Index Introduction Database Detailed Entries Updates Concise List HJT Forums Rogues Message Board

Windows startup programs - Database search

If you're frustrated with the time it takes your Windows 7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.

See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.

Last database update :- 29th Apr, 2013
31819 items listed

You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.

Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:

A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z

NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.

Please click on the Search button

1835 results found for C

Startup Item or Name Status Command or Data Description Tested
(Default)Xc ofor Rin logr.exeDetected by Microsoft as TrojanSpy:MSIL/Smets.gen!B and by Malwarebytes Anti-Malware as Trojan.Keylogger. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %System%No
C0100Mon.exe?C0100Mon.exeLive! Cam Console Auto Launcher for the Creative Live! Cam range of webcams. Launches the camera console when using video messaging for example?No
c0b6b56d66fd455a280a4ddb531e30d5Xc0b6b56d66fd455a280a4ddb531e30d5.exeDetected by Dr.Web as Trojan.DownLoader8.17711 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
c1d0b9d0c2bd42e23f8e442128550693Xc1d0b9d0c2bd42e23f8e442128550693.exeDetected by Dr.Web as Trojan.DownLoader8.22995 and by Malwarebytes Anti-Malware as Trojan.Agent.CP. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
h1b8Xc20t.exeDetected by Kaspersky as Virus.Win32.Virut.ce. The file is located in %Temp%No
c218ba2a7a6bd261c18afce044d068ffXc218ba2a7a6bd261c18afce044d068ff.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
C29.exeXC29.exeAdded by the AGENT-UAJ TROJAN!No
C2CMonitorNC2CMonitor.exeClick to Convert from Inzone Software Limited - a PDF and HTML document converter for Windows documentsNo
c3294e515629d65109551b22b924c29bXc3294e515629d65109551b22b924c29b.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
c32cs2Uc32cs2.exeCyber Sentinel - internet filtering softwareNo
c51dd1d4c0a92fb8c2ee78d1aed16abdXc51dd1d4c0a92fb8c2ee78d1aed16abd.exeDetected by Dr.Web as Trojan.DownLoader8.33364 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
c7192e982641757f14f66356bb4cf303Xc7192e982641757f14f66356bb4cf303.exeDetected by McAfee as RDN/Generic Dropper!h and by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
TV878 Remote ControlUC7XRCtl.exeRelated to Kworld TV878 TunerNo
c828544720dd92f1c08f71a9bce7a42dXc828544720dd92f1c08f71a9bce7a42d.exeDetected by Dr.Web as Trojan.DownLoader8.37112 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
c9mgrXc9mgr.exeDetected by Kaspersky as Trojan-Downloader.Win32.Agent.tgzgNo
cXc:\archiv~1\win.comAdded by the CUYDOC TROJAN!No
[random name]Xc?rss.exePurityScan adwareNo
EZ FirewallYca.exeEZ Firewall - part of the eTrust range of security products formerly available from CA but now discontinued. Available as a stand-alone product or as part of the EZ Armor suiteNo
Zone Labs ClientYca.exeEarlier version of EZ Firewall (based upon a rebranded version of ZoneAlarm Pro) - part of the eTrust range of security products formerly available from CA but now discontinued. Available as a stand-alone product or as part of the EZ Armor suiteNo
caaspydelayedscanYCAAntiSpyware.exePart of CA Anti-Spyware until 2009 (either as a stand-alone product or as part of a suite). Runs a delayed scan on the first boot after installation before exitingYes
CaPPclUCAAntiSpyware.exePart of CA Anti-Spyware (either as a stand-alone product or as part of a suite). Runs a scan for spyware on startupNo
Microsoft Cab ManagerXcab.exeAdded by the DELF-JJ TROJAN!No
cababaafcadXcababaafcad.exeDetected by Sophos as Troj/Agent-AAVL and by Malwarebytes Anti-Malware as Trojan.Agent.FSENo
CabchkXCabchk.exeAdded by the GEMA TROJAN!No
Cabchk32XCabchk32.exeAdded by the GEMA TROJAN!No
CABCInstallXCABCInstall.exeIgnite Technologies (was CABC) content delivery softwareNo
Internet_SpeedupXCable Accelerator.exeAdded by the SPEEDUP-A WORM!No
[12 random characters]Xcabview1.exeIeDriver adware variantNo
cacaowebNcacaoweb.exe"Cacaoweb is a free plugin to watch, share and host videos and files online with no limits"No
DSAcassXcacasp.exeAdded by the SDBOT.AEL WORM!No
Automatic Media UpdateXCACHE.RVDAdded by an unidentified WORM/TROJAN!No
CachemanNCacheman.exeFreeware disk cache tweaker from Outer Technologies. Should only be run once and not loaded at start-upNo
CacheMgrYCacheMgr.exeSophos Antivirus Remote UpdateNo
CacheSentry ProUCacheSentry Pro.exe"CacheSentry Pro is a program that takes over the management of the Internet Explorer (and AOL) web browser cache"No
CACStarterNcacstart.exeCash A Check - check writing softwareNo
com.codeode.cactusspamfilterUcactusspamfilter.exeCactus Spam - free easy-to-use spam blockerNo
CADSUcads.exeCyber Sentinel - internet filtering softwareNo
CafeStationUCafeStation.exe"CafeSuite is the solution for your internet cafe. Our software provides you with ameans to control the workstations, manage customer database, sell products and generate detailed reports and statistics"No
CA Personal FirewallUcafw.exeInstalled with older versions of CA Personal Firewall (either as a stand-alone product or as part of CA Internet Security Suite). The file opens the main firewall configuration Window but does not appear to run on startup - hence the "U" recommendationYes
cafwUcafw.exeInstalled with older versions of CA Personal Firewall (either as a stand-alone product or as part of CA Internet Security Suite). The file opens the main firewall configuration Window but does not appear to run on startup - hence the "U" recommendationYes
cafwcUcafw.exeInstalled with older versions of CA Personal Firewall (either as a stand-alone product or as part of CA Internet Security Suite). The file opens the main firewall configuration Window but does not appear to run on startup - hence the "U" recommendationYes
ABBYY Community AgentNCAGENT.EXEInstalled with the Optical Character Recognition (OCR) software that comes bundled with a Compaq A3000 all-in-one printer/scanner. Its function appears to be to link you to the internet in an attempt to buy the 5.0 version of the softwareNo
CAgentNCAgent.exeAbbyy Fine Reader OCR (Optical Character Recognition) software for scanning and converting documentsNo
CahootWebcardNCahootWebcard.exe"The Cahoot Webcard is a virtual card that allows you to use your Cahoot credit card online without ever having to expose your real card numbers over the web. It works by generating one-off transaction numbers as a substitute for your real cahoot credit card details". Run manually when neededNo
CaISSDTUcaissdt.exeInstalled with older versions of both stand-alone security tools and suites from CA. Provides System Tray access to the dashboard - which indicates the current tool status and can be used to launch scans, updates or access product informationYes
Computer Associates Dashboard TrayUcaissdt.exeInstalled with older versions of both stand-alone security tools and suites from CA. Provides System Tray access to the dashboard - which indicates the current tool status and can be used to launch scans, updates or access product informationYes
Dir1XcaKeAdded by the CAKE WORM!No
DlDir1XcaKeAdded by the CAKE WORM!No
Microsoft CalculatorXcalc.exeAdded by a variant of the IRCBOT BACKDOOR!No
TibiabotXcalc.exeAdded by the BACKDOOR-CEP!IC BACKDOOR! Note - this is not the valid Windows calculator which resides in %System% and will not normally figure in Msconfig/Startup! This version resides in %Windir%No
Windows ConfigurationXcalc.exeDetected by Malwarebytes Anti-Malware as Backdoor.NgrBot. The file is located in %MyDocuments%No
CALC32XCALC32.EXEAdded by the SPYBOT-EC WORM!No
Photo Express Calendar CheckerNcalcheck.exeUlead Photo Express 2 (now Corel) includes the option to create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper and this entry automatically replaces them at the specified intervals. Not required - change them manuallyNo
Photo Express Calendar Checker SENCALCHECK.EXEUlead Photo Express 2 SE (now Corel) includes the option to create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper and this entry automatically replaces them at the specified intervals. Not required - change them manuallyNo
PhotoExplosionCalCheckUcalcheck.exeCalendar management feature of Nova Development's Photo ExplosionNo
Ulead Calendar CheckerNCalCheck.exeUlead Photo Express 6 (now Corel) includes the option to create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper and this entry automatically replaces them at the specified intervals. Not required - change them manuallyNo
Ulead Photo Express 3.0 SE Calendar CheckerNCalCheck.exeUlead Photo Express 3.0 SE (now Corel) includes the option to create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper and this entry automatically replaces them at the specified intervals. Not required - change them manuallyNo
Ulead Photo Express 4.0 Calendar CheckerNcalcheck.exeUlead Photo Express 4.0 (now Corel) includes the option to create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper and this entry automatically replaces them at the specified intervals. Not required - change them manuallyNo
Ulead Photo Express 4.0 SE Calendar CheckerNCalCheck.exeUlead Photo Express 4.0 SE (now Corel) includes the option to create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper and this entry automatically replaces them at the specified intervals. Not required - change them manuallyNo
Ulead Photo Express Calendar CheckerNcalcheck.exeUlead (now Corel) Photo Express 3.0, 4.0, 5 SE and My Scrapbook 2.0 include the option to create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper and this entry automatically replaces them at the specified intervals. Not required - change them manuallyNo
Ulead Photo Express Calendar Checker For My Custom EditionNCalCheck.exeUlead Photo Express 4.0 My Custom Edition (now Corel) includes the option to create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper and this entry automatically replaces them at the specified intervals. Not required - change them manuallyNo
Ulead Photo Express SE Calendar CheckerNCalCheck.exeUlead Photo Express 3.0 SE (now Corel) includes the option to create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper and this entry automatically replaces them at the specified intervals. Not required - change them manuallyNo
Verificador de Calendário Ulead Photo ExpressNCalCheck.exeUlead Photo Express 4.0 SE (now Corel) includes the option to create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper and this entry automatically replaces them at the specified intervals. Not required - change them manually. Portuguese versionNo
CalculatorXCalculator.exeDetected by Malwarebytes Anti-Malware as MSIL.LockScreen. The file is located in %AppData%No
HKCUXcalculator.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\LumiaNo
HKLMXcalculator.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\LumiaNo
PoliciesXcalculator.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\LumiaNo
CalendarUCalendar.exeThis entry can be added by PlainSight Desktop Calendar and older versions of Desktop iCalendar from Desksware and the older Calendar 200X - which is no longer supported by or available from the authorYes
Calendar 200X ReminderNcalendar.exePart of Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. Displays reminders for holidays, anniversaries, tasks, etc. Disabling this entry via the program also disables the "Calendar 200X Monitor" entryYes
Desktop iCalendarUCalendar.exeOlder version of Desktop iCalendar/Desktop iCalendar Lite by Desksware which include support for Google Calendar and add weather, tasks and appointments to your desktopYes
iCalendarUCalendar.exeOlder version of Desktop iCalendar/Desktop iCalendar Lite by Desksware which include support for Google Calendar and add weather, tasks and appointments to your desktopYes
PlainSight Desktop CalendarUCalendar.exePlainSight Desktop Calendar by Desksware - "It can display Microsoft® Outlook® data, which you can directly manipulate, and weather forecasts from weather information servers. It also uses high-quality fonts, looks pretty, and has lots of skins"Yes
Logo Calibration LoaderUCalibrationLoader.exeEye-One Match (or i1Match) monitor calibration software for use with professional imaging tools such as the X-Rite (was GretagMacbeth) Eye-One Display LT and iDisplay 2 or the Pantone Eye-One Display 2No
CalibrizeResumeUCalibrizeResume.exe"Calibrize is free software that helps you to calibrate the colors of your monitor in three simple steps. Just download the software and follow the procedure to generate a reliable color 'profile' and adjust the colors of your monitor automatically"No
calkXcalk.exeAdded by the STARTPA-FH TROJAN!No
calkypamcyfxXcalkypamcyfx.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
Call32XCall32.exeAdded by the SPAMMIT-H TROJAN!No
Active CallerIDUCallerID.exeActive Caller ID from SoftRM - "is a powerful full-featured Caller ID detection software that will turn your PC into an advanced Caller ID device. It uses your MODEM and Caller ID service provided by your local phone company in order to identify who's calling"No
msenngerXcalling.comDetected by Sophos as Troj/Zapchas-EB and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
CMSallyXcallmesally.exeAdded by the CASAL.A TROJAN!No
Calendar Monitor?calmonitorBackground task for Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. The exact purpose of this startup entry is unknown at presentYes
calmonitor?calmonitorBackground task for Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. The exact purpose of this startup entry is unknown at presentYes
Calendar 200X Monitor?calmonitor.exeBackground task for Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. The exact purpose of this startup entry is unknown at present but it appears to be related to the "Calendar 200X Reminder" entry - as disabling that entry via the program also disables this oneYes
calmonitor?calmonitor.exeBackground task for Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. The exact purpose of this startup entry is unknown at present but it appears to be related to the "Calendar 200X Reminder" entry - as disabling that entry via the program also disables this oneYes
Calnique Popup StopUcalniquepopstop.exePopup stopper extra for the Calnique Custom Calculator from Speciality Calendars. No longer available from the publisherNo
Cal Reminder ShortcutNcalrem.exeProduces a pop-up reminder of events scheduled using the MS Office CalendarNo
caluruviqwalXcaluruviqwal.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% - see hereNo
Generic Host ProcessXcamacttiv.exeDetected by AVG as the CIADOOR.13 TROJAN!No
Camaro CalendarUCamaro Calendar.exeCalendar gadget included with the Camaro theme for MyColors from Stardock CorporationNo
Camaro ClockUCamaro Clock.exeClock gadget included with the Camaro theme for MyColors from Stardock CorporationNo
Camaro WeatherUCamaro Weather.exeWeather gadget included with the Camaro theme for MyColors from Stardock CorporationNo
camchatXcamchatplugin.exeDetected by Malwarebytes Anti-Malware as Trojan.VBKrypt. The file is located in %AppData%\camchatpluginNo
CamCheckNCamCheck.exeNuCam camera software relatedNo
Camera DetectorUCamdetect.exeACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automaticallyNo
Camera DetectorUCAMDET~*.EXEACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automaticallyNo
CamenoUCameno.exeCameno is a program which brings tabbed windows to MSN Messenger 6.0 and aboveNo
CameraApplicationLauncher?CameraApplicationLaunchpadLauncher.exeSupports the integrated webcam on IBM/Lenovo Thinkpad notebooks. What does it do and is it required?No
CameraAssistantUCameraAssistant.exeEntry added when you install versions of the Logitech QuickCam webcam software and used to configure and tweak your webcam settings. Includes support for the Quick Assistant - which launches when a video application (such as video conferencing in an instant messaging client) accesses to camera so you can quickly fine tune face tracking and zoom, for example. If you don't use the camera on a daily basis create your own shortcut and run it manually when requiredYes
Logitech QuickCamUCameraAssistant.exeEntry added when you install versions of the Logitech QuickCam webcam software and used to configure and tweak your webcam settings. Includes support for the Quick Assistant - which launches when a video application (such as video conferencing in an instant messaging client) accesses to camera so you can quickly fine tune face tracking and zoom, for example. If you don't use the camera on a daily basis create your own shortcut and run it manually when requiredYes
LogitechCameraAssistantUCameraAssistant.exeEntry added when you install versions of the Logitech QuickCam webcam software and used to configure and tweak your webcam settings. Includes support for the Quick Assistant - which launches when a video application (such as video conferencing in an instant messaging client) accesses to camera so you can quickly fine tune face tracking and zoom, for example. If you don't use the camera on a daily basis create your own shortcut and run it manually when requiredYes
camfrogXcamfrog.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.AI. Note - this is not the legitimate Camfrog video chat software by Camshare Inc. The file is located in %System%\MSDCSCNo
CamfrogNCamfrogNet.exe Camfrog Video Chat.exeCamfrog video chat software by Camshare IncNo
[12 random characters]Xcamocx28.exeIeDriver adware variantNo
[12 random characters]XCAMOCX74.exeIeDriver adware variantNo
HerculesCamService?CamService.exeRelated to the Hercules Dualpix HD Webcam. What does it do and is it required?No
Creative WebCam TrayNCAMTRAY.EXECreative WebCam tray control - can be started manuallyNo
CamWizardYCamWizrd.exeLaunches the Logitech Camera Wizard on the first reboot after installing versions of Logitech QuickCam webcam softwareYes
cam_server.exeXcam_server.exeDetected by Dr.Web as Trojan.MulDrop2.48031 and by Malwarebytes Anti-Malware as Backdoor.Agent.CMSNo
ASDPLUGINXcanada.exeAsdPlug premium rate adult content dialerNo
CanadaNCanada.exeKnown to be a dialler - but is it maliscous or clean?No
HELPERXcanada.exeAsdPlug premium rate adult content dialer variantNo
CanaryUcanary-std.exeCanary keystroke logger/monitoring program - remove unless you installed it yourself!No
Eac_CnryXcanary.exeAdded by the CANARY TROJAN!No
candynaXcandyna.exeDetected by Malwarebytes Anti-Malware as Trojan.Clicker.Gen. The file is located in %UserProfile%\My MyPersonalStuffNo
CANoeUCANoe32.exeCANoe from Vector Informatik. Development and test tool for Engine Control Units (ECU) based upon the CAN, LIN, MOST, FlexRay, Ethernet and J1708 bus systemsNo
ICompXpSpXCap.exeAdded by the BANCOS-BLW TROJAN!No
CAP3ON?CAP3ONN.EXECanon driver, purpose unknown. Is it required in startup?No
[12 random characters]Xcapesnpn.exeIeDriver adware variantNo
Capture Express 2000Ncapexp.exeCapture Express - screen capture utilityNo
CA Personal FirewallYcapfasem.exeRuns the core program for older versions of CA Personal Firewall (installed as either as a stand-alone product or as part of CA Internet Security Suite)Yes
capfasemYcapfasem.exeRuns the core program for older versions of CA Personal Firewall (installed as either as a stand-alone product or as part of CA Internet Security Suite)Yes
CapFaxNCapFax.EXEPhoneTools fax softwareNo
CA Personal Firewall?capfupgrade.exeInstalled with CA Personal Firewall (either as a stand-alone product or as part of CA Internet Security Suite). The exact purpose is unknown at present and it does not normally appear to runYes
capfupgrade?capfupgrade.exeInstalled with older versions of CA Personal Firewall (either as a stand-alone product or as part of CA Internet Security Suite). The exact purpose is unknown at present and it does not normally appear to runYes
CAPingUCAPing.exeCitibank Citianywhere softwareNo
Canon PC1200 iC D600 iR1200G Status Window?CAPM1LAK.EXECanon printer related - is it required in startup?No
CaponYCapon.exeCanon printer driverNo
CaponYCaponn.exeCanon printer driverNo
CappXcapp.exeDetected by Malwarebytes Anti-Malware as PUP.CNNIC. The file is located in %System%No
CA Anti-SpywareYCAPPActiveProtection.exePart of CA Anti-Spyware until 2009 (either as a stand-alone product or as part of a suite). Works in conjunction with the CA Pest Patrol Realtime Protection Service (ITMRTSVC) service to monitor software installations for potentially malicious behaviour, warn the user if any is detected and request user input on how to handle themYes
CAPPActiveProtectionYCAPPActiveProtection.exePart of CA Anti-Spyware until 2009 (either as a stand-alone product or as part of a suite). Works in conjunction with the CA Pest Patrol Realtime Protection Service (ITMRTSVC) service to monitor software installations for potentially malicious behaviour, warn the user if any is detected and request user input on how to handle themYes
Winxp updateXCappp.exeAdded by the RBOT.DKO WORM!No
CapsHookUCapsHook.exeCaps Lock and Num Lock on-screen notifier for ASUS laptops and netbooks that don't have the equivalent LEDsNo
captureXcapture.exeAdded by the THEEF-B TROJAN!No
CaptureBatNCapture.exe!Quick Screen Capture from EtruSoft Inc. - "allows you to take screenshots from any part of your screen in more than 10 ways, and save images in BMP/JPG/GIF formats"No
CaptureAssistantUCaptureAssistant.exeCapture Assistant "is a convenient and easy-to-use text and graphics capture tool". It allows you to capture text, font information, graphics, etcYes
CarboniteSetupLite?CarbonitePreinstaller.exeRelated to the installation of Carbonite backup softwareNo
Carbonite BackupNCarboniteUI.exe"Carbonite's online backup service starts automatically and works quietly and continuously in the background protecting your data"No
Care20XCare20.exeTopMoxie adwareNo
Care2GTUUCare2GTU.exeCare2 Green Thumbs-Up (from the Care2 site). Every online purchase helps environmental causes; tells you how eco-friendly a company really is, thanks to over 200 company profiles from Coop America. Saves 1 square foot of rainforest every day you use it. If it works and you like it, keep itNo
carpservUcarpserv.exeAssociated with Zoltrix and Conexant modems - enables the internal modem speaker, allowing you to listen to the dial-up sounds for exampleYes
CARPserviceUcarpserv.exeAssociated with Zoltrix and Conexant modems - enables the internal modem speaker, allowing you to listen to the dial-up sounds for exampleYes
SoftK56 Modem DriverUcarpserv.exeAssociated with Zoltrix and Conexant modems - enables the internal modem speaker, allowing you to listen to the dial-up sounds for exampleYes
CARPserverXCARPserver.exeAdded by the BANKER-AN TROJAN!No
ConfiggLoaderXcart322.exeAdded by the GAOBOT.DJ WORM!No
cartaoXcartao.exeAdded by the BANKER-FA TROJAN!No
Cas2StubXcas2stub.exeCasinoClient adwareNo
Comodo AntiSpamYCAS32.exeSystem Tray access to and notifications for the now discontinued Comodo AntiSpam from Comodo Group, Inc - "client-based software product that eliminates spam forever from the computer's email system"No
CasAgntUCasAgnt.exeProgram by Extended Systems which allows you to sync your Casio PDA with your PCNo
Harmony 98 - CasioOrgUCasAgnt.exeEnterprise Harmony 98 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000No
XTNDConnect PC - CasioOrgUCasAgnt.exeCasio Pocket PC specific translator for XTNDConnect PC - "award-winning desktop-sync application that enables you to easily synchronize your contacts, calendar, tasks, email and notes between your mobile devices and popular PC applications"No
CA Security SuiteUcasc.exeInstalled with both stand-alone security tools and suites from CA. Provides System Tray access to the Control Center - which indicates the current tool status and can be used to launch scans, updates or access product information. The icon changes appearance if a warning or issue is detectedYes
cascUcasc.exeInstalled with both stand-alone security tools and suites from CA. Provides System Tray access to the Control Center - which indicates the current tool status and can be used to launch scans, updates or access product information. The icon changes appearance if a warning or issue is detectedYes
cctrayUcasc.exeInstalled with both stand-alone security tools and suites from CA. Provides System Tray access to the Control Center - which indicates the current tool status and can be used to launch scans, updates or access product information. The icon changes appearance if a warning or issue is detectedYes
CAS ClientXcasclient.exeCasinoClient adwareNo
SettingValueXcasd.exeDetected by Sophos as W32/Sdbot-PG and by Malwarebytes Anti-Malware as Backdoor.SDBotNo
caseyvideoXcaseyvideo.exeMalware causing adult content popupsNo
caseyvideo[*] [* = digit]Xcaseyvideo[*].exe [* = digit]Malware causing adult content popupsNo
CashBackXcashback.exeCashBackBuddy adwareNo
Cashsurfers Cashbar NavigatorNCashbar.ExeCashsurfers CashBar Navigator - "The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers and deals"No
CashFiestaXCashfiesta.exeDetected by Trend Micro as ADW_CASHFIESTA.ANo
casrcssb.exe%UserTemp\casrcssb.exeXcasrcssb.exeDetected by Malwarebytes Anti-Malware as Trojan.CCProxy. The file is located in %UserTemp%No
CassandraXcassandra.exeSuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as a variant of the KREPPER TROJAN!No
winservitXcassl.exeDetected by Trend Micro as WORM_RBOT.ASGNo
CasStubXcasstub.exeAdded by the CASS-A TROJAN!No
DiskstartXcat.exeStartportal - Switch dialer and hijacker variant, see here. Also detected as the DELF-JE TROJAN!No
CatchCodeXCatchCode.exeCatchCode rogue security software - not recommended, removal instructions hereNo
CATEYEYCATEYE.EXEPart of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. "Prevents your system from virus attack by continuously monitoring the system and prevents virus infection from e-mail attachments, Internet Downloads, network, ftp, floppy, Data storage devices, CD-DVD ROM file executables and during suspected file copying." Also included by vendors who use the Quick Heal engine such as Omniquad and iQonYes
On-Line ProtectionYCATEYE.EXEPart of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. "Prevents your system from virus attack by continuously monitoring the system and prevents virus infection from e-mail attachments, Internet Downloads, network, ftp, floppy, Data storage devices, CD-DVD ROM file executables and during suspected file copying." Also included by vendors who use the Quick Heal engine such as Omniquad and iQonYes
Quick Heal AntiVirusYCATEYE.EXEPart of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. "Prevents your system from virus attack by continuously monitoring the system and prevents virus infection from e-mail attachments, Internet Downloads, network, ftp, floppy, Data storage devices, CD-DVD ROM file executables and during suspected file copying." Also included by vendors who use the Quick Heal engine such as Omniquad and iQonYes
Quick Heal On-Line ProtectionYCateye.exePart of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. "Prevents your system from virus attack by continuously monitoring the system and prevents virus infection from e-mail attachments, Internet Downloads, network, ftp, floppy, Data storage devices, CD-DVD ROM file executables and during suspected file copying"No
ccube_TrustListYcatl_001.exeInstalled with older versions of CA Personal Firewall (either as a stand-alone product or as part of CA Internet Security Suite) and runs only once on the first boot after installation is complete before exitingYes
MonitoringXcatmonn.exeDetected by Dr.Web as Trojan.DownLoad1.16841No
N0Y3MzY2RTQ0MzM1MUU2NzXcatr.exeDetected by Dr.Web as Trojan.DownLoader6.43229 and by Malwarebytes Anti-Malware as Backdoor.Bot.WPMNo
catsrvXcatsrv.exeAdded by an unidentified TROJAN - see hereNo
[12 random characters]Xcatsrvps.exeIeDriver adware variantNo
catxmlXcatxml.exeAdded by the AGENT.CE BACKDOOR!No
Norton Live UpdaterXCavapsvc.exeDetected by Symantec as W32.HLLW.Gaobot.AONo
CA Anti-VirusYCAVRID.exeReal-time scanning engine for versions of CA Anti-Virus products until 2009 (both stand-alone and as part of security suites) - including eTrust EZ Antivirus, eTrust Vet Antivirus and a version available from Yahoo! Scans files for viruses and other malware when you access, create or download themYes
CAVRIDYCAVRID.exeReal-time scanning engine for versions of CA Anti-Virus products until 2009 (both stand-alone and as part of security suites) - including eTrust EZ Antivirus, eTrust Vet Antivirus and a version available from Yahoo! Scans files for viruses and other malware when you access, create or download themYes
CAVSYCAVS.exeCheyenne AntiVirus - acquired by CA and no longer availableNo
CyberScrub AutoUpdateYCAVSch.exeAutomatic updates for CyberScrub AntiVirus - which licensed Kaspersky Anti-Virus Lite. No longer supported or available from the authorNo
CaAvTrayYCAVTray.exeSystem Tray access to earlier versions of the CA antivirus products - including EZ Antivirus, eTrust Vet Antivirus and a version available from Yahoo!No
CAZNOVASXCAZNOVAS.exeAdded by the CAZNO TROJAN!No
ccube_Install_LockYcazz_001.exeInstalled with security products from CA and runs only once on the first boot after installation is complete before exitingYes
CBACK.EXEXCBACK.EXEAdded by the PENTA-A TROJAN!No
AdobeReaderProXcbdzfrsl.exeAdded by the RBOT.AZQ BACKDOOR!No
SystemXcber.exeDetected by Trend Micro as TROJ_DLOADER.NXNo
cbInterfaceUcbInterface.exeSystem Tray access to Cobian Backup versions 8 thru 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista/7). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when requiredNo
Cobian BackupUcbInterface.exeSystem Tray access to Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (XP/Vista/7). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when requiredYes
Cobian Backup 10 InterfaceUcbInterface.exeSystem Tray access to Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (XP/Vista/7). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when requiredYes
Cobian Backup 8 interfaceUcbInterface.exeSystem Tray access to Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when requiredYes
Cobian Backup 9 interfaceUcbInterface.exeSystem Tray access to Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when requiredYes
Cobian Backup AmanitaUcbInterface.exeSystem Tray access to Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when requiredYes
Cobian Backup Black MoonUcbInterface.exeSystem Tray access to Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when requiredYes
exkatajXcbkdkiw.exeAdded by the FANBOT-F WORM!No
CallBumpingYcbpopw.exeRelated to the Gazel 128 PCI ISDN adapter. Required if you use itNo
Microsoft System Restore ConfigurationXCBRSS.EXEAdded by a variant of the SPYBOT WORM!No
Remote Data BackupsUCBSysTray.exeSystem Tray access to Remote Data Backups online system/data backup utilityNo
Remote Data Backups TaskBar IconUCBSysTray.exeSystem Tray access to Remote Data Backups online system/data backup utilityNo
KingSoft PowerWord PENCBTray.exeOld version of the PowerWord Chinese and English two way translation software/e-dictionary from KingsoftNo
CBWAttnUCBWAttn.exeRequired for Bitware to answer incoming faxes, can cause sleep mode problemsNo
CBWUser?CBWDial.exeAssociated with Bitware that integrates fax, voice, pager, and data communications on your desktopNo
CBWHostUCBWHost.exeRequired for Bitware to answer incoming faxes, can cause sleep mode problemsNo
SQConfigCheckerXcc.exeXupiter SQWire toolbar related. Use Malwarebytes, Spybot S&D, Ad-Aware or similar to detect and remove and to prevent it re-installing in the futureNo
Clean Access AgentNCCAAgent.exeCisco Clean Access Agent from Cisco Systems, IncNo
ccagent.exeXccagent.exeControl Center and Control Components rogue security software - not recommended, removal instructions here and hereNo
Core Process AplicationXccapl.exeDetected by Kaspersky as Backdoor.Win32.Rbot.gen. The file is located in %System%\ComNo
Core Process Aplication x16Xccapl16.exeDetected by Trend Micro as WORM_SPYBOT.AFTNo
Core Process Aplication x32Xccapl32.exeDetected by Kaspersky as Trojan-Dropper.Win32.Sramler.e. The file is located in %System%\ComNo
ccAppYccApp.exePart of older versions of Symantec's security products including Norton 360, Norton Internet Security, Norton AntiVirus and the now discontinued Norton SystemWorks suite. Effectively the "master" process which calls the different program features and makes sure they are running. Auto-protect and E-mail check will not function without thisYes
ccApp.exeXccApp.exeAdded by the RBOT-HJ WORM! Note - this is not the legitimate Symantec/Norton file normally located in %CommonFiles%\Symantec Shared. This one is located in %System%No
Client and Host Security PlatformYccApp.exePart of older versions of Symantec's security products including Norton 360, Norton Internet Security, Norton AntiVirus and the now discontinued Norton SystemWorks suite. Effectively the "master" process which calls the different program features and makes sure they are running. Auto-protect and E-mail check will not function without thisYes
Common ClientYccApp.exePart of older versions of Symantec's security products including Norton 360, Norton Internet Security, Norton AntiVirus and the now discontinued Norton SystemWorks suite. Effectively the "master" process which calls the different program features and makes sure they are running. Auto-protect and E-mail check will not function without thisYes
Norton Auto-ProtectXccApp.exeAdded by the AKHER.D WORM! Note - for the valid Norton AV entry the filename is "navapexe". This is also not the valid Norton AV file with the same filenameNo
SymantecXccapp.exeAdded by the REATLE WORM! Note - this is not a Symantec fileNo
Symantec Security TechnologiesYccApp.exePart of older versions of Symantec's security products including Norton 360, Norton Internet Security, Norton AntiVirus and the now discontinued Norton SystemWorks suite. Effectively the "master" process which calls the different program features and makes sure they are running. Auto-protect and E-mail check will not function without thisYes
Symantec ServiceXccApp.exeAdded by the AKHER.D WORM! Note - this is also not the valid Norton AV file with the same filenameNo
System Process UninstallXccapp.exeSystemProcess adware. Note - this is not the legitimate Symantec/Norton file normally located in %CommonFiles%\Symantec Shared. This one is located in %System%No
Antivirus Protection ServicesXccapp2.exeAdded by the RBOT.EXI WORM!No
ServicesLogXccapp32.exeAdded by the RBOT-AMX WORM!No
Symantec Configuration LoaderXccApp32.exeAdded by the AGOBOT-EE WORM!No
HP DesktopXccappms.exeAdded by the SDBOT-TG WORM!No
ccAppsXccApps.exeAdded by the KANGAROO-B WORM!No
SymRunXccApps.exeAdded by the KAGEN-A TROJAN!No
Blah serviceXCCAPPS32.EXEAdded by the RBOT.TV WORM!No
6331905XCCAV.exeDetected by Dr.Web as Worm.Siggen.1163No
ccdbefddcfeaebXccdbefddcfeaeb.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.NV. The file is located in %AppData%\cc60db38-3ef1-4d24-8d95-c429fe359aeb79No
ccdbefddcfeaebadXccdbefddcfeaebad.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%\{GUID}No
ccDHCP32XccDHCP32.exeAdded by the AGOBOT-HJ WORM!No
CCDoctorLogonTestingYccdoctor.exeChecks your system to make sure it's configured properly for running IBM Rational ClearCase, a source code management tool. ClearCase is fairly sophisticated so there are a lot of system-related things that can cause it grief. If you run ClearCase you should not disable this as it provides a valuable service, but technically it isn't required to use the ClearCase productNo
Microsoft Driver SetupXccdrive32.exeAdded by the AGENT-LYL TROJAN!No
ccenterYCCenter.exeRising antivirusNo
ccepicXccepic.exeAdded by the MSIL-H TROJAN!No
CcEvtMgrYccEvtMgr.exeCommon process for older versions of Symantec's security products including Norton Internet Security, Norton AntiVirus and the now discontinued Norton SystemWorks suite. Keeps track of all events occurring for these products and writes these into the Activity log - which can be viewed through the Reports section. Runs as a service on an NT based OS (such as Windows 7/Vista/XP)No
nortonsantivirusXccEvtMngr.exeAdded by the HZDOOR-A TROJAN!No
SunJavaSchedXccEvtMngr.exeAdded by the SDBOT-YP WORM!No
ccEvtMrg.exeXccEvtMrg.exeAdded by the RBOT.GZ WORM!No
dddfXccf.exeDetected by Malwarebytes Anti-Malware as Password.Stealer. The file is located in %Temp%No
ccHelpXccHelp.htaSearchq adwareNo
runXcchost.exeAdded by the SQUATBOT-C TROJAN!No
ccStartXccInfo.exeAdded by the AGOBOT-GQ BACKDOOR!No
CodeCleanXCCIntro.exeCodeClean rogue security software - not recommendedNo
winlogon_userXccIsass.exeAdded by the SILLYFDC.BBT WORM!No
CCleaner UpdateXCCleaner x86.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not a valid CCleaner file and it is located in %AppData%\CCleaner UpdateNo
CCleaner Resident Cleaner ServiceXCCleaner-resident.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. Note - this is not a valid CCleaner entry although the file is located in %ProgramFiles%\CCleanerNo
CCleaner Resident Cleaner ServiceXCCleaner-resident.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. Note - this is not a valid CCleaner entry and the file is located in %System%\Program Files\CCleaner\[random] - see examples here and hereNo
CCleaner Resident Cleaner ServiceXCCleaner-resident.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. Note - this is not a valid CCleaner entry and the file is located in %Temp%\Program Files\CCleaner - see hereNo
CCleanerUCCleaner.exeCCleaner from Piriform Ltd. - "is a freeware system optimization, privacy and cleaning tool". Features include removing unused files, cleaning internet history, managing startup programs and a fully featured registry cleanerYes
CCleaner.exeXCCleaner.exeDetected by McAfee as Generic Dropper!dob and by Malwarebytes Anti-Malware as Backdoor.MSIL.PGen. Note - this is not the legitmate CCleaner utility which has the same filename and is normally located in %ProgramFiles%\CCleaner. This one is located in %AppData%\EcUQcsIdRaxsWYFZemcIQR\EcUQcsIdRaxsWYFZemcIQR\0.0.0.0No
ccleanersXccleaners.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%No
CorrectConnectNCConnect.exeBroadband ISP diagnostic tool - as used by NTL and Cox Communications. Shortcut availableNo
CCProxyUCCProxy.exeCCProxy proxy server software from Youngzsoft. A proxy server is a computer system or (in this case) and application that acts as an intermediary for requests from clients seeking resources from other servers. Located in either %Root%\CCProxy or %ProgramFiles%\CCProxy, this should not be confused with the Symantec version included in older versions of Norton Internet Security or the discontinued Norton AntiSpam which is found in %CommonFiles%\Symantec SharedYes
ccProxyYccProxy.exeCommon process for older versions of Symantec's security products including Norton Internet Security and the now discontinued Norton Personal Firewall, Norton AntiSpam and Norton SystemWorks suite. Without this service running HTTP (web) and SMTP (email) connections fail. It works like a proxy server, acting as an intermediary for requests to/from network services - such as blocking access to domains (websites) and inappropriate pages (content filtering). Runs as a service on an NT based OS (such as Windows 7/Vista/XP). Located in %CommonFiles%\Symantec Shared, this should not be confused with Youngzsoft's CCProxy proxy server software which is found in either %Root%\CCProxy or %ProgramFiles%\CCProxyNo
ccPrxy.exeXccPrxy.exeAdded by the SHIPUP-H WORM!No
ccPwdSvcYccPwdSvc.exeCommon process for older versions of Symantec's security products including Norton Internet Security, Norton AntiVirus and the now discontinued Norton SystemWorks suite. The exact purpose is unknown at presentNo
CcPxySvcYCCPXYSVC.exeCommon process for older versions of Symantec's security products including Norton Internet Security and the now discontinued Norton Personal Firewall, Norton AntiSpam and Norton SystemWorks suite. Without this service running HTTP (web) and SMTP (email) connections fail. It works like a proxy server, acting as an intermediary for requests to/from network services - such as blocking access to domains (websites) and inappropriate pages (content filtering). Runs as a service on an NT based OS (such as Windows 7/Vista/XP)No
Real Statics AgentXccreal.exeAdded by a variant of Win32/RbotNo
ccRegVfyYccRegVfy.exePart of older versions of Symantec's security products including Norton Internet Security, Norton AntiVirus and the now discontinued Norton SystemWorks suite. "Responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack"Yes
Common ClientYccRegVfy.exePart of older versions of Symantec's security products including Norton Internet Security, Norton AntiVirus and the now discontinued Norton SystemWorks suite. "Responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack"Yes
USD DriverXccrss.exeAdded by the SDBOT.BFH WORM!No
ccSetMgrYccSetMgr.exeCommon process for older versions of Symantec's products including Norton Internet Security, Norton AntiVirus, Norton Ghost and the now discontinued Norton Personal Firewall and Norton SystemWorks suite. Manages the secure storage and management of the various configuration settings for these products. Runs as a service on an NT based OS (such as Windows 7/Vista/XP)No
Norton Antivirus CCDebugXCCSEVRT.exeAdded by the SDBOT.ACJ WORM!No
novavappXccsmn.exeSysinternals Antivirus rogue security software - not recommended, removal instructions hereNo
Configuration LoaderXccSort.exeAdded by the AGOBOT.SR WORM!No
Sygate Personals FirewallsXccsrn.exeAdded by a variant of Win32/RbotNo
novavapprXccsrr.exeSysinternals Antivirus rogue security software - not recommended, removal instructions hereNo
WINTASKMGRXccsrs.exeAdded by the MYTOB.Q WORM!No
winprotectionXccsrss.exeAdded by the SILLYFDC.BBT WORM!No
ccStartXccStart.exeAdded by the AGOBOT-IR WORM!No
Norton StartXccStart.exeAdded by the SDBOT-OX WORM!No
ccSvcHst.exeXccSvcHst.exeAdded by the SDBOT-DIW WORM! Note - this is not the legitimate Symantec security service located in %CommonFiles%\Symantec Shared. This one is located in %Windir%No
ccsvit.exeXccsvit.exeAdded by the STARTPA-HP TROJAN!No
(Default)Xcct.exeDetected by Malwarebytes Anti-Malware as Trojan.FakeMS. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %WinTemp%No
CA Security SuiteUcctray.exeInstalled with older versions of both stand-alone security tools and suites from CA. Provides System Tray access to the Control Center - which indicates the current tool status and can be used to launch scans, updates or access product information. The icon changes appearance if a warning or issue is detected and double-clicking on it gives details about the warning or the alert stateYes
cctrayUcctray.exeInstalled with older versions of both stand-alone security tools and suites from CA. Provides System Tray access to the Control Center - which indicates the current tool status and can be used to launch scans, updates or access product information. The icon changes appearance if a warning or issue is detected and double-clicking on it gives details about the warning or the alert stateYes
XGCCTVServerYCCTvServer.exeRelated to the GSec1 XGate 2.0 intellegent wireless ADSL/Cable router which has built-in security featuresNo
nortonavXCCUPD32.EXEAdded by an unidentified WORM or TROJAN!No
ccUpdateXccUpdate.exeAdded by the AGOBOT.YS WORM!No
Norton UpdateXccUpdate.exeAdded by a variant of the AGOBOT WORM!No
Norton UpdaterXccUpdate.exeAdded by the AGOBOT.ALW WORM!No
ccUpdMgrUccUpdMgr.exeIn Loco Parentis remote surveillance software. Uninstall this software unless you put it there yourself!No
CCUTRAYICONUCCU_TrayIcon.exeRelated to Traybar Launcher from Intel Corporation belonging to Intel® Viiv®No
Adobe_RLXXccwap.exeAdded by the BCKDR-RCL TROJAN!No
MP3 CD ExtractorNCD-Extractor.exe"MP3 CD Extractor is an audio CD to MP3 ripper which can extract Digital Audio tracks from Audio CDs into files on the hard disk"No
cd1Xcd1.exePremium rate adult content diallerNo
Computer Defender 2009Xcd2009.exeComputer Defender 2009 rogue security software - not recommended, removal instructions hereNo
Auto CD-ROM StartupXcdaccess.exeAdded by the SPYBOT.BLA WORM!No
Microsoft softwareXcdaccess.exeDetected by Trend Micro as WORM_RBOT.ABKNo
CDANTSRVNCDANTSRV.exeC-Dilla License Management software. Used for any program that uses C-dilla Protection, example: 3D Studio Max 4.x. It loads as a service automatically but is not needed unless you run said program. Can be started and stopped manuallyNo
CyberDefender Early Detection CenterXcdas[random].exeCyberDefender Early Detection Center rogue security software - not recommended. On testing with a clean image, this reported registry entries pointing to the legitimate Java "jqs_plugin.dll" file (located in %ProgramFiles%\Java\jre6\lib\deploy\jqs\ie as the Anticlear rogue (see an example here). In addition, it claimed that the installer for an older version of HashTab contained W32.MalwareF.KJAE and quarantined a valid 7-zip file ("7zCon.sfx" in %ProgramFiles%\7-Zip) as W32/Malware. Also read this post where a Tech Support person uses other free tools such as MBAM to fix a problemNo
cdc10baf8d526aadd954bf3f60e0e69eXcdc10baf8d526aadd954bf3f60e0e69e.exeDetected by McAfee as RDN/Generic.grp!cw and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
cdca408e3cbf7b0daaa425b5705221a4Xcdca408e3cbf7b0daaa425b5705221a4.exeDetected by McAfee as RDN/Generic.dx!bb3 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
CdcompatXCdcompat.exeAdded by the GEMA TROJAN!No
Cddrv32Xcddrv32.exeAdded by the GEMA TROJAN!No
Cool DeskUcdesk.exeCool Desk is a virtual desktops manager. "Ever you wished to have several screens on your computer? Cool Desk creates up to 9 virtual desktops and offers you to have different windows on each of them". Not required but may be of use to youNo
CDInterceptorNcdi.exeCD indexer for measuring the speed of CD playersNo
cdloaderYcdloader2.exeMagicJack - a "softphone device that allows you to attach an analog phone into the PC so you can have a traditional-style phone system in your house without any monthly charge"No
MS-ConnectXcdm.exeMS-Connect - Switch dialer and hijacker variant, see here. Also detected as the DIALER.DD TROJAN!No
CdnCtrXcdnup.exeDetected by Total Defense as CNNIC Update and by Malwarebytes Anti-Malware as Adware.CnnicNo
SystemTraXCDPlay.EXEAdded by the LOVGATE.Z WORM!No
Cdrom ControllerXcdromcntrl.exeDetected by Sophos as Troj/Battry-ANo
MicrosoftROMDriverServiceXcdrss.exeAdded by the IRCBOT.BLF BACKDOOR!No
cdsXcds.exeAdded by the SPYMON TROJAN!No
CDSpeed.exeXCDSpeed.exeAdded by the IRCBOT.AEX BACKDOOR!No
CD Storage MasterNcdstorager.exeCD Storage Master - a program designed to catalog CD information, boasts a number of handy features for organizing your collectionNo
CD Tray PalNCDTray.exeCD Eject Tool from Fomine Software - "is a utility that manages your CD Drive doors. It allows you eject and close the CD Drive door by using a hotkey, desktop shortcut, or via an icon in your system tray"No
CDTrayNCDTray.exeOn HP PCs, this is the small CD icon next to the timeNo
CDTrayPalNcdtray.exeCD Eject Tool from Fomine Software - "is a utility that manages your CD Drive doors. It allows you eject and close the CD Drive door by using a hotkey, desktop shortcut, or via an icon in your system tray"No
UpdateXCDUpdater.exe"Carpe Diem" adult premium rate dialler relatedNo
CD-DVD Lock for Win95/98/Me/2k/XPUCDVAgent.exeLoads CD-DVD Lock from Ixis Research, Ltd - which is "intended for restricting read or write access to removable media devices such as CD, DVD, floppy and flash, as well as for restricting access to certain partitions of hard disk drives. You can restrict access by two ways: hide your devices from viewing or lock access to them". If disabled, hidden and locked drives still retain their original status so the user will only be able to change their status them via the main UIYes
CDVAgentUCDVAgent.exeLoads CD-DVD Lock from Ixis Research, Ltd - which is "intended for restricting read or write access to removable media devices such as CD, DVD, floppy and flash, as well as for restricting access to certain partitions of hard disk drives. You can restrict access by two ways: hide your devices from viewing or lock access to them". If disabled, hidden and locked drives still retain their original status so the user will only be able to change their status them via the main UIYes
JDK55WFMZYXcdx.exeAdded by the MONDER.RON TROJAN!No
CadenzaUCdzSvc.exeCadenza mNotes for Palm and Pocket PC enables users to access Lotus Notes on their mobile devicesNo
ClickTheButtonXcd_load.exeDetected by McAfee as Downloader-MYNo
CyDoorXCD_Load.exeCyDoor adwareNo
CydoorUpdateXCD_Load.exeCyDoor adwareNo
ce034ed846a59de9fb1d175d940837e8Xce034ed846a59de9fb1d175d940837e8.exeDetected by Dr.Web as Trojan.DownLoader7.20094 and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
ceeiLjmUBGBADuXceeiLjmUBGBADu.exeAdded by the FAKEAV-DVF TROJAN!No
CeEKEYUCeEKey.exeHot Key utility included on Toshiba Satellite laptopsNo
Ceic?Ceic.exe??No
run=XCeline.scrAdded by the CELINE-A TROJAN!No
CEventMgrXCell.exeAdded by the BIFROSE-AK TROJAN!No
CenProtectXCenProtect.exeCenProtect rogue security software - not recommended, removal instructions hereNo
Control CenterUCenter.exeAssociated with Hawking Technologies, Inc wireless products. Located in %Program Files%\Hawking\WLAN Card UtilitiesNo
T-Mobile Communication CentreUCentre.exeT-Mobile Communication Centre configuration/management utility for their range of mobile broadband devicesNo
CeEPOWERUCePMTray.exeToshiba's Power Management Utility - allows the user to setup different profiles for both AC power and Battery Power on laptops. Contols CPU speed, Monitor Shut Off, Hard Drive Shut-Off, Monitor Brightness, System Stand-by and System Hibernate timesNo
syscodecaudioXCEQL0H9AT4.exeDetected by Malwarebytes Anti-Malware as Worm.Ainslot. The file is located in %AppData%\audiocodecNo
Advanced Internet ProtocolXcerf.exeAdded by a variant of the SPYBOT WORM!No
CerrusXCerrus.exeDetected by Malwarebytes Anti-Malware as MSIL.LockScreen. The file is located in %AppData%No
Certificate Policy EngineXCertPolEng.exeDetected by Sophos as Troj/Agent-ZBH and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
Legacy VGA Drivers V1.0Xcertproc32.exeAdded by the AGENT.NEM TROJAN!No
CertRegUcertreg.exeRelated to Gemplus Card ReaderNo
CertStoreInitYCertStoreInitAladdin eToken authentication and password managementNo
certtoolYcerttool.exePart of Client Security Software (CSS) for IBM\Lenovo notebooks. If you have configured the software via the associated wizard this will need to be running if you want to mount password protected areas of the disk (created with SafeGuard PrivateDisk), use the password manager or file/folder encryption optionsYes
IBM Client SecurityYcerttool.exePart of Client Security Software (CSS) for IBM\Lenovo notebooks. If you have configured the software via the associated wizard this will need to be running if you want to mount password protected areas of the disk (created with SafeGuard PrivateDisk), use the password manager or file/folder encryption optionsYes
ISS_CerttoolYcerttool.exePart of Client Security Software (CSS) for IBM\Lenovo notebooks. If you have configured the software via the associated wizard this will need to be running if you want to mount password protected areas of the disk (created with SafeGuard PrivateDisk), use the password manager or file/folder encryption optionsYes
SetecCertUtilUCertutil.exeSetec Web and Email Security. Setec PKI smart card software. The PKI technology enables secure and reliable user identification in services offered through Internet, mobile handsets and digital TVNo
Driver Control Manager v7.1Xcetrdeje.exeAdded by the AUTORUN-BKK WORM!No
Driver Control Manager v7.5Xcetrdeosa.exeAdded by the SILLYFDC-FF WORM!No
cryptoexpertUcexpert.exeCryptoExpert from SecureAction Research. Advanced on the fly encryption systemNo
CryptoExTrayV3?CexTray.exePart of the CryptoEx Client Suite from Glück & Kanja Technology AG. What does it do and is it required?No
CryptoExVolumeAutoMount?CexVolume.exePart of the CryptoEx Client Suite from Glück & Kanja Technology AG. What does it do and is it required?No
BJCFDNCFD.exeBroadJump Client Foundation - broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programsNo
CFDNCFD.exeBroadJump Client Foundation - broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programsNo
Microsoft Driver SetupXcfdrive32.exeAdded by the AGENT-OJR TROJAN!No
cfFncEnabler.exeNcfFncEnabler.exeToshiba "Config Free" wireless network manager on their range of laptopsNo
Corel Colleagues & Contacts RemindersNcffrem.exeCorel Colleagues & Contracts - all-in-one organizer for scheduling meetings, maintaining addresses, etc. Part of the now defunct Corel Print OfficeNo
Corel Family & Friends remindersNCFFREM.EXECorel Family & Friends - all-in-one calender, address book and list manager. Part of the now defunct Corel Print House MagicNo
Configuration ManagerXcfg32.exeBookedSpace parasite. Note - the "cfg32.exe" file is located in %Windir%No
cfgboostXcfgboot.exeAdded by an unidentified WORM or TROJAN!No
Microsoft RuntimeXCfgDll32.exeAdded by the RANDEX.BD WORM!No
cfgintprYcfgintpr.exeConfiguration Interpreter - part of Tiny Personal Firewall V4No
cfgmng32Ucfgmng32.exePureSight PC parental controls software by Puresight Technologies Ltd - "offers multi-layered cyberbullying protection for your family and it blocks offensive web-content". Also used by CA for their CA Parental Controls 2008 and 2009 utilities (both stand-alone and in suites)Yes
dvHighMemUcfgmng32.exePureSight PC parental controls software by Puresight Technologies Ltd - "offers multi-layered cyberbullying protection for your family and it blocks offensive web-content". Also used by CA for their CA Parental Controls 2008 and 2009 utilities (both stand-alone and in suites)Yes
Wins32 OnlineXcfgpwnz.exeDetected by Symantec as W32.Bropia.RNo
Printer Update?CFGREG.EXEMaybe a registration reminder or automatically updates drivers or application software for a printer?No
ConfigSafeUCFGSAFE.EXEConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions -- provides a restore function. Your choiceNo
load=?cfgsys32.exe??No
CfgwizUcfgwiz.exeConfiguration wizard for older versions of Symantec's Norton AntiVirus, Norton Internet Security and Norton SystemWorks security products. On the first run after installation or a significant software update via LiveUpdate this entry looks after registration, subscription and post-installation tasks (such as LiveUpdate, full scan and scheduling) and confirms the default configuration settings. If this entry is disabled, the configuration wizard will run the next time the software is launched via the Start MenuYes
IS CfgWizUcfgwiz.exeConfiguration wizard for older versions of Symantec's Norton Internet Security (and the now discontinued Norton Personal Firewall). On the first run after installation or a significant software update via LiveUpdate this entry looks after registration, subscription and post-installation tasks (such as LiveUpdate, full scan and scheduling) and confirms the default configuration settings. If this entry is disabled, the configuration wizard will run the next time Norton Internet Security is launched via the Start MenuYes
NAV CfgWizUCfgWiz.exeConfiguration wizard for older versions of Symantec's Norton AntiVirus. On the first run after installation or a significant software update via LiveUpdate this entry looks after registration, subscription and post-installation tasks (such as LiveUpdate, full scan and scheduling) and confirms the default configuration settings. If this entry is disabled, the configuration wizard will run the next time Norton AntiVirus is launched via the Start MenuYes
NAVCFGUCfgWiz.exeConfiguration wizard for older versions of Symantec's Norton AntiVirus. On the first run after installation or a significant software update via LiveUpdate this entry looks after registration, subscription and post-installation tasks (such as LiveUpdate, full scan and scheduling) and confirms the default configuration settings. If this entry is disabled, the configuration wizard will run the next time Norton AntiVirus is launched via the Start MenuYes
Norton PasswordManagerUcfgwiz.exeConfiguration wizard for Symantec's now discontinued Norton Password Manager security product. On the first run after installation or a significant software update via LiveUpdate this entry looks after registration, subscription and post-installation tasks (such as LiveUpdate) and confirms the default configuration settingsNo
Norton SystemWorksUCfgWiz.exeConfiguration wizard for Symantec's now discontinued Norton SystemWorks security product. On the first run after installation or a significant software update via LiveUpdate this entry looks after registration, subscription and post-installation tasks (such as LiveUpdate, full scan and scheduling) and confirms the default configuration settingsYes
SW CfgWizUcfgwiz.exeConfiguration wizard for Symantec's now discontinued Norton SystemWorks security product. On the first run after installation or a significant software update via LiveUpdate this entry looks after registration, subscription and post-installation tasks (such as LiveUpdate, full scan and scheduling) and confirms the default configuration settingsYes
Configuration WizardXCfgwiz32.exeAdded by the HCKTCK.2K.C BACKDOOR! Not to be confused with the legitimate MS "ISDN Configuration Wizard" (Cfgwiz32.exe)No
TMA distributionUcfinst.exePart of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clientsNo
CFi ShellToys Utility ManagerUCFiShlMan.exeManager for CFi ShellToys from Cool Focus International Ltd - which "puts all the tools you need right where you need them - just a click away on your context menu. Right-click one or more files or folders, the desktop or the window background for instant access to 50 context-sensitive shell extensions"No
Micrcsoft Certificate ServicesXcflmon.exeAdded by the RBOT-FWV WORM!No
CTMON.EXEXcfmon.exeAdded by the CLCKR-AN TROJAN!No
Microsoft Vista Upgrade Validation ServiceXcfmon.exeAdded by a variant of the IRCBOT BACKDOOR!No
cFosDNT?cFosDNT.execFos DSL Modem driver related. What does it do and is it required?No
cFosInst_Check?cfosinst.execFos DSL Modem driver related. What does it do and is it required?No
cFosSpeedUcFosSpeed.execFosSpeed Internet acceleration program from cFos Software GmBH - "increases your throughput and reduces your Ping. Whenever you access the Internet with more than one data stream cFosSpeed can optimize the traffic"No
COMODO Firewall ProYcfp.exeSystem Tray access to and notifications for an older "Pro" version of Comodo Firewall by Comodo Group, IncNo
COMODO Internet SecurityYcfp.exeSystem Tray access to and notifications for the range of internet security products from Comodo - including Internet Security, Antivirus and FirewallNo
Warning: do not remove it! (system)Ycfpsys.exeFolder Password Protect - a program that lets you set a password on folders of your choiceNo
WindowsXCfreer.exeAdded by the CULLER-C WORM!No
CFSServ.exeUCFSServ.exeBelongs to Toshiba's configfree utility and searches for Wireless DevicesNo
cftmocXcftmoc.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%No
autoloadXcftmon.exeAdded by the SOCKS-E WORM!No
cftmonXcftmon.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor.DF. The file is located in %ProgramFiles%No
cftmonXcftmon.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor.DF. The file is located in %System%No
cftmonXcftmon.exeDetected by Malwarebytes Anti-Malware as Trojan.FakePDF. The file is located in %AppData%No
ctfmonXcftmon.exeDetected by Sophos as Troj/Delive-A. The file is located in %Windir%No
HKCUXCftmon.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System%\InstallDirNo
HKCUXCftmon.exeDetected by Kaspersky as Trojan.Win32.VBKrypt.cdor. The file is located in %System%No
HKCUXCftmon.exeDetected by McAfee as Generic.bfr!dx and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\InstallDirNo
HKLMXCftmon.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System%\InstallDirNo
HKLMXCftmon.exeDetected by Kaspersky as Trojan.Win32.VBKrypt.cdor and by Malwarebytes Anti-Malware as Trojan.Backdoor.DF. The file is located in %System%No
HKLMXCftmon.exeDetected by McAfee as Generic.bfr!dx and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\InstallDirNo
PoliciesXCftmon.exeDetected by Kaspersky as Trojan.Win32.VBKrypt.cdor. The file is located in %System%No
Winsock2 driverXCFTMON.EXEAdded by a variant of the IRCBOT BACKDOOR!No
SFtrb ServiceXcftrb32.exeAdded by the SOBIG.D WORM!No
cfyXcfy.exeSurfenhance.com SearchForIt adware variantNo
CGI Firewall ScriptXCGIAGENT.EXEAdded by the BROPIA-U WORM!No
Norton Crashguard MonitorNcgmenu.exeTroublesome program that doesn't actually work with WinME so Norton removed it from SystemWorks 2001No
CGServerUcgserver.exeAssociated with an Eicon Networks (now Dialogic) Diva ISDN or ADSL modem. Call Guard Server (CGserver) watches your modem and blocks incoming or outgoing calls. You need cgard.exe (from Startmenu) to configure cgserver with rules and telephone numbers. Good against unwanted dialer programsNo
Cgtask ServicesXcgtask.exeAdded by the LALA.B TROJAN!No
Microsoft Windows Files LoaderXcgy32win.exeAdded by the RBOT-AXR WORM!No
CgywinXcgywin32.exeAdded by the RBOT-AEI WORM!No
ChamClockUChamClock.exeChameleon Clock - system tray clock replacementNo
HomeAlarmUChamClock.exeChameleon Clock - system tray clock replacementNo
PSD Tools ChannelXChannelUp.exeBuddyLinks adwareNo
Animated WallpaperUCharm Waterfall.exeCharm Waterfall animated desktop wallpaper from Desktop AnimatedNo
[random name]Xcharmapnt.exeAdded by the BANCOS-DR TROJAN!No
System startupUcharmapx.exeOnly required if using an oriental languageNo
Bingo Charm?charms.exeSome kind of screen icon kind of like desk flag, but it gives you a choice of icons?No
ChatangoNChatango.exeChatango - "allows people to be connected in real time through their Web browsers. Include your Chatango contact link or button when you create eBay auctions, blogs, personal websites, Friendster profiles, and your visitors will be able to contact you instantly, without downloading anything, or registering. Alo use it to send email to your friends, allowing them to respond to you in real time!." The 'MessageCatcher' icon in the System Tray notifies you when you get a message. When you get a message, a little alert pops up, which you can click on and start chatting immediatelyNo
Chat loginXchatlogin.exeDetected by Trend Micro as WORM_ANTINNY.FNo
loves2Xchatser.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %System%\InstallDir - see hereNo
loveuoyXchatser.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %System%\InstallDir - see hereNo
mands2Xchatser.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %System%\InstallDir - see hereNo
ChatStatUChatStat.exeChatStat from ChatStat Technologies, Inc. Provides live chat assistance in up to 16 languages allows your operators to be more productiveNo
chaveGBtL2TMXchaveGBtL2TM.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Root%\chaveGBtL2TMNo
ChcenterNchcenter.exeIMSI HiJaak - "the easiest way to convert, capture, and manage all your graphic files"No
ShcenterNchcenter.exeIMSI HiJaak - "the easiest way to convert, capture, and manage all your graphic files"No
chcp.exeXchcp.exeAdded by the SDBOT.BMH BACKDOOR!No
High Definition Audio Property Page ShortcutUCHDAudPropShortcut.exeRealtek audio card related. Probably adds the odd feature to one of the "Sounds" Control Panel applet tabs - doesn't appear to be requiredNo
che32Xche.ocx.vbsAdded by the ADENU-B VIRUS!No
CIONche7e1~1.exeChatItOut webcam chat programNo
GigaByteXCheatle.exeAdded by the SHODI.B VIRUS!No
Check&GetUCheck&Get.exeCheck&Get from ActiveURLs. Manages your browser bookmarks and favorites. Monitors Web sites for changes and updates, captures and highlights the changed contentsNo
CheckXCheck.exeAdded by the VB-DRN WORM!No
eRecoveryServiceYcheck.exeNow part of Acer Empowering Technology. "Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer, and also acts as a versatile standalone backup and recovery manager". Whilst the exact purpose of this entry isn't known it runs and closes so leave it enabled in case it's requiredYes
OBRCheckYcheck.exeNow part of Acer Empowering Technology. "Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer, and also acts as a versatile standalone backup and recovery manager". Whilst the exact purpose of this entry isn't known it runs and closes so leave it enabled in case it's requiredYes
WinCheckXcheck.exeAdded by the DELBOT-Y WORM!No
check119Xcheck119_up.exeCheck119 rogue security software - not recommended, removal instructions hereNo
CheckCustomWorksUpdateNCheckCWupdate.exeUpdate checker, part of CustomWorks - "customize any embroidery designs to design your own unique creations"No
WashAndGo - Cleanup of old BackupfilesUchecker.exeWashAndGo - temp file cleanerNo
CheckIt 86UCheckIt86.exeCheckIt 86 popup blockerNo
ChecklistNChecklist.exeChecklist task management utility by Task Solutions Inc (formerly 4th Software)No
ChecklistSrvUChecklistSrv.exeChecklist task tracking and management utility by Task Solutions Inc (was 4th Software)No
Registry Startup CheckXcheckreg.exeAdded by the REMLOAD-A or DANMEC-B TROJANS!No
svhoostXchecksys.exeAdded by a downloader TROJAN of Chinese origin!No
XvidNCheckUpdate.exeUpdate manager for the Xvid video codecNo
Blackmagic CheckVersion PCI?CheckVersionPCI.exeRelated to the "Decklink" range of products from Blackmagic Design Pty. Ltd. What does it do and is it required?No
Windows firewall managerXchh.exeAdded by a variant of the RANDEX.GEL WORM!No
chiCkieXchiCkie.exeDetected by Symantec as W32.ChikoNo
ChikkaDefaultUChikkaLauncher.exeChikka PC text messanger and IM clientNo
ChilyClientUChilyClient.exeChily Employee Activity Monitoring surveillance software. Uninstall this software unless you put it there yourselfNo
eixfiXchina.batDetected by Trend Micro as BAT_WCUP.ANo
china11msnXCHINA11MSN.EXEAdded by the ENVID.O WORM!No
chisignupXchisignup.exeDetected by Dr.Web as Trojan.DownLoader8.32006No
ChkAdminNCHKADMIN.EXECompaq Network Management System. When running, it places an icon in the system tray titled "Intelligent Manageability"No
SB Audigy 2 Startup Menu?ChkColor.EXERelated to the Creative Sound Blaster Audigy 2 range of sound cardsNo
CheckDialerUChkDial.exeAdded by the CheckDialer modem connection monitoring toolNo
AdobeReaderProXchkdisk.exeAdded by the RBOT-BDV WORM!No
UninstalTimeXchkdisk.exeDetected by Dr.Web as Trojan.Siggen1.31088 and by Malwarebytes Anti-Malware as Backdoor.AgentNo
[random name]Xchkdsk.exePurityScan adware. Note - the legitimate Windows chkdsk.exe will always be located in %System% and will NOT figure among the startups!No
Disk CheckXchkdsk32.exeAdded by the IM TROJAN!No
CHK DiskerXchkdsker.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
NT Printing ServiceXchkdsks.exeAdded by the ARCHIVARIUS series of WORMS!No
NT Printing ServicesXchkdsks.exeAdded by the BUZUS-M TROJAN!No
NT Printing ServiceXchkdskss.exeAdded by the ARCHIVARIUS series of WORMS!No
Microsoft DLL VerifierXchkfile.exeAdded by the RBOT-AOC WORM!No
Pe2ckfnt SENchkfont.exeUsed to check whether the fonts are installed properly on your computer or not for a scanner. If you don't want to execute it, you can uncheck it in the startup menuNo
ASUS ChkMailUChkMail.exeMail-checking utility supplied with some ASUS notebooks that uses an LED to notify the user when an E-mail has arrivedNo
ChkMailUChkMail.exeMail-checking utility supplied with some Acer and ASUS notebooks that uses an LED to notify the user when an E-mail has arrivedNo
Generic ChkMailUChkMail.exeMail-checking utility supplied with some ASUS notebooks that uses an LED to notify the user when an E-mail has arrived. The models supported are AS62FM945GM1, AS62JM945PM1 and AS62JM945PM2 - see hereNo
Java Plug-inXchknt32.exeDetected by McAfee as Spy-Agent.fg and by Malwarebytes Anti-Malware as Trojan.ZbotNo
CHK NTXchkntf.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
[random name]Xchkntfs.exePurityScan adware. Do not confuse with the legitimate NTFS Volume Maitenance Utility (chkntfs.exe) process which is always located in %System% and should not figure in Msconfig/Startup!No
ChkDiskXchk_disk.exeAdded by an unidentified WORM or TROJAN!No
avagent3974Xchnb8895.exeAntiVirus ransomware security software - not recommended, removal instructions hereNo
ChangeLines?chngline.exe??No
ChoiceMailUCHOICEMAIL.EXEChoiceMail from DigiPortal Software. Block spam with an Email firewallNo
ChokeXChoke.exe -blahhhAdded by the CHOKE WORM!No
ChomikBoxUChomikBox.exeChomikBox - Polish utility that "is a small and friendly program that will allow you to easily add files to your hamster, download, and listen to music directly from the pages of the site!" The "hamster" referred to is an online storage serviceNo
chostsvXchostsv.exeAdded by the BANPAES.C TROJAN!No
windows taskbarXChouf-This.exeAdded by the AUTORUN-BQP WORM!No
Microsoft Driver SetupXChrg.exeDetected by Malwarebytes Anti-Malware as Worm.Autorun. The file is located in %System%\driversNo
Christmas Music PlayerNChristmas Music Player.exe"Christmas Music Player brings the music of the Christmas Holiday to your desktop"No
ZackerXChristmas.exeAdded by the MALDAL-C WORM!No
2b5b36b8ef975d928d30dc6bd0460ca5Xchrome crypto.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserTemp%No
b4ada7daa19b8b7f8c9d2810d3477ea5XChrome update.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Temp%No
chromeXchrome.batDetected by Dr.Web as Trojan.DownLoader6.8804No
90480ec0be14f6221b63d9107a2dd7d8Xchrome.exeDetected by Dr.Web as Trojan.DownLoader8.19330 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %AppData%No
aXchrome.exeDetected by Ikarus as Trojan.Win32.VBKrypt and by Malwarebytes Anti-Malware as Trojan.Agent.CRGen. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %UserProfile%\DesktopNo
AVAST32Xchrome.exeDetected by McAfee as BackDoor-CZP.dr and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %Windir%No
bXchrome.exeDetected by Ikarus as Trojan.Win32.VBKrypt and by Malwarebytes Anti-Malware as Trojan.Agent.CRGen. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %MyDocuments%No
cXchrome.exeDetected by Ikarus as Trojan.Win32.VBKrypt and by Malwarebytes Anti-Malware as Trojan.Agent.CRGen. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %UserProfile%\DownloadsNo
chromeXchrome.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.AI. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %Windir%No
chromeXchrome.exeDetected by Dr.Web as Trojan.DownLoader6.5297 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %AppData%\SystemNo
ChromeXChrome.exeDetected by Dr.Web as Trojan.DownLoader6.8983. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
ChromeXChrome.exeDetected by Dr.Web as Trojan.KeyLogger.15604 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %AppData%\Microsoft\System\ServicesNo
ChromeXChrome.exeDetected by McAfee as Generic.dx!b2aq and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %AppData%No
chromeXchrome.exeDetected by McAfee as Generic.bfr!gs and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %Root%No
ChromeXChrome.exeDetected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %ProgramFiles%\ChromeNo
ChromeXchrome.exeDetected by Microsoft as Trojan:Win32/Ransom.EJ and by Malwarebytes Anti-Malware as Trojan,Agent. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %AppData%\google\chromeNo
chromeXchrome.exeDetected by Microsoft as TrojanSpy:Win32/Keylogger.FM and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %UserTemp%No
Chrome ServicesXchrome.exeDetected by Kaspersky as Trojan-PSW.MSIL.Agent.dyi. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %AppData%\Google ChromeNo
chrome.exeXchrome.exeDetected by Dr.Web as Trojan.KeyLogger.15604 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %Windir%No
chrome.exeXchrome.exeDetected by McAfee as PWS-Zbot.gen.aru and by Malwarebytes Anti-Malware as Trojan.Agent.CRGen. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %Windir%No
Chrome.exeaXChrome.exeDetected by Dr.Web as Trojan.DownLoader6.8983 and by Malwarebytes Anti-Malware as Trojan.Inject. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %UserProfile%\DesktopNo
Chrome.exebXChrome.exeDetected by Dr.Web as Trojan.DownLoader6.8983 and by Malwarebytes Anti-Malware as Trojan.Inject. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %UserProfile%\Start Menu\ProgramsNo
Chrome.execXChrome.exeDetected by Dr.Web as Trojan.DownLoader6.8983 and by Malwarebytes Anti-Malware as Trojan.Inject. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %MyDocuments%No
Chrome.exedXChrome.exeDetected by Dr.Web as Trojan.DownLoader6.8983 and by Malwarebytes Anti-Malware as Trojan.Inject. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %UserProfile%\FavoritesNo
Chrome.exeeXChrome.exeDetected by Dr.Web as Trojan.DownLoader6.8983 and by Malwarebytes Anti-Malware as Trojan.Inject. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %UserProfile%\Start MenuNo
dXchrome.exeDetected by Ikarus as Trojan.Win32.VBKrypt and by Malwarebytes Anti-Malware as Trojan.Agent.CRGen. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %UserProfile%No
d5a38e9b5f206c41f8851bf04a251d26Xchrome.exeDetected by Dr.Web as Trojan.DownLoader7.13869 and by Malwarebytes Anti-Malware as Backdoor.Bot. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %Temp%No
d5a38e9b5f206c41f8851bf04a251d26Xchrome.exeDetected by Dr.Web as Trojan.DownLoader7.21837 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %Temp%No
d709f34a2bc48c2ecfacf26803c2c376Xchrome.exeDetected by Dr.Web as Trojan.DownLoader7.19599 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %UserProfile%No
e79d569ba77562f0d4316e586835f0a2XChrome.exeDetected by Dr.Web as Trojan.DownLoader7.10888 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %Temp%No
googleXchrome.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %AppData%No
Google ChromeXchrome.exeDetected by Dr.Web as Trojan.DownLoader4.33575. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %AppData%\GoogleNo
Google UpdateXchrome.exeDetected by Dr.Web as Trojan.MulDrop1.54424. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %AppData%No
Google UpdatesXchrome.exeDetected by McAfee as Generic Dropper. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %AppData%\Google ChromeNo
GoogleChromeXchrome.exeDetected by Dr.Web as Trojan.MulDrop4.9457. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %AppData%\GoogleChromeNo
HKCUXchrome.exeDetected by McAfee as Generic.bfr!gs and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %Root%No
HKLMXchrome.exeDetected by McAfee as Generic.bfr!gs and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %Root%No
MicroUpdateXChrome.exeDetected by Dr.Web as Trojan.DownLoader8.37127. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %Temp%\Google_chromeNo
RUNDLL32Xchrome.exeDetected by Malwarebytes Anti-Malware as Backdoor.Messa. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %AppData%\updaterNo
Yahoo MessenggerXchrome.exeDetected by Sophos as W32/Autorun-NG. Note - this is not the legitimate Google Chrome browser which is normally located in %ProgramFiles%\Google\Chrome\Application. This one is located in %System%No
Yahoo MessenggerXchrome9.exeDetected by Dr.Web as Trojan.StartPage.39111No
HKCUXchromee.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\InstallDirNo
HKLMXchromee.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\InstallDirNo
BunniesXChromesupport.exeDetected by McAfee as RDN/Generic.dx!o and by Malwarebytes Anti-Malware as Backdoor.AgentNo
NoobcakeXChromesupport.exeDetected by McAfee as RDN/Generic.dx!o and by Malwarebytes Anti-Malware as Backdoor.AgentNo
PoliciesXChromesupport.exeDetected by McAfee as RDN/Generic.dx!o and by Malwarebytes Anti-Malware as Backdoor.Agent.PGenNo
ChromeUpdateXChromeUpdate.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not a legitimate Google Chrome browser entry and the file is located in %ProgramData%\ChromeUpdateNo
chromeupdateXChromeUpdate.exeDetected by Dr.Web as Trojan.DownLoader5.27987. Note - this is not a legitimate Google Chrome browser entry and the file is located in %AllUsersProfile%\FavoritesNo
Chrome_Loader.exeXChrome_Loader.exeDetected by Microsoft as Backdoor:Win32/Dekara.ANo
chronoUchrono.exeChronograph is a simple utility that synchronizes internal computer clock to the atomic time. Chronograph automatically maintains correct time using atomic clock servers of the National Institute of Standards and Technology (NIST)." Shows seconds and shows the date without having to hover the mouse. Shows a calendar when hovered overNo
ChronographUchrono.exeChronograph is a simple utility that synchronizes internal computer clock to the atomic time. Chronograph automatically maintains correct time using atomic clock servers of the National Institute of Standards and Technology (NIST)." Shows seconds and shows the date without having to hover the mouse. Shows a calendar when hovered overNo
c3294e515629d65109551b22b924c29bXchroom.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserTemp%No
CyberhawkUCHTray.exeCyberhawk from Novatix. Protects against viruses, spyware, identity theftNo
ChronitelInitTV?CHTVINIT.EXE??No
Task ManagerXchucem.exeDetected by McAfee as W32/Chucem.wormNo
Microsoft Driver SetupXChvgrm.exeDetected by Avira as TR/Kolab.82432No
ci1gntXci1gnt.exeDetected by Kaspersky as the AGENT.DHU TROJAN!No
Windows Printing DriverXciadvs.exeAdded by the BUZUS-M TROJAN!No
Windows Printing DriverXciadvss.exeAdded by the ARCHIVARIUS series of WORMS!No
Component BrowserXcicedit.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.CD. The file is located in %System%No
WindowsFileSystemXcidaemon32.exeAdded by the RBOT-FSP WORM!No
WinXP Catalog ServiceXcidaemon32.exeDetected by Kaspersky as Backdoor.Win32.Rbot.aeuNo
Microsoft Driver SetupXcidrive32.exeAdded by the AGENT-NES TROJAN!No
cihost.exeXcihost.exeAdded by the LINST TROJAN!No
Memory Allocation HostXcihost.exeDetected by Avast as a variant of the IRCBOT-CHZ WORM!No
Microsoft Data HelperXcihost.exeMalware, possibly a variant of the LINST TROJANNo
CIJ2P2PSERVERYCIJ2P2PS.EXECompaq IJ200 printer utility which is required in order to make the printer work correctlyNo
CIJ3P2PSERVERYCIJ3P2PS.EXECompaq IJ300 printer utility which is required in order to make the printer work correctlyNo
CIJ7P2PSERVERYCIJ7P2PS.EXECompaq IJ700 printer utility which is required in order to make the printer work correctlyNo
CIJ9P2PSERVERYCIJ9P2PS.EXECompaq IJ900 printer utility which is required in order to make the printer work correctlyNo
NTdhcpXCiKewl.exeAdded by the QQROB-N TROJAN!No
CimSyncUcimsync.exeProficy CIMPLICITY by GE - "is a client/server based visualization and control solution that helps you visualize your operations, perform supervisory automation and deliver reliable information to higher-level analytic applications"No
CinemaNowMediaManagerAppUCinemanowShell.exeMedia manager for the CinemaNow digital video distribution serviceNo
Cingular Communication ManagerYCingularCCM.exeCingular Communication Manager - now taken over by AT&T. "provides a robust set of wireless communication tools for businesses and individuals. With wireless access to email, the Internet, business applications and corporate intranets, mobile users can be more productive while they're out of the office"No
SoftwareXcipsn.exeAdded by the FORBOT-DM WORM!No
Duwee wong CerbonXCirebons.exeAdded by the BHARAT.A WORM!No
AutoVirusProtectionXciscv.exeAdded by a variant of Win32/RbotNo
boguzooXcisepud.exeDetected by Dr.Web as Trojan.DownLoader8.36444No
Memory Allocation ServerXciserv.exeDetected by Microsoft as Worm:Win32/Slenfbot.BHNo
Memory Allocation ServicesXcisrv.exeAdded by the IRCBOT.FC BACKDOOR!No
CISrvr ProgramNCISRVR.EXERelated to internet setup on Compaq PC'sNo
CissiXCissi.exeAdded by the CISSI.A WORM!No
FamilyKeyLoggerUcisvc.exeFamily Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Located in %ProgramFiles%\FamilyKeyLoggerNo
loadXcisvc.exeAdded by the DOWNBOT TROJAN!No
CisvcXcisvc.exe /waitserviceDetected by Microsoft as TrojanDownloader:Win32/Horst.Q and by Malwarebytes Anti-Malware as Backdoor.Agent. Note - this is not the legitimate cisvc.exe which is always located in %System%. This one is located in either %Windir%, %Windir%\System, %Temp%, %AppData%, %AppData%\Microsoft or %System%\driversNo
Ci SvrXcisvr.exeAdded by the IRCBOT.AWN BACKDOOR!No
CitiUCSUCitiUCS.exeCitibank Virtual Account Numbers - "With this free service for Citi cardmembers, you never have to give out your real credit card number online"No
CitiVANNCitiVAN.exeOption from Citibank to change a credit card number in a random fashion for each purchase. The number will only be used once and never againNo
CivaXCiva.exeAdded by the SDBOT.ARI WORM!No
Windows Loader ServiceXcivsc.exeAdded by a variant of Win32/RbotNo
RunmeAtStartupXcj.exeDetected by Dr.Web as Trojan.DownLoader5.31016 and by Malwarebytes Anti-Malware as Trojan.AgentNo
cjbXcjb*.exeAdded by a variant of the AGENT.ALZE TROJAN - where * is a random digit and the file is located in %ProgramFiles%\cjbNo
cjbXcjb.exeAdded by the AGENT.ALZE TROJAN!No
CJETXCJet.exeFFToolBar adware toolbarNo
CjstcomYCjstcom.exeCanon printer BJ status language monitorNo
BJ Status Monitor 522UCJSTR3G.EXECanon printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor 530UCJSTR4B.EXECanon printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor 550UCJSTR4Y.EXECanon printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor 600UCJSTR5I.EXECanon printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Printer Status MonitorNCjstsr.exeCanon BJ printer status monitorNo
CleverKeysUCK.exeCleverKeys - "is free software that provides instant access to definitions at Dictionary.com, synonyms at Thesaurus.com, facts at Reference.com and more - from almost all Windows programs, including word processors, Web browsers and most e-mail programs"No
CKAUCKA.exePart of Symantec's now discontinued Norton SystemWorks security and utility suite. Keeps a dial-up modem connection aliveYes
SymKeepAliveUCKA.exePart of Symantec's now discontinued Norton SystemWorks security and utility suite. Keeps a dial-up modem connection aliveYes
ckhfs4Xckhfs4.exeDetected by Microsoft as PWS:Win32/Frethog.ADNo
MSConfigXckme.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%No
startkeyXCKOTS.exeAdded by the BIFROSE-HM TROJAN!No
kamsoftXckvo.exeAdded by the GAMANIA-BW TROJAN!No
[various names]Xclamav.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
ClamWinYClamTray.exeSystem Tray access to and notifications for ClamWin free antivirusNo
eckoXclaro.exeAdded by the DLOADR-AQJ TROJAN!No
RegistryUclass0117[random].exeBlackbox captures emails and chat logs, and monitors Internet activity - remove if you didn't intentionally install itNo
class454~@#Uclass454.exeXPSpy surveillance software. Uninstall this software unless you put it there yourselfNo
Classic Start MenuYClassicStartMenu.exeClassic Start Menu (part of Classic Shell by Ivo Beltchev) - "is a clone of the original start menu, which you can find in all versions of Windows from 95 to Vista. It has a variety of advanced features"No
Clavier+UClavier.exeClavier+ allows you to "create keyboard shortcuts using almost any keys, including the Windows key"No
clcbt.exeXclcbt.exeAdded by the AGENT.CBA TROJAN!No
CLCLSetUCLCL.exeCLCL clipboard caching utilityNo
clcl3Xclcl3.exeAdded by the AGENT.ES TROJAN!No
clcl7Xclcl7.exeAdded by a variant of the Covert Sys Exec TROJAN!No
f01489ae591474641e456c050c1db1d7XClean.exeDetected by Dr.Web as Trojan.DownLoader7.29749 and by Malwarebytes Anti-Malware as Trojan.MSILNo
SystemCleanerXClean2.exeAdded by the AUTORUN-AZE WORM!No
CleanEasyImg?cleanall.exe??No
CleanatorXCleanator.exeCleanator rogue privacy program - not recommended, removal instructions hereNo
CleanCatchMainXCleanCatch.exeCleanCatch rogue security software - not recommended, removal instructions hereNo
cleancertXcleancert.exeCleancert rogue security software - not recommended, removal instructions hereNo
PAL Evidence EliminatorNCleaner.exePAL Evidence Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basisNo
Windows SleepXCleaner.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.BCM. The file is located in %AppData%No
MCleanerComXCleanerComLaunch.exeCleanerCom rogue security software - not recommended, removal instructions hereNo
cleanhlcXcleanhlc.exeDetected by Dr.Web as Trojan.DownLoader2.57773 and by Malwarebytes Anti-Malware as Backdoor.BotNo
cleanhtmXcleanhtm.exeAdded by the MDROP-DPE TROJAN!No
cleanmanagerSXcleanmanagerU.exeCleanManager rogue security software - not recommended. One of the OneScan family of rogue scanner programsNo
Clean MgrXcleanmg.exeAdded by the IRCBOT.BBO BACKDOOR!No
winlogonXcleanmg.exeDetected by Sophos as Troj/Agent-ICRNo
Adobe UpdaterXcleanmod.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. This file is located in %AppData%No
CleanRegPath?CleanReg.exeApparently Annex A ADSL modem related. What does it do and is it required?No
cleansweep.exeXcleansweep.exeAdded by the AGENT-NEU TROJAN!No
CleanTempUCleanTemp.exeCleanTemp - automatically deletes the contents of the %Temp% folder that is used to store temporary files at Windows startup and uses no memory or processing powerNo
CleanTemp 1.5UCleanTemp.exeVersion 1.5 of CleanTemp - which automatically deletes the contents of the %Temp% folder that is used to store temporary files at Windows startup and uses no memory or processing powerYes
UCS Clean TempUCleanTemp.exeVersion 1.5 of CleanTemp - which automatically deletes the contents of the %Temp% folder that is used to store temporary files at Windows startup and uses no memory or processing powerYes
CleanTempUCLEANT~1.EXECleanTemp - automatically deletes the contents of the %Temp% folder that is used to store temporary files at Windows startup and uses no memory or processing powerNo
CleanTemp 1.5UCLEANT~1.EXEVersion 1.5 of CleanTemp - which automatically deletes the contents of the %Temp% folder that is used to store temporary files at Windows startup and uses no memory or processing powerYes
adi CleanUpYCleanUp.exeUtility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards to clean-up the files no longer required once the installation is complete. Other programs/drivers may use the same filename for the same purpose. In this case, the file is located in %System% and is listed under the HKLM\RunOnce registry keyYes
CleanUpYCleanUp.exeUtility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards to clean-up the files no longer required once the installation is complete. Other programs/drivers may use the same filename for the same purpose. In this case, the file is located in %System% and is listed under the HKLM\RunOnce registry keyYes
CleanupProgram?cleanup.exeSony Vaio related - what does it do and is it required? Located in a C:\Sonysys folderNo
CleanVMainXCleanV.exeCleanV rogue security software - not recommended, removal instructions hereNo
clean_serviceXclean_service.cmdAdded by the REFAZ WORM!No
Clear meter barUClear meter bar .exeClear Meter Bar widget for the DesktopX desktop utility from Stardock Corporation. Displays free drive space, free memory, CPU usage and system running time on the desktop with a clear background. Once started, Clear meter bar .exe loads a file called "DXWidget.exe" and exitsYes
DesktopX WidgetUClear meter bar .exeClear Meter Bar widget for the DesktopX desktop utility from Stardock Corporation. Displays free drive space, free memory, CPU usage and system running time on the desktop with a clear background. Once started, Clear meter bar .exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entryYes
ArcadeMovieServiceNclear.fiMovieService.exePart of Acer Arcade Deluxe - a default program included with all Acer computers for media management. Movie service by CyberlinkNo
Clear2PCXClear2PCLaunch.exeClearPC rogue security software - not recommended, removal instructions hereNo
Internet Disk CleanerUCLEARH~1.EXE"Internet Disk Cleaner from Elongsoft "protects your privacy by cleaning up all Internet tracks and past computer activities"No
Clear meter barUCLEARM~1.EXEClear Meter Bar widget for the DesktopX desktop utility from Stardock Corporation. Displays free drive space, free memory, CPU usage and system running time on the desktop with a clear background. Once started, Clear meter bar .exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Clear meter bar .exe" is shown as "CLEARM~1.EXE"Yes
DesktopX WidgetUCLEARM~1.EXEClear Meter Bar widget for the DesktopX desktop utility from Stardock Corporation. Displays free drive space, free memory, CPU usage and system running time on the desktop with a clear background. Once started, Clear meter bar .exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 entry where "Clear meter bar .exe" is shown as "CLEARM~1.EXE"Yes
ClearProtectXClearProtect.exeClearProtect rogue security software - not recommended, removal instructions hereNo
ClearVaccineMainXClearVaccine.exeDetected by Malwarebytes Anti-Malware as Rogue.ClearVaccine - not recommended. The file is located in %ProgramFiles%\ClearVaccineNo
H2OYcledx.exeRelated to copyright protection products by SyncroSoftNo
clfmonXclfmon.exeAdded by the TACTSLAY.E TROJAN!No
clfmon.exeXclfmon.exeAdded by the AGENT-BJ TROJAN!No
nvsvca32Xclfmon.exeAdded by the TACTSLAY.E TROJAN!No
SYSTEMYTXclfnom.exeDetected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %ProgramFiles%\Outlook ExpressNo
CLHomeMediaServerNCLHomeMediaServer.exeSystem Tray access to the CyberLink Live remote media access serviceYes
CyberLink LiveNCLHomeMediaServer.exeSystem Tray access to the CyberLink Live remote media access serviceYes
Microsoft Server ApplacationsXcli.exeAdded by the RBOT-GAQ WORM!No
ATICCCNcli.exe runtimeATI's Catalyst™ CONTROL CENTER. Required if you want to change graphics settings on a regular basis but you must have internet access and Microsoft's .NET framework installed. Note that this has "runtime" appended to cli.exe in the "Command" column of MSCONFIG. Recommend that start the program manually via Start → Programs → ATI Catalyst Control Center → Advanced → Restart Runtime as it can cause problems when starting WindowsNo
ATI CATALYST System TrayNCLI.exe SystemTraySystem Tray access to ATI's Catalyst™ Control Center. Note that this has "SystemTray" appended to CLI.exe in the "Command" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktopNo
VonageUclick2call.exeVonage Voice over IP Internet phone serviceNo
ClickMeNClickMe.exeClickM "JOKE" programNo
ClickoffUClickoff.exeClickoff automatically dismisses annoying dialog boxesNo
Best Buy pc appNClickOnceSetup.exe"Best Buy pc app brings you the latest in digital software, games and services. Once it's installed, all you need to do is explore and select the applications you want from our large selection of continuously updated digital content"No
clickpang.exeXclickpang.exeDetected by Dr.Web as Trojan.DownLoad3.16060 and by Malwarebytes Anti-Malware as Adware.KoradNo
ClickPotatoLiteSAXClickPotatoLiteSA.exeClickPotato adwareNo
Click Radio TunerNclickr~1.exeClickRadio - subscription service playing radio music via the internetNo
Click Tray CalendarNClickT~1.EXEClickTray Calendar - shows holidays, reminders of various anniversaries,tasks etcNo
Express ClickYesUClickYes.exe"Express ClickYes is a tiny program that runs in the system tray and automatically clicks the Yes button for the Outlook security prompt, that asks you to confirm mail sending from third party applications or access to Outlook's address book"No
CLICONFGXCLICONFG.EXEAdded by the OPASERV.T WORM!No
Cli ConfgXcliconfig.exeAdded by a variant of the SPYBOT WORM! See hereNo
DigiGuideNCLIENT.EXETV guide and reminderNo
NetWeaveClientXClient.exeDetected by McAfee as Generic.tfr!x and by Malwarebytes Anti-Malware as Trojan.AgentNo
pagmstart?client.exe??No
Windows ClientXclient.exeAdded by the BACKDR-AM BACKDOOR!No
DigiGuideNclient01.exeTV guide and reminderNo
BufferZoneYCLIENTGUI.EXEBufferZone from Trustware - "is the only security software that creates a separate environment allowing you unlimited freedom to enjoy all Internet activities without the fear of external threats"No
eSnipsUClientGW.exeeSnips Client Gateway from eSnipsNo
WIN32DSXclienttimer.exeEziin adwareNo
WIN32ioXclienttimer.exeEziin adwareNo
clipboard.exeXclipboard.exeAdded by an unidentified WORM or TROJAN!No
ClipSrvXCLIPBRD3D.EXEAdded by the MOFEI-D WORM!No
clipdiaryUclipdiary.exeClipdiary from Softvoile - "Free Clipboard Manager for keeping the clipboard history"No
ClipMate7NClipMate.exeClip Mate 7 by Thornsoft - utility that allows you to store more than one item in the clipboardNo
Clip Service ManagerXclipmg.exeAdded by the DELF.DXJ TROJAN!No
ClipMate5xNClipMt5x.exeClip Mate 5.x by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start → ProgramsNo
Clipmate6NCLIPMT60.EXEClip Mate 6 by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start → ProgramsNo
ClipomaticNClipomatic.exeMike Lin's Clipomatic is a clipboard cache program - it remembers what was copied to the clipboard even after new data is copied, and allows you to retrieve the old dataNo
ClipSrvXclipserv.exeAdded by the SDBOT-AAV and SDBOT-AFE WORMS!No
ClipSrvXclipservr.exeAdded by the SDBOT-AFE WORM!No
Clipbook ServiceNClipsrv.exeSupports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooksNo
clipsrvXclipsrv.exeDetected by Kaspersky as Trojan.Win32.Buzus.hgva. Note - this is not the legitimate clipsrv.exe which is always located in %System%. This one is located in %Windir%No
ClipsrvNClipsrv.exeSupports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooksNo
ClipSrvXclipsrv.exe /waitserviceDetected by Microsoft as TrojanDownloader:Win32/Horst.Q. Note - this is not the legitimate clipsrv.exe which is always located in %System%. This one is located in either %Windir%, %Windir%\System, %Temp%, %AppData%, %AppData%\Microsoft or %System%\driversNo
Clip ServicerXclipsrvc.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
Clip SrvXclipsv.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
ClipsvcXclipsv.exeDetected by Trend Micro as BLACKHOLE.F BACKDOOR!No
LocalSystemXclipsvr16.exeAdded by the FEMO BACKDOOR!No
LocalSystemXclipsvr32.exeAdded by the FEMO BACKDOOR!No
ClipTrakNClipTrak.exeClipTrak - clipboard extenderNo
ClipTrakkerNClipTrakker.exeCliptrakker - clipboard extenderNo
CLI ServicesXclisrv.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
ATICCCNCLIStart.exePuts the ATI Catalyst™ Control Center Icon/Shortcut on the System Tray - available via Start → ProgramsNo
Catalyst® Control Center LauncherNCLIStart.exePuts the ATI Catalyst™ Control Center Icon/Shortcut on the System Tray - available via Start → ProgramsNo
CLIStartNCLIStart.exePuts the ATI Catalyst™ Control Center Icon/Shortcut on the System Tray - available via Start → ProgramsNo
StartCCCNCLIStart.exePuts the ATI Catalyst™ Control Center Icon/Shortcut on the System Tray - available via Start → ProgramsNo
SMS Client ServiceUclisvc95.exeWhen the SMS Client service starts on a domain controller, the Client service modifies the SMSCliToknAcct & user account group membership, user rights, and account comment. The Client service then waits for the synchronization of the comment to verify that the account and user rights are properly set for this account. This account is used to obtain a token to start the SMS Client processes, such as the Software Inventory and Software Distribution agents (MS Systems Management Server)No
cllmonoXcllmono.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.TIB. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
CLMemoSysTrayNCLMemoSysTray.exeSystem Tray access to YouMemo from CyberLink - which "is an extremely intuitive way to write notes and reminders in a fun and easy environment" and is "designed specifically as a multi-touch application supporting the latest touch hardware"Yes
CLMemoSysTray ApplicationNCLMemoSysTray.exeSystem Tray access to YouMemo from CyberLink - which "is an extremely intuitive way to write notes and reminders in a fun and easy environment" and is "designed specifically as a multi-touch application supporting the latest touch hardware"Yes
CLMLServerUCLMLSvc.exeCyberLink MediaLibrary Service - installed with Power2Go and PowerCinema from CyberLink and used to manage the media libraries, providing advanced file search, browsing and tracking. Also included with versions of PowerCinema bundled (and re-branded) with systems from Acer, Dell, ASUS and others. Some report it uses excessive system and memory resourcesYes
CLMLServer for HP TouchSmartUCLMLSvc.exeCyberLink MediaLibrary Service - included with the version of CyberLink's PowerCinema installed on the HP Touchsmart range of desktops and notebooks and used to manage the media libraries, providing advanced file search, browsing and tracking. Some report it uses excessive system and memory resourcesNo
CLMLSvcUCLMLSvc.exeCyberLink MediaLibrary Service - installed with Power2Go and PowerCinema from CyberLink and used to manage the media libraries, providing advanced file search, browsing and tracking. Also included with versions of PowerCinema bundled (and re-branded) with systems from Acer, Dell, ASUS and others. Some report it uses excessive system and memory resourcesYes
CyberLink MediaLibrary ServiceUCLMLSvc.exeInstalled with Power2Go and PowerCinema from CyberLink and used to manage the media libraries, providing advanced file search, browsing and tracking. Also included with versions of PowerCinema bundled (and re-branded) with systems from Acer, Dell, ASUS and others. Some report it uses excessive system and memory resourcesYes
CLMFrontPanelUclmpanel.exeSystem tray status/display/configuration utility for a number of modems. Can be disabled by right-clicking on the tray icon. If disabled, connection status is lostNo
Content List Management SubsystemXclmss.exeAdded by the SPYBOT-EL WORM!No
QuickInstallPackXCLN_2009FreeInstall.exeInstalled and used by rogue security products such as Cleaner2009, AntiMalwareSuite, SecureExpertCleaner and System Guard CenterNo
SetDefaultPrinterYcloaker.exeUsed by HP and Compaq computers to hide the windows of programs passed as arguments to itNo
Clock Widget (HTC Home)NClock.exeClock Widget from HTC Home - which is "a free set of widgets for Windows like on HTC Smartphones." The default installation includes the QuickShare ad-supported browser enhancement which can in turn install the Delta toolbarYes
Windows InsecureXClock.exeAdded by the SDBOT.GAV WORM!No
AccessoriesPlusUclockplus.exeClock Plus, part of Accessories Plus allows you to select from dozens of alternatives for the Windows clockNo
SkinClockUClockTraySkins.exeClock Tray Skins by Drive Software - "is the advanced replacement for standard Windows tray clock. See the time, seconds, day, date, percent of memory in use and system UpTime in different skins. Displays the time for any of the time zones"No
ClockWiseUCLOCKWISE.EXEClockWise - produced by R J Software - a time utility. It is a schedueler not only for dates, but you can choose it to run programs at any time. It also updates the time by connecting to an atomic clock server. This is a spyware-free alternative to ClockSyncNo
wiseXclockwise.exeAdded by the LAZAR-A TROJAN!No
ClocXUClocX.exeClocX - places a clock on the desktop that can be moved and then changed into a calendar plus you can set alarms, etcNo
CloneCDNCloneCDTray.exeSystem Tray access to the CloneCD back-up utility from SlySoft, Inc - which is "the perfect tool to make backup copies of your music and data CDs, regardless of standard conformity. CloneCD's award-winning user interface allows you to copy almost any CD in just a few mouse clicks." Other than launching CloneCD, the only other useful option is "Hide CDR Media" which in some isolated cases will treat CD-R media as original CDsYes
CloneCD TrayNCloneCDTray.exeSystem Tray access to the CloneCD back-up utility from SlySoft, Inc - which is "the perfect tool to make backup copies of your music and data CDs, regardless of standard conformity. CloneCD's award-winning user interface allows you to copy almost any CD in just a few mouse clicks." Other than launching CloneCD, the only other useful option is "Hide CDR Media" which in some isolated cases will treat CD-R media as original CDsNo
CloneCDTrayNCloneCDTray.exeSystem Tray access to the CloneCD back-up utility from SlySoft, Inc - which is "the perfect tool to make backup copies of your music and data CDs, regardless of standard conformity. CloneCD's award-winning user interface allows you to copy almost any CD in just a few mouse clicks." Other than launching CloneCD, the only other useful option is "Hide CDR Media" which in some isolated cases will treat CD-R media as original CDsYes
[random name]XCloud AV 2012v121.exeCloud AV 2012 rogue security software - not recommended, removal instructions hereNo
cloudpop.exeXcloudpop.exeDetected by Dr.Web as Trojan.DownLoad3.5224 and by Malwarebytes Anti-Malware as Adware.K.CloudPop. The file is located in %ProgramFiles%\cloudpopNo
cloudpop_.exeXcloudpop_.exeDetected by Malwarebytes Anti-Malware as Adware.K.CloudPop. The file is located in %ProgramFiles%\cloudpopNo
cloud_.exeXcloud_.exeDetected by Dr.Web as Trojan.DownLoad3.5224 and by Malwarebytes Anti-Malware as Adware.K.CloudPop. The file is located in %ProgramFiles%\cloudpopNo
cloverXclover.exeDetected by Kaspersky as AdWare.Win32.KSG.rr and by Malwarebytes Anti-Malware as Adware.CloverPlus. The file is located in %ProgramFiles%\CloverPlusNo
clover_uXclover_updater.exeDetected by Dr.Web as Trojan.DownLoader6.2016 and by Malwarebytes Anti-Malware as Adware.CloverPlus. The file is located in %ProgramFiles%\intothemap CPNo
clover_uXclover_updater.exeDetected by Dr.Web as Trojan.DownLoader7.20450 and by Malwarebytes Anti-Malware as Adware.CloverPlus. The file is located in %ProgramFiles%\brainclan CPNo
clover_uXclover_updater.exeDetected by Dr.Web as Trojan.DownLoader7.4655 and by Malwarebytes Anti-Malware as Adware.CloverPlus. The file is located in %ProgramFiles%\KoreaMessenger CPNo
clover_uXclover_updater.exeDetected by Kaspersky as AdWare.Win32.Agent.svv and by Malwarebytes Anti-Malware as Adware.CloverPlus. The file is located in %ProgramFiles%\CloverPlusNo
ClownfishNClownfish.exeClownfish by Shark Labs - "is an online translator for all your outgoing messages in Skype. Now you could write in your native language and the recipient will receive the message translated to their language. There are different translation services you could choose from"No
WINCLPXclp.exeDetected by McAfee as RDN/PWS-Lineage!c and by Malwarebytes Anti-Malware as Spyware.OnlineGamesNo
COMODOUCLPSLA.exePart of Comodo Group's Cloud Scanner online malware service and their GeekBuddy remote support tool - which is available as a separate product and is installed (but not licensed) with their free and retail security products such as Internet Security, Antivirus and FirewallNo
Comodo Launch Pad TrayUCLPTray.exeSystem Tray access to LaunchPad - as bundled with older versions of Comodo's free offerings such as Comodo Antivirus. Some allege that LaunchPad is impossible-to-uninstall adware, or worse - see hereNo
CLPushUpdate?CLPushUpdate.exePart of the CyberLink Live remote media access service. It's exact purpose isn't know at present but it may be related to automatic updatesYes
CyberLink Live?CLPushUpdate.exePart of the CyberLink Live remote media access service. It's exact purpose isn't know at present but it may be related to automatic updatesYes
CyberLat Ram CleanerUCLRamCleaner.exeCyberLat RAM Cleaner - memory optimizer. No longer supported or available from the authorsNo
MSVersionXClrSchP038.exeAdded by the POPMON.A TROJAN - also known as PopMonster adwareNo
Windows System32Xclsas32.exeAdded by the RBOT-AZO WORM!No
Windows System32 DriverXclsass32.exeAdded by the SDBOT-AGG WORM!No
clsavXclsav.exeAdded by the AUTORUN-BTQ WORM!No
APVXDWINYClShield.exe"Panda ClientShield with TruPrevent is designed for companies that want the best protection for their workstations. It protects against viruses and other known and unknown threats including spam, spyware, dangerous or time-wasting content, phishing scams, hackers and intruders"No
winsrvXclsnsv.exeDetected by Malwarebytes Anti-Malware as Trojan.Korad. The file is located in %ProgramFiles%No
cls_pack.exeXcls_pack.exeAdded by the Malware Defense rogue security software. Also detected as the FAKEAV-AQB TROJAN!No
ClauerUpdateUClUpdate.exeAutomatic updates for the software supporting the Clau-ACCV and Clauer-idCAT digital certificate USB keysNo
ClUpdateUClUpdate.exeAutomatic updates for the software supporting the Clau-ACCV and Clauer-idCAT digital certificate USB keysNo
CleverKeysUClvrKeys.exeOlder version of CleverKeys - which "is free software that provides instant access to definitions at Dictionary.com, synonyms at Thesaurus.com, facts at Reference.com and more - from almost all Windows programs, including word processors, Web browsers and most e-mail programs"No
Start RF Wireless MouseYcm20.exeYuanxun Electronics RF wireless mouse driverNo
cmaUcma.exeDeskSite CMA siftware - "retrieves new content from the DeskSite Data Center"No
Desksite CMAUcma.exeDeskSite CMA siftware - "retrieves new content from the DeskSite Data Center"No
CyberMedia AgentNCMAGENT.EXEPart of CyberMedia's Oil Change program. Not normally required. Note - if you have TextBridge, CyberMedia Agent may attach itself to TextBridge and cause TextBridge to crash everything if this is disabledNo
MachineTestXCMagesta.exeAdded by the SDBOT-NE WORM!No
cnfgCavYCMain.exePart of an older version of Comodo AntivirusNo
Connection ManagerNCManager.exeSBC Yahoo DSL service connection manager. You can connect from the network connections. Users having problems with this have been advised to uninstall the connection manager via Add/Remove Programs and it won't affect the serviceNo
CMAPPXcmappclient.exeCasClient adware - also detected as the CMAPP TROJAN!No
8abe4a316ecd3fb8d5ff2f6f776d9ce3Xcmd.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate cmd.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%No
aXcmd.exeDetected by Dr.Web as Trojan.DownLoader6.3470. Note - this is not the legitimate cmd.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%\DesktopNo
bXcmd.exeDetected by Dr.Web as Trojan.DownLoader6.3470. Note - this is not the legitimate cmd.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%\Start Menu\ProgramsNo
cXcmd.exeDetected by Dr.Web as Trojan.DownLoader6.3470. Note - this is not the legitimate cmd.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %MyDocuments%No
cmdXcmd.exeDetected by Dr.Web as Trojan.Siggen4.27324. Note - this is not the legitimate cmd.exe process which is always located in %System% and should not normally figure in Msconfig/Startup. This one is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
dXcmd.exeDetected by Dr.Web as Trojan.DownLoader6.3470. Note - this is not the legitimate cmd.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%\FavoritesNo
eXcmd.exeDetected by Dr.Web as Trojan.DownLoader6.3470. Note - this is not the legitimate cmd.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%\Start MenuNo
hpcmdXcmd.exeDetected by Sophos as Troj/AdClick-DS. Note - this is not the legitimate cmd.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\spoolNo
name_meXcmd.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader. Note - this is not the legitimate cmd.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %MyDocuments%No
Win32 ConsoleXcmd.exeAdded by the ABI.C WORM! Note - this is not the legitimate cmd.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
WMSDOS-ServicePack2Xcmd.exe /c C:\WMSDOS.sysDetected by Bitdefender as the DELF.OFC TROJAN! See here. Note that cmd.exe is a legitimate Microsoft file normally located in %System% and shouldn't be deletedNo
Sistema OperacionalXcmd.exe [path] aaa.batDetected by Symantec as Trojan.Banker.I. Note - do not delete the legitimate cmd.exe process which is always located in %System%. The "aaa.bat" file is located in %Temp%No
AMD AVT?Cmd.exe [path] kdbsync.exeRelated to AMD's Accelerated Video Transcoding (AVT) architecture which helps speed up video conversations. "AVT is a combination of hardware and low level software to convert H.264 and MPEG-2 video sources, up to 1080p resolution, to H.264 MPEG-2 file format to fit the target device supported resolutions and bitrates, up to 1080p resolution" - read more in this PDFNo
Dynamic Dns BinaryXCMD16.EXEAdded by the RBOT-XM WORM!No
Ass and tittiesXCMD32.EXEAdded by a variant of W32/Sdbot.wormNo
CmdXcmd32.exeAdded by the TANKED WORM!No
Configuration LoaderXcmd32.exeAdded by the SDBOT BACKDOOR!No
ControlPanelXcmd32.exe internat.dll,LoadKeyboardProfileAdded by the DLOADER-HF TROJAN. Note - the "cmd32.exe" file is found in %System%No
cmd64Xcmd64.exeCoolWebSearch Msconfd parasite variantNo
HKCUXcmdagent.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\Sys32No
HKLMXcmdagent.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\Sys32No
PoliciesXcmdagent.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\Sys32No
cmdbcsXcmdbcs.exeAdded by the LINEAG-GKW TROJAN!No
CmdconXcmdcon.exeAdded by the CRYPTER.A TROJAN!No
TrueMobile 1150 Client ManagerYcmdel.exeClient Manager for the Dell TrueMobile 1150 Series PC Card - "a wireless network PC Card that fits into any standard PC Card Type II slot. It has two LED indicators and an integrated antenna"No
CMDHostXCMDHost#.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.Gen - where # represents a number and the file is located in %AppData%No
cmdl32Xcmdl32.exeDetected by Kaspersky as Trojan.Win32.Buzus.hgvaNo
cmdl32.exeXcmdl32.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserTemp%No
relinsonXcmdno.exeAdded by the DROPPER-PS TROJAN!No
Cinnabd Prompt32XCmdPrompt32.pifAdded by the ASSIRAL-B WORM!No
Command Prompt32XCmdPrompt32.pifAdded by the ASSIRAL.B WORM!No
MyLifeXCmdServ.exeDetected by Trend Micro as WORM_HOLAR.ANo
CmdShell.exeXCmdShell.exeAdded by the BCKDR-QHY BACKDOOR!No
MsgSvcMgr32Xcmdzxdll.exeAdded by the RBOT-AEK WORM!No
CMEXcme.exeGAIN adware by Claria CorporationNo
Check MessengerUcmesseng.exeCheck Messenger from Qchex.com - program that helps you manage the activity of your Qchex account. Qchex appear to be no longer in buisnessNo
CmeSYSXCMEsys.exeGAIN adware by Claria CorporationNo
CmeUPDXCMEupd.exeGAIN adware by Claria CorporationNo
COMODO Memory FirewallYcmf.exe"Comodo Memory Firewall is a buffer overflow detection and prevention tool which provides the ultimate defence against one of the most serious and common attack types on the Internet - the buffer overflow attack." Now discontinuedNo
CMFibulaXCMFibula.exeCASClient adwareNo
CmFlywaveNameNCmFlywav.exeDriver for the Cisco Linksys WMB54G Wireless-G Music BridgeNo
CMGrdianUCMGrdian.exeMcAfee Guardian shortcut menu on the System Tray (looks like a castle) given access to Internet Security, Browser Buddy, File Guardian and help. Included with older versions of McAfee Internet Security and possibly othersNo
GuardianUCMGrdian.exeMcAfee Guardian shortcut menu on the System Tray (looks like a castle) given access to Internet Security, Browser Buddy, File Guardian and help. Included with older versions of McAfee Internet Security and possibly othersNo
McAfee GuardianUCMGrdian.exeMcAfee Guardian shortcut menu on the System Tray (looks like a castle) given access to Internet Security, Browser Buddy, File Guardian and help. Included with older versions of McAfee Internet Security and possibly othersNo
CMGShieldUIUCMGShieldUI.exeUI for CMG (CREDANT Mobile Guardian) Shield from Credant Technologies. "The CMG Shield resides on devices and external media to enforce security policies even if the device is disconnected from the network." Used to protect sensitive corporate on laptops, handhelds, smartphones, USB drives and CD-DVDsNo
Microsft Security Monitor ProcessXcmh.exeAdded by the EGGDROP.V WORM!No
ORiNOCOUCmluc.exeClient Manager software for a Proxim ORiNOCO 11a/b/g wireless LAN PCI cardNo
CMManXCMMan.exeAdded by the CMAPP TROJAN!No
sysupdateXcmman32.exeAdded by the VB.AMX TROJAN!No
Microsoft Connection Manager MonitorXcmmon.pifDetected by Sophos as W32/Rbot-AKVNo
cmmon32.exeXcmmon32.exeDetected by Dr.Web as Trojan.Inject1.13506 and by Malwarebytes Anti-Malware as Trojan.InjectNo
Cmmon32SysXcmmon32.exeAdded by the SMALL.CL TROJAN!No
msysXcmmon32.exeDetected by Kaspersky as AdWare.Win32.BHO.dzd. The file is located in %Windir%No
asr_otokXcmmoosk.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor.SK. The file is located in %System%No
run=Ncmmpu.exeMIDI emulator driver for the integrated sound chip by C-Media based on the CMI-8330 chip set normally found in cheap motherboards. Also installed as part of the software for a Guillemot Maxi Muse sound card (PCI)No
Windows Disk ManagerXcmnvc.exeAdded by the SLENFBOT.JR WORM!No
[various names]Xcmon14.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
DC300 MonitorUcmonitor.exeMonitor for a Acer DC300 digital cameraNo
Task AlertXcmosvc.exeAdded by a variant of the IRCBOT BACKDOOR!No
[12 random characters]Xcmpbk321.exeIeDriver adware variantNo
CMPDPSRVUCMPDPSRV.EXEPrinter Driver Plus from ViewAhead Technology (formerly DeviceGuys, Inc.). "Printer Driver Plus seamlessly integrates all the necessary components of a printer driver, plus more". Installed with some Compaq and Lexmark printersNo
cmrsfXcmrsf.exeAdded by the DELF-HU TROJAN!No
cmrssXcmrss.exeDetected by Trend Micro as TROJ_DELF.DU and by Malwarebytes Anti-Malware as Trojan.BankerNo
cmrstXcmrst.exeAdded by the BANCOS.S TROJAN!No
cmrstXcmrst.scrAdded by the DLOADER-FP TROJAN!No
Microsoft System32 UpdateXcmsrg.exeAdded by the RBOT-GN WORM!No
Ethernet DriverXcmsrrs.exeAdded by a variant of Win32/RbotNo
cmssXcmss.exeDetected by Kaspersky as Trojan.Win32.Agent2.eko. The file is located in %Temp%No
IntellRaidConfigurerXcmss.exeDetected by Dr.Web as Trojan.AVKill.15254 and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %ProgramFiles%\JavaUpdaterNo
IntellRaidConfigurerXcmss.exeDetected by Dr.Web as Trojan.AVKill.22183 and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %ProgramFiles%\GoogleUpdaterNo
IntellRaidConfigurerXcmss.exeDetected by Dr.Web as Trojan.DownLoader7.21665 and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %ProgramFiles%\WinAppsNo
Microsoft UpdateXcmss.exeDetected by Sophos as W32/Rbot-ATQNo
MicrosofUpdateXcmss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %ProgramFiles%\ConfigSysNo
Windows CMS ProtocolXcmss.exeDetected by Sophos as W32/Rbot-BFTNo
Microsofts UpdatezXcmsssr.exeAdded by unidentified malware. The file is located in %System%No
CmSTPXcmstp.exe /waitserviceDetected by Microsoft as TrojanDownloader:Win32/Horst.Q. Note - this is not the legitimate cmstp.exe which is always located in %System%. This one is located in either %Windir%, %Windir%\System, %Temp%, %AppData%, %AppData%\Microsoft or %System%\driversNo
CMSystemXCMSystem.exeCASClient adwareNo
Cmt101Xcmt101.exeAdded by the GEMA TROJAN!No
CmUCRRun?CmUCReye.exeRelated to Medion Display Information. What does it do and is it required?No
ClickmonsterXCMupdate.exeDetected by McAfee as Generic.tfr and by Malwarebytes Anti-Malware as Adware.KoradNo
cmutilXcmutil.exeAdded by the AGENT-DFN TROJAN!No
CMWorkstationUcmwkse.exeCyber Monitor 2004 by Enter - "professional billing, monitoring and management system for Internet cafes, libraries, schools, hotels and other institutions that provide computers for public use"No
Cmx32Xcmx32.exeAdded by the GEMA TROJAN!No
Windows System FileXcmxp.exeAdded by the SPYBOT.KHO WORM!No
CNAP2 LauncherUCNAP2LAK.EXECanon printer status monitor - for monitoring printer status, checking ink levels, etcNo
CNBABEXCNBABE.EXEAppears to be spyware added by KAZAA (and maybe others) that displays pop-up ads whilst you're browsingNo
Microsoft Driver SetupXcndrive32.exeAdded by a variant of the SPYBOT WORM! See hereNo
nClientXcnen.exeAdded by the DELBOT-AL WORM!No
UpdateComponentXCNF UPD.EXEAdded by the SPYBOT.GEN VIRUS!No
shambl3rXcnf.batAdded by the REMABL WORM!No
Configuration ManagerXCnfgldr.exeAdded by the SDBOT BACKDOOR!No
Cnfrm32Xcnfrm.exeAdded by the MIMAIL.D WORM!No
Cn323Xcnfrm33.exeDetected by Symantec as W32.Mimail.G@mm and by Malwarebytes Anti-Malware as Worm.AgentNo
[various names]Xcnftips.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
IJNetworkScanUtilityUCNMNSUT.EXENetwork utility available for some Canon scanners and multifunction devices. Allows the device to see computers on a network and those computers running the utility to control scanning via the Control Panel on the scanner - which saves you having to run back and forth between the scanner and your computerNo
BJ Status Monitor Canon i250Ucnmss Canon i250 (Local).exeCanon i250 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon i320Ucnmss Canon i320 (Local).exeCanon i320 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon i455Ucnmss Canon i455 (Local).exeCanon i455 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon i470DUcnmss Canon i470D (Local).exeCanon i470D printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon i550Ucnmss Canon i550 (Local).exeCanon i550 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon i560Ucnmss Canon i560 (Local).exeCanon i560 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon i850Ucnmss Canon i850 (Local).exeCanon i850 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon i860Ucnmss Canon i860 (Local).exeCanon i860 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon i865Ucnmss Canon i865 (Local).exeCanon i865 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon i950Ucnmss Canon i950 (Local).exeCanon i950 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon i9900Ucnmss Canon i9900 (Local).exeCanon i9900 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon MP110 Series PrinterUcnmss Canon MP110 Series Printer (Local).exeCanon MP110 Series printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon MP130 Series PrinterUcnmss Canon MP130 Series Printer (Local).exeCanon MP130 Series printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon MP360 Series PrinterUcnmss Canon MP360 Series Printer (Local).exeCanon MP360 Series printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon MP390 Series PrinterUcnmss Canon MP390 Series Printer (Local).exeCanon MP390 Series printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon MP700 PrinterUcnmss Canon MP700 Printer (Local).exeCanon MP700 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon MP730 PrinterUcnmss Canon MP730 Printer (Local).exeCanon MP730 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon PIXMA iP1000Ucnmss Canon PIXMA iP1000 (Local).exeCanon PIXMA iP1000 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon PIXMA iP1500Ucnmss Canon PIXMA iP1500 (Local).exeCanon PIXMA iP1500 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon PIXMA iP2000Ucnmss Canon PIXMA iP2000 (Local).exeCanon PIXMA iP2000 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon PIXMA iP3000Ucnmss Canon PIXMA iP3000 (Local).exeCanon PIXMA iP3000 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon PIXMA iP4000Ucnmss Canon PIXMA iP4000 (Local).exeCanon PIXMA iP4000 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon PIXMA iP6000DUcnmss Canon PIXMA iP6000D (Local).exeCanon PIXMA iP6000D printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon PIXMA iP8500Ucnmss Canon PIXMA iP8500 (Local).exeCanon PIXMA iP8500 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon BJC-2000Ucnmss1u.exeCanon BJC-2000 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon BJC-2100Ucnmss2f.exeCanon BJC-2100 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor S400Ucnmss2p.exeCanon S400 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor S600Ucnmss2v.exeCanon S600 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon S300Ucnmss38.exeCanon S300 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor S100Ucnmss3a.exeCanon S100 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon S100SPUcnmss3c.exeCanon S100SP printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon S9000Ucnmss3i.exeCanon S9000 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon S520Ucnmss3m.exeCanon S520 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon S750Ucnmss3q.exeCanon S750 printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon S200SPUcnmss3y.exeCanon S200SP printer status monitor - for monitoring printer status, checking ink levels, etcNo
BJ Status Monitor Canon S330Ucnmss45.exeCanon S330 printer status monitor - for monitoring printer status, checking ink levels, etcNo
Microsoft Synchronization ManagerXcnnet.exeDetected by Microsoft as Backdoor:Win32/Sdbot.NL and by Malwarebytes Anti-Malware as Backdoor.BotNo
Mspatch89Xcnqmax.exeAdded by the RANDEX.P WORM!No
CanonSolutionMenuExUCNSEMAIN.EXE"Canon Solution Menu EX immediately starts the manuals or application software that allows you to print album or calendar easily, or scan photos and documents. It is a convenient control centre for your printer, scanner or All-In-One"No
Microsoft Intrenet ExplorerXcnsg.pifAdded by the RBOT-ARO WORM!No
CanonSolutionMenuUCNSLMAIN.exeCanon's Solution Menu dialog box leads you quickly toward documentation, utilities, and help filesNo
b5700x driveXcnssr.exeAdded by the MAHA-T TROJAN!No
System Failure StatisticXcnstat.exeAdded by the RBOT-LF WORM!No
Protection CenterXcntprot.exeProtection Center rogue security software - not recommended, removal instructions hereNo
CnwiDeviceAgentYcnwida.exePart of the Canon imagePROGRAF W8400 printer management softwareNo
GARO Status MonitorUcnwism.exePrint monitor for certain Canon printersNo
CnxAdslLYCnxAdslL.exeDLink, Zoom, or Conexant modem driverNo
CnxDslTaskBarNCnxDslTb.exeConexant DSL Taskbar as used on their AccessRunner ADSL modem and others such as the Samsung AHT-E310, ZTE ZXDSL852 and TeleWell EA100BNo
WooCnxMonNCnxMon.exeWanadoo ISP (now rebranded as Orange) software related - not required - here's how to bypass itNo
ledpointerUCNYHKey.exeChicony Electronics Multimedia Keyboard Hotkey DriverNo
Windows Service AgentXco0l.exeAdded by the RBOT-GQY WORM!No
Remote Data BackupsUCOBackup.exeRemote Data Backups online system/data backup utilityNo
CobBUUCobBU.exeCobian Backup versions 6 and 7 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup option and run it manually when requiredYes
Cobian BackupUCobBU.exeCobian Backup 6 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup option and run it manually when requiredYes
Cobian Backup 6UCobBU.exeCobian Backup 6 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup option and run it manually when requiredYes
Cobian Backup 7UCobBU.exeCobian Backup 7 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup option and run it manually when requiredYes
Cobian Backup 7 ApplicationUCobBU.exeCobian Backup 7 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup option and run it manually when requiredYes
CobianUCobian.exeCobian Backup versions 8 thru 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP/Vista/7). If you don't have regularly scheduled backups then choose the startup option and run it manually when requiredNo
Cobian Backup 10UCobian.exeCobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (XP/Vista/7). If you don't have regularly scheduled backups then choose the startup option and run it manually when requiredYes
Cobian Backup 8UCobian.exeCobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup option and run it manually when requiredYes
Cobian Backup 9UCobian.exeCobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup option and run it manually when requiredYes
Cobian Backup AmanitaUCobian.exeCobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup option and run it manually when requiredYes
Cobian Backup Black MoonUCobian.exeCobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup option and run it manually when requiredYes
Cobian Backup BoletusUCobian.exeCobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (XP/Vista/7). If you don't have regularly scheduled backups then choose the startup option and run it manually when requiredYes
Cobian Backup 7 InterfaceUcobui.exeSystem Tray access to Cobian Backup 7 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when requiredYes
Cobian Backup Interface 6Ucobui.exeSystem Tray access to Cobian Backup 6 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when requiredYes
cobuiUcobui.exeSystem Tray access to Cobian Backup versions 6 and 7 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when requiredYes
DiskstartXCode.exeStartportal - Switch dialer and hijacker variant, see here. Also detected as the DELF-JE TROJAN!No
codecdirectx.exeXcodecdirectx.exeAdded by the BANLOA-AZY TROJAN!No
System ServiceXcoderxt.exeAdded by the RBOT-ALD WORM!No
CodeScanMainXCodeScan.exeCodeScan rogue security software - not recommended, removal instructions hereNo
CodeSecurityMainXCodeSecurity.exeCodeSecurity rogue security software - not recommended, removal instructions hereNo
DivxXcodll.exeAdded by the GRAVEBOT-A TROJAN!No
Compd Service DrivrsXcodq.exeAdded by a variant of W32/Sdbot.wormNo
COEMsgDisplay?COEMsgDisplay.exePart of HP's PC Common Operating Environment (PC COE) project. Located in %ProgramFiles%\Hewlett-Packard\PC COE. What does it do and is it required?No
xcrxXCoffin Of Evil.exeDetected by Malwarebytes Anti-Malware as Worm.Autorun. The file is located in %System%\sohaibNo
xcrxXCoffin Of Evil.exeDetected by Kaspersky as Trojan-Dropper.Win32.Agent.airs. The file is located in %System%\dtgjdtjgdtNo
xcrxXCoffin Of Evil.exeDetected by Kaspersky as Trojan.Win32.Pincav.qyd. The file is located in %Windir%No
xcrxXCoffin Of Evil.exeDetected by Kaspersky as Trojan-Dropper.Win32.Agent.airs. The file is located in %System%No
xcrxXCoffin Of Evil.exeDetected by Kaspersky as Trojan.Win32.Refroso.augc. The file is located in %System%\windowsdirectoryNo
xcrxXCoffin Of Evil.exeDetected by McAfee as Generic Dropper!mm. The file is located in %ProgramFiles%No
xcrxXCoffin Of Evil.exeDetected by McAfee as BackDoor-EDP. The file is located in %System%\fdNo
xcrxXCoffin Of Evil.exeDetected by Trend Micro as BKDR_SPYNET.SMA. The file is located in %System%\MicrosoftNo
xdocxXCoffin Of Evil.exeDetected by Malwarebytes Anti-Malware as Worm.Autorun. The file is located in %System%\sohaibNo
xdocxXCoffin Of Evil.exeDetected by Kaspersky as Trojan-Dropper.Win32.Agent.airs. The file is located in %System%\dtgjdtjgdtNo
xdocxXCoffin Of Evil.exeDetected by Kaspersky as Trojan.Win32.Pincav.qyd. The file is located in %Windir%No
xdocxXCoffin Of Evil.exeDetected by Kaspersky as Trojan-Dropper.Win32.Agent.airs. The file is located in %System%No
xdocxXCoffin Of Evil.exeDetected by Kaspersky as Trojan.Win32.Refroso.augc. The file is located in %System%\windowsdirectoryNo
xdocxXCoffin Of Evil.exeDetected by McAfee as Generic Dropper!mm. The file is located in %ProgramFiles%No
xdocxXCoffin Of Evil.exeDetected by McAfee as BackDoor-EDP. The file is located in %System%\fdNo
xdocxXCoffin Of Evil.exeDetected by Trend Micro as BKDR_SPYNET.SMA. The file is located in %System%\MicrosoftNo
xcrxccXCoffin Of Evile.exeDetected by Malwarebytes Anti-Malware as Trojan.VBAgent. The file is located in %System%\winupdadNo
xdocxccXCoffin Of Evile.exeDetected by Malwarebytes Anti-Malware as Trojan.VBAgent. The file is located in %System%\winupdadNo
cogadXcogad.exeAdded by the DLOADR-CEP TROJAN!No
AntivirusltcUpddatesXcoin.exeDetected by McAfee as Downloader.a!d2i and by Malwarebytes Anti-Malware as PUP.BitCoinMiner.AINo
safe360Xcoiome.exeDetected by Dr.Web as Trojan.StartPage.46605 and by Malwarebytes Anti-Malware as Trojan.StartPage. The file is located in %CommonFiles%\sgcscvyNo
safe360Xcoiome.exeDetected by Dr.Web as Trojan.StartPage.52312 and by Malwarebytes Anti-Malware as Trojan.StartPage. The file is located in %CommonFiles%\sfbsbvyNo
safe360Xcoiome.exeDetected by Kaspersky as Trojan-Dropper.Win32.StartPage.eba and by Malwarebytes Anti-Malware as Trojan.StartPageNo
safe360Xcoiome.exeDetected by Sophos as Mal/FtpBot-A and by Malwarebytes Anti-Malware as Trojan.StartPage. The file is located in %CommonFiles%\sfbsbvxNo
UserinitXcologsver.exeDetected by Trend Micro as TROJ_DROPPER.DJO and by Malwarebytes Anti-Malware as Trojan.AgentNo
siscolorUcolor.exeProbably on-board graphics related based upon the SiS chipsets. Has been seen on ASUS motherboards with SiS chipsets and known to cause conflicts if you choose another graphics card and disable the on-boardNo
colorealUcoloreal.exeMakes colours sharper and brighter, but will only work with coloreal capable monitorsNo
WCOLOREALUcoloreal.exeMakes colours sharper and brighter, but will only work with coloreal capable monitorsNo
ColtsScreenServerUColtsScreenServer.exeScreensaver for the Indianapolis Colts NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supportedNo
ColtsScreenServerSvcUColtsScreenServer.exeScreensaver for the Indianapolis Colts NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supportedNo
Wind0ws Ser7ice AgentXcolwindos.exeAdded by the RBOT-GQO WORM!No
CLSIDXcom.exeNowOnline - Switch dialer and hijacker variant, see hereNo
Microsoft Security Monitor ProcessXcom.exeAdded by a variant of the IRCBOT BACKDOOR!No
ComAgentUComAgent.exeComAgent - MDaemon's instant messaging clientNo
comandoXcomando.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.DF. The file is located in %LocalAppData%No
combo.exeXcombo.exeAdded by the CHIMO-C TROJAN!No
MaxtorComboYComboButton.exeRequired to be able to use the Maxtor OneTouch button on your external Maxtor harddrive. It is used to start up backup software (Retrospect)No
combop.exeXcombop.exeAdded by the BOWFEED-A TROJAN!No
comcfgXcomcfg.exeAdded by the TOADCOM.A BACKDOOR!No
comctl32Xcomctl32.exeAdware - detected by Kaspersky as the AGENT.AM TROJAN!No
VB_runXcomctl_32.exeDubious downloader from densmail.comNo
NB Common Dialog EnhancementsNCOMDLGEX.EXEPart of McAfee Nuts & Bolts. With Common Dialog Enhancements, you can add MRU list box to open dialogsNo
CC2KUIXcomet.exeComet Cursor adwareNo
SSWPlauncherXcomet.exeComet Cursor adwareNo
mssysintXcomime.exeAdded by the NETSNAKE-I TROJAN!No
cimoneXcomine.exeDetected by Trend Micro as TROJ_VB.FPWNo
WindowsXcomine.exeDetected by Dr.Web as Trojan.StartPage.45589 and by Malwarebytes Anti-Malware as Spyware.PasswordNo
COM-IPNCOMIP.EXECOM-IP Virtual Modem Driver (COM-IP Creates a Fake Serial Port that allows you to use older DOS Based Communications Programs over Telnet. Type atdt host.domain.com instead of atdt 5551212)No
p2snetisXcomippwa.exeAdded by the SPAMTOO-AL TROJAN!No
TimerXcomm.exeAdded by the BDOOR-IP BACKDOOR!No
PgzuwhzfnXcomma.exeAdded by the AGENT-QTH TROJAN!No
COMMANDXcommand.exeAdded by the QQPASS.E TROJAN!No
WinProfileXCommand.exeAdded by the BUDDY.E TROJAN!No
Messenger6Xcommand.pifAdded by the INZAE.B WORM!No
candyXcommand32.exeDetected by Sophos as W32/Rbot-LVNo
command32Xcommand32.exeAdded by the LINEADI-A TROJAN!No
Win CommandXcommand32.exeDetected by Trend Micro as WORM_AGOBOT.XQNo
IomegaWareNCOMMANDER.EXEUsed by Iomega drives. Details of its purpose can be found here. Available via Start → ProgramsNo
System FirewallsXcommandprompt32.exeDetected by Trend Micro as WORM_RBOT.BJTNo
Browser LauncherUCommandr.exeLogitech internet keyboard "Commander" software - loads the software for the shortcut keys on the keyboard. Not required unless you want to use the short cut keysNo
zBrowser LauncherUCommandr.exeFor a Logitech internet keyboard - loads the software for the shortcut keys on the keyboard. Also used to display your keyboard LEDs on-screen to indicate Caps Lock, etc if it doesn't have themNo
CommCtrNcommctr.exe"Net2Phone CommCenter® is software that allows you to make phone calls and send faxes to anywhere in the world"No
Windows Common Files ManagerXCommgr.exeDetected by Kaspersky as Worm.Win32.AutoRun.hfp and by Malwarebytes Anti-Malware as Worm.AutoRunNo
Comm DriverUcommh32.exeG Data "PC Spion". PC monitoring and surveilling software, captures all users activity on the PC, see here. Disable/remove if you didn't install it yourself!No
Windows Hijack Protection SystemXcommngr.exeAdded by a variant of Troj/Agent-FYD. The file is located in %System%\ComNo
printer spoolerXcommonaccess.exeDetected by Sophos as Troj/Delf-LBNo
Communications_HelperYCommunications_Helper.exeEntry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also, if it's disabled the camera will not work - at least not in the QuickCapture modeYes
Communications_Helper.exeYCommunications_Helper.exeEntry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also, if it's disabled the camera will not work - at least not in the QuickCapture modeYes
LogitechYCommunications_Helper.exeEntry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also, if it's disabled the camera will not work - at least not in the QuickCapture modeYes
LogitechCommunicationsManagerYCommunications_Helper.exeEntry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also, if it's disabled the camera will not work - at least not in the QuickCapture modeYes
CommunicatorYCommunicator.exeMicrosoft Office Communicator - an integrated communications client that allows information workers to communicate in real time using a range of different communication options, including instant messaging (IM), voice, and video. Now replaced by Microsoft LyncNo
Windows Hijack ProtectionXcomngr.exeDetected by Sophos as Troj/Agent-FYDNo
ComodoXComodo.exeDetected by McAfee as BackDoor-FAJ and by Malwarebytes Anti-Malware as Backdoor.Agent.CM. Note - this is not a valid entry for Comodo security productsNo
PandaXComodo.exeDetected by McAfee as BackDoor-FAJ and by Malwarebytes Anti-Malware as Backdoor.Agent.CM. Note - this is not a valid entry for either Panda Security or Comodo security productsNo
Team ViewerXComodo.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not a valid entry for either the TeamViewer remote support tool or Comodo security products. The file is located in %UserTemp%No
AutoXComp.exeDetected by Malwarebytes Anti-Malware as Trojan.Inject. The file is located in %AppData%\GoogleNo
AOL CompanionUcompanion.exeThe AOL Companion is a small window that appears when you connect to the service using verison 8.0 and early builds of version 9.0. "Use the Companion to quickly get to your favourite features, including your Buddy List, Favourite Places, Address Book, and more!"Yes
Companion ModuleUcompanion.exeThe AOL Companion is a small window that appears when you connect to the service using verison 8.0 and early builds of version 9.0. "Use the Companion to quickly get to your favourite features, including your Buddy List, Favourite Places, Address Book, and more!"Yes
Compaq ConnectionsNCompaq Connections.exeSee here - "messaging service that automatically sends you support information, tips, ideas, and special offers from HP and our partners, especially designed for HP and Compaq desktop computer owners"No
Compaq Message ServerNCOMPAQ-RBA.EXEWorks with the CPQBootPerfDB (CPQBootPerfDB.exe) entry and attempts to connect with Compaq online. Sends information on the "Compaq Advisor/Compaq Message Screener" application that comes with every Compaq computer and provides feedback on how computer users use the Message Advisor. These messages appear occasionally and instruct and advise users on their computer and its use. They generally attempt to get you (these messages) to connect to Compaq's website. They may be safely disabled via (1) MSCONFIG or (2) Start → Programs → Compaq Advisor → Advisor Settings under the "advanced" tab. Not required and can cause problems. Runs as a service on an NT based OS (such as Windows 7/Vista/XP)No
Compaq Service DriversXcompaq.exeAdded by the SDBOT-AFU WORM!No
IPOT Service DriversXcompaq.exeAdded by a variant of the FUROOTKIT TROJAN!No
Compaq ConnectionsNCOMPAQ~1.EXESee here - "messaging service that automatically sends you support information, tips, ideas, and special offers from HP and our partners, especially designed for HP and Compaq desktop computer owners"No
Nvt32Xcomplaint_7251.exeAdded by the ARTIEF.B TROJAN!No
Compaq Service DriversXcompq.exeAdded by a variant of W32/Sdbot.wormNo
Compaq Service Drivers 32Xcompq32.exeAdded by a variant of W32/Sdbot.wormNo
Compaq Service DriversXcompqs.exeAdded by a variant of W32/Sdbot.wormNo
Compaqs Service DriversXcompqs.exeAdded by a variant of W32/Sdbot.wormNo
ComproRemoteUComproRemote.exeVideoMate TV tuner and capture card - remote control driverNo
ComproSchedulerDTVUComproSchedulerDTV.exeVideoMate TV tuner and capture card - schedulerNo
Comprovante.exeXComprovante.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %AppData%No
Service DriversXCompt.exeAdded by the RBOT-ZJ WORM!No
Geography TX 1.0 NTXCompuSpeed.vbsAdded by the NEWLEY-A WORM!No
CompuSpyUCompuSpy.exeCompuSpy surveillance software. Uninstall this software unless you put it there yourselfNo
bd29411177661e07f018c457c7359458Xcomputer.exeDetected by Dr.Web as Trojan.DownLoader8.37156 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJNo
CompanionWizardXcompwiz.exePart of WinAntiVirusPro 2007 rogue security software (and possibly others) - not recommended, see hereNo
Microsft Corporation Version 2001.12.4414Xcomrel.exeAdded by a variant of the SDBOT BACKDOOR!No
ComReplXcomrepl.exe /waitserviceDetected by Microsoft as TrojanDownloader:Win32/Horst.Q. Note - this is not the legitimate comrepl.exe which is always located in %System%. This one is located in either %Windir%, %Windir%\System, %Temp%, %AppData%, %AppData%\Microsoft or %System%\driversNo
Microsft Corporation Version 2002.12.2414Xcomserv.exeAdded by the BUZUS.CL TROJAN!No
COMSMDEXENcomsmd.exe3Com tray iconNo
COMServerXcomsrvr.exeAdded by the AGENT.CWSH TROJAN!No
Meeting ConnectionXcomsutil.exeAdded by the PPDOOR-E TROJAN!No
SMSERIALWORKSTARTERXcomsysobj.exeAdded by the FAKEALERT-AH TROJAN! Installed with the SpyBurner spyware remover - which is not recommended, see hereNo
comxtXcomxt.exeAdded by the COMXT TROJAN!No
mlibsysmcXcomzcinc.exeAdded by the SDBOT-CXS WORM!No
ConnectionCenterUconcentr.exeCitrix Connection CenterNo
Concurre?concurre.exe??No
Zekio StartupsXcondll.exeAdded by the AGOBOT-AGD WORM!No
Microsoft Firewall Settings LoaderXconf32.exeAdded by the SDBOT-KM BACKDOOR!No
confbckpXconfbckp.exeDetected by Dr.Web as Trojan.DownLoader7.22060No
Configuration LoaderXconfgldr.exeAdded by the GAOBOT.GEN!POLY WORM!No
pop3 ServerUconfig.cfgPart of HTML2POP3 - "Convert Webmail to POP3.Is also included a SMTP/POP3 tunneling system that allow send and receive email in a private network HTTP PROXY based. All connection are plugin based. Over 250 email server supported and tested"No
AolConXconfig.comAdded by the TAPLAK WORM!No
ConfigXCONFIG.EXEDetected by Trend Micro as TROJ_PSWGIP.BNo
ConfigServicesNConfig.exePart of initial setup on a Compaq PCNo
Configuration UtilityNCONFIG.EXEConfiguration and management utility for the Cisco Linksys wireless productsNo
Microsoft Config FileXconfig.exeAdded by the KILLFILES.GR TROJAN! This is malware that will attempt to delete all system dlls!No
WelcomeXCONFIG.EXEDetected by Trend Micro as TROJ_PSWGIP.BNo
Windows Config SystemXconfig.exeAdded by a variant of W32/Sdbot.wormNo
Windows Service LayerXconfig.exeAdded by the RBOT.DDJ WORM!No
Config33.exeXConfig33.exeAdded by the SDBOT.T BACKDOOR!No
SERVICESSXconfigdll.exeDetected by Malwarebytes Anti-Malware as Backdoor.Messa. The file is located in %AppData%\tmpsysNo
Configuration LoaderXconfigldr.exeAdded by the AGOBOT-PP TROJAN!No
Configuration LoadingXconfigldr.exeAdded by the AGOBOT-EC WORM!No
cmd32Xconfigs.exeHijacker, also detected as the QURL-2 TROJAN!No
Update32Xconfigs.exeHijacker, also detected as the QURL-2 TROJAN!No
configsetupXconfigsetup32.exeAdded by the AGOBOT-AFP WORM!No
SYSTEMOSRUNXconfigsys.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.RNS. The file is located in %Root%No
Palm MultiUser Config?Configtool.exeMultiUser configuration for a Palm PDA device? Is it required?No
Skype UpdateXconfigupdate.xeDetected by Dr.Web as Trojan.Siggen.65244 and by Malwarebytes Anti-Malware as Malware.Packer.nps. Note - this is not a legitimate entry for the popular Skype VOIP softwareNo
configurationXconfiguration.exeDetected by Kaspersky as Trojan-Clicker.Win32.AutoIt.m and by Malwarebytes Anti-Malware as Trojan.AutoIt. The file is located in %Windir%\configurationNo
Windows Services LayerXconfigure.exeAdded by the RBOT-GAK WORM!No
ConfigUtilityUConfigUtility.exeWireless management utility for the HWC54G Hi-Speed Wireless-G CardBus Card from Hawking Technologies, IncNo
ExplorerXconfig_.comAdded by the FLOPPY-D WORM!No
Explorer5Xconfig_.comAdded by the VB.CBG WORM!No
cartaoXconflicted.exeAdded by the DADOBRA-DV TROJAN!No
GearboxNconfsvr.exeNTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available hereNo
Configuration Loader 2Xconfuldr.exeAdded by the AGOBOT-FC WORM!No
conhostXconhost.exeDetected by McAfee as BackDoor-EXI.gen.e. Note - this is not the legitimate Microsoft Windows 7 process with the same filename which is used to host the cmd.exe console window and is located in %System%. This one is located in %AppData%\MicrosoftNo
svchostXconhost.exeAdded by variants of the BACKDOOR-EXI.GEN.E TROJAN! See examples here and here. Note - this is not the legitimate Microsoft Windows 7 process with the same filename which is used to host the cmd.exe console window and is located in %System%. This one is located in %AppData%\MicrosoftNo
Adobe update managerXconhostf.exeDetected by Dr.Web as Trojan.DownLoader7.27277 and by Malwarebytes Anti-Malware as Trojan.AgentNo
Input ManagerXconima.exeAdded by the VB-FIS TROJAN!No
conimeUconime.exeMicrosoft Console IME process which is located in %System% and is used when a Asian language is used in Windows. Not required if you don't use Asian languages. Note - if you also have the files "bfghost.exe" and "editmm.exe" present on your system this file can be used by the BFGhost 1.0 Remote Administration Tool trojanNo
conime.exeXconime.exeAdded by the AVENDOG WORM! Note - this is not the legitimate Microsoft Console IME process of the same filename which is located in %System% and is used when a Asian language is used in WindowsNo
ExplorerRunXconime.exeDetected by Trend Micro as TROJ_PROXY.ABL. Note - this is not the legitimate Microsoft Console IME process of the same filename which is located in %System% and is used when a Asian language is used in Windows. This one is located in %UserTemp%No
IMEXconime.exeAdded by the DLDR-G TROJAN! Note - this is not the legitimate Microsoft Console IME process of the same filename which is located in %System% and is used when a Asian language is used in Windows. This one is located in %Windir%No
LOCALHOSTXconime.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.Agent.CNM. Note - this is not the legitimate Microsoft Console IME process of the same filename which is located in %System% and is used when a Asian language is used in Windows. This one is located in %Windir%No
taskdayXconime.exeDetected by Sophos as Troj/Comame-E and by Malwarebytes Anti-Malware as Trojan.Agent.CN. Note - this is not the legitimate Microsoft Console IME process of the same filename which is located in %System% and is used when a Asian language is used in Windows. This one is located in %Windir%\tasksNo
Connection KeeperUConKeepM.exe"Connection Keeper is an invaluable time-saving tool for dial-up users. This free program simulates Internet browsing (at a random interval) to prevent your connection from appearing idle, thus preventing your ISP from dropping your connection due to inactivity"No
ConmgrNconmgr.exeStarts Winfax pro at startupNo
ConMgr.exeUconmgr.exeConnection Manager as used by Earthlink and others. If you need this to ensure a proper connection but don't want to connect at startup try creating your own shortcutNo
ChromeUpdateXconmsjt.exeDetected by Dr.Web as Trojan.DownLoader6.32750No
Sistema de CommXconmsyrtl.exeAdded by the AGENT-LMV TROJAN!No
Service aresXconmysys.exeAdded by the VBINJ-V WORM!No
Belkin Home Base Control CenterUConnect.exeControl Center for the Belkin Home Base network USB hub - which lets you configure and access USB devices (such as hard drives, printers and cameras) connected to it over a wired or wireless network. As well a providing System Tray access, this entry will automatically connect any attached devices that have been configured this wayYes
Belkin Network USB Hub Control CenterUConnect.exeControl Center for the Belkin Network USB Hub - which lets you configure and access USB devices (such as hard drives, printers and cameras) connected to it over a wired or wireless network. As well a providing System Tray access, this entry will automatically connect any attached devices that have been configured this wayYes
Cisco WebEx ConnectUconnect.exeCisco WebEx web conferencing - "combines desktop sharing through a web browser with phone conferencing and video, so everyone sees the same thing while you talk"No
Sametime ConnectUConnect.exeIBM Sametime - instant messaging and Web conferencing software. Formerly by LotusNo
SX Virtual LinkUConnect.exeSX Virtual Link from Silex Technology America, Inc. Utility to connect USB devicesNo
Connect2PartyXconnect2party.exeAdult content diallerNo
connectaperXconnectaper.exeDetected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Trojan.Clicker.GenNo
CONNECTAUTrayAppNCONNECTAUTrayApp.exeSystem Tray access to change update settings for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CPYes
Sony Auto Update Tray ApplicationNCONNECTAUTrayApp.exeSystem Tray access to change update settings for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CPYes
ConnectifyUConnectify.exe"Connectify Hotspot is an easy to use software router for Windows computers that utilizes your PC's built in Wi-Fi card to wirelessly share any available Internet connection with friends, co-workers, and mobile devices"No
System ServicesXconnection.exeAdded by an unidentified WORM or TROJAN!No
SBC Yahoo! Connection ManagerNConnectionManager.exeUsed to create and connect your SBC Yahoo DSL connection. This program has been reported to cause problems for some users. If you find that it causes you pc to become slow or unstable you should uninstall it (using Add/Remove programs) and manually connect your DSL connectionNo
CONNECTAuto UpdateNCONNECTScheduler.exeAutomatic update scheduler for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CPYes
CONNECTSchedulerNCONNECTScheduler.exeAutomatic update scheduler for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CPYes
CONNECTAUTrayAppNCONNECTAUTrayApp.exeSystem Tray access to change update settings for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CPYes
conmswfXconrnbne.exeAdded by the SDBOT-DEX WORM!No
conscorrXconscorr.exeDetected by Trend Micro as TROJ_DELF.DWNo
ConsXconsol32.exeHijacker - redirects to an adult content portal, where foistware like ISTBar gets stealth installedNo
CommonXconsole.exeAdded by the GITWEN.A TROJAN!No
systrasxXCONSOLES.EXEAdded by the SDBOT-NW WORM!No
Consumer InputUConsumerInput.exeConsumer Input Toolbar. Opt-in market research monitoring you browsing habits - see the FAQNo
Consumer Input Rewarded with MyPoints, Consumer InputUConsumerInputRewardedwithMyPoints, ConsumerInput.exeConsumer Input Toolbar. Opt-in market research monitoring you browsing habits - see the FAQNo
Consumer Input Rewarded with MyPoints, Consumer Input UpdateUConsumerInputRewardedwithMyPoints, ConsumerInputUa.exeConsumer Input Toolbar. Opt-in market research monitoring you browsing habits - see the FAQNo
Contacte?contacte.exeSome kind of driver?No
ContentTransferWMDetector.exeUContentTransferWMDetector.exePart of Sony's Content Transfer Software which "provides an easy way to transfer music, video, photos, and podcasts to the Walkman® playerNo
ContraviroXContraviro.exeContraviro rogue security software - not recommended, removal instructions hereNo
ContraVirusXContraVirus.exeContraVirus rogue security software - not recommended, removal instructions hereNo
ContraVirusXContraVirusPro.exeContraVirus rogue security software - not recommended, removal instructions hereNo
SandboxieControlUControl.exeSandBoxie - allows data to be read from the hard drive by an application but never written back unless you allow itNo
Windows ControlXControl.exeAdded by the GREK.A TROJAN! If there is another file with the same file name in the Windows folder, this malware overwrites it with the dropped fileNo
j6GgCXwtFMXcontrol.exe [path] j6ggcxwtfm.cplAdded by the SEFNIT.K TROJAN! The "j6ggcxwtfm.cpl" file is located in %ProgramFile%\anouicgfwkkv1vNo
[various names]Xcontrol64.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
ControlCenterXControlCenter.exeDetected by Dr.Web as Trojan.AVKill.29329 and by Malwarebytes Anti-Malware as Trojan.MSILNo
WSEP Status+ConfigurationUcontroldGUI.exeUser interface for the WatchGuard Security Event Processor (WSEP) Status/Configuration dialog box associated with the Firebox series of security products from WatchguardNo
controlkidsYcontrolkids.exeControl Kids parental control systemNo
Windows Update ControllerXcontroller.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %System%No
conuqdewuvykXconuqdewuvyk.exeDetected by McAfee as Downloader.a!dcl and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
windowspisXconvertor.exeAdded by the GENOME.AKNH TROJAN!No
converx6Xconverx6.exeDetected by Malwarebytes Anti-Malware as Trojan.Korad. The file is located in %AppData%\converx6No
CookieWallUcookie.exeCookieWall from Analog X. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you returnNo
Cookie Cop 2UCookieCop.exeCookie Cop 2 from PC Magazine - cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you returnNo
CookieJarUCookiejar.exeCookie Jar cookie manager from Jason's Toolbox. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return. No longer being actively supportedNo
CookienatorUcookienator.exeCookienator is a tool that will help you remain anonymous from search engines such as Google and other notorious web-usage trackers such as Doubleclick or OmnitureNo
CookiePatrolYCookiePatrol.exeMemory-resident spyware cookie detector - part of the original anti-malware program by PestPatrol, Inc. Acquired by CA where it became eTrust PestPatrol Anti-Spyware and then CA Anti-Spyware - which is now included in CA AntiVirus PlusYes
cookwXcookw.exePart of the ErrClean rogue system error and cleaning utility - not recommended. See hereNo
Microsoft System CheckupXCool.exeAdded by the DONK.B WORM!No
NT Logging ServiceXcool.exeAdded by the SDBOT-OO BACKDOOR!No
HELLBOT3Xcoolbot.exeAdded by the MYTOB.AB WORM!No
NortonXcoolbrogameya.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%No
CoolStartUpXCoolGramS.exeDetected by McAfee as Generic.bfr!epNo
CoolMonUCoolMon.exeCoolMon by The CoolMon Project - "will display system information in a small configurable window. Most of the application`s data is retrieved from the Windows performance counters." No longer supportedNo
HP CoolSenseUCoolSense.exeSupports the HP CoolSense Technology feature in some HP notebook PCs "that combines hardware, software, and mechanical design to dynamically manage the temperature of a notebook, and help keep you comfortable while using it"No
CopernicPerUserTaskMgrUCopernicPerUserTaskMgr.exeAutomatic tasking feature of Copernic Pro multi-search engine toolNo
hpilezeleXcoposu.exeAdded by the SDBOT.ASU WORM!No
Compaq Service DrivrsXcopq.exeAdded by a variant of Win32/RbotNo
CS UpdateXcopy /Y [path] ActivationManager.dll.upd [path] ActivationManager.dllDetected by Microsoft as Trojan:Win32/Adclicker.AJNo
Copy handlerUCopy Handler.exeCopy Handler lets you copy between hard disks, floppies, local networks, CDs, and many other storage media. Copy Handler gives you the power to pause, resume, restart, and cancel during the copying and moving processesNo
WinShowUpdateXcopy [path] winshow.new [path] winshow.dllWinshow parasiate related - from the "RunOnce" keys it replaces "winshow.dll" with a new versionNo
LiveUpdateNCopyer.exeSamsung PC Studio is a Windows-based PC program package that you can use easily to manage personal data and multimedia files by connecting a Samsung Electronics Mobile phone (GSM/GPRS/UMTS) to your PC. You can launch the update manually - see the instructions here for exampleNo
copyexXcopyex.exeAdded by the DWNLDR-IUD TROJAN!No
Resume CopyUcopyfstq.exePart of Total Copy - an improved version of the Windows copy function. Allows for resumption file copies or moves in progress when computer was shut down. Not required if your not using the program or don't care about that functionNo
Compaqs Service DriverXcopypad32.exeAdded by the SDBOT.CSO WORM!No
CP?CopyProtectionNotifier.exeRelated to Emuzed Systems and Middleware. Comes included with Windows XP Media EditionNo
Core CalendarUCore Calendar.exeCore Calendar widget for the DesktopX desktop utility from Stardock Corporation. Once started, Core Calendar.exe loads a file called "DXWidget.exe" and exitsYes
DesktopX WidgetUCore Calendar.exeCore Calendar widget for the DesktopX desktop utility from Stardock Corporation. Once started, Core Calendar.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entryYes
Core ClockUCore Clock.exeCore Clock widget for the DesktopX desktop utility from Stardock Corporation. Once started, Core Clock.exe loads a file called "DXWidget.exe" and exitsNo
Core TempUCore Temp.exe"Core Temp is a compact, no fuss, small footprint program to monitor CPU temperatureNo
Core WeatherUCore Weather.exeCore Weather widget for the DesktopX desktop utility from Stardock Corporation. Displays the current weather and forecast for up to 5 days from The Weather Channel for the selected location on the desktop. Once started, Core Weather.exe loads a file called "DXWidget.exe" and exitsYes
DesktopX WidgetUCore Weather.exeCore Weather widget for the DesktopX desktop utility from Stardock Corporation. Displays the current weather and forecast for up to 5 days from The Weather Channel for the selected location on the desktop. Once started, Core Weather.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entryYes
EA CoreNCore.exeElectronic Arts EA Link software - "gives you a secure yet simple way to download EA PC games and patches, as well as other exclusive content"No
Core CalendarUCORECA~1.EXECore Calendar widget for the DesktopX desktop utility from Stardock Corporation. Once started, Core Calendar.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Core Calendar.exe" is shown as "CORECA~1.EXE"Yes
DesktopX WidgetUCORECA~1.EXECore Calendar widget for the DesktopX desktop utility from Stardock Corporation. Once started, Core Calendar.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 MSConfig entry where "Core Calendar.exe" is shown as "CORECA~1.EXE"Yes
CoreCenterUCoreCenter.exeMSI Core Center - motherboard utility for monitoring CPU speed, voltages, temperatures and fans speeds as well as overclockingNo
CoreCenterUCORECE~1.EXEMSI Core Center - motherboard utility for monitoring CPU speed, voltages, temperatures and fans speeds as well as overclockingNo
Coreguard Antivirus 2009XCoreguard 2009.exeCoreguard Antivirus 2009 rogue security software - not recommended, removal instructions hereNo
CorelDraw ToolboxXCorelDraw.exeAdded by the SDBOT-VZ WORM!No
CorePadXCorePad.exeDetected by Dr.Web as Trojan.AVKill.29407 and by Malwarebytes Anti-Malware as Backdoor.AgentNo
CoreScanMainXCoreScan.exeCoreScan rogue security software - not recommended, removal instructions hereNo
CoreSecureMainXCoreSecure.exeCoreSecure rogue security software - not recommended, removal instructions hereNo
CoreSrvXcoresrv.exeSome IRC trojans/worms use this - see here for more informationNo
CORESYS?coresys.exe??No
Core WeatherUCOREWE~1.EXECore Weather widget for the DesktopX desktop utility from Stardock Corporation. Displays the current weather and forecast for up to 5 days from The Weather Channel for the selected location on the desktop. Once started, Core Weather.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Core Weather.exe" is shown as "COREWE~1.EXE"Yes
DesktopX WidgetUCOREWE~1.EXECore Weather widget for the DesktopX desktop utility from Stardock Corporation. Displays the current weather and forecast for up to 5 days from The Weather Channel for the selected location on the desktop. Once started, Core Weather.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 MSConfig entry where "Core Weather.exe" is shown as "COREWE~1.EXE"Yes
Core - To-Do ListUCore_ToDoList.exeCore - To-Do List widget for the DesktopX desktop utility from Stardock Corporation. Adds a "to do" task list on the desktop. Once started, Core_ToDoList.exe loads a file called "DXWidget.exe" and exitsNo
PC-Config32Xcorona.exeAdded by the CORONEX.A WORM!No
[various names]Xcorrida.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
COSUCOSCLIENT.exeSystem Tray access to the Comodo Online Storage backup utility from Comodo Group, Inc - which provides "secure and reliable online storage for home and business users"No
cosineXcosine.exeDetected by Sophos as W32/Rbot-SWNo
1DECHryGWxXCouplex.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%No
couponicaXcouponica.exeAdware - see hereNo
CowboysScreenServerUCowboysScreenServer.exeScreensaver for the Dallas Cowboys NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supportedNo
CowboysScreenServerSvcUCowboysScreenServer.exeScreensaver for the Dallas Cowboys NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supportedNo
Sistema de CommXcoxdsyrtl.exeAdded by the AGENT-NDQ TROJAN!No
(Default)XCoyFilel.exeDetected by Malwarebytes Anti-Malware as Trojan.GamesThief. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %System%No
QuicktlmeXcp.exeQuickPage - Switch dialer and hijacker variant, see here. Also detected as the SWITCH-A TROJAN!No
CP32NOTUCP32BTN.EXEFor the programmable "one-touch" buttons on HP laptops (and others?). Safe to disable if you don't use these buttonsNo
CP888M1NCP888M1.EXERelated to EZbutton quick launcher for the Media player app that comes with certain laptopsNo
CPA9P2PSERVER?CPA9P2PS.exeFound on a Compaq Presario but what is it?No
Verizon Control PadNcpad.exeControl Pad - installed with Verizon DSL accounts. Tool designed to streamline the online experienceNo
Topic cPanrXcPaner.comAdded by the SDBOT.AJP WORM!No
CPATR10UCPATR10.EXEDritek/Compal ATR10 Easy Button driver. Used on certain laptops (e.g. Toshiba, Compaq) to translate special hotkeys such as Play/Pause and ConstrastNo
Cookie PalUCPBRWTCH.EXEKookaburra Software's Cookie Pal cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you returnNo
CPBrWtchUCPBrWtch.exeKookaburra Software's Cookie Pal cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you returnNo
CPCmscl0ckXCPCmsclock.ExEAdded by the IRCFLOOD.BF TROJAN!No
CPD_EXEYCPD.EXEFirewall bundled with McAfee VirusScan 6.*No
McAfee FirewallYCPD.EXEFirewall bundled with McAfee VirusScan 6.*. Can also be listed as CPD_EXENo
Comodo FirewallUCPF.exeSystem Tray access to and notifications for an older version of Comodo Firewall by Comodo Group, IncNo
Comodo Personal FirewallYCPF.exeSystem Tray access to and notifications for an older version of Comodo Firewall by Comodo Group, IncNo
CyberPatrolNewUcphq.exe"CyberPatrol gives you maximum parental control over your kids' online activities. You have the power to filter content, such as adult sites and inappropriate applications, and set limits on when your kids can go online"No
LManagerUCPLBCL53.EXESystem Tray icon found on Acer Travelmate laptops that allow you control access to the Internet and email buttons and other computer configurationsNo
CplBTQ00NCplBTQ00.EXERelated to EZbutton quick launcher for the Media player app that comes with certain laptopsNo
CPLDBL10NCPLDBL10.EXERelated to EZbutton quick launcher for the Media player app that comes with certain laptopsNo
CPLDFL10UCPLDFL10.EXEPart of the EzButton feature on some Toshiba (and maybe others) laptops which support additional buttonsNo
CPM2YCPM.exeEntry added after installing Comodo Programs Manager by Comodo Group, Inc - which "helps users to comprehensively remove programs, drivers, services and Windows components. It monitors and records every change that a program makes to your computer so that it can completely undo those changes when it's time to uninstall." Once the system reboots it's replaced by the "COMODO Programs Manager Service (CPMService)" serviceNo
CPMonitorNCPMonitor.exeBackground process installed with versions of multimedia suites from Roxio and their CinePlayer BD/DVD player which monitors your optical drive and starts CinePlayer when a BD/DVD movie is inserted. Autoplay is normally enabled by default in Windows anyway (which you can set to use CinePlayer) or you can run CinePlayer manuallyNo
CPortPatch?cppatch.exeCPortPatch is a utility is required for Dell laptops that are using a docking station. Is it needed though?No
A1000 Settings UtilityUcpqa1000.exeCompaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan, print, copy and fax. Only required if you use these featuresNo
Compaq Print FaxXcpqa1000.exeAdded by the SDBOT.BCV WORM! Please take note of the difference between the legitimate Compaq Fax Utility Name (A1000 Settings Utility) and the name (Compaq Print Fax) used by this wormNo
CPQAcDcYCPQAcDc.exeCompaq PowerCon power management software for laptopsNo
Compaq AlerterUCPQAlert.exeCompaq's Insight Manager Agent - a tool that allows for "fault, performance, and configuration management". Recommended for corporate users only. It's best removed if installed but not wanted, rather than disabled at startup. See here for more informationNo
CPQAlertUCPQAlert.exeCompaq's Insight Manager Agent - a tool that allows for "fault, performance, and configuration management". Recommended for corporate users only. It's best removed if installed but not wanted, rather than disabled at startup. See here for more informationNo
CPQBootPerfDBNCPQBootPerfDB.EXEWorks with the Compaq Message Server (COMPAQ-RBA.EXE) entry and attempts to connect with Compaq online. Sends information on the "Compaq Advisor/Compaq Message Screener" application that comes with every Compaq computer and provides feedback on how computer users use the Message Advisor. These messages appear occasionally and instruct and advise users on their computer and its use. They generally attempt to get you (these messages) to connect to Compaq's website. They may be safely disabled via (1) MSCONFIG or (2) Start → Programs → Compaq Advisor → Advisor Settings under the "advanced" tab. Not required and can cause problemsNo
CPQCalibYCPQCalib.exeCompaq PowerCon power management software for laptopsNo
CPQDFWAGNCpqDfwAg.exeFor Compaq PC's. Runs Compaq diagnostics on every bootNo
System DLFNcpqdiaga.exeCompaq Diagnostic record system utility which allow you to view information about your computer's hardware and software configuration. Available via Start → ProgramsNo
Compaq DMINcpqdmi.exeCompaq version of the Desktop Management InterfaceNo
CPQEASYACCUcpqeadm.exeFor Compaq PC's. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keysNo
CPQEASYACCUCpqeaui.exeFor Compaq PC's. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keysNo
CpqeauiUcpqeaui.exeFor Compaq PC's. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keysNo
CompaqHW Comp Manager?cpqhcm.exeRunning on a Compaq laptop - any ideas?No
CPQInet Runtime ServiceUCpqInet.exeFor Compaq PC's. Allows AOL and Compuserve to use the Easy Access buttons for the internet. Is not required if you don't use the ISP providersNo
CPQINKAGENTNcpqinkag.exeThat is the Compaq Ink Agent for some inkjet printers, it lets users know when their ink cartridges are getting close to empty (by how many pages they have printed)No
Compaq PK DaemonUcpqkl.exeFor Compaq laptops for programming user configurable keys. Not required unless you use themNo
cpqnsUcpqnpcss.exeRelated to Compaq.Net - not required if you don't use thatNo
CompaqSystrayNcpqpscp.exeCompaq System Tray iconNo
CpqsetNCpqset.exeDefault settings software in Hewlett Packard notebookNo
CPQTEAMUcpqteam.exeThis program is bundled with HP servers. When loaded a system tray icon will be available that launches the HP Network Configuration ToolNo
cprXcprAdroar.com adware downloaderNo
CpRmtKey?CpRmtKey.EXEComponent of the Toshiba Controls. The name suggests it might be related to a remote feature? What does it do and is it required?No
cprocsvcXcproc.exeAdded by MSIL.AGENT.C TROJAN!No
control panel software serviceXcprs.exeAdded by the RBOT-FPI WORM!No
Norton Live Update ServerXcpsdv.exeDetected by Trend Micro as WORM_AGOBOT.EWNo
System DriversXcpsq32.exeAdded by the SDBOT.AXH WORM!No
Microsoft CPU Over Heat ManagerXCPU.exeAdded by the SLENFBOT.ID WORM!No
CPUCooLUCpucool.exeCPUCooL - a program to keep the processor cool when idle in "overclocked" systems. Also available via Start → Settings → Control PanelNo
MSConfigXcpuhmzsa.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.Gen. The file is located in %UserProfile%No
CPU IdleXcpuidlexp.exeAdded by the AGOBOT-BW WORM!No
Cpu Level Up help?CpuLevelUpHelp.exeOverclocking utility - part of the AI Suite system management utility included with some performance ASUS motherboards. "The CPU Level Up application allows you to overclock immediately with OC Profile presets in Windows environment wihtout the hassle of entering the BIOS". Can user's with a supported motherboard (see here) confirm whether this is required for correct operation?Yes
CpuLevelUpHelp?CpuLevelUpHelp.exeOverclocking utility - part of the AI Suite system management utility included with some performance ASUS motherboards. "The CPU Level Up application allows you to overclock immediately with OC Profile presets in Windows environment wihtout the hassle of entering the BIOS". Can user's with a supported motherboard (see here) confirm whether this is required for correct operation?Yes
CpuLevelUpHelp.exe?CpuLevelUpHelp.exeOverclocking utility - part of the AI Suite system management utility included with some performance ASUS motherboards. "The CPU Level Up application allows you to overclock immediately with OC Profile presets in Windows environment wihtout the hassle of entering the BIOS". Can user's with a supported motherboard (see here) confirm whether this is required for correct operation?Yes
CPU ManagerXcpumgr.exeAdded by the PANDEM.B WORM!No
CPUMonNCPUMon.exe"CPUMon continuously displays the updated system statistics in a floating window as well as in system tray area"No
IntelProcNumUtilityUcpunumber.exeIntel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information hereNo
CPU Power MonitorUCpuPowerMonitor.exePart of the AI Suite system management utility included with some ASUS motherboards. This entry is part of AI Gear 3 - "a utility designed to configure and support all ASUS EPU (Energy Processing Unit) features. This easy-to-use utility provides four system performance profiles that adjusts the processor frequency and vCore voltage for different computing needs." Monitors power levels and provides a System Tray icon to indicate current power saving mode which also displays a balloon giving a brief report about the current power used from the systemYes
CpuPowerMonitorUCpuPowerMonitor.exePart of the AI Suite system management utility included with some ASUS motherboards. This entry is part of AI Gear 3 - "a utility designed to configure and support all ASUS EPU (Energy Processing Unit) features. This easy-to-use utility provides four system performance profiles that adjusts the processor frequency and vCore voltage for different computing needs." Monitors power levels and provides a System Tray icon to indicate current power saving mode which also displays a balloon giving a brief report about the current power used from the systemYes
CpuPowerMonitor.exeUCpuPowerMonitor.exePart of the AI Suite system management utility included with some ASUS motherboards. This entry is part of AI Gear 3 - "a utility designed to configure and support all ASUS EPU (Energy Processing Unit) features. This easy-to-use utility provides four system performance profiles that adjusts the processor frequency and vCore voltage for different computing needs." Monitors power levels and provides a System Tray icon to indicate current power saving mode which also displays a balloon giving a brief report about the current power used from the systemYes
CpusaveXCpusave.exeAdded by the GEMA TROJAN!No
Cpusave32XCpusave32.exeAdded by the GEMA TROJAN!No
GT15J4R49VXcpuserv.exeIdentified as a variant of the Trojan.Win32.Radi.gu malwareNo
CPU Windows StatusXcpustats.exeAdded by a variant of Win32/RbotNo
CPVHOST SettingsXcpvhost.exeAdded by a variant of the SDBOT BACKDOOR!No
Microsoft CPXP ProtocolXcpxp.exeDetected by Trend Micro as WORM_RBOT.ATPNo
My ComputerXcqcags.exeAdded by the SDBOT-TJ WORM!No
CQlhkNZXCQlhkNZ.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %System%No
CQSCP2PS?CQSCP2PS.EXE"Compaq printer utility which is required in the startup menu in order to make the printer work correctly". Is it actually required?No
CQSCP2PSERVER?CQSCP2PS.EXE"Compaq printer utility which is required in the startup menu in order to make the printer work correctly". Is it actually required?No
Cr**.exe [* = random char]XCr**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this logNo
Cr**32.exe [* = random char]XCr**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this logNo
cracked_windows1Ucracked_windows1.exeCracked Windows popup killerNo
Cracker CryptXCracker Crypt.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
CrashPlan TrayUCrashPlanTray.exeSystem Tray access to and notifications for the CrashPlan online backup software from Code 42 SoftwareNo
mv2Xcrasos.exeAdded by the DROPPS-A TROJAN!No
PoliciesXCrate Bug.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Root%\dir\install\installNo
CRBroadCastingUCRBroadCasting.exeCardReader2 from On Track Inovations Ltd. USB Card ReaderNo
Crc32stats DependenciesXCrc32stats.exeAdded by the MYTOB.GT WORM!No
Auto updatXcrcss.exeAdded by the SDBOT.AAG WORM!No
Client Server Control ProcessXcrcss.exeAdded by the AGENT-HR TROJAN!No
Configuration LoaderXcrcss.exeDetected by Trend Micro as WORM_AGOBOT.ADGNo
CRCSSXcrcss.exeAdded by the IRCBOT-TH WORM!No
PCprotXcrcss.exeAdded by an unidentified WORM!No
Windows Media UpdaterXcrease.exeAdded by the RBOT-ATI WORM!No
Create A MonsterXcreateAMonster.exeKudd.com CreateAMonster. Reportedly stealth installed and Look2Me adware relatedNo
CreateCDNCreatecd.exeAdaptec Easy CD Creator system tray application (pre version 5). Available via Start → ProgramsNo
CreateCD50NCreatecd50.exeAdaptec Easy CD Creator version 5 system tray application. Available via Start → ProgramsNo
setFTPBackXcreatesw.exeAdded by the FTP_BMAIL TROJAN!No
CreativeXCreative.exeDetected by Symantec as W32.Prolin.Worm. Note - the file is located in %UserStartup% and its presence here ensures it runs when Windows startsNo
Creative Audio DriversXcreative.exeDetected by Sophos as W32/Rbot-FKRNo
CredentialsXCredentials.exeDetected by Dr.Web as Trojan.KillProc.20373 and by Malwarebytes Anti-Malware as Trojan.Agent.CHNo
CreditCop2XCreditCop2Up.exeCreditCop rogue security software - not recommended, removal instructions hereNo
CreditCopXCreditCopUp.exeCreditCop rogue security software - not recommended, removal instructions hereNo
87b2cb3916261d5c807bf44262755cb0Xcrhome.exeDetected by Dr.Web as Trojan.DownLoader8.24208 and by Malwarebytes Anti-Malware as Backdoor.AgentNo
System Updater MachineXcrhwss.exeAdded by the CIADOOR-DQ TROJAN!No
crimepXcrimepDetected by Malwarebytes Anti-Malware as Trojan.Agent.CM. The file is located in %AppData%No
voucherlmfao123XcrimepDetected by Malwarebytes Anti-Malware as Trojan.Agent.CM. The file is located in %AppData%No
MSUpdateXcriticalUpdate.exeAffilred adwareNo
C:\Program Files\dfjdkjfdkjfldjf\dfjdkjfdkjfldjf\winlogin.exeUCritProc.exeKeyProwler keystroke logger/monitoring program - remove unless you installed it yourself!No
cmrssXcrmss.exeAdded by the DLOADER-EK TROJAN!No
Microsoft USB2 DriverXcrmss.exeAdded by the RBOT-VK WORM!No
Windows Firewall UpdaterXcronos.exeAdded by the RBOT-GBY WORM!No
CrossMenuUCrossMenu.exeToshiba CrossMenu Utility - allows the user to create their own menusNo
CrossRiderPluginUCrossrider.exePlugin for Crossrider - "an easy to use Javascript framework to create cross browser extensions in minutes. Save months of cross browser extensions development, and ride our framework with its unique tools and solutions"No
CRP386 NetworkingXcrp386.exeAdded by a variant of the IRCBOT BACKDOOR!No
crrssXcrrss.exeDetected by Sophos as Troj/Agent-VDJ and by Malwarebytes Anti-Malware as Trojan.DownloaderNo
crsXcrs.exeAdded by the AGOBOT-TJ WORM!No
ASP.NET State ServiceXcrsass.exeAdded by the BANLOAD-M TROJAN!No
Windows System ManagerXCRSL.EXEAdded by the SDBOT.MG WORM!No
crsmcap1Xcrsmcap1.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %Root%\registroNo
crsmcap3Xcrsmcap3.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %AppData%No
Print Driver Helper ServiceXcrsrr.exeAdded by the AGENT-BC TROJAN!No
[various names]Xcrsrs.exeAdded by the FORBOT-AK WORM!No
Auto updatXcrsrs.exeAdded by the FORBOT-BP WORM!No
Win32 Information ServiceXcrsrs.exeAdded by the RINBOT.Y WORM!No
Controlled Resource System ServiceXcrss.exeAdded by the AGOBOT.GH WORM!No
CRSSXCRSS.exeAdded by the AGOBOT-RM WORM!No
Document Explorer2Xcrss.exeDetected by McAfee as Downloader.a!cqj and by Malwarebytes Anti-Malware as Trojan.AgentNo
Download Manager2Xcrss.exeDetected by McAfee as Downloader.a!cqj and by Malwarebytes Anti-Malware as Trojan.AgentNo
LogonXcrss.exeDetected by McAfee as PWS-Zbot.gen.aru and by Malwarebytes Anti-Malware as Backdoor.MessaNo
Profile Manager2Xcrss.exeDetected by McAfee as Downloader.a!cqj and by Malwarebytes Anti-Malware as Trojan.AgentNo
Sygate Personal PortXcrss.exeAdded by the RBOT-PX WORM!No
System Config ManagerXcrss.exeDetected by Trend Micro as WORM_AGOBOT.GHNo
Win exe file managrXcrss.exeAdded by the RBOT.CCI WORM!No
Win32 Network DriverXcrss.exeAdded by a variant of the AGOBOT WORM!No
WinDefenderXcrss.exeDetected by McAfee as RDN/Ransom!a and by Malwarebytes Anti-Malware as Trojan.Agent.GenNo
Windows Registry SecurityXcrss.exeAdded by a variant of the IRCBOT TROJAN!No
Windows UpdateXcrss.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %UserTemp%\WindowsNo
Windows UpdateXcrss.exeDetected by Dr.Web as Trojan.Inject1.8151 and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
WindowsUpdatecrssXcrss.exeAdded by a variant of the AGENT-HZ TROJAN!No
2k6 updatzXcrss3.exeAdded by the RBOT-CPD WORM!No
Microsoft Update MachineXcrss32.exeAdded by a variant of Win32/RbotNo
Norton Auto ProtectXcrss32.exeAdded by the SDBOT.ATF WORM!No
Microsoft Driver SetupXcrssc.exeAdded by the VBCHEMAN-A MALWARE!No
Windows System ManagerXcrssm.exeAdded by the RBOT-AFH WORM!No
CaptionMgr32Xcrssr.exeAdded by the ZAR.A WORM!No
MS taskbarXcrssr.exeAdded by the RBOT-AGO WORM!No
SP2 Firewall/Internet UpdaterXcrssrs.exeDetected by Trend Micro as WORM_RBOT.BJONo
CRC Value VerifierXcrsss.exeAdded by the SPYBOT.UK WORM!No
crsssXcrsss.exeDetected by Trend Micro as WORM_AUTORUN.FMNo
MSControl28Xcrsss.exeAdded by the SPYBOT.AJX WORM!No
Msn MessangerXcrsss.exeAdded by a variant of the IRCBOT BACKDOOR!No
start uploadingXcrsss.exeAdded by the RBOT-SZ WORM!No
Vital Master-boot DLLXcrsss.exeDetected by Trend Micro as WORM_RBOT.ASENo
Win32 Security ServiceXcrsss.exeAdded by the DELBOT-O WORM!No
Windows media serviceXcrsss.exeAdded by the RBOT.ACY WORM!No
Windows Service UpdateXcrsss.exeAdded by the SDBOT.CWX WORM!No
CRC Value VerifierXcrsss32.exeAdded by the SPYBOT.GY WORM!No
CRC Value VerifierXCrsss64.exeDetected by Sophos as W32/Rbot-NYNo
CRSSXP SysInfoXcrssxp.exeAdded by a variant of the SDBOT BACKDOOR!No
System32Xcrsvvc.exeDetected by Trend Micro as WORM_RBOT.BLYNo
Microsoft Internet ExplorerXcrsys32.exeAdded by the RBOT.UZ WORM!No
Microsoft Control CenterXcrtl.exeAdded by the RBOT-VX WORM!No
Microsoft CRT Monitor ManagerXcrtmon.exeAdded by the ROBOTON.A WORM!No
Windows (ICS) SpoolerXcrtss.exeAdded by a variant of Win32/RbotNo
USB driversXcrv.exeAdded by the AUTORUN-HS WORM!No
system_memoryXcrvss.exeDetected by Sophos as Troj~Zegost-BZ and by Malwarebytes Anti-Malware as Trojan.Agent.CRVNo
Windows media serviceXcrvss.exeAdded by the SDBOT.VP WORM!No
1zTbQvrrqvgZgXcrypt.exeDetected by Dr.Web as Win32.HLLW.Autoruner1.26359No
AppDataXCrypt.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserTemp%No
SvchostXcrypt.exeDetected by Dr.Web as Win32.HLLW.Autoruner1.26359 and by Malwarebytes Anti-Malware as Backdoor.BotNo
cryptdlgXcryptdlg.exeDetected by SUPERAntiSpyware as Trojan.CryptDlg.Process. The file is located in %System%No
crvyqPeXHorMosHDmzZZBJVxRwUmMmxrKtQzLQNYpEMNWuoSUBXCrypted.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL.Gen. The file is located in %LocalAppData%No
crypted.exeXcrypted.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %UserTemp%No
wacultXcrypted.exeDetected by Malwarebytes Anti-Malware as Backdoor.Messa. The file is located in %AppData%No
wacultXcryptedwacult.exeDetected by McAfee as Generic.dx!b2cs and by Malwarebytes Anti-Malware as Backdoor.Messa.GenNo
CalendarscopeUcs.exeCalendarscope calendar softwareNo
ClickSight LauncherNcs.exeLauncher for the ClickSight® marketing tool from ClickStream Technologies - which "is a patented data-collection technology that helps independent software vendors understand the current and future usage of their product"No
CsecXcs.exeCyber Security rogue security software - not recommended, removal instructions hereNo
WINXXCS4MCLG.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData%No
Adobe CS4 Service ManagerNCS4ServiceManager.exePart of both stand-alone Adobe CS4 products (such as Photoshop and Dreamweaver) and suites, CS4 Service Manager supports online services such as Adobe Drive. Whilst testing, it would appear that this entry can be safely disabled as it will be loaded when required but if you experience problems try re-enabling itYes
AdobeCS4ServiceManagerNCS4ServiceManager.exePart of both stand-alone Adobe CS4 products (such as Photoshop and Dreamweaver) and suites, CS4 Service Manager supports online services such as Adobe Drive. Whilst testing, it would appear that this entry can be safely disabled as it will be loaded when required but if you experience problems try re-enabling itYes
CS4ServiceManagerNCS4ServiceManager.exePart of both stand-alone Adobe CS4 products (such as Photoshop and Dreamweaver) and suites, CS4 Service Manager supports online services such as Adobe Drive. Whilst testing, it would appear that this entry can be safely disabled as it will be loaded when required but if you experience problems try re-enabling itYes
Adobe CS5 Service ManagerNCS5ServiceManager.exePart of both stand-alone Adobe CS5 products (such as Photoshop and Dreamweaver) and suites, CS5 Service Manager supports online services. Whilst testing, it would appear that this entry can be safely disabled as it will be loaded when required but if you experience problems try re-enabling itYes
AdobeCS5ServiceManagerNCS5ServiceManager.exePart of both stand-alone Adobe CS5 products (such as Photoshop and Dreamweaver) and suites, CS5 Service Manager supports online services. Whilst testing, it would appear that this entry can be safely disabled as it will be loaded when required but if you experience problems try re-enabling itYes
CS5ServiceManagerNCS5ServiceManager.exePart of both stand-alone Adobe CS5 products (such as Photoshop and Dreamweaver) and suites, CS5 Service Manager supports online services. Whilst testing, it would appear that this entry can be safely disabled as it will be loaded when required but if you experience problems try re-enabling itYes
AdobeCS6ServiceManagerNCS6ServiceManager.exePart of both stand-alone Adobe CS6 products (such as Photoshop and Dreamweaver) and suites, CS6 Service Manager supports online services. Whilst testing, it would appear that this entry can be safely disabled as it will be loaded when required but if you experience problems try re-enabling itNo
winprocXCS6_Keygen.exeDetected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
CopernicSummarizerWatchdogUCSAgent.exe"Copernic Summarizer can analyze a text of any length, on any subject, in any one of four languages, and create a document summary as short or as long as you want it to be. It can summarize Word documents, Web pages, PDF files, email messages and even text from the Clipboard"No
IPv6 Helper DriverXcsass.exeAdded by the AGOBOT.TC WORM!No
LanGuard Auto UpdaterXcsass.exeAdded by the RBOT-DS WORM!No
PCHELPERXCSASS.EXEDetected by Malwarebytes Anti-Malware as Trojan.Agent.PHGen. The file is located in %Temp%No
WSAConfiguration1Xcsass.exeDetected by Trend Micro as WORM_AGOBOT.WHNo
Windows HostbsXcsbss.exeDetected by Malwarebytes Anti-Malware as Trojan.FakeFolder. The file is located in %AppData%No
WINHOST2Xcsbss.exeDetected by McAfee as RDN/Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
cscUcsc.exeCommand line compiler for Microsoft C# it gets installed with the .NET SDKNo
CSCUPDATESXcsc.exeDetected by McAfee as RDN/Generic BackDoor!p and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
CalcScienceXcscientist.exeAdded by the SDBOT.ACQ WORM!No
cscriptsXcscripts.exeAdded by the BDOOR-AAP BACKDOOR!No
CSCRS ValueXcscrs.exeAdded by the RBOT-AAA WORM!No
Microsoft Data MachineXcsdata32.exeAdded by the WOOTBOT.AW WORM!No
Current Security ConfigXcsecure.exeAdded by the RBOT-AMO WORM!No
csecwizNcsecwiz.exeSetup wizard for the Client Security Software (CSS) for IBM\Lenovo notebooks. This entry only runs once, after the software has been installed and the notebook rebooted for the first time. If the wizard isn't completed a shortcut is available via the Start menu until it isYes
IBM Client Security SoftwareNcsecwiz.exeSetup wizard for the Client Security Software (CSS) for IBM\Lenovo notebooks. This entry only runs once, after the software has been installed and the notebook rebooted for the first time. If the wizard isn't completed a shortcut is available via the Start menu until it isYes
Z_acamucli wizardNcsecwiz.exeSetup wizard for the Client Security Software (CSS) for IBM\Lenovo notebooks. This entry only runs once, after the software has been installed and the notebook rebooted for the first time. If the wizard isn't completed a shortcut is available via the Start menu until it isYes
Fortis Secure Layer ConfigUcseinst.exePart of Fortis Bank Home Banking. Installed with the software necessary to run the Home Banking and according to Fortis Bank this will not in any way be harmful to the system or relay system informationNo
AbsoluteShield Internet EraserUcseraser.exeAbsoluteShield Internet Eraser - "protects your privacy by cleaning up all the tracks of your Internet and computer activities"No
cserv32Xcserv32.exeAdded by the STRATION.EC WORM!No
Microsoft Driver SetupXCsgF.EXEDetected by Avira as Worm/Kolab.eihNo
Adobe Remixer Version 2.4Xcshelp32.exeAdded by the NUCLEROOT.E BACKDOOR!No
CsimPlayerXCsimPlayer.exeAdded by the KOOBFACE-AD WORM!No
CSINJECT.EXEUCSINJECT.EXEPart of Quarterdeck/Norton CleanSweep. "Csinject must be loaded in order for Smart Sweep to automatically monitor installations and properly track registry changes"No
CleanSweep Smart Sweep-Internet SweepUCsinsm32.exeSmart Sweep and Internet Sweep keep track of all files added and any changes made to existing configuration files when you install a program using the now discontinued Norton Cleansweep uninstaller/file cleaning utility. "Smart Sweep tracks all file additions and changes that originate from floppies, CDs, or network drives. Internet Sweep tracks all ActiveX control file and Plug-in installations that originate from a Web site. CleanSweep uses this information later to ensure safe and thorough uninstallations"No
CleanSweep Smart Sweep-Internet SweepUCsinsmNT.exeSmart Sweep and Internet Sweep keep track of all files added and any changes made to existing configuration files when you install a program using the now discontinued Norton Cleansweep uninstaller/file cleaning utility. "Smart Sweep tracks all file additions and changes that originate from floppies, CDs, or network drives. Internet Sweep tracks all ActiveX control file and Plug-in installations that originate from a Web site. CleanSweep uses this information later to ensure safe and thorough uninstallations"Yes
xwareXcskware.exeMalware downloader from xxsware.com, produces adult content popupsNo
csm Win UpdatesXcsm.exeDetected by McAfee as W32/Zotob.worm.bNo
Windows Client/Server Management LayerXcsml.exeAdded by the AGENT.CYC BACKDOOR!No
New Csnm ManagerXcsmn.exeAdded by the SDBOT.BZS WORM!No
cmssSystemProcessXcsms.exeDetected by Sophos as Troj/Agent-YNo
cmssSystemProcessXcsmss.exeAdded by the AGENT-CO TROJAN!No
spoolsvr32Xcsmss.exeAdded by the AGENT-AU TROJAN!No
spoolsvr32Xcsmss32.exeAdded by the AGENT-AU TROJAN!No
ControlServiceMgrXcsmsv.exeDetected by Sophos as Troj/Agent-XCNo
ManageProtocolCtrlXcsmsv.exeAdded by the LOOKSKY.B TROJAN!No
NDAvXcsnss.exeAdded by the SERFLOG.C WORM!No
SDAvXcsnss.exeAdded by the SERFLOG.C WORM!No
Service MonitorXcsnss.exeAdded by the RBOT.EEH BACKDOOR!No
CSO.exeYCSO.exeONO Service Center tool installed when you choose to install their internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabledNo
csosXcsos.exeAdded by the SDBOT-DFE WORM!No
CSV10P1XCSP001.exeClearSearch adwareNo
csrcsXcsrcs.exeDetected by Sophos as Troj/Agent-HUANo
GooglesXcsrcs.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.MODUPX. The file is located in %AppData%No
MessengerXcsrcs.exeDetected by Malwarebytes Anti-Malware as Trojan.Klovbot.ai. The file is located in %AppData%No
MicrosoftsXcsrcs.exeAdded by the VB-FNA TROJAN!No
Windows Custom ServicesXCSRCS.EXEAdded by the SPYBOT-EI WORM!No
Windows Media PlayerXcsrcs.exeDetected by Microsoft as Trojan:Win32/Vboxador.B and by Malwarebytes Anti-Malware as Trojan.VBInjectNo
Windows PlayerXcsrcs.exeDetected by Sophos as W32/Scar-AR and by Malwarebytes Anti-Malware as Trojan.VBInjectNo
RemndrXCsRemnd.exeCasinoOnline foistwareNo
Csrss HostXcsrhost.exeAdded by the IRCBOT.BIZ WORM!No
NT Windows System Manager LoaderXcsrlss.exeDetected by Trend Micro as WORM_AGOBOT.OXNo
Windows Client/Server Runtime Management LayerXcsrml.exeAdded by the AGENT.CWQ BACKDOOR!No
ethernet adapterXcsrmss.exeAdded by a variant of Win32/RbotNo
DriverModuleXcsrnvrt.exeAdded by the IRCBOT.I TROJAN!No
csrXcsrrs.exeAdded by the RBOT-CKM WORM!No
csrrsXcsrrs.exeAdded by the INEUDOK.A TROJAN!No
Service ControllerXCsrrs.exeDetected by Symantec as W32.HLLW.Gaobot.AONo
Windows Taskmanager DataXcsrrss.exeAdded by the RBOT-BBH WORM!No
 Microsoft Client/Server Runtime Server SubsystemXcsrs.exeAdded by the RBOT-AEN WORM! Note the space at the beginning of the "Startup Item" fieldNo
Client Server RuntimeXcsrs.exeAdded by the POEBOT-KR WORM!No
Client Server Runtime ProcessXcsrs.exeAdded by the LINKBOT.M WORM!No
Com+ SysXcsrs.exeAdded by the FORBOT-BT WORM!No
csrsXcsrs.exeAdded by the GAOBOT.GEN!POLY WORM!No
csrs.exeXcsrs.exeDetected by Dr.Web as Trojan.Siggen3.27512 and by Malwarebytes Anti-Malware as Trojan.AgentNo
Intel DriverXcsrs.exeAdded by a variant of the SDBOT WORM - see hereNo
Microsoft Corp. Critical ServicesXcsrs.exeAdded by the RBOT-GTJ WORM!No
NetWorkXcsrs.exeDetected by Trend Micro as WORM_AGOBOT.JJNo
Windows ActionXcsrs.exeAdded by the SECCMU-A WORM!No
Windows Client/Server Runtime ServerXcsrs.exeAdded by the RBOT.KD WORM!No
Windows Update ServiceXcsrs.exeDetected by Sophos as W32/Agobot-NI and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
bobyXcsrs.scrAdded by the BANCBAN-PC TROJAN!No
darkXcsrs.scrDetected by Sophos as Troj/Bancban-GT or Troj/Bancban-GU and by Malwarebytes Anti-Malware as Trojan.BankerNo
Norton SystemXcsrs.scrAdded by the BANLOA-AFM TROJAN!No
System32-DriverXcsrs32.exeAdded by the SDBOT-CP BACKDOOR!No
csrscXcsrsc.exeAdded by the SILLYDC WORM!No
svchost.exeXcsrsc.exeAdded by the BUZUS.AAUP TROJAN!No
Winsock2 driverXCSRSC.EXEAdded by the SPYBOT-CF WORM!No
Microsoft RegistryXcsrse.exeAdded by the RBOT-PC WORM!No
System ProcessXCSRSR.exeAdded by the AGOBOT-SQ WORM!No
Client Server Run Time ProccessXcsrsrv.exeAdded by a variant of W32/Sdbot.wormNo
csrssXcsrss .exeDetected by Dr.Web as Trojan.KillProc.19763 and by Malwarebytes Anti-Malware as Trojan.AgentNo
 SystemDriverXcsrss.exeDetected by Symantec as Trojan.Ascetic.B and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\addins\explorer and note the space at the beginning of the "Startup Item" fieldNo
.svchostXCSRSS.EXEDetected by Symantec as Trojan.Webus.F and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!No
.TEXTCONVXcsrss.exeDetected by Symantec as Trojan.Webus and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!No
.WMAudioXcsrss.exeDetected by Symantec as Trojan.Webus and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!No
_SystemDriverXcsrss.exeDetected by Symantec as Trojan.Ascetic.B and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\addins\explorerNo
97335ed968c8d21501810d2516770677Xcsrss.exeDetected by Dr.Web as Trojan.DownLoader8.24029 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
AdRotator.ApplicationXcsrss.exeDetected by Sophos as Troj/Small-AQ and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the "drivers" subfolderNo
afrriiiiXcsrss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
ApplicationXcsrss.exeDetected by Symantec as W32.Beagle.EG@mm and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
ASP.NET State ServiceXcsrss.exeDetected by Sophos as Troj/Dloader-QI and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
AtiSoundUcsrss.exeWinSpy surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "ComRoot" subfolderNo
AVManagerXcsrss.exeDetected by Sophos as W32/Autorun-DV and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "~A~m~B~u~R~a~D~u~L~" subfolderNo
BagleAVXcsrss.exeDetected by Symantec as W32.Netsky.AB@mm and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
bootstatXcsrss.exeDetected by Symantec as Trojan.Comrerop and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\MediaNo
BuildLabsXcsrss.exeDetected by Symantec as Trojan.Webus and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!No
ccpAppsXcsrss.exeDetected by Symantec as Trojan.Webus and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!No
ClickTheButtonXcsrss.exeClickTheButton adware. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "drivers" subfolderNo
Client Server Runtime ProcessXcsrss.exeDetected by Dr.Web as Trojan.DownLoader6.47266 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\System32No
Client Server Runtime ProcessXcsrss.exeDetected by Dr.Web as Trojan.DownLoader6.51189 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
ComMessengerXcsrss.exeDetected by Dr.Web as Trojan.PWS.Siggen.40403 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\dataNo
conimeXcsrss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "wbem" subfolderNo
Console de Gerenciamento MicrosoftXcsrss.exeDetected by Sophos as Troj/Bancban-ET and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "Central de Segurança" subfolderNo
CriticalSysResrcXcsrss.exeDetected by Dr.Web as Trojan.DownLoader6.61569 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
csrssUcsrss.exeBeyondKeylog surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\SupremtecNo
CsrssXcsrss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
csrssXcsrss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This is located in %Windir% and %UserStartup% and %AllUsersStartup% and its presence there ensures it runs when Windows startsNo
csrssXcsrss.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserTemp%No
csrssXcsrss.exeDetected by Kaspersky as Trojan-Spy.Win32.Ardamax.dke and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserTemp%\tmp-3No
csrssXcsrss.exeDetected by McAfee as Generic.dx!bd3d and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\MicrosoftNo
csrssXcsrss.exeDetected by McAfee as Generic.dx!bdbc and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\Common Files\MicrosoftNo
csrssXcsrss.exeDetected by Sophos as Troj/Keylog-AQ and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
CsrssXCSRSS.EXEDetected by Sophos as W32/Punya-B and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%\WINDOWSNo
CsrssXcsrss.exeDetected by Symantec as W32.Chod@mm and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a random subfolderNo
csrssXcsrss.exeDetected by Symantec as Trojan.Syginre and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%No
Csrss.exeXcsrss.exeDetected by Symantec as W32.Dalbug.Worm and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
csrssLevel4Xcsrss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located %Windir%\System\Level4No
DIECOXXcsrss.exeAdded by a variant of Backdoor.Hale and detected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "qossrv" subfolderNo
Document Explorer3Xcsrss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%\DocumentsNo
Download Manager3Xcsrss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%\DownloadsNo
e101a39ab5de59589562aa0ff3295ba5Xcsrss.exeDetected by McAfee as Generic.tfr!cr and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%No
Explorer.exeXcsrss.exeDetected by Sophos as W32/Juego-B and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\MicrosoftNo
FiendlyTypeXcsrss.exeDetected by Symantec as Trojan.Webus and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!No
FirewallActiviesXcsrss.exeDetected by Sophos as Troj/Banker-AQ and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "3041" subfolderNo
Google UpdXcsrss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\GoogleNo
HKCUXcsrss.exeDetected by Kaspersky as Trojan.Win32.Buzus.emmy and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an "install" subfolderNo
HKLMXcsrss.exeDetected by Kaspersky as P2P-Worm.Win32.Palevo.ahmd and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "winboot" subfolderNo
HKLMXcsrss.exeDetected by Kaspersky as Trojan.Win32.Buzus.emmy and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an "install" subfolderNo
HKLNXcsrss.exeDetected by Kaspersky as P2P-Worm.Win32.Palevo.ahmd and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "winboot" subfolderNo
Host-process Windows (Rundll32.exe)Xcsrss.exeDetected by Dr.Web as Trojan.DownLoader6.47266 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\System32No
Host-process Windows (Rundll32.exe)Xcsrss.exeDetected by Dr.Web as Trojan.DownLoader6.51189 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
IntelXcsrss.exeDetected by Kaspersky as Trojan-Banker.Win32.Qhost.mmu and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
JavaXcsrss.exeDetected by Dr.Web as Trojan.DownLoader4.11626 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\@off@No
JavaXcsrss.exeDetected by McAfee as Generic BackDoor!fj3 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\JavaNo
KernellAppsXcsrss.exeDetected by Sophos as Troj/Bancban-AC and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "System" subfolderNo
Key LoggerXcsrss.exeDetected by Symantec as W32.Buchon.A@mm and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%No
KrnlcheckXcsrss.exeDetected by Symantec as Backdoor.Botnachala and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
Logon<user>XCSRSS.EXEDetected by Sophos as W32/Brontok-BH and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%\WINDOWSNo
LogonAdministratorXCSRSS.EXEDetected by Symantec as W32.Korron.B and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%\WINDOWSNo
LOGONADMINISTRATOR.[ComputerName]XCSRSS.EXEDetected by McAfee as Generic VB.i and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%\WINDOWSNo
Logonrepclient1XCSRSS.EXEDetected by Sophos as W32/Brontok-BT and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%\WINDOWSNo
LogonsaraXcsrss.exeDetected by Sophos as W32/Brontok-BS and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%\WINDOWSNo
Microsoft Office OutlookXcsrss.exeDetected by McAfee as W32/Worm-FDN!F4D562C180AF and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\'\'No
Microsoft Security ClientXcsrss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\MicrosoftNo
Microsoft SourceSafeXcsrss.exeDetected by Symantec as Trojan.Webus and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!No
Microsoft UpdateXCsrss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "winfiles" subfolderNo
Microsoft Windows CSRSSXcsrss.exeDetected by Sophos as W32/Kalel-A and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!No
Microsoft Windows Hosting ServiceXcsrss.exeDetected by Dr.Web as Trojan.FakeAV.14105 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%No
Microsoft Windows Update ClientXcsrss.exeDetected by Sophos as W32/Kebede-G and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Systems32No
Microsoft Word ProfissionalXcsrss.exeDetected by Sophos as Troj/Bancban-DB and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "s1613" subfolderNo
Microsoft Word ProfissionalXcsrss.exeDetected by Sophos as Troj/Bancos-DP and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "JavaVM" subfolderNo
Microsoft Word ProfissionalXcsrss.exeDetected by Sophos as Troj/Banker-DJ and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "protect" subfolderNo
MSNXcsrss.exeDetected by McAfee as Generic PWS.y. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msappsNo
MstaskXcsrss.exeDetected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Trojan.AgentNo
MSWUpdateXcsrss.exeDetected by Sophos as Mal/DrkBot-A and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
Norton Protect ActiviesXcsrss.exeDetected by Sophos as Troj/Banker-CZ and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "D5133" subfolderNo
NTDLMXcsrss.exeDetected by Symantec as Backdoor.Hale and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "qossrv" subfolderNo
nvdisplayXcsrss.exeDetected by Sophos as W32/VB-FBO and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
PagefileManagerXcsrss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\Pagefile System VolumeNo
PoliciesXcsrss.exeDetected by Kaspersky as Trojan.Win32.Buzus.emmy and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an "install" subfolderNo
Profile Manager3Xcsrss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%No
ProgXcsrss.exeDetected by Symantec as Trojan.Webus and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!No
RegDone ExXcsrss.exeDetected by Symantec as Trojan.Webus and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!No
RegWriteXcsrss.exeDetected by Symantec as Backdoor.Sokacaps and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\MediaNo
Remote Registry ServiceXcsrss.exeDetected by Sophos as W32/IRCBot-AKB and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
RPCserv32gXCSRSS.EXEDetected by Trend Micro as WORM_BOBAX.AD and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
rundll32Xcsrss.exeDetected by Symantec as Trojan.Gutta and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
RunnerXcsrss.exeDetected by Sophos as Troj/AdClick-AG and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
Runtime ProcessXCsrss.exeDetected by Sophos as Troj/Ciadoor-J and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
Runtime Server SubsystemXcsrss.exeDetected by Sophos as W32/IRCBot-XV and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!No
SernellApp.pcxXcsrss.exeDetected by Sophos as Troj/Bancban-BJ and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "D5133" subfolderNo
ShockwaveXcsrss.exeDetected by Symantec as W32.Sndog@mm and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
SkypeXcsrss.exeDetected by Malwarebytes Anti-Malware as Trojan.VBKrypt. Note - this is not a legitimate entry for the popular Skype VOIP software and also it is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
SOFICEXcsrss.exeDetected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Trojan.Agent.DPT. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %LocalAppData%\GoogleNo
State ServiceXcsrss.exeDetected by Sophos as Troj/Dadobra-CP and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
svchostXcsrss.exeDetected by Kaspersky as Trojan.Win32.Swisyn.bgkm and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%No
SysinternalsXcsrss.exeGuard Online rogue security software - not recommended, removal instructions here. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
SystemXcsrss.exeDetected by Symantec as Infostealer.Ldpinch.E and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
System ProcessXcsrss.exeDetected by Sophos as Troj/AdClick-AG and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
System32Xcsrss.exeDetected by Symantec as W32.SillyFDC and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "drivers" subfolderNo
SYSTEMSars32Xcsrss.exeDetected by Symantec as W32.Ahlem.A@mm and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
TaskMrgXcsrss.exeDetected by Sophos as Troj/LdPinch-W and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
Torjan ProgramXcsrss.exeDetected by Sophos as Troj/LegMir-BO and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
UpdateXcsrss.exeDetected by Sophos as Troj/AdClick-AG and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
UpdateXcsrss.exeDetected by Symantec as Trojan.Meheerwar and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "winupdate" subfolderNo
UpDaTerXcsrss.exeDetected by Kaspersky as Worm.Win32.AutoRun.dib and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolderNo
WinDefender.exeXcsrss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
Windows 2004Xcsrss.exeDetected by Sophos as Troj/Banker-DY and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Windows 2004\ToolsNo
Windows Client Service 32Xcsrss.exeDetected by Sophos as W32/Rbot-ALB and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "drivers\winsdriver" subfolderNo
Windows defenderXcsrss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the "drivers" subfolderNo
Windows Explorer SP2Xcsrss.exeDetected by Sophos as Troj/Banker-DM and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "JavaBeans" subfolderNo
Windows System Devices ManagerXcsrss.exeDetected by Sophos as Troj/Inject-PX and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
Windows UpdateXcsrss.exeDetected by Sophos as Troj/Banker-HM and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
WindowsExplorerXcsrss.exeMessenger Blocker rogue security software - not recommended. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %CommonFiles%\SystemNo
WINDOWSHOSTEDXcsrss.exeDetected by McAfee as RDN/Generic BackDoor and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
Windowsupdate ServiceXcsrss.exeDetected by Sophos as W32/Baba-B and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root folder (ie, C:\)No
WinlogonXcsrss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
winupdateXcsrss.exeDetected by Kaspersky as P2P-Worm.Win32.Palevo.ahmd and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "winboot" subfolderNo
WinUpdateAdministratorXCSRSS.EXEDetected by Sophos as W32/Punya-A and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Application Data\WINDOWSNo
WinUpdateProtectionUcsrss.exeEmployeeWatch is a commercial surveillance software program designed to monitor user activity on a computer. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a subfolder of C:\windowsupdate\ufpNo
WinXPXcsrss.exeDetected by Sophos as Troj/Bancos-AG and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\WinXP\ToolsNo
WinXP-98XCSRSS.exeDetected by Sophos as Troj~Banker-DS and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\WinXP-98\ToolsNo
WOW64 EmulatorXcsrss.exeDetected by Dr.Web as Trojan.DownLoader8.21350 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %CommonAppData%\WOW64No
ZoneUpdateUcsrss.exeWinSpy surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "ComRoot" subfolderNo
27Xcsrss32.exeAdded by the SLSORVE-D TROJAN!No
ALMXcsrss32.exeAdded by the ANACON-D VIRUS!No
Execution Control ServicesXcsrss32.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.CSR. The file is located in %ProgramFiles%\Windows Service - see hereNo
Microsoft CSRSS32 ProtocolXcsrss32.exeAdded by the RBOT.AAN WORM!No
Microsoft Update ServiceXcsrss32.exeAdded by the AGOBOT-HC WORM!No
OCXSVCXcsrss32.exeDetected by McAfee as RDN/Generic.dx!b2g and by Malwarebytes Anti-Malware as Trojan.Downloader.OCXNo
ServicesXcsrss32.exeAdded by the ANACON-D VIRUS!No
System Log EventXcsrss32.exeDetected by Sophos as W32/Agobot-JINo
System Update ServiceXcsrss32.exeAdded by the AGOBOT-HI WORM!No
Updater Service ProcessXcsrss32.exeAdded by the AGOBOT-GP BACKDOOR!No
Microsoft CSRSS386 ProtocolXcsrss386.exeAdded by a variant of the SPYBOT WORM!No
 Microsoft Client/Server Runtime Server SubsystemXcsrssa.exeAdded by a variant of WORM_AGOBOT.GEN. Note the space at the beginning of the "Startup Item" fieldNo
Jnskdfmf9eldfdXcsrssc.exeAdded by the AGENT.EBC TROJAN!No
OperaXcsrsse.exeAdded by the MDROP-DFQ TROJAN!No
NAV Auto UpdatesXcsrssp.exeAdded by the SDBOT.AQV WORM!No
Microsoft Windows Hosting ServiceXcsrssr.exeDetected by Microsoft as Trojan:Win32/Pefsire.A and by Malwarebytes Anti-Malware as Trojan.MWF.Gen. The file is located in %Windir%No
Microsoft Windows Hosting ServiceXcsrssr.exeDetected by Sophos as Troj/Agent-QRP and by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %UserTemp%No
Windows RPC Host ServiceXcsrssr.exeDetected by Sophos as Troj/Agent-QRPNo
Client Server Runtime ProcessXcsrsss.exeAdded by the SDBOT-LD WORM!No
CSRSS LoaderXcsrsss.exeDetected by Trend Micro as WORM_AGOBOT.TXNo
Microsoft WinsockXcsrsss.exeDetected by Malwarebytes Anti-Malware as Trojan.Sdbot. The file is located in %System%No
CSRSSUXCSRSSU.exeCoolWebSearch parasite variant - hijacking to Slawsearch.com. Also detected as the CWS-E TROJAN!No
Microsoft DLL VerifierXcsrssv.exeAdded by the RBOT-ATK WORM!No
CSRSSWXCSRSSW.EXEAdded by the CWS-F TROJAN!No
argq32Xcsrss_32.exeAdded by the RBOT-CPM WORM!No
csrsvc.exeXcsrsvc.exeDetected by McAfee as W32/Worm-FES!9150D3E9A7A8 and by Malwarebytes Anti-Malware as Worm.Agent.CSNo
WSAConfigurationXcsrsvcs.exeDetected by Trend Micro as WORM_AGOBOT.VINo
System132XCsrtss.exeAdded by the LANFILT-I TROJAN!No
csrvssXcsrvss.exeAdded by a variant of the SDBOT BACKDOOR!No
ProtocolEventTskXcsrwjd.exeAdded by the STINX-N TROJAN!No
dab1c01d088e43d83122e84a5262c4d7Xcss.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserProfile%No
WINHOST3Xcssas.exeDetected by McAfee as RDN/Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
Client Security SolutionNcssauth.exePart of Thinkvantage Client Security Solution for Lenovo ThinkPad notebooks and ThinkCentre desktops. Once configured via the associated setup screens this loads via winlogon.exe (and loads the password manager) and therefore disabling this entry has no effectYes
cssauthNcssauth.exePart of Thinkvantage Client Security Solution for Lenovo ThinkPad notebooks and ThinkCentre desktops. Once configured via the associated setup screens this loads via winlogon.exe (and loads the password manager) and therefore disabling this entry has no effectYes
cssautheNcssauthe.exePart of Thinkvantage Client Security Solution for IBM/Lenovo ThinkPad notebooks and ThinkCentre desktops. Once configured via the associated setup screens this loads via winlogon.exe (and loads the password manager) and therefore disabling this entry has no effectNo
cssrsXcssrs.exeDetected by Dr.Web as Trojan.MulDrop2.47868 and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Windir%\HkN32No
cssrsXcssrs.exeDetected by Dr.Web as Trojan.FakeAV.10930 and by Malwarebytes Anti-Malware as Trojan.Inject. The file is located in %AppData%\MacromidiaNo
cssrsXcssrs.exeDetected by Sophos as Troj/Bancban-DW and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System%No
cssrs.exeXcssrs.exeDetected by Dr.Web as Trojan.Siggen2.56871 and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Temp%No
cssrs.exeXcssrs.exeDetected by Dr.Web as Trojan.DownLoader5.12384 and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AllUsersProfile%\uTorrentNo
ctfmenXcssrs.exeAdded by the STARTP-DC TROJAN!No
Display DriversXcssrs.exeDetected by Trend Micro as WORM_AGOBOT.FXNo
JavaUpdatecda9Xcssrs.exeDetected by Kaspersky as Trojan-Downloader.Win32.Homa.etg and by Malwarebytes Anti-Malware as Trojan.BankerNo
Microsoft CorpXcssrs.exeDetected by Kaspersky as Trojan.Win32.Scar.cpqvNo
Microsoft serviceXcssrs.exeAdded by the STARTP-DC TROJAN!No
NxvstXcssrs.exeDetected by Microsoft as Worm:Win32/Gaobot.CDNo
ServicesActiveXcssrs.exeAdded by the AGOBOT-GB BACKDOOR!No
TINTIMGXcssrs.exeDetected by Kaspersky as Trojan.Win32.Cossta.ndb and by Malwarebytes Anti-Malware as Trojan.StartPageNo
Verificador do sistemaXcssrs.exeAdded by the MOCON WORM!No
WinFXXcssrs.exeDetected by Trend Micro as WORM_AGOBOT.FXNo
cssrss.exeXcssrss.exeMalware installed by different rogue security software including SpyKillerProNo
MSN angXcssrss.exeAdded by the FORBOT-CE WORM!No
WMDM PMSP ServiceXcssrss.exeAdded by the KNOCKIT-A TROJAN!No
csssXCsss.exeAdded by the BALICK TROJAN!No
CSS ServerUCSSServer.exeComSpySysSvr surveillance software. Uninstall this software unless you put it there yourselfNo
COMODO SafeSurfYcssurf.exeComodo SafeSurf Toolbar by Comodo Group, Inc - installed with older versions of their firewall and "protects against data theft, computer crashes and system damage by preventing most types of Buffer Overflow attacks. This type of attack occurs when a malicious program or script deliberately sends more data to a target applications memory buffer than the buffer can handle - which can be exploited to create a back door to the system though which a hacker can gain access"No
Win4HostingXcsszss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserTemp%No
CSS_CentralUCSS_1631.EXEPart of Command AntiVirus for 9x/Me by Command Software Systems, Inc (who became Authentium and are now Commtouch)No
SysW8Ucsta.exeClean Space internet evidence eliminatorNo
ChineseStarUcstar.exeChinese language support softwareNo
nvsv32.exeXcstr.exeAdded by a variant of W32/Sdbot.wormNo
CC2KUIXCSTRAY.EXEComet Cursor adwareNo
WindowsDiskLogXcstsm.exeAdded by the STINX-C or STINX-D TROJANS!No
CleanSweep Useage WatchNCSUSEM32.EXEQuarterdeck/Norton CleanSweep component - tracks how often you use files and alerts you to files that have not been used for a specified period of timeNo
CSV10P70XCSv10P070.exeClearSearch adwareNo
CSV7P70XCSV7P070.exeClearSearch adwareNo
CSV7P26XCSV7P26.exeClearSearch adwareNo
CSV7P91XCSV7P91.exeClearSearch adwareNo
csvdeaUcsvdea.exeSpyArsenalLog surveillance software. Uninstall this software unless you put it there yourselfNo
csvhost.exeXcsvhost.exeAdded by the CIMUZ-BD TROJAN!No
CompuSpy KeyLoggerUcswin2008.exeCompuSpy surveillance software. Uninstall this software unless you put it there yourselfNo
NETServicesXcsxrs.exeAdded by a variant of W32/Sdbot.wormNo
LocalSysLiteXcsxss.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Root%\Users\PublicNo
CardScan AutoSync?CSyncCfg.exeRelated to the CardScan business card reader range of products. May be related to synchronization with E-mail software and mobile devices (see here)?No
System time updatorXCSysTime.exeAdded by the RANDEX.S WORM!No
Ashampoo Core TunerUct.exeAshampoo® Core Tuner - a utility which helps you to get the most out of a multi-processor (or dual core) computer. "For instant results you just need to select Auto-Optimize to optimize all the programs you are running or Boost to give more power to a single program." This entry loads Core Tuner with Windows (required if you use any optimized profiles) and gives System Tray accessYes
checktimeUct.exePart of the "HP Learning Adventure" software installed HP's XP home user PCs which gives access to pre-installed software choices ranging from children's educational titles to family reference software that they can try before they buy. Consumers also receive one free software choice with each system they purchase. Required if you use this featureNo
ctUct.exePart of the "HP Learning Adventure" software installed HP's XP home user PCs which gives access to pre-installed software choices ranging from children's educational titles to family reference software that they can try before they buy. Consumers also receive one free software choice with each system they purchase. Required if you use this featureNo
MicrosoftctfmonXct.exeDetected by Dr.Web as Trojan.DownLoader6.9198 and by Malwarebytes Anti-Malware as Trojan.AgentNo
CTAPR2UCTAPR2.exeConsole Launcher for the Creative Sound Blaster X-Fi seriesNo
CTAVTrayNCTAvTray.exeFor Creative Soundblaster Live! series soundcards. Plays the EAX animation on start-up and adds a System Tray icon for it. Available via AudioHQNo
ClickTheButtonXCTB.EXEClickTheButton adwareNo
CTCheckUCTCheck.exeAssociated with the ZEN range of MP3 players from Creative Technology Ltd. A visitor recommended the "U" status but what does it do?No
CTCMonitorUCTCMonitor.exeClick-to-Convert - document-to-HTML or doc-to-PDF converter. Only required if you are going to use the File → Print method of using Click-to-Convert. If converting directly from MS Office, it is not requiredNo
Creative MediaSource GoUCTCMSGo.exeCreative MediaSource Go! is a combination of a short-cut bar and launcher for the Creative MediaSource™ player/organizer - which "enables you to manage your entire digital music collection on both your computer and your Creative portable music player effortlessly"No
Creative MediaSource GoUCTCMSGoU.exeCreative MediaSource Go! is a combination of a short-cut bar and launcher for the Creative MediaSource™ player/organizer - which "enables you to manage your entire digital music collection on both your computer and your Creative portable music player effortlessly"No
Creative Detector UNCTDetctu.exeRemovable media detector for Creative products - such as the Zen media players - that launches version 5 of the MediaSource™ player organizer when compatible media is detectedNo
Creative DetectorNCTDetect.exeRemovable media detector for Creative products - such as the Zen media players - that launches the appropriate application (such as the MediaSource™ player organizer) when compatible media is detectedNo
CTDVDDetNCTDVDDet.exeAuto-detects and plays a DVD when using a Creative Soundblaster soundcardNo
CTStartupNCTEaxSpl.exeSplash screen with sound on every boot up. Installed with a Sound Blaster Audigy soundcardNo
WINDOWS SYSTEMXctech.exeAdded by the MYTOB-KD WORM!No
ctf.exeXctf.exeAdded by a variant of the BIFROSE TROJAN!No
Windows Firewall UpdaterXctfcom.exeAdded by the RBOT-GCB WORM!No
ctflog managerXctflog.exeAdded by the DONBOMB.A TROJAN!No
CTFMON.CPLXCTFM0N.CMDDetected by Symantec as the SILLYFDC WORM! See hereNo
compmgmtXCTFM0N.EXEAdded by the INJECT.PT TROJAN! Notice the digit "0" in the filename rather than the upper case "o"No
CTFM0N.exeXCTFM0N.exeAdded by the STARTPAGE.P TROJAN! Notice the digit "0" in both columns rather than the upper case "o"No
ctfmon.exeXCTFM0N.EXEAdded by the AUTORUN-AYX WORM! Notice the digit "0" in the filename rather than the upper case "o"No
Windows file monitorXctfm0n.exeDetected by Trend Micro as WORM_MEPAOW.LX. Note the number "0" in place of a lower case "o" in the filenameNo
PHIME2004CXCTFMDN.exeAdded by the DLOADR-AMV TROJAN!No
ctfmgrXctfmgr.exeAdded by the PWS-ATU TROJAN!No
Windows Update Firewall SystemXctfmom.exeDetected by Symantec as W32.Spybot.ANDM and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
0e020ee62e36dea9d9476175e8ebf8d4Xctfmon.exeDetected by Dr.Web as Trojan.DownLoader7.7428 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - this is not the legitimate ctfmon.exe process associated with alternate language and method inputs which is always located in %System%. This one is located in %AppData%No
CTFMonUctfmon.exeFamily KeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in a "CTF" sub-folderNo
ctfmonXctfmon.exeAdded by the AUTORUN-G WORM! Note - this is not the legitimate ctfmon.exe process associated with alternate language and method inputs which is always located in %System%. This one is located in a "1046" sub-folderNo
CTFMONXctfmon.exeDetected by Malwarebytes Anti-Malware as Worm.Agent. Note - this is not the legitimate ctfmon.exe process associated with alternate language and method inputs which is always located in %System%. This one is located in a "1126" sub-folderNo
CTFMONXctfmon.exeDetected by McAfee as Downloader.a!bql. Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in an "InstallDir" sub-folderNo
ctfmonXctfmon.exeDetected by Sophos as Troj/Dloadr-DRL and by Malwarebytes Anti-Malware as Trojan.Backdoor.TJK. Note - this is not the legitimate ctfmon.exe process associated with alternate language and method inputs which is always located in %System%. This one is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
ctfmonUctfmon.exeSupports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or, for example, if speech is selected as an alternative input for MS Office or Notepad. Required to support advanced text services (such as right to left text) for East Asian users. Can be disabled via Start → Control Panel → Regional and Language Options → Languages → Text Services and Input Languages → Details → Advanced → System Configuration → Turn off advanced text services (which also turns off the language bar). See also here and here. Can also cause problems with some other programs if left enabled - see here for such an exampleYes
ctfmon.exeUctfmon.exeTotalSpy keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %ProgramFiles%\TS TrialNo
CTFMON.EXEXctfmon.exeAdded by the VBSP-A WORM! Note - this is not the legitimate ctfmon.exe process associated with alternate language and method inputs which is always located in %System%. This one is located in a "1126" sub-folderNo
ctfmon.exeXctfmon.exeAdded by the RAIDYS TROJAN! Note - this overwrites the legitimate ctfmon.exe process associated with alternate text inputs which is located in %System%No
ctfmon.exeUctfmon.exeSupports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or, for example, if speech is selected as an alternative input for MS Office or Notepad. Required to support advanced text services (such as right to left text) for East Asian users. Can be disabled via Start → Control Panel → Regional and Language Options → Languages → Text Services and Input Languages → Details → Advanced → System Configuration → Turn off advanced text services (which also turns off the language bar). See also here and here. Can also cause problems with some other programs if left enabled - see here for such an exampleYes
ctfnnonXctfmon.exeDetected by Kaspersky as Backdoor.Win32.Turkojan.il. Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%No
DLLÝNSTALLS32Xctfmon.exeDetected by Malwarebytes Anti-Malware as Spyware.Password. Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in a "SYS32DLLS" sub-folderNo
FirewallXctfmon.exeAdded by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%No
HKCUXctfmon.exeDetected by McAfee as Downloader.a!bql. Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in an "InstallDir" sub-folderNo
HKLMXctfmon.exeDetected by McAfee as Downloader.a!bql. Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in an "InstallDir" sub-folderNo
Microsoft CTF LoaderUctfmon.exeSupports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or, for example, if speech is selected as an alternative input for MS Office or Notepad. Required to support advanced text services (such as right to left text) for East Asian users. Can be disabled via Start → Control Panel → Regional and Language Options → Languages → Text Services and Input Languages → Details → Advanced → System Configuration → Turn off advanced text services (which also turns off the language bar). See also here and here. Can also cause problems with some other programs if left enabled - see here for such an exampleYes
MicrosoftctfmonXctfmon.exeDetected by Dr.Web as Trojan.DownLoader5.37566 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Root%\fdstNo
ntuserXctfmon.exeDetected by Sophos as Troj/Agent-GSG. Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %UserProfile%No
QQPLUSXctfmon.exeDetected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Worm.AutoRun. Note - this is not the legitimate ctfmon.exe process associated with alternate language and method inputs which is always located in %System%. This one is located in %ProgramFiles%\MSFCacheNo
Service Pack 2Xctfmon.exeDetected by Kaspersky as Trojan-Downloader.Win32.Genome.anmr and by Malwarebytes Anti-Malware as Trojan.Banker.Gen. Note - this is not the legitimate ctfmon.exe process associated with alternate language and method inputs which is always located in %System%. This one is located in %Root%\Arquivos de programas\Internet ExplorerNo
Service Pack 3Xctfmon.exeDetected by Kaspersky as Trojan-Downloader.Win32.Genome.axxw and by Malwarebytes Anti-Malware as Trojan.Banker.Gen. Note - this is not the legitimate ctfmon.exe process associated with alternate language and method inputs which is always located in %System%. This one is located in %Root%\Arquivos de programas\Internet ExplorerNo
Symantec UpdateXctfmon.exeDetected by Trend Micro as BKDR_GODIN.A and by Malwarebytes Anti-Malware as Backdoor.Agent.CTF. Note - this is not the legitimate ctfmon.exe process associated with alternate language and method inputs which is always located in %System%. This one is located in %UserProfile%\Local SettingsNo
SYS32Xctfmon.exeDetected by Malwarebytes Anti-Malware as Spyware.Password. Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in a "SYS32DLLS" sub-folderNo
WÝNSYS32DLLSXctfmon.exeDetected by Malwarebytes Anti-Malware as Spyware.Password. Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in a "SYS32DLLS" sub-folderNo
WinDefenderXctfmon.exeDetected by Dr.Web as Trojan.KillProc.9740 and by Malwarebytes Anti-Malware as Trojan.Agent.Gen. Note - this is not the legitimate ctfmon.exe process associated with alternate language and method inputs which is always located in %System%. This one is located in %AppData%\AdobeNo
Windows Live Messenger 8.12Xctfmon.exeAdded by the LIPARK-A WORM! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %UserProfile%No
WinXPServiceXctfmon.exeAdded by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in a "ctf" sub-folderNo
ctfmon.exeXctfmon.exe eminem.exeAdded by the BHARAT.A WORM!No
Ctfmon.exeXctfmon32.exeCoolWebSearch Ctfmon32 parasite variantNo
CTFMON32XCTFMON32.EXECoolWebSearch Ctfmon32 parasite variant - also detected as the CWS-E TROJAN!No
ctfmon32.exeXctfmon32.exeDetected by Dr.Web as Trojan.Siggen4.31693 and by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%No
User Input ServicesXCTFMON32.EXEAdded by the MANCSYN.AK TROJAN!No
Windows Services M7Xctfmon32.exeAdded by the AGENT.WOH TROJAN!No
Windows svchostXctfmon32.exeAdded by a variant of the SPYBOT WORM! See hereNo
ctfmonaXctfmona.exeAdded by the DLOADR-BME TROJAN!No
CTF Device LoaderXctfmond.exeAdded by the AGOBOT-FO WORM!No
MicrosoftctfmonXctfmonn.exeDetected by Dr.Web as Trojan.DownLoader6.4115 and by Malwarebytes Anti-Malware as Trojan.AgentNo
CTFMONSSXCTFMONSS.EXEAdded by the CWS-F TROJAN!No
Windows Update Firewall SystemXctfmoom.exeDetected by Sophos as W32/Rbot-GAN and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
ctfmoon.exeXctfmoon.exeDetected by Symantec as Trojan.MowhorcNo
msnXctfmoons.exeAdded by the SPYBOT.HI WORM!No
ctfmunXctfmun.exeAdded by the AGENT.ACEZ TROJAN!No
ntuserXctfmun.exeAdded by the SILLYFDC WORM!No
ctfmomXctfnom.exeAdded by the BCKDR-QTA BACKDOOR!No
ctfnomXctfnom.exeDetected by Dr.Web as Win32.HLLW.Autoruner1.16472 and by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%No
ctfnomXctfnom.exeDetected by Kaspersky as Trojan.Win32.Cospet.hph and by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%\DirNo
twinXctfnom.exeDetected by Symantec as W32.Ogleon.ANo
Win Updator ServicesXctfnom.exeAdded by a variant of the WOOTBOT WORM!No
msconfiguratorXctfsdk.exeAdded by the DELF-ALS TROJAN!No
loadXctftpscr32.exeAdded by the AGENT-FPN TROJAN!No
cft_monXctf_mon.exeDetected by Dr.Web as Trojan.MulDrop2.30269 and by Malwarebytes Anti-Malware as Trojan.KeyloggerNo
ctf_monXctf_mon.exeDetected by Dr.Web as Trojan.MulDrop2.30269 and by Malwarebytes Anti-Malware as Trojan.KeyloggerNo
cthelpXcthelp.exeAdded by the SDBOT BACKDOOR!No
CTHelperXcthelper.exeAdded by the RBOT-XB WORM! Note - do not confuse with the Creative application of the same name. Both files are found in %System% but this entry loads via the HKLM and HKCU "Run" and "RunServices" registry keys, whereas the Creative version only loads via the HKLM "Run" keyNo
CTHelperUCTHELPER.EXECTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative's sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a "leave alone" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need itNo
WINDVDpatchUCTHELPER.EXECTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative's sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a "leave alone" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need itNo
Win32 FireWire DriverXCTHELPER32.EXEAdded by the WOOTBOT TROJAN!No
CTin10XCTin10.exeAdded by the BANCOS.E TROJAN!No
Creative LauncherNCTLauncher.exeFor Creative Soundblaster Live! series soundcards. Adds a quick-launch bar to the top of the display and a System Tray icon. Available via Start → ProgramsNo
Creative Live! Cam ManagerUCTLCMgr.exeCreative Live! Cam ManagerNo
ControlCenterYctlcntr.exePart of Lenovo's (IBM) ThinkVantage Fingerprint Software - used on laptops and keyboards with integrated fingerprint readersNo
TaskBarNCTLTask.exeCreative SoundBlaster Audigy Taskbar - used to choose between different types of EAX Effects, not required in startup. NOTE: if you get a ctltask.exe error message while installing the Audigy drivers, see this Microsoft Knowledge Base articleNo
TasktrayNCTLTray.exeInstalled with the Sound Blaster Audigy range of soundcards. Allows you to set EAX effects or equalizer settings for the Sound Blaster Audigy from a systray icon. Also allows you to launch the Taskbar via right-click → Show Taskbar. The tasktray can be accessed via Start → Programs → Creative → Sound Blaster Audigy → TaskbarNo
CreativeMixerUCTMIX32.EXECreative soundcard System Tray access to, for example, volume slider controls as normally provided by the "speaker" icon. Not required unless you adjust any settings otherwise available via the standard iconNo
ctmmon.exeXctmmon.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.WTO. The file is located in %System%No
CMSETTINGSUctmn.exePart of NetNanny Chat MonitorNo
CtModuleXCtModule.exeAdded by the CLICKER-EG TROJAN!No
(Default)Xctmon.exeAdded by the BANCOS.AAN TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
svcshareXCTMONTv.exeAdded by the FUJACKS-AJ WORM!No
CTNMRUNUctnmrun.exeDetects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connectedNo
NOMAD DetectorUctnmrun.exeDetects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connectedNo
CreativeDiscNotifierNCTNOTIFY.EXEFor Creative sound cards. Detects when you insert a CD, DVD, etcNo
Disc DetectorNCtNotify.exeFor Creative sound cards. Detects when you insert a CD, DVD, etcNo
[various names]XCToolBar.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
CTPDPSRV?CTPDPSRV.EXECompaq A3000 printer driver (in the %System%\spool\DRIVERS\W32\X86 folder). Is it required?No
pdp ServerUctpdpsrvr.exeIncluded and setup with the drivers for my Compaq A3000 all-in-one printer/scanner - maybe for networking. Works fine without it - but may be needed when used over a networkNo
ctpmonXctpmon.exeRegistry Cleaner rogue - not recommended, removal instructions hereNo
ctpopXctpop.exeDetected by Malwarebytes Anti-Malware as Adware.Korad. The file is located in %ProgramFiles%\ctpopNo
CTPerformanceUtilityNCTPowUti.exeRelated to Creative PowerSysTrayApp. This program is a non-essential process, but should not be terminated unless suspected to be causing problemsNo
ctqmon.exeXctqmon.exeDetected by Dr.Web as Trojan.Disabler.84 and by Malwarebytes Anti-Malware as Backdoor.Sdbot. The file location variesNo
Microsoft task tray monitorXctray.exeAdded by a variant of Win32/RbotNo
CTRegRunNCTRegRun.exeFor Creative Soundblaster Live! series soundcards. Reminds you to register your card with CreativeNo
CtrlVolUCtrlVol.exeVolume control key on Acer, Fujitsu and other laptopsNo
CreativeTaskScheduler?CTSched.exeCreative Task Scheduler. What does it do and is it required?No
CTSched?CTSched.exeCreative Task Scheduler. What does it do and is it required?No
Speed racerNCTSRReg.exePart of the Creative PlayCenter for their range of soundcards - now replaced by Creative MediaSourceNo
Windows LoL LayerXctssjmn.exeAdded by the KOLAB.PBY WORM!No
CT Control SettingsXCTSVCCD.EXEDetected by Sophos as W32/Rbot-YSNo
CTSVolFEUCTSVolFE.exeCreative Labs Mixer applet for the Sound Blaster AudigyNo
CTSVolFE.exeUCTSVolFE.exeCreative Labs Mixer applet for the Sound Blaster AudigyNo
CTSyncU.exeNCTSyncU.exeCreative Sync Manager - synchronizes music tracks on your computer with your playerNo
CTsysVolUCTSysVol.exeCreative sound card volume controlsNo
cttdpsrv?cttdpsrv.exe??No
CTUpdateXctupdclt.exeAdded by the RBOT-ABG WORM!No
Windows Tracking ClientXctwsvc.exeDetected by Sophos as Troj/Agent-GMBNo
CTxfiHlpNCTXFIHLP.EXEAdded by the installation of a Creative Labs X-Fi sound card. This particular process provides the help functionality for your cardNo
CTXFIREGNCTxfiReg.exeCreative Labs sound card driver related. It appears that it isn't required and maybe registration relatedNo
*Microsoft UpdateXctxma.exeAdded by the STMU TROJAN!No
yazzzXctxmon.exeDetected by Symantec as W32.Yazz and by Malwarebytes Anti-Malware as Trojan.AgentNo
CTZDetec.exeNCTZDetec.exeAuto-detect feature of Creative Media Lite which assists you in managing your music, ripping CDs and transferring other stored music to your Zen Stone MP3 playerNo
ColdTurkey_notifyUct_notify.exeCold Turkey by Felix Belzile - "is a free/open source program that you can use to temporarily block yourself off of popular social media sites, addicting websites, online games and whatever else you want!"No
cuagentYCUAGENT.EXEPart of Commtouch Command Antivirus (was Authentium)No
cuagentExeYCuagent.exePart of Commtouch Command Antivirus (was Authentium)No
wacultXCujPDQjoAw.exeDetected by Dr.Web as Trojan.DownLoader4.15845 and by Malwarebytes Anti-Malware as Backdoor.Messa.GenNo
Norton UpdateXcUpdate.exeAdded by the AGOBOT.APP BACKDOOR!No
Start CurePCSolutionXCurePCSolution.exeCurePCSolution rogue spyware remover - not recommended, removal instructions hereNo
curoqvocysyxXcuroqvocysyx.exeDetected by McAfee as Generic.tfr!cr and by Malwarebytes Anti-Malware as Trojan.AgentNo
CurseClientNCurseClient.exeCurseClient add-on manager for World of Warcraft and Warhammer Online gamesNo
Intel CursorXCursor.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.JSM. The file is located in %MyDocuments%\ServicesNo
CursorFXUCursorFX.exeCursorFX from Stardock Corporation - cursor editing and management utility. Required if you use any cursors or effects supplied with or created by CursorFXYes
CursorGizmoUCursorGizmo.exeCursor Gizmo - cursor management utilityNo
CursorXPUCursorXP.exeCursorXP (now replaced by CursorFX) from Stardock Corporation - cursor editing and management utility. Required if you use any cursors or effects supplied with or created by CursorXPYes
Stardock CursorXPUCursorXP.exeCursorXP (now replaced by CursorFX) from Stardock Corporation - cursor editing and management utility. Required if you use any cursors or effects supplied with or created by CursorXPYes
CurtainUCurtain.exeCurtain (from Chaotic Visions) - "is a Windows utility which gives you the power to hide any window or group of windows to your system tray"No
System MonitoringXcute.exeAdded by the RAHIWI.A WORM!No
CuteMXNCuteMX.EXEFile sharing utilityNo
CleanUp AntivirusXCU[random].exeCleanup Antivirus rogue security software - not recommended, removal instructions hereNo
SaggwwggXCVAvwwd.exeAdded by the LIOTEN.HT WORM!No
Configuration LoaderXcvcd.exeAdded by the AGOBOT-DH BACKDOOR!No
XPSoftXCVDAsDW.exeAdded by the SDBOT-SY WORM!No
OfficeSyncProcessUCVH.EXEEntry created when you save files to a server (such as SkyDrive) from Click-To-Run versions of MS Office and used local and server copies in syncNo
goXcvir.exeAdded by the SILOV-A WORM!No
cvmonitor.exeXcvmonitor.exeAdded by the SDBOT.BV WORM!No
CVPNDYcvpnd.exeSub-system used by Cisco VPN client for making a connection to a remote IPSec serverNo
Windows media servicesXcvrsss.exeAdded by the RBOT-MW WORM!No
Winamp AgentXcvscc.exeAdded by the AGOBOT-GK WORM!No
smrUcvshost.exeSilent Monitoring surveillance software. Uninstall this software unless you put it there yourselfNo
Startup UpdateXCvshost.exeDetected by Symantec as W32.HLLW.Gaobot.AONo
HKCUXcvshosts.exeDetected by Malwarebytes Anti-Malware as Spyware.Password. The file is located in %Root%\installNo
HKLMXcvshosts.exeDetected by Malwarebytes Anti-Malware as Spyware.Password. The file is located in %Root%\installNo
MicrosoftservicesXcvshosts.exeDetected by Dr.Web as Trojan.DownLoader3.41142 and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
PoliciesXcvshosts.exeDetected by Malwarebytes Anti-Malware as Spyware.Password. The file is located in %Root%\installNo
MSN ManagerXcvss.exeAdded by a variant of the SPYBOT WORM!No
Bron-SpizaetusXCVT.exeAdded by the RONTOKBRO WORM!No
SystemGentXCVT.exeAdded by the BRONTOK-H WORM!No
WindongsXcvtres.exeDetected by Sophos as Troj/Mdrop-EYF and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
Windows MonitorXcvtres.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.CV. The file is located in %Temp%No
CWatchUcw.exeChatWatch - chat monitoring toolNo
CWUcw4.exeChat Watch "is a monitoring and logging software for online chat and instant messaging programs"No
Client Access API Daemon?cwbappcd.exePart of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. What does it do and is it required?No
Client Access Check VersionNcwbckver.exePart of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to. Not required - and can be turned off in the Client Access properties. It's a waste of resourcesNo
cwbckverNcwbckver.exePart of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to. Not required - and can be turned off in the Client Access properties. It's a waste of resourcesNo
Client Access Help UpdateNcwbinhlp.exeClient Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. It only updates the help files on your PC to match the level of the attached iSeriesNo
cwbinhlpNcwbinhlp.exeClient Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. It only updates the help files on your PC to match the level of the attached iSeriesNo
Client Access ServiceNCwbSvStr.ExePart of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resourcesNo
cwbsvstrNcwbsvstr.exePart of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resourcesNo
Client Access Taskbar?cwbuitsk.exePart of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. What does it do and is it required?No
Client Access Express Welcome?cwbwlwiz.exeWelcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. What does it do and is it required?No
cwbwlwiz?cwbwlwiz.exeWelcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. What does it do and is it required?No
Cwcdschk.exe?Cwcdschk.exeIBM Thinkpad related?No
cwcptrayUcwcptray.exeRelated to ContentWatch Parental Control internet filterNo
Crystal 3D Audio Control?CWD3DSND.EXECrystal 3D Audio sound driver. Is it required?No
Microsoft Driver SetupXcwdrive32.exeAdded by the VBINJEC-BT TROJAN!No
cwintoolXcwintool.exeAdded by the SMALL.ZZJ TROJAN!No
CoolwallpaperNcwm_tray.exeCool Wallpaper software allows you to manage high quality photos as desktop wallpaper and screen saversNo
cssmsXcwrcp.exeDetected by Sophos as Troj/Ransom-RF and by Malwarebytes Anti-Malware as Trojan.Agent.RNSNo
cwriterXcwriter.exePart of PcRaiser, SystemOptimizer2008, VelocidadSimple and other rogue optimization utilities - not recommendedNo
Command WorkStation 4Ucws 4.exeEFI's Command WorkStation makes "managing demanding workflows easier by centralizing job management. The software automatically identifies the Fiery servers on the network and offers customization options for displaying information" - for high-end print environmentsNo
WindowsNT CWServicesXCWServices.comDetected by Bitdefender as the AGENT.AGDK TROJAN! See hereNo
cwupdateUcwupdate.exeContentProtect from ContentWatch - internet filterNo
Windows Service AgentXcxfrru.exeDetected by Trend Micro as WORM_SDBOT.GAVNo
KV_HOSTXcxjx.exeAdded by the LEGMIR-BB TROJAN!No
*Microsoft UpdateXcxma.exeAdded by the STMU TROJAN!No
[random name]XCXTPLS_LOADER.EXEAproposMedia adwareNo
AutoloaderaproposclientXcxtpls_loader.exeAproposMedia adwareNo
H2OWIBUUCXWibu.exeRelated to CodeMeter from WIBU-SYSTEMS AG. Software protection hardwareNo
cyadiconXcyadicon.exeDetected by Dr.Web as Trojan.DownLoader3.61568 and by Malwarebytes Anti-Malware as Adware.K.CyadIconNo
CYAKXcyakup.exeCYAK rogue security software - not recommended, removal instructions hereNo
C2KUCYB2K.EXECYBERsitter 2000 or 2001 - anti-adult content filter primarily. Required if you want the sites you visit filtered without having to load the software every time you launch your browserNo
cybansosXcyban.exeAdded by the TATERF-V WORM!No
cyberboanXcyberboan_up.exeCyberBoan rogue security software - not recommended, removal instructions hereNo
CyberNcyberchk.exePart of Belkins "Multimedia Cleaning Kit" and is automatically installed when you run their optical disk drive cleaning utility - to remind you to clean your drive after "x" amount of time has passedNo
CyberLat Ram CleanerUCyberLat Ram Cleaner 1,1.exeCyberLat RAM Cleaner - memory optimizer. No longer supported or available from the authorsNo
24Online ClientUCyberoamClient.exeRelated to Cyberroam from Elitecore Technologies LtdNo
CyberWolfXCyberWolf.exeAdded by the KICKIN.A (or CYDOG.C) WORM!No
Dos Prompt LoaderXcygwin.exeAdded by the SDBOT-VV WORM!No
CYNHKey?CYNHKey.exe??No
CyphTrayNCyphTray.exeCypherus - encryption softwareNo
CypressLinkMonUCypressLinkMon.exeRelated to CypressViewer from Siemens that "allows ACUSON Cypress cardiovascular system PLUS users to store, view, and analyze Cypress system PLUS studies on a standard Windows PC"No
Windows Service Ag3ntXcyqwsb.exeAdded by the SDBOT.EZX TROJAN!No
KlceXcyxevwtj.exeDetected by Malwarebytes Anti-Malware as Trojan.Dropper. The file is located in %System%No
run=Xcyxid98.exeUnidentified malwareNo
ASDPLUGINXczech.exeAsdPlug premium rate adult content dialerNo
Windows Service AgentXczf.exeAdded by the RBOT-GAJ WORM!No
czrssXczrss.exeAdded by the AGENT-PAR TROJAN!No
Counterstrike Service AgentXczrzns.exeDetected by Trend Micro as WORM_MEDBOT.ARNo
httpdXc_pan.exeAdded by a variant of the DELF-A TROJAN!No

Notes & Warnings

If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us (startups_at_pacs-portal_dot_co_dot_uk).

"Status" key:

Variables:

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. We will not be held responsible if changes you make cause a system failure.

WARNING: This is NOT a database of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a database of start-up applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at start-up. For a list of tasks/processes you should try the Process Library from Uniblue, the list at PC Pitstop or one of the many others now available. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSConfig or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

To avoid the database becoming too large, all malware entries are only shown using the registry version which is common to all Windows versions. Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.

As more than 15K entries in this database related to malware you should use a quality internet security package. Which ever you choose, keep it updated and get the latest version at least every two years.

There are a number of virus and malware entried listed in this database where specific removal instructions haven't been given. If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. See here for a tutorial on how to use the program

NOTE: A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Norton eMail Protect" in the registry.

SERVICES: "Services" from the NT/2K/XP/Vista/7 operating systems are not included. We fully understand that some programs with these OS's use "Services" as an alternative to load their component parts at startup but these are handled in a different way. We recommend you try BlackViper for information on services for the relevant operating systems.

Copyright

Presentation, format & comments Copyright © 2001 - 2012 Pacman's Portal
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein, CastleCops & Bleeping Computer
Powered by Malwarebytes
All rights reserved

Valid XHTML 1.0 Transitional

Privacy Policy Site Map Home