Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X(default)winlog.exe"Added by the RBOT-CVY WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X250kg250kg.exe"Added by the AUTORUN-TI WORM!"
XActiveX File Registration Servicefilereg.exe"Added by the RBOT-DVD WORM!"
?ADGADG.exe" SoundBlaster Audigy related?"
XAdobesysconfig.exeAdded by an unidentified WORM or TROJAN!
XAdobeReaderProwinslog.exe"Added by a variant of the RBOT WORM!"
XAdslTaskBarstaskmng.exe"Added by the RBOT-AXZ WORM!"
XAdvancedPrivacyGuardapg.exe"AdvancedPrivacyGuard rogue privacy program - not recommended
UAgere SoftModem Messaging AppletAGRSMMSG.exeInstalled with the drivers for internal software modems based upon Lucent/Agere Systems chipsets - required if you use the SoftModem Assistant to configure the modem
UAGRSMMSGAGRSMMSG.exeInstalled with the drivers for internal software modems based upon Lucent/Agere Systems chipsets - required if you use the SoftModem Assistant to configure the modem
YAirGCFGAirGCFG.exe"Driver and configuration utility for a number of wireless routers and adapters from D-Link"
YAirNCFGAirNCFG.exe"Driver and configuration utility for a number of wireless routers and adapters from D-Link"
YAirPlusCFGAirPlusCFG.exe"Driver and configuration utility for a number of wireless routers and adapters from D-Link"
Xalcomrg.exealcomrg.exe"Added by the SDBOT-DNT WORM!"
XALG.EXEiexplorer .exe"Added by the DEMOTRY-B WORM!"
YALiSndMgrALiSndMg.exeALi AC97 Sound driver
UAlwaysReady Power Message APPARPWRMSG.EXE"""Away Mode"" feature added with Update Rollup 2 for Windows XP Media Center Edition 2005 that allows the computer to appear off to the user while it continues to perform tasks that do not require user input
UAMSGAmsg.exe"Part of the IBM ThinkVantage Productivity Center. ""The Message Center sends automatic notification on ThinkVantage Technologies integrated with your system. Once you're online"""
XAnti-Virus Product Sync[unprintable character][3 characters]log.exe"Added by the KEDEBE.D WORM!"
XAntiMalwareGuardamg.exe"AntiMalwareGuard rogue security software - not recommended
XAntiSpywareGuardasg.exe"AntiSpywareGuard rogue spyware remover - not recommended
XAntiVirwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
UAntiWindowsMessengerAntiMsMsg.exe"Anti-Windows_Messenger is a small application that prevents Windows Messenger from remaining resident in memory"
XAol Configuration Loaderaimsng.exe"Added by the SDBOT-XE WORM!"
XAol Instant Messengeraolmsg.exe"Added by the KELVIR.AL WORM!"
XAPIMonmsreg.exe"Added by the DROPPER.Z TROJAN!"
UARPWRMSGARPWRMSG.EXE"""Away Mode"" feature added with Update Rollup 2 for Windows XP Media Center Edition 2005 that allows the computer to appear off to the user while it continues to perform tasks that do not require user input
?ASUS Camera ScreenSaverASScrProlog.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
UATISmartati2s9ag.exe"ATI's ""SMARTGART""
Xaudiocfg.exeaudiocfg.exeAdded by the VB.ATE WORM!
XaugmsgAUGMSG.EXE"Added by the SPYBOT-CO WORM!"
XAuto updatSysDebug.exe"Added by the FORBOT-BA WORM!"
XAuto WinUpdatetaskmrg.exe"Added by the RBOT-AFA WORM!"
XAutomatic Defrag Managerdefrag.exe"Added by the RBOT-AKE WORM!"
XBanyak_KerjaanTukang.exe"Added by the SILLYFDC.BDM WORM!"
YBCMDMMSGbcmdmmsg.exeBCM voicemodem driver. Required for dial-up if you have one of these modems
YBCMSMMSGBCMSMMSG.exeBCM voicemodem driver. Required for dial-up if you have one of these modems
YBDWizRegbdwizreg.exe"Configuration wizard for BitDefender internet security products. Only runs once the product has been installed. Guides you through the steps necessary to configure the BitDefender modules
YBGNewsAgentbgnewsag.exe"BullGuard antivirus updater"
YBitDefender 12bdwizreg.exe"Configuration wizard for BitDefender internet security products. Only runs once the product has been installed. Guides you through the steps necessary to configure the BitDefender modules
Nbldbubgbldbubg.exePart of Dell Alerts which provides customers with an update on latest updates for his/her system
UBlue Frogbluefrog.exe"Blue Frog by Blue Security Inc. - actively fights spam by posting complaints on the sites advertised by the spam you receive"
XBoot Configbootconfig.exe"Added by the FLOOD-EV TROJAN!"
XBoot Managerbootmng.exe"Added by a variant of the SPYBOT WORM!"
Uborzoiblg.exe"Borzoi surveillance software. Uninstall this software unless you put it there yourself"
XBregbreg.exe"BroadcastPC adware"
XBron-Spizaetussempalong.exe"Added by the BRONTOK-E WORM!"
YBTUSRBDGBtUsrBdg.exe"Used with a Mitsumi USB Bluetooth adaptor (and maybe others)"
YBTUSRBDGFBtUsrBdg.exe"Used with a Mitsumi USB Bluetooth adaptor (and maybe others)"
NBuildBUbldbubg.exePart of Dell Alerts which provides customers with an update on latest updates for his/her system
XcandynetTaskmsg.exe"Added by the RBOT-NA WORM!"
UCAPingCAPing.exeCitibank Citianywhere software
?CardScan AutoSyncCSyncCfg.exe"Related to the CardScan business card reader range of products. May be related to synchronization with E-mail software and mobile devices (see here)?"
Xcartaokilling.exe"Added by the DLOADER-QN TROJAN!"
XCasdvqwabmqnzkg.exe"Added by the RANDEX.BE WORM!"
XccEvtMrg.execcEvtMrg.exe"Added by the RBOT.GZ WORM!"
UCertificateRegistrationSafeSignCertReg.exeSafeSign Certificate Registration Utility for Microsoft Crypto applications
UCertRegcertreg.exe"Related to Gemplus Card Reader"
UCheck Messengercmesseng.exeCheck Messenger from Qchex.com - program that helps you manage the activity of your Qchex account. Qchex appear to be no longer in buisness
XClean Mgrcleanmg.exe"Added by the IRCBOT.BBO BACKDOOR!"
?CleanRegPathCleanReg.exe"Apparently Annex A ADSL modem related. What does it do and is it required?"
XCli Confgcliconfig.exe"Added by a variant of the SPYBOT WORM! See here"
XCLICONFGCLICONFG.EXE"Added by the OPASERV.T WORM!"
XClient Agentipxwping.exe"Added by the PPDOOR-N TROJAN!"
XClip Service Managerclipmg.exe"Added by the DELF.DXJ TROJAN!"
XCOMCFGcomcfg.exe"Added by the TOADCOM.A TROJAN!"
XConfgbootconfig.exe"Added by the VB-ERB WORM!"
XConfigwinconfig.exe"Added by the GIP.113.B1 TROJAN!"
XConfigCONFIG.EXE"Added by the PSWGIP.B TROJAN!"
NConfigServicesConfig.exePart of initial setup on a Compaq PC
XConfiguration LoaderWinreg.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loaderwincffg.exe"Added by the AGOBOT.A3 WORM!"
XConfiguration Loadermsg.exe"Added by the SDBOT.BT WORM!"
NConfiguration UtilityCONFIG.EXEControls linksys wireless connection. Available from the Desktop
NCPQDFWAGCpqDfwAg.exeFor Compaq PC's. Runs Compaq diagnostics on every boot
NCPQINKAGENTcpqinkag.exe"That is the Compaq Ink Agent for some inkjet printers
UCRBroadCastingCRBroadCasting.exe"CardReader2 from On Track Inovations Ltd. USB Card Reader"
Xcryptdlgcryptdlg.exeAdded by an unidentified TROJAN!
Xctflog managerctflog.exe"Added by the DONBOMB.A TROJAN!"
NCTXFIREGCTxfiReg.exeCreative Labs sound card driver related. It appears that it isn't required and maybe registration related
YD-Link Air USB UtilityAirCFG.exeD-Link Air USB wireless driver and configuration utility
YD-Link Air UtilityAirCFG.exeD-Link Air PCI wireless driver and configuration utility
YD-Link AirPlus GAirGCFG.exeD-Link Airplus G wireless router driver and configuration utility
YD-Link AirPlus XtremeGAirPlusCFG.exe"D-Link AirPlus Xtreme G wireless access point driver and configuration utility"
YD-Link D-Link DWA-125AirGCFG.exe"D-Link DWA-125 Wireless 150 USB adapter driver and configuration utility"
YD-Link D-Link RangeBooster N DWA-140AirNCFG.exe"D-Link DWA-140 RangeBooster N USB adapter driver and configuration utility"
YD-Link D-Link Wireless 108G DWA-120AirPlusCFG.exeD-Link DWA-120 Wireless 108G USB adapter driver and configuration utility
YD-Link D-Link Wireless 108G DWA-520AirPlusCFG.exeD-Link DWA-520 Wireless 108G desktop adapter driver and configuration utility
YD-Link D-Link Wireless G DWA-110AirGCFG.exeD-Link DWA-110 Wireless G USB adapter driver and configuration utility
YD-Link D-Link Wireless G DWA-510AirGCFG.exeD-Link DWA-510 Wireless G desktop adapter driver and configuration utility
YD-Link D-Link Wireless N Dual Band DWA-160AirNCFG.exe"D-Link DWA-160 Xtreme N Dual Band USB adapter driver and configuration utility"
YD-Link D-Link Wireless N DWA-130AirNCFG.exe"D-Link DWA-130 Wireless N USB adapter driver and configuration utility"
YD-Link D-Link Xtreme N Dual Band DWA-160AirNCFG.exe"D-Link DWA-160 Xtreme N Dual Band USB adapter driver and configuration utility"
YD-Link RangeBooster G WDA-2320AirPlusCFG.exe"D-Link WDA-2320 RangeBooster G desktop adapter driver and configuration utility"
YD-Link RangeBooster G WUA-2340AirPlusCFG.exe"D-Link WUA-2340 RangeBooster G USB adapter driver and configuration utility"
YD-Link Wireless G WDA-1320AirGCFG.exe"D-Link WDA-1320 Wireless G desktop adapter driver and configuration utility"
YD-Link Wireless G WUA-1340AirGCFG.exe"D-Link WUA-1340 Wireless G USB adapter driver and configuration utility"
NDACONFIGEXEdaconfig.exe3Com NIC Diagnostics. Available via Start -> Programs
UDBISQL9dbisqlg.exe"Related to SQL Anywhere from Sybase. A comprehensive package providing data management and data exchange technologies"
XDebuggerexplorer32dbg.exe"Added by the CWS-M TROJAN!"
XDebuggeriexplore_dbg.exe"Added by the CWS-M TROJAN!"
NDeskflagDeskflag.exe"DeskFlag - animated USA flag on the desktop"
?Devlogdevlog.exe"Apparently mainboard/chipset related
XDiam prlaeroqedrhg.exe"Added by the SDBOT-DEU WORM!"
NDigital Line DetectDLG.exeDetects whether your are plugged into a digital telephone line and displays the information graphically. Installed by Dell (and maybe others) and is included with all Connexant V.92 and Broadcom modems
XDirectX9 Diagdx9diag.exe"Added by the RBOT-ALT WORM!"
?discovegdiscoveg.exe"??"
NDisknagdisknag.exeDell program that reminds you to make your backup diskettes
Xdjdsdvqwavjdhdg.exe"Added by the SDBOT-EF BACKDOOR!"
Xdllregdllreg.exe"Added by the CRYPTER.A TROJAN!"
NDNS7reminderEreg.exe Ereg.ini"Registration reminder for versions of Nuance (ScanSoft) Dragon NaturallySpeaking"
XDNSCacheBoostdnsping.exe"Added by the DNSBUST-A TROJAN!"
?Doingdoing.exe"??"
XDot1XCfgDot1XCfg.exe"Added by the AGOBOT.EA TROJAN!"
NDPConfigDPConfig.exe"Compuware DevPartner Studio Configuration Utility
NDXDllRegExedxdllreg.exe"Created when you select ""Yes"" to check the ""WHQL Digital signatures"" in the DirectX9 files at the first time you open it"
NE-Color RegistrationSonnReg.exe"Registration for Colorific® and 3Deep® monitor calibration sofware from E-Color. Now superseded by ColorWizzard™ and 3DxWizzard™"
UEee DockingEee Docking.exe"Intuitive shortcuts for easy access to digital content
UeonemngeOneMng.exe"eOne Manager
Xeraseplgeraseplg.exe"Added by the GENOME.AQUV TROJAN!"
Xerwghjjrjtucbcg.exe"Added by the SMALL.CUL TROJAN!"
UeTCertMangereTCrtMng.exe"eToken Certificate Manager from Aladdin Knowledge Systems
NEthernettcaudiag.exe3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs
?Event Logeventlog.exe"??"
XExplorer32efsdfgxg.exe"Added by the CLICKER-Y TROJAN!"
XFantasia injectorwincfg.exe"Added by the AGOBOT.US WORM!"
XFILEabcdefg.exe"Added by the KELVIR.DD WORM!"
?First Principle Groupfpg.exe"Related to the E-Players Card from First Principle Group"
XFlash_Player_Installying.exe"Constructor VC2000 malware"
UFlingRunfling.exe"Fling - free FTP software from NCH Software"
Xg.exeg.exe"Added by the GRAYBIRD.Q TROJAN!"
NGadu-Gadugg.exePolish language Instant Messaging client
Xgenserv pathsdqdqg.exe"Added by the SDBOT-RF WORM!"
?GisdnLoggisdnlog.exe"BT Digital Access USB"
XGlobalFlagimglogimglog.exe"Added by the AGENT-GYK TROJAN!"
XGOGGOG.exe"Added by the PHILIS.B VIRUS!"
UGTVEpgGTVEpg.exe"Part of Got All Media - control your TV tuner and other utilities from your PC"
Xgtydfggrrgg.exe"Added by the DLOADR-AZK TROJAN!"
NGWMDMMSGGWMDMMSG.exeUsed with internal modems on Gateway and vprMatrix PCs. This is the "GTW modem messaging applet" and is not required for the modem to work correctly
UHawking HWU54G UtilityHWU54G.exe"Wireless management utility for the HWU54G Mini Wireless-G USB Adapter from Hawking Technologies
XHelp Temp Filesnetreg.exe"Added by the FORBOT-EM WORM!"
XHOT FIXQOching.exe"Added by the WOOTBOT.VH WORM!"
Xhotplughotplug.exe"Added by the SILLYDL TROJAN!"
UHotplughot_plug.exe"Related to the SiS_Hot_Plug_Application. Enables automated driver loading for hotpluggable devices. If this service is stopped
YHPLJ ConfigSetConfig.exeConnects system to networked HP printer.
XI-Worm.GiGuuGiG.eXe"Added by the GINK WORM!"
NiCnNAG.EXE"iChoose - shopping browser enhancement that alerts you to cheaper deals for goods you want to buy
NIconfig.exeIconfig.exeIcon for LS-120 "Superdisk"
Xicq litewinlog.exe"Added by the IRCBOT-TJ TROJAN!"
NIDW Logging Toolidwlog.exeAdded with WinXP SP1. Usually only found in internal builds only to indicate the current build being used. Can cause slow network logon problems
XIE6wkstmg.exe"Added by a variant of the SDBOT WORM!"
XIEengineIEeng.exe"STARTPAG.AI hijacker"
XIEXPLORERmsiecfg.exe"Added by the BDOOR-JU BACKDOOR or BANCBAN-IP TROJAN!"
Xifperxxmliwvug.exe"Added by the SLAPER.U TROJAN!"
?ILO_Office_ManagerIntEdReg.exe /OFFMAN"Intense Educational Ltd - Language Office Software. Is it required?"
Ximcsslxmliwvug.exe"Added by the SLAPER.U TROJAN!"
Nimekrmigimekrmig.exe"Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese
NIMEKRMIG6.1IMEKRMIG.EXE"Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese
UIMJPMIGIMJPMIG.EXE"Microsoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails
UIMJPMIG8.1IMJPMIG.EXE"Microsoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails
XIncredible KeyloggerAdvKeylog.exe"IncredibleKeylogger spyware"
UInstant Wireless Configuration UtilityWUSB11cfg.exe"Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
UInstant Wireless Configuration UtilityWPC11Cfg.exe"Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
?Intense Registry ServiceIntEdReg.exe /CHECK"Intense Educational Ltd - Language Office Software. Is it required?"
XInternet SendMore log.exeUnidentfied adware
XintranetSYS32CFG.EXE"Added by the SPYBOT-DW WORM!"
Xipcfg.exeipcfg.exe"Adware - detected by McAfee as a variant of the ADCLICKER-BM TROJAN!"
Xipregipreg.exe"Added by the ZAGABAN-H TROJAN!"
XKasperskyAVEngKasperskyaveng.exe"Added by the NETSKY.V WORM!"
Xkey2winlog.exe"Added by the BAGLEDI-AL TROJAN!"
Xkragkrag.exe"Added by the AGENT-FOW WORM!"
?Launcglauncg.exe"??"
?LCIDConfiglcidchng.exe"??"
ULfsndmnglfsndmng.exe"LightningFAX Enterprise Fax Server - ""puts faxing at the fingertips of networked enterprise users. It enables rapid
ULightningLightning.exe"Lightning Download from Headlight Software - shareware download manager for resuming downloads. Start it manually unless you want to intercept download links from your browser"
ULightning DownloadLightning.exe"Lightning Download from Headlight Software - shareware download manager for resuming downloads. Start it manually unless you want to intercept download links from your browser"
XLoad-GuardWscript.exe LGuarg.exe.vbs"Added by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""LGuarg.exe.vbs"" file is located in %Windir%"
?load=WINOSCFG.EXE"Could it be something to do with configuring Windows on a new PC from an OEM supplier?"
Xload=a1g.exe"Added by the ATAK.B WORM!"
XLoadWindowsFilewinreg.exe"Added by the HUPIGON.A BACKDOOR!"
ULoginwinlog.exe"Salfeld Child Control - parental control software"
NLogitech . Product RegistrationeReg.exe"Registration reminder from Leader Technologies for Logitech software such as SetPoint for their range of wired and wireless keyboards and pointing devices (mice
Xlsassiglsassig.exe"Added by the BANCOS-EC TROJAN!"
ULtcyCfgApplyLtcyCfg.exe"PCI Latency Tool - ""Utility to set PCI Latency and possibly prevent game stutter or improve FPS"" for older AGP/PCI graphics cards"
YLTMSGltmsg.exe"Lucent Technologies (now Alcatel-Lucent) WinModem - which uses software rather than hardware
NLTSMMSGLTSMMSG.exe"Lucent Tech. Soft Modem Messaging application - may be found on Fujitsu Lifebook
YLTWinModem1ltmsg.exe"Lucent Technologies (now Alcatel-Lucent) WinModem - which uses software rather than hardware
YLUCENT TECHNOLOGIES ltmsgltmsg.exe"Lucent Technologies (now Alcatel-Lucent) WinModem - which uses software rather than hardware
XM1cr0s0ft S3rcuritysystemconfig.exe"Added by the RBOT.BKB WORM!"
NMatrox Diagnosticmgadiag.exeFor Matrox video cards. Quick access to diagnostics
UMaxtorRegAUTOREG.EXEPart of SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of
YMessengerSCANMSG.EXE"AntiVirus Quick Heal - virus protection"
UMgabgMgabg.exe"Matrox BIOS Guard - monitors a Matrox card's BIOS
XMicromedia Flash Updatewdfmrg.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Config Fileconfig.exeAdded by the KILLFILES.GR TROJAN! This is malware that will attempt to delete all system dlls!
XMicrosoft Configuration Wizardtaskmrg.exe"Added by the SDBOT-MX TROJAN!"
XMicrosoft Featuresms32cfg.exe"Added by the RBOT.HO WORM!"
XMicrosoft Genuine Logonmsnmsg.exe"Added by the IRCBOT-XH WORM!"
XMicrosoft Hosting ServiceWINHOSTING.EXE"Added by the RBOT.AEV WORM!"
UMicrosoft IME 2002IMJPMIG.EXE"Microsoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails
XMicrosoft Intrenet Explorerwcumrg.exe"Added by the SDBOT-AFD WORM!"
XMicrosoft Java Virtual MachineMsConfiG.exe"Added by the FORBOT-DV WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
XMicrosoft Ming Serviceming.exe"Added by the RBOT-AWS WORM!"
XMicrosoft MSN 7 Servicesmsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Scanregmicrosoftscanreg.exe"Added by the FRANRIV.A WORM!"
XMicrosoft Security Managementbling.exe"Added by the RBOT.XL WORM!"
XMicrosoft Server Applacationsmsnmsg.exe"Added by the AGOBOT.BBM WORM!"
NMicrosoft System Configuration Utilitymsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
XMicrosoft System32 Updatecmsrg.exe"Added by the RBOT-GN WORM!"
XMicrosoft Updatemsconfg.exe"Added by the RBOT.H WORM!"
XMicrosoft Updatesys32cfg.exe"Added by the RBOT.DR WORM!"
XMicrosoft Updatewin-mang.exe"Added by the RBOT-AFK WORM!"
XMicrosoft Updatebling.exe"Added by the RBOT-AVK WORM!"
XMicrosoft Update 32mscnfg.exe"Added by the RBOT-ALM WORM!"
XMicrosoft Update Clinicsvsipconfig.exe"Added by the RBOT.BR WORM!"
XMicrosoft Update Machinejkydxg.exe"Added by the RBOT.AEA BACKDOOR!"
XMicrosoft Updatervbcjlg.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft USA Plugusaplug.exe"Added by the RBOT-DVC WORM!"
XMicrosoft Visual Studioplscdksxg.exe"Added by the RBOT-AWV WORM!"
UMicrosoft Windows Media Player Network Sharing Service Configuration ApplicationWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XMicrosoft Windows Tasks Managementtaskmng.exe"Added by the RBOT-FXK WORM!"
XMicrosoft Windows Update Servicemsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoftValuesyscnfg.exe"Added by an unidentified VIRUS
UMicrosoft® Windows® Operating SystemWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XMINIBUGMINIBUG.EXE"Displays ads inside Weatherbug - see here"
UminilogMINILOG.EXEIf you don't have ZoneAlarm or ZoneAlarm Pro running you don't need this. This must be enabled if programs such as VisualZone Report utility or ZoneLog Analyzer are in use
UModemOnHoldnetWaiting.exe"NetWaiting/Modem-on-Hold - allows you to place your Internet connection on hold while you take a voice call (if Call Waiting is supported by your phone company). See here for more information"
XModularConfigsyscnfg.exe"Added by an unidentified VIRUS
UMotorola Desktop Suite mRouter ConfigmRouterConfig.exe"Configuration for Motorola's version of Intuwave's m-Router - ""that enables easy connectivity between mobile devices and PCs across Bluetooth
UmRouterConfigmRouterConfig.exe"Configuration for Intuwave's m-Router - ""that enables easy connectivity between mobile devices and PCs across Bluetooth
XMS Configmsdconfig.exe"Added by the RBOT-CZH WORM!"
XMs System ConfigMscfg.exe"Added by the SDBOT-CCR WORM!"
XMSAdminjdbgmrg.exe"Added by the DASMIN.A TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here"
NMSConfigmsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
Xmsconfigmsconfig.exe"CoolWebSearch MSConfig parasite variant. Note - this overwrites the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
Xmsconfigmsconfig.exe"Added by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrun"
Xmsconfigwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
XMsconfig lptt01msconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
XMsconfig ml097emsconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
Xmsconfig.exeproxy.exeAdded by a variant of the AGENT.AH downloader TROJAN!
Xmsconfig.exeuline.exeAdded by a variant of the AGENT.AH downloader TROJAN!
XMSConfigrjdbgmrg.exe"Added by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here"
NMSConfigRemindermsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. This particular entry is specific only to 98/Me and is located in %System%
XMSCOREsyscnfg.exe"Added by an unidentified VIRUS
Xmsdevmsconfig.exe"Added by the AGOBOT.AAU WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
XMSDLLsyscnfg.exe"Added by an unidentified VIRUS
UMSGTAGMSGTAG.exe"MSGTAG is an application that tells you when your emails have been received and opened"
XMSLogMicrosoftLog.exe"Added by a variant of the SDBOT WORM!"
XmsMGRrtkmsg.exe"Added by the SDBOT-BPY WORM!"
XMSMNTJNGMSMNTJNG.EXE"Added by the GRABER-G TROJAN!"
Xmsnmsnmsg.exe"Added by the RBOT-GO WORM!"
XMsn Bootmsnbootcfg.exe"Added by the IRCBOT.BFU BACKDOOR!"
XMSN Configurationmsnconfig.exe"Added by a variant of the IRCBOT TROJAN!"
XMSN Configuration Loadermsmsncfg.exe"Added by the AGOBOT-KX BACKDOOR!"
XMSN File Configurationmsnfilecfg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN Message Servicemsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN Messagesmsnmesg.exe"Added by the RBOT-ACN WORM!"
XMSN Messangermsnmsng.exe"Added by the SDBOT.XN WORM!"
XMsn Messenger Servicemsnmsg.exe"Added by the SDBOT.BMU WORM!"
XMSN Settings Managermsnsetmg.exe"Added by an unidentified WORM or TROJAN! See here"
Xmsnmsgasgag.exe"CoolWebSearch parasite variant"
Xmsnmsgmsnmsg.exe"Added by the BANKER-CLX TROJAN!"
Xmsnmsg.exemscmd32.exeAdded by a variant of the AGENT.AH TROJAN!
Xmsnmsg.exemsnmsg.exe"Added by the BANCBAN-KN TROJAN!"
XMSOfficeCfgmsocfg.exePremium rate adult content dialer
Xmspingmsping.exe"Added by the FLOODBLACK TROJAN!"
Xmsping.exemsping.exe"Added by the BDOOR-MZ BACKDOOR!"
Xmsreg.exemsrege.exe"Added by the ZINX TROJAN!"
Xmsvhostaig.exe"Added by the AIMBOT-BC TROJAN!"
XMultimediawindebug.exe"Added by the VB-ERB WORM!"
NMWProEngMWProEng.exeLogitech Mouseware Pro software - only required when using special functions
XNetWINREG.EXE"Added by the ASSASIN.D TROJAN!"
Xnetconfignetconfig.exe"Added by the NETWARE TROJAN!"
Unetmsgnetmsg.exe"Net_Message is a small tool to send messages across the network
UNetScreen-RemoteSafeCfg.exe"NetScreen Remote VPN client software"
NNowe Gadu-Gadugg.exePolish language Instant Messaging client
NNuance OmniPage 17-reminderEreg.exe Ereg.ini"Registration reminder for Ominpage version 17 from Nuance"
NNuance PDF Create! 5-reminderEreg.exe Ereg.ini"Registration reminder for PDF Create version 5 from Nuance"
NNuance PDF Professional 6-reminderEreg.exe Ereg.ini"Registration reminder for PDF Converter Professional version 6 from Nuance"
NNuance PDF Professional5-reminderEreg.exe Ereg.ini"Registration reminder for PDF Converter Professional version 5 from Nuance"
Unwrecmsgnwrecmsg.exe"Broadcast message handler part of Novell Netware that displays server
UODSPConfigODSPConfig.exe"DsktopSurveil surveillance software. Uninstall this software if you did not install it yourself"
XOffice Desktopsimag.exe"Added by the SPYBOT.AQR WORM!"
NOP12 ReminderEreg.exe ereg.ini"Registration reminder for OmniPage from Nuance (was ScanSoft)"
NOperations Typhoon Rising RegistrationNOVG.EXE"Joint Operations registration reminder"
NOPSE reminderEreg.exe ereg.ini"Registration reminder for OmniPage from Nuance (was ScanSoft)"
XOS Boot Configurationbootconfig.exe"Added by the IRCBOT.HJ WORM!"
XOSDALG.exe"Added by the STARTPAGE-ID TROJAN!"
XOSSrlvknlg.exe"Marketscore.RelevantKnowledge adware"
NP2P NETWORKINGP2P Networking.exePeer to Peer (P2P) sharing of files on the internet
Xp2p networkingp2pnetworking.exe"Added by the RBOT-ECP WORM!"
Xp2pnetworkingp2pnetworking.exe"Added by the RBOT-AFL WORM!"
XPag Windows Monitorpag.exe"Added by the AGENT-EOT TROJAN!"
Xpaint.exeshnlog.exe"Added by the PUPER-A TROJAN!"
UPC Tools Privacy Guardianpg.exe"Part of Privacy Guardian from PC Tools - which ""is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer"". This startup entry runs only on the next reboot if the ""Cache
?PCMMediaSharingPCMMediaSharing.exe"Part of Acer HomeMedia Connect
Upgpg.exe"Part of Privacy Guardian from PC Tools - which ""is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer"". This startup entry runs only on the next reboot if the ""Cache
NPickatagpickatag.exe"Pick-a-tag - ""freeware utility for random selection of your taglines. This utility randomly picks a tagline out of a list of taglines. It will create a signature file which your mailer can use to place under your messages"""
Uplmg.exeplmg.exeParagon Last Minute Bidder - auction assistant software
XPlug And Playmsnmsg.exe"Added by the RBOT-ID WORM!"
NPowerRegeReg.exe"Registration reminder from Leader Technologies for software from Logitech
NPPort10reminderEreg.exe ereg.ini"Registration reminder for PaperPort version 10 from Scansoft (now Nuance)"
NPPort11reminderEreg.exe Ereg.ini"Registration reminder for PaperPort version 11 from Scansoft (now Nuance)"
NPPort12reminderEreg.exe Ereg.ini"Registration reminder for PaperPort version 12 from Nuance"
NPPort9reminderEreg.exe ereg.ini"Registration reminder for PaperPort version 9 from Scansoft (now Nuance)"
?Printer UpdateCFGREG.EXE"Maybe a registration reminder or automatically updates drivers or application software for a printer?"
UPrivacy Guardianpg.exe"Part of Privacy Guardian from PC Tools - which ""is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer"". This startup entry runs only on the next reboot if the ""Cache
Upumcfgpproxycfg.exe"""GuardWare iShield blocks pornographic images when you surf the Internet on your computer using a web browser"""
XQTSvcmsocfg.exePremium rate adult content dialler
NQuickenSEMessageQsemsg.exeQuicken option
XQuickSetmmspng.exeAdded by a variant of the IROFFER.Z TROJAN!
Ureadericonreadericon45G.exeTray icon to set various configuration settings for Sunkist (and maybe other) media card readers
NRed Flagredflag.exePMS prediction program with modes for guys and girls - no longer available
XReg Serviceipcfg.exe"Added by the AGOBOT-SO WORM!"
XReg ServiceWinnConfig.exe"Added by the AGOBOT-PF WORM!"
XRegistry Checkupwinreg.exeAdded by an unidentified WORM or TROJAN!
XRegistry Startup Checkcheckreg.exe"Added by the REMLOAD-A or DANMEC-B TROJANS!"
XRegmonitorregmaping.exe"Added by the BEAGLE.DO WORM!"
YRegrun2WatchDog.exe"Greatis Software's RegRun security suite which amongst other things replaces MSCONFIG. The WatchDog check for registry changes caused by trojan's
XRelevantKnowledgerlvknlg.exe"Marketscore.RelevantKnowledge adware"
?rfwydgrfwydg.exe"??"
URKLG Startupklg.exe"Local Keylogger Pro keystroke logger/monitoring program - remove unless you installed it yourself!"
Xrnwabmigrnwabmig.exe"Added by the AGENT-LMI TROJAN!"
Xrrmsobqhrmug.exe"Added by the AGENT-GYY TROJAN!"
URun Nintendo Wi-Fi USB Connector Registration ToolNintendoWFCReg.exe"Related to Wi-Fi USB Connector from Nintendo"
Xrun=dllreg.exe"Added by the DUMARU-L TROJAN!"
Xrundll***die.exe [path] ttg.exe"Added by the SUMTAX TROJAN! where *** is 134
XRunDLL34syscnfg.exe"Added by an unidentified VIRUS
XRVC6Playertskdbg.exe"Added by the ZAPCHAS-M TROJAN!"
USaitekAutoConfiguresaicnfig.exe"Configuration for Saitek game controllers"
XSam-sungSam-sung.exe"Added by a variant of the SDBOT WORM!"
XSamsongSamsong.exe"Added by the SDBOT.BNE WORM!"
XSB WatchdogSBWatchdog.exeSpyware utility installed by the manufacturers of some laptops (Sony) used to monitor browsing habits and send them back to whoever installed it - released by SoftBank
NScanSoft OmniPage SE 4.0-reminderEreg.exe ereg.ini"Registration reminder for Ominpage SE version 4 from Scansoft (now Nuance)"
NScanSoft PDF Professional 4-reminderEreg.exe Ereg.ini"Registration reminder for PDF Converter Professional version 4 from Scansoft (now Nuance)"
XSecurity Agentsecurag.exe"Added by the BANCBAN-F TROJAN!"
XService Driversmsnpg.exe"Added by the RBOT.BMD WORM!"
UServiceConfigispbeg.exe"Comcast Transition Wizard. On June 30th
XSevicewinconfig.exe"Added by the GIP.113.B1 TROJAN!"
XSexy_sgSexy_sg.exePremium rate adult content dialler
XShelltaskmrg.exe"Added by the BANCBAN-FT TROJAN!"
NSiSUSBRGSiSUSBrg.exeSiS USB Registry Patch File - fixes the undetectable problem with SiS USB controller on Windows XP
NSM1BGSM1BG.EXEUSB driver for downloading from within Napster and iTunes to portable MP3 players. Only required at startup if you use it all the time - otherwise start it manually when required
NSmartDefragIObit SmartDefrag.exe"""IObit SmartDefrag helps defragment your hard drive more efficiently than any other product on the market - free or not"""
USMS Win9x Message AgentSMSMsg.exeThis program assigns a user to a Systems Management Server site
USoloScheduleSolocfg.exe"Scheduler for Solo Antivirus. Leave enabled unless you scan manually on a regular basis"
NSonnRegSonnReg.exe"Registration for Colorific® and 3Deep® monitor calibration sofware from E-Color. Now superseded by ColorWizzard™ and 3DxWizzard™"
NSourcePathgwreg.exeUsed to update Gateway registry settings for System Restoration Kit and Web update programs
NSpeed racerCTSRReg.exeSoftware for a Creative sound card
USpeedtouch USB DiagnosticsDragdiag.exeFor an external Alcatel ADSL high-speed modem. A diagnostic tool and can be run from the Start menu when required. The only reason it might be useful on startup is if you like seeing an 'at-a-glance' status indicator on the taskbar (the icon is a different colour depending on the status of the device/line)
XSRNGsrng.exe"ShopNavSearch.Srng search hijacker"
USrv32Winsysdiag.exe"SpyAgent surveillance software. Uninstall this software unless you put it there yourself"
?ssdiagssdiag.exe"Equinox (now Avocent) ""Configuration and DOS Diagnostic for DOS and Windows platforms"""
XStart Uppingtaskmrg.exe"Added by the RBOT-MA WORM!"
XStarterscvhosting.exe"Added by the SDBOT.RU WORM!"
Xstarterscvhostingg.exe"Added by the FORBOT-FB WORM!"
Xstratasxmconfig.exe"Added by the RBOT-AHR WORM!"
XStratasggfig.exe"Added by the OPANKI.W WORM!"
Xsvchostying.exe"Constructor VC2000 malware"
XSvcsys Registry Managersvcsysreg.exe"Detected by Kaspersky as the AGENT.CV TROJAN!"
Xsysalggsysalgg.exe"Added by the TIBS.BF WORM!"
XSyslog lptt01Syslog.exe"RapidBlaster variant (in a ""Syslog"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSyslog ml097eSyslog.exe"RapidBlaster variant (in a ""Syslog"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSysmonLogmslog.exe"Added by the AGENT.AOV TROJAN!"
XSysRegSysReg.exe"Added by the CHEKIN TROJAN!"
XSysRegSysReg.exe"SearchSeekFind textual marketing foistware"
XSystemabcdefg.exe"Added by the HARWIG-B WORM!"
XSystem Configurator32SYSTEMCFG.EXE"Added by the AGOBOT-KS WORM!"
XSystem CSRSS Patchscrtkfg.exe"Added by the RBOT-ADA WORM!"
XSystem DB Managersysdbmg.exe"Added by an unidentified WORM or TROJAN! See here"
XSystem Information Managermslog.exe"Added by the DELF.AKO TROJAN!"
XSystem Loadersyscfg.exe"Added by the AGOBOT-BS BACKDOOR!"
XSystem Managersysmng.exe"Added by the TAME-C WORM!"
XSYSTEM MESSAGERwmisg.exe"Added by the MYTOB.ES WORM!"
XSystem Supportsyscfg.exe"Added by the RBOT-AGQ WORM!"
XSystem Task Managertaskmrg.exe"Added by a variant of the SPYBOT WORM! See here"
USystem32sysdiag.exe"SpyAgent surveillance software. Uninstall this software unless you put it there yourself"
USystem32kfvwsysdiag.exe"SpyAgent surveillance software. Uninstall this software unless you put it there yourself"
XSystemBackupMicroLog.exe"Added by the MICROLOG.A TROJAN!"
XSystemRegWINREG.EXE"Added by the DEWIN.A TROJAN!"
XSystemServicemsocfg.exePremium rate adult content dialler
?TAGtag.exe"??"
XTapicfgTapicfg.exe"CoolWebSearch Tapicfg parasite variant"
XTapicfg.exetapicfg.exe"Malware installed by different rogue security software including SpyKillerPro"
XTask Debuggertskdbg.exe"Added by the AGOBOT-KK WORM!"
XTask managebrkbtaskmg.exe"Added by a variant of the SPYBOT WORM! See here"
XTask Managertaskmng.exe"Added by the TIOTUA-E WORM!"
Xtaskmrgtaskmrg.exe"Added by the BANKER-BZZ TROJAN!"
Xtaskmrg.exetaskimg.exe"Added by the DLOADER-QZ TROJAN!"
Xtaskmrg.exe[path to trojan]"Added by the BANCBAN-BN TROJAN!"
NTCASUTIEXEtcaudiag.exe3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs
NTCAUDIAG -offtcaudiag.exe3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs
XTiny AVfooding.exe"Added by the NETSKY.I WORM!"
NTray TemperatureWeatherbug.exe"Weatherbug provides current outdoor temperature in the System Tray
Xtskdbgtskdbg.exe"Added by the FLOOD.E TROJAN!"
UTWarnMsgtwarnmsg.exe"Toshiba System Warning Function for Windows 98
XUpdate Checkerwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
NUpdRegUpdreg.exeReminder to register Creative Labs SoundBlaster Live! cards
XUSB Deviceservicelog.exe"Added by the WOOTBOT.CB WORM!"
XUser Debug Managerusndebug.exe"Added by a variant of the SPYBOT WORM! See here"
UUser LoggerUsrLog.exe"UserLogger commercial surveillance software that logs keystrokes
XUser Messagesusrmsg.exe"Added by a variant of the IRCBOT TROJAN! See here"
NUSRobotics 802.11g Wireless Network UtilityUSRWLANG.exe"USRobotics Wireless Network Utility - used to configure security settings for connecting to WEP encrypted Access Point through the USR Wireless adapter. You must uncheck ""Use Windows to configure my wireless settings"" for the program to work properly. Has Site Survey capabilities
NUSSShRegUSSSHREG.EXERegistration reminder for Ulead SmartSaver Pro - compacts large graphics for web designers
XVCXD Settingsphqg.EXE"Added by the RBOT.BRF WORM!"
UVC_Logkeylog.exe"PaqKeylog is a surveillance software program that logs keystrokes and can run in stealth mode. Uninstall this software unless you put it there yourself"
UVenturi Configuratorventcfg.exe"Venturi Wireless mobile broadband configuration utility"
YVet AlertVETMSG.EXE"Computer Associates Vet Anti-Virus software"
YVetAlertVETMSG.EXE"Computer Associates Vet Anti-Virus software"
XVideo Camera Frogwcamfrog.exe"Added by a variant of the IRCBOT TROJAN! See here"
UVirtuaGirlVg.exe"VirtuaGirl is a shareware program featuring scantily dressed girls on your desktop. They say hi in the morning
Xvuaaareg.exe"Added by a variant of the RBOT WORM!"
XW32.Formalin.BetaPocong.exe"Added by the SILLYFDC WORM!"
NWatch Dog Programwatchdog.exeFor Compaq PC's. Associated with Compaq's internet services. Not required if you don't use services provided by them and may not be required even if you do
NWatchdogWatchdog.exe"Definitely part of the Mustek scanner drivers and software (for 600 III EP Plus and maybe others)
?WatchDogwatchdog.exe"Part of Motorola ""Mobile Phone Tools"" v3 - in a ""Mobiile Phone Tools"" sub-directory of Program Files"
UWAWifiMessageWiFiMsg.exe"""HP Wireless Assistant is a user application that provides a method for controlling the enablement of individual wireless devices (such as Bluetooth or WLAN devices) and that shows the state of the radios for these wireless devices"""
Xwblogonalgg.exe"Added by the AGENT.AGGI TROJAN!"
XWebBuyingwebbuying.exe"WebBuying adware"
XWelcomewinconfig.exe"Added by the GIP.113.B1 TROJAN!"
XWelcomeCONFIG.EXE"Added by the PSWGIP.B TROJAN!"
XWhistlerwhismng.exe"Added by the WHISTLER-F TROJAN!"
XWifi Configurationwificonfig.exe"Added by the IRCBOT.AWB BACKDOOR!"
XWifi Debugwifidebug.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWin Configwinconfig.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWin Defragwindfrag.exe"Added by a variant of the SDBOT WORM! See here"
XWin Defrag!windefrag.exe"Added by a variant of the SDBOT WORM! See here"
XWin Defragsdefrag.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWin32 Debug ManagerWin32Debug.exe"Added by a variant of the WOOTBOT WORM!"
XWin32 Usb DriverAvpG.exe"Added by the FORBOT-BX WORM!"
XWin32 USB2 Driversvchosting.exe"Added by the FORBOT-J or SDBOT.HU WORM!"
XWin32 USB2 Driveralgg.exe"Added by the TIBS.BF WORM!"
Xwin32debugwin32debug.exe"Added by the GUDEB WORM!"
Xwincfgsyscnfg.exe"Added by an unidentified VIRUS
XWindows Automatic Updaterwindrg.exe"Added by a variant of the RBOT WORM!"
XWindows Configwinconfig.exe"Added by the IRCBOT.BAP BACKDOOR!"
XWindows Config Systemconfig.exe"Added by a variant of the SDBOT WORM!"
XWindows Core Kernel Updatewin32bootcfg.exe"Added by the RANCK-EL TROJAN!"
XWindows debug loggingwinlogg.exe"Added by the RBOT-OY WORM!"
XWindows Debuggerwindbg.exe"Added by the FORBOT-BY WORM!"
XWindows Debugging Toolsupdatecfg.exe"Added by the RBOT-AXU WORM!"
XWindows Desktop Daemonwinpadg.exe"Added by a variant of the SPYBOT WORM!"
XWindows Executerbling.exe"Added by the SDBOT-DFT WORM!"
XWindows Firewall Logwinlog.exeAdded by an unidentified WORM or TROJAN!
XWindows Generic Procprocmsg.exe"Added by the ALLIM.B WORM!"
XWindows iMessenger Messengerwinimsg.exe"Added by the ALLIM.A WORM!"
XWindows Installer 1msnconfig.exe"Added by the PURITYSCN.B TROJAN!"
XWindows Live Msgswlivemsg.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Loggerwinlog.exe"Added by the NSHADOW-B TROJAN!"
XWindows loggingasgasg.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Loginwinlog.exe"Added by the AGOBOT.MG WORM!"
XWindows Login Servicewinlog.exe"Added by the RBOT-AFN WORM!"
XWindows Management Instrumentationswinmg.exe"Added by the GAOBOT.GW WORM!"
NWindows Media Connect 2WMCCFG.exe"Windows Media Connect from Microsoft - stream digital media files on your computer to digital media receivers (DMRs) that are connected to your home network"
XWindows Messengermsnmsg.exe"Added by the SPYBOT.BV WORM!"
XWindows Messenger Messengerwinmsg.exe"Added by the VELKBOT.A WORM!"
XWindows MSConfig Startup Loggerwinlog.exe"Added by the RBOT.BCU WORM!"
XWindows Networksnetcog.exe"Added by the MYTOB.FH WORM!"
XWindows PDGwinpdg.exe"Added by the RBOT-ADW WORM!"
XWindows Registrymsnmsg.exe"Added by a variant of the RBOT WORM!"
XWindows Registry Controlwinreg.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Service Layerconfig.exe"Added by the RBOT.DDJ WORM!"
XWindows Service Managermsnmrg.exe"Added by the OSCABOT-G WORM!"
XWindows Service Threadssvcthreading.exe"Added by the SHEUR.AUM TROJAN!"
XWindows Servicesscmsg.exe"Added by a variant of the SDBOT WORM!"
XWindows Services Jogsvcjog.exe"Added by the AGENT.ALWZ WORM!"
XWindows Services Jogsvcjogg.exe"Added by the AGENT.QAF WORM!"
XWindows Services Joggingsvcjogging.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Services Jogingsvcjoging.exe"Added by the IRCBOT.AVI BACKDOOR!"
XWindows Services Towersvctowing.exe"Added by the SLENFBOT.LA WORM!"
XWindows System Configurationwincfg.exe"Added by the AGOBOT.OP WORM!"
XWindows System Guardmsng.exe"Added by the EGGDROP-BO WORM!"
XWindows Task Managertaskmrg.exe"Added by the MYTOB.AV WORM!"
XWindows Task Managertaskmg.exe"Browser hijacker - identified by DrWeb antivirus as ""Trojan.StartPage.601"""
XWindows Taskmanagertaskmrg.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centertaksmrg.exe"Added by the AGENT.WOH TROJAN!"
XWindows UDP Control Centerwinudpmg.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Update Servicesmcg.exe"Added by the SDBOT.QY WORM!"
XWindows User Mode Driver Managerwdfmrg.exe"Added by the SDBOT-ZN WORM!"
XWindows-TCP-IPrfkampig.exe"Added by the GIPMA TROJAN!"
XWindowsBoolaimplg.exe"Added by the SDBOT-CNG WORM!"
XWindowsUpdateManagerwupdmng.exe"Added by the IRCBOT.OE BACKDOOR!"
XWinDynManageramsnmsg.exe"Added by the SDBOT-IA BACKDOOR!"
Uwinlgnwinsplg.exe"Related to the Sentry Parental Controls software"
Xwinlogwinlog.exe"Added by the GAOBOT.DF WORM!"
Xwinlog managerwinlog.exe"Added by the DONBOMB.A TROJAN!"
Xwinlog.exewinlog.exe"Added by the BCKDR-RBJ TROJAN!"
XWinlogin.exelog.exeAdded by a variant of the AGENT.AH downloader TROJAN!
Xwinlogoncleanmg.exe"Added by the AGENT-ICR TROJAN!"
XWinnt DNS identmsnmsrg.exe"Added by the RBOT.BVQ WORM!"
XwinRegwinReg.exe"Added by the YAHA.H or YAHA.J WORMS!"
Xwinrunmsconfig.exe"Added by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrun"
XWinsock2 driverwincfg.exe"Added by the SPYBOT.CO WORM!"
XWinsock32 driverTESTING.EXE"Added by the SPYBOT-B WORM!"
Xwinsockdrivertskmg.exe"Added by the SDBOT.GEN TROJAN or WARPIGS.C WORM!"
Xwinsplogwsmmlog.exe"Added by the MAILBOT-CA TROJAN!"
Xwinsyslog lptt01winsyslog.exe"RapidBlaster variant (in a ""Winsyslog"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XWinupdate Enginewupeng.exe"MalwareCrush rogue security software - not recommended
XWinUpdatingWinUpdating.exe"Added by the AGENT-GSC TROJAN!"
XWinXPServiceTskdbg.exe"Added by the MDROP-BPQ TROJAN!"
UWireless PCI Card Configuration UtilityWMP11Cfg.exe"Utility used by the LINKSYS wireless PCI card (WMP11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
UWireless-G Notebook Adapter UtilityWPC54CFG.EXE"Utility used by the LINKSYS Wireless-G Notebook Adapter (WPC54G)"
Uwlancfgwlancfg.exeInventel wireless router related - required in order to automatically connect to the Net at bootup
YWLAN_Cfg.exeWLAN_Cfg.exeLinksys Instant Wireless USB Network Adapter driver
UWMPNSCFGWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
UWonderFrogWonderFrog.exe"Wonder Frog typing monitor"
Xwzdmgwzdmg.exe"Added by a generic downloader TROJAN - see here"
NXeroxRegistationEReg.exeRegistration reminder from Leader Technologies for software from Xerox
UXFilesDialogXFilesDialog.EXE"""XFilesDialog is designed to improve all the (more or less standard) Windows file dialogs (Open / Load / Save)"""
?XGIWatchDogXWatDog.exe"Related to XGI Technology's Volari graphics cards - what does it do and is it required?"
Xxmstartxuming.exe"Added by the GMIN-A WORM!"
XXpp2pnetworking.exe"Added by the SDBOT.XA WORM!"
?xpcfgxpcfg.exe"??"
XXXXmpegXXXmpeg.exeAdult content dialler
XYahoo MessengerYahoomsg.exeAdded by an unidentified WORM or TROJAN!
Xyingying.exe"Constructor VC2000 malware"
?ZDConfigZDConfig.exe"Related to various brands of Wireless USB LAN Adapter - what does it do and is it required?"
NZipGenius Cleanzg.exe"ZipGenius file compression utility"
X[12 random characters]ati2dvag.exe"IeDriver adware variant"
X[14 random numbers]rwg.exe"Green AV rogue security software - not recommended
X[random name]ping.exe"PurityScan adware. Note - do not confuse with the Microsoft utility of the same name as described here"
X[random name]m?config.exe"PurityScan adware"
X[Randomly chosen existing folder name]_cfg.exe"Added by the ANTINNY-L WORM!"
X[Randomly chosen existing folder name]_config.exe"Added by the ANTINNY-L WORM!"
X[various names]bling.exe"Added by the RBOT-NI WORM!"
X[various names]borlandg.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]jopplerg.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]msag.exe"Wareout - malware masquerading as a spyware and dialer remover"
X{78B578D7-BCE1-4d83-9CD4-195BC34D8CB3}syssfzvakqg.exe"Added by the FAKEALERT-AM TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.