| Status | Autorun name | Command | Description |
| X | wgeax | wgeax.exe | Added by the IRCBOT-TM WORM! |
| X | wgs3 | wgs3.exe | Added by the LEGMIR-AQH TROJAN! |
| X | WGV | WGV.exe | Added by the ZIPPIE TROJAN! |
| U | WGWLocalManager | WGWLocalManager.exe | Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so. It could be started by creating a shortcut, running it only when connecting to the internet. If internet is used often, it's recommended to leave it in startup so it starts with the system |
| Y | WgwMngr | WgwMngr.exe | Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so |
| X | whagent | whagent.exe | System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here |
| X | what ever | decom.exe | Added by the RBOT-SC WORM! |
| X | What Frenz | FriendEQUALsuX.exe | Added by the BHARAT.A WORM! |
| U | WhatPulse | WHATPU~1.EXE | WhatPulse collects statistics on how much you type on your computer and sends this information to a server. It is not a keylogger which monitors your keystrokes and what you type - it only counts the number of keystrokes |
| U | WhatPulse | WhatPulse.exe | WhatPulse collects statistics on how much you type on your computer and sends this information to a server. It is not a keylogger which monitors your keystrokes and what you type - it only counts the number of keystrokes |
| U | WheelMouse | 4DMAIN.EXE | Mouse software for "Fellowes" Wheelman mouse. Has caused some users problems but shouldn't be needed if you don't use any enhanced features it may provide |
| U | WheelMouse | AMOUMAIN.EXE | A4Tech wireless mouse driver and utility - required if you use non-standard Windows driver features |
| X | WheelsMouse | [path to trojan] | Added by the SOCKSPR-D TROJAN! |
| X | WhenUSave | Save.exe | WhenU.Save adware |
| X | WhenUSearch | Search.exe | WhenU.Save adware |
| X | WhenUSearchWHSE | whse.exe | WhenU.Save adware |
| X | Whistler | whismng.exe | Added by the WHISTLER-F TROJAN! |
| X | Whitechix | brightx.exe | Added by a variant of the SDBOT WORM! |
| N | WhitephonePersonal | WhitePhonePersonal.exe | WhitePhone Personal from Voice Commerce Group - "provides free PC to PC calls globally and access to low cost calls to phones worldwide." Free internet telephony utility using the VoIP (Voice over Internet Protocol). No longer appears to be available |
| U | WHITNEY_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX-4x21 Series multifunction printers |
| U | Whitney2_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX-4725 Series photocopier |
| U | WHITNEY2_XRX_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Xerox Phaser 3200MFP multifunction laser printer |
| U | WhitneyXerox_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Xerox WorkCentre PE220 Series multifunction laser printer |
| X | Whvlxd | Whvlxd.exe | Added by the ZAPCHAS-CS TROJAN! |
| X | whxpin service | [randomname].exe | Added by the RBOT-FWU WORM! |
| X | wiascr | wiascr.exe | Added by the AGENT.AM TROJAN! Note - example names include "XviD", "Winamp Remote", "Windows Media Player" and "Futuremark" |
| N | WIAWizardMenu | RUNDLL32.EXE sti_ci.dll, WiaCreateWizardMenu | Still Image Class Installer - installed with a webcam |
| X | widelink | widelinke.exe | WideLink adware. File located in %Program Files%\widelink |
| X | Widnows Xp Web scan | xpscan.exe | Added by a variant of the SDBOT WORM! |
| X | wifeman | wifeman.exe | Unidentified malware |
| X | Wifi Boot | wifiboot.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Wifi Booter | wifibooter.exe | Added by the IRCBOT.ATH BACKDOOR! |
| X | Wifi Configuration | wificonfig.exe | Added by the IRCBOT.AWB BACKDOOR! |
| X | Wifi Configuration! | wificonfigs.exe | Added by the IRCBOT.AWB BACKDOOR! |
| X | Wifi Connection | wificon.exe | Added by the SLENFBOT.AC WORM! |
| X | Wifi Connection! | wificonnect.exe | Added by the IRCBOT.XEL BACKDOOR! |
| X | Wifi Debug | wifidebug.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Wifi Loader | wifiload.exe | Added by the IRCBOT.XEL BACKDOOR! |
| X | Wifi Loader! | wifiloader.exe | Added by the IRCBOT.XES BACKDOOR! |
| X | Wifi Setup | wifisetup.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | WiFix service | [random filename] | Added by a variant of the SDBOT WORM! |
| X | Wiinamp | [random].exe | Added by the IRCBOT-OH TROJAN! |
| X | WildFlics | WildFlics.exe | Direct-B premium rate adult content dialler |
| ? | WildTangent CDA | RUNDLL32.exe cdaEngine0400.dll, cdaEngineMain | Part of the WildTangent on-line games system. What does it do and is it required? |
| U | WildTangent Web Driver updater | wcmdmgrl.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| N | Wildwire Monitor | WWMon.exe | This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem |
| X | Will I Ever | anqbse.exe | Added by the SDBOT-TK WORM! |
| N | Willow Road | WillowRoad.exe | Willow Road Screen Saver |
| X | WillPolo | WillPolo.vbs | Added by the SOLOW.AF VIRUS! |
| X | wimpas | wimpas.exe | Added by the AGENT2.FGG TROJAN! |
| X | win | regedit -s win.dll | Added by the SEEKER.K TROJAN! Note that regedit is the legitimate Windows Registry Editor and shouldn't be deleted. The "win.dll" file is located in %Windir% |
| X | win | xwinxrpc32.exe | Added by the AGOBOT-MV WORM! |
| X | win | xwinxrpc.exe | Added by the AGOBOT-MV WORM! |
| X | WIN | ehshell.exe | Added by the MYTOB-CQ WORM! |
| X | WIN | windows.exe | Added by the REATLE.C WORM! |
| U | win | homesec.exe | Related to the Sentry Parental Controls software |
| X | Win Antispyware Center | av.exe | Win Antispyware Center rogue security software - not recommended, removal instructions here |
| X | Win Antivir 2008 | Win Antivir 2008.exe | Win Antivir 2008 rogue security software - not recommended, see here |
| X | Win Antivirus 2008 | Win Antivirus 2008.exe | Win Antivirus 2008 rogue security software - not recommended, see here |
| U | Win Chimes | winchi~1.exe | WinChimes - enhancement software for the system clock that runs in the system tray |
| X | Win Comm | WinComm.exe | Added by the WINCOM TROJAN! |
| X | Win Command | command32.exe | Added by the AGOBOT.XQ WORM! |
| X | Win Config | winconfig.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Win CPU | sysin.pif | Added by the RBOT-AXL WORM! |
| X | win ctl app | wuctl.exe | Added by a variant of the SDBOT WORM! |
| X | Win Defender | WinDefender.exe | Added by a variant of the FAKEAV-CLZ TROJAN! Note - this is not the legitimate Microsoft Windows Defender whose filename is MSASCui.exe |
| X | Win Defrag | windfrag.exe | Added by a variant of the SDBOT WORM! See here |
| X | Win Defrag! | windefrag.exe | Added by a variant of the SDBOT WORM! See here |
| X | Win Defrags | defrag.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Win Drivers SSL | TASKMAN4.exe | Added by a variant of the RBOT WORM! |
| X | Win Drivers SSL | hpws.exe | Added by the IRCBOT.67098 WORM! |
| X | Win Drivers SSL32 | hpwsnnsbc.exe | Added by the SPYBOT.MAR WORM! |
| X | Win exe file managr | crss.exe | Added by the RBOT.CCI WORM! |
| X | Win FTP | wintftp.exe | Added by the SDBOT-KE WORM! |
| X | WIN HOST PROCESS | WIN HOST PROCESS.EXE | Added by the KEYLOGGER.CLONE TROJAN! |
| X | Win I5oahder | [worm filename] | Added by the AGOBOT-DS WORM! |
| X | Win INI 32 | msrp32.exe | Added by the RBOT-FZC WORM! |
| X | Win l5oahder | winampa.exe | Added by the AGOBOT.EG WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of %ProgramFiles% whereas this file is located in %System% |
| X | Win leoahder | winampa.exe | Added by the AGOBOT-DU WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of %ProgramFiles% whereas this file is located in %System% |
| X | Win Login | winlogin.exe | Added by the RBOT-AWE WORM! |
| X | Win Microsoft 98 | win14.exe | Added by the RBOT-AKX WORM! |
| X | win msdt service | mswindtc.exe | Added by the SDBOT.DAE WORM! |
| ? | win name | stat.exe | ?? |
| X | Win Net Wks32 | netwks32.exe | Added by the RBOT.AA WORM! |
| X | Win Patch | ntldr.exe | Added by the SDBOT-GS WORM! |
| X | Win Patch | patch.exe | Added by the SDBOT-GL BACKDOOR! |
| X | Win Process Updates | winupdates.exe | Added by a variant of the SDBOT WORM! |
| X | Win Prosess0r | [random filename] | Added by the RBOT-BIT WORM! |
| X | WIN prosessor16 | [random filename].exe | Added by a variant of the SDBOT WORM! |
| X | Win Proxy32 Protocol | bsvtem.exe | Added by a variant of the SDBOT WORM! |
| X | Win Secure Update | [random filename] | Added by the RBOT-AGI WORM! |
| X | Win Security | msw32.pif | Added by the RBOT-AQT WORM! |
| X | Win Security | winsecure.exe | Added by the SLENFBOT.RD WORM! |
| X | Win Security 360 | WinSecurity360.exe | Win Security 360 rogue security software - not recommended, removal instructions here |
| X | Win Server | winserv.exe | Added by the IMISERV.A TROJAN! |
| X | Win Server Updt | wupdt.exe | Added by the IMISERV.A TROJAN! |
| X | Win Server Updt | winserver.exe | Added by a variant of the IMISERV TROJAN! |
| X | Win Server Updt | pxckdla.exe | IEPlugin adware |
| X | Win SSL | SP2s.exe | Added by the RBOT.BBI WORM! |
| X | Win startup | mscfg32.exe | Added by the SPYBOT-AE WORM! |