Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 795 autoruns. Autorun 101 to 200:

StatusAutorun nameCommandDescription
XICU-SuckerService32.exeAdded by the ILLNOTIFIER.D TROJAN!
NID CommanderIDCom.exeCaller ID utility for identifying incoming telephone numbers
XID8525ID8525.exeAdded by the ID8525.A TROJAN!
XID8525id85255.exeAdded by the ID8525.A TROJAN!
?IDAIDA.EXEPart of HP's PC Common Operating Environment (PC COE) project. Located in %ProgramFiles%\Hewlett-Packard\PC COE. What does it do and is it required?
XIDBoanIDBoan.exeIDBoan rogue security software - not recommended, removal instructions here
XIDEide.exeAdded by the ASSASIN.F TROJAN!
XIDE LoaderIDElibr32.exeAdded by the XILON TROJAN! Related to the game "Diablo II"
Xidecntlidecntl.exeAdded by a variant of the CRYPTER.C TROJAN!
UiDesktopidesktop.exeImmersion TouchWare Desktop software for devices such as the Logitech iFeel Mouse
Xidlesam[8 random letters].exeAdded by the ZHELATIN.EQ WORM!
NIDManIDMan.exeInternet Download Manager - download files faster, schedule and resume
Xidmlssp[random filename]Added by a variant of the SLAPER TROJAN!
UIDriveE StartupIDrvieEStartup.exeIDrive from Pro Softnet Corporation - free full featured online backup up to 2GB with the option of paying for more storage space and managing multiple accounts
XIDT PC Audiostatcvs.exeAdded by the DELFINJ-Y TROJAN!
XIDTemplatesIDTemplate.exeAdded by the BRONTOK-H WORM!
NIDW Logging Toolidwlog.exeAdded with WinXP SP1. Usually only found in internal builds only to indicate the current build being used. Can cause slow network logon problems
XIE[path to backdoor]Added by the MSPOSER.KAX BACKDOOR!
XIE configureexplorer.exeAdded by the LINEAGE-C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!
UIE DoctorIEDoctor.exeIE Doctor Toolbar - "IE Doctor can help you to Repair IE easily, protect IE and OE from all malicious changes. It can Repair the HomePage, context menu, IE toolbar button, startup items, Favorites, typed URLs and the entire Internet Options"
XIE Java Updateiejava.exeAdded by the AGENT-HD TROJAN!
XIE Menu Extension toolbarrundll32.exe [path] tbextn.dll DllShowTBIEMenuExt trackware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
UIE New Window Maximizeriemaximizer.exeIE New Window Maximizer - automatically maximize new Internet Explorer and Outlook Express windows
XIE Runtimewini.exeAdded by the PICRATE.B WORM!
XIE Runtimewinlogo.exeAdded by the RBOT-AMJ WORM!
XIE Runtimeswinis.exeAdded by the RBOT-ADZ TROJAN!
XIE**.exe [* = random char]IE**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
XIE**32.exe [* = random char]IE**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
XIE-Securitywdscan.exeIE-Security rogue spyware remover - not recommended, removal instructions here
XIE-Securityiescan.exeIE-Security rogue spyware remover - not recommended, removal instructions here
XIE6wkstmg.exeAdded by a variant of the SDBOT WORM!
XIE6ssmss.exeAdded by the GAOBOT.DXO WORM!
XIE6porn.pifAdded by the RBOT-ATF WORM!
XIE6winsnt.exeAdded by the RBOT-GOV WORM!
XIEACCESStemp532.exeAsdPlug premium rate adult content dialer variant
XIEACCESSsurfya.exeIEAccess premium rate adult content dialer variant
XIEAgent update checkiewatch.exeAdded by the BOMKA TROJAN!
XIECacheIECache.exeDetected by Bitdefender as the DELF.OFC TROJAN! See here
Niecheckiecheck.exeIntegrity checker for IconEdit2 icon editor. It serves for IconEdit2 internal tasks only and can be safely deleted from the system if you are running the latest version of IconEdit2
XIECheckMSDTCs.exeAdded by the TIRBOT-D WORM!
XIECheckxpssl.exeAdded by the TIRBOT-E WORM!
XIECheckmssvp.exeAdded by the TIRBOT-G WORM!
UIECleanAuxIeboot6.exeIEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc. Performs cleaning tasks at startup
Xiedlliedll.exeHomepage hijacker, redirecting to coolwwwsearch.com
XIEDriverIEDriver.exeIEDriver adware. Can be installed as part of peer-to-peer file sharing software called URLBlaze
XIEDriverxplore.exeIeDriver adware variant
XIEDriverTD.exeIeDriver adware variant
Xiedwa104iedwa104.exeAdded by the DLOADR-BBW TROJAN!
UIEEE 802.11g Wireless LAN UtilityWLANUTL.exeWireless LAN configuration utility
UIEEE802.11b WLAN USB Adapter UtilityWLUSBCFG.exeWireless LAN configuration utility
XIEengineIEeng.exeSTARTPAG.AI TROJAN!
XIEexplorer AUpdateIEexplore32.exeAdded by the RBOT-GRE WORM!
XIEFeaturesIEFeatures.exeAdded by the POPMON.A TROJAN! - also known as PopMonster adware
XIEFeaturesInternetfeatures.exeAdded by the POPMON.A TROJAN! - also known as PopMonster adware
XIefxTrayIefxTray.exeAdded by the RILER-H TROJAN!
Xieharv.exeieharv.exeAdded by the BANKER-HH TROJAN!
XIehelpersyslaunch.exeOutwar adware downloader
Xiel2cde8rundll32.exe iel2cde8.dll,EnableRunDLL32LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "iel2cde8.dll" file is found in %System%
Xielcaaberundll32.exe ielcaabe.dll,EnableRunDLL32LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ielcaabe.dll" file is found in %System%
XIELoader32iexplore32.exeAdded by the SPEX or SPEX.B WORMS!
XIesarIesar.exeBrowser hijacker - redirecting to an adult web page
XIesearch.exeIesearch.exeLookNSearch adware
UIEServerIEServer.exeHB Screen Spy surveillance software. Uninstall this software unless you put it there yourself
XIeServersyswin.exeAdded by the HUPIGON.FDNV BACKDOOR!
XIESetIExplorer.dllAdded by the PWS-BLUEDIT TROJAN!
Xiesetupi.exeiesetupi.exeAdded by a variant of the RBOT WORM!
YIEShowIEShow.exeAnti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames, passwords and credit card details being acquired by web-sites and E-mails masquerading as a trustworthy sources. It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poor
Xiestartiexp1orer.exeAdded by the NEMOG.C TROJAN!
Nietsrietsr.exeIEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc
XIeudinitieudinit.exe /waitserviceAdded by the HORST.Q TROJAN! Note - this is not the legitimate ieudinit.exe which is always located in %System%. This one is located in either %Windir%, %Windir%\System, %Temp%, %AppData%, %AppData%\Microsoft or %System%\drivers
XieupdateMCP****.exe [**** = random char]Added by the ASOXY TROJAN!
Xieupdatemcpdll32.exeAdware downloader trojan
Xieupdate[random filename]Added by the AGENT-C BACKDOOR!
Xieupdatesieupdates.exeAdded by a number of TROJANS such as DWNLDR-HGI and AGENT-HGA and the Antivirus 2009 rogue security software - see here
XIEWinservwinserv.exeAdded by the BANKER-MY TROJAN!
XIEXPL0RERIEXPL0RER.EXEAdded by the AGOBOT-QL WORM! Note the filename has a "0" rather than an upper case "o"
Xiexploiexplor.exeAdded by the SIDEA TROJAN!
XIExploersvshosts.exeAdded by the IRCBOT.BT BACKDOOR!
XIexploitIexploit.htmlAdded by the INKER.B WORM!
Xiexplor.exeiexplor.exeAdded by an unidentified WORM or TROJAN! See here
XIexploreiexplore.exeAdded by the BOXER TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%
XIEXPLOREiexplore.exeAdded by the APHEXDOOR TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XIExploreIEXPLORE.EXEAdded by the DLOADER-YZ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in a "Custom" subfolder
XIEXPLOREIEXPLORE.EXEAdded by the BANKER-BWE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%
XiExplore Iniie4uini.exeAdded by a variant of the IRCBOT BACKDOOR! See here
XIexplore Servicesiexplore.exeAdded by the LITHIUM BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!
XIEXPLORE.EXE[path to trojan]Added by the BANCOS-CJ TROJAN!
XIEXPLORE.EXEgoot.exeAdded by the BIFROSE-C TROJAN!
XIExplorerIexplor32.exeAdded by the BDOOR-BY BACKDOOR!
XIExplorerIExplorer.EXEAdded by the BANCOS-CH TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)
XIEXPLORERmsiecfg.exeAdded by the BDOOR-JU BACKDOOR or BANCBAN-IP TROJAN!
XIexplorerexplorer.exeAdded by the ZAPCHAS-AC TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
Xiexplorerwind.exeAdded by an unidentified VIRUS, WORM or TROJAN! See here
Xiexplorer lptt01iexplorer.exeRapidBlaster variant (in a "iexplorer" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it
Xiexplorer ml097eiexplorer.exeRapidBlaster variant (in a "iexplorer" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it
XIexplorer.exeIexplorer.exeAdded by the BANCBAN-EN TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)
XIExplorer32 Java ScriptingIExplore32b.exeAdded by the RBOT.ABO WORM!
XIExplorer32c Java ScriptingIExplore32cb.exeAdded by the RBOT.ABN WORM!
XIExplorer6 Java ScriptingIExplore326.exeAdded by a variant of the SDBOT WORM!
XIExplorer7 Java ScriptingIExplore327.exeAdded by a variant of the SDBOT WORM!
Page: 1 2 3 4 5 6 7 8

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner