| U | WINDLL | WSYS.EXE | STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes, all passwords transacted even if they weren't keyed in, all web sites visited, every program launched including the path to that program, and more" |
| X | windll | windll32.exe | Added by the ASTEF or RESPAN WORMS! |
| X | Windll.exe | Windll.exe | Added by the STEALER TROJAN! |
| X | Windll32 | Windll32.exe | Added by the MSNPWS TROJAN! |
| X | windllsys32.exe | windllsys32.exe | Added by a variant of the MITGLIEDER.BY TROJAN! |
| X | WinDNS | windns32.exe | Added by the GAOBOT.WX WORM! |
| X | Windoes Kernel | kernel32.exe | Added by the KICKIN.A (or CYDOG.C) WORM! |
| X | Window | explore.exe | Added by the GAOBOT.ADW WORM! |
| X | Window Loader | Dos32.exe | Added by the GAOBOT.AO WORM! |
| X | Window Monitor | winmon32.exe | Added by the SDBOT.RT WORM! |
| U | Window Washer | wwDisp.exe | Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
| X | window.exe | window.exe | Added by the MITGLIEDER.H or MITGLIEDER.J TROJANS! |
| X | window2 | ssvchost.exe | Added by the IRCBOT.H TROJAN! |
| U | WindowBlinds | wbload.exe | WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins |
| X | WindowEnhancer | Winex.exe | SCbar foistware variant |
| U | WindowFX | wfxload.exe | Stardock WindowFX - "Allows you to add an unprecedented number of special effects to windows" |
| X | Windows | Kernel32.exe | Added by the TENDOOLF WORM! |
| X | Windows | msdos98.exe | Added by the PWSTEAL TROJAN! |
| X | Windows | Windows.exe | Added by the KAZMOR, BOBBINS & ALADINZ.D TROJANS! |
| X | Windows | explorer.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | windows | [path to trojan] | Added by the AIMWIN TROJAN! |
| X | windows | hkey.exe | Added by the GAOBOT.AFW WORM! |
| X | windows | system copy.exe | Added by the SALGA.A WORM! |
| X | Windows (random character) | diskcheck.exe | Added by the SINGU.B TROJAN! |
| U | Windows Accelerators | setup.exe | KeySpy keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove |
| X | Windows AdControl | WinAdCtl.exe | Windupdates adware variant |
| X | Windows AdService | WinAdServ.exe | Windupdates adware variant |
| X | Windows AdStatus | WinStat.exe | Windupdates adware variant |
| X | Windows AdTools | WinAdTools.exe | Windupdates adware variant |
| X | Windows Anti-Virus Built 32 | AntiVirus32.exe | Added by the SDBOT-BG WORM! |
| X | windows auto update | penis32.exe | Added by the BLASTER (or MSBLAST.A) WORM! |
| X | Windows Auto Update | winupdater.exe | Added by the SDBOT.TF WORM! |
| X | windows auto update | msblast.exe | Added by the BLASTER.B WORM! |
| X | Windows Automatic Update | wuamgrder.exe | Added by a variant of the RBOT WORM! |
| X | Windows Automatic Updates | dvldr.exe | Added by the RBOT.MF WORM! |
| X | windows automation | mslaugh.exe | Added by the BLASTER.E WORM! |
| X | Windows Automation | msdspr.exe | Added by the SOLAME.A WORM! |
| X | Windows backup | systemss.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows Backup Configuration | IEXPLORER.exe | Added by the GAOBOT.AZ WORM! |
| X | Windows Başlangıç Dosyası | sistem.exe | Added by the MUZK WORM! |
| X | Windows Communicator | wincomm.exe | Added by the AGOBOT-BH WORM! |
| X | Windows Compliant | [random filename] | Added by the RBOT-IR WORM! |
| X | Windows Config | SSYS.EXE | Added by the SPYBOT-DA WORM! |
| X | Windows Config Loader | Wincfg32.exe | Added by the SILVERFTP TROJAN! |
| X | Windows Configuration | wsys32.exe | Added by the GAOBOT.FB WORM! |
| X | Windows Control | Control.exe | Browser hijacker. NOTE - On Win9x systems it will overwrite the Windows file of the same name in the Windows directory, so therefore it will be necessary to extract a fresh copy of the file from the Windows setup cabs! |
| X | Windows ControlAd | WinCtlAd.exe | Windupdates adware variant |
| X | Windows Data Server | autodisc.exe | Added by the SPYBOT-CB WORM! |
| X | Windows Database | WinDat.exe | Added by an unidentified WORM or TROJAN! |
| X | Windows Dcom2 Fix | mscom32.exe | Added by the RBOT-QT WORM! |
| X | Windows debug logging | winlogg.exe | Added by the RBOT-OY WORM! |
| X | Windows debug logging | winloggs.exe | Added by the RBOT-QN WORM! |
| X | Windows Debugger | windbg.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Windows DLL Loader | RUNDLL16.EXE | Added by the DOMWIS TROJAN! |
| X | Windows DLL Loader | defragfat32z.exe | Added by the LINKBOT.A WORM! |
| X | Windows DLL Loader | rundll32.exe | Added by the WHIPSER-B WORM! Note - rundll32.exe file is placed in the WindowsSystem folder, wheras the legitimate rundll32.exe is located in the C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP) |
| X | Windows DLL Loader | defragfat32pi.exe | Added by the RBOT-QQ WORM! |
| X | Windows DLL Loader | defragfat39.exe | Added by the POEBOT-C WORM! |
| X | Windows DLL Loader | defragfatz.exe | Added by the LINKBOT.H WORM! |
| X | Windows DNS Daemon | windnsd.exe | Added by the WOOTBOT.AS WORM! |
| X | Windows Drive Compatibility | System32Driver32.exe | Added by the SUPOVA.Z WORM! |
| X | Windows Driver Services | msdrvs32.exe | Added by the WOOTBOT.L WORM! |
| X | Windows Explorer | [filename].exe | Added by the SDBOT TROJAN! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | Windows Explorer | Lsas.exe | Added by the GAOBOT.AO WORM! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | Windows Explorer | olecom32.exe | Added by an unidentified WORM or TROJAN! |
| X | Windows Explorer | EEXPLORER.EXE | Added by a variant of the SPYBOT WORM! |
| X | Windows Explorer Shell | Winexec32.exe | Added by the REDIST.B WORM! |
| X | Windows Explorer Update Build 1142 | EXPLORER32.EXE | Added by the KaZaA based KWBOT or KWBOT.Y WORMS! |
| X | Windows Explorer-3212 | WINRE16.EXE | Added by the HARDOC WORM! |
| N | Windows Eyes | ?? | For blind people, gives a voice description of items on the screen. Windows application which gives you total control over what you hear, when you hear it, and how you hear it. Available via Start -> Programs |
| X | Windows File Protection | winprotect.exe | Added by the AGOBOT.JB WORM! |
| X | Windows Firewall Manager | msfw.exe | Added by the RBOT.WR WORM! |
| X | Windows Fix | integator.exe | Added by the SDBOT.ZAB WORM! |
| X | Windows FormatAd | WinForm.exe | Windupdates adware variant |
| X | Windows Graphics Loaders | wingraphics.exe | Added by the SPYBOT.JG WORM! |
| U | Windows Guardian | thehel1iawgrd32.exe | Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes |
| U | Windows Guardian | Fawgrd32.exe | Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes |
| X | Windows Help File | winhelper32.exe | Added by the SDBOT-QK TROJAN! |
| X | Windows Help Manager | svchost32.exe | Added by the RBOT-OZ WORM! |
| X | Windows Help Service | winhelpsv.exe | Added by the RBOT-LP WORM! |
| ? | Windows Help System | Help.pif | ?? |
| X | Windows Host Device | hostsvc.exe | Added by the ZOOTY-A WORM! |
| X | Windows HTML file reader | Sysconf32.exe | Added by the NOOMY.A WORM! |
| X | Windows Internet Protocol | winproc32.exe | CoolWebSearch parasite variant |
| X | Windows JavaScript Daemon | Winjsd.exe | Added by the WOOTBOT.AF WORM! |
| ? | Windows Load | windows.com | ?? |
| X | Windows Loader | wstart32.exe | Added by the GAOBOT.CA WORM! |
| X | Windows Loader Service | civsc.exe | Added by a variant of the RBOT WORM! |
| X | Windows logging | winlogd.exe | Added by the RBOT-ON WORM! |
| X | Windows Login | explored.exe | Added by the GAOBOT.SY WORM! |
| X | Windows Logon | winlogin.exe | Added by the SPYBOT-C TROJAN! |
| X | Windows Logon Procedure | Svchoste.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows Logon Procedure | Svchosta.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows Management Instrumentation | mwd.exe | Added by the GRAPS WORM! |
| X | Windows Manager | winmants.exe | Added by the MANTAS WORM! |
| X | Windows mangement | winlogonn.exe | Added by the RANDEX.FC WORM! |
| X | Windows Media Player | wmediaplayer.exe | Added by the AGOBOT-NQ WORM! |
| X | Windows Media Player | MediaPIayer.exe | Added by the SDBOT-QO TROJAN! - note, the executable is called 'MediapIayer', with an 'i' !) |
| X | Windows Media Player | [random filename] | Added by a variant of the RBOT WORM! |
| X | Windows Media Player | msa.exe | Added by the RBOT-SI WORM! |
| X | Windows Media Player | mcafe32.exe | Added by a variant of the SDBOT WORM! |
| X | Windows Media Player | wmplayer.exe | Added by the SPYBOT WORM! Note - this is not the valid Windows Media Player as the executeable resides is C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP) rather than C:Program FilesWindows Media Player |
| X | Windows Media Player Update | [random filename] | Added by the RBOT-ET WORM! |
| N | Windows Media Powerpoint Helper | NSPPTHLP.EXE | German software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start -> Programs |
| X | Windows media service | crvss.exe | Added by the SDBOT.VP WORM! |
| X | Windows media service | crsss.exe | Added by the RBOT.ACY WORM! |
| X | Windows media services | cvrsss.exe | Added by the RBOT-MW WORM! |
| X | Windows Media SP.2.37 | [random filename] | Added by the LEMIR.C TROJAN! |
| X | Windows MeTaLRoCk service | metalrock.exe | Added by the TASTYRED TROJAN! |
| X | Windows Monitor | winmon.exe | Added by the SDBOT.VB WORM! |
| X | Windows Monitoring Service | winmon.exe | Added by a variant of the SDBOT WORM! |
| X | Windows Nets | WinNET.exe | Added by the RBOT-MO WORM! |
| X | Windows Network Controller | Mqguard.exe | Added by the FORBOT-CL WORM! |
| X | Windows Network Controller | WinxPupd.exe | Added by the FORBOT-DK WORM! |
| X | Windows Network Controller | winmms32.exe | Added by the FORBOT-ED WORM! |
| X | Windows Network Service | winvc32.exe | Added by the RBOT.RY WORM! |
| X | Windows Networking | winsys32.exe | Added by the GAOBOT.FL WORM! |
| X | Windows Nivedia Driver | sysMGT.exe | Added by a variant of the RBOT WORM! |
| X | Windows NNT | [path to trojan] | Added by the RANKY.E TROJAN! |
| X | Windows NT 32 | ntlogin32.exe | Added by the RANDEX.BRD WORM! |
| X | Windows NT Login | ntlogin32.exe | Added by the SDBOT.WG WORM! |
| X | Windows NT Service Name | winshock.exe | Added by the RBOT-PK WORM! |
| X | Windows NT Update Manager | WINL0G0N.exe | Added by the AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital "o" |
| X | Windows OEM Tools | winres32.exe | Added by the SPYBOT.FD WORM! |
| X | Windows OLE Automation Server | ole32aut.vbe | CoolWebSearch parasite related browser hijacker |
| X | Windows Online Updater | dllman.exe | Added by the RBOT-TE WORM! |
| ? | Windows Print Spooler | SCVHOSTS.EXE | Suspicious due to the similarity to the valid "svchost.exe" file |
| X | Windows Print Spooler | NavAgent32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Windows Print Spooler | SVEHOST.EXE | Added by the SPYBOT.H WORM! |
| X | Windows Registry | msnmsg.exe | Added by a variant of the RBOT WORM! |
| X | Windows Registry Cleaner | winclean.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows Registry Express Loader | regexpress.exe | Added by the FORBOT-CJ WORM! |
| X | Windows Registry Scan | regscan32.exe | Added by the RBOT.KE WORM! |
| X | Windows Registry Scan | timeupdate.exe | Added by the SPYBOT.JE WORM! |
| X | Windows Registry Security | crss.exe | Added by a variant of the IRC.BOT TROJAN! |
| X | Windows Registry Startup | wind32.exe | Added by the AGOBOT-BZ WORM! |
| X | Windows report | swchost.exe | Added by the SMALL-BD TROJAN! |
| X | Windows Runtime Help | win32hlp.exe | Added by a variant of the AIMVISION TROJAN! |
| X | Windows Runtime Help | WinRunHelp.wrh | Added by a variant of the AIMVISION TROJAN! |
| X | Windows SA | omniscient.exe | BLAZEFIND adware |
| X | Windows secure | setver32.exe | Added by the SPYBOT.EP WORM! |
| X | Windows Secure Messaging System | msnmsgrsrvc.exe | Added by the RBOT-RE WORM! |
| X | Windows Security Assistant | rundll32.vbe | CoolWebSearch parasite variant |
| X | Windows Security Assistant | winsec.exe | CoolWebSearch parasite variant |
| X | Windows Security Module | module.exe | Added by a variant of the RBOT WORM! |
| X | Windows ServeAd | WinServAd.exe | Windupdates adware variant |
| X | Windows service | wuamgrd.exe | Added by the RBOT-QW WORM! |
| X | Windows Service | dddd.exe | Identified by Kaspersky Labs as PornWare.Dialer.Salc, also known to come with the Bube family trojans |
| X | Windows Service | prvdi.exe | Malware, recognized by Kaspersky antivirus as Trojan-Dropper.Win32.Small.rd |
| X | Windows Service Host | scvhost.exe | Added by the SDBOT.N TROJAN! |
| X | Windows Service Host | svchost.exe | Added by the CONE.B WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | Windows Service Pack Auto Update | winworks.exe | Adware downloader, identified by eScan antivirus as Trojan-Clicker.Agent.bt |
| X | Windows Services | service.exe | Added by the RANDEX.R WORM! |
| X | Windows Services | svchosts.exe | Added by the AGOBOT-KL TROJAN! |
| X | Windows Services Host | svchost.exe | Added by the CONE or CONE.E WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | Windows Services Update | svch0st.exe | Added by a variant of the RBOT WORM! |
| ? | Windows shell | win70.exe | ?? |
| X | Windows Shell Library Loader | load shell.dll /c /set | CoolWebSearch parasite variant |
| X | windows shellext.32 | mschost.exe | Added by the BLASTER.K WORM! |
| X | Windows Smart Manager | smart.exe | Added by the RBOT-SL WORM! |
| X | Windows Sound Driver | SndMon32.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows Sound Manager | SndMon32.exe | Added by the FORBOT-BU WORM! |
| X | Windows SP2 Update | Sp2update.exe | Added by the WOOTBOT.BS WORM! |
| X | Windows Spooler | SPOOLSRV.EXE | Added by the SPYBOT.P WORM! |
| X | Windows SSL File | winssv.exe | Added by the WOOTBOT.CA WORM! |
| X | Windows Startup | winsta~1.exe | GoHip foistware |
| X | Windows Startup | winstartup.exe | GoHip foistware |
| X | Windows Startup | Wdrun32.exe | Added by the GAOBOT.AO WORM! |
| X | Windows Startup | services21.exe | Added by the AGOBOT-MX WORM! |
| X | Windows Startup 32 Bits | sysrun32.exe | Added by a variant of the DARKSUN TROJAN! |
| X | Windows Streams Server | localsrv.exe | Added by the SDBOT.LN WORM! |
| X | Windows SyncroAd | SyncroAd.exe | Windupdates adware variant |
| X | Windows System Configuration | SYSCFG16.EXE | Added by the WISDOOR.Z TROJAN! |