Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 227 autoruns. Autorun 1 to 100:

StatusAutorun nameCommandDescription
XK2ps_full.taskK2ps_full.exeAdded by the JUNTADOR.K TROJAN!
NK6CPU.EXEK6CPU.EXEAuthenticates CPU as K6 in system properties
XkaaSVCHHS.exeAdded by the AGENT-JKP TROJAN!
XKadoc[random filename].exeAdded by the STAPREW TROJAN!
UKADxMainKADxMain.exeSystem Tray access to IntelliSonic Speech Enhancement - by Knowles Acoustics. Designed to render speech from a user selectable direction, while canceling interfering speech from other directions, thus minimizing the effects of environmental noise and eliminating acoustic echo feedback. Found on some Dell and Fujitsu Seimens laptops
Xkakkak.htaAdded by the KAKWORM WORM!
UKalenderKalender.exeUK's Kalender "helps you organizing your dates and tasks and reminds you of upcoming events"
UKalibumpKalibump.exeUsed with the now unsupported Kali software for on-line gaming. This is used to automatically bump up the priority of WinProxy to GREATLY improve game speed when using a SOCKS proxy
Xkalvsyskalv****.exe [* = random char]EliteBar adware
Xkalvsyskalv***32.exe [* = random char]EliteBar adware
Xkamsoftckvo.exeAdded by the GAMANIA-BW TROJAN!
NKana ReminderReminder.exeKana Reminder is a program which can be used to set a reminder to be triggered at a specified time
UKaren's Once-A-Day IIPTOAD.exe"Have a job that should be run exactly once each day? Karen's Once-A-Day II is just what you need!" Scheduler that lets you specify progams, web pages and files that be run or opened automatically, the first time
UKASPOESpamTest.exeKaspersky Anti-Spam
XKasper AntivirusKASPERANTIVIRUS.EXEAdded by a variant of the SPYBOT WORM!
YKaspersky Anti-HackerKAVPF.exeKaspersky Anti-Hacker personal firewall - no longer available
YKaspersky Anti-Virus MonitorAvpM.exeKaspersky Anti-Virus Lite - no longer available
XKaspersky AntivirusKasperskyAV.exeAdded by a variant of the RBOT WORM!
XKaspersky Email Securityjavaupd.exeAdded by the SWARLEY.A WORM!
Xkaspersky32kasperskyLabs32.exeAdded by the RBOT-GOT WORM!
XKasperskyAvkaspersky.exeAdded by the MIMAIL.T WORM! Note - this has nothing to do with the real Kaspersky anti-virus
XKasperskyAVEngKasperskyaveng.exeAdded by the NETSKY.V WORM!
XKATKAT.vbsAdded by the SOAD-D WORM!
UKatMouseKatMouse.exeKatMouse - utility to enhance the functionality of mice with a scroll wheel, offering 'universal' scrolling, etc
Ykavavp.exeKaspersky anti-virus and AOL's Active Virus Shield (by Kaspersky) - found in either a Kaspersky or AOL sub-directory
Xkavakavo.exeAdded by the LINEAG-GLG TROJAN!
XKAVFOXwin1ogoin.exeAdded by the GWGHOST-M TROJAN!
Xkavirkavir.exeAdded by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example
XKAVPersonalsvchost.exeAdded by the LINEAGE-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
YKAVPersonal50Kav.exeKaspersky Anti-Virus Personal 5.0
XKAVPersonal90wscntfy.exeAdded by the BANKER-FZ TROJAN!
YKavPFWKavPFW.exeKingSoft Personal Firewall
XKavRunsWindll.exeAdded by the TRYNOMA TROJAN!
Xkavssvchost.exeAdded by the AGENT-GLC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
YKavStartKAVStart.exeKingSoft Personal Firewall
Ykavsvckavsvc.exeKaspersky antivirus
XKavSvc******.exe reg_run [* = random char]Added by the QOOLOGIC TROJAN!
Xkavsvc[random 6 char filename]Added by the QOOLOGIC TROJAN! Uses random file names (examples: nzkklz.exe, rzazzi.exe, ivpaan.exe)
XKAVutil[worm filename]Added by the WINTOO.B WORM!
NKAZAAkazaa.exeKAZAA is a file-sharing program which unfortunately being ad-based includes "Cy-door" adware. Check here for information about "Cy-door" and here for a program that can remove it
NKAZAA[path] kpp.exe [path] kazaalite.kppSystem Tray access to later versions of the Kazaa Lite P2P file sharing utility - namely the K++ and Resurrection variants. Kazaa Lite is the unauthorized modification of the original Kazaa Media Desktop - with the malware removed
XKazaa Download Accelerator Updater (required)regsvr32 kdp****.dll [* = random char]SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%
XKazaa lptt01kazaa.exeRapidBlaster variant (in a "kazaa" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name
XKazaa ml097ekazaa.exeRapidBlaster variant (in a "kazaa" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name
XKAZAACuf9Added by the KITRO.D (or ARGEN.A) WORM!
Nkazaalitekazaalite.exeKazaalite is a file sharing client - not to be confused with the original Kazaa program. Unlike the original, this one does not contain any advertising or tracking mechanisms
NKaZooMKaZooM.ExeKaZoom from Blue Haven Media - "add-on application that automatically speeds up the download process and finds the files you want with far more power than regular KaZaA searches"
XkbAUTO.txtAdded by the BRONTOK-CV WORM!
YKB891711KB891711.exeInstalled by the Windows KB891711 critical update, see this security bulletin - this file reportedly needs to continue running in order to patch the vulnerability, at least until a more practical solution is found. There have however been reports of fatal exception errors in systems running Windows 98, and in such a case Microsoft advises to either uninstall the patch (Add/Remove Programs) or prevent it from running at startup
YKB918547KB918547.EXEBug-fix for a Microsoft graphics rendering engine vulnerability - see here. Windows 98/Me only
YKB926239rundll32.exe apphelp.dll, ShimFlushCacheMicrosoft KB926239 fix. Windows Media Player 10 may close unexpectedly on a Windows XP-based computer
UKBDKBD.EXEMultimedia keyboard manager. Required if you use the multimedia keys
UKBDKbdStub.EXEKey Watcher from HP - watches for Multimedia Keys on HP keyboards
UKBD MediaCenterMEDIACTR.EXEMultimedia keyboard manager. Required if you use the multimedia keys
Xkbddrv32kbddrv32.exeAdded by the CRYPTER.A TROJAN!
Xkbddrvinfkbddrvinf.exeAdded by the CRYPTER.A TROJAN!
NKCeasyKCeasy.exeKCeasy - a Windows peer-to-peer filesharing application which uses giFT as its 'back end' foundation. The networks currently supported are OpenFT and Gnutella
UKClientkstatus.exeKClient Kerberos client software for Win32 systems. It provides the libraries and utilities needed to use Kerberos-based PC applications developed by Computing Services such as KWeb and NiftyTelnet
XKcrnerKcrner.exeAdded by the LINEAG-AIL TROJAN!
Xkdmsx[8 random letters].exeAdded by the SDBOT.AIJ BACKDOOR!
NkdxKHost.exeVerisign Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops
UKE9801DriBat32.exeKE9801 multimedia keyboard driver - required if you use the multimedia keys
XKeenvalueKeenvalue.exeKeenVal adware
XKeepCopKeepCop.exeKeepCop rogue security software - not recommended, removal instructions here. A member of the AntiAID family
XKeepCop.exeKeepCop.exeKeepCop rogue security software - not recommended, removal instructions here. A member of the AntiAID family
Xkeiopkeiop.exeAdded by the VB-ERU TROJAN!
Xkellliser.exeAdded by the AGENT.AUTP TROJAN!
UKEMailKbKEMailKb.EXEControls the buttons at the top of the Micro Innovations 650i Internet Access Keyboard. If you disable it you cannot use the buttons - like volume control or shut down
?Kemetkemet.exe??
UKeNotifyKeNotify.exeToshiba utility found on their laptops. This program is responsible for the Toshiba LapTop Help 'FlashCards' utility that sits at the top of the screen giving easy access to the 'F keys' alternative functions such as Lock,Power Mode,Sleep etc
XkERekERe.exeAdded by the BRONTOK-BT WORM!
UKerio VPN Clientkvpnclient.exeKerio VPN Client
Xkern64dll[random filename]Added by the TARNO.J TROJAN!
XKernal Fault Checkntosrkl.exeAdded by a variant of the SDBOT WORM!
Xkernctl32rundll32 kctl32.dll, initializeAdded by the AGENT.AT TROJAN!
XKerne0223Kerne0223.exeAdded by the LEGMIR-ZA TROJAN!
XKernelbboy.exeAdded by the MUMU.B WORM!
XKernelservices.exeAdded by the FOOZ-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
Xkernelkernel.exeAdded by the MATCASH.CF TROJAN!
XKernelUpdate.exeAdded by the DELF-FN TROJAN!
XKERNEL 32SKERNEL32.comAdded by the SEMAPI-A WORM
UKernel and Hardware Abstraction LayerKHALMNPR.EXEPart of Logitech's SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice, trackballs, etc). When using SetPoint to adjust the mouse sensitivity it is maintained separately from the Windows setting, but is combined with the Windows setting to determine the final sensitivity. For this reason, this entry sets the Windows setting to 0 so it doesn't affect the one you set in SetPoint and then unloads. A separate instance of KHALMNPR.EXE loads via the main Setpoint.exe program to control communication between your radio/bluetooth wireless mouse/keyboard and SetPoint
XKernel Faultsftphost.exeAdded by the RBOT.BHU WORM!
XKernel Loaderntkrnl.exeAdded by the CERVIVEC.A WORM!
XKernel Managerkrnlmgr.exeAdded by the JUNY.A TROJAN!
XKernel Safe Modesmss.exeAdded by the 78CRACK-A TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XKernel Servicesservice32.exeAdded by the PRX-B TROJAN!
Xkernel system daemonACTIVAT0R.exeAdded by the RANDEX.AW WORM!
XKernel_checkwmiprvse.exeAdded by the SONEBOT-B WORM! Note - this is not the legitimate wmiprvse.exe process which is always located in the %System%\wbem folder and should not normally figure in Msconfig/Startup!
Xkernel12.exekernel12.exeAdded by an unidentified WORM or TROJAN!
Xkernel32kern32.exeAdded by the BADTRANS.A WORM!
XKernel32Kernel32.exeAdded by a number of VIRUSES, WORMS and TROJANS!
Xkernel32kernel.dliAdded by the NETDEVIL.B TROJAN!
XKernel32Kernel.dllAdded by the REDLOF.M VIRUS!
Xkernel32kernel32.dlIAdded by the NETDEVIL.15 TROJAN!
XKernel32krnl32.exeAdded by the EPON WORM!
XKernel32Kernel32.winAdded by the GAGGLE.D or GAGGLE.E WORMS!
XKernel32kernel32s.exeAdded by the BCKDR-CIC BACKDOOR!
Xkernel32kernel32.dll.vbsAdded by the WEKODE-A WORM!
XKernel32svchosts.exeAdded by an unidentified WORM or TROJAN!
Page: 1 2 3

The autorun list is presented in association with Sysinfo.org

Our Tip: a-squared Anti-Malware - Best In Test!

a-squared Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner