Windows XP A to Z - http://www.softwaretipsandtricks.com/windowsxp
Start Up Applications W
http://www.softwaretipsandtricks.com/windowsxp/articles/616/1/Start-Up-Applications-W
Super Admin
 
By Super Admin
Published on 03/28/2005
 
Starting with letter W

Start Up Applications W Page 1

Close Program/Task Manager
This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Operating System Differences
A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Noeton eMail Protect" in the registry.

To avoid the list becoming too large, all VIRUSES are shown using the registry version which is common to all Windows versions.

Alternatively use your browsers search facility - Ctrl+F for IE users.

Key:

"Y" - Normally leave to run at start-up
"N" - Not required - typically infrequently used tasks that can be started manually if necessary
"U" - User's choice - depends whether a user deems it necessary
"X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
"?" - Unknown

Use your browsers search facility - Ctrl+F for IE users.

X w32 w32.exe Added by the SOKEVEN TROJAN!
X W32.Scran Scran.exe Added by the NARCS WORM!
X w32alanis mope.scr Added by the SINALA WORM!
X W32Load [random filename].scr Added by the CASPID WORM!
X w32sup w32sup.exe Adult content dialler
X W32Tc WTC32.scr Added by the VOTE.D or VOTE.K WORMS!
X W3KNetwork rundll32.exe w3knet.dll, dllinitrun Advertising spyware. Check here for more info on this particular one
Y W75P2PSERVER W75P2PS.EXE Printer utility which is required in order to make the printer work correctly
? W815DM W815DM.exe ??
N Wanadoo Messenger.exe Wanadoo Messenger.exe Wanadoo ISP instant messenger client
Y WanMPSvc WanMPSvc.exe An AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling AOL doesn’t help
X WAPI wts**.exe [* = random char] PurityScan/Clickspring adware
N war-ftpd.exe WAR-FTPD.EXE War FTP Daemon from JGAA's Internet - FTP client
X Wardo syslaunch.exe Added by the ADLCICKER.G TROJAN!
X WareOut WareOut.exe Malware masquerading as a spyware and dialer remover, see here
N warez warez.exe Warez P2P client
U Warner warner.exe Also known as "CyberWarner". From G-Tek Technologies and pre-installed on some Packard Bell PCs. Protects critical files
U Warnet warnet.exe Warnet - system cleanup software
U Warning: do not remove it! fpplock.exe Part of Folder Password Expert by ZQS Software Team - "a software program to restrict access to the folders that contain your sensitive data"
N WARSVR war-ftpd.exe "War FTP Daemon - the original free FTP server for windows"
U WashAndGo - Cleanup of old Backupfiles checker.exe WashAndGo - temp file cleaner
U Washer washer.exe Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
N Washerie.exe washerie.exe Cookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer, specific for cleaning the IE cache and cookies. Available via Start -> Programs
U washindex washidx.exe Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
X Wast wast.exe Grokster ads updater
N Watch watch.exe Found to be used by a Trust USB scanner for auto starting the scanning software when the lid is lifted
? Watch 1200UBWATCH.EXE ??
N Watch Dog Program watchdog.exe For Compaq PC's. Associated with Compaq's internet services. Not required if you don't use services provided by them and may not be required even if you do
N Watchdog Watchdog.exe Definitely part of the Mustek scanner drivers and software (for 600 III EP Plus and maybe others), launches from the Startup folder in the Start Menu, but not required as they give instructions on removing it on their webpage
? WatchDog watchdog.exe Part of Motorola "Mobile Phone Tools" v3 - in a "Mobiile Phone Tools" sub-directory of Program Files
N WaveTop Launcher WaveTop.exe WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
N WaveTop Receiver 1 N/A WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
N WaveTop Receiver 2 N/A WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
N WaveTop Upload Manager N/A WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
N Wbiff Wbiff.exe Wbiff! E-mail checker - automatically checks your e-mail and notifies you if any new e-mail has been received
? Wbutton Wbutton.exe Related to the Wacom Penabled driver on Acer Tablet PCs. Appears to do nothing so is it required?
N WCESCOMM WCESCOMM.EXE Active sync for use with Windows CE based palm PC
U wcmdmgr wcmdmgrl.exe Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
N wcmdmgr.exe wcmdmgr.exe Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
U wcmdmgrl wcmdmgrl.exe Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
U WCOLOREAL coloreal.exe Makes colours sharper and brighter, but will only work with coloreal capable monitors
? WCPC wintsvcc.exe ??
X WCPI wintsvit.exe PurityScan/Clickspring adware
X WCPS Wint**.exe [* = random char] PurityScan/Clickspring adware
X WCPT wintsvtr.exe PurityScan/Clickspring adware
U WD Button Manager WDBtnMgr.exe Button manager installed with a western digital external disk drive. Allows you to back up your system with one click
X WDInfo wdinfo.exe Added by the DLUCA.B TROJAN!
X wdskctl wdskctl.exe IEPlugin spyware
X wdwctrl wdwctrl.exe Added by the DLUCA.E TROJAN!
N WEATHER WEATHER.EXE Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs
N WeatherCast Weather.exe Weather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight
X WeatherOnTray WeatherOnTray.exe Hotbar's Weather Forecast tool for your desktop - adware
N WeatherWatcher ww.exe WeatherWatcher - weather reporting in the System Tray
X web ******.exe [* = random char] Added by a variant of the EASTO.A TROJAN!
? Web Search ?? ??
X Web Service [random filename].exe Added by the ADMINCASH TROJAN!
Y web3trap web3trap.exe PC-Cillin 2000 anti-virus software -> ActiveX filter. Guards against malicious ActiveX programs, etc 
X webalize webalize.exe Searchcentrix hijacker
N WebArmyKnife WAK.exe Web Army Knife - a suite of web site developer's tools
X webassist webassist.exe Adware popup generator
? Webcam Go Sti Service Application wbcgosvc.exe Control software for the portable Creative Video Blaster Webcam Go digital camera/PC web cam. What does it do and is it required?
N WebcamRT.exe WEBCAMRT.exe For Logitech Web Cams. Not required - camera works fine without it
X Webcelerator webcel.exe Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Spyware and troublesome - see here
X WebCheck WebCheck.pif Added by the CONE.C or CONE.F WORMS!
X WebCpr0 WebCpr0.exe Web_CPR/TopMoxie adware
X Webdav.exe webdav.exe IRC DDoS bot which gives the hacker full control over your system
X WebHancer Agent whagent.exe System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here
X webHancer Survey Companion whSurvey.exe WebHancer foistware - traffic measurement service that uses a client agent that is stealth installed on user machines, gathering detailed data about sites visited, their performance and, most important, what the user actually does while there
X WebInstall WebInstall.exe ClipGenie adware downloader
X WebInstall2 WebInstall.exe ClipGenie adware downloader
N WebKey WebKey.exe WebKey from JB Utilities. Utility to keep track of login data required when browsing the internet
N WebOutfitterTray sttray.exe Intel WebOutfitter service System Tray icon
N Webposition Gold 2 wpsche~1.exe Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines
X WebRebates0 WebRebates0.exe WebRebates adware
X WebRun [Trojan filename] Added by the ADWARELOADER TROJAN!
U websaverlive websaverlive.exe WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your computer is idle
X WebSavingsfromEbates WebSavingsfromEbatesrun.exe Web Savings From Ebates Software, a shopping tool that opens pop-up windows
X WebSavingsFromEbates0 WebSavingsFromEbates0.exe Web Savings From Ebates Software, a shopping tool that opens pop-up windows
X WebScan DEFSCANGUI.EXE eAcceleration Stop-Sign related - not recommended, see note
N webscan stopsignav.exe eAcceleration Stop-Sign related - not recommended, see note
Y WebScanX WebScanX.exe From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc
X websearch wjview ...websearch.exe "Web Savings" From Ebates Software, a shopping tool that opens pop-up windows
X WebSecureAlert WebSecureAlert.exe WebSecureAlert. "Can help protect your browser security and privacy". However, it's by GAIN Publishing, and will display pop up ads on your computer screen based on your online Web surfing behavior
? WebServer VBI_SE~1.EXE Related to a Pinnacle sound card. What does it do and is it needed?
N Webshots Webshots Tray.exe Screensaver program that automatically downloads from the webshots web site
N Webshots websho~1.exe Screensaver program that automatically downloads from the webshots web site
X WebSpecials rundll32 [path] webspec.dll WebSpecials spyware
X Websx Int*****.exe Adult content dialler - where ***** are random
Y Webtrap webtrap.exe Part of PC-Cillin anti-virus software. Checks web-sites for malicious Java and ActiveX elements in a similar way to McAfee WebScanX. A few users find it infuriating
Y WebTrapNT.exe WebTrapNT.exe Part of PC-Cillin Anti-Virus software. Checks visited web-sites for malicious Java and ActiveX elements
U WebWasher wwasher.exe Free Pop-up/ad/javascript filter program from Siemens. If not running then browsers will not be protected but will still work. Available via Start -> Programs
N Welcome Welcome.exe Launches the Welcome to Windows tutorial on boot up
? WEPstat Wepstat.exe Cisco Aironet 340 Series PC Card driver. If it can be started manually it shouldn't be required if you don't use the PC card facility regularily - hence the status could be "U". Can anybody confirm this?
X wersds doriot.exe Added by the JECT.C TROJAN!
N WetSock wetsock.exe RoboMagic Wetsock - weather reporting in the System Tray
N WFGStartup WFGStartup.exe World Weather. "This midlet displays the current weather conditions for major cities around the world. This version is for memory limited mobile phones"
U wfips iphider.exe ICQ (messaging/chat program) anti-bomb software. "WFIPS is anti-bomb software for safeguarding ICQ Bomb before the bombing. 'ICQ Defoolder' is a tool for removing ICQ bomb after being exposed." For more information about ICQ bombs see here
N WFXCTL32.EXE WFXCTL32.EXE From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
Y wfxsnt40 wfxsnt40.exe WinFax 10.0 and maybe earlier versions. The program that opens the port for WinFax and not normally in the start menu. Needed if you want to run WinFax
? WFXSwtch WFXSWTCH.exe Related to WinFax. What does it do and is it required?
Y WG511WLU WG511WLU.exe Netgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card
U WGWLocalManager WGWLocalManager.exe Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so. It could be started by creating a shortcut, running it only when connecting to the internet. If internet is used often, it's recommended to leave it in startup so it starts with the system


Start Up Applications W Page 2
X whagent whagent.exe System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here
U WheelMouse 4DMAIN.EXE Mouse software for "Fellowes" Wheelman mouse. Has caused some users problems but shouldn't be needed if you don't use any enhanced features it may provide
U WheelMouse AMOUMAIN.EXE A4Tech wireless mouse driver and utility - required if you use non-standard Windows driver features
X WhenUSave Save.exe SaveNow adware
X WhenUSearch Search.exe SaveNow adware
X WhenUSearchWHSE whse.exe SaveNow adware
X Whvlxd Whvlxd.exe Added by the W32.LXD.MIRC TROJAN!
N WIAWizardMenu RUNDLL32.EXE sti_ci.dll, WiaCreateWizardMenu Still Image Class Installer - installed with a webcam
? WildTangent CDA RUNDLL32.exe cdaEngine0400.dll,cdaEngineMain Part of the WildTangent on-line games system. What does it do and is it required?
U WildTangent Web Driver updater wcmdmgrl.exe Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
N Wildwire Monitor WWMon.exe This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem
N Willow Road WillowRoad.exe Willow Road Screen Saver
X win regedit -s ..win.dll Added by the SEEKER.K TROJAN!
X win xwinxrpc32.exe Added by the AGOBOT-MV WORM!
X win xwinxrpc.exe Added by the AGOBOT-MV WORM!
U Win Chimes winchi~1.exe WinChimes - enhancement software for the system clock that runs in the system tray
X Win Comm WinComm.exe WebRebates related adware
X Win Command command32.exe Added by the AGOBOT.XQ WORM!
X Win Command command32.exe Added by the AGOBOT.XQ WORM!
X WIN HOST PROCESS WIN HOST PROCESS.EXE Added by the KEYLOGGER.CLONE TROJAN!
X Win l5oahder winampa.exe Added by the SPYBOTER.GEN VIRUS! Not the valid Winamp Agent which uses the same filename. This resides in the System32 sub-folder wheras real one is located in the winamp folder
? win name stat.exe ??
X Win Patch ntldr.exe Added by the SDBOT-GS WORM!
X Win Server winserv.exe Added by the IMISERV.A TROJAN!
X Win Server Updt wupdt.exe Added by the IMISERV.A TROJAN!
X win update wupda32.exe Added by the SDBOT.J WORM!
X WIN USB 2.0 usbsystem.exe Added by an unidentified WORM of TROJAN!
X Win USB 2.0 USB Driver HPPrint.exe Added by the SPYBOT.DNB WORM!
X WIN-BUGSFIX WIN-BUGSFIX.EXE Added by the LOVELETTER (I LOVE YOU) VIRUS!
X win-xp nvsc32.exe Added by the BROPIA.N WORM!
X win-xp winis.exe Added by the BROPIA.N WORM!
X Win2Drv [worm filename] Added by the WINTOO WORM!
X WIN32 WIN32.EXE Added by the RATEGA TROJAN!
X win32 Shakira_1997_Part_1_.Mpeg_.scr Added by the MYLIFE.N WORM!
X win32 Setup_32.exe Added by the EVILBOT.B TROJAN!
X Win32 Win32.exe Added by the ISRAZ.A WORM!
X win32 winsrv32.exe Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites
X win32 WinSetup.exe Added by the EVILBOT.B TROJAN!
X Win32 system32.vbs Added by the SWERUN VIRUS!
X Win32 Game.exe.vbs Added by the SCAFENE WORM!
X Win32 Configuration videosd32.exe Added by the SDBOT.TT WORM!
X Win32 Configuration dllhelp.exe Added by the SDBOT.UL WORM!
X WIN32 DDOSSER dos.exe Added by the KELVIR.F WORM!
X Win32 Device Loader Win32ldr.exe Added by a variant of the AGOBOT/GAOBOT WORM!
X Win32 DRK Driver wdrk32.exe Added by the WOOTBOT.CY WORM!
X Win32 exe file winstr32.exe Added by a variant of the SPYBOT WORM!
X Win32 Explorer Explorer32.exe StartPa-MN homepage hijacker
X Win32 FRT Driver msfr32.exe Added by a variant of the FORBOT WORM!
X Win32 Kernel core component Kernel32.pif Added by the MOKS VIRUS!
X Win32 Ms Auto Updater AutomsUPD.exe Added by a variant of the RBOT WORM!
X Win32 Network Driver crss.exe Added by a variant of the AGOBOT/GAOBOT WORM!
X Win32 NVIDIA Driver MSPMSPSU.EXE Added by a variant of the WOOTBOT.Y WORM!
X win32 regedit msn32.exe Added by an unidentified WORM or TROJAN!
X Win32 Rundll Loader Rundll32.exe Added by the SDBOT.A TROJAN! Note: Rundll32.exe is a valid Windows application called "Run a DLL as an App" and stored in the C:Windows directory. The version created by this virus is saved in the C:WindowsSystem directory
X Win32 Service bazzi.exe Added by the AHKER.E WORM!
X Win32 Services1 wuamngr1.exe Added by the SDBOT-PV WORM!
X Win32 Src Service win32src.exe Added by the RBOT-SX WORM!
X Win32 SSL Driver winssv.exe Added by the FORBOT-BH WORM!
X Win32 System Spool spoolsvc.exe Added by the SDBOT.UK WORM!
X Win32 USB Driver winxpinit.exe Added by the SDBOT.AA TROJAN!
X Win32 USB Driver mvsecn.exe Added by the FORBOT-BK WORM!
X Win32 Usb Driver svhosint32.exe Added by the FORBOT-BE or FORBOT-J WORMS!
X Win32 Usb Driver usb32.exe Added by the SDBOT-OV WORM!
X Win32 USB2 Driver win32usb.exe Added by the SPYBOT.DHV WORM!
X Win32 USB2 Driver smsc.exe Added by the SDBOT.FO WORM!
X Win32 USB2 Driver svchosting.exe Added by the FORBOT.J or SDBOT.HU WORM!
X Win32 USB2 Driver sys32.exe Added by the WOOTBOT.X WORM!
X Win32 USB2 Driver sys32snd.exe Added by the FORBOT-AN WORM!
X Win32 USB2 Driver wind32.exe Added by the FORBOT-AH WORM!
X Win32 USB2 Driver winupdate.exe Added by the AGOBOT.YE WORM!
X Win32 USB2 Driver updatemgr.exe Added by a variant of the FORBOT WORM!
X Win32 USB2 Driver winsnd32.exe Added by a variant of the SDBOT WORM!
X Win32 USB2.0 Driver 386.exe Added by the IRCBOT.D WORM!
X Win32 USB2.0 Driver rundll16.exe Added by the WOOTBOT.H WORM!
X Win32 USB2.0 Driver w32usb2.exe Added by the SPYBOT.DN WORM!
X Win32 USB2.0 Driver service.exe Added by the SDBOT-QF WORM!
X Win32 USB3 Driver win32tool.exe Added by a variant of the RBOT WORM!
X Win32 Wmls Driver winitr32.exe Added by the WOOTBOT.B WORM!
X win32.exe win32.exe Added by the STARTPAGE TROJAN!
X Win32BaseServiceMOD Wintask.exe Added by the NAVIDAD WORM!
X win32clf win32clf.exe Added by an unidentified VIRUS, WORM or TROJAN!
X Win32DLL Win32DLL.vbs Added by the LOVELETTER (I LOVE YOU) VIRUS!
X Win32dll Win32dll.exe Added by the BANPAES TROJAN!
X Win32G Kernel32.com Added by the ESTRELLA TROJAN!
X Win32G Scandisk.com Added by the ESTRELLA TROJAN
X win32gb win32gb.exe All-In-One-Telcom (adult content dialler) variant
X win32info win32info.exe Adult content dialler
X win32ini systroy.exe Added by the IRC.ALADINZ.C TROJAN!
X Win32R Server.com Added by the ESTRELLA TROJAN!
Y WIN32SL Win32sl.exe Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. The specific function of this is to load MIF's in order for Dell OpenManage Client to work
X WIN32SNDS banc.exe Added by an unidentified WORM or TROJAN!
X Win32system [random filename] Added by the DDV.B WORM!
X Win32System win32s.exe Added by the MYDOOM.V WORM!
X Win32SystemMonitor ***.exe [* = random char] Browser hijacker
X win32us win32us.exe All-In-One-Telcom (adult content dialler) variant
X win32usbd ssrs.exe Added by the RBOT-RA WORM!
X win32_i lptt01 win32_i.exe Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
X win32_i ml097e win32_i.exe Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
X Win386 Win386.exe Added by the GOSUSUB VIRUS!
X Win386 sp32.dll Homepage hijacker. Not a dll but a regfile in disguise
X WIN3S2SNDS winabsmod.exe Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well"
X WIN3S2SNDS winiprtx.exe Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well"
X Win64 Compatibility Check load win64.drv CoolWebSearch parasite variant
X WinAC v4 klsuicbn.exe Added by the FORBOT-CS WORM!
X winactive WINACTIVE.EXE Active variant of LOP.com hijacker - see here
X WinActiveJ WinActiveJ.exe Added by the ROTARRAN VIRUS!
X Winad Client Winad.exe WinAd adware by eXact Advertising
X winadm winadm.exe Browser hijacker - redirecting to Search-World.net. Related to the SMALL.LR TROJAN!
X Winahlp.exe Winahlp.exe Added by a variant of the VAGRNOCKER TROJAN!
X winallap winallap.exe Added by the DELF.E TROJAN!
X winallapu winallapu.exe Added by the DELF.E TROJAN!
X Winamp winamp.hta Hijacker - re-directing to adult content sites. Note - this isn't the real Winamp
X Winamp winamp.exe Added by the AGOBOT-MC WORM! Note - this is NOT the Winamp Media Player (WinAmpa.exe)
X Winamp media player winapa.exe Added by an unidentified VIRUS, WORM or TROJAN!
U Winampa WINAMPa.exe Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs
X Winampa winampa.exe Added by the AGOBOT-GS WORM!
X Winampa Agent WINAMPA.EXE Added by the SPYBOT-BR WORM! Note - this is NOT the Winamp Media Player
U WinampAgent WINAMPa.exe Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs
X WinAmpAgent Msexploren.exe Added by the EB TROJAN! Note - this is not the popular WinAmp media player file
X WinAmpAgent Shch.exe Added by the EB TROJAN! Note - this is not the popular WinAmp media player file
X WinAmpAgent svchst.exe Added by the EB TROJAN! Note - this is not the popular WinAmp media player file
X WinAmpAgent Winagent.exe Added by the EB TROJAN! Note - this is not the popular WinAmp media player file
X WinApi winapix.exe Added by a variant of the TIBSER.A downloader TROJAN!
X Winapp winpup32.exe Produces popup ads to adult content sites
X WinApp32 msapp.exe Added by the RSBOT TROJAN!
X WinAuth winlogon.exe Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the valid winlogon.exe process
U WinBackup Scheduler Wbsched.exe LIUtilities WinBackup scheduler - backup software
U WinBar WinBar.exe "WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls"
X winbas12 winbas12.exe Adware, probably CoolWebSearch parasite related - recognized by Kaspersky antivirus as TrojanDownloader.Win32.VB.du
X Winbed winbed.exe Hijacker
X WinCheck WinCheck.exe Added by the PWS-CY TROJAN!
N WINCINEMAMGR WINCIN~1.EXE WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
N WinCinemaMgr WinCinemaMgr.exe WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
X WinCSRSS MSGRT32.EXE Added by the REWINDO-A TROJAN!
X wind.exe wind.exe Added by the MITGLIEDER.BD TROJAN!
X WIND0WS WIND0WS.exe Added by the SPYBOT.DQ WORM!
X WIND0WS mella.bat Added by the ALLEM WORM!
N WinDates windates.exe WinDates is a calendar, date organizer and event reminder program from Rockin' Software
X windbs winxtc.exe Added by the AGOBOT-WD WORM!
X Winde winde.exe Added by the DLUCA TROJAN!
X windef Win32sp.vbs Added by the ANPES WORM!
X windir winrun.exe Added by the WINBUR.B WORM!
X Windll Windll.exe Added by the TRYNOMA TROJAN!

Start Up Applications W Page 3
U WINDLL WSYS.EXE STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes, all passwords transacted even if they weren't keyed in, all web sites visited, every program launched including the path to that program, and more"
X windll windll32.exe Added by the ASTEF or RESPAN WORMS!
X Windll.exe Windll.exe Added by the STEALER TROJAN!
X Windll32 Windll32.exe Added by the MSNPWS TROJAN!
X windllsys32.exe windllsys32.exe Added by a variant of the MITGLIEDER.BY TROJAN!
X WinDNS windns32.exe Added by the GAOBOT.WX WORM!
X Windoes Kernel kernel32.exe Added by the KICKIN.A (or CYDOG.C) WORM!
X Window explore.exe Added by the GAOBOT.ADW WORM!
X Window Loader Dos32.exe Added by the GAOBOT.AO WORM!
X Window Monitor winmon32.exe Added by the SDBOT.RT WORM!
U Window Washer wwDisp.exe Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
X window.exe window.exe Added by the MITGLIEDER.H or MITGLIEDER.J TROJANS!
X window2 ssvchost.exe Added by the IRCBOT.H TROJAN!
U WindowBlinds wbload.exe WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins
X WindowEnhancer Winex.exe SCbar foistware variant
U WindowFX wfxload.exe Stardock WindowFX - "Allows you to add an unprecedented number of special effects to windows"
X Windows Kernel32.exe Added by the TENDOOLF WORM!
X Windows msdos98.exe Added by the PWSTEAL TROJAN!
X Windows Windows.exe Added by the KAZMOR, BOBBINS & ALADINZ.D TROJANS!
X Windows explorer.exe Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually
X windows [path to trojan] Added by the AIMWIN TROJAN!
X windows hkey.exe Added by the GAOBOT.AFW WORM!
X windows system copy.exe Added by the SALGA.A WORM!
X Windows (random character) diskcheck.exe Added by the SINGU.B TROJAN!
U Windows Accelerators setup.exe KeySpy keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove
X Windows AdControl WinAdCtl.exe Windupdates adware variant
X Windows AdService WinAdServ.exe Windupdates adware variant
X Windows AdStatus WinStat.exe Windupdates adware variant
X Windows AdTools WinAdTools.exe Windupdates adware variant
X Windows Anti-Virus Built 32 AntiVirus32.exe Added by the SDBOT-BG WORM!
X windows auto update penis32.exe Added by the BLASTER (or MSBLAST.A) WORM!
X Windows Auto Update winupdater.exe Added by the SDBOT.TF WORM!
X windows auto update msblast.exe Added by the BLASTER.B WORM!
X Windows Automatic Update wuamgrder.exe Added by a variant of the RBOT WORM!
X Windows Automatic Updates dvldr.exe Added by the RBOT.MF WORM!
X windows automation mslaugh.exe Added by the BLASTER.E WORM!
X Windows Automation msdspr.exe Added by the SOLAME.A WORM!
X Windows backup systemss.exe Added by a variant of the SPYBOT WORM!
X Windows Backup Configuration IEXPLORER.exe Added by the GAOBOT.AZ WORM!
X Windows Baþlangýç Dosyasý sistem.exe Added by the MUZK WORM!
X Windows Communicator wincomm.exe Added by the AGOBOT-BH WORM!
X Windows Compliant [random filename] Added by the RBOT-IR WORM!
X Windows Config SSYS.EXE Added by the SPYBOT-DA WORM!
X Windows Config Loader Wincfg32.exe Added by the SILVERFTP TROJAN!
X Windows Configuration wsys32.exe Added by the GAOBOT.FB WORM!
X Windows Control Control.exe Browser hijacker. NOTE - On Win9x systems it will overwrite the Windows file of the same name in the Windows directory, so therefore it will be necessary to extract a fresh copy of the file from the Windows setup cabs!
X Windows ControlAd WinCtlAd.exe Windupdates adware variant
X Windows Data Server autodisc.exe Added by the SPYBOT-CB WORM!
X Windows Database WinDat.exe Added by an unidentified WORM or TROJAN!
X Windows Dcom2 Fix mscom32.exe Added by the RBOT-QT WORM!
X Windows debug logging winlogg.exe Added by the RBOT-OY WORM!
X Windows debug logging winloggs.exe Added by the RBOT-QN WORM!
X Windows Debugger windbg.exe Added by an unidentified VIRUS, WORM or TROJAN!
X Windows DLL Loader RUNDLL16.EXE Added by the DOMWIS TROJAN!
X Windows DLL Loader defragfat32z.exe Added by the LINKBOT.A WORM!
X Windows DLL Loader rundll32.exe Added by the WHIPSER-B WORM! Note - rundll32.exe file is placed in the WindowsSystem folder, wheras the legitimate rundll32.exe is located in the C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP)
X Windows DLL Loader defragfat32pi.exe Added by the RBOT-QQ WORM!
X Windows DLL Loader defragfat39.exe Added by the POEBOT-C WORM!
X Windows DLL Loader defragfatz.exe Added by the LINKBOT.H WORM!
X Windows DNS Daemon windnsd.exe Added by the WOOTBOT.AS WORM!
X Windows Drive Compatibility System32Driver32.exe Added by the SUPOVA.Z WORM!
X Windows Driver Services msdrvs32.exe Added by the WOOTBOT.L WORM!
X Windows Explorer [filename].exe Added by the SDBOT TROJAN! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually
X Windows Explorer Lsas.exe Added by the GAOBOT.AO WORM! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually
X Windows Explorer olecom32.exe Added by an unidentified WORM or TROJAN!
X Windows Explorer EEXPLORER.EXE Added by a variant of the SPYBOT WORM!
X Windows Explorer Shell Winexec32.exe Added by the REDIST.B WORM!
X Windows Explorer Update Build 1142 EXPLORER32.EXE Added by the KaZaA based KWBOT or KWBOT.Y WORMS!
X Windows Explorer-3212 WINRE16.EXE Added by the HARDOC WORM!
N Windows Eyes ?? For blind people, gives a voice description of items on the screen. Windows application which gives you total control over what you hear, when you hear it, and how you hear it. Available via Start -> Programs
X Windows File Protection winprotect.exe Added by the AGOBOT.JB WORM!
X Windows Firewall Manager msfw.exe Added by the RBOT.WR WORM!
X Windows Fix integator.exe Added by the SDBOT.ZAB WORM!
X Windows FormatAd WinForm.exe Windupdates adware variant
X Windows Graphics Loaders wingraphics.exe Added by the SPYBOT.JG WORM!
U Windows Guardian thehel1iawgrd32.exe Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
U Windows Guardian Fawgrd32.exe Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
X Windows Help File winhelper32.exe Added by the SDBOT-QK TROJAN!
X Windows Help Manager svchost32.exe Added by the RBOT-OZ WORM!
X Windows Help Service winhelpsv.exe Added by the RBOT-LP WORM!
? Windows Help System Help.pif ??
X Windows Host Device hostsvc.exe Added by the ZOOTY-A WORM!
X Windows HTML file reader Sysconf32.exe Added by the NOOMY.A WORM!
X Windows Internet Protocol winproc32.exe CoolWebSearch parasite variant
X Windows JavaScript Daemon Winjsd.exe Added by the WOOTBOT.AF WORM!
? Windows Load windows.com ??
X Windows Loader wstart32.exe Added by the GAOBOT.CA WORM!
X Windows Loader Service civsc.exe Added by a variant of the RBOT WORM!
X Windows logging winlogd.exe Added by the RBOT-ON WORM!
X Windows Login explored.exe Added by the GAOBOT.SY WORM!
X Windows Logon winlogin.exe Added by the SPYBOT-C TROJAN!
X Windows Logon Procedure Svchoste.exe Added by a variant of the SPYBOT WORM!
X Windows Logon Procedure Svchosta.exe Added by a variant of the SPYBOT WORM!
X Windows Management Instrumentation mwd.exe Added by the GRAPS WORM!
X Windows Manager winmants.exe Added by the MANTAS WORM!
X Windows mangement winlogonn.exe Added by the RANDEX.FC WORM!
X Windows Media Player wmediaplayer.exe Added by the AGOBOT-NQ WORM!
X Windows Media Player MediaPIayer.exe Added by the SDBOT-QO TROJAN! - note, the executable is called 'MediapIayer', with an 'i' !)
X Windows Media Player [random filename] Added by a variant of the RBOT WORM!
X Windows Media Player msa.exe Added by the RBOT-SI WORM!
X Windows Media Player mcafe32.exe Added by a variant of the SDBOT WORM!
X Windows Media Player wmplayer.exe Added by the SPYBOT WORM! Note - this is not the valid Windows Media Player as the executeable resides is C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP) rather than C:Program FilesWindows Media Player
X Windows Media Player Update [random filename] Added by the RBOT-ET WORM!
N Windows Media Powerpoint Helper NSPPTHLP.EXE German software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start -> Programs
X Windows media service crvss.exe Added by the SDBOT.VP WORM!
X Windows media service crsss.exe Added by the RBOT.ACY WORM!
X Windows media services cvrsss.exe Added by the RBOT-MW WORM!
X Windows Media SP.2.37 [random filename] Added by the LEMIR.C TROJAN!
X Windows MeTaLRoCk service metalrock.exe Added by the TASTYRED TROJAN!
X Windows Monitor winmon.exe Added by the SDBOT.VB WORM!
X Windows Monitoring Service winmon.exe Added by a variant of the SDBOT WORM!
X Windows Nets WinNET.exe Added by the RBOT-MO WORM!
X Windows Network Controller Mqguard.exe Added by the FORBOT-CL WORM!
X Windows Network Controller WinxPupd.exe Added by the FORBOT-DK WORM!
X Windows Network Controller winmms32.exe Added by the FORBOT-ED WORM!
X Windows Network Service winvc32.exe Added by the RBOT.RY WORM!
X Windows Networking winsys32.exe Added by the GAOBOT.FL WORM!
X Windows Nivedia Driver sysMGT.exe Added by a variant of the RBOT WORM!
X Windows NNT [path to trojan] Added by the RANKY.E TROJAN!
X Windows NT 32 ntlogin32.exe Added by the RANDEX.BRD WORM!
X Windows NT Login ntlogin32.exe Added by the SDBOT.WG WORM!
X Windows NT Service Name winshock.exe Added by the RBOT-PK WORM!
X Windows NT Update Manager WINL0G0N.exe Added by the AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital "o"
X Windows OEM Tools winres32.exe Added by the SPYBOT.FD WORM!
X Windows OLE Automation Server ole32aut.vbe CoolWebSearch parasite related browser hijacker
X Windows Online Updater dllman.exe Added by the RBOT-TE WORM!
? Windows Print Spooler SCVHOSTS.EXE Suspicious due to the similarity to the valid "svchost.exe" file
X Windows Print Spooler NavAgent32.exe Added by an unidentified VIRUS, WORM or TROJAN!
X Windows Print Spooler SVEHOST.EXE Added by the SPYBOT.H WORM!
X Windows Registry msnmsg.exe Added by a variant of the RBOT WORM!
X Windows Registry Cleaner winclean.exe Added by a variant of the SPYBOT WORM!
X Windows Registry Express Loader regexpress.exe Added by the FORBOT-CJ WORM!
X Windows Registry Scan regscan32.exe Added by the RBOT.KE WORM!
X Windows Registry Scan timeupdate.exe Added by the SPYBOT.JE WORM!
X Windows Registry Security crss.exe Added by a variant of the IRC.BOT TROJAN!
X Windows Registry Startup wind32.exe Added by the AGOBOT-BZ WORM!
X Windows report swchost.exe Added by the SMALL-BD TROJAN!
X Windows Runtime Help win32hlp.exe Added by a variant of the AIMVISION TROJAN!
X Windows Runtime Help WinRunHelp.wrh Added by a variant of the AIMVISION TROJAN!
X Windows SA omniscient.exe BLAZEFIND adware
X Windows secure setver32.exe Added by the SPYBOT.EP WORM!
X Windows Secure Messaging System msnmsgrsrvc.exe Added by the RBOT-RE WORM!
X Windows Security Assistant rundll32.vbe CoolWebSearch parasite variant
X Windows Security Assistant winsec.exe CoolWebSearch parasite variant
X Windows Security Module module.exe Added by a variant of the RBOT WORM!
X Windows ServeAd WinServAd.exe Windupdates adware variant
X Windows service wuamgrd.exe Added by the RBOT-QW WORM!
X Windows Service dddd.exe Identified by Kaspersky Labs as PornWare.Dialer.Salc, also known to come with the Bube family trojans
X Windows Service prvdi.exe Malware, recognized by Kaspersky antivirus as Trojan-Dropper.Win32.Small.rd
X Windows Service Host scvhost.exe Added by the SDBOT.N TROJAN!
X Windows Service Host svchost.exe Added by the