Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X(Default)llsass.exe"Added by the PROXY-GG TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)msarti.com"Added by the SILLYFDC.CJ WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\..\Policies\Explorer\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X*WindowsAudiosystemupd.exe"Added by the AGENT-TH WORM!"
X-=+(L4r1$$4)+=-(4nt1)-=+(V1ru$)=-+ISASS.exe"Added by the ASSIRAL.B WORM!"
X.mscdrlassa.exe"Added by the WEBUS.C TROJAN!"
X.TEXTCONVlsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
X.WMAudiolsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
?00DSKSVR00desksaver.exe saskda"Part of Advanced Desktop Shield
U00DSKSVR01desksaver.exe tray"System Tray access to Advanced Desktop Shield
?00saskdanewlock.exe saskda"Part of Access Manager
X1lsass.scr"Added by the BANCOS.V TROJAN!"
U12Ghosts SaveLayout12autosl.exe"12Ghosts SaveLayout - ""Always (always!) keep the layout of your desktop icons"""
X180sa180sa.exe"180Search adware"
X2thousandbuck[path to file]"Added by the RANKY.L TROJAN!"
X678lsas32.exe"Added by the SLSORVE-B TROJAN!"
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
NAAATraySaverTraySaver.exe"System Tray management utility from Mike Lin which allows you to hide
XAASSKK2LSASS.EXE"Added by the SILLYFDC.BDB WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%"
NAccess IBM Message Centeribmmessages.exe"""The Access IBM Message Center displays messages to inform you about helpful software that may be pre-installed on your PC. The Message Center can also provide messages about new updates available from the IBM Support Center to keep your computer current"""
XAdobeReaderProlssas.exe"Added by the RBOT-CLB WORM!"
XAdope File Managerlsasv.exeAdded by an unidentified WORM or TROJAN!
XAdsAlertAdsAlert.exe"AdsAlert rogue security software - not recommended"
UAgere SoftModem Messaging AppletAGRSMMSG.exeInstalled with the drivers for internal software modems based upon Lucent/Agere Systems chipsets - required if you use the SoftModem Assistant to configure the modem
NAGSatelliteAGSatellite.exeProgram from AudioGalaxy that lets you download some MP3s from their server. Available via Start -> Programs
XAIM Instant Message Cookies[random filename]"Added by the RBOT-AFV WORM!"
Xakgkagaksad9fsakfask9.exe"Added by the ONLINEG-M TROJAN!"
XAll Sea screen saverTaskTray.exe"Free screensaver
UAlwaysReady Power Message APPARPWRMSG.EXE"""Away Mode"" feature added with Update Rollup 2 for Windows XP Media Center Edition 2005 that allows the computer to appear off to the user while it continues to perform tasks that do not require user input
NAME_CSA"rundll32 amecsa.cpl RUN_DLL"
XAnswer ProblemdSAFsqs.exe"Added by the SDBOT-SC WORM!"
XAntiIsass.exe"Added by the BROPIA.K WORM!"
XAntivirusMSA.exe"MS Antivirus rogue security software - not recommended
XAntivirussav.exe"System Antivirus 2008 rogue security software - not recommended
XAOL Instant Messangeraim.exe"Added by the SDBOT-YT WORM! Note - this is not the popular AOL Instant Messenger utility"
XAOL Instant Messenger dll runtimeMSAOL32dll.exe"Added by the RBOT-ATA WORM!"
?AOLSAVAOLAgent.exe"AOL ISP related. What does it do and is it required?"
XAPcSafeAPcSafe.exe"APcSafe rogue security software - not recommended
UArctosarazerhid.exe"Razer Arctosa gaming keyboard driver - required if you use the additional features and programmed keys/macros"
Xasamasam.exe"Added by the FAKEAV-BGU TROJAN!"
XasccacAasacsqgl.exe"Added by the MULTIDRP.AA TROJAN!"
Xasdsaxcxz13dasxcsx13.exe"Added by the LEGMIR-ARF TROJAN!"
Xasnconsolemsasn.exe"Added by the RBOT.EVU TROJAN!"
XASocksrvSocksA.exe"Added by the VB.CBW WORM!"
XASP.NET State Servicecrsass.exe"Added by the BANLOAD-M TROJAN!"
?ASUS Camera ScreenSaverASScrProlog.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
?ASUS Screen Saver ProtectorASScrPro.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
?AsusACPIServerAsAcpiSvr.exe"Part of the ACPI driver for the Asus Eee PC range. What does it do and is it required?"
UATTBroadbandUpdateSAUpdate.exe"Big Brother from Quest Software. System and network monitor"
YAureal A3D Interactive Audiosa3dsrv.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
UAuto EPSON Stylus Photo R2400 on XE_FATI9SA.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
XautoMewscript.exe samok.vbs"Added by the SAMOK-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""samok.vbs"" file is located in %Windir%"
Xavexpressav.exe"Express Antivirus 2009 rogue security software - not recommended
YBDNewsAgentbdnagent.exe"BitDefender antivirus - updater"
XBeawversaqevre.exe"Added by a variant of the RANKY TROJAN!"
YBGNewsAgentbgnewsag.exe"BullGuard antivirus updater"
XBLMessagingIntegrationblengine.exe"BuddyLinks adware"
Xboby.Isass.scr"Added by the BANCBAN-OH TROJAN!"
UBUFFALO Power Save Utility for HDHDManage.exe"Power Save utility for Buffalo backup hard discs"
XBuildLabslsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XC:WINDOWSasam.exeasam.exe"Added by the PEACOMM.E TROJAN!"
YCAISafeisafe.exe"Part of Computer Associates eTrust EZ Antivirus"
UCasAgntCasAgnt.exeProgram by Extended Systems which allows you to sync your Casio PDA with your PC
XCassandra[10 to 14 random char]THD.EXE"Added by the KREPPER-AI TROJAN!"
XCassandracassandra.exe"SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as a variant of the KREPPER TROJAN!"
XccpAppslsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
UCertificateRegistrationSafeSignCertReg.exeSafeSign Certificate Registration Utility for Microsoft Crypto applications
NCesarFTP FTP Serverserver.exe"CesarFTPd - FTP server"
XChansonsMP3"rundll32.exe MSA64CHK.dllDllMostrar"
NClient Security Solutioncssauth.exe"Part of Thinkvantage Client Security Solution for Lenovo ThinkPad notebooks and ThinkCentre desktops. Once configured via the associated setup screens this loads via winlogon.exe (and loads the password manager) and therefore disabling this entry has no effect"
XCLSRSSLSACS.EXE"Added by the SILLYFDC-X WORM!"
XCMSallycallmesally.exe"Added by the CASAL.A TROJAN!"
Xcmssappiexplore_.exe"Added by the BANCBAN-CQ TROJAN!"
Xcmssappiexplore.exe"Added by the BANCBAN-GF TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XCOM+ System Applicationlsas.exe"Added by the AGOBOT-MO WORM!"
XCOM+ System Applicationslsas.exe"Added by the AGOBOT.SE WORM!"
NCompaq Message ServerCOMPAQ-RBA.EXE"Applies to the CPQBootPerfDB entry as well. These files generate some kind of server or servlet that attempts to connect with Compaq online. They are like Trojans
XComputing Technologie Firewalllsauth.exe"Added by the SDBOT-WX WORM!"
UConfigSafeCFGSAFE.EXE"ConfigSafe - lets you identify changes to the registry
UConfigSafeAUTOCHK.EXE"ConfigSafe - lets you identify changes to the registry
XConfiguration Loadedlssas.exe"Added by a variant of the SDBOT WORM!"
XConfiguration Loadersmsai.exe"Added by the SDBOT-YE WORM!"
UConnect KasambaKasamba.exe"""Finding the expert help that you need is easy on Kasamba. With more than 30
XContentDownload"rundll32.exe MSA64CHK.dllDllMostrar"
XCoolDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XCoolMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XCpusaveCpusave.exe"Added by the GEMA TROJAN!"
XCpusave32Cpusave32.exe"Added by the GEMA TROJAN!"
XCritical Error Safe32GetWaylayer32.exeAdded by the RBOT.IAL WORM!
XCrnsavascrnsave.pif"Added by the SDBOT-ZV WORM!"
XCRSSlssas.exeAdded by an unidentified WORM or TROJAN!
NcsaRemspqmdmui.exeCompaq modem country selection
YCSAV_CheckVirusesvchk.exe"Command Antivirus related"
XCSNetManagerXpisass.exe"Added by the HIDER-O TROJAN!"
Ncssauthcssauth.exe"Part of Thinkvantage Client Security Solution for Lenovo ThinkPad notebooks and ThinkCentre desktops. Once configured via the associated setup screens this loads via winlogon.exe (and loads the password manager) and therefore disabling this entry has no effect"
Ncssauthecssauthe.exe"Part of Thinkvantage Client Security Solution for IBM/Lenovo ThinkPad notebooks and ThinkCentre desktops. Once configured via the associated setup screens this loads via winlogon.exe (and loads the password manager) and therefore disabling this entry has no effect"
XcvhnykzxkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
XDarKNesS LsasSLsasS23.exeAdded by an unidentified WORM or TROJAN!
XDASDS VSAVdjsdsabdw.exe"Added by the SDBOT-RE WORM!"
Xdaskaskfsak6dsfids6.exe"Added by the ONLINEG-J TROJAN!"
Xdaskgfkkcx15dasdsaads15.exe"Added by the ONLINEG-Q TROJAN!"
XDefensaAntiMalwarepgs.exe"DefensaAntiMalware
UDell DataSafe SchedulerDataSafeOnlineScheduler.exe"Scheduler for Dell DataSafe™ Online which ""helps protect your music
UDellSupportDSAgnt.exeDell Support Agent offers additional support and update features for your Dell computer or laptop
Xdelsaapdelsaap.exe"NCase adware"
XDenecaVirus salvado"Added by the DELUZ VIRUS!"
XDepassxXfsa.exe"Added by the SDBOT-SK WORM!"
XderyheruxckeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
XDescargaBromas"rundll32.exe MSA64CHK.dllDllMostrar"
Udesksaverdesksaver.exe"Part of Advanced Desktop Shield
UDeskSaverDeskSaver.exe"DeskSaver from Headway Creative - utility that allows you ""to backup and to restore the icons position easily on the Windows desktop"". The Pro version also includes a ""Taskbar Economizer"" which minimizes an open window to the System Tray instead of the taskbar. Located in %ProgramFiles%\Headway Creative\DeskSaver"
UDeskSaver ProDeskSaver.exe"DeskSaver Pro from Headway Creative - utility that allows you ""to backup and to restore the icons position easily on the Windows desktop"". Includes a ""Taskbar Economizer"" which minimizes an open window to the System Tray instead of the taskbar. Located in %ProgramFiles%\Headway Creative\DeskSaver"
Udesksaver.exedesksaver.exe"Part of Advanced Desktop Shield
XDesktopUpdate"rundll32.exe MSA64CHK.dllDllMostrar"
XDialer"rundll32.exe MSA32CHK.dllReg"
?Disable EHCInousb20.exe"??"
XDisableKeybaord"Rundll32.exe KeyboardDisable"
XDisableMouse"Rundll32.exe MouseDisable"
Xdisnisadisnisa.exe"Added by the DORF-AE WORM!"
XDllLoaderlssas.exe"Added by the BDOOR-JE BACKDOOR!"
XDontworrymysaym.exe"Added by the SDBOT-RC WORM!"
XDownloadLegalMusic"rundll32.exe MSA64CHK.dllDllMostrar"
XDownloadMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XDownloadsAndMP3"rundll32.exe MSA64CHK.dllDllMostrar"
YDPASUpdateDPASAutoUpdate.exe"Automatic updates for DefenderPro AntiSpy spyware remover - now incorporated Defender Pro 15-in-1 and 5-in-1"
Xdsadsa.exeHomepage hijacker - redirecting to downseek.com
XDSAcass[path to file]"Added by the RANKY.M TROJAN!"
Xdsadlsa14dsakfsak14.exe"Added by the ONLINEG-P TROJAN!"
XdsfghjgjkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
Xdsgblcsass.exe"Added by the AGENT.TGZ BACKDOOR!"
XDSSdssagent.exe"Registration reminder for Mattel Interactive (Broderbund) applications and games. Spyware as it sends encrypted emails about the system back to the originators of the program. Also a resource hog. See here for more info"
?DSSSGENSdssagens.exe"??"
?DZKillMeDZSAVEME.EXE"??"
UEasyLinkAdvisorLinksysAgent.exe"Linksys EasyLink Advisor - ""the free application that provides and easy way to setup
XEasyMessageem2.exe"180solutions adware"
UEasySync Pro - LtNts4NtsAgent.exe"Lotus Notes 4 specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
XEDxMC110Isass.exe"Added by the VB-NIA WORM!"
UELSA WINman SuiteWinmsuit.exe"Allows you to totally customize your ELSA graphics card settings
YElsaCapiCtlRcapi.exe"Assumed to stand for Remote Common Application Programming Interface (RCAPI)
UELSAChipGuardelsavect.exe"ChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed
NEnergizer FileSaverEnergizer FileSaver.exe"Energizer FileSaver - UPS back-up utility for Energizer UPS products. From their Tech Support staff this is known to have a memory leak since it's release - with no fix planned! It will grab 2-5 handles per second and crash the average system in less than 3 days - therefore not recommended"
?ENSApServer2_0APSERVER.EXE"Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
XEntraOcio"rundll32.exe MSA64CHK.dllDllMostrar"
UEPSON Stylus Photo R2400E_FATI9SA.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
XError Safeers.exe"ErrorSafe rogue system error and cleaning utility - not recommended"
XError Safe Freeuers.exe"ErrorSafe rogue system error and cleaning utility - not recommended"
XErrorSafeers.exe"ErrorSafe rogue system error and cleaning utility - not recommended"
XErrorSafeFreeUERS.exe"ErrorSafe rogue system error and cleaning utility - not recommended"
YeSafe ProtectESPWatch.exe"eSafe from Aladdin - internet security for gateway and E-mail servers"
?essapmessapm.exe"ESS Solo soundcard driver. Is it required?"
UEW Message Servermsg32.exeConexant (older versions are Brooktree) Wavestream Message Server - associated with Conexant based audio devices
XFastDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XFBSSAie3sh.exe"Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo
UFD_SAPFD.exeReported to be the autopassword program from the Sony Microvault thumb drive
XffeqOMEvcvsav.exe"Added by the RANKY.AB TROJAN!"
XFireWire Driversamx.exe"Added by the SDBOT.AE WORM!"
NForbesForbesAlerts.exeForbes Business News Alerts - displays business news headlines in a little window on the screen
Xfree-save[path to risk]"Freesave security risk that tracks and sends browser information and visited websites on the computer. Uninstall this software unless you put it there yourself"
XFreeMP3download"rundll32.exe MSA64CHK.dllDllMostrar"
XFriendlyTypelsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
Yfsaafsaa.exe"F-Secure antivirus Authentication Agent - creates and stores private keys used by a client to access servers"
Xgadkgak12fsafsakx12.exe"Added by the ONLINEG-N TROJAN!"
NGCSGrabClipSave.exe"GrabClipSave screen capture tool"
XGeneric Host Processlsassw.exe"Added by the AGOBOT-N WORM!"
XGetitAll"rundll32.exe MSA64CHK.dllDllMostrar"
XGetMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XGetTheMusic"rundll32.exe MSA64CHK.dllDllMostrar"
YGhostSurfDelSatelliteDeleteSatellite.exe"Part of SpyCatcher spyware remover from Tenebril. Prevents rogue programs from sending personal information to a remote user via the Internet. If you use SpyCatcher with real time scanning
UGiganews AcceleratorGiganewsAccelerator.exe"Giganews Accelerator from Giganews
XGLSetIT32isass.exe"Added by a variant of the OPTIX PRO TROJAN!"
XGreatDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XGsAdsgms2.exe"PacerD_Media/Pacimedia.com adware"
UHarmony 98 - CasioOrgCasAgnt.exe"Enterprise Harmony 98 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
XhfdtubvnxkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
XhgkytwekeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
XHidup_SusahPembantu.exe"Added by the SILLYFDC.BDM WORM!"
Xhomepage.monitor.exeisamonitor.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
XHostSrvsachostx.exe"Added by the LOOKSKY.H WORM! Drops multiple files in %System%"
XHostSrvsachostx.exe"Added by the LOOKSKY.A or LOOKSKY.F or LOOKSKY.G WORMS!"
XHostSrvsachostx.exe..."Added by the LOOKSKY.E WORM!"
XHotbarSAHotbarSA.exe"Hotbar adware"
UHPGamesActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
UHPLaptopGamesActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
UHPPWRSAVHPPWRSAV.EXE"Power save related for HP Scanners. Many users have complained of system freezes with it running but it stops the light from remaining on all the time. Try www.hp.com
UhpWirelessAssistantHP Wireless Assistant.exeThe HP Wireless Assistant is a user application that provides a way to control the enablement of individual wireless devices (such as Bluetooth or WLAN devices) and that shows the state of the radios for these wireless devices
UhpWirelessAssistantHPWAMain.exeWireless application bundled with HP computers that allows you to control different settings on the computer's wireless devices such as Bluetooth and WLAN
XI just want to say I love Milko and I need a drinksvchost.exe"Added by the CHIKO WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\Administrator\Local Settings\Application Data"
Nibmmessagesibmmessages.exe"""The Access IBM Message Center displays messages to inform you about helpful software that may be pre-installed on your PC. The Message Center can also provide messages about new updates available from the IBM Support Center to keep your computer current"""
NIconsaverIconsaver.exe"IconSaver is a desktop icon manager"
Xidlesam[8 random letters].exe"Added by the ZHELATIN.EQ WORM!"
XIesarIesar.exeBrowser hijacker - redirecting to an adult web page
XIISADMINSsystems.exe"Added by the AGOBOT.U WORM!"
Xilassslsass.exe"Added by the INJECT-GZ TROJAN! Note - the legitimate lsass.exe process should not normally figure in Msconfig/Startup!"
XilortgdgkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
Xinternetwinsas32.exe"Added by a variant of the SDBOT WORM!"
Xinternetlsass.exe"Added by the DSPY-A TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
UInternodeUsagemum.exeAustralian ISP's free monthly download meter
?iPlusAgent2iAgent2.exe"Related to iriver portable media products. What does it do and is it required?"
XIPv6 Helper Drivercsass.exe"Added by the AGOBOT.TC WORM!"
XiSafeAViSafeAV.exe"iSafe AntiVirus rogue security software - not recommended
Xisamini.exeisamonitor.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
Xisamonitor.exeisamonitor.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
XIsassIsass.exe"Added by the FUTRO TROJAN!"
XIsassRenascimentoIssas.exe"Added by the BANKER.GAX TROJAN!"
XiTunesAgentita.exe"Added by the TACTSLAY.U TROJAN!"
NIusagenetdet.exe"Internet Usage Monitor - utility to calculate the cost and time on the internet via dial-up"
Xjavawsa.exejavawsa.exe"Added by the BANK-Y TROJAN!"
XKernel Safe Modesmss.exe"Added by the 78CRACK-A TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XKeyboardlsass.exe"Added by the AGENT.US WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %CommonAppData%\Fearghus"
XKiamat Sudah Dekat_16_04ISASS.exe"Added by the PAHATIA.B WORM!"
ULANMessage ProLANMES~1.exe"LANMessage Pro - ""a powerful tool for communicating with other people on your office/home network"""
ULaplink PDASync 3.0 - LtNts4NtsAgnt.exe"Laplink PDASync for (IBM) Lotus Notes 4 - PDA synchronisation utility"
XLaptop AccessSage.exe"Added by the SDBOT-NB WORM!"
XLARISSA ANTI VIRUSLARISSA_ANTI_VIRUS.exe"Added by the KLASSIR TROJAN!"
XLexmark_X79-55lsasss.exe"Added by the ZONEBAC TROJAN!"
NLifeScape Media DetectorPicasaMediaDetector.exe"Media detector for Picasa's automatic photo organizer"
XLinkSafenessLinkSafeness.exe"LinkSafeness rogue security software - not recommended
XLisaLisa.exe"Added by the SCOM-D premium rate adult content dialler"
XLive Messangerlivemsgr.exe"Added by the RBOT.BXX WORM!"
XLive Messangerwllmsngr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XLive Windows Messenger Versionmsnmessage7.7.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xload=msater.exe"Added by the RETSAM TROJAN!"
XLocal Authority Servicelsass.exe"Added by the MARKTMAN-C TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XLocal Security Authority Servcelssas.exe"Added by the POEBOT-T WORM!"
XLocal Security Authority Servicelssas.exe"Added by the POEBOT-J WORM!"
XLocal Security Authority ServiceIsass.exe"Added by the LINKBOT.M WORM!"
XLogin Screen Saverlogin.scr"Added by the RBOT-AVN WORM!"
XLogonsaracsrss.exe"Added by the BRONTOK-BS WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
XLogServicelsass.exe"Added by the BDOOR-IU BACKDOOR! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XLosMejoresMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XLotsOfGames"rundll32.exe MSA64CHK.dllDllMostrar"
XLotsOfJokes"rundll32.exe MSA64CHK.dllDllMostrar"
XLSAwfdmgr.exe"Added by the MYTOB.C WORM!"
XLSAlsa.exe"Added by the SDBOT-YV WORM!"
XLSAmsdn.exeAdded by an unidentified malware
XLSA ServiceLSASS.exe"Added by the AHKER.G WORM! Note - this is not the legitimate lsass.exe process
Xlsa Serviceslsa2srv.exe"Added by the TAME-C WORM!"
XLSA Shell (Export Version)LSASS.exe"Added by the AHKER.K WORM and variants. Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XLSA Shellulsass.exe"Added by the AUTORUN-CW WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
XLsaManagerlsamgr.exe"Added by the BEAGLE.DR WORM!"
Xlsaslsas.exe"Added by the BIGFAIRY-C WORM!"
XLSAShelllsass.exe"Added by the DAPROSY WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xlsasslsass.exe"Added by the RATSOU.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Debug\UserMode"
Xlsassstart.bat"Added by the ZCREW TROJAN!"
Xlsass[path to lsass.exe]"Added by the ALADINZ.F TROJAN! Note - this is not the legitimate lasss.exe process which should NOT appear in Msconfig/Startup!"
Xlsasslsasrv.exe"Added by the MYDOOM.AG or MYDOOM.AS or MYDOOM.AU WORMS!"
XLsasswoekd.exeAdded by an unidentified WORM or TROJAN!
Xlsasselite***32.exe"EliteBar adware"
XLsassLsass.exe"Added by the ALCOP-B WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XLsassLsass.exe"Added by the VOUMIT-A WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\mirc32"
XLsasSSygate.exe"Added by the SDBOT.BCA WORM!"
XLsasskavmm.exe"Added by an unidentified WORM or TROJAN! NOTE - do NOT confuse with the legitimate Kaspersky antivirus module as described here. Contrary to this impostor
XLsassLSASS.EXE"Added by the PUNYA-B WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%"
XLSASS 32ISASS32.pif"Added by the ASSIRAL-C WORM!"
XLsass 32 Managerlsass32.exe"Added by the SDBOT.EOG WORM!"
Xlsass 32-biTlsass32.exe"Added by the RBOT.QGC WORM!"
XLSASS Authoritylshosts32.exe"Added by the SDBOT-UY TROJAN!"
XLSASS Authoritylsvhosts.exe"Added by the SDBOT.BCE WORM!"
XLSASS DaemonLSASSd.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
Xlsass servicelsass2.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
Xlsass16lsass16.exe"Added by the BANKER-BXX TROJAN!"
Xlsass2k Updatelsass2k.exe"Added by a variant of the RBOT WORM!"
XLSASS32Isass32.exe"Added by the KELVIR.M WORM!"
Xlsass32lsass32.exe"Added by the LYDRA-B TROJAN!"
Xlsass64BiT.exelsass64BiT.exe"Added by the FORBOT-CK WORM!"
Xlsassiglsassig.exe"Added by the BANCOS-EC TROJAN!"
Xlsassslsasss.exe"Added by the GEEKMY-A TROJAN!"
Xlsasss.exelsasss.exe"Added by the SASSER.E WORM!"
Xlssaslssas.exe"Added by the AUTORUN.CEY WORM!"
XLssas Monitoring StartupLSSAS.EXE"Added by the RBOT.XJ WORM!"
Xlssasslssas.exe"Added by the AGOBOT.RL WORM!"
XLTM2lssas.exe"Added by a variant of the LITMUS TROJAN!"
ULycosarazerhid.exe"Razer Lycosa gaming keyboard driver - required if you use the additional features and programmed keys/macros"
XM3Development_WhenUSave_InstallerM3Development_WhenUSave_Installer.exe"WhenU.Save adware"
XMachine Update Softwusas.exeAdded by an unidfentified WORM!
XMainDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XMatrixScreenSavermss.exeUnidentified malware
UMDSA Sentinel Xsmss.exe"SentinelX surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the smss.exe process which is always located in %System%. This one is located in %ProgramFiles%\MDSA Software"
NMessage Center PlusMCPLaunch.exe"Launcher for Message Center Plus ""which alerts you when conditions arise on your computer that require your attention"" on IBM/Lenovo ThinkCentre desktops
XMessage Queuingmsmqs.exe"Added by the FREEFORS TROJAN!"
NMessagerStarter FreeserveStartMessager.exeFreeserve Messenger
UMessage_Blockermessageblock.exe"Message Blocker - "prevents Outlook Express from loading images or other content from the internet without confirmation
XMessangertrillian.exe"Added by the RBOT.CKI WORM!"
XMessangerdeamon.exe"Added by the TACTSLAY.C TROJAN!"
XMessangermsgaol.exe"Added by the TACTSLAY.C TROJAN!"
XMessangers_menu.exe"Added by the TACTSLAY.C TROJAN!"
XMessangerbrowse.exe"Added by the TACTSLAY.C TROJAN!"
XMicrcoft Exploererspoolsal.exe"Added by the RBOT-AKK WORM!"
XMicrcoft Updatspoolsae.exe"Added by the RBOT-AIB WORM!"
XMicrcoft Updatspoolsaex.exe"Added by the RBOT-AJM WORM!"
XMicroft Exploererspoolsac.exe"Added by the RBOT-AMD WORM!"
XMicrosft Conf 32msaconf.exe"Added by the RBOT.EYA WORM!"
XMicrosft Confige 32msaconfigurez.exe"Added by the RBOT.CLC WORM!"
XMicrosft Updtessarvice.exe"Added by a variant of the SDBOT WORM!"
XMicrosoftlsass.ppf"Added by the RBOT-GAA WORM!"
XMicrosoft Admin ProtocalMSADNIN.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Anti Virus Controllermsavc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Anti Virus Controllermsavc32.exe"Added by the SDBOT.EPW BACKDOOR!"
XMicrosoft AOL Instant MessengerMSAOL32.exe"Added by the RBOT-AAI WORM!"
XMicrosoft Application Managermsapl32.exe"Added by the BROPIA-AE TROJAN!"
XMicrosoft Authority Servicelsass.exe"Added by the KALEL-D WORM! Note - this is not the legitimate lsass.exe process
XMicrosoft Automatic Update Serivcemsautou.exe"Added by the RBOT-AOB WORM!"
XMicrosoft Client/Server Runtime Server Subsystemcsrssa.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Corp TLS Certificatesmsauth.exe"Added by the RBOT-GAC WORM!"
YMICROSOFT FIREWALL CLIENTISATRAY.EXE"MS Internet Security and Acceleration Server - see here"
XMicrosoft Hosts ServiceIsass.exe"Added by a variant of the RBOT WORM!"
XMicroSoft IE SasserISASS.EXE"Added by the SDBOT.MX WORM!"
XMicrosoft LSA layerMSLSA32.exe"Added by the RBOT-AKZ WORM!"
XMicrosoft Lsass CenterIsass.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Lsass Centertelecomes.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Lsass Managerlsass.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate lsass.exe process
XMicrosoft Lsass Servicewintcp32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft LSASS386 Protocolscvhost32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Macro Protection SubSsymsacroprots386.exe"Added by the RBOT-KE WORM!"
XMicrosoft Management Consolelssas.exe"EasySearch adware"
XMicrosoft Management Consolelssas1.exe"Added by the DLOADR-AWD TROJAN!"
XMicrosoft Message Machinemsmesg32.exe"Added by the SPYBOT.BI WORM!"
NMicrosoft Officeosa.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
NMicrosoft OfficeOsa9.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
XMicrosoft Office quick launchOSA.exe"Added by the VBOT.A BACKDOOR! Note that OSA.exe was used in older versions of Office to launch common components to help speed up the launch but it is no longer normally used - see here. This file is located in a valid MS Office 2003 (aka Office 11) directory - %Program Files%\Microsoft Office\OFFICE11 - and may overwrite a valid file"
NMicrosoft Office Startuposa.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
NMicrosoft Office StartupOsa9.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
XMicrosoft PC Health Remote Assistance File Open & Save controlssfrcdlg32.exe"Added by the RBOT-AVY WORM!"
XMicrosoft quick launchOSA.exe"Added by a variant of the VBOT.A BACKDOOR! Note that OSA.exe was used in older versions of Office to launch common components to help speed up the launch but it is no longer normally used - see here. This file is located in a valid MS Office 2003 (aka Office 11) directory - %Program Files%\Microsoft Office\OFFICE11 - and may overwrite a valid file"
XMicrosoft Safe Mode Managersafemode.exe"Added by the IRCBOT.HM BACKDOOR!"
XMicrosoft security advisermssadv.exe"Microsoft Security Adviser rogue security software - not recommended"
XMicrosoft Security Centersavservices.exe"Added by the RBOT-ANU WORM!"
XMicrosoft Security Monitor Processlsas.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Security Pansasagersdgkztsqgn.exe"Added by the RBOT-BBJ WORM!"
XMicrosoft Server Applacationslsasss.exe"Added by the RBOT-AQQ WORM!"
XMicrosoft Service Disk Cycledisksave.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service DriversVSADNIM.exe"Added by a variant of the RBOT WORM!"
XMicrosoft SpA Servicemsapps.exe"Added by the RBOT-VI WORM!"
XMicroSoft ssadsadas3s1eXtream.exe"Added by the SPYBOT.ZK TROJAN!"
XMicroSoft ssadssjdhasjadas3s1kdjfsdklfjsl.exe"Added by the SDBOT.AEX WORM!"
XMicroSoft ssas3s1SADASDA.exe"Added by the RBOT.URF WORM!"
XMicrosoft System Saver[path to worm]"Added by the RBOT.BSK WORM!"
XMicrosoft System Security AgentMSTSA.EXE"Added by the RBOT.CCM WORM!"
XMicrosoft UpdateIsac.exe"Added by the RBOT-AU WORM!"
XMicrosoft Updatemsawindows.exe"Added by the GAOBOT.AFJ WORM!"
XMicrosoft Updatelsac.exe"Added by the GAOBOT.XW WORM!"
XMicrosoft Update Machinelsasse.exe"Added by the RBOT-DI WORM!"
XMicrosoft UPDATER32lsass.exe"Added by the RANDEX.AR WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!"
XMicrosoft UPDATER32LSASS32.EXE"Added by the RANDEX.AR WORM!"
XMicrosoft USA Plugusaplug.exe"Added by the RBOT-DVC WORM!"
NMicrosoft Utility StartupOSA9.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
XMicrosoft Visual SourceSafeservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XMicrosoft Visual SourceSafewinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XMicrosoft Visual Studio VSAvarpc32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Windows Updateswsap32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows WinSaSS Managementwinsass.exe"Added by the RBOT-APW WORM!"
XMicrosofts Updateslsasss.exe"Added by the RBOT-AEX WORM!"
XMicrosoftSourceSafecsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XMicrosoftSourceSafelsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
Xmmsassmmdmm.exe"Added by the SDBOT.SO WORM!"
Xmmxrunmsosa.exeAdded by an unidentified TROJAN or WORM!
Xmnsamnso.exe"Added by the LINEAG-AI TROJAN!"
XMoreContent"rundll32.exe MSA64CHK.dllDllMostrar"
UMount Safe & SoundFbmount.exeFrom McAfee VirusScan version 5.x. Creates back-up sets of critical files in a separate area of a hard drive. If you make regular back-ups it's not needed and can be painful during system start
XMoussaEvil[path to file]"Added by the MUSANUB-A WORM!"
XMP3Collection"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3download"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3files"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3freeDownload"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3freeDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3nice"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3Themes"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3ToTheMax"rundll32.exe MSA64CHK.dllDllMostrar"
XMS AntiSpyware 2009msas2009.exe"MS AntiSpyware 2009 rogue spyware remover - not recommended
XMS Auto-IPSec ProtectionMSASP32.exe"Added by the RBOT-AER WORM!"
XMS Autoloader 32MSAuto32.exe"Added by the SPYBOT.BD WORM!"
XMS Config Streammsasm.exe"Added by the AGOBOT-BA WORM!"
XMs Configurationmicrosoftsa32.exe"Added by the KELVIR.X WORM!"
XMS LARISSAMS_LARISSA.exe"Added by the ASSIRAL.B WORM!"
XMS lsass Startuplsass135.exe"Added by the RBOT.WM WORM!"
XMS Screen Saverscrsave.scr"Added by the RBOT-AGT WORM!"
XMS Security Authority Servicelsass.exe"Added by the KALEL-B WORM! Note - this is not the legitimate lsass.exe process
XMS Windows AOL DriverMSAOLdrv.exe"Added by the RBOT-ASP WORM!"
XMS Windows System AlertMSWSA32.exe"Added by the RBOT-BFN WORM!"
XMSACMmsacm.exe"Added by the OPASERV-O WORM!"
Xmsadcheckmsadcheck32.exe"Browser hijacker
XMSAdminjdbgmrg.exe"Added by the DASMIN.A TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here"
XMSAgentmshtm.exeBrowser hijacker - redirecting to buldog-search.com
XMSAgenthhnt.exe"AGENT.JI spyware"
XMSAgentXPMSAgentXP.exeIdentified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the REQLOOK.C TROJAN!
Umsaimmsaolim.exe"MessageSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
Xmsappts32msappts32.exe"Added by the ELBURRO-A TROJAN!"
YMSASCuiMSASCui.exe"Main user interface for Microsoft's Windows Defender on XP/Vista - which ""helps protect your computer against pop-ups
XMsAudioexplorer.exe"Added by the LEGMIR-BY TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMsAudio"MsVM_STI.EXE RunDll32 cmicnfg.cpl CMICtrlWnd"
Xmsavsc.exemsavsc.exe"Added by the AGENT.ANQ TROJAN!"
XMSConfiglssas.exe"Added by the AUTORUN.CEY WORM!"
XMSControl3d1isasse.exe"Added by the RBOT.CGU WORM!"
Xmsfindosa.exemsfindosa.exe"Added by the DOWNLOADER-BS TROJAN!"
NMsgCenterExeRealOneMessageCenter.exe"RealNetworks RealPlayer related - disabling this application will not affect Real Player in any way"
XMSLARISSAMSLARISSA.pif"Added by the ASSIRAL.B WORM!"
XMSNlsass32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN Live Messangermsnlivegs.exe"Added by the RBOT-FSG WORM!"
XMsn Message Acount Helper 7.7msnmessage7.7.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN Message Background loader[path to worm]"Added by the RBOT-AIE WORM!"
XMSN Message Servicemsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMsn Messagermsnmsgr.exe"Added by the DOWNLOADER.19456.C TROJAN! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMSN Messagermsnmgr.exe"Added by the IRCBOT-ACD WORM!"
XMSN Messagesmsnmesg.exe"Added by the RBOT-ACN WORM!"
XMSN Messagesmsnmessgs.exe"Added by the SLENFBOT.UC WORM!"
XMSN Messangermsnmsng.exe"Added by the SDBOT.XN WORM!"
XMSN messangermsnmsgsm.exe"Added by the RBOT-FMP WORM!"
XMSN Messangermsnmsgsmn.exe"Added by the RBOT-FOQ WORM!"
XMsn Messangercrsss.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMsn Messangermsnmsgem.exe"Added by the RBOT.BLL BACKDOOR!"
XMSN MessangerSystem.exe"Added by the IRCBOT-AFX TROJAN!"
XMSN Messanger Livewinntmsn.exe"Added by the RBOT-FSO WORM!"
Xmsnmsgq32sssasasb32.exe"Added by the TACTSLAY.F TROJAN!"
XMsnmsgr.exelsass.exe"Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root directory (i.e. C:\ or D:\)"
XMSNPluginSrIvcsn3vasap23.exe"Added by a variant of the RBOT WORM!"
XMSNPluginSrvcssagate.exe"Added by the SDBOT.AKJ WORM!"
XMsnWinmessagewin.exe"Added by the BANCBAN-D TROJAN!"
XMSPQFileMSA****.TMP [* = random char]Homepage hijacker
Xmssarumssaru.exe"Added by the AGENT.AM TROJAN! Note - example names include ""XviD""
Xmsupdater25lsasser.exe"Added by the RBOT-ATS WORM!"
Xmsvcc25salvage.exe"Added by a variant of the SDBOT WORM!"
XMSWTL32MSATL32.exe"Added by an unidentified WORM or TROJAN! See here"
XMS_LARISSAMS_LARISSA.exe"Added by the ASSIRAL WORM!"
XMy Agentmsagent.exe"Added by the NEGASMS.A TROJAN!"
UmyCIO.com ASaPmyagttry.exeSystem tray notification for the now obsolete McAfee VirusScan ASaP online anti-virus and anti-spyware security tool for small businesses. Not required to be protected but you lose notifications
XNarmonVirusAntismss.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XNAV Auto Updateiamsad.exe"Added by the SPYBOT-CE BACKDOOR!"
XNAV Auto UpdateSadness.exe"Added by the SPYBOT-E WORM!"
XNDIS Adapterlsass2.exe"Added by the WOOTBOT.CW WORM!"
UNetScreen-RemoteSafeCfg.exe"NetScreen Remote VPN client software"
XNewDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XNewMP3"rundll32.exe MSA64CHK.dllDllMostrar"
NNewsalrtNEWSALRT.EXEMSNBC News system tray utility to alert you to new news
XNiceDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XNiceMP3"rundll32.exe MSA64CHK.dllDllMostrar"
Xnisdisanisdisa.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
XNordBullmsa.exe"Added by the DLOADR-CSV TROJAN!"
XNorton Updaterlsa.exe"Added by a variant of the RBOT WORM!"
XNortonAntivirusLSASS.exe"Added by the PEXMOR WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Temp"
XnortonsantivirusccEvtMngr.exe"Added by the HZDOOR-A TROJAN!"
XNTmessageSystemloadnewmessage.exe"Added by the HIDAGENT-B WORM!"
XNumberOneMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XNviDiaGTlsass.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XNvMsnWIsass.exe"Added by the BROPIA.K WORM!"
XNxvstlsas.exe"Added by the GAOBOT.CD WORM!"
NOffice Startuposa.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
NOffice StartupOsa9.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
XOffice SturtUposa9.exe"Added by the CLICKER-EC TROJAN! Note - this trojan is located in %Windir% and should not be confused with the Microsoft office program
XOnluna Sarvicesachost.exe"Added by the TOFGER-AA TROJAN!"
XOnlune Sarvicesachost.exe"Added by the DAEMONI-J TROJAN!"
UOptusNetUsageOptusNet Usage Meter.exe"Designed specifically for OptusNet users who wish to have their connection monitored on a frequent basis. It can also estimate when you are going to hit your usage limit
XOSAwinword.exe"Added by the KANGAROO-A TROJAN!"
XOsa32NTOSA32.exe"Added by the ANIG WORM!"
XOutLooksInSane.exe"Added by the SWOOP TROJAN!"
?Packard Bell EverSafe Tray ControlTrayControl.exe"Packard Bell EverSafe software. What does it do
XPatah HatiISASS.exe"Added by the PAHATIA.A WORM!"
UPCRecSAPCRecSA.exe"Part of the IBM/XPoint Rapid Restore backup utility. If you choose
NpdfSaver3pdfSaver3.exe"PDF-XChange - create Adobe compatible PDF files from virtually any Windows software such as MS Word
NPicasa Media DetectorPicasaMediaDetector.exe"Media detector for Picasa's automatic photo organizer"
NPicasaNetHello.exe"Hello is an application that allows Blogger users to post digital photos and captions directly to their personal weblogs
UPlanlægningsagentmstask.exe"Windows Task Scheduler (on Danish language versions of Windows) - displayed as a box with a stopwatch in the System Tray. Required if you have regularly scheduled tasks like defragmenting
XPopularScreensaversWallpaper"rundll32 [path] F3SCRCTR.DLLLES"
UPowerDOCSAPIHostpapihost.exe"Hummingbird PowerDOCS - ""delivers powerful enterprise document management functionality via a tightly integrated Microsoft WinNT/98/2K environment"""
YPrevxHomeSAGUI.exe"PrevX Home intrusion prevention software"
YPrevxProSAGUI.exe"PrevX Home intrusion prevention software"
XPrinterSpyassault.exe"SpyAssault spyware remover - not recommended
XprinterSpyAssaultScanner.exe"SpyAssault spyware remover - not recommended
NProdikeysAutorunProdload.exe"Creative Prodikeys software - 'an interactive music entertainment device which not only functions as a full-featured
XProglsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
Xpsaload32psaload32.exe"Added by the RBOT-ADL WORM!"
UPwrsavePwrsave.exeToshiba Power Saver utilities. Required on a laptop if you run of a battery and want to conserve power
UPWSActivePrint_5ActivePrintSystem.exe"ActivePrint from Pocket Watch LLC - ""Windows Mobile users are given the invaluable capability of printing from their mobile devices to any Windows 2000/XP/2003/Vista compatible printer without the necessity of wireless hardware"""
NQD FastAndSafeQDCSFS.exeAutomatically runs Fast & Safe clean-up from Norton/Quarterdeck Cleansweep. Deletes safe to remove files such as Temporary Internet Files (cache). Recommended you run it manually
?Qdsafe??"??"
NQuickenSEMessageQsemsg.exeQuicken option
XRBOT v2 with NetAPI exploit traded with billgates I gave my mother Greetz - OG - Bluehell Irc Serverglossary.exe"Added by the VANEBOT-J WORM!"
UReclusarazerhid.exe"Microsoft Reclusa (by Razer) gaming keyboard driver - required if you use the additional features and programmed keys/macros"
XRegDoneExlsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XRegistry Value Name StartMsPMSPSa.exe"Added by a variant of the SDBOT WORM!"
Xresagntrestun.exe"Detected by Panda as the DOWNLOADER.ALQ TROJAN! Adware downloader"
XRsWinlsass.exe"Added by the DELCANTI-B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""12053"" subfolder"
XRsWinlsass.exe"Added by the SILLY.BR WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""4350"" subfolder"
XRTHDBPLlsass.exe"Added by the ROUTROBOT WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\SystemProc"
XRunnerlsass.exe [trojan filename]"Added by the DROWSY-B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRunnerlsass.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
?SASa3.exe"Logitech QuickCam driver. Is it required?"
?SA ServiceSAservice.exe"Associated with Cyber Trio and Warner troubleshooting software from G-Tek Technologies and pre-installed on some Packard Bell and NEC PCs. What function does this perform and is it required?"
NSa3dsrvSa3dsrv.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
Xsaapsaap.exe"180solutions adware"
USabre Printing StartSabstart.exe"Part of the Sabre computer reservations system/global distribution system (GDS) - used by airlines
USabre Serversabserv.exe"Part of the Sabre computer reservations system/global distribution system (GDS) - used by airlines
USabre Task Tray IconSabstart.exe"Part of the Sabre computer reservations system/global distribution system (GDS) - used by airlines
USabreserverSABSERV.EXE"Part of the Sabre computer reservations system/global distribution system (GDS) - used by airlines
Xsacsac.exe"180Search adware"
XSACCsacc.exe"SurfAccuracy adware"
NSAClientRegCon.exe"AT&T or ComCast BBClient - monitors system and network-delivered services for availability. Your current network status is displayed on a color-coded web page in near-real time. When problems are detected
Xsacmemdssmcntlwio.exe"Added by the MAILBOT-BZ TROJAN!"
XSafeSafeWin.exe"Added by the FOCOSENHA TROJAN!"
XSafe[path to trojan]"Added by the BANKER-DT TROJAN!"
XSafeFighterSafeFighter.exe"SafeFighter rogue security software - not recommended
XSafeguard 2009sf2009.exe"Safeguard 2009 rogue spyware remover - not recommended
XSafeGuard Popup Blocker Updaterregsvr32 sfgupd.dll"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeGuard Popup Blocker Updater (required)regsvr32 sfg****.dll [* = ramdom char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeGuard Popup Updater (required)regsvr32 sfg****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeGuard Popup Updater (required)regsvr32 PDF****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeguard.exeSafeguard.exe"Super Spyware Killer rogue spyware remover - not recommended"
XSafeHardDriveSysRep.exe"SafeHardDrive rogue system error and cleaning utility - not recommended
USafeHouseSystemTraySDWTRAY.EXE"SafeHouse ""Personal Privacy"" system tray icon - PP protects and hides your private and personal photos
NSafeInstall.exeSAFEIN~1.EXEMonitors a download and ensures an newer version of a file isn't replaced by an older one
NSafeOFFSafeOff.exeProvides protection that if user accidentally presses the power switch a dialog will pop up for confirmation
XSafePcAvSafePcAv.exe"SafePcAv rogue security software - not recommended
XSafePCToolSysRep.exe"SafePCTool rogue system error and cleaning utility - not recommended
XSafeSearchsafesearch.exe"SafeSearch.A adware"
YSafeSpaceSafeSpaceSysTray.exe"Part of SafeSpace (from Artificial Dynamics) which ""protects computers from Internet malware infection without the need for signature updates or regular maintenance"""
XSafeStripSafeStrip.exe"SafeStrip rogue security software - not recommended
XSafeStripReminderSafeStripReminder.exe"SafeStrip rogue security software - not recommended
XSafeSurfingUpdateSSUpdate.exe"MoneyTree parasite - ActiveX control used to download premium-rate dialers"
XSafeSysSafeSys.exe"Added by the AUTORUN.DMI WORM!"
XSafety Anti-Spyware 3Safety Anti-Spyware 3.exe"Safety Anti-Spyware rogue security software - not recommended
XSafetyCenterprotector.exe"Safety Center rogue security software - not recommended
XSafetyKeeperSafetyKeeper.exe"SafetyKeeper rogue security software - not recommended
USafetyNetipcTray.exe"Safety.Net from Netveda - ""offers Internet security
USafetyNet_NotifieripcLn.exe"Safety.Net from Netveda - ""offers Internet security
USafeworldFreedom.exeSafeWorld Internet Security - now no longer available
XSagate Security Firewallsagate.exe"Added by the GAOBOT.BOW WORM!"
NSAgent2ExePathSAgent2.exeSeiko Epson printer status agent. Disable if printer is not used often
USAGENTSERVICESagent.exe"TinySpyAgent commercial keystroke logger. Uninstall this software if you did not install it yourself"
XSaggwwggCVAvwwd.exe"Added by the LIOTEN.HT WORM!"
Xsagntsagnt.exeAdware web downloader
XSAHagentSahagent.exe"ShopAtHomeSelect parasite"
XSAHBundlebundle.exe"ShopAtHomeSelect parasite"
XSAHBundleshop1003.exe"ShopAtHomeSelect parasite"
Xsaiesaie.exe"180solutions adware"
USaiMfdSaiMfd.exe"Saitek MFD File System Driver - associated with the Saitek SST (Saitek Smart Technolgy) configuration software for their game controllers. Create a shortcut and run manually when required"
USAIMONSaiMon.exe"Saitek joystick driver"
Xsainsain.exe"180Search adware"
Xsaissais.exe"180solutions adware"
USaiSmartSaiSmart.exe"""Smart Button Special Sauce"" - included with the latest software for Saitek game controllers. Related to the ""S""
USaitekAutoConfiguresaicnfig.exe"Configuration for Saitek game controllers"
XSakemsneqlsimenu.exe"Added by the SDBOT.BTO WORM!"
XSakoraSakora.exe"Added by the GOWELES.A TROJAN!"
NSalaatTimeSalaatTime.exe"""Salaat Time is a FREE multi-function Islamic application that calculates the prescribed five daily Muslim prayer times as well as Qiblah direction for anywhere in the world"""
XSalestartWAS7Mon.exe"Part of the WinAntiSpyware 2007 rogue spyware remover - not recommended"
XSalestartbm.exe"Part of the AVSystemCare rogue security software and other members of this family. See here for more examples"
XSalestartdcpasmon.exe"SystemDoctor rogue security software - not recommended
XSalestartdcsm.exe"Part of the PrivacyProtector and DriveCleaner rogue security tools"
XSalestartmc.exe"Part of SecurePCCleaner
XSalestartstm.exe"Part of SecurePCCleaner
XSalestartstrpmon.exe"Part of the ErrClean rogue system error and cleaning utility and other members of this family. See here for more examples"
XSalestartstmon.exe"Part of rogue software including members of the AVSystemCare security suite family (see here for examples) and the PcRaiser and SystemOptimizer2008 optimization utilities"
XSalestartmav_startupmon.exe"Part of the WinAntiVirus Pro 2007 rogue security software - not recommended
XSalestartPASmon.exe"Part of rogue security tools
XSalestartdcmon.exe"SystemDoctor rogue security software - not recommended
XSalestartstartmon.exe"ErrorProtector rogue system error and cleaning utility - not recommended"
Xsalmsalm.exe"180Search adware"
USalmosarazerhid.exe"Razer Salmosa gaming mouse driver - required if you use the additional features and programmed keys/macros"
Xsalysaly*****.exeAdded by a variant of the AW.AWK TROJAN!
XSam-sungSam-sung.exe"Added by a variant of the SDBOT WORM!"
XSaMail[WORM FILE NAME].vbs"Added by the VBS.LIDO WORM!"
USAMcalSAMcal.exe"SamCal - calendar/reminder program"
USametime ConnectConnect.exe"IBM Lotus Sametime - instant messaging and Web conferencing software"
XSamsongSamsong.exe"Added by the SDBOT.BNE WORM!"
XSamsungSamsungs.exe"Added by an IRC TROJAN variant!"
USamsung MJC-900 Series Monitor"RUNDLL32.EXE SMMASHLL.DLLAutoUpdatePnPValue"
USamsung PanelMgrSSMMgr.exe"Monitors ink levels
USamsungSM PanelMgrSSMMgr.exe"Monitors ink levels
USandboxieControlControl.exe"SandBoxie - allows data to be read from the hard drive by an application but never written back unless you allow it"
USandboxieControlSbieCtrl.exe"""SandBoxie runs your programs in an isolated space which prevents them from making permanent changes to other programs and data in your computer"""
NSandIconSandIcon.exe"SanDisk ImageMate CompactFlash card reader SDDR-31 (USB). Very little use except to place the Sandisk icon beside its drive designation in Windows Explorer. The reader itself will work fine without it. The simplest thing is to just unplug the reader when you're not using it. It may slow the startup by a few nanoseconds
XSanitarDiskaGDC.exe"SanitarDiska Romanian rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XSANS Servicesansv.exe"Added by the VANEBOT-AH WORM!"
USansaDispatchSansaDispatch.exe"Sansa Updater - ""The Sansa Updater is an application that checks for the latest firmware updates then downloads and installs the firmware to your Sansa device"""
XSanta Bastards BitchSANTAS.BITCH.txt"Added by the ATNAS.A WORM!"
Xsappsapp.exe"NCase adware"
USaskTel Accelerated Dial-upsasktelgui.exe"""Experience faster surfing
Xsasserfixpackage.exe"Added by the DABBER.B WORM!"
XsaSyncMgr"rundll32.exe sasync.dll SyncWait"
USATARaidSATARaid.exeRAID driver for serial ATA disks on some motherboards such as the DFI Lanparty range. Only loaded if one is using RAID support on SATA drives
Xsatmatsatmat.exe"VX2.Transponder parasite updater/installer related"
Xsausau.exe"180Search adware"
USAUpdateSAUpdate.exe"Big Brother from Quest Software. System and network monitor"
USAutoLaunchExeSAutoLaunchExe.exe"Sharp Zaurus PDA related
YSAVAgentSAVAgent.exe"Part of Sophos anti-virus software. Required for centrally administered Sophos updates to work correctly
XSavasddwqffasd.exe"Added by the SDBOT-SI WORM!"
XSaveSave.exe"WhenU.Save adware"
XSavelssas.exe"Added by an unidentified TROJAN! See here"
XSaveArmorSaveArmor.exe"SaveArmor rogue security software - not recommended
XSaveDateSaveStartDate.ExeUnidentified adware
XSaveDefenderSaveDefender.exe"SaveDefender rogue security software - not recommended
XSaveDefenseSaveDefense.exe"SaveDefense rogue security software - not recommended
XSaveKeepSaveKeep.exe"SaveKeep rogue security software - not recommended
XSaveKeeperSaveKeeper.exe"SaveKeeper rogue security software - not recommended
XSavenowSaveNow.exe"WhenU.Save adware"
XSaveSoldierSaveSoldier.exe"SaveSoldier rogue security software - not recommended
XSavsvc"rundll32.exe savsvc.dllstart"
XSAWsaw.exe"SmartAdware adware"
USay The Time 5.0SAYTIME.EXE"This program has audio cues for the system clock in male and female voices
XScanDiscsatan.exeAdded by the GREGSTAR TROJAN!
XScheduler Servicewsass.exe"Added by the LIOTEN.KX WORM!"
UScreen Guard Message Scansgms.exe"Part of Access Denied security and privacy software"
XScreen Saverscrnsaver.scr"Added by the RBOT-AGP WORM!"
NScreen Saver ControlFSScrCtl.exeInstalls as part of the Hubble Space Telescope screen saver (and possibly others). Lets you control your installed screensavers from a System Tray icon
XScreenSaverPlus"rundll32.exe MSA64CHK.dllDllMostrar"
XSearchMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XSecurity Accounts Manager SMsamsm.exe"Added by the SPYBOT.JE WORM!"
XSecurity Agent Managermssams.exe"Added by the RBOT-SV WORM!"
XSecurity AntivirusSA[random characters].exe"Security Antivirus rogue security software - not recommended
XSecurity Mechaniclsascs.exe"Security Mechanic rogue security software - not recommended
XSeekmoSASeekmoSA.exe"180Solutions.Seekmo adware variant - also see here"
XService Registry NT Savejdbgmgrnt.exe"Added by the BANCOS-CG TROJAN!"
XService Registry NT Savetaskmgrnt.exe"Added by the BANCOS-BY TROJAN!"
XService Registry NT Saveregeditnt.exe"Added by the BANCOS-BM TROJAN!"
XServicessysamp.exe"Added by a variant of the SDBOT WORM!"
Xservicessample.exe"Added by a variant of the RANKY TROJAN!"
XServices Controllerlsassa.exeAdded by the CIADOOR.122 VIRUS!
XServicesActivecssrs.exe"Added by the AGOBOT-GB BACKDOOR!"
XServicesAdministratorSERVICES.EXE"Added by the PUNYA-B WORM! Note - this is not the legitimate services.exe process
XServicesaraservices.exe"Added by the BRONTOK-BS WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
XServicesLoadlsass.exe"Added by the DEARIS-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSession Manager Subsystemsmssa.exe"Added by the RBOT-AGS WORM!"
XShellspllsas.exe"Added by the YALER-A TROJAN!"
XShieldSafenessShieldSafeness.exe"ShieldSafeness rogue security software - not recommended
NShopSafeShopSafe.exe"Created by Orbiscom for MNBA (now Bank of America) - ShopSafe creates a temporary card number each time you make an online purchase"
YSiS7012UtilitySiSAudUt.exeSiS Corporation sound card driver
?SISAM10MSISAM10M.exe"??"
NSiSAudioMP_S3.exeWinME patch for an older SiS 961 chipset FERR bug. Enable if you have audio problems
Xsmsa_exe.exe"Added by the OLFEB.A TROJAN!"
XSmansaAppwinlogon.exe"Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
USMS Win9x Message AgentSMSMsg.exeThis program assigns a user to a Systems Management Server site
XSndsaverSndsaver.exe"Added by the GEMA TROJAN!"
XSocial Security Agencyrpcxsocsa.exe"Added by a variant of the RBOT WORM!"
XSoftSafenessSoftSafeness.exe"SoftSafeness rogue security software - not recommended
XSondBlasterlsass.exe"Added by the PROSTI.AA BACKDOOR! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Media"
NSpellex Anywheresa.exe"Spellex-Anywhere - adds spell checking functionality to almost any Window program. Create a shortcut and run manually before it's to be used"
XSpy Protectorlsascs.exe"Spy Protector rogue security software - not recommended
USRS Audio SandboxSRSSSC.exe"SRS Audio Sandbox ""provide amazing audio immersion and maximum thump for a personalized audio experience!"""
NSsAADSsAAD.exe"Starts Sony's SonicStage CP digital music manager automatically when an ATRAC audio device is connected - such as a Walkman MP3 player or a PlayStation® Portable"
NSsAAD.exeSsAAD.exe"Starts Sony's SonicStage CP digital music manager automatically when an ATRAC audio device is connected - such as a Walkman MP3 player or a PlayStation® Portable"
Xssate.exeirun4.exe"Added by the BEAGLE.J WORM!"
Xssate.exewinsys.exe"Added by the BEAGLE.K WORM!"
Xsssasasb32sssasasb32.exe"Added by the TACTSLAY.F TROJAN!"
Xsssasasb32msnmsgq32.exe"Added by the TACTSLAY.F TROJAN!"
XStartReplySystemloadnewmessage.exe"Added by the HIDAGENT-B WORM!"
Xstatloadspgjd83sa.exe"Added by the SDBOT-UM WORM!"
UStayAlivesa.exe"StayAlive from TFI Technology. "This top-notch tool intercepts crashes when they happen
USuperAdBlockerSAdBlock.exe"SuperAdBlocker"
USureshotpopupkillerpusak.exe"Stop-the-Pop-Up popup blocker"
XSurfAccuracysacc.exe"SurfAccuracy adware"
NSurveysasurveysa.exe"Found on Sony laptops
YSynAsusAcpiSynAsusAcpi.exePart of the Synaptics touchpad driver for the Asus Eee PC range
XSyntax Scriptsaskatcw.exe"Added by the SDBOT-TE WORM!"
XSysAwin***32.exe [* = random char]"EliteBar adware"
USysAgentSysAgent.exeSYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of
XSysAISysAI.exe"AproposMedia adware"
Xsysalggsysalgg.exe"Added by the TIBS.BF WORM!"
XSysanalysingmyrvc.exe"Added by the AUTORUN-RD WORM!"
XSysAntivirus 2009sysav.exe"SysAntivirus 2009 rogue security software - not recommended
XSysATWsysatw.exe"Added by the VANEBOT-AM WORM!"
Xsysavwinav.exe"WinPC Antivirus rogue security software - not recommended
XSYSTEMlsas.exe"Added by the SPYBOT.CJ WORM!"
Xsystemlsasse.exe"Added by the RBOT-YL WORM!"
Xsystemlsass.exe"Added by the SATILOLER.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System"
XSystem Analyzerlsass32.exe"Added by the SDBOT.CNI WORM!"
XSystem Applications Profilesap.exe"Added by the RBOT-QF WORM!"
XSystem HandlerLSASS.EXE"Added by the NIMOS WORM! Note - this is not the legitimate lsass.exe process
XSystem Kernellsass.exe"Added by the VBBOT-G TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSYSTEM MESSAGERwmisg.exe"Added by the MYTOB.ES WORM!"
XSystem Messaging QueueSMCSS.EXE"Added by a variant of the RBOT WORM!"
XSystem Monitoringlsass.exe"Added by the BRONTOK-BS WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
XSystem Processlsass.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem Protectorlsascs.exe"System Protector rogue security software - not recommended
XSystem Spooler Subsystemlssas.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSystem Update Servicewmiprvsa.exe"Added by the AGOBOT-RG TROJAN!"
XSystem32lsasss.exe"Added by the RBOT-XW WORM!"
USystemAgentSage.exe"""Microsoft Plus! System Agent automatically tunes your system
USystemSafeSyssafe.exe"System Safety Monitor - system monitoring tool with additional application firewalling"
XSYSTEMSars32csrss.exe"Added by the AHLEM.A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystemSASSystem32.exe"Added by the KWBOT.C WORM!"
USystem_Messagespprsen.exe"TerminatorX - ""offers an easy and effective method of stopping users running predetermined file sharing programs like KaZaA
XSystesjrdtifkkxbbsa.exe"Added by the RBOT-ADC WORM!"
XTakeMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XTaskLSASS.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate lsass.exe process
XTheBestMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XThemeMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XTimeSink Add ClientTSADBOT.EXEAdvertising spyware
Xtmp_upsample.exeQuickBar adware
XTok-Cirrhatus-1959sarcsv711224030r.exe"Added by the BRONTOK-R WORM!"
XTok-Cirrhatus-1959sarcyesbron.com"Added by the BRONTOK-R WORM!"
XToPLSASS.exe"Added by the WOWCRAFT.C TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XTransaction Taskerstdhost.exe"Added by the SDBOT.HNK BACKDOOR!"
XTraybarlsass.exe"Added by the MYDOOM.L WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NTraySantaCruztbctray.exeProvides quick access via a System Tray icon to the control panel for Turtle Beach's Santa Cruz or VideoLogic's SonicFury soundcards. Available via Start -> Settings -> Control Panel
Xtsatsm.exe"TargetSaver adware"
XTsa2tsm2.exe"TargetSaver adware"
XTsAdbotTSADBOT.EXETimeSink Add Client - advertising spyware
Xttoolsa23sl.exe"Added by the BCKDR-QZZ TROJAN!"
XTXMouiekeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
NTypingSatelliteKBOOST.exe"Typing Master 2002 background utility that collects typing errors and builds up customised typing lessons for your needs. Available via Start -> Programs"
UUCmore XP - The Search Accelerator"rundll32.exe UCMTSAIE.dll DllShowTB"
NUMAX VistaAccessvsaccess.exeVistaAccess gives you quick and easy access to scanning functions right from your desktop
XUniversal Plug & Play devicesWinUPPD.exeAdded by an unidentified WORM/TROJAN!
XUniversal USB Servicesvchost32.exe"Added by the KELVIR.R WORM!"
XUpdatelsass.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XUpgrade Sarvicesxchost.exe"Added by a variant of the TOFGER-I TROJAN!"
XUSAusa.exe"USAntiSpy rogue security software - not recommended
XUSARUSAR.exe"Ultimate Spyware Adware Remover - not recommended
XusbSASS.EXE"Added by the FUNSTA-A TROJAN!"
XUser Messagesusrmsg.exe"Added by a variant of the IRCBOT TROJAN! See here"
XUser Messages Managerusnmsgs.exe"Added by a variant of the IRCBOT TROJAN! See here"
XUserinitlsass.exe"Added by the VIRAN-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Program Files%\Common Files%\System"
XUssirwsa.exe"PurityScan adware"
XUtilisateurSurSysRep.exe"UtilisateurSur
XUtilitiesAndSoftware"rundll32.exe MSA64CHK.dllDllMostrar"
XvcbbjfkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
Uversatoversato.exe"""Hot"" button (such as volume and browser control) management and a CD player as supplied with QTronix (as possibly Micro Innovations) keyboards"
XVideo Card Driver (do not remove)tsasi.exe"Added by the SPYBOT-EF WORM!"
XVirusDifesapgs.exe"VirusDifesa
XViSulaBaCislsass.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
Xvsadminsmrs.exe"Added by the AGOBOT-RC WORM!"
XVsamplewinxpsock.exe"Added by the SDBOT.BLK WORM!"
UWAWifiMessageWiFiMsg.exe"""HP Wireless Assistant is a user application that provides a method for controlling the enablement of individual wireless devices (such as Bluetooth or WLAN devices) and that shows the state of the radios for these wireless devices"""
UWebExRemoteAccessAgentraagtapp.exe"Related to Web Meetings from WebEx Communications
Uwebsaverlivewebsaverlive.exe"WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your computer is idle"
XWebSavingsfromEbatesWebSavingsfromEbatesrun.exe"Web Savings From Ebates Software
XWebSavingsFromEbates0WebSavingsFromEbates0.exe"Web Savings From Ebates Software
XWhenUSaveSave.exe"WhenU.Save adware"
XWin32 LSA Driverlsa.exe"Added by the FORBOT-FJ WORM!"
XWinApp32msapp.exe"Added by the RSBOT TROJAN!"
XWindeows NetStart Service2tesakrmger.exe"Added by the RBOT-AMY WORM!"
XWinDLL (asdfsa.exe)"rundll32.exe asdfsa.exestart"
XWinDLL (slsass.exe)"rundll32.exe slsass.exestart"
XWindow Msn Live Messangermsnmsgsls.exe"Added by the RBOT.BJD BACKDOOR!"
XWindows Authority Servicelsass.exe"Added by the KALEL-E WORM! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XWindows auto updateLSASS.exe"Added by the AHKER.G WORM! Note - this is not the legitimate lsass.exe process
XWindows Console MonitorgcasAV32.exe"Added by the KEDEBE-A WORM!"
YWindows DefenderMSASCui.exe"Main user interface for Microsoft's Windows Defender on XP/Vista - which ""helps protect your computer against pop-ups
XWindows ExplorerLsas.exe"Added by the GAOBOT.AO WORM!"
XWindows Identifysysays.exe"Added by a variant of the SPYBOT WORM! See here"
UWindows Live Family Safety Filterfsui.exe"System Tray access to and notifications from Windows Live Family Safety - optionally installed as part of Windows Live Essentials. ""With Family Safety
XWindows Live Messagesmsgnlive.exe"Added by the AGENT.AYH WORM!"
UWindows Live™ OneCare™ Family Safetyfssui.exe"System Tray access to and notifications from Windows Live OneCare Family Safety - part of the Live OneCare range and now superseded by Windows Live Family Safety which is part of Windows Live Essentials. Allows you to decide how your kids experience the Internet by limiting searches
XWindows Local Spoolerlssas.exe"Added by the RBOT.BXQ WORM!"
XWindows Locatorwsass.exe"Added by the IRCBOT.N TROJAN!"
XWindows Media Playermsa.exe"Added by the RBOT-SI WORM!"
XWindows Media Playermsams.exe"Added by the RBOT.AHR WORM!"
XWindows Media Playermsass43.exe"Added by the RBOT-RT WORM!"
XWindows Messanger Control Centersvchosl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Messanger Control Centersvhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Messanger Control Centerwinlogin.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Messanger Control Centerwinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Messanger Control Centerwinsys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Msn Live Messangermsnmsgsman.exe"Added by a variant of the SDBOT WORM!"
XWindows MSN Live Messangerwmsnlive.exe"Added by the RBOT.BMV BACKDOOR!"
XWindows MSN Live Messangerlivemsngs.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows Recavery Adwarelsass.exe"Added by an unidentified TROJAN - see here. Note - this is not the legitimate lsass.exe process
XWindows SAomniscient.exe"BLAZEFIND adware"
XWindows ScreensaverService.exe"Added by the KELVIR.P WORM!"
XWINDOWS SCREENSAVERssaver.scr"Added by the SDBOT-YZ WORM!"
XWindows Secure Messaging Systemmsnmsgrsrvc.exe"Added by the RBOT-RE WORM!"
XWindows Security Authority Servicelsass.exe"Added by the KALEL-A WORM! Note - this is not the legitimate lsass.exe process
XWindows Security Policylsass32.exe"Added by the AGOBOT-CR WORM!"
XWindows Security Updatendsass.exe"Added by the RBOT.ESM BACKDOOR!"
XWindows Service Agentdsass.exe"Added by the RBOT.MIRCO.BNG WORM!"
YWindows SteadyState - Bubble MessagesBubble.exe"Part of Windows SteadyState
XWindows Svchost Authorityslsass.exe"Added by the RBOT-UA WORM!"
XWindows System32clsas32.exe"Added by the RBOT-AZO WORM!"
XWindows System32 Driverclsass32.exe"Added by the SDBOT-AGG WORM!"
XWindows Taskmanagerlsassx.exe"Added by the KELVIR.E WORM!"
XWindows Updatemsnsa32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Update CenterW32RSA.exeAdded by an unidentified WORM or TROJAN!
XWindows Updatedspoolsae.exe"Added by the RBOT-APM WORM!"
XWindows Updateslsassx.exe"Added by a variant of the SDBOT WORM!"
XWindows WKSwsass.exe"Added by the SDBOT-DK WORM!"
XWindowsACEbaracebarupdate.exe"BarACE adware"
XWindowsAgentWindowsAgent.exe"Added by the GOP.G WORM!"
XWindowsAgentsysexhook.exe"Added by the GOP keyboard logger/TROJAN!"
XWindowsAPI.DLLServer5.exe"Added by the ""Fear and Hope"" TROJAN!"
XWindowsAudiosystemupd.exe"Added by the AGENT-TH WORM!"
XWindowsFirewalllsass.exe"Messenger Blocker rogue security software - not recommended. Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System"
XWindowsProtocolLoglsadst.exe"Added by the NANINF.C TROJAN!"
XWindowsUpdatelsassslsasss.exe"Added by a variant of the AGENT-HZ TROJAN!"
XWindows_LowLevel_Security_Corelsass.exe"Added by the PADMIN-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Repair"
XWindows_Protectlsas.exe"Added by the RBOT.ARO WORM!"
XWindoxs Update CenterW32RfSA.exe"Added by a variant of the SDBOT WORM!"
XWinExecLsass.exe"Added by the CRUTLE-B WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWinFXlsas.exe"Added by the GAOBOT.CD WORM!"
XWinlogonLsass.exe"Added by the ALCOP-B WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xwinlogon_userccIsass.exe"Added by the SILLYFDC.BBT WORM!"
XWinLsassservicec.exe"Added by the SCANE WORM!"
XWinLsass[path to trojan]"Added by the SCANE WORM!"
XWinMenssagewinmax.exe"Added by the BANCOS.B TROJAN!"
XWinMenssagewinmaxy.exe"Added by the BANCOS TROJAN!"
UWinSysAppMonWinSysRM.exe"Home & Family Content Filter related. See here"
XWinToolsWToolsA.exe"Wintools adware"
XWinupdatelsas.exe"Added by the COSPET.JR TROJAN!"
XWinXPServicelsass.exe"Added by the ZAPCHAS-AS TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Lavan"" subfolder"
Xwlsasswlsass.exe"Added by the RANKY.CY TROJAN!"
XWNSAwnsts**.exe [* = random char]"PurityScan adware"
XWNSIrwsa.exe"PurityScan adware"
XWNSTwnsapi**.exe [* = random char]"PurityScan adware"
UWrite DVD-R!saimon.exe"Saimon's WriteDVD! ""gives total support for DVD-RAM drives. It provides many functions such as setting partitions on DVD-RAM disks and FixDVD! can diagnose and repair UDF formatted disks"""
XWSAConfigurationwmon32.exe"Added by the GAOBOT.BAJ WORM!"
XWSAConfigurationsvchostt.exe"Added by the AGOBOT.ZT WORM!"
XWSAConfigurationrpcxmn32.exe"Added by the AGOBOT.ABG WORM!"
XWSAConfigurationwin32upd.exe"Added by a variant of the RBOT WORM!"
XWSAConfigurationdrrss.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWSAConfigurationwinlogon32.exe"Added by the AGOBOT-WC WORM!"
XWSAConfigurationntguard32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWSAConfigurationcsrsvcs.exe"Added by the AGOBOT.VI WORM!"
XWSAConfigurationwinmx32.exe"Added by the AGOBOT-JE WORM!"
XWSAConfigurationkernel32.exe"Added by the AGOBOT-KV WORM!"
XWSAConfigurationwinmon32.exe"Added by the AGOBOT.TM WORM!"
XWSAConfigurationmsnote30.exe"Added by the AGOBOT-KF BACKDOOR!"
XWSAConfigurationsyxtem32.exe"Added by the AGOBOT-MF BACKDOOR!"
XWSAConfigurationsvchostx.exe"Added by the AGOBOT-JV BACKDOOR!"
XWSAConfiguration1csass.exe"Added by the AGOBOT.WH WORM!"
Xwsass32wsass32.exe"Added by the BANKEM-V TROJAN!"
XWSSAConfigurationwmmon32.exe"Added by the AGOBOT-KC WORM!"
XWWKSwsass.exe"Added by the SDBOT-BT WORM!"
XxcfdhtyjkxkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
Xxcxdsaa7slcskxsdl7.exe"Added by the ONLINEG-K TROJAN!"
XxSafexSafe.exe"Added by the SILLYFDC.BAY WORM!"
UXTNDConnect PC - CasioOrgCasAgnt.exe"Casio Pocket PC specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts
UXTNDConnect PC - LtNts4NtsAgnt.exe"(IBM) Lotus Notes 4 specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts
?XWMSUSBAPIXWMSAPI.EXE"Part of the installation of a Xerox WorkCentre printer/scanner. Is it required?"
Xy1959sarsv711224030r.exe"Added by the BRONTOK-AK WORM and variants!"
Xy1959saryesbron.com"Added by the BRONTOK-AK WORM and variants!"
XYa SalamNancyAjram.exe"Added by the JALABED WORM!"
XYahoo! Messangerymsngr32.exe"Added by the WOOTBOT.HY WORM! Note - this should not be confused with Yahoo! Messenger"
Xyay.exeasass.exe"Added by the AGOBOT-M WORM!"
NYeppStudioAgentSamsungMediaStudioAgent.exe"Samsung Media Studio MP3 player file management software - see here for an example"
UYou've Got Pictures Screensaverygpsstra.exeAOL You've Got Pictures Screensaver
XYourMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XZangoSAZangoSA.exe"Zango Search Assistant adware"
XZincgrubIncLsass.exe"Added by the VOUMIT-A WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\mirc32"
X[random]lsass.scr"Added by the BANCBAN-CW TROJAN!"
X[various names]msag.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]SAPSTR.exe"Wareout - malware masquerading as a spyware and dialer remover"
Y_AntiSpywaremasalert.exe"Part of McAfee AntiSpyware"
X{2C70168B-97CE-4f31-B85D-1FEC5002721D}sysavxjgdu.exe"Added by the FAKEALERT-AM TROJAN!"
X{2C70168B-97CE-4f31-B85D-1FEC5002721D}sysawpbkvnq.exe"Added by the FAKEALERT-AH TROJAN!"
X{7DD4A7AC-A3F1-4495-884A-7947C5B89108}sysahbecjh.exe"Added by the FAKEALERT-AM TROJAN!"
X{9754B85A-3B34-4969-BE1F-CD03227E9470}sysatjsicj.exe"Added by the FAKEALERT-AM TROJAN!"
X{BAAA759D-56F0-428c-B8DA-827EA3B08C2C}sysawechod.exe"Added by the FAKEALERT-AH TROJAN!"
X{DD651081-A909-45ad-BD71-2335B0ADE043}sysabmpmfr.exe"Added by the FAKEALERT-AH TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.