Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
XMSPF.EXE"Added by a variant of the SDBOT WORM! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field"
Inc.""Miramar SystemsUatmsg.exe
ME""MS Java Applets for Windows NTXjavaapplets.exe
NT"Ms Java for Windows 98 ME & XP"X
NT"Ms Java for Windows 98 XP & ME"X
XP & ME"MS Java for Windows NTXxpjavams.exe
X(Default)msarti.com"Added by the SILLYFDC.CJ WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\..\Policies\Explorer\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)msnupdate.exe"Added by the RBOT-GWT BACKDOOR! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run & HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X*Bandookmsdll.exe"Added by an unidentified TROJAN - see here"
X*MS Setup[random filename]"Virtumondo adware
X*MSConfig32aecache.exe"Detected by F-Secure as the OBFUSCATED.GP TROJAN!"
X*windows updatewkmst.exe"Added by the SDBOT.AVD WORM!"
X.mscdrlassa.exe"Added by the WEBUS.C TROJAN!"
X.mscdrlsvchost.exe"Added by the WEBUS.D TROJAN!"
X.mscdsrlsvchost.exe"Added by the BDOOR-CR BACKDOOR!"
X.mscsblsvhost.exe"Added by the CMQ TROJAN!"
X.msfupdatemsveup.exe"Added by the ALLOCUP.A WORM!"
X.mssecuremssecure.exe"Added by the DDOS_BOXED.X TROJAN!"
X.NET.msnmgnr.exe"Added by the DELF.AYF WORM!"
X.nvsvcsmss.exe"Added by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
X.nvsvcbsmssb.exe"Added by the BOXED.CG TROJAN!"
X2020Downloadermssvr.exe"2020Search Toolbar"
X27msm32.exe"Added by the SLSORVE-E TROJAN!"
X@wincms.exe"Added by the RBOT.CBR WORM!"
XaMsSvrdll.vbs"Added by the MUTAFROG!INF WORM!"
XAAMSFree702Avengine.com"Added by the DELF.LJ TROJAN!"
XAAMSFree702sys.exeAdded by the BACKDOOR-CPC TROJAN!
XActiveX Streamermsgfix.exe"Added by the SDBOT.NQ WORM!"
XAdobeReadermsni.exe"Added by the RBOT.DAO TROJAN!"
XAdobeReaderPromsnxpsp.exe"Added by the RBOT-ASK or RBOT-AUS WORMS!"
XAdobeReaderPromsnserve.exe"Added by the SDBOT-AKH WORM!"
XAdobeReaderPromsnservex.exe"Added by the RBOT.AKM BACKDOOR!"
XAdobeReaderPromsnsrcdv.exe"Added by the INJECT-H WORM!"
XAdobeReaderProfessionalmsx64.exe"Added by the RBOT-GAT WORM!"
XAdobeReaderProssysmsn.exe"Added by the RBOT-BGH WORM!"
Xafmsmsgsafmsmsgs.exe"Added by the DLOADR-CUX TROJAN!"
UAgere SoftModem Messaging AppletAGRSMMSG.exeInstalled with the drivers for internal software modems based upon Lucent/Agere Systems chipsets - required if you use the SoftModem Assistant to configure the modem
UAGRSMMSGAGRSMMSG.exeInstalled with the drivers for internal software modems based upon Lucent/Agere Systems chipsets - required if you use the SoftModem Assistant to configure the modem
NAIMster??Peer to Peer (P2P) file sharing client that runs over the AOL Instant Messenger network. Available via Start -> Programs
UAlwaysReady Power Message APPARPWRMSG.EXE"""Away Mode"" feature added with Update Rollup 2 for Windows XP Media Center Edition 2005 that allows the computer to appear off to the user while it continues to perform tasks that do not require user input
UAMSGAmsg.exe"Part of the IBM ThinkVantage Productivity Center. ""The Message Center sends automatic notification on ThinkVantage Technologies integrated with your system. Once you're online"""
Xamsgupdateams.exeAdded by a variant of the MAILBOT TROJAN!
NAMSNamsn.exe"aMSN Messenger is a multiplatform MSN messenger clone"
Xamsnamsn.exe"Added by the BANKER-BNZ TROJAN!"
Xangeleyesmsdll.exe"Added by the VB.PI TROJAN!"
XAnti Spam Servicespamsvc.exe"Added by the MYTOB-BK WORM!"
XAnti-Virusvpms.exe"Added by a variant of the SLAPER TROJAN!"
XAntiMalwareSuiteAMS.exe"AntiMalwareSuite rogue security software - not recommended
XAntiVirsmss.exe"Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%"
XAntivirusMSA.exe"MS Antivirus rogue security software - not recommended
UAntiWindowsMessengerAntiMsMsg.exe"Anti-Windows_Messenger is a small application that prevents Windows Messenger from remaining resident in memory"
XAol Configuration Loaderaimsng.exe"Added by the SDBOT-XE WORM!"
XAol Instant Messengeraolmsg.exe"Added by the KELVIR.AL WORM!"
XAOL Instant Messengeraimsgr.exe"Added by the IRCBOT.N TROJAN!"
XAOL Instant Messenger dll runtimeMSAOL32dll.exe"Added by the RBOT-ATA WORM!"
XAOL Messengeraolmsngr.exe"Added by the SDBOT-JF WORM!"
XAPIMonmsreg.exe"Added by the DROPPER.Z TROJAN!"
?Apmsrv9xAPMSRV9X.EXE"Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
YApplicationmdmsetsp.exe"Aztech Labs modem driver"
XApplication In SystemSnxmsh.exe"Added by the AGENT-LNV TROJAN!"
XApplicationProtocolRunsmsbvl32.exe"Added by the IRCBOT-CX TROJAN!"
UARPWRMSGARPWRMSG.EXE"""Away Mode"" feature added with Update Rollup 2 for Windows XP Media Center Edition 2005 that allows the computer to appear off to the user while it continues to perform tasks that do not require user input
Xasnconsolemsasn.exe"Added by the RBOT.EVU TROJAN!"
XATI AS Filtermsnse.exe"Added by the RBOT-CCY WORM! Note - modifies the HOSTS file by appending numerous lines
Xatiupdatemsshed32.exeAdded by the DELF.EP downloader TROJAN!
UAtomSyncatomsync.exe"AtomSync - ""this NTP client synchronizes your PC clock with an internet atomic time server or with a time server on your LAN"""
Xaudlmne32dcmsxe.exe"Added by the MAILBOT-CF TROJAN!"
XAudoi Device Loadersmssv.exe"Added by the AGOBOT-ZY WORM!"
XaugmsgAUGMSG.EXE"Added by the SPYBOT-CO WORM!"
XAutoUpdatesmss.exe"Added by WINSPY.88! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64"
YAVG7_AMSVRAVGAMSVR.EXE"This is the AVG7 Alert Manager for the 7.* series of anti-virus products from AVG Technologies. It is essential for both scheduled activities (such as automatic updates and scans) and for displaying alerts and reports via the Control Center (avgcc.exe). Appears in 9x/Me as a startup entry and as a service in 2K and higher"
Yavgamsvr.exeAvgamsvr.exe"This is the AVG7 Alert Manager for the 7.* series of anti-virus products from AVG Technologies. It is essential for both scheduled activities (such as automatic updates and scans) and for displaying alerts and reports via the Control Center (avgcc.exe). Appears in 9x/Me as a startup entry and as a service in 2K and higher"
Yavgmsvr.exeavgmsvr.exe"AVG Anti-Virus 7.0 related"
Xavnortmsmbw.exe"Added by the SERFLOG.A WORM!"
Xavpmsavpms.exe"Added by the ONLINEGAMES.CPV TROJAN!"
XAvSermsmpatch.exe"Added by the SERFLOG.B WORM!"
Yavx communicatorxcommsur.exe"Anti-virus part of BitDefender virus scanner/firewall"
Xb99msmm.exe"ClientMan parasite variant"
XbalSYSMONMS.EXE"Added by the FAKEALERT TROJAN!"
YBCMDMMSGbcmdmmsg.exeBCM voicemodem driver. Required for dial-up if you have one of these modems
YBCMSMMSGBCMSMMSG.exeBCM voicemodem driver. Required for dial-up if you have one of these modems
XBcvsrv32msxml22.exe"Added by the AGOBOT.AKH WORM!"
XBcvsrv32msc32.exe"Added by the AGOBOT.AKD WORM!"
XBcvsrv32msbvd32.exe"Added by the AGOBOT-SR WORM!"
Nbgsmsndbgsmsnd.exePrinter driver to generate PDF files from any program
NBing Barmswinext.exe"Bing Bar - the latest incarnation of the MSN Toolbar from version 5.* onwards. This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
?Bingo Charmcharms.exe"Some kind of screen icon kind of like desk flag
YBitDefender Communicatorxcommsvr.exe"BitDefender antivirus"
UBitDefender for MSN Messengermsnmon.exe"Bitdefender anti-virus for MSN Messenger - no longer supported at the BitDefender website"
Xblah servicemsnmsgrr.exe"Added by the RBOT.PZ WORM!"
Xblahh servicemsengine.exe"Added by a variant of the RBOT WORM!"
Xblahx servicemsnjompa.exe"Added by the SDBOT.AML WORM!"
Xbrowsermsgaol.exe"Added by the TACTSLAY.C TROJAN!"
Xbtmsre.exebtmsre.exe"Added by the SDBOT.AM WORM!"
YBullGuard XCommXCOMMSVR.EXE"Part of Bullguard antivirus"
XBymer.ScannerMsinit.exe"Added by the BYMER WORM!"
XcandynetTaskmsg.exe"Added by the RBOT-NA WORM!"
XCashToolbarMSCStat.exe"Added by the DOWNLOADER-MY TROJAN!"
Xccrssmsdtc.exe"Added by the STAP-C WORM!"
Xcdmmslpoklpllsm.exe"Added by the TEDIJINI-A TROJAN!"
Xchange-me-nowmsgfix1.exe"Added by the SDBOT.ZD WORM!"
UChangeICONSPMSMON.EXECard reader related program. Note - may cause problems with My Computer loading at startup. Disabling through MsConfig seems to solve the problem
XChansonsMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XCheckdiskmscas.exe"Added by the VAGON-A TROJAN!"
XCheckFaultKernelmswdm.exe"Added by the SMALL-CSK TROJAN!"
YCheckMsgPlus"MsgPlusH.dll VerifyInstallation"
Xchina11msnCHINA11MSN.EXE"Added by the ENVID.O WORM!"
XCiaBackdoormsldr.comAdded by a VIRUS!
XCisco Systems[path to worm]"Added by the AUTORUN.UHR WORM!"
UCisco Systems VPN Clientipsecdialer.exe"Cisco VPN Client - lets local users gain Administrator privileges on the operating system"
UCisco Systems VPN Clientvpngui.exe"Sets up IPSec communications for Cisco's VPN Client"
XClassesMSTAR2.EXE"""Switch"" premium rate adult content dialler variant"
XClassesmstart.exe"""Switch"" premium rate adult content dialler variant"
XClient for Microsoft Networksmsclient32.exe"Added by the SDBOT-BXQ WORM!"
XClient Server Runtime Processsmmss.exe"Backdoor TROJAN! Possible SDBOT-GEN variant"
XClientMan1mscman.exe"ClientMan parasite variant"
XClock Manageramsngr.exe"Added by the SDBOT-XM TROJAN!"
XCLSIDmsgplus.exeAdult content dialler
XCLSIDmsgplus.exePremium rate adult content dialer. Note - this is NOT the MSN Messenger 'MessengerPlus' extension
Xcmrsscrmss.exe"Added by the DLOADER-EK TROJAN!"
Xcmsiserver.exe"Added by the DLOADER-WK TROJAN!"
XCMSallycallmesally.exe"Added by the CASAL.A TROJAN!"
UCMSETTINGSctmn.exe"Part of NetNanny
Xcmsoundvcpdll.exe"Added by the TCXMEDI-D downloader TROJAN!"
Xcmsoundvcsystem.exe"Added by the TCXMEDI-D downloader TROJAN!"
Xcmsssystem.exe"Added by a variant of the RBOT WORM!"
Xcmssappiexplore_.exe"Added by the BANCBAN-CQ TROJAN!"
Xcmssappiexplore.exe"Added by the BANCBAN-GF TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XcmssSystemProcesscsmss.exe"Added by the AGENT-CO TROJAN!"
XcmssSystemProcessmcsmss.exe"Added by the PROXYSER-F TROJAN!"
XcmssSystemProcesscsms.exe"Added by the AGENT-Y TROJAN!"
XCMSystemCMSystem.exe"CASClient adware"
?COEMsgDisplayCOEMsgDisplay.exe"Part of HP's PC Common Operating Environment (PC COE) project. Located in %ProgramFiles%\Hewlett-Packard\PC COE. What does it do and is it required?"
XCOM Servicemscom32.com"Added by the BEASTY.H TROJAN!"
XCOM Servicemsynvr.com"Added by the BEASTY.G TROJAN!"
XCOM Servicemsjclh.com"Added by the BEASTY.E TROJAN!"
XCOM Servicemsdrce.com"Added by the BEASTY.I TROJAN!"
XCOM Servicemsflyx.com"Added by the BEASTDO-O TROJAN!"
XCOM Servicemskwda.com"Added by the AGENT-JIX TROJAN!"
XCompaq Service Driversamsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversmsnt.exe"Added by the SDBOT.CQL WORM!"
XCompaq Service Driverswinmsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversmsnsvc.exe"Added by the RBOT.BKT WORM!"
XCompaq32 Service Driversms32.exe"Added by the SDBOT.BWH WORM!"
XCompaq32 Service Driversmsconfig32.exe"Added by the SDBOT-ADC WORM!"
XCompaq32 Service Driversmsnt32.exe"Added by the RBOT.BVF WORM!"
NCOMSMDEXEcomsmd.exe3Com tray icon
XComStartTrojan Guarder.exe"TrojanGuarder rogue security software - not recommended"
XConfigurationmsgfixs.exe"Added by the SDBOT-NN WORM!"
XConfiguration Loadermsgfix.exe"Added by the GAOBOT.AUS or SDBOT.J or SDBOT-QG WORMS!"
XConfiguration Loadermsnss.exe"Added by the GAOBOT.AUS WORM!"
XConfiguration LoaderMSTasks.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadersmss32.exe"Added by the AGOBOT.MB WORM!"
XConfiguration Loadermsgcfgsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadersmsai.exe"Added by the SDBOT-YE WORM!"
XConfiguration Loadermsg.exe"Added by the SDBOT.BT WORM!"
XConfiguration Loadermsnmsgr.exe"Added by the SDBOT-SO WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XConfiguration Loadermservs.exe"Added by the SDBOT-NM WORM!"
XConfiguration Loadermsgfixy.exe"Added by the SLINBOT.QW BACKDOOR!"
XConfiguration Loadermsrun.exe"Added by the AGOBOT-Y WORM!"
XConfiguration Servicesmswords.exe"Added by the SDBOT-YM WORM!"
Xconmswfconrnbne.exe"Added by the SDBOT-DEX WORM!"
XConnectorsms.EXE"Added by the ExDial-B premium rate adult content dialer"
XContent List Management Subsystemclmss.exe"Added by the SPYBOT-EL WORM!"
XContentDownload"rundll32.exe MSA64CHK.dllDllMostrar"
XControlServiceMgrcsmsv.exe"Added by the AGENT-XC TROJAN!"
XCoolDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XCoolMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XCPCmscl0ckCPCmsclock.ExE"Added by the IRCFLOOD.BF TROJAN!"
Xcplmsgaol.exe"Added by the TACTSLAY.C TROJAN!"
UCreata MailJMSrvr.exe"Creata_Mail. Smileys
UCreative MediaSource GoCTCMSGo.exe"Creative MediaSource Go! is a combination of a short-cut bar and launcher for the Creative MediaSource™ player/organizer - which ""enables you to manage your entire digital music collection on both your computer and your Creative portable music player effortlessly"""
UCreative MediaSource GoCTCMSGoU.exe"Creative MediaSource Go! is a combination of a short-cut bar and launcher for the Creative MediaSource™ player/organizer - which ""enables you to manage your entire digital music collection on both your computer and your Creative portable music player effortlessly"""
Xcrmssrlt[random filename]"Added by a variant of the SLAPER TROJAN!"
Xcrsmonsiomssls.exe"Added by the BACKDR-AU TROJAN!"
XCSCRS Value CheckMsPMSPSd.exe"Added by a variant of the SDBOT WORM!"
Xcsrssmsmsgs.exe"Added by the CHODE-J BACKDOOR! Note - this malware uses MSN Messenger (which is located in %Program Files%\Messenger) in the background to propogate itself"
Xcsrssssms.exeAdded by an unidentified malware
Xctfmonmsnmsgr.exe"Added by the BDOOR-JV BACKDOOR! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
Xctfmon.exemsupdate32.exe"Spy Sheriff/SpywareNO malware
XCurrent32msnpla.exe"Added by the SDBOT-DIS WORM!"
Xcvmsyslpdsdservss.exe"Added by the MAILBOT-BY TROJAN!"
NCyberlink PowerCinema 3.0PCMService.exe"Part of Cyberlink's PowerCinema - which can be used to watch movies
Xdatamsngs.exe"Added by the RBOT-ADQ WORM!"
NDataViz Inc MessengerDvzIncMsgr.exe"Installed with DataViz ""Documents to Go"" software"
NDataViz MessengerDvzMsgr.exe"DataViz Documents to Go - "allows you to use your Word
XDebugSMSS.exe"DreamAd adware. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Udefaultmskbw.exe"PC Surveillance PRO surveillance software. Uninstall this software unless you put it there yourself"
XDelayLoadmsprint.exe"Added by a variant of the Win32.Agent.ryo malware - see here"
Xdelmsbbdelmsbb.exe"180Search adware"
XDescargaBromas"rundll32.exe MSA64CHK.dllDllMostrar"
XDesktop"rundll32.exe msconfd.dllRestore ControlPanel"
XDesktopUpdate"rundll32.exe MSA64CHK.dllDllMostrar"
XDevice Configuration Loadermsdvc32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XDHCPsmss.exe"Added by the WINSPY.AG TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\display"
XDialer"rundll32.exe MSA32CHK.dllReg"
XDisk Defragmentation Loaderpmsvcr.exe"Added by a variant of the IRCBOT TROJAN!"
XDiskCheckmsdarkend.exeAdded by an unidentified WORM or TROJAN!
XDmsvc32Dmsvc32.exe"Added by the AGOBOT.ABU WORM!"
XDM_serverdmserver.exe"Comet Cursor adware"
XDoggy StyleMsPMSPSd.exe"Added by the SDBOT-AAP WORM!"
XDownloadLegalMusic"rundll32.exe MSA64CHK.dllDllMostrar"
XDownloadMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XDownloadsAndMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XDRam prosessormsupdate.exe"Added by the DELF-FAW TROJAN!"
XDrCacheMSTDC.EXE"Added by the BDOOR-JM BACKDOOR!"
Xdreamsserver.exe"Added by a variant of the SDBOT WORM!"
UDriverMagicLogondmschedule.exe"Part of DriverMagic - ""the easiest way to locate device drivers"""
Xdrmsrv32stmhosts.exe"Added by the AGENT.AGWU TROJAN!"
XDsmSerdsm.exe"Added by the SERFLOG.B WORM!"
XDsmSermsmpatch.exe"Added by the SERFLOG.B WORM!"
XDsmSersvosm.exe"Added by the SERFLOG.B WORM!"
XDsmSersysup.exe"Added by the SERFLOG.B WORM!"
Xdxdiag diagnosemsidxdia.exe"Added by a variant of the RBOT WORM!"
Xdxmsrvdxmsrv.exeAdded by an unidentified WORM or TROJAN!
UELSA WINman SuiteWinmsuit.exe"Allows you to totally customize your ELSA graphics card settings
XeMessengeremsn.exe"Added by the RBOT.AHO BACKDOOR!"
YEmsisoft Anti-Malwarea2guard.exe"System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses
Xemsw.exeemsw.exe"Attune HelpExpress - spyware. Disable and uninstall - see here"
XEntraOcio"rundll32.exe MSA64CHK.dllDllMostrar"
NEPSON Background MonitorSTMS.EXESupposed to keep an Epson printer ready for quick printing. Users report little difference whether it is on or not
Xethernetmsnger.exe"Added by a variant of the SDBOT WORM!"
Xethernetmsftp.exe"Added by the SDBOT.BXJ WORM!"
Xethernet adaptercsrmss.exe"Added by a variant of the RBOT WORM!"
XEthernet Drivercmsrrs.exe"Added by a variant of the RBOT WORM!"
XEventApplicationCmdsmschk.exe"Added by the IRCBOT-AO TROJAN!"
UEW Message Servermsg32.exeConexant (older versions are Brooktree) Wavestream Message Server - associated with Conexant based audio devices
XExplorermsrstart.exe"Added by the SOPICLICK TROJAN!"
NExtender Resource MonitorRMSysTry.exe"Related to Windows Media Center from Microsoft"
XFastDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
UFieldForms SyncSyncService.exe"Resco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run
?file indexing servicemsfindfile.exe"New version of MS FindFast and still a resource hog?"
XFireFox Service Driversssmss.exe"Added by a variant of the SDBOT WORM!"
XFirewall Updatermsnupdateit.exe"Added by the RBOT-AAQ WORM!"
XFKS v2.0msngr.exeAdded by an unidentified WORM or TROJAN!
XFlash Mediazrpk��'�'%''msn'�%'fix''.exe"Added by a variant of the IRCBOT BACKDOOR!"
XFlash Mediaskxs��'�'%''msn'�%'fix''.exe"Added by the AGENT.ZOY TROJAN!"
YFltProcessmsinet.exe"Part of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done"
UFMStartFmstart.exe"GFI FAXmaker - native fax connector for Microsoft Exchange Server or for networks
XFMSZfmsz.exe"Added by the FMSZ TROJAN!"
NFpxmnmsrvc.exeRemote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locations
XFreeMP3download"rundll32.exe MSA64CHK.dllDllMostrar"
UFTMSFLT(USB)FTMSFLTU.EXEFujitsu's Touch Panel Message Notifier
NGemStRmWGemStRmW.exe"For a GemPlus smart card reader. If it doesn't start automatically when you insert the smart card
XGeneric Host Process for Win Servicesmscvs.exe"Added by a variant of the SDBOT WORM!"
XGeneric Host Process for WinXP Servicesmshelp.exe"Added by the AGENT-GQP TROJAN!"
Xgerman.exewinsystems.exe"Added by the BAGLEDl-AE TROJAN!"
Xgerman.exewintems.exe"Added by the BAGLE-AS TROJAN!"
XGetitAll"rundll32.exe MSA64CHK.dllDllMostrar"
XGetMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XGetTheMusic"rundll32.exe MSA64CHK.dllDllMostrar"
XGLSetIT32msiexec16.exe"Added by the OPTIX PRO TROJAN!"
XGLSetT32smsiexec.exe"Added by the OPTIX-D TROJAN!"
XGmsvc32gmsvc32.exe"Added by the AGOBOT.ABN WORM!"
XGraphic Driversmss32.exe"Added by a variant of the RBOT WORM!"
XGreatDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XGsAdsgms2.exe"PacerD_Media/Pacimedia.com adware"
NGWMDMMSGGWMDMMSG.exeUsed with internal modems on Gateway and vprMatrix PCs. This is the "GTW modem messaging applet" and is not required for the modem to work correctly
XHardware Monitor Servicemshms.exe"Added by the WOLLF-A TROJAN!"
Xheomstoolheomstool.exe"Added by the HEOMS TROJAN!"
?HerculesCamServiceCamService.exe"Related to the Hercules Dualpix HD Webcam. What does it do and is it required?"
Xhotefixmsnmanegers.exe"Added by the IRCBRUTE.AS TROJAN!"
Xhotfixmsnnmaneger.exe"Added by the WOOTBOT.AF WORM!"
XHP Desktopccappms.exe"Added by the SDBOT-TG WORM!"
XHservicemsservice.exe"Added by the AUTORUN-KL WORM!"
XHTTP Tunneling Servermstunnel.exe"Added by the RBOT.EDL WORM!"
Xhttpdmsgaol.exe"Added by the TACTSLAY.C TROJAN!"
XHyper Startinstantmsgrs.exe"Added by the RBOT-NH WORM!"
XI am not Ranky. I am eTunnel!msyervice.exeAdded by an unidentified WORM or TROJAN!
UIbmpmsvcibmpmsvc.exe"Power management driver for IBM laptops. Provides support for the use of four keys on the thinkpad keyboard with blue key tops - Fn
XICManagementmsic32.exe"Added by the MSIC BACKDOOR!"
XICQMsn[path to trojan]"Added by the RANCK-AH TROJAN! The most common example is ""cbfks.exe"" located in %System%"
XIE6ssmss.exe"Added by the GAOBOT.DXO WORM!"
XIECheckMSDTCs.exe"Added by the TIRBOT-D WORM!"
XIECheckmssvp.exe"Added by the TIRBOT-G WORM!"
XIEXPLORERmsiecfg.exe"Added by the BDOOR-JU BACKDOOR or BANCBAN-IP TROJAN!"
XIISADMINSsystems.exe"Added by the AGOBOT.U WORM!"
XIMJPMIG8.2msime82.exe"Added by the VB-CYG WORM!"
XIMJPMIG8.2msime80.exe"Added by the VB-CYJ TROJAN!"
XImMsntimed.exe"Added by the WEBDOR.AK TROJAN!"
UImScInstImScInst.exe"Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails
UImScInst.exeImScInst.exe"Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails
UIMStartIMStart.exe"InterMute security software related"
XInetChkms[random value].exe"Added by the AGENT-IRL TROJAN!"
XInetMSNmsnet.exe"Added by a variant of the SDBOT TROJAN!"
Xinfosmss.exe"Added by the VB.EIW WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\inetsrv"
UInfoPenMSNInfoPenIM.exe"InfoPenMSN is a MSN Messenger plugin that allows you to send data written/drawn by hand"
XInstant Access"rundll32.exe EGCOMSERVICE_****.dll InstantAccess [**** = digits]"
XInstant Messenger Serviceimservice.exe"Detected by Kaspersky as the HEUR TROJAN!"
Xinstant messengersinstantmsgtr.exe"Added by the AGOBOT-PC BACKDOOR!"
XIntec Service Driversmsmsgrs.exe"Added by the SDBOT-ADN WORM!"
XIntec Service Driversmsmsgredss.exe"Added by the SDBOT-AGL WORM!"
XIntec Services Driversmsupdate22e.exe"Added by the RBOT-CGC WORM!"
XIntel Management Services v32mstime32.exe"Added by the AUTORUN-AYG WORM!"
XIntel Service Driversmsconfig16.exe"Added by the MSCONFIG16 TROJAN!"
XInteliSyssmss.exe"Advertisingvision adware. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XInternatmsgsrv32.exe"Added by the NYRUBOT-A BACKDOOR! Note - this is not the legitimate msgsvr32.exe process on a Win9x/Me system which should not appear in MSConfig/startup!"
Xinternetsmss.exe"Added by the MIFENG-K TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
XInternet Loader1MSInstall61.exe"Added by the KWBOT.B WORM!"
XInternet Mail and Newsmsqdevl.exe"EasySearch adware"
XInternet Mail and Newsmsqdevl1.exe"Added by the DLOADR-AWD TROJAN!"
XInternet Security Servicemsq32.exe"Added by the RBOT-GFP WORM!"
XInternet Security Servicemsq23.exe"Added by the RBOT-GQL WORM!"
XInternet Security Servicemsql23.exe"Added by the RBOT-GML WORM!"
XIntersoft Msngrintersoftmsngr.exe"Added by the AGOBOT-NW WORM!"
NISSI EZUpdate Serviceissimsvc.exePart of IBM Global Services - used internally by IBM for automatic updating of software and Microsoft patching
XJava32 Configuration Loadermsnmesgr.exe"Added by a variant of the RBOT WORM!"
XJavaScriptMsxrsMsxrs.exe"Added by the VB.BL WORM!"
Xjvms.exejvms.exe"Added by the ORCU.B TROJAN!"
Xkamsoftckvo.exe"Added by the GAMANIA-BW TROJAN!"
Xkdmsx[8 random letters].exe"Added by the SDBOT.AIJ BACKDOOR!"
XKernel Safe Modesmss.exe"Added by the 78CRACK-A TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XKernelFaultCheckmsime.exe"Added by the TINY-P TROJAN!"
XKernelFaultChksms.exe"Added by the DEADHAT WORM! Do not confuse with the valid ""kernelfaultcheck"" which runs ""dumprep 0 -k"" or ""dumprep 0 -u"""
XKernellsystems.exe"Added by the TARNO.C TROJAN!"
XKernellApps32smss.exe"Added by the BANCBAN-AN TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
UKONICA MINOLTA magicolor 2400W STDMSTMON_S.EXEKonica Minolta Magicolor 2400W colour printer monitor
XKvmSecure.exeKvmSecure.exe"KvmSecure rogue security software - not recommended
ULanguageMonitorOplmsb01.exeOKI Printer language support monitor
XLEMSRVlemsrv.exe"Added by the IRCBOT-TC TROJAN!"
XLive Messangerlivemsgr.exe"Added by the RBOT.BXX WORM!"
XLive Messangerwllmsngr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XLive Windows Messenger Versionmsnmessage7.7.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XLive Windows Messenger Versionmsnmsngrlive.exe"Added by a variant of the IRCBOT BACKDOOR!"
XLiveSexCamsLiveSexCams.exePremium rate adult content dialler
XLiveUpdatesmss.exe"Added by the VB.BAU BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas"
NLM StatusLMSTATUS.EXEXerox WorkCenter XE - language monitor status application
NLMSTATUSLMSTATUS.EXEXerox WorkCenter XE - language monitor status application
YLMSXXDLMSXXD.exeDriver for Xerox XD series printer/copiers
Xlnternet ExplorerAMSNDMGR.EXE"Added by the KWBOT.R WORM! Note that the ""l"" is a lower case ""L"" and not an upper case ""I"""
Xloadmsgsr32.exe"Added by the SDBOT-QR WORM!"
Xload=msater.exe"Added by the RETSAM TROJAN!"
XLoadingAgentmsload32.exe"Added by the OBLIVION TROJAN! This executable is one of the most common but there are more"
XLoadManagermsload.exe"Added by the OPASERV.T WORM!"
XloadMefssmss32.exe"Added by the FLOOD-EL TROJAN!"
NLoadMSvcmmmsvcmm32.exe"Auto-update for Movielink - internet movie rental System Tray access"
ULogitech ClickSmartLVCOMS.EXEEntry added when you install Logitech ClickSmart webcam software. It allows the camera to be accessed by both the Logitech software and (amongst others) NetMeeting and Windows Movie Maker. If you don't use the camera on a daily basis create your own shortcut and run it manually when required
ULogitech ImageStudioLVCOMS.EXEEntry added when you install Logitech ImageStudio webcam software. It allows the camera to be accessed by both the Logitech software and (amongst others) NetMeeting and Windows Movie Maker. If you don't use the camera on a daily basis create your own shortcut and run it manually when required
ULogitech QuickCamLVCOMS.EXEEntry added when you install older versions of Logitech QuickCam webcam software. It allows the camera to be accessed by both the Logitech software and (amongst others) NetMeeting and Windows Movie Maker. If you don't use the camera on a daily basis create your own shortcut and run it manually when required
ULogitech QuickCamLVComSX.exeEntry added when you install versions of the Logitech QuickCam webcam software - allows the full camera features (such as face tracking) to be accessed by both the Logitech software and (amongst others) NetMeeting and Windows Movie Maker. If you don't use the camera on a daily basis create your own shortcut and run it manually when required
XLosMejoresMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XLotsOfGames"rundll32.exe MSA64CHK.dllDllMostrar"
XLotsOfJokes"rundll32.exe MSA64CHK.dllDllMostrar"
XLSAmsdn.exeAdded by an unidentified malware
Xlsmss.exelsmss.exe"Added by the PROXY-GG TROJAN!"
XLTM2MSGSRV32.EXE"Added by the LITMUS.A BACKDOOR! Note - this is not the legitimate msgsvr32.exe process on a Win9x/Me system which should not appear in MSConfig/startup! This one is located in %Windir%\Litmus"
XLTM2MSGSRV320.EXE"Added by the LITMUS.C TROJAN!"
XLTM2MSGSSV32.EXE"Added by the FC.C TROJAN!"
XLTM2msns6"Added by the LITMUS.C TROJAN!"
YLTMSGltmsg.exe"Lucent Technologies (now Alcatel-Lucent) WinModem - which uses software rather than hardware
NLTSMMSGLTSMMSG.exe"Lucent Tech. Soft Modem Messaging application - may be found on Fujitsu Lifebook
XLTSMSGShell32.exe"Added by the LEMIR.B TROJAN!"
YLTWinModem1ltmsg.exe"Lucent Technologies (now Alcatel-Lucent) WinModem - which uses software rather than hardware
Xltwobmsmbw.exe"Added by the SERFLOG.A WORM!"
YLUCENT TECHNOLOGIES ltmsgltmsg.exe"Lucent Technologies (now Alcatel-Lucent) WinModem - which uses software rather than hardware
XLucky charms CDmylcuky.exe"Added by the SDBOT-SP WORM!"
ULVCOMSLVCOMS.EXE"Entry added when you install Logitech's ClickSmart
ULVCOMSXLVComSX.exeEntry added when you install versions of the Logitech QuickCam webcam software - allows the full camera features (such as face tracking) to be accessed by both the Logitech software and (amongst others) NetMeeting and Windows Movie Maker. If you don't use the camera on a daily basis create your own shortcut and run it manually when required
Ylxamsp32lxamsp32.exeLexmark Scan and Copy Control Program for the X63 (and maybe others) printer/scanner. Required for the scanner to work
XM S DVD DirectX Dll Driversmsxdl.exe"Added by the SDBOT-BJN WORM!"
XMachine Debug Managermsdn.exe"Added by a variant of the RBOT WORM!"
XMachine Debug Managermdms.exe"Added by the SDBOT-CH WORM!"
Xmachine-debuggermdmsv.exe"Added by the AGOBOT-BR WORM!"
Xmackfy.exemsms.exe"Added by the SDBOT-DID WORM!"
XMainDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XManageProtocolCtrlcsmsv.exe"Added by the LOOKSKY.B TROJAN!"
NMass storage check registry"rundll32.exe MSDServ.dll check registry"
XMatrixScreenSavermss.exeUnidentified malware
XMCwintrims.exe"Added by the WINTRIM TROJAN!"
UMcAfee SpamKillerMskAgent.exe"McAfee SpamKiller - rule-based and list-based spam filter. Available as a stand-alone product or included in older versions of Internet Security and Total Protection"
UMDSA Sentinel Xsmss.exe"SentinelX surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the smss.exe process which is always located in %System%. This one is located in %ProgramFiles%\MDSA Software"
Xmdwmdmspmdwmdmsp.exe"Adware - detected by Kaspersky as the AGENT.AM TROJAN!"
XMedia Loadmsn32.exeAdded by a unidentified WORM or TROJAN!
XMedia Plug x.1.2msdm.exeAdded by the MULDROP.352 VIRUS!
XMedia Servermsdts.exe"Added by a variant of the IRCBOT TROJAN!"
XMedia Servicemsn64.exe"Added by the SPYBOT.EV WORM!"
XMedia servicemsnmsgxr.exe"Added by the SDBOT.TF WORM!"
XMedia Transfer Protocalsmsstc.exe"Added by a variant of the IRCBOT TROJAN!"
XMedia X ServicesMSNGRx.exe"Added by the RBOT.AUL WORM!"
XMedia-XP-Service-Pack3msnzx.exe"Added by the SDBOT-ACW WORM!"
XMeeting Connectioncomsutil.exe"Added by the PPDOOR-E TROJAN!"
NMemory Stick MonitorMSTAT.exe"Used with the Sony floppy disk adapter for memory sticks
UMemory Stick MonitorMSstat.exeSony/SmartDisk memorystick-floppydisk-adapter software - allows you to read memorysticks in a normal floppydrive
UMemory+tfimemsr.exe"Memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
XMemScannerMemScanner.exe"Part of Enigma SpyHunter - not recommended
XMessage Queuingmsmqs.exe"Added by the FREEFORS TROJAN!"
XMessangermsgaol.exe"Added by the TACTSLAY.C TROJAN!"
XMessengerWmsngr.exe"Added by a variant of the RBOT WORM!"
YMessengerSCANMSG.EXE"AntiVirus Quick Heal - virus protection"
NMessengerMsnMsgr.exe"Windows Live Messenger (was MSN Messenger) utility - available via the Start menu. Disable by clicking on the ""Show menu"" icon and select Tools → Options → General → deselect ""Automatically run Windows Live Messenger when I log on to Windows"". This is the Windows Defender/Vista MSConfig entry for version 8.*"
NMessengermsmsgs.exe"Windows Messenger instant messenger utility included with Windows 2K/XP. Available via the Start menu. Go to Windows Messenger → Tools → Options → Preferences and uncheck ""Run this program when Windows starts"""
XMessengermsnmsgrr.exe"Added by the RBOT-GYK WORM!"
XMessenger Blockmsngrblock.exe"Added by the PATOO WORM!"
XMessenger Gatewaymsmgs.exe"Added by the AGENT-IGK TROJAN!"
XMessenger Servicemsmsgs.exe"Added by the SDBOT-ZB WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMessenger start-upMsgran.exe"Added by the GRAMOS WORM!"
NMessengerPlusMsgPlus.exe"MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that ""sponsor program""!"
NMessengerPlus2MsgPlus.exe"MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that ""sponsor program""!"
NMessengerPlus3MsgPlus.exe"MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that ""sponsor program""!"
XMicr0s0ft Ms D0smsdx.exe"Added by the RBOT-AON WORM!"
XMICROSFT ANTIVIRUS UPDATE SUPPORTMSGUPDATED.EXE"Added by the RBOT-APZ WORM!"
XMicrosft Conf 32msaconf.exe"Added by the RBOT.EYA WORM!"
XMicrosft Confige 32msaconfigurez.exe"Added by the RBOT.CLC WORM!"
XMicrosft Corporation Version 2002.12.2414comserv.exe"Added by a variant of the SLAPER TROJAN!"
XMICROSFT RAMA UPDATE SUPPORTMSN32.EXE"Added by the RBOT-AWJ WORM!"
XMICROSFT RAMA UPDATE SUPPORTMSGUPDAT32.EXE"Added by the RBOT-BBB WORM!"
XMicrosft Remote Procedure Daemonmsrpcd.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosft Security Monitor Processmssmppp.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosft Security Monitor Processmssmpp.exe"Added by the SDBOT-DJW WORM!"
XMicrosoftssmss.exe"Added by the RBOT-FZF WORM!"
XMicrosoftmsvchost.exe"Added by the RBOT-GAW WORM!"
XMicrosoftmsmsger.exe"Added by a variant of the SDBOT WORM!"
XMicrosoftMSUPDATE.exeAdded by an unidentified WORM or TROJAN!
XMicrosoftmsngerf.exe"Added by the RBOT-GLW WORM!"
XMicrosoftmdms.exe"Added by the AGENT-GHY TROJAN!"
XMicrosoft (R) Windows Network Security Management Servicensms.exe"Added by the RANKY.LC TROJAN!"
XMicrosoft .NET Confinguratormsnconf.exe"Added by an unidentified VIRUS
XMicrosoft Admin ProtocalMSADNIN.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Ansti Updatemsie.exe"Added by the RBOT-LE WORM!"
XMicrosoft Anti Virus Controllermsavc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Anti Virus Controllermsavc32.exe"Added by the SDBOT.EPW BACKDOOR!"
XMicrosoft AOL Instant MessengerMSAOL32.exe"Added by the RBOT-AAI WORM!"
XMicrosoft Application Managermsapl32.exe"Added by the BROPIA-AE TROJAN!"
XMicrosoft AUT UpdateMSlti32.exe"Added by the RBOT-X WORM!"
XMicrosoft AUT UpdateMSlti16.exe"Added by the RBOT.EB WORM!"
XMicrosoft Automatic Update Serivcemsautou.exe"Added by the RBOT-AOB WORM!"
UMicrosoft Broadband NetworkingMSBNTray.exeMicrosoft Broadband Networking Tray Application
XMicrosoft Buffer Appmsbuffer.exe"Added by the SLINBOT.NQ BACKDOOR!"
XMicrosoft checkerMsPMSPTv.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Clientmshost.exe"Added by the RBOT-AND WORM!"
XMicrosoft Clientmsclient.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Configmsconf.exe"Added by the RBOT.PV WORM!"
XMicrosoft ConfigMSCONF.EXE"Added by the RBOT-LG WORM!"
XMicrosoft Config 32msconfigx32.exeReported as the MSCONFIGX32 TROJAN! Possible Rbot variant
XMicrosoft Config 32bitmscnfg32.exe"Added by the RBOT-Z WORM!"
XMicrosoft Config Loadermsconfig32.exe"Added by the AGOBOT.XX WORM!"
XMicrosoft Config Loadermsrun32.exe"Added by the AGOBOT-DY WORM!"
XMicrosoft Config Loadermsconf32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Configoration Servicemsconfigs.exe"Added by the RBOT-ETT WORM!"
XMicrosoft Configs 32msgconfigrs.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Configuewemsconfiguwe.exe"Added by the SDBOT-BPK WORM!"
XMicrosoft Configurationmsconfig32.exe"Added by the SDBOT.MQ WORM!"
XMicrosoft Configure 32msgconfigre.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Core SupportMSxUP32.exe"Added by the RBOT-ANR WORM!"
XMicrosoft Corp TLS Certificatesmsauth.exe"Added by the RBOT-GAC WORM!"
XMicrosoft Corporation Svchost Servicemssvc.exe"Added by a variant of the SDBOT WORM! See here"
XMicrosoft Corporation Svchost Servicemswsc.exeAdded by the AGENT.MAB TROJAN!
XMicrosoft Corporation SYM monitormssym.exe"Added by the RBOT-GDB WORM!"
XMicrosoft CSRSS Servicensmscrs.exe"Added by the RBOT-BPT WORM!"
XMicrosoft Cvrtmscvrt32.exe"Added by an unidentified VIRUS
XMicrosoft Database Handlermssql32.exe"Added by the RANDEX.AX WORM!"
XMicrosoft Datalog Applicationmsdata.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Decryption TechnologyMsfenoe.exe"Added by the SPYBOT-DG WORM!"
XMicrosoft Desktop Managermsdesk32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Development Debuggermsdev.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Development Servicesmsdevelop.exe"Added by the RBOT-FWS WORM!"
XMicrosoft Device Managermsdevmgr32.exe"Added by the LATEDA.B TROJAN!"
XMicrosoft Device Managermscmtl32.exe"Added by the AGENT.BMQ BACKDOOR!"
XMicrosoft Diagnosticmsdiag32.exe"Added by the RBOT-UC WORM!"
XMicrosoft Digital Clockmsclock.exe"Added by the NACKBOT-D WORM!"
XMicrosoft DLL Verifiermscon.exe"Added by the SDBOT.EAH WORM!"
XMicrosoft DNS Querymsdns.exe"Added by the AGENT-BS TROJAN!"
XMicrosoft Domain Controllermstc.exe"Added by the NUGACHE.A WORM!"
XMicrosoft Driver Managermswindrv.exe"Added by the FORBOT-EZ WORM!"
XMicrosoft Driver Setupmsddrv42.exe"Added by the PALEVO WORM!"
XMicrosoft Driver Setupmslsrv32.exe"Added by the SDBOT-DPF TROJAN!"
XMicrosoft driver updateMshome.exeAdded by the SDBOT.BL WORM!
XMicrosoft EV32 ServiceMSev32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Excelmsexcel.exe"Added by the RBOT-TQ WORM!"
XMicrosoft Excelemsmsgs.exe"Added by the AGENT.AJQG TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMicrosoft Explorer Servicemsexplore.exe"Added by the IRCBOT.AYB BACKDOOR!"
XMicrosoft Featuresms32cfg.exe"Added by the RBOT.HO WORM!"
XMicrosoft Featuresmsie.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Genuine Logonmsnmsg.exe"Added by the IRCBOT-XH WORM!"
XMicrosoft Gina V EncryptionMSGINAV.EXE"Added by an unidentified VIRUS
XMicrosoft HDCP for NTmsdhcp.exe"Added by a variant of the RBOT WORM!"
XMicrosoft HDCP for NT and Win9xmsdhcprs.exe"Added by a variant of the PEERBOT WORM!"
XMicrosoft Help Supportmshelp32.exe"Addded by the KELVIR-BF WORM!"
XMicrosoft Help SVCmsnmngr.exe"Added by the SDBOT-PQ WORM!"
XMicrosoft Help Systemmshelp32.exe"CoolWebSearch parasite variant"
XMicrosoft Helpdesk Sidemshelpdsk.exe"Added by the SPYBOT.ANJJ WORM!"
Xmicrosoft hotmail monitormshotmon.exe"Added by the MYTOB-FL WORM!"
XMicrosoft Hyptertext Helpermshtha.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft IDCNmshe1p.exeAdded by an unidentified TROJAN!
XMicrosoft Instant Messengermsngmsngr32.exe"Added by the SPYBOTER.GEN TROJAN!"
XMicrosoft Int ServiceMsIntSrv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Internal AntiVirus SystemsdIlhost.exe"Added by the RBOT-AEV WORM!"
XMicrosoft Internet Explorermsngrt.exe"Added by the SDBOT-GU BACKDOOR!"
XMicrosoft Internet ServicesSmss32.exe"Added by the RBOT.MS WORM!"
XMicrosoft IT Updatemsupdate.exe"Added by the RBOT-FE WORM!"
XMicrosoft Java Virtual MachineMsConfiG.exe"Added by the FORBOT-DV WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
XMicrosoft Java Virtual Machinemsjvm.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Java Virtual Machinemsjavarxp.exe"Added by the FORBOT-DL WORM!"
XMicrosoft JavaVMmsjarun.exe"Added by the RBOT-JW WORM!"
XMicrosoft Kinetik Svcmsftksvc.exe"Added by the AGENT.AGDO TROJAN!"
XMicrosoft LSA layerMSLSA32.exe"Added by the RBOT-AKZ WORM!"
XMicrosoft Macro Protection SubSsymsacroprots386.exe"Added by the RBOT-KE WORM!"
XMicrosoft Macro Protection Subsystemsmsmacroprotxz.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Macro Protection SubsystemsMsmacroprot32.exe"Added by the RBOT.KN WORM!"
XMicrosoft Managermsmanager.exe"Added by the MYTOB.LF WORM!"
XMicrosoft Media player 9msmedia32.exe"Added by the RBOT-ADO WORM!"
XMicrosoft Message Machinemsmesg32.exe"Added by the SPYBOT.BI WORM!"
XMicrosoft Messenger Management Controlsmsmgmctl.exe"Added by the RBOT-APA WORM!"
XMicrosoft messenger sdmsngersd.exeAdded by an unidentified TROJAN!
XMicrosoft Messenger Servicemsmsg32.exe"Added by the RBOT.BOK WORM!"
XMicrosoft Messenger XPMSMSN32.exe"Added by the RBOT-ZP WORM!"
XMicrosoft MSGPLUS32 Protocolmsgplus32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft MSN 7 Servicesmsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft MSN 7 Servicesmsnmsger.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft MSN Messengermsnmnsgr.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Msn Messengermsmsgs.exe"Added by the BUZUS.AYX TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMicrosoft MSN Servicesmsnsm.exe"Added by the RBOT.ARV BACKDOOR!"
XMicrosoft MSNGR32 Protocolmsngr32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft msnserumsnseru.exe"Added by the RBOT-APB WORM!"
XMicrosoft MsnSTmsnst32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft MSUPDATESpoolSvc.exe"Added by the SXTB-A TROJAN!"
XMicrosoft Netviewmssvc32.exe"Added by an unidentified VIRUS
XMicrosoft Netview Component v5.1msnv32.exe"Added by the RANDEX.F WORM!"
XMicrosoft Networkmsnet.exe"Added by the MOCKBOT.A WORM!"
XMicrosoft Network Services Controllermmsvc32.exe"Added by the NANPY-A WORM!"
XMicrosoft Networking Agent For SP2msnac32.exe"Added by the SPYBOT.PEN WORM!"
NMicrosoft OfficeMsoffice.exeFeature included with older versions of MS Office giving you access to common Office functions and optional shortcuts to Office (and other) programs. Some people prefer it but a better way is to create desktop shortcuts if you want access these features and programs quickly. Also available via Start → All Programs
XMicrosoft OfficeMSMSGR.exe"Added by the GAOBOT.BB WORM!"
XMicrosoft Officemsoicons.exe"Added by the RBOT-ZI WORM! - NOTE - do no confuse with the legitimate Msoicons.exe file described here. The latter wil not be listed among your startups!"
XMicrosoft Officemsoffice32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Officemsoff.exe"Added by the RAKER-C TROJAN!"
XMicrosoft Officemsvcp.exe"Added by the AGENT-XK TROJAN!"
XMicrosoft Officemsmsgr.exe"Added by the GAOBOT.BB WORM!"
NMicrosoft Office Shortcut BarMsoffice.exeFeature included with older versions of MS Office giving you access to common Office functions and optional shortcuts to Office (and other) programs. Some people prefer it but a better way is to create desktop shortcuts if you want access these features and programs quickly. Also available via Start → All Programs
XMicrosoft Ofticemsmsgs.exe"Added by the IRCBOT.ALT WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMicrosoft PCI Managermspci.exe"Added by the RBOT.BBG WORM!"
XMicrosoft Proc Driver32msprc.exe"Added by a variant of the WOOTBOT WORM!"
XMicrosoft Procedure CallMSPCALL.exe"Added by a variant of the RBOT WORM!"
XMicrosoft QMGRmsnqmgr.exe"Added by the IRCBOT-S TROJAN!"
XMicroSoft Remote Secure ServiceMSRSS.exe"Added by a variant of the RBOT WORM!"
XMicrosoft SDKP3mswinsdq.exe"Added by the RBOT-ARY WORM!"
XMicrosoft security advisermssadv.exe"Microsoft Security Adviser rogue security software - not recommended"
YMicrosoft Security Essentialsmsseces.exe"System Tray access to a notifications from Microsoft Security Essentials which ""provides real-time protection for your home PC that guards against viruses
XMicrosoft Security Hot Fix Updatemshotfix.exe"Affilred adware"
XMicrosoft Security Monitor Processmssmp.exe"Added by the RBOT-FUB WORM!"
XMicrosoft Security Monitor Processmsmp.exe"Added by the RBOT.GKQ WORM!"
XMicrosoft Security Monitor Processmssm32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Security Monitor Processmsword.exe"Added by the VIRUT.P VIRUS!"
XMicrosoft Security Monitor Processmssm32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processmssmpi32.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Security Systemmssecsys.exe"Added by the IRCBOT-WJ TROJAN!"
XMicrosoft Server Applacationsmsnmsg.exe"Added by the AGOBOT.BBM WORM!"
XMicrosoft Service 32mssvc32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service Informationmsnservices.exe"Added by the RBOT.ID WORM!"
XMicrosoft Service ToolsMStools1.exe"Added by the RBOT-BHT WORM!"
XMicrosoft ServicesSmss32.exe"Added by the RBOT-AD WORM!"
XMicrosoft Servicesmsmpserv.exe"Added by the IRCBOT.BKA BACKDOOR!"
XMicrosoft Services UnitdMSU32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Session Manager Subsystemsmss.exe"Added by the KALEL-D WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
NMicrosoft Sound Volume Toolmssvol.exeThis is a Blue version of the yellow speaker icon on the system tray and is used to edit advanced Sound Features that the MS DSS80 Speakers add. Should be accessible via Start -> Settings -> Control Panel
XMicrosoft SpA Servicemsapps.exe"Added by the RBOT-VI WORM!"
XMicrosoft Supportsys32ms.exe"Added by the RBOT-AHI WORM!"
XMicrosoft SVCmssvc.exe"Added by the BIFROSE-UQ TROJAN!"
XMicrosoft Svchost local servicesmsnserver.exe"Added by the RBOT-GPM WORM!"
XMicroSoft sys32sysmsgr32.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Systemmsupdtm.exe"Added by the SPYBOT.PKC WORM!"
XMicrosoft Systemmssys32.exe"Added by the PETTICK.A WORM!"
NMicrosoft System Configuration Utilitymsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
XMicrosoft System Firewall 2006.2msmsgr.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft System Firewall 2006.2msnmsgr.exe"Added by a variant of the SDBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMicrosoft System Security AgentMSTSA.EXE"Added by the RBOT.CCM WORM!"
XMicrosoft System Service Devicemssdh.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft System Servicesmsnmgsr.exe"Added by the KELVIR.K WORM!"
XMicrosoft System Servicesmsmsgr.exe"Added by the RBOT-ZH WORM!"
XMicrosoft System32 Updatecmsrg.exe"Added by the RBOT-GN WORM!"
XMicrosoft Telecoms Centertelcoms.exe"Added by the IRCBOT.GEN WORM!"
XMicrosoft Telecoms Centerxpfilesys.exeAdded by the RBOT.BCJ TROJAN!
XMicrosoft Telecoms Centerwinupn.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Telecoms Centersvcchost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft TTL Verifiermsttl.exe"Added by the RBOT-GAP WORM!"
XMicrosoft UMA UpdateMSuma32.exe"Added by the RBOT.FS WORM!"
XMicrosoft Updat3mswkst32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatemssmgrd.exe"Added by the SDBOT.JT WORM!"
XMicrosoft Updatemsconfg.exe"Added by the RBOT.H WORM!"
XMicrosoft UpdateMslti32.exe"Added by the RBOT-LX WORM!"
XMicrosoft UpdateSmss32.exe"Added by the RBOT-CB WORM!"
XMicrosoft Updatemsawindows.exe"Added by the GAOBOT.AFJ WORM!"
XMicrosoft Updatemsiwin84.exe"Added by the GAOBOT.AFJ WORM!"
XMicrosoft Updatemsupdate32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft UpdateMsnmsngr.exe"Added by the RBOT.BQS WORM!"
XMicrosoft Updatemsupdate32.exe"Added by the SPYBOT.LZ WORM!"
XMicrosoft Updatems.exe"Added by the SDBOT.CC WORM!"
XMicrosoft Updatewuagmsd.exe"Added by the RBOT-AX WORM!"
XMicrosoft Updatecmss.exe"Added by the RBOT-ATQ WORM!"
XMicrosoft Updatemsupdate.exe"Added by the BOROBOT-I TROJAN!"
XMicrosoft Updatemsnmsgl.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Updatemsgn.exe"Added by the RBOT.RQ BACKDOOR!"
XMicrosoft Update 32MSupdate32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Update 32mscnfg.exe"Added by the RBOT-ALM WORM!"
XMicrosoft Update 32mssetup32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update ControlMs64.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinememstat.exe"Added by the RBOT-OM WORM!"
XMicrosoft Update MachineWinmsixp32.exe"Added by the RBOT.DN WORM!"
XMicrosoft Update Machinesystemse.exe"Added by the RBOT-BD WORM!"
XMicrosoft Update MachineTMEMSER.EXE"Added by the RBOT-NQ WORM!"
XMicrosoft Update MachineMSOICONS.EXE"Added by the RBOT.AWS WORM! Note - do no confuse with the legitimate Msoicons.exe file described here. The latter should not normally figure in Msconfig/Startup!"
XMicrosoft Update Machinepsmszw.exe"Added by the KOLABC.CC WORM!"
XMicrosoft Update Security Patchmssecurityupdatepatch.exeAdded by the AGENT.EF TROJAN!
XMicrosoft Update Servermssrv.exe"Added by an unidentified VIRUS
XMicrosoft Update Servicemswin32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Update Servicemsupdate.pif"Added by the RBOT-AQB WORM!"
XMicrosoft Updatermsconsole.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft upnp Updatemsie.exe"Added by the RBOT-LQ WORM!"
XMicrosoft USB2 Drivercrmss.exe"Added by the RBOT-VK WORM!"
XMicrosoft VertupdateMSvert32.exe"Added by the MYTOB-CY WORM!"
XMicrosoft Video Capture ControlsMSsrvs32.exe"Added by the SDBOT-AAK WORM!"
XMicrosoft Video Controlstskmsgr.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Virual Machinesms.exe"Added by the RBOT-SP WORM!"
XMicrosoft web updatewebmsn.exe"Added by the RBOT-EMQ WORM!"
XMicrosoft Win Corp TLS Verificationmswintls.exe"Added by the RBOT-GCT WORM!"
XMicrosoft WIN32 DOSMSdos32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft WIN32 SecurityMSsec32.exe"Added by the RBOT-DOQ TROJAN!"
XMicrosoft Windowsmstask0.exe"Added by the SDBOT.FQ WORM!"
XMicrosoft Windows 16Bitmswinn16.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Windows 32Bitmswinn32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows 64 Bitmswin32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Client Firewallmsclt.exe"Added by the VANEBOT-F WORM!"
XMicrosoft Windows Controlmswctl32.exe"Added by the RBOT.JP WORM!"
XMicrosoft Windows DLL 32-BITmsncheck32.exe"Added by the SDBOT-XX WORM!"
XMicrosoft Windows Game Updatermsgame32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows GUImsmonk32.exe"Added by the SDBOT-PE WORM!"
XMicrosoft Windows Servicesmsw32.exe"Added by the RBOT-FWQ WORM!"
XMicrosoft Windows Session Manager Subsystemsmss.exe"Added by the PROXYSER-R TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Windows Storage Machine Servicewinms.exe"Added by the RBOT-AHK WORM!"
XMicrosoft Windows Task Managementmstasks.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Task MangerMstosk.exe"Added by the SDBOT-WW WORM!"
XMicrosoft Windows Updatemsoffice2.exe"Added by the RBOT-GB WORM!"
XMicrosoft Windows Updatemsnmessenger.exe"Added by the SDBOT.AJ WORM!"
XMicrosoft Windows Updatemsnwun.exe"Added by the SDBOT-RM WORM!"
XMicrosoft Windows UpdateMSNMSGR.EXE"Added by the SDBOT-WM WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMicrosoft Windows Update Servicemsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Windows Updatermsnupdateit.exe"Added by the AGOBOT-RL WORM!"
XMicrosoft Windows Updating Systemmsresource.exe"Added by the RBOT-EAM WORM!"
XMicrosoft Windows Visual V2.0msiutil.exe"Added by the DELF.JPH TROJAN!"
XMicrosoft Windows W32 Servicesmssw32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Windows WKS Servicemstask0.exe"Added by the SDBOT.FV WORM!"
XMicrosoft Winsockmswinsck.exe"Added by the RBOT-ANK WORM!"
XMicrosoft Winsock Servicemsusvc.exe"Added by the RBOT-ANS WORM!"
XMicrosoft WinUpdatemsupdte.exe"Added by an unidentified TROJAN! See examples here & here"
XMicrosoft WMmswm32.exe"Added by the BCKDR-AM BACKDOOR!"
XMicrosoft XML Servicemsxmlx.exe"Added by the RBOT.KS WORM!"
XMicrosoft Xp Systems loaderwinsystem32xp.exe"Added by the KELVIR.W WORM!"
XMicrosoft Xp Systems loaderswin32xpsys.exe"Added by the SPYBOT.NYT WORM!"
XMicrosoftCorpmsnrmgs.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoftf DDEs Controlmsnn.exe"Added by the RBOT-AXT WORM!"
XMicrosoftMessengermsnserv.exe"Added by the DARKER.M WORM!"
XMicrosoftmsn32.exemicrosoftmsn32.exe"Added by the CERTIF-C TROJAN!"
XMicrosoftNAPCmsnrmgs.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicroSoftRunMSCOMM.dll"Added by the AGENT-DJG TROJAN!"
XMicrosofts Help Servicesmsnmngr.exe"Added by the SDBOT-PJ WORM!"
XMicrosofts Updatezcmsssr.exe"Added by an unidentified VIRUS
XMicrosoftServiceManagermstask32.exe"Added by the YAHA.P WORM!"
XMicrosoftServiceManagermsupdat.exe"Added by the YAHA.AA WORM!"
XMicrsoft Drivermsdriver.exe"Added by the SDBOT-XD WORM!"
XMiosf Updatewimsqaad.exe"Added by the SDBOT.AG TROJAN!"
XMircosoft Sockets SP2mssck.exe"Added by the MYTOB.ET WORM!"
Xmloadlxmstart.exe"Added by an unidentified VIRUS
Xmmsassmmdmm.exe"Added by the SDBOT.SO WORM!"
Xmmsddlx[random filename]"Added by a variant of the SLAPER TROJAN!"
?mmsysrecover.exe"??"
XMMSystem"rundll32.exe mmsystem.dll RunDll32"
Xmmxrunmsosa.exeAdded by an unidentified TROJAN or WORM!
Xmmxrunmswinindex.exe"TwoSeven spyware"
NModemUtilitymdmsetpe.exeSystem Tray configuration icon for Aztech modems
XMoreContent"rundll32.exe MSA64CHK.dllDllMostrar"
Xmousedrive.exeinstantmsgrs.exe"Added by the FORBOT-ER WORM!"
NMovielink Manager Uninstallmsvcmm32.exe"Auto-update for Movielink - internet movie rental System Tray access"
XMP3Collection"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3download"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3files"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3freeDownload"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3freeDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3nice"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3Themes"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3ToTheMax"rundll32.exe MSA64CHK.dllDllMostrar"
XMPR MSGmprmsg32.exe"Added by the MYTOB.CF WORM!"
UMPSExemscifapp.exeMcAfee.com Privacy Service - "combines personal identifiable information (PII) protection with online advertisement blocking and content filtering"
Xmssvhost32.exe"Added by the LEGMIR-AQO TROJAN!"
XMS Agent Protectionag1.exe"Added by the IRCBOT.AZ BACKDOOR!"
XMS AntiSpyware 2009msas2009.exe"MS AntiSpyware 2009 rogue spyware remover - not recommended
XMS Auto-IPSec ProtectionMSASP32.exe"Added by the RBOT-AER WORM!"
XMS Autoloader 32MSAuto32.exe"Added by the SPYBOT.BD WORM!"
XMs BuildersWupated.exe"Added by the AGOBOT-SS WORM!"
XMS Configmsdconfig.exe"Added by the RBOT-CZH WORM!"
XMS Config Loadersvchos1.exe"Added by the AGOBOT.R WORM!"
XMS Config LoaderMSWin32bck.exe"Added by the GAOBOT.AA WORM!"
XMS Config Loadersvcrhost.exe"Added by a variant of the RBOT WORM!"
XMS Config ServiceMsloader32.exe"Added by the RBOT-KJ WORM!"
XMS Config Streammsasm.exe"Added by the AGOBOT-BA WORM!"
XMS Config v12mscfg12.exe"Added by the AGOBOT.YP WORM!"
XMS Config v13lrbz32.exe"Added by the GAOBOT.AOL WORM!"
XMS Config v13mscfg13.exe"Added by the AGOBOT.YQ WORM!"
XMs configsumsconfigsu.exe"Added by a variant of the SDBOT WORM!"
XMS ConfigurationMSFramer.exe"Added by the RANDEX.OL WORM!"
XMs Configurationmicrosoftsa32.exe"Added by the KELVIR.X WORM!"
XMS Configuration Utilitymsconfig32.exe"Added by the WOOTBOT.DY WORM!"
XMS DATABASEMSDATA32.EXE"Added by a variant of the SDBOT WORM!"
XMS Decryption Softwareactive.exe"MediaTickets adware variant"
XMS DirectX Sound Driversmsdrvdx.exe"Added by the RBOT.BCX WORM!"
XMS DLL Library Managerdllsys64.exe"Added by the RANKY TROJAN!"
XMS Domain Name Server DeamonMSDNSD32.exe"Added by the RBOT-CMZ WORM!"
XMS Domain Name SystemMSWDNS32.exe"Added by the RBOT-GKY WORM!"
XMS DVD DirectX Dll Driversmdxdl.exe"Added by the SDBOT-XI WORM!"
XMS DVD DirectX Sound Driversmsdrvdx.exe"Added by the SDBOT-XJ WORM!"
XMS Explorermexplore.exe"Added by the YAHA.AE WORM!"
XMS FIREWALLmsfrewall.exe"Added by the SDBOT-PU WORM!"
XMS FIREWALLmsfirewall.exe"Added by the SDBOT-QH WORM!"
XMS Hostmsthost.exe"Added by the SLENFBOT.AH WORM!"
XMS Host Managerivhost.exe"Added by the RBOT-BJN WORM!"
XMS Hostsmsthosts.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMS HTMLmsHtml.exe"Added by the PESTDOOR.31 TROJAN!"
XMS HTMLmslat.exe"Added by the LATINUS.SVR TROJAN!"
XMS HTML Location ClassMSHTML32.exe"Added by the RBOT-YD WORM!"
XMS Initialmstinitial.exe"Added by the IRCBOT.ASP BACKDOOR!"
XMS Internet Executor 32MSIXEC32.exe"Added by the RBOT-AEQ WORM!"
XMS Internet ExploreMSIEx.exe"Added by a variant of the RBOT WORM!"
XMS Java Applets for Windows NT & XPjavaapplet.exe"Added by the RBOT.BHG WORM!"
XMs Java for Windows NTMS32.exe"Added by the VANEBOT-H WORM!"
XMs Java for Windows NTmsi32java.exe"Added by the VANEBOT-I WORM!"
XMs Java for Windows NTmsjava.exe"Added by the VANEBOT-E WORM!"
XMs Java for Windows NTmsi32info.exe"Added by the RBOT.AFX WORM!"
XMS Java for Windows XP & NTjavanet.exe"Added by the VANEBOT-A WORM!"
XMS Java Service Wrapper Windows NT & XPwrapper.exe"Added by the VANEBOT-D WORM!"
XMs Java Update For Windows NT/XPmsijavaupdt32.exe"Added by the RANDEX.AF WORM!"
XMS Java virtual machinejavavm.exe"Added by the RBOT.ABG WORM!"
XMS LARISSAMS_LARISSA.exe"Added by the ASSIRAL.B WORM!"
XMS lsass Startuplsass135.exe"Added by the RBOT.WM WORM!"
?MS management consolemms.exe"Suspicious as the legitimate ""Microsoft Management Console"" is ""mmc.exe"" and not ""mms.exe"" and doesn't normally run at startup"
XMS Microsoft Socket DeamonMSSCKD32.exe"Added by a variant of the RBOT WORM!"
XMS MSN Menssenger 7.0MSMSN7.exe"Added by the RBOT-ACA WORM!"
XMS MSN Menssenger 7.0MSEXPORT.exe"Added by a variant of the SDBOT WORM!"
XMS Network Controlmswin.exe"Added by the DUMBA TROJAN!"
XMS OfficeOffice10.exe"Added by the VB.DT TROJAN!"
Xms ownagewinPE.exe"Added by the RBOT-AJL WORM!"
XMS Paintmspainter.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMS PLUS INCwpad.exe"Added by the MYTOB-AN WORM!"
XMs Processe Managermsproc.exe"Added by the RBOT.ATO WORM!"
XMS Real PlayerRealPlyr.exe"Added by the RBOT.MR WORM!"
XMS Registry ServiceMSRMS32.exe"Added by the RBOT-AKP WORM!"
XMS Remote Procedure Callmsrpc32.exe"Added by the RBOT-QL WORM!"
XMS Screen Saverscrsave.scr"Added by the RBOT-AGT WORM!"
XMS Securitysystm.pif"Added by the RBOT-AQN WORM!"
XMS Security Authority Servicelsass.exe"Added by the KALEL-B WORM! Note - this is not the legitimate lsass.exe process
XMS Security Hotfixservice5.exe"Added by the GAOBOT.AG WORM!"
XMS Security Update 993msident.exe"Added by a variant of the SDBOT WORM!"
XMS servicemsservice.exe"Added by the RBOT-ZG WORM!"
XMS Service Driverswinscv.exe"Added by the SDBOT-COG WORM!"
XMs sock for Windows NTwinser.exe"Added by a variant of the SDBOT WORM!"
XMS Sound Config 16bitsndcfg16.exe"Added by the SDBOT.MB TROJAN!"
XMs Sound Driversmsdrv.exe"Added by the SDBOT-WR WORM!"
Xms spool servicemsspooler.exe"Added by a variant of the RBOT WORM!"
XMs Spool32MS SPOOL32.EXE"Added by the ASASSIN TROJAN!"
XMS SyS Restoresysrestore.exe"Added by the RBOT.XM WORM!"
XMS Sys Securitymswin.pif"Added by the RBOT-APJ WORM!"
XMS System Call Functionmsscf32.exe"Added by the RBOT-GBZ WORM!"
XMs System ConfigMscfg.exe"Added by the SDBOT-CCR WORM!"
XMs System Configpcedit.exe"Added by a variant of the SDBOT WORM!"
XMS System Securitymswin32.pif"Added by the RBOT-AOX WORM!"
XMs task managertskmgr.exe"Added by the SDBOT.CCD WORM!"
XMS Task Manager 32[trojan filename] .exe"Added by the RANKY.NF TROJAN!"
XMS taskbarcrssr.exe"Added by the RBOT-AGO WORM!"
XMS taskbarnts.exe"Added by the RBOT-AGB WORM!"
XMS taskbartaskbars.exe"Added by the RBOT.BRW WORM!"
XMS Taskbarstaskbars.exe"Added by the SDBOT-ACV WORM!"
XMS taskmanagertskmgr.exe"Added by the RBOT-AKA WORM!"
XMS Timetimezone.exe"Added by the AGOBOT.ADY WORM!"
XMS UniXnavupdate64.exe"Added by the RBOT.CRZ BACKDOOR!"
XMS Unix Binarywin32ttb.exe"Added by the SPYBOT.OQ WORM!"
XMS Unix Binarymsmq2inst.exe"Added by the RBOT-YF WORM!"
XMS Unix Binarymsnupdate.exe"Added by the RBOT-AAM WORM!"
XMS Unix Binaryoutlookexpressupdate.exe"Added by the RBOT-YU WORM!"
XMS Unix BinaryWin32Update.exe"Added by the RBOT-BAS WORM!"
XMS Unix BinaryNorton2005Update.exe"Added by a variant of the RBOT WORM!"
XMS Unix Binarytrmupdate.exe"Added by the RBOT-ACC WORM!"
XMS Unix BinaryWinGuard.exe"Added by the RBOT-ACL WORM!"
XMS Unix Binarymsnq3insller.exe"Added by the RBOT.GXH BACKDOOR!"
XMS Updatesyshost.exe"Added by the EVAMAN-F WORM!"
XMs Update WinServices NT/XPwinservnt32.exe"Added by the VANEBOT-G WORM!"
XMS UPDATERupdate.exe"Added by the RBOT-VC WORM!"
XMS Updatesmscache.exeSpyware web downloader
XMS Updatessyshosts.exe"Added by the MYDOOM.Y WORM!"
XMS Updatesaupd.exeSpyware web downloader
XMS Updating Utilitymsupdater.exe"Added by the RBOT-XR WORM!"
XMS USB 2.0 Windows Supportmsusb32.exe"Added by a variant of the RBOT WORM!"
XMs Valud LoaderSvhots.exe"Added by the AGOBOT-SP WORM!"
XMS Win32 Network Serviceswindriver.exe"Added by the AGOBOT.ADH WORM!"
Xms window update******.exe [* = random character]"Added by a variant of the RBOT WORM!"
XMS Windows AOL DriverMSAOLdrv.exe"Added by the RBOT-ASP WORM!"
XMS windows Data list processMSDATLST.exeAdded by an unidentified WORM or TROJAN!
XMS Windows Executor ProcessMSEXECP32.exe"Added by a variant of the RBOT WORM!"
XMS Windows Local DirectoryMSWLD32.exe"Added by a variant of the RBOT WORM!"
XMS Windows procces 32msprocces.exe"Added by the RBOT-AEZ WORM!"
XMS Windows Process ClassMSPRCSS32.exe"Added by the RBOT-YQ WORM!"
XMS Windows Process InitMSWPI32.exe"Added by the RBOT-ASQ WORM!"
XMS Windows Security Updaterupdater.pif"Added by the RBOT-AKY WORM!"
XMS Windows System AlertMSWSA32.exe"Added by the RBOT-BFN WORM!"
XMS Windows TASK ServiceMSWTASK32.exe"Added by a variant of the RBOT WORM!"
XMS Windows Updatescguard.exe"Added by the RBOT-YZ WORM!"
XMS WINS Binaryign32.pif"Added by the RBOT-ASB WORM!"
XMS Winsockmsws2_32.exe"Added by the AKBOT-A TROJAN!"
Xms************* [* = random digit]ms*************.exe [* = random digit]"WINBO adware"
XMs**.exe [* = random char]Ms**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XMs**32.exe [* = random char]Ms**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XMS-Connectarr.exe"Adult content dialler - see here"
XMS-Connectcdm.exe"Adult content dialler - see here"
XMS-Connectgame.exe"Adult content dialler - see here"
XMS-Connectmsite18.exe"Adult content dialler - see here"
XMS-Connectweb.exe"Adult content dialler - see here"
XMS-DOS Boot ServiceBoot32.pif"Added by the RBOT-AMF WORM!"
XMS-DOS Security Servicems-dos.pif"Added by the RBOT-AMR WORM!"
XMS-DOS ServiceMS-DOS.pif"Added by the RBOT-AII WORM!"
XMS-DOS Windows ServiceMS-DOS.PIF"Added by the RBOT-AJW WORM!"
XMS-HTML[random filename]"Added by the LATINUS.15 TROJAN!"
XMS-patchmsconfig32.exe"Added by the RBOT-AUF WORM!"
XMS-patchmspatch32.exe"Added by the RBOT-AWF TROJAN!"
XMS-RunKeyarr.exeMS-Connect dialler/hijacker
Xms2srcms2src.exe"Added by a TROJAN - see here"
XMS32DLLachi.dll.vbs"Added by the ACHI-A TROJAN!"
XMS32DLLBha.dll.vbs"Added by the BUTSUR-A WORM!"
XMS32DLLMS32DLL.dll.vbs"Added by the ZODGILA WORM!"
XMS32DLLffqca.exe"Added by the SDBOT-YD WORM!"
XMS7531ms7531.exeHomepage hijacker
XMSACMmsacm.exe"Added by the OPASERV-O WORM!"
Xmsadcheckmsadcheck32.exe"Browser hijacker
XMSAdminjdbgmrg.exe"Added by the DASMIN.A TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here"
XMSAgentmshtm.exeBrowser hijacker - redirecting to buldog-search.com
XMSAgenthhnt.exe"AGENT.JI spyware"
XMSAgentXPMSAgentXP.exeIdentified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the REQLOOK.C TROJAN!
Umsaimmsaolim.exe"MessageSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
Xmsappts32msappts32.exe"Added by the ELBURRO-A TROJAN!"
YMSASCuiMSASCui.exe"Main user interface for Microsoft's Windows Defender on XP/Vista - which ""helps protect your computer against pop-ups
XMsAudioexplorer.exe"Added by the LEGMIR-BY TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMsAudio"MsVM_STI.EXE RunDll32 cmicnfg.cpl CMICtrlWnd"
Xmsavsc.exemsavsc.exe"Added by the AGENT.ANQ TROJAN!"
XMSbackupsbackups.exe"Added by the BANLOAD-TL TROJAN!"
Xmsbbmsbb.exe"180Search adware"
XMsbb.exeMsbb.exe"Added by the SDBOT.QJ WORM!"
Xmsbcsmsbcs.exe"Added by the DADOBRA-G TROJAN!"
XMsBootMgr.exeMsBootMgr.exe"Added by the VERIFY TROJAN!"
Xmsbsc[path to trojan]"Added by the BANKER-DF TROJAN!"
Xmscmsc.exe"MaCatte Antivirus 2009 rogue security software - not recommended
Xmsccrtmsccrt.exe"Added by the PWS-ALA TROJAN!"
Xmscheckrundll32.exe wincheck071008.dll mymain"Added by the AGENT.ADXI TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""wincheck071008.dll"" file is located in %System%"
Xmschkdf.exemschkdf.exe"Added by a variant of the SDBOT WORM!"
XMSChoExEsuge.exe"Added by a variant of the RBOT WORM!"
?mscimcinfo.exe"McAfee Internet Security related. What does it do and is it required?"
Xmsclacmsclac.exe"Added by the SDBOT-JM WORM!"
Xmscleanmsvchost.exe"Added by the OPANKI-Q WORM!"
Xmscmanmscman.exe"ClientMan parasite variant"
Xmscmsmscms.exe"Added by the AGENT-MS TROJAN!"
Umscnmscn.exePart of the SafeChildNet internet filtering program - required if you use it
XMscntmscnt.exe"Added by the DLUCA-C TROJAN!"
XMscolourmscolour.exe"Added by the GEMA TROJAN!"
XMSCommXmscommx.exe"Added by a variant of the RBOT WORM!"
XMsconf32Msconf32.exe"Added by the AGOBOT-NR WORM!"
XMSCONFG32.EXEMSCONFG32.EXE"Added by the OPTIX.04.C TROJAN!"
NMSConfigmsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
XMSConfigMSCONFIG32.EXE"Added by the SPYBOT.B WORM!"
Xmsconfigmsconfig.exe"CoolWebSearch MSConfig parasite variant. Note - this overwrites the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
Xmsconfigmsconfig.exe"Added by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrun"
Xmsconfigwins.exe"Added by the RBOT.PF WORM!"
XMSConfigMSCONFIG35.EXE"Added by a variant of the SPYBOT WORM!"
Xmsconfigscvhost.exe"Added by the AGENT-DSF TROJAN!"
Xmsconfigwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
XMsconfigicpldrvx.exe"Added by the BANLOAD.BFT TROJAN!"
Xmsconfigmsconfig.com"Added by the IRCBOT-SM WORM!"
Xmsconfigmsconfig.bat"Added by the PAHATIA.B WORM!"
XMSConfiglssas.exe"Added by the AUTORUN.CEY WORM!"
XMSConfigxwpwqf.exe"Added by the AGENT-NEW TROJAN!"
XMsconfig lptt01msconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
XMSConfig Managermsupdate.exe"CoolWebSearch parasite variant"
XMsconfig ml097emsconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
Xmsconfig serviceMSupdate32.exe"Added by a variant of the SPYBOT WORM!"
Xmsconfig.msconf.exe"Added by the BUZUS-AY WORM!"
Xmsconfig.exeproxy.exeAdded by a variant of the AGENT.AH downloader TROJAN!
Xmsconfig.exeuline.exeAdded by a variant of the AGENT.AH downloader TROJAN!
Xmsconfig38mssvcc.exe"Added by the RBOT-BJV WORM!"
XMSConfig45MSConfig45.exe"Added by the SDBOT.OJ TROJAN!"
XMSConfigrjdbgmrg.exe"Added by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here"
NMSConfigRemindermsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. This particular entry is specific only to 98/Me and is located in %System%
XMsConfigsMsConfigs.exe"Added by the ALCAN.A WORM!"
XMSConfigsRUNDLL64.dll.vbs"Added by the WEKODE-B WORM!"
Xmsconfiguratorctfsdk.exe"Added by the DELF-ALS TROJAN!"
XMSControl28crsss.exe"Added by the SPYBOT.AJX WORM!"
XMSControl31winnsyst.exe"Added by the RBOT.CFY WORM!"
XMSControl3d1isasse.exe"Added by the RBOT.CGU WORM!"
XMSCOREsyscnfg.exe"Added by an unidentified VIRUS
?MSCRMStartupMicrosoft.Crm.Application.Hoster.exe"Related to Microsoft Dynamics CRM integrated solutions for Financial
XMscsgsMSCSGS.EXE"Added by the ZEZER WORM!"
XMscsgs32MSCSGS32.EXE"Added by the ZEZER WORM!"
Xmscsvc.exemscsvc.exe"Added by the BANCOS.T TROJAN!"
Xmsctfg32msctfg32.exe"Added by the RBOT-TJ WORM!"
Xmsctrl.exemsctrl.exe"Microsoft Security Adviser rogue security software - not recommended"
XMsctrl32Msctrl32.scr"Added by the REDIST WORM!"
XMSCVTMSCVT.exe"Added by the SLIDESHOW WORM!"
XMSDatablavadasq.exe"Added by the LIOTEN.IK WORM!"
Xmsdbgm.exemsdbgm.exe"Added by the CIMUZ-CQ TROJAN!"
XMSDcomMSDcom.exe"Added by a variant of the SDBOT WORM!"
Xmsdefendermsdefender.exe"Identified as a variant of the PAKES.CMD TROJAN! See here for an example"
Xmsdefender.exemsdefender.exe"Added by the PAKES.ZL TROJAN!"
Xmsdevmsdev.exe"Added by the FORBOT-CR WORM!"
Xmsdevmsconfig.exe"Added by the AGOBOT.AAU WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
Xmsdev controlmsdevctrl.exe"Added by the SPYBOT.N BACKDOOR!"
Xmsdir32msdir32.bat"Added by the ROOKIE-A TROJAN!"
Xmsdirect.exemsdirect.exe"Added by the CERTIF-L TROJAN!"
XMSDLLsyscnfg.exe"Added by an unidentified VIRUS
XMsdmxmmsdmxm.exe"Added by the DLUCA-DC TROJAN!"
XMSDNnese.exeAdded by the SDBOT.AHY WORM!
XMSDN for Windows NTmsdn.exe"Added by a variant of the RBOT WORM!"
XMSDN for Windows NT & WinXPmsdnxp.exe"Added by the IRCBOT-PE WORM!"
XMSDN for Windows with NT'smsdn-nt.exe"Added by the RBOT-EWD WORM!"
XMSDN HELPmsdn.exe"Added by the AGOBOT.AIB WORM!"
XMSDNMess[path to trojan]"Added by the RANKY.BA TROJAN!"
XMSDNNhelp.exe"Added by the AGENT-GBK TROJAN!"
XMSDOS Security Servicemsdos.pif"Added by the RBOT-AMP WORM!"
XMSDOS ServiceMSDOS.PIF"Added by the RBOT-AIY WORM!"
XMSDOS Windows ServiceMSDOS.PIF"Added by the RBOT-AKF WORM!"
XMsdos32Msdos32.pif"Added by the RECORY WORM!"
Xmsdos423msdos423.exe"Added by the MENACE.A WORM!"
XMSDosdrvmsdosdrv.exe"Added by the BACROS WORM!"
XMSDriverundll32.exe drvkoc.dll"Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvmod.dll"" file is found in %System%"
XMSDriverundll32.exe drvmod.dll"Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvmod.dll"" file is found in %System%"
XMSDriverundll32.exe drvsoh.dll"Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvmod.dll"" file is found in %System%"
XMSDRVNetFilter.exe"Added by the INTERRUPDATE TROJAN!"
Xmsdrvctrlmsdrvctrl.exe"Added by the VIDCACH-A TROJAN!"
NMSDTCmsdtc.exeMS Distributed Transaction Coordinator - handles transactions across multiple servers and is installed by MS Personal Web Server and MS SQL Server
XMsemu32Msemu32.exeUnidentified spyware/adware/hijacker
Xmsenngerl4m3r.exe"Added by the PROGENT-AF TROJAN!"
Xmsenngerournik.com"Added by the IRCFLOOD.AL BACKDOOR!"
Xmservseres.exe"Added by the AGENT-LIL WORM!"
Xmservices.exemservices.exe"Added by the SDBOT.WJ WORM!"
Xmsetsvchost.exe"Added by the BIZEX-F TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""mset"" sub-directory"
XMsfindMsfind.exe"CoolWebSearch parasite variant"
XMSFind32msfind32.exe"Added by the CAYAM WORM!"
Xmsfindosa.exemsfindosa.exe"Added by the DOWNLOADER-BS TROJAN!"
XMSFTP Service Configr3grun.exe"Added by a variant of the SDBOT WORM!"
Xmsfw.exemsfw.exe"Microsoft Security Adviser rogue security software - not recommended"
XMSFWAVTSMFTPDev.exe"Added by the RBOT-ACF WORM!"
XMsg Fixagemsgfixed.exe"Added by the SDBOT.ZD WORM!"
XMsgApi[path to file]"Added by the DEDLER-D TROJAN! The most common filenames seen are ""csmss.exe"" and ""csmrs.exe""
Xmsgb1msgb1.exeAdded by the DLUCA.GEN TROJAN!
NMsgCenterExeRealOneMessageCenter.exe"RealNetworks RealPlayer related - disabling this application will not affect Real Player in any way"
Xmsgex32msgex32.exe"Added by the APPFLET-A WORM!"
Xmsginawuauclt2.exe"Added by the IYUS-H TROJAN!"
XMsgmgr[path to worm]"Added by the BABYBEAR WORM!"
Xmsgmsgsperemption.exe"Added by the SDBOT-KU WORM!"
Xmsgserv_Syss.exe"Added by the FANTA TROJAN!"
Xmsgsm32msgsm32.exe"Added by the RBOT-ASG WORM!"
XMsgsrv16Msgsrv16.exe"Added by the DELF family of TROJANS!"
YMSGSRV32.exemsgsrv32.exe"Windows 32-bit VxD Message Server. For more information on its function and why it's needed
XMsgsvc32[worm filename]"Added by the NAUTICAL-A WORM!"
XMsgSvcMgr32cmdzxdll.exe"Added by the RBOT-AEK WORM!"
Xmsgsvr32msgsvr32.exe"Added by the DEADHAT.B WORM! Note - this is not the legitimate msgsvr32.exe process on a Win9x/Me system which should not appear in MSConfig/startup!"
UMSGTAGMSGTAG.exe"MSGTAG is an application that tells you when your emails have been received and opened"
XMsgtraysys16.exeAdded by an unknown VIRUS!
XMshelp32mshelp32.exe"CoolWebSearch parasite variant"
Xmshmailmshmail.exe"Added by the INJECT.JDT TROJAN!"
XMshostsMshosts.exe"Added by the STARTPAG.CF TROJAN!"
XMSHT@MSHT@.EXE"Added by the MAGISTR.A VIRUS!"
Xmshtmllmshtmll.dll"Added by the DELF.BAS TROJAN!"
XMSI Configurationmsiconf.exe"Added by the AGENT.AKSZ TROJAN!"
Xmsiconf.exemsiconf.exeAdded by a variant of the FAKEALERT TROJAN!
Xmsidlemsidle.exe"Added by the OPASERV-O WORM!"
XMsIdle32.exeMsIdle32.exe"Added by the VERIFY TROJAN!"
XMSIdllwinmp.exe"Added by a variant of the RBOT WORM!"
XMSIE ParsersMSIE32ab.exe"Added by the SDBOT.MV WORM!"
Xmsiemon.exemsiemon.exe"Microsoft Security Adviser rogue security software - not recommended"
Xmsiewmseiw.exe"Added by the LITTLOG TROJAN!"
XMSIEXECMSIEXEC32.exe"Added by the AINESEY.A WORM!"
XMSIEXECMSIEXEC.EXE"Added by the YOSENIO-A VIRUS!"
Xmsiexecsmsiexecs.exe"Added by the SILLYFDC.BBB WORM!"
Xmsiexecs.exemsiexecs.exe"Added by a variant of the SDBOT WORM!"
Xmsigdisk10.exe"Added by the BANBRA-KF TROJAN!"
XMsIMMs32MsIMMs32.exe"ONLINEG.GDJ spyware"
Xmsimnmsimn.exe"Added by the AGOBOT.JL WORM!"
XMSIMN32MSIMN32.EXE"Added by the CWS-M TROJAN!"
?MSINMSin.exe"??"
XMsinetMsinet.exe"Added by the RBOT-AOA WORM!"
XMSInfomsinfo.exe"Added by the ALADINZ.M TROJAN!"
XMSInfoAVBgle.exe"Added by the NETSKY.O WORM!"
XMSInstallsmvss.exe"Added by the DEDLER-G TROJAN!"
Xmsjava servicexpcd.exe"Added by the SDBOT.VM WORM!"
Xmsjdqsfddwqt.exe"Added by the SDBOT-PO WORM!"
UMskAgentMskAgent.exe"McAfee SpamKiller - rule-based and list-based spam filter. Available as a stand-alone product or included in older versions of Internet Security and Total Protection"
UMskAgentexeMskAgent.exe"McAfee SpamKiller - rule-based and list-based spam filter. Available as a stand-alone product or included in older versions of Internet Security and Total Protection"
XMSKCES32[random filename]"Added by the CLONER TROJAN!"
UMSKDetectorExeMSKDetct.exe"Part of McAfee Spamkiller"
XMSKernel32MSKernel32.vbs"Added by the LOVELETTER (I LOVE YOU) VIRUS!"
XMSkernel32System.exe 4820"Added by the TUXDER BACKDOOR!"
UMSKExespamkiller.exe"McAfee Spamkiller"
Xmskjmskj.exe"Added by the KAEMON TROJAN!"
Xmskridermaskrider.dll.vbs"Added by the SOLOW-F WORM!"
UMSKServerExeMSKSrvr.exe"Part of McAfee Spamkiller"
Xmslagentmslagent.exe"Added by the WINTRIM-F TROJAN!"
XMSLARISSAMSLARISSA.pif"Added by the ASSIRAL.B WORM!"
?MSLIB32mswatch32.exe"??"
Xmsliveupdatemsliveupdate.exe"Added by the AGOBOT.ALT WORM!"
XMSLogMicrosoftLog.exe"Added by a variant of the SDBOT WORM!"
XMslogon lptt01mslogon.exe"RapidBlaster variant (in a ""Mslogon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMslogon ml097emslogon.exe"RapidBlaster variant (in a ""Mslogon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xmsmmsm.scr"Added by the BANKER-EHJ TROJAN!"
Xmsmacro32msmacro32.exeIdentified as a variant of the AGENT.QB TROJAN!
Xmsmacro32msmacro64.exe"Added by a variant of the BACKDOOR-DOQ TROJAN!"
XMsManagermsmgr32.exe"Added by the YAHA.AF WORM!"
Xmsmanager32msmngr32.exe"Added by the RANDON-R (or WOMANIZ.A) WORM!"
Xmsmautoprotectmsmssgs.exe"Added by the BIFROSE-AJ TROJAN!"
Xmsmcmscpbo.exe"ClientMan parasite variant"
Xmsmcmsgdmf.exe"ClientMan parasite variant"
Xmsmcmsongn.exe"ClientMan parasite variant"
Xmsmcmsmc.exe"ClientMan parasite variant"
Xmsmcms****.exe [* = random char]"ClientMan parasite variant"
XMSMcAfeeeAvsynmgr32e.exe"Added by the FRAMAR TROJAN!"
XMSMcAfeehAvsynmgr32h.exe"Added by the FRANGO TROJAN!"
XMSMcAfeeSAvsynmgr32S.exe"Added by the VOLAC or VOLAC.DR TROJANS!"
XMSMessngermsnupd.exe"Added by the RBOT-ADY WORM!"
?msmgrmsmgr.exe"??"
XmsMGRrtkmsg.exe"Added by the SDBOT-BPY WORM!"
XMsmgtmsmgt.exe"Total Velocity adware/hijacker"
Xmsmmimsmmi.exe"Added by the AGENT.RFR TROJAN!"
XMSMNTGNTMSMNTGNT.EXE"Added by the BANKER-IE TROJAN!"
XMSMNTJBEMSMNTJBE.EXE"Added by the BANCOS-EF TROJAN!"
XMSMNTJNGMSMNTJNG.EXE"Added by the GRABER-G TROJAN!"
XMSMNTMTSMSMNTMTS.EXE"Added by the BANKER-GZ TROJAN!"
Xmsmonmsmon.exe"Added by a variant of the GEMA.D TROJAN!"
XMsMon32MsMon32b.exe"Added by the SDBOT.O BACKDOOR!"
XMsMoviesMsMovies.exe"Added by the ALCRA-E WORM!"
?MsmqIntCertregsvr32 /s mqrt.dll"Microsoft Message Queue Server - Internal Certificate - see here for more info and here for a potential problem. Is it required?"
XMSMSGNER[4-8 random letters].exe"Added by the FOWLDO-GEN TROJAN!"
XMSMSGNERzzgf.exe"Added by the PWS-CCB TROJAN!"
XMSMSGNERfgozmox.exe"Added by the AGENT-EBJ BACKDOOR!"
Xmsmsgrmsmsgss.exe"Detected by Kaspersky as the RBOT.AJJ WORM!"
NMSMSGSmsmsgs.exe"Windows Messenger instant messenger utility included with Windows 2K/XP. Available via the Start menu. Go to Windows Messenger → Tools → Options → Preferences and uncheck ""Run this program when Windows starts"""
XMsmsgsMsmsgs.exe"Added by the SILLYFDC-AP WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMSMsgsmsmessgs.exe"Added by the SMALL-EW TROJAN!"
Xmsmsgsmsmsgs.exe"Added by the SCLOG-AL TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMSMSGSwinlogon.exe"Added by the BRONTOK-BS WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
Xmsmsgs.exeIEXPLORE.EXE"Added by the VB.FQX TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMsMsgSrvmsmsgsrv.exe"Added by the CQO TROJAN!"
Xmsmsgss[path to trojan]"Added by the RANKY.G BACKDOOR!"
XMSMsgSvcMSMSGSVC.exe"Browser hijacker
Xmsmsngrmsmsngr.exe"Added by the DOPBOT-B WORM!"
Xmsnsystem32.exe"Added by the KITRO.A WORM!"
Xmsnmsnmsg.exe"Added by the RBOT-GO WORM!"
XMSNmsnmsgs.exe"Added by the RBOT-KL WORM! Note - not to be confused with msmsgs.exe
XMSNctfmoons.exe"Added by the SPYBOT.HI WORM!"
XMSNmsnmesengers.exe"Added by the RBOT-ME WORM!"
XMSNMSN.exe"Added by the MINIT WORM!"
XMSNmsnmsgr.exe"Added by the MYTOB or MYTOB.B WORMS! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
Xmsnmsnsvc.exe"Added by a variant of the SDBOT WORM!"
XMSNmsn16.exe"Added by the SDBOT-VN WORM!"
XMSNmsnsgr.exeAdded by an unidentified WORM or TROJAN!
XMSNinstall.exe"Added by the AGENT-GDO TROJAN!"
XMSNnetstats.exe"Added by the IRCBOT.UXP WORM!"
XMSNscvhost.exe"Added by the IRCBOT-ZW WORM!"
XMSNwdlrss.exe"Added by a variant of the SDBOT TROJAN!"
XMSNwkssvr.exe"Added by the PUSHBOT.S WORM!"
XMSNFixdriver.exe"Added by the SILLYFDC.BBY WORM!"
XMSNiTuneshelp.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSNlsass32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSNmsscomd.exe"Added by a variant of the SPYBOT WORM! See here"
XMSNsystems.exeIdentified as a variant of the Backdoor.PosionIvy keylogging malware
XMSNtaskngr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSNwkssvrs.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSNwksvr.exe"Added by the IRCBOT-XU WORM!"
XMSNwmev.exe"Added by a variant of the SPYBOT WORM! See here"
XMSNkys7r.exe"Added by the AUTORUN-AR WORM!"
XMSNservices51651.exe"Added by the IRCBOT-AAL TROJAN!"
XMsn"rundll32.exe ilss32.dllnetwork"
Xmsnwinlogon.exe"Added by the PROSTI.AA BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Media"
XMSNmsnmsgx.exe"Added by the RBOT-PZ WORM!"
XMSNmsservice.exe"Added by the IRCBOT-ABZ TROJAN!"
XMSNsmsss.exe"Added by the BUZUS-D WORM!"
XMSNsvchost.exe"Added by the PUSHBOT.FA WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMsn 8.0 Livemsn.exe"Added by the BANKER.EIE TROJAN!"
XMSN 9.0 Plus[random letters].exe"Added by the RBOT-ALY WORM!"
XMSN Administration For Windowsmsnadp32.exe"Added by the BROPIA.W WORM!"
XMSN angcssrss.exe"Added by the FORBOT-CE WORM!"
XMSN Auto-Updatermsnaupdater.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN Auto-Updatermsnupdates.exe"Added by the AUTORUN.WORM.GEN WORM!"
XMSN BETAservice.exe"Added by the RBOT.AUU WORM!"
XMSN Boostermsnbooster.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMsn Bootmsnbootcfg.exe"Added by the IRCBOT.BFU BACKDOOR!"
XMSN Checkermsnchecker.exe"Added by the SDBOT-AGB WORM!"
XMSN Client Managermsnclimgr.exe"Added by the AUTORUN-FV WORM!"
XMSN CNF Managermsncnfmgr.exe"Added by the VUNDO TROJAN!"
XMSN Communication Managermsncommgr.exe"Added by an unidentified WORM or TROJAN! See here"
XMsn Configmsngf.exe"Added by the RBOT-QG WORM!"
XMSN Configurationmsnconfig.exe"Added by a variant of the IRCBOT TROJAN!"
XMsn Configuration Loadermsngms.exe"Added by the KELVIR.T WORM!"
XMSN Configuration Loadermsmsncfg.exe"Added by the AGOBOT-KX BACKDOOR!"
XMSN CST Managermancstmgr.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN Database Clientmsndbcli.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN Debug Mgrmsndebugs.exe"Added by a variant of the IRCBOT TROJAN!"
XMSN Explorermsnexplorer.exe"Added by the AGENT-CAX TROJAN!"
XMSN Explorerexplorer..exe"Dropper for the Ciadoor.cb TROJAN!"
XMSN File & Folder Sharing Appmsnfileshare.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN File Configurationmsnfilecfg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN File Sharingmsnusr.exe"Added by the SLENFBOT.AM WORM!"
XMSN File Sharing Wizardmsnsharewiz.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN File Sharing!msnuser.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN Funny Imagesimsngsr.exe"Added by the AGOBOT-TT WORM!"
XMSN Gaming ZoneTwain.exe"Added by the AGENT.BEA TROJAN!"
XMSN Hostnmsnhostn.exe"Added by a variant of the IRCBOT BACKDOOR!"
NMSN Internet Accesstrayclnt.exeQuick way to connect to MSN internet service - replaces "MSN Quick View" from V5.6 onwards
XMSN Live Clientmsnlvclient.exe"Added by the IRCBOT.AWF BACKDOOR!"
XMSN Live Messangermsnlivegs.exe"Added by the RBOT-FSG WORM!"
XMSN Managercvss.exe"Added by a variant of the SPYBOT WORM!"
XMSN Managermscmgr.exeUnidentified malware - causes multiple browser windows to open
XMSN Managermsnmgrsv.exe"Added by the IRCBOT.BAZ BACKDOOR!"
XMSN Managerusnmsn.exe"Added by a variant of the IRCBOT TROJAN!"
XMsn Message Acount Helper 7.7msnmessage7.7.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN Message Background loader[path to worm]"Added by the RBOT-AIE WORM!"
XMSN Message Servicemsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMsn Messagermsnmsgr.exe"Added by the DOWNLOADER.19456.C TROJAN! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMSN Messagermsnmgr.exe"Added by the IRCBOT-ACD WORM!"
XMSN Messagesmsnmesg.exe"Added by the RBOT-ACN WORM!"
XMSN Messagesmsnmessgs.exe"Added by the SLENFBOT.UC WORM!"
XMSN Messangermsnmsng.exe"Added by the SDBOT.XN WORM!"
XMSN messangermsnmsgsm.exe"Added by the RBOT-FMP WORM!"
XMSN Messangermsnmsgsmn.exe"Added by the RBOT-FOQ WORM!"
XMsn Messangercrsss.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMsn Messangermsnmsgem.exe"Added by the RBOT.BLL BACKDOOR!"
XMSN MessangerSystem.exe"Added by the IRCBOT-AFX TROJAN!"
XMSN Messanger Livewinntmsn.exe"Added by the RBOT-FSO WORM!"
XMsn Messengwindns.exe"Added by a variant of the RBOT WORM!"
XMsn MessengeIExplorer.exe"Added by the DELF-LL TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMSN messengermessenger.exeAdded by an unidentified TROJAN! Note - this is not the real MSN Messenger
XMsn Messengermsnmsgs.exe"Added by the LOONY-P TROJAN! Note - not to be confused with msmsgs.exe
XMSN MessengerReosmsngr.exe"Added by a variant of the SPYBOT WORM!"
XMSN MESSENGERmsmmsgr.exe"Added by the KELVIR.Q WORM!"
XMSN Messengermsnmsgr.exe"Added by the AGOBOT.AOQ WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMSN Messengermsmsgs.exe"Added by the ZLOB TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMSN Messengermsnmsngr.exe"Added by a variant of the RBOT WORM!"
XMSN MessengerIExplorer.exe"Added by the BANKER-EU TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMsn Messengermsnmsnr.exe"Added by the BANKER-GG TROJAN!"
XMSN MessengerPIC1324.exe"Added by the CHOKE.C WORM!"
XMSN Messengerexplorer..exe"Dropper for the Ciadoor.cb TROJAN!"
XMsn Messengernkbf.exe"Added by the RBOT-GMQ WORM!"
XMSN Messengerlive.messenger.com"Added by the DELF.AOI BACKDOOR!"
XMsn Messengermsnmgr.exe"Added by the AGOBOT.HA WORM!"
XMSN Messengermsnmsxp.exe"Added by the AGOBOT-O WORM!"
NMSN MessengerMsnMsgr.exe"MSN Messenger utility (now replaced by Windows Live Messenger) - available via the Start menu. Disable by clicking on Tools → Options → General → deselect ""Automatically run Messenger when I log on to Windows"""
XMSN Messenger 32msniu.exe"Added by the RBOT-AWB WORM!"
XMSN Messenger 323msniu3.exe"Added by the RBOT-AXB WORM!"
XMSN Messenger 6.2tyd.exe"Added by a variant of the RBOT WORM!"
XMSN MESSENGER 9.0messengerr.exe"Added by a variant of the RBOT WORM!"
XMSN Messenger BETA 7bbsdf.exe"Added by the RANKY.AA TROJAN! Note - this is not a valid MSN Messenger variant"
XMSN Messenger Inbox Loadermsninbox.exe"Added by the SLENFBOT.YG WORM!"
XMSN Messenger Live Loginmsnmessengerlive.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN Messenger Live Windowsmessengerlive.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN messenger servicemssgs.exeAdded by an unidentified TROJAN!
XMsn Messenger Servicemsnmsg.exe"Added by the SDBOT.BMU WORM!"
XMSN Messenger Service Startermsnmgsr.exe"Added by the RBOT-AOS WORM!"
XMSN Messenger Service Startupmsnservice.exe"Added by a variant of the RBOT WORM! See here"
XMSN Messenger Servicesmsnmgr.exe"Added by the RBOT.ADF TROJAN!"
XMSN Messenger Servicesmsnmgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMsn Messenger Updatemsnupdate.exe"Added by a variant of the RBOT WORM!"
XMsn Messenger updatemsnservice.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN Messenger User Controlsmsmsgr.exe"Added by the KELVIR.HI WORM!"
XMsn MessengersMSNMSGR.EXE"Added by the RBOT.KX WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMSN MessenggerMsRun32.exe"Added by the IMAUT.CO WORM!"
XMsn Messsengerregsvr.exe"Added by the AGENT-GXM TROJAN!"
XMSN MMISSENGERmssmmspgr.exe"Added by the KELVIR.AJ WORM!"
XMSN P2P Managermsnp2pmgr.exe"Added by the SLENFBOT.YH WORM!"
XMsn Patchmsndp.exe"Added by the RBOT.AAI WORM!"
XMsn Patchesmsndr.exe"Added by a variant of the SDBOT WORM!"
XMsn Plus Updatermsnplus.exe"Added by the RBOT-MU WORM!"
XMSN Popup Blockermsnpopblck.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMsn Processe Managermsni32.exe"Added by the RBOT-ADX WORM!"
NMSN Quick ViewMsndc.exeQuick way to connect to MSN internet service
XMSN Registry loadermsmnwin.exe"Added by the KELVIR.FK WORM!"
XMSN Routermsnrouter.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN RPC Managermsnrpcmgr.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN Rx Managermsnrxmgr.exe"Added by an unidentified WORM or TROJAN! See here"
NMSN Search ToolbarWindowsSearch.exe"System Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. For this version
XMSN Security Agentmsnsecure.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN Servmsmsnserv.exe"Added by the IRCBOT.AVF BACKDOOR!"
XMsn Servmsnserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN Servermsmsnserver.exe"Added by the IRCBOT.AUS BACKDOOR!"
XMSN servicemsnmgr16.exe"Added by a variant of the RBOT WORM!"
XMSN Serviceamsnmsgrs.exe"Added by a variant of the SDBOT WORM!"
XMsn Servicematrixcam.exe"Added by the MYTOB.JH WORM!"
XMsn Serviceraloded.exe"Added by the MYTOB-DY WORM!"
XMSN servicemsnmsgr16.exe"Added by the RBOT-RZ WORM!"
XMSN serviceNTDKRN.EXE"Added by the RBOT.UJ WORM!"
XMSN Servicemsnsvc.exe"Added by the SLENFBOT.EG WORM!"
XMSN Service Updateswinproc.exe"Added by the KELVIR-BB WORM!"
XMSN Service Utilitiesnkn.exe"Added by the KELVIR-BC WORM!"
XMSN Service!msnservice.exe"Added by a variant of the RBOT WORM! See here"
XMSN Servicermsnsrv.exe"Added by a variant of the IRCBOT TROJAN!"
XMSN Servicermsnservicer.exe"Added by the SLENFBOT.PQ WORM!"
XMSN Servicesmsnserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN Servicesmsnservice.exe"Added by the IMPARD-A TROJAN!"
XMSN Settingsmsnsettings.exe"Added by the IRCBOT.AWH BACKDOOR!"
XMSN Settings Managermsnsetmg.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN SetupMSN.msn"Added by the JAMBU WORM!"
XMSN Softwaremsnsoftware.exe"Added by the IRCBOT.AWD BACKDOOR!"
XMSN Startmsnmsgr7.exe"Added by the RBOT-PH WORM!"
XMsn Startupmsnstartup.exe"Added by the ARBOT.AA WORM!"
NMSN Toolbarmswinext.exe"MSN Toolbar from version 4.* onwards (now known as Bing Bar from version 5.* onwards). This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
XMSN Tray Monitormsnmsgr.exe"Added by the SDBOT.FKX WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%\inetsrv"
XMSN Updatemscon.exe"Added by the RBOT-QA WORM!"
XMSN Updatemsn32.exe"Added by the RBOT.AHN WORM!"
XMSN UpdateDLLCON.EXE"Added by the RBOT-EA WORM!"
XMSN Update Cfgmsnupdbt.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN Update Clientmsnupdater.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN Update Clientmsnupdcli.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMsn Update Manager (Sp2)MSMSGS.EXE"Added by the AGOBOT-NL WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMsn Update Serviceuserx.exe"Added by the MYTOB.JF WORM!"
XMSN Update Servicemsnupdsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMsn Update SUPPORT[random filename]"Added by the RBOT-BPS WORM!"
XMSN Updatermsnms.exe"Added by the FORBOT-CG WORM!"
XMsn Updatermsnplugins.exe"Added by the RBOT-HS WORM!"
XMsn Updaterwindatemanager.exe"Added by the SDBOT.TS WORM!"
XMSN UPDATERSvirtualmemory.exe"Added by the RBOT-JK WORM!"
XMSN Updatingmsnupdate.exe"Added by the QHOST.AEI TROJAN!"
Xmsn upddatemesenger.exe"Added by the RBOT-AVZ WORM!"
XMSN Usermymsnusr.exe"Added by the IRCBOT.AVD BACKDOOR!"
XMSN User Servermsnserver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN User Server!msnservices.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN User Servicemsnsvc.exe"Added by the SLENFBOT.NS WORM!"
XMSN User Service!msnserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN User Servicesmsnuserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN User Svcmsnusnsvc.exe"Added by the IRCBOT.AVV BACKDOOR!"
UMSN Video EnhancedMSNVE.exe"""MSN Video Enhanced can play videos that have dramatically improved video quality and sound. It can play the latest high-quality videos at the best possible quality."" No longer appears to exist"
NMSN Webcam Recorderml20gui.exe"""MSN Webcam Recorder is a tool that allows you to record video streamed to and from your computer by MSN Messenger's Webcam Feature"""
Xmsn.exeson.exe"Added by the STARTPA-GS TROJAN!"
XMSN32 X ServiceMSN32x.EXEAdded by an unidentified WORM!
XMSN6.1 Auto-Updaterv6msn.exe"Added by the AUTORUN-MM WORM!"
XMSN8m Startupmsn8m.exe"Added by a variant of the RBOT WORM!"
Xmsnager32svchostt.exe"Added by the WOMANIZ.E TROJAN!"
Nmsnappaumsnappau.exe"Updater for the MSN toolbar that can be downloaded onto IE. Calls home every day or so to ""update"" the toolbar"
XMsnarratormsnarrator.exe"Added by the NARAT.A TROJAN! - also identified as MPGCOM Toolbar adware"
XMSNavWHMSWkwrH.exe"Added by the ANAV-A WORM!"
Xmsndrvsysmsndrvsys.exe"Added by the BROGGER-D TROJAN!"
XMSNETmsnet.exe"Added by the BOA WORM!"
XMsnExplorerwinagent.exe"Added by the BDOOR-EQ BACKDOOR!"
XMsnExplorerMSEXPLOREN.EXE"Added by the BDOOR-EB BACKDOOR!"
XMsnExplorerSHCH.EXE"Added by the BDOOR-EB BACKDOOR!"
XMsnExplorerSVCHST.EXE"Added by the BDOOR-EB BACKDOOR!"
XMsnExplorermsnexploren.exe"Added by the TACTSLAY.B TROJAN!"
XMsnExplorersdhch.exe"Added by the TACTSLAY.B TROJAN!"
?MsnFixermsnfixjs.js"Located in the HPbinmsnfix directory of a HP PC"
XMSNGrabberMSNgrabber.exe"Added by the ENVID.A WORM!"
Xmsngta32msngta32.exe"Added by a variant of the RBOT WORM!"
NMSNIAMSNIASVC.EXEAdded with MSN version 9. Resets certain internet settings upon bootup and can't be disabled via MSCONFIG
Xmsnload32.exemsnload32.exe"Added by the BANCOS.M TROJAN!"
XMSNMESENGERMain.exe"Added by the PRORAT TROJAN!"
Xmsnmessengermsnmessenger.exe"Added by the BANCBAN-KJ TROJAN!"
XMsnMessengerSvcmsnmsgr.exe"Added by a variant of the RBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
Xmsnmgnrmsnmgnr.exe"Added by the KOLAB.TC WORM!"
Xmsnmgrmsnmgr.exe"Added by the BIFROSE-K WORM!"
UMsnMonitorMsnMonitor.exe"MSN Messenger Monitor Sniffer surveillance software for the MSN instant messenger. Uninstall this software unless you put it there yourself"
Xmsnmsgasgag.exe"CoolWebSearch parasite variant"
XmsnmsgTBC.exeAdded by an unidentified TROJAN!
Xmsnmsgmsnmsg.exe"Added by the BANKER-CLX TROJAN!"
Xmsnmsg.exemscmd32.exeAdded by a variant of the AGENT.AH TROJAN!
Xmsnmsg.exemsnmsg.exe"Added by the BANCBAN-KN TROJAN!"
Xmsnmsgq32msnmsgq.exe"Added by the TACTSLAY.H TROJAN!"
Xmsnmsgq32msnmsgq32.exe"Added by the TACTSLAY.F TROJAN!"
Xmsnmsgq32sssasasb32.exe"Added by the TACTSLAY.F TROJAN!"
Nmsnmsgrmsnmsgr.exe"Windows Live Messenger or the older MSN Messenger utility - available via the Start menu. For Windows Live Messenger
XMsnMsgrMsnMsgrs.exe"Added by the NETSKY.AD WORM!"
XMsnMsgrmsnmsgr.exe"Added by the ANNEW-FAM WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMsnmsgr.exelsass.exe"Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root directory (i.e. C:\ or D:\)"
Xmsnmsgr32-.exemsnmsgr-.exe"Added by a variant of the SPYBOT WORM!"
XMSNMSGR5MSNMSGR5.exe"Added by the RBOT.PQ WORM!"
XMSNMSGREswef.batIRC backdoor TROJAN or WORM!
XMSNMSGRRswin.batIRC backdoor TROJAN or WORM!
XMSNMSGRSswe.batIRC worm or backdoor trojan!
XMSNMSGRSswiss.batIRC worm or backdoor trojan!
XMSNMSGRS1swed.batIRC backdoor TROJAN or WORM!
Xmsnmsgs.exemsnmsgs.exe"Added by the BANKER-HK TROJAN! Note - not to be confused with msmsgs.exe
Xmsnmsgsgsmsnmsgsgs.exe"Added by the ""Catal"" alias Spy.Delitall.B backdoor TROJAN!"
Xmsnmsgy[path to file]"Added by the BANKER-EQ TROJAN!"
Xmsnntwinampb.exe"Chinese originated adware - detected by Kaspersky as the AGENT.TL TROJAN!"
Xmsnntwinampf.exeAdded by the SMALL.DTS TROJAN!
XMSNPluginSrIvcsn3vasap23.exe"Added by a variant of the RBOT WORM!"
XMSNPluginSrvcsp6.exe"Added by the SDBOT.AKJ or RBOT-VJ WORMS!"
XMSNPluginSrvcssagate.exe"Added by the SDBOT.AKJ WORM!"
XMSNPlusmsnplus.exe"Added by the BANKER-DAN TROJAN!"
XMSNS PLUS XP2msdupd.exe"Added by the RBOT-BCE WORM!"
Xmsnsched2msnsched2.exe"Added by the SPYBOT.NNT WORM!"
Xmsnscr.exemsnscr.exe"Added by the CERTIF-P TROJAN!"
XMSNServiceMSNService.exe"Added by the CARPET.C WORM!"
Xmsnsgsmsnsgs.exe"Added by the CHEUKO-B TROJAN!"
Xmsnshedmsnshed.exe"Added by the RBOT-YN WORM!"
XmsnsmgrMsnMsr.exe"Added by the LOONY-N TROJAN!"
Nmsnsyslogmsnappm.exe"Related to Messenger Applications. When you uninstall the trial version the msnappm keeps saying (You have xx days left) this is adware and it very annoying"
XMSNSysRestorepc32.exeAdded by a variant of the MASTAK VIRUS!
XmsnToolbaarmsnmsgesc.exe"Added by the RBOT.BMF WORM!"
Xmsnupdtkolie.exe"Added by a variant of the RBOT WORM!"
XMsnWinmessagewin.exe"Added by the BANCBAN-D TROJAN!"
NMSN® Toolbarmswinext.exe"MSN Toolbar from version 4.* onwards (now known as Bing Bar from version 5.* onwards). This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
XMSObject32MSObject32.js"Added by the PUN TROJAN!"
XMsofficemsoffice.htaHijacker - redirecting to Searchdot.net
XMSOfficeservices.exe"Added by the DLOADER-EU TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""MSOffice"" subfolder"
Xmsofficemsoffice.exe"Added by the LIKASIMAL WORM!"
XMSOffice32msjcf.exe"Added by the RAKER-A TROJAN!"
XMSOfficeCfgmsocfg.exePremium rate adult content dialer
XMSOfficeCfgnavchk.exePremium rate adult content dialer
XMSOfficeCfgqservice.exePremium rate adult content dialer
XMSOfficeCfgshman.exePremium rate adult content dialer
XMSOfficeCfgssvr.exePremium rate adult content dialer
Xmsoffwzmsoffwz.EXE"Added by the BANCBAN-HQ TROJAN!"
Xmsoft-updater23mssysstems.exe"Added by the RBOT-ATU WORM!"
Xmsoft-updater23slssystem.exe"Added by the RBOT-ASR WORM!"
XMSOleath32winss.exe"Added by the KATHER TROJAN!"
XMSOOBDMSOOBD.EXE"Added by the MAGISTR.A VIRUS!"
Xmsoupdatermsoupdater.exe"Added by the DLOADER.GBD TROJAN!"
Xmspaint.execheck32.exe"Added by the AGENT.AH TROJAN!"
XMspatch69[path to trojan]"Added by the MPROX TROJAN!"
XMspatch89cnqmax.exe"Added by the RANDEX.P WORM!"
XMSPetServPET32.EXE"Added by the IRCBOT-VE WORM!"
Xmspingmsping.exe"Added by the FLOODBLACK TROJAN!"
Xmsping.exemsping.exe"Added by the BDOOR-MZ BACKDOOR!"
XMSPluginSrvcp3.exe"Added by the RBOT-WV WORM!"
XMSPLUSmsplus32.exe"Added by the MYTOB-AM or MYTOB-CL WORMS!"
XMSPP System Update 64wiaadmgr.exe"Detected by Kaspersky as the RANKY.GEN TROJAN!"
XMSPQFileMSA****.TMP [* = random char]Homepage hijacker
XMsPrint32DMsPrint32D.exe"Added by the WINKO.AO WORM!"
XMSPRO32[path to worm]"Added by the IBERIO WORM!"
XMSPRO32pnp.exe"Added by the ZOTOB.O WORM!"
XMSprotect.exeMSprotect.exe"Added by the DABYREV.A VIRUS!"
Umspwrpupstman.exe"""Transparent icon background"" feature of Ashampoo'sPowerUp XP (WinNT/2K/XP) and PowerUp Deluxe (Win98/Me)"
Umspwrpupxpman.exe"Related to Ashampoo's PowerUp XP"
Umspwrpwrupst.exe"Ashampoo's PowerUp XP is a ""tool for fine-tuning your Windows NT4
UmspwrPuXpMan2.exe"System Tray access to the Ashampoo® PowerUp XP Platinum 2 tweaking utility from Ashampoo GmbH & Co. KG - which includes (amongst others) one-click tuning
UMSPY2002ImScInst.exe"Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails
Xmsqssrmsqssr.exe"Detected by Kaspersky as the DLUCA.GEN TROJAN!"
XMSRmsr.exe"Added by the AGOBOT.RT WORM!"
XMsrcMsrc.exeAdded by the KRYPTONIC GHOST TROJAN!
Xmsrdcmsrdc.exe"Added by the SDBOT-CXO WORM!"
Xmsreg.exemsrege.exe"Added by the ZINX TROJAN!"
XmsReg32 Loadermsreg32.exe"Added by the AGOBOT.IU WORM!"
XMSREGITMsgp.exe"Added by the KRYPGHOS.13 TROJAN!"
UMSRegScanSGP.exe"SpyGator surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanSSDemo.exe"SupremeSpy surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanETNKL.exe"ComKeylogger surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanKSPDemo.exe"KeyStalker PRO surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanDDSSDemo.exe"SystemSleuth surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanESP+.exe"ESP surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanESPDemo.exe"Eye Spy Pro surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanSBPDemo.exe"SpyBoss Pro surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanYEKPND.exe"EyeCandy Computer Monitor surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanYKPND.exe"YKPMD surveillance software. Uninstall this software unless you put it there yourself"
XMSRegSvcregsvc32.exeHomepage hijacker that changes your homepage to an adult content site
Xmsresear[path to trojan]"Added by the WEASYW-B TROJAN!"
Xmsresearchmsresearch.exe"TROJAN! - 180SearchAssistant adware related"
Xmsresearchtool3.exe"Spy Sheriff/SpywareNO malware
Xmsrundllmsrund1l32.exe"Added by the BINGHE TROJAN!"
Xmsrunocx32msrunocx32.exe"Added by the SKUS WORM!"
XMss Servmsssrv.exe"Added by the SLENFBOT.AA WORM!"
XMss VCmssvc.exe"Added by the OPANKI.AB WORM!"
Xmssarumssaru.exe"Added by the AGENT.AM TROJAN! Note - example names include ""XviD""
Xmsscan.exemsscan.exe"Microsoft Security Adviser rogue security software - not recommended"
UMSSCDLMSSCDLL.exe"SpyCapture keystroke logger/monitoring program - remove unless you installed it yourself!"
Xmssdbsrvmsupdtck.exeAdded by a variant of a password stealing TROJAN!
YMSSEmsseces.exe"System Tray access to a notifications from Microsoft Security Essentials which ""provides real-time protection for your home PC that guards against viruses
Ymssecesmsseces.exe"System Tray access to a notifications from Microsoft Security Essentials which ""provides real-time protection for your home PC that guards against viruses
Xmsserrv32msserrv32.exe"Added by the STRATION.DW WORM!"
Xmsservmsserv.exe"Added by the BLACKLOG-A TROJAN!"
Xmsservlvsrev.exe"Added by the BROWMON-B TROJAN!"
Xmsserv32msserv32.exe"Added by the RBOT-ACK WORM!"
XMsServermsfun80.exe"Added by the VB-CYG WORM!"
XMSServer"Rundll32.exe [random].dll#1"
XMsServermsfir80.exe"Added by the VB-CYJ TROJAN!"
Xmsservicemsserv.exe"Added by the HYD WORM!"
XMSService_v1.0realsched.exe"EHU adware. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name"
XMSService_v1.0vfp02.exe"NewWeb adware"
Xmssfossfool.exe"Added by the RANDEX.EUS WORM!"
XMSSGisg[path to file]"Added by the RANKY.N TROJAN!"
XMsshield.exeMsshield.exe"Added by a variant of the IRCBOT TROJAN!"
XMSShowMSShow.exe"Added by the QQROB-M TROJAN!"
XMSSHVCMSSHVC.exe"Added by the NUFFY.A WORM!"
Xmssonfigwinupdate.exe"Added by a variant of the SDBOT WORM!"
Xmssoulmsmscc2.exe"Added by the DAPIZL.A banker WORM! (A ""banker worm"" is designed to pillage banking information and send it back to the perpetrators!)"
Xmssoulmsmscc.exe"Added by the BANCOS.HKT TROJAN!"
Xmssp3mssp22.exe"Added by the IBANK-D TROJAN!"
XMSSQLMssql.exe"Added by the SDBOT TROJAN!"
XMSSQL for Windows NT & XPmssqlsnt.exe"Added by a variant of the SDBOT WORM!"
XMSSQL Managermssqlmgr.exe"Added by the RBOT-BWU WORM!"
NmssSortmsssort.exe"Maxtor (now Seagate) ""Drag and Sort"" for their external storage - ""Just drag documents onto the Shared Storage II icon and Maxtor's Drag and Sort organizes your files
XMsstartmsstart.exe"Added by the LIVUP.C TROJAN!"
XMSStartOptimizerIexpres.exe"Added by the DASMIN-E TROJAN!"
XMSStartOptimizerWINUPD.EXE"Added by the DASMIN-E TROJAN!"
XMSStartOptimizerSCVHOST.EXE"Added by the DASMIN-E TROJAN!"
Xmsstaskmsstask.exe"Added by the MYPARTY WORM!"
Xmssurfer lptt01mssurfer.exe"RapidBlaster variant (in a ""surfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xmssurfer ml097emssurfer.exe"RapidBlaster variant (in a ""surfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xmssvc[path to trojan]"Added by the PSK TROJAN!"
XMSSVCsvcsys.exe"Added by the FATOOS-C TROJAN!"
YMSSVC.EXEMSSVC.EXE"StealthDisk - hides folders
Xmssvc32mssvc32.exe"Added by the AGOBOT-ME WORM!"
Xmssync20mssync20.exe"Added by the LDPINC-QC TROJAN!"
Xmssysmssys.exe"Added by the MYSS.B TROJAN!"
XmssysintIexplore .exe"Added by the PWSTEAL.ABCHLP and PSPIDER.310.B TROJANS! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the "".exe"""
Xmssysintcomime.exe"Added by the NETSNAKE-I TROJAN!"
Xmssyslanhelpermsmsgri32.exe"Added by the RANDEX.D WORM!"
XMsSystemmsdos.exe"Adult content downloader - see here"
XMsSystemmssys.exe"Added by the VANTA.A TROJAN!"
XMSSYSTEMsvcsys.exe"Added by the FATOOS-C TROJAN!"
UMstapiMstapi.exeKeystroke logger/monitoring program - remove unless you installed it yourself!
XMstaskmstask.exe"Added by the OPASERV.N WORM! Note - this is not the legitimate mstask.exe system file and the executable resides in %Windir%"
Xmstaskmstask.exe"Browser hijacker - redirecting to find-more.net. Note - this is not the legitimate mstask.exe system file"
XMSTaskrun dll.exe"Yuupsearch adware"
XMStasksvchost.exe"Added by the LDPINCH-BV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMsTaskwstask32.exe"Added by the MYTOB-FE WORM!"
XMstaskkernel32.exe"Added by the STAP-C WORM!"
XMstaskMSDTC.exe"Added by the STAP-D WORM!"
XMSTask Monitormstaskmon.exe"Added by the SDBOT-LU WORM!"
XMstask32driverMstask32.exe"Added by the LOONY-D TROJAN!"
XMSTaskbar 32tbsvc32.exe"Added by the RBOT.BQZ WORM!"
Xmstasksmstasks.exe"Added by the MULTIDR-AY TROJAN!"
?MstcgwwMSTCGWW.EXE"??"
Xmstds.exemstds.exe"Added by the IPTABLES TROJAN!"
Xmstg32.exemstg32.exeAdded by the AGENT.BI TROJAN!
NMSTMON_NMSTMON_N.EXEGenerates an error message on startup if a Konica Minolta printer is not turned on and ready
NMSTMON_QMSTMON_Q.exeGenerates an error message on startup if the Konica Minolta PagePro 1350W printer is not turned on and ready
XMstng32MSTng32.exe"Added by the TANG WORM!"
XMSTrayrundll.exe"Added by the BAMER-B TROJAN! Note - this is NOT the Win9x/Me system file of the same name as described here"
Xmstsdsc.exemstsdsc.exe"Added by the CIMUZ-CD TROJAN!"
Xmsupdmsupd.exe"Added by the IEACCESS DIALER!"
XMSUpdatewupd.exe"Added by the ALADINZ.M TROJAN!"
XMSUpdatesvchosthlp.exe"Added by the BLASTER.T WORM!"
Xmsupdatemsupdate.exe"Added by the RBOT-MZ WORM!"
XMSUpdatecriticalUpdate.exe"Affilred adware"
Xmsupdateupdate.exe"Added by a variant of the SDBOT WORM!"
XMsupdateexpIorer.exe"Added by the TACTSLAY.A TROJAN!"
XMsupdateoutIook.exe"Added by the TACTSLAY.A TROJAN!"
XMsupdatesvchosts.exe"Added by a variant of the TACTSLAY TROJAN!"
XMsupdatesvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XMsupdatesvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XMSupdate.exeN/A"CoolWebSearch parasite variant - resets home page to an adult content site"
XMSUpdateDevKitaxfd.exe"Added by the SDBOT-ZD WORM!"
Xmsupdatermsupdater.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
XMsUpdater Systemudpsys32.exe"Added by the RBOT.AAA WORM!"
XMSupdater.exeN/A"CoolWebSearch parasite variant. Installs the Winshow.dll browser plugin"
Xmsupdater25lsasser.exe"Added by the RBOT-ATS WORM!"
Xmsupdatesmsupdt.exe"Added by the RBOT-JO WORM!"
XMSUpdSrvmsupdsrv.exe"Browser hijacker
Xmsupdtwizmsupdtwiz.exe"Added by the STRATION.DD WORM!"
Xmsurlmsurl32.exe"Added by the CRYPTER.A TROJAN!"
Xmsuser32.exemsuser32.exe"Added by the ANDROV TROJAN!"
XMsVBdllsys32dll.exe"Added by the AIMDES.B or AIMDES.C WORMS!"
XMsVBdllMsVBdll.pif"Added by the AIMDES.A WORM!"
XMSVBVM60MSVBVBM60.pif"Added by the SCOLD-B WORM!"
Xmsvc32msvc32.exe"ClientMan parasite variant"
Xmsvc32msvc32.exe"Added by the AGOBOT-NT WORM!"
Xmsvcavmsvcav.exe"Added by the AGENT-ACR TROJAN!"
Xmsvccmsvchost.exe"Added by the XOMBE TROJAN!"
Xmsvcc25svcchost.exe"Added by a variant of the SDBOT WORM!"
Xmsvcc25salvage.exe"Added by a variant of the SDBOT WORM!"
Xmsvcc25svcchost.exe"Added by the SDBOT-CSE WORM!"
Xmsvccc66svcchosst.exe"Added by the RBOT-GLS WORM!"
Xmsvccc66dload.exe"Added by a variant of the RBOT WORM!"
Xmsvchostmsvchost.exe"Added by the IRCBOT-AV WORM!"
XMsvcServicemsvcs.exe"Added by the RBOT-RK WORM!"
Xmsvecuritymsvecurity.exe"Added by the DORF-BO WORM!"
XMSVersionINTERNETFEATURES.exe"Added by the POPMON.A TROJAN! - also known as PopMonster adware"
XMSVersionclrschp038.exe"Added by the POPMON.A TROJAN! - also known as PopMonster adware"
Xmsvhostaig.exe"Added by the AIMBOT-BC TROJAN!"
Xmsvload32msvload32.exe"Added by the RBOT-ACI WORM!"
Xmsvpsmsvps.exe"Added by the AGOBOT.ALI WORM!"
Xmsvsc32msdev.exe"Added by the RBOT-GJ WORM!"
XMSVsmtrpcxctx.exeAdded by an unidentified WORM or TROJAN!
Xmsvsrv32msvsrv32.exe"Added by the AGOBOT-KM WORM!"
Xmsvssmsvss.exe"Added by a variant of the RBOT WORM!"
XMSVSyncvideosync.exe"Added by a variant of the SPYBOT WORM!"
Xmsvupdatermsvupdater.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
XMSVXDMSVXD.EXE"Added by the DATOM.A WORM!"
Xmswavemswave.exe"Added by the CRYPTER.A TROJAN!"
XMswavedllmswavedll.exe"Added by the CRYPTER-C TROJAN!"
UMSwheelmswheel.exeMicrosoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features
Xmswiiz32mswiiz32.exe"Added by the STRATION.DH WORM!"
Xmswiizz32mswiizz32.exe"Added by the STRATION.DL WORM!"
XMSWinmswin.exe"Added by the BANKER-CU TROJAN!"
XMswincfgMswincfg32.exe"Added by the CYBRSPY.D TROJAN!"
XMsWindows DRT Driverswsdrt32.exe"Added by the RBOT.ALT WORM!"
XMsWindows SSL Driversmssl32.exe"Added by the SPYBOT.API WORM!"
XMSWindows SysClmscl32.exe"Added by the RBOT.AHI WORM!"
XMsWindows SysDatesysmsvc.exe"Added by the SPYBOT.FCD WORM!"
XMSWindows Syspgmspg32.exe"Added by the RBOT-TB WORM!"
XMSWindowsUpdateSystern.exe"Added by the RBOT-AFD WORM!"
XMSWindowsUpdatemswinup.exe"Added by a variant of the SDBOT WORM!"
Nmswinextmswinext.exe"MSN Toolbar from version 4.* onwards (now known as Bing Bar from version 5.* onwards). This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
XMSWinlogonSynCor.exe"Added by the AGENT-FZL TROJAN!"
XMSWinlogonwinlogon.exe"Added by the AGENT-FZM TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XMswinpid32mswinpid32.exeAdded by the LAPOS.A TROJAN! This is a keylogger which emails back to China PayPal passwords and account information - thus allowing the perpetrators to steal PayPal funds in the name of the victim!
XMSWinSrvMSWinSrv.exe"Added by the MTRON TROJAN!"
XMSWinSrv32MSWinSrv32.exe"Added by the MTRON-B TROJAN!"
XMSWinupdwinupd.exe"Added by the DLOADER-YE or DLOADR-AAA or DLOADER-ZF TROJANS - and others"
XMSWinupdatewinupdate.exe"Added by the DLOADR-AAW TROJAN!"
XMsWinVgrmsvgr.exe"Added by the MYTOB.LE WORM!"
Xmswiz32mswiz32.exe"Added by the STRATIO-BG WORM!"
Xmswkork Servicemsework.exe"Added by a variant of the RBOT WORM!"
Xmswordmsword.exe"Added by the RBOT-ADR WORM!"
Xmsworddocx.exe"Added by the CODOX-A WORM!"
Xmsword98msword98.exe"Added by the AGENT-KUO TROJAN!"
XMSWorldmsworld.exe"Added by the AGENT.DED TROJAN!"
Xmswspl[random filename]"Added by the SMALL.IQ TROJAN!"
Xmswsplsearchbarcash.exeSearchBarCash adware
Xmswsplvnmispoisn downloader.exeSearchBarCash adware variant
Xmswsplplugin1.exe"Added by the SMALL.IQ TROJAN!"
XMSWTL32MSATL32.exe"Added by an unidentified WORM or TROJAN! See here"
XMSWUpdate[path to worm]"Added by the SILLYFD-V WORM! The most common filename is lsass.exe but it not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
Xmsxctmsxct.exe"eXact Advertising (NaviSearch
XMSxmlHpr"RUNDLL32.EXE [path] msxm192z.dllw"
XMsXSLTmsxslt3.exe"Added by the AGENT.AZMU TROJAN!"
XMsy Startupsmsyh32.exe"Added by the AGOBOT-QC WORM!"
XMsy1 Startupsmsyj32.exe"Added by the AGOBOT-QQ WORM!"
Xmsys lptt01msys.exe"RapidBlaster variant (in a ""Msyss"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMsys32morfitwebentrance.exe"Morfit ADjectPager - ""uses home page rental technology for generating revenues"". Homepage hi-jacker that re-defines your IE or Netscape start page as http://www.web-entrance.com/. Any installed application including this must be un-installed before you can reset your homepage"
XMSysDrvmsdrv.exeAdded by the VB.WF TROJAN!
Xms_anti_spywaremwfirewall.exe"Added by the GAMQOWI TROJAN!"
Xms_anti_spywarebxpmwfirebpx.exe"Added by the SURILA-D TROJAN!"
Xms_anti_spywarebxpmwfibpx.exe"Added by the SURILA-J TROJAN!"
XMS_LARISSAMS_LARISSA.exe"Added by the ASSIRAL WORM!"
XMS_NETD_WIN32netd32.EXE"Added by the RANDEX.F WORM!"
XMS_SETUP.EXEMS_SETUP.EXE"Added by the CHARGE TROJAN!"
XMS_Update Checkwdfmgr.exe"Added by the AGOBOT-TB WORM!"
XMS_update_0704_KB74073.exeMS_update_0704_KB74073.exe"Added by a variant of the UPDATEKB TROJAN!"
XMultimedia extensionsmservice.exe"EasySearch adware"
XMultimedia extensionsmservice1.exe"Added by the DLOADR-AWD TROJAN!"
XMULTIMEDIA KEYBOARD88smss.exe"Added by the SILLYFDC WORM! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
Nmumservicemumservice.exe"Software updater for Motorola products"
?mxomssmenumaxmenumgr.exe"Related to Maxtor's One Touch series of external hard drives. What does it do and is it required?"
XMy Agentmsagent.exe"Added by the NEGASMS.A TROJAN!"
XMy AppSMSSvc.exe"Added by the NEGASMS.A TROJAN!"
XMy Security EngineMS[random characters].exe"My Security Engine rogue security software - not recommended
XMy Security WallMS[random characters].exe"My Security Wall rogue security software - not recommended
XMy SupervisorMSup1bf7.exe"My Supervisor rogue system suite - not recommended
XMySLScanmsvc32.exe"Added by the FORBOT-EH WORM!"
XName Servermswins.exe"Added by a variant of the SDBOT WORM!"
XNarmonVirusAntismss.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XNAV Agentsystems.exe"Added by the TARNO.C TROJAN! Note - this is not the valid Norton Antivirus entry of the same name"
XNAV Auto Protectmsfwe1.exe"Added by a variant of the RBOT WORM!"
XNAV Auto Updateiamsad.exe"Added by the SPYBOT-CE BACKDOOR!"
Xndlhostauiremsyl.exe"Added by a variant of the SDBOT WORM!"
NNero PhotoShow Media Managermssysmgr.exe"Nero rebranded version of Simple Star's PhotoShow photo editing and organizing software
XNeroFileCheckmsjavam32.exe"Added by the AGOBOT.AKM WORM!"
XNeroUpdate Checkmsjava.exe"Added by the AGOBOT.AMH WORM!"
Unetmsgnetmsg.exe"Net_Message is a small tool to send messages across the network
Xnetwork device drivermsfirewall.exe"Added by the DELF-LB TROJAN!"
XNetwork Host Servicemsmnart32.exe"Added by the RBOT-CJV WORM!"
XNewDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XNewMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XNiceDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XNiceMP3"rundll32.exe MSA64CHK.dllDllMostrar"
YNMSSupportIntelHCTAgent.exe"Network monitor for Intel® Hub Connect Technology"
?NMSSvcNMSSVC.EXENIC Management Service - diagnostics program for Intel Pro family network cards
YNMSVCnmSvc.exe"Covenant Eyes - surveillance software that creates records of everything people do on a computer
UNokia M PlatformNokiaMServer.exe"Part of the Nokia Music music manager
UNokiaMServerNokiaMServer.exe"Part of the Nokia Music music manager
Xnonepmsngr.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
XNordBullmsa.exe"Added by the DLOADR-CSV TROJAN!"
XNorton Drive Protectionmsdt32.exe"Added by the FORBOT-GB WORM! Note - this not a valid Norton program!"
XNortons AVS Systemsarse.exe"Added by the RBOT.AWY WORM!"
Xnotepad.exemsmsgs.exe"Added by the ZLOB TROJAN and variants! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
Xntmsevtntmsevt.exe"Added by the STOPED-B TROJAN"
XNumberOneMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XNvCplDaemonmsmsgrs.exe"Added by the DLOADER-YI TROJAN!"
XNvCplScanmsc32.exe"Added by the FORBOT-DD WORM!"
XNVIDIA DriverMSPMSPSU.EXE"Added by the WOOTBOT.Y WORM!"
XnvmsgdwnNVMSGDWN.EXE"Added by the GRABER-D TROJAN!"
XNvMsnWIsass.exe"Added by the BROPIA.K WORM!"
Unwrecmsgnwrecmsg.exe"Broadcast message handler part of Novell Netware that displays server
XOfficeDeamonmsorunner.exe"Added by a variant of the TACTSLAY TROJAN!"
XOfficesmsnmgd32.exe"Added by the FORBOT-DV WORM!"
XOfficeWord Monitormsn32.exe"Added by the RBOT-GUE WORM!"
XOffice_appmsnmrgs.exeAdded by a variant of the VBBANC-A TROJAN!
XOpenMstart[path to dialler]"""Switch-E"" premium rate adult content dialer"
XOS Securitymswind32.pif"Added by the RBOT-ASU WORM!"
XOutlook Expressmsinm.exe"Added by a variant of the RBOT WORM!"
?pagmstartclient.exe"??"
NPCMServicePCMService.exe"Part of Cyberlink's PowerCinema - which can be used to watch movies
XPerforms peer to peer connectionWinPTTP.exe"Added by the RBOT-GMI WORM!"
NPhotoShow Deluxe Media Managermssysmgr.exe"Simple Star PhotoShow Deluxe photo editing and organizing software
Xpicviewmsnmsgr.exe"Added by the BANLOA-AF TROJAN! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %Windir%"
UPlanlægningsagentmstask.exe"Windows Task Scheduler (on Danish language versions of Windows) - displayed as a box with a stopwatch in the System Tray. Required if you have regularly scheduled tasks like defragmenting
?PLoaderumsd.exe"USB Mass Storage Disk related tray icon. Is it required?"
XPlug And Playmsnmsg.exe"Added by the RBOT-ID WORM!"
Xpmsngr.exepmsngr.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
XPostSetupCheckRundll32.exe cpmsky.dll"TrafficSol adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""cpmsky.dll"" file is found in %System%"
?PrimstaPrimsta.exe"Linksys Wireless CompactFlash Card driver related. Is it required?"
Xprinterdrvvdms.exe"Added by the OPTIXKIL.30 TROJAN!"
XPrinting Drivermsprint.exe"Added by the RBOT.JH WORM!"
UPRISMSTA.EXEPRISMSTA.EXECreates a system tray icon for accessing information about Intersil Prism Wireless Settings. Intersil silicon is used by Trendware/Trendnet for example
UPRISMSVRPRISMSVR.EXEConfiguration and settings utility for PRISM chipset based wireless modems such as the 2Wire Wireless Gateway (2701HG) and Siemens Gigaset USB Adapter
UPRISMSVR.EXEPRISMSVR.EXEConfiguration and settings utility for PRISM chipset based wireless modems such as the 2Wire Wireless Gateway (2701HG) and Siemens Gigaset USB Adapter
XProtected StorageRUNDLL32.EXE MSSIGN30.DLL ondll_reg"Added by the LOVGATE-W WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XProtocolDiskChkssrms.exe"Added by the BDOOR-ML BACKDOOR!"
YPSIMSVCPSIMSVC.exe"Part of Panda Antivirus and Internet Security"
Xq36i36Olms2cenu.exeAdded by the SECONDTHOUGHT VIRUS!
UQDMQdmStart.exe"QDM (QDI Desktop Manager) - part of QDI ManageEasy for QDI's series of motherboards for monitoring PSU
UQDMStartQdmStart.exe"QDM (QDI Desktop Manager) - part of QDI ManageEasy for QDI's series of motherboards for monitoring PSU
XQTSvcmsocfg.exePremium rate adult content dialler
NQuickenSEMessageQsemsg.exeQuicken option
XQuickSetmmspng.exeAdded by a variant of the IROFFER.Z TROJAN!
XRrundll32.exe msprt.dll"Chinese originated browser hijacker - redirecting to 4199.com Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XRavTimeMstray.exe"Added by the WUKILL.A WORM!"
NRealPlayer2MsgCenterExe"RealNetworks RealPlayer related - disabling this application will not affect Real Player in any way"
XRecoveru systemssvchost.exe"Added by the SMALL.DDX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XRecycleSTRmsreg32.exe"Added by the RBOT-TC WORM!"
XRegistration Servicemsvdm6.exe"Added by the SDBOT-HE TROJAN!"
XRegistry Value Name StartMsPMSPSa.exe"Added by a variant of the SDBOT WORM!"
XREGMSYS[path to file]"Added by the LOWZONE-AX TROJAN!"
XRegSvr32msmsgs.exe"Added by the ZLOB.B TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XRemote Event Systemresmsvc.exe"Added by the IRCBOT.YF BACKDOOR!"
XRemote Procedure Callsmswinrpc.exe"Added by the RBOT.KJ WORM!"
XRemote Procedure Callsmswinc.exe"Added by the RBOT-IT WORM!"
XRemote Services Managermsrmsvc.exe"Added by the SLENFBOT.AJ WORM!"
XRemove 54tr10smss.exe"Added by the BRONTOK-CH WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data"
?RemStartremstart.exe"Part of McAfee's Remote Desktop 32 Agent application. What does it do and is it required?"
Xrollbkmsmpatch.exe"Added by the SERFLOG.B WORM!"
?Roxio EngineMSMNGR32.EXE"Not believed to be a valid Roxio program - more likely a variant on the WOMANIZ.A TROJAN!"
XRPCMSschost.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XRPC DCOM Vulnerability Patchmsgfix.exe"Added by the RBOT.S WORM!"
XRPCserv32gMSDEFR.EXE"Added by the BOBAX.AD WORM!"
Xrrmsobqhrmug.exe"Added by the AGENT-GYY TROJAN!"
XRun Msn Messengermsnmgr.exe"Added by the AGOBOT.HA WORM!"
XRun MSupdt32wscript MSupdt32.vbs"Added by the CASER WORM!"
Urun=ramsys.exe"Advanced Startup Manager from Rays Lab"
Yrun=smsrun16.exe"Microsoft Systems Management Server (SMS) related - program that reads SMSRUN16.INI on clients running Win 3.1
Xrun=msoffice.exe"Added by the ADWARELOADER TROJAN! Note - do not confuse with the legitimate Microsoft Office file
Xrundll32MSDTC.exe"Added by the STAP-E WORM!"
XRundll32_7"rundll32.exe MSIEFR40.DLL DllRunServer"
XRunOnce[path to mstask32.exe]"Added by the DELF-IA TROJAN!"
XRunOnceExsms.exeIESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!
XSakemsneqlsimenu.exe"Added by the SDBOT.BTO WORM!"
XSamsongSamsong.exe"Added by the SDBOT.BNE WORM!"
XSamsungSamsungs.exe"Added by an IRC TROJAN variant!"
USamsung MJC-900 Series Monitor"RUNDLL32.EXE SMMASHLL.DLLAutoUpdatePnPValue"
USamsung PanelMgrSSMMgr.exe"Monitors ink levels
USamsungSM PanelMgrSSMMgr.exe"Monitors ink levels
Xscanmscman.exe"ClientMan parasite variant"
XScan Registerssms.exe"Added by the RBOT-AT WORM!"
XScheduIrmsexploren.exe"Added by a variant of the SDBOT WORM!"
XSchedulerMSMSGS.EXE"Added by the HOSTBANK-A TROJAN! Note - this particular msmsgs.exe file is located in %System%\Config and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XSchedulermsnexploren.exe"Added by the TACTSLAY.B TROJAN!"
USchedulingAgentmstask.exe"MS Scheduling Agent in Win98/Me/2K - displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting
USchedulingAgentmstinit.exe"MS Scheduling Agent in WinNT - displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting
XSchedulingAgentmstask.exeAdded by unidentified MALWARE! Note - this is not the MS Scheduling Agent in Win98/Me/2K. This one also loads via the HKLM\RunServices registry key but is located in %System% on a WinXP machine - where a file of that name does not normally exist
XSchedulingAgentmstasks.exe"Added by the MSIC BACKDOOR!"
UScreen Guard Message Scansgms.exe"Part of Access Denied security and privacy software"
XScreenSaverPlus"rundll32.exe MSA64CHK.dllDllMostrar"
?SDMSSplashlauncher.exe"Part of HP's Smart Desktop Management System - ""Preloaded on select business desktops
XSearchMP3"rundll32.exe MSA64CHK.dllDllMostrar"
Xsecbootmszx23.exe"Added by a variant of the HAXDOOR.BC TROJAN!"
XSecureLoginMslg32.exe"Added by the REDZED WORM!"
Xsecures23mssecure.exe"Added by the AGOBOT-ABY WORM!"
XSecurity Accounts Manager SMsamsm.exe"Added by the SPYBOT.JE WORM!"
XSecurity Agent Managermssams.exe"Added by the RBOT-SV WORM!"
XSecurity Patchscmss.exe"Added by the RBOT-ZW WORM!"
XSecurity Patchesmsnkn.exe"Added by the RBOT.WW WORM!"
USeMSSeMS.exe"PCsms - tool that enables you to send sms text messages from your PC to any UK mobile phone"
Xserpemsmbw.exe"Added by the SERFLOG.A WORM!"
XServer Runtime Processwbemstest.exe"Added by the SDBOT-DDB WORM!"
XService Driversmsnpg.exe"Added by the RBOT.BMD WORM!"
XService DriversMSNMEssenger.exe"Added by a variant of the RBOT WORM!"
XService Monitormsnfilen.exe"Added by the RBOT-ALE WORM!"
XService Monitorjavams32.exe"Added by the DELF-NK TROJAN!"
XService Monitorjavams64.exe"Added by the SDBOT-AFO WORM!"
XService Monitormsnserve.exe"Added by the SPYBOT.YQW WORM!"
XService Processsmss.exe"Added by the DCMBOT-E TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""config"" subfolder"
XServicesmshost.exe"Added by the LANFILT-J TROJAN!"
XServices Processsmss.exe"Added by the SMALL-EK TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""config"" subfolder"
XServices.dllsmss.exe"Added by the SOBER-L WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\system and note the space at the beginning of the ""Startup Item"" field"
XSession Manager Subsystemsmssa.exe"Added by the RBOT-AGS WORM!"
XShellexplorer.exe msbnc.exe"Added by the AGENT-PL BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""msbnc.exe"" file is located in %System%"
XShellsmsc.exe"Added by the BANCBAN-OY TROJAN!"
XShellExplorer.exe smssnt.exe"Added by the AGOBOT.EE TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""smssnt.exe"" file is located in %System%"
XShellApiSHELLMSN.EXE"Added by the NETDEV.B TROJAN!"
?ShowIcon_Justrams_USB Product Driver v2.12r012shwicon.exe"Related to Just Rams USB product driver. Is it required?"
NSimple Star PhotoShow Media Managermssysmgr.exe"Simple Star PhotoShow photo editing and organizing software
USimpLite-MSNSimpLite-MSN.exeRequired if you use the SimpLite add-on to MSN Messenger (SimpLite adds encryption to the instant messaging service)
XSistema de Commconmsyrtl.exe"Added by the AGENT-LMV TROJAN!"
Xslmssslmss.exe"SeekSeek search hijacker related - see here"
XSmallAndSecuremssecure.exe"Added by the RBOT.CU WORM!"
XSMSiro.bat"Added by the IROFFER.CT TROJAN!"
USMS Application LauncherLAUNCH32.EXE"Microsoft Systems Management Server - used to manage computers on a network remotely"
USMS Client Serviceclisvc95.exe"When the SMS Client service starts on a domain controller
XSms System32SmsSystem32.exeUnidentified malware
USMS Win9x Message AgentSMSMsg.exeThis program assigns a user to a Systems Management Server site
NSmsDiscountSmsDiscount.exe"SmsDiscount - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
NSmserialsm56hlpr.exeHelper utility for Motorola based SM56 software modems - resides in the System Tray
XSMSERIALSTARTERwin32st.exe"Added by the FAKEALERT-AH TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
XSMSERIALWORKERSTARTshellexcon.exe"Added by the FAKEALERT-AH TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
XSMSERIALWORKERSTARTERwinstrse.exe"Added by the RENOS.IC TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
XSMSERIALWORKSTARTERcomsysobj.exe"Added by the FAKEALERT-AH TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
XsmsgerWin.exe"Added by a variant of the SDBOT WORM!"
NSMSI LoaderSMLoader.exe"Smith Micro HotFax - fax software"
Xsmsmsmsm.exe"Added by the BANKER-CO TROJAN!"
Xsmsrvsmsrv.exe"Added by the AGOBOT-SX WORM!"
XSMSSsmss.exe"Added by the FLOOD.F BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Catroot"" subfolder"
Xsmss[path to smss.exe]"Added by the ALADINZ.F TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
Xsmsssmss.exe"Added by the AGENT-TR TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsmsssmss.exe"Added by the BOROBOT-J TROJAN and variants! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
XSmssssms.exe"Added by the RBOT.OP WORM!"
XSmss Hostsmhost.exe"Added by the IRCBOT-ACC TROJAN!"
Xsmss.execsrss.exe"Added by the DALBUG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSmss.exe driverwinupd32.exe"Added by the SDBOT.MI BACKDOOR!"
Xsmss32.exesmss32.exe"Added by the FAKEAV-ATH TROJAN!"
XsmssLevel4smss.exe"Unidentified malware! ! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Windows Media Player\Skins\WindowsMediaSkin\Data\Level4"
XSMSSSsmsss.exe"Added by the SDBOT.ZD WORM!"
XSMSSS Loadersmsss.exe"Added by the AGOBOT.MQ WORM!"
XSMSSUSMSSU.EXE"Added by the STARTPAGE.O TROJAN!"
USMSTraySMSTray.exeSystem tray access to Samsung Media Studio
XSMSvc32smsvc32.exe"Added by the AGOBOT-OL WORM!"
XsmsysExplorer.exe"Added by the CLICKER-C BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in a ""Template"" subfolder"
Xsmsysvi.exeAdult content dialler
USMSystemAnalyzerSMSystemAnalyzer.exe"Part of the Iolo System Mechanic optimization tool"
Xsms_msnsms_msn.exeAdded by an unknown WORM or TROJAN!
Xsms_msn40sms_msn40.exeAdded by an unknown WORM or TROJAN infection
XSN Messengermsnmsgr.exe"Added by the RBOT-AVP WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XSonic RecordNow!smsc.exe"Added by a variant of the SDBOT WORM!"
XSoundViewmsdview32.exeTrojan downloader
USpam SleuthSpamSleuth.exeSpam Sleuth E-mail spam detection program
USpamSubtractSpamSubtract.exe"Intermute SpamSubtract - junk email detection and removal program"
UspamsubtractSpamSub.exeInterMute™ SpamSubtract - junk email detection and removal program. InterMute™ is now part of Trend Micro and their products are no longer supported
XSpooler Subsystem Applicationsmss.exe"Added by the IRCBOT-ZO TROJAN! Note - the legitimate smss.exe process should not normally figure in Msconfig/Startup!"
Xspoolmsspoolms.exe"Added by the LEGMIR-ARO TROJAN!"
Xspoolsvr32csmss.exe"Added by the AGENT-AU TROJAN!"
Xspoolsvr32csmss32.exe"Added by a variant of the AGENT-AU TROJAN!"
XSporeMsNews.vbs"Added by the SORPE.A WORM!"
USRUUninstallmsiexec.exeSymantec Network Driver Update - part of LiveUpdate
Xssgrate.exewinsystems.exe"Added by the BAGLEDL-J TROJAN!"
Xssgrate.exewintems.exe"Added by the MITGLIEDER.Q TROJAN!"
XSSL Manageramsnmsgs.exe"Added by a variant of the SDBOT WORM!"
Xssms.exeSSMS.EXE"Added by the GISMOR WORM!"
Xssms.exewinn.exe"Added by the SDBOT-DHE WORM!"
Xssmssssmss.exe"Added by the AGENT-MOF TROJAN!"
Xsssasasb32msnmsgq32.exe"Added by the TACTSLAY.F TROJAN!"
Xstart uploadingsmsss.exe"Added by a variant of the SDBOT WORM!"
XStart Uppingsmssupdate.exe"Added by a variant of the RBOT WORM!"
XStart Xp Setupmsxp.exe"Added by the RBOT.AKK WORM!"
Xstartkeyrtfmsv.exe"Added by the EDEPOL-C TROJAN!"
XStartKeymsnmsie.exe"Added by the BIFROSE.M BACKDOOR!"
XStartMenumsgaol.exe"Added by the TACTSLAY.C TROJAN!"
UStormCodec_HelperStormSet.exe"Storm Codec is a codec pack for Windows"
XStreams Drivers[trojan filename]"Added by the RESTARTER.E TROJAN!"
Xstrmsnmgrsmsnxmsgrsc.exe"Added by the SDBOT.JDR WORM!"
Xstrmsnmsgrmsnmsgrs.exe"Added by the RBOT-ACQ WORM!"
Xstrmsnmsgrsmsnmsgrsc.exe"Added by a variant of the RBOT WORM!"
Xstrmsnnmsmsnmegrs.exe"Added by the SDBOT-YU TROJAN!"
Xstrmsnnrsmsnmcgrs.exe"Added by the RBOT-ACT TROJAN!"
Xstrmsoumsmsnmegrse.exe"Added by the SDBOT-ZK TROJAN!"
Xstxrmsgmsmstats.exe"Added by the IRCBOT-AE TROJAN!"
Xsuperslutmsslut32.exe"Added by the SLUTER-A WORM!"
XSVC Socksmstaskm.exe"CoolWebSearch parasite variant"
XSvcH0stmsexploren.exe"Added by the BACKDOOR-CGZ TROJAN!"
XSvcH0stmsnexploren.exe"Added by the TACTSLAY.B TROJAN!"
Xsvshost32msgrsv32.exeAdded by the RANKY.AJ TROJAN!
Xsvshostdrivermsnmessengerupdate.exe"Added by the SDBOT-BI BACKDOOR!"
XSwimSuitNetworkSwimSuitNetwork.exeAdvertising spyware
XsyelimS-esreveR-troppuS[filename]"Added by the LITBOT.C TROJAN!"
XSygate Personal FirewallMSNSRV32.exe"Added by a variant of the RBOT WORM!"
XSygate Personal Firewallmsnmsgrs.exe"Added by the RBOT.XN WORM!"
XSyncManagermsorunner.exe"Added by a variant of the TACTSLAY TROJAN!"
XSysCommsnmsgr.exe"Added by the BANK-AF TROJAN! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%MSN Messenger or %ProgramFiles%Windows LiveMessenger. This one is located in %Windir%\system"
?SysCompmssdnl.com"Unknown but suspect as *.com are not usually run at start up and the name isn't recognized"
XSysctrlsmscntrl.exe"Added by the KOLABC.BB WORM!"
XSysCVMS.exeSysCVMS.exe"Added by the SMALL.CBA TROJAN!"
XSysgate Personal Firewallsyst3ms.exe"Added by a variant of the IRCBOT TROJAN!"
Xsysmemmmsete.exe"Added by the NOPIR.C WORM!"
XSysMemory managermdms.exe"Added by the CIMUZ-D TROJAN!"
XSysmonmsnmssgs.exe"Added by the SDBOT.FK WORM!"
XSysmonLogmslog.exe"Added by the AGENT.AOV TROJAN!"
Xsysmsssysems.exe"Added by a variant of the SLAPER TROJAN!"
XsysPersonalFirewallmsnmssgr.exe"Added by a variant of the RBOT WORM!"
YSysPoolMssvc.exe"StealthDisk - hides folders
XSysPoolMSSVC32.EXE"Added by the BANCBAN-IO TROJAN!"
Xsystemsystemsearch.htaJetseeker.com hijacker
XSystemsmss.exe"Added by the AGENT.EP BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem Backupmsystem.exeAdult content dialler
XSystem Config Managersmssl.exe"Added by the AGOBOT-ZJ WORM!"
XSystem Document Applicationmsdocument.exe"Added by the RANDEX.COX WORM!"
XSystem Efficiency Monitormscedit32.exe"Added by the SDBOT.P TROJAN!"
XSystem Efficiency Monitormscommand.exe"Added by the KWBOT.P WORM!"
XSystem Efficiency Monitormsedit32.exe"Added by the STEPH-B WORM!"
XSystem Information ManagerMsbb.exe"Added by the SLINBOT.YR BACKDOOR!"
XSystem Information Managermslog.exe"Added by the DELF.AKO TROJAN!"
XSystem Initializationmsmsgri32.exe"Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS!"
XSystem Loadersystems.exe"Added by the AGOGBOT-FI WORM!"
XSystem Management Servicesmsc.exe"Added by the RBOT-ANN WORM!"
XSystem MessengerSYSMSG32.EXE"Added by the SPYBOT-DK WORM!"
XSystem MScvbmscvb32.exe"Added by the SOBIG.C WORM!"
XSystem ServiceMSREXE.EXE"Added by the AML TROJAN!"
XSystem Servicesystems.exe"Added by the AGOBOT.VZ WORM!"
XSystem Servicemsnwindows.exe"Added by the SPYBOT.YCL WORM!"
XSystem Servicemsnxpexe.exe"Added by the RBOT-AUA WORM!"
XSystem Servicesssms.exe"Added by a variant of the RBOT WORM!"
XSystem Session Managersmss.exe"Added by the KALEL-E WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
XSystem StatsSystemStats.exe"Added by a variant of the WOOTBOT WORM!"
XSystem Traymsccn32.exe"Added by the SOBIG.B WORM! Warning - spreading via infected E-mail attachments with the sender address faked as support@microsoft.com! Note - this is not the legitimate systray.exe process"
XSystem Updatemssetupconf.exe"Added by the RBOT.DLC WORM!"
XSystem Update Applicationmsbuffer.exe"Added by the SDBOT.AFF WORM!"
XSystem Updates 4mssysfix.exe"Added by the RBOT-ADU WORM!"
XSystem-Configmsptmf32.com"Added by the LIOTEN.FA WORM!"
XSystem51616msnmsgesser.exe"Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger"
XSystemBootMshta.exe ...filename.htaAdult content dialler
XSystembootmsnsngr.exe"Added by a variant of the RBOT WORM!"
Xsystemdrvms32sys.exe"Added by an unidentified WORM or TROJAN - most likely GAOBOT variant"
XSystemsscchost.exe"Added by the DAEMOZ.A TROJAN!"
XSystemssvch0st.exe"Added by the MYDOOM.BI WORM!"
XSystemsSystems.exe"Added by the BANKBOA-A TROJAN!"
XSystemsitDDD.exe"Added by the DLOADER-PP TROJAN!"
XSystemssescmgr.exe"Added by the DWNLDR-GAH TROJAN!"
XSystemsspoolsvc.exe"Added by the DLOADR-SW TROJAN!"
XSystemssysmon.exe"Added by the VIXUP-BI WORM!"
XSystems Backupswindrives.exe"Added by the AGOBOT-RB WORM!"
XSystems Restartslchost.exe"Added by the MULTIDROP.C TROJAN!"
XSystems Restartspchost.exeAdded by an unidentified WORM or TROJAN!
XSystems Restart"Rundll32.exe beem.dll DllRegisterServer"
XSystems Restart"Rundll32.exe snim.dll DllRegisterServer"
XSystems Restart"Rundll32.exe zolk.dll DllRegisterServer"
XSystems Restart"Rundll32.exe boln.dll DllRegisterServer"
XSystems Servicedrivex.exe"Added by a variant of the RBOT WORM!"
Xsystems usb driverWindows2.exe"Added by a variant of the RBOT WORM!"
USystems.exeSystems.exe"Keyboard Spectator - monitoring software that creates records of everything people do on a computer
Usystems.exesystems.exe"KGBSpy is a commercial surveillance software program. It logs keystrokes
USystemSafeSyssafe.exe"System Safety Monitor - system monitoring tool with additional application firewalling"
XSYSTEMSars32csrss.exe"Added by the AHLEM.A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystemSASSystem32.exe"Added by the KWBOT.C WORM!"
Xsystemscrootsystembin.exe"Added by a variant of the RBOT WORM!"
XSystemSearchregedit.exe -s ie.reg"Installs a Seachxl.com browser page hijack. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""ie.reg"" is located in the root folder (ie
XSystemSearchregedit.exe -s sys.reg"Installs a i--search.com browser page hijack. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""sys.reg"" is located in %Windir%"
XSystemSecurityzprot32.exe"Added by the AGENT-FK TROJAN!"
XSystemServicemsocfg.exePremium rate adult content dialler
XSystemServicenavchk.exePremium rate adult content dialler
XSystemServiceqservice.exePremium rate adult content dialler
XSystemServiceshman.exePremium rate adult content dialler
USystemServicensserver.exe"NiceSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
XSystemSettingfTRUG.vbs"Added by the TRUG.B MACRO!"
USystemSuite Task ManagerMXTASK.EXE"vcom (nee Ontrack) SystemSuite - PC maintenance and security. Use the program's configuration options to enable only the parts you want running all the time - such as Virusscanner Pro"
XSystemSv12newmaxxsv234.exe"Added by the TIBS-TS TROJAN!"
XSystemSv121n2ewma1xxsv234.exe"Added by the TIBS.TJ TROJAN!"
XSystemTraymssgl2.exe"Added by a variant of the IRCBOT TROJAN!"
XSystesms.exesystesms.exe"Added by the RBOT-HI WORM!"
XSystrayServicesMsxpw.exe"Added by the CITOR WORM!"
XSysUtilssmss.exe"Added by the AUTORUN-AWW WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
USZMsgSvc.exeSZMsgSvc.exe"StopZilla! - pop-up killer"
XTakeMP3"rundll32.exe MSA64CHK.dllDllMostrar"
Xtaskmgr.exepaintms.exeAdded by a variant of the AGENT.AH TROJAN!
Xtaskmngr[path] msnve.exe [path] task.exe"Added by the FLOOD-EK TROJAN!"
Xtaskmsgs[path to trojan]"Added by the BANCOS-BBW TROJAN!"
XTCPIP Protocolmstcpip.exe"Added by the SDBOT-LR WORM!"
XTerminal Servicesmstscc.exe"Added by the SDBOT-CZW WORM!"
XTesting 123msdata.dat"Added by the NITS.A WORM!"
XTheBestMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XThemeMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XTimermsncomm.exe"Added by the WEBDOR.AK TROJAN!"
XTok-Cirrhatussmss.exe"Added by the BRONTOK-A WORM and variants! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%"
XTok-Cirrhatus-2784smss.exe"Added by the BRONTOK-S WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%"
XTopic MSNGR32MSNGR32.com"Added by a variant of the IRCBOT TROJAN!"
XTorjan Programsmss.exe"Added by the WOWCRAFT.B TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UTSClientMSIUninstallertscuinst.vbs"Related to Terminal Services Client Remote Desktop Connection Software from Microsoft"
NTSMsgerTSMsger.exe"Epson scannner software - required for ""one-touch"" operation. Can be launched manually"
UTWarnMsgtwarnmsg.exe"Toshiba System Warning Function for Windows 98
Xtymsetvcosskhbd.exe"Added by the MAILBOT-BW TROJAN!"
XUpdatemshtm.exeBrowser hijacker - redirecting to buldog-search.com
?Update for WorksMSWkstz.exe"Maybe related to later versions of MS Works?"
XUpdate Run MSwordLOGON.EXE"Added by the RBOT.TY WORM!"
XUPDATEMSNsvhost.exeAdded by an unidentified WORM or TROJAN!
XUpdatesmsupdate.exe"CoolWebSearch parasite variant"
XUpdateXpSpMS045-XP2.exe"Added by the IRCBOT.NY TROJAN!"
XUsB drivermsjavx86.exe"Added by the AGOBOT-PQ WORM!"
XUSB Drivers1msupdate.exe"Added by a variant of the RBOT WORM!"
XUSB Driverz2msnplus1.exe"Added by the SDBOT-XQ WORM!"
XUSB MS UpdateUSBS.exe"Added by a variant of the RBOT WORM!"
XUSB Updatesmservices.exe"Added by a variant of the SDBOT WORM!"
XUSB Updatesmsfirewalls.exe"Added by a variant of the RBOT WORM!"
XUsbDsmss32.exe"Adware - detected by Kaspersky as the AGENT.CJ TROJAN!"
XUSBDrivesmsfirewalI.exe"Added by the RBOT-ABP WORM!"
XUSBHWDRVmsdc.exe"Added by a variant of the LOWZONE-I TROJAN!"
XUser Messagesusrmsg.exe"Added by a variant of the IRCBOT TROJAN! See here"
XUser Messages Managerusnmsgs.exe"Added by a variant of the IRCBOT TROJAN! See here"
XUser Messenger Managerusnmsgr.exe"Added by a variant of the IRCBOT TROJAN! See here"
Xuserdsystems.com"Added by the OUTLAW-A WORM!"
Xuserinitsmss.exe"Added by the DLOADR-B TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XUtilitiesAndSoftware"rundll32.exe MSA64CHK.dllDllMostrar"
Xvcmicrecmsccsed.exe"Added by the MAILBOT-CE TROJAN!"
NVegas Palms - LauncherLauncher.exe"Vegas Palms on-line cassino"
YVet Alertvetmsg9x.exe"Computer Associates "InnoculateIT" and Vet Anti-Virus virus software"
YVet AlertVETMSG.EXE"Computer Associates Vet Anti-Virus software"
YVetAlertVETMSG.EXE"Computer Associates Vet Anti-Virus software"
XVFW Encoder/Decoder SettingsRUNDLL32.exe MSSIGN30.DLL ondll_reg"Added by the LOVGATE-W WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XVideo DriverMsregdrv32.exe"Added by the SPIGOT BACKDOOR!"
XVideo ProcessMS32x16.exe"Added by the RBOT.RH WORM!"
XVideo ProcessMSlti64.exe"Added by the AGOBOT.UE WORM!"
XVideo Processmsn5.exe"Added by the AGOBOT-TW WORM!"
XVideo ProcessMStli32s.exe"Added by the RBOT-GAD WORM!"
XVideo Processormsconfsys88.exe"Added by the AGOBOT-QG WORM!"
XVirscannersmss.exe"Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
?VirusScanMSCVsStat.exe"Part of McAfee VirusScan. System Tray application as with previous versions (were also VsStat.exe)
XVisualStudiomsorunner.exe"Added by a variant of the TACTSLAY TROJAN!"
XvmsnGraberVMSNGRABER.EXE"Added by the ENVID.B WORM!"
Xvmssvmss.exe"Delfin Media Viewer or ""Promulgate"" adware variant"
XVnCplUpdatemsdm.exe"Masssend - spam relayer. Listens on a port for the spammers to feed it a list of addresses and what to send out. More information in
XVolume Shadow Configurationvbmsvc.exe"Added by the SLENFBOT.DH WORM!"
Xvssms32vssms32.exe"Added by the BCKDR-LBF BACKDOOR!"
UWAWifiMessageWiFiMsg.exe"""HP Wireless Assistant is a user application that provides a method for controlling the enablement of individual wireless devices (such as Bluetooth or WLAN devices) and that shows the state of the radios for these wireless devices"""
UWDDMStatusWDDMStatus.exe"WD Drive Manager - part of Western Digital's WD SmartWare management software for selected external drives in the My Book and My Passport range. Allows the user see the drive status
XWeb ServiceMSXMIDI.EXE"CoolWebSearch parasite variant
XWin INI 32msrp32.exe"Added by the RBOT-FZC WORM!"
XWin Securitymsw32.pif"Added by the RBOT-AQT WORM!"
XWin startupmscfg32.exe"Added by the SPYBOT-AE WORM!"
XWin TaskLoadermsgmr.exe"Added by the MYTOB.L WORM!"
XWin Updatemsnmger.exe"Added by the RBOT-GDP WORM!"
XWin32msnsrv.exe"Added by a variant of the SDBOT WORM!"
XWin32 Cnfg32msconfgh.exe"Added by the MYTOB.NB WORM!"
XWin32 FRT Drivermsfr32.exe"Added by the WOOTBOT.EJ WORM!"
XWin32 Ms Auto UpdaterAutomsUPD.exe"Added by a variant of the RBOT WORM!"
XWin32 NVIDIA DriverMSPMSPSU.EXE"Added by a variant of the WOOTBOT.Y WORM!"
Xwin32 regeditmsn32.exeAdded by an unidentified WORM or TROJAN!
XWin32 Securemsconfigsvc.exe"Added by a variant of the SDBOT WORM!"
XWin32 USB2 Driversmsc.exe"Added by the SDBOT.FO WORM!"
XWin32 USB2 Drivermsn.exe"Added by the FORBOT-EX WORM!"
XWin32 Word Servicesmsword32.exe"Added by a variant of the RBOT WORM!"
Xwin32servvms1.exe"iSearch adware"
XWinAmpAgentMsexploren.exe"Added by the BDOOR-EB BACKDOOR! Note - this is NOT the popular Winamp media player which has a different filename"
XWinAmpAgentmsnexploren.exe"Added by the TACTSLAY.B TROJAN!"
XWinApp32msapp.exe"Added by the RSBOT TROJAN!"
XWinCSRSSMSGRT32.EXE"Added by the REWINDO-A TROJAN!"
XWind River Systemsvxworks.exe"Added by the ACKANTTA WORM! Note that this is not related to the VxWorks platform from Wind River"
XWind Securitymswi32.pif"Added by the RBOT-ARH WORM!"
XWinDLL (csmss.exe)"rundll32.exe CSMSS.EXEstart"
XWinDLL (slmss.exe)"rundll32.exe slmss.exestart"
XWinDLL (smms.exe)"rundll32.exe smms.exestart"
XWinDll (sslms.exe)"rundll32.exe sslms.exestart"
XWindow Msn Live Messangermsnmsgsls.exe"Added by the RBOT.BJD BACKDOOR!"
XWindowsmsdos98.exeAdded by the PWSTEAL TROJAN!
XWindowssmss.exe"Added by the BANCBAN-QF TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWINDOWSymssgr.exe"Added by the BCKDR-PS BACKDOOR! Note - deactivates the Microsoft\Internet Connection Firewall (ICF)"
Xwindows auto updatemsblast.exe"Added by the BLASTER.B WORM!"
Xwindows automationmslaugh.exe"Added by the BLASTER.E WORM!"
XWindows Automationmsdspr.exe"Added by the SOLAME.A WORM!"
XWindows backupsystemss.exe"Added by a variant of the SPYBOT WORM!"
XWindows Bootupms-wks32.exe"Added by the RBOT-AFM WORM!"
XWindows bypass security SMSS ServiceSbiCvy.exe"Added by the RBOT-GRF WORM!"
XWindows CODE Fix Msy Startupsmsyh32.exe"Added by the AGOBOT.AKK WORM!"
XWindows Config Connectionmsicll.exe"Added by the RBOT-EXQ WORM!"
XWindows Configuration Loadermsgfix.exe"Added by the SDBOT-NP WORM!"
XWindows Console Normswnbsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Dcom2 Fixmscom32.exe"Added by the RBOT-QT WORM!"
XWindows Debuggermsdbg32.exe"Added by a variant of the RBOT WORM!"
YWindows DefenderMSASCui.exe"Main user interface for Microsoft's Windows Defender on XP/Vista - which ""helps protect your computer against pop-ups
XWindows DotFix livemsdotfix.exe"Added by the IRCBOT.XGK BACKDOOR!"
XWindows Driver Servicesmsdrvs32.exe"Added by the WOOTBOT.L WORM!"
XWindows driver updatedmsvc32.exe"Added by the SDBOT-GP BACKDOOR!"
XWindows Driversssms.exe"Added by the RBOT-AT WORM!"
XWindows Email Serverwmserv.exe"Added by the FOUNDU-AWORM!"
XWindows Firewall Managermsfw.exe"Added by the RBOT.WR WORM!"
XWindows firewall managermsguard.exe"Added by a variant of the RANDEX.GEL WORM!"
XWindows Fixes Systemselite.exe"Added by the MYTOB.EG WORM!"
XWindows Generic Procprocmsg.exe"Added by the ALLIM.B WORM!"
XWindows iMessenger Messengerwinimsg.exe"Added by the ALLIM.A WORM!"
XWindows Installer 1msnconfig.exe"Added by the PURITYSCN.B TROJAN!"
XWindows kev Messengermskev.exe"Added by the SDBOT-XV WORM!"
XWindows Livemsgnms.exe"Added by the XPACK.AV TROJAN!"
XWindows Live Clientmsnclient.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Messagesmsgnlive.exe"Added by the AGENT.AYH WORM!"
XWindows Live Messengermsnmsgr.exe"Added by a variant of the RBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XWindows live Messengermsn.com"Added by the IRCBOT-AAV WORM!"
XWindows Live Messengermsnlive.exe"Added by the RBOT.BMV BACKDOOR!"
NWindows Live Messengermsnmsgr.exe"Windows Live Messenger (was MSN Messenger) utility - available via the Start menu. Disable by clicking on the ""Show menu"" icon and select Tools → Options → Sign In → deselect ""Automatically run Windows Live Messenger when I log on to Windows"". This is the Windows Defender/Vista MSConfig entry for version 14.*"
XWindows Live Messengermsnd.exe"Added by the BCKDR-QQQ BACKDOOR!"
XWindows Live Messenger Addonwllivemsngr.exe"Added by a variant of the SDBOT WORM! See here"
XWindows Live Messenger Servicermsmgslive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Messenger Servicesmsgrlive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Messenger!livemsngr.exe"Added by the IRCBOT.AWE BACKDOOR!"
XWindows Live Messenger!msgrlive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Msgswlivemsg.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Msgs!wlivemsgs.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Servicemsnlive.exe"Added by the SLENFBOT.DI WORM!"
XWindows live Supportwlmsngr.exe"Added by the RBOT-BKL WORM!"
XWindows Loginlmss.exe"Added by the AGOBOT-JA WORM!"
XWindows Loginmsnmsgr.exe"Added by the AGOBOT-UC WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XWindows Loginlms.exe"Added by the AGOBOT-IC WORM!"
XWindows Media Centersmss.exe"Added by the WARBOT TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Media Drivermsnger.exe"Added by a variant of the RBOT WORM!"
XWindows Media Playermsa.exe"Added by the RBOT-SI WORM!"
XWindows Media Playermsams.exe"Added by the RBOT.AHR WORM!"
XWindows Media Playermsass43.exe"Added by the RBOT-RT WORM!"
XWindows Media Serverwmserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Media Server!wmserver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Memory Sharingmemshare.exe"Added by the IRCBRUTE.AG TROJAN!"
XWindows Memory Sharingmemshr.exe"Added by the IRCBOT.MC BACKDOOR!"
XWindows Messengermsnsmgs.exe"Added by the RBOT-ANJ WORM!"
XWindows Messengermsnmsg.exe"Added by the SPYBOT.BV WORM!"
XWindows Messenger Live MSNwinlivemsnmessenger.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Messenger Live Startupwindowslivemsn.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows Messenger Live Startupwindowsmsnlive.exe"Added by the DELF.DAX TROJAN!"
XWindows Messenger Messengerwinmsg.exe"Added by the VELKBOT.A WORM!"
XWindows Messenger Servicewinsmsgr.exe"Added by the RBOT-VW WORM!"
XWindows Messenger Sharewmssvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows ms Driversmsnup32.exe"Added by the SDBOT-AAL WORM!"
XWindows MS Update 32fhm.exe"Added by the IRCBOT.GEN WORM!"
XWindows MS Update 32sucker.exe"Added by the FORBOT-GJ WORM!"
XWindows MS Update 32jebote.exe"Added by the FORBOT-GK WORM!"
XWindows MSConfig Startup Loggerwinlog.exe"Added by the RBOT.BCU WORM!"
XWindows MSNMSN.msn"Added by the TRIXCU.A WORM!"
XWindows Msn Live Messangermsnmsgsman.exe"Added by a variant of the SDBOT WORM!"
XWindows MSN Live Messangerwmsnlive.exe"Added by the RBOT.BMV BACKDOOR!"
XWindows MSN Live Messangerlivemsngs.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows MSN Live Messengerwinlivemsn.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows MSN Live Messengerwinmessengerlive.exe"Added by the IRCBOT.EAD BACKDOOR!"
XWindows MSN Updateswnd32.exe"Added by the IRCBOT-ABA TROJAN!"
XWindows MSN2 XPswchost.exe"Added by the KOLAB.AA WORM!"
XWindows MSX driverswinmsx.exe"Added by the RBOT-AYG TROJAN!"
XWindows Network Controllerwinmms32.exe"Added by the FORBOT-ED WORM!"
XWindows Network Controllerwinmms32.exe.exe"Added by the FORBOT-ED WORM!"
XWindows Network ServiceMsconf32.exe"Added by a variant of the RBOT WORM!"
XWindows Performance Monitorwmscupd.exe"Added by the IRCBOT_GEN WORM!"
XWindows Portable Device DriversMSKSVRVS.EXE"Added by a TROJAN - see here"
XWindows Portable DevicesMSKSVRTSS.EXE"Added by the SPYBOT.APEO WORM!"
XWindows Processe Managermspn32.exe"Added by the RBOT.AXO WORM!"
XWindows Recylinder Checkzwdomsgemw.exe"Added by the RBOT-EGJ WORM!"
XWindows Registrymsnmsg.exe"Added by a variant of the RBOT WORM!"
XWindows Rundll Centermsnsmgr.exe"Added by the AGENT-LLB TROJAN!"
XWindows Rundll Centermsmsgrs.exe"Added by the IRCBOT-AFA WORM!"
XWindows Schedulerwmscheduler.exe"Added by a variant of the SDBOT WORM! See here"
XWindows Secure Messaging Systemmsnmsgrsrvc.exe"Added by the RBOT-RE WORM!"
XWindows Secure Servicesssms.exe"Added by the RBOT-GAR WORM!"
XWindows Securityms32.pif"Added by the RBOT-ARN WORM!"
XWindows Service Agentmsnmagr.exe"Added by a variant of the SLAPER TROJAN!"
XWindows Service Agentwmscc.exe"Added by the RBOT-GQP WORM!"
XWindows Service Agentmsngear.exe"Added by the RBOT.AHW BACKDOOR!"
XWindows Service Agentmsngerr.exe"Added by the RBOT.EOZ WORM!"
XWindows Service Agentlcaqmsp.exe"Added by the RBOT.WFR BACKDOOR!"
XWindows Service Agentmsnmsgr.exe"Added by the RBOT.ABIK BACKDOOR! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XWindows Service Managermsgs.exe"Added by the OSCABOT-E WORM!"
XWindows Service Managermsnmrg.exe"Added by the OSCABOT-G WORM!"
XWindows Service oi worms[6 random letters].exe"Added by the SYSTEMHI.OS TROJAN!"
XWindows Service Updatemswsgs.exe"Added by the RBOT.FQB WORM!"
XWindows Servicesscmsg.exe"Added by a variant of the SDBOT WORM!"
XWindows Servicessmsc.exe"Added by a variant of the SDBOT WORM!"
XWindows Services Agentmsngears.exe"Added by the VB-EMS TROJAN!"
XWindows Services Layersslms.exe"Added by the RBOT-GAH WORM!"
XWindows Session Managersmss32.exe"Added by a variant of the RBOT WORM!"
XWindows Session Manager Subsystemsmss.exe"Added by the KALEL-B WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
Xwindows shellext.32mschost.exe"Added by the BLASTER.K WORM!"
XWindows smss serviceservice.exe"Added by the AGENT-FPY TROJAN!"
XWindows Spoolsrv Servicespoolmsv.exe"Added by the SDBOT-ZS WORM!"
XWindows sq Driverswinmsn32.exe"Added by the RBOT-ADI WORM!"
XWindows Streams Serverlocalsrv.exe"Added by the SDBOT.LN WORM!"
XWindows SysNotifymssecc.exe"Added by the AGENT-GFR TROJAN!"
XWINDOWS SYSTEMmsdev32.exe"Added by the MYTOB.EH WORM!"
XWINDOWS SYSTEMsmsc.exe"Added by the MYTOB-BR WORM!"
XWINDOWS SYSTEMmsnl.exe"Added by the MYTOB.IK WORM!"
XWINDOWS SYSTEMmsn32.exe"Added by the MYTOB-FX WORM!"
XWINDOWS SYSTEMmswins.exe"Added by the MYTOB.DP WORM!"
XWindows System Guardmsdn.exe"Added by the FAKEAV-BJD TROJAN!"
XWindows System Guardmsng.exe"Added by the EGGDROP-BO WORM!"
XWindows System Guardmsns.exe"Added by the DWNLDR-IGD TROJAN!"
XWindows System Managersmsc.exe"Added by a variant of the RBOT WORM!"
XWindows System Manager Loadersmsls.exe"Added by the AGOBOT.TF WORM!"
XWINDOWS SYSTEM mscdvvsmscdvvs.exe"Added by the MYTOB.MD WORM!"
UWindows System Traymsni.exe"Iambigbrother monitoring software"
XWindows Systems16winjews16.exe"Added by the SDBOT-CXT WORM!"
XWindows Task Mgrmstasks.exe"Added by the IRCBOT.UN BACKDOOR!"
XWindows Task Mgr!mstasker.exe"Added by the IRCBOT.OE BACKDOOR!"
XWindows Timetmservice.exe"Added by a variant of the RBOT-YK WORM!"
XWindows UDP Control Centermsnmngs.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centermsnpd.exe"Added by the SDBOT.EBA BACKDOOR!"
XWindows UDP Control Centermswinudpmgr32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwinmsn.exe"Added by the SDBOT.EBA BACKDOOR!"
XWindows UDP Control Centerwinudpmsgr.exe"Added by the SDBOT.GAV WORM!"
XWindows UDP Control Centermsnsmsgrs.exe"Added by the PUSHBOT.MF WORM!"
XWindows Updatemsnwinsb.exe"Added by the RBOT-AAH WORM!"
Xwindows updatemsnsever.exe"Added by the RBOT-AHN WORM!"
XWindows Updatemsnupdates.exe"Added by the RBOT-ALK WORM! Note - this file has nothing to do with Windows updates or MSN"
XWindows Updatemsnsupdate.exe"Added by the RBOT-AXS WORM!"
XWindows Updatemsi.exe"Added by the BANKER-XB TROJAN!"
XWindows UpdateMSDEVS30.exeAdded by the SPYBOT.AHC WORM!
XWindows Updatemsconfig32.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows Updatemsnsa32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Updatesmsscr.exe"Added by the BANKER-DK TROJAN!"
XWindows updatemsb32.exe"Added by the GAOBOT.CG WORM!"
XWindows Update Checkermsupdte32.exe"Added by the SDBOT-AEF WORM!"
XWindows Update Firewall Systemwinmsfw.exe"Added by the RBOT-EEO WORM!"
XWindows Update Servicemsupdate32.exe"Added by the DLOADR-CRJ TROJAN!"
XWindows Update Systemmswins.exe"Added by the IRCBOT.DN WORM!"
XWindows Updater Servicesmsnupdate.exe"Added by a variant of the RBOT WORM!"
XWindows USBDmsifirewall.exeAdded by an unidentified WORM or TROJAN!
XWindows Workstationmsup32a.exe"Added by a variant of the SDBOT WORM!"
XWindows Workstation Start Servicemslanmgr.exe"Added by a variant of the RBOT WORM!"
XWindows32 Configuration Loadermsrf32.exe"Added by the SDBOT-ABX WORM!"
XWindows32 Messenger Servicemsmsgv.exe"Added by the RBOT.ANS WORM!"
XWindows32 Net Databasemsnd32.exe"Added by the RBOT-AAL WORM!"
XWindowsRegKey%$ updatemsi332.exe"Added by the RBOT-IX WORM!"
XWindowss Service Agentmssngear.exe"Added by the RBOT.KGU BACKDOOR!"
XWindowsSystem32msnmssgr.exe"Added by the AGENT.ALY BACKDOOR!"
XWindowsSystem32msn_kilo.exe"Added by the AGENT.ALY BACKDOOR!"
XWindowsSystem32msnmgaer.exe"Added by the AGENT.ALY BACKDOOR!"
XWinDOwsUPdatesmss.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
XWinDynManageramsnmsg.exe"Added by the SDBOT-IA BACKDOOR!"
XWinhlp32Wscript.exe Msexec32.vbs"Added by the GANT.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Msexec32.vbs"" file is found in %System%"
Xwinlogin.exemspaint.exeAdded by a variant of the AGENT.AH TROJAN!
Xwinlogonmsreg32.exe"Added by the SDBOT.EO WORM!"
Xwinlogon.exemsole32.exe"Adware
XWinMediamsupd******.exe [*= random digit]Added by the INJECT.163 TROJAN!
XWinmsgwinwork.exe"Added by the GAOBOT.GEN!POLY WORM!"
XWinMsgwinmsgr.exe"Added by the DLOADR-AS TROJAN!"
XWinmsgwinwork8.exe"Added by the AGOBOT-GC WORM!"
XWinMsrv32WinMsrv32.exe"Added by the GAOBOT.AFJ WORM!"
Xwinnsvcmsvc.exe"Added by the PWS.O TROJAN!"
XWinnt DNS identmsnmsrg.exe"Added by the RBOT.BVQ WORM!"
Xwinrunmsconfig.exe"Added by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrun"
XWinsSystemsyssmss.exe"Added by the DELF.IG TROJAN!"
XWinsvrmsupd******.exe [*= random digit]Added by the INJECT.163 TROJAN!
UWinSystemWinSystems.exe"CMKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
Xwinsystem.syssmss.exe"Added by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\win32 and note the space at the beginning of the ""Startup Item"" field"
XWinSystemswinsystems16.exe"Added by the SDBOT-CZT WORM!"
Xwinsystems25winsystems.exe"Added by the RBOT-CNZ WORM!"
XWINTASKmsmgrxp.exe"Added by the MYTOB.AQ WORM!"
XWINTASKmsvhost.exe"Added by the MYTOB-AR WORM!"
XWINTASK DLL32smsrss.exe"Added by the MYTOB.BS WORM!"
XWinTimermsupdate.cmd"Hijacker - detected by Kaspersky as the STARTPAGE.TJ TROJAN!"
XWintlmsdred.exeIdentified as a variant of the Trojan-Spy.Win32.Agent.cch malware
XWinUpdate Loadermsnnm.exe"Added by the REVCUSS.C TROJAN!"
Xwinupdate2846vbsystem35.exe msvbrun.exe"Added by a variant of the MUTIN-C TROJAN!"
Xwinystems25winystems.exe"Added by a variant of the SDBOT WORM!"
XWMDM PMSP Servicecssrss.exe"Added by the KNOCKIT-A TROJAN!"
Xwms3wms3.exe"Added by the LEGMIR-AQG TROJAN!"
XWMSDOS-ServicePack2cmd.exe /c C:WMSDOS.sys"Detected by Bitdefender as the DELF.OFC TROJAN! See here. Note that cmd.exe is a legitimate Microsoft file normally located in %System% and shouldn't be deleted"
Xwmsrc.exewmsrc.exe"PrivacyRedeemer rogue privacy program - not recommended
Xwmsys32wmsys32.exe"Added by the BANPAES.B TROJAN!"
?WM_LOGINMSGLOGIN.EXE"Part of McAfee Firewall. What is it for and is it needed?"
XWormslogon.bat"Added by the DELMP3-A WORM!"
XWSAConfigurationmsnote30.exe"Added by the AGOBOT-KF BACKDOOR!"
Xwscmstdl.exe"MaCatte Antivirus 2009 rogue security software - not recommended
XWSSVCsmsc.exe"Added by the AUTORUN-AGA WORM!"
UXE 8x LM Statuslmsxxe.exeXerox XE8 series laser printer status monitor
XXML Servicemsxml.exe"Added by the RBOT-HD WORM!"
XXMLmedia 10.0wmsdkns.exe"Added by the FAKEALERT TROJAN!"
Xxmstartxuming.exe"Added by the GMIN-A WORM!"
XxpsystemMSXMIDI.EXE"CoolWebSearch parasite variant
Xxswdmse[8 random letters].exe"Added by a variant of the SPYBOT WORM! See here"
?XWMSUSBAPIXWMSAPI.EXE"Part of the installation of a Xerox WorkCentre printer/scanner. Is it required?"
XYahoo Instant MessengarYahooMsgr.exe"Added by the SDBOT.GEN TROJAN!"
XYahoo MessengerYahoomsg.exeAdded by an unidentified WORM or TROJAN!
XYahoo! Messangerymsngr32.exe"Added by the WOOTBOT.HY WORM! Note - this should not be confused with Yahoo! Messenger"
XyahoomsgrYahoomsngr.exe"Added by the AGOBOT.AKZ WORM!"
NYeppStudioAgentSamsungMediaStudioAgent.exe"Samsung Media Studio MP3 player file management software - see here for an example"
XYhooUapdatesymssmsgs.exe"Added by a variant of the SMALL_K TROJAN!"
XYhooUpdatesymsmsgs.exe"Added by the SMALL_K TROJAN!"
XYourMP3"rundll32.exe MSA64CHK.dllDllMostrar"
NZebusmsdc32.exeRuns a HTML tutorial on the Zebus web-site
XZip Driver Loadermsload32.exe"Added by the OBLIVION TROJAN! This executable is one of the most common but there are more"
Xzsmssmss.exe"Added by the BANCOS-CK TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xzsmsccrundll32.exe zsmscc071001.dll mymain"Added by the GENETIK.KQ TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""zsmscc071001.dll"" file is found in %System%"
Xzsmsccrundll32.exe mycc071208.dll mymain"Added by the AGENT.FZK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""mycc071208.dll"" file is found in %System%"
Xzsmsgsiservice.exe"Added by the BANCOS-BU TROJAN!"
Xzsmsssmss.exe"Added by the BANCOS-DD TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X[random characters]rsbmsc.exe"Detected by AntiVir antivirus as the BDS/Agent.adt TROJAN!"
X[random name]msiexec.exe"PurityScan adware. Do not confuse with the legitimate Windows® Installer (msiexec.exe) process which is always located in %System% and should not figure in Msconfig/Startup!"
X[various names]msdos32.exeAdded by a variant of the AGENT.AH TROJAN!
X[various names]msag.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]ms-its.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]MsNetHelper.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]MSTCPDLL.exe"Wareout - malware masquerading as a spyware and dialer remover"
Y_AntiSpywareMssCli.exe"Part of McAfee AntiSpyware"
X_Cat1nmmst.exe"Added by the SMALL.SD TROJAN!"
X_Cat2nmstt.exe"Added by the SMALL-DT TROJAN!"
X_Cat3msmsgrxp.exe"Added by a variant of the SMALL-DT downloader TROJAN"
X_Cat4msmsgr2.exe"Added by the SMALL-EB TROJAN!"
X_Services.dllsmss.exe"Added by the SOBER-L WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\system"
X_winsystem.syssmss.exe"Added by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\win32"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.