| Status | Autorun name | Command | Description |
| X | msnmsgq32 | msnmsgq.exe | Added by the TACTSLAY.F TROJAN! |
| X | msnmsgq32 | sssasasb32.exe | Added by the TACTSLAY.F TROJAN! |
| N | msnmsgr | msnmsgr.exe | Windows Live Messenger or the older MSN Messenger utility - available via the Start menu. For Windows Live Messenger, disable by clicking on the "Show menu" icon and select Tools → Options → Sign In → deselect "Automatically run Windows Live Messenger when I log on to Windows". For MSN Messenger, disable by clicking on Tools → Options → General → deselect "Automatically run Messenger when I log on to Windows" |
| X | MsnMsgr | MsnMsgrs.exe | Added by the NETSKY.AD WORM! |
| X | MsnMsgr | msnmsgr.exe | Added by the ANNEW-FAM WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System% |
| X | Msnmsgr.exe | lsass.exe | Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root directory (i.e. C:\ or D:\) |
| X | msnmsgr32-.exe | msnmsgr-.exe | Added by a variant of the SPYBOT WORM! |
| X | MSNMSGR5 | MSNMSGR5.exe | Added by the RBOT.PQ WORM! |
| X | MSNMSGRE | swef.bat | IRC backdoor TROJAN or WORM! |
| X | MSNMSGRR | swin.bat | IRC backdoor TROJAN or WORM! |
| X | MSNMSGRS | swe.bat | IRC worm or backdoor trojan! |
| X | MSNMSGRS | swiss.bat | IRC worm or backdoor trojan! |
| X | msnmsgrs | msoobe32.exe | Added by the BANBRA.GQU TROJAN! The file is typically located in %UserProfile%\InstallShield Installation Information\{A5BA14E0-7384-5991B8648CBE70A4} |
| X | MSNMSGRS1 | swed.bat | IRC backdoor TROJAN or WORM! |
| X | msnmsgs.exe | msnmsgs.exe | Added by the BANKER-HK TROJAN! Note - not to be confused with msmsgs.exe, the well known MSN Instant Messaging application! |
| X | msnmsgsgs | msnmsgsgs.exe | Added by the "Catal" alias Spy.Delitall.B backdoor TROJAN! |
| X | msnmsgy | [path to file] | Added by the BANKER-EQ TROJAN! |
| X | msnnt | winampb.exe | Chinese originated adware - detected by Kaspersky as the AGENT.TL TROJAN! |
| X | msnnt | winampf.exe | Added by the SMALL.DTS TROJAN! |
| X | msnnt | winampa.exe | Added by the SMALL.DTS TROJAN! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of %ProgramFiles% whereas this file is located in %Windir% |
| X | MSNPluginSrIvcs | n3vasap23.exe | Added by a variant of the RBOT WORM! |
| X | MSNPluginSrvcs | p6.exe | Added by the SDBOT.AKJ or RBOT-VJ WORMS! |
| X | MSNPluginSrvcs | sagate.exe | Added by the SDBOT.AKJ WORM! |
| X | MSNPlus | msnplus.exe | Added by the BANKER-DAN TROJAN! |
| X | Msnr | Msnr.exe | Added by the AUTOIT-MB WORM! |
| X | MSNS PLUS XP2 | msdupd.exe | Added by the RBOT-BCE WORM! |
| X | msnsched2 | msnsched2.exe | Added by the SPYBOT.NNT WORM! |
| X | msnscr.exe | msnscr.exe | Added by the CERTIF-P TROJAN! |
| X | MSNService | MSNService.exe | Added by the CARPET.C WORM! |
| X | msnsgs | msnsgs.exe | Added by the CHEUKO-B TROJAN! |
| X | msnshed | msnshed.exe | Added by the RBOT-YN WORM! |
| X | msnsmgr | MsnMsr.exe | Added by the LOONY-N TROJAN! |
| X | Msnsock | [malware filename] | Added by the BANKER.RQ TROJAN! The most common filename is "msnmnns.exe" which is found in %ProgramFiles% |
| N | msnsyslog | msnappm.exe | Related to Messenger Applications. When you uninstall the trial version the msnappm keeps saying (You have xx days left) this is adware and it very annoying |
| X | MSNSysRestore | pc32.exe | Added by a variant of the MASTAK VIRUS! |
| X | msnToolbaar | msnmsgesc.exe | Added by the RBOT.BMF WORM! |
| X | msnupdt | kolie.exe | Added by a variant of the RBOT WORM! |
| X | MsnWin | messagewin.exe | Added by the BANCBAN-D TROJAN! |
| X | MSObject32 | MSObject32.js | Added by the PUN TROJAN! |
| X | MSODESNV7 | msvmiode.exe | Added by the INJECT-NW TROJAN! |
| X | Msoffice | msoffice.hta | Hijacker - redirecting to Searchdot.net |
| X | MSOffice | services.exe | Added by the DLOADER-EU TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an "MSOffice" subfolder |
| X | msoffice | msoffice.exe | Added by the LIKASIMAL WORM! |
| X | MSOffice32 | msjcf.exe | Added by the RAKER-A TROJAN! |
| X | MSOfficeCfg | msocfg.exe | Premium rate adult content dialer |
| X | MSOfficeCfg | navchk.exe | Premium rate adult content dialer |
| X | MSOfficeCfg | qservice.exe | Premium rate adult content dialer |
| X | MSOfficeCfg | shman.exe | Premium rate adult content dialer |
| X | MSOfficeCfg | ssvr.exe | Premium rate adult content dialer |
| X | msoffwz | msoffwz.EXE | Added by the BANCBAN-HQ TROJAN! |
| X | msoft-updater23 | mssysstems.exe | Added by the RBOT-ATU WORM! |
| X | msoft-updater23 | slssystem.exe | Added by the RBOT-ASR WORM! |
| X | MSOleath32 | winss.exe | Added by the KATHER TROJAN! |
| X | MSOOBD | MSOOBD.EXE | Added by the MAGISTR.A VIRUS! |
| X | msoupdater | msoupdater.exe | Added by the DLOADER.GBD TROJAN! |
| X | mspaint.exe | check32.exe | Added by the AGENT.AH TROJAN! |
| X | Mspatch69 | [path to trojan] | Added by the MPROX TROJAN! |
| X | Mspatch89 | cnqmax.exe | Added by the RANDEX.P WORM! |
| X | MSPetServ | PET32.EXE | Added by the IRCBOT-VE WORM! |
| X | msping | msping.exe | Added by the FLOODBLACK TROJAN! |
| X | msping.exe | msping.exe | Added by the BDOOR-MZ BACKDOOR! |
| X | MSPluginSrvc | p3.exe | Added by the RBOT-WV WORM! |
| X | MSPLUS | msplus32.exe | Added by the MYTOB-AM or MYTOB-CL WORMS! |
| N | MSPMirage | MSPMirage.exe | Part of CyberLink MagicSports - which "is a revolutionary way of watching your sports videos. It automatically detects highlights of the most memorable moments in sports from your recorded games". The exact purpose of this entry is unknown at present but create a shortcut and start it manually before you run MagicSports - which is no longer available from CyberLink |
| N | MSPMirage.exe | MSPMirage.exe | Part of CyberLink MagicSports - which "is a revolutionary way of watching your sports videos. It automatically detects highlights of the most memorable moments in sports from your recorded games". The exact purpose of this entry is unknown at present but create a shortcut and start it manually before you run MagicSports - which is no longer available from CyberLink |
| X | MSPP System Update 64 | wiaadmgr.exe | Detected by Kaspersky as the RANKY.GEN TROJAN! |
| X | MSPQFile | MSA****.TMP [* = random char] | Homepage hijacker |
| X | MsPrint32D | MsPrint32D.exe | Added by the WINKO.AO WORM! |
| X | MSPRO32 | [path to worm] | Added by the IBERIO WORM! |
| X | MSPRO32 | pnp.exe | Added by the ZOTOB.O WORM! |
| X | MSprotect.exe | MSprotect.exe | Added by the DABYREV.A VIRUS! |
| N | MSPService | MSPMirage.exe | Part of CyberLink MagicSports - which "is a revolutionary way of watching your sports videos. It automatically detects highlights of the most memorable moments in sports from your recorded games". The exact purpose of this entry is unknown at present but create a shortcut and start it manually before you run MagicSports - which is no longer available from CyberLink |
| U | mspwr | pupstman.exe | "Transparent icon background" feature of Ashampoo'sPowerUp XP (WinNT/2K/XP) and PowerUp Deluxe (Win98/Me) |
| U | mspwr | pupxpman.exe | Related to Ashampoo's PowerUp XP |
| U | mspwr | pwrupst.exe | Ashampoo's PowerUp XP is a "tool for fine-tuning your Windows NT4, 2000, 2003 Server and XP configuration" |
| U | mspwr | PuXpMan2.exe | System Tray access to the Ashampoo® PowerUp XP Platinum 2 tweaking utility from Ashampoo GmbH & Co. KG - which includes (amongst others) one-click tuning, multiple desktops, taskbar control center and an autostart manager |
| U | MSPY2002 | ImScInst.exe | Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails, documents and other files - should you need to. Found on PCs where these languages have been installed through the Regional and Language options icon in the Control Panel |
| X | msqssr | msqssr.exe | Detected by Kaspersky as the DLUCA.GEN TROJAN! |
| X | MSR | msr.exe | Added by the AGOBOT.RT WORM! |
| X | Msrc | Msrc.exe | Added by the KRYPTONIC GHOST TROJAN! |
| X | msrdc | msrdc.exe | Added by the SDBOT-CXO WORM! |
| X | msreg.exe | msrege.exe | Added by the ZINX TROJAN! |
| X | msReg32 Loader | msreg32.exe | Added by the AGOBOT.IU WORM! |
| X | MSREGIT | Msgp.exe | Added by the KRYPGHOS.13 BACKDOOR! |
| U | MSRegScan | SGP.exe | SpyGator surveillance software. Uninstall this software unless you put it there yourself |
| U | MSRegScan | SSDemo.exe | SupremeSpy surveillance software. Uninstall this software unless you put it there yourself |
| U | MSRegScan | ETNKL.exe | ComKeylogger surveillance software. Uninstall this software unless you put it there yourself |
| U | MSRegScan | KSPDemo.exe | KeyStalker PRO surveillance software. Uninstall this software unless you put it there yourself |
| U | MSRegScan | DDSSDemo.exe | SystemSleuth surveillance software. Uninstall this software unless you put it there yourself |
| U | MSRegScan | ESP+.exe | ESP surveillance software. Uninstall this software unless you put it there yourself |
| U | MSRegScan | ESPDemo.exe | Eye Spy Pro surveillance software. Uninstall this software unless you put it there yourself |
| U | MSRegScan | SBPDemo.exe | SpyBoss Pro surveillance software. Uninstall this software unless you put it there yourself |
| U | MSRegScan | YEKPND.exe | EyeCandy Computer Monitor surveillance software. Uninstall this software unless you put it there yourself |
| U | MSRegScan | YKPND.exe | YKPMD surveillance software. Uninstall this software unless you put it there yourself |
| X | MSRegSvc | regsvc32.exe | Homepage hijacker that changes your homepage to an adult content site |
| X | msresear | [path to trojan] | Added by the WEASYW-B TROJAN! |
| X | msresearch | msresearch.exe | 180SearchAssistant adware related |
| X | msresearch | tool3.exe | Spy Sheriff/SpywareNO malware, also detected as the SPYHOAX-A TROJAN, pretends to be a spyware remover! - file names spotted sofar include VXH8JKDQ2.EXE, NS6281400.so, CVXH8JKDQ2.EXE, down3.exe, sefe.exe, winstall.exe, and tool2.exe |
| X | msrundll | msrund1l32.exe | Added by the BINGHE TROJAN! |
| X | msrunocx32 | msrunocx32.exe | Added by the SKUS WORM! |