Hello.... network guy, not an OS guru. I have multiple machines a day that will show up on a report as attempting to install as autorun. Sometimes these events will be attempted 5-10,000 times a day, but we have software blocking it. Below is 3 examples from different machines, whereas the last '\' has different registry names. Are these actual exes that are attempting to be run at at startup? I've googled like crazy but can't find any info on names like 'dieubt' and 'tier'. And the S-1-21-1078081533 etx (I blocked out some with Xs), is this a user ID?
Thank you for any help.