Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help Forums Windows Startup Programs Database Virus, Spyware, and Malware Removal Guides Computer Tutorials Uninstall Database File Database Computer Glossary Computer Resources
 

Alert!  Have a problem and would like to ask us for help? To learn how to ask your question Click Here!
Stop!  Do you have popups or other malware infecting your computer? If so, Start Here!
Question?  Are you having trouble using this site? Then you should visit the New User Orientation Center!



A    B    C    D    E    F    G    H    I    J    K    L    M    N    O    P    Q    R    S    T    U    V    W    X    Y    Z    Other   
HJT: F0, F1, F2, F3 · O4 · O20 · O21 · O22 · O23
Rootkit List  · Submit a Startup  · Top Submitters
 Startup Index · Newest Entries · Mozilla Search Tools · WebMaster Site Tools · Status Key
Startup Database Forum · Computer Help Forums · How to use the Startup Database

Enter the filename or keyword you would like to search for:
Advanced Search

Name Filename Status Description
adgpfoxs adgpfoxs.dll
X
Identified as a variant of the Adware.Agent malware.
TurboNet c.exe
X
Added by the Troj/Renos-EA Trojan associated with rogue security programs.
Videohost c.exe
X
Unknown malware. Most likely a variant of the Trojan.Win32.FraudPack.gen malware. ... Read More
D5586E6C C107BE90.EXE
X
Added by the Troj/BDoor-AFB backdoor Trojan.
{29F97553-FBD6-33D1-BFC1-47A024D1875C} c2c.dll
X
Added by the Troj/Sifr-A information-stealing Trojan. This file also installs the following files in the same folder as c2c.dll: Nero7Keygen.exe,
Read More
c32cs2 c32cs2.exe
?
Part of the Cyber Sentinel Internet filtering software. Does anyone know if what this does? ... Read More
c c:\archiv~1\win.com
X
Added as a result of the CUYDOC VIRUS! ... Read More
Notepad C:\ASAP!!!.txt
X
Added by the Trojan.Randsom.B ransoming Trojan. Trojan.Randsom.B is a Trojan horse that encrypts files on the compromised computer and then issues a r ... Read More
chkdsk c:\autoexec.bat
X
Added by the ANPES WORM!
OpenCom C:\IO.COM
X
Added by the W32/VB-CRL mass-mailing worm.
BootCom C:\IO.COM
X
Added by the W32/VB-CRL mass-mailing worm.
iseeu.exe C:\WINDOWS:iseeu.exe
X
A variant of the Backdoor:W32/PoisonIvy backdoor Trojan. Backdoor:W32/PoisonIvy is a family of backdoors that give a remote user extensive access to a ... Read More
SIMO.exe C:\WINDOWS:slm.exe
X
A variant of the Backdoor:W32/PoisonIvy backdoor Trojan. Backdoor:W32/PoisonIvy is a family of backdoors that give a remote user extensive access to a ... Read More
{7bcd1ddf-1d68-751a-15f8-4900acc0df46} C:\WINDOWS\system32:cmd.exe
X
Identified as a variant of the Backdoor.Win32.Poison.k keylogger.

Please note that this infection is an Alternate Data Stream file attach ... Read More
svchost.exe C:\WINDOWS\system32:hh2.exe
X
A variant of the Backdoor:W32/PoisonIvy backdoor Trojan. Backdoor:W32/PoisonIvy is a family of backdoors that give a remote user extensive access to a ... Read More
hack1x2 C:\WINDOWS\system32:hlpnod32.exe
X
A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote serv ... Read More
Modifiet Amateur C:\WINDOWS\system32\msl.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
msqn32.dll C:\Windows\System32\msqn32.dll
X
Added by the W32/Feebs-P P2P worm.
ez firewall ca.exe
Y
eTrust EZ_Armor Internet Security ... Read More
JVM0.12 caac.exe
X
Identified as Trojan-Downloader.Win32.Agent.jc.
{9B71D88C-C598-4935-C5D1-43AA4DB90836} caam.exe
X
A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote serv ... Read More
Microsoft Cab Manager cab.exe
X
Added by the Troj/Delf-JJ Trojan! File is found in the root of the C: drive.
Cabchk Cabchk.exe
X
Added by the GEMA TROJAN!
Cabchk32 Cabchk32.exe
X
Added by the GEMA TROJAN!
CABCInstall CABCInstall.exe
X
CABC content delivery software
[not used] Cable.exe
X
Added by the W32/Cablenet-A worm.
<not used> cabvh323.dll
X
Added by the W32.Stration.D@mm mass-mailing worm. W32.Stration.D@mm is a mass-mailing worm that gathers email addresses from the compromised computer. ... Read More
[random 12 digit number] cabview1.exe
X
Adsrv.com/IeDriver adware variant
Cacheman Cacheman.exe
N
Freeware disk cache tweaker from Outer Technologies. Should only be run once and not loaded at start-up ... Read More
CachemanXP CachemanXP.exe
Y
"CachemanXP is a system service designed to improve the performance of your computer by optimizing several caches, auto-recovering RAM and fine tuning ... Read More
CacheMgr CacheMgr.exe
Y
Sophos Antivirus Remote Update
cachesentry pro CacheSentry Pro.exe
U
Related to CacheSentry_Pro A program that takes over the management of the Internet Explorer (and AOL) web browser cache. ... Read More
CACStarter cacstart.exe
N
Cash A Check - check writing software
CADS cads.exe
U
Cyber Sentinel internet filtering software
cafestation CafeStation.exe
U
Related to CafeSuite the solution for your internet cafe. ... Read More
cafwc cafw.exe
Y
Part of the CA Personal Firewall application.
ABBYY Community Agent CAGENT.EXE
N
Installed with the Optical Character Recognition (OCR) software that comes bundled with a Compaq A3000 all-in-one printer/scanner. Its function appear ... Read More
CAgent CAgent.exe
N
Abbyy Fine Reader OCR (Optical Character Recognition) software for scanning and converting documents ... Read More
CahootWebcard CahootWebcard.exe
N
"The Cahoot Webcard is a virtual card that allows you to use your Cahoot credit card online without ever having to expose your real card numbers over ... Read More
caissdt caissdt.exe
U
Related to Computer_Associates Dashboard Tray Applet.
Dir1 caKe
X
Added by the CAKE WORM!
DlDir1 caKe
X
Added by the CAKE WORM!
Cake Cake.vbs
X
Added by the VBS/Sode-E worm.
calc calc.dll
X
Added by the Opachki.a Trojan. Please note that rundll32.exe is a legitimate program and should not be deleted. ... Read More
calc.exe calc.exe
X
Added by the W32.Ackpra.A worm. W32.Ackpra.A is a worm that spreads by copying itself to network shares and removable drives. It may also download pot ... Read More
Microsoft Calculator calc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Tibiabot calc.exe
X
Added by the BackDoor-CEP!ic backdoor Trojan. This infection uses Alternate Data Streams to hide itself. In order to remove these files you will nee ... Read More
CALC32 CALC32.EXE
X
Added by the W32/Spybot-EC worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Photo Express Calendar Checker SE CALCHECK.EXE
N
If you create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper, Photo Express will replace the wallpaper automatically. Photo Express ... Read More
Ulead Photo Express x.0 Calendar calcheck.exe
N
Ulead Calendar Checker - part of Ulead Photo Express, where "x" represents the version number. Automatically replaces your calendar desktop wallpaper ... Read More
Calendar 200X Reminder calendar.exe
N
Calendar 200X - shows holidays, reminders of various anniversaries,tasks etc
calk calk.exe
X
The Troj/StartPa-FH TROJAN adds this to modify Internet Explorer settings.
hola call of duty.exe
X
Added by the W32.Nujama.B worm. W32.Nujama.B is a worm that spreads through mapped drives and shared folders, and lowers security settings on the comp ... Read More
msennger calling.com
X
Added by the Troj/Zapchas-EB Trojan.
Canon Camera Access Library 8 CALMAIN.exe
U
Installed as part of the Canon digital camera software. This service is required to start if you wish to use the Canon CameraWindow software. ... Read More
Cal Reminder Shortcut calrem.exe
N
Produces a pop-up reminder of events scheduled using the MS Office Calendar
{9B71D88C-C598-4935-C5D1-43AA4DB90836} cam.exe
X
Added by the Troj/Bifrose-VM Trojan.
{9D71D88C-C598-4935-C5D1-43AA4DB90836} cam2.exe
X
A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote serv ... Read More
Generic Host Process camacttiv.exe
X
Identified by AVG Anti-Spyware as Backdoor.Ciadoor.13.
CamCheck CamCheck.exe
N
NuCam camera software related
Camera Detector Camdetect.exe
N
ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically ... Read More
Camera Detector CAMDET~*.EXE
N
ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically ... Read More
cameno Cameno.exe
U
Cameno is a program which brings tabbed windows to MSN Messenger 6.0 and above ... Read More
logitechcameraassistant CameraAssistant.exe
N
Related to Logitech QuickCams and provides additional configuration options for these devices. This program is non-essential process to the running of ... Read More
CameraFixer CameraFixer.exe
?
May be related to Bestcam webcams.
Camfrog Camfrog Video Chat.exe
N
Webcam and video chatroom software for use on the CamFrog site.
Creative WebCam Tray Camtray.exe
N
Creative WebCam tray control - can be started manually
Canada Canada.exe
N
Known to be a dialler - but is it maliscous or clean?
ASDPLUGIN canada.exe
X
Malware adult dialer.
ColdFusion Management Service CANamingAdapter.exe
Y
Supports ColdFusion Management features, including Archive/Restore and Server Reporting. ... Read More
Canary canary-std.exe
U
Added by the Spyware.Canary surveillance software. This program should be uninstalled if not installed by yourself. ... Read More
Eac_Cnry canary.exe
X
Added by the CANARY TROJAN!
CanerServer caner.exe
X
Added by the Troj/Hupigon-ES backdoor Trojan.
cap3on CAP3ONN.EXE
?
Canon driver, purpose unknown - is it required in startup? ... Read More
Capture Express 2000 capexp.exe
N
Capture Express - screen capture utility
capfaem capfaem.exe
Y
This is the core engine for the CA Personal Firewall software.
Capfax capfax.exe
N
PhoneTools fax software
capfupgrade capfupgrade.exe
Y
Part of CA security suite.
caping CAPing.exe
U
Citibank Citianywhere software
Canon PC1200 iC D600 iR1200G Status Window CAPM1LAK.EXE
N
Canon P1200 printer status
Capon Capon.exe
Y
Canon printer driver
capon Caponn.exe
Y
Canon printer driver
SRVState_REPCLIENT capslock.exe
X
Added by the Troj/Hasik-A Trojan.
Captainhook CaptainHook.exe
?
Part of the Novell Client.
Captcha7 captcha.dll
X
Added by the W32/Koobface.worm.gen.h worm. The W32/Koobface.worm.gen.h is a variant of Koobface worm, which infects users of Facebook who visit malici ... Read More
capture capture.exe
X
Added by the Troj/Theef-B keylogging Trojan.
eSettings Service capuserv.exe
N
Acer's eSettings software allows you to view your system information, set configuration and boot options, and manage passwords. ... Read More
start extracting car.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Carbonite Backup CarboniteUI.exe
N
Added by the Cabonite online backup service.
Care20 Care20.exe
X
TopMoxie adware
care2gtu Care2GTU.exe
U
Care2 Green Thumbs-Up (from the Care2 site). Every online purchase helps environmental causes; tells you how eco-friendly a company really is, thanks ... Read More
CARPservice carpserv.exe
U
Associated with Zoltrix modems - enables the internal modem speaker, allowing you to listen to the dial-up sounds for example ... Read More
CARPserver CARPserver.exe
X
Added by the BANKER-AN TROJAN!
ConfiggLoader cart322.exe
X
Added by the GAOBOT.DJ WORM!
cartao cartao.exe
X
Added by the Troj/Banker-AY TROJAN, which will also use cartao2.exe.
cas2stub cas2stub.exe
X
CasinoClient Adaware! ... Read More
CasAgnt CasAgnt.exe
U
Program by Extended Systems which allows you to sync your Casio PDA with your PC ... Read More
CAS Client casclient.exe
X
Added by the Adware.CasinoClient.
SettingValue casd.exe
X
Added by the W32/Sdbot-PGworm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
caseyvideo CaseyVideo.exe
X
Malware causing p0rn popups
caseyvideo caseyvideo[*].exe [* = digit]
X
Malware causing p0rn popups
CashBack cashback.exe
X
Part of eXact Advertising Software, consisting of "CashBack by BargainBuddy", BullsEye Network and NaviSearch ... Read More
Cashsurfers Cashbar Navigator Cashbar.Exe
N
Cashsurfers CashBar Navigator - "The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers a ... Read More
cashfiesta Cashfiesta.exe
X
CASHFIESTA.A pay-per-surf adware ... Read More
Caspian-x27 Caspian-x27.exe
X
Added by the W32/Katomik-B worm.
XXXCodec Service casrv.exe
X
Identified by Kaspersky as Trojan-Downloader.Win32.Small.czh
cassandra cassandra.exe
X
Melkosoft_Cassandra adware - also detected as a variant of the WIN32.KREPPER TROJAN! ... Read More
winservit cassl.exe
X
This is an Rbot variant. This infection connects to an IRC server where it will await commands from a remote user. ... Read More
CasStub casstub.exe
X
Added by the Troj/Cass-A trojan.
Diskstart cat.exe
X
MS-Connect dialler
cat cat.exe
N
Added by the CodeAmber desktop ticker. This program displays a ticker on your desktop showing all of the current Amber Alerts. ... Read More
Quick Heal On-Line Protection Cateye.exe
Y
Quick Heal - virus scanner
(random 12 digit number) catsrvps.exe
X
Adsrv.com/IeDriver adware variant ... Read More
ComPlusSetup catsrvut.dll
Y
Part of Microsoft Com+
Norton Live Updater Cavapsvc.exe
X
Added by the GAOBOT.AO WORM!
cavrid CAVRID.exe
Y
eTrust™ EZ_Antivirus
CAVS CAVS.exe
Y
Cheyenne (now eTrust) antivirus
caavtray CAVTray.exe
Y
eTrust™ EZ_Antivirus
caxchg caxchg.exe
?
Used by a USB Flash card reader.
CAZNOVAS CAZNOVAS.exe
X
Added by the CAZNO TROJAN!
CBACK.EXE CBACK.EXE
X
Added by the Troj/Penta-A downloader trojan.
system cber.exe
X
Added by an unidentified TROJAN!
CbEvtSvc CbEvtSvc.exe
X
Identified by Kaspersky as a variant of the Trojan-Downloader.Win32.Agent.jhj Trojan. A link to download this malware is sent as email spam. The con ... Read More
ICQMsn cbfks.exe
X
Added by the Troj/Ranck-AH proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
cbidf2k cbidf2k.sys
Y
CardBus/PCMCIA IDE Miniport Driver Added by Microsoft Corportation
Cobian Backup 8 interface cbInterface.exe
U
User interface for Cobian Backup 8.
CallBumping cbpopw.exe
Y
Associated with the Gazel 128 PCI ISDN adapter. This program is required if you use the ISDN adapter. ... Read More
Microsoft System Restore Configuration CBRSS.EXE
X
Added by a variant of the SPYBOT WORM!
CBWAttn CBWAttn.exe
U
Required for Bitware to answer incoming faxes, can cause sleep mode problems
CBWUser CBWDial.exe
?
Associated with Bitware that integrates fax, voice, pager, and data communications on your desktop ... Read More
CBWHost CBWHost.exe
U
Required for Bitware to answer incoming faxes, can cause sleep mode problems
cbxvssp cbxvssp.dll
X
Identified by Kaspersky antivirus as a varient of the AdWare.Win32.Virtumonde.gen malware. ... Read More
SQConfigChecker cc.exe
X
Xupiter SQWire variant - adware and homepage hijacker. Note - cannot be removed via the Xupiter website in the same way as other Xupiter variants ... Read More
ccagent.exe ccagent.exe
X
Added by the Control Center rogue anti-spyware program.
Core Process Aplication ccapl.exe
X
A variant of the RBot family of worms and IRC backdoor Trojans.
Core Process Aplication x16 ccapl16.exe
X
A variant of the RBot family of worms and IRC backdoor Trojans.
Core Process Aplication x32 ccapl32.exe
X
A variant of the RBot family of worms and IRC backdoor Trojans.
ccApp ccApp.exe
Y
Part of Norton AntiVirus 2003. Auto-protect and E-mail check will not function without this ... Read More
Norton Auto-Protect ccApp.exe
X
Added by the W32.Ahker.D WORM! **Note - for the valid Norton AV entry the filename is "navapexe". This is also not the valid Norton_AV_2003 file wi ... Read More
ccApp.exe ccApp.exe
X
Added by the W32/Rbot-HJ trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Symantec ccapp.exe
X
Added by the W32/Lebreat-A backdoor worm.
Antivirus Protection CCapp1.exe
X
Added by the W32/Rbot-BMG worm and IRC backdoor.
Symantec Configuration Loader ccApp32.exe
X
Added by a variant of the GAOBOT WORM!
ServicesLog ccapp32.exe
X
Added by the W32/Rbot-AMX worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
HP Desktop ccappms.exe
X
Added by the W32/Sdbot-TG WORM/IRC backdoor trojan!
SymRun ccApps.exe
X
Added by the Troj/Kagen-A Trojan. The Trojan also creates and then opens the file kangen.doc which contains a message in Indonesian. ... Read More
ccApps ccApps.exe
X
Added by the W32/Kangaroo-B worm.
blah service CCAPPS32.EXE
X
Added by the RBOT.TV WORM!
CCDoctorLogonTesting ccdoctor.exe
Y
Checks your system to make sure it's configured properly for running Rational ClearCase, a source code management tool. ClearCase is fairly sophistica ... Read More
Microsoft Driver Setup ccdrive32.exe
X
Added by the Troj/Agent-LYL Trojan.
ccenter CCenter.exe
Y
RAV AntiVirus
Rising Process Communication Center CCenter.exe
Y
Related to Rising Antivirus.
<not used> ccEtvMgr.pif
X
Added by the W32.Roty.B@mm worm. W32.Roty.B@mm is a mass-mailing worm that also copies itself to shared folders and mapped network drives. ... Read More
CcEvtMgr ccEvtMgr.exe
Y
Part of Norton AntiVirus 2003. Event manager for scheduling weekly scans and or automatic virus updates. Used to start automatically via "ccApp" and ... Read More
nortonsantivirus ccEvtMngr.exe
X
Added by the HZDOOR-A TROJAN!
sunjavasched ccEvtMngr.exe
X
Added by the W32/Sdbot-YP ... Read More
SunJavaSched ccEvtMngr.exe
X
Added by the W32/Sdbot-YP worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
ccEvtMrg.exe ccEvtMrg.exe
X
Added by the RBOT.GZ WORM!
CcEvtSvc CcEvtSvc.exe
X
Identified by Kaspersky as a variant of the Trojan.Win32.Agent.elr malware.
ccHelp ccHelp.hta
X
"Searchq" adware
<not used> cchost.exe
X
Added by the Troj/Squatbot-B Trojan.
CodeClean CCIntro.exe
X
Added by the CodeClean security risk. CodeClean is a potentially unwanted application described as a spyware removal utility that may give exaggerated ... Read More
winprotection ccIsass.exe
X
Added by the W32.SillyFDC.BBT removable media worm.
ccleaner ccleaner.exe
U
Related to CCleaner Tool to removes unused files from your system. TIFs, MRUs, cookies. etc... ... Read More
ColdFusion Monitoring Service ccmgr.exe
Y
According to this page about ColdFusion, the ColdFusion Monitoring Service "monitors the performance and availability of the ColdFusion Server, the HT ... Read More
CorrectConnect CConnect.exe
N
Broadband ISP diagnostic tool - as used by NTL and Cox Communications. Shortcut available ... Read More
CaCCProvSP ccprovsp.exe
Y
Related to Computer Associate's eTrust Internet Security Suite.
ccProxy CCPROXY.EXE
U
Part of Norton Internet Security, proxy server that is used to support the parental controls. If you turn parental controls off at user level the proc ... Read More
ccPrxy.exe ccPrxy.exe
X
Added by the Troj/ShipUp-A Trojan.
Symantec Password Validation Service ccPwdSvc.exe
Y
Used by Symantec products 2003/2004 possibly to allow certain users Internet access. ... Read More
CcPxySvc CCPXYSVC.exe
Y
Part of Norton's AntiVirus 2003, Internet Security and Firewall products. E-mail proxy service - required for E-mail scanning and the firewall ... Read More
real statics agent ccreal.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
CcRegVfy ccRegVfy.exe
Y
Part of Norton AntiVirus 2003. "ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information ... Read More
ccSetMgr ccSetMgr.exe
Y
Part of Norton AntiVirus 2004. What does it do?
Configuration Loader ccSort.exe
X
Added by the AGOBOT.SR WORM!
Sygate Personals Firewalls ccsrn.exe
X
Added by a variant of the RBOT WORM!
WINTASKMGR ccsrs.exe
X
a Mytob WORM variant adds this file.
winprotection ccsrss.exe
X
Added by the W32.SillyFDC.BBT removable media worm.
ccsserv CCSSERV.EXE
X
Added by the WORM_STRAT.GT worm.
Norton Start ccStart.exe
X
Added by the W32/Sdbot-OX worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Symantec Settings Manager ccSvcHst.exe
Y
Related to Symantec products.
Symantec Lic NetConnect service ccSvcHst.exe
Y
Related to Symantec products.
Symantec Event Manager ccSvcHst.exe
Y
Related to Symantec products.
ccSvcHst.exe ccSvcHst.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
ccsvit.exe ccsvit.exe
X
Added by the Troj/StartPa-HP Trojan.
cctray cctray.exe
Y
Windows taskbar tray icon for the CA Internet Security Suite. This icon allows you to manage all the products in that suite. ... Read More
nortonav CCUPD32.EXE
X
Added by an unidentified WORM or TROJAN!
ccUpdate ccUpdate.exe
X
Added by the AGOBOT.YS WORM!
Norton Update ccUpdate.exe
X
Added by a variant of the AGOBOT/GAOBOT WORM!
ccUpdMgr ccUpdMgr.exe
U
Added by the Spyware.Parentis surveillance software. If you did not install this yourself, then you should uninstall this product. ... Read More
{80ced3d6-ece9-48ba-8df8-2503d8d87c2b} ccyszwl.dll
X
Zlob Trojan that installs VirusProtectPro 3.7 and shows fake security alerts from your Windows taskbar. ... Read More
MP3 CD Extractor CD-Extractor.exe
N
Starts a program called CD Extractor which is used for creating MP3 files.
cd1 cd1.exe
X
Premium rate adult content dialler
Computer Defender 2009 cd2009.exe
X
Added by the Computer Defender 2009 rogue anti-spyware program.
C-DillaCdaC11BA CDAC11BA.EXE
Y
Copy protection software used by companies to stop people from pirating their software. Disabling this service could cause any programs to rely on it ... Read More
Microsoft software cdaccess.exe
X
Added by the RBOT.ABK WORM!
Auto CD-ROM Startup cdaccess.exe
X
Added by the W32/Rbot-AAU WORM/IRC backdoor trojan!
C-DillaService CDANSRV.EXE
X
Identified by Kaspersky Antivirus as a variant of the Trojan-Downloader.Win32.Agent.qzk malware. ... Read More
CDANTSRV CDANTSRV.exe
N
C-Dilla License Management software. Used for any program that uses C-dilla Protection, example: 3D Studio Max 4.x. It loads as a service automaticall ... Read More
CdbgEvtSvc CdbgEvtSvc.exe
X
Identified as as variant of the Trojan-Downloader.Win32.Exchanger.ms malware.
CDCD CDCD.dll
X
Identified by Kaspersky as a variant of the Trojan.Win32.Agent.evy Trojan.
Cdsys cdcd.sys
X
Added by the Troj/Agent-IA Trojan.
CDChk CDChk.dll
X
Identified by Kaspersky as a variant of the Trojan.Win32.Agent.evy Trojan.
Cdcompat Cdcompat.exe
X
Added by the GEMA TROJAN!
cddrv32 cddrv32.exe
X
Added by a variant of the CRYPTER.C TROJAN!
Hotkey CD Eject cdeject.exe
N
Added by the HotKey CD-Eject program. HotKey CD-Eject is a compact tool that lets you eject CDs with a hotkey combination or a double-click on the pro ... Read More
Cool Desk cdesk.exe
U
Cool Desk is a virtual desktops manager. "Ever you wished to have several screens on your computer? Cool Desk creates up to 9 virtual desktops and off ... Read More
Windows Update Service cdfs.exe
X
Added by the W32/Tilebot-HG worm and IRC backdoor. This infection utilizes the rdriv.sys rootkit. ... Read More
CDInterceptor cdi.exe
N
CD indexer for measuring the speed of CD players
cdloader cdloader2.exe
Y
Added by the magicJack free phone service. This software connects to the magicJack servers so that you can make free phone calls using its service. ... Read More
MS-Connect cdm.exe
X
Adult content dialler - see here
CDMon CDMon.dll
X
Identified by Kaspersky as a variant of the Trojan.Win32.Agent.evy Trojan.
SmCtrlDrv cdnprh.dll
X
Added by the Troj/Tiny-DA Trojan. Do not delete C:\Windows\System32\rundll32.exe as it is a legitimate file. ... Read More
cdntran cdnprot.sys
X
Added by the Chinese program Yahoo! Assistant. This program is a controversial program released by Yahoo! China and should be removed. ... Read More
cdntran cdntran.sys
X
Added by the Chinese program Yahoo! Assistant. This program is a controversial program released by Yahoo! China and should be removed. ... Read More
CdnCtr cdnup.exe
X
Added by the Chinese program Yahoo! Assistant. This program is a controversial program released by Yahoo! China and should be removed. ... Read More
{4E854318-1FFB-B264-1032-711E005C6AAA} cdp.exe
X
Identified as a variant of the Backdoor.Win32.Agent.fzy malware.
SystemTra CDPlay.EXE
X
Added by a variant of the LOVGATE WORM!
XCP CD Proxy CDProxyServ.exe
U
Added by the Sony/XCP DRM security software. This service is part of the digital rights management system utilized on certain Sony CDs. If you remove ... Read More
CryptDrive cdr.exe
X
Added by the CryptDrive misleading security application. CryptDrive is a misleading application that may give exaggerated reports about potential risk ... Read More
cdrom controller cdromcntrl.exe
X
Added by the TROJ/BATTRY-A TROJAN! ... Read More
Autorun CDROM Monitor cdrom_mon.exe
?
Unknown cdrom driver?
MicrosoftROMDriverService cdrss.exe
X
Added by the W32.IRCBot worm and IRC backdoor.
cds cds.exe
X
Added by the Backdoor.Spymon backdoor Trojan.
cdscsix3 cdscsix3.dll
X
Added by a variant of the Troj/Haxdoor Trojan. This infection utilizes the cdscsix3r.sys rootkit. ... Read More
CDRW overrun protection cdscsix3r.sys
X
Added by a variant of the Troj/Haxdor-Gen rootkit.
CDSpeed.exe CDSpeed.exe
X
Identified as the Backdoor.Win32.IRCBot.aex malware.
cd storage master cdstorager.exe
N
CD_Storage_Master - a program designed to catalog CD information, boasts a number of handy features for organizing your collection. ... Read More
CDTray CDTray.exe
N
On HP PCs, this is the small CD icon next to the time
Update CDUpdater.exe
X
"Carpe Diem" adult premium rate dialler related
{3afa7405-68e8-4bdb-920e-0d506f552826} cdwvhbf.dll
X
Zlob Trojan that infects your computer with SpyCrush and displays fake security alerts in your Windows taskbar. ... Read More
cadenza CdzSvc.exe
U
Cadenza mNotes for Palm and Pocket PC enables users to access Lotus Notes on their mobile devices ... Read More
CashToolbar CD_Load.exe
X
CashToolbar Downloader-MY adware
CyDoor CD_Load.exe
X
Adware. Check here for information about Cy-Door and here for a program that can remove it ... Read More
CydoorUpdate CD_Load.exe
X
Adware. Check here for information about Cy-Door and here for a program that can remove it ... Read More
ceedabde ceedabde.dll
X
Added by the Troj/Dropper-TV Trojan.
CeEKEY CeEKey.exe
U
It is for Toshiba laptops and enables the use of some of the special Fn keyboard keys, such as speaker on/off, hybernate, powermanagement, etc. If not ... Read More
{a1c16871-b797-4ec7-bbee-83852379c390} cefrjsh.dll
X
Zlob Trojan that installs VirusProtectPro 3.4 and shows fake security alerts from your Windows taskbar. ... Read More
CEF-Seg CefSeg.exe
X
Added by the Troj/Banker-ELG information-stealing Trojan for online banks.
Ceic Ceic.exe
?
??
CE-Infosys Security System ceisvc.exe
Y
Added by the PC Security security software.
[not used] Celine.scr
X
Added by the Troj/Celine-A backdoor trojan.
CEventMgr Cell.exe
X
Added by the Troj/Bifrose-AK backdoor Trojan.
control center Center.exe
U
Related to Asus WLAN Card ... Read More
CeEPOWER cepmtray.exe
U
Toshiba's Power Management Utility - allows the user to setup different profiles for both AC power and Battery Power on laptops. Contols CPU speed, Mo ... Read More
Advanced Internet Protocol cerf.exe
X
Added by a variant of the SPYBOT WORM!
<not used> cert2app.dll
X
Added by the Troj/Agent-GSW Trojan.
OleExport CertMgr.dll
X
Identified by Kaspersky Antivirus as the Trojan.Win32.BHO.gb malware.
certreg certreg.exe
U
Related to Gemplus Card Reader.
CertStoreInit CertStoreInit.exe
Y
Part of eToken's password management and authentication software.
iss_certtool certtool.exe
Y
Related to IBM_Client_Security Certification Tool.
SetecCertUtil Certutil.exe
U
Setec Web and Email Security. Setec PKI smart card software. The PKI technology enables secure and reliable user identification in services offered th ... Read More
cetix cetix.exe
X
Added by the W32/Autorun-MZ removable media worm.
cryptoexpert cexpert.exe
U
Added by the CryptoExpert 2005 Lite file encryption software.
BJCFD CFD.exe
N
BroadJump Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove prog ... Read More
CFD CFD.exe
N
BroadJump Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove prog ... Read More
ColdFusion Executive cfexec.exe
Y
Polls the ColdFusion Application Server service and, if it is not running, restarts it. ... Read More
Corel Colleagues &Contacts Reminders cffrem.exe
N
Corel Colleagues & Contracts - all-in-one organizer for scheduling meetings, maintaining addresses, etc. Part of Corel Print Office ... Read More
Corel Family &Friends reminders CFFREM.EXE
N
Corel Family & Friends - all-in-one calender, address book and list manager. Part of Corel Print House Magic ... Read More
cfg cfg.exe
X
Added by the W32/Bdoor-ZAR backdoor worm.
configuration manager cfg32.exe
X
A BookedSpace variant. Found in running processes as: C:\WINDOWS\cfg32.exe and C:\WINDOWS\cfg32a.exe ... Read More
cfgboost cfgboot.exe
X
Added by an unidentified WORM or TROJAN!
Microsoft Runtime CfgDll32.exe
X
Added by the RANDEX.BD WORM!
cfgintpr cfgintpr.exe
Y
Configuration Interpreter - part of Tiny Personal Firewall V4
cfgmgr51 cfgmgr51.dll
X
A bookedspace malware variant. It is started with this command: RunDLL32.EXE C:\WINNT\cfgmgr51.dll,DllRun ... Read More
Printer Update CFGREG.EXE
?
Maybe a registration reminder or automatically updates drivers or application software for a printer? ... Read More
ConfigSafe CFGSAFE.EXE
U
ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system vers ... Read More
load= cfgsys32.exe
?
??
cfgwiz cfgwiz.exe
N
Introduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it ... Read More
IS CfgWiz cfgwiz.exe
N
Norton Internet Security configuration wizard
NAV CfgWiz cfgwiz.exe
N
Introduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it ... Read More
NAV Configuration Wizard cfgwiz.exe
N
Introduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it ... Read More
Norton SystemWorks cfgwiz.exe
N
Norton System Works configuration wizard. Reportedly a resource hog. Many users find they can live without loading it ... Read More
Configuration Wizard Cfgwiz32.exe
X
Added by a variant of the HACKTACK TROJAN! Not to be confused with the legitimate MS "ISDN Configuration Wizard" (Cfgwiz32.exe) ... Read More
cfkbyse cfhskjn.exe
X
Added by the W32/Autorun.worm.e removable media worm.
TMA distribution cfinst.exe
U
Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients ... Read More
Micrcsoft Certificate Services cflmon.exe
X
Added by the W32/Rbot-FWV worm and IRC backdoor. W32/Rbot-FWV spreads to other network computers by exploiting common buffer overflow vulnerabilities, ... Read More
{ff170564-36c8-43f7-9100-559e166405cf} cfltygd.dll
X
A Trojan used by the rogue anti-spyware program VirusBursters. This Trojan, when installed, will display fake security alerts on your taskbar and inst ... Read More
Sound Sservice Driver cfmon.exe
X
Added by a CodBot variant.
CTMON.EXE cfmon.exe
X
Added by the Troj/Clckr-AN Trojan.
Microsoft Vista Upgrade Validation Service cfmon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
cFosDNT cFosDNT.exe
?
cFos DSL Modem driver related. What does it do and is it required?
cFosInst_Check cfosinst.exe
?
cFos DSL Modem driver related. What does it do and is it required?
cfosspeed cFosSpeed.exe
U
cFos_Software ... Read More
COMODO Firewall Pro cfp.exe
Y
The main control program for the free firewall, Comodo Firewall Pro.
warning: do not remove it! (system) cfpsys.exe
Y
Folder_Password_Protect A program that lets you set a password on folders of your choice ... Read More
{1152a0e8-5be5-41cc-8312-556581690a61} cfqbw.dll
X
Zlob Trojan that installs VirusProtectPro 3.5 and shows fake security alerts from your Windows taskbar. ... Read More
ColdFusion RDS cfrdsservice.exe
Y
rovides security, directory and file browsing, and debugging services for ColdFusion Studio. ... Read More
Windows Cfreer.exe
X
Added by the W32/Culler-C worm that spreads via MSN Messenger.
Cold Fusion Application Server cfserver.exe
Y
The main ColdFusion program.
CFSServ.exe CFSServ.exe
N
CFSServ.exe is a Toshiba Laptop utility that allows you to easily change computer settings in a quick manner. ... Read More
ConfigFree Service CFSvcs.exe
U
Toshiba's wireless card configuration utility.
mscfs cfsys.dll
X
Added by the Trojan.Ourxin adware Trojan. This infection will display popups on the compromised computer. ... Read More
cftm cftm.exe
X
Added by the W32.Harakit worm.
ctfmon cftmon.exe
X
Added by the Troj/Delbot-B TROJAN/IRC backdoor!
autoload cftmon.exe
X
Identified as a variant of the Trojan.Spy.XUL Trojan.
Winsock2 driver CFTMON.EXE
X
A variant of the W32.Spybot.Worm family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
Windows xmutler cftmon32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
cftmonn cftmonn.exe
X
Added by the W32/AutoRun-DJ removable media worm.
Windows Firewall Updater cftpn0ne.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
SFtrb Service cftrb32.exe
X
Added by the SOBIG.D WORM!
SysTray cfustums.dll
X
Added by the Troj/Small-XG dropper Trojan.
cfy cfy.exe
X
Surfenhance.com SearchForIt adware variant ... Read More
CGI Firewall Script CGIAGENT.EXE
X
Added by the W32/Bropia-U P2P worm. This infection also creates the file C:\Windows\System32\fatpammy.exe. ... Read More
Norton Crashguard Monitor cgmenu.exe
N
Troublesome program that doesn't actually work with WinME so Norton removed it from SystemWorks 2001 ... Read More
CGServer cgserver.exe
U
Associated with an Eicon Networks ISDN or ADSL modem. Call Guard Server (CGserver) watches your modem and blocks incoming or outgoing calls. You need ... Read More
Cgtask Services cgtask.exe
X
Added by the LALA.B TROJAN!
microsoft windows files loader cgy32win.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Cgywin cgywin32.exe
X
Added by the W32/Rbot-AEI worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
ChamClock ChamClock.exe
U
Chameleon Clock - system tray clock replacement
PSD Tools Channel ChannelUp.exe
X
BuddyLinks adware
COMSurrogate char.exe
X
Added by the Troj/Erazer-A Trojan.
[value] charmapnt.exe
X
Added by the Troj/Bancos-DR password-stealing Trojan.
System startup charmapx.exe
U
Only required if using an oriental language
Mapa de caracteres para NT charmmpxp.exe
X
Added by the Troj/Bancos-KG Internet banking Trojan.
Bingo Charm charms.exe
?
Some kind of screen icon kind of like desk flag, but it gives you a choice of icons? ... Read More
Chatango Chatango.exe
N
Chatango - "allows people to be connected in real time through their Web browsers. Include your Chatango contact link or button when you create eBay a ... Read More
spup.exe chater.exe
X
Unknown malware.
Ares Chatroom server chatServer.exe
U
Related to the Ares Galaxies P2P file sharing software.
Chcenter chcenter.exe
N
IMSI HiJaak - "the easiest way to convert, capture, and manage all your graphic files" ... Read More
Shcenter chcenter.exe
N
IMSI HiJaak - "the easiest way to convert, capture, and manage all your graphic files" ... Read More
chckntfs chckntfs.exe
X
Added by the W32/Tilebot-EF worm and IRC backdoor.
chcp.exe chcp.exe
X
A variant of the Backdoor.Win32.SdBot.bmh family of worms and IRC backdoor Trojans. ... Read More
High Definition Audio Property Page Shortcut CHDAudPropShortcut.exe
Y
Realtek audio card related - probably adds the odd feature to one of the "Sounds" Control Panel applet tabs - doesn't appear to be required ... Read More
che32 che.ocx.vbs
X
Added by the WM97/Adenu-B prepend virus.
CIO che7e1~1.exe
N
Added by the ChatItOut webcam chat program.
GigaByte Cheatle.exe
X
Added by the SHODI.B VIRUS!
erecoveryservice check.exe
U
Acer Notebook related - Acer eRecovery allows the user to restore the operating system or backup the current system profile, thus ensuring system int ... Read More
Check Check.exe
X
Added by the W32/VB-DRN virus and worm.
WinCheck check.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
mspaint.exe check32.exe
X
Added by the AGENT.AH TROJAN!
CheckAvp CheckAvp.dll
X
Identified by Kaspersky as a variant of the Trojan.Win32.Agent.evy Trojan.
checkcustomworksupdate CheckCWupdate.exe
N
Update checker, part of CustomWorks - "customize any embroidery designs to design your own unique creations" ... Read More
WashAndGo - Cleanup of old Backupfiles checker.exe
U
WashAndGo - temp file cleaner
checkers checkers5.exe
X
Added by the W32.Formshared.A worm. W32.Formshared.A is a worm that attempts to spread a copy of Infostealer through peer-to-peer applications. ... Read More
CheckIt 86 CheckIt86.exe
U
Used to launch the CheckIt86 Popup blocker.
Registry Startup Check checkreg.exe
X
Added by the Troj/RemLoad-A Trojan.
CheckSys CheckSys.dll
X
Identified by Kaspersky as a variant of the Trojan.Win32.Agent.evy Trojan.
CheckWin CheckWin.dll
X
Identified by Kaspersky as a variant of the Trojan.Win32.Agent.evy Trojan.
WDNDrive chgsprt.sys
X
Added by the Troj/Haxspy-A backdoor.
Windows firewall manager chh.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
chiCkie chiCkie.exe
X
Added by the W32.Chiko removable drive worm.
ChikkaDefault ChikkaLauncher.exe
N
Added by the Chikka Messenger program. Chikka Messenger allows you to send text messages and MMS images to mobile phones from your computer. ... Read More
OutPost FireWall child.dll
X
Added by the Troj/Small-ER backdoor Trojan.
(3F143C3A-1457-6CCA-03A7-7AA23B61E40F) child.dll
X
Added by the Troj/Small-EX backdoor Trojan.
ChilyClient ChilyClient.exe
U
Added by the Spyware.ChilyEMon surveillance software. This software should be removed if found on your computer without your knowledge. ... Read More
eixfi china.bat
X
Added by the WCUP.A WORM!
china11msn CHINA11MSN.EXE
X
Added by the W32.ENVID.O WORM! ... Read More
CHKADMIN CHKADMIN.EXE
N
Compaq Network Management System. When running, it places an icon in the system tray titled "Intelligent Manageability" ... Read More
ChkBoot ChkBoot.dll
X
Identified by Kaspersky as a variant of the Trojan.Win32.Agent.evy Trojan.
CheckDialer ChkDial.exe
U
Added by the CheckDialer modem connection monitoring tool.
AdobeReaderPro chkdisk.exe
X
Added by the W32/Rbot-BDV worm and IRC backdoor.
Disk check chkdisk32.exe
X
Added by the Troj/DownLdr-IM Trojan.
Disk Checker Service chkdsk.exe
X
Added by the W32/Tilebot-IS worm and IRC backdoor.
Windows System Controller chkdsk.exe
X
Added by the W32/Tilebot-IR worm and IRC backdoor.
Users service for disk management requests CHKDSK32.EXE
X
Added by the Troj/Telemot-A backdoor Trojan.
Disk Check chkdsk32_.exe
X
A variant of the Trojan-Downloader.Win32.VB.bai malware.
Disk management service for users requests CHKDSK64.exe
X
Added by the Troj/Telemot-B backdoor Trojan.
CHK Disker chkdsker.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
NT Printing Services chkdsks.exe
X
Added by the Troj/Buzus-M Trojan.
chk chke.dll
X
Added by the Troj/Geoload-A/a> downloader Trojan.
chkext(chkext) chkext.exe
X
Added by the W32/Sdbot-CRW worm and IRC backdoor.

W32/Sdbot-CRW spreads to other network computers by exploiting vulnerabilities, inclu ... Read More
Microsoft DLL Verifier chkfile.exe
X
Added by the W32/Rbot-AOC worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute. ... Read More
Pe2ckfnt SE chkfont.exe
N
Used to check whether the fonts are installed properly on your computer or not for a scanner. If you don't want to execute it, you can uncheck it in t ... Read More
chkhbci chkhbci.exe
N
Smart Card reader software for Omnikey readers ... Read More
CHK NT chkntf.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
NTFS Volume Maintenance chkntfs.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
RegistryCheck chkreg.dll
X
Added by the Dialer.Ulubione premium adult dialer.
LoadPowerScheme chkreg.dll
X
Added by the Dialer.Ulubione premium adult dialer.
ChkVolume ChkVolume.dll
X
Identified by Kaspersky as a variant of the Trojan.Win32.Agent.evy Trojan.
system performance logging for TrueTime Driver Edition chkzero.ex
X
Added by the Troj/Hackda-A Trojan & Rootkit.
ChangeLines chngline.exe
?
??
Choke Choke.exe-blahh
X
Added by the CHOKE WORM!
chostsv chostsv.exe
X
Added by the BANPAES.C TROJAN!
(429F4BB8-7BF7-4152-8011-3C6F9EB7E892) chp.dll
X
Added by the Troj/Spabot-E spam mailing Trojan.
Zacker Christmas.exe
X
Added by the W32/Maldal-C mass-mailing worm. This infection displays a picture of Santa with the words "From the heart, Happy new year!". ... Read More
Yahoo Messengger chrome.exe
X
Added by the W32/Autorun-NG removable media worm.
Chronograph chrono.exe
U
Added by the Chronograph time syncronization utility.
ChronitelInitTV CHTVINIT.EXE
?
??
{1ED51D31-70E9-FE03-0103-060602070407} chups.exe
X
Added by the Troj/DwnLdr-GXN downloader Trojan.
EpromSystem chvhost.exe
X
Added by the Troj/Bckdr-QKD backdoor Trojan.
dimanganous chzbi.dll
X
Zlob Trojan which installs the Virus Protect 3.8 rogue anti-spyware program. This program displays fake security alerts stating that your computer ha ... Read More
ci1gnt ci1gnt.exe
X
Identified by Kaspersky Antivirus as Trojan.Win32.Agent.dhu.
ciakaisen.exe ciakaisen.exe
X
Added by the Dialer.BaciamiStupido premium dialer. Dialer.BaciamiStupido is a dialer program that accesses a Web site by dialing a high-cost number us ... Read More
CICache CICache.exe
?
Unknown file. Possibly malware?
WindowsFileSystem cidaemon32.exe
X
Added by the W32/Rbot-FSP worm and IRC backdoor.
CIFPLogAggregator CIFPLogAggregator.exe
Y
Related to the Cyclope Internet Filtering Proxy Internet site and content filtering software. ... Read More
cihost.exe cihost.exe
X
Added by the LINST TROJAN!
Microsoft Data Helper cihost.exe
X
Malware, possibly a variant of the LINST TROJAN
Memory Allocation Host cihost.exe
X
Identified by Avast as a variant of the Win32:IRCBot-CHZ worm and IRC backdoor.
CIJxP2PSERVER CIJxP2PS.EXE
N
Compaq printer utility which is required in order to make the printer work correctly - "x" depends upon the model, ie, for IJ300 x=3, for IJ700 x=7 ... Read More
NTdhcp CiKewl.exe
X
Added by the Troj/QQRob-N backdoor Trojan.
[not used] cinderawasih-4321427.exe
X
Added by the W32/Brontok-R mass-mailing worm.
Software\Microsoft\Windows\CurrentVersion\Runprocess cipsn.exe
X
Added by the W32/Forbot-DM worm. This infection spreads using the LSASS vulnerability. ... Read More
<not used> ciscoutility.exe
X
Added by the Troj/Small-DIV Trojan.
autovirusprotection ciscv.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
Memory Allocation Server ciserv.exe
X
Unknown worm.
Memory Allocation Services cisrv.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
CISrvr Program CISRVR.EXE
N
Related to internet setup on Compaq PC's
HP Smart Array SAS/SATA Event Notification Service cissesrv.exe
Y
The HP Smart Array SAS/SATA Event Notification Service provides event notification to the Windows Server system event log and the HP ProLiant Integrat ... Read More
Cissi Cissi.exe
X
Added by the CISSI.A WORM!
FamilyKeyLogger cisvc.exe
U
"Family Keylogger - is your best choice, if you want to know what other users on your machine are typing". Note! - this is not the cisvc.exe service. ... Read More
Ci Svr cisvr.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
citiucs CitiUCS.exe
U
Citibank Virtual_Account_Numbers ... Read More
CitiVAN CitiVAN.exe
N
Option from Citibank to change a credit card number in a random fashion for each purchase. The number will only be used once and never again ... Read More
Windows Loader Service civsc.exe
X
Added by a variant of the RBOT WORM!
cjamkm cjamkm.sys
X
Added by a variant of the Troj/NTRootK-CM rootkit.
cjb cjb.exe
X
Identified as a variant of the Trojan-Clicker.Win32.Small.BG Trojan.
CJET CJet.exe
X
Added by the Adware.FFToolBar adware toolbar.
Cjstcom Cjstcom.exe
Y
Canon printer BJ status language monitor
Canon Printer Monitor BJCxxx Cjstlst.exe
N
Trayicon for Canon printer. xxx denotes model. Available via Start -> Programs
BJ Status Monitor 5xx CJSTRxx.EXE
N
Canon printer status monitor - where "xx" is different depending upon the version. Not required as you can check the printer status via My Computer -> ... Read More
BJ Printer Status Monitor Cjstsr.exe
N
Canon BJ printer status monitor
disgorging cjuvwa.dll
X
Zlob Trojan which installs the VirusProtect 3.9 rogue anti-spyware program. This program displays fake security alerts stating that your computer has ... Read More
cjwriiigqazft cjwriiigqazft.cat
X
Added by the Backdoor.Rustock backdoor rootkit.
SymKeepAlive CKA.exe
U
Part of Norton SystemWorks 2003 - keeps a dial-up modem connection alive
{5bf53d50-b1ec-47b6-a00a-0bd32baeb7ef} ckimzeb.dll
X
Zlob Trojan that infects your computer with SpyCrush and displays fake security alerts in your Windows taskbar. ... Read More
startkey CKOTS.exe
X
Added by the Troj/Bifrose-HM backdoor Trojan.
kamsoft ckvo.exe
X
Added by the Troj/Gamania-BW Trojan.
[Various Names] clamav.exe
X
Part of the Wareout infection as described here.
ClamWin ClamTray.exe
Y
ClamWin antivirus
ecko claro.exe
X
Added by the Troj/Dloadr-AQJ Trojan.
Registry class0117[random].exe
X
Added by the Spyware.Blackbox spyware.
class454~@# class454.exe
U
Added by the Spyware.XPSpy commercial keylogging software. This software should be uninstalled if it was not installed by yourself.

Spy ... Read More
clbcatex clbcatix.dll
X
Identified as Trojan-Clicker.Win32.Agent.ct.
clbdriver clbdriver.sys
X
Identified as a variant of the Rootkit.Win32.Clbd.cx rootkit.
clboot32 CLBOOT32.EXE
U
PC-Duo_Remote_Control from Vector. "System Snapshot provides a detailed ... Read More
pc-duo system snapshot CLBOOT32.EXE
U
PC-Duo_Remote_Control from Vector. "System Snapshot provides a detailed ... Read More
inquisitionist clbrcek.dll
X
Added by a Zlob Trojan which installs AntiVirgear 3.8 and display fake security alerts in your Windows taskbar. ... Read More
CyberLink Background Capture Service (CBCS) CLCapSvc.exe
U
Used by Cyberlink PowerCinema to record TV in the background while you were watching so that you can pause, rewind, etc. ... Read More
clcbt.exe clcbt.exe
X
Added by the Troj/Agent-CBA downloader Trojan.
CLCLSet CLCL.exe
U
CLCL clipboard caching utility
SystemCleaner Clean2.exe
X
Added by the W32/Autorun-AZE removable media worm.
CleanEasyImg cleanall.exe
?
??
Cleanator Cleanator.exe
X
Added by the Cleanator rogue security software. Cleanator reports false or exaggerated system security threats on the computer. ... Read More
Cleanator Cleanator.exe
X
Added by the Cleanator rogue security tool.
pal evidence eliminator Cleaner.exe
N
Related to PAL_Evidence_Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis ... Read More
Clean Mgr cleanmg.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
winlogon cleanmg.exe
X
Added by the Troj/Agent-ICR Trojan.
cleanmgr.exe cleanmgr.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
cleanregpath CleanReg.exe
?
Apparently Annex A ADSL modem related - what does it do and is it required? ... Read More
CleanTemp CleanTemp.exe
U
CleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory ... Read More
CleanTemp CLEANT~1.EXEB
U
CleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory ... Read More
cleantemp CLEANT~1.EXEBCleanTemp.exe
U
CleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory ... Read More
CleanupProgram cleanup.exe
?
In a C:Sonysys folder - Sony Vaio related?
ldrsvc clean_19d25.dll
X
Added by the Troj/Banker-EFL password-stealing Trojan for online banking sites. When fixing this services, do not delete C:\Windows\System32\svchost. ... Read More
ldrsvc clean_4392d.dll
X
Added by the Troj/Torpig-BV Trojan.
clean_service clean_service.cmd
X
Added by the W32.Refaz WORM! ... Read More
itweaku Clear.exe
U
Related to ItweakU ... Read More
H2O cledx.exe
Y
Related to copyright protection products by Syncrosoft.
clfmon.exe clfmon.exe
X
Added by the TROJ/AGENT-BJ TROJAN!
ATICCC cli.exe
U
ATI's CATALYST™ CONTROL CENTER. Required if you want to change graphics settings on a regular basis but you must have internet access and Microsoft's ... Read More
ati catalyst CLI.exe
N
System Tray access to ATI's CATALYST™ CONTROL CENTER. Note that this has "SystemTray" appended to CLE.exe in the "Command" column of MSCONFIG. Not req ... Read More
Microsoft Server Applacations CLI.exe
X
Added by the W32/Rbot-GAQ worm and IRC backdoor.
ATI CATALYST System Tray CLI.exe SystemTray
N
System Tray access to ATI's CATALYST™ CONTROL CENTER. Note that this has "SystemTray" appended to CLI.exe in the "Command" column of MSCONFIG. Not req ... Read More
CLI32 cli32.exe
X
Identified by AVG antivirus as a variant of the Trojan horse Downloader.Zlob.NP Trojan. ... Read More
Click-N-Type Keyboard Click-N-Type.exe
N
Click-N-Type is an on-screen virtual keyboard designed for anyone with a disability that prevents him or her from typing on a physical computer keybo ... Read More
Vonage click2call.exe
U
Vonage Voice over IP Internet phone service
ClickMe ClickMe.exe
N
ClickM "JOKE" program
Clickoff Clickoff.exe
U
Clickoff automatically dismisses annoying dialog boxes
Click Radio Tuner clickr~1.exe
N
ClickRadio - subscription service playing radio music via the internet
Click Tray Calendar ClickT~1.EXE
N
ClickTray Calendar - shows holidays, reminders of various anniversaries,tasks etc ... Read More
[not used] clicnt40.exe
X
Added by the Troj/PPdoor-AT backdoor Trojan.
CLICONFG CLICONFG.EXE
X
Added by the OPASERV.T WORM!
Cli Confg cliconfig.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
DigiGuide CLIENT.EXE
N
TV guide and reminder
Windows Client client.exe
X
Added by the Troj/Backdr-AM Trojan.
pagmstart client.exe
?
Possibly related to this?
piaoyes client.exe
X
Added by the Backdoor.Djump backdoor.
Client Default Client.exe
U
Samurize is a system monitoring and desktop enhancement engine for Microsoft Windows 2000/XP/2003. ... Read More
DigiGuide client01.exe
N
TV guide and reminder
Client32 client32.exe
X
Part of the NetSupport line of remote control products.
WIN32i clienttimer.exe
X
Added by the Adware.Eziin homepage hijacker.
WIN32DS clienttimer.exe
X
Added by the Adware.Eziin homepage hijacker.
win32io clienttimer.exe
X
Added by Eziin adware ... Read More
Remote ClipBook Viewer clipbk.exe
X
Added by the W32/Mofei-Q network worm.

W32/Mofei-Q provides backdoor access and control over the computer by creating
a port (ba ... Read More
ClipMate6 ClipMate.exe
U
Clipmate is a program that runs in your task bar and captures/saves any data you copy to the clipboard. You can then retrieve this data at a later da ... Read More
ClipMate7 ClipMate.exe
N
Added by the Clipmate 7 clipboard extender.
Clip Service Manager clipmg.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
ClipMate5x ClipMt5x.exe
N
Clip Mate 5.x by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs ... Read More
Clipmate6 CLIPMT60.EXE
N
Clip Mate 6 by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs ... Read More
ClipMate6 ClipMt63.exe
N
Clipmate allows you to store clips of text that you can then assign to hotkeys that will paste that information back to a document. ... Read More
Clipomatic Clipomatic.exe
N
Mike Lin's Clipomatic is a clipboard cache program - it remembers what was copied to the clipboard even after new data is copied, and allows you to re ... Read More
ClipSrv clipserv.exe
X
Added by the W32/Sdbot-AAV worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
ClipSrv clipservr.exe
X
Added by the W32/Sdbot-AFE worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Clipbook Service Clipsrv.exe
N
Supports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooks ... Read More
Clipsrv Clipsrv.exe
N
Supports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooks ... Read More
Clip Servicer clipsrvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Clip Srv clipsv.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
LocalSystem clipsvr16.exe
X
Added by Backdoor.Femo
LocalSystem clipsvr32.exe
X
Added by Backdoor.Femo
ClipTrak ClipTrak.exe
N
ClipTrak - clipboard extender
ClipTrakker ClipTrakker.exe
N
Cliptrakker - clipboard extender
WinApp clipuser32.dll
X
Identified as a variant of the TR/Spy.Agent malware.
CLI Services clisrv.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
ATICCC CLIStart.exe
U
ATI's CATALYST™ CONTROL CENTER. Required if you want to change graphics settings on a regular basis but you must have internet access and Microsoft's ... Read More
StartCCC CLIStart.exe
U
ATI's CATALYST™ CONTROL CENTER. Required if you want to change graphics settings on a regular basis but you must have internet access and Microsoft's ... Read More
SMS Client Service clisvc95.exe
U
When the SMS Client service starts on a domain controller, the Client service modifies the SMSCliToknAcct & user account group membership, user rights ... Read More
Management Consultants clmcs.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
CyberLink Media Library Service CLMLServer.exe
U
Part of the Cyberlink products and is used to manage your audio and video library. ... Read More
CLMFrontPanel clmpanel.exe
U
System tray status/display/configuration utility for a number of modems. Can be disabled by right-clicking on the tray icon. If disabled, connection s ... Read More
clmss clmss.exe
X
Added by the W32/Tilebot-AO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Content List Management Subsystem clmss.exe
X
Added by the W32/Spybot-EL worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Acer HomeMedia Connect Service CLMSServer.exe
U
Related to Acer computers.
[Various Names] cloaker.exe
Y
Used by HP and Compaq computers to hide the windows of programs passed as arguments to it. ... Read More
accessoriesplus clockplus.exe
U
"Clock Plus", part of Accessories_Plus allows you to select from dozens of alternatives for the Windows clock. ... Read More
ClockWise CLOCKWISE.EXE
U
ClockWise - produced by R J Software - a time utility. It is a schedueler not only for dates, but you can choose it to run programs at any time. It al ... Read More
wise clockwise.exe
X
Added by the Troj/Lazar-A backdoor Trojan.
ClocX ClocX.exe
U
ClocX is analog clock application for Microsoft Windows 98/ME/NT/2000/XP/2003.
CloneCD CloneCDTray.exe
U
System tray for CloneCD - the only useful option is "Hide CDR Media" only available via this tray. Has additional unknown functions in later versions ... Read More
CloneCDTray CloneCDTray.exe
U
System tray for CloneCD - the only useful option is "Hide CDR Media" only available via this tray. Has additional unknown functions in later versions ... Read More
CyberLat Ram Cleaner CLRamCleaner.exe
U
CyberLat RAM Cleaner is a program that Frees, Optimizes and Defrags your system's wasted memory (RAM). Some users swear by programs such as this but I ... Read More
MSVersion clrschp038.exe
X
Added by the POPMON.A TROJAN! - also known as PopMonster adware
coolwebprogram clrssn.exe
X
CoolWebSearch parasite variant
clock Loader cls.exe
X
Added by the W32/Sdbot-AFT worm. When connected this infections connects to an IRC server where it waits for remote commands to execute. ... Read More
Windows System32 clsas32.exe
X
Added by the W32/Rbot-AZO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows System32 Driver clsass32.exe
X
Added by the W32/Sdbot-AGG worm and IRC backdoor.
CyberLink Task Scheduler (CTS) CLSched.exe
U
Used by Cyberlink PowerCinema to record scheduled shows.
cltmon cltmon.exe
X
Added by the Troj/Dloadr-CHY Trojan downloader.
CleverKeys ClvrKeys.exe
N
Added by CleverKeys.

"CleverKeys is free software that provides instant access to definitions at Dictionary.com, synonyms at Thesaurus. ... Read More
Chaos Manager loader cm2.exe
U
Chaos Manager is a Freeware Task Sheduler, Calender/Reminder Program.

The startup entry allows chaos manager to run in the system tray an ... Read More
Start RF Wireless Mouse cm20.exe
Y
Yuanxun Electronics RF wireless mouse driver
cma cma.exe
U
DeskSite CMA siftware - "retrieves new content from the DeskSite Data Center"
Desksite CMA cma.exe
U
DeskSite CMA siftware - "retrieves new content from the DeskSite Data Center"
CyberMedia Agent CMAGENT.EXE
N
Part of CyberMedia's Oil Change program. Not normally required. Note - if you have TextBridge, CyberMedia Agent may attach itself to TextBridge and ca ... Read More
MachineTest CMagesta.exe
X
Added by the W32/Sdbot-NE worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
cesmain.dll cmail.dll, Rundll32
X
CnsMin "Chinese Keywords" hijacker related
Connection Manager CManager.exe
N
SBC Yahoo DSL service connection manager. You can connect from the network connections. Users having problems with this have been advised to uninstall ... Read More
CMAPP cmappclient.exe
X
Added by the Trojan.Cmapp Trojan.
hpcmd cmd.exe
X
Added by the Troj/AdClick-DS Trojan.
Dynamic Dns Binary CMD16.EXE
X
A R-Bot WORM variant functioning as a backdoor Trojan uses this file to terminate processes, among other actions. ... Read More
Cmd cmd32.exe
X
Added by the TANKED WORM!
Configuration Loader cmd32.exe
X
Added by the LOADCFG or SDBOT TROJANS!
Ass and titties CMD32.EXE
X
Added by the Troj/SdBot-GG worm. When started, this infection connects to an IRC server where it waits for remote commands to execute. ... Read More
ControlPanel> cmd32.exe internat.dll,LoadKeyboardProfile
X
Added by the Troj/Dloader-JW downloader TROJAN.
Comodo Application Agent cmdagent.exe
Y
The main control program for the free firewall, Comodo Firewall Pro.
cmdbcs cmdbcs.exe
X
Added by the Troj/PWS-AFC information stealing Trojan.
ComodoBackupService CmdBkSvc.exe
Y
Related to Comodo BackUp.
cmdcon cmdcon.exe
X
Added by the CRYPTER.A TROJAN!
relinson cmdno.exe
X
Added by the Troj/Dropper-PS Trojan.
Windows Smrss Service cmdpipe.exe
X
Added by the W32/Tilebot-AE worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
cmdprompt32.pif CmdPrompt32.pif
X
Added by the W32.Assiral.B WORM! ... Read More
cmdriver cmdriver.sys
X
Added by the SecurityRisk.Cashmoa rootkit. SecurityRisk.Cashmoa is a security risk that hides any processes that are named cmc.exe. ... Read More
cmds cmds.exe
X
Identified as W32/Malware.SHZ or Trj/Downloader.OLG.
MyLife CmdServ.exe
X
Added by the HOLAR.A WORM!
CmdShell.exe CmdShell.exe
X
Added by the Troj/Bckdr-QHY backdoor Trojan.
MsgSvcMgr32 cmdzxdll.exe
X
Added by the W32/Rbot-AEK worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
CME cme.exe
X
Part of Gator advertising spyware - see here for removal instructions
Check Messenger cmesseng.exe
U
Check Messenger from Qchex.com - program that helps you manage the activity of your Qchex account ... Read More
CmeSYS CMEsys.exe
X
Part of Gator advertising spyware - see here for removal instructions
CmeUPD CMEupd.exe
X
Part of Gator advertising spyware - see here for removal instructions
COMODO Memory Firewall cmf.exe
Y
Comodo Memory Firewall attempts to protect you from exploits that use buffer overflows. ... Read More
cmflywavename CmFlywav.exe
N
Driver for Linksys Wireless Music Bridge.
CMGrdian CMGrdian.exe
?
One of the McAfee shared components. What does it do and is it required?
Guardian CMGrdian.exe
N
McAfee's QuickClean, an offline version of the one in their online Clinic. Normally run offline and not needed. Incidentally, incorporates more cleanu ... Read More
McAfee Guardian CMGRDIAN.EXE
N
McAfee's QuickClean, an offline version of the one in their online Clinic. Normally run offline and not needed. Incidentally, incorporates more cleanu ... Read More
Microsft Security Monitor Process cmh.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
ORiNOCO Cmluc.exe
U
Client Manager software for an ORiNOCO wireless LAN card
Test Cmm32.exe
U
Added by the Spyware.Bemonitor surveillance program. Spyware.Bemonitor is a spyware program that may log keystrokes on the compromised computer. If t ... Read More
cmman CMMan.exe
X
Added by the Trojan.Cmapp TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. ... Read More
Microsoft Connection Manager Monitor cmmon.pif
X
Added by the W32/Rbot-AKV worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Cmmon32Sys cmmon32.exe
X
Added by the SMALL.CL TROJAN!
run= cmmpu.exe
N
MIDI emulator driver for the integrated sound chip by C-Media based on the CMI-8330 chip set normally found in cheap motherboards. Also installed as p ... Read More
SysTemperatureNotRemove cmmput.exe
X
Added by the W32.Nujama.B worm. W32.Nujama.B is a worm that spreads through mapped drives and shared folders, and lowers security settings on the comp ... Read More
Windows Disk Manager cmnvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
[Various Names] cmon14.exe
X
Part of the Wareout infection as described here.
[Various Names] cmon14.exe
X
Part of the Wareout infection as described here.
cmonsvc322 cmonsvc322.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Task &#097;lert cmosvc.exe
X
A variant of the Backdoor.Win32.IRCbot.vic family of worms and IRC backdoor Trojans. ... Read More
(random 12 digit number) cmpbk321.exe
X
Adsrv.com/IeDriver adware variant ... Read More
CMPDPSRV CMPDPSRV.EXE
U
Printer Driver Plus from ViewAhead Technology (formerly DeviceGuys, Inc.). "Printer Driver Plus seamlessly integrates all the necessary components of ... Read More
cmrrs cmrrs.exe
X
Added by the Troj/Dadobra-FO Trojan.
{1157A4A6-3A8E-3D98-0301-050000030002} cmrs.exe
X
Added by the Troj/Rootkit-DH rootkit.
cmrss cmrss.exe
X
Added by the Troj/Dloader-MR TROJAN!
cmrst cmrst.exe
X
Added by the PWSteal.Bancos.S TROJAN!
cmrst cmrst.scr
X
Added by the Troj/Dloader-FP TROJAN/downloader!
Microsoft System32 Update cmsrg.exe
X
Added by the RBOT-GN WORM!
ethernet adapter cmsrrs.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Update cmss.exe
X
Added by the W32/Rbot-ATQ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows CMS Protocol cmss.exe
X
Added by the W32/Rbot-BFT worm and IRC backdoor.
ATD Direct CD cmssr.exe
X
Added by the Troj/Stinx-V IRC backdoor Trojan.
Microsofts Updatez cmsssr.exe
X
Added by an unidentified VIRUS, WORM or TROJAN!
CmSTP cmstp.exe
X
Added by the Troj/Cosmu-A Trojan.
COM+ System Client cmsvc.exe
X
Identified as the SdBot.bis worm.
cmsystem CMSystem.exe
X
CASClient adware variant ... Read More
cmt101 cmt101.exe
X
Added by a variant of the CRYPTER.C TROJAN!
CmUCReye.exe CmUCReye.exe
U
Related to devices by Medion Display.
Update Browser cmutfilt.exe
X
Unknown malware. Possible trojan downloader and backdoor.
Remote Themes cmutfilt.exe
X
Unknown malware. Possible trojan downloader and backdoor.
cmutil cmutil.exe
X
Added by the Troj/Agent-DFN downloading Trojan.
cmx32 cmx32.exe
X
Added by the GEMA.D TROJAN!
Windows System File cmxp.exe
X
Added by the SPYBOT.KHO WORM!
CNBABE CNBABE.EXE
X
Appears to be spyware added by KAZAA (and maybe others) that displays pop-up ads whilst you're browsing ... Read More
nClient cnen.exe
X
Added by the W32.Rinbot.BF worm. W32.Rinbot.BF is a worm that spreads by exploiting vulnerabilities and opens a back door on the compromised computer. ... Read More
UpdateComponent CNF UPD.EXE
X
Added by the SPYBOT.GEN VIRUS!
shambl3r cnf.bat
X
Added by the REMABL WORM!
Configuration Manager CNFGLD32.EXE
X
Added by the SDBOT TROJAN!
Configuration Loader cnfgld32.exe
X
A variant of the W32/SDBot.AWGY family of worms and IRC backdoor Trojans.
Configuration win32 cnfgld32.exe
X
A variant of the W32/SDBot.AWGW family of worms and IRC backdoor Trojans.
Configuration Manager Cnfgldr.exe
X
Added by the SDBOT TROJAN!
Cnfrm32 cnfrm.exe
X
Added by the MIMAIL.D WORM!
Dluxjp cnfrm.exe
X
Added by the DLUCA.D TROJAN!
Cn323 cnfrm33.exe
X
Added by the MIMAIL.G WORM!
[Various Names] cnftips.exe
X
Part of the Wareout infection as described here.
Mspatch89 cnqmax.exe
X
Added by the RANDEX.P WORM!
{9A0CFC58-5A6F-41ba-9FFE-4320F4F621BA} Cnscheck001.dll
X
Added by the Troj/LegMir-AHT password-stealing and keylogger for the online game Legend of Mir. ... Read More
Microsoft Intrenet Explorer cnsg.pif
X
Added by the W32/Rbot-ARO worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
b5700x drive cnssr.exe
X
Added by the Troj/Maha-T Trojan.
System Failure Statistic cnstat.exe
X
Added by the RBOT-LF WORM!
CnwiDeviceAgent cnwida.exe
Y
Part of the Canon imagePROGRAF W8400 printer software.
GARO Status Monitor cnwism.exe
U
Print monitor for certain Epson printers.
CnxAdslL CnxAdslL.exe
Y
DLink, Zoom, or Conexant modem driver
CnxDslTaskBar CnxDslTb.exe
N
Connexant DSL Taskbar as used on Acess Runner and Samsung AHT-E310 ADSL modems
WooCnxMon CnxMon.exe
N
Wanadoo ISP software related - not required - here's how to bypass it
ledpointer CNYHKey.exe
U
Chicony Electronics Multimedia Keyboard Hotkey Driver
Windows Service Agent co0l.exe
X
Added by the W32/Rbot-GQY worm and IRC backdoor.
UpromiseRemindU Code
U
Part of the Upromise college savings program.
Diskstart Code.exe
X
Adult content dialler
<not used> codeblocks.exe
X
Identified as a variant of the Trojan.Spambot.2424 malware.
codecdirectx.exe codecdirectx.exe
X
Added by the Troj/Banloa-AZY online banking Trojan. If you are infected with this it is advised that you immediately change your online banking passwo ... Read More
Microsoft Corporation codecdivxx.exe
X
Added by the TSPY_BANKER.CZK online banking Trojan.
Myvirus codeme.exe
X
Added by the W32/Patco-A worm.
Hpscanner codeme.exe
X
Added by the W32/Patco-A worm.
System Service coderxt.exe
X
Added by the W32/Rbot-ALD worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Divx codll.exe
X
Added by the Troj/Gravebot-A IRC backdoor. This infection also creates the file C:\Windows\System32\sum.tgz. ... Read More
compd service drivrs codq.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
cogad cogad.exe
X
Added by the Troj/Dloadr-CEP downloading Trojan.
DBGA0EEG Cokmgl32.dll
X
Added by the W32/Doxpar-F worm.
Userinit cologsver.exe
X
Identified by Kaspersky antivirus as the Virus.Win32.Agent.ad virus.
siscolor color.exe
U
Probably on-board graphics related based upon the SiS chipsets. Has been seen on ASUS motherboards with SiS chipsets and known to cause conflicts if y ... Read More
coloreal coloreal.exe
U
Makes colours sharper and brighter, but will only work with coloreal capable monitors ... Read More
WCOLOREAL coloreal.exe
U
Makes colours sharper and brighter, but will only work with coloreal capable monitors ... Read More
ColtsScreenServer ColtsScreenServer.exe
N
Software from the MercurySports for streaming information about the Indianapolis Colts US Football team. Slightly loose Terms or Use and Privacy poli ... Read More
ColtsScreenServerSvc ColtsScreenServer.exe
N
Software from the MercurySports for streaming information about the Indianapolis Colts US Football team. Slightly loose Terms or Use and Privacy poli ... Read More
Wind0ws Ser7ice Agent colwindos.exe
X
Added by the W32/Rbot-GQO worm and IRC backdoor. This infection will connect to an IRC channel where it will await commands to execute. ... Read More
Com+ COM+.EXE
X
Added by the W32/Randon-O worm. This infection, when started, connects to an IRC server using a provided MIRC client to receive commands. ... Read More
CLSID com.exe
X
Adult content dialler
Microsoft Security Monitor Process com.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
ComAgent ComAgent.exe
U
ComAgent - MDaemon's instant messaging client
combo.exe combo.exe
X
Unidentified mass-mailing spam malware. When run this file, and combop.exe, send spam from your machine. ... Read More
MaxtorCombo ComboButton.exe
Y
Required to be able to use the Maxtor OneTouch button on your external Maxtor harddrive. It is used to start up backup software (Retrospect) ... Read More
combop.exe combop.exe
X
Unidentified mass-mailing spam malware. When run this file, and combo.exe, send spam from your machine. ... Read More
COMCFG comcfg.exe
X
Added by the TOADCOM.A TROJAN!
comctl32 comctl32.exe
X
Adware - recognized by Kaspersky antivirus and others as TrojanDownloader.Win32.Agent.am ... Read More
VB_run comctl_32.exe
X
Dubious downloader from densmail.com
comctsvc comctsvc.exe
X
Added by the W32/Tilebot-CM worm and IRC backdoor.
NB Common Dialog Enhancements COMDLGEX.EXE
N
Part of McAfee Nuts & Bolts. With Common Dialog Enhancements, you can add MRU list box to open dialogs ... Read More
CC2KUI comet.exe
X
Comet Cursor - displays different mouse pointers dependent upon the site your visiting. Malware because it automatically installs. See here for more i ... Read More
SSWPlauncher comet.exe /app:SSWPlauncher
X
CometCursor by Comet Systems
COM Host comHost.exe
Y
Related to Norton Internet Security.
mssysint comime.exe
X
Added by the Troj/Netsnake-I backdoor trojan.
COM-IP COMIP.EXE
N
COM-IP Virtual Modem Driver (COM-IP Creates a Fake Serial Port that allows you to use older DOS Based Communications Programs over Telnet. Type atdt h ... Read More
p2snetis comippwa.exe
X
Added by the Troj/SpamToo-AL Trojan.
Timer comm.exe
X
Added by the Troj/Bdoor-IP trojan backdoor.
COMMAND command.exe
X
Added by the QQPASS.E TROJAN!
WinProfile Command.exe
X
Added by the BUDDY TROJAN!
Currency Command.exe
X
Added by the Backdoor.Goster backdoor.
Command Service command.exe
X
Identified as Adware.CommAd.A. This adware delivers popups to your computer. This infection also installs the file asappsrv.dll into the same folder ... Read More
Messenger6 command.pif
X
Added by the INZAE.B WORM!
candy command32.exe
X
Added by the RBOT-LV WORM!
Win Command command32.exe
X
Added by the AGOBOT.XQ WORM!
Win Command command32.exe
X
Added by the AGOBOT.XQ WORM!
command32 command32.exe
X
Added by the Troj/LineaDl-A Trojan.
IomegaWare COMMANDER.EXE
N
Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs ... Read More
Browser Launcher Commandr.exe
U
Logitech internet keyboard "Commander" software - loads the software for the shortcut keys on the keyboard. Not required unless you want to use the sh ... Read More
zBrowser Launcher Commandr.exe
U
For a Logitech internet keyboard - loads the software for the shortcut keys on the keyboard. Also used to display your keyboard LEDs on-screen to indi ... Read More
zBrowser Launcher Commandr.exe
U
For a Logitech internet keyboard - loads the software for the shortcut keys on the keyboard. Also used to display your keyboard LEDs on-screen to indi ... Read More
LeapFrog Connect Device Service CommandService.exe
Y
Allows your PC to communicate with Leapfrog handheld devices via a USB port.
CommCtr commctr.exe
N
"Net2Phone CommCenter is the latest in Internet voice technology allowing you to place calls easily all over the world right from your PC!". Available ... Read More
Comm Driver commh32.exe
U
G Data "PC Spion". PC monitoring and surveilling software, captures all users activity on the PC, see here. Disable/remove if you didn't install it yo ... Read More
Windows Hijack Protection System commngr.exe
X
A variant of the RBot family of worms and IRC backdoor Trojans.
printer spooler commonaccess.exe
X
Added by the Troj/Delf-LB browser hijacking trojan.
<not used> commond.com
X
Added by the W32/Autorun-X removable media worm.
LogitechCommunicationsManager Communications_Helper.exe
U
Found on Acer laptops with webcams and Logitech webcams. Reports indicate that this process can use up a great deal of memory. If this is the case fo ... Read More
Windows Hijack Protection comngr.exe
X
A variant of the RBot family of worms and IRC backdoor Trojans.
AOL Companion companion.exe
N
Part of the AOL Connection Suite and installs an icon on the system tray offering easy access to AOL's additional utilities and functions. This progra ... Read More
Compaq Message Server COMPAQ-RBA.EXE
N
Applies to the CPQBootPerfDB entry as well. These files generate some kind of server or servlet that attempts to connect with Compaq online. They are ... Read More
IPOT Service Drivers compaq.exe
X
Added by a variant of the FUROOTKIT TROJAN!
Compaq Service Drivers compaq.exe
X
Added by the W32/Sdbot-AFU worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
compaq connections COMPAQ~1.EXE
N
See here - "messaging service that automatically sends you support information, tips, ideas, and special offers from HP and our partners, especially ... Read More
(874e009f-7e1e-42b5-86df-b9cde35ad753) comph.dll
X
Added by the Troj/Bdoor-QG backdoor Trojan.
Nvt32 complaint_7251.exe
X
Added by the TROJ_ARTIEF.B downloader Trojan. This infection downloads other malware onto your computer. ... Read More
Complete Antivirus complete.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Compliant compliant.exe
X
Added by the W32/Rbot-LB trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This i ... Read More
{A24CDBE1-DE51-32C9-7C14-F7DF9AD1BA9E} Component.exe
X
A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote serv ... Read More
Microsoft Com Port Manager COMPORT.EXE
X
Added by the W32/Sdbot-AT backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execut ... Read More
compaq service drivers compq.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Compaq Service Drivers 32 compq32.exe
X
Added by a variant of the W32/SDBOT WORM!
compaq service drivers compqs.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
compaqs service drivers compqs.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
comproremote ComproRemote.exe
U
Related to VideoMate TV tuner and capture card for your Computer.
comproschedulerdtv ComproSchedulerDTV.exe
U
Related to VideoMate TV tuner and capture card for your Computer.
Service Drivers Compt.exe
X
Added by the W32/Rbot-ZJ WORM/IRC backdoor Trojan!
Geography TX 1.0 NT CompuSpeed.vbs
X
Added by the VBS/Newley-A. The worm attempts to setup an administrator account, and if uninstalled using Add/Remove programs will likely delete SVCHOS ... Read More
blah service computer.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
CompanionWizard compwiz.exe
X
Related to the WinAntiVirus Pro 2007 rogue anti-spyware program.
Microsft Corporation Version 2001.12.4414 comrel.exe
X
A variant of the RBot family of worms and IRC backdoor Trojans.
comrep comrepl32.exe
X
Added by the W32/Rbot-DNH worm and IRC backdoor.
comrepl comreplsvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsft Corporation Version 2002.12.2414 comserv.exe
X
Identified as a variant of the W32/IRCbot.AXS.worm worm and IRC backdoor.
COMSMDEXE comsmd.exe
N
3Com tray icon
Meeting Connection comsutil.exe
X
Added by the Troj/PPdoor-E TROJAN!
SMSERIALWORKSTARTER comsysobj.exe
X
Trojan installed with the SpyBurner rogue anti-spyware program.
VbDLL COMUSG.EXE
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
comxt comxt.exe
X
Added by the COMXT TROJAN!
mlibsysmc comzcinc.exe
X
Added by the W32/Sdbot-CXS worm and IRC backdoor.
Zekio Startups condll.exe
X
W32/Agobot-AGD is an IRC backdoor Trojan and network worm. This file is located in the Windows system directory. ... Read More
Microsoft Firewall Settings Loader conf32.exe
X
Added by the W32/Sdbot-KM worm. When started this infection connects to an IRC server where it waits for remote commands. ... Read More
cucore agent ConfAgent.exe
U
First Virtual Communications, Inc., Now RADVISION Ltd Click_to_Meet videoconferencing software ... Read More
<not used> confaud.dll
X
Added by the W32/Stration-CJ worm.
<not used> confbrw.dll
X
Added by the W32/Stratio-BN worm.
Configuration Loader confgldr.exe
X
Added by the POLYBOT WORM!
AolCon config.com
X
Added by the TAPLAK WORM!
ConfigServices Config.exe
N
Part of initial setup on a Compaq PC
Configuration Utility CONFIG.EXE
N
Controls linksys wireless connection. Available from the Desktop
Microsoft Config File config.exe
X
Added by the KILLFILES.GR TROJAN! This is malware that will attempt to delete all system dlls! ... Read More
Windows Config System config.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Config33.exe Config33.exe
X
Added by the SDBOT.T TROJAN!
Configuration Loading configldr.exe
X
Added by the AGOBOT-EC WORM!
Configuration Loader configldr.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
cmd32 configs.exe
X
Hijacker, also detected as the QURL-2 TROJAN! ... Read More
update32 configs.exe
X
Hijacker, also detected as the QURL-2 TROJAN! ... Read More
configsetup configsetup32.exe
X
Added by the W32/Agobot-AFP worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Palm MultiUser Config Configtool.exe
?
MultiUser configuration for a Palm PDA device?. Is it required?
Windows Services Layer configure.exe
X
Added by the W32/Rbot-GAK worm and IRC backdoor. W32/Rbot-GAK spreads to other network computers by exploiting common buffer overflow vulnerabilities, ... Read More
Explorer config_.com
X
Added by the W32/Floppy-D floppy drive worm.
<not used> confjpg.dll
X
Added by the W32/Stration-AN mass-mailing worm.
cartao conflicted.exe
X
Added by the Troj/Dadobra-DV trojan.
Gearbox confsvr.exe
N
NTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which ... Read More
<not used> conime.exe
X
Added by the W32.Slurk.A worm. W32.Slurk.A is a worm that copies itself to all removable and shared drives, and drops other threats on to the comprom ... Read More
IME conime.exe
X
Added by the Troj/Dldr-G Trojan. This infection should not be confused with the legitimate C:\Windows\System32\conime.exe file. ... Read More
Windows Management Network (WMN) conime.exe
X
Unknown malware.
Connection Keeper ConKeepM.exe
N
Added by Connection Keeper. This program simulates Internet traffic at random intervals so that you do not go idle and thus have your connection dropp ... Read More
Microsoft Update CONlME.EXE
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Conmgr conmgr.exe
N
Starts Winfax pro at startup
ConMgr.exe conmgr.exe
U
Connection Manager as used by Earthlink and others. If you need this to ensure a proper connection but don't want to connect at startup try creating y ... Read More
Sistema de Comm conmsyrtl.exe
X
Added by the Troj/Agent-LMV Trojan.
Sametime Connect Connect.exe
U
IBM Lotus Instant Messaging and Conferencing software
Connect2Party connect2party.exe
X
Adult content dialler
System Services connection.exe
X
Added by an unidentified WORM or TROJAN!
sbc yahoo! connection manager ConnectionManager.exe
N
The cmanager.exe process is used to create and connect your SBC Yahoo DSL connection. This program has been reported to cause problems for some users. ... Read More
conmswf conrnbne.exe
X
Added by the W32/Sdbot-DEX worm and IRC backdoor.
conscorr conscorr.exe
X
Transponder parasite updater/installer
Cons consol32.exe
X
Hijacker - redirects to a p0rn portal, where foistware like ISTBar gets stealth installed ... Read More
icq center consoles.exe
X
Added as a result of the RANDIN VIRUS! ... Read More
systrasx CONSOLES.EXE
X
Added by the W32/Sdbot-NW worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Contacte contacte.exe
?
Some kind of driver?
Contraviro Contraviro.exe
X
Added by the Contraviro rogue anti-spyware program.
ContraVirus ContraVirus.exe
X
Added by the ContraVirus rogue anti-spyware program. This program uses fake and exaggerated scan results to persuade you to purchase their software. ... Read More
ContraVirus ContraVirusPro.exe
X
Added by the ContraVirus rogue anti-spyware program. This program uses fake and exaggerated scan results to persuade you to purchase their software. ... Read More
Windows Control Control.exe
X
Browser hijacker. NOTE - On Win9x systems it will overwrite the Windows file of the same name in the Windows directory, so therefore it will be necess ... Read More
SandboxieControl Control.exe
Y
Installed by the Sandboxie security software.
[Various Names] control64.exe
X
Part of the Wareout infection as described here.
BkavFw controlsys.exe
X
Added by the Troj/Tiotua-S Trojan.
Task Manager controlsys.exe
X
Added by the Troj/Tiotua-S Trojan.
CookieWall cookie.exe
U
CookieWall from Analog X. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return ... Read More
Cookie Cop 2 CookieCop.exe
U
Cookie Cop 2 from PC Magazine - cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time y ... Read More
CookieJar Cookiejar.exe
U
Cookie Jar cookie manager from Jason's Toolbox. Allows you to decide which internet sites can add "cookies" related to their sites for the next time y ... Read More
CookiePatrol CookiePatrol.exe
U
CookiePatrol - PestPatrol's cookie interceptor stopping spyware cookies
Clean Cookies Cookies.exe
X
Added by the W32/VB-DZA worm.
Microsoft System Checkup Cool.exe
X
Added by the DONK.B WORM!
HELLBOT3 coolbot.exe
X
Added by the W32/Mytob-S WORM/IRC backdoor Trojan!
CoolKill CoolKill.exe
U
Coolkill is a process killer.
copernic desktop search CopernicDesktopSearch.exe
U
Copernic Desktop_Search - "Easily search your entire hard drive in less than a second to pinpoint the right file, e-mail, music or pictures." ... Read More
CopernicPerUserTaskMgr CopernicPerUserTaskMgr.exe
U
Automatic tasking feature of Copernic Pro multi-search engine tool
compaq service drivrs copq.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
WinShowUpdate copy C:\WINDOWS\winshow.new C:\WINDOW\Swinshow.dll
X
Winshow parasiate related - from the "RunOnce" keys it replaces "winshow.dll" with a new version ... Read More
Copy handler Copy Handler.exe
U
Copy_Handler lets you copy between hard disks, floppies, local networks, CDs, and many other storage media. Copy Handler gives you the power to pause, ... Read More
Resume Copy copyfstq.exe
U
Part of Total Copy - an improved version of the Windows copy function. Allows for resumption file copies or moves in progress when computer was shut d ... Read More
compaqs service driver copypad32.exe
X
Added by the SDBOT.CSO ... Read More
cp CopyProtectionNotifier.exe
?
Related to Emuzed Systems and Middleware. Comes included with Windows XP Media Edition ... Read More
core core.sys
X
Identified by Spybot - Search and Destroy as Smitfraud-C.CoreService. This infection is a rootkit found with certain smitfraud infections. ... Read More
CoreCenter CoreCenter.exe
U
MSI Core Center - motherboard utility for monitoring CPU speed, voltages, temperatures and fans speeds as well as overclocking ... Read More
CoreCenter CORECE~1.EXE
U
MSI Core Center - motherboard utility for monitoring CPU speed, voltages, temperatures and fans speeds as well as overclocking ... Read More
Coreguard Antivirus 2009 Coreguard 2009.exe
X
Added by the CoreGuard Antivirus 2009 rogue anti-spyware program.
CorelDraw Toolbox CorelDraw.exe
X
Sdbot WORM/IRC backdoor variant adds this, and will allow for a malicious attacker to exploit the computer. ... Read More
<not used> corelnetwork.exe
X
Added by the Troj/Dial-DH Trojan.
Micosoft Data Core stuff cores.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
CoreSrv coresrv.exe
X
Some IRC trojans/worms use this - see here for more information
CORESYS coresys.exe
?
??
PC-Config32 corona.exe
X
Added by the CORONEX.A WORM!
cleanup corpstats.exe
X
Added by the Troj/Ransom-A ransoming Trojan.
[Various Names] corrida.exe
X
Part of the Wareout infection as described here.
cosine cosine.exe
X
Added by the RBOT-SW WORM!
updata_server Coson.exe
X
Added by the Troj/GrayBir-BO backdoor Trojan.
couponica couponica.exe
X
Adware - see here
CowboysScreenServer CowboysScreenServer.exe
N
Software from the MercurySports for streaming information about the Dallas Cowboys US Football team. Slightly loose Terms or Use and Privacy policy, ... Read More
CowboysScreenServerSvc CowboysScreenServer.exe
N
Software from the MercurySports for streaming information about the Dallas Cowboys US Football team. Slightly loose Terms or Use and Privacy policy, ... Read More
CP32NOT CP32BTN.EXE
U
For the programmable "one-touch" buttons on HP laptops (and others?). Safe to disable if you don't use these buttons ... Read More
CPA9P2PSERVER CPA9P2PS.exe
?
Found on a Compaq Presario but what is it?
Verizon Control Pad cpad.exe
N
Control Pad - installed with Verizon DSL accounts. Tool designed to streamline the online experience ... Read More
cpanelx cpanelx.exe
X
Added by the W32/Tilebot-FC worm and IRC backdoor. This infection is bundled with the hpdriver.sys rootkit in order to remain hidden. ... Read More
Topic cPanr cPaner.com
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Paner cPanle cPanere.exe
X
A variant of the W32.Spybot.Worm family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
CPATR10 CPATR10.EXE
U
Dritek/Compal ATR10 Easy Button driver. Used on certain laptops (e.g. Toshiba, Compaq) to translate special hotkeys such as Play/Pause and Constrast ... Read More
Cookie Pal CPBRWTCH.EXE
U
Kookaburra Softwares Cookie Pal cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time y ... Read More
CPBrWtch CPBrWtch.exe
U
Kookaburra Softwares Cookie Pal cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time y ... Read More
CPD_EXE CPD.EXE
Y
Firewall bundled with McAfee VirusScan 6.*
McAfee Firewall CPD.EXE
Y
Firewall bundled with McAfee VirusScan 6.*. Can also be listed as CPD_EXE
cpds cpds.exe
X
Added by the Troj/Ghudl-C Trojan.
COMODO Firewall Pro CPF.exe
Y
The main control program for the free firewall, Comodo Firewall Pro.
Cpl32ver Cpl32ver.exe
X
Identified as a variant of the Trojan.Drop.Kobcka.EO malware.
LManager CPLBCL53.EXE
U
A system tray icon found on Acer Travelmate laptops that allow you control access to the Internet and email buttons and other computer configurations. ... Read More
cplbtq00 CplBTQ00.EXE
N
Related to EZbutton ... Read More
cpldbl10 CPLDBL10.exe
N
Related to the EZbutton quick launcher ... Read More
CPMP32 Settings cpmp32.exe
X
A variant of the SDBot family of worms and IRC backdoors.
CPortPatch cppatch.exe
?
CPortPatch is a utility is required for Dell laptops that are using a docking station. Is it needed though? ... Read More
cppsesys cppsesys.exe
X
Added by the W32/Pasalavoz-A worm.
A1000 Settings Utility cpqa1000.exe
U
Compaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan, print, copy and fax. Only required if you use ... Read More
Compaq Print Fax cpqa1000.exe
X
Added by the W32/Sdbot-WL WORM/IRC backdoor trojan!
CPQAcDc CPQAcDc.exe
Y
Compaq PowerCon power management software for laptops
Compaq Alerter CPQAlert.exe
U
Compaq's Insight Manager Agent - a tool that allows for "fault, performance, and configuration management". Recommended for corporate users only. It's ... Read More
CPQAlert CPQAlert.exe
U
Compaq's Insight Manager Agent - a tool that allows for "fault, performance, and configuration management". Recommended for corporate users only. It's ... Read More
CPQBootPerfDB CPQBootPerfDB.EXE
N
See the entry for Compaq Message Server
CPQCalib CPQCalib.exe
Y
Compaq PowerCon power management software for laptops
CPQDFWAG CpqDfwAg.exe
N
For Compaq PC's. Runs Compaq diagnostics on every boot
System DLF cpqdiaga.exe
N
Compaq Diagnostic record system utility which allow you to view information about your computer's hardware and software configuration. Available via S ... Read More
Compaq DMI cpqdmi.exe
N
Compaq version of the Desktop Management Interface
CPQEASYACC cpqeadm.exe
U
For Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys ... Read More
cpqeaui cpqeaui.exe
U
For Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys ... Read More
CompaqHW Comp Manager cpqhcm.exe
?
Running on a Compaq laptop - any ideas?
CPQInet Runtime Service CpqInet.exe
U
For Compaq PC's. Allows AOL and Compuserve to use the Easy Access buttons for the internet. Is not required if you don't use the ISP providers ... Read More
CPQINKAGENT cpqinkag.exe
N
That is the Compaq Ink Agent for some inkjet printers, it lets users know when their ink cartridges are getting close to empty (by how many pages they ... Read More
Compaq PK Daemon cpqkl.exe
U
For Compaq laptops for programming user configurable keys. Not required unless you use them ... Read More
digital dashboard CPQMLDET.exe
N
For Compaq PC's. Loads Digital Dashboard options
HP Insight NIC Agents cpqnimgt.exe
Y
HP Insight Management Agents perform in-depth monitoring of a device's state by collecting and measuring key parameters on the device. The HP Insight ... Read More
cpqns cpqnpcss.exe
U
Related to Compaq.Net - not required if you don't use that
CompaqSystray cpqpscp.exe
N
Compaq System Tray icon
HP ProLiant Remote Monitor Service cpqrcmc.exe
Y
The HP ProLiant Remote Monitor Service provides support for HP ProLiant PCI Hot Plug devices and remote management utilities. This service gives hot p ... Read More
Cpqset Cpqset.exe
N
Default settings software in Hewlett Packard notebook
CPQTEAM cpqteam.exe
N
This program is bundled with HP servers. When loaded a system tray icon will be available that launches the HP Network Configuration Tool. ... Read More
cpr cpr
X
Adroar.com adware downloader
control panel software service cprs.exe
X
Added by the W32/Rbot-FPI worm and IRC backdoor.
Compaq Presario SSH cpsd.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Norton Live Update Server cpsdv.exe
X
Added by the AGOBOT.EW TROJAN!
system drivers cpsq32.exe
X
Added by the SDBOT.AXH ... Read More
Cryptic Protected Storage cpstorage.exe
X
Added by the W32/Tilebot-HO worm and IRC backdoor. W32/Tilebot-HO attempts to spread by copying itself to remote network shares or by exploiting any o ... Read More
Microsoft CPU Over Heat Manager CPU.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Sun Java cpu.exe
X
Identified as a variant of the Backdoor.Win32.Rbot.gen malware.
CPUcool Cpucool.exe
U
Program to keep the processor cool when idle in "overclocked" systems. Also available via Start -> Settings -> Control Panel ... Read More
CPU microcode correction cpudev.sys
X
Added by the Troj/Haxdoor-AO Trojan.
Windows USB 2.0 Driver cpufanctrl.exe
X
Added by the W32/Rbot-CLP worm and IRC backdoor. This infection also creates the file C:\Windows\SoftWareProtector\424.pr. ... Read More
CPU Manager cpumgr.exe
X
Added by the PANDEM.B WORM!
IntelProcNumUtility cpunumber.exe
U
Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You ... Read More
Cpusave Cpusave.exe
X
Added by the GEMA TROJAN!
Cpusave32 Cpusave32.exe
X
Added by the GEMA TROJAN!
GT15J4R49V cpuserv.exe
X
Identified as a variant of the Trojan.Win32.Radi.gu malware.
cpu windows status cpustats.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
CPVHOST Settings cpvhost.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
Microsoft CPXP Protocol cpxp.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
My Computer cqcags.exe
X
Added by the W32/Sdbot-TJ WORM/IRC backdoor trojan!
HP Insight Foundation Agents cqmghost.exe
Y
HP Insight Management Agents perform in-depth monitoring of a device's state by collecting and measuring key parameters on the device. The HP Insight ... Read More
HP Insight Server Agents cqmgserv.exe
Y
HP Insight Management Agents help IT administrators rapidly respond to potential and actual system failures, increase system stability, reduce trouble ... Read More
HP Insight Storage Agents cqmgstor.exe
Y
The HP Insight Storage Agent displays information about the Mass Storage Subsystems which consists of fibre channel, drive array and SCSI subsystems c ... Read More
cqpmxujjl.exe cqpmxujjl.exe
X
Added by the Troj/StartP-BAI Trojan.
{cea2e5cd-e849-427b-80f0-59298caef1c4} cqsfk.dll
X
Zlob Trojan that installs VirusProtectPro 3.4 and shows fake security alerts from your Windows taskbar. ... Read More
cracked_windows1 cracked_windows1.exe
U
Cracked Windows popup killer
<not used> crase.exe
X
Added by the W32.Debanpass worm. W32.Debanpass is a worm that copies itself to all drives. It steals confidential information and account details when ... Read More
lameshit crash.exe
X
Added by the Troj/LowZone-H trojan.
<random name> crasos.exe
X
Added by the Troj/DropPS-A Trojan.
$sys$crater crater.sys
U
Added by the Sony/XCP DRM security software. This service is part of the digital rights management system utilized on certain Sony CDs. If you remove ... Read More
crbroadcasting CRBroadCasting.exe
U
Related to CardReader2 from On Track Inovations Ltd. USB Card Reader. ... Read More
CRC Protection crc32.exe
X
Added by the Troj/Agent-PO Trojan.
Crc32stats Dependencies Crc32stats.exe
X
Added by the W32.Mytob.GT@mm worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
<not used> crclan.exe
X
Added by the W32/Rungbu-E virus. W32/Rungbu-E searches for files with a DOC extension and appends them to itself. It then deletes the original file, a ... Read More
PCprot crcss.exe
X
Added by an unidentified WORM!
Client Server Control Process crcss.exe
X
Added by the Troj/Agent-HR backdoor Trojan.
CRCSS crcss.exe
X
A variant of RBot, SDBot, or other IRCBot worm.
Windows Media Updater crease.exe
X
Added by the W32/Rbot-ATI worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Create A Monster createAMonster.exe
X
Kudd.com CreateAMonster. Reportedly stealth installed and Look2Me adware related ... Read More
CreateCD Createcd.exe
N
Adaptec Easy CD Creator system tray application (pre version 5). Available via Start -> Programs ... Read More
CreateCD50 Createcd50.exe
N
Adaptec Easy CD Creator version 5 system tray application. Available via Start -> Programs ... Read More
setFTPBack createsw.exe
X
Added by the FTP_BMAIL TROJAN!
Creative.exe Creative.exe
X
Added by the PROLIN WORM!
Creative Audio Drivers creative.exe
X
Added by the W32/Rbot-FKR worm and IRC backdoor.
crehcjid crehcjid.dll
X
Identified as a variant of the Email-Worm.Win32.Locksky.bp malware.
System Updater Machine crhwss.exe
X
Added by the Troj/Ciadoor-DQ Trojan.
MSUpdate criticalUpdate.exe
X
Affilred adware
C:\Program Files\dfjdkjfdkjfldjf\dfjdkjfdkjfldjf\winlogin.exe CritProc.exe
U
Added by the Spyware.KeyProwler surveillance software. Spyware.KeyProwler is a spyware program that logs keystrokes typed into the computer. This sof ... Read More
Winsock2 driver crizak.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft USB2 Driver crmss.exe
X
Added by the W32/Rbot-VK worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
Windows Firewall Updater cronos.exe
X
Added by the W32/Rbot-GBY worm and IRC backdoor. W32/Rbot-GBY spreads to other network computers by exploiting common buffer overflow vulnerabilities, ... Read More
Windows Cron Service crons.exe
X
Added by the Troj/Hupigon-SR backdoor Trojan.
crossmenu CrossMenu
U
Toshiba CrossMenu Utility - allows the user to create their own menus
CRP386 Networking crp386.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
crs crs.exe
X
Added by the W32/Agobot-TJ worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute. ... Read More
<not used> crs.exe
X
Added by the Troj/Delf-ESL Trojan.
Explorer crs.exe
X
Added by the Troj/PWSteal-G password-stealing Trojan.
ASP.NET State Service crsass.exe
X
Added by the Troj/Banload-M downloader Trojan.
Windows System Manager CRSL.EXE
X
Added by the WORM_SDBOT.MG worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
Print Driver Helper Service crsrr.exe
X
Added by the AGENT-BC TROJAN!
Auto updat and other names crsrs.exe
X
Added by the FORBOT-AK WORM!
Win32 Information Service crsrs.exe
X
Added by the W32/Delbot-S worm and IRC backdoor. W32/Delbot-S spreads to other network computers by scanning network shares for weak passwords and by ... Read More
Windows Executable Dir crsrs.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Controlled Resource System Service crss.exe
X
Added by the AGOBOT.GH WORM!
System Config Manager crss.exe
X
Added by the AGOBOT.GH WORM!
Win32 Network Driver crss.exe
X
Added by a variant of the AGOBOT/GAOBOT WORM!
Windows Registry Security crss.exe
X
Added by a variant of the IRC.BOT TROJAN!
CRSS CRSS.exe
X
added by the W32/Agobot-RM WORM!
Microsoft ActiveX Component crss.exe
X
Added by the Troj/Small-CR trojan downloader.
2k6 updatz crss3.exe
X
Added by the W32/Rbot-CPD worm and IRC backdoor.
[unknown] crss32.exe
X
Added by the W32/Randon-X worm. This infection, when started, connects to an IRC server using a provided MIRC client to receive commands. ... Read More
crss32.exe crss32.exe
X
Added by the W32/Tilebot-GT worm and IRC backdoor.

W32/Tilebot-GT spreads to other network computers by exploiting common buffer overfl ... Read More
Client Server Runtime Counter crssc.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
crssm.exe crssm.exe
X
Added by the W32/Rbot-AFH worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Windows System Manager crssm.exe
X
Added by the W32/Rbot-AFH worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
CaptionMgr32 crssr.exe
X
Added by the Zar.A infection. It attempts to spread itself through emails sent out with the subject "Tsunami Donation!". The file is found in the Wi ... Read More
MS taskbar crssr.exe
X
Added by the W32/Rbot-AGO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
sp2 firewall/internet updater crssrs.exe
X
Added by the RBOT.BJO WORM! ... Read More
Windows media service crsss.exe
X
Added by the RBOT.ACY WORM!
CRC Value Verifier crsss.exe
X
Added by the SPYBOT.UK WORM!
start uploading crsss.exe
X
Added by the W32/Rbot-SZ worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
MSControl28 crsss.exe
X
Added by the W32/Rbot-AQL worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Win32 Security Service crsss.exe
X
Added by the W32/Delbot-O worm and IRC backdoor.
Creates R Files Systems crsss.exe
X
A variant of the W32/Sdbot.KYC.worm family of worms and IRC backdoor Trojans.
Msn Messanger crsss.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Service Update crsss.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
CRC Value Verifier crsss32.exe
X
Added by a variant of the RBOT WORM!
CRC Value Verifier Crsss64.exe
X
Added by the RBOT-NY WORM!
CRSSXP SysInfo crssxp.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
Explorer CRSVS.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
system32 crsvvc.exe
X
Added by the RBOT.BLY WORM! ... Read More
microsoft internet explorer crsys32.exe
X
Added by the RBOT.UZ WORM! ... Read More
Microsoft Control Center crtl.exe
X
Added by W32/Rbot-VX
Microsoft CRT Monitor Manager crtmon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows (ICS) Spooler crtss.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows media service crvss.exe
X
Added by the SDBOT.VP WORM!
Crypkey License crypserv.exe
Y
Used by certain software as copy protection. This should be left running otherwise the program that utilizes it may not work. ... Read More
crypt32net crypt32net.dll
X
Added by the Troj/Banworm-I Trojan.

Troj/Banworm-I may modify the HOSTS file which maps the URLs of selected websites to a loopback IP ... Read More
crypt32 crypt32rt.dll
X
Unknown malware.
Cryptainer service cryptainersrv.exe
Y
Related to the Cryptainer encryption software.
cryptdlg cryptdlg.exe
X
Added by an unidentified TROJAN!
cryptdrv cryptdrv.sys
X
Added by the Backdoor.Rustock backdoor rootkit.
<not used> cryptfg.exe
X
Identified as the Trojan.PWS.Zassan password-stealing Trojan.
cryptonet cryptonet.dll
X
Added by the Troj/Oscor-M backdoor Trojan.
crypt crypts.dll
X
Added by the Troj/Agent-GJR Trojan.
crypta cryptsa.dll
X
Identified as the Trojan-Downloader.Win32.Agent.btd Trojan.
NTP CryptWan.dll
X
Added by the Troj/PWS-AZQ password-stealing Trojan.
calendarscope cs.exe
U
Calendarscope calendar software ... Read More
AdobeCS4ServiceManager CS4ServiceManager.exe
U
This service allows the proper functioning of a service like Adobe Drive and other network functions. ... Read More
IPv6 Helper Driver csass.exe
X
Added by the AGOBOT.TC WORM!
WSAConfiguration1 csass.exe
X
Added by the AGOBOT.WH WORM!
LanGuard Auto Updater csass.exe
X
Added by the W32/Rbot-DS trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
csc csc.exe
?
??
cscripts cscripts.exe
X
Added by the Troj/Bdoor-AAP backdoor Trojan.
CSCRS Value cscrs.exe
X
Added by W32/Rbot-AAA.
Critical Service cscrs.exe
X
Added by the W32/Rbot-BFY worm and IRC backdoor.
Microsoft Data Machine csdata32.exe
X
Added by a variant of the RBOT WORM!
CsdDriver CsdDriver.sys
X
Added by the Troj/Goldun-EE password-stealing Trojan.
WinMX share CSDVqs.exe
X
Added by the W32/Sdbot-UU worm. When started, this infection connects to a remote IRC server and waits for commands to execute. ... Read More
Current Security Config csecure.exe
X
Added by the W32/Rbot-AMO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
fortis secure layer config cseinst.exe
U
Fortis Bank Home Banking part. Installed during the installation of the software necessary to run the Home Banking. According to Fortis Bank this will ... Read More
absoluteshield internet eraser cseraser.exe
Y
Related to AbsoluteShield_Internet_Eraser application. Note: located in C:\Program Files\SysShield Tools\Internet Eraser\ ... Read More
CuteShield Internet Eraser cseraser.exe
U
CuteShield Internet Eraser "Protects your privacy by cleaning up all the tracks of your Internet and computer activities (Free popup blocker included) ... Read More
AbsoluteShield Internet Eraser cseraser.exe
U
CuteShield Internet Eraser "Protects your privacy by cleaning up all the tracks of your Internet and computer activities (Free popup blocker included) ... Read More
cserv32 cserv32.exe
X
Added by the W32/Stration-BQ mass-mailing worm.
CsimPlayer CsimPlayer.exe
X
Added by the W32/Koobface-AD Worm.
CSINJECT.EXE CSINJECT.EXE
U
Part of Quarterdeck/Norton CleanSweep. For a full description see here. An excerpt - "Csinject must be loaded in order for Smart Sweep to automaticall ... Read More
CleanSweep Smart Sweep- Internet Sweep Csinsm32.exe
U
Automatic logging of installs from Norton CleanSweep - available via Start -> Programs ... Read More
MPEO Csinsm32.exe
U
Automatic logging of installs from Norton CleanSweep - available via Start -> Programs ... Read More
NCS_SS Csinsm32.exe
N
Same as CleanSweep Smart Sweep-Internet Sweep
CleanSweep Smart Sweep-Internet Sweep CsinsmNT.exe
N
Related to Norton CleanSweep.
xware cskware.exe
X
Malware downloader from xxsware.com, produces porn popups.
csm Win Updates csm.exe
X
Added by the W32/Zotob-B worm and backdoor Trojan.
<not used> csmm.exe
X
Added by the Troj/VB-DZN Trojan.
new csnm manager csmn.exe
X
Added by the SDBOT.BZS WORM! ... Read More
ConSrvMgr csmrsnv.exe
X
Added by the Troj/Stinx-J backdoor Trojan.
cmsssystemprocess csms.exe
X
Added by the AGENT-Y TROJAN! ... Read More
cmssSystemProcess csmss.exe
X
Added by the AGENT-CO TROJAN!
spoolsvr32 csmss.exe
X
Added by the AGENT-AU TROJAN!
VC5MediaPlayer csmss.exe
X
Added by the DEDLER-B WORM!
WIN95DEFVIEW csmss.exe
X
Added by the TROJ/DEDLER-D TROJAN!
spoolsvr32 csmss32.exe
X
Added by a variant of the AGENT-AU TROJAN!
ControlServiceMgr csmsv.exe
X
Added by the Troj/Agent-XC Trojan.
ManageProtoclCtrl csmsv.exe
X
Added by the Troj/Stinx-B backdoor Trojan.
SDAv CSNSS.EXE
X
Added by the W32/Sumom-C instant messenger and P2P worm.
NDAv CSNSS.EXE
X
Added by the W32/Sumom-C instant messenger and P2P worm.
Service Monitor csnss.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
csos csos.exe
X
Added by the W32/Sdbot-DFE worm and IRC backdoor.
Client Server Runtime Service csr.exe
X
Added by the W32/Sdbot-AFM worm and IRC backdoor.
ClientServerRuntimeService csrcc.exe
X
Added by the Trojan.Sufiage Trojan.
WindowsTaskStat csrcmd.exe
X
Added by the Troj/Brepbot-B backdoor Trojan. This infection also creates the files 466.bat and 755.bat. ... Read More
Windows Custom Services CSRCS.EXE
X
Added by the W32/Spybot-EI worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
csrcs csrcs.exe
X
Added by the Troj/Agent-HUA Trojan.
Client Server csrcs.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
TaskControlLog csrdeu32.exe
X
Added by the BKDR_BREPLIBOT.M worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Remndr CsRemnd.exe
X
CasinoOnline foistware
Csrss Host csrhost.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Privacy Suite RiskMonitor CSRiskmon.exe
U
Added by the Privacy Suite security software. Risk Monitor will alert you when the programs sees that your privacy is at risk. ... Read More
ethernet adapter csrmss.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
DriverModule csrnvrt.exe
X
Added by the Troj/Stinx-Q backdoor Trojan. This infection also creates the files 557.bat and 989.bat in your Temp directory. ... Read More
Service Controller Csrrs.exe
X
Added by the GAOBOT.AO WORM!
csr csrrs.exe
X
Added by the W32/Rbot-CKM worm and IRC backdoor.
Windows Time Service csrrs.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Taskmanager Data csrrss.exe
X
Added by the W32/Rbot-BBH worm and IRC backdoor.
Com+ Sys csrs.exe
X
Added by the FORBOT-BT WORM!
NetWork csrs.exe
X
Added by the AGOBOT.JJ WORM!
Windows Update Service csrs.exe
X
Added by the AGOBOT-NI WORM!
Client Server Runtime Process csrs.exe
X
Added by the W32.Linkbot.M worm.
microsoft client/server runtime server subsystem csrs.exe
X
Added by a variant of the AGOBOT/GAOBOT WORM! ... Read More
windows client/server runtime server csrs.exe
X
Added by the RBOT.KD WORM! ... Read More
Windows Time Sync csrs.exe
X
Added by the W32/Tilebot-N backdoor and IRC worm.
Intel Driver csrs.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Action csrs.exe
X
Added by the W32/Seccmu-A worm.
Creates Files Systems Protections csrs.exe
X
A variant of the Win32/Rbot.HIU family of worms and IRC backdoor Trojans.
Creates Remote Systems csrs.exe
X
A variant of the Win32/Rbot.HIU family of worms and IRC backdoor Trojans.
Microsoft Corp. Critical Services csrs.exe
X
Added by the W32/Rbot-GTJ worm and IRC backdoor.
dark csrs.scr
X
Added by the Troj/Bancban-GT password-stealing Trojan.
boby csrs.scr
X
Added by the Troj/Banker-BMA banking Trojan. If you are infected with this infection it is advised that you immediately change your online banking pas ... Read More
Norton System csrs.scr
X
Added by the Troj/Banloa-AFM downloader Trojan.
System32-Driver csrs32.exe
X
Added by the W32/Sdbot-CP backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execut ... Read More
csrsc csrsc.exe
X
Added by an unidentified VIRUS, WORM or TROJAN!
Network Gateway Manager csrsc.exe
X
Added by the W32/Sdbot-CPE worm and IRC backdoor.

W32/Sdbot-CPE spreads
- to computers vulnerable to common exploits, including: ... Read More
Microsoft Registry csrse.exe
X
Added by the RBOT-PC WORM!
csrse.exe csrse.exe
X
Added by the Backdoor.Hesive Trojan backdoor.
system process CSRSR.exe
X
Added by the W32/AGOBOT-SQ WORM! ... Read More
Windows Services csrsrss.exe
X
Added by the W32.Nujama.B worm. W32.Nujama.B is a worm that spreads through mapped drives and shared folders, and lowers security settings on the comp ... Read More
Client Server Run Time Proccess csrsrv.exe
X
A variant of the IRCBot family of worms and IRC backdoors.
winupdateprotection csrss.ex
U
EmployeeWatch is a commercial spyware program designed to monitor user activity on a computer. ... Read More
.TEXTCONV csrss.exe
X
Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! ... Read More
.WMAudio csrss.exe
X
Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! ... Read More
AdRotator.Application csrss.exe
X
AdRotator adware. Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and ha ... Read More
BagleAV csrss.exe
X
Added by the NETSKY.AB WORM! Note - this is not the legitimate csrss.exe process which should NOT appear in Msconfig/Startup! ... Read More
BuildLabs csrss.exe
X
Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! ... Read More
ccpApps csrss.exe
X
Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! ... Read More
ClickTheButton csrss.exe
X
ClickTheButton Downloader-MY adware. Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! ... Read More
CSRSS CSRSS.EXE
X
Search page hijacker, redirecting to http://www.search-aide.com/. Note - this is not the valid Client Server Runtime Subsystem (csrss.exe) process, wh ... Read More
DIECOX csrss.exe
X
Added by a variant of the ATM.GEN TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! ... Read More
FiendlyType csrss.exe
X
Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! ... Read More
KernellApps csrss.exe
X
Added by the BANCBAN-AC TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! ... Read More
Key Logger csrss.exe
X
Added by the BUCHON.A WORM! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! ... Read More
Microsoft SourceSafe csrss.exe
X
Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! ... Read More
NTDLM csrss.exe
X
Added by the HALE TROJAN! Note - this is not the legitimate csrss.exe process which should NOT appear in Msconfig/Startup! ... Read More
Prog csrss.exe
X
Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! ... Read More
RegDone Ex csrss.exe
X
Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! ... Read More
RegWrite csrss.exe
X
Added by the SOKACAPS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! ... Read More
Run TaskMrg csrss.exe
X
Added by the LDPINCH-W TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! ... Read More
rundll32 csrss.exe
X
Added by the GUTTA TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! ... Read More
Shockwave csrss.exe
X
Added by the SNDOG WORM! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! ... Read More
SYSTEMSars32 csrss.exe
X
Added by the AHLEM.A WORM! Note - this is not the legitimate csrss.exe process which should NOT appear in Msconfig/Startup! ... Read More
WinUpdateProtection csrss.exe
U
ICE Remote Spy monitoring software, "secretly monitors everything your spouse, kids or employees do on the Internet and emails the data to you." Note ... Read More
SernellApp.pcx csrss.exe
X
Added by the Troj/Bancban-BJ trojan. Located in Windows system folderD5133csrss.exe. ... Read More
Runner csrss.exe
X
Added by the Troj/AdClick-AG Trojan! File is found in the Windows folder.
Update csrss.exe
X
Added by the Troj/AdClick-AG Trojan! File is found in the Windows folder.
System Process csrss.exe
X
Added by the Troj/AdClick-AG Trojan! File is found in the Windows folder.
_winsystem.sys CSRSS.EXE
X
Added by the W32/Sober-K infection! File will be found in the %WINDIR%msagentwin32 folder. ... Read More
winsystem.sys CSRSS.EXE
X
Added by the W32/Sober-K infection! File will be found in the %WINDIR%msagentwin32 folder. ... Read More
Windowsupdate Service csrss.exe
X
W32/Baba-E WORM creates this file, not to be mistaken for the legitimate Windows file documented here. ... Read More
System csrss.exe
X
Added by the PWSteal.Ldpinch.E TROJAN!
Krnlcheck csrss.exe
X
Added by Backdoor.Botnachala. This infection also adds entries to your HOSTS file. ... Read More
FirewallActivies csrss.exe
X
Added by the Troj/Banker-AQ TROJAN!
WinXP-98 CSRSS.exe
X
Added by the Troj/Banker-AZ password-stealing trojan that targets Brazilian banks. ... Read More
COM+ System Application csrss.exe
X
Added by the W32.Banish.A@mm mass-mailing worm.
TaskMrg csrss.exe
X
Added by the Troj/LdPinch-W trojan.
systemdriver csrss.exe
X
Added by the ASCETIC.B TROJAN - Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, ... Read More
windows 2004 CSRSS.exe
X
Added as result of a Troj/Banker-DY trojan infection ... Read More
_systemdriver csrss.exe
X
Added by the ASCETIC.B TROJAN - Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, ... Read More
.svchost csrss.exe
X
Added by a new Rbot variant. This infection when started connects to a remote IRC server where it waits for commands to execute. ... Read More
microsoft windows csrss csrss.exe
X
Added by the W32/KALEL-A WORM! - NOTE - this file should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe proce ... Read More
Microsoft Word Profissional csrss.exe
X
Added by the Troj/Bancban-DB password-stealing trojan. This infection targets Brazilian banks, so if you are a user of these banks you should check y ... Read More
COM+ System Application csrss.exe
X
Added by the W32.Banish.A@mm mass-mailing worm. Note: this should not be confused with the legitimate c:\windows\system32\csrss.exe or c:\windows\syst ... Read More
Norton Protect Activies csrss.exe
X
Added by the Troj/Banker-CZ Internet banking trojan. This infection has the ability to steal information and log keystrokes. if you are infected wit ... Read More
Windows Explorer SP2 csrss.exe
X
Added by the Troj/Banker-DM password-stealing trojan for Brazilian banks.
ASP.NET State Service csrss.exe
X
Added by the Troj/Dloader-QI downloader trojan.
csrsslevel4 csrss.exe
X
Unidentified malware - NOTE - this file is placed in a C:\Windows\SystemLevel4 folder, and should NOT be confused with the legitimate Windows Client ... Read More
csrss csrss.exe
U
Added by the Spyware.Keylog surveillance software. Uninstall this software if it was not installed by yourself. ... Read More
State Service csrss.exe
X
Added by the Troj/Dadobra-CP trojan.
Windows Client Service 32 csrss.exe
X
Added by the W32/Rbot-ALB worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Console de Gerenciamento Microsoft csrss.exe
X
Added by the Troj/Bancban-ET password-stealing Trojan.
Windows Time Sync csrss.exe
X
Added by the W32/Tilebot-W worm and IRC backdoor.
atisound csrss.exe
U
Added by the WinSpy surveillance software. Uninstall this software unless you put it there yourself - NOTE - this file is placed in a %System%\ComRoo ... Read More
Windows Spooler csrss.exe
X
Added by the W32/Tilebot-AL worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. This should no ... Read More
Windows Update csrss.exe
X
Added by the Troj/Banker-IA Trojan.
Debugger csrss.exe
X
Added by the W32.Beagle.EA@mm mass-mailing worm. This infection should not be confused with the legitimate c:\windows\system32\csrss.exe file. ... Read More
Application csrss.exe
X
Added by the W32.Beagle.EG@mm mass-mailing worm. The emails that are sent are written in Russian. ... Read More
avast! servers csrss.exe
X
Added by the Troj/Banker-CLW Internet banking Trojan. If you have this infection you should immediately change all of your online banking account inf ... Read More
Clients Server Runtime Process csrss.exe
X
Added by the W32/Sdbot-CPF worm and IRC backdoor.
Logonsara csrss.exe
X
Added by the W32/Brontok-BS worm. This infection should notbe confused with the legitimate C:\Windows\System32\csrss.exe program. ... Read More
Logonrepclient1 CSRSS.EXE
X
Added by the W32/Brontok-BT worm. This infection should notbe confused with the legitimate C:\Windows\System32\CSRSS.EXE program. ... Read More
ClientServerRuntimeProcess csrss.exe
X
Added by the Troj/Sufia-A Trojan. This infection should not be confused with the legitimate C:\Windows\System32\csrss.exe file. ... Read More
VideoDriver csrss.exe
X
Added by the Troj/WinSpy-K backdoor Trojan. This infection should not be confused with the legitimate C:\Windows\System32\csrss.exe. ... Read More
Removabie Storage csrss.exe
X
Added by the Troj/GrayBrd-CM backdoor Trojan. This infection should not be confused with the legitimate C:\Windows\System32\csrss.exe file. ... Read More
Windows Services csrss.exe
X
Added by the W32.Nujama worm. W32.Nujama is a worm that spreads through mapped drives, hides file extensions, and changes system information. ... Read More
Microsoft Windows Update Client csrss.exe
X
Added by the W32/Kebede-G worm.
Client/Server Runtime Server Subsystem csrss.exe
X
Added by the W32/IRCBot-UN worm and IRC backdoor.
WINDOWSNT csrss.exe
X
Added by the Backdoor.Olourk backdoor. This infection should not be confused with the legitimate C:\Windows\System32\csrss.exe infection. ... Read More
Microsoft (R) Windows Client/Server Runtime Service csrss.exe
X
Added by the Backdoor.Ranky backdoor Trojan. This infection should not be confused with the legitimate C:\Windows\System32\csrss.exe. ... Read More
Microsoft (R) Windows TCP/IP Socket Driver csrss.exe
X
Added by the Backdoor.Ranky backdoor Trojan. This infection should not be confused with the legitimate C:\Windows\System32\csrss.exe file. This infect ... Read More
WinUpdateAdministrator CSRSS.EXE
X
Added by the W32/Punya-A worm. This infection should not be confused with the legitimate C:\Windows\System32\CSRSS.EXE file. ... Read More
WindowsExplorer csrss.exe
X
Added by the MessengerBlocker rogue security software. MessengerBlocker is a misleading application that may periodically spam the user's computer wit ... Read More
NAVUpdater csrss.exe
X
Added by an unknown malware.
Client Server Runtime Proces csrss.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
AVManager csrss.exe
X
Added by the W32/Autorun-DV removable media worm. This infection should not be confused with the legitimate C:\Windows\System32\csrss.exe file. ... Read More
Srv32Win csrss.exe
X
Identified as a variant of the Trojan-Downloader.Win32.SpyAgent.r malware. This infection should not be confused with the legitimate C:\Windows\Syste ... Read More
Svchost csrss.exe
X
Identified by Avira as a variant of the BDS/Bandok.HR backdoor Trojan. This infection should not be confused with the legitimate C:\Windows\System32\c ... Read More
LogonAdministrator CSRSS.EXE
X
Added by the W32.Korron.B worm. W32.Korron.B is a worm that replaces some file types with a copy of itself. It also copies itself to all accessible dr ... Read More
Microsoft CSRSS32 Protocol csrss32.exe
X
Added by a variant of the AGOBOT/GAOBOT WORM!
Microsoft Update Service csrss32.exe
X
Added by the AGOBOT-HC WORM!
System Log Event csrss32.exe
X
Added by the AGOBOT-JI WORM!
27 csrss32.exe
X
Added by the Troj/Slsorve-D Trojan.
Microsoft CSRSS386 Protocol csrss386.exe
X
Added by a variant of the SPYBOT WORM!
Csrss csrss5.dll
X
Identified by Avira as a variant of the TR/Agent.rnn malware.
microsoft client/server runtime server subsystem csrssa.exe
X
Added by a variant of the AGOBOT/GAOBOT WORM! ... Read More
(Random Name) csrssc.exe
X
Identified as a variant of the Win32/TrojanDownloader.Small.CYF malware.
Client Server Runtime Process csrsss.exe
X
Added by the SDBOT-LD WORM!
CSRSS Loader csrsss.exe
X
Added by the AGOBOT.TX WORM!
CSRSSU CSRSSU.EXE
X
CoolWebSearch parasite related - hijacking to Slawsearch.com. You are advised to ask for help in our HijackThis forum to remove it. Located in the Win ... Read More
Microsoft DLL Verifier csrssv.exe
X
Added by the W32/Rbot-ATK worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
csrssw CSRSSW.EXE
X
Added by the TROJ/CWS-F TROJAN! ... Read More
argq32 csrss_32.exe
X
Added by the W32/Rbot-CPM worm and IRC backdoor.
wsaconfiguration csrsvcs.exe
X
Added by the AGOBOT.VI WORM! ... Read More
MSN csrsx.exe
X
Added by a variant of the Win32/Pushbot worm and IRC backdoor. Win32/Pushbot is a family of worms that spread using MSN Messenger. ... Read More
System132 Csrtss.exe
X
Added by the Troj/LanFilt-I. This infection connects to an IRC server where it waits for remote commands to execute, it can also log keystrokes, down ... Read More
csrvss csrvss.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
ProtocolEventTsk csrwjd.exe
X
Added by the Troj/Stinx-N backdoor Trojan.
SystemProcEvent csrwnd.exe
X
Added by the Troj/Stinx-O backdoor Trojan.
cssauth cssauth.exe
U
Related to IBM ThinkVantage Client Security Solution
InstallDriver Service csscv.exe
X
Added by the W32/Sdbot-CPL worm and IRC backdoor.
MSN cssr.exe
X
Added by a variant of the Win32/Pushbot worm and IRC backdoor. Win32/Pushbot is a family of worms that spread using MSN Messenger. ... Read More
Display Drivers cssrs.exe
X
Added by the AGOBOT.FX WORM!
WinFX cssrs.exe
X
Added by the AGOBOT.FX WORM!
cssrs cssrs.exe
X
Added by the Troj/Bancban-DW ... Read More
MS Unix Binary cssrs.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MSN cssrs.exe
X
Added by a variant of the Win32/Pushbot worm and IRC backdoor. Win32/Pushbot is a family of worms that spread using MSN Messenger. ... Read More
Verificador do sistema cssrs.exe
X
Added by the W32.Mocon worm. W32.Mocon is a worm that logs keystrokes and steals information from the infected computer. It spreads by copying itself ... Read More
cssrs cssrs.scr
X
Added by the Troj/Banker-DAE Trojan. Troj/Banker-DAE attempts to steal confidential information entered into online banking websites. ... Read More
MSN ang cssrss.exe
X
Added by the FORBOT-CE WORM!
WMDM PMSP Service cssrss.exe
X
Added by the Troj/Knockit-A backdoor Trojan.
MSN cssrss.exe
X
Added by a variant of the Win32/Pushbot worm and IRC backdoor. Win32/Pushbot is a family of worms that spread using MSN Messenger. ... Read More
Microsoft Update Machine cssrssv.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
csss Csss.exe
X
Added by the BALICK TROJAN!
css server CSSServer.exe
U
Added by the ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself. ... Read More
MSN csssrss.exe
X
Added by a variant of the Win32/Pushbot worm and IRC backdoor. Win32/Pushbot is a family of worms that spread using MSN Messenger. ... Read More
Monitoring Service CSSSWD.exe
U
Added by the SnoopStick surveillance software. SnoopStick comes on a USB Flash Drive and can be installed by inserting the USB Drive into the computer ... Read More
CSS_Central CSS_1631.EXE
U
CSS Communication Agent (95 Host) from Command Software Systems "CSS Central™ provides administrators with a powerfully proactive tool to effectively ... Read More
SysW8 csta.exe
U
Clean Space - privacy and perfomance enhancer
ChineseStar cstar.exe
U
Chinese language support software
nvsv32.exe cstr.exe
X
Added by a variant of the W32/SDBOT WORM!
WindowsDiskLog cstsm.exe
X
Added by the Troj/Stinx-C backdoor Trojan.
CleanSweep Useage Watch CSUSEM32.EXE
N
Quarterdeck/Norton CleanSweep component - tracks how often you use files and alerts you to files that have not been used for a specified period of tim ... Read More
CSV10P70 CSv10P070.exe
X
ClearSearch adware related
CSV7P70 CSV7P070.exe
X
ClearSearch adware related
CSV7P26 CSV7P26.exe
X
ClearSearch adware related
CSV7P91 CSV7P91.exe
X
ClearSearch adware related
[not used] csvc.com
X
Added by the Backdoor.Beasty backdoor.
Cryptographic Engine csvc.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
csvdea csvdea.exe
U
Added by the Spyware.SpyArsenalLog surveillance software. This program should be uninstalled if it was not installed by yourself. ... Read More
csvhost.exe csvhost.exe
X
Added by the Troj/Cimuz-BD Trojan.
System csvyj.exe
X
Added by the Troj/Agent-DJT Trojan.
CompuSpy KeyLogger cswin2008.exe
U
Added by the Spyware.CompuSpy surveillance software. Spyware.CompuSpy is a spyware program that attempts to record keystrokes on the computer. If this ... Read More
cswiz cswiz.dll
X
Added by the Troj/Opnis-E Trojan.
netservices csxrs.exe
X
Added by a variant of the W32/SDBOT WORM! ... Read More
System time updator CSysTime.exe
X
Added by the RANDEX.S WORM!
checktime ct.exe
U
Related to the HP Select software on HP computers.
ct ct.exe
Y
ct.exe is a file is for the HP Learning Adventure software and if you use this software it is required to run it ... Read More
AsioThk32Reg CTASIO.DLL
U
ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this ... Read More
CTAVTray CTAvTray.exe
N
For Creative Soundblaster Live! series soundcards. Plays the EAX animation on start-up and adds a System Tray icon for it. Available via AudioHQ ... Read More
ClickTheButton CTB.EXE
X
ClickTheButton Downloader-MY adware
gfxtray ctccw32.dll
X
Added by the Troj/Clicker-EC Trojan. Do not delete C:\Windows\System32\rundll32.exe as it is a legitimate file. ... Read More
CTCMonitor CTCMonitor.exe
U
Click-to-Convert - document-to-HTML or doc-to-PDF converter. Only required if you are going to use the File -> Print method of using Click-to-Conver ... Read More
Creative MediaSource Go CTCMSGo.exe
N
"Creative MediaSource playbacks music in DVD-Audio, MP3, WMA, WAV and other media formats" ... Read More
CTDVDDet CTDetect.exe
N
Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource ... Read More
CTDVDDet CTDVDDet.exe
N
Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource ... Read More
CTStartup CTEaxSpl.exe
N
Splash screen with sound on every boot up. Installed with a Sound Blaster Audigy soundcard ... Read More
WINDOWS SYSTEM ctech.exe
X
Added by the W32/Mytob-KD mass-mailing worm and IRC backdoor. W32/Mytob-KD is capable of spreading through email and through various operating system ... Read More
{9B71D88C-C598-4935-C5D1-43AA4DB90836} ctf.exe
X
Identified as a variant of the Backdoor.Bifrose backdoor Trojan.
ctf.exe ctf.exe
X
Identified as a variant of the Backdoor.Bifrose backdoor Trojan.
Windows Firewall Updater ctfcom.exe
X
Added by the W32/Rbot-GCB worm and IRC backdoor.
ctflog manager ctflog.exe
X
Added by the Trojan.Spexta trojan. When infected your computer will become an open mail relay which will allow your computer to be used to send out s ... Read More
CTFM0N.exe CTFM0N.exe
X
Added by the Trojan.StartPage.P browser hijacker.
Windows Update Firewall System ctfm0Unz.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
PHIME2004C CTFMDN.exe
X
Added by the Troj/Dloadr-AMV Trojan.
ctfmgr ctfmgr.exe
X
Added by the Troj/PWS-ATU password-stealing Trojan.
Windows Update Firewall System ctfmom.exe
X
Added by the W32.Spybot.ANDM worm. W32.Spybot.ANDM is a worm that spreads through mIRC and to network shares protected by weak passwords. It also spre ... Read More
ctfmon.exe ctfmon.exe
U
CTFMon is involved with the language/alternative input services in Office XP. CTFMON.exe will continue to put itself back into MSConfig when you run t ... Read More
ctfmon ctfmon.exe
X
Added by the Troj/SDBot-06 backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execu ... Read More
ctfmon.exe ctfmon.exe
X
Added by the PWSteal.Raidys password-stealing trojan horse.
Alternative User Input Services ctfmon.exe
X
Identified as the Tilebot-JR worm and IRC backdoor. This infection should not be confused with the legitimate C:\Windows\System32\ctfmon.exe file. ... Read More
Windows CTF Loader ctfmon.exe
X
Added by the W32/Sdbot-DFS network worm and IRC backdoor. This infection should not be confused with the legitimate C:\Windows\System32\ctfmon.exe. ... Read More
ntuser ctfmon.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Agent variant malware.
Task Scheduler ctfmon.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Agent variant malware.
LPTRDC server ctfmon.exe
X
Identified as a variant of the TrojanDownloader:Win32/Fourta.A malware. This infection should not be confused with the legitimate C:\Windows\System32 ... Read More
ctfnnon ctfmon.exe
X
Identified as a variant of the Backdoor.Win32.Turkojan.ake malware. Please note that C:\Windows\System32\ctfmon.exe is legitimate and should not be d ... Read More
Windows Live Messenger 8.12 ctfmon.exe
X
Added by the W32/LiPark-A worm. This infection should not be confused with the legitimate C:\Windows\System32\ctfmon.exe file. ... Read More
ctfmon16c ctfmon16c.exe
X
Added by the W32/Sharp-C mass-mailing worm.
Ctfmon.exe ctfmon32.exe
X
CoolWebSearch parasite related - hijacking to Slawsearch.com
ctfmon32 CTFMON32.EXE
X
CoolWebSearch parasite related - also detected as the TROJ/CWS-E TROJAN! ... Read More
User Input Services CTFMON32.EXE
X
Added by the TROJ_MANCSYN.AK Trojan.
Windows svchost ctfmon32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Services M7 ctfmon32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
ctfmona ctfmona.exe
X
Identified as a variant of the W32/Smalltroj.CJDX malware.
CTFMONSS CTFMONSS.EXE
X
Added by the Troj/CWS-F hijacker. This infection will also install a Browser Helper Object with the filename WTLBASS32.DLL or SEHLP.DLL. ... Read More
Windows Update Firewall System ctfmoom.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MSN ctfmoons.exe
X
Added by the SPYBOT.HI WORM!
ntuser ctfmun.exe
X
Identified as a variant of the Trojan-Dropper.Agent.snu malware.
Task Scheduler ctfmun.exe
X
Identified as a variant of the Trojan-Dropper.Agent.snu malware.
Windows modez Verifier ctfn0n3z.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Win Updator Services ctfnom.exe
X
Added by a variant of the W32/WOOTBOT WORM!
twin ctfnom.exe
X
Added by the W32.Ogleon.A worm. W32.Ogleon.A is a worm that spreads through removable storage devices. It also drops a copy of Infostealer.Gampass, on ... Read More
ctfmom ctfnom.exe
X
Added by the Troj/Bckdr-QTA backdoor Trojan.
Windows Services Layer ctfnon.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
<not used> ctftpscr32.exe
X
Added by the Troj/Agent-FPN Trojan.
cthelp cthelp.exe
X
Added by the SDBOT TROJAN! ... Read More
CTHELPER CTHELPER.EXE
U
CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in ... Read More
WINDVDpatch CTHELPER.EXE
U
CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in ... Read More
CTHelper cthelper.exe
X
Added by a WORM, W32/Rbot-XB, and found in the Windows system folder.
Win32 FireWire Driver CTHELPER32.EXE
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
{b59f3ba4-98da-4b5f-8a2d-7b56fb11140b} cthkpcv.dll
X
A Trojan used by the rogue anti-spyware program AntiVermins. This Trojan, when installed, will display fake security alerts on your taskbar and instal ... Read More
CTin10 CTin10.exe
X
Added by the BANCOS.E TROJAN!
Creative Launcher CTLauncher.exe
N
For Creative Soundblaster Live! series soundcards. Adds a quick-launch bar to the top of the display and a System Tray icon. Available via Start -> Pr ... Read More
ctlsys ctlsys.dll
X
Added by a variant of the Goldun.Fam Trojan.
TaskBar CTLTask.exe
N
Creative SoundBlaster Audigy Taskbar - used to choose between different types of EAX Effects, not required in startup. NOTE: if you get a ctltask.exe ... Read More
Tasktray CTLTray.exe
N
Installed with the Sound Blaster Audigy range of soundcards. Allows you to set EAX effects or equalizer settings for the Sound Blaster Audigy from a s ... Read More
ctl_w32 ctl_w32.sys
X
Identified as a variant of the Rootkit.Win32.Agent.pq rootkit.
CreativeMixer CTMIX32.EXE
U
Creative soundcard System Tray access to, for example, volume slider controls as normally provided by the "speaker" icon. Not required unless you adju ... Read More
cmsettings ctmn.exe
U
Part of NetNanny Chat_Monitor ... Read More
NOMAD Detector ctmnrun.exe
U
Detects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use ... Read More
CtModule CtModule.exe
X
Added by the Troj/Clicker-EG Trojan.
svcshare CTMONTv.exe
X
Added by the W32/Fujacks-AJ removable storage device worm.
ctnmrun ctnmrun.exe
U
Detects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use ... Read More
nomad detector ctnmrun.exe
U
Detects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use ... Read More
CreativeDiscNotifier CTNOTIFY.EXE
N
For Creative Soundblaster Live! series soundcards. Detects when you insert a CD-ROM, DVD-ROM, etc. Available via Start -> Settings -> Control Panel ... Read More
Disc Detector CtNotify.exe
N
For Creative sound cards. Detects when you insert a CD, DVD, etc
[Various Names] CToolBar.exe
X
Part of the Wareout infection as described here. This infection is not the same as the legitimate Internet Explorer Toolbar called Crawler Toolbar wh ... Read More
CTPDPSRV CTPDPSRV.EXE
?
Printer driver (in the WINDOWS\System32\spool\DRIVERS\W32X86 folder). Is it required? ... Read More
pdp Server ctpdpsrvr.exe
U
Included and setup with the drivers for my Compaq A3000 all-in-one printer/scanner - maybe for networking. Works fine without it - but may be needed w ... Read More
ctpmon ctpmon.exe
X
Identified by BitDefender as Trojan.Agent.AIR. This infection will display alerts on your desktop stating The registry is corrupted. To help protect ... Read More
Microsoft task tray monitor ctray.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
CTRegRun CTRegRun.exe
N
For Creative Soundblaster Live! series soundcards. Reminds you to register your card with Creative ... Read More
CtrlVol CtrlVol.exe
U
Acer's on screen volume control using the Fn key
ctrmode ctrmode.exe
X
A variant of the Win32/IRCBot.AAB variant family of worms and IRC backdoor Trojans. ... Read More
Speed racer CTSRReg.exe
N
Software for a Creative sound card
Event Locator ctst.exe
X
Added as a service by the W32/Forbot-DJ WORM!
CT Control Settings CTSVCCD.EXE
X
Added by a variant of the WIN32.RBOT WORM!
Creative Service for CDROM Access Ctsvccda.exe
N
Resident program for Creative's PlayCenter included with Soundblaster Audigy sound cards - speeds up detection of some media CDs if the system doesn't ... Read More
CTsysVol CTSYSVOL.exe
U
Creative sound card volume controls
cttdpsrv cttdpsrv.exe
?
??
CTUpdate ctupdclt.exe
X
Added by the W32/Rbot-ABG. This infection tries to delete the I$ network shares on the host computer every 2 minutes. ... Read More
Windows Tracking Client ctwsvc.exe
X
Added by the Troj/Agent-GMB Trojan.
ctxfihlp CTXFIHLP.EXE
N
Added by the installation of a Creative Labs X-Fi sound card. This particular process provides the help functionality for your card. Note: located in ... Read More
CTZDetec.exe CTZDetec.exe
N
Auto-detect and play a DVD when using a Creative Soundblaster card.
CleanUp Antivirus CU345d.exe
X
Added by the Cleanup Antivirus rogue anti-spyware program.
cuagentExe Cuagent.exe
Y
Command Antivirus related
[not used] CulaterLoader.exe
X
Added by the Spyware.Mom spyware.
cuo cuo.exe
X
Added by the BUGBEAR.A WORM!
Start CurePCSolution.exe CurePCSolution.exe
X
A rogue anti-spyware product that uses false positives, misleading reports, and deceptive advertising in order to scare you into purchasing the full v ... Read More
CursorXP CursorXP.exe
N
CursorXP from Stardock - tool for creating mouse cursors
Client Update Service for Novell cusrvc.exe
Y
Part of the Novell Client for Windows and is used to keep the client up to date. It has a service name of cusrvc and is found in the Windows system f ... Read More
System Monitoring cute.exe
X
Added by the W32.Rahiwi.A. W32.Rahiwi.A is a worm that spreads by copying itself to the root of all drives, including removable and shared drives. ... Read More
CuteMX CuteMX.EXE
N
File sharing utility
Windows Update cutix.exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Agent cvchost.exe
X
Added by the W32/Sdbot-DFH worm and IRC backdoor.
XPSoft CVDAsDW.exe
X
Added by the SDBOT-SY WORM!
go cvir.exe
X
Added by the W32/Silov-A overwriting virus. W32/Silov-A overwrites all files in the current and root drive folders with a copy of itself, adding the f ... Read More
Volume Shadow Installer cvisvc.exe
X
Unknown malware.
cvmonitor.exe cvmonitor.exe
X
Added by the SDBOT.BV WORM!
{fe288882-f661-4522-88f3-20cfb7866fa4} cvnzie.dll
X
A Trojan used by the rogue anti-spyware program AntiVermins. This Trojan, when installed, will display fake security alerts on your taskbar and instal ... Read More
CVPND cvpnd.exe
Y
Sub-system used by Cisco VPN client for making a connection to a remote IPSec server ... Read More
Windows media services cvrsss.exe
X
Added by the RBOT-MW WORM!
Startup Update Cvshost.exe
X
Added by the GAOBOT.AO WORM!
smr cvshost.exe
U
Added by the Spyware.SilentMonitor surveillance software. This software should be uninstalled if found on your computer without your knowledge. ... Read More
MSN Manager cvss.exe
X
Added by a variant of the SPYBOT WORM!
Control Task Manager cvsys.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Bron-Spizaetus CVT.exe
X
Added by the W32.Rontokbro@mm mass-mailing worm.
SystemGent CVT.exe
X
Added by the W32/Brontok-H worm.
CWatch cw.exe
U
ChatWatch - chat monitoring tool
cw cw4.exe
U
See Here ... Read More
client access api daemon cwbappcd.exe
U
IBM iSeries Client Access, see here ... Read More
Client Access Check Version cwbckver.exe
N
Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks th ... Read More
cwbckver cwbckver.exe
N
Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks th ... Read More
Client Access Help Update cwbinhlp.exe
N
Client Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and ... Read More
cwbinhlp cwbinhlp.exe
N
Client Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and ... Read More
Client Access Service CwbSvStr.Exe
N
Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if ... Read More
cwbsvstr cwbsvstr.exe
N
Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if ... Read More
client access taskbar cwbuitsk.exe
U
IBM iSeries Client Access taskbar, see here.
Client Access Express Welcome cwbwlwiz.exe
?
Welcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to ... Read More
cwbwlwiz cwbwlwiz.exe
?
Welcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to ... Read More
Cwcdschk.exe Cwcdschk.exe
?
IBM Thinkpad related?
cwcptray cwcptray.exe
U
Related to ContentWatch Parental Control Internet Filter.
Crystal 3D Audio Control CWD3DSND.EXE
?
Crystal 3D Audio sound driver. Is it required?
evacuative cwegus.dll
X
Zlob Trojan which installs the AntivirusTrigger rogue anti-spyware program. This program displays fake security alerts stating that your computer has ... Read More
{2acf3add-34a1-4f2f-99cf-cc69785d1e90} cwgppb.dll
X
A Trojan used by the rogue anti-spyware program AntiVermeans. This Trojan, when installed, will display fake security alerts on your taskbar and insta ... Read More
Coolwallpaper cwm_tray.exe
N
Cool Wallpaper software allows you to manage high quality photos as desktop wallpaper and screen savers ... Read More
cwriter cwriter.exe
X
Added by the PcRaiser rogue security program. PcRaiser is a misleading application that claims to improve the performance of a computer. This executa ... Read More
cwupdate cwupdate.exe
U
ContentProtect, from ContentWatch - internet filter
altigraph cxbrk.dll
X
Zlob Trojan which installs the AntiSpyCheck rogue anti-spyware program. This program displays fake security alerts stating that your computer has a s ... Read More
Zstart.lnk cxdxregt.exe
X
Added by the Adware.ZenoSearch adware.
zstart cxdxregt.exe
X
ZenoSearch adware component ... Read More
CxEvtSvc CxEvtSvc.exe
X
Identified as a variant of the TrojanSpy:Win32/Festeal malware.
KV_HOST cxjx.exe
X
Added by the Troj/LegMir-BB Trojan with password-stealing functionality.
*microsoft update cxma.exe
X
Added by the W32.HLLW.STMU TROJAN! ... Read More
{BC0CFA58-3A6F-51ba-9EFE-B320F4F621BA} cxscheca001.dll
X
Added by the Troj/PWS-AMU password-stealing Trojan.
autoloaderaproposclient cxtpls_loader.exe
X
AproposMedia adware ... Read More
C2K Cyb10.exe
U
Added by the CyberSitter surveillance software. CyberSitter is a Parental Control application that allows a user to monitor system activity on the com ... Read More
C2K CYB2K.EXE
U
CYBERsitter 2000 or 2001 -  anti-porn filter primarily. Required if you want the sites you visit filtered without having to load the software every ti ... Read More
Cyber cyberchk.exe
N
Part of Belkins "Multimedia Cleaning Kit" and is automatically installed when you run their optical disk drive cleaning utility - to remind you to c ... Read More
Microsoft Passport Network CyberShots cybershots.exe
X
Added by the W32/Spybot-ND worm and IRC backdoor. W32/Spybot-ND spreads to other network computers by exploiting common buffer overflow vulnerabilitie ... Read More
CyberWolf CyberWolf.exe
X
Added by the KICKIN.A (or CYDOG.C) WORM!
Microsoft Agent cychost.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojan
Dos Prompt Loader cygwin.exe
X
Added by W32/Sdbot-VV, A WORM/backdoor, and found in the Windows system folder.
cyg_win cygwin.exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
rdshost cymdda.dll
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
CyphTray CyphTray.exe
N
Cypherus - encryption software
WindowsSysBoot cytob.exe
X
Added by the W32/Tilebot-AY worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
run= cyxid98.exe
X
Unidentified malware
czaq czaqi.sys
X
Added by the Troj/QQHelp-Gen downloader Trojan.
ASDPLUGIN czech.exe
X
AsdPlug premium rate adult content dialer variant
Windows Service Agent czf.exe
X
Added by the W32/Rbot-GAJ worm and IRC backdoor.
Counterstrike Service Agent czrzns.exe
X
A variant of the Spybot family of worms and IRC backdoor Trojans.
Szservice czsrv.exe
X
A variant of the Backdoor.Win32.SdBot.bhk family of worms and IRC backdoor Trojans. ... Read More
<not used> czvhost.exe
X
Identified as Backdoor.IRC.Zapchast.
{0e4e5110-a772-4c4a-a7dc-137fe10abd6e} czxtyx.dll
X
Part of the Zlob trojan that displays fake security alerts for the rogue anti-spyware program called SpywareLocked. ... Read More
httpd c_pan.exe
X
Added by a variant of the DELF-A TROJAN!
{C536ECD6-4AE9-5C39-E359-F046B948DA4E} mstscmles.exe
X
Added by the Troj/Keylog-LA Trojan.

Please note that this infection is an Alternate Data Stream file attached to the legitimate C:\Window ... Read More
Total PC Defender Total PC Defender.exe
X
Added by the Total PC Defender rogue anti-spyware program.
WinAntiSpyware 2006 Scanner was6.exe
X
Added by the WinAntiSpyware rogue antispyware program.


> Status Key
Each entry in the database will have a Status assigned to it. The key to this status is the following:
  • Y - This status flag means that this entry should be left alone and be allowed to run as if it is unchecked it may break the functionality or use of a particular program.
  • N - This status flag means it is unnecessary to run this program automatically when Windows starts as you can run it manually when necessary.
  • U - This status flag means it is up to you whether or not you feel this program needs to run automatically.
  • X - This status flags means the item should definitely not start up automatically. Items that have this flag are generally malware such as viruses, trojans, hijackers, spyware but could also be programs that are not desirable to run on your computer.
  • ? - This status flag means the status of this entry is unknown at this time and more research is necessary.
If you require assistance in removing one of these files you can ask us in the Startup Database Forum.

> Disclaimer
It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. BleepingComputer.com will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.


Advertise   |   About Us   |   Terms of Use   |   Privacy Policy   |   Contact Us   |   Site Map   |   Chat   |   Tutorials   |   Uninstall List
Discussion Forums   |   The Computer Glossary   |   Resources   |   RSS Feeds   |   Startups   |   The File Database   |   Virus Removal Guides


Portions of this database © Paul Collins
© 2003-2010 All Rights Reserved Bleeping Computer LLC.
PGT: 0.36545 Queries: 5