Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 24133 autoruns. Autorun 11901 to 12000:

StatusAutorun nameCommandDescription
Xmsnmsgq32msnmsgq.exeAdded by the TACTSLAY.F TROJAN!
Xmsnmsgq32sssasasb32.exeAdded by the TACTSLAY.F TROJAN!
Nmsnmsgrmsnmsgr.exeWindows Live Messenger or the older MSN Messenger utility - available via the Start menu. For Windows Live Messenger, disable by clicking on the "Show menu" icon and select Tools → Options → Sign In → deselect "Automatically run Windows Live Messenger when I log on to Windows". For MSN Messenger, disable by clicking on Tools → Options → General → deselect "Automatically run Messenger when I log on to Windows"
XMsnMsgrMsnMsgrs.exeAdded by the NETSKY.AD WORM!
XMsnMsgrmsnmsgr.exeAdded by the ANNEW-FAM WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%
XMsnmsgr.exelsass.exeAdded by the DWNLDR-GWE TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root directory (i.e. C:\ or D:\)
Xmsnmsgr32-.exemsnmsgr-.exeAdded by a variant of the SPYBOT WORM!
XMSNMSGR5MSNMSGR5.exeAdded by the RBOT.PQ WORM!
XMSNMSGREswef.batIRC backdoor TROJAN or WORM!
XMSNMSGRRswin.batIRC backdoor TROJAN or WORM!
XMSNMSGRSswe.batIRC worm or backdoor trojan!
XMSNMSGRSswiss.batIRC worm or backdoor trojan!
Xmsnmsgrsmsoobe32.exeAdded by the BANBRA.GQU TROJAN! The file is typically located in %UserProfile%\InstallShield Installation Information\{A5BA14E0-7384-5991B8648CBE70A4}
XMSNMSGRS1swed.batIRC backdoor TROJAN or WORM!
Xmsnmsgs.exemsnmsgs.exeAdded by the BANKER-HK TROJAN! Note - not to be confused with msmsgs.exe, the well known MSN Instant Messaging application!
Xmsnmsgsgsmsnmsgsgs.exeAdded by the "Catal" alias Spy.Delitall.B backdoor TROJAN!
Xmsnmsgy[path to file]Added by the BANKER-EQ TROJAN!
Xmsnntwinampb.exeChinese originated adware - detected by Kaspersky as the AGENT.TL TROJAN!
Xmsnntwinampf.exeAdded by the SMALL.DTS TROJAN!
Xmsnntwinampa.exeAdded by the SMALL.DTS TROJAN! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a "Winamp" subdirectory of %ProgramFiles% whereas this file is located in %Windir%
XMSNPluginSrIvcsn3vasap23.exeAdded by a variant of the RBOT WORM!
XMSNPluginSrvcsp6.exeAdded by the SDBOT.AKJ or RBOT-VJ WORMS!
XMSNPluginSrvcssagate.exeAdded by the SDBOT.AKJ WORM!
XMSNPlusmsnplus.exeAdded by the BANKER-DAN TROJAN!
XMsnrMsnr.exeAdded by the AUTOIT-MB WORM!
XMSNS PLUS XP2msdupd.exeAdded by the RBOT-BCE WORM!
Xmsnsched2msnsched2.exeAdded by the SPYBOT.NNT WORM!
Xmsnscr.exemsnscr.exeAdded by the CERTIF-P TROJAN!
XMSNServiceMSNService.exeAdded by the CARPET.C WORM!
Xmsnsgsmsnsgs.exeAdded by the CHEUKO-B TROJAN!
Xmsnshedmsnshed.exeAdded by the RBOT-YN WORM!
XmsnsmgrMsnMsr.exeAdded by the LOONY-N TROJAN!
XMsnsock[malware filename]Added by the BANKER.RQ TROJAN! The most common filename is "msnmnns.exe" which is found in %ProgramFiles%
Nmsnsyslogmsnappm.exeRelated to Messenger Applications. When you uninstall the trial version the msnappm keeps saying (You have xx days left) this is adware and it very annoying
XMSNSysRestorepc32.exeAdded by a variant of the MASTAK VIRUS!
XmsnToolbaarmsnmsgesc.exeAdded by the RBOT.BMF WORM!
Xmsnupdtkolie.exeAdded by a variant of the RBOT WORM!
XMsnWinmessagewin.exeAdded by the BANCBAN-D TROJAN!
XMSObject32MSObject32.jsAdded by the PUN TROJAN!
XMSODESNV7msvmiode.exeAdded by the INJECT-NW TROJAN!
XMsofficemsoffice.htaHijacker - redirecting to Searchdot.net
XMSOfficeservices.exeAdded by the DLOADER-EU TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an "MSOffice" subfolder
Xmsofficemsoffice.exeAdded by the LIKASIMAL WORM!
XMSOffice32msjcf.exeAdded by the RAKER-A TROJAN!
XMSOfficeCfgmsocfg.exePremium rate adult content dialer
XMSOfficeCfgnavchk.exePremium rate adult content dialer
XMSOfficeCfgqservice.exePremium rate adult content dialer
XMSOfficeCfgshman.exePremium rate adult content dialer
XMSOfficeCfgssvr.exePremium rate adult content dialer
Xmsoffwzmsoffwz.EXEAdded by the BANCBAN-HQ TROJAN!
Xmsoft-updater23mssysstems.exeAdded by the RBOT-ATU WORM!
Xmsoft-updater23slssystem.exeAdded by the RBOT-ASR WORM!
XMSOleath32winss.exeAdded by the KATHER TROJAN!
XMSOOBDMSOOBD.EXEAdded by the MAGISTR.A VIRUS!
Xmsoupdatermsoupdater.exeAdded by the DLOADER.GBD TROJAN!
Xmspaint.execheck32.exeAdded by the AGENT.AH TROJAN!
XMspatch69[path to trojan]Added by the MPROX TROJAN!
XMspatch89cnqmax.exeAdded by the RANDEX.P WORM!
XMSPetServPET32.EXEAdded by the IRCBOT-VE WORM!
Xmspingmsping.exeAdded by the FLOODBLACK TROJAN!
Xmsping.exemsping.exeAdded by the BDOOR-MZ BACKDOOR!
XMSPluginSrvcp3.exeAdded by the RBOT-WV WORM!
XMSPLUSmsplus32.exeAdded by the MYTOB-AM or MYTOB-CL WORMS!
NMSPMirageMSPMirage.exePart of CyberLink MagicSports - which "is a revolutionary way of watching your sports videos. It automatically detects highlights of the most memorable moments in sports from your recorded games". The exact purpose of this entry is unknown at present but create a shortcut and start it manually before you run MagicSports - which is no longer available from CyberLink
NMSPMirage.exeMSPMirage.exePart of CyberLink MagicSports - which "is a revolutionary way of watching your sports videos. It automatically detects highlights of the most memorable moments in sports from your recorded games". The exact purpose of this entry is unknown at present but create a shortcut and start it manually before you run MagicSports - which is no longer available from CyberLink
XMSPP System Update 64wiaadmgr.exeDetected by Kaspersky as the RANKY.GEN TROJAN!
XMSPQFileMSA****.TMP [* = random char]Homepage hijacker
XMsPrint32DMsPrint32D.exeAdded by the WINKO.AO WORM!
XMSPRO32[path to worm]Added by the IBERIO WORM!
XMSPRO32pnp.exeAdded by the ZOTOB.O WORM!
XMSprotect.exeMSprotect.exeAdded by the DABYREV.A VIRUS!
NMSPServiceMSPMirage.exePart of CyberLink MagicSports - which "is a revolutionary way of watching your sports videos. It automatically detects highlights of the most memorable moments in sports from your recorded games". The exact purpose of this entry is unknown at present but create a shortcut and start it manually before you run MagicSports - which is no longer available from CyberLink
Umspwrpupstman.exe"Transparent icon background" feature of Ashampoo'sPowerUp XP (WinNT/2K/XP) and PowerUp Deluxe (Win98/Me)
Umspwrpupxpman.exeRelated to Ashampoo's PowerUp XP
Umspwrpwrupst.exeAshampoo's PowerUp XP is a "tool for fine-tuning your Windows NT4, 2000, 2003 Server and XP configuration"
UmspwrPuXpMan2.exeSystem Tray access to the Ashampoo® PowerUp XP Platinum 2 tweaking utility from Ashampoo GmbH & Co. KG - which includes (amongst others) one-click tuning, multiple desktops, taskbar control center and an autostart manager
UMSPY2002ImScInst.exeMicrosoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails, documents and other files - should you need to. Found on PCs where these languages have been installed through the Regional and Language options icon in the Control Panel
Xmsqssrmsqssr.exeDetected by Kaspersky as the DLUCA.GEN TROJAN!
XMSRmsr.exeAdded by the AGOBOT.RT WORM!
XMsrcMsrc.exeAdded by the KRYPTONIC GHOST TROJAN!
Xmsrdcmsrdc.exeAdded by the SDBOT-CXO WORM!
Xmsreg.exemsrege.exeAdded by the ZINX TROJAN!
XmsReg32 Loadermsreg32.exeAdded by the AGOBOT.IU WORM!
XMSREGITMsgp.exeAdded by the KRYPGHOS.13 BACKDOOR!
UMSRegScanSGP.exeSpyGator surveillance software. Uninstall this software unless you put it there yourself
UMSRegScanSSDemo.exeSupremeSpy surveillance software. Uninstall this software unless you put it there yourself
UMSRegScanETNKL.exeComKeylogger surveillance software. Uninstall this software unless you put it there yourself
UMSRegScanKSPDemo.exeKeyStalker PRO surveillance software. Uninstall this software unless you put it there yourself
UMSRegScanDDSSDemo.exeSystemSleuth surveillance software. Uninstall this software unless you put it there yourself
UMSRegScanESP+.exeESP surveillance software. Uninstall this software unless you put it there yourself
UMSRegScanESPDemo.exeEye Spy Pro surveillance software. Uninstall this software unless you put it there yourself
UMSRegScanSBPDemo.exeSpyBoss Pro surveillance software. Uninstall this software unless you put it there yourself
UMSRegScanYEKPND.exeEyeCandy Computer Monitor surveillance software. Uninstall this software unless you put it there yourself
UMSRegScanYKPND.exeYKPMD surveillance software. Uninstall this software unless you put it there yourself
XMSRegSvcregsvc32.exeHomepage hijacker that changes your homepage to an adult content site
Xmsresear[path to trojan]Added by the WEASYW-B TROJAN!
Xmsresearchmsresearch.exe180SearchAssistant adware related
Xmsresearchtool3.exeSpy Sheriff/SpywareNO malware, also detected as the SPYHOAX-A TROJAN, pretends to be a spyware remover! - file names spotted sofar include VXH8JKDQ2.EXE, NS6281400.so, CVXH8JKDQ2.EXE, down3.exe, sefe.exe, winstall.exe, and tool2.exe
Xmsrundllmsrund1l32.exeAdded by the BINGHE TROJAN!
Xmsrunocx32msrunocx32.exeAdded by the SKUS WORM!

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner