| Status | Autorun name | Command | Description |
| X | CTFM0N.exe | CTFM0N.exe | Added by the STARTPAGE.P TROJAN! Notice the digit "0" in both columns rather than the upper case "o" |
| X | ctfmen | cssrs.exe | Added by the STARTP-DC TROJAN! |
| X | ctfmgr | ctfmgr.exe | Added by the PWS-ATU TROJAN! |
| X | ctfmom | ctfnom.exe | Added by the BCKDR-QTA BACKDOOR! |
| U | ctfmon | ctfmon.exe | Supports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or, for example, if speech is selected as an alternative input for MS Office or Notepad. Required to support advanced text services (such as right to left text) for East Asian users. Can be disabled via Start → Control Panel → Regional and Language Options → Languages → Text Services and Input Languages → Details → Advanced → System Configuration → Turn off advanced text services (which also turns off the language bar). See also here and here. Can also cause problems with some other programs if left enabled - see here for such an example |
| X | ctfmon | taskmgr32*.exe [* = number] | Added by the SOWSAT.B WORM! |
| X | ctfmon | cftmon.exe | Added by the DELIVE-A BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir% |
| X | ctfmon | mIRC.dll | Added by the DELBOT-E TROJAN! |
| X | ctfmon | WinConst.exe | Added by the ASSASIN-G TROJAN! |
| U | CTFMon | ctfmon.exe | Family KeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in a "CTF" sub-folder |
| X | ctfmon | msnmsgr.exe | Added by the BDOOR-JV BACKDOOR! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System% |
| X | CTFMON | wscript.exe /E:vbs winjpg.jpg | Added by the RUNAUTO.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "winjpg.jpg" file is located in %System% |
| X | CTFMON | wscript.exe /E:vbs regedit.sys | Added by the VBSAUTO-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "regedit.sys" file is located in %System% |
| X | CTFMON | win.exe | Added by the VBS.RUNAUTO.G WORM! |
| X | Ctfmon | wmisys.exe | Added by the IRCBOT-ADS WORM! |
| X | ctfmon | WinUP.exe | Added by the BANKER-VV TROJAN! |
| X | ctfmon | ctfmon.exe | Added by the AUTORUN-G WORM! Note - this is not the legitimate ctfmon.exe process associated with alternate language and method inputs which is always located in %System%. This one is located in a "1046" sub-folder |
| X | ctfmon | svhost.exe | Added by the BACKDR-EL BACKDOOR! |
| X | CTFMON.CPL | CTFM0N.CMD | Detected by Symantec as the SILLYFDC WORM! See here |
| X | Ctfmon.exe | ctfmon32.exe | CoolWebSearch Ctfmon32 parasite variant |
| X | ctfmon.exe | ctfmon.exe | Added by the RAIDYS TROJAN! Note - this overwrites the legitimate ctfmon.exe process associated with alternate text inputs which is located in %System% |
| X | ctfmon.exe | msupdate32.exe | Spy Sheriff/SpywareNO malware, also detected as the SPYHOAX-A TROJAN, pretends to be a spyware remover! - file names spotted sofar include VXH8JKDQ2.EXE, NS6281400.so, CVXH8JKDQ2.EXE, down3.exe, sefe.exe, winstall.exe, and tool2.exe |
| U | ctfmon.exe | ctfmon.exe | Supports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or, for example, if speech is selected as an alternative input for MS Office or Notepad. Required to support advanced text services (such as right to left text) for East Asian users. Can be disabled via Start → Control Panel → Regional and Language Options → Languages → Text Services and Input Languages → Details → Advanced → System Configuration → Turn off advanced text services (which also turns off the language bar). See also here and here. Can also cause problems with some other programs if left enabled - see here for such an example |
| X | ctfmon.exe | ctfmon.exe eminem.exe | Added by the BHARAT.A WORM! |
| X | CTFMON.EXE | svchost.exe | Added by the JUEGO-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | ctfmon.exe | CTFM0N.EXE | Added by the AUTORUN-AYX WORM! Notice the digit "0" in the filename rather than the upper case "o" |
| U | ctfmon.exe | ctfmon.exe | TotalSpy keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %ProgramFiles%\TS Trial |
| X | CTFMON.EXE | ctfmon.exe | Added by the VBSP-A WORM! Note - this is not the legitimate ctfmon.exe process associated with alternate language and method inputs which is always located in %System%. This one is located in a "1126" sub-folder |
| X | CTFMON32 | CTFMON32.EXE | CoolWebSearch Ctfmon32 parasite variant - also detected as the CWS-E TROJAN! |
| X | ctfmon32 | [random filename].exe | Added by the RBOT-GSN WORM! |
| X | ctfmon32 | taskmgr32*.exe [* = digit] | Added by the SOWSAT.C WORM! |
| X | ctfmona | ctfmona.exe | Added by the DLOADR-BME TROJAN! |
| X | CTFMONSS | CTFMONSS.EXE | Added by the CWS-F TROJAN! |
| X | ctfmoon | microsoftconfigurator.exe | Added by the DELF-ALS TROJAN! |
| X | ctfmun | ctfmun.exe | Added by the AGENT.ACEZ TROJAN! |
| X | ctfnnon | ctfmon.exe | Added by the TURKOJAN.IL BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir% |
| X | ctfnom | rundIl32.exe | Added by the LEGMIR-AW TROJAN! |
| X | ctfnom.exe | SVOHOST.exe | Added by the DIGIDOR-A TROJAN! |
| X | ctfnom.exe | OSRSS.exe | Added by the DLOADER-UQ TROJAN! |
| X | cthelp | cthelp.exe | Added by the SDBOT TROJAN! |
| U | CTHELPER | CTHELPER.EXE | CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative's sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a "leave alone" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it |
| X | CTHelper | cthelper.exe | Added by the RBOT-XB WORM! Note - do not confuse with the Creative application of the same name described here |
| X | CTHELPER | svhost.exe | Added by the SDBOT-RZ WORM! |
| X | CTime | [path to trojan] | Added by the HTTPDOS TROJAN! |
| X | CTin10 | CTin10.exe | Added by the BANCOS.E TROJAN! |
| X | CtModule | CtModule.exe | Added by the CLICKER-EG TROJAN! |
| X | CTMON.EXE | cfmon.exe | Added by the CLCKR-AN TROJAN! |
| U | CTNMRUN | ctnmrun.exe | Detects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connected |
| ? | CTPDPSRV | CTPDPSRV.EXE | Compaq A3000 printer driver (in the %System%\spool\DRIVERS\W32\X86 folder). Is it required? |
| N | CTPerformanceUtility | CTPowUti.exe | Related to Creative PowerSysTrayApp. This program is a non-essential process, but should not be terminated unless suspected to be causing problems |
| X | ctpmon | ctpmon.exe | Registry Cleaner rogue - not recommended, removal instructions here |
| N | CTRegRun | CTRegRun.exe | For Creative Soundblaster Live! series soundcards. Reminds you to register your card with Creative |
| U | CtrlVol | CtrlVol.exe | Volume control key on Acer, Fujitsu and other laptops |
| ? | CTSched | CTSched.exe | Creative Task Scheduler. What does it do and is it required? |
| N | CTStartup | CTEaxSpl.exe | Splash screen with sound on every boot up. Installed with a Sound Blaster Audigy soundcard |
| U | CTSVolFE | CTSVolFE.exe | Creative Labs Mixer applet for the Sound Blaster Audigy |
| U | CTSVolFE.exe | CTSVolFE.exe | Creative Labs Mixer applet for the Sound Blaster Audigy |
| N | CTSyncU.exe | CTSyncU.exe | Creative Sync Manager - synchronizes music tracks on your computer with your player |
| U | CTsysVol | CTSysVol.exe | Creative sound card volume controls |
| ? | cttdpsrv | cttdpsrv.exe | ?? |
| X | CTUpdate | ctupdclt.exe | Added by the RBOT-ABG WORM! |
| N | CTxfiHlp | CTXFIHLP.EXE | Added by the installation of a Creative Labs X-Fi sound card. This particular process provides the help functionality for your card |
| N | CTXFIREG | CTxfiReg.exe | Creative Labs sound card driver related. It appears that it isn't required and maybe registration related |
| X | Ctykd | [path to file] | SMALL.SN spyware |
| N | CTZDetec.exe | CTZDetec.exe | Auto-detect feature of Creative Media Lite which assists you in managing your music, ripping CDs and transferring other stored music to your Zen Stone MP3 player |
| X | CU1 | VCClient.exe | Associated with the Surf Sidekick adware and should be removed |
| X | CU2 | VCMain.exe | Associated with the Surf Sidekick adware and should be removed |
| Y | cuagentExe | Cuagent.exe | Command Antivirus related |
| X | CueX44 | Dago.exe | Added by the PUNYA-B WORM! |
| X | CueX44_stil_here | WINLOGON.EXE | Added by the PUNYA-A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
| X | cuo | cuo.exe | Added by the BUGBEAR.A WORM! |
| U | Currency | windowsintd.exe | Intruder keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | Current Security Config | csecure.exe | Added by the RBOT-AMO WORM! |
| X | Current32 | msnpla.exe | Added by the SDBOT-DIS WORM! |
| X | CurrentVersion | recyclebin.exe | Added by the AUTORUN-AZX WORM! |
| N | CurseClient | CurseClient.exe | CurseClient add-on manager for World of Warcraft and Warhammer Online games |
| N | cursor | Screendragon_VS_Taskbar.exe | ScreenDragon video player |
| U | CursorFX | CursorFX.exe | CursorFX from Stardock Corporation - cursor editing and management utility. Required if you use any cursors or effects supplied with or created by CursorFX |
| U | CursorGizmo | CursorGizmo.exe | Cursor Gizmo - cursor management utility |
| U | CursorXP | CursorXP.exe | CursorXP (now replaced by CursorFX) from Stardock Corporation - cursor editing and management utility. Required if you use any cursors or effects supplied with or created by CursorXP |
| U | Curtain | Curtain.exe | Curtain (from Chaotic Visions) - "is a Windows utility which gives you the power to hide any window or group of windows to your system tray" |
| U | Customizer2000 | logon.exe | Automatic logon feature of Customizer 2000 - "a special utility which is designed to optimize Win9x/ME performance. The program lets you explore the many hidden settings in Windows, and make changes" |
| N | CuteMX | CuteMX.EXE | File sharing utility |
| X | Cvfjx | ANACON.EXE | Added by the NACO.A WORM! |
| X | cvhnykzx | keepSafe.exe | Added by the KILLAV.KAX TROJAN! Note - this is not the legitimate KeepSafe from Stardock Corporation which shares the same filename and is normally located in a %ProgramFiles%\Stardock subfolder. This one is found in %System% |
| X | cvmonitor.exe | cvmonitor.exe | Added by the SDBOT.BV WORM! |
| X | cvmsyslpd | sdservss.exe | Added by the MAILBOT-BY TROJAN! |
| Y | CVPND | cvpnd.exe | Sub-system used by Cisco VPN client for making a connection to a remote IPSec server |
| U | CW | cw4.exe | Chat Watch "is a monitoring and logging software for online chat and instant messaging programs" |
| U | CWatch | cw.exe | ChatWatch - chat monitoring tool |
| N | cwbckver | cwbckver.exe | Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to. Not required - and can be turned off in the Client Access properties. It's a waste of resources |
| N | cwbinhlp | cwbinhlp.exe | Client Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. It only updates the help files on your PC to match the level of the attached iSeries |
| N | cwbsvstr | cwbsvstr.exe | Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resources |
| ? | cwbwlwiz | cwbwlwiz.exe | Welcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. What does it do and is it required? |
| ? | Cwcdschk.exe | Cwcdschk.exe | IBM Thinkpad related? |
| U | cwcptray | cwcptray.exe | Related to ContentWatch Parental Control internet filter |
| X | cwingllib | atllsimm.exe | Added by a variant of the SDBOT WORM! |
| X | cwintool | cwintool.exe | Added by the SMALL.ZZJ TROJAN! |
| X | cwriter | ucookw.exe | Part of the ErrClean rogue system error and cleaning utility and other members of this family. See here for more examples |
| X | cwriter | cwriter.exe | Part of PcRaiser, SystemOptimizer2008, VelocidadSimple and other rogue optimization utilities - not recommended |