| Status | Autorun name | Command | Description |
| X | Microsoft Office | msoffice32.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Office | msoff.exe | Added by the RAKER-C TROJAN! |
| X | Microsoft Office | microsoft.exe | Added by the BANKER-VF TROJAN! |
| X | Microsoft Office | msvcp.exe | Added by the AGENT-XK TROJAN! |
| X | Microsoft Office | msmsgr.exe | Added by the GAOBOT.BB WORM! |
| X | Microsoft Office | mdm.exe | Added by the IBOT-A TROJAN! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only) |
| U | Microsoft Office 2010 | BCSSync.exe | Part of SharePoint Server 2010 which is part of the Microsoft Office 2010 suite. "Business Connectivity Services (BCS) uses a cache to store a copy of the external data required by the BCS solutions deployed on the Office client. A process called BCSSync.EXE runs on the client and provides automatic cache refresh and data synchronization of the entity instances." For more information - see here |
| N | Microsoft Office Fast Cache | Fastboot.exe | Part of MS Office 95 (v7.0). According to this it improves the performance. Most likely a predecessor of MS Find Fast and can be disabled |
| U | Microsoft Office Groove | GROOVE.EXE | System Tray access to and alerts for MS Office Groove - a stand-alone product or included with the Enterprise/Ultimate versions of MS Office 2007. "A collaboration software program that helps teams work together dynamically and effectively, even if team members work for different organizations, work remotely, or work offline". Users can create workspaces and invite other Groove users to share the workspace and when a document is edited within the workspace the changes made become available to all other users in the workspace when they come online - synchronized using LAN, WAN and the Internet |
| X | Microsoft Office Monitor | alg2k.exe | Added by the SDBOT-CZO WORM! |
| X | Microsoft Office Monitor | aql32.exe | Added by the RBOT-GCY TROJAN! |
| N | Microsoft Office OneNote | ONENOTEM.EXE | System Tray access to MS Office OneNote 2003 & 2007 - an electronic notebook that allows you to create free-form notes, including text, graphics and audio/video. When running, ONENOTEM.EXE also enables the WINDOWS KEY combinations - such as WINDOWS KEY+N (new Side Note - 2007 only) and WINDOWS KEY+S (insert screen grab into a note). Leave the icon enabled in OneNote but move the shortcut from Start → All Programs → Startup to the desktop or elsewhere on the Start menu and run when needed |
| N | Microsoft Office OneNote 2003 Quick Launch | ONENOTEM.EXE | System Tray access to MS Office OneNote 2003 - an electronic notebook that allows you to create free-form notes, including text, graphics and audio/video. When running, ONENOTEM.EXE also enables the WINDOWS KEY+S key combination to insert screen grab into a note. Leave the icon enabled in OneNote but move the shortcut from Start → All Programs → Startup to the desktop or elsewhere on the Start menu and run when needed |
| X | Microsoft Office quick launch | OSA.exe | Added by the VBOT.A BACKDOOR! Note that OSA.exe was used in older versions of Office to launch common components to help speed up the launch but it is no longer normally used - see here. This file is located in a valid MS Office 2003 (aka Office 11) directory - %Program Files%\Microsoft Office\OFFICE11 - and may overwrite a valid file |
| X | Microsoft Office Quick Launcher | iau1.exe | Added by the DLOADR-AWD TROJAN! |
| N | Microsoft Office Shortcut Bar | Msoffice.exe | Feature included with older versions of MS Office giving you access to common Office functions and optional shortcuts to Office (and other) programs. Some people prefer it but a better way is to create desktop shortcuts if you want access these features and programs quickly. Also available via Start → All Programs |
| X | Microsoft Office Start | winupdates.exe | Added by the GAOBOT.BC WORM! |
| N | Microsoft Office Startup | osa.exe | On older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs |
| N | Microsoft Office Startup | Osa9.exe | On older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs |
| X | Microsoft Office Studio | scvhvst.exe | Added by the RANDEX.CST WORM! |
| X | Microsoft OfficeTool | svchosts.exe | Added by the DUTAN.A WORM! |
| X | Microsoft OfficeXP | officeXP.exe | Added by the KILLAV.MA WORM! |
| X | Microsoft OfficeXP | vcvsdf.exe | Added by the SDBOT-SF WORM! |
| X | Microsoft Oftice | msmsgs.exe | Added by the IRCBOT.ALT WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger |
| X | MicroSoft OneCare | FreeS3x.exe | Added by the SDBOT-DJT WORM! |
| X | Microsoft Opeions | IEXwe.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Outlook | wincsrss.exe | Added by the AGENT-OUY TROJAN! |
| X | Microsoft Outlook Express Protocol | svchst.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Patch Update | bootini.exe | Added by the RBOT-FMN WORM! |
| X | Microsoft PC Health Remote Assistance File Open & Save controls | sfrcdlg32.exe | Added by the RBOT-AVY WORM! |
| X | Microsoft PCHealth32 | [path to file] | Added by the NICE-A TROJAN! |
| X | Microsoft PCHealth32 | NDDENB.exe | Added by the PWSYAHOO-A TROJAN! |
| X | Microsoft PCI Manager | mspci.exe | Added by the RBOT.BBG WORM! |
| N | Microsoft People Near Me | p2phost.exe | Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that "identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer." Available via Start → Control Panel |
| X | Microsoft Personal Firewalls | bakw.exe | Added by the RBOT-KS WORM! |
| U | Microsoft Pinyin IME Migration | IMSCMIG.EXE | Associated with Microsoft's Input Method Editor for Asian languages which is used to both display and enable the input of characters in e-mails, documents and other files - should you need to (e.g. Chinese, Hindi, Japanese, etc) |
| X | Microsoft Problem Doctor | windr128.exe | Added by the SMALLTRO.EF TROJAN! |
| X | Microsoft Problem Doctor | windr32.exe | Added by a variant of the SMALLTRO.EF TROJAN! |
| X | Microsoft Problem Doctor | windr64.exe | Added by a variant of the SMALLTRO.EF TROJAN! |
| X | Microsoft Proc Driver32 | msprc.exe | Added by a variant of the WOOTBOT WORM! |
| X | Microsoft Procedure Call | MSPCALL.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Process Manager | process32.exe | Added by the CHECKOUT WORM! |
| X | Microsoft Profile Manager | profile.exe | Added by a variant of the IRCBOT TROJAN! |
| X | Microsoft Protection Subsystems | msm32.exe | Added by the RBOT-JU WORM! |
| X | Microsoft PSTCP32 Data | pstcp32.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft QMGR | msnqmgr.exe | Added by the IRCBOT-S TROJAN! |
| X | Microsoft quick launch | OSA.exe | Added by a variant of the VBOT.A BACKDOOR! Note that OSA.exe was used in older versions of Office to launch common components to help speed up the launch but it is no longer normally used - see here. This file is located in a valid MS Office 2003 (aka Office 11) directory - %Program Files%\Microsoft Office\OFFICE11 - and may overwrite a valid file |
| X | Microsoft RDLL | sysconf32.exe | Added by a variant of the SDBOT TROJAN! |
| X | Microsoft Redirect | [path to file] | Added by the BANKER-FW TROJAN! |
| X | Microsoft Redirect | systen.exe | Added by the BANCOS-FO TROJAN! |
| X | Microsoft Regestry Edit Manager | regedit.exe | Added by the SHEUR.HC TROJAN! Note - this is not the valid Windows registry editor which resides in %Windir% and will not normally figure in Msconfig/Startup! This version resides in %System% |
| X | Microsoft Regestry Manager | regedit32.exe | Added by a variant of the IRCBOT.ARD WORM! |
| X | Microsoft Regestry Manager | registry32.exe | Added by the IRCBOT.ARD WORM! |
| X | Microsoft Registro | svchostt.exe | Added by the BANCOS-DH TROJAN! |
| X | Microsoft Registry | csrse.exe | Added by the RBOT-PC WORM! |
| X | MicroSoft Remote Secure Service | MSRSS.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Restore | scrgrd.exe | Added by the SPYBOT.BR WORM! |
| X | Microsoft Router Manager | linksys.exe | Added by a variant of the IRCBOT TROJAN! |
| X | Microsoft Router Manager | router.exe | Added by a variant of the IRCBOT TROJAN! |
| X | Microsoft Rundll | windos.exe | Added by the SDBOT-WF WORM! |
| X | Microsoft Runtime | CfgDll32.exe | Added by the RANDEX.BD WORM! |
| X | Microsoft Safe Mode Manager | safemode.exe | Added by the IRCBOT.HM BACKDOOR! |
| X | Microsoft Scanreg | microsoftscanreg.exe | Added by the FRANRIV.A WORM! |
| X | microsoft scvhost for windows | scvhost.exe | Added by the RANDEX-S WORM! |
| X | Microsoft SCVHOST32 Protocol | scvhost32.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft sddcE Contol | taskmnegr.exe | Added by the RBOT-AUM WORM! |
| X | Microsoft sddcE Contol | taskmn.exe | Added by the RBOT-BJZ WORM! |
| X | Microsoft sdk temp | sdktemp.exe | Added by the RBOT-ANP WORM! |
| X | Microsoft SDKP3 | mswinsdq.exe | Added by the RBOT-ARY WORM! |
| X | Microsoft Secure | Messenger.NET Service | Added by the FORBOT-AM WORM! |
| X | Microsoft Secure Messenger.NET Service | securitychk.exe | Added by the SDBOT.VT WORM! |
| X | Microsoft Security | winService.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft security adviser | mssadv.exe | Microsoft Security Adviser rogue security software - not recommended |
| X | Microsoft Security Center | savservices.exe | Added by the RBOT-ANU WORM! |
| X | Microsoft Security Center | wcsntfy.exe | Added by the SDBOT.BYD WORM! |
| X | Microsoft Security Controlers | fxsecues.exe | Added by a variant of the SDBOT WORM! |
| Y | Microsoft Security Essentials | msseces.exe | System Tray access to a notifications from Microsoft Security Essentials which "provides real-time protection for your home PC that guards against viruses, spyware, and other malicious software" |
| X | Microsoft Security GManagers | [random filename] | Added by a variant of the SDBOT WORM! |
| X | Microsoft Security Hot Fix Update | mshotfix.exe | Affilred adware |
| X | Microsoft Security Management | winnt.exe | Added by the RBOT-MQ WORM! |
| X | Microsoft Security Management | winserv.exe | Added by the RBOT-MJ WORM! |
| X | Microsoft Security Management | winamp.exe | Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player which is located in %ProgramFiles%\Winamp. This one is located in %Windir% |
| X | Microsoft Security Management | wuauct1.exe | Added by a variant of the RBOT WORM! |
| X | Microsoft Security Management | bling.exe | Added by the RBOT.XL WORM! |
| X | Microsoft Security Management | sp2fix.exe | Added by the RBOT.UB WORM! |
| X | Microsoft Security Management | winexz.exe | Added by the RBOT.FH BACKDOOR! |
| X | Microsoft Security Manager | winamp.exe | Added by the RBOT.TU WORM! Note - this is NOT the popular Winamp media player which is located in %ProgramFiles%\Winamp. This one is located in %System% |
| X | Microsoft Security Monitor Process | kar.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Microsoft Security Monitor Process | lindicracker.exe | Added by the BIFROSE.GR BACKDOOR! |
| X | Microsoft Security Monitor Process | mail.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Microsoft Security Monitor Process | mmp.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Microsoft Security Monitor Process | mssm32.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Microsoft Security Monitor Process | mssmpi32.exe | Added by a variant of the RBOT WORM! See here |
| X | Microsoft Security Monitor Process | nitty.exe | Added by the RBOT.AEU BACKDOOR! |
| X | Microsoft Security Monitor Process | ofice.exe | Added by the VIRUT.N VIRUS! |
| X | Microsoft Security Monitor Process | point.exe | Added by the IRCBOT.AVP BACKDOOR! |
| X | Microsoft Security Monitor Process | princ.exe | Added by the HUPIGON.WTL TROJAN! |
| X | Microsoft Security Monitor Process | web.exe | Added by the EGGDROP.V BACKDOOR! |
| X | Microsoft Security Monitor Process | winsys32.exe | Added by the VIRUT.N VIRUS! |
| X | Microsoft Security Monitor Process | winsyss32.exe | Added by the RBOT.AEU BACKDOOR! |