| Status | Autorun name | Command | Description |
| X | MSVBVM60 | MSVBVBM60.pif | Added by the SCOLD-B WORM! |
| X | msvc32 | msvc32.exe | ClientMan parasite variant |
| X | msvc32 | msvc32.exe | Added by the AGOBOT-NT WORM! |
| X | msvcav | msvcav.exe | Added by the AGENT-ACR TROJAN! |
| X | msvcc | msvchost.exe | Added by the XOMBE TROJAN! |
| X | msvcc25 | svcchost25.exe | Added by the SDBOT.BIK WORM! |
| X | msvcc25 | salvage.exe | Added by a variant of the SDBOT WORM! |
| X | msvcc25 | svcchost.exe | Added by the SDBOT-CSE WORM! |
| X | msvccc66 | svcchosst.exe | Added by the RBOT-GLS WORM! |
| X | msvccc66 | dload.exe | Added by a variant of the RBOT WORM! |
| X | msvchost | msvchost.exe | Added by the IRCBOT-AV WORM! |
| X | MsvcService | msvcs.exe | Added by the RBOT-RK WORM! |
| X | msvecurity | msvecurity.exe | Added by the DORF-BO WORM! |
| X | MSVersion | INTERNETFEATURES.exe | Added by the POPMON.A TROJAN! - also known as PopMonster adware |
| X | MSVersion | clrschp038.exe | Added by the POPMON.A TROJAN! - also known as PopMonster adware |
| X | msvhost | aig.exe | Added by the AIMBOT-BC TROJAN! |
| X | msvload32 | msvload32.exe | Added by the RBOT-ACI WORM! |
| X | msvps | msvps.exe | Added by the AGOBOT.ALI WORM! |
| X | msvsc32 | msdev.exe | Added by the RBOT-GJ WORM! |
| X | MSVsmt | rpcxctx.exe | Added by an unidentified WORM or TROJAN! |
| X | msvsrv32 | msvsrv32.exe | Added by the AGOBOT-KM WORM! |
| X | msvss | msvss.exe | Added by a variant of the RBOT WORM! |
| X | MSVSync | videosync.exe | Added by a variant of the SPYBOT WORM! |
| X | msvupdater | msvupdater.exe | Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example |
| X | MSVXD | MSVXD.EXE | Added by the DATOM.A WORM! |
| X | mswave | mswave.exe | Added by the CRYPTER.A TROJAN! |
| X | Mswavedll | mswavedll.exe | Added by the CRYPTER-C TROJAN! |
| U | MSwheel | mswheel.exe | Microsoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features |
| X | mswiiz32 | mswiiz32.exe | Added by the STRATION.DH WORM! |
| X | mswiizz32 | mswiizz32.exe | Added by the STRATION.DL WORM! |
| X | MSWin | mswin.exe | Added by the BANKER-CU TROJAN! |
| X | Mswincfg | Mswincfg32.exe | Added by the CYBRSPY.D BACKDOOR! |
| X | MsWindows DRT Drivers | wsdrt32.exe | Added by the RBOT.ALT WORM! |
| X | MsWindows SSL Drivers | mssl32.exe | Added by the SPYBOT.API WORM! |
| X | MSWindows SysCl | mscl32.exe | Added by the RBOT.AHI WORM! |
| X | MsWindows SysDate | sysmsvc.exe | Added by the SPYBOT.FCD WORM! |
| X | MSWindows Syspg | mspg32.exe | Added by the RBOT-TB WORM! |
| X | MSWindowsUpdate | Systern.exe | Added by the RBOT-AFD WORM! |
| X | MSWindowsUpdate | mswinup.exe | Added by a variant of the SDBOT WORM! |
| N | mswinext | mswinext.exe | MSN Toolbar from version 4.* onwards (now known as Bing Bar from version 5.* onwards). This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed |
| X | MsWinLibrary | scvhost.exe | Added by the BANKER-CLI TROJAN! |
| X | MSWinlogon | SynCor.exe | Added by the AGENT-FZL TROJAN! |
| X | MSWinlogon | winlogon.exe | Added by the AGENT-FZM TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
| X | Mswinpid32 | mswinpid32.exe | Added by the LAPOS.A TROJAN! This is a keylogger which emails back to China PayPal passwords and account information - thus allowing the perpetrators to steal PayPal funds in the name of the victim! |
| X | MSWinSrv | MSWinSrv.exe | Added by the MTRON TROJAN! |
| X | MSWinSrv32 | MSWinSrv32.exe | Added by the MTRON-B TROJAN! |
| X | MSWinupd | winupd.exe | Added by the DLOADER-YE or DLOADR-AAA or DLOADER-ZF TROJANS - and others |
| X | MSWinupdate | winupdate.exe | Added by the DLOADR-AAW TROJAN! |
| X | MsWinVgr | msvgr.exe | Added by the MYTOB.LE WORM! |
| X | mswiz32 | mswiz32.exe | Added by the STRATIO-BG WORM! |
| X | mswkork Service | msework.exe | Added by a variant of the RBOT WORM! |
| X | msword | msword.exe | Added by the RBOT-ADR WORM! |
| X | msword | docx.exe | Added by the CODOX-A WORM! |
| X | msword98 | msword98.exe | Added by the AGENT-KUO TROJAN! |
| X | MSWorld | msworld.exe | Added by the AGENT.DED TROJAN! |
| X | mswspl | [random filename] | Added by the SMALL.IQ TROJAN! |
| X | mswspl | searchbarcash.exe | SearchBarCash adware |
| X | mswspl | vnmispoisn downloader.exe | SearchBarCash adware variant |
| X | mswspl | plugin1.exe | Added by the SMALL.IQ TROJAN! |
| X | MSWTL32 | MSATL32.exe | Added by an unidentified WORM or TROJAN! See here |
| X | MSWUpdate | [path to worm] | Added by the SILLYFD-V WORM! The most common filename is lsass.exe but it's not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
| X | MSWUpdate | services.exe | Added by the VB-FDP TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData% |
| X | msxct | msxct.exe | eXact Advertising (NaviSearch, BargainBuddy, CashBack) adware |
| X | MSxmlHpr | RUNDLL32.EXE [path] msxm192z.dll,w | Added by the Infostealer.Wowcraft keylogger! |
| X | MsXSLT | msxslt3.exe | Added by the AGENT.AZMU TROJAN! |
| X | Msy Startups | msyh32.exe | Added by the AGOBOT-QC WORM! |
| X | Msy1 Startups | msyj32.exe | Added by the AGOBOT-QQ WORM! |
| X | msys lptt01 | msys.exe | RapidBlaster variant (in a "msyss" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | Msys32 | morfitwebentrance.exe | Morfit ADjectPager - "uses home page rental technology for generating revenues". Homepage hi-jacker that re-defines your IE or Netscape start page as http://www.web-entrance.com/. Any installed application including this must be un-installed before you can reset your homepage |
| U | MSys32 | fe33c1ae.exe | Webentrance adware |
| U | MSys32 | morfitwe.exe | Webentrance adware |
| X | MSysDrv | msdrv.exe | Added by the VB.WF TROJAN! |
| N | MtdAcq | MtdAcq.exe | Creative MediaSource "Media Sniffer" - monitors the drive for new media files then automatically adds them to the media library |
| ? | MtdAcqu | MtdAcqu.exe | Metadata monitor part of Creative MediaSource player/organizer - which "enables you to manage your entire digital music collection on both your computer and your Creative portable music player effortlessly." Collects information on the songs. Is it required? |
| X | Mtr2 | mtr2.exe | Added by the KRYPTONIC GHOST TROJAN! |
| X | MTRVEHNT | MTRVEHNT.exe | Added by the PWS-BQO TROJAN! |
| U | MUAL | mual.exe | Millesky video mail updater and launcher |
| N | muamgr | muamgr.exe | Using MicroAngelo On Display, you can easily select the icon images that you prefer rather than the default icons displayed by Windows. On Display provides a consistent and elegant method to customize the icon display for almost every icon on your system |
| X | muBlinder | muBlinder.exe | Program that bypasses Microsoft Update's Genuine Windows Validation |
| ? | Mufix | mufix.exe | Part of INFOConnect, web-based, enterprise client configuration, management, and deployment software, as used by ABSS (a financial management system used by the US military which will allow purchase request packages to be electronically submitted to contracting, and which also facilitates electronic receipt of items and EFT) - what does it do and is it required |
| ? | MUI StartMenu Application | MUIStartMenu.exe | Part of various video and audio utilities from CyberLink - including (but not limited to) LabelPrint, Power2Go, DVD Suite, PowerProducer and PowerDirector. The exact purpose of this entry is unknown at present but it unloads from memory once run. The command line varies depending upon the product |
| X | mule_st_key | flec006.exe | Added by the BAGLE.AV TROJAN! |
| U | Multi-function keyboard | GWHotkey.exe | Software that sets up the Gateway AnyKey keyboard shortcuts (a series of buttons that allow one-click access to e-mail, browser, volume and CD/DVD controls, etc) |
| U | MultiCAM Initializer | MCamBoot.exe | The MultiCAM Initializer is part of the MultiCAM software package provided by Vista Imaging in order to run up to 10 USB ViCAM or 3Com Home Connect PC Digital cameras on a single computer. Clears itself from memory once initialized but can also be safely disabled |
| X | Multimedia | windebug.exe | Added by the VB-ERB WORM! |
| X | Multimedia Codecs | mcc.exe | Added by the DLOADER-MB TROJAN! |
| X | Multimedia extensions | mservice.exe | EasySearch adware |
| X | Multimedia extensions | [path to trojan] | Added by the SMUTSRCH-A TROJAN! |
| X | Multimedia extensions | mservice1.exe | Added by the DLOADR-AWD TROJAN! |
| U | Multimedia KBD | MMKeybd.exe | Multimedia keyboard manager. Required if you use the additional keys |
| U | MULTIMEDIA KEYBOARD | MMKeybd.exe | Multimedia keyboard manager. Required if you use the additional keys |
| X | MULTIMEDIA KEYBOARD88 | smss.exe | Added by the SILLYFDC WORM! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup! |
| Y | Multiplicity | multipl.exe | Multiplicity from Stardock Corporation - "a new program that lets you control multiple computers with a single keyboard and mouse" |
| X | multiran | multiran.exe | Added by the COSIAM-E TROJAN! |
| U | MultiRes | MultiRes.exe | MultiRes - system tray utility allowing quick access to changing desktop resolutions and has the ability to lock the screen refresh rate in WinNT/2K/XP |
| N | mumservice | mumservice.exe | Software updater for Motorola products |
| ? | MUPS | MUPS.exe | Part of Belkin Bulldog Plus UPS management software. Exact purpose unknown at present |
| ? | MUPS.exe | MUPS.exe | Part of Belkin Bulldog Plus UPS management software. Exact purpose unknown at present |
| Y | murphy shield | lmgui.exe | Firewall part of BitDefender virus scanner/firewall |
| X | music | music.exe | Added by the AUTORUN-BP WORM! |