Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X*MSConfig32aecache.exe"Detected by F-Secure as the OBFUSCATED.GP TROJAN!"
?.NET configsysmon32.exe"??"
Y36X Raid ConfigurerJMRaidSetup.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
XAdobesysconfig.exeAdded by an unidentified WORM or TROJAN!
XAol Configuration Loaderaimsng.exe"Added by the SDBOT-XE WORM!"
XAolConconfig.com"Added by the TAPLAK WORM!"
XBluetooth Configbtwindin32.exe"Added by the SDBOT-DFN WORM!"
XBoot Configbootconfig.exe"Added by the FLOOD-EV TROJAN!"
XCli Confgcliconfig.exe"Added by a variant of the SPYBOT WORM! See here"
Xcmd32configs.exe"Hijacker
XCompaq32 Service Driversmsconfig32.exe"Added by the SDBOT-ADC WORM!"
XConfgbootconfig.exe"Added by the VB-ERB WORM!"
XConfigservice.exe"Added by the ISRAZ.B WORM!"
XConfigWinService32.exe"Added by the CRUTCHA-A TROJAN!"
XConfigwinconfig.exe"Added by the GIP.113.B1 TROJAN!"
XConfigCONFIG.EXE"Added by the PSWGIP.B TROJAN!"
XConfigTaskUpdate.exe"Added by the MDROP-BRO TROJAN!"
XConfig LoadationiEEexplore.exe"Added by the SDBOT.H TROJAN!"
XConfig LoadatiorinI3Explorer.exe"Added by the SDBOT.H TROJAN!"
XConfig Loadersvchosl.exe"Added by the GAOBOT.P WORM!"
XConfig Loadersysldr32.exe"Added by the GAOBOT WORM!"
XConfig Loaderscvhost.exe"Added by the GAOBOT.AE or GAOBOT.AO WORMS!"
XConfig Loadersvhost.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfig Loadersvchost2.exe"Added by the AGOBOT.XE WORM!"
XConfig Loader[worm filename]"Added by the AGOBOT-AE WORM!"
XConfig LoaderSYSMGR.EXE"Added by the AGOBOT.C WORM!"
XConfig Loaderwincrt32.exe"Added by the AGOBOT-AW WORM!"
XConfig Loader for Microsoft Windowsmwincfg32.exe"Added by the AGOBOT.BD WORM!"
XConfig Loader2explores.exe"Added by the GAOBOT.BT WORM!"
XConfig Loadrwinsys32.exe"Added by the AGOBOT-HN WORM!"
XConfig33.exeConfig33.exe"Added by the SDBOT.T TROJAN!"
XConfiggLoadercart322.exe"Added by the GAOBOT.DJ WORM!"
UConfigSafeCFGSAFE.EXE"ConfigSafe - lets you identify changes to the registry
UConfigSafeAUTOCHK.EXE"ConfigSafe - lets you identify changes to the registry
NConfigServicesConfig.exePart of initial setup on a Compaq PC
Xconfigsetupconfigsetup32.exe"Added by the AGOBOT-AFP WORM!"
XConfigurationexplorer32.exe"Added by the SDBOT-ML WORM!"
Xconfigurationapphost.exe"Added by the SDBOT-VP WORM!"
XConfigurationntsys32.exe"Added by the SDBOT-LN WORM!"
XConfigurationmsgfixs.exe"Added by the SDBOT-NN WORM!"
XConfiguration DefaultWuxat.exe"Added by the SPYBOT-CA WORM!"
XConfiguration Driverscghost.exe"Added by the SDBOT-DLA WORM!"
XConfiguration FileWinset32.exeAdded by the FLUX.101 TROJAN!
XConfiguration Loadedwupdated.exe"Added by the MOEGA or MOEGA.AG or MOEGA.AP WORMS!"
XConfiguration Loadedlssas.exe"Added by a variant of the SDBOT WORM!"
XConfiguration Loadediexploree.exe"Added by the SDBOT-KC WORM!"
XConfiguration Loaderaim95.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadercmd32.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadersyscfg32.exe"Added by the SDBOT.B BACKDOOR!"
XConfiguration Loaderservice5.exe"Added by the GAOBOT.AF WORM!"
XConfiguration Loaderlfass.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadersycfg34.exe"Added by the GAOBOT.AN WORM!"
XConfiguration Loaderwincrt32.exe"Added by the GAOBOT.BF WORM!"
XConfiguration Loaderwindex.exe"Added by the GAOBOT.BZ WORM!"
XConfiguration Loaderdosrun32.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderService.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderServicess.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadersw32.exe"Added by the AGOBOT.BQ WORM!"
XConfiguration LoaderSystem.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderWinreg.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadersysinfo.exe"Added by the GAOBOT.FQ WORM!"
XConfiguration Loadermicrosoft.exe"Added by the GAOBOT.JB WORM!"
XConfiguration Loaderconfgldr.exe"Added by the GAOBOT.GEN!POLY WORM!"
Xconfiguration loaderwinicfg32.exe"Added by the GAOBOT.RQ WORM!"
XConfiguration Loadersvhst.exe"Added by the GAOBOT.YC WORM!"
XConfiguration Loadermsgfix.exe"Added by the GAOBOT.AUS or SDBOT.J or SDBOT-QG WORMS!"
XConfiguration Loadermsnss.exe"Added by the GAOBOT.AUS WORM!"
XConfiguration LoaderIEXPL0RE.EXE"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration Loaderloadcfg32.exe"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration LoaderMSTasks.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadersystemry.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration LoaderccSort.exe"Added by the AGOBOT.SR WORM!"
XConfiguration Loadersmss32.exe"Added by the AGOBOT.MB WORM!"
XConfiguration Loaderwincffg.exe"Added by the AGOBOT.A3 WORM!"
XConfiguration Loaderseru32.exe"Added by the SDBOT-VR WORM!"
XConfiguration Loaderbotss.exe"Added by the SDBOT-XS WORM!"
XConfiguration Loaderldasp.exe"Added by the AGOBOT.BH WORM!"
XConfiguration Loadermsgcfgsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadersmsai.exe"Added by the SDBOT-YE WORM!"
XConfiguration Loadersvupdate.exe"Added by the RANDEX.DXP WORM!"
XConfiguration Loadercrcss.exe"Added by the AGOBOT.ADG WORM!"
XConfiguration Loaderlexplore.exe"Added by the RBOT-AGX WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XConfiguration Loaderscvhost.exe"Added by the AGOBOT-AAE and SDBOT.AR WORMS!"
XConfiguration Loadersvchost.exe"Added by the PARADROP-A WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XConfiguration Loadersvchost2.exe"Added by the AGOBOT.JR WORM!"
XConfiguration Loaderdezi.exe"Added by the SDBOT-OB WORM!"
XConfiguration Loadermouse.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadermsg.exe"Added by the SDBOT.BT WORM!"
XConfiguration LoaderWinHelper.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loaderextrac.exe"Added by the SDBOT-AFP WORM!"
XConfiguration LoaderDVD-Player.exe"Added by a variant of the SDBOT WORM!"
XConfiguration LoaderIEXPLORE.EXE"Added by the SDBOT-KW WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XConfiguration Loaderwincore.exe"Added by the SDBOT.BHE WORM!"
XConfiguration Loaderconfigldr.exe"Added by the AGOBOT-PP TROJAN!"
XConfiguration Loaderahnhst.exe"Added by the AGOBOT.MX WORM!"
XConfiguration Loaderntdm.exe"Added by the AGOBOT.RV WORM!"
XConfiguration Loadermsnmsgr.exe"Added by the SDBOT-SO WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XConfiguration Loadersvschost.exe"Added by the SDBOT-NS WORM!"
XConfiguration Loaderwump.exe"Added by the AGOBOT-BU BACKDOOR!"
XConfiguration LoaderWinSys32ys.exe"Added by the SDBOT.BCS WORM!"
XConfiguration Loadercvcd.exe"Added by the AGOBOT-DH BACKDOOR!"
XConfiguration Loaderasnclt32.exe"Added by the AGOBOT-EB BACKDOOR!"
XConfiguration Loadersoundconf.exe"Added by the AGOBOT-MH WORM!"
XConfiguration Loaderwin32exec.exe"Added by the SDBOT-LA WORM!"
XConfiguration Loadermservs.exe"Added by the SDBOT-NM WORM!"
XConfiguration Loaderupdate.exe"Added by the SDBOT-OS WORM!"
XConfiguration LoaderFILENAME.EXE"Added by the AGOBOT-DQ WORM!"
XConfiguration Loaderexplore.exe"Added by the GAOBOT.GW WORM!"
XConfiguration Loadermsgfixy.exe"Added by the SLINBOT.QW BACKDOOR!"
XConfiguration Loaderwinfix.exe"Added by the SDBOT-MA WORM!"
XConfiguration Loaderscvh0st.exe"Added by the AGOBOT-AX WORM!"
XConfiguration Loadermsrun.exe"Added by the AGOBOT-Y WORM!"
XConfiguration Loader 2confuldr.exe"Added by the AGOBOT-FC WORM!"
XConfiguration Loader ServiceWinsys32.exe"Added by the RBOT-YV WORM!"
XConfiguration Loader Servicedevl32.exe"Added by the SDBOT-XY WORM!"
XConfiguration Loader10ip7.exe"Added by the AGOBOT-ANZ WORM!"
XConfiguration Loadingsvchos1.exe"Added by the GAOBOT.DK WORM!"
XConfiguration Loadingconfigldr.exe"Added by the AGOBOT-EC WORM!"
XConfiguration Loading Servicewscel.exe"Added by the SDBOT-WJ WORM!"
XConfiguration Loadriexplore.exeeAdded by an unidentified WORM or TROJAN!
XConfiguration ManagerCNFGLD32.EXE"Added by the SDBOT TROJAN!"
XConfiguration ManagerCnfgldr.exe"Added by the SDBOT TROJAN!"
XConfiguration Managercfg32.exe"BookedSpace parasite. Note - the ""cfg32.exe"" file is located in %Windir%"
XConfiguration Serveciesewins.exe"Added by the SDBOT-COH WORM!"
XConfiguration Servicesuchost.exe"Added by the TREB TROJAN!"
XConfiguration Servicesmswords.exe"Added by the SDBOT-YM WORM!"
XConfiguration UpdateUPDT32V2.EXE"Added by the SPYBOT-AA BACKDOOR!"
NConfiguration UtilityCONFIG.EXEControls linksys wireless connection. Available from the Desktop
UConfiguration Utilitywlanutil.exe"NetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards)"
XConfiguration WizardCfgwiz32.exe"Added by a variant of the HACKTACK TROJAN! Not to be confused with the legitimate MS ""ISDN Configuration Wizard"" (Cfgwiz32.exe)"
XConfiguration32 Loader32winamp32.exe"Added by the SDBOT-BIC WORM!"
XConfigurations Ascltasclt.exe"Added by the SDBOT-MX WORM!"
XCONFIGUREvantivir62.exe"Added by the AGOBOT-ZD BACKDOOR!"
UConfigUtilityConfigUtility.exe"Wireless management utility for the HWC54G Hi-Speed Wireless-G CardBus Card from Hawking Technologies
XConfigVirservices.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
NCreative PCI Audio Configuration Utilitystarter.exe"System Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on this special page. Similar to EnsoniqMixer"
Xctfmoonmicrosoftconfigurator.exe"Added by the DELF-ALS TROJAN!"
XCurrent Security Configcsecure.exe"Added by the RBOT-AMO WORM!"
NDACONFIGEXEdaconfig.exe3Com NIC Diagnostics. Available via Start -> Programs
XDefaultConfigurationdefaultconfh.exe"Added by the AGOBOT-JC WORM!"
XDevice Configuration Loadermsdvc32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XDisk Panel Configurationdpcsvc.exe"Added by the IRCBOT.BSQ BACKDOOR!"
XDNS Config servicewin32.exe"Added by the RBOT-TL WORM!"
NDPConfigDPConfig.exe"Compuware DevPartner Studio Configuration Utility
XExplorerconfig_.com"Added by the FLOPPY-D WORM!"
XExplorer5config_.com"Added by the VB.CBG WORM!"
Xfile laoder configurationrnd32.exe"Added by the RBOT.BQJ WORM!"
XFirewall configReadMe.exe"Added by the SILLYFDC.BBT WORM!"
UFortis Secure Layer Configcseinst.exeFortis Bank Home Banking part. Installed during the installation of the software necessary to run the Home Banking. According to Fortis Bank this will not in any way be harmful to the system or relay system information
YHPLJ ConfigSetConfig.exeConnects system to networked HP printer.
NIconfig.exeIconfig.exeIcon for LS-120 "Superdisk"
XiConfigLoaderDIIhost.exe"Added by the GAOBOT.AO WORM!"
Xicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AER WORM!"
XIE configureexplorer.exe"Added by the LINEAGE-C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!"
UInstant Wireless Configuration UtilityWUSB11cfg.exe"Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
UInstant Wireless Configuration UtilityWPC11Cfg.exe"Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
XIntel Service Driversmsconfig16.exe"Added by the MSCONFIG16 TROJAN!"
UIntelZeroConfigZCfgSvc.exe"Zero Config MFC Application
XInternet Configsvchosts.exe"Added by the SDBOT TROJAN!"
XInternet Explorer ConfigurationIEXPLORE.EXE"Added by the SDBOT-UL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Protocol Configuration Loaderipcl32.exe"Added by the SDBOT TROJAN!"
XInters Configuration LoaderRCL0ADERS.exe"Added by the SDBOT-KX WORM!"
XIPConfigsvcxnv32.exe"Added by the HACARMY.E TROJAN!"
XIPConfigsvcxnw32.exe"Added by a variant of the HACARMY.E TROJAN!"
XIPConfigipconfigs.exe"Added by the HACARMY.C BACKDOOR!"
XIPSEC Configurationwsupdate.exe"Added by the AGOBOT-IQ WORM!"
XIPTable ConfigurationWinipcfgs.exe"Added by a variant of the RBOT WORM!"
XJA Config 32Awesome32.exe"Added by a variant of the SDBOT WORM!"
XJava32 Configuration Loadermsnmesgr.exe"Added by a variant of the RBOT WORM!"
UJMB36X ConfigureJMRaidTool.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
YJMB36X ConfigureJMRaidSetup.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
XKernelConfigdestiny32.exe"Added by the AGOBOT.AMB WORM!"
?LCIDConfiglcidchng.exe"??"
XM1cr0s0ft S3rcuritysystemconfig.exe"Added by the RBOT.BKB WORM!"
XMemConfigSetupIE.com"Added by the TAPLAK WORM!"
XMicrosft Confige 32msaconfigurez.exe"Added by the RBOT.CLC WORM!"
XMicrosoft (R) Windows Configuration Backup Servicesvchost.exe"Added by the RANKY.X TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in either a ""config""
XMicrosoft Configmsconf.exe"Added by the RBOT.PV WORM!"
XMicrosoft ConfigMSCONF.EXE"Added by the RBOT-LG WORM!"
XMicrosoft Config 32msconfigx32.exeReported as the MSCONFIGX32 TROJAN! Possible Rbot variant
XMicrosoft Config 32bitmscnfg32.exe"Added by the RBOT-Z WORM!"
XMicrosoft Config Fileconfig.exeAdded by the KILLFILES.GR TROJAN! This is malware that will attempt to delete all system dlls!
XMicrosoft Config Loadermsconfig32.exe"Added by the AGOBOT.XX WORM!"
XMicrosoft Config Loadermsrun32.exe"Added by the AGOBOT-DY WORM!"
XMicrosoft Config Loadermsconf32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Configoration Servicemsconfigs.exe"Added by the RBOT-ETT WORM!"
XMicrosoft Configs 32msgconfigrs.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Configuewemsconfiguwe.exe"Added by the SDBOT-BPK WORM!"
XMicrosoft Configurationmsconfig32.exe"Added by the SDBOT.MQ WORM!"
XMicrosoft Configuration 35microsot1.exe"Added by an unidentified TROJAN!"
XMicrosoft Configuration Wizardtaskmrg.exe"Added by the SDBOT-MX TROJAN!"
XMicrosoft Configure 32msgconfigre.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Java Virtual MachineMsConfiG.exe"Added by the FORBOT-DV WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
NMicrosoft System Configuration Utilitymsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
XMicrosoft System DLL Services Configurationwindir32.exe"Added by the SDBOT-ACY TROJAN!"
XMicrosoft System Restore ConfigurationCBRSS.EXE"Added by a variant of the SPYBOT WORM!"
XMicrosoft Task Messenger Configtaskmgsr.exe"Added by the SDBOT-JK WORM!"
XMicrosoft Update Clinicsvsipconfig.exe"Added by the RBOT.BR WORM!"
XMICROSOFT UPDATE CONFIGURATIONWIN32SNC.EXE"Added by the RBOT-AI WORM!"
XMicrosoft Updaterssysconfigs.exe"Added by the RBOT-DF TROJAN!"
XMicrosoft Windows Config 32win32conf.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows DLL Services Configurationnewdll.exe"Added by the SDBOT-ZR WORM!"
XMicrosoft Windows DLL Services Configurationnewdll2.exe"Added by the SDBOT-ABD WORM!"
XMicrosoft Windows DLL Services Configurationpoker.exe"Added by the SDBOT-ZY WORM!"
XMicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AAH WORM!"
XMicrosoft Windows DLL Services Configurationproxy.exe"Added by the SDBOT-ZL WORM!"
XMicrosoft Windows DLL Services Configurationwindir32.exe"Added by the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindir32a.exe"Added by a variant of the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindll32.exe"Added by the SDBOT.BHD WORM!"
XMicrosoft Windows DLL Services ConfigurationwinDSL.exe"Added by the SDBOT-ZG WORM!"
XMicrosoft Windows DLL Services Configurationdllmanager32.exe"Added by the SDBOT-BTU WORM!"
UMicrosoft Windows Media Player Network Sharing Service Configuration ApplicationWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XMicrosoft Windows XP Configuration Loaderm32svco.exe"Added by the SDBOT.WORM!.48548 WORM!"
XMircrosoft Windows Config DLLrundllc32b.exe"Added by the RBOT-ZY WORM!"
XModularConfigsyscnfg.exe"Added by an unidentified VIRUS
XMotherboard ConfigAti2xxx.exe"Added by the RBOT-AIK WORM!"
UMotorola Desktop Suite mRouter ConfigmRouterConfig.exe"Configuration for Motorola's version of Intuwave's m-Router - ""that enables easy connectivity between mobile devices and PCs across Bluetooth
UmRouterConfigmRouterConfig.exe"Configuration for Intuwave's m-Router - ""that enables easy connectivity between mobile devices and PCs across Bluetooth
XMS Configmsdconfig.exe"Added by the RBOT-CZH WORM!"
XMS Config Loadersvchos1.exe"Added by the AGOBOT.R WORM!"
XMS Config LoaderMSWin32bck.exe"Added by the GAOBOT.AA WORM!"
XMS Config Loadersvcrhost.exe"Added by a variant of the RBOT WORM!"
XMS Config ServiceMsloader32.exe"Added by the RBOT-KJ WORM!"
XMS Config Streammsasm.exe"Added by the AGOBOT-BA WORM!"
XMS Config v12mscfg12.exe"Added by the AGOBOT.YP WORM!"
XMS Config v13lrbz32.exe"Added by the GAOBOT.AOL WORM!"
XMS Config v13mscfg13.exe"Added by the AGOBOT.YQ WORM!"
XMs configsumsconfigsu.exe"Added by a variant of the SDBOT WORM!"
XMS ConfigurationMSFramer.exe"Added by the RANDEX.OL WORM!"
XMs Configurationmicrosoftsa32.exe"Added by the KELVIR.X WORM!"
XMS Configuration Utilitymsconfig32.exe"Added by the WOOTBOT.DY WORM!"
XMS Sound Config 16bitsndcfg16.exe"Added by the SDBOT.MB TROJAN!"
XMs System ConfigMscfg.exe"Added by the SDBOT-CCR WORM!"
XMs System Configpcedit.exe"Added by a variant of the SDBOT WORM!"
XMS-patchmsconfig32.exe"Added by the RBOT-AUF WORM!"
NMSConfigmsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
XMSConfigMSCONFIG32.EXE"Added by the SPYBOT.B WORM!"
Xmsconfigmsconfig.exe"CoolWebSearch MSConfig parasite variant. Note - this overwrites the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
Xmsconfigmsconfig.exe"Added by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrun"
Xmsconfigwins.exe"Added by the RBOT.PF WORM!"
XMSConfigMSCONFIG35.EXE"Added by a variant of the SPYBOT WORM!"
Xmsconfigscvhost.exe"Added by the AGENT-DSF TROJAN!"
Xmsconfigwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
XMsconfigicpldrvx.exe"Added by the BANLOAD.BFT TROJAN!"
Xmsconfigmsconfig.com"Added by the IRCBOT-SM WORM!"
Xmsconfigmsconfig.bat"Added by the PAHATIA.B WORM!"
XMSConfiglssas.exe"Added by the AUTORUN.CEY WORM!"
XMSConfigxwpwqf.exe"Added by the AGENT-NEW TROJAN!"
XMsconfig lptt01msconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
XMSConfig Managermsupdate.exe"CoolWebSearch parasite variant"
XMsconfig ml097emsconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
Xmsconfig serviceMSupdate32.exe"Added by a variant of the SPYBOT WORM!"
Xmsconfig.msconf.exe"Added by the BUZUS-AY WORM!"
Xmsconfig.exeproxy.exeAdded by a variant of the AGENT.AH downloader TROJAN!
Xmsconfig.exeuline.exeAdded by a variant of the AGENT.AH downloader TROJAN!
Xmsconfig38mssvcc.exe"Added by the RBOT-BJV WORM!"
XMSConfig45MSConfig45.exe"Added by the SDBOT.OJ TROJAN!"
XMSConfigrjdbgmrg.exe"Added by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here"
NMSConfigRemindermsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. This particular entry is specific only to 98/Me and is located in %System%
XMsConfigsMsConfigs.exe"Added by the ALCAN.A WORM!"
XMSConfigsRUNDLL64.dll.vbs"Added by the WEKODE-B WORM!"
Xmsconfiguratorctfsdk.exe"Added by the DELF-ALS TROJAN!"
Xmsdevmsconfig.exe"Added by the AGOBOT.AAU WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
XMSFTP Service Configr3grun.exe"Added by a variant of the SDBOT WORM!"
XMSI Configurationmsiconf.exe"Added by the AGENT.AKSZ TROJAN!"
XMsn Configmsngf.exe"Added by the RBOT-QG WORM!"
XMSN Configurationmsnconfig.exe"Added by a variant of the IRCBOT TROJAN!"
XMsn Configuration Loadermsngms.exe"Added by the KELVIR.T WORM!"
XMSN Configuration Loadermsmsncfg.exe"Added by the AGOBOT-KX BACKDOOR!"
XMSN File Configurationmsnfilecfg.exe"Added by a variant of the IRCBOT BACKDOOR!"
NNAV Configuration Wizardcfgwiz.exe"Introduced with Norton Anti-Virus 2002
Xnetconfignetconfig.exe"Added by the NETWARE TROJAN!"
XNetworks ConfiguratorNetConfs.exe"Added by the RBOT-OX WORM!"
UODSPConfigODSPConfig.exe"DsktopSurveil surveillance software. Uninstall this software if you did not install it yourself"
XOS Boot Configurationbootconfig.exe"Added by the IRCBOT.HJ WORM!"
XOS Boot Configuration!bootconf.exe"CoolWebSearch BootConf adware"
XOutlook Express Config*****.exe [* = random char]"Added by a variant of the RBOT WORM!"
?Palm MultiUser ConfigConfigtool.exe"MultiUser configuration for a Palm PDA device?. Is it required?"
XPC-Config32corona.exe"Added by the CORONEX.A WORM!"
Upop3 Serverconfig.cfg"Part of HTML2POP3 - ""Convert Webmail to POP3.Is also included a SMTP/POP3 tunneling system that allow send and receive email in a private network HTTP PROXY based. All connection are plugin based. Over 250 email server supported and tested"""
NRaConfig2500RaConfig2500.exe"RaLink wireless LAN configuration utility"
XReg ServiceWinnConfig.exe"Added by the AGOBOT-PF WORM!"
XRegistryConfigrundll.exe"Added by the AGOBOT-KN WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
Xrun=mouse_configurator.win"Added by the GAGGLE.E WORM!"
USaitekAutoConfiguresaicnfig.exe"Configuration for Saitek game controllers"
UServiceConfigispbeg.exe"Comcast Transition Wizard. On June 30th
XSevicewinconfig.exe"Added by the GIP.113.B1 TROJAN!"
XSPOOL Configurationspoolsvc.exe"Added by the SDBOT-KD WORM!"
XSQConfigCheckercc.exe"Xupiter SQWire toolbar related. Use Spybot S&D
XStartup Configuration[six character filename]"Added by the RBOT-ARV WORM!"
XStartup Configurationwztoid.exe"Added by the RBOT-ASD WORM!"
Xstratasxmconfig.exe"Added by the RBOT-AHR WORM!"
XSymantec Configuration LoaderccApp32.exe"Added by the AGOBOT-EE WORM!"
Xsysconfigiexplorer.exe"Added by the CULT.C WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XSysConfigsyscfg35.exe"Added by the KAZMOR.C WORM!"
XSysConfigwincfg32.exe"Added by the SDBOT.ZD WORM!"
USysconfigStealth KeySpy.exe"StealthKeySpy - keystroke logger/monitoring program - remove unless you installed it yourself!"
Xsysconfig32sysconfig32.exe"Added by the AGENT-MSP TROJAN!"
XSystem ConfigBF3.EXE"Added by the SPYBOT-DT WORM!"
XSystem Configsysloadcnf.exe"Added by a variant of the SDBOT WORM! See here"
XSystem Config Bootsyscgboot.exe"Added by the AGENT.VWU TROJAN!"
XSystem Config Managercrss.exe"Added by the AGOBOT.GH WORM!"
XSystem Config Managersmssl.exe"Added by the AGOBOT-ZJ WORM!"
XSystem Configurationiexplore.exe"Added by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XSystem Configurationsyscfg32.exe"Added by the MYTOB.EA WORM!"
XSystem Configurator32SYSTEMCFG.EXE"Added by the AGOBOT-KS WORM!"
Xsystem configuresvchost.exe"Added by the LINEAGE-C TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XSystem-Configmsptmf32.com"Added by the LIOTEN.FA WORM!"
NThinkPad Configuration UtilityTP98TRAY.EXE"System Tray access to the ThinkPad Configuration utility for IBM/Lenovo ThinkPad notebooks. ""The ThinkPad Configuration utility is a control center to configure your ThinkPad hardware. With this utility
UU.S.Robotics WLAN Adapter Configuration UtilityUSRWLAN.exe"U.S.Robotics LAN Adapter - wireless LAN (WLAN) configuration utility"
XUpdate32configs.exe"Hijacker
XUSBConfigration2wmmndir.exe"Added by the AGOBOT-SV WORM!"
UVenturi Configuratorventcfg.exe"Venturi Wireless mobile broadband configuration utility"
XVolume Shadow Configurationvbmsvc.exe"Added by the SLENFBOT.DH WORM!"
XWelcomewinconfig.exe"Added by the GIP.113.B1 TROJAN!"
XWelcomeCONFIG.EXE"Added by the PSWGIP.B TROJAN!"
XWifi Configurationwificonfig.exe"Added by the IRCBOT.AWB BACKDOOR!"
XWifi Configuration!wificonfigs.exe"Added by the IRCBOT.AWB BACKDOOR!"
XWin Configwinconfig.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWin32 Configurationvideosd32.exe"Added by the SDBOT.TT WORM!"
XWin32 Configurationdllhelp.exe"Added by the SDBOT.UL WORM!"
XWin32 Configurationmplayer.exe"Added by the FORBOT-BZ WORM!"
XWin32 Securemsconfigsvc.exe"Added by a variant of the SDBOT WORM!"
XWin32 Services Configwinwkys.exe"Added by the RBOT.BKY WORM!"
XWinConfig9324wincfgkop9.exe"Added by the RBOT.BVD WORM!"
XWindows Backup ConfigurationIEXPLORER.exe"Added by the GAOBOT.AZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XWindows ConfigSSYS.EXE"Added by the SPYBOT-DA WORM!"
XWindows Configwins.exe"Added by the SPYBOT.JR WORM!"
XWindows ConfigRUNDLL.EXE"Added by the SPYBOT-DX WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XWindows Configpvphost.exe"Added by a variant of the SLAPER TROJAN!"
XWindows Configwinconfig.exe"Added by the IRCBOT.BAP BACKDOOR!"
XWindows ConfigZANBOR.EXE"Added by the SPYBOT-MH WORM!"
XWindows Config Connectionmsicll.exe"Added by the RBOT-EXQ WORM!"
XWindows Config LoaderWincfg32.exe"Added by the SILVERFTP TROJAN!"
XWindows Config Managerwinconf.exe"Added by the RBOT-AIT WORM!"
XWindows Config ManagerWincfgman32.exe"Added by the AGOBOT-AL BACKDOOR!"
XWindows Config Systemconfig.exe"Added by a variant of the SDBOT WORM!"
XWindows Configurationwsys32.exe"Added by the GAOBOT.FB WORM!"
XWindows Configurationwincfg32.exe"Added by the MYTOB.ED WORM!"
XWindows ConfigurationWINHUB.EXE"Added by the SPYBOT-CG WORM!"
XWindows Configuration Loaderasclt.exe"Added by the SDBOT-OA WORM!"
XWindows Configuration Loadermsgfix.exe"Added by the SDBOT-NP WORM!"
XWindows Configuration SystemIExplore.exe"Added by the RBOT-DDG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Configuration Utilitywinxupdate.exe"Added by the AGOBOT.LW WORM!"
XWindows Configuratorwinconf.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Default Configurationsvchost.exe"Added by the DLOADER-U TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XWindows driver updateIpconfig32.exe"Added by the SDBOT-JV WORM!"
XWindows Installer 1msnconfig.exe"Added by the PURITYSCN.B TROJAN!"
XWindows MSConfig Startup Loggerwinlog.exe"Added by the RBOT.BCU WORM!"
XWindows Service Layerconfig.exe"Added by the RBOT.DDJ WORM!"
XWindows System ConfigurationSYSCFG16.EXE"Added by the WISDOOR-K TROJAN!"
XWindows System ConfigurationPasscfg16.exe"Added by the DOMWIS-E TROJAN!"
XWindows System ConfigurationWinfrw.exe"Added by the SOLUFINA TROJAN or the DOMWIS-J WORM!"
XWindows System Configurationwincfg.exe"Added by the AGOBOT.OP WORM!"
XWindows System ConfigurationWINCFG32.EXE"Added by the AGOBOT-TE WORM!"
XWindows System ConfigurationWinNeth.exe"Added by the RETHE-A WORM!"
XWindows System Configurationnether.exe"Added by the OPANKI-AB WORM!"
XWindows System ConfigurationWINSYS32.exe"Added by the SDBOT.AXK WORM!"
XWindows System Restore ConfigurationSblhost.exe"Added by a variant of the SPYBOT WORM!"
XWindows Updatemsconfig32.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows update configsvhost.exe"Added by the SDBOT-PF WORM!"
Xwindows update configuratorsvghost.exe"Added by a variant of the SPYBOT WORM!"
Xwindows update configuratorexplore.exe"Added by the SDBOT.RY BACKDOOR!"
XWindows32 Configuration Loadermsrf32.exe"Added by the SDBOT-ABX WORM!"
XWinDriver Configurationwindrvconf.exe"Added by the AGOBOT-LX TROJAN!"
XWindws Configuration LoaderLEXPLORE.exe"Added by the SODABOT WORM!"
Xwinrunmsconfig.exe"Added by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrun"
XWIP Config GUIWinipcfgs.exe"Added by the RBOT-CN WORM!"
UWireless PCI Card Configuration UtilityWMP11Cfg.exe"Utility used by the LINKSYS wireless PCI card (WMP11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
XWSAConfigurationwmon32.exe"Added by the GAOBOT.BAJ WORM!"
XWSAConfigurationsvchostt.exe"Added by the AGOBOT.ZT WORM!"
XWSAConfigurationrpcxmn32.exe"Added by the AGOBOT.ABG WORM!"
XWSAConfigurationwin32upd.exe"Added by a variant of the RBOT WORM!"
XWSAConfigurationdrrss.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWSAConfigurationwinlogon32.exe"Added by the AGOBOT-WC WORM!"
XWSAConfigurationntguard32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWSAConfigurationcsrsvcs.exe"Added by the AGOBOT.VI WORM!"
XWSAConfigurationwinmx32.exe"Added by the AGOBOT-JE WORM!"
XWSAConfigurationkernel32.exe"Added by the AGOBOT-KV WORM!"
XWSAConfigurationwinmon32.exe"Added by the AGOBOT.TM WORM!"
XWSAConfigurationmsnote30.exe"Added by the AGOBOT-KF BACKDOOR!"
XWSAConfigurationsyxtem32.exe"Added by the AGOBOT-MF BACKDOOR!"
XWSAConfigurationsvchostx.exe"Added by the AGOBOT-JV BACKDOOR!"
XWSAConfiguration1csass.exe"Added by the AGOBOT.WH WORM!"
XWSConfigurationspoolsc.exe"Added by the AGOBOT-HY WORM!"
UWSEP Status+ConfigurationcontroldGUI.exe"User interface for the WatchGuard Security Event Processor (WSEP) Status/Configuration dialog box associated with the Firebox series of security products from Watchguard"
XWSSAConfigurationwmmon32.exe"Added by the AGOBOT-KC WORM!"
?ZDConfigZDConfig.exe"Related to various brands of Wireless USB LAN Adapter - what does it do and is it required?"
X[random name]m?config.exe"PurityScan adware"
X[Randomly chosen existing folder name]_config.exe"Added by the ANTINNY-L WORM!"
X[username] config[path to trojan]"Added by the MOSUCK-H TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.