Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 24133 autoruns. Autorun 20801 to 20900:

StatusAutorun nameCommandDescription
XWin32 Services Configwinwkys.exeAdded by the RBOT.BKY WORM!
XWin32 Services1wuamngr1.exeAdded by the SDBOT-PV WORM!
XWin32 Src Servicewin32src.exeAdded by the RBOT-SX WORM!
XWin32 SSL Driverwinssv.exeAdded by the FORBOT-BH WORM!
XWin32 Svchosts Driversvchosts.exeAdded by the FORBOT-FO WORM!
XWin32 System Kernelwinservice.exeAdded by the SDBOT.KIN WORM!
Xwin32 system serverwinserver.exeAdded by the DERMON-A TROJAN!
XWin32 System Spoolspoolsvc.exeAdded by the SDBOT.UK WORM!
XWin32 Testbleatest.exeAdded by a variant of the RBOT WORM!
XWin32 Updatesvchosts.exeAdded by a variant of the SDBOT WORM!
XWin32 Updatedl32.exeAdded by an unidentified WORM or TROJAN!
Xwin32 update servicesvchostt.exeAdded by a variant of the SDBOT WORM!
XWin32 USB Driverwinxpinit.exeAdded by the SDBOT.AA TROJAN!
XWin32 USB Drivermvsecn.exeAdded by the FORBOT-BK WORM!
XWin32 Usb Driversvhosint32.exeAdded by the FORBOT-BE or FORBOT-J WORMS!
XWin32 Usb Driverusb32.exeAdded by the SDBOT-OV WORM!
XWin32 Usb DriverAvpG.exeAdded by the FORBOT-BX WORM!
XWin32 USB Driverrundll.exeAdded by the FORBOT-BN WORM! Note - this is NOT the Win9x/Me system file of the same name as described here
XWin32 USB2wins32.exeAdded by a variant of the RBOT WORM!
XWin32 USB2 Driverwin32usb.exeAdded by the SPYBOT.DHV WORM!
XWin32 USB2 Driversmsc.exeAdded by the SDBOT.FO WORM!
XWin32 USB2 Driversvchosting.exeAdded by the FORBOT-J or SDBOT.HU WORM!
XWin32 USB2 Driversys32.exeAdded by the WOOTBOT.X WORM!
XWin32 USB2 Driversys32snd.exeAdded by the FORBOT-AN WORM!
XWin32 USB2 Driverwind32.exeAdded by the FORBOT-AH WORM!
XWin32 USB2 Driverwinupdate.exeAdded by the AGOBOT.YE WORM!
XWin32 USB2 Driverupdatemgr.exeAdded by a variant of the FORBOT WORM!
XWin32 USB2 Driverwinsnd32.exeAdded by a variant of the SDBOT WORM!
XWin32 USB2 Drivermsn.exeAdded by the FORBOT-EX WORM!
XWin32 USB2 Driversyscfg32.exeAdded by the FORBOT-R WORM!
XWin32 USB2 Driveralgg.exeAdded by the TIBS.BF WORM!
XWin32 USB2 Driverusb2.exeAdded by the FORBOT-Y WORM!
XWin32 USB2 Driverwinusb32.exeAdded by the FORBOT-M WORM!
XWin32 USB2.0 Driver386.exeAdded by the IRCBOT.D WORM!
XWin32 USB2.0 Driverrundll16.exeAdded by the WOOTBOT.H WORM!
XWin32 USB2.0 Driverw32usb2.exeAdded by the SPYBOT.DN WORM!
XWin32 USB2.0 Driverservice.exeAdded by the SDBOT-QF WORM!
XWin32 USB3 Driverwin32tool.exeAdded by a variant of the RBOT WORM!
XWin32 Wmls Driverwinitr32.exeAdded by the WOOTBOT.B WORM!
XWin32 Word Servicesmsword32.exeAdded by a variant of the RBOT WORM!
XWin32.exeWin32.exeAdded by the AWQ.A BAKCDOOR!
XWin32.Exploit.mzHmzrun.exeAdded by the PAINTER TROJAN!
XWin32.PozarevacPozarevac.exeAdded by the DELF-FBN TROJAN!
XWin32.Trojan.Downloadernetstat2.exeAdded by the PAINTER TROJAN!
XWIN32[random numbers][path to file]WinBo adware
Xwin32_i lptt01win32_i.exeRapidBlaster variant (in a "win32_i" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it
Xwin32_i ml097ewin32_i.exeRapidBlaster variant (in a "win32_i" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it
Xwin3208022-1336687win3208022-1336687.exeAdded by the VB-CFG TROJAN!
XWin32BaseServiceMODWintask.exeAdded by the NAVIDAD WORM!
Xwin32betawin32sys4.exeAdded by the BANKER-DA TROJAN!
Xwin32clfwin32clf.exeAdded by an unidentified VIRUS, WORM or TROJAN!
Xwin32debugwin32debug.exeAdded by the GUDEB WORM!
XWin32DLLWin32DLL.vbsAdded by the LOVELETTER (I LOVE YOU) VIRUS!
XWin32dllWin32dll.exeAdded by the BANPAES TROJAN!
XWIN32DSclienttimer.exeEziin adware
XWin32GKernel32.comAdded by the ESTRELLA TROJAN!
XWin32GScandisk.comAdded by the ESTRELLA TROJAN!
Xwin32gbwin32gb.exeAdded by the DLUCA-F TROJAN!
XWin32Host Processwebemir.exeAdded by the TURGEN -A TROJAN!
Xwin32infowin32info.exeAdult content dialler
Xwin32inisystroy.exeAdded by the IRC.ALADINZ.C TROJAN!
XWIN32ioclienttimer.exeEziin adware
Xwin32Kernelfindx.exeAdded by the BANLOA-EY TROJAN!
XWin32KernelStartmicrosoft.exeAdded by the DELF-EWZ TROJAN!
XWin32load[random].exeAdded by the LODELIT TROJAN! Note - the file is located in %AppData%
XWin32loadnscagent.exeAdded by the DOWNLOADER-BON TROJAN!
XWin32loadptssvc.exeAdded by the FAKEAV-MK TROJAN!
XWin32loadsysrc32.exeAdded by the DOWNLOADER-BON TROJAN!
XWin32Mgr[path to trojan]Added by the AIMSPY TROJAN!
XWin32RServer.comAdded by the ESTRELLA TROJAN!
XWIn32S Java DLLkavsvx.exeAdded by the AGOBOT-RZ WORM!
Xwin32servdevicer.exeAdded by the CHECKOUT WORM!
Xwin32servservicesetup.exeAdded by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger
Xwin32servsystemdevices.exeAdded by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger
Xwin32servvload.exeiSearch adware
Xwin32servvms1.exeiSearch adware
YWIN32SLWin32sl.exePart of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. The specific function of this is to load MIF's in order for Dell OpenManage Client to work
XWIN32SNDSbanc.exeAdded by an unidentified WORM or TROJAN!
XWin32system[random filename]Added by the DDV.B WORM!
XWin32Systemwin32s.exeAdded by the MYDOOM.V WORM!
XWin32SystemMonitor[random filename]Added by the AGENT.IT TROJAN!
XWin32SysVxin.exeAdded by the FORBOT-EO WORM!
XWin32Update[malware filename]Added by the MOMIBOT BACKDOOR!
Xwin32updatewin32update.exeAdded by the GENOME.AQUV TROJAN!
XWin32UpdaterKERNAL32.EXEAdded by the SPYBOT-OK WORM!
Xwin32uswin32us.exeAll-In-One-Telcom (adult content dialler) variant
Xwin32usbdssrs.exeAdded by the RBOT-RA WORM!
XWin32UsrWinCab.exeAdded by the DEDMIR-A WORM!
XWIN32WNsystem_wc.exeEziin adware
XWin386Win386.exeAdded by the GOSUSUB VIRUS!
XWin386sp32.dllHomepage hijacker. Not a dll but a regfile in disguise
XWIN3S2SNDSwinabsmod.exeAdded by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well"
XWIN3S2SNDSwiniprtx.exeAdded by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well"
XWin64 Compatibility Checkload win64.drvCoolWebSearch parasite variant
XWin7 AVWin7 AV.exeWin7 AV rogue security software - not recommended, removal instructions here
XWIN95DEFVIEW[path to file]Added by the DEDLER-D TROJAN! The most common filenames seen are "csmss.exe" and "csmrs.exe", located in %System%
Xwin98 DNSwingrd.exeAdded by a variant of the RBOT WORM!
Xwinabcrundll32.exe [Temp]\[ORIGFILENAME].DLL,InstallLaunchEvAdded by the LINEAGE-PN TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
XWinAblewinable.exeAdded by the MATCASH.BG TROJAN!
XWinAC v4klsuicbn.exeAdded by the FORBOT-CS WORM!

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner