Index Introduction Database Detailed Entries Updates Concise List HJT Forums Rogues Message Board

Windows startup programs - Database search

If you're frustrated with the time it takes your Windows 7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.

See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.

Last database update :- 29th Apr, 2013
31819 items listed

You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.

Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:

A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z

NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.

Please click on the Search button

2873 results found for M

Startup Item or Name Status Command or Data Description Tested
M-Audio Taskbar IconUM-AudioTaskBarIcon.exeSystem Tray access to the M-Audio control panel for their range of music devices/interfacesNo
M-soft OfficeXM-soft Office.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!No
Userinterface Report3rXM0USE.exeDetected by Trend Micro as WORM_MYTOB.HSNo
mmptiNm1mmpti.exeMpact Mediaware Properties Taskbar Icon - multimedia software icon for Chromatic Research Mpact video cardsNo
NvCplDXm2gr32.exeEnterOne - Switch dialer and hijacker variant, see hereNo
m2mXm2m.exeDetected by Malwarebytes Anti-Malware as Trojan.PWS.DF. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
M32infoXm32info.exeAdded by the CRYPTER.A TROJAN!No
Microsoft Windows XP Configuration LoaderXm32svco.exeDetected by McAfee as W32/Sdbot.worm.gen.yNo
M3Development_WhenUSave_InstallerXM3Development_WhenUSave_Installer.exeSaveNow adwareNo
My Web Search Community ToolsXm3IMPipe.exeMyWebSearch parasiteNo
My Web Search Bar Search Scope MonitorXm3SrchMn.exeMyWebSearch parasiteNo
M3TrayNm3tray.exeSystem Tray access to the now defunct Movielink "web-based video on demand (VOD) and electronic sell-through (EST) service offering movies, TV shows and other videos for rental or purchase". Movielink LLC were acquired by Blockbuster in 2008No
Messenger ExplorerXm41n.exeAdded by the SDBOT-SA BACKDOOR!No
m4n70s Personal FirewallXm4n70s.exeAdded by the SDBOT.ARK WORM!No
m4xrnheh.exeXm4xrnheh.exeDetected by McAfee as Generic PWS.y and by Malwarebytes Anti-Malware as PasswordStealer.Tibia. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
[random name]Xm?config.exePurityScan adwareNo
[random name]Xm?dtc.exePurityScan adwareNo
[random name]Xm?iexec.exePurityScan adwareNo
SystemStartXma2012.exeMega Antivirus 2012 rogue security software - not recommended, removal instructions hereNo
LoadServiceXMaaf, tempatmu bukan di sinAdded by the KAGEN-A TROJAN!No
MAAgentUMAAgent.exeRelated to MarkAny - a solution to prevent is unauthorized distribution of information through Floppy, CD, email, etcNo
macadodadinda.exeXmacadodadinda.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %UserProfile%No
{B179023B-6238-4499-8F26-CD73E9D90E0A}UMacDrive.exeMacDrive 7 from Mediafour Corporation - "enables anyone using Windows Vista, XP, and 2003 Server to seamlessly access Mac disks (HFS/HFS+) of all types, including CDs, DVDs, hard drives, floppy, Zip, Jaz, and more!"No
MacDriveUMacDrive.exeMacDrive 7 & MacDrive 6 CrossStripe Edition from Mediafour Corporation - "a perfect way to share files between Mac OS and Windows." Version 6 is not Vista compatible but doesn "include support for striped Mac arrays created with ATTO ExpressStripe software."No
MacDrive applicationUMacDrive.exeMacDrive 7 from Mediafour Corporation - "enables anyone using Windows Vista, XP, and 2003 Server to seamlessly access Mac disks (HFS/HFS+) of all types, including CDs, DVDs, hard drives, floppy, Zip, Jaz, and more!"No
Mediafour MacDriveUMacDrive.exeMacDrive 7 & MacDrive 6 CrossStripe Edition from Mediafour Corporation - "a perfect way to share files between Mac OS and Windows." Version 6 is not Vista compatible but doesn "include support for striped Mac arrays created with ATTO ExpressStripe software."No
MediafourGettingStartedWithMacDrive6UMacDrive.exeMacDrive 6 CrossStripe Edition from Mediafour Corporation - "a perfect way to share files between Mac OS and Windows." Unlike the standard version of MacDrive 7, this version is not Vista compatible but does "include support for striped Mac arrays created with ATTO ExpressStripe software."No
Macromedia Dreamweaver XMXmacdwXM.exeAdded by the AGOBOT-RI WORM!No
ATIMACEUMACE.exeATI Technologies Control Centre - installed alongside ATI graphics hardware and provides additional configuration options for these devices in the Managed Access to Catalyst™ Environment (MACE) componentNo
Yahoo MessenggerXmacfee_.exeAdded by the YAHLOV-G WORM!No
Windows Debugger 32Xmachineupdate32.exeDetected by Sophos as Troj/DwnLdr-JUQNo
Windows Debugger 32Xmachineupper32.exeDetected by McAfee as Generic Dropper and by Malwarebytes Anti-Malware as Trojan.BankerNo
MacLicNMacLic.exePart of the Conversions Plus suite from DataViz (which includes MacOpener) - allowing PC and MAC owners to share disksNo
MacLicenseNMacLic.exePart of the Conversions Plus Suite from DataViz (which includes MacOpener) - allowing PC and MAC owners to share disksNo
MacNameNMacName.exePart of the Conversions Plus Suite from DataViz (which includes MacOpener) - allowing PC and MAC owners to share disksNo
MacroPhoneUmacrophone.exeMacroPhone is a network based telephony application that "allows you to handle server based voice mail and fax functions for all users in your company" and "offers many related functions, like caller id display, call logging, call notification, mobil short message sending and flexible user rights management"Yes
MacroPhone ClientUmacrophone.exeMacroPhone is a network based telephony application that "allows you to handle server based voice mail and fax functions for all users in your company" and "offers many related functions, like caller id display, call logging, call notification, mobil short message sending and flexible user rights management"Yes
MacroVirusXMacroVirus.exeMacroVirus On-call rogue security software - not recommended, removal instructions hereNo
RegRunXmActiveX.exeAdware downloader - detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!No
MACVNTFYUMACVNTFY.EXEPart of MacDrive 6 CrossStripe Edition from Mediafour Corporation - "a perfect way to share files between Mac OS and Windows." Unlike the standard version of MacDrive 7, this version is not Vista compatible but does "include support for striped Mac arrays created with ATTO ExpressStripe software."No
Mediafour Mac Volume NotificationsUMACVNTFY.EXEPart of MacDrive 6 CrossStripe Edition from Mediafour Corporation - "a perfect way to share files between Mac OS and Windows." Unlike the standard version of MacDrive 7, this version is not Vista compatible but does "include support for striped Mac arrays created with ATTO ExpressStripe software."No
MAD.EXEYMAD.EXEMAD.exe is the MS Exchange 5.5 System Attendant and can also consume a large amount of resources - resolved by the latest Exchange 5.5 Service Pack. Also part of Exchange 2000 Server but does it have the same problems?. Apparently you need to leave this running but is it needed at start-up?No
MAFWTaskbarAppUMAFWTray.exeSystem Tray access to the Control Panel for the M-Audio series of Firewire audio interfacesNo
M-Audio Taskbar IconUMAFWTray.exeSystem Tray access to the Control Panel for the M-Audio series of Firewire audio interfacesNo
MagentNMAgent.exeAssociated with Mail.Ru - "the largest free e-mail service of the Runet". "Mail.Ru Agent is the most popular Russian instant messenger"No
MagenticUMagentic.exeMagentic by Incredimail - wallpaper/screensaver managerNo
ashampoo Magical UnInstallNMagicalUnInstall.exeAshampoo® Magical UnInstall - monitors each new program installation, saving a log of the current configuration and using this as a reference to completely uninstall it if you chose to do so at a later dateYes
MagicalUnInstallNMagicalUnInstall.exeAshampoo® Magical UnInstall - monitors each new program installation, saving a log of the current configuration and using this as a reference to completely uninstall it if you chose to do so at a later dateYes
MagUninstallNMagicalUnInstall.exeAshampoo® Magical UnInstall - monitors each new program installation, saving a log of the current configuration and using this as a reference to completely uninstall it if you chose to do so at a later dateYes
MagicantispyXMagicantispy.exeMagicantispy rogue spyware remover - not recommended, removal instructions hereNo
MagicDiscUMagicDisc.exeMagicISO - "very helpful utility designed for creating and managing virtual CD drives and CD/DVD discs"No
MagicDskUMAGICDSK.EXEMagic DeskTop is a small and novel utility which will allow you the option of hiding or showing your desktop iconsNo
MagicFormationUMagicFormation.exeMagicFormation from Tokyo Downstairs - a docking program that allows you to group icons in a ring anywhere on the desktop using mouse gestures to access things like My Documents, Notepad and Calculator. This entry appears when you select "Regist to startup" from the optionsYes
MagicFormation.exeUMagicFormation.exeMagicFormation from Tokyo Downstairs - a docking program that allows you to group icons in a ring anywhere on the desktop using mouse gestures to access things like My Documents, Notepad and Calculator. This entry appears when you select "Regist to startup" from the optionsYes
Activar o desktop sem fio LabtecUMagicKey.exeKeyboard and mouse software used by various manufacturers which allows the user to map keyboard and/or mouse buttons to various functions. Spanish version included with some Labtec wireless desktop setsNo
Activer l'ensemble clavier et souris sans fil LabtecUMagicKey.exeKeyboard and mouse software used by various manufacturers which allows the user to map keyboard and/or mouse buttons to various functions. French version included with some Labtec keyboardsNo
Draadloze Labtec-desktop inschakelenUMagicKey.exeKeyboard and mouse software used by various manufacturers which allows the user to map keyboard and/or mouse buttons to various functions. Dutch version included with some Labtec wireless desktop setsNo
Enable Belkin Wireless Keyboard DriverUMagicKey.exeKeyboard software included with a Belkin wireless keyboard which allows the user to map keys to various functionsNo
Enable Labtec NumPadUMagicKey.exeKeyboard and mouse software used by various manufacturers which allows the user to map keyboard and/or mouse buttons to various functions. Version included with a Labtec wireless number padNo
Enable Labtec Wireless DesktopUMagicKey.exeKeyboard and mouse software used by various manufacturers which allows the user to map keyboard and/or mouse buttons to various functions. Version included with a Labtec wireless desktop setNo
Enable Wireless Keyboard DriverUMagicKey.exeKeyboard software included with some wireless keyboards which allows the user to map keys to various functionsNo
Enable Wireless Mouse DriverUMouseAp.exeMouse software included with some wireless mice which allows the user to map buttons to various functionsNo
Enable Wireless Optical Mouse DriverUMouseAp.exeMouse software included with some optical wireless mice which allows the user to map buttons to various functionsNo
Game KeyboardUMagicKey.exeKeyboard and mouse software used by various manufacturers which allows the user to map keyboard and/or mouse buttons to various functionsNo
Kabellosen Labtec-Desktop aktivierenUMagicKey.exeKeyboard and mouse software used by various manufacturers which allows the user to map keyboard and/or mouse buttons to various functions. German version included with some Labtec wireless desktop setsNo
KB350eUMagicKey.exeKeyboard and mouse software used by various manufacturers which allows the user to map keyboard and/or mouse buttons to various functionsNo
Labtec Cordless Keyboard DriverUMagicKey.exeKeyboard and mouse software used by various manufacturers which allows the user to map keyboard and/or mouse buttons to various functions. Version included with a Labtec wireless keyboardNo
Magic KeyboardUMagicKey.exeKeyboard and mouse software used by various manufacturers which allows the user to map keyboard and/or mouse buttons to various functionsNo
MagicKeyUMagicKey.exeKeyboard and mouse software used by various manufacturers which allows the user to map keyboard and/or mouse buttons to various functionsNo
Media KeyUMagicKey.exeKeyboard and mouse software used by various manufacturers which allows the user to map keyboard and/or mouse buttons to various functionsNo
Povolit program Bezdrátová klávesnice a myš LabtecUMagicKey.exeKeyboard and mouse software used by various manufacturers which allows the user to map keyboard and/or mouse buttons to various functions. Czech version included with some Labtec keyboardsNo
Q-Type ProUMagicKey.exeKeyboard and mouse software used by various manufacturers which allows the user to map keyboard and/or mouse buttons to various functionsNo
Slim Multimedia KeyboardUMagicKey.exeKeyboard and mouse software used by various manufacturers which allows the user to map keyboard and/or mouse buttons to various functionsNo
VersatoUMagicKey.exeKeyboard and mouse software used by various manufacturers which allows the user to map keyboard and/or mouse buttons to various functionsNo
MagicLinker3UMagicLnk.exeThaiSoftware Thai DictionaryNo
MCXMAGICON.EXEAdded by the MAGICON.A TROJAN!No
MagicRotationUMagicPvt.exeMagicRotation for Samsung displays "provides the user with a rotation feature (0, 90, 180, 270 orientation) that facilitates the optimum utilization of computer display screen, better viewing and improved user productivity"No
VersatoUMagicRun.exeKeyboard and mouse software used by various manufacturers which allows the user to map keyboard and/or mouse buttons to various functionsNo
MagitimeNMagitime.exeMagitime - connection tracking utility which monitors online time, expense, data transferNo
LG MagnifierNMagnifyingGlass.exeScreen area magnifying utility for LG NotebooksNo
MagPlayerWatcher_cwzjpUMagPlayer.exeMagPlayer spywareNo
mahmudXmahmud.exeAdded by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an exampleNo
Microsoft Security Monitor ProcessXmail.exeAdded by a variant of the IRCBOT BACKDOOR!No
Winsock32 driverXmail.exeDetected by McAfee as MultiDropper-DC and by Malwarebytes Anti-Malware as Trojan.AgentNo
MailBellUmailbell.exeMailBell "notifies you about new email without interrupting you when you type or work with the mouse in other programs"Yes
mailbell.exeUmailbell.exeMailBell "notifies you about new email without interrupting you when you type or work with the mouse in other programs"Yes
MailCleanerUMAILCLEANER.EXEMailCleaner "offers professional protection against viruses and eliminates up to 99% of spam". Earlier versions contained GAIN adware by Claria CorporationNo
Windows HelpXmailinfo.exeDetected by Trend Micro as WORM_MYTOB.JXNo
mailman.exeXmailman.exeAdded by the CERTIF-E TROJAN!No
DynAdvance NotifierNMailNotifier.Exe"DynAdvance Notifier is an email notification tool that notifies you when you have new email on a variety of account types, including Gmail, Hotmail, MSN, AOL, Yahoo! Mail, POP3 and IMAP Mail.It sits in your system tray and opens a pop-up window whenever you receive new Email"No
MailSkinnerXmailskinner.exeMailSkinner - an application by Electronic Group , notorious for its premium rate "drive by" installed adult content dialers (see here)No
Quick Heal e-mail ProtectionYMailSvr.exePart of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. Anti-malware protection for mail serversNo
MailWasherProUMailWasher.exeMailWasher Pro anti-spam from FireTrustNo
MailWasherProUMailWasherPro.exeMailWasher Pro anti-spam from FireTrustYes
MailWasherProUMAILWA~1.EXEMailWasher Pro anti-spam from FireTrustYes
Mail_CheckXMail_Check.exeDetected by Trend Micro as WORM_PANOIL.CNo
2SearchXmain.exe2Search adwareNo
MAINUmain.exeSpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scanNo
MSNMESENGERXMain.exeAdded by the PRORAT TROJAN!No
PcRaiserXmain.exePcRaiser rogue optimization utility - not recommendedNo
SpyCop ScanCheckUMAIN.EXESpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scanNo
SuperCool Compress BackupUMain.exe"SuperCool Zip Backup software is a data backup, restore and file synchronization program"No
SystemOptimizer2008Xmain.exeSystemOptimizer2008 rogue optimization utility - not recommended, removal instructions hereNo
explorerXmain.vbeAdded by the SHUSH-A WORM!No
Main16Xmain16.exeAdded by the CRYPTER.A TROJAN!No
Winsock StartupXMain2.exeAdded by a variant of W32/Sdbot.wormNo
Main32Xmain32.exeAdded by the CRYPTER.A TROJAN!No
Ultimate System GuardXMainFAVProj.exeUltimate System Guard rogue security software - not recommended, removal instructions hereNo
laidiantuanXMainFrame.exeDetected by Malwarebytes Anti-Malware as Adware.ChinAd. The file is located in %UserProfile%\Documents\ldtNo
Ferramenta de carregamento do WindowsXmainget.exeDetected by McAfee as RDN/Generic PUP.x and by Malwarebytes Anti-Malware as Trojan.AgentNo
MainPrivacyXMainPrivacy.exeMainPrivacy rogue security software - not recommended, removal instructions hereNo
APC_SERVICEYmainserv.exeAPC PowerChute software which controls their range of uninterruptible power supplies (UPS) - to provide unattended shutdown of servers and workstations in the event of an extended power outage and status logging. Runs as a service on an NT based OS (such as Windows 7/Vista/XP)No
CmpntXmainsv.exeAdded by the TOMPAI-C TROJAN!No
MainviewexXmainviewex.exeAdded by the GEMA TROJAN!No
MS Shell ServicesUMainWnd.exeTeslain KidLogger surveillance software. Uninstall this software unless you put it there yourselfNo
AntivirusXmaja.exeAdded by the NETSKY.H WORM!No
ValuSetXMaJde.exeAdded by the SDBOT-OU WORM!No
system firewallXmakeini32.exeAdded by the AGOBOT-PS WORM!No
Microsoft Studio 12Xmaker.exeDetected by Kaspersky as Trojan-Spy.Win32.KeyLogger.sxl and by Malwarebytes Anti-Malware as Backdoor.AgentNo
maksqolpubftqqapfdkXmaksqolpubftqqapfdk.exeDetected by McAfee as Generic BackDoor!fqc and by Malwarebytes Anti-Malware as Trojan.Agent.INJNo
MAKTray?MAKTray.exeBelieved to be a valid HP application. What does it do and is it required?No
Malware ScannerXMalScr.exeMalware Scanner rogue security software - not recommended, removal instructions hereNo
Malware SweeperUMalSwep.exeMalware Sweeper - "Protects the user from malicious malware and monitors the sanity of the running programs"No
AlcmtrXMalware Doctor.exeMalwareDoc rogue security software - not recommended, removal instructions hereNo
Malware-WipeXMalware-Wipe.exeMalwareWipe rogue security software variant - not recommended, removal instructions hereNo
Malware-WipedXMalware-Wiped.exeMalwareWipe rogue security software variant - not recommended, removal instructions hereNo
MalwareAlarmXMalwareAlarm.exeMalwareAlarm rogue security software - not recommended, removal instructions hereNo
MalwareBotXMalwareBot.exeMalwareBot rogue security software - not recommended, removal instructions hereNo
MalwareBurn 6.9XMalwareBurn 6.9.exeMalwareBurn rogue security software - not recommended, removal instructions hereNo
MalwareBurn 7.0XMalwareBurn 7.0.exeMalwareBurn rogue security software - not recommended, removal instructions hereNo
MalwareBurn 7.1XMalwareBurn 7.1.exeMalwareBurn rogue security software - not recommended, removal instructions hereNo
MalwareBurn 7.2XMalwareBurn 7.2.exeMalwareBurn rogue security software - not recommended, removal instructions hereNo
MalwareBurn 7.3XMalwareBurn 7.3.exeMalwareBurn rogue security software - not recommended, removal instructions hereNo
MalwareCore 7.3XMalwareCore 7.3.exeMalwareCore rogue security software - not recommended, removal instructions hereNo
MalwareCore 7.4XMalwareCore 7.4.exeMalwareCore rogue security software - not recommended, removal instructions hereNo
MalwareCrushXMalwareCrush.exeMalwareCrush rogue security software - not recommended, removal instructions hereNo
malwaredefXmalwaredef.exeMalware Defender 2009 rogue security software - not recommended, removal instructions hereNo
MalwareMonitorXMalwareMonitor.exeMalwareMonitor rogue security software - not recommendedNo
MalwareProMFCXMalwarePro.exeMalwarePro rogue security software - not recommended, removal instructions hereNo
MalwareRemovalXMalwareRemoval.exeAdded by a fake version of Microsoft's Malicious Software Removal Tool - removal instructions hereNo
MalwareRemovalBotXMalwareRemovalBot.exeMalwareRemovalBot rogue security software - not recommended, removal instructions hereNo
MalwareStopperXMalwareStopper.exeMalware Stopper rogue security software - not recommendedNo
MalwareWar 7.3XMalwareWar 7.3.exeMalwareWar rogue security software - not recommended, removal instructions hereNo
MalwareWipeXMalwareWipe.exeMalwareWipe rogue security software - not recommended, removal instructions hereNo
MalwareWiped 5.5XMalwareWiped 5.5.exeMalwareWipe rogue security software variant - not recommended, removal instructions hereNo
MalwareWiped 5.6XMalwareWiped 5.6.exeMalwareWipe rogue security software variant - not recommended, removal instructions hereNo
MalwareWiped 5.7XMalwareWiped 5.7.exeMalwareWipe rogue security software variant - not recommended, removal instructions hereNo
MalwareWiped 5.8XMalwareWiped 5.8.exeMalwareWipe rogue security software variant - not recommended, removal instructions hereNo
MalwareWiped 6.1XMalwareWiped 6.1.exeMalwareWipe rogue security software variant - not recommended, removal instructions hereNo
MalwareWiped 6.2XMalwareWiped 6.2.exeMalwareWipe rogue security software variant - not recommended, removal instructions hereNo
MalwareWiped 6.3XMalwareWiped 6.3.exeMalwareWipe rogue security software variant - not recommended, removal instructions hereNo
MalwareWiped 6.4XMalwareWiped 6.4.exeMalwareWipe rogue security software variant - not recommended, removal instructions hereNo
MalwareWiped 6.9XMalwareWiped 6.9.exeMalwareWipe rogue security software variant - not recommended, removal instructions hereNo
MalwareWipedXMalwareWiped.exeMalwareWipe rogue security software variant - not recommended, removal instructions hereNo
MalwaresWipedsXMalwareWipeds.exeMalwareWipe rogue security software variant - not recommended, removal instructions hereNo
MalwareWipedsXMalwareWipeds.exeMalwareWipe rogue security software variant - not recommended, removal instructions hereNo
MalwareWipeProXMalwareWipePro.exeMalwareWipe rogue security software variant - not recommended, removal instructions hereNo
MalwareWiperXMalwareWiper.exeMalwareWipe rogue security software variant - not recommended, removal instructions hereNo
MalWarriorXMalWarrior.exeMalWarrior rogue security software - not recommended, removal instructions hereNo
Mam3PanYMam3Pan.ExeESI MAYA audio interface driverNo
Host ProcessXmame.exeAdded by the RBOT-APO WORM!No
MamutuYmamutu.exeBackground Guard feature of Mamutu from Emsi Software GmbH - which provides behaviour rather than signature based protection that "recognizes new and unknown Trojans, Worms and Viruses (Zero-Day attacks), without daily updates". The Background Guard "recognizes and blocks all potentially dangerous programs before they can cause any damage"Yes
Mamutu GuardYmamutu.exeBackground Guard feature of Mamutu from Emsi Software GmbH - which provides behaviour rather than signature based protection that "recognizes new and unknown Trojans, Worms and Viruses (Zero-Day attacks), without daily updates". The Background Guard "recognizes and blocks all potentially dangerous programs before they can cause any damage"Yes
VersionXmanage.exeJRAUN adware variantNo
ManageDesk LiteUManageDesk Lite.exeManageDesk Lite from Managebytes Desktop management software. Each desktop is a separate working space for you to useNo
ManagerXManagee.exeAdded by the VB-FGC TROJAN!No
PROCESSXManageProcess.exeDetected by McAfee as Generic.grp!mq and by Malwarebytes Anti-Malware as Backdoor.Messa. The file is located in %AppData%No
managerXmanager.exeDetected by Kaspersky as the SMALL.CVT TROJAN!No
Manager.exeXManager.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. Note that the Command field can be either blank or the same as the Name field and located in a sub-folder of %LocalAppData% - see here and hereNo
Microsoft Syn ManagerXManager.exeAdded by the SDBOT.BEF WORM!No
Plug ManagerXmanager.exeAdded by the VIRUT.CE VIRUS!No
RunXManager.exeAdded by the DELF.EUN TROJAN! The file is found in %AppData%\Roaming\Adobe - see the link for more informationNo
SysManagerXManager.EXEAdded by the DAGGER.140 BACKDOOR!No
winsecXmanager.exeDetected by McAfee as PWS-Zbot.gen.aru and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
MS Manager32 StartupXmanager32.exeDetected by Trend Micro as WORM_RBOT.ATFNo
MfgBoot?manboot.exe??No
MSN CST ManagerXmancstmgr.exeAdded by an unidentified WORM or TROJAN! See hereNo
MicroDigitalXmaneger.exeDetected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %AllUsersProfile%\Start Menu\Programs\diskNo
ManiaiconXmaniaicon.exeDetected by Avast as Win32:Adware-gen and by Malwarebytes Anti-Malware as Adware.K.ManiaIcon. The file is located in %ProgramFiles%\ManiaiconNo
Logitech QuickCamNManifestEngine.exeAutomatic updater for versions of Logitech QuickCam webcam software. Check for updates via the System Tray icon - see the "LogitechVideoTray" entryYes
LogitechSoftwareUpdateNManifestEngine.exeAutomatic updater for versions of Logitech QuickCam webcam software. Check for updates via the System Tray icon - see the "LogitechVideoTray" entryYes
ManifestEngineNManifestEngine.exeAutomatic updater for versions of Logitech QuickCam webcam software. Check for updates via the System Tray icon - see the "LogitechVideoTray" entryYes
manrotceXmanrotce.exeAdded by unidentified malwareNo
MatadorUmantispm.exeMailFrontier Desktop (Matador) email spam blocker softwareNo
ManyCamNManyCam.exeManyCam webcam effects softwareNo
MapEDCXMapEDC.exeAdded by the WaveRevenue-McBoo TROJAN!No
ADSL Diagnostic ToolsNmapiicon.exeSystem tray access to ADSL modem diagnostic tools. Available via Start → ProgramsNo
pdfMachine dispatcherUmapisnd.exepdfMachine Windows print driverNo
MAPISRVRXMAPISRVR.EXEDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%\Microsoft\Windows\WSUSNo
mapisvc32Xmapisvc32.exeAdded by the KX VIRUS and also recognised by Symantec as FPAI adwareNo
MapiyashaXMapiyasha.exeAdded by the SILLYFDC-DM WORM!No
Microsoft Application CenterXmappc.exeAdded by a variant of Win32/RbotNo
Microsoft Map PCXmappc.exeAdded by a variant of Win32/RbotNo
Microsoft Mapped PCXmappedpc.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %System%No
Microsoft Mapped PCXmapppc.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %System%No
NtcheckXmapserver.exeAdded by the TOMPAI-B WORM!No
MSConfigXmapwisl.exeDetected by Kaspersky as P2P-Worm.Win32.Palevo.nxsNo
Runmarc8mManagerUmarc8m95.exeMARC Sound System Manager for the Marc 8 MIDI sound card - allows for easy adjustment of the settingsNo
cronosXmarco!.scrDetected by Panda as Opaserv.HNo
mardbd.exeXmardbd.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %UserProfile%No
marioXmario.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %System%No
Remote Desktop ComputingUmarspc.exeMarspc Remote Desktop ComputingNo
Martin PrikrylXMartin Prikryl.exeDetected by Dr.Web as BackDoor.Armagedon.19No
NTSF MICROSOFT SYSTEMXmarya.exeDetected by Sophos as W32/Rbot-AXY and by Malwarebytes Anti-Malware as Backdoor.BotNo
_AntiSpywareYmasalert.exePart of McAfee AntiSpywareNo
kfienqXmasbl.batAdded by the KIFER TROJAN!No
mskriderXmaskrider.dll.vbsAdded by the SOLOW-F WORM!No
maskriderXmaskrider2001.vbsAdded by the SOLOW-G WORM!No
masqform.exeUmasqform.exePureEdge Viewer - provides automation framework to manage and deploy XML forms-based processes for e-business and e-government systems. PureEdge was taken over by IBM and the product eventually became IBM FormsNo
SHOWBOATXmassadhesive.exeDetected by Malwarebytes Anti-Malware as Backdoor.Messa. The file is located in %AppData%\CapturalateNo
WindowsKeyUpdateXmaster.exeAdded by the JOSAM WORM!No
Master Card Updaate 32XMastercard32.exeAdded by a variant of Win32/RbotNo
Master Volume SpyUMASTERVOLUMESPY.EXEVolume control for the Gateway Destination "DestiVu" media interfaceNo
MasWtjoyXmaswtjoy.exeDetected by Kaspersky as Trojan.Win32.Lebag.klgNo
fjdslssdfdXmat2.exeAdded by the SLAPEW.C TROJAN!No
ALLTEL DSL Check-up CenterUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". ALLTEL DSL Check-up Center is required to run with the Help and Support program. If you uncheck ALLTEL DSL Check-up Center and then run Help and Support it will add another ALLTEL DSL Check-up Center in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decideNo
AOL Broadband Check-UpUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". The AOL Self Support Tool is required to run with the Help and Support program. If you uncheck AOL and then run Help and Support it will add another AOL entry in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decideNo
AT&T Self Support ToolUmatcli.exeAT&T Resolution Assistant. "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". Resolution Assistant is required to run with the Help and Support program. If you uncheck AT&T Self Support Tool and then run Help and Support it will add another in the startup menu. If you remove Resolution Assistant via add/remove programs some menus in help and support will not be available. You decideNo
blueyonder Instant Support ToolUmatcli.exeBlueyonder Instant Support Tool. "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". Blueyonder Instant Support Tool is required to run with the Help and Support program. If you uncheck it and then run Help and Support it will add another in the startup menu. If you remove Blueyonder Instant Support Tool via add/remove programs some menus in help and support will not be available. You decideNo
broadband medicUmatcli.exeNTL's Broadband Medic. "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". Broadband Medic is required to run with the Help and Support program. If you uncheck Broadband Medic and then run Help and Support it will add another in the startup menu. If you remove Broadband Medic via add/remove program some menus in Help and Support will not be available. You decideNo
BT Broadband Basic HelpUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". BT Broadband Help is required to run with the Help and Support program. If you uncheck BT Broadband Help and then run Help and Support it will add another BT Broadband Help in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decideNo
BT Broadband Desktop HelpUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". BT Broadband Help is required to run with the Help and Support program. If you uncheck BT Broadband Help and then run Help and Support it will add another BT Broadband Help in the startup menu. If you remove the BT Broadband Help in the add/remove program some help menus in help and support will not be available. You decideNo
BT Broadband HelpUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". BT Broadband Help is required to run with the Help and Support program. If you uncheck BT Broadband Help and then run Help and Support it will add another BT Broadband Help in the startup menu. If you remove the BT Broadband Help in the add/remove program some help menus in help and support will not be available. You decideNo
HP Instant SupportUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". HP Instant Support is required to run with the Help and Support program. If you uncheck HP Instant Support and then run Help and Support it will add another HP Instant Support in the startup menu. If you remove the HP Instant Support in the add/remove program some help menus in help and support will not be available. You decideNo
HughesNet ToolsUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". HughesNet Tools is required to run with the Help and Support program. If you uncheck HughesNet Tools and then run Help and Support it will add another HughesNet Tools in the startup menu. If you remove the HughesNet Tools in the add/remove program some help menus in help and support will not be available. You decideNo
Net AssistantUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". Aliant Net Assistant is required to run with the Help and Support program. If you uncheck Aliant Net Assistant and then run Help and Support it will add another Aliant Net Assistant in the startup menu. If you remove the Aliant Net Assistant in the add/remove program some help menus in help and support will not be available. You decideNo
NetAssistantUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". NetAssistant is required to run with the Help and Support program. If you uncheck NetAssistant and then run Help and Support it will add another NetAssistant in the startup menu. If you remove the NetAssistant in the add/remove program some help menus in help and support will not be available. You decideNo
NetHelpUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". BTopenworld NetHelp is required to run with the Help and Support program. If you uncheck BTopenworld NetHelp and then run Help and Support it will add another BTopenworld NetHelp in the startup menu. If you remove BTopenworld NetHelp in the add/remove program some help menus in help and support will not be available. You decideNo
Quick HelpUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". Bluewin Quick Help is required to run with the Help and Support program. If you uncheck Bluewin Quick Help and then run Help and Support it will add another Bluewin Quick Help in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decideNo
Resolution AssistantUmatcli.exeDell Resolution Assistant. "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". Resolution Assistant is required to run with the Help and Support program. If you uncheck Resolution Assistant and then run Help and Support it will add another Resolution Assistant in the startup menu. If you remove the Resolution Assistant in the add/remove program some help menus in help and support will not be available. You decideNo
SBC Self Support ToolUmatcli.exematcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file. The SBC Self Support Tool is required to run with the Help and Support program. If you uncheck SBC and then run Help and Support it will add another SBC entry in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decideNo
Sprint DSL virtual assistantUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". Sprint DSL Virtual Assistant is required to run with the Help and Support program. If you uncheck Sprint DSL Airtual Assistant and then run Help and Support it will add another Sprint DSL Virtual Assistant in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decideNo
TelstraClear Broadband SupportUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". TelstraClear Broadband Support is required to run with the Help and Support program. If you uncheck TelstraClear Broadband Support and then run Help and Support it will add another TelstraClear Broadband Support entry in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decideNo
TELUS eCareUmatcli.exeTELUS Resolution Assistant. "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". TELUS Resolution Assistant is required to run with the Help and Support program. If you uncheck TELUS Resolution Assistant and then run Help and Support it will add another in the startup menu. If you remove TELUS Resolution Assistant via add/remove programs some menus in Help and Support will not be available. You decideNo
True Online CareUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". True Online Care is required to run with the Help and Support program. If you uncheck True Online Care and then run Help and Support it will add another True Online Care in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decideNo
Verizon Online Help & SupportUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". Verizon Online Help & Support is required to run with the Help and Support program. If you uncheck Verizon Online Help & Support and then run help and Support it will add another Verizon Online Help & Support in the startup menu. If you remove the Verizon Online Help & Support in the add/remove program some help menus in help and support will not be available. You decideNo
Verizon Online Support CenterUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". Verizon Online Support Center is required to run with the Help and Support program. If you uncheck Verizon Online Support Center and then run help and Support it will add another Verizon Online Support Center in the startup menu. If you remove the Verizon Online Support Center in the add/remove program some help menus in help and support will not be available. You decideNo
Windstream Broadband Check-up CenterUmatcli.exePart of the Windstream Broadband service from AllTel. "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". Windstream Broadband Check-up Center is required to run with the Help and Support program. If you uncheck it and then run Help and Support it will add another in the startup menu. If you remove Windstream Broadband Check-up Center via add/remove programs some menus in Help and Support will not be available. You decideNo
Xtra Help AssistantUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". Xtra Help Assistant is required to run with the Help and Support program. If you uncheck Xtra Help Assistant and then run Help and Support it will add another Xtra Help Assistant in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decideNo
rundl332Xmath.exe ...pluged.exeAdded by the DOOMJUICE WORM!No
RealPlayer Ath CheckXmathchk.exeAdded by the MYDOOM-AJ WORM!No
Matrix Screen LockerUmatrix.exeMatrix Screen Locker is a system tray application that allows for quick and secure PC lock when you wish. The screen does a "matrix style" scrolling characters effect when the lock is runningNo
ZMatrixUmatrix.exeZMatrix - "an animated desktop background which displays streaming characters in a style similar to what was used in the movie 'The Matrix'"No
Msn ServiceXmatrixcam.exeDetected by Trend Micro as WORM_MYTOB.JHNo
romahereXmatrixhere.exeSuperSpider hijacker - a CoolWebSearch parasite variantNo
Matrox PowerDesk SENMatrox.PowerDesk SE.exeMatrox PowerDesk SE - multi-display desktop management controlsNo
Matrox PowerDesk 8Nmatrox.powerdesk.exe"Matrox PowerDesk software provides extra multi-display desktop management controls"No
MAV_checkXmav_startupmon.exePart of the WinAntiVirus Pro 2007 rogue security software - not recommended, removal instructions hereNo
mav_startupmonXmav_startupmon.exePart of the WinAntiVirus Pro 2007 rogue security software - not recommended, removal instructions hereNo
SalestartXmav_startupmon.exePart of the WinAntiVirus Pro 2007 rogue security software - not recommended, removal instructions hereNo
MaxAlertsXmax.exeBonzi MaxALERT - spywareNo
MaxAntiSpyXMaxAntiSpy.exeMaxAntispy Russian rogue spyware remover - not recommendedNo
MaxBackScheduleUmaxbackservice.exeBackup scheduler for the Maxtor (now Seagate) range of external hard drives - part of Maxtor Quick StartNo
MaxBlastMonitorUMaxBlastMonitor.exeMaxblast hard drive utility for Maxtor (Seagate) drivesNo
MAXIMESSXmaxi.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData%\MultiNo
Notebook MaximizerUmaximizer_startup.exeToshiba Notebook Maximizer software - adjust settings to save battery power and increase efficiencyNo
RCAutoLiveUpdateXMaxLURC.exeMax Registry Cleaner rogue registry cleaner - not recommended, removal instructions here. The homepage for the tool has a poor reputationNo
mxomssmenuUmaxmenumgr.exeStatus manager for the Maxtor (now Seagate) OneTouch range of external hard drives. It monitors your PC to see if you have connected any supported drives to lauch the backup utilityNo
SystemDriveXmaxpaynow1.exeAdded by the TIBS.BKU TROJAN!No
DriveSystemXmaxpaynowti1.exeAdded by the TIBS.AZT TROJAN!No
RCSystemTrayXMaxRCSystemTray.exeMax Registry Cleaner rogue registry cleaner - not recommended, removal instructions here. The homepage for the tool has a poor reputationNo
MayaPanYMayaPan.ExeAudiotrak Maya soundcard driverNo
MoodBookUmb.exeMoodBook is a free Windows utility that brings art to your desktopNo
Malware BytesXmbam.exeDetected by Malwarebytes Anti-Malware as Trojan.FakeMBAM. Note - this is not the legitmate Malwarebytes file of the same name which is located in %ProgramFiles%\Malwarebytes' Anti-Malware - this one is located in %UserTemp%No
Malwarebytes Anti-Malware (reboot)Ymbam.exePart of Malwarebytes Anti-Malware - which is "considered to be the next step in the detection and removal of malware. This entry appears if MBAM detects malware that needs removing on a reboot if the associated files are lockedNo
Malwarebytes Anti-Malware (rootkit-scan)Ymbam.exePart of Malwarebytes Anti-Malware - which is "considered to be the next step in the detection and removal of malware. This entry appears if MBAM is scheduled to perform a root-kit scan on a rebootNo
Malwarebytes Anti-MalwareYmbamgui.exeEntry that appears under the HKLM\RunOnce registry key during installation of Malwarebytes Anti-MalwareYes
Malwarebytes' Anti-MalwareYmbamgui.exeSystem tray access to and notifications for the registered version of Malwarebytes Anti-Malware - which is "considered to be the next step in the detection and removal of malware. In our product we have compiled a number of new technologies that are designed to quickly detect, destroy, and prevent malware." Included up to version 1.62.* - from version 1.65.* it loads via the MBAMService (mbamservice.exe) serviceYes
mbamguiYmbamgui.exeSystem tray access to and notifications for the registered version of Malwarebytes Anti-Malware - which is "considered to be the next step in the detection and removal of malware. In our product we have compiled a number of new technologies that are designed to quickly detect, destroy, and prevent malware." Included up to version 1.62.* - from version 1.65.* it loads via the MBAMService (mbamservice.exe) serviceYes
MBDeviceXMBDevice.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.Gen. The file is located in %Windir%\MBDeviceNo
NBInstallXMBDownloader_876919.exeDetected by Total Defense as Mirar D. The file is located in %UserTemp%No
MBFreeSubliminalMessageSoftwareNMBFreeSubliminalMessageSoftware.exe"MB Subliminal Message Software is a wonderful personality development program that reaches out to your subconscious mind and creates a positive impact. This program aims at helping you increase your confidence and program your mind to set goals and be able to achieve them"No
SystemDataXMBlocker.exeMessenger Blocker rogue security software - not recommendedNo
MBM 4UMBM4.exeMotherboard Monitor 4 - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start → ProgramsNo
MBM 5UMBM5.exeMotherboard Monitor 5 - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start → ProgramsNo
MBNetUmbnet.exeMBNet (Portugal) Credit Card Processing softwareNo
Mailbox VerifierUmboxvrfy.exeMailbox Verifier (MV) is free software that will notify you about new messages arrived to your mailbox. Only works with POP3 mailboxes (not web-mail based systems). You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance)No
MBProbeUmbrpobe.exeMBProbe - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start → ProgramsNo
mbsmon32Xmbsmon32.exeMicro Bill Systems Billing Software - "is a potentially unwanted application that uses aggressive billing and collection service techniques to demand payment for Web site access after a three-day trial period has elapsed. It has been reported that these techniques may even result in a user no longer being able to browse the Internet"No
mbssm32Xmbssm32.exeMicro Bill Systems Billing Software - "is a potentially unwanted application that uses aggressive billing and collection service techniques to demand payment for Web site access after a three-day trial period has elapsed. It has been reported that these techniques may even result in a user no longer being able to browse the Internet"No
DNSXmc-110-12-0000079.exeShorty adware - also detected as the AGENT.FD TROJAN!No
services32Xmc-110-12-0000079.exeAdded by the TrojanDownloader.Agent.rv TROJAN!No
DNSXmc-58-12-0000080.exeShorty adware - also detected as the AGENT.FD TROJAN!No
DNSXmc-58-12-0000093.exeShorty adware - also detected as the AGENT.FD TROJAN!No
DNSXmc-58-12-0000120.exeShorty adware - also detected as the AGENT.FD TROJAN!No
services32Xmc-58-12-0000120.exe"Shorty" adware - also detected as the AGENT.FD TROJAN!No
DNSXmc-58-12-0000140.exeShorty adware - also detected as the AGENT.FD TROJAN!No
services32Xmc-58-12-0000140.exe"Shorty" adware - also detected as the AGENT.FD TROJAN!No
MC.exeXMC.exeDetected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %AllUsersProfile%\Start MenuNo
MouseCountNMC.exeMouseCount by Kittyfeet Software. "Utility for counting how many times us computer junkies click our mouse in a given session/day/week/month/year." Not requiredNo
mouseElfUMC.exeGenius NetScroll mouse driver - required if you use non-standard Windows driver featuresNo
SalestartXmc.exePart of SecurePCCleaner, WinAnonymous and other members of the PCPrivacyTool rogue privacy tool and other members of this family. See here for more examplesNo
BLMC3MouseUMC3mouse.exeMultimedia USB mouse manager. Required if you use the additional buttonsNo
Windows Media PlayerXmcafe32.exeAdded by the RBOT-YO WORM!No
(Default)XMcafee.exeAdded by the AGENT.AY TROJAN! Note - this is not a valid McAfee program and is located in %System%. This malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
mcafee Software IntrenetXmcafee.exeAdded by the RBOT-ATR WORM! Note - this is not a valid McAfee programNo
start extractingXmcafee.exeDetected by Kaspersky as Backdoor.Win32.Rbot.fo. Note - this is not a valid McAfee program and is located in %System%No
Windows UpdateXMcAfee.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. Note - this is not a valid McAfee program and the file is located in %CommonFiles%\SystemNo
Windows UpdateXMcAfee3.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %CommonFiles%\SystemNo
McAfee Windows ProtectionXmcafee32.exeAdded by a variant of the SPYBOT WORM!No
NAV Auto ProtectXmcafee32.exeAdded by a variant of the SPYBOT WORM!No
McAfee AntivirusXMcAfeeAV.exeAdded by a variant of Win32/RbotNo
McAfee Antivirus ProtectionXmcafeeAV.exeAdded by a variant of Win32/RbotNo
McAfee Antivirus 32XMCAFEEAV32.EXEAdded by the SPYBOT-EH WORM!No
McAfee BackupUMcAfeeDataBackup.exeMcAfee Online Backup (formerly Data Backup) - "takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos". Available as a stand-alone product or included in Internet Security and Total ProtectionYes
McAfee Backup and RestoreUMcAfeeDataBackup.exeMcAfee Online Backup (formerly Data Backup) - "takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos". Available as a stand-alone product or included in Internet Security and Total ProtectionYes
McAfee Data BackupUMcAfeeDataBackup.exeMcAfee Data Backup (now Online Backup) - "takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos". Available as a stand-alone product or included in Internet Security and Total ProtectionYes
McAfeeDataBackupUMcAfeeDataBackup.exeMcAfee Online Backup (formerly Data Backup) - "takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos". Available as a stand-alone product or included in Internet Security and Total ProtectionYes
Windows Media PlayerXmcafeee.exeAdded by the RBOT-SQ WORM!No
McAfeeScanPlusXMcAfeeScanPlus.exeAdded by the MEPCOD TROJAN! This trojan file does not belong to any McAfee Antivirus Software and is found in %Windir%\systemNo
Mcaffe AntivirusXMcafeescn.exeAdded by the RBOT.CP WORM!No
Sygate Personal FirewallXMcafeeupdate.exeAdded by the RBOT.YN WORM!No
Mcafee Auto ProtectXmcafeshield.exeAdded by the RBOT-UH WORM!No
Windows Serv PatchXMcaffe2005.exeAdded by a variant of Win32/RbotNo
McAfeeXMcAffeAv.exeDetected by Trend Micro as WORM_NETSKY.ALNo
MCAFFE FLD LOADERXMCAFFEFLD.EXEAdded by the RBOT-PY WORM!No
McAfee SecurityCenterYmcagent.exeMcAfee SecurityCenter is the main support center for McAfee's range of internet security products such as Total Protection, Internet Security and VirusScan. As well as providing System Tray access (via the "M" icon) for product configuration it also communicates with McAfee's servers to manage updates and virus alertsYes
mcagentYmcagent.exeMcAfee SecurityCenter is the main support center for McAfee's range of internet security products such as Total Protection, Internet Security and VirusScan. As well as providing System Tray access (via the "M" icon) for product configuration it also communicates with McAfee's servers to manage updates and virus alertsYes
mcagent_exeYmcagent.exeMcAfee SecurityCenter is the main support center for McAfee's range of internet security products such as Total Protection, Internet Security and VirusScan. As well as providing System Tray access (via the "M" icon) for product configuration it also communicates with McAfee's servers to manage updates and virus alertsYes
MCAgentExeYmcagent.exeMcAfee SecurityCenter is the main support center for McAfee's range of internet security products such as Total Protection, Internet Security and VirusScan. As well as providing System Tray access (via the "M" icon) for product configuration it also communicates with McAfee's servers to manage updates and virus alertsYes
mcui_exeYmcagent.exeMcAfee SecurityCenter is the main support center for McAfee's range of internet security products such as Total Protection, Internet Security and VirusScan. As well as providing System Tray access (via the "M" icon) for product configuration it also communicates with McAfee's servers to manage updates and virus alertsYes
MCUpdateExeXmcagent.exeDetected by Sophos as Troj/Antimca-A. Note - do not confuse with the legitimate McAfee SecurityCenter file of the same name which is normally located in %ProgramFiles%\McAfee.com\Agent. This one is located in %Root%No
MPFExeXmcagent.exeDetected by Sophos as Troj/Antimca-A. Note - do not confuse with the legitimate McAfee SecurityCenter file of the same name which is normally located in %ProgramFiles%\McAfee.com\Agent. This one is located in %Root%No
VirusScan OnlineXmcagent.exeDetected by Sophos as Troj/Antimca-A. Note - do not confuse with the legitimate McAfee SecurityCenter file of the same name which is normally located in %ProgramFiles%\McAfee.com\Agent. This one is located in %Root%No
VSOCheckTaskXmcagent.exeDetected by Sophos as Troj/Antimca-A. Note - do not confuse with the legitimate McAfee SecurityCenter file of the same name which is normally located in %ProgramFiles%\McAfee.com\Agent. This one is located in %Root%No
Mail.comUmcalert.exeSystem Tray notification for new email from the Mail.com free web-mail serviceNo
MultiCAM InitializerUMCamBoot.exeThe MultiCAM Initializer is part of the MultiCAM software package provided by Vista Imaging in order to run up to 10 USB ViCAM or 3Com Home Connect PC Digital cameras on a single computer. Clears itself from memory once initialized but can also be safely disabledNo
CleanUpYmcappins.exeUsed by older versions of McAfee internet security related products to clean up installation files that are no longer required once the product is installed. This entry will normally only appear once the product has been installed before the system is rebootedYes
McAfee Application InstallerYmcappins.exeUsed by older versions of McAfee internet security related products to clean up installation files that are no longer required once the product is installed. This entry will normally only appear once the product has been installed before the system is rebootedYes
mcappinsYmcappins.exeUsed by older versions of McAfee internet security related products to clean up installation files that are no longer required once the product is installed. This entry will normally only appear once the product has been installed before the system is rebootedYes
Malware Catcher 2009XMCatcher.exeMalware Catcher 2009 rogue security software - not recommended, removal instructions hereNo
McaFee virus detect program.XMcaUpdate.exeAdded by the AUTORUN-T WORM! Note - this is not a legitimate McAfee programNo
Media Card Companion MonitorUMCC Monitor.exeMonitor for Media Card Companion from ArcSoft. "Automates the tedious processes associated with downloading and sharing files from digital cameras, card readers, and other removable media"No
Multimedia CodecsXmcc.exeAdded by the DLOADER-MB TROJAN!No
Microsoft Internet ExplorerXmccagent.exeAdded by the DLOADER-UD TROJAN!No
MicrosoftCertificate®XMcCc.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%\WindowsNo
ACS_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for ACS usersNo
AliceRE_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for AliceRENo
AliceRV_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for AliceRVNo
ATT-SST_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for AT&T usersNo
BellCanada_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for Bell Canada usersNo
BellSouthFPS_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for Bell South usersNo
BellSouthWCC_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for Bell South usersNo
BLUEWIN_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for Bluewin usersNo
blueyonderWCM_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for Blueyonder (now Virgin Media) usersNo
bsnlLiteTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for Bharat Sanchar Nigam Ltd usersNo
btbb_wcm_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for BT usersNo
BTHelena_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for BTHelena usersNo
BTHelena_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for FAHESS/Suadi Telecom usersNo
BTHelena_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for Saudi Telecom usersNo
Club-Internet_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for Club-Internet usersNo
GlobeCom_Full_Client_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for GlobeCom\TELUS usersNo
oukwcm_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for Orange usersNo
poukTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for Orange usersNo
SingTel_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for SingTel usersNo
singtelRV_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for SingTel usersNo
singtelTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for SingTel usersNo
SoftBankBB_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for SoftBankBB usersNo
tcnzTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for Telecom New Zealand usersNo
TEData_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for TEData usersNo
TELUS Support CentreUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for TELUS usersNo
TELUS_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for TELUS usersNo
TelusWCC_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for TELUS Wireless usersNo
TO2SSM_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for Telefónica O2 usersNo
TO2WCM_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for Telefónica O2 usersNo
trueTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for True Online Care usersNo
Verizon_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for Verizon usersNo
Windstream_BCUC_McciTrayAppUMcciTrayApp.exeSystem tray access to Motive's broadband configuration and repair utility - for Windstream usersNo
AliceRE_McciTrayAppUMCCITR~1.EXESystem tray access to Motive's broadband configuration and repair utility - for AliceRENo
WinammpXmccm.exeAdded by the IRCBOT-HH BACKDOOR!No
Network ServiceXMccTrayApp.exeAdded by an unidentified WORM or TROJAN!No
EasyNetworkNMcENUI.exeMcAfee's EasyNetwork user interface - "enables secure file sharing, simplifies file transfers, and automates printer sharing among the computers in your home network." Part of McAfee's security products such as Total Protection and Internet SecurityYes
McENUINMcENUI.exeMcAfee's EasyNetwork user interface - "enables secure file sharing, simplifies file transfers, and automates printer sharing among the computers in your home network." Part of McAfee's security products such as Total Protection and Internet SecurityYes
Microfinder lptt01Xmcf.exeRapidBlaster variant (in a "mcf" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove itNo
Microfinder ml097eXmcf.exeRapidBlaster variant (in a "mcf" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove itNo
Avast72Xmcfartietray.exeDetected by Microsoft as Trojan:Win32/Sisron and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Windir%No
MChangerNMChanger.exeMedia Changer - utility that allows you to change wallpapers, sounds, themes, etcNo
msci?mcinfo.exeMcAfee Internet Security related. What does it do and is it required?No
GenMCLauncherNmcLauncher.exeGenesys Meeting Center - "On-demand integrated audio and web meetings"No
McLogLch_exeNMcLogLch.exeRelated to McAfee security suite. This is a non-essential program, but should not be disabled unless suspected to be causing problemsNo
MCM3Xmcm3.exeShopAtHome/SAHagent adware variantNo
OpenMstartXmcmgr32.exeMStart2Page - Switch dialer and hijacker variant, see here. Also detected as the SWITCH-E TROJAN!No
McAfee VirusScanYmcmnhdlr.exePart of older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online. When Windows boots it checks whether a virus scan is necessary before you do anything with your PC. Typically, this would be the case if a scan was scheduled at boot-up or if a virus was found during a previous scan and VirusScan determined a scan should be run at this timeYes
mcmnhdlrYmcmnhdlr.exePart of older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online. When Windows boots it checks whether a virus scan is necessary before you do anything with your PC. Typically, this would be the case if a scan was scheduled at boot-up or if a virus was found during a previous scan and VirusScan determined a scan should be run at this timeYes
VSOCheckTaskYmcmnhdlr.exePart of older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online. When Windows boots it checks whether a virus scan is necessary before you do anything with your PC. Typically, this would be the case if a scan was scheduled at boot-up or if a virus was found during a previous scan and VirusScan determined a scan should be run at this timeYes
ieupdateXMCP****.exe [**** = random char]Added by the ASOXY TROJAN!No
ieupdateXmcpdll32.exeAdware downloader trojanNo
MCPLaunchNMCPLaunch.exeLauncher for Message Center Plus "which alerts you when conditions arise on your computer that require your attention" on IBM/Lenovo ThinkCentre desktops, Thinkpad notebooks and Value Line systems. Message Center Plus will periodically scan a Lenovo server for new messages that are appropriate for your system and never collects or transmits any information about you or your computerYes
Message Center PlusNMCPLaunch.exeLauncher for Message Center Plus "which alerts you when conditions arise on your computer that require your attention" on IBM/Lenovo ThinkCentre desktops, Thinkpad notebooks and Value Line systems. Message Center Plus will periodically scan a Lenovo server for new messages that are appropriate for your system and never collects or transmits any information about you or your computerYes
1A:Stardock MCPYmcpserver.exeMaster Control Program for Stardock apps, in development. People should leave it running if they're using any of the Stardock applicationsNo
msuwarnXmcpuhost.exeDetected by Kaspersky as Worm.Win32.AutoRun.bciwNo
Windows UpdatesXmcrauto.exeDetected by Dr.Web as Trojan.DownLoader6.53584 and by Malwarebytes Anti-Malware as Worm.AutoRunNo
McRegWizNmcregwiz.exeProduct registration wizard for McAfee's range of internet security toolsNo
Mcrosoftr UpdateXMcrosoftr.exeAdded by a variant of Win32/RbotNo
Start UppingXmcrt32.exeAdded by a variant of the SPYBOT WORM!No
MUPDATEXmcsc.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\CSCNo
McaffeeXmcsheild.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
McShld9xYmcshld9x.exeWindow 9x/Me on-access scanner for older McAfee's internet security products such as VirusScan and VirusScan Online which scans files in real-time for malware as you access, create, copy or download themNo
cmssSystemProcessXmcsmss.exeAdded by the PROXYSER-F TROJAN!No
MCTskShdYmctskshd.exePart of older versions of McAfee's internet security products such as VirusScan and VirusScan Online and used to schedule tasks such as automatic updates, virus scans, etc. Starts via a registry "Run" key on Windows 98/Me and as a service on Windows 2K/XP/VistaNo
McAfee SecurityCenterYMcUpdate.exeAutomatic virus definition and software updates/upgrades for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan OnlineYes
McUpdateYMcUpdate.exeAutomatic virus definition and software updates/upgrades for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan OnlineYes
MCUpdateExeYMcUpdate.exeAutomatic virus definition and software updates/upgrades for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan OnlineYes
Microsoft UpdateXmcupdate.exeAdded by the RBOT.XT WORM! Note - this file is located in %System% and should not be confused with the McAfee antivirus executable as described hereNo
CurrencyXMcUpted.exeDetected by Dr.Web as Trojan.DownLoader8.21662 and by Malwarebytes Anti-Malware as Trojan.Agent.CUGenNo
EmailScanYmcvsescn.exeRelated to McAfee AntiVirus suite - used to automatically scan incoming e-mailsNo
McVsRteYmcvsrte.exePart of older versions of McAfee's internet security products such as VirusScan and VirusScan Online. Runs as a service on an NT based OS (such as Windows 7/Vista/XP)No
Shellapi32Xmcvsrte.exeAdded by an unidentified WORM! Note - do not confuse with the McAfee SecurityCenter file of the same nameNo
ActiveShieldYmcvsshld.exeActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed, including scanning E-mails via the McAfee VirusScan E-mail Scan Module (McVSEscn.exe)Yes
McAfee VirusScanYmcvsshld.exeActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed, including scanning E-mails via the McAfee VirusScan E-mail Scan Module (McVSEscn.exe)Yes
mcvsshldYmcvsshld.exeActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed, including scanning E-mails via the McAfee VirusScan E-mail Scan Module (McVSEscn.exe)Yes
VirusScan OnlineYmcvsshld.exeActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed, including scanning E-mails via the McAfee VirusScan E-mail Scan Module (McVSEscn.exe)Yes
Windows FileSharing ServiceXmcwsvc.exeAdded by the IRCBOT.AJF BACKDOOR!No
workstationsXMc_shield.exeDetected by Dr.Web as Trojan.DownLoader8.24057 and by Malwarebytes Anti-Malware as Trojan.AgentNo
MD IE PluginXmd.exeMarketdart spywareNo
SystemMDXmd.exeHomepage hijackerNo
File0_0XMD1.exeAdded by the DLOADER-OR TROJAN!No
Malware Destructor 2009XMD345d.exeMalware Destructor 2009 rogue security software - not recommended, removal instructions hereNo
MainProXmdamand.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System%No
Network Interfacees ServiceXmdcsc.exeDetected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
MDDiskProtectUMDDiskProtect.exePart of MacDrive 6 CrossStripe Edition from Mediafour Corporation - "a perfect way to share files between Mac OS and Windows." Unlike the standard version of MacDrive 7, this version is not Vista compatible but does "include support for striped Mac arrays created with ATTO ExpressStripe software."No
MDDiskProtect.exeUMDDiskProtect.exePart of MacDrive 6 CrossStripe Edition from Mediafour Corporation - "a perfect way to share files between Mac OS and Windows." Unlike the standard version of MacDrive 7, this version is not Vista compatible but does "include support for striped Mac arrays created with ATTO ExpressStripe software."No
Mediafour MacDriveUMDDiskProtect.exePart of MacDrive 6 CrossStripe Edition from Mediafour Corporation - "a perfect way to share files between Mac OS and Windows." Unlike the standard version of MacDrive 7, this version is not Vista compatible but does "include support for striped Mac arrays created with ATTO ExpressStripe software."No
Malware DefenseXmdefense.exeMalware Defense rogue security software - not recommended, removal instructions hereNo
Getting started with MacDriveUMDGetStarted.exeMacDrive 7 from Mediafour Corporation - "enables anyone using Windows Vista, XP, and 2003 Server to seamlessly access Mac disks (HFS/HFS+) of all types, including CDs, DVDs, hard drives, floppy, Zip, Jaz, and more!"No
MDGetStartedUMDGetStarted.exeMacDrive 7 from Mediafour Corporation - "enables anyone using Windows Vista, XP, and 2003 Server to seamlessly access Mac disks (HFS/HFS+) of all types, including CDs, DVDs, hard drives, floppy, Zip, Jaz, and more!"No
MDGetStarted.exeUMDGetStarted.exeMacDrive 7 from Mediafour Corporation - "enables anyone using Windows Vista, XP, and 2003 Server to seamlessly access Mac disks (HFS/HFS+) of all types, including CDs, DVDs, hard drives, floppy, Zip, Jaz, and more!"No
Mediafour MacDriveUMDGetStarted.exeMacDrive 7 from Mediafour Corporation - "enables anyone using Windows Vista, XP, and 2003 Server to seamlessly access Mac disks (HFS/HFS+) of all types, including CDs, DVDs, hard drives, floppy, Zip, Jaz, and more!"No
Microsoft Digital CryptorsXmdigits.exeDetected by Trend Micro as WORM_SDBOT.LMNo
MedionVFD?MdionLCM.exeRelated to Medion Display Information. What does it do and is it required?No
loadXmdm.exeDetected by Symantec as Backdoor.Binghe. Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %CommonFiles%\Microsoft Shared\VS7Debug (Windows 7/Vista/XP/ME/98) or %System% (WinME/98). This one is located in %System%No
Machine Debug ManagerXmdm.exeDetected by Sophos as W32/Sdbot-APE. Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %CommonFiles%\Microsoft Shared\VS7Debug (Windows 7/Vista/XP/ME/98) or %System% (WinME/98). This one is located in %Windir%No
Machine Debug ManagerUMDM.EXEUsed by developers for debugging and is a component of several MS products including Office and Visual Studio. Those who have encountered it have unchecked it with no degradation in performance. It may cause your computer to "hang" if you have Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendation. For this entry it loads under the "RunServices" key in WinME/98 (located in %System%). It runs a service in Windows 7/Vista/XP (located in %CommonFiles%\Microsoft Shared\VS7Debug)No
mdmXmdm.exeDetected by Sophos as Troj/Lydra-F. Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %CommonFiles%\Microsoft Shared\VS7Debug (Windows 7/Vista/XP/ME/98) or %System% (WinME/98). This one is located in %Windir%No
MDM7UMDM.EXEUsed by developers for debugging and is a component of several MS products including Office and Visual Studio. Those who have encountered it have unchecked it with no degradation in performance. It may cause your computer to "hang" if you have Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendation. For this entry it loads under the "RunServices" key in WinME/98 (located in %CommonFiles%\Microsoft Shared\VS7Debug). It runs a service in Windows 7/Vista/XPNo
Microsoft Firevall EngineXmdm.exeDetected by Sophos as W32/Pushbot-R and by Malwarebytes Anti-Malware as Backdoor.Agent. Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %CommonFiles%\Microsoft Shared\VS7Debug (Windows 7/Vista/XP/ME/98) or %System% (WinME/98). This one is located in %Windir%No
Microsoft OfficeXmdm.exeDetected by Sophos as Troj/IBot-A. Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %CommonFiles%\Microsoft Shared\VS7Debug (Windows 7/Vista/XP/ME/98) or %System% (WinME/98). This one is located in %System%No
Microsoft Visual DebugerXmdm.exeDetected by Sophos as W32/Sdbot-DOO. Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %CommonFiles%\Microsoft Shared\VS7Debug (Windows 7/Vista/XP/ME/98) or %System% (WinME/98). This one is located in %System%No
NOD32Xmdm.exeDetected by Kaspersky as Trojan-Downloader.Win32.VB.rqo and by Malwarebytes Anti-Malware as Trojan.Agent.HDY. Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %CommonFiles%\Microsoft Shared\VS7Debug (Windows 7/Vista/XP/ME/98) or %System% (WinME/98). This one is located in %Root%\hyd\ToolsNo
SVCHOSTXMDM.EXEDetected by Sophos as W32/LCJump-A. Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %CommonFiles%\Microsoft Shared\VS7Debug (Windows 7/Vista/XP/ME/98) or %System% (WinME/98). This one is located in %Windir%No
Windows Networking MonitorXmdm.exeAdded by a variant of W32.IRCBot. Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %CommonFiles%\Microsoft Shared\VS7Debug (Windows 7/Vista/XP/ME/98) or %System% (WinME/98). This one is located in %System%No
Windows Networking MonitoringXmdm.exeDetected by Trend Micro as WORM_IRCBOT.AKZ. Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %CommonFiles%\Microsoft Shared\VS7Debug (Windows 7/Vista/XP/ME/98) or %System% (WinME/98). This one is located in %System%No
MdmXMdm.vbsAdded by the WHITEHO VIRUS or TRAPPY WORM!No
Microsoft Debug Manager ConsoleXmdm32.exeAdded by the AGOBOT-AQ WORM!No
melg34Xmdmd.exeAdded by the IRCBOT.AAK WORM!No
melg3445Xmdmdd.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
MdmdllXmdmdll.exeAdded by the GEMA TROJAN!No
Mdmdll32Xmdmdll32.exeAdded by the GEMA TROJAN!No
Modem Driverz UpdatesXmdmdrv.exeAdded by a variant of W32/Sdbot.worm. The file is located in %System%No
SvcManagerXmdmex2.exeAdded by the ZALON-B BACKDOOR!No
Machine Debug ManagerXmdms.exeAdded by the SDBOT-CH WORM!No
MicrosoftXmdms.exeDetected by Sophos as Troj/Agent-GHYNo
SysMemory managerXmdms.exeAdded by the CIMUZ-D TROJAN!No
ModemUtilityNmdmsetpe.exeSystem Tray configuration icon for Aztech modemsNo
ApplicationYmdmsetsp.exeAztech Labs modem driverNo
machine-debuggerXmdmsv.exeAdded by the AGOBOT-BR WORM!No
MDNXMDN.exeDetected by Trend Micro as WORM_RBOT.AOANo
Microsoft DNSxXmdnex.exeAdded by the DELBOT-AI WORM!No
MDNXMDNS.exeDetected by Symantec as W32.Spybot.JPBNo
MDNXMDNZ.exeDetected by Trend Micro as WORM_RBOT.AQDNo
NvCpl28DeamonXmdosft.exeAdded by the SPYBOT-AD WORM!No
mds.exeXmds.exeAdded by the MADS-A TROJAN!No
MicroUpdateXMDSC.EXEDetected by Dr.Web as Trojan.DownLoader7.2343 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %Root%No
2996400a95b9f7ee767bc0a5f1a67feaXmdsdll.exeDetected by McAfee as RDN/Generic PUP.x!qk and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJNo
svhost1Xmdsn.exeAdded by the VB-EPK TROJAN!No
Microsoft AgentXmdss32.exeAdded by the KEYLOG-AG TROJAN!No
mdwmdmspXmdwmdmsp.exeAdware - detected by Kaspersky as the AGENT.AM TROJAN!No
MS DVD DirectX Dll DriversXmdxdl.exeAdded by the SDBOT-XI WORM!No
meazurufifroXmeazurufifro.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
MECANMeca.exeMeca cross-platform communications technology, branded messengers will connect with AOL, MSN, Yahoo!, and ICQ usersNo
MedGSXMEDGS1.exePacerD Media/Pacimedia.com adwareNo
Media FinderXMedia Finder.exeDetected by McAfee as Generic.bfrNo
IoadqmXMedia Player.exeAdded by the HAWAWI WORM!No
Flash PluginXmedia-player.exeDetected by McAfee as PWS-Banker!hcq and by Malwarebytes Anti-Malware as Trojan.AgentNo
Media PlayerXmedia.exeAdded by the FLDMEDIA-A TROJAN!No
MediaXmedia.exe.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AllUsersProfile% - see hereNo
[various names]Xmedia64.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
Media AccessXMediaAccK.exeWindUpdates MediaPass adwareNo
MediaButtonsUMediaButtons.exeSupports the media buttons on hybrid all-in-one PCs such as the Dell "Studio Hybride" and Trigem "Averatec". For example, if disabled, the user will have to eject the CD/DVD by opening My Computer, right-clicking on the drive and selecting "Eject" from the available optionsNo
MicroMediaXMediaCenter.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserTemp\MicroMedia - see hereNo
mediacodec.exeXmediacodec.exeAdded by the VSCODEC PRO TROJAN!No
KBD MediaCenterUMEDIACTR.EXEMultimedia keyboard manager. Required if you use the multimedia keysNo
Corel Photo DownloaderNMediaDetect.exePart of Corel Photo Album 6 - detects when a camera or memory device is connected to your PC and gives you the option to acquire images from it automaticallyNo
BlazeServoTool?MediaDetector.exeRelated to BlazeDVD from BlazeVideo - which "is leading powerful and easy-to-use DVD player software." What does it do and is it required?No
Media GatewayXMediaGateway.exeWindUpdates MediaPass adwareNo
MediaKeyUMediaKey.exeMultimedia keyboard manager. Required if you use the multimedia keysNo
MediaLifeServiceUMediaLifeService.exeRelated to MediaPlay Cordless Mouse from LogitechNo
media_managerXmediaman.exeMini-Player, IMESH related foistwareNo
MediaMonitorNMediam~1.exeInstalled by Smartdisk MVP CD burning software. Software will work fine without itNo
Microsoft UpdateXmediap.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
Media PassXMediaPass.exeWindUpdates MediaPass adwareNo
Media PassXMediaPassK.exeWindUpdates MediaPass adwareNo
Windows Media PlayerXMediaPIayer.exeAdded by the SDBOT-QO TROJAN! Note - the lower case "l" in "MediapIayer" is a capital "i"No
mediaplayer.exeXmediaplayer.exeAdded by the BANKER-EUT TROJAN! The file is located in %Windir%\Sun\Java\Deployment\logsNo
mediaplayer.exeXmediaplayer.exeAdded by the BANKER.AOVZ TROJAN! The file is located in %Windir%\msagent\gfNo
Microsoft Windows Media PlayerXmediaplayer.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
Start UppingXmediaplayer32.exeDetected by Trend Micro as WORM_RBOT.AAJNo
MediaPlayeSXMediaPlayer_update.exeAdded by the STARTER-K TROJAN!No
mediapluscash.exeXmediapluscash.exeMediaGateway adwareNo
MediaSync?MediaSync.exeFound on Acer laptops, the process name for this entry is "Media Synchronizer" and it's part of Acer eConsole. What does it do and is it required?No
(Default)Xmedia_driver.exeAdded by the TUPEG VIRUS! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
MedicCopMainXMedicCop.exeMedicCop rogue security software - not recommended, removal instructions hereNo
MedichiXmedichi.exeAdded by the VIRANTIX.B TROJAN!No
Medichi2Xmedichi2.exeAdded by the VIRANTIX.B TROJAN!No
loads.exeXmedload.exeMedload adwareNo
Microsoft Media ManagerXmedman.exeAdded by the RBOT.EUZ WORM!No
MegakeyXMegakey.exeMegakey was an adware application which removed premium limitations on Mega services during "happy hour" periods. In return, the users running Megakey agreed to supply some personal identification and demographic data and to allow the substitution of ads on third party websites they visit with those of Megaupload' - see hereNo
MegakeyUpdaterXMegakeyUpdater.exeMegakey was an adware application which removed premium limitations on Mega services during "happy hour" periods. In return, the users running Megakey agreed to supply some personal identification and demographic data and to allow the substitution of ads on third party websites they visit with those of Megaupload' - see hereNo
5-megawatiXmegawati.exeAdded by the BRONTOK-CR WORM!No
vdsadaswXmeka.exeAdded by the MULTIDR-CW TROJAN!No
WIND0WSXmella.batAdded by the ALLEM WORM!No
mem32Xmem32.exeAdded by the AGENT-FWF WORM!No
pstUmemaker2.exeSpymodePCSpy surveillance software. Uninstall this software unless you put it there yourselfNo
5-1-61-96Xmembers-area.exeAdult content diallerNo
DellMCMUMemCard.exeMemory Card Manager - for removable memory cards found on Dell photo printersNo
MemoryCardManagerUMemCard.exeMemory Card Manager - for removable memory cards found on Dell or Lexmark photo printersNo
Fix-it AVYmemcheck.exePart of the anti-virus component of Fix-it Utilities by Avanquest (was by Ontrack and then VCOM). Performs a quick check of memory for signs of any virus. Exits afterward and returns all resources used in one user's experience. Not required but could be left without a drain on resourcesNo
MemCleanerUMemCleaner.exeSmartRAM - the memory management part of the older Advanced WindowsCare V2 optimization utility from IObit - which "monitors you system in the background and frees up memory whenever needed to increase the performance of your computer." Note - in November 2009 IObit were accused of stealing database information from Malwarebytes Anti-Malware and others so review the links on the Wikipedia page and make your own mind upYes
SmartRAMUMemCleaner.exeSmartRAM - the memory management part of the older Advanced WindowsCare V2 optimization utility from IObit - which "monitors you system in the background and frees up memory whenever needed to increase the performance of your computer." Note - in November 2009 IObit were accused of stealing database information from Malwarebytes Anti-Malware and others so review the links on the Wikipedia page and make your own mind upYes
Glary Memory OptimizerUmemdefrag.exeMemory Optimizer feature of Glary Utilities - a "free, powerful and all-in-one utility"No
Microsoft Memory Dumping ProtocolXmemdump.exeAdded by the IRCBOT.BJK BACKDOOR!No
MementoNMemento.exeMemento - simple app to keep text notes on your desktopNo
Memeo AutoBackup LauncherUMemeoLauncher.exeAutomatic backup feature of Memeo backup softwareNo
Memeo LauncherUMemeoLauncher.exeOlder version of Memeo backup software when they were known as TanagraNo
Memeo SendUMemeoLauncher.exeMemeo Send - "the simple way to send large files"No
Seagate DashboardUMemeoLauncher.exeSeagate Dashboard from Seagate Technology LLC (by Memeo) - backup software for their range of external storage drivesNo
Memeo AutoSyncUMemeoLauncher2.exeMemeo AutoSync gives you "the flexibility and simplicity you need to ensure your files are up to date on all of your computers"No
Memeo Instant BackupUMemeoLauncher2.exeMemeo Instant Backup - one-click, set it and forget it backup utility for external hard drives, USB flash drives and Network Attached Storage (NAS)No
WD Anywhere BackupUMemeoLauncher2.exeWD Anywhere Backup from Western Digital (by Memeo) - backup software for their range of external storage drivesNo
WD Anywhere Backup PremiumUMemeoLauncher2.exeWD Anywhere Backup Premium from Western Digital (by Memeo) - backup software for their range of external storage drivesNo
WINDOWS SYSTEM MEMORY LOADERXmemloader.exeAdded by the MYTOB-IN WORM!No
MemMonsterUmemmnstr.exeMagellass MemMonster - memory optimizerNo
MEMonitorUMEMonitor.exeV CAST Music Manager from Verizon WirelessNo
TuneUp MemOptimizerUmemoptimizer.exePart of "TuneUp Utilities", specifically 2003 version. "Monitors and optimizes free memory in the background." Basically, it cleans RAM and also allows you to clear the clipboardNo
Memory CheckXmemore.exeAdded by the KILLAV.C TROJAN!No
T2WXMemoria.exeAdded by the DROPPER.CYG TROJAN!No
MemoryBoostUMemoryBoost.exeMemoryBoost - memory optimizing program made by Tenebril IncNo
Memory ManagerXmemorymanager.pifAdded by the DELF-JJ TROJAN!No
MemoryMeterXMemoryMeter.exeMemoryMeter - bundled with TVMedia adwareNo
Windows Memory SharingXmemoryshr.exeDetected by Microsoft as Worm:Win32/Slenfbot.FX and by Malwarebytes Anti-Malware as Backdoor.Bot.GenNo
Windows Storm-Memory DriversXmemorystorm.exeAdded by the SLENFBOT.CO WORM!No
Memory WatcherXMemoryWatcher.exeMemoryWatcher spywareNo
BsRteXMemoteXZZ.exeAdded by the AUTORUN-AJU WORM!No
MemoThis AgentUmemothis.exeDetected by Malwarebytes Anti-Malware as PUP.MemoThis.K. Unless you installed this yourself uninstall it - the file is located in %AppData%\MemoThisNo
memreader.exeXmemreader.exeAdded by the AGOBOT-TY WORM!No
MEMrealoadXMEMreaload.exeAdded by the LAZAR TROJAN!No
Windows Memory DriversXmemretain.exeDetected by Microsoft as Worm:Win32/Slenfbot.CN and by Malwarebytes Anti-Malware as Backdoor.Bot.GenNo
Windows Memory Running ServicesXmemrun.exeDetected by Kaspersky as Backdoor.Win32.IRCBot.bmd and by Malwarebytes Anti-Malware as Backdoor.Bot.GenNo
MemScannerNMemScanner.exePart of Enigma SpyHunter - not recommended, see hereNo
Windows Memory SharingXmemshare.exeDetected by Trend Micro as TROJ_IRCBRUTE.AG and by Malwarebytes Anti-Malware as Backdoor.Bot.GenNo
Windows Memory SharingXmemshr.exeDetected by Trend Micro as BKDR_IRCBOT.MC and by Malwarebytes Anti-Malware as Backdoor.Bot.GenNo
Microsoft Update MachineXmemstat.exeAdded by the RBOT-OM WORM!No
Systweak Memory OptimizerUmemtuneup.exePart of SysTweak Advanced System OptimizerNo
MemTurboUmemturbo.exeMemTurbo memory optimizerNo
MemoryZipperPlusUmemzip.exeMemory Zipper Plus - "optimizes the memory management of your system and boost-up its performance amazingly!"No
MenuSnapNMenuSnap.exeMenuSnap from Rietta Solutions. Utility that re-orders your Start Menu items alphabetically. You may not want this utility if you're able to do this manually by selecting Start → Programs and right-clicking and choosing "Sort by Name" if availabeNo
BiomenuUmenusw.exeRelated to Sony VAIO - passwords, encryption, and a biometric fingerprint sensorNo
MercoraNMercoraClient.exeMercora MusicSearch "Search, find and listen to music on the world's largest jukebox, built by people just like you". Note - if you subscribe make sure you read the Privacy PolicyNo
msn upddateXmesenger.exeAdded by the RBOT-AVZ WORM!No
WindowsSecurityXMESP.exeMicorsoft Essential Security Pro 2013 rogue security software - not recommended, removal instructions hereNo
Message_BlockerUmessageblock.exeMessage Blocker - "prevents Outlook Express from loading images or other content from the internet without confirmation, as well as executing scripts when displaying a formatted email message"No
MsnWinXmessagewin.exeAdded by the BANCBAN-D TROJAN!No
SpareMessagingUMessagingApp.exeMessaging and reports application for Spare BackupNo
ATI Video Driver ControlXMessen.exeDetected by Microsoft as Backdoor:Win32/Rbot.gen. The file is located in %System%No
ef0bf05487f5b860a3536291dfde1789XMessenger.exeDetected by Dr.Web as Trojan.DownLoader8.24503 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJNo
MessengerXmessenger.exeAdded by the KUTEX TROJAN!No
MmessengerXmessenger.exeDetected by Trend Micro as WORM_AGOBOT.GMNo
svshostXmessenger.exeAdded by the LOONY-G TROJAN!No
systemXmessenger.exeAdded by an unidentified WORM or TROJAN!No
System driverXMessenger.exeAdded by the WOOTBOT.GI WORM!No
WindowsMessengerXmessenger.exeDetected by Dr.Web as Trojan.DownLoader6.22244 and by Malwarebytes Anti-Malware as Trojan.VBAgentNo
Yahoo UpdaterXMessenger.exeAdded by the FORBOT-FE WORM!No
Microsoft SecureXMessenger.NET ServiceAdded by the FORBOT-AM WORM!No
MessengerDiscoveryUMessengerDiscovery.exeMessengerDiscovery is a MSN Messenger add-on - adding over 70 new features. Now superseded by MessengerDiscovery Live - with support added for Windows LiveNo
MSN Messenger Live WindowsXmessengerlive.exeAdded by an unidentified WORM or TROJAN! See hereNo
MSN MESSENGER 9.0Xmessengerr.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
Windows messengerXmessengers.exeAdded by the MYTOB.EI WORM!No
messengerskinnerXMessengerSkinner.exeMessenger Skinner malware - uses a rootkit to hide executable filesNo
SystemBXMessengerStopper.exeMessStopper adwareNo
Messenger91Xmessengersystem.exeAdded by the RBOT-FPF WORM!No
MessenqerXMessenqer.exeAdded by the MDROP-CL MALWARE! Note the lower case "Q" in the name and commandNo
MetacafeNMetacafeAgent.exeMetacafe - video sharing on the web. Note - if you subscribe make sure you read the Privacy PolicyNo
MeTaLRoCk (irc.musirc.com) has sex with printersXmetalrock-is-gay.exeDetected by Trend Micro as WORM_RANDEX.QNo
Windows MeTaLRoCk serviceXmetalrock.exeAdded by the TASTYRED TROJAN!No
runXmexica.exeAdded by the AUTORUN.AEV WORM!No
ASDPLUGINXmexico.exeAsdPlug premium rate adult content dialerNo
MS ExplorerXmexplore.exeAdded by the YAHA.AE WORM!No
Media FinderXMF.exeDetected by Symantec as Adware.MediafinderNo
mf.exeXmf.exeDetected by Malwarebytes Anti-Malware as Spyware.Banker. The file is located in %Root%\winaNo
mf.exeXmf.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %Root%\WindowsgNo
mf.exeXmf.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %Root%\windowshNo
Mfc**.exe [* = random char]XMfc**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this logNo
Mfc**32.exe [* = random char]XMfc**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this logNo
Microsoft® Windows® Operating SystemXMFC110D.exeDetected by Sophos as Troj/Agent-XCK and by Malwarebytes Anti-Malware as Trojan.FakeMS. The file is located in %Templates%No
slack12Xmfcee.exeAdded by a variant of W32/Sdbot.wormNo
staeck12Xmfcee.exeAdded by a variant of the MAILBOT TROJAN!No
staeck122Xmfceee.exeAdded by a variant of the MAILBOT TROJAN!No
mfchlp64Xmfchlp64.exeAdded by the ONLINEGAMES.AJSP TROJAN!No
TsilXMFCO42DK.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.QRJ. The file is located in %System% - see hereNo
PowerProfileXmfcp30.exeAdded by the RINDAS-A TROJAN!No
mfeBTPXmfeBTP.exeDetected by McAfee as W32/Autorun.worm.ho and by Malwarebytes Anti-Malware as Worm.AutoRunNo
HKCUXmfilesdbgr.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %System%\MicrosoftNo
PoliciesXmfilesdbgr.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %System%\MicrosoftNo
mfin32Xmfin32.exeMyFreeInternetUpdate - adware downloaderNo
Corel MEDIA FOLDERS INDEXER 8NMFindexer.exePart of CorelDraw bundles for indexing media files - similar to "fast find" in MS OfficeNo
Corel MEDIA FOLDERS INDEXER 8NMFINDE~1.EXEPart of CorelDraw bundles for indexing media files - similar to "fast find" in MS OfficeNo
SPAM FIREWALLXmfirewall.exeAdded by the SDBOT.AOU WORM!No
MightyFAX ControllerNMFNTCTL.EXEMighty FAX from RKS Software - "installs a printer driver so that you can fax directly from Windows software"No
ICFYmfp.exeMcAfee Family Protection - which 'is easy-to-use and built to empower parents to say "yes" to their children's online interests while protecting them as they learn and explore' and "protects children of all ages from exposure to inappropriate content, social networking risks, strangers, and other threats"Yes
McAfee Family ProtectionYmfp.exeMcAfee Family Protection - which 'is easy-to-use and built to empower parents to say "yes" to their children's online interests while protecting them as they learn and explore' and "protects children of all ages from exposure to inappropriate content, social networking risks, strangers, and other threats"Yes
mfpYmfp.exeMcAfee Family Protection - which 'is easy-to-use and built to empower parents to say "yes" to their children's online interests while protecting them as they learn and explore' and "protects children of all ages from exposure to inappropriate content, social networking risks, strangers, and other threats"Yes
xho9yXmfp3lr9.exeDetected by Kaspersky as Backdoor.Win32.VB.mst. The file is located in %Temp%No
MFP Server AgentUMFPAgent.exeMulti Function Printer (MFP) server agent for products such as Belkin's Wireless G All-in-One Print Server and ZyXEL's NPS-520 which allow multiple computers to use networked all-in-one printersYes
MFPAgentUMFPAgent.exeMulti Function Printer (MFP) server agent for products such as Belkin's Wireless G All-in-One Print Server and ZyXEL's NPS-520 which allow multiple computers to use networked all-in-one printersYes
Panasonic Communications UtilityUMfpscdl.exePort manager for Panasonic Panafax fax_machinesNo
Microsoft IncroporateXmfs.exeAdded by the RBOT-ANF WORM!No
Microsoft ManagerXmfxz.exeAdded by the RANDEX.ZK WORM!No
MediaFire TrayNmf_systray.exeSystem Tray access to MediaFire Express - which "lets you place your files into the cloud with a single click. Now you can easily share, backup, store, and collaborate, all directly from your desktop"No
MgabgUMgabg.exeMatrox BIOS Guard - monitors a Matrox card's BIOS, and will reflash it when needed. Cards like the G400 have a nasty habit of losing their BIOS, especially on poor power supplies. If you make an emergency BIOS disk with the utility in their BIOS package, you can disable Mgabg.exe and just use the crash disk if/when neededNo
Matrox Control CenterNmgactrl.exeFor Matrox video cards. Quick access to settingsNo
Matrox DiagnosticNmgadiag.exeFor Matrox video cards. Quick access to diagnosticsNo
MGA Hook?Mgahook.exeMATROX Graphics card related. What does it do and is it required?No
Matrox QuickDeskNmgaqdesk.exeFor Matrox video cards. Quick access to tweak your card to your likingNo
MGA QuickdeskNMGAQDESK.EXEFor Matrox video cards. Quick access to tweak your card to your likingNo
MGA_CD_InstallNmgasetup.exeMatrox Millennium video driver. Not required once drivers installedNo
mgavctrlYmgavrtcl.exePart of older versions of McAfee's internet security products such as VirusScan and VirusScan OnlineNo
mgavrtclexeYmgavrtcl.exePart of older versions of McAfee's internet security products such as VirusScan and VirusScan OnlineNo
mgavrtclexeYmgavrte.exePart of older versions of McAfee's internet security products such as VirusScan and VirusScan OnlineNo
king_mgXmgking.exeDetected by Sophos as Mal/EncPk-ADE and by Malwarebytes Anti-Malware as Worm.Magania. The file is located in %System%No
king_mgXmgking.exeDetected by Sophos as Troj/Agent-PGG. The file is located in %UserTemp%No
mgmtapiXmgmtapi.exeUnidentified malwareNo
RandomWin32Xmgnwin32.exeAdded by the SDBOT-DV WORM!No
AudioMenagerXmgr.exeDetected by Dr.Web as Trojan.Siggen4.1580 and by Malwarebytes Anti-Malware as Spyware.PasswordNo
qQXMgr.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Windir%No
NvCplDXmgr32.exeEnterOne - Switch dialer and hijacker variant, see hereNo
smgrXmgrs.exeCovert Sys Exec malware variantNo
MGSysCtrlUMGSysCtrl.exePart of the System Control Manager for MSI notebooks - displays animations for hot key commands (such as turning the wireless card on/off)No
Ms Java for Windows NTXmguard.exeAdded by the SDBOT.BSR WORM!No
BullGuardYmgui.exePart of Bullguard antivirusNo
MgxkxkAXMgxkxkA.exeDetected by Malwarebytes Anti-Malware as VirTool.DelfInject. The file is located in %Root%\ProgramData\UuwpypM\RrmowyDNo
MHDOGStartXmhdogst.EXEAdded by an unidentified VIRUS, WORM or TROJAN! A possibility is a trojan known as PENISNo
System GuardXmhguard.exeAdded by the RBOT-AGU WORM!No
MHINITNMHINIT.EXEPart of the Cybermedia Clean Sweep packageNo
CHotKeyUmhotkey.exeEnables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol+, vol-, mute, etc. Only required for extended featuresNo
Microsoft Greetings RemindersNMHPRMIND.EXEMicrosoft Home Publishing greetings reminderNo
Microsoft Greetings ReminderNMHPRMINF.EXEYou really want to be reminded about somebody's birthday at the expense of resources?No
mhs3Xmhs3.exeAdded by the PWS-ALZ TROJAN!No
fmknjjstXmhvrvowe.exeDetected by Malwarebytes Anti-Malware as Trojan.Inject. The file is located in %LocalAppData%No
Microsoft CorporationXMic2011.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System%\System32No
micaamXmicaam.exeDetected by Malwarebytes Anti-Malware as Trojan.Inject.RC. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
Microsoft UpdateXMicr0s0ft.exeDetected by Trend Micro as WORM_AGOBOT.AARNo
MicroXMicro.exeDetected by McAfee as RDN/Generic.bfr!be and by Malwarebytes Anti-Malware as MSIL.LockScreenNo
ANTIVIRUSXmicroAV.exeMicro Antivirus 2009 rogue security software - not recommended, removal instructions hereNo
MicroBrewUMicroBrew2.exeRelated to Bluebeam PDF printer support. Prints AutoCAD .dwgs to PDF'sNo
microconXmicrocon.exeDetected by Dr.Web as Trojan.DownLoader7.13831 and by Malwarebytes Anti-Malware as Trojan.VBAgent. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
Microsoft ServiceXmicrohost.exeAdded by the RBOT-LC WORM!No
MicrostableXMicrointake.exeDetected by McAfee as RDN/Generic.bfr!m and by Malwarebytes Anti-Malware as Trojan.AgentNo
MicroConvertXMicroLabCon.exeDetected by Malwarebytes Anti-Malware as Adware.MicroNames. The file can be found in various locationsNo
MicroLabConXMicroLabCon.exeDetected by Malwarebytes Anti-Malware as Adware.MicroNames. The file can be found in various locationsNo
MicroLabConXMicroLabProc.exeDetected by Malwarebytes Anti-Malware as Adware.MicroNames. The file can be found in various locationsNo
SystemBackupXMicroLog.exeAdded by the MICROLOG.A TROJAN!No
HKCUXmicronet.exeDetected by Malwarebytes Anti-Malware as Trojan.Svchsot. The file is located in %System%\MicrosoftNo
HKLMXmicronet.exeDetected by Malwarebytes Anti-Malware as Trojan.Svchsot. The file is located in %System%\MicrosoftNo
PoliciesXmicronet.exeDetected by Malwarebytes Anti-Malware as Trojan.Svchsot. The file is located in %System%\MicrosoftNo
Required Service DriversXmicront.exeDetected by Sophos as W32/Rbot-ABDNo
MicroPCXMicroPCLaunch.exeMicroPC rogue security software - not recommended, removal instructions hereNo
JavaXMicrophonehelper.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%No
Windows Logon ServiceXmicropoft.exeAdded by the RBOT-FZY WORM!No
MicroLabConXMicroProCon.exeDetected by Malwarebytes Anti-Malware as Adware.MicroNames. The file can be found in various locationsNo
MicroLabProcXMicroProProc.exeDetected by Malwarebytes Anti-Malware as Adware.MicroNames. The file can be found in various locationsNo
MicroProProcXMicroProProc.exeDetected by Malwarebytes Anti-Malware as Adware.K.MicronamesNo
HKCUXmicrosfit.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\microsoftNo
HKLMXmicrosfit.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\microsoftNo
PoliciesXmicrosfit.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\microsoftNo
svchostXMicrosoft (R) Corporation.exeDetected by Malwarebytes Anti-Malware as Backdor.Bot. The file is located in %UserTemp%No
Microsoft.NETXMicrosoft NET.exeDetected by Dr.Web as BackDoor.Blackshades.2No
systemXMicrosoft Office.exeAdded by the BANCBAN-LH TROJAN!No
Microsoft OfficeXMicrosoft Office.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!No
Microsoft SecurityXMicrosoft Security.exeDetected by Malwarebytes Anti-Malware as Worm.Ainslot. The file is located in %AppData%\Microsoft SecurityNo
cdc10baf8d526aadd954bf3f60e0e69eXMicrosoft Support.exeDetected by McAfee as RDN/Generic.grp!cw and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJNo
Microsoft Windows ExpressXMicrosoft UpdateAdded by a variant of the IRCBOT BACKDOOR! See hereNo
11949c545f0c7cc562aa88fdb77ed1adXMicrosoft update.exeDetected by McAfee as Trojan-FAUE!309E7A8C683B and by Malwarebytes Anti-Malware as Trojan.MSILNo
Microsoft WindowsXMicrosoft Windows.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!No
MSCRMStartup?Microsoft.Crm.Application.Hoster.exeRelated to Microsoft Dynamics CRM integrated solutions for Financial, Supply Chain and Customer Relationship Management. What does it do and is it required?No
13cf9d8bf1b79e8de8ac0fe37a6739feXMicrosoft.exeDetected by Dr.Web as Trojan.DownLoader7.18693 and by Malwarebytes Anti-Malware as Trojan.MSILNo
53b6f6cbe7c28bb1a6deaf6cf4f17fd8Xmicrosoft.exeDetected by Dr.Web as Trojan.DownLoader8.34078 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJNo
applicationXmicrosoft.exeAdded by the KASIMOD.A WORM!No
blah serviceXmicrosoft.exeAdded by a variant of Win32/RbotNo
Configuration LoaderXmicrosoft.exeAdded by the GAOBOT.JB WORM!No
Dcom System PatchXMicrosoft.exeAdded by the RANDEX.MS WORM!No
DriverXMicrosoft.exeDetected by Dr.Web as Trojan.DownLoader8.18954 and by Malwarebytes Anti-Malware as Backdoor.AgentNo
Graphics Media Accelerator PlusXMicrosoft.exeDetected by Dr.Web as Trojan.Siggen5.5550 and by Malwarebytes Anti-Malware as Backdoor.AgentNo
hptoolsXmicrosoft.exeAdded by a variant of W32/Sdbot.wormNo
Internet_ExplorerXmicrosoft.exeAdded by the BANKER-EUQ TROJAN!No
MicrosoftXMicrosoft.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %ProgramFiles%\Microsoft SystemNo
MicrosoftXMicrosoft.exeDetected by Malwarebytes Anti-Malware as Backdoor.DarkKomet. The file is located in %AppData%No
MicrosoftXMicrosoft.EXEDetected by Malwarebytes Anti-Malware as Trojan.DarkMoon. The file is located in %System%No
Microsoft ExecutingXmicrosoft.exeAdded by the AGOBOT.UV WORM!No
Microsoft Information CheckXmicrosoft.exeAdded by the SLENFBOT.JU WORM!No
Microsoft OfficeXmicrosoft.exeAdded by the BANKER-VF TROJAN!No
Microsoft Synchronization ManagerXmicrosoft.exeAdded by the SDBOT-OM WORM!No
Microsoft UpdateXMicrosoft.exeAdded by the GAOBOT.AFJ WORM!No
microsoft.exeXmicrosoft.exeDetected by Sophos as Troj/Goldun-GBNo
Win32KernelStartXmicrosoft.exeAdded by the DELF-EWZ TROJAN!No
windows updateXMicrosoft.exeDetected by Trend Micro as TROJ_LMIR.A and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
microsoftXmicrosoft.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!No
[5 or 6 numbers]XMicrosoft.vbsDetected by Malwarebytes Anti-Malware as Trojan.Agent.Gen. The file is located in %Temp%\[6 numbers] - see examples here and hereNo
WindowsUpdateXMicrosoft.vbsDetected by Dr.Web as Trojan.DownLoader7.27354 and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%\dataNo
WindowsUpdateXMicrosoft.vbsDetected by McAfee as RDN/Generic BackDoor and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Temp%\dataNo
Microsoft Dll ManagerXmicrosoft32dll.exeDetected by Trend Micro as TROJ_SHEUR.LH. The file is located in %System%No
microsoft420Xmicrosoft420.exeDetected by Trend Micro as WORM_MENACE.BNo
ctfmoonXmicrosoftconfigurator.exeAdded by the DELF-ALS TROJAN!No
MicrosoftXMicrosoftCorporation.exeAdded by the KILLFILES.AED TROJAN!No
MSLogXMicrosoftLog.exeAdded by a variant of W32/Sdbot.wormNo
Microsoftmsn32.exeXmicrosoftmsn32.exeAdded by the CERTIF-C TROJAN!No
MicrosoftProtectionXMicrosoftProtection.exeDetected by McAfee as Downloader.a!d2i and by Malwarebytes Anti-Malware as Trojan.Agent. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
Ms ConfigurationXmicrosoftsa32.exeAdded by the KELVIR.X WORM!No
Microsoft ScanregXmicrosoftscanreg.exeDetected by Trend Micro as WORM_FRANRIV.ANo
Win32 Debug ManagerXmicrosoftupd.exeAdded by the RBOT-GRJ WORM!No
MicrosoftUpdate##XMicrosoftUpdate##.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent - where # represents a number. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts - see examples hereNo
MicrosoftUpdate##XMicrosoftUpdate##.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent - where # represents a number. The file is located in %System% - see examples hereNo
Microsoft UpdaterXMicrosoftUpdate.exeDetected by Dr.Web as Trojan.DownLoader6.22010 and by Malwarebytes Anti-Malware as Backdoor.BotNo
MicrosoftUpdateXMicrosoftUpdate.exeDetected by Dr.Web as Trojan.Inject.59911 and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%\MicrosoftNo
MicrosoftUpdateXMicrosoftUpdate.exeDetected by Dr.Web as Trojan.DownLoader6.22010 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
MicrosoftUpdateXMicrosoftUpdate.exeDetected by Sophos as Troj/Banker-EHC and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System%No
MicrosoftUpdaterXmicrosoftupdate.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %UserTemp%No
SAFETYUPDATEXMicrosoftUpdate.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AllUsersProfile%\FavoritesNo
MicrosoftUpdateXMicrosoftupdt32.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %LocalAppData%\Microsoft%\MicrosoftUpdateNo
Microsoft UpdateXMicrosoftx.exeAdded by a variant of Win32/RbotNo
Microsoft Configuration 35Xmicrosot1.exeAdded by an unidentified TROJAN!No
Microsoft Configuration 77Xmicrosot32.exeDetected by Trend Micro as WORM_RBOT.ENUNo
MicroUpdateXMicroUpdate.exeDetected by Dr.Web as Trojan.DownLoader7.14395 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %System%\MSDCSCNo
MicroUpdateXMicroUpdate.exeDetected by McAfee as Generic BackDoor!dx3 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData%\MicroUpdateNo
MicroUpdateXMicroUpdate.exeDetected by McAfee as Generic.bfr!dm and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData%\winupdatNo
MicroUpdateXMicroUpdate.exeDetected by Trend Micro as WORM_MYTOB.PX and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %System%No
MicruUpdateXMicroUpdate.exeDetected by Dr.Web as Trojan.DownLoader5.55530 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AllUsersProfile%\Start Menu\MSDCSCNo
microvaccineXmicrovaccineUpdater.exeMicroVaccine rogue security software - not recommended, removal instructions hereNo
microWebAD.exeXmicroWebAD.exeMicroWebAD adwareNo
HKCUXmicrrosoft.exeDetected by Malwarebytes Anti-Malware as Trojan.Dropper. The file is located in %System%No
HKLMXmicrrosoft.exeDetected by Malwarebytes Anti-Malware as Trojan.Dropper. The file is located in %System%No
PoliciesXmicrrosoft.exeDetected by Malwarebytes Anti-Malware as Trojan.Dropper. The file is located in %System%No
MicroUpdXMicUpd.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AllUsersProfile%\Start Menu\Programs\MicroNo
SetDefaultMIDI?MIDIDef.exeRelated to a Soundblaster Audigy soundcards. What does it do and is it required?No
Firewall PolicyXMidiDef32.exeAdded by the PIEBOT-A TROJAN!No
sfwjbbjdXmidiwemshdw.exeAdded by the AGENT-OII TROJAN!No
EleFunAnimatedWallpaperUMidnight Fire.exeMidnight Fire animated wallpaper fromNo
WinsystemsXmiefotoieri.EXEAdded by the DELF-DVT WORM!No
mig2Xmig2.exeAdded by the BRONTOK-BW WORM!No
MigAutoPlayXMigAutoPlay.exeDetected by Sophos as Troj/Ransom-QA and by Malwarebytes Anti-Malware as Trojan.RansomNo
MightymagooXmightymagoo32.exeMighty Magoo adwareNo
MigRegDCXMigRegDC.exeDetected by McAfee as RDN/Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
jotl?millenzje.exe??No
Miller.exeXMiller.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. Note that the Command field can be either blank or the same as the Name field and located in a sub-folder of %LocalAppData% - see here and hereNo
MimBootNmimboot.exeStarts the MusicMatch Jukebox digital music player/CD burner and ripper/music organizer/playlist creator at bootup. Both MusicMatch Jukebox and it's successor (Yahoo! Music Jukebox) are no longer available after being bought by RhapsodyNo
MouseImpUMImpHost.exeMouseImp Pro - "A reliable assistant that turns your mouse into a simple, native but powerful controlling device"No
HKCUXmin.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System%\bifrostNo
HKLMXmin.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System%\bifrostNo
MincerXMincer.exeAdded by the MINCEME-A VIRUS!No
MindfulUMindful.exeMindful from Felitec inc. "Event reminder software with date and time tools in a simple to use system tray application"No
HKCUXMine.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.HMCPol.GenNo
HKLMXMine.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.HMCPol.GenNo
mineXmine.exeDetected by McAfee as Generic BackDoor!fqc and by Malwarebytes Anti-Malware as Trojan.AgentNo
Mine.exeXMine.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%\Mincraft - see hereNo
MicroUpdateXminecraft.exeDetected by Dr.Web as Trojan.DownLoader7.27126 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData%\.minecraftNo
Microsoft Ming ServiceXming.exeAdded by the RBOT-AWS WORM!No
Mini-XPUMini-XP.exeMinimizer-XP from Totalidea Software - adds an additional button in the top right-corner of any application window to allow you to quickly minimize it to the System Tray. No longer available from the author but still available from download sites such as Download.comYes
MINIBUGXMINIBUG.EXEDisplays ads inside Weatherbug - see hereNo
Tray TemperatureXMINIBUG.EXEDisplays ads inside Weatherbug - see hereNo
MINIFERT.EXENMINIFERT.EXEPart of BackwebNo
minilogUMINILOG.EXEPart of older versions of the ZoneAlarm Free and Pro firewalls when running on Windows Me/98. If you don't have the firewall running you don't need this but it must be enabled if programs such as VisualZone Report utility or ZoneLog Analyzer are in use. Runs as a service on XP/2KNo
MiniMavisNMiniMavis.exeMavis Beacon typing tutorNo
MiniNoteNMININOTE.EXEMini NoteTab was the first in the family of "NoteTab" text and HTML editors from Fookes SoftwareNo
MiniPortRtXminiport_mp.exeMalware - see hereNo
MiniReminderUMiniReminder.exe"MiniReminder is a small, fast, and simple program for Microsoft Windows to remind yourself of important yearly events, like birthdays, anniversaries, renewals, etc"No
MiniServer.exeXMiniServer.exeAdded by the LITTLEW-E TROJAN!No
inixsXminix32.exeAdded by the AGENT.CKQX TROJAN!No
minix32Xminix32.exeAdded by the AGENT.CKQX TROJAN!No
CleanMem Mini MonitorUmini_monitor.exeCleanMem memory managerNo
MioSyncUmioSync.exeRelated to Mio GPS navigation devicesNo
MirageDriveXMirageDrives.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\InstallDirNo
Miranda IMNmiranda32.exeMiranda instant messaging clientNo
ToolbarInstallXMirarSetup.exeMirar adwareNo
Mirate Sp 2 InformationXmiratesp2.exeAdded by the RBOT.QH WORM!No
ctfmonXmIRC.dllAdded by the DELBOT-E TROJAN!No
feelalrightXmirc.exeAdded by the IRCFLOOD-M WORM!No
firefoxXmirc.exeDetected by Dr.Web as Trojan.KillProc.15751 and by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %Temp%\greetNo
firefoxXmirc.exeDetected by McAfee as W32/Sdbot.worm!na and by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %Temp%\mamaNo
mirc.exeXmirc.exeAdded by the SILLYFDC-AY WORM!No
StartupXmirc.exeAdded by the FLOOD-EU TROJAN! An uninstall option for mirc.exe can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as mIRC. This one puts 10 files in %Windir%No
taskmgr.exeXmirc.exeAdded by a variant of the AGENT.AH TROJAN!No
UpdateShieldXmIRC.exeDetected by Kaspersky as Worm.Win32.AutoRun.blieNo
WinXPServiceXmirc.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
Winsock2 driverXMIRC32.exeAdded by the SPYBUZZ TROJAN!No
Microsoft Synchronization ManagerXmircup.exeDetected by Trend Micro as WORM_SDBOT.BQDNo
Microsoft UpdattingXmiroupdate.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
MirraUMirra.Client.exeMirra Personal Server from Seagate Tech - "a powerful hardware/software solution that integrates high-capacity storage with content protection, remote access, sharing and multi-computer synchronization"No
misiCTRL?misiCTRL.exeMiro video driver related. Is it required?No
miroVIDEO Tray ToolNmisitray.exeTool for quickly changing options for miro/Pinnacle capture cards during capture/playback/output. When this program is closed, another program (mv-ctrl) is also closed, but mv-ctrl does not have its own EXE file. Only needed when using the capture card, e.g. for the above actionsNo
misiTRAY?misiTRAY.exeMiro video driver related. Is it required?No
VirusXMixa.exeAdded by the AUTORUN-DH WORM!No
C-Media MixerNMixer.exeC-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start → Settings → Control Panel or Start → ProgramsNo
Microsoft UpdateXmixer.exeAdded by the RBOT-AIR WORM!No
MixerNMixer.exeC-Media Mixer - C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start → Settings → Control Panel or Start → ProgramsNo
MicrosoftXmixers.exeAdded by the AGOBOT-AHU WORM!No
MixerselNmixersel.exeConfiguration for Realtek audio devicesNo
MixghostNmixghost.exeManagement software for Altec Lansing speakers. If a change is needed, the user can launch it from the Start menuNo
FxoekmXmiyhart.exeAdded by the SDBOT-CZQ WORM!No
xdwySXMizBD.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%No
mjcXmjc.exeAdded by the AGENT.AKCI TROJAN!No
MemoKitUMK.EXEPart of the MemoKit memory optimizer by Software Benefits Inc. Loads the main program (memokit.exe) at startup and exitsNo
CHotKeyUMK9805.EXEEnables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol+, vol-, mute, etc. Only required for extended featuresNo
mkb.exeUmkb.exeMomKnowsBest surveillance software. Uninstall this software unless you put it there yourselfNo
ml00!.exeXml00!.exeMalware. Detected by Panda as the DOWNLOADER.BWD TROJAN!No
ML1HelperStartUpUML1Helper.exeScreenScenes "Midnight Lake" screensaver. The free version contains GAIN adware by Claria Corporation. An ad-free version was available for a whopping $30!No
ML1HelperStartUpUML1HEL~1.EXEScreenScenes "Midnight Lake" screensaver. The free version contains GAIN adware by Claria Corporation. An ad-free version was available for a whopping $30!No
MSN Webcam RecorderNml20gui.exe"MSN Webcam Recorder is a tool that allows you to record video streamed to and from your computer by MSN Messenger's Webcam Feature"No
MlCROSOFT FEnRXMlCROSOFT.EXEAdded by the GAOBOT.CII WORM! Note that both the name and command have a lower case "L"No
MatadorUmlfbuddy.exeMailFrontier - anti-spam applicationNo
RegistryMonitor1Xmljul1.exeAdded by the SPAMBOT TROJAN!No
ml34Xmlm4.exeAdded by a variant of the MAILBOT-BH TROJAN!No
MicroUpdateXmlogcsc.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\MSDCSCNo
mlogcsc.exeXmlogcsc.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\MSDCSCNo
m66Xmlr66.exeAdded by the AGENT-ACR TROJAN!No
iRiver AutoDB?MLService.exePart of the iRiver AutoDB music management utility for some of their music players which appears to be based upon (or is a rebranded version of) MoodLogic - which has now been discontinued. some users claim it is worthless, prone to lock-ups, and slow as a turtle but what does it do and is it required?No
MoodLogic Service?MLService.exePart of the MoodLogic music management utility - which "automates the process of fixing and organizing digital music (MP3, WMA, and .wav) files in bulk. Once the tunes are organized, you can sort music by genre, artist, tempo, and mood (aggressive, mellow, upbeat, happy, romantic, sad), and create playlists accordingly". Now discontinued but what does it do and is it required?No
motoinXmm15201518.Stub.exeDelfin Promulgate adware variantNo
Key Name skyyXmmacc.exeDetected by Dr.Web as Trojan.DownLoader6.52400 and by Malwarebytes Anti-Malware as Trojan.AgentNo
Microsoft Movie MakerXMmaker.exeDetected by Symantec as W32.IRCBot.C. Note that this is not a valid Microsoft programNo
Microsoft allXmmall.exeWopla.ac malware variantNo
Microsoft® Windows® Operating SystemXMmcAspExt.exeDetected by McAfee as RDN/Generic.bfr!ci and by Malwarebytes Anti-Malware as Backdoor.MessaNo
mmcndmgrXmmcndmgr.exeAdded by an unidentified VIRUS, WORM or TROJAN!No
ClreXmmdc.exeAdded by the PURSCAN-AI TROJAN!No
mmsassXmmdmm.exeAdded by the SDBOT.SO WORM!No
mmemdrvXmmemdrv.exeSecondSight surveillance software. Uninstall this software unless you put it there yourselfNo
DigidesignMMERefreshUMMERefresh.exePart of the Pro Tools audio creation/production software from Avid Technology, Inc (formerly by Digidesgin). Refreshes the midi ports on hardware audio/midi converters connected to your computer and must be running in order to use the MIDI functionalityNo
MMERefreshUMMERefresh.exePart of the Pro Tools audio creation/production software from Avid Technology, Inc (formerly by Digidesgin). Refreshes the midi ports on hardware audio/midi converters connected to your computer and must be running in order to use the MIDI functionalityNo
MinMaxExtenderUMmext.exeMinMaxExtender - window handling toolNo
OpenMstartXmmgr32.exeMStart2Page - Switch dialer and hijacker variant, see here. Also detected as the SWITCH-E TROJAN!No
MmgsvcXmmgsvc.exeMmgsvc spywareNo
MMHK?mmhk.exeA driver found on a Compaq Presario 800T notebook. Possibly something to do with multimedia hot keys?No
KM9801UUMMHotKey.exeMultimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screenNo
MMHotKeyNMMHotKey.exeMultimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screenNo
Microsoft hren1Xmmhren1.exeAdded by a variant of the AGENT.IWW TROJAN!No
ActivboardUMMKeybd.exePackard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock, Caps Lock, Scroll Lock keysNo
DellTouchUMMKeybd.exeDell multimedia keyboard manager. Required if you use the additional keysNo
FLMK08KBUMMKEYBD.EXEMultimedia keyboard manager. Required if you use the additional keysNo
Keyboard ManagerUMMKeybd.exeMultimedia keyboard manager. Required if you use the additional keysNo
MediaKeyUMMKeybd.EXEMultimedia keyboard manager. Required if you use the additional keysNo
MMKeybdUMMKeybd.exeMultimedia keyboard manager. Required if you use the additional keysNo
Multimedia KBDUMMKeybd.exeMultimedia keyboard manager. Required if you use the additional keysNo
MULTIMEDIA KEYBOARDUMMKeybd.exeMultimedia keyboard manager. Required if you use the additional keysNo
MmmUMmm.exeHace Mmm - free utility to configure your Windows menus and move and remove menu-items you never useNo
eZmmodXmmod.exeeZula adwareNo
mmodXmmod.exeeZula adwareNo
OM2_MonitorNMMonitor.exeOlympus Master management tool for their range of digital cameras. Monitors your computer for when the camera is plugged inNo
Microsoft Security Monitor ProcessXmmp.exeAdded by a variant of the IRCBOT BACKDOOR!No
Twain imageXmmp32.exeDailyWinner adwareNo
MMReminderServiceNMMReminderService.exeMind Manager from Mindjet - "easy way to organize ideas and information". Registration reminderNo
Realtime Audio EngineUmmrtkrnl.exeAssociated with ALCATech BPM StudioNo
MMRun?mmrun.exe??No
MS management console?mms.exeSuspicious as the legitimate "Microsoft Management Console" is "mmc.exe" and not "mms.exe" and doesn't normally run at startupNo
sysmemXmmsete.exeAdded by the NOPIR.C WORM!No
QuickSetXmmspng.exeAdded by a variant of the IROFFER.Z TROJAN!No
MMSSJUITXMMSSJUIT.cplDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %System%No
Microsoft Network Services ControllerXmmsvc32.exeAdded by the NANPY-A WORM!No
Communications PanelXmmsystri32.exeAdded by the BACKDR-T BACKDOOR!No
MicrosoftMultimediaTaskXMmtask.exeAdware downloader. Note - this is not the legitimate MusicMatch Jukebox file which has the same filename and is normally located in %ProgramFiles%\Musicmatch\Musicmatch Jukebox. This one is located in %System%No
MmtaskXmmtask.exeAdded by the BURMEC WORM! Note - this is not the legitimate MusicMatch Jukebox file which has the same filename and is normally located in %ProgramFiles%\Musicmatch\Musicmatch Jukebox. This one is located in %System%No
mmtaskNmmtask.exePart of the MusicMatch Jukebox digital music player/CD burner and ripper/music organizer/playlist creator. Both MusicMatch Jukebox and it's successor (Yahoo! Music Jukebox) are no longer available after being bought by RhapsodyNo
MMtask ServiceXmmtask.exeAdded by the BACKGAT.A TROJAN! Note - this is not the legitimate MusicMatch Jukebox file which has the same filename and is normally located in %ProgramFiles%\Musicmatch\Musicmatch Jukebox. This one is located in %System%No
SchedulingAgantXMMTASK.EXEAdded by the YAB.A TROJAN! Note - this is not the legitimate MusicMatch Jukebox file which has the same filename and is normally located in %ProgramFiles%\Musicmatch\Musicmatch Jukebox. This one is located in %Windir%No
MMTASKYmmtask.tskA check on the file's properties reveals "Multimedia background task support module". MMTASK is a very simple 16-bit program used by certain multimedia drivers (which are still 16-bit on Win9x) to perform background processing. Some soundcards need this to support MIDI, etcNo
Winsock2 driverXmmtask5.exeAdded by the SPYBOT-CD WORM!No
MMTrayNMMTray.exePart of Morgan Multimedia Codecs. Only required when the codecs are usedNo
MMTray2KNMMTray2K.exePart of Morgan Multimedia Codecs. Only required when the codecs are usedNo
MMTrayLSINMMTrayLSI.exePart of Morgan Multimedia Codecs. Only required when the codecs are usedNo
mediamotor.exeXmmups.exeAdded by the AGENT-BY TROJAN!No
mmvaXmmvo.exeDetected by Sophos as W32/AutoRun-TD and by Malwarebytes Anti-Malware as Spyware.OnlineGamesNo
XiDXmmx.exeAdded by the ANALOGX TROJAN!No
mmxp2passion.exeXmmxp2passion.exeMediaMotor adwareNo
mm_serverUmm_server.exePart of MusicMatch Jukebox - a digital music player/CD burner and ripper/music organizer/playlist creator. Enables Universal Plug and Play devices (e.g. Apple's iPod) to access the music library. Both MusicMatch Jukebox and it's successor (Yahoo! Music Jukebox) are no longer available after being bought by RhapsodyNo
MMTrayNmm_tray.exeSystem Tray access to the MusicMatch Jukebox digital music player/CD burner and ripper/music organizer/playlist creator. Both MusicMatch Jukebox and it's successor (Yahoo! Music Jukebox) are no longer available after being bought by RhapsodyNo
mndis.exeXmndis.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Root%\addonsNo
Goldensoft_MndlSvrUMndlSvr.exeGoldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive, users can simultaneously access as many as 23 virtual CD-ROM drives at a speed of 200X for true multitaskingNo
mFilterXMNeck.exeAdded by the CLICKER-AG TROJAN!No
Microsoft Norotn Anti VirusXmnhpot.exeAdded by the RBOT-GRO WORM!No
Military Net KillerXMNK.exeAdded by the MILLNET-A WORM!No
mnklinsXmnklins.exeVX2.Transponder parasite updater/installer relatedNo
Mekio StartupsXMnksvc32.exeDetected by Microsoft as Backdoor:Win32/Gaobot.DC and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
FpxNmnmsrvc.exeRemote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locationsNo
MNPolXmnpol.exeAdded by the DLUCA.B TROJAN!No
GOOIGXmns.exeDetected by McAfee as RDN/Generic.bfr!bh and by Malwarebytes Anti-Malware as Backdoor.AgentNo
MNSUMNS.exeMobile Net Switch enables you to use your computer on more then one network with the click of a button. It allows you to automatically select the correct drive mappings, printer settings, IP settings and much moreNo
ServerXmns.exeDetected by McAfee as RDN/Generic.bfr!bh and by Malwarebytes Anti-Malware as Backdoor.AgentNo
Microsoft Security Monitor ProcessXmnsmp.exeAdded by a variant of the IRCBOT BACKDOOR!No
mnsaXmnso.exeAdded by the LINEAG-AI TROJAN!No
Mi7sft sdceXMNSQ.exeAdded by the RBOT.DMU WORM!No
mnsvcXmnsvc.exeAdded by the AUTOUPDER TROJAN!No
mnsvcspXmnsvcsp.exeAdded by an unidentified VIRUS, WORM or TROJAN!No
Microsoft Windows UpdateXmnswinsx.exeAdded by the RBOT-AWH WORM!No
VirusScannerXmnsys.exeAdded by the SDBOT-AFQ WORM!No
Microsoft WinUpdateXmntcgf032.exeAdded by the RBOT-PF WORM!No
[various names]XMNTP.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
HornetMonitorUMntrHrnt.exeHornet Monitor - monitoring system that detects and responds to unauthorized access attempts and sources of channel interference on any local DSSS networkNo
Messenger Sharing ControlXmnwsvc.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
MoneyAgentNmnyexpr.exeMicrosoft MoneyNo
MobileBroadbandNMobileBroadband.exeLauncher and System Tray access to Vodafone Mobile BroadbandYes
Vodafone Mobile BroadbandNMobileBroadband.exeLauncher and System Tray access to Vodafone Mobile BroadbandYes
MobileGo ServiceNMobileGoService.exeMobileGo by Wondershare - "is a one-stop Android phone manager installed on PC. With this handy and smart Android manager, you can manage your Android phone from PC more conveniently and effectively"No
Mobile Phone SuiteUMobilePhoneSuite.exeLogitech Mobile Phone SuiteNo
McAfee Online BackupUMOBKstat.exe.htmSystem Tray access to McAfee Online Backup (formerly Data Backup) - "takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos". Available as a stand-alone product or included in Internet Security and Total ProtectionYes
McAfee Online Backup StatusUMOBKstat.exe.htmSystem Tray access to McAfee Online Backup (formerly Data Backup) - "takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos". Available as a stand-alone product or included in Internet Security and Total ProtectionYes
MobileMeterUmobmeter.exeMobileMeter by Hexmagic - "is a system monitoring utility designed for laptop PCs running under the Windows environment". It can show the following information - CPU clock, CPU temperature, Battery charge/discharge rate and HDD temperatureNo
Microsoft Synchronization ManagerUmobsync.exeMicrosoft Synchronization Manager for 2K/XP - used to update network copies of materials that were edited offline, such as documents, calendars, and e-mail messages. Available via Start → All Programs → Synchronize, this entry appears if you select Setup → "When I log on to my computer"Yes
mobsyncUmobsync.exeMicrosoft Synchronization Manager for 2K/XP - used to update network copies of materials that were edited offline, such as documents, calendars, and e-mail messages. Available via Start → All Programs → Synchronize, this entry appears if you select Setup → "When I log on to my computer"Yes
Synchronization ManagerUmobsync.exeMicrosoft Synchronization Manager for 2K/XP - used to update network copies of materials that were edited offline, such as documents, calendars, and e-mail messages. Available via Start → All Programs → Synchronize, this entry appears if you select Setup → "When I log on to my computer"Yes
MOBSYNC32.EXEXmobsync32.exeAdded by the FINERO TROJAN!No
Synchronization AgentXmobsynca.exeAdded by the RANDEX-E WORM!No
MODEMBTRUMODEMBTR.EXEModem Booster from inKline Global to improve ISP connectionsNo
ModeminfXmodeminf.exeAdded by the GEMA TROJAN!No
ModemListener?ModemListener.exeRelated to USB based mobile broadband services such as those available from Virgin Media, VIVCOM and othersNo
AModemLockDownUModemLockDown.exeModemLockDown - allows you to supervise internet access by disabling the modem, protects againt dialers accessing dial-up connections, etcNo
ModPS2UModPS2Key.exeHotkey drivers for Chicony keyboard. Required if you use the hotkeysNo
Microsoft ServicesXmodule.exeAdded by a variant of the IRCBOT BACKDOOR!No
Windows Security ModuleXmodule.exeAdded by a variant of Win32/RbotNo
tgbcdeXmodule32.exeAdded by the REIGN.R TROJAN!No
modules.exeXmodules.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %AppData%No
FLMOFFICE4DMOUSEUmoffice.exeMouse utility for a Labtec brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouseNo
ModemOnHoldUMOH.EXENetWaiting/Modem-on-Hold - allows you to place your Internet connection on hold while you take a voice call (if Call Waiting is supported by your phone company). See here for more informationNo
96edfdf7556b50dd7375dc1b2c0dd5c6Xmohamed.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserTemp%No
moleculeXmolecule.exeDetected by Malwarebytes Anti-Malware as PasswordStealer.Naughter. The file is located in %System%No
MolldiveUpdaterXMolldiveUpdater.exeDetected by Dr.Web as Trojan.DownLoader5.57491 and by Malwarebytes Anti-Malware as Adware.KraddareNo
WindowsSystem32Xmolox.exeAdded by the RBOT.WBG BACKDOOR!No
HPXmon.exeAdded by the SILLYFDC WORM!No
iPalmNmon.exeInstalled with a Panasonic iPalm digital camera. Used to upload photos from the camera. If your camera is not connected (via USB port) you do not need this program loadedNo
[various names]XMON76234.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
MoneyAgentNmoney express.exePart of MS Money. Available via Start → ProgramsNo
MoneyStartUpNMoney Startup.exeMicrosoft MoneyNo
Money ExpressNmoneyexpress.exePart of MS Money. Available via Start → ProgramsNo
realone_nt2003Xmoniker.exeAdded by the SNONE.A WORM!No
[various names]Xmoniter.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
802.11g Wireless AdatperUMonitor.exeRelated to wireless card (802.11) adapter/standard. System Tray icon that provides a shortcut to "Wireless Connection Status" and allows to turn WL on and off. Supplier unknown. Adapter is miss-spelledNo
Advanced Uninstaller PRO Installation MonitorUmonitor.exeAdvanced Uninstaller PRO by Innovative Solutions - "is the ultimate uninstaller for Windows, allowing you to uninstall programs quickly and completely using its simple and intuitive interface"No
ENCMONITORNmonitor.exeThe Encompass Monitor. This program is the Connect Direct Program. It is more trouble than it is worth and few use itNo
eRecoveryServiceUMonitor.exePart of Acer Empowering Technology. "Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer, and also acts as a versatile standalone backup and recovery manager"No
Manager MonitorUmonitor.exeMindStorm AnalyzerPro from Secure Associates. "A security management tool for customers easy to manage report and analyze security events across heterogeneous security devices"No
monitorXmonitor.exeBrowser hijacker, redirecting to NCM SearchNo
MonitorUMonitor.exeMonitor application for the Philips SPC610NC webcam, those based upon CMOS image sensors from PixArt Imaging Inc (such as the PAC207 and PAC7302) and possibly others. Also the Leapfrog Connect ApplicationNo
Monitor HelperUmonitor.exeMyLittleSpy keystroke logger/monitoring program - remove unless you installed it yourself!No
OM_MonitorNMonitor.exeOlympus Master management tool for their range of digital cameras. Monitors your computer for when the camera is plugged inNo
PAC207_MonitorUMonitor.exeMonitor application for webcams using the PixArt PAC207 CMOS image sensor from PixArt Imaging IncNo
PAC7302_MonitorUMonitor.exeMonitor application for webcams using the PixArt PAC7302 CMOS image sensor from PixArt Imaging IncNo
PAC7311_MonitorUMonitor.exeMonitor application for webcams using the PixArt PAC7311 CMOS image sensor from PixArt Imaging IncNo
Pagis Schedule MonitorUMonitor.exeScheduler for the Pagis scanning suite from Scansoft (now Nuance)No
Pagis SchedulerNMonitor.exeScheduler for the Pagis scanning suite from Scansoft (now Nuance)No
SPC610NC_Monitor?Monitor.exeRelated to the Philips SPC610NC webcam. What does it do and is it required?No
Ulead AutoDetectorNMonitor.exePart of Ulead (now Corel) programs such as Photo Express and VideoStudio - automatically detects the presence of a digital camera or memory card and launches the program that supports itNo
Ulead AutoDetector v2Nmonitor.exePart of Ulead (now Corel) programs such as Photo Express and VideoStudio - automatically detects the presence of a digital camera or memory card and launches the program that supports itNo
Ulead Memory Card DetectorNMonitor.exePart of Ulead (now Corel) programs such as Photo Express and VideoStudio - automatically detects the presence of a memory card and launches the program that supports itNo
monitor1aXmonitor1a.exeAdded by the MSNAGEN-A TROJAN!No
Belkin PCMCIA WLAN MonitorNmonitorbk.exeBelkin USB Network Adapter Management utility - can be started manuallyNo
Softany Monitor ControlUMonitorControl.exeSoftany Monitor Control - "control your computer's monitor and screensaver"No
MonitormgtXMonitormgt.exeAdded by the GEMA TROJAN!No
Canon MultiPASS Status MonitorUmonitr32.exeCanon Multi-Pass status monitorNo
MP_STATUS_MONITORUmonitr32.exeCanon Multi-Pass status monitorNo
mono.exeXmono.exeAdded by the SDBOT-DHV WORM!No
MonoCecilXMonoCecil.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader.SU. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
Alps Electric USB ServerYMonserv.exeAlps Electric USB Server - required according to this articleNo
mbssm32Xmonstu.exeDetected by AVG as the AGENT.CNM TROJAN - see hereNo
Microsoft System MonitorXmonsys.exeAdded by the IRCBOT-YV TROJAN!No
Montreal Canadiens WeatherUMontreal Canadiens Weather.exeWeather gadget included with the Montreal Canadiens theme for MyColors from Stardock CorporationNo
System MonitoringXMooks.EXEAdded by the BHARAT.A WORM!No
moon phaseNmoon.exeMoon Phase - tray icon that indicates the phases of the moonNo
DesktopX WidgetUMoonPhase.exeMoon Phase widget for the DesktopX desktop utility from Stardock Corporation. Displays the current phase of the Moon in true color using NASA imagery. Once started, MoonPhase.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entryYes
Moon PhaseUMoonPhase.exeMoon Phase widget for the DesktopX desktop utility from Stardock Corporation. Displays the current phase of the Moon in true color using NASA imagery. Once started, MoonPhase.exe loads a file called "DXWidget.exe" and exitsYes
DesktopX WidgetUMOONPH~1.EXEMoon Phase widget for the DesktopX desktop utility from Stardock Corporation. Displays the current phase of the Moon in true color using NASA imagery. Once started, MoonPhase.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 MSConfig entry where "MoonPhase.exe" is shown as "MOONPH~1.EXE"Yes
Moon PhaseUMOONPH~1.EXEMoon Phase widget for the DesktopX desktop utility from Stardock Corporation. Displays the current phase of the Moon in true color using NASA imagery. Once started, MoonPhase.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "MoonPhase.exe" is shown as "MOONPH~1.EXE"Yes
MoonyUmoony.exeMoony - ISDN software that lets you "always know who is calling or who called when you were away"Yes
w32alanisXmope.scrAdded by the SINALA WORM!No
mopheXmophe.exeDetected by McAfee as RDN/Generic.bfr!bb and by Malwarebytes Anti-Malware as Trojan.VBKryptNo
ProgramWindow?more comp.exe??No
Internet SendXMore log.exeUnidentfied adwareNo
MoreResultsXMoreResults.exeMoreResults adwareNo
MSys32Umorfitwe.exeWebentrance adwareNo
Msys32Xmorfitwebentrance.exeMorfit ADjectPager - "uses home page rental technology for generating revenues". Homepage hi-jacker that re-defines your IE or Netscape start page as http://www.web-entrance.com/. Any installed application including this must be un-installed before you can reset your homepageNo
MorpheusNmorpheus.exeMusicCity Networks' Morpheus - another peer-to-peer client based on Kazaa. Notable in that this one doesn't seem to install the adware that clog the Kazaa download. They claim they are adware free, and a visitor quotes "I have seen no instance of any since using it"No
morphstbXmorphstb.exeAdware - detected by Kaspersky as the STUBBY.C TROJAN!No
WINDOWS[Chinese chars]Xmorsvr.exeDetected by Malwarebytes Anti-Malware as Spyware.Password. The file is located in %ProgramFiles%\morsvrNo
mosadlXmosadl.exeAdded by the RBOT-GWN WORM!No
mosearchXmosearch.exeFast Search in Office XP - similar to the new revision of the Find Fast feature in Office 2000. Fast Search uses the Indexing Services in Office XP to create a catalog of Office files on your computer's hard disk. As with Find Fast - a waste of resources. If it can't be disabled via MSCONFIG try hereNo
Microsoft Autorun5Xmosou.exeDetected by Symantec as W32.Ogleon.ANo
Motive SmartBridgeNMotiveSB.exeSystem tray icon for the virtual assistant from a number of internet providers - used to communicate internet problems via the network rather than telephone. Known to cause various issues with slow performance and crashes so it's suggested you disable this software and run it only if instructed by your ISP's support staffNo
MotiveSBNMotiveSB.exeSystem tray icon for the virtual assistant from a number of internet providers - used to communicate internet problems via the network rather than telephone. Known to cause various issues with slow performance and crashes so it's suggested you disable this software and run it only if instructed by your ISP's support staffNo
MotiveMonitorUmotmon.exeFound on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used by the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufacturer. For most users it's not requiredNo
MotMonUmotmon.exeFound on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used by the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufacturer. For most users it's not requiredNo
139b6e5c0153981a3f5f0660f5d5ec36XMotorola.exeDetected by Malwarebytes Anti-Malware as Trojan.Ransom. The file is located in %UserTemp%No
vutouXmounaquek.exeAdded by the DLOADR-BDQ TROJAN!No
mount.exeUmount.exePart of "GiPo@FileUtilities - GiPo@Mount "Provides advanced substitutional and mounting services. It allows to attach a local drive to an empty folder on an NTFS volume (only for Windows 2000/XP) and to substitute a local folder for a drive letter"No
Mustek MDC 3000?Mounter.exeRelated to software for the Mustek MDC 3000 digital camera - what does it do and is it required?No
vsobeckmjkXmountvolo.exeDetected by Malwarebytes Anti-Malware as Adware.SanctionedMedia. The file is located in %System%No
Configuration LoaderXmouse.exeAdded by a variant of the AGOBOT WORM!No
mouseXmouse.exeDetected by Sophos as W32/Rbot-AHJNo
FLMBROWSEMOUSEUmouse32a.exeMouse utility - if you disable this entry you will not be able to use any of the non-standard functions of the mouseNo
FLMBROWSERMOUSEUmouse32A.exeMouse utility for a Trust brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouseNo
FLMLABTECMOUSEUmouse32A.exeMouse utility for a Labtec brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouseNo
FLMMEDIONMOUSEUmouse32a.exeMouse utility for a Medion branded Fellowes mouseNo
FLMOFFICE4DMOUSEUmouse32a.exeMouse utility for a Micro Innovations brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouseNo
FLMTRUSTMOUSEUmouse32a.exeMouse utility for a Trust brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouseNo
LWBMOUSEUMOUSE32A.EXEMouse utility for a Lenovo brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouseNo
Mouse 32AUMouse32A.exeMouse utility. If you disable this entry you will not be able to use any of the non-standard functions of the mouseNo
Enable Belkin Wireless Mouse DriverUMouseAp.exeMouse software included with a Belkin wireless mouse which allows the user to map buttons to various functionsNo
MousebutXmousebut.exeAdded by the CRYPTER.A TROJAN!No
MousecntlXmousecntl.exeAdded by the GEMA TROJAN!No
Mousecntl32Xmousecntl32.exeAdded by the GEMA TROJAN!No
LogitechXMouseDriverX86.exeDetected by Malwarebytes Anti-Malware as Trojan.Autoit. The file is located in %AppData%No
MousedrvXmousedrv.exeAdded by the CRYPTER.A TROJAN!No
WireLessMouseUMouseDrv.exeWireless mouse driverNo
WireLessMouse UMouseDrv.exeWireless mouse driver. Note the space at the end of the "Startup Item" fieldNo
mouseElfUmouseElf.exeSystem Tray access to the mouse control panel for Genius Netscroll mice. Required if you use non-standard Windows driver featuresNo
mousepadXmousepad.exeAdded by the CLICKER TROJAN!No
TipsNmousetips.exeSuggests tips on using your mouseNo
Windows Mouse UtilitiesXmouseutils.exeAdded by the RBOT-ABU WORM!No
run=Xmouse_configurator.winAdded by the GAGGLE.E WORM!No
MousinfoUmousinfo.exeMS mouse information tool - for troubleshooting mouse problemsNo
M3TrayNMovielink Tray.exeSystem Tray access to the now defunct Movielink "web-based video on demand (VOD) and electronic sell-through (EST) service offering movies, TV shows and other videos for rental or purchase". Movielink LLC were acquired by Blockbuster in 2008No
moviemkXmoviemk.exeAdded by the DWNLDR-GTB TROJAN!No
MovieNetworksXMovieNetworks.exeMovieNetworks will connect you by a domestic premium rate telephone number 900-xxx-xxxx - so you get xxx rated pictures and junk and high internet costs. Remove the %ProgramFiles%\MovieNetworks directoryNo
MovieplaceXMovieplace.exeMediaCharger\MoviePlace malwareNo
Microsoft Internet ExplorerXmovies.exeAdded by the BANCOS-DZ TROJAN!No
MozilaXmozila.exeAdded by the DELBOT-AJ WORM!No
[various names]Xmozilla-text.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
5a61db202f6f70d1dd9ec94876e237a4XMozilla.exeDetected by Dr.Web as Trojan.DownLoader8.15600 and by Malwarebytes Anti-Malware as Trojan.MSILNo
MozillaXMozilla.exeDetected by Malwarebytes Anti-Malware as Flooder.Ramagedos. The file is located in %AppData%No
Mozilla Quick LaunchNMozilla.exeNetscape 6 and Mozilla browsersNo
Mozy StatusUmozystat.exeMozy - free backup at a secure, remote locationNo
WINPORTXXmp.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.WPX. The file is located in %CommonAppData%No
DRam prmaessorXmp2ld.exeDetected by Total Defense as Win32/Rbot.EYG and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
329d18d46b0a1cbb6d698340a9d3c93dXmp3.exeDetected by Dr.Web as Trojan.DownLoader6.59156 and by Malwarebytes Anti-Malware as Trojan.Agent.SVRNo
MP3 Rocket (silent)NMP3Rocket_on_startup.exe"MP3 Rocket is the fastest and easiest software for converting YouTube to MP3s"No
abtuXmp3serch.exeLoads the executable for Lop.com - final versionNo
MP4 PlayerXmp4Player.exeMP4 Player allows you to view MP4 videos. Marked as undesirable due to the fact that it changes your homepage to a custom Google search engine, changes your browser's default search provider, and runs hidden in the background. Terms of use also state that it collects and tracks urls you visit in order to display relevant adsNo
MPatrolPROXMPatrolPRO.exeMalwarePatrol Pro rogue security software - not recommended, removal instructions hereNo
Motive SmartBridgeNmpbtn.exeSystem tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start → Programs - not requiredNo
Windows WorkstationXmpci.exeDetected by Trend Micro as WORM_RBOT.BNQNo
SiS Mpc ServiceXmpcsvc.exeAdded by the CIADOOR-CJ TROJAN!No
MPFExeYmpf.exeMcAfee Personal FirewallNo
Macfee Security PatchXMpfsheild.exeAdded by the RBOT-NP WORM!No
MPFExeYMpfTray.exeMcAfee Personal FirewallNo
MPFTrayYMpfTray.exeMcAfee Personal FirewallNo
LTM2XMPGSRV32.EXEAdded by the LITMUS.201 BACKDOOR!No
mobile PhoneToolsUmPhonetools.exeMotorola Phone ToolsNo
MapiDrvXmpisvc.exeAdded by the MIPSIV TROJAN!No
MyPopupKillerUmpk.exeMyPopupKiller - popup killerNo
MPL32 driverXMPL32.exeAdded by the LOONY-M TROJAN!No
MPlay64Xmplay64.exeDetected by Trend Micro as TROJ_DLOADE.DATNo
iLLeGaLXMplayer.exeDetected by Trend Micro as WORM_HOLAR.CNo
iLLeGaL.exeXMplayer.exeDetected by Symantec as W32.Galil@mmNo
Win32 ConfigurationXmplayer.exeAdded by the FORBOT-BZ WORM!No
mpXMplayer2.exeDetected by Malwarebytes Anti-Malware as Worm.Ructo. The file is located in %Root%\programdataNo
mpXmplayer2.exeDetected by Dr.Web as Trojan.FakeAV.11067 and by Malwarebytes Anti-Malware as Worm.Ructo. The file is located in %Root%\CRNJEUFUNo
mpXMplayer2.exeDetected by Trend Micro as WORM_RUCTO.BH and by Malwarebytes Anti-Malware as Worm.Ructo. The file is located in %System%No
wmplayerXmplayer2.exeDetected by Microsoft as Worm:Win32/VB.WG and by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %Root%\messengerplusNo
wmplayerXmplayer2.exeDetected by Sophos as Troj/Bancos-BUI and by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %Windir%\system32messengerplusNo
auloadplxXmplprogsm.exeAdded by the SLAPER.K TROJAN!No
MplSetupUMplSetup.exeUsed by Ricoh network printers to enable network printing from the clientNo
Windows UpdateXmplupdate.exeDetected by Symantec as W32.HLLW.Moega and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
HPWG myPrintMileage AgentNmpm.exemyPrintMileage HP printer monitoring utility for the Deskjet 9300 Series that allows you to "forecast printer usage and to plan the purchase of supplies" and "generate reports showing usage data, cost per page, or cost per job for a specific time period using print accounting"No
HPWH myPrintMileage AgentNmpm.exemyPrintMileage HP printer monitoring utility for the Business Inkjet 1100 Series that allows you to "forecast printer usage and to plan the purchase of supplies" and "generate reports showing usage data, cost per page, or cost per job for a specific time period using print accounting"No
HPWS myPrintMileage AgentNmpm.exemyPrintMileage HP printer monitoring utility for the Deskjet 1280 that allows you to "forecast printer usage and to plan the purchase of supplies" and "generate reports showing usage data, cost per page, or cost per job for a specific time period using print accounting"No
HPWT myPrintMileage AgentNmpm.exemyPrintMileage HP printer monitoring utility for the Business Inkjet 1000 that allows you to "forecast printer usage and to plan the purchase of supplies" and "generate reports showing usage data, cost per page, or cost per job for a specific time period using print accounting"No
MPM ManagerXMPM.exeAdded by the DONBOMB.A TROJAN!No
myPrintMileageNmpm.exemyPrintMileage HP printer monitoring utility for the Deskjet 450 that allows you to "forecast printer usage and to plan the purchase of supplies" and "generate reports showing usage data, cost per page, or cost per job for a specific time period using print accounting"No
myPrintMileage HPWT AgentNmpm.exemyPrintMileage HP printer monitoring utility for the Business Inkjet 1000 that allows you to "forecast printer usage and to plan the purchase of supplies" and "generate reports showing usage data, cost per page, or cost per job for a specific time period using print accounting"No
MpMsEngX64XMpMsEngX64.exeDetected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.MessaNo
MPNetXmpn.exeAdded by the DELBOT-W WORM!No
MPowerUMPower.exeMPower from MindBeat - "Defragments and frees your RAM giving more stability to your system and avoiding needless use of swap file. Will also benchmark (speed test) your hard disk drives and your CPU load." No longer supported or available from the authorNo
MediaPipe P2P LoaderXmpp2pl.exeMovieland/MediaPipe subscription-based movie download service reported by CA as adware and by Sunbelt as a hijackerNo
mppddsXmppdds.exeAdded by the PWS-AKZ TROJAN!No
mppdsXmppds.exeDetected by Trend Micro as TSPY_LEGMIR.AQZNo
MPREXEXMPREXE.EXEAdded by the OPASERV.T WORM!No
MPREXE.exeYmprexe.exeWIN32 Network Service Interface Process. MPREXE.exe enables the computer to have multiple clients/protocols for networks. There are some problems with it sometimes though - see here. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background. NOTE : sometimes it will appear in start-ups if you have a virusNo
MprHTMLXMprHTML.exeAdded by a variant of the VAGRNOCKER BACKDOOR!No
rmmonNmprmmon.exeResource Monitor for the now defunct Chromatic Research MPact2 3DVD graphics cardNo
MPR MSGXmprmsg32.exeAdded by the MYTOB.CF WORM!No
mprocessorXmprocessor.exeInstallDollars.com foistwareNo
prognserXmprognser.exeDetected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\prognserNo
MpsOnnYMpsOnn.exeCanon printer driverNo
MP ServicesXmpsvc.exeAdded by the WOOTBOT.EQ WORM!No
MPT?MPT.exe??No
M-Audio MobilePre Control Panel LauncherUMPTask.exeControl Panel Launcher for the M-Audio MobilePre USB bus-powered preamp and audio interfaceNo
MPtask ServicesXmptask.exeAdded by the LALA or AOT TROJANS!No
MPTBoxNMPTBox.exeCanon Multi-Pass toolbox - a button barNo
MP TcloaxsXmptcloaxs.exeAdded by the RANDEX.CT WORM!No
MP TcloakssXmptclock.exeAdded by the NACKBOT-B WORM!No
MP TclockvvXmptclock.exeAdded by the NACKBOT-A WORM!No
MP TclockvvXmptclockvv.exeAdded by the RANDEX.CJ WORM!No
XTNDConnect PC - MyPalmUMPTray.exePalm OS specific translator for XTNDConnect PC - "award-winning desktop-sync application that enables you to easily synchronize your contacts, calendar, tasks, email and notes between your mobile devices and popular PC applications"No
mptsgsvc.exeXmptsgsvc.exeHacker Tool - detected by DiamondCS TDS-3 anti-trojan as "HackTool.Win32.Hidd.j"No
Windows Media PlayerXmpupdata.exeDetected by Trend Micro as WORM_SDBOT.BBGNo
Windows Media PlayerXmpwe.exeAdded by the RBOT-TT WORM!No
MPXTrayNmpxptray.exeWindows Media Player PowerToy which is run from the taskbar. It can be used to hide Windows Media Player (when in use) and choose various standard buttons (play/pause, next,previous) etcNo
Malware Protection CenterXMP[random characters].exeMalware Protection Center rogue security software - not recommended, removal instructions hereNo
SiSAudioNMP_S3.exeWinME patch for an older SiS 961 chipset FERR bug. Enable if you have audio problemsNo
mqadscp3Xmqadscp3.exeAdded by the STRATION.CX WORM!No
mqbkupXmqbkup.exeAdded by the OPASERV.K WORM!No
qbkupdbsXmqbkup.exeAdded by the OPASERV.K WORM!No
Windows Network ControllerXMqguard.exeAdded by the FORBOT-CL WORM!No
MqtgSVCXmqtgsvc.exe /waitserviceDetected by Microsoft as TrojanDownloader:Win32/Horst.Q. Note - this is not the legitimate mqtgsvc.exe which is always located in %System%. This one is located in either %Windir%, %Windir%\System, %Temp%, %AppData%, %AppData%\Microsoft or %System%\driversNo
MQT SvcXmqtsvc.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
8245cc6867990579e6f54d795b6f0ffdXmr 3bsi.exeDetected by McAfee as Trojan-FAUE!DBAE08C48F69 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJNo
[14 random numbers]Xmradll.exeGreen AV rogue security software - not recommended, removal instructions here. The most common entry has the number 37465982736455No
1Xmrcmgr.exeAdded by the BANKER.RQK TROJAN!No
{**-**-**-**-**}Xmrdsregp.exeZenoSearch adware variant where ** are random charactersNo
MirrorFolderShellUmrfshl.exeMirrorFolder backup softwareNo
[random name]Xmrgdll.exeNortel Antivirus rogue security software - not recommendedNo
iudymosjXmrgviurtssd.exeAdded by the AGENT-OEM TROJAN!No
Logical Disk DetectionXmrisvc.exeAdded by the IRCBOT.AOW BACKDOOR!No
Syga432te Pe432rsonal FirewallXMrNo4236.exeAdded by the RBOT-AQY WORM!No
runner1Xmrofinu.exeAdded by the AGENT.CZC TROJAN!No
Motorola Desktop Suite mRouter ConfigUmRouterConfig.exeConfiguration for Motorola's version of Intuwave's m-Router - "that enables easy connectivity between mobile devices and PCs across Bluetooth, Infrared, USB and serial cable connections". It was licensed and used by the Symbian OS but m-Router is no longer readily available since Intuwave went into administration in 2006No
mRouterUmRouterConfig.exeConfiguration for Intuwave's m-Router - "that enables easy connectivity between mobile devices and PCs across Bluetooth, Infrared, USB and serial cable connections". It was licensed and used by the Symbian OS but m-Router is no longer readily available since Intuwave went into administration in 2006Yes
mRouterConfigUmRouterConfig.exeConfiguration for Intuwave's m-Router - "that enables easy connectivity between mobile devices and PCs across Bluetooth, Infrared, USB and serial cable connections". It was licensed and used by the Symbian OS but m-Router is no longer readily available since Intuwave went into administration in 2006Yes
SVCHOSTXmrowyekdc.exeAdded by the GOTORM WORM!No
WinlogonXmrss32.exeDetected by Dr.Web as Trojan.DownLoader6.30444 and by Malwarebytes Anti-Malware as Trojan.AgentNo
Winlogon1Xmrss32.exeDetected by Dr.Web as Trojan.DownLoader6.30444 and by Malwarebytes Anti-Malware as Trojan.AgentNo
mrsvctrXmrsvctr.exeAdded by a variant of W32/Sdbot.wormNo
MRTYMRT.exeMicrosoft's Malicious Software Removal ToolNo
MediaRing TalkNmrtalk.exeMedia Ring Talk, voice recognition software, Resource hog. Available via Start → ProgramsNo
Windows Service Agent 32Xmrthd.exeAdded by the AGENT-GAQ TROJAN!No
mrtMngrNmrtMngr.exeMaintenance Release Task Manager for Intuit's QuickBooks or QuickenNo
Windows LayerXmrtmoons.exeAdded by the KOLAB.AUT WORM!No
mrtwXmrtw.exeFake MSRT rogue security software - not recommended, removal instructions here. This rogue imitates the legitimate Microsoft Malicious Software Removal Tool (MSRT)No
MRU-Blaster Silent CleanNmrublaster.exeMRU-Blaster from Brightfort (formerly Javacool Software) - performs silent cleaning of MRU (most recently used) lists at bootNo
b769a63eba6827200acac1af038bfb34Xmrx.exeDetected by Dr.Web as Trojan.DownLoader7.2082 and by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Temp%No
Ms Spool32XMS SPOOL32.EXEAdded by the ASASSIN TROJAN!No
msmcXms****.exe [* = random char]ClientMan parasite variantNo
Ms**.exe [* = random char]XMs**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this logNo
Ms**32.exe [* = random char]XMs**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this logNo
MS-DOS Security ServiceXms-dos.pifAdded by the RBOT-AMR WORM!No
MS-DOS ServiceXMS-DOS.pifAdded by the RBOT-AII WORM!No
MS-DOS Windows ServiceXMS-DOS.PIFAdded by the RBOT-AJW WORM!No
[various names]Xms-its.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
Windows BootupXms-wks32.exeAdded by the RBOT-AFM WORM!No
Microsoft UpdateXms.exeAdded by the SDBOT.CC BACKDOOR!No
UpdateXpSpXMS045-XP2.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
win32servvXms1.exeDetected by McAfee as Adware-ISearchNo
msdllXms1dll0.exeAdded by the AUTORUN-BMW WORM!No
ms2srcXms2src.exeAdded by a TROJAN - see hereNo
Compaq32 Service DriversXms32.exeDetected by Trend Micro as WORM_SDBOT.BWHNo
Ms Java for Windows NTXMS32.exeAdded by the VANEBOT-H WORM!No
Windows SecurityXms32.pifAdded by the RBOT-ARN WORM!No
Microsoft FeaturesXms32cfg.exeAdded by the RBOT.HO WORM!No
MS32DLLXMS32DLL.dll.vbsAdded by the ZODGILA WORM!No
systemdrvXms32sys.exeAdded by an unidentified WORM or TROJAN - most likely GAOBOT variantNo
Video ProcessXMS32x16.exeAdded by the RBOT.RH WORM!No
Microsoft Update ControlXMs64.exeAdded by a variant of Win32/RbotNo
MS7531Xms7531.exeHomepage hijackerNo
MSPQFileXMSA****.TMP [* = random char]Homepage hijackerNo
AntivirusXMSA.exeMS Antivirus rogue security software - not recommended, removal instructions hereNo
NordBullXmsa.exeAdded by the DLOADR-CSV TROJAN!No
Windows Media PlayerXmsa.exeAdded by the RBOT-SI WORM!No
MSACMXmsacm.exeAdded by the OPASERV-O WORM!No
PostBootReminderXmsacm32.exeAdded by an unidentified WORM or TROJAN!No
Microsft Conf 32Xmsaconf.exeAdded by the RBOT.EYA WORM!No
Microsft Confige 32Xmsaconfigurez.exeAdded by the RBOT.CLC WORM!No
Microsoft Macro Protection SubSsyXmsacroprots386.exeAdded by the RBOT-KE WORM!No
msadcheckXmsadcheck32.exeBrowser hijacker, redirecting to search-system.comNo
Microsoft Admin ProtocalXMSADNIN.exeAdded by a variant of Win32/RbotNo
Microsoft Windows Operating SystemXmsadrh10.exeDetected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Trojan.MWF.GenNo
Microsoft® Windows® Operating SystemXmsadrh10.exeDetected by Dr.Web as BackDoor.Siggen.44167 and by Malwarebytes Anti-Malware as Trojan.FakeMSNo
Microsoft® Windows® Operating SystemXmsadrh15.exeDetected by Dr.Web as BackDoor.Pigeon1.2748 and by Malwarebytes Anti-Malware as Backdoor.MessaNo
COM ServiceXmsafqy.comDetected by McAfee as BackDoor-AMQ and by Malwarebytes Anti-Malware as Backdoor.BeastDoorNo
[various names]Xmsag.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
My AgentXmsagent.exeAdded by the NEGASMS.A TROJAN!No
MSAgentXPXMSAgentXP.exeIdentified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the REQLOOK.C TROJAN!No
MsAiStartXMsAiStart.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%No
MainProXmsamand.exeDetected by Dr.Web as Trojan.DownLoader6.61248 and by Malwarebytes Anti-Malware as Trojan.AgentNo
Windows Media PlayerXmsams.exeAdded by the RBOT.AHR WORM!No
Microsoft AOL Instant MessengerXMSAOL32.exeAdded by the RBOT-AAI WORM!No
AOL Instant Messenger dll runtimeXMSAOL32dll.exeAdded by the RBOT-ATA WORM!No
MS Windows AOL DriverXMSAOLdrv.exeAdded by the RBOT-ASP WORM!No
msaimUmsaolim.exeMessageSpy keystroke logger/monitoring program - remove unless you installed it yourself!No
Microsoft Application ManagerXmsapl32.exeAdded by the BROPIA-AE TROJAN!No
WinApp32Xmsapp.exeAdded by the RSBOT TROJAN!No
Microsoft SpA ServiceXmsapps.exeAdded by the RBOT-VI WORM!No
msappts32Xmsappts32.exeAdded by the ELBURRO-A TROJAN!No
(Default)Xmsarti.comDetected by Trend Micro as WORM_SILLYFDC.CJ. Note - this malware actually changes the value data of the "(Default)" key in HKLM\..\Policies\Explorer\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
MS AntiSpyware 2009Xmsas2009.exeMS AntiSpyware 2009 rogue spyware remover - not recommended, removal instructions hereNo
MSASCuiYMSASCui.exeMain user interface for Microsoft's Windows Defender on XP/Vista - which "helps protect your computer against pop-ups, slow performance, and security threats caused by spyware and other unwanted software by detecting and removing known spyware from your computer". Used in conjunction with the associated service, this entry is always running and the user also has the option to always display the System Tray icon and monitor/control new startup programsYes
Windows DefenderXMSASCui.exeDetected by Kaspersky as Trojan-Spy.MSIL.Caco.d and by Malwarebytes Anti-Malware as Backdoor.Bot. Note - this is not the legitimate user interface for Windows Defender, which has the same filename and is normally located in %ProgramFiles%\Windows Defender. This one is located in %UserTemp%No
Windows DefenderYMSASCui.exeMain user interface for Microsoft's Windows Defender on XP/Vista - which "helps protect your computer against pop-ups, slow performance, and security threats caused by spyware and other unwanted software by detecting and removing known spyware from your computer". Used in conjunction with the associated service, this entry is always running and the user also has the option to always display the System Tray icon and monitor/control new startup programsYes
MS Config StreamXmsasm.exeAdded by the AGOBOT-BA WORM!No
asnconsoleXmsasn.exeAdded by the RBOT.EVU TROJAN!No
MS Auto-IPSec ProtectionXMSASP32.exeDetected by Sophos as W32/Rbot-AERNo
Windows Media PlayerXmsass43.exeAdded by the RBOT-RT WORM!No
load=Xmsater.exeAdded by the RETSAM TROJAN!No
MSWTL32XMSATL32.exeAdded by an unidentified WORM or TROJAN! See hereNo
lsass driverXmsauc.exeAdded by the PAKES.NP TROJAN!No
Microsoft Corp TLS CertificatesXmsauth.exeAdded by the RBOT-GAC WORM!No
MS Autoloader 32XMSAuto32.exeAdded by the SPYBOT.BD WORM!No
Microsoft Automatic Update SerivceXmsautou.exeAdded by the RBOT-AOB WORM!No
Microsoft Anti Virus ControllerXmsavc.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
Microsoft Anti Virus ControllerXmsavc32.exeAdded by the SDBOT.EPW BACKDOOR!No
msavsc.exeXmsavsc.exeAdded by the AGENT.ANQ TROJAN!No
Microsoft UpdateXmsawindows.exeAdded by the GAOBOT.AFJ WORM!No
Windows updateXmsb32.exeDetected by Microsoft as Worm:Win32/Gaobot.CG and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
msbbXmsbb.exe180Search adwareNo
Msbb.exeXMsbb.exeDetected by Trend Micro as WORM_SDBOT.QJNo
System Information ManagerXMsbb.exeAdded by the SLINBOT.YR BACKDOOR!No
COM ServiceXmsbcqg.comDetected by McAfee as BackDoor-AMQ and by Malwarebytes Anti-Malware as Backdoor.BeastDoorNo
msbcsXmsbcs.exeAdded by the DADOBRA-G TROJAN!No
windows auto updateXmsblast.exeAdded by the BLASTER.B WORM!No
Microsoft Broadband NetworkingUMSBNTray.exeMicrosoft Broadband Networking Tray ApplicationNo
MsBootMgr.exeXMsBootMgr.exeAdded by the VERIFY TROJAN!No
COM ServiceXmsbqgu.comDetected by McAfee as BackDoor-AMQ and by Malwarebytes Anti-Malware as Backdoor.BeastDoorNo
msbsound.exeXmsbsound.exeDetected by McAfee as Generic.tfr and by Malwarebytes Anti-Malware as Spyware.BankerNo
Microsoft Buffer AppXmsbuffer.exeAdded by the SLINBOT.NQ BACKDOOR!No
System Update ApplicationXmsbuffer.exeAdded by the SDBOT.AFF WORM!No
Bcvsrv32Xmsbvd32.exeAdded by the AGOBOT-SR WORM!No
Microsoft Core SupportXMSbz32.exeAdded by a variant of Win32/RbotNo
mscXmsc.exeMaCatte Antivirus 2009 rogue security software - not recommended, removal instructions hereNo
Bcvsrv32Xmsc32.exeAdded by the AGOBOT.AKD WORM!No
NvCplScanXmsc32.exeAdded by the FORBOT-DD WORM!No
MS UpdatesXmscache.exeSpyware web downloaderNo
CheckdiskXmscas.exeAdded by the VAGON-A TROJAN!No
KTNNKVLTXmscat32Q.exeDetected by Malwarebytes Anti-Malware as Adware.SanctionedMedia. The file is located in %System%No
System TrayXmsccn32.exeDetected by McAfee as W32/Sobig.b@MM. Warning - spreading via infected E-mail attachments with the sender address faked as support@microsoft.com!No
msccrtXmsccrt.exeDetected by Sophos as Troj/PWS-ALA and by Malwarebytes Anti-Malware as Spyware.OnLineGamesNo
vcmicrecXmsccsed.exeAdded by the MAILBOT-CE TROJAN!No
MSCNXmscdd.exeDetected by McAfee as RDN/Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
MscdexntXmscdexnt.exeDetected by Malwarebytes Anti-Malware as Trojan.Inject.MN. The file is located in %Windir%No
WINDOWS SYSTEM mscdvvsXmscdvvs.exeDetected by Trend Micro as WORM_MYTOB.MDNo
System Efficiency MonitorXmscedit32.exeAdded by the SDBOT.P TROJAN!No
Ms System ConfigXMscfg.exeAdded by the SDBOT-CCR WORM!No
MS Config v12Xmscfg12.exeDetected by Trend Micro as WORM_AGOBOT.YPNo
MS Config v13Xmscfg13.exeDetected by Trend Micro as WORM_AGOBOT.YQNo
Win startupXmscfg32.exeAdded by the SPYBOT-AE WORM!No
mscheckXmscheck.exeAdded by the AGENT-ECP TROJAN!No
star6XMscheldB.exeDetected by Trend Micro as TSPY_BANCOS.SMAM and by Malwarebytes Anti-Malware as Trojan.BankerNo
star7XMscheldncx.exeDetected by Trend Micro as TSPY_BANCOS.SMAM and by Malwarebytes Anti-Malware as Trojan.BankerNo
mschkdf.exeXmschkdf.exeDetected by Sophos as Troj/DwnLdr-GABNo
!SysInitXmschksys.exeAdded by the AGENT.CHS TROJAN!No
windows shellext.32Xmschost.exeAdded by the BLASTER.K WORM!No
MPSExeUmscifapp.exeMcAfee.com Privacy Service - "combines personal identifiable information (PII) protection with online advertisement blocking and content filtering"No
mscj.exeXmscj.exeAdded by the BACKDR-L BACKDOOR!No
mscjm.exeXmscjm.exeAdded by the DOWNLOADER-CJD TROJAN!No
MSWindows SysClXmscl32.exeAdded by the RBOT.AHI WORM!No
msclacXmsclac.exeAdded by the SDBOT-JM WORM!No
Microsoft ClientXmsclient.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
Client for Microsoft NetworksXmsclient32.exeAdded by the SDBOT-BXQ WORM!No
Microsoft Digital ClockXmsclock.exeAdded by the NACKBOT-D WORM!No
Microsoft client for NTXmsclt.exeAdded by the RBOT-DID WORM!No
Microsoft Windows Client FirewallXmsclt.exeAdded by the VANEBOT-F WORM!No
ClientMan1Xmscman.exeClientMan parasite variantNo
mscmanXmscman.exeClientMan parasite variantNo
msnmsg.exeXmscmd32.exeAdded by a variant of the AGENT.AH TROJAN!No
MSN ManagerXmscmgr.exeUnidentified malware - causes multiple browser windows to openNo
mscmsXmscms.exeAdded by the AGENT-MS TROJAN!No
Microsoft Device ManagerXmscmtl32.exeDetected by Kaspersky as Backdoor.Win32.Agent.bmq. The file is located in %Windir%No
mscnUmscn.exePart of the SafeChildNet internet filtering program - required if you use itNo
Microsoft Update 32Xmscnfg.exeAdded by the RBOT-ALM WORM!No
Microsoft Config 32bitXmscnfg32.exeAdded by the RBOT-Z WORM!No
Microszoft Update MachinezsXmscnsz.exeDetected by Sophos as W32/Rbot-FONo
MscntXmscnt.exeAdded by the DLUCA-C TROJAN!No
SysctrlsXmscntrl.exeAdded by the KOLABC.BB WORM!No
MscolourXmscolour.exeAdded by the GEMA TROJAN!No
MSCoolServXmscolsrv.exeAdded by the RAHACK WORM!No
sysserXmscolsrv.exeAdded by the RAHACK WORM!No
Intec Service DriversXmscom.exeAdded by the RBOT.FUA BACKDOOR!No
COM ServiceXmscom32.comDetected by Symantec as Backdoor.Beasty.C and by Malwarebytes Anti-Malware as Backdoor.BeastDoorNo
Windows Dcom2 FixXmscom32.exeAdded by the RBOT-QT WORM!No
MicroSoftRunXMSCOMM.dllAdded by the AGENT-DJG TROJAN!No
MScommXMScomm.exeDetected by Dr.Web as Trojan.MulDrop3.27767. The file is located in %Temp%No
MScommXMScomm.exeDetected by Sophos as Troj/VBInjec-AL. The file is located in %AppData%No
System Efficiency MonitorXmscommand.exeDetected by Symantec as W32.Kwbot.P.WormNo
MSCommXXmscommx.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
Microsoft DLL VerifierXmscon.exeAdded by the SDBOT.EAH WORM!No
MSN UpdateXmscon.exeAdded by the RBOT-QA WORM!No
Microsoft ConfigXmsconf.exeDetected by Sophos as W32/Rbot-LGNo
Microsoft Configuration UtilityXmsconf.exeAdded by the RBOT-AFX WORM!No
msconfig.Xmsconf.exeAdded by the BUZUS-AY WORM!No
Microsoft Config LoaderXmsconf32.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
Msconf32XMsconf32.exeAdded by the AGOBOT-NR WORM!No
Microsoft UpdateXmsconfg.exeDetected by Total Defense as Win32.Rbot.HNo
MsconfgXmsconfg.exeDetected by McAfee as PWS-Zbot.gen.aru and by Malwarebytes Anti-Malware as Trojan.AgentNo
MSCONFG32.EXEXMSCONFG32.EXEAdded by the OPTIX.04.C TROJAN!No
Win32 Cnfg32Xmsconfgh.exeAdded by the MYTOB.NB WORM!No
msconfigXmsconfig.batAdded by the PAHATIA.B WORM!No
msconfigXmsconfig.comAdded by the IRCBOT-SM WORM!No
Microsoft Java Virtual MachineXMsConfiG.exeAdded by the FORBOT-DV WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebootingNo
Microsoft System Configuration UtilityNmsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)Yes
msconfigXmsconfig.exeAdded by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrunNo
msconfigXmsconfig.exeCoolWebSearch MSConfig parasite variant. Note - this overwrites the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebootingNo
msconfigXmsconfig.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in %AppData%No
msconfigXmsconfig.exeDetected by Sophos as Troj/Agent-UDF and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in %AppData%\Microsoft\System\ServicesNo
MSConfigNmsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)Yes
Msconfig lptt01Xmsconfig.exeRapidBlaster variant (in a "msconfig" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not the valid Windows Msconfig which has the same executable nameNo
Msconfig ml097eXmsconfig.exeRapidBlaster variant (in a "msconfig" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not the valid Windows Msconfig which has the same executable nameNo
MSConfigReminderNmsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. This particular entry is specific only to 98/Me and is located in %System%Yes
msdevXmsconfig.exeAdded by the AGOBOT.AAU WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebootingNo
Windows ExplorerXmsconfig.exeDetected by McAfee as Generic.bfr!gw and by Malwarebytes Anti-Malware as Trojan.MSILNo
WindowsUpdateXmsconfig.exeDetected by Dr.Web as BackDoor.IRC.Bot.1436 and by Malwarebytes Anti-Malware as Backdoor.IRCBot.Gen. Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in %AppData%No
winrunXmsconfig.exeAdded by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrunNo
Intel Service DriversXmsconfig16.exeDetected by Trend Micro as WORM_SDBOT.COUNo
Windows ServicesXmsconfig23.exeDetected by Sophos as Troj/Mdrop-DOX and by Malwarebytes Anti-Malware as Backdoor.Agent.GenNo
Compaq32 Service DriversXmsconfig32.exeAdded by the SDBOT-ADC WORM!No
Microsoft Config LoaderXmsconfig32.exeDetected by Trend Micro as WORM_AGOBOT.XXNo
Microsoft ConfigurationXmsconfig32.exeAdded by the SDBOT.MQ WORM!No
MS Configuration UtilityXmsconfig32.exeAdded by the WOOTBOT.DY WORM!No
MSConfigXMSCONFIG32.EXEAdded by the SPYBOT.B WORM!No
msconfig32Xmsconfig32.exeDetected by Dr.Web as Trojan.DownLoader7.2124. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
MS-patchXmsconfig32.exeDetected by Sophos as W32/Rbot-AUF and by Malwarebytes Anti-Malware as Backdoor.BotNo
Windows UpdateXmsconfig32.exeDetected by Symantec as W32.Spybot.Worm and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
Intec Service DriversXmsconfig32x.exeAdded by the RBOT-BCR WORM!No
MSConfigXMSCONFIG35.EXEAdded by a variant of the SPYBOT WORM!No
MSConfig45XMSConfig45.exeAdded by the SDBOT.OJ BACKDOOR!No
Microsoft Configoration ServiceXmsconfigs.exeAdded by the RBOT-ETT WORM!No
MsConfigsXMsConfigs.exeDetected by Trend Micro as WORM_ALCAN.ANo
Ms configsuXmsconfigsu.exeAdded by a variant of W32/Sdbot.wormNo
Win32 SecureXmsconfigsvc.exeAdded by a variant of W32/Sdbot.wormNo
Microsoft ConfigueweXmsconfiguwe.exeAdded by the SDBOT-BPK WORM!No
Microsoft Config 32Xmsconfigx32.exeDetected as SUPERAntiSpyware as Trojan.MSConfigX32.Process. The file is located in %System%No
Video ProcessorXmsconfsys88.exeAdded by the AGOBOT-QG WORM!No
Microsoft UpdaterXmsconsole.exeAdded by the SDBOT.CPJ WORM!No
Microsoft Windows Operating SystemXmscormmc.exeDetected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Trojan.AgentNo
Microsoft® Windows® Operating SystemXmscormmc.exeDetected by Dr.Web as Trojan.MulDrop4.5957 and by Malwarebytes Anti-Malware as Backdoor.MessaNo
[user]NV12K12Xmscorsvw.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.Gen. The file is located in %AppData%\Microsoft\[user]No
msmcXmscpbo.exeClientMan parasite variantNo
48bfd39c0aaf53d0529f3598b1d721f1Xmscpf.exeDetected by Dr.Web as Trojan.DownLoader7.23010 and by Malwarebytes Anti-Malware as Spyware.PasswordNo
MscsgsXMSCSGS.EXEAdded by the ZEZER WORM!No
Mscsgs32XMSCSGS32.EXEAdded by the ZEZER WORM!No
CashToolbarXMSCStat.exeDetected by McAfee as Downloader-MYNo
mscsvc.exeXmscsvc.exeAdded by the BANCOS.T TROJAN!No
msctfg32Xmsctfg32.exeAdded by the RBOT-TJ WORM!No
Activex Application UpdaterXMsCtfMonitor.exeDetected by Dr.Web as Trojan.AVKill.25231 and by Malwarebytes Anti-Malware as Trojan.AgentNo
msctrl.exeXmsctrl.exeMicrosoft Security Adviser rogue security software - not recommendedNo
Msctrl32XMsctrl32.scrAdded by the REDIST WORM!No
artcomXmsctupd.exeDetected by SUPERAntiSpyware as Trojan.artcom.Process and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System%No
System MScvbXmscvb32.exeAdded by the SOBIG.C WORM!No
mscvrdll1Xmscvrdll1.exeDetected by McAfee as BackDoor-EDP and by Malwarebytes Anti-Malware as Backdoor.AgentNo
Microsoft CvrtXmscvrt32.exeAdded by an unidentified VIRUS, WORM or TROJAN!No
Generic Host Process for Win ServicesXmscvs.exeAdded by a variant of the SDBOT BACKDOOR!No
MSCVTXMSCVT.exeAdded by the SLIDESHOW WORM!No
DiskCheckXmsdarkend.exeAdded by an unidentified WORM or TROJAN!No
Testing 123Xmsdata.datAdded by the NITS.A WORM!No
Microsoft Datalog ApplicationXmsdata.exeDetected by Trend Micro as WORM_SPYBOT.AIZNo
MS DATABASEXMSDATA32.EXEAdded by a variant of W32/Sdbot.wormNo
MS windows Data list processXMSDATLST.exeAdded by an unidentified WORM or TROJAN!No
Windows DebuggerXmsdbg32.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
msdbgm.exeXmsdbgm.exeAdded by the CIMUZ-CQ TROJAN!No
USBHWDRVXmsdc.exeAdded by a variant of the LOWZONE-I TROJAN!No
ZebusNmsdc32.exeRuns a HTML tutorial on the Zebus web-siteNo
MSDcomXMSDcom.exeAdded by a variant of W32/Sdbot.wormNo
MS ConfigXmsdconfig.exeAdded by the RBOT-CZH WORM!No
adobeflashXmsdcsc.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\MSDCSCNo
cmdXmsdcsc.exeDetected by McAfee as RDN/Generic BackDoor!p and by Malwarebytes Anti-Malware as Trojan.BackdoorNo
Divx UpdateXmsdcsc.exeDetected by McAfee as Generic BackDoor!fd3 and by Malwarebytes Anti-Malware as Backdoor.Agent.DCGenNo
M6D86X7Xmsdcsc.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %Root%\MSDCSCNo
Microsoft UpdateXmsdcsc.exeDetected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %System%\MSDVCKCNo
MicrosoftUpdateXmsdcsc.exeDetected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %Windir%\MSDCSCNo
MicrosoftUpdateXmsdcsc.exeDetected by McAfee as Generic BackDoor!1br and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %System%\MSDCSCNo
MicrosoftUpdateXmsdcsc.exeDetected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\MSDCSCNo
MicrosoftUpdateXmsdcsc.exeDetected by McAfee as Generic.bfr!ef and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %Root%\MSDCSCNo
MicroUpdateXmsdcsc.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is found in a "MSDCSC" sub-folder in a number of locations including (but not limited to) %System%, %MyDocuments%, %Temp% & %AppData%No
MScommXmsdcsc.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\MSDCSCNo
msdcscXmsdcsc.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.Gen. The file is located in %MyDocuments%\MSDCSCNo
msdcsc.exeXmsdcsc.exeDetected by Dr.Web as Trojan.DownLoader6.34013 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\MSDCSCNo
msdcsc.exeXmsdcsc.exeDetected by Dr.Web as Trojan.DownLoader7.15496 and by Malwarebytes Anti-Malware as Backdoor.Agent.DCGen. The file is located in %Temp%\MSDCSCNo
rundll32Xmsdcsc.exeDetected by Dr.Web as Trojan.DownLoader7.15496 and by Malwarebytes Anti-Malware as Backdoor.Agent.DCGen. The file is located in %Temp%\MSDCSCNo
rundll32Xmsdcsc.exeDetected by Kaspersky as Backdoor.Win32.DarkKomet.eku and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\MSDCSCNo
rundll32Xmsdcsc.exeDetected by Trend Micro as TROJ_DELF.IKU and by Malwarebytes Anti-Malware as Backdoor.Agent.DCGen. The file is located in %System%\MSDCSCNo
rundll32.exeXmsdcsc.exeDetected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %AppData%\MSDCSCNo
sanaXmsdcsc.exeDetected by Malwarebytes Anti-Malware as Trojan.Clicker. The file is located in %System%\sanaNo
softXmsdcsc.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DCGen. The file is located in %UserTemp%\MSDCSCNo
startupXmsdcsc.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\MSDCSCNo
svchostXmsdcsc.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DCGen. The file is located in %AllUsersStartup%\MSDCSCNo
svchost.exeXmsdcsc.exeDetected by Dr.Web as Trojan.MulDrop3.55869 and by Malwarebytes Anti-Malware as Backdoor.Agent.DCGen. The file is located in %System%\MSDCSCNo
svchost.exeXmsdcsc.exeDetected by Dr.Web as Trojan.DownLoader6.46301 and by Malwarebytes Anti-Malware as Backdoor.Agent.DCGen. The file is located in %MyDocuments%\MSDCSCNo
SystemXmsdcsc.exeDetected by Dr.Web as Trojan.DownLoader8.20945 and by Malwarebytes Anti-Malware as Trojan.AgentNo
WinDefenderXmsdcsc.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData%\MSDCSCNo
WinDefenderXmsdcsc.exeDetected by Dr.Web as Trojan.DownLoader7.10694 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\MSDCSCNo
WinDefenderXmsdcsc.exeDetected by McAfee as Generic Backdoor and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %Temp%\MSDCSCNo
Windows DefenderXmsdcsc.exeDetected by Dr.Web as Trojan.MulDrop3.60276 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData%\MSDCSCNo
Windows UpdateXmsdcsc.exeDetected by McAfee as RDN/Generic BackDoor and by Malwarebytes Anti-Malware as Trojan.AgentNo
windowsupdateXmsdcsc.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot.Gen. The file is located in %System%\MSDCSCNo
windowsupdateXmsdcsc.exeDetected by McAfee as Generic.dx!bdt4 and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
MicrosoftUpdateXmsdcscshk.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Trojan.AgentNo
MicroUpdateXmsdcscx.exeDetected by McAfee as Generic BackDoor!fql and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
MicroUpdateXmsdcvssc.exeDetected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %Root%\MSDCSCNo
Microsoft Driver SetupXmsddrv42.exeAdded by the PALEVO WORM!No
UNKRIURXmsdeer.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\FDrwdCNo
msdefenderXmsdefender.exeIdentified as a variant of the PAKES.CMD TROJAN! See here for an exampleNo
msdefender.exeXmsdefender.exeAdded by the PAKES.ZL TROJAN!No
RPCserv32gXMSDEFR.EXEDetected by Trend Micro as WORM_BOBAX.ADNo
Microsoft Desktop ManagerXmsdesk32.exeAdded by a variant of Win32/RbotNo
Microsoft Development DebuggerXmsdev.exeAdded by a variant of Win32/RbotNo
msdevXmsdev.exeAdded by the FORBOT-CR WORM!No
msvsc32Xmsdev.exeAdded by the RBOT-GJ WORM!No
Sygate Personal Firewall StartupXmsdev.exeAdded by the RBOT-QY WORM!No
WINDOWS SYSTEMXmsdev32.exeAdded by the MYTOB.EH WORM!No
msdev controlXmsdevctrl.exeAdded by the SPYBOT.N BACKDOOR!No
Microsoft Development ServicesXmsdevelop.exeAdded by the RBOT-FWS WORM!No
Microsoft Device ManagerXmsdevmgr32.exeDetected by Symantec as Backdoor.Lateda.BNo
Windows UpdateXMSDEVS30.exeDetected by Sophos as W32/Sdbot-DGG and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
Microsoft HDCP for NTXmsdhcp.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
Microsoft HDCP for NT and Win9xXmsdhcprs.exeAdded by a variant of the PEERBOT WORM!No
Microsoft DiagnosticXmsdiag.exeAdded by the RBOT-RV WORM!No
Microsoft DiagnosticXmsdiag32.exeAdded by the RBOT-UC WORM!No
msdir32Xmsdir32.batAdded by the ROOKIE-A TROJAN!No
msdirect.exeXmsdirect.exeAdded by the CERTIF-L TROJAN!No
msdirectx32Xmsdirectx32.exeAdded by the RBOT.AT BACKDOOR!No
*BandookXmsdll.exeAdded by unidentified malware. The file is located in %System%No
angeleyesXmsdll.exeDetected by Kaspersky as Trojan-Downloader.Win32.VB.pi. The file is located in %ProgramFiles%\iSOadNo
BandookXmsdll.exeAdded by unidentified malware. The file is located in %System%No
HKCUXmsdll.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\InstallDirNo
HKLMXmsdll.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\InstallDirNo
Microsoft RedirectXmsdll.exeDetected by Kaspersky as Trojan-Banker.Win32.Banker.agh. The file is located in %System%No
Media Plug x.1.2Xmsdm.exeAdded by the MULDROP.352 VIRUS!No
VnCplUpdateXmsdm.exeMasssend - spam relayer. Listens on a port for the spammers to feed it a list of addresses and what to send out. More information in this advisoryNo
MsdmxmXmsdmxm.exeAdded by the DLUCA-DC TROJAN!No
MSDN for Windows with NT'sXmsdn-nt.exeAdded by the RBOT-EWD WORM!No
Machine Debug ManagerXmsdn.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
MSDN for Windows NTXmsdn.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
MSDN HELPXmsdn.exeDetected by Trend Micro as WORM_AGOBOT.AIBNo
msdn.exeXmsdn.exeDetected by Dr.Web as Trojan.DownLoader6.43365 and by Malwarebytes Anti-Malware as Trojan.Agent.MSD. The file is located in %System%No
msdn.exeXmsdn.exeDetected by Sophos as Troj/Agent-RZW. The file is located in %UserTemp%No
Windows System GuardXmsdn.exeAdded by the FAKEAV-BJD TROJAN!No
Microsoft DNS QueryXmsdns.exeAdded by the AGENT-BS TROJAN!No
MS Domain Name Server DeamonXMSDNSD32.exeAdded by the RBOT-CMZ WORM!No
MSDN for Windows NT & Windows XPXmsdnxp.exeDetected by Trend Micro as WORM_IRCBOT.JVNo
MSDN for Windows NT & WinXPXmsdnxp.exeDetected by Sophos as W32/IRCBot-PENo
System Document ApplicationXmsdocument.exeAdded by the RANDEX.COX WORM!No
MsSystemXmsdos.exeAdult content downloader - see hereNo
MSDOS Security ServiceXmsdos.pifAdded by the RBOT-AMP WORM!No
MSDOS ServiceXMSDOS.PIFAdded by the RBOT-AIY WORM!No
MSDOS Windows ServiceXMSDOS.PIFAdded by the RBOT-AKF WORM!No
[various names]Xmsdos32.exeAdded by a variant of the AGENT.AH TROJAN!No
Microsoft WIN32 DOSXMSdos32.exeAdded by a variant of W32/Sdbot.wormNo
Msdos32XMsdos32.pifAdded by the RECORY WORM!No
msdos423Xmsdos423.exeDetected by Trend Micro as WORM_MENACE.ANo
WindowsXmsdos98.exeAdded by the PWSTEAL TROJAN!No
MSDosdrvXmsdosdrv.exeAdded by the BACROS WORM!No
Windows DotFix liveXmsdotfix.exeAdded by the IRCBOT.XGK BACKDOOR!No
MicroUpdateXmsdr.exeDetected by McAfee as FakeAlert-SysDef.an and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData%\MSDCSCNo
COM ServiceXmsdrce.comDetected by Symantec as Backdoor.Beasty.I and by Malwarebytes Anti-Malware as Backdoor.BeastDoorNo
WintlXmsdred.exeIdentified as a variant of the Trojan-Spy.Win32.Agent.cch malwareNo
Micrsoft DriverXmsdriver.exeAdded by the SDBOT-XD WORM!No
msdriversXmsdrivers.exeDetected by McAfee as Generic.tfr and by Malwarebytes Anti-Malware as Trojan.VbkryptNo
Ms Sound DriversXmsdrv.exeAdded by the SDBOT-WR WORM!No
MSysDrvXmsdrv.exeAdded by the VB.WF TROJAN!No
msdrvctrlXmsdrvctrl.exeAdded by the VIDCACH-A TROJAN!No
MS DirectX Sound DriversXmsdrvdx.exeDetected by Trend Micro as WORM_RBOT.BCXNo
MS DVD DirectX Sound DriversXmsdrvdx.exeAdded by the SDBOT-XJ WORM!No
Windows Driver ServicesXmsdrvs32.exeAdded by the WOOTBOT.L WORM!No
HKLMXmsdsccc.exeDetected by Malwarebytes Anti-Malware as Trojan.VBAgent. The file is located in %Root%\swsetup\nvidia\UpdateNo
msdscccXmsdsccc.exeDetected by Malwarebytes Anti-Malware as Trojan.VBAgent. The file is located in %Root%\swsetup\nvidia\UpdateNo
PoliciesXmsdsccc.exeDetected by Malwarebytes Anti-Malware as Trojan.VBAgent. The file is located in %Root%\swsetup\nvidia\UpdateNo
MicroUpdateXmsdscsc.exeDetected by McAfee as Generic.bfr!dq and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\MSDCSCNo
Windows AutomationXmsdspr.exeAdded by the SOLAME.A WORM!No
Norton Drive ProtectionXmsdt32.exeAdded by the FORBOT-GB WORM! Note - this not a valid Norton program!No
ccrssXmsdtc.exeAdded by the STAP-C WORM!No
MSDTCNmsdtc.exeMS Distributed Transaction Coordinator - handles transactions across multiple servers and is installed by MS Personal Web Server and MS SQL ServerNo
MstaskXMSDTC.exeAdded by the STAP-D WORM!No
rundll32XMSDTC.exeAdded by the STAP-E WORM!No
SysCheckXmsdtc.exeAdded by the SYGINRE TROJAN!No
IECheckXMSDTCs.exeAdded by the TIRBOT-D WORM!No
Microsoft® Windows® Operating SystemXmsdtcstp.exeDetected by Malwarebytes Anti-Malware as Backdoor.Messa. The file is located in %Templates%No
Media ServerXmsdts.exeAdded by the SLENFBOT.KX WORM!No
msdtsXmsdts.exeDataDoctor spywareNo
msduanxw.comXmsduanxw.comDetected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %AllUsersProfile%\Local Settings\TempNo
30367Xmsdubmnax.pifDetected by Sophos as Troj/Bredo-VV and by Malwarebytes Anti-Malware as Trojan.AgentNo
65429Xmsdubmnax.pifDetected by Trend Micro as TROJ_KRYPTIK.AE and by Malwarebytes Anti-Malware as Trojan.AgentNo
MSNS PLUS XP2Xmsdupd.exeAdded by the RBOT-BCE WORM!No
Microsoft DVCXMSdvc32.exeAdded by the SDBOT.LF BACKDOOR!No
SoundViewXmsdview32.exeDetected by Kaspersky as Trojan-Downloader.Win32.Small.actNo
Micr0s0ft Ms D0sXmsdx.exeAdded by the RBOT-AON WORM!No
MsearchXMSearch.exeDetected by Malwarebytes Anti-Malware as Adware.Kraddare. The file is located in %ProgramFiles%\MsearchNo
MICROSFT RAMA UPDATE SUPPORTXMSED32.EXEAdded by the RBOT-AWR WORM!No
System Efficiency MonitorXmsedit32.exeAdded by the STEPH-B WORM!No
msiewXmseiw.exeAdded by the LITTLOG TROJAN!No
Ms Java Update For Windows NT/XPXmsejavaupdt32.exeAdded by the RBOT-FML BACKDOOR!No
COM ServiceXmsemiu.comDetected by McAfee as BackDoor-AMQ and by Malwarebytes Anti-Malware as Backdoor.BeastDoorNo
Msemu32XMsemu32.exeUnidentified spyware/adware/hijackerNo
blahh serviceXmsengine.exeAdded by the WOOTBOT.DZ WORM!No
Multimedia extensionsXmservice.exeEasySearch adwareNo
Multimedia extensionsXmservice1.exeAdded by the DLOADR-AWD TROJAN!No
mservices.exeXmservices.exeAdded by the SDBOT.WJ WORM!No
USB UpdatesXmservices.exeDetected by Trend Micro as WORM_RBOT.BHNNo
Configuration LoaderXmservs.exeAdded by the SDBOT-NM WORM!No
Microsoft Security EssentialsXMsEss.exeAdded by the FAKEAV-EEL TROJAN!No
Microsoft EV32 ServiceXMSev32.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
mswkork ServiceXmsework.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
Microsoft ExcelXmsexcel.exeAdded by the RBOT-TQ WORM!No
JjzhpXmsexcl40C.exeDetected by Malwarebytes Anti-Malware as Adware.SanctionedMedia. The file is located in %System%No
MS Windows Executor ProcessXMSEXECP32.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
Microsoft Explorer ServiceXmsexplore.exeAdded by the IRCBOT.AYB BACKDOOR!No
MsnExplorerXMsexploren.exeDetected by Sophos as Troj/Bdoor-EBNo
ScheduIrXmsexploren.exeAdded by a variant of Troj/Bdoor-EBNo
SheduIerXmsexploren.exeDetected by Sophos as Troj/Bdoor-EBNo
SvcH0stXMsexploren.exeDetected by Sophos as Troj/Bdoor-EBNo
WinAmpAgentXMsexploren.exeDetected by Sophos as Troj/Bdoor-EBNo
Microsoft AOL Instant MessengerXMSEXPORT.exeAdded by a variant of the W32/Rbot-AAINo
26639Xmsezfr.exeDetected by Dr.Web as Trojan.KillProc.22324 and by Malwarebytes Anti-Malware as Trojan.AgentNo
MicroUpdateXmsfe.exeDetected by Dr.Web as Trojan.DownLoader5.63037 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %System%No
Microsoft Decryption TechnologyXMsfenoe.exeAdded by the SPYBOT-DG WORM!No
MsfindXMsfind.exeCoolWebSearch parasite variantNo
MSFind32Xmsfind32.exeAdded by the CAYAM WORM!No
file indexing service?msfindfile.exeNew version of MS FindFast and still a resource hog?No
msfindosa.exeXmsfindosa.exeDetected by McAfee as Downloader-BSNo
MsServerXmsfir80.exeAdded by the VB-CYJ TROJAN!No
MSLogXmsfirelog.exeDetected by Total Defense as Win32/Slinbot.AHCNo
USBDrivesXmsfirewalI.exeAdded by the RBOT-ABP WORM!No
Microsoft Personal FirewallXMsFirewall.exeDetected by Sophos as W32/SillyFD-KNo
MS FIREWALLXmsfirewall.exeDetected by Sophos as W32/Sdbot-QHNo
network device driverXmsfirewall.exeDetected by Sophos as Troj/Delf-LBNo
USB UpdatesXmsfirewalls.exeAdded by a variant of Win32/RbotNo
COM ServiceXmsfkow.comDetected by Malwarebytes Anti-Malware as Backdoor.Beastdoor. The file is located in %Windir%\msagentNo
COM ServiceXmsflyx.comDetected by Sophos as Troj/BeastDo-O and by Malwarebytes Anti-Malware as Backdoor.BeastDoorNo
ethernetXmsfpc.exeAdded by the RBOT.DFU WORM!No
Win32 FRT DriverXmsfr32.exeDetected by Trend Micro as WORM_WOOTBOT.EJNo
ExplorerXmsfragger.exeDetected by Malwarebytes Anti-Malware as Trojan.BCMiner. The file is located in %AppData%No
MS ConfigurationXMSFramer.exeAdded by the RANDEX.OL WORM!No
msframeworkcheckerXmsframeworkchecker.exeDetected by McAfee as Generic.tfr!cr and by Malwarebytes Anti-Malware as Trojan.Clicker.GenNo
MS FIREWALLXmsfrewall.exeAdded by the SDBOT-PU WORM!No
Microsoft Kinetik SvcXmsftksvc.exeAdded by the AGENT.AGDO TROJAN!No
ethernetXmsftp.exeAdded by the SDBOT.BXJ WORM!No
MsServerXmsfun80.exeAdded by the VB-CYG WORM!No
Microsoft Firewall 2.9XMSFW.exeAdded by the VBINJECT.IP VIRUS!No
msfw.exeXmsfw.exeMicrosoft Security Adviser rogue security software - not recommendedNo
Windows Firewall ManagerXmsfw.exeAdded by the RBOT.WR WORM!No
NAV Auto ProtectXmsfwe1.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
COM ServiceXmsfwoq.comDetected by McAfee as BackDoor-AMQ and by Malwarebytes Anti-Malware as Backdoor.BeastDoorNo
Configuration LoaderXmsg.exeAdded by the SDBOT.BT WORM!No
EW Message ServerUmsg32.exeConexant (older versions are Brooktree) Wavestream Message Server - associated with Conexant based audio devicesNo
Microsoft Gaming Update 32Xmsgame32.exeDetected by Trend Micro as WORM_RBOT.BTWNo
Microsoft Gaming Updater 32Xmsgame32.exeDetected by Avira as Worm/RBot.90102No
Microsoft Windows Game UpdaterXmsgame32.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
browserXmsgaol.exeAdded by the TACTSLAY.C TROJAN!No
cplXmsgaol.exeAdded by the TACTSLAY.C TROJAN!No
httpdXmsgaol.exeAdded by the TACTSLAY.C TROJAN!No
MessangerXmsgaol.exeAdded by the TACTSLAY.C TROJAN!No
StartMenuXmsgaol.exeAdded by the TACTSLAY.C TROJAN!No
msgateXmsgate.exeAdded by the SDBOT-OK WORM!No
msgb1Xmsgb1.exeAdded by the DLUCA.GEN TROJAN!No
RealPlayer2NMsgCenterExeRealNetworks RealPlayer related - disabling this application will not affect Real Player in any wayNo
Configuration LoaderXmsgcfgsrv.exeAdded by a variant of the AGOBOT WORM!No
Microsoft Configure 32Xmsgconfigre.exeAdded by a variant of the AGOBOT WORM!No
Microsoft Configs 32Xmsgconfigrs.exeDetected by Trend Micro as WORM_RBOT.DRLNo
msmcXmsgdmf.exeClientMan parasite variantNo
Genuine Windows MonitorXmsgenuine.exeDetected by Kaspersky as Trojan.Win32.Diple.ium and by Malwarebytes Anti-Malware as Trojan.AgentNo
msgex32Xmsgex32.exeAdded by the APPFLET-A WORM!No
ActiveX StreamerXmsgfix.exeAdded by the SDBOT.NQ WORM!No
Configuration LoaderXmsgfix.exeAdded by the GAOBOT.AUS or SDBOT.J or SDBOT-QG WORMS!No
RPC DCOM Vulnerability PatchXmsgfix.exeAdded by the RBOT.S WORM!No
Windows Configuration LoaderXmsgfix.exeAdded by the SDBOT-NP WORM!No
change-me-nowXmsgfix1.exeAdded by the SDBOT.ZD WORM!No
Msg FixageXmsgfixed.exeDetected by Trend Micro as WORM_SDBOT.ZDNo
ConfigurationXmsgfixs.exeAdded by the SDBOT-NN WORM!No
Configuration LoaderXmsgfixy.exeAdded by the SLINBOT.QW BACKDOOR!No
Microsoft Gina V EncryptionXMSGINAV.EXEAdded by an unidentified VIRUS, WORM or TROJAN!No
WM_LOGIN?MSGLOGIN.EXEPart of McAfee Firewall. What is it for and is it needed?No
Win TaskLoaderXmsgmr.exeAdded by the MYTOB.L WORM!No
Microsoft UpdateXmsgn.exeAdded by the RBOT.RQ BACKDOOR!No
Windows Live MessagesXmsgnlive.exeAdded by the AGENT.AYH WORM!No
Windows LiveXmsgnms.exeAdded by the XPACK.AV TROJAN!No
MSREGITXMsgp.exeAdded by the KRYPGHOS.13 BACKDOOR!No
CLSIDXmsgplus.exeOnlineDirect - Switch dialer and hijacker variant, see hereNo
MessengerPlusNMsgPlus.exeOlder version of MessengerPlus - the third party Windows Live Messenger (was MSN Messenger) extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"!No
MessengerPlus2NMsgPlus.exeOlder version of MessengerPlus - the third party Windows Live Messenger (was MSN Messenger) extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"!No
MessengerPlus3NMsgPlus.exeOlder version of MessengerPlus - the third party Windows Live Messenger (was MSN Messenger) extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"!No
Microsoft MSGPLUS32 ProtocolXmsgplus32.exeAdded by a variant of the SPYBOT WORM!No
CheckMsgPlusYMsgPlusH.dll,VerifyInstallationAdded by MSN Messenger Plus, a third party extension to MSN Messenger. This is the auto-update feature - see here for more info.No
MSN MessangerXmsgr.exeAdded by the DWNLDR-IWI TROJAN!No
Messenger start-upXMsgran.exeAdded by the GRAMOS WORM!No
Windows Live Messenger ServicesXmsgrlive.exeAdded by the SLENFBOT.DT WORM!No
Windows Live Messenger!Xmsgrlive.exeAdded by a variant of the IRCBOT TROJAN! See hereNo
Windows Live MessengerXmsgrmsn.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the legitimate Windows Live Messenger filename is "msnmsgr.exe" and this file is located in %AppData%No
svshost32Xmsgrsv32.exeAdded by the RANKY.AJ TROJAN!No
WinCSRSSXMSGRT32.EXEAdded by the REWINDO-A TROJAN!No
MsgrUpdXMsgrUpd.exeAdded by the MDROP-CXY TROJAN!No
SynNglpXMsgrUpd.exeAdded by the BANKER-EZM TROJAN!No
msgsinitXmsgs.exeDetected by Dr.Web as Trojan.DownLoader7.15349 and by Malwarebytes Anti-Malware as Trojan.AgentNo
Windows Service ManagerXmsgs.exeAdded by the OSCABOT-E WORM!No
editmsgsXmsgsedit.exeAdded by the RBOT.ABE WORM!No
msgsm32Xmsgsm32.exeAdded by the RBOT-ASG WORM!No
loadXmsgsr32.exeAdded by the SDBOT-QR WORM!No
Msgsrv16XMsgsrv16.exeAdded by the DELF family of TROJANS!No
Service386ShellXmsgsrv16.exeDetected by Symantec as Backdoor.Revrs and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
InternatXmsgsrv32.exeDetected by Sophos as Troj/Nyrubot-ANo
LTM2XMSGSRV32.EXEDetected by Trend Micro as BKDR_LITMUS.ANo
Msgsrv32XMSGSRV32.EXEDetected by Dr.Web as Trojan.Siggen4.9883 and by Malwarebytes Anti-Malware as Trojan.VloggerNo
MSGSRV32.exeYmsgsrv32.exeWindows 32-bit VxD Message Server. For more information on its function and why it's needed, see here. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the backgroundNo
LTM2XMSGSRV320.EXEDetected by Kaspersky as Backdoor.Win32.Litmus.203No
LTM2XMSGSSV32.EXEAdded by the FC.C TROJAN!No
msgsvr32Xmsgsvr32.exeAdded by the DEADHAT.B WORM! Note - this is not the legitimate msgsvr32.exe process on a Win9x/Me system which should not appear in MSConfig/startup!No
MSGTAGUMSGTAG.exeMSGTAG is an application that tells you when your emails have been received and openedNo
MsgTranAgt?MsgTranAgt.exeRelated to the hotkeys on an ASUS Notebook. What does it do and is it required?No
Windows firewall managerXmsguard.exeAdded by a variant of the RANDEX.GEL WORM!No
MICROSFT RAMA UPDATE SUPPORTXMSGUPDAT32.EXEAdded by the RBOT-BBB WORM!No
MICROSFT ANTIVIRUS UPDATE SUPPORTXMSGUPDATED.EXEAdded by the RBOT-APZ WORM!No
Loader msgzlXmsgzl.exeAdded by the SDBOT.BVF WORM!No
Generic Host Process for WinXP ServicesXmshelp.exeDetected by Sophos as Troj/Agent-GQPNo
Microsoft Help SupportXmshelp32.exeAdded by the KELVIR-BF WORM!No
Microsoft Help SystemXmshelp32.exeCoolWebSearch parasite variantNo
Mshelp32Xmshelp32.exeCoolWebSearch parasite variantNo
Microsoft Helpdesk SideXmshelpdsk.exeAdded by the SPYBOT.ANJJ WORM!No
MSHLPXmshelper_a7.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. Note - this is not a legitimate Windows Media Player file - although it is located in %ProgramFiles%\Windows Media PlayerNo
COM ServiceXmshiwq.comDetected by Microsoft as Backdoor:Win32/Beastdoor.L and by Malwarebytes Anti-Malware as Backdoor.BeastDoorNo
mshmailXmshmail.exeAdded by the INJECT.JDT TROJAN!No
Hardware Monitor ServiceXmshms.exeAdded by the WOLLF-A TROJAN!No
Microsoft driver updateXMshome.exeAdded by the SDBOT.BL WORM!No
Microsoft ClientXmshost.exeAdded by the RBOT-AND WORM!No
ServicesXmshost.exeAdded by the LANFILT-J TROJAN!No
Microsoft Windows HostXmshosts.exeAdded by the SDBOT.AKT WORM!No
MshostsXMshosts.exeAdded by the STARTPAG.CF TROJAN!No
sconfigXmshosts.exeAdded by the BIFROSE.LA BACKDOOR!No
Microsoft Security Hot Fix UpdateXmshotfix.exeAffilred adwareNo
microsoft hotmail monitorXmshotmon.exeAdded by the MYTOB-FL WORM!No
MSHT@XMSHT@.EXEAdded by the MAGISTR.A VIRUS!No
Windows UpdateXmshta.exeDetected by Dr.Web as Trojan.DownLoader6.50217 and by Malwarebytes Anti-Malware as Trojan.AgentNo
SystemBootXMshta.exe ...filename.htaAdult content diallerNo
tcainitXmshtca.exeDetected by Dr.Web as BackDoor.IRC.Mishko.51 and by Malwarebytes Anti-Malware as Trojan.BackdoorNo
Microsoft Hyptertext HelperXmshtha.exeAdded by a variant of the SPYBOT WORM!No
MSAgentXmshtm.exeBrowser hijacker - redirecting to buldog-search.comNo
UpdateXmshtm.exeBrowser hijacker - redirecting to buldog-search.comNo
MS HTMLXmsHtml.exeAdded by the PESTDOOR.31 BACKDOOR!No
MS HTML Location ClassXMSHTML32.exeAdded by the RBOT-YD WORM!No
mshtmllXmshtmll.dllAdded by the DELF.BAS TROJAN!No
mshytmid.exeXmshytmid.exeDetected by McAfee as Generic.tfr and by Malwarebytes Anti-Malware as Spyware.BankerNo
Microsoft Software InstallerXMSI.exeAdded by the SCAR.BXOX TROJAN!No
msi.exeXmsi.exeAdded by the BANCBAN-CT TROJAN!No
Windows UpdateXmsi.exeDetected by Sophos as Troj/Banker-XB and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
Ms Java for Windows NTXmsi32info.exeDetected by Trend Micro as WORM_RBOT.AFXNo
Ms Java for Windows NTXmsi32java.exeAdded by the VANEBOT-I WORM!No
WindowsRegKey%$ updateXmsi332.exeAdded by the RBOT-IX WORM!No
ICManagementXmsic32.exeAdded by the MSIC BACKDOOR!No
Windows Config ConnectionXmsicll.exeAdded by the RBOT-EXQ WORM!No
MSI ConfigurationXmsiconf.exeAdded by the AGENT.AKSZ TROJAN!No
msiconf.exeXmsiconf.exeAdded by a variant of the FAKEALERT TROJAN!No
MS Security Update 993Xmsident.exeAdded by a variant of W32/Sdbot.wormNo
msidleXmsidle.exeAdded by the OPASERV-O WORM!No
MsIdle32.exeXMsIdle32.exeAdded by the VERIFY TROJAN!No
dxdiag diagnoseXmsidxdia.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
Microsoft Ansti UpdateXmsie.exeAdded by the RBOT-LE WORM!No
Microsoft FeaturesXmsie.exeAdded by the RBOT.GI WORM!No
Microsoft upnp UpdateXmsie.exeAdded by the RBOT-LQ WORM!No
MSIE ParsersXMSIE32ab.exeAdded by the SDBOT.MV WORM!No
IEXPLORERXmsiecfg.exeDetected by Sophos as Troj/Bdoor-JU and by Malwarebytes Anti-Malware as Trojan.AgentNo
Internet Explorer HelperXmsiehelp.exeDetected by Sophos as Troj/Iyus-P and by Malwarebytes Anti-Malware as Trojan.BankerNo
msiemon.exeXmsiemon.exeMicrosoft Security Adviser rogue security software - not recommendedNo
MS Internet ExploreXMSIEx.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
[random name]Xmsiexec.exePurityScan adware. Do not confuse with the legitimate Windows® Installer (msiexec.exe) process which is always located in %System% and should not figure in Msconfig/Startup!No
MSIEXECXMSIEXEC.EXEAdded by the YOSENIO-A VIRUS!No
msiexec.exeXmsiexec.exeDetected by McAfee as Generic BackDoor!fql and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. Do not confuse with the legitimate Windows Installer (msiexec.exe) process which is always located in %System% and should not figure in Msconfig/Startup! This one is located in %AppData%No
SRUUninstallUmsiexec.exeSymantec Network Driver Update - part of LiveUpdateNo
GLSetIT32Xmsiexec16.exeDetected by Total Defense as Win32.OptixPro and by Malwarebytes Anti-Malware as Backdoor.OptixNo
MSIEXECXMSIEXEC32.exeAdded by the AINESEY.A WORM!No
msiexecsXmsiexecs.exeAdded by the SILLYFDC.BBB WORM!No
msiexecs.exeXmsiexecs.exeAdded by a variant of W32/Sdbot.wormNo
Netscape Internet BrowserXmsiexplore.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System%No
Windows USBDXmsifirewall.exeAdded by an unidentified WORM or TROJAN!No
Ms Java for Windows NTXmsijavaup32.exeDetected by Sophos as W32/Vanebot-INo
Ms Java Update For Windows NT/XPXmsijavaupdt32.exeDetected by Trend Micro as WORM_RANDEX.AFNo
KernelFaultCheckXmsime.exeAdded by the TINY-P TROJAN!No
IMJPMIG8.2Xmsime80.exeAdded by the VB-CYJ TROJAN!No
IMJPMIG8.2Xmsime82.exeAdded by the VB-CYG WORM!No
MsIMMs32XMsIMMs32.exeDetected by Trend Micro as TSPY_ONLINEG.GDJNo
msimnXmsimn.exeAdded by the AGOBOT.JL WORM! Note - this should not be confused with the legitimate Outlook Express file which shares the same filename and is located in %ProgramFiles%\Outlook Express. This one is located in %System%No
msimn.exeXMSIMN.EXEAdded by the FORBOT-TY WORM! Note - this should not be confused with the legitimate Outlook Express file which has the same filename and is located in %ProgramFiles%\Outlook Express. This one is located in %System%No
msimn.exeXmsimn.exeAdded by the SDBOT-DJH WORM! Note - this should not be confused with the legitimate Outlook Express file which has the same filename and is located in %ProgramFiles%\Outlook Express. This one is located in %Windir%No
Outlook ExpressNmsimn.exeLoads Outlook Express when Windows startsNo
MSIMN32XMSIMN32.EXEAdded by the CWS-M TROJAN!No
MSIN?MSin.exe??No
FltProcessYmsinet.exePart of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's doneNo
MsinetXMsinet.exeAdded by the RBOT-AOA WORM!No
Microsoft Internet Traffic ControlXMsinet32.exeDetected by Sophos as W32/AutoRun-XUNo
MSInfoXmsinfo.exeAdded by the ALADINZ.M TROJAN!No
Bymer.ScannerXMsinit.exeDetected by Symantec as W32.HLLW.BymerNo
Outlook ExpressXmsinm.exeAdded by a variant of the RBOT WORM! Note - this should not be confused with the legitimate Outlook Express file which has the filename "msimn.exe" and is located in %ProgramFiles%\Outlook Express. The file is located in %System%No
Internet Loader1XMSInstall61.exeAdded by the KWBOT.B WORM!No
mscom32Xmsint.exeAdded by the SDBOT.CCD BACKDOOR!No
TaskMonitorXMsinter.exeAdded by the DARKSKY.C BACKDOOR!No
Microsoft Int ServiceXMsIntSrv.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
COM ServiceXmsinul.comDetected by Kaspersky as Backdoor.Win32.Beastdoor.ir and by Malwarebytes Anti-Malware as Backdoor.BeastDoorNo
sv?hostXmsiregnv.exeAdded by the AGENT-TJL TROJAN! Note - the "?" in the name represents a character which is unidentified at presentNo
msisrvXmsisrv.exeDetected by Sophos as Troj/Agent-IQVNo
AntiVirus UpdateXmsisvc.exeAdded by the RBOT-HX WORM!No
MS-ConnectXmsite18.exeMS-Connect - Switch dialer and hijacker variant, see here. Also detected as the DIALER.DD TROJAN!No
brtfet32.exeXMSIUpdater.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%No
Microsoft Windows Visual V2.0Xmsiutil.exeAdded by the DELF.JPH TROJAN!No
Microsoft UpdateXmsiwin84.exeAdded by the GAOBOT.AFJ WORM!No
MS Internet Executor 32XMSIXEC32.exeAdded by the RBOT-AEQ WORM!No
COM ServiceXmsiygy.comDetected by Kaspersky as Backdoor.Win32.Beastdoor.nv and by Malwarebytes Anti-Malware as Backdoor.BeastDoorNo
Microsoft JavaVMXmsjarun.exeAdded by the RBOT-JW WORM!No
Ms Java for Windows NTXmsjava.exeAdded by the VANEBOT-E WORM!No
NeroUpdate CheckXmsjava.exeDetected by Trend Micro as WORM_AGOBOT.AMHNo
NeroFileCheckXmsjavam32.exeDetected by Trend Micro as WORM_AGOBOT.AKMNo
Ms Java for Windows 98, NT, ME & XPXmsjavames.exeAdded by the RBOT.BHJ WORM!No
Microsoft Java Virtual MachineXmsjavarxp.exeAdded by the FORBOT-DL WORM!No
Ms Java for Windows 98, NT, XP & MEXmsjavaxps.exeAdded by the VANEBOT.MS TROJAN!No
UsB driverXmsjavx86.exeAdded by the AGOBOT-PQ WORM!No
d4a5s1d5s5a1d9w4d1w3d1asXmsjbyzxt.exeDetected by Malwarebytes Anti-Malware as Trojan.VBInject. The file is located in %System%No
MSOffice32Xmsjcf.exeAdded by the RAKER-A TROJAN!No
COM ServiceXmsjclh.comDetected by Symantec as Backdoor.Beasty.G and by Malwarebytes Anti-Malware as Backdoor.BeastDoorNo
WinServiceUpdateXmsjssc.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %UserProfile%No
Microsoft Java Virtual MachineXmsjvm.exeDetected by Trend Micro as WORM_WOOTBOT.FZNo
McAfee SpamKillerUMskAgent.exeMcAfee SpamKiller - rule-based and list-based spam filter. Available as a stand-alone product or included in older versions of Internet Security and Total ProtectionYes
MskAgentUMskAgent.exeMcAfee SpamKiller - rule-based and list-based spam filter. Available as a stand-alone product or included in older versions of Internet Security and Total ProtectionYes
MskAgentexeUMskAgent.exeMcAfee SpamKiller - rule-based and list-based spam filter. Available as a stand-alone product or included in older versions of Internet Security and Total ProtectionYes
defaultUmskbw.exePC Surveillance PRO surveillance software. Uninstall this software unless you put it there yourselfNo
MSKDetectorExeUMSKDetct.exePart of McAfee SpamKiller - a rule-based and list-based spam filterNo
Internet Explorer PluginXMskernel16.exeAdded by the BACKAGE BACKDOOR!No
Internet KernelXMskernel16.exeDetected by Microsoft as Backdoor:Win32/Backage.C and by Malwarebytes Anti-Malware as Backdoor.AgentNo
MSKernel32XMSKernel32.vbsDetected by Bitdefender as VBS.LoveLetter.ANo
Windows kev MessengerXmskev.exeDetected by Sophos as W32/Sdbot-XVNo
mskjXmskj.exeAdded by the KAEMON TROJAN!No
MSKServerExeUMSKSrvr.exePart of McAfee SpamKiller - a rule-based and list-based spam filter. Appears as a service in XP/2K and under the "Run" registry key in 98/MeNo
Windows Portable DevicesXMSKSVRTSS.EXEDetected by Symantec as W32.Spybot.APEONo
Windows Portable Device DriversXMSKSVRVS.EXEAdded by a TROJAN - see hereNo
COM ServiceXmskwda.comDetected by Sophos as Troj/Agent-JIX and by Malwarebytes Anti-Malware as Backdoor.BeastDoorNo
mslagentXmslagent.exeSlagent adwareNo
Windows Workstation Start ServiceXmslanmgr.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
MSLARISSAXMSLARISSA.pifAdded by the ASSIRAL.B WORM!No
MS HTMLXmslat.exeAdded by the LATINUS.SVR BACKDOOR!No
windows automationXmslaugh.exeAdded by the BLASTER.E WORM!No
HKCUXmslcomm.exeDetected by McAfee as Generic.bfr!cx and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\Sys\systemNo
HKLMXmslcomm.exeDetected by McAfee as Generic.bfr!cx and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\Sys\systemNo
PoliciesXmslcomm.exeDetected by McAfee as Generic.bfr!cx and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\Sys\systemNo
CiaBackdoorXmsldr.comAdded by a VIRUS!No
SecureLoginXMslg32.exeAdded by the REDZED WORM!No
msngXmslifs.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %Root%\winmenssegerNo
msliveupdateXmslives.exeDetected by Trend Micro as TROJ_FAKEMS.CA and by Malwarebytes Anti-Malware as Trojan.Agent.MSLNo
msupdataXmslives.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %ProgramFiles%\WindowsUpdate\Microsoft - see hereNo
mslivesvc.exeXmslivesvc.exeAdded by the SPYEYE-DO TROJAN!No
msliveupdateXmsliveupdate.exeAdded by the AGOBOT.ALT WORM!No
LoadManagerXmsload.exeAdded by the OPASERV.T WORM!No
LoadingAgentXmsload32.exeDetected by Trend Micro as BKDR_OBLIVION.B and by Malwarebytes Anti-Malware as Backdoor.AgentNo
MS Config ServiceXMsloader32.exeAdded by the RBOT-KJ WORM!No
SysmonLogXmslog.exeDetected by Trend Micro as BKDR_AGENT.AOVNo
System Information ManagerXmslog.exeAdded by the DELF.AKO TROJAN!No
Mslogon lptt01Xmslogon.exeRapidBlaster variant (in a "mslogon" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove itNo
Mslogon ml097eXmslogon.exeRapidBlaster variant (in a "mslogon" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove itNo
Microsoft LSA layerXMSLSA32.exeDetected by Sophos as W32/Rbot-AKZNo
Microsoft Driver SetupXmslsrv32.exeAdded by the SDBOT-DPF TROJAN!No
Microsoft AUT UpdateXMSlti16.exeDetected by Trend Micro as WORM_RBOT.EBNo
Microsoft AUT UpdateXMSlti32.exeAdded by the RBOT-X WORM!No
Microsoft UpdateXMslti32.exeAdded by the RBOT-LX WORM!No
Video ProcessXMSlti64.exeAdded by the AGOBOT.UE WORM!No
msmXmsm.scrDetected by Sophos as Troj/Banker-EHJ and by Malwarebytes Anti-Malware as Trojan.BankerNo
27Xmsm32.exeAdded by the SLSORVE-E TROJAN!No
Microsoft Protection SubsystemsXmsm32.exeDetected by Sophos as W32/Rbot-JUNo
msmacro32Xmsmacro32.exeIdentified as a variant of the AGENT.QB TROJAN!No
msmacro32Xmsmacro64.exeAdded by a variant of the BACKDOOR-DOQ TROJAN!No
Microsoft Macro Protection SubsystemsXMsmacroprot32.exeAdded by the RBOT.KN WORM!No
Microsoft Macro Protection SubsystemsXmsmacroprotxz.exeAdded by a variant of the SPYBOT WORM!No
Microsoft ManagerXmsmanager.exeDetected by Trend Micro as WORM_MYTOB.LFNo
avnortXmsmbw.exeAdded by the SERFLOG.A WORM!No
ltwobXmsmbw.exeAdded by the SERFLOG.A WORM!No
serpeXmsmbw.exeAdded by the SERFLOG.A WORM!No
msmcXmsmc.exeClientMan parasite variantNo
Microsoft Media player 9Xmsmedia32.exeAdded by the RBOT-ADO WORM!No
Microsoft Message MachineXmsmesg32.exeAdded by the SPYBOT.BI WORM!No
MSMsgsXmsmessgs.exeAdded by the SMALL-EW TROJAN!No
Microsoft Messenger Management ControlsXmsmgmctl.exeAdded by the RBOT-APA WORM!No
MSNXmsmgr.exeAdded by the AUTORUN-BHH WORM!No
MsManagerXmsmgr32.exeAdded by the YAHA.AF WORM!No
WINTASKXmsmgrxp.exeAdded by the MYTOB.AQ WORM!No
Messenger GatewayXmsmgs.exeDetected by Sophos as Troj/Agent-IGKNo
Windows Live Messenger ServicerXmsmgslive.exeAdded by a variant of the IRCBOT TROJAN! See hereNo
MsmgtXmsmgt.exeTotal Velocity adware/hijackerNo
b99Xmsmm.exeClientMan parasite variantNo
msmmiXmsmmi.exeAdded by the AGENT.RFR TROJAN!No
MSN MESSENGERXmsmmsgr.exeAdded by the KELVIR.Q WORM!No
Network Host ServiceXmsmnart32.exeAdded by the RBOT-CJV WORM!No
msmanager32Xmsmngr32.exeAdded by the RANDON-R (or WOMANIZ.A) WORM!No
msmanagerw32Xmsmngr32.exeAdded by a variant of BKDR_WOMANIZ.C. The file is located in %System%\toolsNo
msmanagerw32Xmsmngr32.exeDetected by Trend Micro as BKDR_WOMANIZ.C. The file is located in %System%\winupdateNo
Roxio Engine?MSMNGR32.EXENot believed to be a valid Roxio program - more likely a variant on the WOMANIZ.A TROJAN!No
MSMNTGNTXMSMNTGNT.EXEAdded by the BANKER-IE TROJAN!No
MSMNTJBEXMSMNTJBE.EXEAdded by the BANCOS-EF TROJAN!No
MSMNTJNGXMSMNTJNG.EXEAdded by the GRABER-G TROJAN!No
MSMNTMTSXMSMNTMTS.EXEAdded by the BANKER-GZ TROJAN!No
MSN Registry loaderXmsmnwin.exeAdded by the KELVIR.FK WORM!No
MsmonXmsmon.exeAdded by the GEMA TROJAN!No
MsMon32XMsMon32b.exeAdded by the SDBOT.O BACKDOOR!No
Microsoft Windows GUIXmsmonk32.exeAdded by the SDBOT-PE WORM!No
MsMoviesXMsMovies.exeAdded by the ALCRA-E WORM!No
Microsoft Security Monitor ProcessXmsmp.exeAdded by the RBOT.GKQ WORM!No
AvSerXmsmpatch.exeAdded by the SERFLOG.B WORM!No
DsmSerXmsmpatch.exeAdded by the SERFLOG.B WORM!No
rollbkXmsmpatch.exeAdded by the SERFLOG.B WORM!No
Microsoft EssentialsXMsMpEng.exeDetected by McAfee as Generic Dropper!1jh and by Malwarebytes Anti-Malware as Trojan.Agent.GenNo
Microsoft ServicesXmsmpserv.exeAdded by the IRCBOT.BKA BACKDOOR!No
MS Unix BinaryXmsmq2inst.exeAdded by the RBOT-YF WORM!No
Message QueuingXmsmqs.exeAdded by the FREEFORS TROJAN!No
Microsoft Update Virtual MachineXmsmr32g.exeAdded by the RBOT.SA BACKDOOR!No
mackfy.exeXmsms.exeAdded by the SDBOT-DID WORM!No
mssoulXmsmscc.exeAdded by the BANCOS.HKT TROJAN!No
mssoulXmsmscc2.exeAdded by the DAPIZL.A banker WORM! (A "banker worm" is designed to pillage banking information and send it back to the perpetrators!)No
Windows FirewallXmsmsd.exeAdded by the VB-OG MALWARE!No
Microsoft Messenger ServiceXmsmsg32.exeAdded by the RBOT.BOK WORM!No
MicrosoftXmsmsger.exeAdded by a variant of W32/Sdbot.wormNo
Microsoft OfficeXMSMSGR.exeAdded by the GAOBOT.BB WORM!No
Microsoft OfficeXmsmsgr.exeAdded by the GAOBOT.BB WORM!No
Microsoft System Firewall 2006.2Xmsmsgr.exeAdded by a variant of W32/Sdbot.wormNo
Microsoft System ServicesXmsmsgr.exeAdded by the RBOT-ZH WORM!No
MSN Messenger User ControlsXmsmsgr.exeAdded by the KELVIR.HI WORM!No
Windows defendsXMsmsgr.exeDetected by McAfee as Generic.bfr. This entry loads from the HKLM\Run, HKCU\Run and HKLM\policies\Explorer\Run registry keysNo
[random name]Xmsmsgr2.exeDetected by Sophos as Troj/Small-EBNo
Intec Service DriversXmsmsgredss.exeAdded by the SDBOT-AGL WORM!No
mslanhelperXmsmsgri32.exeAdded by the RANDEX.D WORM!No
mssyslanhelperXmsmsgri32.exeAdded by the RANDEX.D WORM!No
System InitializationXmsmsgri32.exeAdded by a variant of the RANDEX.D WORM!No
Intec Service DriversXmsmsgrs.exeAdded by the SDBOT-ADN WORM!No
NvCplDaemonXmsmsgrs.exeAdded by the DLOADER-YI TROJAN!No
Windows Rundll CenterXmsmsgrs.exeAdded by the IRCBOT-AFA WORM!No
MsnLiveMessengerXmsmsgrsu.exeAdded by the IRCBOT.ARA WORM!No
_Cat3Xmsmsgrxp.exeAdded by the SMALL-DT TROJANNo
csrssXmsmsgs.exeAdded by the CHODE-J BACKDOOR! Note - this malware uses MSN Messenger (which is located in %Program Files%\Messenger) in the background to propogate itselfNo
MessengerNmsmsgs.exeWindows Messenger instant messenger utility included with Windows 2K/XP. Available via the Start menu. Go to Windows Messenger → Tools → Options → Preferences and uncheck "Run this program when Windows starts"Yes
Messenger ServiceXmsmsgs.exeAdded by the SDBOT-ZB WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\MessengerNo
Microsoft ExceleXmsmsgs.exeAdded by the AGENT.AJQG TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\MessengerNo
Microsoft Msn MessengerXmsmsgs.exeAdded by the BUZUS.AYX TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\MessengerNo
Microsoft OfticeXmsmsgs.exeAdded by the IRCBOT.ALT WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\MessengerNo
msmsgsXmsmsgs.exeAdded by the SCLOG-AL TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\MessengerNo
MsmsgsXMsmsgs.exeAdded by the SILLYFDC-AP WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\MessengerNo
MSMSGSNmsmsgs.exeWindows Messenger instant messenger utility included with Windows 2K/XP. Available via the Start menu. Go to Windows Messenger → Tools → Options → Preferences and uncheck "Run this program when Windows starts"Yes
MSN MessengerXmsmsgs.exeDetected by Symantec as Trojan.Zlob. Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\MessengerNo
Msn Update Manager (Sp2)XMSMSGS.EXEAdded by the AGOBOT-NL WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\MessengerNo
msnLiverXmsmsgs.exeDetected by Dr.Web as Win32.HLLW.Imager.32 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\MessengerNo
notepad.exeXmsmsgs.exeDetected by Symantec as Trojan.Zlob. Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\MessengerNo
RegSvr32Xmsmsgs.exeAdded by the ZLOB.B TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\MessengerNo
SchedulerXMSMSGS.EXEAdded by the HOSTBANK-A TROJAN! Note - this particular msmsgs.exe file is located in %System%\Config and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\MessengerNo
Msmsgsis.exeXMsmsgsis.exeDetected by SUPERAntiSpyware as Trojan.Downloader-MSMSGSIS.Process and by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Root%No
MsMsgSrvXmsmsgsrv.exeDetected by McAfee as BackDoor-CQONo
msmsgrXmsmsgss.exeDetected by Kaspersky as the RBOT.AJJ WORM!No
msmsgssXmsmsgss.exeAdded by the MDROP-CHV TROJAN!No
MSMsgSvcXMSMSGSVC.exeBrowser hijacker, identified by some antiviruses as a variant of the StartPage.QC TROJAN!No
Windows32 Messenger ServiceXmsmsgv.exeAdded by the RBOT.ANS WORM!No
msmsnXmsmsn.exeDetected by Sophos as Troj/Dloadr-WP and by Malwarebytes Anti-Malware as Trojan.AgentNo
Microsoft Messenger XPXMSMSN32.exeAdded by the RBOT-ZP WORM!No
MS MSN Menssenger 7.0XMSMSN7.exeAdded by the RBOT-ACA WORM!No
MSN Configuration LoaderXmsmsncfg.exeAdded by the AGOBOT-KX BACKDOOR!No
msmsngrXmsmsngr.exeAdded by the DOPBOT-B WORM!No
MSN ServXmsmsnserv.exeAdded by the IRCBOT.AVF BACKDOOR!No
MSN ServerXmsmsnserver.exeAdded by the IRCBOT.AUS BACKDOOR!No
msmautoprotectXmsmssgs.exeAdded by the BIFROSE-AJ TROJAN!No
Windows live MessengerXmsn.comAdded by the IRCBOT-AAV WORM!No
c51dd1d4c0a92fb8c2ee78d1aed16abdXmsn.exeDetected by Dr.Web as Trojan.DownLoader8.33364 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJNo
controlXmsn.exeAdded by the DUCY BACKDOOR!No
MSNXMSN.exeAdded by the MINIT WORM!No
Msn 8.0 LiveXmsn.exeAdded by the BANKER.EIE TROJAN!No
MSN32Xmsn.exeDetected by McAfee as Generic.bfr!pNo
NSIS64Xmsn.exeDetected by Dr.Web as Trojan.AVKill.23906 and by Malwarebytes Anti-Malware as Trojan.VBAgent. The file is located in %ProgramFiles%\WinLiveNo
NSIS64Xmsn.exeDetected by Dr.Web as Trojan.AVKill.25003 and by Malwarebytes Anti-Malware as Trojan.VBAgent. The file is located in %ProgramFiles%\JavaSuppotNo
NSIS64Xmsn.exeDetected by Dr.Web as Trojan.WinSpy.1707 and by Malwarebytes Anti-Malware as Trojan.VBAgent. The file is located in %ProgramFiles%\FirewallNo
Win32 USB2 DriverXmsn.exeAdded by the FORBOT-EX WORM!No
MSN SetupXMSN.msnAdded by the JAMBU WORM!No
Windows MSNXMSN.msnAdded by the TRIXCU.A WORM!No
MSNXmsn16.exeAdded by the SDBOT-VN WORM!No
Media LoadXmsn32.exeAdded by a unidentified WORM or TROJAN!No
MICROSFT RAMA UPDATE SUPPORTXMSN32.EXEAdded by the RBOT-AWJ WORM!No
MSN UpdateXmsn32.exeAdded by a variant of Win32/RbotNo
MSN32Xmsn32.exeDetected by McAfee as BackDoor-CEP!bclNo
OfficeWord MonitorXmsn32.exeAdded by the RBOT-GUE WORM!No
win32 regeditXmsn32.exeAdded by an unidentified WORM or TROJAN!No
WINDOWS SYSTEMXmsn32.exeAdded by the MYTOB-FX WORM!No
MSN32 X ServiceXMSN32x.EXEDetected by Malwarebytes Anti-Malware as Backdoor.AgentNo
MSN32 Z ServicesXMSN32z.EXEDetected by Malwarebytes Anti-Malware as Trojan.AgentNo
Video ProcessXmsn5.exeAdded by the AGOBOT-TW WORM!No
Media ServiceXmsn64.exeDetected by Sophos as W32/Rbot-LWNo
MSN8m StartupXmsn8m.exeDetected by Total Defense as Win32.Rbot.DGYNo
MSN9 StartupXmsn9.exeAdded by the RBOT.BXZ WORM!No
Microsoft Networking Agent For SP2Xmsnac32.exeAdded by the SPYBOT.PEN WORM!No
MSN Administration For WindowsXmsnadp32.exeDetected by Trend Micro as WORM_BROPIA.WNo
msnappauNmsnappau.exeUpdater for the MSN toolbar that can be downloaded onto IE. Calls home every day or so to "update" the toolbarNo
msnsyslogNmsnappm.exeRelated to Messenger Applications. When you uninstall the trial version the msnappm keeps saying (You have xx days left) this is adware and it very annoyingNo
msnarratorXmsnarrator.exeAdded by the NARAT.A TROJAN - also identified as MPGCOM Toolbar adwareNo
MSN Auto-UpdaterXmsnaupdater.exeAdded by a variant of the IRCBOT BACKDOOR!No
MSN BoosterXmsnbooster.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
MSN BooterXmsnbootcf.exeAdded by the DELF-FAS TROJAN!No
Msn BootXmsnbootcfg.exeAdded by the IRCBOT.BFU BACKDOOR!No
COM ServiceXmsncbo.pifDetected by Kaspersky as Backdoor.Win32.Beastdoor.il and by Malwarebytes Anti-Malware as Backdoor.Agent.OLNo
Microsoft Windows DLL 32-BITXmsncheck32.exeAdded by the SDBOT-XX WORM!No
MSN CheckerXmsnchecker.exeAdded by the SDBOT-AGB WORM!No
Windows Live ClientXmsnclient.exeAdded by a variant of the IRCBOT TROJAN! See hereNo
MSN Client ManagerXmsnclimgr.exeAdded by the AUTORUN-FV WORM!No
MSN CNF ManagerXmsncnfmgr.exeAdded by the VUNDO TROJAN!No
ImMsnXmsncomm.exeAdded by the WEBDOR.AK BACKDOOR!No
TimerXmsncomm.exeAdded by the WEBDOR.AK BACKDOOR!No
MSN Communication ManagerXmsncommgr.exeAdded by an unidentified WORM or TROJAN! See hereNo
Microsoft .NET ConfinguratorXmsnconf.exeAdded by an unidentified VIRUS, WORM or TROJAN!No
MSN ConfigurationXmsnconfig.exeAdded by a variant of the IRCBOT BACKDOOR!No
Windows Installer 1Xmsnconfig.exeDetected by Trend Micro as TROJ_PURITYSCN.BNo
Windows Live MessengerXmsnd.exeAdded by the BCKDR-QQQ BACKDOOR!No
Windows System GuardXmsnd.exeAdded by the DWNLDR-IMP TROJAN!No
Windows32 Net DatabaseXmsnd32.exeAdded by the RBOT-AAL WORM!No
MSN Database ClientXmsndbcli.exeAdded by an unidentified WORM or TROJAN! See hereNo
MSN Quick ViewNMsndc.exeQuick way to connect to MSN internet serviceNo
MSN Debug MgrXmsndebugs.exeAdded by a variant of the IRCBOT BACKDOOR!No
Msn PatchXmsndp.exeDetected by Trend Micro as WORM_RBOT.AAINo
msndrvsysXmsndrvsys.exeAdded by the BROGGER-D TROJAN!No
InetMSNXmsnet.exeAdded by a variant of the SDBOT BACKDOOR!No
Microsoft NetworkXmsnet.exeAdded by the MOCKBOT.A WORM!No
MSNETXmsnet.exeAdded by the BOA WORM!No
MS-NetXmsnet.exeAdded by the RBOT-HZ WORM!No
[various names]XMsNetHelper.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
SporeXMsNews.vbsAdded by the SORPE.A WORM!No
MsnExplorerXmsnexploren.exeAdded by the TACTSLAY.B TROJAN!No
SchedulerXmsnexploren.exeAdded by the TACTSLAY.B TROJAN!No
SvcH0stXmsnexploren.exeAdded by the TACTSLAY.B TROJAN!No
WinAmpAgentXmsnexploren.exeAdded by the TACTSLAY.B TROJAN!No
MSN ExplorerXmsnexplorer.exeAdded by the AGENT-CAX TROJAN!No
MSN File ConfigurationXmsnfilecfg.exeAdded by a variant of the IRCBOT BACKDOOR!No
Service MonitorXmsnfilen.exeAdded by the RBOT-ALE WORM!No
MSN File & Folder Sharing AppXmsnfileshare.exeAdded by an unidentified WORM or TROJAN! See hereNo
MsnFixer?msnfixjs.jsLocated in the HPbinmsnfix directory of a HP PCNo
msnfo32sXmsnfo32s.exeAdded by the PROXY-HR TROJAN!No
msng.exeXmsngDetected by Malwarebytes Anti-Malware as Trojan.Backdoor. The file is located in %System%No
Windows System GuardXmsng.exeAdded by the EGGDROP-BO WORM!No
Windows Service AgentXmsngear.exeAdded by the RBOT.AHW BACKDOOR!No
Windows Services AgentXmsngears.exeAdded by the VB-EMS TROJAN!No
ethernetXmsnger.exeDetected by Trend Micro as WORM_RBOT.CHPNo
Microsoft messengerXmsnger.exeDetected by Trend Micro as WORM_SDBOT.CQENo
Windows Media DriverXmsnger.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
MicrosoftXmsngerf.exeAdded by the RBOT-GLW WORM!No
Windows Service AgentXmsngerr.exeAdded by the RBOT.EOZ WORM!No
Microsoft messenger sdXmsngersd.exeDetected by SUPERAntiSpyware as Trojan.Microsoft Messenger sd.Process. The file is located in %Windir%No
Msn ConfigXmsngf.exeAdded by the RBOT-QG WORM!No
Msn Configuration LoaderXmsngms.exeAdded by the KELVIR.T WORM!No
System-ConfigXmsngmsg.exeAdded by the SDBOT-MD WORM!No
Microsoft Instant MessengerXmsngmsngr32.exeAdded by the SPYBOTER.GEN TROJAN!No
FKS v2.0Xmsngr.exeAdded by an unidentified WORM or TROJAN!No
Topic MSNGR32XMSNGR32.comAdded by a variant of the IRCBOT TROJAN!No
Microsoft MSNGR32 ProtocolXmsngr32.exeAdded by the RBOT.AHC WORM!No
MSNGrabberXMSNgrabber.exeAdded by the ENVID.A WORM!No
Messenger BlockXmsngrblock.exeAdded by the PATOO WORM!No
WindowsLiveMessengerXmsngrpmsn.exeAdded by the AGENT-RQF TROJAN!No
Microsoft Internet ExplorerXmsngrt.exeAdded by the SDBOT-GU BACKDOOR!No
Media X ServicesXMSNGRx.exeDetected by Trend Micro as WORM_RBOT.AULNo
dataXmsngs.exeAdded by the RBOT-ADQ WORM!No
msngta32Xmsngta32.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
MSN HostnXmsnhostn.exeAdded by a variant of the IRCBOT BACKDOOR!No
AdobeReaderXmsni.exeAdded by the RBOT.DAO WORM!No
Windows System TrayUmsni.exeIambigbrother monitoring softwareNo
Msn Processe ManagerXmsni32.exeAdded by the RBOT-ADX WORM!No
MSNIANMSNIASVC.EXEAdded with MSN version 9. Resets certain internet settings upon bootup and can't be disabled via MSCONFIGNo
MSN MessengerXmsnimsgr.exeAdded by the RBOT-BFM WORM!No
MSN Messenger Inbox LoaderXmsninbox.exeAdded by the SLENFBOT.YG WORM!No
MSN Messenger 32Xmsniu.exeAdded by the RBOT-AWB WORM!No
MSN Messenger 323Xmsniu3.exeAdded by the RBOT-AXB WORM!No
blahx serviceXmsnjompa.exeAdded by the SDBOT.AML WORM!No
Security PatchesXmsnkn.exeAdded by the RBOT.WW WORM!No
WINDOWS SYSTEMXmsnl.exeAdded by the MYTOB.IK WORM!No
Windows System GuardXmsnl.exeAdded by the PUSHBOT.B TROJAN!No
Windows Live MessengerXmsnlive.exeDetected by Kaspersky as Backdoor.Win32.Rbot.bmvNo
Windows Live ServiceXmsnlive.exeAdded by the SLENFBOT.DI WORM!No
MSN Live MessangerXmsnlivegs.exeAdded by the RBOT-FSG WORM!No
Microsoft Windows LiveMessengerXmsnlmsgrsn.exeAdded by the AGENT-TDN TROJAN!No
msnload32.exeXmsnload32.exeAdded by the BANCOS.M TROJAN!No
MsnLoaderPlus.exeXMsnLoaderPlus.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %Windir%No
MSN Live ClientXmsnlvclient.exeAdded by the IRCBOT.AWF BACKDOOR!No
Windows Service AgentXmsnmagr.exeAdded by a variant of the SLAPER TROJAN!No
hotefixXmsnmanegers.exeAdded by the KOLAB.QA WORM!No
Macafea Personal FirewallXMSNmassegez.exeAdded by the RBOT.BCI WORM!No
strmsnnrsXmsnmcgrs.exeAdded by the RBOT-ACT TROJAN!No
strmsnnmsXmsnmegrs.exeAdded by the SDBOT-YU TROJAN!No
strmsoumsXmsnmegrse.exeAdded by the SDBOT-ZK TROJAN!No
MSNXmsnmesengers.exeAdded by the RBOT-ME WORM!No
MSN MessagesXmsnmesg.exeAdded by the RBOT-ACN WORM!No
Java32 Configuration LoaderXmsnmesgr.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
*winsocksXmsnmess.exeAdded by the PWS-ABU TROJAN!No
winsocksXmsnmess.exeAdded by the PWS-ABU TROJAN!No
Live Windows Messenger VersionXmsnmessage7.7.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
Msn Message Acount Helper 7.7Xmsnmessage7.7.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
FlashMediaXMsnMessenger.exeDetected by Dr.Web as Trojan.MulDrop4.26780 and by Malwarebytes Anti-Malware as Trojan.AgentNo
Microsoft Windows UpdateXmsnmessenger.exeAdded by the SDBOT.AJ BACKDOOR!No
MSN messengerXMSNMessenger.exeAdded by unidentified malwareNo
msnmessengerXmsnmessenger.exeAdded by the BANCBAN-KJ TROJAN!No
MsnMessenger.exeXMsnMessenger.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. Note that the Command field can be either blank or the same as the Name field and located in a sub-folder of %LocalAppData% - see here and hereNo
Service DriversXMSNMEssenger.exeAdded by a variant of Win32/RbotNo
MSN Messenger Live LoginXmsnmessengerlive.exeAdded by an unidentified WORM or TROJAN! See hereNo
svshostdriverXmsnmessengerupdate.exeAdded by the SDBOT-BI BACKDOOR!No
MSN MessagesXmsnmessgs.exeAdded by the SLENFBOT.UC WORM!No
WindowsSystem32Xmsnmgaer.exeAdded by the AGENT.ALY BACKDOOR!No
OfficesXmsnmgd32.exeAdded by the FORBOT-DV WORM!No
Win UpdateXmsnmger.exeAdded by the RBOT-GDP WORM!No
.NET.Xmsnmgnr.exeDetected by Trend Micro as WORM_DELF.AYFNo
msnmgnrXmsnmgnr.exeAdded by the KOLAB.TC WORM!No
MSN MessagerXmsnmgr.exeAdded by the IRCBOT-ACD WORM!No
Msn MessengerXmsnmgr.exeDetected by Trend Micro as WORM_AGOBOT.HANo
MSN Messenger ServicesXmsnmgr.exeAdded by the RBOT.ADF TROJAN!No
msnmgrXmsnmgr.exeAdded by the BIFROSE-K WORM!No
msnmgr.exeXmsnmgr.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %CommonAppData%No
msnmgr.exeXmsnmgr.exeDetected by McAfee as Generic BackDoor!d2k and by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %LocalAppData%No
MSN serviceXmsnmgr16.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
msnmgr32Xmsnmgr32.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this entry loads from the Windows Startup folder and the file is located in %UserProfile%\Start Menu\Programs\Msnmgr32No
msnmgr32Xmsnmgr32.exeDetected by McAfee as Generic Downloader.x and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this entry loads from the Windows Startup folder and the file is located in %AppData%\Msnmgr32No
MSN ManagerXmsnmgrsv.exeAdded by the IRCBOT.BAZ BACKDOOR!No
Microsoft System ServicesXmsnmgsr.exeAdded by the KELVIR.K WORM!No
MSN Messenger Service StarterXmsnmgsr.exeAdded by the RBOT-AOS WORM!No
Microsoft Help SVCXmsnmngr.exeAdded by the SDBOT-PQ WORM!No
Microsofts Help ServicesXmsnmngr.exeAdded by the SDBOT-PJ WORM!No
Windows UDP Control CenterXmsnmngs.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
Microsoft MSN MessengerXmsnmnsgr.exeAdded by a variant of the IRCBOT TROJAN!No
BitDefender for MSN MessengerUmsnmon.exeBitdefender anti-virus for MSN Messenger - no longer supported at the BitDefender websiteNo
MsnMonitorUMsnMonitor.exeMSN Messenger Monitor Sniffer surveillance software for the MSN instant messenger. Uninstall this software unless you put it there yourselfNo
Windows Service ManagerXmsnmrg.exeAdded by the OSCABOT-G WORM!No
Office_appXmsnmrgs.exeAdded by a variant of the VBBANC-A TROJAN!No
MSN UpdaterXmsnms.exeAdded by the FORBOT-CG WORM!No
Microsoft Genuine LogonXmsnmsg.exeAdded by the IRCBOT-XH WORM!No
Microsoft MSN 7 ServicesXmsnmsg.exeAdded by a variant of the IRCBOT BACKDOOR!No
Microsoft Server ApplacationsXmsnmsg.exeDetected by Trend Micro as WORM_AGOBOT.BBMNo
Microsoft Windows Update ServiceXmsnmsg.exeAdded by a variant of the IRCBOT BACKDOOR!No
msnXmsnmsg.exeAdded by the RBOT-GO WORM!No
MSN Message ServiceXmsnmsg.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
Msn Messenger ServiceXmsnmsg.exeAdded by the SDBOT.BMU WORM!No
msnmsgXmsnmsg.exeDetected by Sophos as Mal/VB-JW and by Malwarebytes Anti-Malware as Trojan.VBAgent. The file is located in %Windir%\systemNo
msnmsgXmsnmsg.exeDetected by Sophos as Troj/Banker-CLX. The file is located in %System%No
msnmsg.exeXmsnmsg.exeDetected by Sophos as Troj/Bancban-KNNo
Plug And PlayXmsnmsg.exeAdded by the RBOT-ID WORM!No
Windows LiveXmsnmsg.exeDetected by Sophos as W32/AutoRun-YLNo
Windows Live MessengerXmsnmsg.exeDetected by Malwarebytes Anti-Malware as Trojan.Inject. Note - this is not the valid MSN Messenger (now Windows Live Messenger) (msnmsgr.exe) utility. The file is located in %ProgramFiles%\Windows Live\Messenger\trNo
Windows MessengerXmsnmsg.exeAdded by the SPYBOT.BV WORM!No
Windows RegistryXmsnmsg.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
msnmsgXmsnmsg1.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %CommonAppData%No
Mobile Device ServiceXmsnmsg32.exeDetected by Dr.Web as Trojan.Siggen2.48203 and by Malwarebytes Anti-Malware as Trojan.FakemessNo
msnmsgXmsnmsg4.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %Root%No
Msn MessangerXmsnmsgem.exeAdded by the RBOT.BLL BACKDOOR!No
Microsoft MSN 7 ServicesXmsnmsger.exeAdded by a variant of the IRCBOT BACKDOOR!No
Windowfdgfds DasdLL VerifiewXmsnmsger.exeAdded by the RBOT-GGX WORM!No
msnToolbaarXmsnmsgesc.exeDetected by Trend Micro as WORM_RBOT.BMFNo
System51616Xmsnmsgesser.exeAdded by the PUSHBOT.BS WORM!No
Microsoft UpdateXmsnmsgl.exeAdded by a variant of the SPYBOT WORM! See hereNo
msnmsgq32Xmsnmsgq.exeDetected by Total Defense as Win32/Tactslay.FNo
sssasasb32Xmsnmsgq.exeDetected by Total Defense as Win32/Tactslay.FNo
msnmsgr32-.exeXmsnmsgr-.exeAdded by a variant of the SPYBOT WORM!No
679a7374a36a56838ce90282f328545fXmsnmsgr.exeDetected by Dr.Web as Trojan.DownLoader7.27754 and by Malwarebytes Anti-Malware as Backdoor.Bot. Note - this is not the valid MSN Messenger or Windows Live Messenger (which has now moved to Skype) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %AppData%No
Adobe Flash AcceleratorXmsnmsgr.exeDetected by McAfee as Generic Dropper!fhv and by Malwarebytes Anti-Malware as Backdoor.Bot. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %AppData%\Microsoft\System Root CertificatesNo
Configuration LoaderXmsnmsgr.exeDetected by Sophos as W32/Sdbot-SO. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%No
ctfmonXmsnmsgr.exeDetected by Sophos as Troj/Bdoor-JV. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%No
Intec Service DriversXmsnmsgr.exeDetected by Trend Micro as WORM_SDBOT.DDH. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %Windir%No
MessengerNMsnMsgr.exeWindows Live Messenger (was MSN Messenger) utility - available via the Start menu. Disable by clicking on the "Show menu" icon and select Tools → Options → General → deselect "Automatically run Windows Live Messenger when I log on to Windows". This is the Windows Defender/Vista MSConfig entry for version 8.*Yes
Microsoft System Firewall 2006.2Xmsnmsgr.exeAdded by a variant of W32/Sdbot.worm. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%No
Microsoft Windows UpdateXMSNMSGR.EXEDetected by Sophos as W32/Sdbot-WM and by Malwarebytes Anti-Malware as Trojan.MWF.Gen. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%No
MSNXmsnmsgr.exeDetected by Symantec as W32.Mytob@mm or W32.Mytob.B@mm. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%No
Msn MessagerXmsnmsgr.exeDetected by AhnLab as Dropper/Downloader.19456.C. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%No
MSN MessengerXmsnmsgr.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor.VB. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %Windir%\system3232No
MSN MessengerXmsnmsgr.exeDetected by Trend Micro as WORM_AGOBOT.AOQ. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%No
MSN MessengerNMsnMsgr.exeMSN Messenger utility (now replaced by Windows Live Messenger) - available via the Start menu. Disable by clicking on Tools → Options → General → deselect "Automatically run Messenger when I log on to Windows"Yes
Msn MessengersXMSNMSGR.EXEDetected by Trend Micro as WORM_RBOT.KX. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%No
MSN Tray MonitorXmsnmsgr.exeDetected by Trend Micro as WORM_SDBOT.FKX. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%\inetsrvNo
MsnMessengerSvcXmsnmsgr.exeAdded by a variant of Win32/Rbot. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%No
msnmsgrNmsnmsgr.exeWindows Live Messenger or the older MSN Messenger utility - available via the Start menu. For Windows Live Messenger, disable by clicking on the "Show menu" icon and select Tools → Options → Sign In → deselect "Automatically run Windows Live Messenger when I log on to Windows". For MSN Messenger, disable by clicking on Tools → Options → General → deselect "Automatically run Messenger when I log on to Windows"Yes
msnmsgrXmsnmsgr.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCbot. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %AppData%No
msnmsgrXmsnmsgr.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %UserStartup% and/or %AllUsersStartup% and its presence there ensures it runs when Windows startsNo
MsnMsgrXmsnmsgr.exeDetected by Sophos as W32/Annew-Fam. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%No
picviewXmsnmsgr.exeDetected by Sophos as Troj/Banloa-AF. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %Windir%No
SN MessengerXmsnmsgr.exeDetected by Sophos as W32/Rbot-AVP. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%No
SysComXmsnmsgr.exeDetected by Sophos as Troj/Bank-AF. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %Windir%\systemNo
Windows Live MessengerNmsnmsgr.exeWindows Live Messenger (was MSN Messenger) utility - available via the Start menu. Disable by clicking on the "Show menu" icon and select Tools → Options → Sign In → deselect "Automatically run Windows Live Messenger when I log on to Windows". This is the Windows Defender/Vista MSConfig entry for version 14.*Yes
Windows Live MessengerXmsnmsgr.exeAdded by a variant of Win32/Rbot. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%No
Windows Live MessengerXmsnmsgr.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCbot. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %AppData%No
Windows Live MessengerXmsnmsgr.exeDetected by Malwarebytes Anti-Malware as Backdoor.XTRat.Gen. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %Root%\Windows Live MessengerNo
Windows LoginXmsnmsgr.exeDetected by Sophos as W32/Agobot-UC. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%No
Windows Service AgentXmsnmsgr.exeDetected by Kaspersky as Backdoor.Win32.Rbot.abik and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%No
MSN serviceXmsnmsgr16.exeAdded by the RBOT-RZ WORM!No
MSNMSGR5XMSNMSGR5.exeAdded by the RBOT.PQ WORM!No
MSN StartXmsnmsgr7.exeDetected by Sophos as W32/Rbot-PHNo
MSN MessengerXmsnmsgrc.exeAdded by the RBOT-CNP WORM!No
msnmsgreXmsnmsgre48.exeDetected by Sophos as Troj/Inject-ZZ and by Malwarebytes Anti-Malware as Trojan.Inject. The file location varies and includes (but is not limited to) %Root% and %CommonAppData%No
blah serviceXmsnmsgrr.exeDetected by Trend Micro as WORM_RBOT.PZNo
MessengerXmsnmsgrr.exeAdded by the RBOT-GYK WORM!No
MsnMsgrXMsnMsgrs.exeAdded by the NETSKY.AD WORM!No
strmsnmsgrXmsnmsgrs.exeAdded by the RBOT-ACQ WORM!No
Sygate Personal FirewallXmsnmsgrs.exeAdded by the RBOT.XN WORM!No
strmsnmsgrsXmsnmsgrsc.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
Windows Secure Messaging SystemXmsnmsgrsrvc.exeAdded by the RBOT-RE WORM!No
Msn Msgrs ServiceXmsnmsgrss.exeAdded by the SDBOT.JY WORM!No
Windows UDP Control CenterXmsnmsgrss.exeAdded by the CEEINJ-B TROJAN!No
MSNXmsnmsgs.exeAdded by the RBOT-KL WORM! Note - not to be confused with msmsgs.exe, the well known MSN Instant Messaging application!No
Msn MessengerXmsnmsgs.exeAdded by the LOONY-P TROJAN! Note - not to be confused with msmsgs.exe, the well known MSN Instant Messaging application!No
msnmsgs.exeXmsnmsgs.exeAdded by the BANKER-HK TROJAN! Note - not to be confused with msmsgs.exe, the well known MSN Instant Messaging application!No
msnmsgsgsXmsnmsgsgs.exeAdded by the "Catal" alias Spy.Delitall.B backdoor TROJAN!No
Window Msn Live MessangerXmsnmsgsls.exeAdded by the RBOT.BJD BACKDOOR!No
MSN messangerXmsnmsgsm.exeAdded by the RBOT-FMP WORM!No
Windows Msn Live Messanger Xmsnmsgsman.exeAdded by a variant of W32/Sdbot.worm. Note - the "Name" field has a space at the endNo
MSN MessangerXmsnmsgsmn.exeAdded by the RBOT-FOQ WORM!No
MSNXmsnmsgx.exeAdded by the RBOT-PZ WORM!No
Media serviceXmsnmsgxr.exeDetected by Trend Micro as WORM_SDBOT.TFNo
StartKeyXmsnmsie.exeAdded by the BIFROSE.M BACKDOOR!No
MSN MessangerXmsnmsng.exeAdded by the SDBOT.XN WORM!No
Microsoft UpdateXMsnmsngr.exeDetected by Trend Micro as WORM_RBOT.BQS and by Malwarebytes Anti-Malware as Backdoor.BotNo
MSN MessengerXmsnmsngr.exeDetected by Kaspersky as Backdoor.Win32.Assasin.11. The file is located in %Windir%No
Windows SystemXmsnmsngr.exeDetected by McAfee as W32/Gaobot.worm.gen.d and by Malwarebytes Anti-Malware as Backdoor.AgentNo
Live Windows Messenger VersionXmsnmsngrlive.exeAdded by a variant of the IRCBOT BACKDOOR!No
Msn MessengerXmsnmsnr.exeAdded by the BANKER-GG TROJAN!No
msnsmgrXMsnMsr.exeAdded by the LOONY-N TROJAN!No
Winnt DNS identXmsnmsrg.exeAdded by the RBOT.BVQ WORM!No
sysPersonalFirewallXmsnmssgr.exeDetected by Symantec as W32.Spybot.Worm. The file is located in %System%No
WindowsSystem32Xmsnmssgr.exeAdded by the AGENT.ALY BACKDOOR!No
SysmonXmsnmssgs.exeAdded by the SDBOT.FK WORM!No
MSN MessengerXmsnmsxp.exeAdded by the AGOBOT-O WORM!No
Microsoftf DDEs ControlXmsnn.exeAdded by the RBOT-AXT WORM!No
WinUpdate LoaderXmsnnm.exeAdded by the REVCUSS.C TROJAN!No
hotefixXmsnnmaneger.exeDetected by McAfee as W32/Sdbot.wormNo
hotfixXmsnnmaneger.exeDetected by Trend Micro as WORM_WOOTBOT.AFNo
WSAConfigurationXmsnote30.exeAdded by the AGOBOT-KF BACKDOOR!No
MSN P2P ManagerXmsnp2pmgr.exeAdded by the SLENFBOT.YH WORM!No
MSN Protocol Analyzer v0.9UMSNPAnal.exeMSNPAnalyzer surveillance software. Uninstall this software unless you put it there yourselfNo
Windows UDP Control CenterXmsnpd.exeAdded by the SDBOT.EBA BACKDOOR!No
Service DriversXmsnpg.exeDetected by Trend Micro as WORM_RBOT.BMDNo
Current32Xmsnpla.exeAdded by the SDBOT-DIS WORM!No
MSNDreyePluginYmsnplugin.exePlugin required to automatically translate words with Dr.eye International translation softwareNo
Msn UpdaterXmsnplugins.exeAdded by the RBOT-HS WORM!No
Msn Plus UpdaterXmsnplus.exeAdded by the RBOT-MU WORM!No
MSNPlusXmsnplus.exeAdded by the BANKER-DAN TROJAN!No
USB Driverz2Xmsnplus1.exeAdded by the SDBOT-XQ WORM!No
MSN Popup BlockerXmsnpopblck.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
OTkwMDRCNzlCRUFFQzdEQUXmsnprn.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserProfile%No
MS Unix BinaryXmsnq3insller.exeAdded by the RBOT.DXH BACKDOOR!No
Microsoft QMGRXmsnqmgr.exeAdded by the IRCBOT-S TROJAN!No
MsnrXMsnr.exeAdded by the AUTOIT-MB WORM!No
MicrosoftCorpXmsnrmgs.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
MicrosoftNAPCXmsnrmgs.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
MSN RouterXmsnrouter.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
MSN RPC ManagerXmsnrpcmgr.exeAdded by an unidentified WORM or TROJAN! See hereNo
MSN Rx ManagerXmsnrxmgr.exeAdded by an unidentified WORM or TROJAN! See hereNo
HKCUXmsns.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\SystemNo
HKLMXmsns.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\SystemNo
msnsXmsns.exeDetected by Dr.Web as Trojan.AVKill.22042 and by Malwarebytes Anti-Malware as Trojan.BankerNo
MsnServiceXmsns.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %AppData%\%Root%\ProgramDataNo
PoliciesXmsns.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\SystemNo
Windows System GuardXmsns.exeAdded by the DWNLDR-IGD TROJAN!No
LTM2Xmsns6Added by the LITMUS.C BACKDOOR!No
Windows UpdateXmsnsa32.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %CommonFiles%\SystemNo
MsnschedXmsnsched.exeAdded by the RBOT.AVR WORM!No
msnsched2Xmsnsched2.exeAdded by the SPYBOT.NNT WORM!No
msnscr.exeXmsnscr.exeAdded by the CERTIF-P TROJAN!No
ATI AS FilterXmsnse.exeAdded by the RBOT-CCY WORM! Note - modifies the HOSTS file by appending numerous lines, preventing access to the virus cleaning websitesNo
MSN Security AgentXmsnsecure.exeAdded by a variant of the IRCBOT BACKDOOR!No
Microsoft msnseruXmsnseru.exeAdded by the RBOT-APB WORM!No
MicrosoftMessengerXmsnserv.exeDetected by Trend Micro as WORM_DARKER.MNo
Msn ServXmsnserv.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
MSN ServicesXmsnserv.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
MSN User Service!Xmsnserv.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
AdobeReaderProXmsnserve.exeAdded by the SDBOT-AKH WORM!No
Service MonitorXmsnserve.exeAdded by the SPYBOT.YQW WORM!No
Microsoft Svchost local servicesXmsnserver.exeAdded by the RBOT-GPM WORM!No
MSN User ServerXmsnserver.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
AdobeReaderProXmsnservex.exeAdded by the RBOT.AKM BACKDOOR!No
MSN Messenger Service StartupXmsnservice.exeAdded by a variant of the RBOT WORM! See hereNo
Msn Messenger updateXmsnservice.exeAdded by a variant of the IRCBOT BACKDOOR!No
MSN Service!Xmsnservice.exeAdded by a variant of the RBOT WORM! See hereNo
MSN ServicesXmsnservice.exeAdded by the IMPARD-A TROJAN!No
MSNServiceXMSNService.exeAdded by the CARPET.C WORM!No
MSN ServicerXmsnservicer.exeAdded by the SLENFBOT.PQ WORM!No
Microsoft Service InformationXmsnservices.exeAdded by the RBOT.ID WORM!No
MSN User Server!Xmsnservices.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
MSN Settings ManagerXmsnsetmg.exeAdded by an unidentified WORM or TROJAN! See hereNo
MSN SettingsXmsnsettings.exeAdded by the IRCBOT.AWH BACKDOOR!No
windows updateXmsnsever.exeDetected by Sophos as W32/Rbot-AHN and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
MSNXmsnsgr.exeAdded by an unidentified WORM or TROJAN!No
msnsgsXmsnsgs.exeAdded by the CHEUKO-B TROJAN!No
MSN File Sharing WizardXmsnsharewiz.exeAdded by a variant of the IRCBOT BACKDOOR!No
msnshedXmsnshed.exeAdded by the RBOT-YN WORM!No
Microsoft MSN ServicesXmsnsm.exeAdded by the RBOT.ARV BACKDOOR!No
Windows Rundll CenterXmsnsmgr.exeAdded by the AGENT-LLB TROJAN!No
Windows MessengerXmsnsmgs.exeAdded by the RBOT-ANJ WORM!No
Windows Live MessengerXmsnsmsgr.exeAdded by the SCAR.BD TROJAN! Note - the legitimate Windows Live Messenger filename is "msnmsgr.exe"No
Windows UDP Control CenterXmsnsmsgrs.exeAdded by the PUSHBOT.MF WORM!No
SystembootXmsnsngr.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
MSN SoftwareXmsnsoftware.exeAdded by the IRCBOT.AWD BACKDOOR!No
AdobeReaderProXmsnsrcdv.exeAdded by the INJECT-H WORM!No
MicroUpdateXmsnsrg.exeDetected by McAfee as Generic Dropper and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\MSDCSCNo
MSN ServicerXmsnsrv.exeAdded by the SLENFBOT.EJ WORM!No
Win32Xmsnsrv.exeAdded by a variant of W32/Sdbot.wormNo
Sygate Personal FirewallXmsnsrv32.exeDetected by Microsoft as Backdoor:Win32/Rbot.FG and by Malwarebytes Anti-Malware as Backdoor.BotNo
Configuration LoaderXmsnss.exeAdded by the GAOBOT.AUS WORM!No
Microsoft MsnSTXmsnst32.exeAdded by the SPYBOT.WR WORM!No
Msn StartupXmsnstartup.exeAdded by the ARBOT.AA WORM!No
Windows UpdateXmsnsupdate.exeDetected by Sophos as W32/Rbot-AXS and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
Compaq Service DriversXmsnsvc.exeDetected by Trend Micro as WORM_RBOT.BKTNo
msnXmsnsvc.exeDetected by Trend Micro as WORM_SPYBOT.AIWNo
MSN ServiceXmsnsvc.exeAdded by the SLENFBOT.EG WORM!No
MSN User ServiceXmsnsvc.exeAdded by the SLENFBOT.NS WORM!No
Compaq Service DriversXmsnt.exeAdded by the SDBOT.CQL WORM!No
Compaq32 Service DriversXmsnt32.exeDetected by Trend Micro as WORM_RBOT.BVFNo
MS Windows CachePathXmsnull32.exeAdded by the RBOT.AII WORM!No
Windows ms DriversXmsnup32.exeAdded by the SDBOT-AAL WORM!No
MSMessngerXmsnupd.exeAdded by the RBOT-ADY WORM!No
(Default)Xmsnupdate.exeAdded by the RBOT-GWT BACKDOOR! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run & HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
MS Unix BinaryXmsnupdate.exeAdded by the RBOT-AAM WORM!No
Msn Messenger UpdateXmsnupdate.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
MSN UpdatingXmsnupdate.exeAdded by the QHOST.AEI TROJAN!No
Windows Updater ServicesXmsnupdate.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %Root%\RECYCLERNo
Firewall UpdaterXmsnupdateit.exeAdded by the RBOT-AAQ WORM!No
Microsoft Windows UpdaterXmsnupdateit.exeDetected by Sophos as W32/Agobot-RL and by Malwarebytes Anti-Malware as Trojan.MWF.GenNo
MSN Update ClientXmsnupdater.exeAdded by a variant of the IRCBOT BACKDOOR!No
MSN Auto-UpdaterXmsnupdates.exeAdded by the AUTORUN.WORM.GEN WORM!No
Windows UpdateXmsnupdates.exeDetected by Sophos as W32/Rbot-ALK and by Malwarebytes Anti-Malware as Backdoor.IRCBot. Note - this file has nothing to do with Windows updates or MSNNo
MSN Update CfgXmsnupdbt.exeAdded by an unidentified WORM or TROJAN! See hereNo
MSN Update ClientXmsnupdcli.exeAdded by a variant of the IRCBOT BACKDOOR!No
MSN Update ServiceXmsnupdsv.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
MSN File Sharing!Xmsnuser.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
MSN User ServicesXmsnuserv.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
MSN User SvcXmsnusnsvc.exeDetected by Trend Micro as BKDR_IRCBOT.AVVNo
MSN File SharingXmsnusr.exeAdded by the SLENFBOT.AM WORM!No
Microsoft Netview Component v5.1Xmsnv32.exeAdded by the RANDEX.F WORM!No
MSN Video EnhancedUMSNVE.exe"MSN Video Enhanced can play videos that have dramatically improved video quality and sound. It can play the latest high-quality videos at the best possible quality." No longer appears to existNo
System ServiceXmsnwindows.exeAdded by the SPYBOT.YCL WORM!No
Windows UpdateXmsnwinsb.exeDetected by Sophos as W32/Rbot-AAH and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
Microsoft Windows UpdateXmsnwun.exeAdded by the SDBOT-RM WORM!No
strmsnmgrsXmsnxmsgrsc.exeAdded by a variant of W32/Sdbot.worm. The file is located in %System%No
System ServiceXmsnxpexe.exeAdded by the RBOT-AUA WORM!No
AdobeReaderProXmsnxpsp.exeAdded by the RBOT-ASK or RBOT-AUS WORMS!No
Media-XP-Service-Pack3Xmsnzx.exeAdded by the SDBOT-ACW WORM!No
WindowsSystem32Xmsn_kilo.exeAdded by the AGENT.ALY BACKDOOR!No
MSObject32XMSObject32.jsAdded by the PUN TROJAN!No
MSOfficeCfgXmsocfg.exePremium rate adult content dialerNo
QTSvcXmsocfg.exePremium rate adult content diallerNo
SystemServiceXmsocfg.exePremium rate adult content diallerNo
Microsoft OfficeXmsoff.exeAdded by the RAKER-C TROJAN!No
Adobe AcrobatXmsoffice.exeDetected by Malwarebytes Anti-Malware as Trojan.FakeMS. The file is located in %Root%\iexplorer\Office\winuxNo
Microsoft OfficeNMsoffice.exeFeature included with older versions of MS Office giving you access to common Office functions and optional shortcuts to Office (and other) programs. Some people prefer it but a better way is to create desktop shortcuts if you want access these features and programs quickly. Also available via Start → All ProgramsYes
Microsoft Office Shortcut BarNMsoffice.exeFeature included with older versions of MS Office giving you access to common Office functions and optional shortcuts to Office (and other) programs. Some people prefer it but a better way is to create desktop shortcuts if you want access these features and programs quickly. Also available via Start → All ProgramsYes
msofficeXmsoffice.exeAdded by the LIKASIMAL WORM!No
run=Xmsoffice.exeAdded by the ADWARELOADER TROJAN! Note - do not confuse with the legitimate Microsoft Office file, which would typically be located in %Program Files%\Microsoft Office\OfficeNo
MsofficeXmsoffice.htaHijacker - redirecting to Searchdot.netNo
Microsoft Windows UpdateXmsoffice2.exeAdded by the RBOT-GB WORM!No
Microsoft OfficeXmsoffice32.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
msoffwzXmsoffwz.EXEDetected by Sophos as Troj/Bancban-HQNo
Microsoft OfficeXmsoicons.exeAdded by the RBOT-ZI WORM! - NOTE - do no confuse with the legitimate Msoicons.exe file described here. The latter wil not be listed among your startups!No
Microsoft Update MachineXMSOICONS.EXEDetected by Trend Micro as WORM_RBOT.AWS and by Malwarebytes Anti-Malware as Backdoor.BotNo
winlogon.exeXmsole32.exeAdware, also detected as the FAKESPY-B TROJAN!No
M$ONEXmsone.pifDetected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.AgentNo
msmcXmsongn.exeClientMan parasite variantNo
MSOOBDXMSOOBD.EXEAdded by the MAGISTR.A VIRUS!No
msnmsgrsXmsoobe32.exeDetected by Panda as Banbra.GQUNo
msorcvpXmsorcvp.exeDetected by Sophos as Troj/Lydra-UNo
OfficeDeamonXmsorunner.exeAdded by a variant of the TACTSLAY TROJAN!No
SyncManagerXmsorunner.exeAdded by a variant of the TACTSLAY TROJAN!No
VisualStudioXmsorunner.exeAdded by a variant of the TACTSLAY TROJAN!No
mmxrunXmsosa.exeAdded by unidentified malware. The file is located in %Root%\0000000No
OfficeSyncProcessUMSOSYNC.EXEEntry created when you save files to a server (such as SkyDrive) from versions of MS Office. This uses the MS Office Upload Center to keep local and server copies in syncNo
msoupdaterXmsoupdater.exeAdded by the DLOADER.GBD TROJAN!No
winlogin.exeXmspaint.exeAdded by a variant of the AGENT.AH TROJAN!No
MS PaintXmspainter.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
MS-patchXmspatch32.exeDetected by Sophos as W32/Rbot-AWF and by Malwarebytes Anti-Malware as Backdoor.BotNo
Microsoft Procedure CallXMSPCALL.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
Microsoft PCI DeviceXmspci.exeAdded by a variant of WORM_RBOT.BBGNo
Microsoft PCI ManagerXmspci.exeAdded by the RBOT.BBG WORM!No
Windows mplayercodex ServicesXMSPF.EXEAdded by a variant of the SDBOT WORM! This file is located in %System%No
MSWindows SyspgXmspg32.exeAdded by the RBOT-TB WORM!No
COM ServiceXmspgcs.comDetected by Microsoft as Backdoor:Win32/Beastdoor.DL and by Malwarebytes Anti-Malware as Backdoor.BeastDoorNo
mspingXmsping.exeAdded by the FLOODBLACK TROJAN!No
msping.exeXmsping.exeAdded by the BDOOR-MZ BACKDOOR!No
mspluginXmsplugin.exeDetected by McAfee as Generic.tfr and by Malwarebytes Anti-Malware as Trojan.VbkryptNo
MSPLUSXmsplus32.exeAdded by the MYTOB-AM or MYTOB-CL WORMS!No
Windows Registry CheckerXMsPMDPSv.exeAdded by the AGOBOT.APV WORM!No
MSPMirageNMSPMirage.exePart of CyberLink MagicSports - which "is a revolutionary way of watching your sports videos. It automatically detects highlights of the most memorable moments in sports from your recorded games". The exact purpose of this entry is unknown at present but create a shortcut and start it manually before you run MagicSports - which is no longer available from CyberLinkYes
MSPMirage.exeNMSPMirage.exePart of CyberLink MagicSports - which "is a revolutionary way of watching your sports videos. It automatically detects highlights of the most memorable moments in sports from your recorded games". The exact purpose of this entry is unknown at present but create a shortcut and start it manually before you run MagicSports - which is no longer available from CyberLinkYes
MSPServiceNMSPMirage.exePart of CyberLink MagicSports - which "is a revolutionary way of watching your sports videos. It automatically detects highlights of the most memorable moments in sports from your recorded games". The exact purpose of this entry is unknown at present but create a shortcut and start it manually before you run MagicSports - which is no longer available from CyberLinkYes
Registry Value Name StartXMsPMSPSa.exeAdded by a variant of W32/Sdbot.wormNo
CSCRS Value CheckXMsPMSPSd.exeAdded by a variant of W32/Sdbot.wormNo
Doggy StyleXMsPMSPSd.exeAdded by the SDBOT-AAP WORM!No
NVIDIA DriverXMSPMSPSU.EXEAdded by the WOOTBOT.Y WORM!No
Win32 NVIDIA DriverXMSPMSPSU.EXEAdded by a variant of the WOOTBOT.Y WORM!No
Microsoft checkerXMsPMSPTv.exeAdded by a variant of W32/Sdbot.wormNo
Windows Processe ManagerXmspn32.exeDetected by Trend Micro as WORM_RBOT.AXONo
*Mspool32 DriverXmspool32.exeDetected by Malwarebytes Anti-Malware as Trojan.ModifiedUPX. The file is located in %Windir%No
Mspool32 DriverXmspool32.exeDetected by Malwarebytes Anti-Malware as Trojan.ModifiedUPX. The file is located in %Windir%No
Microsoft Proc Driver32Xmsprc.exeAdded by a variant of the WOOTBOT WORM!No
MS Windows Process ClassXMSPRCSS32.exeAdded by the RBOT-YQ WORM!No
DelayLoadXmsprint.exeAdded by a variant of the Win32.Agent.ryo malware - see hereNo
Printing DriverXmsprint.exeAdded by the RBOT.JH WORM!No
MsPrint32DXMsPrint32D.exeAdded by the WINKO.AO WORM!No
Ms Processe ManagerXmsproc.exeAdded by the RBOT.ATO WORM!No
MS Windows procces 32Xmsprocces.exeAdded by the RBOT-AEZ WORM!No
MSprotect.exeXMSprotect.exeAdded by the DABYREV.A VIRUS!No
System-ConfigXmsptmf32.comDetected by Total Defense as Win32.Lioten.FANo
COM ServiceXmspykt.comDetected by McAfee as BackDoor-AMQ and by Malwarebytes Anti-Malware as Backdoor.BeastDoorNo
Internet Security ServiceXmsq23.exeAdded by the RBOT-GQL WORM!No
Internet Security ServiceXmsq32.exeAdded by the RBOT-GFP WORM!No
Internet Mail and NewsXmsqdevl.exeEasySearch adwareNo
Internet Mail and NewsXmsqdevl1.exeAdded by the DLOADR-AWD TROJAN!No
Internet Security ServiceXmsql23.exeAdded by the RBOT-GML WORM!No
msqssrXmsqssr.exeDetected by Kaspersky as the DLUCA.GEN TROJAN!No
MSRXmsr.exeDetected by Trend Micro as WORM_AGOBOT.RTNo
MsrcXMsrc.exeAdded by the KRYPTONIC GHOST TROJAN!No
msrdcXmsrdc.exeAdded by the SDBOT-CXO WORM!No
APIMonXmsreg.exeAdded by the DROPPER.Z TROJAN!No
Online ServiceXmsreg.exeDetected by Kaspersky as Trojan-Clicker.Win32.Small.bhNo
msReg32 LoaderXmsreg32.exeDetected by Trend Micro as WORM_AGOBOT.IUNo
RecycleSTRXmsreg32.exeAdded by the RBOT-TC WORM!No
winlogonXmsreg32.exeAdded by the SDBOT.EO BACKDOOR!No
Video DriverXMsregdrv32.exeAdded by the SPIGOT BACKDOOR!No
msreg.exeXmsrege.exeAdded by the ZINX TROJAN!No
msresearchXmsresearch.exe180SearchAssistant adware relatedNo
Microsoft Windows Updating SystemXmsresource.exeDetected by Sophos as W32/Rbot-EAM and by Malwarebytes Anti-Malware as Trojan.MWF.GenNo
System ServiceXMSREXE.EXEAdded by the AML TROJAN!No
Windows32 Configuration LoaderXmsrf32.exeAdded by the SDBOT-ABX WORM!No
COM ServiceXmsrfrw.comDetected by McAfee as BackDoor-AMQ and by Malwarebytes Anti-Malware as Backdoor.BeastDoorNo
MS Registry ServiceXMSRMS32.exeDetected by Sophos as W32/Rbot-AKPNo
Remote Services ManagerXmsrmsvc.exeAdded by the SLENFBOT.AJ WORM!No
Win INI 32Xmsrp32.exeAdded by the RBOT-FZC WORM!No
msrpcXmsrpc.exeDetected by Sophos as Troj/Lydra-UNo
MS Remote Procedure CallXmsrpc32.exeDetected by Sophos as W32/Rbot-QLNo
MS Remote Procedure Call ServiceXMSRPC32.exeAdded by a variant of W32/Rbot-QLNo
Microsft Remote Procedure DaemonXmsrpcd.exeAdded by a variant of the IRCBOT BACKDOOR!No
MicroSoft Remote Secure ServiceXMSRSS.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
ExplorerXmsrstart.exeAdded by the SOPICLICK TROJAN!No
msrtsvcXmsrtsvc.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData%No
Configuration LoaderXmsrun.exeAdded by the AGOBOT-Y WORM!No
Microsoft Config LoaderXmsrun32.exeAdded by the AGOBOT-DY WORM!No
MSN MessenggerXMsRun32.exeAdded by the IMAUT.CO WORM!No
msrundllXmsrund1l32.exeAdded by the BINGHE TROJAN!No
DllExecutableXMSRunDll32.exeAdded by the VB-SP WORM!No
msrunocx32Xmsrunocx32.exeAdded by the SKUS WORM!No
Msrv32XMsrv32.exeAdded by the AGOBOT-NB BACKDOOR!No
Intec Service DriversXmss.exeAdded by the RBOT-GLU WORM!No
MatrixScreenSaverXmss.exeUnidentified malwareNo
Microsoft security adviserXmssadv.exeMicrosoft Security Adviser rogue security software - not recommendedNo
Security Agent ManagerXmssams.exeAdded by the RBOT-SV WORM!No
mssansong.exeeXmssansong.exeeDetected by McAfee as Generic.tfr and by Malwarebytes Anti-Malware as Spyware.BankerNo
mssaruXmssaru.exeAdded by the AGENT.AM TROJAN! Note - example names include "XviD", "Winamp Remote", "Windows Media Player" and "Futuremark"No
mssc.exeXmssc.exeDetected by Dr.Web as Trojan.DownLoader8.16713 and by Malwarebytes Anti-Malware as Trojan.Agent.MSSNo
REYxNEM2RjFCMzU2NUI4QkXmssc321.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.RH. The file is located in %UserProfile%No
msscan.exeXmsscan.exeMicrosoft Security Adviser rogue security software - not recommendedNo
MSSCDLUMSSCDLL.exeSpyCapture keystroke logger/monitoring program - remove unless you installed it yourself!No
MS System Call FunctionXmsscf32.exeAdded by the RBOT-GBZ WORM!No
RPCXMSschost.exeAdded by a variant of the AGOBOT WORM!No
Mircosoft Sockets SP2Xmssck.exeDetected by Trend Micro as WORM_MYTOB.ETNo
MS Microsoft Socket DeamonXMSSCKD32.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
_AntiSpywareYMssCli.exePart of McAfee AntiSpywareNo
MSNXmsscomd.exeAdded by a variant of the SPYBOT WORM! See hereNo
Microsoft System Service DeviceXmssdh.exeAdded by a variant of the IRCBOT BACKDOOR!No
SysComp?mssdnl.comUnknown but suspect as *.com are not usually run at start up and the name isn't recognizedNo
xzvowsXmssearch.exeDetected by McAfee as Generic Dropper and by Malwarebytes Anti-Malware as Trojan.AgentNo
Microsoft WIN32 SecurityXMSsec32.exeAdded by the RBOT-DOQ TROJAN!No
Windows SysNotifyXmssecc.exeAdded by the AGENT-GFR TROJAN!No
Microsoft Security EssentialsYmsseces.exeSystem Tray access to and notifications for Microsoft Security Essentials which "provides real-time protection for your home PC that guards against viruses, spyware, and other malicious software"Yes
MSCYmsseces.exeSystem Tray access to and notifications for Microsoft Security Essentials which "provides real-time protection for your home PC that guards against viruses, spyware, and other malicious software"No
MSSEYmsseces.exeSystem Tray access to and notifications for Microsoft Security Essentials which "provides real-time protection for your home PC that guards against viruses, spyware, and other malicious software"Yes
mssecesYmsseces.exeSystem Tray access to and notifications for Microsoft Security Essentials which "provides real-time protection for your home PC that guards against viruses, spyware, and other malicious software"Yes
mydocXmsseces.exeDetected by Dr.Web as Trojan.Siggen2.5150 and by Malwarebytes Anti-Malware as Adware.Cinmus. Note - this is not the legitimate Microsoft Security Essentials file of the same name which is normally found in %ProgramFiles%\Microsoft Security Client or %ProgramFiles%\Microsoft Security Essentials. This one is located in %ProgramFiles%\MessengerNo
Microsoft Security SystemXmssecsys.exeAdded by the IRCBOT-WJ TROJAN!No
.mssecureXmssecure.exeAdded by the DDOS_BOXED.X TROJAN!No
secures23Xmssecure.exeAdded by the AGOBOT-ABY WORM!No
SmallAndSecureXmssecure.exeAdded by the RBOT.CU WORM!No
Microsoft Update Security PatchXmssecurityupdatepatch.exeAdded by the AGENT.EF TROJAN!No
MSSERUmsser.exeMeplex adwareNo
msserrv32Xmsserrv32.exeAdded by the STRATION.DW WORM!No
msservXmsserv.exeAdded by the BLACKLOG-A TROJAN!No
msserviceXmsserv.exeDetected by Symantec as W32.Hyd@mmNo
msserv32Xmsserv32.exeAdded by the RBOT-ACK WORM!No
HserviceXmsservice.exeAdded by the AUTORUN-KL WORM!No
MS serviceXmsservice.exeAdded by the RBOT-ZG WORM!No
MSNXmsservice.exeAdded by the IRCBOT-ABZ TROJAN!No
MicrosoftUpdateXMSServx.exeDetected by Sophos as Troj/DwnLdr-GYF and by Malwarebytes Anti-Malware as Trojan.AgentNo
Microsoft Update 32Xmssetup32.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
System UpdateXmssetupconf.exeAdded by the RBOT-BJA WORM!No
SystemTrayXmssgl2.exeAdded by a variant of the IRCBOT TROJAN!No
atiupdateXmsshed32.exeAdded by the DELF.EP downloader TROJAN!No
MSShellXmsshell.exeDetected by Dr.Web as Trojan.DownLoader7.12326 and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%\Microsoft\WindowsNo
MSShellXmsshell.exeDetected by Trend Micro as TROJ_INJECTO.ASL and by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %UserProfile%\WindowsNo
Msshield.exeXMsshield.exeAdded by a variant of the IRCBOT BACKDOOR!No
MSShowXMSShow.exeAdded by the QQROB-M TROJAN!No
MSSHVCXMSSHVC.exeAdded by the NUFFY.A WORM!No
MsWindows SSL DriversXmssl32.exeAdded by the SPYBOT.API WORM!No
superslutXmsslut32.exeAdded by the SLUTER-A WORM!No
Microsoft Security Monitor ProcessXmssm32.exeAdded by a variant of the IRCBOT BACKDOOR!No
Microsoft Security Monitor ProcessXmssm32.exeAdded by a variant of the IRCBOT TROJAN!No
Microsoft UpdateXmssmgrd.exeAdded by the SDBOT.JT WORM!No
MSN MMISSENGERXmssmmspgr.exeAdded by the KELVIR.AJ WORM!No
Microsoft Security Monitor ProcessXmssmp.exeAdded by the RBOT-FUB WORM!No
Microsoft Security Monitor ProcessXmssmpi32.exeAdded by a variant of the RBOT WORM! See hereNo
Microsft Security Monitor ProcessXmssmpp.exeAdded by the SDBOT-DJW WORM!No
Microsft Security Monitor ProcessXmssmppp.exeAdded by a variant of the IRCBOT BACKDOOR!No
0ddeda67f7df140ce2589c17e11d737eXmssn.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserTemp%No
Windowss Service AgentXmssngear.exeAdded by the RBOT.KGU BACKDOOR!No
mssp3Xmssp22.exeAdded by the IBANK-D TROJAN!No
ms spool serviceXmsspooler.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
MSSQLXMssql.exeAdded by the SDBOT BACKDOOR!No
Microsoft Database HandlerXmssql32.exeAdded by the RANDEX.AX WORM!No
MSSQL ManagerXmssqlmgr.exeAdded by the RBOT-BWU WORM!No
MSSQL for Windows NT & XP