Close Program/Task Manager
This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
Operating System Differences
A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Noeton eMail Protect" in the registry.
To avoid the list becoming too large, all VIRUSES are shown using the registry version which is common to all Windows versions.
Alternatively use your browsers search facility - Ctrl+F for IE users.
Key:
"Y" - Normally leave to run at start-up
"N" - Not required - typically infrequently used tasks that can be started manually if necessary
"U" - User's choice - depends whether a user deems it necessary
"X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
"?" - Unknown
Use your browsers search facility - Ctrl+F for IE users.
| X | w32 | w32.exe | Added by the SOKEVEN TROJAN! |
| X | W32.Scran | Scran.exe | Added by the NARCS WORM! |
| X | w32alanis | mope.scr | Added by the SINALA WORM! |
| X | W32Load | [random filename].scr | Added by the CASPID WORM! |
| X | w32sup | w32sup.exe | Adult content dialler |
| X | W32Tc | WTC32.scr | Added by the VOTE.D or VOTE.K WORMS! |
| X | W3KNetwork | rundll32.exe w3knet.dll, dllinitrun | Advertising spyware. Check here for more info on this particular one |
| Y | W75P2PSERVER | W75P2PS.EXE | Printer utility which is required in order to make the printer work correctly |
| ? | W815DM | W815DM.exe | ?? |
| N | Wanadoo Messenger.exe | Wanadoo Messenger.exe | Wanadoo ISP instant messenger client |
| Y | WanMPSvc | WanMPSvc.exe | An AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling AOL doesn’t help |
| X | WAPI | wts**.exe [* = random char] | PurityScan/Clickspring adware |
| N | war-ftpd.exe | WAR-FTPD.EXE | War FTP Daemon from JGAA's Internet - FTP client |
| X | Wardo | syslaunch.exe | Added by the ADLCICKER.G TROJAN! |
| X | WareOut | WareOut.exe | Malware masquerading as a spyware and dialer remover, see here |
| N | warez | warez.exe | Warez P2P client |
| U | Warner | warner.exe | Also known as "CyberWarner". From G-Tek Technologies and pre-installed on some Packard Bell PCs. Protects critical files |
| U | Warnet | warnet.exe | Warnet - system cleanup software |
| U | Warning: do not remove it! | fpplock.exe | Part of Folder Password Expert by ZQS Software Team - "a software program to restrict access to the folders that contain your sensitive data" |
| N | WARSVR | war-ftpd.exe | "War FTP Daemon - the original free FTP server for windows" |
| U | WashAndGo - Cleanup of old Backupfiles | checker.exe | WashAndGo - temp file cleaner |
| U | Washer | washer.exe | Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
| N | Washerie.exe | washerie.exe | Cookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer, specific for cleaning the IE cache and cookies. Available via Start -> Programs |
| U | washindex | washidx.exe | Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
| X | Wast | wast.exe | Grokster ads updater |
| N | Watch | watch.exe | Found to be used by a Trust USB scanner for auto starting the scanning software when the lid is lifted |
| ? | Watch | 1200UBWATCH.EXE | ?? |
| N | Watch Dog Program | watchdog.exe | For Compaq PC's. Associated with Compaq's internet services. Not required if you don't use services provided by them and may not be required even if you do |
| N | Watchdog | Watchdog.exe | Definitely part of the Mustek scanner drivers and software (for 600 III EP Plus and maybe others), launches from the Startup folder in the Start Menu, but not required as they give instructions on removing it on their webpage |
| ? | WatchDog | watchdog.exe | Part of Motorola "Mobile Phone Tools" v3 - in a "Mobiile Phone Tools" sub-directory of Program Files |
| N | WaveTop Launcher | WaveTop.exe | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
| N | WaveTop Receiver 1 | N/A | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
| N | WaveTop Receiver 2 | N/A | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
| N | WaveTop Upload Manager | N/A | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
| N | Wbiff | Wbiff.exe | Wbiff! E-mail checker - automatically checks your e-mail and notifies you if any new e-mail has been received |
| ? | Wbutton | Wbutton.exe | Related to the Wacom Penabled driver on Acer Tablet PCs. Appears to do nothing so is it required? |
| N | WCESCOMM | WCESCOMM.EXE | Active sync for use with Windows CE based palm PC |
| U | wcmdmgr | wcmdmgrl.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| N | wcmdmgr.exe | wcmdmgr.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| U | wcmdmgrl | wcmdmgrl.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| U | WCOLOREAL | coloreal.exe | Makes colours sharper and brighter, but will only work with coloreal capable monitors |
| ? | WCPC | wintsvcc.exe | ?? |
| X | WCPI | wintsvit.exe | PurityScan/Clickspring adware |
| X | WCPS | Wint**.exe [* = random char] | PurityScan/Clickspring adware |
| X | WCPT | wintsvtr.exe | PurityScan/Clickspring adware |
| U | WD Button Manager | WDBtnMgr.exe | Button manager installed with a western digital external disk drive. Allows you to back up your system with one click |
| X | WDInfo | wdinfo.exe | Added by the DLUCA.B TROJAN! |
| X | wdskctl | wdskctl.exe | IEPlugin spyware |
| X | wdwctrl | wdwctrl.exe | Added by the DLUCA.E TROJAN! |
| N | WEATHER | WEATHER.EXE | Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs |
| N | WeatherCast | Weather.exe | Weather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight |
| X | WeatherOnTray | WeatherOnTray.exe | Hotbar's Weather Forecast tool for your desktop - adware |
| N | WeatherWatcher | ww.exe | WeatherWatcher - weather reporting in the System Tray |
| X | web | ******.exe [* = random char] | Added by a variant of the EASTO.A TROJAN! |
| ? | Web Search | ?? | ?? |
| X | Web Service | [random filename].exe | Added by the ADMINCASH TROJAN! |
| Y | web3trap | web3trap.exe | PC-Cillin 2000 anti-virus software -> ActiveX filter. Guards against malicious ActiveX programs, etc |
| X | webalize | webalize.exe | Searchcentrix hijacker |
| N | WebArmyKnife | WAK.exe | Web Army Knife - a suite of web site developer's tools |
| X | webassist | webassist.exe | Adware popup generator |
| ? | Webcam Go Sti Service Application | wbcgosvc.exe | Control software for the portable Creative Video Blaster Webcam Go digital camera/PC web cam. What does it do and is it required? |
| N | WebcamRT.exe | WEBCAMRT.exe | For Logitech Web Cams. Not required - camera works fine without it |
| X | Webcelerator | webcel.exe | Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Spyware and troublesome - see here |
| X | WebCheck | WebCheck.pif | Added by the CONE.C or CONE.F WORMS! |
| X | WebCpr0 | WebCpr0.exe | Web_CPR/TopMoxie adware |
| X | Webdav.exe | webdav.exe | IRC DDoS bot which gives the hacker full control over your system |
| X | WebHancer Agent | whagent.exe | System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here |
| X | webHancer Survey Companion | whSurvey.exe | WebHancer foistware - traffic measurement service that uses a client agent that is stealth installed on user machines, gathering detailed data about sites visited, their performance and, most important, what the user actually does while there |
| X | WebInstall | WebInstall.exe | ClipGenie adware downloader |
| X | WebInstall2 | WebInstall.exe | ClipGenie adware downloader |
| N | WebKey | WebKey.exe | WebKey from JB Utilities. Utility to keep track of login data required when browsing the internet |
| N | WebOutfitterTray | sttray.exe | Intel WebOutfitter service System Tray icon |
| N | Webposition Gold 2 | wpsche~1.exe | Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines |
| X | WebRebates0 | WebRebates0.exe | WebRebates adware |
| X | WebRun | [Trojan filename] | Added by the ADWARELOADER TROJAN! |
| U | websaverlive | websaverlive.exe | WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your computer is idle |
| X | WebSavingsfromEbates | WebSavingsfromEbatesrun.exe | Web Savings From Ebates Software, a shopping tool that opens pop-up windows |
| X | WebSavingsFromEbates0 | WebSavingsFromEbates0.exe | Web Savings From Ebates Software, a shopping tool that opens pop-up windows |
| X | WebScan | DEFSCANGUI.EXE | eAcceleration Stop-Sign related - not recommended, see note |
| N | webscan | stopsignav.exe | eAcceleration Stop-Sign related - not recommended, see note |
| Y | WebScanX | WebScanX.exe | From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc |
| X | websearch | wjview ...websearch.exe | "Web Savings" From Ebates Software, a shopping tool that opens pop-up windows |
| X | WebSecureAlert | WebSecureAlert.exe | WebSecureAlert. "Can help protect your browser security and privacy". However, it's by GAIN Publishing, and will display pop up ads on your computer screen based on your online Web surfing behavior |
| ? | WebServer | VBI_SE~1.EXE | Related to a Pinnacle sound card. What does it do and is it needed? |
| N | Webshots | Webshots Tray.exe | Screensaver program that automatically downloads from the webshots web site |
| N | Webshots | websho~1.exe | Screensaver program that automatically downloads from the webshots web site |
| X | WebSpecials | rundll32 [path] webspec.dll | WebSpecials spyware |
| X | Websx | Int*****.exe | Adult content dialler - where ***** are random |
| Y | Webtrap | webtrap.exe | Part of PC-Cillin anti-virus software. Checks web-sites for malicious Java and ActiveX elements in a similar way to McAfee WebScanX. A few users find it infuriating |
| Y | WebTrapNT.exe | WebTrapNT.exe | Part of PC-Cillin Anti-Virus software. Checks visited web-sites for malicious Java and ActiveX elements |
| U | WebWasher | wwasher.exe | Free Pop-up/ad/javascript filter program from Siemens. If not running then browsers will not be protected but will still work. Available via Start -> Programs |
| N | Welcome | Welcome.exe | Launches the Welcome to Windows tutorial on boot up |
| ? | WEPstat | Wepstat.exe | Cisco Aironet 340 Series PC Card driver. If it can be started manually it shouldn't be required if you don't use the PC card facility regularily - hence the status could be "U". Can anybody confirm this? |
| X | wersds | doriot.exe | Added by the JECT.C TROJAN! |
| N | WetSock | wetsock.exe | RoboMagic Wetsock - weather reporting in the System Tray |
| N | WFGStartup | WFGStartup.exe | World Weather. "This midlet displays the current weather conditions for major cities around the world. This version is for memory limited mobile phones" |
| U | wfips | iphider.exe | ICQ (messaging/chat program) anti-bomb software. "WFIPS is anti-bomb software for safeguarding ICQ Bomb before the bombing. 'ICQ Defoolder' is a tool for removing ICQ bomb after being exposed." For more information about ICQ bombs see here |
| N | WFXCTL32.EXE | WFXCTL32.EXE | From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs |
| Y | wfxsnt40 | wfxsnt40.exe | WinFax 10.0 and maybe earlier versions. The program that opens the port for WinFax and not normally in the start menu. Needed if you want to run WinFax |
| ? | WFXSwtch | WFXSWTCH.exe | Related to WinFax. What does it do and is it required? |
| Y | WG511WLU | WG511WLU.exe | Netgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card |
| U | WGWLocalManager | WGWLocalManager.exe | Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so. It could be started by creating a shortcut, running it only when connecting to the internet. If internet is used often, it's recommended to leave it in startup so it starts with the system |
| X | whagent | whagent.exe | System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here |
| U | WheelMouse | 4DMAIN.EXE | Mouse software for "Fellowes" Wheelman mouse. Has caused some users problems but shouldn't be needed if you don't use any enhanced features it may provide |
| U | WheelMouse | AMOUMAIN.EXE | A4Tech wireless mouse driver and utility - required if you use non-standard Windows driver features |
| X | WhenUSave | Save.exe | SaveNow adware |
| X | WhenUSearch | Search.exe | SaveNow adware |
| X | WhenUSearchWHSE | whse.exe | SaveNow adware |
| X | Whvlxd | Whvlxd.exe | Added by the W32.LXD.MIRC TROJAN! |
| N | WIAWizardMenu | RUNDLL32.EXE sti_ci.dll, WiaCreateWizardMenu | Still Image Class Installer - installed with a webcam |
| ? | WildTangent CDA | RUNDLL32.exe cdaEngine0400.dll,cdaEngineMain | Part of the WildTangent on-line games system. What does it do and is it required? |
| U | WildTangent Web Driver updater | wcmdmgrl.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| N | Wildwire Monitor | WWMon.exe | This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem |
| N | Willow Road | WillowRoad.exe | Willow Road Screen Saver |
| X | win | regedit -s ..win.dll | Added by the SEEKER.K TROJAN! |
| X | win | xwinxrpc32.exe | Added by the AGOBOT-MV WORM! |
| X | win | xwinxrpc.exe | Added by the AGOBOT-MV WORM! |
| U | Win Chimes | winchi~1.exe | WinChimes - enhancement software for the system clock that runs in the system tray |
| X | Win Comm | WinComm.exe | WebRebates related adware |
| X | Win Command | command32.exe | Added by the AGOBOT.XQ WORM! |
| X | Win Command | command32.exe | Added by the AGOBOT.XQ WORM! |
| X | WIN HOST PROCESS | WIN HOST PROCESS.EXE | Added by the KEYLOGGER.CLONE TROJAN! |
| X | Win l5oahder | winampa.exe | Added by the SPYBOTER.GEN VIRUS! Not the valid Winamp Agent which uses the same filename. This resides in the System32 sub-folder wheras real one is located in the winamp folder |
| ? | win name | stat.exe | ?? |
| X | Win Patch | ntldr.exe | Added by the SDBOT-GS WORM! |
| X | Win Server | winserv.exe | Added by the IMISERV.A TROJAN! |
| X | Win Server Updt | wupdt.exe | Added by the IMISERV.A TROJAN! |
| X | win update | wupda32.exe | Added by the SDBOT.J WORM! |
| X | WIN USB 2.0 | usbsystem.exe | Added by an unidentified WORM of TROJAN! |
| X | Win USB 2.0 USB Driver | HPPrint.exe | Added by the SPYBOT.DNB WORM! |
| X | WIN-BUGSFIX | WIN-BUGSFIX.EXE | Added by the LOVELETTER (I LOVE YOU) VIRUS! |
| X | win-xp | nvsc32.exe | Added by the BROPIA.N WORM! |
| X | win-xp | winis.exe | Added by the BROPIA.N WORM! |
| X | Win2Drv | [worm filename] | Added by the WINTOO WORM! |
| X | WIN32 | WIN32.EXE | Added by the RATEGA TROJAN! |
| X | win32 | Shakira_1997_Part_1_.Mpeg_.scr | Added by the MYLIFE.N WORM! |
| X | win32 | Setup_32.exe | Added by the EVILBOT.B TROJAN! |
| X | Win32 | Win32.exe | Added by the ISRAZ.A WORM! |
| X | win32 | winsrv32.exe | Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites |
| X | win32 | WinSetup.exe | Added by the EVILBOT.B TROJAN! |
| X | Win32 | system32.vbs | Added by the SWERUN VIRUS! |
| X | Win32 | Game.exe.vbs | Added by the SCAFENE WORM! |
| X | Win32 Configuration | videosd32.exe | Added by the SDBOT.TT WORM! |
| X | Win32 Configuration | dllhelp.exe | Added by the SDBOT.UL WORM! |
| X | WIN32 DDOSSER | dos.exe | Added by the KELVIR.F WORM! |
| X | Win32 Device Loader | Win32ldr.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Win32 DRK Driver | wdrk32.exe | Added by the WOOTBOT.CY WORM! |
| X | Win32 exe file | winstr32.exe | Added by a variant of the SPYBOT WORM! |
| X | Win32 Explorer | Explorer32.exe | StartPa-MN homepage hijacker |
| X | Win32 FRT Driver | msfr32.exe | Added by a variant of the FORBOT WORM! |
| X | Win32 Kernel core component | Kernel32.pif | Added by the MOKS VIRUS! |
| X | Win32 Ms Auto Updater | AutomsUPD.exe | Added by a variant of the RBOT WORM! |
| X | Win32 Network Driver | crss.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Win32 NVIDIA Driver | MSPMSPSU.EXE | Added by a variant of the WOOTBOT.Y WORM! |
| X | win32 regedit | msn32.exe | Added by an unidentified WORM or TROJAN! |
| X | Win32 Rundll Loader | Rundll32.exe | Added by the SDBOT.A TROJAN! Note: Rundll32.exe is a valid Windows application called "Run a DLL as an App" and stored in the C:Windows directory. The version created by this virus is saved in the C:WindowsSystem directory |
| X | Win32 Service | bazzi.exe | Added by the AHKER.E WORM! |
| X | Win32 Services1 | wuamngr1.exe | Added by the SDBOT-PV WORM! |
| X | Win32 Src Service | win32src.exe | Added by the RBOT-SX WORM! |
| X | Win32 SSL Driver | winssv.exe | Added by the FORBOT-BH WORM! |
| X | Win32 System Spool | spoolsvc.exe | Added by the SDBOT.UK WORM! |
| X | Win32 USB Driver | winxpinit.exe | Added by the SDBOT.AA TROJAN! |
| X | Win32 USB Driver | mvsecn.exe | Added by the FORBOT-BK WORM! |
| X | Win32 Usb Driver | svhosint32.exe | Added by the FORBOT-BE or FORBOT-J WORMS! |
| X | Win32 Usb Driver | usb32.exe | Added by the SDBOT-OV WORM! |
| X | Win32 USB2 Driver | win32usb.exe | Added by the SPYBOT.DHV WORM! |
| X | Win32 USB2 Driver | smsc.exe | Added by the SDBOT.FO WORM! |
| X | Win32 USB2 Driver | svchosting.exe | Added by the FORBOT.J or SDBOT.HU WORM! |
| X | Win32 USB2 Driver | sys32.exe | Added by the WOOTBOT.X WORM! |
| X | Win32 USB2 Driver | sys32snd.exe | Added by the FORBOT-AN WORM! |
| X | Win32 USB2 Driver | wind32.exe | Added by the FORBOT-AH WORM! |
| X | Win32 USB2 Driver | winupdate.exe | Added by the AGOBOT.YE WORM! |
| X | Win32 USB2 Driver | updatemgr.exe | Added by a variant of the FORBOT WORM! |
| X | Win32 USB2 Driver | winsnd32.exe | Added by a variant of the SDBOT WORM! |
| X | Win32 USB2.0 Driver | 386.exe | Added by the IRCBOT.D WORM! |
| X | Win32 USB2.0 Driver | rundll16.exe | Added by the WOOTBOT.H WORM! |
| X | Win32 USB2.0 Driver | w32usb2.exe | Added by the SPYBOT.DN WORM! |
| X | Win32 USB2.0 Driver | service.exe | Added by the SDBOT-QF WORM! |
| X | Win32 USB3 Driver | win32tool.exe | Added by a variant of the RBOT WORM! |
| X | Win32 Wmls Driver | winitr32.exe | Added by the WOOTBOT.B WORM! |
| X | win32.exe | win32.exe | Added by the STARTPAGE TROJAN! |
| X | Win32BaseServiceMOD | Wintask.exe | Added by the NAVIDAD WORM! |
| X | win32clf | win32clf.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Win32DLL | Win32DLL.vbs | Added by the LOVELETTER (I LOVE YOU) VIRUS! |
| X | Win32dll | Win32dll.exe | Added by the BANPAES TROJAN! |
| X | Win32G | Kernel32.com | Added by the ESTRELLA TROJAN! |
| X | Win32G | Scandisk.com | Added by the ESTRELLA TROJAN |
| X | win32gb | win32gb.exe | All-In-One-Telcom (adult content dialler) variant |
| X | win32info | win32info.exe | Adult content dialler |
| X | win32ini | systroy.exe | Added by the IRC.ALADINZ.C TROJAN! |
| X | Win32R | Server.com | Added by the ESTRELLA TROJAN! |
| Y | WIN32SL | Win32sl.exe | Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. The specific function of this is to load MIF's in order for Dell OpenManage Client to work |
| X | WIN32SNDS | banc.exe | Added by an unidentified WORM or TROJAN! |
| X | Win32system | [random filename] | Added by the DDV.B WORM! |
| X | Win32System | win32s.exe | Added by the MYDOOM.V WORM! |
| X | Win32SystemMonitor | ***.exe [* = random char] | Browser hijacker |
| X | win32us | win32us.exe | All-In-One-Telcom (adult content dialler) variant |
| X | win32usbd | ssrs.exe | Added by the RBOT-RA WORM! |
| X | win32_i lptt01 | win32_i.exe | Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | win32_i ml097e | win32_i.exe | Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | Win386 | Win386.exe | Added by the GOSUSUB VIRUS! |
| X | Win386 | sp32.dll | Homepage hijacker. Not a dll but a regfile in disguise |
| X | WIN3S2SNDS | winabsmod.exe | Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" |
| X | WIN3S2SNDS | winiprtx.exe | Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" |
| X | Win64 Compatibility Check | load win64.drv | CoolWebSearch parasite variant |
| X | WinAC v4 | klsuicbn.exe | Added by the FORBOT-CS WORM! |
| X | winactive | WINACTIVE.EXE | Active variant of LOP.com hijacker - see here |
| X | WinActiveJ | WinActiveJ.exe | Added by the ROTARRAN VIRUS! |
| X | Winad Client | Winad.exe | WinAd adware by eXact Advertising |
| X | winadm | winadm.exe | Browser hijacker - redirecting to Search-World.net. Related to the SMALL.LR TROJAN! |
| X | Winahlp.exe | Winahlp.exe | Added by a variant of the VAGRNOCKER TROJAN! |
| X | winallap | winallap.exe | Added by the DELF.E TROJAN! |
| X | winallapu | winallapu.exe | Added by the DELF.E TROJAN! |
| X | Winamp | winamp.hta | Hijacker - re-directing to adult content sites. Note - this isn't the real Winamp |
| X | Winamp | winamp.exe | Added by the AGOBOT-MC WORM! Note - this is NOT the Winamp Media Player (WinAmpa.exe) |
| X | Winamp media player | winapa.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| U | Winampa | WINAMPa.exe | Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs |
| X | Winampa | winampa.exe | Added by the AGOBOT-GS WORM! |
| X | Winampa Agent | WINAMPA.EXE | Added by the SPYBOT-BR WORM! Note - this is NOT the Winamp Media Player |
| U | WinampAgent | WINAMPa.exe | Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs |
| X | WinAmpAgent | Msexploren.exe | Added by the EB TROJAN! Note - this is not the popular WinAmp media player file |
| X | WinAmpAgent | Shch.exe | Added by the EB TROJAN! Note - this is not the popular WinAmp media player file |
| X | WinAmpAgent | svchst.exe | Added by the EB TROJAN! Note - this is not the popular WinAmp media player file |
| X | WinAmpAgent | Winagent.exe | Added by the EB TROJAN! Note - this is not the popular WinAmp media player file |
| X | WinApi | winapix.exe | Added by a variant of the TIBSER.A downloader TROJAN! |
| X | Winapp | winpup32.exe | Produces popup ads to adult content sites |
| X | WinApp32 | msapp.exe | Added by the RSBOT TROJAN! |
| X | WinAuth | winlogon.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the valid winlogon.exe process |
| U | WinBackup Scheduler | Wbsched.exe | LIUtilities WinBackup scheduler - backup software |
| U | WinBar | WinBar.exe | "WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls" |
| X | winbas12 | winbas12.exe | Adware, probably CoolWebSearch parasite related - recognized by Kaspersky antivirus as TrojanDownloader.Win32.VB.du |
| X | Winbed | winbed.exe | Hijacker |
| X | WinCheck | WinCheck.exe | Added by the PWS-CY TROJAN! |
| N | WINCINEMAMGR | WINCIN~1.EXE | WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
| N | WinCinemaMgr | WinCinemaMgr.exe | WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
| X | WinCSRSS | MSGRT32.EXE | Added by the REWINDO-A TROJAN! |
| X | wind.exe | wind.exe | Added by the MITGLIEDER.BD TROJAN! |
| X | WIND0WS | WIND0WS.exe | Added by the SPYBOT.DQ WORM! |
| X | WIND0WS | mella.bat | Added by the ALLEM WORM! |
| N | WinDates | windates.exe | WinDates is a calendar, date organizer and event reminder program from Rockin' Software |
| X | windbs | winxtc.exe | Added by the AGOBOT-WD WORM! |
| X | Winde | winde.exe | Added by the DLUCA TROJAN! |
| X | windef | Win32sp.vbs | Added by the ANPES WORM! |
| X | windir | winrun.exe | Added by the WINBUR.B WORM! |
| X | Windll | Windll.exe | Added by the TRYNOMA TROJAN! |
| U | WINDLL | WSYS.EXE | STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes, all passwords transacted even if they weren't keyed in, all web sites visited, every program launched including the path to that program, and more" |
| X | windll | windll32.exe | Added by the ASTEF or RESPAN WORMS! |
| X | Windll.exe | Windll.exe | Added by the STEALER TROJAN! |
| X | Windll32 | Windll32.exe | Added by the MSNPWS TROJAN! |
| X | windllsys32.exe | windllsys32.exe | Added by a variant of the MITGLIEDER.BY TROJAN! |
| X | WinDNS | windns32.exe | Added by the GAOBOT.WX WORM! |
| X | Windoes Kernel | kernel32.exe | Added by the KICKIN.A (or CYDOG.C) WORM! |
| X | Window | explore.exe | Added by the GAOBOT.ADW WORM! |
| X | Window Loader | Dos32.exe | Added by the GAOBOT.AO WORM! |
| X | Window Monitor | winmon32.exe | Added by the SDBOT.RT WORM! |
| U | Window Washer | wwDisp.exe | Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
| X | window.exe | window.exe | Added by the MITGLIEDER.H or MITGLIEDER.J TROJANS! |
| X | window2 | ssvchost.exe | Added by the IRCBOT.H TROJAN! |
| U | WindowBlinds | wbload.exe | WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins |
| X | WindowEnhancer | Winex.exe | SCbar foistware variant |
| U | WindowFX | wfxload.exe | Stardock WindowFX - "Allows you to add an unprecedented number of special effects to windows" |
| X | Windows | Kernel32.exe | Added by the TENDOOLF WORM! |
| X | Windows | msdos98.exe | Added by the PWSTEAL TROJAN! |
| X | Windows | Windows.exe | Added by the KAZMOR, BOBBINS & ALADINZ.D TROJANS! |
| X | Windows | explorer.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | windows | [path to trojan] | Added by the AIMWIN TROJAN! |
| X | windows | hkey.exe | Added by the GAOBOT.AFW WORM! |
| X | windows | system copy.exe | Added by the SALGA.A WORM! |
| X | Windows (random character) | diskcheck.exe | Added by the SINGU.B TROJAN! |
| U | Windows Accelerators | setup.exe | KeySpy keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove |
| X | Windows AdControl | WinAdCtl.exe | Windupdates adware variant |
| X | Windows AdService | WinAdServ.exe | Windupdates adware variant |
| X | Windows AdStatus | WinStat.exe | Windupdates adware variant |
| X | Windows AdTools | WinAdTools.exe | Windupdates adware variant |
| X | Windows Anti-Virus Built 32 | AntiVirus32.exe | Added by the SDBOT-BG WORM! |
| X | windows auto update | penis32.exe | Added by the BLASTER (or MSBLAST.A) WORM! |
| X | Windows Auto Update | winupdater.exe | Added by the SDBOT.TF WORM! |
| X | windows auto update | msblast.exe | Added by the BLASTER.B WORM! |
| X | Windows Automatic Update | wuamgrder.exe | Added by a variant of the RBOT WORM! |
| X | Windows Automatic Updates | dvldr.exe | Added by the RBOT.MF WORM! |
| X | windows automation | mslaugh.exe | Added by the BLASTER.E WORM! |
| X | Windows Automation | msdspr.exe | Added by the SOLAME.A WORM! |
| X | Windows backup | systemss.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows Backup Configuration | IEXPLORER.exe | Added by the GAOBOT.AZ WORM! |
| X | Windows Baþlangýç Dosyasý | sistem.exe | Added by the MUZK WORM! |
| X | Windows Communicator | wincomm.exe | Added by the AGOBOT-BH WORM! |
| X | Windows Compliant | [random filename] | Added by the RBOT-IR WORM! |
| X | Windows Config | SSYS.EXE | Added by the SPYBOT-DA WORM! |
| X | Windows Config Loader | Wincfg32.exe | Added by the SILVERFTP TROJAN! |
| X | Windows Configuration | wsys32.exe | Added by the GAOBOT.FB WORM! |
| X | Windows Control | Control.exe | Browser hijacker. NOTE - On Win9x systems it will overwrite the Windows file of the same name in the Windows directory, so therefore it will be necessary to extract a fresh copy of the file from the Windows setup cabs! |
| X | Windows ControlAd | WinCtlAd.exe | Windupdates adware variant |
| X | Windows Data Server | autodisc.exe | Added by the SPYBOT-CB WORM! |
| X | Windows Database | WinDat.exe | Added by an unidentified WORM or TROJAN! |
| X | Windows Dcom2 Fix | mscom32.exe | Added by the RBOT-QT WORM! |
| X | Windows debug logging | winlogg.exe | Added by the RBOT-OY WORM! |
| X | Windows debug logging | winloggs.exe | Added by the RBOT-QN WORM! |
| X | Windows Debugger | windbg.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Windows DLL Loader | RUNDLL16.EXE | Added by the DOMWIS TROJAN! |
| X | Windows DLL Loader | defragfat32z.exe | Added by the LINKBOT.A WORM! |
| X | Windows DLL Loader | rundll32.exe | Added by the WHIPSER-B WORM! Note - rundll32.exe file is placed in the WindowsSystem folder, wheras the legitimate rundll32.exe is located in the C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP) |
| X | Windows DLL Loader | defragfat32pi.exe | Added by the RBOT-QQ WORM! |
| X | Windows DLL Loader | defragfat39.exe | Added by the POEBOT-C WORM! |
| X | Windows DLL Loader | defragfatz.exe | Added by the LINKBOT.H WORM! |
| X | Windows DNS Daemon | windnsd.exe | Added by the WOOTBOT.AS WORM! |
| X | Windows Drive Compatibility | System32Driver32.exe | Added by the SUPOVA.Z WORM! |
| X | Windows Driver Services | msdrvs32.exe | Added by the WOOTBOT.L WORM! |
| X | Windows Explorer | [filename].exe | Added by the SDBOT TROJAN! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | Windows Explorer | Lsas.exe | Added by the GAOBOT.AO WORM! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | Windows Explorer | olecom32.exe | Added by an unidentified WORM or TROJAN! |
| X | Windows Explorer | EEXPLORER.EXE | Added by a variant of the SPYBOT WORM! |
| X | Windows Explorer Shell | Winexec32.exe | Added by the REDIST.B WORM! |
| X | Windows Explorer Update Build 1142 | EXPLORER32.EXE | Added by the KaZaA based KWBOT or KWBOT.Y WORMS! |
| X | Windows Explorer-3212 | WINRE16.EXE | Added by the HARDOC WORM! |
| N | Windows Eyes | ?? | For blind people, gives a voice description of items on the screen. Windows application which gives you total control over what you hear, when you hear it, and how you hear it. Available via Start -> Programs |
| X | Windows File Protection | winprotect.exe | Added by the AGOBOT.JB WORM! |
| X | Windows Firewall Manager | msfw.exe | Added by the RBOT.WR WORM! |
| X | Windows Fix | integator.exe | Added by the SDBOT.ZAB WORM! |
| X | Windows FormatAd | WinForm.exe | Windupdates adware variant |
| X | Windows Graphics Loaders | wingraphics.exe | Added by the SPYBOT.JG WORM! |
| U | Windows Guardian | thehel1iawgrd32.exe | Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes |
| U | Windows Guardian | Fawgrd32.exe | Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes |
| X | Windows Help File | winhelper32.exe | Added by the SDBOT-QK TROJAN! |
| X | Windows Help Manager | svchost32.exe | Added by the RBOT-OZ WORM! |
| X | Windows Help Service | winhelpsv.exe | Added by the RBOT-LP WORM! |
| ? | Windows Help System | Help.pif | ?? |
| X | Windows Host Device | hostsvc.exe | Added by the ZOOTY-A WORM! |
| X | Windows HTML file reader | Sysconf32.exe | Added by the NOOMY.A WORM! |
| X | Windows Internet Protocol | winproc32.exe | CoolWebSearch parasite variant |
| X | Windows JavaScript Daemon | Winjsd.exe | Added by the WOOTBOT.AF WORM! |
| ? | Windows Load | windows.com | ?? |
| X | Windows Loader | wstart32.exe | Added by the GAOBOT.CA WORM! |
| X | Windows Loader Service | civsc.exe | Added by a variant of the RBOT WORM! |
| X | Windows logging | winlogd.exe | Added by the RBOT-ON WORM! |
| X | Windows Login | explored.exe | Added by the GAOBOT.SY WORM! |
| X | Windows Logon | winlogin.exe | Added by the SPYBOT-C TROJAN! |
| X | Windows Logon Procedure | Svchoste.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows Logon Procedure | Svchosta.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows Management Instrumentation | mwd.exe | Added by the GRAPS WORM! |
| X | Windows Manager | winmants.exe | Added by the MANTAS WORM! |
| X | Windows mangement | winlogonn.exe | Added by the RANDEX.FC WORM! |
| X | Windows Media Player | wmediaplayer.exe | Added by the AGOBOT-NQ WORM! |
| X | Windows Media Player | MediaPIayer.exe | Added by the SDBOT-QO TROJAN! - note, the executable is called 'MediapIayer', with an 'i' !) |
| X | Windows Media Player | [random filename] | Added by a variant of the RBOT WORM! |
| X | Windows Media Player | msa.exe | Added by the RBOT-SI WORM! |
| X | Windows Media Player | mcafe32.exe | Added by a variant of the SDBOT WORM! |
| X | Windows Media Player | wmplayer.exe | Added by the SPYBOT WORM! Note - this is not the valid Windows Media Player as the executeable resides is C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP) rather than C:Program FilesWindows Media Player |
| X | Windows Media Player Update | [random filename] | Added by the RBOT-ET WORM! |
| N | Windows Media Powerpoint Helper | NSPPTHLP.EXE | German software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start -> Programs |
| X | Windows media service | crvss.exe | Added by the SDBOT.VP WORM! |
| X | Windows media service | crsss.exe | Added by the RBOT.ACY WORM! |
| X | Windows media services | cvrsss.exe | Added by the RBOT-MW WORM! |
| X | Windows Media SP.2.37 | [random filename] | Added by the LEMIR.C TROJAN! |
| X | Windows MeTaLRoCk service | metalrock.exe | Added by the TASTYRED TROJAN! |
| X | Windows Monitor | winmon.exe | Added by the SDBOT.VB WORM! |
| X | Windows Monitoring Service | winmon.exe | Added by a variant of the SDBOT WORM! |
| X | Windows Nets | WinNET.exe | Added by the RBOT-MO WORM! |
| X | Windows Network Controller | Mqguard.exe | Added by the FORBOT-CL WORM! |
| X | Windows Network Controller | WinxPupd.exe | Added by the FORBOT-DK WORM! |
| X | Windows Network Controller | winmms32.exe | Added by the FORBOT-ED WORM! |
| X | Windows Network Service | winvc32.exe | Added by the RBOT.RY WORM! |
| X | Windows Networking | winsys32.exe | Added by the GAOBOT.FL WORM! |
| X | Windows Nivedia Driver | sysMGT.exe | Added by a variant of the RBOT WORM! |
| X | Windows NNT | [path to trojan] | Added by the RANKY.E TROJAN! |
| X | Windows NT 32 | ntlogin32.exe | Added by the RANDEX.BRD WORM! |
| X | Windows NT Login | ntlogin32.exe | Added by the SDBOT.WG WORM! |
| X | Windows NT Service Name | winshock.exe | Added by the RBOT-PK WORM! |
| X | Windows NT Update Manager | WINL0G0N.exe | Added by the AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital "o" |
| X | Windows OEM Tools | winres32.exe | Added by the SPYBOT.FD WORM! |
| X | Windows OLE Automation Server | ole32aut.vbe | CoolWebSearch parasite related browser hijacker |
| X | Windows Online Updater | dllman.exe | Added by the RBOT-TE WORM! |
| ? | Windows Print Spooler | SCVHOSTS.EXE | Suspicious due to the similarity to the valid "svchost.exe" file |
| X | Windows Print Spooler | NavAgent32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Windows Print Spooler | SVEHOST.EXE | Added by the SPYBOT.H WORM! |
| X | Windows Registry | msnmsg.exe | Added by a variant of the RBOT WORM! |
| X | Windows Registry Cleaner | winclean.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows Registry Express Loader | regexpress.exe | Added by the FORBOT-CJ WORM! |
| X | Windows Registry Scan | regscan32.exe | Added by the RBOT.KE WORM! |
| X | Windows Registry Scan | timeupdate.exe | Added by the SPYBOT.JE WORM! |
| X | Windows Registry Security | crss.exe | Added by a variant of the IRC.BOT TROJAN! |
| X | Windows Registry Startup | wind32.exe | Added by the AGOBOT-BZ WORM! |
| X | Windows report | swchost.exe | Added by the SMALL-BD TROJAN! |
| X | Windows Runtime Help | win32hlp.exe | Added by a variant of the AIMVISION TROJAN! |
| X | Windows Runtime Help | WinRunHelp.wrh | Added by a variant of the AIMVISION TROJAN! |
| X | Windows SA | omniscient.exe | BLAZEFIND adware |
| X | Windows secure | setver32.exe | Added by the SPYBOT.EP WORM! |
| X | Windows Secure Messaging System | msnmsgrsrvc.exe | Added by the RBOT-RE WORM! |
| X | Windows Security Assistant | rundll32.vbe | CoolWebSearch parasite variant |
| X | Windows Security Assistant | winsec.exe | CoolWebSearch parasite variant |
| X | Windows Security Module | module.exe | Added by a variant of the RBOT WORM! |
| X | Windows ServeAd | WinServAd.exe | Windupdates adware variant |
| X | Windows service | wuamgrd.exe | Added by the RBOT-QW WORM! |
| X | Windows Service | dddd.exe | Identified by Kaspersky Labs as PornWare.Dialer.Salc, also known to come with the Bube family trojans |
| X | Windows Service | prvdi.exe | Malware, recognized by Kaspersky antivirus as Trojan-Dropper.Win32.Small.rd |
| X | Windows Service Host | scvhost.exe | Added by the SDBOT.N TROJAN! |
| X | Windows Service Host | svchost.exe | Added by the |