Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

5.0.07.0440 25.00%
5.0.07.0290 43.75%
5.0.05.0290 6.25%
5.0.03.0530 6.25%
5.0.02.0090 6.25%
4.8.02.0010 6.25%
4.7.00.0533 6.25%

Relationships


PE structurePE file structure

Show functions
Import table
crypt32.dll
CryptMsgClose, CertFreeCertificateContext, CertGetNameStringA, CertFindCertificateInStore, CryptMsgGetParam, CryptQueryObject, CertAddCertificateContextToStore, CertSetCertificateContextProperty, CertCreateCertificateContext, CertOpenStore, CertAddEncodedCertificateToStore, CertGetSubjectCertificateFromStore, CertEnumCertificatesInStore, CertDeleteCertificateFromStore, CertAddEncodedCRLToStore, CertFreeCRLContext, CertGetCRLFromStore, CertDeleteCRLFromStore, CertGetCertificateContextProperty, CertCloseStore
kernel32.dll
GetCurrentThreadId, FreeLibrary, GetProcAddress, LoadLibraryA, GetSystemDirectoryA, GetComputerNameA, GlobalFree, HeapAlloc, HeapFree, GetProcessHeap, GetVersionExA, CreateProcessA, TerminateProcess, OpenProcess, GetExitCodeProcess, ReadFile, WriteFile, GetStartupInfoA, DuplicateHandle, GetCurrentProcess, SetStdHandle, CreatePipe, GetStdHandle, CreateDirectoryA, RemoveDirectoryA, DeleteFileA, MoveFileA, GetCurrentDirectoryA, SetCurrentDirectoryA, FindFirstFileA, FindNextFileA, SetConsoleCtrlHandler, CopyFileA, GetExitCodeThread, CreateThread, LocalFree, LocalAlloc, lstrlenA, WritePrivateProfileStringA, GetPrivateProfileIntA, GetWindowsDirectoryA, OutputDebugStringA, MultiByteToWideChar, WideCharToMultiByte, GetTickCount, QueryPerformanceCounter, GetLocalTime, GetProcessTimes, GetThreadTimes, GetCurrentThread, GlobalMemoryStatus, GetProcessWorkingSetSize, GetModuleHandleA, GetCurrentProcessId, SetEndOfFile, SetFilePointer, GetFileAttributesA, FlushFileBuffers, LockFile, UnlockFile, ReleaseMutex, CreateMutexA, CreateEventA, WaitForSingleObject, ResetEvent, GetModuleFileNameA, OpenEventA, Sleep, CreateFileA, DeviceIoControl, GetLastError, CloseHandle, SetEvent, GetFileSize, GetDiskFreeSpaceA, InitializeCriticalSection, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, RaiseException, LCMapStringA, FindClose, InterlockedExchange, LCMapStringW, PeekNamedPipe
msvcirt.dll
_mtlock, _mtunlock
msvcp60.dll
DllMain
msvcrt.dll
DllMain
rasapi32.dll
RasEnumEntriesA
vpnapi.dll
vpn_get_service_start_event
wininet.dll
InternetSetOptionA, InternetQueryOptionA
Export table
IsdGetCapability
IsdGetRandomNumber
IsdGetStatistic
IsdTestRandomGenerator

CVPND.exe

Cisco Systems VPN Client by Cisco Systems (Signed)

Remove CVPND.exe
Version:   5.0.03.0530
MD5:   52ce186247ca74ee01f0742aa6609a30
SHA1:   3b3cb1aaca8bcc96a73f7f2160aa8000924dfa1d
SHA256:   1108f7fd2b8b3b074c2810753b5022a45597d5a1e7daa154bec09d0c3ef3f8cc

Overview

cvpnd.exe runs as a service under the name Cisco Systems, Inc. VPN Service (CVPND) with extensive SYSTEM privileges (full administrator access). The file is digitally signed by Cisco Systems which was issued by the Thawte Consulting (Pty) Ltd. certificate authority (CA).

DetailsDetails

File name:cvpnd.exe
Publisher:Cisco Systems, Inc.
Product name:Cisco Systems VPN Client
Typical file path:C:\Program Files\cisco systems\vpn client\cvpnd.exe
File version:5.0.03.0530
Size:1.46 MB (1,528,608 bytes)
Certificate
Issued to:Cisco Systems
Authority (CA):Thawte Consulting (Pty) Ltd.
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'CVPND' (Cisco Systems, Inc. VPN Service)
  • CVPND
Network connections
  • [UDP] listens on port 62514

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00019649%
    0.028634%
    Kernel CPU:0.00014227%
    0.013761%
    User CPU:0.00005422%
    0.014873%
    Kernel CPU time:8,984 ms/min
    100,923,805ms/min
    Context switches:1/sec
    284/sec
    Memory
    Private memory:3.09 MB
    21.59 MB
    Private (maximum):5.85 MB
    Private (minimum):820 KB
    Non-paged memory:3.09 MB
    21.59 MB
    Virtual memory:38.88 MB
    140.96 MB
    Virtual memory (peak):39.88 MB
    169.69 MB
    Working set:936 KB
    18.61 MB
    Working set (peak):6.07 MB
    37.95 MB
    Resource allocations
    Threads:4
    12
    Handles:175
    600
    GUI GDI count:4
    103
    GUI USER count:5
    49

    BehaviorsProcess properties

    Integrety level:Undefined
    Platform:32-bit
    Command line:"C:\Program Files\cisco systems\vpn client\cvpnd.exe"
    Owner:SYSTEM
    Windows Service
    Service name:CVPND
    Display name:Cisco Systems, Inc. VPN Service
    Type:Win32OwnProcess, InteractiveProcess
    Parent process:services.exe (Services and Controller app by Microsoft)

    ResourcesThreads

    Averages
     
    msvcrt.dll (Windows NT CRT DLL by Microsoft)
    Total CPU:0.00188862%
    0.272967%
    Kernel CPU:0.00126736%
    0.107585%
    User CPU:0.00062126%
    0.165382%
    Memory:352 KB
    1.16 MB
    ADVAPI32.dll
    Total CPU:0.00005422%
    Kernel CPU:0.00004066%
    User CPU:0.00001355%
    Memory:620 KB
    cvpnd.exe (main module)
    Total CPU:0.00001807%
    Kernel CPU:0.00001355%
    User CPU:0.00000452%
    Memory:1.48 MB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Microsoft Windows XP 25.00%
    Windows 7 Professional 25.00%
    Windows 7 Home Premium 18.75%
    Windows Vista Ultimate 12.50%
    Windows 7 Ultimate 12.50%
    Windows Vista Business 6.25%

    Distribution by countryDistribution by country

    United States installs about 37.50% of Cisco Systems VPN Client.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Lenovo 44.44%
    Hewlett-Packard 33.33%
    Toshiba 22.22%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE