Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 3127 autoruns. Autorun 2001 to 2100:

StatusAutorun nameCommandDescription
XSvcH0stmsnexploren.exeAdded by the TACTSLAY.B TROJAN!
XSvcH0stsdhch.exeAdded by the TACTSLAY.B TROJAN!
XSVCH0ST.EXESVCH0ST.EXEAdded by the BANCBAN-HT TROJAN!
XSVCH0TSsp00lvs.exeAdded by the LINEAGE-AZ TROJAN!
Xsvchastsvchast.exeAdded by the LINEAGE-AV TROJAN!
Xsvchctrlsvchctrl.exeAdded by the NURECH TROJAN!
Xsvchossvchos.exeAdded by the EZIBOT-B TROJAN!
Xsvchosd[path to trojan]Added by the BANCOS-BCX TROJAN!
XSVCHOSISVCHOSI.EXEAdded by the VBBOT-AA WORM!
XSVCHOSTscvhost.exeAdded by the MYTOB.E or MYTOB.G WORMS!
XSVCHOSTtaskgmr.exeAdded by the MYTOB.F or MYTOB.H WORMS!
Xsvchostolehelp.exeAdded by the BOOKMARKER.G TROJAN!
XSVCHOSTupdater32.exeAdded by the RANTS.A WORM!
XSVCHOSTSPOOLSV.EXEAdded by the BAITAP-A WORM! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%
XSvcHostsvchost32.exeAdded by the AGOBOT-TM WORM!
Xsvchostsvchost.exeAdded by the BANCBAN-HL TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\config
XSVCHOSTMDM.EXEAdded by the LCJUMP-A WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or %System% (Me only). This one is located in %Windir%
Xsvchost[path to explorer.exe]Added by the UNREAL-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!
Xsvchostrundll16.exeAdded by the STARTPA-PB TROJAN!
XSvchostsvchost.exeAdded by the ADCLICK-AM TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Internet Explorer
Xsvchostsvchost.exeAdded by the BDOOR-ES BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "Microsoft" subfolder
Xsvchostsvchost.exeAdded by the DLOADER-EV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%
Xsvchostwinhelp.exeAdded by the GAOBOT.GEN!POLY WORM!
XSvchostsvchots.exeAdded by the RBOT.ADK WORM!
Xsvchostying.exeConstructor VC2000 malware
Xsvchostinetinfo.scrAdded by the ODELUD WORM!
XSVCHOSTsvchost64.exeAdded by the STARTP-G TROJAN!
Xsvchostsvchost.comAdded by the BANLOA-ABL TROJAN!
Xsvchostwin.exeAdded by the VBSAUTO-A WORM!
Usvchostsvchost.exeInfine Keylogger surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup. This one is located in an "svc" subfolder
Xsvchostlogon.exeAdded by the SLEGON WORM!
Xsvchostsvcst.exeAdded by the AGENT-LIL WORM!
Xsvchostsvchost.exeAdded by the VB-EOK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "MsDtds" sub-directory
Xsvchostwindowsrx.exeAdded by the AGOBOT-MZ WORM!
XSVCHOSTSERVlCES.EXEAdded by the DELF-LF BACKDOOR! Note that the filename has a lower case "L" in place of an upper case "i"
XSvchostwinprint.exeAdded by the AGENT-PGT TROJAN!
Xsvchostconhost.exeAdded by variants of the BACKDOOR-EXI.GEN.E TROJAN! See examples here and here. Note - this is not the legitimate Microsoft Windows 7 process with the same filename which is used to host the cmd.exe console window and is located in %System%. This one is located in %AppData%\Microsoft
Xsvchostsvchost.exe2Search adware. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\2search
XSvchosttaskmmgr.EXEAdded by the AUTORUN-F WORM!
XSVCHOSTsvchost.exeSystem1060 homepage hi-jacker. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\System1060
Xsvchostsvchost.exeAdded by many TROJANS amd WORMS, such as MORB or TARNO. Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!
XSVCHOSTmrowyekdc.exeAdded by the GOTORM WORM!
XsvchostSvch0st.exeAdded by the GRAYBIRD and GRAYBIRD.B TROJANS! Note - the filename has the digit 0 rather then the uppercase "o"
Xsvchost[path to trojan]Added by the HAZZER TROJAN!
XsvchostADMAGIC.EXEAdded by the SMIBAG WORM!
XSvchostwinhost.exeAdded by the LOLAWEB.A TROJAN!
XSvchostsvchost.exeAdded by the MOZE-A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XSVCHOSTvar.txt.exeAdded by the LDPINCH.C TROJAN!
XSvchostsvchosl.pifAdded by the INZAE.A or INZAE.B WORMS!
Xsvchost[path] SETUP.EXEAdded by the SETCLO WORM!
Xsvchost Agentsvchost.exeAdded by the AUTORUN-DB WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "28463" sub-folder
Xsvchost connection monitorsvchost32.exeAdded by a variant of the SDBOT WORM!
XSVCHOST Generic applicationsvchost.exeAdded by the DAEMONI-K TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
Xsvchost Netware Managersvchost.exeAdded by the EXVID.A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XSVCHost Protocol32scvhost32.exeAdded by a variant of the IRCBOT TROJAN!
XSvchost Servicesvchost.exeAdded by the VB-DVQ WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\help
XSvchost Windows Remote Servicessvhost.exeAdded by the IRCBOT-IV WORM!
Xsvchost.exesvchost32.exeCoolWebSearch Svchost32 parasite variant
XSVCHOST.EXESVCHOST.EXEAdded by the WRMSCAN-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
Xsvchost.exe[path to executeable]Added by the BANKER-MO TROJAN!
Xsvchost.exesvchost.exeAdded by the ZAPCHAS-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "drivers" subfolder
Xsvchost.exeswchost.exeAdded by the SADELPHI-A TROJAN!
Xsvchost.exesvchost.exeAdded by the VIRUT.CF WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "3361" subfolder
XSVCHOST.EXEsvchost.exeAdded by the SILLYFDC.BBI WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "Conf" sub-directory
Xsvchost.exesvcnost.exeAdded by the MISLEAD-A TROJAN!
Xsvchost.execsrsc.exeAdded by the BUZUS.AAUP TROJAN!
Xsvchost1svchost1.exeAdded by the AGOBOT.ZZ WORM!
XSVCHost2svchost2.exeAdded by the RBOT.BLC WORM!
XSvcHost32svchost32.exeAdded by the MIMAIL.I or MIMAIL.J WORMS!
Xsvchost32.exesvchost32.exeAdded by the ASSASIN.20B BACKDOOR!
Xsvchost64svchost64.exeAdded by the SDBOTER.G VIRUS!
Xsvchostasvchosta.exeAdded by the SNIFFER-I TROJAN!
Xsvchostbsvchostb.exeAdded by the SNIFFER-J TROJAN!
XSvcHostDHCPsvchost32.exeAdded by the ASSASIN.20B BACKDOOR!
Xsvchostdll.scrsvchostdll.scrAdded by the BANCBAN-FM TROJAN!
Xsvchostn.exesvchosta.exe start4dalifeAdded by the ZOMBIE.SM BACKDOOR!
Xsvchostn.exesvchosth.exe start4dalifeAdded by the ZOMBIE.SM BACKDOOR!
XSvcHostov1rg1n.exeAdded by the AGOBOT-TK WORM!
Xsvchostrsvchostr.exeAdded by an unidentified WORM or TROJAN!
Xsvchostssvchosts.exeAdded by the BANCBAN-DC or BANKER-ED TROJANS!
XSvchostsSCVHOST.EXEAdded by the AGOBOT-RQ BACKDOOR!
Xsvchosts.exesvchosts.exeAdded by the AGOBOT-JN WORM!
Xsvchosts.scrsvchosts.scrAdded by the BANCBAN-DQ TROJAN and variants!
XSVCHOTSVCHOT.exeAdded by the QQROB-U TROJAN!
Xsvchstsvchst.exeAdded by the KBROY-C TROJAN!
Xsvcinfosvcinfo.exeAdded by the CRYPTER.A TROJAN!
XSvclhostsvcchost.exeAdded by an unidentified WORM or TROJAN!
XSvcManagerrestore3.exeAdded by the AGENT-DSS TROJAN!
XSvcManager[path to trojan]Added by the ZALON-A BACKDOOR!
XSvcManagermdmex2.exeAdded by the ZALON-B BACKDOOR!
Usvcmonsvcmon.exePersonInspect surveillance software. Uninstall this software unless you put it there yourself
XSvcnost.exesvcnost.exeAdded by the SELEX.B WORM!
XSvconrSvconr.exeWaveRevenue-lBann adware
XSvcphpwinsslphp32.exeAdded by the AGOBOT-ABR WORM!
Xsvcrootsvcroot.exeAdded by the KEYLOG-AC TROJAN!
Xsvcrootxffanl.exeAdded by the AGENT-BMF TROJAN!
Xsvcs32svcs32.exeAdded by the AGENT-VE MALWARE!
XsvcsharewinampXP.exeAdded by the FUJACKS-J VIRUS!
Xsvcsharespoclsv.exeAdded by the FUJACKS-A VIRUS!
XsvcshareCTMONTv.exeAdded by the FUJACKS-AJ WORM!
Page: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner