| Name | Status | Filename | Description |
|---|
| Money Express | N | moneyexpress.exe | Part of MS Money. Available via Start -> Programs |
| MICROSFT RAMA UPDATE SUPPORT | X | MSN32.EXE | Added by the W32/Rbot-AWJ
WORM!
Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
|
| msccrt | X | msccrt.exe | Troj/PWS-ALA Read the link, steals information |
| MSN Messanger | X | msnmsgsmn.exe | W32/Rbot-FOQ Read the link, allows remote access |
| Matrox Powerdesk | N | PDesk.exe | For Matrox video cards. Quick access to tweak your card to your liking |
| Mspatch69 | X | (path to,trojan) | Added by the MPROX VIRUS! |
| mwsoemon | X | mwsoemon.exe | Added by MyWay An IE Browser Helper Object used by adware WeSearch to add an IE toolbar to provide search features, and hijack browser search requests to its controlling servers run by MyWay. Note: Located in \%Program Files%\MYWEBSEARCH\BAR\5.BIN\ |
| myhuy | X | huy2.exe | Added by the W32/Blaster-L
WORM!
Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
|
| mssfos | X | sfool.exe | Added by the W32.Randex.EUS
WORM!
|
| MSN Configuration | X | msnconfig.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| MSWinupd | X | winupd.exe | Added by the Troj/DwnLdr-GUO TROJAN! Note: This trojan is located in C:\%WINDIR%\System32\ (XP/WinNT/2K) Read the link, allows remote access |
| MailScan Dispatcher | Y | Launch.exe | MailScan Dispatcher splits each e-mail message into various components such as the header, body and attachment. Compressed formats (ZIP, ARJ, etc.) are scanned for viruses and cleaned |
| Microsoft Java Virtual Machine | X | msjvm.exe | Added by a variant of the W32/SDBOT WORM!
|
| Microsoft Update | X | msconfg.exe | Added by the Win32.Rbot.H WORM! |
| Microsoft | X | netsrv.exe | Added by the W32/Rbot-GOS WORM! Note: This worm is located in C:\%WINDIR%\System32\ (XP/WinNT/2K) Read the link, allows remote access |
| msupdates | X | msupdt.exe | Added by a W32/Rbot-JO worm infection |
| Mfc**32.exe (* = random char) | X | Mfc**32.exe (*,= random char) | CoolWebSearch/HomeSearch adware component - for examples, see this log |
| Microsoft AutoUpdater | X | svhost.exe | Added by a RBOT.QG worm infection |
| Microsoft Windows Update Logon | X | win-logon.exe | Added by a variant of the WIN32.RBOT WORM!
|
| McLogLch_exe | N | McLogLch.exe | Related to McAfee_security suite. This is a non-essential program, but should not be disabled unless suspected to be causing problems. Note: Located in C:\Program Files\McAfee\MSC\ |
| Msn Update Manager (Sp2) | X | MSMSGS.EXE | Added by the W32/AGOBOT-NL WORM! |
| Microsoft Update | X | wuamk032.exe | Added by the W32/RBOT-AHD WORM! |
| msconfig.exe | X | uline.exe | Added by a variant of the WIN32.AGENT.AH downloader TROJAN! |
| MutexServiceEx | N | Sys32Smm.exe | Webroot Sofware's discontinued "Privacy Master" |
| Music01 Server | N | Music01,Server.exe | J River Media Jukebox |
| Microsoft Spool 20 Service | X | spool20.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Microsoft Directx click | X | directxclick.exe | Added by a variant of the W32/Rbot-GHT WORM! red]Note: This worm is located in C:\%WINDIR%\ Read the link, rootkit type stealth involved. More here |
| Microsoft Update | X | webm.exe | Added by the SDBOT.WK WORM! |
| MediaMonitor | N | Mediam~1.exe | Installed by Smartdisk MVP CD burning software. Software will work fine without it |
| MicrosoftWindows | X | | MagicSearch - a CoolWebSearch parasite variant, |
| MemoryMeter | X | MemoryMeter.exe | Autoinstalling spyware by Total Velocity |
| Microsoft Servicez Manager | X | servicemgrz.exe | Added by the W32/Rbot-ASN
WORM!
Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
|
| Microsoft Service Host Manager | X | 32svchost.exe | Added by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Microsoft Update 32 | X | mscnfg.exe | Added by the W32/Rbot-ALM
WORM!
|
| MSNPluginSrvcs | X | sagate.exe | Added by the SDBOT.AKJ WORM! |
| MSN Rx Manager | X | msnrxmgr.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Microsoft Genuine Logon | X | msnmsg.exe | Added by the W32/IRCBot-XH Worm Read the link, allows remote access |
| Microsoft Office | X | nxcxtpr.exe | Added by the W32/RBOT-YG WORM! |
| mysvcig38 | X | mysvcc.exe | Added by the W32/Rbot-FOU WORM! This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Microsoft System Checkup | X | ntsysmgr.exe | Added by the W32.Donk.S WORM! |
| Microsoft all | X | mmall.exe | Identified as a variant of the Proxy.Wopla.ac malware. Note: located in \%WINDIR%\ Note: Use SDFix under supervision. |
| msreg.exe | X | msrege.exe | Added by the ZINX VIRUS! |
| My-disgo | U | MyKey disgo.exe | Related to disgo_pro
Program will synchronize data.
|
| Microsoft | X | rundll.exe | Added by the W32/Rbot-GSJ Worm Read the link, allows remote access |
| Microsoft AntiSpyware | X | Bazzi.exe | Added by the AHKER.J WORM! |
| misiCTRL | ? | misiCTRL.exe | Miro video driver related. Is it required? |
| MS Service Drivers | X | winscv.exe | Added by the W32/Sdbot-COG WORM! Note: This worm\trojan is located in C:\%WINDIR%\ |
| moviemk | X | moviemk.exe | Troj/DwnLdr-GTB |
| Microsoft Service Evaluator Engin | X | mssee.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Microsofts Security Manager | X | ****.exe [****,= random char] | Added by the RBOT-WH TROJAN!
|
| mswspl | X | wmplayer.exe, other file,names | Added by a TROJ_SMALL.IQ trojan downloader infection |
| MSN Start | X | msnmsgr7.exe | Added by the W32/RBOT-PH WORM! |
| mousedrv | X | mousedrv.exe | Added by a CRYPTER.A trojan infection
|
| Microsoft Update | X | ms.exe | Added by the BKDR_SDBOT.CC WORM! |
| Microsoft Installshield | X | nundll32.exe | W32/Agobot-AHZ Read the link, allows remote access |