| Status | Autorun name | Command | Description |
| X | MSIMN32 | MSIMN32.EXE | Added by the CWS-M TROJAN! |
| ? | MSIN | MSin.exe | ?? |
| X | Msinet | Msinet.exe | Added by the RBOT-AOA WORM! |
| X | MSInfo | msinfo.exe | Added by the ALADINZ.M TROJAN! |
| X | MSInfo | AVBgle.exe | Added by the NETSKY.O WORM! |
| X | msinfo32msinfo325.1.2600.0.0108171148 | operatingmsinfo32.exe | Added by the TRITE-A WORM! |
| X | MSInstall | smvss.exe | Added by the DEDLER-G TROJAN! |
| X | msisrv | msisrv.exe | Added by the AGENT-IQV TROJAN! |
| X | msjava service | xpcd.exe | Added by the SDBOT.VM WORM! |
| X | msjavadll | jnana.tsa | Added by the JNANABOT TROJAN! |
| X | msjdqs | fddwqt.exe | Added by the SDBOT-PO WORM! |
| U | MskAgent | MskAgent.exe | McAfee SpamKiller - rule-based and list-based spam filter. Available as a stand-alone product or included in older versions of Internet Security and Total Protection |
| U | MskAgentexe | MskAgent.exe | McAfee SpamKiller - rule-based and list-based spam filter. Available as a stand-alone product or included in older versions of Internet Security and Total Protection |
| X | MSKCES32 | [random filename] | Added by the CLONER TROJAN! |
| U | MSKDetectorExe | MSKDetct.exe | Part of McAfee SpamKiller - a rule-based and list-based spam filter |
| X | MSKernel32 | MSKernel32.vbs | Added by the LOVELETTER (I LOVE YOU) VIRUS! |
| X | MSkernel32 | System.exe 4820 | Added by the TUXDER BACKDOOR! |
| U | MSKExe | spamkiller.exe | McAfee SpamKiller - a rule-based and list-based spam filter |
| X | mskj | mskj.exe | Added by the KAEMON TROJAN! |
| X | mskrider | maskrider.dll.vbs | Added by the SOLOW-F WORM! |
| U | MSKServerExe | MSKSrvr.exe | Part of McAfee SpamKiller - a rule-based and list-based spam filter. Appears as a service in XP/2K and under the "Run" registry key in 98/Me |
| X | mslagent | mslagent.exe | Added by the WINTRIM-F TROJAN! |
| X | MSLARISSA | MSLARISSA.pif | Added by the ASSIRAL.B WORM! |
| ? | MSLIB32 | mswatch32.exe | ?? |
| X | msliveupdate | msliveupdate.exe | Added by the AGOBOT.ALT WORM! |
| X | MSLog | MicrosoftLog.exe | Added by a variant of the SDBOT WORM! |
| X | Mslogon lptt01 | mslogon.exe | RapidBlaster variant (in a "mslogon" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | Mslogon ml097e | mslogon.exe | RapidBlaster variant (in a "mslogon" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | msm | msm.scr | Added by the BANKER-EHJ TROJAN! |
| X | msmacro32 | msmacro32.exe | Identified as a variant of the AGENT.QB TROJAN! |
| X | msmacro32 | msmacro64.exe | Added by a variant of the BACKDOOR-DOQ TROJAN! |
| X | MsManager | msmgr32.exe | Added by the YAHA.AF WORM! |
| X | msmanager32 | msmngr32.exe | Added by the RANDON-R (or WOMANIZ.A) WORM! |
| X | msmautoprotect | msmssgs.exe | Added by the BIFROSE-AJ TROJAN! |
| X | msmc | mscpbo.exe | ClientMan parasite variant |
| X | msmc | msgdmf.exe | ClientMan parasite variant |
| X | msmc | msongn.exe | ClientMan parasite variant |
| X | msmc | msmc.exe | ClientMan parasite variant |
| X | msmc | ms****.exe [* = random char] | ClientMan parasite variant |
| X | MSMcAfeee | Avsynmgr32e.exe | Added by the FRAMAR TROJAN! |
| X | MSMcAfeeh | Avsynmgr32h.exe | Added by the FRANGO TROJAN! |
| X | MSMcAfeeS | Avsynmgr32S.exe | Added by the VOLAC or VOLAC.DR TROJANS! |
| X | MSMessnger | msnupd.exe | Added by the RBOT-ADY WORM! |
| X | msMGR | rtkmsg.exe | Added by the SDBOT-BPY WORM! |
| X | Msmgt | msmgt.exe | Total Velocity adware/hijacker |
| X | msmmi | msmmi.exe | Added by the AGENT.RFR TROJAN! |
| X | MSMNTGNT | MSMNTGNT.EXE | Added by the BANKER-IE TROJAN! |
| X | MSMNTJBE | MSMNTJBE.EXE | Added by the BANCOS-EF TROJAN! |
| X | MSMNTJNG | MSMNTJNG.EXE | Added by the GRABER-G TROJAN! |
| X | MSMNTMTS | MSMNTMTS.EXE | Added by the BANKER-GZ TROJAN! |
| X | msmon | msmon.exe | Added by a variant of the GEMA.D TROJAN! |
| X | MsMon32 | MsMon32b.exe | Added by the SDBOT.O BACKDOOR! |
| X | MsMovies | MsMovies.exe | Added by the ALCRA-E WORM! |
| ? | MsmqIntCert | regsvr32 /s mqrt.dll | Microsoft Message Queue Server - Internal Certificate - see here for more info and here for a potential problem. Is it required? |
| X | MSMSGNER | [4-8 random letters].exe | Added by the FOWLDO-GEN TROJAN! |
| X | MSMSGNER | zzgf.exe | Added by the PWS-CCB TROJAN! |
| X | MSMSGNER | fgozmox.exe | Added by the AGENT-EBJ BACKDOOR! |
| X | msmsgr | msmsgss.exe | Detected by Kaspersky as the RBOT.AJJ WORM! |
| N | MSMSGS | msmsgs.exe | Windows Messenger instant messenger utility included with Windows 2K/XP. Available via the Start menu. Go to Windows Messenger → Tools → Options → Preferences and uncheck "Run this program when Windows starts" |
| X | Msmsgs | Msmsgs.exe | Added by the SILLYFDC-AP WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger |
| X | MSMsgs | msmessgs.exe | Added by the SMALL-EW TROJAN! |
| X | msmsgs | msmsgs.exe | Added by the SCLOG-AL TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger |
| X | MSMSGS | winlogon.exe | Added by the BRONTOK-BS WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS |
| X | msmsgs.exe | IEXPLORE.EXE | Added by the VB.FQX TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
| X | MsMsgSrv | msmsgsrv.exe | Added by the CQO TROJAN! |
| X | msmsgss | [path to trojan] | Added by the RANKY.G BACKDOOR! |
| X | msmsgss | msmsgss.exe | Added by the MDROP-CHV TROJAN! |
| X | MSMsgSvc | MSMSGSVC.exe | Browser hijacker, identified by some antiviruses as a variant of the StartPage.QC TROJAN! |
| X | msmsngr | msmsngr.exe | Added by the DOPBOT-B WORM! |
| X | MSN | msmgr.exe | Added by the AUTORUN-BHH WORM! |
| X | msn | system32.exe | Added by the KITRO.A WORM! |
| X | msn | msnmsg.exe | Added by the RBOT-GO WORM! |
| X | MSN | msnmsgs.exe | Added by the RBOT-KL WORM! Note - not to be confused with msmsgs.exe, the well known MSN Instant Messaging application! |
| X | MSN | ctfmoons.exe | Added by the SPYBOT.HI WORM! |
| X | MSN | msnmesengers.exe | Added by the RBOT-ME WORM! |
| X | MSN | MSN.exe | Added by the MINIT WORM! |
| X | MSN | msnmsgr.exe | Added by the MYTOB or MYTOB.B WORMS! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System% |
| X | msn | msnsvc.exe | Added by a variant of the SDBOT WORM! |
| X | MSN | msn16.exe | Added by the SDBOT-VN WORM! |
| X | MSN | msnsgr.exe | Added by an unidentified WORM or TROJAN! |
| X | MSN | install.exe | Added by the AGENT-GDO TROJAN! |
| X | MSN | netstats.exe | Added by the IRCBOT.UXP WORM! |
| X | MSN | scvhost.exe | Added by the IRCBOT-ZW WORM! |
| X | MSN | wdlrss.exe | Added by a variant of the SDBOT TROJAN! |
| X | MSN | wkssvr.exe | Added by the PUSHBOT.S WORM! |
| X | MSN | Fixdriver.exe | Added by the SILLYFDC.BBY WORM! |
| X | MSN | iTuneshelp.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | MSN | lsass32.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | MSN | msscomd.exe | Added by a variant of the SPYBOT WORM! See here |
| X | MSN | systems.exe | Identified as a variant of the Backdoor.PosionIvy keylogging malware |
| X | MSN | taskngr.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | MSN | wkssvrs.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | MSN | wksvr.exe | Added by the IRCBOT-XU WORM! |
| X | MSN | wmev.exe | Added by a variant of the SPYBOT WORM! See here |
| X | MSN | kys7r.exe | Added by the AUTORUN-AR WORM! |
| X | MSN | services51651.exe | Added by the IRCBOT-AAL TROJAN! |
| X | Msn | rundll32.exe ilss32.dll,network | Added by the BANLO-E TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | msn | winlogon.exe | Added by the PROSTI.AA BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Media |
| X | MSN | msnmsgx.exe | Added by the RBOT-PZ WORM! |
| X | MSN | msservice.exe | Added by the IRCBOT-ABZ TROJAN! |