| Status | Autorun name | Command | Description |
| N | MessengerPlus | MsgPlus.exe | MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"! |
| N | MessengerPlus2 | MsgPlus.exe | MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"! |
| N | MessengerPlus3 | MsgPlus.exe | MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"! |
| X | messengerskinner | MessengerSkinner.exe | Messenger Skinner malware - uses a rootkit to hide executable files |
| X | Messenqer | Messenqer.exe | Added by the MDROP-CL MALWARE! Note the lower case "Q" in the name and command |
| X | messnger | [worm filename] | Added by the DELODER WORM! |
| X | messnger | Dvldr32.exe | Added by the DELODER.A WORM! |
| N | Metacafe | MetacafeAgent.exe | Metacafe - video sharing on the web. Note - if you subscribe make sure you read the Privacy Policy |
| X | MeTaLRoCk (irc.musirc.com) has sex with printers | metalrock-is-gay.exe | Added by the RANDEX.Q WORM! |
| X | Meteorite | installed.exe | Added by the KOLAB.EAV WORM! |
| X | MeuPrograma | accwizz.exe | Added by the RULAND.A WORM! |
| X | Mfc**.exe [* = random char] | Mfc**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | Mfc**32.exe [* = random char] | Mfc**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| ? | mfgboot | ?? | ?? |
| X | mfhsornwnduy | regsvr32.exe gisyflngpshcvuakv.dll | Pro AntiSpyware 2009 rogue spyware remover - not recommended, removal instructions here. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The "gisyflngpshcvuakv.dll" file is found in %System% |
| X | mFilter | MNeck.exe | Added by the CLICKER-AG TROJAN! |
| X | mfin32 | mfin32.exe | MyFreeInternetUpdate - adware downloader |
| Y | mfp | mfp.exe | McAfee Family Protection - which 'is easy-to-use and built to empower parents to say "yes" to their children's online interests while protecting them as they learn and explore' and "protects children of all ages from exposure to inappropriate content, social networking risks, strangers, and other threats" |
| U | MFP PanelMgr | SSMMgr.exe | Monitors ink levels, paper present and other parameters for some printers |
| U | MFP Server Agent | MFPAgent.exe | Multi Function Printer (MFP) server agent for products such as Belkin's Wireless G All-in-One Print Server and ZyXEL's NPS-520 which allow multiple computers to use networked all-in-one printers |
| U | MFP1815_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Dell Laser MFP 1815 multifunction printer |
| U | MFPAgent | MFPAgent.exe | Multi Function Printer (MFP) server agent for products such as Belkin's Wireless G All-in-One Print Server and ZyXEL's NPS-520 which allow multiple computers to use networked all-in-one printers |
| X | Mfqneqfeb | vdddwq.exe | Added by the RANDEX.AP WORM! |
| ? | MGA Hook | Mgahook.exe | MATROX Graphics card related. What does it do and is it required? |
| N | MGA Quickdesk | MGAQDESK.EXE | For Matrox video cards. Quick access to tweak your card to your liking |
| N | MGA_CD_Install | mgasetup.exe | Matrox Millennium video driver. Not required once drivers installed |
| U | Mgabg | Mgabg.exe | Matrox BIOS Guard - monitors a Matrox card's BIOS, and will reflash it when needed. Cards like the G400 have a nasty habit of losing their BIOS, especially on poor power supplies. If you make an emergency BIOS disk with the utility in their BIOS package, you can disable Mgabg.exe and just use the crash disk if/when needed |
| Y | mgavctrl | mgavrtcl.exe | Part of older versions of McAfee's internet security products such as VirusScan and VirusScan Online |
| Y | mgavrtclexe | mgavrtcl.exe | Part of older versions of McAfee's internet security products such as VirusScan and VirusScan Online |
| Y | mgavrtclexe | mgavrte.exe | Part of older versions of McAfee's internet security products such as VirusScan and VirusScan Online |
| X | mgmtapi | mgmtapi.exe | Unidentified malware |
| X | Mgsgi service | wkzfn.exe | Added by the AGOBOT-AHL WORM! |
| U | MGSysCtrl | MGSysCtrl | Part of the System Control Manager for MSI notebooks - displays animations for hot key commands (such as turning the wirelss card on/off) |
| X | MHDOGStart | mhdogst.EXE | Added by an unidentified VIRUS, WORM or TROJAN! A possibility is a trojan known as PENIS |
| N | MHINIT | MHINIT.EXE | Part of the Cybermedia Clean Sweep package |
| X | mhs3 | mhs3.exe | Added by the PWS-ALZ TROJAN! |
| X | Mi7sft sdce | b0yz.exe | Added by the RBOT.CWG WORM! |
| X | Mi7sft sdce | MNSQ.exe | Added by the RBOT.DMU WORM! |
| X | Mi7sft sdce | scorti.exe | Added by the RBOT.ELC WORM! |
| X | Mickey Mouse Cereal | [random filename].exe | Added by the RANKY.Q TROJAN! |
| X | Micosoft Data Core | runservice.exe | Added by the IRCBOT.BK WORM! |
| X | Micosoft Data Core stuff | svshosts.exe | Added by the RBOT.FZA WORM! |
| X | Micosoft Startup | syscall.exe | Added by the SDBOT-JI WORM! |
| X | Micosoft Startup | systall.exe | Added by the SDBOT-GM BACKDOOR! |
| X | Micosoftartup | shrl.exe | Added by the SDBOT-JQ WORM! |
| X | MicosoftStartup | syxall.exe | Added by the SDBOT-JR WORM! |
| X | Micr Update | soundblaster.exe | Added by the SDBOT.NP WORM! |
| X | Micr Update System | upwin.exe | Added by the SDBOT.YS WORM! |
| X | Micr0s0ft Ms D0s | msdx.exe | Added by the RBOT-AON WORM! |
| X | Micr0s0ft Upd4t4z | svchost32.exe | Added by the RBOT.ALF WORM! |
| X | Micrcoft Exploerer | spoolsal.exe | Added by the RBOT-AKK WORM! |
| X | Micrcoft Exploerer | svchose.exe | Added by the RBOT-ASL WORM! |
| X | Micrcoft Updat | spoolsae.exe | Added by the RBOT-AIB WORM! |
| X | Micrcoft Updat | spoolsaex.exe | Added by the RBOT-AJM WORM! |
| X | Micrcoft Updat | Internet.exe | Added by the RBOT-ANA WORM! |
| X | Micrcsoft Certificate Services | cflmon.exe | Added by the RBOT-FWV WORM! |
| X | Micro CRC Protocol | scrc32.exe | Added by a variant of the SDBOT WORM! |
| X | Micro Office | [path to trojan] | Added by the BANCBAN-QC TROJAN! |
| X | Micro Process | appconf.exe | Added by an unidentified WORM or TROJAN! |
| X | Micro Update | dailin.exe | Added by the RBOT-ER WORM! |
| N | Microangelo Desktop | Muamgr.exe | Using MicroAngelo On Display, you can easily select the icon images that you prefer rather than the default icons displayed by Windows. On Display provides a consistent and elegant method to customize the icon display for almost every icon on your system |
| N | microAttuneDownload | atmdlusr.exe | Application Launcher, MS Office application. USR (US Robotics) modem auto updater. May be a sub-set of Attune |
| U | MicroBrew | MicroBrew2.exe | Related to Bluebeam PDF printer support. Prints AutoCAD .dwgs to PDF's |
| X | MicroCQ0 | explorer.exe | Added by the LINEAGE-AK TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles% |
| U | MicroDialler | atdialler1.exe | Part of the Freeserve Connection Kit - changes the dial-up for Freeserve AnyTime if access problems are encountered |
| X | MicroedSoft Toolbar | Smoked.exe | Added by the RBOT-ALN WORM! |
| X | Microfinder lptt01 | mcf.exe | RapidBlaster variant (in a "mcf" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | Microfinder ml097e | mcf.exe | RapidBlaster variant (in a "mcf" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | Microfot Update | winldx32.exe | Added by a variant of the RBOT WORM! |
| X | Microft Exploerer | spoolsac.exe | Added by the RBOT-AMD WORM! |
| X | Microft Update 32 | winssx.exe | Added by the RBOT-AQS WORM! |
| X | MicroLoad | [random filename] | Added by the DARBY WORM! |
| X | Micromedia Flash Update | wdfmrg.exe | Added by a variant of the SDBOT WORM! |
| X | Micromedia Flash Update | xptxt.exe | Added by the RBOT-GAB WORM! |
| X | MicroMix32 | WinCon.exe | Added by the VB-ECC TROJAN! |
| X | Microoft Timing | pupdate.exe | Added by a variant of the RBOT WORM! |
| X | MICROSFT ANTIVIRUS UPDATE SUPPORT | [random 10-letter filename].EXE | Added by the RBOT-AQA WORM! |
| X | MICROSFT ANTIVIRUS UPDATE SUPPORT | MSGUPDATED.EXE | Added by the RBOT-APZ WORM! |
| X | Microsft Conf 32 | msaconf.exe | Added by the RBOT.EYA WORM! |
| X | Microsft Confige 32 | msaconfigurez.exe | Added by the RBOT.CLC WORM! |
| X | Microsft Corporation Version 2001.12.4414 | comrel.exe | Added by a variant of the SDBOT TROJAN! |
| X | Microsft Corporation Version 2002.12.2414 | comserv.exe | Added by a variant of the SLAPER TROJAN! |
| X | MICROSFT MX UPDATE SUPPORT | taskmngrs.exe | Added by the RBOT-AUZ WORM! |
| X | MICROSFT MX UPDATE SUPPORT | winmx32.EXE | Added by the IRCBOT-FD WORM! |
| X | MICROSFT NT SUPPORT | jtzbpfnkxk.EXE | Added by the RBOT-CMI WORM! |
| X | MICROSFT RAMA UPDATE SUPPORT | [random filename] | Added by the RBOT-ASM or RBOT-AUW WORMS! |
| X | MICROSFT RAMA UPDATE SUPPORT | MSN32.EXE | Added by the RBOT-AWJ WORM! |
| X | MICROSFT RAMA UPDATE SUPPORT | mtakthmyn.EXE | Added by the RBOT-AUJ WORM! |
| X | MICROSFT RAMA UPDATE SUPPORT | MSGUPDAT32.EXE | Added by the RBOT-BBB WORM! |
| X | MICROSFT RAMA UPDATE SUPPORT | MSED32.EXE | Added by the RBOT-AWR WORM! |
| X | Microsft Remote Procedure Daemon | msrpcd.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Microsft Security Monitor Process | cmh.exe | Added by the EGGDROP.V WORM! |
| X | Microsft Security Monitor Process | mssmppp.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Microsft Security Monitor Process | mssmpp.exe | Added by the SDBOT-DJW WORM! |
| X | Microsft Updtes | sarvice.exe | Added by a variant of the SDBOT WORM! |
| X | Microsft Upgraed | [random filename].exe | Added by a variant of the SDBOT WORM! |
| X | Microsft Windows Adapter 5.1.3013 | [random filename] | Added by the SMALL.HIT TROJAN! |
| X | microsft windows updates | mwupdate32.exe | Added by a variant of the TOXBOT/CODBOT WORM! |
| X | Microsof Value | nmatt.exe | Added by a variant of the RBOT WORM! |
| X | Microsof Windows Host | svhost32.exe | Added by the RBOT.ADY WORM! |