| Status | Autorun name | Command | Description |
| X | wms3 | wms3.exe | Added by the LEGMIR-AQG TROJAN! |
| X | wmsdk64_32.exe | wmsdk64_32.exe | Antivirus rogue security software - not recommended, removal instructions here |
| X | WMSDOS-ServicePack2 | cmd.exe /c C:\WMSDOS.sys | Detected by Bitdefender as the DELF.OFC TROJAN! See here. Note that cmd.exe is a legitimate Microsoft file normally located in %System% and shouldn't be deleted |
| X | Wmsncs Service | wmsncs.exe | Added by the BBJC.A TROJAN! |
| X | wmsrc.exe | wmsrc.exe | PrivacyRedeemer rogue privacy program - not recommended, removal instructions here |
| X | wmsys32 | wmsys32.exe | Added by the BANPAES.B TROJAN! |
| X | wmts | wmts.exe | Added by the VB-EUF WORM! |
| U | WMUAgent.exe | WMUAgent.exe | "WakeMeUp! is an advanced alarm clock for computers with Windows 2000, XP or Server 2003" |
| X | wmupdate | wmupdate.exe | Added by the AGENT-GGJ TROJAN! |
| X | wmv | winmonv.exe | Added by the AGENT-DG TROJAN! |
| X | WN Services | wnsvc.exe | Added by the KBBOT-A TROJAN! |
| X | WNAD | WNAD.EXE | Spyware added as a result of running a program called "Yo Mama Osama" (osama.exe). See here for more and how to get rid of it. There are other ways this can show up on your system, and it will manifest itself by periodically opening a new browser window with advertising for copy DVD software and the like |
| X | wnddrv | svchost.exe | Added by an unidentified TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | WNILOGON | WNILOGON.exe | Added by the LEWOR-M TROJAN! |
| X | WNSA | wnsts**.exe [* = random char] | PurityScan adware |
| X | WNSC | wnsin**.exe [* = random char] | PurityScan adware |
| X | Wnsck2 driver | wlogf.exe | Added by the SPYBOT-AF WORM! |
| X | WNSI | wnscp**.exe [* = random char] | PurityScan adware |
| X | WNSI | rwsa.exe | PurityScan adware |
| X | WNSO | WNSO.exe | Baidu.SoBar adware |
| X | WNST | wnsapi**.exe [* = random char] | PurityScan adware |
| X | wntlgns | wntlgns.exe | CoolWebSearch parasite variant |
| X | wnxpupdate | spvspool.exe | Added by the DABORA.B WORM! |
| X | wnxupdate | updatexp.exe | Added by the COMBRA-G WORM! |
| X | woeadot | woeadot.exe | Added by the MDROP-CYG TROJAN! |
| X | won update | WAPDATE.EXE | Added by the RBOT.N BACKDOOR! |
| U | WonderFrog | WonderFrog.exe | Wonder Frog typing monitor |
| N | WooCnxMon | CnxMon.exe | Wanadoo ISP software related - not required - here's how to bypass it |
| X | Woods Inc | wcmd.exe | Added by the KILLFIL-O TROJAN! |
| ? | WOOKIT | GestMaj.exe EspaceWanadoo.exe | Wanadoo broadband ISP (now rebranded as Orange) related. What does it do and is it required? |
| ? | WOOKIT | Shell.exe appLaunchClientZone.shl | Related to the Wanadoo broadband ISP (now rebranded as Orange). What does it do and is it required? |
| ? | WOOKIT | GestMaj.exe GestionnaireInternet.exe | Wanadoo broadband ISP (now rebranded as Orange) related. What does it do and is it required? |
| X | woopie | winamp.exe | Added by the AGOBOT.XV WORM! Note - this is NOT the popular Winamp media player which is located in %ProgramFiles%\Winamp. This one is located in %System% |
| N | WOOTASKBARICON | GestMaj.exe TaskbarIcon.exe | Wanadoo broadband ISP (now rebranded as Orange) taskbar icon - not required |
| N | Woowatch | Watch.exe | Wanadoo broadband ISP (now rebranded as Orange) related - not required |
| X | WOOZ | autodisc.exe | Added by the AGENT-CPS TROJAN! |
| X | word pair | bopotsvr.exe | Added by the SHED-A TROJAN! |
| N | WordPerfect Office 1215 | Registration.exe | Corel WordPerfect Office 12 registration wizard |
| Y | WordQ carat flag | WordQcrs.exe | Related to WordQ Writing Aid Software |
| X | Words | Words.exe | Added by the AGENT.GIT TROJAN! |
| N | WordWeb | wweb32.exe | WordWeb - free theasaurus and dictionary. Start manually |
| N | WordWeb Pro | wweb32.exe | WordWeb Pro - theasaurus and dictionary. Start manually |
| X | WorkFile | WorkFile.exe | Added by the BANCOS-AWN TROJAN! |
| ? | Workflo | workflow.exe | Related to BroadJump Client Foundation - broadband troubleshooting software installed by various companies. Is it required? |
| X | Working System Analyzer | syswork.exe | Added by the FORBOT-FZ WORM! |
| X | worknote1 | [filename].exe | Added by the MEETOT WORM! |
| U | WorkPace 3.0 | workpace.exe | WorkPace - stress injury prevention software |
| N | Works Calendar Reminder | wkcalrem.exe | If you schedule an event at any time in Microsoft Works Calendar and set a reminder then a shortcut will be added to Start → All Programs → Startup so this reminder service loads every time Windows starts |
| N | WorksFUD | wkfud.exe | A marketing program for MS Works |
| U | Workstation Scheduler | wm95.exe | Desktop Management Scheduler. Part of Novell's Netware Client. Schedueles NDS events. If events have been schedueled, it is required, otherwise, it is useless and a memory hog |
| X | Workstation Services | wrkstn.exe | Added by the RBOT-OJ WORM! |
| X | Workstation Ver 5.0 | vmware.exe | Added by the RBOT-AHB WORM! Note - this is note the legitimate VMware Player/Workstation file with the same name which is located in a %ProgramFiles%\VMware directory. This one is located in %System% |
| X | WorldAntiSpy | worldantispy.exe | WorldAntiSpy rogue spyware remover - not recommended, see here |
| U | WorldTime.exe | WorldTime.exe | Part of AnyTime Organizer Deluxe from Individual Software Inc - "Check the time anywhere in the world and know when to communicate. Place up to twelve clocks on your desktop" |
| U | Worm Detector | wd.exe | Worm Detector - antivirus add-on for Outlook 2K or XP for handling worms and spam |
| X | wormexe | winstart.exe | Added by the EARLYBIRD WORM! |
| X | Worms | logon.bat | Added by the DELMP3-A WORM! |
| X | wovax | wovax.exe | Added by the DAQA.A TROJAN! |
| X | wow | bar.exe | PurityScan adware |
| X | wow | wwf.exe | Added by the LINEAGE-Y TROJAN! |
| X | wow | Launcher.exe | Added by the DELF-DOR TROJAN! |
| X | wow | gewow.exe | Added by the WOWPWS-KA TROJAN! |
| X | wow64main.exe | wow64main.exe | Added by the ALUREON.BT TROJAN! |
| X | WOWKtxsCPP.exe | WOWKtxsCPP.exe | Added by the FAKEAV-BZF TROJAN! |
| N | Wpctrl | wpctrlnt.exe | WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
| N | Wpctrl | wpctrl95.exe | WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
| N | wpctrl95 | wpctrlnt.exe | WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
| N | wpctrl95 | wpctrl95.exe | WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
| U | WPCUMI | WpcUmi.exe | Notifications from the Parental Controls feature in Windows Vista. Note - disabling this entry does not disable Parental Controls and prevent it monitoring a users activity. On the controller account it prevents the pop-up on from displaying messages such as "Reminder: View the Parental Controls activity report". On the user account it prevents the warning messages appearing such as access has been denied and the Parental Controls icon appearing on the System Tray |
| Y | WPCycle.exe | WpCycleWin.exe | Added when selecting Mplayer2 to open media files. Forces other codes to Wait for Previous instructions to end, preventing instability of your CPU (freezing) |
| X | wpds.exe | doriot.exe | Added by the SMALL-KY TROJAN! |
| X | wpds.exe | wwnrot.exe | Added by the BAGLEDI-B TROJAN! |
| X | WPlayer | WPlayer.exe | Identified as a variant of the LDPinch.A malware |
| X | wpqggej | dnierjk.exe | Added by the FANBOT-F WORM! |
| X | WPSVC Services | wpnsc.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | wpwmgrs | wpwmgrs.exe | Added by the MYTOB-DH WORM! |
| X | wpxmls | [random filename] | Added by a variant of the SLAPER TROJAN! |
| X | wqdfadads | sdqdad.exe | Added by the MULDROP.F TROJAN! |
| X | WQK | WQK.exe | Added by the KLEZ.H WORM! |
| ? | wr | WR.EXE | ?? |
| ? | WR Command | wr.exe | ?? |
| X | wrclib | rundll32.exe wrclib.dll,start | Added by the AKBOT-AH WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wrclib.dll" file is found in %System% |
| N | WrCtrl | WrCtrl.exe | Win-Route 4.27 NAT engine on Win2k Pro for connection sharing and security using Win-Route by Tiny Software. A connection sharing/Firewall Application. If service is disabled the program does not work, but you can manually start/stop the service with a shortcut the program installs at any time |
| X | WRDialer | WrDialer.exe | WinPoet DSL dialler |
| ? | WRECK GUARD | ?? | ?? |
| ? | WregBios | wregbios.exe | Desktop Management BIOS (DMI BIOS) related. Apparently invokes the DosBios.exe file. Is it required? |
| U | wrexec | wrexec.exe | Watch Right - monitoring program, part of the PowerTools add-on for AOL. Records instant messages, E-mail, chat. Watch Right appears to be, and functions as an online clock updater which connects with the U.S. National Institute of Standards and Technology. It was designed for parents who wish to keep an eye on what their children are doing online |
| ? | wriste | wriste.exe | ?? |
| U | Write DVD-R! | saimon.exe | Saimon's WriteDVD! "gives total support for DVD-RAM drives. It provides many functions such as setting partitions on DVD-RAM disks and FixDVD! can diagnose and repair UDF formatted disks" |
| X | WRMVan | Windows.exe | Added by the AUTORUN-BGD WORM! |
| U | WrtMon.exe | WrtMon.exe | Related to Presto PageManager which is bundled with Canon Scanners |
| X | ws_d | ws32.exe | Added by the LEGMIR-RL TROJAN! |
| X | ws_ds | sws32.exe | Added by the DELF-GZ TROJAN! |
| X | ws2 32 | svchst.exe | Added by the VOKEN-A TROJAN! |
| X | ws2_64.exe | ws2_64.exe | Added by the AGENT.AOXK TROJAN! |
| X | ws2help | ws2help.exe | Added by a variant of the SMALL.AN TROJAN! |
| X | WSAConfiguration | wmon32.exe | Added by the GAOBOT.BAJ WORM! |
| X | WSAConfiguration | svchostt.exe | Added by the AGOBOT.ZT WORM! |
| X | WSAConfiguration | rpcxmn32.exe | Added by the AGOBOT.ABG WORM! |
| X | WSAConfiguration | win32upd.exe | Added by a variant of the RBOT WORM! |