Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 24133 autoruns. Autorun 22601 to 22700:

StatusAutorun nameCommandDescription
XWindows-TCP-IPrfkampig.exeAdded by the GIPMA TROJAN!
XWindows-Xdatewuamclt32.exeAdded by the SPYBOT.AMUV WORM!
XWindows-XP-Service-Packxpspz.exeAdded by the SDBOT-AAC WORM!
XWindows_LowLevel_Security_Corelsass.exeAdded by the PADMIN-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Repair
XWindows_Protectwinsystem.exeAdded by a variant of the RBOT WORM!
XWindows_Protectwinregal.exeAdded by a variant of the RBOT WORM!
XWindows_Protectlsas.exeAdded by the RBOT.ARO WORM!
XWindows_Protectwincontrol32.exeAdded by the RBOT-ADK WORM!
XWindows_SerivceSERVICE.exeAdded by the WOOTBOT.AH WORM!
Xwindows_startup[random].exeAdded by the NURECH TROJAN!
Xwindows_startupjavawin.exeAdded by the NURECH TROJAN!
XWindows_Updatessvthost.exeAdded by a variant of the SPYBOT WORM!
XWindows_VXDuser32.exeAdded by the PPORT TROJAN!
Xwindows16windows16.exeAdded by the VB-XU TROJAN!
XWindows32rundll.exeAdded by the AGOBOT-LK or AGOBOT-ND WORMS! Note - this is NOT the Win9x/Me system file of the same name as described here
Xwindows32windows32.exeAdded by the VB-XU TROJAN!
XWindows32wuuaclt.exeAdded by the BRATLE.B WORM!
XWindows32win.exeAdded by the AGOBOT-KN WORM!
XWindows32system.exeUnknown malware
XWindows32 Configuration Loadermsrf32.exeAdded by the SDBOT-ABX WORM!
XWindows32 Messenger Servicemsmsgv.exeAdded by the RBOT.ANS WORM!
XWindows32 Net Databasemsnd32.exeAdded by the RBOT-AAL WORM!
XWindows32 Serivceswinser32.exeAdded by the SPYBOT.AAF WORM!
XWindows32KernelStartwks.exeAdded by the LAPURD TROJAN!
YWindows7FirewallControlWindows7FirewallControl.exeWindows 7 Firewall Control from Sphinx Software - "Protects your applications from undesirable network incoming and outgoing activity, controls applications internet access. Allows you to control personal information leakage via controlling application network traffic"
XWindowsACEbaracebarupdate.exeBarACE adware
XWindowsAgentWindowsAgent.exeAdded by the GOP.G WORM!
XWindowsAgentsysexhook.exeAdded by the GOP keyboard logger/TROJAN!
XWindowsAPI.DLLServer5.exeAdded by the "Fear and Hope" TROJAN!
XWindowsAudiosystemupd.exeAdded by the AGENT-TH WORM!
XWindowsBackupWINDOWSBACKUP.EXEAdded by the STANG WORM!
XWindowsBoolaimplg.exeAdded by the SDBOT-CNG WORM!
XWindowsCRCwscrc.exeAdded by the SDBOT-VU WORM!
XWindowsCriticalUpdatewindows_critical_update.exeAdded by the ASTEF or RESPAN WORMS!
XWindowsDs1.exeAdded by the MSNDIABLO.A WORM!
XWindowsDiskEvtsvcsvh32.exeAdded by the NANINF.D TROJAN!
XWindowsDiskLogcstsm.exeAdded by the STINX-C or STINX-D TROJANS!
XWindowsDriverControlwinmsnliv.exeAdded by the AGENT-PME TROJAN!
XWindowsExplorercsrss.exeMessenger Blocker rogue security software - not recommended. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System
XWindowsExplorersvchost.exeMessenger Blocker rogue security software - not recommended. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System
XWindowsFileSystemwinsfs32.exeAdded by the RBOT-FMQ WORM!
XWindowsFileSystemcidaemon32.exeAdded by the RBOT-FSP WORM!
XWindowsFirewalllsass.exeMessenger Blocker rogue security software - not recommended. Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System
XWindowsFirewallSvcwinsvcup.exeAdded by a variant of the SDBOT WORM!
XWINDOWSflashbrgsqldata1.exeAdded by a variant of the AGENT-IC TROJAN!
XWindowsFSwinfs.exeAdded by the AGOBOT-BO WORM!
XWindowsfwvssmf32.exeAdded by the SPIGOT BACKDOOR!
XWindowsfwwindowsfw.exeAdded by the AGOBOT-TA WORM!
XWindowsFYwp.exePart of a "Security IGuard" parasite infestation - also detected as DESKTOPHIJACK
XWindowsFYbsw.exeAdded by a variant of the DESKTOPHIJACK TROJAN! For removal see here
XWindowsFY[path to trojan]Added by the FAKEALE-E TROJAN!
XWindowsFZ[path to file]Added by the DESKTOPHIJACK VIRUS! Also see DESKTOPHIJACK.B TROJAN!
XWindowsFZA5281300.soVariant of the SmitFraud alias FAKEALE-C TROJAN!
XWindowsFZzloader3.exeVariant of the SmitFraud alias FAKEALE-C TROJAN!
XWindowsHiverpcc.exeAdded by the DLENA-A TROJAN!
XWindows�UpdatesUpdate.exeAdded by the RBOT.TRA BACKDOOR!
XWindowsInstaller[path to file]Added by the DEDLER-D TROJAN! The most common filenames seen are "csmss.exe" and "csmrs.exe", located in %System%
XWindowsIPRelaywinipsvc.exeAdded by the IRCBOT-AAA WORM!
XWindowsKa1.exeAdded by the MSNDIABLO.A WORM!
XWindowsKeyUpdatemaster.exeAdded by the JOSAM WORM!
XWindowsLiveMessengermsngrpmsn.exeAdded by the AGENT-RQF TROJAN!
XWindowsMGMWinmgm32.exeAdded by the SOBIG.A WORM and LALA.C TROJAN!
Xwindowsmpwindowsmp.exeAdded by the AUTORUN-DP WORM!
XWindowsNetsDllrundll32.exe WindowsNetsDll.dllAdded by the MDROP-DEK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "WindowsNetsDll.dll" file is located in %UserProfile%\Microsoft
XWindowsNT CWServicesCWServices.comDetected by Bitdefender as the AGENT.AGDK TROJAN! See here
XWindowsNT ServicesServices.comDetected by Bitdefender as the DELF.OFC TROJAN! See here
Xwindowspisconvertor.exeAdded by the GENOME.AKNH TROJAN!
XWindowsProtocolLoglsadst.exeAdded by the NANINF.C TROJAN!
XWindowsReg% update[random filename].exeAdded by the RBOT-HH WORM!
XWindowsRegistration[random filename]Added by the RBOT-NO WORM!
XWindowsRegKey Autoupdate[random filename]Added by a variant of the RBOT WORM!
XWindowsRegKey upd4te2d4te*********.exe [* = random char]Added by the RBOT.XQ WORM!
XWindowsRegKey updatewinupdate.exeAdded by the RBOT-QJ WORM!
XWindowsRegKey updatewindns.exeAdded by the RBOT.IE WORM!
XWindowsRegKey updatewinupdatexx.exeAdded by the RBOT.LW WORM!
XWindowsRegKey update[random filename]Added by the RBOT.QT WORM!
XWindowsRegKey updatesvchoosts.exeAdded by the RBOT.ADB WORM!
XWindowsRegKey updatesvchostc.exeAdded by the RBOT.IF WORM!
XWindowsRegKey updatewdnupdate.exeAdded by the SDBOT.QX WORM!
XWindowsRegKey updateWindowsup.exeAdded by the SDBOT.PU WORM!
XWindowsRegKey updateWINUPDATES.EXEAdded by the RBOT-MM WORM!
XWindowsRegKey updaterkbuouoxfl.exeAdded by the RBOT-OO WORM!
XWindowsRegKey updatewinsys.exeAdded by the RBOT-JY WORM!
XWindowsRegKey updatewinupdat32.exeAdded by the RBOT-AGW WORM!
XWindowsRegKey update XPwindexv1.exeAdded by the RBOT-ABM WORM!
XWindowsRegKey%$ updatemsi332.exeAdded by the RBOT-IX WORM!
XWindowsRegKey%updateethernet32m.exeAdded by the RBOT-EN WORM!
XWindowsRegKeys updatewinsysi.exeAdded by the SDBOT.WE WORM!
XWindowss Service Agentmssngear.exeAdded by the RBOT.KGU BACKDOOR!
XWindowsService[random name].dllAdded by the VUNDO-X TROJAN!
XWindowsServiceservice.exeAdded by the AUTORUN-VPC WORM!
XWindowsServicesservice.exeAdded by the FOLMESS WORM!
XWindowsServicesWinServices.exeAdded by the SDBOT.CCD BACKDOOR!
XWindowsServicesHservicedhs.exeAdded by the AGOBOT-JD WORM!
XWindowsServicesStartupsvchost.exeAdded by the ECUP WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%
XWindowsSetup[path to trojan]Added by the EZBOT TROJAN!
XWindowsSp2sp2.exeAdded by the POSSE WORM!
XWindowsSystem32asper.exeAdded by the AGENT-EFP TROJAN!
XWindowsSystem32svchosts.exeAdded by the AGENT-EDA TROJAN!
XWindowsSystem32[path to worm]Added by the SDBOT-DFG WORM!

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner