Lista de ejecuciones automáticas

Claves:

Y Ejecución automática generalmente inofensiva.
N No requerida pero puede ser ejecutada.
U Elección del usuario. Ejecutarla si es necesario.
X Definitivamente NO requerida. Usualmente Malware.
? Desconocida

Filtro:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Todos

Found 1303 autoruns. Autorun 1101 to 1200:

StatusAutorun nameCommandDescription
XCS Updatecopy /Y [path] ActivationManager.dll.upd [path] ActivationManager.dllAdded by an unidentified malware
NCS4ServiceManagerCS4ServiceManager.exePart of both stand-alone Adobe CS4 products (such as Photoshop and Dreamweaver) and suites, CS4 Service Manager supports online services such as Adobe Drive. Whilst testing, it would appear that this entry can be safely disabled as it will be loaded when required but if you experience problems try re-enabling it
NCS5ServiceManagerCS5ServiceManager.exePart of both stand-alone Adobe CS5 products (such as Photoshop and Dreamweaver) and suites, CS5 Service Manager supports online services. Whilst testing, it would appear that this entry can be safely disabled as it will be loaded when required but if you experience problems try re-enabling it
NcsaRemspqmdmui.exeCompaq modem country selection
YCSAV_CheckVirusesvchk.exeCommand Antivirus related
Ucsccsc.exeCommand line compiler for Microsoft C# it gets installed with the .NET SDK
Xcscriptscscripts.exeAdded by the BDOOR-AAP BACKDOOR!
XCSCRS Valuecscrs.exeAdded by the RBOT-AAA WORM!
XCSCRS Value CheckMsPMSPSd.exeAdded by a variant of the SDBOT WORM!
XCseccs.exeCyber Security rogue security software - not recommended, removal instructions here
Ncsecwizcsecwiz.exeSetup wizard for the Client Security Software for IBM\Lenovo notebooks. This entry only runs once, after the software has been installed and the notebook rebooted for the first time. If the wizard isn't completed a shortcut is available via the Start menu until it is
Xcserv32cserv32.exeAdded by the STRATION.EC WORM!
XCsimPlayerCsimPlayer.exeAdded by the KOOBFACE-AD WORM!
UCSINJECT.EXECSINJECT.EXEPart of Quarterdeck/Norton CleanSweep. "Csinject must be loaded in order for Smart Sweep to automatically monitor installations and properly track registry changes"
Xcsm Win Updatescsm.exeAdded by the ZOTOB.B WORM!
XCSNetManagerXpisass.exeAdded by the HIDER-O TROJAN!
YCSO.exeCSO.exeONO Service Center tool installed when you choose to install their internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabled
Xcsoftoksoftok.exeAdded by the QQPASS.G TROJAN!
Xcsoscsos.exeAdded by the SDBOT-DFE WORM!
Xcsrcsrrs.exeAdded by the RBOT-CKM WORM!
Xcsrcscsrcs.exeAdded by the AGENT-HUA TROJAN!
Xcsrrscsrrs.exeAdded by the INEUDOK.A TROJAN!
Xcsrscsrs.exeAdded by the GAOBOT.GEN!POLY WORM!
Xcsrsccsrsc.exeAdded by the SILLYDC WORM!
XCsrssCSRSS.EXEAdded by the PUNYA-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Documents and Settings\Administrator\Local Settings\Application Data\WINDOWS
Xcsrssssms.exeAdded by an unidentified malware
XCSRSSCSRSS.EXESearch page hijacker, redirecting to h**p://www.search-aide.com/. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!
XCsrsscsrss.exeAdded by the CHOD WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a random subfolder
Xcsrsscsrss.exeAdded by the KEYLOG-AQ KEYLOGGER! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
Xcsrsscsrss.exeAdded by the CHODE-J WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a random subfolder
Xcsrssmsmsgs.exeAdded by the CHODE-J BACKDOOR! Note - this malware uses MSN Messenger (which is located in %Program Files%\Messenger) in the background to propogate itself
Xcsrssnwiz.exeAdded by the CHODE-J WORM!
Ucsrsscsrss.exeBeyondKeylog surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Supremtec
XCsrss Hostcsrhost.exeAdded by the IRCBOT.BIZ WORM!
XCSRSS Loadercsrsss.exeAdded by the AGOBOT.TX WORM!
Xcsrss.execsrss.exeAdded by the DALBUG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
XcsrssLevel4csrss.exeUnidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "Level4" subfolder
XCSRSSUCSRSSU.exeCoolWebSearch parasite variant - hijacking to Slawsearch.com. Also detected as the CWS-E TROJAN!
XCSRSSWCSRSSW.EXEAdded by the CWS-F TROJAN!
XCSRSWIN[trojan filename]Added by the WINSHELL.50 TROJAN!
XCSRSX[trojan filename]Added by the WINSHELL.50.B TROJAN!
Xcsrvsscsrvss.exeAdded by a variant of the SDBOT TROJAN!
UCSS ServerCSSServer.exeComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself
UCSS_CentralCSS_1631.EXECSS Communication Agent (95 Host) from Command Software Systems (now Authentium). "CSS Central™ provides administrators with a powerfully proactive tool to effectively manage and maintain the anti-virus strategy from a centralized console"
Ncssauthcssauth.exePart of Thinkvantage Client Security Solution for Lenovo ThinkPad notebooks and ThinkCentre desktops. Once configured via the associated setup screens this loads via winlogon.exe (and loads the password manager) and therefore disabling this entry has no effect
Ncssauthecssauthe.exePart of Thinkvantage Client Security Solution for IBM/Lenovo ThinkPad notebooks and ThinkCentre desktops. Once configured via the associated setup screens this loads via winlogon.exe (and loads the password manager) and therefore disabling this entry has no effect
YCSScheduleCheckSCHWIZEX.EXEPart of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot
Xcssrscssrs.exeAdded by the BANCBAN-DW TROJAN!
Xcssrss.execssrss.exeMalware installed by different rogue security software including SpyKillerPro
XcsssCsss.exeAdded by the BALICK TROJAN!
UCstlFaxTrayFaxTray.ExeSystem Tray access to OpenText Fax Appliance, FaxPress (formerly Castelle FaxPress) - which "offers a combined hardware and software faxing solution, providing every possible computer-based, network fax option"
XCSV10P1CSP001.exeClearSearch adware
XCSV10P70CSv10P070.exeClearSearch adware
XCSV7P26CSV7P26.exeClearSearch adware
XCSV7P70CSV7P070.exeClearSearch adware
XCSV7P91CSV7P91.exeClearSearch adware
Ucsvdeacsvdea.exeSpyArsenalLog surveillance software. Uninstall this software unless you put it there yourself
Xcsvhost.execsvhost.exeAdded by the CIMUZ-BD TROJAN!
Yctct.exect.exe is a file is for the HP Learning Adventure software and if you use this software it is required to run it
XCT Control SettingsCTSVCCD.EXEAdded by the RBOT-YS WORM!
UCTAPR2CTAPR2.exeConsole Launcher for the Creative Sound Blaster X-Fi series
NCTAVTrayCTAvTray.exeFor Creative Soundblaster Live! series soundcards. Plays the EAX animation on start-up and adds a System Tray icon for it. Available via AudioHQ
UCTCheckCTCheck.exeAssociated with the ZEN range of MP3 players from Creative Technology Ltd. A visitor recommended the "U" status but what does it do?
UCTCMonitorCTCMonitor.exeClick-to-Convert - document-to-HTML or doc-to-PDF converter. Only required if you are going to use the File -> Print method of using Click-to-Convert. If converting directly from MS Office, it is not required
XCTDriverundll32.exe drvmod.dll,startupAdded by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "drvmod.dll" file is found in %System%
NCTDVDDetCTDVDDet.exeAuto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player, selecting Tools, then uncheck the Auto Start box. It should not start up automatically again
XCTF Device Loaderctfmond.exeAdded by the AGOBOT-FO WORM!
Xctf.exectf.exeAdded by a variant of the BIFROSE TROJAN!
Xctflog managerctflog.exeAdded by the DONBOMB.A TROJAN!
XCTFM0N.exeCTFM0N.exeAdded by the STARTPAGE.P TROJAN! Notice the digit "0" in both columns rather than the upper case "o"
Xctfmencssrs.exeAdded by the STARTP-DC TROJAN!
Xctfmgrctfmgr.exeAdded by the PWS-ATU TROJAN!
Xctfmomctfnom.exeAdded by the BCKDR-QTA BACKDOOR!
Uctfmonctfmon.exeSupports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or, for example, if speech is selected as an alternative input for MS Office or Notepad. Required to support advanced text services (such as right to left text) for East Asian users. Can be disabled via Start → Control Panel → Regional and Language Options → Languages → Text Services and Input Languages → Details → Advanced → System Configuration → Turn off advanced text services (which also turns off the language bar). See also here and here. Can also cause problems with some other programs if left enabled - see here for such an example
Xctfmontaskmgr32*.exe [* = number]Added by the SOWSAT.B WORM!
Xctfmoncftmon.exeAdded by the DELIVE-A BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%
XctfmonmIRC.dllAdded by the DELBOT-E TROJAN!
XctfmonWinConst.exeAdded by the ASSASIN-G TROJAN!
UCTFMonctfmon.exeFamily KeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in a "CTF" sub-folder
Xctfmonmsnmsgr.exeAdded by the BDOOR-JV BACKDOOR! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%
XCTFMONwscript.exe /E:vbs winjpg.jpgAdded by the RUNAUTO.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "winjpg.jpg" file is located in %System%
XCTFMONwscript.exe /E:vbs regedit.sysAdded by the VBSAUTO-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "regedit.sys" file is located in %System%
XCTFMONwin.exeAdded by the VBS.RUNAUTO.G WORM!
XCtfmonwmisys.exeAdded by the IRCBOT-ADS WORM!
XctfmonWinUP.exeAdded by the BANKER-VV TROJAN!
Xctfmonctfmon.exeAdded by the AUTORUN-G WORM! Note - this is not the legitimate ctfmon.exe process associated with alternate language and method inputs which is always located in %System%. This one is located in a "1046" sub-folder
Xctfmonsvhost.exeAdded by the BACKDR-EL BACKDOOR!
XCTFMON.CPLCTFM0N.CMDDetected by Symantec as the SILLYFDC WORM! See here
XCtfmon.exectfmon32.exeCoolWebSearch Ctfmon32 parasite variant
Xctfmon.exectfmon.exeAdded by the RAIDYS TROJAN! Note - this overwrites the legitimate ctfmon.exe process associated with alternate text inputs which is located in %System%
Xctfmon.exemsupdate32.exeSpy Sheriff/SpywareNO malware, also detected as the SPYHOAX-A TROJAN, pretends to be a spyware remover! - file names spotted sofar include VXH8JKDQ2.EXE, NS6281400.so, CVXH8JKDQ2.EXE, down3.exe, sefe.exe, winstall.exe, and tool2.exe
Uctfmon.exectfmon.exeSupports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or, for example, if speech is selected as an alternative input for MS Office or Notepad. Required to support advanced text services (such as right to left text) for East Asian users. Can be disabled via Start → Control Panel → Regional and Language Options → Languages → Text Services and Input Languages → Details → Advanced → System Configuration → Turn off advanced text services (which also turns off the language bar). See also here and here. Can also cause problems with some other programs if left enabled - see here for such an example
Xctfmon.exectfmon.exe eminem.exeAdded by the BHARAT.A WORM!
XCTFMON.EXEsvchost.exeAdded by the JUEGO-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
Xctfmon.exeCTFM0N.EXEAdded by the AUTORUN-AYX WORM! Notice the digit "0" in the filename rather than the upper case "o"
Uctfmon.exectfmon.exeTotalSpy keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %ProgramFiles%\TS Trial
XCTFMON.EXEctfmon.exeAdded by the VBSP-A WORM! Note - this is not the legitimate ctfmon.exe process associated with alternate language and method inputs which is always located in %System%. This one is located in a "1126" sub-folder
XCTFMON32CTFMON32.EXECoolWebSearch Ctfmon32 parasite variant - also detected as the CWS-E TROJAN!
Xctfmon32[random filename].exeAdded by the RBOT-GSN WORM!
Xctfmon32taskmgr32*.exe [* = digit]Added by the SOWSAT.C WORM!
Página: 1 2 3 4 5 6 7 8 9 10 11 12 13 14

La lista de ejecuciones automáticas es presentada en asociación con Sysinfo.org