| X | Windows System File | cmxp.exe | Added by the SPYBOT.KHO WORM! |
| X | Windows System Manager | winsystem.exe | Added by the RBOT-AN WORM! |
| X | Windows System Manager Proc | winsmc.exe | Added by the RBOT.JH WORM! |
| X | Windows System Restore Configuration | Sblhost.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows System Restorer | SystemRestorer.exe | Added by the DULOAD.C WORM! |
| X | Windows System Security | winmp.exe | Added by the RBOT.IV WORM! |
| X | Windows System Serivce | winserv.exe | Added by a variant of the RBOT WORM! |
| X | windows system service | winsock.exe | Added by the RBOT-MR WORM! |
| U | Windows System Tray | msni.exe | Iambigbrother monitoring software |
| X | Windows System Tray | swhost.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Windows Task Manager | ACCOUNT_DETAILS.DOC.exe | Added by the QUATERS.A WORM! |
| X | Windows Task Manager | taskmgn.exe | Unidentified malware, either a variant of the WIN32.RBOT WORM, or part of a Casino Palazzo foistware install |
| X | Windows Task Manager Emulator | kennewr.exe | Added by the SPYBOT-FA WORM! |
| X | Windows TaskAd | Wintaskad.exe | Windupdates adware variant |
| X | Windows Taskbar Manager | internat.exe | Added by the PROTORIDE-H WORM! |
| X | Windows Taskbar Manager | [path to file] | Added by the PROTORIDE.B WORM! |
| X | Windows Taskbar System | tasksys.exe | Added by a variant of the SDBOT WORM! |
| X | Windows Taskmanager | lsassx.exe | Added by the KELVIR.E WORM! |
| X | Windows TCP/IP | wintcp.exe | Added by the AGOBOT-ZH WORM! |
| X | Windows Telnet Server | wintel.exe | Added by the AGOBOT-MW WORM! |
| X | Windows Time Server | TimeSRV.exe | Added by the SPYBOT.DNC WORM! |
| X | Windows Upate | rundll.exe | Added by the HAKO TROJAN! Note - this is NOT the Windows system file of the same name as described here |
| X | Windows Update | [filename] | Added by the NORIO TROJAN! Acts as a hi-jacker redirecting to adult content sites |
| X | Windows Update | iexplorere.exe | Added by the GAOBOT.AP WORM! |
| X | windows update | uddater.exe | Added by the LEOX TROJAN! |
| X | Windows Update | wudate.exe | Added by the AGOBOT.ML WORM! |
| X | Windows Update | wupdate.exe | Wengs adware |
| X | windows update | sychost.exe | Added by the LEOX.B WORM! |
| X | Windows Update | Wuamgrd.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows Update | inetinf.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Windows Update | host32.exe | Added by the RBOT-GU WORM! |
| X | windows update | wuraclt.exe | Added by the RBOT-PO WORM! |
| X | windows update | Wuanclt.exe | Added by the RBOT.XZ WORM! |
| X | Windows Update | ebay.exe | Added by the GAOBOT.BUU WORM! |
| X | Windows Update | windows.exe | Added by the RBOT-RB WORM! |
| X | windows update | wuaurlt.exe | Added by the RBOT.ADG WORM! |
| X | Windows Update | Update.exe | Added by the DELF-FN TROJAN! |
| X | Windows Update | winmguard.exe | Added by the RBOT-EM WORM! |
| X | Windows Update | wuampd.exe | Added by the RBOT.UM WORM! |
| X | windows update | wuarclt.exe | Added by the RBOT-OF WORM! |
| X | Windows Update AutoUpdate Client Product | wuauct.exe | Added by the AGOBOT.ACL WORM! |
| X | Windows Update Checker | [random filename] | Adware downloader trojan |
| X | Windows Update Client | wuclient.exe | Added by the SMALL-RN TROJAN! |
| X | Windows Update Client Service | windrvl32.exe | Added by the AGOBOT-MM TROJAN! |
| X | Windows update config | svhost.exe | Added by the SDBOT-PF WORM! |
| X | windows update configurator | svghost.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows Update Files | dnetc.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - wupdmgr.exe is the real Windows Update |
| X | Windows Update Manager | wupdmngr.exe | Added by the RANDEX.BTB WORM! |
| X | Windows Update Manager | Winlog0n.exe | Added by the AGENT-BO TROJAN! |
| X | Windows Update Manager for NT | wupdmgr32.exe | Added by the SDBOT.AH WORM! |
| X | Windows Update Monitoring Service | winupdt.exe | Added by the RBOT-PL WORM! |
| X | Windows Update Process | wmiprvsc.exe | Added by the SDBOT-CB WORM! |
| X | Windows Update Service | csrs.exe | Added by the AGOBOT-NI WORM! |
| X | Windows Update Service | smcg.exe | Added by the SDBOT.QY WORM! |
| X | Windows Update Service 2004/2005 | systemupdate.exe | Added by the RBOT-JE WORM! |
| X | Windows Update V6 | [random filename] | Added by the RBOT-KT WORM! |
| X | Windows Update.exe | N/A | Homepage hijacker, see here |
| X | Windows Updater | wupdmgr32.exe | Added by a variant of the DOS.AUTOCAT TROJAN! |
| N | Windows Version Check | ver_chk.exe | Version checker for CyberAudioLibrary ("A new way to exchange information through the Internet") |
| X | Windows video | vide_32.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Windows Video Acquisition (WVA) | wvsvc.exe | Added by the AGOBOT.YM WORM! |
| X | Windows Video Drivers | videons32.exe | Added by the GAOBOT.AZT WORM! |
| X | Windows-System | System32.exe | Added by the LOGPOLE.C WORM! |
| X | Windows-TCP-IP | rfkampig.exe | Added by the GIPMA TROJAN! |
| X | Windows32 | rundll.exe | Added by the AGOBOT-LK or AGOBOT-ND WORMS! |
| X | Windows32 Messenger Service | msmsgv.exe | Added by the RBOT.ANS WORM! |
| X | WindowsAgent | WindowsAgent.exe | Added by the GOP.G WORM! |
| X | WindowsAPI.DLL | Server5.exe | Added by the "Fear and Hope" TROJAN! |
| X | WindowsBackup | WINDOWSBACKUP.EXE | Added by the STANG WORM! |
| X | WindowsCriticalUpdate | windows_critical_update.exe | Added by the ASTEF or RESPAN WORMS! |
| X | WindowsKeyUpdate | master.exe | Added by the JOSAM WORM! |
| X | WindowsMGM | Winmgm32.exe | Added by the SOBIG WORM and LALA.C TROJAN! |
| X | WindowsReg% update | [random filename].exe | Added by the RBOT-HH WORM! |
| X | WindowsRegistration | [random filename] | Added by the RBOT-NO WORM! |
| X | WindowsRegKey Autoupdate | [random filename] | Added by a variant of the RBOT WORM! |
| X | WindowsRegKey upd4te2d4te | *********.exe [* = random char] | Added by the RBOT.XQ WORM! |
| X | WindowsRegKey update | [random filename] | Added by a variant of the RBOT WORM! |
| X | WindowsRegKey update | winupdate.exe | Added by the RBOT-QJ WORM! |
| X | WindowsRegKey update | windns.exe | Added by the RBOT.IE WORM! |
| X | WindowsRegKey%$ update | msi332.exe | Added by the RBOT-IX WORM! |
| X | WindowsRegKey%update | ethernet32m.exe | Added by the RBOT-EN WORM! |
| X | WindowsRegKeys update | winsysi.exe | Added by the SDBOT.WE WORM! |
| X | WindowsSetup | [path to trojan] | Added by the EZBOT TROJAN! |
| X | WindowsUpd | WindowsUpd4.exe | VirtuMonde adware |
| X | WindowsUpd1 | WindowsUpd1.exe | VirtuMonde adware |
| X | WindowsUpd2 | WindowsUpd2.exe | VirtuMonde adware |
| X | WindowsUpdate | windows_update.exe | Added by the LOFNI WORM! |
| X | WindowsUpdate | svchost.exe | Added by the ASTEF or RESPAN WORMS or AGENT-V TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | windowsupdate | RPCX1sQ3.exe | Added by the IRCBOT.B TROJAN! |
| X | WindowsUpdate | USRINIT.EXE | Added by the MADDIS.B WORM! |
| X | WindowsUpdate Service | wuautlc.exe | Added by the RBOT-NR WORM! |
| X | WindowsXP Module | DirectX3D.exe | Malware, reportedly a keylogger - see here |
| X | WindowsXP Update | windowsxpupdate.exe | Added by the RBOT-PB WORM! |
| X | WindowsXPserv | svcnxp32.exe | Addee by the NANINF-A TROJAN! |
| X | Windows_Serivce | SERVICE.exe | Added by the WOOTBOT.AH WORM! |
| X | Windows_Updates | svthost.exe | Added by a variant of the SPYBOT WORM! |
| X | Windows_VXD | user32.exe | Added by the PWSTEAL.PPORT TROJAN! |
| X | Windowz Update V2.0 | Explorer.exe | Added by the YODO WORM! Note - the valid "explorer.exe" is located in C:Windows or C:Winnt whereas this one is located in the System32 sub-directory |
| X | WinDriv32 | WinDriv32.exe | Added by the SMALL-BA TROJAN! |
| X | WinDriver Configuration | windrvconf.exe | Added by the AGOBOT-LX TROJAN! |
| X | windrv | windrv32.exe | Added by an unidentified VIRUS, WORM or TROJAN! - possibly a strain of OBLIVION or BIONET |
| X | WinDrv | windrvx.exe | Added by a variant of the TIBSER.A downloader TROJAN! |
| U | WinDSL MTU-Adjust | WinDSL_MTU.exe | Adjusts the registry setting of the DUN-Adapters (MTU) and the TCP/IP-Protocol (RWIN) by ENGEL Technologieberatung |
| ? | WinDSL_MTU | WinDSL_MTU.exe | May be realted to Tiscali broadband, if so is it required? |
| X | WinDSNX | Win????.exe | Added by the DNSX TROJAN! |
| X | WindUpdates | [path to trojan] | Added by the AGENT.BF TROJAN! |
| X | WindUpdates | WinUpdt.exe | Windupdates adware variant |
| U | WINDVDpatch | CTHELPER.EXE | CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative’s sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a "leave alone" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it |
| N | WinDVR SchSvr | SchSvr.exe | WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs |
| N | WinDVRCtrl | WinDVRCtrl.exe | Control center software for an AOpen VA1000 TV tuner card |
| X | Windws Configuration Loader | LEXPLORE.exe | Added by the SODABOT WORM! |
| X | WinEssential | Keyhost.exe | Hijacker - hailing from jraun.com |
| X | WinEssential | keyword.exe | Jraun.com hijacker |
| X | WinExec | Winexec.exe.vbs | Added by the AINESEY.A WORM! |
| X | WinExec32 | WinExec32.exe | Added by the KAZWIN WORM! |
| U | WinFast Schedule | Wfwiz.exe | Leadtek WinFast TV tuner scheduler |
| U | Winfast2KLoadDefault | Rundll32.exe Wf2kcpl.dll, DllLoadDefaultSettings | Loads default settings for Leadtek Winfast graphics cards |
| U | Winfast_2K | WF2k.exe | System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card |
| U | WinFast_Gamma | Rundll32.exe wfcpl.dll, DllLoadGammaRampSettings | Loads if you change the gamma settings on Leadtek WinFast graphics cards |
| U | WinFast_Taskbar | rundll32.exe wftask.dll, WFDllLoadDefaultSettings | Loads default settings for Leadtek WinFast graphics cards |
| X | WinFavorites | WinFavorites.exe1 | Loudmarketing.com adware downloader |
| N | WinFax PRO Controller | WFXCTL32.EXE | From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs |
| Y | WinFaxAppPortStarter | wfxsnt40.exe | WinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application. |
| X | winfont | winfont.exe | Added by the DEATH TROJAN! |
| U | WinFoxV2 | WF2k.exe | System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card |
| X | WinFX | cssrs.exe | Added by the AGOBOT.FX WORM! |