Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 24133 autoruns. Autorun 4101 to 4200:

StatusAutorun nameCommandDescription
XCTFM0N.exeCTFM0N.exeAdded by the STARTPAGE.P TROJAN! Notice the digit "0" in both columns rather than the upper case "o"
Xctfmencssrs.exeAdded by the STARTP-DC TROJAN!
Xctfmgrctfmgr.exeAdded by the PWS-ATU TROJAN!
Xctfmomctfnom.exeAdded by the BCKDR-QTA BACKDOOR!
Uctfmonctfmon.exeSupports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or, for example, if speech is selected as an alternative input for MS Office or Notepad. Required to support advanced text services (such as right to left text) for East Asian users. Can be disabled via Start → Control Panel → Regional and Language Options → Languages → Text Services and Input Languages → Details → Advanced → System Configuration → Turn off advanced text services (which also turns off the language bar). See also here and here. Can also cause problems with some other programs if left enabled - see here for such an example
Xctfmontaskmgr32*.exe [* = number]Added by the SOWSAT.B WORM!
Xctfmoncftmon.exeAdded by the DELIVE-A BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%
XctfmonmIRC.dllAdded by the DELBOT-E TROJAN!
XctfmonWinConst.exeAdded by the ASSASIN-G TROJAN!
UCTFMonctfmon.exeFamily KeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in a "CTF" sub-folder
Xctfmonmsnmsgr.exeAdded by the BDOOR-JV BACKDOOR! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%
XCTFMONwscript.exe /E:vbs winjpg.jpgAdded by the RUNAUTO.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "winjpg.jpg" file is located in %System%
XCTFMONwscript.exe /E:vbs regedit.sysAdded by the VBSAUTO-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "regedit.sys" file is located in %System%
XCTFMONwin.exeAdded by the VBS.RUNAUTO.G WORM!
XCtfmonwmisys.exeAdded by the IRCBOT-ADS WORM!
XctfmonWinUP.exeAdded by the BANKER-VV TROJAN!
Xctfmonctfmon.exeAdded by the AUTORUN-G WORM! Note - this is not the legitimate ctfmon.exe process associated with alternate language and method inputs which is always located in %System%. This one is located in a "1046" sub-folder
Xctfmonsvhost.exeAdded by the BACKDR-EL BACKDOOR!
XCTFMON.CPLCTFM0N.CMDDetected by Symantec as the SILLYFDC WORM! See here
XCtfmon.exectfmon32.exeCoolWebSearch Ctfmon32 parasite variant
Xctfmon.exectfmon.exeAdded by the RAIDYS TROJAN! Note - this overwrites the legitimate ctfmon.exe process associated with alternate text inputs which is located in %System%
Xctfmon.exemsupdate32.exeSpy Sheriff/SpywareNO malware, also detected as the SPYHOAX-A TROJAN, pretends to be a spyware remover! - file names spotted sofar include VXH8JKDQ2.EXE, NS6281400.so, CVXH8JKDQ2.EXE, down3.exe, sefe.exe, winstall.exe, and tool2.exe
Uctfmon.exectfmon.exeSupports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or, for example, if speech is selected as an alternative input for MS Office or Notepad. Required to support advanced text services (such as right to left text) for East Asian users. Can be disabled via Start → Control Panel → Regional and Language Options → Languages → Text Services and Input Languages → Details → Advanced → System Configuration → Turn off advanced text services (which also turns off the language bar). See also here and here. Can also cause problems with some other programs if left enabled - see here for such an example
Xctfmon.exectfmon.exe eminem.exeAdded by the BHARAT.A WORM!
XCTFMON.EXEsvchost.exeAdded by the JUEGO-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
Xctfmon.exeCTFM0N.EXEAdded by the AUTORUN-AYX WORM! Notice the digit "0" in the filename rather than the upper case "o"
Uctfmon.exectfmon.exeTotalSpy keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %ProgramFiles%\TS Trial
XCTFMON.EXEctfmon.exeAdded by the VBSP-A WORM! Note - this is not the legitimate ctfmon.exe process associated with alternate language and method inputs which is always located in %System%. This one is located in a "1126" sub-folder
XCTFMON32CTFMON32.EXECoolWebSearch Ctfmon32 parasite variant - also detected as the CWS-E TROJAN!
Xctfmon32[random filename].exeAdded by the RBOT-GSN WORM!
Xctfmon32taskmgr32*.exe [* = digit]Added by the SOWSAT.C WORM!
Xctfmonactfmona.exeAdded by the DLOADR-BME TROJAN!
XCTFMONSSCTFMONSS.EXEAdded by the CWS-F TROJAN!
Xctfmoonmicrosoftconfigurator.exeAdded by the DELF-ALS TROJAN!
Xctfmunctfmun.exeAdded by the AGENT.ACEZ TROJAN!
Xctfnnonctfmon.exeAdded by the TURKOJAN.IL BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%
XctfnomrundIl32.exeAdded by the LEGMIR-AW TROJAN!
Xctfnom.exeSVOHOST.exeAdded by the DIGIDOR-A TROJAN!
Xctfnom.exeOSRSS.exeAdded by the DLOADER-UQ TROJAN!
Xcthelpcthelp.exeAdded by the SDBOT TROJAN!
UCTHELPERCTHELPER.EXECTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative's sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a "leave alone" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it
XCTHelpercthelper.exeAdded by the RBOT-XB WORM! Note - do not confuse with the Creative application of the same name described here
XCTHELPERsvhost.exeAdded by the SDBOT-RZ WORM!
XCTime[path to trojan]Added by the HTTPDOS TROJAN!
XCTin10CTin10.exeAdded by the BANCOS.E TROJAN!
XCtModuleCtModule.exeAdded by the CLICKER-EG TROJAN!
XCTMON.EXEcfmon.exeAdded by the CLCKR-AN TROJAN!
UCTNMRUNctnmrun.exeDetects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connected
?CTPDPSRVCTPDPSRV.EXECompaq A3000 printer driver (in the %System%\spool\DRIVERS\W32\X86 folder). Is it required?
NCTPerformanceUtilityCTPowUti.exeRelated to Creative PowerSysTrayApp. This program is a non-essential process, but should not be terminated unless suspected to be causing problems
Xctpmonctpmon.exeRegistry Cleaner rogue - not recommended, removal instructions here
NCTRegRunCTRegRun.exeFor Creative Soundblaster Live! series soundcards. Reminds you to register your card with Creative
UCtrlVolCtrlVol.exeVolume control key on Acer, Fujitsu and other laptops
?CTSchedCTSched.exeCreative Task Scheduler. What does it do and is it required?
NCTStartupCTEaxSpl.exeSplash screen with sound on every boot up. Installed with a Sound Blaster Audigy soundcard
UCTSVolFECTSVolFE.exeCreative Labs Mixer applet for the Sound Blaster Audigy
UCTSVolFE.exeCTSVolFE.exeCreative Labs Mixer applet for the Sound Blaster Audigy
NCTSyncU.exeCTSyncU.exeCreative Sync Manager - synchronizes music tracks on your computer with your player
UCTsysVolCTSysVol.exeCreative sound card volume controls
?cttdpsrvcttdpsrv.exe??
XCTUpdatectupdclt.exeAdded by the RBOT-ABG WORM!
NCTxfiHlpCTXFIHLP.EXEAdded by the installation of a Creative Labs X-Fi sound card. This particular process provides the help functionality for your card
NCTXFIREGCTxfiReg.exeCreative Labs sound card driver related. It appears that it isn't required and maybe registration related
XCtykd[path to file]SMALL.SN spyware
NCTZDetec.exeCTZDetec.exeAuto-detect feature of Creative Media Lite which assists you in managing your music, ripping CDs and transferring other stored music to your Zen Stone MP3 player
XCU1VCClient.exeAssociated with the Surf Sidekick adware and should be removed
XCU2VCMain.exeAssociated with the Surf Sidekick adware and should be removed
YcuagentExeCuagent.exeCommand Antivirus related
XCueX44Dago.exeAdded by the PUNYA-B WORM!
XCueX44_stil_hereWINLOGON.EXEAdded by the PUNYA-A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
Xcuocuo.exeAdded by the BUGBEAR.A WORM!
UCurrencywindowsintd.exeIntruder keystroke logger/monitoring program - remove unless you installed it yourself!
XCurrent Security Configcsecure.exeAdded by the RBOT-AMO WORM!
XCurrent32msnpla.exeAdded by the SDBOT-DIS WORM!
XCurrentVersionrecyclebin.exeAdded by the AUTORUN-AZX WORM!
NCurseClientCurseClient.exeCurseClient add-on manager for World of Warcraft and Warhammer Online games
NcursorScreendragon_VS_Taskbar.exeScreenDragon video player
UCursorFXCursorFX.exeCursorFX from Stardock Corporation - cursor editing and management utility. Required if you use any cursors or effects supplied with or created by CursorFX
UCursorGizmoCursorGizmo.exeCursor Gizmo - cursor management utility
UCursorXPCursorXP.exeCursorXP (now replaced by CursorFX) from Stardock Corporation - cursor editing and management utility. Required if you use any cursors or effects supplied with or created by CursorXP
UCurtainCurtain.exeCurtain (from Chaotic Visions) - "is a Windows utility which gives you the power to hide any window or group of windows to your system tray"
UCustomizer2000logon.exeAutomatic logon feature of Customizer 2000 - "a special utility which is designed to optimize Win9x/ME performance. The program lets you explore the many hidden settings in Windows, and make changes"
NCuteMXCuteMX.EXEFile sharing utility
XCvfjxANACON.EXEAdded by the NACO.A WORM!
XcvhnykzxkeepSafe.exeAdded by the KILLAV.KAX TROJAN! Note - this is not the legitimate KeepSafe from Stardock Corporation which shares the same filename and is normally located in a %ProgramFiles%\Stardock subfolder. This one is found in %System%
Xcvmonitor.execvmonitor.exeAdded by the SDBOT.BV WORM!
Xcvmsyslpdsdservss.exeAdded by the MAILBOT-BY TROJAN!
YCVPNDcvpnd.exeSub-system used by Cisco VPN client for making a connection to a remote IPSec server
UCWcw4.exeChat Watch "is a monitoring and logging software for online chat and instant messaging programs"
UCWatchcw.exeChatWatch - chat monitoring tool
Ncwbckvercwbckver.exePart of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to. Not required - and can be turned off in the Client Access properties. It's a waste of resources
Ncwbinhlpcwbinhlp.exeClient Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. It only updates the help files on your PC to match the level of the attached iSeries
Ncwbsvstrcwbsvstr.exePart of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resources
?cwbwlwizcwbwlwiz.exeWelcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. What does it do and is it required?
?Cwcdschk.exeCwcdschk.exeIBM Thinkpad related?
Ucwcptraycwcptray.exeRelated to ContentWatch Parental Control internet filter
Xcwingllibatllsimm.exeAdded by a variant of the SDBOT WORM!
Xcwintoolcwintool.exeAdded by the SMALL.ZZJ TROJAN!
Xcwriterucookw.exePart of the ErrClean rogue system error and cleaning utility and other members of this family. See here for more examples
Xcwritercwriter.exePart of PcRaiser, SystemOptimizer2008, VelocidadSimple and other rogue optimization utilities - not recommended

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner