| Name | Status | Filename | Description |
|---|
| Windows Manager | X | winsrv.exe | Added by a variant of the AGOBOT/GAOBOT WORM!
|
| wblogon | X | ubpr01.exe | Added by the Troj/Agent-HFI TROJAN! Note: Located in \%WINDIR%\System32\ |
| WinAVX | X | WinAvX.exe | Installed by WinAntiSpyware Note: Located in \%WINDIR%\System32\ |
| Windows Defender | X | windowsdefender.exe | Added by a variant of the RBOT family of IRC Backdoor trojan. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| WanMPSvc | Y | WanMPSvc.exe | An AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling AOL doesn’t help |
| WebKey | N | WebKey.exe | WebKey from JB Utilities. Utility to keep track of login data required when browsing the internet |
| Web Service | X | [random file,name].exe | Added by the ADMINCASH TROJAN! |
| Winsock32 driver | X | Testing.exe | Added by the SPYBOT.B VIRUS! |
| Windows shell | ? | win70.exe | ?? |
| winlgz2 | X | winlgz2.exe | Added by the TROJ/KILLFIL-Q TROJAN! |
| winrapid | X | winrapid.exe | Added by a variant of the WIN32.RBOT WORM!
|
| windows automation | X | mslaugh.exe | Added by the BLASTER.E VIRUS! |
| Wildwire Monitor | N | WWMon.exe | This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem |
| Windows32 | X | system.exe | Unknown malware. Note: located in \%WINDIR%\System\ Note: Use SDFix under supervision.. |
| WCPS | X | Wint**.exe (* =,random char) | PurityScan/Clickspring Adware |
| Windows System-Control Drivers | X | syscontrl.exe | Added by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ |
| Winini.dll | X | winini.vbs | Added by the Troj/Startp-M Trojan |
| WinHelp | X | realsched.exe | Added by a variant of the LOVGATE WORM! **Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name
|
| WINDOWS SYSTEM | X | dcomuser.exe | Added by the W32.Mytob.EO
WORM!
|
| Windows Services | X | w32edus.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\ Note: Use SDFix under supervision. |
| Wifi Loader! | X | wifiloader.exe | Identified as a variant the Backdoor.Win32.IRCBot.byu malware Note: Located in \%WINDIR%\ Note: Use SDFix under supervision. |
| Windows Live Servicer | X | usrserv.exe | Added by the Trojan.Crypt.XPACK.Gen Trojan |
| Windows Local Services | X | netsvc.exe | Added by the Troj/Dloader-NY
Trojan! |
| winsecure | X | winsecure.exe | Browser hijacker, redirecting to specificsearches.com |
| Windows TaskManager | X | tskmngr.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Windows TaskAd | X | Wintaskad.exe | WindUpdates WinTaskAd adware variant |
| winlogon | X | svchost.exe | Added by the W32/AHKHeap VIRUS! Note: Located in \%ROOT%\heap41a\ Note: Do not remove the legitimate file in \%WINDIR%\System32\ |
| WindowsRegKeys update | X | winsysi.exe | Added by a SDBOT.WE worm infection |
| Windows Logon Application | X | WinIogon.exe | Added by the "Cruel Intentionz" backdoor TROJAN! |
| Windows TCP/IP | X | wintcp.exe | Added by the W32/AGOBOT-ZH WORM! |
| WinPLOSION | U | WinPlosion.exe | WinPLOSION allows you to immediately view and select from all the windows running on your computer, just those of the active application, or to minimise all windows and display a clear desktop.
|
| Windows Service Manager | X | localsvc.exe | Added by the Troj/Dloader-NY
Trojan!
|
| Windows MeTaLRoCk service | X | metalrock.exe | Added by the TASTYRED VIRUS! |
| Windows System Restorer | X | SystemRestorer.exe | Added by the DULOAD.C VIRUS! |
| wincls | X | wincls.dll | Added by the W32/Akbot-AR WORM! Note: This worm is located in C:\%WINDIR%\System32\ (XP/WinNT/2K) spreads to other network computers, may also modify the HOSTS file. |
| Windows DLL Services | X | winsvc32.exe | Added by the W32/RBOT-ZF WORM! |
| Windows Login | X | login.exe | Detected as a variant of Win32/Bifrose by NOD32 |
| Windows Update | X | McAfee3.exe | Added by a variant of the IRCBOT Note: Located in Note: Located in \%Program Files%\Common Files\System\ Note: Use SDFix under supervision. |
| WinPatrol | U | WinPatrol.exe | WinPatrol - "Manage Startup programs, tasks, cookies; will sniff out Worms, Trojan horses, Cookies, Adware, Spyware, Klez, Assumption and other malicious programs" |
| WinRaR Service | X | WinrarCO.com | Added by an unidentified TROJAN! of the RCbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Filename can also be a random with 14 characters |
| Windows Services | X | smsc.exe | Added by a variant of the W32/SDBOT WORM!
|
| Windows Services Tower | X | svctowers.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Windows Spooler | X | spoolsv32.exe | Added by an unidentified WORM or TROJAN! |
| win32serv | X | devicer.exe ,or,,servicesetup.exe,,systemdevices.exe | Added by a variant of the Win32/Pushbot worm and IRC backdoor. Win32/Pushbot is a family of worms that spread using MSN Messenger. Note: Located in \%WINDIR%\System32\ |
| Windows Rescue System | X | winsto.exe | Added by a variant of the Trojan-Downloader.Win32.Agent.avf malware. Note: Located in %Temp%\ |
| winactive | X | WINACTIVE.EXE | Active variant of LOP.com hijacker - see here |
| Windows System32 | X | explorer.exe | Added by the W32/Opanki-V WORM! Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. DO NOT DELETE THE EXPLORER.EXE FILE UNLESS IT NOT FROM MICROSOFT |
| Windows DNS | X | windns.exe | Added by the W32/SDBOT-XU WORM!
|
| Windows System Manager | X | winsysmgr.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| WinSvc16.exe | X | WinSvc16.exe | Added by the BACKDOOR.SDBOT.FQ TROJAN! |
| wssys | U | wssys.exe | WebPI logs keystrokes and captures screenshots. If you didn't install this yourself remove it |
| Win32 USB2.0 Driver | X | w32usb2.exe | WORM_SPYBOT.DN
|
| WinAble | X | winable.exe | Added by a unknown variant of a Trojan/Backdoor TROJAN! Note: Located in \%Program Files%\WinAble\ |
| Win32BaseServiceMOD | X | Wintask.exe | Added by the NAVIDAD VIRUS! |
| win32 | X | winhost.exe | Added by the W32.BROPIA.J WORM! |