| Name | Status | Filename | Description |
|---|
| Mouse Movement Monitor (mousemm) | X | mousemm.exe | Added by the W32/Cuebot-E
WORM!
|
| Mouse Synchronization (mousesync) | X | mousesync.exe | Added by the W32/Esbot-A
WORM!
|
| Mouseb | X | MOUSEB.EXE | Added by the SDBOT.CRQ
WORM!
Read the link, rootkit type stealth involved.
|
| Movielink Core Service | L | MOVIEL~1.EXE | Associated with Movielink
online movie download service with help from IBM. Has also been seen with the file name MOVIEL~2.EXE |
| Mozy Backup Service (MozyBackup) | L | mozybackup.exe | Related to Mozy Free backup at a secure, remote location. Note: Located in C:\Program Files\Mozy\ |
| MozyBackup | L | mozybackup.exe | Related to Mozy Free backup at a secure, remote location. Note: Located in C:\Program Files\Mozy\ |
| MpService | L | MPSERVIC.EXE | Related to Canon Inc.
http://www.canon.com/ |
| mr2kserv | L | mr2kserv.exe | Dell Open Management software installs this service
http://www.anti-spy.info/process/mr2kserv.exe.html |
| MrayPigeonServer | X | M_Server2006.exe | Troj/Hupigon-IV Note: Located in %windir% Read the link, allows remote access |
| MRFCKDLL | X | MRFCKDLL.SYS | Added by the Troj/NtRootK-F
TROJAN!
Read the link, rootkit type stealth involved.
|
| MRMonitor (MegaMonitorSrv) | L | Monitor.exe | Related to Dell SAS RAID Storage Manager. Note: Located in \%Program Files%\Dell SAS RAID Storage Manager\MegaMonitor\ |
| MrobeService | L | MRobeService.exe | Related to Olympus_America_Inc Imaging products. |
| MrPostman | L | Wrapper.exe | Related to MrPostman: POP email access. |
| MRU Web Service (MRUWebService) | L | Apache.exe | Related to Apache web server Note: Located in \%Program Files%\Marvell\61xx\Apache2\bin\ |
| Ms Builders (Ms Builder) | X | Wupated.exe | Added by the W32/Agobot-SS
WORM!
|
| MS Common Service | X | mscomserv.exe | Added by the Troj/Zlob-RF TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| MS Dns Service | X | wincntrl.exe | Added by a variant of the Sdbot/Rbot worm |
| MS Dns Service (WinNet) | X | wincntrl.exe | Added by the W32/Rbot-AYH
WORM!
Note: This worm\trojan file is found in the System32 folder.
|
| MS DTC console | X | msdtc.exe | Added by the W32/Sdbot-DTO WORM! Note: This worm\trojan is located in C:\%WINDIR% |
| MS Ineterner Explorer Update Services (msieupservice) | X | msupsrv.exe | Listed as "Adware.SponsorBox.Process". by SuperAdBlocker |
| MS Internet Countermeasures Framework (ICF) | X | \System32:svchost.exe | Added by an unidentified TROJAN! of the Sdbot family. Note DO NOT delete the svchost.exe file. |
| MS Internet Countermeasures Framework (ICF) | X | icf.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ |
| MS NET Service | X | wiadss.exe | Identified as a variant of the Net-Worm.Win32.Kolabc.b worm. Note: Located in \%WINDIR%\ Note: Use SDFix under supervision. |
| MS Office Updater Service | X | msrvs32.exe | Added by the W32/Tilebot-HM WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder |
| MS Shadow Copy Software (ScSoft) | X | scsoft.exe | W32/Tilebot-JP Read the link, allows remote access |
| MS Software Shadow Download Provider (dnlsvc) | X | dnlsvc.exe | Added by DnlSvc.Process TROJAN! |
| Ms Valud Loader (Ms Valud Load) | X | Svhots.exe | Added by the W32/Agobot-SP
WORM!
|
| Ms-java | X | ms-java.exe | Added by a variant of the Backdoor:Win32/Iroffer TROJAN! Note: This worm\trojan is located in \%WINDIR%\System32\System\ Read the link, allows remote access |
| MSAPI32Svc | X | lcrss.exe | Added by a variant of the BACKDOOR.IRC.BOT Note: This worm\trojan is located in \%WINDIR%\ |
| MSCom | X | mscom.exe | Added by the W32.Woredbot TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K) |
| MSCommmand | X | mswincom32.exe | Added by the W32/Rbot-FMM WORM! Note: This worm\trojan is located in C:\Windows\System\dllcache (Win9x/Me), C:\%WINDIR%\System32\dllcache (XP/WinNT/2K) Disables the automatic startup of other software, deactivates the Microsoft Internet Connection Firewall (ICF). |
| MSCoolServ | X | mscolsrv.exe | Rahack virus |
| MSCRS(mscrs) (MSCRS) | X | mscrs.exe | Added by a variant of the SDBot family of worms and IRC backdoor Trojans. |
| MSCSPTISRV | L | MSCSPTISRV.exe | Related to Sony Corporation. |
| Msdebugsrv | X | dbg32hlp.exe | Added by the SDBOT.CNG
WORM!
Read the link, rootkit type stealth involved.
|
| msdelv (msdevl) | X | msdevl.exe | Added by the W32/IRCBot-VJ WORM! Note: This worm\trojan is located in C:\Program Files\Common Files\System\ |
| msdirectx | X | MSDIRECTX.SYS | Added by the Troj/NtRootK-F
TROJAN! Note: This trojan file is dropped by various other worms and trojans to hide their processes. Read the link, rootkit type stealth involved.
|
| msdll | X | msdll.exe | Added by a variant of the IRCbot family of worms and IRC backdoors. Note: located in C:\%WINDIR%\system\ |
| MSDN Driver (msdndr) | X | msdndr.pif | Added by the Troj/HacDef-EQ TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Msdn Update 32 (msdnupdate32) | X | msdnupdate32 | Added by the W32/Tilebot-M
WORM!
Read the link, rootkit type stealth involved.
|
| Msdn Update 32 (msdnupdate32) | X | msdnupdate32.exe | Added by the SPYBOT.AHT
WORM!
Read the link, rootkit type stealth involved.
|
| Msdtc Manager | X | winlogin.exe | Added by the W32/Rbot-FKU WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| MSDV Driver (msdvdr) | X | msdvdr.pif | A variant of the HackerDefender rootkit . Note: Located in \%WINDIR%\System32\ |
| msecure (mcsecure) | X | mcsecure.exe | Added by the SDBOT.BZJ
WORM!
Read the link, rootkit type stealth involved.
|
| mserv.exe | X | mserv.exe | Related to Trojan.Win32.Killav.br |
| msfsr | X | msfsr.sys | W32/Piggi-B Note: Located in %windir%\system32 Read the link, changes security settings and may disable antivirus programs |
| msftesql | L | msftesql.exe | Related to Microsoft_SQL_server
suite. |
| MsGrd32 | X | MSYRD32.EXE | Added by the SDBOT.BYR
WORM!
Read the link, rootkit type stealth involved.
|
| MsHS64 or cvcworking setting (cvcWork or MsHS64) | X | syscvhost.exe or MsHS64.exe | Added by the W32/Tilebot-BU
WORM!
Note: This worm\trojan file is found in the Windows or Winnt folder. Read the link, rootkit type stealth involved. |
| msie7 | X | msie701.exe | Identified as Trojan_Downloader by PREVX, Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |