Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help Forums Windows Startup Programs Database Virus, Spyware, and Malware Removal Guides Computer Tutorials Uninstall Database File Database Computer Glossary Computer Resources
 

Alert!  Have a problem and would like to ask us for help? To learn how to ask your question Click Here!
Stop!  Do you have popups or other malware infecting your computer? If so, Start Here!
Question?  Are you having trouble using this site? Then you should visit the New User Orientation Center!



A    B    C    D    E    F    G    H    I    J    K    L    M    N    O    P    Q    R    S    T    U    V    W    X    Y    Z    Other   
HJT: F0, F1, F2, F3 · O4 · O20 · O21 · O22 · O23
Rootkit List  · Submit a Startup  · Top Submitters
 Startup Index · Newest Entries · Mozilla Search Tools · WebMaster Site Tools · Status Key
Startup Database Forum · Computer Help Forums · How to use the Startup Database

Enter the filename or keyword you would like to search for:
Advanced Search

Name Filename Status Description
!NoLoad winrecon.exe
N
WinRecon - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it ... Read More
(*)API Machine winSOCKS.exe
X
Homepage hijacker. (* = any digit)
(*)Run win32API.exe
X
Homepage hijacker. (* = any digit)
(04ED35B6-9A10-4EB3-9C1E-66B2CFA5AC77) windir32.dll
X
Added by the Troj/Lineage-JA Trojan.
(32A43994-9CDC-4633-A2F4-3152097D404D) winme32.dll
X
Added by the Troj/Lineage-MO password-stealing Trojan for the online game Lineage. ... Read More
(3B354F63-A696-424c-9E88-7F6BDFBA5CA5) winhosts.dll
X
Added by the Troj/Lineage-AH password-stealing Trojan for the online games Lineage. ... Read More
(44B40E3F-E91C-4ae3-89A6-1D1048A162A6) wintt1.dll
X
Added by the Troj/Lineage-KX password-stealing Trojan for the online game Lineage. ... Read More
(7B484C2F-AEE6-4e29-B894-EDEAA5DAF000) winunits.dll
X
Added by the Troj/Lineage-BN password-stealing Trojan for the online game Lineage. ... Read More
(default) winhelp.exe
X
Added by the BLACKMAL.C WORM!
(default) WINLOGON.EXE
X
Added by the Troj/Delf-LP information stealing Trojan.
(default) winligom.exe
X
Added by the W32/Rbot-GAI worm and IRC backdoor. W32/Rbot-GAI spreads to other network computers by exploiting common buffer overflow vulnerabilities, ... Read More
(default) winxp.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
(default) win32sys.exe
X
Identifed as the Sdbot.KIN worm and IRC backdoor.
(default) winmain.exe
X
Added by the Troj/LdPinch-RC Spyware Trojan.
*microsoft update wuytc.exe
X
Added by the STMU TROJAN!
*windows update wrauclt.exe
X
Added by the RBOT-QU WORM!
*windows update wuanclt.exe
X
Added by the RBOT-PG WORM!
*windows update wuaucrlt.exe
X
Added by the SPYBOT.HUR WORM!
*windows update wuraclt.exe
X
Added by the RBOT-PO WORM!
*windows update wuaruclt.exe
X
Added by W32/Rbot-TF. File is found in the Windows system directory.
*windows update wurauclt.exe
X
Added by the RBOT-SY WORM! This file runs in safe mode as well making it slightly harder to remove. ... Read More
*windows update wscxt.exe
X
Added by an unidentified WORM!
*windows update wkmst.exe
X
Added by the SDBOT.AVD WORM!
*windows update wuruclt.exe
X
Added by the W32/Rbot-TA WORM/IRC backdoor trojan!
*windows update wuacrlt.exe
X
Added by the W32/Rbot-QI worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
*windows update wruaclt.exe
X
Added by the W32/Rbot-QP worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
*windows update wruauclt.exe
X
Added by the W32/Rbot-SF worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
*windows update waurclt.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
*winstats winstats.exe
X
Added by the Trojan.Gargafx Trojan.
*wmstu wmstu.exe
X
Added by the W32/Rbot-TV worm. When started this infection connects to an IRC server where it waits for commands. This program starts in safe mode to ... Read More
*wuauclt.exe wxmct.exe
X
Added by an unidentified WORM or TROJAN!
*wuauclt.exe wmsvc.exe
X
Added by the W32/Rbot-UG network worm. When started this infection connects to an IRC server where it waits for remote commands to execute. ... Read More
,main drive Loader wininfo.exe
X
Suspected malware as it appears in 3 different registry locations - see here
.Prog winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! ... Read More
.service winlgon.exe
X
Added by the Troj/Bdoor-BX trojan backdoor.
0190 Warner WARN0190.EXE
X
Anti-dialer program (Germany)
0900 Warner WARN0900.EXE
X
Anti-dialer program (Germany)
1 winhp32.exe
X
Added by the Troj/Clckr-KY Trojan.
1 winx86.dll.js
X
Added by the JS/Uragon-A javascript worm.
123 wintask.exe
X
Added by the Troj/LegMir-AY password-stealing Trojan for the online game Legend of Mir. ... Read More
1Google Online Search Service winlugan.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Winlagons.ak malware.
1Google Online Search Service winlegal.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Winlagons.an malware.
1wincfg32 WebMailSpy.exe
X
Added by WebMailSpy SPYWARE! ... Read More
252 winmgr.exe
X
Added by the Troj/Mugger-A Trojan.
6435748 winupdates.exe
X
Identified as the Spybot.BMKF worm.
7G21B2J74A wisyst32.exe
X
Added by the Troj/Dloadr-BHE Trojan.
9m winlog0n.exe
X
Added by the Troj/LegMir-AQK password-stealing Trojan for the Legend of Mir.
<not used> win_ak.dll
X
Added by the Troj/Foghorn-A downloading Trojan.
<not used> winhe1p.exe
X
Added by the Troj/Agent-DFT Trojan.
<not used> winfkhide.dll
X
Added by the Backdoor.Ginwui.E rootkit.
<not used> WMISSHIM.DLL
X
Added by the WORM_STRAT.BT mass-mailing worm.
<not used> w3sskbda.dll
X
Added by the W32/Stration-AG worm.
<not used> wuaucll.exe
X
Added by the W32/SillyFDC-M worm.
<not used> winwork.exe
X
Added by the TSPY_WOWCRAFT.BL information stealing Trojan for the online game the World of Warcraft. ... Read More
<not used> winsys16_070307.dll
X
Added by the Troj/Hiphop-G data stealing Trojan.
<not used> wandrv.exe
X
Added by the Troj/Bckdr-QHR backdoor Trojan.
<not used> WinSit.exe
X
Added by the W32/CoiDung-A worm.
<not used> WINFBI32.dll
X
Added by the Backdoor.Ginwui.F backdoor. Backdoor.Ginwui.F is a Trojan horse that opens a back door and uses rootkit techniques to hide its presence. ... Read More
<not used> winsys16_061230.dll
X
Added by the WORM_AGENT.AFFZ worm. Please note that rundll32.exe is a legitimate program. ... Read More
<not used> wuaucl.exe
X
Added by the W32.Vapka.A worm. W32.Vapka.A is a worm that spreads by copying itself to removable media and steals confidential information. ... Read More
<not used> win32ipzip.dll
X
Added by the Trojan.Goldun Trojan.
<not used> WgaTrays.exe
X
Added by the W32.SillyDC worm.
<not used> wowfx.dll
X
Identified as a variant of the Win32/TrojanDownloader.Fakealert.G Trojan. This Trojan displays fake security alerts on your computer. ... Read More
<not used> wsnpoema.exe
X
Identified as a variant of the Troj/SpyAgent-H malware.
<Random Name> winview2.exe
X
Added by the W32/Jared-A worm.
<random name> winlogan.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Small.gdv malware.
<random name> winlogun.exe
X
Identified as a variant of the Trojan.Fakealert.ALU malware.
A New Windows Updater w32NTupdt.exe
X
added by the W32/Mytob-AG WORM, which has IRC channel backdoor trojan functionality. ... Read More
a-winpoet-service winpppoverethernet.exe
Y
WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem supp ... Read More
Access Control App winsto.exe
X
Identified as a variant of the Win32/TrojanDownloader.Small.CYF Trojan.
acecad.wtxpload Wtxpload.exe Acecad
Y
driver for an AceCad USB Graphics Tablet ... Read More
ActiveSync wcescom32.exe
X
Added by the Troj/MancSyn-E Trojan.
ad-aware-6 WINDOWSUPDATER.EXE
X
Added by an unidentified WORM or TROJAN!
AdAware wini.exe
X
Added by the W32/Rbot-XN WORM/IRC backdoor.
AdobeReaderPro winslog.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
AdobeReaderPro winini.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
ADriver windrv.exe
X
Identified by Kaspersky Anti-Virus as Trojan-Clicker.Win32.Delf.fj.
Adsl Not-A-Virus winlogn.exe
X
Added by the W32/Rbot-GUU worm and IRC backdoor.
AFAFilter windefault.exe
U
AFAFilter - internet filter software
agony wininit.sys
X
Added by the NTRootKit-K rootkit.
AKEYNAME WinServ.exe
X
Added by the EVILBOT.C TROJAN!
AMP WinOFF winoff.exe
U
WinOFF is " a utility designed to shut down Windows computers automatically, with several working ways and fully configurable." ... Read More
AndromedaAvDriver winav.sys
X
Added by the Andromeda AntiVirus rogue anti-spyware program.
aniwzcs2service WZCSLDR2.exe
Y
ALPHA_Networks wireless driver ... Read More
ANIWZCSService WZCSLDR.exe
?
D-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity ... Read More
anti-virus update scheduler winsp3.exe
X
Malware - detected by Kaspersky antivirus as TrojanProxy.Agent.fp - A Proxy Trojan is a backdoor which allows a remote hacker to connect to other sys ... Read More
AntiVir winlog.exe
X
Added by the Troj/IRCBot-TJ Trojan.
Antivirus wav.exe
X
Added by the Windows Antivirus 2008 rogue anti-spyware program.
antivirusdll winmsgslive.exe
X
Added by the W32/Sdbot-CXQ worm and IRC backdoor.
APIMon winapix.exe
X
Added by a variant of the TIBSER.A downloader TROJAN!
Application Layer Gateway WeRecl.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Application Layer Service weRecv.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
AS00_WPN511 WPN511.exe
?
NetgearRev MFC Application - software for Netgear wireless network cards - what does it do and is it required in startup? ... Read More
ASC-AntiSpyware WinCleaner.exe
X
Added by the WinCleaner 2009 rogue anti-spyware program. WinCleaner 2009 displays false results and utilizes Trojans to promote itself. ... Read More
ASC-AntiSpyware WinAntivirus.exe
X
Added by the Win Antivirus Vista/XP rogue anti-spyware program.
ASP.NET State Service winupgrad.exe
X
Added by the Troj/Banload-AJ Trojan.
Asus Protocol Driver Control wingptd.exe
X
Identified as a variant of the Trojan.Rootkit.Gen malware.
atisrc2 windfind.exe
X
Adult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), mmxrun (msosa.exe) and RegCompres (REGCPM3 ... Read More
atisrc2 winfind.exe
X
Adult content dialler - see here . This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), mmxrun (msosa.exe) and RegCompres (REGCP ... Read More
Audio Device Manager windrivers.exe
X
A variant of the Backdoor.Win32.IRCBot.afc family of worms and IRC backdoor Trojans. ... Read More
Audio Device Manager winfp.exe
X
Added by the W32/IRCBot-XS worm.
Audio Device Manager WNDXP.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Audio Device Manager WinNT.exe
X
A variant of the Backdoor.IRCBot.USP family of worms and IRC backdoor Trojans.
auto win32.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Small.hpb malware.
Auto Updat WindowsSys32.exe
X
Added by a variant of the FORBOT WORM!
autoload windowsupdate.exe
X
Identified as a variant of the WORM_SOCKS.D malware.
Automatic Update Service wuapi.exe
X
Added by the W32/Codbot-AC worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Automatic Updates wupdmgr32x.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
Automatic Updates wupdmgr32.exe
X
Unknown worm and IRC backdoor variant.
automatic updates for Microsoft Windows wuauclt.exe
X
Added by the W32/Tilebot-JW network worm.
autorun winmain.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Delf.cns malware.
autoupdate WINUP2DATE.DLL,SHStart
X
Unidentified adware - detected by Panda antivirus as Trj/Clicker.CY ... Read More
AVP sub Winspss.exe
X
Added by the Troj/Dloadr-BDM Trojan.
AvpWx WErcx.exe
X
Identified by Kaspersky antivirus as a variant of the Backdoor.IRC.Agent.a malware. ... Read More
axel wam.exe
X
Added by the W32/Melo-E worm.
bayoneting wygomd.dll
X
Zlob Trojan which installs the Virus Protect 3.8 rogue anti-spyware program. This program displays fake security alerts stating that your comput ... Read More
blah service winupdate.exe
X
Added by the GAOBOT.BIA WORM!
blah service winsysengine.exe
X
Added by the RBOT-KI WORM!
Blah Service win32.exe
X
Added by the W32/Rbot-AXO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
blah service win32exec.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
blah service Windows.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
blah service windowsXT.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
blah service. widows.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
BLUETOOTH IPv4 service wnlogow.sys
X
Added by a variant of the Troj/Haxdor-Gen rootkit.
bob winuping.exe
X
Added by the Troj/Banload-IU Trojan.
BootsCfg wscript.exe C:\\WINDOWS\\Update\\Date.POP.vbs %
X
Added by the VBS.KUULLIO WORM!
BootsCfg wscript.exe C:\WINDOWS\User\All Users.vbs %
X
Added by the VBS.Spiltron@mm mass-mailing worm.
bootscfg wscript.exe[path] Install.log.vbs
X
Added by the VBS.YPSAN.E WORM! ... Read More
Bose Wave/PC Monitor wavepcmonitor.exe
N
System Tray access for this system (more info on the system here). Available via Start -> Programs ... Read More
BossIdea winlogin.exe
X
Added by the Troj/Lineage-I TROJAN!
Broadcom Wireless Manager UI WLTRAY.exe
U
Related to Broadcom_Network Adapters for additional configuration options for these devices. Should not be terminated unless suspected to be causing ... Read More
Bron winxp.exe
X
Added by the W32.Phoney.A worm. W32.Phoney.A is a worm that spreads through mapped drives. It also lowers security settings on the compromised compute ... Read More
BuildLab winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! ... Read More
Bymer.Scanner Wininit.exe
X
Added by the BYMER WORM!
C:\Documents and Settings\All Users\Application Data\ADSL Software Limited\WinSpywareProtect\winspywareprotect.exe winspywareprotect.exe
X
Added by the WinSpywareProtect rogue anti-spyware program.
C:\Windows\winnl.exe winnl.exe
X
Added by the Downloader.Kidkiti downloader Trojan. Downloader.Kidkiti is a Trojan horse that downloads files on to the compromised computer. ... Read More
C:\Windows\winnm.exe winnm.exe
X
Added by the Downloader.Kidkiti downloader Trojan. Downloader.Kidkiti is a Trojan horse that downloads files on to the compromised computer. ... Read More
calc microsoft windows wincalc.exe
X
Added by an unidentied WORM or TROJAN!
ccApp WMADZ.EXE
X
Added by the RBOT-LJ WORM!
ccApps winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! ... Read More
CCWinTray wintmr.exe
U
Added by the Child Control parental control software.
CDriver windrv.exe
X
Identified by Kaspersky Anti-Virus as Trojan-Clicker.Win32.Delf.fj.
CEPA wsot.exe
?
??
CFDStart WinMuschi.exe
X
WINMUSCHI dialler
Check for One Touch Update wiseupdt.exe
N
Checks for updates for Visioneer OneTouch scanners
ChicoSys webtmr.exe
U
Added by the Child Control parental control software.
Client agent for ARCserve W95AGENT.EXE
?
Part of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required? ... Read More
client update wup.exe
X
Added by a variant of the W32/OPANKI-A WORM! ... Read More
COM+ Windows System winsyscom.exe
X
Identified by Symantec as a variant of the Backdoor.Trojan malware.
CommonService winup.exe
X
Added by the Troj/Dloadr-BJJ Trojan.
Compaq Jes Drivers winjes.exe
X
Added by the W32/Sdbot-XR worm. When started this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Compaq Service Drivers winmsn.exe
X
Added by a variant of the W32/Sdbot WORM/IRC backdoor Trojan, it also drops a file named msdirectx.sys in your %UserProfile% which acts as a rootkit. ... Read More
Compaq Service Drivers winsvc.exe
X
Added by the W32/Sdbot-AGD worm and IRC backdoor.
ComTry Web Searcher wstray.exe
X
Comtry MP3 Downloader related - spyware
Config WinService32.exe
X
Added by the Troj/Crutcha-A Trojan.
Config Loadr winsys32.exe
X
Added by the AGOBOT-HN WORM!
Configuration Default Wuxat.exe
X
Added by the SPYBOT-CA WORM!
Configuration File Winset32.exe
X
Added by the FLUX.101 TROJAN!
Configuration Loaded wupdated.exe
X
Added by the MOEGA or MOEGA.AG or MOEGA.AP WORMS!
Configuration Loader wincrt32.exe
X
Added by the GAOBOT.BF WORM!
Configuration Loader windex.exe
X
Added by the GAOBOT.BZ WORM!
Configuration Loader Winreg.exe
X
Added by the GAOBOT.AO WORM!
configuration loader winicfg32.exe
X
Added by the GAOBOT.GEN!POLY WORM!
Configuration Loader wincffg.exe
X
Added by the AGOBOT.A3 WORM!
Configuration Loader win32exec.exe
X
Added by the W32/Sdbot-LA worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Configuration Loader winfix.exe
X
Added by the W32/Sdbot-MA worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
configuration loader WinHelper.exe
X
Added by a variant of the AGOBOT/GAOBOT WORM!
Configuration Loader Service winsys32.exe
X
Added by the W32/Rbot-YV WORM/IRC backdoor!
Configuration Loading Service wscel.exe
X
Added by the W32/Sdbot-WJ WORM/IRC backdoor Trojan!
Configuration Utility wlanutil.exe
U
NetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards) ... Read More
Configuration32 Loader32 winamp32.exe
X
Added by the W32/Sdbot-BIC worm. When started, this infection connects to a remote IRC server and waits for commands to execute. ... Read More
Connection Reset webadmin.exe
X
A new service is set by W32/Forbot-FY with a display name of "Website Administrator Info" ... Read More
ContentService winservn.exe
X
Homepage hijacker
Controller WFXCTL32.EXE
N
From Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and display ... Read More
couponsandoffers wjview.exe
X
Added by the Adware.TopMoxie adware. Not to be confused with the legitimate wjview.exe Microsoft file. ... Read More
Cpanel WINLOGIN32.EXE
X
Added by the WORM_SPYBOT.MO worm and IRC backdoor.
cpntmgc wincomp.exe
X
MagicControl downloader trojan variant
cpntmgc winmgts.exe
X
MagicControl downloader trojan variant
CPU Temp Control wuitgurd.exe
X
Added by the W32/Rbot-AHV worm. When infected your computer will become an open mail relay which will allow your computer to be used to send out spam ... Read More
cqlyg world_cup_.bat
X
Added by the WCUP.A WORM!
CriticalUpdate Wucrtupd.exe
N
MS Windows Critical Update Notification. If you want to keep Windows up-to-date, check the Windows Update site ... Read More
crypt32unchain wlnotlfy.dll
X
Added by the TSPY_AGENT.AAVG spyware Trojan.
CTEMON.EXE winlogon.exe
X
Added by the Troj/FakeAv-FU Trojan. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
ctfmon WinConst.exe
X
Added by the Troj/Assasin-G backdoor trojan and keylogger.
ctfmon WinUP.exe
X
Added by the Troj/Banker-VV password/information-stealing Trojan for online banks. ... Read More
CTFMON winjpg.jpg
X
Added by the W32/Autorun-ALB removable media worm. Please note that the C:\Windows\System32\wscript.exe file is legitimate and should not be deleted. ... Read More
CTFMON win.exe
X
Added by the VBS.Runauto.G worm. VBS.Runauto.G is a worm that spreads through removable drives and network shares. The worm also opens a back door on ... Read More
CueX44_stil_here WINLOGON.EXE
X
Added by the W32/Punya-A worm. This infection should not be confused with the legitimate C:\Windows\System32\WINLOGON.EXE file. ... Read More
Currency windowsintd.exe
U
Added by the Spyware.Intruder surveillance software. If this program was not installed by you it should be uninstalled immediately. ... Read More
Cyclope Internet Filtering Proxy WebFilterAccess.exe
Y
Related to the Cyclope Internet Filtering Proxy Internet site and content filtering software. ... Read More
D-Link AirPlus DWL-650+ Utility WLANMON.exe
N
D-Link Air Plus Wireless PC modem connection monitor
d2 winloadhh.dll
X
Added by the Troj/Labrap-A downloader trojan.
Daily Weather Forecast WEATHER.EXE
X
Added by Troj/Dloader-IP TROJAN to the Windows program folder.
DDriver windrv.exe
X
Identified by Kaspersky Anti-Virus as Trojan-Clicker.Win32.Delf.fj.
Delete Me worm.exe
X
Added by the DOOMHUNTER WORM!
dell wireless manager ui WLTRAY
U
Related to Dell Wireless WLAN Card. Provides additional configuration options for these devices. ... Read More
Device Manager wfxmgr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
didact wuuawkz.dll
X
Zlob Trojan that infects you with the VirusHeat rogue anti-spyware program. Please use the guide below to remove this infection. ... Read More
DirectX Service WinSxS\explorer.exe
X
Added by the Troj/Bckdr-PXK backdoor Trojan.
Display Device Driver winadll.exe
X
Unidentified malware.
Distributed File System win.exe
X
Added by the W32/Myfip-L WORM, which also creates a new service/displayname called Distributed Link Tracking Extensions. ... Read More
djuka wbchha.dll
X
Zlob Trojan that infects you with the VirusHeat rogue anti-spyware program. Please use the guide below to remove this infection. ... Read More
DLHelperEXE WATCH.exe
N
Download helper distributed with some software that allows the software installation to redirect download locations. Not required once the installatio ... Read More
DLINK dfe drivers for Windows NT windfe.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
DNS Config service win32.exe
X
Added by the W32/Rbot-TL WORM/IRC backdoor trojan!
DomPlayer Service wakeservice.exe
X
Added by the DomPlayer. DomPlayer is a potentially unwanted application that may download another program and other security risks. ... Read More
DRam prosessor WindowsUpdate.exe
X
Added by the W32/Rbot-BBZ worm and IRC backdoor.
DRam prosessor winupl.exe
X
Added by the W32/Rbot-BCQ worm and IRC backdoor.
DRam prosessor winsys.exe
X
A variant of the RBot family of worms and IRC backdoor Trojans.
DRam rar proc winupdaterar.exe
X
Part of the Rbot family of worms and IRC backdoors.
drmu W95Mm.exe
X
Homepage hijacker installing a toolbar: http://tdko.com/. Lop.com in disguise. See this thread ... Read More
drvsyskit winupgro.exe
X
Added by the Troj/Agent-JQG Trojan.
DsplObjects windspl.exe
X
Added by the W32/Bagle-CF mass-mailing worm and backdoor Trojan.
DsplObjects windspl.exe
X
Added by the W32/Bagle-CK mass-mailing worm and backdoor Trojan.
DSS winoscnfg.exe
X
Added by the HTTPBruteForcer hacking utility.
dvd98 windvd98.exe
X
Added by the CULT.P WORM!
Dvx wsxsvc.exe
X
Delfin Media Viewer or "Promulgate" adware variant
Dynamic Dns Binary winxp34.exe
X
Added by a variant of the WIN32.RBOT WORM!
dynamic dns binary WinHelpcfn.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
EAPCISETUP wizard.exe
N
Part of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation ... Read More
EbatesMoeMoneyMaker wjview ...Code
N
Ebates adware
Eicon NetworksLAN_DAEMON watch.exe
U
Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) ... Read More
Eicon TechnologyLAN_DAEMON watch.exe
U
Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) ... Read More
ELSA WINman Suite Winmsuit.exe
U
Allows you to totally customize your ELSA graphics card settings, including overclocking the GPU ... Read More
Enables Java Support winjava.exe
X
Added by the W32/Codbot-AA backdoor worm.
encapsulated command tool wintr.com
?
??
Encoder Agent WMENCAGT.EXE
N
MS Windows Media Encoder, which already has a shortcut in the Start Menu if installed ... Read More
EnGenius Network Analysis Tool winegne.exe
X
Added by the W32/Rbot-GRC worm and IRC backdoor.
Enterprise Suite WE345d.exe
X
Added by the Remove Enterprise Suite (Uninstall Guide) rogue anti-spyware program. ... Read More
Enumerate Service wsys.exe
X
Added by the MANIFEST TROJAN!
Erfgddfk wind2ll2.exe
X
Added by the WORM_BAGLE.BX mass-mailing worm.
erghgjhgdr windlhhl.exe
X
Added by the W32.Beagle.BG or W32.Beagle.BH or W32.Beagle.BI or W32.Beagle.BJ WORM! ... Read More
erghgjhjgdr windlhhl.exe
X
Added by the BEAGLE.BG mass-mailing worm!
erthegdr windll2.exe
X
Added by the W32.Beagle.CG@mm mass-mailing worm.
erthgdr windll.exe
X
Added by the BEAGLE.AO or BEAGLE.AQ WORMS!
etunnel winfw.exe
X
Added by an unidentified TROJAN!
ExeName32 Warm.scr
X
Added by the SCOLD WORM!
explorer wscript.exe [filename]
X
Sneaky way to start any VBS script. Many viruses use VBS files
Explorer Windows Explorer.exe
X
Added by the W32/SillyFDC-I worm. This infection should not be confused with the legitimate C:\Windows\explorer.exe file. ... Read More
EXPLORER wab32res.exe
X
Added by the W32.Fubalca.B worm. W32.Fubalca.B is a worm that spreads through removable media and infects various file types, including .exe and .html ... Read More
eZWO wo.exe
X
Ezula "Web Offer" foistware
FClear Service wnmifc.sys
X
Added by a variant of the Troj/Haxdor-Gen rootkit.
FDriver windrv.exe
X
Identified by Kaspersky Anti-Virus as Trojan-Clicker.Win32.Delf.fj.
File System Service wmiprvsc.exe
X
Added by the AGOBOT-HZ TROJAN!
FileFreedom_Plugin wtm.exe
N
FileFreedom peer-to-peer sharing program
FileManager32 Wscript.exe ..ChkMgr32.vbs
X
Added by the NOTUP.A WORM!
FileSoft Wscript.exe UpdataFiles.vbs
X
Added by the SST.B WORM!
Fire Wall services wnlmzsfhobi.exe
X
Added by the W32/IRCBot-QY worm and IRC backdoor.
FireFly WinDeBug.exe
X
Added by the Troj/FireFly-A Trojan.
firefox startup drivers wuaclt.exe
X
Added by the RBOT.BYX ... Read More
Firewall wmlaunch .exe
X
Added by a WORM, W32/Elitper-A. It will be found in the Windows Program Files folder. ... Read More
Firewall auto setup winlogon.exe
X
Added by the Troj/Agent-EDB Trojan. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
Firewall Update System1 WinedowsUpdater1.exe
X
Added by the W32/Rbot-ARU worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. ... Read More
FIX WinFIX1.0.vbs
X
Added by the VBS.Gormlez@mm infection! Found in the Windows directory.
Flash Driver winlogon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
flaxen wakjs.dll
X
Zlob Trojan which installs the VirusTrigger rogue anti-spyware program. This program displays fake security alerts stating that your computer has a s ... Read More
Folder Service wssdtu.exe
X
Added by the MANIFEST TROJAN!
Folding@home WINFAH.EXE
N
Folding@Home is a distributed computing project which studies protein folding, misfolding, aggregation, and related diseases - must be running in orde ... Read More
Folding@Home 5.03 winfah.exe
N
Folding@Home is a distributed computing project which studies protein folding, mis-folding, aggregation, and related diseases. This program must be r ... Read More
FriendlyTypeName winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! ... Read More
Fromine WinPopup winpopup.exe
N
Instant Messenger program
FTH2004 WindowsDAT.exe
X
Added by the Backdoor.Futh backdoor. This infection listens on TCP ports 7896 and 7897 awaiting commands. ... Read More
gadcom winlogun.exe
X
Identified as a variant of the Trojan:Win32/Matcash.HZ malware. The * in the command represents a random number. ... Read More
Generic Host wauclt.exe
X
Added by the W32/Sdbot-DNL worm and IRC backdoor.
Generic Host Process for Win32 Services winsvc.exe
X
Added by the SDBOT-O WORM!
Generic Host Process for Win32 Services winlogon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans. This infection should not be confused with the legitimate C:\Windows\System32\winlog ... Read More
GenericHostXP WinLoaderXP.exe
X
Added by the Troj/Bdoor-ACX Trojan.
Genesis Streaming Service WPGApplicationLauncher.exe
U
Allows you to communicate with projectors via wireless.
geosphere wowlze.dll
X
Zlob Trojan which installs the VirusProtect 3.9 rogue anti-spyware program. This program displays fake security alerts stating that your compute ... Read More
Gerenciamento de arquivos do Windows Winmod32.exe
X
Added by the Troj/Dloader-WG downloader Trojan.
german.exe winsystems.exe
X
Added by the Troj/BagleDl-AE Trojan downloader.
german.exe wintems.exe
X
Added by the TROJ_MGLIEDER.AA Trojan.
getwin winB_.exe
X
Added by the Troj/Banker-HS password-stealing Trojan.
global startup WinDash.EXE
X
Reported by Kaspersky Anti-Virus as IM-Worm.Win32.VB.q, may be related to the W32/Attech-C ... Read More
Google Online Search Service winlagons.exe
X
Identified by Bitdefender as a variant of the Trojan.Downloader.Small.AAJM Trojan. ... Read More
Google Online Search Service winlast.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Googles Onlines Search Services wnslogan.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Winlagons.an malware.
gpmce windows.exe
X
Added by the W32/SillyFDC-HO worm.
Graphics adapter service windll.exe
X
Added by the W32.Atnas.A worm. W32.Atnas.A is a worm that performs distributed denial of service attacks and spreads through file-sharing programs. ... Read More
GrayPigeon_Hacker.com.cn windows.exe
X
Added by the Troj/GrayBrd-BA backdoor Trojan.
GrayPigeon_Hacker.com.cn windows update.exe
X
Added by the Troj/GrayBrd-CE backdoor Trojan.
gremier wscript.exe gpremier.vbs
X
Added by the GPREMIER WORM!
GW-NS54CW Service WLService.exe
Y
Driver for the Planex GW-NS54CW router.
g_rkt win32_rkt.sys
X
Identified as a variant of the Win32.Rootkit.Agent.MO rootkit.
H/PC Connection Agent WCESCOMM.EXE
U
Active sync for use with Windows CE based palm PC
Hardware Shell Detection WinHSD.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Hello World WinPad.exe
X
Added by Backdoor.CHCP. This infection listens on TCP port 1145 awaiting remote connections. ... Read More
Help Wizardnil.exe
X
Added by the Troj/Bancos-BCZ online banking Trojan. If you are infected with this file you should immediately change all of your online banking passw ... Read More
Hidetools Spy Monitor wmispe.exe
U
Added by the Spyware.HidetoolsSpy surveillance software. Spyware.HidetoolsSpy is a spyware program that records screen shots and logs keystrokes on t ... Read More
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run windowsupdate.exe
X
Added by the FORBOT-BJ WORM! (where HKLMRun represents HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun) ... Read More
hostserv wiz98.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
HOT FIX windsys2.exe
X
Identified as a variant of the Forbot worm.
Hrxmp Win Const.exe
X
Added by Backdoor.Assasin.E Trojan
http://www.lienvandekelder.be We Love Lien Van de Kelder.exe
X
Added by the W32/Mytob-CV email worm and backdoor IRC trojan.
hyperproduction wcscqa.dll
X
Zlob Trojan that infects you with the VirusHeat rogue anti-spyware program. Please use the guide below to remove this infection. ... Read More
icq lite winlog.exe
X
Added by the Troj/IRCBot-TJ Trojan.
ICQ Net winlogon.exe
X
Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should NOT appear in Msconfig/Startup! ... Read More
icqbeta webcamupdate.exe
X
Added by an unidentified TROJAN!
ICQNet winlogon.exe
X
Added by the W32/Netsky-C mass-mailing worm.
IE Runtime wini.exe
X
Added by the W32/Rbot-ABK worm. When started this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
IE Runtime wini.exe
X
Added by the W32/Rbot-ADM worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
IE Runtime winlogo.exe
X
Added by the W32/Rbot-AMJ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
IE Runtimes winis.exe
X
Added by the W32/Rbot-ADZ worm. When started this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
IE-Security wdscan.exe
X
Added by the IE-Security rogue anti-spyware program.
ie6 wkstmg.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
IE6 winsnt.exe
X
Added by the W32/Rbot-GOV worm and IRC backdoor.
IEEE 802.11g Wireless LAN Utility WLANUTL.exe
U
Configuration utility for your wireless card.
IEWinserv winserv.exe
X
Added by the Troj/Banker-EMY Trojan.
IEXPLORER-Drivers windns.exe
X
A service is created by the W32/Forbot-EP WORM, and run using the display name of "Windows Domain Name Drivers". ... Read More
IExplorerService WinSock.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
ImagePath win32ssr.exe
X
Added by the W32/Tilebot-CW worm and IRC backdoor.
Index Washer WashIdx.exe
U
Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Pr ... Read More
inetservices wsock32.exe
X
Added by the Backdoor.Win32.Delf.ej or TROJ/WOCK32-A TROJAN! ... Read More
infoxmid wseqnx.inf
X
Added by the Backdoor.Rustock backdoor rootkit.
Install Driver Table Manager wpablan.exe
X
Added by the W32/Sdbot-CWR worm and IRC backdoor. W32/Sdbot-CWR spreads to other network computers by exploiting the buffer overflow vulnerabilities: ... Read More
Instant Wireless Configuration Utility WUSB11cfg.exe
U
Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. A ... Read More
instant wireless configuration utility WPC11Cfg.exe
U
Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also use ... Read More
Intec Service Drivers winrvc.exe
X
Added by a variant of the W32/Sdbot family of worms and IRC backdoor Trojans.
Intec Service Drivers wing32.exe
X
A variant of the W32/Rbot-BCR family of worms and IRC backdoor Trojans.
intel system tool winnook.exe
X
Added by the Troj/Spyre-C trojan. This infection will display on your desktop a false message in the attempts to goad you into buying their software. ... Read More
Intel(R) PROSet/Wireless SSO Service WLKeeper.exe
Y
Service related to Intel's wireless software.
internct WinSocks5.exe
X
Added by the GRAYBIRD.F TROJAN!
Internet winlogom.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Internet WinSecUp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Internet winsas32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Internet WinSecUps.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Internet WinSUp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Internet wins.exe
X
A variant of the Worm.Rbot.AAYF family of worms and IRC backdoor Trojans.
Internet wints.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Internet Explorer Plugin WinStop32.exe
X
Added by the Backdoor.Backage backdoor.
INTERNET SERVISES winz32.exe
X
Added by the KWBOT.Z WORM!
internet2 optimizer wkfix.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
InternetExplorer2 windows.exe
X
Added by the W32/Sdbot-CZP worm and IRC backdoor.
InternetGetConnectedState winupdate.exe
X
Added by the W32/SdBot-JN worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
INTERNET_SERVISES winz32.exe
X
Added by the SDBOT.Q TROJAN!
InterU WINDRV.EXE
X
Added by the IRCINTER.A TROJAN!
Intervideo Win Cinema Manager WinCinemaMgr.exe
N
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs ... Read More
Intervideo Win Cinema Manager WINCIN~1.EXE
N
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs ... Read More
Intervideo WinCinema Manager WinCinemaMgr.exe
N
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs ... Read More
Intervideo WinCinema Manager WINCIN~1.EXE
N
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs ... Read More
Intervideo WinScheduler WinScheduler.exe
N
WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will ... Read More
IPC Spool Manager wnmgre.exe
X
Added by the W32/Sdbot-ZC. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
ipc spool manager winspec.exe
X
Added by the W32/SDBOT-BLU WORM! ... Read More
IPTable Configuration Winipcfgs.exe
X
Added by a variant of the RBOT WORM!
iRis Active Monitor winmon32.exe
N
Iris Antivirus - discontinued, replace with good alternative
iRiS AntiVirus Active Monitor WIMMUN32.exe
N
Iris Antivirus - discontinued, replace with good alternative
ISPSERVICE wintmp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
jkdfj94kgdftdf winlogan.exe
X
Identified by Trend Micro as a variant of the PE_VIRUT.XV spamming Trojan.
Jufualt winxp2.exe
X
Added by the W32/Sdbot-AAB worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
KAVFOX win1ogoin.exe
X
Added by the Troj/GWGhost-M key logging Trojan.
KAVPersonal90 wscntfy.exe
X
Added by the Troj/Banker-FZ password-stealing Trojan for certain online Brazilian banks. ... Read More
KavRuns Windll.exe
X
Added by the TRYNOMA TROJAN!
KernelCheck wscnty.exe
X
Added by the Troj/LegMir-BE password-stealing Trojan.
KernelCheck winbery.exe
X
Added by the Troj/LegMir-CG password stealing Trojan for the online game Legend of Mir. ... Read More
KernelCheck winmer.exe
X
Added by the Troj/LegMir-XG password-stealing Trojan for the online game the Legends of Mir. ... Read More
KernelFaultCheck winbin.exe
X
Added by the Troj/Dloadr-AAX downloader Trojan.
KernelFaultCheck winabc3.exe
X
Added by the W32/Nubys-A EXE virus.
Kernel_check wmiprvse.exe
X
Added by the SONEBOT-B WORM!
key winxp.exe
X
Added by the BEAGLE.AG WORM!
key2 winlog.exe
X
Added by the Trojan.Lodav.C Trojan that lowers security settings on your computer. ... Read More
KnowledgeBase GUI wppewafaj.exe
X
Added by the W32/Rbot-GRZ worm and IRC backdoor.
KSD2Service winl0gon.exe
X
Added by the Troj/Dloadr-AXH Trojan.
KV2005 word.EXE
X
Added by the Troj/VB-IW backdoor Trojan.
l44sys33 winmine.exe
X
Added by the VBS.Lido virus and worm. The winmine.exe program is actually a legitimate Windows game bundled with the OS, but in this is case, is being ... Read More
Ldr winnt.exe
X
Added by the TROJ_HARNIG.EO Trojan.
Lien Van de Kelder www.lienvandekelder.be.exe
X
Added by the W32.Mytob.DB@mm mass-mailing worm with backdoor capabilities.
Live Messanger wllmsngr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
load wuauc1t.exe
X
Added by the Troj/Dloader-LY TROJAN!
Load-Guard Wscript.exe LGuarg.exe.vbs
X
Added by the YENO.B and YENO.C WORMS!
load32 winldra.exe
X
Added by the Troj/Dumaru-AT TROJAN!

These files are known to be part of an infection that transmits information about your bank accounts, ... Read More
load= WPSLOAD.EXE
?
Windows printing system that comes with the setup for Canon BJC series on the manufacturer's disk ... Read More
load= WINOSCFG.EXE
?
Could it be something to do with configuring Windows on a new PC from an OEM supplier? ... Read More
Load= wtfeat.exe
?
Associated with the Wintab Digitizer
load= win32exec.exe
X
Added by the BITTER WORM!
loader WMPLAYER.EXE
X
Unknown malware. This infection replaces the legitimate wmplayer.exe file with an infection file of the same name. ... Read More
LoadPFW wmimgr.exe
X
Added by the W32/Qeds-B virus.
LoadWatcher watcher.exe
U
Added by the Watcher surveillance software. Spyware.Watcher is a remote surveillance application that can use a computer's webcam to secretly monitor ... Read More
loadwin winset.exe
X
Added by the Troj/QQPass-I password-stealing trojan.
loadwin winsys.exe
X
Added by the Troj/QQPass-J password-stealing trojan.
Local area connection winlive.exe
X
Added by the W32/Rbot-FPH worm and IRC backdoor.

W32/Rbot-FPH spreads to other network computers by:

- exploiting common ... Read More
Local Security Policy wpablan.exe
X
A variant of the W32/Sdbot family of worms and IRC backdoors.
Local Services winserv32.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
localhost winlogom.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Log Manager winup.exe
X
Added by the W32/Spybot-NV network worm.
LoggonAdministrator WINLOGON.EXE
X
Added by the W32.Korron.A worm. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
LoghDriver winlde.exe
X
Identified as a variant of the IRCBot family of worms and backdoors.
Login winlog.exe
U
Salfeld Child Control 2003 - parental control software
logitech desktop controller wrcam.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Logon winlog.com
X
Added by the W32.Rungbu.C virus. W32.Rungbu.C is a virus that replaces Word Documents with a copy of the virus. ... Read More
logservice wincalc.exe
X
Added by the BACKDOOR.PAPROXY TROJAN! ... Read More
longos WIWT.EXE
X
Added by the Troj/Banker-CD TROJAN!
lost WinUpdate.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
LSA wfdmgr.exe
X
Added by the W32/MyDoom-BG WORM! File is found in the Windows system folder.
lsass woekd.exe
X
Added by an unidentified WORM or TROJAN!
LTM2 winupdate.exe
X
Added by the LITMUS.203 TROJAN!
LTM2 winscan.exe
X
Added by the Troj/Litmus-B TROJAN!
Machine Update Soft wusas.exe
X
Added by an unidfentified WORM!
MalP wkssvr.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
MAT WliveUPdate.exe
X
Added by the Backdoor.Futh backdoor. This infection listens on TCP ports 7896 and 7897 awaiting commands. ... Read More
Maxtor Performance Analysis Tool winrcn.exe
X
Added by the Troj/IRCBot-VY worm and IRC backdoor.
Maya 7.0 Documentation Server wrapper.exe
Y
Related to Autodesk Maya.
MBsync WUAPDC.EXE
X
Added by the W32/Sdbot-IS worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
MC wintrims.exe
X
Added by the WINTRIM TROJAN!
mc WINTRIM.EXE
X
Added by the WINTRIM_A TROJAN! ... Read More
MCafee WinNT.exe
X
Added by the W32.Vig.C virus.
mcafee Win32.dll.vbs
X
Added by the W32/Catcher-B worm. W32/Catcher-B spreads by copying itself to the root of all mapped drives. ... Read More
MCafee Update WinNT.exe
X
Added by the W32.Vig.C virus.
McAfeeWebscanX WebScanX.exe
Y
From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guar ... Read More
MClear Service wnmicf.sys
X
Added by a variant of the Troj/Haxdor-Gen rootkit.
MCX Update wisp.exe
X
Added by the W32/Rbot-AQH worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
MD IE Plugin winy.exe
X
Adware
Media Player wmplayer.exe
X
Added by the AGOBOT-BM WORM!
Meeting Connection wowdache.exe
X
Added by the Troj/PPdoor-D TROJAN!
Memorex Network Analysis Tool winsntp.exe
X
Added by the W32/Vanebot-AT network worm.
Messanger modix Configuration winmsn.exe
X
A variant of the Backdoor.Win32.Rbot.aie family of worms and IRC backdoor Trojans. ... Read More
Messenger WINAMPA.EXE
X
Added by the Troj/Ranck-CG trojan.
messenger Wmsngr.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Mgsgi service wkzfn.exe
X
Added by the W32/Agobot-AHL worm and IRC backdoor.
microfot update winldx32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microft Update 32 winssx.exe
X
Added by the W32/Rbot-AQS worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
micromedia flash update wdfmrg.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
MicroMix32 WinCon.exe
X
Added by the Troj/VB-ECC Trojan.
MICROSFT MX UPDATE SUPPORT winmx32.EXE
X
Added by the W32/Rbot-BFU worm and IRC backdoor.
Microsof Winlog Host wilogon32.exe
X
Added by the RBOT.XC WORM!
Microsoft win32.exe
X
Added by the Backdoor.Darkmoon backdoor Trojan. It also adds the following files as part of the infection:

%System%\Yxgunlzu.d1l
% ... Read More
Microsoft winsock.exe
X
Added by the W32/Rbot-FOT worm and IRC backdoor.
Microsoft wuauclt.exe
X
Added by the Troj/QQRob-AAQ Trojan.
Microsoft wcsntfy.exe
X
Added by the W32/Agobot-AHT worm and IRC backdoor.
Microsoft windl32.exe
X
Added by the W32/Sdbot-DCZ worm and IRC backdoor.
Microsoft wsim32.exe
X
Added by the W32/Rbot-GTL worm and IRC backdoor.
Microsoft WinSecUp.exe
X
Added by the W32/Rbot-GPL worm and IRC backdoor.
Microsoft wuaudit.exe
X
A variant of the RBot.cij family of worms and IRC backdoor Trojans.
Microsoft winlog.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft winlogom.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft winsys32.exe
X
A variant of the W32/Rbot-GSQ family of worms and IRC backdoor Trojans.
Microsoft wmism23.exe
X
Added by the W32/Rbot-GSU worm and IRC backdoor.
Microsoft wplayer.exe
X
Added by the Troj/IRCBot-ABP worm and IRC backdoor.
Microsoft winline.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft winampaa.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft winlogonsys.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft (R) Windows Update Service wuauclt.exe
X
Added by the Backdoor.Ranky backdoor Trojan. This infection should not be confused with the legitimate C:\Windows\System32\wuauclt.exe file. ... Read More
Microsoft 16Bit Update wuapdate16.exe
X
Added by the RBOT.CZ WORM!
microsoft 64 bit runtime updater wupdt64.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft AntiVirus winav32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Apache for Windows wpablin.exe
X
Added by the W32/Tilebot-IL worm and IRC backdoor.
Microsoft auto update winupdate.exe
X
Added by the BMBOT TROJAN!
Microsoft auto update wuauclt.exe
X
Added by BackDoor CLT. This infections connects to an IRC server where it awaits commands. If this infection is on a Windows XP, NT, 2000, 2003, or V ... Read More
Microsoft Command C winhost32.exe
X
Added by the W32/Sdbot-BBA worm and IRC backdoor.
microsoft command line wincmd.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft ConfgKeys wurmgrd32.exe
X
Added by the W32/Rbot-ARX worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. ... Read More
Microsoft CONFIG winmx.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Corp SSL Certificates windowz.exe
X
Added by the W32/Rbot-GCZ worm and IRC backdoor.
Microsoft Corp Updates wupdates.exe
X
Added by the W32/Rbot-AUU worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Corporation wordpad.exe
X
Added by the W32/Tilebot-GL worm and IRC backdoor. This infection should not be confused with the legitimate file C:\Program Files\Windows NT\Accessor ... Read More
Microsoft Corporation Server wupdate.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft CP Web Manager webcp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
microsoft crs fix serv wincrs.exe
X
Added by the SDBOT.BWF WORM! ... Read More
microsoft dde control wupades.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Microsoft DirectX wuamgrd.exe
X
Added by the SDBOT.MY WORM!
Microsoft DirectX wupdate.exe
X
Added by the W32/Rbot-L trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Display Driver windsp.exe
X
Identified by Kaspersky antivirus as the Backdoor.Win32.Rbot.aeu worm and IRC backdoor. ... Read More
Microsoft dll Host Service wkssr.exe
X
Unidentifed worm and IRC backdoor.
Microsoft DLL Library winlib32.exe
X
Added by the W32.Atnas.A worm. W32.Atnas.A is a worm that performs distributed denial of service attacks and spreads through file-sharing programs. ... Read More
Microsoft Dll Management windll.exe
X
Added by the RBOT-MT WORM!
Microsoft DLL Verifier wns.exe
X
Added by the W32/Spybot-LA worm and IRC backdoor.
Microsoft DLL Verifier winavguard.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft DLL Verifier wind0w.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Driver Setup w7services.exe
X
Added by the W32/AutoRun-ARJ removable media worm.
Microsoft Drivers WSconf.exe
X
Added by a variant of the SDBOT WORM!
Microsoft ErgoPack wserb32.exe
X
Added by the RBOT-RI WORM!
Microsoft Excell wuamngr32.exe
X
Added by the RBOT-QH WORM!
microsoft file demand manager wmgrdf.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft Generic Update Manager wupdate.exe
X
Added by the W32/Rbot-AWC worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Genuine Advantage winmga.exe
X
Identified by Kaspersky as the Backdoor.Win32.VanBot.dk worm and IRC backdoor.
Microsoft Hosting Service WINHOSTING.EXE
X
Added by the RBOT.AEV WORM!
Microsoft Internet windows32.exe
X
Added by the SDBOT-F WORM!
microsoft internet wincfg16.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Microsoft Internet Agent winagent.exe
X
Malware bundled with rogue anti-spyware programs.
Microsoft Intranet WIN31.EXE
X
Added by the W32/Rbot-FD trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This ... Read More
Microsoft Intrenet Explorer wcumrg.exe
X
Added by the W32/Sdbot-AFD worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft IT Update win64.exe
X
Added by the RBOT.GA WORM!
Microsoft IT Update winn43.exe
X
Added by a variant of the RBOT WORM!
Microsoft IT Update win43.exe
X
Added by the RBOT-SA WORM!
Microsoft IT Update windows.exe
X
Added by the RBOT-GL WORM!
Microsoft IT Update winsyst32.exe
X
Added by the W32/Rbot-FC trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This ... Read More
Microsoft Java Virtual Machine winscr32.exe
X
Added by a variant of the WOOTBOT WORM!
Microsoft Kernel Windows_kernel32.exe
X
Added by the NETSKY.AE WORM!
Microsoft Loader winsdnz.exe
X
Added by the W32/Rbot-JJ trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Locator Service wkssvc.exe
X
Added by the W32/Sdbot-ABE worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Login winlogin.exe
X
Added by the W32/Rbot-AJP worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Lsass Service wintcp32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Machine winxp43.exe
X
Added by the W32/Rbot-IA trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This ... Read More
microsoft machine winjava.exe
X
Added by a variant of the AGOBOT/GAOBOT WORM! ... Read More
Microsoft media winmplayers.exe
X
Added by a variant of the SPYBOT WORM!
Microsoft media services winmplayer.exe
X
Added by the RBOT.ZO WORM!
Microsoft MediaScope winmes.exe
X
Added by the W32/Rbot-XU WORM/backdoor, it's file will allow a remote attacker to create new accounts, terminate processes, record keysrokes and other ... Read More
Microsoft MicroP Protocol wdgmr32.exe
X
Added by a variant of the WIN32.RBOT WORM!
Microsoft NT Update winexec32.exe
X
Added by a variant of the RBOT WORM!
Microsoft Office Start winupdates.exe
X
Added by the GAOBOT.BC WORM!
Microsoft Patches WUACMGRD.EXE
X
Added by the W32/Rbot-FX trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This i ... Read More
Microsoft Plug n Play win32pnp.exe
X
Added by the W32/Mytob-GW worm and IRC backdoor.
Microsoft Problem Doctor windr32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Problem Doctor windr64.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Problem Doctor windr128.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Redirect winred.exe
X
Added by the Troj/Banker-VK banking Trojan.
Microsoft Rundll windos.exe
X
Added by the W32/Sdbot-WF WORM/IRC backdoor!
microsoft security winService.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft Security Management winnt.exe
X
Added by the RBOT-MQ WORM!
Microsoft Security Management winserv.exe
X
Added by the RBOT-MJ WORM!
microsoft security management wuauct1.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft Security Monitor Process windowsupdate.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Security Process wininit.exe
X
Added by the W32/Rbot-FKM worm and IRC backdoor.
microsoft server applacations wuauct1.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft Service winsvc.exe
X
Added by the SPYBOT-DB WORM!
Microsoft Service winspl.exe
U
Added by the Spyware.SpyMan surveillance software. If this software was installed without your knowledge it should be removed. ... Read More
Microsoft Service Login Manager winlogin.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Service Pack WindowsSP.exe
X
Added by the W32/Rbot-RF worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
Microsoft Sound Technology winsound.exe
X
Added by the W32/Rbot-AGG worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft SpA Service win32.exe
X
This is a SDBot variant backdoor infection. When run this infection connects to an IRC server, d-3.biz. ... Read More
Microsoft SpAr Service winsbsd32.exe
X
Added by the W32/Rbot-TJ WORM/IRC backdoor trojan!
Microsoft Standard Executions Library win32lib.exe
X
Added by the W32/Rbot-AUK worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft standard protector winsocks5.exe
X
Added by the Troj/Stox-A Trojan.
Microsoft startup wmpIayer.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Stuff you know winslogin.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Svchost local services winoem.exe
X
Added by the W32/Rbot-FPE worm and IRC backdoor.
Microsoft Svchost local services Winsec32.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Synchronization Manager WinLoginnn.exe
X
Added by the SPYBOT.FO WORM!
Microsoft Synchronization Manager winupdate.exe
X
Added by the SDBOT.ER WORM!
Microsoft Synchronization Manager win.exe
X
Added by the SDBOT.AK WORM!
Microsoft Synchronization Manager WIN932.EXE
X
Added by the W32/Sdbot-IL worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
Microsoft System winamp1.exe
X
Added by the W32/Sdbot-UF worm. When started, this infection connects to an IRC server where it waits for remote commands. ... Read More
Microsoft System Checkup Wnetlib.exe
X
Added by the DONK.C WORM!
microsoft system checkup wnetmgr.exe
X
Added by the W32.DONK.Q WORM! ... Read More
Microsoft System Service winIogon2.exe
X
A variant of the IRCbot family of backdoor worms.
Microsoft TCP Protocol wintcp32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Telecoms Center winrestore.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Telecoms Center winupcd.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft U wuamkopxp.exe
X
Added by the W32/Rbot-AHC worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
microsoft unpack system winrarx.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft Update winsys32.exe
X
Added by a variant of the RBOT WORM!
Microsoft Update wuamgrd.exe
X
Added by the RBOT-LK WORM!
Microsoft Update wuammgr32.exe
X
Added by the RBOT-AW WORM!
Microsoft Update wudmate.exe
X
Added by the RBOT.AP WORM!
Microsoft Update wuamgrd32.exe
X
Added by the RBOT.ZB WORM!
Microsoft Update webm.exe
X
Added by the SDBOT.WK WORM!
Microsoft Update wuagrd.exe
X
Added by the RBOT-FK WORM!
Microsoft Update wauguard.exe
X
Added by the RBOT.AEE WORM!
Microsoft Update winscv.exe
X
Added by the RBOT-BH WORM!
Microsoft Update winsys.exe
X
Added by the RBOT-GV WORM!
Microsoft Update wserv32.exe
X
Added by the RBOT.AF WORM!
Microsoft Update wtm32.exe
X
Added by the RBOT-AQ WORM!
Microsoft Update wumgrd.exe
X
Added by the SDBOT-KY WORM!
Microsoft Update wssvr.exe
X
Added by the W32/RBOT-OD WORM!
Microsoft Update windows24.exe
X
Added by a variant of the WIN32.RBOT WORM!
Microsoft Update wuamagr32.exe
X
Added by the SPYBOT.CG WORM!
Microsoft Update winupdate32.exe
X
Added by the W32/Rbot-TI WORM/IRC backdoor trojan!
Microsoft Update WINMGARD.EXE
X
Added by the W32/Rbot-BI trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update wuamgrd16.exe
X
Added by the W32/Rbot-BQ trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update wuamgrb.exe
X
Added by the W32/Rbot-BS trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update wssvrs.exe
X
Added by the W32/Rbot-BV trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
MICROSOFT UPDATE WUAGTRD.EXE
X
Added by the W32/Rbot-CJ trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update winsyst.exe
X
Added by the W32/Rbot-DL trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update wingrd32.exe
X
Added by the W32/Rbot-DW trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update wangard.exe
X
Added by the W32/Rbot-LH trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update wkfix.exe
X
Added by the W32/Rbot-ABZ. This worm connects to an IRC server on startup where it waits for remote commands. ... Read More
Microsoft Update win-mang.exe
X
Added by the W32/Rbot-AFK worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update wuamkop.exe
X
Added by the W32/Rbot-AFI worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
microsoft update wuamkop32.exe
X
Added by the RBOT.BGU WORM! ... Read More
Microsoft Update wuamk032.exe
X
Added by the W32/Rbot-AHD worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Update wininit.exe
X
Added by the W32/Rbot-AKR worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
microsoft update Wudates.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft Update wuamgrd3.exe
X
Added by the W32/Rbot-AMC worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Update wuamk0032.exe
X
Added by a variant of the Rbot worm and IRC backdoor.
Microsoft Update windows32.exe
X
Added by the W32/Rbot-BHQ worm and IRC backdoor.
Microsoft Update wuampd.exe
X
Unidentified worm.
Microsoft Update windoc.exe
X
Added by the WORM_SDBOT.PF worm and IRC backdoor.
Microsoft Update win32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Update WinDrv32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Update wkops.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Update 32 wininit.exe
X
Added by the W32/Rbot-AKD worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Update 32 wininit32.exe
X
Added by the W32/Rbot-AKJ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
microsoft update 32 winitXP32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft Update 32 wiit.exe
X
Added by the W32/Rbot-AMS worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Update 32 winnit.exe
X
Added by the W32/Rbot-AOM worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update 32 winin.exe
X
Added by the W32/Rbot-ARR worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. ... Read More
Microsoft Update 32 wuinit.exe
X
Added by the W32/Agobot-UE worm and IRC backdoor.
Microsoft Update 32 windowsp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Update 64 BIT wininit32.exe
X
Added by the W32/Rbot-AHE worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Update 64 BIT winman32.exe
X
Added by the W32/Rbot-AKI worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Update 64 BIT winl32xe.exe
X
Added by the W32/Rbot-AQO worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
MICROSOFT UPDATE CONFIGURATION WIN32SNC.EXE
X
Added by the RBOT-AI WORM!
Microsoft Update Debugger wincfg32.exe
X
Added by the W32/Rbot-DT trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update Device Drivers wuauclt.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans. This infection should not be confused with the legitimate C:\Windows\System32\wuaucl ... Read More
Microsoft Update Emulator wuaddsff.exe
X
Added by the W32/Rbot-GX trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update Engine wumgpds.exe
X
W32/Rbot-WK WORM! File is found in the Windows system folder.
Microsoft Update Loaders 2005 winusers.exe
X
Added by the W32/Rbot-AIQ worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
microsoft update loaders 2006 winusersystem32.exe
X
Added by a variant of the AGOBOT/GAOBOT WORM! ... Read More
Microsoft Update Machine winini.exe
X
Added by the RBOT-KV WORM!
Microsoft Update Machine wuawx.exe
X
Added by the RBOT-CE WORM!
Microsoft Update Machine winupdt.exe
X
Added by the RBOT-FP WORM!
Microsoft Update Machine wuamgd.exe
X
Added by the SDBOT.HQ WORM!
Microsoft Update Machine wupdt32x.exe
X
Added by a variant of the SDBOT WORM!
Microsoft Update Machine windowsu.exe
X
Added by a variant of the RBOT WORM!
Microsoft Update Machine wininigo.exe
X
Added by a variant of the RBOT WORM!
Microsoft Update Machine winmgr.exe
X
Added by a variant of the RBOT WORM!
Microsoft Update Machine Winmsixp32.exe
X
Added by the RBOT.DN WORM!
Microsoft Update Machine Winregs32.exe
X
Added by the RBOT.DN WORM!
Microsoft Update Machine winxpini.exe
X
Added by the RBOT-OB WORM!
Microsoft Update Machine wuamgrd.exe
X
Added by the RBOT-HE WORM!
Microsoft Update Machine wuagrd.exe
X
Added by the RBOT-GF WORM!
Microsoft Update Machine winhost.exe
X
Added by the RBOT-GK WORM!
Microsoft Update Machine winss.exe
X
Added by the RBOT.JU WORM!
Microsoft Update Machine WUAMGRDXS.EXE
X
Added by the RBOT-GL WORM!
Microsoft Update Machine wupdate32.exe
X
Added by a variant of the WIN32.RBOT WORM!
Microsoft Update Machine WININI2.EXE
X
Added by the W32/Rbot-FR trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update Machine winftp32.exe
X
Added by the W32/Rbot-JX trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update Machine winortho.exe
X
Added by the W32/Rbot-NW trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These ... Read More
Microsoft Update Machine winnie.exe
X
Added by the W32/Rbot-ACD worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
microsoft update machine wins32.exe
X
Added by the RBOT.EZ WORM! ... Read More
microsoft update machine wins32.exe
X
Added by the RBOT.EZ WORM! ... Read More
Microsoft Update Machine wftestb.exe
X
Added by the W32//Rbot-AFZ worm. When started, this infection connects to an IRC server where it waits for remote commands to execute. ... Read More
Microsoft Update Machine wlimyc.exe
X
Added by the W32/Rbot-GQN worm and IRC backdoor.
Microsoft Update Machine winsys.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Microsoft Update Machine wuampd.exe
X
A variant of the Rbot-UT family of worms and IRC backdoor Trojans.
Microsoft Update Machine WINDOWSUPDATE.exe
X
A variant of the Rbot.bwj family of worms and IRC backdoor Trojans.
Microsoft Update Machine winmanwan.exe
X
A variant of the RBot family of worms and IRC backdoor Trojans.
Microsoft Update Machine winupdte.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Update Manager WINRLS.EXE
X
Added by the RBOT-AF WORM!
Microsoft Update Manager wupdate.exe
X
Added by the W32/Rbot-BIA worm and IRC backdoor.
microsoft update process wmipcvse.exe
X
Added by the TROJ/AGOBOT-JF TROJAN! ... Read More
Microsoft Update Services wsnfty.exe
X
Added by the W32/Rbot-AFU worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Update Services wcsnfty.exe
X
Added by the W32/Rbot-AGK worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Update Time wuam.exe
X
Added by the RBOT-M WORM!
Microsoft Update USB2 wuammgrd32.exe
X
Added by the W32/Rbot-ADT worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
Microsoft Update Win32a winupdate32a.exe
X
Added by the RBOT-LO WORM!
Microsoft Update Win32x winupdate32x.exe
X
Added by the W32/Rbot-AJN worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Updater winupdate.exe
X
Added by the Troj/Agent-KIR Trojan.
microsoft updater resources WinFixd32.exe
X
Added by the SPYBOT.CA WORM! ... Read More
Microsoft Updaters Pros WINDLL32XP.EXE
X
Added by the SPYBOTTER.GEN VIRUS!
Microsoft Updates wuamgrds.exe
X
Added by a Rbot variant.
Microsoft Updates wkssvrs.exe
X
Added by the W32/Rbot-EB trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Updates wtemp32.exe
X
Added by the W32/Rbot-AHQ worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Updates winit.exe
X
Added by the W32/Sdbot-CSB worm and IRC backdoor.
Microsoft Updates wkssvr.exe
X
Added by the WORM_RBOT.R worm and IRC backdoor.
Microsoft Updates wgcptsud.exe
X
Added by the W32/Rbot-GTF worm and IRC backdoor.
microsoft updates 2 usb wgafixer.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft UpdateS Machine wgrd.exe
X
Added by the W32/Rbot-FI trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This ... Read More
Microsoft Updates Resources WinFixIDs.exe
X
Added by a variant of the RBOT WORM!
Microsoft Updating WAMQUARD.EXE
X
Added by the W32/Rbot-BX trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Updating WUAMGUARDS.EXE
X
Added by the W32/Rbot-BY trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
microsoft updating client websvc.exe
X
Added by the RBOT.AQ WORM! ... Read More
Microsoft Updote wins0cks.exe
X
Added by the W32/Rbot-ARG worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. The file name ... Read More
Microsoft Updote winmsg.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Validation Service wmiprsv.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
Microsoft video capture controls winshosts.exe
X
Added by the W32/Sdbot-MP worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Visual Application winsyshp.exe
X
A variant of the SDBot.blt family of worms and IRC backdoor Trojans.
Microsoft Visual SourceSafe winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup or the Microsoft Visual ... Read More
Microsoft Visual Studio w32mvs.exe
X
Identified by VBA32 as a variant of the Backdoor.Win32.Agent.cjo malware.
Microsoft wd windmrg.exe
X
Added by the W32/Rbot-EEF worm and IRC backdoor.
Microsoft Web CP Manager webcp32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
microsoft web device wdevice.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Microsoft web update webmsn.exe
X
Added by the W32/Rbot-EMQ worm and IRC backdoor.
Microsoft Win Update WinUP.exe
X
Added by the W32/Rbot-BPR worm and IRC backdoor.
microsoft wind0ws updater winsupdater.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
MicroSoft Window Updater winsupdater.exe
X
Added by W32/Rbot-ZZ.
Microsoft Windows windets.com
X
Added by the Troj/Flood-EQ backdoor Trojan.
Microsoft Windows 2000 Winupdsdgm.exe
X
Added by the GAOBOT.AO WORM!
Microsoft Windows 32 Update win32update.exe
X
Part of the IRCBot family of worms and backdoors.
MicroSoft Windows Command wincmdXP.exe
X
Added by the W32/Tilebot-CC worm and IRC backdoor.
Microsoft Windows Communicator for NT/XP wincomm.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Windows Config 32 win32conf.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Windows DLL Services Configuration winDSL.exe
X
Added by the W32/Sdbot-ZG worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
microsoft windows dll services configuration windir32a.exe
X
Added by a variant of the SDBOT.BHF WORM! ... Read More
Microsoft Windows DLL Services Configuration windir32.exe
X
Added by the W32/Sdbot-ABM worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Windows DLL Services Configuration windll32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Windows Drivers windrv.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Windows DVR windvr.exe
X
Added by the W32/Rbot-AXD worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Windows Express websploit.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft windows FTPd winnthosts.exe
X
A variant of the W32/Rbot-FUS family of worms and IRC backdoor Trojans.
Microsoft Windows GUI Windowz.exe
X
Added by the RANDEX.AEV WORM!
Microsoft Windows Kernel Services winkrnl386.exe
X
Added by the ZEBROXY TROJAN!
Microsoft Windows Loader wloader.exe
X
Added by a variant of the AGOBOT/GAOBOT WORM!
Microsoft Windows Loader windat32.exe
X
Added by the W32/Rbot-LU trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft windows log service winlog.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Windows Logon Process winlogon.exe
X
Added by the Troj/Proxyser-R proxy Trojan.
Microsoft Windows Man Service winmgr.exe
X
Added by the W32/Sdbot-DTL worm and IRC backdoor. W32/Sdbot-DTL spreads to other network computers over network shares and by exploiting common buffer ... Read More
Microsoft Windows Media Player wimp.exe
X
Added by the RBOT-FN WORM!
Microsoft Windows Registry Service wregistry.exe
X
A Rbot WORM/IRC backdoor variant adds the file, making possible DoS attacks, running of a file server, password theft or a remote command shell put i ... Read More
Microsoft Windows Registry Updater wreg.exe
X
Added by the W32/Forbot-DN WORM/IRC backdoor trojan, while it creates a new service called wreg. ... Read More
Microsoft Windows Runtime DLL Services WINDEV.EXE
X
Added by the W32/Randex-M worm. When started, this infection connects to an IRC server where it waits for remote commands to execute. ... Read More
Microsoft Windows Secure windocs.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Windows Securety wurguar.exe
X
Added by the RBOT-KY WORM!
Microsoft Windows Security wscndrives.exe
X
Added by the W32/Rbot-AJK worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
microsoft windows service winsys.exe
X
Added by the W32/Rbot-ADP ... Read More
Microsoft Windows Service Pack winspkn.exe
X
Added by the W32/Rbot-AYD worm and IRC backdoor.
microsoft windows services controller wservices.exe
X
Added by the WIN32.RBOT.FD WORM!
Microsoft Windows Socketx32 Services winsockx32.exe
X
Added by the W32/Rbot-FWT worm and IRC backdoor.
Microsoft Windows Storage Machine Service winms.exe
X
Added by the W32/Rbot-AHK WORM/IRC backdoor trojan!
Microsoft Windows System Windows.exe
X
Added by the W32/Zotob-L mass-mailing worm and IRC backdoor.
MICROSOFT WINDOWS SYSTEM 2 winds.exe
X
Added by the WORM_MYTOB.OD mass-mailing worm and IRC backdoor.
microsoft windows system service manager winsvc.exe
X
Added by the SPYBOT.LR WORM! ... Read More
Microsoft Windows System32 winservs.exe
X
Added by the W32/Tilebot-GU worm and IRC backdoor.

W32/Tilebot-GU spreads to other network computers by exploiting common buffer overfl ... Read More
Microsoft Windows TCP Analysis winmwta.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Microsoft Windows TCP Protocol wintcps.exe
X
Added by the W32/Sdbot-DIY worm and IRC backdoor.
Microsoft Windows Updata windows.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Windows Update wuautcl.exe
X
Added by the Troj/Spybot-NQ worm and backdoor Trojan.
Microsoft Windows Update Windows Update.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Windows Update windowsapp.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Windows Update WINUPDATE.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Windows Update 32 winupdate32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
microsoft windows update application wuap.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
microsoft windows update logon win-logon.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft Windows Update Service wupdmgr32.exe
X
Added by the DOS.AUTOCAT TROJAN!
Microsoft Windows Updater winupdgm.exe
X
Added by the GAOBOT.BI WORM!
Microsoft Windows Updater WINIUPDATES.EXE
X
Added by the RBOT-KK WORM!
Microsoft Windows Updater WINUPDATE.EXE
X
Added by the SDBOT-PU WORM!
Microsoft Windows Updater win32upd.exe
X
Added by the RBOT-EC WORM!
Microsoft Windows Updater WINFIX.EXE
X
Added by the W32/Rbot-CM trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Windows Updater WINDATES.EXE
X
Added by the W32/Rbot-H trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Windows Updater2 WINUPDATE2.EXE
X
Added by the W32/Rbot-GTR worm and IRC backdoor.
Microsoft Windows Updates wsap32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Windows WinSaSS Management winsass.exe
X
Added by the W32/Rbot-APW worm and IRC backdoor.
Microsoft Windows XP/2K Explorer winexplorer.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Winedows startup WinKey.exe
X
Identified as a variant of the Net-Worm.Win32.Kolabc.bzi malware.
Microsoft WINGS32 Protocol WinSGR32.exe
X
Added by the W32/Rbot-APU worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft WinRaR winrar.exe
X
Added by the W32/Rbot-AEC worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Winsock Wrapper ws2_32s.exe
X
Added by a variant of the SPYBOT WORM!
Microsoft Winsock32 System winsock32.exe
X
Added by the W32.Spybot.AKKC worm and IRC backdoor.
microsoft winupdate Winamp61.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
microsoft winupdate WinNTinit32.exe
X
Added by the RBOT.VS WORM! ... Read More
Microsoft Word WINWORD.EXE
X
Added by the W32.Kangero.A worm. W32.Kangero.A is a worm that copies itself to mapped drives. It also lowers security settings on the compromised comp ... Read More
Microsoft Works Calendar Reminders wkcalrem.exe
N
Produces a pop-up reminder of events scheduled using the MS Works Calendar
Microsoft Works Portfolio WksSb.exe
N
The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program.Can be prevented from starting from a s ... Read More
Microsoft Works Update Detection wkdetect.exe
N
Checks for updates to MS Works
Microsoft World Service winworld.exe
X
Added by an unidentified IRC worm with backdoor capability!
Microsoft WPCEmail wpcem.exe
X
Added by the Troj/Sniffer-N Trojan. Troj/Sniffer-N monitors network traffic for email addresses. Harvested addresses are submitted to a preconfigured ... Read More
Microsoft wscntfy Service wscntfy.exe
X
Added by the Troj/Tanto-H Trojan. This infection should not be confused with the legitimate C:\Windows\System32\wscntfy.exe file. ... Read More
Microsoft X Update wuamkoppnp.exe
X
Added by the W32/Rbot-ANI worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
microsoft xp systems loader winsystem32xp.exe
X
Added by the W32.KELVIR.W WORM! ... Read More
microsoft xp systems loaders win32xpsys.exe
X
Added by the W32.SPYBOT.NYT WORM! ... Read More
Microsoft XP TCP Ack Timing winxptcp.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Microsoft-Update wngard.exe
X
Added by the RBOT-JV WORM!
microsoftf ddes control wees.exe
X
Added by a variant of the the RBOT.BOF WORM! ... Read More
Microsoftf DDEs Control why-.exe
X
Added by the W32/Rbot-AMV worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoftf DDEs Control w33s.exe
X
Identified as a variant of the RBot family of worms and IRC backdoors.
Microsoftf DDEs Control waes.exe
X
Identified as a variant of the RBot family of worms and IRC backdoors.
MicrosoftNAPC wupdate.exe
X
Added by the Troj/Agent-LAY Trojan.
Microsofts media winmplayd.exe
X
Added by an undidentified WORM or TROJAN!
microsofts media wingtp.exe
X
Added by the W32/RBOT-VO WORM! ... Read More
Microsofts MediaScope winmedplay.exe
X
Added by a variant of the WIN32.RBOT WORM!
Microsofts MediaScope winmep.exe
X
Added by the W32/Rbot-WB worm. When started this infection connects to a remote IRC server where it waits for commands to execute. These infections ... Read More
MicrosoftServiceManager Wintsk32.exe
X
Added by the YAHA.U WORM!
MicrosoftUpdate WinUp32.exe
X
Added by an unidentified VIRUS, WORM or TROJAN!
MicrosoftUpdate windll.exe
X
Added by the W32/Rbot-IH trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This i ... Read More
Microsotufed Update 32 windinit.exe
X
Added by the W32/Rbot-CTJ worm and IRC backdoor.
Micrsoft Driver windrive.exe
X
Added by the SDBOT.AF TROJAN!
Micsorosft Security Center wcnsfty.exe
X
Added by the W32/Rbot-AHU worm. When infected your computer will become an open mail relay which will allow your computer to be used to send out spam. ... Read More
Mims service winmngr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Miosf Update wimsqaad.exe
X
Added by the SDBOT.AG TROJAN!
mIRC Exchanger wavasdw.exe
X
Added by the W32/Sdbot-UO worm. When connected this infections connects to an IRC server where it waits for remote commands to execute. ... Read More
mircosoft update wuampkd.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
mismo win32x.exe
X
Added by the W32/Rbot-JP trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This ... Read More
mjd w32_mjd.dll
X
Identified as a variant of the W32.Mimbot malware.
Mlcr0s0ftf DDEs C0ntr0i WAed.pif
X
Added by the W32/Rbot-BJW worm and IRC backdoor.
Mlcrosoft Updates wmwplayers.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MMCWINMGMT winmgmt.exe
N
Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer he ... Read More
Mobipocket Web Companion webcomp.exe
U
Installed by Mobipocket Reader to create readable documents from RSS or eNews feeds on the web. ... Read More
Modifiet Amateur HTPB wuaclt.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Module WinMeter wimmtre.exe
X
Added by the W32/Sdbot-BE backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execut ... Read More
Monitor Infrared Output WinMIO.exe
X
Identified as Rbot.cnk family of worms and IRC backdoor Trojans.
Monitor Infrared System WinMIS.exe
X
A variant of the RBot family of backdoor worms. Identified as Backdoor.Win32.Rbot.bll by Kaspersky Antivirus. ... Read More
ms builders Wupated.exe
X
Added by the W32/AGOBOT-SS WORM! ... Read More
MS Dns Service wincntrl.exe
X
Added by the W32/Tilebot-BR worm and IRC backdoor.
Ms Java for Windows NT WunosJava.exe
X
Added by the WORM_RANDEX.AM network worm.
MS Java Service Wrapper Windows NT & XP wrapper.exe
X
Added by the W32/Vanebot-D worm and IRC backdoor.
Ms load for Windows NT winskd.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MS NET Service wiadss.exe
X
Identified as a variant of the Net-Worm.Win32.Kolabc.b worm.
ms ownage winPE.exe
X
Added by the W32/Rbot-AJL worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
MS PLUS INC wpad.exe
X
Added by the W32/Mytob-AN mass-mailing worm.
MS Service Drivers winscv.exe
X
Added by the W32/Sdbot-COG worm and IRC backdoor.
Ms sock for Windows NT winser.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MS Unix Binary Win32Update.exe
X
Added by the W32/Rbot-BAS trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
MS Unix Binary WinGuard.exe
X
Added by the W32/Rbot-ACL worm. When started, this infection connects to an IRC where it waits for remote commands to execute. ... Read More
MS Unix Binary win32ttb.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MS Unix Binary wrdpad05.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Ms Update WinServices NT/XP winservnt32.exe
X
Added by the W32/Vanebot-G worm. W32/Vanebot-G spreads to other network computers by exploiting common buffer overflow vulnerabilities, including: SRV ... Read More
MS-Connect web.exe
X
Adult content dialler - see here
MS-Windows Login Service winlogin32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
mscheck wincheck071008.dll
X
Identified as a variant of the Trojan-Spy.Win32.Agent.adq malware.
msconfig wins.exe
X
Added by an unidentified IRC WORM with backdoor trojan capabilities!
msconfig winlog.exe
X
Added by the Troj/IRCBot-TJ Trojan.
MSControl31 winnsyst.exe
X
Added by the W32/Rbot-APF worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
msennger winfix.com
X
Added by the Troj/IRCFlood-R Trojan. When used with an IRC client, it can be used to provide DDoS attacks. ... Read More
msgina wuauclt2.exe
X
Added by the Troj/Iyus-H TROJAN!
Msgw32 WINMSG32.EXE
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MSIdll winmp.exe
X
Added by a variant of the RBOT WORM!
MSMSGNER wcbi.exe
X
Added by the Troj/Bckdr-QMS backdoor Trojan.
MSMSGS winlogon.exe
X
Added by the W32/Brontok-BS worm. This infection should notbe confused with the legitimate C:\Windows\System32\winlogon.exe program. ... Read More
MSMSGS WINLOGON.EXE
X
Added by the W32.Korron.B worm. W32.Korron.B is a worm that replaces some file types with a copy of itself. It also copies itself to all accessible dr ... Read More
msn winlogon.exe
X
Added by the BKDR_PROSTI.A backdoor. This infection should not be confused with the legitimate microsoft file C:\Windows\System32\winlogon.exe. ... Read More
MSN winlog32.exe
X
A variant of the Backdoor.IRCBot.acd family of worms and IRC backdoor Trojans.
MSN wkssvr.exe
X
Added by the W32/IRCBot-XT worm.
MSN wksvr.exe
X
Added by the W32/IRCBot-XU worm and IRC backdoor.
MSN win32dll.exe
X
Added by the Troj/Jenny-A Trojan.
MSN wplayer.exe
X
Added by a variant of the Win32/Pushbot worm and IRC backdoor. Win32/Pushbot is a family of worms that spread using MSN Messenger. ... Read More
MSN winsystem.exe
X
Added by the W32/Sdbot.worm.gen.a worm and IRC backdoor.
MSN wdlrss.exe
X
Identified as a variant of the Backdoor.Win32.SdBot.cwm worm and IRC backdoor.
MSN wkssvrs.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MSN wmev.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MSN winmedia.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MSN Live Login Mgr wlloginmsgs.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MSN Messanger Live winntmsn.exe
X
Added by the W32/Rbot-FSO worm and IRC backdoor. W32/Rbot-FSO spreads via network shares with weak passwords and the following vulnerabilities : LSASS ... Read More
msn messeng windns.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
MSN Service wuampskum.exe
X
Added by the W32/Rbot-KC trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This i ... Read More
MSN Service Updates winproc.exe
X
Added by the W32/Kelvir-BB instant messenger worm.
Msn Updater windatemanager.exe
X
Added by the SDBOT.TS WORM!
MsnExplorer winagent.exe
X
Added by Troj/Bdoor-EQ, a backdoor TROJAN found in the Windows folder.
msnnt winampb.exe
X
Identified as a variant of the Trojan.Win32.Agent.tl malware.
MSOleath32 winss.exe
X
Added by the Kather Trojan. This infection should not be confused with the legitimate winss.exe used by Windows Live One Care. ... Read More
mspp system update 64 wiaadmgr.exe
X
Reported by Kaspersky Anti-Virus as Trojan-Proxy.Win32.Ranky.gen.
MsSecurity Updated winself.exe
X
Added by the TROJ_DNSCHANG.EU Trojan.
mssonfig winupdate.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MSStartOptimizer WINUPD.EXE
X
Adult content dialler - see here. This has to be cleared at the same time as RegCompres (REGCPM32.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), ... Read More
MSSysInterv winself.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Small.ufd malware.
MsTask wstask32.exe
X
Added by the W32/Mytob-FE worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
MStask win2sys.dll
X
Added by the Troj/Dropper-BS dropper Trojan.
MSUpdate wupd.exe
X
Added by the ALADINZ.M TROJAN!
MSUpdate winup.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
MSUpdater winnoob.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
msupdates win32chk.exe
X
A variant of the Backdoor.Win32.SdBot.aad family of worms and IRC backdoor Trojans. ... Read More
mswindows drt drivers wsdrt32.exe
X
Added by the RBOT.ALT ... Read More
MSWinlogon Winlogon.exe
X
Added by the Troj/Small-EJW Trojan.
MSWinupd winupd.exe
X
Added by the Troj/Dloader-YE downloader Trojan.
MSWinupd winnampis.exe
X
Added by the TROJ_BANLOAD.BEX Trojan.
MSWinupdate winupdate.exe
X
Added by the Troj/Dloadr-AAW Trojan.
MS_Update Check wdfmgr.exe
X
Added by the W32/Agobot-TB worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
mynsw wntsrv.exe
U
Added by the Spyware.NetScreenWatch surveillance software. Spyware.NetScreenWatch is a spyware program that monitors user activity on the compromised ... Read More
MyPointsPointAlert wjview ...MyPointsPointAlertrun.exe
X
"With MyPoints you can earn rewards from name-brand merchants. You can even earn vacations and frequent flyer miles". Dubious privacy policy ... Read More
mysoft winexplor.exe
X
Homepage hijacker
NAV Agent winsnav.vbs
X
Added by the ANPES WORM!
NAV Agent wmilib32.exe
X
Added by the Troj/VB-XU trojan.
Navegate wisterd.exe
X
Added by the Troj/Banker-BOS spyware Trojan
NB Windows Patterns WINDBKGND.EXE
N
Part of McAfee Nuts & Bolts. With Background Patterns, you can change background patterns of wizard and dialog windows ... Read More
NCplDeamon winservicess.exe
X
Identified as a variant of the Backdoor.Win32.SpyBoter.ci malware.
NDIS Adapter windows.exe
X
Added by the FORBOT-BR WORM!
NDplDeamon winlogin.exe
X
Added by the RANDEX.E WORM!
Nero Updater.6.12 wmp9.exe
X
Added by the W32/Agobot-AAG worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
neroupdater6.8 winjava.exe
X
Added by the AGOBOT.AMK WORM! ... Read More
Net WINREG.EXE
X
Added by the ASSASIN.D TROJAN!
NET Service wmssvc.exe
X
Added by the Troj/Trinity-C Trojan.
NetApp winserv.exe
X
Added by the SHADOWTHIEF TROJAN!
NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver wg111v2.sys
Y
Driver for the Netgear WG111 USB wireless adapter.
NETGEAR WG111v2 Smart Wizard WG111v2.exe
N
Setup and diagnostics program for the Netgear WG111v2 wireless USB adapter.
NETGEAR WG311v2 Smart Configuration wlancfg5.exe
U
This is Netgear's program for running it's wireless network cards. This program can also configure your wireless settings and monitor your throughput. ... Read More
NetPatrol winclient.exe
U
NetPatrol network monitoring software
NettGain2000 WgwMngr.exe
Y
Required for Starband satellite service.
Netunit32 wunit32.exe
X
Added by an unidentified WORM or TROJAN!
network access winssh.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Network ADSL Server woaisaomm.exe
X
Added by the Troj/GrayBrd-AQ backdoor Trojan.
Network Client winlogon.exe
X
Added by the Trojan.Boxed.E Trojan.
Network DDE DSDM WinDDE.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Network Protocol Service wuamgrd.exe
X
Added by the RBOT.EA WORM!
Network protocol service wintcp.exe
X
Added by a variant of the AGOBOT/GAOBOT WORM!
NetworkDiskRun winzsq.exe
X
Added by the Troj/Stinx-G worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
NetworSVSA wnipsvr.exe
X
Added by the W32.Bratsters worm.
ni.uwa6p_0001_n56m1001 WinAntiVirusPro2006Installer.exe
X
Related to the WinAntivirus programs: bogus, stealth installed "Spyware remover" - see the SpywareWarrior_List of Rogue/Suspect Anti-Spyware Products ... Read More
ni.uwa6p_0001_n69m0303 WinAntiVirusPro2006Installer[1].exe
X
Related to the WinAntivirus programs: bogus, stealth installed "Spyware remover" - see the SpywareWarrior_List of Rogue/Suspect Anti-Spyware Products ... Read More
Norton Service Driver wsul.exe
X
Added by the W32/Rbot-ABI. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infections a ... Read More
Norton Updater winset.exe
X
Added by a variant of the SPYBOT WORM!
NortonAVProtect WliveUPdate.exe
X
Added by the Backdoor.Futh backdoor. This infection listens on TCP ports 7896 and 7897 awaiting commands. ... Read More
notn wtta.exe
X
PurityScan/Clickspring adware ... Read More
Novell ZfD Wake on LAN Status Agent WolSerNT.exe
Y
Part of the Novell Windows Client. The service name is Prometheus Wake-On-LAN Status Agent. It is found in the C:\Program Files\Novell\ZENworks\Remote ... Read More
NT LM Security Support Provider WinNTLM.exe
X
Identified as the SdBot.bil worm and IRC backdoor.
NtDIC(ntdic) winz0r.exe
X
Added by the W32/Tilebot-D worm and IRC backdoor.
NTP winlogon.exe
X
Added by the Troj/Jtram-D IRC backdoor Trojan.
NTSF MICROSOFT SYSTEM wntsf.exe
X
An Rbot variant. This infection connects to an IRC server where it will await commands from a remote user. ... Read More
NTSF MICROSOFT SYSTEM win32db.exe
X
Added by a variant of the RBOT WORM!
ntsf microsoft system winsis32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
NTSF MICROSOFT SYSTEM WinAbring.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
nvchost winlogon.exe
X
Added by the Troj/Klone-J Trojan. This infection should not be confused with the legitimate file C:\Windows\System32\winlogon.exe. ... Read More
NvCpIDeamon WUAUMQR.EXE
X
A variant of the SpyBot.ag family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
NvCplScan winasp.exe
X
Added by a variant of the RBOT WORM!
OEPowerPlugs winoeinit.exe
?
??
OKGO winutade.exe
X
Added by the Troj/Banker-EHZ online banking Trojan. If you are infected with this file you should immediately contact your banks and change your onli ... Read More
OLE Automation Module Wsthunk.dll
X
Added by the Backdoor.Thunker Trojan.
oledll wmldap.dll
X
Identified as a variant of the Trojan-PSW.Win32.Agent.uv malware.
onecareui winssnotify.exe
Y
Part of the Windows Live OneCare support package from Microsoft.
ooocromosomasgenetics Winlogon.vbs
X
Added by the VBS.Wisfidix worm. VBS.Wisfidix is a worm that spreads to preconfigured mapped drives on the compromised computer. Please note that the ... Read More
OSA winword.exe
X
Added by the Trojan.Kangenie trojan.
OWCWebCamDV wcdvtray.exe
U
WebCamDV from Orange Micro, Inc - enables the user to use a DV camera connected via Firewire as a Webcam ... Read More
PaRaY_VM winlogon.exe
X
Added by the W32/Autorun-DV removable media worm. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
Patches Value WinGamed.exe
X
Added by the SDBOT.BR WORM!
Patches Value WinGasys.exe
X
Added by the W32/Rbot-GD trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Performs peer to peer connection WinPTTP.exe
X
Added by the W32/Rbot-GMI worm and IRC backdoor.
Pervasive.SQL Workgroup Engine W3dbsmgr.exe
U
Database Service Manager for Pervasive SQL 2000 Workgroup edition. Required if you use Pervasive SQL but it's recommended you start it manually before ... Read More
PivotSoftware wpctrl.exe
N
PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties ... Read More
Platform SDK Enviroment win32ssr.exe
X
Added by the W32/Rbot-BSD worm and IRC backdoor.
Player00997 WliveUPdate.exe
X
Added by the Backdoor.Futh backdoor. This infection listens on TCP ports 7896 and 7897 awaiting commands. ... Read More
Plug and Play wininet32.exe
X
Added by the Troj/Raznew-B trojan proxy server. This infection allows remote computers to use the Internet through your computer to hide their tracks ... Read More
PMedia winsrvc.exe
X
Internet marketing sofware from PMedia as used in E-Card FriendGreetings foistware - see here. Treated by Trend as the FRIENDGRT.B WORM! ... Read More
PNP wuaaclt.exe
X
Added by the W32/Lilbre-A worm.
pnpext wmc.exe
X
Added by the Troj/LeechPie-D Trojan.
popmark WinTask.exe
X
"Pop Marketing" adware
PPPOEOE WINLITE.EXE
X
Added by the W32/Rbot-AAN WORM/IRC backdoor trojan!
Print System Service wlpnsv.exe
X
Added by the Backdoor.Win32.SdBot.aad worm and IRC backdoor.
Printer Monitor webprinter.exe
X
A TROJAN, Troj/IRCBot-Z adds this file to the Windows system folder.
pro winstall.exe
X
Added by the Troj/Spywad-V Trojan.
Proc993 wqxfne.exe
X
Added by the W32/Ixbot-D worm and IRC backdoor.
Prog winsys.exe
X
Added by the Siteno.Trojan trojan.
Program sieciowy dla SAGEM Wi-Fi 11g USB adapter WLANUTL.exe
U
Generic wireless configuration utility used by many wireless brands.
Q152404 wsript.exe Q152404.VBS
N
Appears to run Scandisk at bootup on NEC PCs
Qualys wmpirvse.exe
X
Identified as a variant of the Worm:Win32/Mytob.SA mass-mailing worm.
Quernt wntfy.exe
X
Added by the W32/Autorun-PF removable media worm.
quicken Winrar.exe
X
CoolWebSearch parasite variant. Note - this is not the file zipping utility also known as WinRAR! ... Read More
quicken Waol.exe
X
CoolWebSearch parasite variant
QuickTask WliveUPdate.exe
X
Added by the Backdoor.Futh backdoor. This infection listens on TCP ports 7896 and 7897 awaiting commands. ... Read More
Quicktime Mediaplayer winmplyer32.exe
X
Added by the RBOT-PM WORM!
quicktime mediaplayr wnmplyr.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Quicktime Pro 3.0 winuodps.exe
X
Added by the GAOBOT.BH WORM!
random 10-character filename Winupdates.exe
X
Added as result of a W32/Rbot-MM worm infection ... Read More
real spy monitor Winrsm.exe
U
Realspy keystroke logger/monitoring program - remove unless you installed it yourself! ... Read More
Reg Service winsy.exe
X
Added by a variant of the SPYBOT WORM!
Reg Service WinnConfig.exe
X
Added by the W32/Agobot-PF network worm.
Reg Service winslogon.exe
X
Added by the W32/Agobot-SC WORM!
Reg Services Winboot32.exe
X
Added by the RBOT.PB WORM!
regdiit win.exe
X
Added by the W32/VBSAuto-A worm and IRC backdoor.
regdiit winxp.exe
X
Added by the W32/Autorun-ALB removable media worm.
RegDone winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! ... Read More
Registry wscript.exe
X
Added by the VBSWG.AQ WORM!
Registry Checkup winreg.exe
X
Added by an unidentified WORM or TROJAN!
Registry Checkup System326a Monitor Winregs326a.exe
X
Added by a variant of the W32/SDBOT WORM!
Registry Checkup System32cd Monitor Winregs32cdn.exe
X
Added by the W32/Rbot-AAV WORM/IRC backdoor trojan!
Registry Integritycheck WCPDT.EXE
X
Added by the W32/Agobot-RF WORM.
Registry Loader winhlpp32.exe
X
Added by the GAOBOT.AO WORM!
registry oidet win32.exe
X
Added by the RBOT.BMT WORM! ... Read More
registry value name winapi32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
RegistryChk winbackup.exe
X
Added by the MERTIAN WORM!
Regkey for autostart winservice.exe
X
Added by the W32/Rbot-NU trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These ... Read More
regManager WinSevices.exe
X
Added by the W32/VB-DZJ worm.
regrun winfix22490.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
RegRun WinBait winbait.exe
U
Part of RegRun - used to detect unknown viruses. RegRun compares winbait.exe with the original copy called winbait.org and warns if the files are ... Read More
Regrun2 WatchDog.exe
Y
Greatis Software's RegRun 3 Security Suite which amongst other things replaces MSCONFIG. The WatchDog check for registry changes caused by trojan's, v ... Read More
ReloadMicrosoftwin worldcstt2.exe
X
Added by the Troj/Bancos-AZA information-stealing Trojan for online banks. It is advised that you change your online banking passwords if you were in ... Read More
ReloadMicrosoftwinamplay worldcstl2.exe
X
Added by the Troj/Bancos-AYZ information-stealing Trojan for online banks. It is advised that you change your online banking passwords if you were in ... Read More
Remote Desktop Help Session Manager WinRDH.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Remote Procedure Call winrpc.exe
X
Added by the RBOT-KM WORM!
Remote Procedure Call winsysrpc.exe
X
Added by the SDBOT-PS WORM!
Remote Procedure Calls win.exe
X
Added by the SDBOT-QI WORM!
REMOVE ME windos.exe
X
Added by the Troj/Sdbot-JC worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
REPCLIENT1 win.pif
X
Added by the W32/AutoRun-DO removable media worm.
Restart Watch Watch.exe
?
Associated with an Eicon Networks Diva ISDN or ADSL modem. What does it do and is it required? ... Read More
Restart WSC Setting wscrestp.exe
U
WinStart Commander - part of Ultra WinCleaner Utility Suite. Starts Windows faster and controls hidden programs to boost performance and prevent syste ... Read More
Restoreds windrives.exe
X
A new service added by the W32/Agobot-RB WORM/IRC backdoor, it's displayname is Systems Backups . ... Read More
RNBc Test wf32vbs.exe
X
Added by the W32/Rbot-AGR worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
RNBz Test wf32vbc.exe
X
Added by the W32/Rbot-AEY worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
rndc test wf32b.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Rontok winxp.exe
X
Added by the W32.Phoney.A worm. W32.Phoney.A is a worm that spreads through mapped drives. It also lowers security settings on the compromised compute ... Read More
ROOT_Machine winlogon.exe
X
Added by the Troj/Banker-FI Trojan.
RPCserr32g winlogon.exe
X
Added by the W32/Ritdoor-B backdoor worm.
Run MSupdt32 wscript MSupdt32.vbs
X
Added by the CASER WORM!
Run POPFile in background wperl.exe
U
POPFile - E-mail spam blocker
run32dll WINClock.exe
X
Added by an unidentified VIRUS, WORM or TROJAN!
run= wallflip.exe
?
Desktop wallpaper changer?
run= win.ini
?
??
run= wswpd.exe
Y
Used with some models of Panasonic, Epson and NEC printers - required for printer to work ... Read More
run= wmplayer.exe
X
CoolWebSearch parasite variant - Note: this is not the Windows Media Player executable! ... Read More
Rund1l32 Winfi1e32.exe
X
Added by the MERTIAN WORM!
RunDLL32 winupdate.exe
X
Added by an unidentified TROJAN! - possibly a BMBOT variant
Rundll32 Windows.exe
X
Added by the QQPASS.E TROJAN!
runing win.exe
X
Added by the Troj/Delf-LC Trojan.
RunProg wini.exe
X
Added by the OPTIX.04.D TROJAN!
runwinlogon winlogon.exe
X
Identified as a variant of the SpamTool.Win32.Agent.gj malware.
S-1-5-21-1635847982-2902227367-3824404516-500} windoskey.exe
X
Added by the Troj/Dropin-A Trojan.
SadNet winlogon.cab.exe
X
Added by the WORM_NETSAD.A worm.
SadNet3 WinServicces.cab.bak.exe
X
Added by the W32.Amirecivel.F@mm mass-mailing worm.
Sagem - 802.11g Wi-Fi USB Dongle LAN Utility WLANUTL.exe
U
Generic wireless configuration utility used by many wireless brands.
Sagem - Utilitaire réseau pour Clé USB Wi-Fi 802.11g WLANUTL.exe
U
WiFi configuration utility for the Sagem wireless USB dongle.
scApp wmiprvse.exe
X
Added by the W32/SillyFDC-AW worm.
Scheduler winagent.exe
X
Added by the Win32.Tactslay backdoor Trojan.
scheduler service wsass.exe
X
Added by the WIN32.LIOTEN.KX WORM! ... Read More
SCNDmem WINLOW.SYS
X
Added by the Troj/Haxdoor-CN rootkit infection. This file is installed as system driver and is used to hide processes, files, and registry keys from ... Read More
scNine windates.exe
X
Unknown malware.
screws winlogon.exe
X
Added by the W32/VB-DWN worm. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
Secboot w32tm.exe
X
Added by the Backdoor.Haxdoor.D backdoor. Found in the Windows system directory. ... Read More
secboot w32_ss.exe
X
Added by the HaxDoor.B rootkit/backdoor Trojan.
Secure WindowsUpdates.exe
X
Identified as AdWare.Win32.Agent.bm.
SECURE SHELL access driver wartamd.sys
X
A variant of the Haxdoor Trojan rootkit.
secure socket layer wins32a.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Security Accounts Center windowo.exe
X
Added by the Troj/Bckdr-AWQ Trojan.
security centre wscntify.exe
X
Added by the W32.Spybot.AFEW worm and IRC backdoor.
Security Fixers WINCAT32.EXE
X
Added by the W32/Sdbot-NR worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Security Patch WinUpdate32.exe
X
Added by the W32/SdBot-BM backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execut ... Read More
Security Patches wuamgrdr.exe
X
Added by the W32/Rbot-IN trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Security Patches wuamgrdk.exe
X
Added by the W32/Rbot-IQ trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Security Patches wuamgrdn.exe
X
Added by the W32/Rbot-JI trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
security patches WinLab32.exe
X
Added by the W32/SDBOT-KB WORM! ... Read More
Senao Network Controller winsno.exe
X
Added by the W32/Vanebot-AU worm and IRC backdoor.
Serv-U wssdsu.exe
X
Added by the MANIFEST TROJAN!
Server Runtime Process wbemstest.exe
X
Added by the W32/Sdbot-DDB worm and IRC backdoor.
service wN2S.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
service win32ev.exe
X
Added by the Troj/Bckdr-QKR backdoor Trojan.
Service Client winsvcli.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Service Monitor WinOcx.exe
X
Added by the W32/Rbot-AQJ worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Service Monitor winxpser.exe
X
Added by the W32/Rbot-BDF worm and IRC backdoor.
Service Process winset.exe
X
Added by a variant of the SPYBOT WORM!
Service System windowsXP.exe
X
Added by the Troj/Bancos-EL Internet banking Trojan which attempts to capture confidential banking information and send it to a remote location. ... Read More
Service System wernell87.exe
X
Added by the Troj/Bancos-FJ Internet Banking Trojan. If you have this infection you should change the passwords to all your online banking accounts. ... Read More
ServiceOptionMP3 winamp.dll.exe
X
Added by the Troj/Samson-A Trojan.
Services winread.exe
X
Added by an unidentified VIRUS, WORM or TROJAN!
services windows32.exe
X
Added by the W32/FlyVB-C worm.
Services32 Startup win32dll.exe
X
Added by the W32/Sdbot-XO. When started this infection connects to an IRC server where it waits for remote commands, able to steal CD game keys, pe ... Read More
ShareSearcher wsusupd.exe
X
Added by the Troj/Enclag-A Trojan.
Shell wmedia16.exe
X
Added by the GOLDUN TROJAN!
Shell wmedia32.exe
X
Added by the Troj/Goldun-B TROJAN!
Shell2938 WliveUPdate.exe
X
Added by the Backdoor.Futh backdoor. This infection listens on TCP ports 7896 and 7897 awaiting commands. ... Read More
shell32 wuauclt10.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Shellwin Time Service Tools winskvc32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
sis32 winsos.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Small.gye malware.
Sistray32 win.bat
X
The W32/Jupir-A is spread via MIRC. The file can be found in the Windows system directory. ... Read More
Sitecom Wireless LAN Utility WLANUTL.exe
U
Configuration utility for your wireless card.
Sitecom Wireless Utility WLANUTL.exe
U
Generic wireless configuration utility used by many wireless brands.
Sitecom WL-112 Utility WLANUTL.exe
U
Generic wireless configuration utility used by many wireless brands.
Sitecom WL-115 Utility WLANUTL.exe
U
Generic wireless configuration utility used by many wireless brands.
SKRSpyWarn Warn.exe
U
Added by the Smart Keystroke Recorder keylogger and surveillance software. This program should be removed if it is found on your computer without you ... Read More
SkynetRevenge winlogon.scr
X
Added by the NETSKY.AA WORM!
SmansaApp winlogon.exe
X
Added by the W32/Romario-A mass-mailing worm. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe. ... Read More
SMC2862W-G 54Mbps WLAN Monitor WLANUTL.exe
U
Generic wireless configuration utility used by many wireless brands.
SMC2862W-G 54Mbps WLAN Monitor WLANUTL.exe
U
Generic wireless configuration utility used by many wireless brands.
smcserv winsrv.exe
X
Added by the AGOBOT-OU WORM!
smile wcs.exe
X
Identified as a variant of the FakeAlert/Zlob malware.
SMSERIALSTARTER win32st.exe
X
Trojan installed with the SpyBurner rogue anti-spyware program.
SMSERIALWORKERSTARTER winstrse.exe
X
Trojan installed with the SpyBurner rogue anti-spyware program.
smsger Win.exe
X
A variant of the W32/SDBot.BGIU family of worms and IRC backdoor Trojans.
sndpnpmix wauctlxp4.exe
X
Added by the WIN32.MUDROP.N TROJAN!
softIce Update 32 wininits.exe
X
Added by the W32/Rbot-ANB worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
some wcs.exe
X
Identified as a variant of the Adware/Netproject malware. Typically bundled with rogue anti-spyware programs and fake codecs. ... Read More
SonudMan WNILOGON.exe
X
Added by the W32/Lewor-AA worm.
Sony Network Analysis Tool winsony.exe
X
Added by the W32/Spybot-NS worm and IRC backdoor.
Sound Manager winrun32.exe
X
A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote serv ... Read More
Sound System WinSound1.exe
X
Added by an unidentified VIRUS, WORM or TROJAN!
SOUNDM winsmd.exe
X
Added by the Troj/Wlook-B information stealing Trojan.
SOUNDM win32smd.exe
X
Added by the Troj/WOW-JA spyware Trojan. This infection utilizes the npf.sys rootkit to hide itself. ... Read More
SPHandler wuauclt28.exe
X
Identified as the Rbot.bll worm and IRC backdoor Trojan.
SPHandler wuauclt23.exe
X
Added by the W32/Sdbot-DIL worm and IRC backdoor.
SPINX Wscript.exe OXNEY.B.VBS
X
Added by the YENO.B and YENO.C WORMS!
spool wys.exe
X
WhileUSurf adware component
spoolsvs wincfy.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
SpyEx Winllogo.exe
X
Added by the W32/PrsKey-A password-stealing and keylogging worm. The worm will store the logged keystrokes into the file C:text.txt. ... Read More
SpywareGuard winproc32.exe
X
Startpage adware Trojan
SpywareGuardPlus winmm64.exe
X
StartPage.ht homepage hijacker
sqservices wins32.exe
X
Added by the Troj/Progent-B Trojan.
srv32win win16dll.exe
U
Screenspy captures screenshots silently. If you didn't install this yourself, remove it. ... Read More
ssate.exe winsys.exe
X
Added by the BEAGLE.K WORM!
ssgrate.exe winerdir.exe
X
Added by the MITGLIEDER.O TROJAN!
ssgrate.exe winsystems.exe
X
Added by the TROJ/BAGLEDL-J TROJAN
ssgrate.exe wintems.exe
X
Added by the Trojan.Mitglieder.Q trojan backdoor/proxy.
SSH Client for Windows winshp.exe
X
Added by the Win32/Duiskbot.BE worm and IRC backdoor.
SSK Service winssk32.exe
X
Added by the SOBIG.E WORM!
ssms.exe winn.exe
X
Added by the W32/Sdbot-DHE worm and IRC backdoor.
star1 Winrun.exe
X
Added by the Troj/DwnLdr-HLK downloading Trojan.
stardust wallpaper control 2003 WCMain.exe
N
Related to Stardust_Software Screen Saver Control 2003 ... Read More
Start windows.vbs
X
Homepage hijacker
Start Upping windupds.exe
X
Added by the SDBOT.AFH WORM!
start upping windupdts.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Starting up wvsvc.exe
X
Added by the W32/Rbot-NF trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These ... Read More
startkey win32i.exe
X
Added by the Troj/Bifrose-R Trojan.
startkey winampXP.exe
X
Added by the Troj/Bifrose-OY backdoor Trojan.
startkey win32.exe
X
Added by a variant of the Backdoor.Bifrose family of Trojans. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a ... Read More
startup WinlogonStartup
X
Unidentified malware
Startup Configuration wztoid.exe
X
Added by the W32/Rbot-ASD worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. ... Read More
Still Image Instrumenta WinMgnt.exe
X
Added by the Troj/Feutel-AP backdoor Trojan. This infection also creates the files c:\windows\WinMgnt.DLL, c:\windows\WinMgntKey.DLL, and c:\windows\ ... Read More
stmha wkfxi.js
X
Added by the SPETH WORM!
stoner winsvcx.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
StreamAppliance wuauclt14.exe
X
Added by the W32/Rbot-GLT worm and IRC backdoor.
StreamAppliance wuauclt16.exe
X
Added by the W32/Rbot-GME worm and IRC backdoor.
Streams Drivers winlogon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
STV winscrne.exe
X
A variant of the WORM_SDBOT family of worms and IRC backdoor Trojans.
SurfinGuard Pro winsfcm.exe
U
SurfinGuard Pro - internet protection software
SvcH0st WINAGENT.EXE
X
Added by the TROJ/BDOOR-EB TROJAN!
Svchost winhost.exe
X
Added by the LOLAWEB.A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! ... Read More
SWd winwd.exe
N
PC Security from Tropical Software - lock files, password protect, etc
SWSetup winrar.exe
X
Added by the Troj/GrayBrd-CQ backdoor Trojan.
Sygate Personal Firewall Win32x.exe
X
Added by the RBOT-KZ WORM!
sygate personal firewall winxpstat.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Sygate Personal Firewall wins.exe
X
Added by the W32/Rbot-DZW worm and IRC backdoor.
Sygate Personal Firewall win31243.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Sygate Personal Firewall Startup wint.exe
X
Added by the W32/Rbot-OV trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These ... Read More
Symantec Antivirus professional windows .exe
X
Identified as Backdoor.Win32.Rbot.ckj.
Symantec Update WinNT.exe
X
Added by the W32.Vig.C virus.
syncman winsync.exe
X
Added by the Troj/MancSyn-A Trojan.
syntax windows32.exe
X
Added by the SDBOT.CQ WORM! ... Read More
Sys29 win***32.exe [* = random char]
X
EliteBar adware
SysA win***32.exe [* = random char]
X
EliteBar adware
sysav winav.exe
X
Added by the WinPC Antivirus rogue anti-spyware program.
Syscheck win.hta
X
Browser hijacker
SysConfig wincfg32.exe
X
Added by the SDBOT.ZD WORM!
Sysctrls winupdate.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Sysctrls win32dll.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
sysdir winrun.exe
X
Added by the WINBUR.B WORM!
syshelps wmhs32.dll
X
Identified as a variant of the IM-Worm.Win32.Agent worm.
SysInit wininit32.exe
X
Added by the XABOT WORM!
SysInit wininit32.exe
X
Added by the W32/Sdbot-NA worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection ... Read More
SysMon wowexece.exe
X
Added by the Troj/Mulan-A trojan.
SysMonitor WinSystem.exe
X
Added by the W32/VB-DWI worm that spreads to removeable storage devices.
sysprep wscntfx.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
SysSupport WindowsServerService.exe
X
Added by the W32.Degnax@mm worm. W32.Degnax@mm is a mass-mailing worm that gathers email addresses from the compromised computer. It also spreads via ... Read More
SYSTEM wuamgre.exe
X
Added by the W32/Rbot-WA Backdoor/WORM! Found in the Windows system folder.
System winipck.exe
X
Added by the W32/Rbot-TK WORM/backdoor trojan!
System WINL0G0N.EXE
X
Added by the Troj/Bancos-DB trojan.
system wiinlogon.exe
X
Added by the W32/Rbot-AVG ... Read More
System winsock32.dll
X
Added by the Troj/Agent-SH Trojan.
System wmplayer.exe
X
Added by the W32/Lazy-A worm.
System WM_.exe
X
Added by the Troj/Dropper-NR Trojan.
SYSTEM windmupdr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
System winupd.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
System wind32.exe
X
Added by an unknown malware.
system Winhelp.exe
X
Added by the W32.Imaut.CN worm. W32.Imaut.CN is a worm that spreads through Yahoo! Instant Messenger and network shares. It may also download potentia ... Read More
System winnet.dll
X
Added by the BKDR_AGENT.XZMS backdoor.
System Check win_klr32.exe
X
Added by the W32/Delf-DRA worm.
system checking wasul.exe
X
Added by the RBOT.BHM WORM! ... Read More
System Defender WS339.exe
X
Added by the System Defender rogue anti-spyware program.
System Document Application winsvc32.exe
X
Added by the W32/Sdbot-VA WORM! Found in the Windows system folder.
System Drivers wingmt.exe
X
Added by the W32/SDBOT-MG WORM!
System Event Notificat winlogon.exe
X
Added by the Troj/Hupigo-SA Trojan. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe. ... Read More
System Information Manager win.exe
X
Added by the W32/Sdbot-MU worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
System Information Manager windowsNt.com
X
Added by the W32/Sdbot-ND worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
System Manager winsrv32.exe
X
Added by an unidentified WORM or TROJAN!
system manager updates winsvc.exe
X
Added by the AGOBOT.AEM WORM! ... Read More
SYSTEM MESSAGER wmisg.exe
X
Added by the W32.Mytob.ES@mm worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
System Process Analization wininxt.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
System Servers windows.exe
X
Added by the Troj/GrayBrd-L Trojan.
System Service WinFx.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
System Update wupdmgr.exe
X
Added by the SOROMO-A TROJAN!
system update wauluclt.exe
X
Added by the SDBOT.EF WORM! ... Read More
System Update winamp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
System Update Service wmiprvsa.exe
X
Added by the AGOBOT-RG TROJAN!
System Update Service winupd32.exe
X
Added by the ADTODA-A TROJAN!
System Update2 webcheck.exe
X
Added by the AUTOTROJ-C TROJAN!
System Update2 wininet.exe
X
Added by the AUTOTROJ-C TROJAN!
System Update2 winlogon.exe
X
Added by the AUTOTROJ-C TROJAN!
System Update2 winspool.exe
X
Added by the AUTOTROJ-C TROJAN!
System Update2 wupdmgr.exe
X
Added by the AUTOTROJ-C TROJAN!
System Updater Service wmiprvsw.exe
X
Added by the GAOBOT.AFC WORM!
system updates winsci.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
System Updates wmkl.exe
X
Added by the W32/Rbot-AYJ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
System Updates Manager winserv32.exe
X
Added by the W32/Agobot-AGA network worm.
System Windos winsyscfg.exe
X
Added by a Mytob mass-mailing worm and IRC backdoor variant.
system32 wcntfy.exe
X
Added by the Troj/Banker-CSY Internet banking Trojan. If you have this infection you should immediately change all of your online banking account inf ... Read More
System32 winds32.exe
X
Identified as a variant of the Trojan:Win32/Tibs.FZ malware.
system32 master windowsys.com
X
Added by the W32/Sdbot-DIE worm and IRC backdoor.
SystemAdministration Wincmp32.exe
X
Added by the ASYLUM TROJAN!
SystemDriver windrv.exe
X
Identified by Kaspersky Anti-Virus as Trojan-Clicker.Win32.Delf.fj.
SystemKey WIN2000.EXE
X
Added by the Troj/QQify-A. It also copies itself as nsconfig.exe, msconfig.exe, regedita.exe and regedit.exe to %Windir%. ... Read More
SystemMigration WinMedia.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
SystemReg WINREG.EXE
X
Added by the DEWIN.A TROJAN!
Systems Backups windrives.exe
X
Added by an Agobot WORM/IRC backdoor variant, also creating a new service, servicename "Restoreds" and a displayname "Systems Backups". ... Read More
systems usb driver Windows2.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
SystemTray wekls4.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
SystemTray Windowsupd.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
SystemTray winligom.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
SystemW Winalx.bat
X
Added by the Virus.Win32.HLLW.Anirak virus/worm.
systhread winkernal.exe
X
Added by the LIAMED WORM!
Systray w32explorer.exe
X
Added by the W32/Rbot-AJY worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
SysUpd WindowsUpd1.exe
X
VirtuMonde adware
SysWsa32 WSA32.EXE
U
Added by the Spyware.BEverywhere.B surveillance software. This program should be uninstalled if it was not installed by yourself. ... Read More
sysygm64 winrxd64.exe
X
Added by the Troj/IRCBot-RK worm and IRC backdoor.
SyteUpdtes wopooe.exe
X
Added by the Troj/Ezio-H IRC backdoor Trojan.
syWMI Performance Adapter Services wmiapsrvs.exe
X
A variant of the RBot family of worms and IRC backdoor Trojans.
T4skM4n4g3r Wink3sk9.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Task Help wualcts.exe
X
Added by a variant of the WIN32.RBOT WORM!
Taskmon driver winampa.exe
X
Added by the LOONY-I TROJAN!
TBMExe wdfmgr.exe
X
Added by the W32.Notong.A virus. W32.Notong.A is a virus that spreads by infecting executable files. ... Read More
TBMonEx wdfmgr.exe
X
Added by the W32/MumaWow malware.
TCPIP route manager winsys.exe
X
Added by the Troj/Lydra-AB Spyware Trojan.
TEXTCONV winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! ... Read More
the wind0s.exe
X
Added by an unidentified WORM or TROJAN!
this free winsyst.exe
X
Added by the W32.Madag.A worm. W32.Madag.A is a worm that spreads by copying itself to removable storage devices and infects .doc files. ... Read More
Thsys winrun.sys.pif
X
Added by the W32/Sachiel-D worm.
Time Zone Synchronization wscript zshell.js
X
Added by the NETDEX-A TROJAN!
Torjan Program WINLOGON.EXE
X
Added by the Troj/WoW-EA password stealing Trojan targetting of the World of Warcraft online computer game. This infection should not be confused with ... Read More
Touch Manager WinLED.exe
U
Dell keyboard utility. Disabling can result in loss of screen saver and power saver functionality ... Read More
Tour wincool.exe
N
Component of WinME that's annoying as hell. Pop's up a prompt to play the C:\WINDOWS\Application Data\Microsoft\INTRO\CONTENT.HTA that plays a full sc ... Read More
Tray Temperature Weatherbug.exe
N
Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs ... Read More
TrayX winppr32.exe
X
Added by the SOBIG.F WORM!
tsk mng hlp wins32.exe
X
Added by the W32/AGOBOT-JB WORM! ... Read More
TVTonic RSS WXRSS.exe
N
Added by the TVTonic podcast / Internet TV download manager.
Tweak Manager WinManager.Exe
?
WinGuides Tweak Manager. Is this required for the live updates feature and/or if settings are changed? ... Read More
twhe wbta.exe
X
PurityScan delivers advertisements to your computer.
UDP Packet Correction Wnlogon.sys
X
Identified as part of a variant of Trojan.PWS.Egold. This file will usually be hidden by the rootkit logon032.dll. ... Read More
ukl wmpusrvc.exe
U
Added by the Spyware.UltimateKeylog surveillance software. Spyware.UltimateKeylog is a program that records keystrokes and takes screenshots of the co ... Read More
UltraVNC Server winvnc.exe
U
Server component which listens for incoming connections for the UltraVnc application. This application allows you to take over your computer from a ... Read More
Undefined winter.exe
X
Fakealert Trojan which shows fake security alerts on your computer.
uninstall_wintools WTuninst.exe
U
WinTools adware uninstaller. Should only need to run once in order to complete uninstall; when done, disable. ... Read More
UnrealIRCd wircd.exe
Y
The UnrealIRCd Daemon. This is the actual FTP Server.
Updade Windows winlogom.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
UpData wupdata.exe
X
Troj/IRCBot-AA , a TROJAN/IRC backdoor, will allow an attacker to access and exploit the computer when this file is added. ... Read More
UPDATE WinUpdater5.0.vbs
X
Added by the VBS.Gormlez@mm infection! Found in the Windows directory
update winis.exe
X
Added by the Rbot-VD worm. This infections connects to an IRC server where it waits for remote commands. ... Read More
Update WinUpdate.exe
X
Added by the W32/Sdbot-CV backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execut ... Read More
Update WinNT.exe
X
Added by the W32.Vig.C virus.
Update winzip.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Update Checker winlog.exe
X
Added by the Troj/IRCBot-TJ Trojan.
Update Grokster WiseUpdt.exe
N
Automatically updates the Grokster file sharing software. Beware of adware and spyware when using this type of program, for instance, Grokster contain ... Read More
Update MCafee WinNT.exe
X
Added by the W32.Vig.C virus.
update service winx.exe
X
Added by a variant of the WIN32.RBOT WORM!
Update Service winu32.exe
X
Added by the W32/RBOT-MG WORM!
Update Symantec WinNT.exe
X
Added by the W32.Vig.C virus.
Update TUT WiseUpdt.exe
?
??
updatecheck winstall.exe
X
Added by the W32/SPYBOT-CY WORM! ... Read More
updater wupdater.exe
X
eUniverse KeenValue parasite related
updater wisvc.exe
X
Added by Troj/Orse-A, which also creates a service using the same name, with a displayname of Windows update Service. ... Read More
updater32 winload32.exe
X
Added by the CULT.M WORM!
UpdateService wservice.exe
X
Added by the W32/Dref-K mass-mailing worm. W32/Dref-K will attempt to infect SCR EXE and RAR files then email itself as an attachment to email address ... Read More
upddateit winit.exe
X
Added by the RBOT-MS WORM!
upgrade service winupd.exe
X
Added by the TROJ/TOFGER-U TROJAN! ... Read More
UPNPService WinSVCservice.exe
X
Added by the AGOBOT.UN WORM!
UPSUtl web.exe
X
CoolWebSearch parasite variant
UpTimes service WinUp.exe
X
Added by the W32/Rbot-AKB worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
urudjeffni winlogon.exe
X
Added by the W32/Romario-A mass-mailing worm. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe. ... Read More
USB 2.0 Driver winsystem.exe
X
Added by the W32/Agobot-QS WORM/IRC backdoor, it kills a variety of processes relating to anti-virus and security related programs. ... Read More
USB 2.0 Driver Winsys32.exe
X
W32/Agobot-QM WORM will add this file, resulting in unauthorised access, by way of an IRC channel, through a backdoor. ... Read More
USB 2.1 Driver winupdate1.exe
X
Added by a variant of the RBOT WORM!
USB Device win32usb.exe
X
Added by the FORBOT-BQ WORM!
usb fix 1.1 wuservices.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
USB Fixes wuafix.exe
X
An SDBot variant. These infections connect to IRC servers and wait for remote commands to execute. ... Read More
USB Hardware32c Monitoring USBHARDWARE32C.EXE
X
Added by the W32/Rbot-UU worm. When started, this infection connects to an IRC server where it waits for remote commands. ... Read More
usb updates 2 wugfixx.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
USBConfigration2 wmmndir.exe
X
Added by the W32/Agobot-SV worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
useful-soft wartsrv.exe
X
Added by the Troj/StartPa-WB IE startpage hijacker. This infection hijackthis your startpage to www.teengb.com. ... Read More
useful-soft winspsrv.exe
X
Added by the Troj/StartP-BCG Trojan.

Troj/StartP-BCG changes the Start Page for Microsoft Internet Explorer by setting the registry an ... Read More
userinit winlogon.exe
X
Added by the Troj/Dloader-TP Trojan.
Userinit winsys16_070813.dll
X
Added by the W32/AutoRun-C Trojan. When run, this infection will disable antivirus programs running on your computer. Please note that the rundll32.ex ... Read More
userinit winmain.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Delf.cns malware.
UserLogon winlogon.exe
X
Added by the W32/VB-DYF worm. This infection should not be confused with the legitmate C:\Windows\System32\winlogon.exe. ... Read More
Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter WLANUTL.exe
U
Generic wireless configuration utility used by many wireless brands.
ValueWin Wink2sk7.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
vbe win.vbe
X
Added by the Bat/LoseSlp-A worm.
vbwq cute winnt.exe
X
Added by the W32.Madag.A worm. W32.Madag.A is a worm that spreads by copying itself to removable storage devices and infects .doc files. ... Read More
Version3 winviews32.dll
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Video winamp32.exe
X
Added by the AGOBOT-NG WORM!
Video Camera Frog wcamfrog.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Video Proces winaps.exe
X
Added by the AGOBOT.HD WORM!
Video Process wincrt32.exe
X
Added by the W32/Agobot-GR WORM/IRC Backdoor. File is found in the Windows system folder. ... Read More
Video Process winasp.exe
X
Added by the AGOBOT-IS WORM!
virtual winit.exe
X
Added by the MUGLY.A or MUGLY.B WORMS!
virtual winprotect.exe
X
Added by the MUGLY.C WORM!
virtual wini.exe
X
Added by the W32/Rbot-YX WORM/IRC backdoor Trojan!
virtual-ie winlogi.exe
X
Malware - detected by Kaspersky antivirus as Trojan-Dropper.Win32.WinAD.h ... Read More
virtual-machine winlogin.exe
X
Added by W32/Rbot-VU
vsample winxpsock.exe
X
Added by the SDBOT.BLK WORM! ... Read More
w0rmname.exe w0rmname.exe
X
Added by the W32/Woned-C worm.
w32 w32.exe
X
Added by the SOKEVEN TROJAN!
W32 Sercure Service wsecur3.exe
X
Added by the W32/Sdbot-DAR worm and IRC backdoor. This infection utilizes the rdriv.sys rootkit to hide itself. ... Read More
w32 Wayang w32 Wayang.exe
X
Added by the W32.Yadurna.A worm. The user is presented with a password recovery dialogue once the malicious program is downloaded. ... Read More
w32pluginsdownloaderxmlhttpselfclearing7520 wiper.exe
X
Added by the Troj/Proxyser-M ... Read More
W32PT W32PT.dll.vbs
X
Identified by Kaspersky as a variant of the Worm.VBS.Solow.a worm.
w32s win442.dll
X
A variant of the Backdoor.Win32.IRCBot.bam family of worms and IRC backdoor Trojans. ... Read More
w32sup w32sup.exe
X
Adult content dialler
W32SYS w32sys.exe
X
Added by the W32/Jambu-A worm. W32/Jambu-A is a mass mailer for the Windows platform that also targets peer-to-peer file sharing networks and local sh ... Read More
W32Tc WTC32.scr
X
Added by the VOTE.D or VOTE.K WORMS!
w32tcomr w32tcomr.dll
X
Added by the WORM_STRATION.RE worm.
W32Time w32t.dll
X
Added by the Backdoor.Fuwudoor backdoor.
W32Time w32time.exe
X
Added by the Troj/Bckdr-HLO backdoor Trojan. If there is another service called W32Time it will replace it. ... Read More
w4y4n9 w4y4n9.exe
X
Added by the W32.Yadurna.A worm. The user is presented with a password recovery dialogue once the malicious program is downloaded. ... Read More
W75P2PSERVER W75P2PS.EXE
Y
Printer utility which is required in order to make the printer work correctly
w7zip w7zip.exe
X
Added by the Troj/Bancban-PX online banking information stealing Trojan. If you are infected with this, you should contact your banks and change any ... Read More
W815DM W815DM.exe
?
??
w98Eject w98Eject.exe
?
Related to USB support for Sigmatel MP3 audio decoder -what does it do, and is it required? ... Read More
wab.exe wab.exe
X
A variant of the SDBot.bhk family of worms and IRC backdoor Trojans.
wait4ip wait4IP.exe
U
Packard Bell net2Plug allows you to network PCs anywhere in your house ... Read More
WakeMeUp! Service WMUSvc.exe
U
Added by the WakeMeUp! alarm clock.
Wakoopa Wakoopa.exe
N
Wakoopa is a new social network that, when using this software, tracks what software and games you use on your computer. This information will then b ... Read More
wallchgr.exe wstart Wallchgr.exe
U
Blue Tree Software ... Read More
wallpaperchanger Wallpaper.exe
U
A wallpaper changer and manager utility. There is the Freeware version and the Pro version. The freeware version is completely free. The Pro version i ... Read More
Wanadoo Messenger.exe Wanadoo Messenger.exe
N
Wanadoo ISP instant messenger client
wanman.exe wanman.exe
X
A variant of the Win32/Rbot.HDO family of worms and IRC backdoor Trojans.
WanMPSvc WanMPSvc.exe
Y
An AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling ... Read More
WAPI wts**.exe [* = random char]
X
PurityScan/Clickspring adware
Wapp Wapp.exe
X
Added by the Troj/Banker-EIK information-stealing Trojan for online banks. If you are infected with this file you should immediately change your onli ... Read More
war ftpd tray icon wartray.exe
N
War-ftpd - FTP server
war-ftpd.exe WAR-FTPD.EXE
N
War FTP Daemon from JGAA's Internet - FTP client
WareOut WareOut.exe
X
Malware masquerading as a spyware and dialer remover, see here
warez warez.exe
N
Warez P2P client
Warner warner.exe
U
Also known as "CyberWarner". From G-Tek Technologies and pre-installed on some Packard Bell PCs. Protects critical files ... Read More
Warnet warnet.exe
U
Warnet - system cleanup software
WarReg_PopUp WarReg_PopUp.exe
N
Displays a popup asking you to register your Acert product.
WARSVR war-ftpd.exe
N
"War FTP Daemon - the original free FTP server for windows"
wartamll wartamll.dll
X
Added by a variant of the Haxdoor Trojan family. This infection utilizes the wartamd.sys rootkit to hide itself. ... Read More
was7cw was7cw.exe
X
Added by the rogue anti-spyware program WinAntiSpyware.
wasfsd wasfsd.sys
X
Trojan that create fake alerts and popups advertising rogue anti-spyware program. Though the guide below is not for this particular infection, it wil ... Read More
Washer washer.exe
U
Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Pr ... Read More
Washerie.exe washerie.exe
N
Cookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer, specific for cleaning the IE cache and cookies. Available ... Read More
washindex washidx.exe
U
Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Pr ... Read More
Wast wast.exe
X
Grokster ads updater
wast wast2.exe
X
Grokster ads updater
Watch watch.exe
N
Found to be used by a Trust USB scanner for auto starting the scanning software when the lid is lifted ... Read More
Watch Dog Program watchdog.exe
N
For Compaq PC's. Associated with Compaq's internet services. Not required if you don't use services provided by them and may not be required even if y ... Read More
Watchdog Watchdog.exe
N
Definitely part of the Mustek scanner drivers and software (for 600 III EP Plus and maybe others), launches from the Startup folder in the Start Menu, ... Read More
WatchDog watchdog.exe
?
Part of Motorola "Mobile Phone Tools" v3 - in a "Mobiile Phone Tools" sub-directory of Program Files ... Read More
WATCHPNP_Samsung watchPnp.exe
U
Printer software used by Samsung printers.
WATCHPNP_Xerox watchPnp.exe
U
Printer software used by Xerox printers.
waults waults.exe
X
Added by the Backdoor.Bifrose.L backdoor.
waumgr waumgr.exe
X
A variant of the W32/Sdbot.BNM family of worms and IRC backdoor Trojans.
WaveTop Launcher WaveTop.exe
N
WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in ... Read More
WAWifiMessage WiFiMsg.exe
?
Wireless utility bundled with HP laptops. Anyone know if this is required?
waxw2k waxw2k.dll
X
A variant of the Troj/Haxdor-Fam Trojan.
Wbcmgr wbcmgr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wbiff Wbiff.exe
N
Wbiff! E-mail checker - automatically checks your e-mail and notifies you if any new e-mail has been received ... Read More
wbqxfpgl wbqxfpgl.dll
X
Added by the VAC, or Trojan.Win32.Vapsup.kfp Trojan.
wbsecsvc wbsecsvc.exe
?
Winbond Seurity Support Service related to Winbond Wireless LAN Adapters.
Wbutton Wbutton.exe
?
Related to the Wacom Penabled driver on Acer Tablet PCs. Appears to do nothing so is it required? ... Read More
WCESCOMM WCESCOMM.EXE
N
Active sync for use with Windows CE based palm PC
WCESMngr WCEMNGR.EXE
X
The W32/Agobot-QX WORM/backdoor Trojan adds this, modifying the HOSTS file and terminating security-related/anti-virus processes also. ... Read More
wcmdmgr wcmdmgrl.exe
U
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note th ... Read More
wcmdmgr.exe wcmdmgr.exe
N
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note th ... Read More
wcmdmgrl wcmdmgrl.exe
U
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note th ... Read More
WCPC wintsvcc.exe
?
??
WCPI wintsvit.exe
X
PurityScan/Clickspring adware
WCPS Wint**.exe [* = random char]
X
PurityScan/Clickspring adware
WCPT wintsvtr.exe
X
PurityScan/Clickspring adware
wcsys wcsys.exe
X
Added by the Troj/Keylog-AP keylogging Trojan.
WD Button Manager WDBtnMgr.exe
U
Button manager installed with a western digital external disk drive. Allows you to back up your system with one click ... Read More
Wdc Wdc.exe
U
Added by the Spyware.Watchdog surveillance software. Spyware.WatchDog is a spyware program that logs keystrokes. It monitors Instant Messenger convers ... Read More
wdcs wdcs.exe
X
A variant of the W32/SDBot.AWGW family of worms and IRC backdoor Trojans.
wdfmgr.exe wdfmgr.exe
X
A variant of the Backdoor.Win32.SdBot.bti family of worms and IRC backdoor Trojans. ... Read More
wdfmgr32 wdfmfr32.exe
X
Added by the Troj/Pindow-A downloader Trojan.
wdfmgr32 wdfmgr32.exe
X
Added by the Troj/Dloadr-AOT Trojan.
WDInfo wdinfo.exe
X
Adult content dialler
wdmcert winsdrv.exe
X
Added by the Troj/Dloadr-AKP Trojan.
wdmon wdmon.exe
X
Added by the Infostealer.Ldpinch Trojan. Infostealer.Ldpinch is a password-stealing Trojan horse that attempts to steal information from an infected c ... Read More
WDNS SYSTEM wdns33.exe
X
Added by the W32/Mytob-BY worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
wdpoefan wdpoefan.dll
X
Identified as a variant of the Adware.Agent malware.
wdskctl wdskctl.exe
X
IEPlugin spyware
wdwctrl wdwctrl.exe
X
Added by the DLUCA.E TROJAN!
WEATHER WEATHER.EXE
N
Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs ... Read More
WeatherCast Weather.exe
N
Weather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight ... Read More
WeatherEye WeatherEye.exe
N
The Weather Network's taskbar weather monitoring software.
WeatherOnTray WeatherOnTray.exe
X
Hotbar's Weather Forecast tool for your desktop - adware
weatherscope Weatherscope.exe
X
WeatherScope software - bundles Gain/Gator adware ... Read More
WeatherWatcher ww.exe
N
WeatherWatcher - weather reporting in the System Tray
Web Live Information Messenger webmsn.exe
X
Added by the W32/Sdbot-CWA worm and IRC backdoor.
Web Management Service WMSvc.exe
U
Allows you to manage Microsoft Internet Information Services (IIS) via the web.
Web Service [random filename]
X
Added by the Trojan.Admincash infection!
web2pop Web2Pop.exe
U
Web2Pop allows you to retrieve your web-based accounts messages to read them in your favorite e-mail client. ... Read More
web3trap web3trap.exe
Y
PC-Cillin 2000 anti-virus software -> ActiveX filter. Guards against malicious ActiveX programs, etc  ... Read More
webalize webalize.exe
X
Searchcentrix hijacker
WebArmyKnife WAK.exe
N
Web Army Knife - a suite of web site developer's tools
webassist webassist.exe
X
Adware popup generator
WebBuying Webbuying.exe
X
Added by the Adware.Webbuy adware. Adware.Webbuy is a Browser Helper Object that displays advertisements. ... Read More
webcam webcam.exe
X
Added by the Troj/Monad-A backdoor Trojan.
Webcam Go Sti Service Application wbcgosvc.exe
?
Control software for the portable Creative Video Blaster Webcam Go digital camera/PC web cam. What does it do and is it required? ... Read More
WebcamRT.exe WEBCAMRT.exe
N
For Logitech Web Cams. Not required - camera works fine without it
Webcelerator webcel.exe
X
Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if yo ... Read More
WebCheck WebCheck.pif
X
Added by the CONE.C or CONE.F WORMS!
WebCpr0 WebCpr0.exe
X
Web_CPR/TopMoxie adware
Webdav.exe webdav.exe
X
IRC DDoS bot which gives the hacker full control over your system
WebHancer Agent whagent.exe
X
System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find ... Read More
webHancer Survey Companion whSurvey.exe
X
WebHancer foistware - traffic measurement service that uses a client agent that is stealth installed on user machines, gathering detailed data about s ... Read More
WebInstall WebInstall.exe
X
ClipGenie adware downloader
WebInstall2 WebInstall.exe
X
ClipGenie adware downloader
WebKey WebKey.exe
N
WebKey from JB Utilities. Utility to keep track of login data required when browsing the internet ... Read More
weblink WebLink.exe
N
Softex WebLink is a "cost-effective way to provide software updates, technical support or new product information to specific end-users - it can sile ... Read More
Webposition Gold 2 wpsche~1.exe
N
Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines ... Read More
WebPrint webprint.exe
X
Added by the Troj/Bckdr-QHH backdoor Trojan.
WebRebates0 WebRebates0.exe
X
WebRebates adware
Webroot Client Service WRConsumerService.exe
Y
Related to Webroot's Spy Sweeper.
Webroot Desktop Firewall WDF.exe
Y
The Webroot Desktop Firewall.
Webroot Desktop Firewall network service wdfsvc.exe
Y
Related to the Webroot Desktop Firewall.
Webroot Spy Sweeper Engine WRSSSDK.exe
Y
Webroot Spysweeper's realtime scanning engine.
websaverlive websaverlive.exe
U
WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your ... Read More
WebSavingsfromEbates WebSavingsfromEbatesrun.exe
X
Web Savings From Ebates Software, a shopping tool that opens pop-up windows
WebSavingsFromEbates0 WebSavingsFromEbates0.exe
X
Web Savings From Ebates Software, a shopping tool that opens pop-up windows
WebScanX WebScanX.exe
Y
From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guar ... Read More
websearch wjview ...websearch.exe
X
"Web Savings" From Ebates Software, a shopping tool that opens pop-up windows
WebSecureAlert WebSecureAlert.exe
X
WebSecureAlert. "Can help protect your browser security and privacy". However, it's by GAIN Publishing, and will display pop up ads on your computer s ... Read More
WebShell webshell.dll
X
Added by the Backdoor.Bebshell Trojan horse with backdoor capabilities.
Webshots Webshots Tray.exe
N
Screensaver program that automatically downloads from the webshots web site
Webshots websho~1.exe
N
Screensaver program that automatically downloads from the webshots web site
Website Administrator Info webadmin.exe
X
W32/Forbot-FY will connect to an IRC server and establish a new service named "Connection Reset", with the display name "Website Administrator Info". ... Read More
WebSpyShield WebSpyShield.exe
X
Added by the WebSpyShield rogue security software. WebSpyShield is a misleading application that may give exaggerated reports of threats on the comput ... Read More
websrvx websrvx.exe
X
Added by the WORM_KOOBFACE.EY worm.
WebTime WebTime.exe
X
Added by the Troj/SleepSrv-A Trojan.
WebTime WebTime.exe
N
Added by the WebTime time synchronization program. WebTime 2000 is a small utility program that will synchronize your PC's internal clock with one of ... Read More
Webtrap webtrap.exe
Y
Part of PC-Cillin anti-virus software. Checks web-sites for malicious Java and ActiveX elements in a similar way to McAfee WebScanX. A few users find ... Read More
WebTrapNT.exe WebTrapNT.exe
Y
Part of PC-Cillin Anti-Virus software. Checks visited web-sites for malicious Java and ActiveX elements ... Read More
WebWasher wwasher.exe
U
Free Pop-up/ad/javascript filter program from Siemens. If not running then browsers will not be protected but will still work. Available via Start -> ... Read More
webwork webwork.dll
X
Added by the Webwork downloader/updater DLL which is known to download and install advertising software. The adware applications Boran and Yokgug may ... Read More
weirdontheweb WeirdOnTheWeb.exe
X
Added by the Adware.WeirdOnTheWeb ... Read More
Welcome Welcome.exe
N
Launches the Welcome to Windows tutorial on boot up
wemwpxpjdb wemwpxpjdb.exe
X
Added by the Troj/Agent-GQB Trojan.
WEP Manager for NT webpmgr.exe
X
Added by the WORM_QQPASS.A worm.
WEPstat Wepstat.exe
?
Cisco Aironet 340 Series PC Card driver. If it can be started manually it shouldn't be required if you don't use the PC card facility regularily - hen ... Read More
werasqlp werasqlp.cur
X
Added by the Backdoor.Rustock backdoor rootkit.
wesumu wiustv.exe
X
Added by the Troj/QQPass- Trojan.
wetkadmr wetkadmr.dll
X
Identified as a variant of the Adware.Agent malware.
WetSock wetsock.exe
N
RoboMagic Wetsock - weather reporting in the System Tray
wfexqnrp wfexqnrp.dll
X
Identified as a variant of the VideoAccessCodec adware.
WFGStartup WFGStartup.exe
N
World Weather. "This midlet displays the current weather conditions for major cities around the world. This version is for memory limited mobile phone ... Read More
WFXCTL32.EXE WFXCTL32.EXE
N
From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displa ... Read More
wfxsnt40 wfxsnt40.exe
Y
WinFax 10.0 and maybe earlier versions. The program that opens the port for WinFax and not normally in the start menu. Needed if you want to run WinFa ... Read More
WFXSwtch WFXSWTCH.exe
U
Related to WinFax. Allows you to use Winfax as a virtual printer so that you can print directly to the application. ... Read More
WG511WLU WG511WLU.exe
Y
Netgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card ... Read More
WgaLogon WgaLogon.dll
Y
This file is a legitimate Windows oeprating system file. It used as part of Windows Genuine Advantage and alerts when you are using an unvalidated Mi ... Read More
wgeax wgeax.exe
X
Added by the W32/IRCBot-TM worm and IRC backdoor.
wgs3 wgs3.exe
X
Added by the Troj/LegMir-AQH password-stealing Trojan.
WGWLocalManager WGWLocalManager.exe
U
Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performan ... Read More
whagent whagent.exe
X
System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find ... Read More
WhatPulse WhatPulse.exe
U
WhatPulse sends statistics on how much you type on your computer and ranks you based on that. It does not log your keystrokes, but only the counts of ... Read More
WhenUSearchWHSE whse.exe
X
SaveNow adware
Whistler whismng.exe
X
Added by the Troj/Whistler-F. It also creates a file at C:WXP to copy over other files and deletes files. ... Read More
Whitman Software whitsoft.exe
X
Added by the W32/Rbot-AUB worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Whvlxd Whvlxd.exe
X
Added by the W32.LXD.MIRC TROJAN!
widuxngq widuxngq.sys
X
Added by the Backdoor.Rustock backdoor rootkit.
wifeman wifeman.exe
X
Unidentified malware
Wifi Boot wifiboot.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Booter wifibooter.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Configuration wificonfig.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Configuration! wificonfigs.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Connection wificon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Connection! wificonnect.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Debug wifidebug.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Loader wifiload.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Loader! wifiloader.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Setup wifisetup.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WildFlics WildFlics.exe
X
Added by the Dial/Direct-B premium rate dialer.
WildTangent Web Driver updater wcmdmgrl.exe
U
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note th ... Read More
Wildwire Monitor WWMon.exe
N
This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem ... Read More
Willow Road WillowRoad.exe
N
Willow Road Screen Saver
WIN windows.exe
X
Added by the W32/Lebreat-B worm.
Win windata.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
win winupdt.exe
X
Identified as a variant of the BKDR_SMALL.GSJ malware.
win aggior winupdt.exe
X
Identified as a variant of the BKDR_SMALL.GSJ malware.
win aggiornamento winupdt.exe
X
Identified as a variant of the BKDR_SMALL.GSJ malware.
Win Antivir 2008 Win Antivir 2008.exe
X
Added by the Win Antiv 2008 rogue antivirus program.
Win Antivirus 2008 Win Antivirus 2008.exe
X
Added by the Win Antivirus 2008 rogue antivirus program.
Win Chimes winchi~1.exe
U
WinChimes - enhancement software for the system clock that runs in the system tray ... Read More
Win Comm WinComm.exe
X
WebRebates related adware
Win Config winconfig.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Win Critical File win.exe
X
A variant of the W32/IRCbot.BGA.worm family of worms and IRC backdoor Trojans.
win ctl app wuctl.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Win Defrag windfrag.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Win Defrag! windefrag.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Win FTP wintftp.exe
X
Added by the W32/Sdbot-KA worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
WIN HOST PROCESS WIN HOST PROCESS.EXE
X
Added by the KEYLOGGER.CLONE TROJAN!
WIN ID SYS64 w3264.exe
X
Added by the W32/Mytob-BO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Win l5oahder winampa.exe
X
Added by the SPYBOTER.GEN VIRUS! Not the valid Winamp Agent which uses the same filename. This resides in the System32 sub-folder wheras real one is l ... Read More
Win Login winlogin.exe
X
Added by the W32/Rbot-AWE worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. Please do not con ... Read More
Win Manager winmanager.sys
X
Added by the Troj/Bancos-BEQ Trojan.
Win Microsoft 98 win14.exe
X
Added by the W32/Rbot-AKX worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
win microsoft config wnmsconfig.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Win Security winsecure.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Win Server winserv.exe
X
Added by the IMISERV.A TROJAN!
Win Server Updt wupdt.exe
X
Added by the IMISERV.A TROJAN!
win server updt winserver.exe
X
Added by a variant of the WIN32.IMISERV TROJAN! ... Read More
Win Tasks 32 wintasks32.exe
X
Added by the W32/Rbot-FPD worm and IRC backdoor.

W32/Rbot-FPD spreads:

- to other network computers infected with: W32/M ... Read More
Win Tmp Service wstmp.exe
X
Added by the W32/SdBot-YS. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
win update wupda32.exe
X
Added by the SDBOT.J WORM!
win update wupdate.exe
X
Added by the W32/Rbot-P worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
win update wapdate.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
win updater WINUPDATER.EXE
X
Added by the RBOT.IP WORM! ... Read More
win winamp winamp.exe
X
Added by the RBOT.AGF WORM! NOTE - this is NOT the Winamp Media Player executable (WinAmpa.exe) ... Read More
win***32 win***32.dll
X
Added by the Trojan.Nebuler Trojan. Trojan.Nebuler is a Trojan horse that attempts to download and execute files from remote sites. It also sends info ... Read More
WIN-BUGSFIX WIN-BUGSFIX.EXE
X
Added by the LOVELETTER (I LOVE YOU) VIRUS!
win-update wiupdat.exe
X
Added by the W32/Sdbot-QPworm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
win-xp winis.exe
X
Added by the W32/Rbot-BBD WORM! Found in the Windows system folder.
win16.dll win16dll.exe
U
Screenspy captures screenshots silently. If you didn't install this yourself, remove it. ... Read More
win23.exe win23.exe
X
A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote serv ... Read More
win24 win24.exe
X
Added by the WORM_KIDALA.A network worm.
WIN32 WIN32.EXE
X
Added by the RATEGA TROJAN!
Win32 Win32.exe
X
Added by the ISRAZ.A and the W32/Mytob-AB WORMS!
win32 winsrv32.exe
X
Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites ... Read More
win32 WinSetup.exe
X
Added by the EVILBOT.B TROJAN!
win32 winhost.exe
X
Added by the Bropia.F worm.
win32 w32word.exe
X
Added by the Trojan.Gared Trojan that overwrites or deletes Word documents.
Win32 wveygxi.exe
X
Added by the W32/Rbot-FYK worm and IRC backdoor.
Win32 winnnit.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Win32 Bios Winbios.exe
X
Added by the W32/Semapi-A. This mass-mailing worm may display a message: "Unable to locate 'semapi.dll' reinstalling this application may fix this ... Read More
Win32 Critical File Win32.exe
X
Added by the W32/Rbot-GUB worm and IRC backdoor.
win32 debug manager Win32Debug.exe
X
Added by a variant of the W32/WOOTBOT WORM! ... Read More
Win32 Device Loader Win32ldr.exe
X
Added by a variant of the AGOBOT/GAOBOT WORM!
Win32 Drivers winlogons.exe
X
Added by the W32/Forbot-FG worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Win32 DRK Driver wdrk32.exe
X
Added by the WOOTBOT.CY WORM!
Win32 exe file winstr32.exe
X
Added by a variant of the SPYBOT WORM!
win32 firewall driver winfw.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Win32 Help32 Service win32help.exe
X
Added by the W32/Delbot-U worm and IRC backdoor.
Win32 Info windowsnfo.exe
X
A variant of the W32/Spybot.SLI family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
win32 internet server winserver.exe
X
Added by the Troj/Dermon-D Trojan.
Win32 Kernel Update win32update.exe
X
Added by the Troj/Proxy-BS backdoor Trojan.
Win32 Kernel Update win32host.exe
X
Added by the W32/Tilebot-FE worm and IRC backdoor.
Win32 Servermgr12345 winimgr.exe
X
Added by the W32/Tiotua-M worm.
Win32 service WIN32SVC.EXE
X
Added by the Backdoor.Selka backdoor.
Win32 Services wuamngr.exe
X
Added by the W32/Sdbot-N worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Win32 Services Config winwkys.exe
X
Added by a new Rbot worm variant.
Win32 Services1 wuamngr1.exe
X
Added by the SDBOT-PV WORM!
Win32 Services1 wuamngr1.exe.exe
X
Added by the Backdoor.Sdbot.AN Backdoor! Found in the Windows system directory. ... Read More
win32 socket win325b.exe
X
Added by the W32/Tilebot-GE worm and IRC backdoor.
Win32 Src Service win32src.exe
X
Added by the RBOT-SX WORM!
Win32 SSL Driver winssv.exe
X
Added by the FORBOT-BH WORM!
win32 system server winserver.exe
X
Added by an unidentified WORM or TROJAN!
Win32 USB Driver winxpinit.exe
X
Added by the SDBOT.AA TROJAN!
win32 usb2 wins32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Win32 USB2 Driver win32usb.exe
X
Added by the SPYBOT.DHV WORM!
Win32 USB2 Driver wind32.exe
X
Added by the FORBOT-AH WORM!
Win32 USB2 Driver winupdate.exe
X
Added by the AGOBOT.YE WORM!
Win32 USB2 Driver winsnd32.exe
X
Added by a variant of the SDBOT WORM!
Win32 USB2.0 Driver w32usb2.exe
X
Added by the SPYBOT.DN WORM!
win32 usb3 driver win32tool.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Win32 Wmls Driver winitr32.exe
X
Added by the WOOTBOT.B WORM!
win32.exe win32.exe
X
Added by the STARTPAGE TROJAN!
win32app Winpup32.exe
X
Added by the Troj/AdClick-N Trojan! File is found in the Windows system folder. ... Read More
Win32BaseServiceMOD Wintask.exe
X
Added by the NAVIDAD WORM!
win32beta win32sys4.exe
X
Added by the Troj/Banker-DA password-stealing trojan for Brazilian banks.
win32clf win32clf.exe
X
Added by an unidentified VIRUS, WORM or TROJAN!
win32client win32client.exe
X
Added by the Troj/Restarter trojan.
win32debug win32debug.exe
X
Added by the W32.Gudeb worm.
Win32DLL Win32DLL.vbs
X
Added by the LOVELETTER (I LOVE YOU) VIRUS!
Win32dll Win32dll.exe
X
Added by the BANPAES TROJAN!
win32gb win32gb.exe
X
All-In-One-Telcom (adult content dialler) variant
Win32Host Process webemir.exe
X
Added by the Troj/Turgen-A password-stealing trojan.
win32info win32info.exe
X
Adult content dialler
win32napp win32napp.exe
X
Added by the W32/Smelles-A virus.
Win32reg.dll Wind32reg.dll.exe
X
Added by the W32/Rackum-A worm/keylogger. This infection attempts to delete the regedit.exe file and logs keystrokes in the Winsck32.sys.Txt file. ... Read More
WIN32SL Win32sl.exe
Y
Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the ... Read More
Win32Sr win32ssr.exe
X
Added by the W32/Sdbot-AOT worm and IRC backdoor.
Win32System win32s.exe
X
Added by the MYDOOM.V WORM!
win32us win32us.exe
X
All-In-One-Telcom (adult content dialler) variant
Win32Usr WinCab.exe
X
Added by the W32/Dedmir-A worm.
win32_i lptt01 win32_i.exe
X
Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use Rapi ... Read More
win32_i ml097e win32_i.exe
X
Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use Rapi ... Read More
Win386 Win386.exe
X
Added by the GOSUSUB VIRUS!
WIN3S2SNDS winabsmod.exe
X
Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" ... Read More
WIN3S2SNDS winiprtx.exe
X
Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" ... Read More
win98 dns wingrd.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
WinAble winable.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Adload.lv malware.
winacsr Winacsr.exe
U
AceScreenSpy keystroke logger/monitoring program - remove unless you installed it yourself! ... Read More
winactive WINACTIVE.EXE
X
Active variant of LOP.com hijacker - see here
WinActiveJ WinActiveJ.exe
X
Added by the ROTARRAN VIRUS!
Winad Client Winad.exe
X
WinAd adware by eXact Advertising
WinAdCnt.exe WinAdCnt.exe
X
Added by Troj/Banker-BU to compromise online banking sites.
WinAdCnt16.exe WinAdCnt16.exe
X
Added by the Troj/Banker-AT TROJAN!
winadm winadm.exe
X
Browser hijacker - redirecting to Search-World.net. Related to the SMALL.LR TROJAN! ... Read More
winafg32 winafg32.dll
X
Added by the Troj/Nebuler-G Trojan.
winagent WinAgent.exe
?
Standard Life Insurance program. Note: This file is legitimate. It is not known if it needs to run at startup. ... Read More
Winahlp.exe Winahlp.exe
X
Added by a variant of the VAGRNOCKER TROJAN!
winallap winallap.exe
X
Added by the DELF.E TROJAN!
winallapu winallapu.exe
X
Added by the DELF.E TROJAN!
Winamp winamp.hta
X
Hijacker - re-directing to adult content sites. Note - this isn't the real Winamp ... Read More
Winamp winamp.exe
X
Added by the AGOBOT-MC WORM! Note - this is NOT the Winamp Media Player (WinAmpa.exe) ... Read More
WinAMP winamp62.exe
X
Added by the W32/Sdbot-WN WORM/IRC backdoor Trojan!
Winamp Agent winamp.exe
X
Added by the W32/Poebot-I WORM! This file is found in the Windows system folder. ... Read More
WinAmp Agent Full wina.exe
X
Identified by Kaspersky Anti-Virus as Trojan-Downloader.Win32.Banload.bfb. If you are infected with this file you should immediately change all of yo ... Read More
Winamp media player winapa.exe
X
Added by an unidentified VIRUS, WORM or TROJAN!
Winamp Media Player winaamp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Winamp Media Player winamap.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Winamp Media Player winamp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WinAmp Player winampp.exe
X
Added by the W32/Rbot-AQI worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Winamp Player 6 Winamp6.exe
X
A variant of the W32.Spybot.Worm family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
winamp to google talk winamptogoogletalk.exe
U
Winamp to Google Talk, available here shows your current Winamp track in your Google_Talk status ... Read More
Winampa WINAMPa.exe
U
Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take ... Read More
Winampa winampa.exe
X
Added by the AGOBOT-GS WORM!
Winampa Agent WINAMPA.EXE
X
Added by the SPYBOT-BR WORM! Note - this is NOT the Winamp Media Player
WinampAgent WINAMPa.exe
U
Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take ... Read More
WinAmpAgent winagent.exe
X
Added by the Win32.Tactslay backdoor Trojan.
WinampPlugin winampa.exe
X
Added by the W32/Sdbot-CNF worm and IRC backdoor.
winantispyware 2005 was5.exe
X
WinAntiSpyware: MALWARE, posing as a spyware remover - for more information, search the Spywarewarrior_List of non-Recommended anti parasite sit ... Read More
WinAntiSpyware 2007 was7.exe
X
Added by the rogue anti-spyware program WinAntiSpyware.
WinAntispyware2008 WinAntispyware2008.exe
X
Added by the WinAntispyware2008 rogue anti-spyware program.
WinAntiVirus Pro 2007 WinAV.exe
X
Startup program associated with WinAntiVirus Pro 2007. WinAntiVirus Pro 2007 is a rogue anti-spyware program that displays fake alerts, and downloads ... Read More
WinAntiVirusPro2006 WinAV.exe
X
Part of WinAntivirus Pro. This program is fake, stealth installed, and bundled with other malware. It is also on the Rogue anti-spyware list. ... Read More
WinApi winapix.exe
X
Added by a variant of the TIBSER.A downloader TROJAN!
WINAPLOGUPD WINAPLOGUPD.EXE
X
Added by the W32/Capside-C WORM, which exploits typical P2P program folders, and spreads via IRC clients and through netwerk shares. ... Read More
Winapp winpup32.exe
X
Produces popup ads to adult content sites
Winapp32.exe Winapp32.exe
X
Added by the Backdoor.GF.13 backdoor trojan!
WinAuth winlogon.exe
X
Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the valid winlogon.exe process ... Read More
WinAVX WinAvX.exe
X
Malware related to and installed with the rogue anti-spyware program called WinAntiSpyware 2006 or WinAntiSpyware 2007. This Trojan is responsible for ... Read More
WinAVX WinAvXX.exe
X
Malware related to and installed with different rogue anti-spyware programs including WinAntiSpyware 2006 or WinAntiSpyware 2007. This Trojan is respo ... Read More
WinAwk WinAwk.exe
X
Added by the W32/Sdbot-AYF worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
winazs32 winazs32.dll
X
Identified as a variant of the Trojan.Win32.Dialer.qn dialer.
WinBackup Scheduler Wbsched.exe
U
LIUtilities WinBackup scheduler - backup software
WinBar WinBar.exe
U
"WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls" ... Read More
winbas12 winbas12.exe
X
Adware, probably CoolWebSearch parasite related - recognized by Kaspersky antivirus as TrojanDownloader.Win32.VB.du ... Read More
winbeans winbeans.exe
X
Added by the W32/Sdbot-BZB worm and IRC backdoor.
Winbed winbed.exe
X
Hijacker
winbfi32 winbfi32.dll
X
Identified as a variant of the Trojan.Win32.Agent.qt Trojan.
winbin32 win32exe.exe
X
Added by the W32/Rbot-ZL WORM/IRC backdoor!
winbjv32 winbjv32.dll
X
A variant of the Trojan.Win32.Agent.qt Trojan.
WinBlueSoft WinBlueSoft.exe
X
Added by the WinBlueSoft rogue anti-spyware program.
winbo32.exe winbo32.exe
X
Added by the W32/Rbot-GRU worm and IRC backdoor.
winboot winboot.exe
X
Added by the Troj/Banload-W Trojan.
Winbot winbot.exe
X
Added by the Troj/Midrug-A backdoor trojan.
winbug32 winbug32.dll
X
A variant of the Trojan.Win32.Agent.qt Trojan.
WinButler WinButler.exe
X
Identified as a variant of the Trojan-Dropper.Agent.DKN malware.
winbyq32 winbyq32.dll
X
Added by the Troj/Agent-DMC Trojan.
Wincbr.exe Wincbr.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
Wincfg.exe Wincfg.exe
X
Added by Backdoor.Elitem.
WinCfg32 WinCfg32.exe
X
Added by the W32/Ronoper-A worm/backdoor trojan.
WinCheck WinCheck.exe
X
Added by the PWS-CY TROJAN!
winchk winchk.exe
U
Added by the Spyware.RemoteSpy surveillance software.
winchost winchost.exe
X
Added by the Troj/Dloader-PO downloader trojan.
WINCINEMAMGR WINCIN~1.EXE
N
WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs ... Read More
WinCinemaMgr WinCinemaMgr.exe
N
WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs ... Read More
winclean winclean.exe
X
Added by the Troj/Cimuz-BO spyware Trojan. Troj/Cimuz-BO may also steal information such as email account usernames and passwords, and create screensh ... Read More