Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 24133 autoruns. Autorun 201 to 300:

StatusAutorun nameCommandDescription
X[empty]dllvirtual.exeAdded by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field
X[empty]dllvirtual.dllAdded by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field
X[empty]dllvirtual.jsAdded by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field
X[empty]ne.exeAdded by the IRCBOT-ZL TROJAN! Note - has a blank entry under the Startup Item/Name field
X[empty]iexpl0re.exeAdded by the RBOT-SD WORM! Note - has a blank entry under the Startup Item/Name field
X[Entry name]System.exeAdded by the NETHIEF-N TROJAN!
X[Ephemeral 2.4] by TreeHugger,[path to worm]Added by the LEMOOR-A WORM!
X[Ephemeral 2.5] by TreeHugger,[path to worm]Added by the LEMOOR-C WORM!
X[Ephemeral 2.x] by TreeHugger,[path to worm]Added by the LEMOOR.A WORM! where "x" represents 3 or 4
X[executed file name]App.exeAdded by the WAXPOW WORM!
X[executed file name]Regsrv32.comAdded by the SOUTHGHOST WORM!
X[filename]svchost.scrAdded by the BANKER-CC TROJAN!
X[number of current month][number of current month].exe hlmrunAdded by the AUTORUN-UN WORM!
X[number of current year][number of current year].exe hcurunAdded by the AUTORUN-UN WORM!
X[original filename]svchost.scrAdded by the BANCBAN-CX TROJAN!
X[original filename]xphost.scrAdded by the BANCBAN-HM TROJAN!
X[random characters]rsbmsc.exeDetected by AntiVir antivirus as the BDS/Agent.adt TROJAN!
X[random characters]_default[random].pifAdded by the BRONTOK-AI WORM and variants!
X[random characters]j[random].exeAdded by the BRONTOK-AI WORM and variants!
X[random characters]sv[random].exeAdded by the BRONTOK-AI WORM and variants!
X[random characters]yesbron.comAdded by the BRONTOK-AI WORM and variants!
X[random characters]systs.exeAdded by the AGENT-GDC TROJAN!
X[random characters]xvassdf.exeAdded by the AUTORUN-BAD WORM!
X[random characters]securewinload32x.exeAdded by the OPTIXP-N TROJAN!
X[random filename]slk8x2peu.exeQuickLinks adware
X[random hex digits]report.exeAdded by the TATANARG TROJAN!
X[random name]ver.exeAdded by the VERTEXBOT BACKDOOR!
X[random name]Sys32Disp.exe.exeAdded by the SKOPVEL.A WORM! The most common name seen appears to be "System Display"
X[random name]wincpu.exeAdded by an unidentified VIRUS, WORM or TROJAN!
X[random name]m?dtc.exePurityScan adware
X[random name]ping.exePurityScan adware. Note - do not confuse with the Microsoft utility of the same name as described here
X[random name]CXTPLS_LOADER.EXEAproposMedia adware
X[random name]??plorer.exePurityScan adware
X[random name]?hkdsk.exePurityScan adware
X[random name]?hkntfs.exePurityScan adware
X[random name]l?gonui.exePurityScan adware
X[random name]m?iexec.exePurityScan adware
X[random name]r?gsvr32.exePurityScan adware
X[random name]t?skmgr.exePurityScan adware
X[random name]w?auboot.exePurityScan adware
X[random name]w?auclt.exePurityScan adware
X[random name]w?crtupd.exePurityScan adware
X[random name]w?wexec.exePurityScan adware
X[random name]??erinit.exePurityScan adware
X[random name]d?dplay.exePurityScan adware
X[random name]n?tepad.exePurityScan adware
X[random name]??chost.exePurityScan adware
X[random name]??oolsv.exePurityScan adware
X[random name]??xplore.exePurityScan adware
X[random name]r?ndll32.exePurityScan adware
X[random name]se?vices.exePurityScan adware
X[random name]w?nlogon.exePurityScan adware
X[random name]w?nword.exePurityScan adware
X[random name]??anregw.exePurityScan adware
X[random name]?ttrib.exePurityScan adware
X[random name]j?vaw.exePurityScan adware
X[random name]l?ass.exePurityScan adware
X[random name]m?config.exePurityScan adware
X[random name]n?lookup.exePurityScan adware
X[random name]n?pdb.exePurityScan adware
X[random name]??ool32.exePurityScan adware
X[random name]??rss.exePurityScan adware
X[random name]??rvices.exePurityScan adware
X[random name]?ti2evxx.exePurityScan adware
X[random name]d?xplore.exePurityScan adware
X[random name]chkdsk.exePurityScan adware. Note - the legitimate Windows chkdsk.exe will always be located in %System% and will NOT figure among the startups!
X[random name]dvdplay.exePurityScan adware
X[random name]spoolsv.exePurityScan adware. Note - this is not the legitimate spoolsv.exe which is always located in %System%
X[random name]w?aclt.exePurityScan adware
X[random name]wucrtupd.exePurityScan adware. Do not confuse with the legitimate Windows Critical Update Notification (wucrtupd.exe) process
X[random name]charmapnt.exeAdded by the BANCOS-DR TROJAN!
X[random name]n?tdde.exePurityScan adware
X[random name]r?gedit.exePurityScan adware
X[random name]r?ndll.exePurityScan adware
X[random name]scanregw.exePurityScan adware. Note - do not confuse this with the legitimate Windows process scanregw.exe which is always found in the Windows folder on Win9x/ME machines
X[random name]wuauboot.exePurityScan adware. Note - do not confuse with the legitimate wuauboot.exe process which should not figure in Msconfig/Startup!
X[random name]w?nspool.exePurityScan adware
X[random name]svchost.exeAdded by the BANCBAN-JC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\config
X[random name][random name].dllSearchNet adware
X[random name]iexpl0ra.exeAdded by the ULPM.BD TROJAN!
X[random name]rundl13a.exeAdded by the GAMPASS-L TROJAN!
X[random name]Servere.exeAdded by the LEGMIR-AQM TROJAN!
X[random name]explore3.exeAdded by the DELF.FAN TROJAN!
X[random name]taskmngr.exeAdded by the AGOBOT-CB WORM!
X[random name]netdde.exePurityScan adware. Do not confuse with the legitimate Network DDE - DDE Communication (netdde.exe) process which is always located in %System% and should not figure in Msconfig/Startup!
X[random name]chkntfs.exePurityScan adware. Do not confuse with the legitimate NTFS Volume Maitenance Utility (chkntfs.exe) process which is always located in %System% and should not figure in Msconfig/Startup!
X[random name]notepad.exePurityScan adware. Note - this is not Windows Notepad which has the same executable name
X[random name]services.exePurityScan adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!
X[random name]ntvdm.exePurityScan adware. Do not confuse with the legitimate ntvdm.exe process which is always located in %System% and should not figure in Msconfig/Startup!
X[random name]msiexec.exePurityScan adware. Do not confuse with the legitimate Windows® Installer (msiexec.exe) process which is always located in %System% and should not figure in Msconfig/Startup!
X[random name]userinit.exePurityScan adware. Do not confuse with the legitimate Userinit Logon Application (userinit.exe) process which is always located in %System% and should not figure in Msconfig/Startup!
X[random name]regedit.exePurityScan adware. Note - this is not the valid Windows registry editor which resides in %Windir% and will not figure in Msconfig/Startup!
X[random name]wuauclt.exePurityScan adware. Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup!
X[random name]?ervices.exePurityScan adware
X[random name]s?chost.exePurityScan adware
X[random name]c?rss.exePurityScan adware
X[random name]mrgdll.exeNortel Antivirus rogue security software - not recommended
X[random name]wox.exeNortel Antivirus rogue security software - not recommended
X[random name]dropped.exeAdded by the VERTEXBOT BACKDOOR!
X[random names]eee2.exeMediaMotor adware

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner