| Name | Status | Filename | Description |
|---|
| WINDOWS SYSTEM | X | efefefe.exe | W32/Mytob-KH Read the link, allows remote access |
| Windows Update | X | SecretStub.exe | Identified as the Trojan-Dropper.Win32.Sramler.c downloader TROJAN!. Note: This trojan is located in \%WINDIR%\ |
| WindowsUpdate | X | svchost.exe | Added by the TROJ/AGENT-V TROJAN! |
| Windows Media Player | X | wmplayer.exe | Added by the W32.Kelvir.G or W32.Kelvir.H or W32.Kelvir.I WORM! |
| Winpower | U | Winpower.exe | Related to InstallAnywhere ZeroG Software is now owned by Macrovision. Note: located in C:\Program Files\UpsPilot\ |
| winlogon | X | winlogin.exe | Added by the RANDEX.E or P2LOAD.A WORM! |
| Windows Firewall Log | X | winlog.exe | Added by an unidentified WORM or TROJAN! |
| Windows LoL Layer | X | win.exe | Added by the W32/Rbot-FTO WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Win32Usr | X | WinCab.exe | W32/Dedmir-A |
| winupated.exe | X | winupated.exe | Added by a variant of the W32/SDBOT WORM! |
| Windows Audio System | X | nndsvc.exe | Added by a A variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| WebSavingsFromEbates0 | X | WebSavingsFromEbates0.exe | "Web Savings" From Ebates Software, a shopping tool that opens pop-up windows |
| WindowsRegKey update | X | rkbuouoxfl.exe | Added by the RBOT-OO WORM!
|
| Windows Servce Agent | X | colwindos.exe | Added by a variant of the BACKDOOR.IRC.BOT TROJAN! The filename is a (Random 8 Letter).exe |
| winskype | X | winskype.exe | Added by the Troj/Brogger-C TROJAN! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. |
| Wins Update 32 | X | services32.exe | Added by the W32/Forbot-FN
WORM!
Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. |
| Windows Registry Security | X | crss.exe | Added by a variant of the BACKDOOR.IRC.BOT TROJAN! |
| Windows MSN Updates | X | wnd32.exe | Added by the Troj/IRCBot-ABA worm and IRC backdoor. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Windows Spool | X | winspool.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| wormexe | X | winstart.exe | Added by the EARLYBIRD VIRUS! |
| WintelUpdate | X | exujd.exe | Identified as a variant of the Backdoor.Win32.Small.crw backdoor. Note: located in \%WINDIR%\ Note: Use SDFix under supervision. |
| WAPI | X | wts**.exe (* =,random char) | PurityScan/Clickspring Adware |
| Win32 Firewall Driver | X | winfw.exe | Added by a variant of the WIN32.RBOT WORM!
|
| Windows Update | X | msi.exe | Added by the Troj/Banker-XB TROJAN! |
| WindowsRegKey Autoupdate | X | Explorer.exe | Added by a variant of the WIN32.RBOT WORM!
NOTE: THis is NOT the legitimate Explorer.exe! |
| Win Updates | X | winupdates.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Windows NTFS Volume Manage | X | (Random 6,Letter).exe | Added by a variant of the Backdoor.Win32.Rbot.edl family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| WinDLL (wchshield.exe) | X | wchshield.exe,start | Added by Worm_Ircbot_Gen Reported by Prevx. Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| WINDOWS SYSTEM | X | xpupdate.exe | Added by the W32/ZOTOB-G WORM! |
| Win Net Wks32 | X | netwks32.exe | Added by the WORM_RBOT.AA Read the link, modifies the hosts file. Adds a rootkit infection. |
| Windows Security Service | X | arrdt.exe | Added by a variant of the WIN32.RBOT WORM!
|
| winstart | X | winstart.exe | Added by the TROJ/SCKEYLO-AB TROJAN! |
| winnet | X | winnet.exe | CommonName Toolbar spyware. To uninstall see here |
| Windows Firewalll | X | winmu.exe | Added by a variant of the WIN32.RBOT WORM!
|
| Windows Service | X | video2.exe | Added by the DOWNLOADER.SMALL.MY TROJAN! |
| winreg_32 | X | sysdll.exe | Added by the TROJ/DLOADER-IJ TROJAN! |
| Windows_Protect | X | winsystem.exe | Added by a variant of the WIN32.RBOT WORM!
|
| WinStart001 or WinStart001.EXE | X | WinStart001.exe | FromIGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge |
| windows update | X | Wruaclt.exe | Added by the RBOT.XZ WORM! |
| wlm | X | [Path to trojan,file] | Added by the Troj/Bancos-BCY Trojan Read the link, steals information |
| winupdate_ | X | [path to file] | Added by the W32.COMDOR.A WORM! |
| Windows Live Service | X | msnlive.exe | Added by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ |
| Winproxy Personal | X | WINPROXY.EXE | Added by the SDBOT.BMF WORM! |
| Windows Autostart Loader | X | notepad32.exe | Added by a variant of the WIN32.RBOT WORM!
|
| WIN USB SUPPORT | X | grxsrv.exe | Added by a variant of the WIN32.RBOT WORM!
|
| Winlogin.exe | X | steam.exe | Added by a variant of the WIN32.AGENT.AH TROJAN! |
| Winsock2 driver | X | WUAUMQR.EXE | Added by the W32/SPYBOT-DP WORM! |
| Windows Service Pack2 | X | WIN43.EXE | Added by the GAOBOT.G WORM! |
| WINTASK | X | taskgmrs.exe | Added by the W32.Mytob.DH
WORM!
|
| Wifi Booter | X | wifibooter.exe | Identified as a variant the Backdoor.Win32.IRCBot.byu malware Note: Located in \%WINDIR%\ Note: Use SDFix under supervision. |
| Windows spoolservr Service | X | spoolservr.exe | Added by the W32/Sdbot-AAN
WORM!
|
| Windows System 32 | X | winsys_32.exe | Added by the W32/Rbot-FTR WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| WindowsSystem32 | X | [Path to Worm] | Added by the W32/Sdbot-DFG Worm Read the link, allows remote access |
| win32servv | X | load.exe | Added by an unidentified trojan or adware |
| Wind0ws | X | wordpad.exe | Added by the W32/Agobot-TL
WORM!
Note: This is not the legitimate Windows application wordpad.exe (Which is found in the Program Files\Accessories folder.) The legitimate Windows application should not be seen in Msconfig or as a Startup item. This worm\trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
|