Note: It is a system process, but if there is a space in front, it is a virus.
Virus Solutions:
1. Download the Antivirus, upgrade to the latest virus database, enter safe mode, turn off the system restore, and check the virus, download address:, avoid infection with virus variants, causing files or photos to be damaged;
Generally, the first step can solve the problem. It is recommended that you install 360, so that the function of adding registry to run is gone, and the following operations are unnecessary.
2. Delete the registry key value of the virus, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Key name: MSIEXEC Key value: ""
The * will also add the following key values to the registry to store its own settings:
HKEY_CLASSES_ROOT\ZPwd_box
HKEY_CLASSES_ROOT\ZPwd_box tmUpgrade_p dword:41bfabb0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ZPwd_box
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ZPwd_box tmUpgrade_p dword:41bfabb0
3. Download the AVG * special killing tool, upgrade the virus database, enter safe mode, turn off the system restore function, and perform full virus prevention.
Process file: wowexec or
Process Name: Microsoft Windows On Windows Execution Process
Produced by: Microsoft Corp.
Belongs to: Microsoft Windows On Windows Execution Process
However, there are spaces in front of this process, which is a virus. Please refer to the following information: Beware of the latest worms
Virus name: Email-Worm.
File size: 13.279k
Writing Language: Microsoft Visual Basic
Shell type: UPX-Scrambler ->
In the past two days, many QQ users have often received QQ emails from others. Please be careful not to open and view them, so as not to get caught in the *.
The worm uses text icons and .extensions to disguise itself, inducing the user to execute the worm body. You will access the 163 mailbox with the number: 163com[20030606] and IP: 202.108.44.153 to obtain upgrade information. Port: 110
User wdboxup
Password:shengjile Password Decoder is a * that is more harmful. It can obtain various timely communication software, EMAIL, online games, online banking, IE, etc. and add registry startup items:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Key name: MSIEXEC Key value: ""
The * will also add the following key values to the registry to store its own settings:
HKEY_CLASSES_ROOT\ZPwd_box
HKEY_CLASSES_ROOT\ZPwd_box tmUpgrade_p dword:41bfabb0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ZPwd_box
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ZPwd_box tmUpgrade_p dword:41bfabb0
Virus Solutions:
1. Download the Antivirus, upgrade to the latest virus database, enter safe mode, turn off the system restore, and check the virus, download address:, avoid infection with virus variants, causing files or photos to be damaged;
Generally, the first step can solve the problem. It is recommended that you install 360, so that the function of adding registry to run is gone, and the following operations are unnecessary.
2. Delete the registry key value of the virus, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Key name: MSIEXEC Key value: ""
The * will also add the following key values to the registry to store its own settings:
HKEY_CLASSES_ROOT\ZPwd_box
HKEY_CLASSES_ROOT\ZPwd_box tmUpgrade_p dword:41bfabb0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ZPwd_box
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ZPwd_box tmUpgrade_p dword:41bfabb0
3. Download the AVG * special killing tool, upgrade the virus database, enter safe mode, turn off the system restore function, and perform full virus prevention.
Process file: wowexec or
Process Name: Microsoft Windows On Windows Execution Process
Produced by: Microsoft Corp.
Belongs to: Microsoft Windows On Windows Execution Process
However, there are spaces in front of this process, which is a virus. Please refer to the following information: Beware of the latest worms
Virus name: Email-Worm.
File size: 13.279k
Writing Language: Microsoft Visual Basic
Shell type: UPX-Scrambler ->
In the past two days, many QQ users have often received QQ emails from others. Please be careful not to open and view them, so as not to get caught in the *.
The worm uses text icons and .extensions to disguise itself, inducing the user to execute the worm body. You will access the 163 mailbox with the number: 163com[20030606] and IP: 202.108.44.153 to obtain upgrade information. Port: 110
User wdboxup
Password:shengjile Password Decoder is a * that is more harmful. It can obtain various timely communication software, EMAIL, online games, online banking, IE, etc. and add registry startup items:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Key name: MSIEXEC Key value: ""
The * will also add the following key values to the registry to store its own settings:
HKEY_CLASSES_ROOT\ZPwd_box
HKEY_CLASSES_ROOT\ZPwd_box tmUpgrade_p dword:41bfabb0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ZPwd_box
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ZPwd_box tmUpgrade_p dword:41bfabb0