| X | Wifi Setup | wifisetup.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Win FTP | wintftp.exe | "Added by the SDBOT-KE WORM!"
|
| X | Win WinAmp | winamp.exe | "Added by the RBOT.AGF WORM! Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of %ProgramFiles%. This file is located in %System%"
|
| X | win32 | WinSetup.exe | "Added by the EVILBOT.B TROJAN!"
|
| X | Win32 | arsetup.exe | Added by the SPAZBOX.A TROJAN!
|
| X | Win32 Configuration | dllhelp.exe | "Added by the SDBOT.UL WORM!"
|
| X | Win32 Help32 Service | win32help.exe | "Added by the DELBOT-U WORM!"
|
| X | Win32 NDIS Driver | Ndistcp.exe | "Added by the WOOTBOT.EU WORM!"
|
| X | win32serv | servicesetup.exe | "Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger"
|
| X | Winahlp.exe | Winahlp.exe | "Added by a variant of the VAGRNOCKER TROJAN!"
|
| X | winallap | winallap.exe | "Added by the DELF.E TROJAN!"
|
| X | Winamp | winamp.exe | "Added by the AGOBOT.XI WORM! Note - this is NOT the popular Winamp media player"
|
| N | Winamp | winamp.exe | "Winamp media player. Resides in a ""Winamp"" subdirectory of the Program Files directory"
|
| X | Winamp Agent | winamp.exe | "Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player. The valid filename for the Winamp Agent is ""winampa.exe"" - see here"
|
| X | Winamp Media Player | winamap.exe | "Added by the SDBOT.ACJM BACKDOOR!"
|
| X | Winamp Media Player | winamp.exe | "Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of %ProgramFiles%"
|
| X | WinAmp Player | winampp.exe | "Added by the RBOT-AQI WORM! Note - this is NOT the popular Winamp media player which has a different filename"
|
| X | WinApp32 | msapp.exe | "Added by the RSBOT TROJAN!"
|
| X | wincmap | wincmapp.exe | "CasClient adware variant - also detected as the CMAPP TROJAN!"
|
| X | WinDLL (tmp.exe) | "rundll32.exe tmp.exe | start" |
| X | WinDLL (wintmp.exe) | "rundll32.exe wintmp.exe | start" |
| U | Window Washer | wwDisp.exe | "Window Washer from Webroot Software. Useful utility that deletes safe to remove files |
| U | Windows Accelerators | setup.exe | "KeySpy keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| X | Windows ARP Detectionc | nvudlsp.exe | "Added by the AGENT.LMW BACKDOOR!"
|
| X | Windows Default Server | wfdmgrsp.exe | "Added by the IRCBOT.BCX BACKDOOR!"
|
| X | Windows Desktop Controler | windesktop.exe | "Added by the SDBOT-XH WORM!"
|
| X | Windows Dialup Service | dialup.exe | "Added by the AGOBOT.AAH WORM!"
|
| X | Windows Guard Pro | WindowsGP.exe | "Windows Guard Pro rogue security software - not recommended |
| X | Windows Helper | winhelp.exe | "Added by the BANKER.APE TROJAN!"
|
| X | Windows Login Folder | winzep.exe | "Added by the AGOBOT-TZ WORM!"
|
| X | Windows Logon Application | win32help.exe | "Added by the DELBOT-X WORM!"
|
| X | Windows Logon Application | winamp.exe | "Added by the POEBOT-LR WORM! Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of the Program Files directory"
|
| X | Windows Media AP | winmapp.exe | Added by an unidentified WORM or TROJAN!
|
| X | Windows Media APP | wmapp.exe | Added by an unidentified WORM or TROJAN!
|
| N | Windows Media Powerpoint Helper | NSPPTHLP.EXE | German software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start -> Programs
|
| X | Windows Monitor | arsetup.exe | Added by the SPAZBOX.A TROJAN!
|
| X | Windows PNP | winpnp.exe | "Added by the RBOT-AKN WORM!"
|
| X | Windows Reverse Preperation | winrvp.exe | "Added by the SLENFBOT.CB WORM!"
|
| X | Windows Reversed Virus Protection | winrsvp.exe | "Added by the SLENFBOT.HX WORM!"
|
| X | Windows Runtime Help | win32hlp.exe | "Added by a variant of the AIMVISION TROJAN!"
|
| X | Windows Secure Update | WinSecUp.exe | "Added by the RBOT-GCD WORM!"
|
| X | Windows Service Agent | lcaqmsp.exe | "Added by the RBOT.WFR BACKDOOR!"
|
| X | Windows Service Agent | WinTcpip.exe | "Added by the SPYBOT.AP WORM!"
|
| X | Windows Services | winudp.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Windows Startup | winstartup.exe | "GoHip foistware"
|
| X | WINDOWS SYSTEM | winaup.exe | "Added by the MYTOB-DN WORM!"
|
| X | Windows System Backup | SysBackup.exe | Unidentified malware
|
| X | Windows System File | cmxp.exe | "Added by the SPYBOT.KHO WORM!"
|
| X | Windows System Security | winmp.exe | "Added by the RBOT.IV WORM!"
|
| X | Windows System32 | windowsp.exe | "Added by the MYTOB.GD WORM!"
|
| X | Windows TCP/IP | wintcp.exe | "Added by the AGOBOT-ZH WORM!"
|
| X | Windows Temperate Services | wintmp.exe | "Added by the SLENFBOT.ZW WORM!"
|
| X | Windows UDP | winudp.exe | "Added by the IRCBOT.GAT WORM!"
|
| X | Windows Update | dllhostup.exe | "Added by the BANCBAN-NB TROJAN!"
|
| X | WindowsBackup | WINDOWSBACKUP.EXE | "Added by the STANG WORM!"
|
| X | WindowsFirewallSvc | winsvcup.exe | "Added by a variant of the SDBOT WORM!"
|
| X | WindowsFY | wp.exe | "Part of a ""Security IGuard"" parasite infestation - also detected as DESKTOPHIJACK"
|
| X | windowsmp | windowsmp.exe | "Added by the AUTORUN-DP WORM!"
|
| X | WindowsRegKey update | Windowsup.exe | "Added by the SDBOT.PU WORM!"
|
| X | WinFix service | rsswjzgp.exe | "Added by the RBOT-FAE WORM!"
|
| U | WinFlip | WinFlip.exe | "WinFlip from Tokyo Downstairs - a 'Flip-3D' task switcher alternative to the standard Alt+Tab on Windows XP that adds the equivalent 'Aero' feature from Windows 7 and Vista. You can either click on the tray icon |
| U | WinFlip.exe | WinFlip.exe | "WinFlip from Tokyo Downstairs - a 'Flip-3D' task switcher alternative to the standard Alt+Tab on Windows XP that adds the equivalent 'Aero' feature from Windows 7 and Vista. You can either click on the tray icon |
| U | WinGuard Pro | wgp.exe | "Winguard Pro"
|
| X | Winhelp | winhe1p.exe | "Added by the QQPASS.E TROJAN!"
|
| X | WinHelp | WinHelp.exe | "Added by the LOVGATE.F WORM! Note - this file is located in %System% whereas the valid one is located in %Windir%"
|
| X | winhlp.exe | winhlp.exe | "Added by the FORMGLIEDER TROJAN!"
|
| X | winltmpv | wutop.exe | "Added by the TCXMEDI-C TROJAN!"
|
| U | winmatrix.exe | WinMatrixXP.exe | "WinMatrix XP - wallpaper replacement that shows different matrix effects (including flowing matrix codes from 'The Matrix' movie) on your desktop"
|
| X | winnt DNS ident | windowxp.exe | "Added by a variant of the RBOT WORM!"
|
| X | Winnt DNS ident | windowsp.exe | "Added by the RBOT.BAL WORM!"
|
| X | WinPCDoctor | SysRep.exe | "WinPCDoctor rogue system error and cleaning utility - not recommended |
| X | WinPop | winpop.exe | "Brudevic A adware"
|
| N | WinPopup | WINPOPUP.EXE | "Intranet chat software provided by windows for chat on small networks. Handy little LAN messaging utility. Has been included in Windows since 95 |
| X | WinSig | NetXP.exe | "Added by the BANKER-FN TROJAN!"
|
| X | Winsock32driver | ZoneLockup.exe | "Added by the HACARMY.D TROJAN!"
|
| X | WINTASK | msmgrxp.exe | "Added by the MYTOB.AQ WORM!"
|
| X | Wintbp.exe | wintbp.exe | "Added by the ZOTOB.E WORM!"
|
| X | winthelp | winthelp.exe | "Associated with the AdvancedCleaner rogue security software - see here. Removal instructions here"
|
| X | Winupdate Service | winxp.exe | "Added by the SPYBOT.IR WORM!"
|
| X | winxp | winxp.exe | "Added by the BRONTOK-DN WORM!"
|
| X | Winxp update | Cappp.exe | "Added by the RBOT.DKO WORM!"
|
| X | WinZap Check | winzbp.exe | "Added by the RBOT-AWZ WORM!"
|
| X | winzip | winzip.exe | "Added by the RBOT.BDA WORM! Note - this is not part of the popular WinZip file compression utility"
|
| X | winzip | ir_ftp.exe | "Added by the BANCBAN-S TROJAN!"
|
| X | WinZip Update | WinZip.exe | "Added by a variant of the RBOT WORM! Note - this is not part of the popular WinZip file compression utility"
|
| X | WMP Auto Update | WINMEDUP.EXE | "Added by the RBOT.CF WORM!"
|
| X | wnxupdate | updatexp.exe | "Added by the COMBRA-G WORM!"
|
| X | woopie | winamp.exe | "Added by the AGOBOT.XV WORM! Note - this is NOT the popular Winamp media player"
|
| X | ws2help | ws2help.exe | "Added by a variant of the SMALL.AN TROJAN!"
|
| X | WSock32 Protocol | wsock32p.exe | "Added by the SDBOT.M BACKDOOR!"
|
| X | Wupftp | wupftp.exe | "Added by the AGOBOT.AKV WORM!"
|
| X | xibquxs | rnxntup.exe | "Added by a variant of the ORCU.B TROJAN!"
|
| X | xmnfuruwk | rnxntup.exe | "Added by the ORCU.B TROJAN!"
|
| X | XP Loader | loaderxp.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | XP System | systemxp.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Xpnet | NetXp.exe | "Added by the BANCBAN-AT TROJAN!"
|
| X | Xupiter Startup | XupiterStartup.exe | "Xupiter - adware and homepage hijacker. Use Spybot S&D |
| N | Yankee Clipper III | YankClip.exe | "Yankee Clipper III - 'A super powerful Windows clipboard extender/memory - now in its third generation. Handles Pictures |
| N | YOP | yop.exe | "Dashboard Module for SBC Yahoo! Online Protection"
|
| U | Zero PoPup Killer XP | zpk_xp.exe | "Intelligent anti-pop-up software product by Ax-Soft"
|
| X | ziphelp | ziphelp.exe | "CoolWebSearch parasite variant"
|
| ? | zzzCamlnSuitelll | setup.exe 46*** | "??"
|
| ? | zzzhpsetup | setup.exe | "??"
|
| X | [3-4 random letters] | nslookup.exe | "PurityScan adware. Not to be confused with the legitimate nslookup.exe which is found in the System32 folder"
|
| X | [executed file name] | App.exe | "Added by the WAXPOW WORM!"
|
| X | [random name] | n?lookup.exe | "PurityScan adware"
|
| X | [Randomly chosen existing folder name] | _setup.exe | "Added by the ANTINNY-L WORM!"
|
| X | [unknown] | WIN32OP.EXE | "Added by the SDBOT-U WORM!"
|
| X | [unknown] | ADVAP.EXE | "Added by the SDBOT-W WORM!"
|
| X | [various names] | _ctcp.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | MNTP.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | _Cat3 | msmsgrxp.exe | "Added by a variant of the SMALL-DT downloader TROJAN"
|
| X | {**-**-**-**-**} | mrdsregp.exe | "Zenosearch adware |
| X | {E4785213-3EFE-4c26-A9B4-332440E31F6F} | sysrxmfdksp.exe | "Added by the FAKEALERT-AH TROJAN!"
|
| X | {F758F78B-0885-490e-AA3C-4A38D28B0240} | sysyeabdgfp.exe | "Added by the FAKEALERT-AM TROJAN!"
|