Pc-processes > W > ADSL Geek

PC process registry

Find if your processes are spyware or a virus:[A][B][C][D][E][F][G][H][I][J][K][L][M][N][O][P][Q][R][S][T][U][V][W][X][Y][Z]

Results for W:

Process NameStatusStartup Item NameComments
winrecon.exeN!NoLoadWinRecon keystroke logger/monitoring program - remove unless you installed it yourself!
wuauqmr.exeXNvCpTDaemonAdded by the CULT-B WORM!
winSOCKS.exeX(*)API MachineHomepage hijacker, see here (* = any digit)
win32API.exeX(*)RunHomepage hijacker, see here (* = any digit)
winhelp.exeX(Default)Added by the BLACKMAL.C WORM! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank
winbas12.exeX(Default)Adware, CoolWebSearch parasite related - detected by Kaspersky as the VB.DU TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank
winlog.exeX(Default)Unidentified adware. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank
winligom.exeX(Default)Added by the RBOT-GAI WORM! Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run, HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank
wstcl.exeX*Microsoft UpdateAdded by the STMU TROJAN!
wucxt.exeX*Microsoft UpdateAdded by the STMU TROJAN!
wuytc.exeX*Microsoft UpdateAdded by the STMU TROJAN!
WerFault.exeN*WerKernelReportingPart of Windows Error Reporting technology (WER) for Vista. WER captures software crash and hang data from end-users who agree to report it - see here
wrauclt.exeX*windows updateAdded by the RBOT-QU WORM!
wuanclt.exeX*windows updateAdded by the RBOT-PG WORM!
wuaucrlt.exeX*windows updateAdded by the SPYBOT.HUR WORM!
wuraclt.exeX*windows updateAdded by the RBOT-PO WORM!
wurauclt.exeX*windows updateAdded by the RBOT-SY WORM!
wsctl.exeX*windows updateAdded by the SPYBOT.PR WORM!
wkmst.exeX*windows updateAdded by the SDBOT.AVD WORM!
wscxt.exeX*windows updateAdded by the RBOT.AOS WORM!
waurclt.exeX*windows updateAdded by a variant of the RBOT WORM!
winstats.exeX*winstatsAdded by the GARGAFX TROJAN!
w****.exe [* = random char]X*wuauclt.exeAdded by a variant of the RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe, wtmsv.exe, wxmst.exe, wmsvc.exe and so on...
wininfo.exeX,main drive LoaderSuspected malware as it appears in 3 different registry locations - see here
winlogon.exeX.ProgAdded by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
WARN0190.EXEU0190 WarnerAnti-dialer program (Germany)
WARN0900.EXEU0900 WarnerAnti-dialer program (Germany)
WebMailSpy.exeX1WinCfg32WebMailSpy spyware
winmgr.exeX252Added by the LEGMIR-AT TROJAN!
winlog0n.exeX9mAdded by the LEGMIR-AQK TROJAN!
wincms.exeX@Added by the RBOT.CBR WORM!
w32NTupdt.exeXA New Windows UpdaterAdded by the MYTOB.BM WORM!
winpppoverethernet.exeYa-winpoet-serviceWinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking
winsto.exeXAccess Control AppDetected by Kaspersky as the AGENT.DGO TROJAN! See here
wcescom32.exeXActiveSyncAdded by the MANCSYN-E TROJAN!
wini.exeXAdAwareAdded by the RBOT-XN WORM!
winlogon.exeXAdministratorAdded by the RUBBLE-C WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
windrv.exeXADriverAdded by the DELF.WG TROJAN!
windefault.exeUAFAFilterAFAFilter - internet filter software
WinServ.exeXAKEYNAMEAdded by the EVILBOT.C TROJAN!

Most of the data for these PC Process lists are kindly provided to the Internet community by the awesome guys from http://www.sysinfo.org/

"Y" - Normally leave to run at start-up
"N" - Not required or not recommended - typically infrequently used tasks that can be started manually if necessary
"U" - User's choice - depends whether a user deems it necessary
"X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
"?" - Unknown

Variables:
%System% - refers to the System folder; by default this is C:\Windows\System (9x/Me), C:\Winnt\System32 (NT/2K), or C:\Windows\System32 (XP/Vista)
%Windir% - refers to the Windows installation folder; by default this is C:\Windows (9x/Me/XP/Vista) or C:\Winnt (NT/2K)
%UserProfile% - refers to the current user's profile folder; by default this is C:\Documents and Settings\ (NT/2K/XP) or C:\Users\ (Vista)
%ProgramFiles% - refers to the Program Files folder; typically the path is C:\Program Files