| X | WinRunners | WinDrivers.exe | Added by the DULOAD.C WORM! |
| X | Wins32 Online | cfgpwnz.exe | Added by the BROPIA.R WORM! |
| X | WinSec | winsec16.exe | Added by the AGOBOT.ZF WORM! |
| X | winsecure | winsecure.exe | Browser hijacker, redirecting to specificsearches.com |
| X | WinSecured32 | ssmr.exe | Added by a variant of the FORBOT WORM! |
| X | Winserv | Winserv.ila | Added by the NODMIN WORM! |
| X | winserver | Server.txt.vbs | Added by the DELTAD.A WORM! |
| U | WinService32 | ssmgr.exe | 007 Spy Software - "stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP" |
| X | WinServices | WinServices.exe | Added by the YAHA.K or YAHA.M WORMS! |
| X | winservn | winservn.exe | PurityScan/Clickspring adware |
| X | winservs | winservs.exe | PurityScan/Clickspring adware |
| X | WinSetBrowse | BasicUpdate.dll.vbs | Added by the BISCUIT.A WORM! |
| ? | Winshoe | wuadfdqr.exe | Probably an unidentified VIRUS! Adds itself to 3 registry "Run" keys and prevents Task Manager being displayed. This is not the Winshoe IRC Client as the visitor did not have it installed |
| X | winshost.exe | winshost.exe | Added by the TOOSO or TOOSO.B or TOOSO.C or TOOSO.D WORMS! |
| X | WinShowUpdate | copy C:WINDOWSwinshow.new C:WINDOWSwinshow.dll | Winshow parasiate related - from the "RunOnce" keys it replaces "winshow.dll" with a new version |
| X | WinSig | NetXP.exe | Added by the BANKER-FN TROJAN! |
| X | winsock | svch0st.exe | Added by the SAGE-A WORM! |
| X | winsock2 | netsvr.exe | Added by the AGOBOT.LY WORM! |
| X | Winsock2 driver | SDJOIJE.EXE | Added by the SPYBOT.DR TROJAN! |
| X | Winsock2 driver | MIRC32.exe | Added by the SPYBUZZ TROJAN! |
| X | Winsock2 driver | kgzgjkpcw.exe | Added by the SDBOT.T TROJAN! |
| X | Winsock2 driver | ZONEALARM.EXE | Added by the SDBOT.T TROJAN! Note - ZONEALARM.EXE is not the valid Zone Labs firewall program |
| X | Winsock2 driver | WINCFG.SCR | Added by a variant of the SPYBOT WORM! |
| X | Winsock2 driver | winupdate.exe | Added by the SPYBOT-BX WORM! |
| X | Winsock2 driver | SPOLSV.EXE | Added by the SPYBOT-CM WORM! |
| X | Winsock2 driver | Zonealarmupdate.exe | Added by a variant of the SPYBOT WORM! |
| X | Winsock2.dll | WINLODR.SCR | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Winsock32 driver | Testing.exe | Added by the SPYBOT.B WORM! |
| X | Winsock32 driver | lcd.exe | Added by the SPYBOT.B WORM! |
| X | Winsock32 driver | Sdjoije.exe | Added by the SPYBOT.B WORM! |
| X | Winsock32driver | win32server.scr | Added by the HACARMY TROJAN! |
| X | Winsock32driver | sp2XPupdate.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Winsock32driver | win32server.exe | Added by the BACKDOOR-AZV TROJAN! |
| X | Winsock32driver | ZoneAlarmPr0.exe | Added by the HACKARMY-B TROJAN! |
| X | Winsock32driver | ZoneLockup.exe | Added by the HACARMY.D TROJAN! |
| X | Winsock32driver | win32server.exe | Added by the HACARMY.F TROJAN! |
| X | Winsock32driver | winXPupdate.exe | Added by the HACKARMY.9728 TROJAN! |
| X | winsockdriver | tskmg.exe | Added by the SDBOT.GEN TROJAN or WARPIGS.C WORM! |
| X | winsockdriver | winsock2.2.exe | Added by a variant of the SPYBOT WORM! |
| X | winsockdriver | iexplor.exe | Added by the BLATIC.A WORM! |
| X | WinSocketComponent | nthost.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | WinSPF | windrv32.exe | Added by the MYDOOM.T WORM! |
| X | WinSPF | winspf32.exe | Added by the MYDOOM.S WORM! |
| X | Winspl | winsplx.exe | Added by a variant of the TROLL-A TROJAN! |
| X | Winspool | spoolsvr.exe | Added by a variant of the SDBOT WORM! |
| X | WinSrv | kn0x.exe | Added by the HOBBIT.F WORM! |
| X | WinSrv | SHIZZLE.EXE | Added by the HOBBIT.C WORM! |
| X | Winsrv | winsrv.exe | Added by the OPASERV.T WORM! |
| X | WinStart | WinStart.exe | From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge |
| X | WinStart | Wscript.exe WinStart.vbs | Added by the CIAN.C WORM! |
| X | WinStart | winstart32.exe | Added by the PUROL WORM! |
| X | WinStart | WinStart.pif | Added by the CONE.E WORM! |
| X | WinStart001 | WinStart001.exe | From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge |
| X | WinStart001.EXE | WinStart001.exe | From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge |
| X | Winsta~1 | winsta~1.exe | GoHip foistware |
| X | WinSth16 | WinSth16.exe | Added by the CAKE WORM! |
| X | winstro | RUN32DLL.exe | Added by the FTP_ANA TROJAN! |
| X | WinSvc16.exe | WinSvc16.exe | Added by the SDBOT.FQ TROJAN! |
| X | Winsvc32 | Winsvc32.exe | Homepage hijacker |
| U | Winsys | Winsys.exe | Win-Spy - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
| X | WINSYS | [path to trojan] | Added by the GOLDPLAY TROJAN! |
| X | WinSys32 | Winsys32.exe | Added by the CIGIVIP TROJAN or RECKUS WORM! |
| X | winsys32 Driver | winsys32.exe | Added by the LOONY-O TROJAN! |
| U | WinSysAppMon | WinSysRM.exe | Home & Family Content Filter related. See here |
| X | winsyslog lptt01
| winsyslog.exe | Variant of the RapidBlaster parasite (in a "Winsyslog" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | WinSysStartUpWKbLw | TaskSystemDll.Exe | Added by the BACKZAT.G WORM! |
| X | WinSyst32 | winsyst32.exe | Added by the MORB WORM! |
| X | WinSystem | winsystem.exe | Added by the WHITEBAIT WORM! |
| X | Winsystem | winsystem.exe | Added by the BANCOS.CR TROJAN! |
| X | winsystem.sys | smss.exe | Added by the SOBER.K WORM! Note - this is not the legitimate Smss.exe system file should normally NOT figure in Msconfig/Startup! |
| X | WINT | wcp****.exe [* = random char] | PurityScan/Clickspring adware |
| X | WINT | wcpcc.exe | PurityScan/Clickspring adware |
| X | WINT | wcpsvit.exe | PurityScan/Clickspring adware |
| X | WinTask | Wintask.exe | Added by the HIPO or LEMIR.F TROJANS! |
| X | WINTASK | taskgmr.exe | Added by the MYTOB.I WORM! |
| X | WinTask driver | wintask.exe | Added by the SMALL.ABD downloader TROJAN! |
| U | WinTasks Traybar | wintasks.exe | WinTasks - "Efficient Resource and Task Management is absolutely critical if you want to achieve the highest system performance levels possible. WinTasks 4 will not only help you achieve this task, but will actually make your system run faster and more smoothly than ever before" |
| X | wintasks.exe | wintasks.exe | Added by the EVAMAN WORM! |
| N | Wintercooler Pro | WINCOOL.EXE | Wintercooler Pro - utility that monitors CPU usage, RAM consumption and Internet connection speed |
| N | WinTidy | WinTidy.exe | Desktop icon manager from PC Magazine (Ziff-Davis) for Win95. Available via Start -> Programs |
| X | Wintime | Wintime.exe | Added by the HARNIG TROJAN! |
| N | Wintime Wtxpload | Wxpload.exe Wintime | Part of the software to support a Dexxa USB graphics tablet. From a visitor - "This gets started anyway when you plug in the USB connector for the graphics tablet, if it's not already running. It then starts an application which manages the tablet messages. Since I leave the tablet unplugged unless I need to use it, I don't need this running at startup. I suspect that this program monitors a number of windows messages, so that when it's loaded, my regular mouse slows down - it acts like it 'sticks' entering and leaving windows. Certainly my performance returned to what I expected when I removed this item using MSCONFIG" |
| X | WinTools | WToolsA.exe | Wintools adware |
| N | WinTOTAL Scheduler | guru.exe | WinTOTAL Real estate appraisal software related |
| X | WinTray | wintray.exe | Added by the LEGUARDIEN.B TROJAN! |
| X | winupated.exe | winupated.exe | Added by a variant of the SDBOT WORM! |
| X | winupd | RUNDLL32.EXE [random value].dll, _mainRD | Added by the MOTA.A WORM! |
| X | winupd.exe | winupd.exe | Added by the BEAGLE.M or BEAGLE.N WORMS! |
| X | WinUPD32 | explorer.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
| X | winupdat | winupdat.exe | Added by the CANBOT.A WORM! |
| X | WinUpdate | RBSKQQBO.EXE | Added by the VBSWG2B.A WORM! |
| X | WinUpdate | wmbem.exe | Added by the REVCUSS.B TROJAN! |
| X | WinUpdate Loader | msnnm.exe | Added by the REVCUSS.C TROJAN! |
| X | winupdate.exe | winupdate.exe | Added by the RADO TROJAN! |
| X | winupdate.reg | winupdate.exe | Added by the SPYBOT.EAS WORM! |
| X | winupdate2846 | vbsystem35.exe msvbrun.exe | Added by a variant of the MUTIN-C TROJAN! |
| U | WinUpdateProtection | csrss.exe | ICE Remote Spy monitoring software, "secretly monitors everything your spouse, kids or employees do on the Internet and emails the data to you." Note - this file is installed in a C:WindowsupdateUfpIrs7 folder |
| X | winupdate_ | [path to file] | Added by the CONDOR.A WORM! |
| X | winupdt | RUNDLL32.EXE [random.dll] | Added by the MABUT.A WORM! |
| X | winupdtl | winupdtl.exe | SecondThought adware variant |
| X | winur | winrun.exe | Added by the WINBUR.B WORM! |
| X | winusb.dll | winguard.exe | Added by the FORBOT-CN WORM! |
| X | Winux Piriax Service | PH32.EXE | Added by the RANDEX.G WORM! |
| X | winversion | winversion.exe | Browser hijacker, redirecting to specificsearches.com |
| U | WinVNC | WinVNC.exe | WinVNC is an application that allows you to remote control your PC from another PC somewhere on the internet |
| X | WinVNC | iexplorer.exe | Added by the EVIVINC VIRUS! |
| X | winwan lptt01 | winwan.exe | Variant of the RapidBlaster parasite (in a "Winwan" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | winwan ml097e | winwan.exe | Variant of the RapidBlaster parasite (in a "Winwan" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | winXP | 33.exe | Added by the ANPES WORM! |
| X | WinXP | plugin1.exe | Added by the Downloader-JW TROJAN! |
| X | WinXP fix | [path to file] | Added by the RANKY.P TROJAN! |
| X | winxpdll32.exe | winxpdll32.exe | Added by a variant of the SMALL downloader TROJAN! |
| X | WinXPHome | plugin2.exe | Added by the malicious INOR.T script! |
| U | WinXPLoad | Rundll32 LoadDll, LoadExe WinXPLoad.exe | Compaq hotkey related - required if you use the hotkeys |
| X | winzip | [path to trojan] | Added by the BANCOS.G or BANCOS.K TROJANS! |
| N | WinZip Quick Pick | WZQKPICK.EXE | Added with WinZip version 8.1. "The new WinZip Quick Pick taskbar tray icon gives you instant access to WinZip and your Zip files. Just left click the icon to open WinZip, or right click it to instantly reopen recently used Zip files, access your Favorite Zip Folders, open WinZip Help, or start WinZip itself.". You can right-click and close it - choosing to not re-load it at start-up |