Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Version"NVIDIA nView Control PanelNnwiz.exe
U3Deep Control Panel3DeepCTL.EXE"3Deep® from E-Color corrects lighting
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
XAccess Control Appwinsto.exe"Added by the AGENT.DGO TROJAN!"
XAccess WebControl[path to file]"Added by the PPDOOR-M TROJAN!"
XAdmanager ControllerAdManCtl.exe"Adware
XAntiSpyControlpgs.exe"AntiSpyControl rogue security software - not recommended
XAntiSpywareControlpgs.exe"AntiSpywareControl rogue security software - not recommended
XARCHIVE CONTROLfixupdattr.exe"Added by the MYTOB.GU WORM!"
UAshampoo HDD Control GuardHDDControlGuard.exe"Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
XAti Control Panelatiphexx.EXE"Added by the RBOT-BR WORM!"
YATI Remote ControlATIRW.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
YATI Remote ControlATIX10.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
XATI Video Driver Controlatigfx.exe"Added by the RBOT-FWL WORM!"
XATI Video Driver Controlbtorrent.exe"Added by a variant of the IRCBOT TROJAN!"
XATI Video Driver Controls[path to worm]"Added by the SDBOT-DDS WORM!"
XATM Controladpn.exe"Added by the MMS.A WORM!"
UBJPD HID ControlTVMon.exe"Related to Canon Photo viewer"
UC-Media Echo ControlEchoCtrl.exeC-Media produce audio chipsets that are often found on popular motherboards with on-board audio. You may need it if you use the echo control feature of C-Media Mixer
NCallControlftctrl32.exe"FaxTalk Messenger Pro is a Windows TAPI based 32-bit application. When installed
XCatalyst Control Centreatixvdm.exe"Added by the RBOT.DMW TROJAN!"
XCdrom Controllercdromcntrl.exe"Added by the BATTRY-A TROJAN!"
XClient Server Control Process[path to trojan]"Added by the AGENT-HR TROJAN!"
NColorific Control PanelHgcctl95.exe"Colorific® from E-Color - ""delivers accurate gamma and color temperature across your entire system - monitor to printer and digital camera to monitor."" Now superseded by ColorWizzard™"
XControl"rundll32.exe ctrlpan.dll Restore ControlPanel"
UControl CenterCenter.exe"Associated with Hawking Technologies
XControl handler***********.exe [* = random char]"CoolWebSearch parasite variant"
XControl handlerahjinst.exe"CoolWebSearch parasite variant"
XControl handler[10 to 14 random char]THD.EXE"Added by the KREPPER-AI TROJAN!"
Ncontrol panelsmctrlw.exeSystem Tray icon for a Silicon Motion LynxEM based PCI Graphics Card
XControl PanelSystem.exe"Added by the DANI TROJAN!"
Xcontrol panel software servicecprs.exe"Added by the RBOT-FPI WORM!"
XControladores[path to trojan]"Added by the TELEFO-A TROJAN!"
YControlCenterctlcntr.exe"Part of Lenovo's (IBM) ThinkVantage Fingerprint Software - used on laptops and keyboards with integrated fingerprint readers"
NControlCenter2.0brctrcen.exeBrother scanner 'Control Center' application - can be started manually
NControlCentreTrayXWCTray.exe"System Tray access for the Xerox ControlCentre 2.0 software for their range of printers
XControlled Resource System Servicecrss.exe"Added by the AGOBOT.GH WORM!"
NControllerWFXCTL32.EXEFrom Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
XControlPanel"rundll32 internat.dll LoadKeyboardProfile"
XControlPanel"host32.exe internat.dll LoadKeyboardProfile"
XControlPanel"cmd32.exe internat.dllLoadKeyboardProfile"
XControlPanel"systemctrl.exe internet.dll LoadNetworkProfile"
XControlPanel"[path to executable] internat.dllLoadKeyboardProfile"
XControlPanel"popcorn.exe internat.dll LoadKeyboardProfile"
XControlPanel"popcorn64.exe rundll.dll LoadMouseProfile"
XControlPanel"popcorn72.exe rundll.dll LoadMouseProfile"
XControlPanel"svcc.exe internat.dllLoadKeyboardProfile"
XControlPanel"popcorn320.exe rundll.dll LoadMouseProfile"
XControlPanel"private.exe internat.dllLoadMouseCarpetProfile"
XControlPanel"twink64.exe internat.dllLoadKeyboardProfile"
XControlServiceMgrcsmsv.exe"Added by the AGENT-XC TROJAN!"
XCPU Temp Controlwuitgurd.exe"Added by the RBOT-AHV WORM!"
?Crystal 3D Audio ControlCWD3DSND.EXE"Crystal 3D Audio sound driver. Is it required?"
XCT Control SettingsCTSVCCD.EXE"Added by the RBOT-YS WORM!"
UDialer Controldc.exe"Dialer-Control. Detects and protects from premium rate adult content diallers"
UDirect UpdateDUControl.exe"DirectUpdate dynamic DNS updater"
YEarthlink Protection Control Centerelnk_pcc.exe"EarthLink Protection Control Center - ""powerful
NFaxTalk CallControl 6.0FTClCtrl.EXEThis allows the software to handle incoming and outgoing communications without requiring the FaxTalk Communicator application to be loaded into memory. Can be started manually
?FireBox Control PanelFireBox.exe"Control panel for the Presonus FireBox firewire based music recording system. Is it required?"
XFirewall Controlssys32.exe"Added by the SDBOT-DGI WORM!"
Ygw port controllerPORTCT95.EXE"From a visitor - "I must keep it active in start up or my Lexmark printer and RCA Cam program cannot discover a working port to work". From the file properties
XHard drive Controllerhdcontroller.exe"Added by the KIMAN.B WORM!"
UHawkEye IV Control PanelHAWK_32.EXE"Control Panel application for the old Number Nine graphics cards to change resolution
UHcontrolhcontrol.exeHotkeys on an ASUS Notebook. Only required if you use the additional keys
UHControlUserHControlUser.exeHotkeys on an ASUS Notebook. Only required if you use the additional keys
NHD Audio Control PanelRtHDVCpl.exe"Realtek HD Audio Manager
UHDDControlGuardHDDControlGuard.exe"Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
UHDDControlGuard.exeHDDControlGuard.exe"Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
?HsuGuiControlHsuGuiControl.exe"Part of the Starband Internet satellite client. What does it do and is it required?"
XI/O Controllerssvcnet.exe"Added by the TIBIK-B TROJAN!"
XICcontroliccontrol.exe"ICcontrol premium rate adult content dialer"
Xicrosof Avps32 Controlav32.pif"Added by the RBOT-AVC WORM!"
Xicrosoftf Avpx Controlavpx.exe"Added by the RBOT-AYN WORM!"
NInControl Desktop ManagerDMHKEY.EXEFor Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start -> Programs
NIW ControlCenteriwctrl.exe"Pinnacle Systems InstantWrite enables you to use your CD-R
UJOYTECH USB Neo S ControllerJoytechNeoSTrayIcon.exe"System Tray access to Joytech Neo S PC gamepad controller software"
XKYK Control SettingsKYSVCXD.EXE"Added by a variant of the RBOT WORM!"
XKYM Control Settingsphqghum.exe"Added by the RBOT.BQD WORM!"
NLightscribeLightScribeControlPanel.exe"System Tray access to the LightScribe Control Panel for CD/DVD writers based upon HP's LightScribe laser-etching process - which allows you to burn a label straight onto specially coated blank disks. Part of the main LightScribe System Software (LSS)"
NLightScribe Control PanelLightScribeControlPanel.exe"System Tray access to the LightScribe Control Panel for CD/DVD writers based upon HP's LightScribe laser-etching process - which allows you to burn a label straight onto specially coated blank disks. Part of the main LightScribe System Software (LSS)"
NLightScribeControlPanelLightScribeControlPanel.exe"System Tray access to the LightScribe Control Panel for CD/DVD writers based upon HP's LightScribe laser-etching process - which allows you to burn a label straight onto specially coated blank disks. Part of the main LightScribe System Software (LSS)"
XLogitech Desktop Controllerwrcam.exe"Added by a variant of the RBOT WORM!"
UM-Audio MobilePre Control Panel LauncherMPTask.exe"Control Panel Launcher for MobilePre USB bus-powered preamp and audio interface from M-Audio"
NMatrox Color Controlhgcctl95.exeFor Matrox video cards. Quick access to changing colors
NMatrox Control Centermgactrl.exeFor Matrox video cards. Quick access to settings
XMessenger Sharing Controlmnwsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft (R) Windows Network Latency Controller1.tmp"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Latency Controllernlc.exe"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Latency Controllersp2vc.exe"Added by a generic password stealer TROJAN - see here"
XMicrosoft Anti Virus Controllermsavc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Anti Virus Controllermsavc32.exe"Added by the SDBOT.EPW BACKDOOR!"
XMicrosoft Control Centercrtl.exe"Added by the RBOT-VX WORM!"
XMicrosoft DDE Controlwupades.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft DDEs ControlErun.pif"Added by the RBOT-AMU WORM!"
XMicrosoft Domain Controllermstc.exe"Added by the NUGACHE.A WORM!"
XMicrosoft Driver Controlwindrv.exe"Added by the SDBOT.FW WORM!"
XMicrosoft Messenger Management Controlsmsmgmctl.exe"Added by the RBOT-APA WORM!"
XMicrosoft Network Services Controllermmsvc32.exe"Added by the NANPY-A WORM!"
XMicrosoft PC Health Remote Assistance File Open & Save controlssfrcdlg32.exe"Added by the RBOT-AVY WORM!"
XMicrosoft Security Controlersfxsecues.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Service Controllerservices.exe"Added by the KALEL-D WORM! Note - this is not the legitimate services.exe process
NMicrosoft Sidewinder Game Controller SoftwareSWTRAY.EXEMS SideWinder game controller system tray icon. Available via Start -> Programs
XMicrosoft Update ControlMs64.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Video Capture ControlsMSsrvs32.exe"Added by the SDBOT-AAK WORM!"
XMicrosoft Video Controlstskmsgr.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Windows Controlmswctl32.exe"Added by the RBOT.JP WORM!"
XMicrosoftf DDEs Controllxes.exe"Added by the RBOT.BOF WORM!"
XMicrosoftf DDEs Controlwees.exe"Added by a variant of the RBOT WORM!"
XMicrosoftf DDEs Controlsoff.pif"Added by the RBOT-AKH WORM!"
XMicrosoftf DDEs Controlwhy-.exe"Added by the RBOT-AMV WORM!"
XMicrosoftf DDEs Controlmsnn.exe"Added by the RBOT-AXT WORM!"
XMicrosoftf DDEs ControlFEnR.exe"Added by the RBOT-AIM WORM!"
XMicrosoftf DDEs Controlw33s.exe"Added by a variant of the RBOT WORM!"
XMicrosoftf DDEs Controlwaes.exe"Added by a variant of the RBOT WORM!"
XMicrosoftz turn Controlaexl.exe"Added by the SDBOT.BCO WORM!"
XMicrosoftz turn Controlread.pif"Added by the RBOT-AFS WORM!"
NMightyFAX ControllerMFNTCTL.EXE"Mighty FAX from RKS Software - "installs a printer driver so that you can fax directly from Windows software""
XMS Network Controlmswin.exe"Added by the DUMBA TROJAN!"
XMSControl28crsss.exe"Added by the SPYBOT.AJX WORM!"
XMSControl31winnsyst.exe"Added by the RBOT.CFY WORM!"
XMSControl3d1isasse.exe"Added by the RBOT.CGU WORM!"
Xmsdev controlmsdevctrl.exe"Added by the SPYBOT.N BACKDOOR!"
XMSN Messenger User Controlsmsmsgr.exe"Added by the KELVIR.HI WORM!"
XNetwork Host Controller[path to trojan]"Added by the WHISPER TROJAN!"
XNetworks ControlerNetsis.exe"Added by the RBOT-NG WORM!"
UNotebookHardwareControlnhc.exe"""With Notebook Hardware Control you can easily control the hardware components of your Notebook"""
UNovaBackup * Tray ControlNbkCtrl.exe"Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here. * represents the version number"
XNvidia Control Daemonnksvc32.exeAdded by an unidentified WORM or TROJAN!
XNvidia Control Panelncsvc32.exe"Added by an unidentified VIRUS
UOmega ASIO Control PanelASIOSysTray.exe"System Tray access to the control panel for the Lexicon Omega ASIO (Audio Streaming I/O) desktop recording studio"
?Packard Bell EverSafe Tray ControlTrayControl.exe"Packard Bell EverSafe software. What does it do
UParentalControlParentalControl.Exe"Crawler Parental Control - ""Get perfect control of websites your children browse
?PDF Converter Registry ControllerRegistryController.exe"Part of PDF Converter Professional version 2 from Scansoft (now Nuance). what does it do and is it required?"
?PDF4 Registry ControllerRegistryController.exe"Part of PDF Converter Professional version 4 from Scansoft (now Nuance). what does it do and is it required?"
?PDF5 Registry ControllerRegistryController.exe"Part of PDF Converter Professional and PDF Create (both version 5) - from Nuance. what does it do and is it required?"
?PDF6 Registry ControllerRegistryController.exe"Part of PDF Converter Professional version 6 from Nuance. what does it do and is it required?"
UPestPatrol Control CenterPPControl.exe"PestPatrol Control Terminal - utility that launched PestPatrol features such as PPMemCheck and CookiePatrol before CA's acquisition"
YPP2000 Taskbar ControlPPTbc.exeProtector Plus anti-virus software - system tray access
UPPControlPPControl.exe"PestPatrol Control Terminal - utility that launched PestPatrol features such as PPMemCheck and CookiePatrol before CA's acquisition"
XProgramControlProgramControl.exe"Added by the DLOADR-BAG TROJAN!"
UQuick ControlsAstrotoolbar.exeGateway Astro Screen and Sound Controls tray icon
NRemote ControlRc.exeHinet Hi-Five ISP software
NRemote ControllerTVRMVCR.EXE"ProLink PlayTVpro TV tuner software"
URemoteControlrmctrl.exe"Remote Control background application for Cyberlink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control
URemoteControlPDVDServ.exe"Remote Control background application for Cyberlink's PowerDVD version 5 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control
URemoteControl8PDVD8Serv.exe"Remote Control background application for Cyberlink's PowerDVD version 8. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control
USandboxieControlControl.exe"SandBoxie - allows data to be read from the hard drive by an application but never written back unless you allow it"
USandboxieControlSbieCtrl.exe"""SandBoxie runs your programs in an isolated space which prevents them from making permanent changes to other programs and data in your computer"""
XSchijfControleurGDC.exe"SchijfControleur Dutch rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
NScreen Saver ControlFSScrCtl.exeInstalls as part of the Hubble Space Telescope screen saver (and possibly others). Lets you control your installed screensavers from a System Tray icon
XSecurity CenterAppControl.exe"Added by the SDBOT.CFT WORM!"
XService Control Managerscm.exe"Added by the AGOBOT-GD BACKDOOR!"
XService ControllerCsrrs.exe"Added by the GAOBOT.AO WORM!"
XService Controllerservice.exe"Added by the PREVERT TROJAN!"
XServices Controllerlsassa.exeAdded by the CIADOOR.122 VIRUS!
XServices Controllerservices.exe"Added by the CIADOOR-F TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UShowLOMControl[strange symbol]"Note that there is a strange symbol in the command field and in logs it's shown as ""O4 - HKLM\..\Run: [ShowLOMControl] [strange symbol]"". Additional registry information for the entry is ""Reg_DWORD 0x00000001 (1)"". It means Show ""LAN on Motherboard"" Control. On systems where you can install an external LAN interface
USoftany Monitor ControlMonitorControl.exe"Softany Monitor Control - ""control your computer's monitor and screensaver"""
NSonic A3D Controlvrtxctrl.exeSound related options
NSoundMAX Control PanelSmax4.exe"System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel"
XSpools Service Controllerspools.exe"Added by the KASSBOT-C WORM!"
XSpy-ControlSpy-Control.exe"Spy-Control spyware remover - not recommended
USpyware Guard Control Panelspywareguardcp.exe"""SpywareGuard provides a real-time protection solution against spyware"""
XSVX Control Servicesvxhost.exe"Added by the FORBOT-K WORM!"
UTaakcontroletaskmon.exe"Task Monitor (on Dutch language versions of Windows) - checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users
NTaskbar Display Controls"RunDLL deskcp16.dll QUICKRES_RUNDLLENTRY"
UTOSHIBA Volume IndicatorVolControl.exeOn-screen volume indicator for Toshiba notebooks
YTray control for Malwarebytes' Anti-Malwarembamtrayctrl.exe"Malwarebytes' Anti-Malware - ""monitors every process and actually stops malicious processes before they even start. It uses our impressive technology that is in fact a completely novel way of heuristic scanning and it is our response to the increasingly complex malware threats"""
UTV878 Remote ControlC7XRCtl.exe"Related to Kworld TV878 Tuner"
XUSB controllerSvcmm32.exeSvcMM backdoor parasite downloader
NVerizon Control Padcpad.exe"Control Pad - installed with Verizon DSL accounts. Tool designed to streamline the online experience"
YVistaFirewallControlVistaFirewallControl.exe"Vista Firewall Control from Sphinx Software (forerunner to Windows 7 Firewall Control) - ""Protects your applications from undesirable network incoming and outgoing activity
XVolume ControllerVolumeControl.exe"Added by the SDBOT.AYI WORM!"
XVSP32 Controlsvsp32.exe"Added by the RBOT-VA WORM!"
XWindow UDP Control Servicwinlogon.exe"Added by the RBOT-GXN WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows AdControlWinAdCtl.exeWindupdates adware variant
XWindows Anti Virus Control Centeravrscan.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Anti Virus Control Centerwinavscan.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows API Control Taskapitsk32.exe"Added by the MYTOB.HI WORM!"
XWindows Audio Controlppnsvc.exe"Added by the HAM TROJAN!"
XWindows ControlControl.exe"Added by the GREK.A TROJAN! If there is another file with the same file name in the Windows folder
XWindows ControlAdWinCtlAd.exeWindupdates adware variant
XWindows Controls Centerwinudmr.exe"Added by the LAMER.AA BACKDOOR!"
XWindows Desktop Controlerwindesktop.exe"Added by the SDBOT-XH WORM!"
XWindows Firevall Control Crundll.exe"Added by the GAERTOB.A TROJAN!"
XWindows Manager ControlWINMUR32.EXE"Added by the AGOBOT-AR WORM!"
XWindows Messanger Control Centersvchosl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Messanger Control Centersvhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Messanger Control Centerwinlogin.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Messanger Control Centerwinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Messanger Control Centerwinsys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Network ControllerMqguard.exe"Added by the FORBOT-CL WORM!"
XWindows Network ControllerWinxPupd.exe"Added by the FORBOT-DK WORM!"
XWindows Network Controllerwinmms32.exe"Added by the FORBOT-ED WORM!"
XWindows Network Controllerwingmt.exe"Added by a variant of the SDBOT WORM!"
XWindows Network ControllerWin9x.exe"Added by the WOOTBOT.I WORM!"
XWindows Network Controllerwinmms32.exe.exe"Added by the FORBOT-ED WORM!"
XWindows pack Control Centertaskmam.exe"Added by the TOMETA-J TROJAN!"
XWindows Registry Controlwinreg.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Security Controlwuaucls.exe"Added by the FORBOT-V WORM!"
XWindows Service Controllerservices.exe"Added by the KALEL-B WORM! Note - this is not the legitimate services.exe process
XWindows Service Controller Agenttaksmgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Spooler Control Serviceqwidh.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows SYN Control Centerwinmnon32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows System-Control Driverssyscontrl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Controlwinudspm.exe"Added by a variant of the SDBOT WORM! See here"
XWindows UDP Control Centerauth.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control CenterehSched.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerfxstaller.exe"Added by the AGENT-IEE TROJAN!"
XWindows UDP Control Centerinstaller.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows UDP Control Centermsnmngs.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centermsnpd.exe"Added by the SDBOT.EBA BACKDOOR!"
XWindows UDP Control Centermswinudpmgr32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerscvhost.exe"Added by the PUSHBOT.EH WORM!"
XWindows UDP Control Centertaksmrg.exe"Added by the AGENT.WOH TROJAN!"
XWindows UDP Control Centertmps.exe"Added by the SDBOT.EBA BACKDOOR!"
XWindows UDP Control Centerwinlive32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwinmsn.exe"Added by the SDBOT.EBA BACKDOOR!"
XWindows UDP Control Centerwinrofl32.exe"Added by the LDPINCH-RZ TROJAN!"
XWindows UDP Control Centerwinudpmg.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwinudpmgrs.exe"Added by the DROPPER.CMV TROJAN!"
XWindows UDP Control Centerwinudpmsgr.exe"Added by the SDBOT.GAV WORM!"
XWindows UDP Control Centerwinupmgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwinuscn32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwksvcsc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwinudpmgr.exe"Added by the DLOADR-HQL TROJAN!"
XWindows UDP Control Centerfxsteller.exe"Added by the IRCBOT-J BACKDOOR!"
XWindows UDP Control Centermsnsmsgrs.exe"Added by the PUSHBOT.MF WORM!"
XWindows UDP Control Centerwinmgrs.exe"Added by the PUSHBOT.MY WORM!"
XWindows UDP Control Managerwinudpmgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Serviceswksvcsc.exe"Added by the ANTIAV-C TROJAN!"
XWindows Update Controllermwoffice.exe"Added by the BATTRY-A TROJAN!"
XWindows USB Control Driveriexplore.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows USB controlerwinusb.exe"Added by the RBOT-HR WORM!"
XWindows Virus Controlplou.exe"Added by the SDBOT-ACZ WORM!"
XWindows Volume Controlongsvc.exe"Added by the SLENFBOT.DZ WORM!"
YWindows7FirewallControlWindows7FirewallControl.exe"Windows 7 Firewall Control from Sphinx Software - ""Protects your applications from undesirable network incoming and outgoing activity
XWindows_Protectwincontrol32.exe"Added by the RBOT-ADK WORM!"
NWinFax PRO ControllerWFXCTL32.EXEFrom WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
XWinSpyControlpgs.exe"WinSpyControl rogue security software - not recommended. A member of the AVSystemCare family"
UWSEP Status+ConfigurationcontroldGUI.exe"User interface for the WatchGuard Security Event Processor (WSEP) Status/Configuration dialog box associated with the Firebox series of security products from Watchguard"
UxPlanetControlxPlanetControl.exe"Tool that displays a globe with current day/night zones and clouds on users desktop."
UXtrem parental controlpcx.exeParentXtreme - surveillance software. Uninstall this software unless you put it there yourself
X[various names]control64.exe"Wareout - malware masquerading as a spyware and dialer remover"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.