| Name | Status | Filename | Description |
|---|
| WindowsRegKey update | X | [random or,different file,name] | Added by the RBOT.QT WORM! |
| Windows System Configuration | X | wincfg.exe | Added by the AGOBOT.OP WORM! |
| Win32System | X | win32s.exe | Added by the W32.Mydoom.V WORM! |
| Windows Service Pack Auto Update | X | figgaz.exe | Added by a TROJAN.CLICKER - identified by Kaspersky antivirus as Trojan-Clicker.Win32.Agent.bt
|
| Windows Logon Procedure | X | Svchosta.exe | Added by a variant of the W32.SPYBOT WORM!
|
| Windows LoL Layer | X | winlolx.exe | W32/Rbot-FOR Read the link, allows remote access |
| WinStart | X | services.exe | Added by the W32.SOBER.O WORM! - Note - this file is placed in a "%Windir%\Connection Wizard\Status folder, and should NOT be confused with the legitimate Windows services.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
|
| WIN32 | X | WIN32.EXE | Added by the WIN32/MYTOB.AD WORM!
|
| Win32 Word Services | X | msword32.exe | Added by a variant of the WIN32.RBOT WORM!
|
| Windows Essensials | X | mvnesc.exe | A variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Windows svchost | X | ups.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\ Note: Use SDFix under supervision. |
| Windows DLL Host | X | dllhost32.exe | Added by an unidentified WORM or TROJAN! |
| Windows TM | X | SVPHOST.exe | Added by a variant of the WIN32.RBOT WORM!
|
| Windows SpoolPrint Service | X | spoolersrv.exe | Added by the W32/Sdbot-ZT
WORM!
|
| WindowsRegKey update | X | 16winupdate32.exe | Added by a variant of the WIN32.RBOT WORM!
|
| winxpdll32.exe | X | winxpdll32.exe | Added by a variant of the Win32.SMALL downloader TROJAN! |
| W32.Scran | X | Scran.exe | Added by the W32.Narcs WORM! |
| WindowsService | X | (random,name).dll | Troj/Vundo-X Read the link, steals information |
| wait4IP | U | wait4IP.exe | Packard Bell net2Plug allows you to network PCs anywhere in your house |
| winltmpv | X | winln.exe | Added by the TCXMEDI-C TROJAN! |
| WIN32SNDS | X | banc.exe | Added by an unidentified WORM or TROJAN! |
| Windows Update | X | usnsvc.exe | Added by the W32/Kobot-C WORM! Note: Located in \%Program Files%\Common Files\System\ Read the link, allows remote access Note: Use SDFix under supervision. |
| Windows Debugger | X | windbg.exe | Added by an unknown worm or trojan infection! |
| Wireless-G Notebook Adapter | Y | Gcc.exe | LinkSys Wireless-G Notebook Adapter diver |
| Win32 USB2 Driver | X | msn.exe | Added by the W32/FORBOT-EX WORM! |
| Windows NetDDe | X | wrmana32.exe | Added by the W32.Mytob.IM
WORM!
|
| Windows Service Agent | X | mssngear.exe | Added by a variant of the RBOT family of IRC Backdoor trojan. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Windows Update | X | msi.exe | Added by the Troj/Banker-XB TROJAN! |
| WinCheck | X | WinCheck.exe | Added by the PWS-CY VIRUS! |
| win msdt service | X | mswindtc.exe | Added by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Windows Media Player 3.6 | X | wmpa36.exe | Added by a variant of the WIN32.RBOT WORM!
|
| Windows UDP Control Center | X | msnpd.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Windows Update 63 | X | shupd64.exe | Added by the W32/Forbot-GA
WORM!
Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. |
| WIN32DS | X | clienttimer.exe | Added by Eziin adware |
| Windows Data Server | X | autodisc.exe | Added by the W32/SPYBOT-CB WORM! |
| Windows Registry Startup | X | wind32.exe | Added by the W32/Agobot-BZ WORM! |
| Win386 | X | sp32.dll | Homepage hijacker. Not a dll but a regfile in disguise |
| Windows CPU host | X | winbog32.exe | Added by a variant of the WIN32.RBOT WORM!
|
| WXProcMgr Module | N | WXprocMgr.exe | TVTonic from Wavexpress - "enjoy 3 full-screen, DVD-quality video channels for FREE". Allows data content to be downloaded and synchronized on your system |
| Windows Security Center Notification Applse | X | sxes.exe | W32/Rbot-GLR Read the link, allows remote access |
| Windows Serviece Agents | X | kgsxwhl.exe | Added by a variant of the Worm.Rbot.ABFK Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. The filename is random |
| Windows System Manager | X | smsc.exe | Added by a variant of the WIN32.RBOT WORM!
|
| Windows Logon Procedure | X | Svchoste.exe | Added by a variant of the W32.SPYBOT WORM!
|
| Windows FAT 32 | X | WINFAT32B.exe | Added by the W32/SPYBOT-AGT WORM! |
| Windows Spoolsrv Service | X | spoolmsv.exe | Added by the W32/Sdbot-ZS
WORM!
|
| Windows Subsys | X | winload.exe | Added by the NETSPREE.C WORM! |
| Win32 Usb Driver | X | AvpG.exe | Added by the W32/FORBOT-BX WORM! |
| www.symantec.com | X | oz11111.exe | Added by the W32.Mydoom.W WORM! |
| WaveTop Upload Manager | N | N/A | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
|
| WinDrg32 | X | windrg32.exe | Added by the DRUDGEBOT.A WORM! |
| Windows Browser Services | X | Browsr32.exe | Added by a A variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| winupdate.exe | X | winupdate.exe | Added by the RADO VIRUS! |
| Windows Update | X | wininfo.exe | Added by the W32.Mytob.GA
WORM!
|
| Win32 FRT Driver | X | msfr32.exe | Added by a variant of the W32/FORBOT WORM!
|
| Windows Secure Messaging System | X | msnmsgrsrvc.exe | Added by the W32/RBOT-RE WORM!
|