| X | whagent | whagent.exe | System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here |
| U | WheelMouse | 4DMAIN.EXE | Mouse software for "Fellowes" Wheelman mouse. Has caused some users problems but shouldn't be needed if you don't use any enhanced features it may provide |
| U | WheelMouse | AMOUMAIN.EXE | A4Tech wireless mouse driver and utility - required if you use non-standard Windows driver features |
| X | WhenUSave | Save.exe | SaveNow adware |
| X | WhenUSearch | Search.exe | SaveNow adware |
| X | WhenUSearchWHSE | whse.exe | SaveNow adware |
| X | Whvlxd | Whvlxd.exe | Added by the W32.LXD.MIRC TROJAN! |
| N | WIAWizardMenu | RUNDLL32.EXE sti_ci.dll, WiaCreateWizardMenu | Still Image Class Installer - installed with a webcam |
| ? | WildTangent CDA | RUNDLL32.exe cdaEngine0400.dll,cdaEngineMain | Part of the WildTangent on-line games system. What does it do and is it required? |
| U | WildTangent Web Driver updater | wcmdmgrl.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| N | Wildwire Monitor | WWMon.exe | This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem |
| N | Willow Road | WillowRoad.exe | Willow Road Screen Saver |
| X | win | regedit -s ..win.dll | Added by the SEEKER.K TROJAN! |
| X | win | xwinxrpc32.exe | Added by the AGOBOT-MV WORM! |
| X | win | xwinxrpc.exe | Added by the AGOBOT-MV WORM! |
| U | Win Chimes | winchi~1.exe | WinChimes - enhancement software for the system clock that runs in the system tray |
| X | Win Comm | WinComm.exe | WebRebates related adware |
| X | Win Command | command32.exe | Added by the AGOBOT.XQ WORM! |
| X | Win Command | command32.exe | Added by the AGOBOT.XQ WORM! |
| X | WIN HOST PROCESS | WIN HOST PROCESS.EXE | Added by the KEYLOGGER.CLONE TROJAN! |
| X | Win l5oahder | winampa.exe | Added by the SPYBOTER.GEN VIRUS! Not the valid Winamp Agent which uses the same filename. This resides in the System32 sub-folder wheras real one is located in the winamp folder |
| ? | win name | stat.exe | ?? |
| X | Win Patch | ntldr.exe | Added by the SDBOT-GS WORM! |
| X | Win Server | winserv.exe | Added by the IMISERV.A TROJAN! |
| X | Win Server Updt | wupdt.exe | Added by the IMISERV.A TROJAN! |
| X | win update | wupda32.exe | Added by the SDBOT.J WORM! |
| X | WIN USB 2.0 | usbsystem.exe | Added by an unidentified WORM of TROJAN! |
| X | Win USB 2.0 USB Driver | HPPrint.exe | Added by the SPYBOT.DNB WORM! |
| X | WIN-BUGSFIX | WIN-BUGSFIX.EXE | Added by the LOVELETTER (I LOVE YOU) VIRUS! |
| X | win-xp | nvsc32.exe | Added by the BROPIA.N WORM! |
| X | win-xp | winis.exe | Added by the BROPIA.N WORM! |
| X | Win2Drv | [worm filename] | Added by the WINTOO WORM! |
| X | WIN32 | WIN32.EXE | Added by the RATEGA TROJAN! |
| X | win32 | Shakira_1997_Part_1_.Mpeg_.scr | Added by the MYLIFE.N WORM! |
| X | win32 | Setup_32.exe | Added by the EVILBOT.B TROJAN! |
| X | Win32 | Win32.exe | Added by the ISRAZ.A WORM! |
| X | win32 | winsrv32.exe | Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites |
| X | win32 | WinSetup.exe | Added by the EVILBOT.B TROJAN! |
| X | Win32 | system32.vbs | Added by the SWERUN VIRUS! |
| X | Win32 | Game.exe.vbs | Added by the SCAFENE WORM! |
| X | Win32 Configuration | videosd32.exe | Added by the SDBOT.TT WORM! |
| X | Win32 Configuration | dllhelp.exe | Added by the SDBOT.UL WORM! |
| X | WIN32 DDOSSER | dos.exe | Added by the KELVIR.F WORM! |
| X | Win32 Device Loader | Win32ldr.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Win32 DRK Driver | wdrk32.exe | Added by the WOOTBOT.CY WORM! |
| X | Win32 exe file | winstr32.exe | Added by a variant of the SPYBOT WORM! |
| X | Win32 Explorer | Explorer32.exe | StartPa-MN homepage hijacker |
| X | Win32 FRT Driver | msfr32.exe | Added by a variant of the FORBOT WORM! |
| X | Win32 Kernel core component | Kernel32.pif | Added by the MOKS VIRUS! |
| X | Win32 Ms Auto Updater | AutomsUPD.exe | Added by a variant of the RBOT WORM! |
| X | Win32 Network Driver | crss.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Win32 NVIDIA Driver | MSPMSPSU.EXE | Added by a variant of the WOOTBOT.Y WORM! |
| X | win32 regedit | msn32.exe | Added by an unidentified WORM or TROJAN! |
| X | Win32 Rundll Loader | Rundll32.exe | Added by the SDBOT.A TROJAN! Note: Rundll32.exe is a valid Windows application called "Run a DLL as an App" and stored in the C:Windows directory. The version created by this virus is saved in the C:WindowsSystem directory |
| X | Win32 Service | bazzi.exe | Added by the AHKER.E WORM! |
| X | Win32 Services1 | wuamngr1.exe | Added by the SDBOT-PV WORM! |
| X | Win32 Src Service | win32src.exe | Added by the RBOT-SX WORM! |
| X | Win32 SSL Driver | winssv.exe | Added by the FORBOT-BH WORM! |
| X | Win32 System Spool | spoolsvc.exe | Added by the SDBOT.UK WORM! |
| X | Win32 USB Driver | winxpinit.exe | Added by the SDBOT.AA TROJAN! |
| X | Win32 USB Driver | mvsecn.exe | Added by the FORBOT-BK WORM! |
| X | Win32 Usb Driver | svhosint32.exe | Added by the FORBOT-BE or FORBOT-J WORMS! |
| X | Win32 Usb Driver | usb32.exe | Added by the SDBOT-OV WORM! |
| X | Win32 USB2 Driver | win32usb.exe | Added by the SPYBOT.DHV WORM! |
| X | Win32 USB2 Driver | smsc.exe | Added by the SDBOT.FO WORM! |
| X | Win32 USB2 Driver | svchosting.exe | Added by the FORBOT.J or SDBOT.HU WORM! |
| X | Win32 USB2 Driver | sys32.exe | Added by the WOOTBOT.X WORM! |
| X | Win32 USB2 Driver | sys32snd.exe | Added by the FORBOT-AN WORM! |
| X | Win32 USB2 Driver | wind32.exe | Added by the FORBOT-AH WORM! |
| X | Win32 USB2 Driver | winupdate.exe | Added by the AGOBOT.YE WORM! |
| X | Win32 USB2 Driver | updatemgr.exe | Added by a variant of the FORBOT WORM! |
| X | Win32 USB2 Driver | winsnd32.exe | Added by a variant of the SDBOT WORM! |
| X | Win32 USB2.0 Driver | 386.exe | Added by the IRCBOT.D WORM! |
| X | Win32 USB2.0 Driver | rundll16.exe | Added by the WOOTBOT.H WORM! |
| X | Win32 USB2.0 Driver | w32usb2.exe | Added by the SPYBOT.DN WORM! |
| X | Win32 USB2.0 Driver | service.exe | Added by the SDBOT-QF WORM! |
| X | Win32 USB3 Driver | win32tool.exe | Added by a variant of the RBOT WORM! |
| X | Win32 Wmls Driver | winitr32.exe | Added by the WOOTBOT.B WORM! |
| X | win32.exe | win32.exe | Added by the STARTPAGE TROJAN! |
| X | Win32BaseServiceMOD | Wintask.exe | Added by the NAVIDAD WORM! |
| X | win32clf | win32clf.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Win32DLL | Win32DLL.vbs | Added by the LOVELETTER (I LOVE YOU) VIRUS! |
| X | Win32dll | Win32dll.exe | Added by the BANPAES TROJAN! |
| X | Win32G | Kernel32.com | Added by the ESTRELLA TROJAN! |
| X | Win32G | Scandisk.com | Added by the ESTRELLA TROJAN |
| X | win32gb | win32gb.exe | All-In-One-Telcom (adult content dialler) variant |
| X | win32info | win32info.exe | Adult content dialler |
| X | win32ini | systroy.exe | Added by the IRC.ALADINZ.C TROJAN! |
| X | Win32R | Server.com | Added by the ESTRELLA TROJAN! |
| Y | WIN32SL | Win32sl.exe | Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. The specific function of this is to load MIF's in order for Dell OpenManage Client to work |
| X | WIN32SNDS | banc.exe | Added by an unidentified WORM or TROJAN! |
| X | Win32system | [random filename] | Added by the DDV.B WORM! |
| X | Win32System | win32s.exe | Added by the MYDOOM.V WORM! |
| X | Win32SystemMonitor | ***.exe [* = random char] | Browser hijacker |
| X | win32us | win32us.exe | All-In-One-Telcom (adult content dialler) variant |
| X | win32usbd | ssrs.exe | Added by the RBOT-RA WORM! |
| X | win32_i lptt01 | win32_i.exe | Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | win32_i ml097e | win32_i.exe | Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | Win386 | Win386.exe | Added by the GOSUSUB VIRUS! |
| X | Win386 | sp32.dll | Homepage hijacker. Not a dll but a regfile in disguise |
| X | WIN3S2SNDS | winabsmod.exe | Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" |
| X | WIN3S2SNDS | winiprtx.exe | Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" |
| X | Win64 Compatibility Check | load win64.drv | CoolWebSearch parasite variant |
| X | WinAC v4 | klsuicbn.exe | Added by the FORBOT-CS WORM! |
| X | winactive | WINACTIVE.EXE | Active variant of LOP.com hijacker - see here |
| X | WinActiveJ | WinActiveJ.exe | Added by the ROTARRAN VIRUS! |
| X | Winad Client | Winad.exe | WinAd adware by eXact Advertising |
| X | winadm | winadm.exe | Browser hijacker - redirecting to Search-World.net. Related to the SMALL.LR TROJAN! |
| X | Winahlp.exe | Winahlp.exe | Added by a variant of the VAGRNOCKER TROJAN! |
| X | winallap | winallap.exe | Added by the DELF.E TROJAN! |
| X | winallapu | winallapu.exe | Added by the DELF.E TROJAN! |
| X | Winamp | winamp.hta | Hijacker - re-directing to adult content sites. Note - this isn't the real Winamp |
| X | Winamp | winamp.exe | Added by the AGOBOT-MC WORM! Note - this is NOT the Winamp Media Player (WinAmpa.exe) |
| X | Winamp media player | winapa.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| U | Winampa | WINAMPa.exe | Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs |
| X | Winampa | winampa.exe | Added by the AGOBOT-GS WORM! |
| X | Winampa Agent | WINAMPA.EXE | Added by the SPYBOT-BR WORM! Note - this is NOT the Winamp Media Player |
| U | WinampAgent | WINAMPa.exe | Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs |
| X | WinAmpAgent | Msexploren.exe | Added by the EB TROJAN! Note - this is not the popular WinAmp media player file |
| X | WinAmpAgent | Shch.exe | Added by the EB TROJAN! Note - this is not the popular WinAmp media player file |
| X | WinAmpAgent | svchst.exe | Added by the EB TROJAN! Note - this is not the popular WinAmp media player file |
| X | WinAmpAgent | Winagent.exe | Added by the EB TROJAN! Note - this is not the popular WinAmp media player file |
| X | WinApi | winapix.exe | Added by a variant of the TIBSER.A downloader TROJAN! |
| X | Winapp | winpup32.exe | Produces popup ads to adult content sites |
| X | WinApp32 | msapp.exe | Added by the RSBOT TROJAN! |
| X | WinAuth | winlogon.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the valid winlogon.exe process |
| U | WinBackup Scheduler | Wbsched.exe | LIUtilities WinBackup scheduler - backup software |
| U | WinBar | WinBar.exe | "WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls" |
| X | winbas12 | winbas12.exe | Adware, probably CoolWebSearch parasite related - recognized by Kaspersky antivirus as TrojanDownloader.Win32.VB.du |
| X | Winbed | winbed.exe | Hijacker |
| X | WinCheck | WinCheck.exe | Added by the PWS-CY TROJAN! |
| N | WINCINEMAMGR | WINCIN~1.EXE | WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
| N | WinCinemaMgr | WinCinemaMgr.exe | WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
| X | WinCSRSS | MSGRT32.EXE | Added by the REWINDO-A TROJAN! |
| X | wind.exe | wind.exe | Added by the MITGLIEDER.BD TROJAN! |
| X | WIND0WS | WIND0WS.exe | Added by the SPYBOT.DQ WORM! |
| X | WIND0WS | mella.bat | Added by the ALLEM WORM! |
| N | WinDates | windates.exe | WinDates is a calendar, date organizer and event reminder program from Rockin' Software |
| X | windbs | winxtc.exe | Added by the AGOBOT-WD WORM! |
| X | Winde | winde.exe | Added by the DLUCA TROJAN! |
| X | windef | Win32sp.vbs | Added by the ANPES WORM! |
| X | windir | winrun.exe | Added by the WINBUR.B WORM! |
| X | Windll | Windll.exe | Added by the TRYNOMA TROJAN! |