| Status | Autorun name | Command | Description |
| X | WinFixer 2005 | wfx5.exe | WinFixer 2005 web installer - "foistware", pretending to be system optimization, protection and recovery software - stealth installed, removal instructions here |
| X | WinFixer 2006 | uwfx6.exe | WinFixer 2006 web installer - "foistware", pretending to be system optimization, protection and recovery software - stealth installed |
| X | WinFixer helper | wfxcwr.exe | WinFixer web installer - "foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here |
| X | WinFixer service | [random filename].exe | Added by a variant of the SDBOT WORM! |
| X | WinFixer_2005 | uwfx5.exe | WinFixer 2005 web installer - "foistware", pretending to be system optimization, protection and recovery software - stealth installed, removal instructions here |
| X | WinFixer2005 | uwfx5.exe | WinFixer 2005 web installer - "foistware", pretending to be system optimization, protection and recovery software - stealth installed, removal instructions here |
| X | WinFixer2006 | uwfx6.exe | WinFixer 2006 web installer - "foistware", pretending to be system optimization, protection and recovery software - stealth installed |
| U | WinFlip | WinFlip.exe | WinFlip from Tokyo Downstairs - a 'Flip-3D' task switcher alternative to the standard Alt+Tab on Windows XP that adds the equivalent 'Aero' feature from Windows 7 and Vista. You can either click on the tray icon, use a keyboard combination or use a mouse gesture. This entry appears when you select "Run automatically" from the options |
| U | WinFlip.exe | WinFlip.exe | WinFlip from Tokyo Downstairs - a 'Flip-3D' task switcher alternative to the standard Alt+Tab on Windows XP that adds the equivalent 'Aero' feature from Windows 7 and Vista. You can either click on the tray icon, use a keyboard combination or use a mouse gesture. This entry appears when you select "Run automatically" from the options |
| X | WinFlyer32.dll | WinFlyer32.dll | Added by the WINFLYER TROJAN! |
| X | winfont | winfont.exe | Added by the DEATH TROJAN! |
| X | winform | winform.exe | Added by the PWS-ALB TROJAN! |
| U | WinFoxV2 | WF2K.EXE | System Tray application that starts up the Winfox utility for a Leadtek Winfast graphics card to restore settings. Can be started manually via Start → Control Panel → Display. Only needed if you wish to run things like the hardware monitor or overclock your card |
| X | WinFX | cssrs.exe | Added by the AGOBOT.FX WORM! |
| X | WinFX | cssrs.exe | Added by the GAOBOT.CD WORM! |
| X | WinFX | lsas.exe | Added by the GAOBOT.CD WORM! |
| U | WinGate Engine Monitor | wgengmon.exe | WinGate Internet Client Dialup Monitor - component of WinGate proxy server software. Displays the status of the WinGate engine, and appears in the system tray of each workstation on the network reassuring clients that their workstations have connectivity with the WinGate Server |
| X | WinGate initialize | WinGate.exe | Added by the LOVGATE.F WORM! |
| X | wingerver2.0.exe | wingerver2.0.exe | Added by the GRAYBRD-AE TROJAN! |
| X | wingo | wingo.exe | Added by the BEAGLE.AW or BEAGLE.AV WORMS! |
| X | wingo | [various filenames] | Added by the BAGLE-AU WORM! |
| N | WinGuage Pro | WGPRO32.EXE | Part of McAfee Nuts & Bolts. "WinGauge is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious". Resource hog. Available via Start -> Programs |
| Y | Winguard | WGFE95.EXE | Dr Solomon's Virex antivirus |
| X | winguard | wingrd32.exe | Added by a variant of the RBOT WORM! |
| X | WinGuard | winguard.exe | Added by the AGOBOT-OQ WORM! The file is located in %System% |
| U | WinGuard | Winguard.exe | Winguard Popup Remover - pop-up stopper. The file is located in %ProgramFiles%\Winguard Popup Remover |
| U | WinGuard Pro | wgp.exe | Winguard Pro |
| X | winguard2 | WinGuard2Up.exe | WinGuard rogue security software - not recommended, removal instructions here |
| N | WinHacker | rundll32.exe wh95.dll, HackMe | WinHacker tweaking utility by Wedge Software. There are far better tweakers and, unlike WinHacker, most are free |
| X | Winhelp | winhe1p.exe | Added by the QQPASS.E TROJAN! |
| X | WinHelp | WinHelp.exe | Added by the LOVGATE.F WORM! Note - this file is located in %System% whereas the valid one is located in %Windir% |
| X | WinHelp | realsched.exe | Added by the LOVGATE-F WORM! Note - this is not the legitimate RealPlayer (realsched.exe) application of the same name. This one is located in %System% |
| X | Winhelp | TkBellExe.exe... | Added by the LOVGATE.Z WORM! |
| X | winhelp | dns32.exe | Added by a variant of the RBOT WORM! |
| X | winhelp | Updadv.exe | Added by the QQPASS-N TROJAN! |
| X | Winhelp | TkBellExe.exe | Added by the LOVGATE.E WORM! |
| X | winhelp | rundll32.exe [path] winhelp.dll,get | Added by the MDROP-DCW TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "winhelp.dll" file is found in %System% |
| X | winhlp.exe | winhlp.exe | Added by the FORMGLIEDER TROJAN! |
| X | winhlp3.exe | winhlp3.exe | Added by a variant of the EASTO.A TROJAN! |
| X | Winhlp32 | Wscript.exe Msexec32.vbs | Added by the GANT.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "Msexec32.vbs" file is found in %System% |
| X | winhlp32.exe | winhlp32.exe | Added by the EASTO.A TROJAN! Note - do not confuse with the legitimate Windows Help (winhlp32.exe) file which is found in %Windir%. This one is found in the "Downloaded Program Files" sub-directory |
| X | winhlpp32.exe | winhlpp32.exe | Added by the GAOBOT.SY WORM! |
| X | Winhost | wintt.exe | Added by the LOLAWEB.B TROJAN! |
| X | Winhost | win.exe | Added by the DLOADER-AP TROJAN! |
| X | Winhost | yahoo.exe | Added by the DELF-KM TROJAN! |
| X | Winhost | winhost.exe | Added by the REATLE.F WORM! |
| X | winhost.exe | winhost.exe | Added by the LOHAV-R TROJAN! |
| X | Winhost1 | yahoo.exe | Added by the DELF-KM TROJAN! |
| X | Winhost1 | winhost.exe | Added by the DELF-JL BACKDOOR! |
| X | Winhost2 | yahoo.exe | Added by the DELF-KM TROJAN! |
| X | Winhost2 | winhost.exe | Added by the DELF-JL BACKDOOR! |
| X | Winhost3 | yahoo.exe | Added by the DELF-KM TROJAN! |
| X | winhost32.exe | winhost32.exe | Added by the TABDIM TROJAN! |
| X | Winhost4 | yahoo.exe | Added by the DELF-KM TROJAN! |
| X | WinHound | WinHound.exe | WinHound rogue security software - not recommended |
| X | WiniBlueSoft | WiniBlueSoft.exe | WiniBlueSoft rogue security software - not recommended, removal instructions here. A member of the WiniGuard family |
| X | WinIeRun | winierun.exe | Added by the RNWATCH-A WORM! |
| X | WiniFighter | WiniFighter.exe | WiniFighter rogue security software - not recommended, removal instructions here. A member of the WiniGuard family |
| X | WinIFixer | WinIFixer.exe | WinIFixer rogue security software - not recommended, removal instructions here |
| X | WiniGuard | WiniGuard.exe | WiniGuard rogue security software - not recommended. There are number of variants in this family sharing the same user interface - see here |
| X | winimage | wvsvc.exe | Added by the RBOT.TX WORM! |
| X | wininet | wininet.exe | Added by the STUBBOT-C WORM! |
| X | wininet.dll | regperf.exe | Added by the ZLOB TROJAN and variants! |
| X | wininet32 | wininet32.exe | Added by the RAZNEW-A TROJAN! |
| X | wininetd | wininetd.exe | Added by the WINET TROJAN! |
| X | Winini.dll | winini.vbs | Added by the STARTP-M TROJAN! |
| X | Winini32 | winini32.exe | Added by the AGOBOT-J WORM! |
| X | wininit | wininit.exe | Added by the WOLLF.16 TROJAN! Note - this is not the legitimate wininit.exe process from Vista/7 which is always located in %System% and should not normally figure in Msconfig/Startup! |
| X | WinInit | Win86.exe | Added by the SMALL-PB TROJAN! |
| X | winint | winint.exe | Added by the SDBOT-ADA WORM! |
| X | winIogom | winIogom.exe | Added by the BANCBAN-ML TROJAN! |
| X | winipsec | winipsec.exe | Unidentified malware |
| U | WinIRXHelper | WinIRXHelper.exe | MSI Media Center Deluxe software - see here |
| X | winis | winis.exe | Added by the RBOT-WI WORM! |
| X | WiniShield | WiniShield.exe | WiniShield rogue security software - not recommended, removal instructions here. A member of the WiniGuard family |
| X | Winjava xml | dirx9.exe | Added by the HAXDOOR ROOTKIT! |
| X | Wink*.exe | Wink*.exe [* = random char] | Added by a variant of the KLEZ WORM! |
| U | Winkb6 | winkb6.exe | Part of We-Blocker - gives parents the opportunity to monitor their children's Internet access and provide them with age-appropriate content, while filtering out sites that contain adult content. Works in conjunction with Winkb6 and both files are needed to run We-Blocker |
| X | WinKernel | WinKer.exe | Added by the MIRAB or SERVIDOR TROJANS! |
| X | WinKernel | [path to virus] | Added by the PLEA VIRUS! |
| X | winkernel32 | wWin32.com | Added by the BANSAP TROJAN! |
| U | WinKey | winkey.exe | Loads Copernic's WinKey. Used to map out Windows key hotkey combinations. Not required for the system, but is necessary for this to be running if you use these hotkey combos |
| X | winla | winla.exe | Added by the DLOADR-AQL TROJAN! |
| X | winldr | [path to file] | Added by the VIDLO-P TROJAN! |
| X | winldr | Rechnung.pdf.exe | Added by the ACS TROJAN! |
| U | winlgn | winsplg.exe | Related to the Sentry Parental Controls software |
| X | winlgz2 | winlgz2.exe | Added by the KILLFIL-Q TROJAN! |
| X | winlibs.exe | winlibs.exe | Added by the EVAMAN.C WORM! |
| X | WinLibUpdate | libupdate.exe | Added by the BIONET series of TROJANS such as BIONET.31 or BIONET.310 |
| X | WinLibUpdate32 | libupdate32.exe | Added by the BIONET.405 TROJAN! |
| X | WinLibUpdte | libupdte.exe | Added by the BIONET.318 BACKDOOR! |
| X | Winlink | winlink32.exe | Added by the GAOBOT.AAY WORM! |
| X | winllogon | winllogon.exe | Added by the DELF-KK TROJAN! |
| X | Winlme | windll.exe | Added by the GOP.F WORM! |
| U | WinLoad | Winload.exe | PCTattletale is a surveillance software program that monitors user activity, logs keystrokes, and takes screenshots. Uninstall this software unless you put it there yourself. Note - do not remove this file if you use Vista, a legitimate file with the same name and location (%Windir%\System32) is used during bootup. Removing this file can cause problems with your OS |
| X | winload | winload.exe | Added by the AGENT-GNY TROJAN! Note - the file is located in %ProgramFiles%\Internet Explorer |
| X | WinLoader | [random filename] | Added by variants of the SUBSEVEN TROJAN! |
| X | winlocatorupdate | updatewinlocator.exe | Locator adult content toolbar related |
| X | winlog | wintask.exe | Added by the SDBOT-GR BACKDOOR! |
| X | winlog | winlog.exe | Added by the GAOBOT.DF WORM! |