Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X.nvsvcsmss.exe"Added by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
X.nvsvcbsmssb.exe"Added by the BOXED.CG TROJAN!"
XAdobeReaderProssysmsn.exe"Added by the RBOT-BGH WORM!"
Xafmsmsgsafmsmsgs.exe"Added by the DLOADR-CUX TROJAN!"
XAntiVirsmss.exe"Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%"
UAntiWindowsMessengerAntiMsMsg.exe"Anti-Windows_Messenger is a small application that prevents Windows Messenger from remaining resident in memory"
XApplicationProtocolRunsmsbvl32.exe"Added by the IRCBOT-CX TROJAN!"
XAudoi Device Loadersmssv.exe"Added by the AGOBOT-ZY WORM!"
XAutoUpdatesmss.exe"Added by WINSPY.88! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64"
Nbgsmsndbgsmsnd.exePrinter driver to generate PDF files from any program
XcmssSystemProcesscsmss.exe"Added by the AGENT-CO TROJAN!"
XcmssSystemProcessmcsmss.exe"Added by the PROXYSER-F TROJAN!"
XcmssSystemProcesscsms.exe"Added by the AGENT-Y TROJAN!"
XConfiguration Loadersmss32.exe"Added by the AGOBOT.MB WORM!"
XConfiguration Loadersmsai.exe"Added by the SDBOT-YE WORM!"
XConnectorsms.EXE"Added by the ExDial-B premium rate adult content dialer"
XControlServiceMgrcsmsv.exe"Added by the AGENT-XC TROJAN!"
Xcsrssmsmsgs.exe"Added by the CHODE-J BACKDOOR! Note - this malware uses MSN Messenger (which is located in %Program Files%\Messenger) in the background to propogate itself"
Xcsrssssms.exeAdded by an unidentified malware
XDebugSMSS.exe"DreamAd adware. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XDHCPsmss.exe"Added by the WINSPY.AG TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\display"
XDsmSerdsm.exe"Added by the SERFLOG.B WORM!"
XDsmSermsmpatch.exe"Added by the SERFLOG.B WORM!"
XDsmSersvosm.exe"Added by the SERFLOG.B WORM!"
XDsmSersysup.exe"Added by the SERFLOG.B WORM!"
XEventApplicationCmdsmschk.exe"Added by the IRCBOT-AO TROJAN!"
XFireFox Service Driversssmss.exe"Added by a variant of the SDBOT WORM!"
XGLSetT32smsiexec.exe"Added by the OPTIX-D TROJAN!"
XGraphic Driversmss32.exe"Added by a variant of the RBOT WORM!"
XIE6ssmss.exe"Added by the GAOBOT.DXO WORM!"
Xinfosmss.exe"Added by the VB.EIW WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\inetsrv"
XIntec Service Driversmsmsgrs.exe"Added by the SDBOT-ADN WORM!"
XIntec Service Driversmsmsgredss.exe"Added by the SDBOT-AGL WORM!"
XInteliSyssmss.exe"Advertisingvision adware. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xinternetsmss.exe"Added by the MIFENG-K TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
XKernel Safe Modesmss.exe"Added by the 78CRACK-A TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XKernelFaultChksms.exe"Added by the DEADHAT WORM! Do not confuse with the valid ""kernelfaultcheck"" which runs ""dumprep 0 -k"" or ""dumprep 0 -u"""
XKernellApps32smss.exe"Added by the BANCBAN-AN TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
XLiveUpdatesmss.exe"Added by the VB.BAU BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas"
XloadMefssmss32.exe"Added by the FLOOD-EL TROJAN!"
Xlsmss.exelsmss.exe"Added by the PROXY-GG TROJAN!"
XLTSMSGShell32.exe"Added by the LEMIR.B TROJAN!"
Xmackfy.exemsms.exe"Added by the SDBOT-DID WORM!"
XManageProtocolCtrlcsmsv.exe"Added by the LOOKSKY.B TROJAN!"
UMDSA Sentinel Xsmss.exe"SentinelX surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the smss.exe process which is always located in %System%. This one is located in %ProgramFiles%\MDSA Software"
NMessengermsmsgs.exe"Windows Messenger instant messenger utility included with Windows 2K/XP. Available via the Start menu. Go to Windows Messenger → Tools → Options → Preferences and uncheck ""Run this program when Windows starts"""
XMessenger Servicemsmsgs.exe"Added by the SDBOT-ZB WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMicrosoftssmss.exe"Added by the RBOT-FZF WORM!"
XMicrosoftmsmsger.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft (R) Windows Network Security Management Servicensms.exe"Added by the RANKY.LC TROJAN!"
XMicrosoft CSRSS Servicensmscrs.exe"Added by the RBOT-BPT WORM!"
XMicrosoft Excelemsmsgs.exe"Added by the AGENT.AJQG TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMicrosoft Internet ServicesSmss32.exe"Added by the RBOT.MS WORM!"
XMicrosoft Messenger Servicemsmsg32.exe"Added by the RBOT.BOK WORM!"
XMicrosoft Messenger XPMSMSN32.exe"Added by the RBOT-ZP WORM!"
XMicrosoft Msn Messengermsmsgs.exe"Added by the BUZUS.AYX TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMicrosoft OfficeMSMSGR.exe"Added by the GAOBOT.BB WORM!"
XMicrosoft Officemsmsgr.exe"Added by the GAOBOT.BB WORM!"
XMicrosoft Ofticemsmsgs.exe"Added by the IRCBOT.ALT WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMicrosoft ServicesSmss32.exe"Added by the RBOT-AD WORM!"
XMicrosoft Session Manager Subsystemsmss.exe"Added by the KALEL-D WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
XMicroSoft sys32sysmsgr32.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft System Firewall 2006.2msmsgr.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft System Servicesmsmsgr.exe"Added by the RBOT-ZH WORM!"
XMicrosoft UpdateSmss32.exe"Added by the RBOT-CB WORM!"
XMicrosoft Update Machinepsmszw.exe"Added by the KOLABC.CC WORM!"
XMicrosoft Virual Machinesms.exe"Added by the RBOT-SP WORM!"
XMicrosoft Windows Session Manager Subsystemsmss.exe"Added by the PROXYSER-R TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMS MSN Menssenger 7.0MSMSN7.exe"Added by the RBOT-ACA WORM!"
Xmsmautoprotectmsmssgs.exe"Added by the BIFROSE-AJ TROJAN!"
XMSMSGNER[4-8 random letters].exe"Added by the FOWLDO-GEN TROJAN!"
XMSMSGNERzzgf.exe"Added by the PWS-CCB TROJAN!"
XMSMSGNERfgozmox.exe"Added by the AGENT-EBJ BACKDOOR!"
Xmsmsgrmsmsgss.exe"Detected by Kaspersky as the RBOT.AJJ WORM!"
NMSMSGSmsmsgs.exe"Windows Messenger instant messenger utility included with Windows 2K/XP. Available via the Start menu. Go to Windows Messenger → Tools → Options → Preferences and uncheck ""Run this program when Windows starts"""
XMsmsgsMsmsgs.exe"Added by the SILLYFDC-AP WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMSMsgsmsmessgs.exe"Added by the SMALL-EW TROJAN!"
Xmsmsgsmsmsgs.exe"Added by the SCLOG-AL TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMSMSGSwinlogon.exe"Added by the BRONTOK-BS WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
Xmsmsgs.exeIEXPLORE.EXE"Added by the VB.FQX TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMsMsgSrvmsmsgsrv.exe"Added by the CQO TROJAN!"
Xmsmsgss[path to trojan]"Added by the RANKY.G BACKDOOR!"
XMSMsgSvcMSMSGSVC.exe"Browser hijacker
Xmsmsngrmsmsngr.exe"Added by the DOPBOT-B WORM!"
XMSNsmsss.exe"Added by the BUZUS-D WORM!"
XMSN Configuration Loadermsmsncfg.exe"Added by the AGOBOT-KX BACKDOOR!"
XMSN MessengerReosmsngr.exe"Added by a variant of the SPYBOT WORM!"
XMSN Messengermsmsgs.exe"Added by the ZLOB TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMSN Messenger User Controlsmsmsgr.exe"Added by the KELVIR.HI WORM!"
XMSN Servmsmsnserv.exe"Added by the IRCBOT.AVF BACKDOOR!"
XMSN Servermsmsnserver.exe"Added by the IRCBOT.AUS BACKDOOR!"
XMsn Update Manager (Sp2)MSMSGS.EXE"Added by the AGOBOT-NL WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
Xmssoulmsmscc2.exe"Added by the DAPIZL.A banker WORM! (A ""banker worm"" is designed to pillage banking information and send it back to the perpetrators!)"
Xmssoulmsmscc.exe"Added by the BANCOS.HKT TROJAN!"
Xmssyslanhelpermsmsgri32.exe"Added by the RANDEX.D WORM!"
XMsWindows SysDatesysmsvc.exe"Added by the SPYBOT.FCD WORM!"
XMULTIMEDIA KEYBOARD88smss.exe"Added by the SILLYFDC WORM! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
XMy AppSMSSvc.exe"Added by the NEGASMS.A TROJAN!"
XNarmonVirusAntismss.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
Xnotepad.exemsmsgs.exe"Added by the ZLOB TROJAN and variants! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XNvCplDaemonmsmsgrs.exe"Added by the DLOADER-YI TROJAN!"
UPRISMSTA.EXEPRISMSTA.EXECreates a system tray icon for accessing information about Intersil Prism Wireless Settings. Intersil silicon is used by Trendware/Trendnet for example
UPRISMSVRPRISMSVR.EXEConfiguration and settings utility for PRISM chipset based wireless modems such as the 2Wire Wireless Gateway (2701HG) and Siemens Gigaset USB Adapter
UPRISMSVR.EXEPRISMSVR.EXEConfiguration and settings utility for PRISM chipset based wireless modems such as the 2Wire Wireless Gateway (2701HG) and Siemens Gigaset USB Adapter
XRegSvr32msmsgs.exe"Added by the ZLOB.B TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XRemote Event Systemresmsvc.exe"Added by the IRCBOT.YF BACKDOOR!"
XRemove 54tr10smss.exe"Added by the BRONTOK-CH WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data"
Yrun=smsrun16.exe"Microsoft Systems Management Server (SMS) related - program that reads SMSRUN16.INI on clients running Win 3.1
XRunOnceExsms.exeIESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!
XScan Registerssms.exe"Added by the RBOT-AT WORM!"
XSchedulerMSMSGS.EXE"Added by the HOSTBANK-A TROJAN! Note - this particular msmsgs.exe file is located in %System%\Config and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XService Processsmss.exe"Added by the DCMBOT-E TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""config"" subfolder"
XServices Processsmss.exe"Added by the SMALL-EK TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""config"" subfolder"
XServices.dllsmss.exe"Added by the SOBER-L WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\system and note the space at the beginning of the ""Startup Item"" field"
XSession Manager Subsystemsmssa.exe"Added by the RBOT-AGS WORM!"
XShellsmsc.exe"Added by the BANCBAN-OY TROJAN!"
XShellExplorer.exe smssnt.exe"Added by the AGOBOT.EE TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""smssnt.exe"" file is located in %System%"
XSMSiro.bat"Added by the IROFFER.CT TROJAN!"
USMS Application LauncherLAUNCH32.EXE"Microsoft Systems Management Server - used to manage computers on a network remotely"
USMS Client Serviceclisvc95.exe"When the SMS Client service starts on a domain controller
XSms System32SmsSystem32.exeUnidentified malware
USMS Win9x Message AgentSMSMsg.exeThis program assigns a user to a Systems Management Server site
NSmsDiscountSmsDiscount.exe"SmsDiscount - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
NSmserialsm56hlpr.exeHelper utility for Motorola based SM56 software modems - resides in the System Tray
XSMSERIALSTARTERwin32st.exe"Added by the FAKEALERT-AH TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
XSMSERIALWORKERSTARTshellexcon.exe"Added by the FAKEALERT-AH TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
XSMSERIALWORKERSTARTERwinstrse.exe"Added by the RENOS.IC TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
XSMSERIALWORKSTARTERcomsysobj.exe"Added by the FAKEALERT-AH TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
XsmsgerWin.exe"Added by a variant of the SDBOT WORM!"
NSMSI LoaderSMLoader.exe"Smith Micro HotFax - fax software"
Xsmsmsmsm.exe"Added by the BANKER-CO TROJAN!"
Xsmsrvsmsrv.exe"Added by the AGOBOT-SX WORM!"
XSMSSsmss.exe"Added by the FLOOD.F BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Catroot"" subfolder"
Xsmss[path to smss.exe]"Added by the ALADINZ.F TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
Xsmsssmss.exe"Added by the AGENT-TR TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsmsssmss.exe"Added by the BOROBOT-J TROJAN and variants! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
XSmssssms.exe"Added by the RBOT.OP WORM!"
XSmss Hostsmhost.exe"Added by the IRCBOT-ACC TROJAN!"
Xsmss.execsrss.exe"Added by the DALBUG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSmss.exe driverwinupd32.exe"Added by the SDBOT.MI BACKDOOR!"
Xsmss32.exesmss32.exe"Added by the FAKEAV-ATH TROJAN!"
XsmssLevel4smss.exe"Unidentified malware! ! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Windows Media Player\Skins\WindowsMediaSkin\Data\Level4"
XSMSSSsmsss.exe"Added by the SDBOT.ZD WORM!"
XSMSSS Loadersmsss.exe"Added by the AGOBOT.MQ WORM!"
XSMSSUSMSSU.EXE"Added by the STARTPAGE.O TROJAN!"
USMSTraySMSTray.exeSystem tray access to Samsung Media Studio
XSMSvc32smsvc32.exe"Added by the AGOBOT-OL WORM!"
XsmsysExplorer.exe"Added by the CLICKER-C BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in a ""Template"" subfolder"
Xsmsysvi.exeAdult content dialler
USMSystemAnalyzerSMSystemAnalyzer.exe"Part of the Iolo System Mechanic optimization tool"
Xsms_msnsms_msn.exeAdded by an unknown WORM or TROJAN!
Xsms_msn40sms_msn40.exeAdded by an unknown WORM or TROJAN infection
XSonic RecordNow!smsc.exe"Added by a variant of the SDBOT WORM!"
XSpooler Subsystem Applicationsmss.exe"Added by the IRCBOT-ZO TROJAN! Note - the legitimate smss.exe process should not normally figure in Msconfig/Startup!"
Xspoolsvr32csmss.exe"Added by the AGENT-AU TROJAN!"
Xspoolsvr32csmss32.exe"Added by a variant of the AGENT-AU TROJAN!"
Xssms.exeSSMS.EXE"Added by the GISMOR WORM!"
Xssms.exewinn.exe"Added by the SDBOT-DHE WORM!"
Xssmssssmss.exe"Added by the AGENT-MOF TROJAN!"
Xstart uploadingsmsss.exe"Added by a variant of the SDBOT WORM!"
Xsysmsssysems.exe"Added by a variant of the SLAPER TROJAN!"
XSystemsmss.exe"Added by the AGENT.EP BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem Config Managersmssl.exe"Added by the AGOBOT-ZJ WORM!"
XSystem Initializationmsmsgri32.exe"Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS!"
XSystem Management Servicesmsc.exe"Added by the RBOT-ANN WORM!"
XSystem MessengerSYSMSG32.EXE"Added by the SPYBOT-DK WORM!"
XSystem Servicesssms.exe"Added by a variant of the RBOT WORM!"
XSystem Session Managersmss.exe"Added by the KALEL-E WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
XSystesms.exesystesms.exe"Added by the RBOT-HI WORM!"
XSysUtilssmss.exe"Added by the AUTORUN-AWW WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
XTok-Cirrhatussmss.exe"Added by the BRONTOK-A WORM and variants! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%"
XTok-Cirrhatus-2784smss.exe"Added by the BRONTOK-S WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%"
XTorjan Programsmss.exe"Added by the WOWCRAFT.B TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NTSMsgerTSMsger.exe"Epson scannner software - required for ""one-touch"" operation. Can be launched manually"
XUsbDsmss32.exe"Adware - detected by Kaspersky as the AGENT.CJ TROJAN!"
Xuserinitsmss.exe"Added by the DLOADR-B TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XVirscannersmss.exe"Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xvssms32vssms32.exe"Added by the BCKDR-LBF BACKDOOR!"
XWin32 USB2 Driversmsc.exe"Added by the SDBOT.FO WORM!"
XWinDLL (csmss.exe)"rundll32.exe CSMSS.EXEstart"
XWindowssmss.exe"Added by the BANCBAN-QF TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows bypass security SMSS ServiceSbiCvy.exe"Added by the RBOT-GRF WORM!"
XWindows Driversssms.exe"Added by the RBOT-AT WORM!"
XWindows Media Centersmss.exe"Added by the WARBOT TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Messenger Live Startupwindowsmsnlive.exe"Added by the DELF.DAX TROJAN!"
XWindows Messenger Servicewinsmsgr.exe"Added by the RBOT-VW WORM!"
XWindows Rundll Centermsmsgrs.exe"Added by the IRCBOT-AFA WORM!"
XWindows Secure Servicesssms.exe"Added by the RBOT-GAR WORM!"
XWindows Servicessmsc.exe"Added by a variant of the SDBOT WORM!"
XWindows Session Managersmss32.exe"Added by a variant of the RBOT WORM!"
XWindows Session Manager Subsystemsmss.exe"Added by the KALEL-B WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
XWindows smss serviceservice.exe"Added by the AGENT-FPY TROJAN!"
XWINDOWS SYSTEMsmsc.exe"Added by the MYTOB-BR WORM!"
XWindows System Managersmsc.exe"Added by a variant of the RBOT WORM!"
XWindows System Manager Loadersmsls.exe"Added by the AGOBOT.TF WORM!"
XWindows UDP Control Centermsnsmsgrs.exe"Added by the PUSHBOT.MF WORM!"
XWindows Updatesmsscr.exe"Added by the BANKER-DK TROJAN!"
XWindows32 Messenger Servicemsmsgv.exe"Added by the RBOT.ANS WORM!"
XWinDOwsUPdatesmss.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
XWinsSystemsyssmss.exe"Added by the DELF.IG TROJAN!"
Xwinsystem.syssmss.exe"Added by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\win32 and note the space at the beginning of the ""Startup Item"" field"
XWINTASK DLL32smsrss.exe"Added by the MYTOB.BS WORM!"
XWSSVCsmsc.exe"Added by the AUTORUN-AGA WORM!"
XYhooUapdatesymssmsgs.exe"Added by a variant of the SMALL_K TROJAN!"
XYhooUpdatesymsmsgs.exe"Added by the SMALL_K TROJAN!"
Xzsmssmss.exe"Added by the BANCOS-CK TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xzsmsccrundll32.exe zsmscc071001.dll mymain"Added by the GENETIK.KQ TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""zsmscc071001.dll"" file is found in %System%"
Xzsmsccrundll32.exe mycc071208.dll mymain"Added by the AGENT.FZK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""mycc071208.dll"" file is found in %System%"
Xzsmsgsiservice.exe"Added by the BANCOS-BU TROJAN!"
Xzsmsssmss.exe"Added by the BANCOS-DD TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X_Cat3msmsgrxp.exe"Added by a variant of the SMALL-DT downloader TROJAN"
X_Cat4msmsgr2.exe"Added by the SMALL-EB TROJAN!"
X_Services.dllsmss.exe"Added by the SOBER-L WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\system"
X_winsystem.syssmss.exe"Added by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\win32"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.