Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 24133 autoruns. Autorun 12001 to 12100:

StatusAutorun nameCommandDescription
XMss Servmsssrv.exeAdded by the SLENFBOT.AA WORM!
XMss VCmssvc.exeAdded by the OPANKI.AB WORM!
Xmssarumssaru.exeAdded by the AGENT.AM TROJAN! Note - example names include "XviD", "Winamp Remote", "Windows Media Player" and "Futuremark"
Xmsscan.exemsscan.exeMicrosoft Security Adviser rogue security software - not recommended
UMSSCDLMSSCDLL.exeSpyCapture keystroke logger/monitoring program - remove unless you installed it yourself!
Xmssdbsrvmsupdtck.exeAdded by a variant of a password stealing TROJAN!
YMSSEmsseces.exeSystem Tray access to a notifications from Microsoft Security Essentials which "provides real-time protection for your home PC that guards against viruses, spyware, and other malicious software"
Ymssecesmsseces.exeSystem Tray access to a notifications from Microsoft Security Essentials which "provides real-time protection for your home PC that guards against viruses, spyware, and other malicious software"
Xmssendsvcnost.exeAdded by the HRUP-C MALWARE!
UMSSERmsser.exeMeplex adware
Xmsserrv32msserrv32.exeAdded by the STRATION.DW WORM!
Xmsservmsserv.exeAdded by the BLACKLOG-A TROJAN!
Xmsservlvsrev.exeAdded by the BROWMON-B TROJAN!
Xmsserv32msserv32.exeAdded by the RBOT-ACK WORM!
XMsServermsfun80.exeAdded by the VB-CYG WORM!
XMSServerRundll32.exe [random].dll,#1Unidentified malware! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The file is typically found in either %System% or the Windows "Temp" folder
XMsServermsfir80.exeAdded by the VB-CYJ TROJAN!
Xmsservicemsserv.exeAdded by the HYD WORM!
XMSService_v1.0realsched.exeEHU adware. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name which is normally located in %ProgramFiles%\Common Files\Real\Update_OB. This one is located in %System% or %Temp%
XMSService_v1.0vfp02.exeNewWeb adware
Xmsservicesservices.exeMsnSpyMaster surveillance software. Uninstall this software unless you put it there yourself! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an "msystem" sub-directory
Xmssfossfool.exeAdded by the RANDEX.EUS WORM!
XMSSGisg[path to file]Added by the RANKY.N TROJAN!
XMsshield.exeMsshield.exeAdded by a variant of the IRCBOT TROJAN!
XMSShowMSShow.exeAdded by the QQROB-M TROJAN!
XMSSHVCMSSHVC.exeAdded by the NUFFY.A WORM!
Xmssonfigwinupdate.exeAdded by a variant of the SDBOT WORM!
Xmssoulmsmscc2.exeAdded by the DAPIZL.A banker WORM! (A "banker worm" is designed to pillage banking information and send it back to the perpetrators!)
Xmssoulmsmscc.exeAdded by the BANCOS.HKT TROJAN!
Xmssp3mssp22.exeAdded by the IBANK-D TROJAN!
XMSSQLMssql.exeAdded by the SDBOT TROJAN!
XMSSQL for Windows NT & XPmssqlsnt.exeAdded by a variant of the SDBOT WORM!
XMSSQL Managermssqlmgr.exeAdded by the RBOT-BWU WORM!
Xmssrv32mssrv32.exeAdded by the AGENT-NKX TROJAN!
NmssSortmsssort.exeMaxtor (now Seagate) "Drag and Sort" for their external storage - "Just drag documents onto the Shared Storage II icon and Maxtor's Drag and Sort organizes your files, placing them in appropriate shared folders"
XMsstartmsstart.exeAdded by the LIVUP.C BACKDOOR!
XMSStartOptimizerIexpres.exeAdded by the DASMIN-E TROJAN!
XMSStartOptimizerWINUPD.EXEAdded by the DASMIN-E TROJAN!
XMSStartOptimizerSCVHOST.EXEAdded by the DASMIN-E TROJAN!
Xmsstaskmsstask.exeAdded by the MYPARTY WORM!
Xmssurfer lptt01mssurfer.exeRapidBlaster variant (in a "surfer" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it
Xmssurfer ml097emssurfer.exeRapidBlaster variant (in a "surfer" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it
Xmssvc[path to trojan]Added by the PSK TROJAN!
XMSSVCsvcsys.exeAdded by the FATOOS-C TROJAN!
YMSSVC.EXEMSSVC.EXEStealthDisk - hides folders, files and applications. Will also encrypt them for better protection
Xmssvc32mssvc32.exeAdded by the AGOBOT-ME WORM!
Xmssync20mssync20.exeAdded by the LDPINC-QC TROJAN!
Xmssysmssys.exeAdded by the MYSS.B TROJAN!
XmssysintIexplore .exeAdded by the PWSTEAL.ABCHLP and PSPIDER.310.B TROJANS! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the ".exe"
Xmssysintcomime.exeAdded by the NETSNAKE-I TROJAN!
Xmssyslanhelpermsmsgri32.exeAdded by the RANDEX.D WORM!
XMsSystemmsdos.exeAdult content downloader - see here
XMsSystemmssys.exeAdded by the VANTA.A TROJAN!
XMSSYSTEMsvcsys.exeAdded by the FATOOS-C TROJAN!
UMstapiMstapi.exeKeystroke logger/monitoring program - remove unless you installed it yourself!
XMstaskmstask.exeAdded by the OPASERV.N WORM! Note - this is not the legitimate mstask.exe system file and the executable resides in %Windir%
Xmstaskmstask.exeBrowser hijacker - redirecting to find-more.net. Note - this is not the legitimate mstask.exe system file
XMSTaskrun_dll.exeYuupsearch adware
XMStasksvchost.exeAdded by the LDPINCH-BV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XMsTaskwstask32.exeAdded by the MYTOB-FE WORM!
XMstaskkernel32.exeAdded by the STAP-C WORM!
XMstaskMSDTC.exeAdded by the STAP-D WORM!
XMSTask Monitormstaskmon.exeAdded by the SDBOT-LU WORM!
XMstask32driverMstask32.exeAdded by the LOONY-D TROJAN!
XMSTaskbar 32tbsvc32.exeAdded by the RBOT.BQZ WORM!
Xmstasksmstasks.exeAdded by the MULTIDR-AY TROJAN!
?MstcgwwMSTCGWW.EXE??
Xmstds.exemstds.exeAdded by the IPTABLES TROJAN!
Xmstg32.exemstg32.exeAdded by the AGENT.BI TROJAN!
NMSTMON_NMSTMON_N.EXEGenerates an error message on startup if a Konica Minolta printer is not turned on and ready
NMSTMON_QMSTMON_Q.exeGenerates an error message on startup if the Konica Minolta PagePro 1350W printer is not turned on and ready
XMstng32MSTng32.exeAdded by the TANG WORM!
XMSTrayrundll.exeAdded by the BAMER-B TROJAN! Note - this is NOT the Win9x/Me system file of the same name as described here
XMstscmstsc.exe /waitserviceAdded by the HORST.Q TROJAN! Note - this is not the legitimate mstsc.exe which is always located in %System%. This one is located in either %Windir%, %Windir%\System, %Temp%, %AppData%, %AppData%\Microsoft or %System%\drivers
Xmstsdsc.exemstsdsc.exeAdded by the CIMUZ-CD TROJAN!
Xmsupdmsupd.exeAdded by the IEACCESS DIALER!
XMSUpdatewupd.exeAdded by the ALADINZ.M TROJAN!
XMSUpdatesvchosthlp.exeAdded by the BLASTER.T WORM!
Xmsupdatemsupdate.exeAdded by the RBOT-MZ WORM!
XMSUpdatecriticalUpdate.exeAffilred adware
XMsupdateUpdate.exeAdded by the RBOT-AUC WORM!
XMsupdateexpIorer.exeAdded by the TACTSLAY.A TROJAN! Note that the filename has a capital "i" in it
XMsupdateoutIook.exeAdded by the TACTSLAY.A TROJAN! Note that the filename has a capital "i" in it
XMsupdatesvchosts.exeAdded by a variant of the TACTSLAY TROJAN!
XMsupdatesvcrhost.exeAdded by the TACTSLAY.A TROJAN!
XMsupdatesvcshost.exeAdded by the TACTSLAY.A TROJAN!
XMSupdate.exeN/ACoolWebSearch parasite variant - resets home page to an adult content site
XMSUpdateDevKitaxfd.exeAdded by the SDBOT-ZD WORM!
Xmsupdatermsupdater.exeAdded by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example
XMsUpdater Systemudpsys32.exeAdded by the RBOT.AAA WORM!
XMSupdater.exeN/ACoolWebSearch parasite variant. Installs the Winshow.dll browser plugin
Xmsupdater25lsasser.exeAdded by the RBOT-ATS WORM!
Xmsupdatesmsupdt.exeAdded by the RBOT-JO WORM!
XMSUpdSrvmsupdsrv.exeBrowser hijacker, redirecting to a adult content site
Xmsupdtwizmsupdtwiz.exeAdded by the STRATION.DD WORM!
Xmsurlmsurl32.exeAdded by the CRYPTER.A TROJAN!
Xmsuser32.exemsuser32.exeAdded by the ANDROV TROJAN!
Xmsuwarnmcpuhost.exeAdded by the AUTORUN.BCIW WORM!
XMsVBdllsys32dll.exeAdded by the AIMDES.B or AIMDES.C WORMS!
XMsVBdllMsVBdll.pifAdded by the AIMDES.A WORM!

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner