Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 3127 autoruns. Autorun 501 to 600:

StatusAutorun nameCommandDescription
XService aresconmysys.exeAdded by the VBINJ-V WORM!
XService arestanga.exeAdded by the IRCBOT-AHO TROJAN!
UService Centrelauncher.exeManagement tool for the Open Networks iConnect series of products - as used by Australian ISP's such as iiNet and Hotkey
XService Cleanerfilen.exeAdded by the RBOT.BRH WORM!
XService Clientwinsvcli.exeAdded by an unidentified WORM or TROJAN! See here
NService Connectionsccenter.exeFor Compaq PC's. Part of Backweb
NService Connectionbwtray.exeFor Compaq PC's. Part of Backweb
XService Control Managerscm.exeAdded by the AGOBOT-GD BACKDOOR!
XService ControllerCsrrs.exeAdded by the GAOBOT.AO WORM!
XService Controllerservice.exeAdded by the PREVERT TROJAN!
XService Defender[random filename]Added by a variant of the ZLOB TROJAN! See here
XService Driversmsnpg.exeAdded by the RBOT.BMD WORM!
XService DriversPC.EXEAdded by the SDBOT-WK WORM!
XService DriversCompt.exeAdded by the RBOT-ZJ WORM!
XService Driversabl.exeAdded by the SDBOT-YX WORM!
XService DriversMSNMEssenger.exeAdded by a variant of the RBOT WORM!
XService Hostsvchost.exeAdded by the TORVEL WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XService Host[filename].exeAdded by the TORVEL.B WORM!
XService Hostspoolxx.exeAdded by the TORVEL WORM!
XService Hostsvchost.exeAdded by the DAOSER-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\Services\{C922CCC4-CF61-4589-A0D1-828160704853}
XService Hostsvchost.exeAdded by the DAOSER-C TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\Services\[random]
XService Hostsvchosts.exePornCleanser spyware
XService Hosttm32.exeAdded by the POISON-AG TROJAN!
XService Host Driversvchost.exeAdded by the HITON TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XService Host Managersvchost.exeAdded by the AUTORUN-CQ WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%
XService Host Processspoolsvc.exeAdded by the GAOBOT.GEN!POLY WORM!
NService Managersqlmangr.exeSQL Server Service Manager - provides tray access to SQL server, the server agent and MSDTC. Available via Start → Programs
XService ManagerSERVICEMGR.EXEAdded by the PASSMAIL-D VIRUS!
XService Managerdxsound.exeAdded by the PROXY-GRIC TROJAN!
Xservice managerservice.exeAdded by the DONBOMB.A TROJAN!
XService Managerserv3manager.exeAdded by the SDBOT-AGO WORM!
XService Monitormsnfilen.exeAdded by the RBOT-ALE WORM!
XService Monitorjavams32.exeAdded by the DELF-NK TROJAN!
XService Monitorjavams64.exeAdded by the SDBOT-AFO WORM!
XService Monitormsnserve.exeAdded by the SPYBOT.YQW WORM!
XService MonitorWinOcx.exeAdded by the RBOT-AQJ WORM!
XService Monitorcsnss.exeAdded by the RBOT.EEH BACKDOOR!
XService Monitorfilen.exeAdded by a variant of the RBOT WORM!
XService Monitorwinxpser.exeAdded by the RBOT-BDF WORM!
XService Noitswinservl.exeAdded by the MDROP-DKO TROJAN!
XService Noutswinservi.exeAdded by the AGENT-RDZ TROJAN!
XService Pack[various filenames]Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe, common.pif, common.scr, Sexo.exe, Sexo.jpg.pif, ini_file__.pif, load_me__.tmp, msfile.pif, system_load_.pif or zipped.rar.pif
XService Pack 1[random filename]Added by the VXGAME.Z TROJAN! Note - the filename is random - see the link. Typical examples are vexg6ame4.exe, vexga3me2.exe, vexga4m1et4.exe, etc
XService Pack 1SPY_NET_RAT.exeAdded by the AGENT-LRO TROJAN!
XService Pack 2SPY_NET_RAT.exeAdded by a variant of the AGENT-LRO TROJAN! See here and here
XService Pack DLL Runtimespdll32.exeAdded by a variant of the RBOT WORM!
XService PAck SFVP[worm filename].exeAdded by a variant of the RBOT WORM! The filename is 4 random characters
XService ProcessSVCHOST.EXEAdded by the DARKER WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XService Processwinset.exeAdded by a variant of the SPYBOT WORM!
XService Processservice.exeAdded by the DCMBOT-C TROJAN!
XService Processsmss.exeAdded by the DCMBOT-E TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "config" subfolder
XService Processsvchost.exeAdded by the DCMBOT-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "config" subfolder
XService Registry NT Savejdbgmgrnt.exeAdded by the BANCOS-CG TROJAN!
XService Registry NT Savetaskmgrnt.exeAdded by the BANCOS-BY TROJAN!
XService Registry NT Saveregeditnt.exeAdded by the BANCOS-BM TROJAN!
XService Schedulerscheduler.exeAdded by the AGOBOT-PH WORM!
XService Systemkernels32.exeAdded by the BANCOS-DA TROJAN!
XService SystemwindowsXP.exeAdded by the BANCOS-EL TROJAN!
XService Systemkgbfsm344.exeAdded by the BANCOS-FS TROJAN!
XService Systemwernell87.exeAdded by the BANCOS-FJ TROJAN!
XService Systemsoftdwind.exeAdded by the BANCOS-JS TROJAN!
Xservice updaerqualityz.exeAdded by an unidentified VIRUS, WORM or TROJAN! - probably a SPYBOT variant
XService Update Clientsvcupdcli.exeAdded by an unidentified WORM or TROJAN! See here
XService.exeService.exe"servedby.advertising" popup generator
XServiceSERVICES.EXEAdded by the BRONTOK-BH WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS
XService2Service2.exeIdentified as a variant of the Win32.Iroffer malware. Located in %Windir%\Drivers\Intel
Xservice32service32.exeAdded by the AGOBOT-ST WORM!
Xservice32.exe[path to trojan]Added by the DLOADR-AYX TROJAN!
XServiceAdministratorSERVICES.EXEAdded by the KORRON.B WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS
UServiceConfigispbeg.exeComcast Transition Wizard. On June 30th, 2003 it will migrate E-mail and web pages from AT&T Broadband Internet to Comcast High-Speed Internet. Until then it will run at startup and then terminate - hence the U recommendation
Xserviceconnectserviceconnect.exeAdded by the AGOBOT.AIR WORM!
XServiceControlAppservices.exeAdded by the SILLYFDC.BDO WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root directory (i.e. C:\ or D:\)
XServiceeservices.exeAdded by the AGENT.DEI TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XServiceHostsvch0st.exeAdded by the VB.HE VIRUS!
XServiceHstsvcnost.exeAdded by the AGOBOT-RS WORM!
Xservicelayerservicelayer.exeAdded by the RENOS.FJ TROJAN! Note - do not confuse this with the Nokia service of the same name which resides in %ProgramFiles%\Common Files\PCSuite\Services or %Program Files%\PC Connectivity Solution. This one is located in %Windir%
Xservicemngservice.exeAdded by the TAME-C WORM!
XServiceOptionMP3winamp.dll.exeAdded by the SAMSON-A TROJAN!
XServicerservcr.exeAdded by the SDBOT.BAH TROJAN!
XServicerepclient1SERVICES.EXEAdded by the BRONTOK-BT WORM and variants! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS
Xservicesstart.batAdded by the ZCREW TROJAN!
XServices[path to trojan]Added by the METEORSHELL TROJAN!
XServicesback32.exe ...service.exeAdded by an unidentified VIRUS, WORM or TROJAN! Back32.exe is the baddie whose purpose is to HIDE the MIRC32 server in service.exe
XServicesservices.exeAdded by a number of VIRUSES, WORMS and TROJANS! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup!
XServiceswinread.exeAdded by an unidentified VIRUS, WORM or TROJAN!
XServiceswindns.exeAdded by a variant of the RBOT WORM!
XServicesmshost.exeAdded by the LANFILT-J TROJAN!
XservicesSvchosts.exeAdded by the SDBOT-N TROJAN!
XServicescsrss.exeAdded by a variant of the RANKY.U TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!
XServicesscks32.exeAdded by a Trojan-Proxy variant. The file is located in %Root% (i.e. C:\ D:\, etc)
XServicessockys32.exeAdded by the RANKY.L TROJAN!
XServicessys.exeAdded by a Trojan-Proxy variant. The file is located in %Root% (i.e. C:\ D:\, etc)
Xserviceswindows32.exeAdded by the FLYVB-C WORM!
Xservicessocks.exeAdded by the WIN32.SMALL.N TROJAN!
XServicesservices.exeAdded by the ZINCITE.A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XServices[path to trojan]Added by the RANCK-DB TROJAN!
XServicesiexplore.exeAdded by the MOGI WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%
XServicessvchost.exeAdded by the REPER-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XServicessysamp.exeAdded by a variant of the SDBOT WORM!
XServicesprosys32.exeAdded by an unidentified WORM or TROJAN!
Page: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner