Necessary At your option Useless Dangerous Application database
Startupapps.com recommends you:

Detect and remove hidden rootkits using UnHackMe UnHackMe - Rootkit Killer Free fully functional 30-days trial.


RegRun Security Suite = 24 system utilities for protecting your computer. Try now!

Buy Now!

I would like to say that RegRun has helped me on more than 1 occasion when it comes to spyware/adware by letting me know automatically that a piece of it got added to Windows startup. There is so much spyware/addware out there today it's hard to imagine being without RegRun. I like many other features too including the daily registry backups and file protection.

Chris Wagers

m_hook.sys
m00.exe
m0447a.exe
m0uce.exe
m1000rmv.exe
m2.2.exe
m2.exe
m2_dll.exe
m2_jpg.exe
m2_rundll16.exe
m2_selfaxtractor.exe
m32info.exe
m32svco.exe
m3impipe.exe
m3skplay.exe
m3slsrch.exe
m3srchmn.exe
m6603.exe
ma.exe
macfeese.exe
machmn32.sys
macro 2000.exe
mad.dll
mages.exe
magic.exe
mags cool.exe
mail.exe
mailshtirlitz.exe
mailskinner.exe
main16.exe
main32.exe
mainmdd.dll
mainserver.exe
mainxp.exe
makeskinz.exe
malantispam.dll
malwareburn 6.9.exe
malwaredestructor.exe
malwaremonitor.exe
malwaremonitor0.dll
malwaremonitor1.dll
malwaremonitor3.dll
malware-wipe.exe
malwarrior.exe
manager32h.exe
manjwax.exe
mansor.exe
mantispam.exe
manual.exe
marco!.scr
mars_03.exe
masremove.exe
master.exe
masterserver.exe
mat2.exe
matcher.exe
materials_0,88mm.exe
matersparadiswvb9,9.exe
matrix.dll
mav_startupmon.exe
max1d1641.exe
maxd1.exe
maxd64.exe
maxd641.exe
maxm2.exe
maxtor-lan.exe
mazzo2.exe
mblocker.exe
mbsmon32.exe
mbsreg.exe
mbsreg32.exe
mbsrm32.exe
mbssm32.exe
mbt.exe
mc-110-12-0000080.exe
mc-110-12-000012.exe
mc-110-12-0000121.exe
mc-110-12-0000122.exe
mc-110-12-0000129.exe
mc-110-12-0000137.exe
mc-110-12-0000140.exe
mc-110-12-0000181.exe
mc-110-12-0000188.exe
mc-110-12-0000190.exe
mc-110-12-0000193.exe
mc-110-12-0000219.exe
mc-110-12-0000228.exe
mc-110-12-0000229.exe
mc-110-12-0000336.exe
mc22.tmp
mc44a44.exe
mc44a56.exe
mc-58-12-0000140.exe
mc-58-12-0000166.exe
mcache32.exe
mcafe32.exe
mcafee32.exe
mcafeee.exe
mcaffe2005.exe
mcd32.exe
mcfdrv.sys
mchinjdrv.sys
mclaunch.dll
mcm3.exe
mcop.dll
mcsi.exe
mcsys.dll
mdelk.exe
mdiction.exe
mdihole.exe
mdm4.exe
mdm7.exe
mdmcls32.exe
mdmd.exe
mdmdd.exe
mdmprs32.exe
mdnex.exe
medcodec[1].exe
mediaacces.exe
mediaaccess.exe
mediaacck.exe
mediacon.exe
mediagatewayx.dll
medialoads
mediasetup.1395.exe
mediasups.exe
meetink point uninstaller.exe
megahost.dll
megainstaller.exe
melt.exe
mem32.exe
memchk.exe
memdrv.sys
memexecu.exe
memore.exe
memory.exe
mendoza1.exe
mensagem.exe
meruoq.exe
mesenger.exe
messenger.dll
messengerr.exe
messengrs.exe
metasploit.exe
mexplore.exe
mfc48.dll
mfc71.exe
mfc71kor.exe
mfcapi32u.exe
mfcck.exe
mfcee.exe
mfcga32.exe
mfckb.exe
mfcmd32.exe
mfcml32.exe
mfcmp32.exe
mfcnn.exe
mfcod.exe
mfcqp.exe
mfcre.exe
mfcth32.exe
mfcts32.exe
mfcvs32.exe
mfcyp.exe
mfiltis.dll
mfxbox.exe
mgadeskdll.exe
mgrs.exe
mgsaak.dll
mgsbar.dll
mgsrv32.exe
mgsvc.exe
mguard.exe
mgxzex.exe
mh.exe
mhidpe.dll
micasa.dll
micasacache.dll
mickeydeedees.exe
micore.exe
micorsoft.exe
micront.exe
microsoft internet office.exe
microsoft winxp crack.exe
microsoft.dll
microsoft.exe
microsoft32.exe
microsoftconfigurator.exe
microsoftpowerpoint.exe
microsoftupd.exe
microsoft-vacina.exe
microsot1.exe
midaddle.dll
midaddle.exe
midsong.exe
mig2.exe
millenium.exe
mincer.dll
mincer.exe
mine.exe
minibug.exe
minibugtransporter.dll
minigolf_affiliate.exe
minime.exe
minipci.sys
minst.exe
mir3584.exe
miranda_dll.dll
mirarsetup_876075.exe
mirc32.exe
mircplus.exe
mirko.bat
misuvstm.exe
miunst_.exe
mkfxut.exe
mksc.exe
mldsvnwm.exe
mljgg.dll
mljgggd.dll
mljjhif.dll
mllmk.dll
mllml.dll
mllmn.dll
mlm4.exe
mm3.exe
mm4.exe
mmbun.exe
mmcexts.exe
mmcvwli.exe
mmdxsync.exe
mmedia.exe
mmf32.exe
mmfc.exe
mmgsvc.exe
mminstall1.exe
mmod.exe
mmsass~1.dll
mmsete.exe
mmsvc.exe
mmttil.exe
mmwork.exe
mmx19g.sys
mmxbabysandra
mmxharr0.exe
mmxonehour.exe
mmxp2passion.exe
mmxrx2.exe
mmxsnet.exe
mmxxxxmas.exe
mmxxxxmas2.exe
mnew6win.exe
mni41.sys
mntr32.exe
mo.exe
mobysync.exe
mocih.exe
modemspy.exe
modifikasi motor.exe
mohobynz.exe
mome.exe
mon76234.exe
money2.exe
monica.exe
monitorbackups.exe
monterreyc_olive.exe
moonpie.exe
morphrec.exe
mosucker.exe
mosucker2.0.exe
motivebrowser.exe
mousegex.dll
mousepad.exe
mousepad1.exe
mousepad15.exe
mousepad16.exe
mousepad9.exe
mouxgthk.sys
mover2.exe
mozila.exe
mp10setup.exe.exe
mp3epnot.exe
mp98b.exe
mpayy.exe
mpci.exe
mpcodec[1].exe
mpisvc.exe
mpl32.exe
mplay64.exe
mplprogsm.exe
mpn.exe
mpoopmns.exe
mprdll.exe
mprexe16.com
mprmsg32.exe
mptft.exe
mqsign32.dll
mqxdjuz.exe
mr20.dll
mrasearch.dll
mricon1.exe
mrj.exe
mrjj.exe
mroot.exe
mroot.sys
mrtdll.dll
mrtstub.exe
mrup.exe
ms windows local directory
ms windows system alert
ms03132202406.exe
ms1.exe
ms162516202222.exe
ms16prn.exe
ms1src.exe
ms2.exe
ms216.exe
ms22.exe
ms2src.exe
ms3.exe
ms32.dll
ms32.sys
ms32cfg.exe
ms32dll.dll.vbs
ms32sgss.exe
ms4.exe
ms7531.exe
msag.exe
msagentxp.exe
msahgjee.dll
msahker.exe
msalph.exe
msappview32.exe
msasp32.exe
msasvc.exe
msaus.exe
msbb.exe
msbb32.dll
msbd32.exe
msbdv32.exe
msbe.dll
msbin32.exe
msbind32.exe
msblank.exe
msblast.exe
msbn.exe
msboot.exe
msbootmgr.exe
msbvd32.exe
msccn32.exe
msccrt.dll
msccrt.exe
mscde32.exe
mscdt.exe
mscf.exe
mscfg.dll
mscfg.exe
mscheldbra.exe
mschkdsk.exe
mschksys.exe
mschost.exe
mschv32.exe
msclient.exe
msclock.dll
mscmippr.exe
mscnf32.exe
mscnt.exe
mscodr.dll
mscom.exe
mscom32.exe
mscombtl32.exe
mscomfig.exe
mscomm32.exe
mscommand.exe
mscomserv.exe
mscomt32.exe
msconf.exe
msconfg.exe
msconfig32.exe
msconfig38.exe
msconfig45.exe
msconfigs.exe
msconfigx32.exe
mscoriezb.dll
mscoriezz.dll
mscornet.exe
mscppdmg.exe
mscppmgr.exe
mscript.exe
mscs.exe
mscstat.exe
mscsvc.exe
msctl32.exe
msctlwin.exe
msctools.exe
msctvr.exe
mscvb32.exe
msdata.dat
msdataaccess.exe
msdbhk.dll
msdc.exe
msdde.dll
msdeco.dll
msdev.exe
msdhcp32.exe
msdic.dll
msdirect.sys
msdirectx.exe
msdirectx.sys
msdn32.dll
msdnc2.exe
msdnc3.exe
msdnc4.exe
msdndr.sys
msdns.dll
msdnsd32.exe
msdntsrv.exe
msdom2.dll
msdos.exe
msdos32.dll
msdos423.exe
msdos98.exe
msdrc.exe
msdrv.exe
msdrv2.exe
msdrv3.exe
msdrvs32.exe
msdspr.exe
msdts.exe
msdweyer.dll
msdy.exe
msed32.exe
msedit.exe
mseiw.exe
msejavaupdt32.exe
msen.exe
mseng.exe
mservice1.exe
msets.exe
msetss.exe
msetus.exe
msevnt.exe
msexcel.exe
msexnpbi.exe
msf.exe
msfck.exe
msfeed.exe
msfir80.exe
msfirewall.exe
msfnt32i.exe
msfport.dll
msfq32.dll
msfrewall.exe
msfun80.exe
msgate.exe
msgbs1.vxd
msgconfigre.exe
msgconfigrs.exe
msgegh.sys
msgfix.exe
msgmr.exe
msgmsr.exe
msgolder.dll
msgran.exe
msgs7.exe
msgsms.exe
msgsrv.cxe
msgsrv16
msgsrv16.exe
msgsrv36.exe
msgsvr16.exe
msgsvr36.exe
msgsvr64.exe
msguard32.exe
msgw32.dll
mshcp.exe
mshepl.exe
mshlpa.exe
mshome32.exe
mshp.dll
mshq.exe
mshs64.exe
mshtml.exe
mshtml2.exe
mshtml3.exe
mshtml32.exe
mshtmldat32.exe
mshtmlsh32.exe
mshytcsx32.exe
msi211.exe
msi216.exe
msib32.exe
msiconfd.exe
msiconfig.exe
mside.dll
msidle32.exe
msidle32hook.dll
msidll.exe
msie4.exe
msie50h.exe
msiehelper.dll
msiesettings.exe
msiesh.dll
msiev32.dll
msiexec.dll
msiexec128.exe
msiexec16.exe
msiexec32.exe
msiexp.exe
msii.exe
msijavaupdt32.exe
msiloi.dll
msime82.exe
msimms32.dll
msimms32.exe
msimn32.exe
msinfo.exe
msinit.exe
msinst26.exe
msio32.dll
msip32.exe
ms-its.exe
msivsm32.dll
msiwa32.exe
msixu.dll
msj32.exe
msjavam32.exe
msjeclus.exe
msjet32.exe
msjvm.exe
msjvm86.exe
msjwer.exe
msjz32.dll
mskdll.dll
mskernel16.exe
mskernel32.vbs
mskev.exe
mskkk.exe
msksvrvs.exe
mslame.exe
mslaugh.exe
msldr32.dll
mslexec.exe
mslog.exe
msloginserv.dll
msloginservtemp.dll
mslogon.exe
mslogon.exe
msls.exe
msls32.exe
mslsnre.exe
mslti64.exe
msm32.exe
msmachine.exe
msmails.exe
msmapi.exe
msmapi32.exe
msmdev.dll
msmdm.exe
msmduo2.dll
msmessgs.exe
msmgmctl.exe
msmgrxp.exe
msmhost.dll
msmicrosoft.exe
msmm32.dll
msmmsgr.exe
msmoni.exe
msmonk32.exe
msmpatch.exe
msmsger.exe
msmsgnc.dll
msmsgnce.exe
msmsgri32.exe
msmsmg.exe
msmssgs.exe
msn16.exe
msn64.exe
msn7.exe
msnadm32.exe
msnavc32.exe
msnba32.exe
msncfg.exe
msncomm.exe
msndll32.exe
msndn.exe
msnet32.exe
msnetcfg.exe
msnethelper.exe
msng.exe
msnger.exe
msngersd.exe
msngmsngr32.exe
msngr.exe
msngrs.exe
msngta32.exe
msnhlp32.dll
msnhost.dll
msnhp32.dll
msni.exe
msninet.dll
msninet.exe
msninst.exe
msnm32.exe
msnmcgrs.exe
msnmesg.exe
msnmessengerupdate.exe
msnmgr.exe
msnmgr32.exe
msnms.exe
msnmsger.exe
msnmsgr32.exe
msnmsgrr.exe
msnmsgrs.exe
msnmsgrsc.exe
msnmsgs.exe
msnmsgsr.exe
msnmsng.exe
msnmsngrs.exe
msnmsrg.exe
msnmssgr.exe
msnn32.exe
msnnet.exe
msnngr32.exe
msnnsn.exe
msnntlp.exe
msnowen32.exe
msnplus.exe
msnprcss.exe
msnql32.exe
msnqmgr.exe
msnr.exe
msnrav.exe
msnsched2.exe
msnsearc.exe
msnserve.exe
msnservers.exe
msnservez.exe
msnservice.exe
msnsgr.exe
msnsgs.exe
msnspy.exe
msnsrv.exe
msnsrv32.exe
msnss.exe
msnsys.exe
msnt32.exe
msntdugd.exe
msnupdate.exe
msnupdateit.exe
msnwebmgr.exe
msnxpexe.exe
msocfg.exe
msofficer.exe
msofficew.exe
msoft17706.exe
msoftconf.exe
msoftconfs2.exe
msohev.exe
msole.dll
msole32.exe
msole41f.dll
msop.exe
msosv.exe
msosvert.exe
msp32.exe
mspa32.exe
mspbbase.dll
mspbhook.dll
mspc32.dll
mspcidrv.sys
msplock.dll
msplus32.exe
mspm.exe
mspmspv.exe
mspmtwnl.exe
mspn32.exe
mspnspsv.exe
mspradme.exe
msprcss32.exe
msprint32d.exe
mspunin.exe
msq32.exe
msqdevl.exe
msqdevl1.exe
msqmx.sys
msqrsm.exe
msqsearc.exe
msqw32.dll
msr2ca.dll
msrdusrc.dll
msreg.exe
msrege.exe
msreged32.exe
msregscn.exe
msregsv.exe
msresearch.exe
msrexe.exe
msrms32.exe
msrnd.exe
msrpc.exe
msrtspr1.exe
msrundll.exe
msrvcp.exe
mssave.exe
mssbupx.dll
mssc.exe
msscan.exe
msscds32.dll
msscf32.exe
msscmc43.exe
msscra.exe
mssearch.dll
mssecu.exe
mssecure.exe
mssecures.exe
msserrv32.exe
msserv.exe
msserv32.exe
msservices.exe
msservx.exe
msset32.exe
mssheis.exe
msskbtfm.exe
msslut32.exe
mssmbios.exe
mssmgrd.exe
mssmmspgr.exe
mssmp.exe
mssmpp.exe
mssmppp.exe
mssnger.exe
mssock.exe
mssocks.exe
mssql.exe
mssrv32.exe
mssrvs32.exe
msstasks.exe
msstersv.dll
msstl.exe
mssvmdll.dll
mssw32.exe
msswchx.exe
mssync20.exe
mssync20.sys
mssysinfo32.exe
mssystem.exe
mssystem98.exe
mstask.exe.exe
mstask32.exe
mstask33.exe
mstask64.dll
mstaskm.exe
mstaskmgr.exe
mstaskmon.exe
mstasks.exe
mstasks1.exe
mstasks2.exe
mstasks3.exe
mstconfig.exe
mstcp.exe
mstcpdll.exe
mstcpip.exe
mstds.exe
mstesk.exe
msthost.exe
mstint.exe
mstls.exe
mstordb0.exe
mstray.exe
mstscc.exe
mstscex.dll
mstsdsc.exe
mstse.exe
mstsk.exe
mstsk32.dll
mstskmgr.exe
mstskmngr32.exe
msua.exe
msudp4.sys
msupd.exe
msupd5.exe
msupdate32.dll
msupdate32.exe
msupdater.exe
msupdatesys.exe
msupdtm.exe
msurl32.exe
msusb.dll
msutil64.exe
msux32.dll
msvbdll.exe
msvbdll.pif
msvbvm60.dll.exe
msvbvm60.exe
msvc.exe
msvchost.exe
msvcr32.exe
msvcr70a.dll
msvcrs.exe
msvcrt64.dll
msveup.exe
msvirtest.exe
msvoid.dll
msvp32.dll
msvsrv.exe
msvxd.exe
msvz32.dll
mswavedll.exe
mswctl32.exe
mswdm.exe
mswiizz32.exe
mswin32.drv
mswin32.exe
mswindrvr.exe
mswindtc.exe
mswinexpl.exe
mswinpad.exe
mswinrun.exe
mswins.exe
mswinsck.exe
mswinsdl.exe
mswinsrv.exe
mswinsrv32.exe
mswinssl.exe
mswinup.exe
mswinup32.dll
mswinupd.exe
mswiz32.exe
mswksai32.exe
mswld32.exe
mswmf32.exe
mswmgs.exe
msword32.exe
msworld.exe
mswosck.dll
mswsa32.exe
mswsck32.dll
mswservice.exe
mswsgs.exe
mswsus.exe
mswupdate32.exe
msx64.exe
msxct.exe
msxmidi.exe
msxup32.exe
msxw32.exe
msxxxx.exe
msys32.exe
msys9.exe
mszo32.exe
mte3ndi6odoxng.exe
mte3ndi6odoxngmte3ndi6odoxng.exe
mtmtask.dl
mtsdsc.exe
mtsinfoidfile.dll
mtsparamcfgfile.dll
mtx_.exe
mulbin32[1].exe
mumu3.exe
muniu.exe
music.exe
musirc4.72.exe
mutihaka.exe
mutou.exe.exe
mvdmodw.exe
mvr2l99o1.dll
mvsr32.exe
mw_4s_stub.exe
mw_setup.exe
mwinkmdt.exe
mwinlqez.exe
mwinnmdt.exe
mwinpodt.exe
mwinqoeg.exe
mwintmdt.exe
mwiole32.dll
mwlauncher.exe
mws.exe
mwsoeman.exe
mwsoemon.exe
mwsrvacc.exe
mwsvm.exe
mxcrtp.dll
mxd.exe
mxdispdr.sys
mxevwtwv.exe
mxpsp.exe
mxthk16.exe
my documents.exe
my life.scr
my pics.exe
my sexy.exe
my_love.exe
mybabypic.exe
mydocuments.exe
myfoot.exe
myftp.exe
myhost.exe
mypic5.exe
myqhasny.exe
myromeo.exe
mysexy.exe
mysvcc.exe
mytoolbar.dll
myurlff.exe
myurlsagain.exe
mywow.dll
mzkernel32.dll
mzu_drv.sys
mzupdate.exe
mzz.exe

Dangerous  DANGEROUS - M
Updated weekly. Last update: April 9 2018

Improve boot up time Run a free scan to diagnose your PC and identify the system boottle necks slowing you down. Start Test

Fix Windows PC's Fast! Automated Software Repairs damaged & slow windows systems in 1 click.


m_hook.sys
M_hook.sys is a kernel mode driver.
m_hook.sys related to W32.Beagle.DZ Trojan.
Read more:
http://www.symantec.com/avcenter/venc/da...
Kill the file m_hook.sys and remove m_hook.sys from Windows startup using RegRun.
www.regrun.com

m00.exe
M00.exe is Trojan.Moo.
Kill the process m00.exe and remove m00.exe from Windows using RegRun.
www.regrun.com
Read more:
http://securityresponse.symantec.com/avc...

m0447a.exe
M0447A.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq152d6...
Kill the process M0447A.EXE and remove M0447A.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

m0uce.exe
M0uce.exe is Trojan/Backdoor.
Kill the process m0uce.exe and remove m0uce.exe from Windows startup.

m1000rmv.exe
M1000Rmv.exe is Trojan/Backdoor.
Kill the process M1000Rmv.exe and remove M1000Rmv.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

m2.2.exe
M2.2.EXE is Worm Warezov.
Read more:
http://fileinfo.prevx.com/fileinfo.asp?P...
Kill the process M2.2.EXE and remove M2.2.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

m2.exe
Steals passwords / Mail trojan
Can be configuered to register on several different places. Alters Win.ini and/or System.ini, or may be found in the Registry under HKEY_LOCAL_MACHINE\ and/or HKEY_CURRENT_USER.

m2_dll.exe
Steals passwords / Mail trojan
Can be configuered to register on several different places. Alters Win.ini and/or System.ini, or may be found in the Registry under HKEY_LOCAL_MACHINE\ and/or HKEY_CURRENT_USER.

m2_jpg.exe
Steals passwords / Mail trojan
Can be configuered to register on several different places. Alters Win.ini and/or System.ini, or may be found in the Registry under HKEY_LOCAL_MACHINE\ and/or HKEY_CURRENT_USER.

m2_rundll16.exe
Steals passwords / Mail trojan
Can be configuered to register on several different places. Alters Win.ini and/or System.ini, or may be found in the Registry under HKEY_LOCAL_MACHINE\ and/or HKEY_CURRENT_USER.

m2_selfaxtractor.exe
Steals passwords / Mail trojan
Can be configuered to register on several different places. Alters Win.ini and/or System.ini, or may be found in the Registry under HKEY_LOCAL_MACHINE\ and/or HKEY_CURRENT_USER.

m32info.exe
We suggest you to remove m32info.exe from your computer as soon as possible.
M32info.exe is Troj/Crypter-C.
Related files:
audiodrv.exe
audioinf.exe
bluecol.exe
cmdcon.exe
diskinf.exe
dllreg.exe
enhance32.exe
infdisk.exe
kbddrv32.exe
kbdrvinf.exe
main16.exe
main32.exe
mousedrv.exe
mswavedll.exe
msurl32.exe
netdll32.exe
netdllex.exe
p4mx4.exe
m32info.exe
pwr32ctr.exe
pwr32crtl.exe
sd32info.exe
vid32cntl.exe
vidcntl.exe
Read more:
http://www.sophos.com/virusinfo/analyses...
Kill the process m32info.exe and remove m32info.exe from Windows startup.

m32svco.exe
M32svco.exe is Trojan/Backdoor.
Kill the process m32svco.exe and remove m32svco.exe from Windows startup.

m3impipe.exe
M3impipe.exe is Adware.Win32.MyWebSearch Toolbar.
Related files:
M3SKPLAY.EXE
MWSOEMON.EXE
F3SCHMON.EXE
Read more:
http://www.emsisoft.com/en/malware/?Adwa...
Kill the process m3impipe.exe and remove m3impipe.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

m3skplay.exe
M3skplay.exe is Adware.Win32.MyWebSearch Toolbar.
Related files:
M3SKPLAY.EXE
MWSOEMON.EXE
F3SCHMON.EXE
Read more:
http://www.emsisoft.com/en/malware/?Adwa...
Kill the process m3skplay.exe and remove m3skplay.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

m3slsrch.exe
M3slsrch.exe is Adware.Win32.MyWebSearch Toolbar.
Related files:
M3SKPLAY.EXE
MWSOEMON.EXE
F3SCHMON.EXE
Read more:
http://www.emsisoft.com/en/malware/?Adwa...
Kill the process m3slsrch.exe and remove m3slsrch.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

m3srchmn.exe
M3SrchMn.exe is a part of MyWebSearch.
MyWebSearch is a Potentially unwanted application.
Read more:
http://www.sophos.com/security/analyses/...
Kill the process m3SrchMn.exe and remove m3SrchMn.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

m6603.exe
M6603.EXE is Trojan System32 Hijacker.
Directory: %windir%\system32\s6147\
Related files:
%localappdata%\dv6132300x\YESBRON.COM
%WINDIR%\_DEFAULT17562.PIF
%WINDIR%\O4175627.EXE
%windir%\system32\s6147\M6603.EXE
Read more:
http://fileinfo.prevx.com/adware/qq874c4...
Kill the process M6603.EXE and remove M6603.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

ma.exe
ma.exe is a Spyware.IamBigBrother.
ma.exe monitors user Internet activity and private information.
It sends stolen data to a hacker site.
Related files:
cpanel.exe
nl.exe
ctl3d32.dll
winl.dll
dmm.dll
ma.exe
%System%\DOM.dll
%System%\DartFtp.dll
%System%\DartSock.dll
%System%\EncodeX.dll
%System%\MabryObj.dll
%System%\MimeX.dll
%System%\SmtpX.DLL
%Windir%\cp.exe
Adds the value:
"Windows System Tray" = "[PATH TO SECURITY RISK]"
"Windows Service Manager" = "[PATH TO SECURITY RISK]"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill ma.exe process and remove ma.exe from Windows startup using RegRun Startup Optimizer.

macfeese.exe
MACFEESE.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq210d8...
Kill the process MACFEESE.EXE and remove MACFEESE.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

machmn32.sys
Machmn32.sys is Trojan/Backdoor.
Kill the file machmn32.sys and remove machmn32.sys from Windows startup using RegRun Reanimator.
http://www.regrun.com

macro 2000.exe
MACRO 2000.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qqc56c6...
Kill the process MACRO 2000.EXE and remove MACRO 2000.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mad.dll
Mad.dll is Trojan/Backdoor TV Media.
Mad.dll is store in the Windows\System32 folder.
Mad.dll is installed in the AppInit registry key and it automatically injects to each new created process.
Kill the process mad.dll and remove mad.dll from Windows startup.

mages.exe
Worm / File virus
Alters Win.ini. "Between midnight and 2.00am on Wednesdays the worm attempts to display an animated graphic of Adolf Hitler shooting himself in the head." (Sophos)

magic.exe
ServeMe
FTP server

mags cool.exe
MAGS COOL.EXE is Trojan/Backdoor.
Kill the process MAGS COOL.EXE and remove MAGS COOL.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mail.exe
Mail.exe is Trojan.Lhdropper.
Trojan.Lhdropper is a Trojan horse that drops malicious files by exploiting a vulnerability in Lhaca, a freeware application that can compress and decompress LZH archive files.
Related files:
%System%\mail.exe - a copy of Backdoor.Trojan
%Desktop%\[ORIGINAL FILE NAME]\[JAPANESE CHARACTERS].jtd - a clean JustSystem Ichitaro document
%System%\nete.dll - a copy of Backdoor.Trojan
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process mail.exe and remove mail.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mailshtirlitz.exe
Name: Shtirlitz
Steals passwords

mailskinner.exe
MailSkinner.exe is Trojan.Skintrim.
Related files:
%ProgramFiles%\MailSkinner\anim_0.gif
%ProgramFiles%\MailSkinner\anim_help.gif
%ProgramFiles%\MailSkinner\MailSkinner.exe
%ProgramFiles%\MailSkinner\OLSkinner.dll
%ProgramFiles%\MailSkinner\uninst.exe
%WinDir%\pack.epk
%WinDir%\msskinner\msbackup.dat
%WinDir%\Temp\install.exe
%WinDir%\Temp\msksetup.log
%System%\nvs2.inf
%System%\[RANDOM].exe
%System%\[RANDOM].dat
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process MailSkinner.exe and remove MailSkinner.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

main16.exe
We suggest you to remove main16.exe from your computer as soon as possible.
Main16.exe is Troj/Crypter-C.
Related files:
audiodrv.exe
audioinf.exe
bluecol.exe
cmdcon.exe
diskinf.exe
dllreg.exe
enhance32.exe
infdisk.exe
kbddrv32.exe
kbdrvinf.exe
main16.exe
main32.exe
mousedrv.exe
mswavedll.exe
msurl32.exe
netdll32.exe
netdllex.exe
p4mx4.exe
m32info.exe
pwr32ctr.exe
pwr32crtl.exe
sd32info.exe
vid32cntl.exe
vidcntl.exe
Read more:
http://www.sophos.com/virusinfo/analyses...
Kill the process main16.exe and remove main16.exe from Windows startup.

main32.exe
We suggest you to remove main32.exe from your computer as soon as possible.
Main32.exe is Troj/Crypter-C.
Related files:
audiodrv.exe
audioinf.exe
bluecol.exe
cmdcon.exe
diskinf.exe
dllreg.exe
enhance32.exe
infdisk.exe
kbddrv32.exe
kbdrvinf.exe
main16.exe
main32.exe
mousedrv.exe
mswavedll.exe
msurl32.exe
netdll32.exe
netdllex.exe
p4mx4.exe
m32info.exe
pwr32ctr.exe
pwr32crtl.exe
sd32info.exe
vid32cntl.exe
vidcntl.exe
Read more:
http://www.sophos.com/virusinfo/analyses...
Kill the process main32.exe and remove main32.exe from Windows startup.

mainmdd.dll
MAINMDD.DLL is Dropper.Payload.
Read more:
http://fileinfo.prevx.com/adware/qqe8f68...
Kill the file MAINMDD.DLL and remove MAINMDD.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

mainserver.exe
FTP server (?) / Remote Access

mainxp.exe
MAINXP.EXE is Trojan/Backdoor.
Kill the process MAINXP.EXE and remove MAINXP.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

makeskinz.exe
Remote Access
Alters Win.ini and System.ini. A servereditor makes it possible for an intruder to change the port used and the UIN to notify upon a new succesful installation.

malantispam.dll
MalAntiSpam.dll is a part of MalwareDestructor software.
MalwareDestructor is a misleading application that may give exaggerated reports about potential risks on the computer.
Related files:
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\MalwareDestructor 4.5.lnk
C:\Documents and Settings\Administrator\Desktop\MalwareDestructor 4.5.lnk
C:\Documents and Settings\Administrator\Start Menu\Programs\MalwareDestructor\MalwareDestructor 4.5 Un-Installer.lnk
C:\Documents and Settings\Administrator\Start Menu\Programs\MalwareDestructor\MalwareDestructor 4.5 Website.lnk
C:\Documents and Settings\Administrator\Start Menu\Programs\MalwareDestructor\MalwareDestructor 4.5.lnk
C:\Documents and Settings\Administrator\Start Menu\MalwareDestructor 4.5.lnk
Related directory:
C:\Program Files\MalwareDestructor\
Read more:
http://www.symantec.com/enterprise/secur...
Kill the file MalAntiSpam.dll and remove MalAntiSpam.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

malwareburn 6.9.exe
MalwareBurn 6.9.exe is a part of MalwareBurn software.
MalwareBurn is a potentially unwanted application that may give exaggerated reports of threats on the computer.
Related files:
%ProgramFiles%\MalwareBurn 6.9\Lang\English.ini
%ProgramFiles%\MalwareBurn 6.9\MalwareBurn 6.9.url
%ProgramFiles%\MalwareBurn 6.9\mwdb.dat
%ProgramFiles%\MalwareBurn 6.9\Lang\English.ini
%ProgramFiles%\MalwareBurn 6.9\MalwareBurn 6.9.exe
%ProgramFiles%\MalwareBurn 6.9\MalwareBurn 6.9.url
%ProgramFiles%\MalwareBurn 6.9\msvcp71.dll
%ProgramFiles%\MalwareBurn 6.9\msvcr71.dll
%ProgramFiles%\MalwareBurn 6.9\mwdb.dat
%ProgramFiles%\MalwareBurn 6.9\uninst.exe
%UserProfile%\Local Settings\Temp\MWLanguage.ini
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\MalwareBurn 6.9.lnk
%UserProfile%\Desktop\MalwareBurn 6.9.lnk
%UserProfile%\Start Menu\Programs\MalwareBurn 6.9\MalwareBurn 6.9 Website.lnk
%UserProfile%\Start Menu\Programs\MalwareBurn 6.9\MalwareBurn 6.9.lnk
%UserProfile%\Start Menu\Programs\MalwareBurn 6.9\Uninstall MalwareBurn 6.9.lnk
%UserProfile%\Start Menu\MalwareBurn 6.9.lnk
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process MalwareBurn 6.9.exe and remove MalwareBurn 6.9.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

malwaredestructor.exe
MalwareDestructor.EXE is a part of MalwareDestructor software.
MalwareDestructor is a misleading application that may give exaggerated reports about potential risks on the computer.
Related files:
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\MalwareDestructor 4.5.lnk
C:\Documents and Settings\Administrator\Desktop\MalwareDestructor 4.5.lnk
C:\Documents and Settings\Administrator\Start Menu\Programs\MalwareDestructor\MalwareDestructor 4.5 Un-Installer.lnk
C:\Documents and Settings\Administrator\Start Menu\Programs\MalwareDestructor\MalwareDestructor 4.5 Website.lnk
C:\Documents and Settings\Administrator\Start Menu\Programs\MalwareDestructor\MalwareDestructor 4.5.lnk
C:\Documents and Settings\Administrator\Start Menu\MalwareDestructor 4.5.lnk
Related directory:
C:\Program Files\MalwareDestructor\
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process MalwareDestructor.EXE and remove MalwareDestructor.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

malwaremonitor.exe
We suggest you to remove MalwareMonitor.exe from your computer as soon as possible.
MalwareMonitor.exe is a part of MalwareMonitor software.
MalwareMonitor is a misleading application that may give exaggerated reports of threats on the computer.
Related files:
%UserProfile%\Desktop\MalwareMonitor.lnk
%UserProfile%\Start Menu\Programs\MalwareMonitor\MalwareMonitor.lnk
%UserProfile%\Start Menu\Programs\MalwareMonitor\Uninstall.lnk
%ProgramFiles%\MalwareMonitor\MalwareMonitor.exe
%ProgramFiles%\MalwareMonitor\MalwareMonitor.lic
%ProgramFiles%\MalwareMonitor\MalwareMonitor0.dll
%ProgramFiles%\MalwareMonitor\MalwareMonitor0.mm
%ProgramFiles%\MalwareMonitor\MalwareMonitor1.dll
%ProgramFiles%\MalwareMonitor\MalwareMonitor1.mm
%ProgramFiles%\MalwareMonitor\MalwareMonitor3.dll
%ProgramFiles%\MalwareMonitor\Uninstall.exe
Read more:
http://www.symantec.com/business/securit...
Kill the process MalwareMonitor.exe and remove MalwareMonitor.exe from Windows startup.

malwaremonitor0.dll
We suggest you to remove MalwareMonitor0.dll from your computer as soon as possible.
MalwareMonitor0.dll is a part of MalwareMonitor software.
MalwareMonitor is a misleading application that may give exaggerated reports of threats on the computer.
Related files:
%UserProfile%\Desktop\MalwareMonitor.lnk
%UserProfile%\Start Menu\Programs\MalwareMonitor\MalwareMonitor.lnk
%UserProfile%\Start Menu\Programs\MalwareMonitor\Uninstall.lnk
%ProgramFiles%\MalwareMonitor\MalwareMonitor.exe
%ProgramFiles%\MalwareMonitor\MalwareMonitor.lic
%ProgramFiles%\MalwareMonitor\MalwareMonitor0.dll
%ProgramFiles%\MalwareMonitor\MalwareMonitor0.mm
%ProgramFiles%\MalwareMonitor\MalwareMonitor1.dll
%ProgramFiles%\MalwareMonitor\MalwareMonitor1.mm
%ProgramFiles%\MalwareMonitor\MalwareMonitor3.dll
%ProgramFiles%\MalwareMonitor\Uninstall.exe
Read more:
http://www.symantec.com/business/securit...
Kill the file MalwareMonitor0.dll and remove MalwareMonitor0.dll from Windows startup.

malwaremonitor1.dll
We suggest you to remove MalwareMonitor1.dll from your computer as soon as possible.
MalwareMonitor1.dll is a part of MalwareMonitor software.
MalwareMonitor is a misleading application that may give exaggerated reports of threats on the computer.
Related files:
%UserProfile%\Desktop\MalwareMonitor.lnk
%UserProfile%\Start Menu\Programs\MalwareMonitor\MalwareMonitor.lnk
%UserProfile%\Start Menu\Programs\MalwareMonitor\Uninstall.lnk
%ProgramFiles%\MalwareMonitor\MalwareMonitor.exe
%ProgramFiles%\MalwareMonitor\MalwareMonitor.lic
%ProgramFiles%\MalwareMonitor\MalwareMonitor0.dll
%ProgramFiles%\MalwareMonitor\MalwareMonitor0.mm
%ProgramFiles%\MalwareMonitor\MalwareMonitor1.dll
%ProgramFiles%\MalwareMonitor\MalwareMonitor1.mm
%ProgramFiles%\MalwareMonitor\MalwareMonitor3.dll
%ProgramFiles%\MalwareMonitor\Uninstall.exe
Read more:
http://www.symantec.com/business/securit...
Kill the file MalwareMonitor1.dll and remove MalwareMonitor1.dll from Windows startup.

malwaremonitor3.dll
We suggest you to remove MalwareMonitor3.dll from your computer as soon as possible.
MalwareMonitor3.dll is a part of MalwareMonitor software.
MalwareMonitor is a misleading application that may give exaggerated reports of threats on the computer.
Related files:
%UserProfile%\Desktop\MalwareMonitor.lnk
%UserProfile%\Start Menu\Programs\MalwareMonitor\MalwareMonitor.lnk
%UserProfile%\Start Menu\Programs\MalwareMonitor\Uninstall.lnk
%ProgramFiles%\MalwareMonitor\MalwareMonitor.exe
%ProgramFiles%\MalwareMonitor\MalwareMonitor.lic
%ProgramFiles%\MalwareMonitor\MalwareMonitor0.dll
%ProgramFiles%\MalwareMonitor\MalwareMonitor0.mm
%ProgramFiles%\MalwareMonitor\MalwareMonitor1.dll
%ProgramFiles%\MalwareMonitor\MalwareMonitor1.mm
%ProgramFiles%\MalwareMonitor\MalwareMonitor3.dll
%ProgramFiles%\MalwareMonitor\Uninstall.exe
Read more:
http://www.symantec.com/business/securit...
Kill the file MalwareMonitor3.dll and remove MalwareMonitor3.dll from Windows startup.

malware-wipe.exe
Malware-wipe.exe is Trojan/Backdoor.
Kill the process malware-wipe.exe and remove malware-wipe.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

malwarrior.exe
We suggest you to remove MalWarrior.exe from your computer as soon as possible.
MalWarrior.exe is a part of MalWarrior software.
MalWarrior is a misleading application that may give exaggerated reports of threats on the computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported threats.
Related files:
%ProgramFiles%\MalWarrior 2007\MWLauncher.exe
%ProgramFiles%\MalWarrior 2007\unins000.dat
%ProgramFiles%\MalWarrior 2007\unins000.exe
%UserProfile%\Application Data\Adsl Software Limited\MalWarrior 2007\BASE\vbase.dat
%UserProfile%\Application Data\Adsl Software Limited\MalWarrior 2007\MalWarrior.exe
%UserProfile%\Application Data\Adsl Software Limited\MalWarrior 2007\program.ini
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\MalWarrior 2007\BASE\vbase.dat
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\MalWarrior 2007\MalWarrior.exe
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\MalWarrior 2007\program.id
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\MalWarrior 2007\program.ini
C:\Documents and Settings\All Users\Desktop\MalWarrior 2007.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\MalWarrior 2007\MalWarrior 2007.lnk
Read more:
http://www.symantec.com/business/securit...
Kill the process MalWarrior.exe and remove MalWarrior.exe from Windows startup.

manager32h.exe
Manager32h.exe is Trojan/Backdoor.
Kill the process manager32h.exe and remove manager32h.exe from Windows startup.

manjwax.exe
We suggest you to remove manjwax.exe from your computer as soon as possible.
Manjwax.exe is Infostealer.Orcu.B.
Infostealer.Orcu.B is a Trojan horse that attempts to steal confidential information. It may arrive as a message spammed across the Orkut network or through Microsoft instant messaging clients.
Related files:
%Windir%\rnxntup.exe
%UserProfile%\Local Settings\Temp\manjwax.exe
%Windir%\xzmsa.adt
%Windir%\xzoka.adt
%Windir%\xzsui.adt
%Windir%\xzwok.adt
Read more:
http://www.symantec.com/business/securit...
Kill the process manjwax.exe and remove manjwax.exe from Windows startup.

mansor.exe
Mansor.exe is Worm Ircbot Gen.
Read more:
http://virusinfo.prevx.com/pxparall.asp?...
Kill the process mansor.exe and remove mansor.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mantispam.exe
mantispam.exe is a mass-mailing worm W32.Kedebe.B@mm.
mantispam.exe tries to terminate antiviral programs installed on a user computer.
mantispam.exe opens a back door on a random TCP port.
Related files:
%System%\winssc32.exe
%System%\mscppmgr.exe
%System%\kerne132.exe
%System%\NAVMON.EXE
%System%\drwmgr32.exe
%System%\DLLH0ST.EXE
%System%\gcasctrl.exe
%System%\msscan.exe
%System%\cuApp.exe
%System%\LSSAS.EXE
%System%\AVmon.exe
%System%\SERVlCES.EXE
%System%\gcasSav32.exe
%System%\LUC0MS~1.EXE
%System%\zlbclient.exe
%System%\mantispam.exe
%System%\NETM0N.EXE
%System%\srvchost.exe
%System%\USRMGRINIT.JFX
Admin Password Cracker.exe
DVD ripper keygen.exe
Messenger 7.0 Installer.exe
Microsoft AntiSpyware Patch.com
Mydoom removal tool.exe
Naked teen-Actions.com
Norton Personal Firewall 2005 Patch.exe
Spyware remover.exe
Win Server 2003 Remote Exploit.cmd
ZoneAlarm Security Suite 2005 Crack.com
Adds the value:
"Windows [worm filename without extension] Monitor" = "[file name of the worm]"
"Run" = "[file name of the worm]"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill mantispam.exe process and remove mantispam.exe from Windows startup using RegRun Startup Optimizer.

manual.exe
Remote Access

marco!.scr
Dangerous Virus. Kill it!

mars_03.exe
MARS_03.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/fileinfo.asp?P...
Kill the process MARS_03.EXE and remove MARS_03.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

masremove.exe
Masremove.exe is Trojan/Backdoor.
Kill the process masremove.exe and remove masremove.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

master.exe
Remote Access

masterserver.exe
Remote Access / ICQ trojan
Works on Windows 95 and 98, together with ICQ. Also uses Telnet as client. The Zip-file password = xc4an.

mat2.exe
Mat2.exe is Trojan.Slapew.C/
Related files:
%System%\helpermat2.exe
%System%\mat2.exe
Read more:
http://securityresponse.symantec.com/avc...
Kill the process mat2.exe and remove mat2.exe from Windows startup using RegRun.
www.regrun.com

matcher.exe
W32/Matcher@MM Virus.
Kill it!
More info:
http://www.symantec.com/avcenter/venc/da...

materials_0,88mm.exe
MATERIALS_0,88MM.EXE is Trojan.URDVXC.
Read more:
http://fileinfo.prevx.com/fileinfo.asp?P...
Kill the process MATERIALS_0,88MM.EXE and remove MATERIALS_0,88MM.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

matersparadiswvb9,9.exe
Remote Access

matrix.dll
Matrix.dll is WinBudget.Adware.
Related files:
%PROGRAM_FILES%\ winbudget\ bin\ matrix.dll
matrix.dll
Read more:
http://research.sunbelt-software.com/thr...
Kill the file matrix.dll and remove matrix.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mav_startupmon.exe
Mav_startupmon.exe related to WinAntiVirus Pro 2007.
WinAntiVirus Pro 2007 is a rogue security application, related to WinFixer.
Read more:
http://www.spywareremove.com/removemav_s...
Kill the process mav_startupmon.exe and remove mav_startupmon.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

max1d1641.exe
Max1d1641.exe is Trojan Downloader Vxidl R.
Related files:
ksd[1].exe
max1d1641.exe
%profile%\local settings\temp\ma1x1dd1.game
%system%\max1d1641.exe
Read more: https://www.ca.com/be/en/securityadvisor/pest/pest.aspx?id=453112105
Kill the process max1d1641.exe and remove max1d1641.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

maxd1.exe
Maxd1.exe is Trojan/Backdoor.
Kill the process maxd1.exe and remove maxd1.exe from Windows startup.

maxd64.exe
Maxd64.exe is Trojan/Backdoor pron dialer.
Kill the process maxd64.exe and remove maxd64.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

maxd641.exe
MAXD641.EXE is Worm Microsotl 35.
Read more:
http://virusinfo.prevx.com/pxparall.asp?...
Kill the process MAXD641.EXE and remove MAXD641.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

maxm2.exe
MAXM2.EXE is Win32.Randon.D@mm.
Read more:
http://fileinfo.prevx.com/adware/qqe2e26...
Kill the process MAXM2.EXE and remove MAXM2.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

maxtor-lan.exe
Maxtor-lan.exe is Trojan/Backdoor.
Kill the process maxtor-lan.exe and remove maxtor-lan.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mazzo2.exe
MAZZO2.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qqeae76...
Kill the process MAZZO2.EXE and remove MAZZO2.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mblocker.exe
We suggest you to remove MBlocker.exe from your computer as soon as possible.
MBlocker.exe is a part of MessengerBlocker software.
MessengerBlocker is a misleading application that may periodically spam the user's computer with random popups and then prompts the user to purchase a registered version of the application in order to protect against unwanted popups.
Related files:
%UserProfile%\Favorites\Messenger Blocker.url
%UserProfile%\Local Settings\Temp\~[RANDOM CHARACTERS].tmp
C:\Documents and Settings\All User\Desktop\Messenger Blocker.lnk
C:\Documents and Settings\All User\Start Menu\Programs\Messenger Blocker\Messenger Blocker.lnk
C:\Documents and Settings\All User\Start Menu\Programs\Messenger Blocker\Purchase Messenger Blocker.lnk
%CommonProgramFiles%\System\csrss.exe
%CommonProgramFiles%\System\lsass.exe
%CommonProgramFiles%\System\ntsvc.ocx
%CommonProgramFiles%\System\servicelog.txt
%CommonProgramFiles%\System\services.exe
%CommonProgramFiles%\System\smss.exe
%ProgramFiles%\MBlocker\MBlocker.exe
%ProgramFiles%\MBlocker\MessengerBlocker.url
%ProgramFiles%\MBlocker\TranImg6.ocx
%Temp%\~[RANDOM CHARACTERS].tmp
%Temp%\~[RANDOM CHARACTERS].tmp
%System%\servicelog.txt
Read more:
http://www.symantec.com/business/securit...
Kill the process MBlocker.exe and remove MBlocker.exe from Windows startup.

mbsmon32.exe
Mbsmon32.exe is MicroBillSys.
MicroBillSys is a potentially unwanted application that uses aggressive billing and collection service techniques to demand payment for Web site access after a three-day trial period has elapsed. It has been reported that these techniques may even result in a user no longer being able to browse the Internet.
Related files:
%System%\mbssm32.exe
%System%\mbsrm32.exe
%System%\mbsmon32.exe
%System%\mbsreg.exe
%System%\mbsreg32.exe
%System%\rmvalid.exe
%System%\smvalid.exe
%System%\Sexxxpassport.ico
%System%\my sex world.ico
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process mbsmon32.exe and remove mbsmon32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mbsreg.exe
Mbsreg.exe is MicroBillSys.
MicroBillSys is a potentially unwanted application that uses aggressive billing and collection service techniques to demand payment for Web site access after a three-day trial period has elapsed. It has been reported that these techniques may even result in a user no longer being able to browse the Internet.
Related files:
%System%\mbssm32.exe
%System%\mbsrm32.exe
%System%\mbsmon32.exe
%System%\mbsreg.exe
%System%\mbsreg32.exe
%System%\rmvalid.exe
%System%\smvalid.exe
%System%\Sexxxpassport.ico
%System%\my sex world.ico
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process mbsreg.exe and remove mbsreg.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mbsreg32.exe
Mbsreg32.exe is MicroBillSys.
MicroBillSys is a potentially unwanted application that uses aggressive billing and collection service techniques to demand payment for Web site access after a three-day trial period has elapsed. It has been reported that these techniques may even result in a user no longer being able to browse the Internet.
Related files:
%System%\mbssm32.exe
%System%\mbsrm32.exe
%System%\mbsmon32.exe
%System%\mbsreg.exe
%System%\mbsreg32.exe
%System%\rmvalid.exe
%System%\smvalid.exe
%System%\Sexxxpassport.ico
%System%\my sex world.ico
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process mbsreg32.exe and remove mbsreg32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mbsrm32.exe
Mbsrm32.exe is MicroBillSys.
MicroBillSys is a potentially unwanted application that uses aggressive billing and collection service techniques to demand payment for Web site access after a three-day trial period has elapsed. It has been reported that these techniques may even result in a user no longer being able to browse the Internet.
Related files:
%System%\mbssm32.exe
%System%\mbsrm32.exe
%System%\mbsmon32.exe
%System%\mbsreg.exe
%System%\mbsreg32.exe
%System%\rmvalid.exe
%System%\smvalid.exe
%System%\Sexxxpassport.ico
%System%\my sex world.ico
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process mbsrm32.exe and remove mbsrm32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mbssm32.exe
Mbssm32.exe is MicroBillSys.
MicroBillSys is a potentially unwanted application that uses aggressive billing and collection service techniques to demand payment for Web site access after a three-day trial period has elapsed. It has been reported that these techniques may even result in a user no longer being able to browse the Internet.
Related files:
%System%\mbssm32.exe
%System%\mbsrm32.exe
%System%\mbsmon32.exe
%System%\mbsreg.exe
%System%\mbsreg32.exe
%System%\rmvalid.exe
%System%\smvalid.exe
%System%\Sexxxpassport.ico
%System%\my sex world.ico
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process mbssm32.exe and remove mbssm32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mbt.exe
Mailsending trojan
Can mailbomb another user

mc-110-12-0000080.exe
Mc-110-12-0000080.exe is Trojan/Backdoor download agent.
Kill the process mc-110-12-0000080.exe and remove mc-110-12-0000080.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mc-110-12-000012.exe
Mc-110-12-000012.exe is Trojan/Backdoor.
Kill the process mc-110-12-000012.exe and remove mc-110-12-000012.exe from Windows startup.

mc-110-12-0000121.exe
Mc-110-12-0000121.exe is Trojan Downloader.
Kill the process mc-110-12-0000121.exe and remove mc-110-12-0000121.exe from Windows startup.

mc-110-12-0000122.exe
Mc-110-12-0000122.exe is Trojan/Backdoor.
Kill the process mc-110-12-0000122.exe and remove mc-110-12-0000122.exe from Windows startup.

mc-110-12-0000129.exe
MC-110-12-0000129.EXE is Trojan/Backdoor download agent.
Kill the process MC-110-12-0000129.EXE and remove MC-110-12-0000129.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mc-110-12-0000137.exe
Mc-110-12-0000137.exe is Trojan/Backdoor download agent.
Kill the process mc-110-12-0000137.exe and remove mc-110-12-0000137.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mc-110-12-0000140.exe
Mc-110-12-0000140.exe is Trojan/Backdoor FreProd.
Kill the process mc-110-12-0000140.exe and remove mc-110-12-0000140.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mc-110-12-0000181.exe
Mc-110-12-0000181.exe is Trojan/Backdoor.
Kill the process mc-110-12-0000181.exe and remove mc-110-12-0000181.exe from Windows startup.

mc-110-12-0000188.exe
Mc-110-12-0000188.exe is Trojan/Backdoor.
Kill the process mc-110-12-0000188.exe and remove mc-110-12-0000188.exe from Windows startup.

mc-110-12-0000190.exe
Mc-110-12-0000190.exe is Trojan/Backdoor.
Kill the process mc-110-12-0000190.exe and remove mc-110-12-0000190.exe from Windows startup.

mc-110-12-0000193.exe
Mc-110-12-0000193.exe is Trojan/Backdoor.
Kill the process mc-110-12-0000193.exe and remove mc-110-12-0000193.exe from Windows startup.

mc-110-12-0000219.exe
Mc-110-12-0000219.exe is INET DELIVERY adware.
Read more:
http://www.spywaredata.com/spyware/threa...
Kill the process mc-110-12-0000219.exe and remove mc-110-12-0000219.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mc-110-12-0000228.exe
Mc-110-12-0000228.exe is Trojan/Backdoor.
Kill the process mc-110-12-0000228.exe and remove mc-110-12-0000228.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mc-110-12-0000229.exe
Mc-110-12-0000229.exe is Trojan/Backdoor.
Kill the process mc-110-12-0000229.exe and remove mc-110-12-0000229.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mc-110-12-0000336.exe
Mc-110-12-0000336.exe is Adware.
Kill the process mc-110-12-0000336.exe and remove mc-110-12-0000336.exe from Windows startup using RegRun.
www.regrun.com

mc22.tmp
MC22.TMP is Backdoor.Graybird.
Remove MC22.TMP from Windows using RegRun.
www.regrun.com
Read more:
http://www.symantec.com/avcenter/venc/da...

mc44a44.exe
MC44A44.EXE is Trojan Downloader.
Read more:
http://fileinfo.prevx.com/adware/qq8a0a5...
Kill the process MC44A44.EXE and remove MC44A44.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mc44a56.exe
MC44A56.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq75255...
Kill the process MC44A56.EXE and remove MC44A56.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mc-58-12-0000140.exe
Mc-58-12-0000140.exe is Trojan/Backdoor Trojan Agent.
Kill the process mc-58-12-0000140.exe and remove mc-58-12-0000140.exe from Windows startup.

mc-58-12-0000166.exe
Mc-58-12-0000166.exe is Trojan AGENT.
Read more:
http://www.spywaredata.com/spyware/malwa...
Kill the process mc-58-12-0000166.exe and remove mc-58-12-0000166.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mcache32.exe
Mcache32.exe is Trojan/Backdoor.
Kill the process mcache32.exe and remove mcache32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mcafe32.exe
Mcafe32.exe is Trojan/Backdoor.
Kill the process mcafe32.exe and remove mcafe32.exe from Windows startup.

mcafee32.exe
Mcafee32.exe is Trojan/Backdoor.
Mcafee32.exe process adds the value:
[McAfee Windows Protection]= mcafee32.exe
to teh Windows startup registry keys.

mcafeee.exe
Mcafeee.exe is Trojan/Backdoor.
Kill the process mcafeee.exe and remove mcafeee.exe from Windows startup.

mcaffe2005.exe
Mcaffe2005.exe is Trojan/Backdoor.
Kill the process Mcaffe2005.exe and remove Mcaffe2005.exe from Windows startup using RegRun.
www.regrun.com

mcd32.exe
Mcd32.exe is Trojan/Backdoor.
Kill the process mcd32.exe and remove mcd32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mcfdrv.sys
Mcfdrv.sys is Trojan/Backdoor W32/Goldax-A.
Kill the file mcfdrv.sys and remove mcfdrv.sys from Windows startup.
http://www.sophos.com/virusinfo/analyses...

mchinjdrv.sys
MchInjDrv.sys is a driver for injecting code to other processes.
Publisher is legitimate:
http://madshi.net
But it is often used by malicious software.
Kill the file mchInjDrv.sys and remove mchInjDrv.sys from Windows startup.

mclaunch.dll
Mclaunch.dll is Trojan/Backdoor.
Kill the file mclaunch.dll and remove mclaunch.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mcm3.exe
Mcm3.exe is Adware.
Kill the process mcm3.exe and remove mcm3.exe from Windows startup.

mcop.dll
Mcop.dll is Troj/MDrop-BPQ.
Related files:
%Windows%\ichan.txt
%Windows%\inv.txt
%Windows%\libparse.exe
%Windows%\login.txt
%Windows%\mcop.dll
%Windows%\os32.txt
%Windows%\ping.exe
%Windows%\pnp11.exe
%Windows%\psexec.exe
%Windows%\r.ini
%Windows%\reader.w
%Windows%\stde9.exe
%Windows%\tskdbg.exe
%Windows%\vlxd.bat
%Windows%\x89.reg
Read more:
http://www.sophos.com/security/analyses/...
Kill the file mcop.dll and remove mcop.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mcsi.exe
MCSI.EXE is Trojan/Backdoor.
Read more:
http://spywarefiles.prevx.com/RRHHDD2303...
Kill the process MCSI.EXE and remove MCSI.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mcsys.dll
Mcsys.dll is Troj/Pindrop-A.
Related files:
%Windows%\csrss.exe
%Windows%\mcsys.dll
Read more:
http://www.sophos.com/security/analyses/...
Kill the file mcsys.dll and remove mcsys.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mdelk.exe
Mdelk.exe is Trojan TROJ_MITGLIED.AA.
Directory: %Application Data%\m\
Read more:
http://www.trendmicro.com/vinfo/virusenc...
Kill the process mdelk.exe and remove mdelk.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mdiction.exe
MDICTION.EXE is Trojan/Backdoor.
Kill the process MDICTION.EXE and remove MDICTION.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mdihole.exe
Remote Access
Alters Win.ini.

mdm4.exe
Mdm4.exe is Trojan/Backdoor.
Kill the process mdm4.exe and remove mdm4.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mdm7.exe
Mdm7.exe is Trojan/Backdoor.
Kill the process mdm7.exe and remove mdm7.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mdmcls32.exe
Mdmcls32.exe is Trojan/Backdoor.
Kill the process mdmcls32.exe and remove mdmcls32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mdmd.exe
MDMD.EXE is Trojan/Backdoor.
Kill the process MDMD.EXE and remove MDMD.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mdmdd.exe
Mdmdd.exe is Trojan/Backdoor.
Kill the process mdmdd.exe and remove mdmdd.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mdmprs32.exe
Mdmprs32 is Trojan/Backdoor.
Kill the file mdmprs32 and remove mdmprs32 from Windows startup using RegRun Reanimator.
http://www.regrun.com

mdnex.exe
Mdnex.exe is W32.Rinbot.BC.
W32.Rinbot.BC is a worm that spreads to network shares and by exploiting system vulnerabilities.
Related files:
%System%\mdnex.exe
%System%\mozila.exe
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process mdnex.exe and remove mdnex.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

medcodec[1].exe
MEDCODEC[1].EXE is Trojan MedCodec.
Read more:
http://fileinfo.prevx.com/fileinfo.asp?P...
Kill the process MEDCODEC[1].EXE and remove MEDCODEC[1].EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mediaacces.exe
MediaAcces.exe is Trojan/Backdoor.
Kill the process MediaAcces.exe and remove MediaAcces.exe from Windows startup.

mediaaccess.exe
Mediaaccess.exe is Adware.
Kill the process mediaaccess.exe and remove mediaaccess.exe from Windows startup.

mediaacck.exe
MediaAccK.exe is Adware made by Windupdate.
MediaAccK.exe is used forinstalling new Adware components to your computer.
Kill MediaAccK.exe process and remove MediaAccK.exe from Windows startup.

mediacon.exe
Mediacon.exe is Trojan/Backdoor.
Kill the process mediacon.exe and remove mediacon.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mediagatewayx.dll
MediaGatewayX.dll is Adware.
Kill the file MediaGatewayX.dll and remove MediaGatewayX.dll from Windows startup.

medialoads
MediaLoads is a Spyware/Adware.
Remove cnshook.dll using RegRun "Scan for Viruses" feature.
http://www.regrun.com

mediasetup.1395.exe
MEDIASETUP.1395.EXE is Trojan.MediaSetup.
Read more:
http://fileinfo.prevx.com/adware/qq6c986...
Kill the process MEDIASETUP.1395.EXE and remove MEDIASETUP.1395.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mediasups.exe
MediaSups.exe is W32.Mediasups.
Related files:
%UserProfile%\Local Settings\Temp\wowexec.tmp - detected as Trojan Horse
%UserProfile%\Local Settings\Temp\MediaSups.exe
%UserProfile%\Local Settings\Temp\[RANDOM 8 CHARACTER].sys
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process MediaSups.exe and remove MediaSups.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

meetink point uninstaller.exe
MEETINK POINT UNINSTALLER.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq77e26...
Kill the process MEETINK POINT UNINSTALLER.EXE and remove MEETINK POINT UNINSTALLER.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

megahost.dll
MegaHost.dll is a Adware.BestSearch.
MegaHost.dll is a Browser Helper Object.
MegaHost.dll displays advertisement web pages.
Related files:
%UserProfile%\Local Settings\Temp\MegaHost.dll
%UserProfile%\Local Settings\Temp\MegaInstaller.exe
%UserProfile%\Local Settings\Temp\temp.dll
Adds the value:
"@" = "%UserProfile%\Local Settings\Temp\MegaHost.dll"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Remove MegaHost.dll from Windows startup using RegRun Startup Optimizer.

megainstaller.exe
MegaInstaller.exe is a Adware.BestSearch.
MegaInstaller.exe is a Browser Helper Object.
MegaInstaller.exe displays advertisement web pages.
Related files:
%UserProfile%\Local Settings\Temp\MegaHost.dll
%UserProfile%\Local Settings\Temp\MegaInstaller.exe
%UserProfile%\Local Settings\Temp\temp.dll
Adds the value:
"@" = "%UserProfile%\Local Settings\Temp\MegaHost.dll"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill MegaInstaller.exe process and remove MegaInstaller.exe from Windows startup using RegRun Startup Optimizer.

melt.exe
Remote Access
DeepBO is a modified client for Back Orifice. Spreads as one of two utilities: "Nonuke" and "ICQ Inhancer".

mem32.exe
Mem32.exe is W32/Agent-FWF.
Related files:
%system%\notepad.dll
%windows%\mem32.exe
Read more:
http://www.sophos.com/security/analyses/...
Kill the process mem32.exe and remove mem32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

memchk.exe
MemChk.exe is Trojan.Win32.Killav.bx.
Read more:
http://www.viruslist.com/en/viruses/ency...
Kill the process MemChk.exe and remove MemChk.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

memdrv.sys
Memdrv.sys is is Rootki&Virus, clone of HackerDefender.
Kill the file memdrv.sys and remove memdrv.sys from Windows startup.
Use UnHackMe to fully remove hidden services and drivers.
www.unhackme.com
Related files:
- mssave.exe
- msinit.exe
- msmail.exe
- mstsk.exe
- lsnr32w.exe
- lsnr32w.dll
- memdrv.sys
- msclean.exe
- msinit.exe
- mslsnre.exe
- pack.exe
- shide32w.exe
- shide32w.ini
- smss.all
- tiinject.exe
- tinject.dll
- tinject.exe
http://webserver1.furman.edu/computing/c...

memexecu.exe
Memexecu.exe is Trojan/Backdoor.
Kill the process memexecu.exe and remove memexecu.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

memore.exe
Trojan.KillAV.C is a Trojan Horse that disables antivirus and firewall applications.
It is most likely used in conjunction with other threats, such as Backdoor.Zinx or another Backdoor.Trojan.

When this trojan runs, it performs the following actions:
Registers itself as a process.
Copies itself to %Windir%\memore.exe. (The existense of the file memore.exe is an indication of a possible infection.)

Sets the following registry value:
"Memory Check" = "%Windir%\memore.exe"
in the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the Trojan runs when Windows starts.

Opens a shell and executes the following commands:
NET STOP NAVAPSVC
NET STOP AVPCC
NET STOP PERSFW
so that these processes are stopped.

You can use Use RegRun Startup Optimizer to disable this trojan at startup.

memory.exe
Anonymous mailer, mail proxy
Sets up a mail relay, or mail proxy, so that anyone can send mails and make them look like they came from the victim.

mendoza1.exe
Mendoza1.exe is TrojanDropper.Win32.VB.MZ.
Read more:
http://www3.ca.com/securityadvisor/pest/...
Kill the process mendoza1.exe and remove mendoza1.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mensagem.exe
Mensagem.exe is Trojan/Backdoor Bancos.
Kill the process mensagem.exe and remove mensagem.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

meruoq.exe
Meruoq.exe is Trojan/Backdoor.
Kill the process meruoq.exe and remove meruoq.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mesenger.exe
Mesenger.exe is Trojan/Backdoor.
Kill the process mesenger.exe and remove mesenger.exe from Windows startup.

messenger.dll
messenger.dll is a Spyware.NiceSpy.
messenger.dll logs keystrokes.
messenger.dll monitors user Internet activity.
Related files:
%ProgramFiles%\NiceSPY system expert\gdiplus.dll
%ProgramFiles%\NiceSPY system expert\messenger.dll
%ProgramFiles%\NiceSPY system expert\nsserver.exe
%ProgramFiles%\NiceSPY system expert\spydll.dll
%ProgramFiles%\NiceSPY system expert\viewer.exe
Adds the value:
"SystemService" = "C:\Program Files\NiceSPY system expert\nsserver.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Remove messenger.dll from Windows startup using RegRun Startup Optimizer.

messengerr.exe
MESSENGERR.EXE is Worm.Ircbot.
Read more:
http://fileinfo.prevx.com/adware/qq13bc8...
Kill the process MESSENGERR.EXE and remove MESSENGERR.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

messengrs.exe
MESSENGRS.EXE is Worm.Ircbot.
Read more:
http://fileinfo.prevx.com/adware/qqd2738...
Kill the process MESSENGRS.EXE and remove MESSENGRS.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

metasploit.exe
Metasploit.exe is SpywareQuake.
Read more:
http://fileinfo.prevx.com/adware/qq6dbe3...
Kill the process metasploit.exe and remove metasploit.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mexplore.exe
W32.Yaha.AE@mm is a variant of the W32.Yaha.J@mm worm that does the following:

Terminates some antivirus and firewall processes.
Uses its own SMTP engine to email itself to all the contacts in Windows Address Book, MSN Messenger, .NET Messenger, Yahoo Pager, ICQ Pager,
as well as in all the files whose extensions contain the letters HT.
Attempts to spread itself through network-shared folders and mapped drives.
Attempts to spread itself through the KaZaA file-sharing network.
Installs a keylogger and emails the logs to its author.
Performs Denial of Service (DoS) attacks to some specified and random hosts on TCP ports 135, 139, and 445.

The email message has a randomly chosen subject line, message, and attachment name. The attachment will have a .com, .exe, or .zip file extension.

For additional information go to the:
http://securityresponse.symantec.com/avc...

Use RegRun Startup Optimizer to remove it from startup.

mfc48.dll
Mfc48.dll is W32/SillyFDC-AT.
Related files:
%Windows%\java\classes\java.dll
%System%\kernel32.sys
%System%\mfc48.dll
Read more:
http://www.sophos.com/security/analyses/...
Kill the file mfc48.dll and remove mfc48.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mfc71.exe
Mfc71.exe is Trojan/Backdoor.
Kill the process mfc71.exe and remove mfc71.exe from Windows startup.

mfc71kor.exe
MFC71KOR.EXE is Trojan/Backdoor.
Kill the process MFC71KOR.EXE and remove MFC71KOR.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mfcapi32u.exe
Mfcapi32u.exe is W32.Toyep.A@mm.
Directory: %System%
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process mfcapi32u.exe and remove mfcapi32u.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mfcck.exe
Mfcck.exe is Trojan/Backdoor.
Kill the process mfcck.exe and remove mfcck.exe from Windows startup.

mfcee.exe
Mfcee.exe is Trojan.Sdbot.
Kill the process mfcee.exe and remove mfcee.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mfcga32.exe
Mfcga32.exe is Trojan/Backdoor.
Kill the process mfcga32.exe and remove mfcga32.exe from Windows startup.

mfckb.exe
Mfckb.exe is Trojan/Backdoor Downloader Agent.
Kill the process mfckb.exe and remove mfckb.exe from Windows startup.

mfcmd32.exe
Mfcmd32.exe is Trojan/Backdoor.
Kill the process mfcmd32.exe and remove mfcmd32.exe from Windows startup.

mfcml32.exe
Mfcml32.exe is Trojan.Win32.Agent.bi.
Read more:
http://www.viruslist.com/en/viruses/ency...
Kill the process mfcml32.exe and remove mfcml32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mfcmp32.exe
Mfcmp32.exe is Trojan/Backdoor.
Read more:
http://www.spywaredata.com/spyware/malwa...
Kill the process mfcmp32.exe and remove mfcmp32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mfcnn.exe
Ntww.exe is dangerous Trojan/Backdoor.
Ntww.exe changes IE home page to www.v61.com.
Trojan runs a lot of its copies to make the removal hard.
Remove it using RegRun Startup Optmizer to get rid all processes at the same time.
[sdkfr32.exe] C:\WINDOWS\sdkfr32.exe
[mfcyp.exe] C:\WINDOWS\mfcyp.exe
[netrt.exe] C:\WINDOWS\netrt.exe
[ntww.exe] C:\WINDOWS\ntww.exe
[ntdf32.exe] C:\WINDOWS\system32\ntdf32.exe
[ntbw32.exe] C:\WINDOWS\ntbw32.exe
[crbn32.exe] C:\WINDOWS\system32\crbn32.exe
[sdkpn32.exe] C:\WINDOWS\sdkpn32.exe
[d3dl.exe] C:\WINDOWS\d3dl.exe
[mfcod.exe] C:\WINDOWS\mfcod.exe
[apiel.exe] C:\WINDOWS\system32\apiel.exe
[ntxo32.exe] C:\WINDOWS\ntxo32.exe
[atlag.exe] C:\WINDOWS\atlag.exe
[mszo32.exe] C:\WINDOWS\system32\mszo32.exe
[d3qk.exe] C:\WINDOWS\d3qk.exe
[javahd32.exe] C:\WINDOWS\system32\javahd32.exe
[appds32.exe] C:\WINDOWS\appds32.exe
[apipp.exe] C:\WINDOWS\system32\apipp.exe
[mfcnn.exe] C:\WINDOWS\mfcnn.exe
[mfckl.exe] C:\WINDOWS\system32\mfckl.exe
[netlc.exe] C:\WINDOWS\system32\netlc.exe
[atlyi32.exe] C:\WINDOWS\system32\atlyi32.exe
[addtm32.exe] C:\WINDOWS\system32\addtm32.exe
[crad.exe] C:\WINDOWS\crad.exe
[javapt.exe] C:\WINDOWS\system32\javapt.exe
[javauu32.exe] C:\WINDOWS\javauu32.exe
[d3yp.exe] C:\WINDOWS\system32\d3yp.exe
[crwo32.exe] C:\WINDOWS\crwo32.exe
[ieim32.exe] C:\WINDOWS\system32\ieim32.exe
[sysyu.exe] C:\WINDOWS\sysyu.exe
[mfcrr.exe] C:\WINDOWS\system32\mfcrr.exe
[atlfg.exe] C:\WINDOWS\system32\atlfg.exe
[winvr32.exe] C:\WINDOWS\winvr32.exe
[iebp.exe] C:\WINDOWS\system32\iebp.exe
[ipyn.exe] C:\WINDOWS\ipyn.exe
[mspm.exe] C:\WINDOWS\mspm.exe
[javaee.exe] C:\WINDOWS\system32\javaee.exe
[addfm32.exe] C:\WINDOWS\addfm32.exe
[addrs.exe] C:\WINDOWS\addrs.exe
[crfy.exe] C:\WINDOWS\system32\crfy.exe
[crrd.exe] C:\WINDOWS\crrd.exe
[apptr32.exe] C:\WINDOWS\system32\apptr32.exe
[d3wk.exe] C:\WINDOWS\d3wk.exe
[apilk32.exe] C:\WINDOWS\apilk32.exe
[iedm.exe] C:\WINDOWS\system32\iedm.exe
[javagm.exe] C:\WINDOWS\system32\javagm.exe
[ntjw32.exe] C:\WINDOWS\ntjw32.exe
[netdo32.exe] C:\WINDOWS\netdo32.exe
[sysuc32.exe] C:\WINDOWS\system32\sysuc32.exe
[sdknd32.exe] C:\WINDOWS\system32\sdknd32.exe
[addko.exe] C:\WINDOWS\addko.exe
[mfcdh32.exe] C:\WINDOWS\system32\mfcdh32.exe
[sdkij32.exe] C:\WINDOWS\system32\sdkij32.exe
[msen.exe] C:\WINDOWS\system32\msen.exe
[msug.exe] C:\WINDOWS\msug.exe
[crkf32.exe] C:\WINDOWS\crkf32.exe
[winqj.exe] C:\WINDOWS\system32\winqj.exe
[sysgh32.exe] C:\WINDOWS\sysgh32.exe
[d3ud32.exe] C:\WINDOWS\d3ud32.exe
[netnm.exe] C:\WINDOWS\system32\netnm.exe
[apihs32.exe] C:\WINDOWS\system32\apihs32.exe
[addfp.exe] C:\WINDOWS\addfp.exe
[sdkqf32.exe] C:\WINDOWS\sdkqf32.exe
[crpn32.exe] C:\WINDOWS\system32\crpn32.exe
[netae.exe] C:\WINDOWS\netae.exe
[iewb.exe] C:\WINDOWS\system32\iewb.exe
[addkz32.exe] C:\WINDOWS\system32\addkz32.exe
[ipdv.exe] C:\WINDOWS\ipdv.exe
[ntqs32.exe] C:\WINDOWS\system32\ntqs32.exe
[winoo.exe] C:\WINDOWS\system32\winoo.exe
[ipwi.exe] C:\WINDOWS\system32\ipwi.exe
[atlzb.exe] C:\WINDOWS\atlzb.exe
[sysss.exe] C:\WINDOWS\sysss.exe
[appfh32.exe] C:\WINDOWS\appfh32.exe
[sysyh.exe] C:\WINDOWS\sysyh.exe
[msge.exe] C:\WINDOWS\system32\msge.exe

mfcod.exe
Ntww.exe is dangerous Trojan/Backdoor.
Ntww.exe changes IE home page to www.v61.com.
Trojan runs a lot of its copies to make the removal hard.
Remove it using RegRun Startup Optmizer to get rid all processes at the same time.
[sdkfr32.exe] C:\WINDOWS\sdkfr32.exe
[mfcyp.exe] C:\WINDOWS\mfcyp.exe
[netrt.exe] C:\WINDOWS\netrt.exe
[ntww.exe] C:\WINDOWS\ntww.exe
[ntdf32.exe] C:\WINDOWS\system32\ntdf32.exe
[ntbw32.exe] C:\WINDOWS\ntbw32.exe
[crbn32.exe] C:\WINDOWS\system32\crbn32.exe
[sdkpn32.exe] C:\WINDOWS\sdkpn32.exe
[d3dl.exe] C:\WINDOWS\d3dl.exe
[mfcod.exe] C:\WINDOWS\mfcod.exe
[apiel.exe] C:\WINDOWS\system32\apiel.exe
[ntxo32.exe] C:\WINDOWS\ntxo32.exe
[atlag.exe] C:\WINDOWS\atlag.exe
[mszo32.exe] C:\WINDOWS\system32\mszo32.exe
[d3qk.exe] C:\WINDOWS\d3qk.exe
[javahd32.exe] C:\WINDOWS\system32\javahd32.exe
[appds32.exe] C:\WINDOWS\appds32.exe
[apipp.exe] C:\WINDOWS\system32\apipp.exe
[mfcnn.exe] C:\WINDOWS\mfcnn.exe
[mfckl.exe] C:\WINDOWS\system32\mfckl.exe
[netlc.exe] C:\WINDOWS\system32\netlc.exe
[atlyi32.exe] C:\WINDOWS\system32\atlyi32.exe
[addtm32.exe] C:\WINDOWS\system32\addtm32.exe
[crad.exe] C:\WINDOWS\crad.exe
[javapt.exe] C:\WINDOWS\system32\javapt.exe
[javauu32.exe] C:\WINDOWS\javauu32.exe
[d3yp.exe] C:\WINDOWS\system32\d3yp.exe
[crwo32.exe] C:\WINDOWS\crwo32.exe
[ieim32.exe] C:\WINDOWS\system32\ieim32.exe
[sysyu.exe] C:\WINDOWS\sysyu.exe
[mfcrr.exe] C:\WINDOWS\system32\mfcrr.exe
[atlfg.exe] C:\WINDOWS\system32\atlfg.exe
[winvr32.exe] C:\WINDOWS\winvr32.exe
[iebp.exe] C:\WINDOWS\system32\iebp.exe
[ipyn.exe] C:\WINDOWS\ipyn.exe
[mspm.exe] C:\WINDOWS\mspm.exe
[javaee.exe] C:\WINDOWS\system32\javaee.exe
[addfm32.exe] C:\WINDOWS\addfm32.exe
[addrs.exe] C:\WINDOWS\addrs.exe
[crfy.exe] C:\WINDOWS\system32\crfy.exe
[crrd.exe] C:\WINDOWS\crrd.exe
[apptr32.exe] C:\WINDOWS\system32\apptr32.exe
[d3wk.exe] C:\WINDOWS\d3wk.exe
[apilk32.exe] C:\WINDOWS\apilk32.exe
[iedm.exe] C:\WINDOWS\system32\iedm.exe
[javagm.exe] C:\WINDOWS\system32\javagm.exe
[ntjw32.exe] C:\WINDOWS\ntjw32.exe
[netdo32.exe] C:\WINDOWS\netdo32.exe
[sysuc32.exe] C:\WINDOWS\system32\sysuc32.exe
[sdknd32.exe] C:\WINDOWS\system32\sdknd32.exe
[addko.exe] C:\WINDOWS\addko.exe
[mfcdh32.exe] C:\WINDOWS\system32\mfcdh32.exe
[sdkij32.exe] C:\WINDOWS\system32\sdkij32.exe
[msen.exe] C:\WINDOWS\system32\msen.exe
[msug.exe] C:\WINDOWS\msug.exe
[crkf32.exe] C:\WINDOWS\crkf32.exe
[winqj.exe] C:\WINDOWS\system32\winqj.exe
[sysgh32.exe] C:\WINDOWS\sysgh32.exe
[d3ud32.exe] C:\WINDOWS\d3ud32.exe
[netnm.exe] C:\WINDOWS\system32\netnm.exe
[apihs32.exe] C:\WINDOWS\system32\apihs32.exe
[addfp.exe] C:\WINDOWS\addfp.exe
[sdkqf32.exe] C:\WINDOWS\sdkqf32.exe
[crpn32.exe] C:\WINDOWS\system32\crpn32.exe
[netae.exe] C:\WINDOWS\netae.exe
[iewb.exe] C:\WINDOWS\system32\iewb.exe
[addkz32.exe] C:\WINDOWS\system32\addkz32.exe
[ipdv.exe] C:\WINDOWS\ipdv.exe
[ntqs32.exe] C:\WINDOWS\system32\ntqs32.exe
[winoo.exe] C:\WINDOWS\system32\winoo.exe
[ipwi.exe] C:\WINDOWS\system32\ipwi.exe
[atlzb.exe] C:\WINDOWS\atlzb.exe
[sysss.exe] C:\WINDOWS\sysss.exe
[appfh32.exe] C:\WINDOWS\appfh32.exe
[sysyh.exe] C:\WINDOWS\sysyh.exe
[msge.exe] C:\WINDOWS\system32\msge.exe

mfcqp.exe
Mfcqp.exe is Trojan/Backdoor.
Kill the process mfcqp.exe and remove mfcqp.exe from Windows startup.

mfcre.exe
Mfcre.exe is Trojan/Backdoor.
Kill the process mfcre.exe and remove mfcre.exe from Windows startup.

mfcth32.exe
Mfcth32.exe is Trojan/Backdoor.
Kill the process mfcth32.exe and remove mfcth32.exe from Windows startup.

mfcts32.exe
Mfcts32.exe is Trojan/Backdoor.
Kill the process mfcts32.exe and remove mfcts32.exe from Windows startup.

mfcvs32.exe
Mfcvs32.exe is Trojan/Backdoor.
Kill the process mfcvs32.exe and remove mfcvs32.exe from Windows startup.

mfcyp.exe
Ntww.exe is dangerous Trojan/Backdoor.
Ntww.exe changes IE home page to www.v61.com.
Trojan runs a lot of its copies to make the removal hard.
Remove it using RegRun Startup Optmizer to get rid all processes at the same time.
[sdkfr32.exe] C:\WINDOWS\sdkfr32.exe
[mfcyp.exe] C:\WINDOWS\mfcyp.exe
[netrt.exe] C:\WINDOWS\netrt.exe
[ntww.exe] C:\WINDOWS\ntww.exe
[ntdf32.exe] C:\WINDOWS\system32\ntdf32.exe
[ntbw32.exe] C:\WINDOWS\ntbw32.exe
[crbn32.exe] C:\WINDOWS\system32\crbn32.exe
[sdkpn32.exe] C:\WINDOWS\sdkpn32.exe
[d3dl.exe] C:\WINDOWS\d3dl.exe
[mfcod.exe] C:\WINDOWS\mfcod.exe
[apiel.exe] C:\WINDOWS\system32\apiel.exe
[ntxo32.exe] C:\WINDOWS\ntxo32.exe
[atlag.exe] C:\WINDOWS\atlag.exe
[mszo32.exe] C:\WINDOWS\system32\mszo32.exe
[d3qk.exe] C:\WINDOWS\d3qk.exe
[javahd32.exe] C:\WINDOWS\system32\javahd32.exe
[appds32.exe] C:\WINDOWS\appds32.exe
[apipp.exe] C:\WINDOWS\system32\apipp.exe
[mfcnn.exe] C:\WINDOWS\mfcnn.exe
[mfckl.exe] C:\WINDOWS\system32\mfckl.exe
[netlc.exe] C:\WINDOWS\system32\netlc.exe
[atlyi32.exe] C:\WINDOWS\system32\atlyi32.exe
[addtm32.exe] C:\WINDOWS\system32\addtm32.exe
[crad.exe] C:\WINDOWS\crad.exe
[javapt.exe] C:\WINDOWS\system32\javapt.exe
[javauu32.exe] C:\WINDOWS\javauu32.exe
[d3yp.exe] C:\WINDOWS\system32\d3yp.exe
[crwo32.exe] C:\WINDOWS\crwo32.exe
[ieim32.exe] C:\WINDOWS\system32\ieim32.exe
[sysyu.exe] C:\WINDOWS\sysyu.exe
[mfcrr.exe] C:\WINDOWS\system32\mfcrr.exe
[atlfg.exe] C:\WINDOWS\system32\atlfg.exe
[winvr32.exe] C:\WINDOWS\winvr32.exe
[iebp.exe] C:\WINDOWS\system32\iebp.exe
[ipyn.exe] C:\WINDOWS\ipyn.exe
[mspm.exe] C:\WINDOWS\mspm.exe
[javaee.exe] C:\WINDOWS\system32\javaee.exe
[addfm32.exe] C:\WINDOWS\addfm32.exe
[addrs.exe] C:\WINDOWS\addrs.exe
[crfy.exe] C:\WINDOWS\system32\crfy.exe
[crrd.exe] C:\WINDOWS\crrd.exe
[apptr32.exe] C:\WINDOWS\system32\apptr32.exe
[d3wk.exe] C:\WINDOWS\d3wk.exe
[apilk32.exe] C:\WINDOWS\apilk32.exe
[iedm.exe] C:\WINDOWS\system32\iedm.exe
[javagm.exe] C:\WINDOWS\system32\javagm.exe
[ntjw32.exe] C:\WINDOWS\ntjw32.exe
[netdo32.exe] C:\WINDOWS\netdo32.exe
[sysuc32.exe] C:\WINDOWS\system32\sysuc32.exe
[sdknd32.exe] C:\WINDOWS\system32\sdknd32.exe
[addko.exe] C:\WINDOWS\addko.exe
[mfcdh32.exe] C:\WINDOWS\system32\mfcdh32.exe
[sdkij32.exe] C:\WINDOWS\system32\sdkij32.exe
[msen.exe] C:\WINDOWS\system32\msen.exe
[msug.exe] C:\WINDOWS\msug.exe
[crkf32.exe] C:\WINDOWS\crkf32.exe
[winqj.exe] C:\WINDOWS\system32\winqj.exe
[sysgh32.exe] C:\WINDOWS\sysgh32.exe
[d3ud32.exe] C:\WINDOWS\d3ud32.exe
[netnm.exe] C:\WINDOWS\system32\netnm.exe
[apihs32.exe] C:\WINDOWS\system32\apihs32.exe
[addfp.exe] C:\WINDOWS\addfp.exe
[sdkqf32.exe] C:\WINDOWS\sdkqf32.exe
[crpn32.exe] C:\WINDOWS\system32\crpn32.exe
[netae.exe] C:\WINDOWS\netae.exe
[iewb.exe] C:\WINDOWS\system32\iewb.exe
[addkz32.exe] C:\WINDOWS\system32\addkz32.exe
[ipdv.exe] C:\WINDOWS\ipdv.exe
[ntqs32.exe] C:\WINDOWS\system32\ntqs32.exe
[winoo.exe] C:\WINDOWS\system32\winoo.exe
[ipwi.exe] C:\WINDOWS\system32\ipwi.exe
[atlzb.exe] C:\WINDOWS\atlzb.exe
[sysss.exe] C:\WINDOWS\sysss.exe
[appfh32.exe] C:\WINDOWS\appfh32.exe
[sysyh.exe] C:\WINDOWS\sysyh.exe
[msge.exe] C:\WINDOWS\system32\msge.exe

mfiltis.dll
Edmond.exe is Edmond Adware/Spywarer.
Also Edmond.exe is known as Trojan-Downloader.Win32.Ieser.a [Kaspersky], TrojanDownloader.Win32.leser.
Edmond.exe display ads, collects personal information.
Related files:
%System32%\isrvs\desktop.exe
%System32%\edmond.exe
%System32%\ffisearch.exe
%System32%\isrvs\mfiltis.dll
%System32%\isrvs\msdbhk.dll
%System32%\isrvs\sysupd.dll
Remove Delprot.sys driver
Kill the process Edmond.exe and remove Edmond.exe from Windows startup.
Kill other spyware files and clean the registry.

mfxbox.exe
MFXBOX.EXE is Trojan MFXBox.
Read more:
http://fileinfo.prevx.com/adware/qq89204...
Kill the process MFXBOX.EXE and remove MFXBOX.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mgadeskdll.exe
Remote Access / ICQ trojan
Sockets des Troie is French for Trojan Sockets and was one of the very first Remote Access trojans being published.

mgrs.exe
Mgrs.exe is Trojan/Backdoor.
Kill the process mgrs.exe and remove mgrs.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mgsaak.dll
Mgsaak.dll is Troj/Kirsun-A.
Read more:
http://www.sophos.com/security/analyses/...
Kill the file mgsaak.dll and remove mgsaak.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mgsbar.dll
MGSBAR.DLL is MyGlobalSearch Toolbar.
Read more:
http://www3.ca.com/securityadvisor/pest/...
Kill the file MGSBAR.DLL and remove MGSBAR.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

mgsrv32.exe
Prank trojan
Reboots a computer remotely.

mgsvc.exe
Mgsvc.exe is a Trojan Trojan.Horrortel.
Mgsvc.exe spreads by e-mail and via open network shares.
Related files:
%System%\mgsvc.exe
Adds the value:
"Message Queuing Service" = "%System%\mgsvc.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill mgsvc.exe process and remove mgsvc.exe from Windows startup using RegRun Startup Optimizer.

mguard.exe
Mguard.exe is Trojan/Backdoor.
Related files:
1 :%CACHE%\CONTENT.IE5\????????\13627_NETAPI[1].EXE
2 :%CACHE%\CONTENT.IE5\????????\46027_NETAPI[1].EXE
3 :%FAVORITES%\SYSTEM32\MGUARD.EXE
4 :%PROFILES%\ADMINISTRATOR\NOOBO.EXE
5 :%PROGRAMFILES%\AHNLAB\V3\BACKUP\60565_NETAPI[1].EXE
6 :%WINDIR%\SYSTEM32\22131_NETAPI.EXE
7 :%WINDIR%\SYSTEM32\41322_NETAPI.EXE
8 :%WINDIR%\SYSTEM32\41470_NETAPI.EXE
9 :%WINDIR%\SYSTEM32\48262_NETAPI.EXE
10:%WINDIR%\SYSTEM32\50765_NETAPI.EXE
Read more:
http://fileinfo.prevx.com/adware/qq82483...
Kill the process mguard.exe and remove mguard.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mgxzex.exe
Mgxzex.exe is Trojan/Backdoor.
Kill the process mgxzex.exe and remove mgxzex.exe from Windows startup.

mh.exe
Steals passwords

mhidpe.dll
MHIDPE.DLL is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq7bc06...
Kill the file MHIDPE.DLL and remove MHIDPE.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

micasa.dll
MICASA.DLL is Trojan/Backdoor.
Kill the file MICASA.DLL and remove MICASA.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

micasacache.dll
MICASACACHE.DLL is Trojan/Backdoor.
Kill the file MICASACACHE.DLL and remove MICASACACHE.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

mickeydeedees.exe
MICKEYDEEDEES.EXE is Malware.CrackServer.
Read more:
http://fileinfo.prevx.com/adware/qq77a66...
Kill the process MICKEYDEEDEES.EXE and remove MICKEYDEEDEES.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

micore.exe
Micore.exe is a Adware.MediaInject.
Micore.exe displays advertisements.
Micore.exe monitors user Internet activity.
Related files:
Micore.exe
Runc.exe
Expin.dll
Wrdget.dll
Adds the value:
"micore"= "%ProgramFiles%\micore\runc.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill Micore.exe process and remove Micore.exe from Windows startup using RegRun Startup Optimizer.

micorsoft.exe
MICORSOFT.EXE is Worm.Rbot.
Read more:
http://www.superadblocker.com/M/MICORSOF...
Kill the process MICORSOFT.EXE and remove MICORSOFT.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

micront.exe
Micront.exe is W32/Rbot-ABD worm.
Read more:
http://www.sophos.com/security/analyses/...
Kill the process micront.exe and remove micront.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

microsoft internet office.exe
Sircam dangerous virus. Before removing from hard disk you must restore default file extension for exe files.

microsoft winxp crack.exe
Microsoft WinXP Crack.exe is a mass-mailing worm W32.Netsky.C.
Microsoft WinXP Crack.exe spreads via open network shares.
Microsoft WinXP Crack.exe tries to terminate antiviral programs installed on a user computer.
Related files:
%Windir%\Winlogon.exe
Microsoft WinXP Crack.exe
Teen Porn 16.jpg.pif
Adobe Premiere 9.exe
Adobe Photoshop 9 full.exe
Best Matrix Screensaver.scr
Porno Screensaver.scr
Dark Angels.pif
XXX hardcore pic.jpg.exe
Microsoft Office 2003 Crack.exe
Serials.txt.exe
Screensaver.scr
Full album.mp3.pif
Ahead Nero 7.exe
Virii Sourcecode.scr
E-Book Archive.rtf.exe
Doom 3 Beta.exe
How to hack.doc.exe
Learn Programming.doc.exe
WinXP eBook.doc.exe
Win Longhorn Beta.exe
Dictionary English - France.doc.exe
RFC Basics Full Edition.doc.exe
1000 Sex and more.rtf.exe
3D Studio Max 3dsmax.exe
Keygen 4 all appz.exe
Windows Sourcecode.doc.exe
Norton Antivirus 2004.exe
Gimp 1.5 Full with Key.exe
Partitionsmagic 9.0.exe
Star Office 8.exe
Magix Video Deluxe 4.exe
Clone DVD 5.exe
MS Service Pack 5.exe
ACDSee 9.exe
Visual Studio Net Crack.exe
Cracks & Warez Archive.exe
WinAmp 12 full.exe
DivX 7.0 final.exe
Opera.exe
IE58.1 full setup.exe
Smashing the stack.rtf.exe
Ulead Keygen.exe
Lightwave SE Update.exe
The Sims 3 crack.exe
Adds the value:
"ICQ Net" = "%Windir%\winlogon.exe -stealth"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill Microsoft WinXP Crack.exe process and remove Microsoft WinXP Crack.exe from Windows startup using RegRun Startup Optimizer.

Type: Dangerous
Part of operation system: No
Microsoft product: No
File Name: Adobe Premiere 9.exe
Short Description: W32.Netsky.C
Actions:
Adobe Premiere 9.exe is a mass-mailing worm W32.Netsky.C.
Adobe Premiere 9.exe spreads via open network shares.
Adobe Premiere 9.exe tries to terminate antiviral programs installed on a user computer.
Related files:
%Windir%\Winlogon.exe
Microsoft WinXP Crack.exe
Teen Porn 16.jpg.pif
Adobe Premiere 9.exe
Adobe Photoshop 9 full.exe
Best Matrix Screensaver.scr
Porno Screensaver.scr
Dark Angels.pif
XXX hardcore pic.jpg.exe
Microsoft Office 2003 Crack.exe
Serials.txt.exe
Screensaver.scr
Full album.mp3.pif
Ahead Nero 7.exe
Virii Sourcecode.scr
E-Book Archive.rtf.exe
Doom 3 Beta.exe
How to hack.doc.exe
Learn Programming.doc.exe
WinXP eBook.doc.exe
Win Longhorn Beta.exe
Dictionary English - France.doc.exe
RFC Basics Full Edition.doc.exe
1000 Sex and more.rtf.exe
3D Studio Max 3dsmax.exe
Keygen 4 all appz.exe
Windows Sourcecode.doc.exe
Norton Antivirus 2004.exe
Gimp 1.5 Full with Key.exe
Partitionsmagic 9.0.exe
Star Office 8.exe
Magix Video Deluxe 4.exe
Clone DVD 5.exe
MS Service Pack 5.exe
ACDSee 9.exe
Visual Studio Net Crack.exe
Cracks & Warez Archive.exe
WinAmp 12 full.exe
DivX 7.0 final.exe
Opera.exe
IE58.1 full setup.exe
Smashing the stack.rtf.exe
Ulead Keygen.exe
Lightwave SE Update.exe
The Sims 3 crack.exe
Adds the value:
"ICQ Net" = "%Windir%\winlogon.exe -stealth"
to the Windows startup registry keys.
More info: http://securityresponse.symantec.com/avc...
Removal:
Kill Microsoft WinXP Crack.exe process and remove Microsoft WinXP Crack.exe from Windows startup using RegRun Startup Optimizer.

microsoft.dll
Microsoft.dll is Troj/Small-EKE.
Related files:
%Root%\microsoft.dll
%Root%\microsoft.exe
Read more:
http://www.sophos.com/security/analyses/...
Kill the file microsoft.dll and remove microsoft.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

microsoft.exe
Microsoft.exe is Trojan/Backdoor.
Kill the process microsoft.exe and remove microsoft.exe from Windows startup.

microsoft32.exe
Microsoft32.exe is Trojan/Backdoor.
Kill the process microsoft32.exe and remove microsoft32.exe from Windows startup.

microsoftconfigurator.exe
Microsoftconfigurator.exe is Troj/Delf-ALS.
Read more:
http://www.sophos.com/virusinfo/analyses...
Kill the process microsoftconfigurator.exe and remove microsoftconfigurator.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

microsoftpowerpoint.exe
Microsoftpowerpoint.exe is W32/AHKHeap.
Related files:
%Temp%\MicrosoftPowerPoint\MicrosoftPowerPoint\2.mp3 (56,467 bytes) --> Media file
%Temp%\MicrosoftPowerPoint\MicrosoftPowerPoint\drivelist.txt (72 bytes) --> List of drives it tries to replicate
%Temp%\MicrosoftPowerPoint\MicrosoftPowerPoint\Icon.ico (318 bytes) --> Icon file
%Temp%\MicrosoftPowerPoint\MicrosoftPowerPoint\Install.txt (8,743 bytes) --> AutoHotKey Script
%Temp%\MicrosoftPowerPoint\MicrosoftPowerPoint\pathlist.txt (varies) --> List of drives worm is copied to
%Temp%\MicrosoftPowerPoint\MicrosoftPowerPoint\svchost.exe (239,104 bytes) --> Copy of worm
c:\heap41a\2.mp3 (56,467 bytes) --> Media file played when alert box is displayed
c:\heap41a\drivelist.txt (72 bytes) --> List of drives to scan for
c:\heap41a\Icon.ico (318 bytes) --> Icon file
c:\heap41a\reproduce.txt (834 bytes) -->AutoHotKey Script for registry manipulation
c:\heap41a\script1.txt (3,588 bytes) --> AutoHotKey Script for Messagebox creation
c:\heap41a\std.txt (439 bytes) --> AutoHotKey Script for registry manipulation / run other scripts
c:\heap41a\svchost.exe (239,104 bytes) --> Copy of worm
c:\heap41a\offspring\autorun.inf (21 bytes) --> used to autorun the worm when the drive is accessed
Read more:
http://vil.nai.com/vil/content/v_142280....
Kill the process microsoftpowerpoint.exe and remove microsoftpowerpoint.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

microsoftupd.exe
Microsoftupd.exe is W32/Rbot-GRJ.
Read more:
http://www.sophos.com/security/analyses/...
Kill the process microsoftupd.exe and remove microsoftupd.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

microsoft-vacina.exe
Microsoft-vacina.exe is Bancos Trojan.
Bancos runs silently in the background to monitor web browser activities. It can create fake login page for certain Brazilian banking sites which is used for stealing usernames and passwords which can be sent to the attacker via e-mail.
Related files:
vale_plugin.exe
trator_d8.exe
showmessage.exe
pugin-setup.exe
plug-in.exe
photos.exe
notificar.exe
minhas-fotos.exe
winfixer2005freeinstall_pt.exe
virusremovaltool2.5.exe
musicalcards.exe
minhafotinha.exe
microsoft-vacina.exe
mensagem_.exe
fotos.exe
mensagem.exe
fotoscensuradas.exe
foto.exe
dsc000.exe
dl_6.exe
dl_3.exe
clarice.exe
catao.exe
cartao_original.exe
cartao_n0234ig.exe
cartao.exe
carta.exe
boticario.exe
amovoce.exe
Read more:
http://www.securemost.com/articles/rm_ba...
Kill the process microsoft-vacina.exe and remove microsoft-vacina.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

microsot1.exe
Microsot1.exe is Trojan/Backdoor.
Kill the process microsot1.exe and remove microsot1.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

midaddle.dll
MIDADDLE.DLL is Adware made by www.midaddle.com.
Kill the process MIDADDLE.DLL and remove MIDADDLE.DLL from Windows startup.
http://www3.ca.com/securityadvisor/pest/...

midaddle.exe
Midaddle.exe is Adware from www.midaddle.com.
Kill the process midaddle.exe and remove midaddle.exe from Windows startup.

midsong.exe
Worm / File virus
Alters Win.ini. "Between midnight and 2.00am on Wednesdays the worm attempts to display an animated graphic of Adolf Hitler shooting himself in the head." (Sophos)

mig2.exe
Mig2.exe is Trojan.Hiween.
Related files:
C:\mig2.exe
C:\mig2\New Folder.exe
C:\Untukmu.txt
C:\mig2\Folder.htt
C:\Data [USERNAME].exe
%Windir%\mig2.exe
%System%\shell.exe
%System%\MrHelloween.scr
%System%\IExplorer.exe
%CurrentFolder%\Data [USERNAME].exe
C:\Document and Settings\All Users\Start Menu\Programs\Startup\Empty.pif
C:\Document and Settings\[USERNAME]\Local Settings\Application Data\WINDOWS\WINLOGON.EXE
C:\Document and Settings\[USERNAME]\Local Settings\Application Data\WINDOWS\CSRSS.EXE
C:\Document and Settings\[USERNAME]\Local Settings\Application Data\WINDOWS\SERVICES.EXE
C:\Document and Settings\[USERNAME]\Local Settings\Application Data\WINDOWS\LSASS.EXE
C:\Document and Settings\[USERNAME]\Local Settings\Application Data\WINDOWS\SMSS.EXE
C:\Document and Settings\All Users\Start Menu\Programs\Startup\Startup.exe
C:\Document and Settings\All Users\My Documents\My Documents.exe
C:\Document and Settings\All Users\Desktop\Desktop.exe
C:\WINDOWS\System32\config\systemprofile\Start Menu\Programs\Startup\Startup.exe
C:\WINDOWS\System32\config\systemprofile\My Documents\My Documents.exe
C:\WINDOWS\System32\config\systemprofile\Desktop\Desktop.exe
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process mig2.exe and remove mig2.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

millenium.exe
Distributed DoS tool
Alters System.ini (on Windows 95 and 98). Is installed in several different places in the Autostart section. Mre.dll is added tothe Drivers section in System.ini. The trojan usually spreads as a mail attachement disguised as a zip file.

mincer.dll
Mincer.dll is a Microsoft Word macro virus W97M.Minceme.
Related files:
%Windir%\Media\MySpy.dot
%Windir%\System\mincer.dll
%CurrentFolder%\Mincer.exe
Adds the value:
"Mincer" = "%CurrentFolder%\Mincer.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Remove mincer.dll from Windows startup using RegRun Startup Optimizer.

mincer.exe
Mincer.exe is a Microsoft Word macro virus W97M.Minceme.
Related files:
%Windir%\Media\MySpy.dot
%Windir%\System\mincer.dll
%CurrentFolder%\Mincer.exe
Adds the value:
"Mincer" = "%CurrentFolder%\Mincer.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill Mincer.exe process and remove Mincer.exe from Windows startup using RegRun Startup Optimizer.

mine.exe
Steals passwords
Alters Win.ini. May alter System.ini. Steals AOL and AIM passwords. It is hard to remove because the user is stopped from entering Win.ini and Regedit, or from booting in DOS.

minibug.exe
MiniBug.exe is WeatherBug ad plugin.
Kill the process MiniBug.exe and remove MiniBug.exe from Windows using RegRun.
www.regrun.com

minibugtransporter.dll
C:\PROGRAM FILES\AWS\WEATHERBUG\MINIBUGTRANSPORTER.DLL
MINIBUGTRANSPORTER.DLL
Minibug is an adware that displays ads on to your computer. It seems to be a variant of adware WeatherBug.

minigolf_affiliate.exe
Minigolf_affiliate.exe is Adware OverPro.
Kill the process minigolf_affiliate.exe and remove minigolf_affiliate.exe from Windows startup.

minime.exe
Minime.exe is Troj/KillAV-EA.
Related files:
%Program Files%\gridhopefirst\bib dent real.exe - detected as Troj/Swizzor-NJ
%Program Files%\gridhopefirst\dkptivyh.exe - detected as Troj/KillAV-EA
%Program Files%\gridhopefirst\minime.exe - detected as Troj/KillAV-EA
%Program Files%\gridhopefirst\savepeak.exe - detected as Troj/KillAV-EA
%Program Files%\3wPlayer\minime.exe - detected as Troj/KillAV-EA
%System%\drivers\iinipn.sys - detected as Troj/KillAV-DW
%System%\wmfptc32.dl_ - detected as Troj/KillAV-DW
Read more:
http://www.sophos.com/security/analyses/...
Kill the process minime.exe and remove minime.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

minipci.sys
MiniPCI.sys is W32.Lecna.A worm.
Related files:
%System%\iexplore.exe
%System%\drivers\MiniPCI.sys (A rootkit component)
%Windir%\DriverNum.dat
Read more:
http://securityresponse.symantec.com/avc...
Kill the file MiniPCI.sys and remove MiniPCI.sys from Windows startup using RegRun.
www.regrun.com

minst.exe
Minst.exe is Trojan/Backdoor.
Kill the process minst.exe and remove minst.exe from Windows startup.

mir3584.exe
Mir3584.exe is Trojan/Backdoor.
Related files:
1 :%TEMP%\1C3584.EXE
2 :%TEMP%\6F3584.EXE
3 :%TEMP%\73584.EXE
4 :%TEMP%\83584.EXE
5 :%TEMP%\D3584.EXE
6 :%TEMP%\STDRUN53584.EXE
7 :%TEMP%\STDRUN63584.EXE
8 :%TEMP%\UPDATE13584.EXE
9 :%WINDIR%\FEI3584.EXE
10:%WINDIR%\TEMP\POL6D23584.EXE
Read more:
http://fileinfo.prevx.com/adware/qq493d4...
Kill the process mir3584.exe and remove mir3584.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

miranda_dll.dll
Miranda_dll.dll is a part of PrivacyGuarantor.
PrivacyGuarantor is a misleading application that provides false warnings about privacy violations.
Related files:
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Privacy Guarantor v2.0.lnk
%UserProfile%\Desktop\Privacy Guarantor v2.0.lnk %USERPROGRAMS%\Privacy Guarantor
%UserProfile%\Start Menu\Programs\Privacy Guarantor\Privacy Guarantor v2.0 Uninstaller.lnk
%UserProfile%\Start Menu\Programs\Privacy Guarantor\Privacy Guarantor v2.0 Website.lnk
%UserProfile%\Start Menu\Programs\Privacy Guarantor\Privacy Guarantor v2.0.lnk
%UserProfile%\Start Menu\Privacy Guarantor v2.0.lnk
%ProgramFiles%\Privacy Guarantor
%ProgramFiles%\Privacy Guarantor\clean.log
%ProgramFiles%\Privacy Guarantor\dlls\cleaner_dlls.dll
%ProgramFiles%\Privacy Guarantor\dlls\Cleaner_Opera.dll
%ProgramFiles%\Privacy Guarantor\dlls\miranda_dll.dll
%ProgramFiles%\Privacy Guarantor\options.xml
%ProgramFiles%\Privacy Guarantor\Privacy Guarantor.url
%ProgramFiles%\Privacy Guarantor\privacyguarantor.chm
%ProgramFiles%\Privacy Guarantor\PrivacyGuarantor.exe
%ProgramFiles%\Privacy Guarantor\uninst.exe
Read more:
http://www.symantec.com/enterprise/secur...
Kill the file miranda_dll.dll and remove miranda_dll.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mirarsetup_876075.exe
Mirarsetup_876075.exe is Mirar adware.
Read more:
http://www3.cai.com/securityadvisor/pest...
Kill the process mirarsetup_876075.exe and remove mirarsetup_876075.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mirc32.exe
Backdoor.IRC.Spybuzz is a backdoor Trojan horse that uses Internet Relay Chat networks as its backdoor channels.

Copies itself as %System%\Mirc32.exe.
Creates a thread that continuously monitors the registry.

Adds the value:
"Winsock2 driver"="MIRC32.exe"
to the registry keys:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

Creates a thread that logs key strokes and creates the file, %System%\keylog.txt, to store the keystrokes.
Connects to predefined set of IRC servers at port 6667 and waits for commands from the attacker.
Once the backdoor is established, the attacker could control the infected system.

Some of the actions the attacker can perform include:
- Downloading and executing files
- Launching Denial of Service attacks
- Stealing information
- Listing, stopping, and creating processes
- Controlling the file system and list, deleting, renaming, and creating files

Use RegRun Startup Optimizer to automatically remove this registry item.

mircplus.exe
Worm / Mail trojan
If the victim´s copy of WinZip is not registred, the worm tries to do it. Apulia 4 uses all addresses in Outlook and sends a mail with the subject "Crack for ICQ".

mirko.bat
VBS.Krim.G@mm is a mass-mailing worm that sends itself to contacts in the Microsoft Outlook address book and propagates through IRC.
If the C:\mirko.bat file is deleted or renamed, it will modify the autoexec.bat file to format the C: drive.
Arrives as an attachment to an email with the following characteristics:
Subject: SYMANTEC NORTON ANTIVIRUS
Body: REMOVE VIRUS SASSER
Attachment: mirko.bat

Searches for an mIRC installation in any of the following folders:
C:\Mirc
C:\Mirc32
C:\Program Files\Mirc
C:\Program Files\Mirc32

If the worm locates an mIRC installation, it creates a script.ini file to send itself to other IRC users.
Displays the following message:
Hello %username%
Launches C:\mirko.vbs and sends itself to all email addresses in the Outlook address book.

Manual removal:
Navigate to the key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value: "mirko"="c:\mirko.bat"

misuvstm.exe
MISuvstm.exe is Troj/Haoba-A.
Related files:
%System%\MISuvstm.exe
%System%\msivsm32.dll
Read more:
http://www.sophos.com/security/analyses/...
Kill the process MISuvstm.exe and remove MISuvstm.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

miunst_.exe
Miunst_.exe is Trojan/Backdoor.
Kill the process miunst_.exe and remove miunst_.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mkfxut.exe
Msnavc32.exe is the new generation of VX2 adware components.
Msnavc32.exe runs from Windows startup registry keys.
Also, Msnavc32 alters the AppInitDLLs registry value to track all started processes and Internet activity.
Msnavc32 copies its body to the Windows\System32 folder.
Msnavc32 can change WinSock2 LSP chain.
It inserts the dolsp.dll into the LSP chain.

Related files:
0er8k4va.exe
Mkfxut.exe
pkdacs.exe
ywrqku.exe
msnavc32.exe
AutoUpdate.exe
winntcreate.exe
vwix32.exe
sysmonnt.exe
winhcek32.exe
qlykdnb.dll
rypgvtoimrl.exe
spwgoc.exe
msnavc32.exe
sysmonnt
hpdll.exe
w?wexec.exe
ffisearch.exe

Delete the files.
They are may be hidden.

C:\Program Files\0er8k4va\0er8k4va.exe
C:\WINDOWS\System32\Mkfxut.exe
C:\WINDOWS\system32\pkdacs.exe
C:\WINDOWS\System32\ywrqku.exe
C:\windows\system32\msnavc32.exe
C:\Program Files\AutoUpdate\AutoUpdate.exe
C:\WINDOWS\System32\winntcreate.exe
C:\WINDOWS\System32\vwix32.exe
C:\WINDOWS\System32\sysmonnt.exe
C:\WINDOWS\System32\winhcek32.exe
C:\WINDOWS\System32\qlykdnb.dll
C:\WINDOWS\System32\rypgvtoimrl.exe
C:\WINDOWS\System32\spwgoc.exe
C:\windows\system32\msnavc32.exe
C:\WINDOWS\System32\sysmonnt
C:\Program Files\hpdll\hpdll.exe
C:\WINDOWS\System32\w?wexec.exe
C:\WINDOWS\isrvs\ffisearch.exe

Removal:
Use RegRun.
Clear Browser Helper Objects list.
Reset to default the AppInitDlls (Anti Spyware module).
Recover LSP using RegRun Winsock2 recovery.
Kill the processes and remove the virus files from Windows startup.

mksc.exe
Mksc.exe is RelevantKnowledge Spyware.
Read more:
http://www.liutilities.com/products/wint...
Kill the process mksc.exe and remove mksc.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mldsvnwm.exe
MLDSVNWM.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq864b6...
Kill the process MLDSVNWM.EXE and remove MLDSVNWM.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mljgg.dll
MLJGG.DLL is Trojan.WinFixer.
Read more:
http://www.superantispyware.com/definiti...
Kill the file MLJGG.DLL and remove MLJGG.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

mljgggd.dll
Mljgggd.dll is Spyware Quake.
Kill the file mljgggd.dll and remove mljgggd.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mljjhif.dll
Mljjhif.dll is Trojan/Backdoor.
Kill the file mljjhif.dll and remove mljjhif.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mllmk.dll
MLLMK.DLL is Trojan/Backdoor.
Kill the file MLLMK.DLL and remove MLLMK.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

mllml.dll
Mllml.dll is WinFixer component.
Read more:
http://www.fbmsoftware.com/spyware-net/p...
Kill the file mllml.dll and remove mllml.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mllmn.dll
Mllmn.dll is Trojan/Backdoor SurfSidekick.
Kill the file mllmn.dll and remove mllmn.dll from Windows startup.

mlm4.exe
Mlm4.exe is Trojan/Backdoor.
Kill the process mlm4.exe and remove mlm4.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mm3.exe
Mm3.exe is Trojan/Backdoor Trojan.Delf.MM.
Kill the process mm3.exe and remove mm3.exe from Windows startup.

mm4.exe
Mm4.exe is Trojan/Backdoor Proxy.Del.
Kill the process mm4.exe and remove mm4.exe from Windows startup.

mmbun.exe
Mmbun.exe is Troj/Popupper-A.
Kill the process mmbun.exe and remove mmbun.exe from Windows startup.
http://secunia.com/virus_information/113...

mmcexts.exe
Mmcexts.exe is Trojan/Backdoor.
Kill the process mmcexts.exe and remove mmcexts.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mmcvwli.exe
MMCVWLI.EXE is Trojan/Backdoor.
Kill the process MMCVWLI.EXE and remove MMCVWLI.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mmdxsync.exe
Mmdxsync.exe is Trojan/Backdoor.
Kill the process mmdxsync.exe and remove mmdxsync.exe from Windows startup.

mmedia.exe
Mmedia.exe is W32.Mancsyn.
W32.Mancsyn is a worm that spreads by exploiting the Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (Bugtraq ID 8205). It may also download potentially malicious files on to the compromised computer.
Related files:
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\mmedia.exe
C:\WINDOWS\system32\rasman32.exe
C:\Documents and Settings\Default User\Local Settings\Temp\filex.exe
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process mmedia.exe and remove mmedia.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mmf32.exe
Mmf32.exe is Trojan/Backdoor W32/DcomDl-A .
Kill the process mmf32.exe and remove mmf32.exe from Windows startup.
http://www.sophos.com/virusinfo/analyses...

mmfc.exe
Mmfc.exe is Backdoor.Papi.
Related files:
%System%\mmfc.exe
%Temp%\b.bat
%System%\setups.bak
%System%\netlib32.dll%system%\capapi32.dll
wsws~6868.tmp
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process mmfc.exe and remove mmfc.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mmgsvc.exe
Mmgsvc.exe is Trojan/Backdoor.
Kill the process mmgsvc.exe and remove mmgsvc.exe from Windows startup.

mminstall1.exe
Mminstall1.exe is Trojan/Backdoor.
Kill the process mminstall1.exe and remove mminstall1.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mmod.exe
Mmod.exe is Trojan/Backdoor.
Kill the process mmod.exe and remove mmod.exe from Windows startup.

mmsass~1.dll
Mmsass~1.dll is Adware-Boran.
Read more:
http://vil.nai.com/vil/content/v_139225....
Kill the file mmsass~1.dll and remove mmsass~1.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mmsete.exe
Mmsete.exe is a worm W32.Nopir.C .
Mmsete.exe tries to terminate antiviral programs installed on a user computer.
Mmsete.exe deletes .MP3, .AVI, .MPG, .MPEG and .RAR files.
Related files:
C:\Program Files\system prot\mmsete.exe
C:\Program Files\Outlook Express.sav\outlookrem.exe
Adds the value:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\"sysmem" = "C:\Program Files\system prot\mmsete.exe"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\"memory" = "C:\Program Files\Outlook Express.sav\outlookrem.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill mmsete.exe process and remove mmsete.exe from Windows startup using RegRun Startup Optimizer.

mmsvc.exe
Mmsvc.exe is Trojan/Backdoor.
Kill the process mmsvc.exe and remove mmsvc.exe from Windows startup.

mmttil.exe
Mmttil.exe is Trojan/Backdoor.
Kill the process mmttil.exe and remove mmttil.exe from Windows startup.

mmwork.exe
Mmwork.exe is Network1.Popups Adware.
Related files:
newpop61.exe
newpop447.exe
a64sddd.exe
seeve.exe
myurlsagain.exe
myurlff.exe
mmwork.exe
hisistheurls.exe
sixtypopsix.exe
newpop63.exe
newpop62.exe
Read more:
http://www.securemost.com/articles/rm_ne...
Kill the process mmwork.exe and remove mmwork.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mmx19g.sys
MMX19G.SYS is Trojan/Backdoor.
Kill the file MMX19G.SYS and remove MMX19G.SYS from Windows startup using RegRun Reanimator.
http://www.regrun.com

mmxbabysandra
Mmxbabysandra is a Malware Lockx SDbot.
Related files:
%CACHE%\CONTENT.IE5\????????\MMXBABYSANDRA[1].EXE
%CACHE%\CONTENT.IE5\????????\MMXXXXMAS2[1].EXE
%CACHE%\CONTENT.IE5\????????\MMXXXXMAS2[2].EXE
%CACHE%\CONTENT.IE5\????????\MMXXXXMAS2[3].EXE
%programfiles%\joysticksavers\setupfiles\TODOIT.EXE
%WINDIR%\SYSTEM32\MMXDOUBLEEXE.EXE
%WINDIR%\SYSTEM32\VAUELS.EXE
MMXBABYSANDRA.EXE
MXEYN007.EXE
MMXGAMESEXE.EXE
Read more:
http://info.prevx.com/pxparall.asp?PXC=5...
Kill the process mmxbabysandra and remove mmxbabysandra from Windows startup using RegRun.
www.regrun.com

mmxharr0.exe
Mmxharr0.exe is a virus W32.Bleshare!dr.
Mmxharr0.exe spreads via open network shares.
Related files:
bleh.exe
slinstaller.exe
emote.exe
loudnew.exe
mmxharr0.exe
toolbar.exe
%Program Files%\windows adstatus\WinStat.exe
%Program Files%\windows adstatus\WinStatComm.dll
%Program Files%\windows adstatus\WinStatKeep.exe
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill mmxharr0.exe process and remove mmxharr0.exe from Windows startup using RegRun Startup Optimizer.

mmxonehour.exe
Mmxonehour.exe is Trojan/Backdoor.
Kill the process mmxonehour.exe and remove mmxonehour.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mmxp2passion.exe
Mmxp2passion.exe is related to Adware.Popuppers.
Related files:
a65d.exe
Read more:
http://securityresponse.symantec.com/avc...
Kill the process mmxp2passion.exe and remove mmxp2passion.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mmxrx2.exe
Mmxrx2.exe is Trojan/Backdoor.
Kill the process mmxrx2.exe and remove mmxrx2.exe from Windows startup.

mmxsnet.exe
Mmxsnet.exe is Adware.MediaMotor.
Kill the process mmxsnet.exe and remove mmxsnet.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mmxxxxmas.exe
Mmxxxxmas.exe is Trojan/Backdoor.
Kill the process mmxxxxmas.exe and remove mmxxxxmas.exe from Windows startup.

mmxxxxmas2.exe
Mmxxxxmas2.exe is Trojan/Backdoor.
Kill the process mmxxxxmas2.exe and remove mmxxxxmas2.exe from Windows startup.

mnew6win.exe
Mnew6win.exe is Worm Ircbot Gen.
Related files:
%CACHE%\CONTENT.IE5\????????\MLRNEW6[1].EXE
%localsettings%\temporary...s\content.ie5\0la3wtqb\MLRNEW6[1].EXE
%profiles%\andrzej\ustawi...s\content.ie5\3bflh9ig\MLRNEW6[1].EXE
%profiles%\andrzej\ustawi...s\content.ie5\xrsx7r6z\MLRNEW6[1].EXE
%profiles%\ba?tyk\M6.EXE
%profiles%\bubacek\local ...s\content.ie5\wdnlp59e\MLRNEW6[1].EXE
%profiles%\bubacek\MNEW6.EXE
%profiles%\claudio\config...t\content.ie5\8xabijw9\MLRNEW6[1].EXE
%profiles%\default user\l...s\content.ie5\8qxb5z4k\MLRNEW6[1].EXE
%profiles%\qba\ustawienia...s\content.ie5\25fxnjmb\MLRNEW6[1].EXE
Read more:
http://fileinfo.prevx.com/QQ26ee21287346...
Kill the process mnew6win.exe and remove mnew6win.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mni41.sys
Mni41.sys is Trojan.Srizbi.
Trojan.Srizbi is a Trojan horse that sends spam and uses a rootkit to hide itself.
Read more:
http://www.symantec.com/enterprise/secur...
Kill the file Mni41.sys and remove Mni41.sys from Windows startup using RegRun Reanimator.
http://www.regrun.com

mntr32.exe
Mntr32.exe is Trojan/Backdoor.
Kill the process mntr32.exe and remove mntr32.exe from Windows startup.

mo.exe
Mo.exe is a Backdoor W32.Kelvir.AL.
Mo.exe spreads via MSN Messenger.
Mo.exe tries to terminate antiviral programs installed on a user computer.
Mo.exe monitors user Internet activity and private information.
It sends stolen data to a hacker site.
Related files:
%ProgramFiles%\slp\mo.exe
%ProgramFiles%\slp\syatem.exe
%System%\aolmsg.exe
Adds the value:
"Aol Instant Messenger" = "aolmsg.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill mo.exe process and remove mo.exe from Windows startup using RegRun Startup Optimizer.

mobysync.exe
Mobysync.exe is Trojan/Backdoor.
Kill the process mobysync.exe and remove mobysync.exe from Windows startup.

mocih.exe
Mocih.exe is Trojan/Backdoor.
Mocih.exe creates the service: ACCRA
Display Name: Trace network connections
Description: Managing network connections
Mocih.exe connects to the servers:
195.225.177.37
pigmailer.scarryserv.biz
and sends spam messages.
Kill the process mocih.exe and remove mocih.exe from Windows startup.
Disable ACCRA service.

modemspy.exe
Modemspy.exe is Trojan/Backdoor.
Steals passwords and user private information.
Read more:
http://www3.ca.com/securityadvisor/pest/...
Kill the process modemspy.exe and remove modemspy.exe from Windows startup.

modifikasi motor.exe
Modifikasi motor.exe is W32.Kasimod.A.
W32.Kasimod.A is a worm that spreads by copying itself to network drives and removable storage devices.
Related files:
%SystemDrive%\computername.reg
%SystemDrive%\information.reg
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process modifikasi motor.exe and remove modifikasi motor.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mohobynz.exe
MOHOBYNZ.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq0c506...
Kill the process MOHOBYNZ.EXE and remove MOHOBYNZ.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mome.exe
Remote Access / Virus dropper
Among other features the trojan can drop the Ping-Pong virus.

mon76234.exe
MON76234.exe is Trojan Wareout.
Kill the process MON76234.exe and remove MON76234.exe from Windows startup.
http://www.doxdesk.com/parasite/WareOut....

money2.exe
Money2.exe is Trojan/Backdoor.
Kill the process money2.exe and remove money2.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

monica.exe
Worm / Mail trojan
Uses several different names to name the attachement, which can be mailed by either Netscape Mail, MS Outlook or MSOutlook Express.

monitorbackups.exe
MONITORBACKUPS.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq00025...
Kill the process MONITORBACKUPS.EXE and remove MONITORBACKUPS.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

monterreyc_olive.exe
MONTERREYC_OLIVE.EXE is Adware.Webhancer.
Read more:
http://fileinfo.prevx.com/adware/qq3fc18...
Kill the process MONTERREYC_OLIVE.EXE and remove MONTERREYC_OLIVE.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

moonpie.exe
Remote Access / Keylogger
Telnet can be used as client to port 25982 and record anything typed on the infetced computer.

morphrec.exe
Morphrec.exe is an adware program Adware.BetterInternet.
Morphrec.exe is a Browser Helper Object.
Morphrec.exe downloads and displays advertisements.
Related files:
%Windir%\Bi.dll
%Windir%\speeryox.dll
%Windir%\Mxtarget.dll
%Windir%\BTGrab.dll
%Windir%\farmmext.exe
%Windir%\dlmax.dll
%Windir%\speer2.dll
%Windir%\VoiceIP.dll
%Windir%\morphacl.dll
%Windir%\Pynix.dll
%Windir%\Biprep.exe
%Windir%\banner.dll
%System%\laziqn.exe
%System%\xxvyaj.exe
%System%\wbtvsffd.exe
%System%\nnmzoq.exe
%Temp%\DrTemp\thnall1b.exe
%Temp%\DrTemp\thnall1p.exe
%Temp%\DrTemp\thnall2r.exe
%Temp%\DrTemp\polall1b.exe
%Temp%\thnall1s.exe
%Temp%\morphrec.exe
Adds the value:
"[File name of adware]" = "[File path to adware]"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill morphrec.exe process and remove morphrec.exe from Windows startup using RegRun Startup Optimizer.

mosucker.exe
Remote Access
May alter System.ini and/or Win.ini. One can choose to let Mosucker randomly decide what autostart method to use. Produces an error message while installing ""Could not find setuplog.bat"" which apparently is used for autostarting. It copies itself to $temp first, as a file named pkg*.exe, ""pkg"" being a fix string. It also copied itself to $windows/unin0686.exe.

mosucker2.0.exe
Remote Access
May alter System.ini and/or Win.ini. One can choose to let Mosucker randomly decide what autostart method to use. Produces an error message while installing ""Could not find setuplog.bat"" which apparently is used for autostarting. It copies itself to $temp first, as a file named pkg*.exe, ""pkg"" being a fix string. It also copied itself to $windows/unin0686.exe.

motivebrowser.exe
MotiveBrowser.exe is Trojan.Syginre.
Related files:
[DRIVE LETTER]\TaskManager.exe
[DRIVE LETTER]\Rundll32.exe
[DRIVE LETTER]\CCAPP.exe
[DRIVE LETTER]\alg.exe
[DRIVE LETTER]\AluScheduler.exe
[DRIVE LETTER]\CachemanXP.exe
[DRIVE LETTER]\lsass.exe
[DRIVE LETTER]\msdtc.exe
[DRIVE LETTER]\NPROTECT.exe
[DRIVE LETTER]\NOPDE.exe
[DRIVE LETTER]\dllhost.exe
[DRIVE LETTER]\CCPROXY.exe
[DRIVE LETTER]\csrss.exe
[DRIVE LETTER]\MotiveBrowser.exe
[DRIVE LETTER]\smss.exe
[DRIVE LETTER]\svchost.exe
[DRIVE LETTER]\spoolsv.exe
[DRIVE LETTER]\System Idle Process.exe
[DRIVE LETTER]\zlclient.exe
[DRIVE LETTER]\System.exe
[DRIVE LETTER]\winlogon.exe
Trojan.Syginre is a Trojan horse that disables the Windows Firewall and may delete some files from the compromised computer.
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process MotiveBrowser.exe and remove MotiveBrowser.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mousegex.dll
Mousegex.dll is Trojan/Backdoor.
Kill the file mousegex.dll and remove mousegex.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mousepad.exe
Mousepad.exe is Trojan/Backdoor.
Kill the process mousepad.exe and remove mousepad.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mousepad1.exe
Mousepad1.exe is Trojan/Backdoor Downloader.
Kill the process mousepad1.exe and remove mousepad1.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mousepad15.exe
MOUSEPAD15.EXE is Trojan/Backdoor.
Kill the process MOUSEPAD15.EXE and remove MOUSEPAD15.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mousepad16.exe
Mousepad16.exe is Spyware.
Kill the process mousepad16.exe and remove mousepad16.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mousepad9.exe
Mousepad9.exe is Trojan/Backdoor.
Kill the process mousepad9.exe and remove mousepad9.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mouxgthk.sys
MOUXGTHK.SYS is Trojan/Backdoor.
Kill the file MOUXGTHK.SYS and remove MOUXGTHK.SYS from Windows startup using RegRun Reanimator.
http://www.regrun.com

mover2.exe
MOVER2.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qqacb06...
Kill the process MOVER2.EXE and remove MOVER2.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mozila.exe
Mozila.exe is W32/Delbot-AJ.
Read more:
http://www.sophos.com/security/analyses/...
Kill the process mozila.exe and remove mozila.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mp10setup.exe.exe
MP10SETUP.EXE.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qqf2365...
Kill the process MP10SETUP.EXE.EXE and remove MP10SETUP.EXE.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mp3epnot.exe
MP3EPNOT.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq41348...
Kill the process MP3EPNOT.EXE and remove MP3EPNOT.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mp98b.exe
Remote Access

mpayy.exe
Mpayy.exe is Troj/BeastPWS-H.
Related files:
%Windows%\mpayy.dll
%Windows%\qnudj.hed
Read more:
http://www.sophos.com/security/analyses/...
Kill the process mpayy.exe and remove mpayy.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mpci.exe
MPCI.EXE is Trojan/Backdoor Rbot.
Kill the process MPCI.EXE and remove MPCI.EXE from Windows startup.

mpcodec[1].exe
MPCODEC[1].EXE is Trojan MPCodec.
Related files:
1 :%appdata%\mozilla\firefox...lzkqxpyn.default\cache\C9BA0EEBD01
2 :%DESKTOP%\MPCODEC.EXE
3 :%DOCUMENTS%\WMV\MPCODEC.EXE
4 :%localappdata%\mozilla\fi...azyiepsk.default\cache\C9BA0EEBD01
5 :%TEMP%\8YO2ZY9T.EXE
6 :%TEMP%\V6MXRQLB.EXE
Read more:
http://fileinfo.prevx.com/fileinfo.asp?P...
Kill the process MPCODEC[1].EXE and remove MPCODEC[1].EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mpisvc.exe
Backdoor.Mipsiv is a Trojan horse that connects to an IRC server and allows an attacker to preform keylogging and network scanning functions.

Copies itself as %System%\mpisvc.exe.

Adds the value: "MapiDrv" = "%System%\mpisvc.exe"
to the registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

Attempts to connect to a predetermined IRC server and channel on TCP port 443.
Awaits commands from an attacker.
The Trojan provides the attacker with keylogging and network scanning functionality.

Use RegRun Startup Optimizer to remove this worm.

mpl32.exe
Troj/Loony-M is a backdoor Trojan which allows unauthorised remote access to the infected computer via IRC channels.
It may display a fake error message with the title "Error-388" and the text "A valid driver.dll file was not found".

Manual removal:
Locate the HKEY_LOCAL_MACHINE entry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
and delete the value: MPL32 Driver = "MPL32.exe" if it exists.
Or use RegRun Startup Optimizer to automatically remove it from startup.

mplay64.exe
Mplay64.exe is Trojan/Backdoor.
Kill the process mplay64.exe and remove mplay64.exe from Windows startup.

mplprogsm.exe
MPLPROGSM.EXE is Trojan/Backdoor.
Read more:
http://virusinfo.prevx.com/pxparall.asp?...
Kill the process MPLPROGSM.EXE and remove MPLPROGSM.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mpn.exe
Mpn.exe is W32/Delbot-W.
W32/Delbot-W is a backdoor IRC worm which allows a remote intruder to gain access and control over the computer.
Read more:
http://www.sophos.com/security/analyses/...
Kill the process mpn.exe and remove mpn.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mpoopmns.exe
MPOOPMNS.EXE is Trojan/Backdoor.
Kill the process MPOOPMNS.EXE and remove MPOOPMNS.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mprdll.exe
Remote Access / Steals passwords
The client also drops a server! The hacker could choose to log passwords only or all text written. One of the functions is to kill antivirus software.

mprexe16.com
MPR16.COM is Trojan (Remote Access / FTP server).
Removal:
Use RegRun AntiSpyware.
Reset to default:
[Current Home Page]
HOMEOldSP=
http://%77%71%6F%78%61%6E%2E%74%2E%6D%75...
[Search Assistant]
SearchAssistant=http://%77%71%6F%78%61%6E%2E%74%2E%6D%75...
[URLSearchHook] {7CE941D9-51CE-9950-7B79-1A0C1569D890}=C:\WINDOWS\Iamcahxj.dll
[Toolbars] {91464AB2-0115-27ED-FBD9-47A7A7A7A7E5}=C:\WINDOWS\Iamcahxj.dll
[Registry Run] PCI Device 32=C:\WINDOWS\SYSTEM\PCIDev32.exe
Open RegRun Start Control Right click and choose Terminate.
Repeat for
[Registry Run] WIN16/DOS Network Interface Service Process=C:\WINDOWS\SYSTEM\Mprexe16.com
[Startup Folder] Validate Antivirus.lnk=C:\ANYWARE\AAWIN.EXE
Check if it is legitimate file.
Remove:
[Win.ini] run=C:\WINDOWS\AsdDLL32.exe
Kill the process AsdDLL32.exe using RegRun Process Manager.r

mprmsg32.exe
Mprmsg32.exe is a mass-mailing worm W32.Mytob.CF@mm.
Mprmsg32.exe tries to terminate antiviral programs installed on a user computer.
Mprmsg32.exe spreads through the network by exploiting the Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (Microsoft Security Bulletin MS03-026) and the Microsoft Windows Local Security Authority Service Remote Buffer Overflow (Microsoft Security Bulletin MS04-011).
Related files:
%System%\mprmsg32.exe
C:\my_photo2005.scr
C:\see_this!!.scr
C:\funny_pic.scr
C:\hellmsn.exe
Adds the value:
"MPR MSG" = "mprmsg32.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill mprmsg32.exe process and remove mprmsg32.exe from Windows startup using RegRun Startup Optimizer.

mptft.exe
MPTFT.EXE is Covert Sys Exec malware.
Directory: %WINDIR%\SYSTEM32\
Read more:
http://fileinfo.prevx.com/adware/qq20d42...
Kill the process MPTFT.EXE and remove MPTFT.EXE from Windows startup using RegRun.
www.regrun.com

mqsign32.dll
MQSIGN32.DLL is Trojan/Backdoor.
Kill the file MQSIGN32.DLL and remove MQSIGN32.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

mqxdjuz.exe
Mqxdjuz.exe is Trojan/Backdoor.
Kill the process mqxdjuz.exe and remove mqxdjuz.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mr20.dll
Mr20.dll is Trojan/Backdoor.
Kill the file mr20.dll and remove mr20.dll from Windows startup.

mrasearch.dll
MRASEARCH.DLL is Adware.MraSearch.
Read more:
http://www.popupsentry.com/M/MRASEARCH.D...
Kill the file MRASEARCH.DLL and remove MRASEARCH.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

mricon1.exe
Mricon1.exe is Trojan/Backdoor.
Read more:
http://www.incodesolutions.com/threats/S...
Kill the process mricon1.exe and remove mricon1.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mrj.exe
Mrj.exe is Trojan/Backdoor Trojan.Win32.LowZones.
Kill the process mrj.exe and remove mrj.exe from Windows startup.

mrjj.exe
Mrjj.exe is Trojan/Backdoor Puper-E Trojan.
Kill the process mrjj.exe and remove mrjj.exe from Windows startup.

mroot.exe
Mroot.exe is Trojan/Backdoor.
Kill the process mroot.exe and remove mroot.exe from Windows startup.

mroot.sys
Mroot.sys is Rootkit
Kill the file mroot.sys and remove mroot.sys from Windows startup using RegRun Reanimator.
http://www.regrun.com

mrtdll.dll
MRTDLL.DLL is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq8f4c6...
Kill the file MRTDLL.DLL and remove MRTDLL.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

mrtstub.exe
Mrtstub.exe is Trojan/Backdoor.
Kill the process mrtstub.exe and remove mrtstub.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mrup.exe
Mrup.exe is DeskAdTop Adware.
Related files:
mrup.exe
deskun.exe
deskipn.dll
fshook.dll
run.dll
Read more:
http://www.securemost.com/articles/rm_de...
Kill the process mrup.exe and remove mrup.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

ms windows local directory
MSWLD32.exe is Trojan/Backdoor.
MSWLD32.exe is installed as "MS Windows Local Directory".
Kill the process MSWLD32.exe and remove MSWLD32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

ms windows system alert
MSWSA32.exe is Trojan/Backdoor.
MSWSA32.exe is executed as MS Windows System Alert.
Kill the process MSWSA32.exe and remove MSWSA32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

ms03132202406.exe
Ms03132202406.exe is Trojan/Backdoor.
Kill the process ms03132202406.exe and remove ms03132202406.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

ms1.exe
Ms1.exe is Trojan/Backdoor.
Kill the process ms1.exe and remove ms1.exe from Windows startup.

ms162516202222.exe
Ms162516202222.exe is Trojan/Backdoor.
Kill the process ms162516202222.exe and remove ms162516202222.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

ms16prn.exe
Backdoor.Throd.a
Throd is a Trojan that allows a 'master' to use the zombie machine as a proxy server.

The Trojan copies itself in the Windows system folder under a randomly combined multi-partite name:
ms, svc, win, 16, 32, 64, mes, prn, reg
"ms16prn.exe", for example.

In order to auto-launch, the Trojan creates a key in the system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
with one of the following names chosen at random:
MS Driver Management
Synchronization Messager
System Directory Service
System Service Control
Windows Messaging System

Throd then attempts to connect to several remote servers and onpass ID information, including IP address and so forth, to the virus coder.
Throd accepts commands from the remote 'master' collets email addresses from the MS Outlook address book in to the mseml.dll file
and uses an http commands to send them to the same remote sites.
Throd can install and launch random files on command.
Throd also works as a proxy server and is capable of accepting and sending any type of data.

Automatic removal:
Use RegRun Startuip Optimizer to remove this worm.

ms1src.exe
Ms1src.exe is Trojan/Backdoor.
Read more:
http://www.spywaredata.com/spyware/malwa...
Kill the process ms1src.exe and remove ms1src.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

ms2.exe
Ms2.exe is Trojan/Backdoor Backdoor.Win32.Haxdoor.gen.
Kill the process ms2.exe and remove ms2.exe from Windows startup.
http://www3.ca.com/securityadvisor/pest/...

ms216.exe
Worm / Destructive trojan / Network trojan
Alters Win.ini. It is also found in Windows Startup Directory. Msinit spreads itself through open network shares and disables infected computers from the network. Most of the files are packed using different versions of UPX. Dnetc is a legitimite program that may have been installed previously. In this case it´s used illegally.

ms22.exe
MS22.exe is Trojan/Backdoor.
Kill the process MS22.exe and remove MS22.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

ms2src.exe
Ms2src.exe is Trojan/Backdoor.
Kill the process ms2src.exe and remove ms2src.exe from Windows startup.

ms3.exe
Ms3.exe is Trojan/Backdoor Backdoor.Win32.Haxdoor.gen.
Kill the process ms3.exe and remove ms3.exe from Windows startup.
http://www3.ca.com/securityadvisor/pest/...

ms32.dll
Ms32.dll is Trojan/Backdoor Troj/Mirchack-B .
Kill the process ms32.dll and remove ms32.dll from Windows startup.
www.sophos.com/virusinfo/analyses/trojmirchackb.html

ms32.sys
Ms32.sys is Trojan.Downloader.Msys.C.
Read more:
http://www.sophos.com/security/analyses/...
Kill the file ms32.sys_êîïèÿ and remove ms32.sys_êîïèÿ from Windows startup using RegRun Reanimator.
http://www.regrun.com

ms32cfg.exe
Ms32cfg.exe is Trojan/Backdoor.
Kill the process ms32cfg.exe and remove ms32cfg.exe from Windows startup.

ms32dll.dll.vbs
MS32DLL.dll.vbs is VBS.Zodgila.
VBS.Zodgila is a worm that copies itself to removable drives.
Related files:
%Windir%\MS32DLL.dll.vbs
[DRIVE LETTER]:\MS32DLL.dll.vbs
[DRIVE LETTER]:\autorun.inf
Read more:
http://www.symantec.com/security_respons...
Kill the file MS32DLL.dll.vbs and remove MS32DLL.dll.vbs from Windows startup using RegRun Reanimator.
http://www.regrun.com

ms32sgss.exe
Ms32sgss.exe is Trojan/Backdoor.
Ms32sgss.exe is executed as Microsoft SDKb.
Kill the process ms32sgss.exe and remove ms32sgss.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

ms4.exe
Ms4.exe is DOASearch adware.
Read more:
http://research.sunbelt-software.com/thr...
Kill the process ms4.exe and remove ms4.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

ms7531.exe
Ms7531.exe is Homepage hijacker.
Kill the process ms7531.exe and remove ms7531.exe from Windows startup.

msag.exe
Msag.exe is a Wareout.
Kill the process msag.exe and remove msag.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msagentxp.exe
Msagentxp.exe is Trojan/Backdoor.
Kill the process msagentxp.exe and remove msagentxp.exe from Windows startup.

msahgjee.dll
MSAHGJEE.DLL is Trojan.VideosAccess.
Read more:
http://fileinfo.prevx.com/adware/qq8c1e6...
Kill the file MSAHGJEE.DLL and remove MSAHGJEE.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

msahker.exe
Msahker.exe is a mass-mailing worm W32.Ahker.C@mm.
Msahker.exe tries to terminate antiviral programs installed on a user computer.
Related files:
%Windir%\msahker.exe
%User Profile%\Start Menu\Programs\Startup\msahker.exe
C:\ParisXXX.zip
c:\Norton Antivirus.txt
Adds the value:
"[default]" = "msahker.exe %1"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill msahker.exe process and remove msahker.exe from Windows startup using RegRun Startup Optimizer.

msalph.exe
Msalph.exe is a mass mailing worm W32.Mediakill.A@mm.
Msalph.exe tries to terminate antiviral programs installed on a user computer.
Msalph.exe attempts to delete media files.
Related files:
%Windir%\SYMRND.LOG
%Windir%\c7052371.log
%Windir%\ORIN7.LOG
%Windir%\1004\syslw.exe
%Windir%\Drivers\winupd.exe
%Windir%\\Help\msop.exe
%Windir%\Cursors\rncmd.exe
%Windir%\ICS\mscs.exe
%Windir%\1004\lsrsa.exe
%Windir%\Drivers\msalph.exe
%Windir%\\Help\msrnd.exe
%Windir%\Cursors\symlg.exe
Adds the value:
"C7" = "[worm file name]"
"load" = "[worm file name]"
"Shell" = "Explorer.exe [worm file name]"
"(Default)" = "[worm file name] "%1" %*"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill msalph.exe process and remove msalph.exe from Windows startup using RegRun Startup Optimizer.

msappview32.exe
Msappview32.exe is Trojan/Backdoor.
Kill the process msappview32.exe and remove msappview32.exe from Windows startup.

msasp32.exe
MSASP32.exe is Trojan/Backdoor.
Kill the process MSASP32.exe and remove MSASP32.exe from Windows startup.
http://www.sophos.com/virusinfo/analyses...

msasvc.exe
Msasvc.exe is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qqc6f64...
Kill the process msasvc.exe and remove msasvc.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msaus.exe
%System%\Msaus.exe is Trojan/Backdoor.
Kill the process msaus.exe and remove msaus.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msbb.exe
Msbb.exe is an adware program Adware.180Search (180Solutions).
Msbb.exe monitors the contents of Web browser windows.
Msbb.exe opens the Web pages of partner sites when it sees certain keywords in search or shopping site windows.
Related files:
Msbb.exe
Boomerang.exe
ClientAX.dll
180SAInstaller.dll
setup4156.exe
sac.exe
sau.exe
%Program Files%\180search Assistant\sain.exe
%Program Files%\180search Assistant\hsr.dll
%Program Files%\180search Assistant\sau.exe
%Program Files%\180search Assistant\sau.log
%Program Files%\180search Assistant\sau.dll
%Program Files%\180search Assistant\sau_[three random letters].dat
%Program Files%\180search Assistant\sauau.dat
%Program Files%\180search Assistant\sac.exe
%Program Files%\180search Assistant\sauhook.dll
%Program Files%\180search Assistant\sachook.dll
%Program Files%\180searchassistant\salm.exe
%Program Files%\180searchassistant\salmau_update.dat
%Program Files%\180searchassistant\salmhook.dll
%Program Files%\180searchassistant\salm.dat
%Program Files%\180searchassistant\salm_[three random letters].dat
%Program Files%\180searchassistant\salm_[three random letters]_update.dat
%Windir%\Downloaded Program Files\ClientAx.dll
%Windir%\Downloaded Program Files\ClientAx.inf
%Temp%\180sainstallernusalm.exe
Adds the value:
"MSBB" = "[Path to adware file]"
"sau" = "%ProgramFiles%\180search assistant\sau.exe"
"sac" = "%ProgramFiles%\180searchassistant\sac.exe"
"sain" = "%ProgramFiles%\180search assistant\sain.exe"
"salm" = "%ProgramFiles%\180searchassistant\salm.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill Msbb.exe process and remove Msbb.exe from Windows startup using RegRun Startup Optimizer.

msbb32.dll
Msbb32.dll is Trojan/Backdoor Feebs.
Kill the file msbb32.dll and remove msbb32.dll from Windows startup using RegRun Reanimator.
http://www.greatis.com/security/Removal_...

msbd32.exe
Msbd32.exe is Trojan/Backdoor.
Kill the process msbd32.exe and remove msbd32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msbdv32.exe
Msbdv32.exe is Trojan/Backdoor.
Kill the process msbdv32.exe and remove msbdv32.exe from Windows startup.

msbe.dll
Msbe.dll is an adware program Adware.BargainBuddy.
Msbe.dll downloads and displays advertisements.
Related files:
Apuc.dll;
Autoheal.exe
%System%\angelex.exe
%System%\instsrv.exe
%System%\msexreg.exe
%System%\bbchk.exe
%System%\exclean.exe
%System%\exdl.exe
%System%\exdl0.exe
%System%\exdl1.exe
%System%\exul.exe
%System%\msbe.dll
%System%\msxct.exe
%ProgramFiles%\BullsEye Network\bin\adv.exe
%ProgramFiles%\BullsEye Network\bin\adx.exe
%ProgramFiles%\BullsEye Network\bin\bargains.exe
%ProgramFiles%\BullsEye Network\Uninstall.exe
%Windows%\bbchk.exe
%Windows%\exclean.exe
%Windows%\exdl.exe
%Windows%\exul.exe
%Windows%\msbe.dll
%Windows%\msxct.exe
%Windows%\zeta.exe
Adds the value:
"[File name of adware]" = "[File path to adware]"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Remove msbe.dll from Windows startup using RegRun Startup Optimizer.

msbin32.exe
Trojan: Network Crack Wizard - NCW.
Steals passwords / Keylogger.
Made in Russia.
Remove it from Windows startup and from your computer.

msbind32.exe
Msbind32.exe is Troj/Dwara-A.
Related files:
%Windows%\system32\msbind32.exe
%Windows%\system32\wmvds32.dll
Read more:
http://www.sophos.com/security/analyses/...
Kill the process msbind32.exe and remove msbind32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msblank.exe
Msblank.exe is Trojan/Backdoor.
Kill the process msblank.exe and remove msblank.exe from Windows startup.

msblast.exe
Lovesan worm.
This worm scans several IP networks (randomly choosen) to get access to port 135 (COM).
The worm sends a buffer-overrun request to vulnerable computers. The newly infected machine then initiates the command shell on TCP port 4444.
Lovesan runs the thread that opens the connection on port 4444 and waits for FTP 'get' request from the victim machine. The worm then forces the victim machine to sends the 'FTP get' request. Thus the victim machine downloads the worm from the infected machine and runs it. The victim machine is now also infected.
Removal:
remove it from startup by RegRun Startup Optimizer.

msbn.exe
Msbn.exe is Trojan/Backdoor.
Kill the process msbn.exe and remove msbn.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msboot.exe
We suggest you to remove MSBOOT.EXE from your computer as soon as possible.
MSBOOT.EXE is Trojan/Backdoor.
Kill the process MSBOOT.EXE and remove MSBOOT.EXE from Windows startup.

msbootmgr.exe
MsBootMgr.exe is a Trojan/Backdoor Backdoor.Verify.
MsBootMgr.exe tries to terminate antiviral programs installed on a user computer.
MsBootMgr.exe opens a back door on TCP port 1906 and 1907.
MsBootMgr.exe spreads via open network shares.
Related files:
%System%\MsIdle32.exe
%System%\MsIdle32Hook.dll
%System%\MsSysInfo32.exe
C:\MsBootMgr.exe
Adds the value:
"MsIdle32.exe" = "C:\WINNT\system32\MsIdle32.exe"
"MsBootMgr.exe" = "C:\MsBootMgr.exe"
"Shell" = "C:\WINNT\system32\MsIdle32.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill MsBootMgr.exe process and remove MsBootMgr.exe from Windows startup using RegRun Startup Optimizer.

msbvd32.exe
Msbvd32.exe is Trojan/Backdoor Agobot.
Kill the process msbvd32.exe and remove msbvd32.exe from Windows startup.
http://www.sophos.com/virusinfo/analyses...

msccn32.exe
I-Worm.Palyh.
Palyn is a worm virus spreading via the Internet as a file attachment to infected emails.
The worm also spreads via local area networks and it masquerades as a
message from Microsoft's technical support.
Open RegRun Startup Optimizer, uncheck all msccn32.exe items and click
on the Optimize.

msccrt.dll
Msccrt.dll is PWS-LegMir!2eff06bc.
This trojan is designed to steal password information of online games including the game "Legend of Mir".
Related files:
%SYSTEMDIR%\msccrt.dll
%WINDIR%\msccrt.exe
Read more:
http://vil.nai.com/vil/content/v_141965....
Kill the file msccrt.dll and remove msccrt.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msccrt.exe
Msccrt.exe is PWS-LegMir!2eff06bc.
This trojan is designed to steal password information of online games including the game "Legend of Mir".
Related files:
%SYSTEMDIR%\msccrt.dll
%WINDIR%\msccrt.exe
Read more:
http://vil.nai.com/vil/content/v_141965....
Kill the process msccrt.exe and remove msccrt.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mscde32.exe
Mscde32.exe is Trojan/Backdoor.
Kill the process Mscde32.exe and remove Mscde32.exe from Windows startup.
Related files for W32.HLLW.Nautic:
* NTDLL.exe
* Win32.exe
* Explore.exe
* Kernel32.exe
* krnl286.exe
* Dllhost32.exe
* MSTCP.exe
* CRSS.exe
* Winlogon32.exe
* Winsrvc.exe
* Ntoskrn.exe
* Vmm32.exe
* Sysmon.exe
* System32.exe
* Sys.exe
* Win.exe
* Rundil32.exe
* Msrvcp.exe
* Msgmsr.exe
* Mscde32.exe
* Regsvclib.exe
* Reg32.exe
* Registry32.exe
* Service.exe
* Rpcsrvc.exe
More info:
http://securityresponse.symantec.com/avc...

mscdt.exe
Mscdt.exe is Trojan/Backdoor.
Kill the process mscdt.exe and remove mscdt.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mscf.exe
Mscf.exe is Trojan/Backdoor W32.HLLW.Acebo.
Kill the process Mscf.exe and remove Mscf.exe from Windows startup.

mscfg.dll
Mscfg.dll is Trojan/Backdoor.
Kill the file mscfg.dll and remove mscfg.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mscfg.exe
Mscfg.exe is Network.vbs or VBS/Netlog.Worm virus.
Read more:
http://support.microsoft.com/default.asp...
Kill the process mscfg.exe and remove mscfg.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mscheldbra.exe
We suggest you to remove mscheldbra.exe from your computer as soon as possible.
Mscheldbra.exe is Trojan/Backdoor.
Kill the process mscheldbra.exe and remove mscheldbra.exe from Windows startup.

mschkdsk.exe
Mschkdsk.exe is Troj/VB-GGG.
Read more:
http://www.sophos.com/security/analyses/...
Kill the process mschkdsk.exe and remove mschkdsk.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mschksys.exe
Mschksys.exe is Trojan.SysInit.
Read more:
http://www.superadblocker.com/definition...
Kill the process mschksys.exe and remove mschksys.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mschost.exe
W32.Blaster.K.Worm is a worm that exploits the DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026) using TCP port 135.
The worm targets only Windows 2000 and Windows XP computers.
It recommends that you block access to TCP port 4444 at the firewall level, and then block the following ports, if you do not use the following applications:
TCP Port 135, "DCOM RPC"
UDP Port 69, "TFTP"

The worm also attempts to perform a Denial of Service (DoS) on the Microsoft Windows Update Web server (windowsupdate.com).
This is an attempt to prevent you from applying a patch on your computer against the DCOM RPC vulnerability.

When worm is executed, it does the following:
Generates an IP address and attempts to infect the computer that has that address.
Sends data on TCP port 135 that may exploit the DCOM RPC vulnerability. The worm sends one of two types of data: either to exploit Windows XP or Windows 2000.
Uses Cmd.exe to create a hidden remote shell process that will listen on TCP port 4444, allowing an attacker to issue remote commands on an infected system.
Listens on UDP port 69. When the worm receives a request from a computer it was able to connect to using the DCOM RPC exploit, it sends mschost.exe to that computer and then executes it.

The worm contains the following text in the code:
Can you hear me? I LOVE YOU SAN!!
Sucky gates why do you made this windows? Stop fooling around and make good things!!!

Use RegRun Startup Optimizer to automatical remove this worm from system registry.

mschv32.exe
DoS tool / ICQ trojan / Steals passwords (?)
Can be used to flood a chanel with thousands of messages.

msclient.exe
Worm / Destructive trojan / Network trojan
Alters Win.ini. It is also found in Windows Startup Directory. Msinit spreads itself through open network shares and disables infected computers from the network. Most of the files are packed using different versions of UPX. Dnetc is a legitimite program that may have been installed previously. In this case it´s used illegally.

msclock.dll
Msclock.dll is Adware.Navipromo.BYD.
Related files:
msclock.dll
msplock.dll
Read more:
http://www.bitdefender.com/VIRUS-1000170...
Kill the file msclock.dll and remove msclock.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mscmippr.exe
Mscmippr.exe is Email-Worm.Win32.Warezov.pb.
Related files:
%System%\mscmippr.dll
%System%\mscmippr.exe
Read more:
http://www.viruslist.com/en/viruses/ency...
Kill the process mscmippr.exe and remove mscmippr.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mscnf32.exe
Mscnf32.exe is Trojan/Backdoor.
Kill the process mscnf32.exe and remove mscnf32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mscnt.exe
Adult content dialer.
This program tries to auto dialing to the adult phones by modem.
Suggest to open RegRun Startup Optimizer and remove it.

mscodr.dll
Mscodr.dll is Troj/Dloadr-ALU.
Read more:
http://www.sophos.com/security/analyses/...
Kill the file mscodr.dll and remove mscodr.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mscom.exe
Mscom.exe is W32.Woredbot.
Directory: %System%\dllcache
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process mscom.exe and remove mscom.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mscom32.exe
Mscom32.exe is Trojan/Backdoor Sdbot.
Kill the process mscom32.exe and remove mscom32.exe from Windows startup.

mscombtl32.exe
Mscombtl32.exe is Trojan/Backdoor.
Kill the process mscombtl32.exe and remove mscombtl32.exe from Windows startup.

mscomfig.exe
Mscomfig.exe is W32.Schting.A.
W32.Schting.A is a worm that spreads by copying itself to local drives. It also attempts to reduce security settings on the compromised computer.
Related files:
C:\Windows\WinSystem.exe
C:\Windows\Win System.exe
C:\Windows\windows.exe
C:\Windows\WinSystem
C:\Windows\WinSystem32.exe
C:\Windows\SystemMonitor.exe
C:\Windows\MonitorSetup.exe
C:\Windows\NowAndForever.exe
C:\Windows\system\mscomfig.exe
C:\Windows\regedif.exe
C:\log.exe
C:\Windows\system32\regedif32.exe
C:\Windows\ErrorReport.exe
C:\Windows\system32\WindowsProtection.exe
C:\Windows\system32\msiexee.exe
C:\Windows\system\msiexece.exe
C:\Windows\system\WindowsUpadate.exe
C:\Windows\system32\msidlI.exe
C:\Windows\system32\SCCONFIG.exe
C:\Windows\system\rundlI.exe
C:\Windows\system32\winlocon.exe
C:\Windows\system32\wpa.bdlx
C:\BootEx.exe
D:\BootEx.exe
C:\Windows\winsystem.exe
%CurrentFolder%\log.txt
%CurrentFolder%\oeminfo.ini
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process mscomfig.exe and remove mscomfig.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mscomm32.exe
MSCOMM32.EXE is Trojan/Backdoor BBQ.
Kill the process MSCOMM32.EXE and remove MSCOMM32.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com
Read more:
http://www.trendmicro.com.au/enterprise/...

mscommand.exe
Mscommand.exe is Trojan/Backdoor.
Kill the process mscommand.exe and remove mscommand.exe from Windows startup.

mscomserv.exe
Mscomserv.exe is Troj/Zlob-RF.
Related files:
\mscomserv.exe (detected as Troj/DDoS-M)
\mscomserv.bin
Read more:
http://www.sophos.com/security/analyses/...
Kill the process mscomserv.exe and remove mscomserv.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mscomt32.exe
Mscomt32.exe is Trojan/Backdoor.
Kill the process mscomt32.exe and remove mscomt32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msconf.exe
Msconf.exe is Trojan/Backdoor W32.Gaobot.ADX.
Kill the process msconf.exe and remove msconf.exe from Windows startup.
http://securityresponse.symantec.com/avc...

msconfg.exe
Msconfg.exe is Trojan/Backdoor Win32.Rbot.H.
Kill the process msconfg.exe and remove msconfg.exe from Windows startup.
http://www3.ca.com/securityadvisor/virus...

msconfig32.exe
W32.Tulu virus.

When W32.Tulu is executed, it attempts to copy itself as
%system%\Rundll32.exe
and
%windir%\Msconfig32.exe
where:
%windir% is C:\Windows or C:\Winnt
%system% is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).

Virus add the value:
shell %system%\rundll32.exe
to the registry key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm runs each time that you start Windows.

Also creates the registry key
HKEY_LOCAL_MACHINE\Software\Microsoft\Ktulu
This key is used by the macro component of the virus.

The virus next attempts to locate the Microsoft Word global template, Normal.dot.
If the virus finds the file, it infects the file with a macro virus. The only purpose of the macro virus is to execute the W32.Tulu virus.

The virus now stays memory resident. Every few minutes, it attempts to copy itself to drive A.

How to delete this virus:

1. Run a full system scan whit your antivirus tools.
If any files are detected as infected with W32.Tulu, click Delete.

For example, Symantec antivirus products detect this macro component as W97M.Tulu.
If any files are detected as infected with W97M.Tulu, click Repair.

2. Delete the value "shell" from the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

msconfig38.exe
Msconfig38.exe is Trojan/Backdoor.
Kill the process msconfig38.exe and remove msconfig38.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msconfig45.exe
Msconfig45.exe is Trojan/Backdoor.
Kill the process msconfig45.exe and remove msconfig45.exe from Windows startup.

msconfigs.exe
MSConfigs.exe is a Backdoor W32.Alcra.A.
MSConfigs.exe spreads via open network shares.
MSConfigs.exe tries to terminate antiviral programs installed on a user computer.
Related files:
%System%\regedit.com
%System%\taskmgr.exe
%System%\tasklist.com
%System%\taskkill.com
%System%\netstat.com
%System%\tracert.com
%System%\ping.com
%System%\cmd.com
%ProgramFiles%\MSConfigs\MSConfigs.exe
%System%\bt.exe
%System%\z.tmp
%System%\temp.zip
%System%\bszip.dll
%System%\p2pnetwork.exe
winis.exe
win32exe.exe
wini.exe
winlogins.exe
muamgr.exe
Adds the value:
"MsConfigs" = "MsConfigs.exe"
"p2pnetwork" = "p2pnetwork.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill MSConfigs.exe process and remove MSConfigs.exe from Windows startup using RegRun Startup Optimizer.

msconfigx32.exe
Msconfigx32.exe is Trojan/Backdoor.
Kill the process msconfigx32.exe and remove msconfigx32.exe from Windows startup.
http://www.superadblocker.com/definition...

mscoriezb.dll
Mscoriezb.dll is Trustin.Bar Adware.
Read more:
http://research.sunbelt-software.com/thr...
Kill the file mscoriezb.dll and remove mscoriezb.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mscoriezz.dll
MSCORIEZZ.DLL is Trojan.Downloader-Small.
Read more:
http://www.spywareremove.com/removeTroja...
Kill the file MSCORIEZZ.DLL and remove MSCORIEZZ.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

mscornet.exe
Mscornet.exe is Trojan/Backdoor Troj/Zlob.
Kill the process mscornet.exe and remove mscornet.exe from Windows startup.

mscppdmg.exe
Mscppdmg.exe is a mass-mailing worm W32.Kedebe@mm.
Mscppdmg.exe tries to terminate antiviral programs installed on a user computer.
Mscppdmg.exe spreads by e-mail and via open network shares.
Related files:
%System%\winssc32.exe
%System%\mscppdmg.exe
%System%\kernel32hlp.exe
%System%\NAVctrl.exe
%System%\dwrdgr32.exe
%System%\gcasctrl.exe
%System%\AVmon.exe
%System%\winxplt.exe
%System%\gcasAV32.exe
%System%\LUCOMS~2.EXE
%System%\zlbclient.exe
%system%\win32infchkr.exe
Adds the value:
"Windows Console Monitor" = "%System%\[path to the worm]"
"load" = "%Userprofile%\LOCALS~1\Applic~1\MICROS~1\Windows\[path to the worm]"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill mscppdmg.exe process and remove mscppdmg.exe from Windows startup using RegRun Startup Optimizer.

mscppmgr.exe
Mscppmgr.exe is a mass-mailing worm W32.Kedebe.B@mm.
Mscppmgr.exe tries to terminate antiviral programs installed on a user computer.
Mscppmgr.exe opens a back door on a random TCP port.
Related files:
%System%\winssc32.exe
%System%\mscppmgr.exe
%System%\kerne132.exe
%System%\NAVMON.EXE
%System%\drwmgr32.exe
%System%\DLLH0ST.EXE
%System%\gcasctrl.exe
%System%\msscan.exe
%System%\cuApp.exe
%System%\LSSAS.EXE
%System%\AVmon.exe
%System%\SERVlCES.EXE
%System%\gcasSav32.exe
%System%\LUC0MS~1.EXE
%System%\zlbclient.exe
%System%\mantispam.exe
%System%\NETM0N.EXE
%System%\srvchost.exe
%System%\USRMGRINIT.JFX
Admin Password Cracker.exe
DVD ripper keygen.exe
Messenger 7.0 Installer.exe
Microsoft AntiSpyware Patch.com
Mydoom removal tool.exe
Naked teen-Actions.com
Norton Personal Firewall 2005 Patch.exe
Spyware remover.exe
Win Server 2003 Remote Exploit.cmd
ZoneAlarm Security Suite 2005 Crack.com
Adds the value:
"Windows [worm filename without extension] Monitor" = "[file name of the worm]"
"Run" = "[file name of the worm]"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill mscppmgr.exe process and remove mscppmgr.exe from Windows startup using RegRun Startup Optimizer.

mscript.exe
Mscript.exe is W32/Ronoper.worm.
Related files:
c:\%Windir%\Lianne.scr
c:\%Windir%\Mscript.exe
c:\%Windir%\WinCfg32.exe
Read more:
http://vil.nai.com/vil/content/v_100675....
Kill the process mscript.exe and remove mscript.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mscs.exe
Mscs.exe is a mass mailing worm W32.Mediakill.A@mm.
Mscs.exe tries to terminate antiviral programs installed on a user computer.
Mscs.exe attempts to delete media files.
Related files:
%Windir%\SYMRND.LOG
%Windir%\c7052371.log
%Windir%\ORIN7.LOG
%Windir%\1004\syslw.exe
%Windir%\Drivers\winupd.exe
%Windir%\\Help\msop.exe
%Windir%\Cursors\rncmd.exe
%Windir%\ICS\mscs.exe
%Windir%\1004\lsrsa.exe
%Windir%\Drivers\msalph.exe
%Windir%\\Help\msrnd.exe
%Windir%\Cursors\symlg.exe
Adds the value:
"C7" = "[worm file name]"
"load" = "[worm file name]"
"Shell" = "Explorer.exe [worm file name]"
"(Default)" = "[worm file name] "%1" %*"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill mscs.exe process and remove mscs.exe from Windows startup using RegRun Startup Optimizer.

mscstat.exe
Changes IE homepage. Installed by Morpheus.
Remove it from startup.
Delete files from disk:
MSCSTAT.EXE
MBHO.DLL
MSC020522.de a
d020326.de.xml
The numbers may be different but the format is: MSC######.DE and
AD######.de.xml

mscsvc.exe
Mscsvc.exe is a Trojan PWSteal.Bancos.T.
Mscsvc.exe monitors user Internet activity and private information.
It sends stolen data to a hacker site.
Related files:
%Windir%\mscsvc.exe
Adds the value:
"mscsvc.exe" = "%Windir%\mscsvc.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill mscsvc.exe process and remove mscsvc.exe from Windows startup using RegRun Startup Optimizer.

msctl32.exe
Msctl32.exe is Trojan/Backdoor.
Kill the process msctl32.exe and remove msctl32.exe from Windows startup.

msctlwin.exe
MSctlWin.exe is the Trojan.
Remove MSctlWin.exe from WIndows startup.

msctools.exe
Msctools.exe is W32.Sixem.A@mm worm.
Read more:
http://securityresponse.symantec.com/avc...
Kill the process msctools.exe and remove msctools.exe from Windows startup using RegRun.
www.regrun.com

msctvr.exe
Steals passwords / EXE Binder
Uses a Configuration Wizzard to specify the details. Uses the ASPack 2000 compression utility.

mscvb32.exe
Sobig worm.
The worm is spread by e-mail.
When a user clicked on the attached file, the worm installs itself to the system and runs a spreading routine.
The Sobig.c worm also creates the file msddr.dat in the Windows directory and writes to this file the email addresses that were found on the infected machine.
Removal:
remove it by Start Control.

msdata.dat
W32.Nits.A
It is a network-aware worm that runs a HTTP proxy on the infected computer.
Launches a thread that generates random IP addresses.
It attempts to copy itself to the following locations for each generated IP address, using a predefined list of user names and passwords.
Opens an HTTP proxy on a range of random ports.

Manual removal:
Navigate to the key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
and delete the value: "Testing 123" = "%System%\msdata.dat"

msdataaccess.exe
Msdataaccess.exe is Trojan/Backdoor.
Kill the process msdataaccess.exe and remove msdataaccess.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msdbhk.dll
Edmond.exe is Edmond Adware/Spywarer.
Also Edmond.exe is known as Trojan-Downloader.Win32.Ieser.a [Kaspersky], TrojanDownloader.Win32.leser.
Edmond.exe display ads, collects personal information.
Related files:
%System32%\isrvs\desktop.exe
%System32%\edmond.exe
%System32%\ffisearch.exe
%System32%\isrvs\mfiltis.dll
%System32%\isrvs\msdbhk.dll
%System32%\isrvs\sysupd.dll
Remove Delprot.sys driver
Kill the process Edmond.exe and remove Edmond.exe from Windows startup.
Kill other spyware files and clean the registry.

msdc.exe
msdc.exe is a Trojan.Pupsv-B.
msdc.exe opens a back door.
msdc.exe relays spam mail.
More info:
http://www.sophos.com/virusinfo/analyses...
Removal:
Kill msdc.exe process and remove msdc.exe from Windows startup using RegRun Startup Optimizer.

msdde.dll
Msdde.dll is Trojan/Backdoor.
Kill the file msdde.dll and remove msdde.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msdeco.dll
Msdeco.dll is W97M.Kukudro.C.
Related files:
C:\cvSecq.exe
C:\vbftgc.exe
C:\brtbvde.exe
%System%\msdeco.dll
%System%\mscodr.dll
Read more:
http://www.symantec.com/enterprise/secur...
Kill the file msdeco.dll and remove msdeco.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msdev.exe
Worm W32/Forbot-CR
The worm can spread to unpatched machines affected by the LSASS vulnerability
(see MS04-011) and through backdoors left open by the Troj/Optix Trojans.
Read more:
http://www.sophos.com/virusinfo/analyses...
Removal:
Install the Microsoft updates and remove the worm using RegRun Startup Optimizer.

msdhcp32.exe
MSDHCP32.EXE is Trojan/Backdoor.
Kill the process MSDHCP32.EXE and remove MSDHCP32.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msdic.dll
msdic.dll is a Trojan.BluEye-E.
msdic.dll opens a back door.
More info:
http://www.sophos.com/virusinfo/analyses...
Removal:
Remove msdic.dll from Windows startup using RegRun Startup Optimizer.

msdirect.sys
msdirect.sys is rootkit Trojan. Dloadr-NB.
msdirect.sys is used to hide files, processes and registry.
msdirect.sys is a kernel mode rootkit.
Rootkit contacts remote hacker server using HTTP session.
Related files:
msdirect.sys
Adds the value:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
R

to the Windows startup registry keys.
More info:
http://www.sophos.com/virusinfo/analyses...

msdirectx.exe
Msdirectx.exe is Trojan/Backdoor.
Kill the process msdirectx.exe and remove msdirectx.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msdirectx.sys
Msdirectx.sys is RootKit driver.
Use UnHackMe to remove a root kit:
http://www.unhackme.com

msdn32.dll
Msdn32.dll is Trojan/Backdoor.
Kill the file msdn32.dll and remove msdn32.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msdnc2.exe
Msdnc2.exe is Trojan/Backdoor.
Kill the process msdnc2.exe and remove msdnc2.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msdnc3.exe
Msdnc3.exe is Trojan/Backdoor.
Kill the process msdnc3.exe and remove msdnc3.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msdnc4.exe
We suggest you to remove msdnc4.exe from your computer as soon as possible.
Msdnc4.exe is Trojan/Backdoor.
Kill the process msdnc4.exe and remove msdnc4.exe from Windows startup.

msdndr.sys
Msdndr.sys is Hacker Defender Malware.
Read more:
http://research.sunbelt-software.com/thr...
Kill the file msdndr.sys and remove msdndr.sys from Windows startup using RegRun Reanimator.
http://www.regrun.com

msdns.dll
Msdns.dll is Trojan/Backdoor.
Kill the file msdns.dll and remove msdns.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msdnsd32.exe
MSDNSD32.exe is MSDNSD32.exe worm.
Read more:
http://www.sophos.com/virusinfo/analyses...
Kill the process MSDNSD32.exe and remove MSDNSD32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msdntsrv.exe
Msdntsrv.exe is Worm Ircbot Gen.
Related files:
%CACHE%\CONTENT.IE5\????????\MSDNTSRV[1].EXE
%CACHE%\CONTENT.IE5\????????\MSDNTSRV[3].EXE
%profiles%\hyogactarus\lo...s\content.ie5\clyzsxir\MSDNTSRV[1].EXE
Read more:
http://fileinfo.prevx.com/adware/qq05e62...
Kill the process msdntsrv.exe and remove msdntsrv.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msdom2.dll
MSDOM2.DLL is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq032a8...
Kill the file MSDOM2.DLL and remove MSDOM2.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

msdos.exe
Msdos.exe is Trojan/Backdoor.
Kill the process msdos.exe and remove msdos.exe from Windows startup.
http://www3.ca.com/securityadvisor/pest/...

msdos32.dll
Msdos32.dll is Troj/Lineag-AAX.
Read more:
http://www.sophos.com/security/analyses/...
Kill the file msdos32.dll and remove msdos32.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msdos423.exe
Msdos423.exe is Trojan/Backdoor.
Kill the process msdos423.exe and remove msdos423.exe from Windows startup.

msdos98.exe
Steals passwords
Alters Win.ini. May alter System.ini. Steals AOL and AIM passwords. It is hard to remove because the user is stopped from entering Win.ini and Regedit, or from booting in DOS.

msdrc.exe
MSDRC.EXE is Trojan/Backdoor.
Kill the process MSDRC.EXE and remove MSDRC.EXE from Windows startup.

msdrv.exe
MSDRV.EXE is W32/Sdbot-WR.
Read more:
http://www.sophos.com/virusinfo/analyses...
Kill the process MSDRV.EXE and remove MSDRV.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msdrv2.exe
Msdrv2.exe is Trojan/Backdoor.
Kill the process msdrv2.exe and remove msdrv2.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msdrv3.exe
Msdrv3.exe is Trojan/Backdoor.
Kill the process msdrv3.exe and remove msdrv3.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msdrvs32.exe
Msdrvs32.exe is Trojan/Backdoor.
Kill the process msdrvs32.exe and remove msdrvs32.exe from Windows startup.

msdspr.exe
W32.Solame.A is a worm that spreads using the backdoor that the variants of W32.Mydoom@mm create. Also Known as Exploit-Mydoom.

Moves itself to %System%\Msdspr.exe.

Adds the value: "Windows Automation"="msdspr.exe"
to the registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Adds the value: "Windows Automation"="msdspr.exe"
to the registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices

Connects to an IRC server and sends abusive messages to users.
Attempts to connect to the IP address on TCP port 3127, which is associated with the variants of W32.Mydoom@mm.
If the connection is successful, it will use a malware command to upload and execute the worm.
This is likely to cause a visible slowdown on an infected system.

Use RegRun Startup Optimizer to automatically remove it from startup.

msdts.exe
Msdts.exe is Trojan Windows Remote Registry.
Read more:
http://www.pestpatrol.com/spywarecenter/...
Kill the process msdts.exe and remove msdts.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msdweyer.dll
Msdweyer.dll is a Trojan Trojan.Goldun.E.
Msdweyer.dll monitors user Internet activity and private information.
It sends stolen data to a hacker site
Related files:
%System%\msdweyer.dll
%Temp%\data_1.exe
%Temp%\data_2.exe
%Temp%\delt.bat
More info:
http://securityresponse.symantec.com/avc...
Removal:
Remove msdweyer.dll from Windows startup using RegRun Startup Optimizer.

msdy.exe
Msdy.exe is Trojan SMALL.
Read more:
http://www.spywaredata.com/spyware/threa...
Kill the process msdy.exe and remove msdy.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msed32.exe
MSED32.EXE is Trojan/Backdoor Worm.RBot-APT.Process.
Kill the process MSED32.EXE and remove MSED32.EXE from Windows startup.

msedit.exe
Msedit.exe is Trojan/Backdoor.
Kill the process msedit.exe and remove msedit.exe from Windows startup.

mseiw.exe
Mseiw.exe is Trojan Trojan.Littlog.
Mseiw.exe monitors user Internet activity and private information.
It sends stolen data to a hacker site.

Related files:
%System%\fontstyles.exe
%Windir%\mseiw.exe
%Windir%\4DFlowerBox.scr
%Windir%\syxsocks.dll
[original folder]\settings.ini
[original folder]\server.exe


Adds the value:
"Shell" = "explorer.exe 4DFlowerBox.scr"
"System" = "C:\WINNT\System32\fontstyles.exe"
to the Windows startup registry keys.

More info:
http://securityresponse.symantec.com/avc...

Removal:
Kill mseiw.exe process and remove mseiw.exe from Windows startup using RegRun Startup Optimizer.

msejavaupdt32.exe
MSEJAVAUPDT32.EXE is Malware Trojan Backdoor Gen.
Related files:
1 :%CACHE%\CONTENT.IE5\????????\13860_NETAPI[1].EXE
2 :%CACHE%\CONTENT.IE5\????????\17561_NETAPI[1].EXE
3 :%CACHE%\CONTENT.IE5\????????\20580_NETAPI[1].EXE
4 :%CACHE%\CONTENT.IE5\????????\21113_NETAPI[1].EXE
5 :%CACHE%\CONTENT.IE5\????????\22843_NETAPI[1].EXE
6 :%CACHE%\CONTENT.IE5\????????\23607_NETAPI[1].EXE
7 :%CACHE%\CONTENT.IE5\????????\33844_NETAPI[1].EXE
8 :%CACHE%\CONTENT.IE5\????????\37142_NETAPI[1].EXE
9 :%CACHE%\CONTENT.IE5\????????\48132_NETAPI[1].EXE
10:%CACHE%\CONTENT.IE5\????????\57572_NETAPI[1].EXE
Read more:
http://fileinfo.prevx.com/adware/qqd7004...
Kill the process MSEJAVAUPDT32.EXE and remove MSEJAVAUPDT32.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msen.exe
Ntww.exe is dangerous Trojan/Backdoor.
Ntww.exe changes IE home page to www.v61.com.
Trojan runs a lot of its copies to make the removal hard.
Remove it using RegRun Startup Optmizer to get rid all processes at the same time.
[sdkfr32.exe] C:\WINDOWS\sdkfr32.exe
[mfcyp.exe] C:\WINDOWS\mfcyp.exe
[netrt.exe] C:\WINDOWS\netrt.exe
[ntww.exe] C:\WINDOWS\ntww.exe
[ntdf32.exe] C:\WINDOWS\system32\ntdf32.exe
[ntbw32.exe] C:\WINDOWS\ntbw32.exe
[crbn32.exe] C:\WINDOWS\system32\crbn32.exe
[sdkpn32.exe] C:\WINDOWS\sdkpn32.exe
[d3dl.exe] C:\WINDOWS\d3dl.exe
[mfcod.exe] C:\WINDOWS\mfcod.exe
[apiel.exe] C:\WINDOWS\system32\apiel.exe
[ntxo32.exe] C:\WINDOWS\ntxo32.exe
[atlag.exe] C:\WINDOWS\atlag.exe
[mszo32.exe] C:\WINDOWS\system32\mszo32.exe
[d3qk.exe] C:\WINDOWS\d3qk.exe
[javahd32.exe] C:\WINDOWS\system32\javahd32.exe
[appds32.exe] C:\WINDOWS\appds32.exe
[apipp.exe] C:\WINDOWS\system32\apipp.exe
[mfcnn.exe] C:\WINDOWS\mfcnn.exe
[mfckl.exe] C:\WINDOWS\system32\mfckl.exe
[netlc.exe] C:\WINDOWS\system32\netlc.exe
[atlyi32.exe] C:\WINDOWS\system32\atlyi32.exe
[addtm32.exe] C:\WINDOWS\system32\addtm32.exe
[crad.exe] C:\WINDOWS\crad.exe
[javapt.exe] C:\WINDOWS\system32\javapt.exe
[javauu32.exe] C:\WINDOWS\javauu32.exe
[d3yp.exe] C:\WINDOWS\system32\d3yp.exe
[crwo32.exe] C:\WINDOWS\crwo32.exe
[ieim32.exe] C:\WINDOWS\system32\ieim32.exe
[sysyu.exe] C:\WINDOWS\sysyu.exe
[mfcrr.exe] C:\WINDOWS\system32\mfcrr.exe
[atlfg.exe] C:\WINDOWS\system32\atlfg.exe
[winvr32.exe] C:\WINDOWS\winvr32.exe
[iebp.exe] C:\WINDOWS\system32\iebp.exe
[ipyn.exe] C:\WINDOWS\ipyn.exe
[mspm.exe] C:\WINDOWS\mspm.exe
[javaee.exe] C:\WINDOWS\system32\javaee.exe
[addfm32.exe] C:\WINDOWS\addfm32.exe
[addrs.exe] C:\WINDOWS\addrs.exe
[crfy.exe] C:\WINDOWS\system32\crfy.exe
[crrd.exe] C:\WINDOWS\crrd.exe
[apptr32.exe] C:\WINDOWS\system32\apptr32.exe
[d3wk.exe] C:\WINDOWS\d3wk.exe
[apilk32.exe] C:\WINDOWS\apilk32.exe
[iedm.exe] C:\WINDOWS\system32\iedm.exe
[javagm.exe] C:\WINDOWS\system32\javagm.exe
[ntjw32.exe] C:\WINDOWS\ntjw32.exe
[netdo32.exe] C:\WINDOWS\netdo32.exe
[sysuc32.exe] C:\WINDOWS\system32\sysuc32.exe
[sdknd32.exe] C:\WINDOWS\system32\sdknd32.exe
[addko.exe] C:\WINDOWS\addko.exe
[mfcdh32.exe] C:\WINDOWS\system32\mfcdh32.exe
[sdkij32.exe] C:\WINDOWS\system32\sdkij32.exe
[msen.exe] C:\WINDOWS\system32\msen.exe
[msug.exe] C:\WINDOWS\msug.exe
[crkf32.exe] C:\WINDOWS\crkf32.exe
[winqj.exe] C:\WINDOWS\system32\winqj.exe
[sysgh32.exe] C:\WINDOWS\sysgh32.exe
[d3ud32.exe] C:\WINDOWS\d3ud32.exe
[netnm.exe] C:\WINDOWS\system32\netnm.exe
[apihs32.exe] C:\WINDOWS\system32\apihs32.exe
[addfp.exe] C:\WINDOWS\addfp.exe
[sdkqf32.exe] C:\WINDOWS\sdkqf32.exe
[crpn32.exe] C:\WINDOWS\system32\crpn32.exe
[netae.exe] C:\WINDOWS\netae.exe
[iewb.exe] C:\WINDOWS\system32\iewb.exe
[addkz32.exe] C:\WINDOWS\system32\addkz32.exe
[ipdv.exe] C:\WINDOWS\ipdv.exe
[ntqs32.exe] C:\WINDOWS\system32\ntqs32.exe
[winoo.exe] C:\WINDOWS\system32\winoo.exe
[ipwi.exe] C:\WINDOWS\system32\ipwi.exe
[atlzb.exe] C:\WINDOWS\atlzb.exe
[sysss.exe] C:\WINDOWS\sysss.exe
[appfh32.exe] C:\WINDOWS\appfh32.exe
[sysyh.exe] C:\WINDOWS\sysyh.exe
[msge.exe] C:\WINDOWS\system32\msge.exe

mseng.exe
MsEng.exe is Trojan/Backdoor.
Kill the process MsEng.exe and remove MsEng.exe from Windows startup.

mservice1.exe
Mservice1.exe is Downloader.Small.ase.
Kill the process mservice1.exe and remove mservice1.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msets.exe
MSETS.EXE is Trojan/Backdoor.
Read more:
http://spywarefiles.prevx.com/RRHDJE0329...
Kill the process MSETS.EXE and remove MSETS.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msetss.exe
MSETSS.EXE is Trojan/Backdoor.
Kill the process MSETSS.EXE and remove MSETSS.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msetus.exe
MSETUS.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq65388...
Kill the process MSETUS.EXE and remove MSETUS.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msevnt.exe
Msevnt.exe is Trojan/Backdoor.
Kill the process msevnt.exe and remove msevnt.exe from Windows startup using RegRun.
www.regrun.com

msexcel.exe
Msexcel.exe is Trojan/Backdoor.
Kill the process msexcel.exe and remove msexcel.exe from Windows startup.

msexnpbi.exe
Msexnpbi.exe is Trojan/Backdoor.
Kill the process msexnpbi.exe and remove msexnpbi.exe from Windows startup.

msf.exe
MSF.exe is SymbOS.Romride.I.
Related files:
C:\System\Data\Apparc.db
C:\System\Data\Applications.dat
C:\System\Data\backupdb.dat
C:\System\Data\Calendar
C:\System\Data\Cdbv3.dat
C:\System\Data\CntModel.ini
C:\System\Data\DRMHS.dat
C:\System\Data\Dtstor.ini
C:\System\Data\eposglpr.db
C:\System\Data\HAL.DAT
C:\System\Data\NITZ.dat
C:\System\Data\Plugins\ECom.idx
C:\System\Data\Plugins\ECom.ROM.dat
C:\System\Data\Profiles\Profile0.dat
C:\System\Data\PTIT9UDB0f.DAT
C:\System\Data\ScShortcutEngine.ini
C:\System\Data\WVSaplni0.DAT
C:\System\MSF.exe
C:\System\Recogs\MSF.mdl
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process MSF.exe and remove MSF.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msfck.exe
Msfck.exe is W32.Falsu.E.
W32.Falsu.E is a worm that spreads through file-sharing networks and mIRC.
Related files:
%Windir%\Win.exe
%Windir%\Winini.scr
%Windir%\msfck.exe
%Windir%\mswin32.exe
%Windir%\winlog.pif
%Windir%\sysreset.scr
%Windir%\sysoff.pif
%Windir%\taskbar.exe
%Windir%\tasker.pif
%Windir%\thefuck.scr
%Windir%\lsass.exe
[MIRC FOLDER]\macbet.mrc
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process msfck.exe and remove msfck.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msfeed.exe
We suggest you to remove msfeed.exe from your computer as soon as possible.
Msfeed.exe is Troj/Sniffer-P.
Related files:
%System%\Packet.dll
%System%\WanPacket.dll
%System%\drivers\npf.sys
%System%\msfeed.exe
%System%\sevices.exe
%System%\wpcap.dll
Read more:
http://www.sophos.com/security/analyses/...
Kill the process msfeed.exe and remove msfeed.exe from Windows startup.

msfir80.exe
We suggest you to remove MSFIR80.EXE from your computer as soon as possible.
MSFIR80.EXE is Troj/VB-CYJ.
Read more:
http://www.sophos.com/security/analyses/...
Kill the process MSFIR80.EXE and remove MSFIR80.EXE from Windows startup.

msfirewall.exe
Msfirewall.exe is Trojan/Backdoor.
Kill the process msfirewall.exe and remove msfirewall.exe from Windows startup.

msfnt32i.exe
Msfnt32i.exe is Trojan/Backdoor.
Kill the process msfnt32i.exe and remove msfnt32i.exe from Windows startup.
http://www3.ca.com/securityadvisor/pest/...

msfport.dll
Msfport.dll is Troj/Clunky-A.
Related files:
IEXPLORER.EXE
adslcom.exe
adslcomdos.exe
wincontxt.dll
Adslcom.sys
msfport.dll
Read more:
http://www.sophos.com/virusinfo/analyses...
Kill the file msfport.dll and remove msfport.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msfq32.dll
Msfq32.dll is Trojan/Backdoor Feebs.
Kill the file msfq32.dll and remove msfq32.dll from Windows startup using RegRun Reanimator.
http://www.greatis.com/security/Removal_...

msfrewall.exe
Msfrewall.exe is Trojan/Backdoor.
Kill the process msfrewall.exe and remove msfrewall.exe from Windows startup.

msfun80.exe
Msfun80.exe is W32/VB-CYG.
Related files:
msime82.exe
msfun80.exe
fun.xls.exe
Read more:
http://www.sophos.com/security/analyses/...
Kill the process msfun80.exe and remove msfun80.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msgate.exe
W32/Sdbot-OK is a worm which attempts to spread to remote network shares.
It spreads to network shares with weak passwords as a result of the backdoor Trojan element receiving the appropriate command from a remote user.
Copies itself to the Windows system folder as MSGATE.EXE and creates the following registry entry to run itself on system logon:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\msgate = msgate.exe

Remove it from startup with RegRun Startup Optimizer.

msgbs1.vxd
Trojan.Win32.KillDisk.f

This Trojan is extremely dangerous.
It installs itself on the system as a driver, and starting from 27th April 2004 it will delete data from the hard disk.

In systems running Windows 9x, the Trojan installs itself as the driver
MSGBS1.VXD

In systems running Windows NT/2000/XP and all subsequent versions, it installs itself as the driver
ACPI89.SYS

The Trojan also creates the following two files:

C:\Program Files\Internet Explorer\fileproc.txt
C:\Program Files\Internet Explorer\filepath.txt

msgconfigre.exe
Msgconfigre.exe is Trojan/Backdoor.
Kill the process msgconfigre.exe and remove msgconfigre.exe from Windows startup.

msgconfigrs.exe
Msgconfigrs.exe is Trojan/Backdoor.
Kill the process msgconfigrs.exe and remove msgconfigrs.exe from Windows startup.

msgegh.sys
MSGEGH.SYS is Trojan/Backdoor.
Kill the file MSGEGH.SYS and remove MSGEGH.SYS from Windows startup using RegRun Reanimator.
http://www.regrun.com

msgfix.exe
Msgfix.exe is a network aware worm W32.Randex.DXP.
Msgfix.exe opens a back door on TCP port 6677.
Msgfix.exe spreads via open network shares.
Related files:
%System%\svupdate.exe
Admin$\system32\msgfix.exe
Admin$\msgfix.exe
c$\winnt\system32\msgfix.exe
c$\windows\system32\msgfix.exe
c$\msgfix.exe
d$\msgfix.exe
IPC$\msgfix.exe
print$\msgfix.exe
Adds the value:
"Configuration Loader" = "svupdate.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill msgfix.exe process and remove msgfix.exe from Windows startup using RegRun Startup Optimizer.

msgmr.exe
Msgmr.exe is a mass-mailing worm W32.Mytob.L@mm.
Msgmr.exe tries to terminate antiviral programs installed on a user computer.
Msgmr.exe opens a back door on a random TCP port.
Msgmr.exe spreads by exploiting the Microsoft Windows Local Security Authority Service Remote Buffer Overflow (Microsoft Security Bulletin MS04-011).
Related files:
%System%\msgmr.exe
C:\funny pic.scr
C:\see_this!!.scr
C:\my_photo2005.scr
Adds the value:
"Win TaskLoader" = "msgmr.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill msgmr.exe process and remove msgmr.exe from Windows startup using RegRun Startup Optimizer.

msgmsr.exe
Msgmsr.exe is Trojan/Backdoor.
Kill the process Msgmsr.exe and remove Msgmsr.exe from Windows startup.
Related files for W32.HLLW.Nautic:
* NTDLL.exe
* Win32.exe
* Explore.exe
* Kernel32.exe
* krnl286.exe
* Dllhost32.exe
* MSTCP.exe
* CRSS.exe
* Winlogon32.exe
* Winsrvc.exe
* Ntoskrn.exe
* Vmm32.exe
* Sysmon.exe
* System32.exe
* Sys.exe
* Win.exe
* Rundil32.exe
* Msrvcp.exe
* Msgmsr.exe
* Mscde32.exe
* Regsvclib.exe
* Reg32.exe
* Registry32.exe
* Service.exe
* Rpcsrvc.exe
More info:
http://securityresponse.symantec.com/avc...

msgolder.dll
Msgolder.dll is a Trojan.Goldun.B.
msgolder.dll monitors user Internet activity and private information.
It sends stolen data to a hacker site.
Related files:
%Temp%\golder.exe
%System%\msgolder.dll
More info:
http://securityresponse.symantec.com/avc...
Removal:
Remove msgolder.dll from Windows startup using RegRun Startup Optimizer.

msgran.exe
W32.Gramos is a network-aware worm that downloads the Trojan proxy, Backdoor.Ranck.

It does the following:
Downloads the Trojan proxy, Backdoor.Ranck, from a hard-coded URL, copies it to C:\winnt\Mh.exe, and then executes it.
Registers itself as a service process on Windows 95/98/Me systems to hide itself from the task list.
Calculates a random IP address.
Enumerates the users on the remote server and then attempts to connect using these usernames with a blank password.
Copies itself to \\\c$\winnt\system32\Msgran.exe.
Remotely schedules a task to run the worm on the newly infected computer.

To remove it from autorun section, navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
and delete the value:
"Messenger start-up"="Msgran.exe"

Use RegRun Startup Optimizer to automatically remove it.

msgs7.exe
We suggest you to remove msgs7.exe from your computer as soon as possible.
Msgs7.exe is Troj/Diazom-B.
Related files:
%Startup%\taskman.exe
%System%\msgs7.exe
Read more:
http://www.sophos.com/security/analyses/...
Kill the process msgs7.exe and remove msgs7.exe from Windows startup.

msgsms.exe
Msgsms.exe is Trojan/Backdoor.
Kill the process msgsms.exe and remove msgsms.exe from Windows startup.

msgsrv.cxe
Trojan.Wintrash is a Gentee installer which drops files that damage Windows.
It causes Windows to restart immediately each time you try to start it.
This Trojan also disables critical registry keys.

When Trojan.Wintrash runs, it performs the following actions:
Displays a black bitmap that masks the screen and the activities that the Trojan performs.
Restarts Windows.

Drops the following files: %Windir%\temp\chichie.cxe; %Windir%\temp\chidk.cxe; %Windir%\temp\winfd.cxe; %System%\msgsrv.cxe; %Windir%\xfwfm.cxe;
Windows desktop\Wincfd

Changes the Value data of these registry keys to prevent you from editing the Windows registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\Policies\System
to: "DisableRegistryTools"=dword:00000001

Adds the value: "MSGSRV" = "MSGSRV.CXE"
to these registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Run

Creates the registry key: HKEY_CLASSES_ROOT\.cxe
with the value: "(Default)"="exefile"
so that the files that have the .cxe extension run as executables.

Changes the Value data of: HKEY_CLASSES_ROOT\.exe
to: "(Default)"="Htmlfi1e"
so that .exe files do not run, and the Trojan runs each time you try to run any .exe file.

Adds the values:
"NoRun" = dword:00000001
"NoDrives" = dword:00000001
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

This causes Windows to shut down immediately after starting and causes any Windows display of drive icons to not include any hard drives associated with the system. Data on the drives is not affected, only the way Windows is displayed. Drive information is still available from native DOS on Windows 95/98/Me.

Removal: Please manual delete all registry keys described above.

msgsrv16
Indoctrination trojan

msgsrv16.exe
Name: Shorm
Worm / Steals passwords / Network trojan
Propagates to all shared discs. Autostarts using Windows Startup directory. Passwords and users names are mailed to two addresses in Russia. The .exe file is compressed using ASPack. It connects to a Web page in Russia, both to receive IP addresses to scan and to update itself.

msgsrv36.exe
Frenzy trojan

msgsvr16.exe
Remote Access

msgsvr36.exe
Remote Access

msgsvr64.exe
Remote Access
A very basic RAT.

msguard32.exe
Msguard32.exe is Trojan/Backdoor.
Kill the process msguard32.exe and remove msguard32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msgw32.dll
MSGW32.DLL is Trojan/Backdoor.
Kill the file MSGW32.DLL and remove MSGW32.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

mshcp.exe
Mshcp.exe is W32/Rbot-FNA.
Directory: %SysDir%\dllcache
Mshcp.exe is registered as a new system driver service named "Microsoft DHCPA Service", with a display name of "Microsoft DHCPA Service" and a startup type of automatic.
Read more:
http://www.sophos.com/security/analyses/...
Kill the process mshcp.exe and remove mshcp.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mshepl.exe
Mshepl.exe is Adware.Findwhatever.
Adware.Findwhatever is an adware program that periodically changes the Internet Explorer start page.
Related files:
%Windir%\smss.exe
%Windir%\mshepl.exe
%Windir%\mssetup.exe
%Windir%\svchost.exe
%Windir%\ups.exe
%Windir%\xcopy.exe
%Windir%\mdm.exe
%Windir%\dpvsetup.exe
%Windir%\autolfn.exe
%Windir%\csrss.exe
%Windir%\label.exe
%Windir%\mmc.exe
%Windir%\msswchx.exe
%Windir%\mstask.exe
%Windir%\netdde.exe
%Windir%\ntvdm.exe
%Windir%\osk.exe
%Windir%\lasss.exe
%Windir%\spoolsv.exe
%Windir%\sptsupd.exe
%Windir%\subst.exe
%Windir%\w32tm.exe
%Windir%\mshta.exe
%Windir%\dsndup.exe
Read more:
http://www.symantec.com/security_respons...
Kill the process mshepl.exe and remove mshepl.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mshlpa.exe
Mshlpa.exe is Trojan/Backdoor Mediket.
Kill the process mshlpa.exe and remove mshlpa.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mshome32.exe
MSHOME32.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qqf53c9...
Kill the process MSHOME32.EXE and remove MSHOME32.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mshp.dll
Mshp.dll is an adware program Adware.Iefeats.
Mshp.dll opens a back door.
Mshp.dll monitors user Internet activity and private information.
It sends stolen data to a hacker site.
Related files:
Msiesh.dll
iefeatsl.dll
image.dll
Mshp.dll
f2install.exe
%SystemDrive%\f2install.log
Adds the value:
"[name of the installer file]" = "[location and name of the installer file]"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Remove Mshp.dll from Windows startup using RegRun Startup Optimizer.

mshq.exe
Mshq.exe is Trojan/Backdoor Feebs.
Kill the process mshq.exe and remove mshq.exe from Windows startup using RegRun Reanimator.
http://www.greatis.com/security/Removal_...

mshs64.exe
Mshs64.exe is Trojan/Backdoor W32/Tilebot-BU.
Kill the process mshs64.exe and remove mshs64.exe from Windows startup.

mshtml.exe
MSHTML.EXE is Virus.MSHTML.
Read more:
http://www.superadblocker.com/definition...
Kill the process MSHTML.EXE and remove MSHTML.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mshtml2.exe
mshtml2.exe is Adware.ClickSpring.
Manufacturer: Clickspring, LLC
www.clickspring.net
Read more:
http://www.superadblocker.com/M/MSHTML2....
Kill the process mshtml2.exe and remove mshtml2.exe from Windows startup using RegRun.
www.regrun.com

mshtml3.exe
MSHTML3.EXE is Spyware Midaddle.
Related files:
%appdata%\?racle\WUAUBOOT.EXE
%commonfiles%\??sembly\RUNDLL32.EXE
%commonfiles%\?ssembly\MSHTA.EXE
%profiles%\default\my documents\à¾sembly\WUCRTUPD.EXE
%profiles%\dustinus\application data\??stem\REGSVR32.EXE
%profiles%\phillip.bilbo\my documents\??mbols\SCANREGW.EXE
%programfiles%\?icrosoft\NTVDM.EXE
%programfiles%\common files\?icrosoft\WUACLT.EXE
%programfiles%\common files\?racle\JAVAW.EXE
%programfiles%\common files\àssembly\WINWORD.EXE
Read more:
http://virusinfo.prevx.com/pxparall.asp?...
Kill the process MSHTML3.EXE and remove MSHTML3.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mshtml32.exe
We suggest you to remove mshtml32.exe from your computer as soon as possible.
Mshtml32.exe is Worm.Win32.Skipi.a.
Related files:
%System%\wndrivs.exe
%System%\mshtml32.exe
%System%\sdrives32.exe
%System%\winlgcver.exe
Read more:
http://www.viruslist.com/en/viruses/ency...
Kill the process mshtml32.exe and remove mshtml32.exe from Windows startup.

mshtmldat32.exe
Mshtmldat32.exe is W32/Pykse-C.
Related files:
%System%\mshtmldat32.exe
%System%\sdrivew32.exe
%System%\winlgcvers.exe
%System%\wndrivs32.exe
%Removable Drive%:\game.exe
%Removable Drive%:\zjbs.exe
Read more:
http://www.sophos.com/security/analyses/...
Kill the process mshtmldat32.exe and remove mshtmldat32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mshtmlsh32.exe
Mshtmlsh32.exe is Win32.HLLW.Crazy.A.
Related files:
wndrivsd32.exe
mshtmlsh32.exe
winlgcverx.exe
sdrivec32.exe
Read more:
http://www.bitdefender.com/VIRUS-1000174...
Kill the process mshtmlsh32.exe and remove mshtmlsh32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mshytcsx32.exe
Mshytcsx32.exe is Trojan/Backdoor.
Mshytcsx32.exe is installed as service "Mhcm".
Disable or delete service "Mhcm" using RegRun Start Control.
Kill the file mshytcsx32.exe.

msi211.exe
Worm / Destructive trojan / Network trojan
Alters Win.ini. It is also found in Windows Startup Directory. Msinit spreads itself through open network shares and disables infected computers from the network. Most of the files are packed using different versions of UPX. Dnetc is a legitimite program that may have been installed previously. In this case it´s used illegally.

msi216.exe
Worm / Destructive trojan / Network trojan
Alters Win.ini. It is also found in Windows Startup Directory. Msinit spreads itself through open network shares and disables infected computers from the network. Most of the files are packed using different versions of UPX. Dnetc is a legitimite program that may have been installed previously. In this case it´s used illegally.

msib32.exe
Msib32.exe is Trojan/Backdoor.
Kill the process msib32.exe and remove msib32.exe from Windows startup.

msiconfd.exe
Msiconfd.exe is Trojan/Backdoor.
Kill the process msiconfd.exe and remove msiconfd.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msiconfig.exe
Msiconfig.exe is Trojan/Backdoor.
Kill the process msiconfig.exe and remove msiconfig.exe from Windows startup.

mside.dll
mside.dll is a Trojan.Goldun-AK.
mside.dll monitors user Internet activity and private information.
It sends stolen data to a hacker site.
More info:
http://www.sophos.com/virusinfo/analyses...
Removal:
Remove mside.dll from Windows startup using RegRun Startup Optimizer.

msidle32.exe
MsIdle32.exe is a Trojan/Backdoor Backdoor.Verify.
MsIdle32.exe tries to terminate antiviral programs installed on a user computer.
MsIdle32.exe opens a back door on TCP port 1906 and 1907.
MsIdle32.exe spreads via open network shares.
Related files:
%System%\MsIdle32.exe
%System%\MsIdle32Hook.dll
%System%\MsSysInfo32.exe
C:\MsBootMgr.exe
Adds the value:
"MsIdle32.exe" = "C:\WINNT\system32\MsIdle32.exe"
"MsBootMgr.exe" = "C:\MsBootMgr.exe"
"Shell" = "C:\WINNT\system32\MsIdle32.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill MsIdle32.exe process and remove MsIdle32.exe from Windows startup using RegRun Startup Optimizer.

msidle32hook.dll
MsIdle32Hook.dll is a Trojan/Backdoor Backdoor.Verify.
MsIdle32Hook.dll tries to terminate antiviral programs installed on a user computer.
MsIdle32Hook.dll opens a back door on TCP port 1906 and 1907.
MsIdle32Hook.dll spreads via open network shares.
Related files:
%System%\MsIdle32.exe
%System%\MsIdle32Hook.dll
%System%\MsSysInfo32.exe
C:\MsBootMgr.exe
Adds the value:
"MsIdle32.exe" = "C:\WINNT\system32\MsIdle32.exe"
"MsBootMgr.exe" = "C:\MsBootMgr.exe"
"Shell" = "C:\WINNT\system32\MsIdle32.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Remove MsIdle32Hook.dll from Windows startup using RegRun Startup Optimizer.

msidll.exe
MSIDLL.EXE is Trojan/Backdoor.
Related files:
1 :%profiles%\mathew\A.EXE
2 :%WINDIR%\SYSTEM32\A.EXE
3 :%WINDIR%\SYSTEM32\DRONE.EXE
4 :%WINDIR%\SYSTEM32\E.EXE
5 :%WINDIR%\SYSTEM32\E_11643.EXE
6 :%WINDIR%\SYSTEM32\E_17837.EXE
7 :%WINDIR%\SYSTEM32\E_27301.EXE
8 :%WINDIR%\SYSTEM32\E_28508.EXE
9 :%WINDIR%\SYSTEM32\E_38663.EXE
10:%WINDIR%\SYSTEM32\E_42823.EXE
Read more:
http://fileinfo.prevx.com/adware/qq17704...
Kill the process MSIDLL.EXE and remove MSIDLL.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msie4.exe
Msie4.exe is Trojan/Backdoor.
Kill the process msie4.exe and remove msie4.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msie50h.exe
Remote Access / FTP server / CQ trojan
InCommand can bind (join or wrap) its server to any other .exe file, and can also add extra legth to it to avoid searches on specific file length. It uses selfinstalling plug-ins to add features to the trojan and can thousands of icons stored inside the EditServer file.

msiehelper.dll
Msiehelper.dll is Trojan/Backdoor Troj/SrchSpy-A.
Kill the file msiehelper.dll and remove msiehelper.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com
Read more:
http://www.sophos.com/virusinfo/analyses...

msiesettings.exe
Msiesettings.exe is Trojan/Backdoor.
Kill the process msiesettings.exe and remove msiesettings.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msiesh.dll
This is Trojan program TROJ_IEFEATS.A.
Read more:
http://www.trendmicro.com/vinfo/virusenc...
Remove it from startup.

msiev32.dll
MSIEV32.DLL is Adware COMMANDERNET.
Read more:
http://vil.mcafeesecurity.com/vil/conten...
Kill the file MSIEV32.DLL and remove MSIEV32.DLL from Windows startup using RegRun.
www.regrun.com

msiexec.dll
Msiexec.dll is Trojan VMMSWM.
Related files:
1 :%WINDIR%\SYSTEM32\ARPA.DLL
2 :%WINDIR%\SYSTEM32\CHKDSK.DLL
3 :%WINDIR%\SYSTEM32\CHKNTFS.DLL
4 :%WINDIR%\SYSTEM32\CMD.DLL
5 :%WINDIR%\SYSTEM32\DLLHOST.DLL
6 :%WINDIR%\SYSTEM32\FAST.DLL
7 :%WINDIR%\SYSTEM32\JAVAW.DLL
8 :%WINDIR%\SYSTEM32\LOGONUI.DLL
9 :%WINDIR%\SYSTEM32\LSASS.DLL
10:%WINDIR%\SYSTEM32\NOTEPAD.DLL
Read more:
http://virusinfo.prevx.com/pxparall.asp?...
Kill the file msiexec.dll and remove msiexec.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msiexec128.exe
Msiexec128.exe is worm RBot family.
Kill the process msiexec128.exe and remove msiexec128.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msiexec16.exe
Troj/OptixP-13 Trojan
This is a backdoor for someone who want to take an unauthorised remote access to the computer over a network.

Troj/OptixP-13 moves itself to the system directory with a predefined name such as explorer.exe or msiexec16.exe.
Also adds entries to the registry at:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
and/or
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

Troj/OptixP-13 send a message about the infection through ICQ via the webaddress web.icq.com.

Removal:
launch RegRun Startup Optimizer to do this operation.

msiexec32.exe
W32.Ainesey.A@mm is a mass-mailing worm that sends a copy of itself to all the email addresses gathered from the computer.
The Subject, Body, and Attachment name in the email vary.

Creates a copy of itself as %Windir%\Msiexec32.exe.
Creates the file, %Windir%\Winexec.exe.vbs, and executes it.
This file is detected as W32.Ainesey.A@mm!vbs.

Adds the values:
"MSIEXEC"="%Windows%\MSIEXEC32.exe"
"WinExec"=""%Windows%\Winexec.exe.vbs"
to the registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices

Searches local hard drives and network drives for files with the following extensions and overwrites them:
.vbs; .vbe; .js; .jse; .css; .wsh; .sct; .hta; .mp3; .wma

The worm appends a .vbs extension to .js, .jse, .css, .wsh, .sct, .hta, .mp3, and .wma files.

Adds the values to some registry keys which decreases security settings in Microsoft Word, Excel, and PowerPoint.
Emails a copy of itself to the email addresses gathered from the system.

Automatic removal: Use RegRun Startup Optimizer to remove it from startup.

msiexp.exe
MSIEXP.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq393e4...
Kill the process MSIEXP.EXE and remove MSIEXP.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msii.exe
Msii.exe is Trojan/Backdoor.
Kill the process msii.exe and remove msii.exe from Windows startup.

msijavaupdt32.exe
MSIJAVAUPDT32.EXE is WORM_RANDEX.AF.
Read more:
http://www.trendmicro.com.au/consumer/vi...
Kill the process MSIJAVAUPDT32.EXE and remove MSIJAVAUPDT32.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msiloi.dll
MSILOI.DLL is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qqd3391...
Kill the file MSILOI.DLL and remove MSILOI.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

msime82.exe
Msime82.exe is W32/VB-CYG.
Related files:
\fun.xls.exe
\autorun.inf
%Windows%\ufdata2000.log
msime82.exe
msfun80.exe
Read more:
http://www.sophos.com/security/analyses/...
Kill the process msime82.exe and remove msime82.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msimms32.dll
MsIMMs32.dll is TSPY_LEGMIR.BJX.
Related files:
%Windows%\MsIMMs32.exe
%System%\MsIMMs32.dll
Read more:
http://www.trendmicro.com/vinfo/grayware...
Kill the file MsIMMs32.dll and remove MsIMMs32.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msimms32.exe
Msimms32.exe is TSPY_LEGMIR.BJX.
Related files:
%Windows%\MsIMMs32.exe
%System%\MsIMMs32.dll
Read more:
http://www.trendmicro.com/vinfo/grayware...
Kill the process msimms32.exe and remove msimms32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msimn32.exe
MSIMN32.EXE is Trojan/Backdoor Trojan.Win32.Agent.cx.
Kill the process MSIMN32.EXE and remove MSIMN32.EXE from Windows startup.

msinfo.exe
Backdoor.IRC.Aladinz.M is a backdoor Trojan horse that uses malicious scripts in the mIRC client software, allowing unauthorized remote access.

When it is executed, it performs the following actions:
Creates different files in %System32%\Wbem\Mof\Good\System:
@ - clean text log file
conn.dll - clean IRC dll file
csrss.dll - malicious IRC script detected as IRC Trojan
and others.

Attempts to copy itself as the following files:
C:\wupd.exe
%System32%\msinfo.exe

Adds the value:
"MSInfo" = "msinfo.exe"
"MSUpdate"="wupd.exe"
to the registry keys:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
and "MSInfo" = "msinfo.exe" to
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices

Disables DCOM support by setting the value to:
"EnableDCOM" = "N"
in the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\EnableDCOM

Allows a remote attacker to control the computer. The functions provided include:

Retrieving information about the computer.
Stopping and restarting the Trojan.
Downloading and running files.
Scanning hosts for vulnerabilities using the Remacc.Dwremote.

EnabledDCOM value to "Y." in the system registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\EnableDCOM

And use RegRun Startup Optimizer to remove it from startup.

msinit.exe
Worm / Destructive trojan / Network trojan
Alters Win.ini. It is also found in Windows Startup Directory. Msinit spreads itself through open network shares and disables infected computers from the network. Most of the files are packed using different versions of UPX. Dnetc is a legitimite program that may have been installed previously. In this case it´s used illegally.

msinst26.exe
Msinst26.exe is W32/Lamud-A.
Related files:
%WinDir%\ACD Wallpaper.bmp
%WinDir%\davcsync.exe
%WinDir%\lmdll.dll
Games.exe
Pictures.exe
Images.exe
Downloads.exe
My documents.exe
Video.exe
Music.exe
New.exe
XXX.exe
Porno.exe
Private.exe
Read more:
http://www.sophos.com/security/analyses/...
Kill the process msinst26.exe and remove msinst26.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msio32.dll
Msio32.dll is Trojan/Backdoor.
Read more:
http://www.incodesolutions.com/threats/W...
Kill the file msio32.dll and remove msio32.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msip32.exe
Msip32.exe is Trojan Downloader.
Kill the process msip32.exe and remove msip32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

ms-its.exe
Ms-its.exe is Trojan/Backdoor.
Kill the process ms-its.exe and remove ms-its.exe from Windows startup.

msivsm32.dll
Msivsm32.dll is Troj/Haoba-A.
Related files:
%System%\MISuvstm.exe
%System%\msivsm32.dll
Read more:
http://www.sophos.com/security/analyses/...
Kill the file msivsm32.dll and remove msivsm32.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msiwa32.exe
MSIWA32.exe is Trojan/Backdoor.
Read more:
http://spywarefiles.prevx.com/RRHDDH0374...
Kill the process MSIWA32.exe and remove MSIWA32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msixu.dll
MSIXU.DLL is Trojan/Backdoor.
Kill the file MSIXU.DLL and remove MSIXU.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

msj32.exe
Msj32.exe is Trojan/Backdoor.
Kill the process msj32.exe and remove msj32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msjavam32.exe
Msjavam32.exe is WORM_AGOBOT.AKM.
Read more:
http://www.trendmicro.com/vinfo/virusenc...
Kill the process msjavam32.exe and remove msjavam32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msjeclus.exe
Msjeclus.exe is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq61162...
Kill the process msjeclus.exe and remove msjeclus.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msjet32.exe
Remote Access

msjvm.exe
Msjvm.exe is Trojan/Backdoor.
Kill the process msjvm.exe and remove msjvm.exe from Windows startup.

msjvm86.exe
Msjvm86.exe is Trojan/Backdoor.
Kill the process msjvm86.exe and remove msjvm86.exe from Windows startup.

msjwer.exe
Msjwer.exe is Troj/DelSpy-E.
Troj/DelSpy-E may inject code into other processes and includes functionality to steal passwords and email the information it steals to a remote user. The Trojan may also include backdoor functionality, allowing a remote user to gain a command prompt on the compromised computer.
Related files:
%Windows%\msjwer.dll - also detected as Troj/DelSpy-E
%System%\msjwer.hts
Read more:
http://www.sophos.com/security/analyses/...
Kill the process msjwer.exe and remove msjwer.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msjz32.dll
Msjz32.dll is Trojan/Backdoor W32.Feebs.A.
Kill the file msjz32.dll and remove msjz32.dll from Windows startup.
http://securityresponse.symantec.com/avc...

mskdll.dll
Mskdll.dll is a network-aware W32.Spybot.OGX.
Mskdll.dll opens a back door on TCP port 8000.
Mskdll.dll spreads via open network shares.
Mskdll.dll tries to terminate antiviral programs installed on a user computer.
Related files:
%System%\sdkimprovment2.exe
%System%\mskdll.dll
%System%\msdirectx.sys
Adds the value:
"SDK Core Function2" = "sdkimprovment2.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Remove mskdll.dll from Windows startup using RegRun Startup Optimizer.

mskernel16.exe
Remote Access
Alters Win.ini and System.ini. A servereditor makes it possible for an intruder to change the port used and the UIN to notify upon a new succesful installation.

mskernel32.vbs
I-Worm.LoveLetter
This is the Internet worm that caused the global epidemic at the beginning of May 2000.
The worm spreads via e-mail by sending infected messages from affected computers.
The worm uses MS Outlook and sends itself to all addresses that are stored in the MS Outlook Address Book.

When run, the worm sends its copies by e-mail, installs itself into the system, performs destructive actions, downloads and installs a Trojan program.
The worm also has the ability to spread through the mIRC channels.

These files are registered in the Windows auto-run section in the system registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\MSKernel32 = MSKERNEL32.VBS
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Win32DLL = Win32DLL.VBS
You can manually delete these key to disable this worm.

mskev.exe
Mskev.exe is W32/Sdbot-XV.
Read more:
http://www.sophos.com/security/analyses/...
Kill the process mskev.exe and remove mskev.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mskkk.exe
Mskkk.exe is Trojan/Backdoor.
Kill the process mskkk.exe and remove mskkk.exe from Windows startup.

msksvrvs.exe
MSKSVRVS.EXE is Trojan/Backdoor.
Kill the process MSKSVRVS.EXE and remove MSKSVRVS.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mslame.exe
W32/MsLame-A
It is a worm for the Windows platform that spreads by copying itself to the A: drive or through IRC channels drive using one of the following names:
doc5.doc; ~word.tmp.doc; ~word.tmp.doc; WORDTEMP~~.doc; ~TEMP.doc; ~WORDTEMP.doc; doc1.rtf; document.doc

Manual removal:
Navigate to the key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\MsLame
and delete the key related to MsLame.exe.

mslaugh.exe
Mslaugh.exe is Trojan/Backdoor Blaster.
Kill the process mslaugh.exe and remove mslaugh.exe from Windows startup.

msldr32.dll
MSLDR32.DLL is Trojan/Backdoor.
Kill the file MSLDR32.DLL and remove MSLDR32.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

mslexec.exe
Mslexec.exe is Trojan/Backdoor.
Kill the process mslexec.exe and remove mslexec.exe from Windows startup.

mslog.exe
MSLOG.EXE is BKDR_AGENT.AOV.
Related files:
mslog.dat - non-malicious file
mslog.dll - detected as BKDR_AGENT.AOV
mslog.exe - detected as BKDR_AGENT.AOV
Read more:
http://www.trendmicro.com/vinfo/virusenc...
Kill the process MSLOG.EXE and remove MSLOG.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msloginserv.dll
msloginserv.dll is a Trojan.ServU-BM.
msloginserv.dll opens a back door.
Related files:
msloginserv.dll
msloginservtemp.dll
More info:
http://www.sophos.com/virusinfo/analyses...
Removal:
Remove msloginserv.dll from Windows startup using RegRun Startup Optimizer.

msloginservtemp.dll
msloginservtemp.dll is a Trojan.ServU-BM.
msloginservtemp.dll opens a back door.
Related files:
msloginserv.dll
msloginservtemp.dll
More info:
http://www.sophos.com/virusinfo/analyses...
Removal:
Remove msloginservtemp.dll from Windows startup using RegRun Startup Optimizer.

mslogon.exe
Mslogon.exe is W32.Bustoy.
Related files:
%UserProfile%\Start Menu\Programs\Startup\systemnt.exe
%System%\mslogon.exe
Read more:
http://www.symantec.com/enterprise/secur...
Kill the file mslogon.exe and remove mslogon.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

Also, it may be Advertising Spyware.
Part of RapidBlaster software
http://www.rapidblaster.com/
Typically displays pop-ups for porn sites.
Read more about:
http://www.doxdesk.com/parasite/RapidBla...

mslogon.exe
Mslogon.exe is W32.Bustoy.
Related files:
%UserProfile%\Start Menu\Programs\Startup\systemnt.exe
%System%\mslogon.exe
Read more:
http://www.symantec.com/enterprise/secur...
Kill the file mslogon.exe and remove mslogon.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

Also, it may be Advertising Spyware.
Part of RapidBlaster software
http://www.rapidblaster.com/
Typically displays pop-ups for porn sites.
Read more about:
http://www.doxdesk.com/parasite/RapidBla...

msls.exe
Msls.exe is Trojan/Backdoor Feebs.
Kill the process msls.exe and remove msls.exe from Windows startup using RegRun Reanimator.
http://www.greatis.com/security/Removal_...

msls32.exe
Msls32.exe is Trojan/Backdoor.
Kill the process msls32.exe and remove msls32.exe from Windows startup.

mslsnre.exe
Mslsnre.exe is Rootki&Virus, clone of HackerDefender.
Kill the process mslsnre.exe and remove mslsnre.exe from Windows startup.
Use UnHackMe to fully remove hidden services and drivers.
www.unhackme.com
Related files:
- mssave.exe
- msinit.exe
- msmail.exe
- mstsk.exe
- lsnr32w.exe
- lsnr32w.dll
- memdrv.sys
- msclean.exe
- msinit.exe
- mslsnre.exe
- pack.exe
- shide32w.exe
- shide32w.ini
- smss.all
- tiinject.exe
- tinject.dll
- tinject.exe
http://webserver1.furman.edu/computing/c...

mslti64.exe
MSLTI64.EXE is Trojan/Backdoor.
Kill the process MSLTI64.EXE and remove MSLTI64.EXE from Windows startup.

msm32.exe
Msm32.exe is Trojan/Backdoor.
Kill the process msm32.exe and remove msm32.exe from Windows startup.

msmachine.exe
Remote Access

msmails.exe
Msmails.exe is Trojan/Backdoor.
Kill the process msmails.exe and remove msmails.exe from Windows startup.

msmapi.exe
MSMAPI.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq8e341...
Kill the process MSMAPI.EXE and remove MSMAPI.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msmapi32.exe
MSMAPI32.EXE is Trojan.Downlaoder.
Read more:
http://www.superadblocker.com/definition...
Kill the process MSMAPI32.EXE and remove MSMAPI32.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msmdev.dll
Msmdev.dll is Trojan/Backdoor.
Kill the file msmdev.dll and remove msmdev.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msmdm.exe
I-Worm.Lentin or W32/Yaha@MM dangerous trojan. Before removing from hard disk you must restore default file extension for exe files.

msmduo2.dll
We suggest you to remove msmduo2.dll from your computer as soon as possible.
Msmduo2.dll is Trojan/Backdoor.
Kill the file msmduo2.dll and remove msmduo2.dll from Windows startup.

msmessgs.exe
msmessgs.exe is a Trojan.Small-EW.
msmessgs.exe opens a back door.
More info:
http://www.sophos.com/virusinfo/analyses...
Removal:
Kill msmessgs.exe process and remove msmessgs.exe from Windows startup using RegRun Startup Optimizer.

msmgmctl.exe
Msmgmctl.exe is Trojan/Backdoor W32/Rbot-APA.
Kill the process msmgmctl.exe and remove msmgmctl.exe from Windows startup.
http://www.sophos.com/virusinfo/analyses...

msmgrxp.exe
Msmgrxp.exe is mass-mailing worm W32.Mytob.AK@mm.
Msmgrxp.exe tries to terminate antiviral programs installed on a user computer.
Msmgrxp.exe opens a back door on TCP port 10087.
Msmgrxp.exe spreads by exploiting the DCOM RPC vulnerability (Microsoft Security Bulletin MS03-026) and the Microsoft Windows Local Security Authority Service Remote Buffer Overflow (Microsoft Security Bulletin MS04-011).
Related files:
%System%\msmgrxp.exe
%System%\bingoo.exe
C:\funny_pic.scr
C:\see_this!!.scr
C:\my_photo2005.scr
C:\hellmsn.exe

Adds the value:
"WINTASK" = "msmgrxp.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill msmgrxp.exe process and remove msmgrxp.exe from Windows startup using RegRun Startup Optimizer.

msmhost.dll
MSMHOST.DLL is Trojan/Backdoor.
Kill the file MSMHOST.DLL and remove MSMHOST.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

msmicrosoft.exe
Msmicrosoft.exe is Trojan/Backdoor.
Kill the process msmicrosoft.exe and remove msmicrosoft.exe from Windows startup.

msmm32.dll
Msmm32.dll is Trojan/Backdoor Feebs.
Kill the file msmm32.dll and remove msmm32.dll from Windows startup using RegRun Reanimator.
http://www.greatis.com/security/Removal_...

msmmsgr.exe
Msmmsgr.exe is a worm W32.Kelvir.Q.
Msmmsgr.exe spreads via MSN Messenger.
Msmmsgr.exe opens a back door on TCP port 8126.
Related files:
%System%\msmmsgr.exe
Adds the value:
"MSN MESSENGER" = "msmmsgr.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill msmmsgr.exe process and remove msmmsgr.exe from Windows startup using RegRun Startup Optimizer.

msmoni.exe
Msmoni.exe is Trojan/Backdoor Sdbot.
Kill the process msmoni.exe and remove msmoni.exe from Windows startup.

msmonk32.exe
Msmonk32.exe is Trojan/Backdoor.
Kill the process msmonk32.exe and remove msmonk32.exe from Windows startup.
http://securityresponse.symantec.com/avc...

msmpatch.exe
Msmpatch.exe is Trojan/Backdoor.
Kill the process msmpatch.exe and remove msmpatch.exe from Windows startup.

msmsger.exe
MSMSGER.EXE is Dropper.Payload.
Read more:
http://fileinfo.prevx.com/adware/qq73467...
Kill the process MSMSGER.EXE and remove MSMSGER.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msmsgnc.dll
msmsgnce.exe is Trojan/Backdoor.
msmsgnce.exe downloads the new viruses/Trojan/updates from master web sites.
Kill it in memory and remove msmsgnce.exe from Windows startup.
Related files:
ssysprs.dll
setfgi.dll
msmsgnc.dll

msmsgnce.exe
msmsgnce.exe is Trojan/Backdoor.
msmsgnce.exe downloads the new viruses/Trojan/updates from master web sites.
Kill it in memory and remove msmsgnce.exe from Windows startup.
Related files:
ssysprs.dll
setfgi.dll
msmsgnc.dll

msmsgri32.exe
Msmsgri32.exe is Trojan/Backdoor.
Kill the process msmsgri32.exe and remove msmsgri32.exe from Windows startup.

msmsmg.exe
Msmsmg.exe is Trojan/Backdoor.
Kill the process msmsmg.exe and remove msmsmg.exe from Windows startup.

msmssgs.exe
msmssgs.exe is a Trojan Backdoor.Bifrose.C.
msmssgs.exe monitors user Internet activity and private information.
It sends stolen data to a hacker site.
Related files:
%System%\msmssgs.exe
Adds the value:
"msmautoprotect" = "%System%\msmssgs.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill msmssgs.exe process and remove msmssgs.exe from Windows startup using RegRun Startup Optimizer.

msn16.exe
Msn16.exe is Trojan/Backdoor.
Kill the process msn16.exe and remove msn16.exe from Windows startup.

msn64.exe
MSN64.EXE is Trojan/Backdoor.
Kill the process MSN64.EXE and remove MSN64.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msn7.exe
Msn7.exe is Trojan/Backdoor Troj/Wurmark-B.
Kill the process msn7.exe and remove msn7.exe from Windows startup.
www.sophos.com/virusinfo/analyses/trojwurmarkb.html

msnadm32.exe
msnadm32.exe is a Backdoor W32.Spybot.PEN.
msnadm32.exe spreads via open network shares.
msnadm32.exe tries to terminate antiviral programs installed on a user computer.
msnadm32.exe monitors user Internet activity and private information.
It sends stolen data to a hacker site.
Related files:
C:\tmpdata\ImSexy.exe
%System%\msnadm32.exe
Adds the value:
"Microsoft Networking Agent For SP2" = "msnac32.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill msnadm32.exe process and remove msnadm32.exe from Windows startup using RegRun Startup Optimizer.

msnavc32.exe
Msnavc32.exe is the new generation of VX2 adware components.
Msnavc32.exe runs from Windows startup registry keys.
Also, Msnavc32 alters the AppInitDLLs registry value to track all started processes and Internet activity.
Msnavc32 copies its body to the Windows\System32 folder.
Msnavc32 can change WinSock2 LSP chain.
It inserts the dolsp.dll into the LSP chain.

Related files:
0er8k4va.exe
Mkfxut.exe
pkdacs.exe
ywrqku.exe
msnavc32.exe
AutoUpdate.exe
winntcreate.exe
vwix32.exe
sysmonnt.exe
winhcek32.exe
qlykdnb.dll
rypgvtoimrl.exe
spwgoc.exe
msnavc32.exe
sysmonnt
hpdll.exe
w?wexec.exe
ffisearch.exe

Delete the files.
They are may be hidden.

C:\Program Files\0er8k4va\0er8k4va.exe
C:\WINDOWS\System32\Mkfxut.exe
C:\WINDOWS\system32\pkdacs.exe
C:\WINDOWS\System32\ywrqku.exe
C:\windows\system32\msnavc32.exe
C:\Program Files\AutoUpdate\AutoUpdate.exe
C:\WINDOWS\System32\winntcreate.exe
C:\WINDOWS\System32\vwix32.exe
C:\WINDOWS\System32\sysmonnt.exe
C:\WINDOWS\System32\winhcek32.exe
C:\WINDOWS\System32\qlykdnb.dll
C:\WINDOWS\System32\rypgvtoimrl.exe
C:\WINDOWS\System32\spwgoc.exe
C:\windows\system32\msnavc32.exe
C:\WINDOWS\System32\sysmonnt
C:\Program Files\hpdll\hpdll.exe
C:\WINDOWS\System32\w?wexec.exe
C:\WINDOWS\isrvs\ffisearch.exe

Removal:
Use RegRun.
Clear Browser Helper Objects list.
Reset to default the AppInitDlls (Anti Spyware module).
Recover LSP using RegRun Winsock2 recovery.
Kill the processes and remove the virus files from Windows startup.

msnba32.exe
Msnba32.exe is Trojan/Backdoor.
Kill the process msnba32.exe and remove msnba32.exe from Windows startup.

msncfg.exe
Msncfg.exe is Trojan/Backdoor.
Kill the process msncfg.exe and remove msncfg.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msncomm.exe
msncomm.exe is BKDR_WEBDOR.AK.
Related files:
TIMED.EXE
MSNCOMM.EXE
Read more:
http://uk.trendmicro-europe.com/enterpri...
Kill the process msncomm.exe and remove msncomm.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msndll32.exe
MSNDLL32.EXE is Trojan/Backdoor.
Kill the process MSNDLL32.EXE and remove MSNDLL32.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msndn.exe
MSNDN.EXE is Trojan/Backdoor.
Related files:
%WINDIR%\SYSTEM32\EDFIMG_04387.EXE
%WINDIR%\SYSTEM32\EDFIMG_05841.EXE
%WINDIR%\SYSTEM32\EDFIMG_16111.EXE
%WINDIR%\SYSTEM32\EDFIMG_23852.EXE
%WINDIR%\SYSTEM32\EDFIMG_75714.EXE
%WINDIR%\SYSTEM32\FDHBE_01661.EXE
%WINDIR%\SYSTEM32\FDHBE_10465.EXE
%WINDIR%\SYSTEM32\FDHBE_10850.EXE
%WINDIR%\SYSTEM32\FDHBE_22380.EXE
%WINDIR%\SYSTEM32\FDHBE_26424.EXE
Read more:
http://fileinfo.prevx.com/QQc19f19289559...
Kill the process MSNDN.EXE and remove MSNDN.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnet32.exe
MSNET32.EXE is Trojan/Backdoor.
Kill the process MSNET32.EXE and remove MSNET32.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnetcfg.exe
Remote Access
May alter System.ini and/or Win.ini. One can choose to let Mosucker randomly decide what autostart method to use. Produces an error message while installing ""Could not find setuplog.bat"" which apparently is used for autostarting. It copies itself to $temp first, as a file named pkg*.exe, ""pkg"" being a fix string. It also copied itself to $windows/unin0686.exe.

msnethelper.exe
MSNETHELPER.EXE is Wareout.
Kill the process MSNETHELPER.EXE and remove MSNETHELPER.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msng.exe
Msng.exe is Trojan/Backdoor.
Msng.exe is installed as Network Security Service.
Delete 'Network Security Service' using RegRun Start Control.
Delete related file:
%SisDir%\msng.exe.

msnger.exe
Msnger.exe is W32/Sdbot.worm.
Kill the process msnger.exe and remove msnger.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com
Read more: http://vil.nai.com/vil/content/v_100454....

msngersd.exe
Msngersd.exe is Worm.
Kill the process msngersd.exe and remove msngersd.exe from Windows startup.

msngmsngr32.exe
MSNGMSNGR32.EXE is Trojan/Backdoor Spybot.
Kill the process MSNGMSNGR32.EXE and remove MSNGMSNGR32.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msngr.exe
Msngr.exe is Troj/Banker-DKN.
Read more:
http://www.sophos.com/security/analyses/...
Kill the process msngr.exe and remove msngr.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msngrs.exe
Msngrs.exe is Trojan/Backdoor.
Kill the process msngrs.exe and remove msngrs.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msngta32.exe
Msngta32.exe is Trojan/Backdoor.
Kill the process msngta32.exe and remove msngta32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnhlp32.dll
Msnhlp32.dll is Trojan-Downloader.Win32.VB.apq.
Related files:
%SYSTEM%\msnhlp32.dll
msnhlp32.dll
msscds32.dll
Read more:
http://research.sunbelt-software.com/thr...
Kill the file msnhlp32.dll and remove msnhlp32.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnhost.dll
Msnhost.dll is Trojan/Backdoor.
Kill the file msnhost.dll and remove msnhost.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnhp32.dll
Msnhp32.dll is Troj/Clckr-KY.
Related files:
%Temp%\Sys.htm
%Temp%\cc1.txt
%Temporary Internet Files%\Content.IE5\\bc1[1].htm
%Windows%\msnhp32.dll
Read more:
http://www.sophos.com/security/analyses/...
Kill the file msnhp32.dll and remove msnhp32.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msni.exe
Msni.exe is Keylogger.
Kill the process msni.exe and remove msni.exe from Windows startup.
http://www.superadblocker.com/definition...

msninet.dll
MSNINET.DLL is Trojan/Backdoor.
Kill the file MSNINET.DLL and remove MSNINET.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

msninet.exe
Msninet.exe is W32/IRCBot-XG.
Related files:
%User%\aria.txt
%System%\libmsns.dll
%System%\msninet.exe
Read more:
http://www.sophos.com/security/analyses/...
Kill the process msninet.exe and remove msninet.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msninst.exe
Msninst.exe is W32.Kuskus.Worm.
Read more:
http://www.symantec.com/avcenter/venc/da...
Kill the process msninst.exe and remove msninst.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnm32.exe
Msnm32.exe is Trojan/Backdoor.
Kill the process msnm32.exe and remove msnm32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnmcgrs.exe
MSNMCGRS.EXE is Trojan/Backdoor Rbot.
Kill the process MSNMCGRS.EXE and remove MSNMCGRS.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnmesg.exe
Msnmesg.exe is Trojan/Backdoor Rbot.
Kill the process msnmesg.exe and remove msnmesg.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnmessengerupdate.exe
Troj/SdBot-BI is an IRC backdoor Trojan which allows unauthorised access and control of the computer from IRC channels.
Also known as Backdoor.SdBot.kd, W32/Spybot.worm.gen.b, Win32/SpyBot.WW, Backdoor.IRC.Bot

Upon execution Troj/SdBot-BI displays the fake error message
"'Error-38427 A valid dll file was not found, Windows is now deleting file."

In order to run automatically when Windows starts up the Trojan copies itself to the file:
mmsnmessengerupdate.exe in the Windows system folder,
and adds the following registry entry to ensure it is started on computer logon:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svshostdriver = msnmessengerupdate.exe

You can easy remove it with RegRun.

msnmgr.exe
Msnmgr.exe is AGOBOT.HA WORM.
Kill the process msnmgr.exe and remove msnmgr.exe from Windows startup.

msnmgr32.exe
Msnmgr32.exe is Trojan/Backdoor.
Kill the process msnmgr32.exe and remove msnmgr32.exe from Windows startup.

msnms.exe
Msnms.exe is Trojan/Backdoor.
Kill the process msnms.exe and remove msnms.exe from Windows startup.

msnmsger.exe
Msnmsger.exe is Trojan/Backdoor.
Kill the process msnmsger.exe and remove msnmsger.exe from Windows startup.

msnmsgr32.exe
MSNMSGR32.EXE is Trojan/Backdoor.
Kill the process MSNMSGR32.EXE and remove MSNMSGR32.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnmsgrr.exe
Msnmsgrr.exe is WORM_RBOT.PZ.
Read more:
http://www.trendmicro.com/vinfo/virusenc...
Kill the process msnmsgrr.exe and remove msnmsgrr.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnmsgrs.exe
W32.Netsky.AD@mm is a mass-mailing worm that uses its own SMTP engine to send itself to the email addresses it finds on the infected computer.
The email subject, message body, and attachment are variable.
Name of attachment: Varies with .bat, .com, .pif, .scr, or .zip file extension.
Copies to shared file folders of various peer-to-peer filesharing applications and instant messaging programs.
Display a message box with the following text: "File Corrupted replace this!!"

Deletes the following values: "Taskmon"; "Explorer"; "KasperskyAv"; "system."
from the registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Deletes the following value: "system."
from the registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Deletes the following key:
HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32

Manual removal:
Navigate to the key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
and delete the value: "MsnMsgr" = "%Windir%\MsnMsgrs.exe"

msnmsgrsc.exe
msnmsgrsc.exe is WIN32.RBOT.
Read more:
http://www3.ca.com/securityadvisor/virus...
Kill the process msnmsgrsc.exe and remove msnmsgrsc.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnmsgs.exe
W32.Netsup.A@mm is a mass-mailing worm that sends itself to addresses gathered from the Microsoft Outlook address book.
The worm can also distribute itself through file-sharing networks.
Sends itself to all email contacts found in the the Outlook address book.
Large scale emailing may impact system performance.

W32.Netsup.A@mm can arrive as an attachment to an email with the following properties:
From: The From line will either be an address taken from the Microsoft Outlook address book or NetworkSupport@.
Subjects: (One of the following)
Attachment: message.eml.pif
Body: A message sent could not be delivered to one or more of its recipients correctly. This is a permanent error. Attached is a copy of the original message.

Uses its own SMTP engine to email itself out to all contacts found in the Outlook address book.
The SMTP server the worm uses is taken from the Internet Account Manager settings.

Manual removal:
Navigate to the key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
and delete the value: "msnmsgs" = "%System%\msnmsgs.exe"

msnmsgsr.exe
Msnmsgsr.exe is Trojan/Backdoor.
Kill the process msnmsgsr.exe and remove msnmsgsr.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnmsng.exe
Msnmsng.exe is Trojan/Backdoor.
Kill the process msnmsng.exe and remove msnmsng.exe from Windows startup.

msnmsngrs.exe
MSNMSNGRS.EXE is Trojan/Backdoor.
Kill the process MSNMSNGRS.EXE and remove MSNMSNGRS.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnmsrg.exe
Msnmsrg.exe is Troj/DelfDldr-A.
Read more:
http://www.sophos.com/virusinfo/analyses...
Kill the process msnmsrg.exe and remove msnmsrg.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnmssgr.exe
Msnmssgr.exe is WIN32.RBOT worm.
Read more:
http://www3.ca.com/securityadvisor/virus...
Kill the process msnmssgr.exe and remove msnmssgr.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnn32.exe
Msnn32.exe is Trojan/Backdoor BKDR_WOMANIZ.B
Kill the process msnn32.exe and remove msnn32.exe from Windows startup.
http://www.trendmicro.com/vinfo/virusenc...

msnnet.exe
We suggest you to remove msnnet.exe from your computer as soon as possible.
Msnnet.exe is Trojan/Backdoor.
Kill the process msnnet.exe and remove msnnet.exe from Windows startup.

msnngr32.exe
MSNNGR32.EXE is Trojan/Backdoor.
Kill the process MSNNGR32.EXE and remove MSNNGR32.EXE from Windows startup.
http://www.trendmicro.com/vinfo/virusenc...

msnnsn.exe
Msnnsn.exe is Trojan/Backdoor.
Kill the process Msnnsn.exe and remove Msnnsn.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnntlp.exe
Msnntlp.exe is W32/Tilebot-JI.
Read more:
http://www.sophos.com/security/analyses/...
Kill the process msnntlp.exe and remove msnntlp.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnowen32.exe
Msnowen32.exe is Trojan/Backdoor.
Kill the process msnowen32.exe and remove msnowen32.exe from Windows startup.

msnplus.exe
Msnplus.exe is Trojan/Backdoor.
Kill the process msnplus.exe and remove msnplus.exe from Windows startup.

msnprcss.exe
MSNPRCSS.EXE is Trojan/Backdoor Trojan.ServiceThreadHandler.Process.
Kill the process MSNPRCSS.EXE and remove MSNPRCSS.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnql32.exe
MSNQL32.EXE is Trojan/Backdoor.
Kill the process MSNQL32.EXE and remove MSNQL32.EXE from Windows startup.
http://www.trendmicro.com/vinfo/virusenc...

msnqmgr.exe
Msnqmgr.exe is Trojan/Backdoor.
Kill the process msnqmgr.exe and remove msnqmgr.exe from Windows startup.

msnr.exe
Msnr.exe is Trojan/Backdoor.
Kill the process msnr.exe and remove msnr.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnrav.exe
Msnrav.exe is W32/Sdbot-DFY.
Read more:
http://www.sophos.com/security/analyses/...
Kill the process msnrav.exe and remove msnrav.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnsched2.exe
Msnsched2.exe is Trojan/Backdoor Spybot.
Kill the process msnsched2.exe and remove msnsched2.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com
Read more:
http://www.symantec.com/avcenter/venc/da...

msnsearc.exe
MSNSEARC.EXE is Trojan/Backdoor.
Kill the process MSNSEARC.EXE and remove MSNSEARC.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnserve.exe
MSNSERVE.EXE is Trojan/Backdoor Sdbot.
Kill the process MSNSERVE.EXE and remove MSNSERVE.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com
Read more:
http://www.sophos.com/virusinfo/analyses...

msnservers.exe
Msnservers.exe is Trojan/Backdoor.
Msnservers.exe is registered in the registry as "AdobeReaderPro".
Kill the process msnservers.exe and remove msnservers.exe from Windows startup.

msnservez.exe
MSNSERVEZ.EXE is Trojan/Backdoor Trojan.MSNServez.Process.
Kill the process MSNSERVEZ.EXE and remove MSNSERVEZ.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com
Read more:
http://www.superadblocker.com/definition...

msnservice.exe
Added as a result of the CARPET.C virus.
W32.HLLW.Carpet.C is a worm that attempts to spread through the A:\ drive.

It does the following:
Copies itself to: %Winir%\MSNService.exe

Adds the value:
"MSNService" = "%Winir%\MSNService.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Attempts to copy to itself to a:\Iswarya.gif.exe every 60 seconds.

Manual remove:
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value below:
"MSNService" = "%Windir%\MSNService.exe"

Automatical remove:
Use RegRun Startup Opimizer.

msnsgr.exe
Msnsgr.exe is Trojan/Backdoor.
Read more:
http://www.nuker.com/container/fn/msnsgr...
Kill the process msnsgr.exe and remove msnsgr.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnsgs.exe
Msnsgs.exe is Trojan/Backdoor Troj/Cheuko-B.
Kill the process msnsgs.exe and remove msnsgs.exe from Windows startup.
www.sophos.com/virusinfo/analyses/trojcheukob.html

msnspy.exe
Msnspy.exe is Spyware.MSNSpyMonitor.
Spyware.MSNSpyMonitor is a spyware program that can be used to record Microsoft instant messaging conversations on a local network.
Related files:
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\MsnSpy.lnk
%UserProfile%\Desktop\MsnSpy.lnk
%UserProfile%\Start Menu\Programs\MsnSpy\MsnSpy Help.lnk
%UserProfile%\Start Menu\Programs\MsnSpy\MsnSpy.lnk
%UserProfile%\Start Menu\Programs\MsnSpy\Uninstall.lnk
%ProgramFiles%\MsnSpy\msnspy.chm
%ProgramFiles%\MsnSpy\msnspy.exe
%ProgramFiles%\MsnSpy\readme.rtf
%ProgramFiles%\MsnSpy\Uninstall.exe
%ProgramFiles%\MsnSpy\WinPcap_3_1.exe
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process msnspy.exe and remove msnspy.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnsrv.exe
MSNSRV.EXE is Trojan/Backdoor Sdbot.
Kill the process MSNSRV.EXE and remove MSNSRV.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com
Read more:
http://www.sophos.com/virusinfo/analyses...

msnsrv32.exe
MSNSRV32.EXE is Trojan/Backdoor.
Kill the process MSNSRV32.EXE and remove MSNSRV32.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnss.exe
W32.Gaobot.AUS
It is a repacked variant of W32.Gaobot.SN.
The worm spreads through open network shares and through backdoors that the Mydoom family of worms open.
Steals CD keys from a number of computer games.
Gives the creator backdoor access to the computer via IRC channel:
- Download and execute files
- Scan the network
- List, stop, and start processes
- Control the file system (Delete, create, and list files)
- Launch Denial of Service (DoS) attacks
- Perform port redirection
- Steal system information and email it to the attacker

Attempts to copy itself to computers with weak passwords.
Scans for computers that have been infected by Mydoom variants.
If it finds any, it uses the backdoor installed by Mydoom to copy itself onto the computer as Msgfix.exe.

Manual removal:
Navigate to the keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
and delete the values, if present:
"Configuration Loader"="msnss.exe"
"Configuration Loader"="msgfix.exe"

msnsys.exe
Msnsys.exe is Trojan/Backdoor MSNSYS.
Kill the process msnsys.exe and remove msnsys.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnt32.exe
MSNT32.EXE is Trojan/Backdoor Rbot.
Kill the process MSNT32.EXE and remove MSNT32.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com
Read more:
http://www.superadblocker.com/definition...

msntdugd.exe
Msntdugd.exe is Trojan/Backdoor.
Kill the process msntdugd.exe and remove msntdugd.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnupdate.exe
MSNUPDATE.EXE is Trojan/Backdoor Sdbot.
Kill the process MSNUPDATE.EXE and remove MSNUPDATE.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnupdateit.exe
MSNUPDATEIT.EXE is Trojan/Backdoor.
Kill the process MSNUPDATEIT.EXE and remove MSNUPDATEIT.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msnwebmgr.exe
MSNWEBMGR.EXE is Trojan.MSNWebMgr.Process.
Read more:
http://www.superadblocker.com/definition...
Kill the process MSNWEBMGR.EXE and remove MSNWEBMGR.EXE from Windows startup using RegRun.
www.regrun.com

msnxpexe.exe
MSNXPEXE.EXE is Trojan/Backdoor.
Kill the process MSNXPEXE.EXE and remove MSNXPEXE.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com
Read more:
http://www.sophos.com/virusinfo/analyses...

msocfg.exe
Msocfg.exe is Adult material premium rate dialer.
Kill the process msocfg.exe and remove msocfg.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msofficer.exe
Msofficer.exe is Trojan/Backdoor.
Kill the process msofficer.exe and remove msofficer.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msofficew.exe
Msofficew.exe is Trojan/Backdoor.
Kill the process msofficew.exe and remove msofficew.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msoft17706.exe
MSOFT17706.EXE is Trojan/Backdoor.
Kill the process MSOFT17706.EXE and remove MSOFT17706.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msoftconf.exe
Msoftconf.exe is Trojan/Backdoor.
Kill the process msoftconf.exe and remove msoftconf.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msoftconfs2.exe
Msoftconfs2.exe is Trojan/Backdoor.
Kill the process msoftconfs2.exe and remove msoftconfs2.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msohev.exe
MSOHEV.EXE is W32.Surubat.A@mm.
Related files:
%ProgramFiles%\MICROSOFT OFFICE\OFFICE\MSOHEV.EXE
%SystemDrive%\PETA_INSTALASI_NUKLIR_ISRAEL.EXE
%Windir%\DATABASE.TXT
%Windir%\Restore\scvhost.exe
%Windir%\Restore\systems.exe
%Windir%\Restore\winamps.exe
%Windir%\Restore\winzip.exe
%Windir%\documents.exe
%Windir%\mmsgs\systema.exe
%Windir%\safemode.exe
%Windir%\taskmanager.exe
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process MSOHEV.EXE and remove MSOHEV.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msole.dll
MSOLE.DLL is Trojan/Backdoor.
Kill the file MSOLE.DLL and remove MSOLE.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

msole32.exe
Msole32.exe is Trojan/Backdoor.
Read more information about Msole32.exe:
http://www.sophos.com/virusinfo/analyses...
Kill the process msole32.exe and remove msole32.exe from Windows startup.
Also it adds "winlogon.exe" to the Windows startup.
Remove "winlogon.exe" from Windows startup registry key.

msole41f.dll
MSOLE41F.DLL is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qqf3dd6...
Kill the file MSOLE41F.DLL and remove MSOLE41F.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

msop.exe
Msop.exe is a mass mailing worm W32.Mediakill.A@mm.
Msop.exe tries to terminate antiviral programs installed on a user computer.
Msop.exe attempts to delete media files.
Related files:
%Windir%\SYMRND.LOG
%Windir%\c7052371.log
%Windir%\ORIN7.LOG
%Windir%\1004\syslw.exe
%Windir%\Drivers\winupd.exe
%Windir%\\Help\msop.exe
%Windir%\Cursors\rncmd.exe
%Windir%\ICS\mscs.exe
%Windir%\1004\lsrsa.exe
%Windir%\Drivers\msalph.exe
%Windir%\\Help\msrnd.exe
%Windir%\Cursors\symlg.exe
Adds the value:
"C7" = "[worm file name]"
"load" = "[worm file name]"
"Shell" = "Explorer.exe [worm file name]"
"(Default)" = "[worm file name] "%1" %*"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill msop.exe process and remove msop.exe from Windows startup using RegRun Startup Optimizer.

msosv.exe
MSOSV.EXE is W32.Fubalca.D.
W32.Fubalca.D is a worm that spreads through removable storage devices. It also infects .exe files and downloads potentially malicious files on to the compromised computer.
Related files:
%CommonProgramFiles%\Microsoft Shared\Web Folders\MSOSV.EXE
%CommonProgramFiles%\Microsoft Shared\Web Folders\MSOSVEXT.EXE
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process MSOSV.EXE and remove MSOSV.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msosvert.exe
Msosvert.exe is Trojan/Backdoor.
Kill the process msosvert.exe and remove msosvert.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msp32.exe
Msp32.exe is Trojan/Backdoor.
Kill the process msp32.exe and remove msp32.exe from Windows startup.

mspa32.exe
MSPA32.EXE is Trojan/Backdoor.
Kill the process MSPA32.EXE and remove MSPA32.EXE from Windows startup.

mspbbase.dll
Mspbbase.dll is a Trojan Backdoor.Powerspider.
Mspbbase.dll tries to terminate antiviral programs installed on a user computer.
Mspbbase.dll monitors user Internet activity and private information.
It sends stolen data to a hacker site.
Related files:
%System%\iexplorejj.exe
%System%\IEXPLORE.EXE
%System%\mspbhook.dll
%System%\psinthk.dll
%System%\Mspbbase.dll
Adds the value:
"mssysint"="%System%\Iexplorerjj.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Remove Mspbbase.dll from Windows startup using RegRun Startup Optimizer.

mspbhook.dll
Mspbhook.dll is a Trojan Backdoor.Powerspider.
Mspbhook.dll tries to terminate antiviral programs installed on a user computer.
Mspbhook.dll monitors user Internet activity and private information.
It sends stolen data to a hacker site.
Related files:
%System%\iexplorejj.exe
%System%\IEXPLORE.EXE
%System%\mspbhook.dll
%System%\psinthk.dll
%System%\Mspbbase.dll
Adds the value:
"mssysint"="%System%\Iexplorerjj.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Remove mspbhook.dll from Windows startup using RegRun Startup Optimizer.

mspc32.dll
Mspc32.dll is Trojan/Backdoor Feebs.
Kill the file mspc32.dll and remove mspc32.dll from Windows startup using RegRun Reanimator.
http://www.greatis.com/security/Removal_...

mspcidrv.sys
Mspcidrv.sys is Trojan/Backdoor.
Kill the file mspcidrv.sys and remove mspcidrv.sys from Windows startup using RegRun Reanimator.
http://www.regrun.com

msplock.dll
Msplock.dll is Adware.Navipromo.BYD.
Related files:
msclock.dll
msplock.dll
Read more:
http://www.bitdefender.com/VIRUS-1000170...
Kill the file msplock.dll and remove msplock.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msplus32.exe
Msplus32.exe is a mass-mailing worm W32.Mytob.CQ@mm.
msplus32.exe tries to terminate antiviral programs installed on a user computer.
msplus32.exe opens a back door on TCP ports 6667 and 10087.
msplus32.exe spreads by exploiting the Microsoft Windows Local Security Authority Service Remote Buffer Overflow (Microsoft Security Bulletin MS04-011).
Related files:
%System%\msplus32.exe
C:\funny_pic.scr
C:\see_this!!.scr
C:\my_photo2005.scr
C:\hellmsn.exe
2pac.txt
bingoo.exe
Adds the value:
"MSPLUS" = "msplus32.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill msplus32.exe process and remove msplus32.exe from Windows startup using RegRun Startup Optimizer.

mspm.exe
Ntww.exe is dangerous Trojan/Backdoor.
Ntww.exe changes IE home page to www.v61.com.
Trojan runs a lot of its copies to make the removal hard.
Remove it using RegRun Startup Optmizer to get rid all processes at the same time.
[sdkfr32.exe] C:\WINDOWS\sdkfr32.exe
[mfcyp.exe] C:\WINDOWS\mfcyp.exe
[netrt.exe] C:\WINDOWS\netrt.exe
[ntww.exe] C:\WINDOWS\ntww.exe
[ntdf32.exe] C:\WINDOWS\system32\ntdf32.exe
[ntbw32.exe] C:\WINDOWS\ntbw32.exe
[crbn32.exe] C:\WINDOWS\system32\crbn32.exe
[sdkpn32.exe] C:\WINDOWS\sdkpn32.exe
[d3dl.exe] C:\WINDOWS\d3dl.exe
[mfcod.exe] C:\WINDOWS\mfcod.exe
[apiel.exe] C:\WINDOWS\system32\apiel.exe
[ntxo32.exe] C:\WINDOWS\ntxo32.exe
[atlag.exe] C:\WINDOWS\atlag.exe
[mszo32.exe] C:\WINDOWS\system32\mszo32.exe
[d3qk.exe] C:\WINDOWS\d3qk.exe
[javahd32.exe] C:\WINDOWS\system32\javahd32.exe
[appds32.exe] C:\WINDOWS\appds32.exe
[apipp.exe] C:\WINDOWS\system32\apipp.exe
[mfcnn.exe] C:\WINDOWS\mfcnn.exe
[mfckl.exe] C:\WINDOWS\system32\mfckl.exe
[netlc.exe] C:\WINDOWS\system32\netlc.exe
[atlyi32.exe] C:\WINDOWS\system32\atlyi32.exe
[addtm32.exe] C:\WINDOWS\system32\addtm32.exe
[crad.exe] C:\WINDOWS\crad.exe
[javapt.exe] C:\WINDOWS\system32\javapt.exe
[javauu32.exe] C:\WINDOWS\javauu32.exe
[d3yp.exe] C:\WINDOWS\system32\d3yp.exe
[crwo32.exe] C:\WINDOWS\crwo32.exe
[ieim32.exe] C:\WINDOWS\system32\ieim32.exe
[sysyu.exe] C:\WINDOWS\sysyu.exe
[mfcrr.exe] C:\WINDOWS\system32\mfcrr.exe
[atlfg.exe] C:\WINDOWS\system32\atlfg.exe
[winvr32.exe] C:\WINDOWS\winvr32.exe
[iebp.exe] C:\WINDOWS\system32\iebp.exe
[ipyn.exe] C:\WINDOWS\ipyn.exe
[mspm.exe] C:\WINDOWS\mspm.exe
[javaee.exe] C:\WINDOWS\system32\javaee.exe
[addfm32.exe] C:\WINDOWS\addfm32.exe
[addrs.exe] C:\WINDOWS\addrs.exe
[crfy.exe] C:\WINDOWS\system32\crfy.exe
[crrd.exe] C:\WINDOWS\crrd.exe
[apptr32.exe] C:\WINDOWS\system32\apptr32.exe
[d3wk.exe] C:\WINDOWS\d3wk.exe
[apilk32.exe] C:\WINDOWS\apilk32.exe
[iedm.exe] C:\WINDOWS\system32\iedm.exe
[javagm.exe] C:\WINDOWS\system32\javagm.exe
[ntjw32.exe] C:\WINDOWS\ntjw32.exe
[netdo32.exe] C:\WINDOWS\netdo32.exe
[sysuc32.exe] C:\WINDOWS\system32\sysuc32.exe
[sdknd32.exe] C:\WINDOWS\system32\sdknd32.exe
[addko.exe] C:\WINDOWS\addko.exe
[mfcdh32.exe] C:\WINDOWS\system32\mfcdh32.exe
[sdkij32.exe] C:\WINDOWS\system32\sdkij32.exe
[msen.exe] C:\WINDOWS\system32\msen.exe
[msug.exe] C:\WINDOWS\msug.exe
[crkf32.exe] C:\WINDOWS\crkf32.exe
[winqj.exe] C:\WINDOWS\system32\winqj.exe
[sysgh32.exe] C:\WINDOWS\sysgh32.exe
[d3ud32.exe] C:\WINDOWS\d3ud32.exe
[netnm.exe] C:\WINDOWS\system32\netnm.exe
[apihs32.exe] C:\WINDOWS\system32\apihs32.exe
[addfp.exe] C:\WINDOWS\addfp.exe
[sdkqf32.exe] C:\WINDOWS\sdkqf32.exe
[crpn32.exe] C:\WINDOWS\system32\crpn32.exe
[netae.exe] C:\WINDOWS\netae.exe
[iewb.exe] C:\WINDOWS\system32\iewb.exe
[addkz32.exe] C:\WINDOWS\system32\addkz32.exe
[ipdv.exe] C:\WINDOWS\ipdv.exe
[ntqs32.exe] C:\WINDOWS\system32\ntqs32.exe
[winoo.exe] C:\WINDOWS\system32\winoo.exe
[ipwi.exe] C:\WINDOWS\system32\ipwi.exe
[atlzb.exe] C:\WINDOWS\atlzb.exe
[sysss.exe] C:\WINDOWS\sysss.exe
[appfh32.exe] C:\WINDOWS\appfh32.exe
[sysyh.exe] C:\WINDOWS\sysyh.exe
[msge.exe] C:\WINDOWS\system32\msge.exe

mspmspv.exe
MSPMSPV.exe is Trojan/Backdoor Chum-A Trojan.
It uses the IRC network to allow an attacker to access the infected computer.
Kill the process MSPMSPV.exe and remove MSPMSPV.exe from Windows startup.

mspmtwnl.exe
MSPMTWNL.EXE is Dropper Payload.
Related files:
1 :%WINDIR%\SYSTEM32\MSPMTWNL.EXE.OLDF
2 :%WINDIR%\SYSTEM32\MSPMTWNL.OLD.EXE
Read more:
http://fileinfo.prevx.com/adware/qqe2a13...
Kill the process MSPMTWNL.EXE and remove MSPMTWNL.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mspn32.exe
Mspn32.exe is Trojan/Backdoor.
Kill the process mspn32.exe and remove mspn32.exe from Windows startup.

mspnspsv.exe
Mspnspsv.exe is Trojan/Backdoor.
Kill the process mspnspsv.exe and remove mspnspsv.exe from Windows startup.

mspradme.exe
Mspradme.exe is Email-Worm.Win32.Warezov.et.
Related files:
%System%\mspradme.exe
%System%\e1.dll
%System%\vb5dmspo.dll
Read more:
http://www.viruslist.com/en/viruses/ency...
Kill the process mspradme.exe and remove mspradme.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msprcss32.exe
Msprcss32.exe is Worm.Rbot.YQ.
Kill the process msprcss32.exe and remove msprcss32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msprint32d.exe
We suggest you to remove msprint32d.exe from your computer as soon as possible.
Msprint32d.exe is Trojan/Backdoor.
Kill the process msprint32d.exe and remove msprint32d.exe from Windows startup.

mspunin.exe
MSPUNIN.exe is Trojan/Backdoor.
Kill the process MSPUNIN.exe and remove MSPUNIN.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msq32.exe
Msq32.exe is W32/Rbot-GFP.
Read more:
http://www.sophos.com/security/analyses/...
Kill the process msq32.exe and remove msq32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msqdevl.exe
Msqdevl.exe is Trojan/Backdoor.
Kill the process msqdevl.exe and remove msqdevl.exe from Windows startup.

msqdevl1.exe
Msqdevl1.exe is Trojan/Backdoor.
Kill the process msqdevl1.exe and remove msqdevl1.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msqmx.sys
Msqmx.sys is Troj/QQHelp-Gen.
Read more:
http://www.sophos.com/security/analyses/...
Kill the file msqmx.sys and remove msqmx.sys from Windows startup using RegRun Reanimator.
http://www.regrun.com

msqrsm.exe
MSQRSM.EXE is Trojan/Backdoor.
Related files:
1 :%WINDIR%\SYSTEM32\AZWOEQ.EXE
2 :%WINDIR%\SYSTEM32\CCBWLZ.EXE
3 :%WINDIR%\SYSTEM32\CRLLIN.EXE
4 :%WINDIR%\SYSTEM32\DCKBVQ.EXE
5 :%WINDIR%\SYSTEM32\HQHXMD.EXE
6 :%WINDIR%\SYSTEM32\NYSHVO.EXE
7 :%WINDIR%\SYSTEM32\OLMNGX.EXE
8 :%WINDIR%\SYSTEM32\QDTYNP.EXE
9 :%WINDIR%\SYSTEM32\RILSXX.EXE
10:%WINDIR%\SYSTEM32\SIIWNT.EXE
http://fileinfo.prevx.com/adware/qq958b3...
Kill the process MSQRSM.EXE and remove MSQRSM.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msqsearc.exe
Msqsearc.exe is Trojan/Backdoor.
Kill the process msqsearc.exe and remove msqsearc.exe from Windows startup.
Related files:
%System%\dxvid.exe
%System%\msqsearc.exe

msqw32.dll
Msqw32.dll is Trojan/Backdoor Feebs.
Kill the file msqw32.dll and remove msqw32.dll from Windows startup using RegRun Reanimator.
http://www.greatis.com/security/Removal_...

msr2ca.dll
Msr2ca.dll is W32.Areses.P@mm worm.
Read more:
http://securityresponse.symantec.com/avc...
Kill the file msr2ca.dll and remove msr2ca.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msrdusrc.dll
Msrdusrc.dll is Trojan.Win32.Agent.CNR.
Related files:
%SYSTEM%\ msrdusrc.dll
%SYSTEM%\ msrdusrc.exe
Read more:
http://research.sunbelt-software.com/thr...
Kill the file msrdusrc.dll and remove msrdusrc.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msreg.exe
This is Backdoor.Zinx.
Backdoor.Zinx is a backdoor Trojan Horse that allows a hacker to use your compter as proxy and
steals information. By default the Trojan opens ports 14728 and 24759.
http://securityresponse.symantec.com/avc...
Suggest to kill it by RegRun Startup Optimizer.

msrege.exe
Backdoor.Zinx is a backdoor Trojan Horse that allows a hacker to use your compter as proxy and steals information.
By default it opens ports 14728 and 24759.
The Trojan is launched using an .html file that contains malicious Visual Basic Script (VBS) code.

When the .html file is opened, it does following:
Drops the q.vbs file and executes it. The file does the following:
Drops x.exe and executes it, which terminates security programs.
Downloads q.exe from a predetermined Web site and executes it.

Drops and executes the following files:
%Windir%\5845.exe
%Windir%\msreg.exe
%System%\svchostc.exe
%System%\svchosts.exe

Downloads configuration information from predetermined Web sites, and then runs svchostc.exe and svchosts.exe with these configurations.
Connects to a predetermined SMTP server and sends email message to a certain email address.

The message contains following information:
- Operating system version
- Registered user name
- Organization name
- AIM user accounts
- ICQ accounts
- Trillian accounts
- Ghisler Windows Commander and Total Commander information
- SMTP and POP email accounts and passwords

Automatical remove:
Use RegRun Startup Opimizer.
And navigate to the %System% folder and delete the svchosts.exe and svchostc.exe files.

msreged32.exe
Msreged32.exe is Trojan/Backdoor.
Kill the process msreged32.exe and remove msreged32.exe from Windows startup.

msregscn.exe
FTP server / IRC trojan
Kills the firewall atGuard. The hacker is able to restart or shut the server down through IRC.

msregsv.exe
Msregsv.exe is W32/Xema.A.
Related files:
%SysDir%\c_10810.nls
%SysDir%\c_19460.nls
%SysDir%\inter32.dll
%SysDir%\msregsv.exe
%SysDir%\serlibk.exe
%SysDir%\shell64.dll
%SysDir%\shlmon.exe
%SysDir%\windfire.exe
Read more:
http://www.pspl.com/virus_info/worms/xem...
Kill the process msregsv.exe and remove msregsv.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msresearch.exe
Msresearch.exe is Trojan/Backdoor.
Kill the process msresearch.exe and remove msresearch.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msrexe.exe
Remote Access / Hacking tool / ICQ trojan
Alters Win.ini and System.ini. Generates several .exe-files with randomly choosen names. The only real change in this version is that the server was recompiled.

msrms32.exe
MSRMS32.exe is Trojan/Backdoor RBOT-AKP WORM.
Installed as MS Registry Service.
Kill the file MSRMS32.exe and remove MSRMS32.exe from Windows startup.

msrnd.exe
Msrnd.exe is a mass mailing worm W32.Mediakill.A@mm.
Msrnd.exe tries to terminate antiviral programs installed on a user computer.
Msrnd.exe attempts to delete media files.
Related files:
%Windir%\SYMRND.LOG
%Windir%\c7052371.log
%Windir%\ORIN7.LOG
%Windir%\1004\syslw.exe
%Windir%\Drivers\winupd.exe
%Windir%\\Help\msop.exe
%Windir%\Cursors\rncmd.exe
%Windir%\ICS\mscs.exe
%Windir%\1004\lsrsa.exe
%Windir%\Drivers\msalph.exe
%Windir%\\Help\msrnd.exe
%Windir%\Cursors\symlg.exe
Adds the value:
"C7" = "[worm file name]"
"load" = "[worm file name]"
"Shell" = "Explorer.exe [worm file name]"
"(Default)" = "[worm file name] "%1" %*"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill msrnd.exe process and remove msrnd.exe from Windows startup using RegRun Startup Optimizer.

msrpc.exe
Msrpc.exe is Trojan/Backdoor.
Msrpc.exe is installed as system service MSRPC.
Kill the file msrpc.exe and remove msrpc.exe from Windows startup.

msrtspr1.exe
Msrtspr1.exe is Trojan/Backdoor.
Related files:
agsystem2.exe
WinUpdate.exe
msrtspr1.exe
agony.sys
Kill the process msrtspr1.exe and remove msrtspr1.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msrundll.exe
Msrundll.exe is W32.Vibmaru.
Related files:
%Windir%\System32.exe
%System%\System.exe
%System%\msrundll.exe
W32.Vibmaru is a worm that spreads through network shares.
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process msrundll.exe and remove msrundll.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msrvcp.exe
Msrvcp.exe is Trojan/Backdoor.
Kill the process Msrvcp.exe and remove Msrvcp.exe from Windows startup.
Related files for W32.HLLW.Nautic:
* NTDLL.exe
* Win32.exe
* Explore.exe
* Kernel32.exe
* krnl286.exe
* Dllhost32.exe
* MSTCP.exe
* CRSS.exe
* Winlogon32.exe
* Winsrvc.exe
* Ntoskrn.exe
* Vmm32.exe
* Sysmon.exe
* System32.exe
* Sys.exe
* Win.exe
* Rundil32.exe
* Msrvcp.exe
* Msgmsr.exe
* Mscde32.exe
* Regsvclib.exe
* Reg32.exe
* Registry32.exe
* Service.exe
* Rpcsrvc.exe
More info:
http://securityresponse.symantec.com/avc...

mssave.exe
Mssave.exe is Rootki&Virus, clone of HackerDefender.
Kill the process mssave.exe and remove mssave.exe from Windows startup.
Use UnHackMe to fully remove hidden services and drivers.
www.unhackme.com
Related files:
- mssave.exe
- msinit.exe
- msmail.exe
- mstsk.exe
- lsnr32w.exe
- lsnr32w.dll
- memdrv.sys
- msclean.exe
- msinit.exe
- mslsnre.exe
- pack.exe
- shide32w.exe
- shide32w.ini
- smss.all
- tiinject.exe
- tinject.dll
- tinject.exe
http://webserver1.furman.edu/computing/c...

mssbupx.dll
MSSBUPX.DLL is Trojan/Backdoor.
Kill the file MSSBUPX.DLL and remove MSSBUPX.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

mssc.exe
Mssc.exe is Trojan/Backdoor.
Kill the process mssc.exe and remove mssc.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msscan.exe
Msscan.exe is a mass-mailing worm W32.Kedebe.B@mm.
Msscan.exe tries to terminate antiviral programs installed on a user computer.
Msscan.exe opens a back door on a random TCP port.
Related files:
%System%\winssc32.exe
%System%\mscppmgr.exe
%System%\kerne132.exe
%System%\NAVMON.EXE
%System%\drwmgr32.exe
%System%\DLLH0ST.EXE
%System%\gcasctrl.exe
%System%\msscan.exe
%System%\cuApp.exe
%System%\LSSAS.EXE
%System%\AVmon.exe
%System%\SERVlCES.EXE
%System%\gcasSav32.exe
%System%\LUC0MS~1.EXE
%System%\zlbclient.exe
%System%\mantispam.exe
%System%\NETM0N.EXE
%System%\srvchost.exe
%System%\USRMGRINIT.JFX
Admin Password Cracker.exe
DVD ripper keygen.exe
Messenger 7.0 Installer.exe
Microsoft AntiSpyware Patch.com
Mydoom removal tool.exe
Naked teen-Actions.com
Norton Personal Firewall 2005 Patch.exe
Spyware remover.exe
Win Server 2003 Remote Exploit.cmd
ZoneAlarm Security Suite 2005 Crack.com
Adds the value:
"Windows [worm filename without extension] Monitor" = "[file name of the worm]"
"Run" = "[file name of the worm]"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill msscan.exe process and remove msscan.exe from Windows startup using RegRun Startup Optimizer.

msscds32.dll
Msscds32.dll is Trojan-Downloader.Win32.VB.apq.
Related files:
%SYSTEM%\msnhlp32.dll
msnhlp32.dll
msscds32.dll
Read more:
http://research.sunbelt-software.com/thr...
Kill the file msscds32.dll and remove msscds32.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msscf32.exe
MSSCF32.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq2a285...
Kill the process MSSCF32.EXE and remove MSSCF32.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msscmc43.exe
MSSCMC43.EXE is Malware.MSWinCom32.
Read more:
http://fileinfo.prevx.com/adware/qq09f66...
Kill the process MSSCMC43.EXE and remove MSSCMC43.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msscra.exe
I-Worm.Lentin or W32/Yaha@MM dangerous trojan. Before removing from hard disk you must restore default file extension for exe files.

mssearch.dll
This is CoolWebSearch parasite.
Read more:
http://www.kephyr.com/spywarescanner/lib...
Remove it from startup.

mssecu.exe
MSSECU.EXE is Trojan/Backdoor.
Kill the process MSSECU.EXE and remove MSSECU.EXE from Windows startup.
Related files:
%WinDir%\BDN.COM
%WinDir%\MSSECU.EXE
%WinDir%\WINSYSTEM.EXE
http://vil.nai.com/vil/content/v_99336.h...

mssecure.exe
Mssecure.exe is Trojan/Backdoor Troj/Borobot-B.
Kill the process mssecure.exe and remove mssecure.exe from Windows startup.
http://www.sophos.com/virusinfo/analyses...

mssecures.exe
MSSECURES.EXE is Trojan/Backdoor.
Related files:
1 :%CACHE%\CONTENT.IE5\????????\SWIT[1].EXE
2 :%CACHE%\CONTENT.IE5\????????\SWIT[2].EXE
3 :%PROFILES%\ADMINISTRATOR\SWIT.EXE
4 :%profiles%\andris\SWIT.EXE
5 :%profiles%\asmar\SWIT.EXE
6 :%profiles%\carolina\SWIT.EXE
7 :%profiles%\dalmatinka\loc...s\content.ie5\cdq3stuj\SWIT[1].EXE
8 :%profiles%\dalmatinka\SWIT.EXE
9 :%PROFILES%\HOME\SWIT.EXE
10:%PROFILES%\IAN\SWIT.EXE
Read more:
http://fileinfo.prevx.com/adware/qq81803...
Kill the process MSSECURES.EXE and remove MSSECURES.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msserrv32.exe
MSSERRV32.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qqe9495...
Kill the process MSSERRV32.EXE and remove MSSERRV32.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msserv.exe
I-Worm.Hadra
This is an Internet worm that spreads via e-mails being attached as an EXE file.
The worm copies itself to the Windows directory with the MSSERV.EXE name and registers that file in the Windows registry auto-run keys:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
msservice = %WinDir%\msserv.exe

The worm then stays in the Windows memory as a service, connects to MS Outlook and registers itself as MS Outlook "NewMail" and "ItemSend" events handler.
When a new mail has arrived, the worm looks as if it is its own message from another infected machine, and then deletes it.
When a message is being sent, the worm looks for already attached files, gets the first one, replaces it with its own copy with .EXE extenstion, and then sends it.
If the message has no attachment, the worm attaches itself with eight bytes of a random name and .EXE extenstion.
The worm disables several types of anti-virus protections, as well as immediately closes Registry editors upon their start-up.

Use RegRun Startup Opimizer for removal.

msserv32.exe
Msserv32.exe is Trojan/Backdoor.
read more:
http://fileinfo.prevx.com/adware/qq81975...
Kill the process msserv32.exe and remove msserv32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msservices.exe
Msservices.exe is Trojan/Backdoor.
Kill the process msservices.exe and remove msservices.exe from Windows startup.

msservx.exe
We suggest you to remove MSServx.exe from your computer as soon as possible.
MSServx.exe is Troj/DwnLdr-GYF.
Read more:
http://www.sophos.com/security/analyses/...
Kill the process MSServx.exe and remove MSServx.exe from Windows startup.

msset32.exe
Steals passwords / Keylogger

mssheis.exe
MSSHEIS.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq84136...
Kill the process MSSHEIS.EXE and remove MSSHEIS.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msskbtfm.exe
Remote Access / Downloading trojan

msslut32.exe
Worm.Win32.Sluter virus.
Spreads other local network.
More info at:
http://www.viruslist.com/eng/viruslist.h...
Remove it from startup by Start Control

mssmbios.exe
Mssmbios.exe (Microsoft System Management BIOS Driver) is W32/Tilebot-AI.
Read more:
http://www.sophos.com/virusinfo/analyses...
Kill the process mssmbios.exe and remove mssmbios.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mssmgrd.exe
WORM_SDBOT.JT
This is a memory-resident SDBOT variant.
It enables a remote user to access and compromise a target system.
It can also steal user and system information from a compromised system.
This worm propagates via network shares. It uses a list of user names and passwords to access a target system.
It exploits certain vulnerabilities to propagate across networks.

Manual removal:
Navigate to the key: HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>CurrentVersion>Run
and delete the entry or entries: Microsoft Update=”mssmgrd.exe”

Navigate to the key:
HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>CurrentVersion>RunServices
and delete the entry or entries: Microsoft Update=”mssmgrd.exe”

Navigate to the key:
HKEY_CURRENT_USER>Software>Microsoft>Windows>CurrentVersion>Run
and delete the entry or entries: Microsoft Update=”mssmgrd.exe”

mssmmspgr.exe
Mssmmspgr.exe is a Backdoor W32.Kelvir.AJ.
Mssmmspgr.exe spreads through MSN Messenger.
Related files:
%System%\mssmmspgr.exe
Adds the value:
"MSN MMISSENGER" = "mssmmspgr.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill mssmmspgr.exe process and remove mssmmspgr.exe from Windows startup using RegRun Startup Optimizer.

mssmp.exe
Mssmp.exe is W32/Rbot-FUB.
Read more:
http://www.sophos.com/security/analyses/...
Kill the process mssmp.exe and remove mssmp.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mssmpp.exe
MSSMPP.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq2cb67...
Kill the process MSSMPP.EXE and remove MSSMPP.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mssmppp.exe
MSSMPPP.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq8eaa4...
Kill the process MSSMPPP.EXE and remove MSSMPPP.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mssnger.exe
Mssnger.exe is Trojan/Backdoor.
Kill the process mssnger.exe and remove mssnger.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mssock.exe
Mssock.exe is Trojan/Backdoor.
Kill the process mssock.exe and remove mssock.exe from Windows startup.

mssocks.exe
Mssocks.exe is Trojan.Proxy.AE.
Kill the process mssocks.exe and remove mssocks.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mssql.exe
Mssql.exe is a Trojan Backdoor.Sdbot.
Mssql.exe spreads via Internet Relay Chat (IRC).
Mssql.exe tries to terminate antiviral programs installed on a user computer.
Mssql.exe monitors user Internet activity and private information.
It sends stolen data to a hacker site.
Related files:
%System%\Cnfgldr.exe
%System%\cthelp.exe
%System%\Sysmon16.exe
%System%\Sys3f2.exe
%System%\Syscfg32.exe
%System%\Mssql.exe
%System%\Aim95.exe
%System%\Svchosts.exe
%System%\FB_PNU.EXE
%System%\Cmd32.exe
%System%\Sys32.exe
%System%\Explorer.exe
%System%\IEXPL0RE.EXE
%System%\iexplore.exe
%System%\sock32.exe
%System%\MSTasks.exe
%System%\service.exe
%System%\Regrun.exe
%System%\ipcl32.exe
%System%\syswin32.exe
%System%\CMagesta.exe
%System%\YahooMsgr.exe
%System%\vcvw.exe
%System%\spooler.exe
%System%\MSsrvs32.exe
%System%\svhost.exe
%System%\winupdate32.exe
%System%\quicktimeprom.exe
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill Mssql.exe process and remove Mssql.exe from Windows startup using RegRun Startup Optimizer.

mssrv32.exe
Mssrv32.exe is Trojan/Backdoor.
Kill the process mssrv32.exe and remove mssrv32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mssrvs32.exe
MSsrvs32.exe is a Trojan Backdoor.Sdbot.
MSsrvs32.exe spreads via Internet Relay Chat (IRC).
MSsrvs32.exe tries to terminate antiviral programs installed on a user computer.
MSsrvs32.exe monitors user Internet activity and private information.
It sends stolen data to a hacker site.
Related files:
%System%\Cnfgldr.exe
%System%\cthelp.exe
%System%\Sysmon16.exe
%System%\Sys3f2.exe
%System%\Syscfg32.exe
%System%\Mssql.exe
%System%\Aim95.exe
%System%\Svchosts.exe
%System%\FB_PNU.EXE
%System%\Cmd32.exe
%System%\Sys32.exe
%System%\Explorer.exe
%System%\IEXPL0RE.EXE
%System%\iexplore.exe
%System%\sock32.exe
%System%\MSTasks.exe
%System%\service.exe
%System%\Regrun.exe
%System%\ipcl32.exe
%System%\syswin32.exe
%System%\CMagesta.exe
%System%\YahooMsgr.exe
%System%\vcvw.exe
%System%\spooler.exe
%System%\MSsrvs32.exe
%System%\svhost.exe
%System%\winupdate32.exe
%System%\quicktimeprom.exe
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill MSsrvs32.exe process and remove MSsrvs32.exe from Windows startup using RegRun Startup Optimizer.

msstasks.exe
Msstasks.exe is Trojan/Backdoor Downloader-KP.
Kill the process msstasks.exe and remove msstasks.exe from Windows startup.
http://vil.nai.com/vil/content/v_125991....

msstersv.dll
Msstersv.dll is W32.Stration.IZ@mm.
W32.Stration.IZ@mm is a worm that spreads by emailing itself to other computers. It also drops and downloads other variants in the W32.Stration@mm family of worms.
Related files:
%System%\msstersv.dll - detected as W32.Stration@mm
%System%\secumsje.exe - detected as W32.Stration.IZ@mm
%System%\secumsje.dat - clean dat file
%System%\trafracp.dll - detected as W32.Stration@mm
%System%\shfoxpob.exe - detected as W32.Stration.IZ@mm
%System%\shfoxpob.dat - clean dat file
Read more:
http://www.symantec.com/enterprise/secur...
Kill the file msstersv.dll and remove msstersv.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msstl.exe
Msstl.exe is Trojan/Backdoor HackTool Rootkit.
Msstl.exe is installed as system service "BusinessContinuity".
Kill the file msstl.exe and remove msstl.exe from Windows startup.

mssvmdll.dll
Mssvmdll.dll is Trojan.FakeAlert.
Read more:
http://research.sunbelt-software.com/thr...
Kill the file mssvmdll.dll and remove mssvmdll.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mssw32.exe
Mssw32.exe is Trojan/Backdoor.
Kill the process mssw32.exe and remove mssw32.exe from Windows startup.

msswchx.exe
Msswchx.exe is Adware.Findwhatever.
Related files:
%Windir%\mshepl.exe
%Windir%\mssetup.exe
%Windir%\svchost.exe
%Windir%\ups.exe
%Windir%\xcopy.exe
%Windir%\mdm.exe
%Windir%\dpvsetup.exe
%Windir%\autolfn.exe
%Windir%\csrss.exe
%Windir%\label.exe
%Windir%\mmc.exe
%Windir%\msswchx.exe
%Windir%\mstask.exe
%Windir%\netdde.exe
%Windir%\ntvdm.exe
%Windir%\osk.exe
%Windir%\lasss.exe
%Windir%\spoolsv.exe
%Windir%\sptsupd.exe
%Windir%\subst.exe
%Windir%\w32tm.exe
%Windir%\mshta.exe
%Windir%\dsndup.exe
Read more:
http://www.symantec.com/avcenter/venc/da...
Kill the process msswchx.exe and remove msswchx.exe from Windows startup using RegRun.
www.regrun.com

mssync20.exe
Mssync20.EXE is Troj/LdPinc-LZ.
Read more:
http://www.sophos.com/security/analyses/...
Kill the process mssync20.EXE and remove mssync20.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mssync20.sys
Mssync20.sys is Troj/LdPinc-LZ.
Read more:
http://www.sophos.com/security/analyses/...
Kill the file mssync20.sys and remove mssync20.sys from Windows startup using RegRun Reanimator.
http://www.regrun.com

mssysinfo32.exe
MsSysInfo32.exe is a Trojan/Backdoor Backdoor.Verify.
MsSysInfo32.exe tries to terminate antiviral programs installed on a user computer.
MsSysInfo32.exe opens a back door on TCP port 1906 and 1907.
MsSysInfo32.exe spreads via open network shares.
Related files:
%System%\MsIdle32.exe
%System%\MsIdle32Hook.dll
%System%\MsSysInfo32.exe
C:\MsBootMgr.exe
Adds the value:
"MsIdle32.exe" = "C:\WINNT\system32\MsIdle32.exe"
"MsBootMgr.exe" = "C:\MsBootMgr.exe"
"Shell" = "C:\WINNT\system32\MsIdle32.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill MsSysInfo32.exe process and remove MsSysInfo32.exe from Windows startup using RegRun Startup Optimizer.

mssystem.exe
Mssystem.exe is Trojan/Backdoor Rbot.
Kill the process mssystem.exe and remove mssystem.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com
More info:
http://vic.zonelabs.com/body/CA/virusDet...

mssystem98.exe
FTP trojan

mstask.exe.exe
Mstask.exe.exe is Trojan/Backdoor.
Kill the process mstask.exe.exe and remove mstask.exe.exe from Windows startup.

mstask32.exe
PWSteal.Bamer.A steals passwords when you visit Web sites the belong to certain banks.
One indication of possible infections is the display of the message:
Invalid Operation at 0000:FF15

Creates the following files:
%System%\Azip32.dll: A legitimate .dll file.
%System%\Mfc91.dll: Detected as Keylogger.Trojan.
%System%\Mstask32.exe: Detected as PWSteal.Bamer.A.
%System%\Ole32a.dll: Detected as Keylogger.Trojan.
%System%\Regxp.reg.

Adds the value: "RunOnce"="%system%\mstask32.exe"
to the registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Monitors for any Internet Explorer windows.
It logs the keystrokes to %Temp%\Recado.txt, if it finds any Internet Explorer containing any of the predefined URLs.
Emails the file, Recado.txt, to a server in Brazil, using the password stealer's built-in SMTP engine.

Please, remove it with RegRun Startup Optimizer.

mstask33.exe
Mstask33.exe is Trojan/Backdoor.
Kill the process mstask33.exe and remove mstask33.exe from Windows startup.

mstask64.dll
MSTASK64.DLL is Trojan DELF.
Read more:
http://www.spywaredata.com/spyware/threa...
Kill the file MSTASK64.DLL and remove MSTASK64.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

mstaskm.exe
Mstaskm.exe is CoolWebSearch.
Read more:
http://cwshredder.net/cwshredder/cwschro...
Kill the process mstaskm.exe and remove mstaskm.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mstaskmgr.exe
MSTASKMGR.EXE is Trojan/Backdoor IRC-Demfire.
Kill the process MSTASKMGR.EXE and remove MSTASKMGR.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com
Related files:
FIREDAEMON.EXE
More info:
http://vil.mcafeesecurity.com/vil/conten...

mstaskmon.exe
I-Worm.Lentin dangerous trojan.
1. Restore default file extensions
2. Kill processes like msmdm.exe or similar, mstaskmon.exe.
3. Remove from startup.
4. Delete files.
Also you use free tool:
ftp://ftp.europe.f-secure.com/anti-virus/tools/yahatool.zip

mstasks.exe
MSTasks.exe is a Trojan Backdoor.Sdbot.
MSTasks.exe spreads via Internet Relay Chat (IRC).
MSTasks.exe tries to terminate antiviral programs installed on a user computer.
MSTasks.exe monitors user Internet activity and private information.
It sends stolen data to a hacker site.
Related files:
%System%\Cnfgldr.exe
%System%\cthelp.exe
%System%\Sysmon16.exe
%System%\Sys3f2.exe
%System%\Syscfg32.exe
%System%\Mssql.exe
%System%\Aim95.exe
%System%\Svchosts.exe
%System%\FB_PNU.EXE
%System%\Cmd32.exe
%System%\Sys32.exe
%System%\Explorer.exe
%System%\IEXPL0RE.EXE
%System%\iexplore.exe
%System%\sock32.exe
%System%\MSTasks.exe
%System%\service.exe
%System%\Regrun.exe
%System%\ipcl32.exe
%System%\syswin32.exe
%System%\CMagesta.exe
%System%\YahooMsgr.exe
%System%\vcvw.exe
%System%\spooler.exe
%System%\MSsrvs32.exe
%System%\svhost.exe
%System%\winupdate32.exe
%System%\quicktimeprom.exe
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill MSTasks.exe process and remove MSTasks.exe from Windows startup using RegRun Startup Optimizer.

mstasks1.exe
Mstasks1.exe is Trojan HARNIG.
Realated files:
%WinDir%\system.exe
%WinDir%\mstasks1.exe
%WinDir%\mstasks2.exe
%WinDir%\mstasks3.exe
%WinDir%\mstasks1.exe
%SysDir%\system32.dll
Mstasks1 Backdoor may be used by spyware/adware programs.
Mstasks1 modifies HOSTS file to prevent access to antiviral software.
Removal: kill Mstasks1.exe and all related processes and clear HOSTS files.

mstasks2.exe
Mstasks1.exe is Trojan HARNIG.
Realated files:
%WinDir%\system.exe
%WinDir%\mstasks1.exe
%WinDir%\mstasks2.exe
%WinDir%\mstasks3.exe
%WinDir%\mstasks1.exe
%SysDir%\system32.dll
Mstasks1 Backdoor may be used by spyware/adware programs.
Mstasks1 modifies HOSTS file to prevent access to antiviral software.
Removal: kill Mstasks1.exe and all related processes and clear HOSTS files.

mstasks3.exe
Mstasks1.exe is Trojan HARNIG.
Realated files:
%WinDir%\system.exe
%WinDir%\mstasks1.exe
%WinDir%\mstasks2.exe
%WinDir%\mstasks3.exe
%WinDir%\mstasks1.exe
%SysDir%\system32.dll
Mstasks1 Backdoor may be used by spyware/adware programs.
Mstasks1 modifies HOSTS file to prevent access to antiviral software.
Removal: kill Mstasks1.exe and all related processes and clear HOSTS files.

mstconfig.exe
Name: Shtirlitz
Steals passwords

mstcp.exe
MSTCP.exe is Trojan/Backdoor.
Kill the process MSTCP.exe and remove MSTCP.exe from Windows startup.
Related files for W32.HLLW.Nautic:
* NTDLL.exe
* Win32.exe
* Explore.exe
* Kernel32.exe
* krnl286.exe
* Dllhost32.exe
* MSTCP.exe
* CRSS.exe
* Winlogon32.exe
* Winsrvc.exe
* Ntoskrn.exe
* Vmm32.exe
* Sysmon.exe
* System32.exe
* Sys.exe
* Win.exe
* Rundil32.exe
* Msrvcp.exe
* Msgmsr.exe
* Mscde32.exe
* Regsvclib.exe
* Reg32.exe
* Registry32.exe
* Service.exe
* Rpcsrvc.exe
More info:
http://securityresponse.symantec.com/avc...

mstcpdll.exe
Mstcpdll.exe is Wareout.
Kill the process mstcpdll.exe and remove mstcpdll.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mstcpip.exe
W32/Sdbot-LR is a network worm for the Windows platform, allows a malicious user remote access to an infected computer through the IRC network.
When run the worm copies itself into the Windows system folder with the name mstcpip.exe and continues execution from this file.
Each time W32/Sdbot-LR is run it attempts to connect to a remote IRC server and join a specific channel.
The worm then runs in the background allowing a remote intruder to issue commands which control the computer.

Manual removal:
Navigate to the keys:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
and delete the value: TCPIP Protocol=mstcpip.exe

mstds.exe
Mstds.exe is Trojan.IPtables.
Related files:
%SYSTEM%\mstds.exe
iptables.exe
Read more:
http://research.sunbelt-software.com/thr...
Kill the process mstds.exe and remove mstds.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mstesk.exe
Remote Access / Keylogger / IRC trojan
Doly is hidden in several different programs: in Memory Manager, in an Interactive Game, and in a Downloading program. The trojan also starts using Windows Startup Directory.

msthost.exe
Msthost.exe is Trojan IRCFlood.
Read more:
http://www3.ca.com/securityadvisor/pest/...
Kill the process msthost.exe and remove msthost.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mstint.exe
Mstint.exe is Trojan/Backdoor.
Kill the process mstint.exe and remove mstint.exe from Windows startup.

mstls.exe
MSTLS.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq8e9f6...
Kill the process MSTLS.EXE and remove MSTLS.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mstordb0.exe
MSTORDB0.EXE is W32.Usbalex.
Related files:
C:\RECYCLER\lsass.exe
C:\RECYCLER\MsInfo\MsInfo.exe
%UserProfile%\csrss.exe
%UserProfile%\winlogon.exe
%Temp%\Temp.exe
%Temp%\FolderData.exe
%Windir%\System\Regedit.exe
%UserProfile%\My Documents\My Data.exe
%ProgramFiles%\Microsoft Office\OFFICE11\MSTORDB0.EXE
A:\Data.exe
E:\Private\My Girls.exe
F:\Data Documents\Documents.exe
G:\My Picture\Pictures.exe
H:\Images\Girls.exe
I:\Application.exe
J:\My CV.exe
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process MSTORDB0.EXE and remove MSTORDB0.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mstray.exe
Mstray.exe is Trojan/Backdoor W32.Wullik.B@mm.
Kill the process Mstray.exe and remove Mstray.exe from Windows startup.
http://securityresponse.symantec.com/avc...

mstscc.exe
Mstscc.exe is W32.Rinbot.H.
W32.Rinbot.H is a worm that spreads through network shares and by exploiting certain vulnerabilities. It also opens a back door on the compromised computer.
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process mstscc.exe and remove mstscc.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mstscex.dll
MSTSCEX.DLL is Trojan/Backdoor.
Kill the file MSTSCEX.DLL and remove MSTSCEX.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

mstsdsc.exe
Mstsdsc.exe is Trojan.Riler.G.
Trojan.Riler.G is a Trojan horse that opens a back door on the compromised computer. It also attempts to disable antivirus applications on the compromised computer.
Related files:
%System%\mstsdsc.exe
%System%\tmwsock.dll
%System%\sporder.dll
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process mstsdsc.exe and remove mstsdsc.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mstse.exe
Mstse.exe is Trojan/Backdoor.
Kill the process mstse.exe and remove mstse.exe from Windows startup using Regrun.
www.regrun.com

mstsk.exe
Mstsk.exe is Rootki&Virus, clone of HackerDefender.
Kill the process mstsk.exe and remove mstsk.exe from Windows startup.
Use UnHackMe to fully remove hidden services and drivers.
www.unhackme.com
Related files:
- mssave.exe
- msinit.exe
- msmail.exe
- mstsk.exe
- lsnr32w.exe
- lsnr32w.dll
- memdrv.sys
- msclean.exe
- msinit.exe
- mslsnre.exe
- pack.exe
- shide32w.exe
- shide32w.ini
- smss.all
- tiinject.exe
- tinject.dll
- tinject.exe
http://webserver1.furman.edu/computing/c...

mstsk32.dll
Mstsk32.dll is Trojan.FakeAlert.
Read more:
http://research.sunbelt-software.com/thr...
Kill the file mstsk32.dll and remove mstsk32.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mstskmgr.exe
Mstskmgr.exe is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq9f604...
Kill the process mstskmgr.exe and remove mstskmgr.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mstskmngr32.exe
Mstskmngr32.exe is Trojan/Backdoor IRC-Demfire.
Mstskmngr32.exe is installed as the system service 'Microsoft TaskManager Dll Starter'.
Disable the service and delete mstskmngr32.exe.
More info:
http://vil.nai.com/vil/content/v_100054....

msua.exe
Msua.exe is Trojan/Virus.
Kill the Msua.exe process and remove it from Windows startup.

msudp4.sys
Msudp4.sys is Trojan/Backdoor.
Kill the file msudp4.sys and remove msudp4.sys from Windows startup.
http://www.sophos.com/virusinfo/analyses...

msupd.exe
Msupd.exe is BKDR_DARKIRC.QZ.
Read more:
http://www.trendmicro.com/vinfo/virusenc...
Kill the process msupd.exe and remove msupd.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msupd5.exe
Msupd5.exe is Trojan/Backdoor.
Kill the process msupd5.exe and remove msupd5.exe from Windows startup.

msupdate32.dll
Msupdate32.dll is Trojan/Backdoor.
Kill the file msupdate32.dll and remove msupdate32.dll from Windows startup.

msupdate32.exe
Msupdate32.exe is Trojan/Backdoor.
Kill the process msupdate32.exe and remove msupdate32.exe from Windows startup.

msupdater.exe
Msupdater.exe is Trojan/Backdoor W32/Rbot-XR.
Kill the process msupdater.exe and remove msupdater.exe from Windows startup.
http://www.sophos.com/virusinfo/analyses...

msupdatesys.exe
Msupdatesys.exe is Trojan/Backdoor.
Kill the process msupdatesys.exe and remove msupdatesys.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msupdtm.exe
Msupdtm.exe is a network-aware worm W32.Spybot.PKC .
Msupdtm.exe spreads via open network shares.
Msupdtm.exe opens a back door.
Msupdtm.exe tries to terminate antiviral programs installed on a user computer.
Msupdtm.exe monitors user Internet activity and private information.
It sends stolen data to a hacker site.
Related files:
%System%\msupdtm.exe
Adds the value:
"Microsoft System" = "msupdtm.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill msupdtm.exe process and remove msupdtm.exe from Windows startup using RegRun Startup Optimizer.

msurl32.exe
We suggest you to remove msurl32.exe from your computer as soon as possible.
Msurl32.exe is Troj/Crypter-C.
Related files:
audiodrv.exe
audioinf.exe
bluecol.exe
cmdcon.exe
diskinf.exe
dllreg.exe
enhance32.exe
infdisk.exe
kbddrv32.exe
kbdrvinf.exe
main16.exe
main32.exe
mousedrv.exe
mswavedll.exe
msurl32.exe
netdll32.exe
netdllex.exe
p4mx4.exe
m32info.exe
pwr32ctr.exe
pwr32crtl.exe
sd32info.exe
vid32cntl.exe
vidcntl.exe
Read more:
http://www.sophos.com/virusinfo/analyses...
Kill the process msurl32.exe and remove msurl32.exe from Windows startup.

msusb.dll
Msusb.dll is Trojan Infostealer.Svcstor.
Related files:
%System%\drivers\services.exe
%System%\dllcache\ntpdll.nls
%System%\dllcache\checkntfs.nls
%System%\dllcache\msvbm60.nls
%Windir%\IME\dllhost.exe
%Windir%\System\svchost.exe
%Windir%\Temp\msusb.dll
%Windir%\Temp\upgrade.log
Read more:
http://securityresponse.symantec.com/avc...
Kill the file msusb.dll and remove msusb.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msutil64.exe
Msutil64.exe is TR/Proxy.Ranky.
Kill the process msutil64.exe and remove msutil64.exe from Windows using RegRun.
www.regrun.com

msux32.dll
Msux32.dll is Trojan/Backdoor Feebs.
Kill the file msux32.dll and remove msux32.dll from Windows startup using RegRun Reanimator.
http://www.greatis.com/security/Removal_...

msvbdll.exe
Worm W32.Aimdes.A@mm.
MsVBdll spreads via e0mail and AOL Instant Messenger.
Adds the value:
"MsVBdll" = "%Windir%\MsVBdll.pif"
to the Windows startup registry keys.
Adds the registry entries:
"FirewallDisableNotify" = "1"
"UpdatesDisableNotify" = "1"
"AntiVirusDisableNotify" = "1"
to the following registry keys
HKEY_CURRENT_USER\Software\Microsoft\security center
HKEY_LOCAL_MACHINE\Software\Microsoft\security center
to lower computer security.
MsVBdll adds:
"DisableTaskMgr" = "1"
"DisableRegistryTools" = "1"
to the registry key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Policies\System
to disable access to the Windows Task Manager and registry editing tools.
MsVBdll adds the registry entry:
"NoAutoUpdate" = "1"
to the registry key
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
to disable Windows Update.
MsVBdll deletes the following registry key if present:
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\
CurrentVersion\Run\"Windows" = "Auto Update.exe"
MsVBdll tries to copy itself to:
A:\homework.exe
Kills the system processes:
* svchost.exe
* lsass.exe
It will break network connections.

msvbdll.pif
Worm W32.Aimdes.A@mm.
MsVBdll spreads via e0mail and AOL Instant Messenger.
Adds the value:
"MsVBdll" = "%Windir%\MsVBdll.pif"
to the Windows startup registry keys.
Adds the registry entries:
"FirewallDisableNotify" = "1"
"UpdatesDisableNotify" = "1"
"AntiVirusDisableNotify" = "1"
to the following registry keys
HKEY_CURRENT_USER\Software\Microsoft\security center
HKEY_LOCAL_MACHINE\Software\Microsoft\security center
to lower computer security.
MsVBdll adds:
"DisableTaskMgr" = "1"
"DisableRegistryTools" = "1"
to the registry key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Policies\System
to disable access to the Windows Task Manager and registry editing tools.
MsVBdll adds the registry entry:
"NoAutoUpdate" = "1"
to the registry key
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
to disable Windows Update.
MsVBdll deletes the following registry key if present:
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\
CurrentVersion\Run\"Windows" = "Auto Update.exe"
MsVBdll tries to copy itself to:
A:\homework.exe
Kills the system processes:
* svchost.exe
* lsass.exe
It will break network connections.

msvbvm60.dll.exe
Msvbvm60.dll.exe is W32.Romariory@mm.
W32.Romariory@mm is a mass-mailing worm that spreads through removable devices and network shares. It masquerades as the Super Mario Brothers game.
Related files:
%Windir%\winlogon.exe
%System%\msvbvm60.dll.exe
C:\explorer.exe
%UserProfile%\Application Data\Emma.exe
%UserProfile%\Application Data\Alisa.exe
%UserProfile%\My Documents\Mario Bross.exe
%UserProfile%\My Documents\Solitaire Card.exe
%UserProfile%\My Documents\Minesweeper.exe
%System%\PANGKALP1NANG.EXE
%System%\SMUNSA_PKP_GAME.EXE
C:\Documents and Settings\All Users\Documents\Bola Pantul.exe
C:\Documents and Settings\All Users\Documents\MyHearts.exe
C:\Documents and Settings\All Users\Documents\FreeCard.exe
%SystemDrive%\Game\Minesweeper.exe
%SystemDrive%\Game\My Heart.exe
%SystemDrive%\Game\Bola.exe
%SystemDrive%\Game\Kartu.exe
%SystemDrive%\Game\Legend.exe
%SystemDrive%\Game\Smart.exe
%SystemDrive%\Game\Crazy Mouse.exe
%SystemDrive%\Game\Text Animation.exe
%SystemDrive%\Game\Pink Panther.exe
%SystemDrive%\Game\Start Hide.exe
%SystemDrive%\Game\XP Button.exe
%SystemDrive%\Game\Goncang.exe
%SystemDrive%\Game\Kelap Kelip.exe
%SystemDrive%\Game\Layar Jatuh.exe
%SystemDrive%\Game\Dark Screen.exe
%SystemDrive%\Mario.exe
%UserProfile%\Application Data\Emira.ini
%UserProfile%\Application Data\Aliciana.htt
%Windir%\Tasks\At1.job (a scheduled task to run the worm everyday at a specified time)
%Temp%\inf[RANDOM].tmp (a clean copy of the Super Mario Brothers game)
C:\Program Files\mario.exe (clean copy of the Super Mario Brothers game)
%SystemDrive%\xplorer.exe
%SystemDrive%\desktop.ini
%SystemDrive%\Alicia.htt
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process msvbvm60.dll.exe and remove msvbvm60.dll.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msvbvm60.exe
Worm / Mail trojan / IRC trojan
The fails startas as follows: "F-Secure, Symantec and Microsoft, top leaders in IT technologies have discovered one very dangerous Internet worm called I-Worm. Universe in the wild." The five plug-in modules are encrypyed with RSA and includes: a mail plug-in that steals information from the Internet cache and mails it using a SMTP server; a feedback plug-in that mails the constructor; a payload plug-in that downloads a new wallpaper (Universe.jpg) and give Internet Explorer a new default page; a IRC plug-in altering mIRC; and a RAR plug-in enambling the uses of RAR compressed archives.

msvc.exe
Trojan Backdoor.Ranky
Adds the value:
"Spool" to Windows startup registry keys.
It uses UDP port 10104 to contact its master host.
The Trojan opens a covert proxy on a randomly-chosen TCP port on the infected computer.

msvchost.exe
Trojan.Xombe is a Trojan horse that has two components: a 4,096 byte downloader and a 27,136 byte Trojan.
The downloader component will retrieve the Trojan file from a predetermined Web site.

The download component has been distributed in an unsolicited email, purporting to be a security update for Windows XP, sent by Microsoft.
The email has the following characteristics:
From: windowsupdate@microsoft.com
Subject: Windows XP Service Pack 1 (Express) - Critical Update.
Body: "Window Update has determined that you are running a beta version of Windows XP Service Pack 1 (SP1)." And so on.
Attachment: winxp_sp1.exe

When the winxp_sp1.exe is executed, it will download another Trojan component from a predetermined Web site and execute it.
When this secondary file is executed, it will perform the following actions:
Creates a copy of itself as %System%\msvchost.exe.
This contains functionality to submit system information, download, and execute additional files from the predetermined Web site.

Adds the value:
"msvcc" = "%system%\msvchost.exe"
in the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

Contacts the predetermined Web site a second time and accesses several scripts and submits information.

To prevent this Trojan from running, outgoing HTTP connections to domain gamemaniacs.org can be blocked.
Remove it from startup by RegRun Startup Optimizer.

msvcr32.exe
Msvcr32.exe is Trojan/Backdoor.
Kill the process msvcr32.exe and remove msvcr32.exe from Windows startup.
www.sophos.com/virusinfo/analyses/trojdaemonit.html

msvcr70a.dll
msvcr70a.dll is a Trojan Backdoor.Ripiner.
msvcr70a.dll opens a back door on TCP port 1026.
msvcr70a.dll monitors user Internet activity and private information.
It sends stolen data to a hacker site.
Related files:
%System%\msvcr70a.dll
More info:
http://securityresponse.symantec.com/avc...
Removal:
Remove msvcr70a.dll using RegRun "Scan for Viruses" feature.
http://www.regrun.com

msvcrs.exe
Msvcrs.exe is Trojan/Backdoor MicroService32.
Delete MicroService32 service.
Kill the process msvcrs.exe and remove msvcrs.exe from Windows startup.

msvcrt64.dll
Msvcrt64.dll is Troj/Torpig-BK.
Read more:
http://www.sophos.com/virusinfo/analyses...
Kill the file msvcrt64.dll and remove msvcrt64.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

msveup.exe
MSVEUP.EXE is Trojan/Backdoor W32.AllocUp.
Kill the process MSVEUP.EXE and remove MSVEUP.EXE from Windows startup.
http://www.symantec.com/avcenter/venc/da...

msvirtest.exe
We suggest you to remove MSVIRTEST.EXE from your computer as soon as possible.
MSVIRTEST.EXE is Trojan/Backdoor.
Kill the process MSVIRTEST.EXE and remove MSVIRTEST.EXE from Windows startup.

msvoid.dll
MSVOID.DLL is Trojan Downloader.Dowdec.
Read more:
http://www.symantec.com/enterprise/secur...
Kill the file MSVOID.DLL and remove MSVOID.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

msvp32.dll
Msvp32.dll is Trojan/Backdoor W32.Feebs.A.
Kill the file msvp32.dll and remove msvp32.dll from Windows startup.
http://securityresponse.symantec.com/avc...

msvsrv.exe
Remote Access
Alters Win.ini.

msvxd.exe
This is a virus.
For removal read instructions:
http://www.bullguard.com/virus/92.aspx

msvz32.dll
Msvz32.dll is Trojan/Backdoor Feebs.
Kill the file msvz32.dll and remove msvz32.dll from Windows startup using RegRun Reanimator.
http://www.greatis.com/security/Removal_...

mswavedll.exe
We suggest you to remove mswavedll.exe from your computer as soon as possible.
Mswavedll.exe is Troj/Crypter-C.
Related files:
audiodrv.exe
audioinf.exe
bluecol.exe
cmdcon.exe
diskinf.exe
dllreg.exe
enhance32.exe
infdisk.exe
kbddrv32.exe
kbdrvinf.exe
main16.exe
main32.exe
mousedrv.exe
mswavedll.exe
msurl32.exe
netdll32.exe
netdllex.exe
p4mx4.exe
m32info.exe
pwr32ctr.exe
pwr32crtl.exe
sd32info.exe
vid32cntl.exe
vidcntl.exe
Read more:
http://www.sophos.com/virusinfo/analyses...
Kill the process mswavedll.exe and remove mswavedll.exe from Windows startup.

mswctl32.exe
W32/Rbot-IE is a worm which attempts to spread to remote network shares.
It allows unauthorised remote access to the computer via IRC channels.
It spreads to network shares with weak passwords and via network security exploits as a result of the backdoor Trojan element receiving the appropriate command from a remote user.

Manual removal:
Navigate to the keys:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
and delete the value: Microsoft Windows Control = mswctl32.exe

mswdm.exe
Mswdm.exe is Malware Exploit.
Kill the process mswdm.exe and remove mswdm.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mswiizz32.exe
Mswiizz32.exe is Troj/StraDl-A.
Read more:
http://www.sophos.com/security/analyses/...
Kill the process mswiizz32.exe and remove mswiizz32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mswin32.drv
JammerKillah12 trojan

mswin32.exe
Steals passwords / Trojan dropper / ICQ trojan
Drops the trojan The Thing 1.6.

mswindrvr.exe
Mswindrvr.exe is a worm W32.Kelvir.FK.
Mswindrvr.exe spreads through MSN Messenger.
Related files:
%System%\msmnwin.exe
%System%\msnmesgr.exe
C:\mswindrvr.exe
Adds the value:
"MSN Registry loader" = "msmnwin.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill mswindrvr.exe process and remove mswindrvr.exe from Windows startup using RegRun Startup Optimizer.

mswindtc.exe
Mswindtc.exe is Trojan/Backdoor.
Kill the process mswindtc.exe and remove mswindtc.exe from Windows startup.

mswinexpl.exe
Mswinexpl.exe is Trojan/Backdoor.
Kill the process mswinexpl.exe and remove mswinexpl.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mswinpad.exe
MSWINPAD.EXE is Trojan/Backdoor Spybot.
Kill the process MSWINPAD.EXE and remove MSWINPAD.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mswinrun.exe
Mswinrun.exe is Trojan-PSW.Win32.Coced.220.
Related files:
%System%\mswinrun.exe
%Temp%\Naebi220.exe
Read more:
http://www.viruslist.com/en/viruses/ency...
Kill the process mswinrun.exe and remove mswinrun.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mswins.exe
Mswins.exe is Trojan/Backdoor.
Kill the process mswins.exe and remove mswins.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mswinsck.exe
Mailsending trojan
Can mailbomb another user.

mswinsdl.exe
Mswinsdl.exe is Trojan/Backdoor.
Kill the process mswinsdl.exe and remove mswinsdl.exe from Windows startup.

mswinsrv.exe
Backdoor.Mtron is a backdoor Trojan that records financial activity and sends it to a remote attacker using IRC.
It also gives the attacker the ability to download and run files on the infected computer.

Copies itself as %System%\MSWinSrv.exe
Attempts to delete all .txt files in the %Cookies% folder.

Records activity in windows that are associated with financial institutions.
It searches for open windows that have any of the following strings in the title bar:
Netbenefits; Fidelity; e-gold; Citibank; Citi
Logs keystrokes in these windows, and sends the information to the attacker using IRC.
No physical log of this information is kept on the local system - meaning that no file is created which stores this data.

Manual removal:
Navigate to the key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
and delete the value: "MSWinSrv"="%system%\MSWinSrv.exe"

mswinsrv32.exe
Troj/Mtron-B is a backdoor Trojan designed to steal online banking information.
It monitors keystrokes in Windows that have titles including Netbenefits, Fidelity, e-gold, Citibank or Citi.
The Trojan also deletes cookies and can act as a SOCKS proxy server.
Also, it can be controlled by a remote attacker via IRC.

Manual removal:
Navigate to the key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run
and delete the value: MSWinSrv32 = %Windows system%\MSWinSrv32.exe

mswinssl.exe
MSWINSSL.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq54af6...
Kill the process MSWINSSL.EXE and remove MSWINSSL.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mswinup.exe
MSWINUP.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq2a7f4...
Kill the process MSWINUP.EXE and remove MSWINUP.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mswinup32.dll
Mswinup32.dll is Trojan/Backdoor Appros.
Kill the files mswinup32.dll and remove mswinup32.dll from Windows startup.

mswinupd.exe
Remote Access
May alter System.ini and/or Win.ini. One can choose to let Mosucker randomly decide what autostart method to use. Produces an error message while installing ""Could not find setuplog.bat"" which apparently is used for autostarting. It copies itself to $temp first, as a file named pkg*.exe, ""pkg"" being a fix string. It also copied itself to $windows/unin0686.exe.

mswiz32.exe
Mswiz32.exe is W32.Stration.DE@mm.
Related files:
%Windir%\mswiz32.exe
%Windir%\mswiz32.wax
%Windir%\mswiz32.dat
%Windir%\mswiz32.s
%System%\e1.dll
Read more:
http://www.symantec.com/security_respons...
Kill the process mswiz32.exe and remove mswiz32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mswksai32.exe
Mswksai32.exe is Trojan/Backdoor.
Kill the process mswksai32.exe and remove mswksai32.exe from Windows startup.

mswld32.exe
MSWLD32.exe is Trojan/Backdoor.
MSWLD32.exe is installed as "MS Windows Local Directory".
Kill the process MSWLD32.exe and remove MSWLD32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mswmf32.exe
Mswmf32.exe is Trojan/Backdoor Metafile.
Kill the process mswmf32.exe and remove mswmf32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mswmgs.exe
Mswmgs.exe is Trojan/Backdoor.
Kill the process mswmgs.exe and remove mswmgs.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

msword32.exe
MSWORD32.EXE is Trojan/Backdoor.
Kill the process MSWORD32.EXE and remove MSWORD32.EXE from Windows startup.

msworld.exe
MSWORLD.EXE is Trojan/Backdoor.
Kill the process MSWORLD.EXE and remove MSWORLD.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mswosck.dll
MSWOSCK.DLL is Trojan-PSW.Win32.QQRob.dm.
Related files:
%SysDir%\FSPLVC.exe
%SysDir%\MsHx.dll
Read more:
http://www.megasecurity.org/trojans/b/bl...
Kill the file MSWOSCK.DLL and remove MSWOSCK.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

mswsa32.exe
MSWSA32.exe is Trojan/Backdoor.
MSWSA32.exe is executed as MS Windows System Alert.
Kill the process MSWSA32.exe and remove MSWSA32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mswsck32.dll
MSWSCK32.DLL is WORM CIMUZ CL.
Read more:
http://fileinfo.prevx.com/adware/qq98746...
Kill the file MSWSCK32.DLL and remove MSWSCK32.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

mswservice.exe
MswService.exe is installer Zangocash Adware.
MswService.exe try to download
http://statis.zangocash.com/Support/Medi... (Adware.W32.MediaAccess).
Kill the process MswService.exe and remove MswService.exe from Windows startup using RegRun.
www.regrun.com

mswsgs.exe
Mswsgs.exe is Trojan/Backdoor.
Kill the process mswsgs.exe and remove mswsgs.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mswsus.exe
Mswsus.exe is Trojan/Backdoor.
Kill the process mswsus.exe and remove mswsus.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mswupdate32.exe
Mswupdate32.exe is Trojan/Backdoor.
Kill the process mswupdate32.exe and remove mswupdate32.exe from Windows startup.

msx64.exe
MSX64.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq61924...
Kill the process MSX64.EXE and remove MSX64.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

msxct.exe
Msxct.exe is Adware/Spyware BargainBuddy.
Kill the process msxct.exe and remove msxct.exe from Windows startup.

msxmidi.exe
MSXMIDI.EXE is Trojan/Backdoor Downloader-AFP.
Kill the process MSXMIDI.EXE and remove MSXMIDI.EXE from Windows startup.
http://vil.mcafeesecurity.com/vil/conten...

msxup32.exe
MSxUP32.exe is a Trojan W32/Rbot-ANR.
MSxUP32.exe opens a back door on IRC channel.
MSxUP32.exe spreads via open network shares.
MSxUP32.exe tries to terminate antiviral programs installed on a user computer.
MSxUP32.exe monitors user Internet activity and private information.
It sends stolen data to a hacker siteRelated files:
More info:
http://www.sophos.com/virusinfo/analyses...
Removal:
Kill MSxUP32.exe process and remove MSxUP32.exe from Windows startup using RegRun Startup Optimizer.

msxw32.exe
Msxw32.exe is Trojan/Backdoor.
Kill the process msxw32.exe and remove msxw32.exe from Windows startup.

msxxxx.exe
Worm / Destructive trojan / Network trojan
Alters Win.ini. It is also found in Windows Startup Directory. Msinit spreads itself through open network shares and disables infected computers from the network. Most of the files are packed using different versions of UPX. Dnetc is a legitimite program that may have been installed previously. In this case it´s used illegally.

msys32.exe
I-Worm.Masana is a worm virus spreading via the Internet as an attachment to infected emails.
The worm has bugs in its code; as a result some of its routines don't work.
Copies itself into the Windows system directory with under the msys32.exe name and registers this file in the system registry or in the SYSTEM.INI auto-run keys:
SYSTEM.INI
[boot]
shell=Explorer.exe msys32.exe -dontrunold
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

Also, creates two additional files on disk that manage the exploit: ERunAsX.exe; ERunAsX.dll
Then creates another copy of itself under the name EEXPLORER.EXE name and by using DepPLoit exploit starts this copy with administrator rights.

To send infected messages the worm uses Windows MAPI functions.
To get victim email addresses Masana:
- looks for *.HTM* files and extracts email-like strings
- by using Windows MAPI functions it reads all unread messages from the Inbox and answers them.

This worm also:
- disables the MS Outlook Express 5.0 MAPISendMail warning.
- adds to the system the user named masyanechkaa with Admin privileges (under Windows NT)

Automatic removal: Use RegRun Startup Optimizer to remove it from startup.

msys9.exe
Msys9.exe is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qqe8913...
Kill the process msys9.exe and remove msys9.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mszo32.exe
Ntww.exe is dangerous Trojan/Backdoor.
Ntww.exe changes IE home page to www.v61.com.
Trojan runs a lot of its copies to make the removal hard.
Remove it using RegRun Startup Optmizer to get rid all processes at the same time.
[sdkfr32.exe] C:\WINDOWS\sdkfr32.exe
[mfcyp.exe] C:\WINDOWS\mfcyp.exe
[netrt.exe] C:\WINDOWS\netrt.exe
[ntww.exe] C:\WINDOWS\ntww.exe
[ntdf32.exe] C:\WINDOWS\system32\ntdf32.exe
[ntbw32.exe] C:\WINDOWS\ntbw32.exe
[crbn32.exe] C:\WINDOWS\system32\crbn32.exe
[sdkpn32.exe] C:\WINDOWS\sdkpn32.exe
[d3dl.exe] C:\WINDOWS\d3dl.exe
[mfcod.exe] C:\WINDOWS\mfcod.exe
[apiel.exe] C:\WINDOWS\system32\apiel.exe
[ntxo32.exe] C:\WINDOWS\ntxo32.exe
[atlag.exe] C:\WINDOWS\atlag.exe
[mszo32.exe] C:\WINDOWS\system32\mszo32.exe
[d3qk.exe] C:\WINDOWS\d3qk.exe
[javahd32.exe] C:\WINDOWS\system32\javahd32.exe
[appds32.exe] C:\WINDOWS\appds32.exe
[apipp.exe] C:\WINDOWS\system32\apipp.exe
[mfcnn.exe] C:\WINDOWS\mfcnn.exe
[mfckl.exe] C:\WINDOWS\system32\mfckl.exe
[netlc.exe] C:\WINDOWS\system32\netlc.exe
[atlyi32.exe] C:\WINDOWS\system32\atlyi32.exe
[addtm32.exe] C:\WINDOWS\system32\addtm32.exe
[crad.exe] C:\WINDOWS\crad.exe
[javapt.exe] C:\WINDOWS\system32\javapt.exe
[javauu32.exe] C:\WINDOWS\javauu32.exe
[d3yp.exe] C:\WINDOWS\system32\d3yp.exe
[crwo32.exe] C:\WINDOWS\crwo32.exe
[ieim32.exe] C:\WINDOWS\system32\ieim32.exe
[sysyu.exe] C:\WINDOWS\sysyu.exe
[mfcrr.exe] C:\WINDOWS\system32\mfcrr.exe
[atlfg.exe] C:\WINDOWS\system32\atlfg.exe
[winvr32.exe] C:\WINDOWS\winvr32.exe
[iebp.exe] C:\WINDOWS\system32\iebp.exe
[ipyn.exe] C:\WINDOWS\ipyn.exe
[mspm.exe] C:\WINDOWS\mspm.exe
[javaee.exe] C:\WINDOWS\system32\javaee.exe
[addfm32.exe] C:\WINDOWS\addfm32.exe
[addrs.exe] C:\WINDOWS\addrs.exe
[crfy.exe] C:\WINDOWS\system32\crfy.exe
[crrd.exe] C:\WINDOWS\crrd.exe
[apptr32.exe] C:\WINDOWS\system32\apptr32.exe
[d3wk.exe] C:\WINDOWS\d3wk.exe
[apilk32.exe] C:\WINDOWS\apilk32.exe
[iedm.exe] C:\WINDOWS\system32\iedm.exe
[javagm.exe] C:\WINDOWS\system32\javagm.exe
[ntjw32.exe] C:\WINDOWS\ntjw32.exe
[netdo32.exe] C:\WINDOWS\netdo32.exe
[sysuc32.exe] C:\WINDOWS\system32\sysuc32.exe
[sdknd32.exe] C:\WINDOWS\system32\sdknd32.exe
[addko.exe] C:\WINDOWS\addko.exe
[mfcdh32.exe] C:\WINDOWS\system32\mfcdh32.exe
[sdkij32.exe] C:\WINDOWS\system32\sdkij32.exe
[msen.exe] C:\WINDOWS\system32\msen.exe
[msug.exe] C:\WINDOWS\msug.exe
[crkf32.exe] C:\WINDOWS\crkf32.exe
[winqj.exe] C:\WINDOWS\system32\winqj.exe
[sysgh32.exe] C:\WINDOWS\sysgh32.exe
[d3ud32.exe] C:\WINDOWS\d3ud32.exe
[netnm.exe] C:\WINDOWS\system32\netnm.exe
[apihs32.exe] C:\WINDOWS\system32\apihs32.exe
[addfp.exe] C:\WINDOWS\addfp.exe
[sdkqf32.exe] C:\WINDOWS\sdkqf32.exe
[crpn32.exe] C:\WINDOWS\system32\crpn32.exe
[netae.exe] C:\WINDOWS\netae.exe
[iewb.exe] C:\WINDOWS\system32\iewb.exe
[addkz32.exe] C:\WINDOWS\system32\addkz32.exe
[ipdv.exe] C:\WINDOWS\ipdv.exe
[ntqs32.exe] C:\WINDOWS\system32\ntqs32.exe
[winoo.exe] C:\WINDOWS\system32\winoo.exe
[ipwi.exe] C:\WINDOWS\system32\ipwi.exe
[atlzb.exe] C:\WINDOWS\atlzb.exe
[sysss.exe] C:\WINDOWS\sysss.exe
[appfh32.exe] C:\WINDOWS\appfh32.exe
[sysyh.exe] C:\WINDOWS\sysyh.exe
[msge.exe] C:\WINDOWS\system32\msge.exe

mte3ndi6odoxng.exe
MTE3NDI6ODOXNG.EXE is Trojan.CmdService.Process.
Kill the process MTE3NDI6ODOXNG.EXE and remove MTE3NDI6ODOXNG.EXE from Windows using RegRun.
www.regrun.com

mte3ndi6odoxngmte3ndi6odoxng.exe
MTE3NDI6ODOXNGMTE3NDI6ODOXNG.EXE is Trojan Downloader.
Read more:
http://fileinfo.prevx.com/adware/qq6b555...
Kill the process MTE3NDI6ODOXNGMTE3NDI6ODOXNG.EXE and remove MTE3NDI6ODOXNGMTE3NDI6ODOXNG.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mtmtask.dl
SubSeven 1.9 trojan
Copies to : c:\windows\system\mtmtask.dl
Default: System.ini
Shell=explorer.exe mtmtask.dl
Uses port 1243

mtsdsc.exe
MTSDSC.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq1f958...
Kill the process MTSDSC.EXE and remove MTSDSC.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mtsinfoidfile.dll
MTSINFOIDFILE.DLL is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qqd3b25...
Kill the file MTSINFOIDFILE.DLL and remove MTSINFOIDFILE.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

mtsparamcfgfile.dll
MTSPARAMCFGFILE.DLL is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq9b105...
Kill the file MTSPARAMCFGFILE.DLL and remove MTSPARAMCFGFILE.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

mtx_.exe
Remote Access / Worm / Virus / Trojan dropper / Mail trojan / Downloading trojan
It tries to destroy up to eight different antivirus programs and makes it impossible to mail the AV company or visit its Web-site. Wsock32.dll is patched by the trojan. Whenever the user sends a mail, the trojan will mail another one to the same recipient with an attachment only. May be updated from the Internet.

mulbin32[1].exe
Mulbin32[1].exe is Trojan.Win32.Dialer.oy.
Related files:
%LOCAL_SETTINGS%\ temp\ win15.tmp.exe
%LOCAL_SETTINGS%\ temp\ win38.tmp.exe
mulbin32[1].exe
win7.tmp.exe
Read more:
http://research.sunbelt-software.com/thr...
Kill the process mulbin32[1].exe and remove mulbin32[1].exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mumu3.exe
MUMU3.EXE is Trojan.SystemPoser.
Read more:
http://fileinfo.prevx.com/adware/qq00f15...
Kill the process MUMU3.EXE and remove MUMU3.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

muniu.exe
Muniu.exe is W32.Niumu.
W32.Niumu is a worm that spreads through network shares and infects .exe and .scr files. The threat also steals passwords typed into Internet Explorer.
Related files:
C:\muniu.exe
%Windir%\rundll32.exe
%Windir%\Downloaded Program Files\muniu.exe
%Windir%\Downloaded Program Files\muniu.dll
%Windir%\Downloaded Program Files\Thumbs.db
%Windir%\Downloaded Program Files\tnumbs.db
[DRIVE LETTER]:\Thunbs.db
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process muniu.exe and remove muniu.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

music.exe
Worm / Downloading trojan
Hidden in a simple music and graphics program. Updates itself from the Web using plug-ins. It checks Windows Address Book and sends itself to every mail address found.

musirc4.72.exe
W32.Randex.AI is a network-aware worm that will attempt to connect to a predetermined IRC server to receive instructions from an attacker.
Spreads itself to other systems on the same network.
Allows unauthorized remote execution of commands on an infected computer.

Adds the value: "MusIRC (irc.music.com) client"="musirc4.72.exe"
to the registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices

Attempts to authenticate itself to randomly generated IP addresses.
Copies itself to the following remote locations when a successful connection is made:
\ADMIN$\system32\musirc4.72.exe
\C$\WINNT\system32\musirc4.72.exe

Schedules itself to execute remotely created files.
Opens a connection to a specified Web site.
Connects to a specific IRC channel on a specific IRC server to receive remote instructions, such as:
- ntscan: Performs the scan of a specific computer with weak administrator passwords and copies itself to these computers.
- sysinfo: Retrieves the infected computer's information, such as CPU speed, memory, and so on.

Automatic removal: Use RegRun Startup Optimizer to remove it from startup.

mutihaka.exe
Remote Access
It kills more than 20 antivirus programs in memory and also four dedicated antitrojan softwares. The trojan can redirect ports and connect to several servers at the same time. It can also be used as a port scanner. Cafeini can also take another program´s place in the Registry. The server will automatically be updated using HTTP.

mutou.exe.exe
MUTOU.EXE.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/fileinfo.asp?P...
Kill the process MUTOU.EXE.EXE and remove MUTOU.EXE.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mvdmodw.exe
Mvdmodw.exe is PacerD adware.
Read more:
http://www3.ca.com/securityadvisor/pest/...
Kill the process mvdmodw.exe and remove mvdmodw.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mvr2l99o1.dll
MVR2L99O1.DLL is Trojan/Backdoor.
Kill the file MVR2L99O1.DLL and remove MVR2L99O1.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

mvsr32.exe
Mvsr32.exe is Trojan/Backdoor.
Kill the process mvsr32.exe and remove mvsr32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mw_4s_stub.exe
Mw_4s_stub.exe is Adware People on People.
Kill the process mw_4s_stub.exe and remove mw_4s_stub.exe from Windows startup.

mw_setup.exe
Mw_setup.exe is Trojan/Backdoor.
Kill the process mw_setup.exe and remove mw_setup.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mwinkmdt.exe
MWINKMDT.EXE is Trojan/Backdoor.
Kill the process MWINKMDT.EXE and remove MWINKMDT.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mwinlqez.exe
Mwinlqez.exe is Trojan QezRez.
Read more:
http://fileinfo.prevx.com/adware/qqc2422...
Kill the process mwinlqez.exe and remove mwinlqez.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mwinnmdt.exe
MWINNMDT.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq00821...
Kill the process MWINNMDT.EXE and remove MWINNMDT.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mwinpodt.exe
MWINPODT.EXE is Trojan/Backdoor.
Kill the process MWINPODT.EXE and remove MWINPODT.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mwinqoeg.exe
MWINQOEG.EXE is Malware.
Read more:
http://fileinfo.prevx.com/adware/qq3fb26...
Kill the process MWINQOEG.EXE and remove MWINQOEG.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mwintmdt.exe
MWINTMDT.EXE is Trojan/Backdoor.
Kill the process MWINTMDT.EXE and remove MWINTMDT.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mwiole32.dll
Mwiole32.dll is Spyware.Look2Me.
Read more:
http://www.symantec.com/security_respons...
Kill the file mwiole32.dll and remove mwiole32.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mwlauncher.exe
We suggest you to remove MWLauncher.exe from your computer as soon as possible.
MWLauncher.exe is a part of MalWarrior software.
MalWarrior is a misleading application that may give exaggerated reports of threats on the computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported threats.
Related files:
%ProgramFiles%\MalWarrior 2007\MWLauncher.exe
%ProgramFiles%\MalWarrior 2007\unins000.dat
%ProgramFiles%\MalWarrior 2007\unins000.exe
%UserProfile%\Application Data\Adsl Software Limited\MalWarrior 2007\BASE\vbase.dat
%UserProfile%\Application Data\Adsl Software Limited\MalWarrior 2007\MalWarrior.exe
%UserProfile%\Application Data\Adsl Software Limited\MalWarrior 2007\program.ini
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\MalWarrior 2007\BASE\vbase.dat
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\MalWarrior 2007\MalWarrior.exe
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\MalWarrior 2007\program.id
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\MalWarrior 2007\program.ini
C:\Documents and Settings\All Users\Desktop\MalWarrior 2007.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\MalWarrior 2007\MalWarrior 2007.lnk
Read more:
http://www.symantec.com/business/securit...
Kill the process MWLauncher.exe and remove MWLauncher.exe from Windows startup.

mws.exe
Mws.exe is Trojan/Backdoor.
Kill the process mws.exe and remove mws.exe from Windows startup.
http://www3.ca.com/securityadvisor/pest/...

mwsoeman.exe
Mwsoeman.exe is MyWebSearch (or MySearch) Toolbar.
Read more:
http://www.free-web-browsers.com/support...
Kill the process mwsoeman.exe and remove mwsoeman.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mwsoemon.exe
MWSOEMON.EXE is MyWebSearch Spyware.
Read more:
http://www.mac-net.com/445088.page
Kill the process MWSOEMON.EXE and remove MWSOEMON.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mwsrvacc.exe
MWSRVACC.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq15fa5...
Kill the process MWSRVACC.EXE and remove MWSRVACC.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mwsvm.exe
Mwsvm.exe is AdRotator/IconAds Adware.
Related files:
%local_settings%\ temp\ 11-9df8e247b1ab6e4ea9303b15294a3428.exe
%local_settings%\ temp\ s11k..exe
%PROGRAM_FILES%\ COMMON FILES\ SLMSS\ slmss.exe
%SYSTEM%\ adrot-uninst.exe
%SYSTEM%\ adrotate.dll
%SYSTEM%\ adrotate1.dll
%system%\ adspipe.dll
%SYSTEM%\ brrotate.dll
%system%\ cpmrotate.dll
%SYSTEM%\ drivers\ csrss.exe
%system%\ mwsvm.exe
%system%\ mwsvm.ocx
%SYSTEM%\ nodeipproc.dll
%SYSTEM%\ uninsticn.exe
Read more:
http://research.sunbelt-software.com/thr...
Kill the process mwsvm.exe and remove mwsvm.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mxcrtp.dll
Mxcrtp.dll is Trojan.FakeAlert.
Read more:
http://research.sunbelt-software.com/thr...
Kill the file mxcrtp.dll and remove mxcrtp.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mxd.exe
MXD.EXE is Covert Sys Exec malware.
Directory: %WinDir%
Read more:
http://fileinfo.prevx.com/adware/qq41402...
Kill the process MXD.EXE and remove MXD.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mxdispdr.sys
Mxdispdr.sys is Trojan.Retvorp.
Rekated files:
%System%\msplrct.dll
Read more:
http://www.symantec.com/enterprise/secur...
Kill the file mxdispdr.sys and remove mxdispdr.sys from Windows startup using RegRun Reanimator.
http://www.regrun.com

mxevwtwv.exe
MXEVWTWV.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qqc96f8...
Kill the process MXEVWTWV.EXE and remove MXEVWTWV.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

mxpsp.exe
Mxpsp.exe is Trojan/Backdoor WIN32.RBOT.
Kill the process mxpsp.exe and remove mxpsp.exe from Windows startup.

mxthk16.exe
Mxthk16.exe is a part of IC Spyware Scanner.
IC Spyware Scanner is a suspect anti-spyware application that may compromise user system stability, and produce ridiculous false positives.
Read more:
http://www.fbmsoftware.com/spyware-net/p...
Kill the process mxthk16.exe and remove mxthk16.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

my documents.exe
My documents.exe is Trojan/Backdoor.
Kill the process my documents.exe and remove my documents.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

my life.scr
I-Worm.MyLife.a
This is the worm virus currently spreading through the Internet in the form of an attachment to infected e-mails.
The worm is attached to infected e-mail messages within the attachment named "My Life.scr".
The worm uses Microsoft Outlook to send out infected e-mail messages to all addresses found in the Microsoft Outlook Address Book.
When the worm is launched for the first time it shows a window with a picture.
The worm checks the current date, if the current minute value is more than 45 it deletes files with extensions .SYS and .COM in the root directory of disk C:,
files with extensions .COM, .SYS, .INI, .EXE in the Windows directory and files with extensions .SYS, .VXD, .EXE, .DLL in the Windows System directory.

Manual removal:
Navigate to the keys:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
and delete the value: stmgr=%SYSTEM%\My Life.scr

my pics.exe
My pics.exe is Trojan/Backdoor.
Kill the process my pics.exe and remove my pics.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

my sexy.exe
My SeXy.exe is W32/SillyFDC-D.
Read more:
http://www.precisesecurity.com/files-pro...
Kill the process My SeXy.exe and remove My SeXy.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

my_love.exe
My_Love.exe is Trojan/Backdoor.
Kill the process My_Love.exe and remove My_Love.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mybabypic.exe
I-Worm.Myba
This is an Internet-worm spreading via e-mail, sending infected messages from infected computers.
While spreading, the worm uses MS Outlook and sends itself to all addresses that are stored in the MS Outlook Address Book.

The worm also installs itself into the system.
It creates its copies in the Windows system directory with the following names:
WINKERNEL32.EXE, MYBABYPIC.EXE, WIN32DLL.EXE, CMD.EXE, COMMAND.EXE
and registers in the Windows auto-run section in the system registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\mybabypic = %WinSystem%\mybabypic.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\WINKernel32 = %WinSystem%\WINKernel32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices = %WinSystem%\Win32DLL.exe

Depending on the system date and time, the worm:
- switches on/off NumLock, CapLock and ScrollLock keys
- sends to keyboard buffer different messages.
The worm also corrupts and/or affects other files.
It scans subdirectory trees on all available drives, lists all files there and depending on filename extension, performs one of the deffirent actions.

Use RegRun Startup Optimizer to automatically remove it from startup.

mydocuments.exe
Mydocuments.exe is Trojan/Backdoor.
The virus changes your files to .exe format (ex: if your file was MyDocuments.doc it changes to MyDocuments.exe, no not MyDocuments.doc.exe just .exe.
Kill the process mydocuments.exe and remove mydocuments.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

myfoot.exe
MYFOOT.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq01b57...
Kill the process MYFOOT.EXE and remove MYFOOT.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

myftp.exe
Myftp.exe is SDBOT.worm.
Read more:
http://vil.nai.com/vil/content/v_100454....
Kill the process myftp.exe and remove myftp.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

myhost.exe
Myhost.exe is W32/Tilebot-AT.
Read more:
http://www.sophos.com/virusinfo/analyses...
Kill the process myhost.exe and remove myhost.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mypic5.exe
Trojan dropper
Dropts the trojan NetBus.

myqhasny.exe
MYQHASNY.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/adware/qq864b5...
Kill the process MYQHASNY.EXE and remove MYQHASNY.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

myromeo.exe
Worm / Mail trojan / Destructive trojan
Always arrives with two attachements. Tries to send mails to all addresses in Outlook through one of several ISPs in Poland. Some of the code is packed with UPX. When the mail is viewed the attachements are automatically saved and a script in the mail is run to view the .chm file, which in turn executes the attached .exe file. En second version of Blebla overwrites datafiles with 21 different file extensions. This version uses 18 pre-defined SMTP servers to spread itself.

mysexy.exe
Mysexy.exe is W32/SillyFDC-AL.
Related files:
%Windows%\default__.pif
%System%\BrO_AcT.exe
%System%\MySexy.exe
%System%\REPCLIENT\svchost.exe
%System%\REPCLIENT\winlogon.exe
%System%\msconfig.com
%System%\regedit.com
Read more:
http://www.sophos.com/security/analyses/...
Kill the process mysexy.exe and remove mysexy.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mysvcc.exe
Mysvcc.exe is W32.Spybot.ANSX.
Read more:
http://www.symantec.com/enterprise/secur...
Kill the file mysvcc.exe and remove mysvcc.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mytoolbar.dll
MYTOOLBAR.DLL is Downloader Drev A.
Read more:
http://fileinfo.prevx.com/adware/qq33462...
Kill the file MYTOOLBAR.DLL and remove MYTOOLBAR.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

myurlff.exe
Myurlff.exe is Network1.Popups Adware.
Related files:
newpop61.exe
newpop447.exe
a64sddd.exe
seeve.exe
myurlsagain.exe
myurlff.exe
mmwork.exe
hisistheurls.exe
sixtypopsix.exe
newpop63.exe
newpop62.exe
Read more:
http://www.securemost.com/articles/rm_ne...
Kill the process myurlff.exe and remove myurlff.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

myurlsagain.exe
Myurlsagain.exe is Network1.Popups Adware.
Related files:
newpop61.exe
newpop447.exe
a64sddd.exe
seeve.exe
myurlsagain.exe
myurlff.exe
mmwork.exe
hisistheurls.exe
sixtypopsix.exe
newpop63.exe
newpop62.exe
Read more:
http://www.securemost.com/articles/rm_ne...
Kill the process myurlsagain.exe and remove myurlsagain.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mywow.dll
Mywow.dll is Trojan/Backdoor.
Kill the file mywow.dll and remove mywow.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mzkernel32.dll
Mzkernel32.dll is Trojan/Backdoor.
Kill the file mzkernel32.dll and remove mzkernel32.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

mzu_drv.sys
MZU_DRV.sys is Trojan.Jupillites.B.
Related files:
%System%\_mzu_stonedrv2.exe
%System%\MZU_DRV.sys
%System%\TheMatrixHasYou.exe
%System%\mini2tone.ini
Read more:
http://www.symantec.com/enterprise/secur...
Kill the file MZU_DRV.sys and remove MZU_DRV.sys from Windows startup using RegRun Reanimator.
http://www.regrun.com

mzupdate.exe
Mzupdate.exe is Worm/Mydoom.CJ.
Read more:
http://www.avira.com/en/threats/section/...
Kill the process mzupdate.exe and remove mzupdate.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

mzz.exe
Mzz.exe is Trojan.IPtables.
Related files:
%SYSTEM%\ mstds.exe
306062.exe
iptables.exe
malware.exe
mstds.exe
mswsck32.dll
mzz.exe
photoalbum.exe
Read more:
http://research.sunbelt-software.com/thr...
Kill the process mzz.exe and remove mzz.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com


Quick Links
What's new?
RSS Feed
Add to AppDatabase
Ask Experts
Join forum
Links

Articles
Virus or not? SPTD####.sys
What is mc21.tmp, mc22.tmp, mc23.tmp?

Select
Necessary
Useless
At your option
Dangerous

Copyright © 1998-2010 Greatis Software