| Name | Status | Filename | Description |
|---|
| cpanel | X | winlogin32.exe | Added by the W32/RBot-FOY WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| CeEKEY | ? | CeEKey.exe | Toshiba Satellite E-Key related. Is it required? |
| Clotusorgreg0 | ? | prtStart.exe,[path],Orgprt.exe | IBM Lotus SmartSuite related. In a LotusOrgReg folder. Unclear what exactly it does?
|
| CTAVTray | N | CTAvTray.exe | For Creative Soundblaster Live! series soundcards. Plays the EAX animation on start-up and adds a System Tray icon for it. Available via AudioHQ |
| Configuration Utility | N | CONFIG.EXE | Controls linksys wireless connection. Available from the Desktop |
| Cmaudio | N | Rundll32,cmicnfg.cpl, CMICtrlWnd | System tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start -> Settings -> Control Panel |
| china11msn | X | CHINA11MSN.EXE | Added by the W32.ENVID.O WORM! |
| Configuration Loader (a2) | X | svchost2.exe | Added by a variant of the WORM_AGOBOT.JR WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| CACStarter | N | cacstart.exe | Cash A Check - check writing software |
| Cyberhawk | U | CHTray.exe | Related to Cyberhawk from Novatix, Protects against Viruses, Spyware, Identity Theft. Note: Located in C:\Program Files\Novatix\Cyberhawk\ |
| Care2GTU | U | Care2GTU.exe | Care2 Green Thumbs-Up (from the Care2 site). Every online purchase helps environmental causes; tells you how eco-friendly a company really is, thanks to over 200 company profiles from Coop America. Saves 1 square foot of rainforest every day you use it. If it works and you like it keep it |
| Compaq Sound Drivers For WINDOWS | X | sounddr.exe | Added by the W32/SDBOT-XG
WORM!
Read the link, rootkit type stealth involved.
|
| Cmmon32Sys | X | cmmon32.exe | Added by the Troj/Clicker-I
TROJAN!
Note: This trojan file is found in the Windows or Winnt folder.
|
| comctl32 | X | comctl32.exe | Adware - recognized by Kaspersky antivirus and others as TrojanDownloader.Win32.Agent.am |
| cartao | X | [path to file] | Added by the TROJ/DLOADER-QD TROJAN! |
| ctfnom | X | rundIl32.exe | Added by the Troj/LegMir-AW
TROJAN!
Note: This is not the legitimate Windows process rundll32.exe (Notice the difference in the spelling). This trojan file (rundIl32.exe) is also located in the System (95/98/Me) or System32 (Nt/2000/XP) folder. |
| Compaq32 Service Drivers | X | ms32.exe | Added by the SDBOT.BWH WORM! |
| Choke | X | Choke.exe-blahh | Added by the CHOKE VIRUS! |
| ChromeMark | ? | keysh.exe | Related to this. Don't know what keysh.exe does though and if it's required |
| ClickMe | N | ClickMe.exe | ClickM "JOKE" program |
| cmssSystemProcess | X | mcsmss.exe | Added by the REPSAMO TROJAN! |
| cctray | U | cctray.exe | Related to Computer_Associates Internet Security. Note: Located in C:\Program Files\CA\CA Internet Security Suite\cctray\ |
| Clipomatic | N | Clipomatic.exe | Mike Lin's Clipomatic is a clipboard cache program - it remembers what was copied to the clipboard even after new data is copied, and allows you to retrieve the old data |
| CentralProcessor | X | taskimgr.exe | Added by the BANCOS.J VIRUS! Read the link, keylogger/password stealing trojan(s) involved. |
| cFosInst_Check | ? | cfosinst.exe | cFos DSL Modem driver related. What does it do and is it required? |
| ccApp | X | gcasServ.exe | Added by a variant of the WIN32.RBOT WORM!
- do NOT confuse with the Microsoft AntiSpyware executable of the same name as described here |
| csvdea | U | csvdea.exe | Added by the SpyArsenalLog surveillance software. Uninstall this software unless you put it there yourself.
|
| ctfmon | X | taskmgr32#.exe | Added by the SOWSAT.B VIRUS! where # is a number from 0 to 9 |
| Client Access Express Welcome | ? | cwbwlwiz.exe | Welcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. What does it do and is it required? |
| Configuration Loader | X | seru32.exe | Added by the W32/SDBOT-VR WORM! |
| CHIPDRIVESmartcardManager | U | SCMgr.exe | ChipDrive Smartcard software |
| Corel Photo Downloader | N | MediaDetect.exe | Related to Corel Photo Album. This program is non-essential process to the running of the system, but should not be terminated unless suspected to be causing problems. |
| CPATR10 | U | CPATR10.EXE | Dritek/Compal ATR10 Easy Button driver. Used on certain laptops (e.g. Toshiba, Compaq) to translate special hotkeys such as Play/Pause and Constrast |
| ccApp | X | WMADZ.EXE | Added by the W32/RBOT-LJ WORM! |
| ChronitelInitTV | ? | CHTVINIT.EXE | ?? |
| CoreSrv | X | coresrv.exe | Some IRC trojans/worms use this - see here for more information |
| cmrst | X | cmrst.scr | Added by the Troj/Dloader-FP
TROJAN!
|
| Capon | Y | Caponn.exe | Canon printer driver |
| ccPrxy.exe | X | ccPrxy.exe | W32/ShipUp-H |
| CypressLinkMon | U | CypressLinkMon.exe | Related to CypressViewer from Siemens. Medical software. Note: Located in C:\Program Files\Acuson\CypressViewer\Bin\Release\ |
Consumer Input Rewarded with MyPoints, Consumer Input Update | U | ConsumerInputRewardedwithMyPoints,ConsumerInputUa.exe | Related to Consumer_Input Toolbar. When you install the toolbar you participate in marketing research. I suggest you read the Frequently_Asked_Question Note: located in C:\Program Files\Consumer Input Rewarded with MyPoints, Consumer Input\ |
| Configuration Loader | X | Servicess.exe | Added by the GAOBOT.AO WORM! |
| clcl7 | X | clcl7.exe | Added by a variant of the Covert.Sys.Exec Note: This worm\trojan is located in C:\%WINDIR%\System32\ (XP/WinNT/2K) |
| Configuration Loader | X | svchost.exe | Added by the W32/ParaDrop-A
WORM!
|
| CorrectConnect | N | CConnect.exe | Broadband ISP diagnostic tool - as used by NTL and Cox Communications. Shortcut available |
| cmdbcs | X | cmdbcs.exe | Troj/Lineag-GKW Note: Located in %windir% Read the link, steals information |
| CSV7P91 | X | CSV7P91.exe | ClearSearch adware related |
| Critical Update Check | X | battlenet.exe | Added by the Troj/Delf-LB
TROJAN!
|
| CyberMedia Agent | N | CMAGENT.EXE | Part of CyberMedia's Oil Change program. Not normally required. Note - if you have TextBridge, CyberMedia Agent may attach itself to TextBridge and cause TextBridge to crash everything if this is disabled |
| Compaq Service Drivers 32 | X | compq32.exe | Added by a variant of the W32/SDBOT WORM!
|
| Capfax | N | capfax.exe | PhoneTools fax software |
| C:\WINDOWS\WinTask.exe | X | WinTask.exe | "Pop Marketing" adware |
| CGServer | U | cgserver.exe | Associated with an Eicon Networks ISDN or ADSL modem. Call Guard Server (CGserver) watches your modem and blocks incoming or outgoing calls. You need cgard.exe (from Startmenu) to configure cgserver with rules and telephone numbers. Good against unwanted dialer programs |
| CRSSXP SysInfo | X | crssxp.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| CMGShieldUI | U | CMGShieldUI.exe | Related to Credant_Technologies data encryption software for laptop and USB encryption to CD-DVD recorders, iPods and Smart Phones. Note: Located in \%WINDIR%\System32\ |