Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 795 autoruns. Autorun 301 to 400:

StatusAutorun nameCommandDescription
YInCDInCD.exeInCD packet writing utility which allows the user to format CDs/DVDs so that they can be used by simply dragging and dropping files to the disk or by saving to disk from within other applications. Included with Nero digital media suites (CD/DVD burning, authoring, etc) until version 9 (optional install for versions 7 thru 9) and now available as a separate download. If you prefer not to use InCD (due to the obvious alternatives such as USB flash drives) you can disable it
NIncMailIncMail.exe"IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality"
Xincognitoincognito.exeAdded by an unidentified WORM or TROJAN! See here
NInControl Desktop ManagerDMHKEY.EXEFor Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start -> Programs
XIncredible KeyloggerAdvKeylog.exeIncredibleKeylogger spyware
NIncredimailincredimail.exe"IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality"
NIncredimailIncMail.exe"IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality"
XIndex Servicedllhost32.exeAdded by the AGOBOT.CH WORM!
UIndex WasherWashIdx.exeWindow Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
UIndexCleanerIdxClnR.exeUtility that cleans the index.dat file when the system restarts. Index.dat files keep a track of pages, images, cookies or sounds from web sites you have visited, even if these files are deleted from your system. Recommended at "Users choice" status because it depends how the user cleans their internet history. Installed as part of the internet security suite packages sourced by Radialpoint for ISP customers such as Virgin Media, AT&T, Bell Canada, TELUS Corporation and Verizon Online
UIndexCleanerIndexCleanerR.exeUtility that cleans the index.dat file when the system restarts. Index.dat files keep a track of pages, images, cookies or sounds from web sites you have visited, even if these files are deleted from your system. Recommended at "Users choice" status because it depends how the user cleans their internet history. Installed as part of the internet security suite packages sourced by Radialpoint for ISP customers such as Virgin Media, AT&T, Bell Canada, TELUS Corporation and Verizon Online
?IndexerIndexer.exePart of the Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents". What does it do and is it required?
XIndexindicatorIndexindicator.exeAdded by the LAZAR TROJAN!
NIndexSearchIndexSearch.exePart of Nuance (ScanSoft) PaperPort - "scan, organize, find and share all of your documents including paper, PDF, application files and photographs". Creates an index of files associated with PaperPort for easy searching
UIndexTrayIndexTray.exePart of Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents"
UIndicatorUtyIndicatorUty.exeFujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook, eg, when you press the hotkey for muting the sound, a loudspeaker icon with a cross on it is displayed
UIndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}NMIndexStoreSvr.exeIndexing and storage service for Nero Scout which is "a database program which indexes and catalogs all media files on your computer and makes the database available to all programs in the Nero product package." Included in version 8 of the Nero digital media suites (CD/DVD burning, authoring, etc). Integrated into a number of Nero applications and is of particular significance for the Nero Home media center - for more information see the link
Xinesvchosts.exeAdded by the RBOT.BNL WORM!
XINETinetsync.exeMeplex adware
Xinetsvhost.exeAdded by the SDBOT-M BACKDOOR!
XInet DataBaseInetdbs.exeAdded by the QEDS WORM!
XInet Deliveryinetdl.exeInet Delivery adware
XInet Deliveryinetdl_2.exeInet Delivery adware
UInet_Perfsvcwinra.exeSystem Surveillance Pro surveillance software. Uninstall this software unless you put it there yourself
XInetapiNetapi.exeAdded by the NETDEVIL.14 BACKDOOR!
XInetChkms[random value].exeAdded by the AGENT-IRL TROJAN!
Uinetcntrlinetcntrl.exeBsafe Online - internet filter
?InetConfinetconf.exe??
UInetdINETD32.EXEWindows Inet Daemon from Hummingbird Communications. "Hummingbird Inetd has the advanced ability to conserve PC resources by listening for connection requests and launching server daemons". Provides PCs with the full functionality of a UNIX workstation
Uinetinfo.exeinetinfo.exeExecutable used by MS Internet Information Server (IIS). If it's running, then so is IIS. Useful in knowing whether you require the patch for the Code Red worm. Comes with PWS (Personal Web Server) or NT4 and handles ASP-, PHP code (+ more)
Xinetinfomon managerinetinfomon.exeAdded by the DONBOMB.A TROJAN!
Xinetmgrinetmgr.exeActual Names (AdvSearch) Internet Keywords parasite
XInetMSNmsnet.exeAdded by a variant of the SDBOT TROJAN!
Xinetruninetrun.exeAdded by the AGENT.CE BACKDOOR!
Xinetservinetserv.exeAdded by the AGENT-OWJ TROJAN!
XInetServiceswsock32.exeAdded by the WOCK32-A TROJAN!
Xinetsys[path to trojan]Added by the DELF-NV TROJAN!
Xinfamous.exewmplayer.exeAdded by unknown malware. WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup
XInfeStopInfeStopRemover.exeInfeStop rogue spyware remover - not recommended, removal instructions here
UInfiumqip.exeQIP (Quiet Internet Pager) Infium multiprotocol instant messaging client
Xinfosmss.exeAdded by the VB.EIW WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\inetsrv
XINFO DATAapc.exeAdded by the RANDON.B WORM!
UInfo Selectis.exeInfo Select from Micro Logic - personal information manager
XInfo32xInfo32x.exeAdded by the GEMA TROJAN!
XInfoDatarundll32.exe ********.dll,realset [* = random char]Added by the VUNDO TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in %System%
Xinfoguardrinfoguardrun.exeInfoGuard rogue security software - not recommended, removal instructions here
UInfoPenMSNInfoPenIM.exeInfoPenMSN is a MSN Messenger plugin that allows you to send data written/drawn by hand
?Infoplay.exeInfoplay.exeWritten by New Media Properties, LLC and you're asked if you want to download and install it if you visit one of their search engine websites (which I chose not to). What does it do and is it needed?
XInfoPureInfoPure.exeInfoPure rogue security software - not recommended, removal instructions here
XInformation Updateiu.exeDetected by Kaspersky as the CENTIM.CH TROJAN!
XInfoSafeInfoSafe.exeInfoSafe rogue security software - not recommended, removal instructions here
UInfra-red MonitorIRMON.EXESystem Tray access to infra-red devices. Not required unless you use infra-red devices
Xinfusinfus.exeAdult content dialler
UInfuzerInfuzer.exeInfuzer - "is a service that copies dates from the web or an email straight to your electronic calendar". Beware of the following adware trait - "Infuzer provides web site owners with a unique opportunity to communicate with their visitors in a way that is useful and relevant to them, as well as increasing return visits and brand awareness, and providing new e-commerce opportunities"
Xinfwininfwin.exeVX2.Transponder parasite updater/installer related
XInit[path to trojan]Added by the DROPPER.EAT TROJAN!
XInit32Init32.exeAdded by the WINEX.A TROJAN!
XInitial Pageinstall.exeEasySearch browser hijack installer
YInitialize8x88x8_init.exeTool that initializes a Pinnacle PCTV card - maybe in capture or in showing overlay
Xinixsminix32.exeAdded by the AGENT.CKQX TROJAN!
Xinjobinjobs.exeAdded by the BINJO TROJAN!
NInk MonitorInkMonitor.exeAssociated with Epson (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
NInkWatchInkWatch.exeAssociated with Canon (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
XInomsnmoo.exeAdded by the RBOT-DPM WORM!
YInoRPCInoRpc.exePart of eTrust Antivirus and InoculateIT - earlier versions of the CA antivirus products
YInoRTInoRT9x.exeReal-time monitor for eTrust Antivirus and InoculateIT - earlier versions of the CA antivirus products
UInoTaskInoTask.exeScheduled scans and signature updates for eTrust Antivirus and InoculateIT - earlier versions of the CA antivirus products. Leave enabled unless you manually update signatures or perform routine scans. If enabled it can result in high CPU usage when performing updates
XiNoticeiservice.exeAdded by a variant of an MSN worm that tries to lure people to an infected site by using nude pictures and videos
UInputDirectorInputDirector.exe"Input Director is a Windows application that lets you control multiple Windows systems using the keyboard/mouse attached to one computer"
?insCOA5insCOA5.exe??
XInsiderInsider.exeAdded by the AGENT.KMC TROJAN!
UInstaAlertInstaAlert.exe"Kayako InstaAlert allows you to receive realtime alerts whenever a ticket gets updated under the assigned departments. The application displays popups as and when the tickets are created or replied to allowing you to answer your customer requests and issues promptly"
XInstafinderinstafinder.exeTopSearch.D adware
XInstaFinderKInstaFinderK_inst.exeInstaFinder adware
UInstaLANBelkinRouterMonitor.exeSystem Tray access to the Belkin Router Manager which indicates the current status of the Router and allows access to the Router settings and bundled software
XInstallInstall.exeAdded by the BANCBAN-HG TROJAN!
XInstall part IIupdates.exeAdded by the RELFEERWORM!
?Install Pending Filessifxinst.exeUninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see here. Is it required?
xinstall32install32.exeAdded by the NUCLEAR.DG BACKDOOR!
NInstallAurealDemosInstallAurealDemos.jsUsed to initialize the Aureal A3D demos InstallShield wizard
UInstallBuddyIbtna.exeInstallBuddy - automatically translates and installs your desktop documents, such as Adobe PDF, HTML, Microsoft Word, Excel and PowerPoint files, to your Palm organizer when you HotSync
XInstallCleanerInstallCleaner.exeAdded by the ANYHOMB.F TROJAN!
XInstalled shell32.dllOffice.exe...Added by the LOVGATE.AO WORM!
XInstalled shell32.dllOffice.exeAdded by the LOVGATE.E WORM!
XInstallerdial.exeMalware - detected by Kaspersky as the AGENT.MM TROJAN!
XInstallMonfbx.exeAdded by the MDROP-CZK TROJAN!
?InstallNAIProductSETUP.EXECould be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error?
XInstallProgram[path to trojan]Added by the AGENT-HHU TROJAN!
XInstallProvidernewsoftware2007install.exePart of WinAntiVirusPro 2007 and Privacy Protector rogue security software (and possibly others) - not recommended
XInstalls SP2[path] repcale.exe [path] palsp.exeAdded by a variant of the RANDON.AN WORM! Both files are located in %System%\qpalsp
XInstalls SP4[path] repcale.exe [path] p0rd.exeAdded by the RANDON-AK WORM! Both files are located in %System%\ekrlgc
UInstallstubinstallstub.exeTool for Outlook and Outlook Express from Plaxo for organising and keeping contacts organised and updated and providing online access to your contacts and access from PDA or mobile phone
XInstance 001[path to worm]Added by the ALASROU-A WORM!
XInstant Accessrundll32.exe EGDHTML_1023.dll, InstantAccessInstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
XInstant Accessrundll32.exe eg_auth_****.dll, InstantAccess [**** = digits]InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
XInstant Accessrundll32.exe EGCOMLIB_****.dll, InstantAccess [**** = digits]InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
XInstant Accessrundll32.exe EGCOMSERVICE_****.dll, InstantAccess [**** = digits]InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
XInstant Accessrundll32.exe p2esocks_****.dll, InstantAccess [**** = digits]InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
XInstant Accessmwsrvacc.exeInstantAccess premium rate adult content dialer
XInstant Accesslinewsrv.exeInstantAccess premium rate adult content dialer variant
Page: 1 2 3 4 5 6 7 8

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner