Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 24133 autoruns. Autorun 18601 to 18700:

StatusAutorun nameCommandDescription
Xsystemguardsystemguard.exeSystem Guard 2009 rogue security software - not recommended, removal instructions here
?SystemGuardAlerterSystemGuardAlerter.exePart of the Iolo System Mechanic maintenance software. What does it do?
XSystemGuardCenterSystemGuardCenter.exeSystem Guard Center rogue security suite - not recommended, removal instructions here
XSystemHelpRUNDLL32.EXE SystemHper.dll,InstallAdded by the WOW.COK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "SystemHper.dll" file is found in %System%
XSystemILSYSTEMIL.EXEAdded by the ABOC VIRUS!
XSystemInitiservc.exeAdded by the FIZZER WORM!
Xsysteminitsysteminit.exeAdded by the SILLYFDC-AN WORM!
XSystemiom UpdaterSystemiom.exeAdded by the SPYBOT.TY WORM!
XSystemIronSystemIron.exeSystemIron rogue security software - not recommended, removal instructions here. A member of the WiniGuard family
Xsystemkernal.exesystemkernal.exeAdded by the AGENT-KPQ TROJAN!
USystemKeyrundll32.exe [path] SystemKey.dll rdlStealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
Xsystemkssystemks.exeAdded by the DKS.11.B TROJAN!
XSystemLoad32sysload32.exeAdded by the MIMAIL.E WORM!
XSystemLoadersysldr32.exeAdded by the DOWNLDR-NS TROJAN!
XSystemManagerSysman32.exeAdded by the DOWNLOADER-BW.B TROJAN!
XSystemManager[random filename]Added by the SETTEC ROOTKIT!
XSystemMap32Netisp32.vbsAdded by the REDIST.C WORM!
XSystemMDmd.exeHomepage hijacker
XSystemMessengerrundll32.exe [path] SystemMessenger.dllStealth Chat Monitor spyware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
XSystemMgrIr32_a.exeAdded by the MAGANIA-OU TROJAN!
XSystemMigrationWinMedia.exeAdded by the KELVIR.EI WORM!
XSystemMonitorSysmon32.exeAdded by the AIDID.A WORM!
XSystemNetworkNETSERV.EXEAdded by the NETCONTROL VIRUS!
XSystemNetworksysnet.exeAdded by a variant of the RBOT WORM!
XSystemNTSystemNT.exeAdded by the PWSVB-EG TROJAN!
Xsystemntfysystemntfy.exeAdded by the MINUDAZASH WORM!
XSystemOPsvscrtvc32.exeAdded by a variant of the SPYBOT WORM!
XSystemOptimizer2008main.exeSystemOptimizer2008 rogue optimization utility - not recommended, removal instructions here
XSystemOrdnareSysRep.exeSystemOrdnare, Swedish rogue system error and cleaning utility - not recommended. A member of the ErrClean family
XSystemProcEvent[trojan filename]Added by the IRCBOT.I TROJAN! Filenames used are csrwnd.exe, csrwjd.exe & csrnvrt.exe
Xsystemrd11host.exeAdded by the VB-GX TROJAN!
Xsystemrgedit.exeAdded by the ADCLICK-AQ TROJAN!
Xsystemr[path to trojan]Added by the VB-HD TROJAN!
?SystemRegPROCES.EXE??
XSystemRegsvchost.exeAdded by the DEWIN.E BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XSystemRegWINREG.EXEAdded by the DEWIN.A BACKDOOR!
XSystemRegistryRepairtemp.exeAdded by the NOKPUDA WORM!
XSystemssescmgr.exeAdded by the DWNLDR-GAH TROJAN!
XSystemsspoolsvc.exeAdded by the DLOADR-SW TROJAN!
XSystemssysmon.exeAdded by the VIXUP-BI WORM!
XSystemsscchost.exeAdded by the DAEMOZ.A TROJAN!
XSystemssvch0st.exeAdded by the MYDOOM.BI WORM!
XSystemsSystems.exeAdded by the BANKBOA-A TROJAN!
XSystemsitDDD.exeAdded by the DLOADER-PP TROJAN!
XSystems Backupswindrives.exeAdded by the AGOBOT-RB WORM!
XSystems Restartslchost.exeAdded by the MULTIDROP.C TROJAN!
XSystems Restartspchost.exeAdded by an unidentified WORM or TROJAN!
XSystems RestartRundll32.exe beem.dll, DllRegisterServerBrowser hijacker - the file serves to register a dll implemented as a browser plugin. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
XSystems RestartRundll32.exe snim.dll, DllRegisterServerAdded by the STARTPAGE.I TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
XSystems RestartRundll32.exe zolk.dll, DllRegisterServerAdded by a variant of the STARTPAGE TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
XSystems RestartRundll32.exe boln.dll, DllRegisterServerAdded by the STARTPAGE.J TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
XSystems Servicedrivex.exeAdded by a variant of the RBOT WORM!
Xsystems usb driverWindows2.exeAdded by a variant of the RBOT WORM!
USystems.exeSystems.exeKeyboard Spectator - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it
Usystems.exesystems.exeKGBSpy is a commercial surveillance software program. It logs keystrokes, Web sites visited, and clipboard activity. It also has a screen capture logger and can be run automatically in a silent, undetectable mode
USystemSafeSyssafe.exeSystem Safety Monitor - system monitoring tool with additional application firewalling
XSYSTEMSars32csrss.exeAdded by the AHLEM.A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XSystemSASSystem32.exeAdded by the KWBOT.C WORM!
Xsystemscrootsystembin.exeAdded by a variant of the RBOT WORM!
XSystemSearchregedit.exe -s ie.regInstalls a Seachxl.com browser page hijack. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file "ie.reg" is located in the root folder (ie, C:\)
XSystemSearchregedit.exe -s sys.regInstalls a i--search.com browser page hijack. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file "sys.reg" is located in %Windir%
XSystemSecurityzprot32.exeAdded by the AGENT-FK TROJAN!
XSystemServicemsocfg.exePremium rate adult content dialler
XSystemServicenavchk.exePremium rate adult content dialler
XSystemServiceqservice.exePremium rate adult content dialler
XSystemServiceshman.exePremium rate adult content dialler
USystemServicensserver.exeNiceSpy keystroke logger/monitoring program - remove unless you installed it yourself!
XSystemSettingfTRUG.vbsAdded by the TRUG.B MACRO!
XsystemStartNtfs.exeAdded by the AUTORUN-JM WORM!
XSystemStartma2012.exeMega Antivirus 2012 rogue security software - not recommended, removal instructions here
USystemSuite Task ManagerMXTASK.EXEvcom (nee Ontrack) SystemSuite - PC maintenance and security. Use the program's configuration options to enable only the parts you want running all the time - such as Virusscanner Pro
XSystemSv12newmaxxsv234.exeAdded by the TIBS-TS TROJAN!
XSystemSv121n2ewma1xxsv234.exeAdded by the TIBS.TJ TROJAN!
XSystemTasksfilez.exeAdult content dialler
XSystemTaskssexypicz.exeAdult content dialler
XSystemTasksloaded.exeAdult content dialler
XSystemToolskernels32.exeAdded by the DLOADER-FC TROJAN!
XSystemToolskernels1118.exeAdded by the SMALL.DGK TROJAN!
XSystemToolskernels8.exeAdded by the FNG TROJAN!
XSystemToolskernels88.exeAdded by the TIBS-PP TROJAN!
XSystemToolstesttestt.exeAdded by the DWNLDR-ZLC TROJAN!
XSystemtraSystra.exeAdded by the LOVGATE-W WORM!
XSystemTraCDPlay.EXEAdded by the LOVGATE.Z WORM!
XSystemTraVideo.EXEAdded by the LOVGATE.E WORM!
USystemTraySysTray.ExeFor Win9x/Me - System Tray Services. Provides the Volume Control, PC Card Status, Power Management and other icons that reside in the System Tray (see here). SYSTRAY.EXE may be disabled if none of these services are required. It will launch as and when required if you later enable the icons. If you need these items they're available via Start → Settings → Control Panel
XSystemTraySystemTray.exeAdded by the BIGFOOT TROJAN! Note - this is not the legitimate systray.exe process
XSystemTraySysTray.exeAdded by the ALADINZ.P TROJAN! Note - this is not the legitimate systray.exe process. If you right-click on the real systray.exe the "Properties" reveal it to be a Microsoft file
XSystemTraylsvhostwinlk.exeAdded by a variant of the SPYBOT WORM!
XSystemTraymssgl2.exeAdded by a variant of the IRCBOT TROJAN!
XSystemTraywekls4.exeAdded by a variant of the IRCBOT TROJAN!
XSystemTrayWindowsupd.exeAdded by a variant of the IRCBOT TROJAN!
XSystemTray MonitorSysTraymon.exeAdded by a variant of the SPYBOT WORM! See here
USystemTraySDSDSystemTray.exeSpyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here
USystemTraySRSRSystemTray.exeSpyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here
XSystemTunerSystemTuner.exeSystem Tuner rogue system suite - not recommended, removal instructions here
NSystemUpdSystemUpd.exeUpdater for Swapoo.com, a kind of Napster for games
XSystemUpdateNegdo.exeAdded by the CULLER-C WORM!
XSystemUpdateXeyu.exeAdded by the CULLER-D WORM!
XSystemVeteran.exeSystemVeteran.exeSystemVeteran rogue security software - not recommended, removal instructions here. A member of the WiniGuard family
Xsystemw32systemw32.exeAdded by a variant of the RBOT WORM!

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner