| Status | Autorun name | Command | Description |
| X | Microsoft Help | svh0st.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Help | svchosl.exe | Added by the AGENT-GPX TROJAN! |
| X | Microsoft Help Support | mshelp32.exe | Added by the KELVIR-BF WORM! |
| X | Microsoft Help SVC | msnmngr.exe | Added by the SDBOT-PQ WORM! |
| X | Microsoft Help System | mshelp32.exe | CoolWebSearch parasite variant |
| X | Microsoft Helpdesk Side | mshelpdsk.exe | Added by the SPYBOT.ANJJ WORM! |
| X | Microsoft Host Protocol | svhost.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Hosting Service | WINHOSTING.EXE | Added by the RBOT.AEV WORM! |
| X | Microsoft Hosts Service | Isass.exe | Added by a variant of the RBOT WORM! |
| X | microsoft hotmail monitor | mshotmon.exe | Added by the MYTOB-FL WORM! |
| X | Microsoft hren1 | mmhren1.exe | Added by a variant of the AGENT.IWW TROJAN! |
| X | Microsoft Hyptertext Helper | mshtha.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft IDCN | mshe1p.exe | Added by an unidentified TROJAN! |
| X | Microsoft IE | Iexplore.exe | Added by the FORBOT-AG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
| X | Microsoft IE Execute shell | IEExec.exe | Added by the ALADINZ.N TROJAN! |
| X | MicroSoft IE Sasser | ISASS.EXE | Added by the SDBOT.MX WORM! |
| X | Microsoft iexplorer11 | avstc.exe | Added by the AUTORUN-BHK WORM! |
| X | Microsoft iexplorer11 | avntsc.exe | Added by the NEERIS-C WORM! |
| X | Microsoft IIS | syshost.exe | Added by the FRANCETTE WORM! |
| X | Microsoft IIS | [filename] | Added by the FRANCETTE-S WORM! |
| U | Microsoft IME 2002 | IMJPMIG.EXE | Microsoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails, documents, web forms and other files - should you need to. Found on PCs where East Asian languages have been installed through the Regional and Language options icon in the Control Panel |
| X | Microsoft Inc. | iexplorer.exe | Added by the LOVGATE.E WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
| X | Microsoft Inc. | iexplorer.exe... | Added by the LOVGATE.AO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
| X | Microsoft Incroporate | mfs.exe | Added by the RBOT-ANF WORM! |
| X | Microsoft Inet Xp.. | teekids.exe | Added by the BLASTER.C WORM! |
| X | Microsoft Information | securenet.exe | Added by the SDBOT.AJM WORM! |
| X | Microsoft Information Check | microsoft.exe | Added by the SLENFBOT.JU WORM! |
| X | Microsoft Initialization Service | initsvc.exe | Added by the IRCBOT.AXK BACKDOOR! |
| X | Microsoft Initialization Services | initserv.exe | Added by the IRCBOT-ABO TROJAN! |
| X | Microsoft Install Shield Services | rundll64 | Added by the RBOT-FSH WORM! |
| X | Microsoft Installshield | nundll32.exe | Added by the AGOBOT-AHZ WORM! |
| X | Microsoft Instant Messenger | msngmsngr32.exe | Added by the SPYBOTER.GEN TROJAN! |
| X | Microsoft Int Service | MsIntSrv.exe | Added by a variant of the RBOT WORM! |
| U | Microsoft IntelliPoint | ipoint.exe | Microsoft IntelliPoint utility (from version 5.5) - required to support the programmable buttons and additional features on Microsoft's range of mice, If this entry is disabled, any programmed buttons or program-specific settings will not be supported |
| U | Microsoft IntelliPoint | point32.exe | Microsoft IntelliPoint utility (up to version 5.4) - required to support the programmable buttons and additional features on Microsoft's range of mice, If this entry is disabled, any programmed buttons or program-specific settings will not be supported |
| U | Microsoft Intellitype Pro | speedkey.exe | Additional keyboard shortcuts on MS programmable keyboard |
| U | Microsoft IntelliType Pro | itype.exe | Microsoft IntelliType Pro utility (from version 5.5) - required to support the multimedia keys, programmed keys and key macros on Microsoft's range of keyboards. If this entry is disabled, any programmed keys or actions will not be supported and keys will not function as expected in applications with advanced text services enabled |
| U | Microsoft IntelliType Pro | type32.exe | Microsoft IntelliType Pro utility (up to version 5.4) - required to support the multimedia keys, programmed keys and key macros on Microsoft's range of keyboards. If this entry is disabled, any programmed keys or actions will not be supported and keys will not function as expected in applications with advanced text services enabled |
| X | Microsoft Internal AntiVirus Systems | dIlhost.exe | Added by the RBOT-AEV WORM! |
| X | Microsoft Internel Corporat | netvhost.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Microsoft Internel Corporat | smbvhost.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Microsoft Internet | expl0rer.exe | Added by a variant of the SPYBOT WORM! |
| X | Microsoft Internet | windows32.exe | Added by the SDBOT-F WORM! |
| X | Microsoft Internet | wincfg16.exe | Added by a variant of the SDBOT WORM! |
| X | Microsoft Internet Acceleration Utility | iau.exe | EasySearch adware |
| X | Microsoft Internet Acceleration Utility | [path to file] | Added by the AGENT-CX TROJAN! |
| X | Microsoft Internet Acceleration Utility | [path to trojan] | Added by the SMUTSRCH-A TROJAN! |
| X | Microsoft Internet Antivirus Protection | antivirus.exe | Detected by Kaspersky as the IRCBOT.BSK TROJAN! |
| X | Microsoft Internet Dumping Protocol | inetdump.exe | Added by the IRCBOT.BLL BACKDOOR! |
| X | Microsoft Internet Exp | iiexplorer.exe | Added by the RBOT-KX WORM! |
| X | Microsoft Internet Explorer | iexplore.exe | Added by the POEBOT-J WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
| X | Microsoft Internet Explorer | iexplorer.exe | Added by the SDBOT-XN WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
| X | Microsoft Internet Explorer | crsys32.exe | Added by the RBOT.UZ WORM! |
| X | Microsoft Internet Explorer | movies.exe | Added by the BANCOS-DZ TROJAN! |
| X | Microsoft Internet Explorer | svzhost.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Internet Explorer | mccagent.exe | Added by the DLOADER-UD TROJAN! |
| X | Microsoft Internet Explorer | sysini.exe | Added by the DELF-LN TROJAN! |
| X | Microsoft Internet Explorer | svchost.exe | Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "drivers" subfolder |
| X | Microsoft Internet Explorer | lEXPLORE.EXE | Added by the RBOT-AMM WORM! Note - the executable is spelt with a lower case "L" rather than an lower or upper case "i" which is the case with Internet Explorer |
| X | Microsoft Internet Explorer | svchosts.exe | Added by the BANCBAN-U TROJAN! |
| X | Microsoft Internet Explorer | [path to trojan] | Added by the BANCBAN-AS TROJAN! |
| X | Microsoft Internet Explorer | msngrt.exe | Added by the SDBOT-GU BACKDOOR! |
| X | Microsoft Internet Explorer | _svchost.exe | Added by the TINY.LX TROJAN! |
| X | Microsoft Internet Explorer | smiissm.exe | Added by the DELF-KK TROJAN! |
| X | Microsoft Internet Explorer | ie8.exe | Added by the BANKER-FBF TROJAN! |
| X | Microsoft Internet Explorer 6 | winupdx.exe | Added by the WOOTBOT.GR WORM! |
| X | Microsoft Internet Explorer Manager | ie.exe | Added by a variant of the IRCBOT TROJAN! |
| X | Microsoft Internet Explorer Update | ieupdate.exe | Added by the SHEUR.MH TROJAN! |
| X | Microsoft Internet Firewall | firewall.exe | Added by the IRCBOT.MD BACKDOOR! Located in %System% |
| X | Microsoft Internet Firewall Manager | GMT16.exe | Added by the RANDEX.AT WORM! |
| X | Microsoft Internet Firewall Update | updater.exe | Added by a variant of the IRCBOT TROJAN! |
| X | Microsoft Internet Services | Smss32.exe | Added by the RBOT.MS WORM! |
| X | Microsoft Internet Syncing | inetsync.exe | Added by the IRCBOT.BLL BACKDOOR! |
| X | Microsoft Intrenet Explorer | goaw.pif | Added by the RBOT-API WORM! |
| X | Microsoft Intrenet Explorer | Soundsyst.exe | Added by the RBOT-AQU WORM! |
| X | Microsoft Intrenet Explorer | cnsg.pif | Added by the RBOT-ARO WORM! |
| X | Microsoft Intrenet Explorer | wcumrg.exe | Added by the SDBOT-AFD WORM! |
| X | Microsoft IPC | system.exe | Added by the NULLBOT TROJAN! |
| X | Microsoft IPC | svshost.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Microsoft IT Update | win43.exe | Added by the RBOT-SA WORM! |
| X | Microsoft IT Update | windows.exe | Added by the RBOT-JM WORM! |
| X | Microsoft IT Update | winsyst32.exe | Added by the RBOT-FC WORM! |
| X | Microsoft IT Update | Rhost32.exe | Added by a variant of the IRCBOT TROJAN! |
| X | Microsoft IT Update | win64.exe | Added by the RBOT.GA WORM! |
| X | Microsoft IT Update | [random filename] | Added by a variant of the RBOT WORM! |
| X | Microsoft IT Update | IEserv.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft IT Update | msupdate.exe | Added by the RBOT-FE WORM! |
| X | Microsoft IT Update | winn43.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft IT Update | svchsst.exe | Added by the RBOT-DH WORM! |
| X | Microsoft Java Virtual Machine | MsConfiG.exe | Added by the FORBOT-DV WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting |
| X | Microsoft Java Virtual Machine | msjvm.exe | Added by a variant of the SDBOT WORM! |
| X | Microsoft Java Virtual Machine | javavm.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Java Virtual Machine | msjavarxp.exe | Added by the FORBOT-DL WORM! |
| X | Microsoft Java Virtual Machine | winscr32.exe | Added by a variant of the WOOTBOT WORM! |
| X | Microsoft Java Windows Update | [filename] | Added by the RBOT-DZ WORM! |
| X | Microsoft JavaVM | msjarun.exe | Added by the RBOT-JW WORM! |
| X | Microsoft Kernel | Windows_kernel32.exe | Added by the NETSKY.AE WORM! |
| X | Microsoft Kernel Patch | kernel3ox.exe | Added by the RBOT-UJ WORM! |
| X | Microsoft Keyboard Enhance 2.0. | iasrecst.exe | Added by the BCKDR-QIL BACKDOOR! |
| X | Microsoft Keyboard Enhance V2.0 | iasrecst.exe | Detected by F-Prot as the DOWNLOADER2.AILI TROJAN! |