| Name | Status | Filename | Description |
|---|
| WinNtBB | X | WinntBB.exe | Added by the DULOAD.C VIRUS! |
| Windows Boot | X | winboot.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Windows Tracking Client | X | ctwsvc.exe | Added by the Troj/Agent-GMB Trojan. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Win32 Secure | X | msconfigsvc.exe | Added by a variant of the W32/SDBOT WORM!
|
| WTIndicator | U | SchedInd.exe | WinTask - software that automates a variety of routine tasks quickly and simply |
| WinTimer | X | msupdate.cmd | Hijacker, detected by Kaspersky antivirus as Trojan.Win32.StartPage.tj
|
| winxpdll32.exe | X | winxpdll32.exe | Added by a variant of the Win32.SMALL downloader TROJAN! |
| WUSB54Gv4 | Y | WUSB54Gv4.exe | Wireless-G USB Wireless Network Adapter related - would appear to be required |
| Windows Services | X | scmsg.exe | Added by a variant of the SDBOT WORM!
|
| Windows SyncroAd | X | SyncroAd.exe | Windupdates adware variant |
| Windows Update Manager | X | Winlog0n.exe | Added by the TROJ/AGENT-BO TROJAN! |
| WINDOWS SYSTEM | X | expI0rer.exe | Added by the W32/Mytob-FI WORM! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. Also, please note the spelling of this file as it is different from the Windows system file explorer.exe. |
| winupdate.exe | X | winupdate.exe | Added by the RADO VIRUS! |
| Win32BaseServiceMOD | X | Wintask.exe | Added by the NAVIDAD VIRUS! |
| word pair | X | bopotsvr.exe | Added by the TROJ/SHED-A TROJAN! |
| Windows Logon Service | X | winlogon.pif | Added by the W32/Rbot-AOU
WORM!
Note: This worm\trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
|
| Web Service | X | [random file,name].exe | Added by the ADMINCASH TROJAN! |
| Windows Services Layer | X | winl0g0.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| WTF Test | X | wtftest.exe | Added by the W32/RBOT-ACM WORM! |
| Winsock2 driver | X | SYSTEM32.EXE | Added by the W32/Spybot-EG WORM! |
| Windows Hijack Protection System | X | commngr.exe | Added by a variant of the W32/SDBOT WORM! Note: Located in \%WINDIR%\System32\Com\ |
| Windows Updating Service | X | updating.pif | Added by the W32/RBOT-ALW WORM! |
| Windows USB v3.2 | X | wsvc.exe | Added by a variant of the WORM_SDBOT family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ |
| winlogin.exe | X | mspaint.exe | Added by a variant of the WIN32.AGENT.AH TROJAN! |
| wuanguard | X | wuanguard32.exe | Added by the W32/RBOT-AAF WORM! |
| winvxd32 | X | winvxd32.exe | Added by the W32.Gabloliz.A WORM! |
| Windows Registry Scan | X | regscan23.exe | Added by a variant of the WIN32.RBOT WORM!
|
| WheelsMouse | X | (Path to,Trojan) | Added by the Troj/SocksPr-D
TROJAN!
|
| WinXPLoad | U | Rundll32,LoadDll, LoadExe,WinXPLoad.exe | Compaq hotkey related - required if you use the hotkeys |
| Windows SP2 Update | X | Sp2update.exe | Added by the WOOTBOT.BS WORM! |
| win | X | xwinxrpc32.exe | Added by the W32/Agobot-MV WORM! |
| Wifi Loader | X | wifiload.exe | Identified as a variant the Backdoor.Win32.IRCBot.byu malware Note: Located in \%WINDIR%\ Note: Use SDFix under supervision. |
| Windows Reg Services | X | lncom.exe | Added by the TROJ/PRORAT-O TROJAN! |
| Windows Update | X | winlogin.exe | Added by the Troj/Banker-DV or Troj/Banker-FY or Troj/Banker-GB TROJAN! |
| WindowsUpd2.exe | | WindowsUpd2.exe | VirtuMonde adware |
| Windows Load | ? | windows.com | ?? |
| WinExec | X | WinExec.exe | Added by the W32/Falus-A
WORM!
|
| Windows Start Server 2000 | X | traficy.exe | Added by the W32/Rbot-AHM
WORM!
|
| Windows System Tray | X | swhost.exe | Unidentified worm or trojan |
| Windows Updates Agent | X | winupdate.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| WinPop | X | winpop.exe | Added by Brudevic_A adware Note: Located in %programfiles%\WinPop |
| WINDOWS SYSTEM | X | smsc.exe | Added by the W32/MYTOB-BR WORM!
|
| WinBackup Scheduler | U | Wbsched.exe | LIUtilities WinBackup scheduler - backup software |
| WINDOWS SYSTEM CLEANER | X | iexplore.exe | Added by the W32.Mytob.ET
WORM!
|
| Win32 Help32 Service | X | win32help.exe | Added by the W32/Delbot-U WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| WSAConfiguration | X | winlogon32.exe | Added by the W32/AGOBOT-WC WORM! |
| WinRun | X | AutoRun.ini | W32/Lovelet-AD |
| winctl | X | winctl.exe | Added by the Troj/IRCBot-YI Trojan Read the link, allows remote access |
| Windows Media Player Update | X | [random,filename] | Added by the RBOT-ET WORM!
|
| Wins32 Online | X | cfgpwnz.exe | Added by the W32.Bropia.R WORM! |
| WinFX | X | cssrs.exe | Added by the AGOBOT.FX WORM! |
| Wintime | X | Wintime.exe | Added by the Harnig
TROJAN!
|
| WinGate initialize | X | WinGate.exe | Added by a variant of the LOVGATE WORM!
|
| Win32 Update | X | dl32.exe | Added by an unidentified variant of the lroffer infection. TROJAN!
Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| winenv | X | winenv.exe | Added by a variant of the Backdoor:W32/SdBot.BZY family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ |