Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 24133 autoruns. Autorun 11401 to 11500:

StatusAutorun nameCommandDescription
XMS-DOS Security Servicems-dos.pifAdded by the RBOT-AMR WORM!
XMS-DOS ServiceMS-DOS.pifAdded by the RBOT-AII WORM!
XMS-DOS Windows ServiceMS-DOS.PIFAdded by the RBOT-AJW WORM!
XMS-HTML[random filename]Added by the LATINUS.15 BACKDOOR!
XMS-Netmsnet.exeAdded by the RBOT-HZ WORM!
XMS-patchmsconfig32.exeAdded by the RBOT-AUF WORM!
XMS-patchmspatch32.exeAdded by the RBOT-AWF TROJAN!
XMS-RunKeyarr.exeMS-Connect dialler/hijacker
Xms[random numbers][path to file]WinBo adware
Xms_anti_spywaremwfirewall.exeAdded by the GAMQOWI TROJAN!
Xms_anti_spywarebxpmwfirebpx.exeAdded by the SURILA-D TROJAN!
Xms_anti_spywarebxpmwfibpx.exeAdded by the SURILA-J TROJAN!
XMS_LARISSAMS_LARISSA.exeAdded by the ASSIRAL WORM!
XMS_NETD_WIN32netd32.EXEAdded by the RANDEX.F WORM!
XMS_SETUP.EXEMS_SETUP.EXEAdded by the CHARGE TROJAN!
XMS_Update Checkwdfmgr.exeAdded by the AGOBOT-TB WORM!
XMS_update_0704_KB74073.exeMS_update_0704_KB74073.exeAdded by a variant of the UPDATEKB TROJAN!
Xms2srcms2src.exeAdded by a TROJAN - see here
XMS32DLLachi.dll.vbsAdded by the ACHI-A TROJAN!
XMS32DLLBha.dll.vbsAdded by the BUTSUR-A WORM!
XMS32DLLMS32DLL.dll.vbsAdded by the ZODGILA WORM!
XMS32DLLffqca.exeAdded by the SDBOT-YD WORM!
XMS7531ms7531.exeHomepage hijacker
XMSACMmsacm.exeAdded by the OPASERV-O WORM!
Xmsadcheckmsadcheck32.exeBrowser hijacker, redirecting to search-system.com
Xmsader15ADOR15datamsadomd2.70.7713.0.exeAdded by the TRITE-A WORM!
XMSAdminjdbgmrg.exeAdded by the DASMIN.A TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here
XMSAgentmshtm.exeBrowser hijacker - redirecting to buldog-search.com
XMSAgenthhnt.exeAGENT.JI spyware
XMSAgentXPMSAgentXP.exeIdentified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the REQLOOK.C TROJAN!
Umsaimmsaolim.exeMessageSpy keystroke logger/monitoring program - remove unless you installed it yourself!
Xmsappts32msappts32.exeAdded by the ELBURRO-A TROJAN!
YMSASCuiMSASCui.exeMain user interface for Microsoft's Windows Defender on XP/Vista - which "helps protect your computer against pop-ups, slow performance, and security threats caused by spyware and other unwanted software by detecting and removing known spyware from your computer". Used in conjunction with the associated service, this entry is always running and the user also has the option to always display the System Tray icon and monitor/control new startup programs
XMsAudioexplorer.exeAdded by the LEGMIR-BY TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
XMsAudioMsVM_STI.EXE RunDll32 cmicnfg.cpl, CMICtrlWndAdded by the LEGMIR-BY TROJAN! Note - this is not associated with C-Media based audio which uses a similar command entry (see here)
Xmsavsc.exemsavsc.exeAdded by the AGENT.ANQ TROJAN!
XMSbackupsbackups.exeAdded by the BANLOAD-TL TROJAN!
Xmsbbmsbb.exe180Search adware
XMsbb.exeMsbb.exeAdded by the SDBOT.QJ WORM!
Xmsbcsmsbcs.exeAdded by the DADOBRA-G TROJAN!
XMsBootMgr.exeMsBootMgr.exeAdded by the VERIFY TROJAN!
Xmsbsc[path to trojan]Added by the BANKER-DF TROJAN!
Xmscmsc.exeMaCatte Antivirus 2009 rogue security software - not recommended, removal instructions here
Xmsccrtmsccrt.exeAdded by the PWS-ALA TROJAN!
UmscfsRUNDLL32 [path] cfsys.dll,cfsAllSum adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "cfsys.dll" file is found in %System%\msibm
Xmscheckrundll32.exe wincheck071008.dll mymainAdded by the AGENT.ADXI TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wincheck071008.dll" file is located in %System%
Xmscheckmscheck.exeAdded by the AGENT-ECP TROJAN!
Xmschkdf.exemschkdf.exeAdded by a variant of the SDBOT WORM!
XMSChoExEsuge.exeAdded by a variant of the RBOT WORM!
?mscimcinfo.exeMcAfee Internet Security related. What does it do and is it required?
Xmscj.exemscj.exeAdded by the BACKDR-L BACKDOOR!
XMSCJACCELERATORbbaka14.exeAdded by the DOWNLOADER-CJD TROJAN!
Xmscjm.exemscjm.exeAdded by the DOWNLOADER-CJD TROJAN!
Xmsclacmsclac.exeAdded by the SDBOT-JM WORM!
Xmscleanmsvchost.exeAdded by the OPANKI-Q WORM!
Xmscmanmscman.exeClientMan parasite variant
Xmscmsmscms.exeAdded by the AGENT-MS TROJAN!
Umscnmscn.exePart of the SafeChildNet internet filtering program - required if you use it
XMscntmscnt.exeAdded by the DLUCA-C TROJAN!
XMscolourmscolour.exeAdded by the GEMA TROJAN!
Xmscom32msint.exeAdded by the SDBOT.CCD BACKDOOR!
Xmscom32mswin.exeAdded by the PEPA-A WORM!
XMScommMScomm.exeAdded by the VBINJEC-AL TROJAN!
XMSCommXmscommx.exeAdded by a variant of the RBOT WORM!
XMsconf32Msconf32.exeAdded by the AGOBOT-NR WORM!
XMSCONFG32.EXEMSCONFG32.EXEAdded by the OPTIX.04.C TROJAN!
XMsconfigicpldrvx.exeAdded by the BANLOAD.BFT TROJAN!
Xmsconfigmsconfig.comAdded by the IRCBOT-SM WORM!
Xmsconfigmsconfig.batAdded by the PAHATIA.B WORM!
XMSConfiglssas.exeAdded by the AUTORUN.CEY WORM!
XMSConfigxwpwqf.exeAdded by the AGENT-NEW TROJAN!
XMSConfigoumy.exeAdded by the AGENT-NGD TROJAN!
XMSConfigprrvtqi.exeAdded by the AGENT-NPH TROJAN!
XMSConfigmapwisl.exeAdded by the PALEVO.NXS WORM!
NMSConfigmsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
XMSConfigMSCONFIG32.EXEAdded by the SPYBOT.B WORM!
Xmsconfigmsconfig.exeCoolWebSearch MSConfig parasite variant. Note - this overwrites the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting
Xmsconfigmsconfig.exeAdded by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrun
Xmsconfigwins.exeAdded by the RBOT.PF WORM!
XMSConfigMSCONFIG35.EXEAdded by a variant of the SPYBOT WORM!
Xmsconfigscvhost.exeAdded by the AGENT-DSF TROJAN!
Xmsconfigwinlog.exeAdded by the IRCBOT-TJ TROJAN!
XMsconfig lptt01msconfig.exeRapidBlaster variant (in a "msconfig" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not the valid Windows Msconfig which has the same executable name
XMSConfig Managermsupdate.exeCoolWebSearch parasite variant
XMsconfig ml097emsconfig.exeRapidBlaster variant (in a "msconfig" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not the valid Windows Msconfig which has the same executable name
Xmsconfig serviceMSupdate32.exeAdded by a variant of the SPYBOT WORM!
Xmsconfig.msconf.exeAdded by the BUZUS-AY WORM!
Xmsconfig.exeproxy.exeAdded by a variant of the AGENT.AH TROJAN!
Xmsconfig.exeuline.exeAdded by a variant of the AGENT.AH TROJAN!
Xmsconfig38mssvcc.exeAdded by the RBOT-BJV WORM!
XMSConfig45MSConfig45.exeAdded by the SDBOT.OJ BACKDOOR!
XMsconfigesolari.exeAdded by the AUTORUN-GU WORM!
XMSConfigrjdbgmrg.exeAdded by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here
NMSConfigRemindermsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. This particular entry is specific only to 98/Me and is located in %System%
XMsConfigsMsConfigs.exeAdded by the ALCAN.A WORM!
XMSConfigsRUNDLL64.dll.vbsAdded by the WEKODE-B WORM!
Xmsconfiguratorctfsdk.exeAdded by the DELF-ALS TROJAN!
XMSControl28crsss.exeAdded by the SPYBOT.AJX WORM!
XMSControl31winnsyst.exeAdded by the RBOT.CFY WORM!
XMSControl3d1isasse.exeAdded by the RBOT.CGU WORM!

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner