Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 24133 autoruns. Autorun 8601 to 8700:

StatusAutorun nameCommandDescription
Xloaddllloaddll.exeWinvest spyware
Xloaddr[path to trojan]Added by the AGENT-DIY TROJAN!
YLoadDvpApi9xDVPAPI9X.exeCommand AntiVirus for Windows 95/98/Me
Xloaderloader.exeHomepage hijacker, redirecting to coolwwwsearch.com. Downloader for iedll.exe
XloaderWMPLAYER.EXEUnknown baddie - WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup
XLoader msgzlmsgzl.exeAdded by the SDBOT.BVF WORM!
Xloader32sys*****.exe [***** = random digit]Added by the DOMCOM TROJAN!
Xloader32Loader32.exeAdded by an unidentified TROJAN!
XLoadersHeIp.exeAdded by the SDBOT-ADB WORM!
XLoadersHeIp.pifAdded by the SDBOT-ACS WORM!
XLoadEWXDmsxml4r.exeLoadEWXD adware
Xloadfaxloadfax.exeAdded by the WINFLUX-C BACKDOOR!
XLoadFontsLoadFonts.vbsHomepage hijacker that changes your homepage to an adult content site
XLoadFontsTahoma.vbsHomepage hijacker that changes your homepage to an adult content site
ULoadFujitsuQuickTouchQuickTouch.exeMaps the keys on a Fujitsu Siemens Lifebook application panel to various programs and functions
XLoadGolfCoursesLoadGolfCourses.exePlayMiniGolf.com foistware - stealth installed!
XLoadhgrundll32.exeAdded by the LINEAG-ABX TROJAN!
XLoadHTMLrundll32.exe regsvr32.exe,MShtmpreMatrixSearch adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
XLoadingAgentZipLoader32.exeAdded by the OBLIVION TROJAN! This executable is one of the most common but there are more
XLoadingAgentmsload32.exeAdded by the OBLIVION TROJAN! This executable is one of the most common but there are more
XLoadManagermsload.exeAdded by the OPASERV.T WORM!
XloadMecq0explorer.exeAdded by the MUMUBOY.C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%
XloadMecq3rundll32.exeAdded by the LEGMIR-AS TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in the root folder (i.e., C:\)
XloadMect1explorer.exeAdded by the LINEAGE-L TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%
XloadMefsrundll32.exeAdded by the LEGMIR-JB TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir%\inf
XloadMefssmss32.exeAdded by the FLOOD-EL TROJAN!
NLoadMSvcmmmsvcmm32.exeAuto-update for the now defunct Movielink "web-based video on demand (VOD) and electronic sell-through (EST) service offering movies, TV shows and other videos for rental or purchase". Movielink LLC were acquired by Blockbuster in 2008
XLoadOrderVerification[random filename]Added by the TRON.A BACKDOOR!
ULoadout Managernost_LM.exeManager for the Belkin Nostromo n50 SpeedPad game controller - see here
XLoadPFWwmimgr.exeAdded by the QEDS-B WORM!
XLoadPowerProfileASDAPI.EXEAdded by the CABRO TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll
ULoadPowerProfileRundll32.exe powrprof.dllPower management specifics such as monitor shut-off, system standby, etc. Associated with power management and is listed twice - see here. Loads your selected power scheme. May not be required - depends upon whether you modify the default Control Panel -> Power Options settings
XLoadPowerProfileRundll.exe powerprof.dllAdded by the LOXOSCAM TROJAN! Note - do not confuse with the valid LoadPowerProfile entry! Notice that the infected version uses "Rundll.exe" whereas the uninfected version uses "Rundll32.exe"
XLoadPowerProfilerundl.exeAdded by the TOFAZZOL TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll
XLoadPowerProfileRundll32.exeAdded by the MIROOT WORM! Note - do not confuse with the valid LoadPowerProfile entry which has "powrprof.dll" appended to the command/data line
XLoadPowerSchemerundll32.exe powerprof.dll CheckPowerProfileUlubione adult content dialer. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
ULoadQMloadqm.exeInstalled with MSN Explorer and loads the MSN Queue Manager. Required to enable the WU AutoUpdate feature. Note that disabling this can sometimes prevent internet sharing working on Win2K Pro SP2. Reports also suggest that removing it will re-enable internet access - hence the "users choice" recommendation. If you have problems leave it, otherwise I recommend you disable it
Xloads.exeloads.exeMediaMotor adware
Xloads.exemedload.exeMedload adware
Xloads.exesuploads.exeAdded by the AGENT-BZ TROJAN!
XLoadServiceRest In PeaceAdded by the KANGAROO-A WORM!
XLoadServiceMaaf, tempatmu bukan di sinAdded by the KAGEN-A TROJAN!
XLoadServiceVirusAdded by the CAGER.A WORM!
XLoadServiceuser32.comAdded by the BURMEC WORM!
XLoadSIPSrundll32.exe SIPSPI32.dll, SIPSPI32123Mania adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "SIPSPI32.dll" file is found in the System folder
XLoadWatcherwatcher.exeWatcher spyware
?LoadWatcherTest.exeReportedly part of a webcam surveillance program that's supposed to test SMTP dialling in the event of an alert? Is this correct?
Xloadwinwinset.exeAdded by the QQPASS-I TROJAN!
Xloadwinwinsys.exeAdded by the QQPASS-J TROJAN!
XLoadWindowsFileKernel32.exeAdded by the DELF.B BACKDOOR!
XLocal Area NetworkOpenGL.exeAdded by a variant of the RBOT WORM!
XLocal Authority Servicelsass.exeAdded by the MARKTMAN-C TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XLocal Internet ConnectionLIC.exeAdded by the SDBOT-YA WORM!
XLOCAL INTERNET WEB DRIVERS FOR WIN32phqghume.exeAdded by a variant of the RBOT WORM!
XLocal Pagehttp://find.naupoint.comNaupoint browser hijacker
XLocal runole servicesrvc32.exeAdded by the SMALL-DP TROJAN!
XLocal Security Authority Servcelssas.exeAdded by the POEBOT-T WORM!
XLocal Security Authority Servicelssas.exeAdded by the POEBOT-J WORM!
XLocal Security Authority ServiceIsass.exeAdded by the LINKBOT.M WORM!
XLocal ServiceIntenat.exeAdded by the NUCLEAR-J TROJAN!
XLocal Serviceservices.exeAdded by the P2PWORM-T WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Cursors
XLocal-Settings-of-[User Name][User Name].exeAdded by the GAVGENT.A WORM!
ULocalProxyproxy4free.exe"ProxyTools is a package of Perl network utilities designed mainly to assist those whose Internet access is censored, unreliable, or otherwise damaged. Uncensored access is provided to any outside service required (Usenet News, Web browsing, IRC, Socks etc.). Setup requires installation of Perl and some modules"
XLocalSystemsvchost.exeEHU adware. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
XLocator Service[filename]Added by the AGOBOT-KY TROJAN!
XLocinxgdicli.exeAdded by the AGENT-PAW TROJAN!
ULock My PClockpc.exeLock My PC - a tool for quick computer locking when you leave it unattended. It shows a lock screen, disables Windows hot keys and mouse
Xlofgyhlofgyh.exeAdded by the SDBOT-TP WORM!
ULogan_S2PScan2pc.exeScan to PC application for the scanning function of the Samsung SCX-4500 Series multifunction printer
Xlogglogo_1.exeAdded by the PWFUZZ-A WORM!
ULogi_MwXLogi_MwX.exeLogitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as "SmartMove". If you disable it and find you don't need it leave it disabled
XLogical Disk Detectionmrisvc.exeAdded by the IRCBOT.AOW BACKDOOR!
NLogiciel de transfert d'images KODAKpts.exeLooks for Kodak camera connection and media insertion. Available via Start -> Programs
NLogiciel notes Post-it®psnotes.exeLogicel Post-it® (developed by 3M) - now replaced by the more advanced Post-it® Digital Notes
ULoginwinlog.exeSalfeld Child Control - parental control software
Xlogin[path to trojan]Added by the HOTWORD-A TROJAN!
XLoginLogin.exeAdded by the BANCBAN-AH TROJAN!
XLoginlala.exeAdded by the BUGSPR-A TROJAN!
XLogin Screen Saverlogin.scrAdded by the RBOT-AVN WORM!
XLogin Service[path to file]Added by the MIGMAF TROJAN!
XLogin Software 2009[path to trojan]Added by the ERTFOR.B TROJAN!
XLoginPassportLgnpsp32.exeAdded by the REDIST.C WORM!
Xloginui32loginui32.exeAdded by the LONGNU.A BACKDOOR!
XLogitechLogitech.exeAdded by the RBOT.BJH WORM!
YLogitechCommunications_Helper.exeEntry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also, if it's disabled the camera will not work - at least not in the QuickCapture mode
NLogitech . Product RegistrationeReg.exeRegistration reminder from Leader Technologies for Logitech software such as SetPoint for their range of wired and wireless keyboards and pointing devices (mice, trackballs, etc)
ULogitech BT WizardLBTWiz.exeBluetooth connection manager for Logitech based bluetooth wireless products
XLogitech CameraSoundcane.exeAdded by the SDBOT.MUC WORM!
?Logitech Camera SoftwareElkCtrl.exeEntry added when you install versions of the Logitech QuickCam webcam software. It's exact purpose is unknown at the present time
ULogitech ClickSmartISStart.exeInstalled with Logitech's QuickSmart webcam software. The exact purpose of this startup entry is unknown at present, with opinions varying from: (i) adding a tray icon when a camera is connected - apparently no longer the case, (ii) repairing a problem with the image gallery and (iii) being required with some versions to take pictures and capture videos
ULogitech ClickSmartLogiTray.exeSystem Tray access to My Logitech Pictures, Camera Settings and other features for Logitech's QuickSmart webcam software. Create your own shortcut and run it manually when required unless you use it all the time
ULogitech ClickSmartLVCOMS.EXEEntry added when you install Logitech ClickSmart webcam software. It allows the camera to be accessed by both the Logitech software and (amongst others) NetMeeting and Windows Movie Maker. If you don't use the camera on a daily basis create your own shortcut and run it manually when required
XLogitech DesktopApPache.exeAdded by the RBOT-YP WORM!
XLogitech DesktopIPCONN.EXEAdded by the SDBOT-WE WORM!
XLogitech Desktop Controllerwrcam.exeAdded by a variant of the RBOT WORM!
NLogitech Desktop Messengersetup-8876480.exeInstaller for Logitech Desktop Messenger included with older versions of the software for Logitech products - which automatically checks for software upgrades and new products, services and special offers from Logitech
NLogitech Desktop Messengerldmconf.exeInstalled with older versions of the software for Logitech products. Configures the options for Logitech Desktop Messenger to activate notifications about software upgrades and/or new products, services and special offers
NLogitech Desktop MessengerLogitechDesktopMessenger.exeInstalled with the software for Logitech products. Automatically checks for software upgrades and new products, services and special offers from Logitech
NLogitech Desktop Messenger Agentldmconf.exeInstalled with older versions of the software for Logitech products. Configures the options for Logitech Desktop Messenger to activate notifications about software upgrades and/or new products, services and special offers
NLogitech Gaming SoftwareLWEMon.exePart of Logitech Gaming Software (formerly Wingman Software) for their range of game controllers. Starts the profiler (button configuration) and loads the last used profile at start-up - including System Tray access. Unless you're a hard-core gamer it's best to leave it disabled and load when needed

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner