| Status | Autorun name | Command | Description |
| X | wesumu | wiustv.exe | Added by the QQPASS-L TROJAN! |
| N | WetSock | wetsock.exe | RoboMagic Wetsock - weather reporting in the System Tray |
| N | wextract_cleanup0 | advpack.dll, DelNodeRunDLL32 [path] [filename].TMP | Wextract Cleanup0 is valid and legal software included or sold to help clean up temporary or cab files created by the installer software for a wide variety of software. It should disapear after a restart of the system. If not fix it |
| U | WF2K | WF2K.EXE | System Tray application that starts up the Winfox utility for a Leadtek Winfast graphics card to restore settings. Can be started manually via Start → Control Panel → Display. Only needed if you wish to run things like the hardware monitor or overclock your card |
| N | WFGStartup | WFGStartup.exe | WorldFlash news ticker which "proactively delivers your news and information about the latest global events" |
| N | WFGStartup | WFGStartupU.exe | WorldFlash news ticker which "proactively delivers your news and information about the latest global events" |
| U | wfips | iphider.exe | ICQ (messaging/chat program) anti-bomb software. "WFIPS is anti-bomb software for safeguarding ICQ Bomb before the bombing. 'ICQ Defoolder' is a tool for removing ICQ bomb after being exposed." For more information about ICQ bombs see here |
| N | WFXCTL32.EXE | WFXCTL32.EXE | From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs |
| U | wfxload | wfxload.exe | WindowFX from Stardock Corporation - "a special effects program for Windows that allows users to add a variety of opening and closing, transition and other visual effects to the user interface" such as shadows, transparency and menu animations. Required for the selected special effects to work. Also part of the Object Desktop suite |
| Y | wfxsnt40 | wfxsnt40.exe | WinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application |
| ? | WFXSwtch | WFXSWTCH.exe | Related to WinFax. What does it do and is it required? |
| U | WG111v2 Smart Wizard Wireless Setting | RtlWake.exe | Configuration utility for the Netgear WG111 54 Mbps Wireless USB 2.0 Adapter that "provides wireless access to your desktop or notebook PC through the computer's USB port" |
| Y | WG511WLU | WG511WLU.exe | Netgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card |
| X | wgeax | wgeax.exe | Added by the IRCBOT-TM WORM! |
| X | wgs3 | wgs3.exe | Added by the LEGMIR-AQH TROJAN! |
| X | WGV | WGV.exe | Added by the ZIPPIE TROJAN! |
| U | WGWLocalManager | WGWLocalManager.exe | Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so. It could be started by creating a shortcut, running it only when connecting to the internet. If internet is used often, it's recommended to leave it in startup so it starts with the system |
| Y | WgwMngr | WgwMngr.exe | Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so |
| X | whagent | whagent.exe | System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here |
| X | what ever | decom.exe | Added by the RBOT-SC WORM! |
| X | What Frenz | FriendEQUALsuX.exe | Added by the BHARAT.A WORM! |
| U | WhatPulse | WHATPU~1.EXE | WhatPulse collects statistics on how much you type on your computer and sends this information to a server. It is not a keylogger which monitors your keystrokes and what you type - it only counts the number of keystrokes |
| U | WhatPulse | WhatPulse.exe | WhatPulse collects statistics on how much you type on your computer and sends this information to a server. It is not a keylogger which monitors your keystrokes and what you type - it only counts the number of keystrokes |
| U | WheelMouse | 4DMAIN.EXE | Mouse software for "Fellowes" Wheelman mouse. Has caused some users problems but shouldn't be needed if you don't use any enhanced features it may provide |
| U | WheelMouse | AMOUMAIN.EXE | A4Tech wireless mouse driver and utility - required if you use non-standard Windows driver features |
| X | WheelsMouse | [path to trojan] | Added by the SOCKSPR-D TROJAN! |
| X | WhenUSave | Save.exe | WhenU.Save adware |
| X | WhenUSearch | Search.exe | WhenU.Save adware |
| X | WhenUSearchWHSE | whse.exe | WhenU.Save adware |
| X | Whistler | whismng.exe | Added by the WHISTLER-F TROJAN! |
| X | Whitechix | brightx.exe | Added by a variant of the SDBOT WORM! |
| N | WhitephonePersonal | WhitePhonePersonal.exe | WhitePhone Personal from Voice Commerce Group - "provides free PC to PC calls globally and access to low cost calls to phones worldwide." Free internet telephony utility using the VoIP (Voice over Internet Protocol). No longer appears to be available |
| U | WHITNEY_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX-4x21 Series multifunction printers |
| U | Whitney2_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX-4725 Series photocopier |
| U | WHITNEY2_XRX_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Xerox Phaser 3200MFP multifunction laser printer |
| U | WhitneyXerox_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Xerox WorkCentre PE220 Series multifunction laser printer |
| X | Whvlxd | Whvlxd.exe | Added by the ZAPCHAS-CS TROJAN! |
| X | whxpin service | [randomname].exe | Added by the RBOT-FWU WORM! |
| X | wiascr | wiascr.exe | Added by the AGENT.AM TROJAN! Note - example names include "XviD", "Winamp Remote", "Windows Media Player" and "Futuremark" |
| N | WIAWizardMenu | RUNDLL32.EXE sti_ci.dll, WiaCreateWizardMenu | Still Image Class Installer - installed with a webcam |
| X | widelink | widelinke.exe | WideLink adware. File located in %Program Files%\widelink |
| X | Widnows Xp Web scan | xpscan.exe | Added by a variant of the SDBOT WORM! |
| X | wifeman | wifeman.exe | Unidentified malware |
| X | Wifi Boot | wifiboot.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Wifi Booter | wifibooter.exe | Added by the IRCBOT.ATH BACKDOOR! |
| X | Wifi Configuration | wificonfig.exe | Added by the IRCBOT.AWB BACKDOOR! |
| X | Wifi Configuration! | wificonfigs.exe | Added by the IRCBOT.AWB BACKDOOR! |
| X | Wifi Connection | wificon.exe | Added by the SLENFBOT.AC WORM! |
| X | Wifi Connection! | wificonnect.exe | Added by the IRCBOT.XEL BACKDOOR! |
| X | Wifi Debug | wifidebug.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Wifi Loader | wifiload.exe | Added by the IRCBOT.XEL BACKDOOR! |
| X | Wifi Loader! | wifiloader.exe | Added by the IRCBOT.XES BACKDOOR! |
| X | Wifi Setup | wifisetup.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | WiFix service | [random filename] | Added by a variant of the SDBOT WORM! |
| X | Wiinamp | [random].exe | Added by the IRCBOT-OH TROJAN! |
| X | WildFlics | WildFlics.exe | Direct-B premium rate adult content dialler |
| ? | WildTangent CDA | RUNDLL32.exe cdaEngine0400.dll, cdaEngineMain | Part of the WildTangent on-line games system. What does it do and is it required? |
| U | WildTangent Web Driver updater | wcmdmgrl.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| N | Wildwire Monitor | WWMon.exe | This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem |
| X | Will I Ever | anqbse.exe | Added by the SDBOT-TK WORM! |
| N | Willow Road | WillowRoad.exe | Willow Road Screen Saver |
| X | WillPolo | WillPolo.vbs | Added by the SOLOW.AF VIRUS! |
| X | wimpas | wimpas.exe | Added by the AGENT2.FGG TROJAN! |
| X | win | regedit -s win.dll | Added by the SEEKER.K TROJAN! Note that regedit is the legitimate Windows Registry Editor and shouldn't be deleted. The "win.dll" file is located in %Windir% |
| X | win | xwinxrpc32.exe | Added by the AGOBOT-MV WORM! |
| X | win | xwinxrpc.exe | Added by the AGOBOT-MV WORM! |
| X | WIN | ehshell.exe | Added by the MYTOB-CQ WORM! |
| X | WIN | windows.exe | Added by the REATLE.C WORM! |
| U | win | homesec.exe | Related to the Sentry Parental Controls software |
| X | Win Antispyware Center | av.exe | Win Antispyware Center rogue security software - not recommended, removal instructions here |
| X | Win Antivir 2008 | Win Antivir 2008.exe | Win Antivir 2008 rogue security software - not recommended, see here |
| X | Win Antivirus 2008 | Win Antivirus 2008.exe | Win Antivirus 2008 rogue security software - not recommended, see here |
| U | Win Chimes | winchi~1.exe | WinChimes - enhancement software for the system clock that runs in the system tray |
| X | Win Comm | WinComm.exe | Added by the WINCOM TROJAN! |
| X | Win Command | command32.exe | Added by the AGOBOT.XQ WORM! |
| X | Win Config | winconfig.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Win CPU | sysin.pif | Added by the RBOT-AXL WORM! |
| X | win ctl app | wuctl.exe | Added by a variant of the SDBOT WORM! |
| X | Win Defender | WinDefender.exe | Added by a variant of the FAKEAV-CLZ TROJAN! Note - this is not the legitimate Microsoft Windows Defender whose filename is MSASCui.exe |
| X | Win Defrag | windfrag.exe | Added by a variant of the SDBOT WORM! See here |
| X | Win Defrag! | windefrag.exe | Added by a variant of the SDBOT WORM! See here |
| X | Win Defrags | defrag.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Win Drivers SSL | TASKMAN4.exe | Added by a variant of the RBOT WORM! |
| X | Win Drivers SSL | hpws.exe | Added by the IRCBOT.67098 WORM! |
| X | Win Drivers SSL32 | hpwsnnsbc.exe | Added by the SPYBOT.MAR WORM! |
| X | Win exe file managr | crss.exe | Added by the RBOT.CCI WORM! |
| X | Win FTP | wintftp.exe | Added by the SDBOT-KE WORM! |
| X | WIN HOST PROCESS | WIN HOST PROCESS.EXE | Added by the KEYLOGGER.CLONE TROJAN! |
| X | Win I5oahder | [worm filename] | Added by the AGOBOT-DS WORM! |
| X | Win INI 32 | msrp32.exe | Added by the RBOT-FZC WORM! |
| X | Win l5oahder | winampa.exe | Added by the AGOBOT.EG WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of %ProgramFiles% whereas this file is located in %System% |
| X | Win leoahder | winampa.exe | Added by the AGOBOT-DU WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of %ProgramFiles% whereas this file is located in %System% |
| X | Win Login | winlogin.exe | Added by the RBOT-AWE WORM! |
| X | Win Microsoft 98 | win14.exe | Added by the RBOT-AKX WORM! |
| X | win msdt service | mswindtc.exe | Added by the SDBOT.DAE WORM! |
| ? | win name | stat.exe | ?? |
| X | Win Net Wks32 | netwks32.exe | Added by the RBOT.AA WORM! |
| X | Win Patch | ntldr.exe | Added by the SDBOT-GS WORM! |
| X | Win Patch | patch.exe | Added by the SDBOT-GL BACKDOOR! |
| X | Win Process Updates | winupdates.exe | Added by a variant of the SDBOT WORM! |