Registry Autorun Locations

A quick listing of common registry AutoRun locations

\Software\Classes\*\ShellEx\ContextMenuHandlers 7
\Software\Classes\.cmd Pending Trojan.MulDrop3.30666 http://www.drwebhk.com/en/virus_techinfo/Trojan.MulDrop3.30666.html
\Software\Classes\.exe Pending Trojan.MulDrop3.30666 http://www.drwebhk.com/en/virus_techinfo/Trojan.MulDrop3.30666.html
\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers Pending
\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance XP BackDoor!9F96808231E5 http://home.mcafee.com/virusinfo/virusprofile.aspx?key=1344398#none
\Software\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance Pending
\Software\Classes\CLSID\{ABE3B9A4-257D-4B97-BD1A-294AF496222E}\Instance Pending
\Software\Classes\CLSID\{AC757296-3522-4E11-9862-C17BE5A1767E}\Instance Pending
\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers 7
\Software\Classes\Directory\ShellEx\ContextMenuHandlers 7 Downloader.gen.a http://www.mcafee.com/threat-intelligence/malware/default.aspx?id=647913
\Software\Classes\Directory\Shellex\CopyHookHandlers Pending
\Software\Classes\Directory\Shellex\DragDropHandlers 7
\Software\Classes\Directory\Shellex\PropertySheetHandlers Pending
\Software\Classes\Exefile\Shell\Open\Command Pending Trojan.Click2.23747 http://www.drwebhk.com/en/virus_techinfo/Trojan.Click2.23747.html
\Software\Classes\Batfile\Shell\Open\Command Pending Trojan.Click2.23747 http://www.drwebhk.com/en/virus_techinfo/Trojan.Click2.23747.html
\Software\Classes\Comfile\Shell\Open\Command Pending Trojan.Click2.23747 http://www.drwebhk.com/en/virus_techinfo/Trojan.Click2.23747.html
\Software\Classes\Htafile\Shell\Open\Command Pending
\Software\Classes\Piffile\Shell\Open\Command Pending
\Software\Classes\Http\Shell\Open\Command Pending
\Software\Classes\Filter XP
\Software\Classes\Folder\Shellex\ColumnHandlers 7
\Software\Classes\Folder\ShellEx\ContextMenuHandlers 7
\Software\Classes\Folder\ShellEx\DragDropHandlers 7
\Software\Classes\Protocols\Filter 7 Win32/Monkif.J https://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=TrojanDropper%3AWin32%2FMonkif.J
\Software\Classes\Protocols\Handler Pending Trojan.DownLoader3.32096 http://www.drwebhk.com/en/virus_techinfo/Trojan.DownLoader3.32096.html
\Software\Microsoft\Active Setup\Installed Components XP, 7 PWS:Win32/OnLineGames.GR https://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=PWS%3aWin32%2fOnLineGames.GR#symptoms_link
\Software\Microsoft\Command Processor\Autorun Pending W32.Rungbu.C http://www.symantec.com/security_response/writeup.jsp?docid=2006-122711-1258-99&tabid=2
\Software\Microsoft\Ctf\LangBarAddin Pending
\Software\Microsoft\Internet Explorer\Explorer Bars Pending
\Software\Microsoft\Internet Explorer\Extensions XP
\Software\Microsoft\Internet Explorer\Toolbar Pending
\Software\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager Pending
\Software\Microsoft\Windows NT\CurrentVersion\AeDebug Pending
\Software\Microsoft\Windows NT\CurrentVersion\Drivers32 XP, 7
\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options Pending W32.Ridnu.B http://www.symantec.com/security_response/writeup.jsp?docid=2006-122714-3255-99&tabid=2
\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run Pending Win32/Slenfbot.AKD http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Worm%3aWin32%2fSlenfbot.AKD
\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Runonce Pending Win32/Neubreku.C http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Worm%3AWin32%2FNeubreku.C
\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunonceEx Pending Win32/Pushbot.QV http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Worm%3AWin32%2FPushbot.QV#techdetails_link
\Software\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls Pending
\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\AppSetup Pending
\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GinaDLL Pending
\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\LsaStart Pending
\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify Pending W32.Naras http://www.symantec.com/security_response/writeup.jsp?docid=2006-052110-1911-99&tabid=2
\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SaveDumpStart Pending
\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ServiceControllerStart Pending
\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell Pending W32.Imaut.BH http://www.symantec.com/security_response/writeup.jsp?docid=2007-110908-2704-99&tabid=2
\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\System Pending Trojan.Sharer.183 https://www.drwebhk.com/en/virus_techinfo/Trojan.Sharer.183.html
\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Taskman Pending Trojan.AVKill.8796 http://www.drwebhk.com/en/virus_techinfo/Trojan.AVKill.8796.html
\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\UIHost Pending Trojan.Sharer.183 https://www.drwebhk.com/en/virus_techinfo/Trojan.Sharer.183.html
\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit Pending Trojan.Astry http://www.symantec.com/security_response/writeup.jsp?docid=2007-111500-1533-99&tabid=2
\Software\Microsoft\Windows\CurrentVersion\App Paths\ Pending
\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers Pending
\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects Pending Win32/BaiduSobar http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=BrowserModifier%3aWin32%2fBaiduSobar#symptoms_link
\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler Pending
\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks Pending W32/Toffus.A http://www.avira.com/en/support-threats-description/tid/4968/w32_toffus.a.html
\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers Pending W32/Toffus.A http://www.avira.com/en/support-threats-description/tid/4968/w32_toffus.a.html
\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown Pending
\Software\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup Pending
\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run Pending Backdoor.Samkams.B http://www.symantec.com/security_response/writeup.jsp?docid=2010-010612-1816-99&tabid=2
\Software\Microsoft\Windows\CurrentVersion\Policies\System\Shell Pending
\Software\Microsoft\Windows\CurrentVersion\Run Pending W32.Imaut.BH http://www.symantec.com/security_response/writeup.jsp?docid=2007-110908-2704-99&tabid=2
\Software\Microsoft\Windows\CurrentVersion\RunOnce 7 Win32/BaiduSobar http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=BrowserModifier%3aWin32%2fBaiduSobar#symptoms_link
\Software\Microsoft\Windows\CurrentVersion\RunOnceEx 7 Nettroj-A http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Troj~Nettroj-A.aspx
\Software\Microsoft\Windows\CurrentVersion\RunServices Pending Nettroj-A http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Troj~Nettroj-A.aspx
\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce Pending Nettroj-A http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Troj~Nettroj-A.aspx
\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved Pending
\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad Pending Trojan.Mixpel http://www.symantec.com/security_response/writeup.jsp?docid=2007-030414-4355-99&tabid=2
\Software\Policies\Microsoft\Windows\System\Scripts\Logoff Pending
\Software\Policies\Microsoft\Windows\System\Scripts\Logon Pending W32/AutoRun-DO http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/W32~AutoRun-DO/detailed-analysis.aspx
\Software\Policies\Microsoft\Windows\System\Scripts\Shutdown Pending
\Software\Policies\Microsoft\Windows\System\Scripts\Startup Pending
\Software\Wow6432Node\Classes\*\ShellEx\ContextMenuHandlers 7 (64-bit)
\Software\Wow6432Node\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance 7 (64-bit)
\Software\Wow6432Node\Classes\Directory\Background\ShellEx\ContextMenuHandlers 7 (64-bit)
\Software\Wow6432Node\Classes\Directory\ShellEx\ContextMenuHandlers 7 (64-bit)
\Software\Wow6432Node\Classes\Directory\Shellex\DragDropHandlers 7 (64-bit)
\Software\Wow6432Node\Classes\Folder\Shellex\ColumnHandlers 7 (64-bit)
\Software\Wow6432Node\Classes\Folder\ShellEx\ContextMenuHandlers 7 (64-bit)
\Software\Wow6432Node\Microsoft\Active Setup\Installed Components 7 (64-bit)
\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar Pending
\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32 Pending
\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects Pending
\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run 7 (64-bit)
\System\CurrentControlSet\Control\BootVerificationProgram\ImagePath Pending
\System\CurrentControlSet\Control\Lsa\Authentication Packages Pending
\System\CurrentControlSet\Control\Lsa\Notification Packages Pending
\System\CurrentControlSet\Control\Lsa\Security Packages Pending
\System\CurrentControlSet\Control\MPRServices Pending Backdoor.Haxdoor.B http://www.symantec.com/security_response/writeup.jsp?docid=2004-052016-0128-99&tabid=2
\System\CurrentControlSet\Control\NetworkProvider\Order Pending
\System\CurrentControlSet\Control\Print\Monitors Pending
\System\CurrentControlSet\Control\SafeBoot\Option Pending W32.Ridnu.B http://www.symantec.com/security_response/writeup.jsp?docid=2006-122714-3255-99&tabid=2
\System\CurrentControlSet\Control\SecurityProviders\SecurityProviders Pending
\System\CurrentControlSet\Control\ServiceControlManagerExtension Pending
\System\CurrentControlSet\Control\Session Manager\BootExecute Pending W32/Toffus.A http://www.avira.com/en/support-threats-description/tid/4968/w32_toffus.a.html
\System\CurrentControlSet\Control\Session Manager\Execute Pending W32/Toffus.A http://www.avira.com/en/support-threats-description/tid/4968/w32_toffus.a.html
\System\CurrentControlSet\Control\Session Manager\KnownDlls Pending W32/Toffus.A http://www.avira.com/en/support-threats-description/tid/4968/w32_toffus.a.html
\System\CurrentControlSet\Control\Session Manager\S0InitialCommand Pending W32/Toffus.A http://www.avira.com/en/support-threats-description/tid/4968/w32_toffus.a.html
\System\CurrentControlSet\Control\Session Manager\SetupExecute Pending W32.Goner.A http://www.symantec.com/security_response/writeup.jsp?docid=2001-120415-2434-99&tabid=2
\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms Pending
\System\CurrentControlSet\Control\WOW Pending Backdoor.Tidserv.M http://www.symantec.com/security_response/writeup.jsp?docid=2011-011801-4707-99&tabid=2
\System\CurrentControlSet\Services XP, 7 Trojan.Necurs http://www.symantec.com/security_response/writeup.jsp?docid=2012-121212-2802-99&tabid=2
\System\CurrentControlSet\Services\WS2IFSL 7 Trojan.Riler.E http://www.symantec.com/security_response/writeup.jsp?docid=2005-070714-5922-99&tabid=2
\System\CurrentControlSet\Services\VxD Pending DonaldD.Trojan.C http://www.symantec.com/security_response/writeup.jsp?docid=2001-091211-2837-99&tabid=2
\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries Pending Trojan.Neloweg http://www.symantec.com/security_response/writeup.jsp?docid=2012-020609-4221-99&tabid=2
\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64 7
\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries Pending
\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64 Pending