| Status | Autorun name | Command | Description |
| U | Mozy Status | mozystat.exe | Mozy - free backup at a secure, remote location |
| X | MP Services | mpsvc.exe | Added by the WOOTBOT.EQ WORM! |
| X | MP Tcloakss | mptclock.exe | Added by the NACKBOT-B WORM! |
| X | MP Tcloaxs | mptcloaxs.exe | Added by the RANDEX.CT WORM! |
| X | MP Tclockvv | mptclock.exe | Added by the NACKBOT-A WORM! |
| X | MP Tclockvv | mptclock.exe | Added by the NACKBOT-A WORM! |
| X | MP Tclockvv | mptclockvv.exe | Added by the RANDEX.CJ WORM! |
| U | MP_STATUS_MONITOR | monitr32.exe | Cannon Multi-Pass status monitor |
| N | MP3 CD Extractor | CD-Extractor.exe | "MP3 CD Extractor is an audio CD to MP3 ripper which can extract Digital Audio tracks from Audio CDs into files on the hard disk" |
| X | Mp3 Loader | Sysdata.EXE | Added by the AVETTE-A VIRUS! |
| X | MP3Collection | rundll32.exe MSA64CHK.dll,DllMostrar | MatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% |
| X | MP3download | rundll32.exe MSA64CHK.dll,DllMostrar | MatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% |
| X | MP3files | rundll32.exe MSA64CHK.dll,DllMostrar | MatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% |
| X | MP3freeDownload | rundll32.exe MSA64CHK.dll,DllMostrar | MatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% |
| X | MP3freeDownloads | rundll32.exe MSA64CHK.dll,DllMostrar | MatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% |
| X | MP3nice | rundll32.exe MSA64CHK.dll,DllMostrar | MatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% |
| X | MP3Themes | rundll32.exe MSA64CHK.dll,DllMostrar | MatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% |
| X | MP3ToTheMax | rundll32.exe MSA64CHK.dll,DllMostrar | MatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% |
| X | MP4 Player | mp4Player.exe | MP4 Player allows you to view MP4 videos. Marked as undesirable due to the fact that it changes your homepage to a custom Google search engine, changes your browser's default search provider, and runs hidden in the background. Terms of use also state that it collects and tracks urls you visit in order to display relevant ads |
| X | MPatrolPRO | MPatrolPRO.exe | MalwarePatrol Pro rogue security software - not recommended, removal instructions here |
| Y | MPFExe | mpf.exe | McAfee Personal Firewall |
| Y | MPFExe | MpfTray.exe | McAfee Personal Firewall |
| Y | MPFTray | MpfTray.exe | McAfee Personal Firewall |
| X | MPL32 driver | MPL32.exe | Added by the LOONY-M TROJAN! |
| X | MPlay64 | mplay64.exe | Added by the MPLAY64 TROJAN! |
| Y | mpLockDrive | LockDrive.exe | LockDrive from i8 Technologies makes selected folders and drives read only and can be used to prevent users downloading or copying data to portable drives and memory sticks - i.e., USB, Firewire, SATA, ZIP, etc |
| U | MplSetup | MplSetup.exe | Used by Ricoh network printers to enable network printing from the client |
| X | MPM Manager | MPM.exe | Added by the DONBOMB.A TROJAN! |
| X | MPNet | mpn.exe | Added by the DELBOT-W WORM! |
| U | MPower | MPower.exe | MPower from MindBeat. "Defragments and frees your RAM giving more stability to your system and avoiding needless use of swap file. Willl also benchmark (speed test) your hard disk drives and your CPU load". MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind |
| X | mppdds | mppdds.exe | Added by the PWS-AKZ TROJAN! |
| X | mppds | mppds.exe | LEGMIR.AQZ spyware |
| X | MPR MSG | mprmsg32.exe | Added by the MYTOB.CF WORM! |
| X | MPREXE | MPREXE.EXE | Added by the OPASERV.T WORM! Note - this is not the legitimate Mprexe.exe system file |
| Y | MPREXE.exe | mprexe.exe | WIN32 Network Service Interface Process. MPREXE.exe enables the computer to have multiple clients/protocols for networks. There are some problems with it sometimes though - see here. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background. NOTE : sometimes it will appear in start-ups if you have a virus |
| X | MprHTML | MprHTML.exe | Added by a variant of the VAGRNOCKER TROJAN! |
| X | mprocessor | mprocessor.exe | InstallDollars.com foistware |
| U | MPSExe | mscifapp.exe | McAfee.com Privacy Service - "combines personal identifiable information (PII) protection with online advertisement blocking and content filtering" |
| Y | MpsOnn | MpsOnn.exe | Canon printer driver |
| ? | MPT | MPT.exe | ?? |
| X | MPtask Services | mptask.exe | Added by the LALA or AOT TROJANS! |
| N | MPTBox | MPTBOX.EXE | Cannon Multi-Pass toolbox - a button bar |
| X | mptsgsvc.exe | mptsgsvc.exe | Hacker Tool - detected by DiamondCS TDS-3 anti-trojan as "HackTool.Win32.Hidd.j" |
| N | MPXTray | mpxptray.exe | Windows Media Player PowerToy which is run from the taskbar. It can be used to hide Windows Media Player (when in use) and choose various standard buttons (play/pause, next,previous) etc |
| X | mqadscp3 | mqadscp3.exe | Added by the STRATION.CX WORM! |
| X | mqbkup | mqbkup.exe | Added by the OPASERV.K WORM! |
| X | MQT Svc | mqtsvc.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | MqtgSVC | mqtgsvc.exe /waitservice | Added by the HORST.Q TROJAN! Note - this is not the legitimate mqtgsvc.exe which is always located in %System%. This one is located in either %Windir%, %Windir%\System, %Temp%, %AppData%, %AppData%\Microsoft or %System%\drivers |
| X | Mr_CoolFace_Game | Emma.exe | Added by the ROMARIO-A WORM! |
| U | mRouter | mRouterConfig.exe | Configuration for Intuwave's m-Router - "that enables easy connectivity between mobile devices and PCs across Bluetooth, Infrared, USB and serial cable connections". It was licensed and used by the Symbian OS but m-Router is no longer readily available since Intuwave went into administration in 2006 |
| U | mRouterConfig | mRouterConfig.exe | Configuration for Intuwave's m-Router - "that enables easy connectivity between mobile devices and PCs across Bluetooth, Infrared, USB and serial cable connections". It was licensed and used by the Symbian OS but m-Router is no longer readily available since Intuwave went into administration in 2006 |
| X | mrsvctr | mrsvctr.exe | Added by a variant of the SDBOT WORM! |
| Y | MRT | MRT.exe | Microsoft's Malicious Software Removal Tool |
| N | mrtMngr | mrtMngr.exe | Maintenance Release Task Manager for Intuit's QuickBooks or Quicken |
| X | mrtw | mrtw.exe | Fake MSRT rogue security software - not recommended, removal instructions here. This rogue imitates the legitimate Microsoft Malicious Software Removal Tool (MSRT) |
| U | MRU-Blaster Scheduler | scheduler.exe | Scheduler for MRU-Blaster - "a program made to do one large task - detect and clean MRU (most recently used) lists on your computer" |
| N | MRU-Blaster Silent Clean | mrublaster.exe | MRU-Blaster - performs silent cleaning of MRU lists at boot |
| U | MRUBlaster | indexcleaner.exe | MRU-Blaster related - runs once in order to delete the index.dat file in the Temporary Internet Files and/or Cookies folder |
| X | ms | svhost32.exe | Added by the LEGMIR-AQO TROJAN! |
| X | MS Agent Protection | ag1.exe | Added by the IRCBOT.AZ BACKDOOR! |
| X | MS AntiSpyware 2009 | msas2009.exe | MS AntiSpyware 2009 rogue spyware remover - not recommended, removal instructions here |
| X | MS Auto-IPSec Protection | MSASP32.exe | Added by the RBOT-AER WORM! |
| X | MS Autoloader 32 | MSAuto32.exe | Added by the SPYBOT.BD WORM! |
| X | Ms Builders | Wupated.exe | Added by the AGOBOT-SS WORM! |
| X | MS Config | msdconfig.exe | Added by the RBOT-CZH WORM! |
| X | MS Config Loader | svchos1.exe | Added by the AGOBOT.R WORM! |
| X | MS Config Loader | MSWin32bck.exe | Added by the GAOBOT.AA WORM! |
| X | MS Config Loader | svcrhost.exe | Added by a variant of the RBOT WORM! |
| X | MS Config Service | Msloader32.exe | Added by the RBOT-KJ WORM! |
| X | MS Config Stream | msasm.exe | Added by the AGOBOT-BA WORM! |
| X | MS Config v12 | mscfg12.exe | Added by the AGOBOT.YP WORM! |
| X | MS Config v13 | lrbz32.exe | Added by the GAOBOT.AOL WORM! |
| X | MS Config v13 | mscfg13.exe | Added by the AGOBOT.YQ WORM! |
| X | Ms configsu | msconfigsu.exe | Added by a variant of the SDBOT WORM! |
| X | MS Configuration | MSFramer.exe | Added by the RANDEX.OL WORM! |
| X | Ms Configuration | microsoftsa32.exe | Added by the KELVIR.X WORM! |
| X | MS Configuration Utility | msconfig32.exe | Added by the WOOTBOT.DY WORM! |
| X | MS DATABASE | MSDATA32.EXE | Added by a variant of the SDBOT WORM! |
| X | MS Decryption Software | active.exe | MediaTickets adware variant |
| X | MS DirectX Sound Drivers | msdrvdx.exe | Added by the RBOT.BCX WORM! |
| X | MS DLL Library Manager | dllsys64.exe | Added by the RANKY TROJAN! |
| X | MS Domain Name Server Deamon | MSDNSD32.exe | Added by the RBOT-CMZ WORM! |
| X | MS Domain Name System | MSWDNS32.exe | Added by the RBOT-GKY WORM! |
| X | MS Driver Management | [trojan filename].exe | Added by the THROD.A TROJAN! The filename is a random combination the following: ms, svc, win, 16, 32, 64, mes, prn, reg - "ms16prn.exe", for example - and is located in %System% |
| X | MS DVD DirectX Dll Drivers | mdxdl.exe | Added by the SDBOT-XI WORM! |
| X | MS DVD DirectX Sound Drivers | msdrvdx.exe | Added by the SDBOT-XJ WORM! |
| X | MS Explorer | mexplore.exe | Added by the YAHA.AE WORM! |
| X | MS FIREWALL | msfrewall.exe | Added by the SDBOT-PU WORM! |
| X | MS FIREWALL | msfirewall.exe | Added by the SDBOT-QH WORM! |
| X | MS Host | msthost.exe | Added by the SLENFBOT.AH WORM! |
| X | MS Host Manager | ivhost.exe | Added by the RBOT-BJN WORM! |
| X | MS Hosts | msthosts.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | MS HTML | msHtml.exe | Added by the PESTDOOR.31 BACKDOOR! |
| X | MS HTML | mslat.exe | Added by the LATINUS.SVR BACKDOOR! |
| X | MS HTML Location Class | MSHTML32.exe | Added by the RBOT-YD WORM! |
| X | MS Initial | mstinitial.exe | Added by the IRCBOT.ASP BACKDOOR! |
| X | MS Internet Executor 32 | MSIXEC32.exe | Added by the RBOT-AEQ WORM! |
| X | MS Internet Explore | MSIEx.exe | Added by a variant of the RBOT WORM! |
| X | MS Java Applets for Windows NT & XP | javaapplet.exe | Added by the RBOT.BHG WORM! |
| X | MS Java Applets for Windows NT, ME | javaapplets.exe | Added by the VANEBOT-B WORM! |