| Name | Status | Filename | Description |
|---|
| Client/Server Runtime Server Subsystem (CSRSS) | X | csrss.exe | W32/IRCBot-UN
Note: Located in %windir%, not to be confused with the legitimate file in %windir%\system32 (%windir%\system on windows 98/ME) Read the link, allows remote access and steals information |
| Client32 | L | client32.exe | NetSupport Manager by "NetSupport Ltd.". |
| Cliente de seguimiento de vinculos distribuidos | L | services.exe | Spanish Windows 2000 distributed links tracking client |
| Cliente DHCP | L | services.exe | Spanish Windows 2000 DHCP client |
| Cliente DNS | L | services.exe | Spanish Windows 2000 DNS client |
| Clients Server Runtime Process | X | csrss.exe | Added by the W32/Sdbot-CPF WORM! Note: This worm\trojan is located in C:\%WINDIR% This is not the legitimate Windows Process. (Which is found in the System32 folder.) |
| Clients Server Runtime Process (Windows Internet) | X | csrss.exe | Added by the W32/Sdbot-CPF WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder. |
| Clip Book | X | gezi-yasuo.exe | Troj/QQHelpe-CY
Note: Troj/QQHelpe-CY installs a number of files besides gezi-yasuo.exe in a few locations. Read the link |
| ClipBo0k | X | book.exe | Added by a variant of the BKDR_HUPIGON.EVG backdoor Trojan. Identified by Trend Micro. Note: Located in \%ROOT%\ |
| clmss (Content List Management Sub System) | X | clmss.exe | Added by the W32/Tilebot-AO
WORM!
Note: This worm file is found in the Windows or Winnt folder.
Read the link, rootkit type stealth involved.
|
| Clr_ui | L | atinpdxx.sys | Related to ATI Specialized PCD VBI Codec. Note: Located in \%WINDIR%\System32\drivers\ |
| CMG Shield (auet4iogie5an) | X | nvslzrygvb.exe | Added by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename. |
| CMG Shield (CMGShield) | L | Credant.exe | Related to CMG_Shield Application from Credant Technologies. CREDANT Mobile Guardian Enterprise Edition (CMG EE) is an integrated, policy-based mobile data security, Note: Located in \%WINDIR%\System32\ |
| CMGShield | L | CmgShieldSvc.exe | Related to Credant_Technologies data encryption software for laptop and USB encryption to CD-DVD recorders, iPods and Smart Phones. Note: Located in \%WINDIR%\System32\ |
| CNG Key Isolation (KeyIso) | L | lsass.exe | Part of Windows Vista
Note:Located in C:\%WINDIR%\System32 |
| Cobian Backup 8 service (CobBMService) | L | cbService.exe | Related to Cobian_Backup An Open Source projects. Note: Located in C:\Program Files\Cobian Backup 8\ Note Open souce project can be modified. Make sure you scan the program with a Virus protection program before using. |
| Codec | X | WINCODEC.EXE | Added by the SDBOT.CJO
WORM!
Read the link, rootkit type stealth involved.
|
| COGECO Security Services (BackWeb Plug-in - 9867844) | O | SERVIC~1.EXE | Related to COGECO_F-Secure Backweb application. Note: Located in \%Program Files%\COGECO~1\backweb\9867844\Program\ |
| Cognos ReportNet | L | cogbootstrapservice.exe | Related to Cognos_ReportNet Business Intelligence software. Note: located in C:\Program Files\Cognos\crn\bin\ |
| Cognos ReportNet (ruzxj7ol3oeak) | X | bnoilfhxkgvz.exe | Added by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename. |
| ColdFusion Graphing Server | L | JRun.exe | Related to MacroMedia_ColdFusion
products. Made by MacroMedia,Inc.
|
ColdFusion Management Repository Server (ColdFusion Management Repository) | L | jrun.exe | Related to MacroMedia_ColdFusion
products. Made by MacroMedia,Inc. |
| ColdFusion Management Service | L | CANamingAdapter.exe | Related to MacroMedia_ColdFusion
products. Made by MacroMedia,Inc.
|
| ColdFusion Monitoring Service (ClusterCATS Service) | L | ccmgr.exe | Related to MacroMedia_ColdFusion
products. Made by MacroMedia,Inc. |
| ColdFusion MX 7 Search Server | L | k2admin.exe | Related to Cold_Fusion from Adobe Systems Incorporated. Note: Located in \%ROOT%\ |
| ColdFusion MX Application Server | L | jrunsvc.exe | Related to Macromedia Cold Fusion software. |
| ColdFusion MX ODBC Server | L | swstrtr.exe | Related to Macromedia Cold Fusion software. |
| Collaboration Runtime Service (xmppd-jse) | L | xmppd-jse.exe | Related to Sun_Java_Studio_Enterprise Software. Note: Located in \%Program Files%\Sun\jstudio_ent81\collab\bin\ |
| COM Host (comHost) | L | comHost.exe | Related to Norton/Symantec Internet Security |
| COM Message Transfer (mscommt) | X | svchost.exe -k mscommt | Added by the Troj/Dbit-A
TROJAN!
|
| COM+ Component Service (COMCSVC) | X | winmgnt.exe | Added by unknown malware, the file winmgnt.exe may be a Serv-U FTP server used to download other malicious files to your computer. File location is in the System32 folder. |
| COM+ Event System (EventSystem) | L | svchost.exe -k LocalService | Part of Windows Vista
Note:Located in C:\%WINDIR%\System32 |
| COM+ Interface (svcmngr) | X | svcgirl.exe | Added by an unknown malware. Note: This worm\trojan is located in C:\%WINDIR%\TEMP\ folder. |
| COM+ Messages | X | svchosts.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| COM+ System Application (COMSysApp) | L | dllhost.exe | Part of Windows Vista
Note:Located in C:\%WINDIR%\System32 |
| COM+ System Applications (COMSystemApp) | X | dllhost.exe | W32/SillyFDC-AV
Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (Vista/XP/WinNT/2K) Turns off anti-virus applications
and Steals information |
| COM+ System Client (ComSysCnt) | X | cmsvc.exe | Identified as the SdBot.bis worm Note: This worm is located in C:\WINDOWS\repair\ |
| COM+ System Service (COMSS) | X | SSMS.EXE | Added by unknown malware. File location is in the System32 folder. |
| COM+ System Service (DLLHOST) | X | dllhost.exe | Added by the Backdoor.Win32.SdBot.xd as identified by Kaspersky TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
|
| COM+ System Source (COMSysSRC) | X | vmnat.exe | W32/Tilebot-JE Note: Located in %windir%\system32 Read the link, allows remote access |
| Com4Qlb | L | Com4Qlb.exe | Related to HP_Compaq Buttons. Note: Located in \%Program Files%\Hewlett-Packard\HP Quick Launch Buttons\ |
| Command Lsass Services | X | svshost.exe | Added by a varian of the Backdoor.Sdbot family of trojan. Note: Located in \%WINDIR%\System32\ |
| Command Service (cmdService) | X | command.exe | Adware |
| CommServer | L | CommSvr.exe | Related to the HiPath 1220 digital PBX system from Siemens. For more information Click_Here
File location is in the Program Files\Siemens\HiPath 1220\CommServer2.0 folder.
|
| CommServer (audieqaad) | X | lmguc.exe | Added by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename. |
| Comodo Anti-Virus and Anti-Spyware Service | L | cavasm.exe | Related to Comodo Anti-Virus and Anti-Spyware Service Note: Located in \%Program Files%\Comodo\common\CAVASpy\ |
| Comodo Application Agent (CmdAgent) | L | cmdagent.exe | Related to Comodo_Firewall from Comodo. Note: Located in C:\Program Files\Comodo\Firewall\ |
| COMODO Firewall Pro Helper Service (cmdAgent) | L | cmdagent.exe | Comodo_Firewall |
| Compaq Advisor (Compaq_RBA) | L | compaq-rba.exe | Related to Compaq |
| Compaq DMI Web Agent | L | WebDmi.exe | Related to Compaq Computer. |