 |
ctxma.exe |
*Microsoft Update
Added by the STMU TROJAN! |
 |
cxma.exe |
*Microsoft Update
Added by the STMU TROJAN! |
 |
CSRSS.EXE |
.svchost
Added by the WEBUS.F TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
csrss.exe |
.TEXTCONV
Added by the WEBUS TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
csrss.exe |
.WMAudio
Added by the WEBUS TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
CyberoamClient.exe |
24Online Client
Related to Cyberroam from Elitecore Technologies Ltd |
 |
csrss32.exe |
27
Added by the SLSORVE-D TROJAN! |
 |
cpqa1000.exe |
A1000 Settings Utility
Compaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan, print, copy and fax. Only required if you use these features |
 |
CAGENT.EXE |
ABBYY Community Agent
Installed with the Optical Character Recognition (OCR) software that comes bundled with a Compaq A3000 all-in-one printer/scanner. Its function appears to be to link you to the internet in an attempt to buy the 5.0 version of the software |
 |
cseraser.exe |
AbsoluteShield Internet Eraser
AbsoluteShield Internet Eraser - "protects your privacy by cleaning up all the tracks of your Internet and computer activities" |
 |
clockplus.exe |
AccessoriesPlus
Clock Plus, part of Accessories Plus allows you to select from dozens of alternatives for the Windows clock |
 |
cerf.exe |
Advanced Internet Protocol
Added by a variant of the SPYBOT WORM! |
 |
ccapp2.exe |
Antivirus Protection Services
Added by the RBOT.EXI WORM! |
 |
companion.exe |
AOL Companion
Part of the AOL Connection Suite and installs an icon on the system tray offering easy access to AOL's additional utilities and functions. This program is a non-essential process, and is installed for ease of use |
 |
config.com |
AolCon
Added by the TAPLAK WORM! |
 |
ClShield.exe |
APVXDWIN
"Panda ClientShield with TruPrevent is designed for companies that want the best protection for their workstations. It protects against viruses and other known and unknown threats including spam, spyware, dangerous or time-wasting content, phishing scams, hackers and intruders" |
 |
canada.exe |
ASDPLUGIN
AsdPlug premium rate adult content dialer variant |
 |
czech.exe |
ASDPLUGIN
AsdPlug premium rate adult content dialer variant |
 |
csrss.exe |
ASP.NET State Service
Added by the DLOADER-QI TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
crsass.exe |
ASP.NET State Service
Added by the BANLOAD-M TROJAN! |
 |
CLI.exe SystemTray |
ATI Catalyst™ System Tray
System Tray access to ATI's Catalyst™ CONTROL CENTER. Note that this has "SystemTray" appended to CLI.exe in the "Command" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktop |
 |
cli.exe runtime |
ATICCC
ATI's Catalyst™ CONTROL CENTER. Required if you want to change graphics settings on a regular basis but you must have internet access and Microsoft's .NET framework installed. Note that this has "runtime" appended to cli.exe in the "Command" column of MSCONFIG. Recommend that start the program manually via Start → Programs → ATI Catalyst Control Center → Advanced → Restart Runtime as it can cause problems when starting Windows |
 |
CLIStart.exe |
ATICCC
Puts the ATI Catalyst™ Control Center Icon/Shortcut on the System Tray - available via Start → Programs |
 |
csrss.exe |
AtiSound
WinSpy surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "ComRoot" subfolder |
 |
cdaccess.exe |
Auto CD-ROM Startup
Added by the SPYBOT.BLA WORM! |
 |
crcss.exe |
Auto updat
Added by the SDBOT.AAG WORM! |
 |
cftmon.exe |
autoload
Detected by Symantec as the SILLYFDC WORM! See here |
 |
cxtpls_loader.exe |
Autoloaderaproposclient
AproposMedia adware |
 |
CACHE.RVD |
Automatic Media Update
Added by an unidentified WORM/TROJAN! |
 |
ciscv.exe |
AutoVirusProtection
Added by a variant of the RBOT WORM! |
 |
csrss.exe |
BagleAV
Added by the NETSKY.AB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
charms.exe |
Bingo Charm
Some kind of screen icon kind of like desk flag, but it gives you a choice of icons? |
 |
Cjstsr.exe |
BJ Printer Status Monitor
Canon BJ printer status monitor |
 |
CJSTRxx.EXE |
BJ Status Monitor 5xx
Canon printer status monitor - where "xx" is different depending upon the version. Not required as you can check the printer status via My Computer -> Printers |
 |
cdf.exe |
bjcfd
BroadJump Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs |
 |
CCAPPS32.EXE |
Blah service
Added by the RBOT.TV WORM! |
 |
csrs.scr |
boby
Added by the BANCBAN-PC TROJAN! |
 |
CVT.exe |
Bron-Spizaetus
Added by the RONTOKBRO WORM! |
 |
Commandr.exe |
Browser Launcher
Logitech internet keyboard "Commander" software - loads the software for the shortcut keys on the keyboard. Not required unless you want to use the short cut keys |
 |
csrss.exe |
BuildLabs
Added by the WEBUS TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
c:archiv~1win.com |
c
Added by the CUYDOC TROJAN! |
 |
CYB2K.EXE |
C2K
CYBERsitter 2000 or 2001 - anti-adult content filter primarily. Required if you want the sites you visit filtered without having to load the software every time you launch your browser |
 |
c32cs2.exe |
c32cs2
Cyber Sentinel - internet filtering software |
 |
CAVTray.exe |
CaAvTray
eTrust? EZ Antivirus system tray application from Computer Associates |
 |
Cabchk.exe |
Cabchk
Added by the GEMA TROJAN! |
 |
Cabchk32.exe |
Cabchk32
Added by the GEMA TROJAN! |
 |
CABCInstall.exe |
CABCInstall
Ignite Technologies (was CABC) content delivery software |
 |
Cacheman.exe |
Cacheman
Freeware disk cache tweaker from Outer Technologies. Should only be run once and not loaded at start-up |
 |
CacheMgr.exe |
CacheMgr
Sophos Antivirus Remote Update |
 |
CacheSentry Pro.exe |
CacheSentry Pro
"CacheSentry Pro is a program that takes over the management of the Internet Explorer (and AOL) web browser cache" |
 |
cacstart.exe |
CACStarter
Cash A Check - check writing software |
 |
CdzSvc.exe |
Cadenza
Cadenza mNotes for Palm and Pocket PC enables users to access Lotus Notes on their mobile devices |
 |
cads.exe |
CADS
Cyber Sentinel - internet filtering software |
 |
CafeStation.exe |
CafeStation
"CafeSuite is the solution for your internet cafe. Our software provides you with ameans to control the workstations, manage customer database, sell products and generate detailed reports and statistics" |
 |
cafw.exe |
cafwc
CA Personal Firewall - part of the CA Internet Security Suite |
 |
CAgent.exe |
CAgent
Abbyy Fine Reader OCR (Optical Character Recognition) software for scanning and converting documents |
 |
CahootWebcard.exe |
CahootWebcard
"The Cahoot Webcard is a virtual card that allows you to use your Cahoot credit card online without ever having to expose your real card numbers over the web. It works by generating one-off transaction numbers as a substitute for your real cahoot credit card details". Run manually when needed |
 |
caissdt.exe |
CaISSDT
Computer Associates Dashboard Tray applet |
 |
calrem.exe |
Cal Reminder Shortcut
Produces a pop-up reminder of events scheduled using the MS Office Calendar |
 |
CALC32.EXE |
CALC32
Added by the SPYBOT-EC WORM! |
 |
calendar.exe |
Calendar 200X Reminder
Calendar 200X - shows holidays, reminders of various anniversaries,tasks etc |
 |
cs.exe |
Calendarscope
Calendarscope calendar software |
 |
calk.exe |
calk
Added by the STARTPA-FH TROJAN! |
 |
Call32.exe |
Call32
Added by the SPAMMIT-H TROJAN! |
 |
cbpopw.exe |
CallBumping
Related to the Gazel 128 PCI ISDN adapter. Required if you use it |
 |
CamCheck.exe |
CamCheck
NuCam camera software related |
 |
Cameno.exe |
Cameno
Cameno is a program which brings tabbed windows to MSN Messenger 6.0 and above |
 |
CAMDET~*.EXE |
Camera Detector
ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically |
 |
Camdetect.exe |
Camera Detector
ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically |
 |
Canada.exe |
Canada
Known to be a dialler - but is it maliscous or clean? |
 |
canary-std.exe |
Canary
Canary keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
command32.exe |
candy
Added by the RBOT-LV WORM! |
 |
CAPM1LAK.EXE |
Canon PC1200 iC D600 iR1200G Status Window
Cannon printer related - is it required in startup? |
 |
Cjstlst.exe |
Canon Printer Monitor BJCxxx
Trayicon for Canon printer. xxx denotes model. Available via Start -> Programs |
 |
CNSLMAIN.exe |
CanonSolutionMenu
Canon's Solution Menu dialog box leads you quickly toward documentation, utilities, and help files |
 |
CAP3ONN.EXE |
CAP3ON
Canon driver, purpose unknown. Is it required in startup? |
 |
capfasem.exe |
capfasem
CA Personal Firewall - part of the CA Internet Security Suite |
 |
capfax.exe |
Capfax
PhoneTools fax software |
 |
capfupgrade.exe |
capfupgrade
CA Personal Firewall - part of the CA Internet Security Suite |
 |
CAPing.exe |
CAPing
Citibank Citianywhere software |
 |
Capon.exe |
Capon
Canon printer driver |
 |
Caponn.exe |
Capon
Canon printer driver |
 |
crssr.exe |
CaptionMgr32
Added by the ZAR.A WORM! |
 |
capture.exe |
capture
Added by the THEEF-B TROJAN! |
 |
capexp.exe |
Capture Express 2000
Capture Express - screen capture utility |
 |
Capture.exe |
CaptureBat
!Quick Screen Capture from EtruSoft Inc. - "allows you to take screenshots from any part of your screen in more than 10 ways, and save images in BMP/JPG/GIF formats" |
 |
CarboniteUI.exe |
Carbonite Backup
"Carbonite?s online backup service starts automatically and works quietly and continuously in the background protecting your data" |
 |
Care20.exe |
Care20
TopMoxie adware |
 |
Care2GTU.exe |
Care2GTU
Care2 Green Thumbs-Up (from the Care2 site). Every online purchase helps environmental causes; tells you how eco-friendly a company really is, thanks to over 200 company profiles from Coop America. Saves 1 square foot of rainforest every day you use it. If it works and you like it, keep it |
 |
carpserv.exe |
carpserv
Associated with Zoltrix and Conexant modems - enables the internal modem speaker, allowing you to listen to the dial-up sounds for example |
 |
CARPserver.exe |
CARPserver
Added by the BANKER-AN TROJAN! |
 |
carpserv.exe |
CARPservice
Associated with Zoltrix and Conexant modems - enables the internal modem speaker, allowing you to listen to the dial-up sounds for example |
 |
conflicted.exe |
cartao
Added by the DADOBRA-DV TROJAN! |
 |
casclient.exe |
CAS Client
CasinoClient adware |
 |
cas2stub.exe |
Cas2Stub
CasinoClient adware |
 |
CasAgnt.exe |
CasAgnt
Program by Extended Systems which allows you to sync your Casio PDA with your PC |
 |
CaseyVideo.exe |
caseyvideo
Malware causing p0rn popups |
 |
caseyvideo[*].exe [* = digit] |
caseyvideo
Malware causing p0rn popups |
 |
cashback.exe |
CashBack
Part of eXact Advertising Software, consisting of "CashBack by BargainBuddy", BullsEye Network and NaviSearch |
 |
Cashfiesta.exe |
CashFiesta
CASHFIESTA.A pay-per-surf adware |
 |
Cashbar.Exe |
Cashsurfers Cashbar Navigator
Cashsurfers CashBar Navigator - "The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers and deals" |
 |
cassandra.exe |
Cassandra
SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as a variant of the KREPPER TROJAN! |
 |
casstub.exe |
CasStub
Added by the CASS-A TROJAN! |
 |
catsrv.exe |
catsrv
Added by the PAPLOK TROJAN! |
 |
CAVRID.exe |
CAVRID
eTrust? EZ Antivirus Real Time Infection Report from Computer Associates |
 |
CAVS.exe |
CAVS
Cheyenne (now eTrust) antivirus |
 |
CAZNOVAS.exe |
CAZNOVAS
Added by the CAZNO TROJAN! |
 |
CBACK.EXE |
CBACK.EXE
Added by the PENTA-A TROJAN! |
 |
CBWAttn.exe |
CBWAttn
Required for Bitware to answer incoming faxes, can cause sleep mode problems |
 |
CBWHost.exe |
CBWHost
Required for Bitware to answer incoming faxes, can cause sleep mode problems |
 |
CBWDial.exe |
CBWUser
Associated with Bitware that integrates fax, voice, pager, and data communications on your desktop |
 |
comet.exe |
CC2KUI
Comet Cursor adware |
 |
ccApp.exe |
ccApp
Part of Norton AntiVirus. Auto-protect and E-mail check will not function without this |
 |
ccApps.exe |
ccApps
Added by the KANGAROO-B WORM! |
 |
ccdoctor.exe |
CCDoctorLogonTesting
Checks your system to make sure it's configured properly for running IBM Rational ClearCase, a source code management tool. ClearCase is fairly sophisticated so there are a lot of system-related things that can cause it grief. If you run ClearCase you should not disable this as it provides a valuable service, but technically it isn't required to use the ClearCase product |
 |
CCenter.exe |
ccenter
RAV AntiVirus |
 |
ccEvtMgr.exe |
CcEvtMgr
Part of Norton AntiVirus 2003. Event manager for scheduling weekly scans and or automatic virus updates. Used to start automatically via "ccApp" and was not required as a seperate entry but a recent update changed this |
 |
ccEvtMrg.exe |
ccEvtMrg.exe
Added by the RBOT.GZ WORM! |
 |
ccHelp.hta |
ccHelp
"Searchq" adware |
 |
ccleaner.exe |
ccleaner
CCleaner - removes unused files from your system |
 |
csrss.exe |
ccpApps
Added by the WEBUS TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
CCPROXY.EXE |
ccProxy
Part of Norton Internet Security, proxy server that is used to support the parental controls. If you turn parental controls off at user level the process is not loaded. Reported to cause excessive CPU usage |
 |
ccPrxy.exe |
ccPrxy.exe
Added by the SHIPUP-H WORM! |
 |
CCPXYSVC.exe |
CcPxySvc
Part of Norton's AntiVirus 2003, Internet Security and Firewall products. E-mail proxy service - required for E-mail scanning and the firewall |
 |
ccRegVfy.exe |
CcRegVfy
Part of Norton AntiVirus 2003. "ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack" |
 |
ccSetMgr.exe |
ccSetMgr
Part of Norton AntiVirus 2004. What does it do? |
 |
ccSvcHst.exe |
ccSvcHst.exe
Added by the SDBOT-DIW WORM! |
 |
ccsvit.exe |
ccsvit.exe
Added by the STARTPA-HP TROJAN! |
 |
cctray.exe |
cctray
Part of CA Internet Security Suite |
 |
ccUpdate.exe |
ccUpdate
Added by the AGOBOT.YS WORM! |
 |
ccUpdMgr.exe |
ccUpdMgr
In Loco Parentis remote surveillance software. Uninstall this software unless you put it there yourself! |
 |
CCU_TrayIcon.exe |
CCUTRAYICON
Related to Traybar Launcher from Intel Corporation belonging to Intel(R) Viiv? |
 |
cdstorager.exe |
CD Storage Master
CD Storage Master - a program designed to catalog CD information, boasts a number of handy features for organizing your collection |
 |
cd1.exe |
cd1
Premium rate adult content dialler |
 |
CDANTSRV.exe |
CDANTSRV
C-Dilla License Management software. Used for any program that uses C-dilla Protection, example: 3D Studio Max 4.x. It loads as a service automatically but is not needed unless you run said program. Can be started and stopped manually |
 |
Cdcompat.exe |
Cdcompat
Added by the GEMA TROJAN! |
 |
cddrv32.exe |
cddrv32
Added by a variant of the CRYPTER.C TROJAN! |
 |
cdi.exe |
CDInterceptor
CD indexer for measuring the speed of CD players |
 |
cdloader2.exe |
cdloader
From MagicJack - "A softphone device that allows you to attach an analog phone into the PC so you can have a traditional-style phone system in your house without any monthly charge" |
 |
cdnup.exe |
CdnCtr
CNNIC Update pest |
 |
cdromcntrl.exe |
Cdrom Controller
Added by the BATTRY-A TROJAN! |
 |
cds.exe |
cds
Added by the SPYMON TROJAN! |
 |
CDSpeed.exe |
CDSpeed.exe
Detected by Kaspersky as the IRCBOT.AEX TROJAN! |
 |
CDTray.exe |
CDTray
On HP PCs, this is the small CD icon next to the time |
 |
CeEKey.exe |
CeEKEY
Hot Key utility included on Toshiba Satellite laptops |
 |
cepmtray.exe |
CeEPOWER
Toshiba's Power Management Utility - allows the user to setup different profiles for both AC power and Battery Power on laptops. Contols CPU speed, Monitor Shut Off, Hard Drive Shut-Off, Monitor Brightness, System Stand-by and System Hibernate times |
 |
Ceic.exe |
Ceic
?? |
 |
certreg.exe |
CertReg
Related to Gemplus Card Reader |
 |
CertStoreInit |
CertStoreInit
Aladdin eToken authentication and password management |
 |
Cell.exe |
CEventMgr
Added by the BIFROSE-AK TROJAN! |
 |
CFD.exe |
CFD
BroadJump Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs |
 |
cfgboot.exe |
cfgboost
Added by an unidentified WORM or TROJAN! |
 |
cfgintpr.exe |
cfgintpr
Configuration Interpreter - part of Tiny Personal Firewall V4 |
 |
cfgwiz.exe |
cfgwiz
Introduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it |
 |
cFosDNT.exe |
cFosDNT
cFos DSL Modem driver related. What does it do and is it required? |
 |
cfosinst.exe |
cFosInst_Check
cFos DSL Modem driver related. What does it do and is it required? |
 |
cFosSpeed.exe |
cFosSpeed
cFos Software Internet acceleration program related. Note - may be necessary for the software to work properly |
 |
CFSServ.exe |
CFSServ.exe
Belongs to Toshiba's configfree utility and searches for Wireless Devices |
 |
cfy.exe |
cfy
Surfenhance.com SearchForIt adware variant |
 |
CGIAGENT.EXE |
CGI Firewall Script
Added by the BROPIA-U WORM! |
 |
cgserver.exe |
CGServer
Associated with an Eicon Networks ISDN or ADSL modem. Call Guard Server (CGserver) watches your modem and blocks incoming or outgoing calls. You need cgard.exe (from Startmenu) to configure cgserver with rules and telephone numbers. Good against unwanted dialer programs |
 |
cgtask.exe |
Cgtask Services
Added by the LALA.B TROJAN! |
 |
cgywin32.exe |
Cgywin
Added by the RBOT-AEI WORM! |
 |
ChamClock.exe |
ChamClock
Chameleon Clock - system tray clock replacement |
 |
chngline.exe |
ChangeLines
?? |
 |
Chatango.exe |
Chatango
Chatango - "allows people to be connected in real time through their Web browsers. Include your Chatango contact link or button when you create eBay auctions, blogs, personal websites, Friendster profiles, and your visitors will be able to contact you instantly, without downloading anything, or registering. Alo use it to send email to your friends, allowing them to respond to you in real time!." The 'MessageCatcher' icon in the System Tray notifies you when you get a message. When you get a message, a little alert pops up, which you can click on and start chatting immediately |
 |
ChatStat.exe |
ChatStat
ChatStat from ChatStat Technologies, Inc. Provides live chat assistance in up to 16 languages allows your operators to be more productive |
 |
chcenter.exe |
Chcenter
IMSI HiJaak - "the easiest way to convert, capture, and manage all your graphic files" |
 |
chcp.exe |
chcp.exe
Detected by Kaspersky as the SDBOT.BMH WORM! See here |
 |
che.ocx.vbs |
che32
Added by the ADENU-B VIRUS! |
 |
Check.exe |
Check
Added by the VB-DRN WORM! |
 |
cmesseng.exe |
Check Messenger
Check Messenger from Qchex.com - program that helps you manage the activity of your Qchex account. Qchex appear to be no longer in buisness |
 |
Check&Get.exe |
Check&Get
Check&Get from ActiveURLs. Manages your browser bookmarks and favorites. Monitors Web sites for changes and updates, captures and highlights the changed contents |
 |
CheckCWupdate.exe |
CheckCustomWorksUpdate
Update checker, part of CustomWorks - "customize any embroidery designs to design your own unique creations" |
 |
ChkDial.exe |
CheckDialer
Added by the CheckDialer modem connection monitoring tool |
 |
CheckIt86.exe |
CheckIt 86
CheckIt 86 popup blocker |
 |
ct.exe |
checktime
Found in the HPSelectFrontend directory on a HP machine. What is it's purpose and is it required? |
 |
chiCkie.exe |
chiCkie
Added by the CHIKO WORM! |
 |
ChikkaLauncher.exe |
ChikkaDefault
Chikka PC text messanger and IM client |
 |
CHINA11MSN.EXE |
china11msn
Added by the ENVID.O WORM! |
 |
cstar.exe |
ChineseStar
Chinese language support software |
 |
chkdsker.exe |
CHK Disker
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
chkntf.exe |
CHK NT
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
CHKADMIN.EXE |
CHKADMIN
Compaq Network Management System. When running, it places an icon in the system tray titled "Intelligent Manageability" |
 |
chk_disk.exe |
ChkDisk
Added by an unidentified WORM or TROJAN! |
 |
ChkMail.exe |
ChkMail
Mail-checking program supplied with Acer notebooks |
 |
CHOICEMAIL.EXE |
ChoiceMail
ChoiceMail from DigiPortal Software. Block spam with an Email firewall |
 |
Choke.exe-blahh |
Choke
Added by the CHOKE WORM! |
 |
chostsv.exe |
chostsv
Added by the BANPAES.C TROJAN! |
 |
CHTVINIT.EXE |
ChronitelInitTV
?? |
 |
chrono.exe |
chrono
Chronograph is a simple utility that synchronizes internal computer clock to the atomic time. Chronograph automatically maintains correct time using atomic clock servers of the National Institute of Standards and Technology (NIST)." Shows seconds and shows the date without having to hover the mouse. Shows a calendar when hovered over |
 |
cisvr.exe |
Ci Svr
Detected by Trend Micro as the IRCBOT.AWN BACKDOOR! See here |
 |
ci1gnt.exe |
ci1gnt
Detected by Kaspersky as the AGENT.DHU TROJAN! |
 |
cihost.exe |
cihost.exe
Added by the LINST TROJAN! |
 |
CIJxP2PS.EXE |
CIJxP2PSERVER
Compaq printer utility which is required in order to make the printer work correctly - "x" depends upon the model, ie, for IJ300 x=3, for IJ700 x=7 |
 |
CingularCCM.exe |
Cingular Communication Manager
Cingular Communication Manager - now taken over by AT&T. "provides a robust set of wireless communication tools for businesses and individuals. With wireless access to email, the Internet, business applications and corporate intranets, mobile users can be more productive while they're out of the office" |
 |
CmdPrompt32.pif |
Cinnabd Prompt32
Added by the ASSIRAL-B WORM! |
 |
che7e1~1.exe |
CIO
ChatItOut webcam chat program |
 |
CISRVR.EXE |
CISrvr Program
Related to internet setup on Compaq PC's |
 |
Cissi.exe |
Cissi
Added by the CISSI.A WORM! |
 |
CitiUCS.exe |
CitiUCS
Citibank Virtual Account Numbers - "With this free service for Citi cardmembers, you never have to give out your real credit card number online" |
 |
CitiVAN.exe |
CitiVAN
Option from Citibank to change a credit card number in a random fashion for each purchase. The number will only be used once and never again |
 |
cjb.exe |
cjb
Added by and unidentified WORM or TROJAN! See here |
 |
CJet.exe |
CJET
FFToolBar adware toolbar |
 |
Cjstcom.exe |
Cjstcom
Canon printer BJ status language monitor |
 |
ClamTray.exe |
ClamWin
ClamWin antivirus |
 |
clcbt.exe |
clcbt.exe
Added by the AGENT.CBA TROJAN! |
 |
clcl3.exe |
clcl3
Added by the AGENT.ES TROJAN! |
 |
clcl7.exe |
clcl7
Added by a variant of the Covert Sys Exec TROJAN! |
 |
CLCL.exe |
CLCLSet
CLCL clipboard caching utility |
 |
CCAAgent.exe |
Clean Access Agent
Cisco Clean Access Agent from Cisco Systems, Inc |
 |
cleanmg.exe |
Clean Mgr
Detected by Trend Micro as the IRCBOT.BBO BACKDOOR! See here |
 |
cleanall.exe |
CleanEasyImg
?? |
 |
CleanReg.exe |
CleanRegPath
Apparently Annex A ADSL modem related. What does it do and is it required? |
 |
Csinsm32.exe |
CleanSweep Smart Sweep- Internet Sweep
Automatic logging of installs from Norton CleanSweep - available via Start -> Programs |
 |
CSUSEM32.EXE |
CleanSweep Useage Watch
Quarterdeck/Norton CleanSweep component - tracks how often you use files and alerts you to files that have not been used for a specified period of time |
 |
CLEANT~1.EXEB |
CleanTemp
CleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory |
 |
CleanTemp.exe |
CleanTemp
CleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory |
 |
cleanup.exe |
CleanupProgram
In a C:Sonysys folder - Sony Vaio related? |
 |
clean_service.cmd |
clean_service
Added by the REFAZ WORM! |
 |
CK.exe |
CleverKeys
CleverKeys - "is free software that provides instant access to definitions at Dictionary.com, synonyms at Thesaurus.com, facts at Reference.com and more ? from almost all Windows programs, including word processors, Web browsers and most e-mail programs" |
 |
clfmon.exe |
clfmon
Added by the TACTSLAY.E TROJAN! |
 |
clfmon.exe |
clfmon.exe
Added by the AGENT-BJ TROJAN! |
 |
cliconfig.exe |
Cli Confg
Added by a variant of the SPYBOT WORM! See here |
 |
clisrv.exe |
CLI Services
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
clickr~1.exe |
Click Radio Tuner
ClickRadio - subscription service playing radio music via the internet |
 |
ClickT~1.EXE |
Click Tray Calendar
ClickTray Calendar - shows holidays, reminders of various anniversaries,tasks etc |
 |
ClickMe.exe |
ClickMe
ClickM "JOKE" program |
 |
Clickoff.exe |
Clickoff
Clickoff automatically dismisses annoying dialog boxes |
 |
CTB.EXE |
ClickTheButton
ClickTheButton adware |
 |
csrss.exe |
ClickTheButton
ClickTheButton adware. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "drivers" subfolder |
 |
cd_load.exe |
ClickTheButton
Added by the DOWNLOADER-MY TROJAN! |
 |
CLICONFG.EXE |
CLICONFG
Added by the OPASERV.T WORM! |
 |
cwbappcd.exe |
Client Access API Daemon
IBM iSeries Client Access, see here |
 |
cwbckver.exe |
Client Access Check Version
Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to. Not required - and can be turned off in the Client Access properties. It's a waste of resources |
 |
cwbwlwiz.exe |
Client Access Express Welcome
Welcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. What does it do and is it required? |
 |
cwbinhlp.exe |
Client Access Help Update
Client Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. It only updates the help files on your PC to match the level of the attached iSeries |
 |
CwbSvStr.Exe |
Client Access Service
Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resources |
 |
cwbuitsk.exe |
Client Access Taskbar
IBM iSeries Client Access taskbar, see here |
 |
csrsrv.exe |
Client Server Run Time Proccess
Added by a variant of the SDBOT WORM! |
 |
csrsss.exe |
Client Server Runtime Process
Added by the SDBOT-LD WORM! |
 |
csrs.exe |
Client Server Runtime Process
Added by the LINKBOT.M WORM! |
 |
clipmg.exe |
Clip Service Manager
Detected by Kaspersky as the DELF.DXJ TROJAN! See here |
 |
clipsrvc.exe |
Clip Servicer
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
clipsv.exe |
Clip Srv
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
clipboard.exe |
clipboard.exe
Added by an unidentified WORM or TROJAN! |
 |
Clipsrv.exe |
Clipbook Service
Supports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooks |
 |
clipdiary.exe |
clipdiary
Clipdiary from Softvoile - "Free Clipboard Manager for keeping the clipboard history" |
 |
ClipMt5x.exe |
ClipMate5x
Clip Mate 5.x by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs |
 |
CLIPMT60.EXE |
Clipmate6
Clip Mate 6 by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs |
 |
ClipMate.exe |
ClipMate7
Clip Mate 7 by Thornsoft - utility that allows you to store more than one item in the clipboard |
 |
Clipomatic.exe |
Clipomatic
Mike Lin's Clipomatic is a clipboard cache program - it remembers what was copied to the clipboard even after new data is copied, and allows you to retrieve the old data |
 |
Clipsrv.exe |
Clipsrv
Supports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooks |
 |
clipserv.exe |
ClipSrv
Added by the SDBOT-AAV and SDBOT-AFE WORMS! |
 |
CLIPBRD3D.EXE |
ClipSrv
Added by the MOFEI-D WORM! |
 |
ClipTrak.exe |
ClipTrak
ClipTrak - clipboard extender |
 |
ClipTrakker.exe |
ClipTrakker
Cliptrakker - clipboard extender |
 |
CLIStart.exe |
CLISTART
Puts the ATI Catalyst™ Control Center Icon/Shortcut on the System Tray - available via Start → Programs |
 |
clmpanel.exe |
CLMFrontPanel
System tray status/display/configuration utility for a number of modems. Can be disabled by right-clicking on the tray icon. If disabled, connection status is lost |
 |
CLOCKWISE.EXE |
ClockWise
ClockWise - produced by R J Software - a time utility. It is a schedueler not only for dates, but you can choose it to run programs at any time. It also updates the time by connecting to an atomic clock server. This is a spyware-free alternative to ClockSync |
 |
ClocX.exe |
ClocX
ClocX - places a clock on the desktop that can be moved and then changed into a calendar plus you can set alarms etc? |
 |
CloneCDTray.exe |
CloneCD
System tray for the now discontinued CloneCD. The only useful option is "Hide CDR Media" only available via this tray. Has additional unknown functions in later versions |
 |
CloneCDTray.exe |
CloneCDTray
System tray for the now discontinued CloneCD. The only useful option is "Hide CDR Media" only available via this tray. Has additional unknown functions in later versions |
 |
com.exe |
CLSID
Adult content dialler |
 |
cma.exe |
cma
DeskSite CMA siftware - "retrieves new content from the DeskSite Data Center" |
 |
cmappclient.exe |
CMAPP
CasClient adware - also detected as the CMAPP TROJAN! |
 |
cmd32.exe |
Cmd
Added by the TANKED WORM! |
 |
configs.exe |
cmd32
Hijacker, also detected as the QURL-2 TROJAN! |
 |
cmd64.exe |
cmd64
CoolWebSearch Search X parasite variant |
 |
cmdbcs.exe |
cmdbcs
Added by the LINEAG-GKW TROJAN! |
 |
cmdcon.exe |
cmdcon
Added by the CRYPTER.A TROJAN! |
 |
CmdShell.exe |
CmdShell.exe
Added by the BCKDR-QHY TROJAN! |
 |
cme.exe |
CME
Part of Gator advertising spyware - see here for removal instructions. Please note that Claria Corporation no longer support GAIN-Supported software - see here |
 |
CMEsys.exe |
CmeSYS
Part of Gator advertising spyware - see here for removal instructions. Please note that Claria Corporation no longer support GAIN-Supported software - see here |
 |
CMEupd.exe |
CmeUPD
Part of Gator advertising spyware - see here for removal instructions. Please note that Claria Corporation no longer support GAIN-Supported software - see here |
 |
CMFibula.exe |
CMFibula
CASClient adware |
 |
CmFlywav.exe |
CmFlywaveName
Driver for Linksys Wireless-G Music Bridge |
 |
CMGrdian.exe |
CMGrdian
One of the McAfee shared components. What does it do and is it required? |
 |
CMGShieldUI.exe |
CMGShieldUI
UI for CMG (CREDANT Mobile Guardian) Shield from Credant Technologies. "The CMG Shield resides on devices and external media to enforce security policies even if the device is disconnected from the network." Used to protect sensitive corporate on laptops, handhelds, smartphones, USB drives and CD-DVDs |
 |
CMMan.exe |
CMMan
Added by the CMAPP TROJAN! |
 |
cmmon32.exe |
Cmmon32Sys
Added by the SMALL.CL TROJAN! |
 |
CMPDPSRV.EXE |
CMPDPSRV
Printer Driver Plus from ViewAhead Technology (formerly DeviceGuys, Inc.). "Printer Driver Plus seamlessly integrates all the necessary components of a printer driver, plus more". Installed with some Compaq and Lexmark printers |
 |
cmrss.exe |
cmrss
Added by the DELF.DU TROJAN! |
 |
crmss.exe |
cmrss
Added by the DLOADER-EK TROJAN! |
 |
cmrst.exe |
cmrst
Added by the BANCOS.S TROJAN! |
 |
cmrst.scr |
cmrst
Added by the DLOADER-FP TROJAN! |
 |
ctmn.exe |
CMSETTINGS
Part of NetNanny Chat Monitor |
 |
csmss.exe |
cmssSystemProcess
Added by the AGENT-CO TROJAN! |
 |
csms.exe |
cmssSystemProcess
Added by the AGENT-Y TROJAN! |
 |
CMSystem.exe |
CMSystem
CASClient adware |
 |
cmt101.exe |
cmt101
Added by a variant of the CRYPTER.C TROJAN! |
 |
CmUCReye.exe |
CmUCRRun
Related to Medion Display Information. What does it do and is it required? |
 |
cmx32.exe |
cmx32
Added by the GEMA.D TROJAN! |
 |
cnfrm33.exe |
Cn323
Added by the MIMAIL.G WORM! |
 |
CNBABE.EXE |
CNBABE
Appears to be spyware added by KAZAA (and maybe others) that displays pop-up ads whilst you're browsing |
 |
CMain.exe |
cnfgCav
Part of Comodo Antivirus |
 |
cnfrm.exe |
Cnfrm32
Added by the MIMAIL.D WORM! |
 |
cnwida.exe |
CnwiDeviceAgent
Part of the Canon imagePROGRAF W8400 printer management software |
 |
CnxAdslL.exe |
CnxAdslL
DLink, Zoom, or Conexant modem driver |
 |
CnxDslTb.exe |
CnxDslTaskBar
Connexant DSL Taskbar as used on Acess Runner and Samsung AHT-E310 ADSL modems |
 |
cbInterface.exe |
Cobian Backup 8 interface
"Cobian Backup is a backup program that can be executed in 2 ways: as a normal application or as a Windows Service. The program can schedule automatic backups for files and directories locally or to FTP servers and can use compression and encryption" |
 |
CCIntro.exe |
CodeClean
CodeClean spyware remover - not recommended, see here |
 |
coloreal.exe |
coloreal
Makes colours sharper and brighter, but will only work with coloreal capable monitors |
 |
csrs.exe |
Com+ Sys
Added by the FORBOT-BT WORM! |
 |
COMIP.EXE |
COM-IP
COM-IP Virtual Modem Driver (COM-IP Creates a Fake Serial Port that allows you to use older DOS Based Communications Programs over Telnet. Type atdt host.domain.com instead of atdt 5551212) |
 |
cactusspamfilter.exe |
com.codeode.cactusspamfilter
Cactus Spam - free easy-to-use spam blocker |
 |
ComAgent.exe |
ComAgent
ComAgent - MDaemon's instant messaging client |
 |
combo.exe |
combo.exe
Added by the CHIMO-C TROJAN! |
 |
combop.exe |
combop.exe
Added by the BOWFEED-A TROJAN! |
 |
comcfg.exe |
COMCFG
Added by the TOADCOM.A TROJAN! |
 |
comctl32.exe |
comctl32
Adware - detected by Kaspersky as the AGENT.AM TROJAN! |
 |
commh32.exe |
Comm Driver
G Data "PC Spion". PC monitoring and surveilling software, captures all users activity on the PC, see here. Disable/remove if you didn't install it yourself! |
 |
command.exe |
COMMAND
Added by the QQPASS.E TROJAN! |
 |
CmdPrompt32.pif |
Command Prompt32
Added by the ASSIRAL.B WORM! |
 |
cws 4.exe |
Command WorkStation 4
EFI's Command WorkStation makes "managing demanding workflows easier by centralizing job management. The software automatically identifies the Fiery servers on the network and offers customization options for displaying information" - for high-end print environments |
 |
command32.exe |
command32
Added by the LINEADI-A TROJAN! |
 |
commctr.exe |
CommCtr
"Net2Phone CommCenter is the latest in Internet voice technology allowing you to place calls easily all over the world right from your PC!". Available via Start -> Programs |
 |
Communicator.exe |
COMMUNICATOR
Part of Microsoft Office Communicator, which is an integrated communications client that allows information workers to communicate in real time using a range of different communication options, including instant messaging (IM), voice, and video |
 |
CPF.exe |
Comodo Firewall
Comodo Firewall |
 |
cfp.exe |
COMODO Firewall Pro
Comodo Firewall Pro |
 |
CLPTray.exe |
Comodo Launch Pad Tray
System Tray access to LaunchPad as bundled with Comodo's freebie offerings such as Comodo Anti-Virus. Some allege that LaunchPad is impossible-to-uninstall adware, or worse - see here |
 |
cmf.exe |
COMODO Memory Firewall
"Comodo Memory Firewall is a buffer overflow detection and prevention tool which provides the ultimate defence against one of the most serious and common attack types on the Internet - the buffer overflow attack" |
 |
compwiz.exe |
CompanionWizard
WinAntiVirus 2006 misleading virus software - not recommended, see here |
 |
CPQAlert.exe |
Compaq Alerter
Compaq's Insight Manager Agent - a tool that allows for "fault, performance, and configuration management". Recommended for corporate users only. It's best removed if installed but not wanted, rather than disabled at startup. See here for more information |
 |
COMPAQ~1.EXE |
Compaq Connections
See here - "messaging service that automatically sends you support information, tips, ideas, and special offers from HP and our partners, especially designed for HP and Compaq desktop computer owners" |
 |
Compaq Connections.exe |
Compaq Connections
See here - "messaging service that automatically sends you support information, tips, ideas, and special offers from HP and our partners, especially designed for HP and Compaq desktop computer owners" |
 |
cpqdmi.exe |
Compaq DMI
Compaq version of the Desktop Management Interface |
 |
COMPAQ-RBA.EXE |
Compaq Message Server
Applies to the CPQBootPerfDB entry as well. These files generate some kind of server or servlet that attempts to connect with Compaq online. They are like Trojans, but fairly harmless. They send information on the "Compaq Advisor/Compaq Message Screener" application that comes with every Compaq computer and provide feedback on how computer users use the Message Advisor. These messages appear occasionally and instruct and advise users on their computer and its use. They generally attempt to get you (these messages) to connect to Compaq's website. They may be safely disabled via (1) MSCONFIG or (2) Start -> Programs -> Compaq Advisor -> Advisor Settings under the "advanced" tab. Not required and can cause problems |
 |
cpqkl.exe |
Compaq PK Daemon
For Compaq laptops for programming user configurable keys. Not required unless you use them |
 |
cpqa1000.exe |
Compaq Print Fax
Added by the SDBOT.BCV WORM! Please take note of the difference between the legitimate Compaq Fax Utility Name (A1000 Settings Utility) and the name (Compaq Print Fax) used by this worm |
 |
compq.exe |
Compaq Service Drivers
Added by a variant of the SDBOT WORM! |
 |
compqs.exe |
Compaq Service Drivers
Added by a variant of the SDBOT WORM! |
 |
compaq.exe |
Compaq Service Drivers
Added by the SDBOT-AFU WORM! |
 |
compq32.exe |
Compaq Service Drivers 32
Added by a variant of the SDBOT WORM! |
 |
copq.exe |
Compaq Service Drivrs
Added by a variant of the RBOT WORM! |
 |
cpqhcm.exe |
CompaqHW Comp Manager
Running on a Compaq laptop - any ideas? |
 |
copypad32.exe |
Compaqs Service Driver
Added by the SDBOT.CSO WORM! |
 |
compqs.exe |
Compaqs Service Drivers
Added by a variant of the SDBOT WORM! |
 |
cpqpscp.exe |
CompaqSystray
Compaq System Tray icon |
 |
codq.exe |
Compd Service Drivrs
Added by a variant of the SDBOT WORM! |
 |
ComproRemote.exe |
ComproRemote
VideoMate TV tuner and capture card - remote control driver |
 |
ComproSchedulerDTV.exe |
ComproSchedulerDTV
VideoMate TV tuner and capture card - scheduler |
 |
comsmd.exe |
COMSMDEXE
3Com tray icon |
 |
comxt.exe |
comxt
Added by the COMXT TROJAN! |
 |
Config33.exe |
Config33.exe
Added by the SDBOT.T TROJAN! |
 |
cart322.exe |
ConfiggLoader
Added by the GAOBOT.DJ WORM! |
 |
CFGSAFE.EXE |
ConfigSafe
ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions -- provides a restore function. Your choice |
 |
Config.exe |
ConfigServices
Part of initial setup on a Compaq PC |
 |
configsetup32.exe |
configsetup
Added by the AGOBOT-AFP WORM! |
 |
cmd32.exe |
Configuration Loader
Added by the LOADCFG or SDBOT TROJANS! |
 |
confgldr.exe |
Configuration Loader
Added by the GAOBOT.GEN!POLY WORM! |
 |
ccSort.exe |
Configuration Loader
Added by the AGOBOT.SR WORM! |
 |
crcss.exe |
Configuration Loader
Added by the AGOBOT.ADG WORM! |
 |
configldr.exe |
Configuration Loader
Added by the AGOBOT-PP TROJAN! |
 |
configldr.exe |
Configuration Loading
Added by the AGOBOT-EC WORM! |
 |
CNFGLD32.EXE |
Configuration Manager
Added by the SDBOT TROJAN! |
 |
Cnfgldr.exe |
Configuration Manager
Added by the SDBOT TROJAN! |
 |
cfg32.exe |
Configuration Manager
BookedSpace parasite. Note - the "cfg32.exe" file is located in the Winnt or Windows folder |
 |
CONFIG.EXE |
Configuration Utility
Controls linksys wireless connection. Available from the Desktop |
 |
Cfgwiz32.exe |
Configuration Wizard
Added by a variant of the HACKTACK TROJAN! Not to be confused with the legitimate MS "ISDN Configuration Wizard" (Cfgwiz32.exe) |
 |
ConfigUtility.exe |
ConfigUtility
Wireless management utility for the HWC54G Hi-Speed Wireless-G CardBus Card from Hawking Technologies, Inc |
 |
conmgr.exe |
Conmgr
Starts Winfax pro at startup |
 |
conmgr.exe |
ConMgr.exe
Connection Manager as used by Earthlink and others. If you need this to ensure a proper connection but don't want to connect at startup try creating your own shortcut |
 |
conrnbne.exe |
conmswf
Added by the SDBOT-DEX WORM! |
 |
connect2party.exe |
Connect2Party
Adult content dialler |
 |
ConKeepM.exe |
Connection Keeper
"Connection Keeper is an invaluable time-saving tool for dial-up users. This free program simulates Internet browsing (at a random interval) to prevent your connection from appearing idle, thus preventing your ISP from dropping your connection due to inactivity" |
 |
CManager.exe |
Connection Manager
SBC Yahoo DSL service connection manager. You can connect from the network connections. Users having problems with this have been advised to uninstall the connection manager via Add/Remove Programs and it won't affect the service |
 |
CONNECTScheduler.exe |
CONNECTScheduler
Scheduler for updating Sony's CONNECT music download service |
 |
consol32.exe |
Cons
Hijacker - redirects to a p0rn portal, where foistware like ISTBar gets stealth installed |
 |
conscorr.exe |
conscorr
VX2.Transponder parasite updater/installer related |
 |
csrss.exe |
Console de Gerenciamento Microsoft
Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "Level4" subfolder |
 |
csrss.exe |
Console de Gerenciamento Microsoft
Added by the BANCBAN-ET TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "Central de Segurança" subfolder |
 |
ConsumerInput.exe |
Consumer Input
Consumer Input Toolbar. Opt-in market research monitoring you browsing habits - see the FAQ |
 |
ConsumerInputRewardedwithMyPoints, ConsumerInput.exe |
Consumer Input Rewarded with MyPoints, Consumer Input
Consumer Input Toolbar. Opt-in market research monitoring you browsing habits - see the FAQ |
 |
ConsumerInputRewardedwithMyPoints, ConsumerInputUa.exe |
Consumer Input Rewarded with MyPoints, Consumer Input Update
Consumer Input Toolbar. Opt-in market research monitoring you browsing habits - see the FAQ |
 |
contacte.exe |
Contacte
Some kind of driver? |
 |
ContraVirusPro.exe |
ContraVirus
ContraVirus misleading security software - not recommended, see here |
 |
Center.exe |
Control Center
Associated with Hawking Technologies, Inc wireless products. Located in %Program Files%\Hawking\WLAN Card Utilities |
 |
cprs.exe |
control panel software service
Added by the RBOT-FPI WORM! |
 |
ctlcntr.exe |
ControlCenter
Part of Lenovo's (IBM) ThinkVantage Fingerprint Software - used on laptops and keyboards with integrated fingerprint readers |
 |
crss.exe |
Controlled Resource System Service
Added by the AGOBOT.GH WORM! |
 |
cmd32.exe internat.dll, LoadKeyboardProfile |
ControlPanel
Added by the DLOADER-HF TROJAN. Note - the "cmd32.exe" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
csmsv.exe |
ControlServiceMgr
Added by the AGENT-XC TROJAN! |
 |
CookieCop.exe |
Cookie Cop 2
Cookie Cop 2 from PC Magazine - cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return |
 |
CPBRWTCH.EXE |
Cookie Pal
Kookaburra Software's Cookie Pal cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return |
 |
Cookiejar.exe |
CookieJar
Cookie Jar cookie manager from Jason's Toolbox. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return. No longer being actively supported |
 |
CookiePatrol.exe |
CookiePatrol
CookiePatrol - cookie interceptor stopping spyware cookies that used to be part of PestPatrol before CA's aquisition |
 |
cookie.exe |
CookieWall
CookieWall from Analog X. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return |
 |
cdesk.exe |
Cool Desk
Cool Desk is a virtual desktops manager. "Ever you wished to have several screens on your computer? Cool Desk creates up to 9 virtual desktops and offers you to have different windows on each of them". Not required but may be of use to you |
 |
CoolMon.exe |
CoolMon
"CoolMon monitors vital system stats and almost anything else you wish to display on the desktop" |
 |
cwm_tray.exe |
Coolwallpaper
Cool Wallpaper software allows you to manage high quality photos as desktop wallpaper and screen savers |
 |
clrssn.exe |
coolwebprogram
CoolWebSearch Smartsearch parasite variant |
 |
CopernicPerUserTaskMgr.exe |
CopernicPerUserTaskMgr
Automatic tasking feature of Copernic Pro multi-search engine tool |
 |
Copy Handler.exe |
Copy handler
Copy Handler lets you copy between hard disks, floppies, local networks, CDs, and many other storage media. Copy Handler gives you the power to pause, resume, restart, and cancel during the copying and moving processes |
 |
ccapl.exe |
Core Process Aplication
Added by a variant of the RBOT WORM! |
 |
ccapl16.exe |
Core Process Aplication x16
Added by a variant of the SLAPER TROJAN! |
 |
ccapl32.exe |
Core Process Aplication x32
Detected by Kaspersky as the SRAMLER.E TROJAN! See here |
 |
CoreCenter.exe |
CoreCenter
MSI Core Center - motherboard utility for monitoring CPU speed, voltages, temperatures and fans speeds as well as overclocking |
 |
CORECE~1.EXE |
CoreCenter
MSI Core Center - motherboard utility for monitoring CPU speed, voltages, temperatures and fans speeds as well as overclocking |
 |
cffrem.exe |
Corel Colleagues & Contacts Reminders
Corel Colleagues & Contracts - all-in-one organizer for scheduling meetings, maintaining addresses, etc. Part of the now defunct Corel Print Office |
 |
CFFREM.EXE |
Corel Family & Friends reminders
Corel Family & Friends - all-in-one calender, address book and list manager. Part of the now defunct Corel Print House Magic |
 |
CorelDraw.exe |
CorelDraw Toolbox
Added by the SDBOT-VZ WORM! |
 |
coresrv.exe |
CoreSrv
Some IRC trojans/worms use this - see here for more information |
 |
coresys.exe |
CORESYS
?? |
 |
CConnect.exe |
CorrectConnect
Broadband ISP diagnostic tool - as used by NTL and Cox Communications. Shortcut available |
 |
cosine.exe |
cosine
Added by the RBOT-SW WORM! |
 |
czrzns.exe |
Counterstrike Service Agent
Added by the MEDBOT.AR WORM! |
 |
couponica.exe |
couponica
Adware - see here |
 |
CopyProtectionNotifier.exe |
CP
Related to Emuzed Systems and Middleware. Comes included with Windows XP Media Edition |
 |
CP32BTN.EXE |
CP32NOT
For the programmable "one-touch" buttons on HP laptops (and others?). Safe to disable if you don't use these buttons |
 |
CP888M1.EXE |
CP888M1
Related to EZbutton quick launcher for the Media player app that comes with certain laptops |
 |
CPA9P2PS.exe |
CPA9P2PSERVER
Found on a Compaq Presario but what is it? |
 |
CPATR10.EXE |
CPATR10
Dritek/Compal ATR10 Easy Button driver. Used on certain laptops (e.g. Toshiba, Compaq) to translate special hotkeys such as Play/Pause and Constrast |
 |
CPBrWtch.exe |
CPBrWtch
Kookaburra Software's Cookie Pal cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return |
 |
CPD.EXE |
CPD_EXE
Firewall bundled with McAfee VirusScan 6.* |
 |
CplBTQ00.EXE |
CplBTQ00
Related to EZbutton quick launcher for the Media player app that comes with certain laptops |
 |
CPLDBL10.exe |
CPLDBL10
Related to EZbutton quick launcher for the Media player app that comes with certain laptops |
 |
cppatch.exe |
CPortPatch
CPortPatch is a utility is required for Dell laptops that are using a docking station. Is it needed though? |
 |
CPQAcDc.exe |
CPQAcDc
Compaq PowerCon power management software for laptops |
 |
CPQAlert.exe |
CPQAlert
Compaq's Insight Manager Agent - a tool that allows for "fault, performance, and configuration management". Recommended for corporate users only. It's best removed if installed but not wanted, rather than disabled at startup. See here for more information |
 |
CPQBootPerfDB.EXE |
CPQBootPerfDB
See the entry for Compaq Message Server |
 |
CPQCalib.exe |
CPQCalib
Compaq PowerCon power management software for laptops |
 |
CpqDfwAg.exe |
CPQDFWAG
For Compaq PC's. Runs Compaq diagnostics on every boot |
 |
cpqeadm.exe |
CPQEASYACC
For Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys |
 |
cpqeaui.exe |
cpqeaui
For Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys |
 |
CpqInet.exe |
CPQInet Runtime Service
For Compaq PC's. Allows AOL and Compuserve to use the Easy Access buttons for the internet. Is not required if you don't use the ISP providers |
 |
cpqinkag.exe |
CPQINKAGENT
That is the Compaq Ink Agent for some inkjet printers, it lets users know when their ink cartridges are getting close to empty (by how many pages they have printed) |
 |
cpqnpcss.exe |
cpqns
Related to Compaq.Net - not required if you don't use that |
 |
Cpqset.exe |
Cpqset
Default settings software in Hewlett Packard notebook |
 |
cpqteam.exe |
CPQTEAM
This program is bundled with HP servers. When loaded a system tray icon will be available that launches the HP Network Configuration Tool |
 |
cpr |
cpr
Adroar.com adware downloader |
 |
cproc.exe |
cprocsvc
Added by MSIL.AGENT.C TROJAN! |
 |
cpumgr.exe |
CPU Manager
Added by the PANDEM.B WORM! |
 |
cpustats.exe |
CPU Windows Status
Added by a variant of the RBOT WORM! |
 |
Cpucool.exe |
CPUcool
Program to keep the processor cool when idle in "overclocked" systems. Also available via Start -> Settings -> Control Panel |
 |
CPUMon.exe |
CPUMon
"CPUMon continuously displays the updated system statistics in a floating window as well as in system tray area" |
 |
Cpusave.exe |
Cpusave
Added by the GEMA TROJAN! |
 |
Cpusave32.exe |
Cpusave32
Added by the GEMA TROJAN! |
 |
cpvhost.exe |
CPVHOST Settings
Added by a variant of the SDBOT TROJAN! |
 |
Cr**.exe [* = random char] |
Cr**.exe [* = random char]
CoolWebSearch/HomeSearch adware - for examples, see this log |
 |
Cr**.exe [* = random char] |
Cr**.exe [* = random char]
CoolWebSearch/HomeSearch adware - for examples, see this log |
 |
Cr**32.exe [* = random char] |
Cr**32.exe [* = random char]
CoolWebSearch/HomeSearch adware - for examples, see this log |
 |
cracked_windows1.exe |
cracked_windows1
Cracked Windows popup killer |
 |
CRBroadCasting.exe |
CRBroadCasting
CardReader2 from On Track Inovations Ltd. USB Card Reader |
 |
crsss32.exe |
CRC Value Verifier
Added by a variant of the RBOT WORM! |
 |
Crsss64.exe |
CRC Value Verifier
Added by the RBOT-NY WORM! |
 |
crsss.exe |
CRC Value Verifier
Added by the SPYBOT.UK WORM! |
 |
Crc32stats.exe |
Crc32stats Dependencies
Added by the MYTOB.GT WORM! |
 |
crcss.exe |
CRCSS
Added by the IRCBOT-TH WORM! |
 |
createAMonster.exe |
Create A Monster
Kudd.com CreateAMonster. Reportedly stealth installed and Look2Me adware related |
 |
Createcd.exe |
CreateCD
Adaptec Easy CD Creator system tray application (pre version 5). Available via Start -> Programs |
 |
Createcd50.exe |
CreateCD50
Adaptec Easy CD Creator version 5 system tray application. Available via Start -> Programs |
 |
creative.exe |
Creative Audio Drivers
Added by the RBOT-FKR WORM! |
 |
CTDetect.exe |
Creative Detector
Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player, selecting Tools, then uncheck the Auto Start box. It should not start up automatically again |
 |
CTLauncher.exe |
Creative Launcher
For Creative Soundblaster Live! series soundcards. Adds a quick-launch bar to the top of the display and a System Tray icon. Available via Start -> Programs |
 |
CTLCMgr.exe |
Creative Live! Cam Manager
Creative Live! Cam Manager |
 |
CTCMSGo.exe |
Creative MediaSource Go
"Creative MediaSource playbacks music in DVD-Audio, MP3, WMA, WAV and other media formats" |
 |
CTCMSGoU.exe |
Creative MediaSource Go
Creative MediaSource playbacks music in DVD-Audio, MP3, WMA, WAV and other media formats" |
 |
Ctsvccda.exe |
Creative Service for CDROM Access
Resident program for Creative's PlayCenter included with Soundblaster Audigy sound cards - speeds up detection of some media CDs if the system doesn't natively support them. Available via Start -> Programs |
 |
Camtray.exe |
Creative WebCam Tray
Creative WebCam tray control - can be started manually |
 |
Creative.exe |
Creative.exe
Added by the PROLIN WORM! |
 |
CTNOTIFY.EXE |
CreativeDiscNotifier
For Creative Soundblaster Live! series soundcards. Detects when you insert a CD-ROM, DVD-ROM, etc. Available via Start -> Settings -> Control Panel |
 |
CTMIX32.EXE |
CreativeMixer
Creative soundcard System Tray access to, for example, volume slider controls as normally provided by the "speaker" icon. Not required unless you adjust any settings otherwise available via the standard icon |
 |
CTSched.exe |
CreativeTaskScheduler
Creative Task Scheduler. What does it do and is it required? |
 |
CrossMenu |
CrossMenu
Toshiba CrossMenu Utility - allows the user to create their own menus |
 |
crp386.exe |
CRP386 Networking
Added by the IRCBOT.N TROJAN! |
 |
crs.exe |
crs
Added by the AGOBOT-TJ WORM! |
 |
crssxp.exe |
CRSSXP SysInfo
Added by a variant of the SDBOT TROJAN! |
 |
cryptdlg.exe |
cryptdlg
Added by an unidentified TROJAN! |
 |
cexpert.exe |
cryptoexpert
CryptoExpert from SecureAction Research. Advanced on the fly encryption system |
 |
CWD3DSND.EXE |
Crystal 3D Audio Control
Crystal 3D Audio sound driver. Is it required? |
 |
copy /Y [path] ActivationManager.dll.upd [path] ActivationManager.dll |
CS Update
Added by an unidentified malware |
 |
csc.exe |
csc
Command line compiler for Microsoft C# it gets installed with the .NET SDK |
 |
cscripts.exe |
cscripts
Added by the BDOOR-AAP BACKDOOR! |
 |
cscrs.exe |
CSCRS Value
Added by the RBOT-AAA WORM! |
 |
CSINJECT.EXE |
CSINJECT.EXE
Part of Quarterdeck/Norton CleanSweep. "Csinject must be loaded in order for Smart Sweep to automatically monitor installations and properly track registry changes" |
 |
csm.exe |
csm Win Updates
Added by the ZOTOB.B WORM! |
 |
csos.exe |
csos
Added by the SDBOT-DFE WORM! |
 |
csrs.exe |
csrs
Added by the GAOBOT.GEN!POLY WORM! |
 |
csrsc.exe |
csrsc
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
CSRSS.EXE |
CSRSS
Search page hijacker, redirecting to h**p://www.search-aide.com/. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
csrss.exe |
Csrss
Added by the CHOD WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a random subfolder |
 |
csrss.exe |
csrss
Added by the KEYLOG-AQ KEYLOGGER! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
csrss.exe |
csrss
Added by the CHODE-J WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a random subfolder |
 |
csrss.exe |
csrss
BeyondKeylog surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Supremtec |
 |
CSRSS.EXE |
Csrss
Added by the PUNYA-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Documents and Settings\Administrator\Local Settings\Application Data\WINDOWS |
 |
csrhost.exe |
Csrss Host
Detected by Trend Micro as the IRCBOT.BIZ WORM! See here |
 |
csrsss.exe |
CSRSS Loader
Added by the AGOBOT.TX WORM! |
 |
csrss.exe |
csrss.exe
Added by the DALBUG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
csrss.exe |
csrssLevel4
Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "Level4" subfolder |
 |
CSRSSU.exe |
CSRSSU
CoolWebSearch parasite variant - hijacking to Slawsearch.com. Also detected as the CWS-E TROJAN! |
 |
CSRSSW.EXE |
CSRSSW
Added by the CWS-F TROJAN! |
 |
csrvss.exe |
csrvss
Added by a variant of the SDBOT TROJAN! |
 |
CSSServer.exe |
CSS Server
ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself |
 |
cssauth.exe |
cssauth
Related to IBM ThinkVantage Client Security Solution |
 |
cssauthe.exe |
cssauthe
Part of the Client Security Solution on an IBM ThinkVantage (now Lenovo) PC - "a suite of ThinkVantage Technology tools designed to help protect access to your computer operating system and your sensitive data. The Client Security Solution integrates the hardware protection of its embedded chip with the protection afforded by its secure software." What does this do and is it required?" |
 |
cssrs.exe |
cssrs
Added by the BANCBAN-DW TROJAN! |
 |
Csss.exe |
csss
Added by the BALICK TROJAN! |
 |
CSS_1631.EXE |
CSS_Central
CSS Communication Agent (95 Host) from Command Software Systems (now Authentium). "CSS Central? provides administrators with a powerfully proactive tool to effectively manage and maintain the anti-virus strategy from a centralized console" |
 |
CSP001.exe |
CSV10P1
ClearSearch adware |
 |
CSv10P070.exe |
CSV10P70
ClearSearch adware |
 |
CSV7P26.exe |
CSV7P26
ClearSearch adware |
 |
CSV7P070.exe |
CSV7P70
ClearSearch adware |
 |
CSV7P91.exe |
CSV7P91
ClearSearch adware |
 |
csvdea.exe |
csvdea
SpyArsenalLog surveillance software. Uninstall this software unless you put it there yourself |
 |
csvhost.exe |
csvhost.exe
Added by the CIMUZ-BD TROJAN! |
 |
ct.exe |
ct
ct.exe is a file is for the HP Learning Adventure software and if you use this software it is required to run it |
 |
CTSVCCD.EXE |
CT Control Settings
Added by the RBOT-YS WORM! |
 |
CTAPR2.exe |
CTAPR2
Console Launcher for the Creative Sound Blaster X-Fi series |
 |
CTAvTray.exe |
CTAVTray
For Creative Soundblaster Live! series soundcards. Plays the EAX animation on start-up and adds a System Tray icon for it. Available via AudioHQ |
 |
CTCMonitor.exe |
CTCMonitor
Click-to-Convert - document-to-HTML or doc-to-PDF converter. Only required if you are going to use the File -> Print method of using Click-to-Convert. If converting directly from MS Office, it is not required |
 |
CTDVDDet.exe |
CTDVDDet
Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player, selecting Tools, then uncheck the Auto Start box. It should not start up automatically again |
 |
CTDetect.exe |
CTDVDDet
Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player, selecting Tools, then uncheck the Auto Start box. It should not start up automatically again |
 |
ctf.exe |
ctf.exe
Added by a variant of the BIFROSE TROJAN! |
 |
ctflog.exe |
ctflog manager
Added by the DONBOMB.A TROJAN! |
 |
CTFM0N.exe |
CTFM0N.exe
Added by the STARTPAGE.P TROJAN! |
 |
ctfmon.exe |
ctfmon
CTFMon is involved with the language/alternative input services in Office XP. Ctfmon.exe will continue to put itself back into MSConfig when you run the Office XP apps as long as the Text Services and Speech applets in the Control Panel are enabled. Not required if you don't need these features. For more info on ctfmon see here. Ctfmon can be disabled from Control Panel, Text & Speech Services. Note - the file will always be located in the System32 folder, if it is located elsewhere it will likely be a worm or trojan! Can cause problems with some other programs if left enabled - see here for such an example |
 |
cftmon.exe |
ctfmon
Added by the DELIVE-A TROJAN! Note - this file is found in C:Windows or C:Winnt and is not the valid MS Office file of the same name (see here) |
 |
ctfmon.exe |
CTFMon
Family Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Located in %System%\CTF |
 |
ctfmon32.exe |
Ctfmon.exe
CoolWebSearch Ctfmon32 parasite variant |
 |
ctfmon.exe |
ctfmon.exe
Added by the RAIDYS TROJAN! Note - this should not be confused with the valid Office XP file, see here |
 |
ctfmon.exe |
ctfmon.exe
CTFMon is involved with the language/alternative input services in Office XP. Ctfmon.exe will continue to put itself back into MSConfig when you run the Office XP apps as long as the Text Services and Speech applets in the Control Panel are enabled. Not required if you don't need these features. For more info on ctfmon see here. Ctfmon can be disabled from Control Panel, Text & Speech Services. Note - the file will always be located in the System32 folder, if it is located elsewhere it will likely be a worm or trojan! Can cause problems with some other programs if left enabled - see here for such an example |
 |
ctfmon.exe eminem.exe |
ctfmon.exe
Added by the BHARAT.A WORM! |
 |
CTFMON32.EXE |
CTFMON32
CoolWebSearch Ctfmon32 parasite variant - also detected as the CWS-E TROJAN! |
 |
ctfmona.exe |
ctfmona
AntiVirusPro misleading security software - not recommended, see here |
 |
CTFMONSS.EXE |
CTFMONSS
Added by the CWS-F TROJAN! |
 |
ctfmun.exe |
ctfmun
Detected by Trend Micro as AGENT.ACEZ spyware - see here |
 |
ctfmon.exe |
ctfnnon
Detected by Kaspersky as the TURKOJAN.IL BACKDOOR! See here. Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir% |
 |
cthelp.exe |
cthelp
Added by the SDBOT TROJAN! |
 |
CTHELPER.EXE |
CTHELPER
CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative's sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a "leave alone" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it |
 |
cthelper.exe |
CTHelper
Added by the RBOT-XB WORM! Note - do not confuse with the Creative application of the same name described here |
 |
CTin10.exe |
CTin10
Added by the BANCOS.E TROJAN! |
 |
CtModule.exe |
CtModule
Added by the CLICKER-EG TROJAN! |
 |
cfmon.exe |
CTMON.EXE
Added by the CLCKR-AN TROJAN! |
 |
ctnmrun.exe |
CTNMRUN
Detects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connected |
 |
CTPDPSRV.EXE |
CTPDPSRV
Printer driver (in the WINDOWSSystem32spoolDRIVERSW32X86 folder). Is it required? |
 |
CTPowUti.exe |
CTPerformanceUtility
Related to Creative PowerSysTrayApp. This program is a non-essential process, but should not be terminated unless suspected to be causing problems |
 |
ctpmon.exe |
ctpmon
System Registry Cleaner - stealth installed foistware from sysregistry.com |
 |
CTRegRun.exe |
CTRegRun
For Creative Soundblaster Live! series soundcards. Reminds you to register your card with Creative |
 |
CtrlVol.exe |
CtrlVol
Volume control key on Acer, Fujitsu and other laptops |
 |
CTSched.exe |
CTSched
Creative Task Scheduler. What does it do and is it required? |
 |
CTEaxSpl.exe |
CTStartup
Splash screen with sound on every boot up. Installed with a Sound Blaster Audigy soundcard |
 |
CTSVolFE.exe |
CTSVolFE
Creative Labs Mixer applet for the Sound Blaster Audigy |
 |
CTSVolFE.exe |
CTSVolFE.exe
Creative Labs Mixer applet for the Sound Blaster Audigy |
 |
CTSyncU.exe |
CTSyncU.exe
Creative Sync Manager - synchronizes music tracks on your computer with your player |
 |
CTSYSVOL.exe |
CTsysVol
Creative sound card volume controls |
 |
cttdpsrv.exe |
cttdpsrv
?? |
 |
ctupdclt.exe |
CTUpdate
Added by the RBOT-ABG WORM! |
 |
CTXFIHLP.EXE |
CTxfiHlp
Added by the installation of a Creative Labs X-Fi sound card. This particular process provides the help functionality for your card |
 |
CTxfiReg.exe |
CTXFIREG
Creative Labs sound card driver related. It appears that it isn't required and maybe registration related |
 |
CTZDetec.exe |
CTZDetec.exe
Auto-detect feature of Creative Media Lite which assists you in managing your music, ripping CDs and transferring other stored music to your Zen Stone MP3 player |
 |
Cuagent.exe |
cuagentExe
Command Antivirus related |
 |
cuo.exe |
cuo
Added by the BUGBEAR.A WORM! |
 |
csecure.exe |
Current Security Config
Added by the RBOT-AMO WORM! |
 |
CurseClient.exe |
CurseClient
CurseClient add-on manager for World of Warcraft and Warhammer Online games |
 |
CursorXP.exe |
CursorXP
CursorXP from Stardock - tool for creating mouse cursors |
 |
Curtain.exe |
Curtain
Curtain (from Chaotic Visions) - "is a Windows utility which gives you the power to hide any window or group of windows to your system tray" |
 |
CuteMX.EXE |
CuteMX
File sharing utility |
 |
cvmonitor.exe |
cvmonitor.exe
Added by the SDBOT.BV WORM! |
 |
cvpnd.exe |
CVPND
Sub-system used by Cisco VPN client for making a connection to a remote IPSec server |
 |
cw4.exe |
CW
Chat Watch "is a monitoring and logging software for online chat and instant messaging programs" |
 |
cw.exe |
CWatch
ChatWatch - chat monitoring tool |
 |
cwbckver.exe |
cwbckver
Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to. Not required - and can be turned off in the Client Access properties. It's a waste of resources |
 |
cwbinhlp.exe |
cwbinhlp
Client Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. It only updates the help files on your PC to match the level of the attached iSeries |
 |
cwbsvstr.exe |
cwbsvstr
Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resources |
 |
cwbwlwiz.exe |
cwbwlwiz
Welcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. What does it do and is it required? |
 |
Cwcdschk.exe |
Cwcdschk.exe
IBM Thinkpad related? |
 |
cwcptray.exe |
cwcptray
Related to ContentWatch Parental Control internet filter |
 |
cwupdate.exe |
cwupdate
ContentProtect from ContentWatch - internet filter |
 |
cyberchk.exe |
Cyber
Part of Belkins "Multimedia Cleaning Kit" and is automatically installed when you run their optical disk drive cleaning utility - to remind you to clean your drive after "x" amount of time has passed |
 |
CHTray.exe |
Cyberhawk
Cyberhawk from Novatix. Protects against viruses, spyware, identity theft |
 |
CLRamCleaner.exe |
CyberLat Ram Cleaner
CyberLat RAM Cleaner - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind |
 |
CyberLat Ram Cleaner 1.1.exe |
CyberLat Ram Cleaner
CyberLat RAM Cleaner - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind |
 |
CMAGENT.EXE |
CyberMedia Agent
Part of CyberMedia's Oil Change program. Not normally required. Note - if you have TextBridge, CyberMedia Agent may attach itself to TextBridge and cause TextBridge to crash everything if this is disabled |
 |
cphq.exe |
CyberPatrolNew
"CyberPatrol is one of the most powerful and popular client-based, browser independent, Internet safety software solutions for Windows-based standalone PCs available today" |
 |
CyberWolf.exe |
CyberWolf
Added by the KICKIN.A (or CYDOG.C) WORM! |
 |
CD_Load.exe |
CyDoor
Adware. Check here for information about Cy-Door and here for a program that can remove it |
 |
CD_Load.exe |
CydoorUpdate
Adware. Check here for information about Cy-Door and here for a program that can remove it |
 |
CYNHKey.exe |
CYNHKey
?? |
 |
CyphTray.exe |
CyphTray
Cypherus - encryption software |
 |
CypressLinkMon.exe |
CypressLinkMon
Related to CypressViewer from Siemens that "allows ACUSON Cypress cardiovascular system PLUS users to store, view, and analyze Cypress system PLUS studies on a standard Windows PC" |
 |
csrs.scr |
dark
Added by the BANCBAN-GT or BANCBAN-GU TROJANS! |
 |
cmonitor.exe |
DC300 Monitor
Monitor for a Acer DC300 digital camera |
 |
cma.exe |
Desksite CMA
DeskSite CMA siftware - "retrieves new content from the DeskSite Data Center" |
 |
csrss.exe |
DIECOX
Added by a variant of the ATM.GEN TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
CLIENT.EXE |
DigiGuide
TV guide and reminder |
 |
client01.exe |
DigiGuide
TV guide and reminder |
 |
caKe |
Dir1
Added by the CAKE WORM! |
 |
CtNotify.exe |
Disc Detector
For Creative sound cards. Detects when you insert a CD, DVD, etc |
 |
chkdsk32.exe |
Disk Check
Added by the IM TROJAN! |
 |
Code.exe |
Diskstart
Adult content dialler |
 |
cat.exe |
Diskstart
MS-Connect dialler |
 |
cssrs.exe |
Display Drivers
Added by the AGOBOT.FX WORM! |
 |
codll.exe |
Divx
Added by the GRAVEBOT-A TROJAN! |
 |
caKe |
DlDir1
Added by the CAKE WORM! |
 |
cygwin.exe |
Dos Prompt Loader
Added by the SDBOT-VV WORM! |
 |
csrnvrt.exe |
DriverModule
Added by the IRCBOT.I TROJAN! |
 |
Cirebons.exe |
Duwee wong Cerbon
Added by the BHARAT.A WORM! |
 |
cfgmng32.exe |
dvHighMem
Related to PureSight PC - designed to offer maximum flexibility and choice as families manage their internet use |
 |
CMD16.EXE |
Dynamic Dns Binary
Added by the RBOT-XM WORM! |
 |
Core.exe |
EA Core
Electronic Arts EA Link software - "gives you a secure yet simple way to download EA PC games and patches, as well as other exclusive content" |
 |
canary.exe |
Eac_Cnry
Added by the CANARY TROJAN! |
 |
claro.exe |
ecko
Added by the DLOADR-AQJ TROJAN! |
 |
china.bat |
eixfi
Added by the WCUP.A WORM! |
 |
check.exe |
eRecoveryService
Acer Notebook related. Acer eRecovery allows the user to restore the operating system or backup the current system profile, thus ensuring system integrity |
 |
ClientGW.exe |
eSnips
eSnips Client Gateway from eSnips |
 |
csrmss.exe |
ethernet adapter
Added by a variant of the RBOT WORM! |
 |
cmsrrs.exe |
Ethernet Driver
Added by a variant of the RBOT WORM! |
 |
config_.com |
Explorer
Added by the FLOPPY-D WORM! |
 |
config_.com |
Explorer5
Added by the VB.CBG WORM! |
 |
ClickYes.exe |
Express ClickYes
"Express ClickYes is a handy tool that runs in the system tray automatically clicks the Yes button for the Outlook Security security prompt, that asks you to confirm mail sending from third party applications" |
 |
ca.exe |
EZ Firewall
eTrust EZ Armor Internet Security |
 |
cisvc.exe |
FamilyKeyLogger
Family Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Located in %System%\CTF |
 |
csrss.exe |
FiendlyType
Added by the WEBUS TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
ctfmon.exe |
Firewall
Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir% |
 |
csrss.exe |
FirewallActivies
Added by the BANKER-AQ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "3041" subfolder |
 |
cseinst.exe |
Fortis Secure Layer Config
Fortis Bank Home Banking part. Installed during the installation of the software necessary to run the Home Banking. According to Fortis Bank this will not in any way be harmful to the system or relay system information |
 |
cnwism.exe |
GARO Status Monitor
Print monitor for certain Canon printers |
 |
confsvr.exe |
Gearbox
NTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available here |
 |
camacttiv.exe |
Generic Host Process
Detected by AVG Anti-Spyware as the CIADOOR.13 TROJAN! |
 |
CompuSpeed.vbs |
Geography TX 1.0 NT
Added by the NEWLEY-A WORM! |
 |
Cheatle.exe |
GigaByte
Added by the SHODI.B VIRUS! |
 |
cvir.exe |
go
Added by the SILOV-A WORM! |
 |
cpuserv.exe |
GT15J4R49V
Identified as a variant of the Trojan.Win32.Radi.gu malware |
 |
CMGrdian.exe |
Guardian
McAfee's QuickClean, an offline version of the one in their online Clinic. Normally run offline and not needed. Incidentally, incorporates more cleanup programs than the likes of WinOptimizer and System Mechanic |
 |
cledx.exe |
H2O
Related to copyright protection products by SyncroSoft |
 |
CXWibu.exe |
H2OWIBU
Related to CodeMeter from WIBU-SYSTEMS AG. Software protection hardware |
 |
coolbot.exe |
HELLBOT3
Added by the MYTOB.AB WORM! |
 |
canada.exe |
HELPER
AsdPlug premium rate adult content dialler variant |
 |
CamService.exe |
HerculesCamService
Related to the http://www.hercules.com/us/webcam/bdd/p/20/hercules-dualpix-hd-webcam/" target="_blank">Hercules Dualpix HD Webcam. What does it do and is it required? |
 |
CHDAudPropShortcut.exe |
High Definition Audio Property Page Shortcut
Realtek high definition audio related |
 |
cmd.exe |
hpcmd
Added by the ADCLICK-DS TROJAN! |
 |
c_pan.exe |
httpd
Added by a variant of the DELF-A TROJAN! |
 |
csrs.exe |
Intel Driver
Added by a variant of the SDBOT WORM! |
 |
cpunumber.exe |
IntelProcNumUtility
Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here |
 |
CLEARH~1.EXE |
Internet Disk Cleaner
"Internet Disk Cleaner from Elongsoft "protects your privacy by cleaning up all Internet tracks and past computer activities" |
 |
COMMANDER.EXE |
IomegaWare
Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs |
 |
compaq.exe |
IPOT Service Drivers
Added by a variant of the FUROOTKIT TROJAN! |
 |
csass.exe |
IPv6 Helper Driver
Added by the AGOBOT.TC WORM! |
 |
cfgwiz.exe |
IS CfgWiz
Norton Internet Security configuration wizard |
 |
certtool.exe |
ISS_Certtool
IBM Client Security Certification Tool |
 |
csrss.exe |
KernellApps
Added by the BANCBAN-AC TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "System" subfolder |
 |
csrss.exe |
Key Logger
Added by the BUCHON.A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root folder (ie, C:\) |
 |
csrss.exe |
Krnlcheck
Added by the BOTNACHALA TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
cxjx.exe |
KV_HOST
Added by the LEGMIR-BB TROJAN! |
 |
CNYHKey.exe |
ledpointer
Chicony Electronics Multimedia Keyboard Hotkey Driver |
 |
Copyer.exe |
LiveUpdate
Samsung PC Studio is a Windows-based PC program package that you can use easily to manage personal data and multimedia files by connecting a Samsung Electronics Mobile phone (GSM/GPRS/UMTS) to your PC. You can launch the update manually - see the instructions here for example |
 |
CPLBCL53.EXE |
LManager
System Tray icon found on Acer Travelmate laptops that allow you control access to the Internet and email buttons and other computer configurations |
 |
ctftpscr32.exe |
load
Added by the AGENT-FPN TROJAN! |
 |
cfgsys32.exe |
load=
?? |
 |
CameraAssistant.exe |
LogitechCameraAssistant
Related to Logitech QuickCams and provides additional configuration options for these devices |
 |
communications_helper.exe |
LogitechCommunicationsManager
Installed with a Logitech Quickcam Messenger and if disabled the camera will not work - at least not in the quick capture mode |
 |
CMagesta.exe |
MachineTest
Added by the SDBOT TROJAN! |
 |
csmsv.exe |
ManageProtocolCtrl
Added by the LOOKSKY.B TROJAN! |
 |
ComboButton.exe |
MaxtorCombo
Required to be able to use the Maxtor OneTouch button on your external Maxtor harddrive. It is used to start up backup software (Retrospect) |
 |
CPD.EXE |
McAfee Firewall
Firewall bundled with McAfee VirusScan 6.*. Can also be listed as CPD_EXE |
 |
CMGRDIAN.EXE |
McAfee Guardian
McAfee's QuickClean, an offline version of the one in their online Clinic. Normally run offline and not needed. Incidentally, incorporates more cleanup programs than the likes of WinOptimizer and System Mechanic |
 |
comsutil.exe |
Meeting Connection
Added by the PPDOOR-E TROJAN! |
 |
cihost.exe |
Memory Allocation Host
Detected by Avast as a variant of the IRCBOT-CHZ WORM! |
 |
ciserv.exe |
Memory Allocation Server
Added by an unidentified malware |
 |
cisrv.exe |
Memory Allocation Services
Detected by Trend Micro as the IRCBOT.FC TROJAN! See here |
 |
command.pif |
Messenger6
Added by the INZAE.B WORM! |
 |
cflmon.exe |
Micrcsoft Certificate Services
Added by the RBOT-FWV WORM! |
 |
comrel.exe |
Microsft Corporation Version 2001.12.4414
Added by a variant of the SDBOT TROJAN! |
 |
comserv.exe |
Microsft Corporation Version 2002.12.2414
Added by a variant of the SLAPER TROJAN! |
 |
cmh.exe |
Microsft Security Monitor Process
Added by a variant of the SDBOT WORM! |
 |
cab.exe |
Microsoft Cab Manager
Added by the DELF-JJ TROJAN! |
 |
calc.exe |
Microsoft Calculator
Added by a variant of the IRCBOT TROJAN! |
 |
csrs.exe |
Microsoft Client/Server Runtime Server Subsystem
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
csrssa.exe |
Microsoft Client/Server Runtime Server Subsystem
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
config.exe |
Microsoft Config File
Added by the KILLFILES.GR TROJAN! This is malware that will attempt to delete all system dlls! |
 |
cmmon.pif |
Microsoft Connection Manager Monitor
Added by the RBOT-AKV WORM! |
 |
crtl.exe |
Microsoft Control Center
Added by the RBOT-VX WORM! |
 |
CPU.exe |
Microsoft CPU Over Heat Manager
Added by a variant of the IRCBOT TROJAN! |
 |
cpxp.exe |
Microsoft CPXP Protocol
Added by the RBOT.ATP WORM! |
 |
crtmon.exe |
Microsoft CRT Monitor Manager
Detected by Trend Micro as the ROBOTON.A WORM! See here |
 |
csrss32.exe |
Microsoft CSRSS32 Protocol
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
csrss386.exe |
Microsoft CSRSS386 Protocol
Added by a variant of the SPYBOT WORM! |
 |
cihost.exe |
Microsoft Data Helper
Malware, possibly a variant of the LINST TROJAN |
 |
csdata32.exe |
Microsoft Data Machine
Added by a variant of the RBOT WORM! |
 |
chkfile.exe |
Microsoft DLL Verifier
Added by the RBOT-AOC WORM! |
 |
csrssv.exe |
Microsoft DLL Verifier
Added by the RBOT-ATK WORM! |
 |
cnsg.pif |
Microsoft Intrenet Explorer
Added by the RBOT-ARO WORM! |
 |
csrse.exe |
Microsoft Registry
Added by the RBOT-PC WORM! |
 |
CfgDll32.exe |
Microsoft Runtime
Added by the RANDEX.BD WORM! |
 |
cli.exe |
Microsoft Server Applacations
Added by the RBOT-GAQ WORM! |
 |
cdaccess.exe |
Microsoft software
Added by the RBOT.ABK WORM! |
 |
csrss.exe |
Microsoft SourceSafe
Added by the WEBUS TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
Cool.exe |
Microsoft System Checkup
Added by the DONK.B WORM! |
 |
CBRSS.EXE |
Microsoft System Restore Configuration
Added by a variant of the SPYBOT WORM! |
 |
cmsrg.exe |
Microsoft System32 Update
Added by the RBOT-GN WORM! |
 |
ctray.exe |
Microsoft task tray monitor
Added by a variant of the RBOT WORM! |
 |
cmss.exe |
Microsoft Update
Added by the RBOT-ATQ WORM! |
 |
crss32.exe |
Microsoft Update Machine
Added by a variant of the RBOT WORM! |
 |
csrss32.exe |
Microsoft Update Service
Added by the AGOBOT-HC WORM! |
 |
crmss.exe |
Microsoft USB2 Driver
Added by the RBOT-VK WORM! |
 |
cfmon.exe |
Microsoft Vista Upgrade Validation Service
Added by a variant of the IRCBOT BACKDOOR! |
 |
csrss.exe |
Microsoft Windows CSRSS
Added by the KALEL-A WORM! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
cgy32win.exe |
Microsoft Windows Files Loader
Added by the RBOT-AXR WORM! |
 |
csrss.exe |
Microsoft Windows Update Client
Added by the KEBEDE-G WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Systems32 |
 |
csrss.exe |
Microsoft Word Profissional
Added by the BANCBAN-DB TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "s1613" subfolder |
 |
csrss.exe |
Microsoft Word Profissional
Added by the BANKER-DJ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "protect" subfolder |
 |
csrss.exe |
Microsoft Word Profissional
Added by the BANKER-DP TROJAN! ! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "JavaVM" subfolder |
 |
cdrss.exe |
MicrosoftROMDriverService
Detected by Kaspersky as the IRCBOT.BLF TROJAN! See here |
 |
cmsssr.exe |
Microsofts Updatez
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
comzcinc.exe |
mlibsysmc
Added by the SDBOT-CXS WORM! |
 |
CD-Extractor.exe |
MP3 CD Extractor
"MP3 CD Extractor is an audio CD to MP3 ripper which can extract Digital Audio tracks from Audio CDs into files on the hard disk" |
 |
Csinsm32.exe |
MPEO
Automatic logging of installs from Norton CleanSweep - available via Start -> Programs |
 |
crssr.exe |
MS taskbar
Added by the RBOT-AGO WORM! |
 |
cdm.exe |
MS-Connect
Adult content dialler - see here |
 |
crsss.exe |
MSControl28
Added by the SPYBOT.AJX WORM! |
 |
cmdzxdll.exe |
MsgSvcMgr32
Added by the RBOT-AEK WORM! |
 |
ctfmoons.exe |
MSN
Added by the SPYBOT.HI WORM! |
 |
cssrss.exe |
MSN ang
Added by the FORBOT-CE WORM! |
 |
cvss.exe |
MSN Manager
Added by a variant of the SPYBOT WORM! |
 |
crsss.exe |
Msn Messanger
Added by a variant of the IRCBOT BACKDOOR! |
 |
check32.exe |
mspaint.exe
Added by the AGENT.AH TROJAN! |
 |
cnqmax.exe |
Mspatch89
Added by the RANDEX.P WORM! |
 |
comime.exe |
mssysint
Added by the NETSNAKE-I TROJAN! |
 |
criticalUpdate.exe |
MSUpdate
Affilred adware |
 |
clrschp038.exe |
MSVersion
Added by the POPMON.A TROJAN! - also known as PopMonster adware |
 |
crasos.exe |
mv2
Added by the DROPPS-A TROJAN! |
 |
CmdServ.exe |
MyLife
Added by the HOLAR.A WORM! |
 |
csrssp.exe |
NAV Auto Updates
Added by a variant of the SDBOT WORM! |
 |
cfgwiz.exe |
NAV CfgWiz
Introduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it |
 |
cfgwiz.exe |
NAV Configuration Wizard
Introduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it |
 |
COMDLGEX.EXE |
NB Common Dialog Enhancements
Part of McAfee Nuts & Bolts. With Common Dialog Enhancements, you can add MRU list box to open dialogs |
 |
cnen.exe |
nClient
Added by the DELBOT-AL WORM! |
 |
Csinsm32.exe |
NCS_SS
Same as CleanSweep Smart Sweep-Internet Sweep |
 |
csnss.exe |
NDAv
Added by the SERFLOG.C WORM! |
 |
csxrs.exe |
NETServices
Added by a variant of the SDBOT WORM! |
 |
csrs.exe |
NetWork
Added by the AGOBOT.JJ WORM! |
 |
csmn.exe |
New Csnm Manager
Added by the SDBOT.BZS WORM! |
 |
ctnmrun.exe |
NOMAD Detector
Detects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connected |
 |
crss32.exe |
Norton Auto Protect
Added by the SDBOT.ATF WORM! |
 |
ccApp.exe |
Norton Auto-Protect
Added by the AKHER.D WORM! Note - for the valid Norton AV entry the filename is "navapexe". This is also not the valid Norton AV file with the same filename |
 |
cgmenu.exe |
Norton Crashguard Monitor
Troublesome program that doesn't actually work with WinME so Norton removed it from SystemWorks 2001 |
 |
cpsdv.exe |
Norton Live Update Server
Added by the AGOBOT.EW TROJAN! |
 |
Cavapsvc.exe |
Norton Live Updater
Added by the GAOBOT.AO WORM! |
 |
csrss.exe |
Norton Protect Activies
Added by the BANKER-CZ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "D5133" subfolder |
 |
csrs.scr |
Norton System
Added by the BANLOA-AFM TROJAN! |
 |
cfgwiz.exe |
Norton SystemWorks
Norton System Works configuration wizard. Reportedly a resource hog. Many users find they can live without loading it |
 |
ccUpdate.exe |
Norton Update
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
cUpdate.exe |
Norton Update
Added by the AGOBOT.APP WORM! |
 |
ccUpdate.exe |
Norton Updater
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
CCUPD32.EXE |
nortonav
Added by an unidentified WORM or TROJAN! |
 |
ccEvtMngr.exe |
nortonsantivirus
Added by the HZDOOR-A TROJAN! |
 |
csrlss.exe |
NT Windows System Manager Loader
Added by the AGOBOT.OX WORM! |
 |
CiKewl.exe |
NTdhcp
Added by the QQROB-N TROJAN! |
 |
csrss.exe |
NTDLM
Added by the HALE TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "Qossrv" subfolder |
 |
ctfmun.exe |
ntuser
Detected by Symantec as the SILLYFDC WORM! See here |
 |
cstr.exe |
nvsv32.exe
Added by a variant of the SDBOT WORM! |
 |
clfmon.exe |
nvsvca32
Added by the TACTSLAY.E TROJAN! |
 |
complaint_7251.exe |
Nvt32
Added by the ARTIEF.B TROJAN! |
 |
Cmluc.exe |
ORiNOCO
Client Manager software for a Proxim ORiNOCO 11a/b/g wireless LAN PCI card |
 |
comippwa.exe |
p2snetis
Added by the SPAMTOO-AL TROJAN! |
 |
client.exe |
pagmstart
?? |
 |
Cleaner.exe |
PAL Evidence Eliminator
PAL Evidence Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis |
 |
Configtool.exe |
Palm MultiUser Config
MultiUser configuration for a Palm PDA device?. Is it required? |
 |
corona.exe |
PC-Config32
Added by the CORONEX.A WORM! |
 |
crcss.exe |
PCprot
Added by an unidentified WORM! |
 |
ctpdpsrvr.exe |
pdp Server
Included and setup with the drivers for my Compaq A3000 all-in-one printer/scanner - maybe for networking. Works fine without it - but may be needed when used over a network |
 |
chkfont.exe |
Pe2ckfnt SE
Used to check whether the fonts are installed properly on your computer or not for a scanner. If you don't want to execute it, you can uncheck it in the startup menu |
 |
CTFMDN.exe |
PHIME2004C
Added by the DLOADR-AMV TROJAN! |
 |
CALCHECK.EXE |
Photo Express Calendar Checker SE
If you create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper, Photo Express will replace the wallpaper automatically. Photo Express 2.0 has a calendar checker which checks the date on your system and updates your wallpaper accordingly |
 |
calcheck.exe |
PhotoExplosionCalCheck
Calendar management feature of Nova Development's Photo Explosion |
 |
config.cfg |
pop3 Server
Part of HTML2POP3 - "Convert Webmail to POP3.Is also included a SMTP/POP3 tunneling system that allow send and receive email in a private network HTTP PROXY based. All connection are plugin based. Over 250 email server supported and tested" |
 |
crsrr.exe |
Print Driver Helper Service
Added by the AGENT-BC TROJAN! |
 |
commonaccess.exe |
printer spooler
Added by the DELF-LB TROJAN! |
 |
CFGREG.EXE |
Printer Update
Maybe a registration reminder or automatically updates drivers or application software for a printer? |
 |
csrss.exe |
Prog
Added by the WEBUS TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
csrwjd.exe |
ProtocolEventTsk
Added by the STINX-N TROJAN! |
 |
ChannelUp.exe |
PSD Tools Channel
BuddyLinks adware |
 |
Cateye.exe |
Quick Heal On-Line Protection
Quick Heal - virus scanner |
 |
ccreal.exe |
Real Statics Agent
Added by a variant of the RBOT WORM! |
 |
csrss.exe |
RegDone Ex
Added by the WEBUS TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
class0117[random].exe |
Registry
Blackbox captures emails and chat logs, and monitors Internet activity - remove if you didn't intentionally install it |
 |
checkreg.exe |
Registry Startup Check
Added by the REMLOAD-A or DANMEC-B TROJANS! |
 |
csrss.exe |
RegWrite
Added by the SOKACAPS TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%Media |
 |
cmdno.exe |
relinson
Added by the DROPPER-PS TROJAN! |
 |
CsRemnd.exe |
Remndr
CasinoOnline foistware |
 |
CBSysTray.exe |
Remote Data Backups
System Tray access to Remote Data Backups online system/data backup utility |
 |
COBackup.exe |
Remote Data Backups
Remote Data Backups online system/data backup utility |
 |
CBSysTray.exe |
Remote Data Backups TaskBar Icon
System Tray access to Remote Data Backups online system/data backup utility |
 |
copyfstq.exe |
Resume Copy
Part of Total Copy - an improved version of the Windows copy function. Allows for resumption file copies or moves in progress when computer was shut down. Not required if your not using the program or don't care about that function |
 |
CSRSS.EXE |
RPCserv32g
Added by the BOBAX.AD WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
cchost.exe |
run
Added by the SQUATBOT-C TROJAN! |
 |
cmmpu.exe |
run=
MIDI emulator driver for the integrated sound chip by C-Media based on the CMI-8330 chip set normally found in cheap motherboards. Also installed as part of the software for a Guillemot Maxi Muse sound card (PCI) |
 |
cyxid98.exe |
run=
Unidentified malware |
 |
Celine.scr |
run=
Added by the CELINE-A TROJAN! |
 |
csrss.exe |
rundll32
Added by the GUTTA TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
csrss.exe |
Runner
Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
Csrss.exe |
Runtime Process
Added by the CIADOOR-J BACKDOOR! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
Connect.exe |
Sametime Connect
IBM Lotus Sametime - instant messaging and Web conferencing software |
 |
Control.exe |
SandboxieControl
SandBoxie - allows data to be read from the hard drive by an application but never written back unless you allow it |
 |
ConnectionManager.exe |
SBC Yahoo! Connection Manager
Used to create and connect your SBC Yahoo DSL connection. This program has been reported to cause problems for some users. If you find that it causes you pc to become slow or unstable you should uninstall it (using Add/Remove programs) and manually connect your DSL connection |
 |
csnss.exe |
SDAv
Added by the SERFLOG.C WORM! |
 |
csrss.exe |
SernellApp.pcx
Added by the BANCBAN-BJ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "D5133" subfolder |
 |
Csrrs.exe |
Service Controller
Added by the GAOBOT.AO WORM! |
 |
Compt.exe |
Service Drivers
Added by the RBOT-ZJ WORM! |
 |
csnss.exe |
Service Monitor
Added by the RBOT.EEH WORM! |
 |
csrss.exe |
Services
Added by a variant of the RANKY.U TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
ccapp32.exe |
ServicesLog
Added by the RBOT-AMX WORM! |
 |
cloaker.exe |
SetDefaultPrinter
Used by HP and Compaq computers to hide the windows of programs passed as arguments to it |
 |
Certutil.exe |
SetecCertUtil
Setec Web and Email Security. Setec PKI smart card software. The PKI technology enables secure and reliable user identification in services offered through Internet, mobile handsets and digital TV |
 |
createsw.exe |
setFTPBack
Added by the FTP_BMAIL TROJAN! |
 |
cftrb32.exe |
SFtrb Service
Added by the SOBIG.D WORM! |
 |
cnf.bat |
shambl3r
Added by the REMABL WORM! |
 |
chcenter.exe |
Shcenter
IMSI HiJaak - "the easiest way to convert, capture, and manage all your graphic files" |
 |
csrss.exe |
Shockwave
Added by the SNDOG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
color.exe |
siscolor
Probably on-board graphics related based upon the SiS chipsets. Has been seen on ASUS motherboards with SiS chipsets and known to cause conflicts if you choose another graphics card and disable the on-board |
 |
clisvc95.exe |
SMS Client Service
When the SMS Client service starts on a domain controller, the Client service modifies the SMSCliToknAcct & user account group membership, user rights, and account comment. The Client service then waits for the synchronization of the comment to verify that the account and user rights are properly set for this account. This account is used to obtain a token to start the SMS Client processes, such as the Software Inventory and Software Distribution agents (MS Systems Management Server) |
 |
comsysobj.exe |
SMSERIALWORKSTARTER
Detected by McAfee as the FAKEALERT-AH TROJAN! See here. Installed with the SpyBurner spyware remover - which is not recommended, see here |
 |
csrss.exe |
smss.exe
Added by the DALBUG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
crssrs.exe |
SP2 Firewall/Internet Updater
Added by the RBOT.BJO WORM! |
 |
CTSRReg.exe |
Speed racer
Software for a Creative sound card |
 |
csmss.exe |
spoolsvr32
Added by the AGENT-AU TROJAN! |
 |
csmss32.exe |
spoolsvr32
Added by a variant of the AGENT-AU TROJAN! |
 |
cc.exe |
SQConfigChecker
Xupiter SQWire toolbar related. Use Spybot S&D, Adware or similar to detect and remove and to prevent it re-installing in the future see here |
 |
comet.exe |
SSWPlauncher
Comet Cursor adware |
 |
CurePCSolution.exe |
Start CurePCSolution
CurePCSolution spyware remover - not recommended, see here |
 |
cm20.exe |
Start RF Wireless Mouse
Yuanxun Electronics RF wireless mouse driver |
 |
CLIStart.exe |
StartCCC
Puts the ATI Catalyst™ Control Center Icon/Shortcut on the System Tray - available via Start → Programs |
 |
CKOTS.exe |
startkey
Added by the BIFROSE-HM TROJAN! |
 |
Cvshost.exe |
Startup Update
Added by the GAOBOT.AO WORM! |
 |
csrss.exe |
State Service
Added by the DADOBRA-CP TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
ccEvtMngr.exe |
SunJavaSched
Added by the SDBOT-YP WORM! |
 |
CTMONTv.exe |
svcshare
Added by the FUJACKS-AJ WORM! |
 |
checksys.exe |
svhoost
Added by a downloader TROJAN of Chinese origin! |
 |
Connect.exe |
SX Virtual Link
SX Virtual Link from Silex Technology America, Inc. Utility to connect USB devices |
 |
crss.exe |
Sygate Personal Port
Added by the RBOT-PX WORM! |
 |
ccsrn.exe |
Sygate Personals Firewalls
Added by a variant of the RBOT WORM! |
 |
ccapp.exe |
Symantec
Added by the REATLE WORM! Note - this is not a Symantec file |
 |
ccApp32.exe |
Symantec Configuration Loader
Added by a variant of the GAOBOT WORM! |
 |
ccApp.exe |
Symantec Service
Added by the AKHER.D WORM! Note - this is also not the valid Norton AV file with the same filename |
 |
CKA.exe |
SymKeepAlive
Part of Norton SystemWorks 2003 - keeps a dial-up modem connection alive |
 |
ccApps.exe |
SymRun
Added by the KAGEN-A TROJAN! |
 |
cber.exe |
System
Added by an unidentified TROJAN! |
 |
csrss.exe |
System
Added by the LDPINCH.E TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
crss.exe |
System Config Manager
Added by the AGOBOT.GH WORM! |
 |
cpqdiaga.exe |
System DLF
Compaq Diagnostic record system utility which allow you to view information about your computer's hardware and software configuration. Available via Start -> Programs |
 |
cpsq32.exe |
System Drivers
Added by the SDBOT.AXH WORM! |
 |
cnstat.exe |
System Failure Statistic
Added by the RBOT-LF WORM! |
 |
commandprompt32.exe |
System Firewalls
Added by the RBOT.BJT WORM! |
 |
csrss32.exe |
System Log Event
Added by the AGOBOT-JI WORM! |
 |
cute.exe |
System Monitoring
Added by the RAHIWI.A WORM! |
 |
csrss.exe |
System Process
Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
CSRSR.exe |
System Process
Added by the AGOBOT-SQ WORM! |
 |
coderxt.exe |
System Service
Added by the RBOT-ALD WORM! |
 |
connection.exe |
System Services
Added by an unidentified WORM or TROJAN! |
 |
charmapx.exe |
System startup
Only required if using an oriental language |
 |
CSysTime.exe |
System time updator
Added by the RANDEX.S WORM! |
 |
crhwss.exe |
System Updater Machine
Added by the CIADOOR-DQ TROJAN! |
 |
Csrtss.exe |
System132
Added by the LANFILT-I TROJAN! |
 |
crsvvc.exe |
System32
Added by the RBOT.BLY WORM! |
 |
csrss.exe |
SystemDriver
Added by the ASCETIC.B TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\addins\explorer |
 |
CVT.exe |
SystemGent
Added by the BRONTOK-H WORM! |
 |
csrwnd.exe |
SystemProcEvent
Added by the IRCBOT.I TROJAN! |
 |
csrss.exe |
SYSTEMSars32
Added by the AHLEM.A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
CDPlay.EXE |
SystemTra
Added by the LOVGATE.Z WORM! |
 |
cmman32.exe |
sysupdate
Added by a variant of the SDBOT WORM! |
 |
csta.exe |
SysW8
Clean Space internet evidence eliminator |
 |
cmosvc.exe |
Task Alert
Added by a variant of the IRCBOT TROJAN! |
 |
CTLTask.exe |
TaskBar
Creative SoundBlaster Audigy Taskbar - used to choose between different types of EAX Effects, not required in startup. NOTE: if you get a ctltask.exe error message while installing the Audigy drivers, see this Microsoft Knowledge Base article |
 |
csrss.exe |
TaskMrg
Added by the LDPINCH-W TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
CTLTray.exe |
Tasktray
Installed with the Sound Blaster Audigy range of soundcards. Allows you to set EAX effects or equalizer settings for the Sound Blaster Audigy from a systray icon. Also allows you to launch the Taskbar via right-click → Show Taskbar. The tasktray can be accessed via Start → Programs → Creative → Sound Blaster Audigy → Taskbar |
 |
comm.exe |
Timer
Added by the IP TROJAN! |
 |
cfinst.exe |
TMA distribution
Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients |
 |
cPaner.com |
Topic cPanr
Detected by Trend Micro as the SDBOT.AJP WORM! See here |
 |
cmdel.exe |
TrueMobile 1150 Client Manager
Client Manager for the Dell TrueMobile 1150 Series PC Card - "a wireless network PC Card that fits into any standard PC Card Type II slot. It has two LED indicators and an integrated antenna" |
 |
C7XRCtl.exe |
TV878 Remote Control
Related to Kworld TV878 Tuner |
 |
CalCheck.exe |
Ulead Calendar Checker
Ulead Calendar Checker - part of Ulead Photo Express - automatically replaces your calendar desktop wallpaper on a weekly/monthly/yearly basis if you've created them. Not required - change them manually |
 |
calcheck.exe |
Ulead Photo Express Calendar Checker
If you create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper, Photo Express will replace the wallpaper automatically. Photo Express 2.0 has a calendar checker which checks the date on your system and updates your wallpaper accordingly |
 |
calcheck.exe |
Ulead Photo Express x.0 Calendar
Ulead Calendar Checker - part of Ulead Photo Express, where "x" represents the version number. Automatically replaces your calendar desktop wallpaper on a weekly/monthly/yearly basis if you've created them. Not required - change them manually |
 |
CDUpdater.exe |
Update
"Carpe Diem" adult premium rate dialler related |
 |
csrss.exe |
Update
Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
csrss.exe |
Update
Added by the MEHEERWAR TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "winupdate" subfolder |
 |
configs.exe |
Update32
Hijacker, also detected as the QURL-2 TROJAN! |
 |
CNF UPD.EXE |
UpdateComponent
Added by the SPYBOT.GEN VIRUS! |
 |
CTFMON32.EXE |
User Input Services
Added by the MANCSYN.AK TROJAN! |
 |
choo_003956f4 |
userinit
Added by the PEED.16896 TROJAN! |
 |
cologsver.exe |
Userinit
Added by the DROPPER.DJO TROJAN! |
 |
comctl_32.exe |
VB_run
Dubious downloader from densmail.com |
 |
csmss.exe |
VC5MediaPlayer
Added by the DEDLER-B WORM! |
 |
cpad.exe |
Verizon Control Pad
Control Pad - installed with Verizon DSL accounts. Tool designed to streamline the online experience |
 |
click2call.exe |
Vonage
Vonage Voice over IP Internet phone service |
 |
cfpsys.exe |
Warning: do not remove it! (system)
Folder Password Protect - a program that lets you set a password on folders of your choice |
 |
checker.exe |
WashAndGo - Cleanup of old Backupfiles
WashAndGo - temp file cleaner |
 |
coloreal.exe |
WCOLOREAL
Makes colours sharper and brighter, but will only work with coloreal capable monitors |
 |
command32.exe |
Win Command
Added by the AGOBOT.XQ WORM! |
 |
ctfnom.exe |
Win Updator Services
Added by a variant of the WOOTBOT WORM! |
 |
CTHELPER32.EXE |
Win32 FireWire Driver
Added by the WOOTBOT TROJAN! |
 |
crsrs.exe |
Win32 Information Service
Added by the RINBOT.Y WORM! |
 |
crss.exe |
Win32 Network Driver
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
crsss.exe |
Win32 Security Service
Added by the DELBOT-O WORM! |
 |
clienttimer.exe |
WIN32DS
Eziin adware |
 |
clienttimer.exe |
WIN32io
Eziin adware |
 |
csmss.exe |
WIN95DEFVIEW
Added by the DEDLER-D TROJAN! |
 |
check.exe |
WinCheck
Added by the DELBOT-Y WORM! |
 |
colwindos.exe |
Wind0ws Ser7ice Agent
Added by the RBOT-GQO TROJAN! |
 |
Cfreer.exe |
Windows
Added by the CULLER-C WORM! |
 |
crtss.exe |
Windows (ICS) Spooler
Added by a variant of the RBOT WORM! |
 |
csrss.exe |
Windows 2004
Added by the BANKER-DY TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Arquivos de programas\Windows 2004\Tools |
 |
csrs.exe |
Windows Action
Added by the SECCMU-A WORM! |
 |
csrss.exe |
Windows Client Service 32
Added by the RBOT-ALB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a drivers&92;winsdriver subfolder |
 |
csrs.exe |
Windows Client/Server Runtime Server
Added by the RBOT.KD WORM! |
 |
config.exe |
Windows Config System
Added by a variant of the SDBOT WORM! |
 |
Control.exe |
Windows Control
Browser hijacker. NOTE - On Win9x systems it will overwrite the Windows file of the same name in the Windows directory, so therefore it will be necessary to extract a fresh copy of the file from the Windows setup cabs! |
 |
CSRCS.EXE |
Windows Custom Services
Added by the SPYBOT-EI WORM! |
 |
cmnvc.exe |
Windows Disk Manager
Added by a variant of the IRCBOT TROJAN! |
 |
csrss.exe |
Windows Explorer SP2
Added by the BANKER-DM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "JavaBeans" subfolder |
 |
chh.exe |
Windows firewall manager
Added by a variant of the RANDEX.GEL WORM! |
 |
cronos.exe |
Windows Firewall Updater
Added by the RBOT-GBY WORM! |
 |
ctfcom.exe |
Windows Firewall Updater
Added by the RBOT-GCB WORM! |
 |
comngr.exe |
Windows Hijack Protection
Added by the AGENT-FYD TROJAN! |
 |
commngr.exe |
Windows Hijack Protection System
Added by a variant of the AGENT-FYD TROJAN! |
 |
civsc.exe |
Windows Loader Service
Added by a variant of the RBOT WORM! |
 |
crvss.exe |
Windows media service
Added by the SDBOT.VP WORM! |
 |
crsss.exe |
Windows media service
Added by the RBOT.ACY WORM! |
 |
cvrsss.exe |
Windows media services
Added by the RBOT-MW WORM! |
 |
crease.exe |
Windows Media Updater
Added by the RBOT-ATI WORM! |
 |
crss.exe |
Windows Registry Security
Added by a variant of the IRCBOT TROJAN! |
 |
czf.exe |
Windows Service Agent
Added by the RBOT-GAJ WORM! |
 |
co0l.exe |
Windows Service Agent
Added by the RBOT-GQY WORM! |
 |
config.exe |
Windows Service Layer
Added by the RBOT.DDJ WORM! |
 |
ctfmon32.exe |
Windows Services M7
Detected by Kaspersky as the AGENT.WOH TROJAN! See here |
 |
ctfmon32.exe |
Windows svchost
Added by a variant of the SPYBOT WORM! See here |
 |
ctech.exe |
WINDOWS SYSTEM
Added by the MYTOB-KD WORM! |
 |
cmxp.exe |
Windows System File
Added by the SPYBOT.KHO WORM! |
 |
CRSL.EXE |
Windows System Manager
Added by the SDBOT.MG WORM! |
 |
crssm.exe |
Windows System Manager
Added by the RBOT-AFH WORM! |
 |
clsas32.exe |
Windows System32
Added by the RBOT-AZO WORM! |
 |
ctwsvc.exe |
Windows Tracking Client
Added by the AGENT-GMB TROJAN! |
 |
csrss.exe |
Windows Update
Added by the BANKER-HM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
ctfmoom.exe |
Windows Update Firewall System
Added by the RBOT-GAN WORM! |
 |
csrs.exe |
Windows Update Service
Added by the AGOBOT-NI WORM! |
 |
cstsm.exe |
WindowsDiskLog
Added by the STINX-C or STINX-D TROJANS! |
 |
csrss.exe |
Windowsupdate Service
Added by the BABA-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root folder (ie, C:\) |
 |
CTHELPER.EXE |
WINDVDpatch
CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative's sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a "leave alone" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it |
 |
cssrs.exe |
WinFX
Added by the AGOBOT.FX WORM! |
 |
cleanmg.exe |
winlogon
Added by the AGENT-ICR TROJAN! |
 |
Command.exe |
WinProfile
Added by the BUDDY TROJAN! |
 |
cfgpwnz.exe |
Wins32 Online
Added by the BROPIA.R WORM! |
 |
cassl.exe |
winservit
Added by the RBOT.ASG WORM! |
 |
copy C:WINDOWSwinshow.new C:WINDOWSwinshow.dll |
WinShowUpdate
Winshow parasiate related - from the "RunOnce" keys it replaces "winshow.dll" with a new version |
 |
CFTMON.EXE |
Winsock2 driver
Added by a variant of the IRCBOT BACKDOOR! |
 |
ccsrs.exe |
WINTASKMGR
Added by the MYTOB.Q WORM! |
 |
CSRSS.EXE |
WinUpdateAdministrator
Added by the PUNYA-A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Application Data\WINDOWS |
 |
csrss.exe |
WinUpdateProtection
EmployeeWatch is a commercial surveillance software program designed to monitor user activity on a computer. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a subfolder of C:\windowsupdate\ufp |
 |
csrss.exe |
WinXP
Added by the BANCOS-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\WinXP\Tools |
 |
Cappp.exe |
Winxp update
Added by the RBOT.DKO WORM! |
 |
CSRSS.exe |
WinXP-98
Added by the BANKER-DS TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Arquivos de programas\WinXP-98\Tools |
 |
clockwise.exe |
wise
Added by the LAZAR-A TROJAN! |
 |
cssrss.exe |
WMDM PMSP Service
Added by the KNOCKIT-A TROJAN! |
 |
CnxMon.exe |
WooCnxMon
Wanadoo ISP software related - not required - here's how to bypass it |
 |
csrsvcs.exe |
WSAConfiguration
Added by the AGOBOT.VI WORM! |
 |
csass.exe |
WSAConfiguration1
Added by the AGOBOT.WH WORM! |
 |
CVDAsDW.exe |
XPSoft
Added by the SDBOT-SY WORM! |
 |
cskware.exe |
xware
Malware downloader from xxsware.com, produces adult content popups |
 |
Commandr.exe |
zBrowser Launcher
For a Logitech internet keyboard - loads the software for the shortcut keys on the keyboard. Also used to display your keyboard LEDs on-screen to indicate Caps Lock, etc if it doesn't have them |
 |
csrss.exe |
ZoneUpdate
WinSpy surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "ComRoot" subfolder |
 |
cxdxregt.exe |
Zstart
ZenoSearch adware |
 |
cabview1.exe |
[random 12 digit number]
Adsrv.com/IeDriver adware variant |
 |
catsrvps.exe |
[random 12 digit number]
Adsrv.com/IeDriver adware variant |
 |
cmpbk321.exe |
[random 12 digit number]
Adsrv.com/IeDriver adware variant |
 |
CXTPLS_LOADER.EXE |
[random name]
AproposMedia adware |
 |
chkdsk.exe |
[random name]
PurityScan/Clickspring adware. Unlike this file, the legitimate Windows chkdisk.exe will in Windows XP/2K/NT always be located in the WinntSystem32 or WindowsSystem32 folder, and ought moreover NOT to figure among the startups! |
 |
charmapnt.exe |
[random name]
Added by the BANCOS-DR TROJAN! |
 |
csrssc.exe |
[random name]
Detected by Trend Micro as the AGENT.EBC TROJAN! See here |
 |
crsrs.exe |
[various names]
Added by the FORBOT-AK WORM! |
 |
clamav.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
cmon14.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
cnftips.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
control64.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
corrida.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
CToolBar.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
csrss.exe |
_SystemDriver
Added by the ASCETIC.B TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\addins\explorer |