| Name | Status | Filename | Description |
|---|
| C-DillaCdaC11BA | O | CDAC11BA.EXE | copy protection software |
| C-DillaSrv | L | CDANTSRV.EXE | C-Dilla License Management software from MacroVison |
| CA ISafe | L | isafe.exe | Related to Computer Associates virus software. |
| CA License Client (CA_LIC_CLNT) | L | lic98rmt.exe | Computer Associates |
| CA License Server (CA_LIC_SRVR) | L | lic98rmtd.exe | Computer associates |
| CA Pest Patrol Realtime Protection Service (ITMRTSVC) | L | ITMRTSVC.exe | Related to CA_Pest_Patrol Realtime Protection Service Note: Located in C:\Program Files\CA\PPRT\bin\ |
| CaCCProvSP | L | ccprovsp.exe | Related to eTrust_Internet_Security_Suite from
Computer Associates International Inc. Note: Located in C:\Program Files\CA\eTrust Internet Security Suite\ |
| CachemanXP (CachemanXPService) | L | CachemanXP.exe | CachemanXP Memory Manager |
| CAILI | L | caili.exe | related to CarryIco Software, installed by a flash card reader driver setup utility. |
| CAISafe | L | ISafe.exe | Part of eTrust EZ Antivirus |
| CamMonitor (uCamMonitor) | L | uCamMonitor.exe | Related to Cam_Monitor from Arcsoft Inc. Note: Located in \%Program Files%\ArcSoft\Magic-i Visual Effects\ |
| CanerServer | X | caner.exe | Troj/Hupigon-ES |
| Canon BJ Memory Card Manager (Bjmcmng) | L | Bjmcmng.exe | Canon Bubblejet Memory Card Utility |
| Canon Camera Access Library 8 (CCALib8) | L | CALMAIN.exe | Canon digital camera software that provides additional configuration options for the devices. |
| Canon Driver Information Assist Service | L | CnxDIAS.exe | CANON
Driver Information Assist Core Module. This file should be found in the Program Files\Canon\DIAS folder. |
Canon PIXMA iP6000D Memory Card Manager (PDUiP6000DMemCrdMgr) | L | PDUiP6000DMemCrdMgr.exe | Related to Canon PIXMA iP6000D Bubble Jet printer |
| Capture Device Service | L | DevSvc.exe | Related to Capture_Device InterVideo Service. Note: Located in C:\Program Files\Common Files\InterVideo\ |
| Capture Service (CaptureService) | L | CaptureService.exe | Related to Impact_360 from Witness Systems, Inc. Workforce management. Note: Located in C:\WINDOWS\system32\DirectX\ |
| Carbon Copy Scheduler (CarbonCopyScheduler) | L | schdsrvc.exe | Related to Alteris services. http://www.altiris.com |
| CarboniteService | L | carboniteservice.exe | Related to Carbonite_online_backup automatically backs up all the the files on your computer. |
| Card Adapter (NETDown) | X | smss.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This is not the legitimate Windows Process smss.exe. (Which is found in the System32 folder.) This worm/trojan file (smss.exe) is found in the Windows or Winnt folder. |
| CaReTaKeR-CT NetMgr 1.2.1 (sfmgr) | L | sfmgr.exe | Related to Brazil_r/s_CaReTaKeR-CT NetMgr. Brazil r/s is the industry standard for high-end quality, flexibility, reliability, and artist-friendly workflow in 3ds Max. Note: Located in \%ROOT%\sfmgr\ |
| CbEvtSvc | X | CbEvtSvc.exe | Identified by Kaspersky as a variant of the Trojan-Downloader.Win32.Agent.jhj Trojan. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| ccEvtMgr | L | ccSvcHst.exe | Related to LiveUpdate_Notice_Service from Symantec |
| CcEvtSvc | X | CcEvtSvc.exe | Identified by Kaspersky as a variant of the Trojan.Win32.Agent.elr malware. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| ccSetMgr | L | ccSvcHst.exe | Related to LiveUpdate_Notice_Service from Symantec |
| CD-ROM drive | X | Qtime.exe | Identified by Kaspersky as a variant of the Backdoor.Win32.SdBot.aad worm and IRC backdoor. Note: located in \%WINDIR%\ Note: Use SDFix under supervision. |
| cdmonsvc32 | X | cmmonsvc32.exe | Worm.Opanki_Variant.Process Note: Located in %windir% |
| Cdsys (Cdsys) | X | cdcd.sys | Added by the Troj/Agent-IA
TROJAN!
Note: This trojan file is found in the System32 folder.
|
CE-Infosys Security System (CE-Infosys Security Service) | ? | ceisvc.exe | Seems to be legit, belongs to this company Ce-infosys_suite
It will be left as unknown until more is found out about the company. |
| CeEPwrSvc | L | CeEPwrSvc.exe | Related to TOSHIBA and COMPAL ELECTRONIC INC. |
| CelInDrv | X | CelInDriver.sys | Win32/Agent.ABF Note:Located in %system% Read the link, collects sensitive information |
| CentennialClientAgent | L | CAgent32.exe | Related to Centennial UK Limited - http://www.centennial.co.uk/ |
| CentennialIPTransferAgent | L | xferwan.exe | Related to Centennial UK Limited - http://www.centennial.co.uk/ |
| Cepstral License Server | L | CepstralLicSrv.exe | Related to Cepstral_License Server from Sepstral, LLC Note: Located in \%Program Files%\Cepstral\bin\ |
| Certificate Propagation (CertPropSvc) | L | svchost.exe -k netsvcs | Part of Windows Vista
Note:Located in C:\%WINDIR%\System32 |
| CesarFTP FTP Server (CesarFTP) | L | server.exe | Related to CesarFTP from ACLogic. FTP server. Note: Located in \%Program Files%\CesarFTP\ |
| cFosSpeed System Service (cFosSpeedS) | L | spd.exe | cFos_Software
Internet acceleration program related. Note: May be necessary for the software to work properly.
|
| change me please (VIRUS) | X | sysdat.exe | Added by the W32/Tilebot-L
WORM!
|
| Changed me (Patch) | X | systemz32.exe | W32/Tilebot-JD Read the link, allows remote access and uses rootkit stealth |
| ChanService (ChanSirv) | X | 2pack.exe | Identified as a variant of Backdoor.Win32.SpyBoter.fb Note: located in \%WINDIR%\ |
| Charter High-Speed Security Suite | O | SERVIC~1.EXE | Related to F-Secure, Backweb application |
| chckntfs | X | chckntfs.exe | Added by the W32/Tilebot-EF WORM! Note: This worm\trojan is located in C:\%WINDIR%\ |
| Check Point SecuRemote Service (SR_Service) | L | SR_Service.exe | Related to Check_Point_Software Technologies Note: Located in C:\Program Files\CheckPoint\ |
| Check Point SecuRemote WatchDog (SR_WatchDog) | L | SR_WatchDog.exe | Related to Check_Point Software Technologies Note: Located in C:\Program Files\CheckPoint\SecuRemote\bin\
|
| Check Point SSL Network Extender (cpextender) | L | slimsvc.exe | Related to SSL_Network_Extender from Check Point Tech. Note: Located in \%Program Files%\CheckPoint\SSL Network Extender\ |
| chkext(chkext) (chkext) | X | chkext.exe | Added by the W32/Sdbot-CRW WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Chong3 Me (MlCR0SOFTS UPDATE) | X | N0RTAN.EXE | Added by the SDBOT.CNM
WORM!
Read the link, rootkit type stealth involved.
|
| Chong3 Me (MlCR0SOFTS UPDATEe) | X | lexplarer.exe | Added by the SDBOT.CWB
WORM!
Read the link, rootkit type stealth involved.
|
| cics.REGION1 | L | cicssvc.exe | Related to IBM Corp. |
| cics.REGION2 | L | cicssvc.exe | Related to IBM Corp. |
| cicssfs.SCMMC223 | L | cicssfssvc.exe | Related to IBM Corp. |
| cidaemon | L | .exe | Microsoft Indexing Service filter daemon |
| cidaemon | L | cidaemon.exe | Microsoft Indexing Service filter daemon |
| Cisco Configuration Service (CCS) | L | ccs.exe | Related to Related to Cisco_Systems Note: Located in C:\WINDOWS\system32\ |
| Cisco Systems, Inc. STC Agent (STCAgent) | L | agent.exe | Related to Cisco Systems inc. SSL VPN Client, Note: located in C:\Program Files\Cisco Systems\SSL VPN Client\ |
| Cisco Systems, Inc. VPN Service (CVPND) | L | cvpnd.exe | part of Cisco VPN |
| Citrix CPU Utilization Mgmt/CPU Rebalancer (CTXCPUBal) | L | ctxcpubal.exe | Related to Citrix MetaFrame |
| Citrix CPU Utilization Mgmt/Resource Mgmt (ctxcpuSched) | L | ctxcpusched.exe | Related to Citrix MetaFrame |
Citrix CPU Utilization Mgmt/User-Session Sync (CTXCPUUsync) | L | ctxcpuusync.exe | Related to Citrix MetaFrame |
| Citrix Print Manager Service (cpsvc) | L | CpSvc.exe | Related to Citrix MetaFrame, control Printer Management. |
| Citrix SMA Service | L | SmaService.exe | Related to Citrix MetaFrame |
| Citrix Virtual Memory Optimization | L | CtxSFOSvc.exe | Related to Citrix MetaFrame, Monitors all DLLs on a server to find where collisions are occurring |
| Citrix WMI Service (CitrixWMIService) | L | ctxwmisvc.exe | Related to Citrix MetaFrame |
| Citrix XML Service (CtxHttp) | L | ctxxmlss.exe | Related to Citrix MetaFrame |
| Citrix XTE Server (CitrixXTEServer) | L | XTE.exe | Related to Citrix MetaFrame |
| CL500_510 Remote Server | L | KaNTSRV.exe | Related to Panasocic_Color_Laser_Printer server. Note: Located in C:\PROGRAM FILES\PANASONIC\REMOTE SERVER\ |
| Client Access Express Remote Command (Cwbrxd) | L | CWBRXD.EXE | Related to IBM Corporation. Note: Located in \%WINDIR%\ |
| Client Debug Manager | X | spoolvc.exe | W32/Sdbot-DCX Read the link, allows remote access |
| Client Disk Manager | X | symon.exe | Added by the W32/Tilebot-IN WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K) |
| Client IP-IPX | X | svchosts.exe | Added by a variant of the W32/SDBOT WORM! Note: Located in C:\%WINDIR%\System32\drivers\ (XP/WinNT/2K) |
| Client Network (CdmService) | L | cdmsvc.exe | Related to Citrix MetaFrame, maps client drives and peripherals for access in ICA sessions. |
| Client Security Agent Service (BNPagent) | L | bndaemon.exe | Related to Client_Security_Agent service from Bradford Networks. Note: Located in \%Program Files%\Bradford Networks\Client Security Agent\ |
| Client Server Runtime Proces | X | csrss.exe | Added by the WORM_SDBOT.BTI WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder. Malicious activities read the topic. Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) This worm\trojan file is found in the Windows or Winnt folder. |
| Client Server Runtime Process | L | csrss.exe | Microsoft Client Server Runtime Process
|
| Client Server Runtime Service (csrss32) | X | csr.exe | Added by the W32/Sdbot-AFM
WORM!
Note: This worm file is found in the Windows or Winnt folder. |
| Client Update Service for Novell | L | cusrvc.exe | Related to Novel server. |
| Client/Server Runtime Server Subsystem (CSRSS) | X | csrss.exe | W32/IRCBot-UN
Note: Located in %windir%, not to be confused with the legitimate file in %windir%\system32 (%windir%\system on windows 98/ME) Read the link, allows remote access and steals information |
| Client32 | L | client32.exe | NetSupport Manager by "NetSupport Ltd.". |
| Cliente de seguimiento de vinculos distribuidos | L | services.exe | Spanish Windows 2000 distributed links tracking client |
| Cliente DHCP | L | services.exe | Spanish Windows 2000 DHCP client |
| Cliente DNS | L | services.exe | Spanish Windows 2000 DNS client |
| Clients Server Runtime Process | X | csrss.exe | Added by the W32/Sdbot-CPF WORM! Note: This worm\trojan is located in C:\%WINDIR% This is not the legitimate Windows Process. (Which is found in the System32 folder.) |
| Clients Server Runtime Process (Windows Internet) | X | csrss.exe | Added by the W32/Sdbot-CPF WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder. |
| Clip Book | X | gezi-yasuo.exe | Troj/QQHelpe-CY
Note: Troj/QQHelpe-CY installs a number of files besides gezi-yasuo.exe in a few locations. Read the link |
| ClipBo0k | X | book.exe | Added by a variant of the BKDR_HUPIGON.EVG backdoor Trojan. Identified by Trend Micro. Note: Located in \%ROOT%\ |
| clmss (Content List Management Sub System) | X | clmss.exe | Added by the W32/Tilebot-AO
WORM!
Note: This worm file is found in the Windows or Winnt folder.
Read the link, rootkit type stealth involved.
|
| Clr_ui | L | atinpdxx.sys | Related to ATI Specialized PCD VBI Codec. Note: Located in \%WINDIR%\System32\drivers\ |
| CMG Shield (auet4iogie5an) | X | nvslzrygvb.exe | Added by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename. |
| CMG Shield (CMGShield) | L | Credant.exe | Related to CMG_Shield Application from Credant Technologies. CREDANT Mobile Guardian Enterprise Edition (CMG EE) is an integrated, policy-based mobile data security, Note: Located in \%WINDIR%\System32\ |
| CNG Key Isolation (KeyIso) | L | lsass.exe | Part of Windows Vista
Note:Located in C:\%WINDIR%\System32 |
| Cobian Backup 8 service (CobBMService) | L | cbService.exe | Related to Cobian_Backup An Open Source projects. Note: Located in C:\Program Files\Cobian Backup 8\ Note Open souce project can be modified. Make sure you scan the program with a Virus protection program before using. |
| Codec | X | WINCODEC.EXE | Added by the SDBOT.CJO
WORM!
Read the link, rootkit type stealth involved.
|
| COGECO Security Services (BackWeb Plug-in - 9867844) | O | SERVIC~1.EXE | Related to COGECO_F-Secure Backweb application. Note: Located in \%Program Files%\COGECO~1\backweb\9867844\Program\ |
| Cognos ReportNet | L | cogbootstrapservice.exe | Related to Cognos_ReportNet Business Intelligence software. Note: located in C:\Program Files\Cognos\crn\bin\ |
| Cognos ReportNet (ruzxj7ol3oeak) | X | bnoilfhxkgvz.exe | Added by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename. |
| ColdFusion Graphing Server | L | JRun.exe | Related to MacroMedia_ColdFusion
products. Made by MacroMedia,Inc.
|
ColdFusion Management Repository Server (ColdFusion Management Repository) | L | jrun.exe | Related to MacroMedia_ColdFusion
products. Made by MacroMedia,Inc. |
| ColdFusion Management Service | L | CANamingAdapter.exe | Related to MacroMedia_ColdFusion
products. Made by MacroMedia,Inc.
|
| ColdFusion Monitoring Service (ClusterCATS Service) | L | ccmgr.exe | Related to MacroMedia_ColdFusion
products. Made by MacroMedia,Inc. |
| ColdFusion MX 7 Search Server | L | k2admin.exe | Related to Cold_Fusion from Adobe Systems Incorporated. Note: Located in \%ROOT%\ |
| ColdFusion MX Application Server | L | jrunsvc.exe | Related to Macromedia Cold Fusion software. |
| ColdFusion MX ODBC Server | L | swstrtr.exe | Related to Macromedia Cold Fusion software. |
| Collaboration Runtime Service (xmppd-jse) | L | xmppd-jse.exe | Related to Sun_Java_Studio_Enterprise Software. Note: Located in \%Program Files%\Sun\jstudio_ent81\collab\bin\ |
| COM Host (comHost) | L | comHost.exe | Related to Norton/Symantec Internet Security |
| COM Message Transfer (mscommt) | X | svchost.exe -k mscommt | Added by the Troj/Dbit-A
TROJAN!
|
| COM+ Component Service (COMCSVC) | X | winmgnt.exe | Added by unknown malware, the file winmgnt.exe may be a Serv-U FTP server used to download other malicious files to your computer. File location is in the System32 folder. |
| COM+ Event System (EventSystem) | L | svchost.exe -k LocalService | Part of Windows Vista
Note:Located in C:\%WINDIR%\System32 |
| COM+ Interface (svcmngr) | X | svcgirl.exe | Added by an unknown malware. Note: This worm\trojan is located in C:\%WINDIR%\TEMP\ folder. |
| COM+ Messages | X | svchosts.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| COM+ System Application (COMSysApp) | L | dllhost.exe | Part of Windows Vista
Note:Located in C:\%WINDIR%\System32 |
| COM+ System Applications (COMSystemApp) | X | dllhost.exe | W32/SillyFDC-AV
Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (Vista/XP/WinNT/2K) Turns off anti-virus applications
and Steals information |
| COM+ System Client (ComSysCnt) | X | cmsvc.exe | Identified as the SdBot.bis worm Note: This worm is located in C:\WINDOWS\repair\ |
| COM+ System Service (COMSS) | X | SSMS.EXE | Added by unknown malware. File location is in the System32 folder. |
| COM+ System Service (DLLHOST) | X | dllhost.exe | Added by the Backdoor.Win32.SdBot.xd as identified by Kaspersky TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
|
| COM+ System Source (COMSysSRC) | X | vmnat.exe | W32/Tilebot-JE Note: Located in %windir%\system32 Read the link, allows remote access |
| Com4Qlb | L | Com4Qlb.exe | Related to HP_Compaq Buttons. Note: Located in \%Program Files%\Hewlett-Packard\HP Quick Launch Buttons\ |
| Command Lsass Services | X | svshost.exe | Added by a varian of the Backdoor.Sdbot family of trojan. Note: Located in \%WINDIR%\System32\ |
| Command Service (cmdService) | X | command.exe | Adware |
| CommServer | L | CommSvr.exe | Related to the HiPath 1220 digital PBX system from Siemens. For more information Click_Here
File location is in the Program Files\Siemens\HiPath 1220\CommServer2.0 folder.
|
| CommServer (audieqaad) | X | lmguc.exe | Added by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename. |
| Comodo Anti-Virus and Anti-Spyware Service | L | cavasm.exe | Related to Comodo Anti-Virus and Anti-Spyware Service Note: Located in \%Program Files%\Comodo\common\CAVASpy\ |
| Comodo Application Agent (CmdAgent) | L | cmdagent.exe | Related to Comodo_Firewall from Comodo. Note: Located in C:\Program Files\Comodo\Firewall\ |
| COMODO Firewall Pro Helper Service (cmdAgent) | L | cmdagent.exe | Comodo_Firewall |
| Compaq Advisor (Compaq_RBA) | L | compaq-rba.exe | Related to Compaq |
| Compaq DMI Web Agent | L | WebDmi.exe | Related to Compaq Computer. |
| Compaq Local Alerter | L | cpqalert.exe | Related to Compaq Computer. Allows for "fault, performance, and configuration management". Recommended for corporate users only. |
| Compaq Local Alerter (CPQALERT) | L | CPQAlert.exe | Related to compaq products |
| Compaq Presario SSH | X | cpsd.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This trojan is located in C:\Windows\System\dllcache (Win9x/Me), C:\%WINDIR%\System32\dllcache (XP/WinNT/2K) |
| Compaq Remote Diagnostics Enabling Agent | O | Cpqdfwag.exe | Related to Compaq diagnostics utility. |
| Computer Browser (Browser) | L | browser.dll | Part of Windows Vista
Note:Located in C:\%WINDIR%\System32 |
| Compuware Open Server | L | cwjboss.exe | Compuware Serversoftware |
| comrepl | X | comrepl32.exe | Added by the W32/Rbot-DNH WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder. |
| comrepl | X | comreplsvc.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder. |
| Config Loader | X | scvhost.exe | several Agobot variants |
| ConfigFree Service (CFSvcs) | L | CFSvcs.exe | Toshiba related |
| Configuration Loader (bF) | X | wincrt32.exe | Virus and Trojan tools.
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.JP&VSect=Sn |
| Configuration Loading | X | svchos1.exe | several Agobot variants |
| Connected Agent Service (AgentSrv) | L | AgentSrv.EXE | Related to Connected Corporation. - http://www.connected.com/ |
| Connected Launcher | L | CBlaunch.exe | Connected backup software |
| Connected RegCap | L | CBRegCap.EXE | Connected backup software |
| Connection Rese | X | webadmin.exe | W32/Forbot-FY adds this, with a display name of Website Administrator Info. |
| Content Index service | L | cisvc.exe | Microsoft Content Index service
|
| Content Monitoring Tool | L | msCMTSrvc.exe | Compaq CMTS |
| ContentProtect (CwCpSvc20) | L | cwsvc.exe | Related to ContentWatch Parental Control Internet Filter. |
| Contivity VPN Service | L | Extranet_serv.exe | Related to Novel server. |
| Contour Shuttle Device Engine (ShuttleEngine) | L | ShuttleEngine.exe | Related to Contou_Design
|
| Control Services | X | expl0rer.exe | Win-Trojan/BlackHole.125440 |
| Control Task Manager | X | cvsys.exe | Added by an unidentified TROJAN! Note: of the IRC/bot Family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| COSIDS_TB | L | TbMux32.exe | Related to http://www.transaction.de/ |
| coste | O | martinr.coste@neuf.fr | antivirus |
| CounterSpyAgent | L | SBCSESvc.exe | Related to CounterSpyAgent From Sunbelt Software. Note: Located in \%Program Files%\System32\Sunbelt Software\CounterSpy\Agent\ |
Cox High Speed Internet Security Suite System Service (AuthSysSvc) | L | SysSvcNt.exe | Related to Cox High Speed Internet Security Suite System Service. Note: Located in C:\Program Files\Cox\Applications\app\ |
| cpanelx (Microsoft Control Panel) | X | cpanelx.exe | Added by a variant of the W32/SDBOT
WORM!
Note: This worm file is found in the Windows or Winnt folder.
|
| cpqdmi | L | cpqdmi.exe | Compaq version of the Desktop Management Interface |
| CPUCooLServer Service (CPUCooLServer) | L | CooLSrv.exe | Part of CPUCooL |
| CQG Installation Service | L | cqginsts.exe | Related to CQG, Inc. CQG provides extensive historical data online for charting and technical analysis. |
| crauto | L | crauto.exe | Background task of the Paragon Encrypted Disk software which enables you to have encrypted virtual hard disks to store sensitive data.
(answers that work) |
| Creative ALchemy AL1 Licensing Service | L | AL1Licensing.exe | Related to Creative_ALchemy EAX® and 3D Audio restoration in Windows Vista. Note: Located in \%Program Files%\Common Files\Creative Labs Shared\Service\ |
| Creative Audio Pack Licensing Service | L | APLicensing.exe | Related to Creative_Audio_Pack Licensing Service. Note: Located in \%Program Files%\Common Files\Creative Labs Shared\Service\ |
| Creative Labs Licensing (udavaaelyeev) | X | wbtqacmhmbv.exe | Added by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename. |
| Creative Labs Licensing Service | L | CreativeLicensing.exe | Related to Creative Labs Licensing Service. Note: located in C:\Program Files\Common Files\Creative Labs Shared\Service\ |
| Creative Service for CDROM Access | L | CTsvcCDA.exe | Creative Service for CDROM Access |
| crss32.exe | X | crss32.exe | Added by the W32/Tilebot-GT WORM! Note: This worm\trojan is located in C:\%WINDIR% |
| Crypkey License | L | crypserv.exe | CrypKey Software Licensing System from Cobalt Systems |
| Cryptainer service (ssoftservice) | L | ssoftsrv.exe | Owner:Cypherix Cypherix Encryption Software |
| Cryptic Protected Storage (CryptProtectedService) | X | cpstorage.exe | Added by the W32/Tilebot-HO WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Cryptographic Engine (EngSvc) | X | csvc.exe | Added by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Cryptographic Services (CryptSvc) | L | svchost.exe -k NetworkService | Part of Windows Vista
Note:Located in C:\%WINDIR%\System32 |
| Crystal APS (CrystalAPS) | L | CrystalAPS.exe | Related to Crystal_APS Now owned by Business Objects. Note: Located in C:\Program Files\Seagate Software\Enterprise\x86\ |
| Crystal Cache Server (CacheServer) | L | cacheserver.exe | Crystal_Decisions_Cache_Server Now owned by Business Objects |
| Crystal Event Server | L | EventServer.exe | Crystal Decisions Event Server |
Crystal Input File Repository Server (CrystalInputFileServer) | L | inputfileserver.exe | Crystal_Decisions_File_Repository_Server Now owned by Business Objects. |
| Crystal Management Server | L | CrystalMS.exe | Crystal Decisions Management Server |
Crystal Output File Repository Server (CrystalOutputFileServer) | L | outputfileserver.exe | Crystal_Decisions_Output_File_Repository_Server Now owned by Business Objects |
| Crystal Program Job Server | L | ProgramServer.exe | Crystal Decisions Job Server |
| Crystal Report Application Server | L | crystalras.exe | Crystal Decisions Report Application Server |
| Crystal Report Job Server (JobServer_Report) | L | JobServer.exe | Crystal_Decisions_Report_Job_Server Now owned by Business Objects |
| Crystal Web Component Server (WebCompServer) | L | WebCompServer.exe | Related to Crystal Decisions Enterprise software. Now owned by Business_Objects Note: Located in C:\Program Files\Seagate Software\WCS\ |
| CsdDriver | X | CsdDriver.sys | Troj/Goldun-EE |
| CSNetManagerXp | X | isass.exe | W32/SillyFDC-AJ Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| CT Device Query service (CTDevice_Srv) | L | CTDevSrv.exe | Related to CT_Device_Query Service from Creative Technology Ltd. Note: Located in \%Program Files%\Creative\Shared Files\ |
| CTI Central Management | X | cti.exe | Lowers IE security settings |
| Curtains for Windows System Service (CurtainsSysSvc) | L | CurtainsSysSvcNt.exe | Related to Authentium, Inc.
http://www.authentium.com/ |
| CVSNT 2.5.01.1927 Dispatch service (cvsnt) | L | cvsservice.exe | Related to CVS_on_NT service Machines. From March Hare Software. Note: Located in C:\Program Files\CVSNT\ |
| CVSNT 2.5.01.1927 locking service (cvslock) | L | cvslock.exe | Related to CVS_on_NT service Machines. From March Hare Software. Note: Located in C:\Program Files\CVSNT\ |
| CWAFAdminController | L | CWAFAdminController.exe | Compuware Seversoftware |
| CWAFAdminMonitor | L | CWAFAdminMonitor.exe | Compuware Serversoftware |
| CWAFEventRouter | L | cwafservice.exe | Compuware Serversoftware |
| CWAFNotesService | L | CWAFNotesService.exe | Compuware Serversoftware |
| CWAFReportScheduler | L | CWAFSchedService.exe | Compuware Serversoftware |
| CWAFRmiRegistry | L | CWAFRmiRegistry.exe | Compuware Serversoftware |
| CWShredder Service | L | CWShredder.exe | CWShredder tool from Trend Micro. |
| CxEvtSvc | X | CxEvtSvc.exe | Identified as a variant of the TrojanSpy:Win32/Festeal malware Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| CXPT_Service | L | wcservice.exe | Related to Internet_Security Suite from COSMI Corp. |
| CyberArmor Run Service | L | casvc.exe | CyberArmor an Enterprise Class Personal Firewall |
| Cyberhawk | L | CHService.exe | Related to Cyberhawk from Novatix, Protects against Viruses, Spyware, Identity Theft. Note: Located in C:\Program Files\Novatix\Cyberhawk\ |
| CyberLink Background Capture Service (CBCS) (CLCapSvc) | L | CLCapSvc.exe | Related to CyberPower Systems, Inc. - http://www.powercinema.com/english/index.jsp |
| CyberLink Media Library Service | L | CLMLServer.exe | Related to CyberPower Systems, Inc. - http://www.powercinema.com/english/index.jsp |
| Cyberlink RichVideo Service(CRVS) (RichVideo) | L | RichVideo.exe | CyberLink RichVideo is an advanced technology designed to save precious video editing time. |
| CyberLink Task Scheduler (CTS) (CLSched) | L | CLSched.exe | Related to CyberPower Systems, Inc. - http://www.powercinema.com/english/index.jsp |
| CYGWIN cygserver (cygserver) | L | cygrunsrv.exe | Related to Cygwin_RedHat powerful tools to assist developers in migrating applications from UNIX®/Linux to the Microsoft® Windows®; platform. Note: located in C:\Apps\cygwin\bin\ |
| CypressLink | L | CypressLinkService.exe | Related to Related to CypressViewer from Siemens. Medical software. Note: Located in C:\Program Files\Acuson\CypressViewer\Bin\Release\ |
| czaqi (czaq) | X | czaqi.sys | Troj/QQHelp-Gen
Note:Located in C:\Windows\System\Drivers (Win9x/Me), C:\%WINDIR%\System32\Drivers (XP/WinNT/2K)
Install numerous files and other services. Read the link |