Autorun List

Keys:

Y Normally harmless autorun.
N Not required, but may be started.
U User's choice. Start if necessary.
X Definitely not required. Usually Malware.
? Unknown

Filter:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Show all

Found 24133 autoruns. Autorun 8501 to 8600:

StatusAutorun nameCommandDescription
Xlivekeywebgrade.exeLiveKeys adware. File located in %Program Files%\livekey\livekeys
Xlivekeyswebgrade.exeLiveKeys adware. File located in %Program Files%\livekey\livekeys
NLiveMonitorLMonitor.exeMSI Live Update - auto-detects and suggests the latest BIOS/Driver/Utilities information
NLiveNoteLivenote.exeAsus graphics card driver live update feature
XLiveProtectLiveProtect.exeSystem Live Protect rogue security software - not recommended, removal instructions here
XLiveSexCamsLiveSexCams.exePremium rate adult content dialler
ULiveUpdateLiveUpdate.exeWeb-update utility as used by various types of software - see here
XLiveUpdate[Windows username]05.exeAdded by the LINEAGE TROJAN!
XLiveUpdatesmss.exeAdded by the VB.BAU BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas
NLiveUpdateCopyer.exeSamsung PC Studio is a Windows-based PC program package that you can use easily to manage personal data and multimedia files by connecting a Samsung Electronics Mobile phone (GSM/GPRS/UMTS) to your PC. You can launch the update manually - see the instructions here for example
XLiveUpdate32services.exeAdded by the VB.BAU BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas
XLivreDibane.batAdded by the BANEDI VIRUS!
XLjxrundll32.exeAdded by the LINEAG-ABD TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir%\inf
Xlk3h1[path to file]Added by the MOSUCK-G TROJAN!
Xllajyn_dflljyn081020.exeAdded by the AUTORUN-MR WORM!
Xllajyn_dflljyn081017.exeAdded by the AUTORUN-MQ WORM!
Xlljy_dfllzjy[random digits].exeAdded by the AUTORUN-GT WORM!
?LLMODCL2rundll.exe setupx.dll, InstallHinfSection ..LLMODCL2.INF??
NLM StatusLMSTATUS.EXEXerox WorkCenter XE - language monitor status application
XLMA Managerlmamanager.exeAdded by the TILEBOT-AD WORM!
ULManagerQtZgAcer.EXEAcer Launch Manager - on Acer laptops it supports the dedicated multimedia buttons and allows users to configure their function. If the optional WLAN module and Bluetooth radio are installed the associated buttons can set their operating state
ULManagerQtZpAcer.exeAcer Launch Manager - on Acer laptops it supports the dedicated multimedia buttons and allows users to configure their function. If the optional WLAN module and Bluetooth radio are installed the associated buttons can set their operating state
ULManagerHotkeyApp.exeProgrammable keys on Acer, Fujitsu and other laptops
ULManagerQtaET2S.EXEAcer Launch Manager - on Acer laptops, provides configurability for the special keys on their range of multimedia keyboards
ULManagerCPLBCL53.EXESystem Tray icon found on Acer Travelmate laptops that allow you control access to the Internet and email buttons and other computer configurations
ULmanagerLManager.exeAcer Launch Manager - manages configuration of the multimedia keys on their range of notebooks, netbooks and desktops
XlMAPllMAPl.exeAdded by the AGOBOT-RE WORM!
ULMgrOSDOSDCtrl.exeOSD (on-screen-display) utility - part of Acer Launch Manager. Gives you control to customize the monitor to your liking...from sound, brightness, contrast, horizontal and vertical positions, phase, pixel clock, color and language
ULMgrVolOSDOSD.EXEDisplays a message or graphic on-screen when you press a corresponding volume "hotkey" - such as increase, decrease or mute. Nice but not required if you don't adjust things regularly - and also known to cause a system freeze in some cases
NLMonitorLMonitor.exeMSI Live Update - auto-detects and suggests the latest BIOS/Driver/Utilities information
?lmpdpsrvlmpdpsrv.exeRelated to a Lexmark printer/scanner. Printer sharing server? Is it required?
Xlmrtlmrt.exeUnidentified adware
NLMSTATUSLMSTATUS.EXEXerox WorkCenter XE - language monitor status application
YLMSXXDLMSXXD.exeDriver for Xerox XD series printer/copiers
XlmuLMU.exeDetected by Kaspersky as the AGENT.BG TROJAN!
Xlmxyzwhq.exelmxyzwhq.exeAdded by the AGENT-GEX TROJAN!
Xlnsaslnsas.exeAdded by the ARKID TROJAN!
Xlnternet ExplorerAMSNDMGR.EXEAdded by the KWBOT.R WORM! Note that the "l" is a lower case "L" and not an upper case "I"
Xlnternet UpdatelExplore.exeAdded by the RBOT-GRH WORM! Note - the executable is spelt with a lower case "L" rather than an lower or upper case "i" which is the case with Internet Explorer
Xlnwin.exelnwin.exeAdded by the DLOADR-ATC TROJAN!
XLO0CvklLO0Cvkl.exeAdded by the FREETHOG-Z WORM!
Xloadmdm.exeAdded by the BINGHE TROJAN! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)
Xloadmsgsr32.exeAdded by the SDBOT-QR WORM!
Xload[path to worm]Added by the KELVIR.AI WORM!
XLoadMyGame.exeAdded by the LAMEYEAR-A WORM!
Xload_Kerne1.exeAdded by the LINEAGE-AN TROJAN!
XloadInternat.exeAdded by the WOWCRAFT TROJAN!
Xloadrundll32.exeAdded by the WOWCRAFT TROJAN!
Xloadsvhost32.exeAdded by the WOWCRAFT TROJAN!
Xloadsvchsot.exeAdded by the GWGHOST-O TROJAN!
Xloadexplorer.exeAdded by the LINEAGE-OZ TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
XloadKerne121.exeAdded by the LINEAGE-ON TROJAN!
XloadKerne1211.exeAdded by the LINEAGE-DY TROJAN!
Xloadrundl132.exeAdded by the LOOKED-CK WORM!
Xloadctftpscr32.exeAdded by the AGENT-FPN TROJAN!
XLoadwin32.exeAdded by the RUBBLE-A WORM!
XloadQQ.exeAdded by the QUADRULE.A WORM! Note - this is not the Tencent QQ Asian instant messanger program which is located in %Windir%
XloadWinExplorer.exeAdded by the VB.EIW WORM!
XloadSystemfile.dll.vbsAdded by an unidentified WORM or TROJAN! See here
XloadKHATRA.exeAdded by the ORBINA-A WORM!
XloadScvhost.exeAdded by the AUTORUN-AJ WORM!
Xloadcisvc.exeAdded by the DOWNBOT TROJAN!
XLoad ServiceSvHost.exeAdded by the PESIN-D WORM!
ULOAD WBLOADWB.EXEPart of Stardock's WindowBlinds custom desktop program. "WindowBlinds is the first utility of its kind. It extends Win98/NT/2K/XP to have a fully skinnable user interface. You can change the style of title bars, buttons, toolbars and much more". If you use it - keep it if not then uninstall it
XLoad-GuardWscript.exe LGuarg.exe.vbsAdded by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "LGuarg.exe.vbs" file is located in %Windir%
Nload=adw30.exeAfter Dark for Windows - screen saver program. Popular before screen savers were integrated into Win95
Uload=asistat.exeStatus monitor for an NEC SuperScript printer
?load=cfgsys32.exe??
Uload=esspk.exeSpeakerphone capability through a soundcard for an ESS modem
Yload=hotkey.exeSolo 5300 display driver for Win2K on some Gateway laptops
Nload=HPWHRC.EXELoads the Status Window software for the HP Laserjet printers
?load=WPSLOAD.EXEWindows printing system that comes with the setup for Canon BJC series on the manufacturer's disk
Nload=vi_grm.exeMonitor drivers for Trio2x/3x based video cards - displays control panel for quick access to display settings
?load=WINOSCFG.EXECould it be something to do with configuring Windows on a new PC from an OEM supplier?
Yload=wpshrc.exeRequired to prevent configuration errors on a Compaq LBP-660 and LBP-460 parallel port laser printers (and maybe others)
Yload=Bfrecv.exeBitware modem driver
Xload=msater.exeAdded by the RETSAM TROJAN!
Xload=shambl3r.exeAdded by the REMABL WORM!
Xload=Spoolsv.exeAdded by the CIADOOR.B TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%
?Load=wtfeat.exeAssociated with the Wintab Digitizer
Yload=AICLIENT.EXEAsset Insight from Tangram - asset managing software. Required if an organisation is running a centrally administered asset management system
Xload=hint.exeAdded by the ATAK WORM!
Xload=win32exec.exeAdded by the BITTER WORM!
Xload=a1g.exeAdded by the ATAK.B WORM!
Xload=dapdll.exeAdded by the ATAK.E WORM!
Xload=svhost32.exeAdded by the LINEAGE-AB TROJAN!
Yload=01comm32.exeRelated to Elsa CommPro (Communicate Pro) access software for Microlink modems - this software contains answering machine and fax functions, plus a terminal program, a WWW-browser launch function, Internet telephony, and address management. Required if you use those
Xload=inetinfo.exeAdded by the PROXY-GG TROJAN!
Xload=Kerne14.exeAdded by the LINEAGE-BA TROJAN!
XLOAD32Lorena.exeAdded by the MAPSON.C WORM!
Xload32load32.exeAdded by the NIBU, BAMBO TROJANS and DUMARU WORM!
Xload32l32x.exeAdded by the DUMARU.Z or DUMARU.Y or DUMARU.AD WORM!
Xload321111a.exeAdded by the DUMARU.AH WORM!
Xload32swchost.exeAdded by the TURTA.A WORM!
Xload32netda.exeAdded by the NIBU.E TROJAN!
Xload32winldra.exeAdded by the NIBU.J BACKDOOR or DUMARU-BI TROJAN! Note - also known as Srv.SSA-KeyLogger by Sunbelt Software which has developed a free removal tool for this keylogger
XLoadab1explorer.exeAdded by the LINEAGE-AJ TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%
YLoadBlackDblackd.exe"Intrusion detection system" of the BlackICE PC Protection (was Defender) firewall which loads independently of the "user interface" (BlackICE Utility). BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when them acquired the NetworkICE parent but is no longer available. Starts via a registry "RunServices" key on Windows 98/Me and as a service on Windows 2K/XP/Vista
ULoadBtnHndBtnHnd.exeFujitsu Siemens Lifebook laptops have some buttons on the case that can be programmed to execute specified programs (like hotkeys). The buttons can also be used as a combination lock input
XLoadDBackUpBcTool.exeAdded by the GIBE WORM!

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner