Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 24133 autoruns. Autorun 15301 to 15400:

StatusAutorun nameCommandDescription
Xrieysharieysha.exeAdded by the DELF.KG WORM!
URightFAX Print-to-Fax DriverFaxCtrl.exePart of RightFAX from Captaris - "the proven market leader in fax server and document delivery software"
URing Central Faxrcenterrll.exeOnly needed if you want a PC to answer faxes automatically
XrIOphosIsrIOPHosIs.vBSAdded by the RIOSYS MACRO!
NRiorad Managerriomgr.exe"Riorad Explorer is hands-down the most advanced Windows software companion for your Rio MP3 player"
URIP 2007 ClockRIP 2007 Clock.exeClock gadget included with the Rest In Peace theme for MyColors from Stardock Corporation
?RIS2PostRebootLaunchRIS2.exePart of the programming software for LEGO® Mindstorms robotic building system. What does it do and is it required?
Xrising[worm filename]Added by the AUTORUN-AW WORM!
XRising Driverdriver.exeAdded by the SILLYFD-TL WORM!
Xrisingssvchost.exeAdded by the AGENT-GLC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XRisorse di Windows[path to backdoor]Added by the MESUB.KJ BACKDOOR!
NRitaglio schermata e avvio di OneNote 2007ONENOTEM.EXESystem Tray access to MS Office OneNote 2007 - an electronic notebook that allows you to create free-form notes, including text, graphics and audio/video. When running, ONENOTEM.EXE also enables the WINDOWS KEY combinations - such as WINDOWS KEY+N (new Side Note) and WINDOWS KEY+S (insert screen grab into a note). Leave the icon enabled in OneNote but move the shortcut from Start → All Programs → Startup to the desktop or elsewhere on the Start menu and run when needed. Italian version
URivaTunerRivaTuner.exeRivaTuner is a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This startup entry is for XP and can appear twice - with registry key names of "RivaTuner" and "RivaTunerStartupDaemon" respectively. The former minimizes it to the System Tray and is primarily required only if you want to use the "Launcher" or monitoring options. The latter applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information
URivaTunerRivaTunerWrapper.exeRivaTuner is a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This startup entry is for Vista and can appear twice - with registry key names of "RivaTuner" and "RivaTunerStartupDaemon" respectively. Both load the main application (RivaTuner.exe). The former minimizes it to the System Tray and is primarily required only if you want to use the "Launcher" or monitoring options. The latter applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information
URivaTuner ApplicationRivaTuner.exeRivaTuner is a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This startup entry is for XP and can appear twice - with registry key names of "RivaTuner" and "RivaTunerStartupDaemon" respectively. The former minimizes it to the System Tray and is primarily required only if you want to use the "Launcher" or monitoring options. The latter applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information
URivaTunerStartupDaemonRivaTuner.exePart of RivaTuner - a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This entry is for XP and applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information
URivaTunerStartupDaemonRivaTunerWrapper.exePart of RivaTuner - a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This entry is for Vista and loads the main application (RivaTuner.exe) to apply overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information
URivaTunerWrapper ApplicationRivaTunerWrapper.exeRivaTuner is a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This startup entry is for Vista and can appear twice - with registry key names of "RivaTuner" and "RivaTunerStartupDaemon" respectively. Both load the main application (RivaTuner.exe). The former minimizes it to the System Tray and is primarily required only if you want to use the "Launcher" or monitoring options. The latter applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information
?RjLyraInstallersetup.exe??
URK LauncherRKLauncher.exeRK Launcher by RaduKing - "is a free application that will allow the user to have a visually pleasing bar at the side of the screen that is used to quickly launch shortcuts"
URKLG Startupklg.exeLocal Keylogger Pro keystroke logger/monitoring program - remove unless you installed it yourself!
XRKrxrundll32.exeAdded by the LINEAG-ADA TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir%\down
XRKrxrundll32.exeAdded by a variant of the LINEAG-ADA TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir%\inf
XrlPympjVAQQ.exerlPympjVAQQ.exeAdded by the FAKEAV-IK MALWARE!
Xrmalt[random filename]Added by the CLICKER-CS TROJAN! Filenames spotted inlcude Setup.exe, Keygen.exe, Keygen-Serial.exe, Photoshop.CS2.KeyGen.exe and more
Urmctrlrmctrl.exeRemote Control background application for Cyberlink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one
Xrmdrfje.dllrundll32.exe rmdrfje.dll,[random characters]Added by the DLOADR-ANM TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "rmdrfje.dll" file is located in %Windir%
Nrmmonmprmmon.exeResource Monitor for the now defunct Chromatic Research MPact2 3DVD graphics card
Urmoc3260.dll OCXregsvr32.exe rmoc3260.dllA module that contains COM components for media playback used by both RealPlayer and Windows Media Player - see here. The "rmoc3260.dll" file is found in %System%
?RMremoteRmRemote.exeRemote control driver for REALmagic Xcard. Is it required?
Xrn4dkolder.exe dirote.exeAdded by the MAROON.A BACKDOOR! Both files are located in %System%\d0e0t1
URnaomfltnaomf.exeNaomi internet filtering software
XRNBc Testwf32vbs.exeAdded by the RBOT-AGR WORM!
XRNBc Testbvldv32.exeAdded by the RBOT-AJF WORM!
URNBOStartsentstrt.exeProgram used to initialise the VxD virtual driver for Sentinel drivers associated with Rainbow H/W keys that plug-in to the parallel port. These are usually supplied with workplace design tools and restrict the use of the software only to the machine to which the H/W key is connected. Required if you have such tools
XRNBz Testwf32vbc.exeAdded by the RBOT-AEY WORM!
XRNDc Testwf32b.exeAdded by a variant of the SDBOT WORM!
?rndll2rndll2.exeMay be related to the DivX program as a *.dat file in the same directory had "DivXPro505Bundle.exe" mentioned within?
Xrngmf[path to trojan]Added by the RANKY.C TROJAN!
XRnudll32tadxtr.exeAdded by the QQPASS-O TROJAN!
Xrnwabmigrnwabmig.exeAdded by the AGENT-LMI TROJAN!
?rnxqhrnxqh.exe??
XRoam04ActiveX.exeAdded by the ROAMER-A TROJAN!
NRoboFormRoboTaskBarIcon.exeRoboform - password manager and web form filler. Will work without this startup entry, as the "active" component is an integrated Internet Explorer browser plugin
NRoboFormWatcherRoboFormWatcher.exeRoboform from Siber Systems. Automatically completes web forms. Available via Start -> Programs
URocket.TimeRocketTime.exeRocket.Time - time synchronization software from Rocket Software
NRocketDockRocketDock.exe"RocketDock is a smoothly animated, alpha blended application launcher. It provides a nice clean interface to drop shortcuts on for easy access and organization"
XRoflcopteurseman.exeAdded by an unidentified WORM or TROJAN!
URogers SHSshs.exe"Rogers Self Help Software is a free suite of tools and utilities for your computer that keeps your system running properly, and makes your Hi-Speed Internet experience smooth and trouble-free"
URogersAgentrogersagent.exe"Rogers Self Help Software is a free suite of tools and utilities for your computer that keeps your system running properly, and makes your Hi-Speed Internet experience smooth and trouble-free"
YRogersServicepointAgent.exeRogersServicepointAgent.exeRogers Servicepoint Agent tool installed when you choose to install their Online Protection internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabled
YRogueMonitorRogueRemoverPRO.exePart of Malwarebytes' RogueRemover PRO - the realtime "RogueMonitor will alert you before you download a rogue application keeping you safe and secure before trouble occurs." Now discontinued and the funtionality is included in Malwarebytes' Anti-Malware
YRogueRemoverPRORogueRemoverPRO.exePart of Malwarebytes' RogueRemover PRO - the realtime "RogueMonitor will alert you before you download a rogue application keeping you safe and secure before trouble occurs." Now discontinued and the funtionality is included in Malwarebytes' Anti-Malware
?roketpiperpclient.exe??
URollbackRollbackTray.exeAdded by the RollBack Rx system restore program
Xrollbkdsm.exeAdded by the SERFLOG.B WORM!
Xrollbkmsmpatch.exeAdded by the SERFLOG.B WORM!
Xrollbksvosm.exeAdded by the SERFLOG.B WORM!
Xrollbksysup.exeAdded by the SERFLOG.B WORM!
Xromaherematrixhere.exeSuperSpider hijacker - a CoolWebSearch parasite variant
Xromahere2************.exe [* = random char]SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as the KREPPER-AE TROJAN!
Xromahere3************.exe [* = random char]SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as the KREPPER-AE TROJAN!
XRoot System Servicerootsvc32.exeAdded by the AUTORUN-BGZ WORM!
XRoot_Machine[path to trojan]Added by the BANCBAN-DI TROJAN!
XROOT_Machinewinlogon.exeAdded by the BANKER-FI TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\inf
XRosTikaRosTika.exeAdded by the BRONTOK-BU WORM!
?ROUTDROUTD.exe??
XRouterRouter.exeAdded by the AGENT.FJN TROJAN!
NRoxAssistRoxAssist.exeRoxio Assistant is designed to correct engine initialization errors in Easy CD & DVD Creator 6. If the engine does not initialize, the applications in Easy CD & DVD Creator will not recognize your recorder. After running this program you should receive the message "Engine initialized successfully with full recorder support". If this doesn't happen you may have to add support for newer drives using Roxio Updater, check for product updates and even re-install the software. See this thread for more information
NRoxAssistantRoxAssist.exeRoxio Assistant is designed to correct engine initialization errors in Easy CD & DVD Creator 6. If the engine does not initialize, the applications in Easy CD & DVD Creator will not recognize your recorder. After running this program you should receive the message "Engine initialized successfully with full recorder support". If this doesn't happen you may have to add support for newer drives using Roxio Updater, check for product updates and even re-install the software. See this thread for more information
?Roxio EngineMSMNGR32.EXENot believed to be a valid Roxio program - more likely a variant on the WOMANIZ.A TROJAN!
YRoxio Engine Compatibility WizardEngUtil.exePart of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools - corrects any modification made to the Roxio Engine, it exits after checking
NRoxioAudioCentralRxMon.exePart of Roxio EasyCD Creator 6.0 - places the Roxio AudioCentral icon in you system tray. "Includes a player, media manager, ripper, tag and sound editor - integrated in a single application". Not required for Roxio to work properly.
NRoxioDragToDiscDrgToDsc.exeSystem Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. "Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically". Not required for Roxio to work properly and available via the Start menu
YRoxioEngineUtilityEngUtil.exePart of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools - corrects any modification made to the Roxio Engine, it exits after checking
NRoxWatchTrayRoxWatchTray.exeSystem Tray access to managing the "Watched Folders", "LiveShares" and "MediaSpace" features of the Roxio Easy Media Creator 8 multimedia suite. All of these options are available from the Media Manager utility. The "Watched Folders" feature monitors specified locations for new pictures, songs and videos being added and makes them available to the Media Manager - if you have 512MB of memory or less available it's recommended you also disable the associated "Roxio Hard Drive Watcher (RoxWatch)" service as well as the combination has been known to use significant amount of memory and cause other problems
NRoxWatchTrayRoxWatchTray10.exeSystem Tray access to managing the "Watched Folders", "LiveShares" and "MediaSpace" features of the Roxio Easy Media Creator 10 multimedia suite. All of these options are available from the Media Manager utility. The "Watched Folders" feature monitors specified locations for new pictures, songs and videos being added and makes them available to the Media Manager - if you have 512MB of memory or less available it's recommended you also disable the associated "Roxio Hard Drive Watcher 10 (RoxWatch10)" service as well as the combination has been known to use significant amount of memory and cause other problems
NRoxWatchTrayRoxWatchTray9.exeSystem Tray access to managing the "Watched Folders", "LiveShares" and "MediaSpace" features of the Roxio Easy Media Creator 9 multimedia suite. All of these options are available from the Media Manager utility. The "Watched Folders" feature monitors specified locations for new pictures, songs and videos being added and makes them available to the Media Manager - if you have 512MB of memory or less available it's recommended you also disable the associated "Roxio Hard Drive Watcher 9 (RoxWatch9)" service as well as the combination has been known to use significant amount of memory and cause other problems
NRoxWatchTray10RoxWatchTray10.exeSystem Tray access to managing the "Watched Folders", "LiveShares" and "MediaSpace" features of the Roxio Easy Media Creator 10 multimedia suite. All of these options are available from the Media Manager utility. The "Watched Folders" feature monitors specified locations for new pictures, songs and videos being added and makes them available to the Media Manager - if you have 512MB of memory or less available it's recommended you also disable the associated "Roxio Hard Drive Watcher 10 (RoxWatch10)" service as well as the combination has been known to use significant amount of memory and cause other problems
NRoxWatchTray9RoxWatchTray9.exeSystem Tray access to managing the "Watched Folders", "LiveShares" and "MediaSpace" features of the Roxio Easy Media Creator 9 multimedia suite. All of these options are available from the Media Manager utility. The "Watched Folders" feature monitors specified locations for new pictures, songs and videos being added and makes them available to the Media Manager - if you have 512MB of memory or less available it's recommended you also disable the associated "Roxio Hard Drive Watcher 9 (RoxWatch9)" service as well as the combination has been known to use significant amount of memory and cause other problems
URP32rp32.exeUnicenter Remote Control (was Remotely Possible) from Enterprise International for remote control and access to Win9x/NT systems
XRPCMSschost.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
XRPC DCOM Vulnerability Patchmsgfix.exeAdded by the RBOT.S WORM!
XRPC Driversrpcall.exeAdded by the SDBOT.FLY WORM!
XRPC Patcher[path to worm]Added by the BOLGI WORM!
XRPC Service[random filename]Added by the BDOOR-AAD BACKDOOR!
XRPC Servicejgszznv.exeAdded by the RBOT-EMS WORM!
Xrpc Win32shost32.exeAdded by the RBOT-ABL WORM!
Xrpc Win32spoolscv.exeAdded by a variant of the RBOT WORM!
XRPCall_[ComputerName]smhost.exeAdded by the REDPLUT-B TROJAN!
XRPCall_WIN2KKurawas.exeAdded by the BHARAT.A WORM!
Xrpccrpcc.exeAdded by the SPAMMIT-E TROJAN!
Xrpcda Win32rpcda.exeAdded by the RBOT-AEE WORM!
XRPCInstall[path to trojan]Added by the AGENT-DQM TROJAN!
XRpcLocatorexplorer.exeAdded by the RBOT-GSA WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
XRPCser32gservices.exeAdded by the RITDOOR-C WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XRPCser32g1services.exeAdded by the PREX.D WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XRPCser32g3services.exeAdded by the PREXOT.D BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XRPCser32g4services.exeAdded by the PREXOT.E BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XRPCserr32gwinlogon.exeAdded by the RITDOOR-B WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner