| Status Code | Name | Command | Description |
| X | MyWebSearch Email Plugin | mwsoemon.exe | "My Web Search" malware |
| U | MyVitalAgent | VtlAgent.exe | MyVitalAgent from Lucent Technologies. Replacement for Net.Medic, monitoring all popular internet transactions and alerting the user of the loaction of connection problems. Available via Start -> Programs |
| X | MyVirt.exe | MyVirt.exe | Added by the REMADM-C TROJAN!
|
| X | MyTotalSearch Email Plugin | mtsoemon.exe | MyTotalSearchBar adware |
| U | MytekSystrayExePath | MyTekSystray.exe | MyTek system tray - web site providing computer tech support in Australia |
| ? | MySoftware NewsFlash | Newsflsh.exe | ?? |
| X | mysoft | winexplor.exe | Homepage hijacker |
| U | myprint mileage | mpm.exe | Reports battery status on a portable printer |
| X | MyPointsPointAlert | wjview ...MyPointsPointAlertrun.exe | "With MyPoints you can earn rewards from name-brand merchants. You can even earn vacations and frequent flyer miles". Dubious privacy policy |
| U | myNetWatchman | nwclient.exe | Sends your firewall alerts to a website, which then filters them and forwards details of suspicious activities to the host ISP they originated from. Only needs to be running when your firewall is running |
| X | MyLife | CmdServ.exe | Added by the HOLAR.A WORM! |
| N | MyFastAccess | myfastupdate.exe | My-Fast-Access toolbar updater |
| X | MyDailyHoroscope | MyDailyHoroscope.exe | MyDailyHoroscope foistware |
| X | MyDailyHoroscope | MYDAIL~1.EXE | MyDailyHoroscope foistware |
| X | MyCometCursor | MYCOME~1.EXE | Comet Cursor adware |
| U | myCIO.com ASaP | MyAgtTry.exe | System tray notification for McAfee VirusScan ASaP on-line scanner. Not required to be protected but you lose notifications |
| N | myCIO.com Splash | Splash.exe | Splash screen for McAfee VirusScan ASaP on-line scanner |
| Y | MyCIO Agent Service | myagtsvc.exe | McAfee VirusScan ASaP Agent service |
| X | MyAV | avpguard.exe | Added by the NETSKY.J WORM! |
| X | Myapp | service.exe | Homepage hijacker |
| X | Myapp | [filename] | Added by the FATEE.B WORM! |
| U | MyAgtTry | MyAgtTry.exe | System tray notification for McAfee VirusScan ASaP on-line scanner. Not required to be protected but you lose notifications |
| X | My Search Bar Eq | S4BAREQ.EXE | MySearch bar parasite |
| X | My App | SMSSvc.exe | Added by the NEGASMS.A TROJAN! |
| X | My Agent | msagent.exe | Added by the NEGASMS.A TROJAN! |
| U | MxRunner | MxRunner.exe | EasyUninstall from Aladdin Systems (formerly by Ontrack) |
| U | MXO Auto Loader | MXOaldr.exe | Maxtor includes a driver to bypass the Windows certified drivers check just when it detects an external drive. MXOaldr.exe is installed with the new driver and if disabled the button on a Maxtor OneTouch External Store no longer functions |
| X | MxHLp32 | MxHLp32.exe | Added by a variant of the VAGRNOCKER TROJAN! |
| X | Mwsvm | mwsvm.exe | SeekSeek search hijacker related - as seen here |
| X | mwsoemon | mwsoemon.exe | "My Web Search" malware |
| N | MWSnap | MWSnap.exe | MWSnap - screen capture utility. Start manually when required |
| N | MWProEng | MWProEng.exe | Logitech Mouseware Pro software - only required when using special functions |
| N | MutexServiceEx | Sys32Smm.exe | Webroot Sofware's discontinued "Privacy Master" |
| U | mwavscan | mwavscan.com | MicroWorld Anti Virus Toolkit is a free anti-virus scanner that runs on-demand. You can choose to scan your entire system, including memory, services, starup items and registry, or only scan files in a specified folder or drive |
| X | MusIRC (irc.music.com) client | musirc4.71.exe | Added by the RANDEX.Q WORM! |
| N | Music01 Server | Music01 Server.exe | J River Media Jukebox |
| Y | murphy shield | lmgui.exe | Firewall part of BitDefender virus scanner/firewall |
| U | MUPS | MUPS.exe | Lauches the Belkin Bulldog Plus Service - required if you want to access the UPS advanced functions |
| U | MULTIMEDIA KEYBOARD | MMKeybd.exe | Multimedia keyboard manager. Required if you use the additional keys |
| U | MultiRes | MultiRes.exe | MultiRes - system tray utility allowing quick access to changing desktop resolutions and has the ability to lock the screen refresh rate in WinNT/2K/XP |
| U | Multimedia KBD | MMKeybd.exe | Multimedia keyboard manager. Required if you use the additional keys |
| X | Multimedia extensions | mservice.exe | EasySearch adware |
| X | Multimedia Codecs | mcc.exe | Added by the MCC TROJAN! |
| U | MultiCAM Initializer | MCamBoot.exe | The MultiCAM Initializer is part of the MultiCAM software package provided by Vista Imaging in order to run up to 10 USB ViCAM or 3Com Home Connect PC Digital cameras on a single computer. Clears itself from memory once initialized but can also be safely disabled |
| U | Multi-function keyboard | GWHotkey.exe | Software that sets up the Gateway AnyKey keyboard shortcuts (a series of buttons that allow one-click access to e-mail, browser, volume and CD/DVD controls, etc) |
| ? | Mufix | mufix.exe | Part of INFOConnect, web-based, enterprise client configuration, management, and deployment software, as used by ABSS (a financial management system used by the US military which will allow purchase request packages to be electronically submitted to contracting, and which also facilitates electronic receipt of items and EFT) - what does it do and is it required |
| U | muamgr | muamgr.exe | Quick access to MicroAngelo 5.0. It can make the background of the icon text transparent and also change the color of the shortcut's text to a color you want. Very useful, if you have a wallpaper. Available via Start -> Programs |
| X | Mtr2 | mtr2.exe | Added by the KRYPTONIC GHOST TROJAN! |
| U | MUAL | mual.exe | Millesky video mail updater and launcher |
| X | MS_SETUP.EXE | MS_SETUP.EXE | Added by the CHARGE TROJAN! |
| X | MS_NETD_WIN32 | netd32.EXE | Added by the RANDEX.F WORM! |
| X | Msys32 | morfitwebentrance.exe | Morfit ADjectPager - "uses home page rental technology for generating revenues". Homepage hi-jacker that re-defines your IE or Netscape start page as http://www.web-entrance.com/. Any installed application including this must be un-installed before you can reset your homepage |
| X | msys lptt01 | msys.exe | New variant of the RapidBlaster parasite (in a "Msyss" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | mswspl | searchbarcash.exe | SearchBarCash adware |
| X | mswspl | [random filename] | Added by the SMALL.IQ TROJAN! |
| X | MSWinSrv32 | MSWinSrv32.exe | Added by the MTRON-B TROJAN! |
| X | MSWinSrv | MSWinSrv.exe | Added by the MTRON TROJAN! |
| X | Mswinpid32 | mswinpid32.exe | Added by the LAPOS.A TROJAN! This is a keylogger which emails back to China PayPal passwords and account information - thus allowing the perpetrators to steal PayPal funds in the name of the victim!
|
| X | MsWindows SysDate | sysmsvc.exe | Added by the SPYBOT.FCD WORM!
|
| X | Mswincfg | Mswincfg32.exe | Added by the CYBRSPY.D TROJAN! |
| U | MSwheel | mswheel.exe | Microsoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features |
| X | Mswavedll | mswavedll.exe | Added by the CRYPTER-C TROJAN! |
| X | mswave | mswave.exe | Added by the CRYPTER.A TROJAN! |
| X | MSVXD | MSVXD.EXE | Added by the DATOM.A WORM! |
| X | MSVSync | videosync.exe | Added by a variant of the SPYBOT WORM! |
| X | msvsc32 | msdev.exe | Added by the RBOT-GJ WORM!
|
| X | MSVersion | clrschp038.exe | Added by the POPMON.A TROJAN! - also known as PopMonster adware |
| X | MSVersion | INTERNETFEATURES.exe | Added by the POPMON.A TROJAN! - also known as PopMonster adware |
| X | msvcc | msvchost.exe | Added by the XOMBE TROJAN! |
| X | msvc32 | msvc32.exe | ClientMan parasite variant |
| X | msuser32.exe | msuser32.exe | Added by the ANDROV TROJAN! |
| X | MSUpdSrv | msupdsrv.exe | Browser hijacker, redirecting to a porn site
|
| X | msurl | msurl32.exe | Added by the CRYPTER.A TROJAN! |
| X | msupdates | msupdt.exe | Added by the RBOT-JO WORM! |
| X | MSupdater.exe | N/A | CoolWebSearch parasite related. Installs the Winshow.dll browser plugin |
| X | MSupdate.exe | N/A | CoolWebSearch parasite related - resets home page to an adult content site |
| X | msupdate | msupdate.exe | Added by the RBOT-MZ WORM!
|
| X | MSUpdate | svchosthlp.exe | Added by the BLASTER.T WORM! |
| X | MSUpdate | wupd.exe | Added by the ALADINZ.M TROJAN! |
| X | Mstng32 | MSTng32.exe | Added by the TANG WORM! |
| ? | Mstcgww | MSTCGWW.EXE | ?? |
| X | mstasks | mstasks.exe | Added by the MULTIDR-AY TROJAN! |
| X | Mstask | mstask.exe | Added by the OPASERV.N WORM! Note - this is not the legitimate mstask.exe system file and the executable resides in C:Windows or C:WINNT |
| X | Mstapi | Mstapi.exe | Keylogger trojan |
| X | MsSystem | mssys.exe | Added by the VANTA.A TROJAN! |
| X | MsSystem | msdos.exe | Adult content downloader - see here |
| X | mssyslanhelper | msmsgri32.exe | Added by the RANDEX.D WORM! |
| X | mssysint | Iexplore .exe | Added by the PWSTEAL.ABCHLP and PSPIDER.310.B TROJANS! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
| X | mssys | mssys.exe | Added by the MYSS.B TROJAN! |
| Y | MSSVC.EXE | MSSVC.EXE | Stealthdisk - hides folders, files and applications. Will also encrypt them for better protection |
| X | mssvc32 | mssvc32.exe | Added by the AGOBOT-ME WORM! |
| X | mssvc | [path to trojan] | Added by the PSK TROJAN! |
| X | mssurfer ml097e | mssurfer.exe | Variant of the RapidBlaster parasite (in a "surfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | mssurfer lptt01 | mssurfer.exe | Variant of the RapidBlaster parasite (in a "surfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | msstask | msstask.exe | Added by the MYPARTY WORM! |
| X | MSStartOptimizer | WINUPD.EXE | Adult content dialler - see here. This has to be cleared at the same time as RegCompres (REGCPM32.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), otherwise they return |
| X | MSStartOptimizer | Iexpres.exe | Added by the POLDO.B TROJAN! |
| X | Msstart | msstart.exe | Added by the LIVUP.C TROJAN! |
| X | mssoul | msmscc2.exe | Added by the DAPIZL.A banker WORM! (A "banker worm" is designed to pillage banking information and send it back to the perpetrators!)
|
| X | MSSQL | Mssql.exe | Added by the SDBOT TROJAN! |
| X | MSSHVC | MSSHVC.exe | Added by the NUFFY.A WORM! |
| X | msservice | msserv.exe | Added by the HYD WORM! |
| X | msrunocx32 | msrunocx32.exe | Added by the SKUS WORM! |
| X | MSRegSvc | regsvc32.exe | Homepage hijacker that changes your homepage to an adult content site |
| X | msreg.exe | msrege.exe | Added by the ZINX TROJAN! |
| X | MSREGIT | Msgp.exe | Added by the KRYPGHOS.13 TROJAN! |
| X | Msrc | Msrc.exe | Added by the KRYPTONIC GHOST TROJAN! |
| N | MSPY2002 | ImScInst.exe | Part of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word |
| U | mspwr | pupstman.exe | "Transparent icon background" feature of Ashampoo's PowerUp XP (WinNT/2K/XP) and PowerUp Deluxe (Win98/Me) |
| X | MSprotect.exe | MSprotect.exe | Added by the DABYREV.A VIRUS! |
| X | MSPQFile | MSA****.TMP | Homepage hijacker. See here for more information. **** can be anything |
| X | Mspatch89 | cnqmax.exe | Added by the RANDEX.P WORM! |
| X | MSOOBD | MSOOBD.EXE | Added by the MAGISTR.A VIRUS! |
| X | Mspatch69 | [path to trojan] | Added by the MPROX TROJAN! |
| X | MSOffice | services.exe | Browser hijacker. The file is placed in a newly created MSOffice folder in System32. Note - this is NOT the legitimate services.exe process, which should NOT figure in Msconfig/Startup!
|
| X | MSNSysRestore | pc32.exe | Added by a variant of the MASTAK VIRUS! |
| X | MSObject32 | MSObject32.js | Added by the PUN TROJAN! |
| X | Msoffice | msoffice.hta | Hijacker - redirecting to Searchdot.net |
| X | MSNService | MSNService.exe | Added by the CARPET.C WORM! |
| X | msnmsgsgs | msnmsgsgs.exe | Added by the "Catal" alias Spy.Delitall.B backdoor TROJAN!
|
| X | MSNMSGRS1 | swed.bat | IRC backdoor TROJAN or WORM! |
| X | MSNMSGRE | swef.bat | IRC backdoor TROJAN or WORM! |
| X | MSNMSGRR | swin.bat | IRC backdoor TROJAN or WORM! |
| X | MSNMSGR5 | MSNMSGR5.exe | Added by the RBOT.PQ WORM! |
| X | msnmsgr32-.exe | msnmsgr-.exe | Added by a variant of the SPYBOT WORM! |
| X | MsnMsgr | MsnMsgrs.exe | Added by the NETSKY-AD WORM!
|
| N | msnmsgr | msnmsgr.exe | MSN Messenger utility. If you don't use MSN Messenger, this can be annoying. Available via Start -> Programs. Go to MS Messenger > Tools > Options > Preferences and uncheck "Run this program when Windows starts" |
| X | MSNMESENGER | Main.exe | Added by the PRORAT TROJAN! |
| X | msnload32.exe | msnload32.exe | Added by the BANCOS.M TROJAN! |
| N | MSNIA | MSNIASVC.EXE | Added with MSN version 9. Resets certain internet settings upon bootup and can't be disabled via MSCONFIG |
| X | MSNGrabber | MSNgrabber.exe | Added by the ENVID.A WORM!
|
| ? | MsnFixer | msnfixjs.js | Located in the HPbinmsnfix directory of a HP PC |
| X | MSNET | msnet.exe | Added by the BOA WORM! |
| X | Msnarrator | msnarrator.exe | Added by the NARAT.A TROJAN! - also identified as MPGCOM Toolbar adware |
| N | msnappau | msnappau.exe | Updater for the MSN toolbar that can be downloaded onto IE. Calls home every day or so to "update" the toolbar |
| X | MSN UPDATERS | virtualmemory.exe | Added by the RBOT-JK WORM! |
| X | Msn Updater | msnplugins.exe | Added by the RBOT-HS WORM! |
| X | MSN Updater | msnms.exe | Added by the FORBOT-CG WORM!
|
| X | Msn Update Manager (Sp2) | MSMSGS.EXE | Added by the AGOBOT-NL WORM!
|
| X | MSN Start | msnmsgr7.exe | Added by the RBOT-PH WORM!
|
| N | MSN Quick View | Msndc.exe | Quick way to connect to MSN internet service |
| X | Msn Plus Updater | msnplus.exe | Added by the RBOT-MU WORM! |
| X | Msn Messengers | MSNMSGR.EXE | Added by the RBOT.KX WORM! |
| X | MSN messenger service | mssgs.exe | Added by an unidentified TROJAN! Note - this is not the real MSN Messenger, see this thread |
| X | MSN messenger | messenger.exe | Added by an unidentified TROJAN! Note - this is not the real MSN Messenger, see this thread |
| X | MSN Messanger | msnmsng.exe | Added by the SDBOT.XN WORM! |
| X | MSN Manager | cvss.exe | Added by a variant of the SPYBOT WORM! |
| N | MSN Internet Access | trayclnt.exe | Quick way to connect to MSN internet service - replaces "MSN Quick View" from V5.6 onwards |
| X | Msn Config | msngf.exe | Added by the RBOT-QG WORM! |
| X | MSN ang | cssrss.exe | Added by the FORBOT-CE WORM!
|
| X | MSN | ctfmoons.exe | Added by the SPYBOT.HI WORM!
|
| X | MSN | msnmsgs.exe | Added by the RBOT-KL WORM! |
| X | msn | msnmsg.exe | Added by the RBOT-GO WORM! |
| X | msn | system32.exe | Added by the KITRO.A WORM! |
| X | MSMsgSvc | MSMSGSVC.exe | Browser hijacker, identified by some antiviruses as a variant of the StartPage.QC TROJAN!
|
| U | MSMSGS | msmsgs.exe | Windows Messenger utility. If you don't use Windows Messenger, this can be annoying. Available via Start -> Programs. Go to Windows Messenger > Tools > Options > Preferences and uncheck "Run this program when Windows starts" |
| ? | MsmqIntCert | regsvr32 /s mqrt.dll | Microsoft Message Queue Server - Internal Certificate - see here for more info and here for a potential problem. Is it required? |
| X | msmon | msmon.exe | Added by a variant of the GEMA.D TROJAN! |
| X | Msmgt | msmgt.exe | Total Velocity adware/hijacker |
| ? | msmgr | msmgr.exe | ?? |
| X | MSMcAfeeS | Avsynmgr32S.exe | Added by the VOLAC or VOLAC.DR TROJANS! |
| X | MSMcAfeeh | Avsynmgr32h.exe | Added by the FRANGO TROJAN! |
| X | MSMcAfeee | Avsynmgr32e.exe | Added by the FRAMAR TROJAN! |
| X | msmc | msmc.exe | ClientMan parasite variant |
| X | msmc | msongn.exe | ClientMan parasite variant |
| X | msmc | msgdmf.exe | ClientMan parasite variant |
| X | msmc | mscpbo.exe | ClientMan parasite variant |
| X | MsManager | msmgr32.exe | Added by the YAHA.AF WORM! |
| X | msmanager32 | msmngr32.exe | Added by the RANDON-R (or WOMANIZ.A) WORM! |
| X | Mslogon ml097e | mslogon.exe | Variant of the RapidBlaster parasite (in a "Mslogon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| ? | MSLIB32 | mswatch32.exe | ?? |
| X | Mslogon lptt01 | mslogon.exe | Variant of the RapidBlaster parasite (in a "Mslogon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | mslagent | mslagent.exe | Added by SIMCSS.B adware! |
| U | MSKServerExe | MSKSrvr.exe | Part of McAfee Spamkiller
|
| U | MSKExe | spamkiller.exe | McAfee SpamKiller |
| X | MSKernel32 | MSKernel32.vbs | Added by the LOVELETTER (I LOVE YOU) VIRUS! |
| X | MSkernel32 | System.exe 4820 | Added by the TUXDER TROJAN! |
| U | MSKDetectorExe | MSKDetct.exe | Part of McAfee Spamkiller |
| X | MSKCES32 | [random filename] | Added by the CLONER TROJAN! |
| U | MSKAGENTEXE | MskAgent.exe | Part of McAfee Spamkiller |
| X | msjava service | xpcd.exe | Added by the SDBOT.VM WORM! |
| X | MSInfo | AVBgle.exe | Added by the NETSKY.O WORM! |
| X | MSInfo | msinfo.exe | Added by the ALADINZ.M TROJAN! |
| X | MSIEXEC | MSIEXEC32.exe | Added by the AINESEY.A WORM! |
| ? | MSIN | MSin.exe | ?? |
| X | msidle | msidle.exe | Added by the OPASERV-O WORM! |
| X | MSHT@ | MSHT@.EXE | Added by the MAGISTR.A VIRUS! |
| X | Msgtray | sys16.exe | Added by an unknown VIRUS! |
| X | msgsvr32 | msgsvr32.exe | Added by the DEADHAT.B WORM! Note - not to be confused with the valid "msgsrv32.exe" file which resides in the same directory (C:WindowsSystem) on a Win9x/Me machine |
| Y | MSGSRV32.exe | msgsrv32.exe | Windows 32-bit VxD Message Server. For more information on its function and why it's needed, see here. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background |
| X | Msgsrv16 | Msgsrv16.exe | Added by the DELF family of TROJANS! |
| X | msgserv_ | Syss.exe | Added by the FANTA TROJAN! |
| X | Msgmgr | [path to worm] | Added by the BABYBEAR WORM! |
| X | msgb1 | msgb1.exe | Added by the DLUCA.GEN TROJAN! |
| X | MsgApi | [path to file] | Added by the DEDLER-D TROJAN! |
| X | msfindosa.exe | msfindosa.exe | Added by the DOWNLOADER-BS TROJAN! |
| X | MSFind32 | msfind32.exe | Added by the CAYAM WORM! |
| X | Msfind | Msfind.exe | CoolWebSearch parasite variant |
| N | MSDTC | msdtc.exe | MS Distributed Transaction Coordinator - handles transactions across multiple servers and is installed by MS Personal Web Server and MS SQL Server |
| X | Msemu32 | Msemu32.exe | Unidentified spyware/adware/hijacker |
| N | MSDosdrv | msdosdrv.exe | Added by the BACROS WORM! |
| X | msdos423 | msdos423.exe | Added by the MENACE.A WORM! |
| X | Msdmxm | msdmxm.exe | Adult premium rate dialler |
| X | Msdos32 | Msdos32.pif | Added by the RECORY WORM! |
| X | MSDLL | syscnfg.exe | Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
| X | msdev | msconfig.exe | Added by the AGOBOT.AAU WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting |
| X | msdev | msdev.exe | Added by the FORBOT-CR WORM! |
| X | MSCVT | MSCVT.exe | Added by the SLIDESHOW WORM! |
| X | Msctrl32 | Msctrl32.scr | Added by the REDIST WORM! |
| X | Mscsgs32 | MSCSGS32.EXE | Added by the ZEZER WORM! |
| X | Mscsgs | MSCSGS.EXE | Added by the ZEZER WORM! |
| X | MSCORE | syscnfg.exe | Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
| N | MSConfigReminder | msconfig.exe | Entry that appears when you uncheck an item in the MSConfig Startup group, and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode |
| X | MSConfigr | jdbgmrg.exe | Added by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here |
| X | msconfig.exe | proxy.exe | Added by a variant of the AGENT.AH downloader TROJAN! |
| X | msconfig.exe | uline.exe | Added by a variant of the AGENT.AH downloader TROJAN! |
| X | MSConfig45 | MSConfig45.exe | Added by the SDBOT.OJ TROJAN! |
| X | msconfig service | MSupdate32.exe | Added by a variant of the SPYBOT WORM! |
| X | Msconfig ml097e | msconfig.exe | Variant of the RapidBlaster parasite (in a "msconfig" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Windows Msconfig which has the same executable name |
| X | MSConfig Manager | msupdate.exe | CoolWebSearch parasite related |
| X | Msconfig lptt01 | msconfig.exe | Variant of the RapidBlaster parasite (in a "msconfig" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Windows Msconfig which has the same executable name |
| X | msconfig | wins.exe | Added by an unidentified IRC WORM with backdoor trojan capabilities!
|
| X | Msconfig | msconfig.exe | Added by the WINUR WORM! Note - this is not the real msconfig.exe as it's located in C:winrun |
| X | msconfig | msconfig.exe | CoolWebSearch parasite related. Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting |
| X | MSConfig | MSCONFIG32.EXE | Unidentified adware, spyware or virus |
| N | MSConfig | msconfig.exe | Entry that appears when you uncheck an item in the MSConfig Startup group, and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode |
| X | MSCONFG32.EXE | MSCONFG32.EXE | Added by the OPTIX.04.C TROJAN! |
| X | Mscolour | mscolour.exe | Added by the GEMA TROJAN! |
| X | MSCommX | mscommx.exe | Added by a variant of the RBOT WORM! |
| X | Mscnt | mscnt.exe | Adult content dialler |
| U | mscn | mscn.exe | Part of the SafeChildNet internet filtering program - required if you use it |
| X | mscman | mscman.exe | Spyware/malware, included into the latest version of Grokster, among others. According to research by SpyBot's PMK, "able to trick ZoneAlarm, auto-clicking it to allow passing through the firewall!" |
| ? | msci | mcinfo.exe | McAfee Internet Security related. What does it do and is it required? |
| X | MSBB | msbb.exe | Advertising spyware |
| X | MSChoExE | suge.exe | Added by a variant of the RBOT WORM!
|
| X | MSAgent | mshtm.exe | Browser hijacker - redirecting to buldog-search.com
|
| X | msadcheck | msadcheck32.exe | Browser hijacker, redirecting to search-system.com
|
| X | MSAdmin | jdbgmrg.exe | Added by the DASMIN.A TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here |
| X | MSACM | msacm.exe | Added by the OPASERV-O WORM! |
| X | MS-RunKey | arr.exe | MS-Connect dialler/hijacker |
| X | MS7531 | ms7531.exe | Homepage hijacker |
| X | MS-HTML | [random filename] | Added by the LATINUS.15 TROJAN! |
| X | MS-Connect | web.exe | Adult content dialler - see here |
| X | MS-Connect | msite18.exe | Adult content dialler - see here |
| X | MS-Connect | game.exe | Adult content dialler - see here |
| X | MS-Connect | cdm.exe | Adult content dialler - see here |
| X | MS-Connect | arr.exe | Adult content dialler - see here |
| X | MS Updates | aupd.exe | Spyware web downloader |
| X | MS Updates | mscache.exe | Spyware web downloader |
| X | MS Updates | syshosts.exe | Added by the MYDOOM.Y WORM! |
| X | MS Update | syshost.exe | Added by the EVAMAN-F WORM! |
| X | MS SyS Restore | sysrestore.exe | Added by the RBOT.XM WORM! |
| X | Ms Spool32 | MS SPOOL32.EXE | Added by the ASASSIN TROJAN! |
| X | MS Sound Config 16bit | sndcfg16.exe | Added by the SDBOT.MB TROJAN! |
| X | MS Security Hotfix | service5.exe | Added by the GAOBOT.AG WORM! |
| X | MS Network Control | mswin.exe | Added by the DUMBA TROJAN! |
| X | MS Remote Procedure Call | msrpc32.exe | Added by the RBOT-QL WORM! |
| ? | MS management console | mms.exe | Suspicious as the Microsoft Management Console is "mmc.exe" and doesn't normally run at startup |
| X | MS lsass Startup | lsass135.exe | Added by the RBOT.WM WORM! |
| X | MS HTML | mslat.exe | Added by the LATINUS.SVR TROJAN! |
| X | MS HTML | msHtml.exe | Added by the PESTDOOR.31 TROJAN! |
| X | MS FIREWALL | msfirewall.exe | Added by the SDBOT-QH WORM!
|
| X | MS FIREWALL | msfrewall.exe | Added by the SDBOT-PU WORM! |
| X | MS Explorer | mexplore.exe | Added by the YAHA.AE WORM! |
| X | MS Decryption Software | active.exe | MediaTickets adware variant |
| X | MS Configuration | MSFramer.exe | Added by the RANDEX.OL WORM! |
| X | MS Config Service | Msloader32.exe | Added by the RBOT-KJ WORM! |
| X | MS Config Loader | MSWin32bck.exe | Added by the GAOBOT.AA WORM! |
| X | MS Config Loader | svchos1.exe | Added by the AGOBOT.R WORM! |
| N | MRU-Blaster Silent Clean | mrublaster.exe | MRU-Blaster - performs silent cleaning of MRU lists at boot |
| U | MRU-Blaster Scheduler | scheduler.exe | MRU-Blaster scheduler - detects and cleans MRU (most recently used) lists on your computer |
| X | mqbkup | mqbkup.exe | Added by the OPASERV.K WORM! |
| N | mrtMngr | mrtMngr.exe | Maintenance Release Task Manager for Intuit?s QuickBooks or Quicken |
| ? | MP_STATUS_MONITOR | monitr32.exe | Related to Cannon Multi-Pass |
| N | MPXTray | mpxptray.exe | Windows Media Player PowerToy which is run from the taskbar. It can be used to hide Windows Media Player (when in use) and choose various standard buttons (play/pause, next,previous) etc |
| N | MPTBox | MPTBOX.EXE | Cannon Multi-Pass toolbox - a button bar |
| X | MPtask Services | mptask.exe | Added by the LALA or AOT TROJANS! |
| ? | MPT | MPT.exe | ?? |
| U | MPSExe | mscifapp.exe | McAfee.com Privacy Service - "combines personal identifiable information (PII) protection with online advertisement blocking and content filtering" |
| X | MprHTML | MprHTML.exe | Added by a variant of the VAGRNOCKER TROJAN! |
| Y | MPREXE.exe | mprexe.exe | WIN32 Network Service Interface Process. MPREXE.exe enables the computer to have multiple clients/protocols for networks. There are some problems with it sometimes though - see here and here. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background. NOTE : sometimes it will appear in start-ups if you have a virus |
| X | MPREXE | MPREXE.EXE | Added by the OPASERV.T WORM! Note - this is not the legitimate Mprexe.exe system file |
| U | MPower | MPower.exe | MPower from MindBeat. "Defragments and frees your RAM giving more stability to your system and avoiding needless use of swap file. Willl also benchmark (speed test) your hard disk drives and your CPU load". Some users swear by programs such as this but I suggest you read this article and make up your own mind |
| X | MPL32 driver | MPL32.exe | Added by the LOONY-M TROJAN! |
| U | MplSetup | MplSetup.exe | Used by Ricoh network printers to enable network printing from the client |
| Y | MPFExe | mpf.exe | McAfee Personal Firewall |
| Y | MPFExe | MpfTray.exe | McAfee Personal Firewall |
| U | MPEO | Csinsm32.exe | Automatic logging of installs from Norton CleanSweep - available via Start -> Programs |
| X | MP Tcloaxs | mptcloaxs.exe | Added by the RANDEX.CT WORM! |
| N | Mozilla Quick Launch | Mozilla.exe | Netscape 6 and Mozilla browsers |
| X | Movieplace | Movieplace.exe | MoviePlace malware |
| N | Mozilla Quick Launch | Netscp6.exe | Netscape 6 and Mozilla browsers |
| X | MovieNetworks | MovieNetworks.exe | MovieNetworks will connect you by DOMESTIC PREMIUM RATE TELEPHONE NUMBER 900-xxx-xxxx. So you get xxx rated pictures and junk. And it will allow you to stay on the internet on their line and $$$ and remove the C:Program FilesMovieNetworks directory |
| N | Movielink Manager Uninstall | msvcmm32.exe | Auto-update for Movielink - internet movie rental System Tray access |
| U | Mousinfo | mousinfo.exe | MS mouse information tool - for troubleshooting mouse problems |
| U | mouseElf | MC.exe | Genius NetScroll mouse driver - required if you use non-standard Windows driver features |
| U | MouseImp | MImpHost.exe | MouseImp Pro - "A reliable assistant that turns your mouse into a simple, native but powerful controlling device" |
| X | mousedrv | mousedrv.exe | Added by the CRYPTER.A TROJAN! |
| N | MouseCount | MC.exe | MouseCount by Kittyfeet Software. "Utility for counting how many times us computer junkies click our mouse in a given session/day/week/month/year." Not required |
| X | Mousecntl | mousecntl.exe | Added by a variant of the CRYPTER.C TROJAN! |
| X | mousebut | mousebut.exe | Added by the CRYPTER.A TROJAN! |
| N | Mouse Suite 98 Daemon | pelmiced.exe | Mouse driver. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games |
| N | Mouse 32A | Mouse32A.exe | Mouse driver to control mouse functions from Azona. Available via Start -> Programs |
| U | Mount Safe & Sound | Fbmount.exe | From McAfee VirusScan version 5.x. Creates back-up sets of critical files in a separate area of a hard drive. If you make regular back-ups it's not needed and can be painful during system start |
| U | MotMon | motmon.exe | Found on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used?the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it's not required |
| N | MotiveSB | MotiveSB.exe | System tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required |
| U | MotiveMonitor | motmon.exe | Found on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used?the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it's not required |
| N | Motive SmartBridge | MotiveSB.exe | System tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required |
| N | Motive SmartBridge | mpbtn.exe | System tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required |
| X | mosearch | mosearch.exe | Fast Search in Office XP - similar to the new revision of the Find Fast feature in Office 2000. Fast Search uses the Indexing Services in Office XP to create a catalog of Office files on your computer's hard disk. As with Find Fast - a waste of resources. If it can't be disabled via MSCONFIG try here |
| N | Morpheus | morpheus.exe | MusicCity Networks' Morpheus - another peer-to-peer client based on Kazaa. Notable in that this one doesn't seem to install the adware that clog the Kazaa download. They claim they are adware free, and a visitor quotes "I have seen no instance of any since using it" |
| N | moon phase | moon.exe | Moon Phase - tray icon that indicates the phases of the moon |
| U | MoodBook | mb.exe | MoodBook is a free Windows utility that brings art to your desktop |
| N | Monstersoundtray | Freectrl.exe | Diamond Multimedia sound card control panel |
| X | Monitormgt | Monitormgt.exe | Added by the GEMA TROJAN! |
| U | Monitor Apache Servers | ApacheMonitor.exe | Part of the Apache Web Server package. Useful only if you're running such a server on your PC. Available via Start -> Programs |
| X | Monitoring Service | svchost.exe | Added by the CONE.C WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| N | MoneyStartUp | Money Startup.exe | Microsoft Money |
| N | MoneyStartUp10.0 | Activation.exe | Part of MS Money 2002. Available via Start -> Programs |
| N | MoneyAgent | money express.exe | Part of MS Money. Available via Start -> Programs |
| N | MoneyAgent | mnyexpr.exe | Microsoft Money |
| N | Money Express | moneyexpress.exe | Part of MS Money. Available via Start -> Programs |
| X | Module Call initialize | RUNDLL32.EXE reg.dll, ondll_reg | Added by a variant of the LOVGATE WORM! |
| X | ModularConfig | syscnfg.exe | Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
| N | ModemUtility | mdmsetpe.exe | System Tray configuration icon for Aztech modems |
| U | ModemOnHold | MOH.EXE | NetWaiting Modem-on-Hold Application |
| U | MODEMBTR | MODEMBTR.EXE | Modem Booster from inKline Global to improve ISP connections |
| X | Modeminf | Modeminf.exe | Added by a variant of the CRYPTER.C TROJAN! |
| N | MOD | muamger.exe | MicroAngelo On Display from Impact Software lets you customize Windows icons. With a few exceptions, you can customize icons by right-clicking on them |
| X | MOBSYNC32.EXE | mobsync32.exe | Added by the FINERO TROJAN! |
| N | mobsync | mobsync.exe | MS Syncrhonization Manager - updates the network copy of materials that were edited offline, such as documents, calendars, and e-mail messages |
| X | mnsvcsp | mnsvcsp.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | mnsvc | mnsvc.exe | Added by the AUTOUPDER TROJAN! |
| U | MNS | MNS.exe | Mobile Net Switch enables you to use your computer on more then one network with the click of a button. It allows you to automatically select the correct drive mappings, printer settings, IP settings and much more |
| X | MNPol | mnpol.exe | Adult content dialler |
| X | mmxrun | msosa.exe | Adult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), atisrc2 (windfind.exe) and RegCompres (REGCPM32.EXE), otherwise they return |
| ? | mmusrstp | procrun.exe | ?? |
| N | MMTrayLSI | MMTrayLSI.exe | Part of Morgan Multimedia Codecs. Only required when the codecs are used |
| N | MMTray2K | MMTray2K.exe | Part of Morgan Multimedia Codecs. Only required when the codecs are used |
| N | MMTray | MMTray.exe | Part of Morgan Multimedia Codecs. Only required when the codecs are used |
| N | MMTray | mm_tray.exe | MusicMatch Jukebox icon in the task tray - digital music player / CD burner and ripper / music organizer / playlist creator |
| X | MMtask Service | mmtask.exe | Added by the BACKGAT.A TROJAN! Not the valid MusicMatch Jukebox which has the same filename |
| N | mmtask | mmtask.exe | Part of MusicMatch Jukebox - digital music player / CD burner and ripper / music organizer / playlist creator |
| Y | MMTASK | mmtask.tsk | A check on the file's properties reveals "Multimedia background task support module". MMTASK is a very simple 16-bit program used by certain multimedia drivers (which are still 16-bit on Win9x) to perform background processing. Some soundcards need this to support MIDI, etc |
| X | MMSystem | RunDll32 | Added by the FUNNER-A WORM!
|
| ? | mmsys | recover.exe | ?? |
| ? | MMRun | mmrun.exe | ?? |
| N | mmpti | m1mmpti.exe | Mpact Mediaware Properties Taskbar Icon - multimedia software icon for Chromatic Research Mpact video cards |
| X | mmod | mmod.exe | Ezula - regarded as spyware/theftware and bundled with the popular iMesh and KaZaA file-sharing programs. Read here for more information |
| U | MMKeybd | MMKeybd.exe | Multimedia keyboard manager. Required if you use the additional keys |
| N | MMHotKey | MMHotKey.exe | Multimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen |
| ? | MMHK | mmhk.exe | A driver found on a Compaq Presario 800T notebook. Possibly something to do with multimedia hot keys? |
| U | MMhid | mmhid.dll | This is the Human Interface Device Server for Win98, it is required only if you are using USB Audio Devices you can disable via Msconfig. See here. Typical examples are USB multimedia keyboards with volume control and web-ready keyboards. For example - loaded by default with MS DSS80 Speakers because they have Volume, Mute and Bass controls on the speaker. Some users may experience problems disabling this - if this is the case then re-enable it. Equivalent to Hidserv in Win98SE/2000/Me/XP |
| X | Mmgsvc | mmgsvc.exe | Mmgsvc spyware
|
| U | MMERefresh | MMERefresh.exe | Part of Digidesgin Protools. Refreshes your midi ports on the 002(R) (the 002R is a hardware audio/midi converter connected to your computer via firewire). Must be running in order to use the MIDI functionality of the Digi002R |
| N | MMCWINMGMT | winmgmt.exe | Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here |
| X | mmcndmgr | mmcndmgr.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| ? | MM Install | setup.exe | Possibly Money Manager from Moneysoft? |
| X | mload | lxmstart.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| N | Mixghost | mixghost.exe | Management software for Altec Lansing speakers. If a change is needed, the user can launch it from the Start menu |
| N | Mixer | Mixer.exe | C-Media Mixer - C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start -> Settings -> Control Panel or Start -> Programs |
| ? | misiCTRL | misiCTRL.exe | Miro video driver related. Is it required? |
| ? | misiTRAY | misiTRAY.exe | Miro video driver related. Is it required? |
| U | MirrorFolderShell | mrfshl.exe | MirrorFolder backup software |
| N | miroVIDEO Tray Tool | misitray.exe | Tool for quickly changing options for miro/Pinnacle capture cards during capture/playback/output. When this program is closed, another program (mv-ctrl) is also closed, but mv-ctrl does not have its own EXE file. Only needed when using the capture card, e.g. for the above actions |
| X | Mirate Sp 2 Information | miratesp2.exe | Added by the RBOT.QH WORM!
|
| N | Mirabilis ICQ | ICQNet.exe | If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs |
| U | Miramar Systems, Inc. | atmsg.exe | Miramar PC/Mac networking software |
| N | Mirabilis ICQ | icq.exe | If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs |
| X | Miosf Update | wimsqaad.exe | Added by the SDBOT.AG TROJAN! |
| N | Mirabilis ICQ | NDetect.exe | If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs |
| U | MinMaxExtender | Mmext.exe | MinMaxExtender - window handling tool |
| N | MiniNote | MININOTE.EXE | Mini NoteTab was the first in the family of "NoteTab" text and HTML editors from Fookes Software |
| N | MiniMavis | MiniMavis.exe | Mavis Beacon typing tutor |
| U | minilog | MINILOG.EXE | If you don't have ZoneAlarm or ZoneAlarm Pro running you don't need this. This must be enabled if programs such as VisualZone Report utility or ZoneLog Analyzer are in use |
| N | MINIFERT.EXE | MINIFERT.EXE | Part of Backweb |
| ? | MigrationVendorSetupCaller | rundll32.exe migrate.dll, CallVendorSetupDlls | ?? |
| X | MINIBUG | MINIBUG.EXE | Displays ads inside Weatherbug - see here |
| N | MightyFAX Controller | MFNTCTL.EXE | Mighty FAX from RKS Software - "installs a printer driver so that you can fax directly from Windows software" |
| X | Micrsoft Driver | windrive.exe | Added by the SDBOT.AF TROJAN! |
| X | Microzoft_Ofiz | KdzEregli.exe | Added by the AMUS.A WORM! |
| X | Microszoft Update Mach1nezs | svchst.exe | Added by the RBOT-ED WORM!
|
| X | Microsoft? System Mapper | SysMap.exe | Added by the MAPSY TROJAN! |
| X | Microsoft? PID Lex | PIDLex.exe | Added by the NIOVADOOR TROJAN! |
| X | MicrosoftWindows | [various filenames] | MagicSearch - a CoolWebSearch parasite variant |
| X | Microsoftvirus | sysoverload.exe | Added by the FORBOT-AL WORM! |
| X | MicrosoftValue | syscnfg.exe | Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
| X | MicrosoftUpdate | syshelper.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | MicrosoftUpdate | WinUp32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | MicrosoftSourceSafe | lsass.exe | Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup! |
| X | MicrosoftServiceManager | msupdat.exe | Added by the YAHA.AA WORM! |
| X | MicrosoftServiceManager | EXPLORERE.EXE | Added by the YAHA.AB WORM! |
| X | MicrosoftServiceManager | Wintsk32.exe | Added by the YAHA.U WORM! |
| X | Microsofts Updatez | cmsssr.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | MicrosoftServiceManager | mstask32.exe | Added by the YAHA.P WORM! |
| X | MicrosoftNetwork Daemon for Win32 | NETD32.EXE | Added by the RANDEX.F WORM! |
| X | MicrosoftMultimediaTask | Mmtask.exe | Adware downloader - not the valid MusicMatch Jukebox which shares the same filename |
| X | Microsoftmsn32.exe | microsoftmsn32.exe | Added by the CERTIF-C TROJAN!
|
| X | Microsoftkeysd | systemwin32s.exe | Added by the WOOTBOT.CO WORM! |
| X | microsoft420 | microsoft420.exe | Added by the MENACE.B WORM! |
| X | Microsoftkeysd | systemproc.exe | Added by the FORBOT-BI WORM!
|
| X | Microsoft-Updates | svxhost.exe | Added by the RBOT-CT WORM! |
| X | Microsoft-Update | wngard.exe | Added by the RBOT-JV WORM! |
| X | Microsoft XML Service | msxmlx.exe | Added by the RBOT.KS WORM! |
| X | Microsoft--Updates | sxvhost.exe | Added by the RBOT-FH WORM! |
| X | microsoft xdaemon 2.0 | xdaemon.exe | Added by the DELF.D TROJAN! |
| X | Microsoft Wxdate | Syswu32.exe | Added by the SPYBOT.HZ WORM! |
| X | Microsoft World Service | winworld.exe | Added by an unidentified IRC worm with backdoor capability!
|
| N | Microsoft Works Update Detection | wkdetect.exe | Checks for updates to MS Works |
| N | Microsoft Works Portfolio | WksSb.exe | The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program.Can be prevented from starting from a setting within Portfolio |
| N | Microsoft Works Calendar Reminders | wkcalrem.exe | Produces a pop-up reminder of events scheduled using the MS Works Calendar |
| X | Microsoft WinUpdate | syswin32.exe | Added by a variant of the SDBOT WORM! |
| X | Microsoft WinUpdates | serm32.exe | Added by the RBOT.GE WORM! |
| X | Microsoft WinUpdate | syslx32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Microsoft WinUpdate | svh0st.exe | Added by the SPYBOT.DL WORM! |
| X | Microsoft WinUpdate | mntcgf032.exe | Added by a variant of the SDBOT WORM! |
| X | Microsoft Winsock Wrapper | ws2_32s.exe | Added by a variant of the SPYBOT WORM!
|
| X | Microsoft Windows Updates | explorer32.exe | Added by the SDBOT.VQ WORM!
|
| X | Microsoft Windows updaterD | log32zx.exe | Added by the MYDOOM.W WORM! |
| X | Microsoft Windows Updater | WINUPDATE.EXE | Added by the SDBOT-PU WORM!
|
| X | Microsoft Windows Updater | svchostz.exe | Added by the DAEMONI-E TROJAN! |
| X | Microsoft Windows Updater | WINIUPDATES.EXE | Added by the RBOT-KK WORM! |
| X | Microsoft Windows Update Service | wupdmgr32.exe | Added by the DOS.AUTOCAT TROJAN! |
| X | Microsoft Windows Updater | winupdgm.exe | Added by the GAOBOT.BI WORM! |
| X | Microsoft Windows Update | svmhost.exe | Added by the FORBOT-CH WORM!
|
| X | Microsoft Windows Update | svshost.exe | Added by the WOOTBOT.CJ WORM!
|
| X | Microsoft Windows Update | svcshost.exe | Added by the FORBOT-CF WORM!
|
| X | Microsoft Windows Update | svchos.exe | Added by the SDBOT.AC WORM! |
| X | Microsoft Windows Update | spools.exe | Added by the SDBOT.TD WORM! |
| X | Microsoft Windows Update | msoffice2.exe | Added by the RBOT-GB WORM! |
| X | Microsoft Windows Update | rundlls.exe | Added by the HABRACK WORM! |
| X | Microsoft Windows Task Manger | Mstosk.exe | Added by the SDBOT-WW WORM! |
| X | Microsoft Windows Secure Server | rpcxWindows.exe | Added by the RBOT-LL WORM! |
| X | Microsoft Windows Loader | wloader.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Microsoft Windows Kernel Services | winkrnl386.exe | Added by the ZEBROXY TROJAN! |
| X | Microsoft Windows GUI | Windowz.exe | Added by the RANDEX.AEV WORM! |
| X | Microsoft Windows DHCP | ___r.exe | Added by the MASLAN.A WORM! |
| X | Microsoft Windows 2000 | Winupdsdgm.exe | Added by the GAOBOT.AO WORM! |
| X | Microsoft Windows | mstask0.exe | Added by the SDBOT.FQ WORM! |
| X | Microsoft Visual Studio VSA | varpc32.exe | Added by a variant of the SPYBOT WORM! |
| U | Microsoft Webserver | svctrl.exe | Personal web server program which enables you to create and host a web server from your computer. Not required for most people |
| X | Microsoft Visual SourceSafe | winlogon.exe | Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup or the Microsoft Visual SourceSafe program |
| X | Microsoft Visual SourceSafe | services.exe | Added by the NEVEG.B or NEVEG.C WORMS!. Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup or the Microsoft Visual SourceSafe program |
| X | Microsoft Video Controls | tskmsgr.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft upnp Update | msie.exe | Added by the RBOT-LQ WORM! |
| X | Microsoft Utility Startup | OSA9.exe | Resource hog that launches common MS Office components to help speed up the launch of Office programs. Some users claim there's no difference with or without it but it isn't required anyway. Different filenames used for different variants |
| X | Microsoft Updates Resources | WinFixIDs.exe | Added by a variant of the RBOT WORM!
|
| X | Microsoft Updaters Pros | WINDLL32XP.EXE | Added by the SPYBOTTER.GEN VIRUS! |
| X | Microsoft UPDATER32 | lsass.exe | Added by the RANDEX.AR WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup! |
| X | Microsoft Update Win32a | winupdate32a.exe | Added by the RBOT-LO WORM! |
| X | Microsoft Update Time | wuam.exe | Added by the RBOT-M WORM! |
| X | Microsoft Update Service | mswin32.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Update Service | csrss32.exe | Added by the AGOBOT-HC WORM! |
| X | Microsoft Update Server | mssrv.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Microsoft Update Mechene | Updatez.exe | Added by the RBOT-GI WORM!
|
| X | Microsoft Update Security Patch | mssecurityupdatepatch.exe | Added by the AGENT.EF TROJAN!
|
| X | Microsoft Update Machine | wuagrd.exe | Added by the RBOT-GF WORM! |
| X | Microsoft Update Machine | winxpini.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update Machine | wuamgrd.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update Machine | Winmsixp32.exe | Added by the RBOT.DN WORM! |
| X | Microsoft Update Machine | Winregs32.exe | Added by the RBOT.DN WORM! |
| X | Microsoft Update Machine | winmgr.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update Machine | wininigo.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update Machine | windowsu.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update Machine | lmrss.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update Machine | linux.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update Machine | [random filename] | Added by a variant of the RBOT WORM! |
| X | Microsoft Update Machine | wupdt32x.exe | Added by a variant of the SDBOT WORM!
|
| X | Microsoft Update Machine | wuamgd.exe | Added by the SDBOT.HQ WORM!
|
| X | Microsoft Update Machine | svshost.exe | Added by the RBOT.AK WORM!
|
| X | Microsoft Update Machine | winupdt.exe | Added by the RBOT-FP WORM!
|
| X | Microsoft Update Machine | systemll.exe | Added by the RBOT-JT WORM!
|
| X | Microsoft Update Machine | wuawx.exe | Added by the RBOT-CE WORM!
|
| X | Microsoft Update Machine | zonealarm.exe | Added by the RBOT-BZ WORM! Note - this is not the valid Zone Labs firewall program!
|
| X | Microsoft Update Machine | system03.exe | Added by the RBOT-NM WORM!
|
| X | Microsoft Update Machine | ntce.exe | Added by the RBOT-FA WORM!
|
| X | Microsoft Update Machine | memstat.exe | Added by the RBOT-OM WORM!
|
| X | Microsoft Update Machine | xvshost.exe | Added by the RBOT.QP WORM! |
| X | Microsoft Update Machine | winini.exe | Added by the RBOT-KV WORM! |
| X | Microsoft Update Machine | SP2.exe | Added by the SPYBOT.FP WORM! |
| X | Microsoft Update Machine | servicz.exe | Added by the RBOT-HU WORM! |
| X | Microsoft Update Machine | rxhost.exe | Added by the RBOT.FC WORM! |
| X | Microsoft Update Machine | expl0rer.exe | Added by the SDBOT.OK WORM! |
| X | Microsoft Update Loader | [random filename] | Added by a variant of the RBOT WORM!
|
| X | Microsoft Update Machine | [random filename] | Added by a variant of the RBOT WORM! |
| X | Microsoft Update 32 | MSupdate32.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Update Emulator | kern-mxe.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update 32 | explore32.exe | Added by the SPYBOT.CYM WORM! |
| X | Microsoft Update | wuagrd.exe | Added by the RBOT-FK WORM! |
| X | Microsoft Update | webm.exe | Added by the SDBOT.WK WORM! |
| X | Microsoft Update | systemi32.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Update | xpupdate.exe | Added by the RBOT-QE WORM! |
| X | Microsoft Update | NAV.exe | Added by the RBOT-IV WORM! |
| X | Microsoft Update | wuamgrd32.exe | Added by the RBOT.ZB WORM!
|
| X | Microsoft Update | msiwin84.exe | Added by the GAOBOT.AFJ WORM! |
| X | Microsoft Update | msawindows.exe | Added by the GAOBOT.AFJ WORM! |
| X | Microsoft Update | wudmate.exe | Added by the RBOT.AP WORM! |
| X | Microsoft Update | wuammgr32.exe | Added by the RBOT-AW WORM! |
| X | Microsoft Update | winsys32.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update | wuamgrd.exe | Added by the RBOT-LK WORM! |
| X | Microsoft Update | VPC32.EXE | Added by the AGOBOT.XM WORM! |
| X | Microsoft Update | sys32cfg.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Update | Smss32.exe | Added by the RBOT.CB WORM! |
| X | Microsoft Update | navmgrd.exe | Added by the SDBOT.DP TROJAN! |
| X | Microsoft Update | muamgrd.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Microsoft Update | Mslti32.exe | Added by the RBOT-LX WORM! |
| X | Microsoft Update | Microsoftx.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update | msconfg.exe | Added by the RBOT.H WORM! |
| X | Microsoft Update | mediap.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update | automgr32.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update | Isac.exe | Added by the RBOT-AU WORM! |
| X | Microsoft Update | ascdl.exe | Added by the GAOBOT.SY WORM! |
| X | Microsoft Update | mvsc.exe | Added by the SPYBOT.DAZ WORM! |
| X | Microsoft Update | mssmgrd.exe | Added by the SDBOT.JT WORM! |
| X | Microsoft Update | Microsoft.exe | Added by the GAOBOT.AFJ WORM! |
| X | Microsoft Tray | [random filename] | Added by the DELF.BZ TROJAN! |
| X | Microsoft Time Manager | dveldr.exe | Added by the RBOT-HQ WORM! |
| X | Microsoft System Checkup | libsysmgr.exe | Added by the SDBOT-CAF WORM! |
| X | Microsoft System Restore Configuration | CBRSS.EXE | Added by a variant of the SPYBOT WORM! |
| X | Microsoft System Checkup | ntsysman.exe | Added by the SDBOT-QW WORM!
|
| X | Microsoft System Checkup | inetman.exe | Added by the DONK.O WORM! |
| X | Microsoft System Checkup | ntsysmgr.exe | Added by the DONK.S WORM! |
| X | Microsoft System Checkup | Keymgr.exe | Added by the DONK.M WORM! |
| X | Microsoft System Checkup | dbnetlib.exe | Added by the DONK.L WORM! |
| X | Microsoft System Checkup | Cool.exe | Added by the DONK.B WORM! |
| X | Microsoft System Checkup | Wnetlib.exe | Added by the DONK.C WORM! |
| X | Microsoft Synchronization Manager | ___synmgr.exe | Added by the MASLAN.A or MASLAN.C WORMS! |
| X | Microsoft Synchronization Manager | xXx.exe | Added by the SDBOT-KZ WORM! |
| X | Microsoft Synchronization Manager | winupdate.exe | Added by the SDBOT.ER WORM! |
| X | Microsoft Synchronization Manager | WinLoginnn.exe | Added by the SPYBOT.FO WORM! |
| X | Microsoft Synchronization Manager | svhost.exe | Added by the SDBOT-PY WORM! |
| X | Microsoft Synchronization Manager | slhost.exe | Added by the SDBOT.YH WORM! |
| X | Microsoft Synchronization Manager | netscape.exe | Added by the RANDEX.AE WORM! |
| X | Microsoft Synchronization Manager | bot.exe | Added by the SDBOT.IH WORM! |
| X | Microsoft Synchronization Manager | asgard.exe | Added by the SDBOT.PH WORM! |
| X | Microsoft SSISVRI32 Protocol | ssisvri.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Spool Server for Win32 | spoolsrv.exe | Added by the RANDEX.H WORM! |
| X | Microsoft SourceSafe | csrss.exe | Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
| N | Microsoft Sound Volume Tool | mssvol.exe | This is a Blue version of the yellow speaker icon on the system tray and is used to edit advanced Sound Features that the MS DSS80 Speakers add. Should be accessible via Start -> Settings -> Control Panel |
| X | Microsoft Software Update | nmon.exe | Added by the RBOT.HZ WORM! |
| X | Microsoft Sound Driver | sound32.exe | Added by a variant of the SPYBOT WORM! |
| N | Microsoft Sidewinder Game Controller Software | SWTRAY.EXE | MS SideWinder game controller system tray icon. Available via Start -> Programs |
| X | Microsoft Software | sysinfo33.exe | Added by the RBOT.LS WORM! |
| X | Microsoft Services | lsrv.exe | Added by the RBOT-BK WORM! |
| X | Microsoft Services | lssrv.exe | Added by the RBOT.CW WORM! |
| X | Microsoft Services | services.exe | Added by the ALETS TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | Microsoft Service | winsvc.exe | Added by the SPYBOT-DB WORM! |
| X | Microsoft Services | lsserv.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Microsoft Service | microhost.exe | Added by the RBOT-LC WORM! |
| X | Microsoft Server Application | Sound.exe | Added by the RBOT-NE WORM!
|
| X | Microsoft Security Management | winnt.exe | Added by the RBOT-MQ WORM!
|
| X | Microsoft Secure Messenger.NET Service | securitychk.exe | Added by the SDBOT.VT WORM! |
| X | Microsoft SCVHOST32 Protocol | scvhost32.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Scanreg | microsoftscanreg.exe | Added by the FRANRIV.A WORM! |
| X | Microsoft Runtime | CfgDll32.exe | Added by the RANDEX.BD WORM! |
| X | Microsoft Restore | scrgrd.exe | Added by the SPYBOT.BR WORM! |
| X | Microsoft Registry | csrse.exe | Added by the RBOT-PC WORM!
|
| X | Microsoft RDLL | sysconf32.exe | Added by a variant of the SDBOT TROJAN! |
| X | Microsoft Personal Firewalls | bakw.exe | Added by the RBOT-KS WORM! |
| N | Microsoft Office Startup | Osa9.exe | Resource hog that launches common MS Office components to help speed up the launch of Office programs. Some users claim there's no difference with or without it but it isn't required anyway. Different filenames used for different variants |
| N | Microsoft Office Startup | Osa.exe | Resource hog that launches common MS Office components to help speed up the launch of Office programs. Some users claim there's no difference with or without it but it isn't required anyway. Different filenames used for different variants |
| X | Microsoft Office Start | winupdates.exe | Added by the GAOBOT.BC WORM! |
| N | Microsoft Office Shortcut Bar | Msoffice.exe | Alternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it but a better way is to create Desktop Shortcuts if you want access these programs quickly |
| U | Microsoft Office OneNote 2003 Quick Launch | ONENOTEM.EXE | ONENOTEM.EXE is a part of the note taking program that ships with Microsoft Office 2003. It's required for the side note windows to work |
| N | Microsoft Office | Osa9.exe | Resource hog that launches common MS Office components to help speed up the launch of Office programs. Some users claim there's no difference with or without it but it isn't required anyway. Different filenames used for different variants |
| N | Microsoft Office Fast Cache | Fastboot.exe | Part of MS Office 95 (v7.0). According to this it improves the performance. Most likely a predecessor of MS Find Fast and can be disabled |
| X | Microsoft Office | MSMSGR.exe | Added by the GAOBOT.BB WORM! |
| N | Microsoft Office | Msoffice.exe | Alternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it but a better way is to create Desktop Shortcuts if you want access these programs quickly |
| N | Microsoft Office | Osa.exe | Resource hog that launches common MS Office components to help speed up the launch of Office programs. Some users claim there's no difference with or without it but it isn't required anyway. Different filenames used for different variants |
| X | Microsoft Network Daemon for Win32 | Netd32.exe | Added by the SDBOT.R TROJAN! |
| X | Microsoft Network | msnet.exe | Added by the MOCKBOT.A WORM! |
| X | Microsoft Netview | mssvc32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Microsoft Netview Component v5.1 | msnv32.exe | Added by the RANDEX.F WORM! |
| X | Microsoft Netview | gesfm32.exe | Added by the RANDEX.C WORM! |
| X | Microsoft MSUPDATE | SpoolSvc.exe | Added by the SXTB-A TROJAN! |
| X | Microsoft NetMeeting Associates, Inc. | NetMeeting.exe | Added by a variant of the LOVGATE WORM! |
| X | Microsoft MsnST | msnst32.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft MSNGR32 Protocol | msngr32.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft MSGPLUS32 Protocol | msgplus32.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Movie Maker | Mmaker.exe | Added by the IRCBOT.C TROJAN! Note that this is not a valid Microsoft program |
| X | Microsoft media services | winmplayer.exe | Added by the RBOT.ZO WORM! |
| X | Microsoft media services | Iassd.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Microsoft media | winmplayers.exe | Added by a variant of the SPYBOT WORM!
|
| X | Microsoft Management Console | lssas.exe | EasySearch adware |
| X | Microsoft Macro Protection Subsystems | Msmacroprot32.exe | Added by the RBOT.KN WORM!
|
| X | Microsoft Macro Protection SubSsy | msacroprots386.exe | Added by the RBOT-KE WORM! |
| X | Microsoft Macro Protection Subsystems | msmacroprotxz.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft LSASS386 Protocol | scvhost32.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Kernel | Windows_kernel32.exe | Added by the NETSKY.AE WORM! |
| X | Microsoft Locals 332 | [random filename] | Added by the RBOT-KU WORM! |
| X | Microsoft JavaVM | msjarun.exe | Added by the RBOT-JW WORM! |
| X | Microsoft IT Update | winn43.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft IT Update | msupdate.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft IT Update | IEserv.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft IT Update | [random filename] | Added by a variant of the RBOT WORM! |
| X | Microsoft IPC | svshost.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Microsoft IT Update | win64.exe | Added by the RBOT.GA WORM! |
| X | Microsoft IPC | system.exe | Added by the NULLBOT TROJAN! |
| X | Microsoft Internet Services | Smss32.exe | Added by the RBOT.MS WORM! |
| X | Microsoft Internet Firewall Manager | GMT16.exe | Added by the RANDEX.AT WORM! |
| X | Microsoft Internet Explorer | iexplore.exe | Downloader trojan. Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
| X | Microsoft Internet Exp | iiexplorer.exe | Added by the RBOT-KX WORM! |
| X | Microsoft Internet | windows32.exe | Added by the SDBOT-F WORM! |
| X | Microsoft Internet Acceleration Utility | iau.exe | EasySearch adware |
| X | Microsoft Internet | expl0rer.exe | Added by a variant of the SPYBOT WORM! |
| U | Microsoft Intellitype Pro | speedkey.exe | Additional keyboard shortcuts on MS programmable keyboard |
| X | Microsoft Inet Xp.. | teekids.exe | Added by the BLASTER.C WORM! |
| X | Microsoft Inc. | iexplorer.exe | Added by a variant of the LOVGATE WORM! |
| X | Microsoft IIS | syshost.exe | Added by the FRANCETTE WORM! |
| X | Microsoft IE Execute shell | IEExec.exe | Added by the ALADINZ.N TROJAN! |
| X | Microsoft IE | Iexplore.exe | Added by the FORBOT-AG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
| X | Microsoft Help SVC | msnmngr.exe | Added by the SDBOT-PQ WORM! |
| N | Microsoft Greetings Reminder | MHPRMINF.EXE | You really want to be reminded about somebody's birthday at the expense of resources? |
| N | Microsoft Greetings Workshop Reminder | Gwremind.exe | You really want to be reminded about somebody's birthday at the expense of resources? |
| X | Microsoft Gina V Encryption | MSGINAV.EXE | Added by an unidentified VIRUS, WORM or TROJAN! |
| N | Microsoft Greetings Reminders | MHPRMIND.EXE | Microsoft Home Publishing greetings reminder |
| Y | MICROSOFT FIREWALL CLIENT | ISATRAY.EXE | MS Internet Security and Acceleration Server 2000 |
| X | Microsoft Firewall | firewallsp2.exe | Added by the RBOT-MC WORM! |
| X | Microsoft Features | ms32cfg.exe | Added by the RBOT.HO WORM! |
| X | Microsoft Find Fast | Findfast.exe | Complete utter waste of space! Part of MS Office - searches disk drives for Office file types and creates an index to make opening them easier |
| X | Microsoft EXPLOREXP Protocol | explorexp.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Document | krisp.exe | Added by the SDBOT-RQ WORM! |
| X | Microsoft Excell | wuamngr32.exe | Added by the RBOT-QH WORM! |
| X | Microsoft Dll Management | windll.exe | Added by the RBOT-MT WORM!
|
| X | Microsoft DNS Query | msdns.exe | Added by a variant of the WOOTBOT WORM!
|
| X | Microsoft DirectX | PDSched.exe | Added by the SDBOT.CN WORM!
|
| X | Microsoft DirectX | rasmngr.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft DirectX | Spoolserv.exe | Added by the DINFOR WORM! |
| X | Microsoft Digital Clock | msclock.exe | Added by the NACKBOT-D WORM! |
| X | Microsoft Diagnostic | [random filename] | Added by the ACEBOT TROJAN! |
| X | Microsoft Decryption Technology | Msfenoe.exe | Added by the SPYBOT-DG WORM!
|
| X | Microsoft Database Handler | mssql32.exe | Added by the RANDEX.AX WORM! |
| X | Microsoft Data Machine | csdata32.exe | Added by a variant of the RBOT WORM!
|
| X | Microsoft Cvrt | mscvrt32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Microsoft Data Helper | cihost.exe | Malware, possibly a variant of the LINST TROJAN |
| X | Microsoft CSRSS386 Protocol | csrss386.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft CSRSS32 Protocol | csrss32.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Microsoft Corporation | [random filename] | Added by various VIRUSES, WORMS & TROJANS! |
| X | Microsoft Config | msconf.exe | Added by the RBOT.PV WORM! |
| X | Microsoft Conf Ldr | sysconf.exe | Added by a variant of the SDBOT TROJAN! |
| X | Microsoft AutoUpdater | svhost.exe | Added by the RBOT.QG WORM! |
| X | Microsoft auto update | winupdate.exe | Added by the BMBOT TROJAN! |
| X | Microsoft AUT Update | MSlti32.exe | Added by the RBOT-X WORM! |
| X | Microsoft Associates, Inc. | iexplorer.exe | Added by a variant of the LOVGATE WORM! |
| X | Microsoft Ansti Update | msie.exe | Added by the RBOT-LE WORM! |
| N | Microsoft Announcement Listener | Annclist.exe | MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it |
| X | Microsoft ALG32 Protocol | alg32.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft 16Bit Update | wuapdate16.exe | Added by the RBOT.CZ WORM! |
| X | Microsoft .NET Confingurator | msnconf.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Microsoft Associates, Inc. | iexplorer.exe | Added by a variant of the LOVGATE WORM! |
| X | microsoft | svchost.exe | Added by the ASTEF or RESPAN WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | Microsofot x386 System Monitor | system32.exe | Added by the WOOTBOT.M WORM! |
| X | Microsof Winlog Host | wilogon32.exe | Added by the RBOT.XC WORM!
|
| X | Microsof Windows Host | svhost32.exe | Added by a variant of the RBOT WORM! |
| X | MicroLoad | [random filename] | Added by the DARBY WORM! |
| X | Microfinder ml097e | mcf.exe | Variant of the RapidBlaster parasite (in a "mcf" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | Microfinder lptt01 | mcf.exe | Variant of the RapidBlaster parasite (in a "mcf" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| U | MicroDialler | atdialler1.exe | Part of the Freeserve Connection Kit - changes the dial-up for Freeserve AnyTime if access problems are encountered |
| N | microAttuneDownload | atmdlusr.exe | USR (US Robotics) modem auto updater. May be a sub-set of Attune |
| U | Microangelo Desktop | Muamgr.exe | Quick access to MicroAngelo 5.0. It can make the background of the icon text transparent and also change the color of the shortcut's text to a color you want. Very useful, if you have a wallpaper. Available via Start -> Programs |
| N | MHINIT | MHINIT.EXE | Part of the Cybermedia Clean Sweep package |
| X | Micr Update | soundblaster.exe | Added by the SDBOT.NP WORM! |
| X | MHDOGStart | mhdogst.EXE | Added by an unidentified VIRUS, WORM or TROJAN! A possibility is a trojan known as PENIS |
| N | MGA_CD_Install | mgasetup.exe | Matrox Millennium video driver. Not required once drivers installed |
| Y | mgavrtclexe | mgavrte.exe | McAfee's Virus Scan Online
|
| Y | mgavrtclexe | mgavrtcl.exe | McAfee's Virus Scan Online |
| Y | mgavctrl | mgavrte.exe | McAfee's Virus Scan Online
|
| Y | mgavctrl | mgavrtcl.exe | McAfee's Virus Scan Online |
| ? | Mgabg | Mgabg.exe | Matrox BIOS Guard. What does it do and is it required? |
| N | MGA Quickdesk | MGAQDESK.EXE | For Matrox video cards. Quick access to tweak your card to your liking |
| ? | mfgboot | ?? | ?? |
| X | mfin32 | mfin32.exe | MyFreeInternetUpdate - adware downloader |
| ? | MGA Hook | Mgahook.exe | MATROX Graphics card related. What does it do and is it required? |
| X | MeTaLRoCk (irc.musirc.com) has sex with printers | metalrock-is-gay.exe | Added by the RANDEX.Q WORM! |
| X | messnger | Dvldr32.exe | Added by the DELODER.A WORM! |
| X | messnger | [worm filename] | Added by the DELODER WORM! |
| N | MessengerPlus3 | MsgPlus.exe | MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"! |
| N | MessengerPlus2 | MsgPlus.exe | MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"! |
| N | MessengerPlus | MsgPlus.exe | MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"! |
| U | MessengerDiscovery | MessengerDiscovery.exe | MessengerDiscovery is a MSN Messenger add-on - adding over 70 new features |
| X | Messenger start-up | Msgran.exe | Added by the GRAMOS WORM! |
| X | Messenger6 | command.pif | Added by the INZAE.B WORM! |
| X | Messenger Block | msngrblock.exe | Added by the PATOO WORM! |
| X | Messenger | messenger.exe | Added by the KUTEX TROJAN! |
| U | Message_Blocker | messageblock.exe | Message Blocker - "prevents Outlook Express from loading images or other content from the internet without confirmation, as well as executing scripts when displaying a formatted email message" |
| N | MessagerStarter Freeserve | StartMessager.exe | Freeserve Messenger |
| X | Message Queuing | msmqs.exe | Added by the FREEFORS TROJAN! |
| N | MenuSnap | MenuSnap.exe | MenuSnap from Rietta Solutions. Utility that re-orders your Start Menu items alphabetically. You may not want this utility if you're able to do this manually by selecting Start -> Programs and right-clicking and choosing "Sort by Name" if availabe |
| N | MemScanner | MemScanner.exe | SpyHunter - spyware remover of somewhat dubious repute, see note |
| U | MemTurbo | memturbo.exe | MemTurbo memory optimizer. MS professionals recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind |
| X | MemoryMeter | MemoryMeter.exe | Autoinstalling spyware by Total Velocity |
| U | Memory+ | tfimemsr.exe | Memory optimizer. MS professionals recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind |
| X | Memory Watcher | MemoryWatcher.exe | MemoryWatcher spyware |
| U | Memory Stick Monitor | MSstat.exe | Sony/SmartDisk memorystick-floppydisk-adapter software - allows you to read memorysticks in a normal floppydrive |
| N | Memory Stick Monitor | MSTAT.exe | Used with the Sony floppy disk adapter for memory sticks, showing if there is a stick in the computer |
| X | Memory Check | memore.exe | Added by the KILLAV.C TROJAN! |
| U | MemoKit | MK.EXE | Memory optimizer. It loads from startup group and it goes off as soon as the program (memokit.exe) is loaded in the System Tray. Mk.exe does not run while the memokit.exe is running. Probably loads a flash screen at startup and shutdown that stays on screen less than 5 seconds and gives you a button to push to purchase the full version. MS professionals recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind |
| X | MemConfig | SetupIE.com | Added by the TAPLAK WORM! |
| X | media_manager | mediaman.exe | Mini-Player, IMESH related foistware, see here |
| X | media_stub | stub.exe | Mini-Player, IMESH related foistware, see here |
| N | MediaRing Talk | mrtalk.exe | Media Ring Talk, voice recognition software, Resource hog. Available via Start -> Programs |
| X | MediaPath | Root.exe | Added by the GRUEL WORM! |
| X | MediaPath | Proyecto1.exe | Added by the GRUEL WORM! |
| X | mediamotor.exe | mmups.exe | Roimoi/Media-Motor adware |
| N | MediaMonitor | Mediam~1.exe | Installed by Smartdisk MVP CD burning software. Software will work fine without it |
| X | MediaLoads Installer | dw.exe | Medialoads is advertising software - running DownloadWare as its executable. Installed as a bundle with Kazaa Media Desktop. See here for more information |
| X | MediaLoads | dw.exe | Medialoads is advertising software - running DownloadWare as its executable. Installed as a bundle with Kazaa Media Desktop. See here for more information |
| U | MediaKey | MediaKey.exe | Multimedia keyboard manager. Required if you use the multimedia keys |
| U | Mediafour XPlay Tray Notification Icon | Xptryicn.exe | Mediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod |
| U | Mediafour Mac Volume Notifications | Macvntfy.exe | Mediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod |
| N | MediaFace Integration | Sethook.exe | Fellowes Neato? cd label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar" |
| X | Media service | msnmsgxr.exe | Added by the SDBOT.TF WORM! |
| X | Media service | SYSTEM64.EXE | Added by the RBOT.QV WORM! |
| X | Media Service | msn64.exe | Added by the SPYBOT.EV WORM! |
| X | Media Player | wmplayer.exe | Added by the AGOBOT-BM WORM! |
| X | Media Plug x.1.2 | msdm.exe | Added by the MULDROP.352 VIRUS! |
| X | Media Player | media.exe | Added by the FLDMEDIA-A TROJAN! |
| U | Media Manager Indexer | AIRSVCU.EXE | Part of MS Visual InterDev, Media Manager is an easy media file management system that works in conjunction with Windows Explorer. The Media Manager Indexer is a program that indexes all the information about your media files and puts it into a database. For more information see here |
| N | MECA | Meca.exe | Meca instant messenging client |
| X | Media Load | msn32.exe | Added by a unidentified WORM or TROJAN! |
| X | Mdmdll32 | mdmdll32.exe | Added by a variant of the CRYPTER.C TROJAN! |
| X | Mdmdll | mdmdll.exe | Added by the CRYPTER TROJAN!
|
| U | MDM7 | mdm.exe | Used by developers for debugging. Those who have encountered it have unchecked it with no degradation in performance. May cause your computer to "hang" if you have MS Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendatioon. Can also be listed as Machine Debug Manager. See here to disable |
| X | mdm | mdm.exe | Added by the LYDRA-F TROJAN! Note - this is not the valid Machine Debug Manager which shares the same filename |
| X | Mdm | Mdm.vbs | Added by the WHITEHO VIRUS or TRAPPY WORM! |
| X | mdetect | [path to trojan] | Added by the SPABOT TROJAN! |
| N | mdac_runonce | runonce.exe | Associated with MS Data Access Components (MDAC). Sometimes left over after installation - not required. NOTE :- don't delete "runonce.exe". |
| X | MD IE Plugin | md.exe | Adult content dialler |
| X | MD IE Plugin | winy.exe | Adware |
| Y | mcvsshld | mcvsshld.exe | McAfee VirusScan On-line. See also the McAgentExe entry |
| Y | McVsRte | mcusrt.exe | Part of McAfee's SecurityCenter. Must remain checked but one user reports Windows glitches with no response from McAfee as to why |
| U | McUpdateExe | mcupdate.exe | From McAfee VirusScan On-line. Automatically updates your virus definitions. Leave enabled unless you regularly update these definitions |
| ? | McRegWiz | mcregwiz.exe | McAfee antivirus related. What does it do and is it required? |
| N | MChanger | MChanger.exe | Media Changer - utility that allows you to change wallpapers, sounds, themes, etc |
| ? | Mcappins.exe | mcappins.exe | McAfee Application Installer. What does it do and is it required? |
| U | McAgentExe | mcagent.exe | From McAfee VirusScan On-line. The Agent is a red M icon that appears in the Windows system tray or Notification Area (if you're running Windows XP). If you don't see the agent icon, VirusScan Online may not be installed |
| X | Mcaffe Antivirus | Mcafeescn.exe | Added by a variant of the SPYBOT WORM! |
| Y | McAfeeWebscanX | WebScanX.exe | From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc |
| Y | McAfeeVirusScanService | Avsynmgr.exe | From McAfee VirusScan version 5.x. Runs VirusScan System Tray (Vsstat.exe), WebScanX (Webscanx.exe), VirusScan System Scan (Vshwin32.exe) and VirusScan Console (Avconsol.exe) under one application |
| ? | McAfeeUpdaterUI | UpdaterUI.exe | Associated with McAfee Enterprise 7.0.0. Updater for McAfee anti-virus and security programs? |
| U | McAfee.InstantUpdate.Monitor | RuLaunch.exe | Instant Updater for McAfee's VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis |
| N | McAfee Winguage | ?? | Part of McAfee Nuts & Bolts. "WinGuage is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious". Resource hog. Available via Start -> Programs |
| N | McAfee Guardian | CMGRDIAN.EXE | McAfee's QuickClean, an offline version of the one in their online Clinic. Normally run offline and not needed. Incidentally, incorporates more cleanup programs than the likes of WinOptimizer and System Mechanic |
| Y | McAfee Firewall | CPD.EXE | Firewall bundled with McAfee VirusScan 6.*. Can also be listed as CPD_EXE |
| X | Mcafee Antivirus Monitoring System32mn | VSStatmn32.exe | Added by a variant of the RBOT WORM! |
| X | Mcafee Anti Scan | NortonScn.exe | Added by a variant of the RBOT WORM! |
| X | MC | wintrims.exe | Added by the WINTRIM TROJAN! |
| U | MBProbe | mbrpobe.exe | MBProbe - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs |
| U | MBM 5 | MBM5.exe | Motherboard Monitor 5 - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs |
| U | MBM 4 | MBM4.exe | Motherboard Monitor 4 - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs |
| U | MaxtorReg | AUTOREG.EXE | Part of SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of |
| Y | MaxtorCombo | ComboButton.exe | Required to be able to use the Maxtor OneTouch button on your external Maxtor harddrive. It is used to start up backup software (Retrospect) |
| N | Matrox QuickDesk | mgaqdesk.exe | For Matrox video cards. Quick access to tweak your card to your liking |
| X | MaxAlerts | max.exe | Bonzi MaxALERT - spyware |
| N | Matrox PowerDesk 8 | Matrox.PowerDesk.exe /silent | For Matrox video cards. Quick access to tweak your card to your liking |
| N | Matrox Powerdesk | PDesk.exe | For Matrox video cards. Quick access to tweak your card to your liking |
| N | Matrox Control Center | mgactrl.exe | For Matrox video cards. Quick access to settings |
| N | Matrox Diagnostic | mgadiag.exe | For Matrox video cards. Quick access to diagnostics |
| N | Matrox Color Control | hgcctl95.exe | For Matrox video cards. Quick access to changing colors |
| X | MatrixScreenSaver | mss.exe | Malware, see here |
| X | MatrixScreen | [filename] | Added by the MATRIXSCREEN TROJAN! |
| U | Matador | mlfbuddy.exe | MailFrontier - anti-spam application |
| U | Matador | mantispm.exe | MailFrontier Desktop (Matador) email spam blocker software |
| U | Master Volume Spy | MASTERVOLUMESPY.EXE | Volume control for the Gateway Destination "DestiVu" media interface |
| N | Mass storage check registry | rundll32.exe MSDServ.dll, check registry | Used with a USB based smartmedia card reader |
| N | masqform.exe | masqform.exe | PureEdge Viewer 6.0, reportedly associated with viewing and text editing US Air Force electronic forms |
| X | mapisvc32 | mapisvc32.exe | Added by the KX VIRUS and also recognised by Symantec as FPAI adware |
| X | MapiDrv | mpisvc.exe | Added by the MIPSIV TROJAN! |
| X | Mantis | [filename] | Added by the MANTIBE VIRUS! |
| N | Mania Win Restore | RESWIN.EXE | Pinball Mania for Windows from 21st Century Entertainment LTD (1995). Runs briefly at start-up then terminates. Available via Start -> Programs |
| X | mainviewex | mainviewex.exe | Added by the GEMA.D TROJAN! |
| X | main16 | main16.exe | Added by the CRYPTER.A TROJAN! |
| X | main32 | main32.exe | Added by the CRYPTER.A TROJAN! |
| ? | Main Executable (HP) | HP05T0R5.exe | HP (Hewlett-Packard) related. Maybe related to printers. Now - what does it do? |
| U | MAIN | main.exe | SpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan |
| X | Mail_Check | Mail_Check.exe | Added by the PANOIL.C WORM! |
| Y | MailScan Dispatcher | Launch.exe | MailScan Dispatcher splits each e-mail message into various components such as the header, body and attachment. Compressed formats (ZIP, ARJ, etc.) are scanned for viruses and cleaned |
| U | Mailbox Verifier | mboxvrfy.exe | Mailbox Verifier (MV) is free software that will notify you about new messages arrived to your mailbox. Only works with POP3 mailboxes (not web-mail based systems). You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance) |
| U | MailBell | mailbell.exe | MailBell e-mail notification tool that will notify you about new messages arrived to your mailbox. Works with both POP3 mailboxes and web-mail based systems. You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance) |
| ? | Mail.com | mcalert.exe | Mail.com - free web-mail service. Does mcalert.exe notify you when new mail has arrived? |
| N | Magitime | Magitime.exe | Magitime - connection tracking utility which monitors online time, expense, data transfer |
| U | MagicDsk | MAGICDSK.EXE | Magic DeskTop is a small and novel utility which will allow you the option of hiding or showing your desktop icons |
| N | MadExe | LaunchRA.exe | Dell Resolution Assistant |
| N | MacName | MacName.exe | Part of Conversions Plus from DataViz - allowing PC and MAC owners to share disks |
| Y | MAD.EXE | MAD.EXE | MAD.exe is the MS Exchange 5.5 System Attendant and can also consume a large amount of resources - resolved by the latest Exchange 5.5 Service Pack. Also part of Exchange 2000 Server but does it have the same problems?. Apparently you need to leave this running but is it needed at start-up? |
| N | MacLic | MacLic.exe | Part of Conversions Plus from DataViz - allowing PC and MAC owners to share disks |
| U | Machine Debug Manager | mdm.exe | Used by developers for debugging. Those who have encountered it have unchecked it with no degradation in performance. May cause your computer to "hang" if you have MS Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendatioon. Can also be listed as MDM7. See here to disable |
| X | Macfee Security Patch | Mpfsheild.exe | Added by the RBOT-NP WORM!
|
| N | M3Tray | m3tray.exe | Movielink - internet movie rental System Tray access |
| X | M1cr0s0ft Upd4t4zS | update32.exe | Added by the RBOT-MI WORM!
|
| X | m32info | m32info.exe | Added by the CRYPTER.A TROJAN! |
| ? | M Player Post Installer | postinstallm.exe | ?? |
| ? | M Player Post Installer | postinstallm.exe | ?? |
| X | M1cr0s0ft Upd4t4zS | update32.exe | Added by the RBOT-MI WORM!
|
| X | m32info | m32info.exe | Added by the CRYPTER.A TROJAN! |
| N | M3Tray | m3tray.exe | Movielink - internet movie rental System Tray access |
| X | Macfee Security Patch | Mpfsheild.exe | Added by the RBOT-NP WORM!
|
| U | Machine Debug Manager | mdm.exe | Used by developers for debugging. Those who have encountered it have unchecked it with no degradation in performance. May cause your computer to "hang" if you have MS Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendatioon. Can also be listed as MDM7. See here to disable |
| N | MacLic | MacLic.exe | Part of Conversions Plus from DataViz - allowing PC and MAC owners to share disks |
| N | MacName | MacName.exe | Part of Conversions Plus from DataViz - allowing PC and MAC owners to share disks |
| Y | MAD.EXE | MAD.EXE | MAD.exe is the MS Exchange 5.5 System Attendant and can also consume a large amount of resources - resolved by the latest Exchange 5.5 Service Pack. Also part of Exchange 2000 Server but does it have the same problems?. Apparently you need to leave this running but is it needed at start-up? |
| N | MadExe | LaunchRA.exe | Dell Resolution Assistant |
| U | MagicDsk | MAGICDSK.EXE | Magic DeskTop is a small and novel utility which will allow you the option of hiding or showing your desktop icons |
| N | Magitime | Magitime.exe | Magitime - connection tracking utility which monitors online time, expense, data transfer |
| ? | Mail.com | mcalert.exe | Mail.com - free web-mail service. Does mcalert.exe notify you when new mail has arrived? |
| U | MailBell | mailbell.exe | MailBell e-mail notification tool that will notify you about new messages arrived to your mailbox. Works with both POP3 mailboxes and web-mail based systems. You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance) |
| U | Mailbox Verifier | mboxvrfy.exe | Mailbox Verifier (MV) is free software that will notify you about new messages arrived to your mailbox. Only works with POP3 mailboxes (not web-mail based systems). You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance) |
| Y | MailScan Dispatcher | Launch.exe | MailScan Dispatcher splits each e-mail message into various components such as the header, body and attachment. Compressed formats (ZIP, ARJ, etc.) are scanned for viruses and cleaned |
| X | Mail_Check | Mail_Check.exe | Added by the PANOIL.C WORM! |
| U | MAIN | main.exe | SpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan |
| ? | Main Executable (HP) | HP05T0R5.exe | HP (Hewlett-Packard) related. Maybe related to printers. Now - what does it do? |
| X | main16 | main16.exe | Added by the CRYPTER.A TROJAN! |
| X | main32 | main32.exe | Added by the CRYPTER.A TROJAN! |
| X | mainviewex | mainviewex.exe | Added by the GEMA.D TROJAN! |
| N | Mania Win Restore | RESWIN.EXE | Pinball Mania for Windows from 21st Century Entertainment LTD (1995). Runs briefly at start-up then terminates. Available via Start -> Programs |
| X | Mantis | [filename] | Added by the MANTIBE VIRUS! |
| X | MapiDrv | mpisvc.exe | Added by the MIPSIV TROJAN! |
| X | mapisvc32 | mapisvc32.exe | Added by the KX VIRUS and also recognised by Symantec as FPAI adware |
| N | masqform.exe | masqform.exe | PureEdge Viewer 6.0, reportedly associated with viewing and text editing US Air Force electronic forms |
| N | Mass storage check registry | rundll32.exe MSDServ.dll, check registry | Used with a USB based smartmedia card reader |
| U | Master Volume Spy | MASTERVOLUMESPY.EXE | Volume control for the Gateway Destination "DestiVu" media interface |
| U | Matador | mlfbuddy.exe | MailFrontier - anti-spam application |
| U | Matador | mantispm.exe | MailFrontier Desktop (Matador) email spam blocker software |
| X | MatrixScreen | [filename] | Added by the MATRIXSCREEN TROJAN! |
| X | MatrixScreenSaver | mss.exe | Malware, see here |
| N | Matrox Color Control | hgcctl95.exe | For Matrox video cards. Quick access to changing colors |
| N | Matrox Control Center | mgactrl.exe | For Matrox video cards. Quick access to settings |
| N | Matrox Diagnostic | mgadiag.exe | For Matrox video cards. Quick access to diagnostics |
| N | Matrox Powerdesk | PDesk.exe | For Matrox video cards. Quick access to tweak your card to your liking |
| N | Matrox PowerDesk 8 | Matrox.PowerDesk.exe /silent | For Matrox video cards. Quick access to tweak your card to your liking |
| N | Matrox QuickDesk | mgaqdesk.exe | For Matrox video cards. Quick access to tweak your card to your liking |
| X | MaxAlerts | max.exe | Bonzi MaxALERT - spyware |
| Y | MaxtorCombo | ComboButton.exe | Required to be able to use the Maxtor OneTouch button on your external Maxtor harddrive. It is used to start up backup software (Retrospect) |
| U | MaxtorReg | AUTOREG.EXE | Part of SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of |
| U | MBM 4 | MBM4.exe | Motherboard Monitor 4 - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs |
| U | MBM 5 | MBM5.exe | Motherboard Monitor 5 - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs |
| U | MBProbe | mbrpobe.exe | MBProbe - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs |
| X | MC | wintrims.exe | Added by the WINTRIM TROJAN! |
| X | Mcafee Anti Scan | NortonScn.exe | Added by a variant of the RBOT WORM! |
| X | Mcafee Antivirus Monitoring System32mn | VSStatmn32.exe | Added by a variant of the RBOT WORM! |
| Y | McAfee Firewall | CPD.EXE | Firewall bundled with McAfee VirusScan 6.*. Can also be listed as CPD_EXE |
| N | McAfee Guardian | CMGRDIAN.EXE | McAfee's QuickClean, an offline version of the one in their online Clinic. Normally run offline and not needed. Incidentally, incorporates more cleanup programs than the likes of WinOptimizer and System Mechanic |
| N | McAfee Winguage | ?? | Part of McAfee Nuts & Bolts. "WinGuage is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious". Resource hog. Available via Start -> Programs |
| U | McAfee.InstantUpdate.Monitor | RuLaunch.exe | Instant Updater for McAfee's VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis |
| ? | McAfeeUpdaterUI | UpdaterUI.exe | Associated with McAfee Enterprise 7.0.0. Updater for McAfee anti-virus and security programs? |
| Y | McAfeeVirusScanService | Avsynmgr.exe | From McAfee VirusScan version 5.x. Runs VirusScan System Tray (Vsstat.exe), WebScanX (Webscanx.exe), VirusScan System Scan (Vshwin32.exe) and VirusScan Console (Avconsol.exe) under one application |
| Y | McAfeeWebscanX | WebScanX.exe | From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc |
| X | Mcaffe Antivirus | Mcafeescn.exe | Added by a variant of the SPYBOT WORM! |
| U | McAgentExe | mcagent.exe | From McAfee VirusScan On-line. The Agent is a red M icon that appears in the Windows system tray or Notification Area (if you're running Windows XP). If you don't see the agent icon, VirusScan Online may not be installed |
| ? | Mcappins.exe | mcappins.exe | McAfee Application Installer. What does it do and is it required? |
| N | MChanger | MChanger.exe | Media Changer - utility that allows you to change wallpapers, sounds, themes, etc |
| ? | McRegWiz | mcregwiz.exe | McAfee antivirus related. What does it do and is it required? |
| U | McUpdateExe | mcupdate.exe | From McAfee VirusScan On-line. Automatically updates your virus definitions. Leave enabled unless you regularly update these definitions |
| Y | McVsRte | mcusrt.exe | Part of McAfee's SecurityCenter. Must remain checked but one user reports Windows glitches with no response from McAfee as to why |
| Y | mcvsshld | mcvsshld.exe | McAfee VirusScan On-line. See also the McAgentExe entry |
| X | MD IE Plugin | md.exe | Adult content dialler |
| X | MD IE Plugin | winy.exe | Adware |
| N | mdac_runonce | runonce.exe | Associated with MS Data Access Components (MDAC). Sometimes left over after installation - not required. NOTE :- don't delete "runonce.exe". |
| X | mdetect | [path to trojan] | Added by the SPABOT TROJAN! |
| X | Mdm | Mdm.vbs | Added by the WHITEHO VIRUS or TRAPPY WORM! |
| X | mdm | mdm.exe | Added by the LYDRA-F TROJAN! Note - this is not the valid Machine Debug Manager which shares the same filename |
| U | MDM7 | mdm.exe | Used by developers for debugging. Those who have encountered it have unchecked it with no degradation in performance. May cause your computer to "hang" if you have MS Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendatioon. Can also be listed as Machine Debug Manager. See here to disable |
| X | Mdmdll | mdmdll.exe | Added by the CRYPTER TROJAN!
|
| X | Mdmdll32 | mdmdll32.exe | Added by a variant of the CRYPTER.C TROJAN! |
| N | MECA | Meca.exe | Meca instant messenging client |
| X | Media Load | msn32.exe | Added by a unidentified WORM or TROJAN! |
| U | Media Manager Indexer | AIRSVCU.EXE | Part of MS Visual InterDev, Media Manager is an easy media file management system that works in conjunction with Windows Explorer. The Media Manager Indexer is a program that indexes all the information about your media files and puts it into a database. For more information see here |
| X | Media Player | media.exe | Added by the FLDMEDIA-A TROJAN! |
| X | Media Player | wmplayer.exe | Added by the AGOBOT-BM WORM! |
| X | Media Plug x.1.2 | msdm.exe | Added by the MULDROP.352 VIRUS! |
| X | Media Service | msn64.exe | Added by the SPYBOT.EV WORM! |
| X | Media service | msnmsgxr.exe | Added by the SDBOT.TF WORM! |
| X | Media service | SYSTEM64.EXE | Added by the RBOT.QV WORM! |
| N | MediaFace Integration | Sethook.exe | Fellowes Neato? cd label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar" |
| U | Mediafour Mac Volume Notifications | Macvntfy.exe | Mediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod |
| U | Mediafour XPlay Tray Notification Icon | Xptryicn.exe | Mediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod |
| U | MediaKey | MediaKey.exe | Multimedia keyboard manager. Required if you use the multimedia keys |
| X | MediaLoads | dw.exe | Medialoads is advertising software - running DownloadWare as its executable. Installed as a bundle with Kazaa Media Desktop. See here for more information |
| X | MediaLoads Installer | dw.exe | Medialoads is advertising software - running DownloadWare as its executable. Installed as a bundle with Kazaa Media Desktop. See here for more information |
| N | MediaMonitor | Mediam~1.exe | Installed by Smartdisk MVP CD burning software. Software will work fine without it |
| X | mediamotor.exe | mmups.exe | Roimoi/Media-Motor adware |
| X | MediaPath | Proyecto1.exe | Added by the GRUEL WORM! |
| X | MediaPath | Root.exe | Added by the GRUEL WORM! |
| N | MediaRing Talk | mrtalk.exe | Media Ring Talk, voice recognition software, Resource hog. Available via Start -> Programs |
| X | media_manager | mediaman.exe | Mini-Player, IMESH related foistware, see here |
| X | media_stub | stub.exe | Mini-Player, IMESH related foistware, see here |
| X | MemConfig | SetupIE.com | Added by the TAPLAK WORM! |
| U | MemoKit | MK.EXE | Memory optimizer. It loads from startup group and it goes off as soon as the program (memokit.exe) is loaded in the System Tray. Mk.exe does not run while the memokit.exe is running. Probably loads a flash screen at startup and shutdown that stays on screen less than 5 seconds and gives you a button to push to purchase the full version. MS professionals recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind |
| X | Memory Check | memore.exe | Added by the KILLAV.C TROJAN! |
| N | Memory Stick Monitor | MSTAT.exe | Used with the Sony floppy disk adapter for memory sticks, showing if there is a stick in the computer |
| U | Memory Stick Monitor | MSstat.exe | Sony/SmartDisk memorystick-floppydisk-adapter software - allows you to read memorysticks in a normal floppydrive |
| X | Memory Watcher | MemoryWatcher.exe | MemoryWatcher spyware |
| U | Memory+ | tfimemsr.exe | Memory optimizer. MS professionals recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind |
| X | MemoryMeter | MemoryMeter.exe | Autoinstalling spyware by Total Velocity |
| N | MemScanner | MemScanner.exe | SpyHunter - spyware remover of somewhat dubious repute, see note |
| U | MemTurbo | memturbo.exe | MemTurbo memory optimizer. MS professionals recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind |
| N | MenuSnap | MenuSnap.exe | MenuSnap from Rietta Solutions. Utility that re-orders your Start Menu items alphabetically. You may not want this utility if you're able to do this manually by selecting Start -> Programs and right-clicking and choosing "Sort by Name" if availabe |
| X | Message Queuing | msmqs.exe | Added by the FREEFORS TROJAN! |
| N | MessagerStarter Freeserve | StartMessager.exe | Freeserve Messenger |
| U | Message_Blocker | messageblock.exe | Message Blocker - "prevents Outlook Express from loading images or other content from the internet without confirmation, as well as executing scripts when displaying a formatted email message" |
| X | Messenger | messenger.exe | Added by the KUTEX TROJAN! |
| X | Messenger Block | msngrblock.exe | Added by the PATOO WORM! |
| X | Messenger start-up | Msgran.exe | Added by the GRAMOS WORM! |
| X | Messenger6 | command.pif | Added by the INZAE.B WORM! |
| U | MessengerDiscovery | MessengerDiscovery.exe | MessengerDiscovery is a MSN Messenger add-on - adding over 70 new features |
| N | MessengerPlus | MsgPlus.exe | MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"! |
| N | MessengerPlus2 | MsgPlus.exe | MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"! |
| N | MessengerPlus3 | MsgPlus.exe | MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"! |
| X | messnger | [worm filename] | Added by the DELODER WORM! |
| X | messnger | Dvldr32.exe | Added by the DELODER.A WORM! |
| X | MeTaLRoCk (irc.musirc.com) has sex with printers | metalrock-is-gay.exe | Added by the RANDEX.Q WORM! |
| ? | mfgboot | ?? | ?? |
| X | mfin32 | mfin32.exe | MyFreeInternetUpdate - adware downloader |
| ? | MGA Hook | Mgahook.exe | MATROX Graphics card related. What does it do and is it required? |
| N | MGA Quickdesk | MGAQDESK.EXE | For Matrox video cards. Quick access to tweak your card to your liking |
| ? | Mgabg | Mgabg.exe | Matrox BIOS Guard. What does it do and is it required? |
| Y | mgavctrl | mgavrtcl.exe | McAfee's Virus Scan Online |
| Y | mgavctrl | mgavrte.exe | McAfee's Virus Scan Online
|
| Y | mgavrtclexe | mgavrtcl.exe | McAfee's Virus Scan Online |
| Y | mgavrtclexe | mgavrte.exe | McAfee's Virus Scan Online
|
| N | MGA_CD_Install | mgasetup.exe | Matrox Millennium video driver. Not required once drivers installed |
| X | MHDOGStart | mhdogst.EXE | Added by an unidentified VIRUS, WORM or TROJAN! A possibility is a trojan known as PENIS |
| N | MHINIT | MHINIT.EXE | Part of the Cybermedia Clean Sweep package |
| X | Micr Update | soundblaster.exe | Added by the SDBOT.NP WORM! |
| U | Microangelo Desktop | Muamgr.exe | Quick access to MicroAngelo 5.0. It can make the background of the icon text transparent and also change the color of the shortcut's text to a color you want. Very useful, if you have a wallpaper. Available via Start -> Programs |
| N | microAttuneDownload | atmdlusr.exe | USR (US Robotics) modem auto updater. May be a sub-set of Attune |
| U | MicroDialler | atdialler1.exe | Part of the Freeserve Connection Kit - changes the dial-up for Freeserve AnyTime if access problems are encountered |
| X | Microfinder lptt01 | mcf.exe | Variant of the RapidBlaster parasite (in a "mcf" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | Microfinder ml097e | mcf.exe | Variant of the RapidBlaster parasite (in a "mcf" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | MicroLoad | [random filename] | Added by the DARBY WORM! |
| X | Microsof Windows Host | svhost32.exe | Added by a variant of the RBOT WORM! |
| X | Microsof Winlog Host | wilogon32.exe | Added by the RBOT.XC WORM!
|
| X | Microsofot x386 System Monitor | system32.exe | Added by the WOOTBOT.M WORM! |
| X | microsoft | svchost.exe | Added by the ASTEF or RESPAN WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | Microsoft Associates, Inc. | iexplorer.exe | Added by a variant of the LOVGATE WORM! |
| X | Microsoft .NET Confingurator | msnconf.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Microsoft 16Bit Update | wuapdate16.exe | Added by the RBOT.CZ WORM! |
| X | Microsoft ALG32 Protocol | alg32.exe | Added by a variant of the SPYBOT WORM! |
| N | Microsoft Announcement Listener | Annclist.exe | MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it |
| X | Microsoft Ansti Update | msie.exe | Added by the RBOT-LE WORM! |
| X | Microsoft Associates, Inc. | iexplorer.exe | Added by a variant of the LOVGATE WORM! |
| X | Microsoft AUT Update | MSlti32.exe | Added by the RBOT-X WORM! |
| X | Microsoft auto update | winupdate.exe | Added by the BMBOT TROJAN! |
| X | Microsoft AutoUpdater | svhost.exe | Added by the RBOT.QG WORM! |
| X | Microsoft Conf Ldr | sysconf.exe | Added by a variant of the SDBOT TROJAN! |
| X | Microsoft Config | msconf.exe | Added by the RBOT.PV WORM! |
| X | Microsoft Corporation | [random filename] | Added by various VIRUSES, WORMS & TROJANS! |
| X | Microsoft CSRSS32 Protocol | csrss32.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Microsoft CSRSS386 Protocol | csrss386.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Cvrt | mscvrt32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Microsoft Data Helper | cihost.exe | Malware, possibly a variant of the LINST TROJAN |
| X | Microsoft Data Machine | csdata32.exe | Added by a variant of the RBOT WORM!
|
| X | Microsoft Database Handler | mssql32.exe | Added by the RANDEX.AX WORM! |
| X | Microsoft Decryption Technology | Msfenoe.exe | Added by the SPYBOT-DG WORM!
|
| X | Microsoft Diagnostic | [random filename] | Added by the ACEBOT TROJAN! |
| X | Microsoft Digital Clock | msclock.exe | Added by the NACKBOT-D WORM! |
| X | Microsoft DirectX | Spoolserv.exe | Added by the DINFOR WORM! |
| X | Microsoft DirectX | rasmngr.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft DirectX | PDSched.exe | Added by the SDBOT.CN WORM!
|
| X | Microsoft Dll Management | windll.exe | Added by the RBOT-MT WORM!
|
| X | Microsoft DNS Query | msdns.exe | Added by a variant of the WOOTBOT WORM!
|
| X | Microsoft Document | krisp.exe | Added by the SDBOT-RQ WORM! |
| X | Microsoft Excell | wuamngr32.exe | Added by the RBOT-QH WORM! |
| X | Microsoft EXPLOREXP Protocol | explorexp.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Features | ms32cfg.exe | Added by the RBOT.HO WORM! |
| X | Microsoft Find Fast | Findfast.exe | Complete utter waste of space! Part of MS Office - searches disk drives for Office file types and creates an index to make opening them easier |
| X | Microsoft Firewall | firewallsp2.exe | Added by the RBOT-MC WORM! |
| Y | MICROSOFT FIREWALL CLIENT | ISATRAY.EXE | MS Internet Security and Acceleration Server 2000 |
| X | Microsoft Gina V Encryption | MSGINAV.EXE | Added by an unidentified VIRUS, WORM or TROJAN! |
| N | Microsoft Greetings Reminders | MHPRMIND.EXE | Microsoft Home Publishing greetings reminder |
| N | Microsoft Greetings Workshop Reminder | Gwremind.exe | You really want to be reminded about somebody's birthday at the expense of resources? |
| N | Microsoft Greetings Reminder | MHPRMINF.EXE | You really want to be reminded about somebody's birthday at the expense of resources? |
| X | Microsoft Help SVC | msnmngr.exe | Added by the SDBOT-PQ WORM! |
| X | Microsoft IE | Iexplore.exe | Added by the FORBOT-AG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
| X | Microsoft IE Execute shell | IEExec.exe | Added by the ALADINZ.N TROJAN! |
| X | Microsoft IIS | syshost.exe | Added by the FRANCETTE WORM! |
| X | Microsoft Inc. | iexplorer.exe | Added by a variant of the LOVGATE WORM! |
| X | Microsoft Inet Xp.. | teekids.exe | Added by the BLASTER.C WORM! |
| U | Microsoft Intellitype Pro | speedkey.exe | Additional keyboard shortcuts on MS programmable keyboard |
| X | Microsoft Internet | expl0rer.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Internet | windows32.exe | Added by the SDBOT-F WORM! |
| X | Microsoft Internet Acceleration Utility | iau.exe | EasySearch adware |
| X | Microsoft Internet Exp | iiexplorer.exe | Added by the RBOT-KX WORM! |
| X | Microsoft Internet Explorer | iexplore.exe | Downloader trojan. Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
| X | Microsoft Internet Firewall Manager | GMT16.exe | Added by the RANDEX.AT WORM! |
| X | Microsoft Internet Services | Smss32.exe | Added by the RBOT.MS WORM! |
| X | Microsoft IPC | system.exe | Added by the NULLBOT TROJAN! |
| X | Microsoft IPC | svshost.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Microsoft IT Update | win64.exe | Added by the RBOT.GA WORM! |
| X | Microsoft IT Update | [random filename] | Added by a variant of the RBOT WORM! |
| X | Microsoft IT Update | IEserv.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft IT Update | msupdate.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft IT Update | winn43.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft JavaVM | msjarun.exe | Added by the RBOT-JW WORM! |
| X | Microsoft Kernel | Windows_kernel32.exe | Added by the NETSKY.AE WORM! |
| X | Microsoft Locals 332 | [random filename] | Added by the RBOT-KU WORM! |
| X | Microsoft LSASS386 Protocol | scvhost32.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Macro Protection SubSsy | msacroprots386.exe | Added by the RBOT-KE WORM! |
| X | Microsoft Macro Protection Subsystems | msmacroprotxz.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Macro Protection Subsystems | Msmacroprot32.exe | Added by the RBOT.KN WORM!
|
| X | Microsoft Management Console | lssas.exe | EasySearch adware |
| X | Microsoft media | winmplayers.exe | Added by a variant of the SPYBOT WORM!
|
| X | Microsoft media services | Iassd.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Microsoft media services | winmplayer.exe | Added by the RBOT.ZO WORM! |
| X | Microsoft Movie Maker | Mmaker.exe | Added by the IRCBOT.C TROJAN! Note that this is not a valid Microsoft program |
| X | Microsoft MSGPLUS32 Protocol | msgplus32.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft MSNGR32 Protocol | msngr32.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft MsnST | msnst32.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft MSUPDATE | SpoolSvc.exe | Added by the SXTB-A TROJAN! |
| X | Microsoft NetMeeting Associates, Inc. | NetMeeting.exe | Added by a variant of the LOVGATE WORM! |
| X | Microsoft Netview | gesfm32.exe | Added by the RANDEX.C WORM! |
| X | Microsoft Netview | mssvc32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Microsoft Netview Component v5.1 | msnv32.exe | Added by the RANDEX.F WORM! |
| X | Microsoft Network | msnet.exe | Added by the MOCKBOT.A WORM! |
| X | Microsoft Network Daemon for Win32 | Netd32.exe | Added by the SDBOT.R TROJAN! |
| N | Microsoft Office | Osa.exe | Resource hog that launches common MS Office components to help speed up the launch of Office programs. Some users claim there's no difference with or without it but it isn't required anyway. Different filenames used for different variants |
| N | Microsoft Office | Msoffice.exe | Alternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it but a better way is to create Desktop Shortcuts if you want access these programs quickly |
| X | Microsoft Office | MSMSGR.exe | Added by the GAOBOT.BB WORM! |
| N | Microsoft Office | Osa9.exe | Resource hog that launches common MS Office components to help speed up the launch of Office programs. Some users claim there's no difference with or without it but it isn't required anyway. Different filenames used for different variants |
| N | Microsoft Office Fast Cache | Fastboot.exe | Part of MS Office 95 (v7.0). According to this it improves the performance. Most likely a predecessor of MS Find Fast and can be disabled |
| U | Microsoft Office OneNote 2003 Quick Launch | ONENOTEM.EXE | ONENOTEM.EXE is a part of the note taking program that ships with Microsoft Office 2003. It's required for the side note windows to work |
| N | Microsoft Office Shortcut Bar | Msoffice.exe | Alternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it but a better way is to create Desktop Shortcuts if you want access these programs quickly |
| X | Microsoft Office Start | winupdates.exe | Added by the GAOBOT.BC WORM! |
| N | Microsoft Office Startup | Osa.exe | Resource hog that launches common MS Office components to help speed up the launch of Office programs. Some users claim there's no difference with or without it but it isn't required anyway. Different filenames used for different variants |
| N | Microsoft Office Startup | Osa9.exe | Resource hog that launches common MS Office components to help speed up the launch of Office programs. Some users claim there's no difference with or without it but it isn't required anyway. Different filenames used for different variants |
| X | Microsoft Personal Firewalls | bakw.exe | Added by the RBOT-KS WORM! |
| X | Microsoft RDLL | sysconf32.exe | Added by a variant of the SDBOT TROJAN! |
| X | Microsoft Registry | csrse.exe | Added by the RBOT-PC WORM!
|
| X | Microsoft Restore | scrgrd.exe | Added by the SPYBOT.BR WORM! |
| X | Microsoft Runtime | CfgDll32.exe | Added by the RANDEX.BD WORM! |
| X | Microsoft Scanreg | microsoftscanreg.exe | Added by the FRANRIV.A WORM! |
| X | Microsoft SCVHOST32 Protocol | scvhost32.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Secure Messenger.NET Service | securitychk.exe | Added by the SDBOT.VT WORM! |
| X | Microsoft Security Management | winnt.exe | Added by the RBOT-MQ WORM!
|
| X | Microsoft Server Application | Sound.exe | Added by the RBOT-NE WORM!
|
| X | Microsoft Service | microhost.exe | Added by the RBOT-LC WORM! |
| X | Microsoft Service | winsvc.exe | Added by the SPYBOT-DB WORM! |
| X | Microsoft Services | lsserv.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Microsoft Services | lssrv.exe | Added by the RBOT.CW WORM! |
| X | Microsoft Services | services.exe | Added by the ALETS TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | Microsoft Services | lsrv.exe | Added by the RBOT-BK WORM! |
| N | Microsoft Sidewinder Game Controller Software | SWTRAY.EXE | MS SideWinder game controller system tray icon. Available via Start -> Programs |
| X | Microsoft Software | sysinfo33.exe | Added by the RBOT.LS WORM! |
| X | Microsoft Software Update | nmon.exe | Added by the RBOT.HZ WORM! |
| X | Microsoft Sound Driver | sound32.exe | Added by a variant of the SPYBOT WORM! |
| N | Microsoft Sound Volume Tool | mssvol.exe | This is a Blue version of the yellow speaker icon on the system tray and is used to edit advanced Sound Features that the MS DSS80 Speakers add. Should be accessible via Start -> Settings -> Control Panel |
| X | Microsoft SourceSafe | csrss.exe | Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
| X | Microsoft Spool Server for Win32 | spoolsrv.exe | Added by the RANDEX.H WORM! |
| X | Microsoft SSISVRI32 Protocol | ssisvri.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Synchronization Manager | asgard.exe | Added by the SDBOT.PH WORM! |
| X | Microsoft Synchronization Manager | bot.exe | Added by the SDBOT.IH WORM! |
| X | Microsoft Synchronization Manager | netscape.exe | Added by the RANDEX.AE WORM! |
| X | Microsoft Synchronization Manager | slhost.exe | Added by the SDBOT.YH WORM! |
| X | Microsoft Synchronization Manager | svhost.exe | Added by the SDBOT-PY WORM! |
| X | Microsoft Synchronization Manager | WinLoginnn.exe | Added by the SPYBOT.FO WORM! |
| X | Microsoft Synchronization Manager | winupdate.exe | Added by the SDBOT.ER WORM! |
| X | Microsoft Synchronization Manager | xXx.exe | Added by the SDBOT-KZ WORM! |
| X | Microsoft Synchronization Manager | ___synmgr.exe | Added by the MASLAN.A or MASLAN.C WORMS! |
| X | Microsoft System Checkup | Cool.exe | Added by the DONK.B WORM! |
| X | Microsoft System Checkup | Wnetlib.exe | Added by the DONK.C WORM! |
| X | Microsoft System Checkup | dbnetlib.exe | Added by the DONK.L WORM! |
| X | Microsoft System Checkup | Keymgr.exe | Added by the DONK.M WORM! |
| X | Microsoft System Checkup | inetman.exe | Added by the DONK.O WORM! |
| X | Microsoft System Checkup | ntsysmgr.exe | Added by the DONK.S WORM! |
| X | Microsoft System Checkup | ntsysman.exe | Added by the SDBOT-QW WORM!
|
| X | Microsoft System Checkup | libsysmgr.exe | Added by the SDBOT-CAF WORM! |
| X | Microsoft System Restore Configuration | CBRSS.EXE | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Time Manager | dveldr.exe | Added by the RBOT-HQ WORM! |
| X | Microsoft Tray | [random filename] | Added by the DELF.BZ TROJAN! |
| X | Microsoft Update | Microsoft.exe | Added by the GAOBOT.AFJ WORM! |
| X | Microsoft Update | mssmgrd.exe | Added by the SDBOT.JT WORM! |
| X | Microsoft Update | mvsc.exe | Added by the SPYBOT.DAZ WORM! |
| X | Microsoft Update | ascdl.exe | Added by the GAOBOT.SY WORM! |
| X | Microsoft Update | Isac.exe | Added by the RBOT-AU WORM! |
| X | Microsoft Update | automgr32.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update | mediap.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update | Microsoftx.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update | msconfg.exe | Added by the RBOT.H WORM! |
| X | Microsoft Update | Mslti32.exe | Added by the RBOT-LX WORM! |
| X | Microsoft Update | muamgrd.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Microsoft Update | navmgrd.exe | Added by the SDBOT.DP TROJAN! |
| X | Microsoft Update | Smss32.exe | Added by the RBOT.CB WORM! |
| X | Microsoft Update | sys32cfg.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Update | VPC32.EXE | Added by the AGOBOT.XM WORM! |
| X | Microsoft Update | winsys32.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update | wuamgrd.exe | Added by the RBOT-LK WORM! |
| X | Microsoft Update | wuammgr32.exe | Added by the RBOT-AW WORM! |
| X | Microsoft Update | wudmate.exe | Added by the RBOT.AP WORM! |
| X | Microsoft Update | msawindows.exe | Added by the GAOBOT.AFJ WORM! |
| X | Microsoft Update | msiwin84.exe | Added by the GAOBOT.AFJ WORM! |
| X | Microsoft Update | wuamgrd32.exe | Added by the RBOT.ZB WORM!
|
| X | Microsoft Update | NAV.exe | Added by the RBOT-IV WORM! |
| X | Microsoft Update | systemi32.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Update | xpupdate.exe | Added by the RBOT-QE WORM! |
| X | Microsoft Update | webm.exe | Added by the SDBOT.WK WORM! |
| X | Microsoft Update | wuagrd.exe | Added by the RBOT-FK WORM! |
| X | Microsoft Update 32 | explore32.exe | Added by the SPYBOT.CYM WORM! |
| X | Microsoft Update 32 | MSupdate32.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Update Emulator | kern-mxe.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update Loader | [random filename] | Added by a variant of the RBOT WORM!
|
| X | Microsoft Update Machine | [random filename] | Added by a variant of the RBOT WORM! |
| X | Microsoft Update Machine | expl0rer.exe | Added by the SDBOT.OK WORM! |
| X | Microsoft Update Machine | rxhost.exe | Added by the RBOT.FC WORM! |
| X | Microsoft Update Machine | servicz.exe | Added by the RBOT-HU WORM! |
| X | Microsoft Update Machine | SP2.exe | Added by the SPYBOT.FP WORM! |
| X | Microsoft Update Machine | winini.exe | Added by the RBOT-KV WORM! |
| X | Microsoft Update Machine | xvshost.exe | Added by the RBOT.QP WORM! |
| X | Microsoft Update Machine | memstat.exe | Added by the RBOT-OM WORM!
|
| X | Microsoft Update Machine | ntce.exe | Added by the RBOT-FA WORM!
|
| X | Microsoft Update Machine | system03.exe | Added by the RBOT-NM WORM!
|
| X | Microsoft Update Machine | wuawx.exe | Added by the RBOT-CE WORM!
|
| X | Microsoft Update Machine | zonealarm.exe | Added by the RBOT-BZ WORM! Note - this is not the valid Zone Labs firewall program!
|
| X | Microsoft Update Machine | systemll.exe | Added by the RBOT-JT WORM!
|
| X | Microsoft Update Machine | winupdt.exe | Added by the RBOT-FP WORM!
|
| X | Microsoft Update Machine | svshost.exe | Added by the RBOT.AK WORM!
|
| X | Microsoft Update Machine | wuamgd.exe | Added by the SDBOT.HQ WORM!
|
| X | Microsoft Update Machine | wupdt32x.exe | Added by a variant of the SDBOT WORM!
|
| X | Microsoft Update Machine | [random filename] | Added by a variant of the RBOT WORM! |
| X | Microsoft Update Machine | linux.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update Machine | lmrss.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update Machine | windowsu.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update Machine | wininigo.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update Machine | winmgr.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update Machine | Winmsixp32.exe | Added by the RBOT.DN WORM! |
| X | Microsoft Update Machine | Winregs32.exe | Added by the RBOT.DN WORM! |
| X | Microsoft Update Machine | winxpini.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update Machine | wuamgrd.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Update Machine | wuagrd.exe | Added by the RBOT-GF WORM! |
| X | Microsoft Update Mechene | Updatez.exe | Added by the RBOT-GI WORM!
|
| X | Microsoft Update Security Patch | mssecurityupdatepatch.exe | Added by the AGENT.EF TROJAN!
|
| X | Microsoft Update Server | mssrv.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Microsoft Update Service | csrss32.exe | Added by the AGOBOT-HC WORM! |
| X | Microsoft Update Service | mswin32.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Update Time | wuam.exe | Added by the RBOT-M WORM! |
| X | Microsoft Update Win32a | winupdate32a.exe | Added by the RBOT-LO WORM! |
| X | Microsoft UPDATER32 | lsass.exe | Added by the RANDEX.AR WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup! |
| X | Microsoft Updaters Pros | WINDLL32XP.EXE | Added by the SPYBOTTER.GEN VIRUS! |
| X | Microsoft Updates Resources | WinFixIDs.exe | Added by a variant of the RBOT WORM!
|
| X | Microsoft upnp Update | msie.exe | Added by the RBOT-LQ WORM! |
| X | Microsoft Utility Startup | OSA9.exe | Resource hog that launches common MS Office components to help speed up the launch of Office programs. Some users claim there's no difference with or without it but it isn't required anyway. Different filenames used for different variants |
| X | Microsoft Video Controls | tskmsgr.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Visual SourceSafe | services.exe | Added by the NEVEG.B or NEVEG.C WORMS!. Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup or the Microsoft Visual SourceSafe program |
| X | Microsoft Visual SourceSafe | winlogon.exe | Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup or the Microsoft Visual SourceSafe program |
| X | Microsoft Visual Studio VSA | varpc32.exe | Added by a variant of the SPYBOT WORM! |
| U | Microsoft Webserver | svctrl.exe | Personal web server program which enables you to create and host a web server from your computer. Not required for most people |
| X | Microsoft Windows | mstask0.exe | Added by the SDBOT.FQ WORM! |
| X | Microsoft Windows 2000 | Winupdsdgm.exe | Added by the GAOBOT.AO WORM! |
| X | Microsoft Windows DHCP | ___r.exe | Added by the MASLAN.A WORM! |
| X | Microsoft Windows GUI | Windowz.exe | Added by the RANDEX.AEV WORM! |
| X | Microsoft Windows Kernel Services | winkrnl386.exe | Added by the ZEBROXY TROJAN! |
| X | Microsoft Windows Loader | wloader.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Microsoft Windows Secure Server | rpcxWindows.exe | Added by the RBOT-LL WORM! |
| X | Microsoft Windows Task Manger | Mstosk.exe | Added by the SDBOT-WW WORM! |
| X | Microsoft Windows Update | rundlls.exe | Added by the HABRACK WORM! |
| X | Microsoft Windows Update | msoffice2.exe | Added by the RBOT-GB WORM! |
| X | Microsoft Windows Update | spools.exe | Added by the SDBOT.TD WORM! |
| X | Microsoft Windows Update | svchos.exe | Added by the SDBOT.AC WORM! |
| X | Microsoft Windows Update | svcshost.exe | Added by the FORBOT-CF WORM!
|
| X | Microsoft Windows Update | svmhost.exe | Added by the FORBOT-CH WORM!
|
| X | Microsoft Windows Update | svshost.exe | Added by the WOOTBOT.CJ WORM!
|
| X | Microsoft Windows Update Service | wupdmgr32.exe | Added by the DOS.AUTOCAT TROJAN! |
| X | Microsoft Windows Updater | winupdgm.exe | Added by the GAOBOT.BI WORM! |
| X | Microsoft Windows Updater | svchostz.exe | Added by the DAEMONI-E TROJAN! |
| X | Microsoft Windows Updater | WINIUPDATES.EXE | Added by the RBOT-KK WORM! |
| X | Microsoft Windows Updater | WINUPDATE.EXE | Added by the SDBOT-PU WORM!
|
| X | Microsoft Windows updaterD | log32zx.exe | Added by the MYDOOM.W WORM! |
| X | Microsoft Windows Updates | explorer32.exe | Added by the SDBOT.VQ WORM!
|
| X | Microsoft Winsock Wrapper | ws2_32s.exe | Added by a variant of the SPYBOT WORM!
|
| X | Microsoft WinUpdate | mntcgf032.exe | Added by a variant of the SDBOT WORM! |
| X | Microsoft WinUpdate | svh0st.exe | Added by the SPYBOT.DL WORM! |
| X | Microsoft WinUpdate | syslx32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Microsoft WinUpdate | syswin32.exe | Added by a variant of the SDBOT WORM! |
| X | Microsoft WinUpdates | serm32.exe | Added by the RBOT.GE WORM! |
| N | Microsoft Works Calendar Reminders | wkcalrem.exe | Produces a pop-up reminder of events scheduled using the MS Works Calendar |
| N | Microsoft Works Portfolio | WksSb.exe | The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program.Can be prevented from starting from a setting within Portfolio |
| N | Microsoft Works Update Detection | wkdetect.exe | Checks for updates to MS Works |
| X | Microsoft World Service | winworld.exe | Added by an unidentified IRC worm with backdoor capability!
|
| X | Microsoft Wxdate | Syswu32.exe | Added by the SPYBOT.HZ WORM! |
| X | microsoft xdaemon 2.0 | xdaemon.exe | Added by the DELF.D TROJAN! |
| X | Microsoft XML Service | msxmlx.exe | Added by the RBOT.KS WORM! |
| X | Microsoft--Updates | sxvhost.exe | Added by the RBOT-FH WORM! |
| X | Microsoft-Update | wngard.exe | Added by the RBOT-JV WORM! |
| X | Microsoft-Updates | svxhost.exe | Added by the RBOT-CT WORM! |
| X | microsoft420 | microsoft420.exe | Added by the MENACE.B WORM! |
| X | Microsoftkeysd | systemproc.exe | Added by the FORBOT-BI WORM!
|
| X | Microsoftkeysd | systemwin32s.exe | Added by the WOOTBOT.CO WORM! |
| X | Microsoftmsn32.exe | microsoftmsn32.exe | Added by the CERTIF-C TROJAN!
|
| X | MicrosoftMultimediaTask | Mmtask.exe | Adware downloader - not the valid MusicMatch Jukebox which shares the same filename |
| X | MicrosoftNetwork Daemon for Win32 | NETD32.EXE | Added by the RANDEX.F WORM! |
| X | Microsofts Updatez | cmsssr.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | MicrosoftServiceManager | mstask32.exe | Added by the YAHA.P WORM! |
| X | MicrosoftServiceManager | Wintsk32.exe | Added by the YAHA.U WORM! |
| X | MicrosoftServiceManager | EXPLORERE.EXE | Added by the YAHA.AB WORM! |
| X | MicrosoftServiceManager | msupdat.exe | Added by the YAHA.AA WORM! |
| X | MicrosoftSourceSafe | lsass.exe | Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup! |
| X | MicrosoftUpdate | syshelper.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | MicrosoftUpdate | WinUp32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | MicrosoftValue | syscnfg.exe | Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
| X | Microsoftvirus | sysoverload.exe | Added by the FORBOT-AL WORM! |
| X | MicrosoftWindows | [various filenames] | MagicSearch - a CoolWebSearch parasite variant |
| X | Microsoft? PID Lex | PIDLex.exe | Added by the NIOVADOOR TROJAN! |
| X | Microsoft? System Mapper | SysMap.exe | Added by the MAPSY TROJAN! |
| X | Microszoft Update Mach1nezs | svchst.exe | Added by the RBOT-ED WORM!
|
| X | Microzoft_Ofiz | KdzEregli.exe | Added by the AMUS.A WORM! |
| X | Micrsoft Driver | windrive.exe | Added by the SDBOT.AF TROJAN! |
| N | MightyFAX Controller | MFNTCTL.EXE | Mighty FAX from RKS Software - "installs a printer driver so that you can fax directly from Windows software" |
| ? | MigrationVendorSetupCaller | rundll32.exe migrate.dll, CallVendorSetupDlls | ?? |
| X | MINIBUG | MINIBUG.EXE | Displays ads inside Weatherbug - see here |
| N | MINIFERT.EXE | MINIFERT.EXE | Part of Backweb |
| U | minilog | MINILOG.EXE | If you don't have ZoneAlarm or ZoneAlarm Pro running you don't need this. This must be enabled if programs such as VisualZone Report utility or ZoneLog Analyzer are in use |
| N | MiniMavis | MiniMavis.exe | Mavis Beacon typing tutor |
| N | MiniNote | MININOTE.EXE | Mini NoteTab was the first in the family of "NoteTab" text and HTML editors from Fookes Software |
| U | MinMaxExtender | Mmext.exe | MinMaxExtender - window handling tool |
| X | Miosf Update | wimsqaad.exe | Added by the SDBOT.AG TROJAN! |
| N | Mirabilis ICQ | NDetect.exe | If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs |
| N | Mirabilis ICQ | icq.exe | If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs |
| N | Mirabilis ICQ | ICQNet.exe | If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs |
| U | Miramar Systems, Inc. | atmsg.exe | Miramar PC/Mac networking software |
| X | Mirate Sp 2 Information | miratesp2.exe | Added by the RBOT.QH WORM!
|
| N | miroVIDEO Tray Tool | misitray.exe | Tool for quickly changing options for miro/Pinnacle capture cards during capture/playback/output. When this program is closed, another program (mv-ctrl) is also closed, but mv-ctrl does not have its own EXE file. Only needed when using the capture card, e.g. for the above actions |
| U | MirrorFolderShell | mrfshl.exe | MirrorFolder backup software |
| ? | misiCTRL | misiCTRL.exe | Miro video driver related. Is it required? |
| ? | misiTRAY | misiTRAY.exe | Miro video driver related. Is it required? |
| N | Mixer | Mixer.exe | C-Media Mixer - C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start -> Settings -> Control Panel or Start -> Programs |
| N | Mixghost | mixghost.exe | Management software for Altec Lansing speakers. If a change is needed, the user can launch it from the Start menu |
| X | mload | lxmstart.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| ? | MM Install | setup.exe | Possibly Money Manager from Moneysoft? |
| X | mmcndmgr | mmcndmgr.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| N | MMCWINMGMT | winmgmt.exe | Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here |
| U | MMERefresh | MMERefresh.exe | Part of Digidesgin Protools. Refreshes your midi ports on the 002(R) (the 002R is a hardware audio/midi converter connected to your computer via firewire). Must be running in order to use the MIDI functionality of the Digi002R |
| X | Mmgsvc | mmgsvc.exe | Mmgsvc spyware
|
| U | MMhid | mmhid.dll | This is the Human Interface Device Server for Win98, it is required only if you are using USB Audio Devices you can disable via Msconfig. See here. Typical examples are USB multimedia keyboards with volume control and web-ready keyboards. For example - loaded by default with MS DSS80 Speakers because they have Volume, Mute and Bass controls on the speaker. Some users may experience problems disabling this - if this is the case then re-enable it. Equivalent to Hidserv in Win98SE/2000/Me/XP |
| ? | MMHK | mmhk.exe | A driver found on a Compaq Presario 800T notebook. Possibly something to do with multimedia hot keys? |
| N | MMHotKey | MMHotKey.exe | Multimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen |
| U | MMKeybd | MMKeybd.exe | Multimedia keyboard manager. Required if you use the additional keys |
| X | mmod | mmod.exe | Ezula - regarded as spyware/theftware and bundled with the popular iMesh and KaZaA file-sharing programs. Read here for more information |
| N | mmpti | m1mmpti.exe | Mpact Mediaware Properties Taskbar Icon - multimedia software icon for Chromatic Research Mpact video cards |
| ? | MMRun | mmrun.exe | ?? |
| ? | mmsys | recover.exe | ?? |
| X | MMSystem | RunDll32 | Added by the FUNNER-A WORM!
|
| Y | MMTASK | mmtask.tsk | A check on the file's properties reveals "Multimedia background task support module". MMTASK is a very simple 16-bit program used by certain multimedia drivers (which are still 16-bit on Win9x) to perform background processing. Some soundcards need this to support MIDI, etc |
| N | mmtask | mmtask.exe | Part of MusicMatch Jukebox - digital music player / CD burner and ripper / music organizer / playlist creator |
| X | MMtask Service | mmtask.exe | Added by the BACKGAT.A TROJAN! Not the valid MusicMatch Jukebox which has the same filename |
| N | MMTray | mm_tray.exe | MusicMatch Jukebox icon in the task tray - digital music player / CD burner and ripper / music organizer / playlist creator |
| N | MMTray | MMTray.exe | Part of Morgan Multimedia Codecs. Only required when the codecs are used |
| N | MMTray2K | MMTray2K.exe | Part of Morgan Multimedia Codecs. Only required when the codecs are used |
| N | MMTrayLSI | MMTrayLSI.exe | Part of Morgan Multimedia Codecs. Only required when the codecs are used |
| ? | mmusrstp | procrun.exe | ?? |
| X | mmxrun | msosa.exe | Adult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), atisrc2 (windfind.exe) and RegCompres (REGCPM32.EXE), otherwise they return |
| X | MNPol | mnpol.exe | Adult content dialler |
| U | MNS | MNS.exe | Mobile Net Switch enables you to use your computer on more then one network with the click of a button. It allows you to automatically select the correct drive mappings, printer settings, IP settings and much more |
| X | mnsvc | mnsvc.exe | Added by the AUTOUPDER TROJAN! |
| X | mnsvcsp | mnsvcsp.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| N | mobsync | mobsync.exe | MS Syncrhonization Manager - updates the network copy of materials that were edited offline, such as documents, calendars, and e-mail messages |
| X | MOBSYNC32.EXE | mobsync32.exe | Added by the FINERO TROJAN! |
| N | MOD | muamger.exe | MicroAngelo On Display from Impact Software lets you customize Windows icons. With a few exceptions, you can customize icons by right-clicking on them |
| U | MODEMBTR | MODEMBTR.EXE | Modem Booster from inKline Global to improve ISP connections |
| X | Modeminf | Modeminf.exe | Added by a variant of the CRYPTER.C TROJAN! |
| U | ModemOnHold | MOH.EXE | NetWaiting Modem-on-Hold Application |
| N | ModemUtility | mdmsetpe.exe | System Tray configuration icon for Aztech modems |
| X | ModularConfig | syscnfg.exe | Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
| X | Module Call initialize | RUNDLL32.EXE reg.dll, ondll_reg | Added by a variant of the LOVGATE WORM! |
| N | Money Express | moneyexpress.exe | Part of MS Money. Available via Start -> Programs |
| N | MoneyAgent | money express.exe | Part of MS Money. Available via Start -> Programs |
| N | MoneyAgent | mnyexpr.exe | Microsoft Money |
| N | MoneyStartUp | Money Startup.exe | Microsoft Money |
| N | MoneyStartUp10.0 | Activation.exe | Part of MS Money 2002. Available via Start -> Programs |
| U | Monitor Apache Servers | ApacheMonitor.exe | Part of the Apache Web Server package. Useful only if you're running such a server on your PC. Available via Start -> Programs |
| X | Monitoring Service | svchost.exe | Added by the CONE.C WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | Monitormgt | Monitormgt.exe | Added by the GEMA TROJAN! |
| N | Monstersoundtray | Freectrl.exe | Diamond Multimedia sound card control panel |
| U | MoodBook | mb.exe | MoodBook is a free Windows utility that brings art to your desktop |
| N | moon phase | moon.exe | Moon Phase - tray icon that indicates the phases of the moon |
| N | Morpheus | morpheus.exe | MusicCity Networks' Morpheus - another peer-to-peer client based on Kazaa. Notable in that this one doesn't seem to install the adware that clog the Kazaa download. They claim they are adware free, and a visitor quotes "I have seen no instance of any since using it" |
| X | mosearch | mosearch.exe | Fast Search in Office XP - similar to the new revision of the Find Fast feature in Office 2000. Fast Search uses the Indexing Services in Office XP to create a catalog of Office files on your computer's hard disk. As with Find Fast - a waste of resources. If it can't be disabled via MSCONFIG try here |
| N | Motive SmartBridge | mpbtn.exe | System tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required |
| N | Motive SmartBridge | MotiveSB.exe | System tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required |
| U | MotiveMonitor | motmon.exe | Found on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used?the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it's not required |
| N | MotiveSB | MotiveSB.exe | System tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required |
| U | MotMon | motmon.exe | Found on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used?the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it's not required |
| U | Mount Safe & Sound | Fbmount.exe | From McAfee VirusScan version 5.x. Creates back-up sets of critical files in a separate area of a hard drive. If you make regular back-ups it's not needed and can be painful during system start |
| N | Mouse 32A | Mouse32A.exe | Mouse driver to control mouse functions from Azona. Available via Start -> Programs |
| N | Mouse Suite 98 Daemon | pelmiced.exe | Mouse driver. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games |
| X | mousebut | mousebut.exe | Added by the CRYPTER.A TROJAN! |
| X | Mousecntl | mousecntl.exe | Added by a variant of the CRYPTER.C TROJAN! |
| N | MouseCount | MC.exe | MouseCount by Kittyfeet Software. "Utility for counting how many times us computer junkies click our mouse in a given session/day/week/month/year." Not required |
| X | mousedrv | mousedrv.exe | Added by the CRYPTER.A TROJAN! |
| U | mouseElf | MC.exe | Genius NetScroll mouse driver - required if you use non-standard Windows driver features |
| U | MouseImp | MImpHost.exe | MouseImp Pro - "A reliable assistant that turns your mouse into a simple, native but powerful controlling device" |
| U | Mousinfo | mousinfo.exe | MS mouse information tool - for troubleshooting mouse problems |
| N | Movielink Manager Uninstall | msvcmm32.exe | Auto-update for Movielink - internet movie rental System Tray access |
| X | MovieNetworks | MovieNetworks.exe | MovieNetworks will connect you by DOMESTIC PREMIUM RATE TELEPHONE NUMBER 900-xxx-xxxx. So you get xxx rated pictures and junk. And it will allow you to stay on the internet on their line and $$$ and remove the C:Program FilesMovieNetworks directory |
| X | Movieplace | Movieplace.exe | MoviePlace malware |
| N | Mozilla Quick Launch | Netscp6.exe | Netscape 6 and Mozilla browsers |
| N | Mozilla Quick Launch | Mozilla.exe | Netscape 6 and Mozilla browsers |
| X | MP Tcloaxs | mptcloaxs.exe | Added by the RANDEX.CT WORM! |
| U | MPEO | Csinsm32.exe | Automatic logging of installs from Norton CleanSweep - available via Start -> Programs |
| Y | MPFExe | mpf.exe | McAfee Personal Firewall |
| Y | MPFExe | MpfTray.exe | McAfee Personal Firewall |
| X | MPL32 driver | MPL32.exe | Added by the LOONY-M TROJAN! |
| U | MplSetup | MplSetup.exe | Used by Ricoh network printers to enable network printing from the client |
| U | MPower | MPower.exe | MPower from MindBeat. "Defragments and frees your RAM giving more stability to your system and avoiding needless use of swap file. Willl also benchmark (speed test) your hard disk drives and your CPU load". Some users swear by programs such as this but I suggest you read this article and make up your own mind |
| X | MPREXE | MPREXE.EXE | Added by the OPASERV.T WORM! Note - this is not the legitimate Mprexe.exe system file |
| Y | MPREXE.exe | mprexe.exe | WIN32 Network Service Interface Process. MPREXE.exe enables the computer to have multiple clients/protocols for networks. There are some problems with it sometimes though - see here and here. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background. NOTE : sometimes it will appear in start-ups if you have a virus |
| X | MprHTML | MprHTML.exe | Added by a variant of the VAGRNOCKER TROJAN! |
| U | MPSExe | mscifapp.exe | McAfee.com Privacy Service - "combines personal identifiable information (PII) protection with online advertisement blocking and content filtering" |
| ? | MPT | MPT.exe | ?? |
| X | MPtask Services | mptask.exe | Added by the LALA or AOT TROJANS! |
| N | MPTBox | MPTBOX.EXE | Cannon Multi-Pass toolbox - a button bar |
| N | MPXTray | mpxptray.exe | Windows Media Player PowerToy which is run from the taskbar. It can be used to hide Windows Media Player (when in use) and choose various standard buttons (play/pause, next,previous) etc |
| ? | MP_STATUS_MONITOR | monitr32.exe | Related to Cannon Multi-Pass |
| X | mqbkup | mqbkup.exe | Added by the OPASERV.K WORM! |
| N | mrtMngr | mrtMngr.exe | Maintenance Release Task Manager for Intuit?s QuickBooks or Quicken |
| U | MRU-Blaster Scheduler | scheduler.exe | MRU-Blaster scheduler - detects and cleans MRU (most recently used) lists on your computer |
| N | MRU-Blaster Silent Clean | mrublaster.exe | MRU-Blaster - performs silent cleaning of MRU lists at boot |
| X | MS Config Loader | svchos1.exe | Added by the AGOBOT.R WORM! |
| X | MS Config Loader | MSWin32bck.exe | Added by the GAOBOT.AA WORM! |
| X | MS Config Service | Msloader32.exe | Added by the RBOT-KJ WORM! |
| X | MS Configuration | MSFramer.exe | Added by the RANDEX.OL WORM! |
| X | MS Decryption Software | active.exe | MediaTickets adware variant |
| X | MS Explorer | mexplore.exe | Added by the YAHA.AE WORM! |
| X | MS FIREWALL | msfrewall.exe | Added by the SDBOT-PU WORM! |
| X | MS FIREWALL | msfirewall.exe | Added by the SDBOT-QH WORM!
|
| X | MS HTML | msHtml.exe | Added by the PESTDOOR.31 TROJAN! |
| X | MS HTML | mslat.exe | Added by the LATINUS.SVR TROJAN! |
| X | MS lsass Startup | lsass135.exe | Added by the RBOT.WM WORM! |
| ? | MS management console | mms.exe | Suspicious as the Microsoft Management Console is "mmc.exe" and doesn't normally run at startup |
| X | MS Network Control | mswin.exe | Added by the DUMBA TROJAN! |
| X | MS Remote Procedure Call | msrpc32.exe | Added by the RBOT-QL WORM! |
| X | MS Security Hotfix | service5.exe | Added by the GAOBOT.AG WORM! |
| X | MS Sound Config 16bit | sndcfg16.exe | Added by the SDBOT.MB TROJAN! |
| X | Ms Spool32 | MS SPOOL32.EXE | Added by the ASASSIN TROJAN! |
| X | MS SyS Restore | sysrestore.exe | Added by the RBOT.XM WORM! |
| X | MS Update | syshost.exe | Added by the EVAMAN-F WORM! |
| X | MS Updates | mscache.exe | Spyware web downloader |
| X | MS Updates | syshosts.exe | Added by the MYDOOM.Y WORM! |
| X | MS Updates | aupd.exe | Spyware web downloader |
| X | MS-Connect | arr.exe | Adult content dialler - see here |
| X | MS-Connect | cdm.exe | Adult content dialler - see here |
| X | MS-Connect | game.exe | Adult content dialler - see here |
| X | MS-Connect | msite18.exe | Adult content dialler - see here |
| X | MS-Connect | web.exe | Adult content dialler - see here |
| X | MS-HTML | [random filename] | Added by the LATINUS.15 TROJAN! |
| X | MS-RunKey | arr.exe | MS-Connect dialler/hijacker |
| X | MS7531 | ms7531.exe | Homepage hijacker |
| X | MSACM | msacm.exe | Added by the OPASERV-O WORM! |
| X | msadcheck | msadcheck32.exe | Browser hijacker, redirecting to search-system.com
|
| X | MSAdmin | jdbgmrg.exe | Added by the DASMIN.A TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here |
| X | MSAgent | mshtm.exe | Browser hijacker - redirecting to buldog-search.com
|
| X | MSBB | msbb.exe | Advertising spyware |
| X | MSChoExE | suge.exe | Added by a variant of the RBOT WORM!
|
| ? | msci | mcinfo.exe | McAfee Internet Security related. What does it do and is it required? |
| X | mscman | mscman.exe | Spyware/malware, included into the latest version of Grokster, among others. According to research by SpyBot's PMK, "able to trick ZoneAlarm, auto-clicking it to allow passing through the firewall!" |
| U | mscn | mscn.exe | Part of the SafeChildNet internet filtering program - required if you use it |
| X | Mscnt | mscnt.exe | Adult content dialler |
| X | Mscolour | mscolour.exe | Added by the GEMA TROJAN! |
| X | MSCommX | mscommx.exe | Added by a variant of the RBOT WORM! |
| X | MSCONFG32.EXE | MSCONFG32.EXE | Added by the OPTIX.04.C TROJAN! |
| N | MSConfig | msconfig.exe | Entry that appears when you uncheck an item in the MSConfig Startup group, and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode |
| X | MSConfig | MSCONFIG32.EXE | Unidentified adware, spyware or virus |
| X | msconfig | msconfig.exe | CoolWebSearch parasite related. Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting |
| X | Msconfig | msconfig.exe | Added by the WINUR WORM! Note - this is not the real msconfig.exe as it's located in C:winrun |
| X | msconfig | wins.exe | Added by an unidentified IRC WORM with backdoor trojan capabilities!
|
| X | Msconfig lptt01 | msconfig.exe | Variant of the RapidBlaster parasite (in a "msconfig" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Windows Msconfig which has the same executable name |
| X | MSConfig Manager | msupdate.exe | CoolWebSearch parasite related |
| X | Msconfig ml097e | msconfig.exe | Variant of the RapidBlaster parasite (in a "msconfig" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Windows Msconfig which has the same executable name |
| X | msconfig service | MSupdate32.exe | Added by a variant of the SPYBOT WORM! |
| X | msconfig.exe | proxy.exe | Added by a variant of the AGENT.AH downloader TROJAN! |
| X | msconfig.exe | uline.exe | Added by a variant of the AGENT.AH downloader TROJAN! |
| X | MSConfig45 | MSConfig45.exe | Added by the SDBOT.OJ TROJAN! |
| X | MSConfigr | jdbgmrg.exe | Added by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here |
| N | MSConfigReminder | msconfig.exe | Entry that appears when you uncheck an item in the MSConfig Startup group, and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode |
| X | MSCORE | syscnfg.exe | Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
| X | Mscsgs | MSCSGS.EXE | Added by the ZEZER WORM! |
| X | Mscsgs32 | MSCSGS32.EXE | Added by the ZEZER WORM! |
| X | Msctrl32 | Msctrl32.scr | Added by the REDIST WORM! |
| X | MSCVT | MSCVT.exe | Added by the SLIDESHOW WORM! |
| X | msdev | msdev.exe | Added by the FORBOT-CR WORM! |
| X | msdev | msconfig.exe | Added by the AGOBOT.AAU WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting |
| X | MSDLL | syscnfg.exe | Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
| X | Msdmxm | msdmxm.exe | Adult premium rate dialler |
| X | Msdos32 | Msdos32.pif | Added by the RECORY WORM! |
| X | msdos423 | msdos423.exe | Added by the MENACE.A WORM! |
| N | MSDosdrv | msdosdrv.exe | Added by the BACROS WORM! |
| N | MSDTC | msdtc.exe | MS Distributed Transaction Coordinator - handles transactions across multiple servers and is installed by MS Personal Web Server and MS SQL Server |
| X | Msemu32 | Msemu32.exe | Unidentified spyware/adware/hijacker |
| X | Msfind | Msfind.exe | CoolWebSearch parasite variant |
| X | MSFind32 | msfind32.exe | Added by the CAYAM WORM! |
| X | msfindosa.exe | msfindosa.exe | Added by the DOWNLOADER-BS TROJAN! |
| X | MsgApi | [path to file] | Added by the DEDLER-D TROJAN! |
| X | msgb1 | msgb1.exe | Added by the DLUCA.GEN TROJAN! |
| X | Msgmgr | [path to worm] | Added by the BABYBEAR WORM! |
| X | msgserv_ | Syss.exe | Added by the FANTA TROJAN! |
| X | Msgsrv16 | Msgsrv16.exe | Added by the DELF family of TROJANS! |
| Y | MSGSRV32.exe | msgsrv32.exe | Windows 32-bit VxD Message Server. For more information on its function and why it's needed, see here. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background |
| X | msgsvr32 | msgsvr32.exe | Added by the DEADHAT.B WORM! Note - not to be confused with the valid "msgsrv32.exe" file which resides in the same directory (C:WindowsSystem) on a Win9x/Me machine |
| X | Msgtray | sys16.exe | Added by an unknown VIRUS! |
| X | MSHT@ | MSHT@.EXE | Added by the MAGISTR.A VIRUS! |
| X | msidle | msidle.exe | Added by the OPASERV-O WORM! |
| X | MSIEXEC | MSIEXEC32.exe | Added by the AINESEY.A WORM! |
| ? | MSIN | MSin.exe | ?? |
| X | MSInfo | msinfo.exe | Added by the ALADINZ.M TROJAN! |
| X | MSInfo | AVBgle.exe | Added by the NETSKY.O WORM! |
| X | msjava service | xpcd.exe | Added by the SDBOT.VM WORM! |
| U | MSKAGENTEXE | MskAgent.exe | Part of McAfee Spamkiller |
| X | MSKCES32 | [random filename] | Added by the CLONER TROJAN! |
| U | MSKDetectorExe | MSKDetct.exe | Part of McAfee Spamkiller |
| X | MSKernel32 | MSKernel32.vbs | Added by the LOVELETTER (I LOVE YOU) VIRUS! |
| X | MSkernel32 | System.exe 4820 | Added by the TUXDER TROJAN! |
| U | MSKExe | spamkiller.exe | McAfee SpamKiller |
| U | MSKServerExe | MSKSrvr.exe | Part of McAfee Spamkiller
|
| X | mslagent | mslagent.exe | Added by SIMCSS.B adware! |
| ? | MSLIB32 | mswatch32.exe | ?? |
| X | Mslogon lptt01 | mslogon.exe | Variant of the RapidBlaster parasite (in a "Mslogon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | Mslogon ml097e | mslogon.exe | Variant of the RapidBlaster parasite (in a "Mslogon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | MsManager | msmgr32.exe | Added by the YAHA.AF WORM! |
| X | msmanager32 | msmngr32.exe | Added by the RANDON-R (or WOMANIZ.A) WORM! |
| X | msmc | mscpbo.exe | ClientMan parasite variant |
| X | msmc | msgdmf.exe | ClientMan parasite variant |
| X | msmc | msongn.exe | ClientMan parasite variant |
| X | msmc | msmc.exe | ClientMan parasite variant |
| X | MSMcAfeee | Avsynmgr32e.exe | Added by the FRAMAR TROJAN! |
| X | MSMcAfeeh | Avsynmgr32h.exe | Added by the FRANGO TROJAN! |
| X | MSMcAfeeS | Avsynmgr32S.exe | Added by the VOLAC or VOLAC.DR TROJANS! |
| ? | msmgr | msmgr.exe | ?? |
| X | Msmgt | msmgt.exe | Total Velocity adware/hijacker |
| X | msmon | msmon.exe | Added by a variant of the GEMA.D TROJAN! |
| ? | MsmqIntCert | regsvr32 /s mqrt.dll | Microsoft Message Queue Server - Internal Certificate - see here for more info and here for a potential problem. Is it required? |
| U | MSMSGS | msmsgs.exe | Windows Messenger utility. If you don't use Windows Messenger, this can be annoying. Available via Start -> Programs. Go to Windows Messenger > Tools > Options > Preferences and uncheck "Run this program when Windows starts" |
| X | MSMsgSvc | MSMSGSVC.exe | Browser hijacker, identified by some antiviruses as a variant of the StartPage.QC TROJAN!
|
| X | msn | system32.exe | Added by the KITRO.A WORM! |
| X | msn | msnmsg.exe | Added by the RBOT-GO WORM! |
| X | MSN | msnmsgs.exe | Added by the RBOT-KL WORM! |
| X | MSN | ctfmoons.exe | Added by the SPYBOT.HI WORM!
|
| X | MSN ang | cssrss.exe | Added by the FORBOT-CE WORM!
|
| X | Msn Config | msngf.exe | Added by the RBOT-QG WORM! |
| N | MSN Internet Access | trayclnt.exe | Quick way to connect to MSN internet service - replaces "MSN Quick View" from V5.6 onwards |
| X | MSN Manager | cvss.exe | Added by a variant of the SPYBOT WORM! |
| X | MSN Messanger | msnmsng.exe | Added by the SDBOT.XN WORM! |
| X | MSN messenger | messenger.exe | Added by an unidentified TROJAN! Note - this is not the real MSN Messenger, see this thread |
| X | MSN messenger service | mssgs.exe | Added by an unidentified TROJAN! Note - this is not the real MSN Messenger, see this thread |
| X | Msn Messengers | MSNMSGR.EXE | Added by the RBOT.KX WORM! |
| X | Msn Plus Updater | msnplus.exe | Added by the RBOT-MU WORM! |
| N | MSN Quick View | Msndc.exe | Quick way to connect to MSN internet service |
| X | MSN Start | msnmsgr7.exe | Added by the RBOT-PH WORM!
|
| X | Msn Update Manager (Sp2) | MSMSGS.EXE | Added by the AGOBOT-NL WORM!
|
| X | MSN Updater | msnms.exe | Added by the FORBOT-CG WORM!
|
| X | Msn Updater | msnplugins.exe | Added by the RBOT-HS WORM! |
| X | MSN UPDATERS | virtualmemory.exe | Added by the RBOT-JK WORM! |
| N | msnappau | msnappau.exe | Updater for the MSN toolbar that can be downloaded onto IE. Calls home every day or so to "update" the toolbar |
| X | Msnarrator | msnarrator.exe | Added by the NARAT.A TROJAN! - also identified as MPGCOM Toolbar adware |
| X | MSNET | msnet.exe | Added by the BOA WORM! |
| ? | MsnFixer | msnfixjs.js | Located in the HPbinmsnfix directory of a HP PC |
| X | MSNGrabber | MSNgrabber.exe | Added by the ENVID.A WORM!
|
| N | MSNIA | MSNIASVC.EXE | Added with MSN version 9. Resets certain internet settings upon bootup and can't be disabled via MSCONFIG |
| X | msnload32.exe | msnload32.exe | Added by the BANCOS.M TROJAN! |
| X | MSNMESENGER | Main.exe | Added by the PRORAT TROJAN! |
| N | msnmsgr | msnmsgr.exe | MSN Messenger utility. If you don't use MSN Messenger, this can be annoying. Available via Start -> Programs. Go to MS Messenger > Tools > Options > Preferences and uncheck "Run this program when Windows starts" |
| X | MsnMsgr | MsnMsgrs.exe | Added by the NETSKY-AD WORM!
|
| X | msnmsgr32-.exe | msnmsgr-.exe | Added by a variant of the SPYBOT WORM! |
| X | MSNMSGR5 | MSNMSGR5.exe | Added by the RBOT.PQ WORM! |
| X | MSNMSGRE | swef.bat | IRC backdoor TROJAN or WORM! |
| X | MSNMSGRR | swin.bat | IRC backdoor TROJAN or WORM! |
| X | MSNMSGRS1 | swed.bat | IRC backdoor TROJAN or WORM! |
| X | msnmsgsgs | msnmsgsgs.exe | Added by the "Catal" alias Spy.Delitall.B backdoor TROJAN!
|
| X | MSNService | MSNService.exe | Added by the CARPET.C WORM! |
| X | MSNSysRestore | pc32.exe | Added by a variant of the MASTAK VIRUS! |
| X | MSObject32 | MSObject32.js | Added by the PUN TROJAN! |
| X | Msoffice | msoffice.hta | Hijacker - redirecting to Searchdot.net |
| X | MSOffice | services.exe | Browser hijacker. The file is placed in a newly created MSOffice folder in System32. Note - this is NOT the legitimate services.exe process, which should NOT figure in Msconfig/Startup!
|
| X | MSOOBD | MSOOBD.EXE | Added by the MAGISTR.A VIRUS! |
| X | Mspatch69 | [path to trojan] | Added by the MPROX TROJAN! |
| X | Mspatch89 | cnqmax.exe | Added by the RANDEX.P WORM! |
| X | MSPQFile | MSA****.TMP | Homepage hijacker. See here for more information. **** can be anything |
| X | MSprotect.exe | MSprotect.exe | |