Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
N!NoLoadwinrecon.exe"WinRecon keystroke logger/monitoring program - remove unless you installed it yourself!"
Consume"Consumer Input Rewarded with MyPointsU"ConsumerInputRewardedwithMyPoints
Consume"Consumer Input Rewarded with MyPointsU"ConsumerInputRewardedwithMyPoints
Version"NVIDIA nView Control PanelNnwiz.exe
X*MSConfig32aecache.exe"Detected by F-Secure as the OBFUSCATED.GP TROJAN!"
?.NET configsysmon32.exe"??"
X.TEXTCONVcsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
X.TEXTCONVlsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
Y36X Raid ConfigurerJMRaidSetup.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
U3Deep Control Panel3DeepCTL.EXE"3Deep® from E-Color corrects lighting
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
UAccess ConnectionsACTray.exe"System Tray access to the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments
XAccess Control Appwinsto.exe"Added by the AGENT.DGO TROJAN!"
XAccess WebControl[path to file]"Added by the PPDOOR-M TROJAN!"
XAcontiaconti.exeAdult content dialler
UACWLIconACWLIcon.exe"Part of the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments
XAdmanager ControllerAdManCtl.exe"Adware
XAdobesysconfig.exeAdded by an unidentified WORM or TROJAN!
NADSL Diagnostic Toolsmapiicon.exeSystem tray access to ADSL modem diagnostic tools. Available via Start -> Programs
NAGEIA PhysX SysTrayTrayIcon.exe"System Tray access to display properties for AGEIA PhysX graphics cards. Unless you change your desktop resolution
XAHUANACON.EXE"Added by the NACO.A WORM!"
NAmerica Online *.* Tray Iconaoltray.exe"Adds the AOL icon in the System Tray (*.* denotes version if present) for versions of AOL up to and including 9.0. Start AOL via the desktop or quick launch shortcuts or via Start → All Programs"
XAntiSpyControlpgs.exe"AntiSpyControl rogue security software - not recommended
XAntiSpywareControlpgs.exe"AntiSpywareControl rogue security software - not recommended
XAol Configuration Loaderaimsng.exe"Added by the SDBOT-XE WORM!"
XAolConconfig.com"Added by the TAPLAK WORM!"
UAppconvAppCon.exe"Vital Application Console - part of POS-partner 2000 point-of-sale software from Vital. This is the taskbar icon and is enabled at startup by the "Auto-start when OS starts" option. Required for a connection to be established"
Xappconnappconn.exe"Added by the CARGAO WORM!"
XARCHIVE CONTROLfixupdattr.exe"Added by the MYTOB.GU WORM!"
NArcSoft ConnectACDaemon.exe"Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia
NArcSoft Connection ServiceACDaemon.exe"Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia
UAshampoo HDD Control GuardHDDControlGuard.exe"Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
Xasnconsolemsasn.exe"Added by the RBOT.EVU TROJAN!"
XAti Control Panelatiphexx.EXE"Added by the RBOT-BR WORM!"
YATI Remote ControlATIRW.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
YATI Remote ControlATIX10.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
XATI Video Driver Controlatigfx.exe"Added by the RBOT-FWL WORM!"
XATI Video Driver Controlbtorrent.exe"Added by a variant of the IRCBOT TROJAN!"
XATI Video Driver Controls[path to worm]"Added by the SDBOT-DDS WORM!"
XATM Controladpn.exe"Added by the MMS.A WORM!"
XAttuneContentUpdaterattune_cu.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAuto File System Conversion Utilityscricon.exe"Added by the SDBOT.EYB WORM!"
XAVantivirusAvconsol.exe"Added by the MSNVB-D WORM!"
UAvconsoleEXEAvconsol.exeFrom McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Used to schedule regular scans. If you don't have scans scheduled you don't need it
XavscanUsbconeted.exe"Added by the PROVIS-A TROJAN!"
UAXIS Print System TrayIconTrayIcon.exe"System Tray access to AXIS Print System from AXIS Communications - ""adds printer discovery
YBDMConBdmcon.exe"BitDefender antivirus"
UBJPD HID ControlTVMon.exe"Related to Canon Photo viewer"
XBluetooth Configbtwindin32.exe"Added by the SDBOT-DFN WORM!"
UBluetooth Connection AssistantLBTWiz.exe"Bluetooth connection manager for Logitech based bluetooth wireless products"
UBoingo Wireless UtilityIcon###XXX#X#.exe"Starts the Boingo Wireless utility
XBoot Configbootconfig.exe"Added by the FLOOD-EV TROJAN!"
UC-Media Echo ControlEchoCtrl.exeC-Media produce audio chipsets that are often found on popular motherboards with on-board audio. You may need it if you use the echo control feature of C-Media Mixer
UCacheBoosttrayicon.exe"CacheBoost ""optimizes the System Cache-Management of Windows XP/2000/NT and Windows .Net Servers
NCallControlftctrl32.exe"FaxTalk Messenger Pro is a Windows TAPI based 32-bit application. When installed
Xcartaoconflicted.exe"Added by the DADOBRA-DV TROJAN!"
XCatalyst Control Centreatixvdm.exe"Added by the RBOT.DMW TROJAN!"
UCCUTRAYICONCCU_TrayIcon.exe"Related to Traybar Launcher from Intel Corporation belonging to Intel® Viiv®"
XCdrom Controllercdromcntrl.exe"Added by the BATTRY-A TROJAN!"
UChangeICONSPMSMON.EXECard reader related program. Note - may cause problems with My Computer loading at startup. Disabling through MsConfig seems to solve the problem
XCiodiagDECCONF.EXE"Added by the STRAT.EL TROJAN!"
XCli Confgcliconfig.exe"Added by a variant of the SPYBOT WORM! See here"
XCLICONFGCLICONFG.EXE"Added by the OPASERV.T WORM!"
XClient Server Control Process[path to trojan]"Added by the AGENT-HR TROJAN!"
Xcmd32configs.exe"Hijacker
Xcmdconcmdcon.exe"Added by the CRYPTER.A TROJAN!"
NColorific Control PanelHgcctl95.exe"Colorific® from E-Color - ""delivers accurate gamma and color temperature across your entire system - monitor to printer and digital camera to monitor."" Now superseded by ColorWizzard™"
NCompaq ConnectionsCOMPAQ~1.EXE"See here - ""messaging service that automatically sends you support information
NCompaq ConnectionsBackWeb-1940576.exe"See here - ""messaging service that automatically sends you support information
NCompaq ConnectionsCompaq Connections.exe"See here - ""messaging service that automatically sends you support information
XCompaq32 Service Driversmsconfig32.exe"Added by the SDBOT-ADC WORM!"
Xcon[path to trojan]"Added by the BRAVE-A TROJAN!"
?Concurreconcurre.exe"??"
XConducteurPriveGDC.exe"ConducteurPrive rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XConfgbootconfig.exe"Added by the VB-ERB WORM!"
XConfidentSurfGDC.exe"ConfidentSurf rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XConfidentUserSRP.exeConfidentUser rogue system error and cleaning utility - not recommended
XConfigservice.exe"Added by the ISRAZ.B WORM!"
XConfigWinService32.exe"Added by the CRUTCHA-A TROJAN!"
XConfigwinconfig.exe"Added by the GIP.113.B1 TROJAN!"
XConfigCONFIG.EXE"Added by the PSWGIP.B TROJAN!"
XConfigTaskUpdate.exe"Added by the MDROP-BRO TROJAN!"
XConfig LoadationiEEexplore.exe"Added by the SDBOT.H TROJAN!"
XConfig LoadatiorinI3Explorer.exe"Added by the SDBOT.H TROJAN!"
XConfig Loadersvchosl.exe"Added by the GAOBOT.P WORM!"
XConfig Loadersysldr32.exe"Added by the GAOBOT WORM!"
XConfig Loaderscvhost.exe"Added by the GAOBOT.AE or GAOBOT.AO WORMS!"
XConfig Loadersvhost.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfig Loadersvchost2.exe"Added by the AGOBOT.XE WORM!"
XConfig Loader[worm filename]"Added by the AGOBOT-AE WORM!"
XConfig LoaderSYSMGR.EXE"Added by the AGOBOT.C WORM!"
XConfig Loaderwincrt32.exe"Added by the AGOBOT-AW WORM!"
XConfig Loader for Microsoft Windowsmwincfg32.exe"Added by the AGOBOT.BD WORM!"
XConfig Loader2explores.exe"Added by the GAOBOT.BT WORM!"
XConfig Loadrwinsys32.exe"Added by the AGOBOT-HN WORM!"
XConfig33.exeConfig33.exe"Added by the SDBOT.T TROJAN!"
XConfiggLoadercart322.exe"Added by the GAOBOT.DJ WORM!"
UConfigSafeCFGSAFE.EXE"ConfigSafe - lets you identify changes to the registry
UConfigSafeAUTOCHK.EXE"ConfigSafe - lets you identify changes to the registry
NConfigServicesConfig.exePart of initial setup on a Compaq PC
Xconfigsetupconfigsetup32.exe"Added by the AGOBOT-AFP WORM!"
XConfigurationexplorer32.exe"Added by the SDBOT-ML WORM!"
Xconfigurationapphost.exe"Added by the SDBOT-VP WORM!"
XConfigurationntsys32.exe"Added by the SDBOT-LN WORM!"
XConfigurationmsgfixs.exe"Added by the SDBOT-NN WORM!"
XConfiguration DefaultWuxat.exe"Added by the SPYBOT-CA WORM!"
XConfiguration Driverscghost.exe"Added by the SDBOT-DLA WORM!"
XConfiguration FileWinset32.exeAdded by the FLUX.101 TROJAN!
XConfiguration Loadedwupdated.exe"Added by the MOEGA or MOEGA.AG or MOEGA.AP WORMS!"
XConfiguration Loadedlssas.exe"Added by a variant of the SDBOT WORM!"
XConfiguration Loadediexploree.exe"Added by the SDBOT-KC WORM!"
XConfiguration Loaderaim95.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadercmd32.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadersyscfg32.exe"Added by the SDBOT.B BACKDOOR!"
XConfiguration Loaderservice5.exe"Added by the GAOBOT.AF WORM!"
XConfiguration Loaderlfass.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadersycfg34.exe"Added by the GAOBOT.AN WORM!"
XConfiguration Loaderwincrt32.exe"Added by the GAOBOT.BF WORM!"
XConfiguration Loaderwindex.exe"Added by the GAOBOT.BZ WORM!"
XConfiguration Loaderdosrun32.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderService.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderServicess.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadersw32.exe"Added by the AGOBOT.BQ WORM!"
XConfiguration LoaderSystem.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderWinreg.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadersysinfo.exe"Added by the GAOBOT.FQ WORM!"
XConfiguration Loadermicrosoft.exe"Added by the GAOBOT.JB WORM!"
XConfiguration Loaderconfgldr.exe"Added by the GAOBOT.GEN!POLY WORM!"
Xconfiguration loaderwinicfg32.exe"Added by the GAOBOT.RQ WORM!"
XConfiguration Loadersvhst.exe"Added by the GAOBOT.YC WORM!"
XConfiguration Loadermsgfix.exe"Added by the GAOBOT.AUS or SDBOT.J or SDBOT-QG WORMS!"
XConfiguration Loadermsnss.exe"Added by the GAOBOT.AUS WORM!"
XConfiguration LoaderIEXPL0RE.EXE"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration Loaderloadcfg32.exe"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration LoaderMSTasks.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadersystemry.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration LoaderccSort.exe"Added by the AGOBOT.SR WORM!"
XConfiguration Loadersmss32.exe"Added by the AGOBOT.MB WORM!"
XConfiguration Loaderwincffg.exe"Added by the AGOBOT.A3 WORM!"
XConfiguration Loaderseru32.exe"Added by the SDBOT-VR WORM!"
XConfiguration Loaderbotss.exe"Added by the SDBOT-XS WORM!"
XConfiguration Loaderldasp.exe"Added by the AGOBOT.BH WORM!"
XConfiguration Loadermsgcfgsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadersmsai.exe"Added by the SDBOT-YE WORM!"
XConfiguration Loadersvupdate.exe"Added by the RANDEX.DXP WORM!"
XConfiguration Loadercrcss.exe"Added by the AGOBOT.ADG WORM!"
XConfiguration Loaderlexplore.exe"Added by the RBOT-AGX WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XConfiguration Loaderscvhost.exe"Added by the AGOBOT-AAE and SDBOT.AR WORMS!"
XConfiguration Loadersvchost.exe"Added by the PARADROP-A WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XConfiguration Loadersvchost2.exe"Added by the AGOBOT.JR WORM!"
XConfiguration Loaderdezi.exe"Added by the SDBOT-OB WORM!"
XConfiguration Loadermouse.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadermsg.exe"Added by the SDBOT.BT WORM!"
XConfiguration LoaderWinHelper.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loaderextrac.exe"Added by the SDBOT-AFP WORM!"
XConfiguration LoaderDVD-Player.exe"Added by a variant of the SDBOT WORM!"
XConfiguration LoaderIEXPLORE.EXE"Added by the SDBOT-KW WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XConfiguration Loaderwincore.exe"Added by the SDBOT.BHE WORM!"
XConfiguration Loaderconfigldr.exe"Added by the AGOBOT-PP TROJAN!"
XConfiguration Loaderahnhst.exe"Added by the AGOBOT.MX WORM!"
XConfiguration Loaderntdm.exe"Added by the AGOBOT.RV WORM!"
XConfiguration Loadermsnmsgr.exe"Added by the SDBOT-SO WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XConfiguration Loadersvschost.exe"Added by the SDBOT-NS WORM!"
XConfiguration Loaderwump.exe"Added by the AGOBOT-BU BACKDOOR!"
XConfiguration LoaderWinSys32ys.exe"Added by the SDBOT.BCS WORM!"
XConfiguration Loadercvcd.exe"Added by the AGOBOT-DH BACKDOOR!"
XConfiguration Loaderasnclt32.exe"Added by the AGOBOT-EB BACKDOOR!"
XConfiguration Loadersoundconf.exe"Added by the AGOBOT-MH WORM!"
XConfiguration Loaderwin32exec.exe"Added by the SDBOT-LA WORM!"
XConfiguration Loadermservs.exe"Added by the SDBOT-NM WORM!"
XConfiguration Loaderupdate.exe"Added by the SDBOT-OS WORM!"
XConfiguration LoaderFILENAME.EXE"Added by the AGOBOT-DQ WORM!"
XConfiguration Loaderexplore.exe"Added by the GAOBOT.GW WORM!"
XConfiguration Loadermsgfixy.exe"Added by the SLINBOT.QW BACKDOOR!"
XConfiguration Loaderwinfix.exe"Added by the SDBOT-MA WORM!"
XConfiguration Loaderscvh0st.exe"Added by the AGOBOT-AX WORM!"
XConfiguration Loadermsrun.exe"Added by the AGOBOT-Y WORM!"
XConfiguration Loader 2confuldr.exe"Added by the AGOBOT-FC WORM!"
XConfiguration Loader ServiceWinsys32.exe"Added by the RBOT-YV WORM!"
XConfiguration Loader Servicedevl32.exe"Added by the SDBOT-XY WORM!"
XConfiguration Loader10ip7.exe"Added by the AGOBOT-ANZ WORM!"
XConfiguration Loadingsvchos1.exe"Added by the GAOBOT.DK WORM!"
XConfiguration Loadingconfigldr.exe"Added by the AGOBOT-EC WORM!"
XConfiguration Loading Servicewscel.exe"Added by the SDBOT-WJ WORM!"
XConfiguration Loadriexplore.exeeAdded by an unidentified WORM or TROJAN!
XConfiguration ManagerCNFGLD32.EXE"Added by the SDBOT TROJAN!"
XConfiguration ManagerCnfgldr.exe"Added by the SDBOT TROJAN!"
XConfiguration Managercfg32.exe"BookedSpace parasite. Note - the ""cfg32.exe"" file is located in %Windir%"
XConfiguration Serveciesewins.exe"Added by the SDBOT-COH WORM!"
XConfiguration Servicesuchost.exe"Added by the TREB TROJAN!"
XConfiguration Servicesmswords.exe"Added by the SDBOT-YM WORM!"
XConfiguration UpdateUPDT32V2.EXE"Added by the SPYBOT-AA BACKDOOR!"
NConfiguration UtilityCONFIG.EXEControls linksys wireless connection. Available from the Desktop
UConfiguration Utilitywlanutil.exe"NetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards)"
XConfiguration WizardCfgwiz32.exe"Added by a variant of the HACKTACK TROJAN! Not to be confused with the legitimate MS ""ISDN Configuration Wizard"" (Cfgwiz32.exe)"
XConfiguration32 Loader32winamp32.exe"Added by the SDBOT-BIC WORM!"
XConfigurations Ascltasclt.exe"Added by the SDBOT-MX WORM!"
XCONFIGUREvantivir62.exe"Added by the AGOBOT-ZD BACKDOOR!"
UConfigUtilityConfigUtility.exe"Wireless management utility for the HWC54G Hi-Speed Wireless-G CardBus Card from Hawking Technologies
XConfigVirservices.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XConfLoadersysconf16.exe"Added by the SDBOT-FB TROJAN!"
Xconime.execonime.exe"Added by the AVENDOG WORM! Note - this is not the legitimate Console IME process of the same filename which is located in %System%"
NConmgrconmgr.exeStarts Winfax pro at startup
UConMgr.execonmgr.exeConnection Manager as used by Earthlink and others. If you need this to ensure a proper connection but don't want to connect at startup try creating your own shortcut
Xconmswfconrnbne.exe"Added by the SDBOT-DEX WORM!"
UConnect KasambaKasamba.exe"""Finding the expert help that you need is easy on Kasamba. With more than 30
XConnect2Partyconnect2party.exeAdult content dialler
NCONNECTAuto UpdateCONNECTScheduler.exe"Automatic update scheduler for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
NCONNECTAUTrayAppCONNECTAUTrayApp.exe"System Tray access to change update settings for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
UConnection KeeperConKeepM.exe"""Connection Keeper is an invaluable time-saving tool for dial-up users. This free program simulates Internet browsing (at a random interval) to prevent your connection from appearing idle
NConnection ManagerCManager.exeSBC Yahoo DSL service connection manager. You can connect from the network connections. Users having problems with this have been advised to uninstall the connection manager via Add/Remove Programs and it won't affect the service
XConnectivity Tool[path to trojan]"Added by the LITEBOT-E TROJAN!"
XConnectorSYS.EXE"Nunci premium rate dialer"
XConnectorsms.EXE"Added by the ExDial-B premium rate adult content dialer"
NCONNECTSchedulerCONNECTScheduler.exe"Automatic update scheduler for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
XConsconsol32.exe"Hijacker - redirects to an adult content portal
Xconscorrconscorr.exe"VX2.Transponder parasite updater/installer related"
XConsole de Gerenciamento Microsoftcsrss.exe"Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Level4"" subfolder"
XConsole de Gerenciamento Microsoftcsrss.exe"Added by the BANCBAN-ET TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Central de Segurança"" subfolder"
UConsumer InputConsumerInput.exe"Consumer Input Toolbar. Opt-in market research monitoring you browsing habits - see the FAQ"
?Contactecontacte.exe"Some kind of driver?"
XContent connector[random filename].exe"Added by the DIALER-Y TROJAN! Note - uses a random filename and random folders. Usually the folder containing the file is a Temp folder"
XContent List Management Subsystemclmss.exe"Added by the SPYBOT-EL WORM!"
XContent Servicewinserv[LETTER].exe"PurityScan adware"
XContentDownload"rundll32.exe MSA64CHK.dllDllMostrar"
XContentEraserGDC.exe"ContentEraser rogue privacy tool - not recommended
XContentServicewinservn.exe"PurityScan adware - see here"
UContentTransferWMDetector.exeContentTransferWMDetector.exe"Part of Sony's Content Transfer Software which ""provides an easy way to transfer music
XContinueInstallbpsinstall.exe"BrowserAid/BrowserPal foistware"
XContraviroContraviro.exe"Contraviro rogue security software - not recommended
XContraVirusContraVirusPro.exe"ContraVirus rogue security software - not recommended
XContraVirusContraVirus.exe"ContraVirus rogue security software - not recommended
XControl"rundll32.exe ctrlpan.dll Restore ControlPanel"
UControl CenterCenter.exe"Associated with Hawking Technologies
XControl handler***********.exe [* = random char]"CoolWebSearch parasite variant"
XControl handlerahjinst.exe"CoolWebSearch parasite variant"
XControl handler[10 to 14 random char]THD.EXE"Added by the KREPPER-AI TROJAN!"
Ncontrol panelsmctrlw.exeSystem Tray icon for a Silicon Motion LynxEM based PCI Graphics Card
XControl PanelSystem.exe"Added by the DANI TROJAN!"
Xcontrol panel software servicecprs.exe"Added by the RBOT-FPI WORM!"
XControladores[path to trojan]"Added by the TELEFO-A TROJAN!"
YControlCenterctlcntr.exe"Part of Lenovo's (IBM) ThinkVantage Fingerprint Software - used on laptops and keyboards with integrated fingerprint readers"
NControlCenter2.0brctrcen.exeBrother scanner 'Control Center' application - can be started manually
NControlCentreTrayXWCTray.exe"System Tray access for the Xerox ControlCentre 2.0 software for their range of printers
XControlled Resource System Servicecrss.exe"Added by the AGOBOT.GH WORM!"
NControllerWFXCTL32.EXEFrom Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
XControlPanel"rundll32 internat.dll LoadKeyboardProfile"
XControlPanel"host32.exe internat.dll LoadKeyboardProfile"
XControlPanel"cmd32.exe internat.dllLoadKeyboardProfile"
XControlPanel"systemctrl.exe internet.dll LoadNetworkProfile"
XControlPanel"[path to executable] internat.dllLoadKeyboardProfile"
XControlPanel"popcorn.exe internat.dll LoadKeyboardProfile"
XControlPanel"popcorn64.exe rundll.dll LoadMouseProfile"
XControlPanel"popcorn72.exe rundll.dll LoadMouseProfile"
XControlPanel"svcc.exe internat.dllLoadKeyboardProfile"
XControlPanel"popcorn320.exe rundll.dll LoadMouseProfile"
XControlPanel"private.exe internat.dllLoadMouseCarpetProfile"
XControlPanel"twink64.exe internat.dllLoadKeyboardProfile"
XControlServiceMgrcsmsv.exe"Added by the AGENT-XC TROJAN!"
NCorel Colleagues & Contacts Reminderscffrem.exe"Corel Colleagues & Contracts - all-in-one organizer for scheduling meetings
NCorrectConnectCConnect.exeBroadband ISP diagnostic tool - as used by NTL and Cox Communications. Shortcut available
XCPU Temp Controlwuitgurd.exe"Added by the RBOT-AHV WORM!"
NCreative PCI Audio Configuration Utilitystarter.exe"System Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on this special page. Similar to EnsoniqMixer"
?Crystal 3D Audio ControlCWD3DSND.EXE"Crystal 3D Audio sound driver. Is it required?"
XCT Control SettingsCTSVCCD.EXE"Added by the RBOT-YS WORM!"
XctfmonWinConst.exe"Added by the ASSASIN-G TROJAN!"
Xctfmoonmicrosoftconfigurator.exe"Added by the DELF-ALS TROJAN!"
XCurrent Security Configcsecure.exe"Added by the RBOT-AMO WORM!"
XCvfjxANACON.EXE"Added by the NACO.A WORM!"
NDACONFIGEXEdaconfig.exe3Com NIC Diagnostics. Available via Start -> Programs
XDefaultConfigurationdefaultconfh.exe"Added by the AGOBOT-JC WORM!"
XDesktop"rundll32.exe msconfd.dllRestore ControlPanel"
UDesktopIconToyDesktopIconToy.exe"""Desktop Icon Toy is an easy to use desktop icon enhancement tool
?DevconDefaultDBREADREG"Appears to be related to older Creative Soundblaster soundcards"
XDevice Configuration Loadermsdvc32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
UDialer Controldc.exe"Dialer-Control. Detects and protects from premium rate adult content diallers"
UDirect UpdateDUControl.exe"DirectUpdate dynamic DNS updater"
XDisk Panel Configurationdpcsvc.exe"Added by the IRCBOT.BSQ BACKDOOR!"
NDiskeeperSystrayDkIcon.exe"DisKeeper defragmentation software - can be started manually"
NDisplayTrayIconTrayIcon.exe"System Tray access to display properties for ABIT graphics cards. Unless you change your desktop resolution
XDNS Config servicewin32.exe"Added by the RBOT-TL WORM!"
NDPConfigDPConfig.exe"Compuware DevPartner Studio Configuration Utility
UDriveIconsDriveIcon.exe"Drive Icons from Realtek - shows a specific icon for each card type for their card reader controllers"
XDriverConfdvrconf.exe"Added by the AGOBOT-IY WORM!"
UDrvIconDrvIcon.exe"""Vista Drive Icon changes the drive icons shown in Windows ""My Computer""
UE-colorIconMgr.ExeSets the colour of your monitor when running games that recognise E-Color so that you get 'what the game designer intended' when you see the game. Also allows monitor callibration through a program called 3-Deep. If you play a lot of games it can be useful. Can be disabled from starting up from within the program
Ueabconfg.cplEabServr.exeEasy Access Buttons control panel on Compaq laptops. Only required if you use the extra keys
YEarthlink Protection Control Centerelnk_pcc.exe"EarthLink Protection Control Center - ""powerful
UEicon NetworksLAN_DAEMONwatch.exe"Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually"
UEicon TechnologyLAN_DAEMONwatch.exe"Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually"
UEnterra Icon KeeperIcnKeepr.exe"Icon Keeper - ""tool to save and restore icon positions on the desktop"""
NEvent Planner Reminders Tray IconPLNRnote.exePart of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
XExplorerconfig_.com"Added by the FLOPPY-D WORM!"
XExplorer5config_.com"Added by the VB.CBG WORM!"
XExplorerRunconime.exe"Added by the DLDR-G TROJAN! Note - this is not the legitimate Console IME process of the same filename which is located in %System%. This one is located in %Temp%"
NFaxTalk CallControl 6.0FTClCtrl.EXEThis allows the software to handle incoming and outgoing communications without requiring the FaxTalk Communicator application to be loaded into memory. Can be started manually
Xfile laoder configurationrnd32.exe"Added by the RBOT.BQJ WORM!"
?FireBox Control PanelFireBox.exe"Control panel for the Presonus FireBox firewire based music recording system. Is it required?"
XFirewall configReadMe.exe"Added by the SILLYFDC.BBT WORM!"
XFirewall Controlssys32.exe"Added by the SDBOT-DGI WORM!"
XFirewall Sp2 systemsys32Conf.exe"Added by the RBOT-ABT WORM!"
UFortis Secure Layer Configcseinst.exeFortis Bank Home Banking part. Installed during the installation of the software necessary to run the Home Banking. According to Fortis Bank this will not in any way be harmful to the system or relay system information
NGearboxconfsvr.exe"NTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available here"
UGetRight - Tray Icongetright.exe"Entry added with older versions of the GetRight download manager from Headlight Software
UGoBack Tray IconGBTray.exe"Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users
UGroupWise PDA Connect - 3CmPlmAutoDet.exe"3Com Palm PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
UGroupWise PDA Connect - GrpWseAgnt.exe"GroupWise PDA Connect PDA synchronisation utility - from Novell"
UGroupWise PDA Connect - PocketPCAUTODE~1.EXE"Windows Mobile Pocket PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
UGroupWise PDA Connect - ScheduleSyncSCHEDU~1.EXE"ScheduleSync specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
NGrpConvgrpconv.exe"Microsoft Windows Program Group Converter - used by installers (ONLY in the RunOnce keys) - provides the translation of groups and group items to folders and links. Also see this MS Knowledge Base article"
NGsiconexeGsicon.exe"ADSL modem monitor from Eicon Networks (as used by BT for its Broadband internet service for example). Can safely be disabled without affecting the connection - all this does is give an indication of connectivity and access to the diagnostic facilities"
Ygw port controllerPORTCT95.EXE"From a visitor - "I must keep it active in start up or my Lexmark printer and RCA Cam program cannot discover a working port to work". From the file properties
UH/PC Connection AgentWCESCOMM.EXE"Connection manager for Microsoft ActiveSync - mobile device synchronization software for Windows XP (and earlier)
XHard drive Controllerhdcontroller.exe"Added by the KIMAN.B WORM!"
UHawkEye IV Control PanelHAWK_32.EXE"Control Panel application for the old Number Nine graphics cards to change resolution
UHcontrolhcontrol.exeHotkeys on an ASUS Notebook. Only required if you use the additional keys
UHControlUserHControlUser.exeHotkeys on an ASUS Notebook. Only required if you use the additional keys
NHD Audio Control PanelRtHDVCpl.exe"Realtek HD Audio Manager
UHDDControlGuardHDDControlGuard.exe"Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
UHDDControlGuard.exeHDDControlGuard.exe"Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
YHPLJ ConfigSetConfig.exeConnects system to networked HP printer.
Xhpsysconf1[random filename]"Added by a variant of the VIVIA.A TROJAN!"
?HsuGuiControlHsuGuiControl.exe"Part of the Starband Internet satellite client. What does it do and is it required?"
XHvewsveqmgANACON.EXE"Added by the NACO.A WORM!"
XI/O Controllerssvcnet.exe"Added by the TIBIK-B TROJAN!"
XICcontroliccontrol.exe"ICcontrol premium rate adult content dialer"
NIcon AnimationHDE.EXEPart of McAfee Nuts & Bolts. Provides entertaining animation of your desktop icons
NIcon Hearit 95hearit95.exeAudio desktop customization utility from Moon Valley Software. Resource hog
NIcon Hearit 98hearit98.exeAudio desktop customization utility from Moon Valley Software. Resource hog
XIcon lptt01icon.exe"RapidBlaster variant (in a ""Icon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XIcon ml097eicon.exe"RapidBlaster variant (in a ""Icon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Yiconcacheicon.bat"Related to the Vista Customization Pack"
YICONCLNTiconclnt.exe"APC PowerChute® Personal Edition tray icon"
UICONDESKICONDESK.EXESmall utility which will allow you the option of hiding or showing your desktop icons
NIconfig.exeIconfig.exeIcon for LS-120 "Superdisk"
XiConfigLoaderDIIhost.exe"Added by the GAOBOT.AO WORM!"
NIconoidIconoid.exe"Iconoid is a desktop icon manager"
NIconsaverIconsaver.exe"IconSaver is a desktop icon manager"
Xicrosof Avps32 Controlav32.pif"Added by the RBOT-AVC WORM!"
Xicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AER WORM!"
Xicrosoftf Avpx Controlavpx.exe"Added by the RBOT-AYN WORM!"
XIE configureexplorer.exe"Added by the LINEAGE-C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!"
XIMEconime.exe"Added by the DLDR-G TROJAN! Note - this is not the legitimate Console IME process of the same filename which is located in %System%. This one is located in %Windir%"
UImgIconImgIcon.exe"Displays Iomega icons in Explorer/My Computer
NInControl Desktop ManagerDMHKEY.EXEFor Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start -> Programs
?InetConfinetconf.exe"??"
UInstant Wireless Configuration UtilityWUSB11cfg.exe"Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
UInstant Wireless Configuration UtilityWPC11Cfg.exe"Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
NIntel PROSet Tray Iconpromon.exeSystem Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features
XIntel Service Driversmsconfig16.exe"Added by the MSCONFIG16 TROJAN!"
UIntelZeroConfigZCfgSvc.exe"Zero Config MFC Application
XInternat Confbootconf.exe"Homepage hijacker
XInternet Configsvchosts.exe"Added by the SDBOT TROJAN!"
XInternet Connection Wizardstisvsq.exe"EasySearch adware"
XInternet Connection Wizard[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XInternet Connection Wizardstisvsq1.exe"Added by the DLOADR-AWD TROJAN!"
XInternet Content PublisherICP.EXE"Added by the RBOT-UD WORM!"
XInternet Explorer ConfigurationIEXPLORE.EXE"Added by the SDBOT-UL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Protocol Configuration Loaderipcl32.exe"Added by the SDBOT TROJAN!"
XInternetGetConnectedStatewinupdate.exe"Added by the SDBOT-JN WORM!"
XInternetGetConnectedStateExwinupdate.exe"Added by the SDBOT-JN WORM!"
XInters Configuration LoaderRCL0ADERS.exe"Added by the SDBOT-KX WORM!"
UIomega Disk IconsIMGICON.EXE"Displays Iomega icons in Explorer/My Computer
UIomega Drive IconsIMGICON.EXE"Displays Iomega icons in Explorer/My Computer
UIomega ImIconXPimiconxp.exe"Iomega REV System Software - allows your Iomega REV drive to interact with the operating system via the Iomega REV UDF file system
XIPC Connectionipcconn.exe"Added by the RBOT-AEG WORM!"
XIPConfigsvcxnv32.exe"Added by the HACARMY.E TROJAN!"
XIPConfigsvcxnw32.exe"Added by a variant of the HACARMY.E TROJAN!"
XIPConfigipconfigs.exe"Added by the HACARMY.C BACKDOOR!"
XIpCtrlipcon32.exe"Added by an unidentified VIRUS
XIPSEC Configurationwsupdate.exe"Added by the AGOBOT-IQ WORM!"
XIPTable ConfigurationWinipcfgs.exe"Added by a variant of the RBOT WORM!"
NIW ControlCenteriwctrl.exe"Pinnacle Systems InstantWrite enables you to use your CD-R
UIW_Drop_Iconiwctrl.exe"Pinnacle Systems InstantWrite enables you to use your CD-R
XJA Config 32Awesome32.exe"Added by a variant of the SDBOT WORM!"
XJava32 Configuration Loadermsnmesgr.exe"Added by a variant of the RBOT WORM!"
UJMB36X ConfigureJMRaidTool.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
YJMB36X ConfigureJMRaidSetup.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
UJOYTECH USB Neo S ControllerJoytechNeoSTrayIcon.exe"System Tray access to Joytech Neo S PC gamepad controller software"
XKernelConfigdestiny32.exe"Added by the AGOBOT.AMB WORM!"
?KYE_Showiconshwicon.exe"Card reader for memory cards from digital cameras. Is it required? "
XKYK Control SettingsKYSVCXD.EXE"Added by a variant of the RBOT WORM!"
XKYM Control Settingsphqghum.exe"Added by the RBOT.BQD WORM!"
NLaunch Context 5.0Launch.exe"Context - electronic dictionary"
?LCIDConfiglcidchng.exe"??"
NLightscribeLightScribeControlPanel.exe"System Tray access to the LightScribe Control Panel for CD/DVD writers based upon HP's LightScribe laser-etching process - which allows you to burn a label straight onto specially coated blank disks. Part of the main LightScribe System Software (LSS)"
NLightScribe Control PanelLightScribeControlPanel.exe"System Tray access to the LightScribe Control Panel for CD/DVD writers based upon HP's LightScribe laser-etching process - which allows you to burn a label straight onto specially coated blank disks. Part of the main LightScribe System Software (LSS)"
NLightScribeControlPanelLightScribeControlPanel.exe"System Tray access to the LightScribe Control Panel for CD/DVD writers based upon HP's LightScribe laser-etching process - which allows you to burn a label straight onto specially coated blank disks. Part of the main LightScribe System Software (LSS)"
NLIURubicon.exe"Logitech Internet Update. Used to update drivers/software for Logitech's Wingman
XLocal Internet ConnectionLIC.exe"Added by the SDBOT-YA WORM!"
XLogitech DesktopIPCONN.EXE"Added by the SDBOT-WE WORM!"
XLogitech Desktop Controllerwrcam.exe"Added by a variant of the RBOT WORM!"
NLogitech Desktop Messengerldmconf.exe"Installed with older versions of the software for Logitech products. Configures the options for Logitech Desktop Messenger to activate notifications about software upgrades and/or new products
NLogitech Desktop Messenger Agentldmconf.exe"Installed with older versions of the software for Logitech products. Configures the options for Logitech Desktop Messenger to activate notifications about software upgrades and/or new products
NM-Audio Delta Taskbar IconDeltTray.exeM-Audio Delta Control Panel for M-Audio brand Delta series audio cards. System Tray access to audio settings - available through Control Panel
UM-Audio MobilePre Control Panel LauncherMPTask.exe"Control Panel Launcher for MobilePre USB bus-powered preamp and audio interface from M-Audio"
UM-Audio Taskbar IconDeltaIITray.exe"System Tray access to the Delta Control Panel for the M-Audio Delta series of PCI audio cards"
XM1cr0s0ft S3rcuritysystemconfig.exe"Added by the RBOT.BKB WORM!"
NMatrox Color Controlhgcctl95.exeFor Matrox video cards. Quick access to changing colors
NMatrox Control Centermgactrl.exeFor Matrox video cards. Quick access to settings
XMCMAGICON.EXE"Added by the MAGICON.A TROJAN!"
UMCI USB IconUSBIcon.exeMCI USB software used for managing a USB card reader
UMediafour XPlay Tray Notification IconXptryicn.exe"Mediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod"
UMediafour XPlay Tray Notification IconXptryicn.exe"Xplay 2 from Mediafour Corporation - ""expands what you can do with any iPod
XMeeting Connectioncomsutil.exe"Added by the PPDOOR-E TROJAN!"
XMeeting Connectionwowdache.exe"Added by the PPDOOR-D TROJAN!"
XMeeting Connectionhgakdl32.exe"Looks like a variant of the PPDOOR-E TROJAN!"
XMemConfigSetupIE.com"Added by the TAPLAK WORM!"
XMessenger Sharing Controlmnwsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicro Processappconf.exeAdded by an unidentified WORM or TROJAN!
XMicroMix32WinCon.exe"Added by the VB-ECC TROJAN!"
XMicrosft Conf 32msaconf.exe"Added by the RBOT.EYA WORM!"
XMicrosft Confige 32msaconfigurez.exe"Added by the RBOT.CLC WORM!"
XMicrosoft (R) Windows Configuration Backup Servicesvchost.exe"Added by the RANKY.X TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in either a ""config""
XMicrosoft (R) Windows Network Latency Controller1.tmp"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Latency Controllernlc.exe"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Latency Controllersp2vc.exe"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Protected Content Restoration Serviceservices.exe"Added by the AGENT.AGV BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\etc"
XMicrosoft .NET Confinguratormsnconf.exe"Added by an unidentified VIRUS
XMicrosoft Anti Virus Controllermsavc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Anti Virus Controllermsavc32.exe"Added by the SDBOT.EPW BACKDOOR!"
XMicrosoft Conf Ldrsysconf.exe"Added by a variant of the SDBOT TROJAN!"
XMicrosoft ConfgKeyswurmgrd32.exe"Added by the RBOT-ARX WORM!"
XMicrosoft Configmsconf.exe"Added by the RBOT.PV WORM!"
XMicrosoft ConfigMSCONF.EXE"Added by the RBOT-LG WORM!"
XMicrosoft Config 32msconfigx32.exeReported as the MSCONFIGX32 TROJAN! Possible Rbot variant
XMicrosoft Config 32bitmscnfg32.exe"Added by the RBOT-Z WORM!"
XMicrosoft Config Fileconfig.exeAdded by the KILLFILES.GR TROJAN! This is malware that will attempt to delete all system dlls!
XMicrosoft Config Loadermsconfig32.exe"Added by the AGOBOT.XX WORM!"
XMicrosoft Config Loadermsrun32.exe"Added by the AGOBOT-DY WORM!"
XMicrosoft Config Loadermsconf32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Configoration Servicemsconfigs.exe"Added by the RBOT-ETT WORM!"
XMicrosoft Configs 32msgconfigrs.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Configuewemsconfiguwe.exe"Added by the SDBOT-BPK WORM!"
XMicrosoft Configurationmsconfig32.exe"Added by the SDBOT.MQ WORM!"
XMicrosoft Configuration 35microsot1.exe"Added by an unidentified TROJAN!"
XMicrosoft Configuration Wizardtaskmrg.exe"Added by the SDBOT-MX TROJAN!"
XMicrosoft Configure 32msgconfigre.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Connection Manager Monitorcmmon.pif"Added by the RBOT-AKV WORM!"
XMicrosoft Control Centercrtl.exe"Added by the RBOT-VX WORM!"
XMicrosoft DDE Controlwupades.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft DDEs ControlErun.pif"Added by the RBOT-AMU WORM!"
XMicrosoft Debug Manager Consolemdm32.exe"Added by the AGOBOT-AQ WORM!"
XMicrosoft DLL Verifiermscon.exe"Added by the SDBOT.EAH WORM!"
XMicrosoft Domain Controllermstc.exe"Added by the NUGACHE.A WORM!"
XMicrosoft Driver Controlwindrv.exe"Added by the SDBOT.FW WORM!"
XMicrosoft DriversWSconf.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Java Virtual MachineMsConfiG.exe"Added by the FORBOT-DV WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
XMicrosoft Management Consolelssas.exe"EasySearch adware"
XMicrosoft Management Console[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XMicrosoft Management Consolelssas1.exe"Added by the DLOADR-AWD TROJAN!"
XMicrosoft Messenger Management Controlsmsmgmctl.exe"Added by the RBOT-APA WORM!"
XMicrosoft Network Services Controllermmsvc32.exe"Added by the NANPY-A WORM!"
XMicrosoft Officemsoicons.exe"Added by the RBOT-ZI WORM! - NOTE - do no confuse with the legitimate Msoicons.exe file described here. The latter wil not be listed among your startups!"
XMicrosoft PC Health Remote Assistance File Open & Save controlssfrcdlg32.exe"Added by the RBOT-AVY WORM!"
XMicrosoft RDLLsysconf32.exe"Added by a variant of the SDBOT TROJAN!"
XMicrosoft sddcE Contoltaskmnegr.exe"Added by the RBOT-AUM WORM!"
XMicrosoft sddcE Contoltaskmn.exe"Added by the RBOT-BJZ WORM!"
XMicrosoft Security Controlersfxsecues.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Service Controllerservices.exe"Added by the KALEL-D WORM! Note - this is not the legitimate services.exe process
NMicrosoft Sidewinder Game Controller SoftwareSWTRAY.EXEMS SideWinder game controller system tray icon. Available via Start -> Programs
NMicrosoft System Configuration Utilitymsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
XMicrosoft System DLL Services Configurationwindir32.exe"Added by the SDBOT-ACY TROJAN!"
XMicrosoft System Restore ConfigurationCBRSS.EXE"Added by a variant of the SPYBOT WORM!"
XMicrosoft Task Messenger Configtaskmgsr.exe"Added by the SDBOT-JK WORM!"
XMicrosoft TCP/IP Connection Monitorsvchost32.exe"Added by the RBOT.KS WORM!"
XMicrosoft Updatemsconfg.exe"Added by the RBOT.H WORM!"
XMicrosoft Update Clinicsvsipconfig.exe"Added by the RBOT.BR WORM!"
XMICROSOFT UPDATE CONFIGURATIONWIN32SNC.EXE"Added by the RBOT-AI WORM!"
XMicrosoft Update ControlMs64.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update MachineMSOICONS.EXE"Added by the RBOT.AWS WORM! Note - do no confuse with the legitimate Msoicons.exe file described here. The latter should not normally figure in Msconfig/Startup!"
XMicrosoft Updatermsconsole.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Updaterssysconfigs.exe"Added by the RBOT-DF TROJAN!"
XMicrosoft Video Capture ControlsMSsrvs32.exe"Added by the SDBOT-AAK WORM!"
XMicrosoft Video Controlstskmsgr.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Windows Config 32win32conf.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Controlmswctl32.exe"Added by the RBOT.JP WORM!"
XMicrosoft Windows DLL Services Configurationnewdll.exe"Added by the SDBOT-ZR WORM!"
XMicrosoft Windows DLL Services Configurationnewdll2.exe"Added by the SDBOT-ABD WORM!"
XMicrosoft Windows DLL Services Configurationpoker.exe"Added by the SDBOT-ZY WORM!"
XMicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AAH WORM!"
XMicrosoft Windows DLL Services Configurationproxy.exe"Added by the SDBOT-ZL WORM!"
XMicrosoft Windows DLL Services Configurationwindir32.exe"Added by the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindir32a.exe"Added by a variant of the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindll32.exe"Added by the SDBOT.BHD WORM!"
XMicrosoft Windows DLL Services ConfigurationwinDSL.exe"Added by the SDBOT-ZG WORM!"
XMicrosoft Windows DLL Services Configurationdllmanager32.exe"Added by the SDBOT-BTU WORM!"
UMicrosoft Windows Media Player Network Sharing Service Configuration ApplicationWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XMicrosoft Windows XP Configuration Loaderm32svco.exe"Added by the SDBOT.WORM!.48548 WORM!"
XMicrosoftf DDEs ContDLLrune.pif"Added by the RBOT-AGF WORM!"
XMicrosoftf DDEs ContrDLrunm.pif"Added by the RBOT-AFQ WORM!"
XMicrosoftf DDEs Controllxes.exe"Added by the RBOT.BOF WORM!"
XMicrosoftf DDEs Controlwees.exe"Added by a variant of the RBOT WORM!"
XMicrosoftf DDEs Controlsoff.pif"Added by the RBOT-AKH WORM!"
XMicrosoftf DDEs Controlwhy-.exe"Added by the RBOT-AMV WORM!"
XMicrosoftf DDEs Controlmsnn.exe"Added by the RBOT-AXT WORM!"
XMicrosoftf DDEs ControlFEnR.exe"Added by the RBOT-AIM WORM!"
XMicrosoftf DDEs Controlw33s.exe"Added by a variant of the RBOT WORM!"
XMicrosoftf DDEs Controlwaes.exe"Added by a variant of the RBOT WORM!"
XMicrosoftz turn Controlaexl.exe"Added by the SDBOT.BCO WORM!"
XMicrosoftz turn Controlread.pif"Added by the RBOT-AFS WORM!"
NMightyFAX ControllerMFNTCTL.EXE"Mighty FAX from RKS Software - "installs a printer driver so that you can fax directly from Windows software""
XMircrosoft Windows Config DLLrundllc32b.exe"Added by the RBOT-ZY WORM!"
NMobile Connectivity SuiteApplication Launcher.exe"System Tray access to the HTC Sync mobile phone management utility for models including the Hero
XModularConfigsyscnfg.exe"Added by an unidentified VIRUS
XMonContenuassistantGDC.exe"MonContenuassistant French rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XMoreContent"rundll32.exe MSA64CHK.dllDllMostrar"
XMotherboard ConfigAti2xxx.exe"Added by the RBOT-AIK WORM!"
UMotorola Desktop Suite mRouter ConfigmRouterConfig.exe"Configuration for Motorola's version of Intuwave's m-Router - ""that enables easy connectivity between mobile devices and PCs across Bluetooth
UmRouterConfigmRouterConfig.exe"Configuration for Intuwave's m-Router - ""that enables easy connectivity between mobile devices and PCs across Bluetooth
XMS Configmsdconfig.exe"Added by the RBOT-CZH WORM!"
XMS Config Loadersvchos1.exe"Added by the AGOBOT.R WORM!"
XMS Config LoaderMSWin32bck.exe"Added by the GAOBOT.AA WORM!"
XMS Config Loadersvcrhost.exe"Added by a variant of the RBOT WORM!"
XMS Config ServiceMsloader32.exe"Added by the RBOT-KJ WORM!"
XMS Config Streammsasm.exe"Added by the AGOBOT-BA WORM!"
XMS Config v12mscfg12.exe"Added by the AGOBOT.YP WORM!"
XMS Config v13lrbz32.exe"Added by the GAOBOT.AOL WORM!"
XMS Config v13mscfg13.exe"Added by the AGOBOT.YQ WORM!"
XMs configsumsconfigsu.exe"Added by a variant of the SDBOT WORM!"
XMS ConfigurationMSFramer.exe"Added by the RANDEX.OL WORM!"
XMs Configurationmicrosoftsa32.exe"Added by the KELVIR.X WORM!"
XMS Configuration Utilitymsconfig32.exe"Added by the WOOTBOT.DY WORM!"
?MS management consolemms.exe"Suspicious as the legitimate ""Microsoft Management Console"" is ""mmc.exe"" and not ""mms.exe"" and doesn't normally run at startup"
XMS Network Controlmswin.exe"Added by the DUMBA TROJAN!"
XMS Sound Config 16bitsndcfg16.exe"Added by the SDBOT.MB TROJAN!"
XMs System ConfigMscfg.exe"Added by the SDBOT-CCR WORM!"
XMs System Configpcedit.exe"Added by a variant of the SDBOT WORM!"
XMS-Connectarr.exe"Adult content dialler - see here"
XMS-Connectcdm.exe"Adult content dialler - see here"
XMS-Connectgame.exe"Adult content dialler - see here"
XMS-Connectmsite18.exe"Adult content dialler - see here"
XMS-Connectweb.exe"Adult content dialler - see here"
XMS-patchmsconfig32.exe"Added by the RBOT-AUF WORM!"
XMsconf32Msconf32.exe"Added by the AGOBOT-NR WORM!"
XMSCONFG32.EXEMSCONFG32.EXE"Added by the OPTIX.04.C TROJAN!"
NMSConfigmsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
XMSConfigMSCONFIG32.EXE"Added by the SPYBOT.B WORM!"
Xmsconfigmsconfig.exe"CoolWebSearch MSConfig parasite variant. Note - this overwrites the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
Xmsconfigmsconfig.exe"Added by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrun"
Xmsconfigwins.exe"Added by the RBOT.PF WORM!"
XMSConfigMSCONFIG35.EXE"Added by a variant of the SPYBOT WORM!"
Xmsconfigscvhost.exe"Added by the AGENT-DSF TROJAN!"
Xmsconfigwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
XMsconfigicpldrvx.exe"Added by the BANLOAD.BFT TROJAN!"
Xmsconfigmsconfig.com"Added by the IRCBOT-SM WORM!"
Xmsconfigmsconfig.bat"Added by the PAHATIA.B WORM!"
XMSConfiglssas.exe"Added by the AUTORUN.CEY WORM!"
XMSConfigxwpwqf.exe"Added by the AGENT-NEW TROJAN!"
XMsconfig lptt01msconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
XMSConfig Managermsupdate.exe"CoolWebSearch parasite variant"
XMsconfig ml097emsconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
Xmsconfig serviceMSupdate32.exe"Added by a variant of the SPYBOT WORM!"
Xmsconfig.msconf.exe"Added by the BUZUS-AY WORM!"
Xmsconfig.exeproxy.exeAdded by a variant of the AGENT.AH downloader TROJAN!
Xmsconfig.exeuline.exeAdded by a variant of the AGENT.AH downloader TROJAN!
Xmsconfig38mssvcc.exe"Added by the RBOT-BJV WORM!"
XMSConfig45MSConfig45.exe"Added by the SDBOT.OJ TROJAN!"
XMSConfigrjdbgmrg.exe"Added by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here"
NMSConfigRemindermsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. This particular entry is specific only to 98/Me and is located in %System%
XMsConfigsMsConfigs.exe"Added by the ALCAN.A WORM!"
XMSConfigsRUNDLL64.dll.vbs"Added by the WEKODE-B WORM!"
Xmsconfiguratorctfsdk.exe"Added by the DELF-ALS TROJAN!"
XMSControl28crsss.exe"Added by the SPYBOT.AJX WORM!"
XMSControl31winnsyst.exe"Added by the RBOT.CFY WORM!"
XMSControl3d1isasse.exe"Added by the RBOT.CGU WORM!"
Xmsdevmsconfig.exe"Added by the AGOBOT.AAU WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
Xmsdev controlmsdevctrl.exe"Added by the SPYBOT.N BACKDOOR!"
XMSFTP Service Configr3grun.exe"Added by a variant of the SDBOT WORM!"
XMSI Configurationmsiconf.exe"Added by the AGENT.AKSZ TROJAN!"
Xmsiconf.exemsiconf.exeAdded by a variant of the FAKEALERT TROJAN!
XMsn Configmsngf.exe"Added by the RBOT-QG WORM!"
XMSN Configurationmsnconfig.exe"Added by a variant of the IRCBOT TROJAN!"
XMsn Configuration Loadermsngms.exe"Added by the KELVIR.T WORM!"
XMSN Configuration Loadermsmsncfg.exe"Added by the AGOBOT-KX BACKDOOR!"
XMSN File Configurationmsnfilecfg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN Messenger User Controlsmsmsgr.exe"Added by the KELVIR.HI WORM!"
XMSN Updatemscon.exe"Added by the RBOT-QA WORM!"
XMSN UpdateDLLCON.EXE"Added by the RBOT-EA WORM!"
XMyContentAssistantGDC.exe"MyContentAssistant rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
UMyEmoticonsMYEMOTICONS.EXE"MyEmoticons from Persona Ltd - add icons (emoticons) to your E-mail"
NNAV Configuration Wizardcfgwiz.exe"Introduced with Norton Anti-Virus 2002
NNeroNETTrayIconNNServiceCtrl.exe"System tray access to NeroNET - Ahead Software's network-capable extension of their CD/DVD burning program. NeroNET allows a burner to be shared across a network"
XNet CoNNAntispy.exe"Added by the AGOBOT.ALK WORM!"
Xnetconfignetconfig.exe"Added by the NETWARE TROJAN!"
XNetwork Connectionsinternat.exe"Added by the VB-ZD TROJAN!"
XNetwork Host Controller[path to trojan]"Added by the WHISPER TROJAN!"
XNetworks ConfiguratorNetConfs.exe"Added by the RBOT-OX WORM!"
XNetworks ControlerNetsis.exe"Added by the RBOT-NG WORM!"
NNokia Connection MonitorNclConf.exe"Monitors the infrared port
UNotebookHardwareControlnhc.exe"""With Notebook Hardware Control you can easily control the hardware components of your Notebook"""
UNovaBackup * Tray ControlNbkCtrl.exe"Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here. * represents the version number"
Xnssysconf[random filename]"Added by the VIVIA.A TROJAN!"
XNvidia Control Daemonnksvc32.exeAdded by an unidentified WORM or TROJAN!
XNvidia Control Panelncsvc32.exe"Added by an unidentified VIRUS
UODSPConfigODSPConfig.exe"DsktopSurveil surveillance software. Uninstall this software if you did not install it yourself"
UOmega ASIO Control PanelASIOSysTray.exe"System Tray access to the control panel for the Lexicon Omega ASIO (Audio Streaming I/O) desktop recording studio"
YOrange Connection Kitatdialler1.exe"Part of the Orange Connection Kit - changes the dial-up for Orange Any Time if access problems are encountered"
XOS Boot Configurationbootconfig.exe"Added by the IRCBOT.HJ WORM!"
XOS Boot Configuration!bootconf.exe"CoolWebSearch BootConf adware"
XOutlook Express Config*****.exe [* = random char]"Added by a variant of the RBOT WORM!"
?Packard Bell EverSafe Tray ControlTrayControl.exe"Packard Bell EverSafe software. What does it do
?Palm MultiUser ConfigConfigtool.exe"MultiUser configuration for a Palm PDA device?. Is it required?"
NPaperQuote System Tray IconPQTRAY.EXEPaperQuote is a "wallpaper" changer with daily quotes that are either for inspiration or motivation
UParentalControlParentalControl.Exe"Crawler Parental Control - ""Get perfect control of websites your children browse
XPC-Config32corona.exe"Added by the CORONEX.A WORM!"
?PDF Converter Registry ControllerRegistryController.exe"Part of PDF Converter Professional version 2 from Scansoft (now Nuance). what does it do and is it required?"
?PDF4 Registry ControllerRegistryController.exe"Part of PDF Converter Professional version 4 from Scansoft (now Nuance). what does it do and is it required?"
?PDF5 Registry ControllerRegistryController.exe"Part of PDF Converter Professional and PDF Create (both version 5) - from Nuance. what does it do and is it required?"
?PDF6 Registry ControllerRegistryController.exe"Part of PDF Converter Professional version 6 from Nuance. what does it do and is it required?"
XPerforms peer to peer connectionWinPTTP.exe"Added by the RBOT-GMI WORM!"
UPestPatrol Control CenterPPControl.exe"PestPatrol Control Terminal - utility that launched PestPatrol features such as PPMemCheck and CookiePatrol before CA's acquisition"
UPhone Connection Monitoraudevicemgr.exe"Connection monitor part of the Sony Ericsson PC Suite mobile phone management utility for some models
NPocketCam 3Mega MonitorICON.exeInstalled with the Aiptek PocketCam 3Mega digital camera. Automatically invokes an import process if the camera is connected and has media on it
Upop3 Serverconfig.cfg"Part of HTML2POP3 - ""Convert Webmail to POP3.Is also included a SMTP/POP3 tunneling system that allow send and receive email in a private network HTTP PROXY based. All connection are plugin based. Over 250 email server supported and tested"""
UPowerTools Tray Iconpttray.exe"PowerTools - add-on for AOL"
YPP2000 Taskbar ControlPPTbc.exeProtector Plus anti-virus software - system tray access
UPPControlPPControl.exe"PestPatrol Control Terminal - utility that launched PestPatrol features such as PPMemCheck and CookiePatrol before CA's acquisition"
YPrevxOnePXConsole.exe"Prevx intrusion prevention software"
XPrivacyConductorGDC.exe"PrivacyConductor rogue privacy tool - not recommended
XProgramControlProgramControl.exe"Added by the DLOADR-BAG TROJAN!"
XProtectionConuepgs.exe"ProtectionConue rogue security software - not recommended. A member of the AVSystemCare family"
NPSIWin2.3 Connection ServerPsconsv.exeAllows connectivity between a PC and a Psion device. Access can be gained from the Desktop or Start -> Programs
UPspContrpspcontr.exeDriver/controller for the Philips SpeechMike 6174. As the Philips FreeSpeech application is no longer supported it can be disabled but the Mike can still be used for certain functions using this driver
UQchex Tray IconQchex.exe"Related to G7 Productivity Systems Check Software"
UQCWLICONQCWLICON.EXE"Part of IBM Access Connections - forerunner to the current ThinkVantage verison. Connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments
UQuick ControlsAstrotoolbar.exeGateway Astro Screen and Sound Controls tray icon
NRaConfig2500RaConfig2500.exe"RaLink wireless LAN configuration utility"
?RAMConnectionCheckerRAMConnChecker.exe"Part of Remote Access Manager (RAM) for Nortel Networks - which ""combines an intuitive
?RAMGINAConnWatchRAMConnWatcher.exe"Part of Remote Access Manager (RAM) for Nortel Networks - which ""combines an intuitive
XRasCon Remote Access Service Managerrasmngr.exe"Added by the SPYBOT.EM WORM!"
Ureadericonreadericon45G.exeTray icon to set various configuration settings for Sunkist (and maybe other) media card readers
?readericon10readericon10.exe"Related to a multimedia card reader - possibly based upon an Alcor Micro chipset. What does it do and is it required?"
XReg ServiceWinnConfig.exe"Added by the AGOBOT-PF WORM!"
XRegistryConfigrundll.exe"Added by the AGOBOT-KN WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
NRemote ControlRc.exeHinet Hi-Five ISP software
NRemote ControllerTVRMVCR.EXE"ProLink PlayTVpro TV tuner software"
URemote Data Backups TaskBar IconCBSysTray.exe"System Tray access to Remote Data Backups online system/data backup utility"
URemoteControlrmctrl.exe"Remote Control background application for Cyberlink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control
URemoteControlPDVDServ.exe"Remote Control background application for Cyberlink's PowerDVD version 5 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control
URemoteControl8PDVD8Serv.exe"Remote Control background application for Cyberlink's PowerDVD version 8. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control
NRoboFormRoboTaskBarIcon.exe"Roboform - password manager and web form filler. Will work without this startup entry
URun Nintendo Wi-Fi USB Connector Registration ToolNintendoWFCReg.exe"Related to Wi-Fi USB Connector from Nintendo"
Xrun=mouse_configurator.win"Added by the GAGGLE.E WORM!"
USabre Task Tray IconSabstart.exe"Part of the Sabre computer reservations system/global distribution system (GDS) - used by airlines
NSAClientRegCon.exe"AT&T or ComCast BBClient - monitors system and network-delivered services for availability. Your current network status is displayed on a color-coded web page in near-real time. When problems are detected
USaitekAutoConfiguresaicnfig.exe"Configuration for Saitek game controllers"
USametime ConnectConnect.exe"IBM Lotus Sametime - instant messaging and Web conferencing software"
USandboxieControlControl.exe"SandBoxie - allows data to be read from the hard drive by an application but never written back unless you allow it"
USandboxieControlSbieCtrl.exe"""SandBoxie runs your programs in an isolated space which prevents them from making permanent changes to other programs and data in your computer"""
NSandIconSandIcon.exe"SanDisk ImageMate CompactFlash card reader SDDR-31 (USB). Very little use except to place the Sandisk icon beside its drive designation in Windows Explorer. The reader itself will work fine without it. The simplest thing is to just unplug the reader when you're not using it. It may slow the startup by a few nanoseconds
NSBC Yahoo! Connection ManagerConnectionManager.exeUsed to create and connect your SBC Yahoo DSL connection. This program has been reported to cause problems for some users. If you find that it causes you pc to become slow or unstable you should uninstall it (using Add/Remove programs) and manually connect your DSL connection
XSchijfControleurGDC.exe"SchijfControleur Dutch rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
NScreen Saver ControlFSScrCtl.exeInstalls as part of the Hubble Space Telescope screen saver (and possibly others). Lets you control your installed screensavers from a System Tray icon
USecond Copy 2000SecCopy.exe"Related to Second Copy? - a files/folders backup utility"
USecondChancesctray.exe"Power Quest Second Chance. Sets checkpoints for saving a backup copy of the registry to a disk so you can restore it if you have a crash"
XSecurity CenterAppControl.exe"Added by the SDBOT.CFT WORM!"
NService Connectionsccenter.exeFor Compaq PC's. Part of Backweb
NService Connectionbwtray.exeFor Compaq PC's. Part of Backweb
XService Control Managerscm.exe"Added by the AGOBOT-GD BACKDOOR!"
XService ControllerCsrrs.exe"Added by the GAOBOT.AO WORM!"
XService Controllerservice.exe"Added by the PREVERT TROJAN!"
UServiceConfigispbeg.exe"Comcast Transition Wizard. On June 30th
Xserviceconnectserviceconnect.exe"Added by the AGOBOT.AIR WORM!"
XServices Controllerlsassa.exeAdded by the CIADOOR.122 VIRUS!
XServices Controllerservices.exe"Added by the CIADOOR-F TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
?ServUTrayIconServUTray.exe"System Tray icon for Serv-U FTP server. Is it required?"
NSetIconSetIcon.exe"Installed by a 6-in-1 (4 Media Card slots
NSetupICWDesktopicwconn1.exeAppears to be the "Internet Connection Wizard" from Internet Explorer being set-up as a desktop shortcut. Appears under the RunOnce registry key but is available under Start -> Programs -> Accessories -> Communication (or similar) anyway
XSevicewinconfig.exe"Added by the GIP.113.B1 TROJAN!"
XShedule Connectionarpo412.exe"Added by the PPDOOR-R WORM!"
?ShowIcon_Justrams_USB Product Driver v2.12r012shwicon.exe"Related to Just Rams USB product driver. Is it required?"
UShowIcon_PNY_PNY Attachéshwicon.exe"PNY Attaché USB flash memory stick System Tray icon - shows when the device is plugged in"
?ShowIcon_SmartDisk Corporation_USB Card Reader v1.14e051shwicon.exe"Card reader for memory cards from digital cameras. Is it required? "
UShowLOMControl[strange symbol]"Note that there is a strange symbol in the command field and in logs it's shown as ""O4 - HKLM\..\Run: [ShowLOMControl] [strange symbol]"". Additional registry information for the entry is ""Reg_DWORD 0x00000001 (1)"". It means Show ""LAN on Motherboard"" Control. On systems where you can install an external LAN interface
XSistema de Commconmsyrtl.exe"Added by the AGENT-LMV TROJAN!"
USmart Connect MonitorSCMon.exeAppears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio
USmart Connect SetupSCSetup.exeAppears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio
NSmileyconssmileycons.exe"Smileycons - free smileys
XSMSERIALWORKERSTARTshellexcon.exe"Added by the FAKEALERT-AH TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
NSnsiconSnsicon.exeLaunches a screensaver program from Second Nature
USoftany Monitor ControlMonitorControl.exe"Softany Monitor Control - ""control your computer's monitor and screensaver"""
NSonic A3D Controlvrtxctrl.exeSound related options
NSony Auto Update Tray ApplicationCONNECTAUTrayApp.exe"System Tray access to change update settings for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
Xsoundcontrlsoundcontrl.exe"Added by the GAOBOT.AFJ WORM!"
NSoundMAX Control PanelSmax4.exe"System Tray icon for Analog Devices SoundMax integrated soundcards. Sound properties can be accessed through the Start Menu or Control Panel"
USP2 Connection PatcherSP2ConnPatcher.exeChanges limit of concurrent TCP connections of Windows Service Pack 2
XSPOOL Configurationspoolsvc.exe"Added by the SDBOT-KD WORM!"
XSpools Service Controllerspools.exe"Added by the KASSBOT-C WORM!"
XSpy-ControlSpy-Control.exe"Spy-Control spyware remover - not recommended
USpyware Guard Control Panelspywareguardcp.exe"""SpywareGuard provides a real-time protection solution against spyware"""
XSQConfigCheckercc.exe"Xupiter SQWire toolbar related. Use Spybot S&D
XStartup Configuration[six character filename]"Added by the RBOT-ARV WORM!"
XStartup Configurationwztoid.exe"Added by the RBOT-ASD WORM!"
NStay Connected!StayCon.exe"More than just a pinger
Xstratasxmconfig.exe"Added by the RBOT-AHR WORM!"
XSun Java Console for Windows NT & XPjconsole.exe"Added by the VANEBOT-C WORM!"
USunkistshwicon98.exe"Card reader for memory cards from digital cameras
USunkist2kshwicon2k.exe"Card reader for memory cards from digital cameras
USunKistEMshwiconem.exe"Used by your computer to communicate with your Alcor Micro Multimedia Card Reader - necessary if you're using this software"
Xsvchost connection monitorsvchost32.exe"Added by a variant of the SDBOT WORM!"
XSvconrSvconr.exe"WaveRevenue-lBann adware"
XSVX Control Servicesvxhost.exe"Added by the FORBOT-K WORM!"
USX Virtual LinkConnect.exe"SX Virtual Link from Silex Technology America
XSymantec Configuration LoaderccApp32.exe"Added by the AGOBOT-EE WORM!"
Xsysconsyscon.exe"Added by the APRILCONE.A WORM!"
Xsyscon lptt01syscon.exe"RapidBlaster variant (in a ""Syscon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xsyscon ml097esyscon.exe"RapidBlaster variant (in a ""Syscon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xsysconfigiexplorer.exe"Added by the CULT.C WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XSysConfigsyscfg35.exe"Added by the KAZMOR.C WORM!"
XSysConfigwincfg32.exe"Added by the SDBOT.ZD WORM!"
USysconfigStealth KeySpy.exe"StealthKeySpy - keystroke logger/monitoring program - remove unless you installed it yourself!"
Xsysconfig32sysconfig32.exe"Added by the AGENT-MSP TROJAN!"
XsysPnPbootconf.exe"Homepage hijacker
XSystem ConfigBF3.EXE"Added by the SPYBOT-DT WORM!"
XSystem Configsysloadcnf.exe"Added by a variant of the SDBOT WORM! See here"
XSystem Config Bootsyscgboot.exe"Added by the AGENT.VWU TROJAN!"
XSystem Config Managercrss.exe"Added by the AGOBOT.GH WORM!"
XSystem Config Managersmssl.exe"Added by the AGOBOT-ZJ WORM!"
XSystem Configurationiexplore.exe"Added by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XSystem Configurationsyscfg32.exe"Added by the MYTOB.EA WORM!"
XSystem Configurator32SYSTEMCFG.EXE"Added by the AGOBOT-KS WORM!"
Xsystem configuresvchost.exe"Added by the LINEAGE-C TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XSystem Servicesconnection.exeAdded by an unidentified WORM or TROJAN!
XSystem Updatemssetupconf.exe"Added by the RBOT.DLC WORM!"
XSystem-Configmsptmf32.com"Added by the LIOTEN.FA WORM!"
XSystemCONF98iSystemCONF98i.exe"Added by the GLITCH TROJAN!"
XsystrasxCONSOLES.EXE"Added by the SDBOT-NW WORM!"
UT3ConsoleT3Console.exe"Related to T3 Security Suite - prevents unauthorized or inappropriate access to your PC and data"
UTaakcontroletaskmon.exe"Task Monitor (on Dutch language versions of Windows) - checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users
NTaskbar Display Controls"RunDLL deskcp16.dll QUICKRES_RUNDLLENTRY"
XTEXTCONVservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XTEXTCONVwinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
NThinkPad Configuration UtilityTP98TRAY.EXE"System Tray access to the ThinkPad Configuration utility for IBM/Lenovo ThinkPad notebooks. ""The ThinkPad Configuration utility is a control center to configure your ThinkPad hardware. With this utility
UThinkVantage Access ConnectionsACTray.exe"System Tray access to the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments
UThinkVantage Access ConnectionsACWLIcon.exe"Part of the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments
UTOSHIBA Volume IndicatorVolControl.exeOn-screen volume indicator for Toshiba notebooks
Xtotacontotacon.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
Utranicontranicon.exe"A Tweak-XP component (only in the registered version)
UTransparentIconstranicon.exe"A Tweak-XP component (only in the registered version)
YTray control for Malwarebytes' Anti-Malwarembamtrayctrl.exe"Malwarebytes' Anti-Malware - ""monitors every process and actually stops malicious processes before they even start. It uses our impressive technology that is in fact a completely novel way of heuristic scanning and it is our response to the increasingly complex malware threats"""
YTridentTVIcontvicon.exe"Trident Microsystems
UTrue Internet Color Iconinternetcolor.exe"Part of 3Deep® from E-Color (now superseded by 3DxWizzard™) - ""With True Internet Color PCs can display the best color possible over the web. Enabled web sites will know how connected monitors display color and will send them color corrected images"""
NTurbine Download Manager Tray IconTurbineDownloadManagerIcon.exe"Turbine Download Manager (TDM) - download manager associated with the game ""The Lord of the Rings Online™"""
UTV878 Remote ControlC7XRCtl.exe"Related to Kworld TV878 Tuner"
UU.S.Robotics WLAN Adapter Configuration UtilityUSRWLAN.exe"U.S.Robotics LAN Adapter - wireless LAN (WLAN) configuration utility"
UUberIconUberIcon Manager.exe"Uber Icon by Punk Labs. Creates a more customizable atmosphere on your desktop by extending Windows to perform new effects when you launch your icons and folders"
NUpConfgVerUpgConf.exe"Part of Panda Antivirus and Internet Security. Purpose unclear
XUpdate32configs.exe"Hijacker
XUSB controllerSvcmm32.exeSvcMM backdoor parasite downloader
XUSBConfigration2wmmndir.exe"Added by the AGOBOT-SV WORM!"
XUsrManagementConfumcss.exe"Added by the IRCBOT-W TROJAN!"
XVagiconlinevadaSq.exe"Added by the SDBOT-TD WORM!"
UVenturi Configuratorventcfg.exe"Venturi Wireless mobile broadband configuration utility"
UVeo Velocity Connectstim11.exeSupport software for the Veo Velocity Connect webcam
NVerizon Control Padcpad.exe"Control Pad - installed with Verizon DSL accounts. Tool designed to streamline the online experience"
XVideo Processsysconf.exe"Added by the GAOBOT.GEN!POLY or GAOBOT.UM or GAOBOT.ADX WORMS!"
XVideo Processormsconfsys88.exe"Added by the AGOBOT-QG WORM!"
UViewpointPhotosDeviceConnectFotomatDeviceConnect.exe"Related to Viewpoint which is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything ""bad"". This will change from what we know in 2006 according to this article. You can remove it via Start -> Settings -> Control Panel -> Add/Remove Programs list..."
YVistaFirewallControlVistaFirewallControl.exe"Vista Firewall Control from Sphinx Software (forerunner to Windows 7 Firewall Control) - ""Protects your applications from undesirable network incoming and outgoing activity
?VMConsole.exeVMConsole.exe"Sony VAIO Media Console - installed on the VAIO Media Integrated Server PCs. What does it do and is it required?"
XVolume ControllerVolumeControl.exe"Added by the SDBOT.AYI WORM!"
XVolume Shadow Configurationvbmsvc.exe"Added by the SLENFBOT.DH WORM!"
XVSP32 Controlsvsp32.exe"Added by the RBOT-VA WORM!"
XW32.Formalin.BetaPocong.exe"Added by the SILLYFDC WORM!"
NWar FTPD Tray Iconwartray.exe"War-ftpd - FTP server"
XWelcomewinconfig.exe"Added by the GIP.113.B1 TROJAN!"
XWelcomeCONFIG.EXE"Added by the PSWGIP.B TROJAN!"
XWifi Configurationwificonfig.exe"Added by the IRCBOT.AWB BACKDOOR!"
XWifi Configuration!wificonfigs.exe"Added by the IRCBOT.AWB BACKDOOR!"
XWifi Connectionwificon.exe"Added by the SLENFBOT.AC WORM!"
XWifi Connection!wificonnect.exe"Added by the IRCBOT.XEL BACKDOOR!"
XWin Configwinconfig.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWin32 Cnfg32msconfgh.exe"Added by the MYTOB.NB WORM!"
XWin32 Configurationvideosd32.exe"Added by the SDBOT.TT WORM!"
XWin32 Configurationdllhelp.exe"Added by the SDBOT.UL WORM!"
XWin32 Configurationmplayer.exe"Added by the FORBOT-BZ WORM!"
XWin32 Consolecmd.exe"Added by the ABI.C WORM! Note - this is not the legitimate cmd.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWin32 Securemsconfigsvc.exe"Added by a variant of the SDBOT WORM!"
XWin32 Services Configwinwkys.exe"Added by the RBOT.BKY WORM!"
XWinConfig9324wincfgkop9.exe"Added by the RBOT.BVD WORM!"
Xwinconnvbrun6nt.exe"Added by the AGOBOT-AEI BACKDOOR!"
XWindow UDP Control Servicwinlogon.exe"Added by the RBOT-GXN WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows AdControlWinAdCtl.exeWindupdates adware variant
XWindows Anti Virus Control Centeravrscan.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Anti Virus Control Centerwinavscan.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows API Control Taskapitsk32.exe"Added by the MYTOB.HI WORM!"
XWindows Audio Controlppnsvc.exe"Added by the HAM TROJAN!"
XWindows Backup ConfigurationIEXPLORER.exe"Added by the GAOBOT.AZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XWindows Confwindowsconf.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows ConfigSSYS.EXE"Added by the SPYBOT-DA WORM!"
XWindows Configwins.exe"Added by the SPYBOT.JR WORM!"
XWindows ConfigRUNDLL.EXE"Added by the SPYBOT-DX WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XWindows Configpvphost.exe"Added by a variant of the SLAPER TROJAN!"
XWindows Configwinconfig.exe"Added by the IRCBOT.BAP BACKDOOR!"
XWindows ConfigZANBOR.EXE"Added by the SPYBOT-MH WORM!"
XWindows Config Connectionmsicll.exe"Added by the RBOT-EXQ WORM!"
XWindows Config LoaderWincfg32.exe"Added by the SILVERFTP TROJAN!"
XWindows Config Managerwinconf.exe"Added by the RBOT-AIT WORM!"
XWindows Config ManagerWincfgman32.exe"Added by the AGOBOT-AL BACKDOOR!"
XWindows Config Systemconfig.exe"Added by a variant of the SDBOT WORM!"
XWindows Configurationwsys32.exe"Added by the GAOBOT.FB WORM!"
XWindows Configurationwincfg32.exe"Added by the MYTOB.ED WORM!"
XWindows ConfigurationWINHUB.EXE"Added by the SPYBOT-CG WORM!"
XWindows Configuration Loaderasclt.exe"Added by the SDBOT-OA WORM!"
XWindows Configuration Loadermsgfix.exe"Added by the SDBOT-NP WORM!"
XWindows Configuration SystemIExplore.exe"Added by the RBOT-DDG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Configuration Utilitywinxupdate.exe"Added by the AGOBOT.LW WORM!"
XWindows Configuratorwinconf.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows connection managerInternet.exe"Added by the RBOT-APN WORM! Note - file is found in the Windows or Winnt folder. Make sure you check the link on this one
XWindows Consolewkssvc.exe"Added by the SDBOT-DJX WORM!"
XWindows Console Componentwrasvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Console Monitor[path to worm]"Added by the KEDEBE WORM!"
XWindows Console MonitorgcasAV32.exe"Added by the KEDEBE-A WORM!"
XWindows Console Normswnbsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Console Sourcewnbsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows ControlControl.exe"Added by the GREK.A TROJAN! If there is another file with the same file name in the Windows folder
XWindows ControlAdWinCtlAd.exeWindupdates adware variant
XWindows Controls Centerwinudmr.exe"Added by the LAMER.AA BACKDOOR!"
XWindows Default Configurationsvchost.exe"Added by the DLOADER-U TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XWindows Desktop Controlerwindesktop.exe"Added by the SDBOT-XH WORM!"
XWindows driver updateIpconfig32.exe"Added by the SDBOT-JV WORM!"
XWindows Firevall Control Crundll.exe"Added by the GAERTOB.A TROJAN!"
XWindows HTML file readerSysconf32.exe"Added by the NOOMY.A WORM!"
XWindows Icons Managerwicomgr.exe"Added by the RBOT-AIF WORM!"
XWindows IncontextInSearch.exe"PacerD_Media/Pacimedia.com/Z-Quest adware installer"
XWindows Installer 1msnconfig.exe"Added by the PURITYSCN.B TROJAN!"
XWindows Logical Connectionwcnsvc.exe"Added by the VIRUT.AO VIRUS!"
XWindows Manager ControlWINMUR32.EXE"Added by the AGOBOT-AR WORM!"
NWindows Media Connect 2WMCCFG.exe"Windows Media Connect from Microsoft - stream digital media files on your computer to digital media receivers (DMRs) that are connected to your home network"
XWindows Messanger Control Centersvchosl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Messanger Control Centersvhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Messanger Control Centerwinlogin.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Messanger Control Centerwinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Messanger Control Centerwinsys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Messenger Connectwmdsvc.exe"Added by the SLENFBOT.S WORM!"
XWindows More ChoiceTopContext.exe"ZQuest adware"
XWindows MSConfig Startup Loggerwinlog.exe"Added by the RBOT.BCU WORM!"
XWindows Network ControllerMqguard.exe"Added by the FORBOT-CL WORM!"
XWindows Network ControllerWinxPupd.exe"Added by the FORBOT-DK WORM!"
XWindows Network Controllerwinmms32.exe"Added by the FORBOT-ED WORM!"
XWindows Network Controllerwingmt.exe"Added by a variant of the SDBOT WORM!"
XWindows Network ControllerWin9x.exe"Added by the WOOTBOT.I WORM!"
XWindows Network Controllerwinmms32.exe.exe"Added by the FORBOT-ED WORM!"
XWindows Network ServiceMsconf32.exe"Added by a variant of the RBOT WORM!"
XWindows pack Control Centertaskmam.exe"Added by the TOMETA-J TROJAN!"
XWindows Recovery Consolerecovery.exe"Added by the RANSOM.FD WORM!"
XWindows Registry Controlwinreg.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Secure Connectionwinsc.exe"Added by the SDBOT.BTN WORM!"
XWindows Security Controlwuaucls.exe"Added by the FORBOT-V WORM!"
XWindows Service Controllerservices.exe"Added by the KALEL-B WORM! Note - this is not the legitimate services.exe process
XWindows Service Controller Agenttaksmgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Service Layerconfig.exe"Added by the RBOT.DDJ WORM!"
XWindows Spooler Control Serviceqwidh.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows SSL Secondary DriversSSL32Dr.exe"Added by the SDBOT.ASQ WORM!"
XWindows SYN Control Centerwinmnon32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows System ConfigurationSYSCFG16.EXE"Added by the WISDOOR-K TROJAN!"
XWindows System ConfigurationPasscfg16.exe"Added by the DOMWIS-E TROJAN!"
XWindows System ConfigurationWinfrw.exe"Added by the SOLUFINA TROJAN or the DOMWIS-J WORM!"
XWindows System Configurationwincfg.exe"Added by the AGOBOT.OP WORM!"
XWindows System ConfigurationWINCFG32.EXE"Added by the AGOBOT-TE WORM!"
XWindows System ConfigurationWinNeth.exe"Added by the RETHE-A WORM!"
XWindows System Configurationnether.exe"Added by the OPANKI-AB WORM!"
XWindows System ConfigurationWINSYS32.exe"Added by the SDBOT.AXK WORM!"
XWindows System Managersysconf.exe"Added by the MYTOB.AL WORM!"
XWindows System Restore ConfigurationSblhost.exe"Added by a variant of the SPYBOT WORM!"
XWindows System-Control Driverssyscontrl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Controlwinudspm.exe"Added by a variant of the SDBOT WORM! See here"
XWindows UDP Control Centerauth.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control CenterehSched.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerfxstaller.exe"Added by the AGENT-IEE TROJAN!"
XWindows UDP Control Centerinstaller.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows UDP Control Centermsnmngs.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centermsnpd.exe"Added by the SDBOT.EBA BACKDOOR!"
XWindows UDP Control Centermswinudpmgr32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerscvhost.exe"Added by the PUSHBOT.EH WORM!"
XWindows UDP Control Centertaksmrg.exe"Added by the AGENT.WOH TROJAN!"
XWindows UDP Control Centertmps.exe"Added by the SDBOT.EBA BACKDOOR!"
XWindows UDP Control Centerwinlive32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwinmsn.exe"Added by the SDBOT.EBA BACKDOOR!"
XWindows UDP Control Centerwinrofl32.exe"Added by the LDPINCH-RZ TROJAN!"
XWindows UDP Control Centerwinudpmg.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwinudpmgrs.exe"Added by the DROPPER.CMV TROJAN!"
XWindows UDP Control Centerwinudpmsgr.exe"Added by the SDBOT.GAV WORM!"
XWindows UDP Control Centerwinupmgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwinuscn32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwksvcsc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwinudpmgr.exe"Added by the DLOADR-HQL TROJAN!"
XWindows UDP Control Centerfxsteller.exe"Added by the IRCBOT-J BACKDOOR!"
XWindows UDP Control Centermsnsmsgrs.exe"Added by the PUSHBOT.MF WORM!"
XWindows UDP Control Centerwinmgrs.exe"Added by the PUSHBOT.MY WORM!"
XWindows UDP Control Managerwinudpmgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Serviceswksvcsc.exe"Added by the ANTIAV-C TROJAN!"
XWindows Updatemsconfig32.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows update configsvhost.exe"Added by the SDBOT-PF WORM!"
Xwindows update configuratorsvghost.exe"Added by a variant of the SPYBOT WORM!"
Xwindows update configuratorexplore.exe"Added by the SDBOT.RY BACKDOOR!"
XWindows Update Controllermwoffice.exe"Added by the BATTRY-A TROJAN!"
XWindows USB Control Driveriexplore.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows USB controlerwinusb.exe"Added by the RBOT-HR WORM!"
XWindows Virus Controlplou.exe"Added by the SDBOT-ACZ WORM!"
XWindows Volume Controlongsvc.exe"Added by the SLENFBOT.DZ WORM!"
XWindows32 Configuration Loadermsrf32.exe"Added by the SDBOT-ABX WORM!"
YWindows7FirewallControlWindows7FirewallControl.exe"Windows 7 Firewall Control from Sphinx Software - ""Protects your applications from undesirable network incoming and outgoing activity
XWindows_Protectwincontrol32.exe"Added by the RBOT-ADK WORM!"
XWinDriver Configurationwindrvconf.exe"Added by the AGOBOT-LX TROJAN!"
XWindws Configuration LoaderLEXPLORE.exe"Added by the SODABOT WORM!"
NWinFax PRO ControllerWFXCTL32.EXEFrom WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
Xwinrunmsconfig.exe"Added by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrun"
XWinsock2 LoaderWICONF.EXE"Added by the SDBOT-LA WORM!"
XWinSpyControlpgs.exe"WinSpyControl rogue security software - not recommended. A member of the AVSystemCare family"
XWINTASKyahooicons.exe"Added by the MYTOB-HM WORM!"
Xwinupdateconn[path to file]"Added by the COMBRA-A WORM!"
Xwinupdateconn_Explorer.EXE"Added by the COMBRA-B WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
Xwin_supp00.exeWin Const.exe"Added by the ASSASIN-H TROJAN!"
XWIP Config GUIWinipcfgs.exe"Added by the RBOT-CN WORM!"
XWireless ConectionsWireConnect.exe"Added by the SDBOT-VF WORM!"
UWireless Connection Managerwirelesscm.exe"Wireless adapter configuration utility for D-Link's range"
XWireless ConnectionsWIRECONNECT.EXE"Added by the SDBOT-VM WORM!"
NWireless Consolewcourier.exe"ASUS Wireless Console - installed alongside ASUS wireless components and provides additional configuration options for these devices"
NWireless Console 2wcourier.exe"ASUS Wireless Console - installed alongside ASUS wireless components and provides additional configuration options for these devices"
NWireless Console 3wcourier.exe"ASUS Wireless Console - installed alongside ASUS wireless components and provides additional configuration options for these devices"
UWireless PCI Card Configuration UtilityWMP11Cfg.exe"Utility used by the LINKSYS wireless PCI card (WMP11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
XWMI Standard Event Consumer - Scriptingscrcons32.exe"Added by the RBOT-GRD WORM!"
XWMI Standard Event Consumer - Scriptingscrcs.exe"Added by a variant of the RBOT-GRD WORM!"
NWOOTASKBARICONGestMaj.exe TaskbarIcon.exe"Wanadoo broadband ISP (now rebranded as Orange) taskbar icon - not required"
XWSAConfigurationwmon32.exe"Added by the GAOBOT.BAJ WORM!"
XWSAConfigurationsvchostt.exe"Added by the AGOBOT.ZT WORM!"
XWSAConfigurationrpcxmn32.exe"Added by the AGOBOT.ABG WORM!"
XWSAConfigurationwin32upd.exe"Added by a variant of the RBOT WORM!"
XWSAConfigurationdrrss.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWSAConfigurationwinlogon32.exe"Added by the AGOBOT-WC WORM!"
XWSAConfigurationntguard32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWSAConfigurationcsrsvcs.exe"Added by the AGOBOT.VI WORM!"
XWSAConfigurationwinmx32.exe"Added by the AGOBOT-JE WORM!"
XWSAConfigurationkernel32.exe"Added by the AGOBOT-KV WORM!"
XWSAConfigurationwinmon32.exe"Added by the AGOBOT.TM WORM!"
XWSAConfigurationmsnote30.exe"Added by the AGOBOT-KF BACKDOOR!"
XWSAConfigurationsyxtem32.exe"Added by the AGOBOT-MF BACKDOOR!"
XWSAConfigurationsvchostx.exe"Added by the AGOBOT-JV BACKDOOR!"
XWSAConfiguration1csass.exe"Added by the AGOBOT.WH WORM!"
XWSConfigurationspoolsc.exe"Added by the AGOBOT-HY WORM!"
XWsdata serviceWSconf.exe"Added by the SDBOT.ZU WORM!"
UWSEP Status+ConfigurationcontroldGUI.exe"User interface for the WatchGuard Security Event Processor (WSEP) Status/Configuration dialog box associated with the Firebox series of security products from Watchguard"
XWSSAConfigurationwmmon32.exe"Added by the AGOBOT-KC WORM!"
?xiconxicon.exe"Part of the IBM/XPoint Rapid Restore utility. What does it do and is it required?"
UxPlanetControlxPlanetControl.exe"Tool that displays a globe with current day/night zones and clouds on users desktop."
UXTNDConnect PCXCPCMenu.exe"XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts
UXTNDConnect PC - 3CmPlmAutodet.exe"3Com Palm PC specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts
UXTNDConnect PC - CasioOrgCasAgnt.exe"Casio Pocket PC specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts
UXTNDConnect PC - ErPhn2ErTray.exe"Sony Ericsson IrMC (Infrared Mobile Connectivity) phones and smartphones specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts
UXTNDConnect PC - LtNts4NtsAgnt.exe"(IBM) Lotus Notes 4 specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts
UXTNDConnect PC - MyPalmMPTray.exe"Palm OS specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts
UXTNDConnect PC - PocketPCAutoDetect.exe"Windows Mobile Pocket PC specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts
UXTNDConnect PC - ScheduleSyncSCHEDU~1.EXE"ScheduleSync specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts
UXtrem parental controlpcx.exeParentXtreme - surveillance software. Uninstall this software unless you put it there yourself
NYBrowserybrwicon.exeSBC Yahoo! Browser system tray icon
?ZDConfigZDConfig.exe"Related to various brands of Wireless USB LAN Adapter - what does it do and is it required?"
XZekio Startupscondll.exe"Added by the AGOBOT-AGD WORM!"
YZENRC Tray Iconzentray.exe"Part of Novell's ZenWorks - "Complete End-to-End Directory-enabled Network Management". Best left alone"
UZipDisk IconsIMGICON.EXE"Displays Iomega icons in Explorer/My Computer
X[random name]m?config.exe"PurityScan adware"
X[Randomly chosen existing folder name]_config.exe"Added by the ANTINNY-L WORM!"
X[username] config[path to trojan]"Added by the MOSUCK-H TROJAN!"
X[various names]control64.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]LOPTCON.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]sysconf16.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]typeconf.exe"Wareout - malware masquerading as a spyware and dialer remover"
X_svchost.consvchost.com"Added by the ERKEZ.C WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.