32/Rbot-AFK worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Update wuamkop.exe X Added by the W32/Rbot-AFI worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windows Configuration wincfg32.exe X Added by the W32.Mytob.ED@mm mass-mailing worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
ctfmon WinConst.exe X Added by the Troj/Assasin-G backdoor trojan and keylogger.
WINDOWS SYSTEM winsys33.exe X Added by the W32/Mytob-BI worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windows Login Service winlog.exe X Added by the W32/Rbot-AFN worm. This infection when started, connects to a remote IRC server where it waits for commands to execute.
Microsoft Update Machine wftestb.exe X Added by the W32//Rbot-AFZ worm. When started, this infection connects to an IRC server where it waits for remote commands to execute.
ssgrate.exe wintems.exe X Added by the Trojan.Mitglieder.Q trojan backdoor/proxy.
Microsoft Windows DLL Services Configuration winDSL.exe X Added by the W32/Sdbot-ZG worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Windows Security winmon.exe X Added by the W32/Sdbot-SR worm. When started, this infection will connect to a remote IRC server and wait for commands to execute.
WINDOWS SYSTEM winligon.exe X Added by the W32/Mytob-FD worm. When started, this infection connects to a remote IRC server and waits for commands to execute.
LoadPFW wmimgr.exe X Added by the W32/Qeds-B virus.
WINDOWS SYSTEM win.exe.exe X Added by the W32.Mytob.FA@mm worm. When started, this infection connects to a remote IRC server and waits for commands to execute.
WINDOWS SYSTEM Dns windsns.exe X Added by the W32.Mytob.EY@mm worm. When started, this infection connects to a remote IRC server and waits for commands to execute.
WINDOWS SYSTEM winvnc.exe X Added by the W32.Mytob.EU@mm worm. When started, this infection connects to a remote IRC server and waits for commands to execute.
Windows User Mode Driver Manager wdfmrg.exe X Added by the W32/Sdbot-ZN worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
wintnask32.exe wintnask32.exe X Added by the W32/Rbot-AFP worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
SYSTEM MESSAGER wmisg.exe X Added by the W32.Mytob.ES@mm worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Windows32 Windows32.exe X Added by the Troj/Resod-C trojan.
WINDOWS SYSTEM winxpserv.exe X Added by the W32/Mytob-BQ worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
WinRep winrep.exe X Added by the W32/Rbot-AFW worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
Winsock2 driver WUAUMQR.EXE X Added by the W32/Spybot-DP worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
Microsoft Update Services wsnfty.exe X Added by the W32/Rbot-AFU worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
wallchgr.exe wstart Wallchgr.exe U Blue Tree Software
windows system 32-bat service win32bat.exe X Added by the W32.Mytob.FI(AT)mm
wssys wssys.exe U Added by the Spyware.WebPI surveillance software. If you did not install this software, you should immediately remove it.
Windows Update Service wupdated.exe X Added by the W32/Sdbot-TB worm. When started, this infection connects to a remote IRC server and waits for commands to execute.
[unknown] WIN32OP.EXE X Added by the W32/SdBot-U worm. When started, this infection connects to a remote IRC server and waits for commands to execute.
Winzip Compression Utility Winzip32.exe X Added by the Troj/Sdbot-UI worm. When started, this infection connects to a remote IRC server and waits for commands to execute.
Windows installer winstall.exe X Related to the SpySheriff infection.
Configuration32 Loader32 winamp32.exe X Added by the W32/Sdbot-BIC worm. When started, this infection connects to a remote IRC server and waits for commands to execute.
NAV Agent wmilib32.exe X Added by the Troj/VB-XU trojan.
windows16 windows16.exe X Added by the Troj/VB-XU trojan.
Microsoft Sound Technology winsound.exe X Added by the W32/Rbot-AGG worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
wlogon wlogon.dll X Added by the W32/Wenper-B worm.
WinLoad Winload.exe U Added by the Spyware.PCTattletale surveillance software. If you did not install this software, then uninstall it immediately.

NOTE TO VISTA USERS: If you use Windows Vista, do not remove this file. A legitimate file with the same name and location is used by Windows Vista during bootup. Removing this file can cause problems with your operating system.
winupdates winupdates.exe X Added by the W32/Alcra-B worm.
Microsoft Update Services wcsnfty.exe X Added by the W32/Rbot-AGK worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
WinAwk WinAwk.exe X Added by the W32/Sdbot-AYF worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
OSA winword.exe X Added by the Trojan.Kangenie trojan.
Windows Update wininfo.exe X Added by the W32.Mytob.GA@mm worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
WINDOWS SYSTEM winmon.exe X Added by the W32.Mytob.GB@mm worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
WINDOWS SYSTEM WinSys4.exe X Added by the W32.Mytob.GG@mm worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Prog winsys.exe X Added by the Siteno.Trojan trojan.
[not used] Winn.exe X Added by the Snob.IRCworm IRC worm.
SysWsa32 WSA32.EXE U Added by the Spyware.BEverywhere.B surveillance software. This program should be uninstalled if it was not installed by yourself.
WinSystem WinSystems.exe U Added by the Spyware.CMKeyLogger surveillance software. This should be removed if it was not installed by yourself.
WINDOWS SYSTEM wdns33.exe X Added by the W32/Mytob-BY worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
WDNS SYSTEM wdns33.exe X Added by the W32/Mytob-BY worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Win32Host Process webemir.exe X Added by the Troj/Turgen-A password-stealing trojan.
winchost winchost.exe X Added by the Troj/Dloader-PO downloader trojan.
RNBc Test wf32vbs.exe X Added by the W32/Rbot-AGR worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
System WINL0G0N.EXE X Added by the Troj/Bancos-DB trojan.
KAVFOX win1ogoin.exe X Added by the Troj/GWGhost-M key logging Trojan.
WMI Application Interface wmiapi.exe X Added by the W32.Spybot.RBY worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
wow wwf.exe X Added by the Troj/Lineage-Y password stealing trojan for the online game Lineage.
WindowsRegKey update winupdat32.exe X Added by the W32/Rbot-AGW worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
dynamic dns binary WinHelpcfn.exe X Added by a variant of the WIN32.RBOT WORM!
microsoft update wuamkop32.exe X Added by the RBOT.BGU WORM!
microsoft updates 2 usb wgafixer.exe X Added by a variant of the WIN32.RBOT WORM!
microsoft windows dll services configuration windir32a.exe X Added by a variant of the SDBOT.BHF WORM!
microsoft windows update logon win-logon.exe X Added by a variant of the WIN32.RBOT WORM!
microsoftf ddes control wees.exe X Added by a variant of the the RBOT.BOF WORM!
rndc test wf32b.exe X Added by a variant of the W32/SDBOT WORM!
service wN2S.exe X Added by a variant of the WIN32.RBOT WORM!
srv32win win16dll.exe U Screenspy captures screenshots silently. If you didn't install this yourself, remove it.
system updates winsci.exe X Added by a variant of the WIN32.RBOT WORM!
weirdontheweb WeirdOnTheWeb.exe X Added by the Adware.WeirdOnTheWeb
win16.dll win16dll.exe U Screenspy captures screenshots silently. If you didn't install this yourself, remove it.
windows command wincmd.exe X Added by the RBOT.ANV WORM!
windows nt login session manager WNSM.EXE X Added by the RBOT.BIV WORM!
windows tm WinxSys.exe X Added by a variant of the WIN32.RBOT WORM!
winnt dns ident wuamgrd33.exe X Added by a variant of the WIN32.RBOT WORM!
winsos verify WINSOS.EXE U WinSOS - "deletes spyware, optimizes your computer - backs up selected data"
Compaq Service Drivers winmsn.exe X Added by a variant of the W32/Sdbot WORM/IRC backdoor Trojan, it also drops a file named msdirectx.sys in your %UserProfile% which acts as a rootkit.
Microsoft U wuamkopxp.exe X Added by the W32/Rbot-AHC worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
Jufualt winxp2.exe X Added by the W32/Sdbot-AAB worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
Microsoft Update wuamk032.exe X Added by the W32/Rbot-AHD worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
Microsoft Update 64 BIT wininit32.exe X Added by the W32/Rbot-AHE worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
Microsoft Updates wtemp32.exe X Added by the W32/Rbot-AHQ worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
winudll.exe winudll.exe X Added by the Troj/Mitglie-CE backdoor trojan.
wpwmgrs wpwmgrs.exe X Added by the W32/Mytob-DH worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
winstart winstart.exe X Added by the Troj/SCKeyLo-AB trojan.
winstart winstart.dll X Added by the Troj/SCKeyLo-AB trojan.
winlog manager winlog.exe X Added by the Trojan.Spexta trojan. When infected your computer will become an open mail relay which will allow your computer to be used to send out spam.
loadwin winset.exe X Added by the Troj/QQPass-I password-stealing trojan.
WINDOWS SYSTEM winsvc32.exe X Added by the W32/Mytob-DJ worm. When infected your computer will become an open mail relay which will allow your computer to be used to send out spam.
Micsorosft Security Center wcnsfty.exe X Added by the W32/Rbot-AHU worm. When infected your computer will become an open mail relay which will allow your computer to be used to send out spam.
CPU Temp Control wuitgurd.exe X Added by the W32/Rbot-AHV worm. When infected your computer will become an open mail relay which will allow your computer to be used to send out spam.
loadwin winsys.exe X Added by the Troj/QQPass-J password-stealing trojan.
WINDOWS SYSTEM winNTsys32.exe X Added by the W32/Mytob-DM worm. When infected your computer will become an open mail relay which will allow your computer to be used to send out spam.
Windowsfw windowsfw.exe X Added by the W32/Agobot-TA backdoor worm.
wskrnl wskrnl.exe U Added by the Spyware.ActMon surveillance software. Uninstall this software if it was not installed by yourself.
Winsock driver winnt64.exe X Added by the W32/Spybot-DR worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
WINDOWS SYSTEM winaup.exe X Added by the W32/Mytob-DN worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
Windows Sql Service For Windows 32 Bit winsql32.exe X Added by the W32/Forbot-FC worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
MS_Update Check wdfmgr.exe X Added by the W32/Agobot-TB worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
Windows Servic2 winsy.exe X Added by the W32/Rbot-AIA worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
aniwzcs2service WZCSLDR2.exe Y ALPHA_Networks wireless driver
microsoft unpack system winrarx.exe X Added by a variant of the WIN32.RBOT WORM!
hostserv wiz98.exe X Added by a variant of the W32/SDBOT WORM!
ie6 wkstmg.exe X Added by a variant of the W32/SDBOT WORM!
lsass woekd.exe X Added by an unidentified WORM or TROJAN!
microsoft crs fix serv wincrs.exe X Added by the SDBOT.BWF WORM!
microsoft dde control wupades.exe X Added by a variant of the W32/SDBOT WORM!
microsoft web device wdevice.exe X Added by a variant of the W32/SDBOT WORM!
mircosoft update wuampkd.exe X Added by a variant of the W32/SDBOT WORM!
network access winssh.exe X Added by a variant of the W32/SDBOT WORM!
windows system init winit32.exe X Added by a variant of the WIN32.RBOT WORM!
windows system notepad wnpsm.exe X Added by an unidentified WORM or TROJAN!
spool wys.exe X WhileUSurf adware component
system checking wasul.exe X Added by the RBOT.BHM WORM!
usb updates 2 wugfixx.exe X Added by a variant of the WIN32.RBOT WORM!
windows 32 editor Win32edit.exe X Added by the WOOTBOT.GQ WORM!
windows cpu host winbog32.exe X Added by a variant of the WIN32.RBOT WORM!
windows desktop daemon winpadg.exe X Added by a variant of the W32.SPYBOT WORM!
windows dll loader wdevice.exe X Added by a variant of the W32/SDBOT WORM!
winlogon wpwlogon.exe X Added by an unidentified WORM or TROJAN!
winmovieplugin WinMoviePlugIn.exe X Sfonditalia adult content premium rate dialer
winspd32dll winspd32.exe X Added by a variant of the AGOBOT/GAOBOT WORM!
wntlgns wntlgns.exe X Added by a CoolWebSearch parasite related TROJAN!
microsoft windows system service manager winsvc.exe X Added by the SPYBOT.LR WORM!
msn messeng windns.exe X Added by a variant of the WIN32.RBOT WORM!
registry oidet win32.exe X Added by the RBOT.BMT WORM!
scheduler service wsass.exe X Added by the WIN32.LIOTEN.KX WORM!
system manager updates winsvc.exe X Added by the AGOBOT.AEM WORM!
win winamp winamp.exe X Added by the RBOT.AGF WORM! NOTE - this is NOT the Winamp Media Player executable (WinAmpa.exe)
windows application layer walg32.exe X Added by the AGOBOT.ATN WORM!
windows dynamic loading header winDLL32.exe X Added by a variant of the W32/SDBOT WORM!
winows system winnt.exe X Added by the MYTOB.ID WORM!
services windows32.exe X Added by the W32/FlyVB-C worm.
WIN windows.exe X Added by the W32/Lebreat-B worm.
Windows Icons Manager wicomgr.exe X Added by the W32/Rbot-AIF worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
winlgz2 winlgz2.exe X Added by the Troj/KillFil-Q trojan.
SysMon wowexece.exe X Added by the Troj/Mulan-A trojan.
Winbot winbot.exe X Added by the Troj/Midrug-A backdoor trojan.
Microsoft Update Loaders 2005 winusers.exe X Added by the W32/Rbot-AIQ worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windows Config Manager winconf.exe X Added by the W32/Rbot-AIT worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
KV2005 word.EXE X Added by the Troj/VB-IW backdoor Trojan.
winfws winfws.exe X Added by the W32/Sdbot-ABA worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
252 winmgr.exe X Added by the Troj/Mugger-A Trojan.
Win_Pigeon_Server Win_Server.dll X Added by the Troj/Feutel-N backdoor Trojan.
Microsoft Windows Security wscndrives.exe X Added by the W32/Rbot-AJK worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
WinExec WinExec.exe X Added by the W32/Falus-A worm.
Microsoft Locator Service wkssvc.exe X Added by the W32/Sdbot-ABE worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Update Win32x winupdate32x.exe X Added by the W32/Rbot-AJN worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windows NetDDe wrmana32.exe X Added by the W32.Mytob.IM@mm worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Win32 Drivers winlogons.exe X Added by the W32/Forbot-FG worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
wesumu wiustv.exe X Added by the Troj/QQPass- Trojan.
icqbeta webcamupdate.exe X Added by an unidentified TROJAN!
inetservices wsock32.exe X Added by the Backdoor.Win32.Delf.ej or TROJ/WOCK32-A TROJAN!
microsoft internet wincfg16.exe X Added by a variant of the W32/SDBOT WORM!
microsoft winupdate WinNTinit32.exe X Added by the RBOT.VS WORM!
ntsf microsoft system winsis32.exe X Added by a variant of the WIN32.RBOT WORM!
quicktime mediaplayr wnmplyr.exe X Added by a variant of the WIN32.RBOT WORM!
registry value name winapi32.exe X Added by a variant of the WIN32.RBOT WORM!
wincx wincore332.exe X Added by the W32/AGOBOT-MG WORM!
windows system32 windowsp.exe X Added by the MYTOB.GD WORM!
windows32 wuuaclt.exe X Added by the W32.Bratle.B
winfixer 2005 wfx5.exe X "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
winnt dns ident windowsp.exe X Added by the RBOT.BAL WORM!
winplosion WinPlosion.exe U WinPLOSION allows you to immediately view and select from all the windows running on your computer, just those of the active application, or to minimise all windows and display a clear desktop.
winrestore1 winrestore.exe X Added by the TROJ/KILLFIL-Q TROJAN!
wsock32 wsock32.exe X Added by an unidentified WORM or TROJAN!
Microsoft Login winlogin.exe X Added by the W32/Rbot-AJP worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Microsoft Windows DLL Services Configuration windir32.exe X Added by the W32/Sdbot-ABM worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
ms ownage winPE.exe X Added by the W32/Rbot-AJL worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Webroot Spy Sweeper Engine WRSSSDK.exe Y Webroot Spysweeper's realtime scanning engine.
WNSI wnscpit.exe X PurityScan delivers advertisements to your computer.
[not used] Winroad.exe X Added by the Backdoor.Augudor backdoor.
[not used] wsv.com X Added by the Backdoor.Beasty.B backdoor. This backdoor listens on port 666.
[not used] wb.com X Added by the Backdoor.Beasty.E backdoor. This backdoor listens on port 666.
[not used] wb.com X Added by the Backdoor.Beasty.F backdoor. This backdoor listens on port 666.
Systray w32explorer.exe X Added by the W32/Rbot-AJY worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Windows System Configuration WINCFG32.EXE X Added by the W32/Agobot-TE worm.
Windows DLL Loader WINCFG32.EXE X Added by the W32/Agobot-TE worm.
Microsoft standard protector winsocks5.exe X Added by the Troj/Stox-A Trojan.
UpTimes service WinUp.exe X Added by the W32/Rbot-AKB worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
WinTasks DLL Library (32-bits) winkll.exe X Added by the W32/Rbot-AJZ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Windows System Configuration WinNeth.exe X Added by the W32/Rethe-A worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
W32Time w32t.dll X Added by the Backdoor.Fuwudoor backdoor.
Microsoft Update 32 wininit.exe X Added by the W32/Rbot-AKD worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. Please note that this infection should not be confused with the legitimate Windows file located at %System%\wininit.exe. You should only think this file is an infection if you also have a Run entry containing the name listed in this page.
syncman winsync.exe X Added by the Troj/MancSyn-A Trojan.
Microsoft Update 64 BIT winman32.exe X Added by the W32/Rbot-AKI worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Windows Update 32 winlogons.exe X Added by the W32/Forbot-FI worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
WhatPulse WhatPulse.exe U WhatPulse sends statistics on how much you type on your computer and ranks you based on that. It does not log your keystrokes, but only the counts of them.
Windows Login Security winlogin.pif or random name X Added by the W32/Rbot-AKL worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Microsoft Update 32 wininit32.exe X Added by the W32/Rbot-AKJ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Windows PNP winpnp.exe X Added by the W32/Rbot-AKN worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Microsoft Update wininit.exe X Added by the W32/Rbot-AKR worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. Please note that this infection should not be confused with the legitimate Windows file located at %System%\wininit.exe. You should only think this file is an infection if you also have a Run entry containing the name listed in this page.
WinFire WF.exe X Added by the Troj/Delf-SY keylogging Trojan.
WinDrg32 windrg32.exe X Added by the W32/Dogbot-A worm/backdoor. This file may be found in other directories as well.
wintbp.exe wintbp.exe X Added by the W32/Tpbot-A worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
wintbpx.exe wintbpx.exe X Added by the W32/Zotob-F worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
WindowsProduct Activation wpa.exe X Added by the W32/Hwbot-B worm.
windown wiusyt.exe X Added by the Troj/QQPass-M password-stealing Trojan.
Windows Help Service winhlp.pif X Added by the W32/Rbot-AKW worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
wintnpx.exe wintnpx.exe X Added by the W32.Zotob.H worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
WinFax PRO WFXSVC.EXE U This service handles many of the automated tasks of Winfax Pro such as receiving faxes. Disabling this service will impair the functioning of this program.
Wupdm32 Wupdm32.exe X Added by the W32.Midlak@mm mass-mailing worm.
Win Microsoft 98 win14.exe X Added by the W32/Rbot-AKX worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Win32 service WIN32SVC.EXE X Added by the Backdoor.Selka backdoor.
Windows 32-bit PnP Driver winpnp32.exe X Added by the W32.Wallz worm.
Network Client winlogon.exe X Added by the Trojan.Boxed.E Trojan.
*microsoft update wuytc.exe X Added by the STMU TROJAN!
windows firewalll winmu.exe X Added by a variant of the RBOT WORM!
war ftpd tray icon wartray.exe N War-ftpd - FTP server
windows media ap winmapp.exe X Added by an unidentified WORM or TROJAN!
windows media app wmapp.exe X Added by an unidentified WORM or TROJAN!
windows process manager winproc.exe X Added by an unidentified WORM or TROJAN!
windows logon procedure winlogonpc.exe X Added by the "WinLogon" TROJAN!
windows download manager windlmngr.exe X Added by an unidentified TROJAN!
wincms wincms.exe X Added by the RBOT.CBR WORM! - NOTE: this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot. Name field may be empty.
microsoft security management wuauct1.exe X Added by a variant of the WIN32.RBOT WORM!
microsoft server applacations wuauct1.exe X Added by a variant of the WIN32.RBOT WORM!
microsoft update Wudates.exe X Added by a variant of the WIN32.RBOT WORM!
microsoft update 32 winitXP32.exe X Added by a variant of the WIN32.RBOT WORM!
microsoft windows update application wuap.exe X Added by a variant of the WIN32.RBOT WORM!
Windows Socket 2.0 Non-IFS Service Provider Support Environment ws2ifsl.sys Y This is a legitimate service and is used by LSPs which do not use IFS (Installable File System) supported sockets.
Microsoft win32.exe X Added by the Backdoor.Darkmoon backdoor Trojan. It also adds the following files as part of the infection:

%System%\Yxgunlzu.d1l
%System%\drivers\Yxgunlzu.sys
windows Loadxm Win_.exe X Added by the Troj/Fodder-A password-stealing backdoor Trojan.
runing win.exe X Added by the Troj/Delf-LC Trojan.
SpyEx Winllogo.exe X Added by the W32/PrsKey-A password-stealing and keylogging worm. The worm will store the logged keystrokes into the file C:text.txt.
PNP wuaaclt.exe X Added by the W32/Lilbre-A worm.
Windows NT Logon Application WINLOGON.SCR X Added by the W32/Rbot-ALP worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
win32 internet server winserver.exe X Added by the Troj/Dermon-D Trojan.
Windows Debugger windbg32.exe X Added by the W32.Zotob.L worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
wintnl.exe wintnl.exe X Added by the W32.Zotob.K worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
AMP WinOFF winoff.exe U WinOFF is " a utility designed to shut down Windows computers automatically, with several working ways and fully configurable."
Windows Update windowsx.exe X Added by the Troj/Bancd-A password-stealing Trojan.
OLE Automation Module Wsthunk.dll X Added by the Backdoor.Thunker Trojan.
Wlan1934 wlan1934.sys X Added by the Troj/Dloader-TB Trojan.
Microsoft Update wuamgrd3.exe X Added by the W32/Rbot-AMC worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
AS00_WPN511 WPN511.exe ? NetgearRev MFC Application - software for Netgear wireless network cards - what does it do and is it required in startup?
messenger Wmsngr.exe X Added by a variant of the WIN32.RBOT WORM!
microsoft file demand manager wmgrdf.exe X Added by a variant of the WIN32.RBOT WORM!
weatherscope Weatherscope.exe X WeatherScope software - bundles Gain/Gator adware
win ctl app wuctl.exe X Added by a variant of the W32/SDBOT WORM!
windows netstart service2 winsN2SD.exe X Added by a variant of the WIN32.RBOT WORM!
winrapid winrapid.exe X Added by a variant of the WIN32.RBOT WORM!
winreups winreups.exe X Added by a variant of the WIN32.RBOT WORM!
IE Runtime winlogo.exe X Added by the W32/Rbot-AMJ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Windows Security Service windows.pif X Added by the W32/Rbot-AMG worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Windows Login Service winlogin.pif X Added by the W32/Sdbot-ACU worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
ROOT_Machine winlogon.exe X Added by the Troj/Banker-FI Trojan.
winstats winstats.exe X Added by the Trojan.Gargafx Trojan.
*winstats winstats.exe X Added by the Trojan.Gargafx Trojan.
Microsoftf DDEs Control why-.exe X Added by the W32/Rbot-AMV worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Microsoft Update 32 wiit.exe X Added by the W32/Rbot-AMS worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
userinit winlogon.exe X Added by the Troj/Dloader-TP Trojan.
[not used] winmgd.win X Added by the VBS_GEDZA.A worm.
softIce Update 32 wininits.exe X Added by the W32/Rbot-ANB worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
wordpad wordpad.exe X Added by the W32.Spybot.WON worm.
Microsoft X Update wuamkoppnp.exe X Added by the W32/Rbot-ANI worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
pnpext wmc.exe X Added by the Troj/LeechPie-D Trojan.
Windows Update 64 WinV.exe X Added by the W32/Forbot-FP worm and IRC backdoor.
winint winint.exe X Added by the W32/Sdbot-ADA worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
123 wintask.exe X Added by the Troj/LegMir-AY password-stealing Trojan for the online game Legend of Mir.
erthegdr windll2.exe X Added by the W32.Beagle.CG@mm mass-mailing worm.
Windows Update wupdmgr.exe X Added by the Troj/Bancban-FC password stealing Trojan.
sqservices wins32.exe X Added by the Troj/Progent-B Trojan.
Wind0ws wordpad.exe X Added by the W32/Agobot-TL worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
anti-virus update scheduler winsp3.exe X Malware - detected by Kaspersky antivirus as TrojanProxy.Agent.fp - A Proxy Trojan is a backdoor which allows a remote hacker to connect to other systems via the compromised system.
microsoft 64 bit runtime updater wupdt64.exe X Added by a variant of the WIN32.RBOT WORM!
etunnel winfw.exe X Added by an unidentified TROJAN!
instant wireless configuration utility WPC11Cfg.exe U Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration
microsoft machine winjava.exe X Added by a variant of the AGOBOT/GAOBOT WORM!
microsoft update loaders 2006 winusersystem32.exe X Added by a variant of the AGOBOT/GAOBOT WORM!
neroupdater6.8 winjava.exe X Added by the AGOBOT.AMK WORM!
the wind0s.exe X Added by an unidentified WORM or TROJAN!
vsample winxpsock.exe X Added by the SDBOT.BLK WORM!
weblink WebLink.exe N Softex WebLink is a "cost-effective way to provide software updates, technical support or new product information to specific end-users - it can silently provide end-users with software updates, technical support and new product information customized to their specific needs through a a persistent link."
win32 firewall driver winfw.exe X Added by a variant of the WIN32.RBOT WORM!
winamp to google talk winamptogoogletalk.exe U Winamp to Google Talk, available here shows your current Winamp track in your Google_Talk status
winantispyware 2005 was5.exe X WinAntiSpyware: MALWARE, posing as a spyware remover - for more information, search the Spywarewarrior_List of non-Recommended anti parasite sites/software for "WinAntiSpyware 2005"
wincmap wincmapp.exe X CasClient adware variant - also known as Trojan.Cmapp
windows java update weatherBug32.exe X Added by a variant of the WIN32.RBOT WORM!
windows run-time 64bit win64rt.exe X Added by a variant of the WIN32.RBOT WORM!
windows update center W32RSA.exe X Added by an unidentified WORM or TROJAN!
windows xp sp2 keygen Windows XP SP2 KeyGen.exe X Added by the W32/TIBICK-C WORM!
winremote WinRemote.exe U InterVideo WinCinema Manager - needed for the use of WinDVD_Remote_Control
winxpusbd winxp64.exe X Added by a variant of the WIN32.RBOT WORM!
wn services wnsvc.exe X Added by the W32/KBBot-A
Windows Logon Service winlogon.pif X Added by the W32/Rbot-AOU worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windows UPnP Service wupnp.exe X Added by the W32/Cuebot-F backdoor worm.
[not used] winlog.exe X Added by the Troj/Sharp-J Trojan.
Windows GMT32 wingmt32.exe X Added by the W32/Mytob-EN worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Enables Java Support winjava.exe X Added by the W32/Codbot-AA backdoor worm.
MSControl31 winnsyst.exe X Added by the W32/Rbot-APF worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
wupdmgr32.exe wupdmgr32.exe X Added by the Troj/Certif-I password-stealing Trojan.
microfot update winldx32.exe X Added by a variant of the WIN32.RBOT WORM!
windowsupdate winnnint.exe X Added by an unidentified WORM or TROJAN!
WildFlics WildFlics.exe X Added by the Dial/Direct-B premium rate dialer.
[not used] winldr.exe X Added by the W32/Bagle-AK worm.
Service System windowsXP.exe X Added by the Troj/Bancos-EL Internet banking Trojan which attempts to capture confidential banking information and send it to a remote location.
winwsl.exe winwsl.exe X Added by the W32/Zotob-J worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windows Security win.pif X Added by the W32/Rbot-APT worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Windows WinSaSS Management winsass.exe X Added by the W32/Rbot-APW worm and IRC backdoor.
win_supp00.exe Win Const.exe X Added by the Troj/Assasin-H Trojan.
Wins Service Driver winet.exe X Added by the W32/Rbot-APV worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft WINGS32 Protocol WinSGR32.exe X Added by the W32/Rbot-APU worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
windows update wudupdate.exe X Adware downloader - Istbar related
wm vcr WMVCR.exe N WM_Recorder allows you to record Windows Media™ streaming Video or Audio content. Can be accessed via Start Menu -> Programs
wsrv32 wsrv32.exe X Added by a TROJAN.CLICKER - identified by Kaspersky antivirus as Win32.Agent.ep
NTP winlogon.exe X Added by the Troj/Jtram-D IRC backdoor Trojan.
Microsoft Update 32 winnit.exe X Added by the W32/Rbot-AOM worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microft Update 32 winssx.exe X Added by the W32/Rbot-AQS worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
windef windef.exe X Added by the W32/Wurmark-O mass-mailing worm.
WinAmp Player winampp.exe X Added by the W32/Rbot-AQI worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
MCX Update wisp.exe X Added by the W32/Rbot-AQH worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Service Monitor WinOcx.exe X Added by the W32/Rbot-AQJ worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windows Internet/Server winlogo.exe X Added by the Troj/GrayBrd-AC Trojan.
Automatic Update Service wuapi.exe X Added by the W32/Codbot-AC worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Update 64 BIT winl32xe.exe X Added by the W32/Rbot-AQO worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
wininet wininet.exe X Added by the W32/Stubbot-C worm and backdoor Trojan.
Microsoft Updote wins0cks.exe X Added by the W32/Rbot-ARG worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. The file name may also be random.
WindowsSysBoot winsys.exe X Added by the W32/Rbot-ARJ worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer.
Firewall Update System1 WinedowsUpdater1.exe X Added by the W32/Rbot-ARU worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer.
Microsoft Update 32 winin.exe X Added by the W32/Rbot-ARR worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer.
Microsoft ConfgKeys wurmgrd32.exe X Added by the W32/Rbot-ARX worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer.
WINDOWS SVC winsvc.exe X Added by the W32.Mytob.KR@mm worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer.
WINDOWS SYSTEM By FEnR windasz-updote.exe X Added by the W32/Mytob-EZ worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer.
Gerenciamento de arquivos do Windows Winmod32.exe X Added by the Troj/Dloader-WG downloader Trojan.
Startup Configuration wztoid.exe X Added by the W32/Rbot-ASD worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer.
WINDOWS ID SYSTEM wID32.exe X Added by the W32/Mytob-FA worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer.
Windows Workstation Service wkssvc.exe X Added by the W32/Sdbot-AED worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer.
Windows Service Utitity winsrvc.exe X Added by the W32/Rbot-ASI worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer.
virtual-ie winlogi.exe X Malware - detected by Kaspersky antivirus as Trojan-Dropper.Win32.WinAD.h
winlogoff winlogoff.exe X Added by the W32/AGOBOT-TR WORM!
worldantispy worldantispy.exe X WorldAntiSpy, "rogue" spyware remover, installed as part of this_scam
wscsvc.exe wscsvc.exe X Added by a password stealing Banker TROJAN!
micromedia flash update wdfmrg.exe X Added by a variant of the W32/SDBOT WORM!
microsoft command line wincmd.exe X Added by a variant of the WIN32.RBOT WORM!
upgrade service winupd.exe X Added by the TROJ/TOFGER-U TROJAN!
winagent WinAgent.exe ? Standard Life Insurance program. Note: This file is legitimate. It is not known if it needs to run at startup.
windows pc winmgr.exe X Added by the W32/BIBOT-A WORM!
windows subsys winload.exe X Added by the NETSPREE.C WORM!
windows updater online winupdatexx.exe X Added by a variant of the WIN32.RBOT WORM!
winproxy personal WINPROXY.EXE X Added by the SDBOT.BMF WORM!
wintnl wintnl.exe X Added by a variant of the W32.ZOTOB.K WORM!
winzip update WinZip.exe X Added by a variant of the WIN32.RBOT WORM!
_winmain winexec.exe X Malware - detected by Kaspersky antivirus as Trojan-Downloader.Win32.Agent.ts
configuration loader WinHelper.exe X Added by a variant of the AGOBOT/GAOBOT WORM!
[random name] wuauboot.exe X PurityScan/Clickspring adware. Note - do not confuse with the legitimate wuauboot.exe file, which should not figure in Msconfig/Startup!
KAVPersonal90 wscntfy.exe X Added by the Troj/Banker-FZ password-stealing Trojan for certain online Brazilian banks.
WinCRT32 wincrt32.exe X Added by the W32/Dogbot-D worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
WindowsSysBoot winsysnet.exe X Added by the W32/Tilebot-AF worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Security Accounts Center windowo.exe X Added by the Troj/Bckdr-AWQ Trojan.
windows drivers32 windrvrs32.exe X Added by the W32/Tilebot-AG worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
WRM CPU driver wrmdrv.sys X Added by the W32/Goldax-B worm.
Windows UDP Communication wudpcom.exe X Added by the IRC-Mocbot IRC backdoor.
KernelCheck wscnty.exe X Added by the Troj/LegMir-BE password-stealing Trojan.
wcsys wcsys.exe X Added by the Troj/Keylog-AP keylogging Trojan.
Microsoft Update wuamk0032.exe X Added by a variant of the Rbot worm and IRC backdoor.
WIN ID SYS64 w3264.exe X Added by the W32/Mytob-BO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Whitman Software whitsoft.exe X Added by the W32/Rbot-AUB worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Microsoft Standard Executions Library win32lib.exe X Added by the W32/Rbot-AUK worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Windows Login Folder winzep.exe X Added by the W32/Agobot-TZ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
WinPWD Manager wpwdmgr.exe X Added by the W32/Rbot-AUT worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Windows Spools SV winsv.exe X Added by the W32/Rbot-AUQ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
WRNotifier WRLogonNTF.dll Y Used by Webroot Spy Sweeper 4.5.
Microsoft Corp Updates wupdates.exe X Added by the W32/Rbot-AUU worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
MsTask wstask32.exe X Added by the W32/Mytob-FE worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Windows Internet Service wininet.exe X Added by the W32/Rbot-AUX worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
ad-aware-6 WINDOWSUPDATER.EXE X Added by an unidentified WORM or TROJAN!
web2pop Web2Pop.exe U Web2Pop allows you to retrieve your web-based accounts messages to read them in your favorite e-mail client.
w32pluginsdownloaderxmlhttpselfclearing7520 wiper.exe X Added by the Troj/Proxyser-M
Windows update Service wisvcc.exe X Added by the Troj/Orse-G Trojan. This infection also creates the file %System%zlbw.dll.
Update Symantec WinNT.exe X Added by the W32.Vig.C virus.
Symantec Update WinNT.exe X Added by the W32.Vig.C virus.
Update MCafee WinNT.exe X Added by the W32.Vig.C virus.
MCafee Update WinNT.exe X Added by the W32.Vig.C virus.
Update WinNT.exe X Added by the W32.Vig.C virus.
MCafee WinNT.exe X Added by the W32.Vig.C virus.
wingerver2.0.exe wingerver2.0.exe X Added by the Troj/GrayBrd-AE backdoor Trojan.
Microsoft Intrenet Explorer wcumrg.exe X Added by the W32/Sdbot-AFD worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
RPCserr32g winlogon.exe X Added by the W32/Ritdoor-B backdoor worm.
Windows Update winupdmon.exe X Added by the W32/Tilebot-AR worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Proc993 wqxfne.exe X Added by the W32/Ixbot-D worm and IRC backdoor.