| Status | Autorun name | Command | Description |
| X | Mss Serv | msssrv.exe | Added by the SLENFBOT.AA WORM! |
| X | Mss VC | mssvc.exe | Added by the OPANKI.AB WORM! |
| X | mssaru | mssaru.exe | Added by the AGENT.AM TROJAN! Note - example names include "XviD", "Winamp Remote", "Windows Media Player" and "Futuremark" |
| X | msscan.exe | msscan.exe | Microsoft Security Adviser rogue security software - not recommended |
| U | MSSCDL | MSSCDLL.exe | SpyCapture keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | mssdbsrv | msupdtck.exe | Added by a variant of a password stealing TROJAN! |
| Y | MSSE | msseces.exe | System Tray access to a notifications from Microsoft Security Essentials which "provides real-time protection for your home PC that guards against viruses, spyware, and other malicious software" |
| Y | msseces | msseces.exe | System Tray access to a notifications from Microsoft Security Essentials which "provides real-time protection for your home PC that guards against viruses, spyware, and other malicious software" |
| X | mssend | svcnost.exe | Added by the HRUP-C MALWARE! |
| U | MSSER | msser.exe | Meplex adware |
| X | msserrv32 | msserrv32.exe | Added by the STRATION.DW WORM! |
| X | msserv | msserv.exe | Added by the BLACKLOG-A TROJAN! |
| X | msserv | lvsrev.exe | Added by the BROWMON-B TROJAN! |
| X | msserv32 | msserv32.exe | Added by the RBOT-ACK WORM! |
| X | MsServer | msfun80.exe | Added by the VB-CYG WORM! |
| X | MSServer | Rundll32.exe [random].dll,#1 | Unidentified malware! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The file is typically found in either %System% or the Windows "Temp" folder |
| X | MsServer | msfir80.exe | Added by the VB-CYJ TROJAN! |
| X | msservice | msserv.exe | Added by the HYD WORM! |
| X | MSService_v1.0 | realsched.exe | EHU adware. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name which is normally located in %ProgramFiles%\Common Files\Real\Update_OB. This one is located in %System% or %Temp% |
| X | MSService_v1.0 | vfp02.exe | NewWeb adware |
| X | msservices | services.exe | MsnSpyMaster surveillance software. Uninstall this software unless you put it there yourself! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an "msystem" sub-directory |
| X | mssfos | sfool.exe | Added by the RANDEX.EUS WORM! |
| X | MSSGisg | [path to file] | Added by the RANKY.N TROJAN! |
| X | Msshield.exe | Msshield.exe | Added by a variant of the IRCBOT TROJAN! |
| X | MSShow | MSShow.exe | Added by the QQROB-M TROJAN! |
| X | MSSHVC | MSSHVC.exe | Added by the NUFFY.A WORM! |
| X | mssonfig | winupdate.exe | Added by a variant of the SDBOT WORM! |
| X | mssoul | msmscc2.exe | Added by the DAPIZL.A banker WORM! (A "banker worm" is designed to pillage banking information and send it back to the perpetrators!) |
| X | mssoul | msmscc.exe | Added by the BANCOS.HKT TROJAN! |
| X | mssp3 | mssp22.exe | Added by the IBANK-D TROJAN! |
| X | MSSQL | Mssql.exe | Added by the SDBOT TROJAN! |
| X | MSSQL for Windows NT & XP | mssqlsnt.exe | Added by a variant of the SDBOT WORM! |
| X | MSSQL Manager | mssqlmgr.exe | Added by the RBOT-BWU WORM! |
| X | mssrv32 | mssrv32.exe | Added by the AGENT-NKX TROJAN! |
| N | mssSort | msssort.exe | Maxtor (now Seagate) "Drag and Sort" for their external storage - "Just drag documents onto the Shared Storage II icon and Maxtor's Drag and Sort organizes your files, placing them in appropriate shared folders" |
| X | Msstart | msstart.exe | Added by the LIVUP.C BACKDOOR! |
| X | MSStartOptimizer | Iexpres.exe | Added by the DASMIN-E TROJAN! |
| X | MSStartOptimizer | WINUPD.EXE | Added by the DASMIN-E TROJAN! |
| X | MSStartOptimizer | SCVHOST.EXE | Added by the DASMIN-E TROJAN! |
| X | msstask | msstask.exe | Added by the MYPARTY WORM! |
| X | mssurfer lptt01 | mssurfer.exe | RapidBlaster variant (in a "surfer" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | mssurfer ml097e | mssurfer.exe | RapidBlaster variant (in a "surfer" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | mssvc | [path to trojan] | Added by the PSK TROJAN! |
| X | MSSVC | svcsys.exe | Added by the FATOOS-C TROJAN! |
| Y | MSSVC.EXE | MSSVC.EXE | StealthDisk - hides folders, files and applications. Will also encrypt them for better protection |
| X | mssvc32 | mssvc32.exe | Added by the AGOBOT-ME WORM! |
| X | mssync20 | mssync20.exe | Added by the LDPINC-QC TROJAN! |
| X | mssys | mssys.exe | Added by the MYSS.B TROJAN! |
| X | mssysint | Iexplore .exe | Added by the PWSTEAL.ABCHLP and PSPIDER.310.B TROJANS! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the ".exe" |
| X | mssysint | comime.exe | Added by the NETSNAKE-I TROJAN! |
| X | mssyslanhelper | msmsgri32.exe | Added by the RANDEX.D WORM! |
| X | MsSystem | msdos.exe | Adult content downloader - see here |
| X | MsSystem | mssys.exe | Added by the VANTA.A TROJAN! |
| X | MSSYSTEM | svcsys.exe | Added by the FATOOS-C TROJAN! |
| U | Mstapi | Mstapi.exe | Keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | Mstask | mstask.exe | Added by the OPASERV.N WORM! Note - this is not the legitimate mstask.exe system file and the executable resides in %Windir% |
| X | mstask | mstask.exe | Browser hijacker - redirecting to find-more.net. Note - this is not the legitimate mstask.exe system file |
| X | MSTask | run_dll.exe | Yuupsearch adware |
| X | MStask | svchost.exe | Added by the LDPINCH-BV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | MsTask | wstask32.exe | Added by the MYTOB-FE WORM! |
| X | Mstask | kernel32.exe | Added by the STAP-C WORM! |
| X | Mstask | MSDTC.exe | Added by the STAP-D WORM! |
| X | MSTask Monitor | mstaskmon.exe | Added by the SDBOT-LU WORM! |
| X | Mstask32driver | Mstask32.exe | Added by the LOONY-D TROJAN! |
| X | MSTaskbar 32 | tbsvc32.exe | Added by the RBOT.BQZ WORM! |
| X | mstasks | mstasks.exe | Added by the MULTIDR-AY TROJAN! |
| ? | Mstcgww | MSTCGWW.EXE | ?? |
| X | mstds.exe | mstds.exe | Added by the IPTABLES TROJAN! |
| X | mstg32.exe | mstg32.exe | Added by the AGENT.BI TROJAN! |
| N | MSTMON_N | MSTMON_N.EXE | Generates an error message on startup if a Konica Minolta printer is not turned on and ready |
| N | MSTMON_Q | MSTMON_Q.exe | Generates an error message on startup if the Konica Minolta PagePro 1350W printer is not turned on and ready |
| X | Mstng32 | MSTng32.exe | Added by the TANG WORM! |
| X | MSTray | rundll.exe | Added by the BAMER-B TROJAN! Note - this is NOT the Win9x/Me system file of the same name as described here |
| X | Mstsc | mstsc.exe /waitservice | Added by the HORST.Q TROJAN! Note - this is not the legitimate mstsc.exe which is always located in %System%. This one is located in either %Windir%, %Windir%\System, %Temp%, %AppData%, %AppData%\Microsoft or %System%\drivers |
| X | mstsdsc.exe | mstsdsc.exe | Added by the CIMUZ-CD TROJAN! |
| X | msupd | msupd.exe | Added by the IEACCESS DIALER! |
| X | MSUpdate | wupd.exe | Added by the ALADINZ.M TROJAN! |
| X | MSUpdate | svchosthlp.exe | Added by the BLASTER.T WORM! |
| X | msupdate | msupdate.exe | Added by the RBOT-MZ WORM! |
| X | MSUpdate | criticalUpdate.exe | Affilred adware |
| X | Msupdate | Update.exe | Added by the RBOT-AUC WORM! |
| X | Msupdate | expIorer.exe | Added by the TACTSLAY.A TROJAN! Note that the filename has a capital "i" in it |
| X | Msupdate | outIook.exe | Added by the TACTSLAY.A TROJAN! Note that the filename has a capital "i" in it |
| X | Msupdate | svchosts.exe | Added by a variant of the TACTSLAY TROJAN! |
| X | Msupdate | svcrhost.exe | Added by the TACTSLAY.A TROJAN! |
| X | Msupdate | svcshost.exe | Added by the TACTSLAY.A TROJAN! |
| X | MSupdate.exe | N/A | CoolWebSearch parasite variant - resets home page to an adult content site |
| X | MSUpdateDevKit | axfd.exe | Added by the SDBOT-ZD WORM! |
| X | msupdater | msupdater.exe | Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example |
| X | MsUpdater System | udpsys32.exe | Added by the RBOT.AAA WORM! |
| X | MSupdater.exe | N/A | CoolWebSearch parasite variant. Installs the Winshow.dll browser plugin |
| X | msupdater25 | lsasser.exe | Added by the RBOT-ATS WORM! |
| X | msupdates | msupdt.exe | Added by the RBOT-JO WORM! |
| X | MSUpdSrv | msupdsrv.exe | Browser hijacker, redirecting to a adult content site |
| X | msupdtwiz | msupdtwiz.exe | Added by the STRATION.DD WORM! |
| X | msurl | msurl32.exe | Added by the CRYPTER.A TROJAN! |
| X | msuser32.exe | msuser32.exe | Added by the ANDROV TROJAN! |
| X | msuwarn | mcpuhost.exe | Added by the AUTORUN.BCIW WORM! |
| X | MsVBdll | sys32dll.exe | Added by the AIMDES.B or AIMDES.C WORMS! |
| X | MsVBdll | MsVBdll.pif | Added by the AIMDES.A WORM! |