Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 3127 autoruns. Autorun 1901 to 2000:

StatusAutorun nameCommandDescription
XSunJavaUpdaterjavaw.exeAdded by the MYTOB.QR WORM! Note - this is not the legitimate Oracle (was Sun Microsystems) file of the same name located in %ProgramFiles%\Java which is used to view Java applications. This one is located in %System%
XSunJavaUpdaterv12javajar.exeAdded by the VBINJECT-D MALWARE!
XSunJavaUpdaterv13javaupdater.exeAdded by the ROUTROBOT WORM!
NSunJavaUpdateSchedjusched.exeChecks with Oracle's (was Sun Micrsosystems) Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now
XSunJavaUpdateSched[path to trojan]Added by the BANKER-AU TROJAN!
XSunJavaUpdateSchedscvhost.exeAdded by the SDBOT-AVX WORM!
XSunJavaUpdateSchedjavamx.exeAdded by the SDBOT-WI WORM!
XSunJavaUpdateSchedjavaupd.exeAdded by the SISCOS.VA TROJAN!
XSunJavaUpdateSchedjusched.exeAdded by the AGENT.ETQ TROJAN! Note that this is not the legitimate Oracle (was Sun Microsystems) file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %ProgramFiles%\Common Files
XSunJavaUpdateSchedrundll32.exeAdded by the VBKRYPT.FNL TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (Windows 7/Vista/XP/2K/NT). This one is located in %AppData%
XSunJavaUpdateSched v2jushed.exeAdded by the ACKNATTA.B WORM!
XSunJavaUpdateSched v3jucshed.exeAdded by the AUTORUN-ABC WORM!
XSunJavaUpdateSched v3.3jushed.exeAdded by the BUZUS.ASUU WORM!
XSunJavaUpdateSched v3.4jshed.exeAdded by the BUZUS.AUUB TROJAN!
XSunJavaUpdateSched v3.5javacq.exeAdded by the PROLACO-A WORM!
XSunJavaUpdateSched10jushed.exeAdded by the ACKANTTA.F WORM!
XSunJavaUpdateSched132jschd.exeAdded by the AUTORUN-AQY WORM!
XSunJavaUpdateSched16jvshed.exeAdded by the ACKANTTA.G WORM!
XSunJavaUpdatSchedspoolsv.exeAdded by the BANCBAN-NP TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %ProgramFiles%\MSN Messenger
USunkistshwicon98.exeCard reader for memory cards from digital cameras, etc
USunkist2kshwicon2k.exeCard reader for memory cards from digital cameras, etc
USunKistEMshwiconem.exeUsed by your computer to communicate with your Alcor Micro Multimedia Card Reader - necessary if you're using this software
USuNotificationsuatshut.exeShadowSurfer - "provides a safe computing environment by creating a virtual twin of your PC. Restore the pre-ShadowMode system state no matter what changes have occurred to your PC"
YSunProtectionServerSunProtectionServer.exeCounterSpy antispyware software
YSunServerSunServer.exeCounterSpy antispyware software
USup_SmartRAMSup_SmartRAM.exeSmartRAM - the memory management part of the Advanced SystemCare 3 optimization utility from IObit - which "monitors you system in the background and frees up memory whenever needed to increase the performance of your computer." Note - in November 2009 IObit were accused of stealing database information from Malwarebytes' Anti-Malware and others so review the links on the Wikipedia page and make your own mind up
USup_SmartRAM.exeSup_SmartRAM.exeSmartRAM - the memory management part of the Advanced SystemCare 3 optimization utility from IObit - which "monitors you system in the background and frees up memory whenever needed to increase the performance of your computer." Note - in November 2009 IObit were accused of stealing database information from Malwarebytes' Anti-Malware and others so review the links on the Wikipedia page and make your own mind up
?SupaDialSupaDial.exeSupaNet.com modem driver related - is it required?
NSupastatusstatus.exeSupanet ISP software
Xsupdatesupdate.exeAdded by the MALWARE.D TROJAN!
Xsupdate2.dllrundll32.exe supdate2.dll,RunAdded by the ZLOB-VL TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "supdate2.dll" file is found in %System%
Xsupdate2.dllregsvr32.exe /s supdate2.dllAdded by the ZLOB-VL TROJAN! Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The "supdate2.dll" file is found in %System%
Xsuperfuckbx.exeAdded by the LINEAGE-H TROJAN!
Xsupersuper.exeAdded by the AGOBOT-QT WORM!
USuper Popup Blockerpopkill.exeSaga Super Popup Blocker - pop-up stopper
USuper X Desktop Version 3.4SXDesk.exeSuper X Desktop - virtual desktop manager
USuperAdBlockerSAdBlock.exeSuperAdBlocker
YSUPERAntiSpywareSUPERAntiSpyware.exeSUPERAntiSpyware - spyware, malware and other threat remover
XSuperBar.Componentservices.exeFakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an "Inetsrv" subfolder
XSuperBar.Component[path to services.exe]Added by the SMALL-AQ TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\Inetsrv
USupercleanerSupercleaner.exeSupercleaner - all in one disk cleaner for your computer
USuperCool Compress BackupMain.exe"SuperCool Zip Backup software is a data backup, restore and file synchronization program"
USuperCopier2.exeSuperCopier2.exe"SuperCopier replaces windows explorer file copy and adds many features"
XSuperHeissSexSuperHeissSex.exeHeissSex premium rate adult content dialer!
Xsupernews12newsd32.exeAdware, also detected as the DLOADER-JN TROJAN!
XSupernova[worm filename]Added by the SURNOVA.A (or SUPOVA) WORM!
XSupernovaBlaargh.exeAdded by the SUPOVA.E WORM!
Xsuperproxysuperproxy.exeAdded by the DELBACK-B TROJAN!
USuperRamSuperRam.exeSuperRam memory manager. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See SuperRam article and make up your own mind
Xsuperslutmsslut32.exeAdded by the SLUTER-A WORM!
USuperSpamKiller ProSsk.exeSuperSpamKiller Pro email spam blocker
XSuperVaccineMainSuperVaccine.exeSuperVaccine rogue security software - not recommended, removal instructions here
XSupervise.exeSupervise.exeAdded by the DELF-DZX TROJAN!
XSupervisor.exeSupervisor.exeHas been reported to be associated with various antitrojan software like ATS and PC Doorguard. If so it's required in Startup - any further information is welcome
Xsupport-reverse-smileys[trojan filename]Added by the LITEBOT TROJAN!
USupport.com Scheduler and Command Dispatchertgcmd.exePart of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers, fix faults, etc. Also see the TgAddServer entry. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation"
Xsupporter5supporter5.exePart of eScorcher anti-virus software- responsible for updates of new virus bases each time you logon to the web. Used to collect information about the user and therefore treated as spyware - now the web-site is dead
XSupports RAS Connectionssvhost.exeAdded by the RBOT-GXH WORM!
USureCleanProfessionalSRClean.exeSureClean PC and Internet tracks cleaner
USureshotpopupkillerStopthepop.exeStop-the-Pop-Up popup blocker
USureshotpopupkillerpusak.exeStop-the-Pop-Up popup blocker
XSurfAccuracysacc.exeSurfAccuracy adware
XSurfBuddyrundll32 [path] sbuddy.dllSurfBuddy adware - not to be confused with the legitimate SurfBuddy application by SurfApps!. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
USurfChoiceSCMan.exeSCMan is a utility that can control services on WinNT from the command line. This utility can create, start, pause, stop, delete services. Furthermore it can retrieve a service's current state, get the displayname for a service and vice versa
XSurfer lptt01surfer.exeRapidBlaster variant (in a "mssurfer" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it
XSurfer ml097esurfer.exeRapidBlaster variant (in a "mssurfer" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it
USurfHelperSurfHelp.exeRelated to SurfHelper - a free tool to remove popup windows, clear history, control window properties of IE, and more
USurfinGuard Prowinsfcm.exeSurfinGuard Pro from Finjan - internet protection software, protects against all malicious code delivered through executables, scripting files, ActiveX and Java
USurfSecretss2-full.exePrivacy Protector from SurfSecret - internet history and file cleaner "is an easy and powerful tool for users who hold their online privacy sacred"
XSurfSideKickSsk.exeSurfSideKick adware
XSurfSideKick 2Ssk.exeSurfSideKick adware
XSurfSideKick 3Ssk.exeSurfSideKick adware
USurfStreamSurfStream.exeConceiva "SurfStream lets you surf the Web faster. It contains a fully featured proxy server that lets you surf the Web significantly faster. It also blocks all pop-up windows and banner ads from Web pages. An intelligent tune-up tool automatically analyzes and optimizes your computer's Internet connection and TCP/IP settings"
XSursawab.exePurityScan adware
NSurveysasurveysa.exeFound on Sony laptops, it brings up a prompt to take a survey. It goes away if you fill out the survey or you choose "never prompt me again" but keeps popping if you either exit out of it or select "take survey later"
NsuSchedulerUCLauncher.exeScheduler for versions of ThinkVantage System Update (for software updates) found on IBM/Lenovo ThinkCentre/ThinkStation desktops and Thinkpad notebooks
XSuspSusp.exeVX2.Transponder parasite updater/installer related
XSuspenzorPCGDC.exeSuspenzorPC Czech rogue privacy tool - not recommended. A member of the PCPrivacyTool family
Xsussehpsw.exeLinkMaker adware
XSustemexplorer.exeAdded by an unidentified VIRUS, WORM or TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!
XSustemUpdateexplorer.exeAdded by an unidentified VIRUS, WORM or TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!
XSV00LSVSV00LSV.EXEAdded by the GRAYBIRD-C TROJAN!
XSVA PlayerSVAplayer.exeSVAPlayer parasite
XSvcsvc.exeClientMan parasite variant
USVCsvchost.exeElfSpy keystroke logger/monitoring program - remove unless you installed it yourself!
Xsvcexpseny.exeAdded by the PWS-ANG TROJAN!
XSVC Servicesvcinit.exeAdded by the SINIT TROJAN!
XSVC Servicesvcinit.exeCoolWebSearch parasite variant
XSVC Servicesvcpack.exeCoolWebSearch Svcinit parasite variant
XSVC Servicesvc32.pifAdded by the RBOT-ASC WORM!
XSVC Socksmstaskm.exeCoolWebSearch parasite variant
Xsvc32svc32.exeIdentified as a variant of the Banker-EQC/DLoader.GPJI malware
Xsvcdata.exesvcdata.exeAdded by the SPYBOT.ZIF WORM!
XSvcedSvced.exeAdded by the DELF.F TROJAN!
XSvcH0stmsexploren.exeAdded by the BACKDOOR-CGZ TROJAN!
XSvcH0stSHCH.EXEAdded by the BDOOR-EB BACKDOOR!
XSvcH0stSVCHST.EXEAdded by the BDOOR-EB BACKDOOR!
XSvcH0stWINAGENT.EXEAdded by the BDOOR-EB BACKDOOR!
XSVCH0STspoo1sv.exeAdded by the VB-HF TROJAN!
XSVCH0STSVCH0ST.EXEAdded by the VB-IK TROJAN! Note - the filename has the digit 0 rather then the uppercase "o"
Page: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner