Lista de ejecuciones automáticas

Claves:

Y Ejecución automática generalmente inofensiva.
N No requerida pero puede ser ejecutada.
U Elección del usuario. Ejecutarla si es necesario.
X Definitivamente NO requerida. Usualmente Malware.
? Desconocida

Filtro:





View: All # A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Todos

Found 14337 autoruns. Autorun 1 to 100:

StatusAutorun nameCommandDescription
Xsystem32.exeAdded by the AGOBOT-KU WORM! Note - has a blank entry under the Startup Item/Name field
Xpathex.exeAdded by the MKMOOSE-A WORM! Note - has a blank entry under the Startup Item/Name field
Xsvchost.exeAdded by the DELF-UX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field
XMSPF.EXEAdded by a variant of the SDBOT WORM! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field
Xdllvirtual.exeAdded by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field
Xdllvirtual.dllAdded by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field
Xdllvirtual.jsAdded by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field
X SystemBootservices.exeAdded by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Help\Help subfolder of the Windows or Winnt folder
X WinCheckservices.exeAdded by the SOBER-S WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "ConnectionStatus\Microsoft" subfolder of the Windows or Winnt folder
X Windowsservices.exeAdded by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "WinSecurity" subfolder of the Windows or Winnt folder
X WinStartservices.exeAdded by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Connection Wizard\Status subfolder of the Windows or Winnt folder
X winsystem.syssmss.exeAdded by the SOBER.K TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a msagent\win32 subfolder of the Winnt or Windows folder
Y!1_pgaccountpgaccount.exeDiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. You will see one instant of pgaccount.exe for every active account on your system, and this is essential for PG to work properly
Y!1_ProcessGuard_Startupprocguard.exeDiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks
U!AVG Anti-Spywareavgas.exePart of AVG Anti-Spyware from Grisoft
U!ewidoewido.exePart of Ewido anti-spyware
N!NoLoadwinrecon.exeWinRecon keystroke logger/monitoring program - remove unless you installed it yourself!
?$EnterNetEnternet.exeConnection manager for the EnterNet ISP. You can also use RASPPOE
X$sys$cmp$sys$xp.exeAdded by the RYKNOS.B TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer
X$sys$crash$sys$sonyTimer.exeAdded by the WELOMOCH TROJAN!
X$sys$crash$sys$sos$sys$.exeAdded by the WELOMOCH TROJAN!
X$sys$crash$sys$WeLoveMcCOL.exeAdded by the WELOMOCH TROJAN!
X$sys$drv$sys$drv.exeAdded by the RYKNOS TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer
X$sys$momomomochin$sys$sonyTimer.exeAdded by the WELOMOCH TROJAN!
X$sys$momomomochin$sys$sos$sys$.exeAdded by the WELOMOCH TROJAN!
X$sys$momomomochin$sys$WeLoveMcCOL.exeAdded by the WELOMOCH TROJAN!
X$sys$umaiyo$sys$sonyTimer.exeAdded by the WELOMOCH TROJAN!
X$sys$umaiyo$sys$sos$sys$.exeAdded by the WELOMOCH TROJAN!
X$sys$umaiyo$sys$WeLoveMcCOL.exeAdded by the WELOMOCH TROJAN!
U$Volumouse$volumouse.exeVolumouse from Nirsoft. "Provides you a quick and easy way to control the sound volume on your system - simply by rolling the wheel of your wheel mouse"
X$WindowsRegKey%updateIEXPLORE.EXEAdded by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program Files\Internet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder
N%cmpmixtitle%%cmpmixstr%Possibly related to C-Media Mixer Control panel?
N%FP%012-L2TP fts.exefts.exe012.Net.il Israeli ISP software front-end
U%FP%012-L2TP FWPortal.exeFWPortal.exe012.Net.il Israeli ISP dial-up software
N%FP%1776 Internet fts.exefts.exe1776 Internet US ISP software ISP software front-end
U%FP%1776 Internet FWPortal.exeFWPortal.exe1776 Internet US ISP dial-up software
N%FP%Barak013 fts.exefts.exeBarak013 Israeli ISP software front-end
U%FP%Barak013 FWPortal.exeFWPortal.exeBarak013 Israeli ISP dial-up software
N%FP%Friendly fts.exefts.exeFriendly ISP software front-end
X(*)API MachinewinSOCKS.exeHomepage hijacker, see here (* = any digit)
X(*)Runwin32API.exeHomepage hijacker, see here (* = any digit)
X(default)[random filename].exeAdded by the BLACKMAL WORM!
X(default)rundll32.exe [path] Zykheptd.dllAdded by the HESIVE.B TROJAN!
X(L4r1$$4) (4nt1) (V1ruz)SP00Lsv32.pifAdded by the ASSIRAL.B WORM!
X*JanisRuckenbrodIIjanis.comAdded by the POPS WORM!
X*Microsoft Updatectxma.exeAdded by the STMU TROJAN!
X*Microsoft Updatecxma.exeAdded by the STMU TROJAN!
X*Microsoft Updatewstcl.exeAdded by the STMU TROJAN!
X*Microsoft Updatewucxt.exeAdded by the STMU TROJAN!
X*Microsoft Updatewuytc.exeAdded by the STMU TROJAN!
X*MS Setup[random filename]Virtumondo adware, also known as the VUNDO TROJAN!
X*Security Centersecctr.exeAdded by the SDBOT.BRO WORM!
Y*StateMgrstatemgr.exeWindows ME default for System Restore. Do NOT disable!
X*Windows [filename] Checker[filename]Added by the KEDEBE-B WORM!
X*windows updatewrauclt.exeAdded by the RBOT-QU WORM!
X*windows updatewuanclt.exeAdded by the RBOT-PG WORM!
X*windows updatewuaucrlt.exeAdded by the SPYBOT.HUR WORM!
X*windows updatewuraclt.exeAdded by the RBOT-PO WORM!
X*windows updatewurauclt.exeAdded by the RBOT-SY WORM!
X*windows updatewsctl.exeAdded by the SPYBOT.PR WORM!
X*windows updatewkmst.exeAdded by the SDBOT.AVD WORM!
X*windows updatewscxt.exeAdded by the RBOT.AOS WORM!
X*windows updatewaurclt.exeAdded by a variant of the RBOT WORM!
X*WindowsAudiosystemupd.exeAdded by the AGENT-TH WORM!
X*WinLogon[trojan path] ren time:[random number]Added by the VUNDO TROJAN!
X*winstatswinstats.exeAdded by the GARGAFX TROJAN!
X*wuauclt.exew****.exe [* = random char]Added by a variant of the RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe, wtmsv.exe, wxmst.exe, wmsvc.exe and so on...
X,main drive Loaderwininfo.exeSuspected malware as it appears in 3 different registry locations - see here
X..ABC2007.exeAdded by the DLOADR-ASH TROJAN!
X.mscdrlassa.exeAdded by the WEBUS.C TROJAN!
X.mscdrlsvchost.exeAdded by the WEBUS.D TROJAN!
X.mscdsrlsvchost.exeAdded by the CR TROJAN!
X.mscsblsvhost.exeAdded by the CMQ TROJAN!
X.msfupdatemsveup.exeAdded by the ALLOCUP.A WORM!
X.mssecuremssecure.exeAdded by the DDOS_BOXED.X TROJAN!
?.NET configsysmon32.exe??
X.nortonrchost.exeAdded by a variant of the BOXED-A TROJAN!
X.nvsvcsmss.exeAdded by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!
X.nvsvcbsmssb.exeAdded by the BOXED.CG TROJAN!
X.Progservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
X.Progwinlogon.exeAdded by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
X.protectedN/ASmitfraud variant
X.svchostCSRSS.EXEAdded by the WEBUS.F TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
X.TEXTCONVcsrss.exeAdded by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
X.TEXTCONVlsass.exeAdded by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
X.WMAudiocsrss.exeAdded by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
X.WMAudiolsass.exeAdded by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
N/l:engN/ARelated to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search function
X;Rundll[filename]Added by the PWSLEGMIR.E TROJAN!
X?ekio Startups?nksvc32.exeAdded by the AGOBOT-OV WORM where ? is a random character
X@regedit -s ..win.dllAdded by the SEEKER.K TROJAN!
N@Hoc ToolbarAtHoc.exeOne-click activated browsing toolbar used by various web-sites. See here for more info
N@lohareminder.exeRegistration reminder for @loha@home E-mail utility
X@tour_ww@tour_ww[1].exeAdult content dialler
X[3-4 random letters]nslookup.exePurityScan/Clickspring adware. Not to be confused with the legitimate nslookup.exe which is found in the System32 folder
X[3-4 random letters]Srv32[path to file]Added by the BANCSADE-A TROJAN!
X[decimal number][path to worm]Added by the OPOSSUM-A WORM! The decimal number can be anything, eg, 0.12345678
X[default]DrWatson32.exeAdded by the DREMN TROJAN!
X[Entry name]System.exeAdded by the NETHIEF-N TROJAN!
X[Ephemeral 2.5] by TreeHugger,[path to worm]Added by the LEMOOR-C WORM!

La lista de ejecuciones automáticas es presentada en asociación con Sysinfo.org