Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 24133 autoruns. Autorun 8101 to 8200:

StatusAutorun nameCommandDescription
XKernel Safe Modesmss.exeAdded by the 78CRACK-A TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XKernel Servicesservice32.exeAdded by the PRX-B TROJAN!
Xkernel system daemonACTIVAT0R.exeAdded by the RANDEX.AW WORM!
XKernel_checkwmiprvse.exeAdded by the SONEBOT-B WORM! Note - this is not the legitimate wmiprvse.exe process which is always located in the %System%\wbem folder and should not normally figure in Msconfig/Startup!
Xkernel12.exekernel12.exeAdded by an unidentified WORM or TROJAN!
Xkernel32kern32.exeAdded by the BADTRANS.A WORM!
XKernel32Kernel32.exeAdded by a number of VIRUSES, WORMS and TROJANS!
Xkernel32kernel.dliAdded by the NETDEVIL.B TROJAN!
XKernel32Kernel.dllAdded by the REDLOF.M VIRUS!
Xkernel32kernel32.dlIAdded by the NETDEVIL.15 TROJAN!
XKernel32krnl32.exeAdded by the EPON WORM!
XKernel32Kernel32.winAdded by the GAGGLE.D or GAGGLE.E WORMS!
XKernel32kernel32s.exeAdded by the BCKDR-CIC BACKDOOR!
Xkernel32kernel32.dll.vbsAdded by the WEKODE-A WORM!
XKernel32svchosts.exeAdded by an unidentified WORM or TROJAN!
XKernel32svchost.exeAdded by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\drivers
XKernel32_sysdampersysdamp.exeAdded by an unidentified WORM or TROJAN! See here
Xkernel32dllguardpc.exeAdded by the FORBOT-CU WORM!
Xkernel32sys.dllIEXPLORER.exeAdded by the RBOT-MK WORM!
Xkernel44.dlltaskkill /f /fi "PID ge 0" /im *Added by the VBS.LIDO WORM!
XKernelChecksys****.exe [* = digit]Added by an unidentified TROJAN!
XKernelCheckwinser.exeAdded by the TSPY_LMIR.SL TROJAN!
XKernelCheckwinbery.exeAdded by the LEGMIR-CG TROJAN!
XKernelConfigdestiny32.exeAdded by the AGOBOT.AMB WORM!
Nkernelfaultcheckdumprep 0 -kUsed in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
XKernelFaultCheckptool32.exeAdded by the LEGMIR-BN TROJAN!
XKernelFaultCheckmsime.exeAdded by the TINY-P TROJAN!
XKernelFaultChecktell32.exeAdded by the LEGMIR-BF TROJAN!
XKernelFaultCheckwinabc3.exeAdded by the NUBYS-A VIRUS!
XKernelFaultCheckwinbin.exeAdded by the DLOADR-AAX TROJAN!
XKernelFaultChksms.exeAdded by the DEADHAT WORM! Do not confuse with the valid "kernelfaultcheck" which runs "dumprep 0 -k"
XKernellsystems.exeAdded by the TARNO.C TROJAN!
XKernell32Kernell.dllAdded by the DESTINY.A TROJAN!
XKernellAppscsrss.exeAdded by the BANCBAN-AC TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "System" subfolder
XKernellAppslexplore.exeAdded by the BANCBAN-BS TROJAN! Note - the executable is spelt with a lower case "L" rather than an lower or upper case "i" which is the case with Internet Explorer
XKernellAppssvshosti.exeAdded by the BANCBAN-V TROJAN!
XKernellApps32smss.exeAdded by the BANCBAN-AN TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!
XKernelRuntime[path to worm]Added by the MYTOB-JO WORM!
XKernelwKernelw32.exeAdded by the INDOR.E WORM!
Xkeysysxp.exeAdded by the BEAGLE.AB WORM!
Xkeysys_xp.exeAdded by the BEAGLE.AC WORM!
Xkeywinxp.exeAdded by the BEAGLE.AG WORM!
XKey Loggercsrss.exeAdded by the BUCHON.A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root folder (ie, C:\)
NKey TextKeyText.exeKey Text 2000 from MJMSoft Design - utility to automate repetitive keyboard tasks. Available via Start -> Programs
XKey1Rlid.exeAdded by the LIXY TROJAN!
?Key2serve.exe??
Xkey2winlog.exeAdded by the BAGLEDI-AL TROJAN!
YKeyAccesskeyacc32.exeKeyServer KeyAccess client software - "when the KeyServer program is launched, the KeyServer process becomes active so license requests from client computers can be serviced. Without KeyAccess, a keyed program cannot run, so license control is very secure"
XKeybdcntlkeybdcntl.exeAdded by a variant of the CRYPTER.C TROJAN!
?KeybdUtilityHotKey.exeLocated in a LG Software\LG OSD directory. Related to function keys on and LG Electronics system?
UKeyBoardKeyboard.exeLabtec keyboard utility
Xkeyboardkeyboard*.exe [* = number]Detected by Kaspersky as the VB.ZG TROJAN!
Xkeyboard[spyware filename]DollarRevenue spyware. The file is located in %Root% (i.e. C:\ D:\, etc)
Xkeyboard[path to trojan]Added by the DLOADR-AOZ TROJAN!
XKeyboardlsass.exeAdded by the AGENT.US WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %CommonAppData%\Fearghus
NKeyboard CustomizerTpKmapAp.exePart of the Keyboard Customizer Utility for IBM/Lenovo Thinkpad notebooks. This is the main user interface for the utility but it doesn't normally seem to be running if enabled at startup. Also, it doesn't appear to need to be running for custom key combinations to work (via TpKmapMn.exe)
UKeyboard LauchpadKeys.exeKeyboard Launchpad from Stardock Corporation - "can create keyboard short-cuts for your programs, saved clipboards, URLs, system commands, and more." Required if you want to use the custom keyboard shortcuts. Also part of the Object Desktop suite
UKeyboard LoggerLogger.exeKeyboard Logger keystroke logger/monitoring program - remove unless you installed it yourself!
UKeyboard ManagerMMKeybd.exeMultimedia keyboard manager. Required if you use the additional keys
YKeyboard Preload CheckPreload.exeMillenium Multi-Function Keyboard driver
?Keyboard StatusKeyStat.exeMultimedia keyboard manager for Medion desktop and notebook PCs? Located in %ProgramFiles%\Medion\KeyStat
Xkeyboard_enumkeyboard_enum.exeAdded by the BDOOR-GP BACKDOOR!
Ukeyhookkeyhook.exeHotkey manager for Silicon Integrated Systems (SiS) based graphics chipsets - disable unless you use hotkeys
UKeyLoggersyssafe.exeGhostLog surveillance software. Uninstall this software unless you put it there yourself
UKeyMaestrokmaestro.exeMultimedia keyboard manager. Required if you use the multimedia keys
Ukeymapkeymap.exeSystem Tray utility and background task used by games produced by Kesmai (published by Interactive Magic) and which enables you to program keys to do specific actions during the game
Xkeymgrldrrundll32 setupapi, InstallHinfSection... keymgr3.infCoolWebSearch Oemsyspnp parasite variant
YKeyPatrolKeyPatrol.exeKeyPatrol - keylogger detector using both behavioral and pattern-matching algorithms. Part of the original anti-malware program by PestPatrol, Inc. Acquired by CA where it became eTrust PestPatrol Anti-Spyware and then CA Anti-Spyware - which is now included in CA AntiVirus Plus
Ukeyplusplusstartk.exeKey++ Invisible Spy Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!
YKeyScramblerkeyscrambler.exeKeyScrambler from QFX Software Corporation - "encrypts your keystrokes deep in the kernel, foiling keylogging attacks with scrambled, undecipherable data"
Xkeyservkeyserv.exeKeyThief spyware
UKeyspan Digital Media RemoteKDMRdmn.exeRemote control driver for Keyspan Digital Media Remote devices
Ukeystrokekeystroke.exeQuickLaunch surveillance software. Uninstall this software unless you put it there yourself
UKeyWalletKWallet.exe"KeyWallet is a useful and convenient desktop utility that spares you the trouble of filling in your logins, passwords and other personal data manually"
XKeywordSearchUpdaterKeywordSearchUpdater.exeKeyword Search adware
XKf3pn4myclient.exeAdded by the VBINJ-S TROJAN!
Xkfienqmasbl.batAdded by the KIFER TROJAN!
Xkgjdi27kgjdie27.exeAdded by the SDBOT.AP BACKDOOR!
XKgjgrnnypbw.exeAdded by the QuickLinks/Forethought adware
UKHALMNPRKHALMNPR.EXEPart of Logitech's SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice, trackballs, etc). When using SetPoint to adjust the mouse sensitivity it is maintained separately from the Windows setting, but is combined with the Windows setting to determine the final sensitivity. For this reason, this entry sets the Windows setting to 0 so it doesn't affect the one you set in SetPoint and then unloads. A separate instance of KHALMNPR.EXE loads via the main Setpoint.exe program to control communication between your radio/bluetooth wireless mouse/keyboard and SetPoint
XKHATARNAK LoaderKHATARNAK.exeAdded by the AUTORUN.ACO WORM!
Nkhookerkhooker.exeSiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required
XKiamat Sudah Dekat_16_04ISASS.exeAdded by the PAHATIA.B WORM!
UKICKMON.EXEKICKMON.EXEKeepItClean - utility that deletes safe to remove files, cookies, browsing history, etc. This is the scheduler - if you don't schedule clean-ups it isn't required
UKiesKiesHelper.exeInstalled with the SAMSUNG Kies mobile device management software. Preloads part of Kies into memory to speed up the loading time of the main program and exits after running. Tested without a supported device on a system with more than 1GB of memory it took twice as long for Kies to start with this entry disabled
NKies TrayAgentKiesTrayAgent.exeSAMSUNG Kies mobile device management software which also allows you to view apps in full screen on your PC, no matter what network you're on. Allows you (amongst other options) to backup your devices contents to your PC, use it to connect to the internet, transfer files and synchronize contacts, etc. Only required if you want to autostart Kies when your device is connected
UKiesHelperKiesHelper.exeInstalled with the SAMSUNG Kies mobile device management software. Preloads part of Kies into memory to speed up the loading time of the main program and exits after running. Tested without a supported device on a system with more than 1GB of memory it took twice as long for Kies to start with this entry disabled
NKiesTrayAgentKiesTrayAgent.exeSAMSUNG Kies mobile device management software which also allows you to view apps in full screen on your PC, no matter what network you're on. Allows you (amongst other options) to backup your devices contents to your PC, use it to connect to the internet, transfer files and synchronize contacts, etc. Only required if you want to autostart Kies when your device is connected
UKill PopupKillPopup.exeKillPopup - pop-up stopper
XKillAndCleanKillAndClean.exeKillAndClean rogue spyware remover - not recommended, removal instructions here
Xkimochiz.exekimochiz.exeAdded by the MDROP-BB TROJAN!
NKinberlinkKinberlink.exeKinberlink network messaging. Available via Start -> Programs
XKing_ararking.exeAdded by the PWS-BOS TROJAN!
Xking_hghgking.exeAdded by the AUTORUN-BMQ WORM!
Xking_jpjpking.exeAdded by the AGENT-POO TROJAN!
XKing_kokoking.exeAdded by the AUTORUN-BMU WORM!
Xking_mgmgking.exeAdded by the AGENT-PGG TROJAN!
XKinofilmoff.NetReklamer.exeAdded by the AGENT-NGX TROJAN!
Ykisavp.exeSystem Tray access to and notifications for Kaspersky Internet Security 6.0 from Kaspersky Lab. Runs together with a related service - AVP - which runs a separate instance of the same file. Also Steganos Internet Security 2007 - by Kaspersky and now discontinued. Found in either a Kaspersky or Steganos sub-directory
Xkisspingy.exeAdded by a variant of the IRCBOT BACKDOOR! The file is located in a random subfolder of %ProgramFiles%

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner