Index Introduction Database Detailed Entries Updates Concise List HJT Forums Rogues Message Board

Windows startup programs - Database search

If you're frustrated with the time it takes your Windows 7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.

See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.

Last database update :- 29th Apr, 2013
31819 items listed

You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.

Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:

A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z

NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.

Please click on the Search button

1019 results found for N

Startup Item or Name Status Command or Data Description Tested
CEUSZ9TMXN-More.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\MoRe-NNo
UNC5KUXN-More.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\MoRe-NNo
dpzProtectXn.vbeAdded by the RUNAUTO.H WORM!No
.protectedXN/ASmitfraud variantNo
/l:engNN/ARelated to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search functionNo
/sNN/ARelated to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search functionNo
17779Proj2002?N/A??No
ARCSolo RecoveryNN/ABackup software by Computer Associates - no longer supportedNo
Batchreg1NN/APart of the Windows System Recovery process. Added to the registry via Msbatch.inf. The existence of this key or process after the last reboot during installation indicates an unsuccessful installation, as that key should be deleted automatically. See hereNo
ccAppsXN/AAdded by the KANGAROO-A TROJAN!No
DashIE?N/ACould be related to "Dash Power Shopping" tool bar in IE?No
Datechecker?N/ACould be related to this?No
DDT?N/A??No
DLHelperEXE.exeXN/ADownloader for Microgaming/Casino software - stealth installedNo
HostXN/AAdded by the POPDIS or STARTPAGE.F TROJANS!No
hpoddt01.exeNN/AInstalled by the "HP Photo and Imaging Director" software. If you ask for the imaging software, this program will be startedNo
HWinstYN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left outNo
IPinstYN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left outNo
IZE?N/A??No
LASTinstYN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left outNo
MCXN/AAdded by the SIMCSS TROJAN!No
MSupdate.exeXN/ACoolWebSearch parasite variant - resets home page to an adult content siteNo
MSupdater.exeXN/ACoolWebSearch parasite variant. Installs the Winshow.dll browser pluginNo
nAv AGENTXN/AAdded by the RIOSYS MACRO! Note the lower-case "n" and "v" in the name as this is not the valid Norton AntiVirus entry of the same name - indeed it closes Norton AV processesNo
NCClient?N/A??No
piiserviceOEUN/ASpam Inspector (nee Postal Inspector) from The Giant Company or iHateSpam from Sunbelt Software - spam filter add-ons for OENo
RecoverNN/AAdded during the installation of Comcast High Speed Internet software. During installation the system reboots and if the disk is removed a screen appears asking for the disk to be re-inserted to complete installation. Not required once installion is completeNo
regtmlp?N/A??No
RTStartMute?N/A??No
rvdeXN/ARelated to li-speed****No
ScanRegistryXN/AAdded by the DINOXI or DINOXI.B WORMS!No
SchedulingAgentXN/AAdded by the DINOXI or DINOXI.B WORMS!No
SOFTinstYN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left outNo
SymRunXN/AAdded by the KANGAROO-A TROJAN!No
TDockNUndock?N/AFound on a Toshiba laptop - for use with a docking station?No
TheMainStart?N/A??No
TWarmBay?N/AFound on a Toshiba laptop. Related to hotswap bay management?No
TWBbtn?N/AFound on a Toshiba laptopNo
UTILsInstYN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left outNo
WaveTop Receiver 1NN/AWaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98No
WaveTop Receiver 2NN/AWaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98No
WaveTop Upload ManagerNN/AWaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98No
Winlogon.exeXN/ACoolWebSearch parasite variant - resets home page to an adult content siteNo
WMBootNN/AAssociated with Logitech Wingman game controllers. Not required but what does it do?No
Nod3d2 Free antivirusXN0D32KRN.EXEAdded by the RBOT-ABQ WORM!No
svtcinXn20050308.a.Stub.EXEDetected by SUPERAntiSpyware as Trojan.N20050308.Process. The file is typically located in %System%No
nsvcinXn20050308.exeDelfin Media Viewer adware relatedNo
ntechinXn20050308.exeDelfin Media Viewer adware relatedNo
tsvcinXn20050308.exeDelfin Media Viewer adware relatedNo
SystemSv121Xn2ewma1xxsv234.exeAdded by the TIBS.TJ TROJAN!No
MONPluginSrIvcsXn3monap23.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
MSNPluginSrIvcsXn3vasap23.exeDetected by Microsoft as Backdoor:Win32/Sdbot.DI and by Malwarebytes Anti-Malware as Backdoor.BotNo
[random name]Xn?lookup.exePurityScan adwareNo
[random name]Xn?pdb.exePurityScan adwareNo
[random name]Xn?tdde.exePurityScan adwareNo
[random name]Xn?tepad.exePurityScan adwareNo
anbv32Xnabv32.exeAdded by the TITOG.C WORM!No
nacarXnacar.exeDetected by McAfee as Generic PWS.y!d2u and by Malwarebytes Anti-Malware as Adware.KoradNo
Net Activity DiagramUnad.exeNet Activity Diagram from MetaProducts. Monitors your computer internet activity. Available via Start → ProgramsNo
NADaemonNNADAEMON.EXEProgram by NetActive which appears to be piggybacked onto some Nvidia graphics cards software. They seem to look after "digital rights management". One user reports disabling it has no detrimental affect - not requiredNo
iCnNNAG.EXEiChoose - shopping browser enhancement that alerts you to cheaper deals for goods you want to buy, if they exist. Not related to the Mac icon program of the same nameNo
Razer Naga DriverUNagaEpicSysTray.exeRazer Naga gaming mouse driver - required if you use the additional features and programmed keys/macrosNo
Razer Naga DriverUNagaTray.exeRazer Naga gaming mouse driver - required if you use the additional features and programmed keys/macrosNo
NaggerrunkeyNnagger.exePackard Bell Free Internet Signup screenNo
nah_ShellXnah_[random].exeDetected by Symantec as Backdoor.Snifula.ENo
Naimagent_UIYnaimag32.exeWorkstation background program for Network Associates McAfee ePolicy Orchestrator - a network management tool for enforcing antivirus protection of the workstations using system policies. Works with both McAfee and Norton AntiVirus. NAIMAG32 and NAIMAS32 communicate with the ePolicy Orchestrator processes on the network fileserver to check for virus updates or for the need to perform a virus scanNo
GoOutsideXnakedx.exeAdded by the SDBOT-AGK WORM!No
Application ExplorerUNaldesk.exeNovell Zenworks Application Explorer Executable. "For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components."No
Application ExplorerUNalView.exeApplication Explorer - file manager type access to Novell Application Launcher for installing and updating network residing applicationsNo
namclean199Xnamclean199.exeDetected by McAfee as Downloader.a!c2a and by Malwarebytes Anti-Malware as Trojan.AgentNo
Startup KeyXName.exeDetected by McAfee as Generic Dropper and by Malwarebytes Anti-Malware as Trojan.MSILNo
NAMEDPIPE SYSTEMXnamedpipe.exeAdded by the MYTOB-FH TROJAN!No
nana2009Xnana2009.exeAdded by the POISON.PG BACKDOOR!No
Ya SalamXNancyAjram.exeAdded by the JALABED WORM!No
Nano AntivirusXnanoav.exeNano Antivirus rogue security software - not recommended, removal instructions hereNo
RnaomfltUnaomf.exeNaomi internet filtering softwareNo
Mionix NAOS 5000UNAOS_Monitor.EXESupport software for the Mionix NAOS 5000 laser gaming mouseNo
NAP32XNAP32.exePremium rate adult content diallerNo
nvpatchXnapatch.exeAdded by the SASSER-F WORM!No
Windows Logon ServiceXnapi32.exeAdded by the SPYBOT.ANDM WORM!No
egikuguXnapolecy.exeAdded by the LIOTEN.KS WORM!No
napumdeadyfsXnapumdeadyfs.exeDetected by Sophos as Troj/Cutwail-AI and by Malwarebytes Anti-Malware as Trojan.Agent.EDNo
NarratorUNarrator.exeAssociated with the Narrator accessibility feature on Windows XP. It is used to convert text to speechNo
RunNarratorUNarrator.exeAssociated with the Narrator accessibility feature on Windows XP. It is used to convert text to speechNo
Windows Audio LayerXnarsvc.exeAdded by the IRCBOT.AFT BACKDOOR!No
NasUnas.exeClearx adwareNo
Network AdministrationXNAS.exeAdded by the ANTILAM.20.Q TROJAN!No
ccAppXNasty.exeDetected by Symantec as Trojan.ObsorbNo
NavScanXNasty.exeDetected by Symantec as Trojan.ObsorbNo
4wd!!!XNatal!.pifAdded by the OPASERV.AI WORM!No
NatalXNatal.scrAdded by the OPASERV.AE WORM!No
atargetXNatarget.exeDetected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\AtargetNo
NateFinderXNateFinderUpt.exeDetected by McAfee as Generic.dxNo
NateXnate_as.exeDetected by Malwarebytes Anti-Malware as Adware.Korad. The file is located in %ProgramFiles%\nate_as - see hereNo
NATDriverXnatsdrv.exeDetected by Dr.Web as Trojan.DownLoader7.22726 and by Malwarebytes Anti-Malware as Trojan.RansomNo
Dragon NaturallySpeakingUnatspeak.exeDragon NaturallySpeaking speech recognition software from Nuance (was ScanSoft)No
Natural DesktopUNatural Desktop.exeAnimated desktop gadget included with the Natural Desktop theme for MyColors from Stardock CorporationNo
Naughty.exeXNaughty.exeDetected by McAfee as RDN/Generic PWS.y and by Malwarebytes Anti-Malware as Trojan.Agent.JVNo
Microsoft UpdateXNAV.exeAdded by the RBOT-IV WORM!No
SystemXnav32.exeAdded by the RBOT-BHV WORM!No
Norton Auto ProtectXnava.exeAdded by an unidentified VIRUS, WORM or TROJAN! The file is located in %System%No
Nortan Anti VirusXnava32.exeAdded by the FTP_ANA.C BACKDOOR!No
Windows Print SpoolerXNavAgent32.exeAdded by an unidentified VIRUS, WORM or TROJAN!No
WinNavap ServiceXnavapdlls32.exeAdded by the RBOT.BLF WORM!No
navappXnavapp.exeNavExcel adware variantNo
AUTOPROTECTUXnavapq32.exeAdded by an unidentified WORM or TROJAN!No
Compaq Service DriversXnavapqwa.exeAdded by the SDBOT.BBQ WORM!No
protecseXnavapss32.exeAdded by the SDBOT.AFE WORM!No
Norton Service ProcessXnavapsvc.exeAdded by the AGOBOT-GV WORM! Note - this is not the valid Norton Anti-Virus service which has the same file and is located in %ProgramFiles%\Norton AntiVirus. This one is located in %System%No
Video ProcessXNavapsvcc.exeAdded by the SPYBOT-CW WORM!No
Norton Service ProcessXnavapvc.exeAdded by the AGOBOT.GV BACKDOOR!No
NAV AgentYnavapw32.exeBackground scanning process for older versions of Norton AntiVirus which continuously detects and repairs viruses and other malwareYes
navapw32Ynavapw32.exeBackground scanning process for older versions of Norton AntiVirus which continuously detects and repairs viruses and other malwareYes
Norton AntiVirus AutoProtectYnavapw32.exeBackground scanning process for older versions of Norton AntiVirus which continuously detects and repairs viruses and other malwareNo
Norton Auto-ProtectYnavapw32.exeBackground scanning process for older versions of Norton AntiVirus which continuously detects and repairs viruses and other malwareNo
Corel ReminderNNAVBrowser.exeRegistration reminder for some Corel productsNo
NavRegReminderNNAVBrowser.exeRegistration reminderNo
ScanSoft PaperPort 7 Registration ReminderNNAVBrowser.EXE NavLoad.iniRegistration reminder for PaperPort version 7 from Scansoft (now Nuance)No
MSOfficeCfgXnavchk.exePremium rate adult content dialerNo
NAVCheckXnavchk.exePremium rate adult content dialerNo
QTSvcXnavchk.exePremium rate adult content diallerNo
SchedulerMgrXnavchk.exePremium rate adult content dialerNo
SystemServiceXnavchk.exePremium rate adult content diallerNo
System Information ManagerXNavcpe.exeAdded by the SDBOT-QB WORM!No
NaverAgentXNaverAgent.exeDetected by Malwarebytes Anti-Malware as Adware.K.NaverAgent. The file is located in %ProgramFiles%\naver\NaverAgentNo
navert.exeXnavert.exeDetected by Dr.Web as Trojan.Click2.51385No
Microsoft UpdatingXnavguard.exeAdded by the RBOT.HW WORM!No
NaviscopeUnaviscope.exeNaviscope is a multipurpose browser enhancement that can speed up Web searches, lock out cookies, examine HTML send/receive headers, provide single-click network diagnostics, and much moreNo
Microsoft UpdateXnavmgrd.exeAdded by the SDBOT.DP BACKDOOR!No
NAVMon32XNAVMon32.exEAdded by the WINKO.AO WORM!No
navp.exeXnavp.exeAdded by the AGOBOT-OE WORM!No
NavPassXNavPass.exeFree system for gaining access to and downloading from adult content web-sitesNo
Symantec Security Routine AddonXnavpaw.exeAdded by the AGOBOT-ES BACKDOOR!No
cpntmgcXnavpmc.exeAdded by the SIMCSS TROJAN!No
mslagentXnavpmc.exeSlagent adwareNo
NAV Auto ProtXnavprot1.exeAdded by the RBOT.ZAC WORM!No
Norton AutoProtectXnavprot32.exeAdded by the RBOT-UX WORM! Note - this is not a valid Symantec/Norton entryNo
NAV Auto ProtectXnavprotect.exeAdded by the RBOT.BKW WORM! Note - this is not a valid Norton AntiVirus product from SymantecNo
AVSTRTXnavpsrvc.exeAdded by the FORBOT-EF WORM!No
Symantec Security Routine Addon for Microsoft WindowsXnavpxaw32.exeAdded by the AGOBOT-GJ TROJAN!No
NAV Scan ServiceXNAVSCAN32.EXEAdded by the SDBOT.VG WORM!No
NAVSCAN32.EXEXNAVSCAN32.exeAdded by the SDBOT-DO WORM!No
NAVSCAN64.EXE /sXNAVSCAN64.exeAdded by the RBOT-T WORM!No
NAVSCANNER32XNAVSCANNER32.EXEAdded by the RBOT.QC WORM!No
Norton Antiviral ScannerXnavscnr.exeAdded by the DELBOT-K WORM!No
bootsecXNAVSSE.exeAdded by the FORBOT-CY WORM!No
NvCplDmnXNAVSVC.EXEAdded by an unidentified VIRUS, WORM or TROJAN!No
Norton SpySweeper AutoUpdateXnavsw.exeAdded by the FORBOT-AS WORM!No
Norton AntiVirus SysXNAVsys32.exeAdded by a variant of the WOOTBOT WORM!No
NAVtaskXNAVtask.exeAdded by the REMBOT-A BACKDOOR!No
MS UniXXnavupdate64.exeAdded by the RBOT.CRZ BACKDOOR!No
NAV Auto UpdatesXnavupdaters.exeAdded by the RBOT-UN WORM!No
NAV Auto UpdatesXnavupdaterx.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
Norton UpdaterXnavupdtr.exeAdded by the SDBOT.AXV WORM!No
NAVWatchXNAVWatcher.exeVX2.Transponder parasite updater/installer relatedNo
NAV Auto UpdatesXnavwindows.exeAdded by a variant of the SDBOT BACKDOOR!No
NAV_UpdateXNAV_Update.exeUnidentified WORM or TROJAN!No
nawadll32Xnawadll32.exeAdded by the SDBOT-ZI WORM!No
nawdll32Xnawdll32.exeAdded by the SDBOT-ZM WORM!No
xvihkdgoyXnaxjasb.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System%No
WinDefendXNB.exeDetected by Dr.Web as Trojan.MulDrop2.44757 and by Malwarebytes Anti-Malware as Backdoor.MessaNo
HelloworldXnb32ext2.exeDetected by Trend Micro as WORM_BOBAX.ADNo
RPCserv32gXNB32EXT2.EXEDetected by Trend Micro as WORM_BOBAX.ADNo
helloworldXnb32ext3.exeDetected by Trend Micro as WORM_MYTOB.JTNo
helloworld3Xnb32ext4.exeAdded by the RITDOOR.A WORM!No
NBAgentUNBAgent.exeCore task for Nero BackItUp version 4 which provides System Tray access and runs all backup jobs (to hard disk, Network, FTP, CD/DVD) for the files and folders that you specify to either a local folder or Nero Online Backup. Required if you have have any scheduled backups or use the Autobackup feature. Installed as part of both Nero BackItUp & Burn and Nero Multimedia Suite 10Yes
Nero BackItUpUNBAgent.exeCore task for Nero BackItUp version 4 which provides System Tray access and runs all backup jobs (to hard disk, Network, FTP, CD/DVD) for the files and folders that you specify to either a local folder or Nero Online Backup. Required if you have have any scheduled backups or use the Autobackup feature. Installed as part of both Nero BackItUp & Burn and Nero Multimedia Suite 10Yes
MicrosoftctfmonXnbb.exeDetected by Dr.Web as Trojan.DownLoad3.6216 and by Malwarebytes Anti-Malware as Trojan.AgentNo
NBCoreUNBCore.exeAutobackup feature of Nero BackItUp version 4 which runs in the background and backs up the files and folders that you specify to either a local folder or Nero Online Backup. If there are modifications or new files, Autobackup carries out a backup update automatically, replacing the existing backup with the current one. Installed as part of both the stand alone product and Nero 9 digital media suites (CD/DVD burning, authoring, etc)Yes
Nero BackItUpUNBCore.exeAutobackup feature of Nero BackItUp version 4 which runs in the background and backs up the files and folders that you specify to either a local folder or Nero Online Backup. If there are modifications or new files, Autobackup carries out a backup update automatically, replacing the existing backup with the current one. Installed as part of both the stand alone product and Nero 9 digital media suites (CD/DVD burning, authoring, etc)Yes
NBHGuiUNBHGui.exeSecurDisc support for the Nero InCD packet writing utility. "SecureDisc includes special protection properties, such as data integrity, rebuilding, encryption and duplication protection". If you don't use InCD or your optical drive doesn't support SecureDisc you can disable thisYes
Nero SecurDisc clientUNBHGui.exeSecurDisc support for the Nero InCD packet writing utility. "SecureDisc includes special protection properties, such as data integrity, rebuilding, encryption and duplication protection". If you don't use InCD or your optical drive doesn't support SecureDisc you can disable thisYes
SecurDiscUNBHGui.exeSecurDisc support for the Nero InCD packet writing utility. "SecureDisc includes special protection properties, such as data integrity, rebuilding, encryption and duplication protection". If you don't use InCD or your optical drive doesn't support SecureDisc you can disable thisYes
NBJUNBJ.exeScheduler for backup jobs using Nero BackItUp in earlier versions of Nero digital media suites (CD/DVD burning, authoring, etc). If no backup jobs are scheduled this entry will remain but it will not run at start-up. If you have any scheduled backup jobs and try disabling it by a means other than the program's own option (right-click on tray icon → Settings) it will re-instate itself on the next run of Nero BackItUpYes
Nero BackItUp SchedulerUNBJ.exeScheduler for backup jobs using Nero BackItUp in earlier versions of Nero digital media suites (CD/DVD burning, authoring, etc). If no backup jobs are scheduled this entry will remain but it will not run at start-up. If you have any scheduled backup jobs and try disabling it by a means other than the program's own option (right-click on tray icon → Settings) it will re-instate itself on the next run of Nero BackItUpYes
NbkCtrlUNbkCtrl.exeScheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see hereNo
NovaBackup * Tray ControlUNbkCtrl.exeScheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here. * represents the version numberNo
NBKeyScanUNBKeyScan.exeNero BackItUp versions 2 thru 4 support the "Push for backup" feature that's implemented on some external hard disks - which enables the user to start a predefined backup by pushing a button on the drive. NBKeyScan is used to scan the peripherals for compatible devices and - if such devices have been found - to communicate between Nero BackItUp and the external hard drive. Installed as part of both stand alone products and Nero digital media suites (CD/DVD burning, authoring, etc)Yes
Nero BackItUpUNBKeyScan.exeNero BackItUp versions 2 thru 4 support the "Push for backup" feature that's implemented on some external hard disks - which enables the user to start a predefined backup by pushing a button on the drive. NBKeyScan is used to scan the peripherals for compatible devices and - if such devices have been found - to communicate between Nero BackItUp and the external hard drive. Installed as part of both stand alone products and Nero digital media suites (CD/DVD burning, authoring, etc)Yes
NotebookManager?nbm.exeAssociated with Acer notebook PCs. What does it do and is it required?No
Timer SettingXNboot.exeDetected by McAfee as RDN/Generic.bfr!k and by Malwarebytes Anti-Malware as Backdoor.AgentNo
NB ProbeUNBProbe.exeMonitors the status of notebooks from ASUS - including CPU (speed, temperature and fan), disk and system informationNo
nbsessionXnbsystem.exeAdded by the DTR BACKDOOR!No
Netbios HelperXnbthlp.exeDetected by McAfee as PWS-Banker.yNo
msgsmgrXnbtsdump.exeDetected by Dr.Web as Trojan.MulDrop4.30998No
Windows Update 64Xnbupd64.exeDetected by Trend Micro as WORM_WOOTBOT.JB and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
nbustrce1D?nbustrce1D.exeDevice driver, possibly CD/DVD - what exactly is it and is it required in startup?No
NetworkControlXnc.exeNetworkControl ransomware firewall - not recommended, removal instructions hereNo
NCDNncd.exeNorton Change Directory - from the DOS days that allows the user to change directories on their machine without typing the complete pathNo
NetCruiser DialerUNCDialer.exeNetCruiser Dialer from NetCruiser Software. "An Internet dialer and connection monitor with features to launch applications when a connection is detected, dial and hangup at predefined times and automatic redialing of dropped connections"No
name_meXnCkmr.exeDetected by Dr.Web as Trojan.DownLoader7.19846 and by Malwarebytes Anti-Malware as Trojan.DownloaderNo
NCLaunchNNCLAUNCH.ExePart of SWF Studio from Northcode Inc. - an extension to Flash. Bundled when you create a self-installing screen-saver on Win2K/XPNo
Nokia Connection MonitorNNclConf.exeMonitors the infrared port, the serial ports and the Bluetooth for a Nokia phone connection. It is installed by the Nokia PC Suite (and Nokia PC Connectivity SDK), and the tray icon shows if a phone has been connected. If you have a conflict with another program, such as TV tuner card remote control monitor, you can disable it, and run only when needed. Available via a desktop shortcut or Start → Programs - not requiredNo
Srv RPCromXNClienti386.exeAdded by the WATSOON.A TROJAN!No
NclTrayNNclTray.exePart of Nokia PC Suite version 5 - which "is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one." Monitors ports to see if a phone has been connected and provides System Tray access to the Connection Manager (and other PC Suite components if a phone is connected). Available via the Control Panel as "Nokia Connection Manager"Yes
Nokia Status MonitorNNclTray.exePart of Nokia PC Suite version 5 - which "is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one." Monitors ports to see if a phone has been connected and provides System Tray access to the Connection Manager (and other PC Suite components if a phone is connected). Available via the Control Panel as "Nokia Connection Manager"Yes
Nokia Tray ApplicationNNclTray.exePart of Nokia PC Suite version 5 - which "is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one." Monitors ports to see if a phone has been connected and provides System Tray access to the Connection Manager (and other PC Suite components if a phone is connected). Available via the Control Panel as "Nokia Connection Manager"Yes
DeewooXncntnkwd.exeZenoSearch adware variantNo
NuTCSetupEnvironYncoeenv.exeUsed by the MKS Toolkit for Enterprise Developers product. NuTCracker is a Unix runtime environment for Windows, so disabling this would be unwise if you are using NuTCracker or any 3rd party package that is using it. Since you might not know what is actually using it it's probably best left aloneNo
NcpBudget?ncpbudgt.exeRelated to VPN client software from WatchGuard, Lancom, NCP, Astaro, D-Link and maybe others. What does it do and is it required?No
NcpMonitor?ncpmon.exeRelated to VPN client software from WatchGuard, Lancom, NCP, Astaro, D-Link and maybe others. What does it do and is it required?No
NcpPopup?ncppopup.exeRelated to VPN client software from WatchGuard, Lancom, NCP, Astaro, D-Link and maybe others. What does it do and is it required?No
Ncr3Uncrcore3.exeNetwork camera recording software for home/office security systems using wired or wireless Panasonic cameras that enables you to locally view, record and adjust the settings for the cameras - see hereNo
DCASS SUBLOADXncrvs.exeDetected by Trend Micro as WORM_RBOT.BHINo
*Intelli Mouse Pro Version 2.0B*Xncsjapi32.exeAdded by the BUZUS-O WORM!No
Intelli Mouse Pro Version 2.0BXncsjapi32.exeAdded by the BUZUS-O WORM!No
Nvidia Control PanelXncsvc32.exeAdded by an unidentified VIRUS, WORM or TROJAN!No
Nvidia Control PanelXncsvc33.exeDetected by Malwarebytes Anti-Malware as Trojan.Sdbot. The file is located in %System%No
NCSW ServerYNcsW.exeLockLink access control management software. LockLink 7.0 lets users seamlessly manage both offline and online access control solutions available from IR Security & SafetyNo
securwXNctrup.exeAdded by the NOPIR.A WORM!No
System ManagerXncvs32.exeAdded by a variant of the IRCBOT BACKDOOR!No
Norton Disk DoctorNNDD32.EXENorton Disk Doctor from older versions of Norton Utilities (either as a standalone product or as part of Norton SystemWorks) - which "diagnoses and repairs a variety of disk problems. It performs several tests, checking everything from the disk's partition table to its physical surface. If Norton Disk Doctor finds a problem, it notifies you before making repairs. If you check Automatically Fix Errors, Norton Disk Doctor makes the necessary repairs automatically"Yes
NDDEAGNT?NDDEAGNT.EXEWinNT default process. Network Dynamic Data Exchange (DDE) Agent, handles requests for network DDE servicesNo
Microsoft PCHealth32XNDDENB.exeAdded by the PWSYAHOO-A TROJAN!No
NET DEMONXndemon.exeAdded by the AGOBOT-LA WORM!No
Mirabilis ICQNNDetect.exeIf connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start → ProgramsNo
Windows Service AgentXndibbeu.exeAdded by the RBOT.XVD BACKDOOR!No
NDIS AdapterXndis.exeDetected by Trend Micro as WORM_SDBOT.VFNo
Win32 NDIS DriverXNdistcp.exeAdded by the WOOTBOT.EU WORM!No
Win32 NDISXNdiswin.exeDetected by Trend Micro as WORM_RBOT.AMGNo
NDL StartXNDL.exeDetected by Malwarebytes Anti-Malware as Trojan.Keylogger. The file is located in %CommonAppData%\HGGGXENo
Video Multimedia DriverXndrives32.exeAdded by the RBOT-DK WORM!No
NDrvXNDrv.exePurityScan adwareNo
Windows Security UpdateXndsass.exeAdded by the RBOT.ESM BACKDOOR!No
NDSTrayUNDSTray.exeConfigFree Tray on a Toshiba laptop. Tray utility for their network switching application which permits switching network devices and settings with a click on the tray icon. While it is not required, for people who span multiple networks and want an easy way to go from wired to wireless and change addresses and other network settings, it's a must haveNo
NDSTray.exeUNDSTray.exeConfigFree Tray on a Toshiba laptop. Tray utility for their network switching application which permits switching network devices and settings with a click on the tray icon. While it is not required, for people who span multiple networks and want an easy way to go from wired to wireless and change addresses and other network settings, it's a must haveNo
Microsoft Windows UpdateXndsuhyz.exeAdded by the RBOT-GVG WORM!No
Compaq Services DriversXndt32.exeAdded by the RBOT.CQZ WORM!No
NdtstatXNdtstat.exeAdded by a variant of the BANLOAD family of TROJANS!No
NDW StartXNDW.exeDetected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Trojan.STRGenNo
[empty]Xne.exeAdded by the IRCBOT-ZL TROJAN! Note - has a blank entry under the Startup Item/Name fieldNo
WINDOWS SYSTEMXnec.exeAdded by the MYTOB-L WORM and variants!No
NecbarNNecbar.exeNec Assistant; Ark's Navigator, a graphical interface for NEC computersNo
NECMFKYnecmfk.exeNEC wireless keyboard driverNo
NecutrayUNecutray.exeDriver for external USB storage devices (hard drives, flsh disks, etc)No
nedpro0xzXnedpro0xz.exeDetected by McAfee as W32/Hamweq.worm.av and by Malwarebytes Anti-Malware as Trojan.DownloaderNo
SystemUpdateXNegdo.exeAdded by the CULLER-C WORM!No
nemu.exeXnemu.exeDetected by Kaspersky as Virus.Win32.Virut.ce and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%No
Price PatrolNneo.exePrice Patrol by Half.com - internet shopping companion for finding the best on-line pricesNo
MOJNPluginSrIvcsXneomonap23.exeAdded by the SPYBOT.MJ WORM!No
neoprotectXneoprotect.exeNeoProtect rogue security software - not recommended, removal instructions hereNo
neosXneos.exeAdded by the BDOORB-FAM TROJAN!No
neoDVDplus5NneoTasks.exeneoDVDplus video editing and DVD authoring utility from MedioStream. Superseded by neoDVDNo
neoTasksNneoTasks.exeneoDVDplus video editing and DVD authoring utility from MedioStream. Superseded by neoDVDNo
Nepsa0m1PXNepsa0m1P.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%No
neqprvfy.exe?neqprvfy.exeAppears to be related to the downloading of some application - possibly verifying updates?No
WinXPServiceXnero.exeAdded by the IRCFLOOD.AG BACKDOOR! Note - this is not the Nero CD/DVD burning software by Ahead Software which is normally located in %ProgramFiles%\Ahead\Nero. This file is found in %System%No
editsunjavaXnerO3.exeDetected by McAfee as BackDoor-CEP.gen.aj and by Malwarebytes Anti-Malware as Backdoor.AgentNo
Nero 7Xnero32.exeDetected by McAfee as RDN/Generic Dropper!d and by Malwarebytes Anti-Malware as Backdoor.Messa. Note - this is not a valid Nero processNo
NeroAutoStartClientXNeroASM.exeDetected by Trend Micro as WORM_AGOBOT.VGNo
Ahead Software Gmbh NeroCheckNNeroCheck.exeIncluded with some Nero digital media suites (CD/DVD burning, authoring, etc). Looks for known driver conflicts with Nero software and lists these in a log file to help the user determine what may be causing a problem. This is therefore not required if the Nero software is working correctlyYes
Nero AG NeroCheckNNeroCheck.exeIncluded with some Nero digital media suites (CD/DVD burning, authoring, etc). Looks for known driver conflicts with Nero software and lists these in a log file to help the user determine what may be causing a problem. This is therefore not required if the Nero software is working correctlyYes
Nero CheckerXnerocheck.exeAdded by the PROXY-X TROJAN! Note - this is not the legitimate file of the same name from the Nero CD/DVD burning software which is usually located in %System%. This one is located in %Windir%No
NeroCheckNNeroCheck.exeIncluded with some Nero digital media suites (CD/DVD burning, authoring, etc). Looks for known driver conflicts with Nero software and lists these in a log file to help the user determine what may be causing a problem. This is therefore not required if the Nero software is working correctlyYes
NeroFilterCheckNNeroCheck.exeIncluded with some Nero digital media suites (CD/DVD burning, authoring, etc). Looks for known driver conflicts with Nero software and lists these in a log file to help the user determine what may be causing a problem. This is therefore not required if the Nero software is working correctlyYes
ShedulerXnerocheck.exeAdded by the TACTSLAY.B TROJAN! Note - this is not the legitmate file of the same name from the Nero CD/DVD burning software which is usually located in %System%No
NeroFilXNeroFil.EXEAdded by the RBOT.EAM BACKDOOR!No
NeroCheckXNeroFilter.EXEAdded by the RBOT.DAO WORM!No
NeroLoaderXNeroLoader.exeDetected by Sophos as Troj/Bancban-EJNo
Nero MediaHomeUNeroMediaHome.exeNero MediaHome is a UPnP AV (Audio/Video) Media Server. This allows your computer to link up you other home entertainment electronic devices (ie, televisions, stereos) to create a unified media centre, sharing media files such as MP3's and videosYes
Nero MediaHome 4UNeroMediaHome.exeNero MediaHome is a UPnP AV (Audio/Video) Media Server. This allows your computer to link up you other home entertainment electronic devices (ie, televisions, stereos) to create a unified media centre, sharing media files such as MP3's and videosYes
NeroMediaHomeUNeroMediaHome.exeNero MediaHome is a UPnP AV (Audio/Video) Media Server. This allows your computer to link up you other home entertainment electronic devices (ie, televisions, stereos) to create a unified media centre, sharing media files such as MP3's and videosYes
NeroMediaHomeXNeroUpgrade.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %System%No
SERV PacK2Xnerx.exeAdded by the SDBOT-ACP WORM!No
Microsoft Neser ExperienceXnese.exeAdded by the RBOT-YH WORM!No
MSDNXnese.exeAdded by the SDBOT.AHY WORM!No
Net**.exe [* = random char]XNet**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this logNo
Net**32.exe [* = random char]XNet**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this logNo
system32XNeT-BoT.exeAdded by the AGOBOT-LJ WORM!No
d3b723be6cda7831128c70a6114bebc5Xnet.exeDetected by Dr.Web as Trojan.DownLoader7.13092 and by Malwarebytes Anti-Malware as Trojan.MSILNo
HKCUXnet.exeDetected by Kaspersky as Backdoor.Win32.IRCBot.rcz and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %ProgramFiles%\NetMeetingNo
HKLMXnet.exeDetected by Kaspersky as Backdoor.Win32.IRCBot.rcz and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %ProgramFiles%\NetMeetingNo
PoliciesXnet.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System%\installNo
PoliciesXnet.exeDetected by Kaspersky as Backdoor.Win32.IRCBot.rcz and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %ProgramFiles%\NetMeetingNo
PoliciesXnet.exeDetected by Kaspersky as Trojan.Win32.Buzus.emdc and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Windir%\NetNo
netXnet.netAdded by the MDROP-CIF TROJAN!No
net24E0EFEEsecurityXnet24E0EFEEsecurity.cplDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
N2PTrayUNet2fone.exeAn Internet telephony application. Needed only if you have an account at Net2Phone, IncNo
Net4SwitchUNet4Switch.exeASUS Net4Switch utility as provided on their range of notebooks - which "helps users to quickly configure the notebook PC's network settings and easily switch between different network environments. A wizard guides users to create and edit configuration settings as well as diagnose problems in the settings for timely connection"No
netLoaderXnet64.exeDetected by McAfee as RDN/Generic.dx!a and by Malwarebytes Anti-Malware as Trojan.Agent.GenNo
net905BF052securityXnet905BF052security.cplDetected by Malwarebytes Anti-Malware as Trojan.Agent.CPL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
Microsoft Update 32Xneta.exeAdded by the RBOT-AMI WORM!No
NetAcceleratorUNetAccel.exeNetAccelerator is a "software utility that optimizes your internet access up to 1200% faster!. NetAccelerator speeds all modems allowing you to download faster, browse faster, surf faster!. Only required if you find it helps improve your performanceNo
Net AcceleratorUNetAccelerator.exeRizal NetAccelerator - "Optimizing Dial-Up, Lan, Cable, DSL, and Satellite connections do you want to speed up your Internet access up to 200% - 300% ???". Only required if you find it helps improve your performanceNo
NetAdm7XNETADM7.EXEAdded by the BANCOS.F TROJAN!No
InetapiXNetapi.exeAdded by the NETDEVIL.14 BACKDOOR!No
NetapiXNetapi.exeAdded by the NETDEVIL.14 BACKDOOR!No
Microsoft System CheckupXnetapi32.exeAdded by the DONK-E WORM!No
netapi32Xnetapi32.exeAdded by unidentified malware. The file is located in %System%No
NetAppelNNetAppel.exeNetAppel - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular SkypeYes
NetbeansXnetbeans.exeAdded by the DELBOT-R WORM!No
NetBioy ClientXnetbioy.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
00notify33?NetBrowser.exePart of Best Network Security, 1st Network Admin and Corporate Network Security (and maybe others) - network-based password-protected security software that lets you impose access restrictions to all your PC workstations you have in your corporate network to stop users from tampering with them. The exact purpose of this startup entry is unknown at presentYes
NetBrowser?NetBrowser.exePart of Best Network Security, 1st Network Admin and Corporate Network Security (and maybe others) - network-based password-protected security software that lets you impose access restrictions to all your PC workstations you have in your corporate network to stop users from tampering with them. The exact purpose of this startup entry is unknown at presentYes
NetBrowser.exe?NetBrowser.exePart of Best Network Security, 1st Network Admin and Corporate Network Security (and maybe others) - network-based password-protected security software that lets you impose access restrictions to all your PC workstations you have in your corporate network to stop users from tampering with them. The exact purpose of this startup entry is unknown at presentYes
bobyXnetburn.scrAdded by the BANCBAN-OX TROJAN!No
Paradyne ADSL Network Driver V2.3Xnetcfgx32.exeAdded by the DELF-EYS TROJAN!No
Netline UserNnetchk.exeNetline supplies internet related products and services and this program identifies user ID and IP information. Found installed along with the Falcon 4 game, for exampleNo
Windows NetworksXnetcog.exeDetected by Trend Micro as WORM_MYTOB.FHNo
netconfigXnetconfig.exeAdded by the NETWARE TROJAN!No
Networks ConfiguratorXNetConfs.exeAdded by the RBOT-OX WORM!No
vtmesysXnetcxcfm.exeAdded by a variant of the RBOT-GNA WORM!No
Microsoft Network Daemon for Win32Xnetd32.exeAdded by the SDBOT.R TROJAN!No
MicrosoftNetwork Daemon for Win32XNETD32.EXEAdded by the RANDEX.F WORM!No
MS_NETD_WIN32Xnetd32.exeAdded by the RANDEX.F WORM!No
load32Xnetda.exeAdded by the NIBU.E TROJAN!No
netdaemonXnetdaemon /vMalware designed to "kill" a number of antispyware applications (SpyBot, Giant, SpyDoctor, SpySweeper, SpyHunter, Anvir, WinPatrol, and more)No
xload32Xnetdd.exeAdded by the NETSPY TROJAN!No
[random name]Xnetdde.exePurityScan adware. Do not confuse with the legitimate Network DDE - DDE Communication (netdde.exe) process which is always located in %System% and should not figure in Msconfig/Startup!No
IusageNnetdet.exeInternet Usage Monitor - utility to calculate the cost and time on the internet via dial-upNo
NetWork Device SwitchUNetDevSW.exeToshiba laptops with built-in Wi-Fi. Allows switching between Wi-Fi and internal ethernet. Only necessary if you have regular need to switch back and forward between these network interfaces. Located in Startup folder so make own shortcut to it and disable if not really necessaryNo
4684735485910Xnetdll32.exeAdded by the SDBOT-DEV WORM!No
Netdll32Xnetdll32.exeAdded by the CRYPTER.A TROJAN!No
NetdllexXnetdllex.exeAdded by the CRYPTER.A TROJAN!No
netfilt4Xnetfilt4.exeDetected by Trend Micro as TROJ_PROXY.FXNo
MSDRVXNetFilter.exeAdded by the INTERRUPDATE TROJAN!No
NETFP32.EXEXNETFP32.EXEAdded by the AGENT.CD TROJAN!No
netfxupdate?netfxupdate.exeWould appear to be a valid Microsoft .NET file (see here) but other sources suggest it could be a trojanNo
NetFxUpdate_v1.0.3705?netfxupdate.exeWould appear to be a valid Microsoft .NET file (see here) but other sources suggest it could be a trojanNo
NETGEARGenieNNETGEARGenie.exeNETGEARGenie network management utilityNo
NetGuardUNetGuard.exeFBM Software ZeroSpyware 2004 spyware detector and remover - real time monitorNo
Windows System ConfigurationXnether.exeAdded by the OPANKI-AB WORM!No
ASDPLUGINXnetherlands.exeAsdPlug premium rate adult content dialerNo
HELPERXNetherlands.exeAsdPlug premium rate adult content dialer variantNo
NethostsXNethosts#.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.Gen - where ~ represents a number and the file is located in %AppData%No
hdlpscomXnetilxgn.exeAdded by the RBOT-FXD WORM!No
Microsoft WinUpdateXnetip.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor. The file is located in %System%No
SystemMap32XNetisp32.vbsAdded by the REDIST.C WORM!No
NetworkKeyXnetkey.exeAdded by the IRCBOT-AJ TROJAN!No
Net Functions LibraryXNetlib.exeAdded by the AGOBOT.AGY WORM!No
NetlibXNetlib.exeAdded by a variant of the TOXBOT WORM!No
NetlimiterUNetlimiter.exeNetlimiter - "An internet traffic control tool to monitor applications which access the internet and actively control their internet traffic. Use it o set (download/upload) speed limits for applications or even single connection. NetLimiter also allows you to share your internet connection bandwidth among all applications running on your PC"No
netlimiterXnetlimiter.vbsDetected by Malwarebytes Anti-Malware as Trojan.Agent.VBS. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
NetLinkXnetlink32.exeAdded by the GAOBOT.WO WORM!No
HKCDCXnetlog.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.RGen. The file is located in %AppData%\MicrosoftNo
HKLMCXnetlog.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.RGen. The file is located in %AppData%\MicrosoftNo
policiesXnetlog.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.RGen. The file is located in %AppData%\MicrosoftNo
Microsoft System CheckupXnetlogin32.exeAdded by the SDBOT-GN BACKDOOR!No
Netlog Music ToolUNetlogMusicTool.exeMusic tool for Netlog - "an online platform where users can keep in touch with and extend their social network." Automatically publishes your playlist on your profile, allowing your friends to see what your listening too and you to search for others listening to the same music. No longer appears to be available to downloadNo
vtmesysXnetlprto.exeAdded by the RBOT-GNA WORM!No
1CmailS?NETMAIL.EXE??No
Netman_Server.exeXNetman_Server.exeDetected by McAfee as RDN/Generic.bfr!cp and by Malwarebytes Anti-Malware as Backdoor.AgentNo
{29123221-3AF8-488c-85DE-6B3EC59E8074}Xnetmedia.exeNetMedia adwareNo
Microsoft NetMeeting Associates, Inc.XNetMeeting.exeAdded by the LOVGATE.AB WORM!No
C:\Program Files\NetMeter\NetMeter.exeUNetMeter.exe"Net Meter is a small, customizable network bandwidth monitoring program for Win9x/Me/NT4/2K/XP. NetMeter is and will always stay freeware. The program has been tested extensively on Win2K/XP, but it should work just as well on all other Win32 operating systems"No
NetMeterUNetMeter.exe"Net Meter is a small, customizable network bandwidth monitoring program for Win9x/Me/NT4/2K/XP. NetMeter is and will always stay freeware. The program has been tested extensively on Win2K/XP, but it should work just as well on all other Win32 operating systems"No
NetMonXnetmon.exeAdded by the MIMAIL.M WORM!No
NetmonwXNetmonw.exeAdded by the BDOOR-FX BACKDOOR!No
netmsgUnetmsg.exeNet_Message is a small tool to send messages across the network, using the Windows Messenger Service, so there is no client install required to receive the messages. It has a number of other features as wellNo
OpenHardwareMonitorXnetnvm32.exeDetected by Malwarebytes Anti-Malware as Trojan.FakeMS. The file is located in %System%No
Network ODBCXNetODBC.exeDetected by Symantec as W32.SnabanNo
netpc32.exeXnetpc32.exeMalware, probably a CoolWebSearch parasite variantNo
NetPerSecNNetPerSec.exeNetPerSec - measures the real-time speed of your Internet connectionNo
NliaClientUNetpia.exeNetpia NLIA System - "In the existing Internet address system, the Domain Name System (DNS) layer runs on the IP address layer. In the NLIA system, however, the upper layer is implemented on DNS"No
NetprotocolXnetprotocol.exeDetected by Kaspersky as Trojan.Win32.Jorik.Buterat.dp and by Malwarebytes Anti-Malware as Trojan.AgentNo
NetPumperXNetPumperIEProxy.exeNetPumper download manager - bundles Cydoor and SaveNow adware, see hereNo
PremeterUNetratings.exeNetRatings Premeter spywareNo
Help Temp FilesXnetreg.exeAdded by the FORBOT-EM WORM!No
Netropa Internet ReceiverXNetropa.exeNetropa Internet Receiver. Shows a scrolling bar with the news. Major resource hog and flagged as spywareNo
NetRunUNetRun.exeNetRun - will 'RUN' a 'List' of programs only when a internet connection is detected, and close/kill the same 'List' when the connection is lostNo
Microsoft Synchronization ManagerXnetscape.exeDetected by Trend Micro as WORM_SDBOT.RJNo
Netscape MessengerNNETSCAPE.EXEIn Netscape 6 (I know for sure with 6.2.1, maybe with 6.0) Netscape.exe is the main executable file for Netscape Navigator, Netscape Mail and News, and Netscape Messenger (the new name for the embedded AIM, no doubt to make it sound like Windows Messenger, the XP version of MSN Messenger). Basically, netscape.exe can be more than just Netscape Messenger, and Messenger can be more then just AIM in disguise, depending on the version of Netscape installedNo
Mozilla Quick LaunchNNetscp6.exeNetscape 6 and Mozilla browsersNo
Netscp6NNetscp6.exeNetscape 6No
Messenger ProtocolXnetsender.exeAdded by the SDBOT-ACC WORM!No
SystemNetworkXNETSERV.EXEAdded by the NETCONTROL VIRUS!No
Akamai NetSession InterfaceUnetsession_win.exeAkamai download manager as used by companies such as Adobe and Corel to download and install their online products. Required for the download to start and complete but once finished it can be disabled and re-instated at a later date if neededNo
BsqxXnetsfigx.exeAdded by the AUTORUN-BDL WORM!No
LisaXnetsfigx.exeAdded by the AUTORUN-BDL WORM!No
Networks ControlerXNetsis.exeDetected by Sophos as W32/Rbot-NGNo
MicrosoftXnetsrv.exeAdded by the RBOT-GOS WORM!No
NET protection systemXnetst.exeDetected by GFI as Backdoor.Rizo.A. The file is located in %System%\ComNo
nstatXnetstat.exeAdult content diallerNo
Win32.Trojan.DownloaderXnetstat2.exeAdded by the PAINTER TROJAN!No
NvCplScanXnetstat32.exeAdded by the SDBOT.BRL WORM!No
Mozilla Firebird v0.8 Internet BrowserXnetstats.exeAdded by the IRCBOT.MC BACKDOOR!No
MSNXnetstats.exeAdded by the IRCBOT.UXP WORM!No
IPv6 STUN ServiceXnetstun.exeAdded by a variant of the SDBOT BACKDOOR!No
Optimum OnlineXNetsurf.exeOptimumOnline ISP software related spyware - displays advertising popups and collects information about user activityNo
netsv32Xnetsv32.exeAdded by the SDBOT-PX WORM!No
Network ServicesXnetsvacs.exeAdded by the GAOBOT.AIS WORM!No
Internet ServicesXNetsvc.exeAdded by the MYTOB.MN WORM!No
Network Service ManagerXnetsvc.exeAdded by a variant of the AGOBOT WORM!No
Network ServicesXnetsvc.exeDetected by Trend Micro as WORM_AGOBOT.MLNo
Run Services as ApplicationXnetsvc.exeAdded by the DLOADER-NY TROJAN!No
Services AdministratorXnetsvc.exeAdded by the DLOADER-NY TROJAN!No
Spooler SubSystem ApplicationXnetsvc.exeAdded by the DLOADER-NY TROJAN!No
Tcp Application ManagerXnetsvc.exeAdded by the DLOADER-NY TROJAN!No
Windows .Net ManagerXnetsvc.exeAdded by the DLOADER-NY TROJAN!No
Windows Local ServicesXnetsvc.exeAdded by the DLOADER-NY TROJAN!No
Windows Service ManagerXnetsvc.exeAdded by the DLOADER-NY TROJAN!No
Windows Web ServicesXnetsvc.exeAdded by the DLOADER-NY TROJAN!No
Video ProcessXnetsvcs.exeDetected by Trend Micro as WORM_AGOBOT.LHNo
Google Web ServicesXnetsvcss.exeDetected by Dr.Web as Trojan.DownLoader2.17374 and by Malwarebytes Anti-Malware as Worm.AgentNo
winsock2Xnetsvr.exeDetected by Trend Micro as WORM_AGOBOT.LYNo
NetSwitcher Tray ApplicationUNetSwTray.exe"NetSwitcher is a great tool for mobile computer users. If you've ever had to change your network settings every time you sit down at a client's site or fumble with your IP address configuration every time you plug into your home network, NetSwitcher is the tool for you"No
NetSwitcher Tray ApplicationUNETSWT~1.EXE"NetSwitcher is a great tool for mobile computer users. If you've ever had to change your network settings every time you sit down at a client's site or fumble with your IP address configuration every time you plug into your home network, NetSwitcher is the tool for you"No
RSyncXnetsync.exeDetected by Symantec as Spyware.SafeSurfingNo
Windows Netsystem LayerXNetsystem.exeDetected by Trend Micro as WORM_RBOT.BEINo
NettGain2000 VerifierYNettGain2000 Verifier.exePart of the Starband satellite client that attempts to optimize your satellite connection to increase speedNo
NetTimeUNETTIME.EXEFrom a visitor - "This is the executable for NetTime. It is started from the registry when you check the box to start at startup. NetTime allows you to synchronize your computers' clock with a server on your local net or the internet using any of several protocols, e.g. NTP."No
NetTurboUnetturbo.exeNetTurbo from SharewareOnline.com. "Accelerate Your Internet Connections by up to 600%". If you find it helps your connectivity leave it enabledNo
netupdate32Xnetupdate32.exeAdded by the RBOT-GQZ WORM!No
ChckupXNetverchk.exeCovert Sys Exec malware variantNo
Microsoft Internel CorporatXnetvhost.exeAdded by a variant of the IRCBOT BACKDOOR!No
netviewXnetview.exeAdded by the BIFROSE.L BACKDOOR!No
ShellRunXnetview.exeDetected by Dr.Web as Trojan.MulDrop3.18306 and by Malwarebytes Anti-Malware as Trojan.AgentNo
FASTTRACKNETVISIONXNETVISION.exeDialCar-Z premium rate dialerNo
ModemOnHoldUnetWaiting.exeNetWaiting/Modem-on-Hold - allows you to place your Internet connection on hold while you take a voice call (if Call Waiting is supported by your phone company). See here for more informationNo
NetWatch32Xnetwatch.exeAdded by the MIMAIL.C WORM!No
NetworkXnetwin.exeAdded by the SILLYFDC-CG WORM!No
Win Net Wks32Xnetwks32.exeDetected by Trend Micro as WORM_RBOT.AANo
Network controllerXNetwork controller.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%No
Microsoft Update 32Xnetwork.exeAdded by the RBOT-ARZ WORM!No
NETWORK.EXEXNETWORK.EXEAdded by the DELF-GM TROJAN!No
NetworkClientXNetworkClient.exeAdded by the LEMUR WORM!No
Windows ServicesXNetworkDriver32.exeDetected by Sophos as W32/Rbot-ACR and by Malwarebytes Anti-Malware as Backdoor.Agent.GenNo
Windows ServicesXNetworkDrivers.exeDetected by Sophos as W32/Sdbot-YO and by Malwarebytes Anti-Malware as Backdoor.Agent.GenNo
Microsoft Network NeighbourhoodXnetworknbh.exeAdded by the RBOT.DMN WORM!No
Microsoft NetworkXNetworksystem.exeAdded by the SDBOT-AAI WORM!No
Microsoft xpsp2XNetworksystem.exeAdded by a variant of W32/Sdbot.wormNo
NetWorxNnetworx.exeNetWorx from SoftPerfect Research - "is a simple and free, yet powerful tool that helps you objectively evaluate your bandwidth situation. You can use it to collect bandwidth usage data and measure the speed of your Internet or any other network connection"No
Network Sharing CenterXnetwrkcnt .exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Temp%No
WinSigXNetXP.exeAdded by the BANKER-FN TROJAN!No
XpnetXNetXp.exeAdded by the BANCBAN-AT TROJAN!No
Windows Media UpgradeXNeUpgrade.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
NeuroMedia(IESpeaker)XNeuroMedia.exePart of an older freeware version of IESpeaker - a program that allows you to listen to web pages. NeuroMedia.exe only downloads advertisments. Not included in the paid-for version currently availableNo
QffqqftXnevat.exeDetected by Trend Micro as TROJ_DROPPER.CRNo
2256a916c776d4838169e5d1ff3b1f29XNew Microsoft Word Document.exeDetected by Dr.Web as Trojan.DownLoader6.53733 and by Malwarebytes Anti-Malware as Trojan.DropperNo
VBC.EXEXNew.exeDetected by McAfee as Generic.dx!bh3v and by Malwarebytes Anti-Malware as Backdoor.Messa.GenNo
New2CleanXNew2CleanLaunch.exeNew2Clean rogue security software - not recommended, removal instructions hereNo
[various names]Xnew32.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
Onet.pl AutoUpdate?NewAutoUpdate.exeRelated to the Onet.pl Polish web portalNo
Ci ServsXnewbin.exeAdded by the RIMECUD-BC TROJAN!No
[various names]Xnewbreed.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
newcontr8nd7Xnewcont8rnd7.exeDetected by McAfee as W32/Pinkslipbot.gen.be and by Malwarebytes Anti-Malware as Trojan.MPGenNo
oaiyhlyvXnewdevi.exeAdded by the AGENT-QTM TROJAN!No
Microsoft Windows DLL Services ConfigurationXnewdll.exeAdded by the SDBOT-ZR WORM!No
Microsoft Windows DLL Services ConfigurationXnewdll2.exeAdded by the SDBOT-ABD WORM!No
newdotnet.exeXnewdotnet.exeDetected by McAfee as Generic VBNo
newframework.exeXnewframework.exeDetected by McAfee as Generic VBNo
NewFrnXnewfrn.exeAdded by the ACTUX.A TROJAN!No
newlockUnewlock.exePart of Access Manager, 1st Security Agent, Security Administrator and PC Security Tweaker (and maybe others) - which which let you control which users are allowed to access your PC and the level of access each user may have. You can choose to tweak access to lots of Control Panel applet functions, including Display, Network, Passwords, Printers, System, Add/Remove Programs, etc. For more details please see the "00saskda" or "zzsecagent"Yes
newlock.exeUnewlock.exePart of Access Manager, 1st Security Agent, Security Administrator and PC Security Tweaker (and maybe others) - which which let you control which users are allowed to access your PC and the level of access each user may have. You can choose to tweak access to lots of Control Panel applet functions, including Display, Network, Passwords, Printers, System, Add/Remove Programs, etc. For more details please see the "00saskda" or "zzsecagent" entriesYes
zzsecagentUnewlock.exe login shutdownPart of Access Manager, 1st Security Agent, Security Administrator and PC Security Tweaker (and maybe others) - which which let you control which users are allowed to access your PC and the level of access each user may have. You can choose to tweak access to lots of Control Panel applet functions, including Display, Network, Passwords, Printers, System, Add/Remove Programs, etc. This entry is enabled if you select to start the Screen Lock feature when booting via Restrictions → Common Restrictions → Boot → Always Check Password on BootYes
00saskda?newlock.exe saskdaPart of Access Manager, 1st Security Agent, Security Administrator and PC Security Tweaker (and maybe others) - which let you control which users are allowed to access your PC and the level of access each user may have. You can choose to tweak access to lots of Control Panel applet functions, including Display, Network, Passwords, Printers, System, Add/Remove Programs, etc. The exact purpose of this startup entry is unknown at present but it appears to be related to the "Screen Lock" featureYes
DivXCodecXNEWMAIL.exeAdded by the DELF-RQ BACKDOOR!No
SystemSv12Xnewmaxxsv234.exeAdded by the TIBS-TS TROJAN!No
AutoStart PC StudioNNewPCStudio.exeSAMSUNG New PC Studio - "is the application to organize the contents between Samsung mobile and PC. NPS provides you with convenient access to your device, data management via easy backup and sync, and powerful multimedia features". This allows you (amongst other options) to backup your devices contents to your PC, use it to connect to the internet, transfer files and synchronize contacts, etc. Available from the start menuYes
New PC StudioNNewPCStudio.exeSAMSUNG New PC Studio - "is the application to organize the contents between Samsung mobile and PC. NPS provides you with convenient access to your device, data management via easy backup and sync, and powerful multimedia features". This allows you (amongst other options) to backup your devices contents to your PC, use it to connect to the internet, transfer files and synchronize contacts, etc. Available from the start menuYes
NewPCStudioNNewPCStudio.exeSAMSUNG New PC Studio - "is the application to organize the contents between Samsung mobile and PC. NPS provides you with convenient access to your device, data management via easy backup and sync, and powerful multimedia features". This allows you (amongst other options) to backup your devices contents to your PC, use it to connect to the internet, transfer files and synchronize contacts, etc. Available from the start menuYes
popuppersXnewpop63.exeMedload adwareNo
newprotectXnewprotect_up.exeNewProtect rogue security software - not recommended, removal instructions hereNo
NewsalrtNNEWSALRT.EXEMSNBC News system tray utility to alert you to new newsNo
newsfeed12Xnewsd.exeDetected by Trend Micro as TROJ_AGENT.MXNo
supernews12Xnewsd32.exeAdware, also detected as the DLOADER-JN TROJAN!No
MySoftware NewsFlashNNewsflsh.exeRuns in your task bar and receives alerts and release information on MySoftware products from AvenquestNo
Newsgroup lptt01Xnewsgroup.exeRapidBlaster variant (in a "newsgroup" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove itNo
Newsgroup ml097eXnewsgroup.exeRapidBlaster variant (in a "newsgroup" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove itNo
InstallProviderXnewsoftware2007install.exePart of WinAntiVirusPro 2007 and Privacy Protector rogue security software (and possibly others) - not recommendedNo
NewsUpdNnewsupd.exeFor Creative Soundblaster Live! series soundcards. System tray application for News updates. Available via Start → Programs. Also spyware - see here.No
NewtonKnowsUpdXNewtKnow.exe [path] NewtnUpd.dll,runkeyNewtonKnows spyware. Both files are located in %ProgramFiles%\Newton KnowsNo
newupelevmdsXnewupelevmds.exeDetected by Malwarebytes Anti-Malware as Adware.Kraddare. The file is located in %ProgramFiles%\newupelevNo
HELPERXnew_zealand.exeAsdPlug premium rate adult content dialer variantNo
NexXnex.exeAdded by the AGENT-FPQ TROJAN!No
Nexus RadioNNexus Radio.exeNexus Radio by Talam Group, LLC - "is a free internet radio service that allows members to listen to music, and create unique personal profiles in order to communicate with other Nexus Radio members"No
NexusUNexus.exeNexus Dock by Winstep - "is a FREE professional dock for Windows. With Nexus, your most frequently used applications are only a mouse click away - and Nexus turns working with your computer into a fun and exciting experience"No
HKCUXnfconfig.exeDetected by Malwarebytes Anti-Malware as Trojan.VBKrypt. The file is located in %Windir%\installNo
HKLMXnfconfig.exeDetected by Malwarebytes Anti-Malware as Trojan.VBKrypt. The file is located in %Windir%\installNo
PoliciesXnfconfig.exeDetected by Malwarebytes Anti-Malware as Trojan.VBKrypt. The file is located in %Windir%\installNo
NfoXnfomon.exePromulGate adwareNo
NGClientUngctw32.exeSymantec Ghost Server software - needed for a "a Ghost multicast" (transfer images to multiple machines). Can be launched manuallyNo
Windows Global InitXngpsvc.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
ngpw36Xngpw36.exeAdBlaster adwareNo
Norton GProtectXngrfn.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
NGServerNngserver.exeSymantec/Norton Ghost Console serviceNo
nHancerUnHancer.exeSystem Tray access to nHancer which is an advanced control panel and profile editor for NVIDIA graphic cards - offering enhanced features above those available via the standard NVIDIA control panel such as additional Anti-Aliasing and Anisotropic Filtering modesYes
NotebookHardwareControlUnhc.exe"With Notebook Hardware Control you can easily control the hardware components of your Notebook"No
lMKuOKzbgaiwaEB_RwVlzLCjHAXNIamMWNHdGknyQ.exeDetected by Sophos as Troj/Ranbyus-I and by Malwarebytes Anti-Malware as Trojan.AgentNo
WDNS SYSTEMXnibie.exeAdded by the MYTOB-BY WORM!No
WINDOWS SYSTEMXnibie.exeAdded by the MYTOB-BY WORM!No
WinXP CentOS DriverXnicloader.exeDetected by Trend Micro as WORM_AGOBOT.ALFNo
nieguideplusXnieguideup.exeDetected by Malwarebytes Anti-Malware as Adware.K.IEGuide. The file is located in %ProgramFiles%\nieguideplusNo
NetMeterUNielsenOnline.exeNeilsen//NetRatings NetMeter market research software - provides "the industry's global standard for Internet and digital media measurement and analysis, offering technology-driven Internet information solutions for media, advertising, ecommerce and financial companies"No
NielsenOnlineUNielsenOnline.exeNeilsen//NetRatings NetSight market research software - provides "the industry's global standard for Internet and digital media measurement and analysis, offering technology-driven Internet information solutions for media, advertising, ecommerce and financial companies"No
CostAwareUniIPCApp.exeNetInternals CostAware - download quota measuring toolNo
Nike+ ConnectNNike+ Connect daemon.exeRelated to the Nike+ range of running accessories such as the Nike+ SportBandNo
Nike+ UtilityNNike+ Utility.exeRelated to the Nike+ range of running accessories such as the Nike+ SportBandNo
nikLausXnikLaus.exeAdded by the NIKLAS WORM!No
Net-It LauncherNNILaunch.exeNet-It - web publishing softwareNo
Windows Service AgentXnimcoo.exeAdded by the RBOT.EWV WORM!No
WINDOWS SYSTEMXninfoie.exeAdded by the MYTOB-EP WORM!No
NInitNNInit.exeNorton Uninstall Deluxe. Monitors programs being installed and logs them for removing later. Available via Start → Programs for manual logging - not requiredNo
Microsoft Winedows UpdateingXNinKey.exeAdded by a variant of the SPYBOT WORM! See hereNo
Microsoft Winedows UpdateingXNinKey.exeDetected by McAfee as W32/Sdbot.worm!mkNo
Run Nintendo Wi-Fi USB Connector Registration ToolUNintendoWFCReg.exeRelated to Wi-Fi USB Connector from NintendoNo
iPrint LPT Redirector?nipplpte.exeRelated to Novell® iPrint - a "best-of-breed printing solution for businesses running as traditional enterprises, for those operating entirely on the Net, and for those anywhere on the large spectrum in between." Is it required?No
NiroFile UpdatedXNiroFile.exeAdded by a variant of the IRCBOT TROJAN!No
nisdisaXnisdisa.exeAdded by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an exampleNo
nisservYNISSERV.EXEPart of Symantec's now discontinued Norton Personal Firewall and also included in older versions of Norton Internet Security. Also part of their now discontinued Symantec Client Firewall (part of Symantec Client Security for business customers). Runs as a service on an NT based OS (such as Windows 7/Vista/XP)No
NisumYNISUM.EXEPart of Symantec's now discontinued Norton Personal Firewall and also included in older versions of Norton Internet Security. Runs as a service on an NT based OS (such as Windows 7/Vista/XP)No
niSvcLocUniSvcLoc.exeRelated to National Instruments Corp. LabViewNo
WinNiteXniteaim.exeAdded by the OPANKI.B WORM!No
Wkyo86XNitip.exeAdded by the PITIN-A WORM!No
Nitro PDF Printer MonitorUNitroPDFPrinterMonitor.exePrinter monitor for Nitro PDF Professional from Nitro PDF, Inc. - "complete, affordable and easy-to-use set of tools to work with PDF documents"No
Microsoft Security Monitor ProcessXnitty.exeAdded by the RBOT.AEU BACKDOOR!No
niuXniu.exeAdded by the SILLYFDC.BCS WORM!No
Video ProcessXNivopsvc.exeAdded by the AGOBOT-GT WORM!No
NJG40XNJG40.EXEAdded by the BANCOS.D TROJAN!No
Boot ManagerXNjgal.exeAdded by the KILO TROJAN!No
NJILXnjil.exeAdded by the DELF-ELF TROJAN!No
BArVzWJrYXnjUOghDDY.exeDetected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Trojan.MSILNo
Msn MessengerXnkbf.exeAdded by the RBOT-GMQ WORM!No
NkbMonitor.exeNNkbMonitor.exePart of Nikon PictureProject - image management for Nikon digital camerasNo
Nikon Message Center 2NNkMC2.exeApplication for Nikon digital camera products that informs users of the latest information regarding updates to Nikon software and firmware upgrades. Currently supports the Camera Control Pro and ViewNX applicationsNo
Nikon MonitorNnkmonitor.exeMonitors for a Nikon CoolPix camera being connected via USB port. As soon as it detects a CoolPix camera it executes the Nikon View software to enable the user to transfer images from the camera to the PCNo
MSN Service UtilitiesXnkn.exeAdded by the KELVIR-BC WORM!No
Nvidia Control DaemonXnksvc32.exeAdded by an unidentified WORM or TROJAN!No
NkvMon.exeNNkvMon.exeNikon View 5 - for transferring pictures from Nikon digital camerasNo
NkVwMon.exeNNkVwMon.exeNikon View - for transferring pictures from Nikon digital camerasNo
NkwkwxXNkwkwx.scrDetected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %AppData%No
Microsoft (R) Windows Network Latency ControllerXnlc.exeAdded by a generic password stealer TROJAN - see hereNo
Microsoft Update MachineXnlczty.exeAdded by the RBOT-GUR WORM!No
sv18h5jckqdfo6zgc2i0nlzh0uwz2q93waXnlkptmqe.exeDetected by Malwarebytes Anti-Malware as Trojan.VBAgent. The file is located in %System%No
NaviSearchXnls.exeNaviSearch adwareNo
NLS MonitorXnlsmon.exeAdded by the RBOT-AXJ WORM!No
fofficeXnm.exeAdded by the DELF-CB TROJAN!No
ujmUnm32.exeStranget keystroke logger/monitoring program - remove unless you installed it yourself! Found in %Windir%\fytNo
nmappUnmapp.exePure Networks "Network Magic eliminates common frustrations and saves time by simplifying and automating set up, management and repair of home networks, and makes printer and file sharing effortless"No
Microsof ValueXnmatt.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}UNMBgMonitor.exeLooks for new files which can be included in Nero Scout which is "a database program which indexes and catalogs all media files on your computer and makes the database available to all programs in the Nero product package." Included in version 7 of the Nero digital media suites (CD/DVD burning, authoring, etc). Integrated into a number of Nero applications and is of particular significance for the Nero Home media center - for more information see the link. If you have trouble disabling Nero Scout try hereYes
Nero HomeUNMBgMonitor.exeLooks for new files which can be included in Nero Scout which is "a database program which indexes and catalogs all media files on your computer and makes the database available to all programs in the Nero product package." Included in version 7 of the Nero digital media suites (CD/DVD burning, authoring, etc). Integrated into a number of Nero applications and is of particular significance for the Nero Home media center - for more information see the link. If you have trouble disabling Nero Scout try hereYes
NMBgMonitorUNMBgMonitor.exeLooks for new files which can be included in Nero Scout which is "a database program which indexes and catalogs all media files on your computer and makes the database available to all programs in the Nero product package." Included in version 7 of the Nero digital media suites (CD/DVD burning, authoring, etc). Integrated into a number of Nero applications and is of particular significance for the Nero Home media center - for more information see the link. If you have trouble disabling Nero Scout try hereYes
NMBgMonitor.exeXNMBgMonitor.exeAdded by the BRAVO-G TROJAN! Note - this is not the legitimate Nero Scout entry, which is normally located in %CommonFiles%\Nero\Lib. This one is located in %System%No
NetManageImportUnmcpdata.exeNetManage business software relatedNo
nmctxthUnmctxth.exeRelated to Pure Networks comprehensive home and small business networking software that simplifies network configurationNo
[various names]Xnmdllw.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
Nero HomeYNMFirstStart.exeAppears to be related to the first run of Nero Home, which "combines television and the recording of television programs with playback of DVD-Videos and audio/video files in an easy-to-use interface" and "can also catalog them and organize them into individual libraries." Included in versions 7 and 8 of Nero digital media suites (CD/DVD burning, authoring, etc). Loads only on the first reboot after installation via the HKCU\RunOnce keyYes
NeroHomeFirstStartYNMFirstStart.exeAppears to be related to the first run of Nero Home, which "combines television and the recording of television programs with playback of DVD-Videos and audio/video files in an easy-to-use interface" and "can also catalog them and organize them into individual libraries." Included in versions 7 and 8 of Nero digital media suites (CD/DVD burning, authoring, etc). Loads only on the first reboot after installation via the HKCU\RunOnce keyYes
IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}UNMIndexStoreSvr.exeIndexing and storage service for Nero Scout which is "a database program which indexes and catalogs all media files on your computer and makes the database available to all programs in the Nero product package." Included in version 8 of the Nero digital media suites (CD/DVD burning, authoring, etc). Integrated into a number of Nero applications and is of particular significance for the Nero Home media center - for more information see the linkYes
Nero HomeUNMIndexStoreSvr.exeIndexing and storage service for Nero Scout which is "a database program which indexes and catalogs all media files on your computer and makes the database available to all programs in the Nero product package." Included in version 8 of the Nero digital media suites (CD/DVD burning, authoring, etc). Integrated into a number of Nero applications and is of particular significance for the Nero Home media center - for more information see the linkYes
NMIndexStoreSvrUNMIndexStoreSvr.exeIndexing and storage service for Nero Scout which is "a database program which indexes and catalogs all media files on your computer and makes the database available to all programs in the Nero product package." Included in version 8 of the Nero digital media suites (CD/DVD burning, authoring, etc). Integrated into a number of Nero applications and is of particular significance for the Nero Home media center - for more information see the linkYes
_Cat1Xnmmst.exeDetected by Trend Micro as TROJ_SMALL.SDNo
System Document ApplicationXnmod.exeAdded by the SDBOT-ABB WORM!No
Microsoft Software UpdateXnmon.exeAdded by the RBOT.HZ WORM!No
NMPSystrayUNMPSystray.exeSystem Tray access to NotesMedic from Cassetica Software Inc. - which "contains a suite of Tools that make life easier when using Lotus Notes"No
RiauXnmrc.exePurityScan adwareNo
Windows driver updateXnmsmtp32.exeAdded by the SDBOT-JT WORM!No
NMSSvc?NMSSVC.EXENIC Management Service - diagnostics program for Intel Pro family network cardsNo
_Cat2Xnmstt.exeDetected by Kaspersky as Trojan-Downloader.Win32.Small.ahg. The file is located in %Windir%No
NMSVCYnmSvc.exeCovenant Eyes - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it. Disabling it means loss of internet connection until renabled - therefore required if you use itNo
nMTaskBarService?nMtsk.exeTaskbar control for ISDN NetMod modem. What does it do and is it required?No
Windows Zero SpoolerXnmvcs.exeAdded by the SLENFBOT.JQ WORM!No
Windows Audio ComponentsXnncsvc.exeAdded by a variant of the IRCBOT TROJAN! See hereNo
Windows Audio StartupXnndsvc.exeAdded by the IRCBOT-AAE TROJAN!No
Windows Audio SystemXnndsvc.exeAdded by a variant of the IRCBOT TROJAN! See hereNo
NNLLUnnll.exeNet Nanny internet filterNo
Norton Navigator LoaderNnnloader.exeAn older Norton utility for file management under Windows 95. More information hereNo
nmgrXnnmgr.exeFFToolBar adware toolbarNo
nnqcouuXnnqcouu.exeThe Abi Network adwareNo
NeroNETTrayIconNNNServiceCtrl.exeSystem tray access to NeroNET - Ahead Software's network-capable extension of their CD/DVD burning program. NeroNET allows a burner to be shared across a networkNo
NNTrayUnnstart.exeNet Nanny internet filterNo
NNSvcUnnsvc.exeNet Nanny internet filter. Runs as a service on an NT based OS (such as Windows 7/Vista/XP)No
IBM Lotus Notes Preloader?nntspreld.exePreloader for IBM Lotus Notes. Is it required on modern, faster systems?No
Microsoft UpdateXnnwyaupdtAdded by the RBOT.RHK BACKDOOR!No
PopUp StopperXNO POPUP.EXEAdded by the SPYBOT-DC WORM!No
System Information ManagerXno.exeAdded by the SPYBOT.NO WORM!No
NoAdsUNoAds.exeBlocks advertisement banners in Internet ExplorerNo
NoAdwareXNoAdware.exeNoAdware - spyware remover. This version is not recommended - see hereNo
NoAdware3UNoAdware3.exeNoAdware - spyware remover. Initially not recommended due to false positives and aggressive advertising but the later versions have since improved - see hereNo
NoAdware4UNoAdware4.exeNoAdware - spyware remover. Initially not recommended due to false positives and aggressive advertising but the later versions have since improved - see hereNo
nobfudycomalXnobfudycomal.exeDetected by Sophos as Troj/Bckdr-RPP and by Malwarebytes Anti-Malware as Trojan.Ransom.GenNo
NortonOnlineBackupReminderNNobuActivation.exeActivation reminder for Norton Online BackupNo
Dell DataSafe OnlineUNOBuClient.exeSystem Tray access to and notifications for the Dell DataSafe Online storage utilityYes
NOBuClientUNOBuClient.exeSystem Tray access to and notifications for Symantec's Norton Online Backup and Dell DataSafe Online storage utilitiesYes
Norton Online BackupUNOBuClient.exeSystem Tray access to and notifications for Symantec's Norton Online Backup online storage utilityYes
NortonOnlineBackupUNOBuClient.exeSystem Tray access to and notifications for Symantec's Norton Online Backup online storage utilityYes
ActiveScript32Xnod.exeAdded by the SOHANA-AJ WORM!No
Nod23 ServiceXnod23.exeAdded by the RBOT-GMK WORM!No
nod32 antivirusXnod32.exeAdded by the VB-FFT TROJAN! Note - this is not Eset's NOD32 antivirusNo
Windows Service AgentXnod32.exeAdded by the RBOT.BNG BACKDOOR!No
NOD321XNOD321.exeDetected by McAfee as RDN/Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
Nod32CCUnod32cc.exeControl Center part of Eset's NOD32 antivirus. Leave this enabled if you want to update your virus data files via the click of a buttonNo
Nod32 Free antivirusXnod32krn.exeAdded by the RBOT-AAO WORM! Note - this is not Eset's NOD32 antivirus which shares the same filename and is normally found in %ProgramFiles%\Eset. This one is located in %System%No
NOD32kernelYNod32krn.exeEset's NOD32 antivirus. Runs as a service on an NT based OS (such as Windows 7/Vista/XP)No
nod32kuiYnod32kui.exeEset's NOD32 antivirusNo
Nod32 ServiceXnod6.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
Nod32 ServiceXnod64.exeAdded by the RBOT.ESJ WORM!No
nodsosXnodabc.exeAdded by the PWS-BLE TROJAN!No
NodeMnger?Nodemngr.exePart of the Dell OpenManage Client installation - to allow Dell representatives to remote logon?No
NoDNSXNoDNS.exeAdded by the CLICKER.WI TROJAN!No
nod32Xnodqq.exeDetected by Sophos as W32/Autorun-BBVNo
Nod29 ServiceXnodwr.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
NTsocketXNoeWinnt.exeDetected by Sophos as Troj/Ataka-ENo
NOFIIN.EXEXNOFIIN.EXEAdded by the HAXDOOR-DP TROJAN!No
WINDOWS-SHELLXnofud.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%No
Nokia CheckXnokiacheck.exeAdded by the RBOT.CDC WORM!No
Nokia M PlatformUNokiaMServerPart of Nokia Ovi Player (and the older Nokia Music) music manager, Nokia Photos photo and video manager or Nokia Ovi Suite mobile device manager. Used to watch for any new file types that have been associated with these utilitiesYes
NokiaMServerUNokiaMServerPart of Nokia Ovi Player (and the older Nokia Music) music manager, Nokia Photos photo and video manager or Nokia Ovi Suite mobile device manager. Used to watch for any new file types that have been associated with these utilitiesYes
Nokia FastStartNNokiaMusic.exePart of the Nokia Music music manager - which has now been replaced by Ovi Player. "With Nokia Music, you can play music, discover and buy new music, transfer music between your compatible PC and your compatible Nokia mobile devices, and rip and burn audio CDs". If enabled, this entry will reduce the time taken for Nokia Music to run by a few seconds for the first time after Windows has loadedYes
Nokia MusicNNokiaMusic.exePart of the Nokia Music music manager - which has now been replaced by Ovi Player. "With Nokia Music, you can play music, discover and buy new music, transfer music between your compatible PC and your compatible Nokia mobile devices, and rip and burn audio CDs". If enabled, this entry will reduce the time taken for Nokia Music to run by a few seconds for the first time after Windows has loadedYes
NokiaMusicNNokiaMusic.exePart of the Nokia Music music manager - which has now been replaced by Ovi Player. "With Nokia Music, you can play music, discover and buy new music, transfer music between your compatible PC and your compatible Nokia mobile devices, and rip and burn audio CDs". If enabled, this entry will reduce the time taken for Nokia Music to run by a few seconds for the first time after Windows has loadedYes
Nokia Ovi PlayerNNokiaOviPlayer.exePart of the Nokia Ovi Player - which is "a free PC application for playing and organising your music, discovering and downloading new music on Ovi, transferring songs and playlists between your compatible PC and compatible Nokia mobile devices, and ripping and burning your audio CDs". If enabled, this entry will reduce the time taken for Nokia Music to run by a few seconds for the first time after Windows has loadedYes
NokiaMusic FastStartNNokiaOviPlayer.exePart of the Nokia Ovi Player - which is "a free PC application for playing and organising your music, discovering and downloading new music on Ovi, transferring songs and playlists between your compatible PC and compatible Nokia mobile devices, and ripping and burning your audio CDs". If enabled, this entry will reduce the time taken for Nokia Music to run by a few seconds for the first time after Windows has loadedYes
NokiaOviPlayerNNokiaOviPlayer.exePart of the Nokia Ovi Player - which is "a free PC application for playing and organising your music, discovering and downloading new music on Ovi, transferring songs and playlists between your compatible PC and compatible Nokia mobile devices, and ripping and burning your audio CDs". If enabled, this entry will reduce the time taken for Nokia Music to run by a few seconds for the first time after Windows has loadedYes
Nokia Ovi SuiteNNokiaOviSuite.exeFirst generation of Nokia Ovi Suite for managing Nokia mobile devices - "gives you an easy access to the contents of your Nokia device. Transfer files and information effortlessly between your device and your computer, and experience a new way of browsing your photos, videos and music. Furthermore, you can share photos quickly and safely through the Share on Ovi service"Yes
Nokia Ovi Suite 2NNokiaOviSuite.exeSecond generation of Nokia Ovi Suite for managing Nokia mobile devices - which "gives you an easy access to the contents of your Nokia device. Transfer files and information effortlessly between your device and your computer, and experience a new way of browsing your photos, videos and music. Furthermore, you can share photos quickly and safely through the Share on Ovi service"Yes
NokiaOviSuiteNNokiaOviSuite.exeNokia Ovi Suite for managing Nokia mobile devices - "gives you an easy access to the contents of your Nokia device. Transfer files and information effortlessly between your device and your computer, and experience a new way of browsing your photos, videos and music. Furthermore, you can share photos quickly and safely through the Share on Ovi service"Yes
NokiaOviSuite.exeNNokiaOviSuite.exeFirst generation of Nokia Ovi Suite for managing Nokia mobile devices - "gives you an easy access to the contents of your Nokia device. Transfer files and information effortlessly between your device and your computer, and experience a new way of browsing your photos, videos and music. Furthermore, you can share photos quickly and safely through the Share on Ovi service"Yes
NokiaOviSuite2NNokiaOviSuite.exeSecond generation of Nokia Ovi Suite for managing Nokia mobile devices - which "gives you an easy access to the contents of your Nokia device. Transfer files and information effortlessly between your device and your computer, and experience a new way of browsing your photos, videos and music. Furthermore, you can share photos quickly and safely through the Share on Ovi service"Yes
NokKernel installUNok_install.exeInstaller for the NokNet Workstation Monitor surveillance software. Uninstall this software unless you put it there yourselfNo
NomdCheckNnomdchek.exePart of Intel's Native AudioNo
Microsoft Explorer2Xnome.exeDetected by Trend Micro as WORM_RANDEX.AANo
nomtrayUnomtray.exeSystem Tray access to NetMotion Wireless options - including connectivity status (see here)No
NonohNNonoh.exeNonoh - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular SkypeYes
Microsoft Nod32 ServiceXnood32.exeAdded by the RBOT.EJP WORM!No
EptrXnopdb.exeAdded by an unidentified WORM or TROJAN!No
NOPDBSXNOPDBS.exeAdded by the BANCBAN-AS TROJAN!No
[various names]XNopeZ.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
NoPopUpUnopopup.exeNoPopUp 2003 by NEXT-Soft - popup blockerNo
Bron-SpizaetusXnorBtok.exeAdded by the RONTOKBRO.B WORM!No
NordXnordsys.exeAdded by the DREF-S WORM!No
normally.exeXnormally.exeDetected by Dr.Web as Trojan.DownLoader8.24079 and by Malwarebytes Anti-Malware as Trojan.BankerNo
NortE AntivirusXnorte.exeDetected by Trend Micro as WORM_RBOT.BQQNo
NortE AntivirusXnorten.exeAdded by the RBOT-AFF WORM!No
norten Software IntrenetXnorten.pifAdded by the RBOT-AWA WORM!No
ProtectionXNorton Internet Security.exeAdded by the ELITPER.E WORM!No
Wxp4XNorton Update.exeAdded by the ERKEZ.D WORM!No
Microsoft Norton AntivirusXnorton.exeAdded by a variant of the IRCBOT BACKDOOR!No
System Service ManagerXnorton.exeAdded by the GAOBOT.AJE WORM!No
Windows System Service Configuration LoaderXnorton.exeAdded by the AGOBOT.GN WORM!No
MS Unix BinaryXNorton2005Update.exeAdded by a variant of the RBOT WORM!No
norton32Xnorton32.exeAdded by an unidentified VIRUS, WORM or TROJAN!No
Norton AntiBotYNortonAntiBot.exeControl Center for Norton Antibot from Symantec - which "provides advanced, real-time protection against emerging threats, including bots that are used to perpetrate identity theft and other online crimes" and "protects your PC from unauthorized access and tampering, detects and stops attempts by hackers to take remote control of your computer, and delivers extra protection against emerging 'zero-day' threats." Designed to work with existing antivirus software but now discontinuedYes
NortonAntiBotYNortonAntiBot.exeControl Center for Norton Antibot from Symantec - which "provides advanced, real-time protection against emerging threats, including bots that are used to perpetrate identity theft and other online crimes" and "protects your PC from unauthorized access and tampering, detects and stops attempts by hackers to take remote control of your computer, and delivers extra protection against emerging 'zero-day' threats." Designed to work with existing antivirus software but now discontinuedYes
Norton AntivirusXnortonav.exeAdded by the RBOT-AYE TROJAN! Note - this is not the real Norton AV!No
Norton Antivirus UpdaterXnortonav.exeAdded by the DELBOT-T WORM! Note - this is not the real Norton AV!No
Windows XpXnortonguard.exeAdded by the MYTOB-DZ WORM!No
nortonpXnortonp.exeAdded by the JD-A TROJAN!No
Mcafee Anti ScanXNortonScn.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
Norton UpdaterXNortonUpdate.exeAdded by an unidentified WORM or TROJAN!No
NortonAVXnorton_antivirus.exeAdded by the NETJOE TROJAN! Note - this is not the legitimate Symantec AV programNo
noskrnlXnoskrnl.exeDetected by Symantec as Trojan.Peacomm.DNo
Loadout ManagerUnost_LM.exeManager for the Belkin Nostromo n50 SpeedPad game controller - see hereNo
notesXnotepaad.exeAdded by the RBOT.BME WORM!No
(Default)XNOTEPAD.exeAdded by the RUSTY WORM! Note - not to be confused with the valid Windows "NOTEPAD" text editor! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
[random name]Xnotepad.exePurityScan adware. Note - this is not Windows Notepad which has the same executable nameNo
Lao AntivirusXNOTEPAD.EXEDetected by Dr.Web as Win32.HLLW.Autoruner1.2826 and by Malwarebytes Anti-Malware as Worm.AutoRunNo
MicrosoftXnotepad.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.AI. Note - this is not the legitimate text editor of the same filename which is located in %Windir%. This version is located in %AppData%\FlashPlayerNo
MicrosoftXnotepad.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.AI. Note - this is not the legitimate text editor of the same filename which is located in %Windir%. This version is located in %Windir%\FlashPlayerNo
MicrosoftXnotepad.exeDetected by Malwarebytes Anti-Malware as Trojan.Autoit. Note - this is not the legitimate text editor of the same filename which is located in %Windir%. This version is located in %System%\FlashPlayerNo
Microsoft NotePadXnotepad.exeAdded by a variant of Win32/RbotNo
Notepad lptt01Xnotepad.exeRapidBlaster variant (in a "windows" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not Windows Notepad which has the same executable nameNo
Notepad ml097eXnotepad.exeRapidBlaster variant (in a "windows" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not Windows Notepad which has the same executable nameNo
EYOREXNotepad.scrAdded by the GIMLET-A WORM!No
Windows Autostart LoaderXnotepad32.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
msdtccXnotepod.exeDetected by Trend Micro as TROJ_VB.FPWNo
notesXnotes.exeAdded by the SYKIPOT BACKDOOR!No
NoticeP.exeUNoticeP.exePart of iSync which allows "you to transfer songs from any music downloading software to your iTunes® library". The trial version displays advertisements which disappear if you purchase the softwareNo
Notify MailNNOTIFY.EXEE-mail notification utilityNo
pagofileXnotoped.exeDetected by Trend Micro as TROJ_VB.FPW and by Malwarebytes Anti-Malware as Email.Worm.NTONo
bee0c4d45bcdd7deadce6b70f4861060XNotpad.exeDetected by Dr.Web as Trojan.DownLoader8.31864 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJNo
Media serviceXnotpad.exeDetected by Trend Micro as WORM_SDBOT.CHU and by Malwarebytes Anti-Malware as Backdoor.SDBotNo
system23XnotPad.exeAdded by the ESTEEMS.D TROJAN!No
gabougoolXnounina.exeDetected by Sophos as Troj/Agent-JVXNo
Vista&SenvenXNourinfo.exeAdded by the AGENT-QXP TROJAN!No
Disable EHCI?nousb20.exe??No
Operations Typhoon Rising RegistrationNNOVG.EXEJoint Operations registration reminderNo
novsvida.exeXnovsvida.exeGlobalAccess dialerNo
NaverPCGreenUNPCGreenUpgrader.exeRelated to Naver_Anti-virus Realtime Monitor From NHNCorpNo
Disk Panel SetupXnpcsvc.exeAdded by the SLENFBOT.JV WORM!No
HtiUnpdor.exeAppears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not requiredNo
NFM ServiceUNPDOR9x.exeAppears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not requiredNo
IBM ThinkPad UtilityUNPDTray.exeSystem Tray access to Presentation Director for IBM/Lenovo Thinkpad notebooks - which allows you to create and quickly select between various single and multiple display options. Scheme selection and settings are also available via Fn+F7 key combination on some modelsYes
NPDTrayUNPDTray.exeSystem Tray access to Presentation Director for IBM/Lenovo Thinkpad notebooks - which allows you to create and quickly select between various single and multiple display options. Scheme selection and settings are also available via Fn+F7 key combination on some modelsYes
ThinkPad Presentation DirectorUNPDTray.exeSystem Tray access to Presentation Director for IBM/Lenovo Thinkpad notebooks - which allows you to create and quickly select between various single and multiple display options. Scheme selection and settings are also available via Fn+F7 key combination on some modelsYes
Windows Network LogonXnpesvc.exeAdded by the AGENT.ERZ TROJAN!No
GLF Network Lan MonitorXNPFMNTOR.exeAdded by the RBOT-AGY WORM!No
NPFMonitorYNPFMntor.exeFirewall install monitor for older versions of Symantec's security products including Norton Internet Security, Norton AntiVirus and the now discontinued Norton SystemWorks suite. Helps detect immediately after boot-up whether the firewall part is currently installed and working properly, whether it is currently enabled or disabled, and what features of the firewall are turned on. Runs as a service on an NT based OS (such as Windows 7/Vista/XP)No
NPF ValueXNPFMONTR.exeAdded by the RBOT-AWD WORM!No
Norton Personal FirewallXnpfw.exeAdded by the RBOT-UI WORM!No
Norton Personal FirewallXnpfw32.exeAdded by the RBOT-UQ WORM!No
userinitXnpgkij.exeDetected by McAfee as Generic BackDoor.acx and by Malwarebytes Anti-Malware as Trojan.AgentNo
npkmncXnpkmnc.exeWebVia adwareNo
Norton Personal FirewallXnpmsys.exeDetected by Sophos as W32/Rbot-ALONo
Netzip Smart DownloaderXnpnzdad.exeAdvertising spywareNo
RealDownload ExpressXnpnzdad.exeAdvertising spywareNo
Norton ProtectXnpprotect.exeAdded by the RBOT-WW WORM!No
Windows Audio PanelXnppsvc.exeAdded by a variant of the IRCBOT TROJAN! See hereNo
NPROTECTXNPROTECT.exeDetected by Symantec as Trojan.Syginre. Note - this is not the legitimate file used by the Norton Protected Recycled Bin feature from older versions of Norton Utilities and is located in %Root%No
NPROTECTUNPROTECT.EXESupports the Norton Protected Recycled Bin feature of older versions of Norton Utilities (either as a standalone product or as part of Norton SystemWorks). Adds an extra layer of safety to the deletion of information from the standard Windows Recycled Bin. Runs as a service on an NT based OS (such as Windows 7/Vista/XP)No
AutoStartNPSAgentNNPSAgent.exeInstalled with the SAMSUNG New PC Studio mobile device management utility. Detects when a supported mobile device is connection and optionally automatically loads the main programYes
NPSAgentNNPSAgent.exeInstalled with the SAMSUNG New PC Studio mobile device management utility. Detects when a supported mobile device is connection and optionally automatically loads the main programYes
Samsung PC StudioNNPSAgent.exeInstalled with the SAMSUNG New PC Studio mobile device management utility. Detects when a supported mobile device is connection and optionally automatically loads the main programYes
Norton Program Scheduler Event Checker?npscheck.exePart of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as NPS Event CheckerNo
NPS Event Checker?npscheck.exePart of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as Norton Program Scheduler Event CheckerNo
Norton Program SchedulerUNPSsvc.exeInstalled on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95, WinNT(?), Win2K(?)) to schedule automatic tasks such as Norton Anti-Virus scansNo
Windows Protected StorageXnpssvc.exeAdded by the IRCBOT.AUL BACKDOOR!No
NovaPortal Single User Service?NPSU.exe??No
NQaKwkjGRxPmQog.exeXNQaKwkjGRxPmQog.exeDetected by Malwarebytes Anti-Malware as Trojan.Foury. The file is located in %CommonAppData%No
WinLoaderXnqvrcni.exeDetected by Dr.Web as Trojan.MulDrop4.14194No
NR7XNR7.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%No
NetReachXnrcheck.exeAdded by an unidentified VIRUS, WORM or TROJAN!No
QTimeXnrchk.exePremium rate adult content diallerNo
ScheduIeXnrchk.exePremium rate adult content diallerNo
Microsoft (R) Windows Vista/NT Runtime Compatibility ServiceXnrcs.exeAdded by the RANKY.X TROJAN!No
PremeterXnrpr.exeNetRatings Premeter spywareNo
nrtwcfXnrtwcf.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %ProgramFiles%\WinRARNo
NSXns.exeAdded by the AGOBOT-HS WORM!No
Run32Xns.exeDetected by Sophos as Troj/DwnLdr-KNN and by Malwarebytes Anti-Malware as Trojan.MSILNo
NLS MonBoardXNSBARD.EXEAdded by the SPYBOT.T BACKDOOR!No
Win32loadXnscagent.exeDetected by McAfee as Downloader-BONNo
Scanner File UtilityYNsCatCom.exeKycocera Mita network copier/printer/scanner process to dump scanned documents onto a workstationNo
NSCheckXnscheck.exeMarketScore parasite - ActiveX control used to download premium-rate diallersNo
Norton Program SchedulerUnsched32.exeInstalled on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95, WinNT(?), Win2K(?)) to schedule automatic tasks such as Norton Anti-Virus scansNo
nscntrlXnscntrl.exeAdded by the DLOAD-DC TROJAN!No
[various names]XNsCplTray.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
NSCSysTrayUIUNSCSysTrayUI.exeSystem Tray access to the NetworkScan utility for some Samsung AIO devices which allows scanning and printing over a networkNo
NSCSysTrayUI_XEROXUNSCSysUI_XEROX.exeSystem Tray access to the NetworkScan utility for some Xerox AIO devices which allows scanning and printing over a networkNo
nsdcmd servicesXnsdcmdav.exeAdded by a variant of the AGOBOT WORM!No
nsdcmd vid processXnsdcmdwin.exeAdded by a variant of the AGOBOT WORM!No
nsdluaXnsdlua.exeAll-In-One Telcom - adult content diallerNo
nseXnse.exeDetected by Sophos as W32/Agobot-MLNo
Network SecurityXNSecurity.exeAdded by the IRCBOT.AAV WORM!No
NsengineUNsengine.exeScheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see hereNo
nservice32Xnservice32.exeDetected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Trojan.AgentNo
signupXnsignup.exeDetected by Dr.Web as Trojan.DownLoader7.12599 and by Malwarebytes Anti-Malware as Adware.KorAdNo
NSKUNSK.exeArdakey keystroke logger/monitoring program - remove unless you installed it yourself!No
NetStat LiveNNsl.exeAnalogX NetStat Live - TCP/IP protocol monitor which can be used to see your exact throughput on both incoming and outgoing dataNo
[3-4 random letters]Xnslookup.exePurityScan adware. Not to be confused with the legitimate nslookup.exe which is found in the System32 folderNo
PI_NsLookup.exeXNsLookup.exeDetected by Sophos as Troj/Agent-ZBG and by Malwarebytes Anti-Malware as Trojan.AgentNo
Microsoft (R) Windows Network Security Management ServiceXnsms.exeDetected by Trend Micro as TROJ_RANKY.LCNo
Microsoft CSRSS ServiceXnsmscrs.exeAdded by the RBOT-BPT WORM!No
NetShow Powerpoint HelperUNSPPTHLP.EXEIf disabled, user created fonts can no longer be seen by other programsNo
Windows Media Powerpoint HelperNNSPPTHLP.EXEGerman software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start → ProgramsNo
Windows Network SessionXnspsvc.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
Norton Save and RestoreUNSRTray.exeSystem Tray access to and notifications for Symantec's Norton Save and Restore 1.0 backup software (either as a standalone product or as part of Norton SystemWorks Premier) - which is a renamed version of Norton GhostYes
NSRKeyUNSRTray.exeSystem Tray access to and notifications for Symantec's Norton Save and Restore 1.0 backup software (either as a standalone product or as part of Norton SystemWorks Premier) - which is a renamed version of Norton GhostYes
NSRTrayUNSRTray.exeSystem Tray access to and notifications for Symantec's Norton Save and Restore 1.0 backup software (either as a standalone product or as part of Norton SystemWorks Premier) - which is a renamed version of Norton GhostYes
ScanRegistryXnsrvnt.exeDetected by Symantec as Backdoor.NerteNo
SystemServiceUnsserver.exeNiceSpy keystroke logger/monitoring program - remove unless you installed it yourself!No
TSService?NSSERVICE.EXE??No
nsdriverXnssys32.exeNetShagg adwareNo
NDplDeamonXnstask32.exeAdded by the RANDEX.E WORM!No
PofatchXnstrue.exeAdded by the RANDEX.Z WORM!No
NSupdateXNSupdate.exeAdded by the Dial/Laet-B premium rate dialer!No
NokiaXnsu_ui_client.exeAdded by the BANKER-FAQ TROJAN! Note - this is not the legitimate Nokia Software Updater which shares the same filename and is located in %ProgramFiles%\Nokia\Nokia Software Updater. This one is located in %Windir%No
Nokia Software UpdaterYnsu_ui_client.exeUtility that only runs once after installing the Nokia Software Updater which is used to update the operating system (or firmware) for selected Nokia mobile devicesYes
nsu_ui_clientYnsu_ui_client.exeUtility that only runs once after installing the Nokia Software Updater which is used to update the operating system (or firmware) for selected Nokia mobile devicesYes
nsu_ui_client.exeYnsu_ui_client.exeUtility that only runs once after installing the Nokia Software Updater which is used to update the operating system (or firmware) for selected Nokia mobile devicesYes
NsvdrXnsvdr.exeAdult content diallerNo
NsvXnsvsvc.exeDelfin PromulGate adwareNo
NSWCfg.exeUNSWCfg.exeInformation wizard for older versions of Symantec's now discontinued Norton SystemWorks system utility suite. On the first run after installation this entry looks after registration, subscription and confirms the default configuration settingsYes
Norton SystemWorksNNswUiTray.exeSystem Tray access to Symantec's now discontinued Norton SystemWorks 2009 security and utility suiteYes
NswUiTrayNNswUiTray.exeSystem Tray access to Symantec's now discontinued Norton SystemWorks 2009 security and utility suiteYes
nsysUnsys.exeNetSpy keystroke logger/monitoring program - remove unless you installed it yourself!No
nsys32Xnsys32.exeAdded by the AGOBOT-SU WORM!No
[various names]XNSYSCPLSTR.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
Nt**.exe [* = random char]XNt**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this logNo
Nt**32.exe [* = random char]XNt**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this logNo
Reg ServiceXNT32.exeDetected by Trend Micro as BKDR_AGOBOT.GNo
NT Video API32XNTAPI32.exeAdded by the RBOT-FW WORM!No
ntasvrXntasvr.exeDetected by Emsisoft as Adware.Win32.NateSrch!A2. The file is located in %ProgramFiles%\Nate\AddressSearchNo
NET Bios StatsXntbstats.exeAdded by the SDBOT-ZX WORM!No
Microsoft Update MachineXntce.exeAdded by the RBOT-FA WORM!No
directxXNTCmd.exeAdded by the SDBOT.D TROJAN!No
NvCplDXntcpl.exeEnterOne - Switch dialer and hijacker variant, see hereNo
ntddetectXntddetect.exeAdded by the AGENT-CU TROJAN!No
rundll32Xntdevice.exeAdded by the AGENT-OUM TROJAN!No
NTdhcpXNTdhcp.exeAdded by the QQROB-C TROJAN!No
MSN serviceXNTDKRN.EXEAdded by the RBOT.UJ WORM!No
ntdllXntdll.exeAdded by the BIONET.404 TROJAN!No
Windows InstallerXntdll.exeAdded by an unidentified WORM or TROJAN!No
Configuration LoaderXntdm.exeDetected by Trend Micro as WORM_AGOBOT.RVNo
Microsoft NT DriversXntdrv.exeAdded by the SDBOT.AJN TROJAN!No
InternetXnteusodp.exeAdded by the RBOT-GFJ WORM!No
Windows File System FrameXntframe.exeAdded by an unidentified WORM or TROJAN!No
systemStartXNtfs.exeAdded by the AUTORUN-JM WORM!No
NTFS16Xntfs16.exeAdded by the RBOT-LY WORM!No
ntfsmonitorproXntfs64.exeAdded by the FORBOT-EB WORM!No
ConfigSafeYNTFSCLUP.EXEPart of ConfigSafe - "checks if an ntfssos restore has been performed since it was last run. It exits immediately after running. 99+% of the time it will only execute about a dozen instructions before exiting"No
NTFSCLUPYNTFSCLUP.EXEPart of ConfigSafe - "checks if an ntfssos restore has been performed since it was last run. It exits immediately after running. 99+% of the time it will only execute about a dozen instructions before exiting"No
*ntfsqueuedns.exeXntfsqueuedns.exeAdded by the FAKEAV-EMN TROJAN!No
ntfyappXntfyapp.exeAdded by the ZHELATIN WORM!No
GinaDllXntgina.dllDetected by Trend Micro as WORM_ANIG.ANo
Norton Guard 32Xntguard32.exeAdded by a variant of Win32/RbotNo
WSAConfigurationXntguard32.exeAdded by a variant of the AGOBOT WORM!No
WinSocketComponentXnthost.exeAdded by an unidentified VIRUS, WORM or TROJAN!No
ntiMUIUntiMUI.exePart of NTI CD & DVD Maker from NTI Corporation - now superseded by NTI Media MakerNo
AdobeReaderProXntkernell32.exeAdded by the RBOT-ATY WORM!No
Compaq Service DriversXNtKernelSystem.exeAdded by a variant of W32/Sdbot.wormNo
Kernel LoaderXntkrnl.exeAdded by the CERVIVEC.A WORM!No
NT Kernel PatchNntkrnlpt.exePart of Bitware from 2Point Communications, Inc - "a Windows based solution that allows users to integrate your voice messaging and faxing to an individual PC." Now known as Simply Messenger PRONo
ntldrXntldr.exeBrowser hijacker re-directing to search-control.com. In addition to the registry changes found by HijackThis it also creates the following system files: %System%\ntldr.exe, C:\m.exe, %Windir%\Search-For-You.url, C:\n.bat, C:\q.exe and C:\r.batNo
Win PatchXntldr.exeAdded by the SDBOT-GS WORM!No
shell32Xntldrt.exeAdded by the JLOK-A WORM!No
sysclxXntldrt.exeAdded by the JLOK-A WORM!No
Windows NT 32Xntlogin32.exeAdded by the RANDEX.BRD WORM!No
Windows NT LoginXntlogin32.exeAdded by the SDBOT.WG WORM!No
csrssXntmdi.exeDetected by Malwarebytes Anti-Malware as Trojan.FakeAdobe. The file is located in %UserProfile%No
ntmsevtXntmsevt.exeAdded by the STOPED-B TROJANNo
FastStartXntnut32.exeAdded by the STARTPAGE.L TROJAN!No
NotepadXntoepad.exeAdded by the DELBOT-AK WORM!No
ntokrnlXntokrnl.exeAdded by the BANKER.AWA TROJAN!No
NT ServiceXNTOKSRNL.EXEAdded by the RBOT-AAG WORM!No
NvCplDXntopengl.exeEnterOne - Switch dialer and hijacker variant, see hereNo
userinitXntos.exeDetected by Symantec as Trojan.Gpcoder.E and by Malwarebytes Anti-Malware as Trojan.AgentNo
Osa32XNTOSA32.exeAdded by the ANIG WORM!No
RealActiveXntoscore.exeAdded by the VIRUT.VQ VIRUS!No
sittachasnahalbasyaXntoskernel.exeAdded by the HANSAH-A WORM!No
Kernal Fault CheckXntosrkl.exeAdded by a variant of W32/Sdbot.wormNo
nTrayFwYntrayfw.exeSystem Tray access to the NVIDIA ActiveArmor hardware-optimized firewall built into some older nForce 3 and 4 series motherboard chipsetsNo
NVIDIA ActiveArmorYntrayfw.exeSystem Tray access to the NVIDIA ActiveArmor hardware-optimized firewall built into some older nForce 3 and 4 series motherboard chipsetsNo
NTrtcNntrtc.exeDell year 2000 tool to deal with non-standard applications. Only required on older Dell PCs that may need this supportNo
MS taskbarXnts.exeAdded by the RBOT-AGB WORM!No
EasySync Pro - LtNts4UNtsAgent.exeLotus Notes 4 specific translator for IBM® Lotus® EasySync® Pro - "a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"No
Laplink PDASync 3.0 - LtNts4UNtsAgnt.exeLaplink PDASync for (IBM) Lotus Notes 4 - PDA synchronisation utilityNo
XTNDConnect PC - LtNts4UNtsAgnt.exe(IBM) Lotus Notes 4 specific translator for XTNDConnect PC - "award-winning desktop-sync application that enables you to easily synchronize your contacts, calendar, tasks, email and notes between your mobile devices and popular PC applications"No
Intec Service DriversXntservice.exeAdded by the RBOT.FGW BACKDOOR!No
Microsoft UpdateXntservice.exeAdded by the AGENT-DIS TROJAN!No
NTSF MICROSOFT SYSTEMXntsf.exeDetected by Trend Micro as WORM_RBOT.ARQ and by Malwarebytes Anti-Malware as Backdoor.BotNo
NTSF MICROSOFT SYSTEMXntsfd.exeDetected by Sophos as W32/Rbot-BAP and by Malwarebytes Anti-Malware as Backdoor.BotNo
ntsmodXntsmod.exeAdware downloader/installer, probably VX2/Look2Me related - also detected as the WIN32.VB.RL TROJAN!No
Generic Host Process for Win32 ServicesXntspcv.exeAdded by the SDBOT.S TROJAN!No
NTSpoolXNTSpool.exeDetected by Sophos as Troj/Agent-GPYNo
NTsrv.exeXNTsrv.exeAdded by a variant of the SERVU-O TROJAN!No
System Server ManagerXNtsrvc.exeAdded by the DARKSKY.B BACKDOOR!No
NetManagerServiceXntss.exeDetected by Trend Micro as BESTPICS.A BACKDOOR!No
Network Translation System ServiceXntss.exeAdded by the UNPDOOR TROJAN!No
NTSF MICROSOFT SYSTEMXntssf.exeDetected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %System%No
MessengerXntsubsys.exeAdded by the SDBOT.BGE WORM!No
NetServiceXntsvc.exeAdded by the QQPASS-DU TROJAN!No
NT ServicesXntsvc.exeAdded by the AGOBOT.VJ WORM!No
Windows NT Net Service MonitorXntsvc.exeAdded by the SDBOT-DKY WORM!No
MicrosoftXntsvr.exeAdded by a variant of W32.Spybot.Worm. The file is located in %System%No
VxD Driver InitializationXntsvxd.exeAdded by the SDBOT-LW WORM!No
Compaq Service DriversXntsys32.exeDetected by Trend Micro as WORM_RBOT.CIWNo
ConfigurationXntsys32.exeAdded by the SDBOT-LN WORM!No
Winsock2 driverXntsys32.exeAdded by the SPYBOT-DD WORM!No
Nt System KernelXntsyskrnl.exeAdded by the AGOBOT.IK WORM!No
Microsoft System CheckupXntsysman.exeAdded by the SDBOT-QW WORM!No
Microsoft System CheckupXntsysmgr.exeAdded by the DONK.S WORM!No
ConfigurationXntsyst32.exeAdded by the SDBOT-LT WORM!No
gwizXntsystem.exeAdded by the NITWIZ.A TROJAN!No
Microsoft Update MachineXntsystem.exeAdded by the RBOT.GF WORM!No
Nt System ProtocolXntsystem.exeAdded by the RBOT.DSB BACKDOOR!No
Video ProcessXntsystm.exeAdded by the GAOBOT.ZX WORM!No
NtsysvXntsysv.exeAdded by the MIFENG-E TROJAN!No
nTuneUnTune.exeOlder version of the NVIDIA nTune utilty for monitoring and modifying the settings (such as temperatures, voltages, clocks and fan speeds) of NVIDIA based motherboards and graphics cards from within Windows. Now part of NVIDIA System ToolsNo
NVIDIA nTuneUnTune.exeOlder version of the NVIDIA nTune utilty for monitoring and modifying the settings (such as temperatures, voltages, clocks and fan speeds) of NVIDIA based motherboards and graphics cards from within Windows. Now part of NVIDIA System ToolsNo
nTuneCmdUnTuneCmd.exeNow part of NVIDIA System Tools under the "Peformance" tag. NVIDIA nTune is utilty for monitoring and modifying the settings (such as temperatures, voltages, clocks and fan speeds) of NVIDIA based motherboards and graphics cards from within Windows. Until version 6.01 (when System Tools was released) graphics settings weren't retained in a profile but now they are. From version 6.05, nTuneCmd is no longer loaded via the registry "Run" keys but instead runs via the Performance Service (nTuneService.exe)Yes
NVIDIA nTuneUnTuneCmd.exeNow part of NVIDIA System Tools under the "Peformance" tag. NVIDIA nTune is utilty for monitoring and modifying the settings (such as temperatures, voltages, clocks and fan speeds) of NVIDIA based motherboards and graphics cards from within Windows. Until version 6.01 (when System Tools was released) graphics settings weren't retained in a profile but now they are. From version 6.05, nTuneCmd is no longer loaded via the registry "Run" keys but instead runs via the Performance Service (nTuneService.exe)Yes
ntupd32Xntupd32.exeUnidentified malware - see hereNo
ntuserXntuser.exeAdded by an unidentified TROJAN! See hereNo
Fast startXNtut.exeAdware - detected by Kaspersky as the FAVADD.I TROJAN!No
Kernel Fault CheckXntvbm.exeAdded by the RBOT-CKP WORM!No
[random name]Xntvdm.exePurityScan adware. Do not confuse with the legitimate ntvdm.exe process which is always located in %System% and should not figure in Msconfig/Startup!No
NTVDMUNTVDM.EXEWindows NT Virtual DOS Machine (NTVDM) for running 16-bit tasks on the 32-bit OS's (Windows NT, 2K and XP). Required if hardware on a machine with these OS's needs 16-bit DOS drivers. You can find a bit more about NTVDM hereNo
Graphic LoaderXntvdm32.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
ntvdmdXntvdmd.exeAdware downloader - also detected as the DLOADER-YP TROJAN!No
NT-Virtual Device ManagerXntvdmn.exeAdded by the SDBOT-AAA WORM!No
ntvdscmXntvdscm.exeAdded by the SCKEYLOG-I TROJAN!No
NT MICROSOFT SVCDXntvsvcd.exeAdded by a variant of Win32/RbotNo
ntwk.exeXntwk.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %AppData%No
ntx32Xntx32.exeAdded by an unidentified WORM or TROJAN!No
dxdll32Xntxdll.exeAdded by the GAOBOT.CPX WORM!No
ntxp2Xntxp2.exeAdded by the VB-API TROJAN!No
NT_KernalXNT_Kernal.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%No
Norton UtilitiesNnu.exePart of version 14.* of Symantec's Norton Utilities PC tune up suite. This entry will be present if you optionally select any of the following startup options (via Administer → Settings): "Custom Scan", "Privacy Clean & Full Scan" or "Send to tray"Yes
NortonUtilitiesNnu.exePart of version 14.* of Symantec's Norton Utilities PC tune up suite. This entry will be present if you optionally select any of the following startup options (via Administer → Settings): "Custom Scan", "Privacy Clean & Full Scan" or "Send to tray"Yes
nuNnu.exePart of version 14.* of Symantec's Norton Utilities PC tune up suite. This entry will be present if you optionally select any of the following startup options (via Administer → Settings): "Custom Scan", "Privacy Clean & Full Scan" or "Send to tray"Yes
uptolateXnucle.exeAdded by a variant of the BIFROSE TROJAN!No
nudylvataxnoXnudylvataxno.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %UserProfile%No
Audio SPP Solutions Engine PnP-X BuilderXnuikcmdeioi.exeDetected by McAfee as Downloader.a!dch and by Malwarebytes Anti-Malware as Trojan.AgentNo
[various names]XNukeSpan.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
Microsoft InstallshieldXnundll32.exeAdded by the AGOBOT-AHZ WORM!No
AhnLab V3Lite Update ProcessXnusb3mon.exeDetected by Microsoft as TrojanDownloader:Win32/Navattle.A and by Malwarebytes Anti-Malware as Trojan.Downloader. Note - this is neither a legitimate AhnLab V3 entry or the Renesas (was NEC) USB 3.0 monitor which has the same filename and is normally located in %ProgramFiles%\[vendor]\USB 3.0 Host Controller Driver\Application - this one is located in %System%No
NUSB3MONUnusb3mon.exeSupports USB 3.0 ports based upon the Renesas (was NEC) range of controllers on both system motherboards and external disk drives. Disabling it didn't seem to have any ill effects on USB 3.0 transfer speeds but it may be required to support power management featuresYes
USB 3.0 MonitorUnusb3mon.exeSupports USB 3.0 ports based upon the Renesas (was NEC) range of controllers on both system motherboards and external disk drives. Disabling it didn't seem to have any ill effects on USB 3.0 transfer speeds but it may be required to support power management featuresYes
NuvaTimeUNuvaTime.exeNuvaTime - reminder for women using NuvaRingNo
NUAgentInstallPathUNU_Install.exeInstaller associated with Chily Employee Activity Monitoring surveillance software. Uninstall this software unless you put it there yourselfNo
NvagNTXnvagNT.exeAdded by the AGOBOT-RV WORM!No
Microsoft System CheckupXnvapi32.exeAdded by the DONK.B WORM!No
NVIDIA nForce APU1 UtilitiesNNVATray.exenVidia's nForce Audio Processing Unit (APU)- "provides 3D positional audio and DirectX 8.0 compatibility, and encodes and decodes Dolby Digital 5.1 audio in real time"No
NvCCCplXNvCCCpl.exeAdded by the NOGATA-A TROJAN!No
NvCCplXNvCCpl.exeAdded by the CHILIN-A WORM!No
nVidia Chip4XNVCHIP4.EXEAdded by the LAMECADA-D BACKDOOR!No
winlogonXnvchost.exeAdded by an unidentified WORM or TROJAN!No
nvcoiXnvcoi.exeAdded by the DLOADER.TYO TROJAN!No
NVCOMXNVCOM.exeAdded by the AGOBOT-SB WORM!No
NvCplXNvCpl.EXEAdded by the YANZ.B WORM!No
NvCpl32DeamonXnvcpl.exeAdded by the SPYBOT.S WORM!No
NvCPL32Xnvcpl32.exeDetected by Trend Micro as WORM_AGOBOT.DAANo
nvcpllXnvcpll.exeAdded by the BANCBAN-PF TROJAN!No
FireWire ServicesXnvcsv32.exeDetected by Trend Micro as WORM_RBOT.AUMNo
HD MediaXnvcsvc.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Windir%No
nvctrl.exeXnvctrl.exeAdded by the ZLOB.G TROJAN!No
NaverVaccineXNVCUpgrader.exeDetected by Kaspersky as Trojan.Win32.Scar.rfw and by Malwarebytes Anti-Malware as Adware.K.NaverVaccine. The file is located in %ProgramFiles%\Naver\NaverVaccineNo
Win32 nvcXnvcva.exeAdded by the RBOT-ABF WORM!No
nvc Win32Xnvcvc.exeAdded by the RBOT-ADD WORM!No
nvd32 lptt01Xnvd32.exeRapidBlaster variant (in a "NvidStar" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove itNo
nvd32 ml097eXnvd32.exeRapidBlaster variant (in a "NvidStar" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove itNo
PostdavatchXnvdas.exeAdded by the RANDEX.T WORM!No
PostpatchXnvdes.exeAdded by the RANDEX.T WORM!No
NvCplDeamonXnvdisp.exeAdded by the PEEPVIE-I TROJAN!No
NVDispDrvXNVDispDRV.EXEAdded by the WINKO.AO WORM!No
NVIDIA PANELXnvdpnl.exeDetected by Malwarebytes Anti-Malware as Backdoor.Messa. The file is located in %AppData%No
NVidiaDrvXnvfsvm.comAdded by the DELF-A BACKDOOR!No
Messenger ServiceXnvhost.exeAdded by the JLOK-A WORM!No
Nvid32XNvid32.exeAdded by the GEMA TROJAN!No
Nvidex32XNvidex32.exeAdded by the GEMA TROJAN!No
DRIVERSSXnvidia.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DCGen. The file is located in %AppData%\driversNo
Microsoft Nvidia VideoXnvidia.exeAdded by a variant of W32/Sdbot.wormNo
nvidia:Xnvidia.exeDetected by Symantec as W32.KueightNo
Nvidia32Xnvidia32.exeCoolWebSearch parasite variant - also detected as the HOSTS-B TROJAN!No
NVIDIA DriversXNVIDIADrivers.exeDetected by Dr.Web as Trojan.KillFiles.10692 and by Malwarebytes Anti-Malware as Backdoor.AgentNo
nVidia DriversXnVidiaDrvers.exeAdded by the SDBOT-AFX WORM! Note - this is not related to any nVidia based motherboard or graphics cardNo
nVidia Application DriversXnvidiav32.exeAdded by a variant of the IRCBOT BACKDOOR!No
nvidll32Xnvidll32.exeAdded by the RBOT-XK WORM!No
nviload32Xnviload32.exeAdded by the SDBOT-VT WORM!No
nvirundllXnvirundll.exeAdded by the SPYBOT.NPS WORM!No
nvjxueXnvjxue.exeAdded by the EYEVEG-J WORM!No
NVmaxYNVmax.exeNVmax is a old tweaking utility for NVidia graphics cards. In the startup list if the user chooses to overclock their cardNo
NVMixerTrayNNVMixerTray.exeSystem Tray access to audio controls from nVidia's motherboard ForceWare softwareNo
NVIDIA System MonitorUNVMonitor.exeNVIDIA System Monitor - part of NVIDIA System Tools. Utility for monitoring and logging system statistics (such as temperatures, voltages, clocks and fan speeds) of NVIDIA based motherboards and graphics cardsYes
NVMonitorUNVMonitor.exeNVIDIA System Monitor - part of NVIDIA System Tools. Utility for monitoring and logging system statistics (such as temperatures, voltages, clocks and fan speeds) of NVIDIA based motherboards and graphics cardsYes
nvmsgdwnXNVMSGDWN.EXEAdded by the GRABER-D TROJAN!No
PCMCIA Resource Monitor?nvp2pmon.exeNVIDIA nForce P2P Driver. What does it do and is it required?No
NvPvrNetMonUNvPvrNetMon.exeNetwork monitor for the Personal Video Recorder function of the NVIDIA ForceWare Multimedia application - "makes sure you don't miss your favorite show. If you won't be home to watch the show, just use the PVR to set future recordings"No
NVIDIA® NVRAIDUnvraidservice.exePart of NVIDIA® MediaShield™ Storage - NVIDIA's management utility for creating and monitoring hard disk RAID arrays for the controllers integrated on their motherboards. Includes a Disk Alert System for troubleshooting with notifications via the System Tray. Not required if you don't have a RAID array or if you created the array at the BIOS level. Some users complain that it can report false errorsYes
NVRaidServiceUnvraidservice.exePart of NVIDIA® MediaShield™ Storage - NVIDIA's management utility for creating and monitoring hard disk RAID arrays for the controllers integrated on their motherboards. Includes a Disk Alert System for troubleshooting with notifications via the System Tray. Not required if you don't have a RAID array or if you created the array at the BIOS level. Some users complain that it can report false errorsYes
NVRTNnvrt.exeNVRefreshTool is a utility that will automatically detect the maximum refresh rate at each resolution that your monitor supportsNo
NVRTClk?NVRTClk.exeRelated to a Gigabyte video card. What does it do, and is it required?No
NvCplScanXnvsc32.exeDetected by Symantec as W32.Bropia.NNo
win-xpXnvsc32.exeDetected by Symantec as W32.Bropia.NNo
32.exeXnvscv32.exeAdded by the AGENT-LOL TROJAN!No
FireWire ServiceXnvscv32.exeDetected by Trend Micro as WORM_SDBOT.AXTNo
nvscv32Xnvscv32.exeDetected by McAfee as W32/Fujacks.sNo
NVSystem32Xnvscv32.exeAdded by the AGOBOT-NO WORM!No
svcshareXnvscv32.exeAdded by the FUJACKS-Z WORM!No
Winsock DriverXnvscv32.exeAdded by the AGOBOT-FD WORM!No
Net Command SenterXnvscvse.exeAdded by the IRCBOT!DF6280E5 VIRUS!No
nvsmudfmXnvsmudfm.exeDetected by Malwarebytes Anti-Malware as Adware.PinSearch. The file is located in %System%No
ctfmonXnvsv32.exeDetected by McAfee as Generic Dropper!fhr and by Malwarebytes Anti-Malware as Trojan.DelfNo
Norton updatedXnvsv32.exeDetected by Trend Micro as WORM_SDBOT.ABHNo
nvsv32.exeXnvsv32.exeDetected by Sophos as W32/Forbot-DINo
nvsv32.exeXnvsv33.exeAdded by the WOOTBOT.FP WORM!No
Generic Service ProcessXnvsvc.exeDetected by Trend Micro as WORM_AGOBOT.BY. Note - this is not the valid "NVIDIA Driver Helper Service" and is located in %System%No
Norton protectXnvsvc.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
nvsvcXnvsvc.exeAdded by the BANKER-HQ TROJAN! Note - this is not the valid "NVIDIA Driver Helper Service" and is located in %System%No
NVSVCXnvsvc.exeDetected by Trend Micro as WORM_AGOBOT.ALX. Note - this is not the valid "NVIDIA Driver Helper Service" and is located in %System%No
NvSvcNnvsvc.exeNVIDIA Driver Helper Service - installed when you change from the WDM drivers to nVidia's latest versions but not requied. Extreme shutdown delays can be encountered with this service active, but no adverse side effects with it disabled. NOTE: If using drivers other than nVidia's, such as Asus, this service may have been renamed to reflect thatNo
Symantec Security AddonXnvsvc.exeAdded by the AGOBOT-EN WORM! Note - do NOT confuse with the legitimate NVIDIA Driver Helper Service file of the same nameNo
nvsvc16Unvsvc16.exeMySuperSPy surveillance software. Uninstall this software unless you put it there yourselfNo
NVIDIA driver monitorXnvsvc32.exeDetected by Sophos as Troj~Agent-OZH and by Malwarebytes Anti-Malware as Trojan.CryptNo
nVidia Display DriverXnvsvc64.exeDetected by Sophos as W32/IRCBot-YK. Note - this is not related to any nVidia based graphics cardNo
Network Security XPXnvsvc86.exeAdded by the RBOT-GUI WORM!No
Office MonitorXnvsvc86.exeAdded by the IRCBOT.BVO BACKDOOR!No
clfmonXnvsvca32.exeAdded by the TACTSLAY.E TROJAN!No
nvsvca32Xnvsvca32.exeAdded by the TACTSLAY.E TROJAN!No
nVidia System DriversXnvsys32.exeAdded by an unidentified WORM or TROJAN! See hereNo
nVidia Display Drivers (x86)Xnvsys86.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
NVRotateSysTray?nvsysrot.dllRelated to NVIDIA nView Control Panel. What does it do and is it required?No
NVidia System UtilityUNVSystemUtility.exeNVidia System Utility - older version of the NVIDIA nTune utilty for monitoring and modifying the settings (such as temperatures, voltages, clocks and fan speeds) of NVIDIA based motherboards and graphics cards from within Windows. Now part of NVIDIA System ToolsNo
System File DriversXnvsysvc32.exeAdded by the AGOBOT.WJ WORM!No
Nvidia Control Center4XNvTaskbarIne.exeDetected by Trend Micro as TROJ_BREDOLAB.KONo
Nvidia Control Center3XNvTaskbarInh.exeDetected by Sophos as Troj/DelfInj-YNo
Nvidia Control Center2XNvTaskbarIni.exeDetected by Trend Micro as WORM_PROLACO.CUNo
Nvidia Control CenterXNvTaskbarInit.exeAdded by the HILOTI-AY TROJAN!No
Windows ARP DetectioncXnvudlsp.exeAdded by the AGENT.LMW BACKDOOR!No
9UmxQPSiTJMbAXNVUKZ.exeDetected by Sophos as Troj/Agent-LMNNo
zvb0dl2X8ttXNVUKZ.exeAdded by the AGENT-LMN TROJAN!No
nvvdirXnvvdir.exeDetected by Malwarebytes Anti-Malware as Trojan.Dropper. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
NvVideoCenterXNvVid.exeAdded by the HAXDOOR-DO TROJAN!No
CLCKRXnvvsvc.exeAdded by the AGENT-TQK TROJAN!No
Microsoft® Windows® Operating SystemXnvxdsinc.exeDetected by Dr.Web as Trojan.DownLoader5.40693 and by Malwarebytes Anti-Malware as Backdoor.MessaNo
kernel32Xnvxdsync.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserTemp%No
MSConfigXnvxp.exeDetected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Trojan.AgentNo
Netword AgentNnwant33.exeAn interesting browser utility that allows you to navigate by typing a single word or phrase (a "NetWord") related to what you're looking for into your browser's location field. It also puts an icon in the system tray icon that is a circle with the letter N in the center to access the menu faster. Available via Start → ProgramsNo
myNetWatchmanUnwclient.exeSends your firewall alerts to a website, which then filters them and forwards details of suspicious activities to the host ISP they originated from. Only needs to be running when your firewall is runningNo
Norman Worl System AbilityXnwcss32.exeAdded by the DELF.IO TROJAN!No
Windows Services TsXnwdpqqoiwm.exeAdded by the RBOT-GRV WORM!No
ZenoXnwinrqez.exeAdded by unidentified malware. The file is located in %System%No
csrssXnwiz.exeAdded by the CHODE-J WORM!No
Norton WizzardXnwiz.exeAdded by the GAOBOT.ADV WORM! Note - this is not the valid nVidia application that shares the same nameNo
nwizUnwiz.exePart of NVIDIA's NVIEW Display Management Software - included in drivers for consumer and professional graphics products. This entry runs the "NVIDIA Display Setup Wizard" if you connect (or already have connected) an additional display once the drivers have been installed. In later drivers it also loads the "nView Desktop Manager" (if you enable it via Control Panel → NVIDIA nView Desktop Manager) if you want to use features such as Hot Keys and Zoom. In both cases nwiz.exe doesn't remain in memoryYes
nwiz.exeUnwiz.exePart of NVIDIA's NVIEW Display Management Software - included in drivers for consumer and professional graphics products. This entry runs the "NVIDIA Display Setup Wizard" if you connect (or already have connected) an additional display once the drivers have been installed. In later drivers it also loads the "nView Desktop Manager" (if you enable it via Control Panel → NVIDIA nView Desktop Manager) if you want to use features such as Hot Keys and Zoom. In both cases nwiz.exe doesn't remain in memoryYes
NvUpdaterXnwiz32.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
nwiz32Xnwiz32.exeAdded by the SINBANK-A TROJAN!No
Microsoft Autorun1Xnwizdh.exeDetected by Symantec as W32.Ogleon.ANo
Microsoft Autorun20Xnwizfy.exeDetected by Symantec as W32.Ogleon.ANo
Microsoft Autorun3Xnwizhx2.exeDetected by Symantec as W32.Ogleon.ANo
nwizsXnwizs.exeAdded by the QUESHARE WORM! Note - the file is located in %ProgramFiles%\NVIDIA Corporation\PhysX\Common but is not a valid NVIDA PhysX fileNo
Microsoft Autorun7Xnwiztlbu.exeDetected by Symantec as W32.Ogleon.ANo
Microsoft Autorun11Xnwizwlwzs.exeDetected by Symantec as W32.Ogleon.ANo
Microsoft Autorun10Xnwizwmgjs.exeDetected by Symantec as W32.Ogleon.ANo
Microsoft Autorun12Xnwizzhuxians.exeDetected by Symantec as W32.Ogleon.ANo
NwpopupYNwpopup.exeBroadcast message handler part of Novell Netware that displays server, printer and other messagesNo
nwrecmsgUnwrecmsg.exeBroadcast message handler part of Novell Netware that displays server, printer and other messages - can cause crashesNo
NWTRAYYnwtray.exeNovell Netware. Displays the red "N" tray icon which can be disabled (by right-click on the icon) but is also needed by the clientNo
Microsoft WindowsXnwxdse.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %Windir%\SetNo
Microsoft OfficeXNxcao.exeAdded by the RBOT-ZE WORM!No
Microsoft OfficeXnxcxtpr.exeAdded by the RBOT-YG WORM!No
Dialog TrackerUNxdlghlp.exeExplorerPlus advanced file management alternative to Windows Explorer from Novatix. No longer availableNo
Nyet.exeXNyet.exeAdded by the DELF.MP TROJAN!No
nylycwamkosuXnylycwamkosu.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
NZ01XNZ01.exeAdded by the SCAR-K TROJAN!No
NetZIPFoldersNnzfprop.exeNetzip Classic zip file managerNo
WindowsUpdateXNzil.exeAdded by the CULLER-C WORM!No
McAfee Online Virus ScannerXnzm.exeAdded by the IRCBOT.XV WORM!No
SystemXXnzm.exeAdded by a variant of Win32/RbotNo
Microsoft Svchost local servicesXnzm23.exeAdded by the RBOT-GMC WORM!No
spc_wNnzspc.exeNetZero Search Enhancement relatedNo
nzwnt.exeXnzwnt.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.NT. The file is located in %Windir% - see hereNo
mikrosoft.exeXN_K.exeDetected by Dr.Web as Trojan.Siggen5.11268 and by Malwarebytes Anti-Malware as Backdoor.AgentNo
mikrosoft_servises.exeXN_K.exeDetected by Dr.Web as Trojan.Siggen5.11268 and by Malwarebytes Anti-Malware as Backdoor.AgentNo
N_K.exeXN_K.exeDetected by Dr.Web as Trojan.Siggen5.11268 and by Malwarebytes Anti-Malware as Backdoor.AgentNo
servises_mikrosoft.exeXN_K.exeDetected by Dr.Web as Trojan.Siggen5.11268 and by Malwarebytes Anti-Malware as Backdoor.AgentNo
sirvises.exeXN_K.exeDetected by Dr.Web as Trojan.Siggen5.11268 and by Malwarebytes Anti-Malware as Backdoor.AgentNo

Notes & Warnings

If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us (startups_at_pacs-portal_dot_co_dot_uk).

"Status" key:

Variables:

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. We will not be held responsible if changes you make cause a system failure.

WARNING: This is NOT a database of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a database of start-up applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at start-up. For a list of tasks/processes you should try the Process Library from Uniblue, the list at PC Pitstop or one of the many others now available. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSConfig or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

To avoid the database becoming too large, all malware entries are only shown using the registry version which is common to all Windows versions. Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.

As more than 15K entries in this database related to malware you should use a quality internet security package. Which ever you choose, keep it updated and get the latest version at least every two years.

There are a number of virus and malware entried listed in this database where specific removal instructions haven't been given. If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. See here for a tutorial on how to use the program

NOTE: A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Norton eMail Protect" in the registry.

SERVICES: "Services" from the NT/2K/XP/Vista/7 operating systems are not included. We fully understand that some programs with these OS's use "Services" as an alternative to load their component parts at startup but these are handled in a different way. We recommend you try BlackViper for information on services for the relevant operating systems.

Copyright

Presentation, format & comments Copyright © 2001 - 2012 Pacman's Portal
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein, CastleCops & Bleeping Computer
Powered by Malwarebytes
All rights reserved

Valid XHTML 1.0 Transitional

Privacy Policy Site Map Home