| Name | Status | Filename | Description |
|---|
| WINDOWS MANAGEMENT SYSTEM | X | wm1exe.exe | Added by the W32/RBOT-VT WORM! |
| winupdate2846 | X | (path),vbsystem35.exe,(path),msvbrun.exe | Added by a Mutin-C IRC backdoor trojan infection |
| Windows Logon | X | winlogin.exe | Added by the TROJ/SPYBOT-C TROJAN! |
| WUSB11B.exe | Y | WUSB11B.exe | Linksys WUSB11 WLAN USB adapter |
| Winsock2 driver | X | AMSNMGR.EXE | Added by a variant of the W32.SPYBOT WORM!
|
| Windows Reverse Preperation | X | winrvp.exe | Identified as a variant of the Backdoor.Win32.IRCBot.axp worm.
Note: Located in \%WINDIR%\System32\ |
| Windows MeTaLRoCk service | X | metalrock.exe | Added by the TASTYRED VIRUS! |
| Windows System Drivers | X | sysretain.exe | Added by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Windows Secure Services | X | ssms.exe | Added by a variant of the W32/SDBOT WORM! Note: Located in C:\%WINDIR%\System32\ (XP/WinNT/2K) |
| Windows | X | msdos98.exe | Added by the PWSTEAL VIRUS! |
| WebCpr0 | X | WebCpr0.exe | Web_CPR/TopMoxie adware |
| winreg_32 | X | svchosst.exe | Added by the BANCOS-CE TROJAN! Read the link, keylogger/password stealing trojan(s) involved. |
| WindowsKeyUpdate | X | master.exe | Added by the W32.JOSAM WORM! |
| winupd.exe | X | winupd.exe | Added by the BEAGLE.M or BEAGLE.N WORMS! |
| Windows Messenger Messenger | X | winmsg.exe | Added by W32.Velkbot.A WORM! |
| wlsass | X | wlsass.exe | Added by the WLSASS/32.Process TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| WSAConfiguration | X | svchostt.exe | Added by the AGOBOT.ZT WORM! |
| WinMsrv32 | X | WinMsrv32.exe | Added by the GAOBOT.AFJ WORM! |
| Windows Registry Security | X | crss.exe | Added by a variant of the BACKDOOR.IRC.BOT TROJAN! |
| Winampa Agent | X | WINAMPA.EXE | Added by the W32/SPYBOT-BR WORM! - NOTE: this is NOT the Winamp Media Player, as described here |
| WinCheck | X | WinCheck.exe | Added by the PWS-CY VIRUS! |
| Windows Remote Launcher | X | wnpmcs.exe | Added by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: Located in \%WINDIR%\System32\ |
| WinLsass | X | (path to file) | Added by the W32/WORT-B TROJAN! |
| Win32 Usb Driver | X | AvpG.exe | Added by the W32/FORBOT-BX WORM! |
| WindUpdates | X | WinUpdt.exe | Windupdates adware |
| Wireless Console | N | wcourier.exe | Related to Wireless_Console installed alongside Asus wireless components. Provides configuration options for these devices. Note: Located in C:\Program Files\Generic\Wireless Consol |
| WireLessKeyboard | U | PS2USBKbdDrv.exe | Related to WireLess_Keyboard Multimedia Combo Set by SANSUN Industries. Note: Located in C:\Program Files\Multimedia Combo Set\ |
| WinGuage Pro | N | WGPRO32.EXE | Part of McAfee Nuts & Bolts. "WinGauge is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious". Resource hog. Available via Start -> Programs |
| Windows Service Agent | X | ******.exe (* =,random char) | Added by a variant of the WIN32.RBOT WORM!
|
| WinAC v4 | X | klsuicbn.exe | Added by the W32/FORBOT-CS WORM! |
| Windows Live Servicer | X | usrserv.exe | Added by the Trojan.Crypt.XPACK.Gen Trojan |
| Windows Firewalll | X | svvhost.exe | Added by a variant of the WIN32.RBOT WORM!
|
| Windows Printing Driver | X | WinSpooler.exe | Added by an Unknown malware. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Windows Hijack Protection | X | comngr.exe | Added by a variant of the W32/SDBOT WORM! Note: Located in \%WINDIR%\System32\Com\ |
| WinDLL (dlfksdld.exe) | X | dlfksdld.exe | Added by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. DO NOT DELETE THIS FILE C:\WINDOWS\RUNDLL32.EXE |
| Win32Usr | X | WinCab.exe | W32/Dedmir-A |
| Windows Messenger Service | X | winsmsgr.exe | Added by the W32/RBOT-VW WORM! |
| Windows Taskmanager | X | winpifviewer.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Windows Media Player | X | msass43.exe | Added by a variant of the WIN32.RBOT WORM!
|
| Win32 Security Protocol | X | secure32.exe | Added by the W32/Rbot-ETI WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| wscript.exe | X | vabian.vbs | Added by the VABI VIRUS! |
| Windows Configuration | X | wsys32.exe | Added by the GAOBOT.FB WORM! |
| WinLibUpdte | X | libupdte.exe | Added by the BIONET.318 VIRUS! |
| Windows Update 63 | X | shupd64.exe | Added by the W32/Forbot-GA
WORM!
Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. |
| Windows Host32 Starter | X | hostserv.exe | Added by the W32/SDBOT-WU WORM! |
| Windows Service Manager | X | svcrun.exe | Added by the Troj/Dloader-NY
Trojan!
|
| WINDOWS SYSTEM | X | servises.exe | Added by the W32/Zotob-I
WORM!
Note: (servises.exe) is not the legitimate Windows Process. (Notice the difference in the spelling.) The legitimate Windows Process (services.exe) should not be seen in Msconfig or as a Startup item. |
| Windows Firewall | X | svchost.exe | Added by the Troj/Proxy-HT Trojan Read the link, allows remote access |
| WindowsUpdate | X | path to,executable | Added by the Troj/Dupa-B
TROJAN!
Note: This worm\trojan file is found in the Windows or Winnt folder.
|
| Winkb6 | U | winkb6.exe | Part of We-Blocker, works in tandem with syswb6. Both files are needed to run WeBlocker. Required if We-Blocker is installed |
| Windows firewall manager | X | msguard.exe | Added by a variant of W32.Randex.GEL WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) steal information and terminate anti-virus applications |
| WINDOWS SYSTEM By FEnR | X | windasz-updote.exe | Added by the MYTOB.LR WORM! |
| WinUpdsv | X | winupdsv.exe | Added by the X97M.DROPO Macro VIRUS! |
| Windows Update Firewall System | X | winmsfw.exe | Added by the W32/Rbot-EEO WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Ssteal product registration information from certain software and turn off security software such as anti-virus or firewall |
| WNST | X | wns*****.exe (*,= random char) | PurityScan/Clickspring Adware |