Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 304 autoruns. Autorun 1 to 100:

StatusAutorun nameCommandDescription
Xg.exeg.exeAdded by the GRAYBIRD.Q TROJAN!
XG_HostgHost.exeAdded by the AUTOIT-BP WORM!
XG_Server.exeG_Server.exeAdded by the FEUTEL-C TROJAN!
XG_Server1.2.exeG_Server1.2.exeAdded by the GRAYBIRD-Z TROJAN!
XG00123[worm filename]Added by the BUGBROS WORM!
XG0mezG0mez.vbsAdded by the GORMLEZ-A WORM!
XG3GSMedia3.exeMalware downloader - detected by Kaspersky as the VB.UX TROJAN!
?g3dctlg3dctl.exe??
XG4G[random filename]Detected as Trojan-Downloader.Win32.VB.fki
UG6FTP Server Tray MonitorG6FTPTray.exeSystem Tray monitoring tool for Gene6 FTP Server - "an advanced FTP server software for Windows developed specifically for security and high performance requirements"
Xga6pcwga6pcw.exePart of the AVSystemCare rogue security software and other members of this family. See here for more examples
Xgabougoolnounina.exeAdded by the AGENT-JVX TROJAN!
Xgacgac.exePart of VirusVakt, Swedish rogue security software - not recommended. A member of the AVSystemCare family
?GACServiceGACService.exeRelated to a Gemplus product. What does it do and is it required?
Xgadcomgadcom.exeAdded by the AGENT-HIC TROJAN!
Xgadkgak12fsafsakx12.exeAdded by the ONLINEG-N TROJAN!
NGadu-Gadugg.exePolish language Instant Messaging client
NGadwin PrintScreenPrintScreen.exeGadwin PrintScreen - utility to capture, print or save the current window
XGAELICUM.EXEGAELICUM.EXEAdded by the PENTA-A TROJAN!
Xgah95on6gah95on6.exeShopAtHome/SAHagent adware
Ugaimgaim.exeGaim is an instant messenger client with capability to connect to AIM, ICQ, MSN Messenger, Yahoo, IRC, Jabber, Gadu-Gadu and Zephyr networks
UGainwardTBPanel.exeConfiguration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel
Xgameshit.exeAdded by the Netclap Gold backdoor TROJAN!
Xgamepatcher.scrAdded by the PSW-ED TROJAN!
NGame DeviceJOYUPDRV.EXEGenius game controller profile activator
XGame HouseGameHouse.exeAdded by the DELF-DRA WORM!
NGameDriveGDTask.exeGameDrive from FarStone - virtual CD/DVD drive emulator that allows you to run your PC games without the disc. Available via Start → Programs
XGames Accelerationsvshost.exeEasySearch adware
XGames Acceleration[path to trojan]Added by the SMUTSRCH-A TROJAN!
XGames Accelerationsvshost1.exeAdded by the DLOADR-AWD TROJAN!
XGames toolbarrundll32.exe [path] tbGame.dll DllShowTBTopconverting.com/180Search "Games Toolbar" adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
NGameSpotkontiki.exeKontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops
NGameTrackerGTLite.exeGameTracker - "Keep track of and launch all your games from one application with the Game Tracker Client. Instantly announce on your profile and to your friends what game and on which server you are playing!"
Ugameutil.exegameutil.exePart of Redline RegTweak as supplied with Sapphire ATI graphics cards. You can configure different overlclocking settings on a per game basis and this sets those conditions following a re-boot
Xgammasvchost.exeAdded by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies
UGammaHotKeyssetgamma.exePart of the RadeonTweaker program for adjusting ATI Radeon graphics cards. Allows you to adjust the gamma (or brightness) when playing a full-screen game without switching back to the desktop
Xgangstagangsta.exeAdded by the RIMA.A BACKDOOR!
UGARO Status Monitorcnwism.exePrint monitor for certain Canon printers
XgaSrvgaSrv.exeDetected by Panda as the DOWNLOADER.ALQ TROJAN! Adware downloader
XgaSrvegaSrve.exeDetected by Panda as the DOWNLOADER.ALQ TROJAN! Adware downloader
XGate Personal FirewallSystpl.exeAdded by the RBOT.ADC WORM
NGateway Extended WarrantyGWCares.exeGateway Extended Warranty reminder
XGatorgator.exeGator eWallet adware. Please note that Claria Corporation no longer support GAIN-Supported software - see here
XGator eWalletgator.exeGator eWallet adware. Please note that Claria Corporation no longer support GAIN-Supported software - see here
XGay_Sexy_**Gay_Sexy_**.exePremium rate adult content dialler (where * is a random char)
UGazelDisplaygsyno.exeBT Digital Access USB - Gazel ISDN installation System Tray icon
YGBMHome7AgentGBMAgent.exeGenie Backup Manager Home 7 - backup software
YGBMLite7AgentGBMAgent.exeGenie Backup Manager Lite 7 - backup software
YGBMPro7AgentGBMAgent.exeGenie Backup Manager Pro 7 - backup software
YGBSpaceManSpaceMan.exeGreenBorder - secure your browsing activities on the internet
UGBTrayGBTray.exeSystem Tray icon access to Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
XgCacgcac.exeAdded by the TACTSLAY.U TROJAN!
XgcasDtServgcasDtServ.exeAdded by an unidentified WORM or TROJAN. Note - this is not related to Microsoft Antispyware which has a process bearing the same name which doesn't appear as a startup
YgcasServgcasServ.exeGiant Antipsyware - now superseded by Microsoft's Windows Defender
XgcasServrealsched.exeAdded by a variant of the TACTSLAY.A TROJAN! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name
?GCC Remindergccrem.exeAssociated with AcraMax Greeting Card Creator. Is it a registration reminder?
NGCSGrabClipSave.exeGrabClipSave screen capture tool
Xgcwgcw.exePart of BestsellerAntivirus, PCSecureSystem and other members of the AVSystemCare family of rogue security software suites. See here for more examples
Xgdagdgajsbbsbw.exeAdded by the SDBOT-QX WORM!
XGDAX[path to backdoor]Added by the RANKY.K TROJAN!
XgdcwGDCW.exePart of ContentEraser, WinAnonymous and other members of the PCPrivacyTool rogue privacy tool and other members of this family. See here for more examples
XGddlibrundll32.exe gddlib.dll,startAdded by the AKBOT.EG WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "gddlib.dll" file is found in %System%
YGDFirewallTrayGDFirewallTray.exeSystem Tray access to the firewall part of G Data range of internet security products
Xgdien32gdien32.exeAdded by the SINGU-P TROJAN!
Xgdimxgdimx.exeMPB-D dialer. Note - provides an uninstall option which can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as "gdimx"
UGDMgr.exegdmgr.exeGuardMon is a commercial surveillance software program designed to monitor all forms of user activity on a computer
NGDriveGDriver.exeFound on IBM systems. All it does is set the CDROM drive letter to G:. Set your drive letter manually via Start -> Settings -> Control Panel -> System -> Device Manager
NGearboxconfsvr.exeNTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available here
NGEARsecgearsec.exeInstalled by Apple Quicktime package - iPod®/iTunes® CDRW support. Can be disabled if you only require Quicktime player
XGEDZACGEDZAC.exeAdded by the GEMEL WORM!
XGekio Startupsgnksvc32.exeAdded by the AGOBOT.AFJ WORM!
NGemStRmWGemStRmW.exeFor a GemPlus smart card reader. If it doesn't start automatically when you insert the smart card, start it manually
Xgencrootgencroot.exeAdded by the SDBOT-AED WORM!
UGene USB MonitorUSBMonit.exeMonitors USB ports for insertion of Sandisk USB flashdrives
XGeneral AntivirusGenAvir.exeGeneral Antivirus rogue security software - not recommended, removal instructions here
Xgeneral lptt01general.exeRapidBlaster variant (in a "General" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
Xgeneral ml097egeneral.exeRapidBlaster variant (in a "General" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
XGeneric Hostwauclt.exeAdded by the SDBOT-DNL WORM!
XGeneric host proccess for windowsSVCHOSTS.EXEAdded by the SPYBOT-GQ WORM!
XGeneric Host ProcessSCHOST.EXEAdded by the RBOT-NC WORM!
XGeneric Host Processsvchost.exeAdded by the DLOADER-NX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XGeneric Host Processcamacttiv.exeDetected by AVG as the CIADOOR.13 TROJAN!
XGeneric Host Processlsassw.exeAdded by the AGOBOT-N WORM!
XGeneric Host Process for Win Servicesmscvs.exeAdded by a variant of the SDBOT WORM!
XGeneric Host Process for Win32 Servicesvlhost.exeAdded by the WOOTBOT.EX WORM!
XGeneric Host Process for Win32 Servicerpchost.exeAdded by the IRCBOT.DCN WORM!
XGeneric Host Process for Win32 Servicesntspcv.exeAdded by the SDBOT.S TROJAN!
XGeneric Host Process for Win32 Servicesintspvc.exeAdded by the DINFOR.D WORM!
XGeneric Host Process for Win32 Serviceswinsvc.exeAdded by the SDBOT-O WORM!
XGeneric Host Process for Win32 Servicesbazzi.exeAdded by the AHKER.E WORM!
XGeneric Host Process for Win32 Serviceswinsvc32.exeAdded by the SDBOT-P WORM!
XGeneric Host Process for Win32 Serviceslspsvc.exeAdded by the MUMU.C WORM!
XGeneric Host Process for Win32 ServicesSPSVC.EXEAdded by the SDBOT.DA WORM!
XGeneric Host Process for Win32 Servicessvchost32.exeAdded by the AGOBOT.ALH WORM!
XGeneric Host Process for Win32 Servicessvñhîst.exeAdded by the DLOADER.AK TROJAN!
XGeneric Host Process for Win32 Serviceswinlogon.exeAdded by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!
XGeneric Host Process For Win32 Servicesmtsc32.exeAdded by the VB-CPL TROJAN!
XGeneric Host Process for WinXP Servicesmshelp.exeAdded by the AGENT-GQP TROJAN!
XGeneric Host Process2 System Backupscvhost2.exeAdded by the RBOT-BAH WORM!
XGeneric Host Process326a System Backupscvhost326a.exeAdded by a variant of the SDBOT WORM!
Page: 1 2 3 4

The autorun list is presented in association with Sysinfo.org

Our Tip: a-squared Anti-Malware - Best In Test!

a-squared Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner