Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X*Intelli Mouse Pro Version 2.0B*ncsjapi32.exe"Added by the BUZUS-O WORM!"
X.mscsblsvhost.exe"Added by the CMQ TROJAN!"
X.svchostCSRSS.EXE"Added by the WEBUS.F TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X.TEXTCONVcsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
X.WMAudiocsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
X27csrss32.exe"Added by the SLSORVE-D TROJAN!"
X852EBF20-A95D-4F1F-B9C2-B2CD24350F3Esysodkcs.exe"Added by the FAKEALERT-AH TROJAN!"
UAbsoluteShield Internet Erasercseraser.exe"AbsoluteShield Internet Eraser - ""protects your privacy by cleaning up all the tracks of your Internet and computer activities"""
XActiveXUpdatesvcss.exe"Added by a variant of the DEDLER.C TROJAN!"
UAdobe Version Cue CS2VersionCueCS2Tray.exe"File manager that's part of Adobe Creative Suite 2 - ""find files fast
XAdRotator.Application[path to csrss.exe]"Added by the SMALL-AQ TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
YAiptek Graphics Tablet (USB)atwtusb.exeUSB interface for Aiptek Graphics Tablet (USB)
XALMcsrss32.exe"Added by the ANACON-D VIRUS!"
NAME_CSA"rundll32 amecsa.cpl RUN_DLL"
YANIWZCS2ServiceWZCSLDR2.exe"ALPHA Networks wireless driver"
?ANIWZCSServiceWZCSLDR.exeD-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity
XAntivirusPCSuitepgs.exe"AntivirusPCSuite rogue security software - not recommended
YAolAcsDaemon1Acsd.exe"AOL Connectivity Service - automatically restores the connection to AOL should you lose it while online. Negates having to go through the procedure of signing back on manually. This version is obsolete and has been replaced by AOLACSD.EXE so update your version of AOL. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
YAolAcsDaemon1AOLACSD.EXE"AOL Connectivity Service - automatically restores the connection to AOL should you lose it while online. Negates having to go through the procedure of signing back on manually. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
XAPcSafeAPcSafe.exe"APcSafe rogue security software - not recommended
XAPcSecureAPcSecure.exe"APcSecure rogue security software - not recommended
XApplicationcsrss.exe"Added by the BEAGLE.EG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NArcSoft ConnectACDaemon.exe"Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia
NArcSoft Connection ServiceACDaemon.exe"Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia
NARCSolo RecoveryN/ABackup software by Computer Associates - no longer supported
Xargq32csrss_32.exe"Added by the RBOT-CPM WORM!"
XasccacAasacsqgl.exe"Added by the MULTIDRP.AA TROJAN!"
Xasdsaxcxz13dasxcsx13.exe"Added by the LEGMIR-ARF TROJAN!"
XASP.NET State Servicecsrss.exe"Added by the DLOADER-QI TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XATI Active Graphics Card Monitoratievx.exe"Added by the IRCBOT-TL WORM!"
UAtiSoundcsrss.exe"WinSpy surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""ComRoot"" subfolder"
Xaupdsymcsvc.exe"Added by the ABWIZ.D TROJAN!"
Xaupdsysvcs.exe"Added by the ABWIZ.C TROJAN!"
Xaupdsywsvcs.exe"Added by the ORSE-M TROJAN!"
UAuslogics BoostSpeedboostspeed.exe"System Tray access to Auslogics BoostSpeed system optimization utility - which allows you to ""Start programs faster. Speed up computer start time. Increase Internet speed
UAuslogics BoostSpeed 4boostspeed.exe"System Tray access to Auslogics BoostSpeed 4 system optimization utility - which ""Start programs faster. Speed up computer start time. Increase Internet speed
XAuto updatcrcss.exe"Added by the SDBOT.AAG WORM!"
NAutoCADacstart17.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
NAutoCAD Startup Acceleratoracstart16.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
NAutoCAD Startup Acceleratoracstart17.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
XAVManagercsrss.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
UBackupExecSchedulerbesch.exe"Veritas ""Back Up My PC"" software"
NBacsTrayBacsTray.exeBroadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
XBagleAVcsrss.exe"Added by the NETSKY.AB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NbascstrayBascsTray.exeBroadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
UBCSSyncBCSSync.exe"Part of SharePoint Server 2010 which is part of the Microsoft Office 2010 suite. ""Business Connectivity Services (BCS) uses a cache to store a copy of the external data required by the BCS solutions deployed on the Office client. A process called BCSSync.EXE runs on the client and provides automatic cache refresh and data synchronization of the entity instances."" For more information - see here"
Xbobycsrs.scr"Added by the BANCBAN-PC TROJAN!"
XBuildLabscsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
Uc32cs2c32cs2.exe"Cyber Sentinel - internet filtering software"
NCACStartercacstart.exeCash A Check - check writing software
UCalendarscopecs.exe"Calendarscope calendar software"
?CardScan AutoSyncCSyncCfg.exe"Related to the CardScan business card reader range of products. May be related to synchronization with E-mail software and mobile devices (see here)?"
XCashToolbarMSCStat.exe"Added by the DOWNLOADER-MY TROJAN!"
Xcbvcsurretnd.exe"Added by the FRETHOG-C WORM!"
XccApprsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XccpAppscsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XccRegVfYsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
YccSetMgrccSetMgr.exe"Part of Norton AntiVirus 2004. What does it do?"
XccStartccStart.exe"Added by the AGOBOT-IR WORM!"
XccStartccInfo.exe"Added by the AGOBOT-GQ BACKDOOR!"
XccSvcHst.execcSvcHst.exe"Added by the SDBOT-DIW WORM!"
Xccsvit.execcsvit.exe"Added by the STARTPA-HP TROJAN!"
UChineseStarcstar.exeChinese language support software
UCitiUCSCitiUCS.exe"Citibank Virtual Account Numbers - ""With this free service for Citi cardmembers
UCleanSweep Smart Sweep- Internet SweepCsinsm32.exeAutomatic logging of installs from Norton CleanSweep - available via Start -> Programs
NCleanSweep Useage WatchCSUSEM32.EXEQuarterdeck/Norton CleanSweep component - tracks how often you use files and alerts you to files that have not been used for a specified period of time
NClickSight Launchercs.exe"Launcher for the ClickSight® marketing tool from ClickStream Technologies - which ""is a patented data-collection technology that helps independent software vendors understand the current and future usage of their product"""
XClickTheButtoncsrss.exe"ClickTheButton adware. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
?Client agent for ARCserveW95AGENT.EXE"Part of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required?"
NClient Security Solutioncssauth.exe"Part of Thinkvantage Client Security Solution for Lenovo ThinkPad notebooks and ThinkCentre desktops. Once configured via the associated setup screens this loads via winlogon.exe (and loads the password manager) and therefore disabling this entry has no effect"
XClient Server Run Time Proccesscsrsrv.exe"Added by a variant of the SDBOT WORM!"
XClient Server Runtime Processcsrsss.exe"Added by the SDBOT-LD WORM!"
XClient Server Runtime Processcsrs.exe"Added by the LINKBOT.M WORM!"
XCLSRSSLSACS.EXE"Added by the SILLYFDC-X WORM!"
Xcmdbcscmdbcs.exe"Added by the LINEAG-GKW TROJAN!"
Xcmsoundvcsystem.exe"Added by the TCXMEDI-D downloader TROJAN!"
XcmssSystemProcesscsmss.exe"Added by the AGENT-CO TROJAN!"
XcmssSystemProcessmcsmss.exe"Added by the PROXYSER-F TROJAN!"
XcmssSystemProcesscsms.exe"Added by the AGENT-Y TROJAN!"
XCOM+ EventSystem ServicesECSERVER.EXE"Added by a variant of the SDBOT WORM!"
XCom+ Syscsrs.exe"Added by the FORBOT-BT WORM!"
UCompuSpy KeyLoggercswin2008.exe"CompuSpy surveillance software. Uninstall this software unless you put it there yourself"
XConfiguration LoaderccSort.exe"Added by the AGOBOT.SR WORM!"
XConfiguration Loadercrcss.exe"Added by the AGOBOT.ADG WORM!"
XConsole de Gerenciamento Microsoftcsrss.exe"Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Level4"" subfolder"
XConsole de Gerenciamento Microsoftcsrss.exe"Added by the BANCBAN-ET TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Central de Segurança"" subfolder"
XControlServiceMgrcsmsv.exe"Added by the AGENT-XC TROJAN!"
Xcpntmgcsimcss.exe"Added by the MAGICON.A TROJAN!"
Ucpqnscpqnpcss.exeRelated to Compaq.Net - not required if you don't use that
Xcprocsvccproc.exeAdded by MSIL.AGENT.C TROJAN!
XCRCSScrcss.exe"Added by the IRCBOT-TH WORM!"
XCStsc.exe"Cyber Security rogue security software - not recommended
XCS Updatecopy /Y [path] ActivationManager.dll.upd [path] ActivationManager.dllAdded by an unidentified malware
NcsaRemspqmdmui.exeCompaq modem country selection
YCSAV_CheckVirusesvchk.exe"Command Antivirus related"
Ucsccsc.exeCommand line compiler for Microsoft C# it gets installed with the .NET SDK
Xcscriptscscripts.exe"Added by the BDOOR-AAP BACKDOOR!"
XCSCRS Valuecscrs.exe"Added by the RBOT-AAA WORM!"
XCSCRS Value CheckMsPMSPSd.exe"Added by a variant of the SDBOT WORM!"
XCseccs.exe"Cyber Security rogue security software - not recommended
Ncsecwizcsecwiz.exe"Setup wizard for the Client Security Software for IBM\Lenovo notebooks. This entry only runs once
Xcserv32cserv32.exe"Added by the STRATION.EC WORM!"
XCsimPlayerCsimPlayer.exe"Added by the KOOBFACE-AD WORM!"
UCSINJECT.EXECSINJECT.EXE"Part of Quarterdeck/Norton CleanSweep. ""Csinject must be loaded in order for Smart Sweep to automatically monitor installations and properly track registry changes"""
Xcsm Win Updatescsm.exe"Added by the ZOTOB.B WORM!"
XCSNetManagerXpisass.exe"Added by the HIDER-O TROJAN!"
Xcsoftoksoftok.exe"Added by the QQPASS.G TROJAN!"
Xcsoscsos.exe"Added by the SDBOT-DFE WORM!"
Xcsrcscsrcs.exe"Added by the AGENT-HUA TROJAN!"
Xcsrscsrs.exe"Added by the GAOBOT.GEN!POLY WORM!"
Xcsrsccsrsc.exe"Added by an unidentified VIRUS
XCSRSSCSRSS.EXE"Search page hijacker
XCsrsscsrss.exe"Added by the CHOD WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a random subfolder"
Xcsrsscsrss.exe"Added by the KEYLOG-AQ KEYLOGGER! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xcsrsscsrss.exe"Added by the CHODE-J WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a random subfolder"
Xcsrssmsmsgs.exe"Added by the CHODE-J BACKDOOR! Note - this malware uses MSN Messenger (which is located in %Program Files%\Messenger) in the background to propogate itself"
Xcsrssnwiz.exe"Added by the CHODE-J WORM!"
Ucsrsscsrss.exe"BeyondKeylog surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Supremtec"
XCsrssCSRSS.EXE"Added by the PUNYA-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Documents and Settings\Administrator\Local Settings\Application Data\WINDOWS"
Xcsrssssms.exeAdded by an unidentified malware
XCsrss Hostcsrhost.exe"Added by the IRCBOT.BIZ WORM!"
XCSRSS Loadercsrsss.exe"Added by the AGOBOT.TX WORM!"
Xcsrss.execsrss.exe"Added by the DALBUG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XcsrssLevel4csrss.exe"Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Level4"" subfolder"
XCSRSSUCSRSSU.exe"CoolWebSearch parasite variant - hijacking to Slawsearch.com. Also detected as the CWS-E TROJAN!"
XCSRSSWCSRSSW.EXE"Added by the CWS-F TROJAN!"
XCSRSWIN[trojan filename]"Added by the WINSHELL.50 TROJAN!"
XCSRSX[trojan filename]"Added by the WINSHELL.50.B TROJAN!"
Xcsrvsscsrvss.exe"Added by a variant of the SDBOT TROJAN!"
UCSS ServerCSSServer.exe"ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself"
Ncssauthcssauth.exe"Part of Thinkvantage Client Security Solution for Lenovo ThinkPad notebooks and ThinkCentre desktops. Once configured via the associated setup screens this loads via winlogon.exe (and loads the password manager) and therefore disabling this entry has no effect"
Ncssauthecssauthe.exe"Part of Thinkvantage Client Security Solution for IBM/Lenovo ThinkPad notebooks and ThinkCentre desktops. Once configured via the associated setup screens this loads via winlogon.exe (and loads the password manager) and therefore disabling this entry has no effect"
YCSScheduleCheckSCHWIZEX.EXE"Part of ConfigSafe - lets you identify changes to the registry
Xcssrscssrs.exe"Added by the BANCBAN-DW TROJAN!"
Xcssrss.execssrss.exe"Malware installed by different rogue security software including SpyKillerPro"
XcsssCsss.exe"Added by the BALICK TROJAN!"
UCSS_CentralCSS_1631.EXE"CSS Communication Agent (95 Host) from Command Software Systems (now Authentium). ""CSS Central™ provides administrators with a powerfully proactive tool to effectively manage and maintain the anti-virus strategy from a centralized console"""
XCSV10P1CSP001.exe"ClearSearch adware"
XCSV10P70CSv10P070.exe"ClearSearch adware"
XCSV7P26CSV7P26.exe"ClearSearch adware"
XCSV7P70CSV7P070.exe"ClearSearch adware"
XCSV7P91CSV7P91.exe"ClearSearch adware"
Ucsvdeacsvdea.exe"SpyArsenalLog surveillance software. Uninstall this software unless you put it there yourself"
Xcsvhost.execsvhost.exe"Added by the CIMUZ-BD TROJAN!"
Xctfmencssrs.exe"Added by the STARTP-DC TROJAN!"
XCurrent Security Configcsecure.exe"Added by the RBOT-AMO WORM!"
Xdarkcsrs.scr"Added by the BANCBAN-GT or BANCBAN-GU TROJANS!"
Xdcsmdcsm.exe"Part of the PrivacyProtector and DriveCleaner rogue security tools"
XDevice Securitydvcsecure.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDevice Security Managerdvcsecure.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDIECOXcsrss.exe"Added by a variant of the ATM.GEN TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XDisk Panel Configurationdpcsvc.exe"Added by the IRCBOT.BSQ BACKDOOR!"
XDisk Panel Setupnpcsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XDisplay Driverscssrs.exe"Added by the AGOBOT.FX WORM!"
Ndlbcservdlbcserv.exeRelated to Dell Photo Printers and provides additional configuration options for these devices
YDPCProxyLoadOnStartupdpcstart.exe"DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
YDpcstartdpcstart.exe"DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
XDriverModulecsrnvrt.exe"Added by the IRCBOT.I TROJAN!"
Xdsgblcsass.exe"Added by the AGENT.TGZ BACKDOOR!"
?EDFcsndiscfcsn.exe"Related to Hewlett-Packard's Discovery Agent. What does it do and is it required?"
?ENCSurfsurfboard.exe"??"
Uenginecs2enginecs2.exe"Cyber Sentinel - internet filtering software"
Xethernet adaptercsrmss.exe"Added by a variant of the RBOT WORM!"
XExplorer.execsrss.exe"Added by the JUEGO-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft"
XFHStartshdocsvc.exe"Added by the WINHOUND TROJAN!"
UFieldForms SyncSyncService.exe"Resco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run
XFiendlyTypecsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XFirewallActiviescsrss.exe"Added by the BANKER-AQ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""3041"" subfolder"
XFireWire Servicesnvcsv32.exe"Added by a variant of the SPYBOT WORM!"
NFoneSyncSystemTrayFoneSyncSystemTray.exeSystem Tray icon for Nokia FoneSync utility for the 7160/7190 mobiles. Useful to send data from/to the cell phone and the computer. You can use it to backup data or even to input data through the computer keyboard (which naturally is much more comfortable). Run manually when required
UFortis Secure Layer Configcseinst.exeFortis Bank Home Banking part. Installed during the installation of the software necessary to run the Home Banking. According to Fortis Bank this will not in any way be harmful to the system or relay system information
?GACServiceGACService.exe"Related to a Gemplus product. What does it do and is it required?"
NGCSGrabClipSave.exe"GrabClipSave screen capture tool"
XGraphics_default.pif"Added by the AUTOSKY WORM!"
XGraphics adapter servicewindll.exe"Added by the ATNAS.A WORM!"
XGuardPcs.exeGuardPcs.exe"GuardPcs rogue security software - not recommended
Nhcsystrayhc_tray.exe"Kuma Notifier for the Shootout! game from the History Channel. ""It lets you know whenever there's a new episode that's been released or an announcement from the Kuma team. Just click it to get up-to-the-minute game and event information"""
NHPUProvenTactics.exe"Proven Internet Marketing software"
NIBM Client Security Softwarecsecwiz.exe"Setup wizard for the Client Security Software for IBM\Lenovo notebooks. This entry only runs once
UICSDCLT"rundll32.exe Icsdclt.dll ICSClient"
NICServerIcserver.exeIntel Intercast viewer software. Gives access to selected internet pages which are broadcasted by several TV stations
YICSMGRICSMGR.EXEMonitors DNS and DHCP requests for ICS (Internet Connection Sharing). Needed if you're sharing the internet on various computers
XIECheckMSDTCs.exe"Added by the TIRBOT-D WORM!"
Ximcsslxmliwvug.exe"Added by the SLAPER.U TROJAN!"
Ximxecsvbrun70sp4.exe"Added by the AGOBOT.ALA WORM!"
XIntel Drivercsrs.exe"Added by a variant of the SDBOT WORM!"
XIntelli Mouse Pro Version 2.0Bncsjapi32.exe"Added by the BUZUS-O WORM!"
XIPv6 Helper Drivercsass.exe"Added by the AGOBOT.TC WORM!"
XJnskdfmf9eldfdcsrssc.exe"Added by the AGENT.EBC TROJAN!"
XJvcHostjvcsvc32.exe"Added by the AGOBOT-AIU WORM!"
XKernellAppscsrss.exe"Added by the BANCBAN-AC TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""System"" subfolder"
XKey Loggercsrss.exe"Added by the BUCHON.A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root folder (ie
XKL AntiFunLoveflcss.exe"Added by the FUNLOVE.4099 VIRUS!"
YKodakCCSKodakCCS.exeKodak DC File System Driver
XKrnlcheckcsrss.exe"Added by the BOTNACHALA TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XLogonCSRSS.EXE"Added by the BRONTOK-BH WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
XLogonAdministratorCSRSS.EXE"Added by the KORRON.B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
XLogonrepclient1CSRSS.EXE"Added by the BRONTOK-BT WORM and variants! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
XLogonsaracsrss.exe"Added by the BRONTOK-BS WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
XManageProtocolCtrlcsmsv.exe"Added by the LOOKSKY.B TROJAN!"
XMcafee VirusScan Managermvcsvm.exe"Added by the SILLYFDC.BBV TROJAN!"
XMcaffeemcsheild.exe"Added by the RBOT-FDP WORM!"
YMcShld9xmcshld9x.exe"Window 9x/Me on-access scanner for older McAfee's internet security products such as VirusScan and VirusScan Online which scans files in real-time for malware as you access
XMcsoftgfeqzvq.exe"Added by the SDBOT-NV WORM!"
XMedia Software UPdatersscs.exe"Added by the RBOT-ABE WORM!"
Umedicsp2sprtcmd.exe /P medicsp2"Self-help support tool for an unidentified high-speed internet provider (provided by SupportSoft
XMicrcsoft Certificate Servicescflmon.exe"Added by the RBOT-FWV WORM!"
XMicrosoftwcsntfy.exe"Added by the AGOBOT-AHT WORM!"
XMicrosoftrtvcscan.exe"Added by the RBOT-GGU WORM!"
XMicrosoft (R) Windows Vista/NT Runtime Compatibility Servicenrcs.exe"Added by the RANKY.X TROJAN!"
XMicrosoft Client/Server Runtime Server Subsystemcsrs.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Client/Server Runtime Server Subsystemcsrssa.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft CSRSS Servicensmscrs.exe"Added by the RBOT-BPT WORM!"
XMicrosoft CSRSS32 Protocolcsrss32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft CSRSS386 Protocolcsrss386.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Data Machinecsdata32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Device Managersvcswin.exe"Added by the IRCBOT-YH TROJAN!"
XMicrosoft DLL Verifiercsrssv.exe"Added by the RBOT-ATK WORM!"
XMicrosoft Keyboard Enhance 2.0.iasrecst.exe"Added by the BCKDR-QIL BACKDOOR!"
XMicrosoft Keyboard Enhance V2.0iasrecst.exe"Detected by F-Prot as the DOWNLOADER2.AILI TROJAN!"
UMicrosoft Office 2010BCSSync.exe"Part of SharePoint Server 2010 which is part of the Microsoft Office 2010 suite. ""Business Connectivity Services (BCS) uses a cache to store a copy of the external data required by the BCS solutions deployed on the Office client. A process called BCSSync.EXE runs on the client and provides automatic cache refresh and data synchronization of the entity instances."" For more information - see here"
XMicrosoft Registrycsrse.exe"Added by the RBOT-PC WORM!"
XMicrosoft Security Centerwcsntfy.exe"Added by the SDBOT.BYD WORM!"
XMicrosoft Security Systemmssecsys.exe"Added by the IRCBOT-WJ TROJAN!"
XMicrosoft servicecssrs.exe"Added by the STARTP-DC TROJAN!"
XMicrosoft Update Servicecsrss32.exe"Added by the AGOBOT-HC WORM!"
XMicrosoft Update Serviceswcsnfty.exe"Added by the RBOT-AGK WORM!"
XMicrosoft Windows CSRSScsrss.exe"Added by the KALEL-A WORM! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XMicrosoft Windows Securewindocs.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Securewindocs.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updatesvcshost.exe"Added by the FORBOT-CF WORM!"
XMicrosoft Windows Updateservcs.exe"Added by the SDBOT.AL BACKDOOR!"
XMicrosoft Windows Update Clientcsrss.exe"Added by the KEBEDE-G WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Systems32"
XMicrosoft Word Profissionalcsrss.exe"Added by the BANCBAN-DB TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""s1613"" subfolder"
XMicrosoft Word Profissionalcsrss.exe"Added by the BANKER-DJ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""protect"" subfolder"
XMicrosoft Word Profissionalcsrss.exe"Added by the BANKER-DP TROJAN! ! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""JavaVM"" subfolder"
XMicrosofts Servicelcsrv16.exe"Added by a variant of the RBOT WORM!"
XMicrosoftSourceSafecsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XMicsoft-Published-Softwareexplrer.exe"Added by the RBOT-GFL WORM!"
XMicsorosft Security Centerwcnsfty.exe"Added by the RBOT-AHU WORM!"
Xmnsvcspmnsvcsp.exe"Added by an unidentified VIRUS
XMONPluginSrIvcsn3monap23.exe"Added by a variant of the RBOT WORM!"
UMPEOCsinsm32.exeAutomatic logging of installs from Norton CleanSweep - available via Start -> Programs
XMS Windows Process ClassMSPRCSS32.exe"Added by the RBOT-YQ WORM!"
Xmsbcsmsbcs.exe"Added by the DADOBRA-G TROJAN!"
XMscsgsMSCSGS.EXE"Added by the ZEZER WORM!"
XMscsgs32MSCSGS32.EXE"Added by the ZEZER WORM!"
Xmscsvc.exemscsvc.exe"Added by the BANCOS.T TROJAN!"
Xmsiexecsmsiexecs.exe"Added by the SILLYFDC.BBB WORM!"
Xmsiexecs.exemsiexecs.exe"Added by a variant of the SDBOT WORM!"
XMSN angcssrss.exe"Added by the FORBOT-CE WORM!"
XMSN CST Managermancstmgr.exe"Added by an unidentified WORM or TROJAN! See here"
XMSNPluginSrIvcsn3vasap23.exe"Added by a variant of the RBOT WORM!"
XMSNPluginSrvcsp6.exe"Added by the SDBOT.AKJ or RBOT-VJ WORMS!"
XMSNPluginSrvcssagate.exe"Added by the SDBOT.AKJ WORM!"
XMSSVCsvcsys.exe"Added by the FATOOS-C TROJAN!"
XMSSYSTEMsvcsys.exe"Added by the FATOOS-C TROJAN!"
XMsupdatesvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XMsvcServicemsvcs.exe"Added by the RBOT-RK WORM!"
XMultimedia Codecsmcc.exe"Added by the DLOADER-MB TROJAN!"
Xmvsyswinaacsysiom.exe"Added by a variant of the SDBOT WORM!"
XMyPcSecureMyPcSecure.exe"MyPcSecure rogue security software - not recommended
Xmysvcig38recsl.exe"Added by a variant of the RBOT-FOU WORM!"
XNAV Auto Updatescsrssp.exe"Added by a variant of the SDBOT WORM!"
YNCSW ServerNcsW.exe"LockLink access control management software. LockLink 7.0 lets users seamlessly manage both offline and online access control solutions available from IR Security & Safety"
NNCS_SSCsinsm32.exeSame as CleanSweep Smart Sweep-Internet Sweep
XNDAvcsnss.exe"Added by the SERFLOG.C WORM!"
XNETServicescsxrs.exe"Added by a variant of the SDBOT WORM!"
XNetWorkcsrs.exe"Added by the AGOBOT.JJ WORM!"
XNetwork Securitysecsvc.exe"Added by the RBOT-ALX WORM!"
XNetwork Servicesnetsvacs.exe"Added by the GAOBOT.AIS WORM!"
XNew Csnm Managercsmn.exe"Added by the SDBOT.BZS WORM!"
NNokia PC SyncPCSync2.exe"System Tray access to Nokia PC Sync - which ""allows you to synchronise contacts
NNokia.PCSyncPCSync2.exe"System Tray access to Nokia PC Sync - which ""allows you to synchronise contacts
NNokiaPCSuiteTrayLaunchApplication.exe"System Tray access to Nokia PC Suite - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" This allows you (amongst other options) to backup your devices contents to your PC
NNokiaPCSyncTrayPCSync.exe"System Tray access to Nokia PC Sync - which ""allows you to synchronise contacts
XNorman Worl System Abilitynwcss32.exe"Added by the DELF.IO TROJAN!"
XNorton Protect Activiescsrss.exe"Added by the BANKER-CZ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""D5133"" subfolder"
XNorton StartccStart.exe"Added by the SDBOT-OX WORM!"
XNorton Systemcsrs.scr"Added by the BANLOA-AFM TROJAN!"
XNT Windows System Manager Loadercsrlss.exe"Added by the AGOBOT.OX WORM!"
XNTDLMcsrss.exe"Added by the HALE TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Qossrv"" subfolder"
YNuTCSetupEnvironncoeenv.exe"Used by the MKS Toolkit for Enterprise Developers product. NuTCracker is a Unix runtime environment for Windows
XNvGraphicsInterface[path to trojan]"Added by the BCKDR-QKI BACKDOOR!"
XNvidia Control Panelncsvc32.exe"Added by an unidentified VIRUS
Xnvsv32.execstr.exe"Added by a variant of the SDBOT WORM!"
XNxvstcssrs.exe"Added by the GAOBOT.CD WORM!"
XOfficeAgentsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XOfficeGuardUIsvcss.exe"Added by the DEDLER-C TROJAN!"
UPC Dynamics SdwMon32sdwmon32.exe"SafeHouse ""Personal Privacy"" protects and hides your private and personal photos
XPC Scoutpcscout.exe"PC Scout rogue security software - not recommended
NPC SpeedScan ProPCSpeedScan.exe"Ascentive PC SpeedScan Pro registry optimizer - not recommended
NPC SuitePCSuite.exe"System Tray access to Nokia PC Suite - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" This allows you (amongst other options) to backup your devices contents to your PC
NPC Suite TrayPCSuite.exe"System Tray access to Nokia PC Suite - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" This allows you (amongst other options) to backup your devices contents to your PC
NPC SyncPCSync2.exe"System Tray access to Nokia PC Sync - which ""allows you to synchronise contacts
XPCprotcrcss.exeAdded by an unidentified WORM!
UPCRecSAPCRecSA.exe"Part of the IBM/XPoint Rapid Restore backup utility. If you choose
XPcSecureNetPcSecureNet.exe"PcSecureNet rogue security software - not recommended
XPCSecureSystempgs.exe"PCSecureSystem rogue security software - not recommended. A member of the AVSystemCare family"
XpcServerserver.exe"Ssppyy spyware"
XPCShieldregsvr32 sfg_****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XPcsProtectorPcsProtector.exe"PcsProtector rogue security software - not recommended
XPcsSecurePcsSecure.exe"PcsSecure rogue security software - not recommended
NPCStartPcm25.exe"Runs as part of PCMonitor which is a program for monitoring your activity on your system. It makes screen dumps and key logging. It can hang-up your system because the screen dump page gets VERY big"
NPCSuitePCSuite.exe"System Tray access to Nokia PC Suite - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" This allows you (amongst other options) to backup your devices contents to your PC
NPCSuiteTrayApplicationTrayApplication.exe"System Tray access to Nokia PC Suite - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" This allows you (amongst other options) to backup your devices contents to your PC
NPCSuiteTrayApplicationLaunchApplication.exe"System Tray access to Nokia PC Suite - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" This allows you (amongst other options) to backup your devices contents to your PC
NPCSuiteTrayApplicationTRAYAP~1.EXE"System Tray access to Nokia PC Suite - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" This allows you (amongst other options) to backup your devices contents to your PC
NPCSuiteTrayApplicationLAUNCH~1.EXE"System Tray access to Nokia PC Suite - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" This allows you (amongst other options) to backup your devices contents to your PC
XPcsvpcsvc.exe"Delfin Media Viewer or ""Promulgate"" adware"
NPCSyncPCSync.exe"System Tray access to Nokia PC Sync - which ""allows you to synchronise contacts
XPcSyncPcSync.exe"Added by the RBOT-XJ WORM! Note - do not confuse with the Nokia application described here"
NPcSyncPcSync2.exe"System Tray access to Nokia PC Sync - which ""allows you to synchronise contacts
NPCSync.exePCSync.exe"System Tray access to Nokia PC Sync - which ""allows you to synchronise contacts
NPCSync2PCSync2.exe"System Tray access to Nokia PC Sync - which ""allows you to synchronise contacts
XPerfomance Monitordavcsync.exe"Added by the LAMUD-A WORM!"
Xpicsvrpicsvr.exe"Delfin Promulgate adware"
?PMCSPMC.Service.Main.exe"Related to MediaCenterService from Pinnacle Systems. What does it do and is it required?"
UPowerDOCSAPIHostpapihost.exe"Hummingbird PowerDOCS - ""delivers powerful enterprise document management functionality via a tightly integrated Microsoft WinNT/98/2K environment"""
XProgcsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XProtectPcs.exeProtectPcs.exe"ProtectPcs rogue security software - not recommended
XProtocolEventTskcsrwjd.exe"Added by the STINX-N TROJAN!"
NQD FastAndSafeQDCSFS.exeAutomatically runs Fast & Safe clean-up from Norton/Quarterdeck Cleansweep. Deletes safe to remove files such as Temporary Internet Files (cache). Recommended you run it manually
XRapdataravsecs.exe"Added by the QQPASS-V TROJAN!"
URapid Restorerrpcsb.exe"XPoint ""Rapid Restore PC"" - ""a Managed Recovery solution that enables IT Administrators to protect the corporate image
URCScheduleCheckRCSCHED.EXE"Scheduler for VCOM's Recovery Commander - which ""can restore your non-booting system back to normal. It only takes a few minutes to get your system back up and running"""
XRcshweaa.exe"PurityScan adware"
XRCSyncRCSync.exe"PrizeSurfer related. ""PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!"" Stealth installed malware"
URCSystemDLLML.exe RCSystem"Related to Creative DLL Module Loader for the Sound Blaster X-Fi (and maybe others). This program is non-essential process to the running of the system
XRCSystemTrayMaxRCSystemTray.exe"Max Registry Cleaner rogue registry cleaner - not recommended
XReal Statics Agentccreal.exe"Added by a variant of the RBOT WORM!"
NRecSheRecSche.exeRecording scheduler for WatchTV Capture Card (TV Tuner card)
URegClean Expert SchedulerRCScheduler.exe"""Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry
XRegDone Excsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
?Register SeqChkregsvr32.exe ..csseqchk.dll"??"
XRegistrywscript.exe ShakiraPics.jpg.vbs"Added by the VBSWG.AQ WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ShakiraPics.jpg.vbs"" file is located in %Windir%"
XRegWritecsrss.exe"Added by the SOKACAPS TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Media"
XRemndrCsRemnd.exeCasinoOnline foistware
XRPCser32gservices.exe"Added by the RITDOOR-C WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCser32g1services.exe"Added by the PREX.D WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCser32g3services.exe"Added by the PREXOT.D BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCser32g4services.exe"Added by the PREXOT.E BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCserr32gwinlogon.exe"Added by the RITDOOR-B WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCserv32services.exe"Added by the MYDOOM.AL WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCserv32gservices.exe"Added by the BOBAX.AA WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCserv32gCSRSS.EXE"Added by the BOBAX.AD WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCserv32gMSDEFR.EXE"Added by the BOBAX.AD WORM!"
XRPCserv32gNB32EXT2.EXE"Added by the BOBAX.AD WORM!"
XRPCserv32gWINLOGON.EXE"Added by the BOBAX.AD WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
YRPCSS.exerpcss.exe"Remote Procedure Call. Required by windows for programs to communicate with each other on networks/different machines. Originally for NT only but now installed with Win98/98se. Under Win98/98se
Xrundll32csrss.exe"Added by the GUTTA TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRunnercsrss.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRuntime ProcessCsrss.exe"Added by the CIADOOR-J BACKDOOR! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRuntime Server Subsystemcsrss.exe"Added by the IRCBOT-XV WORM!"
XSalestartdcsm.exe"Part of the PrivacyProtector and DriveCleaner rogue security tools"
YSBCSTraySBCSTray.exe"System Tray access to CounterSpy antispyware software"
XSchedulersvcshost.exe"Added by the TACTSLAY.A TROJAN!"
YScsiScsi.exeSCSI Miniport driver
Xscssrr.exeServices.exe"Added by the VB-EMX TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSDAvcsnss.exe"Added by the SERFLOG.C WORM!"
XSDR6V_Checkudcsdr.exe"Part of the DriveCleaner rogue security software - not recommended
XSDR6_Checkudcsdr.exe"Part of the DriveCleaner rogue security software - not recommended
Xsecserv.exesecserv.exe"Detected by Panda as an EasySearch adware variant. Note - EasySearch modifies the Internet Explorer settings and may download programs onto the infected computer"
Xsecsvc32secsvcnt.exe"Added by the GLOBAL PATROL TROJAN!"
USecsysSecsys.exe"UltraSoft Key Interceptor surveillance software - uninstall this unless you put it there yourself!"
USecurePCSolutionsBootCheckBootCheck.exe"1 Click Fixer PLUS from Secure PC Solutions ""takes the guesswork out of locating and solving problems in the Windows registry"""
XSecurity Mechaniclsascs.exe"Security Mechanic rogue security software - not recommended
XSecurity Server DBsecserver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSecurity Servicesecsvc.exe"Added by the RBOT-GGF WORM!"
XSecurity Service DBsecservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSelect serverslcsvr.exe"Added by the DLOADER-WD TROJAN!"
NSEPCSuiteSEPCSuite.exe"System Tray access to Sony Ericsson PC Suite which ""connects your phone to your computer and expands the capabilities of your phone"". Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone"
XSernellApp.pcxcsrss.exe"Added by the BANCBAN-BJ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""D5133"" subfolder"
XService ControllerCsrrs.exe"Added by the GAOBOT.AO WORM!"
XService Monitorcsnss.exe"Added by the RBOT.EEH WORM!"
XServicescsrss.exe"Added by a variant of the RANKY.U TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XServicescsrss32.exe"Added by the ANACON-D VIRUS!"
XServices Managementsservcs.exe"Added by the RBOT-GUC WORM!"
XServicesActivecssrs.exe"Added by the AGOBOT-GB BACKDOOR!"
Xservicsservics.exe"Added by the SINGU-J TROJAN!"
XShockwavecsrss.exe"Added by the SNDOG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSiS Mpc Servicempcsvc.exe"Added by the CIADOOR-CJ TROJAN!"
USmart Connect SetupSCSetup.exeAppears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio
Xsmcservwinsrv.exe"Added by the AGOBOT-OU WORM!"
YSmcServicesmc.exeSygate Firewall
YSmcServicessmc.exeSygate Firewall
YSmcServicesspfsmc.exeSygate Firewall
Xsmcsssmcss.exe"Added by the SCLOG-AJ TROJAN!"
?Smcsta.exeSmcsta.exe"SMC Networks wireless PCI card driver. Is it required?"
XSmcSVRSmcSVR.exe"Added by the LEGMIR.JU TROJAN!"
Xsmilewcs.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
USmpcSysSmpSys.exe"""Set Up My PC"" utility supplied with some Packard Bell computers"
Xsmss.execsrss.exe"Added by the DALBUG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSocial Security Agencyrpcxsocsa.exe"Added by a variant of the RBOT WORM!"
Xsomewcs.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
NSony Ericsson PC SuiteApplication Launcher.exe"System Tray access to Sony Ericsson PC Suite which ""connects your phone to your computer and expands the capabilities of your phone"". Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone"
NSony Ericsson PC SuiteSEPCSuite.exe"System Tray access to Sony Ericsson PC Suite which ""connects your phone to your computer and expands the capabilities of your phone"". Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone"
USpeedtouch USB DiagnosticsDragdiag.exeFor an external Alcatel ADSL high-speed modem. A diagnostic tool and can be run from the Start menu when required. The only reason it might be useful on startup is if you like seeing an 'at-a-glance' status indicator on the taskbar (the icon is a different colour depending on the status of the device/line)
Xspoolsvr32csmss.exe"Added by the AGENT-AU TROJAN!"
Xspoolsvr32csmss32.exe"Added by a variant of the AGENT-AU TROJAN!"
XSpy Protectorsrcss.exe"SpyProtector rogue security suite - not recommended
XSpy Protectorlsascs.exe"Spy Protector rogue security software - not recommended
XSpyBlocsSpyBlocs.exe"SpyBlocs spyware remover - not recommended
XSpyBlocs3.0SpyBlocs3.0.exe"SpyBlocs spyware remover - not recommended
NStacSysTrayStacSysTray.exeSystem Tray control panel for SigmaTel C-Major on-board audio - as used on some Dell and Packard Bell PCs
XStart CurePCSolutionCurePCSolution.exe"CurePCSolution spyware remover - not recommended
XState Servicecsrss.exe"Added by the DADOBRA-CP TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XStatisticsstatslist.exe"Added by the OPANKI-S WORM!"
XSun Java Updaterstacsv.exe"Added by the BUZUS.DBFM TROJAN!"
Xsvchostsvcst.exe"Added by the AGENT-LIL WORM!"
XsvcsharewinampXP.exe"Added by the FUJACKS-J VIRUS!"
Xsvcsharespoclsv.exe"Added by the FUJACKS-A VIRUS!"
XsvcshareCTMONTv.exe"Added by the FUJACKS-AJ WORM!"
Xsvcsharenvscv32.exe"Added by the FUJACKS-Z WORM!"
XSvcSys[path to file]"Added by the BANCOS.Z TROJAN!"
XSvcsys Registry Managersvcsysreg.exe"Detected by Kaspersky as the AGENT.CV TROJAN!"
Xsvcsys32svcsys32.exe"Added by the AGOBOT-LL WORM!"
XSygate Personals Firewallsccsrn.exe"Added by a variant of the RBOT WORM!"
YSymantec Core LCsymlcsvc.exe"Part of Norton AntiVirus 2004. What does it do?"
XSymlcs[path to file]"Added by the YASPY-A TROJAN!"
USynaptics Pointing Device DriverSynTPEnh.exe"Synaptics TouchPad Enhancements - included with drivers for Synaptics based TouchPads
XSysSearchRegedit.exe -s pcsearch.reg"Added by the STARTPAGE-FN TROJAN! Note that regedit.exe is a legitimate Microsoft file and shouldn't be deleted. The ""pcsearch.reg"" file is located in %Windir%"
XSystemcsrss.exe"Added by the LDPINCH.E TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem CSRSS Patchscrtkfg.exe"Added by the RBOT-ADA WORM!"
XSystem Diagnosticssysdiag32.exe"Added by the SDBOT.GEN TROJAN!"
XSystem Event Managersecsvc.exe"Added by the RBOT.BMY WORM!"
XSystem Log Eventcsrss32.exe"Added by the AGOBOT-JI WORM!"
XSystem Messaging QueueSMCSS.EXE"Added by a variant of the RBOT WORM!"
XSystem Processcsrss.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem ProcessCSRSR.exe"Added by the AGOBOT-SQ WORM!"
XSystem Protectorlsascs.exe"System Protector rogue security software - not recommended
XSystem Servicessvcsenes.exe"Added by a variant of the RBOT WORM!"
XSystem Servicessvcsenes32a.exe"Added by the RBOT-AFG WORM!"
XSystem Startup Managersmcss.exe"Added by the RBOT.AMD WORM!"
XSystem time updatorCSysTime.exe"Added by the RANDEX.S WORM!"
XSystem Update Servicecsrss32.exe"Added by the AGOBOT-HI WORM!"
XSystem132Csrtss.exe"Added by the LANFILT-I TROJAN!"
XSystem32csrss.exe"Added by the SILLYFDC WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XSystem32-Drivercsrs32.exe"Added by the SDBOT-CP BACKDOOR!"
XSystemDrivercsrss.exe"Added by the ASCETIC.B TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\addins\explorer"
XSYSTEMSars32csrss.exe"Added by the AHLEM.A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
USysW8csta.exe"Clean Space internet evidence eliminator"
XTaskMrgcsrss.exe"Added by the LDPINCH-W TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UTHCSsvchost.exe"AllMonitor surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup. This one is located in a ""drivers\imon"" subfolder"
XTINTIMGcssrs.exe"Added by the PASTA.KRI TROJAN!"
UTotRecSchedTotRecSched.exe"Scheduler for Total Recorder - allows automatic recording of a show at a given time for later playback or you can use the scheduler as an alarm"
UU.S.Robotics WLAN Adapter Configuration UtilityUSRWLAN.exe"U.S.Robotics LAN Adapter - wireless LAN (WLAN) configuration utility"
XUateoocs.exe"PurityScan adware"
Nucstartupucstartup.exe"IBM Update Connector - old auto updater feature for IBM machines that connects to IBM to see if there are any new drivers
Nucstartup.exeucstartup.exe"IBM Update Connector - old auto updater feature for IBM machines that connects to IBM to see if there are any new drivers
NUC_SMBucstart.exePart of IBM Update connector on IBM PCs for updating drivers on a new installation. Once you manually run the IBM Update connector program (shortcut) this entry is removed
NUC_Startucstartup.exe"IBM Update Connector - old auto updater feature for IBM machines that connects to IBM to see if there are any new drivers
XUltimateServicesultsvcs.exe"Added by the AGENT-LGT TROJAN!"
XUpdatecsrss.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XUpdatecsrss.exe"Added by the MEHEERWAR TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""winupdate"" subfolder"
XUpDaTercsrss.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
XUpdater Service Processcsrss32.exe"Added by the AGOBOT-GP BACKDOOR!"
XUPNPServiceWinSVCservice.exe"Added by the AGOBOT.UN WORM!"
XUsrManagementConfumcss.exe"Added by the IRCBOT-W TROJAN!"
NUSRobotics 802.11g Wireless Network UtilityUSRWLANG.exe"USRobotics Wireless Network Utility - used to configure security settings for connecting to WEP encrypted Access Point through the USR Wireless adapter. You must uncheck ""Use Windows to configure my wireless settings"" for the program to work properly. Has Site Survey capabilities
NUsrobotics Online Registration??Pop-up reminding customers to register their products online at US Robotics
Xvcmicrecmsccsed.exe"Added by the MAILBOT-CE TROJAN!"
XVCS Hostvcshost.exe"Added by the RBOT-FKT WORM!"
NVCSPlayervcsplay.exe"Virtual CD drive emulator. Available via Start -> Programs"
XVerificador do sistemacssrs.exe"Added by the MOCON WORM!"
XVideo Processnetsvcs.exe"Added by the AGOBOT.LH WORM!"
XVolume Shadow Managervbcsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
Xwcsyswcsys.exe"Added by the KEYLOG-AP TROJAN!"
XWildFlicsWildFlics.exe"Direct-B premium rate adult content dialler"
UWinacsrWinacsr.exe"AceScreenSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
XWinCSRSSMSGRT32.EXE"Added by the REWINDO-A TROJAN!"
XWinDLL (csmss.exe)"rundll32.exe CSMSS.EXEstart"
XWindows (ICS) Spoolercrtss.exe"Added by a variant of the RBOT WORM!"
XWindows 2004csrss.exe"Added by the BANKER-DY TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Windows 2004\Tools"
XWindows Actioncsrs.exe"Added by the SECCMU-A WORM!"
XWindows Audio Componentsnncsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Client Service 32csrss.exe"Added by the RBOT-ALB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a drivers\winsdriver subfolder"
XWindows Client/Server Runtime Servercsrs.exe"Added by the RBOT.KD WORM!"
XWindows Custom ServicesCSRCS.EXE"Added by the SPYBOT-EI WORM!"
XWindows Event Detectionwecsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Explorer SP2csrss.exe"Added by the BANKER-DM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""JavaBeans"" subfolder"
XWindows Graphics Loaderswingraphics.exe"Added by the SPYBOT.JG WORM!"
XWindows Image Acquisition (WIASC)WIAcs.exe"Added by the RIZO.A TROJAN!"
XWindows Image Acquisition (WIASSC)WIAcss.exe"Added by the RIZO.A TROJAN!"
XWindows IP Security Serviceipsecs.exe"Added by the RBOT.BPW WORM!"
XWindows Messenger Panelwbcsvc.exe"Added by the IRCBOT.ADA BACKDOOR!"
XWindows NT Service Namesvchcst.exe"Added by the RBOT-NV WORM!"
XWindows Remote Launcherwnpmcs.exe"Added by the IRCBOT.ASX BACKDOOR!"
XWindows Svshost Service Update 32svcsshost32.exe"Added by the FORBOT-GD WORM!"
XWindows Taskmanager Datacsrrss.exe"Added by the RBOT-BBH WORM!"
XWindows UDP Control Centerwksvcsc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Serviceswksvcsc.exe"Added by the ANTIAV-C TROJAN!"
XWindows Updatecsrss.exe"Added by the BANKER-HM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Update Servicecsrs.exe"Added by the AGOBOT-NI WORM!"
XWindows Update serviceswins32svcs.exe"Added by a variant of the RBOT WORM!"
XWindows Update System Shellsvhostcs32.exe"Added by the RBOT-AAZ WORM!"
XWindows Video Componentwvcsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Zero Spoolernmvcs.exe"Added by the SLENFBOT.JQ WORM!"
XWindowsDiskEvtsvcsvh32.exe"Added by the NANINF.D TROJAN!"
XWindowsDiskLogcstsm.exe"Added by the STINX-C or STINX-D TROJANS!"
XWindowsExplorercsrss.exe"Messenger Blocker rogue security software - not recommended. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System"
XWindowsupdate Servicecsrss.exe"Added by the BABA-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root folder (ie
Xwinexecswinexecs.exe"Added by the SILLYFDC.BBB WORM!"
XWinFXcssrs.exe"Added by the AGOBOT.FX WORM!"
XWinFXcssrs.exe"Added by the GAOBOT.CD WORM!"
XWinlogonscssrr.exe"Added by the AGENT-LXB TROJAN!"
Xwinphonics7536vbsystem35.exe setups.exe vb.vb"Added by a variant of the MUTIN-C TROJAN!"
Xwinprotectionccsrss.exe"Added by the SILLYFDC.BBT WORM!"
XWINTASKMGRccsrs.exe"Added by the MYTOB.Q WORM!"
XWinUpdateAdministratorCSRSS.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Application Data\WINDOWS"
UWinUpdateProtectioncsrss.exe"EmployeeWatch is a commercial surveillance software program designed to monitor user activity on a computer. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a subfolder of C:\windowsupdate\ufp"
XWinXPcsrss.exe"Added by the BANCOS-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\WinXP\Tools"
XWinXP-98CSRSS.exe"Added by the BANKER-DS TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\WinXP-98\Tools"
XWMDM PMSP Servicecssrss.exe"Added by the KNOCKIT-A TROJAN!"
XWMI Standard Event Consumer - Scriptingscrcs.exe"Added by a variant of the RBOT-GRD WORM!"
XWSAConfigurationcsrsvcs.exe"Added by the AGOBOT.VI WORM!"
XWSAConfiguration1csass.exe"Added by the AGOBOT.WH WORM!"
Xwscsvc.exewscsvc.exe"Added by a password stealing BANKER TROJAN!"
Xwscsvc32.exewscsvc32.exe"Antivirus rogue security software - not recommended
UWSVCSSERVICES.EXE"WSLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
Xwupdsymcsvc.exe"Added by the ABWIZ.C TROJAN!"
Xxcxdsaa7slcskxsdl7.exe"Added by the ONLINEG-K TROJAN!"
?XTCsgloaderXTCsgloader.exe"Another Xupiter toolbar variant??"
Xxwarecskware.exe"Malware downloader from xxsware.com
XYahoo MessenggerSSVICSSHOST.exe"Added by the IMAUT.AA WORM!"
Xzcseacrt[random filename]"Added by a variant of the SLAPER TROJAN!"
UZoneUpdatecsrss.exe"WinSpy surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""ComRoot"" subfolder"
NZ_acamucli wizardcsecwiz.exe"Setup wizard for the Client Security Software for IBM\Lenovo notebooks. This entry only runs once
X[unknown name]WINBASICS32.EXE"Added by the SDBOT-JH WORM!"
X_SystemDrivercsrss.exe"Added by the ASCETIC.B TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\addins\explorer"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.