Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 24133 autoruns. Autorun 701 to 800:

StatusAutorun nameCommandDescription
U3Deep Control Panel3DeepCTL.EXE3Deep® from E-Color corrects lighting, shading and color for all your 2D and 3D games. Now superseded by 3DxWizzard™
X3Dfx AccGFXACC.EXEAdded by the GIBE WORM!
N3dfx Task Manager3dfxMan.exeSystem Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs
Y3dfx Toolsrundll32.exe 3dfxCmn.dll,CMNUpdateOnBootUpdates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards
Y3dfxv2ps.dll3dfxv2ps.dllUpdates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards
?3Dlabs Taskbar Display Manager3DLman.exe3DLabs graphics driver related. System Tray access to display settings?
U3DLabsHelperDemon3dldemon.exeDirectly from the programs author "It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore), so it should take zero CPU time and virtually zero memory, since it will all be paged out to the hard drive." In most cases it can be safely disabled
Y3DMouse.EXE3DMouse.EXEDritek System Inc. 3DMouse driver. A 3D Mouse works in all 3-dimensions instead of the usual 2, similar to the Ninteno Wii Remote - see here
X3P_UDEC_IAIAInstall.exeInstaller for the Internet Antivirus and Internet Antivirus Pro rogue security software - not recommended, removal instructions here
U3qdctl.exe3qdctl.exeProvided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup, restoring volume and other audio settings to a pre-determined default. Similar to Creative Lab's AudioHQ
Y3ware 3DM3dm.exeMonitors status of the disk array on 3ware IDE RAID controllers
X4-gusdurgusdur.exeAdded by the BRONTOK-CR WORM!
X456655explorer.exeAdded by the BIFROSE-DE TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
X4684735485910netdll32.exeAdded by the SDBOT-DEV WORM!
U49ersScreenServer49ersScreenServer.exeScreensaver for the San Francisco 49'ers NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supported
U49ersScreenServerSvc49ersScreenServer.exeScreensaver for the San Francisco 49'ers NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supported
X49U5T1N449U5T1N4.exeAdded by the KORRON.B WORM!
X4da92ad5.exe4da92ad5.exeAdded by the DLOADR-WZ TROJAN!
X4k51k44k51k4.exeAdded by the BRONTOK-BH WORM!
U4oDKHost.exeVerisign Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops
X4wd!!!Natal!.pifAdded by the OPASERV.AI WORM!
U4x26 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung SCX4x26 multifunction laser printers
U4x28 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung SCX4x28 multifunction laser printers
X5-1-61-96members-area.exeAdult content dialler
X5-2-46-1125-2-46-112.exeAdult content pop-up dialler. Removal instructions here
X5-megawatimegawati.exeAdded by the BRONTOK-CR WORM!
X55278grepclient1.exeAdded by the LINEAGE-S TROJAN!
X56a10a26-dc02-40f3-a4da-8fa92d06b357_33rundll32.exe 56a10a26-dc02-40f3-a4da-8fa92d06b357_33.aviSecurity Defender rogue security software - not recommended, removal instructions here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "56a10a26-dc02-40f3-a4da-8fa92d06b357_33.avi" file is located in %CommonAppData%
X5p4m[path to trojan]Added by the LITEBOT-C TROJAN!
X5whgue215whgue21.exeClearSearch adware
X6-susilo bsby.exeAdded by the BRONTOK-CR WORM!
X60xu9qtfcyyp.exeAdded by the VIRUT.CE VIRUS!
U6200 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung CLX6200 multifunction laser printer
X65438761234587528rkgnd.exeANG AntiVirus 09 rogue security software - not recommended, removal instructions here
X66253663426625366342.exeAdded by the AGENT-OSO TROJAN!
X666Ska.exeAdded by the PIPES TROJAN!
X678lsas32.exeAdded by the SLSORVE-B TROJAN!
X6GMQKO1OIZ4OY2X2NCRZX.exeAdded by the DWNLDR-JCP TROJAN!
X756349DC-6D9E-4F2A-9B24-269661F073C3sysoghcx.exeAdded by the FAKEALERT-AH TROJAN!
X76112549345328287angpd.exeANG AntiVirus 09 rogue security software - not recommended, removal instructions here
X7f8ez****.exe 9idfDetected by Eset's NOD32 antivirus as the SMALL.ALI TROJAN! Note - it creates a number of extra z****.dll files in the %System% folder
X7u5607u560.exeAdded by the SCAR.ACIT TROJAN!
X7X29C2X78Ysyss_.exeAdded by the AGENT-GMS TROJAN!
U80's ArcadeArcade.exe80's Arcade widget included with the DesktopX desktop utility from Stardock Corporation. Allows you to play classic 1980's arcade games such as Pacman and Space Invaders on the desktop. Once started, Arcade.exe loads a file called "DXWidget.exe" and exits
U802.11b+g USB Wireless LAN UtilityZDWlan.exeWireless LAN configuration utility for ZyDAS (now acquired by Atheros) based chipsets
U802.11g MIMO Wireless UtilityRaUI.exeWireless configuration utility for Railink 802.11g MIMO based products
U802.11g Wireless AdatperMonitor.exeRelated to wireless card (802.11) adapter/standard. System Tray icon that provides a shortcut to "Wireless Connection Status" and allows to turn WL on and off. Supplier unknown. Adapter is miss-spelled
X80280735708028073570.exeAdded by the AGENT-OQY TROJAN!
X8254502482545024.exeAdded by the AGENT-MBV TROJAN!
X852EBF20-A95D-4F1F-B9C2-B2CD24350F3Esysodkcs.exeAdded by the FAKEALERT-AH TROJAN!
X8jg53l4ojo74khk.exe8jg53l4ojo74khk.exeAdded by the AUTOIT.AAK TROJAN!
X9130231891302318.exeSecurityTool rogue security software - not recommended
X98D0CE0C16B1rundll32.exe D0CE0C16B1,D0CE0C16B1BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
X9mwinlog0n.exeAdded by the LEGMIR-AQK TROJAN!
X9UmxQPSiTJMbANVUKZ.exeAdded by the AGENT-LMN TROJAN!
Y9xadiras9xadiras.exeAllied Telesyn AT series router/modem related - apparently required
X9xHtProtectAVprotect9x.exeAdded by the NETSKY.M WORM!
Xaa.exeCommercials file that registers itself in the system registry and redirects IE to a certain commercial website
Xajesse.exeAdded by the MELO-A WORM!
XaMsSvrdll.vbsAdded by the MUTAFROG!INF WORM!
XA New Windows Updaterw32NTupdt.exeAdded by the MYTOB.BM WORM!
NA NoteA Note.exe"A Note is a program that lets you create post-it like notes on your Microsoft Windows desktop"
UA Verizon AppVERIZO~1.EXEPart of Verizon Online Support Manager
Ya-squareda2guard.exeSystem Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides "comprehensive PC protection against viruses, trojans, spyware, adware, worms, bots, keyloggers and rootkits". Previously known as "a-squared Antitrojan" and "a-squared Anti-Malware"
Ya-squareda2adguard.exeSystem Tray access to and Background Guard feature of Emsisoft Anti-Dialer from Emsi Software GmbH - which "provides a complete defense against Dialers"
Ya-squared Anti-Dialera2adguard.exeSystem Tray access to and Background Guard feature of Emsisoft Anti-Dialer from Emsi Software GmbH - which "provides a complete defense against Dialers"
Ya-winpoet-servicewinpppoverethernet.exeWinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking
XA_M_P_NETAntiMalwarePro.exeAntiMalware Pro rogue security software - not recommended, removal instructions here
?a_vpdvpd.exeLocated in an IBMTOOLS\VPD sub-directory. What does it do and is it required?
Ya2guard.exeSystem Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides "comprehensive PC protection against viruses, trojans, spyware, adware, worms, bots, keyloggers and rootkits". Previously known as "a-squared Antitrojan" and "a-squared Anti-Malware"
UA1000 Settings Utilitycpqa1000.exeCompaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan, print, copy and fax. Only required if you use these features
Ya2adguarda2adguard.exeSystem Tray access to and Background Guard feature of Emsisoft Anti-Dialer from Emsi Software GmbH - which "provides a complete defense against Dialers"
?a2dservicea2dservice.exeRelated to the Air2Data Wireless HISA (High-Speed Internet Access) service. What does it do and is it required?
Ya2guarda2guard.exeSystem Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides "comprehensive PC protection against viruses, trojans, spyware, adware, worms, bots, keyloggers and rootkits". Previously known as "a-squared Antitrojan" and "a-squared Anti-Malware"
UA4ProxyA4Proxy.exeAnonymity 4 Proxy - local proxy server that makes you anonymous when visiting web sites
XA5118r_default32142.pifAdded by the BRONTOK-AK WORM and variants!
XA5118rj6321422.exeAdded by the BRONTOK-AK WORM and variants!
XA70F6A1D-0195-42a2-934C-D8AC0F7C08EBrundll32.exe E6F1873B.DLL, D9EBC318CBrowserAid adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "E6F1873B.DLL" file is located in %System%
Xa9z1eizA1eatulabov.exeAdded by the AGENT-GWD TROJAN!
Xaa bbcc dde effgghh jjupdate.exeAdded by a variant of the IRCBOT BACKDOOR!
Xaaaaaa.exeAdded by the POISON.PG BACKDOOR!
?AAACLEANAAACLEAN.INF??
?AAAKeyboardrundll.exe setupx.dll,InstallHinfSection KBDCLEAN.INF??
UaaAPMClientamclient.EXELANDesk® Management Suite software component
NAAATraySaverTraySaver.exeSystem Tray management utility from Mike Lin which allows you to hide, show, restore icons that are lost in an Explorer crash, remove dead tray icons, minimize any window to the System Tray
Xaacmeyfaacmeyf.exeAdded by the AF.20 TROJAN!
XAaepopar.exePurityScan/Clickspring adware
UAAKaak.exeAdvanced Anti-Keylogger - "Anti-spy software to prohibit operation of any keyloggers currently in use or presently being developed anywhere"
UaaLDISCN32LDISCN32.EXELANDesk® Management Suite software component
UaaLDSoftMonSoftMon.EXELANDesk® Management Suite software component
UaaLDTaskCompletionamclient.EXELANDesk® Management Suite software component
XAAMSFree702Avengine.comAdded by the DELF.LJ TROJAN!
XAAMSFree702sys.exeAdded by the BACKDOOR-CPC TROJAN!
XAaouamee.exePurityScan adware
XAAPatchstart.batAdded by the XBLOCKER.BCT TROJAN!
XAappadprotAdBlaster adware
Xaaprotect[path to trojan]Added by the BANCBAN-MJ TROJAN!
XAASSKK2LSASS.EXEAdded by the SILLYFDC.BDB WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%
?aauclientACNUpdater.exeAppears to be related to software from Accenture.com
UAAWAd-Aware.exeOld versions of the Lavasoft Ad-Aware anti-malware tool

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner