Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 24133 autoruns. Autorun 22901 to 23000:

StatusAutorun nameCommandDescription
Xwinlogwindowxs.exeAdded by the SDBOT-KT BACKDOOR!
Xwinlogwinsx.exeAdded by the SDBOT-MH BACKDOOR!
Xwinlog managerwinlog.exeAdded by the DONBOMB.A TROJAN!
Xwinlog.exewinlog.exeAdded by the BCKDR-RBJ TROJAN!
XWINLOG0NWINLOG0N.EXEAdded by the MYDOOM.BI WORM!
XWinLoginwinlogin.exeAdded by the AGOBOT-IX WORM!
Xwinloginwin32x.exeAdded by the STARTPA-DF TROJAN!
XwinloginReadMe.exeAdded by the SILLYFDC.BBT WORM!
XWinlogin.exelog.exeAdded by a variant of the AGENT.AH TROJAN!
Xwinlogin.exelogfile.exeAdded by the AGENT.AH TROJAN!
Xwinlogin.exemspaint.exeAdded by a variant of the AGENT.AH TROJAN!
XWinlogin.exesteam.exeAdded by a variant of the AGENT.AH TROJAN!
Xwinlogins.exewinlogins.exeAdded by the OPTIX.H BACKDOOR!
Xwinlogoffwinlogoff.exeAdded by the AGOBOT-TR WORM!
Xwinlogonwinlogin.exeAdded by the RANDEX.E WORM!
Xwinlogonwinlogon.exeAdded by the TRODAL TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
Xwinlogonmsreg32.exeAdded by the SDBOT.EO BACKDOOR!
Xwinlogonwinlogon32.exeAdded by the MASLAN.C WORM!
Xwinlogonwpwlogon.exeAdded by an unidentified WORM or TROJAN!
XWINLOGONwscript.exe WINLOGON.vbsAdded by the YSPAN.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "WINLOGON.vbs" file is found in %System%
XWinlogonLsass.exeAdded by the ALCOP-B WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
Xwinlogonnvchost.exeAdded by an unidentified WORM or TROJAN!
XWinlogonWINLOGON.EXEAdded by the PUNYA-B WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Documents and Settings\Administrator\Local Settings\Application Data\WINDOWS
Xwinlogonsystem.exeAdded by a variant of the DELF.CNS TROJAN!
Xwinlogoncleanmg.exeAdded by the AGENT-ICR TROJAN!
XWinlogonscssrr.exeAdded by the AGENT-LXB TROJAN!
Xwinlogonircbsbot.exeAdded by the AGENT-RGJ TROJAN!
Xwinlogon serviceurx.exeAdded by the SPYBOT.EN WORM!
XWinlogon ShellExplorer.exe svchost.exeAdded by the KIPIS.M WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "1032" sub-folder
XWinlogon.exeN/ACoolWebSearch parasite variant - resets home page to an adult content site
Xwinlogon.exehelper.exeAdded by the FAKESPY-A TROJAN!
Xwinlogon.exemsole32.exeAdware, also detected as the FAKESPY-B TROJAN!
Xwinlogon_userccIsass.exeAdded by the SILLYFDC.BBT WORM!
Xwinlogon32_[path to file]Added by the RULAND.A WORM!
XWinLogonndwinlogonnd.exeAdded by the AGENT-NNQ TROJAN!
XWinlogunwinlogin.exeAdded by the P2LOAD-C WORM!
XWinLsassservicec.exeAdded by the SCANE WORM!
XWinLsass[path to trojan]Added by the SCANE WORM!
Xwinltmpvwinln.exeAdded by the TCXMEDI-C TROJAN!
Xwinltmpvwutop.exeAdded by the TCXMEDI-C TROJAN!
XWinmainwinmain.exeOne of the first of a new breed of malware. When run it immediately loads MSHTA.EXE from the Windows folder, placing it on "hot standby", ready to accept HTA scripting within a web page and then EXECUTE what is embedded IN the page as a program! In other words, it's possible for a "rogue" website to actually embed trojans, worms and/or viruses directly into a web page. NSClean's HTA Stop offers an easy way to toggle this capabiltity, or rather vulnerability, on and off. I suggest you leave it disabled!
XWinManagewmanage.exeAdded by a variant of the IRCBOT BACKDOOR! See here
?WinManagerschost.exe??
Uwinmatrix.exeWinMatrixXP.exeWinMatrix XP - wallpaper replacement that shows different matrix effects (including flowing matrix codes from 'The Matrix' movie) on your desktop
XWinMedwinmed.exeAdded by the AGENT.AIRF TROJAN!
XWinMedia[path to trojan]Added by the ZEROBE-A TROJAN!
XWinMediamsupd******.exe [*= random digit]Added by the INJECT.163 TROJAN!
XWinMedia32winmedia32.exeAdded by the YABE.F TROJAN!
UWinMemWinMem.exeWinMem Cleaner - part of Ultra WinCleaner Utility Suite. Makes more memory available for your programs and the Operating System. It also defragments your system
XWinMenssagewinmax.exeAdded by the BANCOS.B TROJAN!
XWinMenssagewinmaxy.exeAdded by the BANCOS TROJAN!
XWinMessengersyshost.exeAdded by the OPANKI-E WORM!
NWinMgmtWinMgmt.exeUsed for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here
Xwinmgmtwmiprvse.exeAdded by the AGENT-GHP TROJAN!
Xwinmgmt32.exewinmgmt32.exeAdded by the LUZIA.AD TROJAN!
XWINMGRtaskgmgr.exeAdded by the MYTOB.AN WORM!
XWinMgrwinmgr32.exeAdded by the VB-EDY TROJAN!
XWinmgr.exescvhost.exeAdded by the AGOBOT.AFG WORM!
XWinMgr32winmgr32.exeAdded by the MIMAIL.P WORM!
XWinMineD4NG3.vbsAdded by the BISCUIT.A WORM!
XWinMngndllhost.exeAdded by the SIVION-A TROJAN! Note - this is not the legitimate dllhost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\system
Xwinmngr.exe[path to trojan]Added by the AGENT-ZB TROJAN!
Ywinmodemwmexe.exeSoftware for software based modems. Required if you have one of these. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information
XWinmon32winmon32.exeAdded by the RBOT-OQ WORM!
XWinMoviePlugInWinMoviePlugIn.exeSfonditalia adult content premium rate dialer
XWinmsgwinwork.exeAdded by the GAOBOT.GEN!POLY WORM!
XWinMsgwinmsgr.exeAdded by the DLOADR-AS TROJAN!
XWinmsgwinwork8.exeAdded by the AGOBOT-GC WORM!
XWinMsrv32WinMsrv32.exeAdded by the GAOBOT.AFJ WORM!
NWinMXWinMX.exeWinMX file sharing application
Nwinmysqladminwinmysqladmin.exeStarts the MySQL database admin tool
NWinMySQLadmin Toolwinmysqladmin.exeStarts the MySQL database admin tool
Xwinnetwinnet.exeCommonName Toolbar spyware. To uninstall see here
XWinNetDDE[random characters].exeAdded by the NETDEPIX.B TROJAN!
XWinNiteniteaim.exeAdded by the OPANKI.B WORM!
Xwinnloadwinnload.COMAdded by the DOWNLD-ABG TROJAN!
?Winnov MenuWnvMenu.ExeWinnov Video Capture Card related. What does it do and is it required?
?Winnov RemoteWnvRsvr.ExeWinnov Video Capture Card related. What does it do and is it required?
?Winnov StatusWvStatus.ExeWinnov Video Capture Card related. What does it do and is it required?
Xwinnsvcmsvc.exeAdded by the PWS.O TROJAN!
Xwinntwinnt.exeAdded by the MONA-E WORM!
XWinNTWinNT.comAdded by the AUTOSKY WORM!
Xwinnt DNS identpidchk32.exeAdded by the RBOT-ACY WORM!
Xwinnt DNS identwindowxp.exeAdded by a variant of the RBOT WORM!
Xwinnt DNS identWinupd32.exeAdded by the RBOT.AVU WORM!
Xwinnt DNS identwinupdate32.exeAdded by a variant of the RBOT WORM!
Xwinnt DNS identwuamgrd33.exeAdded by a variant of the RBOT WORM!
XWinnt DNS identwindowsp.exeAdded by the RBOT.BAL WORM!
XWinnt DNS identmsnmsrg.exeAdded by the RBOT.BVQ WORM!
Xwinnt DNS identwuamgrd32.exeAdded by the RBOT-BAU WORM!
Xwinnt DNS identiexplorer.exeAdded by a variant of the RBOT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)
XwinNT updatcwupgrd.exeAdded by a variant of the RBOT WORM!
Xwinnt2winnt2.exeAdded by the AGENT.CJZO TROJAN and variants
Xwinnt3winnt3.exeAdded by the AGENT.CJZO TROJAN and variants
Xwinnt4winnt4.exeAdded by the AGENT.CJZO TROJAN and variants
Xwinnt5winnt5.exeAdded by the AGENT.CJZO TROJAN and variants
Xwinnt6winnt6.exeAdded by the AGENT.CJZO TROJAN and variants
XWinNtBBWinntBB.exeAdded by the DULOAD.C WORM!
XwinntR1winntR1.exeAdded by the AGENT.CJZO TROJAN and variants
XwinntR2winntR2.exeAdded by the AGENT.CJZO TROJAN and variants

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner