Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
?.NET configsysmon32.exe"??"
X.nvsvcsmss.exe"Added by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
X.nvsvcbsmssb.exe"Added by the BOXED.CG TROJAN!"
X27msm32.exe"Added by the SLSORVE-E TROJAN!"
UAbsolute StartUp monitorASMon.exe"Absolute Startup - startup monitor from F-Group Software"
UAccessManagerAccessMgr.exe"Part of SmartPipes SecureSite software. ""SecureSite enables rapid turnup and enhanced administration of VPNs. It automates and simplifies tasks for VPN design and policy management
XAccessMedia P2P Loaderamp2pl.exe"My AccessMedia toolbar related
?Acer Empowering Technology MonitorSysMonitor.exe"Part of Acer Empowering Technology. What does it do and is it required?"
XAdobeReaderProssysmsn.exe"Added by the RBOT-BGH WORM!"
YADSMTrayADSMTray.exeASUS Data Security Manager provides password protected data encryption on ASUS notebooks
Xafmsmsgsafmsmsgs.exe"Added by the DLOADR-CUX TROJAN!"
UAgere SoftModem Messaging AppletAGRSMMSG.exeInstalled with the drivers for internal software modems based upon Lucent/Agere Systems chipsets - required if you use the SoftModem Assistant to configure the modem
UAGRSMMSGAGRSMMSG.exeInstalled with the drivers for internal software modems based upon Lucent/Agere Systems chipsets - required if you use the SoftModem Assistant to configure the modem
XAltnetPointsManagerpoints manager.exe"Altnet TopSearch adware"
XAntiSpywareMasterasm.exe"AntiSpywareMaster rogue security software - not recommended
XAntiVirsmss.exe"Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%"
UAntiWindowsMessengerAntiMsMsg.exe"Anti-Windows_Messenger is a small application that prevents Windows Messenger from remaining resident in memory"
UAOL TopSpeedMonitoraoltsmon.exe"AOL's TopSpeed ""web-acceleration technology speeds up your web-browsing experience by storing and reusing elements of web pages that you visit
XApplicationProtocolRunsmsbvl32.exe"Added by the IRCBOT-CX TROJAN!"
XAsiaeasm.exe"PurityScan adware"
UASMASMonitor.exe"Active Security Monitor from AOL - helps you determine how vulnerable your PC is to computer viruses
UAsmw Soft Popups Burnerpopups burner.exe"Popup blocker
UASUS SmartDoctorVGAProbe.exeASUS video card fan/thermal monitor
UATISmartati2s9ag.exe"ATI's ""SMARTGART""
XAudioManExplorer.sm1"Added by the HUPIGON.IFZ BACKDOOR!"
XAudoi Device Loadersmssv.exe"Added by the AGOBOT-ZY WORM!"
Xauloadplxmplprogsm.exe"Added by the SLAPER.K TROJAN!"
UAutoroute SMTPAutoSmtp.exe"Autoroute SMTP - ""automatic switching between SMTP servers depending on what network you are currently working in."" You need to have two Internet service providers"
XAutoUpdatesmss.exe"Added by WINSPY.88! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64"
Xavnortmsmbw.exe"Added by the SERFLOG.A WORM!"
XAvSerdsm.exe"Added by the SERFLOG.B WORM!"
XAvSermsmpatch.exe"Added by the SERFLOG.B WORM!"
XAvSersvosm.exe"Added by the SERFLOG.B WORM!"
XAwoasmmo.exe"PurityScan adware"
Xb99msmm.exe"ClientMan parasite variant"
XBackup Onesmbguard.exe"Added by the SDBOT-MI WORM!"
XbalSYSMONMS.EXE"Added by the FAKEALERT TROJAN!"
YBCMSMMSGBCMSMMSG.exeBCM voicemodem driver. Required for dial-up if you have one of these modems
XBedreigingsMonitoorpgs.exe"BedreigingsMonitoor rogue security software - not recommended. A member of the AVSystemCare family"
Nbgsmsndbgsmsnd.exePrinter driver to generate PDF files from any program
Xblah servicesmnp.exe"Added by the RBOT.IZ WORM!"
XBootCleansmartdrv.exe"Added by the LURKA-A VIRUS!"
?BsMntBsMnt.exe"Related to a Bison webcam - which is used on notebooks from a number of manufacturers including Acer
Xcdmmslpoklpllsm.exe"Added by the TEDIJINI-A TROJAN!"
Xcesmain.dll"Rundll32.exe [path] cmail.dll Rundll32"
UChangeICONSPMSMON.EXECard reader related program. Note - may cause problems with My Computer loading at startup. Disabling through MsConfig seems to solve the problem
XChansonsMP3"rundll32.exe MSA64CHK.dllDllMostrar"
UCHIPDRIVESmartcardManagerSCMgr.exe"ChipDrive Smartcard software"
UCleanSweep Smart Sweep- Internet SweepCsinsm32.exeAutomatic logging of installs from Norton CleanSweep - available via Start -> Programs
XClient Server Runtime Processsmmss.exe"Backdoor TROJAN! Possible SDBOT-GEN variant"
?CLMLServer for HP TouchSmartCLMLSvc.exe"Found on the HP Touchsmart range of desktops and notebooks. What does it do and is it required?"
?CM-SmWizardSmWizard.exe"SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required?"
Xcmonitorpasmon.exe"SystemDoctor rogue security software - not recommended
XcmssSystemProcesscsmss.exe"Added by the AGENT-CO TROJAN!"
XcmssSystemProcessmcsmss.exe"Added by the PROXYSER-F TROJAN!"
XcmssSystemProcesscsms.exe"Added by the AGENT-Y TROJAN!"
XCnsMaxInternat.exe"Added by the POINTEX TROJAN! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) whereas this version resides in %windir%"
XCnsMin"Rundll32.exe [path] CNSMIN.DLL Rundll32"
NCOMSMDEXEcomsmd.exe3Com tray icon
XConfig LoaderSYSMGR.EXE"Added by the AGOBOT.C WORM!"
XConfiguration Loadersmss32.exe"Added by the AGOBOT.MB WORM!"
XConfiguration Loadersmsai.exe"Added by the SDBOT-YE WORM!"
XConnectorsms.EXE"Added by the ExDial-B premium rate adult content dialer"
Ncontrol panelsmctrlw.exeSystem Tray icon for a Silicon Motion LynxEM based PCI Graphics Card
XControlServiceMgrcsmsv.exe"Added by the AGENT-XC TROJAN!"
XCrossMenuCrossMenuToshiba CrossMenu Utility - allows the user to create their own menus
UCrossMenuCrossMenu.exeToshiba CrossMenu Utility - allows the user to create their own menus
Xcrsmonsiomssls.exe"Added by the BACKDR-AU TROJAN!"
Xcsm Win Updatescsm.exe"Added by the ZOTOB.B WORM!"
Xcsrssmsmsgs.exe"Added by the CHODE-J BACKDOOR! Note - this malware uses MSN Messenger (which is located in %Program Files%\Messenger) in the background to propogate itself"
Xcsrssssms.exeAdded by an unidentified malware
Xdcsmdcsm.exe"Part of the PrivacyProtector and DriveCleaner rogue security tools"
XDebugSMSS.exe"DreamAd adware. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UDell PanelMgrSSMMgr.exe"Monitors ink levels
Xdevenvsmvss.exe"Added by the DEDLER-G TROJAN!"
XDHCPsmss.exe"Added by the WINSPY.AG TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\display"
UdRMON SmartAgentSmartAgt.exe"Part of the network monitoring program group for 3Com NIC cards. See here for more info"
XDsmSerdsm.exe"Added by the SERFLOG.B WORM!"
XDsmSermsmpatch.exe"Added by the SERFLOG.B WORM!"
XDsmSersvosm.exe"Added by the SERFLOG.B WORM!"
XDsmSersysup.exe"Added by the SERFLOG.B WORM!"
UEasy-PrintToolBoxBJPSMAIN.EXEA utility to launch the applications that are bundled with a Canon bubblejet printer
XEbatesMoeMoneyMakerwjview ...Code"Ebates adware"
XEbatesMoeMoneyMaker0EbatesMoeMoneyMaker0.exe"Ebates adware"
Xebmmmebatesmmmv.exe"Ebates adware"
XELNKProxysmproxy.exe"Surfmonkey adware"
?ENSMIX32.EXEENSMIX32.EXE"Sound card driver. Is it required?"
UEnterprise HarmonyrsMenu.exe"Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
UEnterprise Harmony '99rsMenu.exe"Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
XEthernet Driverssmrrs.exe"Added by the RBOT-AAK WORM!"
YeTrustCIPEezdsmain.exeeTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior
XEventApplicationCmdsmschk.exe"Added by the IRCBOT-AO TROJAN!"
UEZSMART Appezsmart.exeEZ-S.M.A.R.T. hard drive monitoring software from StorageSoft - appears to be no longer supported
UF-Secure Management AgentFSMA32.EXE"F-Secure antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products"
YF-Secure ManagerFSM32.EXE"F-Secure antivirus - carry out scheduled virus scans automatically"
Xfastsmellfastsmell.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
UFaxCtrl.exeASMediaProxyServer.exe"Part of Avaya's Contact Center Express - ""a multi-channel
?FBIFBISM.exe"Compaq related but what does it do?"
XFireFox Service Driversssmss.exe"Added by a variant of the SDBOT WORM!"
NfkSysMonfksysmon.exe"fkWrae SysMon - system monitor - ""displays the current memory consumption
XG3GSMedia3.exe"Malware downloader - detected by Kaspersky as the VB.UX TROJAN!"
UGARO Status Monitorcnwism.exePrint monitor for certain Canon printers
NGet Smilegetsmile.exePuts smilie faces in your E-mail. Run manually when required
Xgimmysmileysgimmysmileys.exe"GimmySmileys adware"
XGLSetT32smsiexec.exe"Added by the OPTIX-D TROJAN!"
XGMedia2GSM2.exe"Malware downloader - detected by Kaspersky as the VB.UX TROJAN!"
XGMedia2GSMedia3.exe"Malware downloader - detected by Kaspersky as the VB.UX TROJAN!"
XGotSmileyGotSmiley.exe"GotSmiley - ad supported program that provides the user with smileys for use in emails. Not recommended. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XGraphic Driversmss32.exe"Added by a variant of the RBOT WORM!"
UHostsManhm.exe"""HostsMan is a freeware application that lets you manage your Hosts file with ease"". It is mainly intended to block specific domains (mostly advertising servers) by redirecting them to localhost
NHP Photosmart Premier Fast Starthpqthb08.exe"Improves the startup time of HP Image Zone. If you disable it
YICSMGRICSMGR.EXEMonitors DNS and DHCP requests for ICS (Internet Connection Sharing). Needed if you're sharing the internet on various computers
XIE6ssmss.exe"Added by the GAOBOT.DXO WORM!"
Xinfosmss.exe"Added by the VB.EIW WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\inetsrv"
XIntec Service Driversmsmsgrs.exe"Added by the SDBOT-ADN WORM!"
XIntec Service Driversmsmsgredss.exe"Added by the SDBOT-AGL WORM!"
XInteliSyssmss.exe"Advertisingvision adware. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xinternetsmss.exe"Added by the MIFENG-K TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
Niolo Utility BarSMUtilityBar.exe"Iolo System Mechanic Utility Bar - can be launched manually"
XISMModuleISMModule.exe"Internet Speed Monitor C adware related - see example here"
XISMModule2ISMModule2.exe"Internet Speed Monitor C adware related - see example here"
XISMModule3ISMModule3.exe"Internet Speed Monitor C adware"
XISMModule4ISMModule4.exe"Internet Speed Monitor A adware related"
XISMModule6ISMModule6.exe"Internet Speed Monitor C adware related - see example here"
XISMModule7ISMModule7.exe"Internet Speed Monitor C adware related - see example here"
XISMModule8ISMModule8.exe"Internet Speed Monitor C adware related"
XISMPack5ISMPack5.exe"Internet Speed Monitor C adware related - see example here"
XISMPack6ISMPack6.exe"Internet Speed Monitor C adware related - see example here"
XISMPack7ISMPack7.exe"Internet Speed Monitor C adware"
XISMPack8ISMPack8.exe"Internet Speed Monitor C adware related - see example here"
XJava Applicationvssmf32.exe"Added by the SPIGOT BACKDOOR!"
XKernel Safe Modesmss.exe"Added by the 78CRACK-A TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XKernelFaultChksms.exe"Added by the DEADHAT WORM! Do not confuse with the valid ""kernelfaultcheck"" which runs ""dumprep 0 -k"" or ""dumprep 0 -u"""
XKernellApps32smss.exe"Added by the BANCBAN-AN TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
XLayersecurity ServicemonitorLSSMON.EXE"Added by the BANKER.ZAQ TROJAN!"
ULCD SmartieLCDSmartie.exe"""LCD Smartie is software for Windows that you can use to show lots of different types of information on your LCD/VFD."" Typically used by the PC modding community to display statistics such as CPU temp
XLiveUpdatesmss.exe"Added by the VB.BAU BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas"
XloadMefssmss32.exe"Added by the FLOOD-EL TROJAN!"
ULogitech ClickSmartISStart.exe"Installed with Logitech's QuickSmart webcam software. The exact purpose of this startup entry is unknown at present
ULogitech ClickSmartLogiTray.exe"System Tray access to My Logitech Pictures
ULogitech ClickSmartLVCOMS.EXEEntry added when you install Logitech ClickSmart webcam software. It allows the camera to be accessed by both the Logitech software and (amongst others) NetMeeting and Windows Movie Maker. If you don't use the camera on a daily basis create your own shortcut and run it manually when required
YLogitechCommunicationsManagerCommunications_Helper.exe"Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also
XLosMejoresMP3"rundll32.exe MSA64CHK.dllDllMostrar"
NLotus QuickStartsmartctr.exe"Lotus central application
Xlsmasslsmass.exe"Added by the WALLOP-B TROJAN!"
Xlsmss.exelsmss.exe"Added by the PROXY-GG TROJAN!"
NLTSMMSGLTSMMSG.exe"Lucent Tech. Soft Modem Messaging application - may be found on Fujitsu Lifebook
XLTSMSGShell32.exe"Added by the LEMIR.B TROJAN!"
Xltwobmsmbw.exe"Added by the SERFLOG.A WORM!"
Xmackfy.exemsms.exe"Added by the SDBOT-DID WORM!"
XManageProtocolCtrlcsmsv.exe"Added by the LOOKSKY.B TROJAN!"
Xmbsmon32mbsmon32.exe"Micro Bill Systems Billing Software - ""is a potentially unwanted application that uses aggressive billing and collection service techniques to demand payment for Web site access after a three-day trial period has elapsed. It has been reported that these techniques may even result in a user no longer being able to browse the Internet"""
Xmbssm32mbssm32.exe"Micro Bill Systems Billing Software - ""is a potentially unwanted application that uses aggressive billing and collection service techniques to demand payment for Web site access after a three-day trial period has elapsed. It has been reported that these techniques may even result in a user no longer being able to browse the Internet"""
Xmbssm32monstu.exe"Detected by AVG as the AGENT.CNM TROJAN - see here"
UMDSA Sentinel Xsmss.exe"SentinelX surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the smss.exe process which is always located in %System%. This one is located in %ProgramFiles%\MDSA Software"
XMessage Queuingmsmqs.exe"Added by the FREEFORS TROJAN!"
NMessengermsmsgs.exe"Windows Messenger instant messenger utility included with Windows 2K/XP. Available via the Start menu. Go to Windows Messenger → Tools → Options → Preferences and uncheck ""Run this program when Windows starts"""
XMessenger Gatewaymsmgs.exe"Added by the AGENT-IGK TROJAN!"
XMessenger Servicemsmsgs.exe"Added by the SDBOT-ZB WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
UMFP PanelMgrSSMMgr.exe"Monitors ink levels
XMicroedSoft ToolbarSmoked.exe"Added by the RBOT-ALN WORM!"
XMicrosft Security Monitor Processmssmppp.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosft Security Monitor Processmssmpp.exe"Added by the SDBOT-DJW WORM!"
XMicrosoftssmss.exe"Added by the RBOT-FZF WORM!"
XMicrosoftmsmsger.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft (R) Windows Network Security Management Servicensms.exe"Added by the RANKY.LC TROJAN!"
XMicrosoft CSRSS Servicensmscrs.exe"Added by the RBOT-BPT WORM!"
XMicrosoft DirectXrasmngr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Driver Setupsysmngsr322.exe"Added by the BUZUS-AS TROJAN!"
XMicrosoft Excelemsmsgs.exe"Added by the AGENT.AJQG TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMicrosoft Internel Corporatsmbvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Internet ServicesSmss32.exe"Added by the RBOT.MS WORM!"
XMicrosoft Macro Protection Subsystemsmsmacroprotxz.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Macro Protection SubsystemsMsmacroprot32.exe"Added by the RBOT.KN WORM!"
XMicrosoft Managermsmanager.exe"Added by the MYTOB.LF WORM!"
XMicrosoft Media player 9msmedia32.exe"Added by the RBOT-ADO WORM!"
XMicrosoft Message Machinemsmesg32.exe"Added by the SPYBOT.BI WORM!"
XMicrosoft Messenger Management Controlsmsmgmctl.exe"Added by the RBOT-APA WORM!"
XMicrosoft Messenger Servicemsmsg32.exe"Added by the RBOT.BOK WORM!"
XMicrosoft Messenger XPMSMSN32.exe"Added by the RBOT-ZP WORM!"
XMicrosoft Msn Messengermsmsgs.exe"Added by the BUZUS.AYX TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMicrosoft MSN Servicesmsnsm.exe"Added by the RBOT.ARV BACKDOOR!"
XMicrosoft OfficeMSMSGR.exe"Added by the GAOBOT.BB WORM!"
XMicrosoft Officemsmsgr.exe"Added by the GAOBOT.BB WORM!"
XMicrosoft Ofticemsmsgs.exe"Added by the IRCBOT.ALT WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMicrosoft Security Monitor Processmssmp.exe"Added by the RBOT-FUB WORM!"
XMicrosoft Security Monitor Processmnsmp.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processmsmp.exe"Added by the RBOT.GKQ WORM!"
XMicrosoft Security Monitor Processmssm32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Security Monitor Processmssm32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processmssmpi32.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft ServicesSmss32.exe"Added by the RBOT-AD WORM!"
XMicrosoft Servicesmsmpserv.exe"Added by the IRCBOT.BKA BACKDOOR!"
XMicrosoft Session Manager Subsystemsmss.exe"Added by the KALEL-D WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
XMicroSoft sys32sysmsgr32.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft System Checkupntsysmgr.exe"Added by the DONK.S WORM!"
XMicrosoft System Checkupntsysman.exe"Added by the SDBOT-QW WORM!"
XMicrosoft System Checkuplibsysmgr.exe"Added by the SDBOT-CAF WORM!"
XMicrosoft System Checkupsysmgr.exe"Added by the SDBOT-OO TROJAN!"
XMicrosoft System Firewall 2006.2msmsgr.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft System Servicesmsmsgr.exe"Added by the RBOT-ZH WORM!"
XMicrosoft Updatemssmgrd.exe"Added by the SDBOT.JT WORM!"
XMicrosoft UpdateSmss32.exe"Added by the RBOT-CB WORM!"
XMicrosoft Update Machinepsmszw.exe"Added by the KOLABC.CC WORM!"
XMicrosoft Virual Machinesms.exe"Added by the RBOT-SP WORM!"
XMicrosoft Windows GUImsmonk32.exe"Added by the SDBOT-PE WORM!"
XMicrosoft Windows Session Manager Subsystemsmss.exe"Added by the PROXYSER-R TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft's System ModuleSysmodule.exe"Added by the BDOOR-FJ BACKDOOR!"
XMicrosoft(R) System Managersysmgr.exe"Added by the AGENT.QTR TROJAN!"
XMicrosoftOEMsmvss.exe"Added by the DEDLER-G TROJAN!"
XMicrosoft© System MapperSysMap.exe"Added by the MAPSY TROJAN!"
XMismowin32x.exe"Added by the RBOT-JP WORM!"
Xmlibsysmccomzcinc.exe"Added by the SDBOT-CXS WORM!"
NMotive SmartBridgempbtn.exe"System tray icon for the Virtual Assistant from AT&T Broadband
NMotive SmartBridgeMotiveSB.exe"System tray icon for the Virtual Assistant from AT&T Broadband
NMotive SmartBridgeBTHelpNotifier.exe"System tray icon for help from BT Broadband
UMPEOCsinsm32.exeAutomatic logging of installs from Norton CleanSweep - available via Start -> Programs
XMS Config Streammsasm.exe"Added by the AGOBOT-BA WORM!"
XMS MSN Menssenger 7.0MSMSN7.exe"Added by the RBOT-ACA WORM!"
XMS Unix Binarymsmq2inst.exe"Added by the RBOT-YF WORM!"
XMSFWAVTSMFTPDev.exe"Added by the RBOT-ACF WORM!"
Xmsgsm32msgsm32.exe"Added by the RBOT-ASG WORM!"
XMSInstallsmvss.exe"Added by the DEDLER-G TROJAN!"
Xmsmmsm.scr"Added by the BANKER-EHJ TROJAN!"
Xmsmacro32msmacro32.exeIdentified as a variant of the AGENT.QB TROJAN!
Xmsmacro32msmacro64.exe"Added by a variant of the BACKDOOR-DOQ TROJAN!"
XMsManagermsmgr32.exe"Added by the YAHA.AF WORM!"
Xmsmanager32msmngr32.exe"Added by the RANDON-R (or WOMANIZ.A) WORM!"
Xmsmautoprotectmsmssgs.exe"Added by the BIFROSE-AJ TROJAN!"
Xmsmcmscpbo.exe"ClientMan parasite variant"
Xmsmcmsgdmf.exe"ClientMan parasite variant"
Xmsmcmsongn.exe"ClientMan parasite variant"
Xmsmcmsmc.exe"ClientMan parasite variant"
Xmsmcms****.exe [* = random char]"ClientMan parasite variant"
XMSMcAfeeeAvsynmgr32e.exe"Added by the FRAMAR TROJAN!"
XMSMcAfeehAvsynmgr32h.exe"Added by the FRANGO TROJAN!"
XMSMcAfeeSAvsynmgr32S.exe"Added by the VOLAC or VOLAC.DR TROJANS!"
XMSMessngermsnupd.exe"Added by the RBOT-ADY WORM!"
?msmgrmsmgr.exe"??"
XmsMGRrtkmsg.exe"Added by the SDBOT-BPY WORM!"
XMsmgtmsmgt.exe"Total Velocity adware/hijacker"
Xmsmmimsmmi.exe"Added by the AGENT.RFR TROJAN!"
XMSMNTGNTMSMNTGNT.EXE"Added by the BANKER-IE TROJAN!"
XMSMNTJBEMSMNTJBE.EXE"Added by the BANCOS-EF TROJAN!"
XMSMNTJNGMSMNTJNG.EXE"Added by the GRABER-G TROJAN!"
XMSMNTMTSMSMNTMTS.EXE"Added by the BANKER-GZ TROJAN!"
Xmsmonmsmon.exe"Added by a variant of the GEMA.D TROJAN!"
XMsMon32MsMon32b.exe"Added by the SDBOT.O BACKDOOR!"
XMsMoviesMsMovies.exe"Added by the ALCRA-E WORM!"
?MsmqIntCertregsvr32 /s mqrt.dll"Microsoft Message Queue Server - Internal Certificate - see here for more info and here for a potential problem. Is it required?"
XMSMSGNER[4-8 random letters].exe"Added by the FOWLDO-GEN TROJAN!"
XMSMSGNERzzgf.exe"Added by the PWS-CCB TROJAN!"
XMSMSGNERfgozmox.exe"Added by the AGENT-EBJ BACKDOOR!"
Xmsmsgrmsmsgss.exe"Detected by Kaspersky as the RBOT.AJJ WORM!"
NMSMSGSmsmsgs.exe"Windows Messenger instant messenger utility included with Windows 2K/XP. Available via the Start menu. Go to Windows Messenger → Tools → Options → Preferences and uncheck ""Run this program when Windows starts"""
XMsmsgsMsmsgs.exe"Added by the SILLYFDC-AP WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMSMsgsmsmessgs.exe"Added by the SMALL-EW TROJAN!"
Xmsmsgsmsmsgs.exe"Added by the SCLOG-AL TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMSMSGSwinlogon.exe"Added by the BRONTOK-BS WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
Xmsmsgs.exeIEXPLORE.EXE"Added by the VB.FQX TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMsMsgSrvmsmsgsrv.exe"Added by the CQO TROJAN!"
Xmsmsgss[path to trojan]"Added by the RANKY.G BACKDOOR!"
XMSMsgSvcMSMSGSVC.exe"Browser hijacker
Xmsmsngrmsmsngr.exe"Added by the DOPBOT-B WORM!"
XMSNsmsss.exe"Added by the BUZUS-D WORM!"
XMSN Configuration Loadermsmsncfg.exe"Added by the AGOBOT-KX BACKDOOR!"
XMSN messangermsnmsgsm.exe"Added by the RBOT-FMP WORM!"
XMSN Messangermsnmsgsmn.exe"Added by the RBOT-FOQ WORM!"
XMSN MessengerReosmsngr.exe"Added by a variant of the SPYBOT WORM!"
XMSN MESSENGERmsmmsgr.exe"Added by the KELVIR.Q WORM!"
XMSN Messengermsmsgs.exe"Added by the ZLOB TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMSN Messenger User Controlsmsmsgr.exe"Added by the KELVIR.HI WORM!"
XMSN MMISSENGERmssmmspgr.exe"Added by the KELVIR.AJ WORM!"
XMSN Registry loadermsmnwin.exe"Added by the KELVIR.FK WORM!"
XMSN Servmsmsnserv.exe"Added by the IRCBOT.AVF BACKDOOR!"
XMSN Servermsmsnserver.exe"Added by the IRCBOT.AUS BACKDOOR!"
XMsn Update Manager (Sp2)MSMSGS.EXE"Added by the AGOBOT-NL WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XmsnsmgrMsnMsr.exe"Added by the LOONY-N TROJAN!"
Xmssoulmsmscc2.exe"Added by the DAPIZL.A banker WORM! (A ""banker worm"" is designed to pillage banking information and send it back to the perpetrators!)"
Xmssoulmsmscc.exe"Added by the BANCOS.HKT TROJAN!"
Xmssyslanhelpermsmsgri32.exe"Added by the RANDEX.D WORM!"
XMSVsmtrpcxctx.exeAdded by an unidentified WORM or TROJAN!
XMsWindows SysDatesysmsvc.exe"Added by the SPYBOT.FCD WORM!"
XMULTIMEDIA KEYBOARD88smss.exe"Added by the SILLYFDC WORM! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
NMutexServiceExSys32Smm.exe"Webroot Sofware's discontinued ""Privacy Master"""
?mxomssmenumaxmenumgr.exe"Related to Maxtor's One Touch series of external hard drives. What does it do and is it required?"
XMy AppSMSSvc.exe"Added by the NEGASMS.A TROJAN!"
XMyAccessMediatmp**.exe [* = random char/digit]"My AccessMedia toolbar related
XNarmonVirusAntismss.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
NNCS_SSCsinsm32.exeSame as CleanSweep Smart Sweep-Internet Sweep
NNero PhotoShow Media Managermssysmgr.exe"Nero rebranded version of Simple Star's PhotoShow photo editing and organizing software
XNeroAutoStartClientNeroASM.exe"Added by the AGOBOT.VG WORM!"
UNETGEAR WG111T Smart Wizardwlan111t.exe"Configuration utility for the Netgear WG111T multi-rate Wireless USB 2.0 Adapter that ""provides wireless access to your desktop or notebook PC through the computer's USB port"""
XNetwork Host Servicemsmnart32.exe"Added by the RBOT-CJV WORM!"
XNetzip Smart Downloadernpnzdad.exeAdvertising spyware
XNew Csnm Managercsmn.exe"Added by the SDBOT.BZS WORM!"
XNI.UERSM_0001_N68M1602[path to file]"Installer for the ErrorSafe rogue system error and cleaning utility - see here"
XNI.UGESM_0001_N122M0303[path to file]"Installer for the DokterFix Dutch rogue system error and cleaning utility - see here"
XNLS Monitornlsmon.exe"Added by the RBOT-AXJ WORM!"
Xnotepad.exemsmsgs.exe"Added by the ZLOB TROJAN and variants! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
Xntfsmonitorprontfs64.exe"Added by the FORBOT-EB WORM!"
XNTSF MICROSOFT SYSTEMsysman.exe"Added by the RBOT.EDP WORM!"
Xntsmodntsmod.exe"Adware downloader/installer
XNvCplDaemonmsmsgrs.exe"Added by the DLOADER-YI TROJAN!"
UOnlinePCfix SmoothSurferSS.exe"Smooth-Surfer - blocks banners
Xorder_Shellorder_smey.exe"Added by the BANKSNIF-H TROJAN!"
XPaintingRoom smile monitorpaintingroom.exePaintingroom.com smiley software - not recommended as the site tries to drop a trojan on you...
XPASMonitorpbm.exe"PersonalAntiSpy rogue spyware remover - not recommended
Xpas_checkpasmon.exe"SystemDoctor rogue security software - not recommended
NPC Suite for SmartphonesApplication Launcher.exe"System Tray access to the Sony Ericsson PC Suite mobile phone management utility for some models
UPervasive.SQL Workgroup EngineW3dbsmgr.exeDatabase Service Manager for Pervasive SQL 2000 Workgroup edition. Required if you use Pervasive SQL but it's recommended you start it manually before using it as it has a tendancy to crash/freeze if loaded with other applications at startup
NPhotoShow Deluxe Media Managermssysmgr.exe"Simple Star PhotoShow Deluxe photo editing and organizing software
UPop-Up SmasherPopupSmasher.exe"Pop-Up Smasher - pop-up killer"
UPRISMSTA.EXEPRISMSTA.EXECreates a system tray icon for accessing information about Intersil Prism Wireless Settings. Intersil silicon is used by Trendware/Trendnet for example
UPRISMSVRPRISMSVR.EXEConfiguration and settings utility for PRISM chipset based wireless modems such as the 2Wire Wireless Gateway (2701HG) and Siemens Gigaset USB Adapter
UPRISMSVR.EXEPRISMSVR.EXEConfiguration and settings utility for PRISM chipset based wireless modems such as the 2Wire Wireless Gateway (2701HG) and Siemens Gigaset USB Adapter
XProteção de telassmaze.scr"Added by the BANCBAN-FB TROJAN!"
UPsMFCardPsMFCard.exe"Component of the Toshiba Controls. Provides power-saving functions for the PCMCIA slots. Through the Power Save Mode Properties dialogue
URandsoft Harmony '98rsMenu.exe"Randsoft Harmony '98 (superseded by Enterprise Harmony 99) for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
XRasCon Remote Access Service Managerrasmngr.exe"Added by the SPYBOT.EM WORM!"
Xrasmanrasman32.exe"Added by the BCKDR-QGN BACKDOOR!"
XRasMan.exeRasMan.exe"Added by the FEUTEL-H TROJAN!"
UReal Spy MonitorWinrsm.exe"Realspy keystroke logger/monitoring program - remove unless you installed it yourself!"
XRegSvr32msmsgs.exe"Added by the ZLOB.B TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XRemote Access Service Managerrasmngr.exe"Added by the AGOBOT.KU WORM!"
XRemote Event Systemresmsvc.exe"Added by the IRCBOT.YF BACKDOOR!"
XRemove 54tr10smss.exe"Added by the BRONTOK-CH WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data"
Xrollbkdsm.exe"Added by the SERFLOG.B WORM!"
Xrollbkmsmpatch.exe"Added by the SERFLOG.B WORM!"
Xrollbksvosm.exe"Added by the SERFLOG.B WORM!"
?Roxio EngineMSMNGR32.EXE"Not believed to be a valid Roxio program - more likely a variant on the WOMANIZ.A TROJAN!"
XRPCall_[ComputerName]smhost.exe"Added by the REDPLUT-B TROJAN!"
Xrsmbrsmb.exe"Added by the WAREZOV.C WORM!"
Xrsmb32rsmb32.exe"Added by the STRATION.AV WORM!"
UrsMenursMenu.exe"Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000. Formally Randsoft Harmony '98"
Yrun=smsrun16.exe"Microsoft Systems Management Server (SMS) related - program that reads SMSRUN16.INI on clients running Win 3.1
XRunOnceExsms.exeIESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!
Xsacmemdssmcntlwio.exe"Added by the MAILBOT-BZ TROJAN!"
USaiSmartSaiSmart.exe"""Smart Button Special Sauce"" - included with the latest software for Saitek game controllers. Related to the ""S""
XSalestartdcpasmon.exe"SystemDoctor rogue security software - not recommended
XSalestartdcsm.exe"Part of the PrivacyProtector and DriveCleaner rogue security tools"
XSalestartPASmon.exe"Part of rogue security tools
USamsung MJC-900 Series Monitor"RUNDLL32.EXE SMMASHLL.DLLAutoUpdatePnPValue"
USamsung PanelMgrSSMMgr.exe"Monitors ink levels
USamsungSM PanelMgrSSMMgr.exe"Monitors ink levels
XScan Registerssms.exe"Added by the RBOT-AT WORM!"
XSchedulerMSMSGS.EXE"Added by the HOSTBANK-A TROJAN! Note - this particular msmsgs.exe file is located in %System%\Config and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
USecretSmileysss.exe"""Secret Smileys is an add-on for AIM that provides users access to 1000's of new Smileys that can be viewed by anyone using a current version of AIM. Secret Smileys also adds other features such as logging of IM conversations
XSecurity Accounts Manager SMsamsm.exe"Added by the SPYBOT.JE WORM!"
XSecurity Master AVSM[random characters].exe"Security Master AV rogue security software - not recommended
Xserpemsmbw.exe"Added by the SERFLOG.A WORM!"
XService Processsmss.exe"Added by the DCMBOT-E TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""config"" subfolder"
XService Systemkgbfsm344.exe"Added by the BANCOS-FS TROJAN!"
XServices Managersvsmanager.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XServices Processsmss.exe"Added by the SMALL-EK TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""config"" subfolder"
XServices.dllsmss.exe"Added by the SOBER-L WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\system and note the space at the beginning of the ""Startup Item"" field"
XSession Manager Subsystemsmssa.exe"Added by the RBOT-AGS WORM!"
XShellsmsc.exe"Added by the BANCBAN-OY TROJAN!"
XShellExplorer.exe smssnt.exe"Added by the AGOBOT.EE TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""smssnt.exe"" file is located in %System%"
NShockmachineReminderSmReminder.exe"""Shockmachine is a stand-alone application that lets users collect Macromedia Shockwave and Flash titles and play them offline"". Could be a registration reminder for the trial version"
?ShowIcon_SmartDisk Corporation_USB Card Reader v1.14e051shwicon.exe"Card reader for memory cards from digital cameras. Is it required? "
NSimple Star PhotoShow Media Managermssysmgr.exe"Simple Star PhotoShow photo editing and organizing software
YSkySurfer Management ServiceSmaServ.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
Xsmsa_exe.exe"Added by the OLFEB.A TROJAN!"
Xsmsf_exe.exe"Added by the OLFEB.A TROJAN!"
Xsmsm_exe.exe"Added by the OLFEB.A TROJAN!"
Xsmsr_exe.exe"Added by the LUKUSPAM TROJAN!"
XSMiro.bat"Added by the IROFFER.CT TROJAN!"
NSM1BGSM1BG.EXEUSB driver for downloading from within Napster and iTunes to portable MP3 players. Only required at startup if you use it all the time - otherwise start it manually when required
NSM1NINTSM1NINT.exeCypress USB Mass Storage Driver Notification Icon Application - tray notification for Cypress base memory sticks and external storage devices for Win98
NSM56 Helper Win32 Utilitysm56hlpr.exeHelper utility for Motorola based SM56 software modems - resides in the System Tray
NSm56aclsm56hlpr.exeHelper utility for Motorola based SM56 software modems - resides in the System Tray
Usmasma.exe"SmartKeylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XSmallAndSecuremssecure.exe"Added by the RBOT.CU WORM!"
Xsmanapp***.tmp [* = digit]Unidentified adware
XSManagersmanager.*.exe [* = digit]"Added by the AGENT.BJO TROJAN!"
XSManagersmanager.7.exe"Added by the DWNLDR-GVG TROJAN!"
XSmansaAppwinlogon.exe"Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NSmappSmtray.exe"System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel"
XSmart Antivirus-2009.exeSmart Antivirus-2009.exe"Smart Antivirus 2009 rogue security software - not recommended
NSmart Card ServiceScardSvr.exe"For Smart Card readers. Known to cause problems
USmart Connect MonitorSCMon.exeAppears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio
USmart Connect SetupSCSetup.exeAppears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio
XSmart Defender PROsmrtdefp.exe"Smart Defender PRO rogue security software - not recommended
USmart KeyboardSmartkbd.exeNetropa Smart Keyboard driver
NSmart Label O Serverssloserv.exePart of the printer software for the smart-label printer made by Seiko. Can be disabled safely
NSmart Label RFViewerSSLFVIEW.EXEPart of the printer software for the smart-label printer made by Seiko. Can be disabled safely
USmart Protector ProSmartProtector-Pro.exe"Smart Protector Pro internet eraser from SmartSoft - ""keeps out prying eyes and protects your private data on all Windows systems"""
NSmart Start UPPnPDetect.exe"Part of Presto! Mr.Photo - ""an ideal program for creating
USmart TouchSTouch.exe"Related to Plustek OpticSlim scanner"
NSmart Type Assistantsta.exe"Smart Type Assistant - a complex typing automation tool
XSmart Virus EliminatorSM[random characters].exe"Smart Virus Eliminator rogue security software - not recommended
USmartalecpcaccel.exe"Smartalec PC Accelerator - system optimization utility"
USmartAudioSmartAudio.exeConexant SmartAudio PC audio chipset software - typically available on HP notebooks with built-in microphones
NSmartBarXPSmartBarXP.exe"SmartBarXP is a bar that runs down the side of your screen
NsMaRTcaPsSMARTC~1.EXE"sMaRTcaPs from Phoebus LLC - enables you to configure the time needed to depress Caps Lock
?SmartCopySmartCopy.exe"Related to SmartCopy from Northstar Systems Corp. What does it do and is it required?"
NSmartDefragIObit SmartDefrag.exe"""IObit SmartDefrag helps defragment your hard drive more efficiently than any other product on the market - free or not"""
XSmartfixerSmartFixer.exe"SmartFixer rogue system error and cleaning utility - not recommended"
USmarthruengineQS.exe"Samsung smarthru software
?SmartLauncherSmartLauncher.exe"Related to SmartLauncher from Northstar Systems Corp. What does it do and is it required?"
USmartPCXLpcaccel.exe"Smartalec PC Accelerator - system optimization utility"
Xsmartprotectorsmartprotector.exe"Smart Protector rogue security software - not recommended
USmartProtector-ProSmartProtector-Pro.exe"Smart Protector Pro internet eraser from SmartSoft - ""keeps out prying eyes and protects your private data on all Windows systems"""
USmartRAMMemCleaner.exe"Memory Cleaner - monitors your system in the background and frees up memory when ever need to increase the performance of your computer. Part of IOBit Advanced Windows Care Personal/Professional"
USmartRAMSup_SmartRAM.exe"Memory management part of the Advanced SystemCare system utility from IObit"
XSmartSecuritySmartSecurity.exe"Smart Security rogue security software - not recommended
USmartSync ProSmartSync.exe"Related to CompanionLink Software Inc. Synchronization solutions for ACT!
?SmAudioSmAudio.exe"Audio driver for Conexant SmartAudio HD integrated soundcards. System Tray access to the control panel?"
NSmax4Smax4.exe"System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel"
USMax4PNPSMax4PNP.exe"Analog Devices SoundMax integrated soundcard utility. Brings up the SoundMAX Control Panel when it detects if new audio devices (such as microphones
USMax4PNP ApplicationSMax4PNP.exe"Analog Devices SoundMax integrated soundcard utility. Brings up the SoundMAX Control Panel when it detects if new audio devices (such as microphones
?smbdpmismbdpmi.exe"IBM Netfinity Director and Universal Management Services related. What does it do and is it required?"
Ysmcsmc.exeSygate Firewall
Ysmcspfsmc.exeSygate Firewall
Xsmcsmc.exe"Added by the EBOD TROJAN! Note that this should not be confused with the now discontinued Sygate Firewall which shares the same filename. This file is located in %System%"
YSMC Servicesmc.exeSygate Firewall
YSMC Servicespfsmc.exeSygate Firewall
Xsmcservwinsrv.exe"Added by the AGOBOT-OU WORM!"
YSmcServicesmc.exeSygate Firewall
YSmcServicessmc.exeSygate Firewall
YSmcServicesspfsmc.exeSygate Firewall
Xsmcsssmcss.exe"Added by the SCLOG-AJ TROJAN!"
?Smcsta.exeSmcsta.exe"SMC Networks wireless PCI card driver. Is it required?"
XSmcSVRSmcSVR.exe"Added by the LEGMIR.JU TROJAN!"
Xsmgrmgrs.exe"Covert Sys Exec malware variant"
Xsmgrsmgr.exeAdded by an unidentified WORM or TROJAN!
Xsmilewcs.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
NSmileboxTraySmileboxTray.exe"System Tray access to Smilebox photo sharing/printing service"
XSmiley Districtplugin.exe"Smiley District adware"
XSmileyAppstbapp.exe"DoubleD adware"
NSmileyconssmileycons.exe"Smileycons - free smileys
NSmith Micro trysmiptray.exeSmith Micro shared files. Comes with D-Link web cam
Usmodulsmodule.exe"UserMonitor from Neuber. Teachers can broadcast screen to other screens
NSmoothViewSmoothView.exe"TOSHIBA Zooming Utility - allows ""automatic"" zoom feature in some appications
USMPAutoStartsmpdemo.exe"Smart Phone Recorder demo from KenGolf.com. Answering Machine
USmpcSysSmpSys.exe"""Set Up My PC"" utility supplied with some Packard Bell computers"
Usmrcvshost.exe"Silent Monitoring surveillance software. Uninstall this software unless you put it there yourself"
Xsmressmres.exe"Added by the AGOBOT-UA WORM!"
Xsmrsssmrss.exe"Added by the BANPAES-B TROJAN!"
Xsmrtdrvruntime.exe"Added by the AGOBOT.MT WORM!"
Xsmrtprtsmrtprt.exe"Smart Protector rogue security software - not recommended
XSMSiro.bat"Added by the IROFFER.CT TROJAN!"
USMS Application LauncherLAUNCH32.EXE"Microsoft Systems Management Server - used to manage computers on a network remotely"
USMS Client Serviceclisvc95.exe"When the SMS Client service starts on a domain controller
XSms System32SmsSystem32.exeUnidentified malware
USMS Win9x Message AgentSMSMsg.exeThis program assigns a user to a Systems Management Server site
NSmsDiscountSmsDiscount.exe"SmsDiscount - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
NSmserialsm56hlpr.exeHelper utility for Motorola based SM56 software modems - resides in the System Tray
XSMSERIALSTARTERwin32st.exe"Added by the FAKEALERT-AH TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
XSMSERIALWORKERSTARTshellexcon.exe"Added by the FAKEALERT-AH TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
XSMSERIALWORKERSTARTERwinstrse.exe"Added by the RENOS.IC TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
XSMSERIALWORKSTARTERcomsysobj.exe"Added by the FAKEALERT-AH TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
XsmsgerWin.exe"Added by a variant of the SDBOT WORM!"
NSMSI LoaderSMLoader.exe"Smith Micro HotFax - fax software"
Xsmsmsmsm.exe"Added by the BANKER-CO TROJAN!"
Xsmsrvsmsrv.exe"Added by the AGOBOT-SX WORM!"
XSMSSsmss.exe"Added by the FLOOD.F BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Catroot"" subfolder"
Xsmss[path to smss.exe]"Added by the ALADINZ.F TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
Xsmsssmss.exe"Added by the AGENT-TR TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsmsssmss.exe"Added by the BOROBOT-J TROJAN and variants! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
XSmssssms.exe"Added by the RBOT.OP WORM!"
XSmss Hostsmhost.exe"Added by the IRCBOT-ACC TROJAN!"
Xsmss.execsrss.exe"Added by the DALBUG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSmss.exe driverwinupd32.exe"Added by the SDBOT.MI BACKDOOR!"
Xsmss32.exesmss32.exe"Added by the FAKEAV-ATH TROJAN!"
XsmssLevel4smss.exe"Unidentified malware! ! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Windows Media Player\Skins\WindowsMediaSkin\Data\Level4"
XSMSSSsmsss.exe"Added by the SDBOT.ZD WORM!"
XSMSSS Loadersmsss.exe"Added by the AGOBOT.MQ WORM!"
XSMSSUSMSSU.EXE"Added by the STARTPAGE.O TROJAN!"
USMSTraySMSTray.exeSystem tray access to Samsung Media Studio
XSMSvc32smsvc32.exe"Added by the AGOBOT-OL WORM!"
XsmsysExplorer.exe"Added by the CLICKER-C BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in a ""Template"" subfolder"
Xsmsysvi.exeAdult content dialler
USMSystemAnalyzerSMSystemAnalyzer.exe"Part of the Iolo System Mechanic optimization tool"
Xsms_msnsms_msn.exeAdded by an unknown WORM or TROJAN!
Xsms_msn40sms_msn40.exeAdded by an unknown WORM or TROJAN infection
USmtSMT.exe"Win-Spy keyboard logger/monitoring software - remove unless you installed it yourself"
NSMToolbarSMToolbar.exeStartMake.com toolbar
XSMTP32 Mailing Protocolsmtp32.exe"Added by a variant of the RBOT WORM!"
NSMTraySmtray.exe"System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel"
?SmWizardSmWizard.exe"SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required?"
XSM[random][random].exe"Malware Protector 2008 rogue security software - not recommended
XSM_IANian_monitor.exe"AdvancedCleaner rogue security software - not recommended
XSonic RecordNow!smsc.exe"Added by a variant of the SDBOT WORM!"
NSoundMAXSmax4.exe"System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel"
NSoundMAX Control PanelSmax4.exe"System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel"
NSoundMAX Integrated Digital AudioSmtray.exe"System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel"
USoundMAXPnPSMax4PNP.exe"Analog Devices SoundMax integrated soundcard utility. Brings up the SoundMAX Control Panel when it detects if new audio devices (such as microphones
XSoundMixersmvss.exe"Added by the DEDLER-G TROJAN!"
XSpooler Hostsmhost.exe"Added by the IRCBOT.BSQ BACKDOOR!"
XSpooler Subsystem Applicationsmss.exe"Added by the IRCBOT-ZO TROJAN! Note - the legitimate smss.exe process should not normally figure in Msconfig/Startup!"
Xspoolsvr32csmss.exe"Added by the AGENT-AU TROJAN!"
Xspoolsvr32csmss32.exe"Added by a variant of the AGENT-AU TROJAN!"
USprint SmartViewSprintSV.exe"Sprint SmartView wireless connectivity manager which supports cards from multiple manufacturers including Intel
USPSTEALTSmartProtectorPro.exe"Smart Protector Pro - internet privacy tool that erases tracks
USPSTEALTSmartProtector-Pro.exe"Smart Protector Pro internet eraser from SmartSoft - ""keeps out prying eyes and protects your private data on all Windows systems"""
XSpyOnThis MonitorSpyOnThisMonitor.exe"SpyOnThis rogue spyware remover - not recommended"
USSMMgrSSMMgr.exe"Monitors ink levels
Xssms.exeSSMS.EXE"Added by the GISMOR WORM!"
Xssms.exewinn.exe"Added by the SDBOT-DHE WORM!"
Xssmssssmss.exe"Added by the AGENT-MOF TROJAN!"
Xstart uploadingsmsss.exe"Added by a variant of the SDBOT WORM!"
XStart Uppingtaksmgr.exe"Added by the RBOT-QK WORM!"
UStopSignSsTsMon"sstsmon.dll VerifyStatus"
XSunjavajavasmart.exe"Added by the AGENT.AHV TROJAN!"
XSunJavaUpdatesmvss.exe"Added by the DEDLER-G TROJAN!"
Xsupport-reverse-smileys[trojan filename]"Added by the LITEBOT TROJAN!"
USup_SmartRAMSup_SmartRAM.exe"Memory management part of the Advanced SystemCare system utility from IObit"
USup_SmartRAM.exeSup_SmartRAM.exe"Memory management part of the Advanced SystemCare system utility from IObit"
XSyesmSyesm.exe"Added by the BUZUS WORM!"
XSysMainbuff.exe"Added by the AGENT-ECW TROJAN!"
USysmanSysman.exe"KeyTrap is a surveillance software program that records all keyboard activities. Uninstall this software unless you put it there yourself"
XSysManagerManager.EXE"Added by the DAGGER.140 TROJAN!"
Xsysmesysme.exe"Added by the PSW_STEALER_C TROJAN!"
Xsysmemmmsete.exe"Added by the NOPIR.C WORM!"
Xsysmemoutlookrem.exe"Added by the NOPIR-C WORM!"
XSysMemory managermdms.exe"Added by the CIMUZ-D TROJAN!"
USysMetrixSysMetrix.exe"SysMetrix - skinnable clock and metering application. It monitors and reports on a great number of statistics"
XsysMett1explorer.exe"Added by the LEGMIR-Y TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
Xsysminisysmini.exe"Added by the ADLOAD.DD TROJAN!"
Xsysmngr32sys64mnger.exe"Added by a variant of the RBOT WORM!"
Xsysmntrcsysmntrc.exe"Added by the BANCOS-FX TROJAN!"
Xsysmodsysmod.exe"Added by the SPYBOT-DU WORM!"
Xsysmonsysmon.exe"Added by the BIZEX WORM!"
XSysmonrpcmon.exe"Added by the RANDEX.ATX WORM!"
Xsysmonsysmon44.exe"Added by a variant of the BACKDOOR-CBA TROJAN!"
XSysMonwowexece.exe"Added by the MULAN-A TROJAN!"
XSysmonSystemMonitor.exe"Added by the NUJAMA-A WORM!"
XSysmonmsnmssgs.exe"Added by the SDBOT.FK WORM!"
Xsysmon12[various filenames]"Wareout - malware masquerading as a spyware and dialer remover"
XSysmonLogmslog.exe"Added by the AGENT.AOV TROJAN!"
Xsysmonntsysmonnt.exe"SearchPounder sends keywords typed into HTML forms and popular Internet search engines to a remote server"
XSysMonXPSysMonXP.exe"Added by the NETSKY.Q WORM!"
XSysmppcvpppSysTdSvr.dll"Generic2.PQG adware"
Xsysmsssysems.exe"Added by a variant of the SLAPER TROJAN!"
XSysRsysmd.exe"Ulubione adult content dialer"
XSYSTEMVSSMON.exe"Added by the RBOT-AWW TROJAN!"
XSystemsmss.exe"Added by the AGENT.EP BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSystem Config Managersmssl.exe"Added by the AGOBOT-ZJ WORM!"
XSystem Download ManagerSysMgr.exe"Added by the RBOT.CIG WORM!"
XSystem Initializationmsmsgri32.exe"Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS!"
XSystem Management Servicesmsc.exe"Added by the RBOT-ANN WORM!"
XSystem Managersysmng.exe"Added by the TAME-C WORM!"
XSystem Managersysmgr.exe"Added by the IRCBOT.AGW BACKDOOR!"
XSystem Managersysmngr.exe"Added by the IRCBOT.BAQ BACKDOOR!"
NSystem Mechanic Professional Update [Incinerator.dll]SysMech4.exe /REREG: [path] Incinerator.dll"Iolo System Mechanic ""Incinerator"" feature securely deletes files and folders from your PC so they can never be recovered again"
XSystem Messaging QueueSMCSS.EXE"Added by a variant of the RBOT WORM!"
XSystem MessengerSYSMSG32.EXE"Added by the SPYBOT-DK WORM!"
XSystem Microsoft Coresmc.exe"Added by the RIZO.A TROJAN!"
USystem MonitorSYSMON.EXE"Comes with some Aopen motherboards. Monitors CPU temp
XSystem MonitorSysmon16.exe"Added by the SDBOT TROJAN!"
XSystem Security Updatersvsmons.exe"Added by the RBOT-OW WORM!"
XSystem Service Managerlsmas.exe"Added by the AGOBOT-IK BACKDOOR!"
XSystem Servicesssms.exe"Added by a variant of the RBOT WORM!"
XSystem Session Managersmss.exe"Added by the KALEL-E WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
XSystem Startup Managersmcss.exe"Added by the RBOT.AMD WORM!"
XSystemManagerSysman32.exe"Added by the DOWNLOADER-BW.B TROJAN!"
XSystemMonitorSysmon32.exe"Added by the AIDID.A WORM!"
XSystemssysmon.exe"Added by the VIXUP-BI WORM!"
XSystesms.exesystesms.exe"Added by the RBOT-HI WORM!"
XSysUtilssmss.exe"Added by the AUTORUN-AWW WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
XTAKSMGNtaskmr.exe"Added by the RBOT-AHS WORM!"
UTallyGenicom PanelMgrSSMMgr.exe"Monitors ink levels
XTasmgrTaskmgr.bat"Added by the YPSAN.G WORM!"
XTok-Cirrhatussmss.exe"Added by the BRONTOK-A WORM and variants! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%"
XTok-Cirrhatus-2784smss.exe"Added by the BRONTOK-S WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%"
XTorjan Programsmss.exe"Added by the WOWCRAFT.B TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
YTosMemtosmem.exeToshiba laptop related. Win98/Me ACPI system can not hibernate or go on standby if all of the physical memory lower than 640KB is locked. This utility allocates and locks three pages on boot and then releases them on standby/hibernation for ACPI.SYS in order to solve the above problem
UTPSmainTPSMain.exeToshiba Power Saver - associated with Toshiba laptops/desktops. Manages the power save function to make sure that the system goes to a power saver mode when not used
YTrueVectorVSMON.EXEEven if you don't have ZoneAlarm or ZoneAlarm Pro run at start-up you do need this
Xtsatsm.exe"TargetSaver adware"
XTsa2tsm2.exe"TargetSaver adware"
?TSMAgentTSMAgent.exe"Found on the HP Touchsmart range of desktops and notebooks. What does it do and is it required?"
NTSMsgerTSMsger.exe"Epson scannner software - required for ""one-touch"" operation. Can be launched manually"
?tsyssmontsyssmon.exe"Found in a Toshiba\sysstability directory"
NUC_SMBucstart.exePart of IBM Update connector on IBM PCs for updating drivers on a new installation. Once you manually run the IBM Update connector program (shortcut) this entry is removed
UUPSMONUPSMON.exe"UPSMON Power Management software"
XUsbDsmss32.exe"Adware - detected by Kaspersky as the AGENT.CJ TROJAN!"
Xuserinitsmss.exe"Added by the DLOADR-B TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XVirscannersmss.exe"Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
?voowsmcrhuhdir.exe"??"
Xvsadminsmrs.exe"Added by the AGOBOT-RC WORM!"
XVSMPhlojsnigc.exe"Added by the RBOT-GQS WORM!"
Xvssms32vssms32.exe"Added by the BCKDR-LBF BACKDOOR!"
Xwas_checkPASmon.exe"Part of the ErrorSafe rogue system error and cleaning utility - not recommended"
XWCESMngrspoolsb.exe"Added by the AGOBOT-QZ WORM!"
XWCESMngrWCEMNGR.EXE"Added by the AGOBOT-QX WORM!"
UWDSmartWareWDSmartWare.exe"Western Digital's WD SmartWare management software for selected external drives in the My Book and My Passport range"
XWeb Servicesm.exe"Added by the BUBE-F VIRUS!"
UWG111v2 Smart Wizard Wireless SettingRtlWake.exe"Configuration utility for the Netgear WG111 54 Mbps Wireless USB 2.0 Adapter that ""provides wireless access to your desktop or notebook PC through the computer's USB port"""
XWheelsMouse[path to trojan]"Added by the SOCKSPR-D TROJAN!"
XWhistlerwhismng.exe"Added by the WHISTLER-F TROJAN!"
XWin32sysmon.exe"Added by the MYTOB-HQ TROJAN!"
XWin32 Driversysmls.exe"Added by the MYTOB.JH WORM!"
XWin32 USB2 Driversmsc.exe"Added by the SDBOT.FO WORM!"
XWIN3S2SNDSwinabsmod.exe"Added by the AGENT.DN TROJAN - known to BOClean as ""CWS/INDEX""
XWinDLL (csmss.exe)"rundll32.exe CSMSS.EXEstart"
XWinDLL (smaprnter.exe)"rundll32.exe smaprnter.exestart"
XWinDLL (smms.exe)"rundll32.exe smms.exestart"
XWindowssmss.exe"Added by the BANCBAN-QF TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows bypass security SMSS ServiceSbiCvy.exe"Added by the RBOT-GRF WORM!"
XWindows Driversssms.exe"Added by the RBOT-AT WORM!"
XWindows Live Messenger Servicermsmgslive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Media Centersmss.exe"Added by the WARBOT TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Memory Managerwindowsmem.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Messengermsnsmgs.exe"Added by the RBOT-ANJ WORM!"
XWindows Messenger Live Startupwindowsmsnlive.exe"Added by the DELF.DAX TROJAN!"
XWindows Messenger Servicewinsmsgr.exe"Added by the RBOT-VW WORM!"
XWindows Msn Live Messangermsnmsgsman.exe"Added by a variant of the SDBOT WORM!"
XWindows Nivedia DriversysMGT.exe"Added by a variant of the RBOT WORM!"
XWindows NT Login Session ManagerWNSM.EXE"Added by the RBOT.BIV WORM!"
XWindows Registry Managertasksmanagers.exe"Added by the MYTOB.ER WORM!"
XWindows Rundll Centermsnsmgr.exe"Added by the AGENT-LLB TROJAN!"
XWindows Rundll Centermsmsgrs.exe"Added by the IRCBOT-AFA WORM!"
XWindows Secure Servicesssms.exe"Added by the RBOT-GAR WORM!"
XWindows Service Agentsjbsm.exe"Added by the SMALLTRO.II TROJAN!"
XWindows Service Agentsjbsmgm.exe"Added by the IRCBOT.AHX WORM!"
XWindows Service Controller Agenttaksmgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Servicessmsc.exe"Added by a variant of the SDBOT WORM!"
XWindows Session Managersmss32.exe"Added by a variant of the RBOT WORM!"
XWindows Session Manager Subsystemsmss.exe"Added by the KALEL-B WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
XWindows Smart Managersmart.exe"Added by the RBOT-SL WORM!"
XWindows SMB Managersmb32.exe"Added by the RBOT-BHZ WORM!"
XWindows smss serviceservice.exe"Added by the AGENT-FPY TROJAN!"
XWINDOWS SYSTEMsmoc.exe"Added by the MYTOB.FU WORM!"
XWINDOWS SYSTEMsmsc.exe"Added by the MYTOB-BR WORM!"
XWindows System Managersmsc.exe"Added by a variant of the RBOT WORM!"
XWindows System Managercrssm.exe"Added by the RBOT-AFH WORM!"
XWindows System Managerwinsysmgr.exe"Added by the IRCBOT.BJG BACKDOOR!"
XWindows System Manager Loadersmsls.exe"Added by the AGOBOT.TF WORM!"
XWindows System Manager Procwinsmc.exe"Added by the RBOT.JH WORM!"
Xwindows system notepadwnpsm.exe"Added by a variant of the RBOT WORM!"
XWindows UDP Control Centertaksmrg.exe"Added by the AGENT.WOH TROJAN!"
XWindows UDP Control Centermsnsmsgrs.exe"Added by the PUSHBOT.MF WORM!"
XWindows Updatesmsscr.exe"Added by the BANKER-DK TROJAN!"
XWindows Update Servicesmcg.exe"Added by the SDBOT.QY WORM!"
XWindows32 Messenger Servicemsmsgv.exe"Added by the RBOT.ANS WORM!"
XWindowsDiskLogcstsm.exe"Added by the STINX-C or STINX-D TROJANS!"
XWindowsfwvssmf32.exe"Added by the SPIGOT BACKDOOR!"
XWindowsMGMWinmgm32.exe"Added by the SOBIG.A WORM and LALA.C TROJAN!"
Xwindowsmpwindowsmp.exe"Added by the AUTORUN-DP WORM!"
XWinDOwsUPdatesmss.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
XWinScMngrwinsmc.exe"Added by the SDBOT-BPZ WORM!"
XWinSecured32ssmr.exe"Added by a variant of the FORBOT WORM!"
UWinService32ssmgr.exe"007 Spy Software - ""stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP"""
Xwinsplogwsmmlog.exe"Added by the MAILBOT-CA TROJAN!"
XWinsSystemsyssmss.exe"Added by the DELF.IG TROJAN!"
Xwinsupdatesysmngr64winsys64mnger.exe"Added by the RBOT-BAG WORM!"
XWinSysM371662M.exe"Added by the WINKO.AO WORM!"
XWinSysModule[path to trojan]"Added by the AGENT-DIQ TROJAN!"
Xwinsystem.syssmss.exe"Added by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\win32 and note the space at the beginning of the ""Startup Item"" field"
XWINTASKmsmgrxp.exe"Added by the MYTOB.AQ WORM!"
XWINTASK DLL32smsrss.exe"Added by the MYTOB.BS WORM!"
XWinXPServicetaksmgr.exeIdentified as a variant of the IRC/Flood.tool malware
XWinXPServicetaksmgr.exe"Added by the KIRSUN.A BACKDOOR! The file is located in %System%"
XWinXPServicetaksmgr.exe"Added by the KIRSUN.A BACKDOOR! The file is located in the root directory
UWireLessMouseStartAutorun.exe MouseDrv.exe"Related to WireLess Mouse Multimedia Combo Set by SANSUN Industries"
XWSSVCsmsc.exe"Added by the AUTORUN-AGA WORM!"
UXerox PanelMgrSSMMgr.exe"Monitors ink levels
Xyemarvdsysmon.exe"Added by the AGENT-CH TROJAN!"
XYhooUapdatesymssmsgs.exe"Added by a variant of the SMALL_K TROJAN!"
XYhooUpdatesymsmsgs.exe"Added by the SMALL_K TROJAN!"
XZone Alarmvsmon.exe"Added by the RBOT.BO WORM! If this was the ZoneAlarm firewall the name column would be TrueVector"
Xzsmssmss.exe"Added by the BANCOS-CK TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xzsmsccrundll32.exe zsmscc071001.dll mymain"Added by the GENETIK.KQ TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""zsmscc071001.dll"" file is found in %System%"
Xzsmsccrundll32.exe mycc071208.dll mymain"Added by the AGENT.FZK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""mycc071208.dll"" file is found in %System%"
Xzsmsgsiservice.exe"Added by the BANCOS-BU TROJAN!"
Xzsmsssmss.exe"Added by the BANCOS-DD TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X[various names]ParisM.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]sysmon12.exe"Wareout - malware masquerading as a spyware and dialer remover"
X_Cat3msmsgrxp.exe"Added by a variant of the SMALL-DT downloader TROJAN"
X_Cat4msmsgr2.exe"Added by the SMALL-EB TROJAN!"
X_Services.dllsmss.exe"Added by the SOBER-L WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\system"
X_winsystem.syssmss.exe"Added by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\win32"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.