| Status | Autorun name | Command | Description |
| X | MSNavWH | MSWkwrH.exe | Added by the ANAV-A WORM! |
| X | msndrvsys | msndrvsys.exe | Added by the BROGGER-D TROJAN! |
| X | MSNET | msnet.exe | Added by the BOA WORM! |
| X | MsnExplorer | winagent.exe | Added by the BDOOR-EQ BACKDOOR! |
| X | MsnExplorer | MSEXPLOREN.EXE | Added by the BDOOR-EB BACKDOOR! |
| X | MsnExplorer | SHCH.EXE | Added by the BDOOR-EB BACKDOOR! |
| X | MsnExplorer | SVCHST.EXE | Added by the BDOOR-EB BACKDOOR! |
| X | MsnExplorer | msnexploren.exe | Added by the TACTSLAY.B TROJAN! |
| X | MsnExplorer | sdhch.exe | Added by the TACTSLAY.B TROJAN! |
| ? | MsnFixer | msnfixjs.js | Located in the HPbinmsnfix directory of a HP PC |
| X | MSNGrabber | MSNgrabber.exe | Added by the ENVID.A WORM! |
| X | msngta32 | msngta32.exe | Added by a variant of the RBOT WORM! |
| N | MSNIA | MSNIASVC.EXE | Added with MSN version 9. Resets certain internet settings upon bootup and can't be disabled via MSCONFIG |
| X | msnlive | 22.exe | Added by the DLOADR-DGJ TROJAN! |
| X | msnlive | 20.exe | Added by the MDROP-DER TROJAN! |
| X | msnload32.exe | msnload32.exe | Added by the BANCOS.M TROJAN! |
| X | MSNMESENGER | Main.exe | Added by the PRORAT TROJAN! |
| X | msnmessenger | msnmessenger.exe | Added by the BANCBAN-KJ TROJAN! |
| X | MsnMessengerSvc | msnmsgr.exe | Added by a variant of the RBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System% |
| X | msnmgnr | msnmgnr.exe | Added by the KOLAB.TC WORM! |
| X | msnmgr | msnmgr.exe | Added by the BIFROSE-K WORM! |
| U | MsnMonitor | MsnMonitor.exe | MSN Messenger Monitor Sniffer surveillance software for the MSN instant messenger. Uninstall this software unless you put it there yourself |
| X | msnmsg | asgag.exe | CoolWebSearch parasite variant |
| X | msnmsg | TBC.exe | Added by an unidentified TROJAN! |
| X | msnmsg | msnmsg.exe | Added by the BANKER-CLX TROJAN! |
| X | msnmsg.exe | mscmd32.exe | Added by a variant of the AGENT.AH TROJAN! |
| X | msnmsg.exe | msnmsg.exe | Added by the BANCBAN-KN TROJAN! |
| X | msnmsgq32 | msnmsgq.exe | Added by the TACTSLAY.F TROJAN! |
| X | msnmsgq32 | sssasasb32.exe | Added by the TACTSLAY.F TROJAN! |
| N | msnmsgr | msnmsgr.exe | Windows Live Messenger or the older MSN Messenger utility - available via the Start menu. For Windows Live Messenger, disable by clicking on the "Show menu" icon and select Tools → Options → Sign In → deselect "Automatically run Windows Live Messenger when I log on to Windows". For MSN Messenger, disable by clicking on Tools → Options → General → deselect "Automatically run Messenger when I log on to Windows" |
| X | MsnMsgr | MsnMsgrs.exe | Added by the NETSKY.AD WORM! |
| X | MsnMsgr | msnmsgr.exe | Added by the ANNEW-FAM WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System% |
| X | Msnmsgr.exe | lsass.exe | Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root directory (i.e. C:\ or D:\) |
| X | msnmsgr32-.exe | msnmsgr-.exe | Added by a variant of the SPYBOT WORM! |
| X | MSNMSGR5 | MSNMSGR5.exe | Added by the RBOT.PQ WORM! |
| X | MSNMSGRE | swef.bat | IRC backdoor TROJAN or WORM! |
| X | MSNMSGRR | swin.bat | IRC backdoor TROJAN or WORM! |
| X | MSNMSGRS | swe.bat | IRC worm or backdoor trojan! |
| X | MSNMSGRS | swiss.bat | IRC worm or backdoor trojan! |
| X | msnmsgrs | msoobe32.exe | Added by the BANBRA.GQU TROJAN! The file is typically located in %UserProfile%\InstallShield Installation Information\{A5BA14E0-7384-5991B8648CBE70A4} |
| X | MSNMSGRS1 | swed.bat | IRC backdoor TROJAN or WORM! |
| X | msnmsgs.exe | msnmsgs.exe | Added by the BANKER-HK TROJAN! Note - not to be confused with msmsgs.exe, the well known MSN Instant Messaging application! |
| X | msnmsgsgs | msnmsgsgs.exe | Added by the "Catal" alias Spy.Delitall.B backdoor TROJAN! |
| X | msnmsgy | [path to file] | Added by the BANKER-EQ TROJAN! |
| X | msnnt | winampb.exe | Chinese originated adware - detected by Kaspersky as the AGENT.TL TROJAN! |
| X | msnnt | winampf.exe | Added by the SMALL.DTS TROJAN! |
| X | msnnt | winampa.exe | Added by the SMALL.DTS TROJAN! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of %ProgramFiles% whereas this file is located in %Windir% |
| X | MSNPluginSrIvcs | n3vasap23.exe | Added by a variant of the RBOT WORM! |
| X | MSNPluginSrvcs | p6.exe | Added by the SDBOT.AKJ or RBOT-VJ WORMS! |
| X | MSNPluginSrvcs | sagate.exe | Added by the SDBOT.AKJ WORM! |
| X | MSNPlus | msnplus.exe | Added by the BANKER-DAN TROJAN! |
| X | Msnr | Msnr.exe | Added by the AUTOIT-MB WORM! |
| X | MSNS PLUS XP2 | msdupd.exe | Added by the RBOT-BCE WORM! |
| X | msnsched2 | msnsched2.exe | Added by the SPYBOT.NNT WORM! |
| X | msnscr.exe | msnscr.exe | Added by the CERTIF-P TROJAN! |
| X | MSNService | MSNService.exe | Added by the CARPET.C WORM! |
| X | msnsgs | msnsgs.exe | Added by the CHEUKO-B TROJAN! |
| X | msnshed | msnshed.exe | Added by the RBOT-YN WORM! |
| X | msnsmgr | MsnMsr.exe | Added by the LOONY-N TROJAN! |
| X | Msnsock | [malware filename] | Added by the BANKER.RQ TROJAN! The most common filename is "msnmnns.exe" which is found in %ProgramFiles% |
| N | msnsyslog | msnappm.exe | Related to Messenger Applications. When you uninstall the trial version the msnappm keeps saying (You have xx days left) this is adware and it very annoying |
| X | MSNSysRestore | pc32.exe | Added by a variant of the MASTAK VIRUS! |
| X | msnToolbaar | msnmsgesc.exe | Added by the RBOT.BMF WORM! |
| X | msnupdt | kolie.exe | Added by a variant of the RBOT WORM! |
| X | MsnWin | messagewin.exe | Added by the BANCBAN-D TROJAN! |
| X | MSObject32 | MSObject32.js | Added by the PUN TROJAN! |
| X | MSODESNV7 | msvmiode.exe | Added by the INJECT-NW TROJAN! |
| X | Msoffice | msoffice.hta | Hijacker - redirecting to Searchdot.net |
| X | MSOffice | services.exe | Added by the DLOADER-EU TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an "MSOffice" subfolder |
| X | msoffice | msoffice.exe | Added by the LIKASIMAL WORM! |
| X | MSOffice32 | msjcf.exe | Added by the RAKER-A TROJAN! |
| X | MSOfficeCfg | msocfg.exe | Premium rate adult content dialer |
| X | MSOfficeCfg | navchk.exe | Premium rate adult content dialer |
| X | MSOfficeCfg | qservice.exe | Premium rate adult content dialer |
| X | MSOfficeCfg | shman.exe | Premium rate adult content dialer |
| X | MSOfficeCfg | ssvr.exe | Premium rate adult content dialer |
| X | msoffwz | msoffwz.EXE | Added by the BANCBAN-HQ TROJAN! |
| X | msoft-updater23 | mssysstems.exe | Added by the RBOT-ATU WORM! |
| X | msoft-updater23 | slssystem.exe | Added by the RBOT-ASR WORM! |
| X | MSOleath32 | winss.exe | Added by the KATHER TROJAN! |
| X | MSOOBD | MSOOBD.EXE | Added by the MAGISTR.A VIRUS! |
| X | msoupdater | msoupdater.exe | Added by the DLOADER.GBD TROJAN! |
| X | mspaint.exe | check32.exe | Added by the AGENT.AH TROJAN! |
| X | Mspatch69 | [path to trojan] | Added by the MPROX TROJAN! |
| X | Mspatch89 | cnqmax.exe | Added by the RANDEX.P WORM! |
| X | MSPetServ | PET32.EXE | Added by the IRCBOT-VE WORM! |
| X | msping | msping.exe | Added by the FLOODBLACK TROJAN! |
| X | msping.exe | msping.exe | Added by the BDOOR-MZ BACKDOOR! |
| X | MSPluginSrvc | p3.exe | Added by the RBOT-WV WORM! |
| X | MSPLUS | msplus32.exe | Added by the MYTOB-AM or MYTOB-CL WORMS! |
| N | MSPMirage | MSPMirage.exe | Part of CyberLink MagicSports - which "is a revolutionary way of watching your sports videos. It automatically detects highlights of the most memorable moments in sports from your recorded games". The exact purpose of this entry is unknown at present but create a shortcut and start it manually before you run MagicSports - which is no longer available from CyberLink |
| N | MSPMirage.exe | MSPMirage.exe | Part of CyberLink MagicSports - which "is a revolutionary way of watching your sports videos. It automatically detects highlights of the most memorable moments in sports from your recorded games". The exact purpose of this entry is unknown at present but create a shortcut and start it manually before you run MagicSports - which is no longer available from CyberLink |
| X | MSPP System Update 64 | wiaadmgr.exe | Detected by Kaspersky as the RANKY.GEN TROJAN! |
| X | MSPQFile | MSA****.TMP [* = random char] | Homepage hijacker |
| X | MsPrint32D | MsPrint32D.exe | Added by the WINKO.AO WORM! |
| X | MSPRO32 | [path to worm] | Added by the IBERIO WORM! |
| X | MSPRO32 | pnp.exe | Added by the ZOTOB.O WORM! |
| X | MSprotect.exe | MSprotect.exe | Added by the DABYREV.A VIRUS! |
| N | MSPService | MSPMirage.exe | Part of CyberLink MagicSports - which "is a revolutionary way of watching your sports videos. It automatically detects highlights of the most memorable moments in sports from your recorded games". The exact purpose of this entry is unknown at present but create a shortcut and start it manually before you run MagicSports - which is no longer available from CyberLink |
| U | mspwr | pupstman.exe | "Transparent icon background" feature of Ashampoo'sPowerUp XP (WinNT/2K/XP) and PowerUp Deluxe (Win98/Me) |