| Name | Status | Filename | Description |
|---|
| CreativeTaskScheduler | N | CTSched.exe | Related to Creative_TaskScheduler Note: Located in C:\Program Files\Creative\Shared Files\ |
| CodeClean | X | CCIntro.exe | CodeClean - rogue "security software of Korean origin hailing from codeclean.co.kr |
| Configuration Loader | X | msgfix.exe | Added by the W32/SDBOT-QG
and W32/Sdbot-BTE
WORMS! |
| Classes | X | int1.exe | "Switch" adult content dialler |
| CSRSS Loader | X | csrsss.exe | Added by the AGOBOT.TX WORM! |
| chkhbci | N | chkhbci.exe | Smart Card reader software for Omnikey readers
|
| Configuration Loader | X | wincffg.exe | Added by the AGOBOT.A3 WORM! |
| cmrst | X | cmrst.scr | Added by the Troj/Dloader-FP
TROJAN!
|
| Chatango | N | Chatango.exe | Chatango "allows people to be connected in real time through their Web browsers. Include your Chatango contact link or button when you create eBay auctions, blogs, personal websites, Friendster profiles, and your visitors will be able to contact you instantly, without downloading anything, or registering. Alo use it to send email to your friends, allowing them to respond to you in real time!."
The 'MessageCatcher' icon in the System Tray notifies you when you get a message. When you get a message, a little alert pops up, which you can click on and start chatting immediately. |
| Configuration Loader | X | windex.exe | Added by the GAOBOT.BM WORM! |
| Corel Family & Friends reminders | N | CFFREM.EXE | Corel Family & Friends - all-in-one calender, address book and list manager. Part of Corel Print House Magic |
| ctfmon | X | taskmgr32#.exe | Added by the SOWSAT.B VIRUS! where # is a number from 0 to 9 |
| CMPDPSRV | U | CMPDPSRV.EXE | Printer Driver Plus from ViewAhead Technology (formerly DeviceGuys, Inc.). "Printer Driver Plus seamlessly integrates all the necessary components of a printer driver, plus more." Installed with some Compaq and Lexmark printers |
| cpntmgc | X | wincomp.exe, winmgts.exe | Added by the MagicControl TROJAN! |
| CLSID | X | plugin.exe | Adult content dialler |
| CmdShell.exe | X | CmdShell.exe | Troj/Bckdr-QHY Read the link, allows remote access |
| cftmon | X | sfcmonit.exe | Identified as a variant of the Backdoor.Win32.Agent.erg malware. Note: Located in \%Program Files%\Common Files\System\ Note: Use SDFix under supervision. |
| CMGrdian | ? | CMGrdian.exe | One of the McAfee shared components. What does it do and is it required? |
| Clickoff | U | Clickoff.exe | Related to Clickoff automatically dismisses annoying dialog boxes. Note: Located in \%Program Files%\ClickOff\ |
| ClickMe | N | ClickMe.exe | ClickM "JOKE" program |
| Coupon Offers | ? | ?? | ?? |
| cjb | X | cjb.exe | Added by a variant of the Trojan-Clicker.Win32.Small.BG TROJAN! Note: Located in \%Program Files%\cjb\ Note: Use SDFix under supervision. |
| CherryKeyMan | U | KeyMan.exe | Multimedia keyboard manager for the Cherry keyboard series. Only required if you use any of the special keys |
| CPQTEAM | U | cpqteam.exe | Related to HP_Network_Configuration_Utility from Hewlett-Packard. Note: C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Configuration Loader | X | aim95.exe | Added by the LOADCFG or SDBOT TROJANS |
| Colorific Control Panel | N | Hgcctl95.exe | From E_Color. Colorific delivers accurate gamma and color temperature across your entire system - monitor to printer and digital camera to monitor |
| cttdpsrv | ? | cttdpsrv.exe | ?? |
| Configuration | X | ntsys32.exe | Added by the W32/SDBOT-LN WORM! |
| Capture Express 2000 | N | capexp.exe | Capture Express - screen capture utility |
| Control handler | X | ***********.exe,(* = random,char) | CoolWebSearch parasite variant |
| Capon | Y | Caponn.exe | Canon printer driver |
| Curtain | U | Curtain.exe | Related to Curtain from ChaoticVisions.com - utility which gives you the power to hide any window or group of windows to your system tray. C:\Documents and Settings\Users\Desktop\ |
| clfmon.exe | X | clfmon.exe | Added by the TROJ/AGENT-BJ TROJAN! |
| CM108Sound | U | CM108.cpl | Related to C-Media USB audio solution. |
| ControlCenter | Y | ctlcntr.exe | IBM_fingerprint_software |
| ClickTheButton | X | csrss.exe | "ClickTheButton" Downloader-MY TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
| conscorr | X | conscorr.exe | VX2.Transponder parasite updater/installer related |
| CanonMyPrinter | U | BJMyPrt.exe | Related to CanonMyPrinter printer software for Canon Bubblejet printers. Note: Located in C:\Program Files\Canon\MyPrinter\BJMyPrt.exe |
| CW | U | cw4.exe | Chat_Watch "is a monitoring and logging software for online chat and instant messaging programs"
|
| CmeUPD | X | CMEupd.exe | Part of Gator advertising spyware - see here for removal instructions. Please note that Claria Corporation no longer support GAIN-Supported software - see here
|
| crs | X | crs.exe | Added by the W32/Agobot-TJ
WORM!
Note: This worm\trojan file is found in the Root folder. Example: ( C:\ )
|
| CARPservice | U | carpserv.exe | Associated with Zoltrix modems - enables the internal modem speaker, allowing you to listen to the dial-up sounds for example |
| csc | ? | csc.exe | ?? |
| CTFMon | U | ctfmon.exe | Family_Keylogger
is a program that lets you record to a special file and then view all the keystrokes typed by everyone using your computer. Remember if you did not put this on your computer then someone else did! This Keylogging file is found in the System\CTF (95/98/ME) or System32\CTF (NT/2000/XP) folder. |
| Configuration Loading | X | configldr.exe | Added by the AGOBOT-EC WORM! |
| Cashsurfers Cashbar Navigator | N | Cashbar.Exe | Cashsurfers CashBar Navigator - "The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers and deals" |
| ControlPanel | X | private.exe | Reported by Norman Virus Control as W32/Downloader.
* Creates file sdfff.
* Creates file C:\WINDOWS\SYSTEM32\d.exe.
* Creates file fdsf.
* Creates file C:\WINDOWS\SYSTEM32\s.exe.
* Creates file zxczxc.
* Creates file C:\WINDOWS\SYSTEM32\r.exe.
* Opens URL: htt://www.perlink.biz/07/1002.exe.
* Opens URL: htt://www.perlink.biz/07/1001.exe.
* Opens URL: htt://www.perlink.biz/07/1003.exe.
Full Path looks like %Drive%\WINDOWS\system32\private.exe internat.dll,LoadMouseCarpetProfile
|
| CU1 | X | VCClient.exe | Associated with the Surf Sidekick adware and should be removed.
This file is located in the Program Files\Common Files\VCClient folder. |
| Client Server Run Time Proccess | X | csrsrv.exe | Added by the HackerDefender SDBot TROJAN! ROOTKIT INFECTION Note: This worm\trojan is located in C:\Windows\ |
| Cassandra | X | cassandra.exe | Melkosoft_Cassandra adware - also detected as a variant of the WIN32.KREPPER TROJAN! |
| Client Agent | X | (Path To random,filename) | Added by the Troj/PPdoor-J
TROJAN!
|
| CJET | X | CJet.exe | Added by the Adware.FFToolBar adware toolbar. |
| Cobian Backup 8 interface | U | cbInterface.exe | Related to Cobian_Backup An Open Source projects. Note: Located in C:\Program Files\Cobian Backup 8\ Note Open souce project can be modified. Make sure you scan the program with a Virus protection program before using. |
| Crnsava | X | scrnsave.pif | Added by the W32/Sdbot-ZV
WORM!
|
| Checkdisk | X | mscas.exe | Added by the W32/VAGON.A-TR downloader TROJAN!
|