| Status | Autorun name | Command | Description |
| X | MS-DOS Security Service | ms-dos.pif | Added by the RBOT-AMR WORM! |
| X | MS-DOS Service | MS-DOS.pif | Added by the RBOT-AII WORM! |
| X | MS-DOS Windows Service | MS-DOS.PIF | Added by the RBOT-AJW WORM! |
| X | MS-HTML | [random filename] | Added by the LATINUS.15 BACKDOOR! |
| X | MS-Net | msnet.exe | Added by the RBOT-HZ WORM! |
| X | MS-patch | msconfig32.exe | Added by the RBOT-AUF WORM! |
| X | MS-patch | mspatch32.exe | Added by the RBOT-AWF TROJAN! |
| X | MS-RunKey | arr.exe | MS-Connect dialler/hijacker |
| X | ms[random numbers] | [path to file] | WinBo adware |
| X | ms_anti_spyware | mwfirewall.exe | Added by the GAMQOWI TROJAN! |
| X | ms_anti_spywarebxp | mwfirebpx.exe | Added by the SURILA-D TROJAN! |
| X | ms_anti_spywarebxp | mwfibpx.exe | Added by the SURILA-J TROJAN! |
| X | MS_LARISSA | MS_LARISSA.exe | Added by the ASSIRAL WORM! |
| X | MS_NETD_WIN32 | netd32.EXE | Added by the RANDEX.F WORM! |
| X | MS_SETUP.EXE | MS_SETUP.EXE | Added by the CHARGE TROJAN! |
| X | MS_Update Check | wdfmgr.exe | Added by the AGOBOT-TB WORM! |
| X | MS_update_0704_KB74073.exe | MS_update_0704_KB74073.exe | Added by a variant of the UPDATEKB TROJAN! |
| X | ms2src | ms2src.exe | Added by a TROJAN - see here |
| X | MS32DLL | achi.dll.vbs | Added by the ACHI-A TROJAN! |
| X | MS32DLL | Bha.dll.vbs | Added by the BUTSUR-A WORM! |
| X | MS32DLL | MS32DLL.dll.vbs | Added by the ZODGILA WORM! |
| X | MS32DLL | ffqca.exe | Added by the SDBOT-YD WORM! |
| X | MS7531 | ms7531.exe | Homepage hijacker |
| X | MSACM | msacm.exe | Added by the OPASERV-O WORM! |
| X | msadcheck | msadcheck32.exe | Browser hijacker, redirecting to search-system.com |
| X | msader15ADOR15 | datamsadomd2.70.7713.0.exe | Added by the TRITE-A WORM! |
| X | MSAdmin | jdbgmrg.exe | Added by the DASMIN.A TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here |
| X | MSAgent | mshtm.exe | Browser hijacker - redirecting to buldog-search.com |
| X | MSAgent | hhnt.exe | AGENT.JI spyware |
| X | MSAgentXP | MSAgentXP.exe | Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the REQLOOK.C TROJAN! |
| U | msaim | msaolim.exe | MessageSpy keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | msappts32 | msappts32.exe | Added by the ELBURRO-A TROJAN! |
| Y | MSASCui | MSASCui.exe | Main user interface for Microsoft's Windows Defender on XP/Vista - which "helps protect your computer against pop-ups, slow performance, and security threats caused by spyware and other unwanted software by detecting and removing known spyware from your computer". Used in conjunction with the associated service, this entry is always running and the user also has the option to always display the System Tray icon and monitor/control new startup programs |
| X | MsAudio | explorer.exe | Added by the LEGMIR-BY TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System% |
| X | MsAudio | MsVM_STI.EXE RunDll32 cmicnfg.cpl, CMICtrlWnd | Added by the LEGMIR-BY TROJAN! Note - this is not associated with C-Media based audio which uses a similar command entry (see here) |
| X | msavsc.exe | msavsc.exe | Added by the AGENT.ANQ TROJAN! |
| X | MSbackups | backups.exe | Added by the BANLOAD-TL TROJAN! |
| X | msbb | msbb.exe | 180Search adware |
| X | Msbb.exe | Msbb.exe | Added by the SDBOT.QJ WORM! |
| X | msbcs | msbcs.exe | Added by the DADOBRA-G TROJAN! |
| X | MsBootMgr.exe | MsBootMgr.exe | Added by the VERIFY TROJAN! |
| X | msbsc | [path to trojan] | Added by the BANKER-DF TROJAN! |
| X | msc | msc.exe | MaCatte Antivirus 2009 rogue security software - not recommended, removal instructions here |
| X | msccrt | msccrt.exe | Added by the PWS-ALA TROJAN! |
| U | mscfs | RUNDLL32 [path] cfsys.dll,cfs | AllSum adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "cfsys.dll" file is found in %System%\msibm |
| X | mscheck | rundll32.exe wincheck071008.dll mymain | Added by the AGENT.ADXI TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wincheck071008.dll" file is located in %System% |
| X | mscheck | mscheck.exe | Added by the AGENT-ECP TROJAN! |
| X | mschkdf.exe | mschkdf.exe | Added by a variant of the SDBOT WORM! |
| X | MSChoExE | suge.exe | Added by a variant of the RBOT WORM! |
| ? | msci | mcinfo.exe | McAfee Internet Security related. What does it do and is it required? |
| X | mscj.exe | mscj.exe | Added by the BACKDR-L BACKDOOR! |
| X | MSCJACCELERATOR | bbaka14.exe | Added by the DOWNLOADER-CJD TROJAN! |
| X | mscjm.exe | mscjm.exe | Added by the DOWNLOADER-CJD TROJAN! |
| X | msclac | msclac.exe | Added by the SDBOT-JM WORM! |
| X | msclean | msvchost.exe | Added by the OPANKI-Q WORM! |
| X | mscman | mscman.exe | ClientMan parasite variant |
| X | mscms | mscms.exe | Added by the AGENT-MS TROJAN! |
| U | mscn | mscn.exe | Part of the SafeChildNet internet filtering program - required if you use it |
| X | Mscnt | mscnt.exe | Added by the DLUCA-C TROJAN! |
| X | Mscolour | mscolour.exe | Added by the GEMA TROJAN! |
| X | mscom32 | msint.exe | Added by the SDBOT.CCD BACKDOOR! |
| X | mscom32 | mswin.exe | Added by the PEPA-A WORM! |
| X | MScomm | MScomm.exe | Added by the VBINJEC-AL TROJAN! |
| X | MSCommX | mscommx.exe | Added by a variant of the RBOT WORM! |
| X | Msconf32 | Msconf32.exe | Added by the AGOBOT-NR WORM! |
| X | MSCONFG32.EXE | MSCONFG32.EXE | Added by the OPTIX.04.C TROJAN! |
| X | Msconfig | icpldrvx.exe | Added by the BANLOAD.BFT TROJAN! |
| X | msconfig | msconfig.com | Added by the IRCBOT-SM WORM! |
| X | msconfig | msconfig.bat | Added by the PAHATIA.B WORM! |
| X | MSConfig | lssas.exe | Added by the AUTORUN.CEY WORM! |
| X | MSConfig | xwpwqf.exe | Added by the AGENT-NEW TROJAN! |
| X | MSConfig | oumy.exe | Added by the AGENT-NGD TROJAN! |
| X | MSConfig | prrvtqi.exe | Added by the AGENT-NPH TROJAN! |
| X | MSConfig | mapwisl.exe | Added by the PALEVO.NXS WORM! |
| N | MSConfig | msconfig.exe | Entry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP) |
| X | MSConfig | MSCONFIG32.EXE | Added by the SPYBOT.B WORM! |
| X | msconfig | msconfig.exe | CoolWebSearch MSConfig parasite variant. Note - this overwrites the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting |
| X | msconfig | msconfig.exe | Added by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrun |
| X | msconfig | wins.exe | Added by the RBOT.PF WORM! |
| X | MSConfig | MSCONFIG35.EXE | Added by a variant of the SPYBOT WORM! |
| X | msconfig | scvhost.exe | Added by the AGENT-DSF TROJAN! |
| X | msconfig | winlog.exe | Added by the IRCBOT-TJ TROJAN! |
| X | Msconfig lptt01 | msconfig.exe | RapidBlaster variant (in a "msconfig" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not the valid Windows Msconfig which has the same executable name |
| X | MSConfig Manager | msupdate.exe | CoolWebSearch parasite variant |
| X | Msconfig ml097e | msconfig.exe | RapidBlaster variant (in a "msconfig" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not the valid Windows Msconfig which has the same executable name |
| X | msconfig service | MSupdate32.exe | Added by a variant of the SPYBOT WORM! |
| X | msconfig. | msconf.exe | Added by the BUZUS-AY WORM! |
| X | msconfig.exe | proxy.exe | Added by a variant of the AGENT.AH TROJAN! |
| X | msconfig.exe | uline.exe | Added by a variant of the AGENT.AH TROJAN! |
| X | msconfig38 | mssvcc.exe | Added by the RBOT-BJV WORM! |
| X | MSConfig45 | MSConfig45.exe | Added by the SDBOT.OJ BACKDOOR! |
| X | Msconfige | solari.exe | Added by the AUTORUN-GU WORM! |
| X | MSConfigr | jdbgmrg.exe | Added by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here |
| N | MSConfigReminder | msconfig.exe | Entry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. This particular entry is specific only to 98/Me and is located in %System% |
| X | MsConfigs | MsConfigs.exe | Added by the ALCAN.A WORM! |
| X | MSConfigs | RUNDLL64.dll.vbs | Added by the WEKODE-B WORM! |
| X | msconfigurator | ctfsdk.exe | Added by the DELF-ALS TROJAN! |
| X | MSControl28 | crsss.exe | Added by the SPYBOT.AJX WORM! |
| X | MSControl31 | winnsyst.exe | Added by the RBOT.CFY WORM! |
| X | MSControl3d1 | isasse.exe | Added by the RBOT.CGU WORM! |