Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 3127 autoruns. Autorun 2501 to 2600:

StatusAutorun nameCommandDescription
XSysqqLSESS.exeAdded by the FORBOT-BF WORM!
XSysqqweiba.exeAdded by the DELF-CFX TROJAN!
XSysRsysmd.exeUlubione adult content dialer
XSysRegSysReg.exeAdded by the CHEKIN TROJAN!
XSysRegSysReg.exeSearchSeekFind textual marketing foistware
XSysresSysres.exeAdded by the LOGMOD.A TROJAN!
XSysResTASKMANAGER.exeAdded by the ELIPTER.A or ELIPTER.B WORMS!
XSysResWWE DIVAS.exeAdded by the ELIPTER.D WORM!
XSysResIExpIore .exeAdded by the ELITPER.E WORM!
Xsysrest32.exesysrest32.exeAdded by the AGENT-GIN TROJAN!
Xsysrestore32.exesysrestore32.exeUnknown malware detected by McAfee - see here
XSyssehuupdate.exeEHU adware
XSysScanbvt.exeAdded by the AUTOUPDER TROJAN!
XSysSearchRegedit.exe -s pcsearch.regAdded by the STARTPAGE-FN TROJAN! Note that regedit.exe is a legitimate Microsoft file and shouldn't be deleted. The "pcsearch.reg" file is located in %Windir%
XSysSearchRegedit.exe -s sysreg.regAdded by the STARTPA-ME TROJAN! Note that regedit.exe is a legitimate Microsoft file and shouldn't be deleted. The "sysreg.reg" file is located in %Windir%
USysSenseSysSense.exe"SysSense is your personal desktop Google AdSense monitor. It keeps your current Google AdSense information in the Windows system tray". Google AdSense account required
Xsysser[path to file]Added by the RAHACK WORM!
XSysServiceSysService.exeAdded by the BDFORM-A BACKDOOR!
USysServiceSERVICES.EXENSKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\NSkeylogger
XSysService32SysService32.exeAdded by the KINDAL VIRUS!
XSysService32ln32k.dllAdded by the KINDAL VIRUS!
XSysService32lsystask32l.exeAdded by the THEUG WORM!
XSysServicesSERVICES.EXEAdded by the DELF-EY TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XSYSsfitbSYSsfitb.exeAdShooter adware
XSySSLsysl.exeAdded by the RBOT-CKH WORM!
XSySSLsyssl.exeAdded by the RBOT-DAA WORM!
XSysStart[random filename]ZenoSearch adware
XSysStartsyswin.exe 1Added by the AUTORUN-EY WORM!
XSysStrtsystemc.exeAdded by the AGOBOT-QA TROJAN!
Xsyssvc.exesyssvc.exeAdded by the AGENT-QQM TROJAN!
Xsystsyst.exeAdded by the BANLOAD.BEJ TROJAN!
Xsyst32syst32.exeAdded by the AUTORUN-AFL WORM!
XSystam13f1r5st83.exeAdded by the IRCBOT-YM WORM!
XSystam13exp.exeAdded by the RBOT.ESD BACKDOOR!
XSystam13first.exeAdded by the RBOT.GND BACKDOOR!
XSystam13resx.exeAdded by a variant of the IRCBOT BACKDOOR! See here
XSystam13speedwin.exeAdded by the RBOT.GVH BACKDOOR!
Xsystemwscript.exe [path to worm script]Added by the AUTORUN-FG WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted
Xsystemwind.exeAdded by the AUTORUN.BND WORM!
XSystemnav32.exeAdded by the RBOT-BHV WORM!
XSYSTEMwuamgre.exeAdded by the RBOT-WA WORM!
XSystemwmplayer.exeAdded by the LASY-A WORM! Note - this is not the valid Windows Media Player as the file is located in %Windir% rather than %ProgramFiles%\Windows Media Player
XSystemrun322.exeAdded by the LANFILT TROJAN!
XSystemsystem.exeAdded by various WORMS and TROJANS!
Xsystemregedit -s system.dllHomepage hijacker
Xsystemsystemsearch.htaJetseeker.com hijacker
XSystemdcomx.exeAdded by the CIREBOT TROJAN!
XsystemExplorer.exeAdded by the GRAYBIRD BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
XSystemYPager.exeAdded by the JUNTADOR.K TROJAN! Note - this is not the older version of Yahoo! Messenger which shares the same filename and is located on %ProgramFiles%\Yahoo!\Messenger
Xsystemoutlook.exeAdded by the MIMAIL.Q WORM! Note that the valid Microsoft Outlook executeable is located in %ProgramFiles%\Microsoft Office\Office whereas this one is located in %Windir%
XSystemAtira.exeAdded by the KOTIRA VIRUS!
XSYSTEMlsas.exeAdded by the SPYBOT.CJ WORM!
XSystemkernels32.exeAdded by the DLOADER-FC TROJAN!
USystemsysctrl.exeAdded by WinGuardian. Note - this commercial keylogger is no longer made or sold by Webroot but older copies may still be in existance, those copies will be identified as spyware
XSystemcsrss.exeAdded by the LDPINCH.E TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XSystemSVCHOST.EXEAdded by the LDPINCH-AU TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
Xsystemlsasse.exeAdded by the RBOT-YL WORM!
XSystemsystray.exeAdded by the PISABOY-A TROJAN! Note - this is not the legitimate systray.exe process
XSystemabcdefg.exeAdded by the HARWIG-B WORM!
XSystemcber.exeAdded by an unidentified TROJAN!
XSystemserwin.exeAdded by the LDPINCH-BN TROJAN!
XSystemsvchîst.exeAdded by the LDPINCH-BF TROJAN!
XSystemsystem.exe (74295303)Added by the VB-IU WORM!
XSystemWINL0G0N.EXEAdded by the BANCOS-DB TROJAN!
XSystemwumgrd32.exeAdded by a variant of the RBOT WORM!
XSystemSPOOLSU.EXEAdded by the BANKER-FC TROJAN!
XSystemsystem23.exeAdded by the LEBREAT-D WORM!
XSystemwindowsps.exeAdded by a variant of the RBOT WORM!
XSYSTEMd.exeAdded by the MYTOB.LP WORM!
XSysteminetinfo.exeAdded by the PARDROP-A TROJAN!
Xsystemservices.exeAdded by the DELF-LQ TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\HELP
XSYSTEMVSSMON.exeAdded by the RBOT-AWW TROJAN!
XSYSTEMwiinlogon.exeAdded by the RBOT-AVG WORM!
XSystemkernels64.exeAdded by the VIXUP-S TROJAN!
Xsystemlsass.exeAdded by the SATILOLER.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System
XSystemsmss.exeAdded by the AGENT.EP BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XSystemwinupd.exeAdded by a variant of the SDBOT WORM!
Xsystemmessenger.exeAdded by an unidentified WORM or TROJAN!
XSystemkernels1118.exeAdded by a variant of the SDBOT WORM!
XSystemwsscntfy.exeAdded by a variant of the SDBOT WORM!
XSYSTEMwindmupdr.exeAdded by a variant of the RBOT WORM!
Xsystemsvcr.exeAdded by the SPYONE TROJAN!
XSystemkernels88.exeAdded by the TIBS-PP TROJAN!
XSystemkernels8.exeAdded by the TIBS.AI TROJAN!
XSystemOeApi.vbsAdded by the AGUI WORM!
XSystemUpdaterun.exeAdded by the QQHELP-DX TROJAN!
XSystemZap.exeAdded by the MSNVB-D WORM!
XSystemBrO_AcT.exeAdded by the SILLYFDC-AL WORM!
XSystemJuegs.exeAdded by the CULLER-C WORM!
XSystemkernel8.exeAdded by the DLOADR-AOL TROJAN!
XSystemkernelwind32.exeAdded by the VXIDL.FT TROJAN!
XSystemXsfr.exeAdded by the CULLER-D WORM!
XSystemkernelwind64.exeAdded by the DLOADER.DJD TROJAN!
XSYSTEMSystemFile.exeAdded by a variant of the IRCBOT BACKDOOR! See here
Xsystemssclie.exeAdded by the AGENT.LW BACKDOOR!
XsystemWinhelp.exeAdded by the IMAUT.CN WORM!
Xsystemkernel32.iniAdded by the SILLYFDC.CJ WORM!
XSystemtesttestt.exeAdded by the DWNLDR-ZLC TROJAN!
XsystemMicrosoft Office.exeAdded by the BANCBAN-LH TROJAN!
XSystemIEXPL0RE.EXEAdded by the VB.KS WORM! Note the number "0" in the filename
Page: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner