Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 24133 autoruns. Autorun 16401 to 16500:

StatusAutorun nameCommandDescription
Xshellexplorer.exeAdded by the KAKKEYS TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
XShellExplorer.exe iexplore.exeAdded by the KIPIS-U WORM! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The legitimate Internet Explorer (iexplore.exe) is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%\Microsoft
XShellibm0000*.exe [* = digit]Added by the TORPIG-C and TORPIG-J TROJANS! Filenames spotted include ibm00001.exe, ibm00002.exe, ibm00005.exe and so on
XShelltaskmrg.exeAdded by the BANCBAN-FT TROJAN!
XShellExplorer.exe winupdate.exeAdded by the AGENT-FD TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The "winupdate.exe" file is located in %System%
XShellExplorer.exe [path] ibm[RANDOM 5 DIGIT NUMBER].exeAdded by the ANSERIN TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files
XShellsvchost.exeAdded by the GOLDSPY-B TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XShellibm00001.dllAdded by the TORPIG-Q TROJAN!
XShellwmedia32.exeAdded by the AGENT-BR TROJAN!
XShellExplorer.exe winsys32.exeAdded by the DELF.CP BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The "winsys32.exe" file is located in %Windir%
XShellWin32.dll.exeAdded by the VB.BTX TROJAN!
XShelltaskmam.exeAdded by the BANCBAN-OL TROJAN!
XShellexplorer.exe msbnc.exeAdded by the AGENT-PL BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The "msbnc.exe" file is located in %System%
XShellExplorer.exe kbdsys.exeAdded by the DAPROSY WORM! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The "kbdsys.exe" file is located in %AppData%\Microsoft\Keyboard
XShellsmsc.exeAdded by the BANCBAN-OY TROJAN!
XShellExplorer.exe init32m.exeAdded by the DLSW-B TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The "init32m.exe" file is located in %System%
XShellExplorer.exe smssnt.exeAdded by the AGOBOT.EE TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The "smssnt.exe" file is located in %System%
XShell API32svcnet.exeAdded by the TIBICK.C WORM!
XShell Extensionspollsv.exeAdded by the LOVGATE.Z WORM!
XShell Tray WindowShellTraywnd.exeAdded by the STULTDOR-A TROJAN!
Xshell updateshellexec.exeAdded by the RBOT-ANC WORM!
XShell.exeShell.exeAdded by the EMERLEOX.S WORM!
XShell32Shell32.vbsAdded by the SCAFENE WORM!
Xshell32ntldrt.exeAdded by the JLOK-A WORM!
XShell32iexplore.exeAdded by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%
XShell32explorer.exeAdded by the SDBOT-NF WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
XShellApiSHELLMSN.EXEAdded by the NETDEV.B BACKDOOR!
XShellapi32Shellapi32.exeAdded by the NETDEVIL (or NERTE) TROJAN!
XShellapi32mcvsrte.exeAdded by an unidentified WORM! Note - do not confuse with the McAfee SecurityCenter file of the same name
Xshellbn[random].dllSoftStop rogue security software - not recommended
Xshellbnshlext32.exeMalware installed by different rogue security software including SpyKillerPro and the XP AntiVirus series
XShellCommand[path to file]Added by the REMCON-A TROJAN!
XShelldaemonShelldaemon.exeAdded by a variant of the AGENT.ALN TROJAN!
XShellExShellEx.exeAdded by the ANAKHA TROJAN!
XShellNisca.exeAdded by the IBILL.Z TROJAN!
XShellOSA+++.exeAdded by the AV TROJAN!
XShellRunlexplore_.exeAdded by the MSNOPT-A TROJAN!
XShellRun32iexplore.exeAdded by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%
XShellspllsas.exeAdded by the YALER-A TROJAN!
XShellsplspools.exeAdded by the PROXAGE-A TROJAN!
Xshellsystemshellsystem.exeAdded by the UPCHAN TROJAN!
Xshhostshhost.exeAdded by the AGENT.CE BACKDOOR!
Nshicoxpshicoxp.exeInstalled with the drivers for multi card readers of various brands. To differentiate between the various card slots on multi slot readers the shicoxp.exe file assigns and loads unique drive icons for the various card slots that are displayed in Windows Explorer
XShield Securityshield.exeAdded by the RIZO.A TROJAN!
XShield32 Securityshield32.exeAdded by the RIZO.A TROJAN!
XShieldSafenessShieldSafeness.exeShieldSafeness rogue security software - not recommended, removal instructions here. A member of the WiniGuard family
XShineShine.exeAdded by the HAPPYLOW (or NISHE-A) VIRUS!
?SHINITVshinitv.exe??
XShmgrate.exeibot4.exeAdded by the GASTER TROJAN!
NShockmachineReminderSmReminder.exe"Shockmachine is a stand-alone application that lets users collect Macromedia Shockwave and Flash titles and play them offline". Could be a registration reminder for the trial version
XShockwavecsrss.exeAdded by the SNDOG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
NShockwave InitSWINIT.EXEPart of Macromedia Shockwave. Controls the Shockwave Remote Control Panel. The Remote Control can be activated manually from the Start Menu by locating and selecting Shockwave and then Shockwave Remote under Programs
XShockwave SupportFlashPlayer.exeAdded by the DELF-DRA WORM!
Xshoketsvchs0t.exeAdded by the WOWPWS-E TROJAN!
NShopSafeShopSafe.exeCreated by Orbiscom for MNBA (now Bank of America) - ShopSafe creates a temporary card number each time you make an online purchase
NShortKeys 99SHORTKEY.EXEShortKeys from Insight Software Solutions - allows you to program keys with text strings
UShortKeys Liteshklite.exeShortKeys Lite from Insight Software Solutions, Inc. A macro utility to automate a task that you perform repeatedly or on a regular basis
YsHotKeysHotKey.exeSpecial function key manager for Chicony keyboards - see here
NShottyShotty.exeShotty by Thomas Baumann - "is an application to take pictures from your computers screen (called screenshots) or from one application only. Unlike other applications that does this Shotty provides various other features that are useful to modify the taken screenshot"
NShotty - Tiny but impressive screenshot utilityShotty.exeShotty by Thomas Baumann - "is an application to take pictures from your computers screen (called screenshots) or from one application only. Unlike other applications that does this Shotty provides various other features that are useful to modify the taken screenshot"
XShowbehindSHOWBEHIND.EXEAdvertisement display which can be stopped here
XShowFFShowFF.exeFFToolBar adware toolbar
?ShowIcon_Justrams_USB Product Driver v2.12r012shwicon.exeRelated to Just Rams USB product driver. Is it required?
UShowIcon_PNY_PNY Attachéshwicon.exePNY Attaché USB flash memory stick System Tray icon - shows when the device is plugged in
?ShowIcon_SmartDisk Corporation_USB Card Reader v1.14e051shwicon.exeCard reader for memory cards from digital cameras. Is it required?
UShowLOMControl[strange symbol]Note that there is a strange symbol in the command field and in logs it's shown as "O4 - HKLM\..\Run: [ShowLOMControl] [strange symbol]". Additional registry information for the entry is "Reg_DWORD 0x00000001 (1)". It means Show "LAN on Motherboard" Control. On systems where you can install an external LAN interface, it will warn you that you already have a built-in LAN interface. Appears to be a feature on certain Dell systems
XShowmeRuden.vbsAdded by the HANDLE-A VIRUS!
UShowWndShowWnd.exeFound on Gateway computers (and maybe others) - see here. "Showwnd is included with the Chicony keyboard software and is used by the software to stop the keyboard driver's taskbar entry from reappearing. It is not necessary to remove the keyboard software, however if you wish it can be removed through Add or Remove Programs"
USHPC32SHPC32.exePort monitor for Lexmark printers on a USB connection. Ties in with the Printer Control Program. Features like cancelling a print are unavailable if disabled
USHSSHS.exe"Rogers Self Help Software is a free suite of tools and utilities for your computer that keeps your system running properly, and makes your Hi-Speed Internet experience smooth and trouble-free"
YShStatEXESHSTAT.EXEPart of McAfee's VirusScan Enterprise corporate anti-virus and anti-spyware security tool
UShutdownawareshutdownaware.exeLoaded by the SWEEX 6-in-1 Media Card Reader to properly manage the reader while it is connected to your system
UShutDownProShutDownPro.exeShutDownPro - shutdown, reboot, logoff your System with one mouse click
XShutDownWindowsRundll32.exe User,ExitWindowsAdded by the VB-HE TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
XShutdownWithoutLjiasvt.exe[path to trojan]Added by the BIFROSE.F BACKDOOR!
Xshvantit.exeAdded by the AGENT-JKU TROJAN!
NSi MeterSIMETER.EXESi Meter - keep track of things like CPU activity, network activity and speed, hard-drive activity, hard-drive space, system memory, running processes, or just date and time
Xsi91e44brundll32.exe si91e44b.dll, EnableRunDLL32LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "si91e44b.dll" file is found in %System%
USIA2006SIA2006.exePart of Steganos Internet Anonym privacy software
USIAPRO6sia.exeSteganos Internet Anonym privacy software
Xsibawerixtomup.exeAdded by the SDBOT.AVB WORM!
XSichererAntiviruspgs.exeSichererAntivirus, German rogue security software - not recommended. A member of the AVSystemCare family
XSichererSchutzpgs.exeSichererSchutz, German rogue security software - not recommended. A member of the AVSystemCare family
XSicherheitsToolSysRep.exeSicherheitsTool, Dutch rogue system error and cleaning utility - not recommended. A member of the ErrClean family
XSicomSicom.exeAdded by the NETLIP WORM!
USideACT!SideACT.exeTo-Do list add-on for the Sage ACT! contact manager
USidebarSidebar.exeWindows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijacker
NSIDEBARdsidebar.exe"Desktop Sidebar provides you with instant access to the information you most desire by grabbing data from your PC and the internet. The result is a dynamic visual display you configure and control"
XSideGreenSideGreen.exeSideGreen adware. File located in %Program Files%\SideGreen
XSideTabSideTab.exeSideTab adware
NSideWinderTrayV4SWTrayV4.exeMS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs
?SIECACSTsiecacst.exeRelated to a Siemens card reader. Is it required?
USightSpeedSightSpeed.exeSightSpeed Video Chat - "lets you connect with all your friends and family easily. Make video calls, phone calls, and send video mails and text messages to everyone in your network, anywhere in the world"
NSigmaTel Audiosetup.exeSigmatel audio driver
NSigmaTel StacMonstacmon.exeInstalled with the drivers for a SigmaTel C-Major Audio card (on a Dell Inspiron 600m PC for example). Appears as though it can be disabled with no ill effects
NSigmatelSysTrayAppstsystra.exeSystem tray program for the Sigmatel Audio sound card. Often found on Dell computers
NSigmatelSysTrayAppsttray.exeSystem tray program for the Sigmatel Audio sound card. Often found on Dell computers
USigXsigx.exeSigX is a "dynamic signature image generated based on whatever data your computer sends it though our SigX program. It can display your current Mp3, current OS, Free Ram, your current time and more"
USigXCSigX.exeSigX is a "dynamic signature image generated based on whatever data your computer sends it though our SigX program. It can display your current Mp3, current OS, Free Ram, your current time and more"
XSilentSoftech[worm filename]Added by the SILLYFDC-BL WORM!

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner