Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 24133 autoruns. Autorun 23301 to 23400:

StatusAutorun nameCommandDescription
NWinTOTAL Schedulerguru.exeWinTOTAL Real estate appraisal software related
XWinTouchWinTouch.exeAdded by the AGENT.BUO TROJAN!
XWinTraywintray.exeAdded by the LEGUARDIEN.B TROJAN!
Xwintsk32dllwintsk32dll.exeAdded by the RBOT-AAJ WORM!
Xwinudll.exewinudll.exeAdded by the MITGLIE-CE TROJAN!
Xwinuiz.exeAdded by the KONDELI TROJAN!
XWinUpsvchost.exeAdded by the SILLY.BR WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This file is located in a "4350" sub-folder
Xwinupated.exewinupated.exeAdded by a variant of the SDBOT WORM!
XwinupdRUNDLL32.EXE [random value].dll,_mainRDAdded by the MOTA.A WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in %Windir%
Xwinupdwinupd.exeSearchNew adware
Xwinupd.exewinupd.exeAdded by the BEAGLE.M or BEAGLE.N WORMS!
XWinUPD32explorer.exeAdded by an unidentified VIRUS, WORM or TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!
Xwinupd64x.exewinupd64x.exeAdded by the FAKEAV-FI TROJAN!
Xwinupdatwinupdat.exeAdded by the CANBOT.A BACKDOOR!
XWinUpdateRBSKQQBO.EXEAdded by the VBSWG2B.A WORM!
XWinUpdatewmbem.exeAdded by the REVCUSS.B TROJAN!
XWinUpdateupdsys.exeAdded by a variant of the RBOT WORM!
Xwinupdatewinupdate.exeAdded by the ALCAN.B WORM!
XWinUpdatesvhost.exeAdded by a variant of the SDBOT WORM!
XWinUpdatesvchots.exeAdded by the SMALL.GXJ TROJAN!
Xwinupdatejusched.exeAdded by the DWNLDR-FUX TROJAN! Note that this is not the legitimate Oracle (was Sun Microsystems) file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %Windir%
XWinupdatelsas.exeAdded by the COSPET.JR TROJAN!
Xwinupdatesvchost.exeAdded by the MDROP-CHC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%
XWinupdate Enginewupeng.exeMalwareCrush rogue security software - not recommended, removal instructions here
XWinUpdate Loadermsnnm.exeAdded by the REVCUSS.C TROJAN!
XWinupdate Servicewinxp.exeAdded by the SPYBOT.IR WORM!
Xwinupdate.exewinupdate.exeAdded by the RADO TROJAN!
Xwinupdate.regwinupdate.exeAdded by the SPYBOT.EAS WORM!
Xwinupdate_[path to file]Added by the COMDOR.A WORM!
Xwinupdate2846vbsystem35.exe msvbrun.exeAdded by a variant of the MUTIN-C TROJAN!
Xwinupdate86.exewinupdate86.exeAdded by the FAKEAV-AHQ TROJAN!
XWinUpdateAdministratorCSRSS.EXEAdded by the PUNYA-A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Application Data\WINDOWS
XWinUpdateBbreatle.exeAdded by the BRATLE.AWORM!
Xwinupdateconn[path to file]Added by the COMBRA-A WORM!
Xwinupdateconn_Explorer.EXEAdded by the COMBRA-B WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
XWinupdateewinsvcc.exeAdded by the AGENT.AN TROJAN!
Xwinupdatefiv_[path to file]Added by the COMBRA.C WORM!
UWinUpdateProtectioncsrss.exeEmployeeWatch is a commercial surveillance software program designed to monitor user activity on a computer. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a subfolder of C:\windowsupdate\ufp
XWinUpdaterupdate.exeAdded by the STARTPAGE.C TROJAN!
Xwinupdateswinupdates.exeAdded by the ALCRA-B WORM!
XWinUpdatingWinUpdating.exeAdded by the AGENT-GSC TROJAN!
XWinUPDbcwinupdbc.exeAdded by the BANKER-DSN TROJAN!
XWinUpdsvwinupdsv.exeAdded by the DROPO MACRO!
XwinupdtRUNDLL32.EXE [random.dll]Added by the MABUT.A WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in %Windir%
Xwinupdtlwinupdtl.exeSecondThought adware
XWinUpgrader[path to trojan]Added by the AGENT-DZ TROJAN!
XWinUPPD.exe[random filename]Added by an unidentified WORM/TROJAN!
Xwinurwinrun.exeAdded by the WINUR.B WORM!
Xwinusb.dllwinguard.exeAdded by the FORBOT-CN WORM!
XWinUser32Kusr32wink.exeAdded by the HK TROJAN!
XWinUsrWinUsr.exe K1S2Added by the CLUNK.A WORM!
UWinUtilities Memory OptimizerToolMemoryOptimizer.exe"WinUtilities Memory Optimizer optimizes the memory management of your system and boost-up its performance amazingly!" MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
XWinux Piriax ServicePH32.EXEAdded by the RANDEX.G WORM!
Xwinversionwinversion.exeBrowser hijacker, redirecting to specificsearches.com
UWinVNCWinVNC.exeWinVNC is an application that allows you to remote control your PC from another PC somewhere on the internet. Now superseded by RealVNC
XWinVNCiexplorer.exeAdded by the EVIVINC BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe)
Xwinvxd32winvxd32.exeAdded by the GABLOLIZ.A WORM!
Xwinwan lptt01winwan.exeRapidBlaster variant (in a "winwan" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it
Xwinwan ml097ewinwan.exeRapidBlaster variant (in a "winwan" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it
XWinwebSecurityWinwebSecurity.exeWinweb Security rogue security software - not recommended, removal instructions here
Xwinwordwinword.exeAdded by the TORPID-C TROJAN!
XWINWORD.exeWINWORD.exeAdded by the DRIVUS TROJAN! Note - this is not the legitimate MS Word process of the same name, which is always located in %ProgramFiles%. This one is located in %System% and should not normally figure in Msconfig/Startup!
XWinWorksvstmgr.exeAdded by the AGOBOT.ACJ WORM!
Xwinwsl.exewinwsl.exeAdded by the ZOTOB-J WORM!
XWinX Security CenterWinX Security Center.exeWinX Security Center rogue security software - not recommended, removal instructions here
XWINX16winx16.exeAdded by the AGOBOT-LS WORM!
XWinXDefenderWinXDefender.exeWinXDefender rogue spyware remover - not recommended, removal instructions here
XWinxDiagUpdateWinxDiagUpdateAdded by the RBOT.BWQ BACKDOOR!
XwinXP33.exeAdded by the ANPES WORM!
XWinXPplugin1.exeAdded by the Downloader-JW TROJAN!
XWinXPcsrss.exeAdded by the BANCOS-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\WinXP\Tools
Xwinxpwinxp.exeAdded by the BRONTOK-DN WORM!
XWinXP fix[path to file]Added by the RANKY.P TROJAN!
XWinXP Processor Generator v1.2intspnsr32.exeAdded by the SDBOT.LP BACKDOOR!
XWinxp updateCappp.exeAdded by the RBOT.DKO WORM!
XWinXp Updaterwinxp32.exeAdded by the RBOT-HG WORM!
XWinXP-98CSRSS.exeAdded by the BANKER-DS TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\WinXP-98\Tools
Xwinxpdll32.exewinxpdll32.exeAdded by a variant of the SMALL downloader TROJAN!
XWinXPHomeplugin2.exeAdded by the malicious INOR.T SCRIPT!
UWinXPLoadRundll32 LoadDll, LoadExe WinXPLoad.exeCompaq hotkey related - required if you use the hotkeys
XWinXProtectorWinXProtector.exeWinXProtector rogue security software - not recommended, removal instructions here
XWinXPServicelsass.exeAdded by the ZAPCHAS-AS TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "Lavan" subfolder
XWinXPServicetaksmgr.exeIdentified as a variant of the IRC/Flood.tool malware
XWinXPServiceTskdbg.exeAdded by the MDROP-BPQ TROJAN!
XWinXPServicectfmon.exeAdded by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in a "ctf" sub-folder
XWinXPServicemirc.exeAdded by a variant of the IRCBOT BACKDOOR! See here
XWinXPServicenero.exeAdded by the IRCFLOOD.AG BACKDOOR! Note - this is not the Nero CD/DVD burning software by Ahead Software which is normally located in %ProgramFiles%\Ahead\Nero. This file is found in %System%
XWinXPServicetaksmgr.exeAdded by the KIRSUN.A BACKDOOR! The file is located in %System%
XWinXPServicetaksmgr.exeAdded by the KIRSUN.A BACKDOOR! The file is located in the root directory, i.e., C:\
XWinXPServicewacult.exeAdded by the KIRSUN.A BACKDOOR! The file is located in %Windir%\Fonts
XWinXPServicewacult.exeAdded by the KIRSUN.A BACKDOOR! The file is located in %System%\mnut
XWinXPServiceprinter.exeAdded by the MDROP-BYD TROJAN!
XWinXpUpdate32WinXpUpdate32.exeAdded by the AGENT.YWL WORM!
Xwinxpusbdwinxp64.exeAdded by a variant of the RBOT WORM!
Xwinystems25winystems.exeAdded by a variant of the SDBOT WORM!
XWinz Firewall[random filename].exeAdded by a variant of the SDBOT WORM!
XWinZap Checkwinzbp.exeAdded by the RBOT-AWZ WORM!
Xwinzip[path to trojan]Added by the BANCOS.G or BANCOS.K TROJANS! Note - this is not part of the popular WinZip file compression utility
XWinzip[various filenames]Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe, common.pif, common.scr, Sexo.exe, Sexo.jpg.pif, ini_file__.pif, load_me__.tmp, msfile.pif, system_load_.pif or zipped.rar.pif
Xwinzipwinzip.exeAdded by the RBOT.BDA WORM! Note - this is not part of the popular WinZip file compression utility

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner