Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 24133 autoruns. Autorun 11201 to 11300:

StatusAutorun nameCommandDescription
UMozy Statusmozystat.exeMozy - free backup at a secure, remote location
XMP Servicesmpsvc.exeAdded by the WOOTBOT.EQ WORM!
XMP Tcloakssmptclock.exeAdded by the NACKBOT-B WORM!
XMP Tcloaxsmptcloaxs.exeAdded by the RANDEX.CT WORM!
XMP Tclockvvmptclock.exeAdded by the NACKBOT-A WORM!
XMP Tclockvvmptclock.exeAdded by the NACKBOT-A WORM!
XMP Tclockvvmptclockvv.exeAdded by the RANDEX.CJ WORM!
UMP_STATUS_MONITORmonitr32.exeCannon Multi-Pass status monitor
NMP3 CD ExtractorCD-Extractor.exe"MP3 CD Extractor is an audio CD to MP3 ripper which can extract Digital Audio tracks from Audio CDs into files on the hard disk"
XMp3 LoaderSysdata.EXEAdded by the AVETTE-A VIRUS!
XMP3Collectionrundll32.exe MSA64CHK.dll,DllMostrarMatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System%
XMP3downloadrundll32.exe MSA64CHK.dll,DllMostrarMatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System%
XMP3filesrundll32.exe MSA64CHK.dll,DllMostrarMatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System%
XMP3freeDownloadrundll32.exe MSA64CHK.dll,DllMostrarMatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System%
XMP3freeDownloadsrundll32.exe MSA64CHK.dll,DllMostrarMatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System%
XMP3nicerundll32.exe MSA64CHK.dll,DllMostrarMatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System%
XMP3Themesrundll32.exe MSA64CHK.dll,DllMostrarMatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System%
XMP3ToTheMaxrundll32.exe MSA64CHK.dll,DllMostrarMatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System%
XMP4 Playermp4Player.exeMP4 Player allows you to view MP4 videos. Marked as undesirable due to the fact that it changes your homepage to a custom Google search engine, changes your browser's default search provider, and runs hidden in the background. Terms of use also state that it collects and tracks urls you visit in order to display relevant ads
XMPatrolPROMPatrolPRO.exeMalwarePatrol Pro rogue security software - not recommended, removal instructions here
YMPFExempf.exeMcAfee Personal Firewall
YMPFExeMpfTray.exeMcAfee Personal Firewall
YMPFTrayMpfTray.exeMcAfee Personal Firewall
XMPL32 driverMPL32.exeAdded by the LOONY-M TROJAN!
XMPlay64mplay64.exeAdded by the MPLAY64 TROJAN!
YmpLockDriveLockDrive.exeLockDrive from i8 Technologies makes selected folders and drives read only and can be used to prevent users downloading or copying data to portable drives and memory sticks - i.e., USB, Firewire, SATA, ZIP, etc
UMplSetupMplSetup.exeUsed by Ricoh network printers to enable network printing from the client
XMPM ManagerMPM.exeAdded by the DONBOMB.A TROJAN!
XMPNetmpn.exeAdded by the DELBOT-W WORM!
UMPowerMPower.exeMPower from MindBeat. "Defragments and frees your RAM giving more stability to your system and avoiding needless use of swap file. Willl also benchmark (speed test) your hard disk drives and your CPU load". MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
Xmppddsmppdds.exeAdded by the PWS-AKZ TROJAN!
Xmppdsmppds.exeLEGMIR.AQZ spyware
XMPR MSGmprmsg32.exeAdded by the MYTOB.CF WORM!
XMPREXEMPREXE.EXEAdded by the OPASERV.T WORM! Note - this is not the legitimate Mprexe.exe system file
YMPREXE.exemprexe.exeWIN32 Network Service Interface Process. MPREXE.exe enables the computer to have multiple clients/protocols for networks. There are some problems with it sometimes though - see here. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background. NOTE : sometimes it will appear in start-ups if you have a virus
XMprHTMLMprHTML.exeAdded by a variant of the VAGRNOCKER TROJAN!
Xmprocessormprocessor.exeInstallDollars.com foistware
UMPSExemscifapp.exeMcAfee.com Privacy Service - "combines personal identifiable information (PII) protection with online advertisement blocking and content filtering"
YMpsOnnMpsOnn.exeCanon printer driver
?MPTMPT.exe??
XMPtask Servicesmptask.exeAdded by the LALA or AOT TROJANS!
NMPTBoxMPTBOX.EXECannon Multi-Pass toolbox - a button bar
Xmptsgsvc.exemptsgsvc.exeHacker Tool - detected by DiamondCS TDS-3 anti-trojan as "HackTool.Win32.Hidd.j"
NMPXTraympxptray.exeWindows Media Player PowerToy which is run from the taskbar. It can be used to hide Windows Media Player (when in use) and choose various standard buttons (play/pause, next,previous) etc
Xmqadscp3mqadscp3.exeAdded by the STRATION.CX WORM!
Xmqbkupmqbkup.exeAdded by the OPASERV.K WORM!
XMQT Svcmqtsvc.exeAdded by a variant of the IRCBOT BACKDOOR! See here
XMqtgSVCmqtgsvc.exe /waitserviceAdded by the HORST.Q TROJAN! Note - this is not the legitimate mqtgsvc.exe which is always located in %System%. This one is located in either %Windir%, %Windir%\System, %Temp%, %AppData%, %AppData%\Microsoft or %System%\drivers
XMr_CoolFace_GameEmma.exeAdded by the ROMARIO-A WORM!
UmRoutermRouterConfig.exeConfiguration for Intuwave's m-Router - "that enables easy connectivity between mobile devices and PCs across Bluetooth, Infrared, USB and serial cable connections". It was licensed and used by the Symbian OS but m-Router is no longer readily available since Intuwave went into administration in 2006
UmRouterConfigmRouterConfig.exeConfiguration for Intuwave's m-Router - "that enables easy connectivity between mobile devices and PCs across Bluetooth, Infrared, USB and serial cable connections". It was licensed and used by the Symbian OS but m-Router is no longer readily available since Intuwave went into administration in 2006
Xmrsvctrmrsvctr.exeAdded by a variant of the SDBOT WORM!
YMRTMRT.exeMicrosoft's Malicious Software Removal Tool
NmrtMngrmrtMngr.exeMaintenance Release Task Manager for Intuit's QuickBooks or Quicken
Xmrtwmrtw.exeFake MSRT rogue security software - not recommended, removal instructions here. This rogue imitates the legitimate Microsoft Malicious Software Removal Tool (MSRT)
UMRU-Blaster Schedulerscheduler.exeScheduler for MRU-Blaster - "a program made to do one large task - detect and clean MRU (most recently used) lists on your computer"
NMRU-Blaster Silent Cleanmrublaster.exeMRU-Blaster - performs silent cleaning of MRU lists at boot
UMRUBlasterindexcleaner.exeMRU-Blaster related - runs once in order to delete the index.dat file in the Temporary Internet Files and/or Cookies folder
Xmssvhost32.exeAdded by the LEGMIR-AQO TROJAN!
XMS Agent Protectionag1.exeAdded by the IRCBOT.AZ BACKDOOR!
XMS AntiSpyware 2009msas2009.exeMS AntiSpyware 2009 rogue spyware remover - not recommended, removal instructions here
XMS Auto-IPSec ProtectionMSASP32.exeAdded by the RBOT-AER WORM!
XMS Autoloader 32MSAuto32.exeAdded by the SPYBOT.BD WORM!
XMs BuildersWupated.exeAdded by the AGOBOT-SS WORM!
XMS Configmsdconfig.exeAdded by the RBOT-CZH WORM!
XMS Config Loadersvchos1.exeAdded by the AGOBOT.R WORM!
XMS Config LoaderMSWin32bck.exeAdded by the GAOBOT.AA WORM!
XMS Config Loadersvcrhost.exeAdded by a variant of the RBOT WORM!
XMS Config ServiceMsloader32.exeAdded by the RBOT-KJ WORM!
XMS Config Streammsasm.exeAdded by the AGOBOT-BA WORM!
XMS Config v12mscfg12.exeAdded by the AGOBOT.YP WORM!
XMS Config v13lrbz32.exeAdded by the GAOBOT.AOL WORM!
XMS Config v13mscfg13.exeAdded by the AGOBOT.YQ WORM!
XMs configsumsconfigsu.exeAdded by a variant of the SDBOT WORM!
XMS ConfigurationMSFramer.exeAdded by the RANDEX.OL WORM!
XMs Configurationmicrosoftsa32.exeAdded by the KELVIR.X WORM!
XMS Configuration Utilitymsconfig32.exeAdded by the WOOTBOT.DY WORM!
XMS DATABASEMSDATA32.EXEAdded by a variant of the SDBOT WORM!
XMS Decryption Softwareactive.exeMediaTickets adware variant
XMS DirectX Sound Driversmsdrvdx.exeAdded by the RBOT.BCX WORM!
XMS DLL Library Managerdllsys64.exeAdded by the RANKY TROJAN!
XMS Domain Name Server DeamonMSDNSD32.exeAdded by the RBOT-CMZ WORM!
XMS Domain Name SystemMSWDNS32.exeAdded by the RBOT-GKY WORM!
XMS Driver Management[trojan filename].exeAdded by the THROD.A TROJAN! The filename is a random combination the following: ms, svc, win, 16, 32, 64, mes, prn, reg - "ms16prn.exe", for example - and is located in %System%
XMS DVD DirectX Dll Driversmdxdl.exeAdded by the SDBOT-XI WORM!
XMS DVD DirectX Sound Driversmsdrvdx.exeAdded by the SDBOT-XJ WORM!
XMS Explorermexplore.exeAdded by the YAHA.AE WORM!
XMS FIREWALLmsfrewall.exeAdded by the SDBOT-PU WORM!
XMS FIREWALLmsfirewall.exeAdded by the SDBOT-QH WORM!
XMS Hostmsthost.exeAdded by the SLENFBOT.AH WORM!
XMS Host Managerivhost.exeAdded by the RBOT-BJN WORM!
XMS Hostsmsthosts.exeAdded by a variant of the IRCBOT BACKDOOR! See here
XMS HTMLmsHtml.exeAdded by the PESTDOOR.31 BACKDOOR!
XMS HTMLmslat.exeAdded by the LATINUS.SVR BACKDOOR!
XMS HTML Location ClassMSHTML32.exeAdded by the RBOT-YD WORM!
XMS Initialmstinitial.exeAdded by the IRCBOT.ASP BACKDOOR!
XMS Internet Executor 32MSIXEC32.exeAdded by the RBOT-AEQ WORM!
XMS Internet ExploreMSIEx.exeAdded by a variant of the RBOT WORM!
XMS Java Applets for Windows NT & XPjavaapplet.exeAdded by the RBOT.BHG WORM!
XMS Java Applets for Windows NT, MEjavaapplets.exeAdded by the VANEBOT-B WORM!

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner