Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X(Default)llsass.exe"Added by the PROXY-GG TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X-=+(L4r1$$4)+=-(4nt1)-=+(V1ru$)=-+ISASS.exe"Added by the ASSIRAL.B WORM!"
X.nvsvcsmss.exe"Added by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
X.svchostCSRSS.EXE"Added by the WEBUS.F TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X.TEXTCONVcsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
X.TEXTCONVlsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
X.WMAudiocsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
X.WMAudiolsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XAASSKK2LSASS.EXE"Added by the SILLYFDC.BDB WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%"
Xabassabass.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
XActiveXUpdatesvcss.exe"Added by a variant of the DEDLER.C TROJAN!"
XAddClassAddClass.exe"CoolWebSearch Addclass parasite variant"
XaDiradirss.exe"Added by the SPAMSRV-E TROJAN!"
XAdobeReaderProspoolss.exe"Added by the SDBOT-AKZ WORM!"
XAdRotator.Application[path to csrss.exe]"Added by the SMALL-AQ TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
YADSSADSS.exe"ADSS is part of Access Denied security and privacy software (Access Denied Security Server) that monitors power status and provides some other services for Screen Guard. Important to keep its running while using Access Denied"
UALPassALPass.exe"ALPass password manager"
Xanimalssanimalss.exe"Added by the AGOBOT-VE WORM!"
XAntiIsass.exe"Added by the BROPIA.K WORM!"
XAntiVirsmss.exe"Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%"
XApplicationcsrss.exe"Added by the BEAGLE.EG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XASDPLUGINdsldbaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINdbaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINdslgeaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINgeaccess.exe"AsdPlug premium rate adult content dialer"
Xashcapservirsess.exe"SpySure spyware"
XASP.NET State Servicecsrss.exe"Added by the DLOADER-QI TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XASP.NET State Servicecrsass.exe"Added by the BANLOAD-M TROJAN!"
UAtiSoundcsrss.exe"WinSpy surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""ComRoot"" subfolder"
XAuto CD-ROM Startupcdaccess.exe"Added by the SPYBOT.BLA WORM!"
XAuto updatcrcss.exe"Added by the SDBOT.AAG WORM!"
XAutoUpdatesmss.exe"Added by WINSPY.88! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64"
XAVManagercsrss.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XBagleAVcsrss.exe"Added by the NETSKY.AB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
YBitDefender Scan Serverbdss.exe"BitDefender antivirus"
Xblssblss.exe"Added by the BLARUL TROJAN!"
XBuildLabscsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XBuildLabslsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XccpAppscsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XccpAppslsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
Xcdoosoftherss.exe"Added by the SILLYFDC.BCT WORM!"
XClickTheButtoncsrss.exe"ClickTheButton adware. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XClient Server Runtime Processcsrsss.exe"Added by the SDBOT-LD WORM!"
XClient Server Runtime Processsmmss.exe"Backdoor TROJAN! Possible SDBOT-GEN variant"
Xcmrsscmrss.exe"Added by the DELF.DU TROJAN!"
Xcmrsscrmss.exe"Added by the DLOADER-EK TROJAN!"
XcmssSystemProcesscsmss.exe"Added by the AGENT-CO TROJAN!"
XcmssSystemProcessmcsmss.exe"Added by the PROXYSER-F TROJAN!"
XConfiguration Loaderlfass.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration LoaderServicess.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadermsnss.exe"Added by the GAOBOT.AUS WORM!"
XConfiguration Loaderbotss.exe"Added by the SDBOT-XS WORM!"
XConfiguration Loadercrcss.exe"Added by the AGOBOT.ADG WORM!"
XConsole de Gerenciamento Microsoftcsrss.exe"Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Level4"" subfolder"
XConsole de Gerenciamento Microsoftcsrss.exe"Added by the BANCBAN-ET TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Central de Segurança"" subfolder"
XContent List Management Subsystemclmss.exe"Added by the SPYBOT-EL WORM!"
XControlled Resource System Servicecrss.exe"Added by the AGOBOT.GH WORM!"
Xcpntmgcsimcss.exe"Added by the MAGICON.A TROJAN!"
Ucpqnscpqnpcss.exeRelated to Compaq.Net - not required if you don't use that
XCRC Value Verifiercrsss.exe"Added by the SPYBOT.UK WORM!"
XCRCSScrcss.exe"Added by the IRCBOT-TH WORM!"
XCRSSCRSS.exe"Added by the AGOBOT-RM WORM!"
Xcrssscrsss.exe"Added by the AUTORUN.FM WORM!"
XCSNetManagerXpisass.exe"Added by the HIDER-O TROJAN!"
XCSRSSCSRSS.EXE"Search page hijacker
XCsrsscsrss.exe"Added by the CHOD WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a random subfolder"
Xcsrsscsrss.exe"Added by the KEYLOG-AQ KEYLOGGER! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xcsrsscsrss.exe"Added by the CHODE-J WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a random subfolder"
Ucsrsscsrss.exe"BeyondKeylog surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Supremtec"
XCsrssCSRSS.EXE"Added by the PUNYA-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Documents and Settings\Administrator\Local Settings\Application Data\WINDOWS"
XCSRSS Loadercsrsss.exe"Added by the AGOBOT.TX WORM!"
Xcsrss.execsrss.exe"Added by the DALBUG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XcsrssLevel4csrss.exe"Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Level4"" subfolder"
Xcsrvsscsrvss.exe"Added by a variant of the SDBOT TROJAN!"
Xcssrss.execssrss.exe"Malware installed by different rogue security software including SpyKillerPro"
XcsssCsss.exe"Added by the BALICK TROJAN!"
XCTFMONSSCTFMONSS.EXE"Added by the CWS-F TROJAN!"
Xctfnom.exeOSRSS.exe"Added by the DLOADER-UQ TROJAN!"
Xcvmsyslpdsdservss.exe"Added by the MAILBOT-BY TROJAN!"
XDebugSMSS.exe"DreamAd adware. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xdevenvsmvss.exe"Added by the DEDLER-G TROJAN!"
XDHCPsmss.exe"Added by the WINSPY.AG TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\display"
XDIECOXcsrss.exe"Added by a variant of the ATM.GEN TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
Xdlcipscldcpavss.exe"Added by the MAILBOT-CB TROJAN!"
Xdsgblcsass.exe"Added by the AGENT.TGZ BACKDOOR!"
XDSServicedmrss.exe"Added by the AGOBOT-XX WORM!"
NDVD@ccessDVDAccess.exe"Part of DVD Studio Pro from Apple Inc. - ""The DVD@CCESS feature allows you to add additional interactivity to your DVD title when it is played on a computer"""
XEDxMC110Isass.exe"Added by the VB-NIA WORM!"
Xethernet adaptercsrmss.exe"Added by a variant of the RBOT WORM!"
XExplorer.execsrss.exe"Added by the JUEGO-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft"
Xffeqfqsdqddss.exe"Added by the SDBOT-SG WORM!"
XFiendlyTypecsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XFireFox Service Driversssmss.exe"Added by a variant of the SDBOT WORM!"
XFirewallActiviescsrss.exe"Added by the BANKER-AQ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""3041"" subfolder"
XFriendlyTypelsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
NFSCBossFSCBoss.exeFree Store Club shop online software
UGhostSecuritySuitegss.exe"Ghost Security Suite - protect the registry from unauthorized reading and modification and other tools"
XGLSetIT32isass.exe"Added by a variant of the OPTIX PRO TROJAN!"
Uhksshkss.exeCompaq HotKey Support - multimedia keyboard support
XHot_KissHot_Kiss.exeAdult content dialler
XIE6ssmss.exe"Added by the GAOBOT.DXO WORM!"
Xilassslsass.exe"Added by the INJECT-GZ TROJAN! Note - the legitimate lsass.exe process should not normally figure in Msconfig/Startup!"
Xinfosmss.exe"Added by the VB.EIW WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\inetsrv"
XIntec Service Driversmsmsgredss.exe"Added by the SDBOT-AGL WORM!"
XInteliSyssmss.exe"Advertisingvision adware. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xinternetsmss.exe"Added by the MIFENG-K TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
Xinternetlsass.exe"Added by the DSPY-A TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XIPv6 Helper Drivercsass.exe"Added by the AGOBOT.TC WORM!"
XIsassIsass.exe"Added by the FUTRO TROJAN!"
XKernel Safe Modesmss.exe"Added by the 78CRACK-A TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XKernellAppscsrss.exe"Added by the BANCBAN-AC TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""System"" subfolder"
XKernellApps32smss.exe"Added by the BANCBAN-AN TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
XKey Loggercsrss.exe"Added by the BUCHON.A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root folder (ie
XKeyboardlsass.exe"Added by the AGENT.US WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %CommonAppData%\Fearghus"
XKiamat Sudah Dekat_16_04ISASS.exe"Added by the PAHATIA.B WORM!"
XKL AntiFunLoveflcss.exe"Added by the FUNLOVE.4099 VIRUS!"
XKrnlcheckcsrss.exe"Added by the BOTNACHALA TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XLarLlass.exe"Added by the INOR-A TROJAN!"
XLcassLcass.exe"Added by the SILLYFDC-W WORM!"
XLexmark_X79-55lsasss.exe"Added by the ZONEBAC TROJAN!"
NLG MagnifierMagnifyingGlass.exe"Screen area magnifying utility for LG Notebooks"
XLinkSafenessLinkSafeness.exe"LinkSafeness rogue security software - not recommended
XLive Security SuiteLiveSS.exe"Live Security Suite rogue security software - not recommended
XLiveUpdatesmss.exe"Added by the VB.BAU BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas"
XLocal Authority Servicelsass.exe"Added by the MARKTMAN-C TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XLocal Security Authority ServiceIsass.exe"Added by the LINKBOT.M WORM!"
XLogonCSRSS.EXE"Added by the BRONTOK-BH WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
XLogonAdministratorCSRSS.EXE"Added by the KORRON.B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
XLogonrepclient1CSRSS.EXE"Added by the BRONTOK-BT WORM and variants! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
XLogonsaracsrss.exe"Added by the BRONTOK-BS WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
XLogServicelsass.exe"Added by the BDOOR-IU BACKDOOR! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XLogServicelsrss.exe"Added by the PAPROXY-D TROJAN!"
XLSA ServiceLSASS.exe"Added by the AHKER.G WORM! Note - this is not the legitimate lsass.exe process
XLSA Shell (Export Version)LSASS.exe"Added by the AHKER.K WORM and variants. Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XLSA Shellulsass.exe"Added by the AUTORUN-CW WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
XLSAShelllsass.exe"Added by the DAPROSY WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xlsasslsass.exe"Added by the RATSOU.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Debug\UserMode"
Xlsass[path to lsass.exe]"Added by the ALADINZ.F TROJAN! Note - this is not the legitimate lasss.exe process which should NOT appear in Msconfig/Startup!"
XLsassLsass.exe"Added by the ALCOP-B WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XLsassLsass.exe"Added by the VOUMIT-A WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\mirc32"
XLsassLSASS.EXE"Added by the PUNYA-B WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%"
Xlsassslsasss.exe"Added by the GEEKMY-A TROJAN!"
Xlsasss.exelsasss.exe"Added by the SASSER.E WORM!"
Xlsesslsess.exe"Added by the SINNAKA.A WORM!"
Xlsmasslsmass.exe"Added by the WALLOP-B TROJAN!"
Xlsmss.exelsmss.exe"Added by the PROXY-GG TROJAN!"
XMatrixScreenSavermss.exeUnidentified malware
UMDSA Sentinel Xsmss.exe"SentinelX surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the smss.exe process which is always located in %System%. This one is located in %ProgramFiles%\MDSA Software"
XMedia PassMediaPass.exe"WindUpdates MediaPass adware"
XMicrosoftssmss.exe"Added by the RBOT-FZF WORM!"
XMicrosoft Authority Servicelsass.exe"Added by the KALEL-D WORM! Note - this is not the legitimate lsass.exe process
XMicrosoft Hosts ServiceIsass.exe"Added by a variant of the RBOT WORM!"
XMicroSoft IE SasserISASS.EXE"Added by the SDBOT.MX WORM!"
XMicrosoft Lsass CenterIsass.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Lsass Managerlsass.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate lsass.exe process
XMicroSoft Remote Secure ServiceMSRSS.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Server Applacationslsasss.exe"Added by the RBOT-AQQ WORM!"
Xmicrosoft server baselass.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Service Access ManagerAccess.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Session Manager Subsystemsmss.exe"Added by the KALEL-D WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
XMicrosoft softwarecdaccess.exe"Added by the RBOT.ABK WORM!"
XMicrosoft System Restore ConfigurationCBRSS.EXE"Added by a variant of the SPYBOT WORM!"
XMicrosoft Updatecmss.exe"Added by the RBOT-ATQ WORM!"
XMicrosoft Update Machinelmrss.exe"Added by the RBOT-DY WORM!"
XMicrosoft Update Machinewinss.exe"Added by the RBOT.JU WORM!"
XMicrosoft UPDATER32lsass.exe"Added by the RANDEX.AR WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!"
XMicrosoft USB2 Drivercrmss.exe"Added by the RBOT-VK WORM!"
XMicrosoft Windows CSRSScsrss.exe"Added by the KALEL-A WORM! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XMicrosoft Windows Session Manager Subsystemsmss.exe"Added by the PROXYSER-R TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Windows Update Clientcsrss.exe"Added by the KEBEDE-G WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Systems32"
XMicrosoft Windows WinSaSS Managementwinsass.exe"Added by the RBOT-APW WORM!"
XMicrosoft Word Profissionalcsrss.exe"Added by the BANCBAN-DB TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""s1613"" subfolder"
XMicrosoft Word Profissionalcsrss.exe"Added by the BANKER-DJ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""protect"" subfolder"
XMicrosoft Word Profissionalcsrss.exe"Added by the BANKER-DP TROJAN! ! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""JavaVM"" subfolder"
XMicrosoftOEMsmvss.exe"Added by the DEDLER-G TROJAN!"
XMicrosoftROMDriverServicecdrss.exe"Added by the IRCBOT.BLF BACKDOOR!"
XMicrosofts Updateslsasss.exe"Added by the RBOT-AEX WORM!"
XMicrosoftSourceSafecsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XMicrosoftSourceSafelsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XMicrost dds servicewsrss.exeAdded by an unidentified WORM or TROJAN!
NMoney Expressmoneyexpress.exePart of MS Money. Available via Start -> Programs
NMoneyAgentmoney express.exePart of MS Money. Available via Start -> Programs
XMS Security Authority Servicelsass.exe"Added by the KALEL-B WORM! Note - this is not the legitimate lsass.exe process
XMSControl28crsss.exe"Added by the SPYBOT.AJX WORM!"
Xmsgserv_Syss.exe"Added by the FANTA TROJAN!"
XMSInstallsmvss.exe"Added by the DEDLER-G TROJAN!"
Xmsmsgrmsmsgss.exe"Detected by Kaspersky as the RBOT.AJJ WORM!"
XMSNwdlrss.exe"Added by a variant of the SDBOT TROJAN!"
XMSNsmsss.exe"Added by the BUZUS-D WORM!"
XMSN angcssrss.exe"Added by the FORBOT-CE WORM!"
XMSN Managercvss.exe"Added by a variant of the SPYBOT WORM!"
XMsn Messangercrsss.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMsnmsgr.exelsass.exe"Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root directory (i.e. C:\ or D:\)"
XMSOleath32winss.exe"Added by the KATHER TROJAN!"
Xmsvssmsvss.exe"Added by a variant of the RBOT WORM!"
XMULTIMEDIA KEYBOARD88smss.exe"Added by the SILLYFDC WORM! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
XNarmonVirusAntismss.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XNAV Auto UpdateSadness.exe"Added by the SPYBOT-E WORM!"
XNavPassNavPass.exeFree system for gaining access to and downloading from adult content web-sites
XNDAvcsnss.exe"Added by the SERFLOG.C WORM!"
XNetManagerServicentss.exe"Added by the BESTPICS.A TROJAN!"
XNetwork Translation System Servicentss.exe"Added by the UNPDOOR TROJAN!"
XNorton Protect Activiescsrss.exe"Added by the BANKER-CZ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""D5133"" subfolder"
XNortonAntivirusLSASS.exe"Added by the PEXMOR WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Temp"
XNT Printing Servicechkdskss.exe"Added by the ARCHIVARIUS series of WORMS!"
XNT Windows System Manager Loadercsrlss.exe"Added by the AGOBOT.OX WORM!"
XNTDLMcsrss.exe"Added by the HALE TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Qossrv"" subfolder"
XNTFSS MICROSOFT SYSTEMfiless.exe"Added by the RBOT.AXZ WORM!"
XNviDiaGTlsass.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XNvMsnWIsass.exe"Added by the BROPIA.K WORM!"
XOfficeGuardUIsvcss.exe"Added by the DEDLER-C TROJAN!"
UOnlinePCfix SmoothSurferSS.exe"Smooth-Surfer - blocks banners
XOutlook Mail Servicesexpress.exe"Added by the RBOT.CJN WORM!"
XPatah HatiISASS.exe"Added by the PAHATIA.A WORM!"
XPCprotcrcss.exeAdded by an unidentified WORM!
UPower2GoExpressPower2GoExpress.exe"Power2GoExpress - all media disc burning software"
Xprinter spoolercommonaccess.exe"Added by the DELF-LB TROJAN!"
XPrinter Spooler Subsystemspoolss.exe"Added by a variant of the RBOT WORM! Note - this is not the legitimate Windows spoolss.exe process which is always located in %System% and should not figure in Msconfig/Startup!"
UPrintSpoolerlass.exe"Win-Spy keystroke logger/monitoring program - remove unless you installed it yourself!"
UPro PCL Status MonitorPENGSS.EXEXerox printer/fax/copier status monitor (PCL = printer control language)
XProcaprocess.exe"Added by the MOVINGMOUSE.475811 TROJAN!"
Xprocess.exeprocess.exe"Added by the BANCOS.P TROJAN!"
XProgcsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XProglsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XQQsendmess.exe"Added by the SEMES TROJAN!"
XRegDone Excsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XRegDoneExlsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XRegWritecsrss.exe"Added by the SOKACAPS TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Media"
XRemove 54tr10smss.exe"Added by the BRONTOK-CH WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data"
URetroExpressRetroExpress.exe"EMC (was Dantz) Retrospect Express - backup software for external hardware storage devices"
XRPCserv32gCSRSS.EXE"Added by the BOBAX.AD WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
YRPCSS.exerpcss.exe"Remote Procedure Call. Required by windows for programs to communicate with each other on networks/different machines. Originally for NT only but now installed with Win98/98se. Under Win98/98se
XRsWinlsass.exe"Added by the DELCANTI-B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""12053"" subfolder"
XRsWinlsass.exe"Added by the SILLY.BR WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""4350"" subfolder"
XRTHDBPLlsass.exe"Added by the ROUTROBOT WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\SystemProc"
Xrundll32csrss.exe"Added by the GUTTA TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRunnerlsass.exe [trojan filename]"Added by the DROWSY-B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRunnercsrss.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRunnerlsass.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRuntime ProcessCsrss.exe"Added by the CIADOOR-J BACKDOOR! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRuntime Server Subsystemcsrss.exe"Added by the IRCBOT-XV WORM!"
Xsbss Launchersbss.exe"SideBySide adware"
XScheduler Servicewsass.exe"Added by the LIOTEN.KX WORM!"
Xsck121helpsyss.exeAdded by a variant of the MAILBOT TROJAN!
Xscrssscrss.exe"Added by the HACDEF-R TROJAN!"
XSDAvcsnss.exe"Added by the SERFLOG.C WORM!"
Xsdrsssdrss.exe"Added by the SDBOT-SQ WORM!"
USecretSmileysss.exe"""Secret Smileys is an add-on for AIM that provides users access to 1000's of new Smileys that can be viewed by anyone using a current version of AIM. Secret Smileys also adds other features such as logging of IM conversations
XSecurity Patchscmss.exe"Added by the RBOT-ZW WORM!"
Xsecurity servicesyss.exeAdded by an unidentified WORM or TROJAN!
XSernellApp.pcxcsrss.exe"Added by the BANCBAN-BJ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""D5133"" subfolder"
XService Monitorcsnss.exe"Added by the RBOT.EEH WORM!"
XService Processsmss.exe"Added by the DCMBOT-E TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""config"" subfolder"
XServicescsrss.exe"Added by a variant of the RANKY.U TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XServices Processsmss.exe"Added by the SMALL-EK TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""config"" subfolder"
XServices.dllsmss.exe"Added by the SOBER-L WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\system and note the space at the beginning of the ""Startup Item"" field"
Xservices.exeservicess.exe"Added by the MSNSPY-B TROJAN!"
XServicesLoadlsass.exe"Added by the DEARIS-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XShieldSafenessShieldSafeness.exe"ShieldSafeness rogue security software - not recommended
XShockwavecsrss.exe"Added by the SNDOG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xslmssslmss.exe"SeekSeek search hijacker related - see here"
Xsmcsssmcss.exe"Added by the SCLOG-AJ TROJAN!"
Xsmrsssmrss.exe"Added by the BANPAES-B TROJAN!"
XSMSSsmss.exe"Added by the FLOOD.F BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Catroot"" subfolder"
Xsmss[path to smss.exe]"Added by the ALADINZ.F TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
Xsmsssmss.exe"Added by the AGENT-TR TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsmsssmss.exe"Added by the BOROBOT-J TROJAN and variants! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
Xsmss.execsrss.exe"Added by the DALBUG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSmss.exe driverwinupd32.exe"Added by the SDBOT.MI BACKDOOR!"
XsmssLevel4smss.exe"Unidentified malware! ! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Windows Media Player\Skins\WindowsMediaSkin\Data\Level4"
XSMSSSsmsss.exe"Added by the SDBOT.ZD WORM!"
XSMSSS Loadersmsss.exe"Added by the AGOBOT.MQ WORM!"
XSNSS.EXESNSS.EXE"Nunci premium rate dialer"
XSoftSafenessSoftSafeness.exe"SoftSafeness rogue security software - not recommended
XSondBlasterlsass.exe"Added by the PROSTI.AA BACKDOOR! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Media"
XSoundMixersmvss.exe"Added by the DEDLER-G TROJAN!"
XSpooler Subsystem Applicationsmss.exe"Added by the IRCBOT-ZO TROJAN! Note - the legitimate smss.exe process should not normally figure in Msconfig/Startup!"
Xspoolsvr32csmss.exe"Added by the AGENT-AU TROJAN!"
XSpy Protectorsrcss.exe"SpyProtector rogue security suite - not recommended
Xssmssssmss.exe"Added by the AGENT-MOF TROJAN!"
Xstart uploadingsmsss.exe"Added by a variant of the SDBOT WORM!"
Xstart uploadingcrsss.exe"Added by the RBOT-SZ WORM!"
XStartupBiniwnujdss.exe"Added by the SDBOT-XZ WORM!"
XState Servicecsrss.exe"Added by the DADOBRA-CP TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NStatus Monitor XEENGSS.EXEThe Xerox Document WorkCentre XE Series Status Monitor displays information about your printer and currently active or waiting print jobs. You can use it to control your printing environment and manage your printing operations. Available via Start -> Programs
XSunJavaUpdatesmvss.exe"Added by the DEDLER-G TROJAN!"
XSygate Personal Portcrss.exe"Added by the RBOT-PX WORM!"
XSysinolsess.exe"Added by the FORBOT-BF WORM!"
XsysinterADIRSS.EXE"Added by the AGENT.JVJ TROJAN!"
XSysqqLSESS.exe"Added by the FORBOT-BF WORM!"
XSystemcsrss.exe"Added by the LDPINCH.E TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsystemlsass.exe"Added by the SATILOLER.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System"
XSystemsmss.exe"Added by the AGENT.EP BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem Config Managercrss.exe"Added by the AGOBOT.GH WORM!"
XSystem HandlerLSASS.EXE"Added by the NIMOS WORM! Note - this is not the legitimate lsass.exe process
XSystem Information Managersyspass.exe"Added by the SDBOT-MO WORM!"
XSystem Kernellsass.exe"Added by the VBBOT-G TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem Messaging QueueSMCSS.EXE"Added by a variant of the RBOT WORM!"
XSystem Monitoringlsass.exe"Added by the BRONTOK-BS WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
XSystem Processcsrss.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem Processlsass.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem Session Managersmss.exe"Added by the KALEL-E WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
XSystem Startup Managersmcss.exe"Added by the RBOT.AMD WORM!"
XSystem Updater Machinecrhwss.exe"Added by the CIADOOR-DQ TROJAN!"
XSystem132Csrtss.exe"Added by the LANFILT-I TROJAN!"
XSystem32lsasss.exe"Added by the RBOT-XW WORM!"
XSystem32csrss.exe"Added by the SILLYFDC WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XSystemDrivercsrss.exe"Added by the ASCETIC.B TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\addins\explorer"
XSYSTEMSars32csrss.exe"Added by the AHLEM.A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSysUtilssmss.exe"Added by the AUTORUN-AWW WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
XTapisystss.exeAdded by the SMALL TROJAN!
XTaskLSASS.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate lsass.exe process
XTaskMrgcsrss.exe"Added by the LDPINCH-W TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xtattatss.exe"Delfin Promulgate adware variant"
XTok-Cirrhatussmss.exe"Added by the BRONTOK-A WORM and variants! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%"
XTok-Cirrhatus-2784smss.exe"Added by the BRONTOK-S WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%"
XToPLSASS.exe"Added by the WOWCRAFT.C TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
?ToPassSrvPktopass.exe"Related to Caere Pagekeeper scanning software (now taken over by Scansoft)
XTorjan Programsmss.exe"Added by the WOWCRAFT.B TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XTraybarlsass.exe"Added by the MYDOOM.L WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NUMAX VistaAccessvsaccess.exeVistaAccess gives you quick and easy access to scanning functions right from your desktop
UUniblue Quick Accessqaccess.exe"Quick Access application from UniBlue Systems Ltd - ""helps you account for all processes on your computer by providing an additional plug-in for the Windows task manager"""
XUpdatecsrss.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XUpdatecsrss.exe"Added by the MEHEERWAR TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""winupdate"" subfolder"
XUpdatelsass.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XUpDaTercsrss.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
XusbSASS.EXE"Added by the FUNSTA-A TROJAN!"
XUSD Driverccrss.exe"Added by the SDBOT.BFH WORM!"
XUserinitlsass.exe"Added by the VIRAN-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Program Files%\Common Files%\System"
Xuserinitsmss.exe"Added by the DLOADR-B TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XUsrManagementConfumcss.exe"Added by the IRCBOT-W TROJAN!"
XVirscannersmss.exe"Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XViSulaBaCislsass.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
XVital Master-boot DLLcrsss.exe"Added by the RBOT.ASE WORM!"
Xvmssvmss.exe"Delfin Media Viewer or ""Promulgate"" adware variant"
UWallpaperSSWallpaperSS.exe"Wallpaper Slideshow LT from gPhotoShow.com - ""a great utility for displaying your favorite photos as your desktop wallpaper"""
XWin exe file managrcrss.exe"Added by the RBOT.CCI WORM!"
XWIN HOST PROCESSWIN HOST PROCESS.EXE"Added by the KEYLOGGER.CLONE TROJAN!"
XWin32 Network Drivercrss.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWin32 Security Servicecrsss.exe"Added by the DELBOT-O WORM!"
XWinDLL (csmss.exe)"rundll32.exe CSMSS.EXEstart"
XWinDLL (lcass.exe)"rundll32.exe lcass.exestart"
XWinDLL (slmss.exe)"rundll32.exe slmss.exestart"
XWinDLL (slsass.exe)"rundll32.exe slsass.exestart"
XWindowssmss.exe"Added by the BANCBAN-QF TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindowsspoovlss.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows (ICS) Spoolercrtss.exe"Added by a variant of the RBOT WORM!"
XWindows 2004csrss.exe"Added by the BANKER-DY TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Windows 2004\Tools"
XWindows Authority Servicelsass.exe"Added by the KALEL-E WORM! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XWindows auto updateLSASS.exe"Added by the AHKER.G WORM! Note - this is not the legitimate lsass.exe process
XWindows backupsystemss.exe"Added by a variant of the SPYBOT WORM!"
XWindows Client Service 32csrss.exe"Added by the RBOT-ALB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a drivers\winsdriver subfolder"
XWindows Explorer SP2csrss.exe"Added by the BANKER-DM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""JavaBeans"" subfolder"
XWindows FirewalLsess.exe"Added by a variant of the RBOT WORM!"
XWindows Genuine Validatewinservicessss.exe"Added by the IRCBOT.UUI BACKDOOR!"
XWindows Host Namelmass.exe"Added by the GAOBOT.O WORM!"
XWindows Image Acquisition (WIASSC)WIAcss.exe"Added by the RIZO.A TROJAN!"
XWindows Locatorwsass.exe"Added by the IRCBOT.N TROJAN!"
XWindows Loginlmss.exe"Added by the AGOBOT-JA WORM!"
XWindows Media Centersmss.exe"Added by the WARBOT TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows media servicecrvss.exe"Added by the SDBOT.VP WORM!"
XWindows media servicecrsss.exe"Added by the RBOT.ACY WORM!"
XWindows media servicescvrsss.exe"Added by the RBOT-MW WORM!"
XWindows NT Session Managersess.exe"Added by a variant of the RBOT WORM!"
XWindows Portable DevicesMSKSVRTSS.EXE"Added by the SPYBOT.APEO WORM!"
XWindows Printing Driverciadvss.exe"Added by the ARCHIVARIUS series of WORMS!"
XWindows Recavery Adwarelsass.exe"Added by an unidentified TROJAN - see here. Note - this is not the legitimate lsass.exe process
XWindows Registerswinservicess.exe"Added by a variant of the SDBOT WORM!"
XWindows Registry Express Loaderregexpress.exe"Added by the FORBOT-CJ WORM!"
XWindows Registry Securitycrss.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Security Authority Servicelsass.exe"Added by the KALEL-A WORM! Note - this is not the legitimate lsass.exe process
XWindows Security Updatendsass.exe"Added by the RBOT.ESM BACKDOOR!"
XWindows Service Agentdsass.exe"Added by the RBOT.MIRCO.BNG WORM!"
XWindows Service Updatecrsss.exe"Added by the SDBOT.CWX WORM!"
XWindows Session Manager Subsystemsmss.exe"Added by the KALEL-B WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
XWindows svchostupss.exe"Added by the PUSHBOT.GJ WORM!"
XWindows Svchost Authorityslsass.exe"Added by the RBOT-UA WORM!"
XWindows Taskmanager Datacsrrss.exe"Added by the RBOT-BBH WORM!"
XWindows TMSyss.exe"Added by the RBOT.ADF BACKDOOR!"
XWindows Updatecsrss.exe"Added by the BANKER-HM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Updateklass.exe"Added by the BIFROSE-ZH TROJAN!"
XWindows Update 32rempss.exe"Added by the FORBOT-FW WORM!"
XWindows Update ServiceSP00ISS.exe"Added by the SDBOT-ZH WORM!"
XWindows WKSwsass.exe"Added by the SDBOT-DK WORM!"
XWindowsExplorercsrss.exe"Messenger Blocker rogue security software - not recommended. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System"
XWindowsFirewalllsass.exe"Messenger Blocker rogue security software - not recommended. Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System"
XWinDOwsUPdatesmss.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
XWindowsupdate Servicecsrss.exe"Added by the BABA-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root folder (ie
XWindowsUpdatecrsscrss.exe"Added by a variant of the AGENT-HZ TROJAN!"
XWindowsUpdatelsassslsasss.exe"Added by a variant of the AGENT-HZ TROJAN!"
XWindowsUpdatesvchostsssvchostss.exe"Added by the AGENT-HZ TROJAN!"
XWindows_LowLevel_Security_Corelsass.exe"Added by the PADMIN-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Repair"
XWinExecLsass.exe"Added by the CRUTLE-B WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWinlogonLsass.exe"Added by the ALCOP-B WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xwinlogon_userccIsass.exe"Added by the SILLYFDC.BBT WORM!"
Xwinprotectionccsrss.exe"Added by the SILLYFDC.BBT WORM!"
XWinsSystemsyssmss.exe"Added by the DELF.IG TROJAN!"
Xwinsystem.syssmss.exe"Added by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\win32 and note the space at the beginning of the ""Startup Item"" field"
XWINTASK DLL32smsrss.exe"Added by the MYTOB.BS WORM!"
XWinUpdateAdministratorCSRSS.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Application Data\WINDOWS"
UWinUpdateProtectioncsrss.exe"EmployeeWatch is a commercial surveillance software program designed to monitor user activity on a computer. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a subfolder of C:\windowsupdate\ufp"
XWinXPcsrss.exe"Added by the BANCOS-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\WinXP\Tools"
XWinXP-98CSRSS.exe"Added by the BANKER-DS TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\WinXP-98\Tools"
XWinXPServicelsass.exe"Added by the ZAPCHAS-AS TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Lavan"" subfolder"
Xwlsasswlsass.exe"Added by the RANKY.CY TROJAN!"
XWMDM PMSP Servicecssrss.exe"Added by the KNOCKIT-A TROJAN!"
XWSAConfigurationdrrss.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWSAConfiguration1csass.exe"Added by the AGOBOT.WH WORM!"
XWWKSwsass.exe"Added by the SDBOT-BT WORM!"
Xwzservicehess.exeAdded by the HACKARMY.W TROJAN!
Xyay.exeasass.exe"Added by the AGOBOT-M WORM!"
XZincgrubIncLsass.exe"Added by the VOUMIT-A WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\mirc32"
UZoneUpdatecsrss.exe"WinSpy surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""ComRoot"" subfolder"
Xzsmssmss.exe"Added by the BANCOS-CK TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xzsmsssmss.exe"Added by the BANCOS-DD TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X[random name]l?ass.exe"PurityScan adware"
X[random name]??rss.exe"PurityScan adware"
X[random name]c?rss.exe"PurityScan adware"
X[various names]svchostss.exe"Added by a variant of the RBOT WORM!"
X[various names]Serviceprocess.exe"Wareout - malware masquerading as a spyware and dialer remover"
X_Services.dllsmss.exe"Added by the SOBER-L WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\system"
X_SystemDrivercsrss.exe"Added by the ASCETIC.B TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\addins\explorer"
X_winsystem.syssmss.exe"Added by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\win32"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.