Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 3127 autoruns. Autorun 2901 to 3000:

StatusAutorun nameCommandDescription
Xsystem34.exesystem34.exeAdded by the DWNLDR-FXY TROJAN!
XSystem4224411VirusAdded by the CAGER.A WORM!
XSystem4224411Systemdll.exeAdded by the YUSUFALI-B WORM!
Xsystem43.exesystem43.exeAdded by a variant of the SDBOT WORM!
XSystem51616msnmsgesser.exeAdded by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger
XSystem64inet.exeAdded by the DENGLE-A TROJAN!
XSYSTEM798RUNNER.exeSYSTEM798RUNNER.exeAdded by the VB-EYW TROJAN!
Xsystemaddsysdate32.exeAdded by the AUTORUN-AVN WORM!
XSystemAdministrationWincmp32.exeAdded by the ASYLUM TROJAN!
USystemAgentSage.exe"Microsoft Plus! System Agent automatically tunes your system, performing tasks such as disk optimization and error correction. It can also run any application at prescheduled times"
XSystemArmorSystemArmor.exeSystemArmor rogue security software - not recommended, removal instructions here
XSystemBMessengerStopper.exeMessStopper adware
Xsystembsystemb.exeAdded by a variant of the IRCBOT TROJAN!
XSystemBackupmtx.exeAdded by the MTX VIRUS/WORM!
XSystemBackupMicroLog.exeAdded by the MICROLOG.A TROJAN!
XSystemBooster2009sbr_updater.exeSystemBooster2009 rogue system suite - not recommended, removal instructions here
?SystemBootladies.htmUnknown but sounds very suspicious??
XSystemBootMshta.exe ...filename.htaAdult content dialler
XSystemBootservices.exeAdded by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help\Help
XSystembootmsnsngr.exeAdded by a variant of the RBOT WORM!
XSystemCheckSystemcheck.exeAdded by the LAVITS WORM!
XSystemCheckservices.exeAdded by the SOBER-M WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Config\system
XSystemChecksvchost.exeAdded by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "DriverLoad" sub-directory of the Root folder (C:\), (D:\), etc
XSystemCheck[path to file]WinBo adware
USystemchecksb32mon.exePart of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!
XSystemCheckerSyschk.exeAdded by the GALIL.F WORM!
XSystemCleanerClean2.exeAdded by the AUTORUN-AZE WORM!
XSystemCleanerPROsysclpro.exeSystemCleanerPro rogue security software - not recommended, removal instructions here
XSystemCONF98iSystemCONF98i.exeAdded by the GLITCH TROJAN!
XSystemCopSystemCop.exeSystemCop rogue security software - not recommended, removal instructions here. A member of the WiniGuard family
XSystemDataMBlocker.exeMessenger Blocker rogue security software - not recommended
XSystemDebugSysdeb32.exeAdded by the SYSBUG TROJAN!
XSystemDefenderSystemDefender.exeSystemDefender rogue spyware remover - not recommended, removal instructions here
XSystemDevicdevic.exeAdded by the MIMBOT.A WORM!
XSystemDllSystemDll.exeAdded by the LOXOSCAM TROJAN!
Xsystemdll.dllwinsys32.exeAdded by the DELF.CP BACKDOOR!
Xsystemdll32.exesystemdll32.exeAdded by the FEUTEL-F TROJAN!
XSystemDoctor 2006 Freesd2006.exeSystemDoctor rogue security software - not recommended, removal instructions here
XSystemDoctor Freesystemdoc.exeSystemDoctor rogue security software - not recommended, removal instructions here
Xsystemdrearundll32.exe [path] systemdrea.dllAdded by the AGENT-RKB TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "systemdrea.dll" file is located in %UserProfile%\Microsoft
XSystemDrivemaxpaynow1.exeAdded by the TIBS.BKU TROJAN!
XSystemDrivercsrss.exeAdded by the ASCETIC.B TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\addins\explorer
XSystemDriverChecksvchost.exeAdded by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "DriverLoad" sub-directory of the Root folder (C:\), (D:\), etc
XSystemDriverLoadsvchost.exeAdded by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "DriverLoad" sub-directory of the Root folder (C:\), (D:\), etc
Xsystemdrvms32sys.exeAdded by an unidentified WORM or TROJAN - most likely GAOBOT variant
XSystemEmergency[various filenames]CoolWebSearch Smartsearch parasite variant. Also detected as the GOWEH.A WORM! Typical filenames include internet.exe, systeem.exe, explore.exe and directx.exe
XSystemErrorFixerSysRep.exeSystemErrorFixer rogue system error and cleaning utility - not recommended. A member of the ErrClean family
XSystemExplorerexplore.exeHomepage hijacker - file located in the "Services" folder in Common Files
NSystemExplorerSystemExplorer.exeSystem Explorer by Mister Group - a "free, awards winning software for exploration and management of System Internals." Provides detailed information about tasks, processes, startups and services; suspicious file checking via VirusTotal, Jotti and their own database and other resources
NSystemExplorerAutoStartSystemExplorer.exeSystem Explorer by Mister Group - a "free, awards winning software for exploration and management of System Internals." Provides detailed information about tasks, processes, startups and services; suspicious file checking via VirusTotal, Jotti and their own database and other resources
XSystemeysystemey.exeAdded by the SLINBOT.JF BACKDOOR!
XSystemFighterSystemFighter.exeSystemFighter rogue security software - not recommended, removal instructions here. A member of the WiniGuard family
XSystemFileSystemFile.exeAdded by the DULLDOOR-A TROJAN!
XSystemFTPVSENMB.exeMalware (ie, malicious software). Also changes the system.ini Shell line to read Shell=Explorer.exe VSENMB.exe, and it hacks the Winstart.bat as well
XSystemGentCVT.exeAdded by the BRONTOK-H WORM!
Xsystemguardsystemguard.exeSystem Guard 2009 rogue security software - not recommended, removal instructions here
?SystemGuardAlerterSystemGuardAlerter.exePart of the Iolo System Mechanic maintenance software. What does it do?
XSystemGuardCenterSystemGuardCenter.exeSystem Guard Center rogue security suite - not recommended, removal instructions here
XSystemHelpRUNDLL32.EXE SystemHper.dll,InstallAdded by the WOW.COK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "SystemHper.dll" file is found in %System%
XSystemILSYSTEMIL.EXEAdded by the ABOC VIRUS!
XSystemInitiservc.exeAdded by the FIZZER WORM!
Xsysteminitsysteminit.exeAdded by the SILLYFDC-AN WORM!
XSystemiom UpdaterSystemiom.exeAdded by the SPYBOT.TY WORM!
XSystemIronSystemIron.exeSystemIron rogue security software - not recommended, removal instructions here. A member of the WiniGuard family
Xsystemkernal.exesystemkernal.exeAdded by the AGENT-KPQ TROJAN!
USystemKeyrundll32.exe [path] SystemKey.dll rdlStealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
Xsystemkssystemks.exeAdded by the DKS.11.B TROJAN!
XSystemLoad32sysload32.exeAdded by the MIMAIL.E WORM!
XSystemLoadersysldr32.exeAdded by the DOWNLDR-NS TROJAN!
XSystemManagerSysman32.exeAdded by the DOWNLOADER-BW.B TROJAN!
XSystemManager[random filename]Added by the SETTEC ROOTKIT!
XSystemMap32Netisp32.vbsAdded by the REDIST.C WORM!
XSystemMDmd.exeHomepage hijacker
XSystemMessengerrundll32.exe [path] SystemMessenger.dllStealth Chat Monitor spyware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
XSystemMgrIr32_a.exeAdded by the MAGANIA-OU TROJAN!
XSystemMigrationWinMedia.exeAdded by the KELVIR.EI WORM!
XSystemMonitorSysmon32.exeAdded by the AIDID.A WORM!
XSystemNetworkNETSERV.EXEAdded by the NETCONTROL VIRUS!
XSystemNetworksysnet.exeAdded by a variant of the RBOT WORM!
XSystemNTSystemNT.exeAdded by the PWSVB-EG TROJAN!
Xsystemntfysystemntfy.exeAdded by the MINUDAZASH WORM!
XSystemOPsvscrtvc32.exeAdded by a variant of the SPYBOT WORM!
XSystemOptimizer2008main.exeSystemOptimizer2008 rogue optimization utility - not recommended, removal instructions here
XSystemOrdnareSysRep.exeSystemOrdnare, Swedish rogue system error and cleaning utility - not recommended. A member of the ErrClean family
XSystemProcEvent[trojan filename]Added by the IRCBOT.I TROJAN! Filenames used are csrwnd.exe, csrwjd.exe & csrnvrt.exe
Xsystemrd11host.exeAdded by the VB-GX TROJAN!
Xsystemrgedit.exeAdded by the ADCLICK-AQ TROJAN!
Xsystemr[path to trojan]Added by the VB-HD TROJAN!
?SystemRegPROCES.EXE??
XSystemRegsvchost.exeAdded by the DEWIN.E BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XSystemRegWINREG.EXEAdded by the DEWIN.A BACKDOOR!
XSystemRegistryRepairtemp.exeAdded by the NOKPUDA WORM!
XSystemssescmgr.exeAdded by the DWNLDR-GAH TROJAN!
XSystemsspoolsvc.exeAdded by the DLOADR-SW TROJAN!
XSystemssysmon.exeAdded by the VIXUP-BI WORM!
XSystemsscchost.exeAdded by the DAEMOZ.A TROJAN!
XSystemssvch0st.exeAdded by the MYDOOM.BI WORM!
XSystemsSystems.exeAdded by the BANKBOA-A TROJAN!
XSystemsitDDD.exeAdded by the DLOADER-PP TROJAN!
XSystems Backupswindrives.exeAdded by the AGOBOT-RB WORM!
Page: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner