Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 24133 autoruns. Autorun 13001 to 13100:

StatusAutorun nameCommandDescription
YNortonAntiBotNortonAntiBot.exeControl Center for Norton Antibot from Symantec - which "provides advanced, real-time protection against emerging threats, including bots that are used to perpetrate identity theft and other online crimes" and "protects your PC from unauthorized access and tampering, detects and stops attempts by hackers to take remote control of your computer, and delivers extra protection against emerging 'zero-day' threats." Designed to work with existing antivirus software but now discontinued
XNortonAntivirusLSASS.exeAdded by the PEXMOR WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Temp
XNortonAVnorton_antivirus.exeAdded by the NETJOE TROJAN! Note - this is not the legitimate Symantec AV program
XnortonavCCUPD32.EXEAdded by an unidentified WORM or TROJAN!
UNortonOnlineBackupNOBuClient.exeSystem Tray access to and notifications for Symantec's Norton Online Backup online storage utility
Xnortonpnortonp.exeAdded by the JD-A TROJAN!
XNortons AV SYSTEMscvchost.exeAdded by a variant of the RBOT WORM!
XNortons AVS Systemsarse.exeAdded by the RBOT.AWY WORM!
XnortonsantivirusccEvtMngr.exeAdded by the HZDOOR-A TROJAN!
NNortonUtilitiesnu.exePart of version 14.* of Symantec's Norton Utilities PC tune up suite. This entry will be present if you optionally select any of the following startup options (via Administer → Settings): "Custom Scan", "Privacy Clean & Full Scan" or "Send to tray"
XNortonVPlussvchost.exeAdded by the ROAMER-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!
Xnoskrnlnoskrnl.exeAdded by the PEACOMM.D TROJAN!
UNotebook Maximizermaximizer_startup.exeToshiba Notebook Maximizer software - adjust settings to save battery power and increase efficiency
UNotebookHardwareControlnhc.exe"With Notebook Hardware Control you can easily control the hardware components of your Notebook"
?NotebookManagernbm.exeAssociated with Acer notebook PCs. What does it do and is it required?
NNoteBurnerVTBurnerGUI.exeNoteBurner from NoteBurner Inc. - "a versatile music converter that can be used as MP3 music converter, AAC audio converter, WAV to MP3 converter, M4A to MP3 converter, and RM to MP3 converter"
XNotePad[worm filename]Added by the SILLYFDC-G WORM!
XNotepadntoepad.exeAdded by the DELBOT-AK WORM!
Xnotepadrundll32.exe notepad.dll,_IWMPEvents@0Added by the OPACHKI.A TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "notepad.dll" file is found in %System%
Xnotepadrundll32.exe ntload.dll,_IWMPEvents@0Added by the OPACHKI.A TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ntload.dll" file is found in %UserProfile%
Xnotepadrundll32.exe notepad.dll,_NtLoad@0Added by the AGENT-NJZ TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "notepad.dll" file is found in %System%
XNotepad lptt01notepad.exeRapidBlaster variant (in a "windows" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not Windows Notepad which has the same executable name
XNotepad ml097enotepad.exeRapidBlaster variant (in a "windows" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not Windows Notepad which has the same executable name
Xnotepad.exeupx.exeAdded by a variant of the AGENT.AH TROJAN!
Xnotepad.exemsmsgs.exeAdded by the ZLOB TROJAN and variants! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger
Xnotepad2.exepopuper.exeAdded by the PUPER-E TROJAN!
Xnotesnotepaad.exeAdded by the RBOT.BME WORM!
Xnotesnotes.exeAdded by the SYKIPOT BACKDOOR!
XNotFautflxper.exeAdded by the SDBOT-AGZ WORM!
UNoticeP.exeNoticeP.exePart of iSync which allows "you to transfer songs from any music downloading software to your iTunes® library". The trial version displays advertisements which disappear if you purchase the software
XNotification UtilityaltpayV2.exeAltPay adware
XNotnEber.exePurityScan adware
XNotnwtta.exePurityScan adware
UNovaBackup * Tray ControlNbkCtrl.exeScheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here. * represents the version number
?NovaPortal Single User ServiceNPSU.exe??
UNovastorSchedulerdSCHENGD.EXENovaStor NovaBACKUP Scheduler - back-up utility. If you don't have regularly scheduled back-ups you don't need it
Xnovavappccsmn.exeSysinternals Antivirus rogue security software - not recommended, removal instructions here
Xnovavapprccsrr.exeSysinternals Antivirus rogue security software - not recommended, removal instructions here
Xnovsvida.exenovsvida.exeGlobalAccess dialer
XNoWayViruspgs.exeNoWayVirus rogue security software - not recommended, removal instructions here. A member of the AVSystemCare family
NNowe Gadu-Gadugg.exePolish language Instant Messaging client
XNOYPI_KANG_ASTIGExit to DosPrompt.pifAdded by the FILUKIN.A WORM!
Xnpupnp.exeAdded by the YABE.AE TROJAN!
UNPDTrayNPDTray.exeSystem Tray access to Presentation Director for IBM/Lenovo Thinkpad notebooks - which allows you to create and quickly select between various single and mulitple display options. Scheme selection and settings are also available via Fn+F7 key combination on some models
XNPF ValueNPFMONTR.exeAdded by the RBOT-AWD WORM!
YNPFMonitorNPFMntor.exeNorton AntiVirus Firewall Install Monitor. Helps Norton AntiVirus detect immediately after boot-up whether the Personal Firewall part is currently installed and working properly, whether it is currently enabled or disabled, and what features of the firewall are turned on. Loads via a registry "RunServices" key in 98/Me and as a service in XP
Xnpkmncnpkmnc.exeWebVia adware
UNPROTECTNPROTECT.EXESupports the Norton Protected Recycled Bin feature of older versions of Norton Utilities (either as a standalone product or as part of Norton SystemWorks). Adds an extra layer of safety to the deletion of information from the standard Windows Recycled Bin. Loads via the registry "Run" or "RunServices" keys in 98/Me and as a service in XP
?NPS Event Checkernpscheck.exePart of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as Norton Program Scheduler Event Checker
NNPSAgentNPSAgent.exeInstalled with the SAMSUNG New PC Studio mobile device management utility. Detects when a supported mobile device is connection and optionally automatically loads the main program
XNSns.exeAdded by the AGOBOT-HS WORM!
XNSChecknscheck.exeMarketScore parasite - ActiveX control used to download premium-rate diallers
Xnscntrlnscntrl.exeAdded by the DLOAD-DC TROJAN!
Xnsdcmd servicesnsdcmdav.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
Xnsdcmd vid processnsdcmdwin.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
Xnsdluansdlua.exeAll-In-One Telcom - adult content dialler
Xnsdrivernssys32.exeNetShagg adware
Xnsense.exeAdded by the AGOBOT-ML WORM!
UNsengineNsengine.exeScheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here
UNSHelperaexnsinstallhelper.exeAltiris Express Notification Server Install helper - monitors integrity of the installation
UNSKNSK.exeArdakey keystroke logger/monitoring program - remove unless you installed it yourself!
UNSRKeyNSRTray.exeSystem Tray access to and notifications for Symantec's Norton Save and Restore 1.0 backup software (either as a standalone product or as part of Norton SystemWorks Premier) - which is a renamed version of Norton Ghost
UNSRTrayNSRTray.exeSystem Tray access to and notifications for Symantec's Norton Save and Restore 1.0 backup software (either as a standalone product or as part of Norton SystemWorks Premier) - which is a renamed version of Norton Ghost
Xnssysconf[random filename]Added by the VIVIA.A TROJAN!
Xnstatnetstat.exeAdult content dialler
Ynsu_ui_clientnsu_ui_client.exeUtility that only runs once after installing the Nokia Software Updater which is used to update the operating system (or firmware) for selected Nokia mobile devices
Ynsu_ui_client.exensu_ui_client.exeUtility that only runs once after installing the Nokia Software Updater which is used to update the operating system (or firmware) for selected Nokia mobile devices
XNSupdateNSupdate.exeAdded by the Dial/Laet-B premium rate dialer!
XNsvnsvsvc.exeDelfin PromulGate adware
Xnsvcinn20050308.exeDelfin Media Viewer adware related
XNsvdrnsvdr.exeAdult content dialler
UNSWCfg.exeNSWCfg.exeInformation wizard for older versions of Symantec's now discontinued Norton SystemWorks system utility suite. On the first run after installation this entry looks after registration, subscription and confirms the default configuration settings
UNSWosCheckosCheck.exePart of Symantec's now discontinued Norton SystemWorks security and utility suite. Checks at boot-time to see if you are still using the same OS as your last Windows session and terminates if you are. If Windows has been upgraded it will attempt to download the relevant updates for the new OS on the first reboot
NNswUiTrayNswUiTray.exeSystem Tray access to Symantec's now discontinued Norton SystemWorks 2009 security and utility suite
Unsysnsys.exeNetSpy keystroke logger/monitoring program - remove unless you installed it yourself!
Xnsys32nsys32.exeAdded by the AGOBOT-SU WORM!
Xnsysconf[7 random letters].exeZioCom.C adware
NNSystemMonitorSymmon.exeNorton Uninstall Deluxe - monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging
NNT Kernel Patchntkrnlpt.exeFaxServe network fax software
XNT LM Security Support ProviderWinNTLM.exeAdded by a variant of the SDBOT WORM!
XNT Logging ServiceSyslog32.exeAdded by the DONK.B WORM and variants!
XNT Logging Servicecool.exeAdded by the SDBOT-OO BACKDOOR!
XNT Logging Servicesysmgr.exeAdded by the SDBOT-OO BACKDOOR!
XNT MICROSOFT SVCDntvsvcd.exeAdded by a variant of the RBOT WORM!
XNT Printing Servicespoolsc.exeAdded by the BUZUS-K WORM!
XNT Printing Servicechkdsks.exeAdded by the ARCHIVARIUS series of WORMS!
XNT Printing Servicechkdskss.exeAdded by the ARCHIVARIUS series of WORMS!
XNT Printing Serviceschkdsks.exeAdded by the BUZUS-M TROJAN!
XNT securityrundll32.comAdded by the RBOT-AJC WORM!
XNT ServiceNTOKSRNL.EXEAdded by the RBOT-AAG WORM!
XNT Servicesntsvc.exeAdded by the AGOBOT.VJ WORM!
XNt System Kernelntsyskrnl.exeAdded by the AGOBOT.IK WORM!
XNt System Protocolntsystem.exeAdded by the RBOT.DSB BACKDOOR!
XNT Video API32NTAPI32.exeAdded by the RBOT-FW WORM!
XNT Virtual Machine[path to file]Added by the SCAERBOT-A WORM!
XNT Windows System Manager Loadercsrlss.exeAdded by the AGOBOT.OX WORM!
XNt**.exe [* = random char]Nt**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
XNt**32.exe [* = random char]Nt**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this log
XNT-Virtual Device Managerntvdmn.exeAdded by the SDBOT-AAA WORM!
XNT_Authoritylsass.exeAdded by the KUKOO-A WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner