wmiapi.exe is a Backdoor W32.Spybot.RBY. wmiapi.exe spreads via open network shares. wmiapi.exe tries to terminate antiviral programs installed on a user computer. Related files: %System%\wmiapi.exe %Temp%\1.reg C:\a.bat Adds the value: "WMI Application Interface" = "wmiapi.exe" to the Windows startup registry keys. More info: http://securityresponse.symantec.com/avc... Removal: Kill wmiapi.exe process and remove wmiapi.exe from Windows startup using antivirus (also check How To Remove section)Startup Optimizer.