? |
CAP3ON |
CAP3ONN.EXE | "Canon driver |
Y |
capfasem |
capfasem.exe | "CA Personal Firewall - part of the CA Internet Security Suite"
|
N |
Capfax |
capfax.exe | "PhoneTools fax software"
|
U |
capfupgrade |
capfupgrade.exe | "CA Personal Firewall - part of the CA Internet Security Suite"
|
U |
CAPing |
CAPing.exe | Citibank Citianywhere software
|
Y |
Capon |
Capon.exe | Canon printer driver
|
Y |
Capon |
Caponn.exe | Canon printer driver
|
X |
Captcha7 |
rundll captcha.dll | "Added by the TINY.WRE TROJAN!"
|
X |
CaptionMgr32 |
crssr.exe | "Added by the ZAR.A WORM!"
|
X |
capture |
capture.exe | "Added by the THEEF-B TROJAN!"
|
N |
Capture Express 2000 |
capexp.exe | "Capture Express - screen capture utility"
|
U |
CaptureAssistant |
CaptureAssistant.exe | "Capture Assistant ""is a convenient and easy-to-use text and graphics capture tool"". It allows you to capture text |
N |
CaptureBat |
Capture.exe | "!Quick Screen Capture from EtruSoft Inc. - ""allows you to take screenshots from any part of your screen in more than 10 ways |
N |
Carbonite Backup |
CarboniteUI.exe | """Carbonite's online backup service starts automatically and works quietly and continuously in the background protecting your data"""
|
N |
Card Monitor |
REGCNT09.exe | For the USB connection on a Panasonic PV-DV701 Digital Camcorder. Available via Start -> Programs
|
? |
CardScan AutoSync |
CSyncCfg.exe | "Related to the CardScan business card reader range of products. May be related to synchronization with E-mail software and mobile devices (see here)?"
|
X |
Care20 |
Care20.exe | "TopMoxie adware"
|
U |
Care2GTU |
Care2GTU.exe | "Care2 Green Thumbs-Up (from the Care2 site). Every online purchase helps environmental causes; tells you how eco-friendly a company really is |
U |
carpserv |
carpserv.exe | "Associated with Zoltrix and Conexant modems - enables the internal modem speaker |
X |
CARPserver |
CARPserver.exe | "Added by the BANKER-AN TROJAN!"
|
U |
CARPservice |
carpserv.exe | "Associated with Zoltrix and Conexant modems - enables the internal modem speaker |
X |
cartao |
[path to file] | "Added by the DLOADER-QD TROJAN!"
|
X |
cartao |
conflicted.exe | "Added by the DADOBRA-DV TROJAN!"
|
X |
cartao |
killing.exe | "Added by the DLOADER-QN TROJAN!"
|
X |
cartao |
cartao.exe | "Added by the BANKER-FA TROJAN!"
|
X |
CAS Client |
casclient.exe | "CasinoClient adware"
|
X |
Cas2Stub |
cas2stub.exe | "CasinoClient adware"
|
U |
CasAgnt |
CasAgnt.exe | Program by Extended Systems which allows you to sync your Casio PDA with your PC
|
X |
Casdvqwa |
bmqnzkg.exe | "Added by the RANDEX.BE WORM!"
|
X |
caseyvideo |
caseyvideo.exe | Malware causing adult content popups
|
X |
caseyvideo[*] [* = digit] |
caseyvideo[*].exe [* = digit] | Malware causing adult content popups
|
X |
CashBack |
cashback.exe | "Part of eXact Advertising Software |
X |
CashFiesta |
Cashfiesta.exe | "CASHFIESTA.A pay-per-surf adware"
|
N |
Cashsurfers Cashbar Navigator |
Cashbar.Exe | "Cashsurfers CashBar Navigator - ""The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers and deals"""
|
X |
CashToolbar |
MSCStat.exe | "Added by the DOWNLOADER-MY TROJAN!"
|
X |
CashToolbar |
svchost.exe | "BrowserAid/CashToolbar adware! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
|
X |
Casino Royale |
jamesbond.exe | "Added by the RBOT-FZO WORM!"
|
X |
Cassandra |
[10 to 14 random char]THD.EXE | "Added by the KREPPER-AI TROJAN!"
|
X |
Cassandra |
cassandra.exe | "SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as a variant of the KREPPER TROJAN!"
|
X |
CasStub |
casstub.exe | "Added by the CASS-A TROJAN!"
|
X |
Catalyst Control Centre |
atixvdm.exe | "Added by the RBOT.DMW TROJAN!"
|
X |
catsrv |
catsrv.exe | "Added by the PAPLOK TROJAN!"
|
Y |
CAVRID |
CAVRID.exe | "eTrust™ EZ Antivirus Real Time Infection Report from Computer Associates"
|
Y |
CAVS |
CAVS.exe | "Cheyenne (now eTrust) antivirus"
|
X |
CAZNOVAS |
CAZNOVAS.exe | "Added by the CAZNO TROJAN!"
|
X |
CBACK.EXE |
CBACK.EXE | "Added by the PENTA-A TROJAN!"
|
U |
cbInterface |
cbInterface.exe | "System Tray access to Cobian Backup versions 8 thru 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
|
X |
cbvcs |
urretnd.exe | "Added by the FRETHOG-C WORM!"
|
U |
CBWAttn |
CBWAttn.exe | "Required for Bitware to answer incoming faxes |
U |
CBWHost |
CBWHost.exe | "Required for Bitware to answer incoming faxes |
? |
CBWUser |
CBWDial.exe | "Associated with Bitware that integrates fax |
X |
CC2KUI |
comet.exe | "Comet Cursor adware"
|
X |
ccagent.exe |
ccagent.exe | "Control Center and Control Components rogue security software - not recommended |
X |
Ccao |
regedit.exe | "Probably a variant of MediaTickets adware. Note - this is not the valid Windows registry editor which resides in %Windir% and will not figure in Msconfig/Startup! This version resides in a ""mduu"" subfolder |
Y |
ccApp |
ccApp.exe | "Part of earlier versions of Norton AntiVirus - Auto-protect and E-mail check will not function without this"
|
X |
ccApp |
[random filename] | "Added by the OBSORB TROJAN! Note the random filename compared to the valid Norton AntiVirus"
|
X |
ccApp |
WMADZ.EXE | "Added by the RBOT-LJ WORM!"
|
X |
ccApp |
.EXE | "Added by the RBOT-LJ WORM!"
|
X |
ccApp |
gcasServ.exe | "Added by a variant of the RBOT WORM! Do not confuse with the Microsoft AntiSpyware executable of the same name"
|
X |
ccApp |
example.exe | "TwoSeven spyware"
|
X |
ccAppr |
svcrhost.exe | "Added by the TACTSLAY.A TROJAN!"
|
X |
ccAppr |
expIorer.exe | "Added by the TACTSLAY.A TROJAN!"
|
X |
ccAppr |
outIook.exe | "Added by the TACTSLAY.A TROJAN!"
|
X |
ccAppr |
svcshost.exe | "Added by the TACTSLAY.A TROJAN!"
|
X |
ccApps |
services.exe | "Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process |
X |
ccApps |
winlogon.exe | "Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process |
X |
ccApps |
N/A | "Added by the KANGAROO-A TROJAN!"
|
X |
ccApps |
ccApps.exe | "Added by the KANGAROO-B WORM!"
|
X |
ccctp |
HistoryJMTi.exe | "Added by the GANBATE.A WORM!"
|
U |
CCD Manager |
DDS.EXE | "Project Labs Century CD manager for their CD/DVD storage device"
|
N |
Ccdecode |
"rundll32.exe streamci | StreamingDeviceSetup" |
X |
ccDHCP32 |
ccDHCP32.exe | "Added by the AGOBOT-HJ WORM!"
|
Y |
CCDoctorLogonTesting |
ccdoctor.exe | "Checks your system to make sure it's configured properly for running IBM Rational ClearCase |
Y |
ccenter |
CCenter.exe | "RAV AntiVirus"
|
Y |
CcEvtMgr |
ccEvtMgr.exe | "Part of Norton AntiVirus 2003. Event manager for scheduling weekly scans and or automatic virus updates. Used to start automatically via ""ccApp"" and was not required as a seperate entry but a recent update changed this"
|
X |
ccEvtMrg.exe |
ccEvtMrg.exe | "Added by the RBOT.GZ WORM!"
|
X |
ccExecute |
bootcfg1.exe | "Added by the NEMSI-B VIRUS!"
|
X |
ccHelp |
ccHelp.hta | "Searchq adware"
|
U |
CCleaner |
CCleaner.exe | "CCleaner from Piriform Ltd. - ""is a freeware system optimization |
X |
ccpApps |
csrss.exe | "Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
|
X |
ccpApps |
lsass.exe | "Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
|
U |
ccProxy |
CCPROXY.EXE | "Part of Norton Internet Security |
X |
ccPrxy.exe |
ccPrxy.exe | "Added by the SHIPUP-H WORM!"
|
Y |
CcPxySvc |
CCPXYSVC.exe | "Part of Norton's AntiVirus 2003 |
X |
ccreg |
explorer.exe | "Added by the ZCREW BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
Y |
ccRegVfy |
ccRegVfy.exe | "Part of earlier versions of Norton AntiVirus - ""ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack"""
|
X |
ccRegVfY |
expIorer.exe | "Added by the TACTSLAY.A TROJAN!"
|
X |
ccRegVfY |
svcrhost.exe | "Added by the TACTSLAY.A TROJAN!"
|
X |
ccRegVfY |
svcshost.exe | "Added by the TACTSLAY.A TROJAN!"
|
X |
ccRegVfY |
outIook.exe | "Added by the TACTSLAY.A TROJAN!"
|
X |
ccrss |
msdtc.exe | "Added by the STAP-C WORM!"
|
Y |
ccSetMgr |
ccSetMgr.exe | "Part of Norton AntiVirus 2004. What does it do?"
|
X |
ccStart |
ccStart.exe | "Added by the AGOBOT-IR WORM!"
|
X |
ccStart |
ccInfo.exe | "Added by the AGOBOT-GQ BACKDOOR!"
|
X |
ccSvcHst.exe |
ccSvcHst.exe | "Added by the SDBOT-DIW WORM!"
|
X |
ccsvit.exe |
ccsvit.exe | "Added by the STARTPA-HP TROJAN!"
|
U |
cctray |
cctray.exe | "Part of CA Internet Security Suite"
|
X |
ccUpdate |
ccUpdate.exe | "Added by the AGOBOT.YS WORM!"
|
U |
ccUpdMgr |
ccUpdMgr.exe | "In Loco Parentis remote surveillance software. Uninstall this software unless you put it there yourself!"
|
U |
CCUTRAYICON |
CCU_TrayIcon.exe | "Related to Traybar Launcher from Intel Corporation belonging to Intel® Viiv®"
|
U |
ccWasher |
aolwasher.exe | "Webroot Cache & Cookie Washer - cleaning browser tracks |
U |
CCWC7a |
ac.exe | "Moleculesoft Cache |
U |
CCWC7I |
idxl.exe | "Moleculesoft Cache |
U |
CCWC7s |
stealth.exe | "Moleculesoft Cache |
Y |
CCWinTray |
wintmr.exe | "System Tray access to Child Control parental control software by Salfield"
|
N |
CD Storage Master |
cdstorager.exe | "CD Storage Master - a program designed to catalog CD information |
U |
CD-DVD Lock for Win95/98/Me/2k/XP |
CDVAgent.exe | "Loads CD-DVD Lock from Ixis Research |
X |
cd1 |
cd1.exe | Premium rate adult content dialler
|
N |
CDANTSRV |
CDANTSRV.exe | "C-Dilla License Management software. Used for any program that uses C-dilla Protection |
X |
Cdcompat |
Cdcompat.exe | "Added by the GEMA TROJAN!"
|
X |
cddrv32 |
cddrv32.exe | "Added by a variant of the CRYPTER.C TROJAN!"
|
N |
CDInterceptor |
cdi.exe | CD indexer for measuring the speed of CD players
|
Y |
cdloader |
cdloader2.exe | "From MagicJack - ""A softphone device that allows you to attach an analog phone into the PC so you can have a traditional-style phone system in your house without any monthly charge"""
|
U |
CDLoader |
sb32mon.exe | "Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
|
X |
cdmmslpo |
klpllsm.exe | "Added by the TEDIJINI-A TROJAN!"
|
X |
CdnCtr |
cdnup.exe | "CNNIC Update pest"
|
X |
cdoosoft |
herss.exe | "Added by the SILLYFDC.BCT WORM!"
|
X |
cdoosoft |
olhrwef.exe | "Added by the AUTORUN-AAG WORM!"
|
X |
CDriver |
windrv.exe | "Added by the DELF.WG TROJAN!"
|
X |
CDriver |
svchost.exe | "Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
|
X |
Cdrom Controller |
cdromcntrl.exe | "Added by the BATTRY-A TROJAN!"
|
X |
cds |
cds.exe | "Added by the SPYMON TROJAN!"
|
X |
CDSpeed.exe |
CDSpeed.exe | "Added by the IRCBOT.AEX BACKDOOR!"
|
N |
CDTray |
CDTray.exe | "On HP PCs |
U |
CDVAgent |
CDVAgent.exe | "Loads CD-DVD Lock from Ixis Research |
U |
CeEKEY |
CeEKey.exe | Hot Key utility included on Toshiba Satellite laptops
|
U |
CeEPOWER |
cepmtray.exe | "Toshiba's Power Management Utility - allows the user to setup different profiles for both AC power and Battery Power on laptops. Contols CPU speed |
? |
Ceic |
Ceic.exe | "??"
|