| Name | Status | Filename | Description |
|---|
| Microsoft Internet | X | msnm.exe | W32/Sdbot worm variant
|
| Mswincfg | X | Mswincfg32.exe | Added by the BACKDOOR.CYBSPY TROJAN! |
| Microsoft Updatting | X | miroupdate.exe | Added by a variant of the WIN32.RBOT WORM!
|
| Microsoft Update | X | spool.exe | Added by the Troj/Agent-GJC TROJAN! |
| MatrixScreen | X | [filename] | Added by the MATRIXSCREEN TROJAN! |
| Microsoft Update | X | taskmgr32.exe | Added by the W32/Rbot-CV WORM! |
| MSInstall | X | smvss.exe | Added by the TROJ/DEDLER-G TROJAN! |
| MSKExe | U | spamkiller.exe | McAfee SpamKiller |
| MSN messanger | X | msnmsgsm.exe | Added by the W32/Rbot-FMP WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| MplSetup | U | MplSetup.exe | Used by Ricoh network printers to enable network printing from the client |
| Microsoft Internet Firewall | X | firewall.exe | A variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Macromedia Critical Updater | X | rarww.exe | Added by a variant of the WIN32.RBOT WORM!
|
| msresearch | X | tool3.exe | Spy Sheriff/SpywareNO malware component, also detected as the SPYHOAX-A TROJAN, pretends to be a spyware remover! - file names spotted sofar include VXH8JKDQ2.EXE, NS6281400.so, CVXH8JKDQ2.EXE, down3.exe, sefe.exe, winstall.exe, and tool2.exe |
| Microsoft Windows Update x86 | X | firefox.exe ,or, opera.exe | Added by a variant of the Rbot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ |
| Microsoft Sidewinder Game Controller Software | N | SWTRAY.EXE | MS SideWinder game controller system tray icon. Available via Start -> Programs |
| MS Internet Explore | X | MSIEx.exe | Added by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: Located in \%WINDIR%\System32\ |
| Mailbox Verifier | U | mboxvrfy.exe | Mailbox Verifier (MV) is free software that will notify you about new messages arrived to your mailbox. Only works with POP3 mailboxes (not web-mail based systems). You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance) |
| Micrsft Updese | X | xagwxz.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Microsoft Memory Flow Cycle | X | flowcycles.exe | Added by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Microsoft Update Win32x | X | winupdate32x.exe | Added by the W32/Rbot-AJN
WORM!
|
| Motorola Desktop Suite mRouter Config | U | mRouterConfig.exe | Related to mRouterConfig is for configuration of mRouterRuntime. Used by Datassuite Software from Nokia / Siemens Sybian-Based. Note: located in C:\Program Files\... |
| Microsoft Update Services | X | wsnfty.exe | Added by the W32/RBOT-AFU WORM! |
| Microsoft Update Device Drivers | X | wuauclt.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System\drivers\ (Win9x/Me), C:\%WINDIR%\System32\drivers\ (XP/WinNT/2K) |
| Microsoft SCVHOST32 Protocol | X | scvhost32.exe | Added by a variant of the WIN32.RBOT WORM!
|
| msvccc66 | X | dload.exe | Added by a variant of the W32/Rbot-GLS family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ |
| Microsoft Services | X | module.exe | Added by the LAVITS WORM!
|
| Microsoft Windows Logon Process | X | winlogon.exe | Added by the Troj/Proxyser-R TROJAN! |
| MSConfigr | X | jdbgmrg.exe | Added by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here
|
| MS Java for Windows NT, XP & ME | X | xpjavams.exe | Added by the W32/Kassbot-V WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Microsoft Internet Explorer Manager | X | ie.exe | Added by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| msconfig | X | msconfig.exe | CoolWebSearch parasite related. **Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting |
| Microsoft CPU Over Heat Manager | X | CPU.exe | Added by a variant of the Backdoor.IRCBot.USP family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Microsoft | X | msvchost.exe | Added by the W32/Rbot-GAW WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Microsoft Corporation | X | (random,filename) | Added by various VIRUSES such as VISAGES, BABYBEAR and TOFACED |
| Microsoft-software | X | ****.exe (where,* = random,char) | Added by a variant of the WIN32.RBOT WORM!
|
| Microsoft PCHealth32 | X | [path to file] | Added by the TROJ/NICE-A TROJAN! |
| MSPP System Update 64 | X | wiaadmgr.exe | Reported by Kaspersky Anti-Virus as Trojan-Proxy.Win32.Ranky.gen.
Note: This trojan file is found in the System32 folder (NT/2000/XP).
May be found in the System folder for (95/98/ME). |
| Microsoft Locals 332 | X | sywrscds.exe, random file,names | Added by a W32/Rbot-KU worm infection |
| Microsoft Update | X | msconfg.exe | Added by the Win32.Rbot.H WORM! |
| MSN Messenger | X | live.messenger.com | Added by a variant of the IRCBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Multi-function keyboard | U | GWHotkey.exe | Software that sets up the Gateway AnyKey keyboard shortcuts (a series of buttons that allow one-click access to e-mail, browser, volume and CD/DVD controls, etc) |
| Microsoft Windows Update | X | MSNMSGR.EXE | Added by the W32/SDBOT-WM WORM! |
| Micrcsoft Certificate Services | X | cflmon.exe | Added by the W32/Rbot-FWV WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) modifies the system HOSTS file, preventing access to certain anti-virus websites. |
| MDN | X | MDN.exe | Added by the RBOT.AOA WORM! |
| Microsoft Viral Scanning Protection | X | msviral.exe | Added by the W32/Sdbot-CLH
WORM!
Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
|
| Microsoft Update | X | ms.exe | Added by the BKDR_SDBOT.CC WORM! |
| Microsoft DLL Host Service | X | svcdllhst.exe | Added by the BKDR_AGENT.EAK Note: Located in \%WINDIR%\System32\ |
| mule_st_key | X | flec006.exe | Added by the Trojan.Lodeight.C
aka TROJ_BAGLE.AV
Located in %UserProfile%\Application Data\m\flec006.exe
Note: %UserProfile% is a variable that refers to the current user's profile folder. By default, this is C:\Documents and Settings\[CURRENT USER] (Windows NT/2000/XP). |
| Micrsoft CFG 32 | X | lrbzus32.exe | Added by a variant of the AGOBOT/GAOBOT WORM!
|
| mnsa | X | mnso.exe | Added by the Troj/Lineag-AI Trojan Read the link, steals information |
| Microsoft Security Panagers | X | [random file,name] | Added by the W32/RBOT-AIG WORM! |
| MsnExplorer | X | SVCHST.EXE | Added by the TROJ/BDOOR-EB TROJAN! |
| msvload32 | X | msvload32.exe | Added by the W32/RBOT-ACI WORM! |
| Ms Update WinServices NT/XP | X | winservnt32.exe | Added by the W32/Vanebot-G Read the link, keylogger/password stealing trojan(s) involved.
Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| MultiCAM Initializer | U | MCamBoot.exe | The MultiCAM Initializer is part of the MultiCAM software package provided by Vista Imaging in order to run up to 10 USB ViCAM or 3Com Home Connect PC Digital cameras on a single computer. Clears itself from memory once initialized but can also be safely disabled |