Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 24133 autoruns. Autorun 11601 to 11700:

StatusAutorun nameCommandDescription
XMSIMN32MSIMN32.EXEAdded by the CWS-M TROJAN!
?MSINMSin.exe??
XMsinetMsinet.exeAdded by the RBOT-AOA WORM!
XMSInfomsinfo.exeAdded by the ALADINZ.M TROJAN!
XMSInfoAVBgle.exeAdded by the NETSKY.O WORM!
Xmsinfo32msinfo325.1.2600.0.0108171148operatingmsinfo32.exeAdded by the TRITE-A WORM!
XMSInstallsmvss.exeAdded by the DEDLER-G TROJAN!
Xmsisrvmsisrv.exeAdded by the AGENT-IQV TROJAN!
Xmsjava servicexpcd.exeAdded by the SDBOT.VM WORM!
Xmsjavadlljnana.tsaAdded by the JNANABOT TROJAN!
Xmsjdqsfddwqt.exeAdded by the SDBOT-PO WORM!
UMskAgentMskAgent.exeMcAfee SpamKiller - rule-based and list-based spam filter. Available as a stand-alone product or included in older versions of Internet Security and Total Protection
UMskAgentexeMskAgent.exeMcAfee SpamKiller - rule-based and list-based spam filter. Available as a stand-alone product or included in older versions of Internet Security and Total Protection
XMSKCES32[random filename]Added by the CLONER TROJAN!
UMSKDetectorExeMSKDetct.exePart of McAfee SpamKiller - a rule-based and list-based spam filter
XMSKernel32MSKernel32.vbsAdded by the LOVELETTER (I LOVE YOU) VIRUS!
XMSkernel32System.exe 4820Added by the TUXDER BACKDOOR!
UMSKExespamkiller.exeMcAfee SpamKiller - a rule-based and list-based spam filter
Xmskjmskj.exeAdded by the KAEMON TROJAN!
Xmskridermaskrider.dll.vbsAdded by the SOLOW-F WORM!
UMSKServerExeMSKSrvr.exePart of McAfee SpamKiller - a rule-based and list-based spam filter. Appears as a service in XP/2K and under the "Run" registry key in 98/Me
Xmslagentmslagent.exeAdded by the WINTRIM-F TROJAN!
XMSLARISSAMSLARISSA.pifAdded by the ASSIRAL.B WORM!
?MSLIB32mswatch32.exe??
Xmsliveupdatemsliveupdate.exeAdded by the AGOBOT.ALT WORM!
XMSLogMicrosoftLog.exeAdded by a variant of the SDBOT WORM!
XMslogon lptt01mslogon.exeRapidBlaster variant (in a "mslogon" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it
XMslogon ml097emslogon.exeRapidBlaster variant (in a "mslogon" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it
Xmsmmsm.scrAdded by the BANKER-EHJ TROJAN!
Xmsmacro32msmacro32.exeIdentified as a variant of the AGENT.QB TROJAN!
Xmsmacro32msmacro64.exeAdded by a variant of the BACKDOOR-DOQ TROJAN!
XMsManagermsmgr32.exeAdded by the YAHA.AF WORM!
Xmsmanager32msmngr32.exeAdded by the RANDON-R (or WOMANIZ.A) WORM!
Xmsmautoprotectmsmssgs.exeAdded by the BIFROSE-AJ TROJAN!
Xmsmcmscpbo.exeClientMan parasite variant
Xmsmcmsgdmf.exeClientMan parasite variant
Xmsmcmsongn.exeClientMan parasite variant
Xmsmcmsmc.exeClientMan parasite variant
Xmsmcms****.exe [* = random char]ClientMan parasite variant
XMSMcAfeeeAvsynmgr32e.exeAdded by the FRAMAR TROJAN!
XMSMcAfeehAvsynmgr32h.exeAdded by the FRANGO TROJAN!
XMSMcAfeeSAvsynmgr32S.exeAdded by the VOLAC or VOLAC.DR TROJANS!
XMSMessngermsnupd.exeAdded by the RBOT-ADY WORM!
XmsMGRrtkmsg.exeAdded by the SDBOT-BPY WORM!
XMsmgtmsmgt.exeTotal Velocity adware/hijacker
Xmsmmimsmmi.exeAdded by the AGENT.RFR TROJAN!
XMSMNTGNTMSMNTGNT.EXEAdded by the BANKER-IE TROJAN!
XMSMNTJBEMSMNTJBE.EXEAdded by the BANCOS-EF TROJAN!
XMSMNTJNGMSMNTJNG.EXEAdded by the GRABER-G TROJAN!
XMSMNTMTSMSMNTMTS.EXEAdded by the BANKER-GZ TROJAN!
Xmsmonmsmon.exeAdded by a variant of the GEMA.D TROJAN!
XMsMon32MsMon32b.exeAdded by the SDBOT.O BACKDOOR!
XMsMoviesMsMovies.exeAdded by the ALCRA-E WORM!
?MsmqIntCertregsvr32 /s mqrt.dllMicrosoft Message Queue Server - Internal Certificate - see here for more info and here for a potential problem. Is it required?
XMSMSGNER[4-8 random letters].exeAdded by the FOWLDO-GEN TROJAN!
XMSMSGNERzzgf.exeAdded by the PWS-CCB TROJAN!
XMSMSGNERfgozmox.exeAdded by the AGENT-EBJ BACKDOOR!
Xmsmsgrmsmsgss.exeDetected by Kaspersky as the RBOT.AJJ WORM!
NMSMSGSmsmsgs.exeWindows Messenger instant messenger utility included with Windows 2K/XP. Available via the Start menu. Go to Windows Messenger → Tools → Options → Preferences and uncheck "Run this program when Windows starts"
XMsmsgsMsmsgs.exeAdded by the SILLYFDC-AP WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger
XMSMsgsmsmessgs.exeAdded by the SMALL-EW TROJAN!
Xmsmsgsmsmsgs.exeAdded by the SCLOG-AL TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger
XMSMSGSwinlogon.exeAdded by the BRONTOK-BS WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS
Xmsmsgs.exeIEXPLORE.EXEAdded by the VB.FQX TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%
XMsMsgSrvmsmsgsrv.exeAdded by the CQO TROJAN!
Xmsmsgss[path to trojan]Added by the RANKY.G BACKDOOR!
Xmsmsgssmsmsgss.exeAdded by the MDROP-CHV TROJAN!
XMSMsgSvcMSMSGSVC.exeBrowser hijacker, identified by some antiviruses as a variant of the StartPage.QC TROJAN!
Xmsmsngrmsmsngr.exeAdded by the DOPBOT-B WORM!
XMSNmsmgr.exeAdded by the AUTORUN-BHH WORM!
Xmsnsystem32.exeAdded by the KITRO.A WORM!
Xmsnmsnmsg.exeAdded by the RBOT-GO WORM!
XMSNmsnmsgs.exeAdded by the RBOT-KL WORM! Note - not to be confused with msmsgs.exe, the well known MSN Instant Messaging application!
XMSNctfmoons.exeAdded by the SPYBOT.HI WORM!
XMSNmsnmesengers.exeAdded by the RBOT-ME WORM!
XMSNMSN.exeAdded by the MINIT WORM!
XMSNmsnmsgr.exeAdded by the MYTOB or MYTOB.B WORMS! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%
Xmsnmsnsvc.exeAdded by a variant of the SDBOT WORM!
XMSNmsn16.exeAdded by the SDBOT-VN WORM!
XMSNmsnsgr.exeAdded by an unidentified WORM or TROJAN!
XMSNinstall.exeAdded by the AGENT-GDO TROJAN!
XMSNnetstats.exeAdded by the IRCBOT.UXP WORM!
XMSNscvhost.exeAdded by the IRCBOT-ZW WORM!
XMSNwdlrss.exeAdded by a variant of the SDBOT TROJAN!
XMSNwkssvr.exeAdded by the PUSHBOT.S WORM!
XMSNFixdriver.exeAdded by the SILLYFDC.BBY WORM!
XMSNiTuneshelp.exeAdded by a variant of the IRCBOT BACKDOOR! See here
XMSNlsass32.exeAdded by a variant of the IRCBOT BACKDOOR! See here
XMSNmsscomd.exeAdded by a variant of the SPYBOT WORM! See here
XMSNsystems.exeIdentified as a variant of the Backdoor.PosionIvy keylogging malware
XMSNtaskngr.exeAdded by a variant of the IRCBOT BACKDOOR! See here
XMSNwkssvrs.exeAdded by a variant of the IRCBOT BACKDOOR! See here
XMSNwksvr.exeAdded by the IRCBOT-XU WORM!
XMSNwmev.exeAdded by a variant of the SPYBOT WORM! See here
XMSNkys7r.exeAdded by the AUTORUN-AR WORM!
XMSNservices51651.exeAdded by the IRCBOT-AAL TROJAN!
XMsnrundll32.exe ilss32.dll,networkAdded by the BANLO-E TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
Xmsnwinlogon.exeAdded by the PROSTI.AA BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Media
XMSNmsnmsgx.exeAdded by the RBOT-PZ WORM!
XMSNmsservice.exeAdded by the IRCBOT-ABZ TROJAN!

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner