| Status Code | Name | Command | Description |
| X | MyWebSearch Email Plugin | mwsoemon.exe | "My Web Search" malware |
| U | MyVitalAgent | VtlAgent.exe | MyVitalAgent from Lucent Technologies. Replacement for Net.Medic, monitoring all popular internet transactions and alerting the user of the loaction of connection problems. Available via Start -> Programs |
| X | MyVirt.exe | MyVirt.exe | Added by the REMADM-C TROJAN!
|
| X | MyTotalSearch Email Plugin | mtsoemon.exe | MyTotalSearchBar adware |
| U | MytekSystrayExePath | MyTekSystray.exe | MyTek system tray - web site providing computer tech support in Australia |
| ? | MySoftware NewsFlash | Newsflsh.exe | ?? |
| X | mysoft | winexplor.exe | Homepage hijacker |
| U | myprint mileage | mpm.exe | Reports battery status on a portable printer |
| X | MyPointsPointAlert | wjview ...MyPointsPointAlertrun.exe | "With MyPoints you can earn rewards from name-brand merchants. You can even earn vacations and frequent flyer miles". Dubious privacy policy |
| U | myNetWatchman | nwclient.exe | Sends your firewall alerts to a website, which then filters them and forwards details of suspicious activities to the host ISP they originated from. Only needs to be running when your firewall is running |
| X | MyLife | CmdServ.exe | Added by the HOLAR.A WORM! |
| N | MyFastAccess | myfastupdate.exe | My-Fast-Access toolbar updater |
| X | MyDailyHoroscope | MyDailyHoroscope.exe | MyDailyHoroscope foistware |
| X | MyDailyHoroscope | MYDAIL~1.EXE | MyDailyHoroscope foistware |
| X | MyCometCursor | MYCOME~1.EXE | Comet Cursor adware |
| U | myCIO.com ASaP | MyAgtTry.exe | System tray notification for McAfee VirusScan ASaP on-line scanner. Not required to be protected but you lose notifications |
| N | myCIO.com Splash | Splash.exe | Splash screen for McAfee VirusScan ASaP on-line scanner |
| Y | MyCIO Agent Service | myagtsvc.exe | McAfee VirusScan ASaP Agent service |
| X | MyAV | avpguard.exe | Added by the NETSKY.J WORM! |
| X | Myapp | service.exe | Homepage hijacker |
| X | Myapp | [filename] | Added by the FATEE.B WORM! |
| U | MyAgtTry | MyAgtTry.exe | System tray notification for McAfee VirusScan ASaP on-line scanner. Not required to be protected but you lose notifications |
| X | My Search Bar Eq | S4BAREQ.EXE | MySearch bar parasite |
| X | My App | SMSSvc.exe | Added by the NEGASMS.A TROJAN! |
| X | My Agent | msagent.exe | Added by the NEGASMS.A TROJAN! |
| U | MxRunner | MxRunner.exe | EasyUninstall from Aladdin Systems (formerly by Ontrack) |
| U | MXO Auto Loader | MXOaldr.exe | Maxtor includes a driver to bypass the Windows certified drivers check just when it detects an external drive. MXOaldr.exe is installed with the new driver and if disabled the button on a Maxtor OneTouch External Store no longer functions |
| X | MxHLp32 | MxHLp32.exe | Added by a variant of the VAGRNOCKER TROJAN! |
| X | Mwsvm | mwsvm.exe | SeekSeek search hijacker related - as seen here |
| X | mwsoemon | mwsoemon.exe | "My Web Search" malware |
| N | MWSnap | MWSnap.exe | MWSnap - screen capture utility. Start manually when required |
| N | MWProEng | MWProEng.exe | Logitech Mouseware Pro software - only required when using special functions |
| N | MutexServiceEx | Sys32Smm.exe | Webroot Sofware's discontinued "Privacy Master" |
| U | mwavscan | mwavscan.com | MicroWorld Anti Virus Toolkit is a free anti-virus scanner that runs on-demand. You can choose to scan your entire system, including memory, services, starup items and registry, or only scan files in a specified folder or drive |
| X | MusIRC (irc.music.com) client | musirc4.71.exe | Added by the RANDEX.Q WORM! |
| N | Music01 Server | Music01 Server.exe | J River Media Jukebox |
| Y | murphy shield | lmgui.exe | Firewall part of BitDefender virus scanner/firewall |
| U | MUPS | MUPS.exe | Lauches the Belkin Bulldog Plus Service - required if you want to access the UPS advanced functions |
| U | MULTIMEDIA KEYBOARD | MMKeybd.exe | Multimedia keyboard manager. Required if you use the additional keys |
| U | MultiRes | MultiRes.exe | MultiRes - system tray utility allowing quick access to changing desktop resolutions and has the ability to lock the screen refresh rate in WinNT/2K/XP |
| U | Multimedia KBD | MMKeybd.exe | Multimedia keyboard manager. Required if you use the additional keys |
| X | Multimedia extensions | mservice.exe | EasySearch adware |
| X | Multimedia Codecs | mcc.exe | Added by the MCC TROJAN! |
| U | MultiCAM Initializer | MCamBoot.exe | The MultiCAM Initializer is part of the MultiCAM software package provided by Vista Imaging in order to run up to 10 USB ViCAM or 3Com Home Connect PC Digital cameras on a single computer. Clears itself from memory once initialized but can also be safely disabled |
| U | Multi-function keyboard | GWHotkey.exe | Software that sets up the Gateway AnyKey keyboard shortcuts (a series of buttons that allow one-click access to e-mail, browser, volume and CD/DVD controls, etc) |
| ? | Mufix | mufix.exe | Part of INFOConnect, web-based, enterprise client configuration, management, and deployment software, as used by ABSS (a financial management system used by the US military which will allow purchase request packages to be electronically submitted to contracting, and which also facilitates electronic receipt of items and EFT) - what does it do and is it required |
| U | muamgr | muamgr.exe | Quick access to MicroAngelo 5.0. It can make the background of the icon text transparent and also change the color of the shortcut's text to a color you want. Very useful, if you have a wallpaper. Available via Start -> Programs |
| X | Mtr2 | mtr2.exe | Added by the KRYPTONIC GHOST TROJAN! |
| U | MUAL | mual.exe | Millesky video mail updater and launcher |
| X | MS_SETUP.EXE | MS_SETUP.EXE | Added by the CHARGE TROJAN! |
| X | MS_NETD_WIN32 | netd32.EXE | Added by the RANDEX.F WORM! |
| X | Msys32 | morfitwebentrance.exe | Morfit ADjectPager - "uses home page rental technology for generating revenues". Homepage hi-jacker that re-defines your IE or Netscape start page as http://www.web-entrance.com/. Any installed application including this must be un-installed before you can reset your homepage |
| X | msys lptt01 | msys.exe | New variant of the RapidBlaster parasite (in a "Msyss" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | mswspl | searchbarcash.exe | SearchBarCash adware |
| X | mswspl | [random filename] | Added by the SMALL.IQ TROJAN! |
| X | MSWinSrv32 | MSWinSrv32.exe | Added by the MTRON-B TROJAN! |
| X | MSWinSrv | MSWinSrv.exe | Added by the MTRON TROJAN! |
| X | Mswinpid32 | mswinpid32.exe | Added by the LAPOS.A TROJAN! This is a keylogger which emails back to China PayPal passwords and account information - thus allowing the perpetrators to steal PayPal funds in the name of the victim!
|
| X | MsWindows SysDate | sysmsvc.exe | Added by the SPYBOT.FCD WORM!
|
| X | Mswincfg | Mswincfg32.exe | Added by the CYBRSPY.D TROJAN! |
| U | MSwheel | mswheel.exe | Microsoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features |
| X | Mswavedll | mswavedll.exe | Added by the CRYPTER-C TROJAN! |
| X | mswave | mswave.exe | Added by the CRYPTER.A TROJAN! |
| X | MSVXD | MSVXD.EXE | Added by the DATOM.A WORM! |
| X | MSVSync | videosync.exe | Added by a variant of the SPYBOT WORM! |
| X | msvsc32 | msdev.exe | Added by the RBOT-GJ WORM!
|
| X | MSVersion | clrschp038.exe | Added by the POPMON.A TROJAN! - also known as PopMonster adware |
| X | MSVersion | INTERNETFEATURES.exe | Added by the POPMON.A TROJAN! - also known as PopMonster adware |
| X | msvcc | msvchost.exe | Added by the XOMBE TROJAN! |
| X | msvc32 | msvc32.exe | ClientMan parasite variant |
| X | msuser32.exe | msuser32.exe | Added by the ANDROV TROJAN! |
| X | MSUpdSrv | msupdsrv.exe | Browser hijacker, redirecting to a porn site
|
| X | msurl | msurl32.exe | Added by the CRYPTER.A TROJAN! |
| X | msupdates | msupdt.exe | Added by the RBOT-JO WORM! |
| X | MSupdater.exe | N/A | CoolWebSearch parasite related. Installs the Winshow.dll browser plugin |
| X | MSupdate.exe | N/A | CoolWebSearch parasite related - resets home page to an adult content site |
| X | msupdate | msupdate.exe | Added by the RBOT-MZ WORM!
|
| X | MSUpdate | svchosthlp.exe | Added by the BLASTER.T WORM! |
| X | MSUpdate | wupd.exe | Added by the ALADINZ.M TROJAN! |
| X | Mstng32 | MSTng32.exe | Added by the TANG WORM! |
| ? | Mstcgww | MSTCGWW.EXE | ?? |
| X | mstasks | mstasks.exe | Added by the MULTIDR-AY TROJAN! |
| X | Mstask | mstask.exe | Added by the OPASERV.N WORM! Note - this is not the legitimate mstask.exe system file and the executable resides in C:Windows or C:WINNT |
| X | Mstapi | Mstapi.exe | Keylogger trojan |
| X | MsSystem | mssys.exe | Added by the VANTA.A TROJAN! |
| X | MsSystem | msdos.exe | Adult content downloader - see here |
| X | mssyslanhelper | msmsgri32.exe | Added by the RANDEX.D WORM! |
| X | mssysint | Iexplore .exe | Added by the PWSTEAL.ABCHLP and PSPIDER.310.B TROJANS! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
| X | mssys | mssys.exe | Added by the MYSS.B TROJAN! |
| Y | MSSVC.EXE | MSSVC.EXE | Stealthdisk - hides folders, files and applications. Will also encrypt them for better protection |
| X | mssvc32 | mssvc32.exe | Added by the AGOBOT-ME WORM! |
| X | mssvc | [path to trojan] | Added by the PSK TROJAN! |
| X | mssurfer ml097e | mssurfer.exe | Variant of the RapidBlaster parasite (in a "surfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | mssurfer lptt01 | mssurfer.exe | Variant of the RapidBlaster parasite (in a "surfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | msstask | msstask.exe | Added by the MYPARTY WORM! |
| X | MSStartOptimizer | WINUPD.EXE | Adult content dialler - see here. This has to be cleared at the same time as RegCompres (REGCPM32.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), otherwise they return |
| X | MSStartOptimizer | Iexpres.exe | Added by the POLDO.B TROJAN! |
| X | Msstart | msstart.exe | Added by the LIVUP.C TROJAN! |
| X | mssoul | msmscc2.exe | Added by the DAPIZL.A banker WORM! (A "banker worm" is designed to pillage banking information and send it back to the perpetrators!)
|
| X | MSSQL | Mssql.exe | Added by the SDBOT TROJAN! |
| X | MSSHVC | MSSHVC.exe | Added by the NUFFY.A WORM! |
| X | msservice | msserv.exe | Added by the HYD WORM! |
| X | msrunocx32 | msrunocx32.exe | Added by the SKUS WORM! |
| X | MSRegSvc | regsvc32.exe | Homepage hijacker that changes your homepage to an adult content site |
| X | msreg.exe | msrege.exe | Added by the ZINX TROJAN! |
| X | MSREGIT | Msgp.exe | Added by the KRYPGHOS.13 TROJAN! |
| X | Msrc | Msrc.exe | Added by the KRYPTONIC GHOST TROJAN! |
| N | MSPY2002 | ImScInst.exe | Part of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word |
| U | mspwr | pupstman.exe | "Transparent icon background" feature of Ashampoo's PowerUp XP (WinNT/2K/XP) and PowerUp Deluxe (Win98/Me) |
| X | MSprotect.exe | MSprotect.exe | Added by the DABYREV.A VIRUS! |
| X | MSPQFile | MSA****.TMP | Homepage hijacker. See here for more information. **** can be anything |
| X | Mspatch89 | cnqmax.exe | Added by the RANDEX.P WORM! |
| X | MSOOBD | MSOOBD.EXE | Added by the MAGISTR.A VIRUS! |
| X | Mspatch69 | [path to trojan] | Added by the MPROX TROJAN! |
| X | MSOffice | services.exe | Browser hijacker. The file is placed in a newly created MSOffice folder in System32. Note - this is NOT the legitimate services.exe process, which should NOT figure in Msconfig/Startup!
|
| X | MSNSysRestore | pc32.exe | Added by a variant of the MASTAK VIRUS! |
| X | MSObject32 | MSObject32.js | Added by the PUN TROJAN! |
| X | Msoffice | msoffice.hta | Hijacker - redirecting to Searchdot.net |
| X | MSNService | MSNService.exe | Added by the CARPET.C WORM! |
| X | msnmsgsgs | msnmsgsgs.exe | Added by the "Catal" alias Spy.Delitall.B backdoor TROJAN!
|
| X | MSNMSGRS1 | swed.bat | IRC backdoor TROJAN or WORM! |
| X | MSNMSGRE | swef.bat | IRC backdoor TROJAN or WORM! |
| X | MSNMSGRR | swin.bat | IRC backdoor TROJAN or WORM! |
| X | MSNMSGR5 | MSNMSGR5.exe | Added by the RBOT.PQ WORM! |
| X | msnmsgr32-.exe | msnmsgr-.exe | Added by a variant of the SPYBOT WORM! |
| X | MsnMsgr | MsnMsgrs.exe | Added by the NETSKY-AD WORM!
|
| N | msnmsgr | msnmsgr.exe | MSN Messenger utility. If you don't use MSN Messenger, this can be annoying. Available via Start -> Programs. Go to MS Messenger > Tools > Options > Preferences and uncheck "Run this program when Windows starts" |
| X | MSNMESENGER | Main.exe | Added by the PRORAT TROJAN! |
| X | msnload32.exe | msnload32.exe | Added by the BANCOS.M TROJAN! |
| N | MSNIA | MSNIASVC.EXE | Added with MSN version 9. Resets certain internet settings upon bootup and can't be disabled via MSCONFIG |
| X | MSNGrabber | MSNgrabber.exe | Added by the ENVID.A WORM!
|
| ? | MsnFixer | msnfixjs.js | Located in the HPbinmsnfix directory of a HP PC |
| X | MSNET | msnet.exe | Added by the BOA WORM! |
| X | Msnarrator | msnarrator.exe | Added by the NARAT.A TROJAN! - also identified as MPGCOM Toolbar adware |
| N | msnappau | msnappau.exe | Updater for the MSN toolbar that can be downloaded onto IE. Calls home every day or so to "update" the toolbar |
| X | MSN UPDATERS | virtualmemory.exe | Added by the RBOT-JK WORM! |
| X | Msn Updater | msnplugins.exe | Added by the RBOT-HS WORM! |
| X | MSN Updater | msnms.exe | Added by the FORBOT-CG WORM!
|
| X | Msn Update Manager (Sp2) | MSMSGS.EXE | Added by the AGOBOT-NL WORM!
|
| X | MSN Start | msnmsgr7.exe | Added by the RBOT-PH WORM!
|
| N | MSN Quick View | Msndc.exe | Quick way to connect to MSN internet service |
| X | Msn Plus Updater | msnplus.exe | Added by the RBOT-MU WORM! |
| X | Msn Messengers | MSNMSGR.EXE | Added by the RBOT.KX WORM! |
| X | MSN messenger service | mssgs.exe | Added by an unidentified TROJAN! Note - this is not the real MSN Messenger, see this thread |
| X | MSN messenger | messenger.exe | Added by an unidentified TROJAN! Note - this is not the real MSN Messenger, see this thread |
| X | MSN Messanger | msnmsng.exe | Added by the SDBOT.XN WORM! |
| X | MSN Manager | cvss.exe | Added by a variant of the SPYBOT WORM! |
| N | MSN Internet Access | trayclnt.exe | Quick way to connect to MSN internet service - replaces "MSN Quick View" from V5.6 onwards |
| X | Msn Config | msngf.exe | Added by the RBOT-QG WORM! |
| X | MSN ang | cssrss.exe | Added by the FORBOT-CE WORM!
|
| X | MSN | ctfmoons.exe | Added by the SPYBOT.HI WORM!
|
| X | MSN | msnmsgs.exe | Added by the RBOT-KL WORM! |
| X | msn | msnmsg.exe | Added by the RBOT-GO WORM! |
| X | msn | system32.exe | Added by the KITRO.A WORM! |
| X | MSMsgSvc | MSMSGSVC.exe | Browser hijacker, identified by some antiviruses as a variant of the StartPage.QC TROJAN!
|
| U | MSMSGS | msmsgs.exe | Windows Messenger utility. If you don't use Windows Messenger, this can be annoying. Available via Start -> Programs. Go to Windows Messenger > Tools > Options > Preferences and uncheck "Run this program when Windows starts" |
| ? | MsmqIntCert | regsvr32 /s mqrt.dll | Microsoft Message Queue Server - Internal Certificate - see here for more info and here for a potential problem. Is it required? |
| X | msmon | msmon.exe | Added by a variant of the GEMA.D TROJAN! |
| X | Msmgt | msmgt.exe | Total Velocity adware/hijacker |
| ? | msmgr | msmgr.exe | ?? |
| X | MSMcAfeeS | Avsynmgr32S.exe | Added by the VOLAC or VOLAC.DR TROJANS! |
| X | MSMcAfeeh | Avsynmgr32h.exe | Added by the FRANGO TROJAN! |
| X | MSMcAfeee | Avsynmgr32e.exe | Added by the FRAMAR TROJAN! |
| X | msmc | msmc.exe | ClientMan parasite variant |
| X | msmc | msongn.exe | ClientMan parasite variant |
| X | msmc | msgdmf.exe | ClientMan parasite variant |
| X | msmc | mscpbo.exe | ClientMan parasite variant |
| X | MsManager | msmgr32.exe | Added by the YAHA.AF WORM! |
| X | msmanager32 | msmngr32.exe | Added by the RANDON-R (or WOMANIZ.A) WORM! |
| X | Mslogon ml097e | mslogon.exe | Variant of the RapidBlaster parasite (in a "Mslogon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| ? | MSLIB32 | mswatch32.exe | ?? |
| X | Mslogon lptt01 | mslogon.exe | Variant of the RapidBlaster parasite (in a "Mslogon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | mslagent | mslagent.exe | Added by SIMCSS.B adware! |
| U | MSKServerExe | MSKSrvr.exe | Part of McAfee Spamkiller
|
| U | MSKExe | spamkiller.exe | McAfee SpamKiller |
| X | MSKernel32 | MSKernel32.vbs | Added by the LOVELETTER (I LOVE YOU) VIRUS! |
| X | MSkernel32 | System.exe 4820 | Added by the TUXDER TROJAN! |
| U | MSKDetectorExe | MSKDetct.exe | Part of McAfee Spamkiller |
| X | MSKCES32 | [random filename] | Added by the CLONER TROJAN! |
| U | MSKAGENTEXE | MskAgent.exe | Part of McAfee Spamkiller |
| X | msjava service | xpcd.exe | Added by the SDBOT.VM WORM! |
| X | MSInfo | AVBgle.exe | Added by the NETSKY.O WORM! |
| X | MSInfo | msinfo.exe | Added by the ALADINZ.M TROJAN! |
| X | MSIEXEC | MSIEXEC32.exe | Added by the AINESEY.A WORM! |
| ? | MSIN | MSin.exe | ?? |
| X | msidle | msidle.exe | Added by the OPASERV-O WORM! |
| X | MSHT@ | MSHT@.EXE | Added by the MAGISTR.A VIRUS! |
| X | Msgtray | sys16.exe | Added by an unknown VIRUS! |
| X | msgsvr32 | msgsvr32.exe | Added by the DEADHAT.B WORM! Note - not to be confused with the valid "msgsrv32.exe" file which resides in the same directory (C:WindowsSystem) on a Win9x/Me machine |
| Y | MSGSRV32.exe | msgsrv32.exe | Windows 32-bit VxD Message Server. For more information on its function and why it's needed, see here. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background |
| X | Msgsrv16 | Msgsrv16.exe | Added by the DELF family of TROJANS! |
| X | msgserv_ | Syss.exe | Added by the FANTA TROJAN! |
| X | Msgmgr | [path to worm] | Added by the BABYBEAR WORM! |
| X | msgb1 | msgb1.exe | Added by the DLUCA.GEN TROJAN! |
| X | MsgApi | [path to file] | Added by the DEDLER-D TROJAN! |
| X | msfindosa.exe | msfindosa.exe | Added by the DOWNLOADER-BS TROJAN! |
| X | MSFind32 | msfind32.exe | Added by the CAYAM WORM! |
| X | Msfind | Msfind.exe | CoolWebSearch parasite variant |
| N | MSDTC | msdtc.exe | MS Distributed Transaction Coordinator - handles transactions across multiple servers and is installed by MS Personal Web Server and MS SQL Server |
| X | Msemu32 | Msemu32.exe | Unidentified spyware/adware/hijacker |
| N | MSDosdrv | msdosdrv.exe | Added by the BACROS WORM! |
| X | msdos423 | msdos423.exe | Added by the MENACE.A WORM! |
| X | Msdmxm | msdmxm.exe | Adult premium rate dialler |
| X | Msdos32 | Msdos32.pif | Added by the RECORY WORM! |
| X | MSDLL | syscnfg.exe | Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
| X | msdev | msconfig.exe | Added by the AGOBOT.AAU WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting |
| X | msdev | msdev.exe | Added by the FORBOT-CR WORM! |
| X | MSCVT | MSCVT.exe | Added by the SLIDESHOW WORM! |
| X | Msctrl32 | Msctrl32.scr | Added by the REDIST WORM! |
| X | Mscsgs32 | MSCSGS32.EXE | Added by the ZEZER WORM! |
| X | Mscsgs | MSCSGS.EXE | Added by the ZEZER WORM! |
| X | MSCORE | syscnfg.exe | Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
| N | MSConfigReminder | msconfig.exe | Entry that appears when you uncheck an item in the MSConfig Startup group, and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode |
| X | MSConfigr | jdbgmrg.exe | Added by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here |
| X | msconfig.exe | proxy.exe | Added by a variant of the AGENT.AH downloader TROJAN! |
| X | msconfig.exe | uline.exe | Added by a variant of the AGENT.AH downloader TROJAN! |
| X | MSConfig45 | MSConfig45.exe | Added by the SDBOT.OJ TROJAN! |
| X | msconfig service | MSupdate32.exe | Added by a variant of the SPYBOT WORM! |
| X | Msconfig ml097e | msconfig.exe | Variant of the RapidBlaster parasite (in a "msconfig" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Windows Msconfig which has the same executable name |
| X | MSConfig Manager | msupdate.exe | CoolWebSearch parasite related |
| X | Msconfig lptt01 | msconfig.exe | Variant of the RapidBlaster parasite (in a "msconfig" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Windows Msconfig which has the same executable name |
| X | msconfig | wins.exe | Added by an unidentified IRC WORM with backdoor trojan capabilities!
|
| X | Msconfig | msconfig.exe | Added by the WINUR WORM! Note - this is not the real msconfig.exe as it's located in C:winrun |
| X | msconfig | msconfig.exe | CoolWebSearch parasite related. Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting |
| X | MSConfig | MSCONFIG32.EXE | Unidentified adware, spyware or virus |
| N | MSConfig | msconfig.exe | Entry that appears when you uncheck an item in the MSConfig Startup group, and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode |
| X | MSCONFG32.EXE | MSCONFG32.EXE | Added by the OPTIX.04.C TROJAN! |
| X | Mscolour | mscolour.exe | Added by the GEMA TROJAN! |
| X | MSCommX | mscommx.exe | Added by a variant of the RBOT WORM! |
| X | Mscnt | mscnt.exe | Adult content dialler |
| U | mscn | mscn.exe | Part of the SafeChildNet internet filtering program - required if you use it |
| X | mscman | mscman.exe | Spyware/malware, included into the latest version of Grokster, among others. According to research by SpyBot's PMK, "able to trick ZoneAlarm, auto-clicking it to allow passing through the firewall!" |
| ? | msci | mcinfo.exe | McAfee Internet Security related. What does it do and is it required? |
| X | MSBB | msbb.exe | Advertising spyware |
| X | MSChoExE | suge.exe | Added by a variant of the RBOT WORM!
|
| X | MSAgent | mshtm.exe | Browser hijacker - redirecting to buldog-search.com
|
| X | msadcheck | msadcheck32.exe | Browser hijacker, redirecting to search-system.com
|
| X | MSAdmin | jdbgmrg.exe | Added by the DASMIN.A TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here |
| X | MSACM | msacm.exe | Added by the OPASERV-O WORM! |
| X | MS-RunKey | arr.exe | MS-Connect dialler/hijacker |
| X | MS7531 | ms7531.exe | Homepage hijacker |
| X | MS-HTML | [random filename] | Added by the LATINUS.15 TROJAN! |
| X | MS-Connect | web.exe | Adult content dialler - see here |
| X | MS-Connect | msite18.exe | Adult content dialler - see here |
| X | MS-Connect | game.exe | Adult content dialler - see here |
| X | MS-Connect | cdm.exe | Adult content dialler - see here |
| X | MS-Connect | arr.exe | Adult content dialler - see here |
| X | MS Updates | aupd.exe | Spyware web downloader |
| X | MS Updates | mscache.exe | Spyware web downloader |
| X | MS Updates | syshosts.exe | Added by the MYDOOM.Y WORM! |
| X | MS Update | syshost.exe | Added by the EVAMAN-F WORM! |
| X | MS SyS Restore | sysrestore.exe | Added by the RBOT.XM WORM! |
| X | Ms Spool32 | MS SPOOL32.EXE | Added by the ASASSIN TROJAN! |
| X | MS Sound Config 16bit | sndcfg16.exe | Added by the SDBOT.MB TROJAN! |
| X | MS Security Hotfix | service5.exe | Added by the GAOBOT.AG WORM! |
| X | MS Network Control | mswin.exe | Added by the DUMBA TROJAN! |
| X | MS Remote Procedure Call | msrpc32.exe | Added by the RBOT-QL WORM! |
| ? | MS management console | mms.exe | Suspicious as the Microsoft Management Console is "mmc.exe" and doesn't normally run at startup |
| X | MS lsass Startup | lsass135.exe | Added by the RBOT.WM WORM! |
| X | MS HTML | mslat.exe | Added by the LATINUS.SVR TROJAN! |
| X | MS HTML | msHtml.exe | Added by the PESTDOOR.31 TROJAN! |
| X | MS FIREWALL | msfirewall.exe | Added by the SDBOT-QH WORM!
|
| X | MS FIREWALL | msfrewall.exe | Added by the SDBOT-PU WORM! |
| X | MS Explorer | mexplore.exe | Added by the YAHA.AE WORM! |
| X | MS Decryption Software | active.exe | MediaTickets adware variant |
| X | MS Configuration | MSFramer.exe | Added by the RANDEX.OL WORM! |
| X | MS Config Service | Msloader32.exe | Added by the RBOT-KJ WORM! |
| X | MS Config Loader | MSWin32bck.exe | Added by the GAOBOT.AA WORM! |
| X | MS Config Loader | svchos1.exe | Added by the AGOBOT.R WORM! |
| N | MRU-Blaster Silent Clean | mrublaster.exe | MRU-Blaster - performs silent cleaning of MRU lists at boot |
| U | MRU-Blaster Scheduler | scheduler.exe | MRU-Blaster scheduler - detects and cleans MRU (most recently used) lists on your computer |
| X | mqbkup | mqbkup.exe | Added by the OPASERV.K WORM! |
| N | mrtMngr | mrtMngr.exe | Maintenance Release Task Manager for Intuit?s QuickBooks or Quicken |
| ? | MP_STATUS_MONITOR | monitr32.exe | Related to Cannon Multi-Pass |
| N | MPXTray | mpxptray.exe | Windows Media Player PowerToy which is run from the taskbar. It can be used to hide Windows Media Player (when in use) and choose various standard buttons (play/pause, next,previous) etc |
| N | MPTBox | MPTBOX.EXE | Cannon Multi-Pass toolbox - a button bar |
| X | MPtask Services | mptask.exe | Added by the LALA or AOT TROJANS! |
| ? | MPT | MPT.exe | ?? |
| U | MPSExe | mscifapp.exe | McAfee.com Privacy Service - "combines personal identifiable information (PII) protection with online advertisement blocking and content filtering" |
| X | MprHTML | MprHTML.exe | Added by a variant of the VAGRNOCKER TROJAN! |
| Y | MPREXE.exe | mprexe.exe | WIN32 Network Service Interface Process. MPREXE.exe enables the computer to have multiple clients/protocols for networks. There are some problems with it sometimes though - see here and here. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background. NOTE : sometimes it will appear in start-ups if you have a virus |
| X | MPREXE | MPREXE.EXE | Added by the OPASERV.T WORM! Note - this is not the legitimate Mprexe.exe system file |
| U | MPower | MPower.exe | MPower from MindBeat. "Defragments and frees your RAM giving more stability to your system and avoiding needless use of swap file. Willl also benchmark (speed test) your hard disk drives and your CPU load". Some users swear by programs such as this but I suggest you read this article and make up your own mind |
| X | MPL32 driver | MPL32.exe | Added by the LOONY-M TROJAN! |
| U | MplSetup | MplSetup.exe | Used by Ricoh network printers to enable network printing from the client |
| Y | MPFExe | mpf.exe | McAfee Personal Firewall |
| Y | MPFExe | MpfTray.exe | McAfee Personal Firewall |
| U | MPEO | Csinsm32.exe | Automatic logging of installs from Norton CleanSweep - available via Start -> Programs |
| X | MP Tcloaxs | mptcloaxs.exe | Added by the RANDEX.CT WORM! |
| N | Mozilla Quick Launch | Mozilla.exe | Netscape 6 and Mozilla browsers |
| X | Movieplace | Movieplace.exe | MoviePlace malware |
| N | Mozilla Quick Launch | Netscp6.exe | Netscape 6 and Mozilla browsers |
| X | MovieNetworks | MovieNetworks.exe | MovieNetworks will connect you by DOMESTIC PREMIUM RATE TELEPHONE NUMBER 900-xxx-xxxx. So you get xxx rated pictures and junk. And it will allow you to stay on the internet on their line and $$$ and remove the C:Program FilesMovieNetworks directory |
| N | Movielink Manager Uninstall | msvcmm32.exe | Auto-update for Movielink - internet movie rental System Tray access |
| U | Mousinfo | mousinfo.exe | MS mouse information tool - for troubleshooting mouse problems |
| U | mouseElf | MC.exe | Genius NetScroll mouse driver - required if you use non-standard Windows driver features |
| U | MouseImp | MImpHost.exe | MouseImp Pro - "A reliable assistant that turns your mouse into a simple, native but powerful controlling device" |
| X | mousedrv | mousedrv.exe | Added by the CRYPTER.A TROJAN! |
| N | MouseCount | MC.exe | MouseCount by Kittyfeet Software. "Utility for counting how many times us computer junkies click our mouse in a given session/day/week/month/year." Not required |
| X | Mousecntl | mousecntl.exe | Added by a variant of the CRYPTER.C TROJAN! |
| X | mousebut | mousebut.exe | Added by the CRYPTER.A TROJAN! |
| N | Mouse Suite 98 Daemon | pelmiced.exe | Mouse driver. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games |
| N | Mouse 32A | Mouse32A.exe | Mouse driver to control mouse functions from Azona. Available via Start -> Programs |
| U | Mount Safe & Sound | Fbmount.exe | From McAfee VirusScan version 5.x. Creates back-up sets of critical files in a separate area of a hard drive. If you make regular back-ups it's not needed and can be painful during system start |
| U | MotMon | motmon.exe | Found on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used?the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it's not required |
| N | MotiveSB | MotiveSB.exe | System tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required |
| U | MotiveMonitor | motmon.exe | Found on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used?the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it's not required |
| N | Motive SmartBridge | MotiveSB.exe | System tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required |
| N | Motive SmartBridge | mpbtn.exe | System tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required |
| X | mosearch | mosearch.exe | Fast Search in Office XP - similar to the new revision of the Find Fast feature in Office 2000. Fast Search uses the Indexing Services in Office XP to create a catalog of Office files on your computer's hard disk. As with Find Fast - a waste of resources. If it can't be disabled via MSCONFIG try here |
| N | Morpheus | morpheus.exe | MusicCity Networks' Morpheus - another peer-to-peer client based on Kazaa. Notable in that this one doesn't seem to install the adware that clog the Kazaa download. They claim they are adware free, and a visitor quotes "I have seen no instance of any since using it" |
| N | moon phase | moon.exe | Moon Phase - tray icon that indicates the phases of the moon |
| U | MoodBook | mb.exe | MoodBook is a free Windows utility that brings art to your desktop |
| N | Monstersoundtray | Freectrl.exe | Diamond Multimedia sound card control panel |
| X | Monitormgt | Monitormgt.exe | Added by the GEMA TROJAN! |
| U | Monitor Apache Servers | ApacheMonitor.exe | Part of the Apache Web Server package. Useful only if you're running such a server on your PC. Available via Start -> Programs |
| X | Monitoring Service | svchost.exe | Added by the CONE.C WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| N | MoneyStartUp | Money Startup.exe | Microsoft Money |
| N | MoneyStartUp10.0 | Activation.exe | Part of MS Money 2002. Available via Start -> Programs |
| N | MoneyAgent | money express.exe | Part of MS Money. Available via Start -> Programs |
| N | MoneyAgent | mnyexpr.exe | Microsoft Money |
| N | Money Express | moneyexpress.exe | Part of MS Money. Available via Start -> Programs |
| X | Module Call initialize | RUNDLL32.EXE reg.dll, ondll_reg | Added by a variant of the LOVGATE WORM! |
| X | ModularConfig | syscnfg.exe | Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
| N | ModemUtility | mdmsetpe.exe | System Tray configuration icon for Aztech modems |
| U | ModemOnHold | MOH.EXE | NetWaiting Modem-on-Hold Application |
| U | MODEMBTR | MODEMBTR.EXE | Modem Booster from inKline Global to improve ISP connections |
| X | Modeminf | Modeminf.exe | Added by a variant of the CRYPTER.C TROJAN! |
| N | MOD | muamger.exe | MicroAngelo On Display from Impact Software lets you customize Windows icons. With a few exceptions, you can customize icons by right-clicking on them |
| X | MOBSYNC32.EXE | mobsync32.exe | Added by the FINERO TROJAN! |
| N | mobsync | mobsync.exe | MS Syncrhonization Manager - updates the network copy of materials that were edited offline, such as documents, calendars, and e-mail messages |
| X | mnsvcsp | mnsvcsp.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | mnsvc | mnsvc.exe | Added by the AUTOUPDER TROJAN! |
| U | MNS | MNS.exe | Mobile Net Switch enables you to use your computer on more then one network with the click of a button. It allows you to automatically select the correct drive mappings, printer settings, IP settings and much more |
| X | MNPol | mnpol.exe | Adult content dialler |
| X | mmxrun | msosa.exe | Adult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), atisrc2 (windfind.exe) and RegCompres (REGCPM32.EXE), otherwise they return |
| ? | mmusrstp | procrun.exe | ?? |
| N | MMTrayLSI | MMTrayLSI.exe | Part of Morgan Multimedia Codecs. Only required when the codecs are used |
| N | MMTray2K | MMTray2K.exe | Part of Morgan Multimedia Codecs. Only required when the codecs are used |
| N | MMTray | MMTray.exe | Part of Morgan Multimedia Codecs. Only required when the codecs are used |
| N | MMTray | mm_tray.exe | MusicMatch Jukebox icon in the task tray - digital music player / CD burner and ripper / music organizer / playlist creator |
| X | MMtask Service | mmtask.exe | Added by the BACKGAT.A TROJAN! Not the valid MusicMatch Jukebox which has the same filename |
| N | mmtask | mmtask.exe | Part of MusicMatch Jukebox - digital music player / CD burner and ripper / music organizer / playlist creator |
| Y | MMTASK | mmtask.tsk | A check on the file's properties reveals "Multimedia background task support module". MMTASK is a very simple 16-bit program used by certain multimedia drivers (which are still 16-bit on Win9x) to perform background processing. Some soundcards need this to support MIDI, etc |
| X | MMSystem | RunDll32 | Added by the FUNNER-A WORM!
|
| ? | mmsys | recover.exe | ?? |
| ? | MMRun | mmrun.exe | ?? |
| N | mmpti | m1mmpti.exe | Mpact Mediaware Properties Taskbar Icon - multimedia software icon for Chromatic Research Mpact video cards |
| X | mmod | mmod.exe | Ezula - regarded as spyware/theftware and bundled with the popular iMesh and KaZaA file-sharing programs. Read here for more information |
| U | MMKeybd | MMKeybd.exe | Multimedia keyboard manager. Required if you use the additional keys |
| N | MMHotKey | |