Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 24133 autoruns. Autorun 15001 to 15100:

StatusAutorun nameCommandDescription
URefereereferee.exeMediaComm's monitor for file association changes. Stop rogue programs from screwing your settings either on installation or whenever they run
UReflex VisionReflexVision.exeReflex Vision from Increment Software. "A background application for Windows XP that makes switching windows faster and easier"
NRefreshRefresh.exe(Iomega) Refresh - loads the Iomega desktop icons at startup
XRegReg.htaPasson homepage hi-jacker
?Reg Checklpt.exeRelated to Supanet ISP software - what does it do and is it required?
XReg Servicewinsy.exeAdded by a variant of the SPYBOT WORM!
XReg Servicewinslogon.exeAdded by the AGOBOT-SC WORM!
XReg Serviceipcfg.exeAdded by the AGOBOT-SO WORM!
XReg ServiceREGSRV32.EXEAdded by the RBOT.ZW WORM!
XReg ServiceWinnConfig.exeAdded by the AGOBOT-PF WORM!
XReg ServiceNT32.exeAdded by the AGOBOT.G BACKDOOR!
XReg ServicesWinboot32.exeAdded by the RBOT.PB WORM!
XReg ToolReg Tool.exeRegTool rogue registry cleaner - not recommended, removal instructions here
Xreg_keyFUKULAMER.exeAdded by the BEAGLE.AH WORM!
Xreg_keyloader_name.exeAdded by the BEAGLE.Y or BEAGLE.Z or BEAGLE.AA WORMS!
Xreg_runSysten.exeAdded by the BANCOS-BS TROJAN!
Xreg_run[path to trojan]Added by the BANKER-BQ TROJAN!
XReg_WFTRegsysw.comAdded by the WILSEF VIRUS!
XReg_WFTscanreg32.comAdded by the SENNASPY-F TROJAN!
XReg_WFTRegsysw.exeAdded by the WILSEF.A WORM!
Xreg1.regvuamgard.exeAdded by a variant of the IRCBOT TROJAN!
Ureg2.0SVCH0ST.EXEeSpyNow surveillance software. Uninstall this software unless you put it there yourself. Note - the filename has the digit 0 rather then the uppercase "o"
XReg32Reg32.exeHijacker - redirecting to only-virgins.com
Xreg32reg32.exeAdded by the NOUPDATE.B TROJAN!
XReg32reg33.exeCoolWebSearch parasite variant - also detected as the STARTPA-M TROJAN!
URegBarregsvr32.exe bocaitoolbar.dllBocaiToolbar adware. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The "bocaitoolbar.dll" file is found in %ProgramFiles%\blogmark
XRegcheck~CAB001.EXEAdded by the CYBRSPY.13A or CYBRSPY.13B BAKCDOORS!
Xregcheck[path to file]Added by the SERVPAM TROJAN!
XRegCleanRegClean.exeRegClean rogue registry cleaner - not recommended
URegClean Expert SchedulerRCHelper.exe"Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry, your system will run faster and error free"
URegClean Expert SchedulerRCScheduler.exe"Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry, your system will run faster and error free"
XRegCleanerSYSio32.exeAdded by an unidentified VIRUS, WORM or TROJAN! Note - do not confuse this with the popular RegCleaner registry cleaner freeware
XRegCompresRegcpm32.exeAdded by the POLDO.B TROJAN!
XRegCompresREGCPM32.EXEAdded by the DASMIN-E TROJAN!
XRegcxdinafREGCXDINAF.EXEAdded by the BANCOS-BW TROJAN!
XRegcxmarq REGCXMARQ.EXEAdded by the BANCOS.DK TROJAN! Note that the filename has a leading space, ie, " REGCXMARQ.EXE"
XRegcxnRegcxn.exeAdded by the COIBOA-D TROJAN!
Uregdefendregdefend.exe"RegDefend is a configurable, kernel based registry protection system, designed to intercept selected changes before they occur, thus also preventing malicious software like viruses, trojans and worms from using the registry to their advantage"
Xregdiitwinxp.exeAdded by the RUNAUTO.F WORM!
Xregdiitwin.exeAdded by the VBSAUTO-A WORM!
XRegDoneservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
XRegDonewinlogon.exeAdded by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
XRegDone Excsrss.exeAdded by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!
XRegDoneExlsass.exeAdded by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!
Xregeditregedit.exeAdded by the BRID.A WORM! Note - this is not the valid Windows registry editor which resides in %Windir$ and will not figure in Msconfig/Startup! This version resides in %System%
XREGEDITRegsrv32.comAdded by the SOUTHGHOST WORM!
Xregeditautoexe.exeAdded by a variant of the RBOT WORM!
Xregedit svchost.exe ccRegVfyAdded by the HOTWORD.B TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is also located in %System% but has a space at the beginning of the filename
Xregeditregedit.exeAdded by the GANBATE.A WORM! Note that the legitimate Windows registry editor (regedit.exe) is located %Windir% and will not figure in Msconfig/Startup! This one is located in %Windir%\security\Database
XRegeditregedits.exeAdded by the BANCBAN-QV TROJAN!
XRegEdit32RegEdit32.exeAdded by the VOUMIT-A WORM! Note - this is not the legitimate regedit32.exe application which is always located in %System% and should not normally figure in Msconfig/Startup! This file is located in a "mirc32" folder
XRegedit32regedit.exeAdded by the MDROP-CMO TROJAN! Note - this is not the valid Windows registry editor which resides in %Windir% and will not normally figure in Msconfig/Startup! This version resides in %System%
XRegexitrunlli32.exeAdded by the QQPASS-U TROJAN!
XRegexitUpdadv.exeAdded by the QQPASS-N TROJAN!
XRegFreezeregfreeze.exeRegFreeze rogue spyware remover - not recommended, removal instructions here
Xreggsdgspoolserv.exeAdded by the SDBOT-MS WORM!
Xreggsdgspoolsrv.exeAdded by the SDBOT-DI WORM!
URegHelpsvchosts.exeSpyGraphica spy software - "Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world."
Xreghostreghost.exeSpyPal surveillance software. Uninstall this software unless you put it there yourself
XRegiFastRFManager.exeRegiFast adware
?reginfo32reginfo32.exe??
XRegional Valueisng.exeAdded by the SDBOT-OW WORM!
UREGIST~1REGIST~1.EXEPart of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for "Send To" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation
XRegister ManagerRegistryManage.exeAdded by the SDBOT.AYH WORM!
NRegister MediaRing Talkregister.exeIf you don't want to register MediaRing and be reminded about it every bootup disable it
?Register SeqChkregsvr32.exe ..csseqchk.dll??
URegisterDropHandlerREGIST~1.EXEPart of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for "Send To" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation
XRegistration Servicetoker.exeAdded by the SDBOT-BB WORM!
XRegistration Servicemsvdm6.exeAdded by the SDBOT-HE TROJAN!
NRegistration-Studio 8RegTool.exeRegistration for Pinnacle Studio Version 8 home video software from Pinnacle Systems
XRegistrywscript.exe ShakiraPics.jpg.vbsAdded by the VBSWG.AQ WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "ShakiraPics.jpg.vbs" file is located in %Windir%
URegistryclass0117[random].exeBlackbox captures emails and chat logs, and monitors Internet activity - remove if you didn't intentionally install it
XRegistry CheckerRegrun.exeAdded by the SDBOT TROJAN!
XRegistry Checkupwinreg.exeAdded by an unidentified WORM or TROJAN!
XRegistry Checkup System326a MonitorWinregs326a.exeAdded by a variant of the SDBOT WORM!
XRegistry CleanerRegclean.exeRegistry Cleaner misleading security software - not recommended, see here
XRegistry Integrity Checkerregintmon.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
XRegistry IntegritycheckWCPDT.EXEAdded by the AGOBOT-RF WORM!
XRegistry Loaderregloadr.exeAdded by the GAOBOT.AO WORM!
XRegistry Loaderwinhlpp32.exeAdded by the GAOBOT.AO WORM!
NRegistry MechanicRegMech.exePart of Registry Mechanic from PC Tools - which "is an advanced registry cleaner for Windows that can safely clean, repair and optimize your registry in a few simple mouse clicks!". This entry is created when Registry Mechanic is installed on XP and loads the System Tray icon and runs a registry scan at startup - if either are enabled. Run manually at regular intervals
NRegistry Mechanic Vista TrayRMTray.exePart of Registry Mechanic from PC Tools - which "is an advanced registry cleaner for Windows that can safely clean, repair and optimize your registry in a few simple mouse clicks!" This entry is created when Registry Mechanic is installed on Vista and loads the System Tray icon (RegMech.exe) and runs a registry scan at startup - if either are enabled. Run manually at regular intervals
XRegistry Monitorregmon.exeAdded by the BCKDR-QKH BACKDOOR!
XRegistry oidetwin32.exeAdded by the RBOT.BMT WORM!
XRegistry Protectorregprotect.exeAdded by the ARIVER.A WORM!
XRegistry Scannerregscanr.exeAdded by a variant of the OPTIX TROJAN!
XRegistry Servregsvr.exeAdded by the WEBMONEY-G TROJAN!
XRegistry Serverregsrv32.exeAdded by the RBOT-GM WORM!
XRegistry Serverregserv.exeAdded by a variant of the IRCBOT BACKDOOR! See here
XRegistry Serviceregsvc.exeAdded by the IRCBOT-ZM BACKDOOR!
XRegistry ServiceREGSRV32.EXEAdded by a variant of the RBOT WORM!
XRegistry Serviceresvs.exeAdded by the DELBOT-I WORM!
XRegistry ServicesRegistry.exeAdded by the CILE TROJAN!
XRegistry Startup Checkcheckreg.exeAdded by the REMLOAD-A or DANMEC-B TROJANS!
XRegistry SystemRegsys.exeAdded by a variant of the IRCBOT BACKDOOR! See here
XRegistry System16 Checkup MonitorSystemReg16.exeAdded by the RBOT.AGD WORM!
XRegistry System166 Checkup MonitorSystemReg166.exeAdded by the RBOT.ATN WORM!
XRegistry Value Nameroses.exeAdded by the RBOT-AFT WORM!
XRegistry Value Nameservice.exeAdded by the RBOT-AHT WORM!
XRegistry Value Namewinapi32.exeAdded by a variant of the RBOT WORM!

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner