Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 24133 autoruns. Autorun 21301 to 21400:

StatusAutorun nameCommandDescription
NWindows Desktop SearchWindowsSearch.exeSystem Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. On earlier versions this entry also runs the indexing function at startup which indexes files and e-mails items so you can quickly find words and phrases (replaced by a service in later versions). Disabling this entry does not affect the normal operation and indexing will occur when you next perform a search
XWindows Dialup Servicedialup.exeAdded by the AGOBOT.AAH WORM!
XWindows Disk Defragmenterwpabaln32.exeAdded by the BANCOS-ASJ TROJAN!
XWindows Disk Managercmnvc.exeAdded by a variant of the IRCBOT TROJAN!
XWindows Display Couplerdisplay.exeAdded by the IRCBOT-YS TROJAN!
XWindows DLL hostwinupd32.exeAdded by a variant of the SPYBOT WORM!
XWindows DLL Hostdllhost32.exeAdded by an unidentified WORM or TROJAN!
XWindows DLL Loaderrundll32.exeAdded by the WHIPSER-B WORM! Note - this is not the legitimate rundll32.exe process
XWindows DLL Loaderdefragfat32pi.exeAdded by the RBOT-QQ WORM!
XWindows DLL Loaderdefragfat39.exeAdded by the POEBOT-C WORM!
XWindows DLL Loaderdefragfatz.exeAdded by the LINKBOT.H WORM!
XWindows DLL Loaderdefragfat32.exeAdded by the SDBOT-SS WORM!
XWindows DLL Loaderdefragfat32abc.exeAdded by the RBOT-RG WORM!
XWindows DLL Loaderwdevice.exeAdded by a variant of the SDBOT WORM!
XWindows DLL LoaderSYSCFG16.EXEAdded by the DOMWIS-N WORM!
XWindows DLL LoaderWINCFG32.EXEAdded by the AGOBOT-TE WORM!
XWindows DLL Loaderdefragfatx.exeAdded by the POEBOT-F WORM!
XWindows DLL LoaderRUNDLL16.EXEAdded by the DOMWIS TROJAN!
XWindows DLL Loaderdefragfat32z.exeAdded by the LINKBOT.A WORM!
XWindows DLL Serviceswinsvc32.exeAdded by the RBOT-ZF WORM!
XWindows DLL Servicessvchost.exeAGENT.H spyware. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!
XWindows DLL Servicessystem.exeAGENT.H spyware
XWindows DLL Trackerspoolsrv.exeAdded by a variant of the WOOTBOT WORM!
XWindows DLL Verifierxptl.exeAdded by a variant of the RBOT WORM!
XWindows DLL Verifierwindlls.exeAdded by the RBOT-AZQ WORM!
XWindows DNSwindns.exeAdded by the SDBOT-XU WORM!
XWindows DNS Daemonwindnsd.exeAdded by the WOOTBOT.AS WORM!
XWindows Domain Name Driverswindns.exeAdded by the FORBOT-EP WORM!
XWindows DOSdosw.exeAdded by the SALAY-A WORM!
XWindows DotFix livemsdotfix.exeAdded by the IRCBOT.XGK BACKDOOR!
XWindows Download Managerwindlmngr.exeAdded by an unidentified TROJAN!
XWindows Drive CompatibilitySystem32Driver32.exeAdded by the SUPOVA.Z WORM!
XWindows Driverwinxpdriver.exeAdded by the WOOTBOT.EE WORM!
XWindows Driverwindrive.exeAdded by a variant of the IRCBOT BACKDOOR! See here
XWindows Driver Adaptersvchost.exeAdded by the ANTINNY-K WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "drivers" subfolder
XWindows Driver FoundationMTVSCMXT.EXEAdded by a variant of the RBOT WORM!
XWindows Driver Servicesmsdrvs32.exeAdded by the WOOTBOT.L WORM!
XWindows Driver Supwindvrhost.exeAdded by a variant of the IRCBOT BACKDOOR! See here
XWindows driver updatedmsvc32.exeAdded by the SDBOT-GP BACKDOOR!
XWindows driver updateIpconfig32.exeAdded by the SDBOT-JV WORM!
XWindows driver updatenmsmtp32.exeAdded by the SDBOT-JT WORM!
XWindows Driver!windriver.exeAdded by a variant of the IRCBOT BACKDOOR! See here
XWindows Driversssms.exeAdded by the RBOT-AT WORM!
XWindows drivers updatewindowsupdate.exeAdded by the RBOT-ACE WORM!
XWindows Dump Errortaskmgr.exeAdded by the PALEVO-X WORM! Note - this is not the legitimate taskmgr.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XWindows Dynamic Library Cachedllcache.exeAdded by the INJECT-HT TROJAN!
XWindows Dynamic Loading HeaderwinDLL32.exeAdded by a variant of the SDBOT WORM!
XWindows Email Serverwmserv.exeAdded by the FOUNDU-AWORM!
XWindows Enterprise DefenderWindowsEDefender.exeWindows Enterprise Defender rogue security software - not recommended, removal instructions here
XWindows Enterprise SuiteWE[random characters].exeWindows Enterprise Suite rogue security software - not recommended, removal instructions here
XWindows Essensialsmvnesc.exeAdded by a variant of the IRCBOT TROJAN!
XWindows Event Detectionwecsvc.exeAdded by a variant of the IRCBOT TROJAN! See here
XWindows Event Providerwposvc.exeAdded by a variant of the IRCBOT TROJAN! See here
XWindows Event Sectionsntsvc.exeAdded by a variant of the IRCBOT TROJAN! See here
XWindows Event Servicewinserv.exeAdded by a variant of the IRCBOT BACKDOOR!
XWindows Executablewinmys.exeAdded by the RBOT-ABO WORM!
XWindows Executerbling.exeAdded by the SDBOT-DFT WORM!
XWindows Executersvchostie.exeAdded by the EGGDROP.V BACKDOOR!
XWindows ExpIorer[random filename]Added by the RBOT-AKO WORM!
XWindows Explorer[filename].exeAdded by the SDBOT TROJAN!
XWindows ExplorerLsas.exeAdded by the GAOBOT.AO WORM!
XWindows Explorerolecom32.exeAdded by an unidentified WORM or TROJAN!
XWindows ExplorerEEXPLORER.EXEAdded by a variant of the SPYBOT WORM!
XWindows Explorerexplorer.exeAdded by the POEBOT-J WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
XWindows Explorerexplorer.pifAdded by the RBOT-AID WORM!
XWindows Explorersystem32.exeAdded by the RBOT-AJH WORM!
XWindows Explorerexplorer32.exeAdded by a variant of the SDBOT WORM!
XWindows ExplorerWindows Explorer.EXEAdded by the VB-EBA WORM!
XWindows Explorersystem.exeAdded by the STIRAUT WORM!
XWindows Explorer Keyexplorer.exeAdded by the IRCBOT-YB WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
XWindows Explorer Servicesexploresys.exeAdded by a variant of the IRCBOT BACKDOOR! See here
XWindows Explorer ShellWinexec32.exeAdded by the REDIST.B WORM!
XWindows Explorer SP2csrss.exeAdded by the BANKER-DM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "JavaBeans" subfolder
XWindows Explorer Update Build 1142EXPLORER32.EXEAdded by the KaZaA based KWBOT or KWBOT.Y WORMS!
XWindows Explorer-3212WINRE16.EXEAdded by the HARDOC WORM!
XWindows Explorer.exeExplorer.exeAdded by the FALTER-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
XWindows Expresspci32b.exeAdded by the BUZUS.C TROJAN!
XWindows Extensions for Win32winprgs32.exeAdded by the SDBOT.AFA WORM!
NWindows Eyes??For blind people, gives a voice description of items on the screen. Windows application which gives you total control over what you hear, when you hear it, and how you hear it. Available via Start -> Programs
XWindows FAT 32WINFAT32B.exeAdded by the SPYBOT-AGT WORM!
XWindows File Migration WizardHIMENSYST.EXEAdded by the RBOT-EMO WORM!
XWindows File Protectionwinprotect.exeAdded by the AGOBOT.JB WORM!
XWindows File System Framentframe.exeAdded by an unidentified WORM or TROJAN!
XWindows File Verification Servicewfvs.exeAdded by the RANKY.AC TROJAN!
XWindows File XP Managerwfdmgr.exeAdded by the SDBOT.XD TROJAN!
XWindows FileSharing Servicemcwsvc.exeAdded by the IRCBOT.AJF BACKDOOR!
XWindows Firevall Control Crundll.exeAdded by the GAERTOB.A TROJAN!
XWindows FirewalLsess.exeAdded by a variant of the RBOT WORM!
XWindows FirewallWindowsFirewall.exeAdded by the MYTOB.AO WORM!
XWindows Firewallsvchost.exeAdded by the PROXY-HT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XWindows Firewallipservice32.exeAdded by a variant of the RBOT WORM!
XWindows Firewallrundll32.exeAdded by a variant of the IRCBOT BACKDOOR!
XWindows Firewallmsmsd.exeAdded by the VB-OG MALWARE!
XWindows Firewall Logwinlog.exeAdded by an unidentified WORM or TROJAN!
XWindows Firewall Managermsfw.exeAdded by the RBOT.WR WORM!
XWindows firewall managerchh.exeAdded by a variant of the RANDEX.GEL WORM!
XWindows firewall managermsguard.exeAdded by a variant of the RANDEX.GEL WORM!
XWindows Firewall Servicewfsvc.exeAdded by the IRCBOT-YL WORM!
XWindows Firewall Updaterupdatees.exeAdded by the RBOT-GBX WORM!
XWindows Firewall Updatercronos.exeAdded by the RBOT-GBY WORM!

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner