Welcome Guest (Log In | Create Account)
New Member? Join for free.




A    B    C    D    E    F    G    H    I    J    K    L    M    N    O    P    Q    R    S    T    U    V    W    X    Y    Z    Other   
HJT: F0, F1, F2, F3 · O4 · O20 · O21 · O22 · O23
Rootkit List  · Submit a Startup  · Top Submitters
 Startup Index · Newest Entries · Mozilla Search Tools · WebMaster Site Tools · Status Key
Startup Database Forum · How to use the Startup Database

Enter the filename or keyword you would like to search for:
Advanced Search

Name Filename Status Description
!NoLoad winrecon.exe
N
WinRecon - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it ... Read More
(*)API Machine winSOCKS.exe
X
Homepage hijacker. (* = any digit)
(*)Run win32API.exe
X
Homepage hijacker. (* = any digit)
(04ED35B6-9A10-4EB3-9C1E-66B2CFA5AC77) windir32.dll
X
Added by the Troj/Lineage-JA Trojan.
(32A43994-9CDC-4633-A2F4-3152097D404D) winme32.dll
X
Added by the Troj/Lineage-MO password-stealing Trojan for the online game Lineage. ... Read More
(3B354F63-A696-424c-9E88-7F6BDFBA5CA5) winhosts.dll
X
Added by the Troj/Lineage-AH password-stealing Trojan for the online games Lineage. ... Read More
(44B40E3F-E91C-4ae3-89A6-1D1048A162A6) wintt1.dll
X
Added by the Troj/Lineage-KX password-stealing Trojan for the online game Lineage. ... Read More
(7B484C2F-AEE6-4e29-B894-EDEAA5DAF000) winunits.dll
X
Added by the Troj/Lineage-BN password-stealing Trojan for the online game Lineage. ... Read More
(default) winhelp.exe
X
Added by the BLACKMAL.C WORM!
(default) WINLOGON.EXE
X
Added by the Troj/Delf-LP information stealing Trojan.
(default) winligom.exe
X
Added by the W32/Rbot-GAI worm and IRC backdoor. W32/Rbot-GAI spreads to other network computers by exploiting common buffer overflow vulnerabilities, ... Read More
(default) winxp.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
(default) win32sys.exe
X
Identifed as the Sdbot.KIN worm and IRC backdoor.
(default) winmain.exe
X
Added by the Troj/LdPinch-RC Spyware Trojan.
*microsoft update wuytc.exe
X
Added by the STMU TROJAN!
*windows update wrauclt.exe
X
Added by the RBOT-QU WORM!
*windows update wuanclt.exe
X
Added by the RBOT-PG WORM!
*windows update wuaucrlt.exe
X
Added by the SPYBOT.HUR WORM!
*windows update wuraclt.exe
X
Added by the RBOT-PO WORM!
*windows update wuaruclt.exe
X
Added by W32/Rbot-TF. File is found in the Windows system directory.
*windows update wurauclt.exe
X
Added by the RBOT-SY WORM! This file runs in safe mode as well making it slightly harder to remove. ... Read More
*windows update wscxt.exe
X
Added by an unidentified WORM!
*windows update wkmst.exe
X
Added by the SDBOT.AVD WORM!
*windows update wuruclt.exe
X
Added by the W32/Rbot-TA WORM/IRC backdoor trojan!
*windows update wuacrlt.exe
X
Added by the W32/Rbot-QI worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
*windows update wruaclt.exe
X
Added by the W32/Rbot-QP worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
*windows update wruauclt.exe
X
Added by the W32/Rbot-SF worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
*windows update waurclt.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
*winstats winstats.exe
X
Added by the Trojan.Gargafx Trojan.
*wmstu wmstu.exe
X
Added by the W32/Rbot-TV worm. When started this infection connects to an IRC server where it waits for commands. This program starts in safe mode to ... Read More
*wuauclt.exe wxmct.exe
X
Added by an unidentified WORM or TROJAN!
*wuauclt.exe wmsvc.exe
X
Added by the W32/Rbot-UG network worm. When started this infection connects to an IRC server where it waits for remote commands to execute. ... Read More
,main drive Loader wininfo.exe
X
Suspected malware as it appears in 3 different registry locations - see here
.Prog winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! ... Read More
.service winlgon.exe
X
Added by the Troj/Bdoor-BX trojan backdoor.
0190 Warner WARN0190.EXE
X
Anti-dialer program (Germany)
0900 Warner WARN0900.EXE
X
Anti-dialer program (Germany)
1 winhp32.exe
X
Added by the Troj/Clckr-KY Trojan.
1 winx86.dll.js
X
Added by the JS/Uragon-A javascript worm.
123 wintask.exe
X
Added by the Troj/LegMir-AY password-stealing Trojan for the online game Legend of Mir. ... Read More
1Google Online Search Service winlugan.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Winlagons.ak malware.
1Google Online Search Service winlegal.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Winlagons.an malware.
1wincfg32 WebMailSpy.exe
X
Added by WebMailSpy SPYWARE! ... Read More
252 winmgr.exe
X
Added by the Troj/Mugger-A Trojan.
6435748 winupdates.exe
X
Identified as the Spybot.BMKF worm.
7G21B2J74A wisyst32.exe
X
Added by the Troj/Dloadr-BHE Trojan.
9m winlog0n.exe
X
Added by the Troj/LegMir-AQK password-stealing Trojan for the Legend of Mir.
<not used> win_ak.dll
X
Added by the Troj/Foghorn-A downloading Trojan.
<not used> winhe1p.exe
X
Added by the Troj/Agent-DFT Trojan.
<not used> winfkhide.dll
X
Added by the Backdoor.Ginwui.E rootkit.
<not used> WMISSHIM.DLL
X
Added by the WORM_STRAT.BT mass-mailing worm.
<not used> w3sskbda.dll
X
Added by the W32/Stration-AG worm.
<not used> wuaucll.exe
X
Added by the W32/SillyFDC-M worm.
<not used> winwork.exe
X
Added by the TSPY_WOWCRAFT.BL information stealing Trojan for the online game the World of Warcraft. ... Read More
<not used> winsys16_070307.dll
X
Added by the Troj/Hiphop-G data stealing Trojan.
<not used> wandrv.exe
X
Added by the Troj/Bckdr-QHR backdoor Trojan.
<not used> WinSit.exe
X
Added by the W32/CoiDung-A worm.
<not used> WINFBI32.dll
X
Added by the Backdoor.Ginwui.F backdoor. Backdoor.Ginwui.F is a Trojan horse that opens a back door and uses rootkit techniques to hide its presence. ... Read More
<not used> winsys16_061230.dll
X
Added by the WORM_AGENT.AFFZ worm. Please note that rundll32.exe is a legitimate program. ... Read More
<not used> wuaucl.exe
X
Added by the W32.Vapka.A worm. W32.Vapka.A is a worm that spreads by copying itself to removable media and steals confidential information. ... Read More
<not used> win32ipzip.dll
X
Added by the Trojan.Goldun Trojan.
<not used> WgaTrays.exe
X
Added by the W32.SillyDC worm.
<not used> wowfx.dll
X
Identified as a variant of the Win32/TrojanDownloader.Fakealert.G Trojan. This Trojan displays fake security alerts on your computer. ... Read More
<not used> wsnpoema.exe
X
Identified as a variant of the Troj/SpyAgent-H malware.
<not used> winlogon86.exe
X
Identified by BitDefender as a variant of the Gen:Trojan.Heur.PT.cqW@bCL2Eje malware. ... Read More
<not used> winlogon32.exe
X
Fake AV Trojan. When fixing this entry, please be careful. If you do not change the userinit key to point back to userinit.exe, then your computer wil ... Read More
<not used> winlogons.EXE
X
Added by the W32.SillyFDC.BDN worm.
<not used> watermark.exe
X
Added by the Troj/Zbot-ADH Trojan.
<Random Name> winview2.exe
X
Added by the W32/Jared-A worm.
<random name> winlogan.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Small.gdv malware.
<random name> winlogun.exe
X
Identified as a variant of the Trojan.Fakealert.ALU malware.
A New Windows Updater w32NTupdt.exe
X
added by the W32/Mytob-AG WORM, which has IRC channel backdoor trojan functionality. ... Read More
a-winpoet-service winpppoverethernet.exe
Y
WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem supp ... Read More
Access Control App winsto.exe
X
Identified as a variant of the Win32/TrojanDownloader.Small.CYF Trojan.
acecad.wtxpload Wtxpload.exe Acecad
Y
driver for an AceCad USB Graphics Tablet ... Read More
ActiveSync wcescom32.exe
X
Added by the Troj/MancSyn-E Trojan.
ad-aware-6 WINDOWSUPDATER.EXE
X
Added by an unidentified WORM or TROJAN!
AdAware wini.exe
X
Added by the W32/Rbot-XN WORM/IRC backdoor.
Additional Guard WI339.exe
X
Added by the Additional Guard rogue anti-spyware program.
AdobeReaderPro winslog.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
AdobeReaderPro winini.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
AdobeUpdate Wininet.exe
X
Added by the TROJ_DROPPER.WTH Trojan.
ADriver windrv.exe
X
Identified by Kaspersky Anti-Virus as Trojan-Clicker.Win32.Delf.fj.
Adsl Not-A-Virus winlogn.exe
X
Added by the W32/Rbot-GUU worm and IRC backdoor.
AFAFilter windefault.exe
U
AFAFilter - internet filter software
agony wininit.sys
X
Added by the NTRootKit-K rootkit.
AKEYNAME WinServ.exe
X
Added by the EVILBOT.C TROJAN!
AMP WinOFF winoff.exe
U
WinOFF is " a utility designed to shut down Windows computers automatically, with several working ways and fully configurable." ... Read More
AndromedaAvDriver winav.sys
X
Added by the Andromeda AntiVirus rogue anti-spyware program.
aniwzcs2service WZCSLDR2.exe
Y
ALPHA_Networks wireless driver ... Read More
ANIWZCSService WZCSLDR.exe
?
D-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity ... Read More
anti-virus update scheduler winsp3.exe
X
Malware - detected by Kaspersky antivirus as TrojanProxy.Agent.fp - A Proxy Trojan is a backdoor which allows a remote hacker to connect to other sys ... Read More
AntiVir winlog.exe
X
Added by the Troj/IRCBot-TJ Trojan.
Antivirus wav.exe
X
Added by the Windows Antivirus 2008 rogue anti-spyware program.
antivirusdll winmsgslive.exe
X
Added by the W32/Sdbot-CXQ worm and IRC backdoor.
APIMon winapix.exe
X
Added by a variant of the TIBSER.A downloader TROJAN!
Application Layer Gateway WeRecl.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Application Layer Service weRecv.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
AS00_WPN511 WPN511.exe
?
NetgearRev MFC Application - software for Netgear wireless network cards - what does it do and is it required in startup? ... Read More
ASC-AntiSpyware WinCleaner.exe
X
Added by the WinCleaner 2009 rogue anti-spyware program. WinCleaner 2009 displays false results and utilizes Trojans to promote itself. ... Read More
ASC-AntiSpyware WinAntivirus.exe
X
Added by the Win Antivirus Vista/XP rogue anti-spyware program.
ASP.NET State Service winupgrad.exe
X
Added by the Troj/Banload-AJ Trojan.
Asus Protocol Driver Control wingptd.exe
X
Identified as a variant of the Trojan.Rootkit.Gen malware.
atisrc2 windfind.exe
X
Adult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), mmxrun (msosa.exe) and RegCompres (REGCPM3 ... Read More
atisrc2 winfind.exe
X
Adult content dialler - see here . This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), mmxrun (msosa.exe) and RegCompres (REGCP ... Read More
Audio Device Manager windrivers.exe
X
A variant of the Backdoor.Win32.IRCBot.afc family of worms and IRC backdoor Trojans. ... Read More
Audio Device Manager winfp.exe
X
Added by the W32/IRCBot-XS worm.
Audio Device Manager WNDXP.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Audio Device Manager WinNT.exe
X
A variant of the Backdoor.IRCBot.USP family of worms and IRC backdoor Trojans.
auto win32.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Small.hpb malware.
Auto Updat WindowsSys32.exe
X
Added by a variant of the FORBOT WORM!
autoload windowsupdate.exe
X
Identified as a variant of the WORM_SOCKS.D malware.
Automatic Update Service wuapi.exe
X
Added by the W32/Codbot-AC worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Automatic Updates wupdmgr32x.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
Automatic Updates wupdmgr32.exe
X
Unknown worm and IRC backdoor variant.
automatic updates for Microsoft Windows wuauclt.exe
X
Added by the W32/Tilebot-JW network worm.
autorun winmain.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Delf.cns malware.
autoupdate WINUP2DATE.DLL,SHStart
X
Unidentified adware - detected by Panda antivirus as Trj/Clicker.CY ... Read More
AVP sub Winspss.exe
X
Added by the Troj/Dloadr-BDM Trojan.
AvpWx WErcx.exe
X
Identified by Kaspersky antivirus as a variant of the Backdoor.IRC.Agent.a malware. ... Read More
axel wam.exe
X
Added by the W32/Melo-E worm.
bayoneting wygomd.dll
X
Zlob Trojan which installs the Virus Protect 3.8 rogue anti-spyware program. This program displays fake security alerts stating that your computer ha ... Read More
blah service winupdate.exe
X
Added by the GAOBOT.BIA WORM!
blah service winsysengine.exe
X
Added by the RBOT-KI WORM!
Blah Service win32.exe
X
Added by the W32/Rbot-AXO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
blah service win32exec.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
blah service Windows.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
blah service windowsXT.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
blah service. widows.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
BLUETOOTH IPv4 service wnlogow.sys
X
Added by a variant of the Troj/Haxdor-Gen rootkit.
bob winuping.exe
X
Added by the Troj/Banload-IU Trojan.
BootsCfg wscript.exe C:\\WINDOWS\\Update\\Date.POP.vbs %
X
Added by the VBS.KUULLIO WORM!
BootsCfg wscript.exe C:\WINDOWS\User\All Users.vbs %
X
Added by the VBS.Spiltron@mm mass-mailing worm.
bootscfg wscript.exe[path] Install.log.vbs
X
Added by the VBS.YPSAN.E WORM! ... Read More
Bose Wave/PC Monitor wavepcmonitor.exe
N
System Tray access for this system (more info on the system here). Available via Start -> Programs ... Read More
BossIdea winlogin.exe
X
Added by the Troj/Lineage-I TROJAN!
Broadcom Wireless Manager UI WLTRAY.exe
U
Related to Broadcom_Network Adapters for additional configuration options for these devices. Should not be terminated unless suspected to be causing p ... Read More
Bron winxp.exe
X
Added by the W32.Phoney.A worm. W32.Phoney.A is a worm that spreads through mapped drives. It also lowers security settings on the compromised compute ... Read More
BuildLab winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! ... Read More
Bymer.Scanner Wininit.exe
X
Added by the W32.HLLW.Bymer worm! Please note that this infection should not be confused with the legitimate Windows file located at %System%\wininit. ... Read More
C:\Documents and Settings\All Users\Application Data\ADSL Software Limited\WinSpywareProtect\winspywareprotect.exe winspywareprotect.exe
X
Added by the WinSpywareProtect rogue anti-spyware program.
C:\Windows\System32\Windows Update wuaclt.exe
X
Added by the W32/VBWave-A worm.
C:\Windows\winnl.exe winnl.exe
X
Added by the Downloader.Kidkiti downloader Trojan. Downloader.Kidkiti is a Trojan horse that downloads files on to the compromised computer. ... Read More
C:\Windows\winnm.exe winnm.exe
X
Added by the Downloader.Kidkiti downloader Trojan. Downloader.Kidkiti is a Trojan horse that downloads files on to the compromised computer. ... Read More
calc microsoft windows wincalc.exe
X
Added by an unidentied WORM or TROJAN!
ccApp WMADZ.EXE
X
Added by the RBOT-LJ WORM!
ccApps winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! ... Read More
CCWinTray wintmr.exe
U
Added by the Child Control parental control software.
CDriver windrv.exe
X
Identified by Kaspersky Anti-Virus as Trojan-Clicker.Win32.Delf.fj.
CEPA wsot.exe
?
??
CFDStart WinMuschi.exe
X
WINMUSCHI dialler
Check for One Touch Update wiseupdt.exe
N
Checks for updates for Visioneer OneTouch scanners
ChicoSys webtmr.exe
U
Added by the Child Control parental control software.
Client agent for ARCserve W95AGENT.EXE
?
Part of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required? ... Read More
client update wup.exe
X
Added by a variant of the W32/OPANKI-A WORM! ... Read More
COM+ Windows System winsyscom.exe
X
Identified by Symantec as a variant of the Backdoor.Trojan malware.
CommonService winup.exe
X
Added by the Troj/Dloadr-BJJ Trojan.
Compaq Jes Drivers winjes.exe
X
Added by the W32/Sdbot-XR worm. When started this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Compaq Service Drivers winmsn.exe
X
Added by a variant of the W32/Sdbot WORM/IRC backdoor Trojan, it also drops a file named msdirectx.sys in your %UserProfile% which acts as a rootkit. ... Read More
Compaq Service Drivers winsvc.exe
X
Added by the W32/Sdbot-AGD worm and IRC backdoor.
ComTry Web Searcher wstray.exe
X
Comtry MP3 Downloader related - spyware
Config WinService32.exe
X
Added by the Troj/Crutcha-A Trojan.
Config Loadr winsys32.exe
X
Added by the AGOBOT-HN WORM!
Configuration Default Wuxat.exe
X
Added by the SPYBOT-CA WORM!
Configuration File Winset32.exe
X
Added by the FLUX.101 TROJAN!
Configuration Loaded wupdated.exe
X
Added by the MOEGA or MOEGA.AG or MOEGA.AP WORMS!
Configuration Loader wincrt32.exe
X
Added by the GAOBOT.BF WORM!
Configuration Loader windex.exe
X
Added by the GAOBOT.BZ WORM!
Configuration Loader Winreg.exe
X
Added by the GAOBOT.AO WORM!
configuration loader winicfg32.exe
X
Added by the GAOBOT.GEN!POLY WORM!
Configuration Loader wincffg.exe
X
Added by the AGOBOT.A3 WORM!
Configuration Loader win32exec.exe
X
Added by the W32/Sdbot-LA worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Configuration Loader winfix.exe
X
Added by the W32/Sdbot-MA worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
configuration loader WinHelper.exe
X
Added by a variant of the AGOBOT/GAOBOT WORM!
Configuration Loader Service winsys32.exe
X
Added by the W32/Rbot-YV WORM/IRC backdoor!
Configuration Loading Service wscel.exe
X
Added by the W32/Sdbot-WJ WORM/IRC backdoor Trojan!
Configuration Utility wlanutil.exe
U
NetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards) ... Read More
Configuration32 Loader32 winamp32.exe
X
Added by the W32/Sdbot-BIC worm. When started, this infection connects to a remote IRC server and waits for commands to execute. ... Read More
Connection Reset webadmin.exe
X
A new service is set by W32/Forbot-FY with a display name of "Website Administrator Info" ... Read More
ContentService winservn.exe
X
Homepage hijacker
Controller WFXCTL32.EXE
N
From Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and display ... Read More
couponsandoffers wjview.exe
X
Added by the Adware.TopMoxie adware. Not to be confused with the legitimate wjview.exe Microsoft file. ... Read More
Cpanel WINLOGIN32.EXE
X
Added by the WORM_SPYBOT.MO worm and IRC backdoor.
cpntmgc wincomp.exe
X
MagicControl downloader trojan variant
cpntmgc winmgts.exe
X
MagicControl downloader trojan variant
CPU Temp Control wuitgurd.exe
X
Added by the W32/Rbot-AHV worm. When infected your computer will become an open mail relay which will allow your computer to be used to send out spam ... Read More
cqlyg world_cup_.bat
X
Added by the WCUP.A WORM!
CriticalUpdate Wucrtupd.exe
N
MS Windows Critical Update Notification. If you want to keep Windows up-to-date, check the Windows Update site ... Read More
Crtlink winpack.exe
X
Added by the Troj/Agent-PVR Trojan.
crypt32unchain wlnotlfy.dll
X
Added by the TSPY_AGENT.AAVG spyware Trojan.
CTEMON.EXE winlogon.exe
X
Added by the Troj/FakeAv-FU Trojan. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
ctfmon WinConst.exe
X
Added by the Troj/Assasin-G backdoor trojan and keylogger.
ctfmon WinUP.exe
X
Added by the Troj/Banker-VV password/information-stealing Trojan for online banks. ... Read More
CTFMON winjpg.jpg
X
Added by the W32/Autorun-ALB removable media worm. Please note that the C:\Windows\System32\wscript.exe file is legitimate and should not be deleted. ... Read More
CTFMON win.exe
X
Added by the VBS.Runauto.G worm. VBS.Runauto.G is a worm that spreads through removable drives and network shares. The worm also opens a back door on ... Read More
ctfmon.exe wmisqst.exe
X
Added by the Troj/VBInj-B Trojan.
CueX44_stil_here WINLOGON.EXE
X
Added by the W32/Punya-A worm. This infection should not be confused with the legitimate C:\Windows\System32\WINLOGON.EXE file. ... Read More
Currency windowsintd.exe
U
Added by the Spyware.Intruder surveillance software. If this program was not installed by you it should be uninstalled immediately. ... Read More
Cyclope Internet Filtering Proxy WebFilterAccess.exe
Y
Related to the Cyclope Internet Filtering Proxy Internet site and content filtering software. ... Read More
D-Link AirPlus DWL-650+ Utility WLANMON.exe
N
D-Link Air Plus Wireless PC modem connection monitor
d2 winloadhh.dll
X
Added by the Troj/Labrap-A downloader trojan.
Daily Weather Forecast WEATHER.EXE
X
Added by Troj/Dloader-IP TROJAN to the Windows program folder.
DDriver windrv.exe
X
Identified by Kaspersky Anti-Virus as Trojan-Clicker.Win32.Delf.fj.
Delete Me worm.exe
X
Added by the DOOMHUNTER WORM!
dell wireless manager ui WLTRAY
U
Related to Dell Wireless WLAN Card. Provides additional configuration options for these devices. ... Read More
Device Manager wfxmgr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
DF windf.exe
X
Added by the Win32/Windage.A password-stealing Trojan.
didact wuuawkz.dll
X
Zlob Trojan that infects you with the VirusHeat rogue anti-spyware program. Please use the guide below to remove this infection. ... Read More
DirectX Service WinSxS\explorer.exe
X
Added by the Troj/Bckdr-PXK backdoor Trojan.
Display Device Driver winadll.exe
X
Unidentified malware.
Distributed File System win.exe
X
Added by the W32/Myfip-L WORM, which also creates a new service/displayname called Distributed Link Tracking Extensions. ... Read More
djuka wbchha.dll
X
Zlob Trojan that infects you with the VirusHeat rogue anti-spyware program. Please use the guide below to remove this infection. ... Read More
DLHelperEXE WATCH.exe
N
Download helper distributed with some software that allows the software installation to redirect download locations. Not required once the installatio ... Read More
DLINK dfe drivers for Windows NT windfe.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
DNS Config service win32.exe
X
Added by the W32/Rbot-TL WORM/IRC backdoor trojan!
DomPlayer Service wakeservice.exe
X
Added by the DomPlayer. DomPlayer is a potentially unwanted application that may download another program and other security risks. ... Read More
DRam prosessor WindowsUpdate.exe
X
Added by the W32/Rbot-BBZ worm and IRC backdoor.
DRam prosessor winupl.exe
X
Added by the W32/Rbot-BCQ worm and IRC backdoor.
DRam prosessor winsys.exe
X
A variant of the RBot family of worms and IRC backdoor Trojans.
DRam rar proc winupdaterar.exe
X
Part of the Rbot family of worms and IRC backdoors.
DRIVESYS1 windo.exe
X
Added by the W32/Autorun-SR removable media worm.
drmu W95Mm.exe
X
Homepage hijacker installing a toolbar: http://tdko.com/. Lop.com in disguise. See this thread ... Read More
drvsyskit winupgro.exe
X
Added by the Troj/Agent-JQG Trojan.
DsplObjects windspl.exe
X
Added by the W32/Bagle-CF mass-mailing worm and backdoor Trojan.
DsplObjects windspl.exe
X
Added by the W32/Bagle-CK mass-mailing worm and backdoor Trojan.
DSS winoscnfg.exe
X
Added by the HTTPBruteForcer hacking utility.
dvd98 windvd98.exe
X
Added by the CULT.P WORM!
Dvx wsxsvc.exe
X
Delfin Media Viewer or "Promulgate" adware variant
Dynamic Dns Binary winxp34.exe
X
Added by a variant of the WIN32.RBOT WORM!
dynamic dns binary WinHelpcfn.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
EAPCISETUP wizard.exe
N
Part of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation ... Read More
EbatesMoeMoneyMaker wjview ...Code
N
Ebates adware
Eicon NetworksLAN_DAEMON watch.exe
U
Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) ... Read More
Eicon TechnologyLAN_DAEMON watch.exe
U
Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) ... Read More
ELSA WINman Suite Winmsuit.exe
U
Allows you to totally customize your ELSA graphics card settings, including overclocking the GPU ... Read More
Enables Java Support winjava.exe
X
Added by the W32/Codbot-AA backdoor worm.
encapsulated command tool wintr.com
?
??
Encoder Agent WMENCAGT.EXE
N
MS Windows Media Encoder, which already has a shortcut in the Start Menu if installed ... Read More
EnGenius Network Analysis Tool winegne.exe
X
Added by the W32/Rbot-GRC worm and IRC backdoor.
Enterprise Suite WE345d.exe
X
Added by the Remove Enterprise Suite (Uninstall Guide) rogue anti-spyware program. ... Read More
Enumerate Service wsys.exe
X
Added by the MANIFEST TROJAN!
Erfgddfk wind2ll2.exe
X
Added by the WORM_BAGLE.BX mass-mailing worm.
erghgjhgdr windlhhl.exe
X
Added by the W32.Beagle.BG or W32.Beagle.BH or W32.Beagle.BI or W32.Beagle.BJ WORM! ... Read More
erghgjhjgdr windlhhl.exe
X
Added by the BEAGLE.BG mass-mailing worm!
erthegdr windll2.exe
X
Added by the W32.Beagle.CG@mm mass-mailing worm.
erthgdr windll.exe
X
Added by the BEAGLE.AO or BEAGLE.AQ WORMS!
etunnel winfw.exe
X
Added by an unidentified TROJAN!
ExeName32 Warm.scr
X
Added by the SCOLD WORM!
explorer wscript.exe [filename]
X
Sneaky way to start any VBS script. Many viruses use VBS files
Explorer Windows Explorer.exe
X
Added by the W32/SillyFDC-I worm. This infection should not be confused with the legitimate C:\Windows\explorer.exe file. ... Read More
EXPLORER wab32res.exe
X
Added by the W32.Fubalca.B worm. W32.Fubalca.B is a worm that spreads through removable media and infects various file types, including .exe and .html ... Read More
eZWO wo.exe
X
Ezula "Web Offer" foistware
FClear Service wnmifc.sys
X
Added by a variant of the Troj/Haxdor-Gen rootkit.
FDriver windrv.exe
X
Identified by Kaspersky Anti-Virus as Trojan-Clicker.Win32.Delf.fj.
File System Service wmiprvsc.exe
X
Added by the AGOBOT-HZ TROJAN!
FileFreedom_Plugin wtm.exe
N
FileFreedom peer-to-peer sharing program
FileManager32 Wscript.exe ..ChkMgr32.vbs
X
Added by the NOTUP.A WORM!
FileSoft Wscript.exe UpdataFiles.vbs
X
Added by the SST.B WORM!
Fire Wall services wnlmzsfhobi.exe
X
Added by the W32/IRCBot-QY worm and IRC backdoor.
FireFly WinDeBug.exe
X
Added by the Troj/FireFly-A Trojan.
firefox startup drivers wuaclt.exe
X
Added by the RBOT.BYX ... Read More
Firewall wmlaunch .exe
X
Added by a WORM, W32/Elitper-A. It will be found in the Windows Program Files folder. ... Read More
Firewall auto setup winlogon.exe
X
Added by the Troj/Agent-EDB Trojan. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
Firewall Update System1 WinedowsUpdater1.exe
X
Added by the W32/Rbot-ARU worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. ... Read More
FIX WinFIX1.0.vbs
X
Added by the VBS.Gormlez@mm infection! Found in the Windows directory.
Flash Driver winlogon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
flaxen wakjs.dll
X
Zlob Trojan which installs the VirusTrigger rogue anti-spyware program. This program displays fake security alerts stating that your computer has a s ... Read More
Folder Service wssdtu.exe
X
Added by the MANIFEST TROJAN!
Folding@home WINFAH.EXE
N
Folding@Home is a distributed computing project which studies protein folding, misfolding, aggregation, and related diseases - must be running in orde ... Read More
Folding@Home 5.03 winfah.exe
N
Folding@Home is a distributed computing project which studies protein folding, mis-folding, aggregation, and related diseases. This program must be r ... Read More
FriendlyTypeName winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! ... Read More
Fromine WinPopup winpopup.exe
N
Instant Messenger program
FTH2004 WindowsDAT.exe
X
Added by the Backdoor.Futh backdoor. This infection listens on TCP ports 7896 and 7897 awaiting commands. ... Read More
gadcom winlogun.exe
X
Identified as a variant of the Trojan:Win32/Matcash.HZ malware. The * in the command represents a random number. ... Read More
Generic Host wauclt.exe
X
Added by the W32/Sdbot-DNL worm and IRC backdoor.
Generic Host Process for Win32 Services winsvc.exe
X
Added by the SDBOT-O WORM!
Generic Host Process for Win32 Services winlogon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans. This infection should not be confused with the legitimate C:\Windows\System32\winlog ... Read More
GenericHostXP WinLoaderXP.exe
X
Added by the Troj/Bdoor-ACX Trojan.
Genesis Streaming Service WPGApplicationLauncher.exe
U
Allows you to communicate with projectors via wireless.
geosphere wowlze.dll
X
Zlob Trojan which installs the VirusProtect 3.9 rogue anti-spyware program. This program displays fake security alerts stating that your computer has ... Read More
Gerenciamento de arquivos do Windows Winmod32.exe
X
Added by the Troj/Dloader-WG downloader Trojan.
german.exe winsystems.exe
X
Added by the Troj/BagleDl-AE Trojan downloader.
german.exe wintems.exe
X
Added by the TROJ_MGLIEDER.AA Trojan.
getwin winB_.exe
X
Added by the Troj/Banker-HS password-stealing Trojan.
global startup WinDash.EXE
X
Reported by Kaspersky Anti-Virus as IM-Worm.Win32.VB.q, may be related to the W32/Attech-C ... Read More
Google Online Search Service winlagons.exe
X
Identified by Bitdefender as a variant of the Trojan.Downloader.Small.AAJM Trojan. ... Read More
Google Online Search Service winlast.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Googles Onlines Search Services wnslogan.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Winlagons.an malware.
gpmce windows.exe
X
Added by the W32/SillyFDC-HO worm.
Graphics adapter service windll.exe
X
Added by the W32.Atnas.A worm. W32.Atnas.A is a worm that performs distributed denial of service attacks and spreads through file-sharing programs. ... Read More
GrayPigeon_Hacker.com.cn windows.exe
X
Added by the Troj/GrayBrd-BA backdoor Trojan.
GrayPigeon_Hacker.com.cn windows update.exe
X
Added by the Troj/GrayBrd-CE backdoor Trojan.
gremier wscript.exe gpremier.vbs
X
Added by the GPREMIER WORM!
GW-NS54CW Service WLService.exe
Y
Driver for the Planex GW-NS54CW router.
g_rkt win32_rkt.sys
X
Identified as a variant of the Win32.Rootkit.Agent.MO rootkit.
H/PC Connection Agent WCESCOMM.EXE
U
Active sync for use with Windows CE based palm PC
Hardware Shell Detection WinHSD.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Hello World WinPad.exe
X
Added by Backdoor.CHCP. This infection listens on TCP port 1145 awaiting remote connections. ... Read More
Help Wizardnil.exe
X
Added by the Troj/Bancos-BCZ online banking Trojan. If you are infected with this file you should immediately change all of your online banking passw ... Read More
Hidetools Spy Monitor wmispe.exe
U
Added by the Spyware.HidetoolsSpy surveillance software. Spyware.HidetoolsSpy is a spyware program that records screen shots and logs keystrokes on t ... Read More
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run windowsupdate.exe
X
Added by the FORBOT-BJ WORM! (where HKLMRun represents HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun) ... Read More
hostserv wiz98.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
HOT FIX windsys2.exe
X
Identified as a variant of the Forbot worm.
Hrxmp Win Const.exe
X
http://www.lienvandekelder.be We Love Lien Van de Kelder.exe
X
Added by the W32/Mytob-CV email worm and backdoor IRC trojan.
hyperproduction wcscqa.dll
X
Zlob Trojan that infects you with the VirusHeat rogue anti-spyware program. Please use the guide below to remove this infection. ... Read More
icq lite winlog.exe
X
Added by the Troj/IRCBot-TJ Trojan.
ICQ Net winlogon.exe
X
Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should NOT appear in Msconfig/Startup! ... Read More
icqbeta webcamupdate.exe
X
Added by an unidentified TROJAN!
ICQNet winlogon.exe
X
Added by the W32/Netsky-C mass-mailing worm.
IE Runtime wini.exe
X
Added by the W32/Rbot-ABK worm. When started this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
IE Runtime wini.exe
X
Added by the W32/Rbot-ADM worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
IE Runtime winlogo.exe
X
Added by the W32/Rbot-AMJ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
IE Runtimes winis.exe
X
Added by the W32/Rbot-ADZ worm. When started this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
IE-Security wdscan.exe
X
Added by the IE-Security rogue anti-spyware program.
ie6 wkstmg.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
IE6 winsnt.exe
X
Added by the W32/Rbot-GOV worm and IRC backdoor.
IEEE 802.11g Wireless LAN Utility WLANUTL.exe
U
Configuration utility for your wireless card.
IEWinserv winserv.exe
X
Added by the Troj/Banker-EMY Trojan.
IEXPLORER-Drivers windns.exe
X
A service is created by the W32/Forbot-EP WORM, and run using the display name of "Windows Domain Name Drivers". ... Read More
IExplorerService WinSock.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
ImagePath win32ssr.exe
X
Added by the W32/Tilebot-CW worm and IRC backdoor.
Index Washer WashIdx.exe
U
Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Pr ... Read More
inetservices wsock32.exe
X
Added by the Backdoor.Win32.Delf.ej or TROJ/WOCK32-A TROJAN! ... Read More
infoxmid wseqnx.inf
X
Added by the Backdoor.Rustock backdoor rootkit.
Install Driver Table Manager wpablan.exe
X
Added by the W32/Sdbot-CWR worm and IRC backdoor. W32/Sdbot-CWR spreads to other network computers by exploiting the buffer overflow vulnerabilities: ... Read More
Instant Wireless Configuration Utility WUSB11cfg.exe
U
Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. A ... Read More
instant wireless configuration utility WPC11Cfg.exe
U
Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also use ... Read More
Intec Service Drivers winrvc.exe
X
Added by a variant of the W32/Sdbot family of worms and IRC backdoor Trojans.
Intec Service Drivers wing32.exe
X
A variant of the W32/Rbot-BCR family of worms and IRC backdoor Trojans.
intel system tool winnook.exe
X
Added by the Troj/Spyre-C trojan. This infection will display on your desktop a false message in the attempts to goad you into buying their software. ... Read More
Intel(R) PROSet/Wireless SSO Service WLKeeper.exe
Y
Service related to Intel's wireless software.
internct WinSocks5.exe
X
Added by the GRAYBIRD.F TROJAN!
Internet winlogom.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Internet WinSecUp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Internet winsas32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Internet WinSecUps.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Internet WinSUp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Internet wins.exe
X
A variant of the Worm.Rbot.AAYF family of worms and IRC backdoor Trojans.
Internet wints.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
internet wuauclt.exe
X
Unkown malware.
Internet Explorer Plugin WinStop32.exe
X
Added by the Backdoor.Backage backdoor.
INTERNET SERVISES winz32.exe
X
Added by the KWBOT.Z WORM!
internet2 optimizer wkfix.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
InternetExplorer2 windows.exe
X
Added by the W32/Sdbot-CZP worm and IRC backdoor.
InternetGetConnectedState winupdate.exe
X
Added by the W32/SdBot-JN worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
INTERNET_SERVISES winz32.exe
X
Added by the SDBOT.Q TROJAN!
InterU WINDRV.EXE
X
Added by the IRCINTER.A TROJAN!
Intervideo Win Cinema Manager WinCinemaMgr.exe
N
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs ... Read More
Intervideo Win Cinema Manager WINCIN~1.EXE
N
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs ... Read More
Intervideo WinCinema Manager WinCinemaMgr.exe
N
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs ... Read More
Intervideo WinCinema Manager WINCIN~1.EXE
N
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs ... Read More
Intervideo WinScheduler WinScheduler.exe
N
WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will ... Read More
IPC Spool Manager wnmgre.exe
X
Added by the W32/Sdbot-ZC. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
ipc spool manager winspec.exe
X
Added by the W32/SDBOT-BLU WORM! ... Read More
IPTable Configuration Winipcfgs.exe
X
Added by a variant of the RBOT WORM!
iRis Active Monitor winmon32.exe
N
Iris Antivirus - discontinued, replace with good alternative
iRiS AntiVirus Active Monitor WIMMUN32.exe
N
Iris Antivirus - discontinued, replace with good alternative
ISPSERVICE wintmp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
jkdfj94kgdftdf winlogan.exe
X
Identified by Trend Micro as a variant of the PE_VIRUT.XV spamming Trojan.
Jufualt winxp2.exe
X
Added by the W32/Sdbot-AAB worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
KAVFOX win1ogoin.exe
X
Added by the Troj/GWGhost-M key logging Trojan.
KAVPersonal90 wscntfy.exe
X
Added by the Troj/Banker-FZ password-stealing Trojan for certain online Brazilian banks. ... Read More
KavRuns Windll.exe
X
Added by the TRYNOMA TROJAN!
KernelCheck wscnty.exe
X
Added by the Troj/LegMir-BE password-stealing Trojan.
KernelCheck winbery.exe
X
Added by the Troj/LegMir-CG password stealing Trojan for the online game Legend of Mir. ... Read More
KernelCheck winmer.exe
X
Added by the Troj/LegMir-XG password-stealing Trojan for the online game the Legends of Mir. ... Read More
KernelFaultCheck winbin.exe
X
Added by the Troj/Dloadr-AAX downloader Trojan.
KernelFaultCheck winabc3.exe
X
Added by the W32/Nubys-A EXE virus.
Kernel_check wmiprvse.exe
X
Added by the SONEBOT-B WORM!
key winxp.exe
X
Added by the BEAGLE.AG WORM!
key2 winlog.exe
X
Added by the Trojan.Lodav.C Trojan that lowers security settings on your computer. ... Read More
KnowledgeBase GUI wppewafaj.exe
X
Added by the W32/Rbot-GRZ worm and IRC backdoor.
KSD2Service winl0gon.exe
X
Added by the Troj/Dloadr-AXH Trojan.
KV2005 word.EXE
X
Added by the Troj/VB-IW backdoor Trojan.
l44sys33 winmine.exe
X
Added by the VBS.Lido virus and worm. The winmine.exe program is actually a legitimate Windows game bundled with the OS, but in this is case, is being ... Read More
Ldr winnt.exe
X
Added by the TROJ_HARNIG.EO Trojan.
Lien Van de Kelder www.lienvandekelder.be.exe
X
Added by the W32.Mytob.DB@mm mass-mailing worm with backdoor capabilities.
Live Messanger wllmsngr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
load wuauc1t.exe
X
Added by the Troj/Dloader-LY TROJAN!
Load-Guard Wscript.exe LGuarg.exe.vbs
X
Added by the YENO.B and YENO.C WORMS!
load32 winldra.exe
X
Added by the Troj/Dumaru-AT TROJAN!

These files are known to be part of an infection that transmits information about your bank accounts, ... Read More
load= WPSLOAD.EXE
?
Windows printing system that comes with the setup for Canon BJC series on the manufacturer's disk ... Read More
load= WINOSCFG.EXE
?
Could it be something to do with configuring Windows on a new PC from an OEM supplier? ... Read More
Load= wtfeat.exe
?
Associated with the Wintab Digitizer
load= win32exec.exe
X
Added by the BITTER WORM!
loader WMPLAYER.EXE
X
Unknown malware. This infection replaces the legitimate wmplayer.exe file with an infection file of the same name. ... Read More
LoadPFW wmimgr.exe
X
Added by the W32/Qeds-B virus.
LoadWatcher watcher.exe
U
Added by the Watcher surveillance software. Spyware.Watcher is a remote surveillance application that can use a computer's webcam to secretly monitor ... Read More
loadwin winset.exe
X
Added by the Troj/QQPass-I password-stealing trojan.
loadwin winsys.exe
X
Added by the Troj/QQPass-J password-stealing trojan.
Local area connection winlive.exe
X
Added by the W32/Rbot-FPH worm and IRC backdoor.

W32/Rbot-FPH spreads to other network computers by:

- exploiting common ... Read More
Local Security Policy wpablan.exe
X
A variant of the W32/Sdbot family of worms and IRC backdoors.
Local Services winserv32.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
localhost winlogom.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Log Manager winup.exe
X
Added by the W32/Spybot-NV network worm.
LoggonAdministrator WINLOGON.EXE
X
Added by the W32.Korron.A worm. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
LoghDriver winlde.exe
X
Identified as a variant of the IRCBot family of worms and backdoors.
Login winlog.exe
U
Salfeld Child Control 2003 - parental control software
logitech desktop controller wrcam.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Logon winlog.com
X
Added by the W32.Rungbu.C virus. W32.Rungbu.C is a virus that replaces Word Documents with a copy of the virus. ... Read More
logservice wincalc.exe
X
Added by the BACKDOOR.PAPROXY TROJAN! ... Read More
longos WIWT.EXE
X
Added by the Troj/Banker-CD TROJAN!
lost WinUpdate.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
LSA wfdmgr.exe
X
Added by the W32/MyDoom-BG WORM! File is found in the Windows system folder.
lsass woekd.exe
X
Added by an unidentified WORM or TROJAN!
LTM2 winupdate.exe
X
Added by the LITMUS.203 TROJAN!
LTM2 winscan.exe
X
Added by the Troj/Litmus-B TROJAN!
Machine Update Soft wusas.exe
X
Added by an unidfentified WORM!
MalP wkssvr.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
MAT WliveUPdate.exe
X
Added by the Backdoor.Futh backdoor. This infection listens on TCP ports 7896 and 7897 awaiting commands. ... Read More
Maxtor Performance Analysis Tool winrcn.exe
X
Added by the Troj/IRCBot-VY worm and IRC backdoor.
Maya 7.0 Documentation Server wrapper.exe
Y
Related to Autodesk Maya.
MBsync WUAPDC.EXE
X
Added by the W32/Sdbot-IS worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
MC wintrims.exe
X
Added by the WINTRIM TROJAN!
mc WINTRIM.EXE
X
Added by the WINTRIM_A TROJAN! ... Read More
MCafee WinNT.exe
X
Added by the W32.Vig.C virus.
mcafee Win32.dll.vbs
X
Added by the W32/Catcher-B worm. W32/Catcher-B spreads by copying itself to the root of all mapped drives. ... Read More
MCafee Update WinNT.exe
X
Added by the W32.Vig.C virus.
McAfeeWebscanX WebScanX.exe
Y
From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guar ... Read More
MClear Service wnmicf.sys
X
Added by a variant of the Troj/Haxdor-Gen rootkit.
MCX Update wisp.exe
X
Added by the W32/Rbot-AQH worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
MD IE Plugin winy.exe
X
Adware
Media Player wmplayer.exe
X
Added by the AGOBOT-BM WORM!
Meeting Connection wowdache.exe
X
Added by the Troj/PPdoor-D TROJAN!
Memorex Network Analysis Tool winsntp.exe
X
Added by the W32/Vanebot-AT network worm.
Messanger modix Configuration winmsn.exe
X
A variant of the Backdoor.Win32.Rbot.aie family of worms and IRC backdoor Trojans. ... Read More
Messenger WINAMPA.EXE
X
Added by the Troj/Ranck-CG trojan.
messenger Wmsngr.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Mgsgi service wkzfn.exe
X
Added by the W32/Agobot-AHL worm and IRC backdoor.
microfot update winldx32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microft Update 32 winssx.exe
X
Added by the W32/Rbot-AQS worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
micromedia flash update wdfmrg.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
MicroMix32 WinCon.exe
X
Added by the Troj/VB-ECC Trojan.
MICROSFT MX UPDATE SUPPORT winmx32.EXE
X
Added by the W32/Rbot-BFU worm and IRC backdoor.
Microsof Winlog Host wilogon32.exe
X
Added by the RBOT.XC WORM!
Microsoft win32.exe
X
Added by the Backdoor.Darkmoon backdoor Trojan. It also adds the following files as part of the infection:

%System%\Yxgunlzu.d1l
% ... Read More
Microsoft winsock.exe
X
Added by the W32/Rbot-FOT worm and IRC backdoor.
Microsoft wuauclt.exe
X
Added by the Troj/QQRob-AAQ Trojan.
Microsoft wcsntfy.exe
X
Added by the W32/Agobot-AHT worm and IRC backdoor.
Microsoft windl32.exe
X
Added by the W32/Sdbot-DCZ worm and IRC backdoor.
Microsoft wsim32.exe
X
Added by the W32/Rbot-GTL worm and IRC backdoor.
Microsoft WinSecUp.exe
X
Added by the W32/Rbot-GPL worm and IRC backdoor.
Microsoft wuaudit.exe
X
A variant of the RBot.cij family of worms and IRC backdoor Trojans.
Microsoft winlog.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft winlogom.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft winsys32.exe
X
A variant of the W32/Rbot-GSQ family of worms and IRC backdoor Trojans.
Microsoft wmism23.exe
X
Added by the W32/Rbot-GSU worm and IRC backdoor.
Microsoft wplayer.exe
X
Added by the Troj/IRCBot-ABP worm and IRC backdoor.
Microsoft winline.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft winampaa.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft winlogonsys.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft (R) Windows Update Service wuauclt.exe
X
Added by the Backdoor.Ranky backdoor Trojan. This infection should not be confused with the legitimate C:\Windows\System32\wuauclt.exe file. ... Read More
Microsoft 16Bit Update wuapdate16.exe
X
Added by the RBOT.CZ WORM!
microsoft 64 bit runtime updater wupdt64.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft AntiVirus winav32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Apache for Windows wpablin.exe
X
Added by the W32/Tilebot-IL worm and IRC backdoor.
Microsoft auto update winupdate.exe
X
Added by the BMBOT TROJAN!
Microsoft auto update wuauclt.exe
X
Added by BackDoor CLT. This infections connects to an IRC server where it awaits commands. If this infection is on a Windows XP, NT, 2000, 2003, or V ... Read More
Microsoft Command C winhost32.exe
X
Added by the W32/Sdbot-BBA worm and IRC backdoor.
microsoft command line wincmd.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft ConfgKeys wurmgrd32.exe
X
Added by the W32/Rbot-ARX worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. ... Read More
Microsoft CONFIG winmx.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Config Setup wjdrive32.exe
X
Added by the W32/Autorun-BPF removable media worm.
Microsoft Corp SSL Certificates windowz.exe
X
Added by the W32/Rbot-GCZ worm and IRC backdoor.
Microsoft Corp Updates wupdates.exe
X
Added by the W32/Rbot-AUU worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Corporation wordpad.exe
X
Added by the W32/Tilebot-GL worm and IRC backdoor. This infection should not be confused with the legitimate file C:\Program Files\Windows NT\Accessor ... Read More
Microsoft Corporation Server wupdate.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft CP Web Manager webcp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
microsoft crs fix serv wincrs.exe
X
Added by the SDBOT.BWF WORM! ... Read More
microsoft dde control wupades.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Microsoft DirectX wuamgrd.exe
X
Added by the SDBOT.MY WORM!
Microsoft DirectX wupdate.exe
X
Added by the W32/Rbot-L trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Display Driver windsp.exe
X
Identified by Kaspersky antivirus as the Backdoor.Win32.Rbot.aeu worm and IRC backdoor. ... Read More
Microsoft dll Host Service wkssr.exe
X
Unidentifed worm and IRC backdoor.
Microsoft DLL Library winlib32.exe
X
Added by the W32.Atnas.A worm. W32.Atnas.A is a worm that performs distributed denial of service attacks and spreads through file-sharing programs. ... Read More
Microsoft Dll Management windll.exe
X
Added by the RBOT-MT WORM!
Microsoft DLL Verifier wns.exe
X
Added by the W32/Spybot-LA worm and IRC backdoor.
Microsoft DLL Verifier winavguard.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft DLL Verifier wind0w.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Driver Setup w7services.exe
X
Added by the W32/AutoRun-ARJ removable media worm.
Microsoft Driver Setup wndrive32.exe
X
Added by the Troj/Agent-NRS Trojan.
Microsoft Drivers WSconf.exe
X
Added by a variant of the SDBOT WORM!
Microsoft ErgoPack wserb32.exe
X
Added by the RBOT-RI WORM!
Microsoft Excell wuamngr32.exe
X
Added by the RBOT-QH WORM!
microsoft file demand manager wmgrdf.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft Firewall 2.9 WMPRWISE.EXE
X
Added by the Troj/Agent-ROB Trojan.
Microsoft Generic Update Manager wupdate.exe
X
Added by the W32/Rbot-AWC worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Genuine Advantage winmga.exe
X
Identified by Kaspersky as the Backdoor.Win32.VanBot.dk worm and IRC backdoor.
Microsoft Hosting Service WINHOSTING.EXE
X
Added by the RBOT.AEV WORM!
Microsoft Internet windows32.exe
X
Added by the SDBOT-F WORM!
microsoft internet wincfg16.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Microsoft Internet Agent winagent.exe
X
Malware bundled with rogue anti-spyware programs.
Microsoft Intranet WIN31.EXE
X
Added by the W32/Rbot-FD trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This ... Read More
Microsoft Intrenet Explorer wcumrg.exe
X
Added by the W32/Sdbot-AFD worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft IT Update win64.exe
X
Added by the RBOT.GA WORM!
Microsoft IT Update winn43.exe
X
Added by a variant of the RBOT WORM!
Microsoft IT Update win43.exe
X
Added by the RBOT-SA WORM!
Microsoft IT Update windows.exe
X
Added by the RBOT-GL WORM!
Microsoft IT Update winsyst32.exe
X
Added by the W32/Rbot-FC trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This ... Read More
Microsoft Java Virtual Machine winscr32.exe
X
Added by a variant of the WOOTBOT WORM!
Microsoft Kernel Windows_kernel32.exe
X
Added by the NETSKY.AE WORM!
Microsoft Loader winsdnz.exe
X
Added by the W32/Rbot-JJ trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Locator Service wkssvc.exe
X
Added by the W32/Sdbot-ABE worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Login winlogin.exe
X
Added by the W32/Rbot-AJP worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Lsass Service wintcp32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Machine winxp43.exe
X
Added by the W32/Rbot-IA trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This ... Read More
microsoft machine winjava.exe
X
Added by a variant of the AGOBOT/GAOBOT WORM! ... Read More
Microsoft media winmplayers.exe
X
Added by a variant of the SPYBOT WORM!
Microsoft media services winmplayer.exe
X
Added by the RBOT.ZO WORM!
Microsoft MediaScope winmes.exe
X
Added by the W32/Rbot-XU WORM/backdoor, it's file will allow a remote attacker to create new accounts, terminate processes, record keysrokes and other ... Read More
Microsoft MicroP Protocol wdgmr32.exe
X
Added by a variant of the WIN32.RBOT WORM!
Microsoft NT Update winexec32.exe
X
Added by a variant of the RBOT WORM!
Microsoft Office Start winupdates.exe
X
Added by the GAOBOT.BC WORM!
Microsoft Outlook wincsrss.exe
X
Added by the Troj/Agent-OUY Trojan.
Microsoft Patches WUACMGRD.EXE
X
Added by the W32/Rbot-FX trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This i ... Read More
Microsoft Plug n Play win32pnp.exe
X
Added by the W32/Mytob-GW worm and IRC backdoor.
Microsoft Problem Doctor windr32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Problem Doctor windr64.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Problem Doctor windr128.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Redirect winred.exe
X
Added by the Troj/Banker-VK banking Trojan.
Microsoft Rundll windos.exe
X
Added by the W32/Sdbot-WF WORM/IRC backdoor!
microsoft security winService.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft Security Management winnt.exe
X
Added by the RBOT-MQ WORM!
Microsoft Security Management winserv.exe
X
Added by the RBOT-MJ WORM!
microsoft security management wuauct1.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft Security Monitor Process windowsupdate.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Security Process wininit.exe
X
Added by the W32/Rbot-FKM worm and IRC backdoor. Please note that this infection should not be confused with the legitimate Windows file located at %S ... Read More
microsoft server applacations wuauct1.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft Service winsvc.exe
X
Added by the SPYBOT-DB WORM!
Microsoft Service winspl.exe
U
Added by the Spyware.SpyMan surveillance software. If this software was installed without your knowledge it should be removed. ... Read More
Microsoft Service Login Manager winlogin.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Service Pack WindowsSP.exe
X
Added by the W32/Rbot-RF worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
Microsoft Sound Technology winsound.exe
X
Added by the W32/Rbot-AGG worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft SpA Service win32.exe
X
This is a SDBot variant backdoor infection. When run this infection connects to an IRC server, d-3.biz. ... Read More
Microsoft SpAr Service winsbsd32.exe
X
Added by the W32/Rbot-TJ WORM/IRC backdoor trojan!
Microsoft Standard Executions Library win32lib.exe
X
Added by the W32/Rbot-AUK worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft standard protector winsocks5.exe
X
Added by the Troj/Stox-A Trojan.
Microsoft startup wmpIayer.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Stuff you know winslogin.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Svchost local services winoem.exe
X
Added by the W32/Rbot-FPE worm and IRC backdoor.
Microsoft Svchost local services Winsec32.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Synchronization Manager WinLoginnn.exe
X
Added by the SPYBOT.FO WORM!
Microsoft Synchronization Manager winupdate.exe
X
Added by the SDBOT.ER WORM!
Microsoft Synchronization Manager win.exe
X
Added by the SDBOT.AK WORM!
Microsoft Synchronization Manager WIN932.EXE
X
Added by the W32/Sdbot-IL worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
Microsoft System winamp1.exe
X
Added by the W32/Sdbot-UF worm. When started, this infection connects to an IRC server where it waits for remote commands. ... Read More
Microsoft System Checkup Wnetlib.exe
X
Added by the DONK.C WORM!
microsoft system checkup wnetmgr.exe
X
Added by the W32.DONK.Q WORM! ... Read More
Microsoft System Service winIogon2.exe
X
A variant of the IRCbot family of backdoor worms.
Microsoft TCP Protocol wintcp32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Telecoms Center winrestore.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Telecoms Center winupcd.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft U wuamkopxp.exe
X
Added by the W32/Rbot-AHC worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
microsoft unpack system winrarx.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft Update winsys32.exe
X
Added by a variant of the RBOT WORM!
Microsoft Update wuamgrd.exe
X
Added by the RBOT-LK WORM!
Microsoft Update wuammgr32.exe
X
Added by the RBOT-AW WORM!
Microsoft Update wudmate.exe
X
Added by the RBOT.AP WORM!
Microsoft Update wuamgrd32.exe
X
Added by the RBOT.ZB WORM!
Microsoft Update webm.exe
X
Added by the SDBOT.WK WORM!
Microsoft Update wuagrd.exe
X
Added by the RBOT-FK WORM!
Microsoft Update wauguard.exe
X
Added by the RBOT.AEE WORM!
Microsoft Update winscv.exe
X
Added by the RBOT-BH WORM!
Microsoft Update winsys.exe
X
Added by the RBOT-GV WORM!
Microsoft Update wserv32.exe
X
Added by the RBOT.AF WORM!
Microsoft Update wtm32.exe
X
Added by the RBOT-AQ WORM!
Microsoft Update wumgrd.exe
X
Added by the SDBOT-KY WORM!
Microsoft Update wssvr.exe
X
Added by the W32/RBOT-OD WORM!
Microsoft Update windows24.exe
X
Added by a variant of the WIN32.RBOT WORM!
Microsoft Update wuamagr32.exe
X
Added by the SPYBOT.CG WORM!
Microsoft Update winupdate32.exe
X
Added by the W32/Rbot-TI WORM/IRC backdoor trojan!
Microsoft Update WINMGARD.EXE
X
Added by the W32/Rbot-BI trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update wuamgrd16.exe
X
Added by the W32/Rbot-BQ trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update wuamgrb.exe
X
Added by the W32/Rbot-BS trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update wssvrs.exe
X
Added by the W32/Rbot-BV trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
MICROSOFT UPDATE WUAGTRD.EXE
X
Added by the W32/Rbot-CJ trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update winsyst.exe
X
Added by the W32/Rbot-DL trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update wingrd32.exe
X
Added by the W32/Rbot-DW trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update wangard.exe
X
Added by the W32/Rbot-LH trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update wkfix.exe
X
Added by the W32/Rbot-ABZ. This worm connects to an IRC server on startup where it waits for remote commands. ... Read More
Microsoft Update win-mang.exe
X
Added by the W32/Rbot-AFK worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update wuamkop.exe
X
Added by the W32/Rbot-AFI worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
microsoft update wuamkop32.exe
X
Added by the RBOT.BGU WORM! ... Read More
Microsoft Update wuamk032.exe
X
Added by the W32/Rbot-AHD worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Update wininit.exe
X
Added by the W32/Rbot-AKR worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. Please note that ... Read More
microsoft update Wudates.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft Update wuamgrd3.exe
X
Added by the W32/Rbot-AMC worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Update wuamk0032.exe
X
Added by a variant of the Rbot worm and IRC backdoor.
Microsoft Update windows32.exe
X
Added by the W32/Rbot-BHQ worm and IRC backdoor.
Microsoft Update wuampd.exe
X
Unidentified worm.
Microsoft Update windoc.exe
X
Added by the WORM_SDBOT.PF worm and IRC backdoor.
Microsoft Update win32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Update WinDrv32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Update wkops.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Update 32 wininit.exe
X
Added by the W32/Rbot-AKD worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. Please note that ... Read More
Microsoft Update 32 wininit32.exe
X
Added by the W32/Rbot-AKJ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
microsoft update 32 winitXP32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft Update 32 wiit.exe
X
Added by the W32/Rbot-AMS worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Update 32 winnit.exe
X
Added by the W32/Rbot-AOM worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update 32 winin.exe
X
Added by the W32/Rbot-ARR worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. ... Read More
Microsoft Update 32 wuinit.exe
X
Added by the W32/Agobot-UE worm and IRC backdoor.
Microsoft Update 32 windowsp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Update 64 BIT wininit32.exe
X
Added by the W32/Rbot-AHE worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Update 64 BIT winman32.exe
X
Added by the W32/Rbot-AKI worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Update 64 BIT winl32xe.exe
X
Added by the W32/Rbot-AQO worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
MICROSOFT UPDATE CONFIGURATION WIN32SNC.EXE
X
Added by the RBOT-AI WORM!
Microsoft Update Debugger wincfg32.exe
X
Added by the W32/Rbot-DT trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update Device Drivers wuauclt.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans. This infection should not be confused with the legitimate C:\Windows\System32\wuaucl ... Read More
Microsoft Update Emulator wuaddsff.exe
X
Added by the W32/Rbot-GX trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update Engine wumgpds.exe
X
W32/Rbot-WK WORM! File is found in the Windows system folder.
Microsoft Update Loaders 2005 winusers.exe
X
Added by the W32/Rbot-AIQ worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
microsoft update loaders 2006 winusersystem32.exe
X
Added by a variant of the AGOBOT/GAOBOT WORM! ... Read More
Microsoft Update Machine winini.exe
X
Added by the RBOT-KV WORM!
Microsoft Update Machine wuawx.exe
X
Added by the RBOT-CE WORM!
Microsoft Update Machine winupdt.exe
X
Added by the RBOT-FP WORM!
Microsoft Update Machine wuamgd.exe
X
Added by the SDBOT.HQ WORM!
Microsoft Update Machine wupdt32x.exe
X
Added by a variant of the SDBOT WORM!
Microsoft Update Machine windowsu.exe
X
Added by a variant of the RBOT WORM!
Microsoft Update Machine wininigo.exe
X
Added by a variant of the RBOT WORM!
Microsoft Update Machine winmgr.exe
X
Added by a variant of the RBOT WORM!
Microsoft Update Machine Winmsixp32.exe
X
Added by the RBOT.DN WORM!
Microsoft Update Machine Winregs32.exe
X
Added by the RBOT.DN WORM!
Microsoft Update Machine winxpini.exe
X
Added by the RBOT-OB WORM!
Microsoft Update Machine wuamgrd.exe
X
Added by the RBOT-HE WORM!
Microsoft Update Machine wuagrd.exe
X
Added by the RBOT-GF WORM!
Microsoft Update Machine winhost.exe
X
Added by the RBOT-GK WORM!
Microsoft Update Machine winss.exe
X
Added by the RBOT.JU WORM!
Microsoft Update Machine WUAMGRDXS.EXE
X
Added by the RBOT-GL WORM!
Microsoft Update Machine wupdate32.exe
X
Added by a variant of the WIN32.RBOT WORM!
Microsoft Update Machine WININI2.EXE
X
Added by the W32/Rbot-FR trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update Machine winftp32.exe
X
Added by the W32/Rbot-JX trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Update Machine winortho.exe
X
Added by the W32/Rbot-NW trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These ... Read More
Microsoft Update Machine winnie.exe
X
Added by the W32/Rbot-ACD worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
microsoft update machine wins32.exe
X
Added by the RBOT.EZ WORM! ... Read More
microsoft update machine wins32.exe
X
Added by the RBOT.EZ WORM! ... Read More
Microsoft Update Machine wftestb.exe
X
Added by the W32//Rbot-AFZ worm. When started, this infection connects to an IRC server where it waits for remote commands to execute. ... Read More
Microsoft Update Machine wlimyc.exe
X
Added by the W32/Rbot-GQN worm and IRC backdoor.
Microsoft Update Machine winsys.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Microsoft Update Machine wuampd.exe
X
A variant of the Rbot-UT family of worms and IRC backdoor Trojans.
Microsoft Update Machine WINDOWSUPDATE.exe
X
A variant of the Rbot.bwj family of worms and IRC backdoor Trojans.
Microsoft Update Machine winmanwan.exe
X
A variant of the RBot family of worms and IRC backdoor Trojans.
Microsoft Update Machine winupdte.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Update Manager WINRLS.EXE
X
Added by the RBOT-AF WORM!
Microsoft Update Manager wupdate.exe
X
Added by the W32/Rbot-BIA worm and IRC backdoor.
microsoft update process wmipcvse.exe
X
Added by the TROJ/AGOBOT-JF TROJAN! ... Read More
Microsoft Update Services wsnfty.exe
X
Added by the W32/Rbot-AFU worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Update Services wcsnfty.exe
X
Added by the W32/Rbot-AGK worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Update Time wuam.exe
X
Added by the RBOT-M WORM!
Microsoft Update USB2 wuammgrd32.exe
X
Added by the W32/Rbot-ADT worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
Microsoft Update Win32a winupdate32a.exe
X
Added by the RBOT-LO WORM!
Microsoft Update Win32x winupdate32x.exe
X
Added by the W32/Rbot-AJN worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Updater winupdate.exe
X
Added by the Troj/Agent-KIR Trojan.
microsoft updater resources WinFixd32.exe
X
Added by the SPYBOT.CA WORM! ... Read More
Microsoft Updaters Pros WINDLL32XP.EXE
X
Added by the SPYBOTTER.GEN VIRUS!
Microsoft Updates wuamgrds.exe
X
Added by a Rbot variant.
Microsoft Updates wkssvrs.exe
X
Added by the W32/Rbot-EB trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Updates wtemp32.exe
X
Added by the W32/Rbot-AHQ worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Updates winit.exe
X
Added by the W32/Sdbot-CSB worm and IRC backdoor.
Microsoft Updates wkssvr.exe
X
Added by the WORM_RBOT.R worm and IRC backdoor.
Microsoft Updates wgcptsud.exe
X
Added by the W32/Rbot-GTF worm and IRC backdoor.
microsoft updates 2 usb wgafixer.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft UpdateS Machine wgrd.exe
X
Added by the W32/Rbot-FI trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This ... Read More
Microsoft Updates Resources WinFixIDs.exe
X
Added by a variant of the RBOT WORM!
Microsoft Updating WAMQUARD.EXE
X
Added by the W32/Rbot-BX trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Updating WUAMGUARDS.EXE
X
Added by the W32/Rbot-BY trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
microsoft updating client websvc.exe
X
Added by the RBOT.AQ WORM! ... Read More
Microsoft Updote wins0cks.exe
X
Added by the W32/Rbot-ARG worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. The file name ... Read More
Microsoft Updote winmsg.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Validation Service wmiprsv.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
Microsoft video capture controls winshosts.exe
X
Added by the W32/Sdbot-MP worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Visual Application winsyshp.exe
X
A variant of the SDBot.blt family of worms and IRC backdoor Trojans.
Microsoft Visual SourceSafe winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup or the Microsoft Visual ... Read More
Microsoft Visual Studio w32mvs.exe
X
Identified by VBA32 as a variant of the Backdoor.Win32.Agent.cjo malware.
Microsoft wd windmrg.exe
X
Added by the W32/Rbot-EEF worm and IRC backdoor.
Microsoft Web CP Manager webcp32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
microsoft web device wdevice.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Microsoft web update webmsn.exe
X
Added by the W32/Rbot-EMQ worm and IRC backdoor.
Microsoft Win Update WinUP.exe
X
Added by the W32/Rbot-BPR worm and IRC backdoor.
microsoft wind0ws updater winsupdater.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
MicroSoft Window Updater winsupdater.exe
X
Added by W32/Rbot-ZZ.
Microsoft Windows windets.com
X
Added by the Troj/Flood-EQ backdoor Trojan.
Microsoft Windows 2000 Winupdsdgm.exe
X
Added by the GAOBOT.AO WORM!
Microsoft Windows 32 Update win32update.exe
X
Part of the IRCBot family of worms and backdoors.
MicroSoft Windows Command wincmdXP.exe
X
Added by the W32/Tilebot-CC worm and IRC backdoor.
Microsoft Windows Communicator for NT/XP wincomm.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Windows Config 32 win32conf.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Windows DLL Services Configuration winDSL.exe
X
Added by the W32/Sdbot-ZG worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
microsoft windows dll services configuration windir32a.exe
X
Added by a variant of the SDBOT.BHF WORM! ... Read More
Microsoft Windows DLL Services Configuration windir32.exe
X
Added by the W32/Sdbot-ABM worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Windows DLL Services Configuration windll32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Windows Drivers windrv.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Windows DVR windvr.exe
X
Added by the W32/Rbot-AXD worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoft Windows Express websploit.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft windows FTPd winnthosts.exe
X
A variant of the W32/Rbot-FUS family of worms and IRC backdoor Trojans.
Microsoft Windows GUI Windowz.exe
X
Added by the RANDEX.AEV WORM!
Microsoft Windows Kernel Services winkrnl386.exe
X
Added by the ZEBROXY TROJAN!
Microsoft Windows Loader wloader.exe
X
Added by a variant of the AGOBOT/GAOBOT WORM!
Microsoft Windows Loader windat32.exe
X
Added by the W32/Rbot-LU trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft windows log service winlog.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Windows Logon Process winlogon.exe
X
Added by the Troj/Proxyser-R proxy Trojan. This malware is also commonly bundled with rogue anti-spyware program. ... Read More
Microsoft Windows Man Service winmgr.exe
X
Added by the W32/Sdbot-DTL worm and IRC backdoor. W32/Sdbot-DTL spreads to other network computers over network shares and by exploiting common buffer ... Read More
Microsoft Windows Media Player wimp.exe
X
Added by the RBOT-FN WORM!
Microsoft Windows Registry Service wregistry.exe
X
A Rbot WORM/IRC backdoor variant adds the file, making possible DoS attacks, running of a file server, password theft or a remote command shell put i ... Read More
Microsoft Windows Registry Updater wreg.exe
X
Added by the W32/Forbot-DN WORM/IRC backdoor trojan, while it creates a new service called wreg. ... Read More
Microsoft Windows Runtime DLL Services WINDEV.EXE
X
Added by the W32/Randex-M worm. When started, this infection connects to an IRC server where it waits for remote commands to execute. ... Read More
Microsoft Windows Secure windocs.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Windows Securety wurguar.exe
X
Added by the RBOT-KY WORM!
Microsoft Windows Security wscndrives.exe
X
Added by the W32/Rbot-AJK worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
microsoft windows service winsys.exe
X
Added by the W32/Rbot-ADP ... Read More
Microsoft Windows Service Pack winspkn.exe
X
Added by the W32/Rbot-AYD worm and IRC backdoor.
microsoft windows services controller wservices.exe
X
Added by the WIN32.RBOT.FD WORM!
Microsoft Windows Socketx32 Services winsockx32.exe
X
Added by the W32/Rbot-FWT worm and IRC backdoor.
Microsoft Windows Storage Machine Service winms.exe
X
Added by the W32/Rbot-AHK WORM/IRC backdoor trojan!
Microsoft Windows System Windows.exe
X
Added by the W32/Zotob-L mass-mailing worm and IRC backdoor.
MICROSOFT WINDOWS SYSTEM 2 winds.exe
X
Added by the WORM_MYTOB.OD mass-mailing worm and IRC backdoor.
microsoft windows system service manager winsvc.exe
X
Added by the SPYBOT.LR WORM! ... Read More
Microsoft Windows System32 winservs.exe
X
Added by the W32/Tilebot-GU worm and IRC backdoor.

W32/Tilebot-GU spreads to other network computers by exploiting common buffer overfl ... Read More
Microsoft Windows TCP Analysis winmwta.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Microsoft Windows TCP Protocol wintcps.exe
X
Added by the W32/Sdbot-DIY worm and IRC backdoor.
Microsoft Windows Updata windows.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Windows Update wuautcl.exe
X
Added by the Troj/Spybot-NQ worm and backdoor Trojan.
Microsoft Windows Update Windows Update.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Windows Update windowsapp.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Windows Update WINUPDATE.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Windows Update 32 winupdate32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
microsoft windows update application wuap.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
microsoft windows update logon win-logon.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Microsoft Windows Update Service wupdmgr32.exe
X
Added by the DOS.AUTOCAT TROJAN!
Microsoft Windows Updater winupdgm.exe
X
Added by the GAOBOT.BI WORM!
Microsoft Windows Updater WINIUPDATES.EXE
X
Added by the RBOT-KK WORM!
Microsoft Windows Updater WINUPDATE.EXE
X
Added by the SDBOT-PU WORM!
Microsoft Windows Updater win32upd.exe
X
Added by the RBOT-EC WORM!
Microsoft Windows Updater WINFIX.EXE
X
Added by the W32/Rbot-CM trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Windows Updater WINDATES.EXE
X
Added by the W32/Rbot-H trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Windows Updater2 WINUPDATE2.EXE
X
Added by the W32/Rbot-GTR worm and IRC backdoor.
Microsoft Windows Updates wsap32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Windows WinSaSS Management winsass.exe
X
Added by the W32/Rbot-APW worm and IRC backdoor.
Microsoft Windows XP/2K Explorer winexplorer.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Winedows startup WinKey.exe
X
Identified as a variant of the Net-Worm.Win32.Kolabc.bzi malware.
Microsoft WINGS32 Protocol WinSGR32.exe
X
Added by the W32/Rbot-APU worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft WinRaR winrar.exe
X
Added by the W32/Rbot-AEC worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft Winsock Wrapper ws2_32s.exe
X
Added by a variant of the SPYBOT WORM!
Microsoft Winsock32 System winsock32.exe
X
Added by the W32.Spybot.AKKC worm and IRC backdoor.
microsoft winupdate Winamp61.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
microsoft winupdate WinNTinit32.exe
X
Added by the RBOT.VS WORM! ... Read More
Microsoft Word WINWORD.EXE
X
Added by the W32.Kangero.A worm. W32.Kangero.A is a worm that copies itself to mapped drives. It also lowers security settings on the compromised comp ... Read More
Microsoft Works Calendar Reminders wkcalrem.exe
N
Produces a pop-up reminder of events scheduled using the MS Works Calendar
Microsoft Works Portfolio WksSb.exe
N
The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program.Can be prevented from starting from a s ... Read More
Microsoft Works Update Detection wkdetect.exe
N
Checks for updates to MS Works
Microsoft World Service winworld.exe
X
Added by an unidentified IRC worm with backdoor capability!
Microsoft WPCEmail wpcem.exe
X
Added by the Troj/Sniffer-N Trojan. Troj/Sniffer-N monitors network traffic for email addresses. Harvested addresses are submitted to a preconfigured ... Read More
Microsoft wscntfy Service wscntfy.exe
X
Added by the Troj/Tanto-H Trojan. This infection should not be confused with the legitimate C:\Windows\System32\wscntfy.exe file. ... Read More
Microsoft X Update wuamkoppnp.exe
X
Added by the W32/Rbot-ANI worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
microsoft xp systems loader winsystem32xp.exe
X
Added by the W32.KELVIR.W WORM! ... Read More
microsoft xp systems loaders win32xpsys.exe
X
Added by the W32.SPYBOT.NYT WORM! ... Read More
Microsoft XP TCP Ack Timing winxptcp.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Microsoft-Update wngard.exe
X
Added by the RBOT-JV WORM!
microsoftf ddes control wees.exe
X
Added by a variant of the the RBOT.BOF WORM! ... Read More
Microsoftf DDEs Control why-.exe
X
Added by the W32/Rbot-AMV worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsoftf DDEs Control w33s.exe
X
Identified as a variant of the RBot family of worms and IRC backdoors.
Microsoftf DDEs Control waes.exe
X
Identified as a variant of the RBot family of worms and IRC backdoors.
MicrosoftNAPC wupdate.exe
X
Added by the Troj/Agent-LAY Trojan.
MicrosoftOfficeTools Winece.exe
X
Added by the Troj/Docscar-A Trojan.
Microsofts media winmplayd.exe
X
Added by an undidentified WORM or TROJAN!
microsofts media wingtp.exe
X
Added by the W32/RBOT-VO WORM! ... Read More
Microsofts MediaScope winmedplay.exe
X
Added by a variant of the WIN32.RBOT WORM!
Microsofts MediaScope winmep.exe
X
Added by the W32/Rbot-WB worm. When started this infection connects to a remote IRC server where it waits for commands to execute. These infections ... Read More
MicrosoftServiceManager Wintsk32.exe
X
Added by the YAHA.U WORM!
MicrosoftUpdate WinUp32.exe
X
Added by an unidentified VIRUS, WORM or TROJAN!
MicrosoftUpdate windll.exe
X
Added by the W32/Rbot-IH trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This i ... Read More
MicrosoftWindows windows32.exe
X
Added by the Troj/PWS-BOQ Trojan.
Microsotufed Update 32 windinit.exe
X
Added by the W32/Rbot-CTJ worm and IRC backdoor.
Micrsoft Driver windrive.exe
X
Added by the SDBOT.AF TROJAN!
Micsorosft Security Center wcnsfty.exe
X
Added by the W32/Rbot-AHU worm. When infected your computer will become an open mail relay which will allow your computer to be used to send out spam. ... Read More
Mims service winmngr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Miosf Update wimsqaad.exe
X
Added by the SDBOT.AG TROJAN!
mIRC Exchanger wavasdw.exe
X
Added by the W32/Sdbot-UO worm. When connected this infections connects to an IRC server where it waits for remote commands to execute. ... Read More
mircosoft update wuampkd.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
mismo win32x.exe
X
Added by the W32/Rbot-JP trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This ... Read More
mjd w32_mjd.dll
X
Identified as a variant of the W32.Mimbot malware.
Mlcr0s0ftf DDEs C0ntr0i WAed.pif
X
Added by the W32/Rbot-BJW worm and IRC backdoor.
Mlcrosoft Updates wmwplayers.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MMCWINMGMT winmgmt.exe
N
Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer he ... Read More
Mobipocket Web Companion webcomp.exe
U
Installed by Mobipocket Reader to create readable documents from RSS or eNews feeds on the web. ... Read More
mobiswing webp.exe
X
Identified by Kaspersky as a variant of the AdWare.Win32.Agent.bzo malware.
Modifiet Amateur HTPB wuaclt.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Module WinMeter wimmtre.exe
X
Added by the W32/Sdbot-BE backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execut ... Read More
Monitor Infrared Output WinMIO.exe
X
Identified as Rbot.cnk family of worms and IRC backdoor Trojans.
Monitor Infrared System WinMIS.exe
X
A variant of the RBot family of backdoor worms. Identified as Backdoor.Win32.Rbot.bll by Kaspersky Antivirus. ... Read More
ms builders Wupated.exe
X
Added by the W32/AGOBOT-SS WORM! ... Read More
MS Dns Service wincntrl.exe
X
Added by the W32/Tilebot-BR worm and IRC backdoor.
Ms Java for Windows NT WunosJava.exe
X
Added by the WORM_RANDEX.AM network worm.
MS Java Service Wrapper Windows NT & XP wrapper.exe
X
Added by the W32/Vanebot-D worm and IRC backdoor.
Ms load for Windows NT winskd.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MS NET Service wiadss.exe
X
Identified as a variant of the Net-Worm.Win32.Kolabc.b worm.
ms ownage winPE.exe
X
Added by the W32/Rbot-AJL worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
MS PLUS INC wpad.exe
X
Added by the W32/Mytob-AN mass-mailing worm.
MS Service Drivers winscv.exe
X
Added by the W32/Sdbot-COG worm and IRC backdoor.
Ms sock for Windows NT winser.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MS Unix Binary Win32Update.exe
X
Added by the W32/Rbot-BAS trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
MS Unix Binary WinGuard.exe
X
Added by the W32/Rbot-ACL worm. When started, this infection connects to an IRC where it waits for remote commands to execute. ... Read More
MS Unix Binary win32ttb.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MS Unix Binary wrdpad05.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Ms Update WinServices NT/XP winservnt32.exe
X
Added by the W32/Vanebot-G worm. W32/Vanebot-G spreads to other network computers by exploiting common buffer overflow vulnerabilities, including: SRV ... Read More
MS-Connect web.exe
X
Adult content dialler - see here
MS-Windows Login Service winlogin32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
mscheck wincheck071008.dll
X
Identified as a variant of the Trojan-Spy.Win32.Agent.adq malware.
msconfig wins.exe
X
Added by an unidentified IRC WORM with backdoor trojan capabilities!
msconfig winlog.exe
X
Added by the Troj/IRCBot-TJ Trojan.
MSControl31 winnsyst.exe
X
Added by the W32/Rbot-APF worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
msennger winfix.com
X
Added by the Troj/IRCFlood-R Trojan. When used with an IRC client, it can be used to provide DDoS attacks. ... Read More
msgina wuauclt2.exe
X
Added by the Troj/Iyus-H TROJAN!
Msgw32 WINMSG32.EXE
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MSIdll winmp.exe
X
Added by a variant of the RBOT WORM!
MSMSGNER wcbi.exe
X
Added by the Troj/Bckdr-QMS backdoor Trojan.
MSMSGS winlogon.exe
X
Added by the W32/Brontok-BS worm. This infection should notbe confused with the legitimate C:\Windows\System32\winlogon.exe program. ... Read More
MSMSGS WINLOGON.EXE
X
Added by the W32.Korron.B worm. W32.Korron.B is a worm that replaces some file types with a copy of itself. It also copies itself to all accessible dr ... Read More
msn winlogon.exe
X
Added by the BKDR_PROSTI.A backdoor. This infection should not be confused with the legitimate microsoft file C:\Windows\System32\winlogon.exe. ... Read More
MSN winlog32.exe
X
A variant of the Backdoor.IRCBot.acd family of worms and IRC backdoor Trojans.
MSN wkssvr.exe
X
Added by the W32/IRCBot-XT worm.
MSN wksvr.exe
X
Added by the W32/IRCBot-XU worm and IRC backdoor.
MSN win32dll.exe
X
Added by the Troj/Jenny-A Trojan.
MSN wplayer.exe
X
Added by a variant of the Win32/Pushbot worm and IRC backdoor. Win32/Pushbot is a family of worms that spread using MSN Messenger. ... Read More
MSN winsystem.exe
X
Added by the W32/Sdbot.worm.gen.a worm and IRC backdoor.
MSN wdlrss.exe
X
Identified as a variant of the Backdoor.Win32.SdBot.cwm worm and IRC backdoor.
MSN wkssvrs.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MSN wmev.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MSN winmedia.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MSN Live Login Mgr wlloginmsgs.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MSN Messanger Live winntmsn.exe
X
Added by the W32/Rbot-FSO worm and IRC backdoor. W32/Rbot-FSO spreads via network shares with weak passwords and the following vulnerabilities : LSASS ... Read More
msn messeng windns.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
MSN Service wuampskum.exe
X
Added by the W32/Rbot-KC trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This i ... Read More
MSN Service Updates winproc.exe
X
Added by the W32/Kelvir-BB instant messenger worm.
Msn Updater windatemanager.exe
X
Added by the SDBOT.TS WORM!
MsnExplorer winagent.exe
X
Added by Troj/Bdoor-EQ, a backdoor TROJAN found in the Windows folder.
msnnt winampb.exe
X
Identified as a variant of the Trojan.Win32.Agent.tl malware.
MSOleath32 winss.exe
X
Added by the Kather Trojan. This infection should not be confused with the legitimate winss.exe used by Windows Live One Care. ... Read More
mspp system update 64 wiaadmgr.exe
X
Reported by Kaspersky Anti-Virus as Trojan-Proxy.Win32.Ranky.gen.
MsSecurity Updated winself.exe
X
Added by the TROJ_DNSCHANG.EU Trojan.
mssonfig winupdate.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MSStartOptimizer WINUPD.EXE
X
Adult content dialler - see here. This has to be cleared at the same time as RegCompres (REGCPM32.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), ... Read More
MSSysInterv winself.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Small.ufd malware.
MsTask wstask32.exe
X
Added by the W32/Mytob-FE worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
MStask win2sys.dll
X
Added by the Troj/Dropper-BS dropper Trojan.
MSUpdate wupd.exe
X
Added by the ALADINZ.M TROJAN!
MSUpdate winup.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
MSUpdater winnoob.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
msupdates win32chk.exe
X
A variant of the Backdoor.Win32.SdBot.aad family of worms and IRC backdoor Trojans. ... Read More
mswindows drt drivers wsdrt32.exe
X
Added by the RBOT.ALT ... Read More
MSWinlogon Winlogon.exe
X
Added by the Troj/Small-EJW Trojan.
MSWinupd winupd.exe
X
Added by the Troj/Dloader-YE downloader Trojan.
MSWinupd winnampis.exe
X
Added by the TROJ_BANLOAD.BEX Trojan.
MSWinupdate winupdate.exe
X
Added by the Troj/Dloadr-AAW Trojan.
MS_Update Check wdfmgr.exe
X
Added by the W32/Agobot-TB worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
Multimedia windebug.exe
X
Added by the W32/VB-ERB worm.
mynsw wntsrv.exe
U
Added by the Spyware.NetScreenWatch surveillance software. Spyware.NetScreenWatch is a spyware program that monitors user activity on the compromised ... Read More
MyPointsPointAlert wjview ...MyPointsPointAlertrun.exe
X
"With MyPoints you can earn rewards from name-brand merchants. You can even earn vacations and frequent flyer miles". Dubious privacy policy ... Read More
mysoft winexplor.exe
X
Homepage hijacker
NAV Agent winsnav.vbs
X
Added by the ANPES WORM!
NAV Agent wmilib32.exe
X
Added by the Troj/VB-XU trojan.
Navegate wisterd.exe
X
Added by the Troj/Banker-BOS spyware Trojan
NB Windows Patterns WINDBKGND.EXE
N
Part of McAfee Nuts & Bolts. With Background Patterns, you can change background patterns of wizard and dialog windows ... Read More
NCplDeamon winservicess.exe
X
Identified as a variant of the Backdoor.Win32.SpyBoter.ci malware.
NDIS Adapter windows.exe
X
Added by the FORBOT-BR WORM!
NDplDeamon winlogin.exe
X
Added by the RANDEX.E WORM!
Nero Updater.6.12 wmp9.exe
X
Added by the W32/Agobot-AAG worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
neroupdater6.8 winjava.exe
X
Added by the AGOBOT.AMK WORM! ... Read More
Net WINREG.EXE
X
Added by the ASSASIN.D TROJAN!
NET Service wmssvc.exe
X
Added by the Troj/Trinity-C Trojan.
NetApp winserv.exe
X
Added by the SHADOWTHIEF TROJAN!
NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver wg111v2.sys
Y
Driver for the Netgear WG111 USB wireless adapter.
NETGEAR WG111v2 Smart Wizard WG111v2.exe
N
Setup and diagnostics program for the Netgear WG111v2 wireless USB adapter.
NETGEAR WG311v2 Smart Configuration wlancfg5.exe
U
This is Netgear's program for running it's wireless network cards. This program can also configure your wireless settings and monitor your throughput. ... Read More
NetPatrol winclient.exe
U
NetPatrol network monitoring software
NettGain2000 WgwMngr.exe
Y
Required for Starband satellite service.
Netunit32 wunit32.exe
X
Added by an unidentified WORM or TROJAN!
network access winssh.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Network ADSL Server woaisaomm.exe
X
Added by the Troj/GrayBrd-AQ backdoor Trojan.
Network Client winlogon.exe
X
Added by the Trojan.Boxed.E Trojan.
Network DDE DSDM WinDDE.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Network Protocol Service wuamgrd.exe
X
Added by the RBOT.EA WORM!
Network protocol service wintcp.exe
X
Added by a variant of the AGOBOT/GAOBOT WORM!
NetworkDiskRun winzsq.exe
X
Added by the Troj/Stinx-G worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
NetworSVSA wnipsvr.exe
X
Added by the W32.Bratsters worm.
ni.uwa6p_0001_n56m1001 WinAntiVirusPro2006Installer.exe
X
Related to the WinAntivirus programs: bogus, stealth installed "Spyware remover" - see the SpywareWarrior_List of Rogue/Suspect Anti-Spyware Products ... Read More
ni.uwa6p_0001_n69m0303 WinAntiVirusPro2006Installer[1].exe
X
Related to the WinAntivirus programs: bogus, stealth installed "Spyware remover" - see the SpywareWarrior_List of Rogue/Suspect Anti-Spyware Products ... Read More
Norton Service Driver wsul.exe
X
Added by the W32/Rbot-ABI. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infections a ... Read More
Norton Updater winset.exe
X
Added by a variant of the SPYBOT WORM!
NortonAVProtect WliveUPdate.exe
X
Added by the Backdoor.Futh backdoor. This infection listens on TCP ports 7896 and 7897 awaiting commands. ... Read More
notn wtta.exe
X
PurityScan/Clickspring adware ... Read More
Novell ZfD Wake on LAN Status Agent WolSerNT.exe
Y
Part of the Novell Windows Client. The service name is Prometheus Wake-On-LAN Status Agent. It is found in the C:\Program Files\Novell\ZENworks\Remote ... Read More
NT LM Security Support Provider WinNTLM.exe
X
Identified as the SdBot.bil worm and IRC backdoor.
NtDIC(ntdic) winz0r.exe
X
Added by the W32/Tilebot-D worm and IRC backdoor.
NTP winlogon.exe
X
Added by the Troj/Jtram-D IRC backdoor Trojan.
NTSF MICROSOFT SYSTEM wntsf.exe
X
An Rbot variant. This infection connects to an IRC server where it will await commands from a remote user. ... Read More
NTSF MICROSOFT SYSTEM win32db.exe
X
Added by a variant of the RBOT WORM!
ntsf microsoft system winsis32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
NTSF MICROSOFT SYSTEM WinAbring.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
nvchost winlogon.exe
X
Added by the Troj/Klone-J Trojan. This infection should not be confused with the legitimate file C:\Windows\System32\winlogon.exe. ... Read More
NvCpIDeamon WUAUMQR.EXE
X
A variant of the SpyBot.ag family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
NvCplDaemonTool wtload08.dll
X
Added by the Troj/Sinowa-Gen Trojan. Please note C:\Windows\System32\rundll32.exe is a legitimate file and should not be deleted. ... Read More
NvCplScan winasp.exe
X
Added by a variant of the RBOT WORM!
NVIDIA Media Center Library winlogon.exe
X
Added by the W32/AutoRun-AZK removable media worm.
OEPowerPlugs winoeinit.exe
?
??
OKGO winutade.exe
X
Added by the Troj/Banker-EHZ online banking Trojan. If you are infected with this file you should immediately contact your banks and change your onli ... Read More
OLE Automation Module Wsthunk.dll
X
Added by the Backdoor.Thunker Trojan.
oledll wmldap.dll
X
Identified as a variant of the Trojan-PSW.Win32.Agent.uv malware.
onecareui winssnotify.exe
Y
Part of the Windows Live OneCare support package from Microsoft.
ooocromosomasgenetics Winlogon.vbs
X
Added by the VBS.Wisfidix worm. VBS.Wisfidix is a worm that spreads to preconfigured mapped drives on the compromised computer. Please note that the ... Read More
OSA winword.exe
X
Added by the Trojan.Kangenie trojan.
OWCWebCamDV wcdvtray.exe
U
WebCamDV from Orange Micro, Inc - enables the user to use a DV camera connected via Firewire as a Webcam ... Read More
PaRaY_VM winlogon.exe
X
Added by the W32/Autorun-DV removable media worm. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
Patches Value WinGamed.exe
X
Added by the SDBOT.BR WORM!
Patches Value WinGasys.exe
X
Added by the W32/Rbot-GD trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Performs peer to peer connection WinPTTP.exe
X
Added by the W32/Rbot-GMI worm and IRC backdoor.
Pervasive.SQL Workgroup Engine W3dbsmgr.exe
U
Database Service Manager for Pervasive SQL 2000 Workgroup edition. Required if you use Pervasive SQL but it's recommended you start it manually before ... Read More
PivotSoftware wpctrl.exe
N
PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties ... Read More
Platform SDK Enviroment win32ssr.exe
X
Added by the W32/Rbot-BSD worm and IRC backdoor.
Player00997 WliveUPdate.exe
X
Added by the Backdoor.Futh backdoor. This infection listens on TCP ports 7896 and 7897 awaiting commands. ... Read More
Plug and Play wininet32.exe
X
Added by the Troj/Raznew-B trojan proxy server. This infection allows remote computers to use the Internet through your computer to hide their tracks ... Read More
PMedia winsrvc.exe
X
Internet marketing sofware from PMedia as used in E-Card FriendGreetings foistware - see here. Treated by Trend as the FRIENDGRT.B WORM! ... Read More
PNP wuaaclt.exe
X
Added by the W32/Lilbre-A worm.
pnpext wmc.exe
X
Added by the Troj/LeechPie-D Trojan.
popmark WinTask.exe
X
"Pop Marketing" adware
PPPOEOE WINLITE.EXE
X
Added by the W32/Rbot-AAN WORM/IRC backdoor trojan!
Print System Service wlpnsv.exe
X
Added by the Backdoor.Win32.SdBot.aad worm and IRC backdoor.
Printer Monitor webprinter.exe
X
A TROJAN, Troj/IRCBot-Z adds this file to the Windows system folder.
pro winstall.exe
X
Added by the Troj/Spywad-V Trojan.
Proc993 wqxfne.exe
X
Added by the W32/Ixbot-D worm and IRC backdoor.
Prog winsys.exe
X
Added by the Siteno.Trojan trojan.
Program sieciowy dla SAGEM Wi-Fi 11g USB adapter WLANUTL.exe
U
Generic wireless configuration utility used by many wireless brands.
Q152404 wsript.exe Q152404.VBS
N
Appears to run Scandisk at bootup on NEC PCs
Qualys wmpirvse.exe
X
Identified as a variant of the Worm:Win32/Mytob.SA mass-mailing worm.
Quernt wntfy.exe
X
Added by the W32/Autorun-PF removable media worm.
quicken Winrar.exe
X
CoolWebSearch parasite variant. Note - this is not the file zipping utility also known as WinRAR! ... Read More
quicken Waol.exe
X
CoolWebSearch parasite variant
QuickTask WliveUPdate.exe
X
Added by the Backdoor.Futh backdoor. This infection listens on TCP ports 7896 and 7897 awaiting commands. ... Read More
Quicktime Mediaplayer winmplyer32.exe
X
Added by the RBOT-PM WORM!
quicktime mediaplayr wnmplyr.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Quicktime Pro 3.0 winuodps.exe
X
Added by the GAOBOT.BH WORM!
random 10-character filename Winupdates.exe
X
Added as result of a W32/Rbot-MM worm infection ... Read More
real spy monitor Winrsm.exe
U
Realspy keystroke logger/monitoring program - remove unless you installed it yourself! ... Read More
Reg Service winsy.exe
X
Added by a variant of the SPYBOT WORM!
Reg Service WinnConfig.exe
X
Added by the W32/Agobot-PF network worm.
Reg Service winslogon.exe
X
Added by the W32/Agobot-SC WORM!
Reg Services Winboot32.exe
X
Added by the RBOT.PB WORM!
regdiit win.exe
X
Added by the W32/VBSAuto-A worm and IRC backdoor.
regdiit winxp.exe
X
Added by the W32/Autorun-ALB removable media worm.
RegDone winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! ... Read More
Registry wscript.exe
X
Added by the VBSWG.AQ WORM!
Registry Checkup winreg.exe
X
Added by an unidentified WORM or TROJAN!
Registry Checkup System326a Monitor Winregs326a.exe
X
Added by a variant of the W32/SDBOT WORM!
Registry Checkup System32cd Monitor Winregs32cdn.exe
X
Added by the W32/Rbot-AAV WORM/IRC backdoor trojan!
Registry Integritycheck WCPDT.EXE
X
Added by the W32/Agobot-RF WORM.
Registry Loader winhlpp32.exe
X
Added by the GAOBOT.AO WORM!
registry oidet win32.exe
X
Added by the RBOT.BMT WORM! ... Read More
registry value name winapi32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
RegistryChk winbackup.exe
X
Added by the MERTIAN WORM!
Regkey for autostart winservice.exe
X
Added by the W32/Rbot-NU trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These ... Read More
regManager WinSevices.exe
X
Added by the W32/VB-DZJ worm.
regrun winfix22490.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
RegRun WinBait winbait.exe
U
Part of RegRun - used to detect unknown viruses. RegRun compares winbait.exe with the original copy called winbait.org and warns if the files are ... Read More
Regrun2 WatchDog.exe
Y
Greatis Software's RegRun 3 Security Suite which amongst other things replaces MSCONFIG. The WatchDog check for registry changes caused by trojan's, v ... Read More
ReloadMicrosoftwin worldcstt2.exe
X
Added by the Troj/Bancos-AZA information-stealing Trojan for online banks. It is advised that you change your online banking passwords if you were in ... Read More
ReloadMicrosoftwinamplay worldcstl2.exe
X
Added by the Troj/Bancos-AYZ information-stealing Trojan for online banks. It is advised that you change your online banking passwords if you were in ... Read More
Remote Desktop Help Session Manager WinRDH.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Remote Procedure Call winrpc.exe
X
Added by the RBOT-KM WORM!
Remote Procedure Call winsysrpc.exe
X
Added by the SDBOT-PS WORM!
Remote Procedure Calls win.exe
X
Added by the SDBOT-QI WORM!
REMOVE ME windos.exe
X
Added by the Troj/Sdbot-JC worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
REPCLIENT1 win.pif
X
Added by the W32/AutoRun-DO removable media worm.
Restart Watch Watch.exe
?
Associated with an Eicon Networks Diva ISDN or ADSL modem. What does it do and is it required? ... Read More
Restart WSC Setting wscrestp.exe
U
WinStart Commander - part of Ultra WinCleaner Utility Suite. Starts Windows faster and controls hidden programs to boost performance and prevent syste ... Read More
Restoreds windrives.exe
X
A new service added by the W32/Agobot-RB WORM/IRC backdoor, it's displayname is Systems Backups . ... Read More
RNBc Test wf32vbs.exe
X
Added by the W32/Rbot-AGR worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
RNBz Test wf32vbc.exe
X
Added by the W32/Rbot-AEY worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
rndc test wf32b.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Rontok winxp.exe
X
Added by the W32.Phoney.A worm. W32.Phoney.A is a worm that spreads through mapped drives. It also lowers security settings on the compromised compute ... Read More
ROOT_Machine winlogon.exe
X
Added by the Troj/Banker-FI Trojan.
RPCserr32g winlogon.exe
X
Added by the W32/Ritdoor-B backdoor worm.
Run MSupdt32 wscript MSupdt32.vbs
X
Added by the CASER WORM!
Run POPFile in background wperl.exe
U
POPFile - E-mail spam blocker
run32dll WINClock.exe
X
Added by an unidentified VIRUS, WORM or TROJAN!
run= wallflip.exe
?
Desktop wallpaper changer?
run= win.ini
?
??
run= wswpd.exe
Y
Used with some models of Panasonic, Epson and NEC printers - required for printer to work ... Read More
run= wmplayer.exe
X
CoolWebSearch parasite variant - Note: this is not the Windows Media Player executable! ... Read More
Rund1l32 Winfi1e32.exe
X
Added by the MERTIAN WORM!
RunDLL32 winupdate.exe
X
Added by an unidentified TROJAN! - possibly a BMBOT variant
Rundll32 Windows.exe
X
Added by the QQPASS.E TROJAN!
runing win.exe
X
Added by the Troj/Delf-LC Trojan.
RunProg wini.exe
X
Added by the OPTIX.04.D TROJAN!
runwinlogon winlogon.exe
X
Identified as a variant of the SpamTool.Win32.Agent.gj malware.
S-1-5-21-1635847982-2902227367-3824404516-500} windoskey.exe
X
Added by the Troj/Dropin-A Trojan.
SadNet winlogon.cab.exe
X
Added by the WORM_NETSAD.A worm.
SadNet3 WinServicces.cab.bak.exe
X
Added by the W32.Amirecivel.F@mm mass-mailing worm.
Sagem - 802.11g Wi-Fi USB Dongle LAN Utility WLANUTL.exe
U
Generic wireless configuration utility used by many wireless brands.
Sagem - Utilitaire réseau pour Clé USB Wi-Fi 802.11g WLANUTL.exe
U
WiFi configuration utility for the Sagem wireless USB dongle.
scApp wmiprvse.exe
X
Added by the W32/SillyFDC-AW worm.
Scheduler winagent.exe
X
Added by the Win32.Tactslay backdoor Trojan.
scheduler service wsass.exe
X
Added by the WIN32.LIOTEN.KX WORM! ... Read More
SCNDmem WINLOW.SYS
X
Added by the Troj/Haxdoor-CN rootkit infection. This file is installed as system driver and is used to hide processes, files, and registry keys from ... Read More
scNine windates.exe
X
Unknown malware.
screws winlogon.exe
X
Added by the W32/VB-DWN worm. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
Secboot w32tm.exe
X
Added by the Backdoor.Haxdoor.D backdoor. Found in the Windows system directory. ... Read More
secboot w32_ss.exe
X
Added by the HaxDoor.B rootkit/backdoor Trojan.
Secure WindowsUpdates.exe
X
Identified as AdWare.Win32.Agent.bm.
SECURE SHELL access driver wartamd.sys
X
A variant of the Haxdoor Trojan rootkit.
secure socket layer wins32a.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Security Accounts Center windowo.exe
X
Added by the Troj/Bckdr-AWQ Trojan.
security centre wscntify.exe
X
Added by the W32.Spybot.AFEW worm and IRC backdoor.
Security Fixers WINCAT32.EXE
X
Added by the W32/Sdbot-NR worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Security Patch WinUpdate32.exe
X
Added by the W32/SdBot-BM backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execut ... Read More
Security Patches wuamgrdr.exe
X
Added by the W32/Rbot-IN trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Security Patches wuamgrdk.exe
X
Added by the W32/Rbot-IQ trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Security Patches wuamgrdn.exe
X
Added by the W32/Rbot-JI trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
security patches WinLab32.exe
X
Added by the W32/SDBOT-KB WORM! ... Read More
Senao Network Controller winsno.exe
X
Added by the W32/Vanebot-AU worm and IRC backdoor.
Serv-U wssdsu.exe
X
Added by the MANIFEST TROJAN!
Server Runtime Process wbemstest.exe
X
Added by the W32/Sdbot-DDB worm and IRC backdoor.
service wN2S.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
service win32ev.exe
X
Added by the Troj/Bckdr-QKR backdoor Trojan.
Service winlogon.exe
X
Unknown malware. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe program. ... Read More
Service Client winsvcli.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Service Monitor WinOcx.exe
X
Added by the W32/Rbot-AQJ worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Service Monitor winxpser.exe
X
Added by the W32/Rbot-BDF worm and IRC backdoor.
Service Process winset.exe
X
Added by a variant of the SPYBOT WORM!
Service System windowsXP.exe
X
Added by the Troj/Bancos-EL Internet banking Trojan which attempts to capture confidential banking information and send it to a remote location. ... Read More
Service System wernell87.exe
X
Added by the Troj/Bancos-FJ Internet Banking Trojan. If you have this infection you should change the passwords to all your online banking accounts. ... Read More
ServiceOptionMP3 winamp.dll.exe
X
Added by the Troj/Samson-A Trojan.
Services winread.exe
X
Added by an unidentified VIRUS, WORM or TROJAN!
services windows32.exe
X
Added by the W32/FlyVB-C worm.
Services32 Startup win32dll.exe
X
Added by the W32/Sdbot-XO. When started this infection connects to an IRC server where it waits for remote commands, able to steal CD game keys, pe ... Read More
ShareSearcher wsusupd.exe
X
Added by the Troj/Enclag-A Trojan.
Shell wmedia16.exe
X
Added by the GOLDUN TROJAN!
Shell wmedia32.exe
X
Added by the Troj/Goldun-B TROJAN!
Shell2938 WliveUPdate.exe
X
Added by the Backdoor.Futh backdoor. This infection listens on TCP ports 7896 and 7897 awaiting commands. ... Read More
shell32 wuauclt10.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Shellwin Time Service Tools winskvc32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
sis32 winsos.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Small.gye malware.
Sistray32 win.bat
X
The W32/Jupir-A is spread via MIRC. The file can be found in the Windows system directory. ... Read More
Sitecom Wireless LAN Utility WLANUTL.exe
U
Configuration utility for your wireless card.
Sitecom Wireless Utility WLANUTL.exe
U
Generic wireless configuration utility used by many wireless brands.
Sitecom WL-112 Utility WLANUTL.exe
U
Generic wireless configuration utility used by many wireless brands.
Sitecom WL-115 Utility WLANUTL.exe
U
Generic wireless configuration utility used by many wireless brands.
SKRSpyWarn Warn.exe
U
Added by the Smart Keystroke Recorder keylogger and surveillance software. This program should be removed if it is found on your computer without you ... Read More
SkynetRevenge winlogon.scr
X
Added by the NETSKY.AA WORM!
SmansaApp winlogon.exe
X
Added by the W32/Romario-A mass-mailing worm. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe. ... Read More
SMC2862W-G 54Mbps WLAN Monitor WLANUTL.exe
U
Generic wireless configuration utility used by many wireless brands.
SMC2862W-G 54Mbps WLAN Monitor WLANUTL.exe
U
Generic wireless configuration utility used by many wireless brands.
smcserv winsrv.exe
X
Added by the AGOBOT-OU WORM!
smile wcs.exe
X
Identified as a variant of the FakeAlert/Zlob malware.
SMSERIALSTARTER win32st.exe
X
Trojan installed with the SpyBurner rogue anti-spyware program.
SMSERIALWORKERSTARTER winstrse.exe
X
Trojan installed with the SpyBurner rogue anti-spyware program.
smsger Win.exe
X
A variant of the W32/SDBot.BGIU family of worms and IRC backdoor Trojans.
sndpnpmix wauctlxp4.exe
X
Added by the WIN32.MUDROP.N TROJAN!
softIce Update 32 wininits.exe
X
Added by the W32/Rbot-ANB worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
some wcs.exe
X
Identified as a variant of the Adware/Netproject malware. Typically bundled with rogue anti-spyware programs and fake codecs. ... Read More
SonudMan WNILOGON.exe
X
Added by the W32/Lewor-AA worm.
Sony Network Analysis Tool winsony.exe
X
Added by the W32/Spybot-NS worm and IRC backdoor.
Sound Manager winrun32.exe
X
A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote serv ... Read More
Sound System WinSound1.exe
X
Added by an unidentified VIRUS, WORM or TROJAN!
SOUNDM winsmd.exe
X
Added by the Troj/Wlook-B information stealing Trojan.
SOUNDM win32smd.exe
X
Added by the Troj/WOW-JA spyware Trojan. This infection utilizes the npf.sys rootkit to hide itself. ... Read More
SPHandler wuauclt28.exe
X
Identified as the Rbot.bll worm and IRC backdoor Trojan.
SPHandler wuauclt23.exe
X
Added by the W32/Sdbot-DIL worm and IRC backdoor.
SPINX Wscript.exe OXNEY.B.VBS
X
Added by the YENO.B and YENO.C WORMS!
spool wys.exe
X
WhileUSurf adware component
spoolsvs wincfy.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
SpyEx Winllogo.exe
X
Added by the W32/PrsKey-A password-stealing and keylogging worm. The worm will store the logged keystrokes into the file C:text.txt. ... Read More
SpywareGuard winproc32.exe
X
Startpage adware Trojan
SpywareGuardPlus winmm64.exe
X
StartPage.ht homepage hijacker
sqservices wins32.exe
X
Added by the Troj/Progent-B Trojan.
srv32win win16dll.exe
U
Screenspy captures screenshots silently. If you didn't install this yourself, remove it. ... Read More
ssate.exe winsys.exe
X
Added by the BEAGLE.K WORM!
ssgrate.exe winerdir.exe
X
Added by the MITGLIEDER.O TROJAN!
ssgrate.exe winsystems.exe
X
Added by the TROJ/BAGLEDL-J TROJAN
ssgrate.exe wintems.exe
X
Added by the Trojan.Mitglieder.Q trojan backdoor/proxy.
SSH Client for Windows winshp.exe
X
Added by the Win32/Duiskbot.BE worm and IRC backdoor.
SSK Service winssk32.exe
X
Added by the SOBIG.E WORM!
ssms.exe winn.exe
X
Added by the W32/Sdbot-DHE worm and IRC backdoor.
star1 Winrun.exe
X
Added by the Troj/DwnLdr-HLK downloading Trojan.
stardust wallpaper control 2003 WCMain.exe
N
Related to Stardust_Software Screen Saver Control 2003 ... Read More
Start windows.vbs
X
Homepage hijacker
Start Upping windupds.exe
X
Added by the SDBOT.AFH WORM!
start upping windupdts.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Starting up wvsvc.exe
X
Added by the W32/Rbot-NF trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These ... Read More
startkey win32i.exe
X
Added by the Troj/Bifrose-R Trojan.
startkey winampXP.exe
X
Added by the Troj/Bifrose-OY backdoor Trojan.
startkey win32.exe
X
Added by a variant of the Backdoor.Bifrose family of Trojans. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a ... Read More
startup WinlogonStartup
X
Unidentified malware
Startup Configuration wztoid.exe
X
Added by the W32/Rbot-ASD worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. ... Read More
Still Image Instrumenta WinMgnt.exe
X
Added by the Troj/Feutel-AP backdoor Trojan. This infection also creates the files c:\windows\WinMgnt.DLL, c:\windows\WinMgntKey.DLL, and c:\windows\ ... Read More
stmha wkfxi.js
X
Added by the SPETH WORM!
stoner winsvcx.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
StreamAppliance wuauclt14.exe
X
Added by the W32/Rbot-GLT worm and IRC backdoor.
StreamAppliance wuauclt16.exe
X
Added by the W32/Rbot-GME worm and IRC backdoor.
Streams Drivers winlogon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
STV winscrne.exe
X
A variant of the WORM_SDBOT family of worms and IRC backdoor Trojans.
SurfinGuard Pro winsfcm.exe
U
SurfinGuard Pro - internet protection software
SvcH0st WINAGENT.EXE
X
Added by the TROJ/BDOOR-EB TROJAN!
Svchost winhost.exe
X
Added by the LOLAWEB.A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! ... Read More
Svchost winprint.exe
X
Added by the Troj/Agent-PGT Trojan.
SWd winwd.exe
N
PC Security from Tropical Software - lock files, password protect, etc
SWSetup winrar.exe
X
Added by the Troj/GrayBrd-CQ backdoor Trojan.
Sygate Personal Firewall Win32x.exe
X
Added by the RBOT-KZ WORM!
sygate personal firewall winxpstat.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Sygate Personal Firewall wins.exe
X
Added by the W32/Rbot-DZW worm and IRC backdoor.
Sygate Personal Firewall win31243.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Sygate Personal Firewall Startup wint.exe
X
Added by the W32/Rbot-OV trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These ... Read More
Symantec Antivirus professional windows .exe
X
Identified as Backdoor.Win32.Rbot.ckj.
Symantec Update WinNT.exe
X
Added by the W32.Vig.C virus.
syncman winsync.exe
X
Added by the Troj/MancSyn-A Trojan.
syncman wuaucldt.exe
X
Added by the Troj/Namsys-A Trojan.
syntax windows32.exe
X
Added by the SDBOT.CQ WORM! ... Read More
Sys29 win***32.exe [* = random char]
X
EliteBar adware
SysA win***32.exe [* = random char]
X
EliteBar adware
sysav winav.exe
X
Added by the WinPC Antivirus rogue anti-spyware program.
Syscheck win.hta
X
Browser hijacker
SysConfig wincfg32.exe
X
Added by the SDBOT.ZD WORM!
Sysctrls winupdate.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Sysctrls win32dll.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
sysdir winrun.exe
X
Added by the WINBUR.B WORM!
syshelps wmhs32.dll
X
Identified as a variant of the IM-Worm.Win32.Agent worm.
SysInit wininit32.exe
X
Added by the XABOT WORM!
SysInit wininit32.exe
X
Added by the W32/Sdbot-NA worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection ... Read More
SysMon wowexece.exe
X
Added by the Troj/Mulan-A trojan.
SysMonitor WinSystem.exe
X
Added by the W32/VB-DWI worm that spreads to removeable storage devices.
sysprep wscntfx.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
SysSupport WindowsServerService.exe
X
Added by the W32.Degnax@mm worm. W32.Degnax@mm is a mass-mailing worm that gathers email addresses from the compromised computer. It also spreads via ... Read More
SYSTEM wuamgre.exe
X
Added by the W32/Rbot-WA Backdoor/WORM! Found in the Windows system folder.
System winipck.exe
X
Added by the W32/Rbot-TK WORM/backdoor trojan!
System WINL0G0N.EXE
X
Added by the Troj/Bancos-DB trojan.
system wiinlogon.exe
X
Added by the W32/Rbot-AVG ... Read More
System winsock32.dll
X
Added by the Troj/Agent-SH Trojan.
System wmplayer.exe
X
Added by the W32/Lazy-A worm.
System WM_.exe
X
Added by the Troj/Dropper-NR Trojan.
SYSTEM windmupdr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
System winupd.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
System wind32.exe
X
Added by an unknown malware.
system Winhelp.exe
X
Added by the W32.Imaut.CN worm. W32.Imaut.CN is a worm that spreads through Yahoo! Instant Messenger and network shares. It may also download potentia ... Read More
System winnet.dll
X
Added by the BKDR_AGENT.XZMS backdoor.
System Check win_klr32.exe
X
Added by the W32/Delf-DRA worm.
system checking wasul.exe
X
Added by the RBOT.BHM WORM! ... Read More
System Defender WS339.exe
X
Added by the System Defender rogue anti-spyware program.
System Document Application winsvc32.exe
X
Added by the W32/Sdbot-VA WORM! Found in the Windows system folder.
System Drivers wingmt.exe
X
Added by the W32/SDBOT-MG WORM!
System Event Notificat winlogon.exe
X
Added by the Troj/Hupigo-SA Trojan. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe. ... Read More
System Information Manager win.exe
X
Added by the W32/Sdbot-MU worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
System Information Manager windowsNt.com
X
Added by the W32/Sdbot-ND worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
System Manager winsrv32.exe
X
Added by an unidentified WORM or TROJAN!
system manager updates winsvc.exe
X
Added by the AGOBOT.AEM WORM! ... Read More
SYSTEM MESSAGER wmisg.exe
X
Added by the W32.Mytob.ES@mm worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
System Process Analization wininxt.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
System Servers windows.exe
X
Added by the Troj/GrayBrd-L Trojan.
System Service WinFx.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
System Update wupdmgr.exe
X
Added by the SOROMO-A TROJAN!
system update wauluclt.exe
X
Added by the SDBOT.EF WORM! ... Read More
System Update winamp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
System Update Service wmiprvsa.exe
X
Added by the AGOBOT-RG TROJAN!
System Update Service winupd32.exe
X
Added by the ADTODA-A TROJAN!
System Update2 webcheck.exe
X
Added by the AUTOTROJ-C TROJAN!
System Update2 wininet.exe
X
Added by the AUTOTROJ-C TROJAN!
System Update2 winlogon.exe
X
Added by the AUTOTROJ-C TROJAN!
System Update2 winspool.exe
X
Added by the AUTOTROJ-C TROJAN!
System Update2 wupdmgr.exe
X
Added by the AUTOTROJ-C TROJAN!
System Updater Service wmiprvsw.exe
X
Added by the GAOBOT.AFC WORM!
system updates winsci.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
System Updates wmkl.exe
X
Added by the W32/Rbot-AYJ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
System Updates Manager winserv32.exe
X
Added by the W32/Agobot-AGA network worm.
System Windos winsyscfg.exe
X
Added by a Mytob mass-mailing worm and IRC backdoor variant.
system32 wcntfy.exe
X
Added by the Troj/Banker-CSY Internet banking Trojan. If you have this infection you should immediately change all of your online banking account inf ... Read More
System32 winds32.exe
X
Identified as a variant of the Trojan:Win32/Tibs.FZ malware.
system32 master windowsys.com
X
Added by the W32/Sdbot-DIE worm and IRC backdoor.
SystemAdministration Wincmp32.exe
X
Added by the ASYLUM TROJAN!
SystemDriver windrv.exe
X
Identified by Kaspersky Anti-Virus as Trojan-Clicker.Win32.Delf.fj.
SystemKey WIN2000.EXE
X
Added by the Troj/QQify-A. It also copies itself as nsconfig.exe, msconfig.exe, regedita.exe and regedit.exe to %Windir%. ... Read More
SystemMigration WinMedia.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
SystemReg WINREG.EXE
X
Added by the DEWIN.A TROJAN!
Systems Backups windrives.exe
X
Added by an Agobot WORM/IRC backdoor variant, also creating a new service, servicename "Restoreds" and a displayname "Systems Backups". ... Read More
systems usb driver Windows2.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
SystemTray wekls4.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
SystemTray Windowsupd.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
SystemTray winligom.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
SystemW Winalx.bat
X
Added by the Virus.Win32.HLLW.Anirak virus/worm.
systhread winkernal.exe
X
Added by the LIAMED WORM!
Systray w32explorer.exe
X
Added by the W32/Rbot-AJY worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
SysUpd WindowsUpd1.exe
X
VirtuMonde adware
SysWsa32 WSA32.EXE
U
Added by the Spyware.BEverywhere.B surveillance software. This program should be uninstalled if it was not installed by yourself. ... Read More
sysygm64 winrxd64.exe
X
Added by the Troj/IRCBot-RK worm and IRC backdoor.
SyteUpdtes wopooe.exe
X
Added by the Troj/Ezio-H IRC backdoor Trojan.
syWMI Performance Adapter Services wmiapsrvs.exe
X
A variant of the RBot family of worms and IRC backdoor Trojans.
T4skM4n4g3r Wink3sk9.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Task Help wualcts.exe
X
Added by a variant of the WIN32.RBOT WORM!
Taskmon driver winampa.exe
X
Added by the LOONY-I TROJAN!
TBMExe wdfmgr.exe
X
Added by the W32.Notong.A virus. W32.Notong.A is a virus that spreads by infecting executable files. ... Read More
TBMonEx wdfmgr.exe
X
Added by the W32/MumaWow malware.
TCPIP route manager winsys.exe
X
Added by the Troj/Lydra-AB Spyware Trojan.
TEXTCONV winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! ... Read More
the wind0s.exe
X
Added by an unidentified WORM or TROJAN!
this free winsyst.exe
X
Added by the W32.Madag.A worm. W32.Madag.A is a worm that spreads by copying itself to removable storage devices and infects .doc files. ... Read More
Thsys winrun.sys.pif
X
Added by the W32/Sachiel-D worm.
Time Zone Synchronization wscript zshell.js
X
Added by the NETDEX-A TROJAN!
Torjan Program WINLOGON.EXE
X
Added by the Troj/WoW-EA password stealing Trojan targetting of the World of Warcraft online computer game. This infection should not be confused with ... Read More
Touch Manager WinLED.exe
U
Dell keyboard utility. Disabling can result in loss of screen saver and power saver functionality ... Read More
Tour wincool.exe
N
Component of WinME that's annoying as hell. Pop's up a prompt to play the C:\WINDOWS\Application Data\Microsoft\INTRO\CONTENT.HTA that plays a full sc ... Read More
Tray Temperature Weatherbug.exe
N
Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs ... Read More
TrayX winppr32.exe
X
Added by the SOBIG.F WORM!
tsk mng hlp wins32.exe
X
Added by the W32/AGOBOT-JB WORM! ... Read More
TVTonic RSS WXRSS.exe
N
Added by the TVTonic podcast / Internet TV download manager.
Tweak Manager WinManager.Exe
?
WinGuides Tweak Manager. Is this required for the live updates feature and/or if settings are changed? ... Read More
twhe wbta.exe
X
PurityScan delivers advertisements to your computer.
UDP Packet Correction Wnlogon.sys
X
Identified as part of a variant of Trojan.PWS.Egold. This file will usually be hidden by the rootkit logon032.dll. ... Read More
UDP Service Control CenteRMS winudp.exe
X
Added by the Mal/VBPit-A malware.
ukl wmpusrvc.exe
U
Added by the Spyware.UltimateKeylog surveillance software. Spyware.UltimateKeylog is a program that records keystrokes and takes screenshots of the co ... Read More
UltraVNC Server winvnc.exe
U
Server component which listens for incoming connections for the UltraVnc application. This application allows you to take over your computer from a ... Read More
Undefined winter.exe
X
Fakealert Trojan which shows fake security alerts on your computer.
uninstall_wintools WTuninst.exe
U
WinTools adware uninstaller. Should only need to run once in order to complete uninstall; when done, disable. ... Read More
UnrealIRCd wircd.exe
Y
The UnrealIRCd Daemon. This is the actual FTP Server.
Updade Windows winlogom.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
UpData wupdata.exe
X
Troj/IRCBot-AA , a TROJAN/IRC backdoor, will allow an attacker to access and exploit the computer when this file is added. ... Read More
UPDATE WinUpdater5.0.vbs
X
Added by the VBS.Gormlez@mm infection! Found in the Windows directory
update winis.exe
X
Added by the Rbot-VD worm. This infections connects to an IRC server where it waits for remote commands. ... Read More
Update WinUpdate.exe
X
Added by the W32/Sdbot-CV backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execut ... Read More
Update WinNT.exe
X
Added by the W32.Vig.C virus.
Update winzip.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Update Checker winlog.exe
X
Added by the Troj/IRCBot-TJ Trojan.
Update Grokster WiseUpdt.exe
N
Automatically updates the Grokster file sharing software. Beware of adware and spyware when using this type of program, for instance, Grokster contain ... Read More
Update MCafee WinNT.exe
X
Added by the W32.Vig.C virus.
update service winx.exe
X
Added by a variant of the WIN32.RBOT WORM!
Update Service winu32.exe
X
Added by the W32/RBOT-MG WORM!
Update Symantec WinNT.exe
X
Added by the W32.Vig.C virus.
Update TUT WiseUpdt.exe
?
??
updatecheck winstall.exe
X
Added by the W32/SPYBOT-CY WORM! ... Read More
UpdateFirewall32 Windows32Shield.exe
X
Added by the W32/Autorun-BEG worm.
updater wupdater.exe
X
eUniverse KeenValue parasite related
updater wisvc.exe
X
Added by Troj/Orse-A, which also creates a service using the same name, with a displayname of Windows update Service. ... Read More
updater32 winload32.exe
X
Added by the CULT.M WORM!
UpdateService wservice.exe
X
Added by the W32/Dref-K mass-mailing worm. W32/Dref-K will attempt to infect SCR EXE and RAR files then email itself as an attachment to email address ... Read More
upddateit winit.exe
X
Added by the RBOT-MS WORM!
upgrade service winupd.exe
X
Added by the TROJ/TOFGER-U TROJAN! ... Read More
UPNPService WinSVCservice.exe
X
Added by the AGOBOT.UN WORM!
UPSUtl web.exe
X
CoolWebSearch parasite variant
UpTimes service WinUp.exe
X
Added by the W32/Rbot-AKB worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
urudjeffni winlogon.exe
X
Added by the W32/Romario-A mass-mailing worm. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe. ... Read More
USB 2.0 Driver winsystem.exe
X
Added by the W32/Agobot-QS WORM/IRC backdoor, it kills a variety of processes relating to anti-virus and security related programs. ... Read More
USB 2.0 Driver Winsys32.exe
X
W32/Agobot-QM WORM will add this file, resulting in unauthorised access, by way of an IRC channel, through a backdoor. ... Read More
USB 2.1 Driver winupdate1.exe
X
Added by a variant of the RBOT WORM!
USB Device win32usb.exe
X
Added by the FORBOT-BQ WORM!
usb fix 1.1 wuservices.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
USB Fixes wuafix.exe
X
An SDBot variant. These infections connect to IRC servers and wait for remote commands to execute. ... Read More
USB Hardware32c Monitoring USBHARDWARE32C.EXE
X
Added by the W32/Rbot-UU worm. When started, this infection connects to an IRC server where it waits for remote commands. ... Read More
usb updates 2 wugfixx.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
USBConfigration2 wmmndir.exe
X
Added by the W32/Agobot-SV worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
useful-soft wartsrv.exe
X
Added by the Troj/StartPa-WB IE startpage hijacker. This infection hijackthis your startpage to www.teengb.com. ... Read More
useful-soft winspsrv.exe
X
Added by the Troj/StartP-BCG Trojan.

Troj/StartP-BCG changes the Start Page for Microsoft Internet Explorer by setting the registry an ... Read More
UserIMEsm wualt.exe
X
Added by the Troj/Agent-OIM Trojan.
userinit winlogon.exe
X
Added by the Troj/Dloader-TP Trojan.
Userinit winsys16_070813.dll
X
Added by the W32/AutoRun-C Trojan. When run, this infection will disable antivirus programs running on your computer. Please note that the rundll32.ex ... Read More
userinit winmain.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Delf.cns malware.
UserLogon winlogon.exe
X
Added by the W32/VB-DYF worm. This infection should not be confused with the legitmate C:\Windows\System32\winlogon.exe. ... Read More
Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter WLANUTL.exe
U
Generic wireless configuration utility used by many wireless brands.
ValueWin Wink2sk7.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
vbc wdt.exe
X
Added by the Mal/MsilDyn-L malware.
vbe win.vbe
X
Added by the Bat/LoseSlp-A worm.
vbwq cute winnt.exe
X
Added by the W32.Madag.A worm. W32.Madag.A is a worm that spreads by copying itself to removable storage devices and infects .doc files. ... Read More
Version3 winviews32.dll
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Video winamp32.exe
X
Added by the AGOBOT-NG WORM!
Video Camera Frog wcamfrog.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Video Proces winaps.exe
X
Added by the AGOBOT.HD WORM!
Video Process wincrt32.exe
X
Added by the W32/Agobot-GR WORM/IRC Backdoor. File is found in the Windows system folder. ... Read More
Video Process winasp.exe
X
Added by the AGOBOT-IS WORM!
virtual winit.exe
X
Added by the MUGLY.A or MUGLY.B WORMS!
virtual winprotect.exe
X
Added by the MUGLY.C WORM!
virtual wini.exe
X
Added by the W32/Rbot-YX WORM/IRC backdoor Trojan!
Virtual Java wintgtsv.exe
X
Identified by Kaspersky Antivirus as a variant of the Spy-Agent.cs malware.
virtual-ie winlogi.exe
X
Malware - detected by Kaspersky antivirus as Trojan-Dropper.Win32.WinAD.h ... Read More
virtual-machine winlogin.exe
X
Added by W32/Rbot-VU
vsample winxpsock.exe
X
Added by the SDBOT.BLK WORM! ... Read More
w0rmname.exe w0rmname.exe
X
Added by the W32/Woned-C worm.
w32 w32.exe
X
Added by the SOKEVEN TROJAN!
W32 Sercure Service wsecur3.exe
X
Added by the W32/Sdbot-DAR worm and IRC backdoor. This infection utilizes the rdriv.sys rootkit to hide itself. ... Read More
w32 Wayang w32 Wayang.exe
X
Added by the W32.Yadurna.A worm. The user is presented with a password recovery dialogue once the malicious program is downloaded. ... Read More
w32pluginsdownloaderxmlhttpselfclearing7520 wiper.exe
X
Added by the Troj/Proxyser-M ... Read More
W32PT W32PT.dll.vbs
X
Identified by Kaspersky as a variant of the Worm.VBS.Solow.a worm.
w32s win442.dll
X
A variant of the Backdoor.Win32.IRCBot.bam family of worms and IRC backdoor Trojans. ... Read More
w32sup w32sup.exe
X
Adult content dialler
W32SYS w32sys.exe
X
Added by the W32/Jambu-A worm. W32/Jambu-A is a mass mailer for the Windows platform that also targets peer-to-peer file sharing networks and local sh ... Read More
W32Tc WTC32.scr
X
Added by the VOTE.D or VOTE.K WORMS!
w32tcomr w32tcomr.dll
X
Added by the WORM_STRATION.RE worm.
W32Time w32t.dll
X
Added by the Backdoor.Fuwudoor backdoor.
W32Time w32time.exe
X
Added by the Troj/Bckdr-HLO backdoor Trojan. If there is another service called W32Time it will replace it. ... Read More
w4y4n9 w4y4n9.exe
X
Added by the W32.Yadurna.A worm. The user is presented with a password recovery dialogue once the malicious program is downloaded. ... Read More
W7.exe Nacional W7.exe
X
Added by the Troj/Agent-ODZ Trojan.
W75P2PSERVER W75P2PS.EXE
Y
Printer utility which is required in order to make the printer work correctly
w7zip w7zip.exe
X
Added by the Troj/Bancban-PX online banking information stealing Trojan. If you are infected with this, you should contact your banks and change any ... Read More
W815DM W815DM.exe
?
??
w98Eject w98Eject.exe
?
Related to USB support for Sigmatel MP3 audio decoder -what does it do, and is it required? ... Read More
wab.exe wab.exe
X
A variant of the SDBot.bhk family of worms and IRC backdoor Trojans.
wait4ip wait4IP.exe
U
Packard Bell net2Plug allows you to network PCs anywhere in your house ... Read More
WakeMeUp! Service WMUSvc.exe
U
Added by the WakeMeUp! alarm clock.
Wakoopa Wakoopa.exe
N
Wakoopa is a new social network that, when using this software, tracks what software and games you use on your computer. This information will then b ... Read More
wallchgr.exe wstart Wallchgr.exe
U
Blue Tree Software ... Read More
wallpaperchanger Wallpaper.exe
U
A wallpaper changer and manager utility. There is the Freeware version and the Pro version. The freeware version is completely free. The Pro version i ... Read More
Wanadoo Messenger.exe Wanadoo Messenger.exe
N
Wanadoo ISP instant messenger client
wanman.exe wanman.exe
X
A variant of the Win32/Rbot.HDO family of worms and IRC backdoor Trojans.
WanMPSvc WanMPSvc.exe
Y
An AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling ... Read More
WAPI wts**.exe [* = random char]
X
Wapp Wapp.exe
X
Added by the Troj/Banker-EIK information-stealing Trojan for online banks. If you are infected with this file you should immediately change your onli ... Read More
war ftpd tray icon wartray.exe
N
War-ftpd - FTP server
war-ftpd.exe WAR-FTPD.EXE
N
War FTP Daemon from JGAA's Internet - FTP client
WareOut WareOut.exe
X
Malware masquerading as a spyware and dialer remover, see here
warez warez.exe
N
Warez P2P client
Warner warner.exe
U
Also known as "CyberWarner". From G-Tek Technologies and pre-installed on some Packard Bell PCs. Protects critical files ... Read More
Warnet warnet.exe
U
Warnet - system cleanup software
WarReg_PopUp WarReg_PopUp.exe
N
Displays a popup asking you to register your Acert product.
WARSVR war-ftpd.exe
N
"War FTP Daemon - the original free FTP server for windows"
wartamll wartamll.dll
X
Added by a variant of the Haxdoor Trojan family. This infection utilizes the wartamd.sys rootkit to hide itself. ... Read More
was7cw was7cw.exe
X
Added by the rogue anti-spyware program WinAntiSpyware.
wasfsd wasfsd.sys
X
Trojan that create fake alerts and popups advertising rogue anti-spyware program. Though the guide below is not for this particular infection, it wil ... Read More
Washer washer.exe
U
Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Pr ... Read More
Washerie.exe washerie.exe
N
Cookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer, specific for cleaning the IE cache and cookies. Available ... Read More
washindex washidx.exe
U
Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Pr ... Read More
Wast wast.exe
X
Grokster ads updater
wast wast2.exe
X
Grokster ads updater
Watch watch.exe
N
Found to be used by a Trust USB scanner for auto starting the scanning software when the lid is lifted ... Read More
Watch Dog Program watchdog.exe
N
For Compaq PC's. Associated with Compaq's internet services. Not required if you don't use services provided by them and may not be required even if y ... Read More
Watchdog Watchdog.exe
N
Definitely part of the Mustek scanner drivers and software (for 600 III EP Plus and maybe others), launches from the Startup folder in the Start Menu, ... Read More
WatchDog watchdog.exe
?
Part of Motorola "Mobile Phone Tools" v3 - in a "Mobiile Phone Tools" sub-directory of Program Files ... Read More
WATCHPNP_Samsung watchPnp.exe
U
Printer software used by Samsung printers.
WATCHPNP_Xerox watchPnp.exe
U
Printer software used by Xerox printers.
waults waults.exe
X
Added by the Backdoor.Bifrose.L backdoor.
waumgr waumgr.exe
X
A variant of the W32/Sdbot.BNM family of worms and IRC backdoor Trojans.
WaveTop Launcher WaveTop.exe
N
WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in ... Read More
WAWifiMessage WiFiMsg.exe
?
Wireless utility bundled with HP laptops. Anyone know if this is required?
waxw2k waxw2k.dll
X
A variant of the Troj/Haxdor-Fam Trojan.
Wbcmgr wbcmgr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wbiff Wbiff.exe
N
Wbiff! E-mail checker - automatically checks your e-mail and notifies you if any new e-mail has been received ... Read More
wbqxfpgl wbqxfpgl.dll
X
Added by the VAC, or Trojan.Win32.Vapsup.kfp Trojan.
wbsecsvc wbsecsvc.exe
?
Winbond Seurity Support Service related to Winbond Wireless LAN Adapters.
Wbutton Wbutton.exe
?
Related to the Wacom Penabled driver on Acer Tablet PCs. Appears to do nothing so is it required? ... Read More
WCESCOMM WCESCOMM.EXE
N
Active sync for use with Windows CE based palm PC
WCESMngr WCEMNGR.EXE
X
The W32/Agobot-QX WORM/backdoor Trojan adds this, modifying the HOSTS file and terminating security-related/anti-virus processes also. ... Read More
wcmdmgr wcmdmgrl.exe
U
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note th ... Read More
wcmdmgr wcmdmgr.exe
N
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note th ... Read More
wcmdmgrl wcmdmgrl.exe
U
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note th ... Read More
WCPC wintsvcc.exe
?
??
WCPI wintsvit.exe
X
WCPS Wint**.exe [* = random char]
X
WCPT wintsvtr.exe
X
wcsys wcsys.exe
X
Added by the Troj/Keylog-AP keylogging Trojan.
WD Button Manager WDBtnMgr.exe
U
Button manager installed with a western digital external disk drive. Allows you to back up your system with one click ... Read More
Wdc Wdc.exe
U
Added by the Spyware.Watchdog surveillance software. Spyware.WatchDog is a spyware program that logs keystrokes. It monitors Instant Messenger convers ... Read More
wdcs wdcs.exe
X
A variant of the W32/SDBot.AWGW family of worms and IRC backdoor Trojans.
wdfmgr.exe wdfmgr.exe
X
A variant of the Backdoor.Win32.SdBot.bti family of worms and IRC backdoor Trojans. ... Read More
wdfmgr32 wdfmfr32.exe
X
Added by the Troj/Pindow-A downloader Trojan.
wdfmgr32 wdfmgr32.exe
X
Added by the Troj/Dloadr-AOT Trojan.
WDInfo wdinfo.exe
X
Adult content dialler
wdmcert winsdrv.exe
X
Added by the Troj/Dloadr-AKP Trojan.
wdmon wdmon.exe
X
Added by the Infostealer.Ldpinch Trojan. Infostealer.Ldpinch is a password-stealing Trojan horse that attempts to steal information from an infected c ... Read More
WDNS SYSTEM wdns33.exe
X
Added by the W32/Mytob-BY worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
wdpoefan wdpoefan.dll
X
Identified as a variant of the Adware.Agent malware.
wdskctl wdskctl.exe
X
IEPlugin spyware
wdwctrl wdwctrl.exe
X
Added by the DLUCA.E TROJAN!
WEATHER WEATHER.EXE
N
Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs ... Read More
WeatherCast Weather.exe
N
Weather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight ... Read More
WeatherEye WeatherEye.exe
N
The Weather Network's taskbar weather monitoring software.
WeatherOnTray WeatherOnTray.exe
X
Hotbar's Weather Forecast tool for your desktop - adware
weatherscope Weatherscope.exe
X
WeatherScope software - bundles Gain/Gator adware ... Read More
WeatherWatcher ww.exe
N
WeatherWatcher - weather reporting in the System Tray
Web Live Information Messenger webmsn.exe
X
Added by the W32/Sdbot-CWA worm and IRC backdoor.
Web Management Service WMSvc.exe
U
Allows you to manage Microsoft Internet Information Services (IIS) via the web.
Web Service [random filename]
X
Added by the Trojan.Admincash infection!
web2pop Web2Pop.exe
U
Web2Pop allows you to retrieve your web-based accounts messages to read them in your favorite e-mail client. ... Read More
web3trap web3trap.exe
Y
PC-Cillin 2000 anti-virus software -> ActiveX filter. Guards against malicious ActiveX programs, etc  ... Read More
webalize webalize.exe
X
Searchcentrix hijacker
WebArmyKnife WAK.exe
N
Web Army Knife - a suite of web site developer's tools
webassist webassist.exe
X
Adware popup generator
WebBuying Webbuying.exe
X
Added by the Adware.Webbuy adware. Adware.Webbuy is a Browser Helper Object that displays advertisements. ... Read More
webcam webcam.exe
X
Added by the Troj/Monad-A backdoor Trojan.
Webcam Go Sti Service Application wbcgosvc.exe
?
Control software for the portable Creative Video Blaster Webcam Go digital camera/PC web cam. What does it do and is it required? ... Read More
WebcamRT.exe WEBCAMRT.exe
N
For Logitech Web Cams. Not required - camera works fine without it
Webcelerator webcel.exe
X
Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if yo ... Read More
WebCheck WebCheck.pif
X
Added by the CONE.C or CONE.F WORMS!
WebCpr0 WebCpr0.exe
X
Webdav.exe webdav.exe
X
IRC DDoS bot which gives the hacker full control over your system
WebHancer Agent whagent.exe
X
System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find ... Read More
webHancer Survey Companion whSurvey.exe
X
WebHancer foistware - traffic measurement service that uses a client agent that is stealth installed on user machines, gathering detailed data about s ... Read More
WebInstall WebInstall.exe
X
ClipGenie adware downloader
WebInstall2 WebInstall.exe
X
ClipGenie adware downloader
WebKey WebKey.exe
N
WebKey from JB Utilities. Utility to keep track of login data required when browsing the internet ... Read More
weblink WebLink.exe
N
Softex WebLink is a "cost-effective way to provide software updates, technical support or new product information to specific end-users - it can sile ... Read More
Webposition Gold 2 wpsche~1.exe
N
Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines ... Read More
WebPrint webprint.exe
X
Added by the Troj/Bckdr-QHH backdoor Trojan.
WebRebates0 WebRebates0.exe
X
WebRebates adware
Webroot Client Service WRConsumerService.exe
Y
Related to Webroot's Spy Sweeper.
Webroot Desktop Firewall WDF.exe
Y
Webroot Desktop Firewall network service wdfsvc.exe
Y
Related to the Webroot Desktop Firewall.
Webroot Spy Sweeper Engine WRSSSDK.exe
Y
Webroot Spysweeper's realtime scanning engine.
websaverlive websaverlive.exe
U
WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your ... Read More
WebSavingsfromEbates WebSavingsfromEbatesrun.exe
X
Web Savings From Ebates Software, a shopping tool that opens pop-up windows
WebSavingsFromEbates0 WebSavingsFromEbates0.exe
X
Web Savings From Ebates Software, a shopping tool that opens pop-up windows
WebScanX WebScanX.exe
Y
From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guar ... Read More
websearch wjview ...websearch.exe
X
"Web Savings" From Ebates Software, a shopping tool that opens pop-up windows
WebSecureAlert WebSecureAlert.exe
X
WebSecureAlert. "Can help protect your browser security and privacy". However, it's by GAIN Publishing, and will display pop up ads on your computer s ... Read More
WebShell webshell.dll
X
Added by the Backdoor.Bebshell Trojan horse with backdoor capabilities.
Webshots Webshots Tray.exe
N
Screensaver program that automatically downloads from the webshots web site
Webshots websho~1.exe
N
Screensaver program that automatically downloads from the webshots web site
Website Administrator Info webadmin.exe
X
W32/Forbot-FY will connect to an IRC server and establish a new service named "Connection Reset", with the display name "Website Administrator Info". ... Read More
WebSpyShield WebSpyShield.exe
X
Added by the WebSpyShield rogue security software. WebSpyShield is a misleading application that may give exaggerated reports of threats on the comput ... Read More
websrvx websrvx.exe
X
Added by the WORM_KOOBFACE.EY worm.
WebTime WebTime.exe
X
Added by the Troj/SleepSrv-A Trojan.
WebTime WebTime.exe
N
Added by the WebTime time synchronization program. WebTime 2000 is a small utility program that will synchronize your PC's internal clock with one of ... Read More
Webtrap webtrap.exe
Y
Part of PC-Cillin anti-virus software. Checks web-sites for malicious Java and ActiveX elements in a similar way to McAfee WebScanX. A few users find ... Read More
WebTrapNT.exe WebTrapNT.exe
Y
Part of PC-Cillin Anti-Virus software. Checks visited web-sites for malicious Java and ActiveX elements ... Read More
WebWasher wwasher.exe
U
Free Pop-up/ad/javascript filter program from Siemens. If not running then browsers will not be protected but will still work. Available via Start -> ... Read More
webwork webwork.dll
X
Added by the Webwork downloader/updater DLL which is known to download and install advertising software. The adware applications Boran and Yokgug may ... Read More
weirdontheweb WeirdOnTheWeb.exe
X
Added by the Adware.WeirdOnTheWeb ... Read More
Welcome Welcome.exe
N
Launches the Welcome to Windows tutorial on boot up
wemwpxpjdb wemwpxpjdb.exe
X
Added by the Troj/Agent-GQB Trojan.
WEP Manager for NT webpmgr.exe
X
Added by the WORM_QQPASS.A worm.
WEPstat Wepstat.exe
?
Cisco Aironet 340 Series PC Card driver. If it can be started manually it shouldn't be required if you don't use the PC card facility regularily - hen ... Read More
werasqlp werasqlp.cur
X
Added by the Backdoor.Rustock backdoor rootkit.
wesumu wiustv.exe
X
Added by the Troj/QQPass- Trojan.
wetkadmr wetkadmr.dll
X
Identified as a variant of the Adware.Agent malware.
WetSock wetsock.exe
N
RoboMagic Wetsock - weather reporting in the System Tray
wfexqnrp wfexqnrp.dll
X
Identified as a variant of the VideoAccessCodec adware.
WFGStartup WFGStartup.exe
N
World Weather. "This midlet displays the current weather conditions for major cities around the world. This version is for memory limited mobile phone ... Read More
WFPService WFPService.exe
U
Added by Microsoft's Windows Feedback Program utility.
WFXCTL32.EXE WFXCTL32.EXE
N
From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displa ... Read More
wfxsnt40 wfxsnt40.exe
Y
WinFax 10.0 and maybe earlier versions. The program that opens the port for WinFax and not normally in the start menu. Needed if you want to run WinFa ... Read More
WFXSwtch WFXSWTCH.exe
U
Related to WinFax. Allows you to use Winfax as a virtual printer so that you can print directly to the application. ... Read More
WG511WLU WG511WLU.exe
Y
Netgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card ... Read More
WgaLogon WgaLogon.dll
Y
This file is a legitimate Windows oeprating system file. It used as part of Windows Genuine Advantage and alerts when you are using an unvalidated Mi ... Read More
wgeax wgeax.exe
X
Added by the W32/IRCBot-TM worm and IRC backdoor.
wgs3 wgs3.exe
X
Added by the Troj/LegMir-AQH password-stealing Trojan.
WGWLocalManager WGWLocalManager.exe
U
Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performan ... Read More
whagent whagent.exe
X
System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find ... Read More
WhatPulse WhatPulse.exe
U
WhatPulse sends statistics on how much you type on your computer and ranks you based on that. It does not log your keystrokes, but only the counts of ... Read More
WhenUSearchWHSE whse.exe
X
SaveNow adware
Whistler whismng.exe
X
Added by the Troj/Whistler-F. It also creates a file at C:WXP to copy over other files and deletes files. ... Read More
Whitman Software whitsoft.exe
X
Added by the W32/Rbot-AUB worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Whvlxd Whvlxd.exe
X
Added by the W32.LXD.MIRC TROJAN!
widuxngq widuxngq.sys
X
Added by the Backdoor.Rustock backdoor rootkit.
wifeman wifeman.exe
X
Unidentified malware
Wifi Boot wifiboot.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Booter wifibooter.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Configuration wificonfig.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Configuration! wificonfigs.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Connection wificon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Connection! wificonnect.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Debug wifidebug.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Loader wifiload.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Loader! wifiloader.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Wifi Setup wifisetup.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WildFlics WildFlics.exe
X
Added by the Dial/Direct-B premium rate dialer.
WildTangent Web Driver updater wcmdmgrl.exe
U
Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note th ... Read More
Wildwire Monitor WWMon.exe
N
This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem ... Read More
Willow Road WillowRoad.exe
N
Willow Road Screen Saver
WIN windows.exe
X
Added by the W32/Lebreat-B worm.
Win windata.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
win winupdt.exe
X
Identified as a variant of the BKDR_SMALL.GSJ malware.
win aggior winupdt.exe
X
Identified as a variant of the BKDR_SMALL.GSJ malware.
win aggiornamento winupdt.exe
X
Identified as a variant of the BKDR_SMALL.GSJ malware.
Win Antivir 2008 Win Antivir 2008.exe
X
Added by the Win Antiv 2008 rogue antivirus program.
Win Antivirus 2008 Win Antivirus 2008.exe
X
Added by the Win Antivirus 2008 rogue antivirus program.
Win Chimes winchi~1.exe
U
WinChimes - enhancement software for the system clock that runs in the system tray ... Read More
Win Comm WinComm.exe
X
WebRebates related adware
Win Config winconfig.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Win Critical File win.exe
X
A variant of the W32/IRCbot.BGA.worm family of worms and IRC backdoor Trojans.
win ctl app wuctl.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Win Defrag windfrag.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Win Defrag! windefrag.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Win FTP wintftp.exe
X
Added by the W32/Sdbot-KA worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
WIN HOST PROCESS WIN HOST PROCESS.EXE
X
Added by the KEYLOGGER.CLONE TROJAN!
WIN ID SYS64 w3264.exe
X
Added by the W32/Mytob-BO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Win l5oahder winampa.exe
X
Added by the SPYBOTER.GEN VIRUS! Not the valid Winamp Agent which uses the same filename. This resides in the System32 sub-folder wheras real one is l ... Read More
Win Login winlogin.exe
X
Added by the W32/Rbot-AWE worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. Please do not con ... Read More
Win Manager winmanager.sys
X
Added by the Troj/Bancos-BEQ Trojan.
Win Microsoft 98 win14.exe
X
Added by the W32/Rbot-AKX worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
win microsoft config wnmsconfig.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Win Security winsecure.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Win Security 360 WinSecurity360.exe
X
Added by the Win Security 360 rogue anti-spyware program.
Win Server winserv.exe
X
Added by the IMISERV.A TROJAN!
Win Server Updt wupdt.exe
X
Added by the IMISERV.A TROJAN!
win server updt winserver.exe
X
Added by a variant of the WIN32.IMISERV TROJAN! ... Read More
Win Tasks 32 wintasks32.exe
X
Added by the W32/Rbot-FPD worm and IRC backdoor.

W32/Rbot-FPD spreads:

- to other network computers infected with: W32/M ... Read More
Win Tmp Service wstmp.exe
X
Added by the W32/SdBot-YS. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
win update wupda32.exe
X
Added by the SDBOT.J WORM!
win update wupdate.exe
X
Added by the W32/Rbot-P worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
win update wapdate.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
win updater WINUPDATER.EXE
X
Added by the RBOT.IP WORM! ... Read More
win winamp winamp.exe
X
Added by the RBOT.AGF WORM! NOTE - this is NOT the Winamp Media Player executable (WinAmpa.exe) ... Read More
win***32 win***32.dll
X
Added by the Trojan.Nebuler Trojan. Trojan.Nebuler is a Trojan horse that attempts to download and execute files from remote sites. It also sends info ... Read More
WIN-BUGSFIX WIN-BUGSFIX.EXE
X
Added by the LOVELETTER (I LOVE YOU) VIRUS!
win-update wiupdat.exe
X
Added by the W32/Sdbot-QPworm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
win-xp winis.exe
X
Added by the W32/Rbot-BBD WORM! Found in the Windows system folder.
win16.dll win16dll.exe
U
Screenspy captures screenshots silently. If you didn't install this yourself, remove it. ... Read More
win23.exe win23.exe
X
A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote serv ... Read More
win24 win24.exe
X
Added by the WORM_KIDALA.A network worm.
WIN32 WIN32.EXE
X
Added by the RATEGA TROJAN!
Win32 Win32.exe
X
Added by the ISRAZ.A and the W32/Mytob-AB WORMS!
win32 winsrv32.exe
X
Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites ... Read More
win32 WinSetup.exe
X
Added by the EVILBOT.B TROJAN!
win32 winhost.exe
X
Added by the Bropia.F worm.
win32 w32word.exe
X
Added by the Trojan.Gared Trojan that overwrites or deletes Word documents.
Win32 wveygxi.exe
X
Added by the W32/Rbot-FYK worm and IRC backdoor.
Win32 winnnit.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Win32 Bios Winbios.exe
X
Added by the W32/Semapi-A. This mass-mailing worm may display a message: "Unable to locate 'semapi.dll' reinstalling this application may fix this ... Read More
Win32 Critical File Win32.exe
X
Added by the W32/Rbot-GUB worm and IRC backdoor.
win32 debug manager Win32Debug.exe
X
Added by a variant of the W32/WOOTBOT WORM! ... Read More
Win32 Device Loader Win32ldr.exe
X
Added by a variant of the AGOBOT/GAOBOT WORM!
Win32 Drivers winlogons.exe
X
Added by the W32/Forbot-FG worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Win32 DRK Driver wdrk32.exe
X
Added by the WOOTBOT.CY WORM!
Win32 exe file winstr32.exe
X
Added by a variant of the SPYBOT WORM!
win32 firewall driver winfw.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Win32 Help32 Service win32help.exe
X
Added by the W32/Delbot-U worm and IRC backdoor.
Win32 Info windowsnfo.exe
X
A variant of the W32/Spybot.SLI family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
win32 internet server winserver.exe
X
Added by the Troj/Dermon-D Trojan.
Win32 Kernel Update win32update.exe
X
Added by the Troj/Proxy-BS backdoor Trojan.
Win32 Kernel Update win32host.exe
X
Added by the W32/Tilebot-FE worm and IRC backdoor.
Win32 Servermgr12345 winimgr.exe
X
Added by the W32/Tiotua-M worm.
Win32 service WIN32SVC.EXE
X
Added by the Backdoor.Selka backdoor.
Win32 Services wuamngr.exe
X
Added by the W32/Sdbot-N worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Win32 Services Config winwkys.exe
X
Added by a new Rbot worm variant.
Win32 Services1 wuamngr1.exe
X
Added by the SDBOT-PV WORM!
Win32 Services1 wuamngr1.exe.exe
X
Added by the Backdoor.Sdbot.AN Backdoor! Found in the Windows system directory. ... Read More
win32 socket win325b.exe
X
Added by the W32/Tilebot-GE worm and IRC backdoor.
Win32 Src Service win32src.exe
X
Added by the RBOT-SX WORM!
Win32 SSL Driver winssv.exe
X
Added by the FORBOT-BH WORM!
win32 system server winserver.exe
X
Added by an unidentified WORM or TROJAN!
Win32 USB Driver winxpinit.exe
X
Added by the SDBOT.AA TROJAN!
win32 usb2 wins32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Win32 USB2 Driver win32usb.exe
X
Added by the SPYBOT.DHV WORM!
Win32 USB2 Driver wind32.exe
X
Added by the FORBOT-AH WORM!
Win32 USB2 Driver winupdate.exe
X
Added by the AGOBOT.YE WORM!
Win32 USB2 Driver winsnd32.exe
X
Added by a variant of the SDBOT WORM!
Win32 USB2.0 Driver w32usb2.exe
X
Added by the SPYBOT.DN WORM!
win32 usb3 driver win32tool.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Win32 Wmls Driver winitr32.exe
X
Added by the WOOTBOT.B WORM!
win32.exe win32.exe
X
Added by the STARTPAGE TROJAN!
win32app Winpup32.exe
X
Added by the Troj/AdClick-N Trojan! File is found in the Windows system folder. ... Read More
Win32BaseServiceMOD Wintask.exe
X
Added by the NAVIDAD WORM!
win32beta win32sys4.exe
X
Added by the Troj/Banker-DA password-stealing trojan for Brazilian banks.
win32clf win32clf.exe
X
Added by an unidentified VIRUS, WORM or TROJAN!
win32client win32client.exe
X
Added by the Troj/Restarter trojan.
win32debug win32debug.exe
X
Added by the W32.Gudeb worm.
Win32DLL Win32DLL.vbs
X
Added by the LOVELETTER (I LOVE YOU) VIRUS!
Win32dll Win32dll.exe
X
Added by the BANPAES TROJAN!
win32gb win32gb.exe
X
All-In-One-Telcom (adult content dialler) variant
Win32Host Process webemir.exe
X
Added by the Troj/Turgen-A password-stealing trojan.
win32info win32info.exe
X
Adult content dialler
win32k.sys win32k.sys:1
X
The ZeroAccess rootkit. This rootkit terminates any program that scans its processes or files and then changes the permissions on them so you can no ... Read More
win32k.sys win32k.sys:2
X
The ZeroAccess rootkit. This rootkit terminates any program that scans its processes or files and then changes the permissions on them so you can no ... Read More
win32napp win32napp.exe
X
Added by the W32/Smelles-A virus.
Win32reg.dll Wind32reg.dll.exe
X
Added by the W32/Rackum-A worm/keylogger. This infection attempts to delete the regedit.exe file and logs keystrokes in the Winsck32.sys.Txt file. ... Read More
WIN32SL Win32sl.exe
Y
Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the ... Read More
Win32Sr win32ssr.exe
X
Added by the W32/Sdbot-AOT worm and IRC backdoor.
Win32System win32s.exe
X
Added by the MYDOOM.V WORM!
win32us win32us.exe
X
All-In-One-Telcom (adult content dialler) variant
Win32Usr WinCab.exe
X
Added by the W32/Dedmir-A worm.
win32_i lptt01 win32_i.exe
X
Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use Rapi ... Read More
win32_i ml097e win32_i.exe
X
Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use Rapi ... Read More
Win386 Win386.exe
X
Added by the GOSUSUB VIRUS!
WIN3S2SNDS winabsmod.exe
X
Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" ... Read More
WIN3S2SNDS winiprtx.exe
X
Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" ... Read More
Win7 AV Win7 AV.exe
X
Added by the Win7 AV rogue anti-spyware program.
win98 dns wingrd.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
wina wina.exe
X
Identified as a variant of the Mal/BankSpy-C malware.
WinAble winable.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Adload.lv malware.
winacsr Winacsr.exe
U
AceScreenSpy keystroke logger/monitoring program - remove unless you installed it yourself! ... Read More
winactive WINACTIVE.EXE
X
Active variant of LOP.com hijacker - see here
WinActiveJ WinActiveJ.exe
X
Added by the ROTARRAN VIRUS!
Winad Client Winad.exe
X
WinAd adware by eXact Advertising
WinAdCnt.exe WinAdCnt.exe
X
Added by Troj/Banker-BU to compromise online banking sites.
WinAdCnt16.exe WinAdCnt16.exe
X
Added by the Troj/Banker-AT TROJAN!
winadm winadm.exe
X
Browser hijacker - redirecting to Search-World.net. Related to the SMALL.LR TROJAN! ... Read More
winafg32 winafg32.dll
X
Added by the Troj/Nebuler-G Trojan.
winagent WinAgent.exe
?
Standard Life Insurance program. Note: This file is legitimate. It is not known if it needs to run at startup. ... Read More
Winahlp.exe Winahlp.exe
X
Added by a variant of the VAGRNOCKER TROJAN!
winakd32 winakd32.dll
X
Added by the Troj/Nebuler-V Trojan.
winallap winallap.exe
X
Added by the DELF.E TROJAN!
winallapu winallapu.exe
X
Added by the DELF.E TROJAN!
Winamp winamp.hta
X
Hijacker - re-directing to adult content sites. Note - this isn't the real Winamp ... Read More
Winamp winamp.exe
X
Added by the AGOBOT-MC WORM! Note - this is NOT the Winamp Media Player (WinAmpa.exe) ... Read More
WinAMP winamp62.exe
X
Added by the W32/Sdbot-WN WORM/IRC backdoor Trojan!
Winamp Agent winamp.exe
X
Added by the W32/Poebot-I WORM! This file is found in the Windows system folder. ... Read More
WinAmp Agent Full wina.exe
X
Identified by Kaspersky Anti-Virus as Trojan-Downloader.Win32.Banload.bfb. If you are infected with this file you should immediately change all of yo ... Read More
Winamp media player winapa.exe
X
Added by an unidentified VIRUS, WORM or TROJAN!
Winamp Media Player winaamp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Winamp Media Player winamap.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Winamp Media Player winamp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WinAmp Player winampp.exe
X
Added by the W32/Rbot-AQI worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Winamp Player 6 Winamp6.exe
X
A variant of the W32.Spybot.Worm family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
winamp to google talk winamptogoogletalk.exe
U
Winamp to Google Talk, available here shows your current Winamp track in your Google_Talk status ... Read More
Winampa WINAMPa.exe
U
Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take ... Read More
Winampa winampa.exe
X
Added by the AGOBOT-GS WORM!
Winampa Agent WINAMPA.EXE
X
Added by the SPYBOT-BR WORM! Note - this is NOT the Winamp Media Player
WinampAgent WINAMPa.exe
U
Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take ... Read More
WinAmpAgent winagent.exe
X
Added by the Win32.Tactslay backdoor Trojan.
WinampPlugin winampa.exe
X
Added by the W32/Sdbot-CNF worm and IRC backdoor.
winantispyware 2005 was5.exe
X
WinAntiSpyware: MALWARE, posing as a spyware remover - for more information, search the Spywarewarrior_List of non-Recommended anti parasite sit ... Read More
WinAntiSpyware 2007 was7.exe
X
Added by the rogue anti-spyware program WinAntiSpyware.
WinAntispyware2008 WinAntispyware2008.exe
X
Added by the WinAntispyware2008 rogue anti-spyware program.
WinAntiVirus Pro 2007 WinAV.exe
X
Startup program associated with WinAntiVirus Pro 2007. WinAntiVirus Pro 2007 is a rogue anti-spyware program that displays fake alerts, and downloads ... Read More
WinAntiVirusPro2006 WinAV.exe
X
Part of WinAntivirus Pro. This program is fake, stealth installed, and bundled with other malware. It is also on the Rogue anti-spyware list. ... Read More
WinApi winapix.exe
X
Added by a variant of the TIBSER.A downloader TROJAN!
WINAPLOGUPD WINAPLOGUPD.EXE
X
Added by the W32/Capside-C WORM, which exploits typical P2P program folders, and spreads via IRC clients and through netwerk shares. ... Read More
Winapp winpup32.exe
X
Produces popup ads to adult content sites
Winapp32.exe Winapp32.exe
X
Added by the Backdoor.GF.13 backdoor trojan!
WinAuth winlogon.exe
X
Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the valid winlogon.exe process ... Read More
WinAVX WinAvX.exe
X
Malware related to and installed with the rogue anti-spyware program called WinAntiSpyware 2006 or WinAntiSpyware 2007. This Trojan is responsible for ... Read More
WinAVX WinAvXX.exe
X
Malware related to and installed with different rogue anti-spyware programs including WinAntiSpyware 2006 or WinAntiSpyware 2007. This Trojan is respo ... Read More
WinAwk WinAwk.exe
X
Added by the W32/Sdbot-AYF worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
winazs32 winazs32.dll
X
Identified as a variant of the Trojan.Win32.Dialer.qn dialer.
WinBackup Scheduler Wbsched.exe
U
LIUtilities WinBackup scheduler - backup software
WinBar WinBar.exe
U
"WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls" ... Read More
winbas12 winbas12.exe
X
Adware, probably CoolWebSearch parasite related - recognized by Kaspersky antivirus as TrojanDownloader.Win32.VB.du ... Read More
winbeans winbeans.exe
X
Added by the W32/Sdbot-BZB worm and IRC backdoor.
Winbed winbed.exe
X
Hijacker
winbfi32 winbfi32.dll
X
Identified as a variant of the Trojan.Win32.Agent.qt Trojan.
winbin32 win32exe.exe
X
Added by the W32/Rbot-ZL WORM/IRC backdoor!
winbjv32 winbjv32.dll
X
A variant of the Trojan.Win32.Agent.qt Trojan.
WinBlueSoft WinBlueSoft.exe
X
Added by the WinBlueSoft rogue anti-spyware program.
winbo32.exe winbo32.exe
X
Added by the W32/Rbot-GRU worm and IRC backdoor.
winboot winboot.exe
X
Added by the Troj/Banload-W Trojan.
Winbot winbot.exe
X
Added by the Troj/Midrug-A backdoor trojan.
winbug32 winbug32.dll
X
A variant of the Trojan.Win32.Agent.qt Trojan.
WinButler WinButler.exe
X
Identified as a variant of the Trojan-Dropper.Agent.DKN malware.
winbyq32 winbyq32.dll
X
Added by the Troj/Agent-DMC Trojan.
Wincbr.exe Wincbr.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
Wincfg.exe Wincfg.exe
X
WinCfg32 WinCfg32.exe
X
Added by the W32/Ronoper-A worm/backdoor trojan.
WINCHAT WINCHAT.EXE
X
Added by the Backdoor.Specfix backdoor.
WinCheck WinCheck.exe
X
Added by the PWS-CY TROJAN!
winchk winchk.exe
U
Added by the Spyware.RemoteSpy surveillance software.
winchost winchost.exe
X
Added by the Troj/Dloader-PO downloader trojan.
WINCINEMAMGR WINCIN~1.EXE
N
WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs ... Read More
WinCinemaMgr WinCinemaMgr.exe
N
WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs ... Read More
winclean winclean.exe
X
Added by the Troj/Cimuz-BO spyware Trojan. Troj/Cimuz-BO may also steal information such as email account usernames and passwords, and create screensh ... Read More
wincls wincls.dll
X
Added by the W32/Akbot-AR worm. W32/Akbot-AR spreads to other network computers infected with W32/Sasser and to other network computers by exploiting ... Read More
wincmap wincmapp.exe
X
CasClient adware variant - also known as Trojan.Cmapp ... Read More
wincms wincms.exe
X
Added by the RBOT.CBR WORM! - NOTE: this malware actually changes the default value data of the Registry "Run" key in order to force Windows to lau ... Read More
wincom32 wincom32.sys
X
Added by the Trojan.Peacomm downloader Trojan. This infection contains rootkit functionality that enables it to hide some of its associated files. ... Read More
WinCon (wincon net driver) wincon.exe
X
Added by the W32/Sdbot-DJB worm and IRC backdoor.
Winconfig Windows Update.exe
X
Added by the Troj/Banker-BUM information-stealing Trojan for online banking sites. If you are infected with this you should immediately change all yo ... Read More
winconfig winconfig.js
X
Added by the Trojan.Chafpin Trojan. Trojan.Chafpin is a Trojan horse that downloads files on to the compromised computer. Please note that c:\Windows ... Read More
winconfig.exe win32dll.exe
X
Added by the W32/Kassbot-P worm and IRC backdoor.
WinCore32.exe WinCore32.exe
X
Added by the Troj/Clicker-EN Trojan.
wincqt32 wincqt32.dll
X
Added by the Troj/Bckdr-JCK backdoor Trojan.
WinCRT32 wincrt32.exe
X
Added by the W32/Dogbot-D worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
WinCTL winctl.dll
X
Added by the Troj/Small-EJG Trojan downloader.
winctl winctl.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
winctrl winupgrm.exe
X
Added by the Troj/Kbroy-A keylogging Trojan.
WinCtrl32 WinCtrl32.dll
X
Added by a variant of the Trojan-Downloader.Win32.Mutant.yf Trojan.
wincx wincore332.exe
X
Added by the W32/AGOBOT-MG WORM! ... Read More
Wind Optimizer WindOptimizer.exe
X
Added by the Wind Optimizer rogue Windows optimization software.
wind.exe wind.exe
X
Added by the MITGLIEDER.BD TROJAN!
WIND0WS WIND0WS.exe
X
Added by the SPYBOT.DQ WORM!
Wind0ws wordpad.exe
X
Added by the W32/Agobot-TL worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute. ... Read More
Wind32 Wind32.exe
X
Identified as a variant of the Backdoor.Win32.Poison.avs malware.
WinDates windates.exe
N
WinDates is a calendar, date organizer and event reminder program from Rockin' Software ... Read More
windbg48 windbg48.sys
X
Added by the Troj/RKAgen-A rootkit.
windbs winxtc.exe
X
Added by the AGOBOT-WD WORM!
Winde winde.exe
X
Added by the DLUCA TROJAN!
windef Win32sp.vbs
X
Added by the ANPES WORM!
windef windef.exe
X
Added by the W32/Wurmark-O mass-mailing worm.
windefend windefend.exe
X
Related to the WinAntivirus rogue anti-spyware program.
WinDefender wicfte.exe
X
Added by the Troj/Scar-AG Trojan.
WinDefender 2008 WDefDemo.exe
X
Added by the WinDefender 2008 rogue privacy program.
windefender.exe windefender.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Agent.byh Trojan.
WinDefender2009 windef.exe
X
Added by the WinDefender 2009 rogue anti-spyware program.
windev-4a8c-4822 windev-4a8c-4822.sys
X
Added by the Troj/Dorf-C Trojan.
windev-b51-433 windev-b51-433.sys
X
Added by the Troj/Dorf-H rootkit.
WinDevils WinDevils.exe
X
Added by the W32/Brontok-BS worm.
windhost.exe windhost.exe
X
Added by Troj/Banker-BV or Troj/PWSAgent-A trojans.
windhost.exe winos.exe
X
Added by the Troj/PWSAgent-A trojan.
windir winrun.exe
X
Added by the WINBUR.B WORM!
Windir Working wuaumqr1.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windll Windll.exe
X
Added by the TRYNOMA TROJAN!
WINDLL WSYS.EXE
U
STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes, all passwords transacted even if they weren't keyed i ... Read More
windll windll32.exe
X
Added by the ASTEF or RESPAN WORMS!
Windll wingmnt.exe
X
Added by Backdoor.Cmjspy.B.
windll windotnetsrv.exe
X
Added by the W32/Autorun-ANO removable media worm.
WinDLL (windns32.dll) windns32.dll
X
Identified as a variant of the Backdoor.Win32.Akbot.e malware.
WinDLL (wintmp.exe) wintmp.exe
X
Identified as a variant of the Backdoor:Win32/Akbot.A malware. Do not delete C:\Windows\System32\rundll32.exe as it is a legitimate application. ... Read More
Windll.exe Windll.exe
X
Added by the STEALER TROJAN!
Windll32 Windll32.exe
X
Added by the MSNPWS TROJAN!
windllsys32.exe windllsys32.exe
X
Added by a variant of the MITGLIEDER.BY TROJAN!
WinDNS windns32.exe
X
Added by the GAOBOT.WX WORM!
Windos Service Protocol Line wspl.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
WindosSysDrivers WindosSysDrivers.dll
X
Added by the Troj/PWS-BOB Trojan. Please note that C:\Windows\System32\rundll32.exe is a legitimate Windows file and should not be deleted. ... Read More
Window UDP Control Servic winlogon.exe
X
Identified as a variant of the TR/Dropper.Gen malware.
Window Monitor winmon32.exe
X
Added by the SDBOT.RT WORM!
Window UDP Control Servic winlogon.exe
X
Added by the W32/Rbot-GXN worm and IRC backdoor.
Window Washer wwDisp.exe
U
Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Pr ... Read More
window.exe window.exe
X
Added by the MITGLIEDER.H or MITGLIEDER.J TROJANS!
WindowBlinds wbload.exe
U
WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object De ... Read More
WindowEnhancer Winex.exe
X
SCbar foistware variant
Windowfdgfds DasdLL Verifier winupdatr.exe
X
Identified as a variant of the WORM_AGOBOT.HZ worm.
Windowfdgfds DLL fgfdg Verifier winsecure.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WindowFX wfxload.exe
U
Stardock WindowFX - "Allows you to add an unprecedented number of special effects to windows" ... Read More
windown wiusyt.exe
X
Added by the Troj/QQPass-M password-stealing Trojan.
windowregkey update wins.exe
X
Added by the SPYBOT.I WORM! ... Read More
Windows Windows.exe
X
Added by the KAZMOR, BOBBINS & ALADINZ.D TROJANS!
WINDOWS winhlpapi.exe
X
Added by the W32/Mytob-QG mass-mailing worm and IRC backdoor.
windows WindowsMediaPlayer.exe
X
Added by the Backdoor.Sekorbdal backdoor Trojan.
windows windowssys.exe
X
Added by the Troj/Banloa-FK Trojan.
windows winbows.exe
X
Added by the W32/Autorun-AAI removable media worm.
Windows winlogons.exe
X
Added by the W32/AutoIt-OQ worm.
windows 128 module win128.exe
X
Added by the W32/FORBOT-ES WORM! ... Read More
Windows 32 Bit WinVid32.exe
X
Added by the W32/Tilebot-BH worm and IRC backdoor. This infection also installs the rootkit Rdriv.sys. ... Read More
windows 32 editor Win32edit.exe
X
Added by the WOOTBOT.GQ WORM! ... Read More
Windows 32 Rescue win32resc.exe
X
Added by the W32/Forbot-EU worm. When started this infection connects to an IRC server where it waits for remote commands to executed. ... Read More
Windows 32 Rescue win32resc.exe
X
Added by the W32/Forbot-EU worm. When started this infection connects to an IRC server where it waits for remote commands to executed. This startup ... Read More
windows 32 update Windows-Update.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Windows 32-bit PnP Driver winpnp32.exe
X
Added by the W32.Wallz worm.
Windows 32bit System Manager win32sys.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Account Alternation wauclt.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Activation Technologies Service WatAdminSvc.exe
Y
Microsoft service that periodically determines if your Windows Product ID is valid, and if not, displays warnings that your copy of Windows may not be ... Read More
Windows AdControl WinAdCtl.exe
X
Windupdates adware variant
Windows Additional Guard WI345d.exe
X
Added by the Windows Additional Guard rogue anti-spyware program.
Windows AdService WinAdServ.exe
X
Windupdates adware variant
Windows AdStatus WinStat.exe
X
Unknown adware which causes popups. Can be removed via Add/Remove Programs in your control panel. ... Read More
Windows AdTools WinAdTools.exe
X
Windupdates adware variant
Windows Advance Firewall Protection Service wafps.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Advanced GFX Devolping Software wagfxds.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Anti Verifier Windows-Anti.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Anti Virus Control Center winavscan.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Application Extension W32AppSrv.exe
X
Added by the Troj/GrayBrd-AX backdoor Trojan.
windows application layer walg32.exe
X
Added by the AGOBOT.ATN WORM! ... Read More
Windows Application Layer Gateway walg32.exe
X
Added by the W32/Agobot-AAZ worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
Windows Application Security winappp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Archiver windat.exe
X
Added by the W32/Tilebot-BA worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows ARP Detectionc winlogon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows ARP Detectioncx winlogon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Auto Update winupdater.exe
X
Added by the SDBOT.TF WORM!
Windows Auto Update Tool wault.exe
X
Added by the W32/Tilebot-JQ worm with IRC backdoor Trojan functionality.
Windows Automatic Update wuamgrder.exe
X
Added by a variant of the RBOT WORM!
Windows Automatic Updater windrg.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Bool Service WinBool32.exe
X
Added by the Troj/Agent-GCV Trojan.
Windows Boot winboot.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Boot windowsboot.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Booter! winbooter.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windows clean-up pro WINDOWS CLEAN-UP PRO.Exe
X
WINDOWS CLEAN-UP PRO Rogue anti-spyware program. ... Read More
Windows Cleaner Service winclean.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Client Login Identafacation System wclis.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Client/Server Runtime Server Subsystem wcsrss.exe
X
Added by the W32/Tilebot-DA worm and IRC backdoor.
Windows Clock Configuration windowstm.exe
X
Added by the W32/Sdbot-DB backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execut ... Read More
windows command wincmd.exe
X
Added by the RBOT.ANV WORM! ... Read More
Windows Communicator wincomm.exe
X
Added by the AGOBOT-BH WORM!
Windows Conf windowsconf.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Config winbot.exe
X
Identified as an IRCbot variant.
Windows Config winconfig.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Config Loader Wincfg32.exe
X
Added by the SILVERFTP TROJAN!
Windows Config Loader WINNITE.EXE
X
Added by the Troj/Wisdoor-A backdoor Trojan.
Windows Config Manager winconf.exe
X
Added by the W32/Rbot-AIT worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Windows Configuration wsys32.exe
X
Added by the GAOBOT.FB WORM!
Windows Configuration wincfg32.exe
X
Added by the W32.Mytob.ED@mm mass-mailing worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Windows configuration wsconfig.exe
X
An Agobot worm and IRC backdoor variant.
Windows Configuration Service WinConfSrv.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Configurator winconf.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Connection Extension wcmsvc.exe
X
A variant of the SDBot family of worms and IRC backdoor Trojans.
Windows Console wkssvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Console Component wrasvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Console Norms wnbsvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Console Source wnbsvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Control Server wlmsvcxp.exe
X
Added by the W32/Bckdr-QLH worm and IRC backdoor.
Windows Control Server wksmgrtsgs.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows ControlAd WinCtlAd.exe
X
Windupdates adware variant
Windows Controls Center winudmr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Core Kernel Update win32bootcfg.exe
X
Added by the Troj/Ranck-EL proxy Trojan.
windows cpu host winbog32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Windows Critical Alert wincrt.exe
X
Trojan that display fake security warnings on your computer. This Trojan is part of the Smitfraud family of malware. You should use the guide below t ... Read More
Windows Database WinDat.exe
X
Added by an unidentified WORM or TROJAN!
Windows Database wiinsvc.exe
X
Added by the W32/Agobot-RU. When started this infection connects to an IRC server where it waits for remote commands. It can log key strokes, list o ... Read More
Windows DDE wmservet.exe
X
Added by the Troj/OnLineG-AO password-stealing Trojan.
Windows DDE Loader windde32.exe
X
Added by the W32/Sdbot-UZ WORM! Found in the Windows system folder.
Windows debug logging winlogg.exe
X
Added by the RBOT-OY WORM!
Windows debug logging winloggs.exe
X
Added by the RBOT-QN WORM!
Windows Debugger windbg.exe
X
Added by an unidentified VIRUS, WORM or TROJAN!
Windows Debugger windbg32.exe
X
Added by the W32.Zotob.L worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Decrypt manager wincrypt32.exe
X
Added by the W32/Tilebot-GC worm and IRC backdoor.
Windows Default Server wfdmgrsp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Default Server winampa.exe
X
Added by the WORM_IRCBOT.AUN worm and IRC backdoor.
Windows Defender wdc*.exe
X
A variant of the Trojan.Fakealert malware. This infection displays fake Windows Defender alerts which link to spyware-kicker.com. ... Read More
Windows Defender windowsdefender.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Defender windefender.exe
X
Added by the Troj/FakeAV-CYT fake alert malware.
Windows Defender Windefend.exe
X
Added by the Troj/FakeAV-EIE Trojan.
Windows Defender Adds wda*.exe
X
A variant of the Trojan.Fakealert malware. This infection displays fake Windows Defender alerts which link to spyware-kicker.com. ... Read More
Windows Defender Monitor wdm*.exe
X
A variant of the Trojan.Fakealert malware. This infection displays fake Windows Defender alerts which link to spyware-kicker.com. ... Read More
Windows Defender Updater wdu*.exe
X
A variant of the Trojan.Fakealert malware. This infection displays fake Windows Defender alerts which link to spyware-kicker.com. ... Read More
Windows Desktop Controler windesktop.exe
X
Added by the W32/Sdbot-XH WORM/IRC backdoor trojan!
windows desktop daemon winpadg.exe
X
Added by a variant of the W32.SPYBOT WORM! ... Read More
Windows Desktop Search WindowsSearch.exe
U
Main executable for Windows Desktop Search.
Windows DHCP Service windhcp.ocx
X
Added by the Troj/Agent-DWU Trojan. Do not delete C:\Windows\system32\rundll32.exe as that is a legitimate file. ... Read More
Windows Disk Defender windiskdefend.exe
X
Added by the Win7 AV rogue anti-spyware program.
Windows Disk Defragmenter wpabaln32.exe
X
Added by the Troj/Bancos-AEK Internet banking Trojan. If you are infected with this Trojan it is advised that you change all your online banking passw ... Read More
Windows DLL host winupd32.exe
X
Added by a variant of the W32.SPYBOT WORM!
windows dll loader wdevice.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Windows DLL Loader WINCFG32.EXE
X
Added by the W32/Agobot-TE worm.
Windows DLL Services winsvc32.exe
X
Added by the W32/Rbot-ZF WORM/IRC backdoor Trojan!
Windows DLL Verifier windlls.exe
X
Added by the W32/Rbot-AZQ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows DNS windns.exe
X
Added by the W32/Sdbot-XU worm. When started this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows DNS Daemon windnsd.exe
X
Added by the WOOTBOT.AS WORM!
Windows Domain Name Drivers windns.exe
X
Added by the W32/Forbot-EP WORM/IRC backdoor Trojan to thee Windows system folder,and is as a new service called "IEXPLORER-Drivers" with a display na ... Read More
windows download manager windlmngr.exe
X
Added by an unidentified TROJAN!
Windows Driver winxpdriver.exe
X
Added by the WOOTBOT.EE WORM!
Windows Driver windrive.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windows driver manager windriv32.exe
X
Added by the W32/Tilebot-CY worm and IRC backdoor.
Windows Driver Sup windvrhost.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Driver! windriver.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Drivers wmimgr.exe
X
Added by the Troj/Keylog-JT keylogger.
Windows Drivers windrivers.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows drivers update windowsupdate.exe
X
Added by the W32/Rbot-ACE worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
Windows Drivers Version WinDV.exe
X
A variant of the SDBot family of worms and IRC backdoor Trojans.
windows drivers32 windrvrs32.exe
X
Added by the W32/Tilebot-AG worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
windows dynamic loading header winDLL32.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Windows Email winemail.exe
X
Added by the W32/Mytob-JI worm. W32/Mytob-JI is a mass-mailing worm and backdoor Trojan that can be controlled through the Internet Relay Chat (IRC) n ... Read More
Windows Email Server wmserv.exe
X
Added by the W32/Foundu-A worm and IRC backdoor.
Windows Enterprise Defender WindowsEDefender.exe
X
Added by the Windows Enterprise Defender rogue anti-spyware program.
Windows Enterprise Suite WE83b.exe
X
Added by the Windows Enterprise Suite rogue anti-spyware program.
Windows Event Detection wecsvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Event Log wevtsvc.dll
Y
This service manages events and event logs. It supports logging events, querying events, subscribing to events, archiving event logs, and managing eve ... Read More
Windows Event Provider wposvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Event Service winserv.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Executable winmys.exe
X
Added by the W32/Rbot-ABO worm. When started, this infection connects to an IRC server where it waits for commands to execute. ... Read More
Windows Explorer Shell Winexec32.exe
X
Added by the REDIST.B WORM!
Windows Explorer-3212 WINRE16.EXE
X
Added by the HARDOC WORM!
Windows FAT 32 WINFAT32B.exe
X
Added by the W32/Spybot-AGT worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
Windows File Protection winprotect.exe
X
Added by the AGOBOT.JB WORM!
Windows File Update Auto Check Program WuxService.exe
X
Added by the Troj/Dloadr-BAF downloader Trojan.
Windows File Verification Service wfvs.exe
X
Identified as a variant of the Backdoor.Ranky malware.
Windows File XP Manager wfdmgr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Firewall WindowsFirewall.exe
X
Added by the W32/Mytob-X WORM/IRC backdoor trojan!
Windows Firewall Exception List Management Subsystem wfwmss.exe
X
Added by the Troj/Ranck-EH HTTP proxy server Trojan.
windows firewall log winlog.exe
X
Added by an unidentified WORM or TROJAN!
Windows Firewall Service wfsvc.exe
X
Added by the W32/IRCBot-YL worm and IRC backdoor.
Windows Firewall Updater windowsupdate.exe
X
Added by the W32.Spybot.AVEO worm. W32.Spybot.AVEO is a worm that attempts to exploit a number of vulnerabilities in order to spread. It may also spre ... Read More
windows firewalll winmu.exe
X
Added by a variant of the RBOT WORM!
Windows Fix Services winfix32.exe
X
Added by the W32/Tilebot-EW worm and IRC backdoor.
Windows Fixer winfix.exe
X
Added by the W32/Virut-I virus and backdoor Trojan.

W32/Virut-I runs continuously in the background, providing a backdoor server which ... Read More
Windows FormatAd WinForm.exe
X
Windupdates adware variant
Windows Gamma Display wingamma.exe
X
Added by the Antivirus 2010 rogue anti-spyware program.
Windows Genuine Advantage Registration Service wgareg.exe
X
Added by the W32/Cuebot-L worm and IRC backdoor.
Windows Genuine Advantage Validation Monitor wgavm.exe
X
Added by the W32/Cuebot-M worm and IRC backdoor.
Windows Genuine Advantage Validation Notification wgavn.exe
X
Identified as W32/Cuebot-K instant messaging worm and IRC backdoor.
Windows Genuine Check Windows Genuine Check.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Genuine Validate winservicessss.exe
X
A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote serv ... Read More
Windows GMT32 wingmt32.exe
X
Added by the W32/Mytob-EN worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Windows Graphics Loaders wingraphics.exe
X
Added by the SPYBOT.JG WORM!
Windows Guard WAUMGRD.EXE
X
Added by the W32/Rbot-GY trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Windows Guard Pro WindowsGP.exe
X
Added by the Windows Guard Pro rogue anti-spyware program.
Windows Guardian WinGuard.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Help winhlep.exe
X
Added by the Troj/Hupigon-SM Trojan.
Windows Help File winhelper32.exe
X
Added by the SDBOT-QK TROJAN!
Windows help Manager winhelp.exe
X
Added by the W32.Scrimge.G worm. W32.Scrimge.G is a worm that spreads through Microsoft instant messaging clients and opens a back door on the comprom ... Read More
Windows Help Service winhelpsv.exe
X
Added by the RBOT-LP WORM!
Windows Help Service winhlp.pif
X
Added by the W32/Rbot-AKW worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Helper winhelp.exe
X
Identified as a variant of the Trojan-Spy.Win32.Banker.ape malware.
Windows Helper wsctnfy.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
windows host winhost.exe
X
Added by the BACKDOOR.PRYSAT TROJAN! ... Read More
Windows Hosts winhosts.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows HTTP services winhttps.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Icons Manager wicomgr.exe
X
Added by the W32/Rbot-AIF worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
WINDOWS ID SYSTEM wID32.exe
X
Added by the W32/Mytob-FA worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. ... Read More
Windows Image wintimage.exe
X
A variant of the SDBot worm and IRC backdoor.
Windows Image Acquisition (WIASC) WIAcs.exe
X
A variant of the Backdoor.Rizo.A backdoor worm.
Windows Image Acquisition (WIASSC) WIAcss.exe
X
A variant of the Backdoor.Rizo.A backdoor worm.
windows imessenger messenger winimsg.exe
X
Added by the W32.ALLIM.A WORM! ... Read More
WINDOWS INIT wininit.exe
X
Added by the W32/Zotob-K worm and IRC backdoor. Please note that this infection should not be confused with the legitimate Windows file located at %Sy ... Read More
Windows Input Service wibsvc.exe
X
A variant of the Backdoor.Win32.SdBot.bzc family of worms and IRC backdoor Trojans. ... Read More
Windows installer winstall.exe
X
Related to the SpySheriff infection.
Windows Installer Manager winins.exe
X
Added by the W32/Sdbot-DHP worm and IRC backdoor.
Windows Instruction Services winstruct32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Internet Protocol winproc32.exe
X
CoolWebSearch parasite variant
Windows Internet Service wininet.exe
X
Added by the W32/Rbot-AUX worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Internet/Server winlogo.exe
X
Added by the Troj/GrayBrd-AC Trojan.
Windows IPv6 Drivers wipv6.exe
X
Added by the W32/Sdbot-VJ WORM! Found in the Windows system folder.
windows java update weatherBug32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Windows JavaScript Daemon Winjsd.exe
X
Added by the WOOTBOT.AF WORM!
Windows Kernel Log WinKettle.exe
X
Added by the Troj/Agent-HFA Trojan.
Windows Kernel Server wkserver.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Kernel System Service wkssvr.exe
X
Added by the W32/Rbot-FLL worm and IRC backdoor. W32/Rbot-FLL spreads to other network computers by exploiting common buffer overflow vulnerabilities, ... Read More
Windows Kernel System Service wkssvc.exe
X
Added by the W32/Vanebot-AA worm and IRC backdoor.
Windows Keyboard Services winkeybrd.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Keyboard Services winkeyboard.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Live WindowsLive.exe
X
Added by the W32/RealBot-A worm and IRC backdoor.
Windows Live Manager winlivemgr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Live Messenger Addon wllivemsngr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Live Msgr wllivemsgr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Live Msgs wlivemsg.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Live Msgs! wlivemsgs.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Live OneCare winss.exe
Y
Part of the Windows Live OneCare support package from Microsoft.
Windows Live OneCare winss.exe
Y
Microsoft's Windows Live One Care security software.
Windows live Support wlmsngr.exe
X
Added by the W32/Rbot-BKL worm and IRC backdoor.
Windows Load windows.com
?
??
Windows Loader wstart32.exe
X
Added by the GAOBOT.CA WORM!
windows loader winServices.pif
X
Reported by Kaspersky Anti-Virus as Spy.Win32.Cardspy.d TROJAN!
Windows Loader winBoot_INI.pif
X
Added by the PWSteal.Marlap information-stealing Trojan.
windows Loadxm Win_.exe
X
Added by the Troj/Fodder-A password-stealing backdoor Trojan.
Windows Local ISP winthcr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Logger winlog.exe
X
added by the Backdoor.Netshadow backdoor.
Windows logging winlogd.exe
X
Added by the RBOT-ON WORM!
Windows Logical Adapter wsrsvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Logical Connection wcnsvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Logical Driver wzrsvc.exe
X
Identified by Kaspersky Anti-Virus as a variant of the Backdoor.Win32.IRCBot.arv worm and IRC backdoor. ... Read More
Windows Login access windows.exe
X
Added by the Troj/DwnLdr-JDP Trojan.
Windows Login Folder winzep.exe
X
Added by the W32/Agobot-TZ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Login Manager winlogin.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Login Screen winlogin.exe
X
A variant of the Backdoor.Rizo.A backdoor worm.
Windows Login Security winlogin.pif or random name
X
Added by the W32/Rbot-AKL worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Login Service winlog.exe
X
Added by the W32/Rbot-AFN worm. This infection when started, connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Login Service winlogin.pif
X
Added by the W32/Sdbot-ACU worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Logins Screen winlogins.exe
X
A variant of the Backdoor.Rizo.A backdoor worm.
Windows Logon winlogin.exe
X
Added by the SPYBOT-C TROJAN!
Windows Logon Application winlogon.exe
X
Added by Backdoor.Dsklite. This infection listens on port 890 awaiting commands. ... Read More
Windows Logon Application WinIogon.exe
X
Added by the "Cruel Intentionz" backdoor TROJAN!
Windows Logon Application win32help.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Logon Applicationedc winlogon.exe
X
Added by the Troj/DwnLdr-HGR Trojan.
Windows Logon Applicatonedc winlogon.exe
X
Added by the Troj/VB-EBV Trojan. This infection should not be confused with the legitmate C:\Windows\System32\winlogon.exe file. ... Read More
windows logon procedure winlogonpc.exe
X
Added by the "WinLogon" TROJAN! ... Read More
Windows Logon Screen winlogon.exe
X
A variant of the Backdoor.Rizo.A backdoor worm.
Windows Logon Service winlogon.pif
X
Added by the W32/Rbot-AOU worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Windows Logon Service winlogoservice.exe
X
Added by the W32.Spybot.ANOO worm and IRC backdoor.
Windows Logons Screen winlogons.exe
X
A variant of the Backdoor.Rizo.A backdoor worm.
Windows LoL Layer winlolx.exe
X
Added by the W32/Rbot-FOR worm and IRC backdoor.
Windows LoL Layer win.exe
X
Added by the W32/Rbot-FTO worm and IRC backdoor.
Windows Lord Anti-Virus winlord32.EXE
X
Added by the Troj/SdBot-GW worm. When started, this infection connects to an IRC server where it waits for remote commands to execute. ... Read More
Windows Mail Services WinMailSrv.exe
X
Added by the Troj/Hupigo-VY Trojan.
Windows Maintenance WINMAINT.EXE
X
Identified by VBA32 antivirus as Trojan-Dropper.Agent.35.
Windows Management Instrumentation wmimgr.exe
X
Added by the W32.Qdens.A QQ messenger worm.
WINDOWS MANAGEMENT SYSTEM wm1exe.exe
X
W32/Rbot-VT is a network worm that has backdoor functionality. Located in the Window system directory. ... Read More
Windows Manager winmants.exe
X
Added by the MANTAS WORM!
Windows Manager windows31.exe
X
Added by the W32/Sdbot-DY backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execut ... Read More
Windows Manager System winoper.exe
X
Added by the W32/Rbot-GXV worm and IRC backdoor.
Windows mangement winlogonn.exe
X
Added by the RANDEX.FC WORM!
windows media ap winmapp.exe
X
Added by an unidentified WORM or TROJAN!
windows media app wmapp.exe
X
Added by an unidentified WORM or TROJAN!
windows media connect 2 WMCCFG.exe
U
Related to Windows_Media_Connect from Microsoft. Stream digital media files on your computer to digital media receivers (DMRs) that are connected to ... Read More
windows media loader wmloader.exe
X
Added by the W32.HLLW.Gaobot.gen WORM! ... Read More
Windows Media Player wmediaplayer.exe
X
Added by the AGOBOT-NQ WORM!
Windows Media Player wmplayer.exe
X
An R-bot variant adds this, opening a backdoor to a malicious user and allowing the start of a remote shell, and download/upload/execution of various ... Read More
Windows Media Player wmplayer.exe
X
The W32/Rbot-YT WORM/IRC backdoor adds the file, a hidden, read-only, system file. ... Read More
Windows Media Player wmplayer.exe
X
Added by the W32.Kelvir.G or W32.Kelvir.H or W32.Kelvir.I WORM!
Windows Media Player winmedia.exe
X
Added by the Troj/Banker-AVX password-stealing Trojan.
Windows Media Player wmplayerc.exe
X
Added by the W32.SillyFDC.BDG worm. W32.SillyFDC.BDG is a worm that spreads by copying itself to mapped drives. It also attempts to download files, lo ... Read More
windows media player 3.6 wmpa36.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Windows Media Player 3.6b WMPA36B.EXE
X
Added by the W32/Rbot-VV worm. When started this infection connects to a remote IRC server where it waits for commands to execute. These infections ... Read More
Windows Media Player 3.6d wmpa36d.exe
X
The W32/Rbot-YA WORM/backdoor places this to spread to network shares, and allow unauthorised remote access. ... Read More
windows media player 3.9 wmpa36.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Windows Media Player Service wmedia.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Media Server wmserv.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Media Server! wmserver.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Media Sharing wmsvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windows media utility wmediautil.exe
X
Added by a variant of the W32.SPYBOT WORM! ... Read More
Windows Memory Manager windowsmem.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Messanger Control Center winlogon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Messanger Control Center winlogin.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Messenger Connect wmdsvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Messenger Fileshare wivsvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Messenger Live MSN winlivemsnmessenger.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Messenger Live Startup windowslivemsn.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Messenger Live Startup windowsmsnlive.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windows messenger messenger winmsg.exe
X
Added by W32.Velkbot.A WORM! ... Read More
Windows Messenger Panel wbcsvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Messenger Service winsmsgr.exe
X
Added by W32/Rbot-VW. Found in the Windows system folder.
Windows Messenger Share wmssvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Messenger Starter wmvsvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Micro Drivers wupdates32.exe
X
Added by the W32/Rbot-AEH worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Windows Microsoft Update wintask32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Microsoft Verifier winauth23.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows mid Control Services wuactll.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Mobile Device Center wmdc.exe
N
Added by the Windows Mobile Device Center. The Windows Mobile Device Center enables you to set up new partnerships, synchronize content and manage mus ... Read More
Windows Mobile-based device managemen wmdSync.exe
U
Added by the Windows Mobile Device Center is a program for Windows Vista and Windows 7 that allows you to manage device settings, media, and programs ... Read More
Windows mod Verifier Windows-mod.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Mode Verifier WindowsActivation.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows modez Verifier Windows-.exe
X
Added by the W32/Rbot-DIO worm and IRC backdoor.
Windows modez Verifier winl0g0z.exe
X
Added by the W32/Rbot-FNB worm and IRC backdoor.

W32/Rbot-FNB spreads to other network computers by exploiting common buffer overflow v ... Read More
Windows modez Verifier Windows12.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows modez Verifier Window2.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows modez Verifier Windows-.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows modez Verifier winl0g0z.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows modez Verifier winlogom.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows modez Verifier wuamguard.exe
X
A variant of the Backdoor.Win32.Rbot.cya family of worms and IRC backdoor Trojans. ... Read More
Windows Monitor winmon.exe
X
Added by the SDBOT.VB WORM!
Windows Monitor Winsys32.exe
X
Unknown malware.
Windows Monitor Services winmonitor.exe
X
The W32/Rbot-XX WORM/IRC backdoor Trojan adds this, allowing unauthorized remote access and termination of processes, DoS attack participation, and do ... Read More
Windows Monitoring Service winmon.exe
X
Added by a variant of the SDBOT WORM!
Windows Mouse Services winmouse.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Mouse Services winmouse64.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windows msconfig startup logger winlog.exe
X
Added by the RBOT.BCU WORM! ... Read More
Windows MSN wmsnlivexp.exe
X
Added by the W32/Sdbot-CXR worm and IRC backdoor.
Windows MSN Live Messenger winlivemsn.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows MSN Live Messenger winmessengerlive.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows MSN Updates wnd32.exe
X
Added by the Troj/IRCBot-ABA worm and IRC backdoor.
Windows MSX drivers winmsx.exe
X
Added by the W32/Rbot-AYG worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows NetDDe wrmana32.exe
X
Added by the W32.Mytob.IM@mm worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Windows Nets WinNET.exe
X
Added by the RBOT-MO WORM!
Windows NetStart Service winsN2S.exe
X
Added by W32/Rbot-ZX.
Windows NetStart Service2 winsN2S.exe
X
Added by the W32/Rbot-ABN trojan. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infec ... Read More
windows netstart service2 winsN2SD.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Windows Network Controller winmms32.exe.exe
X
Added by the W32/Forbot-ED wORM! It is found in the Windows system directory. ... Read More
Windows Network Controller WinxPupd.exe
X
Added by the FORBOT-DK WORM!
Windows Network Controller wingmt.exe
X
Added by a variant of the W32/SDBOT WORM!
windows network controller Win9x.exe
X
Added by the WOOTBOT.I WORM! ... Read More
Windows Network Data Management Service wndms.exe
X
Identified as a variant of the Backdoor:Win32/Redvoz.A malware.
Windows Network Firewall w32svc.exe
X
Added by the W32/Sdbot.worm!811a7027 worm and IRC backdoor.
Windows Network Policy Manager Service wnpms.exe
X
Added by the Backdoor.Wnetpols backdoor Trojan.
Windows Network Security Service wnss.exe
X
Identified as a variant of the Backdoor.Win32.Agent.dvq backdoor Trojan.
Windows Network Service winvc32.exe
X
Added by the RBOT.RY WORM!
Windows Network Services winnetwork.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Network Services winnetwork32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Network Services winnetwork64.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Networking winsys32.exe
X
Added by the GAOBOT.FL WORM!
Windows Newresck wzolehqt.exe
X
Added by the W32/Sdbot-DOA worm and IRC backdoor.
Windows Notification Service winntify.exe
X
Rootkit found with SmitFraud infections.
Windows NT application winlogon.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Windows NT Login Application winlogons.exe
X
Added by the Troj/BitCDl-A Trojan.
windows nt login session manager WNSM.EXE
X
Added by the RBOT.BIV WORM! ... Read More
Windows NT Logon Application WINLOGON.SCR
X
Added by the W32/Rbot-ALP worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows NT Logon Application winlogon.exe
X
Unknown malware. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
Windows NT Service Name winshock.exe
X
Added by the RBOT-PK WORM!
Windows NT Update Manager WINL0G0N.exe
X
Added by the AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital "o" ... Read More
Windows Ocx Service winocx.exe
X
A IRCBot worm and IRC backdoor variant.
Windows OEM Tools winres32.exe
X
Added by the SPYBOT.FD WORM!
windows pc winmgr.exe
X
Added by the W32/BIBOT-A WORM! ... Read More
Windows PC Defender WP345d.exe
X
Added by the Windows PC Defender rogue anti-spyware program. Please note that the file and folder that this infection resides in may be random. ... Read More
Windows PDG winpdg.exe
X
Added by the W32/Rbot-ADW worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
windows performance monitor wmscupd.exe
X
Added by Ircbot_Gen WORM! Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) ... Read More
Windows Plug and Play wpnsvc.exe
X
A variant of the W32/SDBot family of worms and IRC backdoor Trojans.
Windows Plugin winmsn.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows PNP winpnp.exe
X
Added by the W32/Rbot-AKN worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Population Logger winpo32.exe
X
Identified as the WORM_AGENT.YKR malware.
Windows Printing Driver WinPrint.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Printing Driver WinSpooler.exe
X
Unknown malware.
Windows Process Dump windumper32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windows process manager winproc.exe
X
Added by an unidentified WORM or TROJAN!
Windows Protection Suite WI345d.exe
X
Added by the Windows Protection Suite rogue anti-spyware program.
Windows Protector winprot32.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Registers winservicess.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Registry winhost.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Registry Cleaner winclean.exe
X
Added by a variant of the SPYBOT WORM!
Windows Registry Control winreg.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Registry DLL winregdll.exe
X
Unknown malware.
Windows Registry Name winses.exe
X
Added by the W32/Rbot-ADB worm. When started this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Registry Name WinUUpdate.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Registry Name winupdate_.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Registry Startup wind32.exe
X
Added by the AGOBOT-BZ WORM!
Windows Registry XP winxptdl.exe
X
Added by the WORM_IRCBOT.AUN worm and IRC backdoor.
Windows Remote Addressing wnpcgs.exe
X
Added by the Troj/Delf-EZN Trojan.
Windows Rescue System winsto.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Agent.avf malware.
Windows Reserve winrvs.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Reverse Preperation winrvp.exe
X
Identified as a variant of the Backdoor.Win32.IRCBot.axp worm.
Windows Reversed Virus Protection winrsvp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows RPC Services winrpc.exe
X
Added by the W32/Tilebot-CR worm and IRC backdoor.
windows run-time 64bit win64rt.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Windows Runtime Help win32hlp.exe
X
Added by a variant of the AIMVISION TROJAN!
Windows Runtime Help WinRunHelp.wrh
X
Added by a variant of the AIMVISION TROJAN!
Windows SafeAssist winlogon.exe
X
Added by the Troj/VB-FGB Trojan. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
Windows Scanner Service winscnr.exe
X
Added by the Troj/Agent-JBC Trojan.
Windows Scheduler wmscheduler.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Search WindowsSearch.exe
U
Windows Search adds support for indexing encrypted files, and enables PC-to-PC search on every operating system where Windows Search 4.0 runs-while an ... Read More
windows secure connection winsc.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Windows Secure Update WinUpdate.exe
X
Added by the Troj/Banker-AAO banking Trojan.
Windows Secure Update WinSecUp.exe
X
Added by the W32/Rbot-GCD worm and IRC backdoor.
Windows Secure Update winupser.exe
X
Added by the W32/Rbot-GCG worm and IRC backdoor.
Windows Secure Update WinSecure.exe
X
Added by the W32/Rbot-GDO worm and IRC backdoor. W32/Rbot-GDO spreads to other network computers by exploiting common buffer overflow vulnerabilities, ... Read More
Windows Secure Update wupdate.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Security winmon.exe
X
Added by the W32/Sdbot-SR worm. When started, this infection will connect to a remote IRC server and wait for commands to execute. ... Read More
Windows Security win.pif
X
Added by the W32/Rbot-APT worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Windows Security winscure.exe
X
Added by the W32/Rbot-BAF worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Security Alert wsçntfy.exe
X
Added by the W32/Spelit-A mass-mailing worm and IRC backdoor.
Windows Security Assistant winsec.exe
X
CoolWebSearch parasite variant
Windows Security Center winmgr.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Windows Security Center winlogon.exe
X
Added by the W32/Autorun-BEX removable media worm.
Windows Security Center Notification App wscnfty.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Security Center Notification Appl wscnfty.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windows security manager winsecurity.exe
X
Added by the W32/AGOBOT-KI WORM! ... Read More
Windows Security Service windows.pif
X
Added by the W32/Rbot-AMG worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Security Tool WinSecure.exe
X
Added by the Troj/Agent-GPY Trojan.
Windows Security Update winupdat.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windows security updater WINFRW.exe
X
Added by the Solufina TROJAN! ... Read More
Windows ServeAd WinServAd.exe
X
Windupdates adware variant
Windows Server winserv.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Server AutoUpdate Winupdate.exe
X
Added by the Troj/GrayBrd-CF backdoor Trojan.
Windows Server Client Verification Service wscvs.exe
X
A variant of the Backdoor.Ranky malware.
Windows Server IP Verification Service wsivs.exe
X
Added by the Backdoor.Ranky backdoor Trojan.
Windows Server! winsvr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Servic2 winsy.exe
X
Added by the W32/Rbot-AIA worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows service wuamgrd.exe
X
Added by the RBOT-QW WORM!
Windows Service windowz.exe
X
Added by the W32/Sdbot-AYI worm and IRC backdoor. This infection utilizes stealth rootkit technology to protect itself via the c:\Windows\System32\ms ... Read More
Windows service winsrv.exe
X
A variant of the SdBot.bhk family of worms and IRC backdoor Trojans.
Windows Service WINSVC.EXE
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Service Agent winupds32.exe
X
Added by the W32/Rbot-GQT worm and IRC backdoor.
Windows Service Agent wmscc.exe
X
Added by the W32/Rbot-GQP worm and IRC backdoor.
Windows Service Agent win32wins.exe
X
Added by the W32/Rbot-LOL worm and IRC backdoor.
Windows Service Agent wit.exe
X
Added by the W32/Rbot-GQV worm and IRC backdoor.
Windows Service Agent winup32.exe
X
Added by the W32/Rbot-GQX worm and IRC backdoor.
Windows Service Agent wgl23.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Service Agent winserv.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Service Find wrfkuk.exe
X
Added by the Troj/IRCBot-XZ worm and IRC backdoor.
Windows Service help winservices.exe
X
Added by the TROJ_DROPPER.TT Trojan.
Windows Service Loader window.exe
X
An Rbot variant. This infections connects to an IRC server where it awaits commands from a remote user. ... Read More
Windows Service Manager userint32.exe
X
Added by the W32/Oscabot-C worm. When started, this infection connects to an IRC where it waits for remote commands to execute. ... Read More
Windows Service Manager winmgr32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Service Pack 2 WindowsSP2.exe
X
Added by the W32/Sdbot-TQ worm/backdoor.
Windows Service Supply winsupply.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Service Utitity winsrvc.exe
X
Added by the W32/Rbot-ASI worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. ... Read More
Windows Services winsvc32.exe
X
Added by the W32/Mytob-CB. This infection connects to an IRC server on startup where it waits for remote commands to execute. ... Read More
Windows Services winspsv.exe
X
Added by the Troj/Sdbot-BA backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execu ... Read More
Windows Services winserv.exe
X
Identified as the Trojan.Win32.Agent.awz malware.
Windows Services winlogon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Services winudp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Services w32services.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Services w32service.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Services w32edus.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Services winsysdll.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Services winsyssrv.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Services windows.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Services weccom.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windows services ink platform tablet input subsystem wsiptis.exe
X
Added by the RBOT.APC WORM! ... Read More
Windows Services Layer winlogz2.exe
X
Added by the W32/Rbot-FZE worm and IRC backdoor.

W32/Rbot-FZE spreads to other network computers by:
- exploiting common buffer ... Read More
Windows Services Layer winl0g0.exe
X
Added by the W32/Rbot-FZQ worm and IRC backdoor.
Windows Services Managt wpservice.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Services32 winsvc32.exe
X
Added by the W32/Mytob-GK worm and IRC backdoor.
Windows shell win70.exe
?
??
Windows Shell winshell.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Shutdown Service Launcher wssl.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Socket 2.0 Non-IFS Service Provider Support Environment ws2ifsl.sys
Y
This is a legitimate service and is used by LSPs which do not use IFS (Installable File System) supported sockets. ... Read More
Windows Socket Procedure WinSock32.exe
X
Added by the W32/Rbot-FMX worm and IRC backdoor.
Windows Socket System Service wksrvs.exe
X
Added by the Troj/IRCBot-RC worm and IRC backdoor Trojan.
Windows Sound Verifier WinIp32.exe
X
Added by the W32/Rbot-FMO worm and IRC backdoor.

W32/Rbot-FMO runs continuously in the background, providing a backdoor server
w ... Read More
windows sp2 firewall wfirewall7.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
windows sp2 version load wuauclt32.exe
X
Added by the GAOBOT.CX WORM! ... Read More
Windows Spool winspool.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Spooler winsplr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Spools SV winsv.exe
X
Added by the W32/Rbot-AUQ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows spyware remover Windows-spyware.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windows sq drivers winmsn32.exe
X
Added by the W32/Rbot-ADI ... Read More
Windows Sql Service For Windows 32 Bit winsql32.exe
X
Added by the W32/Forbot-FC worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows SRS Client winsrs.exe
X
Added by the W32/Rbot-BXQ worm and IRC backdoor. This infection also modifies your C:\Windows\system32\drivers\etc\hosts file so that you can not con ... Read More
Windows SRT Client winsrt.exe
X
Added by the W32/Rbot-BFR worm and IRC backdoor.
Windows SSH Client winssh.exe
X
Added by the W32/Rbot-AXC worm. When started, this infection connects to a remote IRC server where it waits for commands to execute ... Read More
Windows SSL File winssv.exe
X
Added by the WOOTBOT.CA WORM!
Windows Startup winsta~1.exe
X
GoHip foistware
Windows Startup winstartup.exe
X
GoHip foistware
Windows Startup Wdrun32.exe
X
Added by the GAOBOT.AO WORM!
windows subsys winload.exe
X
Added by the NETSPREE.C WORM! ... Read More
WINDOWS SVC winsvc.exe
X
Added by the W32.Mytob.KR@mm worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. ... Read More
Windows SYN Control Center winmnon32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Sync-Manager wmisvmgr.exe
X
Added by the W32/Rbot-GXK worm and IRC backdoor.
Windows System WINSYS.exe
X
Added by the W32/Rbot-AEF worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
WINDOWS SYSTEM winsys33.exe
X
Added by the W32/Mytob-BI worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
WINDOWS SYSTEM winligon.exe
X
Added by the W32/Mytob-FD worm. When started, this infection connects to a remote IRC server and waits for commands to execute. ... Read More
WINDOWS SYSTEM win.exe.exe
X
Added by the W32.Mytob.FA@mm worm. When started, this infection connects to a remote IRC server and waits for commands to execute. ... Read More
WINDOWS SYSTEM winvnc.exe
X
Added by the W32.Mytob.EU@mm worm. When started, this infection connects to a remote IRC server and waits for commands to execute. ... Read More
WINDOWS SYSTEM winxpserv.exe
X
Added by the W32/Mytob-BQ worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
WINDOWS SYSTEM winmon.exe
X
Added by the W32.Mytob.GB@mm worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
WINDOWS SYSTEM WinSys4.exe
X
Added by the W32.Mytob.GG@mm worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
WINDOWS SYSTEM wdns33.exe
X
Added by the W32/Mytob-BY worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
WINDOWS SYSTEM winsvc32.exe
X
Added by the W32/Mytob-DJ worm. When infected your computer will become an open mail relay which will allow your computer to be used to send out spam. ... Read More
WINDOWS SYSTEM winNTsys32.exe
X
Added by the W32/Mytob-DM worm. When infected your computer will become an open mail relay which will allow your computer to be used to send out spam. ... Read More
WINDOWS SYSTEM winaup.exe
X
Added by the W32/Mytob-DN worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
WINDOWS SYSTEM Win32IMAPSVR.exe
X
Added by the W32/Mytob-FQ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
WINDOWS SYSTEM wupdate.exe
X
Added by the W32/Mytob-HT mass-mailing worm and IRC backdoor.
Windows System winsys32.exe
X
Added by the W32/Mytob-IS mass-mailing worm and IRC backdoor.
Windows System winsystem.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WINDOWS SYSTEM 32 windowsupdated32.exe
X
Added by the WORM_MYTOB.NS worm and IRC backdoor.
Windows System 32 winsys_32.exe
X
Added by the W32/Rbot-FTR worm and IRC backdoor. W32/Rbot-FTR spreads to other network computers by exploiting common buffer overflow vulnerabilities, ... Read More
windows system 32-bat service win32bat.exe
X
Added by the W32.Mytob.FI(AT)mm ... Read More
WINDOWS SYSTEM By FEnR windasz-updote.exe
X
Added by the W32/Mytob-EZ worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. ... Read More
Windows System Configuration WINFRW.EXE
X
Added by the W32/Domwis-H WORM/IRC backdoor Trojan, it will grant an attacker remote access to perform a wide variety of actions. ... Read More
Windows System Configuration WINCFG32.EXE
X
Added by the W32/Agobot-TE worm.
Windows System Configuration WinNeth.exe
X
Added by the W32/Rethe-A worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows System Defender WS83b.exe
X
Added by the Windows System Defender rogue anti-spyware program.
WINDOWS SYSTEM Dns windsns.exe
X
Added by the W32.Mytob.EY@mm worm. When started, this infection connects to a remote IRC server and waits for commands to execute. ... Read More
windows system init winit32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Windows System Manager winsystem.exe
X
Added by the RBOT-AN WORM!
Windows System Manager winsysmngr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows System Manager winsysmgr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows System Manager Proc winsmc.exe
X
Added by the RBOT.JH WORM!
windows system notepad wnpsm.exe
X
Added by an unidentified WORM or TROJAN!
Windows System Security winmp.exe
X
Added by the RBOT.IV WORM!
Windows System Serivce winserv.exe
X
Added by a variant of the RBOT WORM!
windows system service winsock.exe
X
Added by the RBOT-MR WORM!
Windows System Service wnuserv.exe
X
Added by the W32.Spybot.ANDM worm. W32.Spybot.ANDM is a worm that spreads through mIRC and to network shares protected by weak passwords. It also spre ... Read More
Windows System Suite WS<random characters>.exe
X
Added by the Windows System Suite rogue security program.
Windows System Tray wintray.exe
X
Added by the W32/Tilebot-EH worm and IRC backdoor.
Windows System32 winsystem32.exe
X
Added by the W32/Rbot-UO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
windows system32 windowsp.exe
X
Added by the MYTOB.GD WORM! ... Read More
Windows System32 winsys32.exe
X
Added by the W32/Sdbot-AFW worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. It also creates ... Read More
Windows System32 windows32.exe
X
Added by the W32/Rbot-FPB worm and IRC backdoor.

W32/Rbot-FPB spreads to other network computers by exploiting common buffer overflow v ... Read More
Windows System32 wingrd32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Systems16 winjews16.exe
X
Added by the W32/Sdbot-CXT worm and IRC backdoor.
windows sz host winshvc.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Windows TaskAd Wintaskad.exe
X
Windupdates adware variant
Windows Taskbar Manager wlmsn.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Taskmanager wdtsvc.exe
X
Unknown malware.
Windows Taskmanager winpifviewer.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows TCP/IP wintcp.exe
X
Added by the AGOBOT-ZH WORM!
Windows Telnet Server wintel.exe
X
Added by the AGOBOT-MW WORM!
Windows Temperate Services wintmp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Time winmgr.exe
X
The W32/Rbot-XC WORM/backdoor Trojan adds this and allows malicious remote access by way of the IRC network. ... Read More
Windows Time Keeper windowstime.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Time Service Diagnostic Tool winscrvs.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Time Sync wstime.exe
X
Added by the W32/Rbot-AZA worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
windows tm WinxSys.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Windows UDP winudp.exe
X
Added by the WORM_IRCBOT.GAT worm and IRC backdoor.
Windows UDP Communication wudpcom.exe
X
Added by the IRC-Mocbot IRC backdoor.
Windows UDP Control winudspm.exe
X
Added by an unknown worm and IRC backdoor.
Windows UDP Control Center winudpmg.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows UDP Control Center winuscn32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows UDP Control Center wksvcsc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows UDP Control Center winlive32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows UDP Control Center winupmgr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows UDP Control Center winudpmgrs.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows UDP Control Center winrofl32.exe
X
Added by the Troj/LdPinch-RZ Trojan.
Windows UDP Control Center winudpmgr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows UDP Control Center winudpmsgr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows UDP Control Center winmsn.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows UDP Control Manager winudpmgr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows UDP Control Services wksvcsc.exe
X
Added by the Troj/AntiAV-C backdoor Trojan.
Windows Updat winupdat.exe
X
Added by the Troj/Agent-QYU Trojan.
Windows Update wudate.exe
X
Added by the AGOBOT.ML WORM!
Windows Update wupdate.exe
X
Wengs adware
Windows Update Wuamgrd.exe
X
Added by a variant of the SPYBOT WORM!
windows update wuraclt.exe
X
Added by the RBOT-PO WORM!
windows update Wuanclt.exe
X
Added by the RBOT.XZ WORM!
Windows Update windows.exe
X
Added by the RBOT-RB WORM!
windows update wuaurlt.exe
X
Added by the RBOT.ADG WORM!
Windows Update winmguard.exe
X
Added by the RBOT-EM WORM!
Windows Update wuampd.exe
X
Added by the RBOT.UM WORM!
windows update wuarclt.exe
X
Added by the RBOT-OF WORM!
Windows Update winupdate.exe
X
Added by the W32/Sdbot-WS WORM/IRC backdoor Trojan.
Windows Update winupupdate1.exe
X
Added by the W32/Rbot-UV worm. When started, this infection connects to an IRC server where it waits for remote commands. ... Read More
Windows Update winlogin.exe
X
Added by the Troj/Banker-DV password-stealing trojan.
Windows Update wininfo.exe
X
Added by the W32.Mytob.GA@mm worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Update windowsx.exe
X
Added by the Troj/Bancd-A password-stealing Trojan.
Windows Update wupdmgr.exe
X
Added by the Troj/Bancban-FC password stealing Trojan.
windows update wudupdate.exe
X
Adware downloader - Istbar related ... Read More
Windows Update winupdmon.exe
X
Added by the W32/Tilebot-AR worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Update wrundll2.exe
X
Added by the Troj/Bdoor-VK backdoor Trojan.
Windows Update Windows Update.exe
X
Added by the Troj/Banker-BIQ Trojan.
Windows Update winlog.exe
X
Added by the Troj/IRCBot-TJ Trojan.
Windows Update winlogonEvt.exe
X
Added by the Troj/VB-DXM Trojan.
Windows Update winsck.exe
X
Identified as a variant of the Backdoor.Win32.Shark.bb malware.
Windows Update win32update.exe
X
A variant of the Worm.SdBot.FTK family of worms and IRC backdoor Trojans.
Windows Update windowsupdats.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Update winupd.exe
X
Added by the Troj/Dwnldr-ZLD Trojan.
Windows Update winsyser.exe
X
A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote serv ... Read More
Windows Update winsc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Update winserv.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Windows Update WindowsUpdate.exe
X
Added by the Troj/Bdoor-AOH backdoor Trojan.
Windows Update wuauclt32.exe
X
Added by the WORM_SDBOT.DHY worm and IRC backdoor.
Windows Update winup.exe
X
Added by the W32/Autorun-BGA removable media worm.
Windows Update winvv.exe
X
Added by the Troj/PHPBot-B Trojan.
Windows Update 32 winlogons.exe
X
Added by the W32/Forbot-FI worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Update 64 WinV.exe
X
Added by the W32/Forbot-FP worm and IRC backdoor.
Windows Update Auto Update wuaumgr.exe
X
Added by a variant of the W32.SPYBOT WORM!
Windows Update Automation winuptdate.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Update Automation winupdate.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Update Automation wndupdate.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Update AutoUpdate Client waucult.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Update AutoUpdate Client Product wuauct.exe
X
Added by the AGOBOT.ACL WORM!
windows update center W32RSA.exe
X
Added by an unidentified WORM or TROJAN!
Windows Update Client wuclient.exe
X
Added by the SMALL-RN TROJAN!
Windows Update Client Service windrvl32.exe
X
Added by the AGOBOT-MM TROJAN!
Windows Update Firewall System winmsfw.exe
X
Added by the W32/Rbot-EEO worm and IRC backdoor.
Windows Update Firewall System winmsfws.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Update GUI Executable x32x wupdategux32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Update Host winupsvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Update Manager wupdmngr.exe
X
Added by the RANDEX.BTB WORM!
Windows Update Manager Winlog0n.exe
X
Added by the AGENT-BO TROJAN!
Windows Update Manager winup.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Update Manager WindowsUpdateManager.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Update Manager for NT wupdmgr32.exe
X
Added by the SDBOT.AH WORM!
Windows Update Manager Security Service wumss.exe
X
Identified as a variant of the Backdoor.Win32.Agent.ekc backdoor Trojan.
Windows Update Monitoring Service winupdt.exe
X
Added by the RBOT-PL WORM!
Windows Update Process wmiprvsc.exe
X
Added by the SDBOT-CB WORM!
Windows Update Servers winupdate.exe
X
Added by the Troj/Dloadr-HAD Trojan downloader.
Windows Update Service wuacltl.exe
X
Added by the W32/Rbot-KB trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This i ... Read More
Windows Update Service wupdated.exe
X
Added by the W32/Sdbot-TB worm. When started, this infection connects to a remote IRC server and waits for commands to execute. ... Read More
Windows update Service wisvcc.exe
X
Added by the Troj/Orse-G Trojan. This infection also creates the file %System%zlbw.dll. ... Read More
Windows Update Service WindowsUP.exe
X
Added by the W32/Sdbot-CRV worm and backdoor.

W32/Sdbot-CRV is capable of spreading to network shares protected by weak passwords. The ... Read More
windows update services wservices.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
windows update services wins32svcs.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Windows Update SP3 Windat.EXE
X
Added by the W32/Rbot-GTS worm and IRC backdoor.
Windows Updater wupdmgr32.exe
X
Added by a variant of the DOS.AUTOCAT TROJAN!
Windows Updater win64tyt.exe
X
Added by the W32/Sdbot-CNH worm and IRC backdoor.
Windows Updater WinUpdater.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
windows updater online winupdatexx.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Windows Updater Service Manager winupdatr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Updater Services winupdate.exe
X
Identified as the Spybot.AHM.worm worm and IRC backdoor.
windows updaters winupdats.exe
X
Added by the W32/Spybot-IS worm and IRC backdoor. This infections spreads to computers already infected with Troj Sub7 and Troj/Kuang. ... Read More
Windows Updates winupd32.exe
X
Added by the W32/Mytob-AY worm. When started, this infection connects to an IRC where it waits for remote commands to execute. ... Read More
Windows Updates w32dns.exe
X
Added by the W32/Sdbot-BFW worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Windows Updates WindowsUpdates.exe
X
Added by the WORM_SDBOT.CLU worm and IRC backdoor. This infection is also bundled the rdriv.sys rootkit. ... Read More
Windows Updates winlogon32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Updates Agent winupdate.exe
X
A variant of the Worm.Rbot.AAOO family of worms and IRC backdoor Trojans.
Windows Updtee Mgnr W1NT45K.exe
X
Added by the W32.Mytob.DC@mm worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Windows Upgrate Utility winulty.exe
X
Added by the W32/Autorun-ASR removable media worm.
Windows UPnP Service wupnp.exe
X
Added by the W32/Cuebot-F backdoor worm.
Windows Uptade winupd.exe
X
A variant of the Backdoor:W32/PoisonIvy backdoor Trojan. Backdoor:W32/PoisonIvy is a family of backdoors that give a remote user extensive access to a ... Read More
Windows USB controler winusb.exe
X
Added by the W32/Rbot-HR trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Windows USB Driver Support Windowsusb.exe
X
Added by a variant of the W32.SPYBOT WORM!
Windows USB Service wsftpsrv32.exe
X
Added by the W32/Rbot-CDV worm and IRC backdoor.
Windows USB v3.2 wsvc.exe
X
A variant of the WORM_SDBOT family of worms and IRC backdoor Trojans. This infection hides itself using the msdirectx.sys rootkit. ... Read More
Windows User Mode Driver Manager wdfmrg.exe
X
Added by the W32/Sdbot-ZN worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
windows user starter winuser32.exe
X
Added by the RBOT.SN WORM! ... Read More
Windows Utilities Manager Windows.exe
X
A variant of the Sdbot family of worms and IRC backdoor Trojans.
Windows Video wvidsvc.exe
X
Added by the W32/Rbot-SJ worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
Windows Video Acquisition (WVA) wvsvc.exe
X
Added by the AGOBOT.YM WORM!
Windows Video Component wvcsvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Virtual Services winvirtual.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Virtual Services winvirtual32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Virus Scanner winvsvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Vista Corparation Agent Services winxp_sp3.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Web Services websvc.exe
X
Added by the Troj/Dloader-NY trojan.
Windows Winhlp32 Stub Service winhlp32.pif
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows WKS Services wkssvr1.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows WMF Fix winfix.exe
X
Added by the W32/Rbot-FTQ worm and IRC backdoor. W32/Rbot-FTQ spreads to other network computers by exploiting common buffer overflow vulnerabilities, ... Read More
Windows Workstation Service wkssvc.exe
X
Added by the W32/Sdbot-AED worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. ... Read More
Windows Workstation Service wksssv.exe
X
Added by the W32/Tibick-B P2P worm and IRC backdoor Trojan.
Windows Workstation Service wor.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Workstation Service (32-bits) wkssvc32.exe
X
Identified as a SDBot variant.
Windows Workstation Service [5.1-2600] windrm.exe
X
Added by the W32/Rbot-CNY worm and IRC backdoor. This infection also utilizes the rootkit msdirectx.sys to hide itself and associated registry entrie ... Read More
Windows xp Wins.exe
X
A variant of the BKDR_RBOT.VH family of worms and IRC backdoor Trojans.
Windows XP Automatic Update wXPupdate.exe
X
Added by the W32/Rbot-AFC worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
windows xp sp2 keygen Windows XP SP2 KeyGen.exe
X
Added by the W32/TIBICK-C WORM! ... Read More
Windows-Management Service WinMgmt.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Windows-Xdate wuauclt4.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows-Xordate wuauclt9.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows-Xordate wuauclt6.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
windows.bat windows.bat
X
Added by the Troj/Bckdr-MSY backdoor Trojan.
windows.exe windows.exe
X
Added by the W32/SillyP2P-A worm.
windows16 windows16.exe
X
Added by the Troj/VB-XU trojan.
Windows32 Windows32.exe
X
Added by the Troj/Resod-C trojan.
windows32 wuuaclt.exe
X
Added by the W32.Bratle.B
windows32 windows32.exe
X
Added by the W32/Rbot-FUK worm and IRC backdoor.

W32/Rbot-FUK spreads to other network computers by:

- exploiting common ... Read More
Windows32 win.exe
X
Added by the Troj/Banker-EKI Trojan.
windows32 serivces winser32.exe
X
Added by the SPYBOT.AAF WORM! ... Read More
Windows32KernelStart wks.exe
X
Added by the Generic Downloader.c malware.
WindowsAgent WindowsAgent.exe
X
Added by the GOP.G WORM!
windowsbackup WINDOWSBACKUP.EXE
X
Added by the W32.Stang WORM! ... Read More
WindowsCRC wscrc.exe
X
Added by W32/Sdbot-VU, a WORM!
WindowsCriticalUpdate windows_critical_update.exe
X
Added by the ASTEF or RESPAN WORMS!
WindowsDriverControl winmsnliv.exe
X
Added by the Troj/Agent-PME Trojan.
WindowsFileSystem winsfs32.exe
X
Added by the W32/Rbot-FMQ worm and IRC backdoor.
WindowsFirewallSvc winsvcup.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windowsfw windowsfw.exe
X
Added by the W32/Agobot-TA backdoor worm.
WindowsFY wp.exe
X
Identified as Trojan.Win32.Agent.ct. When run this file extracts a bmp file to the c: folder and sets it as your desktop background. ... Read More
WindowsIPRelay winipsvc.exe
X
Added by the W32/IRCBot-AAA worm and IRC backdoor.
WindowsLogon winlogon.exe
X
Added by the W32/Todnab-A worm. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
WindowsMessenger win32boot.exe
X
Added by the W32/Tilebot-GF worm and backdoor Trojan.
WindowsMGM Winmgm32.exe
X
Added by the SOBIG WORM and LALA.C TROJAN!
windowsmp windowsmp.exe
X
Added by the W32/Autorun-DP removable media worm.
WindowsNetsDll WindowsNetsDll.dll
X
Added by the Troj/Mdrop-DEK Trojan.
windowsnetwork winkernel32.exe
X
Added by the W32/Tilebot-BM worm and IRC backdoor. This infection will also install the rdriv.sys rootkit. ... Read More
WindowsNod winnod.exe
X
Added by the W32/Tilebot-CG worm and IRC backdoor.
WindowsNT winat.exe
X
Added by the W32/Tilebot-AZ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
WindowsProduct Activation wpa.exe
X
Added by the W32/Hwbot-B worm.
WindowsRegKey update winupdate.exe
X
Added by the RBOT-QJ WORM!
WindowsRegKey update windowsup.EXE
X
Added by the W32/Rbot-FV trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
WindowsRegKey update winsys.exe
X
Added by the W32/Rbot-JY trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
windowsregkey update winupdatexx.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
WindowsRegKey update winupdat32.exe
X
Added by the W32/Rbot-AGW worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
WindowsRegKey update winhost.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WindowsRegKey update winupdte.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WindowsRegKey update XP windexv1.exe
X
Added by the W32/Rbot-ABM worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infectio ... Read More
WindowsRegKeys update winsysi.exe
X
Added by the SDBOT.WE WORM!
windowsregkeys update windup.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
WindowsShell winsrc32.exe
X
Added by the Troj/Bancos-RT Internet banking Trojan.
Windowssyesm Windowssyesm
X
Added by the Troj/GrayBir-I backdoor Trojan.
WindowsSysBoot winsys.exe
X
Added by the W32/Rbot-ARJ worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. ... Read More
WindowsSysBoot winsysnet.exe
X
Added by the W32/Tilebot-AF worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
WindowsSystem32 Winsec.exe
X
Identified as the Sdbot-DFG worm and IRC backdoor.
windowstime.exe windowstime.exe
X
Added by the Troj/Dloadr-AQV downloading Trojan.
WindowsUpd WindowsUpd4.exe
X
VirtuMonde adware
WindowsUpd1 WindowsUpd1.exe
X
VirtuMonde adware
windowsupd1.exe WindowsUpd1.exe
X
VirtuMonde adware ... Read More
WindowsUpd2 WindowsUpd2.exe
X
VirtuMonde adware
windowsupd2.exe WindowsUpd2.exe
X
VirtuMonde adware
WindowsUpdate windows_update.exe
X
Added by the LOFNI WORM!
WindowsUpdate WUpdate_35253825.vbs
X
Added by VBS/Ediboy-C. File is located in the Windows directory. Also see SysReg.vbs ... Read More
windowsupdate winnnint.exe
X
Added by an unidentified WORM or TROJAN!
WindowsUpdate WindowsUpdate.scr
X
Added by the W32/Scrapkut-A worm.
windowsupdate windowsupdate.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
WindowsUpdate wupdmgr98.exe
X
Identified as a variant of the MIRC/Backdoor malware.
WindowsUpdate webdev.exe
X
Added by the Troj/Agent-RYU Trojan.
WindowsUpdate winupdate.exe.exe
X
Added by the BKDR_EXDEPH.A backdoor.
WindowsUpdate Service wuautlc.exe
X
Added by the RBOT-NR WORM!
WindowsUpdate.exe WindowsUpdate.exe
X
Identified as a SpamTrojan malware.
WindowsUpdateManager wupdmng.exe
X
Identified as a variant of the Trojan.Win32.Mnless.sun malware.
WindowsUpdater WinUpdter.exe
X
Added by the W32/Autorun.worm.cb removable media worm.
WindowsUpdates WindowsSystem.exe
X
Added by the W32/Autorun-BLA removable media worm.
WindowsXP Update windowsxpupdate.exe
X
Added by the RBOT-PB WORM!
Windowsxp Updater 16Bit winupdos.exe
X
Added by the W32/Rbot-BE trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Windowsxxx windowsxxx.exe
X
Added by the Troj/DuBing-A Trojan.
Windows_Protect winregal.exe
X
Added by a variant of the WIN32.RBOT WORM!
windows_protect wincontrol32.exe
X
Added by the W32/Rbot-ADK ... Read More
windows_update win32.exe
X
Added by the TROJ_SMALL.FAR Trojan.
Window_Protect winsi32.exe
X
Added by a variant of the Rbot worm. This worm, when started, connects to IRC servers where it sits in a desginated channel waiting for commands from ... Read More
Windoxs Update Center W32RfSA.exe
X
Added by a variant of the W32/SDBOT WORM!
WinDrg32 windrg32.exe
X
Added by the W32/Dogbot-A worm/backdoor. This file may be found in other directories as well. ... Read More
WinDriv32 WinDriv32.exe
X
Added by the SMALL-BA TROJAN!
WinDriver Configuration windrvconf.exe
X
Added by the AGOBOT-LX TROJAN!
WinDrives WinDrives.EXE
X
Added by the W32/Small-DHR worm.
windrv windrv32.exe
X
Added by an unidentified VIRUS, WORM or TROJAN! - possibly a strain of OBLIVION or BIONET ... Read More
WinDrv windrvx.exe
X
Added by a variant of the TIBSER.A downloader TROJAN!
WinDSL MTU-Adjust WinDSL_MTU.exe
U
Adjusts the registry setting of the DUN-Adapters (MTU) and the TCP/IP-Protocol (RWIN) by ENGEL Technologieberatung ... Read More
WinDSL_MTU WinDSL_MTU.exe
?
May be realted to Tiscali broadband, if so is it required?
WinDSNX Win????.exe
X
Added by the DNSX TROJAN!
WindUpdates WinUpdt.exe
X
Windupdates adware
WinDVRCtrl WinDVRCtrl.exe
N
Control center software for an AOpen VA1000 TV tuner card
windvrctrl WDVRCtrl.exe
Y
Driver task installed by the drivers for some TV capture cards; no further information available, so best left alone. ... Read More
Windxs mxzez Vexifier winlogos.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
wineij32 wineij32.dll
X
Identified as a variant of the Trojan.Win32.Dialer.yz malware.
winemx32 winemx32.dll
X
Identified as a variant of the Trojan.Win32.Dialer.yz malware.
winenv winenv.exe
X
A variant of the Backdoor:W32/SdBot.BZY family of worms and IRC backdoor Trojans. ... Read More
winepi32 winepi32.dll
X
Identified as Win32/Nebuler variants.
winetn32 winetn32.dll
X
Added by the BackDoor-CVT malware.
WinetWork WinetWork.exe
X
Added by the Troj/Banker-BQQ Internet banking Trojan.
wineula wineula.dll
X
Added by the Trojan.Vundo.B adware/redirector.
WinExec Winexec.exe.vbs
X
Added by the AINESEY.A WORM!
WinExec WinExec.exe
X
Added by the W32/Falus-A worm.
WinExec32 WinExec32.exe
X
Added by the KAZWIN WORM!
Winexec32 win.exe
X
Added by the Troj/Banker-ELQ information stealing Trojan for online banking.
Winexec32 windhelp32.exe
X
Added by the Troj/Agent-HKU Trojan.
Winexec32 windhelp32.exe
X
Added by the TROJ_BANKER.FRU online banking Trojan.
winexy32 winexy32.dll
X
Identified as a variant of the Trojan.Win32.Agent.qt malware.
WinFast Schedule Wfwiz.exe
U
Leadtek WinFast TV tuner scheduler
Winfast_2K WF2k.exe
U
System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start ... Read More
WinFavorites WinFavorites.exe1
X
Loudmarketing.com adware downloader
WinFax PRO WFXSVC.EXE
U
This service handles many of the automated tasks of Winfax Pro such as receiving faxes. Disabling this service will impair the functioning of this pr ... Read More
WinFax PRO Controller WFXCTL32.EXE
N
From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displa ... Read More
WinFaxAppPortStarter wfxsnt40.exe
Y
WinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application. ... Read More
winFile winFile.exe
X
Added by the Troj/Banker-FDB Trojan.
WinFire WF.exe
X
Added by the Troj/Delf-SY keylogging Trojan.
winfixer 2005 wfx5.exe
X
"Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here ... Read More
winfixer helper wfxcwr.exe
X
WinFixer web installer - Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, generall ... Read More
WinFk winfk32.dll
X
Added by the Backdoor.Ginwui.E backdoor Trojan.
WinFlyer32.dll WinFlyer32.dll
X
Identified as Trojan.Downloader-WinFlyer.Process.
winfont winfont.exe
X
Added by the DEATH TROJAN!
winform winform.exe
X
Added by the Troj/PWS-ALB password-stealing Trojan.
WinForm WinForm.exe
X
Added by the Troj/PWS-ANN password-stealing Trojan.
WinFoxV2 WF2k.exe
U
System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start ... Read More
winfws winfws.exe
X
Added by the W32/Sdbot-ABA worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
WinGate WinGate.exe
X
Added by a variant of the LOVGATE WORM!
WinGate Engine Monitor wgengmon.exe
U
WinGate Internet Client Dialup Monitor - component of WinGate proxy server software. Displays the status of the WinGate engine, and appears in the sys ... Read More
WinGate initialize WinGate.exe
X
Added by a variant of the LOVGATE WORM!
wingerver2.0.exe wingerver2.0.exe
X
Added by the Troj/GrayBrd-AE backdoor Trojan.
winghy32 winghy32.dll
X
Identified by Kaspersky antivirus as a variant of the Trojan.Win32.Dialer.yz malware. ... Read More
Wingmnt wingmnt.exe
X
Added by Backdoor.Cmjspy.B.
wingo wingo.exe
X
Added by the BEAGLE.AW or BEAGLE.AV WORMS!
wingsa32 wingsa32.dll
X
Identified as a variant of the Trojan.Win32.Dialer.yz malware.
wingsc32 wingsc32.dll
X
Added by the Troj/Bckdr-PNH backdoor.
WinGuage Pro WGPRO32.EXE
N
Part of McAfee Nuts & Bolts. "WinGauge is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to ... Read More
Winguard WGFE95.EXE
Y
Dr Solomon's Virex antivirus
winguard wingrd32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WinGuard Pro wgp.exe
U
wingvd32 wingvd32.dll
X
Added by the Troj/Bckdr-PNT backdoor Trojan.
Winhelp winhe1p.exe
X
Added by the QQPASS.E TROJAN!
WinHelp WinHelp.exe
X
Added by a variant of the LOVGATE WORM! Note - "winhelp.exe" resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\Syst ... Read More
winhelp winhelp.dll
X
Added by the Troj/Mdrop-DCW Trojan. Please note that c:\windows\system32\rundll32.exe is a legitimate Windows file and should not be deleted. ... Read More
winhld32 winhld32.dll
X
Identified as a variant of the Trojan.Agent.qt malware.
winhlp.exe winhlp.exe
X
Added by the PWSteal.Formglieder Infection! Found in the Windows directory.
winhlp3.exe winhlp3.exe
X
Added by a variant of the EASTO.A TROJAN!
Winhlp32 Wscript.exe ..Msexec32.vbs
X
Added by the GANT.B WORM!
winhlp32.exe winhlp32.exe
X
Added by a variant of the EASTO.A TROJAN! This should not be confused with the legitimate winhlp32.exe file residing in your C:\Windows directory. ... Read More
winhlpp32.exe winhlpp32.exe
X
Added by the GAOBOT.SY WORM!
winhoq32 winhoq32.dll
X
Identified as a variant of the Trojan.Win32.Dialer.yz malware.
Winhost wintt.exe
X
Added by the LOLAWEB.B TROJAN!
Winhost win.exe
X
Added by the DLOADER-AP TROJAN!
Winhost winhost.exe
X
Added by the Troj/Delf-JL TROJAN!
winhost.exe winhost.exe
X
Added by the roj/Lohav-R proxy server and downloader trojan. Machines that are infected with this can be used by the remote user to send Internet tra ... Read More
winhost32.exe winhost32.exe
X
Added by the TABDIM TROJAN!
WinHound WinHound.exe
X
Rogue antispyware/AV app which issues fake virus alert messages.
WiniBlueSoft WiniBlueSoft.exe
X
Added by the WiniBlueSoft rogue anti-spyware program.
winierun winierun.exe
X
Added by the Troj/RNWatch-A ... Read More
WiniFighter WiniFighter.exe
X
Added by the WiniFighter rogue anti-spyware program.
WiniFighter Security Service WiniFighterSvc.exe
X
Added by the WiniFighter rogue anti-spyware program.
WinIFixer WinIFixer.exe
X
Added by the WinIFixer rogue anti-spyware program.
WiniGuard WiniGuard.exe
X
Added by the WiniGuard rogue anti-spyware program.
winimage wvsvc.exe
X
Added by the RBOT.TX WORM! ... Read More
wininet wininet.exe
X
Added by the W32/Stubbot-C worm and backdoor Trojan.
wininet32 wininet32.exe
X
Added by the RAZNEW-A TROJAN!
wininetd wininetd.exe
X
Added by the WINET TROJAN!
Winini.dll winini.vbs
X
Added by the VBS.Lido virus and worm.
wininit wininit.exe
X
Added by the WOLLF.16 TROJAN! Please note that this infection should not be confused with the legitimate Windows file located at %System%\wininit.exe. ... Read More
WinInit Win86.exe
X
Added by the Troj/Small-PB TROJAN!
winint winint.exe
X
Added by the W32/Sdbot-ADA worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
winIogom winIogom.exe
X
Added by the Troj/Bancban-ML Internet banking Trojan.
winipsec winipsec.exe
X
Unidentified malware
winirxhelper WinIRXHelper.exe
U
MSI™ Media Center Deluxe software - see here ... Read More
winis winis.exe
X
Added by the W32/RBOT-WI WORM! ... Read More
winis winis.exe
X
Identified as a variant of the Net-Worm.Win32.Kolab malware.
WiniShield WiniShield.exe
X
Added by the WiniShield rogue anti-spyware program.
WiniShield Security Service WiniShieldSvc.exe
X
Added by the WiniShield rogue anti-spyware program.
winjne32 winjne32.dll
X
Added by the Troj/Agent-CIK Trojan Trojan.
winjvd32 winjvd32.dll
X
Identified as the Trojan.Agent.qt/Win32/Nebuler.BW malware.
Wink*.exe Wink*.exe [* = random char]
X
Added by a variant of the KLEZ WORM!
Winkb6 winkb6.exe
U
Part of We-Blocker, works in tandem with syswb6. Both files are needed to run WeBlocker. Required if We-Blocker is installed ... Read More
WinKernel WinKer.exe
X
Added by the MIRAB or SERVIDOR TROJANS!
winkernel32 wWin32.com
X
Added by the BANSAP TROJAN!
WinKey winkey.exe
U
Loads Copernic's WinKey. Used to map out Windows key hotkey combinations. Not required for the system, but is necessary for this to be running if you ... Read More
winla winla.exe
X
Added by the Troj/Dloadr-AQL Trojan.
winlgz2 winlgz2.exe
X
Added by the Troj/KillFil-Q trojan.
winlibs.exe winlibs.exe
X
Added by the EVAMAN.C WORM!
winlig32 winlig32.dll
X
Added by the Troj/Geezo-F Trojan.
Winlink winlink32.exe
X
Added by the GAOBOT.AAY WORM!
WinLiveMessanger wlliveapp.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Winlme windll.exe
X
Added by the GOP.F WORM!
WinLoad Winload.exe
U
Added by the Spyware.PCTattletale surveillance software. If you did not install this software, then uninstall it immediately.

NOTE TO V ... Read More
WinLoad win.exe
X
Added by the Troj/Asb-A backdoor Trojan.
winlog windowxs.exe
X
Added by the W32/Sdbot-KT worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
winlog wintask.exe
X
Added by the W32/Sdbot-GR worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute. ... Read More
winlog winsx.exe
X
Added by the W32/Sdbot-MH worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
winlog winlog.exe
X
Added by the Backdoor.Win32.Bifrose.acs backdoor Trojan.
winlog manager winlog.exe
X
Added by the Trojan.Spexta trojan. When infected your computer will become an open mail relay which will allow your computer to be used to send out s ... Read More
winlog.exe winlog.exe
X
Added by the Troj/Bckdr-RBJ backdoor Trojan.
WINLOG0N WINLOG0N.EXE
X
Added by the W32.MYDOOM.BI WORM!
WinLogin winlogin.exe
X
Added by the AGOBOT-IX WORM!
winlogin save server winlogin.scr
X
Added by the Mal/EncPk-VD malware.
winlogin.exe winlogin.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
Winlogo Winlogo.EXE
X
Added by the Troj/GrayBir-CQ backdoor Trojan.
winlogoff winlogoff.exe
X
Added by the W32/AGOBOT-TR WORM! ... Read More
winlogon winlogon.exe
Y
Windows Logon Process - handles user logons described here
winlogon winlogon.exe
X
Hijacker or adult content dialler - file is located in C:\Windows or C:\Winnt, and not in it's System or System32 subdirectory, as is the case with th ... Read More
winlogon winlogin.exe
X
Added by the RANDEX.E WORM!
winlogon winlogon.exe
X
Added by the TRODAL TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! File is located in C: ... Read More
WINLOGON WINL0GON.exe
X
The Troj/Nethief-K TROJAN adds the file, which you'll note contains "zero" instead of "o". ... Read More
WINLOGON wscript.exe %System%\WINLOGON.vbs %
X
Added by the VBS.Ypsan.F@mm mass-mailing worm. When cleaning this infection you only want to delete the %System%Winlogon.vbs file. ... Read More
winlogon wpwlogon.exe
X
Added by an unidentified WORM or TROJAN!
winlogon winlogon32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
winlogon winlogon.dll
X
Identified as the Trojan.Popuper malware.
winlogon win_sp.exe
X
Identified as a variant of the Trojan-PWS.Win32.VB malware.
WinLogonnd winlogonnd.exe
X
Added by the Troj/Agent-NNQ Trojan.
Winlogun winlogin.exe
X
Added by the W32/P2Load-C worm.
winltmpv winln.exe
X
Added by the TCXMEDI-C TROJAN!
winltmpv wutop.exe
X
Added by the TCXMEDI-C TROJAN!
winltmpv WINLTMPV.EXE
X
Added by the TCXMEDI-C TROJAN!
winluj32 winluj32.dll
X
Added by the Troj/Nebuler-L Trojan.
winm TCP winm32.sys
X
Troj/Haxdor-Gen rootkit utilized by the Troj/Haxdoor family.
winm32 winm32.dll
X
Added by the Troj/Haxdoor-BQ backdoor Trojan. This infection utilizes the winm64.sys and the winm32.sys rootkit. ... Read More
winm64 TCP winm64.sys
X
Troj/Haxdor-Gen rootkit utilized by the Troj/Haxdoor family.
Winmain winmain.exe
X
One of the first of a new breed of malware. When run it immediately loads MSHTA.EXE from the Windows folder, placing it on "hot standby", ready to acc ... Read More
WinMan winmngr.exe
X
Added by the W32/Tilebot-BY worm and IRC backdoor.
WinManage wmanage.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
winmatrix.exe WinMatrixXP.exe
U
WinMatrix XP - wallpaper replacement that shows different matrix effects (including flowing matrix codes from 'The Matrix' movie) on your desktop ... Read More
winmdgr winsvcmgr.exe
X
Added as a new service by the W32/Sdbot-WQ WORM/IRC backdoor, and uses a displayname of Microsoft Service Manager. ... Read More
winme winme.exe
X
Added by the W32.Rahiwi.B worm.
WinMed winmed.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Agent.ktf malware.
WinMedia wwwloader.exe
X
Added by the Troj/Dloadr-KB Trojan.
WinMedia32 winmedia32.exe
X
Added by the Troj/Agent-UF Trojan. This infection also creates the file %Temp%removeMe290233.bat. ... Read More
WinMem WinMem.exe
U
WinMem Cleaner - part of Ultra WinCleaner Utility Suite. Makes more memory available for your programs and the Operating System. It also defragments y ... Read More
winMem winMem.exe
X
Added by the W32.Hocgaly.A@mm worm.
WinMenssage winmax.exe
X
Added by the BANCOS.B TROJAN!
winmfu32 winmfu32.dll
X
Identified as the Trojan.Win32.Agent.qt/BackDoor-CVT malware.
WinMgmt WinMgmt.exe
N
Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer he ... Read More
winmgmt wmiprvse.exe
X
Added by the Troj/Agent-GHP Trojan.
WinMgr32 winmgr32.exe
X
Added by the MIMAIL.P WORM!
winmodem wmexe.exe
Y
Software for software based modems. Required if you have one of these. WinModems use software rather than hardware - hence putting a load on the CPU. ... Read More
Winmon32 winmon32.exe
X
Added by the W32/Rbot-OQ trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These ... Read More
winmovieplugin WinMoviePlugIn.exe
X
Sfonditalia adult content premium rate dialer ... Read More
winmrg winmrg.exe
X
Added by the Backdoor.AntiLam.20 backdoor.
WinMsg winmsgr.exe
X
Added by the Troj/Dloadr-AS downloading Trojan.
winmsg.exe winmsg.exe
X
Added by the W32/Blehs-A worm.
WinMsrv32 WinMsrv32.exe
X
Added by the GAOBOT.AFJ WORM!
WinMX WinMX.exe
N
WinMX file sharing application
winmxw32 winmxw32.dll
X
Identified as a variant of the Trojan.Win32.Dialer.yz malware.
winmysqladmin winmysqladmin.exe
N
Starts the MySQL database admin tool
WinMySQLadmin Tool winmysqladmin.exe
N
Starts the MySQL database admin tool
winnet winnet.exe
X
CommonName Toolbar spyware. To uninstall see here
winnload winnload.COM
X
Added by the Troj/DownLd-ABG Trojan downloader.
winnok32 winnok32.dll
X
Added by the Troj/Nebuler-F Spyware Trojan. Troj/Nebuler-F gathers details relating to dialup services and sends collected information to a remote sit ... Read More
Winnov Menu WnvMenu.Exe
?
Winnov Video Capture Card related. What does it do and is it required?
Winnov Remote WnvRsvr.Exe
?
Winnov Video Capture Card related. What does it do and is it required?
Winnov Status WvStatus.Exe
?
Winnov Video Capture Card related. What does it do and is it required?
WinNT WinNT.com
X
Added by the W32.Autosky worm. W32.Autosky is a worm that attempts to spread to all shared and removable drives that are accessible from the compromis ... Read More
winnt DNS ident wuamgrd32.exe
X
Added by an Rbot WORM variant.
winnt dns ident wuamgrd33.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
winnt dns ident windowsp.exe
X
Added by the RBOT.BAL WORM! ... Read More
winnt updatc wupgrd.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
winnt.exe winnt.exe
X
Added by the W32/Mona-B instant messenger and email worm.
WinNt32 WinNt32.dll
X
Identified as a variant of the TrojanDownloader:Win32/Cutwail.S malware.
WinNt64 WinNt64.dll
X
Added by the Troj/DwnLdr-HEI Trojan.
WinNtBB WinntBB.exe
X
Added by the DULOAD.C WORM!
winntR1 winntR1.exe
X
Added by the Troj/Banker-EUR password-stealing banking Trojan.
Winnup win32nls.exe
X
Added by a variant of the SPYBOT WORM!
winocx32 winocx32.exe
X
Added by the PROTORIDE.I WORM!
winool32 winool32.dll
X
Added by the Troj/Nebuler-N Trojan.
winopn32 winopn32.dll
X
Identified by Kaspersky antivirus as Trojan-Downloader.Win32.Small.cml.
winosz32 winosz32.dll
X
Identified as Win32/Nebuler variants.
winowl32 winowl32.dll
X
Added by the Trojan.Nebuler Trojan.
winows system winnt.exe
X
Added by the MYTOB.ID WORM! ... Read More
WINP winmic.exe
X
Added by the W32/Spybot-EB worm. When started, this infection connects to a remote IRC server where it waits for commands to execute ... Read More
Winpack winpack.exe
X
Adware downloader - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Agent.gg ... Read More
WinPatch Protection winpatch.exe
X
Identified as Backdoor/VanBot.do.
WinPatrol WinPatrol.exe
U
WinPatrol - "Manage Startup programs, tasks, cookies; will sniff out Worms, Trojan horses, Cookies, Adware, Spyware, Klez, Assumption and other malici ... Read More
WinPerformance WinPerformance.lnk
X
Added by the RogueAntiSpyware.WinPerf rogue anti-spyware proram.
winpipe winpipe.exe
X
Browser hijacker redirecting to wow-access.com
winplosion WinPlosion.exe
U
WinPLOSION allows you to immediately view and select from all the windows running on your computer, just those of the active application, or to minimi ... Read More
WinPoet WinPPPoverEthernet.exe
Y
WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem supp ... Read More
WinPop winpop.exe
X
Added by the Brudevic A adware.
WinPopup WINPOPUP.EXE
N
Intranet chat software provided by windows for chat on small networks. Handy little LAN messaging utility. Has been included in Windows since 95, and ... Read More
winpopup winupie.exe
X
Adware by Tradeexit.com
winpower Winpower.exe
U
Related to InstallAnywhere ZeroG Software is now owned by Macrovision. Note: located in C:\Program Files\UpsPilot\ ... Read More
winppdf winppdf.exe
X
Added by the Troj/Mdrop-DBR Trojan.
winprint winprint.dll
X
A variant of the Troj/Haxdor-Fam Trojan. This infection utilizes the eps32sys.sys rootkit to hide itself. ... Read More
winprocer32 update winprocer32.exe
X
Added by the RBOT.GW WORM! ... Read More
winprocessor update winprocessor.exe
X
Added by the RBOT.IO WORM! ... Read More
WinProt Winprot.exe
X
Added by the CHUPACABRA TROJAN!
winprot Winprot.exeserver.exe
X
Added as a result of the CHUPACABRA VIRUS! ... Read More
winprotect win32.exe
X
Added by the MUGLY.E WORM!
winprotect winprotect.exe
X
Added by the W32/Sdbot-SB worm! Found in the Windows system folder.
WinProtector WinProtector.exe
X
Added by the WinProtector rogue anti-spyware program.
WinProxy WinProxy.EXE
U
"WinProxy is the world-first proxy server and a firewall with integrated mail server for Windows 95/98/ME/NT/2000/XP" ... Read More
winproxy personal WINPROXY.EXE
X
Added by the SDBOT.BMF WORM! ... Read More
winpsa32 winpsa32.dll
X
Identified as the Trojan.Agent.qt malware.
winpsd winpsd.exe
X
Added by the MYDOOM.Q WORM!
winpsd.exe winlibs.exe
X
Added by the Mydoom.S WORM! Located in the Windows system directory.
winpup32 Winpup32.exe
X
Added as a result of the ADCLICKER VIRUS! ... Read More
WinPWD Manager wpwdmgr.exe
X
Added by the W32/Rbot-AUT worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
WinQak32 WinQak32.exe
X
Added by the W32.HLLW.Ducktest worm.
WinRam WinRam.dll
X
Identified by Kaspersky antivirus as a variant of the Trojan.Win32.Agent.feh malware. ... Read More
winrapid winrapid.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
winrar winrar.exe
X
CoolWebSearch parasite variant. Note - this is not the file zipping utility also known as WinRAR and it's located in C:\Winnt or C:\Windows ... Read More
WinRAR WinRAR.exe
X
Added by the W32.Snaban worm. W32.Snaban is a worm that spreads by copying itself to removable drives and network drives on the compromised computer. ... Read More
WinRAR Archive winrar.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
winrarshell winrarshell32.exe
X
Added by the SALIRA TROJAN!
WinReanimator WinReanimator.exe
X
Added by the WinReanimator rogue anti-spyware program. WinReanimator uses aggressive advertising and displays false positives. ... Read More
winReg winReg.exe
X
Added by the YAHA.H or YAHA.J WORMS!
WinReg win32cfg.exe
X
Added by the Troj/Sdbot-CR backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execu ... Read More
WinRegork Walcult.exe
X
Identified by Dr. Web as a variant of the Trojan.PWS.Banker.origin Trojan.
winregsrv winregsrv.exe
X
Added by the SYNRG TROJAN!
winremote WinRemote.exe
U
InterVideo WinCinema Manager - needed for the use of WinDVD_Remote_Control
WinRep winrep.exe
X
Added by the W32/Rbot-AFW worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
winrestore1 winrestore.exe
X
Added by the TROJ/KILLFIL-Q TROJAN! ... Read More
winreups winreups.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
winrnt32 winrnt32.dll
X
Added by the Troj/Nebuler-C Trojan. Troj/Nebuler-C gathers details relating to dialup services and sends collected
information to a remote site ... Read More
winroot winsn.exe
X
Identified as a variant of the Trojan-PSW.Win32.QQPass.aom malware.
winroute winroute.exe
N
Win-Route 4.27. WinRoute Tray Icon for starting and stopping the WrCtrl.exe process, also to log in to the console to view logs and change settings. C ... Read More
WinRPC winrpcmx.exe
X
Added by the Troj/Banker-EEI online banking Trojan. This infection attempts to steal logon credential when you use online banking. It is advised that ... Read More
winrun winrun.exe
X
Added by the WINBUR.B WORM!
winrun z W1NT45K.exe
X
Added by W32.Mytob.BL WORM! ... Read More
winrun.dll winrun.dll.vbs
X
Added by the VBS.Solow.G worm.
WinRunners WinDrivers.exe
X
Added by the DULOAD.C WORM!
winrvc32 winrvc32.dll
X
Identified as a variant of the Trojan.Win32.Dialer.yz malware.
Wins Service Driver winet.exe
X
Added by the W32/Rbot-APV worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
wins(WINS) winscntrl.exe
X
Added by the W32/Sdbot-BCJ worm and IRC backdoor.
winsaf32 winsaf32.dll
X
Identified as a variant of the Trojan.Win32.Agent.qt Trojan.
winscheduler WINSCH~1.EXE
U
InterVideo WinDVR scheduler ... Read More
winscmngr winsmc.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
WinSec winsec16.exe
X
Added by the AGOBOT.ZF WORM!
winsecure winsecure.exe
X
Browser hijacker, redirecting to specificsearches.com
Winserv Winserv.ila
X
Added by the W32.Nodmin@mm infection!. Found in the Windows directory.
winserver Server winserver.exe
X
Added by the Troj/Agent-GHC Trojan.
winservice winmain.exe
X
porn related malware
WinService WinServ.exe
X
Added by the W32/Skowor-O worm.
WinServices WinServices.exe
X
Added by the YAHA.K or YAHA.M WORMS!
Winservices winlogon.exe
X
Added by the Troj/KeyLog-JQ keylogging Trojan. This infection should not be confused with the legitimate C:\Windows\System32\winlogon.exe file. ... Read More
winservn winservn.exe
X
winservs winservs.exe
X
winsfc winsfc.exe
X
Added by the W32.Wisfc worm.
winshell windll32lib.exe
X
Added by the W32/Bagle-DM mass-mailing and P2P worm.
Winshoe wuadfdqr.exe
?
Probably an unidentified VIRUS! Adds itself to 3 registry "Run" keys and prevents Task Manager being displayed. This is not the Winshoe IRC Client as ... Read More
winshost.exe winshost.exe
X
Added by the Troj/BagleDl-K Trojan. The file for this infection is found in the Windows system folder. ... Read More
winshow winshow.exe
X
Added by the Troj/VB-DXP backdoor Trojan.
WinSideMatchUpDate.exe WinSideMatchUpDate.exe
X
Detected by Kaspersky Antivirus as AdWare.Win32.Agent.seb.
winsis32 winsis32.dll
X
Added by the Troj/Nebuler-H Trojan. Troj/Nebuler-H gathers details relating to dialup services and sends collected information to a remote site via HT ... Read More
winskype winskype.exe
X
Added by the Troj/Brogger-C information-stealing Trojan.
WinSL WinSL.exe
X
Added by the Spyware.StarLogger spyware. Spyware.StarLogger is a spyware program that may steal sensitive information from the computer. ... Read More
Winsock driver winnt update.exe
X
Added by the Troj/Spybot-DM TROJAN/IRC backdoor!
Winsock driver winnt64.exe
X
Added by the W32/Spybot-DR worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
Winsock driver winupdate32.exe
X
Added by the Troj/Spybot-JZ i worm and IRC backdoor.
Winsock driver wuaumqr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Winsock driver win.exe
X
A variant of the W32.Spybot.Worm family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
winsock.client winsock.exe
X
Added by the Troj/Diablo-M backdoor Trojan.
Winsock2 driver WINCFG.SCR
X
Added by a variant of the SPYBOT WORM!
Winsock2 driver winupdate.exe
X
Added by the SPYBOT-BX WORM!
Winsock2 driver WUAUMQR.EXE
X
Added by the W32/Spybot-DP worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
Winsock2 driver wuaumqr3.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Winsock2 driver WINLOGO.EXE
X
A variant of the W32.Spybot.Worm family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
Winsock2 driver wuaumqr12.exe
X
A variant of the W32.Spybot.Worm family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
Winsock2 driver winsock3.exe
X
A variant of the W32.Spybot.Worm family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
Winsock2 driver win.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Winsock2 driver winnt4.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Winsock2 driver WINDATE.EXE
X
Added by the W32.Spybot.Worm worm and IRC backdoor.
Winsock2 Loader WICONF.EXE
X
Added by the W32/Sdbot-LC worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Winsock2 wqr1s wuaumqr1.exe
X
Identified as the Backdoor.Win32.SpyBoter.fv worm and IRC backdoor.
Winsock2.dll WINLODR.SCR
X
Added by an unidentified VIRUS, WORM or TROJAN!
winsock32 winsock32
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Winsock32driver win32server.scr
X
Added by the HACARMY TROJAN!
Winsock32driver win32server.exe
X
Added by the BACKDOOR-AZV TROJAN!
Winsock32driver win32server.exe
X
Added by the HACARMY.F TROJAN!
Winsock32driver winXPupdate.exe
X
Added by the HACKARMY.9728 TROJAN!
Winsock32driver win32scs.exe
X
Added by the Troj/Hackarmy-C backdoor.
winsockdriver winsock2.2.exe
X
Added by a variant of the SPYBOT WORM!
winsockdriver winsock3.exe
X
Added by the W32/Spybot-DO worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
winsos verify WINSOS.EXE
U
WinSOS - "deletes spyware, optimizes your computer - backs up selected data" ... Read More
winsp1up.exe winsp1up.exe
X
Added by the HDD Defragmenter rogue defragging software.
winsp2up.exe winsp2up.exe
X
Added by the Troj/Mdrop-DAF Trojan.
winspd32dll winspd32.exe
X
Added by a variant of the AGOBOT/GAOBOT WORM! ... Read More
Winspector winspector.lnk
X
Added by the TROJ_MULDROP.GP dropper Trojan. This link corresponds to the file C:\Windows\System32\drivers\shellz\winspector.exe. ... Read More
WinSPF windrv32.exe
X
Added by the MYDOOM.T WORM!
WinSPF winspf32.exe
X
Added by the MYDOOM.S WORM!
Winspl winsplx.exe
X
Added by a variant of the TROLL-A TROJAN!
winsplog wsmmlog.exe
X
Added by the Troj/Mailbot-CA IRC Backdoor Trojan.
WinSpyDemo WinSpyDemo.exe
X
Added by the WinSpy rogue anti-spyware program. WinSpy is a misleading application that may give exaggerated reports about potential risks on the comp ... Read More
WinSpyKiller WinSpyKiller.exe
X
Added by the WinSpyKiller rogue anti-spyware program. Uses false advertising and exaggerated scan results as a tactic to have you purchase the softwa ... Read More
WinSpywareProtect (ver. 5.1) WinSpywareProtect.exe
X
Added by the WinSpywareProtect rogue anti-spyware program.
Winsrv winsrv.exe
X
Added by the OPASERV.T WORM!
winsrv winntui.exe
X
Added by the Troj/Netsnake-M password-stealing Trojan.
WinStabilizer WinStabilizer.exe
X
Added by the W32/Agobot-SW worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
WinStart WinStart.exe
X
From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address ... Read More
WinStart Wscript.exe WinStart.vbs
X
Added by the CIAN.C WORM!
WinStart winstart32.exe
X
Added by the PUROL WORM!
WinStart WinStart.pif
X
Added by the CONE.E WORM!
winstart winstart.exe
X
Added by the Troj/SCKeyLo-AB trojan.
winstart winstart.dll
X
Added by the Troj/SCKeyLo-AB trojan.
WinStart001 WinStart001.exe
X
From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address ... Read More
WinStart001.EXE WinStart001.exe
X
From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address ... Read More
winstats winstats.exe
X
Added by the Trojan.Gargafx Trojan.
Winsta~1 winsta~1.exe
X
GoHip foistware
WinSth16 WinSth16.exe
X
Added by the CAKE WORM!
winsupdater winsupdater.exe
X
Added by the W32/Alcra- P2P worm.
winsupdatesysmngr64 winsys64mnger.exe
X
Added by the W32/Rbot-BAG worm and IRC backdoor.
WinSvc WinSvc.exe
X
Added by the Troj/Dloadr-ANJ downloading Trojan.
WinSvc16.exe WinSvc16.exe
X
Added by the SDBOT.FQ TROJAN!
Winsvc32 Winsvc32.exe
X
Homepage hijacker
winsvc32.exe winsvc32.exe
X
Added by the GREPAGE TROJAN! ... Read More
winsy32.exe winsy32.exe
X
Trojan related to the CoolWebSearch group of malware.
Winsys Winsys.exe
U
Win-Spy - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it  ... Read More
winsys2freg winsys2freg.dll
X
Added by the Troj/Xorpix-X proxy Trojan.
WinSys3 winsys3.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Banload.ibq malware.
WinSys32 Winsys32.exe
X
Added by the CIGIVIP TROJAN or RECKUS WORM!
winsys32 Driver winsys32.exe
X
Added by the LOONY-O TROJAN!
winsys32mon winsysmon32.exe
X
Added by the SecurityRisk.SexxPass security risk. This infection adds certain sites to your IE trusted zone allowing software to install on your comp ... Read More
WinSysAppMon WinSysRM.exe
U
Home & Family Content Filter related. See here
winsysban winsysban.exe
X
Added by the Troj/Clicker-CD Trojan.
winsyslog lptt01 winsyslog.exe
X
Variant of the RapidBlaster parasite (in a "Winsyslog" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use Ra ... Read More
WinSysmc Win32Sysmc.exe
X
Added by the Troj/Dloadr-BLU Trojan.
WinSyst32 winsyst32.exe
X
Added by the MORB WORM!
WinSystem winsystem.exe
X
Added by the WHITEBAIT WORM!
Winsystem winsystem.exe
X
Added by the BANCOS.CR TROJAN!
WinSystem WinSystems.exe
U
Added by the Spyware.CMKeyLogger surveillance software. This should be removed if it was not installed by yourself. ... Read More
winsystem.sys WINLOGON.EXE
X
Added by the W32/Sober-K infection! File will be found in the %WINDIR%msagentwin32 folder. ... Read More
WinSystems winsystems16.exe
X
Added by the W32/Sdbot-CZT worm and IRC backdoor.
winsystems25 winsystems.exe
X
Added by the W32/Rbot-CNZ worm and IRC backdoor.
winsysupd winsysupd.exe
X
Added by the Troj/StartPa-NI Internet Explorer hijacker.
WINT wcp****.exe [* = random char]
X
WINT wcpcc.exe
X
WINT wcpsvit.exe
X
WinTab Service WTSRV.EXE
Y
Part of the Windows Tablet driver. Necessary for certain functions like eraser or being pressure sensitive among other options. ... Read More
WinTask Wintask.exe
X
Added by the HIPO or LEMIR.F TROJANS!
WinTask driver wintask.exe
X
Added by the SMALL.ABD downloader TROJAN!
WINTASKS winxpro.exe
X
Added by the W32/Mytob-T worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
WinTasks DLL Library (32-bits) winkll.exe
X
Added by the W32/Rbot-AJZ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
WinTasks Traybar wintasks.exe
U
WinTasks - "Efficient Resource and Task Management is absolutely critical if you want to achieve the highest system performance levels possible. WinTa ... Read More
wintasks.exe wintasks.exe
X
Added by the EVAMAN WORM!
wintbp.exe wintbp.exe
X
Added by the W32/Tpbot-A worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
wintbpx.exe wintbpx.exe
X
Added by the W32/Zotob-F worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
wintective wintective.exe
U
Added by the Spyware.Wintective keylogger and screen capture program. If you did not install this program, then you should uninstall it. ... Read More
Wintercooler Pro WINCOOL.EXE
N
Wintercooler Pro - utility that monitors CPU usage, RAM consumption and Internet connection speed ... Read More
winthelp winthelp.exe
X
A Trojan installed by a fake video codec supposedly required to view a movie on the Internet. ... Read More
WinTidy WinTidy.exe
N
Desktop icon manager from PC Magazine (Ziff-Davis) for Win95. Available via Start -> Programs ... Read More
Wintime Wintime.exe
X
Added by the HARNIG TROJAN!
Wintime Wtxpload Wxpload.exe Wintime
N
Part of the software to support a Dexxa USB graphics tablet. From a visitor - "This gets started anyway when you plug in the USB connector for the gra ... Read More
wintjv32 wintjv32.dll
X
Added by the Troj/Bckdr-AOI backdoor Trojan.
wintnask32.exe wintnask32.exe
X
Added by the W32/Rbot-AFP worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
wintnl wintnl.exe
X
Added by a variant of the W32.ZOTOB.K WORM! ... Read More
wintnl.exe wintnl.exe
X
Added by the W32.Zotob.K worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
wintnpx.exe wintnpx.exe
X
Added by the W32.Zotob.H worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
WinTools WToolsA.exe
X
Wintools adware
WinTouch WinTouch.exe
X
Identified as a variant of the Win32/Matcash.BU malware.
WinTray wintray.exe
X
Added by the LEGUARDIEN.B TROJAN!
wintroters wintroters.exe
X
Added by the Troj/GrayBrd-AJ backdoor Trojan. This infection also creates the file c:\windows\wintroters.DLL. ... Read More
wintsk32dll wintsk32dll.exe
X
Added by the W32/Rbot-AAJ WORM/IRC backdoor trojan!
wintxr32 wintxr32.dll
X
Added by the Troj/Bckdr-PLK Trojan.
winudll.exe winudll.exe
X
Added by the Troj/Mitglie-CE backdoor trojan.
winudpt32.exe winudpt32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
winudu32 winudu32.dll
X
Identified as the BackDoor-CVT malware.
winupated.exe winupated.exe
X
Added by a variant of the SDBOT WORM!
winupd.exe winupd.exe
X
Added by the BEAGLE.M or BEAGLE.N WORMS!
winupd64x.exe winupd64x.exe
X
Added by the Mal/FakeAV-FI Trojan that displays fake security alerts.
winupdat winupdat.exe
X
Added by the CANBOT.A WORM!
WinUpdate wmbem.exe
X
Added by the REVCUSS.B TROJAN!
Winupdate Engine wupeng.exe
X
Added by the MalwareCrush program. MalwareCrush is a rogue anti-spyware program installed through Trojans and other malware. When run, the program wi ... Read More
winupdate.exe winupdate.exe
X
Added by the RADO TROJAN!
winupdate.reg winupdate.exe
X
Added by the SPYBOT.EAS WORM!
winupdate86.exe winupdate86.exe
X
Added by the Troj/FakeAV-AHQ fake-alert Trojan.
winupdater winupdate.exe
X
Identified by Kaspersky Antivirus as a variant of the Backdoor.Win32.Agent.bjev malware. ... Read More
winupdates winupdates.exe
X
Added by the W32/Alcra-B worm.
WinUpdating WinUpdating.exe
X
Unknown malware.
WinUPDbc winupdbc.exe
X
Added by the Troj/Banker-DSN Internet banking Trojan. Troj/Banker-DSN will then continuously monitor Microsoft Internet Explorer for certain strings r ... Read More
winupdsv winupdsv.exe
X
Added by the X97M.DROPO Macro VIRUS! ... Read More
winupdtl winupdtl.exe
X
SecondThought adware variant
winupdtl winupdt.exe
X
winuqw32 winuqw32.dll
X
Identified as a variant of the Trojan.Win32.Dialer.yz malware.
winur winrun.exe
X
Added by the WINBUR.B WORM!
winusb.dll winguard.exe
X
Added by the FORBOT-CN WORM!
Winuser Winuser.exe
X
Added by the Troj/Banker-DLT Trojan.
winusr WinUsr.exe K1S2
X
Added by the W32.CLUNK.A WORM! ... Read More
winversion winversion.exe
X
Browser hijacker, redirecting to specificsearches.com
winvex32 winvex32.dll
X
Added by the Troj/Nebuler-B Trojan.
WinVM32 WINVM32.EXE
X
Added by the Troj/RasAsper-A dialer. This infection divers all numbers dialed via modem to a phone number preceded with 0190. ... Read More
WinVNC WinVNC.exe
U
WinVNC is an application that allows you to remote control your PC from another PC somewhere on the internet ... Read More
winvtv32 winvtv32.dll
X
Identified by Kaspersky as a variant of the Trojan.Win32.Agent.qt Trojan.
winvxd32 winvxd32.exe
X
Added by the W32.Gabloliz.A WORM! ... Read More
winwan lptt01 winwan.exe
X
Variant of the RapidBlaster parasite (in a "Winwan" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use Rapid ... Read More
winwan ml097e winwan.exe
X
Variant of the RapidBlaster parasite (in a "Winwan" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use Rapid ... Read More
WinwebSecurity WinwebSecurity.exe
X
Added by the Winweb Security rogue anti-spyware program.
winwim32 winwim32.dll
X
Identified as Win32/Nebuler variants.
winwly32 winwly32.dll
X
Identified as a variant of the Trojan.Win32.Dialer.yz malware.
winword winword.exe
X
Added by the Troj/Torpid-C ... Read More
winwsl.exe winwsl.exe
X
Added by the W32/Zotob-J worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
winwvv32 winwvv32.dll
X
Added by the Troj/Nebuler-U Trojan.
winwxj32 winwxj32.dll
X
Added by the Troj/Small-DYN Trojan.
WinX Security Center WinX Security Center.exe
X
Added by the WinX Security Center rogue anti-spyware program.
WinXDefender WinXDefender.exe
X
Added by the WinXDefender rogue anti-spyware program. WinXDefender is a misleading application described as a spyware removal utility that may give ex ... Read More
WinXP win.exe
X
Added by the Troj/Gaduka-G backdoor Trojan.
winxp winxp.exe
X
Added by the W32/Brontok-DN worm.
WinXp Updater winxp32.exe
X
Added by the W32/Rbot-HG trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
winxpdll32.exe winxpdll32.exe
X
Added by a variant of the SMALL downloader TROJAN!
WinXProtector WinXProtector.exe
X
Added by the WinXProtector rogue anti-spyware program.
WinXpUpdate32 WinXpUpdate32.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
winxpusbd winxp64.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
winxtx32 winxtx32.dll
X
Added by the Troj/Nebuler-D Trojan. Troj/Nebuler-D gathers details relating to dialup services and sends collected information to a remote site via HT ... Read More
winxtx32 winxtx32.dll
X
Added by the Troj/Mdrop-BUO Trojan.
winxyl32 winxyl32.dll
X
Added by the Troj/Nebule-B Trojan.
winystems25 winystems.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
winyvo32 winyvo32.dll
X
Added by the Troj/Bckdr-GIR Trojan.
WinZap Check winzbp.exe
X
Added by the W32/Rbot-AWZ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
winzip winzip.exe
X
Added by a variant of the RBOT WORM!
WinZip wzip32.exe
X
Added by the Infostealer.Orcu information-stealing Trojan. This infection steals confidential info such as banking information. ... Read More
Winzip Application winzip81.exe
X
Added by the W32/Rbot-BJY worm and IRC backdoor.
Winzip Compression Utility Winzip32.exe
X
Added by the Troj/Sdbot-UI worm. When started, this infection connects to a remote IRC server and waits for commands to execute. ... Read More
WinZip Quick Pick WZQKPICK.EXE
N
Added with WinZip version 8.1. "The new WinZip Quick Pick taskbar tray icon gives you instant access to WinZip and your Zip files. Just left click the ... Read More
winzip update WinZip.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
winzoa32 winzoa32.dll
X
Identified as a Virtumonde related file.
winzwr32 winzwr32.dll
X
Added by the Trojan.Win32.Dialer.qn malware.
winzzc32 winzzc32.dll
X
Identified as a variant of the Trojan.Win32.Agent.qt malware.
Win_Pigeon_Server Win_Server.dll
X
Added by the Troj/Feutel-N backdoor Trojan.
win_shell win32lib.exe
X
Added by the W32/Bagle-DO mass-mailing and peer to peer worm.
win_spool2 win_spool2.exe
X
Added by the SCKEYLOG.B TROJAN!
win_supp00.exe Win Const.exe
X
Added by the Troj/Assasin-H Trojan.
win_upd.exe WINdirect.exe
X
Added by the MITGLIEDER.M TROJAN!
win_upd2.exe WINdirect.exe
X
Added by the BEAGLE.AO WORM!
Win_vader Win_vader.vbs
X
Added by the INVASION.A VIRUS!
WIP Config GUI Winipcfgs.exe
X
Added by the RBOT-CN WORM!
wipicdec wipicdec.exe
X
Identified as a variant of the Trojan-PWS.OnlineGames.ADRD malware.
Wippien Wippien.exe
N
Added by the Wippien open source p2p VPN software.
wipxcdec wipxcdec.exe
X
Identified as a variant of the Trojan-PWS.OnlineGames.ADRD malware.
Wireless Conections WireConnect.exe
X
Added by the W32/Sdbot-VF WORM! Found in the Windows system folder.
Wireless Configuration Utility HW.32 WlanCU.exe
U
Wireless configuration utility used by various wireless devices. This only needs to run if you do not have Windows managing your wireless connection. ... Read More
Wireless PCI Card Configuration Utility WMP11Cfg.exe
U
Utility used by the LINKSYS wireless PCI card (WMP11) and indicates when a wireless access connection is made by a screen colour change. Also used for ... Read More
Wireless Provider Server wpsvr.exe
X
Added by the FORBOT-AD WORM!
Wireless Zero Daemon wzdsvc.exe
X
Added by the W32/Codbot-E WORM! This service loads in safe mode to make it more difficult to remove. ... Read More
Wireless-G Notebook Adapter Utility WPC54CFG.EXE
U
Utility used by the LINKSYS Wireless-G Notebook Adapter (WPC54G)
Wireless.exe Nacional Wireless.exe
X
Added by the Troj/VBInj-T Trojan.
wise-ftp scheduler WF_Scheduler.exe
U
WISE-FTP file transfer software scheduler ... Read More
WisLMSvc WisLMSvc.exe
U
Found on Acer laptops. Anyone know what it is?
wistaantivirus wistaantivirus.exe
X
Added by the Wista Antivirus rogue anti-spyware program.
wjview wjview.exe
N
MS tool used to view window-based Java applications from the command line
wkcalrem wkcalrem.exe
N
Produces a pop-up reminder of events scheduled using the MS Works Calendar
WkDetect WkDetect.exe
N
Checks for updates to MS Works
wke.exe wke.exe
X
Added by the Troj/Small-CPQ Trojan.
wkfud wkfud.exe
N
A marketing program for MS Works
WksSb WksSb.exe
N
The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program. The Works Portfolio provides a locatio ... Read More
wksscvs wksscvs.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
wkssvc wkssvc.exe
X
Added by the W32/Sdbot-AOR worm and IRC backdoor.
WkUFind WkUFind.exe
N
MS Works Update Detection. MS Picture It! (versions 7 to current) use this automatic update feature during the log on process. It can also cause your ... Read More
Wkyo86 Wk86.exe
X
Added by the W32.Pitin worm. W32.Pitin is a worm that copies itself to the local drive and network shares. ... Read More
WL230USB Wireless B+G Utility WLANUTL.exe
U
Configuration utility for your wireless card.
Wlan Drier Winusb2.exe
X
Added by the WOOTBOT.DC WORM!
WLAN Status Tray Applet WLANSTA.EXE
N
System Tray icon for checking the status of a Wireless LAN
Wlan1934 wlan1934.sys
X
Added by the Troj/Dloader-TB Trojan.
wlancfg wlancfg.exe
U
Inventel wireless router related - required in order to automatically connect to the Net at bootup. ... Read More
WLANKEEPER WLKeeper.exe
Y
Service related to Intel's wireless software.
WLANSTA.EXE WLANSTA.EXE
N
System Tray icon for checking the status of a Wireless LAN
WLAN_Cfg.exe WLAN_Cfg.exe
Y
Linksys Instant Wireless USB Network Adapter driver
wlcrdplauncher wlcrdplauncher.dll
Y
Used by Microsoft Live Mesh. This program is necessary to use the Remote Desktop component of Live Mesh. ... Read More
WLCtrl32 WLCtrl32.dll
X
Identified as a variant of the Email-Worm.Win32.Agent.e worm.
wldmgr wldmgr.exe
X
Added by the W32.Mytob.SA@mm worm.
WLiveCD.exe WLiveCD.exe
X
Added by the Troj/VB-EQI Trojan.
wlmsngr wlmsngr.exe
X
Added by the W32/Sdbot-CTX worm and IRC backdoor.

W32/Sdbot-CTX spreads via:
- to computers vulnerable to common exploits, incl ... Read More
WlN32 winsys.cer
X
Added by the Troj/Zikdow-B Trojan. This infections redirects your browser to use www.3241.com as it's start page. ... Read More
wlogon wlogon.dll
X
Added by the W32/Wenper-B worm.
WLogon wlogon32.dll
X
Identified as a variant of the Trojan-Spy.Banker malware.
wltray.exe wltray.exe
?
Belkin wireless configuration utility and tray icon.
WLTRYSVC WLTRYSVC.EXE
Y
Part of the Broadcom Corporation Wireless Network Tray Applet which allows you to change and see settings for the hardware. ... Read More
wm vcr WMVCR.exe
N
WM_Recorder allows you to record Windows Media™ streaming Video or Audio content. Can be accessed via Start Menu -> Programs ... Read More
wm24pan Wm24Pan.Exe
Y
ESI external sound card driver ... Read More
WMAudio winlogon.exe
X
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! ... Read More
WmdmPmSn wmdmsvc32.dll
X
Added by the Troj/Dloadr-BJH Trojan.
WMedia16 wmedia16.exe
X
Added by the WORM_MYDOOM.BK worm and IRC backdoor. This infection also has rootkit capabilities which hook into the following APIs in order to hide it ... Read More
WMedia32 wmedia32.exe
X
Added by the PWSteal.Banger password-stealing Trojan.
WMI Application Interface wmiapi.exe
X
Added by the W32.Spybot.RBY worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
WMI Service Client wmispv.exe
X
Added by the W32/AutoRun-ASX removable media worm.
WMI Sync-DB wmisynd.exe
X
Added by the W32/IRCBot-AEH worm and IRC backdoor.
WMI System App wmisys.exe
X
Added by the W32/IRCBot-ADR worm and IRC backdoor.
WMI-Service wmiaqsrv.exe
X
Added by the Troj/Mdrop-AIA multi-dropper backdoor Trojan.
wmi32 wmimgmt.exe
X
Added by the W32/Autorun-AVX removable media worm.
WMIEXE.exe wmiexe.exe
U
NT component, used by Windows Millennium to detect  Plug and Play-compliant IEEE 1394 devices during the startup process. Since this is important for ... Read More
Wminf Wminf.exe
X
Added by the GEMA TROJAN!
Wminfo Wminfo.exe
X
Added by the GEMA TROJAN!
wmiprevse wmiprevse.exe
X
Added by the Troj/Banker-EPN online banking Trojan.
wmiprv wmiprv.exe
X
Added by the RBOT-WM WORM!
wmisrv wmisrv.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WMP54Gv4 WMP54Gv4.exe
Y
Linksys WMP54G Wireless-G PCI Adapter driver
wmpconf wmpconf.dll
X
Added by a variant of the MyGeek/CPVFeed adware.
wmpdev wmpdev.dll
X
Malware related to Smitfraud infections.
wmpdriver wmpdriver.exe
X
Added by the Troj/Lurk-A Trojan.
wmpdriver wmpdriverd.exe
X
Added by the Troj/Agent-HJE Trojan.
wmpenv wmpenv.dll
X
Added by a variant of the MyGeek/CPVFeed adware.
wmphost wmphost.dll
X
Malware related to Smitfraud infections.
wmplayer wmplayer.dll
X
A variant of the Cpvfeed adware.
wmplayer.exe wmplayer.exe
X
Added by the Troj/Bancban-CT password-stealing trojan. If you were infected with this trojan you should immediately change all your passwords for you ... Read More
WMPNSCFG WMPNSCFG.exe
U
A program associated with Windows Media Player. According to this technote, wmpnscfg.exe is used to alert users when a new media device is found on t ... Read More
WmpTray wmptray.exe
X
Added by the WinCodecPro Trojan.
WMPVer WMPVer.EXE
?
Dritek System Inc. 3D Mouse related - is it required?
wms3 wms3.exe
X
Added by the Troj/LegMir-AQG password-stealing Trojan for the online game The Legend of Mir. ... Read More
wmsdk64_32.exe wmsdk64_32.exe
X
Added by the Antivirus rogue anti-spyware program.
wmsger wmsger.exe
X
Added by the Troj/QQPass-EP Trojan.
wmsound wmsound.dll
X
A variant of the Cpvfeed adware.
wmsrc.exe wmsrc.exe
X
Rogue security software called Privacy Redeemer that displays exaggerated results about security issues on your computer. ... Read More
wmstream32 wmstream32.dll
X
Added by the Troj/PWS-AHX password-stealing Trojan.
wmsys32 wmsys32.exe
X
Added by the BANPAES.B TROJAN!
wmts wmts.exe
X
Added by the W32/VB-EUF worm.
WMUAgent.exe WMUAgent.exe
U
Added by the WakeMeUp! alarm clock.
wmupdate wmupdate.exe
X
Added by the Troj/Agent-GGJ Trojan.
wmv winmonv.exe
X
Added by the Troj/Agent-DG TROAJAN/backdoor.
wn services wnsvc.exe
X
Added by the W32/KBBot-A
WNAD WNAD.EXE
X
Spyware added as a result of running a program called "Yo Mama Osama" (osama.exe). See here for more and how to get rid of it. There are other ways th ... Read More
wndtx1 wndtx1.dll
X
Added by a variant of the Goldun Trojan. This infection utilizes the ipudpb2.sys rootkit to hide itself. ... Read More
WNILOGON WNILOGON.exe
X
Added by the W32/Lewor-M instant messenger worm.
wnmicf wnmicf.dll
X
Added by a variant of the Haxdoor Trojan family. This infection utilizes the wnmicf.sys and the wnmifc.sys rootkits to hide itself. ... Read More
WNSC wns*****.exe [* = random char]
X
wnsck2 driver wlogf.exe
X
Added by the W32/SPYBOT-AF WORM! ... Read More
WNSI wnscp**.exe [* = random char]
X
WNSI wnscpit.exe
X
PurityScan delivers advertisements to your computer.
wnslvxtf wnslvxtf.dll
X
Identified as a variant of the Adware.Agent malware.
WNST wns*****.exe [* = random char]
X
wntlgns wntlgns.exe
X
Added by a CoolWebSearch parasite related TROJAN! ... Read More
wnxpupdate wcupshell.exe
X
Added by the W32/Combra-I mass-mailing worm.
won update WAPDATE.EXE
X
Added by the WIN32.RBOT.N WORM! ... Read More
wonderfrog WonderFrog.exe
U
Wonder Frog typing monitor ... Read More
Woods Inc wcmd.exe
X
Added by the Troj/KillFil-O Trojan.
Woowatch Watch.exe
N
Wanadoo ISP software, not required
wordpad wordpad.exe
X
Added by the W32.Spybot.WON worm.
wordq carat flag WordQcrs.exe
Y
Related to WordQ Writing Aid Software ... Read More
Words Words.exe
X
A variant of the AdWare.Win32.Agent.dn adware.
WordWeb wweb32.exe
N
WordWeb - free theasaurus and dictionary. Start manually
Work world.exe
X
Added by the W32/Randon-AE worm. This infection, when started, connects to an IRC server using a provided MIRC client to receive commands. ... Read More
WorkFile WorkFile.exe
X
Added by the Troj/Bancos-AWN Trojan.
Workflo workflow.exe
?
Related to BroadJump Client Foundation - broadband troubleshooting software installed by various companies. Is it required? ... Read More
WorkFlowTray WorkFlowTray.exe
N
Taskbar tray icon for OmniPagePro.
workpace 3.0 workpace.exe
U
Related to WorkPace Stress Injury prevention software. WorkPace comes in two editions, Personal and Professional. Note: located in C:\Program Files\W ... Read More
Works Calendar Reminder wkcalrem.exe
N
Produces a pop-up reminder of events scheduled using the MS Works Calendar
WorksFUD wkfud.exe
N
A marketing program for MS Works
Workstation wkssvc.dll
Y
Windows service that creates and maintains client network connections to remote servers using the SMB protocol. If this service is stopped, these conn ... Read More
Workstation Manager wm.exe
Y
Part of the Novell Windows client. Found in the C:\Program Files\Novell\ZENworks folder. ... Read More
Workstation Scheduler wm95.exe
U
Desktop Management Scheduler. Part of Novell's Netware Client. Schedueles NDS events. If events have been schedueled, it is required, otherwise, it is ... Read More
Workstation Services wrkstn.exe
X
Added by the RBOT-OJ WORM!
worldantispy worldantispy.exe
X
WorldAntiSpy, "rogue" spyware remover, installed as part of this_scam ... Read More
Worm Detector wd.exe
U
Worm Detector - antivirus add-on for Outlook 2K or XP for handling worms and spam ... Read More
wormexe winstart.exe
X
Added by the EARLYBIRD WORM!
wovax wovax.exe
X
Added by the DAQA.A TROJAN!
wow wwf.exe
X
Added by the Troj/Lineage-Y password stealing trojan for the online game Lineage. ... Read More
wow64main.exe wow64main.exe
X
Identified by Kaspersky as a variant of the Packed.Win32.TDSS.aa malware.
WOWKtxsCPP.exe WOWKtxsCPP.exe
X
Added by the Troj/FakeAV-BZF Trojan.
wp wp.exe
X
Added by the W32/Rbot-GWA worm and IRC backdoor.
wpconfigs wpconfigs.exe
X
Added by the Troj/Sdbot-AGX backdoor Trojan.
Wpctrl wpctrlnt.exe
N
WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available ... Read More
Wpctrl wpctrl95.exe
N
WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available ... Read More
wpctrl95 wpctrlnt.exe
N
WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available ... Read More
wpctrl95 wpctrl95.exe
N
WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available ... Read More
WPCycle.exe WpCycleWin.exe
Y
Added when selecting Mplayer2 to open media files. Forces other codes to Wait for Previous instructions to end, preventing instability of your CPU (fr ... Read More
wpds.exe wnrot.exe
X
Added by the TROJ_BAGLE.CC Trojan.
WPDShServiceObj WPDShServiceObj.dll
Y
Windows Portable Device Shell Service Object
WPlayer WPlayer.exe
X
Identified as a variant of the LDPinch.A malware.
wpvmqosg wpvmqosg.dll
X
Identified as a variant of the Adware.Agent malware.
wpwmgrs wpwmgrs.exe
X
Added by the W32/Mytob-DH worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
WQK WQK.exe
X
Added by a variant of the KLEZ WORM!
wr WR.EXE
?
??
WR Command wr.exe
?
??
wrapkm wrapkm.dll
X
Added by a variant of the Goldun.Fam Trojan.
wrclib wrclib.dll
X
Added by the W32/Akbot-AH worm. W32/Akbot-AH spreads to other network computers by exploiting common buffer overflow vulnerabilities, including ASN.1 ... Read More
WrCtrl WrCtrl.exe
N
Win-Route 4.27 NAT engine on Win2k Pro for connection sharing and security using Win-Route by Tiny Software. A connection sharing/Firewall Application ... Read More
WRDialer WrDialer.exe
X
WinPoet DSL dialler
WregBios wregbios.exe
?
Desktop Management BIOS (DMI BIOS) related. Apparently invokes the DosBios.exe file. Is it required? ... Read More
wrexec wrexec.exe
U
Watch Right - monitoring program, part of the PowerTools add-on for AOL. Records instant messages, E-mail, chat. Watch Right appears to be, and funct ... Read More
wriste wriste.exe
?
??
WRM CPU driver wrmdrv.sys
X
Added by the W32/Goldax-B worm.
WRMVan Windows.exe
X
Added by the W32/AutoRun-BGD removable media worm.
WRNotifier WRLogonNTF.dll
Y
WrtMon.exe WrtMon.exe
N
This program is part of Presto PageManager that is bundled with Canon Scanners.
ws2help ws2help.exe
X
Added by a variant of the SMALL.AN TROJAN!
ws2_32 ws2_32.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
ws2_64.exe ws2_64.exe
X
Identified as a variant of the Trojan-Proxy.Win32.Agent.ji malware.
WSAConfiguration wmon32.exe
X
Added by the GAOBOT.BAJ WORM!
WSAConfiguration win32upd.exe
X
Added by a variant of the RBOT WORM!
wsass32 wsass32.exe
X
Added by the Troj/Bankem-V password stealing Trojan.
wsbklite wsbklite.exe
?
Related to the Acer Soft Button on Acer Tablet PCs. Appears to do nothing so is it required? ... Read More
WScheduler WScheduler.exe
U
Windows Scheduler - "schedule unattended running of applications, batch files, scripts and much more. Also, you can schedule popup reminders so you'll ... Read More
wscmgr wscmgr.exe
X
Added by the W32/Autorun-AA removable media worm.
wscntfy wscntfy.exe
X
Added by the W32/VBSp-A worm.
wscntfys wsscntfy.exe
X
Added by the W32/Sdbot-TN. When started this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
wscsvc.exe wscsvc.exe
X
Added by a password stealing Banker TROJAN! ... Read More
wscsvc32.exe wscsvc32.exe
X
Added by the Antivirus rogue anti-spyware program.
Wsdata service WSconf.exe
X
Added by the SDBOT.ZU WORM!
wserver wserver.exe
X
Added by the NETSKY.AC or SASSER.G WORMS!
WService WService.exe
U
Tablet client Driver for UC-Logic Pen/Graphics Tablet
WServing Service wserving.exe
X
Identified by Kaspersky Antivirus as a variant of the Trojan-Downloader.Win32.Delf.gru malware. ... Read More
wsfit32 wsfit32.sys
X
Rootkit used by the Rogoo LSP Hijacker to protect it's files. Other associated files are discussed here. ... Read More
wsg32 wsg32.exe
U
GoldenKeylog keystroke logger/monitoring program - remove unless you installed it yourself! ... Read More
wskrnl wskrnl.exe
U
Added by the Spyware.ActMon surveillance software. Uninstall this software if it was not installed by yourself. ... Read More
wsmsag wsmsag.dll
X
A variant of the Troj/Haxdor-Fam Trojan. This infection utilizes the mswsaf.sys and the mswsag.sys rootkits to hide itself. ... Read More
wsmsge wsmsge.dll
X
A variant of the Goldun Trojan. This infection utilizes the mswsaf.sys rootkit to hide itself. ... Read More
wsnpoem.sys wsnpoem.sys
X
Identified as the Backdoor.Win32.Small.lu/Rootkit.V malware.
wsock32 wsock32.exe
X
Added by an unidentified WORM or TROJAN!
WSockDrv32 WSockDrv32.exe
X
Unknown malware.
Wspn wspn.exe
U
Added by the Spyware.Espion surveillance software. Spyware.Espion is a spyware program that monitors and records keystrokes, instant message conversat ... Read More
wsrv32 wsrv32.exe
X
Added by a TROJAN.CLICKER - identified by Kaspersky antivirus as Win32.Agent.ep ... Read More
WSSAConfiguration wmmon32.exe
X
Added by the AGOBOT-KC WORM!
wssys wssys.exe
U
Added by the Spyware.WebPI surveillance software. If you did not install this software, you should immediately remove it. ... Read More
Wstat32 driver Wstat32.exe
X
Added by the LOONBOT TROJAN!
wstimeb wstimeb.exe
Y
Used with NEC printers. You can disable it before printing but it re-loads itself when printing so you may as well leave it ... Read More
wsttrs wsttrs.exe
X
Added by the Troj/LdPinch-QS information-stealing Trojan.
wsvbs wsvbs.exe
X
Added by the Troj/Lineag-AIQ password-stealing Trojan for the online game Lineage. ... Read More
wswpd wswpd.exe
Y
Used with some models of Panasonic, Epson and NEC printers. Some older drivers known to have a "memory leak". Needed for printing to work  ... Read More
wsys.exe wsys.exe
U
Added by the Spyware.SpyloPCMonitor surveillance software. If you did not install this software you should remove it immediately. ... Read More
ws_d ws32.exe
X
Added by the Troj/LegMir-RL password-stealing Trojan. This infection also creates the file C:\Windows\win32.dll. ... Read More
WT Game Channel wtgamechannel.exe
N
WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy use ... Read More
WT GameChannel wtgamechannel.exe
N
WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy use ... Read More
WTF Test wtftest.exe
X
Added by the W32/Rbot-ACM worm. When started this infection connects to an IRC server where it waits for remote commands to execute. ... Read More
WTSI wapisvit.exe
X
WTSS wap***.exe [* = random char]
X
WTST wapisvtr.exe
X
wtzlank.dll wtzlank.dll
X
Added by the Adware.DisableKey adware. When installed this program will display advertisements on your computer. The filename and registry name may b ... Read More
WU713STA.EXE WU713STA.EXE
Y
Blitzz Technology wireless NIC adapter driver
wuanguard wuanguard32.exe
X
Added by W32/Rbot-AAF. The WORM has IRC backdoor trojan functionality.
wuauc1t.exe wuauc1t.exe
X
Added by the Troj/Clicker-DR TROJAN!
wuaucldt wuaucldt.exe
X
Added by the Troj/Mdrop-CUS Trojan.
wuauclt3 wuauclt3.exe
X
Unidentified malware.
wudb wudb.dll
X
Identified as Trojan.Downloader.Agent.BFO.
WUOLService WUOLService9x.exe
Y
Remote wakeup status agent. Part of Novell's ZenWorks. Processes Wake-up on LAN requests (turn on a computer remotely on LAN) ... Read More
wuosdial wuosdial.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
wupd win32.exe
X
Added by the Troj/Orse-C trojan.
wupd32 wupd.exe
X
Added by the W32.Stration.EL@mm worm. W32.Stration.EL@mm is a worm that spreads by emailing itself to other computers. It also drops and downloads oth ... Read More
wupdate wisvccz.exe
X
Added by the Troj/Orse-B TROJAN!
wupdate wi32.exe
X
Added by a new variant of Trojan.Abwiz.
WUpdates WUpdates.exe
X
Added by the Trojan.Swepdat Trojan.
Wupdm32 Wupdm32.exe
X
Added by the W32.Midlak@mm mass-mailing worm.
wupdmgr.exe wupdmgr.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
wupdmgr32.exe wupdmgr32.exe
X
Added by the Troj/Certif-I password-stealing Trojan.
wupdt wupdt.exe
X
Added by the IMISERV.A TROJAN!
WUSB11B.exe WUSB11B.exe
Y
Linksys WUSB11 WLAN USB adapter
WUSB300NSvc WLService.exe
Y
WUSB54Gv4 WUSB54Gv4.exe
Y
Wireless-G USB Wireless Network Adapter related - would appear to be required
wuviewer wuviewer.exe
X
Added by a Proxy_Trojan variant
wuweb wuweb.exe
X
Added by the Trojan.Wuwo Trojan. Trojan.Wuwo is a Trojan horse that drops more malware on to the compromised computer. ... Read More
wvbegpqs wvbegpqs.dll
X
Identified as a variant of the VideoAccessCodec adware.
wvsvc wvsvc.exe
X
Added by the AGOBOT.YM WORM!
wvurqqo wvurqqo.dll
X
Identified by Kaspersky antivirus as a variant of the not-a-virus:AdWare.Win32.Virtumonde.gen malware. ... Read More
wwks wsass.exe
X
Added by the W32/SDBOT-BT WORM! ... Read More
WXProcMgr Module WXprocMgr.exe
N
TVTonic from Wavexpress - "enjoy 3 full-screen, DVD-quality video channels for FREE". Allows data content to be downloaded and synchronized on your sy ... Read More
wxtw PNP DRIVER wxtwdx.sys
X
Added by the Troj/Haxdor-Gen rootkit.
wxtwdu PNP DRIVER wxtwdu.sys
X
Added by the Troj/Haxdor-Gen rootkit.
wxtwdx wxtwdx.dll
X
Added by the Troj/Haxdoor-IJ Trojan backdoor.
wzghui wzghui.sys
X
Added by the Backdoor.Rustock backdoor rootkit.
wzhelper wzhelper.exe
X
Searchcentrix hijacker
X10Weax WTHRTRAY.EXE
X
WeatherCheck - "bring the latest local weather to your desktop". Not recommended as it reportedly pops ads, and contains no uninstaller ... Read More
xBus_ReceiverService Wrapper.exe
Y
Related to xBus.
xem winlogon.exe
X
Identified as a variant of the Trojan-Downloader.Win32.CWS.am downloader Trojan. This infection should not be confused with the legitimate C:\Windows\ ... Read More
XMLmedia 10.0 wmsdkns.exe
X
Identified as a variant of the Trojan.Downloader.VB.VQL malware.
Xordate wuauclt10.exe
X
Added by the W32/Rbot-GKN worm and IRC backdoor.
Xordate wuauclt11.exe
X
Added by the W32/Rbot-GLI worm and IRC backdoor.
Xordate wuauclt13.exe
X
Added by the W32/Rbot-GLM worm and IRC backdoor.
Xordate wuauclt12.exe
X
Added by the W32/Rbot-GLQ worm and IRC backdoor.
xp winis.exe
X
Added by the W32/Rbot-WO worm. When started this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
xpstart wini.exe
X
Added by the W32/Rbot-ABC. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infections are ... Read More
xpstat winlogins.exe
X
Added by the W32/Rbot-AAR WORM/IRC backdoor trojan!
xp_system winlogon.exe
X
KREPPER-G trojan, a CoolWebSearch parasite variant. Note - this is NOT the legitimate winlogon.exe process, which should NOT figure in Msconfig/Startu ... Read More
XTN Service Drivers winxtn.exe
X
Added by the W32/Sdbot-YK worm. When started this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Yahoo Messengger winfiles.exe
X
Added by the W32/Autorun-BCY removable media worm.
YOW tuner WatchPNM.exe
?
??
ytghyuiokjnmvrq wincab.sys
X
Added by the Mal/RootKit-A rootkit. The service and display name are typically random. ... Read More
z-WrDialer WrDialer.exe
U
WinPoet DSL dialer
Zone Labs Client win32dll.exe
X
Added by the Trojan.Syginre Trojan. Trojan.Syginre is a Trojan horse that disables the Windows Firewall and may delete some files from the compromised ... Read More
ZPoint winmuse.exe
X
Added by the Troj/Dloadr-VJ Trojan.
[not used] wpshrc.exe
Y
Required to prevent configuration errors on a Compaq LBP-660 parallel port laser printer (and maybe others) ... Read More
[not used] Winn.exe
X
Added by the Snob.IRCworm IRC worm.
[not used] Winroad.exe
X
Added by the Backdoor.Augudor backdoor.
[not used] wsv.com
X
Added by the Backdoor.Beasty.B backdoor. This backdoor listens on port 666.
[not used] wb.com
X
Added by the Backdoor.Beasty.E backdoor. This backdoor listens on port 666.
[not used] wb.com
X
Added by the Backdoor.Beasty.F backdoor. This backdoor listens on port 666.
[not used] winmgd.win
X
Added by the VBS_GEDZA.A worm.
[not used] winlog.exe
X
Added by the Troj/Sharp-J Trojan.
[not used] winldr.exe
X
Added by the W32/Bagle-AK worm.
[not used] winupdate.exe
X
Added by the Troj/Agent-FD Trojan. This infection also creates the files c:\windows\system32\Filesys.ini and c:\windows\system32\ntfilesys.ini.
[not used] wmfhotfix.dll
U
Added by the Windows WMF Metafile Vulnerability HotFix. This patch is used to protect your computer for the unpatched WMF vulnerability in Windows. ... Read More
[not used] winspols.scr
X
Added by the Troj/Fusion-B keylogging backdoor Trojan.
[not used] wmiadapt.exe
X
Added by the Troj/Small-BNQ backdoor Trojan.
[not used] WINGUIS.DLL
X
Added by the Troj/Oscor-B backdoor Trojan.
[not used] win_sk6.dll
X
Added by the Troj/Small-BVX Trojan.
[not used] win_7p5.dll
X
Added by the Troj/Small-BWA Trojan.
[not used] winvsp.exe
X
Added by the Troj/Paproxy-C Trojan.
[random name] wincpu.exe
X
Added by an unidentified VIRUS, WORM or TROJAN!
[random name] w?nlogon.exe
X
PurityScan adware variant.
[random name] w?nword.exe
X
PurityScan adware variant.
[random name] w?auboot.exe
X
[random name] w?auclt.exe
X
[random name] wuauboot.exe
X
PurityScan/Clickspring adware. Note - do not confuse with the legitimate wuauboot.exe file, which should not figure in Msconfig/Startup! ... Read More
[unknown name] WINBASICS32.EXE
X
Added by the Troj/Sdbot-JH worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
[unknown] WUAGMSD.EXE
X
Added by the W32/Rbot-AX trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
[unknown] WUAPDCT32.EXE
X
Added by the W32/Rbot-FG trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
[unknown] WIN32OP.EXE
X
Added by the W32/SdBot-U worm. When started, this infection connects to a remote IRC server and waits for commands to execute. ... Read More
[various names] Windows32.exe
X
Added by any of a number of WORM or TROJAN variants
[various names] winlogon32.exe
X
Added by an unidentified WORM or TROJAN!
[various names] win32snd.exe
X
Added by the RBOT-DQ WORM!
[Various Names] WinInitDll.exe
X
Part of the Wareout infection as described here.
[Various Names] WTFCTF.exe
X
Part of the Wareout infection as described here.
[Various Names] wormexe.exe
X
Part of the Wareout infection as described here.
[Various Names] WhatsNewBot.exe
X
Part of the Wareout infection as described here.
[X] WUCMDEX.EXE
X
Added by the W32/Rbot-DO WORM/IRC backdoor Trojan!
[] winbas12.exe
X
Adware, probably CoolWebSearch parasite related - recognized by Kaspersky antivirus as TrojanDownloader.Win32.VB.du ... Read More
\Generic Host Process for Win32 Services winsvc32.exe
X
Added by the W32/Sdbot-Pworm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
_ wmq.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Agent.euu malware.
_WGAw WgsDisp.exe
X
Added by the Troj/Small-CSJ Trojan.
_winadm winadm.exe
U
Parents Friend - "Log any activity and protect programs with a password. Further more you can lock the pc any hour in the week you want with the main ... Read More
_winmain winexec.exe
X
Malware - detected by Kaspersky antivirus as Trojan-Downloader.Win32.Agent.ts ... Read More
_winsystem.sys WINLOGON.EXE
X
Added by the W32/Sober-K infection! File will be found in the %WINDIR%msagentwin32 folder. ... Read More
{0976BE78-EA53-4DD6-91E6-E6175940032B} winstyle32.dll
X
Identified by Kaspersky Antivirus as a variant of Trojan-Downloader.Win32.Delf.qq. ... Read More
{0c7416f0-dd23-420f-97f5-aae352ea2bf1} wfkduei.dll
X
A file used by the rogue antispyware app, SpywareQuake, to issue fake security alerts on your taskbar. ... Read More
{0C8106F9-EAD2-8A05-0204-070602040008} wjn.exe
X
Added by the Troj/Inject-CM Trojan.
{10388970-0592-BCC4-1BCB-3147DA75A2F6} wblinds.exe
X
A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote serv ... Read More
{10388970-0592-BCC4-1BCB-3147DA75A2F6} wga.exe
X
A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote serv ... Read More
{143404b0-ee92-40a7-8705-06fba9a7abf4} wqzdtjg.dll
X
Added by a Zlob Trojan which installs AntiVirgear 3.7 and display fake security alerts in your Windows taskbar. ... Read More
{168cf174-6dab-461c-a761-a7adfa5a5719} wuwbxp.dll
X
A Trojan used by the rogue anti-spyware program VirusBurst. This Trojan, when installed, will display fake security alerts on your taskbar and install ... Read More
{19787F52-F569-66C9-0107-060800060008} WinSecDir.exe
X
A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote serv ... Read More
{24E27EA9-FCF3-444F-BD80-20543BA5D946} wschtm35.dll
X
A program in the TrustInCash malware suite, which includes Trust Cleaner, that issues fake security notification on your desktop and when you click on ... Read More
{28ABC5C0-4FCB-11CF-AAX5-81CX1C635612} winse32.exe
X
Identified as a variant of the Worm.AutoRun.DHA malware.
{2BDEC973-B5AC-4e5b-8AB3-5A0500880DA2} winload.dll
X
Identified as a variant of the Infostealer.Nuklus Trojan. Infostealer.Nuklus is a Trojan horse that steals sensitive information from the compromised ... Read More
{2D0CCE2D-2EEF-4432-0503-020002010803} wmp.exe
X
Added by the TSPY_SKPE.A spyware.
{4F12545B-1212-1314-5679-4512ACEF8904} wddpri.dll
X
Added by the Troj/QQPass-AOZ Trojan.
{5640F1A1-C8EB-170B-7DE1-F55B77CA0E98} winocxdll.exe
X
Added by the Troj/Dloadr-BEV Trojan.
{585A8A5E-27F0-9E11-21EA-07F58E9ED69B} wmhost.exe
X
Added by the Troj/Bckdr-QHS backdoor Trojan.
{5889f7b0-3277-4266-b4bd-1bf2d394aee6} wpchz.dll
X
Zlob Trojan that installs VirusProtectPro 3.4 and shows fake security alerts from your Windows taskbar. ... Read More
{5EE30F07-BB1C-4067-9BFB-7D5B11389506} winewtpas.dll
X
Added by the Troj/Lineage-PO password-stealing Trojan for the online game Lineage. ... Read More
{7B587C5A-28E3-4763-A5B5-CC19D89DFD22} winall.dll
X
Added by the Troj/Lineag-H password-stealing Trojan for the online game Lineage. ... Read More
{8169E97B-3F20-C6CB-E19B-C29D99B4F767} WinIni.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Delf.cxm malware.
{9311b8a8-0fd7-f849-5b42-67bbb89472f7} C:\windows:schost.exe
X
Identified as a variant of the Troj/Poison-K backdoor and keylogger. It is advised that once you remove this infection you immediately change all of ... Read More
{9af8f31b-b778-4413-b8ed-ae63a62e1f7d} wfcof.dll
X
Zlob Trojan that installs VirusProtectPro 3.3 and shows fake security alerts from your Windows taskbar. ... Read More
{9AFE2F49-58BA-4E47-A085-16E9123DD660} winplfg.dll
X
Added by the Troj/Lineag-AET password-stealing Trojan.
{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F} wbeconm.dll
X
Added by the Adware.TopAV which replaces the Windows wallpaper with a fake virus alert message containing links to topantivirus.biz or Spyaxe and issu ... Read More
{AA6B979A-796F-452A-94B3-DF1F17B72031} winpow32.dll
X
Added by the Troj/Lineag-BJ information stealing Trojan for the online game Lineage. ... Read More
{aa6d4f53-4c8d-4549-84d2-02d584acc4e9} wzhtjqo.dll
X
Zlob Trojan that installs VirusProtectPro 3.5 and shows fake security alerts from your Windows taskbar. ... Read More
{B212D577-05B7-4963-911E-4A8588160DFA} winstyle3.dll
X
Identified by Kaspersky Anti-Virus as Trojan-Downloader.Win32.Delf.h.
{B9BA1F0E-091E-ECF9-0A09-CC4C2EE29C62} task.exe
X
Identified as a variant of the Troj/Poison-K backdoor and keylogger. It is advised that once you remove this infection you immediately change all of ... Read More
{C1A2FDA2-2A5B-2C8A-F2A2-BA2DB3A2C31C} wiatwain.dll
X
Added by a rogue antispyware program who's affiliates install files that replaces the Windows wallpaper with a fake virus alert message and issues fak ... Read More
{E22DC74F-B084-F0F8-1BCE-00C8AF63188D} winlogon_patchv1.dll
X
Added by the Troj/BeastPWS-C keylogging Trojan.


> Status Key
Each entry in the database will have a Status assigned to it. The key to this status is the following:
  • Y - This status flag means that this entry should be left alone and be allowed to run as if it is unchecked it may break the functionality or use of a particular program.
  • N - This status flag means it is unnecessary to run this program automatically when Windows starts as you can run it manually when necessary.
  • U - This status flag means it is up to you whether or not you feel this program needs to run automatically.
  • X - This status flags means the item should definitely not start up automatically. Items that have this flag are generally malware such as viruses, trojans, hijackers, spyware but could also be programs that are not desirable to run on your computer.
  • ? - This status flag means the status of this entry is unknown at this time and more research is necessary.
If you require assistance in removing one of these files you can ask us in the Startup Database Forum.

> Disclaimer
It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. BleepingComputer.com will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.


Advertise   |   About Us   |   Terms of Use   |   Privacy Policy   |   Contact Us   |   Site Map   |   Chat   |   Tutorials   |   Uninstall List
Discussion Forums   |   The Computer Glossary   |   Resources   |   RSS Feeds   |   Startups   |   The File Database   |   Virus Removal Guides


Portions of this database © Paul Collins
© 2003-2012 All Rights Reserved Bleeping Computer LLC.
PGT: 0.60639 Queries: 4