| Status | Autorun name | Command | Description |
| X | Auto Start | windos.exe | Added by the SLINBOT.BO BACKDOOR! |
| X | Auto Started | winsME.exe | Added by the RBOT.B WORM! |
| U | Auto Switch | TASKBAR.exe | Related to 2-port Bitronics AutoSwitch kit from Belkin |
| N | Auto T Bar | autotbar.exe | If you disable the HP VIEW toolbar in IE and rearrange the toolbars on a reboot they will be back as they were before if this is left enabled |
| X | Auto Updat | WindowsSys32.exe | Added by a variant of the FORBOT WORM! |
| X | Auto updat | crcss.exe | Added by the SDBOT.AAG WORM! |
| X | Auto updat | SysDebug.exe | Added by the FORBOT-BA WORM! |
| X | Auto Update | AUP.exe | Added by the RBOT.ACD WORM! |
| X | Auto Update | dma.exe | Added by the RBOT-AVO WORM! |
| X | Auto Update | svchost.exe | Added by the DUMARDI-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Auto Updater | asclt.exe | Added by the SLINBOT.CJ BACKDOOR! |
| X | Auto Updates | svchost.exe | Added by the CHEUKO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Auto WinUpdate | taskmrg.exe | Added by the RBOT-AFA WORM! |
| X | auto__antiav__key | antiav_exe.exe | Added by the BAGLEDI-AA TROJAN! |
| X | auto__hloader__key | hloader_exe.exe | Added by the BAGLE.AB TROJAN! |
| X | AutoAdministrator | SERVICES.EXE | Added by the PUNYA-A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\Application Data\WINDOWS |
| U | Autobar | autobar.exe | Connect buttons on the keyboard for internet direct access, etc. on HP computers |
| N | AutoCAD | acstart17.exe | Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings |
| N | AutoCAD Startup Accelerator | acstart16.exe | Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings |
| N | AutoCAD Startup Accelerator | acstart17.exe | Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings |
| X | autochk | rundll32.exe autochk.dll,_IWMPEvents@16 | Added by the OPACHKI.A TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "autochk.dll" file is found in %System% |
| X | autochk | rundll32.exe protect.dll,_IWMPEvents@16 | Added by the OPACHKI.A TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "protect.dll" file is found in %UserProfile% |
| U | autoclk | autoclk.exe | Autoclik is a Windows utility "that allows you to perform all mouse activity with absolutely no clicking" |
| X | AutoDiscovery/AutoPurge (ADAP) Service | wmiadapi.exe | Added by the RBOT.FLT WORM! |
| N | AutoEA | Ahqrun.exe | For Creative Soundblaster Live! series soundcards. Specify for any audio application what audio preset to automatically associate with currently active speaker output. Available via AudioHQ |
| X | AUTOEXE | AUTOEXE.exe | Added by the SEMAPI-A WORM! |
| X | autoload | cftmon.exe | Added by the SOCKS-E WORM! |
| X | autoload | spooll.exe | Added by the SILLYFDC WORM! |
| X | autoload | windowsupdate.exe | Added by the POLYCRYP.DY TROJAN! |
| X | autoload | spool.exe | Added by the AGENT-GSG TROJAN! |
| X | Autoloaderaproposclient | Apropos_Client_Loader.exe | AproposMedia adware |
| X | Autoloaderaproposclient | cxtpls_loader.exe | AproposMedia adware |
| X | AutoLoaderEnvoloAutoUpdater | auto_update_loader.exe | Envolo/AproposMedia adware updater |
| N | AutoMate Task Service | automate.exe | Task scheduler for Unisyn Automate 4 task automation/macro running software. Available via a desktop shortcut or Start → Programs |
| U | AutoMate5 | Am5HkWnd.exe | "Automate is the Leading Software for Automation of front and back-office business processes.It provides all the tools necessary to completely automate business processes, regardless of their complexity" |
| U | AutoMate6 | AMEM.exe | AutoMate 6 for automating repetitive tasks |
| X | Automated Windows Updates | wauclt.exe | Added by the GAOBOT.AJD WORM! |
| X | Automatic Defrag Manager | defrag.exe | Added by the RBOT-AKE WORM! |
| X | Automatic Media Update | CACHE.RVD | Added by an unidentified WORM/TROJAN! |
| X | Automatic Media Update | HPLNT32.RVD | Added by an unidentified WORM/TROJAN! |
| X | Automatic Microsoft Windows Updater | suchost.exe | Added by the RBOT-EQ WORM! |
| X | Automatic Updates | algs.exe | Added by the IRCBOT-AAM TROJAN! |
| X | Automatic Windows Updater | Update.exe | Added by the GAOBOT.AO WORM! |
| N | Automatically launches the United Devices Agent when you start your computer | UD.EXE | The United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start > Programs |
| X | autoMe | wscript.exe solution.vbs | Added by the VBS.SASAN WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "solution.vbs" file is found in %Windir% |
| X | autoMe | wscript.exe samok.vbs | Added by the SAMOK-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "samok.vbs" file is located in %Windir% |
| X | Autopdate | Autopdate.exe | Added by the RBOT-AGL WORM! |
| N | AUTOPROP | REGPROP.EXE WMPADDIN.DLL | Both the files are in the MS Office/Bots/FP_WMP directory. Apparently, it registers the FrontPage WiMP extension |
| X | AutoProtect | AutoProtect.vbs | Added by the KILLBAT-C WORM! |
| X | AUTOPROTECTU | navapq32.exe | Added by an unidentified WORM or TROJAN! |
| X | autorepair | dexs.exe | Added by a variant of the SDBOT WORM! |
| X | autorn | autorn.exe | Added by the SILLYFDC.BCY WORM! |
| U | Autoroute SMTP | AutoSmtp.exe | Autoroute SMTP - "automatic switching between SMTP servers depending on what network you are currently working in." You need to have two Internet service providers |
| X | autorun | autorun.exe | Added by the AUTOM-B WORM! |
| X | autorun | sxs.exe | Added by the SMALLVBS-A WORM! |
| X | autorun | winmain.exe | Added by a variant of the DELF.CNS TROJAN! |
| X | AutoRun | allrs.exe | Added by the MUDROP.LJ TROJAN! |
| X | AUTORUN_VAL | AntiSpyCheck 2.1.exe | AntiSpyCheck rogue spyware remover - not recommended, removal instructions here |
| X | AUTORUN_VAL | asc 2.1.exe | AntiSpyCheck rogue spyware remover - not recommended, removal instructions here |
| X | autorundemo | [path to trojan] | Added by the AGENT-FPX TROJAN! |
| ? | AutoShutdown | pssvc.exe | Utility to fix vCard Export in MS Outlook 2000 - although why are these together? |
| U | AutoSizer | AUTOSIZER.EXE | AutoSizer - utility that automatically maximizes windows when they're opened |
| N | AutoSpell | autospel.exe | AutoSpell - spell checker (version 6.*) |
| N | AutoSpell 5 | ASWATC32.EXE | AutoSpell - spell checker |
| X | AutoStart | [path to backdoor] | Added by the QUEJOB.EVL BACKDOOR! |
| N | AutoStart PC Studio | NewPCStudio.exe | SAMSUNG New PC Studio - "is the application to organize the contents between Samsung mobile and PC. NPS provides you with convenient access to your device, data management via easy backup and sync, and powerful multimedia features". This allows you (amongst other options) to backup your devices contents to your PC, use it to connect to the internet, transfer files and synchronize contacts, etc. Available from the start menu |
| N | AutoStartNPSAgent | NPSAgent.exe | Installed with the SAMSUNG New PC Studio mobile device management utility. Detects when a supported mobile device is connection and optionally automatically loads the main program |
| U | AutoSys | autosys.exe | Winguardian surveillance software. Uninstall this software unless you put it there yourself |
| N | autotbar | autotbar.exe | If you disable the HP VIEW toolbar in IE and rearrange the toolbars on a reboot they will be back as they were before if this is left enabled |
| N | AutoTKit | AUTOTKIT.EXE | On HP PC's. Unclear what purpose it serves - but there's a known issue with Internet Explorer Toolbar settings not being saved with it enabled |
| N | autoupd | autoupd.exe | Raxco Software auto update utility |
| X | autoupd | autoupd.exe | Added by an unidentified VIRUS, WORM or TROJAN! - found in a folder of the same name |
| X | autoupdate | rundll32 DATADX.DLL,SHStart | Added by a variant of the QOOLOGIC TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "DATADX.DLL" file is found in %System% |
| X | autoupdate | rundll32 SUPDATE.DLL,SHStart | Added by a variant of the QOOLOGIC TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "SUPDATE.DLL" file is found in %System% |
| X | AutoUpdate | smss.exe | Added by WINSPY.88! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64 |
| X | Autoupdate Service | kaka.exe | Added by the SYMPE-B TROJAN! |
| X | Autoupdate Service | [path to trojan] | Added by the AGENT-CB TROJAN! |
| X | AutoUpdate32 | services.exe | Added by WINSPY.88! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64 |
| X | AutoUpdater | aupdate.exe | Tinybar variant |
| X | AutoUpdater | AutoUpdate.exe | PeopleonPage foistware |
| X | autoupdatev2 | [path to file] | Added by the DROPPER-BM TROJAN! |
| X | autoupdatev2 | autoupdatev2.exe | Detected by Kaspersky as the AGENT.FQ TROJAN! |
| X | AutoVaccineMain | AutoVaccine.exe | AutoVaccine rogue security software - not recommended, removal instructions here |
| X | AutoVirusProtection | ciscv.exe | Added by a variant of the RBOT WORM! |
| X | aux.exe | aux.exe | Added by the ZINS TROJAN! |
| X | auxAudioDevice | aux32.exe | Added by the AIZU WORM! |
| N | AUXXTRAY | au30setp.exe | System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel |
| X | AV | UPDATE-28062004.exe[25 blank spaces].vbs | Added by the MIDFIN WORM! |
| X | AV | Antivir.exe | Antivir rogue security software - not recommended, removal instructions here |
| X | av | expressav.exe | Express Antivirus 2009 rogue security software - not recommended, removal instructions here |
| X | AV AntiSpyware | ava.exe | AV AntiSpyware rogue security software - not recommended, removal instructions here |
| X | AV Care | AvCare.exe | AvCare rogue security software - not recommended, removal instructions here |
| X | AV Client | patch31345.exe | Added by the MYDOOM.AD WORM! |
| X | AV Industry | patch31345.exe | Added by the MYDOOM.AD WORM! |
| X | AV UpDate | Update.exe | Added by the FUROOT-A TROJAN! |
| X | AV7 | antivirus7.exe | Antivirus7 rogue security software - not recommended, removal instructions here |
| X | AV8 | av8.exe | Antivirus8 rogue security software - not recommended, removal instructions here |
| N | AvaFind | AvaFind.exe | AvaFind file search utility |
| X | avagent3974 | chnb8895.exe | AntiVirus ransomware security software - not recommended, removal instructions here |
| X | AVantivirus | Avconsol.exe | Added by the MSNVB-D WORM! |