| Name | Status | Filename | Description |
|---|
| CriticalUpdate | X | wucrtupd.exe | Added by the W32/NOALA.B WORM! - NOTE: this file is located in the Windows or Winnt folder, and must not be confused with the legitimate Windows process of the same name as described here |
| configuration loader | X | winicfg32.exe | Added by the GAOBOT.GEN!POLY WORM! |
| cursor | N | Screendragon_VS_Taskbar.exe | ScreenDragon video player |
| Connectivity Tool | X | (Path to Trojan,file) | Added by the Troj/Litebot-E
TROJAN!
Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
|
| CertReg | U | certreg.exe | Related to Gemplus Card Reader Note: located in C:\Program Files\Common Files\Gemplus\CertReg\ |
| Configuration Loader | X | svchost2.exe | Added by the WORM_AGOBOT.JR WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Can terminate several files, most of which are antivirus processes |
| cttdpsrv | ? | cttdpsrv.exe | ?? |
| CSV7P70 | X | CSV7P070.exe | ClearSearch adware related |
| CT Control Settings | X | CTSVCCD.EXE | Added by the W32/RBOT-YS WORM! |
| Configuration Loader | X | systemry.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| Configuration Loaded | X | lssas.exe | Added by a variant of the SDBOT WORM! Note - this is not the legitimate http://www.liutilities.com/products/wintaskspro/processlibrary/lsass/" target=_blank>lsass.exe process
|
| CORESYS | ? | coresys.exe | ?? |
| Command | X | system.exe | Added by the GATECRASH.A or GATECRASH.B VIRUSES! |
| Config Loader | X | svchosl.exe | Added by the GAOBOT.P WORM! |
| cfy | X | cfy.exe | Surfenhance.com SearchForIt adware variant |
| Config Loadatiorin | X | I3Explorer.exe | Added by the SDBOT.H WORM! |
| Cookie Cop 2 | U | CookieCop.exe | Cookie Cop 2 from PC Magazine - cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return
|
| CookiePatrol | U | CookiePatrol.exe | CookiePatrol - PestPatrol's cookie interceptor stopping spyware cookies |
| Configuration Loader | X | msg.exe | Added by the SDBOT.BT WORM! |
| Configuration Manager | X | CNFGLD32.EXE, Cnfgldr.exe | Added by the SDBOT WORM! |
| clock | X | (various file,names) | LiveChat Adware - known file names include: mssetup.exe, kstatus.exe, spoolsv.exe, sptsupd.exe, osk.exe, msswchx.exe, netdde.exe, msbkup.exe
|
| ccRegVfY | X | svcrhost.exe | Added by the WIN32.TACTSLAY.A TROJAN! |
| Creates stractures for system management | X | stacture.exe | Added by the W32/Sdbot-DHS WORM! Note: Located in \%WINDIR%\System32\ Read the link, allows remote access |
| cctray | U | cctray.exe | Related to Computer_Associates Internet Security. Note: Located in C:\Program Files\CA\CA Internet Security Suite\cctray\ |
| Compaq Service Drivers | X | amsn.exe | Added by a variant of the W32/SDBOT WORM!
|
| CPQBootPerfDB | N | CPQBootPerfDB.EXE | See the entry for Compaq Message Server |
| Config Loader | X | sysldr32.exe | Added by the GAOBOT WORM! |
| Casdvqwa | X | bmqnzkg.exe | Added by the RANDEX.BE VIRUS! |
| CTFMON32 | X | CTFMON32.EXE | CoolWebSearch parasite related - also detected as the TROJ/CWS-E TROJAN! |
| Cmmon32Sys | X | cmmon32.exe | Added by the Troj/Clicker-I
TROJAN!
Note: This trojan file is found in the Windows or Winnt folder.
|
| CPQINKAGENT | N | cpqinkag.exe | That is the Compaq Ink Agent for some inkjet printers, it lets users know when their ink cartridges are getting close to empty (by how many pages they have printed) |
| csm Win Updates | X | csm.exe | Added by the W32/ZOTOB.B WORM! |
| CLSRSS | X | LSACS.EXE | W32/SillyFDC-X Read the link, steals information |
| clfmon | X | clfmon.exe | Added by the TACTSLAY.E Trojan Read the link, allows remote access
|
| ccApps | X | winlogon.exe | Added by NEVEG.A WORM! Note - this is not the valid Windows Logon winlogon.exe process |
| CONNECTScheduler | Y | CONNECTScheduler.exe | Sony CONNECTAuto Update Scheduler |
| CeEKEY | ? | CeEKey.exe | Toshiba Satellite E-Key related. Is it required? |
| Creative.exe | X | Creative.exe | Added by the PROLIN VIRUS! |
| Ci Svr | X | cisvr.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| CPU Manager | X | cpumgr.exe | Added by the PANDEM.B VIRUS! |
| Chatango | N | Chatango.exe | Chatango "allows people to be connected in real time through their Web browsers. Include your Chatango contact link or button when you create eBay auctions, blogs, personal websites, Friendster profiles, and your visitors will be able to contact you instantly, without downloading anything, or registering. Alo use it to send email to your friends, allowing them to respond to you in real time!."
The 'MessageCatcher' icon in the System Tray notifies you when you get a message. When you get a message, a little alert pops up, which you can click on and start chatting immediately. |
| ctfmon | X | WinConst.exe | Added by the Troj/Assasin-G
Trojan! |
| Control Center | U | Center.exe | Related to Asus WLAN Card |
| ctfmon.exe | X | ctfmon.exe | Added by the Troj/Bckdr-QF
TROJAN!
NOTE: do not confuse with the MS Office file of the same name as described here
Read the link, rootkit type stealth involved. |
| ccApp | X | WMADZ.EXE | Added by the W32/RBOT-LJ WORM! |
| C:Program Files1&11&1 EasyLoginEasyLogin.exe | U | 1&1 EasyLogin | Related to 1&1_EasyLogin an Internet Provider. Note: Located in \%Program Files%\1&1\1&1 EasyLogin\ |
| CyberLat Ram Cleaner | U | CyberLat Ram,Cleaner 1,1.exe | Related to CyberLat_RAM_Cleaner is a program that Frees, Optimizes and Defrags your system\'s wasted memory (RAM). Some users swear by programs such as this but I suggest you read this article and make up your own mind. Note: Located in \%Program Files%\CyberLat\CyberLat RAM Cleaner 1.1\ |
| CACStarter | N | cacstart.exe | Cash A Check - check writing software |
| Contacte | ? | contacte.exe | Some kind of driver? |
| Camera Assistant Software | U | traybar.exe | Related to Camera_Assistant_Software FROM Toshiba. Note: Located in \%Program Files%\Camera Assistant Software for Toshiba\ |
| cma | U | cma.exe | DeskSite CMA siftware - "retrieves new content from the DeskSite Data Center"
|
| CoolMon | U | CoolMon.exe | Related to CoolMon monitors vital system stats and almost anything else you wish to display on the desktop. Note: Located in \%Program Files%\CoolMon\ |
| Classes | X | int1.exe | "Switch" adult content dialler |
| ChikkaDefault | U | ChikkaLauncher.exe, | Chikka_Text_Messenger |
| coolwebprogram | X | clrssn.exe | CoolWebSearch parasite related |