| Name | Status | Filename | Description |
|---|
| Microsoft Update | X | wserv32.exe | Added by the RBOT.AF WORM! |
| Microsoft Config 32bit | X | mscnfg32.exe | Added by the W32/RBOT-Z WORM! |
| MoneyStartUp10.0 | N | Activation.exe | Part of MS Money 2002. Available via Start -> Programs |
| Microsoft Spool 25 Service | X | spool25.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| MsVBdll | X | MsVBdll.pif | Added by the W32.Aimdes.A WORM! |
| MPFExe | X | mcagent.exe | Added by the TROJ/ANTIMCA-A TROJAN! - do NOT confuse with the McAfee VirusScan executable as described here |
| msrunocx32 | X | msrunocx32.exe | Added by the SKUS VIRUS! |
| MSN Messenger 32 | X | msniu.exe | Added by the W32/Rbot-AWB
WORM!
Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
|
| Microsoft Updates | X | svdhost.exe | Added by the W32/Rbot-GVH WORM! Read the link, allows remote access Note: Located in \%WINDIR%\System32\ |
| Mcafee Auto Protect | X | mcafeshield.exe | Added by the W32/RBOT-UH WORM! |
| mousebut | X | mousebut.exe | Added by a CRYPTER.A trojan infection
|
| Microsoft Manage Services | X | sychost.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Microsoft Internet Syncing | X | inetsync.exe | Added by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| m4n70s Personal Firewall | X | m4n70s.exe | Added by a variant of the W32.SPYBOT WORM!
|
| MsWinVgr | X | msvgr.exe | Added by the W32.Mytob.LE
WORM!
Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
|
| mspwr | U | pupxpman.exe | Related to Ashampoo's PowerUp XP
|
| MSN Manager | X | usnmsn.exe | Added by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Microsoft WinRaR | X | winrar.exe | Added by the W32/Rbot-AEC
Worm! |
| MonitorSD | U | SDMonitor.exe | Spyware Detector, Adware/Spyware remover - initially considerered a "rogue" program. The latest version has since apparently mended its ways: see note |
| Microsoft NT Drivers | X | ntdrv.exe | Added by the Backdoor.SdBot.ajn reported by ewido, TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Microsoft Service | X | microhost.exe | Added by a W32/Rbot-LC worm infection |
| msdir32 | X | msdir32.bat | VBS/Rookie-A |
| Microsoft msnseru | X | msnseru.exe | Added by the W32/Rbot-APB
WORM!
Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. |
| Microsoft Win Corp TLS Verification | X | mswintls.exe | Added by the W32/Rbot-GCT WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) The hosts file may be modified. |
| Media Server | X | msdts.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| MPatrolPRO | X | MPatrolPRO.exe | Added by the Malware_Patrol_Pro a rogue anti-spyware program. Note: Located in \%Program Files%\MPatrolPRO\ Note: Use Malwarebytes RogueRemover tool. |
| MagicLinker3 | U | MagicLnk.exe | ThaiSoftware Thai Dictionary |
| Msn Patch | X | msndp.exe | Added by the RBOT.AAI WORM! |
| MGA Quickdesk | N | MGAQDESK.EXE | For Matrox video cards. Quick access to tweak your card to your liking |
| Microsoft Cab Manager | X | exec.exe | Affilred.B adware |
| mppds | X | mppds.exe | Added by the TSPY_LEGMIR.AQZ TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ steals information, typically account names and passwords, related to certain online games. |
| MusIRC | X | musirc4.71.exe | Added by the RANDEX.Q WORM! |
| Microsoft Update 32 | X | mscnfg.exe | Added by the W32/Rbot-ALM
WORM!
|
| MotMon | U | motmon.exe | Found on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it\'s not required |
| Macfee Security Patch | X | Mpfsheild.exe | Added by the W32/RBOT-NP WORM! |
| McAfee Online virus Scanner | X | avp.exe | Added by the RBOT-GCV WORM! Not to be confused with AOL's Active Virus Shield (by Kaspersky)
|
| Microsoft IPC | X | svshost.exe | Added by an unidentified VIRUS! |
| Microsoft Dll Management | X | windll.exe | Added by the W32/RBOT-MT WORM! |
| Microsoft Dll | X | runapidll.exe | Added by the W32/Rbot-GRG Worm Read the link, allows remote access |
| Microsoft Update Machine | X | lsasse.exe | Added by the W32/RBOT-DI WORM! |
| msdefender.exe | X | msdefender.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Modeminf | X | Modeminf.exe | Added by a CRYPTER.C trojan variant infection |
| Micrsoft CFG 32 | X | lrbzus32.exe | Added by a variant of the AGOBOT/GAOBOT WORM!
|
| MSSHVC | X | MSSHVC.exe | Added by the NUFFY.A VIRUS! |
| Microsoft Windows Update | X | spools.exe | WORM_SDBOT.TD
|
| Microsoft Windows Updater | X | TMNTSrv.exe | Added by a variant of the WIN32.RBOT WORM!
|
| Microsoft Update 33 | X | init.exe | Added by W32/Rbot-ATT WORM! |
| Mscnt | X | mscnt.exe | Added by the Troj/Dluca-C TROJAN! |
| Microsoft Update | X | wuamgrd3.exe | Added by the W32/Rbot-AMC
WORM!
|
| Microsoft Update 32 | X | neta.exe | Added by the W32/Rbot-AMI WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| MSupdater.exe | X | N/A | CoolWebSearch parasite related. |
| Microsoft Update Machine | X | memstat.exe | Added by the W32/RBOT-OM WORM! |
| Microsoft Windows XP Configuration Loader | X | m32svco.exe | Added by the http://vil.nai.com/vil/content/v_132310.htm" target= blank>SDBOT.WORM!.48548 WORM!
|
| Music01 Server | N | Music01,Server.exe | J River Media Jukebox |
| msmc | X | ms****.exe (*,= random char) | ClientMan parasite variant |