Yesterday, my firewall blocked "GWXConfigManager.exe" from accessing the internet. As with any program I don't recognize, I attempted to look it up, but I found only one English result: "https://support.microsoft.com/en-us/kb/3035583". However, that page doesn't actually contain any references to "GWXConfigManager.exe". Next, I scanned it with Avira and uploaded it to VirusTotal, and there were no detections. Finally, I checked out the folder where the file is located: "C:\Windows\System32\GWX". It was created on March 28. There's a "config.xml" which has a few potentially useful clues, including two URLs: "https://go.microsoft.com/fwlink/?LinkID=526874" and "http://g.bing.com/GWX/". Since they're both in Microsoft-owned domains, I didn't see any harm in opening them, but they both redirect to the nonsensical URL "https://invalid.html/".

Here's the full text of "config.xml":

<?xml version="1.0" encoding="utf-16"?>

<CONFIG>

<!--inbox config-->

<VERSION>1</VERSION>

<AuTargetSetting>2</AuTargetSetting>

<CompatExpiryTime>45</CompatExpiryTime>

<GlobalAdTimeOut>30</GlobalAdTimeOut>

<OnlineAdUrl>https://go.microsoft.com/fwlink/?LinkID=526874&</OnlineAdUrl>

<!--Relative path to download folder for main html file-->

<OfflineAppUrl>index.html</OfflineAppUrl>

<MinAppraiserUpgradeExperience>Green</MinAppraiserUpgradeExperience>

<!--pre-req temp disabled-->

<AppraiserPrereq>true</AppraiserPrereq>

<DownloadPrereq>true</DownloadPrereq>

<EnableDomainJoined>false</EnableDomainJoined>

<EnableEnterpriseSku>false</EnableEnterpriseSku>

<Telemetry BaseURL="http://g.bing.com/GWX/">

<linkid>GWX</linkid>

<xmlLocation>TelemetryStore.xml</xmlLocation>

<honorCeip>true</honorCeip>

</Telemetry>

<NonCeipSetting>GwxMarkersOnly</NonCeipSetting>

<AdWindowSizes>

<S>

<x>350</x>

<y>160</y>

</S>

<M>

<x>320</x>

<y>210</y>

</M>

<L>

<x>480</x>

<y>320</y>

</L>

</AdWindowSizes>

<AppWindowSize>

<x>800</x>

<y>492</y>

</AppWindowSize>

<Filters>

<Filter>

<Phase>None</Phase>

<triggers>

</triggers>

</Filter>

</Filters>

<Phases>

<Phase name="None">

<AntUXProcess>false</AntUXProcess>

<TrayIcon>false</TrayIcon>

<Advertisement>false</Advertisement>

<ReservationPage>false</ReservationPage>

<Upgrading>false</Upgrading>

<DownloadInProgress>false</DownloadInProgress>

<DownloadComplete>false</DownloadComplete>

<ReadyForSetup>false</ReadyForSetup>

<SetupInProgress>false</SetupInProgress>

<SetupComplete>false</SetupComplete>

</Phase>

<Phase name="AnticipationUX">

<AntUXProcess>true</AntUXProcess>

<TrayIcon>true</TrayIcon>

<Advertisement>true</Advertisement>

<ReservationPage>false</ReservationPage>

<Upgrading>false</Upgrading>

<DownloadInProgress>false</DownloadInProgress>

<DownloadComplete>false</DownloadComplete>

<ReadyForSetup>false</ReadyForSetup>

<SetupInProgress>false</SetupInProgress>

<SetupComplete>false</SetupComplete>

</Phase>

<Phase name="Reservation">

<AntUXProcess>true</AntUXProcess>

<TrayIcon>true</TrayIcon>

<Advertisement>true</Advertisement>

<ReservationPage>true</ReservationPage>

<Upgrading>false</Upgrading>

<DownloadInProgress>false</DownloadInProgress>

<DownloadComplete>false</DownloadComplete>

<ReadyForSetup>false</ReadyForSetup>

<SetupInProgress>false</SetupInProgress>

<SetupComplete>false</SetupComplete>

</Phase>

<Phase name="Reserved">

<AntUXProcess>true</AntUXProcess>

<TrayIcon>true</TrayIcon>

<Advertisement>true</Advertisement>

<ReservationPage>false</ReservationPage>

<Upgrading>false</Upgrading>

<DownloadInProgress>false</DownloadInProgress>

<DownloadComplete>false</DownloadComplete>

<ReadyForSetup>false</ReadyForSetup>

<SetupInProgress>false</SetupInProgress>

<SetupComplete>false</SetupComplete>

</Phase>

<Phase name="RTM">

<AntUXProcess>true</AntUXProcess>

<TrayIcon>true</TrayIcon>

<Advertisement>true</Advertisement>

<ReservationPage>false</ReservationPage>

<Upgrading>false</Upgrading>

<DownloadInProgress>false</DownloadInProgress>

<DownloadComplete>false</DownloadComplete>

<ReadyForSetup>false</ReadyForSetup>

<SetupInProgress>false</SetupInProgress>

<SetupComplete>false</SetupComplete>

</Phase>

<Phase name="GA">

<AntUXProcess>true</AntUXProcess>

<TrayIcon>true</TrayIcon>

<Advertisement>false</Advertisement>

<ReservationPage>false</ReservationPage>

<Upgrading>true</Upgrading>

<DownloadInProgress>false</DownloadInProgress>

<DownloadComplete>false</DownloadComplete>

<ReadyForSetup>false</ReadyForSetup>

<SetupInProgress>false</SetupInProgress>

<SetupComplete>false</SetupComplete>

</Phase>

<Phase name="UpgradeDetected">

<AntUXProcess>true</AntUXProcess>

<TrayIcon>true</TrayIcon>

<Advertisement>false</Advertisement>

<ReservationPage>false</ReservationPage>

<Upgrading>true</Upgrading>

<DownloadInProgress>false</DownloadInProgress>

<DownloadComplete>false</DownloadComplete>

<ReadyForSetup>false</ReadyForSetup>

<SetupInProgress>false</SetupInProgress>

<SetupComplete>false</SetupComplete>

</Phase>

<Phase name="UpgradeDownloadInProgress">

<AntUXProcess>true</AntUXProcess>

<TrayIcon>true</TrayIcon>

<Advertisement>false</Advertisement>

<ReservationPage>false</ReservationPage>

<Upgrading>true</Upgrading>

<DownloadInProgress>true</DownloadInProgress>

<DownloadComplete>false</DownloadComplete>

<ReadyForSetup>false</ReadyForSetup>

<SetupInProgress>false</SetupInProgress>

<SetupComplete>false</SetupComplete>

</Phase>

<Phase name="UpgradeDownloaded">

<AntUXProcess>true</AntUXProcess>

<TrayIcon>true</TrayIcon>

<Advertisement>false</Advertisement>

<ReservationPage>false</ReservationPage>

<Upgrading>true</Upgrading>

<DownloadInProgress>false</DownloadInProgress>

<DownloadComplete>true</DownloadComplete>

<ReadyForSetup>false</ReadyForSetup>

<SetupInProgress>false</SetupInProgress>

<SetupComplete>false</SetupComplete>

</Phase>

<Phase name="UpgradeReadyToInstall">

<AntUXProcess>true</AntUXProcess>

<TrayIcon>true</TrayIcon>

<Advertisement>false</Advertisement>

<ReservationPage>false</ReservationPage>

<Upgrading>true</Upgrading>

<DownloadInProgress>false</DownloadInProgress>

<DownloadComplete>false</DownloadComplete>

<ReadyForSetup>true</ReadyForSetup>

<SetupInProgress>false</SetupInProgress>

<SetupComplete>false</SetupComplete>

</Phase>

<Phase name="UpgradeReadySetupInProgress">

<AntUXProcess>true</AntUXProcess>

<TrayIcon>true</TrayIcon>

<Advertisement>false</Advertisement>

<ReservationPage>false</ReservationPage>

<Upgrading>true</Upgrading>

<DownloadInProgress>false</DownloadInProgress>

<DownloadComplete>false</DownloadComplete>

<ReadyForSetup>false</ReadyForSetup>

<SetupInProgress>true</SetupInProgress>

<SetupComplete>false</SetupComplete>

</Phase>

<Phase name="UpgradeSetupCompatBlock">

<AntUXProcess>true</AntUXProcess>

<TrayIcon>true</TrayIcon>

<Advertisement>false</Advertisement>

<ReservationPage>false</ReservationPage>

<Upgrading>true</Upgrading>

<DownloadInProgress>false</DownloadInProgress>

<DownloadComplete>false</DownloadComplete>

<ReadyForSetup>false</ReadyForSetup>

<SetupInProgress>false</SetupInProgress>

<SetupComplete>false</SetupComplete>

</Phase>

<Phase name="UpgradeSetupRolledBack">

<AntUXProcess>true</AntUXProcess>

<TrayIcon>true</TrayIcon>

<Advertisement>false</Advertisement>

<ReservationPage>false</ReservationPage>

<Upgrading>true</Upgrading>

<DownloadInProgress>false</DownloadInProgress>

<DownloadComplete>false</DownloadComplete>

<ReadyForSetup>false</ReadyForSetup>

<SetupInProgress>false</SetupInProgress>

<SetupComplete>false</SetupComplete>

</Phase>

<Phase name="UPgradeSetupFailed">

<AntUXProcess>true</AntUXProcess>

<TrayIcon>true</TrayIcon>

<Advertisement>false</Advertisement>

<ReservationPage>false</ReservationPage>

<Upgrading>true</Upgrading>

<DownloadInProgress>false</DownloadInProgress>

<DownloadComplete>false</DownloadComplete>

<ReadyForSetup>false</ReadyForSetup>

<SetupInProgress>false</SetupInProgress>

<SetupComplete>false</SetupComplete>

</Phase>

<Phase name="UpgradeSetupComplete">

<AntUXProcess>true</AntUXProcess>

<TrayIcon>true</TrayIcon>

<Advertisement>false</Advertisement>

<ReservationPage>false</ReservationPage>

<Upgrading>true</Upgrading>

<DownloadInProgress>false</DownloadInProgress>

<DownloadComplete>false</DownloadComplete>

<ReadyForSetup>false</ReadyForSetup>

<SetupInProgress>false</SetupInProgress>

<SetupComplete>true</SetupComplete>

</Phase>

</Phases>

<Triggers>

</Triggers>

</CONFIG>

Since I suspect that this might be a legitimate program added by a recent Windows Update, I wanted to ask about it here first.

Thank you!